diff options
author | tv <tv@krebsco.de> | 2022-12-30 21:34:05 +0100 |
---|---|---|
committer | tv <tv@krebsco.de> | 2022-12-30 21:41:43 +0100 |
commit | 2ebbec1f2d9c16fe084abba87718d0f60e61bf88 (patch) | |
tree | 961f24ea689a45061087ab27d26f79d487d23111 /krebs | |
parent | 42f604cd1b45e73422277a7c0431eab97165a910 (diff) |
krebs.iptables: precedence -> mkOrder
Diffstat (limited to 'krebs')
-rw-r--r-- | krebs/3modules/iptables.nix | 8 |
1 files changed, 1 insertions, 7 deletions
diff --git a/krebs/3modules/iptables.nix b/krebs/3modules/iptables.nix index 7007090c0..052dad9c6 100644 --- a/krebs/3modules/iptables.nix +++ b/krebs/3modules/iptables.nix @@ -43,10 +43,6 @@ let target = mkOption { type = str; }; - precedence = mkOption { - type = int; - default = 0; - }; v4 = mkOption { type = bool; default = true; @@ -145,13 +141,11 @@ let buildChain = tn: cn: let filteredRules = filter (r: r."${v}") ts."${tn}"."${cn}".rules; - sortedRules = sort (a: b: a.precedence > b.precedence) filteredRules; - in #TODO: double check should be unneccessary, refactor! if ts.${tn}.${cn}.rules or null != null then concatMapStringsSep "\n" (rule: "\n-A ${cn} ${rule}") ([] - ++ map (buildRule tn cn) sortedRules + ++ map (buildRule tn cn) filteredRules ) else "" |