Switch to nft interface by default

This commit is contained in:
2025-10-14 15:34:23 +03:00
parent 302e24b8df
commit a3d03d2133
8 changed files with 93 additions and 37 deletions
+29 -22
View File
@@ -2,40 +2,47 @@
# BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE
# BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT
DOWNLOAD="https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz"
FILENAME="${DOWNLOAD##*/}"
# The prepare function is executed in the root of the temp directory
# This function is used for downloading files and putting them into the correct location
prepare() {
wget "$DOWNLOAD"
tar -xvf "$FILENAME" --strip-components=1 -C "$BPM_SOURCE"
}
# The build function is executed in the source directory
# This function is used to compile the source code
build() {
./configure --prefix=/usr \
--disable-nftables \
--enable-libipq
./configure --prefix=/usr --enable-bpf-compiler --enable-devel --enable-libipq --enable-shared
make
}
# The package function is executed in the source directory
# This function is used to move the compiled files into the output directory
package() {
package_iptables() {
make DESTDIR="$BPM_OUTPUT" install
# Link to xtables-nft-multi
for x in {arp,eb,ip,ip6}tables{,-restore,-save}; do
ln -sf xtables-nft-multi "$BPM_OUTPUT"/usr/sbin/"$x"
done
ln -sf /usr/sbin/xtables-nft-multi "$BPM_OUTPUT"/usr/bin/iptables-xml
# Install esvm service
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
# Install iptables rules
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
# Install package license
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
}
package_iptables-legacy() {
make DESTDIR="$BPM_OUTPUT" install
# Install esvm service
install -Dm755 "$BPM_WORKDIR"/iptables-flush.sh "$BPM_OUTPUT"/etc/esvm/scripts/iptables-flush.sh
install -Dm644 "$BPM_WORKDIR"/iptables.esv "$BPM_OUTPUT"/etc/esvm/services/iptables.esv
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
# Rules from Arch Linux
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/iptables.rules
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/ip6tables.rules
install -Dm644 "$BPM_WORKDIR"/rules/*.rules -t "$BPM_OUTPUT"/usr/share/iptables/
ln -srt "$BPM_OUTPUT"/etc/iptables "$BPM_OUTPUT"/usr/share/iptables/{empty,simple_firewall}.rules
# Install iptables rules
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
# Install package license
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/LICENSE
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
}