Skip to content

Commit

Permalink
fix: 优化防火墙端口转发错误信息 (#6967)
Browse files Browse the repository at this point in the history
  • Loading branch information
ssongliu authored Nov 6, 2024
1 parent eb01649 commit 8d35c54
Show file tree
Hide file tree
Showing 6 changed files with 42 additions and 13 deletions.
22 changes: 22 additions & 0 deletions backend/app/service/firewall.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ import (

"github.com/1Panel-dev/1Panel/backend/app/dto"
"github.com/1Panel-dev/1Panel/backend/app/model"
"github.com/1Panel-dev/1Panel/backend/buserr"
"github.com/1Panel-dev/1Panel/backend/constant"
"github.com/1Panel-dev/1Panel/backend/global"
"github.com/1Panel-dev/1Panel/backend/utils/cmd"
Expand Down Expand Up @@ -86,6 +87,11 @@ func (u *FirewallService) SearchWithPage(req dto.RuleSearch) (int64, interface{}
case "port":
rules, err = client.ListPort()
case "forward":
isSupport, errSup := checkIsSupport()
if !isSupport {
return 0, nil, errSup
}

rules, err = client.ListForward()
case "address":
rules, err = client.ListAddress()
Expand Down Expand Up @@ -306,6 +312,11 @@ func (u *FirewallService) OperatePortRule(req dto.PortRuleOperate, reload bool)
}

func (u *FirewallService) OperateForwardRule(req dto.ForwardRuleOperate) error {
isSupport, errSup := checkIsSupport()
if !isSupport {
return errSup
}

client, err := firewall.NewFirewallClient()
if err != nil {
return err
Expand Down Expand Up @@ -689,3 +700,14 @@ func checkPortUsed(ports, proto string, apps []portOfApp) string {
}
return ""
}

func checkIsSupport() (bool, error) {
std, err := cmd.Exec("iptables --version")
if err != nil {
return false, fmt.Errorf("handle iptables --version failed, stdout: %s, err: %v", std, err)
}
if strings.Contains(std, "nf_tables") {
return false, buserr.New(constant.ErrNFTables)
}
return true, nil
}
4 changes: 3 additions & 1 deletion backend/constant/errs.go
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,9 @@ var (
)

var (
ErrFirewall = "ErrFirewall"
ErrFirewallNone = "ErrFirewallNone"
ErrFirewallBoth = "ErrFirewallBoth"
ErrNFTables = "ErrNFTables"
)

// cronjob
Expand Down
4 changes: 3 additions & 1 deletion backend/i18n/lang/en.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -165,7 +165,9 @@ ErrConfigAlreadyExist: "A configuration file with the same name already exists"
ErrUserFindErr: "Failed to find user {{ .name }} {{ .err }}"

#ssh
ErrFirewall: "No firewalld or ufw service is detected. Please check and try again!"
ErrFirewallNone: "No firewalld or ufw service detected on the system. Please check and try again!"
ErrFirewallBoth: "Both firewalld and ufw services are detected on the system. To avoid conflicts, please uninstall one and try again!"
ErrNFTables: "Port forwarding functionality relies on the iptables service and is currently not compatible with nftables operations!"

#cronjob
ErrBashExecute: "Script execution error, please check the specific information in the task output text area."
Expand Down
4 changes: 3 additions & 1 deletion backend/i18n/lang/zh-Hant.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -166,7 +166,9 @@ ErrConfigAlreadyExist: "已存在同名配置文件"
ErrUserFindErr: "用戶 {{ .name }} 查找失敗 {{ .err }}"

#ssh
ErrFirewall: "當前未檢測到系統 firewalld 或 ufw 服務,請檢查後重試!"
ErrFirewallNone: "未檢測到系統 firewalld 或 ufw 服務,請檢查後重試!"
ErrFirewallBoth: "檢測到系統同時存在 firewalld 或 ufw 服務,為避免衝突,請卸載後重試!"
ErrNFTables: "端口轉發功能依賴於 iptables 服務,暫不兼容 nftables 操作!"

#cronjob
ErrBashExecute: "腳本執行錯誤,請在任務輸出文本域中查看具體信息。"
Expand Down
4 changes: 3 additions & 1 deletion backend/i18n/lang/zh.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -168,7 +168,9 @@ ErrConfigAlreadyExist: "已存在同名配置文件"
ErrUserFindErr: "用户 {{ .name }} 查找失败 {{ .err }}"

#ssh
ErrFirewall: "当前未检测到系统 firewalld 或 ufw 服务,请检查后重试!"
ErrFirewallNone: "未检测到系统 firewalld 或 ufw 服务,请检查后重试!"
ErrFirewallBoth: "检测到系统同时存在 firewalld 或 ufw 服务,为避免冲突,请卸载后重试!"
ErrNFTables: "端口转发功能依赖于 iptables 服务,暂不兼容 nftables 操作!"

#cronjob
ErrBashExecute: "脚本执行错误,请在任务输出文本域中查看具体信息。"
Expand Down
17 changes: 8 additions & 9 deletions backend/utils/firewall/client.go
Original file line number Diff line number Diff line change
@@ -1,10 +1,9 @@
package firewall

import (
"os"

"github.com/1Panel-dev/1Panel/backend/buserr"
"github.com/1Panel-dev/1Panel/backend/constant"
"github.com/1Panel-dev/1Panel/backend/utils/cmd"
"github.com/1Panel-dev/1Panel/backend/utils/firewall/client"
)

Expand All @@ -29,18 +28,18 @@ type FirewallClient interface {
}

func NewFirewallClient() (FirewallClient, error) {
_, firewalldErr := os.Stat("/usr/sbin/firewalld")
_, ufwErr := os.Stat("/usr/sbin/ufw")
firewalld := cmd.Which("firewalld")
ufw := cmd.Which("ufw")

if firewalldErr == nil && ufwErr == nil {
return nil, buserr.New("firewalld and ufw both found, only one firewall should be active")
if firewalld && ufw {
return nil, buserr.New(constant.ErrFirewallBoth)
}

if firewalldErr == nil {
if firewalld {
return client.NewFirewalld()
}
if ufwErr == nil {
if ufw {
return client.NewUfw()
}
return nil, buserr.New(constant.ErrFirewall)
return nil, buserr.New(constant.ErrFirewallNone)
}

0 comments on commit 8d35c54

Please # to comment.