From fa1ddd92a5caf0d21e0937f377736f9b70d4d714 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 16 Sep 2026 23:34:00 +0200 Subject: [PATCH] CHAOS NIGHT: the internet-block accident now cleans up unconditionally Reviewed before it runs unattended at ~01:11, not after. The accident flips a host-wide sysctl on demo-hp and inserts two FORWARD rules, and its cleanup ran only on the happy path: if the script were killed during its ten-minute sleep, or the SSH dropped, the rules and the sysctl would have stayed. demo-hp is a Tier-0 host that guests 9201 and 9202 also live on, so an abandoned FORWARD rule is a fence breach rather than a measurement. It now traps EXIT, INT and TERM, removes both rules and restores the sysctl whatever happens, and clears the trap on the normal path so the cleanup does not run twice. The rules still match --physdev-in on this VM's own tap, resolved at run time, and the default FORWARD policy is never touched. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- .../audits/evidence-chaos-night-2026-09-17/inject.sh | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh b/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh index b0d06dc0..d2315e0c 100755 --- a/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh +++ b/documentation/audits/evidence-chaos-night-2026-09-17/inject.sh @@ -49,11 +49,22 @@ case "$A" in H "sysctl -w net.bridge.bridge-nf-call-iptables=1 >/dev/null iptables -I FORWARD 1 -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT iptables -I FORWARD 2 -m physdev --physdev-in $TAP -j DROP" + # UNCONDITIONAL cleanup: if this script is killed during the sleep, or the SSH drops, the host + # must NOT be left with the rules in place and the sysctl flipped. demo-hp is a Tier-0 host that + # 9201 and 9202 also live on, and an abandoned FORWARD rule is a fence breach, not a measurement. + netcleanup(){ + H "iptables -D FORWARD -m physdev --physdev-in $TAP -j DROP 2>/dev/null + iptables -D FORWARD -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT 2>/dev/null + sysctl -w net.bridge.bridge-nf-call-iptables=0 >/dev/null 2>&1" >/dev/null 2>&1 + say "net cleanup ran (rules removed, sysctl restored)" + } + trap 'netcleanup' EXIT INT TERM say "blocked (LAN allowed, everything else dropped) — 10 minutes" sleep 600 H "iptables -D FORWARD -m physdev --physdev-in $TAP -j DROP iptables -D FORWARD -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT sysctl -w net.bridge.bridge-nf-call-iptables=0 >/dev/null" + trap - EXIT INT TERM say "unblocked; host sysctl restored to 0 and both rules removed" H "iptables -S FORWARD | head -5" | tee -a "$LOG" ;;