132cbe5e29
Ship keys for the root zone and add two uci options to enable DNSSEC checks: Option 'dnssec': Activate DNSSEC validation Option 'dnsseccheckunsigned': Ensure answers without DNSSEC are in unsigned zones. Signed-off-by: Andre Heider <a.heider@gmail.com> SVN-Revision: 41245
610 lines
14 KiB
Bash
610 lines
14 KiB
Bash
#!/bin/sh /etc/rc.common
|
|
# Copyright (C) 2007-2012 OpenWrt.org
|
|
|
|
START=60
|
|
|
|
USE_PROCD=1
|
|
PROG=/usr/sbin/dnsmasq
|
|
|
|
DNS_SERVERS=""
|
|
DOMAIN=""
|
|
|
|
ADD_LOCAL_DOMAIN=1
|
|
ADD_LOCAL_HOSTNAME=1
|
|
|
|
CONFIGFILE="/var/etc/dnsmasq.conf"
|
|
HOSTFILE="/tmp/hosts/dhcp"
|
|
TRUSTANCHORSFILE="/usr/share/dnsmasq/trust-anchors.conf"
|
|
|
|
xappend() {
|
|
local value="$1"
|
|
|
|
echo "${value#--}" >> $CONFIGFILE
|
|
}
|
|
|
|
dhcp_calc() {
|
|
local ip="$1"
|
|
local res=0
|
|
|
|
while [ -n "$ip" ]; do
|
|
part="${ip%%.*}"
|
|
res="$(($res * 256))"
|
|
res="$(($res + $part))"
|
|
[ "${ip%.*}" != "$ip" ] && ip="${ip#*.}" || ip=
|
|
done
|
|
echo "$res"
|
|
}
|
|
|
|
dhcp_check() {
|
|
local ifname="$1"
|
|
local stamp="/var/run/dnsmasq.$ifname.dhcp"
|
|
local rv=0
|
|
|
|
[ -s "$stamp" ] && return $(cat "$stamp")
|
|
|
|
udhcpc -n -q -s /bin/true -t 1 -i "$ifname" >&- && rv=1 || rv=0
|
|
|
|
[ $rv -eq 1 ] && \
|
|
logger -t dnsmasq \
|
|
"found already running DHCP-server on interface '$ifname'" \
|
|
"refusing to start, use 'option force 1' to override"
|
|
|
|
echo $rv > "$stamp"
|
|
return $rv
|
|
}
|
|
|
|
log_once() {
|
|
pidof dnsmasq >/dev/null || \
|
|
logger -t dnsmasq "$@"
|
|
}
|
|
|
|
append_bool() {
|
|
local section="$1"
|
|
local option="$2"
|
|
local value="$3"
|
|
local _loctmp
|
|
config_get_bool _loctmp "$section" "$option" 0
|
|
[ $_loctmp -gt 0 ] && xappend "$value"
|
|
}
|
|
|
|
append_parm() {
|
|
local section="$1"
|
|
local option="$2"
|
|
local switch="$3"
|
|
local _loctmp
|
|
config_get _loctmp "$section" "$option"
|
|
[ -z "$_loctmp" ] && return 0
|
|
xappend "$switch=$_loctmp"
|
|
}
|
|
|
|
append_server() {
|
|
xappend "--server=$1"
|
|
}
|
|
|
|
append_address() {
|
|
xappend "--address=$1"
|
|
}
|
|
|
|
append_interface() {
|
|
local ifname=$(uci_get_state network "$1" ifname "$1")
|
|
xappend "--interface=$ifname"
|
|
}
|
|
|
|
append_notinterface() {
|
|
local ifname=$(uci_get_state network "$1" ifname "$1")
|
|
xappend "--except-interface=$ifname"
|
|
}
|
|
|
|
append_addnhosts() {
|
|
xappend "--addn-hosts=$1"
|
|
}
|
|
|
|
append_bogusnxdomain() {
|
|
xappend "--bogus-nxdomain=$1"
|
|
}
|
|
|
|
dnsmasq() {
|
|
local cfg="$1"
|
|
append_bool "$cfg" authoritative "--dhcp-authoritative"
|
|
append_bool "$cfg" nodaemon "--no-daemon"
|
|
append_bool "$cfg" domainneeded "--domain-needed"
|
|
append_bool "$cfg" filterwin2k "--filterwin2k"
|
|
append_bool "$cfg" nohosts "--no-hosts"
|
|
append_bool "$cfg" nonegcache "--no-negcache"
|
|
append_bool "$cfg" strictorder "--strict-order"
|
|
append_bool "$cfg" logqueries "--log-queries"
|
|
append_bool "$cfg" noresolv "--no-resolv"
|
|
append_bool "$cfg" localise_queries "--localise-queries"
|
|
append_bool "$cfg" readethers "--read-ethers"
|
|
append_bool "$cfg" dbus "--enable-dbus"
|
|
append_bool "$cfg" boguspriv "--bogus-priv"
|
|
append_bool "$cfg" expandhosts "--expand-hosts"
|
|
append_bool "$cfg" enable_tftp "--enable-tftp"
|
|
append_bool "$cfg" nonwildcard "--bind-interfaces"
|
|
append_bool "$cfg" fqdn "--dhcp-fqdn"
|
|
append_bool "$cfg" proxydnssec "--proxy-dnssec"
|
|
|
|
append_parm "$cfg" dhcpscript "--dhcp-script"
|
|
append_parm "$cfg" cachesize "--cache-size"
|
|
append_parm "$cfg" dnsforwardmax "--dns-forward-max"
|
|
append_parm "$cfg" port "--port"
|
|
append_parm "$cfg" ednspacket_max "--edns-packet-max"
|
|
append_parm "$cfg" dhcpleasemax "--dhcp-lease-max"
|
|
append_parm "$cfg" "queryport" "--query-port"
|
|
append_parm "$cfg" "domain" "--domain"
|
|
append_parm "$cfg" "local" "--server"
|
|
config_list_foreach "$cfg" "server" append_server
|
|
config_list_foreach "$cfg" "address" append_address
|
|
config_list_foreach "$cfg" "interface" append_interface
|
|
config_list_foreach "$cfg" "notinterface" append_notinterface
|
|
config_list_foreach "$cfg" "addnhosts" append_addnhosts
|
|
config_list_foreach "$cfg" "bogusnxdomain" append_bogusnxdomain
|
|
append_parm "$cfg" "leasefile" "--dhcp-leasefile"
|
|
append_parm "$cfg" "resolvfile" "--resolv-file"
|
|
append_parm "$cfg" "tftp_root" "--tftp-root"
|
|
append_parm "$cfg" "dhcp_boot" "--dhcp-boot"
|
|
append_parm "$cfg" "local_ttl" "--local-ttl"
|
|
|
|
config_get DOMAIN "$cfg" domain
|
|
|
|
config_get_bool ADD_LOCAL_DOMAIN "$cfg" add_local_domain 1
|
|
config_get_bool ADD_LOCAL_HOSTNAME "$cfg" add_local_hostname 1
|
|
|
|
config_get_bool readethers "$cfg" readethers
|
|
[ "$readethers" = "1" -a \! -e "/etc/ethers" ] && touch /etc/ethers
|
|
|
|
config_get leasefile $cfg leasefile
|
|
[ -n "$leasefile" -a \! -e "$leasefile" ] && touch "$leasefile"
|
|
config_get_bool cachelocal "$cfg" cachelocal 1
|
|
|
|
config_get hostsfile "$cfg" dhcphostsfile
|
|
[ -e "$hostsfile" ] && xappend "--dhcp-hostsfile=$hostsfile"
|
|
|
|
mkdir -p /tmp/hosts /tmp/dnsmasq.d
|
|
xappend "--addn-hosts=/tmp/hosts"
|
|
xappend "--conf-dir=/tmp/dnsmasq.d"
|
|
|
|
local rebind
|
|
config_get_bool rebind "$cfg" rebind_protection 1
|
|
[ $rebind -gt 0 ] && {
|
|
log_once \
|
|
"DNS rebinding protection is active," \
|
|
"will discard upstream RFC1918 responses!"
|
|
xappend "--stop-dns-rebind"
|
|
|
|
local rebind_localhost
|
|
config_get_bool rebind_localhost "$cfg" rebind_localhost 0
|
|
[ $rebind_localhost -gt 0 ] && {
|
|
log_once "Allowing 127.0.0.0/8 responses"
|
|
xappend "--rebind-localhost-ok"
|
|
}
|
|
|
|
append_rebind_domain() {
|
|
log_once "Allowing RFC1918 responses for domain $1"
|
|
xappend "--rebind-domain-ok=$1"
|
|
}
|
|
|
|
config_list_foreach "$cfg" rebind_domain append_rebind_domain
|
|
}
|
|
|
|
config_get dnssec "$cfg" dnssec
|
|
[ "$dnssec" -gt 0 ] && {
|
|
xappend "--conf-file=$TRUSTANCHORSFILE"
|
|
xappend "--dnssec"
|
|
append_bool "$cfg" dnsseccheckunsigned "--dnssec-check-unsigned"
|
|
}
|
|
|
|
dhcp_option_add "$cfg" "" 0
|
|
|
|
xappend "--dhcp-broadcast=tag:needs-broadcast"
|
|
|
|
echo >> $CONFIGFILE
|
|
}
|
|
|
|
dhcp_subscrid_add() {
|
|
local cfg="$1"
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] || return 0
|
|
|
|
config_get subscriberid "$cfg" subscriberid
|
|
[ -n "$subscriberid" ] || return 0
|
|
|
|
xappend "--dhcp-subscrid=$networkid,$subscriberid"
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
|
|
dhcp_option_add "$cfg" "$networkid" "$force"
|
|
}
|
|
|
|
dhcp_remoteid_add() {
|
|
local cfg="$1"
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] || return 0
|
|
|
|
config_get remoteid "$cfg" remoteid
|
|
[ -n "$remoteid" ] || return 0
|
|
|
|
xappend "--dhcp-remoteid=$networkid,$remoteid"
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
|
|
dhcp_option_add "$cfg" "$networkid" "$force"
|
|
}
|
|
|
|
dhcp_circuitid_add() {
|
|
local cfg="$1"
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] || return 0
|
|
|
|
config_get circuitid "$cfg" circuitid
|
|
[ -n "$circuitid" ] || return 0
|
|
|
|
xappend "--dhcp-circuitid=$networkid,$circuitid"
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
|
|
dhcp_option_add "$cfg" "$networkid" "$force"
|
|
}
|
|
|
|
dhcp_userclass_add() {
|
|
local cfg="$1"
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] || return 0
|
|
|
|
config_get userclass "$cfg" userclass
|
|
[ -n "$userclass" ] || return 0
|
|
|
|
xappend "--dhcp-userclass=$networkid,$userclass"
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
|
|
dhcp_option_add "$cfg" "$networkid" "$force"
|
|
}
|
|
|
|
dhcp_vendorclass_add() {
|
|
local cfg="$1"
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] || return 0
|
|
|
|
config_get vendorclass "$cfg" vendorclass
|
|
[ -n "$vendorclass" ] || return 0
|
|
|
|
xappend "--dhcp-vendorclass=$networkid,$vendorclass"
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
|
|
dhcp_option_add "$cfg" "$networkid" "$force"
|
|
}
|
|
|
|
dhcp_host_add() {
|
|
local cfg="$1"
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] && dhcp_option_add "$cfg" "$networkid" "$force"
|
|
|
|
config_get name "$cfg" name
|
|
config_get ip "$cfg" ip
|
|
[ -n "$ip" -o -n "$name" ] || return 0
|
|
|
|
config_get mac "$cfg" mac
|
|
[ -z "$mac" ] && {
|
|
[ -n "$name" ] || return 0
|
|
mac="$name"
|
|
name=""
|
|
}
|
|
|
|
macs=""
|
|
for m in $mac; do append macs "$m" ","; done
|
|
|
|
config_get tag "$cfg" tag
|
|
|
|
config_get_bool broadcast "$cfg" broadcast 0
|
|
[ "$broadcast" = "0" ] && broadcast=
|
|
|
|
xappend "--dhcp-host=$macs${networkid:+,net:$networkid}${broadcast:+,set:needs-broadcast}${tag:+,set:$tag}${ip:+,$ip}${name:+,$name}"
|
|
|
|
config_get_bool dns "$cfg" dns 0
|
|
[ "$dns" = "1" ] && {
|
|
echo "$ip $name${DOMAIN:+.$DOMAIN}" >> $HOSTFILE
|
|
}
|
|
}
|
|
|
|
dhcp_tag_add() {
|
|
local cfg="$1"
|
|
|
|
tag="$cfg"
|
|
|
|
[ -n "$tag" ] || return 0
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
[ "$force" = "0" ] && force=
|
|
|
|
config_get option "$cfg" dhcp_option
|
|
for o in $option; do
|
|
xappend "--dhcp-option${force:+-force}=tag:$tag,$o"
|
|
done
|
|
}
|
|
|
|
dhcp_mac_add() {
|
|
local cfg="$1"
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] || return 0
|
|
|
|
config_get mac "$cfg" mac
|
|
[ -n "$mac" ] || return 0
|
|
|
|
xappend "--dhcp-mac=$networkid,$mac"
|
|
|
|
dhcp_option_add "$cfg" "$networkid"
|
|
}
|
|
|
|
dhcp_boot_add() {
|
|
local cfg="$1"
|
|
|
|
config_get networkid "$cfg" networkid
|
|
|
|
config_get filename "$cfg" filename
|
|
[ -n "$filename" ] || return 0
|
|
|
|
config_get servername "$cfg" servername
|
|
[ -n "$servername" ] || return 0
|
|
|
|
config_get serveraddress "$cfg" serveraddress
|
|
[ -n "$serveraddress" ] || return 0
|
|
|
|
xappend "--dhcp-boot=${networkid:+net:$networkid,}$filename,$servername,$serveraddress"
|
|
|
|
config_get_bool force "$cfg" force 0
|
|
|
|
dhcp_option_add "$cfg" "$networkid" "$force"
|
|
}
|
|
|
|
|
|
dhcp_add() {
|
|
local cfg="$1"
|
|
config_get net "$cfg" interface
|
|
[ -n "$net" ] || return 0
|
|
|
|
config_get networkid "$cfg" networkid
|
|
[ -n "$networkid" ] || networkid="$net"
|
|
|
|
network_get_subnet subnet "$net" || return 0
|
|
network_get_device ifname "$net" || return 0
|
|
network_get_protocol proto "$net" || return 0
|
|
|
|
[ "$cachelocal" = "0" ] && network_get_dnsserver dnsserver "$net" && {
|
|
DNS_SERVERS="$DNS_SERVERS $dnsserver"
|
|
}
|
|
|
|
append_bool "$cfg" ignore "--no-dhcp-interface=$ifname" && return 0
|
|
|
|
# Do not support non-static interfaces for now
|
|
[ static = "$proto" ] || return 0
|
|
|
|
# Override interface netmask with dhcp config if applicable
|
|
config_get netmask "$cfg" netmask "${subnet##*/}"
|
|
|
|
#check for an already active dhcp server on the interface, unless 'force' is set
|
|
config_get_bool force "$cfg" force 0
|
|
[ $force -gt 0 ] || dhcp_check "$ifname" || return 0
|
|
|
|
config_get start "$cfg" start
|
|
config_get limit "$cfg" limit
|
|
config_get leasetime "$cfg" leasetime
|
|
config_get options "$cfg" options
|
|
config_get_bool dynamicdhcp "$cfg" dynamicdhcp 1
|
|
|
|
leasetime="${leasetime:-12h}"
|
|
start="$(dhcp_calc "${start:-100}")"
|
|
limit="${limit:-150}"
|
|
[ "$limit" -gt 0 ] && limit=$((limit-1))
|
|
eval "$(ipcalc.sh "${subnet%%/*}" $netmask $start $limit)"
|
|
if [ "$dynamicdhcp" = "0" ]; then END="static"; fi
|
|
xappend "--dhcp-range=$networkid,$START,$END,$NETMASK,$leasetime${options:+ $options}"
|
|
|
|
dhcp_option_add "$cfg" "$networkid"
|
|
}
|
|
|
|
dhcp_option_add() {
|
|
local cfg="$1"
|
|
local networkid="$2"
|
|
local force="$3"
|
|
|
|
[ "$force" = "0" ] && force=
|
|
|
|
config_get dhcp_option "$cfg" dhcp_option
|
|
for o in $dhcp_option; do
|
|
xappend "--dhcp-option${force:+-force}=${networkid:+$networkid,}$o"
|
|
done
|
|
|
|
}
|
|
|
|
dhcp_domain_add() {
|
|
local cfg="$1"
|
|
local ip name names record
|
|
|
|
config_get names "$cfg" name "$2"
|
|
[ -n "$names" ] || return 0
|
|
|
|
config_get ip "$cfg" ip "$3"
|
|
[ -n "$ip" ] || return 0
|
|
|
|
for name in $names; do
|
|
[ "${name%.*}" == "$name" ] && \
|
|
name="$name${DOMAIN:+.$DOMAIN}"
|
|
|
|
record="${record:+$record/}$name"
|
|
done
|
|
|
|
xappend "--address=/$record/$ip"
|
|
}
|
|
|
|
dhcp_srv_add() {
|
|
local cfg="$1"
|
|
|
|
config_get srv "$cfg" srv
|
|
[ -n "$srv" ] || return 0
|
|
|
|
config_get target "$cfg" target
|
|
[ -n "$target" ] || return 0
|
|
|
|
config_get port "$cfg" port
|
|
[ -n "$port" ] || return 0
|
|
|
|
config_get class "$cfg" class
|
|
config_get weight "$cfg" weight
|
|
|
|
local service="$srv,$target,$port${class:+,$class${weight:+,$weight}}"
|
|
|
|
xappend "--srv-host=$service"
|
|
}
|
|
|
|
dhcp_mx_add() {
|
|
local cfg="$1"
|
|
local domain relay pref
|
|
|
|
config_get domain "$cfg" domain
|
|
[ -n "$domain" ] || return 0
|
|
|
|
config_get relay "$cfg" relay
|
|
[ -n "$relay" ] || return 0
|
|
|
|
config_get pref "$cfg" pref 0
|
|
|
|
local service="$domain,$relay,$pref"
|
|
|
|
xappend "--mx-host=$service"
|
|
}
|
|
|
|
dhcp_cname_add() {
|
|
local cfg="$1"
|
|
local cname target
|
|
|
|
config_get cname "$cfg" cname
|
|
[ -n "$cname" ] || return 0
|
|
|
|
config_get target "$cfg" target
|
|
[ -n "$target" ] || return 0
|
|
|
|
xappend "--cname=${cname},${target}"
|
|
}
|
|
|
|
dhcp_hostrecord_add() {
|
|
local cfg="$1"
|
|
local names addresses record val
|
|
|
|
config_get names "$cfg" name "$2"
|
|
if [ -z "$names" ]; then
|
|
return 0
|
|
fi
|
|
|
|
config_get addresses "$cfg" ip "$3"
|
|
if [ -z "$addresses" ]; then
|
|
return 0
|
|
fi
|
|
|
|
for val in $names $addresses; do
|
|
record="${record:+$record,}$val"
|
|
done
|
|
|
|
xappend "--host-record=$record"
|
|
}
|
|
|
|
service_triggers()
|
|
{
|
|
procd_add_reload_trigger "dhcp"
|
|
}
|
|
|
|
boot() {
|
|
# Will be launched through hotplug
|
|
return 0
|
|
}
|
|
|
|
start_service() {
|
|
include /lib/functions
|
|
|
|
config_load dhcp
|
|
|
|
procd_open_instance
|
|
procd_set_param command $PROG -C $CONFIGFILE -k
|
|
procd_set_param file $CONFIGFILE
|
|
procd_close_instance
|
|
|
|
# before we can call xappend
|
|
mkdir -p $(dirname $CONFIGFILE)
|
|
|
|
echo "# auto-generated config file from /etc/config/dhcp" > $CONFIGFILE
|
|
echo "# auto-generated config file from /etc/config/dhcp" > $HOSTFILE
|
|
|
|
# if we did this last, we could override auto-generated config
|
|
[ -f /etc/dnsmasq.conf ] && {
|
|
xappend "--conf-file=/etc/dnsmasq.conf"
|
|
}
|
|
|
|
args=""
|
|
config_foreach dnsmasq dnsmasq
|
|
config_foreach dhcp_host_add host
|
|
echo >> $CONFIGFILE
|
|
config_foreach dhcp_boot_add boot
|
|
config_foreach dhcp_mac_add mac
|
|
config_foreach dhcp_tag_add tag
|
|
config_foreach dhcp_vendorclass_add vendorclass
|
|
config_foreach dhcp_userclass_add userclass
|
|
config_foreach dhcp_circuitid_add circuitid
|
|
config_foreach dhcp_remoteid_add remoteid
|
|
config_foreach dhcp_subscrid_add subscrid
|
|
config_foreach dhcp_domain_add domain
|
|
config_foreach dhcp_hostrecord_add hostrecord
|
|
|
|
# add own hostname
|
|
local lanaddr
|
|
[ $ADD_LOCAL_HOSTNAME -eq 1 ] && network_get_ipaddr lanaddr "lan" && {
|
|
local hostname="$(uci_get system @system[0] hostname OpenWrt)"
|
|
dhcp_hostrecord_add "" "${hostname%.$DOMAIN}${DOMAIN:+.$DOMAIN ${hostname%.$DOMAIN}}" "$lanaddr"
|
|
}
|
|
|
|
echo >> $CONFIGFILE
|
|
config_foreach dhcp_srv_add srvhost
|
|
config_foreach dhcp_mx_add mxhost
|
|
echo >> $CONFIGFILE
|
|
|
|
config_get odhcpd_is_active odhcpd maindhcp
|
|
if [ "$odhcpd_is_active" != "1" ]; then
|
|
config_foreach dhcp_add dhcp
|
|
fi
|
|
|
|
echo >> $CONFIGFILE
|
|
config_foreach dhcp_cname_add cname
|
|
echo >> $CONFIGFILE
|
|
|
|
rm -f /tmp/resolv.conf
|
|
[ $ADD_LOCAL_DOMAIN -eq 1 ] && [ -n "$DOMAIN" ] && {
|
|
echo "search $DOMAIN" >> /tmp/resolv.conf
|
|
}
|
|
DNS_SERVERS="$DNS_SERVERS 127.0.0.1"
|
|
for DNS_SERVER in $DNS_SERVERS ; do
|
|
echo "nameserver $DNS_SERVER" >> /tmp/resolv.conf
|
|
done
|
|
}
|
|
|
|
reload_service() {
|
|
rc_procd start_service "$@"
|
|
return 0
|
|
}
|
|
|
|
stop_service() {
|
|
[ -f /tmp/resolv.conf ] && {
|
|
rm -f /tmp/resolv.conf
|
|
ln -s /tmp/resolv.conf.auto /tmp/resolv.conf
|
|
}
|
|
rm -f /var/run/dnsmasq.*.dhcp
|
|
}
|