|
18 | 18 | # To avoid: <...>/NaCl/type_processors/conntrack.py:1: RuntimeWarning: Parent module '<...>/NaCl/type_processors' not found while handling absolute import |
19 | 19 |
|
20 | 20 | from NaCl import exit_NaCl, NaCl_exception, Typed |
21 | | -from shared import TEMPLATE_KEY_NAME, TCP, UDP, ICMP |
| 21 | +from shared import TEMPLATE_KEY_NAME, TCP, UDP, ICMP, TRUE |
22 | 22 |
|
23 | 23 | # -------------------- CONSTANTS Conntrack -------------------- |
24 | 24 |
|
25 | | -TYPE_CONNTRACK = "conntrack" |
| 25 | +TYPE_CONNTRACK = "conntrack" |
26 | 26 |
|
27 | 27 | # ---- Conntrack keys ---- |
28 | 28 |
|
29 | | -CONNTRACK_KEY_LIMIT = "limit" |
30 | | -CONNTRACK_KEY_RESERVE = "reserve" |
31 | | -CONNTRACK_KEY_TIMEOUT = "timeout" |
| 29 | +CONNTRACK_KEY_LIMIT = "limit" |
| 30 | +CONNTRACK_KEY_RESERVE = "reserve" |
| 31 | +CONNTRACK_KEY_STATEFUL_TCP = "stateful_tcp" |
| 32 | +CONNTRACK_KEY_TIMEOUT = "timeout" |
32 | 33 |
|
33 | 34 | PREDEFINED_CONNTRACK_KEYS = [ |
34 | | - CONNTRACK_KEY_LIMIT, |
35 | | - CONNTRACK_KEY_RESERVE, |
36 | | - CONNTRACK_KEY_TIMEOUT |
| 35 | + CONNTRACK_KEY_LIMIT, |
| 36 | + CONNTRACK_KEY_RESERVE, |
| 37 | + CONNTRACK_KEY_STATEFUL_TCP, |
| 38 | + CONNTRACK_KEY_TIMEOUT |
37 | 39 | ] |
38 | 40 |
|
39 | 41 | CONNTRACK_TIMEOUT_KEY_ESTABLISHED = "established" |
40 | 42 | CONNTRACK_TIMEOUT_KEY_UNCONFIRMED = "unconfirmed" |
41 | 43 | CONNTRACK_TIMEOUT_KEY_CONFIRMED = "confirmed" |
42 | 44 |
|
43 | 45 | PREDEFINED_CONNTRACK_TIMEOUT_KEYS = [ |
44 | | - CONNTRACK_TIMEOUT_KEY_ESTABLISHED, |
45 | | - CONNTRACK_TIMEOUT_KEY_UNCONFIRMED, |
46 | | - CONNTRACK_TIMEOUT_KEY_CONFIRMED |
| 46 | + CONNTRACK_TIMEOUT_KEY_ESTABLISHED, |
| 47 | + CONNTRACK_TIMEOUT_KEY_UNCONFIRMED, |
| 48 | + CONNTRACK_TIMEOUT_KEY_CONFIRMED |
47 | 49 | ] |
48 | 50 |
|
49 | 51 | PREDEFINED_CONNTRACK_TIMEOUT_INNER_KEYS = [ |
50 | | - TCP, |
51 | | - UDP, |
52 | | - ICMP |
| 52 | + TCP, |
| 53 | + UDP, |
| 54 | + ICMP |
53 | 55 | ] |
54 | 56 |
|
55 | 57 | # -------------------- TEMPLATE KEYS (pystache) -------------------- |
56 | 58 |
|
57 | 59 | TEMPLATE_KEY_CONNTRACKS = "conntracks" |
58 | 60 |
|
59 | | -TEMPLATE_KEY_CONNTRACK_TIMEOUTS = "timeouts" |
60 | | -TEMPLATE_KEY_CONNTRACK_TYPE = "type" |
| 61 | +TEMPLATE_KEY_CONNTRACK_LIMIT = CONNTRACK_KEY_LIMIT |
| 62 | +TEMPLATE_KEY_CONNTRACK_RESERVE = CONNTRACK_KEY_RESERVE |
| 63 | +TEMPLATE_KEY_CONNTRACK_STATEFUL = "stateful" |
| 64 | +TEMPLATE_KEY_CONNTRACK_TIMEOUTS = "timeouts" |
| 65 | +TEMPLATE_KEY_CONNTRACK_TYPE = "type" |
61 | 66 |
|
62 | 67 | # -------------------- class Conntrack -------------------- |
63 | 68 |
|
64 | 69 | class Conntrack(Typed): |
65 | | - def __init__(self, nacl_state, idx, name, ctx, base_type, type_t): |
66 | | - super(Conntrack, self).__init__(nacl_state, idx, name, ctx, base_type, type_t) |
67 | | - |
68 | | - def add_conntrack(self): |
69 | | - timeout = self.members.get(CONNTRACK_KEY_TIMEOUT) |
70 | | - timeouts = [] |
71 | | - |
72 | | - if timeout is not None: |
73 | | - class_name = self.get_class_name() |
74 | | - |
75 | | - if not isinstance(timeout, dict): |
76 | | - exit_NaCl(self.ctx, "Invalid " + CONNTRACK_KEY_TIMEOUT + " value of " + class_name + " (needs to be an object)") |
77 | | - |
78 | | - for conntrack_type in timeout: |
79 | | - t = timeout.get(conntrack_type) |
80 | | - |
81 | | - if not isinstance(t, dict): |
82 | | - exit_NaCl(self.ctx, "Invalid " + conntrack_type + " value of " + class_name + " (needs to be an object)") |
83 | | - |
84 | | - tcp_timeout = t.get(TCP) |
85 | | - udp_timeout = t.get(UDP) |
86 | | - icmp_timeout = t.get(ICMP) |
87 | | - |
88 | | - timeouts.append({ |
89 | | - TEMPLATE_KEY_CONNTRACK_TYPE: conntrack_type, |
90 | | - TCP: tcp_timeout, |
91 | | - UDP: udp_timeout, |
92 | | - ICMP: icmp_timeout |
93 | | - }) |
94 | | - |
95 | | - self.nacl_state.append_to_pystache_data_list(TEMPLATE_KEY_CONNTRACKS, { |
96 | | - TEMPLATE_KEY_NAME: self.name, |
97 | | - CONNTRACK_KEY_LIMIT: self.members.get(CONNTRACK_KEY_LIMIT), |
98 | | - CONNTRACK_KEY_RESERVE: self.members.get(CONNTRACK_KEY_RESERVE), |
99 | | - TEMPLATE_KEY_CONNTRACK_TIMEOUTS: timeouts |
100 | | - }) |
101 | | - |
102 | | - # Overriding |
103 | | - def validate_dictionary_key(self, key, parent_key, level, value_ctx): |
104 | | - class_name = self.get_class_name() |
105 | | - |
106 | | - if level == 1: |
107 | | - if key not in PREDEFINED_CONNTRACK_KEYS: |
108 | | - exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key) |
109 | | - return |
110 | | - |
111 | | - if parent_key == "": |
112 | | - exit_NaCl(value_ctx, "Internal error: Parent key of " + key + " has not been given") |
113 | | - |
114 | | - if level == 2: |
115 | | - if parent_key == CONNTRACK_KEY_TIMEOUT and key not in PREDEFINED_CONNTRACK_TIMEOUT_KEYS: |
116 | | - exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key + " in " + self.name + "." + parent_key) |
117 | | - elif level == 3: |
118 | | - if parent_key not in PREDEFINED_CONNTRACK_TIMEOUT_KEYS: |
119 | | - exit_NaCl(value_ctx, "Internal error: Invalid parent key " + parent_key + " of " + key) |
120 | | - if key not in PREDEFINED_CONNTRACK_TIMEOUT_INNER_KEYS: |
121 | | - exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key) |
122 | | - else: |
123 | | - exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key) |
124 | | - |
125 | | - # Overriding |
126 | | - def resolve_dictionary_value(self, dictionary, key, value): |
127 | | - # Add found value |
128 | | - dictionary[key] = self.nacl_state.transpile_value(value) |
129 | | - |
130 | | - # Main processing method |
131 | | - def process(self): |
132 | | - if self.res is None: |
133 | | - # Then process |
134 | | - |
135 | | - self.process_ctx() |
136 | | - self.process_assignments() |
137 | | - self.add_conntrack() |
138 | | - |
139 | | - self.res = self.members |
140 | | - |
141 | | - return self.res |
| 70 | + def __init__(self, nacl_state, idx, name, ctx, base_type, type_t): |
| 71 | + super(Conntrack, self).__init__(nacl_state, idx, name, ctx, base_type, type_t) |
| 72 | + |
| 73 | + def add_conntrack(self): |
| 74 | + timeout = self.members.get(CONNTRACK_KEY_TIMEOUT) |
| 75 | + timeouts = [] |
| 76 | + |
| 77 | + if timeout is not None: |
| 78 | + class_name = self.get_class_name() |
| 79 | + |
| 80 | + if not isinstance(timeout, dict): |
| 81 | + exit_NaCl(self.ctx, "Invalid " + CONNTRACK_KEY_TIMEOUT + " value of " + class_name + " (needs to be an object)") |
| 82 | + |
| 83 | + for conntrack_type in timeout: |
| 84 | + t = timeout.get(conntrack_type) |
| 85 | + |
| 86 | + if not isinstance(t, dict): |
| 87 | + exit_NaCl(self.ctx, "Invalid " + conntrack_type + " value of " + class_name + " (needs to be an object)") |
| 88 | + |
| 89 | + tcp_timeout = t.get(TCP) |
| 90 | + udp_timeout = t.get(UDP) |
| 91 | + icmp_timeout = t.get(ICMP) |
| 92 | + |
| 93 | + timeouts.append({ |
| 94 | + TEMPLATE_KEY_CONNTRACK_TYPE: conntrack_type, |
| 95 | + TCP: tcp_timeout, |
| 96 | + UDP: udp_timeout, |
| 97 | + ICMP: icmp_timeout |
| 98 | + }) |
| 99 | + |
| 100 | + stateful = False |
| 101 | + stateful_tcp = self.members.get(CONNTRACK_KEY_STATEFUL_TCP) |
| 102 | + if stateful_tcp is not None and stateful_tcp == TRUE: |
| 103 | + stateful = True |
| 104 | + |
| 105 | + self.nacl_state.append_to_pystache_data_list(TEMPLATE_KEY_CONNTRACKS, { |
| 106 | + TEMPLATE_KEY_NAME: self.name, |
| 107 | + TEMPLATE_KEY_CONNTRACK_LIMIT: self.members.get(CONNTRACK_KEY_LIMIT), |
| 108 | + TEMPLATE_KEY_CONNTRACK_RESERVE: self.members.get(CONNTRACK_KEY_RESERVE), |
| 109 | + TEMPLATE_KEY_CONNTRACK_STATEFUL: stateful, |
| 110 | + TEMPLATE_KEY_CONNTRACK_TIMEOUTS: timeouts |
| 111 | + }) |
| 112 | + |
| 113 | + # Overriding |
| 114 | + def validate_dictionary_key(self, key, parent_key, level, value_ctx): |
| 115 | + class_name = self.get_class_name() |
| 116 | + |
| 117 | + if level == 1: |
| 118 | + if key not in PREDEFINED_CONNTRACK_KEYS: |
| 119 | + exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key) |
| 120 | + return |
| 121 | + |
| 122 | + if parent_key == "": |
| 123 | + exit_NaCl(value_ctx, "Internal error: Parent key of " + key + " has not been given") |
| 124 | + |
| 125 | + if level == 2: |
| 126 | + if parent_key == CONNTRACK_KEY_TIMEOUT and key not in PREDEFINED_CONNTRACK_TIMEOUT_KEYS: |
| 127 | + exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key + " in " + self.name + "." + parent_key) |
| 128 | + elif level == 3: |
| 129 | + if parent_key not in PREDEFINED_CONNTRACK_TIMEOUT_KEYS: |
| 130 | + exit_NaCl(value_ctx, "Internal error: Invalid parent key " + parent_key + " of " + key) |
| 131 | + if key not in PREDEFINED_CONNTRACK_TIMEOUT_INNER_KEYS: |
| 132 | + exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key) |
| 133 | + else: |
| 134 | + exit_NaCl(value_ctx, "Invalid " + class_name + " member " + key) |
| 135 | + |
| 136 | + # Overriding |
| 137 | + def resolve_dictionary_value(self, dictionary, key, value): |
| 138 | + # Add found value |
| 139 | + dictionary[key] = self.nacl_state.transpile_value(value) |
| 140 | + |
| 141 | + # Main processing method |
| 142 | + def process(self): |
| 143 | + if self.res is None: |
| 144 | + # Then process |
| 145 | + |
| 146 | + self.process_ctx() |
| 147 | + self.process_assignments() |
| 148 | + self.add_conntrack() |
| 149 | + |
| 150 | + self.res = self.members |
| 151 | + |
| 152 | + return self.res |
142 | 153 |
|
143 | 154 | # < class Conntrack |
144 | 155 |
|
145 | 156 | def create_connstrack_pystache_lists(nacl_state): |
146 | | - nacl_state.create_pystache_data_lists([ |
| 157 | + nacl_state.create_pystache_data_lists([ |
147 | 158 | TEMPLATE_KEY_CONNTRACKS |
148 | | - ]) |
| 159 | + ]) |
149 | 160 |
|
150 | 161 | def init(nacl_state): |
151 | 162 | # print "Init conntrack: Conntrack" |
|
0 commit comments