Two bugs prevented the firewall step from working:
1. `netstat` was used to detect the SSH peer IP — not installed on
OpenWrt by default, so raw_conn was empty and the entire firewall
step was silently skipped.
2. Even if detection had worked, `src='*'` is wrong when zones have
`input='REJECT'`. The rule only takes effect before the zone policy
if `src` is the exact zone name.
Fix: switch to `ss` (always present), strip any IPv6-mapped prefix,
then walk `uci show firewall` to find the zone whose network interface
shares the same /24 as the peer IP. Use that zone name as `src`.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>