<feed xmlns='http://www.w3.org/2005/Atom'>
<title>firewall4/tests, branch master</title>
<subtitle>OpenWrt nftables firewall</subtitle>
<id>https://git-03.infra.openwrt.org/project/firewall4/atom?h=master</id>
<link rel='self' href='https://git-03.infra.openwrt.org/project/firewall4/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/'/>
<updated>2026-08-27T16:26:56Z</updated>
<entry>
<title>fw4: support forwardings in procd and netifd firewall data</title>
<updated>2026-08-27T16:26:56Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-06-04T21:50:38Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=c2ae8c8940a89407da32fbd662d4010ee2c9bbe6'/>
<id>urn:sha1:c2ae8c8940a89407da32fbd662d4010ee2c9bbe6</id>
<content type='text'>
Zones synthesised from published firewall data can now also declare
the forwardings between them. All zones are parsed before any
forwarding, so resolution is independent of declaration order.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>fw4: support zones in procd and netifd firewall data</title>
<updated>2026-08-27T16:26:56Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-06-04T21:50:33Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=b263f8ccbda7ea103cdfe553b631663438d0725e'/>
<id>urn:sha1:b263f8ccbda7ea103cdfe553b631663438d0725e</id>
<content type='text'>
Zone specs were collected from published firewall data but never
parsed. Accept them from the netifd interface data channel and from
procd service data, keep their declared names, default their policies
to drop to stay fail-closed, and attribute diagnostics for malformed
specs to their publisher.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>fw4: anchor per-interface ubus firewall specs by kind</title>
<updated>2026-08-27T16:26:24Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-06-04T21:50:24Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=d92213a9345efc984ff9c191e3b32eaedeac695d'/>
<id>urn:sha1:d92213a9345efc984ff9c191e3b32eaedeac695d</id>
<content type='text'>
Only rule and nat specs pin to the publishing interface device, which
protocol handlers such as 464xlat rely on; zone, forwarding, redirect
and ipset specs resolve through their own references, and an explicit
device on them is kept. An empty device opts a rule or nat out of the
pin and then requires a zone reference.

Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>fw4: accept a source rewrite range for ICMP</title>
<updated>2026-08-27T16:26:05Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-08-22T12:30:31Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=2b55562cdfb294e6baae14fa41f8d2f4b5c30556'/>
<id>urn:sha1:2b55562cdfb294e6baae14fa41f8d2f4b5c30556</id>
<content type='text'>
A snat_port range on proto icmp maps the ICMP identifier rather than
a port. map.sh emits one per MAP-E portset (RFC 7597) and firewall3
accepted it, while fw4 rejects the section, breaking ICMP source NAT
for MAP. Accept the range for ICMP and infer the IPv6 family for
ipv6-icmp; port match options still require UDP or TCP.

Fixes: 59dbb982b7fe ("Initial commit")
Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>fw4: warn about ubus firewall specs of unknown type</title>
<updated>2026-08-27T16:26:05Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-08-22T03:29:33Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=500d30940e55a0090a93c6a958df694be5a21340'/>
<id>urn:sha1:500d30940e55a0090a93c6a958df694be5a21340</id>
<content type='text'>
A typo in the type field silently disables the spec. Warn instead;
entries without a type field remain ignored as before.

Fixes: 59dbb982b7fe ("Initial commit")
Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>fw4: skip zones with duplicate names</title>
<updated>2026-08-27T16:12:55Z</updated>
<author>
<name>Daniel Golle</name>
</author>
<published>2026-08-22T03:29:13Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=22afe51bed7cf42015eb2403a84b571c3c670ad8'/>
<id>urn:sha1:22afe51bed7cf42015eb2403a84b571c3c670ad8</id>
<content type='text'>
Same-named zones emit duplicate defines and nft rejects the whole
ruleset. Keep the first zone of a name, skip later ones with a
diagnostic; a zone published over ubus never displaces a uci zone.

Fixes: 59dbb982b7fe ("Initial commit")
Signed-off-by: Daniel Golle &lt;daniel@makrotopia.org&gt;
</content>
</entry>
<entry>
<title>ruleset: apply egress MSS fixup later to apply final MTU before wire</title>
<updated>2023-11-03T13:33:55Z</updated>
<author>
<name>Andris PE</name>
</author>
<published>2023-06-21T10:06:24Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=698a53354fd280aae097efe08803c0c9a10c14c2'/>
<id>urn:sha1:698a53354fd280aae097efe08803c0c9a10c14c2</id>
<content type='text'>
Reduce scope of MSS fixup to TCP SYN packets only and relocate the fixing
of egress MSS to the mangle/postrouting chain in order to properly apply
final known MTU size.

Fixes: openwrt/openwrt#12112
Signed-off-by: Andris PE &lt;neandris@gmail.com&gt;
[fix S-o-b tag, fix commit author, reword commit message]
Signed-off-by: Jo-Philipp Wich &lt;jo@mein.io&gt;
</content>
</entry>
<entry>
<title>tests: adjust zone log limit testcases</title>
<updated>2023-11-03T13:14:15Z</updated>
<author>
<name>Jo-Philipp Wich</name>
</author>
<published>2023-11-03T13:14:15Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=de3483c561a728d5234a0a3f49b5dde4527a0f3f'/>
<id>urn:sha1:de3483c561a728d5234a0a3f49b5dde4527a0f3f</id>
<content type='text'>
Fix testcase failure introduced by a previous commit.

Fixes: a5553da ("ruleset: reduce ksoftirqd load by refering to looopback by numeric id")
Signed-off-by: Jo-Philipp Wich &lt;jo@mein.io&gt;
</content>
</entry>
<entry>
<title>ruleset: reduce ksoftirqd load by refering to looopback by numeric id</title>
<updated>2023-11-03T13:11:06Z</updated>
<author>
<name>Andris PE</name>
</author>
<published>2023-09-19T15:23:59Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=a5553dae70439c7e4fa910490fcf12a1ffff5bd2'/>
<id>urn:sha1:a5553dae70439c7e4fa910490fcf12a1ffff5bd2</id>
<content type='text'>
Reduce ksoftirq load by half using more efficient reference to loopback
which always has index equal to one.

Should help a lot with openwrt/openwrt#12914, openwrt/openwrt#12121 and
similar iperf3 cases clamping against 100% CPU usage.

Signed-off-by: Andris PE &lt;neandris@gmail.com&gt;
[fix S-o-b tag, fix commit author, rewrap commit message]
Signed-off-by: Jo-Philipp Wich &lt;jo@mein.io&gt;
</content>
</entry>
<entry>
<title>ruleset: dispatch ct states using verdict map</title>
<updated>2023-11-03T13:09:43Z</updated>
<author>
<name>Andris PE</name>
</author>
<published>2023-09-07T19:04:35Z</published>
<link rel='alternate' type='text/html' href='https://git-03.infra.openwrt.org/project/firewall4/commit/?id=19a8caf614ec338513e58535ea02c6ee52988170'/>
<id>urn:sha1:19a8caf614ec338513e58535ea02c6ee52988170</id>
<content type='text'>
In case the dropping of invalid conntrack states is enabled, using a verdict
map allows us to use only one rule instead of two, lowering the initial rule
match overhead.

Signed-off-by: Andris PE &lt;neandris@gmail.com&gt;
[whitespace cleanup, rebase, extend commit subject and message]
Signed-off-by: Jo-Philipp Wich &lt;jo@mein.io&gt;
</content>
</entry>
</feed>
