From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) by lore.proxmox.com (Postfix) with ESMTPS id 592F81FF380 for ; Fri, 19 Apr 2024 09:31:05 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 3E139526; Fri, 19 Apr 2024 09:31:04 +0200 (CEST) From: Stefan Hanreich To: pve-devel@lists.proxmox.com Date: Thu, 18 Apr 2024 18:14:11 +0200 Message-Id: <20240418161434.709473-17-s.hanreich@proxmox.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20240418161434.709473-1-s.hanreich@proxmox.com> References: <20240418161434.709473-1-s.hanreich@proxmox.com> MIME-Version: 1.0 X-SPAM-LEVEL: Spam detection results: 0 AWL -0.280 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods RDNS_NONE 0.793 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record Subject: [pve-devel] [PATCH proxmox-firewall v3 16/39] config: firewall: add conntrack helper types X-BeenThere: pve-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: Proxmox VE development discussion Cc: Wolfgang Bumiller Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: pve-devel-bounces@lists.proxmox.com Sender: "pve-devel" Reviewed-by: Lukas Wagner Reviewed-by: Max Carrara Co-authored-by: Wolfgang Bumiller Signed-off-by: Stefan Hanreich --- proxmox-ve-config/resources/ct_helper.json | 52 +++++++++ proxmox-ve-config/src/firewall/ct_helper.rs | 115 ++++++++++++++++++++ proxmox-ve-config/src/firewall/mod.rs | 1 + 3 files changed, 168 insertions(+) create mode 100644 proxmox-ve-config/resources/ct_helper.json create mode 100644 proxmox-ve-config/src/firewall/ct_helper.rs diff --git a/proxmox-ve-config/resources/ct_helper.json b/proxmox-ve-config/resources/ct_helper.json new file mode 100644 index 0000000..5e70a3a --- /dev/null +++ b/proxmox-ve-config/resources/ct_helper.json @@ -0,0 +1,52 @@ +[ + { + "name": "amanda", + "v4": true, + "v6": true, + "udp": 10080 + }, + { + "name": "ftp", + "v4": true, + "v6": true, + "tcp": 21 + } , + { + "name": "irc", + "v4": true, + "tcp": 6667 + }, + { + "name": "netbios-ns", + "v4": true, + "udp": 137 + }, + { + "name": "pptp", + "v4": true, + "tcp": 1723 + }, + { + "name": "sane", + "v4": true, + "v6": true, + "tcp": 6566 + }, + { + "name": "sip", + "v4": true, + "v6": true, + "udp": 5060 + }, + { + "name": "snmp", + "v4": true, + "udp": 161 + }, + { + "name": "tftp", + "v4": true, + "v6": true, + "udp": 69 + } +] diff --git a/proxmox-ve-config/src/firewall/ct_helper.rs b/proxmox-ve-config/src/firewall/ct_helper.rs new file mode 100644 index 0000000..40e4fee --- /dev/null +++ b/proxmox-ve-config/src/firewall/ct_helper.rs @@ -0,0 +1,115 @@ +use anyhow::{bail, Error}; +use serde::Deserialize; +use std::collections::HashMap; +use std::sync::OnceLock; + +use crate::firewall::types::address::Family; +use crate::firewall::types::rule_match::{Ports, Protocol, Tcp, Udp}; + +#[derive(Clone, Debug, Deserialize)] +pub struct CtHelperMacroJson { + pub v4: Option, + pub v6: Option, + pub name: String, + pub tcp: Option, + pub udp: Option, +} + +impl TryFrom for CtHelperMacro { + type Error = Error; + + fn try_from(value: CtHelperMacroJson) -> Result { + if value.tcp.is_none() && value.udp.is_none() { + bail!("Neither TCP nor UDP port set in CT helper!"); + } + + let family = match (value.v4, value.v6) { + (Some(true), Some(true)) => None, + (Some(true), _) => Some(Family::V4), + (_, Some(true)) => Some(Family::V6), + _ => bail!("Neither v4 nor v6 set in CT Helper Macro!"), + }; + + let mut ct_helper = CtHelperMacro { + family, + name: value.name, + tcp: None, + udp: None, + }; + + if let Some(dport) = value.tcp { + let ports = Ports::from_u16(None, dport); + ct_helper.tcp = Some(Tcp::new(ports).into()); + } + + if let Some(dport) = value.udp { + let ports = Ports::from_u16(None, dport); + ct_helper.udp = Some(Udp::new(ports).into()); + } + + Ok(ct_helper) + } +} + +#[derive(Clone, Debug, Deserialize)] +#[serde(try_from = "CtHelperMacroJson")] +pub struct CtHelperMacro { + family: Option, + name: String, + tcp: Option, + udp: Option, +} + +impl CtHelperMacro { + fn helper_name(&self, protocol: &str) -> String { + format!("helper-{}-{protocol}", self.name) + } + + pub fn tcp_helper_name(&self) -> String { + self.helper_name("tcp") + } + + pub fn udp_helper_name(&self) -> String { + self.helper_name("udp") + } + + pub fn family(&self) -> Option { + self.family + } + + pub fn name(&self) -> &str { + self.name.as_ref() + } + + pub fn tcp(&self) -> Option<&Protocol> { + self.tcp.as_ref() + } + + pub fn udp(&self) -> Option<&Protocol> { + self.udp.as_ref() + } +} + +fn hashmap() -> &'static HashMap { + const MACROS: &str = include_str!("../../resources/ct_helper.json"); + static HASHMAP: OnceLock> = OnceLock::new(); + + HASHMAP.get_or_init(|| { + let macro_data: Vec = match serde_json::from_str(MACROS) { + Ok(data) => data, + Err(err) => { + log::error!("could not load data for ct helpers: {err}"); + Vec::new() + } + }; + + macro_data + .into_iter() + .map(|elem| (elem.name.clone(), elem)) + .collect() + }) +} + +pub fn get_cthelper(name: &str) -> Option<&'static CtHelperMacro> { + hashmap().get(name) +} diff --git a/proxmox-ve-config/src/firewall/mod.rs b/proxmox-ve-config/src/firewall/mod.rs index 0f438ca..2cf57e2 100644 --- a/proxmox-ve-config/src/firewall/mod.rs +++ b/proxmox-ve-config/src/firewall/mod.rs @@ -1,5 +1,6 @@ pub mod cluster; pub mod common; +pub mod ct_helper; pub mod fw_macros; pub mod guest; pub mod host; -- 2.39.2 _______________________________________________ pve-devel mailing list pve-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel