summaryrefslogtreecommitdiffstats
path: root/main/ipset
diff options
context:
space:
mode:
authorKaarle Ritvanen <kaarle.ritvanen@datakunkku.fi>2012-08-24 11:54:22 +0000
committerKaarle Ritvanen <kaarle.ritvanen@datakunkku.fi>2012-08-28 11:09:19 +0000
commit216f0f040bbdf2265ecf1f20d9e29387c7dcb81f (patch)
tree4b441257b4f15acf12a7cddff3bb55edd06658c5 /main/ipset
parent522f3fb09d4838e9ea1b0345677f517484177aeb (diff)
downloadaports-216f0f040bbdf2265ecf1f20d9e29387c7dcb81f.tar.bz2
aports-216f0f040bbdf2265ecf1f20d9e29387c7dcb81f.tar.xz
main/ipset: separate config file for each ipset, save/reload commands in init script
Diffstat (limited to 'main/ipset')
-rw-r--r--main/ipset/APKBUILD4
-rw-r--r--main/ipset/ipset.initd106
2 files changed, 99 insertions, 11 deletions
diff --git a/main/ipset/APKBUILD b/main/ipset/APKBUILD
index e8b88ef82..3693efc5a 100644
--- a/main/ipset/APKBUILD
+++ b/main/ipset/APKBUILD
@@ -2,7 +2,7 @@
# Maintainer: Kaarle Ritvanen <kaarle.ritvanen@datakunkku.fi>
pkgname=ipset
pkgver=6.11
-pkgrel=1
+pkgrel=2
pkgdesc="Manage Linux IP sets"
url=http://ipset.netfilter.org/
arch=all
@@ -40,4 +40,4 @@ package() {
}
md5sums="bfcc92e30a0fcf10ae6e7c4affa03c84 ipset-6.11.tar.bz2
-9f2e07dc13cafe456aa9d70fb631f175 ipset.initd"
+b104b06d68e17919c4a82ea2f7b41952 ipset.initd"
diff --git a/main/ipset/ipset.initd b/main/ipset/ipset.initd
index 6e3294c8e..fdca0a15f 100644
--- a/main/ipset/ipset.initd
+++ b/main/ipset/ipset.initd
@@ -3,22 +3,110 @@
# Copyright (C) 2012 Kaarle Ritvanen
# Licensed under the terms of the GPL2
+extra_started_commands="save reload"
+
+
+IPSET=/usr/sbin/ipset
+DIR=/etc/ipset.d
+STATUS=0
+
+ipset() {
+ $IPSET $* || STATUS=1
+}
+
+set_files() {
+ (cd $DIR && ls)
+}
+
+set_file() {
+ grep -v ^# $DIR/$1
+}
+
+set_exists() {
+ $IPSET save $1 &> /dev/null
+}
+
+sets() {
+ $IPSET save | sed "s/^create \\([^ ]\\+\\) ${1:+$1 }.*/\\1/;ta;d;:a"
+}
+
+
depend() {
before iptables ip6tables
}
start() {
- if ls /etc/ipset.d/* &> /dev/null; then
- ebegin "Loading firewall IP sets"
- for f in /etc/ipset.d/*; do
- /usr/sbin/ipset restore < $f
- done
- eend $?
- fi
+ reload
}
stop() {
ebegin "Flushing firewall IP sets"
- /usr/sbin/ipset destroy
- eend $?
+
+ for name in $(sets list:set); do
+ ipset destroy $name
+ done
+
+ for name in $(sets); do
+ ipset destroy $name
+ done
+
+ eend $STATUS
+}
+
+save() {
+ ebegin "Saving firewall IP sets"
+
+ ipset save | while read cmd; do
+ set -- $cmd
+ local action=$1
+ local file=$DIR/$2
+ shift 2
+ if [ "$action" = create ]; then
+ echo $* > $file
+ elif [ "$action" = add ]; then
+ echo $* >> $file
+ fi
+ done
+
+ for name in $(set_files); do
+ set_exists $name || rm -f $DIR/$name
+ done
+
+ eend $STATUS
+}
+
+reload() {
+ ebegin "Loading firewall IP sets"
+
+ local swap=
+ for name in $(set_files); do
+ local new=$name
+ if set_exists $name; then
+ new=_init_$name
+ swap="$swap $name"
+ fi
+ ipset create $new $(set_file $name | head -n 1)
+ done
+
+ for name in $(set_files); do
+ local new=$name
+ set_exists _init_$name && new=_init_$name
+ set_file $name | tail -n +2 | while read m; do
+ ipset add $new $m
+ done
+ done
+
+ for name in $swap; do
+ ipset swap $name _init_$name
+ done
+
+ for name in $(sets list:set); do
+ [ -f $DIR/$name ] || ipset destroy $name
+ done
+
+ for name in $(sets); do
+ [ -f $DIR/$name ] || ipset destroy $name
+ done
+
+ eend $STATUS
}