Skip to content

RDKB-66199: In coperate mesh baul firewall rules for XER2 (#428) - #429

Merged
MonekaLakshmi merged 1 commit into
topic/RDKB-66824from
develop
Sep 24, 2026
Merged

MonekaLakshmi merged 1 commit into
topic/RDKB-66824from
develop

Conversation

@MonekaLakshmi

Copy link
Copy Markdown
Contributor

Reason for change: Add meshbahul firewall rules for xer2 platform. Test Procedure:Make sure required iptable rules are applied for XER2. Priority:P1
Risks: Low

Reason for change: Add meshbahul firewall rules for xer2 platform.
Test Procedure:Make sure required iptable rules are applied for XER2.
Priority:P1
Risks: Low
Signed-off-by: Vysakh A V <vysakh.venugopal@sky.uk>
Copilot AI lite review requested due to automatic review settings September 24, 2026 05:34
@MonekaLakshmi
MonekaLakshmi requested review from a team as code owners September 24, 2026 05:34
@github-actions

Copy link
Copy Markdown

📋 PR Format Reminder

  • Description missing:
    • Test Procedure
    • Priority (P0 / P1 / P2)

Expected:

TICKET-123 : brief description

Reason for change: why
Test Procedure: how to verify
Risks: Low / Medium / High
Priority: P0 / P1 / P2

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Firewall rule generation has unresolved range, nft syntax, and extender-mode issues.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds XER2 mesh backhaul firewall rules to legacy iptables and nftables paths.

Changes:

  • Enables XER2 in mesh firewall rule branches.
  • Adds XER2 interface filtering and forwarding rules.
File Summary Findings
source/​firewall/​firewall.c Adds XER2 iptables mesh rules. Moderate: mesh ranges do not match XER2 DHCP configuration.
source/​firewall_nft/​firewall_nft.c Adds XER2 nftables mesh rules. Critical: generated nft rules include invalid iptables -j syntax. Moderate: range mismatch and missing extender-mode coverage.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

fprintf(filter_fp, "add rule ip filter INPUT iifname brebhaul ip daddr 169.254.85.0/24 counter accept\n");
fprintf(filter_fp, "add rule ip filter INPUT iifname brebhaul pkttype != unicast counter accept\n");
#elif defined(_XB7_PRODUCT_REQ_) || defined (_CBR2_PRODUCT_REQ_)
#elif defined(_XB7_PRODUCT_REQ_) || defined (_CBR2_PRODUCT_REQ_) || defined(_XER2_PRODUCT_REQ_)
@MonekaLakshmi
MonekaLakshmi merged commit 00ab138 into topic/RDKB-66824 Sep 24, 2026
22 of 24 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 24, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants