Compare commits

..

14 Commits

Author SHA1 Message Date
benvin fff9967da0 Merge pull request 'Agent: translate blrules/conntrack/secmarks/vars' (#8) from benvin/agent-longtail-global2 into main
ci/woodpecker/tag/release Pipeline was successful
Reviewed-on: #8
2026-07-26 16:56:25 +10:00
benvin 4b703f854c Merge pull request 'Agent: translate traffic-control long-tail (mangle/accounting/tc_*)' (#7) from benvin/agent-longtail-tc into main
Reviewed-on: #7
2026-07-26 16:55:32 +10:00
benvin 8ae09c0941 Agent: translate blrules/conntrack/secmarks/vars
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Map the rendered global-compiled tail into native config.Blrules/Conntrack/
Secmarks/Vars.
2026-07-26 16:07:28 +10:00
benvin 6d16035a0b Agent: translate traffic-control long-tail (mangle/accounting/tc_*)
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Map the rendered mangle/accounting/tc_* sections into native tomswall config.
2026-07-26 15:57:05 +10:00
benvin 09f39ec9fe Merge pull request 'Agent: translate per-device L2/misc long-tail' (#6) from benvin/agent-longtail-l2 into main
Reviewed-on: #6
2026-07-26 15:46:07 +10:00
benvin b94cb96510 Agent: translate per-device L2/misc long-tail
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Map the rendered tunnels/stopped_rules/proxy_arp/proxy_ndp/arp_rules/maclist
sections into native tomswall config.
2026-07-26 15:19:09 +10:00
benvin 9fd300652f Merge pull request 'Agent: translate per-device routing long-tail' (#5) from benvin/agent-longtail-routing into main
Reviewed-on: #5
2026-07-26 15:09:15 +10:00
benvin 59e8320dda Agent: translate per-device routing long-tail (hosts/providers/routes/routing_rules)
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
Map the rendered hosts/providers/routes/routing_rules sections into native
tomswall config (config.Host/Provider/StaticRoute/RoutingRule). The route's
egress interface (oif) maps to StaticRoute.Device.
2026-07-26 13:02:17 +10:00
benvin 17b2130047 Merge pull request 'Agent: translate the NAT tier into native config' (#4) from benvin/agent-nat into main
Reviewed-on: #4
2026-07-21 22:30:10 +10:00
benvin 06928bc150 Agent: translate the NAT tier into native config
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
The agent now maps the rendered NAT sections into native tomswall config:
- snat/masquerade -> config.SNAT, expanding a rendered rule's egress interface
  list and source CIDRs into one native rule per (egress, source) pair (a native
  SNAT rule takes a single dest interface); carries address/probability.
- netmap -> config.Netmap (from_net/to_net -> net1/net2 on the resolved interface).
- 1:1 nat -> config.StaticNAT.
Unit-tested end to end from RenderedConfig to config.Config.
2026-07-21 22:21:24 +10:00
benvin 6f1ac9a1ae Merge pull request 'Agent: report the FIB for reachability scoping' (#3) from benvin/agent-fib into main
Reviewed-on: #3
2026-07-20 22:40:25 +10:00
benvin a739d87597 Merge pull request 'Add release machinery: version bump, nfpm RPM, release-on-tag' (#2) from benvin/release-machinery into main
Reviewed-on: #2
2026-07-20 22:39:21 +10:00
benvin 66265764df Agent: report the FIB for reachability scoping
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
The agent now collects the device's reachable prefixes from the kernel FIB
(including FRR-installed routes) via 'ip route show' / 'ip -6 route show' and
reports them to the control plane (POST /devices/{name}/routes) alongside its
status. tomswallapi uses these to scope which routers enforce a rule. Route
parsing (default routes, ECMP nexthop lines, route-type keywords, host routes,
v4/v6) is unit-tested; collection degrades to nil without iproute2.
2026-07-20 22:37:24 +10:00
benvin a3b51018a9 Add release machinery: version bump, nfpm RPM, release-on-tag pipeline
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
- Makefile: add make patch|minor|major (tag + push), dist-build, completions,
  and rpm/rpm-package targets.
- packaging/nfpm.yaml + scripts/build-rpm.sh: package the tomswall binary with
  bash/zsh completions, the example config, and a systemd agent unit into an RPM.
- packaging/tomswall-agent.service + agent.env: run `tomswall agent` as a
  systemd service (CAP_NET_ADMIN/CAP_NET_RAW), configured via /etc/tomswall/agent.env.
- .woodpecker/release.yaml: on v* tag, test -> build -> package RPM -> PUT to the
  artifactapi rpm-internal repo. Matches node-lookup conventions.
2026-07-20 22:30:57 +10:00
13 changed files with 907 additions and 15 deletions
+82
View File
@@ -0,0 +1,82 @@
when:
- event: tag
ref: refs/tags/v*
steps:
- name: test
image: golang:1.23
commands:
- go test ./...
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 1
limits:
memory: 2Gi
cpu: 2
- name: build
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
commands:
- make dist-build VERSION=${CI_COMMIT_TAG}
depends_on: [test]
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 1
limits:
memory: 2Gi
cpu: 2
- name: package
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
commands:
- ./scripts/build-rpm.sh ${CI_COMMIT_TAG}
depends_on: [build]
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 512Mi
cpu: 1
limits:
memory: 2Gi
cpu: 2
- name: upload-rpm
image: git.unkin.net/unkin/almalinux9-base:20260606
commands:
- |
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
REPO="rpm-internal"
for rpm in dist/*.rpm; do
FILE=$$(basename "$$rpm")
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/Packages/$$FILE" || true)
if [ "$$code" = "200" ]; then
echo "$$FILE already exists in $$REPO (HTTP $$code); skipping upload"
continue
fi
echo "Uploading $$FILE to $$REPO (existence probe returned $$code)"
curl -f -X PUT \
"$$HOST/api/v2/remotes/$$REPO/files/$$FILE" \
-H "Content-Type: application/x-rpm" \
--data-binary @"$$rpm"
done
depends_on: [package]
backend_options:
kubernetes:
serviceAccountName: default
resources:
requests:
memory: 128Mi
cpu: 100m
limits:
memory: 512Mi
cpu: 500m
+55 -5
View File
@@ -1,12 +1,17 @@
BINARY := tomswall
MODULE := git.unkin.net/unkin/tomswall
PREFIX := /usr/local
BINARY := tomswall
MODULE := git.unkin.net/unkin/tomswall
PREFIX := /usr/local
CONFDIR := /etc/tomswall
DIST := dist
VERSION := $(shell git describe --tags --always --dirty 2>/dev/null || echo dev)
GOFLAGS := -ldflags="-s -w -X main.version=$(VERSION)"
OS ?= $(shell go env GOOS)
ARCH ?= $(shell go env GOARCH)
.PHONY: build install clean check test
.PHONY: build install clean check test fmt dist-build completions rpm rpm-package patch minor major _tag
build:
go build -o $(BINARY) ./cmd/tomswall
go build $(GOFLAGS) -o $(BINARY) ./cmd/tomswall
install: build
install -Dm755 $(BINARY) $(DESTDIR)$(PREFIX)/sbin/$(BINARY)
@@ -17,9 +22,54 @@ install: build
clean:
rm -f $(BINARY)
rm -rf $(DIST)
check:
go vet ./...
test:
go test ./...
fmt:
gofmt -w .
# Build the binary into dist/ for the RPM packaging step.
dist-build:
@mkdir -p $(DIST)
CGO_ENABLED=0 GOOS=$(OS) GOARCH=$(ARCH) go build $(GOFLAGS) -o $(DIST)/$(BINARY) ./cmd/tomswall
# Generate bash/zsh completions into dist/completions.
completions: dist-build
@mkdir -p $(DIST)/completions
$(DIST)/$(BINARY) completion bash > $(DIST)/completions/$(BINARY).bash
$(DIST)/$(BINARY) completion zsh > $(DIST)/completions/_$(BINARY)
# Build the binary then package it (with completions) into an RPM via nfpm.
rpm: dist-build rpm-package
# Package an already-built dist/ binary into an RPM (used by CI after build).
rpm-package:
./scripts/build-rpm.sh $(VERSION)
# Bump helpers — read the latest semver tag and create+push the next one, which
# triggers the release-on-tag pipeline. Starts from v0.0.0 when no tag exists.
_LATEST := $(shell git tag --sort=-v:refname | grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$$' | head -1)
_BASE := $(if $(_LATEST),$(_LATEST),v0.0.0)
_MAJ := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f1)
_MIN := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f2)
_PAT := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f3)
patch:
@NEW=v$(_MAJ).$(_MIN).$(shell expr $(_PAT) + 1); \
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
minor:
@NEW=v$(_MAJ).$(shell expr $(_MIN) + 1).0; \
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
major:
@NEW=v$(shell expr $(_MAJ) + 1).0.0; \
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
_tag:
git push origin $(TAG)
+6
View File
@@ -90,6 +90,12 @@ func (a *Agent) applyConfig(ctx context.Context, rc *RenderedConfig, report bool
if err := a.Client.ReportStatus(ctx, rc.Generation); err != nil {
slog.Warn("agent: reporting status failed", "err", err)
}
// Report the FIB so the control plane can scope router enforcement.
if fib := CollectFIB(ctx); len(fib) > 0 {
if err := a.Client.ReportRoutes(ctx, fib); err != nil {
slog.Warn("agent: reporting routes failed", "err", err)
}
}
}
return nil
}
+35
View File
@@ -84,6 +84,41 @@ func TestTranslateBareZone(t *testing.T) {
}
}
func TestTranslateNATTier(t *testing.T) {
prob := 0.5
rc := &RenderedConfig{
Enforcing: true,
SNAT: []RenderedSNAT{
{Action: "masquerade", Source: []string{"10.1.0.0/24"}, Egress: []string{"eth0", "eth3"}},
{Action: "snat", Source: []string{"10.2.0.0/24"}, Egress: []string{"eth0"}, Address: "203.0.113.1", Probability: &prob},
},
Netmap: []RenderedNetmap{{Type: "dnat", FromNet: "10.0.0.0/24", ToNet: "192.168.1.0/24", Interface: "eth0"}},
NAT: []RenderedNAT{{External: "203.0.113.10", Internal: "10.1.0.10", Interface: "eth0"}},
}
cfg, err := Translate(rc)
if err != nil {
t.Fatalf("Translate: %v", err)
}
// masquerade with two egress interfaces expands to two rules; snat adds one.
if len(cfg.SNAT) != 3 {
t.Fatalf("expected 3 SNAT rules, got %d: %+v", len(cfg.SNAT), cfg.SNAT)
}
if cfg.SNAT[0].Action != config.SNATMasquerade || cfg.SNAT[0].Source != "10.1.0.0/24" || cfg.SNAT[0].Dest != "eth0" {
t.Errorf("unexpected masquerade rule: %+v", cfg.SNAT[0])
}
if cfg.SNAT[2].Address != "203.0.113.1" || cfg.SNAT[2].Probability != 0.5 {
t.Errorf("snat address/probability not carried: %+v", cfg.SNAT[2])
}
if len(cfg.Netmap) != 1 || cfg.Netmap[0].Net1 != "10.0.0.0/24" || cfg.Netmap[0].Net2 != "192.168.1.0/24" || cfg.Netmap[0].Interface != "eth0" {
t.Errorf("netmap not translated: %+v", cfg.Netmap)
}
if len(cfg.StaticNAT) != 1 || cfg.StaticNAT[0].External != "203.0.113.10" || cfg.StaticNAT[0].Internal != "10.1.0.10" {
t.Errorf("static nat not translated: %+v", cfg.StaticNAT)
}
}
func TestTranslateRejectsUnknownAction(t *testing.T) {
rc := &RenderedConfig{Enforcing: true, Rules: []RenderedRule{{Action: "bogus"}}}
if _, err := Translate(rc); err == nil {
+24
View File
@@ -70,6 +70,30 @@ func ParseRendered(body []byte) (*RenderedConfig, error) {
return &cfg, nil
}
// ReportRoutes reports the device's reachable prefixes (FIB) so the control
// plane can scope which routers enforce a rule.
func (c *Client) ReportRoutes(ctx context.Context, prefixes []string) error {
url := fmt.Sprintf("%s/api/v1/devices/%s/routes", c.BaseURL, c.Device)
payload, _ := json.Marshal(map[string][]string{"prefixes": prefixes})
req, err := http.NewRequestWithContext(ctx, http.MethodPost, url, bytes.NewReader(payload))
if err != nil {
return err
}
req.Header.Set("Authorization", "Bearer "+c.Token)
req.Header.Set("Content-Type", "application/json")
resp, err := c.HTTP.Do(req)
if err != nil {
return err
}
defer resp.Body.Close()
io.Copy(io.Discard, io.LimitReader(resp.Body, 1<<16))
if resp.StatusCode >= 400 {
return fmt.Errorf("report routes: %d", resp.StatusCode)
}
return nil
}
// ReportStatus tells the control plane which generation this device has applied.
func (c *Client) ReportStatus(ctx context.Context, generation int64) error {
url := fmt.Sprintf("%s/api/v1/devices/%s/status", c.BaseURL, c.Device)
+76
View File
@@ -0,0 +1,76 @@
package agent
import (
"context"
"os/exec"
"strings"
)
// CollectFIB returns the device's reachable prefixes from the kernel FIB — which
// includes FRR-installed routes — by shelling out to `ip route`. The control
// plane uses these to scope which routers enforce a rule. On a host without
// iproute2 it returns nil, and the control plane falls back to over-approximation.
func CollectFIB(ctx context.Context) []string {
var prefixes []string
for _, spec := range []struct {
args []string
def string
}{
{[]string{"route", "show"}, "0.0.0.0/0"},
{[]string{"-6", "route", "show"}, "::/0"},
} {
out, err := exec.CommandContext(ctx, "ip", spec.args...).Output()
if err != nil {
continue
}
prefixes = append(prefixes, parseRoutes(string(out), spec.def)...)
}
return dedup(prefixes)
}
// routeTypeKeywords are leading tokens in `ip route` output that precede the
// actual destination (e.g. "unreachable 10.0.0.0/8").
var routeTypeKeywords = map[string]bool{
"unreachable": true, "blackhole": true, "prohibit": true, "throw": true,
"local": true, "broadcast": true, "multicast": true, "anycast": true, "nat": true,
}
// parseRoutes extracts destination prefixes from `ip route show` output.
// defaultPrefix is substituted for a "default" route (family-specific).
func parseRoutes(output, defaultPrefix string) []string {
var out []string
for _, line := range strings.Split(output, "\n") {
fields := strings.Fields(line)
if len(fields) == 0 {
continue
}
dst := fields[0]
// ECMP routes emit continuation "nexthop ..." lines with no destination.
if dst == "nexthop" {
continue
}
if routeTypeKeywords[dst] {
if len(fields) < 2 {
continue
}
dst = fields[1]
}
if dst == "default" {
out = append(out, defaultPrefix)
continue
}
out = append(out, normalizePrefix(dst))
}
return out
}
// normalizePrefix turns a bare host address into a host prefix (/32 or /128).
func normalizePrefix(dst string) string {
if strings.Contains(dst, "/") {
return dst
}
if strings.Contains(dst, ":") {
return dst + "/128"
}
return dst + "/32"
}
+55
View File
@@ -0,0 +1,55 @@
package agent
import (
"reflect"
"sort"
"testing"
)
func TestParseRoutesV4(t *testing.T) {
// Representative `ip route show` output, including a default route, an ECMP
// route with nexthop continuation lines, a connected route, and a host route.
out := `default via 10.0.0.1 dev eth0 proto dhcp
10.1.0.0/24 dev eth1 proto kernel scope link src 10.1.0.5
10.4.0.0/24 proto bgp metric 20
nexthop via 10.0.0.2 dev eth0 weight 1
nexthop via 10.0.0.3 dev eth0 weight 1
192.0.2.7 dev eth2 scope link
blackhole 172.16.0.0/12
`
got := parseRoutes(out, "0.0.0.0/0")
sort.Strings(got)
want := []string{"0.0.0.0/0", "10.1.0.0/24", "10.4.0.0/24", "172.16.0.0/12", "192.0.2.7/32"}
sort.Strings(want)
if !reflect.DeepEqual(got, want) {
t.Errorf("parseRoutes v4 = %v, want %v", got, want)
}
}
func TestParseRoutesV6(t *testing.T) {
out := `default via fe80::1 dev eth0 metric 1024
2001:db8:1::/64 dev eth1 proto kernel metric 256
2001:db8:4::5 dev eth2
`
got := parseRoutes(out, "::/0")
sort.Strings(got)
want := []string{"2001:db8:1::/64", "2001:db8:4::5/128", "::/0"}
sort.Strings(want)
if !reflect.DeepEqual(got, want) {
t.Errorf("parseRoutes v6 = %v, want %v", got, want)
}
}
func TestNormalizePrefix(t *testing.T) {
cases := map[string]string{
"10.1.0.0/24": "10.1.0.0/24",
"10.1.0.5": "10.1.0.5/32",
"2001:db8::1": "2001:db8::1/128",
"2001:db8::/32": "2001:db8::/32",
}
for in, want := range cases {
if got := normalizePrefix(in); got != want {
t.Errorf("normalizePrefix(%q) = %q, want %q", in, got, want)
}
}
}
+260 -10
View File
@@ -8,16 +8,266 @@ package agent
// GET /api/v1/devices/{name}/config. It mirrors the control plane's compiler
// output: interface-agnostic, address-matched rules plus named sets.
type RenderedConfig struct {
Generation int64 `yaml:"generation" json:"generation"`
Device string `yaml:"device" json:"device"`
Class string `yaml:"class" json:"class"`
Enforcing bool `yaml:"enforcing" json:"enforcing"`
Settings RenderedSettings `yaml:"settings" json:"settings"`
Resolver []string `yaml:"resolver,omitempty" json:"resolver,omitempty"`
Bindings map[string][]string `yaml:"bindings,omitempty" json:"bindings,omitempty"` // zone -> interfaces
Sets []RenderedSet `yaml:"sets,omitempty" json:"sets,omitempty"`
Rules []RenderedRule `yaml:"rules,omitempty" json:"rules,omitempty"`
Policies []RenderedPolicy `yaml:"policies,omitempty" json:"policies,omitempty"`
Generation int64 `yaml:"generation" json:"generation"`
Device string `yaml:"device" json:"device"`
Class string `yaml:"class" json:"class"`
Enforcing bool `yaml:"enforcing" json:"enforcing"`
Settings RenderedSettings `yaml:"settings" json:"settings"`
Resolver []string `yaml:"resolver,omitempty" json:"resolver,omitempty"`
Bindings map[string][]string `yaml:"bindings,omitempty" json:"bindings,omitempty"` // zone -> interfaces
Sets []RenderedSet `yaml:"sets,omitempty" json:"sets,omitempty"`
Rules []RenderedRule `yaml:"rules,omitempty" json:"rules,omitempty"`
Policies []RenderedPolicy `yaml:"policies,omitempty" json:"policies,omitempty"`
SNAT []RenderedSNAT `yaml:"snat,omitempty" json:"snat,omitempty"`
Netmap []RenderedNetmap `yaml:"netmap,omitempty" json:"netmap,omitempty"`
NAT []RenderedNAT `yaml:"nat,omitempty" json:"nat,omitempty"`
Hosts []RenderedHost `yaml:"hosts,omitempty" json:"hosts,omitempty"`
Providers []RenderedProvider `yaml:"providers,omitempty" json:"providers,omitempty"`
Routes []RenderedRoute `yaml:"routes,omitempty" json:"routes,omitempty"`
RoutingRules []RenderedRoutingRule `yaml:"routing_rules,omitempty" json:"routing_rules,omitempty"`
Tunnels []RenderedTunnel `yaml:"tunnels,omitempty" json:"tunnels,omitempty"`
StoppedRules []RenderedStoppedRule `yaml:"stopped_rules,omitempty" json:"stopped_rules,omitempty"`
ProxyARP []RenderedProxy `yaml:"proxy_arp,omitempty" json:"proxy_arp,omitempty"`
ProxyNDP []RenderedProxy `yaml:"proxy_ndp,omitempty" json:"proxy_ndp,omitempty"`
ArpRules []RenderedArpRule `yaml:"arp_rules,omitempty" json:"arp_rules,omitempty"`
Maclist []RenderedMaclist `yaml:"maclist,omitempty" json:"maclist,omitempty"`
Mangle []RenderedMangle `yaml:"mangle,omitempty" json:"mangle,omitempty"`
Accounting []RenderedAccounting `yaml:"accounting,omitempty" json:"accounting,omitempty"`
TCDevices []RenderedTCDevice `yaml:"tc_devices,omitempty" json:"tc_devices,omitempty"`
TCClasses []RenderedTCClass `yaml:"tc_classes,omitempty" json:"tc_classes,omitempty"`
TCFilters []RenderedTCFilter `yaml:"tc_filters,omitempty" json:"tc_filters,omitempty"`
TCInterfaces []RenderedTCInterface `yaml:"tc_interfaces,omitempty" json:"tc_interfaces,omitempty"`
TCPriorities []RenderedTCPriority `yaml:"tc_priorities,omitempty" json:"tc_priorities,omitempty"`
Blrules []RenderedBlrule `yaml:"blrules,omitempty" json:"blrules,omitempty"`
Conntrack []RenderedConntrack `yaml:"conntrack,omitempty" json:"conntrack,omitempty"`
Secmarks []RenderedSecmark `yaml:"secmarks,omitempty" json:"secmarks,omitempty"`
Vars map[string]string `yaml:"vars,omitempty" json:"vars,omitempty"`
}
type RenderedBlrule struct {
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
Action string `yaml:"action" json:"action"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
Log string `yaml:"log,omitempty" json:"log,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedConntrack struct {
Action string `yaml:"action" json:"action"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
Chain string `yaml:"chain,omitempty" json:"chain,omitempty"`
Helper string `yaml:"helper,omitempty" json:"helper,omitempty"`
User string `yaml:"user,omitempty" json:"user,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedSecmark struct {
Secmark string `yaml:"secmark" json:"secmark"`
Chain string `yaml:"chain" json:"chain"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedMangle struct {
Action string `yaml:"action" json:"action"`
Chain string `yaml:"chain,omitempty" json:"chain,omitempty"`
MarkValue string `yaml:"mark_value,omitempty" json:"mark_value,omitempty"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
User string `yaml:"user,omitempty" json:"user,omitempty"`
Mark string `yaml:"mark,omitempty" json:"mark,omitempty"`
Length string `yaml:"length,omitempty" json:"length,omitempty"`
TOS string `yaml:"tos,omitempty" json:"tos,omitempty"`
Helper string `yaml:"helper,omitempty" json:"helper,omitempty"`
Probability *float64 `yaml:"probability,omitempty" json:"probability,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedAccounting struct {
Action string `yaml:"action" json:"action"`
Section string `yaml:"section,omitempty" json:"section,omitempty"`
Chain string `yaml:"chain,omitempty" json:"chain,omitempty"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
Mark string `yaml:"mark,omitempty" json:"mark,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedTCDevice struct {
Interface string `yaml:"interface" json:"interface"`
InBandwidth string `yaml:"in_bandwidth,omitempty" json:"in_bandwidth,omitempty"`
OutBandwidth string `yaml:"out_bandwidth,omitempty" json:"out_bandwidth,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedTCClass struct {
Interface string `yaml:"interface" json:"interface"`
Mark int `yaml:"mark,omitempty" json:"mark,omitempty"`
Rate string `yaml:"rate,omitempty" json:"rate,omitempty"`
Ceil string `yaml:"ceil,omitempty" json:"ceil,omitempty"`
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedTCFilter struct {
Class string `yaml:"class" json:"class"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
TOS string `yaml:"tos,omitempty" json:"tos,omitempty"`
Length int `yaml:"length,omitempty" json:"length,omitempty"`
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedTCInterface struct {
Interface string `yaml:"interface" json:"interface"`
Type string `yaml:"type,omitempty" json:"type,omitempty"`
InBandwidth string `yaml:"in_bandwidth,omitempty" json:"in_bandwidth,omitempty"`
OutBandwidth string `yaml:"out_bandwidth,omitempty" json:"out_bandwidth,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedTCPriority struct {
Band int `yaml:"band" json:"band"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
Address string `yaml:"address,omitempty" json:"address,omitempty"`
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
Helper string `yaml:"helper,omitempty" json:"helper,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedTunnel struct {
Type string `yaml:"type" json:"type"`
Zone string `yaml:"zone" json:"zone"`
Gateways []string `yaml:"gateways,omitempty" json:"gateways,omitempty"`
GatewayZones []string `yaml:"gateway_zones,omitempty" json:"gateway_zones,omitempty"`
Port int `yaml:"port,omitempty" json:"port,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedStoppedRule struct {
Action string `yaml:"action" json:"action"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Proto string `yaml:"proto,omitempty" json:"proto,omitempty"`
DPort []string `yaml:"dport,omitempty" json:"dport,omitempty"`
SPort []string `yaml:"sport,omitempty" json:"sport,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedProxy struct {
Address string `yaml:"address" json:"address"`
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
External string `yaml:"external" json:"external"`
HaveRoute bool `yaml:"haveroute,omitempty" json:"haveroute,omitempty"`
Persistent bool `yaml:"persistent,omitempty" json:"persistent,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedArpRule struct {
Action string `yaml:"action" json:"action"`
ActionAddress string `yaml:"action_address,omitempty" json:"action_address,omitempty"`
ActionMAC string `yaml:"action_mac,omitempty" json:"action_mac,omitempty"`
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Opcode int `yaml:"opcode,omitempty" json:"opcode,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedMaclist struct {
Action string `yaml:"action" json:"action"`
Interface string `yaml:"interface" json:"interface"`
MAC string `yaml:"mac,omitempty" json:"mac,omitempty"`
Addresses []string `yaml:"addresses,omitempty" json:"addresses,omitempty"`
Log string `yaml:"log,omitempty" json:"log,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedHost struct {
Zone string `yaml:"zone" json:"zone"`
Interface string `yaml:"interface" json:"interface"`
Addresses []string `yaml:"addresses,omitempty" json:"addresses,omitempty"`
Exclusions []string `yaml:"exclusions,omitempty" json:"exclusions,omitempty"`
Dynamic bool `yaml:"dynamic,omitempty" json:"dynamic,omitempty"`
}
type RenderedProvider struct {
Name string `yaml:"name" json:"name"`
Number int `yaml:"number" json:"number"`
Mark int `yaml:"mark,omitempty" json:"mark,omitempty"`
Duplicate string `yaml:"duplicate,omitempty" json:"duplicate,omitempty"`
Interface string `yaml:"interface" json:"interface"`
Gateway string `yaml:"gateway,omitempty" json:"gateway,omitempty"`
Copy []string `yaml:"copy,omitempty" json:"copy,omitempty"`
}
type RenderedRoute struct {
Provider string `yaml:"provider,omitempty" json:"provider,omitempty"`
Dest string `yaml:"dest" json:"dest"`
Gateway string `yaml:"gateway,omitempty" json:"gateway,omitempty"`
Oif string `yaml:"oif,omitempty" json:"oif,omitempty"`
Persistent bool `yaml:"persistent,omitempty" json:"persistent,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedRoutingRule struct {
Source string `yaml:"source,omitempty" json:"source,omitempty"`
Dest string `yaml:"dest,omitempty" json:"dest,omitempty"`
Provider string `yaml:"provider" json:"provider"`
Priority int `yaml:"priority,omitempty" json:"priority,omitempty"`
Persistent bool `yaml:"persistent,omitempty" json:"persistent,omitempty"`
Mark string `yaml:"mark,omitempty" json:"mark,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
// RenderedSNAT is a resolved SNAT/masquerade rule (egress carries interface names).
type RenderedSNAT struct {
Action string `yaml:"action" json:"action"`
Source []string `yaml:"source,omitempty" json:"source,omitempty"`
Egress []string `yaml:"egress" json:"egress"`
Address string `yaml:"address,omitempty" json:"address,omitempty"`
Probability *float64 `yaml:"probability,omitempty" json:"probability,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
// RenderedNetmap is a resolved network-to-network mapping on one interface.
type RenderedNetmap struct {
Type string `yaml:"type" json:"type"`
FromNet string `yaml:"from_net" json:"from_net"`
ToNet string `yaml:"to_net" json:"to_net"`
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
// RenderedNAT is a resolved one-to-one static NAT on one interface.
type RenderedNAT struct {
External string `yaml:"external" json:"external"`
Internal string `yaml:"internal" json:"internal"`
Interface string `yaml:"interface,omitempty" json:"interface,omitempty"`
Comment string `yaml:"comment,omitempty" json:"comment,omitempty"`
}
type RenderedSettings struct {
+183
View File
@@ -60,9 +60,192 @@ func Translate(rc *RenderedConfig) (*config.Config, error) {
})
}
for _, s := range rc.SNAT {
cfg.SNAT = append(cfg.SNAT, translateSNAT(s)...)
}
for _, n := range rc.Netmap {
cfg.Netmap = append(cfg.Netmap, config.Netmap{
Type: config.NetmapType(n.Type),
Net1: n.FromNet,
Net2: n.ToNet,
Interface: n.Interface,
Comment: n.Comment,
})
}
for _, n := range rc.NAT {
cfg.StaticNAT = append(cfg.StaticNAT, config.StaticNAT{
External: n.External,
Internal: n.Internal,
Interface: n.Interface,
Comment: n.Comment,
})
}
for _, h := range rc.Hosts {
cfg.Hosts = append(cfg.Hosts, config.Host{
Zone: h.Zone, Interface: h.Interface, Addresses: h.Addresses,
Exclusions: h.Exclusions, Dynamic: h.Dynamic,
})
}
for _, p := range rc.Providers {
cfg.Providers = append(cfg.Providers, config.Provider{
Name: p.Name, Number: p.Number, Mark: p.Mark, Duplicate: p.Duplicate,
Interface: p.Interface, Gateway: p.Gateway, Copy: p.Copy,
})
}
for _, r := range rc.Routes {
cfg.Routes = append(cfg.Routes, config.StaticRoute{
Provider: r.Provider, Dest: r.Dest, Gateway: r.Gateway,
Device: r.Oif, Persistent: r.Persistent, Comment: r.Comment,
})
}
for _, r := range rc.RoutingRules {
cfg.RoutingRules = append(cfg.RoutingRules, config.RoutingRule{
Source: r.Source, Dest: r.Dest, Provider: r.Provider, Priority: r.Priority,
Persistent: r.Persistent, Mark: r.Mark, Comment: r.Comment,
})
}
for _, t := range rc.Tunnels {
cfg.Tunnels = append(cfg.Tunnels, config.Tunnel{
Type: t.Type, Zone: t.Zone, Gateways: t.Gateways,
GatewayZones: t.GatewayZones, Port: t.Port, Comment: t.Comment,
})
}
for _, r := range rc.StoppedRules {
cfg.StoppedRules = append(cfg.StoppedRules, config.StoppedRule{
Action: config.StoppedAction(r.Action), Source: r.Source, Dest: r.Dest,
Proto: r.Proto, DPort: config.PortSpec(r.DPort), SPort: config.PortSpec(r.SPort), Comment: r.Comment,
})
}
for _, p := range rc.ProxyARP {
cfg.ProxyARP = append(cfg.ProxyARP, config.ProxyARP{
Address: p.Address, Interface: p.Interface, External: p.External,
HaveRoute: p.HaveRoute, Persistent: p.Persistent, Comment: p.Comment,
})
}
for _, p := range rc.ProxyNDP {
cfg.ProxyNDP = append(cfg.ProxyNDP, config.ProxyNDP{
Address: p.Address, Interface: p.Interface, External: p.External,
HaveRoute: p.HaveRoute, Persistent: p.Persistent, Comment: p.Comment,
})
}
for _, a := range rc.ArpRules {
cfg.ArpRules = append(cfg.ArpRules, config.ArpRule{
Action: config.ArpAction(a.Action), ActionAddress: a.ActionAddress, ActionMAC: a.ActionMAC,
Source: a.Source, Dest: a.Dest, Opcode: a.Opcode, Comment: a.Comment,
})
}
for _, m := range rc.Maclist {
cfg.Maclist = append(cfg.Maclist, config.MaclistEntry{
Action: config.MaclistAction(m.Action), Interface: m.Interface, MAC: m.MAC,
Addresses: m.Addresses, Log: m.Log, Comment: m.Comment,
})
}
for _, m := range rc.Mangle {
mr := config.MangleRule{
Action: config.MangleAction(m.Action), Chain: config.MangleChain(m.Chain), MarkValue: m.MarkValue,
Source: m.Source, Dest: m.Dest, Proto: m.Proto, DPort: config.PortSpec(m.DPort), SPort: config.PortSpec(m.SPort),
User: m.User, Mark: m.Mark, Length: m.Length, TOS: m.TOS, Helper: m.Helper, Comment: m.Comment,
}
if m.Probability != nil {
mr.Probability = *m.Probability
}
cfg.Mangle = append(cfg.Mangle, mr)
}
for _, a := range rc.Accounting {
cfg.Accounting = append(cfg.Accounting, config.AccountingRule{
Action: config.AccountingAction(a.Action), Section: config.AccountingSection(a.Section), Chain: a.Chain,
Source: a.Source, Dest: a.Dest, Proto: a.Proto, DPort: config.PortSpec(a.DPort), SPort: config.PortSpec(a.SPort),
Mark: a.Mark, Comment: a.Comment,
})
}
for _, t := range rc.TCDevices {
cfg.TCDevices = append(cfg.TCDevices, config.TCDevice{
Interface: t.Interface, InBandwidth: t.InBandwidth, OutBandwidth: t.OutBandwidth, Comment: t.Comment,
})
}
for _, t := range rc.TCClasses {
cfg.TCClasses = append(cfg.TCClasses, config.TCClass{
Interface: t.Interface, Mark: t.Mark, Rate: t.Rate, Ceil: t.Ceil, Priority: t.Priority, Comment: t.Comment,
})
}
for _, t := range rc.TCFilters {
cfg.TCFilters = append(cfg.TCFilters, config.TCFilter{
Class: t.Class, Source: t.Source, Dest: t.Dest, Proto: t.Proto,
DPort: config.PortSpec(t.DPort), SPort: config.PortSpec(t.SPort),
TOS: t.TOS, Length: t.Length, Priority: t.Priority, Comment: t.Comment,
})
}
for _, t := range rc.TCInterfaces {
cfg.TCInterfaces = append(cfg.TCInterfaces, config.TCInterface{
Interface: t.Interface, Type: t.Type, InBandwidth: t.InBandwidth, OutBandwidth: t.OutBandwidth, Comment: t.Comment,
})
}
for _, t := range rc.TCPriorities {
cfg.TCPriorities = append(cfg.TCPriorities, config.TCPriority{
Band: t.Band, Proto: t.Proto, DPort: config.PortSpec(t.DPort), SPort: config.PortSpec(t.SPort),
Address: t.Address, Interface: t.Interface, Helper: t.Helper, Comment: t.Comment,
})
}
for _, b := range rc.Blrules {
cfg.Blrules = append(cfg.Blrules, config.BlruleRule{
Action: config.BlruleAction(b.Action), Source: b.Source, Dest: b.Dest, Proto: b.Proto,
DPort: config.PortSpec(b.DPort), SPort: config.PortSpec(b.SPort), Log: b.Log, Comment: b.Comment,
})
}
for _, c := range rc.Conntrack {
cfg.Conntrack = append(cfg.Conntrack, config.ConntrackRule{
Action: config.ConntrackAction(c.Action), Source: c.Source, Dest: c.Dest, Proto: c.Proto,
DPort: config.PortSpec(c.DPort), SPort: config.PortSpec(c.SPort),
Chain: config.ConntrackChain(c.Chain), Helper: c.Helper, User: c.User, Comment: c.Comment,
})
}
for _, sm := range rc.Secmarks {
cfg.Secmarks = append(cfg.Secmarks, config.SecmarkRule{
Secmark: sm.Secmark, Chain: sm.Chain, Source: sm.Source, Dest: sm.Dest, Proto: sm.Proto,
DPort: config.PortSpec(sm.DPort), SPort: config.PortSpec(sm.SPort), Comment: sm.Comment,
})
}
if len(rc.Vars) > 0 {
cfg.Vars = make(map[string]string, len(rc.Vars))
for k, v := range rc.Vars {
cfg.Vars[k] = v
}
}
return cfg, nil
}
// translateSNAT expands a rendered SNAT (which carries a list of egress
// interfaces and source CIDRs) into native tomswall SNAT rules — one per
// (egress interface, source) pair, since a native rule takes a single Dest.
func translateSNAT(s RenderedSNAT) []config.SNATRule {
sources := s.Source
if len(sources) == 0 {
sources = []string{""}
}
var out []config.SNATRule
for _, egress := range s.Egress {
for _, src := range sources {
r := config.SNATRule{
Action: config.SNATAction(s.Action),
Source: src,
Dest: egress,
Address: s.Address,
Comment: s.Comment,
}
if s.Probability != nil {
r.Probability = *s.Probability
}
out = append(out, r)
}
}
return out
}
// indexSets maps set name -> concrete member CIDRs (invalid members skipped).
func indexSets(sets []RenderedSet) map[string][]string {
m := make(map[string][]string, len(sets))
+58
View File
@@ -0,0 +1,58 @@
---
# nfpm config for building the tomswall RPM.
# Rendered through envsubst (see scripts/build-rpm.sh) then fed to `nfpm pkg`.
name: ${PACKAGE_NAME}
version: ${PACKAGE_VERSION}
release: ${PACKAGE_RELEASE}
arch: ${PACKAGE_ARCH}
platform: ${PACKAGE_PLATFORM}
section: default
priority: extra
description: "${PACKAGE_DESCRIPTION}"
maintainer: ${PACKAGE_MAINTAINER}
homepage: ${PACKAGE_HOMEPAGE}
license: ${PACKAGE_LICENSE}
disable_globbing: false
replaces:
- tomswall
provides:
- tomswall
contents:
- src: dist/tomswall
dst: /usr/sbin/tomswall
file_info:
mode: 0755
owner: root
group: root
# Example configuration (never overwrites an existing tomswall.yaml).
- src: tomswall.example.yaml
dst: /etc/tomswall/tomswall.example.yaml
file_info:
mode: 0644
# systemd unit + environment file for the control-plane agent.
- src: packaging/tomswall-agent.service
dst: /usr/lib/systemd/system/tomswall-agent.service
file_info:
mode: 0644
- src: packaging/tomswall-agent.env
dst: /etc/tomswall/agent.env
type: config|noreplace
file_info:
mode: 0640
# Shell completions (generated by scripts/build-rpm.sh before packaging).
- src: dist/completions/tomswall.bash
dst: /usr/share/bash-completion/completions/tomswall
file_info:
mode: 0644
- src: dist/completions/_tomswall
dst: /usr/share/zsh/site-functions/_tomswall
file_info:
mode: 0644
+12
View File
@@ -0,0 +1,12 @@
# Environment for the tomswall control-plane agent (tomswall-agent.service).
# The agent reads these; flags may also be passed via ExecStart.
# Base URL of the tomswallapi control plane.
TOMSWALL_API_URL=https://tomswallapi.k8s.syd1.au.unkin.net
# Agent bearer token (issued by the control plane / Vault). Keep this file 0640.
TOMSWALL_AGENT_TOKEN=
# The device name defaults to the system hostname. To override it, add
# `--device <name>` to ExecStart in the unit (drop-in), e.g.:
# ExecStart=/usr/sbin/tomswall agent --device fw-a
+18
View File
@@ -0,0 +1,18 @@
[Unit]
Description=tomswall control-plane agent (pull and apply firewall config)
Documentation=https://git.unkin.net/unkin/tomswall
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
EnvironmentFile=/etc/tomswall/agent.env
ExecStart=/usr/sbin/tomswall agent
Restart=on-failure
RestartSec=10
# The agent programs nftables and needs the requisite capabilities.
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_RAW
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_RAW
[Install]
WantedBy=multi-user.target
+43
View File
@@ -0,0 +1,43 @@
#!/usr/bin/env bash
#
# Package the (already built) tomswall binary into an RPM with nfpm, bundling
# generated bash/zsh shell completions and the systemd agent unit.
# Usage: scripts/build-rpm.sh [version] (version defaults to $CI_COMMIT_TAG)
#
set -euo pipefail
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "${ROOT_DIR}"
VERSION="${1:-${CI_COMMIT_TAG:-0.0.0-dev}}"
VERSION="${VERSION#v}" # strip a leading v
BINARY="tomswall"
DIST="dist"
if [ ! -f "${DIST}/${BINARY}" ]; then
echo "ERROR: ${DIST}/${BINARY} not found; run 'make dist-build' first" >&2
exit 1
fi
# Generate shell completions from the freshly built binary so they always match
# the shipped flags/subcommands.
COMP_DIR="${DIST}/completions"
mkdir -p "${COMP_DIR}"
"./${DIST}/${BINARY}" completion bash >"${COMP_DIR}/${BINARY}.bash"
"./${DIST}/${BINARY}" completion zsh >"${COMP_DIR}/_${BINARY}"
export PACKAGE_NAME="${BINARY}"
export PACKAGE_VERSION="${VERSION}"
export PACKAGE_RELEASE="1"
export PACKAGE_ARCH="amd64"
export PACKAGE_PLATFORM="linux"
export PACKAGE_DESCRIPTION="Spiritual successor to shorewall — nftables firewall manager, with a control-plane agent that pulls compiled config from tomswallapi"
export PACKAGE_MAINTAINER="Ben Vincent <ben@unkin.net>"
export PACKAGE_HOMEPAGE="https://git.unkin.net/unkin/tomswall"
export PACKAGE_LICENSE="MIT"
envsubst <packaging/nfpm.yaml >"${DIST}/nfpm.yaml"
nfpm pkg --config "${DIST}/nfpm.yaml" --target "${DIST}" --packager rpm
echo "Built:"
ls -1 "${DIST}"/*.rpm