bump google/nftables to v0.3.0
Set NAT.Specified on DNAT with a port so compiled exprs match kernel readback.
This commit is contained in:
@@ -563,6 +563,7 @@ func (c *Compiler) compileDNATRule(state *FirewallState, tag, srcZone, srcAddr,
|
||||
)
|
||||
natExpr.RegProtoMin = 2
|
||||
natExpr.RegProtoMax = 2
|
||||
natExpr.Specified = true
|
||||
}
|
||||
exprs = append(exprs, natExpr)
|
||||
} else {
|
||||
@@ -583,6 +584,7 @@ func (c *Compiler) compileDNATRule(state *FirewallState, tag, srcZone, srcAddr,
|
||||
)
|
||||
natExpr.RegProtoMin = 2
|
||||
natExpr.RegProtoMax = 2
|
||||
natExpr.Specified = true
|
||||
}
|
||||
exprs = append(exprs, natExpr)
|
||||
}
|
||||
|
||||
@@ -456,15 +456,19 @@ func TestCompile_DNAT(t *testing.T) {
|
||||
t.Fatalf("Compile() error: %v", err)
|
||||
}
|
||||
|
||||
found := false
|
||||
var nat *expr.NAT
|
||||
for _, r := range state.Rules["prerouting"] {
|
||||
if r.Tag == "rule:0" {
|
||||
found = true
|
||||
nat, _ = r.Exprs[len(r.Exprs)-1].(*expr.NAT)
|
||||
break
|
||||
}
|
||||
}
|
||||
if !found {
|
||||
t.Error("no DNAT rule found in prerouting chain")
|
||||
if nat == nil {
|
||||
t.Fatal("no DNAT rule found in prerouting chain")
|
||||
}
|
||||
// The kernel reports PROTO_SPECIFIED whenever a port register is set.
|
||||
if nat.RegProtoMin != 2 || !nat.Specified {
|
||||
t.Errorf("DNAT with port must set RegProtoMin and Specified to match kernel readback, got %+v", nat)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user