diff --git a/.github/workflows/review.yml b/.github/workflows/review.yml index f9f17c4..45f67a5 100644 --- a/.github/workflows/review.yml +++ b/.github/workflows/review.yml @@ -11,50 +11,4 @@ permissions: jobs: review: name: review - runs-on: ubuntu-latest - steps: - - - name: Checkout code - uses: actions/checkout@v7 - - parallel: - - - name: Hadolint - uses: reviewdog/action-hadolint@v1 - with: - level: warning - fail_level: error - reporter: github-pr-review - hadolint_ignore: DL3008 DL3018 DL3020 DL3029 DL3059 - github_token: ${{ secrets.GITHUB_TOKEN }} - - - name: YamlLint - uses: reviewdog/action-yamllint@v1 - with: - level: warning - reporter: github-pr-review - github_token: ${{ secrets.GITHUB_TOKEN }} - - - name: ActionLint - uses: reviewdog/action-actionlint@v1 - with: - level: warning - reporter: github-pr-review - github_token: ${{ secrets.GITHUB_TOKEN }} - - - name: Shellformat - uses: reviewdog/action-shfmt@v1 - if: false - with: - level: warning - fail_on_error: "true" - shfmt_flags: "-i 2 -ci -bn" - github_token: ${{ secrets.GITHUB_TOKEN }} - - - name: Shellcheck - uses: reviewdog/action-shellcheck@v1 - with: - level: warning - fail_level: error - reporter: github-pr-review - shellcheck_flags: -x -e SC1091 -e SC2001 -e SC2002 -e SC2034 -e SC2064 -e SC2153 -e SC2317 -e SC2028 - github_token: ${{ secrets.GITHUB_TOKEN }} + uses: action-pack/.github/.github/workflows/review.yml@master diff --git a/src/network.sh b/src/network.sh index 48bc260..8e0f60c 100644 --- a/src/network.sh +++ b/src/network.sh @@ -11,7 +11,6 @@ set -Eeuo pipefail : "${BRIDGE:="vmbr0"}" : "${MASK:="255.255.255.0"}" - # Sanitize variables DEV=$(strip "$DEV") MTU=$(strip "$MTU") @@ -140,7 +139,6 @@ networkCIDR() { return 0 } - detectInterface() { if [ -n "$DEV" ]; then @@ -756,11 +754,31 @@ clearTables() { return 0 } +hasTaggedRules() { + + local save="$1" + local rules="" + local rule_tag="PROXMOX_NAT" + local own_rule="--comment[[:space:]]+\"?$rule_tag\"?([[:space:]]|\$)" + + # Return 2 when the backend cannot be inspected. + if ! rules=$("$save" 2>/dev/null); then + return 2 + fi + + if grep -Eq -- "$own_rule" <<< "$rules"; then + return 0 + fi + + return 1 +} + configureTables() { local subnet="$1" local preferred="" - local alternate="" rc=0 + local alternate="" + local alternate_save="" local preferred_clean="N" local alternate_dirty="N" @@ -777,6 +795,47 @@ configureTables() { return 1 ;; esac + # Inspect the alternate backend without changing the active alternative. + alternate_save=$(command -v "iptables-$alternate-save" 2>/dev/null || true) + + if [ -n "$alternate_save" ]; then + + if hasTaggedRules "$alternate_save"; then + + # Only switch backends when stale Proxmox rules were positively found. + if ! setTables "$alternate"; then + error "failed to select the $alternate IP tables backend for cleanup!" + return 1 + fi + + if ! clearTables; then + alternate_dirty="Y" + fi + + # Always restore the originally selected backend after cleanup. + if ! setTables "$preferred"; then + error "failed to restore the preferred $preferred IP tables backend!" + return 1 + fi + + if enabled "$alternate_dirty"; then + error "failed to clean up the existing $alternate IP tables configuration!" + return 1 + fi + + else + + local rc=$? + + # An unavailable alternate backend does not affect normal startup. + if (( rc == 2 )) && enabled "$DEBUG"; then + warn "failed to inspect the $alternate IP tables backend!" + fi + + fi + + fi + # Try the preferred backend first. if clearTables; then @@ -796,7 +855,7 @@ configureTables() { else - rc=$? + local rc=$? # The preferred backend was accessible, but its rules could not be removed. # Do not switch while partial or stale rules may still be active. @@ -834,7 +893,7 @@ configureTables() { else - rc=$? + local rc=$? # Only mark the alternate backend dirty when it was accessible but cleanup failed. if (( rc == 1 )); then