Skip to content

Fix managed bridge forwarding and flat host ports - #24

Merged
chen21019 merged 2 commits into
mainfrom
fix/managed-forwarding-v0.8.19
Sep 14, 2026
Merged

chen21019 merged 2 commits into
mainfrom
fix/managed-forwarding-v0.8.19

Conversation

@chen21019

Copy link
Copy Markdown

Result

  • allow managed CNI subnets to initiate forwarding while permitting only established or related replies
  • restore Metadata and DNS reachability behind current Docker bridge filters
  • masquerade only owned flat-L2 DNAT targets so host-port replies return through the publishing host
  • enable loopback host ports only on the exact managed bridge and keep global firewall policy unchanged
  • publish a checksum-covered image identity file with each release

Verification

  • full Go unit/race test suite and validation scripts
  • native nft lifecycle test in an unshared network namespace
  • two Ubuntu 26.04.1 / Docker 29.8 VMs: native nftables and iptables-legacy
  • bidirectional L2, localhost and peer host ports, Metadata, DNS, and egress through a valid lab gateway

@chen21019
chen21019 requested a review from a team as a code owner September 13, 2026 23:33
@chen21019
chen21019 merged commit 1cfebba into main Sep 14, 2026
5 checks passed
@chen21019
chen21019 deleted the fix/managed-forwarding-v0.8.19 branch September 14, 2026 01:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant