#!/bin/sh

# This file is part of netfilter-persistent
# (was iptables-persistent)
# Copyright (C) 2009, Simon Richter <sjr@debian.org>
# Copyright (C) 2010, 2014 Jonathan Wiltshire <jmw@debian.org>
#
# This program is free software; you can redistribute it and/or
# modify it under the terms of the GNU General Public License
# as published by the Free Software Foundation, either version 3
# of the License, or (at your option) any later version.

set -e

rc=0

# Source configuration
if [ -f "/etc/default/netfilter-persistent" ]; then
	. /etc/default/netfilter-persistent
fi

load_rules()
{
	if [ "${IPTABLES_RESTORE_NOFLUSH}x" = "yesx" ]; then
		NOFLUSH='--noflush'
	else
		NOFLUSH=''
	fi

	#load IPv4 rules
	if [ ! -f /etc/iptables/rules.v4 ]; then
		echo "Warning: skipping IPv4 (no rules to load)"
	else
		/sbin/iptables-restore $NOFLUSH < /etc/iptables/rules.v4 2> /dev/null
		if [ $? -ne 0 ]; then
			rc=1
		fi
	fi
}

save_rules()
{
	#save IPv4 rules
	#need at least iptable_filter loaded:
	/sbin/modprobe -q iptable_filter || true
	if [ ! -f /proc/net/ip_tables_names ]; then
		echo "Warning: skipping IPv4 (no modules loaded)"
	elif [ -x /sbin/iptables-save ]; then
		touch /etc/iptables/rules.v4
		chmod 0640 /etc/iptables/rules.v4
		/sbin/iptables-save > /etc/iptables/rules.v4
		if [ $? -ne 0 ]; then
			rc=1
		fi
	fi
}

flush_rules()
{
	if [ ! -f /proc/net/ip_tables_names ]; then
		log_action_cont_msg "Warning: skipping IPv4 (no module loaded)"
	elif [ -x /sbin/iptables ]; then
		for chain in INPUT FORWARD OUTPUT
		do
			/sbin/iptables -P $chain ACCEPT
		done
		for param in F Z X; do /sbin/iptables -$param; done
		for table in $(cat /proc/net/ip_tables_names)
		do
			/sbin/iptables -t $table -F
			/sbin/iptables -t $table -Z
			/sbin/iptables -t $table -X
		done
	fi
}

case "$1" in
start|restart|reload|force-reload)
	load_rules
	;;
save)
	save_rules
	;;
stop)
	# Why? because if stop is used, the firewall gets flushed for a variable
	# amount of time during package upgrades, leaving the machine vulnerable
	# It's also not always desirable to flush during purge
	echo "Automatic flushing disabled, use \"flush\" instead of \"stop\""
	;;
flush)
	flush_rules
	;;
*)
    echo "Usage: $0 {start|restart|reload|force-reload|save|flush}" >&2
    exit 1
    ;;
esac

exit $rc
