Update iptables esvm service

This commit is contained in:
2025-09-24 14:53:40 +03:00
parent ec69aaec16
commit 302e24b8df
5 changed files with 20 additions and 34 deletions
+1
View File
@@ -1,6 +1,7 @@
name: iptables
description: userspace CLI program used to configure the Linux packet filtering ruleset
version: 1.8.11
revision: 2
url: https://www.netfilter.org/projects/iptables/index.html
license: GPL2-only
architecture: any
+14
View File
@@ -0,0 +1,14 @@
# Flush iptables (Code from archlinux)
iptables=ip$1tables
if ! type -p "$iptables" &>/dev/null; then
echo "error: invalid argument"
exit 1
fi
while read -r table; do
tables+=("/usr/share/iptables/empty-$table.rules")
done <"/proc/net/ip$1_tables_names"
if (( ${#tables[*]} )); then
cat "${tables[@]}" | "$iptables-restore"
fi
+4 -3
View File
@@ -1,5 +1,6 @@
name: iptables
description: IPv4 Packet Filtering Framework
type: background
start_cmd: /etc/esvm/scripts/iptables.sh
exit_method: kill
type: simple
start_cmd: /usr/sbin/iptables-restore /etc/iptables/iptables.rules
stop_cmd: /etc/esvm/scripts/iptables-flush.sh
exit_method: stop_command
-30
View File
@@ -1,30 +0,0 @@
#!/bin/bash
stop() {
# Flush iptables (Code from archlinux)
iptables=ip$1tables
if ! type -p "$iptables" &>/dev/null; then
echo "error: invalid argument"
exit 1
fi
while read -r table; do
tables+=("/usr/share/iptables/empty-$table.rules")
done <"/proc/net/ip$1_tables_names"
if (( ${#tables[*]} )); then
cat "${tables[@]}" | "$iptables-restore"
fi
# Clear the trap
trap - SIGINT SIGTERM
kill -- -$(pgrep iptables.sh)
}
/usr/sbin/iptables-restore /etc/iptables/iptables.rules
# Run stop function when SIGINT or SIGTERM signals are caught
trap "stop $1" SIGINT SIGTERM
sleep infinity
+1 -1
View File
@@ -27,8 +27,8 @@ package() {
make DESTDIR="$BPM_OUTPUT" install
# Install esvm service
install -Dm755 "$BPM_WORKDIR"/iptables-flush.sh "$BPM_OUTPUT"/etc/esvm/scripts/iptables-flush.sh
install -Dm644 "$BPM_WORKDIR"/iptables.esv "$BPM_OUTPUT"/etc/esvm/services/iptables.esv
install -Dm755 "$BPM_WORKDIR"/iptables.sh "$BPM_OUTPUT"/etc/esvm/scripts/iptables.sh
# Rules from Arch Linux
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/iptables.rules