mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
The shipped fips.yaml comment and the package README told users to bind physical port names and never a bridge name such as br-lan, while the shipped lan entry itself binds br-lan. A lab test settled which is right: with a two-member Linux bridge, a socket on br-lan forms links and carries traffic, while a socket on a bridge member port sends frames but never forms a link, because the bridge takes the frames that arrive on its members. br_netfilter does not change that, unloaded or loaded with its call hooks off or on. Correct the comment and the README rule to say: bind the LAN bridge, never one of its member ports; ports outside any bridge bind by their own name. Which ports the bridge holds depends on the board (on x86/64 OpenWrt eth0 is the LAN port and eth1 the WAN port), so the README describes the members by board type and points at `bridge link`, which lists them. A DSA switch with hardware bridge offload was not covered and needs a check on a router. fips-bridge.conf, the package Makefile, 90-fips-setup and the README said kmod-br-netfilter is needed for the Ethernet transport to receive frames on bridge member ports. They now say what the module and the sysctl file actually do (load br_netfilter with its IP, IPv6 and ARP call hooks off) and that they do not make member ports usable. The dependency, the sysctl file and the module load are kept as shipped; their removal waits on a check on a router. The shipped configuration is unchanged.
18 lines
891 B
Plaintext
18 lines
891 B
Plaintext
# FIPS: bridge netfilter settings
|
|
#
|
|
# The package loads br_netfilter (kmod-br-netfilter) and this file turns
|
|
# off its IP/IPv6/ARP call hooks, so frames the bridge forwards are not
|
|
# also run through the firewall's IP, IPv6 and ARP tables.
|
|
#
|
|
# Loading br_netfilter does not make a bridge member port usable for the
|
|
# FIPS Ethernet transport. A lab test with a two-member Linux bridge found
|
|
# that a socket bound to a member port never forms a link, with
|
|
# br_netfilter unloaded, loaded with these hooks off, or loaded with them
|
|
# on. A socket bound to the bridge itself (br-lan) works, both with
|
|
# br_netfilter unloaded and with it loaded as this file sets it.
|
|
# Bind the bridge. The module, its dependency and this file stay until
|
|
# their removal has been checked on a router.
|
|
net.bridge.bridge-nf-call-iptables=0
|
|
net.bridge.bridge-nf-call-ip6tables=0
|
|
net.bridge.bridge-nf-call-arptables=0
|