Skip to content

Firewall types and cross-stack subnet stuff#1509

Merged
JackDoan merged 7 commits intomasterfrom
firewall-types
Nov 12, 2025
Merged

Firewall types and cross-stack subnet stuff#1509
JackDoan merged 7 commits intomasterfrom
firewall-types

Conversation

@JackDoan
Copy link
Collaborator

@JackDoan JackDoan commented Oct 21, 2025

firewall can distinguish if the host connecting has an overlapping network, is a VPN peer without an overlapping network, or is a unsafe network

has elements of #1498, but not the behavioral changes

  • needs many more tests!

@JackDoan JackDoan requested a review from nbrownus October 21, 2025 16:09
@JackDoan JackDoan force-pushed the firewall-types branch 2 times, most recently from 0a95deb to f09b99a Compare October 21, 2025 18:01
@JackDoan JackDoan mentioned this pull request Oct 28, 2025
7 tasks
@JackDoan JackDoan added this to the v1.10.0 milestone Nov 4, 2025
wadey
wadey previously approved these changes Nov 10, 2025
@JackDoan JackDoan changed the title Firewall types Firewall types and cross-stack subnet stuff Nov 11, 2025
…twork, is a VPN peer without an overlapping network, or is a unsafe network
* experiment with not filtering out non-common addresses in hostinfo.networks

* allow handshakes without overlaps

* checkpt

* wow

* lint

* these comments were backwards and bamboozled me

* lint

* unsafe network test

* unsafe network test reply

* change HostInfo.buildNetworks argument to reference the cert
@JackDoan JackDoan merged commit a89f951 into master Nov 12, 2025
9 checks passed
@JackDoan JackDoan deleted the firewall-types branch November 12, 2025 19:40
@nbrownus nbrownus mentioned this pull request Nov 19, 2025
63 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants