2 # dns based ad/abuse domain blocking script
3 # written by Dirk Brenken (dev@brenken.org)
5 # This is free software, licensed under the GNU General Public License v3.
6 # You should have received a copy of the GNU General Public License
7 # along with this program. If not, see <http://www.gnu.org/licenses/>.
16 adb_pidfile
="/var/run/adblock.pid"
17 adb_log
="$(which logger)"
19 if [ -r "${adb_pidfile}" ]
22 "${adb_log}" -s -t "adblock[${adb_pid}] error" "adblock service already running ($(cat ${adb_pidfile}))"
25 printf "${adb_pid}" > "${adb_pidfile}"
28 # get current directory and set script/config version
30 adb_scriptdir
="${0%/*}"
34 # source in adblock function library
36 if [ -r "${adb_scriptdir}/adblock-helper.sh" ]
38 .
"${adb_scriptdir}/adblock-helper.sh"
41 "${adb_log}" -s -t "adblock[${adb_pid}] error" "adblock function library not found"
42 rm -f "${adb_pidfile}"
46 # call trap function on error signals (HUP, INT, QUIT, BUS, SEGV, TERM)
48 trap "rc=250; f_log 'error signal received/trapped' '${rc}'; f_exit" 1 2 3 10 11 15
56 f_log
"domain adblock processing started (${adb_scriptver}, ${adb_sysver}, $(/bin/date "+%d.
%m.
%Y
%H
:%M
:%S
"))"
62 # loop through active adblock domain sources,
63 # download sources, prepare output and store all extracted domains in temp file
65 for src_name
in ${adb_sources}
67 eval "url=\"\${adb_src_${src_name}}\""
68 eval "src_rset=\"\${adb_src_rset_${src_name}}\""
69 adb_dnsfile
="${adb_dnsdir}/${adb_dnsprefix}.${src_name}"
70 list_time
="$(${adb_uci} -q get "adblock.
${src_name}.adb_src_timestamp
")"
71 f_log
"=> processing adblock source '${src_name}'"
73 # check 'url' and 'src_rset' values
75 if [ -z "${url}" ] ||
[ -z "${src_rset}" ]
77 "${adb_uci}" -q set "adblock.${src_name}.adb_src_timestamp=broken config"
78 f_log
" broken source configuration, check 'adb_src' and 'adb_src_rset' in config"
82 # prepare find statement with active adblock list sources
84 if [ -z "${adb_srclist}" ]
86 adb_srclist
="! -name ${adb_dnsprefix}.${src_name}*"
88 adb_srclist
="${adb_srclist} -a ! -name ${adb_dnsprefix}.${src_name}*"
91 # download only block list with newer/updated timestamp
93 if [ "${src_name}" = "blacklist" ]
95 url_time
="$(date -r "${url}")"
97 url_time
="$(${adb_fetch} ${fetch_parm} --server-response --spider "${url}" 2>&1 | awk '$0 ~ /Last-Modified/ {printf substr($0,18)}')"
99 if [ -z "${url_time}" ]
102 f_log
" online timestamp not received, current date will be used"
104 if [ -z "${list_time}" ] || [ "${list_time}" != "${url_time}" ] || [ ! -r "${adb_dnsfile}" ] ||\
105 ([ "${backup_ok}" = "true" ] && [ ! -r "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz" ])
107 if [ "${src_name}" = "blacklist" ]
109 tmp_domains
="$(cat "${url}")"
110 elif [ "${src_name}" = "shalla" ]
112 shalla_archive
="${adb_tmpdir}/shallalist.tar.gz"
113 shalla_file
="${adb_tmpdir}/shallalist.txt"
114 "${adb_fetch}" ${fetch_parm} --output-document="${shalla_archive}" "${url}"
119 for category
in ${adb_src_cat_shalla}
121 tar -xOzf "${shalla_archive}" BL/${category}/domains >> "${shalla_file}"
125 f_log
" archive extraction failed (${category})"
129 tmp_domains
="$(cat "${shalla_file}")"
130 rm -rf "${adb_tmpdir}/BL"
131 rm -f "${shalla_archive}"
132 rm -f "${shalla_file}"
135 tmp_domains
="$(${adb_fetch} ${fetch_parm} --output-document=- "${url}")"
139 f_log " source doesn
't change, no update required"
143 # check download result and prepare domain output, backup/restore if needed
145 if [ $((rc)) -eq 0 ] && [ -n "${tmp_domains}" ]
147 count="$(printf "%s\n" "${tmp_domains}" | awk "${src_rset}" | tee "${adb_tmpfile}" | wc -l)"
148 "${adb_uci}" -q set "adblock.${src_name}.adb_src_timestamp=${url_time}"
149 if [ "${backup_ok}" = "true" ]
151 gzip -cf "${adb_tmpfile}" > "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz"
153 f_log " source download finished (${count} entries)"
155 elif [ $((rc)) -eq 0 ] && [ -z "${tmp_domains}" ]
157 "${adb_uci}" -q set "adblock.${src_name}.adb_src_timestamp=empty download"
158 f_log " empty source download finished"
162 if [ "${backup_ok}" = "true" ] && [ -r "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz" ]
164 gunzip -cf "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz" > "${adb_tmpfile}"
165 count="$(wc -l < "${adb_tmpfile}")"
166 "${adb_uci}" -q set "adblock.${src_name}.adb_src_timestamp=list restored"
167 f_log " source download failed, list restored (${count} entries)"
169 "${adb_uci}" -q set "adblock.${src_name}.adb_src_timestamp=download failed"
170 f_log " source download failed"
175 # remove whitelist domains, sort domains and make them unique,
176 # rewrite ad/abuse domain information to separate dnsmasq files
178 if [ $((count)) -gt 0 ] && [ -n "${adb_tmpfile}" ]
180 if [ -s "${adb_tmpdir}/tmp.whitelist" ]
182 grep -vf "${adb_tmpdir}/tmp.whitelist" "${adb_tmpfile}" | sort -u | eval "${adb_dnsformat}" > "${adb_dnsfile}"
184 sort -u "${adb_tmpfile}" | eval "${adb_dnsformat}" > "${adb_dnsfile}"
188 # finish domain processing, prepare find statement with revised adblock list source
192 if [ -z "${adb_revsrclist}" ]
194 adb_revsrclist="-name ${adb_dnsprefix}.${src_name}"
196 adb_revsrclist="${adb_revsrclist} -o -name ${adb_dnsprefix}.${src_name}"
198 f_log " domain merging finished"
201 rm -f "${adb_dnsfile}"
202 if [ "${backup_ok}" = "true" ] && [ -r "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz" ]
204 rm -f "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz"
206 f_log " domain merging failed, list removed"
210 rm -f "${adb_dnsfile}"
211 if [ "${backup_ok}" = "true" ] && [ -r "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz" ]
213 rm -f "${adb_dir_backup}/${adb_dnsprefix}.${src_name}.gz"
215 "${adb_uci}" -q set "adblock.${src_name}.adb_src_timestamp=empty domain input"
216 f_log " empty domain input received, list removed"
221 # remove disabled adblock lists and their backups
223 if [ -n "${adb_srclist}" ]
225 rm_done="$(find "${adb_dnsdir}" -maxdepth 1 -type f \( ${adb_srclist} \) -print -exec rm -f "{}" \;)"
226 if [ "${backup_ok}" = "true" ] && [ -n "${rm_done}" ]
228 find "${adb_dir_backup}" -maxdepth 1 -type f \( ${adb_srclist} \) -exec rm -f "{}" \;
231 rm_done="$(find "${adb_dnsdir}" -maxdepth 1 -type f -name "${adb_dnsprefix}*" -print -exec rm -f "{}" \;)"
232 if [ "${backup_ok}" = "true" ]
234 find "${adb_dir_backup}" -maxdepth 1 -type f -name "${adb_dnsprefix}*" -exec rm -f "{}" \;
237 if [ -n "${rm_done}" ]
239 f_rmconfig "${rm_done}"
240 f_log "disabled adblock lists removed"
243 # make separate adblock lists entries unique
245 if [ "${mem_ok}" = "true" ] && [ -n "${adb_revsrclist}" ]
247 f_log "remove duplicates in separate adblock lists"
249 # generate a unique overall block list
251 sort -u "${adb_dnsdir}/${adb_dnsprefix}."* > "${adb_tmpdir}/blocklist.overall"
253 # loop through all separate lists, ordered by size (ascending)
255 for list in $(ls -ASr "${adb_dnsdir}/${adb_dnsprefix}"*)
257 # check overall block list vs. separate block list,
258 # write all duplicate entries to separate list
261 sort "${adb_tmpdir}/blocklist.overall" "${adb_dnsdir}/${adb_dnsprefix}.${list}" | uniq -d > "${adb_tmpdir}/tmp.${list}"
262 mv -f "${adb_tmpdir}/tmp.${list}" "${adb_dnsdir}/${adb_dnsprefix}.${list}"
264 # write all unique entries back to overall block list
266 sort "${adb_tmpdir}/blocklist.overall" "${adb_dnsdir}/${adb_dnsprefix}.${list}" | uniq -u > "${adb_tmpdir}/tmp.overall"
267 mv -f "${adb_tmpdir}/tmp.overall" "${adb_tmpdir}/blocklist.overall"
269 rm -f "${adb_tmpdir}/blocklist.overall"
272 # restart & check dnsmasq with newly generated set of adblock lists
275 adb_count="$(${adb_uci} -q get "adblock.global.adb_overall_count")"
276 if [ -n "${adb_revsrclist}" ] || [ -n "${rm_done}" ]
278 "${adb_uci}" -q set "adblock.global.adb_dnstoggle=on"
279 /etc/init.d/dnsmasq restart
281 check="$(pgrep -f "dnsmasq")"
284 f_log "adblock lists with overall ${adb_count} domains loaded"
286 f_log "dnsmasq restart failed, retry without newly generated block lists"
287 rm_done="$(find "${adb_dnsdir}" -maxdepth 1 -type f \( ${adb_revsrclist} \) -print -exec rm -f "{}" \;)"
288 if [ -n "${rm_done}" ]
290 f_log "bogus adblock lists removed"
291 f_rmconfig "${rm_done}"
292 /etc/init.d/dnsmasq restart
294 check="$(pgrep -f "dnsmasq")"
298 f_log "adblock lists with overall ${adb_count} domains loaded"
301 f_log "dnsmasq restart failed, please check 'logread
' output" "${rc}"
307 f_log "adblock lists with overall ${adb_count} domains are still valid, no update required"
310 # remove temporary files and exit