diff options
author | Kaarle Ritvanen <kaarle.ritvanen@datakunkku.fi> | 2012-08-24 11:54:22 +0000 |
---|---|---|
committer | Kaarle Ritvanen <kaarle.ritvanen@datakunkku.fi> | 2012-08-28 11:09:19 +0000 |
commit | 216f0f040bbdf2265ecf1f20d9e29387c7dcb81f (patch) | |
tree | 4b441257b4f15acf12a7cddff3bb55edd06658c5 /main | |
parent | 522f3fb09d4838e9ea1b0345677f517484177aeb (diff) | |
download | aports-216f0f040bbdf2265ecf1f20d9e29387c7dcb81f.tar.bz2 aports-216f0f040bbdf2265ecf1f20d9e29387c7dcb81f.tar.xz |
main/ipset: separate config file for each ipset, save/reload commands in init script
Diffstat (limited to 'main')
-rw-r--r-- | main/ipset/APKBUILD | 4 | ||||
-rw-r--r-- | main/ipset/ipset.initd | 106 |
2 files changed, 99 insertions, 11 deletions
diff --git a/main/ipset/APKBUILD b/main/ipset/APKBUILD index e8b88ef82e..3693efc5a0 100644 --- a/main/ipset/APKBUILD +++ b/main/ipset/APKBUILD @@ -2,7 +2,7 @@ # Maintainer: Kaarle Ritvanen <kaarle.ritvanen@datakunkku.fi> pkgname=ipset pkgver=6.11 -pkgrel=1 +pkgrel=2 pkgdesc="Manage Linux IP sets" url=http://ipset.netfilter.org/ arch=all @@ -40,4 +40,4 @@ package() { } md5sums="bfcc92e30a0fcf10ae6e7c4affa03c84 ipset-6.11.tar.bz2 -9f2e07dc13cafe456aa9d70fb631f175 ipset.initd" +b104b06d68e17919c4a82ea2f7b41952 ipset.initd" diff --git a/main/ipset/ipset.initd b/main/ipset/ipset.initd index 6e3294c8e0..fdca0a15f4 100644 --- a/main/ipset/ipset.initd +++ b/main/ipset/ipset.initd @@ -3,22 +3,110 @@ # Copyright (C) 2012 Kaarle Ritvanen # Licensed under the terms of the GPL2 +extra_started_commands="save reload" + + +IPSET=/usr/sbin/ipset +DIR=/etc/ipset.d +STATUS=0 + +ipset() { + $IPSET $* || STATUS=1 +} + +set_files() { + (cd $DIR && ls) +} + +set_file() { + grep -v ^# $DIR/$1 +} + +set_exists() { + $IPSET save $1 &> /dev/null +} + +sets() { + $IPSET save | sed "s/^create \\([^ ]\\+\\) ${1:+$1 }.*/\\1/;ta;d;:a" +} + + depend() { before iptables ip6tables } start() { - if ls /etc/ipset.d/* &> /dev/null; then - ebegin "Loading firewall IP sets" - for f in /etc/ipset.d/*; do - /usr/sbin/ipset restore < $f - done - eend $? - fi + reload } stop() { ebegin "Flushing firewall IP sets" - /usr/sbin/ipset destroy - eend $? + + for name in $(sets list:set); do + ipset destroy $name + done + + for name in $(sets); do + ipset destroy $name + done + + eend $STATUS +} + +save() { + ebegin "Saving firewall IP sets" + + ipset save | while read cmd; do + set -- $cmd + local action=$1 + local file=$DIR/$2 + shift 2 + if [ "$action" = create ]; then + echo $* > $file + elif [ "$action" = add ]; then + echo $* >> $file + fi + done + + for name in $(set_files); do + set_exists $name || rm -f $DIR/$name + done + + eend $STATUS +} + +reload() { + ebegin "Loading firewall IP sets" + + local swap= + for name in $(set_files); do + local new=$name + if set_exists $name; then + new=_init_$name + swap="$swap $name" + fi + ipset create $new $(set_file $name | head -n 1) + done + + for name in $(set_files); do + local new=$name + set_exists _init_$name && new=_init_$name + set_file $name | tail -n +2 | while read m; do + ipset add $new $m + done + done + + for name in $swap; do + ipset swap $name _init_$name + done + + for name in $(sets list:set); do + [ -f $DIR/$name ] || ipset destroy $name + done + + for name in $(sets); do + [ -f $DIR/$name ] || ipset destroy $name + done + + eend $STATUS } |