/usr/bin
NameSizeModeActions
2to31060755editdlrm
2to3-3.61060755editdlrm
ab743680755editdlrm
aclocal364780755editdlrm
aclocal-1.16364780755editdlrm
acyclic127120755editdlrm
addr2line342240755editdlrm
alias290755editdlrm
animate121280755editdlrm
apropos553360755editdlrm
ar634480755editdlrm
arch382320755editdlrm
aria_chk56372320755editdlrm
aria_dump_log54318640755editdlrm
aria_ftdump54444320755editdlrm
aria_pack54708640755editdlrm
aria_read_log55913840755editdlrm
arpaname121040755editdlrm
as9112640755editdlrm
aspell1633280755editdlrm
at587040755editdlrm
atq587040755editdlrm
atrm587040755editdlrm
aulast210720755editdlrm
aulastlog127360755editdlrm
ausyscall125680755editdlrm
authselect421120755editdlrm
autoconf147680755editdlrm
autoheader85340755editdlrm
autom4te321810755editdlrm
automake2579490755editdlrm
automake-1.162579490755editdlrm
autopoint265720755editdlrm
autoreconf210660755editdlrm
autoscan171240755editdlrm
autoupdate338720755editdlrm
auvirt335120755editdlrm
awk6858480755editdlrm
b2sum590720755editdlrm
base32424640755editdlrm
base64424800755editdlrm
basename383120755editdlrm
bash11546800755editdlrm
bashbug73480755editdlrm
bashbug-6473480755editdlrm
batch1370755editdlrm
bc972560755editdlrm
bcomps211120755editdlrm
bdftopcf464880755editdlrm
bg260755editdlrm
bind9-config34160755editdlrm
bison4482240755editdlrm
bluemoon1000480755editdlrm
bluetoothctl2941200755editdlrm
bond2team232890755editdlrm
bootctl462320755editdlrm
brotli7569440755editdlrm
btattach916880755editdlrm
btmon9667360755editdlrm
bunzip2377440755editdlrm
busctl791200755editdlrm
bwrap712960755editdlrm
bzcat377440755editdlrm
bzcmp21280755editdlrm
bzdiff21280755editdlrm
bzegrep16770755editdlrm
bzfgrep16770755editdlrm
bzgrep16770755editdlrm
bzip2377440755editdlrm
bzip2recover168320755editdlrm
bzless12590755editdlrm
bzmore12590755editdlrm
c++12666160755editdlrm
c++filt295840755editdlrm
c892240755editdlrm
c992150755editdlrm
ca-legacy16440755editdlrm
cairo-sphinx713840755editdlrm
cal675600755editdlrm
captoinfo873600755editdlrm
cat383600755editdlrm
catchsegv32830755editdlrm
catman424480755editdlrm
cc12665760755editdlrm
ccomps253120755editdlrm
cd260755editdlrm
centrino-decode115360755editdlrm
certutil2039280755editdlrm
chacl167680755editdlrm
chage795440755editdlrm
chardetect4000755editdlrm
chattr168000755editdlrm
chcon720240755editdlrm
checkmodule4372560755editdlrm
checkpolicy5003680755editdlrm
chfn336880711editdlrm
chgrp678640755editdlrm
chmem465600755editdlrm
chmod636880755editdlrm
chown719760755editdlrm
chronyc1306640755editdlrm
chrt380800755editdlrm
chsh253120711editdlrm
chvt128320755editdlrm
cifsiostat423440755editdlrm
ciptool2158160755editdlrm
circo125520755editdlrm
cksum382880755editdlrm
clear128400755editdlrm
cloud-id4020755editdlrm
cloud-init4060755editdlrm
cloud-init-per21080755editdlrm
cluster5307680755editdlrm
cmp1062480755editdlrm
cmsutil1254000755editdlrm
col297040755editdlrm
colcrt168720755editdlrm
colrm254800755editdlrm
column506560755editdlrm
comm425600755editdlrm
command310755editdlrm
compare121360755editdlrm
compile_et13420755editdlrm
composite121200755editdlrm
config_data71380755editdlrm
conjure121200755editdlrm
convert121200755editdlrm
coredumpctl459920755editdlrm
corelist149950755editdlrm
cp1515280755editdlrm
cpan83700755editdlrm
cpan-mirrors42880755editdlrm
cpapi134969120755editdlrm
cpapi234969120755editdlrm
cpapi334969120755editdlrm
cpio1636400755editdlrm
cpp12665520755editdlrm
cpupower685120755editdlrm
crb26440744editdlrm
crc3210430755editdlrm
crlutil1381840755editdlrm
cronnext510000755editdlrm
crontab631524755editdlrm
csplit549680755editdlrm
csslint-0.6251520755editdlrm
curl2356000755editdlrm
cut507040755editdlrm
cvtsudoers2910320755editdlrm
cxpm298080755editdlrm
date1084960755editdlrm
dbilogstrip13800755editdlrm
dbiprof62060755editdlrm
dbus-binding-tool1130800755editdlrm
dbus-cleanup-sockets167840755editdlrm
dbus-daemon2454480755editdlrm
dbus-monitor292640755editdlrm
dbus-run-session162640755editdlrm
dbus-send292240755editdlrm
dbus-test-tool251920755editdlrm
dbus-update-activation-environment168080755editdlrm
dbus-uuidgen126720755editdlrm
dbxtool252400755editdlrm
db_archive127520755editdlrm
db_checkpoint168720755editdlrm
db_deadlock168720755editdlrm
db_dump169040755editdlrm
db_dump185712240755editdlrm
db_hotbackup209840755editdlrm
db_load292960755editdlrm
db_log_verify169120755editdlrm
db_printlog342000755editdlrm
db_recover169040755editdlrm
db_replicate168880755editdlrm
db_stat168720755editdlrm
db_tuner251440755editdlrm
db_upgrade127520755editdlrm
db_verify168560755editdlrm
dc542960755editdlrm
dd798400755editdlrm
deallocvt128400755editdlrm
debuginfo-install37020755editdlrm
debuginfod-find168640755editdlrm
delv434800755editdlrm
df932720755editdlrm
diff2744400755editdlrm
diff31316880755editdlrm
diffimg125680755editdlrm
dig1660640755editdlrm
dijkstra171120755editdlrm
dir1432480755editdlrm
dircolors507440755editdlrm
dirmngr5938080755editdlrm
dirmngr-client1230000755editdlrm
dirname341600755editdlrm
display121280755editdlrm
dltest121520755editdlrm
dmesg797440755editdlrm
dnf21040755editdlrm
dnf-321040755editdlrm
dnsdomainname216640755editdlrm
dnstap-read209200755editdlrm
domainname216640755editdlrm
dot125520755editdlrm
dot2gxl422880755editdlrm
dotty20850755editdlrm
doveadm9735040755editdlrm
doveconf3978480755editdlrm
dovecot-sysreport64310755editdlrm
dpkg3237600755editdlrm
dpkg-deb1694720755editdlrm
dpkg-divert1615360755editdlrm
dpkg-maintscript-helper211620755editdlrm
dpkg-query1698240755editdlrm
dpkg-realpath41490755editdlrm
dpkg-split1355680755editdlrm
dpkg-statoverride680080755editdlrm
dpkg-trigger897680755editdlrm
dracut691820755editdlrm
dtrace178080755editdlrm
du1095680755editdlrm
dumpkeys1739520755editdlrm
dumpsexp168320755editdlrm
dwp22334400755editdlrm
dwz1716640755editdlrm
ea-php7463827840755editdlrm
ea-php74-pear3830755editdlrm
ea-php74-pecl2990755editdlrm
ea-php8281471280755editdlrm
ea-php82-pear3830755editdlrm
ea-php82-pecl2990755editdlrm
ea-php8381757760755editdlrm
ea-php83-pear3830755editdlrm
ea-php83-pecl2990755editdlrm
ea-wappspector1000755editdlrm
easy_install-32460755editdlrm
easy_install-3.62460755editdlrm
echo382480755editdlrm
edgepaint4308880755editdlrm
egrep280755editdlrm
eject591680755editdlrm
elfedit340800755editdlrm
enc2xs419580755editdlrm
encguess29800755editdlrm
env423520755editdlrm
envml41970755editdlrm
envsubst501680755editdlrm
eps2eps6390755editdlrm
eqn2377280755editdlrm
event_rpcgen.py555590755editdlrm
evmctl640400755editdlrm
ex11805600755editdlrm
expand425920755editdlrm
expr507520755editdlrm
factor880320755editdlrm
fallocate296560755editdlrm
false341200755editdlrm
fc260755editdlrm
fc-cache1320755editdlrm
fc-cache-64208400755editdlrm
fc-cat167440755editdlrm
fc-conflist125440755editdlrm
fc-list125440755editdlrm
fc-match166480755editdlrm
fc-pattern125520755editdlrm
fc-query125360755editdlrm
fc-scan125520755editdlrm
fc-validate166480755editdlrm
fdp125520755editdlrm
fg260755editdlrm
fgconsole128480755editdlrm
fgrep280755editdlrm
filan969920755editdlrm
file252800755editdlrm
fincore338320755editdlrm
find2286320755editdlrm
find-repos-of-install37020755editdlrm
findmnt723040755editdlrm
fips-finish-install13230755editdlrm
fips-mode-setup40070755editdlrm
firewall-cmd1429550755editdlrm
firewall-offline-cmd1236240755editdlrm
flex4387280755editdlrm
flex++4387280755editdlrm
flock339920755editdlrm
fmt465840755editdlrm
fold424160755editdlrm
fonttosfnt421680755editdlrm
free212880755editdlrm
freetype-config44160755editdlrm
fribidi216480755editdlrm
ftp1036320755editdlrm
funzip375040755editdlrm
fwupdmgr1620800755editdlrm
fwupdtool2118480755editdlrm
g++12666160755editdlrm
g132170640755editdlrm
galera_new_cluster12680755editdlrm
galera_recovery33660755editdlrm
gapplication209360755editdlrm
garb-systemd13450755editdlrm
garbd17353040755editdlrm
gatttool3801760755editdlrm
gawk6858480755editdlrm
gc170400755editdlrm
gcc12665760755editdlrm
gcc-ar375360755editdlrm
gcc-nm375360755editdlrm
gcc-ranlib375360755editdlrm
gcov13774080755editdlrm
gcov-dump5846640755editdlrm
gcov-tool6223600755editdlrm
gdbmtool1142480755editdlrm
gdbm_dump215600755editdlrm
gdbm_load259200755editdlrm
gdbus498880755editdlrm
gdk-pixbuf-query-loaders-64163120755editdlrm
gdk-pixbuf-thumbnailer209440755editdlrm
gdlib-config28610755editdlrm
gencat254320755editdlrm
genl-ctrl-list123280755editdlrm
geqn2377280755editdlrm
GET162170755editdlrm
getconf332400755editdlrm
getent339200755editdlrm
getfacl293840755editdlrm
getkeycodes128400755editdlrm
getopt210240755editdlrm
getopts310755editdlrm
gettext501440755editdlrm
gettext.sh46290755editdlrm
gettextize437180755editdlrm
ghostscript126480755editdlrm
gio872640755editdlrm
gio-querymodules-64166960755editdlrm
git276658160755editdlrm
git-receive-pack276658160755editdlrm
git-shell165537680755editdlrm
git-upload-archive276658160755editdlrm
git-upload-pack276658160755editdlrm
glib-compile-schemas500240755editdlrm
gmake2409680755editdlrm
gml2gv422160755editdlrm
gneqn9080755editdlrm
gnroff33120755editdlrm
gpasswd841444755editdlrm
gpg10903440755editdlrm
gpg-agent4293600755editdlrm
gpg-connect-agent1692720755editdlrm
gpg-error349760755editdlrm
gpg-error-config23180755editdlrm
gpg-wks-server2116720755editdlrm
gpg-zip35250755editdlrm
gpg210903440755editdlrm
gpgconf1803280755editdlrm
gpgme-json877360755editdlrm
gpgparsemail294320755editdlrm
gpgrt-config23180755editdlrm
gpgsm5268080755editdlrm
gpgsplit891120755editdlrm
gpgv4623440755editdlrm
gpgv24623440755editdlrm
gpic3008960755editdlrm
gpio-event-mon153200755editdlrm
gpio-hammer153200755editdlrm
gprof1058320755editdlrm
gr2fonttest306720755editdlrm
graphml2gv211440755editdlrm
grep1982800755editdlrm
groff1279200755editdlrm
grops1957280755editdlrm
grotty1453040755editdlrm
groups382880755editdlrm
growpart298950755editdlrm
grub2-editenv4588480755editdlrm
grub2-file9508320755editdlrm
grub2-fstest12104560755editdlrm
grub2-glue-efi2861200755editdlrm
grub2-kbdcomp16680755editdlrm
grub2-menulst2cfg2689600755editdlrm
grub2-mkfont3196160755editdlrm
grub2-mkimage4417600755editdlrm
grub2-mklayout2964320755editdlrm
grub2-mknetdir4974880755editdlrm
grub2-mkpasswd-pbkdf22988880755editdlrm
grub2-mkrelpath2859680755editdlrm
grub2-mkrescue11702080755editdlrm
grub2-mkstandalone6085600755editdlrm
grub2-render-label9595760755editdlrm
grub2-script-check3235840755editdlrm
grub2-syslinux2cfg8822880755editdlrm
gs126480755editdlrm
gsettings292960755editdlrm
gsnd2770755editdlrm
gsoelim435760755editdlrm
gss-client251520755editdlrm
gtar4597680755editdlrm
gtbl1583200755editdlrm
gtk-query-immodules-2.0-64166800755editdlrm
gtk-update-icon-cache338240755editdlrm
gtroff8243440755editdlrm
gunzip23450755editdlrm
gv2gml252880755editdlrm
gv2gxl422880755editdlrm
gvcolor480240755editdlrm
gvgen253920755editdlrm
gvmap5389440755editdlrm
gvmap.sh21900755editdlrm
gvpack4716400755editdlrm
gvpr80160755editdlrm
gxl2dot422880755editdlrm
gxl2gv422880755editdlrm
gzexe63750755editdlrm
gzip969440755editdlrm
h2ph293820755editdlrm
h2xs608660755editdlrm
hash280755editdlrm
hciattach2073280755editdlrm
hciconfig2009840755editdlrm
hcidump4932400755editdlrm
hcitool2169840755editdlrm
HEAD162170755editdlrm
head466000755editdlrm
hex2hcd167760755editdlrm
hexdump588880755editdlrm
hmac256172720755editdlrm
host1457120755editdlrm
hostid341360755editdlrm
hostname216640755editdlrm
hostnamectl213280755editdlrm
htdbm324800755editdlrm
htdigest222320755editdlrm
html2text4060755editdlrm
htpasswd323040755editdlrm
httxt2dbm216080755editdlrm
hunspell1481680755editdlrm
i386212560755editdlrm
iceauth428720755editdlrm
iconv629040755editdlrm
id465280755editdlrm
identify121280755editdlrm
idiag-socket-details123760755editdlrm
idn403520755editdlrm
ifnames41280755editdlrm
iio_event_monitor235280755editdlrm
iio_generic_buffer276240755editdlrm
import121200755editdlrm
imunify-agent-proxy137819220755editdlrm
imunify-antivirus10240755editdlrm
imunify-fgw-dump81830000755editdlrm
imunify-service10200755editdlrm
imunify360-agent10240755editdlrm
imunify360-command-wrapper122100755editdlrm
info2558880755editdlrm
infocmp625120755editdlrm
infotocap873600755editdlrm
innochecksum47652960755editdlrm
install1598880755editdlrm
install-tools41580755editdlrm
instmodsh41940755editdlrm
intel-speed-select952560755editdlrm
ionice296800755editdlrm
iostat590720755editdlrm
ipcalc471840755editdlrm
ipcmk298400755editdlrm
ipcrm296880755editdlrm
ipcs546800755editdlrm
isc-config.sh34160755editdlrm
isosize254800755editdlrm
ispell9880755editdlrm
isql374560755editdlrm
iusql293440755editdlrm
jcat-tool419120755editdlrm
jobs280755editdlrm
join549840755editdlrm
journalctl788400755editdlrm
jq290960755editdlrm
jsondiff10330755editdlrm
jsondiff-310330755editdlrm
jsondiff-3.610330755editdlrm
jsonpatch36760755editdlrm
jsonpatch-336760755editdlrm
jsonpatch-3.636760755editdlrm
jsonpointer13560755editdlrm
jsonpointer-313560755editdlrm
jsonpointer-3.613560755editdlrm
jsonschema-34090755editdlrm
json_pp42860755editdlrm
json_reformat169520755editdlrm
json_verify125680755editdlrm
json_xs70020755editdlrm
kbdinfo169600755editdlrm
kbdrate168400755editdlrm
kbd_mode128560755editdlrm
kbxutil1816080755editdlrm
kdumpctl337220755editdlrm
kernel-install45110755editdlrm
keyctl377040755editdlrm
kill381760755editdlrm
killall304800755editdlrm
kmod1637840755editdlrm
krb5-config71440755editdlrm
kvm_stat623070755editdlrm
l2ping1676880755editdlrm
l2test1844960755editdlrm
last504160755editdlrm
lastb504160755editdlrm
lastlog211200755editdlrm
lchfn208400755editdlrm
lchsh167440755editdlrm
ld17890800755editdlrm
ld.bfd17890800755editdlrm
ld.gold24676560755editdlrm
ld.so11040640755editdlrm
ldd54410755editdlrm
lefty3118320755editdlrm
less1779280755editdlrm
lessecho126960755editdlrm
lesskey225200755editdlrm
lesspipe.sh31430755editdlrm
lex4387280755editdlrm
lexgrog959520755editdlrm
libgcrypt-config39310755editdlrm
libnetcfg157750755editdlrm
libpng-config23820755editdlrm
libpng16-config23820755editdlrm
libtool3677240755editdlrm
libtoolize1291970755editdlrm
libwmf-fontmap133400755editdlrm
link341360755editdlrm
linux-boot-prober59930755editdlrm
linux32212560755editdlrm
linux64212560755editdlrm
ln721920755editdlrm
lneato15470755editdlrm
loadkeys2155840755editdlrm
loadunimap297280755editdlrm
locale577920755editdlrm
localectl295520755editdlrm
localedef3148480755editdlrm
logger511840755editdlrm
login419440755editdlrm
loginctl586560755editdlrm
logname341440755editdlrm
logresolve219680755editdlrm
look168560755editdlrm
ls1432480755editdlrm
lsattr122160755editdlrm
lsblk923040755editdlrm
lscpu836560755editdlrm
lsgpio154240755editdlrm
lsiio235280755editdlrm
lsinitrd88860755editdlrm
lsipc755120755editdlrm
lslocks384320755editdlrm
lslogins671920755editdlrm
lsmem464240755editdlrm
lsns504720755editdlrm
lsof1796080755editdlrm
lsphp9370755editdlrm
lsscsi880720755editdlrm
lua209440755editdlrm
luac1564400755editdlrm
lwp-download102920755editdlrm
lwp-dump27110755editdlrm
lwp-mirror24130755editdlrm
lwp-request162170755editdlrm
m41900160755editdlrm
Mail4187040755editdlrm
mail4187040755editdlrm
mailx4187040755editdlrm
make2409680755editdlrm
make-dummy-cert6100755editdlrm
makedb254320755editdlrm
man1152240755editdlrm
mandb1377440755editdlrm
manpath342240755editdlrm
mapscrn254400755editdlrm
mariadb55014880755editdlrm
mariadb-access1119610755editdlrm
mariadb-admin50426560755editdlrm
mariadb-binlog53285040755editdlrm
mariadb-check50355760755editdlrm
mariadb-config124880755editdlrm
mariadb-conv47561040755editdlrm
mariadb-convert-table-format42200755editdlrm
mariadb-dump51282240755editdlrm
mariadb-dumpslow82420755editdlrm
mariadb-embedded249113200755editdlrm
mariadb-find-rows32900755editdlrm
mariadb-fix-extensions12500755editdlrm
mariadb-hotcopy353590755editdlrm
mariadb-import50304480755editdlrm
mariadb-install-db226920755editdlrm
mariadb-plugin47349120755editdlrm
mariadb-secure-installation137990755editdlrm
mariadb-service-convert25060755editdlrm
mariadb-setpermission179770755editdlrm
mariadb-show50247360755editdlrm
mariadb-slap50442800755editdlrm
mariadb-tzinfo-to-sql47343360755editdlrm
mariadb-upgrade51858560755editdlrm
mariadb-waitpid47216160755editdlrm
mariadbd-multi274250755editdlrm
mariadbd-safe312140755editdlrm
mariadbd-safe-helper46917920755editdlrm
mariadb_config124880755editdlrm
mcookie340640755editdlrm
mcpp92320755editdlrm
md5sum466400755editdlrm
mdig496800755editdlrm
memstrack857920755editdlrm
mesg167520755editdlrm
miniterm-3.6.py338870755editdlrm
miniterm-3.py338870755editdlrm
mkdir846800755editdlrm
mkfifo680560755editdlrm
mkfontdir650755editdlrm
mkfontscale425920755editdlrm
mkinitrd65850755editdlrm
mknod721600755editdlrm
mktemp467600755editdlrm
mm2gv927040755editdlrm
mmdblookup171440755editdlrm
modulecmd3939800755editdlrm
modulemd-validator255600755editdlrm
modutil1816880755editdlrm
mogrify121200755editdlrm
mokutil511840755editdlrm
montage121200755editdlrm
more460160755editdlrm
mount503280755editdlrm
mountpoint168800755editdlrm
mpicalc208720755editdlrm
mpris-proxy1013680755editdlrm
mpstat547920755editdlrm
msgattrib261920755editdlrm
msgcat261680755editdlrm
msgcmp267440755editdlrm
msgcomm261680755editdlrm
msgconv220720755editdlrm
msgen220640755editdlrm
msgexec220720755editdlrm
msgfilter353600755editdlrm
msgfmt924640755editdlrm
msggrep446480755editdlrm
msginit694800755editdlrm
msgmerge732000755editdlrm
msgunfmt366640755editdlrm
msguniq261760755editdlrm
msql2mysql14460755editdlrm
mv1474080755editdlrm
myisamchk51451360755editdlrm
myisamlog50024160755editdlrm
myisampack50416000755editdlrm
myisam_ftdump50203120755editdlrm
mysql55014880755editdlrm
mysqlaccess1119610755editdlrm
mysqladmin50426560755editdlrm
mysqlbinlog53285040755editdlrm
mysqlcheck50355760755editdlrm
mysqldump51282240755editdlrm
mysqld_multi274250755editdlrm
mysqld_safe312140755editdlrm
mysqld_safe_helper46917920755editdlrm
mysqlimport50304480755editdlrm
mysqlshow50247360755editdlrm
mysqlslap50442800755editdlrm
mysql_config46230755editdlrm
mysql_embedded249113200755editdlrm
mysql_find_rows32900755editdlrm
mysql_fix_extensions12500755editdlrm
mysql_install_db226920755editdlrm
mysql_plugin47349120755editdlrm
mysql_tzinfo_to_sql47343360755editdlrm
mysql_upgrade51858560755editdlrm
mysql_waitpid47216160755editdlrm
mytop737570755editdlrm
my_print_defaults47262880755editdlrm
nail4187040755editdlrm
named-rrchecker203520755editdlrm
namei338960755editdlrm
nano2538880755editdlrm
nc505760755editdlrm
ncurses6-config60150755editdlrm
ncursesw6-config60180755editdlrm
ndptool250400755editdlrm
neato125520755editdlrm
needs-restarting37020755editdlrm
neqn9080755editdlrm
netcat505760755editdlrm
netstat1624880755editdlrm
newgidmap489600755editdlrm
newgrp434800755editdlrm
newuidmap489200755editdlrm
nf-ct-add168560755editdlrm
nf-ct-events126720755editdlrm
nf-ct-list168880755editdlrm
nf-exp-add172720755editdlrm
nf-exp-delete170560755editdlrm
nf-exp-list168880755editdlrm
nf-log126480755editdlrm
nf-monitor126560755editdlrm
nf-queue167440755editdlrm
ngettext501440755editdlrm
nice382240755editdlrm
nisdomainname216640755editdlrm
nl466480755editdlrm
nl-addr-add126320755editdlrm
nl-addr-delete171680755editdlrm
nl-addr-list172800755editdlrm
nl-class-add171280755editdlrm
nl-class-delete129280755editdlrm
nl-class-list128960755editdlrm
nl-classid-lookup127680755editdlrm
nl-cls-add171680755editdlrm
nl-cls-delete171760755editdlrm
nl-cls-list130400755editdlrm
nl-fib-lookup128000755editdlrm
nl-link-enslave121520755editdlrm
nl-link-ifindex2name121520755editdlrm
nl-link-list125280755editdlrm
nl-link-name2ifindex121440755editdlrm
nl-link-release121440755editdlrm
nl-link-set130720755editdlrm
nl-link-stats128880755editdlrm
nl-list-caches125680755editdlrm
nl-list-sockets121520755editdlrm
nl-monitor128160755editdlrm
nl-neigh-add129280755editdlrm
nl-neigh-delete129680755editdlrm
nl-neigh-list124800755editdlrm
nl-neightbl-list122960755editdlrm
nl-pktloc-lookup128640755editdlrm
nl-qdisc-add129520755editdlrm
nl-qdisc-delete129280755editdlrm
nl-qdisc-list171440755editdlrm
nl-route-add167840755editdlrm
nl-route-delete172880755editdlrm
nl-route-get126480755editdlrm
nl-route-list168320755editdlrm
nl-rule-list123360755editdlrm
nl-tctree-list129600755editdlrm
nl-util-addr121360755editdlrm
nm515840755editdlrm
nm-online213360755editdlrm
nmcli10332160755editdlrm
nmtui8029360755editdlrm
nmtui-connect8029360755editdlrm
nmtui-edit8029360755editdlrm
nmtui-hostname8029360755editdlrm
nohup383120755editdlrm
nop128000755editdlrm
nproc383040755editdlrm
nroff33120755editdlrm
nsenter340960755editdlrm
nslookup1497680755editdlrm
nss-policy-check166960755editdlrm
nsupdate748080755editdlrm
numfmt672160755editdlrm
objcopy2458320755editdlrm
objdump4298320755editdlrm
od755760755editdlrm
odbcinst295760755editdlrm
odbc_config121280755editdlrm
open214720755editdlrm
openssl7638480755editdlrm
openvt214720755editdlrm
os-prober59150755editdlrm
osage125520755editdlrm
p11-kit380400755editdlrm
package-cleanup37020755editdlrm
page_owner_sort116160755editdlrm
pango-list121600755editdlrm
pango-view588160755editdlrm
paperconf133840755editdlrm
passwd335604755editdlrm
paste382800755editdlrm
patch2114160755editdlrm
patchwork125520755editdlrm
pathchk382240755editdlrm
pathfix.py67900755editdlrm
pcre2-config19500755editdlrm
pdf2dsc6980755editdlrm
pdf2ps9090755editdlrm
pdnsutil54421120755editdlrm
pdns_control4979360755editdlrm
peekfd169040755editdlrm
perl127280755editdlrm
perl5.26.3127280755editdlrm
perlbug454580755editdlrm
perldoc1180755editdlrm
perlivp108130755editdlrm
perlml67680755editdlrm
perlthanks454580755editdlrm
perror49280080755editdlrm
pflags26360755editdlrm
pftp1036320755editdlrm
pgrep295360755editdlrm
php9370755editdlrm
pic3008960755editdlrm
piconv82710755editdlrm
pidof170960755editdlrm
pidstat672960755editdlrm
pigz1283920755editdlrm
pinentry24040755editdlrm
pinentry-curses797600755editdlrm
ping677120755editdlrm
pinky424560755editdlrm
pip-32090755editdlrm
pip-3.62090755editdlrm
pip32090755editdlrm
pip3.62090755editdlrm
pk12util1137840755editdlrm
pkaction167760755editdlrm
pkcheck250160755editdlrm
pkexec290880755editdlrm
pkg-config410000755editdlrm
pkgconf410000755editdlrm
pkill295360755editdlrm
pkla-admin-identities263360755editdlrm
pkla-check-authorization345920755editdlrm
pkttyagent208720755editdlrm
pl2pm45330755editdlrm
pldd171520755editdlrm
pmap335680755editdlrm
png-fix-itxt121360755editdlrm
pngfix541200755editdlrm
pod2html41340755editdlrm
pod2man150340755editdlrm
pod2text108030755editdlrm
pod2usage39480755editdlrm
podchecker36580755editdlrm
podselect25270755editdlrm
POST162170755editdlrm
post-grohtml2444560755editdlrm
powernow-k8-decode111360755editdlrm
pr841200755editdlrm
pre-grohtml1336880755editdlrm
precat56560755editdlrm
preconv590320755editdlrm
preunzip56560755editdlrm
prezip56560755editdlrm
prezip-bin122640755editdlrm
printenv341200755editdlrm
printf548480755editdlrm
prlimit384400755editdlrm
prl_backup75440755editdlrm
procan845840755editdlrm
protoc168880755editdlrm
protoc-c2506640755editdlrm
protoc-gen-c2506640755editdlrm
prove135620755editdlrm
prtstat210000755editdlrm
prune171280755editdlrm
ps1379840755editdlrm
ps2ascii6310755editdlrm
ps2epsi27520755editdlrm
ps2pdf2720755editdlrm
ps2pdf122150755editdlrm
ps2pdf132150755editdlrm
ps2pdf142150755editdlrm
ps2pdfwr10970755editdlrm
ps2ps6470755editdlrm
ps2ps26690755editdlrm
psfaddtable211520755editdlrm
psfgettable211520755editdlrm
psfstriptable211520755editdlrm
psfxtable211520755editdlrm
pslog127840755editdlrm
pstree343360755editdlrm
pstree.x11343360755editdlrm
ptar34560755editdlrm
ptardiff25350755editdlrm
ptargrep42990755editdlrm
ptx798640755editdlrm
pure-pw397680755editdlrm
pure-pwconvert109760755editdlrm
pure-statsdecode109760755editdlrm
pv753280755editdlrm
pwd383200755editdlrm
pwdx129840755editdlrm
pwmake125600755editdlrm
pwscore125600755editdlrm
pybabel3880755editdlrm
pydoc-3890755editdlrm
pydoc3890755editdlrm
pydoc3.6890755editdlrm
pydoc3.12790755editdlrm
pyjwt3840755editdlrm
python-html2text4060755editdlrm
python3118720755editdlrm
python3-config2040755editdlrm
python3-html2text4060755editdlrm
python3.6118720755editdlrm
python3.6-config2040755editdlrm
python3.6m118720755editdlrm
python3.6m-config2040755editdlrm
python3.6m-x86_64-config36260755editdlrm
python3.1277520755editdlrm
pyvenv-34460755editdlrm
pyvenv-3.64460755editdlrm
qemu-ga10044080755editdlrm
quota936884755editdlrm
quotasync764800755editdlrm
ranlib634560755editdlrm
raw168960755editdlrm
rctest2157440755editdlrm
read280755editdlrm
readelf6395280755editdlrm
readlink469840755editdlrm
realpath511440755editdlrm
recode-sr-latin184240755editdlrm
rename168960755editdlrm
renew-dummy-cert7250755editdlrm
renice168560755editdlrm
replace47040880755editdlrm
repo-graph37020755editdlrm
repoclosure37020755editdlrm
repodiff37020755editdlrm
repomanage37020755editdlrm
repoquery37020755editdlrm
reposync37020755editdlrm
repotrack37020755editdlrm
rescan-scsi-bus.sh391610755editdlrm
reset253520755editdlrm
resizecons212720755editdlrm
resolvectl2004480755editdlrm
resolveip47215600755editdlrm
resolve_stack_dump47257280755editdlrm
rev127600755editdlrm
rfcomm1766640755editdlrm
rm720640755editdlrm
rmdir465520755editdlrm
rnano2538880755editdlrm
rpcbind630240755editdlrm
rpcinfo334240755editdlrm
rpm213520755editdlrm
rpm2archive209520755editdlrm
rpm2cpio121280755editdlrm
rpmdb173680755editdlrm
rpmkeys172720755editdlrm
rpmquery213520755editdlrm
rpmverify213520755editdlrm
rsync5348880755editdlrm
rsyslog-recover-qi.pl60980755editdlrm
run-parts19830755editdlrm
run-with-aspell850755editdlrm
runcon382720755editdlrm
rvi11805600755editdlrm
rview11805600755editdlrm
rvim30678560755editdlrm
sadf3426000755editdlrm
sar1390240755editdlrm
sccmap211120755editdlrm
scl377520755editdlrm
scl_enabled2580755editdlrm
scl_source18630755editdlrm
scp1053120755editdlrm
script376800755editdlrm
scriptreplay296960755editdlrm
scsi-rescan391610755editdlrm
scsi_logging_level85850755editdlrm
scsi_mandat36020755editdlrm
scsi_readcap13270755editdlrm
scsi_ready11210755editdlrm
scsi_satl38570755editdlrm
scsi_start12850755editdlrm
scsi_stop14740755editdlrm
scsi_temperature9360755editdlrm
sdiff1078560755editdlrm
sdptool2813600755editdlrm
secon260720755editdlrm
secret-tool216800755editdlrm
sed1180400755editdlrm
sedismod2802320755editdlrm
sedispol2032480755editdlrm
semodule_expand125760755editdlrm
semodule_link125760755editdlrm
semodule_package170800755editdlrm
semodule_unpackage125920755editdlrm
seq547280755editdlrm
sessreg178000755editdlrm
setarch212560755editdlrm
setfacl460640755editdlrm
setfont462720755editdlrm
setkeycodes128640755editdlrm
setleds170000755editdlrm
setmetamode128640755editdlrm
setpriv462400755editdlrm
setsid167680755editdlrm
setterm462080755editdlrm
setup-nsssysinit15390755editdlrm
setup-nsssysinit.sh15390755editdlrm
setvtrgb170400755editdlrm
sfdp125520755editdlrm
sftp1635840755editdlrm
sg434800755editdlrm
sginfo766480755editdlrm
sgm_dd333440755editdlrm
sgp_dd378480755editdlrm
sg_bg_ctl164640755editdlrm
sg_compare_and_write214080755editdlrm
sg_copy_results213200755editdlrm
sg_dd456640755editdlrm
sg_decode_sense208320755editdlrm
sg_emc_trespass125600755editdlrm
sg_format341840755editdlrm
sg_get_config341280755editdlrm
sg_get_lba_status209680755editdlrm
sg_ident165680755editdlrm
sg_inq1207440755editdlrm
sg_logs1536320755editdlrm
sg_luns254640755editdlrm
sg_map168080755editdlrm
sg_map26254800755editdlrm
sg_modes449440755editdlrm
sg_opcodes293760755editdlrm
sg_persist349600755editdlrm
sg_prevent123680755editdlrm
sg_raw249840755editdlrm
sg_rbuf213520755editdlrm
sg_rdac162640755editdlrm
sg_read250160755editdlrm
sg_readcap213760755editdlrm
sg_read_attr356400755editdlrm
sg_read_block_limits124160755editdlrm
sg_read_buffer214800755editdlrm
sg_read_long166640755editdlrm
sg_reassign166240755editdlrm
sg_referrals166320755editdlrm
sg_rep_zones211680755editdlrm
sg_requests167040755editdlrm
sg_reset171440755editdlrm
sg_reset_wp165680755editdlrm
sg_rmsn123680755editdlrm
sg_rtpg165680755editdlrm
sg_safte207600755editdlrm
sg_sanitize251840755editdlrm
sg_sat_identify171280755editdlrm
sg_sat_phy_event210880755editdlrm
sg_sat_read_gplog166960755editdlrm
sg_sat_set_features166640755editdlrm
sg_scan169120755editdlrm
sg_seek172720755editdlrm
sg_senddiag258880755editdlrm
sg_ses1210880755editdlrm
sg_ses_microcode302000755editdlrm
sg_start214480755editdlrm
sg_stpg208000755editdlrm
sg_stream_ctl207600755editdlrm
sg_sync166240755editdlrm
sg_test_rwbuf212480755editdlrm
sg_timestamp212560755editdlrm
sg_turs171600755editdlrm
sg_unmap249120755editdlrm
sg_verify209600755editdlrm
sg_vpd1113760755editdlrm
sg_write_buffer217680755editdlrm
sg_write_long167360755editdlrm
sg_write_same250800755editdlrm
sg_write_verify212960755editdlrm
sg_write_x550560755editdlrm
sg_wr_mode207920755editdlrm
sg_xcopy415760755editdlrm
sg_zone166960755editdlrm
sh11546800755editdlrm
sha1hmac334400755editdlrm
sha1sum466480755editdlrm
sha224hmac334400755editdlrm
sha224sum466720755editdlrm
sha256hmac334400755editdlrm
sha256sum466720755editdlrm
sha384hmac334400755editdlrm
sha384sum466800755editdlrm
sha512hmac334400755editdlrm
sha512sum466880755editdlrm
shasum98920755editdlrm
showconsolefont212320755editdlrm
showkey169760755editdlrm
showrgb133680755editdlrm
shred633360755editdlrm
shuf594880755editdlrm
sieve-dump358720755editdlrm
sieve-filter455520755editdlrm
sieve-test413920755editdlrm
sievec361280755editdlrm
signver1175440755editdlrm
sim_client166640755editdlrm
size340480755editdlrm
skill294880755editdlrm
slabinfo370160755editdlrm
slabtop213440755editdlrm
sleep382960755editdlrm
slencheck125840755editdlrm
sm3hmac334400755editdlrm
snice294880755editdlrm
socat4162480755editdlrm
soelim435760755editdlrm
sort1264320755editdlrm
sotruss42810755editdlrm
spell1220755editdlrm
splain191500755editdlrm
split594400755editdlrm
sprof293600755editdlrm
sqlite313465120755editdlrm
ssh7757760755editdlrm
ssh-add3544480755editdlrm
ssh-agent3333840755editdlrm
ssh-copy-id106940755editdlrm
ssh-keygen4374320755editdlrm
ssh-keyscan4429920755editdlrm
ssltap1336400755editdlrm
sss_ssh_authorizedkeys294720755editdlrm
sss_ssh_knownhostsproxy294720755editdlrm
stat882320755editdlrm
stdbuf506880755editdlrm
strace20298320755editdlrm
strace-log-merge18210755editdlrm
stream121120755editdlrm
strings383280755editdlrm
strip2458560755editdlrm
stty794720755editdlrm
stunnel2305040755editdlrm
su501684750editdlrm
sudo1910004111editdlrm
sudoedit1910004111editdlrm
sudoreplay1220560111editdlrm
sum466240755editdlrm
sw-engine210956320755editdlrm
sxpm295040755editdlrm
sync382560755editdlrm
systemctl2236960755editdlrm
systemd-analyze16348640755editdlrm
systemd-ask-password123120755editdlrm
systemd-cat164160755editdlrm
systemd-cgls168320755editdlrm
systemd-cgtop336720755editdlrm
systemd-delta250320755editdlrm
systemd-detect-virt121680755editdlrm
systemd-escape163920755editdlrm
systemd-firstboot378720755editdlrm
systemd-hwdb296000755editdlrm
systemd-inhibit164160755editdlrm
systemd-machine-id-setup253440755editdlrm
systemd-mount538960755editdlrm
systemd-notify164160755editdlrm
systemd-path164000755editdlrm
systemd-resolve2004480755editdlrm
systemd-run501200755editdlrm
systemd-socket-activate253680755editdlrm
systemd-stdio-bridge164080755editdlrm
systemd-sysusers543200755editdlrm
systemd-tmpfiles750560755editdlrm
systemd-tty-ask-password-agent336080755editdlrm
systemd-umount538960755editdlrm
tabs169520755editdlrm
tac424880755editdlrm
tail759120755editdlrm
tapestat423120755editdlrm
tar4597680755editdlrm
taskset381520755editdlrm
tbl1583200755editdlrm
tclsh92560755editdlrm
tclsh8.692560755editdlrm
tcptraceroute15850755editdlrm
teamd1643680755editdlrm
teamdctl310960755editdlrm
teamnl209600755editdlrm
tee424720755editdlrm
test548480755editdlrm
tic873600755editdlrm
timedatectl378480755editdlrm
timeout428640755editdlrm
tload171600755editdlrm
tmon405760755editdlrm
tmpwatch363200755editdlrm
toe168480755editdlrm
top1246160755editdlrm
touch961920755editdlrm
tput253920755editdlrm
tr508160755editdlrm
tracepath209280755editdlrm
traceroute726720755editdlrm
traceroute6726720755editdlrm
tred169840755editdlrm
troff8243440755editdlrm
true341280755editdlrm
truncate423520755editdlrm
trust2248240755editdlrm
tset253520755editdlrm
tsort424880755editdlrm
tty341120755editdlrm
turbostat1339360755editdlrm
twopi125520755editdlrm
type280755editdlrm
tzselect153700755editdlrm
uapi34969120755editdlrm
ucs2any250000755editdlrm
udevadm4347520755editdlrm
udisksctl621920755editdlrm
ul210800755editdlrm
ulimit300755editdlrm
umask290755editdlrm
umount335360755editdlrm
unalias310755editdlrm
uname382240755editdlrm
uname26212560755editdlrm
unexpand466880755editdlrm
unflatten170240755editdlrm
unicode_start26130755editdlrm
unicode_stop3630755editdlrm
uniq508320755editdlrm
unlink341440755editdlrm
unpigz1283920755editdlrm
unshare255280755editdlrm
unversioned-python1570755editdlrm
unxz840560755editdlrm
unzip2067280755editdlrm
unzipsfx1039120755editdlrm
update-ca-trust12680755editdlrm
update-crypto-policies870755editdlrm
update-gtk-immodules3130755editdlrm
update-mime-database585920755editdlrm
uptime128880755editdlrm
users382960755editdlrm
usleep121440755editdlrm
utmpdump293520755editdlrm
uuclient162560755editdlrm
uuidgen167680755editdlrm
uuidparse380240755editdlrm
vdir1432560755editdlrm
vi11805600755editdlrm
view11805600755editdlrm
vim30678560755editdlrm
vimdiff30678560755editdlrm
vimdot10820755editdlrm
vimtutor21210755editdlrm
vlock213280755editdlrm
vmstat376720755editdlrm
w212480755editdlrm
wait280755editdlrm
wall338400755editdlrm
watch298880755editdlrm
watchgnupg168320755editdlrm
wc508320755editdlrm
wdctl378640755editdlrm
wget5339440755editdlrm
whatis553360755editdlrm
whereis299760755editdlrm
which300880755editdlrm
whiptail338800755editdlrm
who548800755editdlrm
whoami341360755editdlrm
wmf2eps175600755editdlrm
wmf2fig175600755editdlrm
wmf2gd175520755editdlrm
wmf2svg175760755editdlrm
wmf2x175360755editdlrm
word-list-compress122800755editdlrm
write211120755editdlrm
wsrep_sst_backup24470755editdlrm
wsrep_sst_common701410644editdlrm
wsrep_sst_mariabackup542650755editdlrm
wsrep_sst_mysqldump82960755editdlrm
wsrep_sst_rsync314730755editdlrm
wsrep_sst_rsync_wan314730755editdlrm
x86_64212560755editdlrm
x86_64-redhat-linux-c++12666160755editdlrm
x86_64-redhat-linux-g++12666160755editdlrm
x86_64-redhat-linux-gcc12665760755editdlrm
x86_64-redhat-linux-gcc-812665760755editdlrm
x86_64-redhat-linux-gnu-pkg-config4240755editdlrm
x86_energy_perf_policy327200755editdlrm
xargs758880755editdlrm
xb-tool293920755editdlrm
xgamma174880755editdlrm
xgettext2906960755editdlrm
xhost175280755editdlrm
xinput651360755editdlrm
xkill175120755editdlrm
xml2-config17460755editdlrm
xmlcatalog208720755editdlrm
xmllint751360755editdlrm
xmlwf378560755editdlrm
xmodmap409360755editdlrm
xorg-x11-fonts-update-dirs13220744editdlrm
xrandr670320755editdlrm
xrdb348000755editdlrm
xrefresh183680755editdlrm
xset380880755editdlrm
xsetpointer133680755editdlrm
xsetroot219520755editdlrm
xslt-config24180755editdlrm
xsltproc291520755editdlrm
xstdcmap181040755editdlrm
xsubpp50800755editdlrm
xxd210320755editdlrm
xz840560755editdlrm
xzcat840560755editdlrm
xzcmp66320755editdlrm
xzdec168800755editdlrm
xzdiff66320755editdlrm
xzegrep59020755editdlrm
xzfgrep59020755editdlrm
xzgrep59020755editdlrm
xzless18020755editdlrm
xzmore21610755editdlrm
yat2m341440755editdlrm
yes341680755editdlrm
ypdomainname216640755editdlrm
yum21040755editdlrm
yum-builddep37020755editdlrm
yum-config-manager37020755editdlrm
yum-debug-dump37020755editdlrm
yum-debug-restore37020755editdlrm
yum-groups-manager37020755editdlrm
yumdownloader37020755editdlrm
zcat19830755editdlrm
zcmp16770755editdlrm
zdiff58790755editdlrm
zegrep290755editdlrm
zfgrep290755editdlrm
zforce20800755editdlrm
zgrep75820755editdlrm
zip2344960755editdlrm
zipcloak1053760755editdlrm
zipdetails505760755editdlrm
zipgrep29530755editdlrm
zipinfo2067280755editdlrm
zipnote1001040755editdlrm
zipsplit1001040755editdlrm
zless22050755editdlrm
zmore18410755editdlrm
znew45520755editdlrm
zone2json14526480755editdlrm
zone2sql14737760755editdlrm
zsoelim435760755editdlrm
[548880755editdlrm
Edit: /usr/bin/firewall-offline-cmd (123624B)
#!/usr/libexec/platform-python -s # -*- coding: utf-8 -*- # # Copyright (C) 2009-2016 Red Hat, Inc. # # Authors: # Thomas Woerner # Jiri Popelka # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; either version 2 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program. If not, see . # from gi.repository import GObject import sys sys.modules['gobject'] = GObject import argparse import os from firewall.client import FirewallClientIPSetSettings, \ FirewallClientZoneSettings, FirewallClientServiceSettings, \ FirewallClientIcmpTypeSettings, FirewallClientHelperSettings, \ FirewallClientPolicySettings from firewall.errors import FirewallError from firewall import config from firewall.core.fw import Firewall from firewall.functions import joinArgs, splitArgs, getPortRange from firewall.core.io.functions import check_config from firewall.core.io.zone import zone_reader from firewall.core.io.policy import policy_reader from firewall.core.io.service import service_reader from firewall.core.io.ipset import ipset_reader from firewall.core.io.icmptype import icmptype_reader from firewall.core.io.helper import helper_reader from firewall.command import FirewallCommand # check for root user def assert_root(): if os.getuid() != 0: sys.stderr.write("You need to be root to run %s.\n" % sys.argv[0]) sys.exit(-1) SYSTEM_CONFIG_FIREWALL = config.SYSCONFIGDIR + '/system-config-firewall' def __usage(): sys.stdout.write(""" Usage: firewall-offline-cmd [OPTIONS...] If no options are given, configuration from '%s' will be migrated. General Options -h, --help Prints a short help text and exits -V, --version Print the version string of firewalld -q, --quiet Do not print status messages --system-config Path to firewalld system configuration --default-config Path to firewalld default configuration --check-config Check system and default configuration Lokkit Compatibility Options --migrate-system-config-firewall= Import configuration data from the given configuration file. --enabled Enable firewall (default) --disabled Disable firewall --addmodule= Ignored option, was used to enable an iptables module --removemodule= Ignored option, was used to disable an iptables module -s , --service= Enable a service in the default zone (example: ssh) --remove-service= Disable a service in the default zone (example: ssh) -p [-]:, --port=[-]: Enable a port in the default zone (example: ssh:tcp) -t , --trust= Bind an interface to the trusted zone -m , --masq= Enables masquerading in the default zone, interface argument is ignored. This is IPv4 only. --custom-rules=[:][:] Ignored option. Was used to add custom rules to the firewall (Example: ipv4:filter:%s/ipv4_filter_addon) --forward-port=if=:port=:proto=[:toport=][:toaddr=] Forward the port with protocol for the interface to either another local destination port (no destination address given) or to an other destination address with an optional destination port. This will be added to the default zone. This is IPv4 only. --block-icmp= Block this ICMP type in the default zone. The default is to accept all ICMP types. Log Denied Options --get-log-denied Print the log denied value --set-log-denied= Set log denied value Automatic Helpers Options --get-automatic-helpers Print the automatic helpers value --set-automatic-helpers= Set automatic helpers value Zone Options --get-default-zone Print default zone for connections and interfaces --set-default-zone= Set default zone --get-zones Print predefined zones --get-services Print predefined services --get-icmptypes Print predefined icmptypes --get-zone-of-interface= Print name of the zone the interface is bound to --get-zone-of-source=[/]||ipset: Print name of the zone the source is bound to --list-all-zones List everything added for or enabled in all zones --new-zone= Add a new empty zone --new-zone-from-file= [--name=] Add a new zone from file with optional name override [P only] --delete-zone= Delete an existing zone --load-zone-defaults= Load zone default settings --zone= Use this zone to set or query options, else default zone Usable for options marked with [Z] --info-zone= Print information about a zone --path-zone= Print file path of a zone Policy Options --get-policies Print predefined policies --list-all-policies List everything added for or enabled in all policies --new-policy= Add a new empty policy --new-policy-from-file= [--name=] Add a new policy from file with optional name override [P only] --delete-policy= Delete an existing policy --load-policy-defaults= Load policy default settings --policy= Use this policy to set or query options Usable for options marked with [O] --info-policy= Print information about a policy --path-policy= Print file path of a policy IPSet Options --new-ipset= --type= [--option=[=]].. Add a new empty ipset --new-ipset-from-file= [--name=] Add a new ipset from file with optional name override [P only] --delete-ipset= Delete an existing ipset --load-ipset-defaults= Load ipset default settings --info-ipset= Print information about an ipset --path-ipset= Print file path of an ipset --get-ipsets Print predefined ipsets --ipset= --set-description= Set new description to ipset --ipset= --get-description Print description for ipset --ipset= --set-short= Set new short description to ipset --ipset= --get-short Print short description for ipset --ipset= --add-entry= Add a new entry to an ipset --ipset= --remove-entry= Remove an entry from an ipset --ipset= --query-entry= Return whether ipset has an entry --ipset= --get-entries List entries of an ipset --ipset= --add-entries-from-file= Add a new entries to an ipset --ipset= --remove-entries-from-file= Remove entries from an ipset IcmpType Options --new-icmptype= Add a new empty icmptype --new-icmptype-from-file= [--name=] Add a new icmptype from file with optional name override [P only] --delete-icmptype= Delete an existing icmptype --load-icmptype-defaults= Load icmptype default settings --info-icmptype= Print information about an icmptype --path-icmptype= Print file path of an icmptype --icmptype= --set-description= Set new description to icmptype --icmptype= --get-description Print description for icmptype --icmptype= --set-short= Set new short description to icmptype --icmptype= --get-short Print short description for icmptype --icmptype= --add-destination= Enable destination for ipv in icmptype --icmptype= --remove-destination= Disable destination for ipv in icmptype --icmptype= --query-destination= Return whether destination ipv is enabled in icmptype --icmptype= --get-destinations List destinations in icmptype Service Options --new-service= Add a new empty service --new-service-from-file= [--name=] Add a new service from file with optional name override [P only] --delete-service= Delete an existing service --load-service-defaults= Load icmptype default settings --info-service= Print information about a service --path-service= Print file path of a service --service= --set-description= Set new description to service --service= --get-description Print description for service --service= --set-short= Set new short description to service --service= --get-short Print short description for service --service= --add-port=[-]/ Add a new port to service --service= --remove-port=[-]/ Remove a port from service --service= --query-port=[-]/ Return whether the port has been added for service --service= --get-ports List ports of service --service= --add-protocol= Add a new protocol to service --service= --remove-protocol= Remove a protocol from service --service= --query-protocol= Return whether the protocol has been added for service --service= --get-protocols List protocols of service --service= --add-source-port=[-]/ Add a new source port to service --service= --remove-source-port=[-]/ Remove a source port from service --service= --query-source-port=[-]/ Return whether the source port has been added for service [P only] --service= --get-source-ports List source ports of service --service= --add-helper= Add a new helper to service --service= --remove-helper= Remove a helper from service --service= --query-helper= Return whether the helper has been added for service --service= --get-service-helpers List helpers of service --service= --set-destination=:
[/] Set destination for ipv to address in service --service= --remove-destination= Disable destination for ipv i service --service= --query-destination=:
[/] Return whether destination ipv is set for service --service= --get-destinations List destinations in service --service= --add-include= Add a new include to service --service= --remove-include= Remove a include from service --service= --query-include= Return whether the include has been added for service --service= --get-includes List includes of service Options to Adapt and Query Zones and Policies --list-all List everything added for or enabled [Z] [O] --set-description= Set new description [Z] [O] --get-description Print description [Z] [O] --get-target Get the target [Z] [O] --set-target= Set the target [Z] [O] --set-short= Set new short description to zone [Z] [O] --get-short Print short description for zone [Z] [O] --list-services List services added [Z] [O] --add-service= Add a service [Z] [O] --remove-service-from-zone= Remove a service from a zone [Z] --remove-service-from-policy= Remove a service from a policy [O] --query-service= Return whether service has been added [Z] [O] --list-ports List ports added [Z] [O] --add-port=[-]/ Add the port [Z] [O] --remove-port=[-]/ Remove the port [Z] [O] --query-port=[-]/ Return whether the port has been added [Z] [O] --list-protocols List protocols added [Z] [O] --add-protocol= Add the protocol [Z] [O] --remove-protocol= Remove the protocol [Z] [O] --query-protocol= Return whether the protocol has been added [Z] [O] --list-source-ports List source ports added [Z] [O] --add-source-port=[-]/ Add the source port [Z] [O] --remove-source-port=[-]/ Remove the source port [Z] [O] --query-source-port=[-]/ Return whether the source port has been added [Z] [O] --list-icmp-blocks List Internet ICMP type blocks added [Z] [O] --add-icmp-block= Add an ICMP block [Z] [O] --remove-icmp-block= Remove the ICMP block [Z] [O] --query-icmp-block= Return whether an ICMP block has been added [Z] [O] --list-forward-ports List IPv4 forward ports added [Z] [O] --add-forward-port=port=[-]:proto=[:toport=[-]][:toaddr=
[/]] Add the IPv4 forward port [Z] [O] --remove-forward-port=port=[-]:proto=[:toport=[-]][:toaddr=
[/]] Remove the IPv4 forward port [Z] [O] Options to Adapt and Query Zones --add-icmp-block-inversion Enable inversion of icmp blocks for a zone [Z] --remove-icmp-block-inversion Disable inversion of icmp blocks for a zone [Z] --query-icmp-block-inversion Return whether inversion of icmp blocks has been enabled for a zone [Z] --add-forward Enable forwarding of packets between interfaces and sources in a zone [Z] --remove-forward Disable forwarding of packets between interfaces and sources in a zone [Z] --query-forward Return whether forwarding of packets between interfaces and sources has been enabled for a zone [Z] Options to Adapt and Query Policies --get-priority Get the priority [O] --set-priority= Set the priority [O] --list-ingress-zones List ingress zones that are bound to a policy [O] --add-ingress-zone= Add the ingress zone to a policy [O] --remove-ingress-zone= Remove the ingress zone from a policy [O] --query-ingress-zone= Query whether the ingress zone has been adedd to a policy [O] --list-egress-zones List egress zones that are bound to a policy [O] --add-egress-zone= Add the egress zone to a policy [O] --remove-egress-zone= Remove the egress zone from a policy [O] --query-egress-zone= Query whether the egress zone has been adedd to a policy [O] Options to Handle Bindings of Interfaces --list-interfaces List interfaces that are bound to a zone [Z] --add-interface= Bind the to a zone [Z] --change-interface= Change zone the is bound to [Z] --query-interface= Query whether is bound to a zone [Z] --remove-interface= Remove binding of from a zone [Z] Options to Handle Bindings of Sources --list-sources List sources that are bound to a zone [Z] --add-source=[/]||ipset: Bind the source to a zone [Z] --change-source=[/]||ipset: Change zone the source is bound to [Z] --query-source=[/]||ipset: Query whether the source is bound to a zone [Z] --remove-source=[/]||ipset: Remove binding of the source from a zone [Z] Helper Options --new-helper= --module= [--family=] Add a new helper --new-helper-from-file= [--name=] Add a new helper from file with optional name --delete-helper= Delete an existing helper --load-helper-defaults= Load helper default settings --info-helper= Print information about an helper --path-helper= Print file path of an helper --get-helpers Print predefined helpers --helper= --set-description= Set new description to helper --helper= --get-description Print description for helper --helper= --set-short= Set new short description to helper --helper= --get-short Print short description for helper --helper= --add-port=[-]/ Add a new port to helper --helper= --remove-port=[-]/ Remove a port from helper --helper= --query-port=[-]/ Return whether the port has been added for helper --helper= --get-ports List ports of helper --helper= --set-module= Set module to helper --helper= --get-module Get module from helper --helper= --set-family={ipv4|ipv6|} Set family for helper --helper= --get-family Get module from helper Direct Options --direct First option for all direct options --get-all-chains Get all chains --get-chains {ipv4|ipv6|eb}
Get all chains added to the table --add-chain {ipv4|ipv6|eb}
Add a new chain to the table --remove-chain {ipv4|ipv6|eb}
Remove the chain from the table --query-chain {ipv4|ipv6|eb}
Return whether the chain has been added to the table --get-all-rules Get all rules --get-rules {ipv4|ipv6|eb}
Get all rules added to chain in table --add-rule {ipv4|ipv6|eb}
... Add rule to chain in table --remove-rule {ipv4|ipv6|eb}
... Remove rule with priority from chain in table --remove-rules {ipv4|ipv6|eb}
Remove rules from chain in table --query-rule {ipv4|ipv6|eb}
... Return whether a rule with priority has been added to chain in table --get-all-passthroughs Get all passthrough rules --get-passthroughs {ipv4|ipv6|eb} ... Get passthrough rules --add-passthrough {ipv4|ipv6|eb} ... Add a new passthrough rule --remove-passthrough {ipv4|ipv6|eb} ... Remove a passthrough rule --query-passthrough {ipv4|ipv6|eb} ... Return whether the passthrough rule has been added Lockdown Options --lockdown-on Enable lockdown. --lockdown-off Disable lockdown. --query-lockdown Query whether lockdown is enabled Lockdown Whitelist Options --list-lockdown-whitelist-commands List all command lines that are on the whitelist --add-lockdown-whitelist-command= Add the command to the whitelist --remove-lockdown-whitelist-command= Remove the command from the whitelist --query-lockdown-whitelist-command= Query whether the command is on the whitelist --list-lockdown-whitelist-contexts List all contexts that are on the whitelist --add-lockdown-whitelist-context= Add the context context to the whitelist --remove-lockdown-whitelist-context= Remove the context from the whitelist --query-lockdown-whitelist-context= Query whether the context is on the whitelist --list-lockdown-whitelist-uids List all user ids that are on the whitelist --add-lockdown-whitelist-uid= Add the user id uid to the whitelist --remove-lockdown-whitelist-uid= Remove the user id uid from the whitelist --query-lockdown-whitelist-uid= Query whether the user id uid is on the whitelist --list-lockdown-whitelist-users List all user names that are on the whitelist --add-lockdown-whitelist-user= Add the user name user to the whitelist --remove-lockdown-whitelist-user= Remove the user name user from the whitelist --query-lockdown-whitelist-user= Query whether the user name user is on the whitelist Polkit Options --policy-server Change Polkit actions to 'server' (more restricted) --policy-desktop Change Polkit actions to 'desktop' (less restricted) """ % (SYSTEM_CONFIG_FIREWALL, config.SYSCONFIGDIR)) def parse_port_lokkit(value): try: (port, proto) = value.split(":") except Exception: cmd.fail("bad port (most likely missing protocol), correct syntax is portid[-portid]:protocol") return (port, proto) def pk_symlink(product='server'): _PK_DIR = '/usr/share/polkit-1/actions/' _PK_NAME = 'org.fedoraproject.FirewallD1.' os.chdir(_PK_DIR) if os.path.isfile(_PK_NAME+product+'.policy.choice'): if os.path.isfile(_PK_NAME+'policy'): os.remove(_PK_NAME+'policy') os.symlink(_PK_NAME+product+'.policy.choice', _PK_NAME+'policy') cmd.print_and_exit('symlink '+_PK_DIR+_PK_NAME+product+'.policy.choice -> '+_PK_NAME+'policy') else: cmd.fail('no such file '+_PK_DIR+_PK_NAME+product+'.policy.choice') # system-config-firewall def read_sysconfig_args(config_file=SYSTEM_CONFIG_FIREWALL): filename = None if os.path.exists(config_file) and os.path.isfile(config_file): filename = config_file try: f = open(filename, 'r') except Exception: return None argv = [ ] for line in f: if not line: break line = line.strip() if len(line) < 1 or line[0] == '#': continue argv.append(line) f.close() return argv parser = argparse.ArgumentParser(usage="see firewall-offline-cmd man page", add_help=False) parser_group_output = parser.add_mutually_exclusive_group() parser_group_output.add_argument("-v", "--verbose", action="store_true") parser_group_output.add_argument("-q", "--quiet", action="store_true") parser_group_lokkit = parser.add_argument_group() parser_group_lokkit.add_argument("--enabled", action="store_true") parser_group_lokkit.add_argument("--disabled", action="store_true") parser_group_lokkit.add_argument("--addmodule", metavar="", action='append') parser_group_lokkit.add_argument("--removemodule", metavar="", action='append') parser_group_lokkit.add_argument("--service", "-s", metavar="", action='append') parser_group_lokkit.add_argument("--remove-service", metavar="", action='append') parser_group_lokkit.add_argument("--port", "-p", metavar="", action='append') parser_group_lokkit.add_argument("--trust", "-t", metavar="", action='append') parser_group_lokkit.add_argument("--masq", "-m", metavar="", action='append') parser_group_lokkit.add_argument("--custom-rules", metavar="", action='append') parser_group_lokkit.add_argument("--forward-port", metavar="", action='append') parser_group_lokkit.add_argument("--block-icmp", metavar="", action='append') parser.add_argument("--system-config", metavar="path") parser.add_argument("--default-config", metavar="path") parser.add_argument("--check-config", action="store_true") parser_group_standalone = parser.add_mutually_exclusive_group() parser_group_standalone.add_argument("-h", "--help", action="store_true") parser_group_standalone.add_argument("-V", "--version", action="store_true") parser_group_standalone.add_argument("--get-log-denied", action="store_true") parser_group_standalone.add_argument("--set-log-denied", metavar="") parser_group_standalone.add_argument("--get-automatic-helpers", action="store_true") parser_group_standalone.add_argument("--set-automatic-helpers", metavar="") parser_group_standalone.add_argument("--policy-server", action="store_true") parser_group_standalone.add_argument("--policy-desktop", action="store_true") parser_group_standalone.add_argument("--lockdown-on", action="store_true") parser_group_standalone.add_argument("--lockdown-off", action="store_true") parser_group_standalone.add_argument("--query-lockdown", action="store_true") parser_group_standalone.add_argument("--get-default-zone", action="store_true") parser_group_standalone.add_argument("--set-default-zone", metavar="") parser_group_standalone.add_argument("--get-zones", action="store_true") parser_group_standalone.add_argument("--get-policies", action="store_true") parser_group_standalone.add_argument("--get-services", action="store_true") parser_group_standalone.add_argument("--get-icmptypes", action="store_true") parser_group_standalone.add_argument("--get-zone-of-interface", metavar="", action='append') parser_group_standalone.add_argument("--get-zone-of-source", metavar="", action='append') parser_group_standalone.add_argument("--list-all-zones", action="store_true") parser_group_standalone.add_argument("--list-all-policies", action="store_true") parser_group_standalone.add_argument("--info-zone", metavar="") parser_group_standalone.add_argument("--info-policy", metavar="") parser_group_standalone.add_argument("--info-service", metavar="") parser_group_standalone.add_argument("--info-icmptype", metavar="") parser_group_standalone.add_argument("--info-ipset", metavar="") parser_group_standalone.add_argument("--info-helper", metavar="") parser_group_config = parser.add_mutually_exclusive_group() parser_group_config.add_argument("--new-icmptype", metavar="") parser_group_config.add_argument("--new-icmptype-from-file", metavar="") parser_group_config.add_argument("--delete-icmptype", metavar="") parser_group_config.add_argument("--load-icmptype-defaults", metavar="") parser_group_config.add_argument("--new-service", metavar="") parser_group_config.add_argument("--new-service-from-file", metavar="") parser_group_config.add_argument("--delete-service", metavar="") parser_group_config.add_argument("--load-service-defaults", metavar="") parser_group_config.add_argument("--new-zone", metavar="") parser_group_config.add_argument("--new-zone-from-file", metavar="") parser_group_config.add_argument("--delete-zone", metavar="") parser_group_config.add_argument("--load-zone-defaults", metavar="") parser_group_config.add_argument("--new-policy", metavar="") parser_group_config.add_argument("--new-policy-from-file", metavar="") parser_group_config.add_argument("--delete-policy", metavar="") parser_group_config.add_argument("--load-policy-defaults", metavar="") parser_group_config.add_argument("--new-ipset", metavar="") parser_group_config.add_argument("--new-ipset-from-file", metavar="") parser_group_config.add_argument("--delete-ipset", metavar="") parser_group_config.add_argument("--load-ipset-defaults", metavar="") parser_group_config.add_argument("--new-helper", metavar="") parser_group_config.add_argument("--new-helper-from-file", metavar="") parser_group_config.add_argument("--delete-helper", metavar="") parser_group_config.add_argument("--load-helper-defaults", metavar="") parser_group_config.add_argument("--path-zone", metavar="") parser_group_config.add_argument("--path-policy", metavar="") parser_group_config.add_argument("--path-service", metavar="") parser_group_config.add_argument("--path-icmptype", metavar="") parser_group_config.add_argument("--path-ipset", metavar="") parser_group_config.add_argument("--path-helper", metavar="") parser.add_argument("--name", default="", metavar="") parser_group_lockdown_whitelist = parser.add_mutually_exclusive_group() parser_group_lockdown_whitelist.add_argument("--list-lockdown-whitelist-commands", action="store_true") parser_group_lockdown_whitelist.add_argument("--add-lockdown-whitelist-command", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--remove-lockdown-whitelist-command", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--query-lockdown-whitelist-command", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--list-lockdown-whitelist-contexts", action="store_true") parser_group_lockdown_whitelist.add_argument("--add-lockdown-whitelist-context", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--remove-lockdown-whitelist-context", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--query-lockdown-whitelist-context", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--list-lockdown-whitelist-uids", action="store_true") parser_group_lockdown_whitelist.add_argument("--add-lockdown-whitelist-uid", metavar="", type=int, action='append') parser_group_lockdown_whitelist.add_argument("--remove-lockdown-whitelist-uid", metavar="", type=int, action='append') parser_group_lockdown_whitelist.add_argument("--query-lockdown-whitelist-uid", metavar="", type=int, action='append') parser_group_lockdown_whitelist.add_argument("--list-lockdown-whitelist-users", action="store_true") parser_group_lockdown_whitelist.add_argument("--add-lockdown-whitelist-user", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--remove-lockdown-whitelist-user", metavar="", action='append') parser_group_lockdown_whitelist.add_argument("--query-lockdown-whitelist-user", metavar="", action='append') parser.add_argument("--zone", default="", metavar="") parser.add_argument("--policy", default="", metavar="") parser_group_zone_or_policy = parser.add_mutually_exclusive_group() parser_group_zone_or_policy.add_argument("--add-interface", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-interface", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-interface", metavar="", action='append') parser_group_zone_or_policy.add_argument("--change-interface", "--change-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--list-interfaces", action="store_true") parser_group_zone_or_policy.add_argument("--add-source", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-source", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-source", metavar="", action='append') parser_group_zone_or_policy.add_argument("--change-source", metavar="", action='append') parser_group_zone_or_policy.add_argument("--list-sources", action="store_true") parser_group_zone_or_policy.add_argument("--add-ingress-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-ingress-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-ingress-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--list-ingress-zones", action="store_true") parser_group_zone_or_policy.add_argument("--add-egress-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-egress-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-egress-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--list-egress-zones", action="store_true") parser_group_zone_or_policy.add_argument("--add-rich-rule", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-rich-rule", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-rich-rule", metavar="", action='append') parser_group_zone_or_policy.add_argument("--add-service", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-service-from-zone", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-service-from-policy", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-service", metavar="", action='append') parser_group_zone_or_policy.add_argument("--add-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--add-protocol", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-protocol", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-protocol", metavar="", action='append') parser_group_zone_or_policy.add_argument("--add-source-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-source-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-source-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--add-forward", action="store_true") parser_group_zone_or_policy.add_argument("--remove-forward", action="store_true") parser_group_zone_or_policy.add_argument("--query-forward", action="store_true") parser_group_zone_or_policy.add_argument("--add-masquerade", action="store_true") parser_group_zone_or_policy.add_argument("--remove-masquerade", action="store_true") parser_group_zone_or_policy.add_argument("--query-masquerade", action="store_true") parser_group_zone_or_policy.add_argument("--add-icmp-block", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-icmp-block", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-icmp-block", metavar="", action='append') parser_group_zone_or_policy.add_argument("--add-icmp-block-inversion", action="store_true") parser_group_zone_or_policy.add_argument("--remove-icmp-block-inversion", action="store_true") parser_group_zone_or_policy.add_argument("--query-icmp-block-inversion", action="store_true") parser_group_zone_or_policy.add_argument("--add-forward-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--remove-forward-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--query-forward-port", metavar="", action='append') parser_group_zone_or_policy.add_argument("--list-rich-rules", action="store_true") parser_group_zone_or_policy.add_argument("--list-services", action="store_true") parser_group_zone_or_policy.add_argument("--list-ports", action="store_true") parser_group_zone_or_policy.add_argument("--list-protocols", action="store_true") parser_group_zone_or_policy.add_argument("--list-icmp-blocks", action="store_true") parser_group_zone_or_policy.add_argument("--list-forward-ports", action="store_true") parser_group_zone_or_policy.add_argument("--list-source-ports", action="store_true") parser_group_zone_or_policy.add_argument("--list-all", action="store_true") parser_group_zone_or_policy.add_argument("--get-target", action="store_true") parser_group_zone_or_policy.add_argument("--set-target", metavar="") parser_group_zone_or_policy.add_argument("--get-priority", action="store_true") parser_group_zone_or_policy.add_argument("--set-priority", metavar="") parser.add_argument("--option", metavar="[=]", action='append') parser.add_argument("--type", metavar="") parser.add_argument("--ipset", metavar="") parser_ipset = parser.add_mutually_exclusive_group() #parser_ipset.add_argument("--add-option", metavar="[=]") #parser_ipset.add_argument("--remove-option", metavar="[=]") #parser_ipset.add_argument("--query-option", metavar="[=]") #parser_ipset.add_argument("--get-options", action="store_true") parser_ipset.add_argument("--get-ipsets", action="store_true") parser_ipset.add_argument("--add-entry", metavar="", action='append') parser_ipset.add_argument("--remove-entry", metavar="", action='append') parser_ipset.add_argument("--query-entry", metavar="", action='append') parser_ipset.add_argument("--get-entries", action="store_true") parser_ipset.add_argument("--add-entries-from-file", metavar="", action='append') parser_ipset.add_argument("--remove-entries-from-file", metavar="", action='append') parser.add_argument("--icmptype", metavar="") parser_icmptype = parser.add_mutually_exclusive_group() parser_icmptype.add_argument("--add-destination", metavar="", action='append') parser_icmptype.add_argument("--remove-destination", metavar="", action='append') parser_icmptype.add_argument("--query-destination", metavar="", action='append') parser_icmptype.add_argument("--get-destinations", action="store_true") parser_service = parser.add_mutually_exclusive_group() parser_service.add_argument("--get-ports", action="store_true") parser_service.add_argument("--get-source-ports", action="store_true") parser_service.add_argument("--get-protocols", action="store_true") parser_service.add_argument("--add-module", metavar="", action='append') parser_service.add_argument("--remove-module", metavar="", action='append') parser_service.add_argument("--query-module", metavar="", action='append') parser_service.add_argument("--get-modules", action="store_true") parser_service.add_argument("--add-helper", metavar="", action='append') parser_service.add_argument("--remove-helper", metavar="", action='append') parser_service.add_argument("--query-helper", metavar="", action='append') parser_service.add_argument("--get-service-helpers", action="store_true") parser_service.add_argument("--add-include", metavar="", action='append') parser_service.add_argument("--remove-include", metavar="", action='append') parser_service.add_argument("--query-include", metavar="", action='append') parser_service.add_argument("--get-includes", action="store_true") parser_service.add_argument("--set-destination", metavar="", action='append') parser_service.add_argument("--get-destination", action="store_true") parser_service.add_argument("--set-description", metavar="") parser_service.add_argument("--get-description", action="store_true") parser_service.add_argument("--set-short", metavar="") parser_service.add_argument("--get-short", action="store_true") parser.add_argument("--helper", metavar="") parser.add_argument("--family", metavar="") parser.add_argument("--module", metavar="") parser_helper = parser.add_mutually_exclusive_group() #parser_helper.add_argument("--get-ports", action="store_true") parser_helper.add_argument("--get-helpers", action="store_true") parser_helper.add_argument("--set-module", metavar="") parser_helper.add_argument("--get-module", action="store_true") #parser_helper.add_argument("--query-module", metavar="") parser_helper.add_argument("--set-family", metavar="|''", nargs="*") parser_helper.add_argument("--get-family", action="store_true") parser.add_argument("--direct", action="store_true") # not possible to have sequences of options here parser_direct = parser.add_mutually_exclusive_group() parser_direct.add_argument("--add-passthrough", nargs=argparse.REMAINDER, metavar=("{ ipv4 | ipv6 | eb }", "")) parser_direct.add_argument("--remove-passthrough", nargs=argparse.REMAINDER, metavar=("{ ipv4 | ipv6 | eb }", "")) parser_direct.add_argument("--query-passthrough", nargs=argparse.REMAINDER, metavar=("{ ipv4 | ipv6 | eb }", "")) parser_direct.add_argument("--get-passthroughs", nargs=1, metavar=("{ ipv4 | ipv6 | eb }")) parser_direct.add_argument("--get-all-passthroughs", action="store_true") parser_direct.add_argument("--add-chain", nargs=3, metavar=("{ ipv4 | ipv6 | eb }", "
", "")) parser_direct.add_argument("--remove-chain", nargs=3, metavar=("{ ipv4 | ipv6 | eb }", "
", "")) parser_direct.add_argument("--query-chain", nargs=3, metavar=("{ ipv4 | ipv6 | eb }", "
", "")) parser_direct.add_argument("--get-all-chains", action="store_true") parser_direct.add_argument("--get-chains", nargs=2, metavar=("{ ipv4 | ipv6 | eb }", "
")) parser_direct.add_argument("--add-rule", nargs=argparse.REMAINDER, metavar=("{ ipv4 | ipv6 | eb }", "
")) parser_direct.add_argument("--remove-rule", nargs=argparse.REMAINDER, metavar=("{ ipv4 | ipv6 | eb }", "
")) parser_direct.add_argument("--remove-rules", nargs=3, metavar=("{ ipv4 | ipv6 | eb }", "
")) parser_direct.add_argument("--query-rule", nargs=argparse.REMAINDER, metavar=("{ ipv4 | ipv6 | eb }", "
")) parser_direct.add_argument("--get-rules", nargs=3, metavar=("{ ipv4 | ipv6 | eb }", "
", "")) parser_direct.add_argument("--get-all-rules", action="store_true") ############################################################################## cmd = FirewallCommand() def myexcepthook(exctype, value, traceback): cmd.exception_handler(str(value)) sys.excepthook = myexcepthook if len(sys.argv) > 1 and \ any('--migrate-system-config-firewall' in arg for arg in sys.argv): args = sys.argv[1:] migration_parser = argparse.ArgumentParser( usage="see firewall-offline-cmd man page", add_help=False) migration_parser.add_argument("-h", "--help", action="store_true") migration_parser.add_argument("-v", "--verbose", action="store_true") migration_parser.add_argument("-q", "--quiet", action="store_true") migration_parser.add_argument("--migrate-system-config-firewall", metavar="", action='store') a,unknown = migration_parser.parse_known_args(args) cmd.set_quiet(a.quiet) cmd.set_verbose(a.verbose) if a.help: __usage() sys.exit(0) else: assert_root() if a.quiet: # it makes no sense to use --quiet with these options a.quiet = False cmd.set_quiet(a.quiet) cmd.fail("-q/--quiet can't be used with this option(s)") if a.migrate_system_config_firewall: args = read_sysconfig_args(a.migrate_system_config_firewall) if not args: cmd.fail("Opening of '%s' failed, exiting." % \ a.migrate_system_config_firewall) args += unknown elif len(sys.argv) > 1: i = -1 args = sys.argv[1:] if '--add-passthrough' in args: i = args.index('--add-passthrough') + 1 elif '--remove-passthrough' in args: i = args.index('--remove-passthrough') + 1 elif '--query-passthrough' in args: i = args.index('--query-passthrough') + 1 elif '--add-rule' in args: i = args.index('--add-rule') + 4 elif '--remove-rule' in args: i = args.index('--remove-rule') + 4 elif '--query-rule' in args: i = args.index('--query-rule') + 4 # join into one argument to prevent parser from parsing each iptables # option, because they can conflict with firewall-cmd options # # e.g. --delete (iptables) and --delete-* (firewall-cmd) if (i > -1) and (i < len(args) - 1): aux_args = args[:] args = aux_args[:i+1] # all but not args.append(joinArgs(aux_args[i+1:])) # add as one arg else: assert_root() # migrate configuration from SYSTEM_CONFIG_FIREWALL args = read_sysconfig_args() if not args: cmd.fail("Opening of '%s' failed, exiting." % SYSTEM_CONFIG_FIREWALL) a = parser.parse_args(args) options_lokkit = a.enabled or a.disabled or a.addmodule or a.removemodule or \ a.trust or a.masq or a.custom_rules or \ a.service or a.remove_service or a.port or \ a.trust or a.masq or a.forward_port or a.block_icmp options_standalone = a.help or a.version or \ a.policy_server or a.policy_desktop or \ a.lockdown_on or a.lockdown_off or a.query_lockdown or \ a.get_default_zone or a.set_default_zone or \ a.get_log_denied or a.set_log_denied or \ a.get_automatic_helpers or a.set_automatic_helpers options_desc_xml_file = a.set_description or a.get_description or \ a.set_short or a.get_short options_lockdown_whitelist = \ a.list_lockdown_whitelist_commands or a.add_lockdown_whitelist_command or \ a.remove_lockdown_whitelist_command or \ a.query_lockdown_whitelist_command or \ a.list_lockdown_whitelist_contexts or a.add_lockdown_whitelist_context or \ a.remove_lockdown_whitelist_context or \ a.query_lockdown_whitelist_context or \ a.list_lockdown_whitelist_uids or a.add_lockdown_whitelist_uid is not None or \ a.remove_lockdown_whitelist_uid is not None or \ a.query_lockdown_whitelist_uid is not None or \ a.list_lockdown_whitelist_users or a.add_lockdown_whitelist_user or \ a.remove_lockdown_whitelist_user or \ a.query_lockdown_whitelist_user options_config = a.get_zones or a.get_services or a.get_icmptypes or \ options_lockdown_whitelist or a.list_all_zones or \ a.get_zone_of_interface or a.get_zone_of_source or \ a.info_zone or a.info_icmptype or a.info_service or \ a.info_ipset or a.info_policy or a.get_ipsets or a.info_helper or \ a.get_helpers or a.get_policies or a.list_all_policies options_zone_and_policy_adapt_query = \ a.add_service or a.remove_service_from_zone or a.query_service or \ a.add_port or a.remove_port or a.query_port or \ a.add_protocol or a.remove_protocol or a.query_protocol or \ a.add_source_port or a.remove_source_port or a.query_source_port or \ a.add_icmp_block or a.remove_icmp_block or a.query_icmp_block or \ a.add_forward_port or a.remove_forward_port or a.query_forward_port or \ a.add_rich_rule or a.remove_rich_rule or a.query_rich_rule or \ a.add_masquerade or a.remove_masquerade or a.query_masquerade or \ a.list_services or a.list_ports or a.list_protocols or \ a.list_source_ports or \ a.list_icmp_blocks or a.list_forward_ports or a.list_rich_rules or \ a.list_all or a.get_target or a.set_target options_zone_unique = \ a.add_icmp_block_inversion or a.remove_icmp_block_inversion or \ a.query_icmp_block_inversion or \ a.add_forward or a.remove_forward or a.query_forward or \ a.list_interfaces or a.change_interface or \ a.add_interface or a.remove_interface or a.query_interface or \ a.list_sources or a.change_source or \ a.add_source or a.remove_source or a.query_source options_zone_ops = options_zone_unique or options_zone_and_policy_adapt_query options_policy_unique = \ a.list_ingress_zones or a.add_ingress_zone or \ a.remove_ingress_zone or a.query_ingress_zone or \ a.list_egress_zones or a.add_egress_zone or \ a.remove_egress_zone or a.query_egress_zone or \ a.set_priority or a.get_priority options_policy_ops = options_policy_unique or options_zone_and_policy_adapt_query options_zone = a.zone or options_zone_ops or options_desc_xml_file options_policy = a.policy or options_policy_ops or options_desc_xml_file options_ipset = a.add_entry or a.remove_entry or a.query_entry or \ a.get_entries or a.add_entries_from_file or \ a.remove_entries_from_file or options_desc_xml_file options_icmptype = a.add_destination or a.remove_destination or \ a.query_destination or a.get_destinations or \ options_desc_xml_file options_service = a.add_port or a.remove_port or a.query_port or \ a.get_ports or \ a.add_protocol or a.remove_protocol or a.query_protocol or \ a.get_protocols or \ a.add_source_port or a.remove_source_port or \ a.query_source_port or a.get_source_ports or \ a.add_module or a.remove_module or a.query_module or \ a.get_modules or \ a.set_destination or a.remove_destination or \ a.query_destination or a.get_destinations or \ options_desc_xml_file or \ a.add_include or a.remove_include or a.query_include or \ a.get_includes or \ a.add_helper or a.remove_helper or a.query_helper or \ a.get_service_helpers options_helper = a.add_port or a.remove_port or a.query_port or \ a.get_ports or a.set_module or a.get_module or \ a.set_family or a.get_family or \ options_desc_xml_file options_permanent = options_config or options_zone or options_policy or \ a.new_icmptype or a.delete_icmptype or \ a.new_icmptype_from_file or \ a.load_icmptype_defaults or \ a.new_service or a.delete_service or \ a.new_service_from_file or \ a.load_service_defaults or \ a.new_zone or a.delete_zone or \ a.new_zone_from_file or \ a.load_zone_defaults or \ a.new_policy or a.delete_policy or \ a.new_policy_from_file or \ a.load_policy_defaults or \ a.new_helper or a.delete_helper or \ a.new_helper_from_file or \ a.load_helper_defaults or \ a.new_ipset or a.delete_ipset or \ a.new_ipset_from_file or \ a.load_ipset_defaults or \ a.ipset or options_ipset or \ (a.icmptype and options_icmptype) or \ (a.service and options_service) or \ (a.helper and options_helper) or \ a.path_zone or a.path_icmptype or a.path_service or \ a.path_ipset or a.path_helper or a.path_policy options_direct = \ a.add_chain or a.remove_chain or a.query_chain or \ a.get_chains or a.get_all_chains or \ a.add_rule or a.remove_rule or a.remove_rules or a.query_rule or \ a.get_rules or a.get_all_rules or \ a.add_passthrough or a.remove_passthrough or a.query_passthrough or \ a.get_passthroughs or a.get_all_passthroughs # these are supposed to only write out some output options_list_get = a.help or a.version or a.list_all or a.list_all_zones or \ a.list_lockdown_whitelist_commands or a.list_lockdown_whitelist_contexts or \ a.list_lockdown_whitelist_uids or a.list_lockdown_whitelist_users or \ a.list_services or a.list_ports or a.list_protocols or a.list_icmp_blocks or \ a.list_forward_ports or a.list_rich_rules or a.list_interfaces or \ a.list_sources or a.get_default_zone or \ a.get_zone_of_interface or a.get_zone_of_source or a.get_zones or \ a.get_services or a.get_icmptypes or a.get_target or \ a.info_zone or a.info_icmptype or a.info_service or \ a.info_ipset or a.get_ipsets or a.get_entries or \ a.info_helper or a.get_helpers or \ a.get_destinations or a.get_description or \ a.list_all_policies or a.info_policy or a.get_policies # Set quiet and verbose cmd.set_quiet(a.quiet) cmd.set_verbose(a.verbose) # Check various impossible combinations of options if not (options_standalone or options_ipset or \ options_lokkit or \ options_icmptype or options_service or options_helper or \ options_permanent or options_direct or options_desc_xml_file or \ a.check_config): cmd.fail(parser.format_usage() + "No option specified.") if options_lokkit and (options_standalone or \ options_permanent or options_direct) and \ not (options_service and a.service): cmd.fail(parser.format_usage() + "Can't use lokkit options with other options.") if options_standalone and (options_permanent or \ options_direct or options_ipset): cmd.fail(parser.format_usage() + "Can't use stand-alone options with other options.") if options_ipset and not options_desc_xml_file and not a.ipset: cmd.fail(parser.format_usage() + "No ipset specified.") if (options_icmptype and not a.icmptype) and \ not (options_service and a.service) and not options_desc_xml_file: cmd.fail(parser.format_usage() + "No icmptype specified.") if options_service and a.service and len(a.service) > 0: if len(a.service) > 1: cmd.fail(parser.format_usage() + "More than one service specified.") # use the first entry in the array only a.service = a.service[0] if (options_helper and not a.helper) and \ not (options_service and a.service) and \ not options_zone and not options_desc_xml_file and \ not options_policy: cmd.fail(parser.format_usage() + "No helper specified.") if options_direct and (options_zone or options_policy): cmd.fail(parser.format_usage() + "Can't use 'direct' options with other options.") if (a.direct and not options_direct) or (options_direct and not a.direct): cmd.fail(parser.format_usage() + "Wrong usage of 'direct' options.") if a.name and not (a.new_zone_from_file or a.new_service_from_file or \ a.new_ipset_from_file or a.new_icmptype_from_file or \ a.new_helper_from_file or a.new_policy_from_file): cmd.fail(parser.format_usage() + "Wrong usage of '--name' option.") if options_config and (options_zone or options_policy): cmd.fail(parser.format_usage() + "Wrong usage of --get-zones | --get-services | --get-icmptypes | --get-policies.") if a.quiet and options_list_get: # it makes no sense to use --quiet with these options a.quiet = False cmd.set_quiet(a.quiet) cmd.fail("-q/--quiet can't be used with this option(s)") if a.zone and a.policy: cmd.fail(parser.format_usage() + "Can't use --zone with --policy.") if a.policy and options_zone_unique: cmd.fail(parser.format_usage() + "Can't use --policy with zone only options.") if a.zone and options_policy_unique: cmd.fail(parser.format_usage() + "Can't use --zone with policy only options.") if not a.policy and options_policy_unique: cmd.fail(parser.format_usage() + "Must use --policy with policy only options.") if a.help: __usage() sys.exit(0) assert_root() if a.system_config: config.set_system_config_paths(a.system_config) if a.default_config: config.set_default_config_paths(a.default_config) if a.check_config: try: fw = Firewall(offline=True) fw.start() check_config(fw) except FirewallError as error: cmd.print_and_exit("Configuration error: %s" % error, error.code) except Exception as msg: cmd.fail("Configuration error: %s" % msg) sys.exit(0) zone = a.zone fw = Firewall(offline=True) fw.start() try: # Lokkit Compatibility Options if options_lokkit and not (options_service and a.service): trusted_zone = "trusted" default_zone = fw.get_default_zone() fw_zone = fw.config.get_zone(default_zone) fw_settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(fw_zone)) if a.enabled: # Enable firewall (default) os.system("systemctl enable firewalld.service") if a.disabled: # Disable firewall os.system("systemctl disable firewalld.service") if a.addmodule: for m in a.addmodule: cmd.print_msg("Ignoring addmodule '%s'" % m) if a.removemodule: for m in a.removemodule: cmd.print_msg("Ignoring removemodule '%s'" % m) if a.custom_rules: for c in a.custom_rules: cmd.print_msg("Ignoring custom-rule '%s'" % c) if a.service: for s in a.service: cmd.print_msg("Adding service '%s' to default zone." % s) if not fw_settings.queryService(s): fw_settings.addService(s) else: cmd.print_msg("ALREADY_ENABLED: %s" % s) if a.remove_service: for s in a.remove_service: cmd.print_msg("Removing service '%s' from default zone." % s) if fw_settings.queryService(s): fw_settings.removeService(s) else: cmd.print_msg("NOT_ENABLED: %s" % s) if a.port: for port_proto in a.port: (port, proto) = parse_port_lokkit(port_proto) cmd.print_msg("Adding port '%s/%s' to default zone." % (port, proto)) if not fw_settings.queryPort(port, proto): fw_settings.addPort(port, proto) else: cmd.print_msg("ALREADY_ENABLED: %s" % port_proto) if a.trust: if default_zone != trusted_zone: fw_trusted = fw.config.get_zone("trusted") fw_trusted_settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(fw_trusted)) # Bind an interface to the trusted zone for i in a.trust: cmd.print_msg("Interface '%s' will be bound to zone '%s'." % \ (i, trusted_zone)) if not fw_trusted_settings.queryInterface(i): fw_trusted_settings.addInterface(i) else: cmd.print_msg("ALREADY_ENABLED: %s" % i) fw.config.set_zone_config_dict(fw_trusted, fw_trusted_settings.getSettingsDict()) else: for i in a.trust: cmd.print_msg("Interface '%s' will be bound to zone '%s'." % \ (i, trusted_zone)) if not fw_settings.queryInterface(i): fw_settings.addInterface(i) else: cmd.print_msg("ALREADY_ENABLED: %s" % i) if a.masq: # Enables masquerading in the default zone, interface argument is ignored cmd.print_msg("Enabling masquerade for the default zone.") fw_settings.setMasquerade(True) if a.forward_port: for fp in a.forward_port: (port, protocol, toport, toaddr) = cmd.parse_forward_port( fp, compat=True) cmd.print_msg("Adding forward port %s:%s:%s:%s to default zone." % \ (port, protocol, toport, toaddr)) if not fw_settings.queryForwardPort(port, protocol, toport, toaddr): fw_settings.addForwardPort(port, protocol, toport, toaddr) else: cmd.print_msg("ALREADY_ENABLED: %s" % fp) if a.block_icmp: for ib in a.block_icmp: cmd.print_msg("Adding icmpblock '%s' to default zone." % ib) if not fw_settings.queryIcmpBlock(ib): fw_settings.addIcmpBlock(ib) else: cmd.print_msg("ALREADY_ENABLED: %s" % ib) fw.config.set_zone_config_dict(fw_zone, fw_settings.getSettingsDict()) elif a.version: cmd.print_and_exit(config.VERSION) elif a.get_log_denied: cmd.print_and_exit(fw.get_log_denied()) elif a.set_log_denied: fw.set_log_denied(a.set_log_denied) elif a.get_automatic_helpers: cmd.print_and_exit(fw.get_automatic_helpers()) elif a.set_automatic_helpers: fw.set_automatic_helpers(a.set_automatic_helpers) elif a.policy_server: pk_symlink('server') elif a.policy_desktop: pk_symlink('desktop') # options from firewall-cmd elif a.get_default_zone: cmd.print_and_exit(fw.get_default_zone()) elif a.set_default_zone: fw.set_default_zone(a.set_default_zone) # lockdown elif a.lockdown_on: fw.enable_lockdown() elif a.lockdown_off: fw.disable_lockdown() elif a.query_lockdown: cmd.print_query_result(fw.policies.query_lockdown()) # zones elif a.get_zones: zones = fw.config.get_zones() cmd.print_and_exit(" ".join(zones)) elif a.new_zone: fw.config.new_zone_dict(a.new_zone, FirewallClientZoneSettings().getSettingsDict()) elif a.new_zone_from_file: filename = os.path.basename(a.new_zone_from_file) dirname = os.path.dirname(a.new_zone_from_file) if dirname == "": dirname = "./" try: obj = zone_reader(filename, dirname) except FirewallError as msg: cmd.print_and_exit("Failed to load zone file '%s': %s" % \ (a.new_zone_from_file, msg), msg.code) except IOError as msg: cmd.fail("Failed to load zone file: %s" % msg) if a.name: obj.name = a.name fw.config.new_zone(obj.name, obj.export_config()) elif a.delete_zone: obj = fw.config.get_zone(a.delete_zone) fw.config.remove_zone(obj) elif a.load_zone_defaults: obj = fw.config.get_zone(a.load_zone_defaults) fw.config.load_zone_defaults(obj) elif a.info_zone: zone = fw.config.get_zone(a.info_zone) settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(zone)) cmd.print_zone_info(a.info_zone, settings, True) sys.exit(0) elif a.path_zone: obj = fw.config.get_zone(a.path_zone) cmd.print_and_exit("%s/%s" % (obj.path, obj.filename)) # policies elif a.get_policies: policies = fw.config.get_policy_objects() cmd.print_and_exit(" ".join(policies)) elif a.new_policy: fw.config.new_policy_object_dict(a.new_policy, FirewallClientPolicySettings().getSettingsDict()) elif a.new_policy_from_file: filename = os.path.basename(a.new_policy_from_file) dirname = os.path.dirname(a.new_policy_from_file) if dirname == "": dirname = "./" try: obj = policy_reader(filename, dirname) except FirewallError as msg: cmd.print_and_exit("Failed to load policy file '%s': %s" % \ (a.new_policy_from_file, msg), msg.code) except IOError as msg: cmd.fail("Failed to load policy file: %s" % msg) if a.name: obj.name = a.name fw.config.new_policy_object_dict(obj.name, obj.export_config_dict()) elif a.delete_policy: obj = fw.config.get_policy_object(a.delete_policy) fw.config.remove_policy_object(obj) elif a.load_policy_defaults: obj = fw.config.get_policy_object(a.load_policy_defaults) fw.config.load_policy_object_defaults(obj) elif a.info_policy: policy = fw.config.get_policy_object(a.info_policy) settings = FirewallClientPolicySettings(fw.config.get_policy_object_config_dict(policy)) cmd.print_policy_info(a.info_policy, settings, True) sys.exit(0) elif a.path_policy: obj = fw.config.get_policy_object(a.path_policy) cmd.print_and_exit("%s/%s" % (obj.path, obj.filename)) # services elif a.get_services: services = fw.config.get_services() cmd.print_and_exit(" ".join(services)) elif a.new_service: fw.config.new_service_dict(a.new_service, FirewallClientServiceSettings().getSettingsDict()) elif a.new_service_from_file: filename = os.path.basename(a.new_service_from_file) dirname = os.path.dirname(a.new_service_from_file) if dirname == "": dirname = "./" try: obj = service_reader(filename, dirname) except FirewallError as msg: cmd.print_and_exit("Failed to load service file '%s': %s" % \ (a.new_service_from_file, msg), msg.code) except IOError as msg: cmd.fail("Failed to load service file: %s" % msg) if a.name: obj.name = a.name fw.config.new_service_dict(obj.name, obj.export_config_dict()) elif a.delete_service: obj = fw.config.get_service(a.delete_service) fw.config.remove_service(obj) # remove service from all zones zones = fw.config.get_zones() for zone in zones: _zone = fw.config.get_zone(zone) _settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(_zone)) if _settings.queryService(a.delete_service): _settings.removeService(a.delete_service) fw.config.set_zone_config_dict(_zone, _settings.getSettingsDict()) # remove service from all policies for policy in fw.config.get_policy_objects(): _policy = fw.config.get_policy_object(policy) _settings = FirewallClientPolicySettings(fw.config.get_policy_object_config_dict(_policy)) if _settings.queryService(a.delete_service): _settings.removeService(a.delete_service) fw.config.set_policy_object_config_dict(_policy, _settings.getSettingsDict()) elif a.load_service_defaults: obj = fw.config.get_service(a.load_service_defaults) fw.config.load_service_defaults(obj) elif a.info_service: service = fw.config.get_service(a.info_service) settings = FirewallClientServiceSettings( fw.config.get_service_config_dict(service)) cmd.print_service_info(a.info_service, settings) sys.exit(0) elif a.path_service: obj = fw.config.get_service(a.path_service) cmd.print_and_exit("%s/%s" % (obj.path, obj.filename)) # icmptypes elif a.get_icmptypes: icmptypes = fw.config.get_icmptypes() cmd.print_and_exit(" ".join(icmptypes)) elif a.new_icmptype: fw.config.new_icmptype(a.new_icmptype, FirewallClientIcmpTypeSettings().settings) elif a.new_icmptype_from_file: filename = os.path.basename(a.new_icmptype_from_file) dirname = os.path.dirname(a.new_icmptype_from_file) if dirname == "": dirname = "./" try: obj = icmptype_reader(filename, dirname) except FirewallError as msg: cmd.print_and_exit("Failed to load icmptype file '%s': %s" % \ (a.new_icmptype_from_file, msg), msg.code) except IOError as msg: cmd.fail("Failed to load icmptype file: %s" % msg) if a.name: obj.name = a.name fw.config.new_icmptype(obj.name, obj.export_config()) elif a.delete_icmptype: obj = fw.config.get_icmptype(a.delete_icmptype) fw.config.remove_icmptype(obj) # remove icmpyte from all zones zones = fw.config.get_zones() for zone in zones: _zone = fw.config.get_zone(zone) _settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(_zone)) if _settings.queryIcmpBlock(a.delete_icmptype): _settings.removeIcmpBlock(a.delete_icmptype) fw.config.set_zone_config_dict(_zone, _settings.getSettingsDict()) for policy in fw.config.get_policy_objects(): _policy = fw.config.get_policy_object(policy) _settings = FirewallClientPolicySettings(fw.config.get_policy_object_config_dict(_policy)) if _settings.queryIcmpBlock(a.delete_icmptype): _settings.removeIcmpBlock(a.delete_icmptype) fw.config.set_policy_object_config_dict(_policy, _settings.getSettingsDict()) elif a.load_icmptype_defaults: obj = fw.config.get_icmptype(a.load_icmptype_defaults) fw.config.load_icmptype_defaults(obj) elif a.info_icmptype: icmptype = fw.config.get_icmptype(a.info_icmptype) settings = FirewallClientIcmpTypeSettings( list(fw.config.get_icmptype_config(icmptype))) cmd.print_icmptype_info(a.info_icmptype, settings) sys.exit(0) elif a.path_icmptype: obj = fw.config.get_icmptype(a.path_icmptype) cmd.print_and_exit("%s/%s" % (obj.path, obj.filename)) elif a.icmptype and options_icmptype: icmptype = fw.config.get_icmptype(a.icmptype) settings = FirewallClientIcmpTypeSettings( list(fw.config.get_icmptype_config(icmptype))) if a.add_destination: cmd.add_sequence(a.add_destination, settings.addDestination, settings.queryDestination, cmd.check_destination_ipv, "'%s'") fw.config.set_icmptype_config(icmptype, settings.settings) elif a.remove_destination: cmd.remove_sequence(a.remove_destination, settings.removeDestination, settings.queryDestination, cmd.check_destination_ipv, "'%s'") fw.config.set_icmptype_config(icmptype, settings.settings) elif a.query_destination: cmd.query_sequence(a.query_destination, settings.queryDestination, cmd.check_destination_ipv , "'%s'") elif a.get_destinations: l = settings.getDestinations() if len(l) == 0: l = [ "ipv4", "ipv6" ] cmd.print_and_exit("\n".join(l)) elif a.set_description: settings.setDescription(a.set_description) fw.config.set_icmptype_config(icmptype, settings.settings) elif a.get_description: cmd.print_and_exit(settings.getDescription()) elif a.set_short: settings.setShort(a.set_short) fw.config.set_icmptype_config(icmptype, settings.settings) elif a.get_short: cmd.print_and_exit(settings.getShort()) else: cmd.fail(parser.format_usage() + "Unknown option") cmd.print_and_exit("success") elif a.service and options_service: service = fw.config.get_service(a.service) settings = FirewallClientServiceSettings( fw.config.get_service_config_dict(service)) if a.add_port: cmd.add_sequence(a.add_port, settings.addPort, settings.queryPort, cmd.parse_port, "%s/%s") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.remove_port: cmd.remove_sequence(a.remove_port, settings.removePort, settings.queryPort, cmd.parse_port, "%s/%s") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.query_port: cmd.query_sequence(a.query_port, settings.queryPort, cmd.parse_port, "%s/%s") elif a.get_ports: l = settings.getPorts() cmd.print_and_exit(" ".join(["%s/%s" % (port[0], port[1]) for port in l])) elif a.add_protocol: cmd.add_sequence(a.add_protocol, settings.addProtocol, settings.queryProtocol, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.remove_protocol: cmd.remove_sequence(a.remove_protocol, settings.removeProtocol, settings.queryProtocol, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.query_protocol: cmd.query_sequence(a.query_protocol, settings.queryProtocol, None, "'%s'") elif a.get_protocols: l = settings.getProtocols() cmd.print_and_exit(" ".join(["%s" % protocol for protocol in l])) elif a.add_source_port: cmd.add_sequence(a.add_source_port, settings.addSourcePort, settings.querySourcePort, cmd.parse_port, "%s/%s") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.remove_source_port: cmd.remove_sequence(a.remove_source_port, settings.removeSourcePort, settings.querySourcePort, cmd.parse_port, "%s/%s") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.query_source_port: cmd.query_sequence(a.query_source_port, settings.querySourcePort, cmd.parse_port, "%s/%s") elif a.get_source_ports: l = settings.getSourcePorts() cmd.print_and_exit(" ".join(["%s/%s" % (port[0], port[1]) for port in l])) elif a.add_module: cmd.add_sequence(a.add_module, settings.addModule, settings.queryModule, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.remove_module: cmd.remove_sequence(a.remove_module, settings.removeModule, settings.queryModule, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.query_module: cmd.query_sequence(a.query_module, settings.queryModule, None, "'%s'") elif a.get_modules: l = settings.getModules() cmd.print_and_exit(" ".join(["%s" % module for module in l])) elif a.set_destination: cmd.add_sequence(a.set_destination, settings.setDestination, settings.queryDestination, cmd.parse_service_destination, "%s:%s") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.remove_destination: # special case for removeDestination: Only ipv, no address for ipv in a.remove_destination: cmd.check_destination_ipv(ipv) if ipv not in settings.getDestinations(): if len(a.remove_destination) > 1: cmd.print_warning("Warning: NOT_ENABLED: '%s'" % ipv) else: code = FirewallError.get_code("NOT_ENABLED") cmd.print_and_exit("Error: NOT_ENABLED: '%s'" % ipv, code) else: settings.removeDestination(ipv) fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.query_destination: cmd.query_sequence(a.query_destination, settings.queryDestination, cmd.parse_service_destination, "'%s'") elif a.get_destinations: l = settings.getDestinations() cmd.print_and_exit(" ".join(["%s:%s" % (dest[0], dest[1]) for dest in l.items()])) elif a.add_include: cmd.add_sequence(a.add_include, settings.addInclude, settings.queryInclude, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.remove_include: cmd.remove_sequence(a.remove_include, settings.removeInclude, settings.queryInclude, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.query_include: cmd.query_sequence(a.query_include, settings.queryInclude, None, "'%s'") elif a.get_includes: l = settings.getIncludes() cmd.print_and_exit(" ".join(["%s" % include for include in sorted(l)])) elif a.add_helper: cmd.add_sequence(a.add_helper, settings.addHelper, settings.queryHelper, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.remove_helper: cmd.remove_sequence(a.remove_helper, settings.removeHelper, settings.queryHelper, None, "'%s'") fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.query_helper: cmd.query_sequence(a.query_helper, settings.queryHelper, None, "'%s'") elif a.get_service_helpers: l = settings.getHelpers() cmd.print_and_exit(" ".join(["%s" % helper for helper in sorted(l)])) elif a.set_description: settings.setDescription(a.set_description) fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.get_description: cmd.print_and_exit(settings.getDescription()) elif a.set_short: settings.setShort(a.set_short) fw.config.set_service_config_dict(service, settings.getSettingsDict()) elif a.get_short: cmd.print_and_exit(settings.getShort()) else: cmd.fail(parser.format_usage() + "Unknown option") cmd.print_and_exit("success") # ipsets if a.get_ipsets: ipsets = fw.config.get_ipsets() cmd.print_and_exit(" ".join(sorted(ipsets))) elif a.new_ipset: if not a.type: cmd.fail(parser.format_usage() + "No type specified.") if a.type=='hash:mac' and a.family: cmd.fail(parser.format_usage() + "--family is not compatible with the hash:mac type") settings = FirewallClientIPSetSettings() settings.setType(a.type) if a.option: for opt in a.option: settings.addOption(*cmd.parse_ipset_option(opt)) fw.config.new_ipset(a.new_ipset, settings.settings) elif a.new_ipset_from_file: filename = os.path.basename(a.new_ipset_from_file) dirname = os.path.dirname(a.new_ipset_from_file) if dirname == "": dirname = "./" try: obj = ipset_reader(filename, dirname) except FirewallError as msg: cmd.print_and_exit("Failed to load ipset file '%s': %s" % \ (a.new_ipset_from_file, msg), msg.code) except IOError as msg: cmd.fail("Failed to load ipset file: %s" % msg) if a.name: obj.name = a.name fw.config.new_ipset(obj.name, obj.export_config()) elif a.delete_ipset: ipset = fw.config.get_ipset(a.delete_ipset) fw.config.remove_ipset(ipset) elif a.load_ipset_defaults: obj = fw.config.get_ipset(a.load_ipset_defaults) fw.config.load_ipset_defaults(obj) elif a.info_ipset: ipset = fw.config.get_ipset(a.info_ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) cmd.print_ipset_info(a.info_ipset, settings) sys.exit(0) elif a.path_ipset: obj = fw.config.get_ipset(a.path_ipset) cmd.print_and_exit("%s/%s" % (obj.path, obj.filename)) elif a.ipset: if a.add_entry: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) cmd.add_sequence(a.add_entry, settings.addEntry, settings.queryEntry, None, "'%s'") fw.config.set_ipset_config(ipset, settings.settings) elif a.remove_entry: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) cmd.remove_sequence(a.remove_entry, settings.removeEntry, settings.queryEntry, None, "'%s'") fw.config.set_ipset_config(ipset, settings.settings) elif a.query_entry: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) cmd.query_sequence(a.query_entry, settings.queryEntry, None, "'%s'") elif a.get_entries: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) l = settings.getEntries() cmd.print_and_exit("\n".join(l)) elif a.add_entries_from_file: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) changed = False for filename in a.add_entries_from_file: try: entries = cmd.get_ipset_entries_from_file(filename) except IOError as msg: message = "Failed to read file '%s': %s" % (filename, msg) if len(a.add_entries_from_file) > 1: cmd.print_warning(message) else: cmd.print_and_exit(message) else: old_entries = settings.getEntries() entries_set = set() for entry in old_entries: entries_set.add(entry) for entry in entries: if entry not in entries_set: old_entries.append(entry) entries_set.add(entry) changed = True else: cmd.print_if_verbose( "Warning: ALREADY_ENABLED: %s" % entry) if changed: settings.setEntries(old_entries) if changed: fw.config.set_ipset_config(ipset, settings.settings) elif a.remove_entries_from_file: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) changed = False for filename in a.remove_entries_from_file: try: entries = cmd.get_ipset_entries_from_file(filename) except IOError as msg: message = "Failed to read file '%s': %s" % (filename, msg) if len(a.remove_entries_from_file) > 1: cmd.print_warning(message) else: cmd.print_and_exit(message) else: old_entries = settings.getEntries() entries_set = set() for entry in old_entries: entries_set.add(entry) for entry in entries: if entry in entries_set: old_entries.remove(entry) entries_set.discard(entry) changed = True else: cmd.print_if_verbose("Warning: NOT_ENABLED: %s" % \ entry) if changed: settings.setEntries(old_entries) if changed: fw.config.set_ipset_config(ipset, settings.settings) elif a.set_description: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) settings.setDescription(a.set_description) fw.config.set_ipset_config(ipset, settings.settings) elif a.get_description: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) cmd.print_and_exit(settings.getDescription()) elif a.set_short: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) settings.setShort(a.set_short) fw.config.set_ipset_config(ipset, settings.settings) elif a.get_short: ipset = fw.config.get_ipset(a.ipset) settings = FirewallClientIPSetSettings( list(fw.config.get_ipset_config(ipset))) cmd.print_and_exit(settings.getShort()) else: cmd.fail(parser.format_usage() + "Unknown option") cmd.print_and_exit("success") # helper elif a.get_helpers: cmd.print_and_exit(" ".join(sorted(fw.config.get_helpers()))) elif a.new_helper: if not a.module: cmd.fail(parser.format_usage() + "No module specified.") settings = FirewallClientHelperSettings() settings.setModule(a.module) if a.family: settings.setFamily(a.family) fw.config.new_helper(a.new_helper, settings.settings) elif a.new_helper_from_file: filename = os.path.basename(a.new_helper_from_file) dirname = os.path.dirname(a.new_helper_from_file) if dirname == "": dirname = "./" try: obj = helper_reader(filename, dirname) except FirewallError as msg: cmd.print_and_exit("Failed to load helper file '%s': %s" % \ (a.new_helper_from_file, msg), msg.code) except IOError as msg: cmd.fail("Failed to load helper file: %s" % msg) if a.name: obj.name = a.name fw.config.new_helper(obj.name, obj.export_config()) elif a.delete_helper: obj = fw.config.get_helper(a.delete_helper) fw.config.remove_helper(obj) elif a.load_helper_defaults: obj = fw.config.get_helper(a.load_helper_defaults) fw.config.load_helper_defaults(obj) elif a.info_helper: obj = fw.config.get_helper(a.info_helper) settings = FirewallClientHelperSettings( list(fw.config.get_helper_config(obj))) cmd.print_helper_info(a.info_helper, settings) sys.exit(0) elif a.path_helper: obj = fw.config.get_helper(a.path_helper) cmd.print_and_exit("%s/%s" % (obj.path, obj.filename)) elif a.helper: obj = fw.config.get_helper(a.helper) settings = FirewallClientHelperSettings( list(fw.config.get_helper_config(obj))) if a.add_port: cmd.add_sequence(a.add_port, settings.addPort, settings.queryPort, cmd.parse_port, "%s/%s") fw.config.set_helper_config(obj, settings.settings) elif a.remove_port: cmd.remove_sequence(a.remove_port, settings.removePort, settings.queryPort, cmd.parse_port, "%s/%s") fw.config.set_helper_config(obj, settings.settings) elif a.query_port: cmd.query_sequence(a.query_port, settings.queryPort, cmd.parse_port, "%s/%s") elif a.get_ports: l = settings.getPorts() cmd.print_and_exit(" ".join(["%s/%s" % (port[0], port[1]) for port in l])) elif a.get_module: cmd.print_and_exit(settings.getModule()) elif a.set_module: settings.setModule(cmd.check_module(a.set_module)) fw.config.set_helper_config(obj, settings.settings) elif a.get_family: cmd.print_and_exit(settings.getFamily()) elif a.set_family: settings.setFamily(cmd.check_helper_family(a.set_family[0])) fw.config.set_helper_config(obj, settings.settings) elif a.set_description: settings.setDescription(a.set_description) fw.config.set_helper_config(obj, settings.settings) elif a.get_description: cmd.print_and_exit(settings.getDescription()) elif a.set_short: settings.setShort(a.set_short) fw.config.set_helper_config(obj, settings.settings) elif a.get_short: cmd.print_and_exit(settings.getShort()) else: cmd.fail(parser.format_usage() + "Unknown option") # lockdown whitelist elif options_lockdown_whitelist: whitelist = fw.config.get_policies().lockdown_whitelist # commands if a.list_lockdown_whitelist_commands: l = whitelist.get_commands() cmd.print_and_exit("\n".join(l)) elif a.add_lockdown_whitelist_command: cmd.add_sequence(a.add_lockdown_whitelist_command, whitelist.add_command, whitelist.has_command, None, "'%s'") elif a.remove_lockdown_whitelist_command: cmd.remove_sequence(a.remove_lockdown_whitelist_command, whitelist.remove_command, whitelist.has_command, None, "'%s'") elif a.query_lockdown_whitelist_command: cmd.query_sequence(a.query_lockdown_whitelist_command, whitelist.has_command, None, "'%s'") # contexts elif a.list_lockdown_whitelist_contexts: l = whitelist.get_contexts() cmd.print_and_exit("\n".join(l)) elif a.add_lockdown_whitelist_context: cmd.add_sequence(a.add_lockdown_whitelist_context, whitelist.add_context, whitelist.has_context, None, "'%s'") elif a.remove_lockdown_whitelist_context: cmd.remove_sequence(a.remove_lockdown_whitelist_context, whitelist.remove_context, whitelist.has_context, None, "'%s'") elif a.query_lockdown_whitelist_context: cmd.query_sequence(a.query_lockdown_whitelist_context, whitelist.has_context, None, "'%s'") # uids elif a.list_lockdown_whitelist_uids: l = whitelist.get_uids() cmd.print_and_exit(" ".join(map(str, l))) elif a.add_lockdown_whitelist_uid: cmd.add_sequence(a.add_lockdown_whitelist_uid, whitelist.add_uid, whitelist.has_uid, None, "'%s'") elif a.remove_lockdown_whitelist_uid: cmd.remove_sequence(a.remove_lockdown_whitelist_uid, whitelist.remove_uid, whitelist.has_uid, None, "'%s'") elif a.query_lockdown_whitelist_uid: cmd.query_sequence(a.query_lockdown_whitelist_uid, whitelist.has_uid, None, "'%s'") # users elif a.list_lockdown_whitelist_users: l = whitelist.get_users() cmd.print_and_exit("\n".join(l)) elif a.add_lockdown_whitelist_user: cmd.add_sequence(a.add_lockdown_whitelist_user, whitelist.add_user, whitelist.has_user, None, "'%s'") elif a.remove_lockdown_whitelist_user: cmd.remove_sequence(a.remove_lockdown_whitelist_user, whitelist.remove_user, whitelist.has_user, None, "'%s'") elif a.query_lockdown_whitelist_user: cmd.query_sequence(a.query_lockdown_whitelist_user, whitelist.has_user, None, "'%s'") # apply whitelist changes whitelist.write() elif options_direct: obj = fw.config.get_direct() if a.add_passthrough: if len(a.add_passthrough) < 2: cmd.fail("usage: --direct --add-passthrough { ipv4 | ipv6 | eb } ") cmd.print_msg( obj.add_passthrough(cmd.check_ipv(a.add_passthrough[0]), splitArgs(a.add_passthrough[1]))) elif a.remove_passthrough: if len(a.remove_passthrough) < 2: cmd.fail("usage: --direct --remove-passthrough { ipv4 | ipv6 | eb } ") obj.remove_passthrough(cmd.check_ipv(a.remove_passthrough[0]), splitArgs(a.remove_passthrough[1])) elif a.query_passthrough: if len(a.query_passthrough) < 2: cmd.fail("usage: --direct --query-passthrough { ipv4 | ipv6 | eb } ") cmd.print_query_result( obj.query_passthrough(cmd.check_ipv(a.query_passthrough[0]), splitArgs(a.query_passthrough[1]))) sys.exit(0) elif a.get_passthroughs: rules = obj.get_passthroughs(cmd.check_ipv(a.get_passthroughs[0])) for rule in rules: cmd.print_msg(joinArgs(rule)) sys.exit(0) elif a.get_all_passthroughs: rules = obj.get_all_passthroughs() for ipv in rules: for rule in rules[ipv]: cmd.print_msg("%s %s" % (ipv, joinArgs(rule))) sys.exit(0) elif a.add_chain: obj.add_chain(cmd.check_ipv(a.add_chain[0]), a.add_chain[1], a.add_chain[2]) elif a.remove_chain: obj.remove_chain(cmd.check_ipv(a.remove_chain[0]), a.remove_chain[1], a.remove_chain[2]) elif a.query_chain: cmd.print_query_result( obj.query_chain(cmd.check_ipv(a.query_chain[0]), a.query_chain[1], a.query_chain[2])) sys.exit(0) elif a.get_chains: cmd.print_and_exit( " ".join(obj.get_chains(cmd.check_ipv(a.get_chains[0]), a.get_chains[1]))) sys.exit(0) elif a.get_all_chains: chains = obj.get_all_chains() for (ipv, table) in chains: for chain in chains[(ipv, table)]: cmd.print_msg("%s %s %s" % (ipv, table, chain)) sys.exit(0) elif a.add_rule: if len(a.add_rule) < 5: cmd.fail("usage: --direct --add-rule { ipv4 | ipv6 | eb }
") try: priority = int(a.add_rule[3]) except ValueError: cmd.fail("wrong priority\nusage: --direct --add-rule { ipv4 | ipv6 | eb }
") obj.add_rule(cmd.check_ipv(a.add_rule[0]), a.add_rule[1], a.add_rule[2], priority, splitArgs(a.add_rule[4])) elif a.remove_rule: if len(a.remove_rule) < 5: cmd.fail("usage: --direct --remove-rule { ipv4 | ipv6 | eb }
") try: priority = int(a.remove_rule[3]) except ValueError: cmd.fail("usage: --direct --remove-rule { ipv4 | ipv6 | eb }
") obj.remove_rule(cmd.check_ipv(a.remove_rule[0]), a.remove_rule[1], a.remove_rule[2], priority, splitArgs(a.remove_rule[4])) elif a.remove_rules: if len(a.remove_rules) < 3: cmd.fail("usage: --direct --remove-rules { ipv4 | ipv6 | eb }
") obj.remove_rules(cmd.check_ipv(a.remove_rules[0]), a.remove_rules[1], a.remove_rules[2]) elif a.query_rule: if len(a.query_rule) < 5: cmd.fail("usage: --direct --query-rule { ipv4 | ipv6 | eb }
") try: priority = int(a.query_rule[3]) except ValueError: cmd.fail("usage: --direct --query-rule { ipv4 | ipv6 | eb }
") cmd.print_query_result( obj.query_rule(cmd.check_ipv(a.query_rule[0]), a.query_rule[1], a.query_rule[2], priority, splitArgs(a.query_rule[4]))) sys.exit(0) elif a.get_rules: rules = obj.get_rules(cmd.check_ipv(a.get_rules[0]), a.get_rules[1], a.get_rules[2]) for (priority, rule) in rules: cmd.print_msg("%d %s" % (priority, joinArgs(rule))) sys.exit(0) elif a.get_all_rules: rules = obj.get_all_rules() for (ipv, table, chain) in rules: for (priority, rule) in rules[(ipv, table, chain)]: cmd.print_msg("%s %s %s %d %s" % \ (ipv, table, chain, priority, joinArgs(rule))) sys.exit(0) obj.write() # list everything elif a.list_all_policies: policies = fw.config.get_policy_objects() for policy in policies: fw_policy = fw.config.get_policy_object(policy) fw_settings = FirewallClientPolicySettings(fw.config.get_policy_object_config_dict(fw_policy)) cmd.print_policy_info(policy, fw_settings) cmd.print_msg("") sys.exit(0) elif a.policy: fw_policy = fw.config.get_policy_object(a.policy) fw_settings = FirewallClientPolicySettings(fw.config.get_policy_object_config_dict(fw_policy)) # ingress zones if a.list_ingress_zones: l = fw_settings.getIngressZones() cmd.print_and_exit(" ".join(sorted(l))) elif a.add_ingress_zone: cmd.add_sequence(a.add_ingress_zone, fw_settings.addIngressZone, fw_settings.queryIngressZone, None, "'%s'") elif a.remove_ingress_zone: cmd.remove_sequence(a.remove_ingress_zone, fw_settings.removeIngressZone, fw_settings.queryIngressZone, None, "'%s'") elif a.query_ingress_zone: cmd.query_sequence(a.query_ingress_zone, fw_settings.queryIngressZone, None, "'%s'") # egress zones if a.list_egress_zones: l = fw_settings.getEgressZones() cmd.print_and_exit(" ".join(sorted(l))) elif a.add_egress_zone: cmd.add_sequence(a.add_egress_zone, fw_settings.addEgressZone, fw_settings.queryEgressZone, None, "'%s'") elif a.remove_egress_zone: cmd.remove_sequence(a.remove_egress_zone, fw_settings.removeEgressZone, fw_settings.queryEgressZone, None, "'%s'") elif a.query_egress_zone: cmd.query_sequence(a.query_egress_zone, fw_settings.queryEgressZone, None, "'%s'") # priority elif a.get_priority: cmd.print_and_exit(str(fw_settings.getPriority())) elif a.set_priority: fw_settings.setPriority(a.set_priority) # rich rules if a.list_rich_rules: l = fw_settings.getRichRules() cmd.print_and_exit("\n".join(l)) elif a.add_rich_rule: cmd.add_sequence(a.add_rich_rule, fw_settings.addRichRule, fw_settings.queryRichRule, None, "'%s'") elif a.remove_rich_rule: cmd.remove_sequence(a.remove_rich_rule, fw_settings.removeRichRule, fw_settings.queryRichRule, None, "'%s'") elif a.query_rich_rule: cmd.query_sequence(a.query_rich_rule, fw_settings.queryRichRule, None, "'%s'") # service if a.list_services: l = fw_settings.getServices() cmd.print_and_exit(" ".join(sorted(l))) elif a.add_service: cmd.add_sequence(a.add_service, fw_settings.addService, fw_settings.queryService, None, "'%s'") elif a.remove_service_from_policy: cmd.remove_sequence(a.remove_service_from_policy, fw_settings.removeService, fw_settings.queryService, None, "'%s'") elif a.query_service: cmd.query_sequence(a.query_service, fw_settings.queryService, None, "'%s'") # port elif a.list_ports: l = fw_settings.getPorts() cmd.print_and_exit(" ".join(["%s/%s" % (port[0], port[1]) for port in sorted(l, key=lambda x: (x[1], getPortRange(x[0])[0]))])) elif a.add_port: cmd.add_sequence(a.add_port, fw_settings.addPort, fw_settings.queryPort, cmd.parse_port, "%s/%s") elif a.remove_port: cmd.remove_sequence(a.remove_port, fw_settings.removePort, fw_settings.queryPort, cmd.parse_port, "%s/%s") elif a.query_port: cmd.query_sequence(a.query_port, fw_settings.queryPort, cmd.parse_port, "%s/%s") # protocol elif a.list_protocols: l = fw_settings.getProtocols() cmd.print_and_exit(" ".join(sorted(l))) elif a.add_protocol: cmd.add_sequence(a.add_protocol, fw_settings.addProtocol, fw_settings.queryProtocol, None, "'%s'") elif a.remove_protocol: cmd.remove_sequence(a.remove_protocol, fw_settings.removeProtocol, fw_settings.queryProtocol, None, "'%s'") elif a.query_protocol: cmd.query_sequence(a.query_protocol, fw_settings.queryProtocol, None, "'%s'") # source port elif a.list_source_ports: l = fw_settings.getSourcePorts() cmd.print_and_exit(" ".join(["%s/%s" % (port[0], port[1]) for port in sorted(l, key=lambda x: (x[1], getPortRange(x[0])[0]))])) elif a.add_source_port: cmd.add_sequence(a.add_source_port, fw_settings.addSourcePort, fw_settings.querySourcePort, cmd.parse_port, "%s/%s") elif a.remove_source_port: cmd.remove_sequence(a.remove_source_port, fw_settings.removeSourcePort, fw_settings.querySourcePort, cmd.parse_port, "%s/%s") elif a.query_source_port: cmd.query_sequence(a.query_source_port, fw_settings.querySourcePort, cmd.parse_port, "%s/%s") # masquerade elif a.add_masquerade: fw_settings.setMasquerade(True) elif a.remove_masquerade: fw_settings.setMasquerade(False) elif a.query_masquerade: cmd.print_query_result(fw_settings.getMasquerade()) # forward port elif a.list_forward_ports: l = fw_settings.getForwardPorts() cmd.print_and_exit("\n".join(["port=%s:proto=%s:toport=%s:toaddr=%s" % (_port, _protocol, _toport, _toaddr) for (_port, _protocol, _toport, _toaddr) in l])) elif a.add_forward_port: cmd.add_sequence(a.add_forward_port, fw_settings.addForwardPort, fw_settings.queryForwardPort, cmd.parse_forward_port, "port=%s:proto=%s:toport=%s:toaddr=%s") elif a.remove_forward_port: cmd.remove_sequence(a.remove_forward_port, fw_settings.removeForwardPort, fw_settings.queryForwardPort, cmd.parse_forward_port, "port=%s:proto=%s:toport=%s:toaddr=%s") elif a.query_forward_port: cmd.query_sequence(a.query_forward_port, fw_settings.queryForwardPort, cmd.parse_forward_port, "port=%s:proto=%s:toport=%s:toaddr=%s") # block icmp elif a.list_icmp_blocks: l = fw_settings.getIcmpBlocks() cmd.print_and_exit(" ".join(l)) elif a.add_icmp_block: cmd.add_sequence(a.add_icmp_block, fw_settings.addIcmpBlock, fw_settings.queryIcmpBlock, None, "'%s'") elif a.remove_icmp_block: cmd.remove_sequence(a.remove_icmp_block, fw_settings.removeIcmpBlock, fw_settings.queryIcmpBlock, None, "'%s'") elif a.query_icmp_block: cmd.query_sequence(a.query_icmp_block, fw_settings.queryIcmpBlock, None, "'%s'") # policy target elif a.get_target: cmd.print_and_exit(fw_settings.getTarget()) elif a.set_target: fw_settings.setTarget(a.set_target) # list all policy settings elif a.list_all: cmd.print_policy_info(a.policy, fw_settings) sys.exit(0) elif a.set_description: fw_settings.setDescription(a.set_description) elif a.get_description: cmd.print_and_exit(fw_settings.getDescription()) elif a.set_short: fw_settings.setShort(a.set_short) elif a.get_short: cmd.print_and_exit(fw_settings.getShort()) fw.config.set_policy_object_config_dict(fw_policy, fw_settings.getSettingsDict()) cmd.print_and_exit("success") else: if zone == "": zone = fw.get_default_zone() fw_zone = fw.config.get_zone(zone) fw_settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(fw_zone)) # interface if a.list_interfaces: l = fw_settings.getInterfaces() cmd.print_and_exit(" ".join(l)) elif a.get_zone_of_interface: for interface in a.get_zone_of_interface: ret = [ ] for zone in fw.config.get_zones(): obj = fw.config.get_zone(zone) if interface in obj.interfaces: ret.append(obj.name) if len(ret) > 1: # Even it shouldn't happen, it's actually possible that # the same interface is in several zone XML files cmd.print_warning(" ".join(ret) + " (ERROR: interface '%s' is in %s zone XML files, can be only in one)" % (interface, len(ret))) if len(ret) == 1: if len(a.get_zone_of_interface) > 1: cmd.print_warning("%s: %s" % (interface, ret[0])) else: cmd.print_and_exit(ret[0]) else: if len(a.get_zone_of_interface) > 1: cmd.print_warning("%s: no zone" % interface) else: cmd.print_and_exit("no zone", 2) elif a.change_interface: for interface in a.change_interface: for old_zone in fw.config.get_zones(): old_zone_obj = fw.config.get_zone(old_zone) if interface in old_zone_obj.interfaces: if old_zone_obj.name != zone: old_zone_settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(old_zone_obj)) old_zone_settings.removeInterface(interface) # remove from old fw.config.set_zone_config_dict(old_zone_obj, old_zone_settings.getSettingsDict()) fw_settings.addInterface(interface) # add to new elif a.add_interface: cmd.add_sequence(a.add_interface, fw_settings.addInterface, fw_settings.queryInterface, None, "'%s'") elif a.remove_interface: cmd.remove_sequence(a.remove_interface, fw_settings.removeInterface, fw_settings.queryInterface, None, "'%s'") elif a.query_interface: cmd.query_sequence(a.query_interface, fw_settings.queryInterface, None, "'%s'") # source if a.list_sources: sources = fw_settings.getSources() cmd.print_and_exit(" ".join(sources)) elif a.get_zone_of_source: for source in a.get_zone_of_source: ret = [ ] for zone in fw.config.get_zones(): obj = fw.config.get_zone(zone) if source in obj.sources: ret.append(obj.name) if len(ret) > 1: # Even it shouldn't happen, it's actually possible that # the same source is in several zone XML files cmd.print_warning(" ".join(ret) + " (ERROR: source '%s' is in %s zone XML files, can be only in one)" % (source, len(ret))) if len(ret) == 1: if len(a.get_zone_of_source) > 1: cmd.print_warning("%s: %s" % (source, ret[0])) else: cmd.print_and_exit(ret[0]) else: if len(a.get_zone_of_source) > 1: cmd.print_warning("%s: no zone" % source) else: cmd.print_and_exit("no zone", 2) elif a.change_source: for source in a.change_source: for old_zone in fw.config.get_zones(): old_zone_obj = fw.config.get_zone(old_zone) if source in old_zone_obj.sources: if old_zone_obj.name != zone: old_zone_settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(old_zone_obj)) old_zone_settings.removeSource(source) # remove from old fw.config.set_zone_config_dict(old_zone_obj, old_zone_settings.getSettingsDict()) fw_settings.addSource(source) # add to new elif a.add_source: cmd.add_sequence(a.add_source, fw_settings.addSource, fw_settings.querySource, None, "'%s'") elif a.remove_source: cmd.remove_sequence(a.remove_source, fw_settings.removeSource, fw_settings.querySource, None, "'%s'") elif a.query_source: cmd.query_sequence(a.query_source, fw_settings.querySource, None, "'%s'") # rich rules if a.list_rich_rules: l = fw_settings.getRichRules() cmd.print_and_exit("\n".join(l)) elif a.add_rich_rule: cmd.add_sequence(a.add_rich_rule, fw_settings.addRichRule, fw_settings.queryRichRule, None, "'%s'") elif a.remove_rich_rule: cmd.remove_sequence(a.remove_rich_rule, fw_settings.removeRichRule, fw_settings.queryRichRule, None, "'%s'") elif a.query_rich_rule: cmd.query_sequence(a.query_rich_rule, fw_settings.queryRichRule, None, "'%s'") # service if a.list_services: l = fw_settings.getServices() cmd.print_and_exit(" ".join(sorted(l))) elif a.add_service: cmd.add_sequence(a.add_service, fw_settings.addService, fw_settings.queryService, None, "'%s'") elif a.remove_service_from_zone: cmd.remove_sequence(a.remove_service_from_zone, fw_settings.removeService, fw_settings.queryService, None, "'%s'") elif a.query_service: cmd.query_sequence(a.query_service, fw_settings.queryService, None, "'%s'") # port elif a.list_ports: l = fw_settings.getPorts() cmd.print_and_exit(" ".join(["%s/%s" % (port[0], port[1]) for port in sorted(l, key=lambda x: (x[1], getPortRange(x[0])[0]))])) elif a.add_port: cmd.add_sequence(a.add_port, fw_settings.addPort, fw_settings.queryPort, cmd.parse_port, "%s/%s") elif a.remove_port: cmd.remove_sequence(a.remove_port, fw_settings.removePort, fw_settings.queryPort, cmd.parse_port, "%s/%s") elif a.query_port: cmd.query_sequence(a.query_port, fw_settings.queryPort, cmd.parse_port, "%s/%s") # protocol elif a.list_protocols: l = fw_settings.getProtocols() cmd.print_and_exit(" ".join(sorted(l))) elif a.add_protocol: cmd.add_sequence(a.add_protocol, fw_settings.addProtocol, fw_settings.queryProtocol, None, "'%s'") elif a.remove_protocol: cmd.remove_sequence(a.remove_protocol, fw_settings.removeProtocol, fw_settings.queryProtocol, None, "'%s'") elif a.query_protocol: cmd.query_sequence(a.query_protocol, fw_settings.queryProtocol, None, "'%s'") # source port elif a.list_source_ports: l = fw_settings.getSourcePorts() cmd.print_and_exit(" ".join(["%s/%s" % (port[0], port[1]) for port in sorted(l, key=lambda x: (x[1], getPortRange(x[0])[0]))])) elif a.add_source_port: cmd.add_sequence(a.add_source_port, fw_settings.addSourcePort, fw_settings.querySourcePort, cmd.parse_port, "%s/%s") elif a.remove_source_port: cmd.remove_sequence(a.remove_source_port, fw_settings.removeSourcePort, fw_settings.querySourcePort, cmd.parse_port, "%s/%s") elif a.query_source_port: cmd.query_sequence(a.query_source_port, fw_settings.querySourcePort, cmd.parse_port, "%s/%s") # forward elif a.add_forward: fw_settings.setForward(True) elif a.remove_forward: fw_settings.setForward(False) elif a.query_forward: cmd.print_query_result(fw_settings.getForward()) # masquerade elif a.add_masquerade: fw_settings.setMasquerade(True) elif a.remove_masquerade: fw_settings.setMasquerade(False) elif a.query_masquerade: cmd.print_query_result(fw_settings.getMasquerade()) # forward port elif a.list_forward_ports: l = fw_settings.getForwardPorts() cmd.print_and_exit("\n".join(["port=%s:proto=%s:toport=%s:toaddr=%s" % (_port, _protocol, _toport, _toaddr) for (_port, _protocol, _toport, _toaddr) in l])) elif a.add_forward_port: cmd.add_sequence(a.add_forward_port, fw_settings.addForwardPort, fw_settings.queryForwardPort, cmd.parse_forward_port, "port=%s:proto=%s:toport=%s:toaddr=%s") elif a.remove_forward_port: cmd.remove_sequence(a.remove_forward_port, fw_settings.removeForwardPort, fw_settings.queryForwardPort, cmd.parse_forward_port, "port=%s:proto=%s:toport=%s:toaddr=%s") elif a.query_forward_port: cmd.query_sequence(a.query_forward_port, fw_settings.queryForwardPort, cmd.parse_forward_port, "port=%s:proto=%s:toport=%s:toaddr=%s") # block icmp elif a.list_icmp_blocks: l = fw_settings.getIcmpBlocks() cmd.print_and_exit(" ".join(l)) elif a.add_icmp_block: cmd.add_sequence(a.add_icmp_block, fw_settings.addIcmpBlock, fw_settings.queryIcmpBlock, None, "'%s'") elif a.remove_icmp_block: cmd.remove_sequence(a.remove_icmp_block, fw_settings.removeIcmpBlock, fw_settings.queryIcmpBlock, None, "'%s'") elif a.query_icmp_block: cmd.query_sequence(a.query_icmp_block, fw_settings.queryIcmpBlock, None, "'%s'") # icmp block inversion elif a.add_icmp_block_inversion: fw_settings.addIcmpBlockInversion() elif a.remove_icmp_block_inversion: fw_settings.removeIcmpBlockInversion() elif a.query_icmp_block_inversion: cmd.print_query_result(fw_settings.queryIcmpBlockInversion()) # zone target elif a.get_target: cmd.print_and_exit(fw_settings.getTarget()) elif a.set_target: fw_settings.setTarget(a.set_target) # list all zone settings elif a.list_all: cmd.print_zone_info(zone if zone else fw.get_default_zone(), fw_settings) sys.exit(0) # list everything elif a.list_all_zones: zones = fw.config.get_zones() for zone in zones: fw_zone = fw.config.get_zone(zone) fw_settings = FirewallClientZoneSettings(fw.config.get_zone_config_dict(fw_zone)) cmd.print_zone_info(zone, fw_settings) cmd.print_msg("") sys.exit(0) elif a.set_description: fw_settings.setDescription(a.set_description) elif a.get_description: cmd.print_and_exit(fw_settings.getDescription()) elif a.set_short: fw_settings.setShort(a.set_short) elif a.get_short: cmd.print_and_exit(fw_settings.getShort()) fw.config.set_zone_config_dict(fw_zone, fw_settings.getSettingsDict()) cmd.print_and_exit("success") except FirewallError as msg: cmd.print_and_exit("%s" % msg, msg.code) except Exception as msg: cmd.fail("%s" % msg) else: cmd.print_and_exit("success")