Emit nft-decodable family guards #40
Reference in New Issue
Block a user
Delete Branch "benvin/nft-decodable"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why:
nft listcannot decode rules carrying repeated or conflictingmeta nfprotoguards, and single-family guards on negated lists made DROPs fail open.TOMSWALL_NETNS_TEST=1) lists all three families!192.0.2.1) is now guardedip4, so the DROP/REJECT no longer matches IPv6 packets (before, the non-matching payload compare was true for them);Dest: "net:!2001:db8::5"with a v4 zone is dropped outright by the contradiction check (:98) so the rule vanishes → for negated lists emit the guarded compare plus an unguarded other-family variant (as zoneMatchExprs does per family), and do not treat a negated guard as a hard family requirement.!192.0.2.1,2001:db8::1) stay unguarded, so the v4 compare reads bytes 12-15 of an IPv6 header (attacker-chosen source bits) and the v6 compare reads past the IPv4 header; a v6 source with 2001:db8:c000:201:: bits skips the exclusion and the DROP does not fire → split by family into one guarded rule per family instead of leaving the list unguarded.ip6 saddr/ip saddrof the wrong length), contrary to the "other-family dropped" contract; the new TestCompile_FamilyGuardsDecodable fails for ip and ip6 as soon as guardCfg addsSource: "net:!192.0.2.1,2001:db8::1"→ fix with the per-family split above and add that rule to guardCfg.Source: net:!10.0.0.0/8) now fails to compile inipandip6tables (and with a single-family negation in inet), where one rule was emitted before and only one is emitted now. Shorewall v4 configs oniptables regress → count alternatives after dropping the other family (skip those whose addrFamily differs from the table family; for a negated single-family list in inet keep the guard only if both alternatives survive) and add an ip-table test with ratelimit + negated source.No findings.