From 1e33119b04a583fbf18b5b562edb14301a2ca7d6 Mon Sep 17 00:00:00 2001 From: Michael Rash Date: Wed, 8 Apr 2015 18:29:03 -0700 Subject: [PATCH] [server] use 'success' string for firewalld as returned firewall-cmd for command success --- server/fw_util_firewalld.c | 46 +++++++++++++++++++++----------------- 1 file changed, 26 insertions(+), 20 deletions(-) diff --git a/server/fw_util_firewalld.c b/server/fw_util_firewalld.c index 60a9472d..31efd191 100644 --- a/server/fw_util_firewalld.c +++ b/server/fw_util_firewalld.c @@ -299,6 +299,9 @@ comment_match_exists(const fko_srv_options_t * const opts) log_msg(LOG_DEBUG, "comment_match_exists() CMD: '%s' (res: %d, err: %s)", cmd_buf, res, err_buf); + if(strncmp(err_buf, "success", strlen("success")) != 0) + log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, cmd_out); + zero_cmd_buffers(); snprintf(cmd_buf, CMD_BUFSIZE-1, "%s " FIREWD_LIST_RULES_ARGS, @@ -311,9 +314,6 @@ comment_match_exists(const fko_srv_options_t * const opts) WANT_STDERR, NO_TIMEOUT, &pid_status, opts); chop_newline(cmd_out); - if(!EXTCMD_IS_SUCCESS(res)) - log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, cmd_out); - ndx = strstr(cmd_out, TMP_COMMENT); if(ndx == NULL) res = 0; /* did not find the tmp comment */ @@ -342,7 +342,7 @@ comment_match_exists(const fko_srv_options_t * const opts) static int add_jump_rule(const fko_srv_options_t * const opts, const int chain_num) { - int res = 0; + int res = 0, rv = 0; zero_cmd_buffers(); @@ -360,14 +360,17 @@ add_jump_rule(const fko_srv_options_t * const opts, const int chain_num) log_msg(LOG_DEBUG, "add_jump_rule() CMD: '%s' (res: %d, err: %s)", cmd_buf, res, err_buf); - if(EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) == 0) + { log_msg(LOG_INFO, "Added jump rule from chain: %s to chain: %s", fwc.chain[chain_num].from_chain, fwc.chain[chain_num].to_chain); + rv = 1; + } else log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); - return res; + return rv; } static int @@ -390,7 +393,7 @@ chain_exists(const fko_srv_options_t * const opts, const int chain_num) log_msg(LOG_DEBUG, "chain_exists() CMD: '%s' (res: %d, err: %s)", cmd_buf, res, err_buf); - if(EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) == 0) log_msg(LOG_DEBUG, "'%s' table '%s' chain exists", fwc.chain[chain_num].table, fwc.chain[chain_num].to_chain); @@ -503,7 +506,7 @@ fw_dump_rules(const fko_srv_options_t * const opts) cmd_buf, res); /* Expect full success on this */ - if(! EXTCMD_IS_SUCCESS(res)) + if(!EXTCMD_IS_SUCCESS(res)) { log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); got_err++; @@ -541,7 +544,7 @@ fw_dump_rules(const fko_srv_options_t * const opts) cmd_buf, res); /* Expect full success on this */ - if(! EXTCMD_IS_SUCCESS(res)) + if(!EXTCMD_IS_SUCCESS(res)) { log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); got_err++; @@ -587,7 +590,7 @@ delete_all_chains(const fko_srv_options_t * const opts) cmd_buf, res, err_buf); /* Expect full success on this */ - if(! EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) != 0) log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); cmd_ctr++; @@ -611,7 +614,7 @@ delete_all_chains(const fko_srv_options_t * const opts) cmd_buf, res, err_buf); /* Expect full success on this */ - if(! EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) != 0) log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); zero_cmd_buffers(); @@ -630,7 +633,7 @@ delete_all_chains(const fko_srv_options_t * const opts) cmd_buf, res, err_buf); /* Expect full success on this */ - if(! EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) != 0) log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); } @@ -640,7 +643,7 @@ delete_all_chains(const fko_srv_options_t * const opts) static int create_chain(const fko_srv_options_t * const opts, const int chain_num) { - int res = 0; + int res = 0, rv = 0; zero_cmd_buffers(); @@ -660,10 +663,12 @@ create_chain(const fko_srv_options_t * const opts, const int chain_num) cmd_buf, res, err_buf); /* Expect full success on this */ - if(! EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) != 0) log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); + else + rv = 1; - return res; + return rv; } static void @@ -697,14 +702,14 @@ create_fw_chains(const fko_srv_options_t * const opts) /* Create the chain */ - if(! EXTCMD_IS_SUCCESS(create_chain(opts, i))) + if(! create_chain(opts, i)) got_err++; /* Then create the jump rule to that chain if it * doesn't already exist (which is possible) */ if(jump_rule_exists(opts, i) == 0) - if(! EXTCMD_IS_SUCCESS(add_jump_rule(opts, i))) + if(! add_jump_rule(opts, i)) got_err++; } } @@ -949,7 +954,7 @@ create_rule(const fko_srv_options_t * const opts, log_msg(LOG_DEBUG, "create_rule() CMD: '%s' (res: %d, err: %s)", cmd_buf, res, err_buf); - if(EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) == 0) { log_msg(LOG_DEBUG, "create_rule() Rule: '%s' added to %s", fw_rule, fw_chain); res = 1; @@ -1447,7 +1452,8 @@ check_firewall_rules(const fko_srv_options_t * const opts) WANT_STDERR, NO_TIMEOUT, &pid_status, opts); chop_newline(cmd_out); - log_msg(LOG_DEBUG, "check_firewall_rules() CMD: '%s' (res: %d, cmd_out: %s)", + log_msg(LOG_DEBUG, + "check_firewall_rules() CMD: '%s' (res: %d, cmd_out: %s)", cmd_buf, res, cmd_out); if(!EXTCMD_IS_SUCCESS(res)) @@ -1559,7 +1565,7 @@ check_firewall_rules(const fko_srv_options_t * const opts) log_msg(LOG_DEBUG, "check_firewall_rules() CMD: '%s' (res: %d, err: %s)", cmd_buf, res, err_buf); - if(EXTCMD_IS_SUCCESS(res)) + if(strncmp(err_buf, "success", strlen("success")) == 0) { log_msg(LOG_INFO, "Removed rule %s from %s with expire time of %u", rule_num_str, ch[i].to_chain, rule_exp