ssongliu
78402e1b7d
refactor(firewall): consolidate utilities and flatten packages ( #13833 )
2026-09-16 16:48:48 +08:00
ssongliu
782bc1e67c
fix(firewall): manage SSH access and queue stop operations ( #13831 )
...
* fix(firewall): manage SSH access and queue stop operations
* fix(firewall): reconcile whitelist rules and sync differences
2026-09-16 16:45:33 +08:00
ssongliu
fe742b9f41
fix(firewall): improve whitelist management and rule lifecycle ( #13826 )
2026-09-15 23:55:01 +08:00
ssongliu
eb0f5264d7
refactor: simplify firewall rule management and whitelist updates ( #13758 )
2026-09-09 15:33:24 +08:00
ssongliu
da5682a600
fix(firewall): harden port switching and rule synchronization ( #13731 )
2026-09-07 18:05:31 +08:00
ssongliu
eab0bb4a94
fix: repair firewall forwarding migration ( #13689 )
2026-09-02 14:48:47 +08:00
ssongliu
fb377d2e99
fix(firewall): recover rules after upgrade ( #13680 )
2026-09-01 14:53:01 +08:00
ssongliu
7915230121
refactor: rebuild firewall management ( #13628 )
...
* refactor(firewall): rebuild rule management foundation
* refactor(firewall): streamline rule checks and inventory
* feat(firewall): improve native rule inventory
* refactor(firewall): refine rule management
* feat: add Docker port guard
* feat(firewall): support native nftables
* feat(firewall): add configurable firewall selection
* feat(firewall): support nftables docker port guard
* refactor(firewall): complete v2 rule management and migration
* refactor(firewall): align state and API contracts
* refactor(firewall): unify rule management operations
* feat: refine firewall v2 rules and forwarding
* fix(firewall): harden dual-stack rule management
* refactor(firewall): consolidate rule validation and persistence
2026-08-24 12:51:34 +08:00
HynoR
f35b0deb29
refactor(firewall): extract port forwarding subsystem ( #13347 )
...
Port forwarding no longer shares the filter client. FilterClient keeps only
filter capabilities, and forwarding gets its own adapter, service and boot
replay:
- utils/firewall/forwarding holds the provider adapters. firewalld uses native
forward-port, ufw and iptables share the NAT implementation moved out of
client/iptables/forward.go.
- service/forwarding.go owns base info, search, operate, enable and replay.
The API keeps its routes and dispatches on name/type/operate.
- init/firewall replays forwarding through that service instead of loading NAT
rule files inline.
Also adds 1PANEL_FORWARD to the IptablesOp name enum: the frontend already
sends {"name":"1PANEL_FORWARD","operate":"init-forward"} and the validator
rejected it with 400 before reaching the service. Besides that, the only
observable difference is that a forward-tab search no longer triggers the
port/address record cleanup goroutine on the side.
2026-07-30 14:07:41 +08:00
ssongliu
d55982bde0
refactor: update agent and core utilities ( #12621 )
2026-05-21 12:35:09 +08:00
ssongliu
d8a08a6c0c
fix: Fix iptables rule display abnormality issue ( #11555 )
2026-01-05 14:48:49 +08:00
ssongliu
50947f4ddc
feat: ICMP ping disable compatibility with Debian 13 ( #11514 )
...
Refs #11472
2025-12-29 09:35:36 +00:00
ssongliu
bb9d9042f0
chore: Modify iptables initialization logic ( #11145 )
2025-12-01 22:20:17 +08:00
ssongliu
94f7d78cc9
fix: Fix iptables state persistence issue ( #11137 )
...
Refs #11126
2025-12-01 06:33:38 +00:00
ssongliu
c3cc26a136
fix: Fix the issue of abnormal iptables persistence loading ( #11066 )
2025-11-25 14:21:24 +08:00
ssongliu
496c0b50b4
fix: Fix the issue of abnormal iptables rule persistence ( #11056 )
...
Refs #11027
2025-11-24 14:33:15 +00:00
ssongliu
102f7c316d
fix: display iptables default allowed ports ( #10922 )
2025-11-11 14:22:42 +00:00
KOMATA
02d22ba63f
feat: refactor regex usage across multiple files and centralize patterns in a new utility ( #10896 )
2025-11-11 16:14:09 +08:00
ssongliu
6db79f4b7b
feat: support iptables firewall control ( #10903 )
2025-11-10 21:17:53 +08:00