From 7f30f58a3e2f5e9a7333fa1f5be9c998c6ad098a Mon Sep 17 00:00:00 2001 From: lassulus Date: Sat, 18 Jul 2015 13:55:17 +0200 Subject: 3 lass.iptables: sort rules by precedence --- 3modules/lass/iptables.nix | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) (limited to '3modules/lass') diff --git a/3modules/lass/iptables.nix b/3modules/lass/iptables.nix index 1cd6d3f8e..ba05abeb2 100644 --- a/3modules/lass/iptables.nix +++ b/3modules/lass/iptables.nix @@ -95,10 +95,12 @@ let }; }; - #buildTable :: iptablesAttrSet` -> str + #buildTable :: iptablesVersion -> iptablesAttrSet` -> str #todo: differentiate by iptables-version - buildTables = iptv: ts: + buildTables = v: ts: let + sortedTable = sort (a: b: a.precedence < b.precedence) ts; + declareChain = t: cn: #TODO: find out what to do whit these count numbers ":${cn} ${t."${cn}".policy} [0:0]"; @@ -106,7 +108,6 @@ let buildChain = tn: cn: #"${concatStringsSep " " ((attrNames t."${cn}") ++ [cn])}"; - #TODO: sort by precedence #TODO: double check should be unneccessary, refactor! if (hasAttr "rules" ts."${tn}"."${cn}") then if (ts."${tn}"."${cn}".rules == null) then @@ -144,7 +145,7 @@ let "\nCOMMIT"; in concatStringsSep "\n" ([] - ++ map buildTable (attrNames ts) + ++ map buildTable (attrNames sortedTable) ); #===== -- cgit v1.2.3