I would like to submit the following PR and need a Task ID. Could you please approve this?
https://github.com/Amiya-Corp/vyos-1x_fork/pull/1
The summary below is copied from my PR:
Change summary
Fixes inconsistent handling of protocol specification in firewall configuration. When users specify protocol by IANA number (e.g., 6 for TCP), certain options like port specifications, TCP flags, and GRE settings would fail validation because the checks compare against string names.
This PR normalizes protocol numbers to their string names early in verify_rule() so all subsequent validations work consistently.
Example of the bug:
# This works set firewall ipv4 name RULE rule 1 protocol 6 # This fails with "Protocol must be tcp, udp, or tcp_udp when specifying a port" set firewall ipv4 name RULE rule 2 protocol 6 set firewall ipv4 name RULE rule 2 destination port 443
Types of changes
- Bug fix (non-breaking change which fixes an issue)
Related Task(s)
<!-- N/A -->
Related PR(s)
<!-- N/A -->
Component(s) name
src/conf_mode/firewall.py
How to test / Smoketest result
After this fix, all combinations work correctly. Each test case includes both Protocol Number and Protocol Name variants.
1. Port specification (TCP)
# Numeric protocol (6 = TCP) set firewall ipv4 name RULE rule 1 action accept set firewall ipv4 name RULE rule 1 protocol 6 set firewall ipv4 name RULE rule 1 destination port 443 # String protocol set firewall ipv4 name RULE rule 2 action accept set firewall ipv4 name RULE rule 2 protocol tcp set firewall ipv4 name RULE rule 2 destination port 443
2. Port specification (UDP)
# Numeric protocol (17 = UDP) set firewall ipv4 name RULE rule 3 action accept set firewall ipv4 name RULE rule 3 protocol 17 set firewall ipv4 name RULE rule 3 destination port 53 # String protocol set firewall ipv4 name RULE rule 4 action accept set firewall ipv4 name RULE rule 4 protocol udp set firewall ipv4 name RULE rule 4 destination port 53
3. TCP flags
# Numeric protocol (6 = TCP) set firewall ipv4 name RULE rule 5 action accept set firewall ipv4 name RULE rule 5 protocol 6 set firewall ipv4 name RULE rule 5 tcp flags syn # String protocol set firewall ipv4 name RULE rule 6 action accept set firewall ipv4 name RULE rule 6 protocol tcp set firewall ipv4 name RULE rule 6 tcp flags syn
4. GRE matching
# Numeric protocol (47 = GRE) set firewall ipv4 name RULE rule 7 action accept set firewall ipv4 name RULE rule 7 protocol 47 set firewall ipv4 name RULE rule 7 gre flags checksum unset set firewall ipv4 name RULE rule 7 gre key 100 # String protocol set firewall ipv4 name RULE rule 8 action accept set firewall ipv4 name RULE rule 8 protocol gre set firewall ipv4 name RULE rule 8 gre flags checksum unset set firewall ipv4 name RULE rule 8 gre key 100
5. synproxy action
# Numeric protocol (6 = TCP) set firewall ipv4 name RULE rule 9 action synproxy set firewall ipv4 name RULE rule 9 protocol 6 set firewall ipv4 name RULE rule 9 synproxy tcp mss 1460 # String protocol set firewall ipv4 name RULE rule 10 action synproxy set firewall ipv4 name RULE rule 10 protocol tcp set firewall ipv4 name RULE rule 10 synproxy tcp mss 1460
6. ICMP protocol (IPv4)
# Numeric protocol (1 = ICMP) set firewall ipv4 name RULE rule 11 action accept set firewall ipv4 name RULE rule 11 protocol 1 set firewall ipv4 name RULE rule 11 icmp type-name echo-request # String protocol set firewall ipv4 name RULE rule 12 action accept set firewall ipv4 name RULE rule 12 protocol icmp set firewall ipv4 name RULE rule 12 icmp type-name echo-request
7. ICMPv6 protocol (IPv6)
# Numeric protocol (58 = ICMPv6) set firewall ipv6 name RULE6 rule 1 action accept set firewall ipv6 name RULE6 rule 1 protocol 58 set firewall ipv6 name RULE6 rule 1 icmpv6 type-name echo-request # String protocol set firewall ipv6 name RULE6 rule 2 action accept set firewall ipv6 name RULE6 rule 2 protocol ipv6-icmp set firewall ipv6 name RULE6 rule 2 icmpv6 type-name echo-request
Link to Devin run: https://app.devin.ai/sessions/5a7eed8e95a944fdb70ed1183be15929
Requested by: @Nyandorew