From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: development@lists.ipfire.org Subject: Re: [PATCH 1/2] Refactor "get_available_network_zones", move to network-functions.pl Date: Mon, 25 Jan 2021 19:35:33 +0000 Message-ID: <1231177C-6100-4DAF-8058-EBE8BC7BEAC3@ipfire.org> In-Reply-To: <20210117142004.984-1-hofmann@leo-andres.de> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============5674476431778421771==" List-Id: --===============5674476431778421771== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hey Leo, Thank you very much for working on this. This is an outstanding patch showing us how messy some of the code has become. I have merged it and I am looking forward to more to get a much cleaner code = base. Best, -Michael > On 17 Jan 2021, at 14:20, Leo-Andres Hofmann wrot= e: >=20 > This function nicely translates the ethernet/settings "CONFIG_TYPE" > into a list of available zones. Therefore it should be more accessible! >=20 > Signed-off-by: Leo-Andres Hofmann > --- > config/cfgroot/ids-functions.pl | 39 ++--------------------------- > config/cfgroot/network-functions.pl | 36 ++++++++++++++++++++++++++ > config/suricata/convert-snort | 3 ++- > html/cgi-bin/ids.cgi | 3 ++- > 4 files changed, 42 insertions(+), 39 deletions(-) >=20 > diff --git a/config/cfgroot/ids-functions.pl b/config/cfgroot/ids-functions= .pl > index d45e1c70a..2fdae4a7a 100644 > --- a/config/cfgroot/ids-functions.pl > +++ b/config/cfgroot/ids-functions.pl > @@ -24,6 +24,7 @@ > package IDS; >=20 > require '/var/ipfire/general-functions.pl'; > +require "${General::swroot}/network-functions.pl"; >=20 > # Location where all config and settings files are stored. > our $settingsdir =3D "${General::swroot}/suricata"; > @@ -410,42 +411,6 @@ sub _store_error_message ($) { > &set_ownership("$storederrorfile"); > } >=20 > -# > -## Function to get a list of all available network zones. > -# > -sub get_available_network_zones () { > - # Get netsettings. > - my %netsettings =3D (); > - &General::readhash("${General::swroot}/ethernet/settings", \%netsettings); > - > - # Obtain the configuration type from the netsettings hash. > - my $config_type =3D $netsettings{'CONFIG_TYPE'}; > - > - # Hash which contains the conversation from the config mode > - # to the existing network interface names. They are stored like > - # an array. > - # > - # Mode "0" red is a modem and green > - # Mode "1" red is a netdev and green > - # Mode "2" red, green and orange > - # Mode "3" red, green and blue > - # Mode "4" red, green, blue, orange > - my %config_type_to_interfaces =3D ( > - "0" =3D> [ "red", "green" ], > - "1" =3D> [ "red", "green" ], > - "2" =3D> [ "red", "green", "orange" ], > - "3" =3D> [ "red", "green", "blue" ], > - "4" =3D> [ "red", "green", "blue", "orange" ] > - ); > - > - # Obtain and dereference the corresponding network interaces based on the= read > - # network config type. > - my @network_zones =3D @{ $config_type_to_interfaces{$config_type} }; > - > - # Return them. > - return @network_zones; > -} > - > # > ## Function to check if the IDS is running. > # > @@ -613,7 +578,7 @@ sub generate_home_net_file() { > &General::readhash("${General::swroot}/ethernet/settings", \%netsettings); >=20 > # Get available network zones. > - my @network_zones =3D &get_available_network_zones(); > + my @network_zones =3D &Network::get_available_network_zones(); >=20 > # Temporary array to store network address and prefix of the configured > # networks. > diff --git a/config/cfgroot/network-functions.pl b/config/cfgroot/network-f= unctions.pl > index 3d7f04743..622731f96 100644 > --- a/config/cfgroot/network-functions.pl > +++ b/config/cfgroot/network-functions.pl > @@ -444,6 +444,42 @@ sub get_mac_by_name($) { > return $mac; > } >=20 > +# > +## Function to get a list of all available network zones. > +# > +sub get_available_network_zones () { > + # Get netsettings. > + my %netsettings =3D (); > + &General::readhash("${General::swroot}/ethernet/settings", \%netsettings); > + > + # Obtain the configuration type from the netsettings hash. > + my $config_type =3D $netsettings{'CONFIG_TYPE'}; > + > + # Hash which contains the conversation from the config mode > + # to the existing network interface names. They are stored like > + # an array. > + # > + # Mode "0" red is a modem and green > + # Mode "1" red is a netdev and green > + # Mode "2" red, green and orange > + # Mode "3" red, green and blue > + # Mode "4" red, green, blue, orange > + my %config_type_to_interfaces =3D ( > + "0" =3D> [ "red", "green" ], > + "1" =3D> [ "red", "green" ], > + "2" =3D> [ "red", "green", "orange" ], > + "3" =3D> [ "red", "green", "blue" ], > + "4" =3D> [ "red", "green", "blue", "orange" ] > + ); > + > + # Obtain and dereference the corresponding network interaces based on the= read > + # network config type. > + my @network_zones =3D @{ $config_type_to_interfaces{$config_type} }; > + > + # Return them. > + return @network_zones; > +} > + > 1; >=20 > # Remove the next line to enable the testsuite > diff --git a/config/suricata/convert-snort b/config/suricata/convert-snort > index 3e938137e..7d75233b4 100644 > --- a/config/suricata/convert-snort > +++ b/config/suricata/convert-snort > @@ -23,6 +23,7 @@ use strict; >=20 > require '/var/ipfire/general-functions.pl'; > require "${General::swroot}/ids-functions.pl"; > +require "${General::swroot}/network-functions.pl"; >=20 > # Snort settings file, which contains the settings from the WUI. > my $snort_settings_file =3D "${General::swroot}/snort/settings"; > @@ -129,7 +130,7 @@ my %rulessettings =3D ( > ); >=20 > # Get all available network zones. > -my @network_zones =3D &IDS::get_available_network_zones(); > +my @network_zones =3D &Network::get_available_network_zones(); >=20 > # Read-in snort settings file. > &General::readhash("$snort_settings_file", \%snortsettings); > diff --git a/html/cgi-bin/ids.cgi b/html/cgi-bin/ids.cgi > index bc31a341f..83d5f52ba 100644 > --- a/html/cgi-bin/ids.cgi > +++ b/html/cgi-bin/ids.cgi > @@ -29,6 +29,7 @@ require '/var/ipfire/general-functions.pl'; > require "${General::swroot}/lang.pl"; > require "${General::swroot}/header.pl"; > require "${General::swroot}/ids-functions.pl"; > +require "${General::swroot}/network-functions.pl"; >=20 > my %color =3D (); > my %mainsettings =3D (); > @@ -47,7 +48,7 @@ my %ignored=3D(); >=20 > # Get the available network zones, based on the config type of the system a= nd store > # the list of zones in an array. > -my @network_zones =3D &IDS::get_available_network_zones(); > +my @network_zones =3D &Network::get_available_network_zones(); >=20 > # Check if openvpn is started and add it to the array of network zones. > if ( -e "/var/run/openvpn.pid") { > --=20 > 2.27.0.windows.1 >=20 --===============5674476431778421771==--