Files
fips/packaging/openwrt-ipk/files
Johnathan Corgan 14f9ab1637 OpenWrt: bind the Ethernet transport to the LAN bridge, and correct why br_netfilter is loaded
The shipped fips.yaml comment and the package README told users to bind
physical port names and never a bridge name such as br-lan, while the
shipped lan entry itself binds br-lan. A lab test settled which is right:
with a two-member Linux bridge, a socket on br-lan forms links and carries
traffic, while a socket on a bridge member port sends frames but never
forms a link, because the bridge takes the frames that arrive on its
members. br_netfilter does not change that, unloaded or loaded with its
call hooks off or on.

Correct the comment and the README rule to say: bind the LAN bridge, never
one of its member ports; ports outside any bridge bind by their own name.
Which ports the bridge holds depends on the board (on x86/64 OpenWrt eth0
is the LAN port and eth1 the WAN port), so the README describes the members
by board type and points at `bridge link`, which lists them. A DSA switch
with hardware bridge offload was not covered and needs a check on a router.

fips-bridge.conf, the package Makefile, 90-fips-setup and the README said
kmod-br-netfilter is needed for the Ethernet transport to receive frames
on bridge member ports. They now say what the module and the sysctl file
actually do (load br_netfilter with its IP, IPv6 and ARP call hooks off)
and that they do not make member ports usable. The dependency, the sysctl
file and the module load are kept as shipped; their removal waits on a
check on a router. The shipped configuration is unchanged.
2026-10-01 22:41:14 +00:00
..