From nobody Tue Feb 10 01:15:15 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of redhat.com designates 170.10.133.124 as permitted sender) client-ip=170.10.133.124; envelope-from=libvir-list-bounces@redhat.com; helo=us-smtp-delivery-124.mimecast.com; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1663859620; cv=none; d=zohomail.com; s=zohoarc; b=i8PTYQLV6IDqpeh00S0a7BIR0BqCHjPtGN6rd3Rd3mYy74MZHAtMyl+Gd/6zQFy4qCMG0zN/zNKcZMpSjVvZdKLT/UJJBhFUFry3C2RguycZi+Vp8radR/4Dj8IF7xJa0ciPULLyIfjh9117Bt5Uu/pFQ9zTKo6EUNR1+CObPCA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1663859620; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=qz5zggcIRg63Abq2IDbyaRslMZL3xXzN+LL8A0M9VEg=; b=S1+FeuwXyCiiptapWENr4TBXf8slPDOB3hKXzcqWxS3aGwYCO1l+AyziLwwIqL3GfoeZ4ETpPxEv8O/EHjsdzBDelLESaVZW1QGT8Je/Xs70hCyLJcpzvBtP+AnjwlF96VC7xlmwLb25R15LFWj2hOdwh8Qo44bmSteYuMfrZ/I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 170.10.133.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by mx.zohomail.com with SMTPS id 1663859619999170.31163557978584; Thu, 22 Sep 2022 08:13:39 -0700 (PDT) Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-186-XJvHN55FMS2w1pVNwmrVSQ-1; Thu, 22 Sep 2022 11:13:33 -0400 Received: from smtp.corp.redhat.com (int-mx02.intmail.prod.int.rdu2.redhat.com [10.11.54.2]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 5AC7D857F90; Thu, 22 Sep 2022 15:13:30 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (unknown [10.30.29.100]) by smtp.corp.redhat.com (Postfix) with ESMTP id 48D2640C6EC2; Thu, 22 Sep 2022 15:13:30 +0000 (UTC) Received: from mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (localhost [IPv6:::1]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id DA5021946A69; Thu, 22 Sep 2022 15:13:29 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.rdu2.redhat.com [10.11.54.3]) by mm-prod-listman-01.mail-001.prod.us-east-1.aws.redhat.com (Postfix) with ESMTP id 95E0E1947040 for ; Thu, 22 Sep 2022 15:13:28 +0000 (UTC) Received: by smtp.corp.redhat.com (Postfix) id 7BDBD111F3B0; Thu, 22 Sep 2022 15:13:28 +0000 (UTC) Received: from egarver.remote.csb (unknown [10.22.34.107]) by smtp.corp.redhat.com (Postfix) with ESMTP id 356A11121331; Thu, 22 Sep 2022 15:13:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1663859618; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=qz5zggcIRg63Abq2IDbyaRslMZL3xXzN+LL8A0M9VEg=; b=OfBsE5mEqcdyfbvD6L2lJ9zrGVZpynTVy9pIEP0xH9zs/w6XocmD1HctJGiKRub1XqkzRH zA9aJjxeX+GMyijg/lv5+Ygn5t8UqPWAciK8+XzhLgLEoU/ZiTwolcbU8Fhw/UuW4m6gwB PRaepVj24TkZkfxl0r+uQnVncHqFzoA= X-MC-Unique: XJvHN55FMS2w1pVNwmrVSQ-1 X-Original-To: libvir-list@listman.corp.redhat.com From: Eric Garver To: libvir-list@redhat.com Subject: [PATCH v3 5/5] network: firewalld: add support for routed networks Date: Thu, 22 Sep 2022 11:13:24 -0400 Message-Id: <20220922151324.1650415-6-eric@garver.life> In-Reply-To: <20220922151324.1650415-1-eric@garver.life> References: <20220922151324.1650415-1-eric@garver.life> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.1 on 10.11.54.3 X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Laine Stump Errors-To: libvir-list-bounces@redhat.com Sender: "libvir-list" X-Scanned-By: MIMEDefang 3.1 on 10.11.54.2 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1663859620400100002 Content-Type: text/plain; charset="utf-8"; x-default="true" Signed-off-by: Eric Garver --- src/network/bridge_driver_linux.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/src/network/bridge_driver_linux.c b/src/network/bridge_driver_= linux.c index a0f593b06636..d9597d91beed 100644 --- a/src/network/bridge_driver_linux.c +++ b/src/network/bridge_driver_linux.c @@ -857,8 +857,17 @@ int networkAddFirewallRules(virNetworkDef *def) * nftables + default zone means that traffic cannot be * forwarded (and even DHCP and DNS from guest to host * will probably no be permitted by the default zone + * + * Routed networks use a different zone and policy which we al= so + * need to verify exist. Probing for the policy guarantees the + * running firewalld has support for policies (firewalld >=3D = 0.9.0). */ - if (virFirewallDZoneExists("libvirt")) { + if (def->forward.type =3D=3D VIR_NETWORK_FORWARD_ROUTE && + virFirewallDPolicyExists("libvirt-routed-out") && + virFirewallDZoneExists("libvirt-routed")) { + if (virFirewallDInterfaceSetZone(def->bridge, "libvirt-rou= ted") < 0) + return -1; + } else if (virFirewallDZoneExists("libvirt")) { if (virFirewallDInterfaceSetZone(def->bridge, "libvirt") <= 0) return -1; } else { --=20 2.35.3