Warning
Breaking Configuration Change in v1.5.0
- Configuration file has moved from
/etc/nft-blackhole.confto/etc/nft-blackhole/config.yaml. WHITELISTandBLACKLISTsections now use a new structure:static(direct IP/CIDR),file(local file paths),url(remote URLs).- Backward compatibility for the old
v4/v6dictionary format is maintained temporarily (deprecated — will be removed in a future release). - Users upgrading from v1.4.1 or earlier must manually migrate and adapt their configuration to the new structure. See
config.yamlfor a complete reference.
What's Changed
Added
- Configurable nftables chain priority (
PRIORITYoption) in configuration and template (#18) - Support for
static,file, andurlsource sections inWHITELISTandBLACKLIST(#17) - Automatic detection and splitting of IPv4 and IPv6 addresses across all sources without manual IP version separation
- Support for local file lists in whitelist and blacklist (
filesection) - Support for single IP addresses and subnets directly in blacklist (
staticsection) - Support for remote URLs in whitelist (
urlsection)
Changed
- Relocated configuration file from
/etc/nft-blackhole.confto/etc/nft-blackhole/config.yaml(nft-blackhole.confrenamed toconfig.yaml) - Automatic fallback to legacy
/etc/nft-blackhole.confwith migration warning if the old configuration file is present - Symmetrical configuration format for
WHITELISTandBLACKLISTwith temporary fallback support for legacy formats (deprecated) - Consolidated nftables set operations into a unified
apply_nft_sets()function - Unified country IP fetching into
get_country_ips()with parallel download of all active IP versions - Immediate
stopaction execution without requiring valid configuration file - Optimized comment parsing and native set deduplication
Full Changelog: v1.4.1...v1.5.0