dnsmasq: rework jail mounts
[openwrt/openwrt.git] / package / network / services / dnsmasq / files / dnsmasq.init
1 #!/bin/sh /etc/rc.common
2 # Copyright (C) 2007-2012 OpenWrt.org
3
4 START=19
5
6 USE_PROCD=1
7 PROG=/usr/sbin/dnsmasq
8
9 ADD_LOCAL_DOMAIN=1
10 ADD_LOCAL_HOSTNAME=1
11 ADD_WAN_FQDN=0
12 ADD_LOCAL_FQDN=""
13
14 BASECONFIGFILE="/var/etc/dnsmasq.conf"
15 BASEHOSTFILE="/tmp/hosts/dhcp"
16 TRUSTANCHORSFILE="/usr/share/dnsmasq/trust-anchors.conf"
17 TIMEVALIDFILE="/var/state/dnsmasqsec"
18 BASEDHCPSTAMPFILE="/var/run/dnsmasq"
19 DHCPBOGUSHOSTNAMEFILE="/usr/share/dnsmasq/dhcpbogushostname.conf"
20 RFC6761FILE="/usr/share/dnsmasq/rfc6761.conf"
21 DHCPSCRIPT="/usr/lib/dnsmasq/dhcp-script.sh"
22 DHCPSCRIPT_DEPENDS="/usr/share/libubox/jshn.sh /usr/bin/jshn /bin/ubus"
23
24 DNSMASQ_DHCP_VER=4
25
26 dnsmasq_ignore_opt() {
27 local opt="$1"
28
29 if [ -z "$dnsmasq_features" ]; then
30 dnsmasq_features="$(dnsmasq --version | grep -m1 'Compile time options:' | cut -d: -f2) "
31 [ "${dnsmasq_features#* DHCP }" = "$dnsmasq_features" ] || dnsmasq_has_dhcp=1
32 [ "${dnsmasq_features#* DHCPv6 }" = "$dnsmasq_features" ] || dnsmasq_has_dhcp6=1
33 [ "${dnsmasq_features#* DNSSEC }" = "$dnsmasq_features" ] || dnsmasq_has_dnssec=1
34 [ "${dnsmasq_features#* TFTP }" = "$dnsmasq_features" ] || dnsmasq_has_tftp=1
35 [ "${dnsmasq_features#* ipset }" = "$dnsmasq_features" ] || dnsmasq_has_ipset=1
36 fi
37
38 case "$opt" in
39 dhcp-duid|\
40 ra-param)
41 [ -z "$dnsmasq_has_dhcp6" ] ;;
42 dhcp-*|\
43 bootp-*|\
44 pxe-*)
45 [ -z "$dnsmasq_has_dhcp" ] ;;
46 dnssec*|\
47 trust-anchor)
48 if [ -z "$dnsmasq_has_dnssec" ]; then
49 echo "dnsmasq: \"$opt\" requested, but dnssec support is not available" >&2
50 exit 1
51 fi
52 return 1
53 ;;
54 tftp-*)
55 [ -z "$dnsmasq_has_tftp" ] ;;
56 ipset)
57 [ -z "$dnsmasq_has_ipset" ] ;;
58 *)
59 return 1
60 esac
61 }
62
63 xappend() {
64 local value="${1#--}"
65 local opt="${value%%=*}"
66
67 if ! dnsmasq_ignore_opt "$opt"; then
68 echo "$value" >>$CONFIGFILE_TMP
69 fi
70 }
71
72 hex_to_hostid() {
73 local var="$1"
74 local hex="${2#0x}" # strip optional "0x" prefix
75
76 if [ -n "${hex//[0-9a-fA-F]/}" ]; then
77 # is invalid hex literal
78 return 1
79 fi
80
81 # convert into host id
82 export "$var=$(
83 printf "%0x:%0x" \
84 $(((0x$hex >> 16) % 65536)) \
85 $(( 0x$hex % 65536))
86 )"
87
88 return 0
89 }
90
91 dhcp_calc() {
92 local ip="$1"
93 local res=0
94
95 while [ -n "$ip" ]; do
96 part="${ip%%.*}"
97 res="$(($res * 256))"
98 res="$(($res + $part))"
99 [ "${ip%.*}" != "$ip" ] && ip="${ip#*.}" || ip=
100 done
101 echo "$res"
102 }
103
104 dhcp_check() {
105 local ifname="$1"
106 local stamp="${BASEDHCPSTAMPFILE_CFG}.${ifname}.dhcp"
107 local rv=0
108
109 [ -s "$stamp" ] && return $(cat "$stamp")
110
111 # If interface is down, skip it.
112 # The init script will be called again once the link is up
113 case "$(devstatus "$ifname" | jsonfilter -e @.up)" in
114 false) return 1;;
115 esac
116
117 udhcpc -n -q -s /bin/true -t 1 -i "$ifname" >&- && rv=1 || rv=0
118
119 echo $rv > "$stamp"
120 return $rv
121 }
122
123 log_once() {
124 pidof dnsmasq >/dev/null || \
125 logger -t dnsmasq "$@"
126 }
127
128 has_handler() {
129 local file
130
131 for file in /etc/hotplug.d/dhcp/* /etc/hotplug.d/tftp/* /etc/hotplug.d/neigh/*; do
132 [ -f "$file" ] && return 0
133 done
134
135 return 1
136 }
137
138 append_bool() {
139 local section="$1"
140 local option="$2"
141 local value="$3"
142 local default="$4"
143 local _loctmp
144 [ -z "$default" ] && default="0"
145 config_get_bool _loctmp "$section" "$option" "$default"
146 [ $_loctmp -gt 0 ] && xappend "$value"
147 }
148
149 append_parm() {
150 local section="$1"
151 local option="$2"
152 local switch="$3"
153 local default="$4"
154 local _loctmp
155 config_get _loctmp "$section" "$option" "$default"
156 [ -z "$_loctmp" ] && return 0
157 xappend "$switch=$_loctmp"
158 }
159
160 append_server() {
161 xappend "--server=$1"
162 }
163
164 append_rev_server() {
165 xappend "--rev-server=$1"
166 }
167
168 append_address() {
169 xappend "--address=$1"
170 }
171
172 append_ipset() {
173 xappend "--ipset=$1"
174 }
175
176 append_interface() {
177 network_get_device ifname "$1" || ifname="$1"
178 xappend "--interface=$ifname"
179 }
180
181 append_listenaddress() {
182 xappend "--listen-address=$1"
183 }
184
185 append_notinterface() {
186 network_get_device ifname "$1" || ifname="$1"
187 xappend "--except-interface=$ifname"
188 }
189
190 append_addnhosts() {
191 append EXTRA_MOUNT "$1"
192 xappend "--addn-hosts=$1"
193 }
194
195 append_bogusnxdomain() {
196 xappend "--bogus-nxdomain=$1"
197 }
198
199 append_pxe_service() {
200 xappend "--pxe-service=$1"
201 }
202
203 append_interface_name() {
204 xappend "--interface-name=$1,$2"
205 }
206
207 filter_dnsmasq() {
208 local cfg="$1" func="$2" match_cfg="$3" found_cfg
209
210 # use entry when no instance entry set, or if it matches
211 config_get found_cfg "$cfg" "instance"
212 if [ -z "$found_cfg" ] || [ "$found_cfg" = "$match_cfg" ]; then
213 $func $cfg
214 fi
215 }
216
217 dhcp_subscrid_add() {
218 local cfg="$1"
219
220 config_get networkid "$cfg" networkid
221 [ -n "$networkid" ] || return 0
222
223 config_get subscriberid "$cfg" subscriberid
224 [ -n "$subscriberid" ] || return 0
225
226 xappend "--dhcp-subscrid=$networkid,$subscriberid"
227
228 config_get_bool force "$cfg" force 0
229
230 dhcp_option_add "$cfg" "$networkid" "$force"
231 }
232
233 dhcp_remoteid_add() {
234 local cfg="$1"
235
236 config_get networkid "$cfg" networkid
237 [ -n "$networkid" ] || return 0
238
239 config_get remoteid "$cfg" remoteid
240 [ -n "$remoteid" ] || return 0
241
242 xappend "--dhcp-remoteid=$networkid,$remoteid"
243
244 config_get_bool force "$cfg" force 0
245
246 dhcp_option_add "$cfg" "$networkid" "$force"
247 }
248
249 dhcp_circuitid_add() {
250 # TODO: DHCPV6 does not have circuitid; catch "option6:"
251 local cfg="$1"
252
253 config_get networkid "$cfg" networkid
254 [ -n "$networkid" ] || return 0
255
256 config_get circuitid "$cfg" circuitid
257 [ -n "$circuitid" ] || return 0
258
259 xappend "--dhcp-circuitid=$networkid,$circuitid"
260
261 config_get_bool force "$cfg" force 0
262
263 dhcp_option_add "$cfg" "$networkid" "$force"
264 }
265
266 dhcp_userclass_add() {
267 local cfg="$1"
268
269 config_get networkid "$cfg" networkid
270 [ -n "$networkid" ] || return 0
271
272 config_get userclass "$cfg" userclass
273 [ -n "$userclass" ] || return 0
274
275 xappend "--dhcp-userclass=$networkid,$userclass"
276
277 config_get_bool force "$cfg" force 0
278
279 dhcp_option_add "$cfg" "$networkid" "$force"
280 }
281
282 dhcp_vendorclass_add() {
283 # TODO: DHCPV6 vendor class has stricter definitions; catch? fixup?
284 local cfg="$1"
285
286 config_get networkid "$cfg" networkid
287 [ -n "$networkid" ] || return 0
288
289 config_get vendorclass "$cfg" vendorclass
290 [ -n "$vendorclass" ] || return 0
291
292 xappend "--dhcp-vendorclass=$networkid,$vendorclass"
293
294 config_get_bool force "$cfg" force 0
295
296 dhcp_option_add "$cfg" "$networkid" "$force"
297 }
298
299 dhcp_match_add() {
300 local cfg="$1"
301
302 config_get networkid "$cfg" networkid
303 [ -n "$networkid" ] || return 0
304
305 config_get match "$cfg" match
306 [ -n "$match" ] || return 0
307
308 xappend "--dhcp-match=$networkid,$match"
309
310 config_get_bool force "$cfg" force 0
311
312 dhcp_option_add "$cfg" "$networkid" "$force"
313 }
314
315 dhcp_host_add() {
316 local cfg="$1"
317 local hosttag nametime addrs duids macs tags
318
319 config_get_bool force "$cfg" force 0
320
321 config_get networkid "$cfg" networkid
322 [ -n "$networkid" ] && dhcp_option_add "$cfg" "$networkid" "$force"
323
324 config_get_bool enable "$cfg" enable 1
325 [ "$enable" = "0" ] && return 0
326
327 config_get name "$cfg" name
328 config_get ip "$cfg" ip
329 config_get hostid "$cfg" hostid
330
331 [ -z "$ip" ] && [ -z "$name" ] && [ -z "$hostid" ] && return 0
332
333 config_get_bool dns "$cfg" dns 0
334 [ "$dns" = "1" ] && [ -n "$ip" ] && [ -n "$name" ] && {
335 echo "$ip $name${DOMAIN:+.$DOMAIN}" >> $HOSTFILE_TMP
336 }
337
338 config_get mac "$cfg" mac
339 config_get duid "$cfg" duid
340 config_get tag "$cfg" tag
341
342 if [ -n "$mac" ]; then
343 # --dhcp-host=00:20:e0:3b:13:af,192.168.0.199,lap
344 # many MAC are possible to track a laptop ON/OFF dock
345 for m in $mac; do append macs "$m" ","; done
346 fi
347
348 if [ $DNSMASQ_DHCP_VER -eq 6 ] && [ -n "$duid" ]; then
349 # --dhcp-host=id:00:03:00:01:12:00:00:01:02:03,[::beef],lap
350 # one (virtual) machine gets one DUID per RFC3315
351 duids="id:${duid// */}"
352 fi
353
354 if [ -z "$macs" ] && [ -z "$duids" ]; then
355 # --dhcp-host=lap,192.168.0.199,[::beef]
356 [ -n "$name" ] || return 0
357 macs="$name"
358 name=""
359 fi
360
361 if [ -n "$hostid" ]; then
362 hex_to_hostid hostid "$hostid"
363 fi
364
365 if [ -n "$tag" ]; then
366 for t in $tag; do append tags "$t" ",set:"; done
367 fi
368
369 config_get_bool broadcast "$cfg" broadcast 0
370 config_get leasetime "$cfg" leasetime
371
372 [ "$broadcast" = "0" ] && broadcast= || broadcast=",set:needs-broadcast"
373
374 hosttag="${networkid:+,set:${networkid}}${tags:+,set:${tags}}$broadcast"
375 nametime="${name:+,$name}${leasetime:+,$leasetime}"
376
377 if [ $DNSMASQ_DHCP_VER -eq 6 ]; then
378 addrs="${ip:+,$ip}${hostid:+,[::$hostid]}"
379 xappend "--dhcp-host=$macs${duids:+,$duids}$hosttag$addrs$nametime"
380 else
381 xappend "--dhcp-host=$macs$hosttag${ip:+,$ip}$nametime"
382 fi
383 }
384
385 dhcp_this_host_add() {
386 local net="$1"
387 local ifname="$2"
388 local mode="$3"
389 local routerstub routername ifdashname
390 local lanaddr lanaddr6 lanaddrs6 ulaprefix
391
392 if [ "$mode" -gt 0 ] ; then
393 ifdashname="${ifname//./-}"
394 routerstub="$( md5sum /etc/os-release )"
395 routerstub="router-${routerstub// */}"
396 routername="$( uci_get system @system[0] hostname $routerstub )"
397
398 if [ "$mode" -gt 1 ] ; then
399 if [ "$mode" -gt 2 ] ; then
400 if [ "$mode" -gt 3 ] ; then
401 append_interface_name "$ifdashname.$routername.$DOMAIN" "$ifname"
402 fi
403
404 append_interface_name "$routername.$DOMAIN" "$ifname"
405 fi
406
407 # All IP addresses discovered by dnsmasq will be labeled (except fe80::)
408 append_interface_name "$routername" "$ifname"
409
410 else
411 # This uses a static host file entry for only limited addresses.
412 # Use dnsmasq option "--expandhosts" to enable FQDN on host files.
413 ulaprefix="$(uci_get network @globals[0] ula_prefix)"
414 network_get_ipaddr lanaddr "$net"
415 network_get_ipaddrs6 lanaddrs6 "$net"
416
417 if [ -n "$lanaddr" ] ; then
418 dhcp_domain_add "" "$routername" "$lanaddr"
419 fi
420
421 if [ -n "$ulaprefix" ] && [ -n "$lanaddrs6" ] ; then
422 for lanaddr6 in $lanaddrs6 ; do
423 case "$lanaddr6" in
424 "${ulaprefix%%:/*}"*)
425 dhcp_domain_add "" "$routername" "$lanaddr6"
426 ;;
427 esac
428 done
429 fi
430 fi
431 fi
432 }
433
434 dhcp_tag_add() {
435 # NOTE: dnsmasq has explicit "option6:" prefix for DHCPv6 so no collisions
436 local cfg="$1"
437
438 tag="$cfg"
439
440 [ -n "$tag" ] || return 0
441
442 config_get_bool force "$cfg" force 0
443 [ "$force" = "0" ] && force=
444
445 config_get option "$cfg" dhcp_option
446 for o in $option; do
447 xappend "--dhcp-option${force:+-force}=tag:$tag,$o"
448 done
449 }
450
451 dhcp_mac_add() {
452 local cfg="$1"
453
454 config_get networkid "$cfg" networkid
455 [ -n "$networkid" ] || return 0
456
457 config_get mac "$cfg" mac
458 [ -n "$mac" ] || return 0
459
460 xappend "--dhcp-mac=$networkid,$mac"
461
462 dhcp_option_add "$cfg" "$networkid"
463 }
464
465 dhcp_boot_add() {
466 # TODO: BOOTURL is different between DHCPv4 and DHCPv6
467 local cfg="$1"
468
469 config_get networkid "$cfg" networkid
470
471 config_get filename "$cfg" filename
472 [ -n "$filename" ] || return 0
473
474 config_get servername "$cfg" servername
475 config_get serveraddress "$cfg" serveraddress
476
477 [ -n "$serveraddress" ] && [ ! -n "$servername" ] && return 0
478
479 xappend "--dhcp-boot=${networkid:+net:$networkid,}${filename}${servername:+,$servername}${serveraddress:+,$serveraddress}"
480
481 config_get_bool force "$cfg" force 0
482
483 dhcp_option_add "$cfg" "$networkid" "$force"
484 }
485
486
487 dhcp_add() {
488 local cfg="$1"
489 local dhcp6range="::"
490 local nettag
491 local tags
492
493 config_get net "$cfg" interface
494 [ -n "$net" ] || return 0
495
496 config_get networkid "$cfg" networkid
497 [ -n "$networkid" ] || networkid="$net"
498
499 network_get_device ifname "$net" || return 0
500
501 [ "$cachelocal" = "0" ] && network_get_dnsserver dnsserver "$net" && {
502 DNS_SERVERS="$DNS_SERVERS $dnsserver"
503 }
504
505 append_bool "$cfg" ignore "--no-dhcp-interface=$ifname" && {
506 # Many ISP do not have useful names for DHCP customers (your WAN).
507 dhcp_this_host_add "$net" "$ifname" "$ADD_WAN_FQDN"
508 return 0
509 }
510
511 network_get_subnet subnet "$net" || return 0
512 network_get_protocol proto "$net" || return 0
513
514 # Do not support non-static interfaces for now
515 [ static = "$proto" ] || return 0
516
517 # Override interface netmask with dhcp config if applicable
518 config_get netmask "$cfg" netmask "${subnet##*/}"
519
520 #check for an already active dhcp server on the interface, unless 'force' is set
521 config_get_bool force "$cfg" force 0
522 [ $force -gt 0 ] || dhcp_check "$ifname" || {
523 logger -t dnsmasq \
524 "found already running DHCP-server on interface '$ifname'" \
525 "refusing to start, use 'option force 1' to override"
526 return 0
527 }
528
529 config_get start "$cfg" start 100
530 config_get limit "$cfg" limit 150
531 config_get leasetime "$cfg" leasetime 12h
532 config_get options "$cfg" options
533 config_get_bool dynamicdhcp "$cfg" dynamicdhcp 1
534
535 config_get dhcpv4 "$cfg" dhcpv4
536 config_get dhcpv6 "$cfg" dhcpv6
537
538 config_get ra "$cfg" ra
539 config_get ra_management "$cfg" ra_management
540 config_get ra_preference "$cfg" ra_preference
541 config_get dns "$cfg" dns
542
543 config_list_foreach "$cfg" "interface_name" append_interface_name "$ifname"
544
545 # Put the router host name on this DHCP served interface address(es)
546 dhcp_this_host_add "$net" "$ifname" "$ADD_LOCAL_FQDN"
547
548 start="$( dhcp_calc "$start" )"
549
550 add_tag() {
551 tags="${tags}tag:$1,"
552 }
553 config_list_foreach "$cfg" tag add_tag
554
555 nettag="${networkid:+set:${networkid},}"
556
557 if [ "$limit" -gt 0 ] ; then
558 limit=$((limit-1))
559 fi
560
561 eval "$(ipcalc.sh "${subnet%%/*}" $netmask $start $limit)"
562
563 if [ "$dynamicdhcp" = "0" ] ; then
564 END="static"
565 dhcp6range="::,static"
566 else
567 dhcp6range="::1000,::ffff"
568 fi
569
570
571 if [ "$dhcpv4" != "disabled" ] ; then
572 xappend "--dhcp-range=$tags$nettag$START,$END,$NETMASK,$leasetime${options:+ $options}"
573 fi
574
575
576 if [ $DNSMASQ_DHCP_VER -eq 6 ] && [ "$ra" = "server" ] ; then
577 # Note: dnsmasq cannot just be a DHCPv6 server (all-in-1)
578 # and let some other machine(s) send RA pointing to it.
579
580 case $ra_preference in
581 *high*)
582 xappend "--ra-param=$ifname,high,0,7200"
583 ;;
584 *low*)
585 xappend "--ra-param=$ifname,low,0,7200"
586 ;;
587 *)
588 # Send UNSOLICITED RA at default interval and live for 2 hours.
589 # TODO: convert flexible lease time into route life time (only seconds).
590 xappend "--ra-param=$ifname,0,7200"
591 ;;
592 esac
593
594 if [ "$dhcpv6" = "disabled" ] ; then
595 ra_management="3"
596 fi
597
598
599 case $ra_management in
600 0)
601 # SLACC with DCHP for extended options
602 xappend "--dhcp-range=$nettag::,constructor:$ifname,ra-stateless,ra-names"
603 ;;
604 2)
605 # DHCP address and RA only for management redirection
606 xappend "--dhcp-range=$nettag$dhcp6range,constructor:$ifname,$leasetime"
607 ;;
608 3)
609 # SLAAC only but dnsmasq attempts to link HOSTNAME, DHCPv4 MAC, and SLAAC
610 xappend "--dhcp-range=$nettag::,constructor:$ifname,ra-only,ra-names"
611 ;;
612 *)
613 # SLAAC and full DHCP
614 xappend "--dhcp-range=$nettag$dhcp6range,constructor:$ifname,slaac,ra-names,$leasetime"
615 ;;
616 esac
617
618 if [ -n "$dns" ]; then
619 dnss=""
620 for d in $dns; do append dnss "[$d]" ","; done
621 else
622 dnss="[::]"
623 fi
624
625 dhcp_option_append "option6:dns-server,$dnss" "$networkid"
626 fi
627
628 dhcp_option_add "$cfg" "$networkid" 0
629 dhcp_option_add "$cfg" "$networkid" 2
630 }
631
632 dhcp_option_append() {
633 local option="$1"
634 local networkid="$2"
635 local force="$3"
636
637 xappend "--dhcp-option${force:+-force}=${networkid:+$networkid,}$option"
638 }
639
640 dhcp_option_add() {
641 # NOTE: dnsmasq has explicit "option6:" prefix for DHCPv6 so no collisions
642 local cfg="$1"
643 local networkid="$2"
644 local force="$3"
645 local opt="dhcp_option"
646
647 [ "$force" = "0" ] && force=
648 [ "$force" = "2" ] && opt="dhcp_option_force"
649
650 local list_len
651 config_get list_len "$cfg" "${opt}_LENGTH"
652
653 if [ -n "$list_len" ]; then
654 config_list_foreach "$cfg" "$opt" dhcp_option_append "$networkid" "$force"
655 else
656 config_get dhcp_option "$cfg" "$opt"
657
658 [ -n "$dhcp_option" ] && echo "Warning: the 'option $opt' syntax is deprecated, use 'list $opt'" >&2
659
660 local option
661 for option in $dhcp_option; do
662 dhcp_option_append "$option" "$networkid" "$force"
663 done
664 fi
665 }
666
667 dhcp_domain_add() {
668 local cfg="$1"
669 local ip name names record
670
671 config_get names "$cfg" name "$2"
672 [ -n "$names" ] || return 0
673
674 config_get ip "$cfg" ip "$3"
675 [ -n "$ip" ] || return 0
676
677 for name in $names; do
678 record="${record:+$record }$name"
679 done
680
681 echo "$ip $record" >> $HOSTFILE_TMP
682 }
683
684 dhcp_srv_add() {
685 local cfg="$1"
686
687 config_get srv "$cfg" srv
688 [ -n "$srv" ] || return 0
689
690 config_get target "$cfg" target
691 [ -n "$target" ] || return 0
692
693 config_get port "$cfg" port
694 [ -n "$port" ] || return 0
695
696 config_get class "$cfg" class
697 config_get weight "$cfg" weight
698
699 local service="$srv,$target,$port${class:+,$class${weight:+,$weight}}"
700
701 xappend "--srv-host=$service"
702 }
703
704 dhcp_mx_add() {
705 local cfg="$1"
706 local domain relay pref
707
708 config_get domain "$cfg" domain
709 [ -n "$domain" ] || return 0
710
711 config_get relay "$cfg" relay
712 [ -n "$relay" ] || return 0
713
714 config_get pref "$cfg" pref 0
715
716 local service="$domain,$relay,$pref"
717
718 xappend "--mx-host=$service"
719 }
720
721 dhcp_cname_add() {
722 local cfg="$1"
723 local cname target
724
725 config_get cname "$cfg" cname
726 [ -n "$cname" ] || return 0
727
728 config_get target "$cfg" target
729 [ -n "$target" ] || return 0
730
731 xappend "--cname=${cname},${target}"
732 }
733
734 dhcp_hostrecord_add() {
735 local cfg="$1"
736 local names addresses record val
737
738 config_get names "$cfg" name "$2"
739 if [ -z "$names" ]; then
740 return 0
741 fi
742
743 config_get addresses "$cfg" ip "$3"
744 if [ -z "$addresses" ]; then
745 return 0
746 fi
747
748 for val in $names $addresses; do
749 record="${record:+$record,}$val"
750 done
751
752 xappend "--host-record=$record"
753 }
754
755 dhcp_relay_add() {
756 local cfg="$1"
757 local local_addr server_addr interface
758
759 config_get local_addr "$cfg" local_addr
760 [ -n "$local_addr" ] || return 0
761
762 config_get server_addr "$cfg" server_addr
763 [ -n "$server_addr" ] || return 0
764
765 config_get interface "$cfg" interface
766 if [ -z "$interface" ]; then
767 xappend "--dhcp-relay=$local_addr,$server_addr"
768 else
769 network_get_device ifname "$interface" || return
770 xappend "--dhcp-relay=$local_addr,$server_addr,$ifname"
771 fi
772 }
773
774 dnsmasq_ipset_add() {
775 local cfg="$1"
776 local ipsets domains
777
778 add_ipset() {
779 ipsets="${ipsets:+$ipsets,}$1"
780 }
781
782 add_domain() {
783 # leading '/' is expected
784 domains="$domains/$1"
785 }
786
787 config_list_foreach "$cfg" "name" add_ipset
788 config_list_foreach "$cfg" "domain" add_domain
789
790 if [ -z "$ipsets" ] || [ -z "$domains" ]; then
791 return 0
792 fi
793
794 xappend "--ipset=$domains/$ipsets"
795 }
796
797 dnsmasq_start()
798 {
799 local cfg="$1"
800 local disabled user_dhcpscript
801 local resolvfile resolvdir localuse=0
802
803 config_get_bool disabled "$cfg" disabled 0
804 [ "$disabled" -gt 0 ] && return 0
805
806 # reset list of DOMAINS and DNS servers (for each dnsmasq instance)
807 DNS_SERVERS=""
808 DOMAIN=""
809 CONFIGFILE="${BASECONFIGFILE}.${cfg}"
810 CONFIGFILE_TMP="${CONFIGFILE}.$$"
811 HOSTFILE="${BASEHOSTFILE}.${cfg}"
812 HOSTFILE_TMP="${HOSTFILE}.$$"
813 BASEDHCPSTAMPFILE_CFG="${BASEDHCPSTAMPFILE}.${cfg}"
814
815 # before we can call xappend
816 mkdir -p /var/run/dnsmasq/
817 mkdir -p $(dirname $CONFIGFILE)
818 mkdir -p $(dirname $HOSTFILE)
819 mkdir -p /var/lib/misc
820 chown dnsmasq:dnsmasq /var/run/dnsmasq
821
822 echo "# auto-generated config file from /etc/config/dhcp" > $CONFIGFILE_TMP
823 echo "# auto-generated config file from /etc/config/dhcp" > $HOSTFILE_TMP
824
825 local dnsmasqconffile="/etc/dnsmasq.${cfg}.conf"
826 if [ ! -r "$dnsmasqconffile" ]; then
827 dnsmasqconffile=/etc/dnsmasq.conf
828 fi
829
830 # if we did this last, we could override auto-generated config
831 [ -f "${dnsmasqconffile}" ] && {
832 xappend "--conf-file=${dnsmasqconffile}"
833 }
834
835 $PROG --version | grep -osqE "^Compile time options:.* DHCPv6( |$)" && DHCPv6CAPABLE=1 || DHCPv6CAPABLE=0
836
837
838 if [ -x /usr/sbin/odhcpd ] && [ -x /etc/init.d/odhcpd ] ; then
839 local odhcpd_is_main odhcpd_is_enabled
840 config_get odhcpd_is_main odhcpd maindhcp 0
841 /etc/init.d/odhcpd enabled && odhcpd_is_enabled=1 || odhcpd_is_enabled=0
842
843
844 if [ "$odhcpd_is_enabled" -eq 0 ] && [ "$DHCPv6CAPABLE" -eq 1 ] ; then
845 # DHCP V4 and V6 in DNSMASQ
846 DNSMASQ_DHCP_VER=6
847 elif [ "$odhcpd_is_main" -gt 0 ] ; then
848 # ODHCPD is doing it all
849 DNSMASQ_DHCP_VER=0
850 else
851 # You have ODHCPD but use DNSMASQ for DHCPV4
852 DNSMASQ_DHCP_VER=4
853 fi
854
855 elif [ "$DHCPv6CAPABLE" -eq 1 ] ; then
856 # DHCP V4 and V6 in DNSMASQ
857 DNSMASQ_DHCP_VER=6
858 else
859 DNSMASQ_DHCP_VER=4
860 fi
861
862 # Allow DHCP/DHCPv6 to be handled by ISC DHCPD
863 if [ -x /usr/sbin/dhcpd ] ; then
864 if [ -x /etc/init.d/dhcpd ] ; then
865 /etc/init.d/dhcpd enabled && DNSMASQ_DHCP_VER=0
866 fi
867 if [ -x /etc/init.d/dhcpd6 ] && [ "$DNSMASQ_DHCP_VER" -gt 0 ] ; then
868 /etc/init.d/dhcpd6 enabled && DNSMASQ_DHCP_VER=4
869 fi
870 fi
871
872 append_bool "$cfg" authoritative "--dhcp-authoritative"
873 append_bool "$cfg" nodaemon "--no-daemon"
874 append_bool "$cfg" domainneeded "--domain-needed"
875 append_bool "$cfg" filterwin2k "--filterwin2k"
876 append_bool "$cfg" nohosts "--no-hosts"
877 append_bool "$cfg" nonegcache "--no-negcache"
878 append_bool "$cfg" strictorder "--strict-order"
879 append_bool "$cfg" logqueries "--log-queries=extra"
880 append_bool "$cfg" noresolv "--no-resolv"
881 append_bool "$cfg" localise_queries "--localise-queries"
882 append_bool "$cfg" readethers "--read-ethers"
883
884 local instance_name="dnsmasq.$cfg"
885 if [ "$cfg" = "$DEFAULT_INSTANCE" ]; then
886 instance_name="dnsmasq"
887 fi
888 config_get_bool dbus "$cfg" "dbus" 0
889 [ $dbus -gt 0 ] && xappend "--enable-dbus=uk.org.thekelleys.$instance_name"
890 config_get_bool ubus "$cfg" "ubus" 1
891 [ $ubus -gt 0 ] && xappend "--enable-ubus=$instance_name"
892
893 append_bool "$cfg" expandhosts "--expand-hosts"
894 config_get tftp_root "$cfg" "tftp_root"
895 [ -n "$tftp_root" ] && mkdir -p "$tftp_root" && append_bool "$cfg" enable_tftp "--enable-tftp"
896 append_bool "$cfg" tftp_no_fail "--tftp-no-fail"
897 append_bool "$cfg" nonwildcard "--bind-dynamic" 1
898 append_bool "$cfg" fqdn "--dhcp-fqdn"
899 append_bool "$cfg" proxydnssec "--proxy-dnssec"
900 append_bool "$cfg" localservice "--local-service"
901 append_bool "$cfg" logdhcp "--log-dhcp"
902 append_bool "$cfg" quietdhcp "--quiet-dhcp"
903 append_bool "$cfg" sequential_ip "--dhcp-sequential-ip"
904 append_bool "$cfg" allservers "--all-servers"
905 append_bool "$cfg" noping "--no-ping"
906 append_bool "$cfg" rapidcommit "--dhcp-rapid-commit"
907 append_bool "$cfg" scriptarp "--script-arp"
908
909 append_parm "$cfg" logfacility "--log-facility"
910
911 append_parm "$cfg" cachesize "--cache-size"
912 append_parm "$cfg" dnsforwardmax "--dns-forward-max"
913 append_parm "$cfg" port "--port"
914 append_parm "$cfg" ednspacket_max "--edns-packet-max"
915 append_parm "$cfg" dhcpleasemax "--dhcp-lease-max"
916 append_parm "$cfg" "queryport" "--query-port"
917 append_parm "$cfg" "minport" "--min-port"
918 append_parm "$cfg" "maxport" "--max-port"
919 append_parm "$cfg" "domain" "--domain"
920 append_parm "$cfg" "local" "--local"
921 config_list_foreach "$cfg" "listen_address" append_listenaddress
922 config_list_foreach "$cfg" "server" append_server
923 config_list_foreach "$cfg" "rev_server" append_rev_server
924 config_list_foreach "$cfg" "address" append_address
925 config_list_foreach "$cfg" "ipset" append_ipset
926 [ -n "$BOOT" ] || {
927 config_list_foreach "$cfg" "interface" append_interface
928 config_list_foreach "$cfg" "notinterface" append_notinterface
929 }
930 config_list_foreach "$cfg" "addnhosts" append_addnhosts
931 config_list_foreach "$cfg" "bogusnxdomain" append_bogusnxdomain
932 append_parm "$cfg" "leasefile" "--dhcp-leasefile" "/tmp/dhcp.leases"
933 append_parm "$cfg" "serversfile" "--servers-file"
934 append_parm "$cfg" "tftp_root" "--tftp-root"
935 append_parm "$cfg" "dhcp_boot" "--dhcp-boot"
936 append_parm "$cfg" "local_ttl" "--local-ttl"
937 append_parm "$cfg" "max_ttl" "--max-ttl"
938 append_parm "$cfg" "min_cache_ttl" "--min-cache-ttl"
939 append_parm "$cfg" "max_cache_ttl" "--max-cache-ttl"
940 append_parm "$cfg" "pxe_prompt" "--pxe-prompt"
941 append_parm "$cfg" "tftp_unique_root" "--tftp-unique-root"
942 config_list_foreach "$cfg" "pxe_service" append_pxe_service
943 config_get DOMAIN "$cfg" domain
944
945 config_get_bool ADD_LOCAL_DOMAIN "$cfg" add_local_domain 1
946 config_get_bool ADD_LOCAL_HOSTNAME "$cfg" add_local_hostname 1
947 config_get ADD_LOCAL_FQDN "$cfg" add_local_fqdn ""
948 config_get ADD_WAN_FQDN "$cfg" add_wan_fqdn 0
949
950 if [ -z "$ADD_LOCAL_FQDN" ] ; then
951 # maintain support for previous UCI
952 ADD_LOCAL_FQDN="$ADD_LOCAL_HOSTNAME"
953 fi
954
955 config_get user_dhcpscript $cfg dhcpscript
956 if has_handler || [ -n "$user_dhcpscript" ]; then
957 xappend "--dhcp-script=$DHCPSCRIPT"
958 xappend "--script-arp"
959 fi
960
961 config_get leasefile $cfg leasefile "/tmp/dhcp.leases"
962 [ -n "$leasefile" ] && [ ! -e "$leasefile" ] && touch "$leasefile"
963 config_get_bool cachelocal "$cfg" cachelocal 1
964
965 config_get_bool noresolv "$cfg" noresolv 0
966 if [ "$noresolv" != "1" ]; then
967 config_get resolvfile "$cfg" resolvfile /tmp/resolv.conf.d/resolv.conf.auto
968 [ -n "$resolvfile" ] && [ ! -e "$resolvfile" ] && touch "$resolvfile"
969 xappend "--resolv-file=$resolvfile"
970 [ "$resolvfile" = "/tmp/resolv.conf.d/resolv.conf.auto" ] && localuse=1
971 resolvdir="$(dirname "$resolvfile")"
972 fi
973 config_get_bool localuse "$cfg" localuse "$localuse"
974
975 config_get hostsfile "$cfg" dhcphostsfile
976 [ -e "$hostsfile" ] && xappend "--dhcp-hostsfile=$hostsfile"
977
978 local rebind
979 config_get_bool rebind "$cfg" rebind_protection 1
980 [ $rebind -gt 0 ] && {
981 log_once \
982 "DNS rebinding protection is active," \
983 "will discard upstream RFC1918 responses!"
984 xappend "--stop-dns-rebind"
985
986 local rebind_localhost
987 config_get_bool rebind_localhost "$cfg" rebind_localhost 0
988 [ $rebind_localhost -gt 0 ] && {
989 log_once "Allowing 127.0.0.0/8 responses"
990 xappend "--rebind-localhost-ok"
991 }
992
993 append_rebind_domain() {
994 log_once "Allowing RFC1918 responses for domain $1"
995 xappend "--rebind-domain-ok=$1"
996 }
997
998 config_list_foreach "$cfg" rebind_domain append_rebind_domain
999 }
1000
1001 config_get_bool dnssec "$cfg" dnssec 0
1002 [ "$dnssec" -gt 0 ] && {
1003 xappend "--conf-file=$TRUSTANCHORSFILE"
1004 xappend "--dnssec"
1005 [ -x /etc/init.d/sysntpd ] && {
1006 if /etc/init.d/sysntpd enabled || [ "$(uci_get system.ntp.enabled)" = "1" ] ; then
1007 [ -f "$TIMEVALIDFILE" ] || xappend "--dnssec-no-timecheck"
1008 fi
1009 }
1010 config_get_bool dnsseccheckunsigned "$cfg" dnsseccheckunsigned 1
1011 [ "$dnsseccheckunsigned" -eq 0 ] && xappend "--dnssec-check-unsigned=no"
1012 }
1013
1014 config_get addmac "$cfg" addmac 0
1015 [ "$addmac" != "0" ] && {
1016 [ "$addmac" = "1" ] && addmac=
1017 xappend "--add-mac${addmac:+="$addmac"}"
1018 }
1019
1020 dhcp_option_add "$cfg" "" 0
1021 dhcp_option_add "$cfg" "" 2
1022
1023 xappend "--dhcp-broadcast=tag:needs-broadcast"
1024
1025 config_get_bool ignore_hosts_dir "$cfg" ignore_hosts_dir 0
1026 if [ "$ignore_hosts_dir" = "1" ]; then
1027 xappend "--addn-hosts=$HOSTFILE"
1028 else
1029 xappend "--addn-hosts=$(dirname $HOSTFILE)"
1030 fi
1031
1032 config_get dnsmasqconfdir "$cfg" confdir "/tmp/dnsmasq.d"
1033 xappend "--conf-dir=$dnsmasqconfdir"
1034 dnsmasqconfdir="${dnsmasqconfdir%%,*}"
1035 [ ! -d "$dnsmasqconfdir" ] && mkdir -p $dnsmasqconfdir
1036 xappend "--user=dnsmasq"
1037 xappend "--group=dnsmasq"
1038 echo >> $CONFIGFILE_TMP
1039
1040 config_get_bool enable_tftp "$cfg" enable_tftp 0
1041 [ "$enable_tftp" -gt 0 ] && {
1042 config_get tftp_root "$cfg" tftp_root
1043 append EXTRA_MOUNT $tftp_root
1044 }
1045
1046 config_foreach filter_dnsmasq host dhcp_host_add "$cfg"
1047 echo >> $CONFIGFILE_TMP
1048
1049 config_get_bool dhcpbogushostname "$cfg" dhcpbogushostname 1
1050 [ "$dhcpbogushostname" -gt 0 ] && {
1051 xappend "--dhcp-ignore-names=tag:dhcp_bogus_hostname"
1052 [ -r "$DHCPBOGUSHOSTNAMEFILE" ] && xappend "--conf-file=$DHCPBOGUSHOSTNAMEFILE"
1053 }
1054
1055 config_foreach filter_dnsmasq boot dhcp_boot_add "$cfg"
1056 config_foreach filter_dnsmasq mac dhcp_mac_add "$cfg"
1057 config_foreach filter_dnsmasq tag dhcp_tag_add "$cfg"
1058 config_foreach filter_dnsmasq vendorclass dhcp_vendorclass_add "$cfg"
1059 config_foreach filter_dnsmasq userclass dhcp_userclass_add "$cfg"
1060 config_foreach filter_dnsmasq circuitid dhcp_circuitid_add "$cfg"
1061 config_foreach filter_dnsmasq remoteid dhcp_remoteid_add "$cfg"
1062 config_foreach filter_dnsmasq subscrid dhcp_subscrid_add "$cfg"
1063 config_foreach filter_dnsmasq match dhcp_match_add "$cfg"
1064 config_foreach filter_dnsmasq domain dhcp_domain_add "$cfg"
1065 config_foreach filter_dnsmasq hostrecord dhcp_hostrecord_add "$cfg"
1066 [ -n "$BOOT" ] || config_foreach filter_dnsmasq relay dhcp_relay_add "$cfg"
1067
1068 echo >> $CONFIGFILE_TMP
1069 config_foreach filter_dnsmasq srvhost dhcp_srv_add "$cfg"
1070 config_foreach filter_dnsmasq mxhost dhcp_mx_add "$cfg"
1071 echo >> $CONFIGFILE_TMP
1072
1073 config_get_bool boguspriv "$cfg" boguspriv 1
1074 [ "$boguspriv" -gt 0 ] && {
1075 xappend "--bogus-priv"
1076 [ -r "$RFC6761FILE" ] && xappend "--conf-file=$RFC6761FILE"
1077 }
1078
1079 if [ "$DNSMASQ_DHCP_VER" -gt 4 ] ; then
1080 # Enable RA feature for when/if it is constructed,
1081 # and RA is selected per interface pool (RA, DHCP, or both),
1082 # but no one (should) want RA broadcast in syslog
1083 [ -n "$BOOT" ] || config_foreach filter_dnsmasq dhcp dhcp_add "$cfg"
1084 xappend "--enable-ra"
1085 xappend "--quiet-ra"
1086 append_bool "$cfg" quietdhcp "--quiet-dhcp6"
1087
1088 elif [ "$DNSMASQ_DHCP_VER" -gt 0 ] ; then
1089 [ -n "$BOOT" ] || config_foreach filter_dnsmasq dhcp dhcp_add "$cfg"
1090 fi
1091
1092
1093 echo >> $CONFIGFILE_TMP
1094 config_foreach filter_dnsmasq cname dhcp_cname_add "$cfg"
1095 echo >> $CONFIGFILE_TMP
1096
1097 echo >> $CONFIGFILE_TMP
1098 config_foreach filter_dnsmasq ipset dnsmasq_ipset_add "$cfg"
1099 echo >> $CONFIGFILE_TMP
1100
1101 echo >> $CONFIGFILE_TMP
1102 mv -f $CONFIGFILE_TMP $CONFIGFILE
1103 mv -f $HOSTFILE_TMP $HOSTFILE
1104
1105 [ "$localuse" -gt 0 ] && {
1106 rm -f /tmp/resolv.conf
1107 [ $ADD_LOCAL_DOMAIN -eq 1 ] && [ -n "$DOMAIN" ] && {
1108 echo "search $DOMAIN" >> /tmp/resolv.conf
1109 }
1110 DNS_SERVERS="$DNS_SERVERS 127.0.0.1"
1111 [ -e /proc/sys/net/ipv6 ] && DNS_SERVERS="$DNS_SERVERS ::1"
1112 for DNS_SERVER in $DNS_SERVERS ; do
1113 echo "nameserver $DNS_SERVER" >> /tmp/resolv.conf
1114 done
1115 }
1116
1117 procd_open_instance $cfg
1118 procd_set_param command $PROG -C $CONFIGFILE -k -x /var/run/dnsmasq/dnsmasq."${cfg}".pid
1119 procd_set_param file $CONFIGFILE
1120 [ -n "$user_dhcpscript" ] && procd_set_param env USER_DHCPSCRIPT="$user_dhcpscript"
1121 procd_set_param respawn
1122
1123 procd_add_jail dnsmasq ubus log
1124 procd_add_jail_mount $CONFIGFILE $TRUSTANCHORSFILE $HOSTFILE $RFC6761FILE
1125 procd_add_jail_mount $EXTRA_MOUNT $DHCPBOGUSHOSTNAMEFILE $DHCPSCRIPT $DHCPSCRIPT_DEPENDS
1126 procd_add_jail_mount $dnsmasqconffile $dnsmasqconfdir $resolvdir $user_dhcpscript
1127 procd_add_jail_mount /dev/null /dev/urandom
1128 procd_add_jail_mount /etc/passwd /etc/group /etc/TZ /etc/hosts /etc/ethers
1129 procd_add_jail_mount_rw /var/run/dnsmasq/ $leasefile
1130
1131 procd_close_instance
1132 }
1133
1134 dnsmasq_stop()
1135 {
1136 local cfg="$1"
1137 local noresolv resolvfile localuse=0
1138
1139 config_get_bool noresolv "$cfg" noresolv 0
1140 config_get resolvfile "$cfg" "resolvfile"
1141
1142 [ "$noresolv" = 0 ] && [ "$resolvfile" = "/tmp/resolv.conf.d/resolv.conf.auto" ] && localuse=1
1143 config_get_bool localuse "$cfg" localuse "$localuse"
1144 [ "$localuse" -gt 0 ] && ln -sf "/tmp/resolv.conf.d/resolv.conf.auto" /tmp/resolv.conf
1145
1146 rm -f ${BASEDHCPSTAMPFILE}.${cfg}.*.dhcp
1147 }
1148
1149 add_interface_trigger()
1150 {
1151 local interface ignore
1152
1153 config_get interface "$1" interface
1154 config_get_bool ignore "$1" ignore 0
1155
1156 [ -n "$interface" ] && [ $ignore -eq 0 ] && procd_add_interface_trigger "interface.*" "$interface" /etc/init.d/dnsmasq reload
1157 }
1158
1159 service_triggers()
1160 {
1161 procd_add_reload_trigger "dhcp" "system"
1162
1163 config_load dhcp
1164 config_foreach add_interface_trigger dhcp
1165 config_foreach add_interface_trigger relay
1166 }
1167
1168 boot()
1169 {
1170 BOOT=1
1171 start "$@"
1172 }
1173
1174 start_service() {
1175 local instance="$1"
1176 local instance_found=0
1177 local first_instance=""
1178
1179 . /lib/functions/network.sh
1180
1181 config_cb() {
1182 local type="$1"
1183 local name="$2"
1184 if [ "$type" = "dnsmasq" ]; then
1185 if [ -n "$instance" ] && [ "$instance" = "$name" ]; then
1186 instance_found=1
1187 fi
1188 if [ -z "$DEFAULT_INSTANCE" ]; then
1189 local disabled
1190 config_get_bool disabled "$name" disabled 0
1191 if [ "$disabled" -eq 0 ]; then
1192 # First enabled section will be assigned default instance name.
1193 # Unnamed sections get precedence over named sections.
1194 if expr "$cfg" : 'cfg[0-9a-f]*$' >/dev/null = "9"; then # See uci_fixup_section.
1195 DEFAULT_INSTANCE="$name" # Unnamed config section.
1196 elif [ -z "$first_instance" ]; then
1197 first_instance="$name"
1198 fi
1199 fi
1200 fi
1201 fi
1202 }
1203
1204 DEFAULT_INSTANCE=""
1205 config_load dhcp
1206 if [ -z "$DEFAULT_INSTANCE" ]; then
1207 DEFAULT_INSTANCE="$first_instance" # No unnamed config section was found.
1208 fi
1209
1210 if [ -n "$instance" ]; then
1211 [ "$instance_found" -gt 0 ] || return
1212 dnsmasq_start "$instance"
1213 else
1214 config_foreach dnsmasq_start dnsmasq
1215 fi
1216 }
1217
1218 reload_service() {
1219 rc_procd start_service "$@"
1220 procd_send_signal dnsmasq "$@"
1221 }
1222
1223 stop_service() {
1224 local instance="$1"
1225 local instance_found=0
1226
1227 config_cb() {
1228 local type="$1"
1229 local name="$2"
1230 if [ "$type" = "dnsmasq" ]; then
1231 if [ -n "$instance" ] && [ "$instance" = "$name" ]; then
1232 instance_found=1
1233 fi
1234 fi
1235 }
1236
1237 config_load dhcp
1238
1239 if [ -n "$instance" ]; then
1240 [ "$instance_found" -gt 0 ] || return
1241 dnsmasq_stop "$instance"
1242 else
1243 config_foreach dnsmasq_stop dnsmasq
1244 fi
1245 }