firewall

package
v1.0.12 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 8, 2026 License: Apache-2.0 Imports: 23 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func EnsureIPSet

func EnsureIPSet(name, hashtype string, p *Params) error

func EnsureTProxySupport

func EnsureTProxySupport(ipv6Enabled bool) error

func IPSetExists

func IPSetExists(name string) bool

func IpsetName

func IpsetName(vpnType, chainName string) (string, error)

func IpsetName6

func IpsetName6(vpnType, chainName string) (string, error)

func IpsetName6FromBase

func IpsetName6FromBase(base string) (string, error)

func ManagedIpsetCounts

func ManagedIpsetCounts() (v4, v6 int64)

func Swap

func Swap(from, to string) error

Types

type ChainSpec

type ChainSpec struct {
	IPSetName string
	Port      int
	Ifaces    []string
}

type DomainRuleMatcher

type DomainRuleMatcher interface {
	MatchDomain(domain string) (vpnType string, chainName string, rule string, ok bool)
}

type IPSet

type IPSet struct {
	Name         string
	HashType     string
	HashFamily   string
	HashSize     int
	MaxElem      int
	Timeout      int
	WithComments bool
}

func NewIPset

func NewIPset(name, hashtype string, p *Params) (*IPSet, error)

func (*IPSet) Add

func (s *IPSet) Add(entry string, timeout int) error

func (*IPSet) AddComment

func (s *IPSet) AddComment(entry, comment string, timeout int) error

func (*IPSet) BulkAddComment

func (s *IPSet) BulkAddComment(entries []string, comment string, timeout int) error

func (*IPSet) Del

func (s *IPSet) Del(entry string) error

type IPSetRegistry

type IPSetRegistry struct {
	// contains filtered or unexported fields
}

func NewIPSetRegistry

func NewIPSetRegistry() *IPSetRegistry

func (*IPSetRegistry) ClearRefreshByPrefix

func (r *IPSetRegistry) ClearRefreshByPrefix(prefix string)

func (*IPSetRegistry) ClearRefreshKey

func (r *IPSetRegistry) ClearRefreshKey(key string)

func (*IPSetRegistry) ClearStaleCountsForRule

func (r *IPSetRegistry) ClearStaleCountsForRule(ipsetName, pattern string)

func (*IPSetRegistry) CollectStaleEntries

func (r *IPSetRegistry) CollectStaleEntries(key string, existing []string, resolved map[string]struct{}, threshold int) []staleEntry

func (*IPSetRegistry) ConfirmStaleDeleted

func (r *IPSetRegistry) ConfirmStaleDeleted(key string, entries []string)

func (*IPSetRegistry) EnsureKernelFamily

func (r *IPSetRegistry) EnsureKernelFamily(name, family string) (*IPSet, error)

func (*IPSetRegistry) IsLegacySwept

func (r *IPSetRegistry) IsLegacySwept(name string) bool

func (*IPSetRegistry) IsStaticEntry

func (r *IPSetRegistry) IsStaticEntry(set, entry string) bool

func (*IPSetRegistry) LockSet

func (r *IPSetRegistry) LockSet(name string) func()

func (*IPSetRegistry) MarkLegacySwept

func (r *IPSetRegistry) MarkLegacySwept(name string)

func (*IPSetRegistry) MarkRefreshed

func (r *IPSetRegistry) MarkRefreshed(key, fingerprint string, window time.Duration)

func (*IPSetRegistry) ObtainOrCreateFamily

func (r *IPSetRegistry) ObtainOrCreateFamily(name, family string) (*IPSet, error)

func (*IPSetRegistry) RecentlyRefreshed

func (r *IPSetRegistry) RecentlyRefreshed(key, fingerprint string, window time.Duration) bool

func (*IPSetRegistry) RegisterStaticEntry

func (r *IPSetRegistry) RegisterStaticEntry(set, entry string)

func (*IPSetRegistry) SetEntryTimeout

func (r *IPSetRegistry) SetEntryTimeout(seconds int)

func (*IPSetRegistry) UnregisterStaticEntry

func (r *IPSetRegistry) UnregisterStaticEntry(set, entry string)

type IpRuleManager

type IpRuleManager struct {
	// contains filtered or unexported fields
}

func NewIpRuleManager

func NewIpRuleManager(matcher DomainRuleMatcher, opts RuleRuntimeOptions, registry *IPSetRegistry) *IpRuleManager

func (*IpRuleManager) DropAAAA

func (m *IpRuleManager) DropAAAA(domain string) bool

func (*IpRuleManager) PrepareAnswers

func (m *IpRuleManager) PrepareAnswers(domain string, ips []net.IP) error

func (*IpRuleManager) ResyncAnswers

func (m *IpRuleManager) ResyncAnswers(domain string, ips []net.IP) error

func (*IpRuleManager) SyncFromAnswers

func (m *IpRuleManager) SyncFromAnswers(domain string, ips []net.IP) error

type IptablesManager

type IptablesManager struct {
	// contains filtered or unexported fields
}

func NewIptablesManager

func NewIptablesManager(ipv6Enabled, tproxyEnabled bool, ipsetEntryTimeout int, localExceptions []string) *IptablesManager

func (*IptablesManager) AddMarkRoute

func (i *IptablesManager) AddMarkRoute(vpnType vpnkind.Kind, ipsetName string, lanIfaces []string, vpnIface string) error

func (*IptablesManager) AddRules

func (i *IptablesManager) AddRules(vpnType vpnkind.Kind, ipsetName string, param int, iface, vpnIface string) error

func (*IptablesManager) BatchApplyAllRedirect

func (i *IptablesManager) BatchApplyAllRedirect(specs []ChainSpec) error

func (*IptablesManager) BatchApplyAllTProxy

func (i *IptablesManager) BatchApplyAllTProxy(specs []ChainSpec) error

func (*IptablesManager) CleanupStaleState

func (i *IptablesManager) CleanupStaleState()

func (*IptablesManager) EnsureMarkIPSets

func (i *IptablesManager) EnsureMarkIPSets(ipsetName string) error

func (*IptablesManager) IPv6Enabled

func (i *IptablesManager) IPv6Enabled() bool

func (*IptablesManager) ListXrayIPSets

func (i *IptablesManager) ListXrayIPSets() []string

func (*IptablesManager) MarkRouteIntact

func (i *IptablesManager) MarkRouteIntact(ipsetName string) bool

func (*IptablesManager) MarkRouteKnown

func (i *IptablesManager) MarkRouteKnown(ipsetName string) bool

func (*IptablesManager) PrepareXrayChain

func (i *IptablesManager) PrepareXrayChain(chain string, port int, ifaces []string) (ChainSpec, XrayRouteState, error)

func (*IptablesManager) RemoveAllXrayRoutes

func (i *IptablesManager) RemoveAllXrayRoutes()

func (*IptablesManager) RemoveMarkRoute

func (i *IptablesManager) RemoveMarkRoute(ipsetName string) error

func (*IptablesManager) RemoveRules

func (i *IptablesManager) RemoveRules(ipsetName string) error

func (*IptablesManager) RemoveRulesV4

func (i *IptablesManager) RemoveRulesV4(ipsetName string) error

func (*IptablesManager) RemoveRulesV6

func (i *IptablesManager) RemoveRulesV6(ipsetName string) error

func (*IptablesManager) RemoveXrayChain

func (i *IptablesManager) RemoveXrayChain(chain string) error

func (*IptablesManager) ResetAfterFlush

func (i *IptablesManager) ResetAfterFlush(table string, resetV4, resetV6 bool)

func (*IptablesManager) ResetXrayFamilies

func (i *IptablesManager) ResetXrayFamilies(resetV4, resetV6 bool)

func (*IptablesManager) RestoreRouting

func (i *IptablesManager) RestoreRouting(table string, restoreV4, restoreV6 bool)

func (*IptablesManager) RoutingIntact

func (i *IptablesManager) RoutingIntact() bool

func (*IptablesManager) Shutdown

func (i *IptablesManager) Shutdown()

func (*IptablesManager) SyncMarkRoute

func (i *IptablesManager) SyncMarkRoute(ipsetName, vpnIface string) error

func (*IptablesManager) TProxyEnabled

func (i *IptablesManager) TProxyEnabled() bool

func (*IptablesManager) XrayState

func (i *IptablesManager) XrayState(ipsetName string) XrayRouteState

func (*IptablesManager) XrayTable

func (i *IptablesManager) XrayTable() string

type Params

type Params struct {
	HashFamily   string
	HashSize     int
	MaxElem      int
	Timeout      int
	WithComments bool
}

type RuleRuntimeOptions

type RuleRuntimeOptions struct {
	IPv6Enabled       bool
	IPSetDebug        bool
	IPSetStaleQueries int
	IPSetEntryTimeout int
}

type UnblockManager

type UnblockManager struct {
	FilePath string
	// contains filtered or unexported fields
}

func NewUnblockManager

func NewUnblockManager(path string, ipv6Enabled bool, ipsetDebug bool, ipsetStaleQueries, ipsetEntryTimeout int, registry *IPSetRegistry) *UnblockManager

func (*UnblockManager) AddRule

func (m *UnblockManager) AddRule(vpnType, chainName, pattern string) error

func (*UnblockManager) DelChain

func (m *UnblockManager) DelChain(vpnType, chainName string) error

func (*UnblockManager) DelRule

func (m *UnblockManager) DelRule(vpnType, chainName, pattern string) error

func (*UnblockManager) GetAllRules

func (m *UnblockManager) GetAllRules() (*VPNRulesConfig, error)

func (*UnblockManager) GetRules

func (m *UnblockManager) GetRules(vpnType, chainName string) ([]string, error)

func (*UnblockManager) IPSetDebug

func (m *UnblockManager) IPSetDebug() bool

func (*UnblockManager) IPSetEntryTimeout

func (m *UnblockManager) IPSetEntryTimeout() int

func (*UnblockManager) IPSetStaleQueries

func (m *UnblockManager) IPSetStaleQueries() int

func (*UnblockManager) IPv6Enabled

func (m *UnblockManager) IPv6Enabled() bool

func (*UnblockManager) Init

func (m *UnblockManager) Init() error

func (*UnblockManager) MatchDomain

func (m *UnblockManager) MatchDomain(domain string) (string, string, string, bool)

func (*UnblockManager) ResyncStaticEntries

func (m *UnblockManager) ResyncStaticEntries() (int, error)

type VPNRuleSet

type VPNRuleSet map[string][]string

type VPNRulesConfig

type VPNRulesConfig struct {
	Rules map[string]VPNRuleSet `yaml:",inline"`
}

func (*VPNRulesConfig) Clone

func (v *VPNRulesConfig) Clone() *VPNRulesConfig

type XrayRouteState

type XrayRouteState struct {
	Known     bool
	V4Applied bool
	V6Applied bool
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL