Skip to content

firewall: No length check in YANG #1389

@mattiaswal

Description

@mattiaswal

Current Behavior

For code snippets, logs, commands, etc., please use triple backticks:

admin@tauri:/> 
admin@tauri:/> 
admin@tauri:~$ tail -f /var/log/syslog
Feb  2 15:07:10 tauri hostapd: wifi0-untrusted: STA 28:6b:b4:e2:ac:ab IEEE 802.11: associated (aid 7)
Feb  2 15:07:10 tauri hostapd: wifi0-untrusted: STA 28:6b:b4:e2:ac:ab WPA: pairwise key handshake completed (RSN)
Feb  2 15:07:12 tauri firewalld[5418]: ERROR: Failed to load policy file 'appletv-to-lan-guest.xml': INVALID_NAME: Policy 'appletv-to-lan-guest': name has 20 chars, max is 18
Feb  2 15:07:13 tauri firewalld[5418]: ERROR: Failed to load direct rules file '/etc/firewalld/direct.xml': 'NoneType' object has no attribute 'cleanup'
Feb  2 15:07:13 tauri hostapd: wifi0-IoT: STA 34:b7:da:92:c5:30 IEEE 802.11: disassociated
lazzer@tollan ~/src/github.com/kernelkit/infix (new-frr)$ as 20 chars, max is 18

resulted in this configuration:

admin@tauri:/> show firewall 
Firewall            : active
Lockdown mode       : inactive
Default zone        : block
Log denied traffic  : off

─────────────────────────────────────────────
Zones
   NAME   TYPE  DATA    ALLOWED HOST SERVICES
⚷  block  iif   (none)  (none)

─────────────────────────────────────────────
Policies
   NAME             ACTION    INGRESS  EGRESS
⚷  allow-host-ipv6  continue  ANY      HOST
⚷  default-drop     drop      ANY      ANY


admin@tauri:/> 

And a brick, requiring serial recover.

Expected Behavior

admin@infix-c0-ff-ee:/> show log
May 15 07:21:02 infix-c0-ff-ee container[3192]: Successfully created container test from curios-httpd-v24.03.0
- (press h for help or q to quit)

Steps To Reproduce

No response

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingtriagePending investigation & classification (CCB)

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions