fix: compare rule expressions by value in diff
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

This commit is contained in:
2026-10-03 20:48:29 +10:00
parent 410109515e
commit e16d95fb63
3 changed files with 62 additions and 7 deletions
+9 -5
View File
@@ -2,6 +2,7 @@ package nftables
import (
"fmt"
"reflect"
"strings"
"github.com/google/nftables/expr"
@@ -51,7 +52,7 @@ func computeDiff(current, desired *FirewallState) *ChangeSet {
for _, rules := range current.Rules {
for _, r := range rules {
if r.Tag != "" {
currentByTag[r.Tag] = append(currentByTag[r.Tag], r)
currentByTag[ruleKey(r)] = append(currentByTag[ruleKey(r)], r)
}
}
}
@@ -59,7 +60,7 @@ func computeDiff(current, desired *FirewallState) *ChangeSet {
desiredByTag := make(map[string][]ManagedRule)
for _, rules := range desired.Rules {
for _, r := range rules {
desiredByTag[r.Tag] = append(desiredByTag[r.Tag], r)
desiredByTag[ruleKey(r)] = append(desiredByTag[ruleKey(r)], r)
}
}
@@ -84,6 +85,11 @@ func computeDiff(current, desired *FirewallState) *ChangeSet {
return cs
}
// a tag can span chains and map iteration order is random, so group per chain
func ruleKey(r ManagedRule) string {
return r.Chain + "\x00" + r.Tag
}
func rulesMatch(a, b []ManagedRule) bool {
if len(a) != len(b) {
return false
@@ -103,7 +109,5 @@ func exprsEqual(a, b []expr.Any) bool {
if len(a) != len(b) {
return false
}
as := fmt.Sprintf("%v", a)
bs := fmt.Sprintf("%v", b)
return as == bs
return reflect.DeepEqual(a, b)
}