about summary refs log tree commit diff
path: root/nixos
diff options
context:
space:
mode:
authorMaciej Krüger <mkg20001@gmail.com>2023-03-27 20:10:18 +0200
committerMaciej Krüger <mkg20001@gmail.com>2023-08-28 00:40:22 +0200
commit6658b3fcf185f6b9eef7ab1923711c35023407b2 (patch)
tree7803d2771c1b7c6b3106ac64bc68537d1c37384e /nixos
parenta1dd69d7615feb8d3f6ddc63351849f279344395 (diff)
downloadnixlib-6658b3fcf185f6b9eef7ab1923711c35023407b2.tar
nixlib-6658b3fcf185f6b9eef7ab1923711c35023407b2.tar.gz
nixlib-6658b3fcf185f6b9eef7ab1923711c35023407b2.tar.bz2
nixlib-6658b3fcf185f6b9eef7ab1923711c35023407b2.tar.lz
nixlib-6658b3fcf185f6b9eef7ab1923711c35023407b2.tar.xz
nixlib-6658b3fcf185f6b9eef7ab1923711c35023407b2.tar.zst
nixlib-6658b3fcf185f6b9eef7ab1923711c35023407b2.zip
networking/nftables: make ruleset+rulesetFile non-exclusive
Diffstat (limited to 'nixos')
-rw-r--r--nixos/modules/services/networking/nftables.nix5
1 files changed, 3 insertions, 2 deletions
diff --git a/nixos/modules/services/networking/nftables.nix b/nixos/modules/services/networking/nftables.nix
index cf32876c2c5b..5397917d0cec 100644
--- a/nixos/modules/services/networking/nftables.nix
+++ b/nixos/modules/services/networking/nftables.nix
@@ -273,9 +273,10 @@ in
                 ${table.content}
               }
             '') enabledTables)}
-            ${if cfg.rulesetFile != null then ''
+            ${cfg.ruleset}
+            ${lib.optionalString (cfg.rulesetFile != null) ''
               include "${cfg.rulesetFile}"
-            '' else cfg.ruleset}
+            ''}
           '';
           checkPhase = lib.optionalString cfg.checkRuleset ''
             cp $out ruleset.conf