o
    O6ufC  ã                   @   s*   d dl mZmZmZ G dd„ deeƒZdS )é    )ÚPluginÚIndependentPluginÚSoSPredicatec                   @   sD   e Zd ZdZdZdZdZdZdZdd„ Z	d	d
„ Z
dd„ Zdd„ ZdS )ÚFirewallTablesa   Collects information about local firewall tables, such as iptables,
    and nf_tables (via nft). Note that this plugin does _not_ collect firewalld
    information, which is handled by a separate plugin.

    Collections from this plugin are largely gated byt the presence of relevant
    kernel modules - for example,  the plugin will not collect the nf_tables
    ruleset if both the `nf_tables` and `nfnetlink` kernel modules are not
    currently loaded (unless using the --allow-system-changes option).
    zfirewall tablesÚfirewall_tables)ÚnetworkÚsystem)ú/etc/nftables)Ú	ip_tablesÚ
ip6_tablesÚ	nf_tablesÚ	nfnetlinkÚebtablesc                 C   ó2   d| }d| d }| j |t| |dgd�d� dS )zÍ Collecting iptables rules for a table loads either kernel module
        of the table name (for kernel <= 3), or nf_tables (for kernel >= 4).
        If neither module is present, the rules must be empty.Úiptable_ziptables -t ú -nvLr   ©Úkmods©ÚpredN©Úadd_cmd_outputr   ©ÚselfÚ	tablenameÚmodnameÚcmd© r   úD/usr/lib/python3/dist-packages/sos/report/plugins/firewall_tables.pyÚcollect_iptable   s   
þzFirewallTables.collect_iptablec                 C   r   )z& Same as function above, but for ipv6 Ú	ip6table_zip6tables -t r   r   r   r   Nr   r   r   r   r   Úcollect_ip6table*   s   
þzFirewallTables.collect_ip6tablec                 C   s&   t | ddgddid�}| jd|dd�S )	zS Collects nftables rulesets with 'nft' commands if the modules
        are present r   r   r   Úall)r   Úrequiredznft -a list rulesetT)r   Úchanges)r   Úcollect_cmd_output)r   Únft_predr   r   r   Úcollect_nftables3   s   þÿzFirewallTables.collect_nftablesc                 C   s  |   ¡ }g g dœ}|d dkr|d nd}| ¡ D ]'}| ¡ dd… }t|ƒdkr@|d dkr@|d |v r@||d   |d	 ¡ qd
}zd}t|ddd��}| ¡ }	W d   ƒ n1 s\w   Y  W n tym   |}	Y nw |	 ¡ D ]}
|d dkr…|
|d v r…|  |
¡ qrzd}t|ddd��}| ¡ }	W d   ƒ n1 sŸw   Y  W n ty°   |}	Y nw |	 ¡ D ]}
|d dkrÈ|
|d v rÈ|  	|
¡ qµ|d dksÕd|d v râ| j
dt| ddgd�d� |d dksîd|d v rû| j
dt| ddgd�d� |  g d¢¡ d S )N)ÚipÚip6Ústatusr   ÚoutputÚ é   Útableé   é   zmangle
filter
nat
z/proc/net/ip_tables_namesÚrzUTF-8)Úencodingr(   z/proc/net/ip6_tables_namesr)   Úfilterziptables -vnxLÚiptable_filterr   r   r   zip6tables -vnxLÚip6table_filter)r	   z/etc/sysconfig/nftables.confz/etc/nftables.conf)r'   Ú
splitlinesÚsplitÚlenÚappendÚopenÚreadÚIOErrorr   r!   r   r   Úadd_copy_spec)r   Únft_listÚnft_ip_tablesÚ	nft_linesÚlineÚwordsÚdefault_ip_tablesÚproc_net_ip_tablesÚifileÚip_tables_namesr.   Úproc_net_ip6_tablesÚipfiler   r   r   Úsetup>   s^   
€
ÿ€ÿ
€
ÿ€ÿ
€þþzFirewallTables.setupN)Ú__name__Ú
__module__Ú__qualname__Ú__doc__Ú
short_descÚplugin_nameÚprofilesÚfilesÚkernel_modsr   r!   r'   rI   r   r   r   r   r      s    
	r   N)Úsos.report.pluginsr   r   r   r   r   r   r   r   Ú<module>   s   