#!/bin/bash
# 
# This script is used for Administration of RSBAC Network Templates
#
#
# Make sure we're really running bash.
#
[ -z "$BASH" ] && { echo "This menu requires bash" 1>&2; exit 1; }

#
# Cache function definitions, turn off posix compliance
#
set -h +o posix

# The dir for tmp files
if test -z "$TMPDIR" ; then TMPDIR=/tmp ; fi

# This must be a unique temporary filename
TMPFILE=`mktemp -q $TMPDIR/rsbac_dialog.XXXXXX`
if test -z $TMPFILE
then
  TMPFILE=$TMPDIR/rsbac_dialog.$$
  if test -e $TMPFILE
  then rm $TMPFILE
  fi
fi
TMPFILETWO=`mktemp -q $TMPDIR/rsbac_dialog.XXXXXX`
if test -z $TMPFILETWO
then
  TMPFILETWO=$TMPDIR/rsbac_dialog.$$.2
  if test -e $TMPFILETWO
  then rm $TMPFILETWO
  fi
fi

# set this to rsbac bin dir, if not in path (trailing / is mandatory!)
#
#if test -z "$RSBACPATH" ; then RSBACPATH=./ ; fi

# set this to initial dir on script startup
LASTDIR='.'

# which dialog tool to use - dialog or kdialog
if test -z $DIALOG
then DIALOG=${RSBACPATH}rsbac_dialog
fi

if ! $DIALOG --clear
then
  echo $DIALOG menu program required! >&2
  exit
fi

# test for LINES and COLUMNS (should be exported e.g. in /etc/profile)
if test -z "$LINES" ; then LINES=25 ; fi
if test -z "$COLUMNS" ; then COLUMNS=80 ; fi
export LINES
export COLUMNS
declare -i BL=$LINES-4
declare -i BC=$COLUMNS-4
declare -i MAXWIDTH=$BC-26
declare -i MAXLINES=$LINES-10
gl () {
  if test $1 -gt $MAXLINES
  then echo $MAXLINES
  else echo $1
  fi
}

if test -z "$BACKTITLE"
  then BACKTITLE="RSBAC Administration Tools v1.2.0" ; fi
TITLE="`whoami`@`hostname`: RSBAC Network Template Administration"
HELPTITLE="$TITLE Help"
ERRTITLE="RSBAC Network Template Administration - ERROR"

## no changes below this line!

NO_USER=65533
ALL_USERS=65532
GETMODE=real
GETSWITCH=

show_help () {
 {
  echo "$1"
  echo ""
  case "$1" in
    'Add Template')
      echo "Add another template with ID number and name."
      ;;

    "Remove Template")
      echo "Remove a template."
      ;;

    Name)
      echo "New name for Template."
      ;;

    "Address Family")
      echo "Choose Address Family. Select ANY to match any family."
      ;;

    "Socket Type")
      echo "Type of socket: Mostly stream, datagram or raw."
      echo ""
      echo "Set to ANY to match any type."
      ;;

    Address)
      echo "Enter Address - only UNIX (text string) and INET (IPv4, a.b.c.d address)"
      echo "family addresses are currently supported. For all other families, the"
      echo "address is ignored by the matching code."
      echo ""
      echo "Leave empty to match any UNIX address."
      echo ""
      echo "The number of supported families will be increased later."
      ;;

    "Valid Length")
      echo "Length of address that is matched. Characters for UNIX and bits for"
      echo "INET family."
      echo ""
      echo "Set to 0 to match any address."
      ;;

    "Protocol")
      echo "INET (IPv4) family protocol type."
      echo ""
      echo "Set to ANY to match any protocol."
      ;;

    "Network Device")
      echo "Local device name. Only usable for local addresses, otherwise any string"
      echo "entered here will result in no match!"
      echo ""
      echo "Leave empty to match any device."
      ;;

    "Min Port")
      echo "Minimum port matched. Useful mostly for INET family."
      echo "Note: ICMP protocol packet types are also matched as port numbers."
      ;;

    "Max Port")
      echo "Maximum port matched. Useful mostly for INET family."
      echo "Note: ICMP protocol packet types are also matched as port numbers."
      ;;

    "NetTemp Attributes")
      echo "Go to Network Template attribute menu for this template."
      ;;

    Quit)
      echo 'Quit this menu.'
      ;;

    *)
        echo "No help for $1 available!"
  esac
 } > $TMPFILE
  $DIALOG --title "$HELPTITLE" \
          --backtitle "$BACKTITLE" \
          --textbox $TMPFILE $BL $BC
#  sleep 1
}

onoff () {
   if test "$1" = "$2"
     then echo on
   else echo off
   fi
}

gen_tlist () {
  $RSBACPATH""net_temp list_temp_names
}

template_menu () {
  TEMPLATE=$1
  if $RSBACPATH""net_temp get_name $TEMPLATE >$TMPFILE 2>$TMPFILETWO
  then NAME=`cat $TMPFILE`
  else
    $DIALOG --title "$ERRTITLE" \
           --backtitle "$BACKTITLE" \
           --msgbox "`head -n 1 $TMPFILETWO`" $BL $BC
    return
  fi
  ADDRFAM=`$RSBACPATH""net_temp get_address_family $TEMPLATE`
  ADDR=`$RSBACPATH""net_temp get_address $TEMPLATE`
  VALLEN=`$RSBACPATH""net_temp get_valid_len $TEMPLATE`
  TYPE=`$RSBACPATH""net_temp get_type $TEMPLATE`
  PROTO=`$RSBACPATH""net_temp get_protocol $TEMPLATE`
  NETDEV=`$RSBACPATH""net_temp get_netdev $TEMPLATE`
  MINPORT=`$RSBACPATH""net_temp get_min_port $TEMPLATE`
  MAXPORT=`$RSBACPATH""net_temp get_max_port $TEMPLATE`
  while true ; do \
    if ! \
    $DIALOG --title "$TITLE" \
           --backtitle "$BACKTITLE" \
           --help-button --default-item "$SELECTED" \
           --menu "Template Menu - Template $TEMPLATE" $BL $BC 14 \
                  "Name" "$NAME" \
                  "Address Family" "$ADDRFAM" \
                  "Socket Type" "$TYPE" \
                  "Address" "$ADDR" \
                  "Valid Length" "$VALLEN" \
                  "Protocol" "$PROTO" \
                  "Network Device" "$NETDEV" \
                  "Min Port" "$MINPORT" \
                  "Max Port" "$MAXPORT" \
                  "--------------" "" \
                  "Remove Template" "Remove this template" \
                  "--------------" "" \
                  "NetTemp Attributes" "Go to NetTemp attributes" \
                  "Quit" "" \
           2>$TMPFILE
    then rm $TMPFILETWO ; return
    fi

    SELECTED=`cat $TMPFILE`
    case $SELECTED in
      HELP*)
          show_help "${SELECTED:5}"
          SELECTED="${SELECTED:5}"
        ;;

      Name)
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --max-input 15 \
                    --inputbox "New name for Template $TEMPLATE (maxlen = 15)" $BL $BC "$NAME" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            if $RSBACPATH""net_temp set_name $TEMPLATE "$TMP" &>$TMPFILE
            then
              NAME="$TMP"
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

      "Address Family")
        if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --default-item "$ADDRFAM" \
                   --menu "Choose Address Family for Template $TEMPLATE / $NAME" $BL $BC `gl 27` \
                      "ANY"		"0 Match any Address Family" \
                      "UNIX"		"1 Unix domain sockets" \
                      "INET"		"2 Internet IP Protocol" \
                      "AX25"		"3 Amateur Radio AX.25" \
                      "IPX"		"4 Novell IPX" \
                      "APPLETALK"	"5 AppleTalk DDP" \
                      "NETROM"		"6 Amateur Radio NET/ROM" \
                      "BRIDGE"		"7 Multiprotocol bridge" \
                      "ATMPVC"		"8 ATM PVCs" \
                      "X25"		"9 Reserved for X.25 project" \
                      "INET6"		"10 IP version 6" \
                      "ROSE"		"11 Amateur Radio X.25 PLP" \
                      "DECnet"		"12 Reserved for DECnet project" \
                      "NETBEUI"		"13 Reserved for 802.2LLC project" \
                      "SECURITY"	"14 Security callback pseudo AF" \
                      "KEY"		"15 PF_KEY key management API" \
                      "NETLINK"		"16" \
                      "PACKET"		"17 Packet family" \
                      "ASH"		"18 Ash" \
                      "ECONET"		"19 Acorn Econet" \
                      "ATMSVC"		"20 ATM SVCs" \
                      "SNA"		"22 Linux SNA Project (nutters!)" \
                      "IRDA"		"23 IRDA sockets" \
                      "PPPOX"		"24 PPPoX sockets" \
                      "WANPIPE"		"25 Wanpipe API Sockets" \
                      "BLUETOOTH"	"31 Bluetooth sockets" \
                      "MAX"		"32 Maximum Value - never matched" \
          2>$TMPFILE
        then TMP=`cat $TMPFILE`
             if $RSBACPATH""net_temp set_address_family $TEMPLATE $TMP &>$TMPFILE
             then
               ADDRFAM=$TMP
               ADDR=`$RSBACPATH""net_temp get_address $TEMPLATE`
             else \
               $DIALOG --title "$ERRTITLE" \
                       --backtitle "$BACKTITLE" \
                       --msgbox "`head -n 1 $TMPFILE`" $BL $BC
             fi
        fi
        ;;

      "Socket Type")
        if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --default-item "$TYPE" \
                   --menu "Choose Socket Type for Template $TEMPLATE / $NAME" $BL $BC `gl 27` \
                      "ANY"		"0 Match any Socket Type" \
                      "STREAM"		"1 stream (connection) socket" \
                      "DGRAM"		"2 datagram (conn.less) socket" \
                      "RAW"		"3 raw socket" \
                      "RDM"		"4 reliably-delivered message" \
                      "SEQPACKET"	"5 sequential packet socket" \
                      "PACKET"		"10 getting packets at the dev/user level (rarp etc.)" \
                      "MAX"		"32 Maximum Value - never matched" \
          2>$TMPFILE
        then TMP=`cat $TMPFILE`
             if $RSBACPATH""net_temp set_type $TEMPLATE $TMP &>$TMPFILE
             then
               TYPE=$TMP
             else \
               $DIALOG --title "$ERRTITLE" \
                       --backtitle "$BACKTITLE" \
                       --msgbox "`head -n 1 $TMPFILE`" $BL $BC
             fi
        fi
        ;;

      Address)
          case $ADDRFAM in
            UNIX)
              ;;
            INET)
              ;;
            *)
              $DIALOG --title "$ERRTITLE" \
                      --backtitle "$BACKTITLE" \
                      --msgbox "Cannot set address for $ADDRFAM address family!" $BL $BC
              continue
          esac
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --max-input 127 \
                    --inputbox "New $ADDRFAM Address for Template $TEMPLATE (maxlen = 127)" \
                        $BL $BC "$ADDR" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            case $ADDRFAM in
              UNIX)
                  if $RSBACPATH""net_temp -u set_address $TEMPLATE "$TMP" &>$TMPFILE
                  then
                    ADDR="$TMP"
                  else
                    $DIALOG --title "$ERRTITLE" \
                            --backtitle "$BACKTITLE" \
                            --msgbox "`head -n 1 $TMPFILE`" $BL $BC
                  fi
                ;;
              INET)
                  if $RSBACPATH""net_temp set_address $TEMPLATE "$TMP" &>$TMPFILE
                  then
                    ADDR="$TMP"
                  else
                    $DIALOG --title "$ERRTITLE" \
                            --backtitle "$BACKTITLE" \
                            --msgbox "`head -n 1 $TMPFILE`" $BL $BC
                  fi
                ;;
              *)
            esac
          fi
        ;;

      "Valid Length")
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --inputbox "New Valid Address Length for Template $TEMPLATE" \
                        $BL $BC "$VALLEN" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            if $RSBACPATH""net_temp set_valid_len $TEMPLATE "$TMP" &>$TMPFILE
            then
              VALLEN="$TMP"
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

      "Protocol")
        if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --default-item "$PROTO" \
                   --menu "Choose Protocol for Template $TEMPLATE / $NAME" $BL $BC `gl 27` \
                      "ANY"		"0 Match any Socket Type" \
                      "ICMP"		"1 Internet Control Message Protocol" \
                      "IGMP" 		"2 Internet Group Management Protocol" \
                      "IPIP"		"4 IPIP tunnels (older KA9Q tunnels use 94)" \
                      "TCP"		"6 Transmission Control Protocol" \
                      "EGP"		"8 Exterior Gateway Protocol" \
                      "PUP"		"12 PUP protocol" \
                      "UDP"		"17 User Datagram Protocol" \
                      "IDP"		"22 XNS IDP protocol" \
                      "IPV6"		"41 IPv6-in-IPv4 tunnelling" \
                      "RSVP"		"46 RSVP protocol" \
                      "GRE"		"47 Cisco GRE tunnels (rfc 1701,1702)" \
                      "ESP"		"50 Encapsulation Security Payload protocol" \
                      "AH"		"51 Authentication Header protocol" \
                      "PIM"		"103 Protocol Independent Multicast" \
                      "COMP"		"108 Compression Header protocol" \
                      "RAW"		"255 Raw IP packets" \
                      "MAX"		"256 Maximum Value - never matched" \
          2>$TMPFILE
        then TMP=`cat $TMPFILE`
             if $RSBACPATH""net_temp set_protocol $TEMPLATE $TMP &>$TMPFILE
             then
               PROTO=$TMP
             else \
               $DIALOG --title "$ERRTITLE" \
                       --backtitle "$BACKTITLE" \
                       --msgbox "`head -n 1 $TMPFILE`" $BL $BC
             fi
        fi
        ;;

      "Network Device")
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --max-input 16 \
                    --inputbox "New local Network Device for Template $TEMPLATE (maxlen = 16)" \
                      $BL $BC "$NETDEV" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            if $RSBACPATH""net_temp set_netdev $TEMPLATE "$TMP" &>$TMPFILE
            then
              NETDEV="$TMP"
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

      "Min Port")
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --inputbox "New Minimum Port number for Template $TEMPLATE (max = 65535)" \
                        $BL $BC "$MINPORT" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            if $RSBACPATH""net_temp set_min_port $TEMPLATE "$TMP" &>$TMPFILE
            then
              MINPORT="$TMP"
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

      "Max Port")
          if $DIALOG --title "$TITLE" \
                    --backtitle "$BACKTITLE" \
                    --inputbox "New Maximum Port number for Template $TEMPLATE (max = 65535)" \
                        $BL $BC "$MAXPORT" \
            2>$TMPFILE
          then
            TMP=`cat $TMPFILE`
            if $RSBACPATH""net_temp set_max_port $TEMPLATE "$TMP" &>$TMPFILE
            then
              MAXPORT="$TMP"
            else
              $DIALOG --title "$ERRTITLE" \
                     --backtitle "$BACKTITLE" \
                     --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        ;;

    "Remove Template")
        if $DIALOG --title "$TITLE" \
                   --backtitle "$BACKTITLE" \
                   --yesno "Delete template $TEMPLATE ($NAME)?" 5 $BC \
          2>/dev/null
        then
          if $RSBACPATH""net_temp delete_template $TEMPLATE &>$TMPFILE
          then
            TEMPLATE=
            SELECTED=
            return
          else 
            $DIALOG --title "$ERRTITLE" \
                    --backtitle "$BACKTITLE" \
                    --msgbox "`head -n 1 $TMPFILE`" $BL $BC
          fi
        fi
      ;;

      "NetTemp Attributes")
          $RSBACPATH""rsbac_nettemp_menu $TEMPLATE
          return
        ;;

      Quit)
          rm $TMPFILETWO
          return
        ;;

      *)
          $DIALOG --title "$ERRTITLE" \
                 --backtitle "$BACKTITLE" \
                 --msgbox "Template Menu: Selection Error!" 5 $BC
        ;;

    esac
  done
}

###################### Menu #################

if test "$1" == "-h" -o "$1" == "--help"
then
  echo Use: $0 '[template-id]'
  exit
fi
if test -n "$1"
then
  SELECTED=$1
  template_menu $1
  exit
fi

while true ; do \
  if ! \
  $DIALOG --title "$TITLE" \
         --backtitle "$BACKTITLE" \
         --help-button --default-item "$SELECTED" \
         --menu "Main Menu" $BL $BC $MAXLINES \
                "Add Template" "" \
                "Remove Template" "" \
                "--------------" "" \
                `gen_tlist` \
                "--------------" "" \
                "Quit" "" \
         2>$TMPFILE
   then rm $TMPFILE ; exit
  fi

  SELECTED=`cat $TMPFILE`
  case $SELECTED in
    HELP*)
        show_help "${SELECTED:5}"
        SELECTED="${SELECTED:5}"
      ;;

    'Add Template')
        if $DIALOG --title "$TITLE" \
                  --backtitle "$BACKTITLE" \
                  --inputbox "Number for new template" $BL $BC "" \
           2>$TMPFILE
        then
          TEMPID=`cat $TMPFILE`
          if $DIALOG --title "$TITLE" \
                     --backtitle "$BACKTITLE" \
                     --max-input 15 \
                     --inputbox "Name for new template (maxlen = 15)" $BL $BC "New Template" \
            2>$TMPFILE
          then
            TEMPNAME=`cat $TMPFILE`
            if test -n "$TEMPNAME"
            then
              if $RSBACPATH""net_temp new_template $TEMPID "$TEMPNAME" &>$TMPFILE
              then
                SELECTED=$TEMPID
              else
                $DIALOG --title "$ERRTITLE" \
                        --backtitle "$BACKTITLE" \
                        --msgbox "`head -n 1 $TMPFILE`" $BL $BC
              fi
            fi
          fi
        fi
      ;;

    "Remove Template")
        if $DIALOG --title "$TITLE" \
                  --backtitle "$BACKTITLE" \
                  --default-item "$SELECTED" \
                  --menu "Choose template to delete" $BL $BC $MAXLINES \
                  `gen_tlist` \
               2>$TMPFILE
        then
          TMP=`cat $TMPFILE`
          if $DIALOG --title "$TITLE" \
                     --backtitle "$BACKTITLE" \
                     --yesno "Delete template $TMP?" 5 $BC \
            2>/dev/null
          then
            if ! $RSBACPATH""net_temp delete_template $TMP &>$TMPFILE
            then 
              $DIALOG --title "$ERRTITLE" \
                      --backtitle "$BACKTITLE" \
                      --msgbox "`head -n 1 $TMPFILE`" $BL $BC
            fi
          fi
        fi
      ;;

    Quit)
        rm $TMPFILE ; exit
      ;;

    -------------------)
        $DIALOG --title "$ERRTITLE" \
               --backtitle "$BACKTITLE" \
               --msgbox "Main Menu: Selection Error!" 5 $BC
      ;;

    *)
      template_menu $SELECTED
      ;;

  esac
# sleep 2
done
