1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
use crate::network::firewall::Firewall;
use crate::network::netns::NetworkNamespace;
pub fn open_ports(
netns: &NetworkNamespace,
ports: &[u16],
firewall: Firewall,
) -> anyhow::Result<()> {
// TODO: Allow UDP port forwarding?
// IPv6 forwarding?
for port in ports {
match firewall {
Firewall::IpTables => {
NetworkNamespace::exec(
&netns.name,
&[
"iptables",
"-I",
"INPUT",
"-p",
"tcp",
"--dport",
&port.to_string(),
"-j",
"ACCEPT",
],
)?;
NetworkNamespace::exec(
&netns.name,
&[
"iptables",
"-I",
"OUTPUT",
"-p",
"tcp",
"--sport",
&port.to_string(),
"-j",
"ACCEPT",
],
)?;
}
Firewall::NfTables => {
NetworkNamespace::exec(
&netns.name,
&[
"nft",
"insert",
"rule",
"inet",
&netns.name,
"input",
"tcp",
"dport",
&port.to_string(),
"counter",
"accept",
],
)?;
NetworkNamespace::exec(
&netns.name,
&[
"nft",
"add",
"chain",
"inet",
&netns.name,
"output",
"{ type filter hook output priority 100 ; }",
],
)?;
NetworkNamespace::exec(
&netns.name,
&[
"nft",
"insert",
"rule",
"inet",
&netns.name,
"output",
"tcp",
"sport",
&port.to_string(),
"counter",
"accept",
],
)?;
}
}
}
Ok(())
}