isolate_linux.go 1.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142
  1. // Copyright 2015 CoreOS, Inc.
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package netutil
  15. import (
  16. "fmt"
  17. "os/exec"
  18. )
  19. // DropPort drops all tcp packets that are received from the given port and sent to the given port.
  20. func DropPort(port int) error {
  21. cmdStr := fmt.Sprintf("sudo iptables -A OUTPUT -p tcp --destination-port %d -j DROP", port)
  22. if _, err := exec.Command("/bin/sh", "-c", cmdStr).Output(); err != nil {
  23. return err
  24. }
  25. cmdStr = fmt.Sprintf("sudo iptables -A INPUT -p tcp --destination-port %d -j DROP", port)
  26. _, err := exec.Command("/bin/sh", "-c", cmdStr).Output()
  27. return err
  28. }
  29. // RecoverPort stops dropping tcp packets at given port.
  30. func RecoverPort(port int) error {
  31. cmdStr := fmt.Sprintf("sudo iptables -D OUTPUT -p tcp --destination-port %d -j DROP", port)
  32. if _, err := exec.Command("/bin/sh", "-c", cmdStr).Output(); err != nil {
  33. return err
  34. }
  35. cmdStr = fmt.Sprintf("sudo iptables -D INPUT -p tcp --destination-port %d -j DROP", port)
  36. _, err := exec.Command("/bin/sh", "-c", cmdStr).Output()
  37. return err
  38. }