#!/bin/bash
#
# init script for the Ethernet Bridge filter tables
#
# Written by Dag Wieers <dag@wieers.com>.
#
# chkconfig: - 15 85
# description: Ethernet Bridge filtering tables
#
# config: /etc/sysconfig/ebtables.filter
# config: /etc/sysconfig/ebtables.nat
# config: /etc/sysconfig/ebtables.route

source /etc/rc.d/init.d/functions
source /etc/sysconfig/network

# Check that networking is up.
[ ${NETWORKING} = "no" ] && exit 0

[ -x /sbin/ebtables ] || exit 1

[ -r /etc/sysconfig/ebtables.filter ] || exit 1
[ -r /etc/sysconfig/ebtables.nat ] || exit 1
[ -r /etc/sysconfig/ebtables.broute ] || exit 1

RETVAL=0
prog="ebtables"
desc="Ethernet bridge filtering"

start() {
    echo -n $"Starting $desc ($prog): "
    /sbin/ebtables -t filter --atomic-file /etc/sysconfig/ebtables.filter --atomic-commit || RETVAL=1
    /sbin/ebtables -t nat --atomic-file /etc/sysconfig/ebtables.nat --atomic-commit | RETVAL=1
    /sbin/ebtables -t broute --atomic-file /etc/sysconfig/ebtables.broute --atomic-commit || RETVAL=1

    if [ $RETVAL -eq 0 ]; then
        success "$prog startup"
        rm -f /var/lock/subsys/$prog
    else
        failure "$prog startup"
    fi

    echo
    return $RETVAL
}

stop() {
    echo -n $"Starting $desc ($prog): "
    /sbin/ebtables -t filter --init-table || RETVAL=1
    /sbin/ebtables -t nat --init-table || RETVAL=1
    /sbin/ebtables -t broute --init-table || RETVAL=1

    for mod in $(grep -E '^(ebt|ebtable)_' /proc/modules | cut -f1 -d' ') ebtables; do
        rmmod $mod || RETVAL=1
    done

    if [ $RETVAL -eq 0 ]; then
        success "$prog shutdown"
        rm -f /var/lock/subsys/$prog
    else
        failure "$prog shutdown"
    fi

    echo
    return $RETVAL
}

restart() {
    stop
    start
}

save() {
    echo -n $"Saving $desc ($prog): "
    /sbin/ebtables -t filter --atomic-file /etc/sysconfig/ebtables.filter --atomic-save || RETVAL=1
    /sbin/ebtables -t nat --atomic-file /etc/sysconfig/ebtables.nat --atomic-save || RETVAL=1
    /sbin/ebtables -t broute --atomic-file /etc/sysconfig/ebtables.broute --atomic-save || RETVAL=1

    if [ $RETVAL -eq 0 ]; then
        success "$prog saved"
    else
        failure "$prog saved"
    fi
    echo
}

case "$1" in
  start)
    start
    ;;
  stop)
    stop
    ;;
  restart|reload)
    restart
    ;;
  condrestart)
    [ -e /var/lock/subsys/$prog ] && restart
    RETVAL=$?
    ;;
  save)
    save
    ;;
  status)
    status $prog
    RETVAL=$?
    ;;
  *)
    echo $"Usage $0 {start|stop|restart|condrestart|save|status}"
    RETVAL=1
esac

exit $RETVAL
