1 -- Copyright 2011-2012 Jo-Philipp Wich <xm@subsignal.org>
2 -- Licensed to the public under the Apache License 2.0.
4 module("luci.tools.firewall", package.seeall)
6 local ut = require "luci.util"
7 local ip = require "luci.ip"
8 local nx = require "nixio"
10 local translate, translatef = luci.i18n.translate, luci.i18n.translatef
12 local function tr(...)
13 return tostring(translate(...))
17 if type(x) == "string" then
18 local v, neg = x:gsub("^ *! *", "")
20 return v, "%s " % tr("not")
31 local l = { tr("MAC"), " " }
32 for m in ut.imatch(x) do
34 l[#l+1] = "<var>%s%s</var>" %{ n, m }
42 return table.concat(l, "")
47 function fmt_port(x, d)
50 local l = { tr("port"), " " }
51 for p in ut.imatch(x) do
53 local a, b = p:match("(%d+)%D+(%d+)")
56 l[#l+1] = "<var>%s%d-%d</var>" %{ n, a, b }
58 l[#l+1] = "<var>%s%d</var>" %{ n, p }
67 return table.concat(l, "")
70 return d and "<var>%s</var>" % d
75 local l = { tr("IP"), " " }
77 for v in ut.imatch(x) do
79 a, m = v:match("(%S+)/(%d+%.%S+)")
81 a = a:match(":") and ip.IPv6(a, m) or ip.IPv4(a, m)
82 if a and (a:is6() and a:prefix() < 128 or a:prefix() < 32) then
84 l[#l+1] = "<var title='%s - %s'>%s%s</var>" %{
90 l[#l+1] = "<var>%s%s</var>" %{
102 return table.concat(l, "")
105 return d and "<var>%s</var>" % d
108 function fmt_zone(x, d)
110 return "<var>%s</var>" % tr("any zone")
111 elseif x and #x > 0 then
112 return "<var>%s</var>" % x
114 return "<var>%s</var>" % d
118 function fmt_icmp_type(x)
121 local l = { tr("type"), " " }
122 for v in ut.imatch(x) do
124 l[#l+1] = "<var>%s%s</var>" %{ n, v }
132 return table.concat(l, "")
137 function fmt_proto(x, icmp_types)
141 local t = fmt_icmp_type(icmp_types)
142 for v in ut.imatch(x) do
144 if v == "tcpudp" then
149 elseif v ~= "all" then
150 local p = nx.getproto(v)
153 if (p.proto == 1 or p.proto == 58) and t then
154 l[#l+1] = translatef(
156 n, p.aliases[1] or p.name, t
161 p.aliases[1] or p.name
170 return table.concat(l, "")
175 function fmt_limit(limit, burst)
176 burst = tonumber(burst)
177 if limit and #limit > 0 then
178 local l, u = limit:match("(%d+)/(%w+)")
179 l = tonumber(l or limit)
182 if u:match("^s") then
184 elseif u:match("^m") then
186 elseif u:match("^h") then
188 elseif u:match("^d") then
191 if burst and burst > 0 then
192 return translatef("<var>%d</var> pkts. per <var>%s</var>, \
193 burst <var>%d</var> pkts.", l, u, burst)
195 return translatef("<var>%d</var> pkts. per <var>%s</var>", l, u)
201 function fmt_target(x, dest)
202 if dest and #dest > 0 then
203 if x == "ACCEPT" then
204 return tr("Accept forward")
205 elseif x == "REJECT" then
206 return tr("Refuse forward")
207 elseif x == "NOTRACK" then
208 return tr("Do not track forward")
209 else --if x == "DROP" then
210 return tr("Discard forward")
213 if x == "ACCEPT" then
214 return tr("Accept input")
215 elseif x == "REJECT" then
216 return tr("Refuse input")
217 elseif x == "NOTRACK" then
218 return tr("Do not track input")
219 else --if x == "DROP" then
220 return tr("Discard input")
226 function opt_enabled(s, t, ...)
227 if t == luci.cbi.Button then
228 local o = s:option(t, "__enabled")
229 function o.render(self, section)
230 if self.map:get(section, "enabled") ~= "0" then
231 self.title = tr("Rule is enabled")
232 self.inputtitle = tr("Disable")
233 self.inputstyle = "reset"
235 self.title = tr("Rule is disabled")
236 self.inputtitle = tr("Enable")
237 self.inputstyle = "apply"
239 t.render(self, section)
241 function o.write(self, section, value)
242 if self.map:get(section, "enabled") ~= "0" then
243 self.map:set(section, "enabled", "0")
245 self.map:del(section, "enabled")
250 local o = s:option(t, "enabled", ...)
256 function opt_name(s, t, ...)
257 local o = s:option(t, "name", ...)
259 function o.cfgvalue(self, section)
260 return self.map:get(section, "name") or
261 self.map:get(section, "_name") or "-"
264 function o.write(self, section, value)
266 self.map:set(section, "name", value)
267 self.map:del(section, "_name")
273 function o.remove(self, section)
274 self.map:del(section, "name")
275 self.map:del(section, "_name")