#!/bin/bash
#
# init script for the Ethernet Bridge filter tables
#
# Written by Dag Wieers <dag@wieers.com>
# Modified by Rok Papez <rok.papez@arnes.si>
#             Bart De Schuymer <bdschuym@pandora.be>
#
# chkconfig: - 15 85
# description: Ethernet Bridge filtering tables
#
# config: /etc/ebtables         (text)
#         /etc/ebtables.<table> (binary)
### BEGIN INIT INFO
# Provides:          ebtables
# Required-Start:    $remote_fs $network
# Required-Stop:     $remote_fs $network
# Short-Description: Ethernet Bridge filter tables
# Description:       Ethernet Bridge filter tables
# Default-Start:     2 3 5
# Default-Stop:      0 1 6
### END INIT INFO

[ -x /usr/sbin/ebtables ] || exit 1
[ -x /usr/sbin/ebtables-save ] || exit 1
[ -x /usr/sbin/ebtables-restore ] || exit 1

RETVAL=0
prog="ebtables"
desc="Ethernet bridge filtering"
umask 0077

#default configuration
EBTABLES_TEXT_FORMAT="yes"
EBTABLES_BINARY_FORMAT="yes"
EBTABLES_MODULES_UNLOAD="no"
EBTABLES_SAVE_ON_STOP="no"
EBTABLES_SAVE_ON_RESTART="no"
EBTABLES_SAVE_COUNTER="no"

. /etc/rc.status
rc_reset

config=/etc/sysconfig/ebtables
[ -f "$config" ] && . "$config"

start() {
	echo -n $"Starting $desc ($prog): "
	if [ "$EBTABLES_BINARY_FORMAT" = "yes" ]; then
		for table in $(ls /etc/ebtables.* 2>/dev/null | sed -e 's/.*ebtables\.//' -e '/save/d' ); do
			/usr/sbin/ebtables -t $table --atomic-file /etc/ebtables.$table --atomic-commit || RETVAL=1
		done
	else
		/usr/sbin/ebtables-restore < /etc/ebtables || RETVAL=1
	fi

	if [ $RETVAL -eq 0 ]; then
		touch /var/run/rcebtables
		rc_failed 0
	else
		rc_failed 3
	fi
}

stop() {
	echo -n $"Stopping $desc ($prog): "
	for table in $(grep '^ebtable_' /proc/modules | sed -e 's/ebtable_\([^ ]*\).*/\1/'); do
		/usr/sbin/ebtables -t $table --init-table || RETVAL=1
	done

	if [ "$EBTABLES_MODULES_UNLOAD" = "yes" ]; then
		for mod in $(grep -E '^(ebt|ebtable)_' /proc/modules | cut -f1 -d' ') ebtables; do
			rmmod $mod 2> /dev/null
		done
	fi

	if [ $RETVAL -eq 0 ]; then
		rm -f /var/run/rcebtables
		rc_failed 0
	else
		rc_failed 3
	fi
}

restart() {
	stop
	rc_status -v
	start
	rc_status -v
}

save() {
	echo -n $"Saving $desc ($prog): "
	if [ "$EBTABLES_TEXT_FORMAT" = "yes" ]; then
		if [ -e /etc/ebtables ]; then
			chmod 0600 /etc/ebtables
			mv -f /etc/ebtables /etc/ebtables.save
		fi
		/usr/sbin/ebtables-save > /etc/ebtables || RETVAL=1
	fi
	if [ "$EBTABLES_BINARY_FORMAT" = "yes" ]; then
		rm -f /etc/ebtables.*.save
		for oldtable in $(ls /etc/ebtables.* 2>/dev/null | grep -vF 'ebtables.save'); do
			chmod 0600 $oldtable
			mv -f $oldtable $oldtable.save
		done
		for table in $(grep '^ebtable_' /proc/modules | sed -e 's/ebtable_\([^ ]*\).*/\1/'); do
			/usr/sbin/ebtables -t $table --atomic-file /etc/ebtables.$table --atomic-save || RETVAL=1
			if [ "$EBTABLES_SAVE_COUNTER" = "no" ]; then
				/usr/sbin/ebtables -t $table --atomic-file /etc/ebtables.$table -Z || RETVAL=1
			fi
		done
	fi

	if [ $RETVAL -ne 0 ]; then
		rc_failed 3
	fi
}

case "$1" in
  start)
	start
	rc_status -v
	;;
  stop)
	[ "$EBTABLES_SAVE_ON_STOP" = "yes" ] && save
	stop
	rc_status -v
	;;
  restart|reload)
	[ "$EBTABLES_SAVE_ON_RESTART" = "yes" ] && save
	restart
	;;
  try-restart|condrestart)
	if [ -e /var/run/rcebtables ]; then
		restart
	fi
	;;
  save)
	save
	rc_status -v
	;;
  status)
	/usr/sbin/ebtables-save
	rc_status -v
	;;
  *)
	echo $"Usage $0 {start|stop|restart|try-restart|save|status}"
	exit 1
	;;
esac

rc_exit
