Skip to content

Reject explicit legacy probing on modern Docker hosts - #5

Merged
chen21019 merged 2 commits into
mainfrom
verification/ipsec-vxlan-overlay-network-explicit-backend
Sep 12, 2026
Merged

chen21019 merged 2 commits into
mainfrom
verification/ipsec-vxlan-overlay-network-explicit-backend

Conversation

@chen21019

Copy link
Copy Markdown

Prevent a mistaken explicit iptables-legacy choice on an iptables-nft host from invoking the legacy frontend (which can load old modules merely for an inspection). Require an already-loaded legacy NAT table for old hosts; native nft and automatic selection stay unchanged. Add fail-closed tests and document the boundary. The protected release remains gated by same-SHA main CI and a published image digest.

@chen21019
chen21019 requested a review from a team as a code owner September 12, 2026 07:28
@chen21019
chen21019 merged commit 8bdf403 into main Sep 12, 2026
5 checks passed
@chen21019
chen21019 deleted the verification/ipsec-vxlan-overlay-network-explicit-backend branch September 12, 2026 07:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant