Handle empty successful snapshot output in high-level client
This commit is contained in:
@@ -77,10 +77,21 @@ public sealed class NftablesClient : INftablesClient
|
|||||||
NftApplyRequest request = NftApplyRequest.FromText(_options.SnapshotCommandText, dryRun: false);
|
NftApplyRequest request = NftApplyRequest.FromText(_options.SnapshotCommandText, dryRun: false);
|
||||||
CommandExecutionResult result = Execute(request, forceDryRun: null, ct);
|
CommandExecutionResult result = Execute(request, forceDryRun: null, ct);
|
||||||
string snapshotText = result.Output ?? string.Empty;
|
string snapshotText = result.Output ?? string.Empty;
|
||||||
|
string errorText = result.Error ?? string.Empty;
|
||||||
|
|
||||||
if (string.IsNullOrWhiteSpace(snapshotText))
|
if (string.IsNullOrWhiteSpace(snapshotText))
|
||||||
{
|
{
|
||||||
throw new NftException("Snapshot returned an empty ruleset output.", nativeErrorOutput: result.Error);
|
if (ContainsAny(errorText, "Operation not permitted", "Permission denied", "CAP_NET_ADMIN"))
|
||||||
|
{
|
||||||
|
throw new NftPermissionException("Snapshot requires elevated privileges.", 0, result.Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!string.IsNullOrWhiteSpace(errorText))
|
||||||
|
{
|
||||||
|
throw new NftException("Snapshot returned an empty ruleset output.", nativeErrorOutput: result.Error);
|
||||||
|
}
|
||||||
|
|
||||||
|
snapshotText = "flush ruleset";
|
||||||
}
|
}
|
||||||
|
|
||||||
return new NftSnapshot(snapshotText, System.DateTimeOffset.UtcNow);
|
return new NftSnapshot(snapshotText, System.DateTimeOffset.UtcNow);
|
||||||
@@ -175,5 +186,23 @@ public sealed class NftablesClient : INftablesClient
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private static bool ContainsAny(string value, params string[] candidates)
|
||||||
|
{
|
||||||
|
if (string.IsNullOrWhiteSpace(value))
|
||||||
|
{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
foreach (string candidate in candidates)
|
||||||
|
{
|
||||||
|
if (value.Contains(candidate, System.StringComparison.OrdinalIgnoreCase))
|
||||||
|
{
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
private sealed record CommandExecutionResult(string? Output, string? Error);
|
private sealed record CommandExecutionResult(string? Output, string? Error);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user