[PR #6930] [client] Escape dots in interface names for sysctl configuration #30031

Open
opened 2026-08-05 08:09:47 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/6930

State: closed
Merged: Yes


Describe your changes

This PR fixes a bug where sysctl settings fail to apply on network interfaces that contain dots in their names, such as flannel.1.

Previously, the Set function blindly replaced all dots in the sysctl key with slashes (/). For an interface like flannel.1, this incorrectly resolved to /proc/sys/net/ipv4/conf/flannel/1/rp_filter, which caused the operation to fail.

Changes made:

  • Introduced a dotEscape and percentEscape placeholder.
  • In Setup(), dots and percent signs inside interface names are now temporarily escaped before they are formatted into the standard sysctl key.
  • In Set(), after all standard dots are converted to directory slashes, the placeholder dots and percent signs are unescaped back into their literal representation for the final /proc/sys/... file path.
  • This ensures interface names are perfectly preserved on the filesystem without breaking the standard dotted sysctl format used in the keys map and Cleanup() routine.
  • Prevents path injection by combingin dots and percent sign replacement.

Closes #4396 - IP routing fails with flannel interface

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)
    Explanation: This is an internal fix for sysctl file path resolution on Linux to support interfaces with dots in their names (like flannel). It does not change any user-facing configuration, APIs, or CLI commands.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • Bug Fixes
    • Fixed handling of periods in network interface names when configuring Linux sysctl settings.
    • Ensured interface-specific reverse path filtering settings are applied to the correct system paths.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/6930 **State:** closed **Merged:** Yes --- ## Describe your changes This PR fixes a bug where sysctl settings fail to apply on network interfaces that contain dots in their names, such as `flannel.1`. Previously, the `Set` function blindly replaced all dots in the sysctl key with slashes (`/`). For an interface like `flannel.1`, this incorrectly resolved to `/proc/sys/net/ipv4/conf/flannel/1/rp_filter`, which caused the operation to fail. **Changes made:** - Introduced a `dotEscape` and `percentEscape` placeholder. - In `Setup()`, dots and percent signs inside interface names are now temporarily escaped before they are formatted into the standard sysctl key. - In `Set()`, after all standard dots are converted to directory slashes, the placeholder dots and percent signs are unescaped back into their literal representation for the final `/proc/sys/...` file path. - This ensures interface names are perfectly preserved on the filesystem without breaking the standard dotted sysctl format used in the `keys` map and `Cleanup()` routine. - Prevents path injection by combingin dots and percent sign replacement. ## Issue ticket number and link Closes #4396 - [IP routing fails with flannel interface](https://github.com/netbirdio/netbird/issues/4396) ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [x] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) *Explanation: This is an internal fix for sysctl file path resolution on Linux to support interfaces with dots in their names (like flannel). It does not change any user-facing configuration, APIs, or CLI commands.* <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6930"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787776674&installation_model_id=427504&pr_number=6930&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6930&signature=d139afd28be4fdd61e11d12d6971aae72bdfff6de1211f3fc58f0675fa509109"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>@codesmith-bot</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Fixed handling of periods in network interface names when configuring Linux sysctl settings. * Ensured interface-specific reverse path filtering settings are applied to the correct system paths. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 08:09:47 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#30031