From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 030A61FF0E1 for ; Thu, 27 Aug 2026 15:18:09 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 5EB13214C0; Thu, 27 Aug 2026 15:18:08 +0200 (CEST) From: Hannes Laimer To: pve-devel@lists.proxmox.com Subject: [PATCH proxmox-firewall] nftables: add support for mark-keyed verdict maps Date: Thu, 27 Aug 2026 15:17:56 +0200 Message-ID: <20260827131756.1413841-1-h.laimer@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1787836669256 X-SPAM-LEVEL: Spam detection results: 1 AWL 0.904 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_BLACK 3 Contains an URL listed in the URIBL blacklist [types.rs] URIBL_CSS_A 0.1 Contains URL's A record listed in the Spamhaus CSS blocklist [23.95.107.30] Message-ID-Hash: TTQMXRKRMQX53QCAXZ2B27QZI275D5LS X-Message-ID-Hash: TTQMXRKRMQX53QCAXZ2B27QZI275D5LS X-MailFrom: h.laimer@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: nftables sets and maps can be keyed by the packet mark, but the mark element type has not yet been exposed by proxmox-nftables. A vmap statement could so far only be parsed, not constructed, so the only ones in use come from the static ruleset skeleton. Add both to the lib. Signed-off-by: Hannes Laimer --- proxmox-nftables/src/statement.rs | 9 +++++++++ proxmox-nftables/src/types.rs | 1 + 2 files changed, 10 insertions(+) diff --git a/proxmox-nftables/src/statement.rs b/proxmox-nftables/src/statement.rs index 44a4c48..0416623 100644 --- a/proxmox-nftables/src/statement.rs +++ b/proxmox-nftables/src/statement.rs @@ -312,6 +312,15 @@ pub struct Vmap { data: Expression, } +impl Vmap { + pub fn new(key: impl Into, data: impl Into) -> Self { + Self { + key: key.into(), + data: data.into(), + } + } +} + #[derive(Clone, Debug, Deserialize, Serialize)] pub struct Match { op: Operator, diff --git a/proxmox-nftables/src/types.rs b/proxmox-nftables/src/types.rs index 86ccaf8..f79229b 100644 --- a/proxmox-nftables/src/types.rs +++ b/proxmox-nftables/src/types.rs @@ -56,6 +56,7 @@ pub enum ElementType { Ifname, Ipv4Addr, Ipv6Addr, + Mark, } proxmox_serde::forward_display_to_serialize!(ElementType); -- 2.47.3