You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

253 lines
5.9 KiB

  1. #!/bin/sh /etc/rc.common
  2. # Copyright (C) 2008-2013 OpenWrt.org
  3. # Copyright (C) 2008 Jo-Philipp Wich
  4. # This is free software, licensed under the GNU General Public License v2.
  5. # See /LICENSE for more information.
  6. START=90
  7. STOP=10
  8. USE_PROCD=1
  9. PROG=/usr/sbin/openvpn
  10. LIST_SEP="
  11. "
  12. UCI_STARTED=
  13. UCI_DISABLED=
  14. append_param() {
  15. local s="$1"
  16. local v="$2"
  17. case "$v" in
  18. *_*_*_*) v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_} ;;
  19. *_*_*) v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_} ;;
  20. *_*) v=${v%%_*}-${v#*_} ;;
  21. esac
  22. echo -n "$v" >> "/var/etc/openvpn-$s.conf"
  23. return 0
  24. }
  25. append_bools() {
  26. local p; local v; local s="$1"; shift
  27. for p in $*; do
  28. config_get_bool v "$s" "$p"
  29. [ "$v" = 1 ] && append_param "$s" "$p" && echo >> "/var/etc/openvpn-$s.conf"
  30. done
  31. }
  32. append_params() {
  33. local p; local v; local s="$1"; shift
  34. for p in $*; do
  35. config_get v "$s" "$p"
  36. IFS="$LIST_SEP"
  37. for v in $v; do
  38. [ -n "$v" ] && [ "$p" != "push" ] && append_param "$s" "$p" && echo " $v" >> "/var/etc/openvpn-$s.conf"
  39. [ -n "$v" ] && [ "$p" = "push" ] && append_param "$s" "$p" && echo " \"$v\"" >> "/var/etc/openvpn-$s.conf"
  40. done
  41. unset IFS
  42. done
  43. }
  44. append_list() {
  45. local p; local v; local s="$1"; shift
  46. list_cb_append() {
  47. v="${v}:$1"
  48. }
  49. for p in $*; do
  50. unset v
  51. config_list_foreach "$s" "$p" list_cb_append
  52. [ -n "$v" ] && append_param "$s" "$p" && echo " ${v:1}" >> "/var/etc/openvpn-$s.conf"
  53. done
  54. }
  55. section_enabled() {
  56. config_get_bool enable "$1" 'enable' 0
  57. config_get_bool enabled "$1" 'enabled' 0
  58. [ $enable -gt 0 ] || [ $enabled -gt 0 ]
  59. }
  60. create_temp_file() {
  61. mkdir -p "$(dirname "$1")"
  62. rm -f "$1"
  63. touch "$1"
  64. chown root "$1"
  65. chmod 0600 "$1"
  66. }
  67. openvpn_get_dev() {
  68. local dev dev_type
  69. local name="$1"
  70. local conf="$2"
  71. # Do override only for configurations with config_file
  72. config_get config_file "$name" config
  73. [ -n "$config_file" ] || return
  74. # Check there is someething to override
  75. config_get dev "$name" dev
  76. config_get dev_type "$name" dev_type
  77. [ -n "$dev" ] || return
  78. # If there is a no dev_type, try to guess it
  79. if [ -z "$dev_type" ]; then
  80. . /lib/functions/openvpn.sh
  81. local odev odev_type
  82. get_openvpn_option "$conf" odev dev
  83. get_openvpn_option "$conf" odev_type dev-type
  84. [ -n "$odev_type" ] || odev_type="$odev"
  85. case "$odev_type" in
  86. tun*) dev_type="tun" ;;
  87. tap*) dev_type="tap" ;;
  88. *) return;;
  89. esac
  90. fi
  91. # Return overrides
  92. echo "--dev-type $dev_type --dev $dev"
  93. }
  94. openvpn_get_credentials() {
  95. local name="$1"
  96. local ret=""
  97. config_get cert_password "$name" cert_password
  98. config_get password "$name" password
  99. config_get username "$name" username
  100. if [ -n "$cert_password" ]; then
  101. create_temp_file /var/run/openvpn.$name.pass
  102. echo "$cert_password" > /var/run/openvpn.$name.pass
  103. ret=" --askpass /var/run/openvpn.$name.pass "
  104. fi
  105. if [ -n "$username" ]; then
  106. create_temp_file /var/run/openvpn.$name.userpass
  107. echo "$username" > /var/run/openvpn.$name.userpass
  108. echo "$password" >> /var/run/openvpn.$name.userpass
  109. ret=" --auth-user-pass /var/run/openvpn.$name.userpass "
  110. fi
  111. # Return overrides
  112. echo "$ret"
  113. }
  114. openvpn_add_instance() {
  115. local name="$1"
  116. local dir="$2"
  117. local conf="$3"
  118. local security="$4"
  119. local up="$5"
  120. local down="$6"
  121. procd_open_instance "$name"
  122. procd_set_param command "$PROG" \
  123. --syslog "openvpn($name)" \
  124. --status "/var/run/openvpn.$name.status" \
  125. --cd "$dir" \
  126. --config "$conf" \
  127. --up "/usr/libexec/openvpn-hotplug up $name" \
  128. --down "/usr/libexec/openvpn-hotplug down $name" \
  129. ${up:+--setenv user_up "$up"} \
  130. ${down:+--setenv user_down "$down"} \
  131. --script-security "${security:-2}" \
  132. $(openvpn_get_dev "$name" "$conf") \
  133. $(openvpn_get_credentials "$name" "$conf")
  134. procd_set_param file "$dir/$conf"
  135. procd_set_param term_timeout 15
  136. procd_set_param respawn
  137. procd_append_param respawn 3600
  138. procd_append_param respawn 5
  139. procd_append_param respawn -1
  140. procd_close_instance
  141. }
  142. start_instance() {
  143. local s="$1"
  144. config_get config "$s" config
  145. config="${config:+$(readlink -f "$config")}"
  146. section_enabled "$s" || {
  147. append UCI_DISABLED "$config" "$LIST_SEP"
  148. return 1
  149. }
  150. local up down script_security
  151. config_get up "$s" up
  152. config_get down "$s" down
  153. config_get script_security "$s" script_security
  154. [ ! -d "/var/run" ] && mkdir -p "/var/run"
  155. if [ ! -z "$config" ]; then
  156. append UCI_STARTED "$config" "$LIST_SEP"
  157. [ -n "$up" ] || get_openvpn_option "$config" up up
  158. [ -n "$down" ] || get_openvpn_option "$config" down down
  159. openvpn_add_instance "$s" "${config%/*}" "$config" "$script_security" "$up" "$down"
  160. return
  161. fi
  162. create_temp_file "/var/etc/openvpn-$s.conf"
  163. append_bools "$s" $OPENVPN_BOOLS
  164. append_params "$s" $OPENVPN_PARAMS
  165. append_list "$s" $OPENVPN_LIST
  166. openvpn_add_instance "$s" "/var/etc" "openvpn-$s.conf" "$script_security" "$up" "$down"
  167. }
  168. start_service() {
  169. local instance="$1"
  170. local instance_found=0
  171. config_cb() {
  172. local type="$1"
  173. local name="$2"
  174. if [ "$type" = "openvpn" ]; then
  175. if [ -n "$instance" -a "$instance" = "$name" ]; then
  176. instance_found=1
  177. fi
  178. fi
  179. }
  180. . /lib/functions/openvpn.sh
  181. . /usr/share/openvpn/openvpn.options
  182. config_load 'openvpn'
  183. if [ -n "$instance" ]; then
  184. [ "$instance_found" -gt 0 ] || return
  185. start_instance "$instance"
  186. else
  187. config_foreach start_instance 'openvpn'
  188. local path name up down
  189. for path in /etc/openvpn/*.conf; do
  190. if [ -f "$path" ]; then
  191. name="${path##*/}"; name="${name%.conf}"
  192. # don't start configs again that are already started by uci
  193. if echo "$UCI_STARTED" | grep -qxF "$path"; then
  194. continue
  195. # don't start configs which are set to disabled in uci
  196. elif echo "$UCI_DISABLED" | grep -qxF "$path"; then
  197. logger -t openvpn "$name.conf is disabled in /etc/config/openvpn"
  198. continue
  199. fi
  200. get_openvpn_option "$path" up up || up=""
  201. get_openvpn_option "$path" down down || down=""
  202. openvpn_add_instance "$name" "${path%/*}" "$path" "" "$up" "$down"
  203. fi
  204. done
  205. fi
  206. }
  207. service_triggers() {
  208. procd_add_reload_trigger openvpn
  209. }