Add try/confirm safe-apply and agent auto-revert
This commit is contained in:
@@ -2,6 +2,7 @@ package nftables
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"sort"
|
||||
"strings"
|
||||
|
||||
"github.com/google/nftables/expr"
|
||||
@@ -84,6 +85,32 @@ func computeDiff(current, desired *FirewallState) *ChangeSet {
|
||||
return cs
|
||||
}
|
||||
|
||||
// restoreChangeSet replaces every managed rule in current with the snapshot's,
|
||||
// in snapshot order, so a restore cannot reorder rules.
|
||||
func restoreChangeSet(current, snap *FirewallState) *ChangeSet {
|
||||
cs := &ChangeSet{}
|
||||
for _, rules := range current.Rules {
|
||||
for _, r := range rules {
|
||||
if r.Tag != "" {
|
||||
cs.Remove = append(cs.Remove, r)
|
||||
}
|
||||
}
|
||||
}
|
||||
chains := make([]string, 0, len(snap.Rules))
|
||||
for c := range snap.Rules {
|
||||
chains = append(chains, c)
|
||||
}
|
||||
sort.Strings(chains)
|
||||
for _, c := range chains {
|
||||
for _, r := range snap.Rules[c] {
|
||||
if r.Tag != "" {
|
||||
cs.Add = append(cs.Add, r)
|
||||
}
|
||||
}
|
||||
}
|
||||
return cs
|
||||
}
|
||||
|
||||
func rulesMatch(a, b []ManagedRule) bool {
|
||||
if len(a) != len(b) {
|
||||
return false
|
||||
|
||||
Reference in New Issue
Block a user