fix: keep bypass network entries on the physical link #222
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/bypass-networks-table"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem: Network entries mark forwarded traffic with the same fwmark as the app cgroup, so it resolves through table 11 - whose default a bypass VPN tunnel takes over (bypass_up.sh for OpenVPN, the table-11 route for WireGuard). Every listed network then rides the bypass tunnel: forwarded, so not masqueraded, so rejected by the server and retransmitted at line rate. Found live during #217's verification with gluetun's subnet listed: 43 GiB pushed into wg_aqomui_b in ten minutes, and the queue starvation hung every bypassed app's connection too. An OpenVPN bypass misroutes the same way, without the starvation making it obvious (#221).
Fix: Network entries get their own mark and routing table (12), which holds the physical link's default and is never touched by a tunnel. Table 11 keeps its role for the cgroup's sockets. set_routing installs both; the fwmark sweep and the startup flush cover both.
Verification: suite 543 passed - both tables' rules and defaults on both stacks, the sweep and flush covering table 12, network rules carrying the network mark. Live: with a bypass tunnel up and gluetun's network entry configured, gluetun keeps working (its own VPN stays on the physical link) and
aqomui-bypass curlshows the bypass tunnel's exit;ip route show table 12shows only the physical default.Closes #221.
🤖 Generated with Claude Code
Live-verified 2026-09-16 with main + OpenVPN bypass and gluetun's network entry configured: bypassed shell egresses via the bypass server, gluetun unaffected,
ip route show table 12holds only the physical-link default. Suite on this branch: 540. Ready to merge; the per-entry destination question this raised is #223.