|
| 1 | +package firewall |
| 2 | + |
| 3 | +import ( |
| 4 | + "common/modulefirewall" |
| 5 | + "common/settings" |
| 6 | + "common/system" |
| 7 | + "fmt" |
| 8 | + "nvm/log" |
| 9 | + "strings" |
| 10 | +) |
| 11 | + |
| 12 | +// Event codes (NVM44xx firewall range). |
| 13 | +const ( |
| 14 | + CodePolicyMutate = 4401 |
| 15 | + CodeElevationRequired = 4404 |
| 16 | + CodeInvalidRule = 4405 |
| 17 | +) |
| 18 | + |
| 19 | +type Root struct { |
| 20 | + Trust TrustRoot `cmd:"trust" help:"Manage TrustedModules for self-updating global CLIs."` |
| 21 | + PromptTrust PromptTrust `cmd:"prompt-trust" hidden:"true" help:"Internal: dual-channel trust prompt for proxy."` |
| 22 | +} |
| 23 | + |
| 24 | +type TrustRoot struct { |
| 25 | + Module TrustModule `cmd:"module" help:"Manage TrustedModules (self-update auto-reshim allow list)."` |
| 26 | +} |
| 27 | + |
| 28 | +type TrustModule struct { |
| 29 | + Entries []string `arg:"" name:"entry" help:"Module patterns to trust for auto-reshim (or NOT to revoke)."` |
| 30 | +} |
| 31 | + |
| 32 | +func requireMachine() error { |
| 33 | + if err := system.RequireAdministrator(); err != nil { |
| 34 | + log.ErrorStructured("firewall.elevation_required", map[string]any{ |
| 35 | + "error": err.Error(), |
| 36 | + }, CodeElevationRequired) |
| 37 | + return fmt.Errorf("firewall policy changes require an elevated administrator prompt (NVM%d): %w", CodeElevationRequired, err) |
| 38 | + } |
| 39 | + return nil |
| 40 | +} |
| 41 | + |
| 42 | +func appendSettingsList(cfgKey, regLabel string, add []string, negate bool) error { |
| 43 | + if err := requireMachine(); err != nil { |
| 44 | + return err |
| 45 | + } |
| 46 | + cur, _ := settings.Get(cfgKey) |
| 47 | + var list []string |
| 48 | + switch v := cur.(type) { |
| 49 | + case []string: |
| 50 | + list = append([]string{}, v...) |
| 51 | + case string: |
| 52 | + if strings.TrimSpace(v) != "" { |
| 53 | + list = []string{v} |
| 54 | + } |
| 55 | + } |
| 56 | + for _, e := range add { |
| 57 | + e = strings.TrimSpace(e) |
| 58 | + if e == "" { |
| 59 | + continue |
| 60 | + } |
| 61 | + if negate && !strings.HasPrefix(strings.ToLower(e), "not ") && !strings.HasPrefix(e, "!") { |
| 62 | + e = "NOT " + e |
| 63 | + } |
| 64 | + if err := modulefirewall.ValidateRuleEntry(e); err != nil { |
| 65 | + log.ErrorStructured("firewall.invalid_rule", map[string]any{ |
| 66 | + "key": cfgKey, |
| 67 | + "entry": e, |
| 68 | + "error": err.Error(), |
| 69 | + }, CodeInvalidRule) |
| 70 | + return fmt.Errorf("invalid firewall entry %q (NVM%d): %w", e, CodeInvalidRule, err) |
| 71 | + } |
| 72 | + list = append(list, e) |
| 73 | + } |
| 74 | + if err := settings.PutMachine(cfgKey, list); err != nil { |
| 75 | + log.ErrorStructured("firewall.policy_mutate_failed", map[string]any{ |
| 76 | + "key": cfgKey, |
| 77 | + "error": err.Error(), |
| 78 | + }, CodePolicyMutate) |
| 79 | + return err |
| 80 | + } |
| 81 | + log.Logf("firewall: updated %s (+%d entries)", regLabel, len(add)) |
| 82 | + log.LogStructured("firewall.policy_mutated", map[string]any{ |
| 83 | + "key": cfgKey, |
| 84 | + "added": add, |
| 85 | + "negate": negate, |
| 86 | + "action": "append", |
| 87 | + }, CodePolicyMutate) |
| 88 | + return nil |
| 89 | +} |
| 90 | + |
| 91 | +func (t *TrustModule) Run() error { |
| 92 | + return appendSettingsList("trusted_modules", "TrustedModules", t.Entries, false) |
| 93 | +} |
0 commit comments