RDKB-66199: In coperate mesh baul firewall rules for XER2 (#428) - #429
Merged
Merged
Conversation
Reason for change: Add meshbahul firewall rules for xer2 platform. Test Procedure:Make sure required iptable rules are applied for XER2. Priority:P1 Risks: Low Signed-off-by: Vysakh A V <vysakh.venugopal@sky.uk>
|
📋 PR Format Reminder
Expected: |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Firewall rule generation has unresolved range, nft syntax, and extender-mode issues.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds XER2 mesh backhaul firewall rules to legacy iptables and nftables paths.
Changes:
- Enables XER2 in mesh firewall rule branches.
- Adds XER2 interface filtering and forwarding rules.
| File | Summary | Findings |
|---|---|---|
source/firewall/firewall.c |
Adds XER2 iptables mesh rules. | Moderate: mesh ranges do not match XER2 DHCP configuration. |
source/firewall_nft/firewall_nft.c |
Adds XER2 nftables mesh rules. | Critical: generated nft rules include invalid iptables -j syntax. Moderate: range mismatch and missing extender-mode coverage. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| fprintf(filter_fp, "add rule ip filter INPUT iifname brebhaul ip daddr 169.254.85.0/24 counter accept\n"); | ||
| fprintf(filter_fp, "add rule ip filter INPUT iifname brebhaul pkttype != unicast counter accept\n"); | ||
| #elif defined(_XB7_PRODUCT_REQ_) || defined (_CBR2_PRODUCT_REQ_) | ||
| #elif defined(_XB7_PRODUCT_REQ_) || defined (_CBR2_PRODUCT_REQ_) || defined(_XER2_PRODUCT_REQ_) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Reason for change: Add meshbahul firewall rules for xer2 platform. Test Procedure:Make sure required iptable rules are applied for XER2. Priority:P1
Risks: Low