diff options
author | sarthurdev <965089+sarthurdev@users.noreply.github.com> | 2022-01-10 01:00:12 +0100 |
---|---|---|
committer | sarthurdev <965089+sarthurdev@users.noreply.github.com> | 2022-01-10 21:18:03 +0100 |
commit | a5ad98b2307af974dd498a84caec94fa613f7491 (patch) | |
tree | 2c5f037102ad455f22d272e8794c5394e2f34656 /src | |
parent | 436805a69df324767c3efdf8d72127bef42fd720 (diff) | |
download | vyos-1x-a5ad98b2307af974dd498a84caec94fa613f7491.tar.gz vyos-1x-a5ad98b2307af974dd498a84caec94fa613f7491.zip |
firewall: validators: T2199: Improve port validation
Diffstat (limited to 'src')
-rwxr-xr-x | src/validators/port-multi | 43 |
1 files changed, 43 insertions, 0 deletions
diff --git a/src/validators/port-multi b/src/validators/port-multi new file mode 100755 index 000000000..763d34e57 --- /dev/null +++ b/src/validators/port-multi @@ -0,0 +1,43 @@ +#!/usr/bin/python3 + +import sys +import re + +from vyos.util import read_file + +services_file = '/etc/services' + +def get_services(): + names = [] + service_data = read_file(services_file, "") + for line in service_data.split("\n"): + if not line or line[0] == '#': + continue + names.append(line.split(None, 1)[0]) + return names + +if __name__ == '__main__': + if len(sys.argv)>1: + ports = sys.argv[1].split(",") + services = get_services() + + for port in ports: + if re.match('^[0-9]{1,5}-[0-9]{1,5}$', port): + port_1, port_2 = port.split('-') + if int(port_1) not in range(1, 65535) or int(port_2) not in range(1, 65535): + print(f'Error: {port} is not a valid port range') + sys.exit(1) + if int(port_1) > int(port_2): + print(f'Error: {port} is not a valid port range') + sys.exit(1) + elif port.isnumeric(): + if int(port) not in range(1, 65535): + print(f'Error: {port} is not a valid port') + sys.exit(1) + elif port not in services: + print(f'Error: {port} is not a valid service name') + sys.exit(1) + else: + sys.exit(2) + + sys.exit(0) |