Keep set references and rule tracking consistent when a routing rule fails

This commit is contained in:
Viktor Liu
2026-08-21 12:32:36 +02:00
parent dd54240f42
commit 4b70772a4a
3 changed files with 55 additions and 3 deletions
@@ -158,7 +158,13 @@ func (r *family) queueNatRule(pair firewall.RouterPair, exprs []expr.Any) {
if _, exists := r.rules[ruleID]; exists {
if err := r.removeNatRule(pair); err != nil {
// The rule this replaces may still be in the kernel. Keep tracking
// it and skip the new one: overwriting the entry would leave the old
// rule installed with nothing that can find it again, while keeping
// it lets the next update retry the whole replacement.
log.Errorf("replace prerouting rule %s: %v", ruleID, err)
r.dropNetworkMatch(exprs)
return
}
}
@@ -360,7 +366,10 @@ func (r *family) queueLegacyRouteRule(pair firewall.RouterPair, exprs []expr.Any
if _, exists := r.rules[ruleID]; exists {
if err := r.removeLegacyRouteRule(pair); err != nil {
// Keep the old rule tracked instead of losing it, as in queueNatRule.
log.Errorf("replace legacy forwarding rule %s: %v", ruleID, err)
r.dropNetworkMatch(exprs)
return
}
}