mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-06 05:29:07 +02:00
[client] Unify peer and route ACL filtering with multi-source rules (#6322)
* Unify peer and route ACL filtering with multi-source peer rules * Remove partial userspace firewall mode and open foreign chains via a table-less allower * Snapshot iptables rule maps before persisting state * Scope userspace firewall wildcard source rules per address family * Install nftables peer filter and mangle rules in a single transaction * Share the iptables jump rule spec between install and cleanup * Fix legacy ACL source wildcard and keep rollback tracking on delete failure * Fix CI: recognize multi-value port set lookups in tests and correct PeerIP lint suppression * Fall back to per-prefix filter rules when ipset is unavailable * Annotate legacy PeerIP usages in ACL tests and fix import formatting * Keep firewall rule bookkeeping in step with the kernel on replace and teardown * Release the routing reference when the route manager shuts down * Keep set references and rule tracking consistent when a routing rule fails
This commit is contained in:
@@ -135,6 +135,14 @@ func (r *Router) CleanUp() {
|
||||
}
|
||||
}
|
||||
|
||||
// Give back the routing reference taken in UpdateRoutes, after the routes
|
||||
// are gone as above. Without this the sysctls enabling it changed (IPv6
|
||||
// forwarding and the accept_ra values that keep RA handling alive next to
|
||||
// it) stay applied once the client stops.
|
||||
if err := r.firewall.DisableRouting(); err != nil {
|
||||
log.Errorf("Failed to disable routing: %v", err)
|
||||
}
|
||||
|
||||
r.statusRecorder.CleanLocalPeerStateRoutes()
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user