blob: f7f48e5ba465b2bd6c53cfd819ad4755fa398a83 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
|
# 6to4.sh - IPv6-in-IPv4 tunnel backend
# Copyright (c) 2010-2011 OpenWrt.org
find_6to4_wanif() {
local if=$(ip -4 r l e 0.0.0.0/0); if="${if#default* dev }"; if="${if%% *}"
[ -n "$if" ] && grep -qs "^ *$if:" /proc/net/dev && echo "$if"
}
find_6to4_wanip() {
local ip=$(ip -4 a s dev "$1"); ip="${ip#*inet }"
echo "${ip%%[^0-9.]*}"
}
find_6to4_prefix() {
local ip4="$1"
local oIFS="$IFS"; IFS="."; set -- $ip4; IFS="$oIFS"
printf "2002:%02x%02x:%02x%02x\n" $1 $2 $3 $4
}
test_6to4_rfc1918()
{
local oIFS="$IFS"; IFS="."; set -- $1; IFS="$oIFS"
[ $1 -eq 10 ] && return 0
[ $1 -eq 192 ] && [ $2 -eq 168 ] && return 0
[ $1 -eq 172 ] && [ $2 -ge 16 ] && [ $2 -le 31 ] && return 0
return 1
}
set_6to4_radvd_interface() {
local cfgid="$1"
local lanif="${2:-lan}"
local ifmtu="${3:-1280}"
local ifsection=""
find_ifsection() {
local net
local cfg="$1"
config_get net "$cfg" interface
[ "$net" = "$lanif" ] && {
ifsection="$cfg"
return 1
}
}
config_foreach find_ifsection interface
[ -z "$ifsection" ] && {
ifsection="iface_$sid"
uci_set_state radvd "$ifsection" "" interface
uci_set_state radvd "$ifsection" interface "$lanif"
}
uci_set_state radvd "$ifsection" ignore 0
uci_set_state radvd "$ifsection" IgnoreIfMissing 1
uci_set_state radvd "$ifsection" AdvSendAdvert 1
uci_set_state radvd "$ifsection" MaxRtrAdvInterval 30
uci_set_state radvd "$ifsection" AdvLinkMTU "$ifmtu"
}
set_6to4_radvd_prefix() {
local cfgid="$1"
local lanif="${2:-lan}"
local wanif="${3:-wan}"
local prefix="${4:-0:0:0:1::/64}"
local vlt="${5:-300}"
local plt="${6:-120}"
local pfxsection=""
find_pfxsection() {
local net base
local cfg="$1"
config_get net "$cfg" interface
config_get base "$cfg" Base6to4Interface
[ "$net" = "$lanif" ] && [ "$base" = "$wanif" ] && {
pfxsection="$cfg"
return 1
}
}
config_foreach find_pfxsection prefix
[ -z "$pfxsection" ] && {
pfxsection="prefix_${sid}_${lanif}"
uci_set_state radvd "$pfxsection" "" prefix
uci_set_state radvd "$pfxsection" ignore 0
uci_set_state radvd "$pfxsection" interface "$lanif"
uci_set_state radvd "$pfxsection" prefix "$prefix"
uci_set_state radvd "$pfxsection" AdvOnLink 1
uci_set_state radvd "$pfxsection" AdvAutonomous 1
uci_set_state radvd "$pfxsection" AdvValidLifetime "$vlt"
uci_set_state radvd "$pfxsection" AdvPreferredLifetime "$plt"
uci_set_state radvd "$pfxsection" Base6to4Interface "$wanif"
}
}
# Hook into scan_interfaces() to synthesize a .device option
# This is needed for /sbin/ifup to properly dispatch control
# to setup_interface_6to4() even if no .ifname is set in
# the configuration.
scan_6to4() {
config_set "$1" device "6to4-$1"
}
coldplug_interface_6to4() {
setup_interface_6to4 "6to4-$1" "$1"
}
setup_interface_6to4() {
local iface="$1"
local cfg="$2"
local link="6to4-$cfg"
local local4=$(uci_get network "$cfg" ipaddr)
local mtu
config_get mtu "$cfg" mtu
local ttl
config_get ttl "$cfg" ttl
local metric
config_get metric "$cfg" metric
local defaultroute
config_get_bool defaultroute "$cfg" defaultroute 1
local wanif=$(find_6to4_wanif)
[ -z "$wanif" ] && {
logger -t "$link" "Cannot find wan interface - aborting"
return
}
local wancfg=$(find_config "$wanif")
[ -z "$wancfg" ] && {
logger -t "$link" "Cannot find wan network - aborting"
return
}
# If local4 is unset, guess local IPv4 address from the
# interface used by the default route.
[ -z "$local4" ] && {
[ -n "$wanif" ] && {
local4=$(find_6to4_wanip "$wanif")
uci_set_state network "$cfg" wan_device "$wanif"
}
}
test_6to4_rfc1918 "$local4" && {
logger -t "$link" "Local wan ip $local4 is private - aborting"
return
}
[ -n "$local4" ] && {
logger -t "$link" "Starting ..."
# creating the tunnel below will trigger a net subsystem event
# prevent it from touching or iface by disabling .auto here
uci_set_state network "$cfg" ifname $link
uci_set_state network "$cfg" auto 0
# find our local prefix
local prefix6=$(find_6to4_prefix "$local4")
local local6="$prefix6::1/16"
logger -t "$link" " * IPv4 address is $local4"
logger -t "$link" " * IPv6 address is $local6"
ip tunnel add $link mode sit remote any local $local4 ttl ${ttl:-64}
ip link set $link up
ip link set mtu ${mtu:-1280} dev $link
ip addr add $local6 dev $link
uci_set_state network "$cfg" ipaddr $local4
uci_set_state network "$cfg" ip6addr $local6
[ "$defaultroute" = 1 ] && {
logger -t "$link" " * Adding default route"
ip -6 route add ::/0 via ::192.88.99.1 metric ${metric:-1} dev $link
uci_set_state network "$cfg" defaultroute 1
}
[ -f /etc/config/radvd ] && /etc/init.d/radvd enabled && {
local sid="6to4_$cfg"
uci_revert_state radvd
config_load radvd
# find delegation target
local adv_interface
config_get adv_interface "$cfg" adv_interface
local adv_subnet=$(uci_get network "$cfg" adv_subnet)
adv_subnet=$((0x${adv_subnet:-1}))
local adv_subnets=""
for adv_interface in ${adv_interface:-lan}; do
local adv_ifname
config_get adv_ifname "${adv_interface:-lan}" ifname
grep -qs "^ *$adv_ifname:" /proc/net/dev && {
local adv_valid_lifetime adv_preferred_lifetime
config_get adv_valid_lifetime "$cfg" adv_valid_lifetime
config_get adv_preferred_lifetime "$cfg" adv_preferred_lifetime
local subnet6="$(printf "%s:%x::1/64" "$prefix6" $adv_subnet)"
logger -t "$link" " * Advertising IPv6 subnet $subnet6 on ${adv_interface:-lan} ($adv_ifname)"
ip -6 addr add $subnet6 dev $adv_ifname
set_6to4_radvd_interface "$sid" "$adv_interface" "$mtu"
set_6to4_radvd_prefix "$sid" "$adv_interface" \
"$wancfg" "$(printf "0:0:0:%x::/64" $adv_subnet)" \
"$adv_valid_lifetime" "$adv_preferred_lifetime"
adv_subnets="${adv_subnets:+$adv_subnets }$adv_ifname:$subnet6"
adv_subnet=$(($adv_subnet + 1))
}
done
uci_set_state network "$cfg" adv_subnets "$adv_subnets"
/etc/init.d/radvd restart
}
logger -t "$link" "... started"
env -i ACTION="ifup" INTERFACE="$cfg" DEVICE="$link" PROTO=6to4 /sbin/hotplug-call "iface" &
} || {
echo "Cannot determine local IPv4 address for 6to4 tunnel $cfg - skipping"
}
}
stop_interface_6to4() {
local cfg="$1"
local link="6to4-$cfg"
local local6=$(uci_get_state network "$cfg" ip6addr)
local defaultroute=$(uci_get_state network "$cfg" defaultroute)
local adv_subnets=$(uci_get_state network "$cfg" adv_subnets)
grep -qs "^ *$link:" /proc/net/dev && {
logger -t "$link" "Shutting down ..."
env -i ACTION="ifdown" INTERFACE="$cfg" DEVICE="$link" PROTO=6to4 /sbin/hotplug-call "iface" &
[ -n "$adv_subnets" ] && {
uci_revert_state radvd
/etc/init.d/radvd enabled && /etc/init.d/radvd restart
local adv_subnet
for adv_subnet in $adv_subnets; do
local ifname="${adv_subnet%%:*}"
local subnet="${adv_subnet#*:}"
logger -t "$link" " * Removing IPv6 subnet $subnet from interface $ifname"
ip -6 addr del $subnet dev $ifname
done
}
[ "$defaultroute" = "1" ] && \
ip -6 route del ::/0 via ::192.88.99.1 dev $link
ip addr del $local6 dev $link
ip link set $link down
ip tunnel del $link
logger -t "$link" "... stopped"
}
}
|