#!/bin/bash
# 
# This script is used for Administration of RSBAC Network Templates
#
#
# Make sure we're really running bash.
#
[ -z "$BASH" ] && { echo "This menu requires bash" 1>&2; exit 1; }

#
# Cache function definitions, turn off posix compliance
#
set -h +o posix

# The dir for tmp files
if test -z "$TMPDIR" ; then TMPDIR=/tmp ; fi

# Set conf filename
RSBACCONF=/etc/rsbac.conf
# Read settings
if test -f $RSBACCONF
then . $RSBACCONF
fi
if test -f ~/.rsbacrc
then . ~/.rsbacrc
fi
if test -z "$RSBACMOD"
then RSBACMOD='GEN MAC PM DAZ FF RC AUTH ACL CAP JAIL RES PAX'
fi
for i in $RSBACMOD
do
  export SHOW_${i}=yes
done

# This must be a unique temporary filename
TMPFILE=`mktemp -q $TMPDIR/rsbac_dialog.XXXXXX`
if test -z $TMPFILE
then
  TMPFILE=$TMPDIR/rsbac_dialog.$$
  if test -e $TMPFILE
  then rm $TMPFILE
  fi
fi
TMPFILETWO=`mktemp -q $TMPDIR/rsbac_dialog.XXXXXX`
if test -z $TMPFILETWO
then
  TMPFILETWO=$TMPDIR/rsbac_dialog.$$.2
  if test -e $TMPFILETWO
  then rm $TMPFILETWO
  fi
fi

# set this to rsbac bin dir, if not in path (trailing / is mandatory!)
#
#if test -z "$RSBACPATH" ; then RSBACPATH=./ ; fi

# set this to initial dir on script startup
LASTDIR='.'

# which dialog tool to use - dialog or kdialog or xdialog...
if test -z $DIALOG
then DIALOG=${RSBACPATH}dialog
fi
if ! $DIALOG --clear
then
  echo $DIALOG menu program required! >&2
  exit
fi
if ! $DIALOG --help 2>&1 | grep -q "help-button"
then
  echo "Newer dialog menu version >= 0.9a-20020309a with '--help-button' option" >&2
  echo "required, please use dialog from admin tools contrib dir or set" >&2
  echo "\$DIALOG to another dialog program, e.g. with rsbac_settings_menu!" >&2
  exit
fi

set_geometry ()
{
        BL=${1:-24}
        BC=${2:-80}
        [ $BL = 0 ] && BL=24
        [ $BC = 0 ] && BC=80
        export LINES=$BL
        export COLUMNS=$BC
        BL=$((BL-4))
        BC=$((BC-5))
        MAXLINES=$((LINES-10))
}

set_geometry `stty size 2>/dev/null`

gl ()
{
        if test $1 -gt $MAXLINES
        then echo $MAXLINES
        else echo $1
        fi
}

if test -z "$LINES" ; then LINES=25 ; fi
if test -z "$COLUMNS" ; then COLUMNS=80 ; fi
export LINES
export COLUMNS
declare -i BL=$LINES-4
declare -i BC=$COLUMNS-4
declare -i MAXWIDTH=$BC-26
declare -i MAXLINES=$LINES-10

if test -z "$BACKTITLE"
then BACKTITLE="RSBAC Administration Tools 1.4.0"
fi
TITLE="`whoami`@`hostname`: RSBAC Network Template Administration"
HELPTITLE="$TITLE Help"
ERRTITLE="RSBAC Network Template Administration - ERROR"

## no changes below this line!

NO_USER=65533
ALL_USERS=65532
GETMODE=real
GETSWITCH=

declare -i MAXCOMPLEN=$BC-40
comp_print () {
  if test ${#1} -le $MAXCOMPLEN
  then echo $1
  else echo ${1:0:$MAXCOMPLEN}'*'
  fi
}

show_help () {
 {
  echo "$1"
  echo ""
  case "$1" in
    'Add Template')
      echo "Add another template with ID number and name."
      ;;

    "Remove Template")
      echo "Remove a template."
      ;;

    Name)
      echo "New name for template."
      ;;

    "Address Family")
      echo "Choose Address Family. Select ANY to match any family."
      ;;

    "Socket Type")
      echo "Type of socket: Mostly stream, datagram or raw."
      echo ""
      echo "Set to ANY to match any type."
      ;;

    Address)
      echo "Enter Address - only INET (IPv4, a.b.c.d/n address)"
      echo "family addresses are currently supported. For all other families, the"
      echo "address is ignored by the matching code."
      echo ""
      echo "Leave empty to never match any INET address."
      echo ""
      echo "The number of supported families will be increased later."
      ;;

    "Protocol")
      echo "INET (IPv4) family protocol type."
      echo ""
      echo "Set to ANY to match any protocol."
      ;;

    "Network Device")
      echo "Local device name. Only usable for local addresses, otherwise any string"
      echo "entered here will result in no match!"
      echo ""
      echo "Leave empty to match any device."
      ;;

    "Ports")
      echo "Port ranges matched. Useful mostly for INET family."
      echo "Note: ICMP protocol packet types are also matched as port numbers."
      ;;

    "NetTemp Attributes")
      echo "Go to Network Template attribute menu for this template."
      ;;

    Quit)
      echo 'Quit this menu.'
      ;;

    *)
        echo "No help for $1 available!"
  esac
 } > $TMPFILE
  $DIALOG --title "$HELPTITLE" \
          --backtitle "$BACKTITLE" \
          --textbox $TMPFILE $BL $BC
#  sleep 1
}

onoff () {
   if test "$1" = "$2"
     then echo on
   else echo off
   fi
}

gen_tlist () {
  $RSBACPATH""net_temp list_temp_names|sort -n
}

template_menu () {
  TEMPLATE=$1
  if $RSBACPATH""net_temp get_name $TEMPLATE >$TMPFILE 2>$TMPFILETWO
  then NAME=`cat $TMPFILE`
  else
    $DIALOG --title "$ERRTITLE" \
           --backtitle "$BACKTITLE" \
           --msgbox "`head -n 1 $TMPFILETWO`" $BL $BC
    return
  fi
  ADDRFAM=`$RSBACPATH""net_temp get_address_family $TEMPLATE`
  ADDR=`$RSBACPATH""net_temp get_address $TEMPLATE`
  TYPE=`$RSBACPATH""net_temp get_type $TEMPLATE`
  PROTO=`$RSBACPATH""net_temp get_protocol $TEMPLATE`
  NETDEV=`$RSBACPATH""net_temp get_netdev $TEMPLATE`
  PORTS=`$RSBACPATH""net_temp get_ports $TEMPLATE`
  while true ; do \
    if ! \
    $DIALOG --title "$TITLE" \
           --backtitle "$BACKTITLE" \
           --help-button --default-item "$SELECTED" \
           --menu "Template Menu - Template $TEMPLATE" $BL $BC 12 \
                  "Name" "$NAME" \
                  "Address Family" "$ADDRFAM" \
                  "Socket Type" "$TYPE" \
                  "Address" "$(comp_print "$ADDR")" \
                  "Protocol" "$PROTO" \
                  "Network Device" "$NETDEV" \
                  "Ports" "$(comp_print "$PORTS")" \
                  "--------------" "" \
                  "Remove Template" "Remove this template" \
                  "--------------" "" \
                  "NetTemp Attributes" "Go to NetTemp attributes" \
                  "Quit" "" \
           2>$TMPFILE
    then rm $TMPFILETWO ; return
    fi

    SELECTED=`cat $TMPFILE`
    case $SELECTED in
      HELP*)
          show_help "${SELECTED:5}"
          SELECTED="${SELECTED:5}"
        ;;

      Name)
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --max-input 15 \
                    --inputbox "New name for Template $TEMPLATE (maxlen = 15)" $BL $BC "$NAME" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            if $RSBACPATH""net_temp set_name $TEMPLATE "$TMP" &>$TMPFILE
            then
              NAME="$TMP"
              if test -n "$RSBACLOGFILE"
              then
                echo $RSBACPATH""net_temp set_name $TEMPLATE \"$TMP\" >>"$RSBACLOGFILE"
              fi
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

      "Address Family")
        if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --default-item "$ADDRFAM" \
                   --menu "Choose Address Family for Template $TEMPLATE / $NAME" $BL $BC `gl 27` \
                      "ANY"		"0 Match any Address Family" \
                      "UNIX"		"1 Unix sockets - never matched" \
                      "INET"		"2 Internet IP Protocol" \
                      "AX25"		"3 Amateur Radio AX.25" \
                      "IPX"		"4 Novell IPX" \
                      "APPLETALK"	"5 AppleTalk DDP" \
                      "NETROM"		"6 Amateur Radio NET/ROM" \
                      "BRIDGE"		"7 Multiprotocol bridge" \
                      "ATMPVC"		"8 ATM PVCs" \
                      "X25"		"9 Reserved for X.25 project" \
                      "INET6"		"10 IP version 6" \
                      "ROSE"		"11 Amateur Radio X.25 PLP" \
                      "DECnet"		"12 Reserved for DECnet project" \
                      "NETBEUI"		"13 Reserved for 802.2LLC project" \
                      "SECURITY"	"14 Security callback pseudo AF" \
                      "KEY"		"15 PF_KEY key management API" \
                      "NETLINK"		"16" \
                      "PACKET"		"17 Packet family" \
                      "ASH"		"18 Ash" \
                      "ECONET"		"19 Acorn Econet" \
                      "ATMSVC"		"20 ATM SVCs" \
                      "SNA"		"22 Linux SNA Project (nutters!)" \
                      "IRDA"		"23 IRDA sockets" \
                      "PPPOX"		"24 PPPoX sockets" \
                      "WANPIPE"		"25 Wanpipe API Sockets" \
                      "BLUETOOTH"	"31 Bluetooth sockets" \
                      "MAX"		"32 Maximum Value - never matched" \
          2>$TMPFILE
        then TMP=`cat $TMPFILE`
             if $RSBACPATH""net_temp set_address_family $TEMPLATE $TMP &>$TMPFILE
             then
               ADDRFAM=$TMP
               ADDR=`$RSBACPATH""net_temp get_address $TEMPLATE`
               if test -n "$RSBACLOGFILE"
               then
                 echo $RSBACPATH""net_temp set_address_family $TEMPLATE $TMP >>"$RSBACLOGFILE"
               fi
             else \
               $DIALOG --title "$ERRTITLE" \
                       --backtitle "$BACKTITLE" \
                       --msgbox "`head -n 1 $TMPFILE`" $BL $BC
             fi
        fi
        ;;

      "Socket Type")
        if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --default-item "$TYPE" \
                   --menu "Choose Socket Type for Template $TEMPLATE / $NAME" $BL $BC `gl 27` \
                      "ANY"		"0 Match any Socket Type" \
                      "STREAM"		"1 stream (connection) socket" \
                      "DGRAM"		"2 datagram (conn.less) socket" \
                      "RAW"		"3 raw socket" \
                      "RDM"		"4 reliably-delivered message" \
                      "SEQPACKET"	"5 sequential packet socket" \
                      "PACKET"		"10 getting packets at the dev/user level (rarp etc.)" \
                      "MAX"		"32 Maximum Value - never matched" \
          2>$TMPFILE
        then TMP=`cat $TMPFILE`
             if $RSBACPATH""net_temp set_type $TEMPLATE $TMP &>$TMPFILE
             then
               TYPE=$TMP
               if test -n "$RSBACLOGFILE"
               then
                 echo $RSBACPATH""net_temp set_type $TEMPLATE $TMP >>"$RSBACLOGFILE"
               fi
             else \
               $DIALOG --title "$ERRTITLE" \
                       --backtitle "$BACKTITLE" \
                       --msgbox "`head -n 1 $TMPFILE`" $BL $BC
             fi
        fi
        ;;

      Address)
          case $ADDRFAM in
            INET)
              ;;
            *)
              $DIALOG --title "$ERRTITLE" \
                      --backtitle "$BACKTITLE" \
                      --msgbox "Cannot set address for $ADDRFAM address family!" $BL $BC
              continue
          esac
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --max-input 127 \
                    --inputbox "New $ADDRFAM Addresses for Template $TEMPLATE (a.b.c.d/n, separate multiple addresses with spaces (max. 20), leave empty to never match)" \
                        $BL $BC "$ADDR" \
            2>$TMPFILE
          then
            TMP="`cat $TMPFILE`"
            case $ADDRFAM in
              INET)
                  if $RSBACPATH""net_temp -d set_address $TEMPLATE $TMP &>$TMPFILE
                  then
                    ADDR="`$RSBACPATH""net_temp get_address $TEMPLATE`"
                    if test -n "$RSBACLOGFILE"
                    then
                      echo $RSBACPATH""net_temp -d set_address $TEMPLATE $TMP >>"$RSBACLOGFILE"
                    fi
                  else
                    $DIALOG --title "$ERRTITLE" \
                            --backtitle "$BACKTITLE" \
                            --msgbox "`head -n 1 $TMPFILE`" $BL $BC
                  fi
                ;;
              *)
            esac
          fi
        ;;

      "Protocol")
        case "$ADDRFAM" in
          INET)
            if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --default-item "$PROTO" \
                   --menu "Choose INET Protocol for Template $TEMPLATE / $NAME" $BL $BC `gl 27` \
                      "ANY"		"0 Match any Socket Type" \
                      "ICMP"		"1 Internet Control Message Protocol" \
                      "IGMP" 		"2 Internet Group Management Protocol" \
                      "IPIP"		"4 IPIP tunnels (older KA9Q tunnels use 94)" \
                      "TCP"		"6 Transmission Control Protocol" \
                      "EGP"		"8 Exterior Gateway Protocol" \
                      "PUP"		"12 PUP protocol" \
                      "UDP"		"17 User Datagram Protocol" \
                      "IDP"		"22 XNS IDP protocol" \
                      "IPV6"		"41 IPv6-in-IPv4 tunnelling" \
                      "RSVP"		"46 RSVP protocol" \
                      "GRE"		"47 Cisco GRE tunnels (rfc 1701,1702)" \
                      "ESP"		"50 Encapsulation Security Payload protocol" \
                      "AH"		"51 Authentication Header protocol" \
                      "PIM"		"103 Protocol Independent Multicast" \
                      "COMP"		"108 Compression Header protocol" \
                      "RAW"		"255 Raw IP packets" \
                      "MAX"		"256 Maximum Value - never matched" \
              2>$TMPFILE
            then TMP=`cat $TMPFILE`
              if $RSBACPATH""net_temp set_protocol $TEMPLATE $TMP &>$TMPFILE
              then
                PROTO=$TMP
                if test -n "$RSBACLOGFILE"
                then
                  echo $RSBACPATH""net_temp set_protocol $TEMPLATE $TMP >>"$RSBACLOGFILE"
                fi
              else \
                $DIALOG --title "$ERRTITLE" \
                        --backtitle "$BACKTITLE" \
                        --msgbox "`head -n 1 $TMPFILE`" $BL $BC
              fi
            fi
            ;;
          NETLINK)
            if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --default-item "$PROTO" \
                   --menu "Choose NETLINK Protocol for Template $TEMPLATE / $NAME" $BL $BC `gl 20` \
		"ROUTE" "0 Routing/device hook" \
		"UNUSED" "1 Unused number" \
		"USERSOCK" "2 Reserved for user mode socket protocols" \
		"FIREWALL" "3 Firewalling hook" \
		"INET_DIAG" "4 INET socket monitoring" \
		"NFLOG" "5 netfilter/iptables ULOG" \
		"XFRM",	"6 ipsec" \
		"SELINUX" "7 SELinux event notifications" \
		"ISCSI" "8 Open-iSCSI" \
		"AUDIT" "9 auditing" \
		"FIB_LOOKUP" "10 FIB Lookup" \
		"CONNECTOR" "11 Connector" \
		"NETFILTER" "12 netfilter subsystem" \
		"IP6_FW" "13 IPv6 Firewall" \
		"DNRTMSG" "14 DECnet routing messages" \
		"KOBJECT_UEVENT" "15 Kernel messages to userspace" \
		"GENERIC" "16 Generic for various uses" \
		"DM", "17 (DM Events)" \
		"SCSITRANSPORT" "18 SCSI Transports" \
		"ECRYPTFS" "19 ECryptFS" \
              2>$TMPFILE
            then TMP=`cat $TMPFILE`
              if $RSBACPATH""net_temp set_protocol $TEMPLATE $TMP &>$TMPFILE
              then
                PROTO=$TMP
                if test -n "$RSBACLOGFILE"
                then
                  echo $RSBACPATH""net_temp set_protocol $TEMPLATE $TMP >>"$RSBACLOGFILE"
                fi
              else \
                $DIALOG --title "$ERRTITLE" \
                        --backtitle "$BACKTITLE" \
                        --msgbox "`head -n 1 $TMPFILE`" $BL $BC
              fi
            fi
            ;;
          *)
            $DIALOG --title "$ERRTITLE" \
                    --backtitle "$BACKTITLE" \
                    --msgbox "Cannot set protocol for $ADDRFAM address family!" $BL $BC
            ;;
        esac
        ;;

      "Network Device")
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --max-input 16 \
                    --inputbox "New local Network Device for Template $TEMPLATE (maxlen = 16)" \
                      $BL $BC "$NETDEV" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            if $RSBACPATH""net_temp set_netdev $TEMPLATE "$TMP" &>$TMPFILE
            then
              NETDEV="$TMP"
              if test -n "$RSBACLOGFILE"
              then
                echo $RSBACPATH""net_temp set_netdev $TEMPLATE \"$TMP\" >>"$RSBACLOGFILE"
              fi
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

      "Ports")
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --inputbox "New Port ranges for Template $TEMPLATE (a:b, empty = any, separate multiple port ranges with spaces (max 10))" \
                        $BL $BC "$PORTS" \
            2>$TMPFILE
          then
            TMP="`cat $TMPFILE`"
            if $RSBACPATH""net_temp set_ports $TEMPLATE $TMP &>$TMPFILE
            then
              PORTS="$TMP"
              if test -n "$RSBACLOGFILE"
              then
                echo $RSBACPATH""net_temp set_ports $TEMPLATE $TMP >>"$RSBACLOGFILE"
              fi
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

    "Remove Template")
        if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --yesno "Delete template $TEMPLATE ($NAME)?" 5 $BC \
          2>/dev/null
        then
          if $RSBACPATH""net_temp delete_template $TEMPLATE &>$TMPFILE
          then
            if test -n "$RSBACLOGFILE"
            then
              echo $RSBACPATH""net_temp delete_template $TEMPLATE >>"$RSBACLOGFILE"
            fi
            TEMPLATE=
            SELECTED=
            return
          else 
            $DIALOG --title "$ERRTITLE" \
                    --backtitle "$BACKTITLE" \
                    --msgbox "`head -n 1 $TMPFILE`" $BL $BC
          fi
        fi
      ;;

      "NetTemp Attributes")
          $RSBACPATH""rsbac_nettemp_menu $TEMPLATE
          return
        ;;

      Quit)
          rm $TMPFILETWO
          return
        ;;

      *)
          $DIALOG --title "$ERRTITLE" \
                 --backtitle "$BACKTITLE" \
                 --msgbox "Template Menu: Selection Error!" 5 $BC
        ;;

    esac
  done
}

###################### Menu #################

if test "$1" = "-h" -o "$1" = "--help"
then
  echo Use: $0 '[template-id]'
  exit
fi
if test -n "$RSBACLOGFILE"
then
  {
    echo ""
    echo "# $0 start `date`"
  } >> "$RSBACLOGFILE"
fi
if test -n "$1"
then
  SELECTED=$1
  template_menu $1
  exit
fi

while true ; do \
  if ! \
  $DIALOG --title "$TITLE" \
         --backtitle "$BACKTITLE" \
         --help-button --default-item "$SELECTED" \
         --menu "Main Menu" $BL $BC $MAXLINES \
                "Add Template" "" \
                "Remove Template" "" \
                "--------------" "" \
                `gen_tlist` \
                "--------------" "" \
                "Quit" "" \
         2>$TMPFILE
   then rm $TMPFILE ; exit
  fi

  SELECTED=`cat $TMPFILE`
  case $SELECTED in
    HELP*)
        show_help "${SELECTED:5}"
        SELECTED="${SELECTED:5}"
      ;;

    'Add Template')
        if $DIALOG --title "$TITLE" \
                  --backtitle "$BACKTITLE" \
                  --inputbox "Number for new template" $BL $BC "" \
           2>$TMPFILE
        then
          TEMPID=`cat $TMPFILE`
          if $DIALOG --title "$TITLE" \
                     --backtitle "$BACKTITLE" \
                     --max-input 15 \
                     --inputbox "Name for new template (maxlen = 15)" $BL $BC "New Template" \
            2>$TMPFILE
          then
            TEMPNAME=`cat $TMPFILE`
            if test -n "$TEMPNAME"
            then
              if $RSBACPATH""net_temp new_template $TEMPID "$TEMPNAME" &>$TMPFILE
              then
                SELECTED=$TEMPID
                if test -n "$RSBACLOGFILE"
                then
                  echo $RSBACPATH""net_temp new_template $TEMPID \"$TEMPNAME\" >>"$RSBACLOGFILE"
                fi
              else
                $DIALOG --title "$ERRTITLE" \
                        --backtitle "$BACKTITLE" \
                        --msgbox "`head -n 1 $TMPFILE`" $BL $BC
              fi
            fi
          fi
        fi
      ;;

    "Remove Template")
        if $DIALOG --title "$TITLE" \
                  --backtitle "$BACKTITLE" \
                  --default-item "$SELECTED" \
                  --menu "Choose template to delete" $BL $BC $MAXLINES \
                  `gen_tlist` \
               2>$TMPFILE
        then
          TMP=`cat $TMPFILE`
          if $DIALOG --title "$TITLE" \
                     --backtitle "$BACKTITLE" \
                     --yesno "Delete template $TMP?" 5 $BC \
            2>/dev/null
          then
            if $RSBACPATH""net_temp delete_template $TMP &>$TMPFILE
            then
              if test -n "$RSBACLOGFILE"
              then
                echo $RSBACPATH""net_temp delete_template $TMP >>"$RSBACLOGFILE"
              fi
            else 
              $DIALOG --title "$ERRTITLE" \
                      --backtitle "$BACKTITLE" \
                      --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        fi
      ;;

    Quit)
        rm $TMPFILE ; exit
      ;;

    -------------------)
        $DIALOG --title "$ERRTITLE" \
               --backtitle "$BACKTITLE" \
               --msgbox "Main Menu: Selection Error!" 5 $BC
      ;;

    *)
      template_menu $SELECTED
      ;;

  esac
# sleep 2
done
