mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-08 16:01:29 +02:00
* Unify peer and route ACL filtering with multi-source peer rules * Remove partial userspace firewall mode and open foreign chains via a table-less allower * Snapshot iptables rule maps before persisting state * Scope userspace firewall wildcard source rules per address family * Install nftables peer filter and mangle rules in a single transaction * Share the iptables jump rule spec between install and cleanup * Fix legacy ACL source wildcard and keep rollback tracking on delete failure * Fix CI: recognize multi-value port set lookups in tests and correct PeerIP lint suppression * Fall back to per-prefix filter rules when ipset is unavailable * Annotate legacy PeerIP usages in ACL tests and fix import formatting * Keep firewall rule bookkeeping in step with the kernel on replace and teardown * Release the routing reference when the route manager shuts down * Keep set references and rule tracking consistent when a routing rule fails
28 lines
696 B
Go
28 lines
696 B
Go
package manager
|
|
|
|
import (
|
|
"fmt"
|
|
"net/netip"
|
|
)
|
|
|
|
// ForwardRule todo figure out better place to this to avoid circular imports
|
|
type ForwardRule struct {
|
|
Protocol Protocol
|
|
DestinationPort Port
|
|
TranslatedAddress netip.Addr
|
|
TranslatedPort Port
|
|
}
|
|
|
|
func (r ForwardRule) ID() RuleID {
|
|
id := fmt.Sprintf("%s;%s;%s;%s",
|
|
r.Protocol,
|
|
r.DestinationPort.String(),
|
|
r.TranslatedAddress.String(),
|
|
r.TranslatedPort.String())
|
|
return RuleID(id)
|
|
}
|
|
|
|
func (r ForwardRule) String() string {
|
|
return fmt.Sprintf("protocol: %s, destinationPort: %s, translatedAddress: %s, translatedPort: %s", r.Protocol, r.DestinationPort.String(), r.TranslatedAddress.String(), r.TranslatedPort.String())
|
|
}
|