fix: compare rule expressions by value in diff
This commit is contained in:
@@ -2,6 +2,7 @@ package nftables
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"reflect"
|
||||
"strings"
|
||||
|
||||
"github.com/google/nftables/expr"
|
||||
@@ -51,7 +52,7 @@ func computeDiff(current, desired *FirewallState) *ChangeSet {
|
||||
for _, rules := range current.Rules {
|
||||
for _, r := range rules {
|
||||
if r.Tag != "" {
|
||||
currentByTag[r.Tag] = append(currentByTag[r.Tag], r)
|
||||
currentByTag[ruleKey(r)] = append(currentByTag[ruleKey(r)], r)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -59,7 +60,7 @@ func computeDiff(current, desired *FirewallState) *ChangeSet {
|
||||
desiredByTag := make(map[string][]ManagedRule)
|
||||
for _, rules := range desired.Rules {
|
||||
for _, r := range rules {
|
||||
desiredByTag[r.Tag] = append(desiredByTag[r.Tag], r)
|
||||
desiredByTag[ruleKey(r)] = append(desiredByTag[ruleKey(r)], r)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -84,6 +85,11 @@ func computeDiff(current, desired *FirewallState) *ChangeSet {
|
||||
return cs
|
||||
}
|
||||
|
||||
// a tag can span chains and map iteration order is random, so group per chain
|
||||
func ruleKey(r ManagedRule) string {
|
||||
return r.Chain + "\x00" + r.Tag
|
||||
}
|
||||
|
||||
func rulesMatch(a, b []ManagedRule) bool {
|
||||
if len(a) != len(b) {
|
||||
return false
|
||||
@@ -103,7 +109,5 @@ func exprsEqual(a, b []expr.Any) bool {
|
||||
if len(a) != len(b) {
|
||||
return false
|
||||
}
|
||||
as := fmt.Sprintf("%v", a)
|
||||
bs := fmt.Sprintf("%v", b)
|
||||
return as == bs
|
||||
return reflect.DeepEqual(a, b)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user