Flush using AF_UNSPEC and netfilter package

This commit is contained in:
Quentin McGaw
2026-02-25 22:03:01 +00:00
parent 2bb4deccd5
commit 6467f3b4ad
+15 -18
View File
@@ -5,6 +5,7 @@ import (
"github.com/mdlayher/netlink" "github.com/mdlayher/netlink"
"github.com/ti-mo/netfilter" "github.com/ti-mo/netfilter"
"golang.org/x/sys/unix"
) )
func (n *NetLink) FlushConntrack() error { func (n *NetLink) FlushConntrack() error {
@@ -14,25 +15,21 @@ func (n *NetLink) FlushConntrack() error {
} }
defer conn.Close() defer conn.Close()
families := [...]netfilter.ProtoFamily{netfilter.ProtoIPv4, netfilter.ProtoIPv6} const ipCtnlMsgCtDelete = netfilter.MessageType(2)
for _, family := range families { header := netfilter.Header{
const IPCtnlMsgCtDelete = 2 SubsystemID: netfilter.NFSubsysCTNetlink,
request, err := netfilter.MarshalNetlink( MessageType: ipCtnlMsgCtDelete,
netfilter.Header{ Family: unix.AF_UNSPEC,
SubsystemID: netfilter.NFSubsysCTNetlink, Flags: netlink.Request | netlink.Acknowledge,
MessageType: netfilter.MessageType(IPCtnlMsgCtDelete), }
Family: family, request, err := netfilter.MarshalNetlink(header, nil)
Flags: netlink.Request | netlink.Acknowledge, if err != nil {
}, return fmt.Errorf("encoding netlink request: %w", err)
nil) }
if err != nil {
return fmt.Errorf("encoding netlink request: %w", err)
}
_, err = conn.Query(request) _, err = conn.Query(request)
if err != nil { if err != nil {
return fmt.Errorf("querying netlink request: %w", err) return fmt.Errorf("querying netlink request: %w", err)
}
} }
return nil return nil
} }