Unverified Commit 7e55d522 authored by Maciej Krüger's avatar Maciej Krüger Committed by GitHub
Browse files

nixos/nftables: replace script with file (#494143)

parents 0a2609f3 dc49e8c9
Loading
Loading
Loading
Loading
+2 −3
Original line number Diff line number Diff line
@@ -298,7 +298,6 @@ in
        let
          enabledTables = lib.filterAttrs (_: table: table.enable) cfg.tables;
          deletionsScript = pkgs.writeScript "nftables-deletions" ''
            #! ${pkgs.nftables}/bin/nft -f
            ${
              if cfg.flushRuleset then
                "flush ruleset"
@@ -313,9 +312,9 @@ in
            ${cfg.extraDeletions}
          '';
          deletionsScriptVar = "/var/lib/nftables/deletions.nft";
          makeDeletions = "${pkgs.nftables}/bin/nft -f ${deletionsScriptVar}";
          ensureDeletions = pkgs.writeShellScript "nftables-ensure-deletions" ''
            touch ${deletionsScriptVar}
            chmod +x ${deletionsScriptVar}
          '';
          saveDeletionsScript = pkgs.writeShellScript "nftables-save-deletions" ''
            cp ${deletionsScript} ${deletionsScriptVar}
@@ -380,7 +379,7 @@ in
            saveDeletionsScript
          ];
          ExecStop = [
            deletionsScriptVar
            makeDeletions
            cleanupDeletionsScript
          ];
          StateDirectory = "nftables";