Switch to nft interface by default

This commit is contained in:
2025-10-14 15:34:23 +03:00
parent 302e24b8df
commit a3d03d2133
8 changed files with 93 additions and 37 deletions
+28 -2
View File
@@ -1,9 +1,35 @@
name: iptables
description: userspace CLI program used to configure the Linux packet filtering ruleset
version: 1.8.11
revision: 2
revision: 3
url: https://www.netfilter.org/projects/iptables/index.html
license: GPL2-only
architecture: any
depends: ["bash"]
type: source
keep:
- etc/ethertypes
- etc/iptables/iptables.rules
- etc/iptables/ip6tables.rules
depends:
- libnetfilter_conntrack
- libnfnetlink
- libnftnl
- libpcap
- nftables
downloads:
- url: https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz
extract_to: ${BPM_SOURCE}
extract_strip_components: 1
checksum: d87303d55ef8c92bcad4dd3f978b26d272013642b029425775f5bad1009fe7b2
split_packages:
- name: iptables
conflicts:
- iptables-legacy
- name: iptables-legacy
depends:
- libnetfilter_conntrack
- libnfnetlink
- libnftnl
- libpcap
conflicts:
- iptables
+6
View File
@@ -0,0 +1,6 @@
name: iptables
description: IPv6 Packet Filtering Framework
type: simple
start_cmd: /etc/esvm/scripts/ip6tables.sh
stop_cmd: /etc/esvm/scripts/iptables-flush.sh -6
exit_method: stop_command
+5
View File
@@ -0,0 +1,5 @@
#!/bin/sh
[ ! -e /etc/iptables/ip6tables.rules ] && exit 0
ip6tables-restore -w 3 /etc/iptables/ip6tables.rules || exit 1
exec ip6tables pause
+18 -11
View File
@@ -1,14 +1,21 @@
# Flush iptables (Code from archlinux)
iptables=ip$1tables
if ! type -p "$iptables" &>/dev/null; then
echo "error: invalid argument"
exit 1
#!/bin/sh
# Usage: iptables-flush [-6]
iptables=/usr/sbin/iptables
tables="filter mangle raw"
if [ "$1" = "-6" ]; then
iptables=/usr/bin/ip6tables
else
# Only ipv4 has a nat table
tables="$tables nat"
fi
while read -r table; do
tables+=("/usr/share/iptables/empty-$table.rules")
done <"/proc/net/ip$1_tables_names"
for table in ${tables}; do
$iptables -t "$table" -F
$iptables -t "$table" -X
done
if (( ${#tables[*]} )); then
cat "${tables[@]}" | "$iptables-restore"
fi
for chain in INPUT FORWARD OUTPUT; do
$iptables -P "$chain" ACCEPT
done
+1 -1
View File
@@ -1,6 +1,6 @@
name: iptables
description: IPv4 Packet Filtering Framework
type: simple
start_cmd: /usr/sbin/iptables-restore /etc/iptables/iptables.rules
start_cmd: /etc/esvm/scripts/iptables.sh
stop_cmd: /etc/esvm/scripts/iptables-flush.sh
exit_method: stop_command
+5
View File
@@ -0,0 +1,5 @@
#!/bin/sh
[ ! -e /etc/iptables/iptables.rules ] && exit 0
iptables-restore -w 3 /etc/iptables/iptables.rules || exit 1
exec iptables pause
+1 -1
View File
@@ -3,7 +3,7 @@
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -p icmp -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -j REJECT --reject-with tcp-reset
-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable
+29 -22
View File
@@ -2,40 +2,47 @@
# BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE
# BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT
DOWNLOAD="https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz"
FILENAME="${DOWNLOAD##*/}"
# The prepare function is executed in the root of the temp directory
# This function is used for downloading files and putting them into the correct location
prepare() {
wget "$DOWNLOAD"
tar -xvf "$FILENAME" --strip-components=1 -C "$BPM_SOURCE"
}
# The build function is executed in the source directory
# This function is used to compile the source code
build() {
./configure --prefix=/usr \
--disable-nftables \
--enable-libipq
./configure --prefix=/usr --enable-bpf-compiler --enable-devel --enable-libipq --enable-shared
make
}
# The package function is executed in the source directory
# This function is used to move the compiled files into the output directory
package() {
package_iptables() {
make DESTDIR="$BPM_OUTPUT" install
# Link to xtables-nft-multi
for x in {arp,eb,ip,ip6}tables{,-restore,-save}; do
ln -sf xtables-nft-multi "$BPM_OUTPUT"/usr/sbin/"$x"
done
ln -sf /usr/sbin/xtables-nft-multi "$BPM_OUTPUT"/usr/bin/iptables-xml
# Install esvm service
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
# Install iptables rules
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
# Install package license
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
}
package_iptables-legacy() {
make DESTDIR="$BPM_OUTPUT" install
# Install esvm service
install -Dm755 "$BPM_WORKDIR"/iptables-flush.sh "$BPM_OUTPUT"/etc/esvm/scripts/iptables-flush.sh
install -Dm644 "$BPM_WORKDIR"/iptables.esv "$BPM_OUTPUT"/etc/esvm/services/iptables.esv
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
# Rules from Arch Linux
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/iptables.rules
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/ip6tables.rules
install -Dm644 "$BPM_WORKDIR"/rules/*.rules -t "$BPM_OUTPUT"/usr/share/iptables/
ln -srt "$BPM_OUTPUT"/etc/iptables "$BPM_OUTPUT"/usr/share/iptables/{empty,simple_firewall}.rules
# Install iptables rules
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
# Install package license
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/LICENSE
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
}