2023-10-06 11:16:39 +01:00
|
|
|
// Package ipset provides ipset functionality.
|
|
|
|
package ipset
|
2021-06-18 15:55:01 +01:00
|
|
|
|
|
|
|
import (
|
|
|
|
"net"
|
|
|
|
)
|
|
|
|
|
2023-10-06 11:16:39 +01:00
|
|
|
// Manager is the ipset manager interface.
|
2021-06-18 15:55:01 +01:00
|
|
|
//
|
|
|
|
// TODO(a.garipov): Perhaps generalize this into some kind of a NetFilter type,
|
|
|
|
// since ipset is exclusive to Linux?
|
2023-10-06 11:16:39 +01:00
|
|
|
type Manager interface {
|
2021-06-18 15:55:01 +01:00
|
|
|
Add(host string, ip4s, ip6s []net.IP) (n int, err error)
|
|
|
|
Close() (err error)
|
|
|
|
}
|
|
|
|
|
2023-10-06 11:16:39 +01:00
|
|
|
// NewManager returns a new ipset manager. IPv4 addresses are added to an
|
|
|
|
// ipset with an ipv4 family; IPv6 addresses, to an ipv6 ipset. ipset must
|
|
|
|
// exist.
|
2021-06-18 15:55:01 +01:00
|
|
|
//
|
|
|
|
// The syntax of the ipsetConf is:
|
|
|
|
//
|
2022-08-31 16:57:02 +01:00
|
|
|
// DOMAIN[,DOMAIN].../IPSET_NAME[,IPSET_NAME]...
|
2021-06-18 15:55:01 +01:00
|
|
|
//
|
2024-06-14 10:32:19 +01:00
|
|
|
// If ipsetConf is empty, msg and err are nil. The error's chain contains
|
|
|
|
// [errors.ErrUnsupported] if current OS is not supported.
|
2023-10-06 11:16:39 +01:00
|
|
|
func NewManager(ipsetConf []string) (mgr Manager, err error) {
|
2021-12-27 17:54:00 +00:00
|
|
|
if len(ipsetConf) == 0 {
|
|
|
|
return nil, nil
|
|
|
|
}
|
|
|
|
|
2023-10-06 11:16:39 +01:00
|
|
|
return newManager(ipsetConf)
|
2021-06-18 15:55:01 +01:00
|
|
|
}
|