Blame lenses/iptables.aug

Packit Service a2ae7a
module Iptables =
Packit Service a2ae7a
  autoload xfm
Packit Service a2ae7a
Packit Service a2ae7a
(*
Packit Service a2ae7a
Module: Iptables
Packit Service a2ae7a
   Parse the iptables file format as produced by iptables-save. The
Packit Service a2ae7a
   resulting tree is fairly simple; in particular a rule is simply
Packit Service a2ae7a
   a long list of options/switches and their values (if any)
Packit Service a2ae7a
Packit Service a2ae7a
   This lens should be considered experimental
Packit Service a2ae7a
*)
Packit Service a2ae7a
Packit Service a2ae7a
let comment = Util.comment
Packit Service a2ae7a
let empty = Util.empty
Packit Service a2ae7a
let eol = Util.eol
Packit Service a2ae7a
let spc = Util.del_ws_spc
Packit Service a2ae7a
let dels = Util.del_str
Packit Service a2ae7a
Packit Service a2ae7a
let chain_name = store /[A-Za-z0-9_-]+/
Packit Service a2ae7a
let chain =
Packit Service a2ae7a
  let policy = [ label "policy" . store /ACCEPT|DROP|REJECT|-/ ] in
Packit Service a2ae7a
  let counters_eol = del /[ \t]*(\[[0-9:]+\])?[ \t]*\n/ "\n" in
Packit Service a2ae7a
    [ label "chain" .
Packit Service a2ae7a
        dels ":" . chain_name . spc . policy . counters_eol ]
Packit Service a2ae7a
Packit Service a2ae7a
let param (long:string) (short:string) =
Packit Service a2ae7a
  [ label long .
Packit Service a2ae7a
      spc . del (/--/ . long | /-/ . short) ("-" . short) . spc .
Packit Service a2ae7a
      store /(![ \t]*)?[^ \t\n!-][^ \t\n]*/ ]
Packit Service a2ae7a
Packit Service a2ae7a
(* A negatable parameter, which can either be FTW
Packit Service a2ae7a
     ! --param arg
Packit Service a2ae7a
   or
Packit Service a2ae7a
     --param ! arg
Packit Service a2ae7a
*)
Packit Service a2ae7a
let neg_param (long:string) (short:string) =
Packit Service a2ae7a
  [ label long .
Packit Service a2ae7a
      [ spc . dels "!" . label "not" ]? .
Packit Service a2ae7a
      spc . del (/--/ . long | /-/ . short) ("-" . short) . spc .
Packit Service a2ae7a
      store /(![ \t]*)?[^ \t\n!-][^ \t\n]*/ ]
Packit Service a2ae7a
Packit Service a2ae7a
let tcp_flags =
Packit Service a2ae7a
  let flags = /SYN|ACK|FIN|RST|URG|PSH|ALL|NONE/ in
Packit Service a2ae7a
  let flag_list (name:string) =
Packit Service a2ae7a
    Build.opt_list [label name . store flags] (dels ",") in
Packit Service a2ae7a
  [ label "tcp-flags" .
Packit Service a2ae7a
      spc . dels "--tcp-flags" .
Packit Service a2ae7a
      spc . flag_list "mask" . spc . flag_list "set" ]
Packit Service a2ae7a
Packit Service a2ae7a
(* misses --set-counters *)
Packit Service a2ae7a
let ipt_match =
Packit Service a2ae7a
  let any_key = /[a-zA-Z-][a-zA-Z0-9-]+/ -
Packit Service a2ae7a
    /protocol|source|destination|jump|goto|in-interface|out-interface|fragment|match|tcp-flags/ in
Packit Service a2ae7a
  let any_val = /([^" \t\n!-][^ \t\n]*)|"([^"\\\n]|\\\\.)*"/ in
Packit Service a2ae7a
  let any_param =
Packit Service a2ae7a
    [ [ spc . dels "!" . label "not" ]? .
Packit Service a2ae7a
      spc . dels "--" . key any_key . (spc . store any_val)? ] in
Packit Service a2ae7a
    (neg_param "protocol" "p"
Packit Service a2ae7a
    |neg_param "source" "s"
Packit Service a2ae7a
    |neg_param "destination" "d"
Packit Service a2ae7a
    |param "jump" "j"
Packit Service a2ae7a
    |param "goto" "g"
Packit Service a2ae7a
    |neg_param "in-interface" "i"
Packit Service a2ae7a
    |neg_param "out-interface" "o"
Packit Service a2ae7a
    |neg_param "fragment" "f"
Packit Service a2ae7a
    |param "match" "m"
Packit Service a2ae7a
    |tcp_flags
Packit Service a2ae7a
    |any_param)*
Packit Service a2ae7a
Packit Service a2ae7a
let chain_action (n:string) (o:string) =
Packit Service a2ae7a
    [ label n .
Packit Service a2ae7a
        del (/--/ . n | o) o .
Packit Service a2ae7a
        spc . chain_name . ipt_match . eol ]
Packit Service a2ae7a
Packit Service a2ae7a
let table_rule = chain_action "append" "-A"
Packit Service a2ae7a
	       | chain_action "insert" "-I"
Packit Service a2ae7a
	       | empty
Packit Service a2ae7a
Packit Service a2ae7a
Packit Service a2ae7a
let table = [ del /\*/ "*" . label "table" . store /[a-z]+/ . eol .
Packit Service a2ae7a
                (chain|comment|table_rule)* .
Packit Service a2ae7a
                dels "COMMIT" . eol ]
Packit Service a2ae7a
Packit Service a2ae7a
let lns = (comment|empty|table)*
Packit Service a2ae7a
let xfm = transform lns (incl "/etc/sysconfig/iptables"
Packit Service a2ae7a
                       . incl "/etc/sysconfig/iptables.save"
Packit Service a2ae7a
                       . incl "/etc/iptables-save")