use Digest::SHA;
use PVE::INotify;
use PVE::Exception qw(raise raise_param_exc);
-use PVE::JSONSchema qw(get_standard_option);
+use PVE::JSONSchema qw(register_standard_option get_standard_option);
use PVE::Cluster;
use PVE::ProcFSTools;
-use PVE::Tools;
+use PVE::Tools qw($IPV4RE);
use File::Basename;
use File::Path;
use IO::File;
$have_pve_manager = 1;
};
+PVE::JSONSchema::register_format('IPv4orCIDR', \&pve_verify_ipv4_or_cidr);
+sub pve_verify_ipv4_or_cidr {
+ my ($cidr, $noerr) = @_;
+
+ if ($cidr =~ m!^(?:$IPV4RE)(/(\d+))?$!) {
+ return $cidr if Net::IP->new($cidr);
+ return undef if $noerr;
+ die Net::IP::Error() . "\n";
+ }
+ return undef if $noerr;
+ die "value does not look like a valid IP address or CIDR network\n";
+}
+
+PVE::JSONSchema::register_standard_option('ipset-name', {
+ description => "IP set name.",
+ type => 'string',
+ pattern => '[A-Za-z][A-Za-z0-9\-\_]+',
+ minLength => 2,
+ maxLength => 20,
+});
+
+my $security_group_pattern = '[A-Za-z][A-Za-z0-9\-\_]+';
+
+PVE::JSONSchema::register_standard_option('pve-security-group-name', {
+ description => "Security Group name.",
+ type => 'string',
+ pattern => $security_group_pattern,
+ minLength => 2,
+ maxLength => 20,
+});
+
my $feature_ipset_nomatch = 0;
eval {
my (undef, undef, $release) = POSIX::uname();
sub parse_address_list {
my ($str) = @_;
- return if $str !~ m/^(\+)(\S+)$/; # ipset ref
+ return if $str =~ m/^(\+)(\S+)$/; # ipset ref
my $count = 0;
my $iprange = 0;
my $services = PVE::Firewall::get_etc_services();
my $count = 0;
+ my $icmp_port = 0;
+
foreach my $item (split(/,/, $str)) {
$count++;
if ($item =~ m/^(\d+):(\d+)$/) {
my $port = $1;
die "invalid port '$port'\n" if $port > 65535;
} else {
- die "invalid port '$item'\n" if !$services->{byname}->{$item};
+ if ($icmp_type_names->{$item}) {
+ $icmp_port = 1;
+ } else {
+ die "invalid port '$item'\n" if !$services->{byname}->{$item};
+ }
}
}
+ die "ICPM ports not allowed in port range\n" if $icmp_port && $count > 1;
+
return $count;
}
minimum => 0,
optional => 1,
},
- digest => {
- type => 'string',
- optional => 1,
- maxLength => 27,
- minLength => 27,
- },
+ digest => get_standard_option('pve-config-digest'),
type => {
type => 'string',
optional => 1,
enum => ['in', 'out', 'group'],
},
action => {
+ description => "Rule action ('ACCEPT', 'DROP', 'REJECT') or security group name.",
type => 'string',
optional => 1,
- enum => ['ACCEPT', 'DROP', 'REJECT'],
+ pattern => $security_group_pattern,
+ maxLength => 20,
+ minLength => 2,
},
macro => {
type => 'string',
return $rule;
}
+my $apply_macro = sub {
+ my ($macro_name, $param, $verify) = @_;
+
+ my $macro_rules = $pve_fw_parsed_macros->{$macro_name};
+ die "unknown macro '$macro_name'\n" if !$macro_rules; # should not happen
+
+ my $rules = [];
+
+ foreach my $templ (@$macro_rules) {
+ my $rule = {};
+ my $param_used = {};
+ foreach my $k (keys %$templ) {
+ my $v = $templ->{$k};
+ if ($v eq 'PARAM') {
+ $v = $param->{$k};
+ $param_used->{$k} = 1;
+ } elsif ($v eq 'DEST') {
+ $v = $param->{dest};
+ $param_used->{dest} = 1;
+ } elsif ($v eq 'SOURCE') {
+ $v = $param->{source};
+ $param_used->{source} = 1;
+ }
+
+ if (!defined($v)) {
+ my $msg = "missing parameter '$k' in macro '$macro_name'";
+ raise_param_exc({ macro => $msg }) if $verify;
+ die "$msg\n";
+ }
+ $rule->{$k} = $v;
+ }
+ foreach my $k (keys %$param) {
+ next if $k eq 'macro';
+ next if !defined($param->{$k});
+ next if $param_used->{$k};
+ if (defined($rule->{$k})) {
+ if ($rule->{$k} ne $param->{$k}) {
+ my $msg = "parameter '$k' already define in macro (value = '$rule->{$k}')";
+ raise_param_exc({ $k => $msg }) if $verify;
+ die "$msg\n";
+ }
+ } else {
+ $rule->{$k} = $param->{$k};
+ }
+ }
+ push @$rules, $rule;
+ }
+
+ return $rules;
+};
+
sub verify_rule {
my ($rule, $allow_groups) = @_;
raise_param_exc({ type => "security groups not allowed"})
if !$allow_groups;
raise_param_exc({ action => "invalid characters in security group name"})
- if $rule->{action} !~ m/^[A-Za-z0-9_\-]+$/;
+ if $rule->{action} !~ m/^${security_group_pattern}$/;
} else {
raise_param_exc({ type => "unknown rule type '$type'"});
}
raise_param_exc({ dest => $@ }) if $@;
}
+ if ($rule->{macro}) {
+ &$apply_macro($rule->{macro}, $rule, 1);
+ }
+
return $rule;
}
return scalar(@cmd) ? join(' ', @cmd) : undef;
}
-my $apply_macro = sub {
- my ($macro_name, $param) = @_;
-
- my $macro_rules = $pve_fw_parsed_macros->{$macro_name};
- die "unknown macro '$macro_name'\n" if !$macro_rules; # should not happen
-
- my $rules = [];
-
- foreach my $templ (@$macro_rules) {
- my $rule = {};
- my $param_used = {};
- foreach my $k (keys %$templ) {
- my $v = $templ->{$k};
- if ($v eq 'PARAM') {
- $v = $param->{$k};
- $param_used->{$k} = 1;
- } elsif ($v eq 'DEST') {
- $v = $param->{dest};
- $param_used->{dest} = 1;
- } elsif ($v eq 'SOURCE') {
- $v = $param->{source};
- $param_used->{source} = 1;
- }
-
- die "missing parameter '$k' in macro '$macro_name'\n" if !defined($v);
- $rule->{$k} = $v;
- }
- foreach my $k (keys %$param) {
- next if $k eq 'macro';
- next if !defined($param->{$k});
- next if $param_used->{$k};
- if (defined($rule->{$k})) {
- die "parameter '$k' already define in macro (value = '$rule->{$k}')\n"
- if $rule->{$k} ne $param->{$k};
- } else {
- $rule->{$k} = $param->{$k};
- }
- }
- push @$rules, $rule;
- }
-
- return $rules;
-};
-
sub ruleset_generate_rule {
my ($ruleset, $chain, $rule, $actions, $goto, $cluster_conf) = @_;
die "wrong number of rule elements\n" if scalar(@data) != 3;
die "groups disabled\n" if !$allow_groups;
- die "invalid characters in group name\n" if $action !~ m/^[A-Za-z0-9_\-]+$/;
+ die "invalid characters in group name\n" if $action !~ m/^${security_group_pattern}$/;
} else {
die "unknown rule type '$type'\n";
}
push @{$res->{$section}}, $rule;
}
-$res->{digest} = $digest->b64digest;
+ $res->{digest} = $digest->b64digest;
return $res;
}
my $section;
my $group;
- my $res = { rules => [], options => {}, groups => {}, ipset => {} };
+ my $res = {
+ rules => [],
+ options => {},
+ groups => {},
+ group_comments => {},
+ ipset => {} ,
+ ipset_comments => {},
+ };
my $digest = Digest::SHA->new('sha1');
next;
}
- if ($line =~ m/^\[group\s+(\S+)\]\s*$/i) {
+ if ($line =~ m/^\[group\s+(\S+)\]\s*(?:#\s*(.*?)\s*)?$/i) {
$section = 'groups';
$group = lc($1);
+ my $comment = $2;
+ $res->{$section}->{$group} = [];
+ $res->{group_comments}->{$group} = $comment if $comment;
next;
}
next;
}
- if ($line =~ m/^\[ipset\s+(\S+)\]\s*$/i) {
+ if ($line =~ m/^\[ipset\s+(\S+)\]\s*(?:#\s*(.*?)\s*)?$/i) {
$section = 'ipset';
$group = lc($1);
+ my $comment = $2;
+ $res->{$section}->{$group} = [];
+ $res->{ipset_comments}->{$group} = $comment if $comment;
next;
}
}
push @{$res->{$section}->{$group}}, $rule;
} elsif ($section eq 'ipset') {
- chomp $line;
- $line =~ m/^(\!)?\s*((\d+)\.(\d+)\.(\d+)\.(\d+)(\/(\d+))?)/;
+ # we can add single line comments to the end of the rule
+ my $comment = decode('utf8', $1) if $line =~ s/#\s*(.*?)\s*$//;
+
+ $line =~ m/^(\!)?\s*(\S+)\s*$/;
my $nomatch = $1;
- my $ip = $2;
+ my $cidr = $2;
- if(!$ip){
- warn "$prefix: $line is not an valid ip address\n";
- next;
- }
- if (!Net::IP->new($ip)) {
- warn "$prefix: $line is not an valid ip address\n";
+ $cidr =~ s|/32$||;
+
+ eval { pve_verify_ipv4_or_cidr($cidr); };
+ if (my $err = $@) {
+ warn "$prefix: $cidr - $err";
next;
}
- if ($nomatch) {
- if ($feature_ipset_nomatch) {
- push @{$res->{$section}->{$group}}, "$ip nomatch";
- } else {
- warn "$prefix: ignore $line - nomatch not supported by kernel\n";
- }
- } else {
- push @{$res->{$section}->{$group}}, $ip;
- }
+ my $entry = { cidr => $cidr };
+ $entry->{nomatch} = 1 if $nomatch;
+ $entry->{comment} = $comment if $comment;
+
+ push @{$res->{$section}->{$group}}, $entry;
}
}
my $raw = '';
foreach my $rule (@$rules) {
- if ($rule->{type} eq 'in' || $rule->{type} eq 'out') {
+ if ($rule->{type} eq 'in' || $rule->{type} eq 'out' || $rule->{type} eq 'group') {
$raw .= '|' if defined($rule->{enable}) && !$rule->{enable};
$raw .= uc($rule->{type});
if ($rule->{macro}) {
$raw .= " " . $rule->{action};
}
$raw .= " " . ($rule->{iface} || '-') if $need_iface;
- $raw .= " " . ($rule->{source} || '-');
- $raw .= " " . ($rule->{dest} || '-');
- $raw .= " " . ($rule->{proto} || '-');
- $raw .= " " . ($rule->{dport} || '-');
- $raw .= " " . ($rule->{sport} || '-');
+
+ if ($rule->{type} ne 'group') {
+ $raw .= " " . ($rule->{source} || '-');
+ $raw .= " " . ($rule->{dest} || '-');
+ $raw .= " " . ($rule->{proto} || '-');
+ $raw .= " " . ($rule->{dport} || '-');
+ $raw .= " " . ($rule->{sport} || '-');
+ }
+
$raw .= " # " . encode('utf8', $rule->{comment})
if $rule->{comment} && $rule->{comment} !~ m/^\s*$/;
$raw .= "\n";
} else {
- die "implement me '$rule->{type}'";
+ die "unknown rule type '$rule->{type}'";
}
}
return $raw;
};
+my $format_ipset = sub {
+ my ($options) = @_;
+
+ my $raw = '';
+
+ my $nethash = {};
+ foreach my $entry (@$options) {
+ $nethash->{$entry->{cidr}} = $entry;
+ }
+
+ foreach my $cidr (sort keys %$nethash) {
+ my $entry = $nethash->{$cidr};
+ my $line = $entry->{nomatch} ? '!' : '';
+ $line .= $entry->{cidr};
+ $line .= " # " . encode('utf8', $entry->{comment})
+ if $entry->{comment} && $entry->{comment} !~ m/^\s*$/;
+ $raw .= "$line\n";
+ }
+
+ return $raw;
+};
+
sub save_vmfw_conf {
my ($vmid, $vmfw_conf) = @_;
push @{$ipset_ruleset->{$name}}, "create $name hash:net family inet hashsize $hashsize maxelem $hashsize";
- foreach my $ip (@$options) {
- push @{$ipset_ruleset->{$name}}, "add $name $ip";
+ # remove duplicates
+ my $nethash = {};
+ foreach my $entry (@$options) {
+ $nethash->{$entry->{cidr}} = $entry;
+ }
+
+ foreach my $cidr (sort keys %$nethash) {
+ my $entry = $nethash->{$cidr};
+
+ my $cmd = "add $name $cidr";
+ if ($entry->{nomatch}) {
+ if ($feature_ipset_nomatch) {
+ push @{$ipset_ruleset->{$name}}, "$cmd nomatch";
+ } else {
+ warn "ignore !$cidr - nomatch not supported by kernel\n";
+ }
+ } else {
+ push @{$ipset_ruleset->{$name}}, $cmd;
+ }
}
}
my $options = $cluster_conf->{options};
$raw .= &$format_options($options) if scalar(keys %$options);
- # fixme: save ipset
+ foreach my $ipset (sort keys %{$cluster_conf->{ipset}}) {
+ if (my $comment = $cluster_conf->{ipset_comments}->{$ipset}) {
+ $raw .= "[IPSET $ipset] # $comment\n\n";
+ } else {
+ $raw .= "[IPSET $ipset]\n\n";
+ }
+ my $options = $cluster_conf->{ipset}->{$ipset};
+ $raw .= &$format_ipset($options);
+ $raw .= "\n";
+ }
my $rules = $cluster_conf->{rules};
if (scalar(@$rules)) {
foreach my $group (sort keys %{$cluster_conf->{groups}}) {
my $rules = $cluster_conf->{groups}->{$group};
- $raw .= "[group $group]\n\n";
+ if (my $comment = $cluster_conf->{group_comments}->{$group}) {
+ $raw .= "[group $group] # $comment\n\n";
+ } else {
+ $raw .= "[group $group]\n\n";
+ }
+
$raw .= &$format_rules($rules, 0);
$raw .= "\n";
}
my $active_chains = ipset_get_chains();
my $statushash = get_ruleset_status($ruleset, $active_chains, \&ipset_chain_digest, $verbose);
+ # remove stale _swap chains
+ foreach my $chain (keys %$active_chains) {
+ if ($chain =~ m/^PVEFW-\S+_swap$/) {
+ $cmdlist .= "destroy $chain\n";
+ }
+ }
+
foreach my $chain (sort keys %$ruleset) {
my $stat = $statushash->{$chain};
die "internal error" if !$stat;