2 LuCI - Lua Configuration Interface
4 Copyright 2008 Steven Barth <steven@midlink.org>
5 Copyright 2008 Jo-Philipp Wich <xm@leipzig.freifunk.net>
7 Licensed under the Apache License, Version 2.0 (the "License");
8 you may not use this file except in compliance with the License.
9 You may obtain a copy of the License at
11 http://www.apache.org/licenses/LICENSE-2.0
18 local uci = require "luci.model.uci".cursor()
19 local tools = require "luci.tools.ffwizard"
20 local util = require "luci.util"
21 local sys = require "luci.sys"
22 local ip = require "luci.ip"
24 local function mksubnet(community, meship)
25 local subnet_prefix = tonumber(uci:get("freifunk", community, "splash_prefix")) or 27
26 local pool_network = uci:get("freifunk", community, "splash_network") or "10.104.0.0/16"
27 local pool = luci.ip.IPv4(pool_network)
30 local hosts_per_subnet = 2^(32 - subnet_prefix)
31 local number_of_subnets = (2^pool:prefix())/hosts_per_subnet
33 local seed1, seed2 = meship:match("(%d+)%.(%d+)$")
34 math.randomseed(seed1 * seed2)
36 local subnet = pool:add(hosts_per_subnet * math.random(number_of_subnets))
38 local subnet_ipaddr = subnet:network(subnet_prefix):add(1):string()
39 local subnet_netmask = subnet:mask(subnet_prefix):string()
41 return subnet_ipaddr, subnet_netmask
46 -------------------- View --------------------
47 f = SimpleForm("ffwizward", "Freifunkassistent",
48 "Dieser Assistent unterstüzt bei der Einrichtung des Routers für das Freifunknetz.")
51 dev = f:field(ListValue, "device", "WLAN-Gerät")
52 uci:foreach("wireless", "wifi-device",
54 dev:value(section[".name"])
58 main = f:field(Flag, "wifi", "Freifunkzugang einrichten")
60 net = f:field(Value, "net", "Freifunk Community", "Mesh Netzbereich")
62 net:depends("wifi", "1")
63 uci:foreach("freifunk", "community", function(s)
64 net:value(s[".name"], "%s (%s)" % {s.name, s.mesh_network or "?"})
67 function net.cfgvalue(self, section)
68 return uci:get("freifunk", "wizard", "net")
70 function net.write(self, section, value)
71 uci:set("freifunk", "wizard", "net", value)
75 meship = f:field(Value, "meship", "Mesh IP Adresse", "Netzweit eindeutige Identifikation")
77 meship:depends("wifi", "1")
78 function meship.cfgvalue(self, section)
79 return uci:get("freifunk", "wizard", "meship")
81 function meship.write(self, section, value)
82 uci:set("freifunk", "wizard", "meship", value)
85 function meship.validate(self, value)
86 local x = ip.IPv4(value)
87 return ( x and x:prefix() == 32 ) and x:string() or ""
90 client = f:field(Flag, "client", "WLAN-DHCP anbieten")
91 client:depends("wifi", "1")
92 client.rmempty = false
93 function client.cfgvalue(self, section)
94 return uci:get("freifunk", "wizard", "dhcp_splash") or "0"
97 olsr = f:field(Flag, "olsr", "OLSR einrichten")
100 lat = f:field(Value, "lat", "Latitude")
101 lat:depends("olsr", "1")
102 function lat.cfgvalue(self, section)
103 return uci:get("freifunk", "wizard", "latitude")
105 function lat.write(self, section, value)
106 uci:set("freifunk", "wizard", "latitude", value)
110 lon = f:field(Value, "lon", "Longitude")
111 lon:depends("olsr", "1")
112 function lon.cfgvalue(self, section)
113 return uci:get("freifunk", "wizard", "longitude")
115 function lon.write(self, section, value)
116 uci:set("freifunk", "wizard", "longitude", value)
120 share = f:field(Flag, "sharenet", "Eigenen Internetzugang freigeben")
123 wansec = f:field(Flag, "wansec", "WAN-Zugriff auf Gateway beschränken")
124 wansec.rmempty = false
125 wansec:depends("sharenet", "1")
126 function wansec.cfgvalue(self, section)
127 return uci:get("freifunk", "wizard", "wan_security")
129 function wansec.write(self, section, value)
130 uci:set("freifunk", "wizard", "wan_security", value)
134 -------------------- Control --------------------
135 function f.handle(self, state, data)
136 if state == FORM_VALID then
137 luci.http.redirect(luci.dispatcher.build_url("admin", "uci", "changes"))
139 elseif state == FORM_INVALID then
140 self.errmessage = "Ungültige Eingabe: Bitte die Formularfelder auf Fehler prüfen."
145 local function _strip_internals(tbl)
147 for k, v in pairs(tbl) do
148 if k:sub(1, 1) == "." then
155 -- Configure Freifunk checked
156 function main.write(self, section, value)
161 local device = dev:formvalue(section)
162 local node_ip, external
164 -- Collect IP-Address
165 local community = net:formvalue(section)
168 if not community then
169 net.tag_missing[section] = true
171 external = uci:get("freifunk", community, "external") or ""
172 network = ip.IPv4(uci:get("freifunk", community, "mesh_network") or "104.0.0.0/8")
173 node_ip = meship:formvalue(section) and ip.IPv4(meship:formvalue(section))
175 if not node_ip or not network or not network:contains(node_ip) then
176 meship.tag_missing[section] = true
181 if not node_ip then return end
185 tools.wifi_delete_ifaces(device)
186 tools.network_remove_interface(device)
187 tools.firewall_zone_remove_interface("freifunk", device)
189 -- Tune community settings
190 if community and uci:get("freifunk", community) then
191 uci:tset("freifunk", "community", uci:get_all("freifunk", community))
195 local devconfig = uci:get_all("freifunk", "wifi_device")
196 util.update(devconfig, uci:get_all(external, "wifi_device") or {})
197 uci:tset("wireless", device, devconfig)
200 local ifconfig = uci:get_all("freifunk", "wifi_iface")
201 util.update(ifconfig, uci:get_all(external, "wifi_iface") or {})
202 ifconfig.device = device
203 ifconfig.network = device
204 ifconfig.ssid = uci:get("freifunk", community, "ssid")
205 uci:section("wireless", "wifi-iface", nil, ifconfig)
210 -- Create firewall zone and add default rules (first time)
211 local newzone = tools.firewall_create_zone("freifunk", "REJECT", "ACCEPT", "REJECT", true)
213 uci:foreach("freifunk", "fw_forwarding", function(section)
214 uci:section("firewall", "forwarding", nil, section)
216 uci:foreach(external, "fw_forwarding", function(section)
217 uci:section("firewall", "forwarding", nil, section)
220 uci:foreach("freifunk", "fw_rule", function(section)
221 uci:section("firewall", "rule", nil, section)
223 uci:foreach(external, "fw_rule", function(section)
224 uci:section("firewall", "rule", nil, section)
228 -- Enforce firewall include
229 local has_include = false
230 uci:foreach("firewall", "include",
232 if section.path == "/etc/firewall.freifunk" then
237 if not has_include then
238 uci:section("firewall", "include", nil,
239 { path = "/etc/firewall.freifunk" })
242 -- Allow state: invalid packets
243 uci:foreach("firewall", "defaults",
245 uci:set("firewall", section[".name"], "drop_invalid", "0")
248 -- Prepare advanced config
249 local has_advanced = false
250 uci:foreach("firewall", "advanced",
251 function(section) has_advanced = true end)
253 if not has_advanced then
254 uci:section("firewall", "advanced", nil,
255 { tcp_ecn = "0", ip_conntrack_max = "8192", tcp_westwood = "1" })
261 -- Create network interface
262 local netconfig = uci:get_all("freifunk", "interface")
263 util.update(netconfig, uci:get_all(external, "interface") or {})
264 netconfig.proto = "static"
265 netconfig.ipaddr = node_ip:string()
266 uci:section("network", "interface", device, netconfig)
270 tools.firewall_zone_add_interface("freifunk", device)
273 local new_hostname = node_ip:string():gsub("%.", "-")
274 local old_hostname = sys.hostname()
276 uci:foreach("system", "system",
279 uci:set("system", s['.name'], "cronloglevel", "10")
282 if old_hostname == "OpenWrt" or old_hostname:match("^%d+-%d+-%d+-%d+$") then
283 uci:set("system", s['.name'], "hostname", new_hostname)
284 sys.hostname(new_hostname)
292 function olsr.write(self, section, value)
298 local device = dev:formvalue(section)
300 local community = net:formvalue(section)
301 local external = community and uci:get("freifunk", community, "external") or ""
303 local latval = tonumber(lat:formvalue(section))
304 local lonval = tonumber(lon:formvalue(section))
307 -- Delete old interface
308 uci:delete_all("olsrd", "Interface", {interface=device})
310 -- Write new interface
311 local olsrbase = uci:get_all("freifunk", "olsr_interface")
312 util.update(olsrbase, uci:get_all(external, "olsr_interface") or {})
313 olsrbase.interface = device
314 olsrbase.ignore = "0"
315 uci:section("olsrd", "Interface", nil, olsrbase)
317 -- Delete old watchdog settings
318 uci:delete_all("olsrd", "LoadPlugin", {library="olsrd_watchdog.so.0.1"})
320 -- Write new watchdog settings
321 uci:section("olsrd", "LoadPlugin", nil, {
322 library = "olsrd_watchdog.so.0.1",
323 file = "/var/run/olsrd.watchdog",
327 -- Delete old nameservice settings
328 uci:delete_all("olsrd", "LoadPlugin", {library="olsrd_nameservice.so.0.3"})
330 -- Write new nameservice settings
331 uci:section("olsrd", "LoadPlugin", nil, {
332 library = "olsrd_nameservice.so.0.3",
334 hosts_file = "/var/etc/hosts.olsr",
335 latlon_file = "/var/run/latlon.js",
336 lat = latval and string.format("%.15f", latval) or "",
337 lon = lonval and string.format("%.15f", lonval) or ""
340 -- Save latlon to system too
341 if latval and lonval then
342 uci:foreach("system", "system", function(s)
343 uci:set("system", s[".name"], "latlon",
344 string.format("%.15f %.15f", latval, lonval))
347 uci:foreach("system", "system", function(s)
348 uci:delete("system", s[".name"], "latlon")
353 uci:foreach("dhcp", "dnsmasq", function(s)
354 uci:set("dhcp", s[".name"], "addnhosts", "/var/etc/hosts.olsr")
357 -- Make sure that OLSR is enabled
358 sys.exec("/etc/init.d/olsrd enable")
365 function share.write(self, section, value)
366 uci:delete_all("firewall", "forwarding", {src="freifunk", dest="wan"})
367 uci:delete_all("olsrd", "LoadPlugin", {library="olsrd_dyn_gw_plain.so.0.4"})
368 uci:foreach("firewall", "zone",
370 if s.name == "wan" then
371 uci:delete("firewall", s['.name'], "local_restrict")
377 uci:section("firewall", "forwarding", nil, {src="freifunk", dest="wan"})
378 uci:section("olsrd", "LoadPlugin", nil, {library="olsrd_dyn_gw_plain.so.0.4"})
380 if wansec:formvalue(section) == "1" then
381 uci:foreach("firewall", "zone",
383 if s.name == "wan" then
384 uci:set("firewall", s['.name'], "local_restrict", "1")
397 function client.write(self, section, value)
399 uci:delete("freifunk", "wizard", "dhcp_splash")
404 local device = dev:formvalue(section)
406 -- Collect IP-Address
407 local node_ip = meship:formvalue(section)
409 if not node_ip then return end
411 local community = net:formvalue(section)
412 local external = community and uci:get("freifunk", community, "external") or ""
413 local splash_ip, splash_mask = mksubnet(community, node_ip)
416 uci:delete("network", device .. "dhcp")
419 local aliasbase = uci:get_all("freifunk", "alias")
420 util.update(aliasbase, uci:get_all(external, "alias") or {})
421 aliasbase.interface = device
422 aliasbase.ipaddr = splash_ip
423 aliasbase.netmask = splash_mask
424 aliasbase.proto = "static"
425 uci:section("network", "alias", device .. "dhcp", aliasbase)
430 local dhcpbase = uci:get_all("freifunk", "dhcp")
431 util.update(dhcpbase, uci:get_all(external, "dhcp") or {})
432 dhcpbase.interface = device .. "dhcp"
433 dhcpbase.start = dhcpbeg
434 dhcpbase.limit = limit
437 uci:section("dhcp", "dhcp", device .. "dhcp", dhcpbase)
440 uci:delete_all("firewall", "rule", {
445 uci:section("firewall", "rule", nil, {
451 uci:delete_all("firewall", "rule", {
457 uci:section("firewall", "rule", nil, {
464 uci:delete_all("firewall", "rule", {
469 uci:section("firewall", "rule", nil, {
479 uci:delete_all("luci_splash", "iface", {network=device.."dhcp", zone="freifunk"})
482 uci:section("luci_splash", "iface", nil, {network=device.."dhcp", zone="freifunk"})
483 uci:save("luci_splash")
485 -- Make sure that luci_splash is enabled
486 sys.exec("/etc/init.d/luci_splash enable")
489 uci:set("freifunk", "wizard", "dhcp_splash", "1")