Commit 84076f29 authored by Haw Loeung's avatar Haw Loeung Committed by Brian May

Handle when default chains already exists (#392)

parent ad31ac4e
import socket import socket
from sshuttle.firewall import subnet_weight from sshuttle.firewall import subnet_weight
from sshuttle.helpers import Fatal, log
from sshuttle.linux import nft, nft_get_handle, nonfatal from sshuttle.linux import nft, nft_get_handle, nonfatal
from sshuttle.methods import BaseMethod from sshuttle.methods import BaseMethod
...@@ -21,16 +22,19 @@ class Method(BaseMethod): ...@@ -21,16 +22,19 @@ class Method(BaseMethod):
def _nft(action, *args): def _nft(action, *args):
return nft(family, table, action, *args) return nft(family, table, action, *args)
chain = 'sshuttle-%s' % port
# basic cleanup/setup of chains # basic cleanup/setup of chains
_nft('add table', '') _nft('add table', '')
_nft('add chain', 'prerouting', # prerouting, postrouting, and output chains may already exist
'{ type nat hook prerouting priority -100; policy accept; }') for chain in ['prerouting', 'postrouting', 'output']:
_nft('add chain', 'postrouting', rules = '{{ type nat hook {} priority -100; policy accept; }}' \
'{ type nat hook postrouting priority 100; policy accept; }') .format(chain)
_nft('add chain', 'output', try:
'{ type nat hook output priority -100; policy accept; }') _nft('add chain', chain, rules)
except Fatal:
log('Chain {} already exists, ignoring\n'.format(chain))
chain = 'sshuttle-%s' % port
_nft('add chain', chain) _nft('add chain', chain)
_nft('flush chain', chain) _nft('flush chain', chain)
_nft('add rule', 'output jump %s' % chain) _nft('add rule', 'output jump %s' % chain)
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment