You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

220 lines
6.0 KiB

  1. #!/bin/sh /etc/rc.common
  2. # Copyright 2019-2020 Stan Grishin (stangri@melmac.net)
  3. # shellcheck disable=SC2039
  4. PKG_VERSION='dev-test'
  5. # shellcheck disable=SC2034
  6. START=80
  7. # shellcheck disable=SC2034
  8. USE_PROCD=1
  9. if type extra_command 1>/dev/null 2>&1; then
  10. extra_command 'version' 'Show version information'
  11. else
  12. # shellcheck disable=SC2034
  13. EXTRA_COMMANDS='version'
  14. fi
  15. readonly PROG=/usr/sbin/https-dns-proxy
  16. dnsmasqConfig=''
  17. forceDNS='1'
  18. version() { echo "$PKG_VERSION"; }
  19. xappend() { param="$param $1"; }
  20. append_bool() {
  21. local section="$1"
  22. local option="$2"
  23. local value="$3"
  24. local default="$4"
  25. local _loctmp
  26. [ -z "$default" ] && default="0"
  27. config_get_bool _loctmp "$section" "$option" "$default"
  28. [ "$_loctmp" != "0" ] && xappend "$value"
  29. }
  30. append_parm() {
  31. local section="$1"
  32. local option="$2"
  33. local switch="$3"
  34. local default="$4"
  35. local _loctmp
  36. config_get _loctmp "$section" "$option" "$default"
  37. [ -z "$_loctmp" ] && return 0
  38. xappend "$switch $_loctmp"
  39. }
  40. start_instance() {
  41. local cfg="$1" param listen_addr listen_port i
  42. append_parm "$cfg" 'resolver_url' '-r'
  43. append_parm "$cfg" 'polling_interval' '-i'
  44. append_parm "$cfg" 'listen_addr' '-a' '127.0.0.1'
  45. append_parm "$cfg" 'listen_port' '-p' "$p"
  46. append_parm "$cfg" 'dscp_codepoint' '-c'
  47. append_parm "$cfg" 'bootstrap_dns' '-b'
  48. append_parm "$cfg" 'user' '-u' 'nobody'
  49. append_parm "$cfg" 'group' '-g' 'nogroup'
  50. append_parm "$cfg" 'proxy_server' '-t'
  51. append_parm "$cfg" 'logfile' '-l'
  52. append_bool "$cfg" 'use_http1' '-x'
  53. config_get_bool ipv6_resolvers_only "$cfg" 'use_ipv6_resolvers_only' '0'
  54. config_get verbosity "$cfg" 'verbosity' '0'
  55. # shellcheck disable=SC2086,SC2154
  56. for i in $(seq 1 $verbosity); do
  57. xappend '-v'
  58. done
  59. # shellcheck disable=SC2154
  60. if [ "$ipv6_resolvers_only" = 0 ]; then
  61. xappend '-4'
  62. fi
  63. procd_open_instance
  64. # shellcheck disable=SC2086
  65. procd_set_param command ${PROG} ${param}
  66. procd_set_param stderr 1
  67. procd_set_param stdout 1
  68. procd_set_param respawn
  69. procd_close_instance
  70. config_get listen_addr "$cfg" 'listen_addr' '127.0.0.1'
  71. config_get listen_port "$cfg" 'listen_port' "$p"
  72. if [ "$dnsmasqConfig" = "*" ]; then
  73. config_load 'dhcp'
  74. config_foreach dnsmasq_add_doh_server 'dnsmasq' "${listen_addr}" "${listen_port}"
  75. elif [ -n "$dnsmasqConfig" ]; then
  76. for i in $dnsmasqConfig; do
  77. dnsmasq_add_doh_server "@dnsmasq[${i}]" "${listen_addr}" "${listen_port}"
  78. done
  79. fi
  80. p="$((p+1))"
  81. }
  82. is_force_dns_active() { iptables-save | grep -q -w -- '--dport 53'; }
  83. start_service() {
  84. local p=5053
  85. config_load 'https-dns-proxy'
  86. config_get dnsmasqConfig 'config' 'update_dnsmasq_config' '*'
  87. config_get_bool forceDNS 'config' 'force_dns' '1'
  88. dhcp_backup 'create'
  89. config_load 'https-dns-proxy'
  90. config_foreach start_instance 'https-dns-proxy'
  91. if [ "$forceDNS" -ne 0 ]; then
  92. procd_open_instance 'main'
  93. procd_set_param command /bin/true
  94. procd_set_param stdout 1
  95. procd_set_param stderr 1
  96. procd_open_data
  97. json_add_array firewall
  98. json_add_object ''
  99. json_add_string type redirect
  100. json_add_string name https_dns_proxy_dns_redirect
  101. json_add_string target DNAT
  102. json_add_string src lan
  103. json_add_string proto tcpudp
  104. json_add_string src_dport 53
  105. json_add_string dest_port 53
  106. json_add_string reflection 0
  107. json_close_object
  108. json_close_array
  109. procd_close_data
  110. procd_close_instance
  111. fi
  112. if [ -n "$(uci -q changes dhcp)" ]; then
  113. uci -q commit dhcp
  114. [ -x /etc/init.d/dnsmasq ] && /etc/init.d/dnsmasq restart >/dev/null 2>&1
  115. fi
  116. }
  117. stop_service() {
  118. config_load 'https-dns-proxy'
  119. config_get dnsmasqConfig 'config' 'update_dnsmasq_config' '*'
  120. dhcp_backup 'restore'
  121. if [ -n "$(uci -q changes dhcp)" ]; then
  122. uci -q commit dhcp
  123. [ -x /etc/init.d/dnsmasq ] && /etc/init.d/dnsmasq restart >/dev/null 2>&1
  124. fi
  125. }
  126. service_triggers() {
  127. procd_add_config_trigger "config.change" "https-dns-proxy" /etc/init.d/https-dns-proxy reload
  128. }
  129. service_started() { procd_set_config_changed firewall; }
  130. service_stopped() { procd_set_config_changed firewall; }
  131. dnsmasq_add_doh_server() {
  132. local cfg="$1" address="$2" port="$3"
  133. case $address in
  134. 0.0.0.0|::ffff:0.0.0.0) address='127.0.0.1';;
  135. ::) address='::1';;
  136. esac
  137. uci -q del_list "dhcp.${cfg}.server=${address}#${port}"
  138. uci -q add_list "dhcp.${cfg}.server=${address}#${port}"
  139. }
  140. dnsmasq_create_server_backup() {
  141. local cfg="$1"
  142. local i
  143. uci -q get "dhcp.${cfg}" >/dev/null || return 0
  144. if ! uci -q get "dhcp.${cfg}.doh_backup_noresolv" >/dev/null; then
  145. if [ -z "$(uci -q get "dhcp.${cfg}.noresolv")" ]; then
  146. uci -q set "dhcp.${cfg}.noresolv=1"
  147. uci -q set "dhcp.${cfg}.doh_backup_noresolv=-1"
  148. elif [ "$(uci -q get "dhcp.${cfg}.noresolv")" != "1" ]; then
  149. uci -q set "dhcp.${cfg}.noresolv=1"
  150. uci -q set "dhcp.${cfg}.doh_backup_noresolv=0"
  151. fi
  152. fi
  153. if ! uci -q get "dhcp.${cfg}.doh_backup_server" >/dev/null; then
  154. for i in $(uci -q get "dhcp.${cfg}.server"); do
  155. uci -q add_list "dhcp.${cfg}.doh_backup_server=$i"
  156. if [ "$i" = "${i//127.0.0.1}" ] && [ "$i" = "$(echo "$i" | tr -d /)" ]; then
  157. uci -q del_list "dhcp.${cfg}.server=$i"
  158. fi
  159. done
  160. fi
  161. }
  162. dnsmasq_restore_server_backup() {
  163. local cfg="$1"
  164. local i
  165. uci -q get "dhcp.${cfg}" >/dev/null || return 0
  166. if uci -q get "dhcp.${cfg}.doh_backup_noresolv" >/dev/null; then
  167. if [ "$(uci -q get "dhcp.${cfg}.doh_backup_noresolv")" = "0" ]; then
  168. uci -q set "dhcp.${cfg}.noresolv=0"
  169. else
  170. uci -q del "dhcp.${cfg}.noresolv"
  171. fi
  172. uci -q del "dhcp.${cfg}.doh_backup_noresolv"
  173. fi
  174. if uci -q get "dhcp.${cfg}.doh_backup_server" >/dev/null; then
  175. uci -q del "dhcp.${cfg}.server"
  176. for i in $(uci -q get "dhcp.${cfg}.doh_backup_server"); do
  177. uci -q add_list "dhcp.${cfg}.server=$i"
  178. done
  179. uci -q del "dhcp.${cfg}.doh_backup_server"
  180. fi
  181. }
  182. dhcp_backup() {
  183. local i
  184. config_load 'dhcp'
  185. case "$1" in
  186. create)
  187. if [ "$dnsmasqConfig" = "*" ]; then
  188. config_foreach dnsmasq_create_server_backup 'dnsmasq'
  189. elif [ -n "$dnsmasqConfig" ]; then
  190. for i in $dnsmasqConfig; do
  191. dnsmasq_create_server_backup "@dnsmasq[${i}]"
  192. done
  193. fi
  194. ;;
  195. restore)
  196. config_foreach dnsmasq_restore_server_backup 'dnsmasq'
  197. ;;
  198. esac
  199. }