add: icmp as a bypass network entry protocol #226
Loading…
Reference in a new issue
No description provided.
Delete branch "add/icmp-network-entries"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Network bypass entries (#116) take
tcp/udpplus a port, or nothing. A monitoring container that should ping a public target over the physical link (docker#413) cannot be expressed: a bare subnet entry sends everything from that subnet past the tunnel, container-to-container traffic included, because the network table only holds the physical link's default.Fix
icmpas a third protocol, no port: the validator refuses a port with it, the entry dialog disables the port field for it, and the v6 rule usesicmpv6. README sentence added.Verification
pytest: 548 passed. New cases: icmp parses, icmp with a port is rejected,-p icmpon ip4 and-p icmpv6on ip6, no--dport.ruff check --select E9,F63,F7,F82 .and the SyntaxWarning compileall gate pass.172.18.7.0/24 icmpentry and aqomui connected, blackbox's ICMP RTT to 1.1.1.1 should sit at the raw link's ~13 ms rather than the tunnel's ~50 ms.🤖 Generated with Claude Code
Verified live, built from this branch (
aqomui-git 0.9.2.r427.g7260b5f), service restarted, entry172.18.7.0/24 icmpadded in the bypass tab, tunnel connected.iptables-legacy -t mangle -L aqomui_bypass_net -v -n:The icmp counter climbed 9 → 95 → 99 across three reads at the probe's rate (two targets every 15 s), the udp rule kept counting gluetun. Consumer: mysticalsoap/docker PR for #413.