Skip to content

RDKB-66917 : [MNGVULN] Remediation of managed vulnerabilities in firewall - #434

Merged
snayak002c merged 11 commits into
developfrom
lan2self_isolated
Oct 1, 2026
Merged

snayak002c merged 11 commits into
developfrom
lan2self_isolated

Conversation

@Selvaranjani971

Copy link
Copy Markdown
Contributor

Reason for change: Added rules that are required for lan2self_isolatedBridges.
Test Procedure: To validate the testcases required for this rule created.
Risks: Medium
Priority: P1

Copilot AI balanced review requested due to automatic review settings September 30, 2026 08:13
@Selvaranjani971
Selvaranjani971 requested review from a team as code owners September 30, 2026 08:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Build guards, one-way nftables filtering, and hard-coded /24 prefixes leave security gaps.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity

Open (3)
What changed in this PR

Adds dynamic isolation rules for LAN bridges across iptables and nftables backends.

Changes:

  • Generates LAN-to-self isolation chains dynamically.
  • Adds cross-bridge forwarding drops.
  • Removes several hard-coded destination rules.
File Description
source/​firewall/​firewall.c Adds iptables bridge isolation rules.
source/​firewall_nft/​firewall_nft.c Adds nftables LAN-to-self isolation rules.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread source/firewall/firewall.c Outdated
Comment thread source/firewall_nft/firewall_nft.c Outdated
Comment thread source/firewall_nft/firewall_nft.c Outdated
Copilot AI balanced review requested due to automatic review settings September 30, 2026 10:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Hardcoded subnet assumptions and non-MultiLAN rule regressions leave security gaps.

Review effort: Balanced
Findings: 3 High severity

Open (3)
Resolved since last review (2)

Comment thread source/firewall/firewall.c
Comment thread source/firewall_nft/firewall_nft.c
Copilot AI balanced review requested due to automatic review settings September 30, 2026 13:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Source spoofing and earlier ACCEPT rules can bypass the new isolation controls.

Review effort: Balanced
Findings: 4 High severity

Open (4)
Resolved since last review (1)

Comment thread source/firewall/firewall.c
Comment thread source/firewall_nft/firewall_nft.c
Copilot AI balanced review requested due to automatic review settings October 1, 2026 18:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Hard-coded /24 source matching leaves configurable non-/24 bridge networks incompletely isolated.

Review effort: Balanced
Findings: 4 High severity

Open (4)

@snayak002c
snayak002c merged commit c40010a into develop Oct 1, 2026
11 of 13 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants