698a906
commit 7e7be5658c2b1a8aa130480ad8e1a7314c83bba9
698a906
Author: Thomas Woerner <twoerner@redhat.com>
698a906
Date:   Wed Feb 15 11:11:40 2017 +0100
698a906
698a906
    firewall.core.fw_ipset: get_ipset may not ckeck if set is applied by default
698a906
    
698a906
    This breaks the ipset overloading from /etc/firewalld/ipsets.
698a906
    Fixes: #206
698a906
698a906
diff --git a/src/firewall/core/fw_ipset.py b/src/firewall/core/fw_ipset.py
698a906
index bbbc8eb..952d122 100644
698a906
--- a/src/firewall/core/fw_ipset.py
698a906
+++ b/src/firewall/core/fw_ipset.py
698a906
@@ -55,10 +55,11 @@ class FirewallIPSet(object):
698a906
     def has_ipsets(self):
698a906
         return len(self._ipsets) > 0
698a906
 
698a906
-    def get_ipset(self, name):
698a906
+    def get_ipset(self, name, applied=False):
698a906
         self.check_ipset(name)
698a906
         obj = self._ipsets[name]
698a906
-        self.check_applied_obj(obj)
698a906
+        if applied:
698a906
+            self.check_applied_obj(obj)
698a906
         return obj
698a906
 
698a906
     def _error2warning(self, f, name, *args):
698a906
@@ -141,11 +142,11 @@ class FirewallIPSet(object):
698a906
     # TYPE
698a906
 
698a906
     def get_type(self, name):
698a906
-        return self.get_ipset(name).type
698a906
+        return self.get_ipset(name, applied=True).type
698a906
 
698a906
     # DIMENSION
698a906
     def get_dimension(self, name):
698a906
-        return len(self.get_ipset(name).type.split(","))
698a906
+        return len(self.get_ipset(name, applied=True).type.split(","))
698a906
 
698a906
     # APPLIED
698a906
 
698a906
@@ -164,7 +165,7 @@ class FirewallIPSet(object):
698a906
     # OPTIONS
698a906
 
698a906
     def get_family(self, name):
698a906
-        obj = self.get_ipset(name)
698a906
+        obj = self.get_ipset(name, applied=True)
698a906
         if "family" in obj.options:
698a906
             if obj.options["family"] == "inet6":
698a906
                 return "ipv6"
698a906
@@ -179,7 +180,7 @@ class FirewallIPSet(object):
698a906
         pass
698a906
 
698a906
     def add_entry(self, name, entry):
698a906
-        obj = self.get_ipset(name)
698a906
+        obj = self.get_ipset(name, applied=True)
698a906
         if "timeout" in obj.options and obj.options["timeout"] != "0":
698a906
             # no entries visible for ipsets with timeout
698a906
             raise FirewallError(errors.IPSET_WITH_TIMEOUT, name)
698a906
@@ -201,7 +202,7 @@ class FirewallIPSet(object):
698a906
                 obj.entries.append(entry)
698a906
 
698a906
     def remove_entry(self, name, entry):
698a906
-        obj = self.get_ipset(name)
698a906
+        obj = self.get_ipset(name, applied=True)
698a906
         if "timeout" in obj.options and obj.options["timeout"] != "0":
698a906
             # no entries visible for ipsets with timeout
698a906
             raise FirewallError(errors.IPSET_WITH_TIMEOUT, name)
698a906
@@ -222,7 +223,7 @@ class FirewallIPSet(object):
698a906
                 obj.entries.remove(entry)
698a906
 
698a906
     def query_entry(self, name, entry):
698a906
-        obj = self.get_ipset(name)
698a906
+        obj = self.get_ipset(name, applied=True)
698a906
         if "timeout" in obj.options and obj.options["timeout"] != "0":
698a906
             # no entries visible for ipsets with timeout
698a906
             raise FirewallError(errors.IPSET_WITH_TIMEOUT, name)
698a906
@@ -230,11 +231,11 @@ class FirewallIPSet(object):
698a906
         return entry in obj.entries
698a906
 
698a906
     def get_entries(self, name):
698a906
-        obj = self.get_ipset(name)
698a906
+        obj = self.get_ipset(name, applied=True)
698a906
         return obj.entries
698a906
 
698a906
     def set_entries(self, name, entries):
698a906
-        obj = self.get_ipset(name)
698a906
+        obj = self.get_ipset(name, applied=True)
698a906
         if "timeout" in obj.options and obj.options["timeout"] != "0":
698a906
             # no entries visible for ipsets with timeout
698a906
             raise FirewallError(errors.IPSET_WITH_TIMEOUT, name)