mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-09 16:31:29 +02:00
* Unify peer and route ACL filtering with multi-source peer rules * Remove partial userspace firewall mode and open foreign chains via a table-less allower * Snapshot iptables rule maps before persisting state * Scope userspace firewall wildcard source rules per address family * Install nftables peer filter and mangle rules in a single transaction * Share the iptables jump rule spec between install and cleanup * Fix legacy ACL source wildcard and keep rollback tracking on delete failure * Fix CI: recognize multi-value port set lookups in tests and correct PeerIP lint suppression * Fall back to per-prefix filter rules when ipset is unavailable * Annotate legacy PeerIP usages in ACL tests and fix import formatting * Keep firewall rule bookkeeping in step with the kernel on replace and teardown * Release the routing reference when the route manager shuts down * Keep set references and rule tracking consistent when a routing rule fails
28 lines
577 B
Go
28 lines
577 B
Go
//go:build privileged
|
|
|
|
package iptables
|
|
|
|
import (
|
|
"fmt"
|
|
"net"
|
|
"net/netip"
|
|
)
|
|
|
|
func pfx(ip net.IP) []netip.Prefix {
|
|
if ip == nil {
|
|
return []netip.Prefix{netip.PrefixFrom(netip.IPv4Unspecified(), 0)}
|
|
}
|
|
if ip.IsUnspecified() {
|
|
if ip.To4() != nil {
|
|
return []netip.Prefix{netip.PrefixFrom(netip.IPv4Unspecified(), 0)}
|
|
}
|
|
return []netip.Prefix{netip.PrefixFrom(netip.IPv6Unspecified(), 0)}
|
|
}
|
|
a, ok := netip.AddrFromSlice(ip)
|
|
if !ok {
|
|
panic(fmt.Sprintf("invalid IP length: %d", len(ip)))
|
|
}
|
|
a = a.Unmap()
|
|
return []netip.Prefix{netip.PrefixFrom(a, a.BitLen())}
|
|
}
|