From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 5A33D1FF0AB for ; Wed, 23 Sep 2026 12:01:17 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 2A14D21579; Wed, 23 Sep 2026 12:01:15 +0200 (CEST) Message-ID: Date: Wed, 23 Sep 2026 12:01:11 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH proxmox-firewall] nftables: add support for mark-keyed verdict maps To: pve-devel@lists.proxmox.com References: <20260827131756.1413841-1-h.laimer@proxmox.com> Content-Language: en-US From: Stefan Hanreich In-Reply-To: <20260827131756.1413841-1-h.laimer@proxmox.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-SPAM-LEVEL: Spam detection results: 1 AWL 0.634 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_BLACK 3 Contains an URL listed in the URIBL blacklist [types.rs] URIBL_CSS_A 0.1 Contains URL's A record listed in the Spamhaus CSS blocklist [23.95.107.30] Message-ID-Hash: I6BSYILAADAYBADICGP3P62734S26JG2 X-Message-ID-Hash: I6BSYILAADAYBADICGP3P62734S26JG2 X-MailFrom: s.hanreich@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: lgtm Reviewed-by: Stefan Hanreich On 8/27/26 3:18 PM, Hannes Laimer wrote: > nftables sets and maps can be keyed by the packet mark, but the mark > element type has not yet been exposed by proxmox-nftables. A vmap > statement could so far only be parsed, not constructed, so the only ones > in use come from the static ruleset skeleton. Add both to the lib. > > Signed-off-by: Hannes Laimer > --- > proxmox-nftables/src/statement.rs | 9 +++++++++ > proxmox-nftables/src/types.rs | 1 + > 2 files changed, 10 insertions(+) > > diff --git a/proxmox-nftables/src/statement.rs b/proxmox-nftables/src/statement.rs > index 44a4c48..0416623 100644 > --- a/proxmox-nftables/src/statement.rs > +++ b/proxmox-nftables/src/statement.rs > @@ -312,6 +312,15 @@ pub struct Vmap { > data: Expression, > } > > +impl Vmap { > + pub fn new(key: impl Into, data: impl Into) -> Self { > + Self { > + key: key.into(), > + data: data.into(), > + } > + } > +} > + > #[derive(Clone, Debug, Deserialize, Serialize)] > pub struct Match { > op: Operator, > diff --git a/proxmox-nftables/src/types.rs b/proxmox-nftables/src/types.rs > index 86ccaf8..f79229b 100644 > --- a/proxmox-nftables/src/types.rs > +++ b/proxmox-nftables/src/types.rs > @@ -56,6 +56,7 @@ pub enum ElementType { > Ifname, > Ipv4Addr, > Ipv6Addr, > + Mark, > } > proxmox_serde::forward_display_to_serialize!(ElementType); >