2023-05-21 16:37:59 +00:00
|
|
|
package matcher
|
|
|
|
|
|
|
|
import (
|
|
|
|
"net/netip"
|
|
|
|
|
|
|
|
"github.com/juanfont/headscale/hscontrol/util"
|
|
|
|
"go4.org/netipx"
|
|
|
|
"tailscale.com/tailcfg"
|
|
|
|
)
|
|
|
|
|
|
|
|
type Match struct {
|
|
|
|
Srcs *netipx.IPSet
|
|
|
|
Dests *netipx.IPSet
|
|
|
|
}
|
|
|
|
|
|
|
|
func MatchFromFilterRule(rule tailcfg.FilterRule) Match {
|
2023-06-08 17:50:59 +00:00
|
|
|
dests := []string{}
|
|
|
|
for _, dest := range rule.DstPorts {
|
|
|
|
dests = append(dests, dest.IP)
|
|
|
|
}
|
|
|
|
|
|
|
|
return MatchFromStrings(rule.SrcIPs, dests)
|
|
|
|
}
|
|
|
|
|
|
|
|
func MatchFromStrings(sources, destinations []string) Match {
|
2023-05-21 16:37:59 +00:00
|
|
|
srcs := new(netipx.IPSetBuilder)
|
|
|
|
dests := new(netipx.IPSetBuilder)
|
|
|
|
|
2023-06-08 17:50:59 +00:00
|
|
|
for _, srcIP := range sources {
|
2023-05-21 16:37:59 +00:00
|
|
|
set, _ := util.ParseIPSet(srcIP, nil)
|
|
|
|
|
|
|
|
srcs.AddSet(set)
|
|
|
|
}
|
|
|
|
|
2023-06-08 17:50:59 +00:00
|
|
|
for _, dest := range destinations {
|
|
|
|
set, _ := util.ParseIPSet(dest, nil)
|
2023-05-21 16:37:59 +00:00
|
|
|
|
|
|
|
dests.AddSet(set)
|
|
|
|
}
|
|
|
|
|
|
|
|
srcsSet, _ := srcs.IPSet()
|
|
|
|
destsSet, _ := dests.IPSet()
|
|
|
|
|
|
|
|
match := Match{
|
|
|
|
Srcs: srcsSet,
|
|
|
|
Dests: destsSet,
|
|
|
|
}
|
|
|
|
|
|
|
|
return match
|
|
|
|
}
|
|
|
|
|
|
|
|
func (m *Match) SrcsContainsIPs(ips []netip.Addr) bool {
|
|
|
|
for _, ip := range ips {
|
|
|
|
if m.Srcs.Contains(ip) {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
|
|
|
func (m *Match) DestsContainsIP(ips []netip.Addr) bool {
|
|
|
|
for _, ip := range ips {
|
|
|
|
if m.Dests.Contains(ip) {
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return false
|
|
|
|
}
|