]> git.proxmox.com Git - pve-firewall.git/blob - PVE/Firewall.pm
0c1a37afccbcc93c0de111e4f3d09b290f0f4c11
[pve-firewall.git] / PVE / Firewall.pm
1 package PVE::Firewall;
2
3 use warnings;
4 use strict;
5 use Data::Dumper;
6 use Digest::MD5;
7 use PVE::Tools;
8 use PVE::QemuServer;
9 use File::Path;
10 use IO::File;
11 use Net::IP;
12 use PVE::Tools qw(run_command lock_file);
13
14 use Data::Dumper;
15
16 my $pve_fw_lock_filename = "/var/lock/pvefw.lck";
17
18 my $macros;
19
20 # todo: implement some kind of MACROS, like shorewall /usr/share/shorewall/macro.*
21 sub get_firewall_macros {
22
23 return $macros if $macros;
24
25 #foreach my $path (</usr/share/shorewall/macro.*>) {
26 # if ($path =~ m|/macro\.(\S+)$|) {
27 # $macros->{$1} = 1;
28 # }
29 #}
30
31 $macros = {}; # fixme: implemet me
32
33 return $macros;
34 }
35
36 my $etc_services;
37
38 sub get_etc_services {
39
40 return $etc_services if $etc_services;
41
42 my $filename = "/etc/services";
43
44 my $fh = IO::File->new($filename, O_RDONLY);
45 if (!$fh) {
46 warn "unable to read '$filename' - $!\n";
47 return {};
48 }
49
50 my $services = {};
51
52 while (my $line = <$fh>) {
53 chomp ($line);
54 next if $line =~m/^#/;
55 next if ($line =~m/^\s*$/);
56
57 if ($line =~ m!^(\S+)\s+(\S+)/(tcp|udp).*$!) {
58 $services->{byid}->{$2}->{name} = $1;
59 $services->{byid}->{$2}->{$3} = 1;
60 $services->{byname}->{$1} = $services->{byid}->{$2};
61 }
62 }
63
64 close($fh);
65
66 $etc_services = $services;
67
68
69 return $etc_services;
70 }
71
72 my $etc_protocols;
73
74 sub get_etc_protocols {
75 return $etc_protocols if $etc_protocols;
76
77 my $filename = "/etc/protocols";
78
79 my $fh = IO::File->new($filename, O_RDONLY);
80 if (!$fh) {
81 warn "unable to read '$filename' - $!\n";
82 return {};
83 }
84
85 my $protocols = {};
86
87 while (my $line = <$fh>) {
88 chomp ($line);
89 next if $line =~m/^#/;
90 next if ($line =~m/^\s*$/);
91
92 if ($line =~ m!^(\S+)\s+(\d+)\s+.*$!) {
93 $protocols->{byid}->{$2}->{name} = $1;
94 $protocols->{byname}->{$1} = $protocols->{byid}->{$2};
95 }
96 }
97
98 close($fh);
99
100 $etc_protocols = $protocols;
101
102 return $etc_protocols;
103 }
104
105 sub parse_address_list {
106 my ($str) = @_;
107
108 my $nbaor = 0;
109 foreach my $aor (split(/,/, $str)) {
110 if (!Net::IP->new($aor)) {
111 my $err = Net::IP::Error();
112 die "invalid IP address: $err\n";
113 }else{
114 $nbaor++;
115 }
116 }
117 return $nbaor;
118 }
119
120 sub parse_port_name_number_or_range {
121 my ($str) = @_;
122
123 my $services = PVE::Firewall::get_etc_services();
124 my $nbports = 0;
125 foreach my $item (split(/,/, $str)) {
126 my $portlist = "";
127 foreach my $pon (split(':', $item, 2)) {
128 if ($pon =~ m/^\d+$/){
129 die "invalid port '$pon'\n" if $pon < 0 && $pon > 65536;
130 }else{
131 die "invalid port $services->{byname}->{$pon}\n" if !$services->{byname}->{$pon};
132 }
133 $nbports++;
134 }
135 }
136
137 return ($nbports);
138 }
139
140 my $rule_format = "%-15s %-30s %-30s %-15s %-15s %-15s\n";
141
142 sub iptables {
143 my ($cmd) = @_;
144
145 run_command("/sbin/iptables $cmd", outfunc => sub {}, errfunc => sub {});
146 }
147
148 sub iptables_restore_cmdlist {
149 my ($cmdlist) = @_;
150
151 run_command("/sbin/iptables-restore -n", input => $cmdlist);
152 }
153
154 sub iptables_get_chains {
155
156 my $res = {};
157
158 # check what chains we want to track
159 my $is_pvefw_chain = sub {
160 my $name = shift;
161
162 return 1 if $name =~ m/^BRIDGEFW-(:?IN|OUT)$/;
163 return 1 if $name =~ m/^proxmoxfw-\S+$/;
164 return 1 if $name =~ m/^tap\d+i\d+-(:?IN|OUT)$/;
165 return 1 if $name =~ m/^vmbr\d+-(:?IN|OUT)$/;
166 return 1 if $name =~ m/^GROUP-(:?[^\s\-]+)-(:?IN|OUT)$/;
167 return 1 if $name =~ m/^host-(:?IN|OUT)$/;
168
169 return undef;
170 };
171
172 my $table = '';
173
174 my $parser = sub {
175 my $line = shift;
176
177 return if $line =~ m/^#/;
178 return if $line =~ m/^\s*$/;
179
180 if ($line =~ m/^\*(\S+)$/) {
181 $table = $1;
182 return;
183 }
184
185 return if $table ne 'filter';
186
187 if ($line =~ m/^:(\S+)\s/) {
188 my $chain = $1;
189 return if !&$is_pvefw_chain($chain);
190 $res->{$chain} = "unknown";
191 } elsif ($line =~ m/^-A\s+(\S+)\s.*--log-prefix\s+\"PVESIG:(\S+)\"/) {
192 my ($chain, $sig) = ($1, $2);
193 return if !&$is_pvefw_chain($chain);
194 $res->{$chain} = $sig;
195 } else {
196 # simply ignore the rest
197 return;
198 }
199 };
200
201 run_command("/sbin/iptables-save", outfunc => $parser);
202
203 return $res;
204 }
205
206 sub iptables_chain_exist {
207 my ($chain) = @_;
208
209 eval{
210 iptables("-n --list $chain");
211 };
212 return undef if $@;
213
214 return 1;
215 }
216
217 sub iptables_rule_exist {
218 my ($rule) = @_;
219
220 eval{
221 iptables("-C $rule");
222 };
223 return undef if $@;
224
225 return 1;
226 }
227
228 sub ruleset_generate_rule {
229 my ($ruleset, $chain, $rule) = @_;
230
231 my $cmd = '';
232
233 $cmd .= " -m iprange --src-range" if $rule->{nbsource} && $rule->{nbsource} > 1;
234 $cmd .= " -s $rule->{source}" if $rule->{source};
235 $cmd .= " -m iprange --dst-range" if $rule->{nbdest} && $rule->{nbdest} > 1;
236 $cmd .= " -d $rule->{dest}" if $rule->{destination};
237 $cmd .= " -p $rule->{proto}" if $rule->{proto};
238 $cmd .= " --match multiport" if $rule->{nbdport} && $rule->{nbdport} > 1;
239 $cmd .= " --dport $rule->{dport}" if $rule->{dport};
240 $cmd .= " --match multiport" if $rule->{nbsport} && $rule->{nbsport} > 1;
241 $cmd .= " --sport $rule->{sport}" if $rule->{sport};
242 $cmd .= " -j $rule->{action}" if $rule->{action};
243
244 ruleset_addrule($ruleset, $chain, $cmd) if $cmd;
245 }
246
247 sub ruleset_create_chain {
248 my ($ruleset, $chain) = @_;
249
250 die "chain '$chain' already exists\n" if $ruleset->{$chain};
251
252 $ruleset->{$chain} = [];
253 }
254
255 sub ruleset_chain_exist {
256 my ($ruleset, $chain) = @_;
257
258 return $ruleset->{$chain} ? 1 : undef;
259 }
260
261 sub ruleset_addrule {
262 my ($ruleset, $chain, $rule) = @_;
263
264 die "no such chain '$chain'\n" if !$ruleset->{$chain};
265
266 push @{$ruleset->{$chain}}, "-A $chain $rule";
267 }
268
269 sub ruleset_insertrule {
270 my ($ruleset, $chain, $rule) = @_;
271
272 die "no such chain '$chain'\n" if !$ruleset->{$chain};
273
274 unshift @{$ruleset->{$chain}}, "-A $chain $rule";
275 }
276
277 sub generate_bridge_chains {
278 my ($ruleset, $bridge) = @_;
279
280 ruleset_create_chain($ruleset, "BRIDGEFW-IN");
281 ruleset_create_chain($ruleset, "BRIDGEFW-OUT");
282
283 if (!ruleset_chain_exist($ruleset, "proxmoxfw-FORWARD")){
284 ruleset_create_chain($ruleset, "proxmoxfw-FORWARD");
285
286 ruleset_addrule($ruleset, "proxmoxfw-FORWARD", "-m state --state RELATED,ESTABLISHED -j ACCEPT");
287 ruleset_addrule($ruleset, "proxmoxfw-FORWARD", "-m physdev --physdev-is-in --physdev-is-bridged -j BRIDGEFW-OUT");
288 ruleset_addrule($ruleset, "proxmoxfw-FORWARD", "-m physdev --physdev-is-out --physdev-is-bridged -j BRIDGEFW-IN");
289 }
290
291 if (!ruleset_chain_exist($ruleset, "$bridge-IN")) {
292 ruleset_create_chain($ruleset, "$bridge-IN");
293 ruleset_addrule($ruleset, "proxmoxfw-FORWARD", "-i $bridge -j DROP"); # disable interbridge routing
294 ruleset_addrule($ruleset, "BRIDGEFW-IN", "-j $bridge-IN");
295 ruleset_addrule($ruleset, "$bridge-IN", "-j ACCEPT");
296 }
297
298 if (!ruleset_chain_exist($ruleset, "$bridge-OUT")) {
299 ruleset_create_chain($ruleset, "$bridge-OUT");
300 ruleset_addrule($ruleset, "proxmoxfw-FORWARD", "-o $bridge -j DROP"); # disable interbridge routing
301 ruleset_addrule($ruleset, "BRIDGEFW-OUT", "-j $bridge-OUT");
302 }
303 }
304
305 sub generate_tap_rules_direction {
306 my ($ruleset, $iface, $netid, $rules, $bridge, $direction) = @_;
307
308 my $tapchain = "$iface-$direction";
309
310 ruleset_create_chain($ruleset, $tapchain);
311
312 ruleset_addrule($ruleset, $tapchain, "-m state --state INVALID -j DROP");
313 ruleset_addrule($ruleset, $tapchain, "-m state --state RELATED,ESTABLISHED -j ACCEPT");
314
315 if ($rules) {
316 foreach my $rule (@$rules) {
317 next if $rule->{iface} && $rule->{iface} ne $netid;
318 if($rule->{action} =~ m/^(GROUP-(\S+))$/){
319 $rule->{action} .= "-$direction";
320 # generate empty group rule if don't exist
321 if(!ruleset_chain_exist($ruleset, $rule->{action})){
322 generate_group_rules($ruleset, $2);
323 }
324 }
325 # we go to vmbr-IN if accept in out rules
326 $rule->{action} = "$bridge-IN" if $rule->{action} eq 'ACCEPT' && $direction eq 'OUT';
327 ruleset_generate_rule($ruleset, $tapchain, $rule);
328 }
329 }
330
331 ruleset_addrule($ruleset, $tapchain, "-j LOG --log-prefix \"$tapchain-dropped: \" --log-level 4");
332 ruleset_addrule($ruleset, $tapchain, "-j DROP");
333
334 # plug the tap chain to bridge chain
335 my $physdevdirection = $direction eq 'IN' ? "out" : "in";
336 my $rule = "-m physdev --physdev-$physdevdirection $iface --physdev-is-bridged -j $tapchain";
337 ruleset_insertrule($ruleset, "$bridge-$direction", $rule);
338
339 if ($direction eq 'OUT'){
340 # add tap->host rules
341 my $rule = "-m physdev --physdev-$physdevdirection $iface -j $tapchain";
342 ruleset_addrule($ruleset, "proxmoxfw-INPUT", $rule);
343 }
344 }
345
346 sub enablehostfw {
347 my ($ruleset) = @_;
348
349 my $filename = "/etc/pve/local/host.fw";
350 my $fh = IO::File->new($filename, O_RDONLY);
351 return if !$fh;
352
353 my $rules = parse_fw_rules($filename, $fh);
354
355 # host inbound firewall
356 ruleset_create_chain($ruleset, "host-IN");
357
358 ruleset_addrule($ruleset, "host-IN", "-m state --state INVALID -j DROP");
359 ruleset_addrule($ruleset, "host-IN", "-m state --state RELATED,ESTABLISHED -j ACCEPT");
360 ruleset_addrule($ruleset, "host-IN", "-i lo -j ACCEPT");
361 ruleset_addrule($ruleset, "host-IN", "-m addrtype --dst-type MULTICAST -j ACCEPT");
362 ruleset_addrule($ruleset, "host-IN", "-p udp -m state --state NEW -m multiport --dports 5404,5405 -j ACCEPT");
363 ruleset_addrule($ruleset, "host-IN", "-p udp -m udp --dport 9000 -j ACCEPT"); #corosync
364
365 if ($rules->{in}) {
366 foreach my $rule (@{$rules->{in}}) {
367 # we use RETURN because we need to check also tap rules
368 $rule->{action} = 'RETURN' if $rule->{action} eq 'ACCEPT';
369 ruleset_generate_rule($ruleset, "host-IN", $rule);
370 }
371 }
372
373 ruleset_addrule($ruleset, "host-IN", "-j LOG --log-prefix \"kvmhost-IN dropped: \" --log-level 4");
374 ruleset_addrule($ruleset, "host-IN", "-j DROP");
375
376 # host outbound firewall
377 ruleset_create_chain($ruleset, "host-OUT");
378 ruleset_addrule($ruleset, "host-OUT", "-m state --state INVALID -j DROP");
379 ruleset_addrule($ruleset, "host-OUT", "-m state --state RELATED,ESTABLISHED -j ACCEPT");
380 ruleset_addrule($ruleset, "host-OUT", "-o lo -j ACCEPT");
381 ruleset_addrule($ruleset, "host-OUT", "-m addrtype --dst-type MULTICAST -j ACCEPT");
382 ruleset_addrule($ruleset, "host-OUT", "-p udp -m state --state NEW -m multiport --dports 5404,5405 -j ACCEPT");
383 ruleset_addrule($ruleset, "host-OUT", "-p udp -m udp --dport 9000 -j ACCEPT"); #corosync
384
385 if ($rules->{out}) {
386 foreach my $rule (@{$rules->{out}}) {
387 # we use RETURN because we need to check also tap rules
388 $rule->{action} = 'RETURN' if $rule->{action} eq 'ACCEPT';
389 ruleset_generate_rule($ruleset, "host-OUT", $rule);
390 }
391 }
392
393 ruleset_addrule($ruleset, "host-OUT", "-j LOG --log-prefix \"kvmhost-OUT dropped: \" --log-level 4");
394 ruleset_addrule($ruleset, "host-OUT", "-j DROP");
395
396 ruleset_addrule($ruleset, "proxmoxfw-OUTPUT", "-j host-OUT");
397 ruleset_addrule($ruleset, "proxmoxfw-INPUT", "-j host-IN");
398 }
399
400 sub generate_group_rules {
401 my ($ruleset, $group) = @_;
402
403 my $filename = "/etc/pve/firewall/groups.fw";
404 my $fh = IO::File->new($filename, O_RDONLY);
405 return if !$fh;
406
407 my $rules = parse_fw_rules($filename, $fh, $group);
408
409 my $chain = "GROUP-${group}-IN";
410
411 ruleset_create_chain($ruleset, $chain);
412
413 if ($rules->{in}) {
414 foreach my $rule (@{$rules->{in}}) {
415 ruleset_generate_rule($ruleset, $chain, $rule);
416 }
417 }
418
419 $chain = "GROUP-${group}-OUT";
420
421 ruleset_create_chain($ruleset, $chain);
422
423 if ($rules->{out}) {
424 foreach my $rule (@{$rules->{out}}) {
425 # we go the BRIDGEFW-IN because we need to check also other tap rules
426 # (and group rules can be set on any bridge, so we can't go to VMBRXX-IN)
427 $rule->{action} = 'BRIDGEFW-IN' if $rule->{action} eq 'ACCEPT';
428 ruleset_generate_rule($rule, $chain, $rule);
429 }
430 }
431 }
432
433 sub parse_fw_rules {
434 my ($filename, $fh, $group) = @_;
435
436 my $section;
437 my $securitygroup;
438 my $securitygroupexist;
439
440 my $res = { in => [], out => [] };
441
442 my $macros = get_firewall_macros();
443 my $protocols = get_etc_protocols();
444
445 while (defined(my $line = <$fh>)) {
446 next if $line =~ m/^#/;
447 next if $line =~ m/^\s*$/;
448
449 if ($line =~ m/^\[(in|out)(:(\S+))?\]\s*$/i) {
450 $section = lc($1);
451 $securitygroup = lc($3) if $3;
452 $securitygroupexist = 1 if $securitygroup && $securitygroup eq $group;
453 next;
454 }
455 next if !$section;
456 next if $group && $securitygroup ne $group;
457
458 my ($action, $iface, $source, $dest, $proto, $dport, $sport) =
459 split(/\s+/, $line);
460
461 if (!$action) {
462 warn "skip incomplete line\n";
463 next;
464 }
465
466 my $service;
467 if ($action =~ m/^(ACCEPT|DROP|REJECT|GROUP-(\S+))$/) {
468 # OK
469 } elsif ($action =~ m/^(\S+)\((ACCEPT|DROP|REJECT)\)$/) {
470 ($service, $action) = ($1, $2);
471 if (!$macros->{$service}) {
472 warn "unknown service '$service'\n";
473 next;
474 }
475 } else {
476 warn "unknown action '$action'\n";
477 next;
478 }
479
480 $iface = undef if $iface && $iface eq '-';
481 if ($iface && $iface !~ m/^(net0|net1|net2|net3|net4|net5)$/) {
482 warn "unknown interface '$iface'\n";
483 next;
484 }
485
486 $proto = undef if $proto && $proto eq '-';
487 if ($proto && !(defined($protocols->{byname}->{$proto}) ||
488 defined($protocols->{byid}->{$proto}))) {
489 warn "unknown protokol '$proto'\n";
490 next;
491 }
492
493 $source = undef if $source && $source eq '-';
494 $dest = undef if $dest && $dest eq '-';
495
496 $dport = undef if $dport && $dport eq '-';
497 $sport = undef if $sport && $sport eq '-';
498 my $nbdport = undef;
499 my $nbsport = undef;
500 my $nbsource = undef;
501 my $nbdest = undef;
502
503 eval {
504 $nbsource = parse_address_list($source) if $source;
505 $nbdest = parse_address_list($dest) if $dest;
506 $nbdport = parse_port_name_number_or_range($dport) if $dport;
507 $nbsport = parse_port_name_number_or_range($sport) if $sport;
508 };
509 if (my $err = $@) {
510 warn $err;
511 next;
512
513 }
514
515
516 my $rule = {
517 action => $action,
518 service => $service,
519 iface => $iface,
520 source => $source,
521 dest => $dest,
522 nbsource => $nbsource,
523 nbdest => $nbdest,
524 proto => $proto,
525 dport => $dport,
526 sport => $sport,
527 nbdport => $nbdport,
528 nbsport => $nbsport,
529
530 };
531
532 push @{$res->{$section}}, $rule;
533 }
534
535 die "security group $group don't exist" if $group && !$securitygroupexist;
536 return $res;
537 }
538
539 sub run_locked {
540 my ($code, @param) = @_;
541
542 my $timeout = 10;
543
544 my $res = lock_file($pve_fw_lock_filename, $timeout, $code, @param);
545
546 die $@ if $@;
547
548 return $res;
549 }
550
551 sub read_local_vm_config {
552
553 my $openvz = {};
554
555 my $qemu = {};
556
557 my $list = PVE::QemuServer::config_list();
558
559 foreach my $vmid (keys %$list) {
560 my $cfspath = PVE::QemuServer::cfs_config_path($vmid);
561 if (my $conf = PVE::Cluster::cfs_read_file($cfspath)) {
562 $qemu->{$vmid} = $conf;
563 }
564 }
565
566 my $vmdata = { openvz => $openvz, qemu => $qemu };
567
568 return $vmdata;
569 };
570
571 sub read_vm_firewall_rules {
572 my ($vmdata) = @_;
573 my $rules = {};
574 foreach my $vmid (keys %{$vmdata->{qemu}}, keys %{$vmdata->{openvz}}) {
575 my $filename = "/etc/pve/firewall/$vmid.fw";
576 my $fh = IO::File->new($filename, O_RDONLY);
577 next if !$fh;
578
579 $rules->{$vmid} = parse_fw_rules($filename, $fh);
580 }
581
582 return $rules;
583 }
584
585 sub compile {
586 my $vmdata = read_local_vm_config();
587 my $rules = read_vm_firewall_rules($vmdata);
588
589 #print Dumper($rules);
590
591 my $ruleset = {};
592
593 # setup host firewall rules
594 ruleset_create_chain($ruleset, "proxmoxfw-INPUT");
595 ruleset_create_chain($ruleset, "proxmoxfw-OUTPUT");
596
597 enablehostfw($ruleset);
598
599 # generate firewall rules for QEMU VMs
600 foreach my $vmid (keys %{$vmdata->{qemu}}) {
601 my $conf = $vmdata->{qemu}->{$vmid};
602 next if !$rules->{$vmid};
603
604 foreach my $netid (keys %$conf) {
605 next if $netid !~ m/^net(\d+)$/;
606 my $net = PVE::QemuServer::parse_net($conf->{$netid});
607 next if !$net;
608 my $iface = "tap${vmid}i$1";
609
610 my $bridge = $net->{bridge};
611 next if !$bridge; # fixme: ?
612
613 $bridge .= "v$net->{tag}" if $net->{tag};
614
615 generate_bridge_chains($ruleset, $bridge);
616
617 generate_tap_rules_direction($ruleset, $iface, $netid, $rules->{$vmid}->{in}, $bridge, 'IN');
618 generate_tap_rules_direction($ruleset, $iface, $netid, $rules->{$vmid}->{out}, $bridge, 'OUT');
619 }
620 }
621
622 return $ruleset;
623 }
624
625 sub get_ruleset_status {
626 my ($ruleset, $verbose) = @_;
627
628 my $active_chains = iptables_get_chains();
629
630 my $statushash = {};
631
632 foreach my $chain (sort keys %$ruleset) {
633 my $digest = Digest::MD5->new();
634 foreach my $cmd (@{$ruleset->{$chain}}) {
635 $digest->add("$cmd\n");
636 }
637 my $sig = $digest->b64digest;
638 $statushash->{$chain}->{sig} = $sig;
639
640 my $oldsig = $active_chains->{$chain};
641 if (!defined($oldsig)) {
642 $statushash->{$chain}->{action} = 'create';
643 } else {
644 if ($oldsig eq $sig) {
645 $statushash->{$chain}->{action} = 'exists';
646 } else {
647 $statushash->{$chain}->{action} = 'update';
648 }
649 }
650 print "$statushash->{$chain}->{action} $chain ($sig)\n" if $verbose;
651 foreach my $cmd (@{$ruleset->{$chain}}) {
652 print "\t$cmd\n" if $verbose;
653 }
654 }
655
656 foreach my $chain (sort keys %$active_chains) {
657 if (!defined($ruleset->{$chain})) {
658 my $sig = $active_chains->{$chain};
659 $statushash->{$chain}->{action} = 'delete';
660 $statushash->{$chain}->{sig} = $sig;
661 print "delete $chain ($sig)\n" if $verbose;
662 }
663 }
664
665 return $statushash;
666 }
667
668 sub print_ruleset {
669 my ($ruleset) = @_;
670
671 get_ruleset_status($ruleset, 1);
672 }
673
674 sub print_sig_rule {
675 my ($chain, $sig) = @_;
676
677 # Note: This rule should never match! We just use this hack to store a SHA1 checksum
678 # used to detect changes
679 return "-A $chain -j LOG --log-prefix \"PVESIG:$sig\" -p tcp -s \"127.128.129.130\" --dport 1\n";
680 }
681
682 sub compile_and_start {
683 my ($verbose) = @_;
684
685 my $ruleset = compile();
686
687 my $cmdlist = "*filter\n"; # we pass this to iptables-restore;
688
689 my $statushash = get_ruleset_status($ruleset, $verbose);
690
691 # create missing chains first
692 foreach my $chain (sort keys %$ruleset) {
693 my $stat = $statushash->{$chain};
694 die "internal error" if !$stat;
695 next if $stat->{action} ne 'create';
696
697 $cmdlist .= ":$chain - [0:0]\n";
698 }
699
700 my $rule = "INPUT -j proxmoxfw-INPUT";
701 if (!PVE::Firewall::iptables_rule_exist($rule)) {
702 $cmdlist .= "-A $rule\n";
703 }
704 $rule = "OUTPUT -j proxmoxfw-OUTPUT";
705 if (!PVE::Firewall::iptables_rule_exist($rule)) {
706 $cmdlist .= "-A $rule\n";
707 }
708
709 $rule = "FORWARD -j proxmoxfw-FORWARD";
710 if (!PVE::Firewall::iptables_rule_exist($rule)) {
711 $cmdlist .= "-A $rule\n";
712 }
713
714 foreach my $chain (sort keys %$ruleset) {
715 my $stat = $statushash->{$chain};
716 die "internal error" if !$stat;
717
718 if ($stat->{action} eq 'update' || $stat->{action} eq 'create') {
719 $cmdlist .= "-F $chain\n";
720 foreach my $cmd (@{$ruleset->{$chain}}) {
721 $cmdlist .= "$cmd\n";
722 }
723 $cmdlist .= print_sig_rule($chain, $stat->{sig});
724 } elsif ($stat->{action} eq 'delete') {
725 $cmdlist .= "-F $chain\n";
726 $cmdlist .= "-X $chain\n";
727 } elsif ($stat->{action} eq 'exists') {
728 # do nothing
729 } else {
730 die "internal error - unknown status '$stat->{action}'";
731 }
732 }
733
734 $cmdlist .= "COMMIT\n";
735
736 print $cmdlist if $verbose;
737
738 iptables_restore_cmdlist($cmdlist);
739
740 # test: re-read status and check if everything is up to date
741 $statushash = get_ruleset_status($ruleset);
742
743 my $errors;
744 foreach my $chain (sort keys %$ruleset) {
745 my $stat = $statushash->{$chain};
746 if ($stat->{action} ne 'exists') {
747 warn "unable to update chain '$chain'\n";
748 $errors = 1;
749 }
750 }
751
752 die "unable to apply firewall changes\n" if $errors;
753 }
754
755 1;