dnsmasq: add config option for connmark DNS filtering
[openwrt/staging/hauke.git] / package / network / services / dnsmasq / files / dnsmasq.init
1 #!/bin/sh /etc/rc.common
2 # Copyright (C) 2007-2012 OpenWrt.org
3
4 START=19
5
6 USE_PROCD=1
7 PROG=/usr/sbin/dnsmasq
8
9 ADD_LOCAL_DOMAIN=1
10 ADD_LOCAL_HOSTNAME=1
11 ADD_WAN_FQDN=0
12 ADD_LOCAL_FQDN=""
13
14 BASECONFIGFILE="/var/etc/dnsmasq.conf"
15 BASEHOSTFILE="/tmp/hosts/dhcp"
16 TRUSTANCHORSFILE="/usr/share/dnsmasq/trust-anchors.conf"
17 TIMEVALIDFILE="/var/state/dnsmasqsec"
18 BASEDHCPSTAMPFILE="/var/run/dnsmasq"
19 DHCPBOGUSHOSTNAMEFILE="/usr/share/dnsmasq/dhcpbogushostname.conf"
20 RFC6761FILE="/usr/share/dnsmasq/rfc6761.conf"
21 DHCPSCRIPT="/usr/lib/dnsmasq/dhcp-script.sh"
22
23 DNSMASQ_DHCP_VER=4
24
25 dnsmasq_ignore_opt() {
26 local opt="$1"
27
28 if [ -z "$dnsmasq_features" ]; then
29 dnsmasq_features="$(dnsmasq --version | grep -m1 'Compile time options:' | cut -d: -f2) "
30 [ "${dnsmasq_features#* DHCP }" = "$dnsmasq_features" ] || dnsmasq_has_dhcp=1
31 [ "${dnsmasq_features#* DHCPv6 }" = "$dnsmasq_features" ] || dnsmasq_has_dhcp6=1
32 [ "${dnsmasq_features#* DNSSEC }" = "$dnsmasq_features" ] || dnsmasq_has_dnssec=1
33 [ "${dnsmasq_features#* TFTP }" = "$dnsmasq_features" ] || dnsmasq_has_tftp=1
34 [ "${dnsmasq_features#* ipset }" = "$dnsmasq_features" ] || dnsmasq_has_ipset=1
35 fi
36
37 case "$opt" in
38 dhcp-duid|\
39 ra-param)
40 [ -z "$dnsmasq_has_dhcp6" ] ;;
41 dhcp-*|\
42 bootp-*|\
43 pxe-*)
44 [ -z "$dnsmasq_has_dhcp" ] ;;
45 dnssec*|\
46 trust-anchor)
47 if [ -z "$dnsmasq_has_dnssec" ]; then
48 echo "dnsmasq: \"$opt\" requested, but dnssec support is not available" >&2
49 exit 1
50 fi
51 return 1
52 ;;
53 tftp-*)
54 [ -z "$dnsmasq_has_tftp" ] ;;
55 ipset)
56 [ -z "$dnsmasq_has_ipset" ] ;;
57 *)
58 return 1
59 esac
60 }
61
62 xappend() {
63 local value="${1#--}"
64 local opt="${value%%=*}"
65
66 if ! dnsmasq_ignore_opt "$opt"; then
67 echo "$value" >>$CONFIGFILE_TMP
68 fi
69 }
70
71 hex_to_hostid() {
72 local var="$1"
73 local hex="${2#0x}" # strip optional "0x" prefix
74
75 if [ -n "${hex//[0-9a-fA-F]/}" ]; then
76 # is invalid hex literal
77 return 1
78 fi
79
80 # convert into host id
81 export "$var=$(
82 printf "%0x:%0x" \
83 $(((0x$hex >> 16) % 65536)) \
84 $(( 0x$hex % 65536))
85 )"
86
87 return 0
88 }
89
90 dhcp_calc() {
91 local ip="$1"
92 local res=0
93
94 while [ -n "$ip" ]; do
95 part="${ip%%.*}"
96 res="$(($res * 256))"
97 res="$(($res + $part))"
98 [ "${ip%.*}" != "$ip" ] && ip="${ip#*.}" || ip=
99 done
100 echo "$res"
101 }
102
103 dhcp_check() {
104 local ifname="$1"
105 local stamp="${BASEDHCPSTAMPFILE_CFG}.${ifname}.dhcp"
106 local rv=0
107
108 [ -s "$stamp" ] && return $(cat "$stamp")
109
110 # If interface is down, skip it.
111 # The init script will be called again once the link is up
112 case "$(devstatus "$ifname" | jsonfilter -e @.up)" in
113 false) return 1;;
114 esac
115
116 udhcpc -n -q -s /bin/true -t 1 -i "$ifname" >&- && rv=1 || rv=0
117
118 echo $rv > "$stamp"
119 return $rv
120 }
121
122 log_once() {
123 pidof dnsmasq >/dev/null || \
124 logger -t dnsmasq "$@"
125 }
126
127 has_handler() {
128 local file
129
130 for file in /etc/hotplug.d/dhcp/* /etc/hotplug.d/tftp/* /etc/hotplug.d/neigh/*; do
131 [ -f "$file" ] && return 0
132 done
133
134 return 1
135 }
136
137 append_bool() {
138 local section="$1"
139 local option="$2"
140 local value="$3"
141 local default="$4"
142 local _loctmp
143 [ -z "$default" ] && default="0"
144 config_get_bool _loctmp "$section" "$option" "$default"
145 [ $_loctmp -gt 0 ] && xappend "$value"
146 }
147
148 append_parm() {
149 local section="$1"
150 local option="$2"
151 local switch="$3"
152 local default="$4"
153 local _loctmp
154 config_get _loctmp "$section" "$option" "$default"
155 [ -z "$_loctmp" ] && return 0
156 xappend "$switch=$_loctmp"
157 }
158
159 append_server() {
160 xappend "--server=$1"
161 }
162
163 append_rev_server() {
164 xappend "--rev-server=$1"
165 }
166
167 append_address() {
168 xappend "--address=$1"
169 }
170
171 append_ipset() {
172 xappend "--ipset=$1"
173 }
174
175 append_connmark_allowlist() {
176 xappend "--connmark-allowlist=$1"
177 }
178
179 append_interface() {
180 network_get_device ifname "$1" || ifname="$1"
181 xappend "--interface=$ifname"
182 }
183
184 append_listenaddress() {
185 xappend "--listen-address=$1"
186 }
187
188 append_notinterface() {
189 network_get_device ifname "$1" || ifname="$1"
190 xappend "--except-interface=$ifname"
191 }
192
193 append_addnhosts() {
194 xappend "--addn-hosts=$1"
195 }
196
197 append_bogusnxdomain() {
198 xappend "--bogus-nxdomain=$1"
199 }
200
201 append_pxe_service() {
202 xappend "--pxe-service=$1"
203 }
204
205 append_interface_name() {
206 xappend "--interface-name=$1,$2"
207 }
208
209 filter_dnsmasq() {
210 local cfg="$1" func="$2" match_cfg="$3" found_cfg
211
212 # use entry when no instance entry set, or if it matches
213 config_get found_cfg "$cfg" "instance"
214 if [ -z "$found_cfg" ] || [ "$found_cfg" = "$match_cfg" ]; then
215 $func $cfg
216 fi
217 }
218
219 dhcp_subscrid_add() {
220 local cfg="$1"
221
222 config_get networkid "$cfg" networkid
223 [ -n "$networkid" ] || return 0
224
225 config_get subscriberid "$cfg" subscriberid
226 [ -n "$subscriberid" ] || return 0
227
228 xappend "--dhcp-subscrid=$networkid,$subscriberid"
229
230 config_get_bool force "$cfg" force 0
231
232 dhcp_option_add "$cfg" "$networkid" "$force"
233 }
234
235 dhcp_remoteid_add() {
236 local cfg="$1"
237
238 config_get networkid "$cfg" networkid
239 [ -n "$networkid" ] || return 0
240
241 config_get remoteid "$cfg" remoteid
242 [ -n "$remoteid" ] || return 0
243
244 xappend "--dhcp-remoteid=$networkid,$remoteid"
245
246 config_get_bool force "$cfg" force 0
247
248 dhcp_option_add "$cfg" "$networkid" "$force"
249 }
250
251 dhcp_circuitid_add() {
252 # TODO: DHCPV6 does not have circuitid; catch "option6:"
253 local cfg="$1"
254
255 config_get networkid "$cfg" networkid
256 [ -n "$networkid" ] || return 0
257
258 config_get circuitid "$cfg" circuitid
259 [ -n "$circuitid" ] || return 0
260
261 xappend "--dhcp-circuitid=$networkid,$circuitid"
262
263 config_get_bool force "$cfg" force 0
264
265 dhcp_option_add "$cfg" "$networkid" "$force"
266 }
267
268 dhcp_userclass_add() {
269 local cfg="$1"
270
271 config_get networkid "$cfg" networkid
272 [ -n "$networkid" ] || return 0
273
274 config_get userclass "$cfg" userclass
275 [ -n "$userclass" ] || return 0
276
277 xappend "--dhcp-userclass=$networkid,$userclass"
278
279 config_get_bool force "$cfg" force 0
280
281 dhcp_option_add "$cfg" "$networkid" "$force"
282 }
283
284 dhcp_vendorclass_add() {
285 # TODO: DHCPV6 vendor class has stricter definitions; catch? fixup?
286 local cfg="$1"
287
288 config_get networkid "$cfg" networkid
289 [ -n "$networkid" ] || return 0
290
291 config_get vendorclass "$cfg" vendorclass
292 [ -n "$vendorclass" ] || return 0
293
294 xappend "--dhcp-vendorclass=$networkid,$vendorclass"
295
296 config_get_bool force "$cfg" force 0
297
298 dhcp_option_add "$cfg" "$networkid" "$force"
299 }
300
301 dhcp_match_add() {
302 local cfg="$1"
303
304 config_get networkid "$cfg" networkid
305 [ -n "$networkid" ] || return 0
306
307 config_get match "$cfg" match
308 [ -n "$match" ] || return 0
309
310 xappend "--dhcp-match=$networkid,$match"
311
312 config_get_bool force "$cfg" force 0
313
314 dhcp_option_add "$cfg" "$networkid" "$force"
315 }
316
317 dhcp_host_add() {
318 local cfg="$1"
319 local hosttag nametime addrs duids macs tags
320
321 config_get_bool force "$cfg" force 0
322
323 config_get networkid "$cfg" networkid
324 [ -n "$networkid" ] && dhcp_option_add "$cfg" "$networkid" "$force"
325
326 config_get_bool enable "$cfg" enable 1
327 [ "$enable" = "0" ] && return 0
328
329 config_get name "$cfg" name
330 config_get ip "$cfg" ip
331 config_get hostid "$cfg" hostid
332
333 [ -z "$ip" ] && [ -z "$name" ] && [ -z "$hostid" ] && return 0
334
335 config_get_bool dns "$cfg" dns 0
336 [ "$dns" = "1" ] && [ -n "$ip" ] && [ -n "$name" ] && {
337 echo "$ip $name${DOMAIN:+.$DOMAIN}" >> $HOSTFILE_TMP
338 }
339
340 config_get mac "$cfg" mac
341 config_get duid "$cfg" duid
342 config_get tag "$cfg" tag
343
344 if [ -n "$mac" ]; then
345 # --dhcp-host=00:20:e0:3b:13:af,192.168.0.199,lap
346 # many MAC are possible to track a laptop ON/OFF dock
347 for m in $mac; do append macs "$m" ","; done
348 fi
349
350 if [ $DNSMASQ_DHCP_VER -eq 6 ] && [ -n "$duid" ]; then
351 # --dhcp-host=id:00:03:00:01:12:00:00:01:02:03,[::beef],lap
352 # one (virtual) machine gets one DUID per RFC3315
353 duids="id:${duid// */}"
354 fi
355
356 if [ -z "$macs" ] && [ -z "$duids" ]; then
357 # --dhcp-host=lap,192.168.0.199,[::beef]
358 [ -n "$name" ] || return 0
359 macs="$name"
360 name=""
361 fi
362
363 if [ -n "$hostid" ]; then
364 hex_to_hostid hostid "$hostid"
365 fi
366
367 if [ -n "$tag" ]; then
368 for t in $tag; do append tags "$t" ",set:"; done
369 fi
370
371 config_get_bool broadcast "$cfg" broadcast 0
372 config_get leasetime "$cfg" leasetime
373
374 [ "$broadcast" = "0" ] && broadcast= || broadcast=",set:needs-broadcast"
375
376 hosttag="${networkid:+,set:${networkid}}${tags:+,set:${tags}}$broadcast"
377 nametime="${name:+,$name}${leasetime:+,$leasetime}"
378
379 if [ $DNSMASQ_DHCP_VER -eq 6 ]; then
380 addrs="${ip:+,$ip}${hostid:+,[::$hostid]}"
381 xappend "--dhcp-host=$macs${duids:+,$duids}$hosttag$addrs$nametime"
382 else
383 xappend "--dhcp-host=$macs$hosttag${ip:+,$ip}$nametime"
384 fi
385 }
386
387 dhcp_this_host_add() {
388 local net="$1"
389 local ifname="$2"
390 local mode="$3"
391 local routerstub routername ifdashname
392 local lanaddr lanaddr6 lanaddrs6 ulaprefix
393
394 if [ "$mode" -gt 0 ] ; then
395 ifdashname="${ifname//./-}"
396 routerstub="$( md5sum /etc/os-release )"
397 routerstub="router-${routerstub// */}"
398 routername="$( uci_get system @system[0] hostname $routerstub )"
399
400 if [ "$mode" -gt 1 ] ; then
401 if [ "$mode" -gt 2 ] ; then
402 if [ "$mode" -gt 3 ] ; then
403 append_interface_name "$ifdashname.$routername.$DOMAIN" "$ifname"
404 fi
405
406 append_interface_name "$routername.$DOMAIN" "$ifname"
407 fi
408
409 # All IP addresses discovered by dnsmasq will be labeled (except fe80::)
410 append_interface_name "$routername" "$ifname"
411
412 else
413 # This uses a static host file entry for only limited addresses.
414 # Use dnsmasq option "--expandhosts" to enable FQDN on host files.
415 ulaprefix="$(uci_get network @globals[0] ula_prefix)"
416 network_get_ipaddr lanaddr "$net"
417 network_get_ipaddrs6 lanaddrs6 "$net"
418
419 if [ -n "$lanaddr" ] ; then
420 dhcp_domain_add "" "$routername" "$lanaddr"
421 fi
422
423 if [ -n "$ulaprefix" ] && [ -n "$lanaddrs6" ] ; then
424 for lanaddr6 in $lanaddrs6 ; do
425 case "$lanaddr6" in
426 "${ulaprefix%%:/*}"*)
427 dhcp_domain_add "" "$routername" "$lanaddr6"
428 ;;
429 esac
430 done
431 fi
432 fi
433 fi
434 }
435
436 dhcp_tag_add() {
437 # NOTE: dnsmasq has explicit "option6:" prefix for DHCPv6 so no collisions
438 local cfg="$1"
439
440 tag="$cfg"
441
442 [ -n "$tag" ] || return 0
443
444 config_get_bool force "$cfg" force 0
445 [ "$force" = "0" ] && force=
446
447 config_get option "$cfg" dhcp_option
448 for o in $option; do
449 xappend "--dhcp-option${force:+-force}=tag:$tag,$o"
450 done
451 }
452
453 dhcp_mac_add() {
454 local cfg="$1"
455
456 config_get networkid "$cfg" networkid
457 [ -n "$networkid" ] || return 0
458
459 config_get mac "$cfg" mac
460 [ -n "$mac" ] || return 0
461
462 xappend "--dhcp-mac=$networkid,$mac"
463
464 dhcp_option_add "$cfg" "$networkid"
465 }
466
467 dhcp_boot_add() {
468 # TODO: BOOTURL is different between DHCPv4 and DHCPv6
469 local cfg="$1"
470
471 config_get networkid "$cfg" networkid
472
473 config_get filename "$cfg" filename
474 [ -n "$filename" ] || return 0
475
476 config_get servername "$cfg" servername
477 config_get serveraddress "$cfg" serveraddress
478
479 [ -n "$serveraddress" ] && [ ! -n "$servername" ] && return 0
480
481 xappend "--dhcp-boot=${networkid:+net:$networkid,}${filename}${servername:+,$servername}${serveraddress:+,$serveraddress}"
482
483 config_get_bool force "$cfg" force 0
484
485 dhcp_option_add "$cfg" "$networkid" "$force"
486 }
487
488
489 dhcp_add() {
490 local cfg="$1"
491 local dhcp6range="::"
492 local nettag
493 local tags
494
495 config_get net "$cfg" interface
496 [ -n "$net" ] || return 0
497
498 config_get networkid "$cfg" networkid
499 [ -n "$networkid" ] || networkid="$net"
500
501 network_get_device ifname "$net" || return 0
502
503 [ "$cachelocal" = "0" ] && network_get_dnsserver dnsserver "$net" && {
504 DNS_SERVERS="$DNS_SERVERS $dnsserver"
505 }
506
507 append_bool "$cfg" ignore "--no-dhcp-interface=$ifname" && {
508 # Many ISP do not have useful names for DHCP customers (your WAN).
509 dhcp_this_host_add "$net" "$ifname" "$ADD_WAN_FQDN"
510 return 0
511 }
512
513 network_get_subnet subnet "$net" || return 0
514 network_get_protocol proto "$net" || return 0
515
516 # Do not support non-static interfaces for now
517 [ static = "$proto" ] || return 0
518
519 # Override interface netmask with dhcp config if applicable
520 config_get netmask "$cfg" netmask "${subnet##*/}"
521
522 #check for an already active dhcp server on the interface, unless 'force' is set
523 config_get_bool force "$cfg" force 0
524 [ $force -gt 0 ] || dhcp_check "$ifname" || {
525 logger -t dnsmasq \
526 "found already running DHCP-server on interface '$ifname'" \
527 "refusing to start, use 'option force 1' to override"
528 return 0
529 }
530
531 config_get start "$cfg" start 100
532 config_get limit "$cfg" limit 150
533 config_get leasetime "$cfg" leasetime 12h
534 config_get options "$cfg" options
535 config_get_bool dynamicdhcp "$cfg" dynamicdhcp 1
536
537 config_get dhcpv4 "$cfg" dhcpv4
538 config_get dhcpv6 "$cfg" dhcpv6
539
540 config_get ra "$cfg" ra
541 config_get ra_management "$cfg" ra_management
542 config_get ra_preference "$cfg" ra_preference
543 config_get dns "$cfg" dns
544
545 config_list_foreach "$cfg" "interface_name" append_interface_name "$ifname"
546
547 # Put the router host name on this DHCP served interface address(es)
548 dhcp_this_host_add "$net" "$ifname" "$ADD_LOCAL_FQDN"
549
550 start="$( dhcp_calc "$start" )"
551
552 add_tag() {
553 tags="${tags}tag:$1,"
554 }
555 config_list_foreach "$cfg" tag add_tag
556
557 nettag="${networkid:+set:${networkid},}"
558
559 if [ "$limit" -gt 0 ] ; then
560 limit=$((limit-1))
561 fi
562
563 eval "$(ipcalc.sh "${subnet%%/*}" $netmask $start $limit)"
564
565 if [ "$dynamicdhcp" = "0" ] ; then
566 END="static"
567 dhcp6range="::,static"
568 else
569 dhcp6range="::1000,::ffff"
570 fi
571
572
573 if [ "$dhcpv4" != "disabled" ] ; then
574 xappend "--dhcp-range=$tags$nettag$START,$END,$NETMASK,$leasetime${options:+ $options}"
575 fi
576
577
578 if [ $DNSMASQ_DHCP_VER -eq 6 ] && [ "$ra" = "server" ] ; then
579 # Note: dnsmasq cannot just be a DHCPv6 server (all-in-1)
580 # and let some other machine(s) send RA pointing to it.
581
582 case $ra_preference in
583 *high*)
584 xappend "--ra-param=$ifname,high,0,7200"
585 ;;
586 *low*)
587 xappend "--ra-param=$ifname,low,0,7200"
588 ;;
589 *)
590 # Send UNSOLICITED RA at default interval and live for 2 hours.
591 # TODO: convert flexible lease time into route life time (only seconds).
592 xappend "--ra-param=$ifname,0,7200"
593 ;;
594 esac
595
596 if [ "$dhcpv6" = "disabled" ] ; then
597 ra_management="3"
598 fi
599
600
601 case $ra_management in
602 0)
603 # SLACC with DCHP for extended options
604 xappend "--dhcp-range=$nettag::,constructor:$ifname,ra-stateless,ra-names"
605 ;;
606 2)
607 # DHCP address and RA only for management redirection
608 xappend "--dhcp-range=$nettag$dhcp6range,constructor:$ifname,$leasetime"
609 ;;
610 3)
611 # SLAAC only but dnsmasq attempts to link HOSTNAME, DHCPv4 MAC, and SLAAC
612 xappend "--dhcp-range=$nettag::,constructor:$ifname,ra-only,ra-names"
613 ;;
614 *)
615 # SLAAC and full DHCP
616 xappend "--dhcp-range=$nettag$dhcp6range,constructor:$ifname,slaac,ra-names,$leasetime"
617 ;;
618 esac
619
620 if [ -n "$dns" ]; then
621 dnss=""
622 for d in $dns; do append dnss "[$d]" ","; done
623 else
624 dnss="[::]"
625 fi
626
627 dhcp_option_append "option6:dns-server,$dnss" "$networkid"
628 fi
629
630 dhcp_option_add "$cfg" "$networkid" 0
631 dhcp_option_add "$cfg" "$networkid" 2
632 }
633
634 dhcp_option_append() {
635 local option="$1"
636 local networkid="$2"
637 local force="$3"
638
639 xappend "--dhcp-option${force:+-force}=${networkid:+$networkid,}$option"
640 }
641
642 dhcp_option_add() {
643 # NOTE: dnsmasq has explicit "option6:" prefix for DHCPv6 so no collisions
644 local cfg="$1"
645 local networkid="$2"
646 local force="$3"
647 local opt="dhcp_option"
648
649 [ "$force" = "0" ] && force=
650 [ "$force" = "2" ] && opt="dhcp_option_force"
651
652 local list_len
653 config_get list_len "$cfg" "${opt}_LENGTH"
654
655 if [ -n "$list_len" ]; then
656 config_list_foreach "$cfg" "$opt" dhcp_option_append "$networkid" "$force"
657 else
658 config_get dhcp_option "$cfg" "$opt"
659
660 [ -n "$dhcp_option" ] && echo "Warning: the 'option $opt' syntax is deprecated, use 'list $opt'" >&2
661
662 local option
663 for option in $dhcp_option; do
664 dhcp_option_append "$option" "$networkid" "$force"
665 done
666 fi
667 }
668
669 dhcp_domain_add() {
670 local cfg="$1"
671 local ip name names record
672
673 config_get names "$cfg" name "$2"
674 [ -n "$names" ] || return 0
675
676 config_get ip "$cfg" ip "$3"
677 [ -n "$ip" ] || return 0
678
679 for name in $names; do
680 record="${record:+$record }$name"
681 done
682
683 echo "$ip $record" >> $HOSTFILE_TMP
684 }
685
686 dhcp_srv_add() {
687 local cfg="$1"
688
689 config_get srv "$cfg" srv
690 [ -n "$srv" ] || return 0
691
692 config_get target "$cfg" target
693 [ -n "$target" ] || return 0
694
695 config_get port "$cfg" port
696 [ -n "$port" ] || return 0
697
698 config_get class "$cfg" class
699 config_get weight "$cfg" weight
700
701 local service="$srv,$target,$port${class:+,$class${weight:+,$weight}}"
702
703 xappend "--srv-host=$service"
704 }
705
706 dhcp_mx_add() {
707 local cfg="$1"
708 local domain relay pref
709
710 config_get domain "$cfg" domain
711 [ -n "$domain" ] || return 0
712
713 config_get relay "$cfg" relay
714 [ -n "$relay" ] || return 0
715
716 config_get pref "$cfg" pref 0
717
718 local service="$domain,$relay,$pref"
719
720 xappend "--mx-host=$service"
721 }
722
723 dhcp_cname_add() {
724 local cfg="$1"
725 local cname target
726
727 config_get cname "$cfg" cname
728 [ -n "$cname" ] || return 0
729
730 config_get target "$cfg" target
731 [ -n "$target" ] || return 0
732
733 xappend "--cname=${cname},${target}"
734 }
735
736 dhcp_hostrecord_add() {
737 local cfg="$1"
738 local names addresses record val
739
740 config_get names "$cfg" name "$2"
741 if [ -z "$names" ]; then
742 return 0
743 fi
744
745 config_get addresses "$cfg" ip "$3"
746 if [ -z "$addresses" ]; then
747 return 0
748 fi
749
750 for val in $names $addresses; do
751 record="${record:+$record,}$val"
752 done
753
754 xappend "--host-record=$record"
755 }
756
757 dhcp_relay_add() {
758 local cfg="$1"
759 local local_addr server_addr interface
760
761 config_get local_addr "$cfg" local_addr
762 [ -n "$local_addr" ] || return 0
763
764 config_get server_addr "$cfg" server_addr
765 [ -n "$server_addr" ] || return 0
766
767 config_get interface "$cfg" interface
768 if [ -z "$interface" ]; then
769 xappend "--dhcp-relay=$local_addr,$server_addr"
770 else
771 network_get_device ifname "$interface" || return
772 xappend "--dhcp-relay=$local_addr,$server_addr,$ifname"
773 fi
774 }
775
776 dnsmasq_ipset_add() {
777 local cfg="$1"
778 local ipsets domains
779
780 add_ipset() {
781 ipsets="${ipsets:+$ipsets,}$1"
782 }
783
784 add_domain() {
785 # leading '/' is expected
786 domains="$domains/$1"
787 }
788
789 config_list_foreach "$cfg" "name" add_ipset
790 config_list_foreach "$cfg" "domain" add_domain
791
792 if [ -z "$ipsets" ] || [ -z "$domains" ]; then
793 return 0
794 fi
795
796 xappend "--ipset=$domains/$ipsets"
797 }
798
799 dnsmasq_start()
800 {
801 local cfg="$1"
802 local disabled user_dhcpscript
803 local resolvfile resolvdir localuse=0
804
805 config_get_bool disabled "$cfg" disabled 0
806 [ "$disabled" -gt 0 ] && return 0
807
808 # reset list of DOMAINS and DNS servers (for each dnsmasq instance)
809 DNS_SERVERS=""
810 DOMAIN=""
811 CONFIGFILE="${BASECONFIGFILE}.${cfg}"
812 CONFIGFILE_TMP="${CONFIGFILE}.$$"
813 HOSTFILE="${BASEHOSTFILE}.${cfg}"
814 HOSTFILE_TMP="${HOSTFILE}.$$"
815 BASEDHCPSTAMPFILE_CFG="${BASEDHCPSTAMPFILE}.${cfg}"
816
817 # before we can call xappend
818 mkdir -p /var/run/dnsmasq/
819 mkdir -p $(dirname $CONFIGFILE)
820 mkdir -p $(dirname $HOSTFILE)
821 mkdir -p /var/lib/misc
822 chown dnsmasq:dnsmasq /var/run/dnsmasq
823
824 echo "# auto-generated config file from /etc/config/dhcp" > $CONFIGFILE_TMP
825 echo "# auto-generated config file from /etc/config/dhcp" > $HOSTFILE_TMP
826
827 local dnsmasqconffile="/etc/dnsmasq.${cfg}.conf"
828 if [ ! -r "$dnsmasqconffile" ]; then
829 dnsmasqconffile=/etc/dnsmasq.conf
830 fi
831
832 # if we did this last, we could override auto-generated config
833 [ -f "${dnsmasqconffile}" ] && {
834 xappend "--conf-file=${dnsmasqconffile}"
835 }
836
837 $PROG --version | grep -osqE "^Compile time options:.* DHCPv6( |$)" && DHCPv6CAPABLE=1 || DHCPv6CAPABLE=0
838
839
840 if [ -x /usr/sbin/odhcpd ] && [ -x /etc/init.d/odhcpd ] ; then
841 local odhcpd_is_main odhcpd_is_enabled
842 config_get odhcpd_is_main odhcpd maindhcp 0
843 /etc/init.d/odhcpd enabled && odhcpd_is_enabled=1 || odhcpd_is_enabled=0
844
845
846 if [ "$odhcpd_is_enabled" -eq 0 ] && [ "$DHCPv6CAPABLE" -eq 1 ] ; then
847 # DHCP V4 and V6 in DNSMASQ
848 DNSMASQ_DHCP_VER=6
849 elif [ "$odhcpd_is_main" -gt 0 ] ; then
850 # ODHCPD is doing it all
851 DNSMASQ_DHCP_VER=0
852 else
853 # You have ODHCPD but use DNSMASQ for DHCPV4
854 DNSMASQ_DHCP_VER=4
855 fi
856
857 elif [ "$DHCPv6CAPABLE" -eq 1 ] ; then
858 # DHCP V4 and V6 in DNSMASQ
859 DNSMASQ_DHCP_VER=6
860 else
861 DNSMASQ_DHCP_VER=4
862 fi
863
864 # Allow DHCP/DHCPv6 to be handled by ISC DHCPD
865 if [ -x /usr/sbin/dhcpd ] ; then
866 if [ -x /etc/init.d/dhcpd ] ; then
867 /etc/init.d/dhcpd enabled && DNSMASQ_DHCP_VER=0
868 fi
869 if [ -x /etc/init.d/dhcpd6 ] && [ "$DNSMASQ_DHCP_VER" -gt 0 ] ; then
870 /etc/init.d/dhcpd6 enabled && DNSMASQ_DHCP_VER=4
871 fi
872 fi
873
874 append_bool "$cfg" authoritative "--dhcp-authoritative"
875 append_bool "$cfg" nodaemon "--no-daemon"
876 append_bool "$cfg" domainneeded "--domain-needed"
877 append_bool "$cfg" filterwin2k "--filterwin2k"
878 append_bool "$cfg" nohosts "--no-hosts"
879 append_bool "$cfg" nonegcache "--no-negcache"
880 append_bool "$cfg" strictorder "--strict-order"
881 append_bool "$cfg" logqueries "--log-queries=extra"
882 append_bool "$cfg" noresolv "--no-resolv"
883 append_bool "$cfg" localise_queries "--localise-queries"
884 append_bool "$cfg" readethers "--read-ethers"
885 append_bool "$cfg" dbus "--enable-dbus"
886 append_bool "$cfg" ubus "--enable-ubus" 1
887 append_bool "$cfg" expandhosts "--expand-hosts"
888 config_get tftp_root "$cfg" "tftp_root"
889 [ -n "$tftp_root" ] && mkdir -p "$tftp_root" && append_bool "$cfg" enable_tftp "--enable-tftp"
890 append_bool "$cfg" tftp_no_fail "--tftp-no-fail"
891 append_bool "$cfg" nonwildcard "--bind-dynamic" 1
892 append_bool "$cfg" fqdn "--dhcp-fqdn"
893 append_bool "$cfg" proxydnssec "--proxy-dnssec"
894 append_bool "$cfg" localservice "--local-service"
895 append_bool "$cfg" logdhcp "--log-dhcp"
896 append_bool "$cfg" quietdhcp "--quiet-dhcp"
897 append_bool "$cfg" sequential_ip "--dhcp-sequential-ip"
898 append_bool "$cfg" allservers "--all-servers"
899 append_bool "$cfg" noping "--no-ping"
900 append_bool "$cfg" rapidcommit "--dhcp-rapid-commit"
901 append_bool "$cfg" scriptarp "--script-arp"
902
903 append_parm "$cfg" logfacility "--log-facility"
904
905 append_parm "$cfg" cachesize "--cache-size"
906 append_parm "$cfg" dnsforwardmax "--dns-forward-max"
907 append_parm "$cfg" port "--port"
908 append_parm "$cfg" ednspacket_max "--edns-packet-max"
909 append_parm "$cfg" dhcpleasemax "--dhcp-lease-max"
910 append_parm "$cfg" "queryport" "--query-port"
911 append_parm "$cfg" "minport" "--min-port"
912 append_parm "$cfg" "maxport" "--max-port"
913 append_parm "$cfg" "domain" "--domain"
914 append_parm "$cfg" "local" "--server"
915 config_list_foreach "$cfg" "listen_address" append_listenaddress
916 config_list_foreach "$cfg" "server" append_server
917 config_list_foreach "$cfg" "rev_server" append_rev_server
918 config_list_foreach "$cfg" "address" append_address
919 config_list_foreach "$cfg" "ipset" append_ipset
920
921 local connmark_allowlist_enable
922 config_get connmark_allowlist_enable "$cfg" connmark_allowlist_enable 0
923 [ "$connmark_allowlist_enable" -gt 0 ] && {
924 append_parm "$cfg" "connmark_allowlist_enable" "--connmark-allowlist-enable"
925 config_list_foreach "$cfg" "connmark_allowlist" append_connmark_allowlist
926 }
927
928 [ -n "$BOOT" ] || {
929 config_list_foreach "$cfg" "interface" append_interface
930 config_list_foreach "$cfg" "notinterface" append_notinterface
931 }
932 config_list_foreach "$cfg" "addnhosts" append_addnhosts
933 config_list_foreach "$cfg" "bogusnxdomain" append_bogusnxdomain
934 append_parm "$cfg" "leasefile" "--dhcp-leasefile" "/tmp/dhcp.leases"
935 append_parm "$cfg" "serversfile" "--servers-file"
936 append_parm "$cfg" "tftp_root" "--tftp-root"
937 append_parm "$cfg" "dhcp_boot" "--dhcp-boot"
938 append_parm "$cfg" "local_ttl" "--local-ttl"
939 append_parm "$cfg" "max_ttl" "--max-ttl"
940 append_parm "$cfg" "min_cache_ttl" "--min-cache-ttl"
941 append_parm "$cfg" "max_cache_ttl" "--max-cache-ttl"
942 append_parm "$cfg" "pxe_prompt" "--pxe-prompt"
943 append_parm "$cfg" "tftp_unique_root" "--tftp-unique-root"
944 config_list_foreach "$cfg" "pxe_service" append_pxe_service
945 config_get DOMAIN "$cfg" domain
946
947 config_get_bool ADD_LOCAL_DOMAIN "$cfg" add_local_domain 1
948 config_get_bool ADD_LOCAL_HOSTNAME "$cfg" add_local_hostname 1
949 config_get ADD_LOCAL_FQDN "$cfg" add_local_fqdn ""
950 config_get ADD_WAN_FQDN "$cfg" add_wan_fqdn 0
951
952 if [ -z "$ADD_LOCAL_FQDN" ] ; then
953 # maintain support for previous UCI
954 ADD_LOCAL_FQDN="$ADD_LOCAL_HOSTNAME"
955 fi
956
957 config_get user_dhcpscript $cfg dhcpscript
958 if has_handler || [ -n "$user_dhcpscript" ]; then
959 xappend "--dhcp-script=$DHCPSCRIPT"
960 xappend "--script-arp"
961 fi
962
963 config_get leasefile $cfg leasefile "/tmp/dhcp.leases"
964 [ -n "$leasefile" ] && [ ! -e "$leasefile" ] && touch "$leasefile"
965 config_get_bool cachelocal "$cfg" cachelocal 1
966
967 config_get_bool noresolv "$cfg" noresolv 0
968 if [ "$noresolv" != "1" ]; then
969 config_get resolvfile "$cfg" resolvfile /tmp/resolv.conf.d/resolv.conf.auto
970 [ -n "$resolvfile" ] && [ ! -e "$resolvfile" ] && touch "$resolvfile"
971 xappend "--resolv-file=$resolvfile"
972 [ "$resolvfile" = "/tmp/resolv.conf.d/resolv.conf.auto" ] && localuse=1
973 resolvdir="$(dirname "$resolvfile")"
974 fi
975 config_get_bool localuse "$cfg" localuse "$localuse"
976
977 config_get hostsfile "$cfg" dhcphostsfile
978 [ -e "$hostsfile" ] && xappend "--dhcp-hostsfile=$hostsfile"
979
980 local rebind
981 config_get_bool rebind "$cfg" rebind_protection 1
982 [ $rebind -gt 0 ] && {
983 log_once \
984 "DNS rebinding protection is active," \
985 "will discard upstream RFC1918 responses!"
986 xappend "--stop-dns-rebind"
987
988 local rebind_localhost
989 config_get_bool rebind_localhost "$cfg" rebind_localhost 0
990 [ $rebind_localhost -gt 0 ] && {
991 log_once "Allowing 127.0.0.0/8 responses"
992 xappend "--rebind-localhost-ok"
993 }
994
995 append_rebind_domain() {
996 log_once "Allowing RFC1918 responses for domain $1"
997 xappend "--rebind-domain-ok=$1"
998 }
999
1000 config_list_foreach "$cfg" rebind_domain append_rebind_domain
1001 }
1002
1003 config_get_bool dnssec "$cfg" dnssec 0
1004 [ "$dnssec" -gt 0 ] && {
1005 xappend "--conf-file=$TRUSTANCHORSFILE"
1006 xappend "--dnssec"
1007 [ -x /etc/init.d/sysntpd ] && {
1008 if /etc/init.d/sysntpd enabled || [ "$(uci_get system.ntp.enabled)" = "1" ] ; then
1009 [ -f "$TIMEVALIDFILE" ] || xappend "--dnssec-no-timecheck"
1010 fi
1011 }
1012 config_get_bool dnsseccheckunsigned "$cfg" dnsseccheckunsigned 1
1013 [ "$dnsseccheckunsigned" -eq 0 ] && xappend "--dnssec-check-unsigned=no"
1014 }
1015
1016 config_get addmac "$cfg" addmac 0
1017 [ "$addmac" != "0" ] && {
1018 [ "$addmac" = "1" ] && addmac=
1019 xappend "--add-mac${addmac:+="$addmac"}"
1020 }
1021
1022 dhcp_option_add "$cfg" "" 0
1023 dhcp_option_add "$cfg" "" 2
1024
1025 xappend "--dhcp-broadcast=tag:needs-broadcast"
1026
1027 config_get_bool ignore_hosts_dir "$cfg" ignore_hosts_dir 0
1028 if [ "$ignore_hosts_dir" = "1" ]; then
1029 xappend "--addn-hosts=$HOSTFILE"
1030 else
1031 xappend "--addn-hosts=$(dirname $HOSTFILE)"
1032 fi
1033
1034 config_get dnsmasqconfdir "$cfg" confdir "/tmp/dnsmasq.d"
1035 xappend "--conf-dir=$dnsmasqconfdir"
1036 dnsmasqconfdir="${dnsmasqconfdir%%,*}"
1037 [ ! -d "$dnsmasqconfdir" ] && mkdir -p $dnsmasqconfdir
1038 xappend "--user=dnsmasq"
1039 xappend "--group=dnsmasq"
1040 echo >> $CONFIGFILE_TMP
1041
1042 config_get_bool enable_tftp "$cfg" enable_tftp 0
1043 [ "$enable_tftp" -gt 0 ] && {
1044 config_get tftp_root "$cfg" tftp_root
1045 append EXTRA_MOUNT $tftp_root
1046 }
1047
1048 config_foreach filter_dnsmasq host dhcp_host_add "$cfg"
1049 echo >> $CONFIGFILE_TMP
1050
1051 config_get_bool dhcpbogushostname "$cfg" dhcpbogushostname 1
1052 [ "$dhcpbogushostname" -gt 0 ] && {
1053 xappend "--dhcp-ignore-names=tag:dhcp_bogus_hostname"
1054 [ -r "$DHCPBOGUSHOSTNAMEFILE" ] && xappend "--conf-file=$DHCPBOGUSHOSTNAMEFILE"
1055 }
1056
1057 config_foreach filter_dnsmasq boot dhcp_boot_add "$cfg"
1058 config_foreach filter_dnsmasq mac dhcp_mac_add "$cfg"
1059 config_foreach filter_dnsmasq tag dhcp_tag_add "$cfg"
1060 config_foreach filter_dnsmasq vendorclass dhcp_vendorclass_add "$cfg"
1061 config_foreach filter_dnsmasq userclass dhcp_userclass_add "$cfg"
1062 config_foreach filter_dnsmasq circuitid dhcp_circuitid_add "$cfg"
1063 config_foreach filter_dnsmasq remoteid dhcp_remoteid_add "$cfg"
1064 config_foreach filter_dnsmasq subscrid dhcp_subscrid_add "$cfg"
1065 config_foreach filter_dnsmasq match dhcp_match_add "$cfg"
1066 config_foreach filter_dnsmasq domain dhcp_domain_add "$cfg"
1067 config_foreach filter_dnsmasq hostrecord dhcp_hostrecord_add "$cfg"
1068 [ -n "$BOOT" ] || config_foreach filter_dnsmasq relay dhcp_relay_add "$cfg"
1069
1070 echo >> $CONFIGFILE_TMP
1071 config_foreach filter_dnsmasq srvhost dhcp_srv_add "$cfg"
1072 config_foreach filter_dnsmasq mxhost dhcp_mx_add "$cfg"
1073 echo >> $CONFIGFILE_TMP
1074
1075 config_get_bool boguspriv "$cfg" boguspriv 1
1076 [ "$boguspriv" -gt 0 ] && {
1077 xappend "--bogus-priv"
1078 [ -r "$RFC6761FILE" ] && xappend "--conf-file=$RFC6761FILE"
1079 }
1080
1081 if [ "$DNSMASQ_DHCP_VER" -gt 4 ] ; then
1082 # Enable RA feature for when/if it is constructed,
1083 # and RA is selected per interface pool (RA, DHCP, or both),
1084 # but no one (should) want RA broadcast in syslog
1085 [ -n "$BOOT" ] || config_foreach filter_dnsmasq dhcp dhcp_add "$cfg"
1086 xappend "--enable-ra"
1087 xappend "--quiet-ra"
1088 append_bool "$cfg" quietdhcp "--quiet-dhcp6"
1089
1090 elif [ "$DNSMASQ_DHCP_VER" -gt 0 ] ; then
1091 [ -n "$BOOT" ] || config_foreach filter_dnsmasq dhcp dhcp_add "$cfg"
1092 fi
1093
1094
1095 echo >> $CONFIGFILE_TMP
1096 config_foreach filter_dnsmasq cname dhcp_cname_add "$cfg"
1097 echo >> $CONFIGFILE_TMP
1098
1099 echo >> $CONFIGFILE_TMP
1100 config_foreach filter_dnsmasq ipset dnsmasq_ipset_add "$cfg"
1101 echo >> $CONFIGFILE_TMP
1102
1103 echo >> $CONFIGFILE_TMP
1104 mv -f $CONFIGFILE_TMP $CONFIGFILE
1105 mv -f $HOSTFILE_TMP $HOSTFILE
1106
1107 [ "$localuse" -gt 0 ] && {
1108 rm -f /tmp/resolv.conf
1109 [ $ADD_LOCAL_DOMAIN -eq 1 ] && [ -n "$DOMAIN" ] && {
1110 echo "search $DOMAIN" >> /tmp/resolv.conf
1111 }
1112 DNS_SERVERS="$DNS_SERVERS 127.0.0.1"
1113 [ -e /proc/sys/net/ipv6 ] && DNS_SERVERS="$DNS_SERVERS ::1"
1114 for DNS_SERVER in $DNS_SERVERS ; do
1115 echo "nameserver $DNS_SERVER" >> /tmp/resolv.conf
1116 done
1117 }
1118
1119 procd_open_instance $cfg
1120 procd_set_param command $PROG -C $CONFIGFILE -k -x /var/run/dnsmasq/dnsmasq."${cfg}".pid
1121 procd_set_param file $CONFIGFILE
1122 [ -n "$user_dhcpscript" ] && procd_set_param env USER_DHCPSCRIPT="$user_dhcpscript"
1123 procd_set_param respawn
1124
1125 procd_add_jail dnsmasq ubus log
1126 procd_add_jail_mount $CONFIGFILE $TRUSTANCHORSFILE $HOSTFILE $RFC6761FILE $DHCPBOGUSHOSTNAMEFILE /etc/passwd /etc/group /etc/TZ /dev/null /dev/urandom $dnsmasqconffile $dnsmasqconfdir $resolvdir $user_dhcpscript /etc/hosts /etc/ethers /sbin/hotplug-call $EXTRA_MOUNT $DHCPSCRIPT
1127 procd_add_jail_mount_rw /var/run/dnsmasq/ $leasefile
1128
1129 procd_close_instance
1130 }
1131
1132 dnsmasq_stop()
1133 {
1134 local cfg="$1"
1135 local noresolv resolvfile localuse=0
1136
1137 config_get_bool noresolv "$cfg" noresolv 0
1138 config_get resolvfile "$cfg" "resolvfile"
1139
1140 [ "$noresolv" = 0 ] && [ "$resolvfile" = "/tmp/resolv.conf.d/resolv.conf.auto" ] && localuse=1
1141 config_get_bool localuse "$cfg" localuse "$localuse"
1142 [ "$localuse" -gt 0 ] && ln -sf "/tmp/resolv.conf.d/resolv.conf.auto" /tmp/resolv.conf
1143
1144 rm -f ${BASEDHCPSTAMPFILE}.${cfg}.*.dhcp
1145 }
1146
1147 add_interface_trigger()
1148 {
1149 local interface ignore
1150
1151 config_get interface "$1" interface
1152 config_get_bool ignore "$1" ignore 0
1153
1154 [ -n "$interface" ] && [ $ignore -eq 0 ] && procd_add_interface_trigger "interface.*" "$interface" /etc/init.d/dnsmasq reload
1155 }
1156
1157 service_triggers()
1158 {
1159 procd_add_reload_trigger "dhcp" "system"
1160
1161 config_load dhcp
1162 config_foreach add_interface_trigger dhcp
1163 config_foreach add_interface_trigger relay
1164 }
1165
1166 boot()
1167 {
1168 BOOT=1
1169 start "$@"
1170 }
1171
1172 start_service() {
1173 local instance="$1"
1174 local instance_found=0
1175
1176 . /lib/functions/network.sh
1177
1178 config_cb() {
1179 local type="$1"
1180 local name="$2"
1181 if [ "$type" = "dnsmasq" ]; then
1182 if [ -n "$instance" ] && [ "$instance" = "$name" ]; then
1183 instance_found=1
1184 fi
1185 fi
1186 }
1187
1188 config_load dhcp
1189
1190 if [ -n "$instance" ]; then
1191 [ "$instance_found" -gt 0 ] || return
1192 dnsmasq_start "$instance"
1193 else
1194 config_foreach dnsmasq_start dnsmasq
1195 fi
1196 }
1197
1198 reload_service() {
1199 rc_procd start_service "$@"
1200 procd_send_signal dnsmasq "$@"
1201 }
1202
1203 stop_service() {
1204 local instance="$1"
1205 local instance_found=0
1206
1207 config_cb() {
1208 local type="$1"
1209 local name="$2"
1210 if [ "$type" = "dnsmasq" ]; then
1211 if [ -n "$instance" ] && [ "$instance" = "$name" ]; then
1212 instance_found=1
1213 fi
1214 fi
1215 }
1216
1217 config_load dhcp
1218
1219 if [ -n "$instance" ]; then
1220 [ "$instance_found" -gt 0 ] || return
1221 dnsmasq_stop "$instance"
1222 else
1223 config_foreach dnsmasq_stop dnsmasq
1224 fi
1225 }