summaryrefslogtreecommitdiffstats
path: root/modules/networking/applicationFirewall.nix
blob: 2bab9b390f76761b86b87259547583387f6b22bd (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
{ config, lib, ... }:
let
  cfg = config.networking.applicationFirewall;

  socketfilterfw =
    option: value:
    lib.concatStringsSep " " [
      "/usr/libexec/ApplicationFirewall/socketfilterfw"
      "--${option}"
      (if value then "on" else "off")
    ];
in
{
  meta.maintainers = [
    (lib.maintainers.prince213 or "prince213")
    (lib.maintainers.ryanccn or "ryanccn")
  ];

  options.networking.applicationFirewall = {
    enable = lib.mkOption {
      type = lib.types.nullOr lib.types.bool;
      default = null;
      example = true;
      description = "Whether to enable application firewall.";
    };

    blockAllIncoming = lib.mkOption {
      type = lib.types.nullOr lib.types.bool;
      default = null;
      example = true;
      description = "Whether to block all incoming connections.";
    };

    allowSigned = lib.mkOption {
      type = lib.types.nullOr lib.types.bool;
      default = null;
      example = true;
      description = "Whether to allow built-in software to receive incoming connections.";
    };

    allowSignedApp = lib.mkOption {
      type = lib.types.nullOr lib.types.bool;
      default = null;
      example = true;
      description = "Whether to allow downloaded signed software to receive incoming connections.";
    };

    enableStealthMode = lib.mkOption {
      type = lib.types.nullOr lib.types.bool;
      default = null;
      example = true;
      description = "Whether to enable stealth mode.";
    };
  };

  config = {
    system.activationScripts.networking.text = ''
      echo "configuring application firewall..." >&2

      ${lib.optionalString (cfg.enable != null) (socketfilterfw "setglobalstate" cfg.enable)}
      ${lib.optionalString (cfg.blockAllIncoming != null) (
        socketfilterfw "setblockall" cfg.blockAllIncoming
      )}
      ${lib.optionalString (cfg.allowSigned != null) (socketfilterfw "setallowsigned" cfg.allowSigned)}
      ${lib.optionalString (cfg.allowSignedApp != null) (
        socketfilterfw "setallowsignedapp" cfg.allowSignedApp
      )}
      ${lib.optionalString (cfg.enableStealthMode != null) (
        socketfilterfw "setstealthmode" cfg.enableStealthMode
      )}
    '';
  };
}