+
    ޠiAN  c                   sT    ^ RI t ^ RI5 ^ RIt^ RItRt ! R R4      t ! R R4      tR# )    N)Z*z0.1c                   s0   a  ] tR t^t o RtR tR tRtV tR# )SchemaValidatorz+Libnftables JSON validator using jsonschemac                s2   \         P                  P                  \         P                  P                  \        4      R 4      p\        VR4      ;_uu_ 4       p\        P                  ! V4      V n        RRR4       ^ RI	pW0n	        R#   + '       g   i     L; i)zschema.jsonZrN)
osZpathZjoinZdirnameZ__file__ZopenjsonZloadschema
jsonschema)selfZschema_pathZschema_filer   s   &   6/usr/lib/python3.14/site-packages/nftables/nftables.py__init__ZSchemaValidator.__init__   sX    ggll277??8#<mL+s##{))K0DK $$ $#s   BB	c                sR    V P                   P                  WP                  R 7       R# ))Zinstancer   N)r   validater   )r   r      &&r   r	   ZSchemaValidator.validate"   s      ${{ C    )r   r   N)	__name__
__module____qualname____firstlineno____doc__r   r	   __static_attributes____classdictcell__Z__classdict__   @r   r   r      s     5%D Dr   r   c                   s  a  ] tR t^%t o RtR^R^/tR^R^R^R^R^R	^ R
^@/tR^R^R^R^R^R^ R^@R^RRDRRERRFRRG/tRtRHR lt	R t
R tR tR tR tR tR tR tR  tR! tR" tR# tR$ tR% tR& tR' tR( tR) tR* tR+ tR, tR- tR. t R/ t!R0 t"R1 t#R2 t$R3 t%R4 t&R5 t'R6 t(R7 t)R8 t*R9 t+R: t,R; t-R< t.R= t/R> t0R? t1R@ t2RA t3RB t4RCt5V t6R# )INftablesz*A class representing libnftables interfacezno-dnsr   ZscannerZparserZevalZnetlinkZmnlz	proto-ctxZsegtree
reversednsservice	statelesshandleechoguidnumeric_protonumeric_prionumeric_symbolnumeric_timeterseNc                s	   RV n         \        P                  V4      pVP                  V n        \        V P                  n        \        .V P                  n        VP                  V n        \        V P                  n        \        .V P                  n        VP                  V n
        \        V P                  n        \        \        .V P                  n        VP                  V n        \        V P                  n        \        .V P                  n        VP                  V n        \        \        .V P                  n        VP                  V n        \        V P                  n        \        .V P                  n        VP                  V n        \        \        .V P                  n        VP                  V n        \        V P                  n        \        .V P                  n        VP                   V n        \"        V P                   n        \        .V P                   n        VP$                  V n        \        V P$                  n        \        .V P$                  n        VP&                  V n        \"        V P&                  n        \        .V P&                  n        VP(                  V n        \        V P(                  n        \        \"        .V P(                  n        VP*                  V n        \        V P*                  n        \        \"        .V P*                  n        VP,                  V n        \        V P,                  n        \        \"        .V P,                  n        VP.                  V n        \        .V P.                  n        VP0                  V n        \2        V P0                  n        \        .V P0                  n        VP4                  V n        \        \2        .V P4                  n        VP6                  V n        \        V P6                  n        \        \"        .V P6                  n        VP8                  V n        \        .V P8                  n        VP:                  V n        \        .VP:                  n        V P                  ^ 4      V n         V P                  V P                   4       V P%                  V P                   4       R# )a<  Instantiate a new Nftables class object.

Accepts a shared object file to open, by default standard search path
is searched for a file named 'libnftables.so'.

After loading the library using ctypes module, a new nftables context
is requested from the library and buffering of output and error streams
is turned on.
N)_Nftables__ctxZcdllZLoadLibrarynft_ctx_newZc_void_pZrestypeZc_intZargtypesnft_ctx_input_get_flagsZc_uintnft_ctx_input_set_flagsnft_ctx_output_get_flagsnft_ctx_output_set_flagsnft_ctx_output_get_debugnft_ctx_output_set_debugnft_ctx_buffer_outputnft_ctx_get_output_bufferZc_char_pnft_ctx_buffer_errornft_ctx_get_error_buffernft_run_cmd_from_buffernft_run_cmd_from_filenamenft_ctx_add_include_pathnft_ctx_clear_include_pathsnft_ctx_get_dry_runZc_boolnft_ctx_set_dry_runnft_ctx_add_varnft_ctx_clear_varsnft_ctx_free)r   ZsofileZlib   && r   r   ZNftables.__init__H   s    
v& ??#+ %*G!'*'B'B$/5$$,19
$$-'*'B'B$/5$$,1960B$$-(+(D(D%06%%-2:%%.(+(D(D%2:F1C%%.(+(D(D%05%%-2:%%.(+(D(D%2:E1B%%.%(%>%>"-2""*/7j""+),)F)F&19&&.3;*&&/$'$<$<!,1!!).6Z!!*(+(D(D%08%%-2:%%.'*'B'B$/4$$,1980D$$-),)F)F&16&&.3;X2F&&/(+(D(D%05%%-2:H1E%%.+.+J+J(5=J((1#&#:#: +1  (-5J  )#&#:#: -5v,>  )"22',$)18(<%"%"8"8,4:(,,%-J! %%a(
""4::.!!$**-r   c                sj    V P                   e%   V P                  V P                   4       R V n         R # R # N)r!   r5   r      &r   __del__ZNftables.__del__   s*    ::!djj)DJ "r   c                s    . pVP                  4        F/  w  rEW%,          '       g   K  VP                  V4       W%( ,          pK1  	  V'       d   VP                  V4       V# r7   )ZitemsZappend)r   
flags_dictvalZnamesZnv   &&&   r   _flags_from_numericZNftables._flags_from_numeric   sM    $$&DAwwQr	 ' LLr   c                sN   \        V\        \        34      '       d   V3p^ pV F}  p\        V\        4      '       d"   VP                  V4      pVf   \	        R4      hM;\        V\        4      '       d   V^ 8  g   VR8  d   \	        R4      hM\        R4      hW4,          pK  	  V# )r    zInvalid argumentl    zNot a valid flag)
isinstancestrZintZgetZ
ValueErrorZ	TypeError)r   r;   valuesr<   r=   s   &&&  r   _flags_to_numericZNftables._flags_to_numeric   s    fsCj))YFA!S!!NN1%9$%788 As##q5A
N$%788 +   233HC  
r   c                p    V P                  V P                  4      pV P                  V P                  V4      # )zcGet currently active input flags.

Returns a set of flag names. See set_input_flags() for details.
)r#   r!   r?   input_flagsr   r<      & r   get_input_flagsZNftables.get_input_flags   s1    
 **4::6''(8(8#>>r   c                s    V P                  V P                  V4      pV P                  V P                  V4      pV P	                  V P                  V4      # )a  Set input flags.

Resets all input flags to values. Accepts either a single flag or a list
of flags. Each flag might be given either as string or integer value as
shown in the following table:

Name      | Value (hex)
-----------------------
"no-dns"  | 0x1
"json"    | 0x2

"no-dns" disables blocking address lookup.
"json" enables JSON mode for input.

Returns a set of previously active input flags, as returned by
get_input_flags() method.
)rC   rE   r$   r!   r?   r   rB   r<   old   &&  r   set_input_flagsZNftables.set_input_flags   sK    $ $$T%5%5v>**4::s;''(8(8#>>r   c                sr    V P                   V,          pV P                  V P                  4      V,          ^ 8g  # r    )output_flagsr%   r!   )r   nameflagr6   r   Z__get_output_flagZNftables.__get_output_flag   s1      &--djj9D@QFFr   c                s    V P                   V,          pV P                  V P                  4      pV'       d
   WC,          pM	WC( ,          pV P                  V P                  V4       WC,          ^ 8g  # rM   )rN   r%   r!   r&   )r   rO   r<   rP   ZflagsZ	new_flagsr>   r   Z__set_output_flagZNftables.__set_output_flag   sZ      &--djj9II%%djj)<""r   c                $    V P                  R4      # )zGet the current state of reverse DNS output.

Returns a boolean indicating whether reverse DNS lookups are performed
for IP addresses in output.
r   _Nftables__get_output_flagr8   r9   r   get_reversedns_outputZNftables.get_reversedns_output   s     %%l33r   c                &    V P                  RV4      # )zEnable or disable reverse DNS output.

Accepts a boolean turning reverse DNS lookups in output on or off.

Returns the previous value.
r   _Nftables__set_output_flagrF   r
   r   set_reversedns_outputZNftables.set_reversedns_output   s     %%lC88r   c                rQ   )zGet the current state of service name output.

Returns a boolean indicating whether service names are used for port
numbers in output or not.
r   rR   r8   r9   r   get_service_outputZNftables.get_service_output  s     %%i00r   c                rU   )zEnable or disable service name output.

Accepts a boolean turning service names for port numbers in output on
or off.

Returns the previous value.
r   rV   rF   r
   r   set_service_outputZNftables.set_service_output  s     %%i55r   c                rQ   )ztGet the current state of stateless output.

Returns a boolean indicating whether stateless output is active or not.
r   rR   r8   r9   r   get_stateless_outputZNftables.get_stateless_output  s    
 %%k22r   c                rU   )zEnable or disable stateless output.

Accepts a boolean turning stateless output either on or off.

Returns the previous value.
r   rV   rF   r
   r   set_stateless_outputZNftables.set_stateless_output  s     %%k377r   c                rQ   )znGet the current state of handle output.

Returns a boolean indicating whether handle output is active or not.
r   rR   r8   r9   r   get_handle_outputZNftables.get_handle_output(  s    
 %%h//r   c                rU   )zrEnable or disable handle output.

Accepts a boolean turning handle output on or off.

Returns the previous value.
r   rV   rF   r
   r   set_handle_outputZNftables.set_handle_output/  s     %%h44r   c                rQ   )zjGet the current state of JSON output.

Returns a boolean indicating whether JSON output is active or not.
r   rR   r8   r9   r   get_json_outputZNftables.get_json_output8      
 %%f--r   c                rU   )zuEnable or disable JSON output.

Accepts a boolean turning JSON output either on or off.

Returns the previous value.
r   rV   rF   r
   r   set_json_outputZNftables.set_json_output?       %%fc22r   c                rQ   )zjGet the current state of echo output.

Returns a boolean indicating whether echo output is active or not.
r   rR   r8   r9   r   get_echo_outputZNftables.get_echo_outputH  r`   r   c                rU   )znEnable or disable echo output.

Accepts a boolean turning echo output on or off.

Returns the previous value.
r   rV   rF   r
   r   set_echo_outputZNftables.set_echo_outputO  rb   r   c                rQ   )zGet the current state of GID/UID output.

Returns a boolean indicating whether names for group/user IDs are used
in output or not.
r   rR   r8   r9   r   get_guid_outputZNftables.get_guid_outputX  s     %%f--r   c                rU   )z~Enable or disable GID/UID output.

Accepts a boolean turning names for group/user IDs on or off.

Returns the previous value.
r   rV   rF   r
   r   set_guid_outputZNftables.set_guid_output`  rb   r   c                rQ   )zdGet current status of numeric protocol output flag.

Returns a boolean value indicating the status.
r   rR   r8   r9   r   get_numeric_proto_outputZ!Nftables.get_numeric_proto_outputi  s    
 %%o66r   c                rU   )zSet numeric protocol output flag.

Accepts a boolean turning numeric protocol output either on or off.

Returns the previous value.
r   rV   rF   r
   r   set_numeric_proto_outputZ!Nftables.set_numeric_proto_outputp  s     %%os;;r   c                rQ   )zjGet current status of numeric chain priority output flag.

Returns a boolean value indicating the status.
r   rR   r8   r9   r   get_numeric_prio_outputZ Nftables.get_numeric_prio_outputy      
 %%n55r   c                rU   )zSet numeric chain priority output flag.

Accepts a boolean turning numeric chain priority output either on or
off.

Returns the previous value.
r   rV   rF   r
   r   set_numeric_prio_outputZ Nftables.set_numeric_prio_output       %%nc::r   c                rQ   )zcGet current status of numeric symbols output flag.

Returns a boolean value indicating the status.
r   rR   r8   r9   r   get_numeric_symbol_outputZ"Nftables.get_numeric_symbol_output  s    
 %%&677r   c                rU   )zSet numeric symbols output flag.

Accepts a boolean turning numeric representation of symbolic constants
in output either on or off.

Returns the previous value.
r   rV   rF   r
   r   set_numeric_symbol_outputZ"Nftables.set_numeric_symbol_output  s     %%&6<<r   c                rQ   )zaGet current status of numeric times output flag.

Returns a boolean value indicating the status.
r   rR   r8   r9   r   get_numeric_time_outputZ Nftables.get_numeric_time_output  rj   r   c                rU   )zSet numeric times output flag.

Accepts a boolean turning numeric representation of time values
in output either on or off.

Returns the previous value.
r   rV   rF   r
   r   set_numeric_time_outputZ Nftables.set_numeric_time_output  rl   r   c                rQ   )zlGet the current state of terse output.

Returns a boolean indicating whether terse output is active or not.
r    rR   r8   r9   r   get_terse_outputZNftables.get_terse_output  s    
 %%g..r   c                rU   )zwEnable or disable terse output.

Accepts a boolean turning terse output either on or off.

Returns the previous value.
r    rV   rF   r
   r   set_terse_outputZNftables.set_terse_output  s     %%gs33r   c                rD   )z]Get currently active debug flags.

Returns a set of flag names. See set_debug() for details.
)r'   r!   r?   debug_flagsrF   rG   r   	get_debugZNftables.get_debug  s1    
 ++DJJ7''(8(8#>>r   c                s    V P                  V P                  V4      pV P                  4       pV P                  V P                  V4       V# )a  Set debug output flags.

Accepts either a single flag or a set of flags. Each flag might be
given either as string or integer value as shown in the following
table:

Name      | Value (hex)
-----------------------
scanner   | 0x1
parser    | 0x2
eval      | 0x4
netlink   | 0x8
mnl       | 0x10
proto-ctx | 0x20
segtree   | 0x40

Returns a set of previously active debug flags, as returned by
get_debug() method.
)rC   rs   rt   r(   r!   rI   rK   r   	set_debugZNftables.set_debug  sA    ( $$T%5%5v>nn%%djj#6
r   c                sX   Rp\        V\        4      '       g   RpVP                  R4      pV P                  V P                  V4      pV P                  V P                  4      pV P                  V P                  4      pV'       d#   VP                  R4      pVP                  R4      pW4V3# )a  Run a simple nftables command via libnftables.

Accepts a string containing an nftables command just like what one
would enter into an interactive nftables (nft -i) session.

Returns a tuple (rc, output, error):
rc     -- return code as returned by nft_run_cmd_from_buffer() fuction
output -- a string containing output written to stdout
error  -- a string containing output written to stderr
FTutf-8)r@   bytesencoder-   r!   r*   r,   decode)r   ZcmdlineZcmdline_is_unicodercoutputerror   &&    r   cmdZNftables.cmd  s     #'5))!%nnW-G))$**g>//

;--djj9]]7+FLL)EE""r   c                s    V P                  R4      pV P                  \        P                  ! V4      4      w  r4pV'       g   V P                  V4       \	        V4      '       d   \        P
                  ! V4      pW4V3# )a9  Run an nftables command in JSON syntax via libnftables.

Accepts a hash object as input.

Returns a tuple (rc, output, error):
rc     -- return code as returned by nft_run_cmd_from_buffer() function
output -- a hash object containing library standard output
error  -- a string containing output written to stderr
T)ra   r~   r   ZdumpsZlenZloads)r   	json_rootZjson_out_oldrz   r{   r|   r}   r   json_cmdZNftables.json_cmd  sc     ++D1 HHTZZ	%:;E  .v;;ZZ'FE""r   c                s~    V P                   '       g   \        4       V n         V P                   P                  V4       R# )zValidate JSON object against libnftables schema.

Accepts a hash object as input.

Returns True if JSON is valid, raises an exception otherwise.
T)	validatorr   r	   )r   r   r
   r   json_validateZNftables.json_validate  s,     ~~~,.DN	*r   c                sn   Rp\        V\        4      '       g   Rp\        V4      pVP                  R4      pV P	                  V P
                  V4      pV P                  V P
                  4      pV P                  V P
                  4      pV'       d#   VP                  R4      pVP                  R4      pW4V3# )a&  Run a nftables command set from a file

filename can be a str or a Path

Returns a tuple (rc, output, error):
rc     -- return code as returned by nft_run_cmd_from_filename() function
output -- a string containing output written to stdout
error  -- a string containing output written to stderr
FTrv   )	r@   rw   rA   rx   r.   r!   r*   r,   ry   )r   filenameZfilename_is_unicoderz   r{   r|   r}   r   cmd_from_fileZNftables.cmd_from_file  s     $(E**"&8}Hoog.H++DJJA//

;--djj9]]7+FLL)EE""r   c                s    \        V\        4      '       g   \        V4      pVP                  R4      pV P	                  V P
                  V4      pV^ 8H  # )zAdd a path to the include file list
The default list includes the built-in default one

Returns True on success, False if memory allocation fails
rv   )r@   rw   rA   rx   r/   r!   )r   r   rz   r6   r   add_include_pathZNftables.add_include_path+  sG     (E**8}Hoog.H**4::x@Qwr   c                <    V P                  V P                  4       R# )zCClear include path list

Will also remove the built-in default one
N)r0   r!   r8   r9   r   clear_include_pathsZNftables.clear_include_paths7  s    
 	((4r   c                s8    V P                  V P                  4      # )z8Get dry run state

Returns True if set, False otherwise
)r1   r!   r8   r9   r   get_dry_runZNftables.get_dry_run>  s    
 ''

33r   c                s^    V P                  4       pV P                  V P                  V4       V# )z6Set dry run state

Returns the previous dry run state
)r   r2   r!   )r   ZonoffrJ   r6   r   set_dry_runZNftables.set_dry_runE  s+    
    U3
r   c                s    \        V\        4      '       g   VP                  R4      pV P                  V P                  V4      pV^ 8H  # )zLAdd a variable to the variable list

Returns True if added, False otherwise
rv   )r@   rw   rx   r3   r!   )r   Zvarrz   r6   r   add_varZNftables.add_varO  s>    
 #u%%**W%C!!$**c2Qwr   c                r   )zClear variable list
        N)r4   r!   r8   r9   r   
clear_varsZNftables.clear_varsY  s     	

+r   )Z__ctxr/   r3   r+   r)   r0   r4   r5   r1   r,   r*   r#   r$   r"   r'   r%   r(   r&   r2   r-   r.   r   i   i   i   i   )zlibnftables.so.1)7r   r   r   r   r   rE   rs   rN   r   r   r:   r?   rC   rH   rL   rS   rW   rT   rX   rY   rZ   r[   r\   r]   r^   r_   ra   rc   rd   re   rf   rg   rh   ri   rk   rm   rn   ro   rp   rq   rr   rt   ru   r~   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   r   %   sw    4 	#K 	SSSSTTTK 	666666666677L I].~
&??,G#49163805.3.3.37<6;8=6;/4?2#0#$#.
54, ,r   r   )r   ZctypesZsysr   ZNFTABLES_VERSIONr   r   ) r   r   <module>r      s1   "   
 	 D Dw, w,r   