Aktualisisert von Coderberg
This commit is contained in:
parent
8caa3cf881
commit
0ccf139311
41 changed files with 649 additions and 186 deletions
|
|
@ -1,2 +1,3 @@
|
|||
---
|
||||
exam_mode: true
|
||||
exam_teacherpc_last_digit: 80
|
||||
|
|
|
|||
|
|
@ -5,10 +5,16 @@
|
|||
|
||||
if [[ "${PAM_USER}" =~ -exam$ ]]; then
|
||||
systemctl start firewalld.service
|
||||
if [[ -f /usr/local/sbin/no-way-out-nftable ]]; then
|
||||
/usr/local/sbin/no-way-out-nftable || true
|
||||
fi
|
||||
if systemctl is-enabled --quiet libvirtd.service; then
|
||||
systemctl restart libvirtd.service
|
||||
fi
|
||||
elif ! (users | grep -q -- "-exam"); then
|
||||
if /usr/sbin/nft list tables | /usr/bin/grep -q filtermacvtap; then
|
||||
/usr/sbin/nft delete table netdev filtermacvtap || true
|
||||
fi
|
||||
systemctl stop firewalld.service
|
||||
if systemctl is-enabled --quiet libvirtd.service; then
|
||||
systemctl restart libvirtd.service
|
||||
|
|
|
|||
|
|
@ -50,6 +50,38 @@
|
|||
- pam-exec.sh
|
||||
- rmexam
|
||||
|
||||
- name: Append teacherPC to exam_destination_allowed_ipv4 addresses
|
||||
ansible.builtin.set_fact:
|
||||
exam_destination_allowed_ipv4: "{{ exam_destination_allowed_ipv4 + (exam_teacherpc_ips | default([ ansible_default_ipv4.address.rsplit('.', 1)[0] ~ '.' ~ exam_teacherpc_last_digit ])) }}"
|
||||
when:
|
||||
- exam_destination_allowed_ipv4 is defined
|
||||
- exam_destination_allowed_ipv4 | length > 0
|
||||
- exam_teacherpc_ips is defined or exam_teacherpc_last_digit | default('') | string | length > 0
|
||||
|
||||
- name: Install no-way-out-policy
|
||||
ansible.builtin.template:
|
||||
src: no-way-out.xml.j2
|
||||
dest: "/etc/firewalld/policies/no-way-out-{{ item }}.xml"
|
||||
mode: '0644'
|
||||
vars:
|
||||
zones:
|
||||
- HOST
|
||||
- "{{ 'libvirt' if vm_support | default(false) else '' }}"
|
||||
loop: "{{ zones | reject('match','^$') }}"
|
||||
when:
|
||||
- exam_destination_allowed_ipv4 is defined
|
||||
- exam_destination_allowed_ipv4 | length > 0
|
||||
|
||||
- name: Install no-way-out nf-table for macvtap device
|
||||
ansible.builtin.template:
|
||||
src: no-way-out-nftable.j2
|
||||
dest: "/usr/local/sbin/no-way-out-nftable"
|
||||
mode: '0755'
|
||||
when:
|
||||
- exam_destination_allowed_ipv4 is defined
|
||||
- exam_destination_allowed_ipv4 | length > 0
|
||||
- vm_support is defined and vm_support
|
||||
|
||||
- name: Enable login script via pam_exec.so
|
||||
ansible.builtin.lineinfile:
|
||||
dest: /etc/pam.d/common-session
|
||||
|
|
|
|||
43
roles/lmn_exam/templates/no-way-out-nftable.j2
Normal file
43
roles/lmn_exam/templates/no-way-out-nftable.j2
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
#!/usr/bin/bash
|
||||
|
||||
set -eu
|
||||
|
||||
interfaces=$(/usr/bin/ip link | /usr/bin/sed -En 's/.*(macvtap-.*)@.*/\1/p')
|
||||
gateway=$(/usr/bin/ip route list default | /usr/bin/head -1 | /usr/bin/cut -f 3 -d " ")
|
||||
|
||||
filterchain=""
|
||||
for interface in ${interfaces}; do
|
||||
filterchain=$(cat <<- EOF
|
||||
${filterchain}
|
||||
|
||||
chain filterin_${interface} {
|
||||
type filter hook ingress device ${interface} priority filter; policy drop;
|
||||
ip saddr \$allowed_ipv4 accept
|
||||
ip saddr ${gateway} accept
|
||||
ip saddr 255.255.255.255 accept
|
||||
ether type arp accept
|
||||
}
|
||||
|
||||
chain filterout_${interface} {
|
||||
type filter hook egress device ${interface} priority filter; policy drop;
|
||||
ip daddr \$allowed_ipv4 accept
|
||||
ip daddr ${gateway} accept
|
||||
ip daddr 255.255.255.255 accept
|
||||
ether type arp accept
|
||||
}
|
||||
EOF
|
||||
)
|
||||
done
|
||||
|
||||
|
||||
|
||||
nft_table=$(cat <<- EOF
|
||||
define allowed_ipv4 = { {{ exam_destination_allowed_ipv4 | join(",") }} }
|
||||
|
||||
table netdev filtermacvtap {
|
||||
${filterchain}
|
||||
}
|
||||
EOF
|
||||
)
|
||||
|
||||
echo "$nft_table" | /usr/sbin/nft -f -
|
||||
10
roles/lmn_exam/templates/no-way-out.xml.j2
Normal file
10
roles/lmn_exam/templates/no-way-out.xml.j2
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
<policy target="REJECT">
|
||||
{% for address in exam_destination_allowed_ipv4 %}
|
||||
<rule family="ipv4">
|
||||
<destination address="{{ address }}"/>
|
||||
<accept/>
|
||||
</rule>
|
||||
{% endfor %}
|
||||
<ingress-zone name="{{ item }}"/>
|
||||
<egress-zone name="ANY"/>
|
||||
</policy>
|
||||
Loading…
Add table
Add a link
Reference in a new issue