2 # map.sh - IPv4-in-IPv6 tunnel backend
4 # Author: Steven Barth <cyrus@openwrt.org>
5 # Copyright (c) 2014 cisco Systems, Inc.
7 # This program is free software; you can redistribute it and/or modify
8 # it under the terms of the GNU General Public License version 2
9 # as published by the Free Software Foundation
11 # This program is distributed in the hope that it will be useful,
12 # but WITHOUT ANY WARRANTY; without even the implied warranty of
13 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 # GNU General Public License for more details.
16 [ -n "$INCLUDE_ONLY" ] ||
{
18 .
/lib
/functions
/network.sh
28 # uncomment for legacy MAP0 mode
31 local type mtu ttl tunlink zone
32 local rule ipaddr ip4prefixlen ip6prefix ip6prefixlen peeraddr ealen psidlen psid offset
33 json_get_vars
type mtu ttl tunlink zone
34 json_get_vars rule ipaddr ip4prefixlen ip6prefix ip6prefixlen peeraddr ealen psidlen psid offset
36 [ -z "$zone" ] && zone
="wan"
37 [ -z "$type" ] && type="map-e"
38 [ -z "$ip4prefixlen" ] && ip4prefixlen
=32
40 ( proto_add_host_dependency
"$cfg" "::" "$tunlink" )
42 # fixme: handle RA/DHCPv6 address race for LW
43 [ "$type" = lw4o6
] && sleep 5
45 if [ -z "$rule" ]; then
46 rule
="type=$type,ipv6prefix=$ip6prefix,prefix6len=$ip6prefixlen,ipv4prefix=$ipaddr,prefix4len=$ip4prefixlen"
47 [ -n "$psid" ] && rule
="$rule,psid=$psid"
48 [ -n "$psidlen" ] && rule
="$rule,psidlen=$psidlen"
49 [ -n "$offset" ] && rule
="$rule,offset=$offset"
50 [ -n "$ealen" ] && rule
="$rule,ealen=$ealen"
51 if [ "$type" = "map-t" ]; then
52 rule
="$rule,dmr=$peeraddr"
54 rule
="$rule,br=$peeraddr"
58 echo "rule=$rule" > /tmp
/map-
$cfg.rules
59 RULE_DATA
=$
(mapcalc
${tunlink:-\*} $rule)
60 if [ "$?" != 0 ]; then
61 proto_notify_error
"$cfg" "INVALID_MAP_RULE"
62 proto_block_restart
"$cfg"
66 echo "$RULE_DATA" >> /tmp
/map-
$cfg.rules
69 if [ -z "$RULE_BMR" ]; then
70 proto_notify_error
"$cfg" "NO_MATCHING_PD"
71 proto_block_restart
"$cfg"
76 if [ "$type" = "lw4o6" -o "$type" = "map-e" ]; then
77 proto_init_update
"$link" 1
78 proto_add_ipv4_address $
(eval "echo \$RULE_${k}_IPV4ADDR") "" "" ""
81 json_add_string mode ipip6
82 json_add_int mtu
"${mtu:-1280}"
83 json_add_int ttl
"${ttl:-64}"
84 json_add_string
local $
(eval "echo \$RULE_${k}_IPV6ADDR")
85 json_add_string remote $
(eval "echo \$RULE_${k}_BR")
86 json_add_string link $
(eval "echo \$RULE_${k}_PD6IFACE")
88 if [ "$type" = "map-e" ]; then
89 json_add_object
"data"
91 for i
in $
(seq $RULE_COUNT); do
92 [ "$(eval "echo \
$RULE_${i}_FMR
")" != 1 ] && continue
94 json_add_string prefix6
"$(eval "echo \
$RULE_${i}_IPV6PREFIX
")/$(eval "echo \
$RULE_${i}_PREFIX6LEN
")"
95 json_add_string prefix4
"$(eval "echo \
$RULE_${i}_IPV4PREFIX
")/$(eval "echo \
$RULE_${i}_PREFIX4LEN
")"
96 json_add_int ealen $
(eval "echo \$RULE_${i}_EALEN")
97 json_add_int offset $
(eval "echo \$RULE_${i}_OFFSET")
105 elif [ "$type" = "map-t" -a -f "/proc/net/nat46/control" ]; then
106 proto_init_update
"$link" 1
108 [ "$LEGACY" = 1 ] && style
="MAP0"
110 echo add
$link > /proc
/net
/nat46
/control
111 local cfgstr
="local.style $style local.v4 $(eval "echo \
$RULE_${k}_IPV4PREFIX
")/$(eval "echo \
$RULE_${k}_PREFIX4LEN
")"
112 cfgstr
="$cfgstr local.v6 $(eval "echo \
$RULE_${k}_IPV6PREFIX
")/$(eval "echo \
$RULE_${k}_PREFIX6LEN
")"
113 cfgstr
="$cfgstr local.ea-len $(eval "echo \
$RULE_${k}_EALEN
") local.psid-offset $(eval "echo \
$RULE_${k}_OFFSET
")"
114 cfgstr
="$cfgstr remote.v4 0.0.0.0/0 remote.v6 $(eval "echo \
$RULE_${k}_DMR
") remote.style RFC6052 remote.ea-len 0 remote.psid-offset 0"
115 echo config
$link $cfgstr > /proc
/net
/nat46
/control
117 for i
in $
(seq $RULE_COUNT); do
118 [ "$(eval "echo \
$RULE_${i}_FMR
")" != 1 ] && continue
119 local cfgstr
="remote.style $style remote.v4 $(eval "echo \
$RULE_${i}_IPV4PREFIX
")/$(eval "echo \
$RULE_${i}_PREFIX4LEN
")"
120 cfgstr
="$cfgstr remote.v6 $(eval "echo \
$RULE_${i}_IPV6PREFIX
")/$(eval "echo \
$RULE_${i}_PREFIX6LEN
")"
121 cfgstr
="$cfgstr remote.ea-len $(eval "echo \
$RULE_${i}_EALEN
") remote.psid-offset $(eval "echo \
$RULE_${i}_OFFSET
")"
122 echo insert
$link $cfgstr > /proc
/net
/nat46
/control
125 proto_notify_error
"$cfg" "UNSUPPORTED_TYPE"
126 proto_block_restart
"$cfg"
129 proto_add_ipv4_route
"0.0.0.0" 0
131 [ "$zone" != "-" ] && json_add_string zone
"$zone"
133 json_add_array firewall
134 if [ -z "$(eval "echo \
$RULE_${k}_PORTSETS
")" ]; then
136 json_add_string
type nat
137 json_add_string target SNAT
138 json_add_string family inet
139 json_add_string snat_ip $
(eval "echo \$RULE_${k}_IPV4ADDR")
142 for portset
in $
(eval "echo \$RULE_${k}_PORTSETS"); do
143 for proto
in icmp tcp udp
; do
145 json_add_string
type nat
146 json_add_string target SNAT
147 json_add_string family inet
148 json_add_string proto
"$proto"
149 json_add_boolean connlimit_ports
1
150 json_add_string snat_ip $
(eval "echo \$RULE_${k}_IPV4ADDR")
151 json_add_string snat_port
"$portset"
156 if [ "$type" = "map-t" ]; then
158 json_add_string
type rule
159 json_add_string family inet6
160 json_add_string proto all
161 json_add_string direction
in
162 json_add_string dest
"$zone"
163 json_add_string src
"$zone"
164 json_add_string src_ip $
(eval "echo \$RULE_${k}_IPV6ADDR")
165 json_add_string target ACCEPT
168 json_add_string
type rule
169 json_add_string family inet6
170 json_add_string proto all
171 json_add_string direction out
172 json_add_string dest
"$zone"
173 json_add_string src
"$zone"
174 json_add_string dest_ip $
(eval "echo \$RULE_${k}_IPV6ADDR")
175 json_add_string target ACCEPT
177 proto_add_ipv6_route $
(eval "echo \$RULE_${k}_IPV6ADDR") 128
182 proto_send_update
"$cfg"
184 if [ "$type" = "lw4o6" -o "$type" = "map-e" ]; then
186 json_add_string name
"${cfg}_"
187 json_add_string ifname
"@$(eval "echo \
$RULE_${k}_PD6IFACE
")"
188 json_add_string proto
"static"
189 json_add_array ip6addr
190 json_add_string
"" "$(eval "echo \
$RULE_${k}_IPV6ADDR
")"
193 ubus call network add_dynamic
"$(json_dump)"
197 proto_map_teardown
() {
199 local link
="map-$cfg"
201 json_get_var
type type
203 [ -z "$type" ] && type="map-e"
206 "map-e"|
"lw4o6") ifdown
"${cfg}_" ;;
207 "map-t") [ -f "/proc/net/nat46/control" ] && echo del
$link > /proc
/net
/nat46
/control
;;
210 rm -f /tmp
/map-
$cfg.rules
213 proto_map_init_config
() {
217 proto_config_add_string
"rule"
218 proto_config_add_string
"ipaddr"
219 proto_config_add_int
"ip4prefixlen"
220 proto_config_add_string
"ip6prefix"
221 proto_config_add_int
"ip6prefixlen"
222 proto_config_add_string
"peeraddr"
223 proto_config_add_int
"ealen"
224 proto_config_add_int
"psidlen"
225 proto_config_add_int
"psid"
226 proto_config_add_int
"offset"
228 proto_config_add_string
"tunlink"
229 proto_config_add_int
"mtu"
230 proto_config_add_int
"ttl"
231 proto_config_add_string
"zone"
234 [ -n "$INCLUDE_ONLY" ] ||
{