Revision history for Net-Firewall-BlockerHelper

0.1.0   2026-08-05/00:00
        - Add CIDR ban support via new ban_cidr, unban_cidr, and list_cidr
          methods, for backends advertising cidr_supported.
        - New backends:
          - nftables       :: per-instance inet table with v4/v6 sets.
          - firewalld      :: ipset plus firewall-cmd --direct rules.
          - ufw            :: per-IP prepend/delete rules.
          - linux_ip_route :: iproute2 null routes; needs no firewall.
          - npf            :: NetBSD npf table declared in npf.conf.
          - shorewall      :: Shorewall dynamic blacklist.
          - hosts_deny     :: TCP wrappers; marked region in /etc/hosts.deny.
          - file_reload    :: render the ban list to a file, run a reload hook.
          - xdp            :: XDP/eBPF drops via xdp-filter.
          - bgp_rtbh       :: BGP Remote Triggered Black Hole via ExaBGP,
            gobgp, or FRR; optional FlowSpec announcements.
          - dns_rpz        :: DNS RPZ triggers via nsupdate.
          - nsupdate       :: DNS blocklist via BIND dynamic updates.
          - routeros       :: MikroTik RouterOS address-list over ssh.
          - routeros_api   :: RouterOS address-list via the REST API.
          - vyos           :: VyOS firewall address-group via the HTTP API.
          - pfsense        :: pfSense alias via the pfSense-API package.
          - opnsense       :: OPNsense alias via its REST API.
          - fortigate      :: FortiGate address group via the FortiOS REST API.
          - panos          :: PAN-OS User-ID tag registration for a Dynamic
            Address Group.
          - juniper_srx    :: Junos address-book/address-set via REST.
          - cisco_fmc      :: Cisco Firepower (FMC) network group literals.
          - checkpoint     :: Check Point host objects in a group via the
            Management API.
          - f5_bigip       :: F5 BIG-IP address-list via iControl REST.
          - netscaler      :: NetScaler/ADC policy dataset via NITRO.
          - cloudflare     :: Cloudflare IP access rules via the v4 API.
          - aws_wafv2      :: AWS WAFv2 IP sets via the aws CLI.
          - azure          :: Azure NSG deny rule source prefixes via az.
          - cloud_armor    :: GCP Cloud Armor rule source ranges via gcloud.
          - fastly         :: Fastly Edge ACL entries.
          - akamai         :: Akamai Network Lists v2, EdgeGrid authenticated.
          - abuseipdb      :: report bans to AbuseIPDB; reporting only, pairs
            with a blocking backend.
        - Rework the iptables backend to use ipset with iptables/ip6tables.
          Adds tarpit and delude ban types via xtables-addons (TCP only).
        - Add stop, check, and flush methods to the frontend and all backends.
        - Add optional self healing: re_init the firewall setup if it was
          removed externally. On by default via the self_heal option.
        - re_init now treats teardown as best effort.
        - Kill commands now handle IPv6 as well as IPv4 and are scoped to the
          configured protocols and ports.
        - Security: anchor the IPv4/IPv6 validation regexps, preventing shell
          command injection via crafted ban targets.
        - Validate the prefix + name length against kernel object name limits
          at new, raising nameTooLong instead of a confusing init failure.
        - Validate ports as 1-65535 so bad ports fail at new, not at init.
        - Lowercase IPs on ban/unban so IPv6 case differences can not create
          duplicate or orphaned entries.
        - ipfw: block IPv4 and IPv6 by default with family-correct rules.
          The type option is now deny-vs-reject; legacy values still accepted.
        - ipfw: fix the kill option; remove the no-op UDP pipeline and match
          the IP as a fixed word.
        - ipfw/pf: only attach ports to port-capable protocols (tcp/udp/sctp),
          defaulting to tcp/udp when ports are given without protocols.
        - pf: fix ban/unban pfctl table syntax; kill without ports now kills
          all connections for the IP; kill pipelines are recorded instead of
          run in testing mode.
        - Frontend: fix swapped error/perror for a bad backend name; methods
          called before init_backend now raise a clear error.
        - Fix backends reporting invalidPrefixSpecified instead of invalidName
          for a bad or missing name.
        - Fix exit-code checks to use numeric comparison.
        - Fix protocol validation errors to reference getprotobyname.
        - init_backend now loads backends via require instead of string eval.
        - Only write test_data in testing mode.
        - Add tests covering command execution and failure handling,
          self-heal, IPv6 handling, and error codes.
        - Documentation and packaging fixes.

0.0.1   2025-07-09/22:00
        - Initial release.
