bump google/nftables to v0.3.0
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

Set NAT.Specified on DNAT with a port so compiled exprs match kernel readback.
This commit is contained in:
2026-10-03 22:56:20 +10:00
parent 63c46fec81
commit 445d14c61e
4 changed files with 24 additions and 21 deletions
+2
View File
@@ -563,6 +563,7 @@ func (c *Compiler) compileDNATRule(state *FirewallState, tag, srcZone, srcAddr,
)
natExpr.RegProtoMin = 2
natExpr.RegProtoMax = 2
natExpr.Specified = true
}
exprs = append(exprs, natExpr)
} else {
@@ -583,6 +584,7 @@ func (c *Compiler) compileDNATRule(state *FirewallState, tag, srcZone, srcAddr,
)
natExpr.RegProtoMin = 2
natExpr.RegProtoMax = 2
natExpr.Specified = true
}
exprs = append(exprs, natExpr)
}
+8 -4
View File
@@ -456,15 +456,19 @@ func TestCompile_DNAT(t *testing.T) {
t.Fatalf("Compile() error: %v", err)
}
found := false
var nat *expr.NAT
for _, r := range state.Rules["prerouting"] {
if r.Tag == "rule:0" {
found = true
nat, _ = r.Exprs[len(r.Exprs)-1].(*expr.NAT)
break
}
}
if !found {
t.Error("no DNAT rule found in prerouting chain")
if nat == nil {
t.Fatal("no DNAT rule found in prerouting chain")
}
// The kernel reports PROTO_SPECIFIED whenever a port register is set.
if nat.RegProtoMin != 2 || !nat.Specified {
t.Errorf("DNAT with port must set RegProtoMin and Specified to match kernel readback, got %+v", nat)
}
}