aboutsummaryrefslogtreecommitdiffstats
path: root/home/root/arrakis.nix
diff options
context:
space:
mode:
Diffstat (limited to 'home/root/arrakis.nix')
-rw-r--r--home/root/arrakis.nix65
1 files changed, 64 insertions, 1 deletions
diff --git a/home/root/arrakis.nix b/home/root/arrakis.nix
index d9d9162..ea918fe 100644
--- a/home/root/arrakis.nix
+++ b/home/root/arrakis.nix
@@ -5,7 +5,69 @@
];
home.file = {
+ "bin/games-fw" = {
+ executable = true;
+ text = ''
+ #!${pkgs.zsh}/bin/zsh
+
+ # load module to parse command line arguments
+ zmodload zsh/zutil
+ zparseopts -D -E -A opts -- d h l x
+
+ # enable XTRACE shell option for full debugging output of scripts
+ if (( ''${+opts[-x]} )); then
+ set -x
+ fi
+
+ if ! (( ''${+opts[-l]} )) && [[ -z "''${1}" ]] || (( ''${+opts[-h]} )); then
+ echo "usage: ''${0:t} [ -h ] [ -x ] { -d handle | -l | cidr }" >&2
+ echo '
+ -d delete a rule by handle; handle must be specified ( nft -a list ruleset )
+ -h this message
+ -l list games chain
+ -x enable shell debugging
+ cidr IPv4 host or CIDR network address
+ ' >&2
+ exit 1
+ fi
+
+ function list_games_chain {
+ nft -a list ruleset | sed -ne '/\tchain games {/,/\t}$/p'
+ }
+
+ if (( ''${+opts[-d]} )); then
+
+ handle="''${1}"
+ rule=$(nft -a list ruleset | grep ' # handle '"''${handle}"'$')
+
+ if [[ -z "''${rule}" ]]; then
+ echo 'no matching handle found!' >&2
+ exit 1
+ else
+
+ nft delete rule inet nixos-fw games handle ''${handle}
+ list_games_chain
+
+ fi
+
+ elif (( ''${+opts[-l]} )); then
+
+ list_games_chain
+
+ else
+
+ cidr="''${1}"
+ nft insert rule inet nixos-fw games 'ip saddr '"''${cidr}"' counter accept'
+ list_games_chain
+
+ fi
+
+ exit 0
+ '';
+ };
+
"bin/knock".source = ../common/scripts/knock;
+
"bin/vpnctl" = {
executable = true;
text = ''
@@ -20,7 +82,8 @@
function start_vpn {
- ip netns add vpn
+ ip netns add vpn
+ ip netns exec vpn ip link set lo up
ip link add veth.host type veth peer veth.vpn
ip link set dev veth.host up
ip link set veth.vpn netns vpn up