From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo-Andres Hofmann To: development@lists.ipfire.org Subject: [PATCH 1/2] Refactor "get_available_network_zones", move to network-functions.pl Date: Sun, 17 Jan 2021 15:20:03 +0100 Message-ID: <20210117142004.984-1-hofmann@leo-andres.de> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1787743533576988587==" List-Id: --===============1787743533576988587== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable This function nicely translates the ethernet/settings "CONFIG_TYPE" into a list of available zones. Therefore it should be more accessible! Signed-off-by: Leo-Andres Hofmann --- config/cfgroot/ids-functions.pl | 39 ++--------------------------- config/cfgroot/network-functions.pl | 36 ++++++++++++++++++++++++++ config/suricata/convert-snort | 3 ++- html/cgi-bin/ids.cgi | 3 ++- 4 files changed, 42 insertions(+), 39 deletions(-) diff --git a/config/cfgroot/ids-functions.pl b/config/cfgroot/ids-functions.pl index d45e1c70a..2fdae4a7a 100644 --- a/config/cfgroot/ids-functions.pl +++ b/config/cfgroot/ids-functions.pl @@ -24,6 +24,7 @@ package IDS; =20 require '/var/ipfire/general-functions.pl'; +require "${General::swroot}/network-functions.pl"; =20 # Location where all config and settings files are stored. our $settingsdir =3D "${General::swroot}/suricata"; @@ -410,42 +411,6 @@ sub _store_error_message ($) { &set_ownership("$storederrorfile"); } =20 -# -## Function to get a list of all available network zones. -# -sub get_available_network_zones () { - # Get netsettings. - my %netsettings =3D (); - &General::readhash("${General::swroot}/ethernet/settings", \%netsettings); - - # Obtain the configuration type from the netsettings hash. - my $config_type =3D $netsettings{'CONFIG_TYPE'}; - - # Hash which contains the conversation from the config mode - # to the existing network interface names. They are stored like - # an array. - # - # Mode "0" red is a modem and green - # Mode "1" red is a netdev and green - # Mode "2" red, green and orange - # Mode "3" red, green and blue - # Mode "4" red, green, blue, orange - my %config_type_to_interfaces =3D ( - "0" =3D> [ "red", "green" ], - "1" =3D> [ "red", "green" ], - "2" =3D> [ "red", "green", "orange" ], - "3" =3D> [ "red", "green", "blue" ], - "4" =3D> [ "red", "green", "blue", "orange" ] - ); - - # Obtain and dereference the corresponding network interaces based on the r= ead - # network config type. - my @network_zones =3D @{ $config_type_to_interfaces{$config_type} }; - - # Return them. - return @network_zones; -} - # ## Function to check if the IDS is running. # @@ -613,7 +578,7 @@ sub generate_home_net_file() { &General::readhash("${General::swroot}/ethernet/settings", \%netsettings); =20 # Get available network zones. - my @network_zones =3D &get_available_network_zones(); + my @network_zones =3D &Network::get_available_network_zones(); =20 # Temporary array to store network address and prefix of the configured # networks. diff --git a/config/cfgroot/network-functions.pl b/config/cfgroot/network-fun= ctions.pl index 3d7f04743..622731f96 100644 --- a/config/cfgroot/network-functions.pl +++ b/config/cfgroot/network-functions.pl @@ -444,6 +444,42 @@ sub get_mac_by_name($) { return $mac; } =20 +# +## Function to get a list of all available network zones. +# +sub get_available_network_zones () { + # Get netsettings. + my %netsettings =3D (); + &General::readhash("${General::swroot}/ethernet/settings", \%netsettings); + + # Obtain the configuration type from the netsettings hash. + my $config_type =3D $netsettings{'CONFIG_TYPE'}; + + # Hash which contains the conversation from the config mode + # to the existing network interface names. They are stored like + # an array. + # + # Mode "0" red is a modem and green + # Mode "1" red is a netdev and green + # Mode "2" red, green and orange + # Mode "3" red, green and blue + # Mode "4" red, green, blue, orange + my %config_type_to_interfaces =3D ( + "0" =3D> [ "red", "green" ], + "1" =3D> [ "red", "green" ], + "2" =3D> [ "red", "green", "orange" ], + "3" =3D> [ "red", "green", "blue" ], + "4" =3D> [ "red", "green", "blue", "orange" ] + ); + + # Obtain and dereference the corresponding network interaces based on the r= ead + # network config type. + my @network_zones =3D @{ $config_type_to_interfaces{$config_type} }; + + # Return them. + return @network_zones; +} + 1; =20 # Remove the next line to enable the testsuite diff --git a/config/suricata/convert-snort b/config/suricata/convert-snort index 3e938137e..7d75233b4 100644 --- a/config/suricata/convert-snort +++ b/config/suricata/convert-snort @@ -23,6 +23,7 @@ use strict; =20 require '/var/ipfire/general-functions.pl'; require "${General::swroot}/ids-functions.pl"; +require "${General::swroot}/network-functions.pl"; =20 # Snort settings file, which contains the settings from the WUI. my $snort_settings_file =3D "${General::swroot}/snort/settings"; @@ -129,7 +130,7 @@ my %rulessettings =3D ( ); =20 # Get all available network zones. -my @network_zones =3D &IDS::get_available_network_zones(); +my @network_zones =3D &Network::get_available_network_zones(); =20 # Read-in snort settings file. &General::readhash("$snort_settings_file", \%snortsettings); diff --git a/html/cgi-bin/ids.cgi b/html/cgi-bin/ids.cgi index bc31a341f..83d5f52ba 100644 --- a/html/cgi-bin/ids.cgi +++ b/html/cgi-bin/ids.cgi @@ -29,6 +29,7 @@ require '/var/ipfire/general-functions.pl'; require "${General::swroot}/lang.pl"; require "${General::swroot}/header.pl"; require "${General::swroot}/ids-functions.pl"; +require "${General::swroot}/network-functions.pl"; =20 my %color =3D (); my %mainsettings =3D (); @@ -47,7 +48,7 @@ my %ignored=3D(); =20 # Get the available network zones, based on the config type of the system an= d store # the list of zones in an array. -my @network_zones =3D &IDS::get_available_network_zones(); +my @network_zones =3D &Network::get_available_network_zones(); =20 # Check if openvpn is started and add it to the array of network zones. if ( -e "/var/run/openvpn.pid") { --=20 2.27.0.windows.1 --===============1787743533576988587==--