> + if ( $param->{full}){ > + my $hostfw_conf = PVE::Firewall::load_hostfw_conf(); > + PVE::Firewall::apply_ruleset($ruleset, $hostfw_conf, > $ipset_ruleset, 1); > + } Oh, I think compile should not touch actual firewall settings, so simply calling apply_ruleset() is not good.