Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

provision: reload the firewall only once #1846

Open
wants to merge 6 commits into
base: dev
Choose a base branch
from
Open
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
29 changes: 20 additions & 9 deletions src/utils/resources.py
Original file line number Diff line number Diff line change
Expand Up @@ -1291,7 +1291,14 @@ def _port_is_used(self, port):
return used_by_process or used_by_app or used_by_self_provisioning

def provision_or_update(self, context: Dict = {}):
from yunohost.firewall import firewall_allow, firewall_disallow
from yunohost.firewall import (
firewall_allow,
firewall_disallow,
firewall_list,
firewall_reload,
)

previous_ports = firewall_list(raw=True)

for name, infos in self.ports.items():
setting_name = f"port_{name}" if name != "main" else "port"
Expand Down Expand Up @@ -1322,23 +1329,27 @@ def provision_or_update(self, context: Dict = {}):
self.set_setting(setting_name, port_value)

if infos["exposed"]:
firewall_allow(infos["exposed"], port_value, reload_only_if_change=True)
firewall_allow(infos["exposed"], port_value, no_reload=True)
else:
firewall_disallow(
infos["exposed"], port_value, reload_only_if_change=True
)
firewall_disallow(infos["exposed"], port_value, no_reload=True)

if firewall_list(raw=True) != previous_ports:
firewall_reload()

def deprovision(self, context: Dict = {}):
from yunohost.firewall import firewall_disallow
from yunohost.firewall import firewall_disallow, firewall_list, firewall_reload

previous_ports = firewall_list(raw=True)

for name, infos in self.ports.items():
setting_name = f"port_{name}" if name != "main" else "port"
value = self.get_setting(setting_name)
self.delete_setting(setting_name)
if value and str(value).strip():
firewall_disallow(
infos["exposed"], int(value), reload_only_if_change=True
)
firewall_disallow(infos["exposed"], int(value), no_reload=True)

if firewall_list(raw=True) != previous_ports:
firewall_reload()


class DatabaseAppResource(AppResource):
Expand Down