NetVM: never NAT host<->netvm traffic (fixes host->netns CDP)

This commit is contained in:
Antigravity Agent
2026-10-03 00:58:23 -04:00
parent 921e45566a
commit 63d1d10055
2 changed files with 7 additions and 3 deletions
+5 -2
View File
@@ -26,8 +26,11 @@ nsexec ip link set lo up
# host NAT + forwarding for the veth subnet
sysctl -qw net.ipv4.ip_forward=1
iptables -t nat -C POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || \
iptables -t nat -A POSTROUTING -s "$SUB" -j MASQUERADE
# NB: never NAT host<->netvm traffic — SNATing the host's own veth IP breaks
# host->netns connections (e.g. CDP): the reply would route out the tunnel.
iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true # migrate old broad rule
iptables -t nat -C POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE 2>/dev/null || \
iptables -t nat -A POSTROUTING -s "$SUB" ! -d 10.201.0.0/16 -j MASQUERADE
# endpoint bypasses the tunnel (else the handshake routes into itself)
ENDPOINT=$(grep -oP '^\s*Endpoint\s*=\s*\K[^:;#]+' "$CONF" | head -1)