CHAOS NIGHT: the internet-block accident now cleans up unconditionally
gates / gates (push) Successful in 20s

Reviewed before it runs unattended at ~01:11, not after. The accident flips a
host-wide sysctl on demo-hp and inserts two FORWARD rules, and its cleanup ran
only on the happy path: if the script were killed during its ten-minute sleep,
or the SSH dropped, the rules and the sysctl would have stayed. demo-hp is a
Tier-0 host that guests 9201 and 9202 also live on, so an abandoned FORWARD
rule is a fence breach rather than a measurement.

It now traps EXIT, INT and TERM, removes both rules and restores the sysctl
whatever happens, and clears the trap on the normal path so the cleanup does
not run twice. The rules still match --physdev-in on this VM's own tap, resolved
at run time, and the default FORWARD policy is never touched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-16 23:34:00 +02:00
parent 7221367f38
commit fa1ddd92a5
@@ -49,11 +49,22 @@ case "$A" in
H "sysctl -w net.bridge.bridge-nf-call-iptables=1 >/dev/null
iptables -I FORWARD 1 -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT
iptables -I FORWARD 2 -m physdev --physdev-in $TAP -j DROP"
# UNCONDITIONAL cleanup: if this script is killed during the sleep, or the SSH drops, the host
# must NOT be left with the rules in place and the sysctl flipped. demo-hp is a Tier-0 host that
# 9201 and 9202 also live on, and an abandoned FORWARD rule is a fence breach, not a measurement.
netcleanup(){
H "iptables -D FORWARD -m physdev --physdev-in $TAP -j DROP 2>/dev/null
iptables -D FORWARD -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT 2>/dev/null
sysctl -w net.bridge.bridge-nf-call-iptables=0 >/dev/null 2>&1" >/dev/null 2>&1
say "net cleanup ran (rules removed, sysctl restored)"
}
trap 'netcleanup' EXIT INT TERM
say "blocked (LAN allowed, everything else dropped) — 10 minutes"
sleep 600
H "iptables -D FORWARD -m physdev --physdev-in $TAP -j DROP
iptables -D FORWARD -m physdev --physdev-in $TAP -d 192.168.0.0/24 -j ACCEPT
sysctl -w net.bridge.bridge-nf-call-iptables=0 >/dev/null"
trap - EXIT INT TERM
say "unblocked; host sysctl restored to 0 and both rules removed"
H "iptables -S FORWARD | head -5" | tee -a "$LOG"
;;