You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

262 lines
7.6 KiB

  1. #!/bin/sh /etc/rc.common
  2. # Copyright 2019-2020 Stan Grishin (stangri@melmac.net)
  3. # shellcheck disable=SC2039,SC3043,SC3060
  4. PKG_VERSION='dev-test'
  5. # shellcheck disable=SC2034
  6. START=80
  7. # shellcheck disable=SC2034
  8. USE_PROCD=1
  9. if type extra_command 1>/dev/null 2>&1; then
  10. extra_command 'version' 'Show version information'
  11. else
  12. # shellcheck disable=SC2034
  13. EXTRA_COMMANDS='version'
  14. fi
  15. readonly PROG=/usr/sbin/https-dns-proxy
  16. readonly DEFAULT_BOOTSTRAP='1.1.1.1,1.0.0.1,2606:4700:4700::1111,2606:4700:4700::1001,8.8.8.8,8.8.4.4,2001:4860:4860::8888,2001:4860:4860::8844'
  17. dnsmasqConfig=''; forceDNS=''; forceDNSPorts='';
  18. str_contains() { [ -n "$2" ] && [ "${1//$2}" != "$1" ]; }
  19. is_mac_address() { expr "$1" : '[0-9A-F][0-9A-F]:[0-9A-F][0-9A-F]:[0-9A-F][0-9A-F]:[0-9A-F][0-9A-F]:[0-9A-F][0-9A-F]:[0-9A-F][0-9A-F]$' >/dev/null; }
  20. is_ipv4() { expr "$1" : '[0-9][0-9]*\.[0-9][0-9]*\.[0-9][0-9]*\.[0-9][0-9]*$' >/dev/null; }
  21. is_ipv6() { ! is_mac_address "$1" && str_contains "$1" ":"; }
  22. version() { echo "$PKG_VERSION"; }
  23. xappend() { param="$param $1"; }
  24. append_bool() {
  25. local section="$1"
  26. local option="$2"
  27. local value="$3"
  28. local default="${4:-0}"
  29. local _loctmp
  30. config_get_bool _loctmp "$section" "$option" "$default"
  31. [ "$_loctmp" -ne 0 ] && xappend "$value"
  32. }
  33. append_parm() {
  34. local section="$1"
  35. local option="$2"
  36. local switch="$3"
  37. local default="$4"
  38. local _loctmp
  39. config_get _loctmp "$section" "$option" "$default"
  40. [ -n "$_loctmp" ] && xappend "$switch $_loctmp"
  41. }
  42. append_counter() {
  43. local section="$1"
  44. local option="$2"
  45. local switch="$3"
  46. local default="${4:-0}"
  47. local _loctmp i
  48. config_get _loctmp "$section" "$option" "$default"
  49. # shellcheck disable=SC2086,SC2154
  50. for i in $(seq 1 $_loctmp); do
  51. xappend '-v'
  52. done
  53. }
  54. append_bootstrap() {
  55. local section="$1"
  56. local option="$2"
  57. local switch="$3"
  58. local default="$4"
  59. local _old_ifs="$IFS"
  60. local _loctmp _newtmp i
  61. config_get _loctmp "$section" "$option" "$default"
  62. [ -z "$_loctmp" ] && return 0
  63. IFS=" ,"
  64. for i in $_loctmp; do
  65. if { [ "$ipv6_resolvers_only" -eq 0 ] && is_ipv4 "$i"; } || \
  66. { [ "$ipv6_resolvers_only" -ne 0 ] && is_ipv6 "$i"; }; then
  67. [ -z "$_newtmp" ] && _newtmp="$i" || _newtmp="${_newtmp},${i}"
  68. fi
  69. done
  70. IFS="$_old_ifs"
  71. [ -n "$_newtmp" ] && xappend "$switch $_newtmp"
  72. [ "$ipv6_resolvers_only" -eq 0 ] && xappend '-4'
  73. }
  74. start_instance() {
  75. local cfg="$1" param listen_addr listen_port i ipv6_resolvers_only
  76. config_get_bool ipv6_resolvers_only "$cfg" 'use_ipv6_resolvers_only' '0'
  77. append_parm "$cfg" 'resolver_url' '-r'
  78. append_parm "$cfg" 'polling_interval' '-i'
  79. append_parm "$cfg" 'listen_addr' '-a' '127.0.0.1'
  80. append_parm "$cfg" 'listen_port' '-p' "$p"
  81. append_parm "$cfg" 'dscp_codepoint' '-c'
  82. append_bootstrap "$cfg" 'bootstrap_dns' '-b' "$DEFAULT_BOOTSTRAP"
  83. append_parm "$cfg" 'user' '-u' 'nobody'
  84. append_parm "$cfg" 'group' '-g' 'nogroup'
  85. append_parm "$cfg" 'proxy_server' '-t'
  86. append_parm "$cfg" 'logfile' '-l'
  87. append_bool "$cfg" 'use_http1' '-x'
  88. append_counter "$cfg" 'verbosity' '-v' '0'
  89. procd_open_instance
  90. # shellcheck disable=SC2086
  91. procd_set_param command $PROG $param
  92. procd_set_param stderr 1
  93. procd_set_param stdout 1
  94. procd_set_param respawn
  95. if [ "$forceDNS" -ne 0 ]; then
  96. procd_open_data
  97. json_add_array firewall
  98. for c in $forceDNSPorts; do
  99. if netstat -tuln | grep 'LISTEN' | grep ":${c}" >/dev/null 2>&1 || [ "$c" = "53" ]; then
  100. json_add_object ""
  101. json_add_string type redirect
  102. json_add_string target DNAT
  103. json_add_string src lan
  104. json_add_string proto "tcp udp"
  105. json_add_string src_dport "$c"
  106. json_add_string dest_port "$c"
  107. json_add_boolean reflection 0
  108. json_close_object
  109. else
  110. json_add_object ""
  111. json_add_string type rule
  112. json_add_string src lan
  113. json_add_string dest "*"
  114. json_add_string proto "tcp udp"
  115. json_add_string dest_port "$c"
  116. json_add_string target REJECT
  117. json_close_object
  118. fi
  119. done
  120. json_close_array
  121. procd_close_data
  122. forceDNS='0'
  123. fi
  124. procd_close_instance
  125. config_get listen_addr "$cfg" 'listen_addr' '127.0.0.1'
  126. config_get listen_port "$cfg" 'listen_port' "$p"
  127. if [ "$dnsmasqConfig" = "*" ]; then
  128. config_load 'dhcp'
  129. config_foreach dnsmasq_add_doh_server 'dnsmasq' "${listen_addr}" "${listen_port}"
  130. elif [ -n "$dnsmasqConfig" ]; then
  131. for i in $dnsmasqConfig; do
  132. dnsmasq_add_doh_server "@dnsmasq[${i}]" "${listen_addr}" "${listen_port}"
  133. done
  134. fi
  135. p="$((p+1))"
  136. }
  137. is_force_dns_active() { iptables-save | grep -q -w -- '--dport 53'; }
  138. start_service() {
  139. local p=5053 c
  140. config_load 'https-dns-proxy'
  141. config_get dnsmasqConfig 'config' 'update_dnsmasq_config' '*'
  142. config_get_bool forceDNS 'config' 'force_dns' '1'
  143. config_get forceDNSPorts 'config' 'force_dns_port' '53 853'
  144. dhcp_backup 'create'
  145. config_load 'https-dns-proxy'
  146. config_foreach start_instance 'https-dns-proxy'
  147. if [ -n "$(uci -q changes dhcp)" ]; then
  148. uci -q commit dhcp
  149. [ -x /etc/init.d/dnsmasq ] && /etc/init.d/dnsmasq restart >/dev/null 2>&1
  150. fi
  151. }
  152. stop_service() {
  153. config_load 'https-dns-proxy'
  154. config_get dnsmasqConfig 'config' 'update_dnsmasq_config' '*'
  155. dhcp_backup 'restore'
  156. if [ -n "$(uci -q changes dhcp)" ]; then
  157. uci -q commit dhcp
  158. [ -x /etc/init.d/dnsmasq ] && /etc/init.d/dnsmasq restart >/dev/null 2>&1
  159. fi
  160. }
  161. service_triggers() {
  162. procd_add_config_trigger "config.change" "https-dns-proxy" /etc/init.d/https-dns-proxy reload
  163. }
  164. service_started() { procd_set_config_changed firewall; }
  165. service_stopped() { procd_set_config_changed firewall; }
  166. dnsmasq_add_doh_server() {
  167. local cfg="$1" address="$2" port="$3"
  168. case $address in
  169. 0.0.0.0|::ffff:0.0.0.0) address='127.0.0.1';;
  170. ::) address='::1';;
  171. esac
  172. uci -q del_list "dhcp.${cfg}.server=${address}#${port}"
  173. uci -q add_list "dhcp.${cfg}.server=${address}#${port}"
  174. }
  175. dnsmasq_create_server_backup() {
  176. local cfg="$1"
  177. local i
  178. uci -q get "dhcp.${cfg}" >/dev/null || return 1
  179. if ! uci -q get "dhcp.${cfg}.doh_backup_noresolv" >/dev/null; then
  180. if [ -z "$(uci -q get "dhcp.${cfg}.noresolv")" ]; then
  181. uci -q set "dhcp.${cfg}.noresolv=1"
  182. uci -q set "dhcp.${cfg}.doh_backup_noresolv=-1"
  183. elif [ "$(uci -q get "dhcp.${cfg}.noresolv")" != "1" ]; then
  184. uci -q set "dhcp.${cfg}.noresolv=1"
  185. uci -q set "dhcp.${cfg}.doh_backup_noresolv=0"
  186. fi
  187. fi
  188. if ! uci -q get "dhcp.${cfg}.doh_backup_server" >/dev/null; then
  189. if [ -z "$(uci -q get "dhcp.${cfg}.server")" ]; then
  190. uci -q add_list "dhcp.${cfg}.doh_backup_server="
  191. fi
  192. for i in $(uci -q get "dhcp.${cfg}.server"); do
  193. uci -q add_list "dhcp.${cfg}.doh_backup_server=$i"
  194. if [ "$i" = "$(echo "$i" | tr -d /\#)" ]; then
  195. uci -q del_list "dhcp.${cfg}.server=$i"
  196. fi
  197. done
  198. fi
  199. return 0
  200. }
  201. dnsmasq_restore_server_backup() {
  202. local cfg="$1"
  203. local i
  204. uci -q get "dhcp.${cfg}" >/dev/null || return 0
  205. if uci -q get "dhcp.${cfg}.doh_backup_noresolv" >/dev/null; then
  206. if [ "$(uci -q get "dhcp.${cfg}.doh_backup_noresolv")" = "0" ]; then
  207. uci -q set "dhcp.${cfg}.noresolv=0"
  208. else
  209. uci -q del "dhcp.${cfg}.noresolv"
  210. fi
  211. uci -q del "dhcp.${cfg}.doh_backup_noresolv"
  212. fi
  213. if uci -q get "dhcp.${cfg}.doh_backup_server" >/dev/null; then
  214. uci -q del "dhcp.${cfg}.server"
  215. for i in $(uci -q get "dhcp.${cfg}.doh_backup_server"); do
  216. uci -q add_list "dhcp.${cfg}.server=$i"
  217. done
  218. uci -q del "dhcp.${cfg}.doh_backup_server"
  219. fi
  220. }
  221. dhcp_backup() {
  222. local i
  223. config_load 'dhcp'
  224. case "$1" in
  225. create)
  226. if [ "$dnsmasqConfig" = "*" ]; then
  227. config_foreach dnsmasq_create_server_backup 'dnsmasq'
  228. elif [ -n "$dnsmasqConfig" ]; then
  229. for i in $dnsmasqConfig; do
  230. dnsmasq_create_server_backup "@dnsmasq[${i}]" || \
  231. dnsmasq_create_server_backup "$i"
  232. done
  233. fi
  234. ;;
  235. restore)
  236. config_foreach dnsmasq_restore_server_backup 'dnsmasq'
  237. ;;
  238. esac
  239. }