diff --git a/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh b/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh index b0d06dc0..d2315e0c 100755 --- a/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh +++ b/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh @@ -49,11 +49,22 @@ case "$A" in H "sysctl -w net.bridge.bridge-nf-call-iptables=1 >/dev/null iptables -I FORWARD 1 -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT iptables -I FORWARD 2 -m physdev --physdev-in $TAP -j DROP" + # UNCONDITIONAL cleanup: if this script is killed during the sleep, or the SSH drops, the host + # must NOT be left with the rules in place and the sysctl flipped. demo-hp is a Tier-0 host that + # 9201 and 9202 also live on, and an abandoned FORWARD rule is a fence breach, not a measurement. + netcleanup(){ + H "iptables -D FORWARD -m physdev --physdev-in $TAP -j DROP 2>/dev/null + iptables -D FORWARD -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT 2>/dev/null + sysctl -w net.bridge.bridge-nf-call-iptables=0 >/dev/null 2>&1" >/dev/null 2>&1 + say "net cleanup ran (rules removed, sysctl restored)" + } + trap 'netcleanup' EXIT INT TERM say "blocked (LAN allowed, everything else dropped) — 10 minutes" sleep 600 H "iptables -D FORWARD -m physdev --physdev-in $TAP -j DROP iptables -D FORWARD -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT sysctl -w net.bridge.bridge-nf-call-iptables=0 >/dev/null" + trap - EXIT INT TERM say "unblocked; host sysctl restored to 0 and both rules removed" H "iptables -S FORWARD | head -5" | tee -a "$LOG" ;;