[package] do not ignore enabled option in init script, bump release number (#6072)
[packages.git] / net / miniupnpd / files / miniupnpd.init
index 33f6b5b..4705fc8 100644 (file)
@@ -1,37 +1,88 @@
 #!/bin/sh /etc/rc.common
 START=95
+
 start() {
        config_load "upnpd"
+       local extiface intiface upload download logging secure enabled
+
+       config_get extiface config external_iface
+       config_get intiface config internal_iface
+       config_get upload   config upload
+       config_get download config download
+       config_get_bool logging config log_output 0
+       config_get_bool secure config secure_mode 0
+       config_get_bool enabled config enabled 0 
+
        include /lib/network
        scan_interfaces
-       . /var/state/network
-       config_get ifname wan ifname
-       config_get ipaddr lan ipaddr
-       
-       echo "miniupnpd starting ..."
-       stop
-       iptables_init.sh
-       # get bitspeed information, if provided
-       config_get upnp_up_bitspeed config upload
-       config_get upnp_down_bitspeed config download
-       bitspeed_str=""
-       [ -n "$upnpd_up_bitspeed" ] && [ -n "$upnpd_down_bitspeed" ] && {
-               # covert to bytespeed
-               upnpd_up_bytespeed=$(($upnpd_up_bitspeed * 1024 / 8))
-               upnpd_down_bytespeed=$(($upnpd_down_bitspeed * 1024 / 8))
-               bitspeed_str="-B $upnpd_down_bytespeed $upnpd_up_bytespeed"
-       }
-       config_get log_output config log_output
-       if [ "$log_output" = "1" ]; then
-               miniupnpd -i "$ifname" -a "$ipaddr" -p 5000 -U $bitspeed_str -d | logger -t miniupnpd &
+
+       local ifname
+       config_get ifname ${extiface:-wan} ifname
+
+       if [ -n "$ifname" ]; then
+               local args="-i $ifname"
+               local iface
+
+               for iface in ${intiface:-lan}; do
+                       local ipaddr
+                       config_get ipaddr "$iface" ipaddr
+                       [ -n "$ipaddr" ] && append args "-a $ipaddr"
+               done
+
+               append args "-p 5000 -U"
+
+               [ -n "$upload" -a -n "$download" ] && \
+                       append args "-B $(($download * 1024 * 8)) $(($upload * 1024 * 8))"
+
+               [ "$secure" -gt 0 ] && \
+                       append args "-S"
+
+               if [ "$logging" = "1" ]; then
+                       [ "$enabled" -gt 0 ] && eval start-stop-daemon -S -x miniupnpd -- $args -d | logger -t miniupnpd &
+               else
+                       [ "$enabled" -gt 0 ] && eval start-stop-daemon -S -x miniupnpd -- $args 2>/dev/null
+               fi
+
+               # start firewall
+               local zone
+               config_load firewall
+               config_get zone core "${extiface:-wan}_zone"
+               [ -n "$zone" ] && \
+                       ACTION="add" ZONE="$zone" INTERFACE="${extiface:-wan}" DEVICE="$ifname" \
+                               . /etc/hotplug.d/firewall/50-miniupnpd 
        else
-               miniupnpd -i "$ifname" -a "$ipaddr" -p 5000 -U $bitspeed_str
+               logger -t "upnp daemon" "external interface not found, not starting"
        fi
 }
 
+clear_rule() {
+       local state="$1"
+       local ifname ipaddr
+
+       config_get ifname "$state" ifname
+       config_get ipaddr "$state" ipaddr
+
+       [ -n "$ifname" ] && [ -n "$ipaddr" ] && {
+               iptables -t nat -D prerouting_rule -i $ifname -d $ipaddr -j MINIUPNPD
+               iptables -t filter -D forwarding_rule -i $ifname ! -o $ifname -j MINIUPNPD
+               uci_revert_state upnpd "$state"
+               unset "CONFIG_${state}_ifname"
+               unset "CONFIG_${state}_ipaddr"
+       }
+}
+
 stop() {
-       pnpd_pid=$(cat /var/run/miniupnpd.pid) 2>&- >&-
-       iptables_flush.sh 2>&- >&-
-       kill $pnpd_pid 2>&-
-       iptables_removeall.sh 2>&- >&-
+       start-stop-daemon -K -q -x miniupnpd -p /var/run/miniupnpd.pid
+       rm -f /var/run/miniupnpd.pid
+
+       logger -t "upnp" "removing firewall rules"
+
+       config_load upnpd
+       config_foreach clear_rule firewall
+
+       iptables -t nat -F MINIUPNPD 2>/dev/null
+       iptables -t nat -X MINIUPNPD 2>/dev/null
+       iptables -t filter -F MINIUPNPD 2>/dev/null
+       iptables -t filter -X MINIUPNPD 2>/dev/null
 }
+