This file is indexed.

/usr/share/plinth/actions/firewall is in plinth 0.24.0.

This file is owned by root:root, with mode 0o755.

The actual contents of the file can be viewed below.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
#!/usr/bin/python3
#
# This file is part of FreedomBox.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public License
# along with this program.  If not, see <http://www.gnu.org/licenses/>.
#
"""
Configuration helper for FreedomBox firewall interface.
"""

import argparse
import subprocess


def parse_arguments():
    """Return parsed command line arguments as dictionary"""
    parser = argparse.ArgumentParser()
    subparsers = parser.add_subparsers(dest='subcommand', help='Sub command')

    # Setup
    subparsers.add_parser('setup', help='Perform basic firewall setup')

    # Get status
    subparsers.add_parser('get-status',
                          help='Get whether firewalld is running')

    # Get service status
    get_enabled_services = subparsers.add_parser(
        'get-enabled-services', help='Get list of enabled services')
    get_enabled_services.add_argument(
        '--zone', help='Zone from which the list is to be retrieved',
        required=True)

    # Add a service
    add_service = subparsers.add_parser('add-service', help='Add a service')
    add_service.add_argument('service', help='Name of the service to add')
    add_service.add_argument('--zone',
                             help='Zone to which service is to be added',
                             required=True)

    # Remove a service status
    remove_service = subparsers.add_parser('remove-service',
                                           help='Remove a service')
    remove_service.add_argument('service',
                                help='Name of the service to remove')
    remove_service.add_argument(
        '--zone', help='Zone from which service is to be removed',
        required=True)

    subparsers.required = True
    return parser.parse_args()


def subcommand_setup(_):
    """Perform basic firewalld setup."""
    subprocess.call(['firewall-cmd', '--set-default-zone=external'])

    add_service('external', 'http')
    add_service('internal', 'http')
    add_service('external', 'https')
    add_service('internal', 'https')
    add_service('internal', 'dns')
    add_service('internal', 'dhcp')


def subcommand_get_status(_):
    """Print status of the firewalld service"""
    subprocess.call(['firewall-cmd', '--state'])


def subcommand_get_enabled_services(arguments):
    """Print the status of variours services"""
    subprocess.call(['firewall-cmd', '--zone', arguments.zone,
                     '--list-services'])


def subcommand_add_service(arguments):
    """Permit a service in the firewall."""
    add_service(arguments.zone, arguments.service)


def add_service(zone, service):
    """Permit a service in the firewall."""
    subprocess.call(['firewall-cmd', '--zone', zone, '--add-service', service])
    subprocess.call(['firewall-cmd', '--zone', zone, '--permanent',
                     '--add-service', service])


def subcommand_remove_service(arguments):
    """Block a service in the firewall"""
    subprocess.call(['firewall-cmd', '--zone', arguments.zone,
                     '--remove-service', arguments.service])
    subprocess.call(['firewall-cmd', '--zone', arguments.zone, '--permanent',
                     '--remove-service', arguments.service])


def main():
    """Parse arguments and perform all duties"""
    arguments = parse_arguments()

    subcommand = arguments.subcommand.replace('-', '_')
    subcommand_method = globals()['subcommand_' + subcommand]
    subcommand_method(arguments)


if __name__ == "__main__":
    main()