No unattended security updates and no firewall ruleset #15
Labels
No labels
blocked-physical
cleanup
hardware
infra
kernel
P1-critical
P2-high
P3-normal
P4-later
reliability
security
upstream
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tiagoagueda/a80#15
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
unattended-upgradesis not installed, andnftis present with an empty ruleset.Only port 22 listens today, but nothing prevents that changing as services are added.
⚠️ If unattended-upgrades is enabled, keep
Automatic-Rebootoff until the SPL hang issueis resolved — an automatic reboot on a board that sometimes does not come back is a worse
failure than a late patch.
Done when
unattended-upgradesinstalled, security-only, no automatic rebootDone — and the issue was understating it
Both boxes met, but the premise needed correcting first.
nft is present with an empty ruleset— it was worse than thatnftables was installed and
nftran, so an empty ruleset looked like the whole problem. It wasn't. This kernel was built withCONFIG_NETFILTERswitched off entirely:No firewall of any kind was possible. The package being installed made it look one command away; it was a kernel rebuild away. That is the third time today a capability looked present in userspace and was absent in the kernel, after zram (#13) and the module tree (#54).
IPv6 was enabled at the same time, which changes the stakes
The board now holds two global IPv6 addresses. That matters more than it sounds: with IPv4 only it sat behind NAT and was unreachable from outside by construction. A routed prefix has no such property — every address is globally routable, and the ruleset becomes the only thing between the internet and sshd, which listens on
::.So ssh over v6 is allowed from link-local and ULA only, never global. If the ISP routes a prefix here, a global rule would silently publish this board's sshd to the internet and look identical from inside. Local access is unaffected; ouranos reaches the board over IPv4.
NF_TABLES_INETdepends onIPV6, so the first pass had to use an IPv4-onlytable ip. With IPv6 on, the ruleset istable inetand covers both stacks.The ruleset
Default-drop input, drop forward, accept output. Beyond ssh and mDNS, two rules exist because their absence is expensive and looks like something else entirely:
The subnet is written as RFC1918 generally rather than this lab's /24 — behind NAT that blocks nothing that could otherwise reach the board, and it keeps the addressing out of a public repo (#6).
unattended-upgrades
Security origin only,
Automatic-Reboot "false", andRemove-Unused-Kernel-Packages "false"since the running kernel comes fromdeploy-kernel.shrather than apt. The reboot restriction is written into the config file with its reasoning, so nobody enables it later without meeting the argument — #3 records this board failing to return from an ordinary reboot, and #5 records that there is no remote power control.One mistake worth recording
Applying
provision.shafterwards silently replaced the IPv6 ruleset with the earlier IPv4-only one, and reportedfailures: 0. The staged copy was stale, and every check I had written passed on the old file too — it also hashook input,tcp dport 22 acceptandudp dport 68 accept. Nothing reloads nftables on install, so it would have surfaced only at the next reboot, as a firewall quietly missing every IPv6 rule.Checks are now specific enough to fail on the previous version. A check that passes on the thing it is meant to reject is worse than no check, because it converts "I did not look" into "I looked and it was fine".
Verified after a reboot, on both media
nftables active,policy drop, 2 ip6 rules, icmpv6 by type, 2 global IPv6 addresses, ssh/ping/DNS/apt all working, 0 failed units, drop counter showing only stray broadcast. The ruleset was applied behind a 180-second auto-rollback each time, because a wrong rule here costs the only access path.Done when
unattended-upgradesinstalled, security-only, no automatic reboot