Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

NDS 5.0.2 on OpenWrt 22.03: iptables-nft translation strips port matchers — pre-auth DNAT hijacks all TCP (not just :80)

オープン
#398 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
38/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
bash, go, linux

調査の方向性

Start from the OpenWrt packaging that ships NDS and the 20-nds-enforce.nft include (mentioned as hooking inet fw4 forward). Confirm how NDS 5.0.2 inserts iptables-nft rules on 22.03 versus 24.10, and where a version check or chain flush would live. Done means 22.03 is documented as unsupported and/or packaging flushes broken nds* chains so pre-auth TCP is not hijacked; this needs OpenWrt/nftables familiarity, not a one-file Go edit.

索引モデルが issue の本文から書いたものです。

説明

Environment

  • OpenWrt 22.03.3 (x86/64), mac80211_hwsim virtual radios
  • nodogsplash 5.0.2 (from 22.03 opkg feed)
  • tollgate-wrt v0.6.0-alpha1-lab (main@373770a)

Bug

NDS 5.0.2 on OpenWrt 22.03 inserts its firewall rules via iptables-nft. The translation to nftables strips the port match expressions from every TCP rule, leaving # xt_tcp comment markers:

chain ndsRTR {
    meta l4proto tcp # xt_tcp counter packets 0 bytes 0 drop
    meta l4proto tcp # xt_tcp counter packets 0 bytes 0 accept
    ...
}
chain ndsOUT {
    meta l4proto tcp # xt_tcp counter packets 4 bytes 240 # xt_DNAT
}
Consequences:
  1. ndsOUT (NAT PREROUTING): the DNAT rule has no port matcher → redirects ALL TCP from pre-auth clients, not just :80. Clients connecting to :2121 (the tollgate API) or :2051 (the portal SPA) get silently DNAT'd to NDS's internal gateway → blank page / hang.
  2. ndsRTR (INPUT): the port-specific allow rules (22, 53, 80, 2050, 2051, 2121) are dead — the meta l4proto tcp matches all TCP but the port discriminator is gone. Pre-auth clients can't reach the router on ANY TCP port.
Reproduction:
  1. Install NDS 5.0.2 on OpenWrt 22.03
  2. Start it on a bridge interface with clients
  3. From a pre-auth client, try to reach any router TCP port (e.g. :2121)
  4. Connection hangs or gets blank response (DNAT'd to NDS)
  5. Run nft list chain ip nat ndsOUT — observe # xt_tcp where port matchers should be
Why it works on 24.10:

The 20-nds-enforce.nft include in the tollgate packaging hooks into inet fw4 forward at priority -1, which solves a DIFFERENT problem (fw4 accepting before NDS sees packets). On 22.03, the problem is earlier in the pipeline — the iptables-nft translation itself is broken, so NDS's rules never function correctly regardless of the enforcement hook.

Workaround (for testing on 22.03):

Flush all NDS-inserted chains and write explicit nftables rules:

for T in ip filter ip nat ip mangle; do
  for C in $(nft list table $T | grep "chain nds" | sed "s/.*chain \([^ ]*\).*/\1/"); do
    nft flush chain $T $C
  done
done
echo f > /proc/net/nf_conntrack  # clear stale DNAT entries
Recommendation:
  • Document 22.03 as unsupported (or add a version check to the packaging)
  • The 20-nds-enforce.nft include should also flush NDS's broken iptables-nft chains on 22.03, not just add the fw4 hook
主要言語
Go
スター
12
フォーク
14
平均マージ
1日 5時間
マージ済み PR(30日)
220

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

OpenTollGate/tollgate-module-basic-go のほかの issue

OpenTollGate/tollgate-module-basic-go の issue をすべて見る

似ている issue

Go の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。