From 6bcebe565c9d2f691ba5f6d032ffeca379416973 Mon Sep 17 00:00:00 2001 From: Damien Stuart Date: Sun, 29 Aug 2010 01:32:04 +0000 Subject: [PATCH] Made fw_cleanup not remove rules from the expired rule set. Added code to read in any existing expired rules into the rule_map at startup. git-svn-id: file:///home/mbr/svn/fwknop/trunk@286 510a4753-2344-4c79-9c09-4d669213fbeb --- server/fw_util_ipfw.c | 73 +++++++++++++++++++++++++++++++++++++++++-- server/fw_util_ipfw.h | 1 + server/pcap_capture.c | 2 +- 3 files changed, 72 insertions(+), 4 deletions(-) diff --git a/server/fw_util_ipfw.c b/server/fw_util_ipfw.c index b93d8629..a8601db3 100644 --- a/server/fw_util_ipfw.c +++ b/server/fw_util_ipfw.c @@ -136,7 +136,9 @@ fw_config_init(fko_srv_options_t *opts) void fw_initialize(fko_srv_options_t *opts) { - int res = 0; + int res = 0; + unsigned short curr_rule; + char *ndx; /* For now, we just call fw_cleanup to start with clean slate. */ @@ -201,8 +203,67 @@ fw_initialize(fko_srv_options_t *opts) fwc.expire_set_num); else log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, err_buf); + + /* Now read the expire set in case there are existing + * rules to track. + */ + zero_cmd_buffers(); + + snprintf(cmd_buf, CMD_BUFSIZE-1, "%s " IPFW_LIST_EXP_SET_RULES_ARGS, + opts->fw_config->fw_command, + fwc.expire_set_num + ); + + res = run_extcmd(cmd_buf, cmd_out, STANDARD_CMD_OUT_BUFSIZE, 0); + + if(!EXTCMD_IS_SUCCESS(res)) + { + log_msg(LOG_ERR, "Error %i from cmd:'%s': %s", res, cmd_buf, cmd_out); + return; + } + + if(opts->verbose > 2) + log_msg(LOG_INFO, "RES=%i, CMD_BUF: %s\nRULES LIST: %s", res, cmd_buf, cmd_out); + + /* Find the first "# DISABLED" string (if any). + */ + ndx = strstr(cmd_out, "# DISABLED "); + + /* Assume no disabled rules if we did not see the string. + */ + if(ndx == NULL) + return; + + /* Otherwise we walk each line to pull the rule number and + * set the appropriate rule map entries. + */ + while(ndx != NULL) + { + /* Skip over the DISABLED string to the rule num. + */ + ndx += 11; + + if(isdigit(*ndx)) + { + curr_rule = atoi(ndx); + + if(curr_rule >= fwc.start_rule_num + && curr_rule < fwc.start_rule_num + fwc.max_rules) + { + fwc.rule_map[curr_rule - fwc.start_rule_num] = RULE_EXPIRED; + fwc.total_rules++; + } + } + else + log_msg(LOG_WARNING, "fw_initialize: No rule number found where expected."); + + /* Find the next "# DISABLED" string (if any). + */ + ndx = strstr(ndx, "# DISABLED "); + } } + int fw_cleanup(void) { @@ -230,9 +291,13 @@ fw_cleanup(void) } } +/* --DSS Keep expired rule list so any existing established + are not lost */ +#if 0 + if(fwc.expire_set_num > 0) { - /* Create the set delete command for active rules + /* Create the set delete command for expired rules */ snprintf(cmd_buf, CMD_BUFSIZE-1, "%s " IPFW_DEL_RULE_SET_ARGS, fwc.fw_command, @@ -249,10 +314,12 @@ fw_cleanup(void) got_err++; } } +#endif /* Free the rule map. */ - free(fwc.rule_map); + if(fwc.rule_map != NULL) + free(fwc.rule_map); return(got_err); } diff --git a/server/fw_util_ipfw.h b/server/fw_util_ipfw.h index f1738eb4..45862129 100644 --- a/server/fw_util_ipfw.h +++ b/server/fw_util_ipfw.h @@ -44,6 +44,7 @@ enum { #define IPFW_DEL_RULE_SET_ARGS "delete set %u" #define IPFW_LIST_RULES_ARGS "-d -S -T set %u list" #define IPFW_LIST_SET_RULES_ARGS "set %u list" +#define IPFW_LIST_EXP_SET_RULES_ARGS "-S set %u list" #define IPFW_LIST_SET_DYN_RULES_ARGS "-d set %u list" void purge_expired_rules(fko_srv_options_t *opts); diff --git a/server/pcap_capture.c b/server/pcap_capture.c index a8b0cc30..bd36e6c7 100644 --- a/server/pcap_capture.c +++ b/server/pcap_capture.c @@ -271,7 +271,7 @@ pcap_capture(fko_srv_options_t *opts) /* Purge expired rules that no longer have any corresponding * dynamic rules. */ - if(opts->fw_config->total_rule > 0) + if(opts->fw_config->total_rules > 0) { time(&now); if(opts->fw_config->last_purge < (now - opts->fw_config->purge_interval))