Skip to content

Feat/x4b hpfw provider - #6

Merged
splitice merged 25 commits into
masterfrom
feat/x4b-hpfw-provider
Sep 27, 2026
Merged

splitice merged 25 commits into
masterfrom
feat/x4b-hpfw-provider

Conversation

@splitice

Copy link
Copy Markdown
Member

No description provided.

@splitice

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ce20c3d22b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/xt_banset.c Outdated
Comment on lines +205 to +210
static inline u16 banset_expiry(u32 timeout)
{
u32 epochs = DIV_ROUND_UP(timeout, 1U << BANSET_EPOCH_SHIFT);

epochs = clamp_t(u32, epochs, 1, S16_MAX);
return banset_epoch() + epochs;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Preserve the requested timeout across epoch boundaries

For entries added late in a 32-second epoch, this computes expiry from the truncated current epoch rather than from the current time. For example, an entry added at boot second 31 with a 32-second timeout gets expiry epoch 1 and is considered expired at second 32, after only one second; even the documented 600-second timeout can expire about 23 seconds early. Round the absolute expiry time instead so entries cannot expire before their requested timeout.

Useful? React with 👍 / 👎.

Comment thread src/xt_banset.c Outdated
Comment on lines +207 to +210
u32 epochs = DIV_ROUND_UP(timeout, 1U << BANSET_EPOCH_SHIFT);

epochs = clamp_t(u32, epochs, 1, S16_MAX);
return banset_epoch() + epochs;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Do not silently cap long bans at roughly twelve days

Any timeout above S16_MAX * 32 seconds is silently reduced to that limit by this clamp. Thus a valid 30-day set or element timeout is reported and accepted through the ipset interface but expires after roughly 12.1 days, allowing traffic earlier than configured. Either use a representation that covers the supported timeout range or reject out-of-range values instead of shortening them.

Useful? React with 👍 / 👎.

Comment thread src/xt_banset.c Outdated
Comment on lines +1762 to +1765
list_for_each_entry(set, &banset_bindings, bindings)
if (set->family == family && set->net == net &&
!strncmp(set->set->name, name,
IPSET_MAXNAMELEN))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Resolve bindings from the current owner after ipset swap

When two bansets are exchanged with ipset swap, the core swaps their data while the name-bearing struct ip_set objects stay in place, but each struct banset retains the creator-time set->set backpointer. This lookup therefore returns the pre-swap backend for a name, so existing iptables and native lookups continue enforcing the old contents instead of the atomically swapped replacement; destroying the other name afterward can make those rules stop matching entirely.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T12:45:07.477539Z ce20c3d Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@splitice
splitice merged commit ddd843d into master Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant