wf: loopback condition should use MatchTypeFlagsAllSet.

Signed-off-by: Maisem Ali <maisem@tailscale.com>
This commit is contained in:
Maisem Ali 2021-06-15 23:35:36 -07:00 committed by Maisem Ali
parent 48c25fa36f
commit 2919b3e3e6

View File

@ -152,7 +152,7 @@ func (f *Firewall) enable() error {
return fmt.Errorf("permitDNS failed: %w", err) return fmt.Errorf("permitDNS failed: %w", err)
} }
if err := f.permitLoopback(weightKnownTraffic); err != nil { if err := f.permitLoopback(weightTailscaleTraffic); err != nil {
return fmt.Errorf("permitLoopback failed: %w", err) return fmt.Errorf("permitLoopback failed: %w", err)
} }
@ -457,7 +457,7 @@ func (f *Firewall) permitLoopback(w weight) error {
condition := []*wf.Match{ condition := []*wf.Match{
{ {
Field: wf.FieldFlags, Field: wf.FieldFlags,
Op: wf.MatchTypeEqual, Op: wf.MatchTypeFlagsAllSet,
Value: wf.ConditionFlagIsLoopback, Value: wf.ConditionFlagIsLoopback,
}, },
} }