openvpn: add generic hotplug mechanism
[openwrt/staging/dedeckeh.git] / package / network / services / openvpn / files / openvpn.init
1 #!/bin/sh /etc/rc.common
2 # Copyright (C) 2008-2013 OpenWrt.org
3 # Copyright (C) 2008 Jo-Philipp Wich
4 # This is free software, licensed under the GNU General Public License v2.
5 # See /LICENSE for more information.
6
7 START=90
8 STOP=10
9
10 USE_PROCD=1
11 PROG=/usr/sbin/openvpn
12
13 LIST_SEP="
14 "
15
16 UCI_STARTED=
17 UCI_DISABLED=
18
19 append_param() {
20 local s="$1"
21 local v="$2"
22 case "$v" in
23 *_*_*_*) v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_} ;;
24 *_*_*) v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_} ;;
25 *_*) v=${v%%_*}-${v#*_} ;;
26 esac
27 echo -n "$v" >> "/var/etc/openvpn-$s.conf"
28 return 0
29 }
30
31 append_bools() {
32 local p; local v; local s="$1"; shift
33 for p in $*; do
34 config_get_bool v "$s" "$p"
35 [ "$v" = 1 ] && append_param "$s" "$p" && echo >> "/var/etc/openvpn-$s.conf"
36 done
37 }
38
39 append_params() {
40 local p; local v; local s="$1"; shift
41 for p in $*; do
42 config_get v "$s" "$p"
43 IFS="$LIST_SEP"
44 for v in $v; do
45 [ -n "$v" ] && [ "$p" != "push" ] && append_param "$s" "$p" && echo " $v" >> "/var/etc/openvpn-$s.conf"
46 [ -n "$v" ] && [ "$p" == "push" ] && append_param "$s" "$p" && echo " \"$v\"" >> "/var/etc/openvpn-$s.conf"
47 done
48 unset IFS
49 done
50 }
51
52 append_list() {
53 local p; local v; local s="$1"; shift
54
55 list_cb_append() {
56 v="${v}:$1"
57 }
58
59 for p in $*; do
60 unset v
61 config_list_foreach "$s" "$p" list_cb_append
62 [ -n "$v" ] && append_param "$s" "$p" && echo " ${v:1}" >> "/var/etc/openvpn-$s.conf"
63 done
64 }
65
66 section_enabled() {
67 config_get_bool enable "$1" 'enable' 0
68 config_get_bool enabled "$1" 'enabled' 0
69 [ $enable -gt 0 ] || [ $enabled -gt 0 ]
70 }
71
72 openvpn_add_instance() {
73 local name="$1"
74 local dir="$2"
75 local conf="$3"
76 local security="$4"
77
78 procd_open_instance "$name"
79 procd_set_param command "$PROG" \
80 --syslog "openvpn($name)" \
81 --status "/var/run/openvpn.$name.status" \
82 --cd "$dir" \
83 --config "$conf" \
84 --up "/usr/libexec/openvpn-hotplug up $name" \
85 --down "/usr/libexec/openvpn-hotplug down $name" \
86 --script-security "${security:-2}"
87 procd_set_param file "$dir/$conf"
88 procd_set_param term_timeout 15
89 procd_set_param respawn
90 procd_append_param respawn 3600
91 procd_append_param respawn 5
92 procd_append_param respawn -1
93 procd_close_instance
94 }
95
96 start_instance() {
97 local s="$1"
98
99 config_get config "$s" config
100 config="${config:+$(readlink -f "$config")}"
101
102 section_enabled "$s" || {
103 append UCI_DISABLED "$config" "$LIST_SEP"
104 return 1
105 }
106
107 local script_security
108 config_get script_security "$s" script_security
109
110 [ ! -d "/var/run" ] && mkdir -p "/var/run"
111
112 if [ ! -z "$config" ]; then
113 append UCI_STARTED "$config" "$LIST_SEP"
114 openvpn_add_instance "$s" "${config%/*}" "$config" "$script_security"
115 return
116 fi
117
118 [ ! -d "/var/etc" ] && mkdir -p "/var/etc"
119 [ -f "/var/etc/openvpn-$s.conf" ] && rm "/var/etc/openvpn-$s.conf"
120
121 append_bools "$s" $OPENVPN_BOOLS
122 append_params "$s" $OPENVPN_PARAMS
123 append_list "$s" $OPENVPN_LIST
124
125 openvpn_add_instance "$s" "/var/etc" "openvpn-$s.conf" "$script_security"
126 }
127
128 start_service() {
129 local instance="$1"
130 local instance_found=0
131
132 config_cb() {
133 local type="$1"
134 local name="$2"
135 if [ "$type" = "openvpn" ]; then
136 if [ -n "$instance" -a "$instance" = "$name" ]; then
137 instance_found=1
138 fi
139 fi
140 }
141
142 . /usr/share/openvpn/openvpn.options
143 config_load 'openvpn'
144
145 if [ -n "$instance" ]; then
146 [ "$instance_found" -gt 0 ] || return
147 start_instance "$instance"
148 else
149 config_foreach start_instance 'openvpn'
150
151 local path name
152 for path in /etc/openvpn/*.conf; do
153 if [ -f "$path" ]; then
154 name="${path##*/}"; name="${name%.conf}"
155
156 # don't start configs again that are already started by uci
157 if echo "$UCI_STARTED" | grep -qxF "$path"; then
158 continue
159
160 # don't start configs which are set to disabled in uci
161 elif echo "$UCI_DISABLED" | grep -qxF "$path"; then
162 logger -t openvpn "$name.conf is disabled in /etc/config/openvpn"
163 continue
164 fi
165
166 openvpn_add_instance "$name" "${path%/*}" "$path"
167 fi
168 done
169 fi
170 }
171
172 service_triggers() {
173 procd_add_reload_trigger openvpn
174 }