From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 3237D90C86 for ; Tue, 2 Apr 2024 19:25:48 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 1AC10B3BF for ; Tue, 2 Apr 2024 19:25:48 +0200 (CEST) Received: from lana.proxmox.com (unknown [94.136.29.99]) by firstgate.proxmox.com (Proxmox) with ESMTP for ; Tue, 2 Apr 2024 19:25:46 +0200 (CEST) Received: by lana.proxmox.com (Postfix, from userid 10043) id 44C972C34AF; Tue, 2 Apr 2024 19:16:31 +0200 (CEST) From: Stefan Hanreich To: pve-devel@lists.proxmox.com Cc: Stefan Hanreich , Wolfgang Bumiller Date: Tue, 2 Apr 2024 19:16:08 +0200 Message-Id: <20240402171629.536804-17-s.hanreich@proxmox.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20240402171629.536804-1-s.hanreich@proxmox.com> References: <20240402171629.536804-1-s.hanreich@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL -0.312 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 0.793 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record URIBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [self.family, mod.rs] Subject: [pve-devel] [PATCH proxmox-firewall 16/37] config: firewall: add conntrack helper types X-BeenThere: pve-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Apr 2024 17:25:48 -0000 Co-authored-by: Wolfgang Bumiller Signed-off-by: Stefan Hanreich --- proxmox-ve-config/resources/ct_helper.json | 52 +++++++++ proxmox-ve-config/src/firewall/ct_helper.rs | 115 ++++++++++++++++++++ proxmox-ve-config/src/firewall/mod.rs | 1 + 3 files changed, 168 insertions(+) create mode 100644 proxmox-ve-config/resources/ct_helper.json create mode 100644 proxmox-ve-config/src/firewall/ct_helper.rs diff --git a/proxmox-ve-config/resources/ct_helper.json b/proxmox-ve-config/resources/ct_helper.json new file mode 100644 index 0000000..5e70a3a --- /dev/null +++ b/proxmox-ve-config/resources/ct_helper.json @@ -0,0 +1,52 @@ +[ + { + "name": "amanda", + "v4": true, + "v6": true, + "udp": 10080 + }, + { + "name": "ftp", + "v4": true, + "v6": true, + "tcp": 21 + } , + { + "name": "irc", + "v4": true, + "tcp": 6667 + }, + { + "name": "netbios-ns", + "v4": true, + "udp": 137 + }, + { + "name": "pptp", + "v4": true, + "tcp": 1723 + }, + { + "name": "sane", + "v4": true, + "v6": true, + "tcp": 6566 + }, + { + "name": "sip", + "v4": true, + "v6": true, + "udp": 5060 + }, + { + "name": "snmp", + "v4": true, + "udp": 161 + }, + { + "name": "tftp", + "v4": true, + "v6": true, + "udp": 69 + } +] diff --git a/proxmox-ve-config/src/firewall/ct_helper.rs b/proxmox-ve-config/src/firewall/ct_helper.rs new file mode 100644 index 0000000..40e4fee --- /dev/null +++ b/proxmox-ve-config/src/firewall/ct_helper.rs @@ -0,0 +1,115 @@ +use anyhow::{bail, Error}; +use serde::Deserialize; +use std::collections::HashMap; +use std::sync::OnceLock; + +use crate::firewall::types::address::Family; +use crate::firewall::types::rule_match::{Ports, Protocol, Tcp, Udp}; + +#[derive(Clone, Debug, Deserialize)] +pub struct CtHelperMacroJson { + pub v4: Option, + pub v6: Option, + pub name: String, + pub tcp: Option, + pub udp: Option, +} + +impl TryFrom for CtHelperMacro { + type Error = Error; + + fn try_from(value: CtHelperMacroJson) -> Result { + if value.tcp.is_none() && value.udp.is_none() { + bail!("Neither TCP nor UDP port set in CT helper!"); + } + + let family = match (value.v4, value.v6) { + (Some(true), Some(true)) => None, + (Some(true), _) => Some(Family::V4), + (_, Some(true)) => Some(Family::V6), + _ => bail!("Neither v4 nor v6 set in CT Helper Macro!"), + }; + + let mut ct_helper = CtHelperMacro { + family, + name: value.name, + tcp: None, + udp: None, + }; + + if let Some(dport) = value.tcp { + let ports = Ports::from_u16(None, dport); + ct_helper.tcp = Some(Tcp::new(ports).into()); + } + + if let Some(dport) = value.udp { + let ports = Ports::from_u16(None, dport); + ct_helper.udp = Some(Udp::new(ports).into()); + } + + Ok(ct_helper) + } +} + +#[derive(Clone, Debug, Deserialize)] +#[serde(try_from = "CtHelperMacroJson")] +pub struct CtHelperMacro { + family: Option, + name: String, + tcp: Option, + udp: Option, +} + +impl CtHelperMacro { + fn helper_name(&self, protocol: &str) -> String { + format!("helper-{}-{protocol}", self.name) + } + + pub fn tcp_helper_name(&self) -> String { + self.helper_name("tcp") + } + + pub fn udp_helper_name(&self) -> String { + self.helper_name("udp") + } + + pub fn family(&self) -> Option { + self.family + } + + pub fn name(&self) -> &str { + self.name.as_ref() + } + + pub fn tcp(&self) -> Option<&Protocol> { + self.tcp.as_ref() + } + + pub fn udp(&self) -> Option<&Protocol> { + self.udp.as_ref() + } +} + +fn hashmap() -> &'static HashMap { + const MACROS: &str = include_str!("../../resources/ct_helper.json"); + static HASHMAP: OnceLock> = OnceLock::new(); + + HASHMAP.get_or_init(|| { + let macro_data: Vec = match serde_json::from_str(MACROS) { + Ok(data) => data, + Err(err) => { + log::error!("could not load data for ct helpers: {err}"); + Vec::new() + } + }; + + macro_data + .into_iter() + .map(|elem| (elem.name.clone(), elem)) + .collect() + }) +} + +pub fn get_cthelper(name: &str) -> Option<&'static CtHelperMacro> { + hashmap().get(name) +} diff --git a/proxmox-ve-config/src/firewall/mod.rs b/proxmox-ve-config/src/firewall/mod.rs index 0f438ca..2cf57e2 100644 --- a/proxmox-ve-config/src/firewall/mod.rs +++ b/proxmox-ve-config/src/firewall/mod.rs @@ -1,5 +1,6 @@ pub mod cluster; pub mod common; +pub mod ct_helper; pub mod fw_macros; pub mod guest; pub mod host; -- 2.39.2