Skip to content

Commit 04ef8d4

Browse files
committed
feat(firewall): notrack support
1 parent a000db6 commit 04ef8d4

2 files changed

Lines changed: 26 additions & 5 deletions

File tree

‎src/nethsec/firewall/__init__.py‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
from nethsec import utils, objects
1919

2020
PROTOCOLS = ['tcp', 'udp', 'udplite', 'icmp', 'esp', 'ah', 'sctp']
21-
TARGETS = ['ACCEPT', 'DROP', 'REJECT']
21+
TARGETS = ['ACCEPT', 'DROP', 'REJECT', 'NOTRACK']
2222

2323
def add_device_to_zone(uci, device, zone):
2424
'''
@@ -1464,7 +1464,7 @@ def validate_rule(uci, src: str, src_ip: list[str], dest: str, dest_ip: list[str
14641464
dest_ip: a list of destination ip
14651465
proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp"
14661466
dest_port: a list of destination ports, each element cna be be a port number, a comma-separated list of port numbers or a range with `-` (eg. 80-90)
1467-
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP'
1467+
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK'
14681468
service: service name
14691469
ns_src: an object in the form `<database>/<id>`
14701470
ns_dst: an object in the form `<database>/<id>`
@@ -1533,7 +1533,7 @@ def setup_rule(uci, id: str, name: str, src: str, src_ip: list[str], dest: str,
15331533
dest_ip: a list of destination IP addresses
15341534
proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp"
15351535
dest_port: a list of destination ports, each element can be a port number, a comma-separated list of port numbers, or a range with `-` (e.g., 80-90)
1536-
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP'
1536+
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK'
15371537
service: service name
15381538
enabled: if True, rule is enabled; if False, rule is disabled
15391539
log: if True, log traffic
@@ -1680,7 +1680,7 @@ def add_rule(uci, name: str, src: str, src_ip: list[str], dest: str, dest_ip: li
16801680
dest_ip: a list of destination ip
16811681
proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp"
16821682
dest_port: a list of destination ports, each element cna be be a port number, a comma-separated list of port numbers or a range with `-` (eg. 80-90)
1683-
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP'
1683+
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK'
16841684
service: service name
16851685
enabled: if True, rule is enabled, if False, rule is disabled
16861686
log: if True, log traffic
@@ -1728,7 +1728,7 @@ def edit_rule(uci, id: str, name: str, src: str, src_ip: list[str], dest: str, d
17281728
dest_ip: a list of destination ip
17291729
proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp"
17301730
dest_port: a list of destination ports, each element cna be be a port number, a comma-separated list of port numbers or a range with `-` (eg. 80-90)
1731-
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP'
1731+
target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK'
17321732
service: service name
17331733
enabled: if True, rule is enabled, if False, rule is disabled
17341734
log: if True, log traffic

‎tests/test_firewall.py‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -960,6 +960,27 @@ def test_edit_rule(u, mocker):
960960
assert u.get_all("firewall", rid, "proto") == ('tcp',)
961961
assert u.get("firewall", rid, "dest_port") == "80"
962962

963+
def test_add_rule_with_notrack(u, mocker):
964+
mocker.patch('builtins.open', mocker.mock_open(read_data=services_file))
965+
mock_isfile = mocker.patch('os.path.isfile')
966+
mock_isfile.return_value = True
967+
rid = firewall.add_rule(u, 'notrack_rule', 'lan', ['192.168.1.0/24'], 'wan', [], [], '', 'NOTRACK', "*", True, False, [], False)
968+
assert u.get("firewall", rid, "name") == "notrack_rule"
969+
assert u.get("firewall", rid, "target") == "NOTRACK"
970+
assert u.get("firewall", rid, "src") == "lan"
971+
assert u.get("firewall", rid, "dest") == "wan"
972+
assert u.get_all("firewall", rid, "src_ip") == ("192.168.1.0/24",)
973+
assert u.get("firewall", rid, "enabled") == "1"
974+
975+
def test_edit_rule_to_notrack(u, mocker):
976+
mocker.patch('builtins.open', mocker.mock_open(read_data=services_file))
977+
mock_isfile = mocker.patch('os.path.isfile')
978+
mock_isfile.return_value = True
979+
rid = firewall.add_rule(u, 'rule_to_change', 'lan', [], 'wan', [], [], '', 'ACCEPT', "*", True, False, [], False)
980+
assert u.get("firewall", rid, "target") == "ACCEPT"
981+
firewall.edit_rule(u, rid, 'rule_to_change', 'lan', [], 'wan', [], [], '', 'NOTRACK', "*", True, False, [])
982+
assert u.get("firewall", rid, "target") == "NOTRACK"
983+
963984
def test_delete_rule(u):
964985
ids = firewall.list_rule_ids(u)
965986
id_to_delete = ids.pop()

0 commit comments

Comments
 (0)