applications/luci-ffwizard-leipzig: force /etc/firewall.freifunk include and set...
authorJo-Philipp Wich <jow@openwrt.org>
Mon, 19 Jan 2009 00:16:13 +0000 (00:16 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Mon, 19 Jan 2009 00:16:13 +0000 (00:16 +0000)
applications/luci-ffwizard-leipzig/luasrc/model/cbi/ffwizard.lua

index 87bbe4d1f29cf480239d977351523a9d734aac96..053df036a9c1182e45f0f0f26a5f87a1f72f6221 100644 (file)
@@ -187,10 +187,30 @@ function main.write(self, section, value)
                uci:foreach(external, "fw_rule", function(section)
                        uci:section("firewall", "rule", nil, section)
                end)
+       end
+
+       -- Enforce firewall include
+       local has_include = false
+       uci:foreach("firewall", "include",
+               function(section)
+                       if section.path == "/etc/firewall.freifunk" then
+                               has_include = true
+                       end
+               end)
 
-               uci:save("firewall")
+       if not has_include then
+               uci:section("firewall", "include", nil,
+                       { path = "/etc/firewall.freifunk" })
        end
 
+       -- Allow state: invalid packets
+       uci:foreach("firewall", "defaults",
+               function(section)
+                       uci:set("firewall", section[".name"], "drop_invalid", "0")
+               end)
+
+       uci:save("firewall")
+
 
        -- Crate network interface
        local netconfig = uci:get_all("freifunk", "interface")