fix: keep bypass network entries on the physical link #222

Merged
mysticalsoap merged 1 commit from fix/bypass-networks-table into trunk 2026-09-17 00:25:52 -04:00
Owner

Problem: Network entries mark forwarded traffic with the same fwmark as the app cgroup, so it resolves through table 11 - whose default a bypass VPN tunnel takes over (bypass_up.sh for OpenVPN, the table-11 route for WireGuard). Every listed network then rides the bypass tunnel: forwarded, so not masqueraded, so rejected by the server and retransmitted at line rate. Found live during #217's verification with gluetun's subnet listed: 43 GiB pushed into wg_aqomui_b in ten minutes, and the queue starvation hung every bypassed app's connection too. An OpenVPN bypass misroutes the same way, without the starvation making it obvious (#221).

Fix: Network entries get their own mark and routing table (12), which holds the physical link's default and is never touched by a tunnel. Table 11 keeps its role for the cgroup's sockets. set_routing installs both; the fwmark sweep and the startup flush cover both.

Verification: suite 543 passed - both tables' rules and defaults on both stacks, the sweep and flush covering table 12, network rules carrying the network mark. Live: with a bypass tunnel up and gluetun's network entry configured, gluetun keeps working (its own VPN stays on the physical link) and aqomui-bypass curl shows the bypass tunnel's exit; ip route show table 12 shows only the physical default.

Closes #221.

🤖 Generated with Claude Code

**Problem**: Network entries mark forwarded traffic with the same fwmark as the app cgroup, so it resolves through table 11 - whose default a bypass VPN tunnel takes over (bypass_up.sh for OpenVPN, the table-11 route for WireGuard). Every listed network then rides the bypass tunnel: forwarded, so not masqueraded, so rejected by the server and retransmitted at line rate. Found live during #217's verification with gluetun's subnet listed: 43 GiB pushed into wg_aqomui_b in ten minutes, and the queue starvation hung every bypassed app's connection too. An OpenVPN bypass misroutes the same way, without the starvation making it obvious (#221). **Fix**: Network entries get their own mark and routing table (12), which holds the physical link's default and is never touched by a tunnel. Table 11 keeps its role for the cgroup's sockets. set_routing installs both; the fwmark sweep and the startup flush cover both. **Verification**: suite 543 passed - both tables' rules and defaults on both stacks, the sweep and flush covering table 12, network rules carrying the network mark. Live: with a bypass tunnel up and gluetun's network entry configured, gluetun keeps working (its own VPN stays on the physical link) and `aqomui-bypass curl` shows the bypass tunnel's exit; `ip route show table 12` shows only the physical default. Closes #221. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix: keep bypass network entries on the physical link
All checks were successful
ci / test (pull_request) Successful in 23s
ci / test (push) Successful in 26s
37af64d6c0
Network entries marked forwarded traffic with the cgroup's fwmark, so
it resolved through table 11 - whose default a bypass VPN tunnel takes
over. Every listed network then rode the bypass tunnel: forwarded, so
not masqueraded, so rejected by the server and retransmitted at line
rate. With a WireGuard bypass that flood starved the device queue and
hung the bypassed apps too.

The entries exist to route past tunnels, not into one (#168). They get
their own mark and table now, holding the physical link's default and
never touched by a tunnel.

Closes #221

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Author
Owner

Live-verified 2026-09-16 with main + OpenVPN bypass and gluetun's network entry configured: bypassed shell egresses via the bypass server, gluetun unaffected, ip route show table 12 holds only the physical-link default. Suite on this branch: 540. Ready to merge; the per-entry destination question this raised is #223.

Live-verified 2026-09-16 with main + OpenVPN bypass and gluetun's network entry configured: bypassed shell egresses via the bypass server, gluetun unaffected, `ip route show table 12` holds only the physical-link default. Suite on this branch: 540. Ready to merge; the per-entry destination question this raised is #223.
mysticalsoap deleted branch fix/bypass-networks-table 2026-09-17 00:25:53 -04:00
Sign in to join this conversation.
No description provided.