get_port_forwards moves from ResidentialGatewayDriver to NatVpnMixin, which firewalls and home gateways already share, and PortForwardDict moves next to NATTranslationDict.
The contract now says what counts:
Only forwards from the WAN. Destination NAT between internal networks is left out, and so are rules that only exempt traffic from redirection.
"ANY" means every protocol.
External port 0 means every port, i.e. a whole host forwarded.
This is a declaration under TYPE_CHECKING only; nothing changes at runtime.
`get_port_forwards` moves from `ResidentialGatewayDriver` to `NatVpnMixin`, which firewalls and home gateways already share, and `PortForwardDict` moves next to `NATTranslationDict`.
The contract now says what counts:
- **Only forwards from the WAN.** Destination NAT between internal networks is left out, and so are rules that only exempt traffic from redirection.
- **`"ANY"`** means every protocol.
- **External port `0`** means every port, i.e. a whole host forwarded.
This is a declaration under `TYPE_CHECKING` only; nothing changes at runtime.
Related: NetOrk/netork#504
get_port_forwards was declared on ResidentialGatewayDriver alone, as if a
port forward were a home-router feature. A firewall forwards ports just the
same (OPNsense calls it destination NAT), and netOrk asks both: is this host
reachable from the internet, which CVEs are exposed. The declaration moves to
NatVpnMixin, where the two roles already overlap, and PortForwardDict next to
NATTranslationDict.
The contract now says what counts. Destination NAT between internal networks
and rules that only exempt traffic are not port forwards: callers read every
entry as "reachable from outside". "ANY" forwards every protocol and an
external port of 0 every port -- a whole host forwarded is the most exposed
case and must not fall out for lack of a port number.
Declaration only, under TYPE_CHECKING: nothing changes at runtime.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
get_port_forwardsmoves fromResidentialGatewayDrivertoNatVpnMixin, which firewalls and home gateways already share, andPortForwardDictmoves next toNATTranslationDict.The contract now says what counts:
"ANY"means every protocol.0means every port, i.e. a whole host forwarded.This is a declaration under
TYPE_CHECKINGonly; nothing changes at runtime.Related: NetOrk/netork#504