X-Git-Url: http://git.archive.openwrt.org/?p=project%2Ffirewall3.git;a=blobdiff_plain;f=utils.c;h=dbc713cd36e8ff675813b6d0a5f0f7117bd293c4;hp=c3dbb3d93fc61bce6b401763d0aa76ddde9903fc;hb=eb2a20924afd979feb485298111ced679de42aa0;hpb=5b051a66fad3c208380d69b4b13d09929fcfe101 diff --git a/utils.c b/utils.c index c3dbb3d..dbc713c 100644 --- a/utils.c +++ b/utils.c @@ -19,10 +19,17 @@ #include "utils.h" #include "options.h" +#include "zones.h" +#include "ipsets.h" + + static int lock_fd = -1; static pid_t pipe_pid = -1; static FILE *pipe_fd = NULL; +bool fw3_pr_debug = false; + + static void warn_elem_section_name(struct uci_section *s, bool find_name) { @@ -237,6 +244,7 @@ __fw3_command_pipe(bool silent, const char *command, ...) signal(SIGPIPE, SIG_IGN); pipe_pid = pid; close(pfds[0]); + fcntl(pfds[1], F_SETFD, fcntl(pfds[1], F_GETFD) | FD_CLOEXEC); } pipe_fd = fdopen(pfds[1], "w"); @@ -246,10 +254,18 @@ __fw3_command_pipe(bool silent, const char *command, ...) void fw3_pr(const char *fmt, ...) { - va_list args; - va_start(args, fmt); - vfprintf(pipe_fd, fmt, args); - va_end(args); + va_list args; + + if (fw3_pr_debug && pipe_fd != stdout) + { + va_start(args, fmt); + vfprintf(stderr, fmt, args); + va_end(args); + } + + va_start(args, fmt); + vfprintf(pipe_fd, fmt, args); + va_end(args); } void @@ -332,66 +348,118 @@ fw3_unlock(void) } -struct list_head * -fw3_read_statefile(void) +bool +fw3_read_statefile(void *state) { FILE *sf; - int n; + int type; char line[128]; - const char *p; + const char *p, *name; - struct list_head *state; - struct fw3_statefile_entry *entry; + uint32_t flags[2]; + + struct fw3_state *s = state; + struct fw3_zone *zone; + struct fw3_ipset *ipset; + struct fw3_device *net, *dev; sf = fopen(FW3_STATEFILE, "r"); if (!sf) - return NULL; - - state = malloc(sizeof(*state)); - - if (!state) - return NULL; - - INIT_LIST_HEAD(state); + return false; while (fgets(line, sizeof(line), sf)) { - entry = malloc(sizeof(*entry)); + p = strtok(line, " \t\n"); - if (!entry) + if (!p) continue; - memset(entry, 0, sizeof(*entry)); + type = strtoul(p, NULL, 16); + name = strtok(NULL, " \t\n"); - p = strtok(line, " \t\n"); - - if (!p) + if (!name) continue; - entry->type = strtoul(p, NULL, 10); + if (!(p = strtok(NULL, " \t\n"))) + continue; - p = strtok(NULL, " \t\n"); + flags[0] = strtoul(p, NULL, 16); - if (!p) + if (!(p = strtok(NULL, " \t\n"))) continue; - entry->name = strdup(p); + flags[1] = strtoul(p, NULL, 16); - for (n = 0, p = strtok(NULL, " \t\n"); - n < ARRAY_SIZE(entry->flags) && p != NULL; - n++, p = strtok(NULL, " \t\n")) + switch (type) { - entry->flags[n] = strtoul(p, NULL, 10); - } + case FW3_TYPE_DEFAULTS: + s->defaults.flags[0] = flags[0]; + s->defaults.flags[1] = flags[1]; + break; + + case FW3_TYPE_ZONE: + if (!(zone = fw3_lookup_zone(state, name, false))) + { + zone = fw3_alloc_zone(); + + if (!zone) + continue; + + zone->name = strdup(name); + list_add_tail(&zone->list, &s->zones); + } + + zone->flags[0] = flags[0]; + zone->flags[1] = flags[1]; + list_add_tail(&zone->running_list, &s->running_zones); + break; + + case FW3_TYPE_IPSET: + if (!(ipset = fw3_lookup_ipset(state, name, false))) + { + ipset = fw3_alloc_ipset(); + + if (!ipset) + continue; + + ipset->name = strdup(name); + list_add_tail(&ipset->list, &s->ipsets); + } + + ipset->flags[0] = flags[0]; + ipset->flags[1] = flags[1]; + list_add_tail(&ipset->running_list, &s->running_ipsets); + break; + + case FW3_TYPE_NETWORK: + if (!(zone = fw3_lookup_zone(state, name, false))) + continue; + + if (!(p = strtok(NULL, " \t\n")) || !(name = strtok(NULL, " \t\n"))) + continue; - list_add_tail(&entry->list, state); + if (!(net = malloc(sizeof(*net)))) + continue; + + memset(net, 0, sizeof(*net)); + snprintf(net->name, sizeof(net->name), "%s", p); + list_add_tail(&net->list, &zone->running_networks); + + if (!(dev = malloc(sizeof(*dev)))) + continue; + + memset(dev, 0, sizeof(*dev)); + dev->network = net; + snprintf(dev->name, sizeof(dev->name), "%s", name); + list_add_tail(&dev->list, &zone->running_devices); + } } fclose(sf); - return state; + return true; } void @@ -399,13 +467,12 @@ fw3_write_statefile(void *state) { FILE *sf; struct fw3_state *s = state; - struct fw3_defaults *d = &s->defaults; + struct fw3_defaults *defs = &s->defaults; struct fw3_zone *z; struct fw3_ipset *i; + struct fw3_device *d; - int mask = (1 << FW3_DEFAULT_IPV4_LOADED) | (1 << FW3_DEFAULT_IPV6_LOADED); - - if (!(d->has_flag & mask)) + if (fw3_no_table(defs->flags[0]) && fw3_no_table(defs->flags[1])) { if (unlink(FW3_STATEFILE)) warn("Unable to remove state %s: %s", @@ -422,39 +489,152 @@ fw3_write_statefile(void *state) return; } - fprintf(sf, "%u - %u\n", FW3_TYPE_DEFAULTS, d->has_flag); + fprintf(sf, "%x - %x %x\n", + FW3_TYPE_DEFAULTS, defs->flags[0], defs->flags[1]); + + list_for_each_entry(z, &s->running_zones, running_list) + { + if (fw3_no_table(z->flags[0]) && fw3_no_table(z->flags[1])) + continue; + + fprintf(sf, "%x %s %x %x\n", + FW3_TYPE_ZONE, z->name, z->flags[0], z->flags[1]); + + list_for_each_entry(d, &z->devices, list) + { + if (!d->network) + continue; + + fprintf(sf, "%x %s 0 0 %s %s\n", + FW3_TYPE_NETWORK, z->name, d->network->name, d->name); + } + } + + list_for_each_entry(i, &s->running_ipsets, running_list) + { + if (!fw3_no_family(i->flags[0]) || !fw3_no_family(i->flags[1])) + { + fprintf(sf, "%x %s %x %x\n", + FW3_TYPE_IPSET, i->name, i->flags[0], i->flags[1]); + } + } + + fclose(sf); +} + + +struct object_list_heads +{ + struct list_head list; + struct list_head running_list; +}; + +void +fw3_set_running(void *object, struct list_head *dest) +{ + struct object_list_heads *o = object; + + if (dest && !o->running_list.next) + list_add_tail(&o->running_list, dest); + else if (!dest && o->running_list.next) + list_del(&o->running_list); +} + +void +fw3_free_object(void *obj, const void *opts) +{ + const struct fw3_option *ol; + struct list_head *list, *cur, *tmp; - list_for_each_entry(z, &s->zones, list) + for (ol = opts; ol->name; ol++) { - fprintf(sf, "%u %s %u %u\n", FW3_TYPE_ZONE, - z->name, z->has_src_target, z->has_dest_target); + if (!ol->elem_size) + continue; + + list = (struct list_head *)((char *)obj + ol->offset); + list_for_each_safe(cur, tmp, list) + { + list_del(cur); + free(cur); + } } - list_for_each_entry(i, &s->ipsets, list) + free(obj); +} + + +bool +fw3_pr_rulespec(int table, int family, uint32_t *flags, uint32_t mask, + const struct fw3_rule_spec *r, const char *fmt, ...) +{ + char buf[256]; + bool rv = false; + + va_list ap; + uint32_t f = flags ? flags[family == FW3_FAMILY_V6] : 0; + + if (mask) + f &= mask; + + for (; r->format; r++) { - if (i->external && *i->external) + if (!fw3_is_family(r, family)) continue; - fprintf(sf, "%u %s\n", FW3_TYPE_IPSET, i->name); + if (r->table != table) + continue; + + if ((r->flag != 0) && !hasbit(f, r->flag)) + continue; + + va_start(ap, fmt); + vsnprintf(buf, sizeof(buf), r->format, ap); + va_end(ap); + + fw3_pr(fmt, buf); + + rv = true; } - fclose(sf); + return rv; } -void -fw3_free_statefile(struct list_head *statefile) + +bool +fw3_hotplug(bool add, void *zone, void *device) { - struct fw3_statefile_entry *e, *tmp; + struct fw3_zone *z = zone; + struct fw3_device *d = device; - if (!statefile) - return; + if (!d->network) + return false; - list_for_each_entry_safe(e, tmp, statefile, list) + switch (fork()) { - list_del(&e->list); - free(e->name); - free(e); + case -1: + warn("Unable to fork(): %s\n", strerror(errno)); + return false; + + case 0: + break; + + default: + return true; } - free(statefile); + close(0); + close(1); + close(2); + chdir("/"); + + clearenv(); + setenv("ACTION", add ? "add" : "remove", 1); + setenv("ZONE", z->name, 1); + setenv("INTERFACE", d->network->name, 1); + setenv("DEVICE", d->name, 1); + + execl(FW3_HOTPLUG, FW3_HOTPLUG, "firewall", NULL); + + /* unreached */ + return false; }