applications/luci-ffwizard-leipzig: prepare advanced firewall config and disable...
[project/luci.git] / applications / luci-ffwizard-leipzig / luasrc / model / cbi / ffwizard.lua
index cd737c9..6373c7a 100644 (file)
@@ -17,6 +17,7 @@ $Id$
 
 local uci = require "luci.model.uci".cursor()
 local tools = require "luci.tools.ffwizard"
+local util = require "luci.util"
 
 
 -------------------- View --------------------
@@ -33,11 +34,13 @@ uci:foreach("wireless", "wifi-device",
 
 main = f:field(Flag, "wifi", "Freifunkzugang einrichten")
 
-net = f:field(Value, "net", "Freifunknetz")
+net = f:field(Value, "net", "Freifunknetz", "1. Teil der IP-Adresse")
 net.rmempty = true
 net:depends("wifi", "1")
-net:value("104.61", "Leipzig (104.61)")
-net:value("104.62", "Halle (104.62)")
+uci:foreach("freifunk", "community", function(s)
+       net:value(s[".name"], "%s (%s)" % {s.name, s.prefix})
+end)
+
 function net.cfgvalue(self, section)
        return uci:get("freifunk", "wizard", "net")
 end
@@ -47,12 +50,9 @@ function net.write(self, section, value)
 end
 
 
-subnet = f:field(ListValue, "subnet", "Subnetz (Projekt)")
+subnet = f:field(Value, "subnet", "Subnetz (Projekt)", "2. Teil der IP-Adresse")
 subnet.rmempty = true
 subnet:depends("wifi", "1")
-for i=0, 255 do
-       subnet:value(i)
-end 
 function subnet.cfgvalue(self, section)
        return uci:get("freifunk", "wizard", "subnet")
 end
@@ -61,7 +61,7 @@ function subnet.write(self, section, value)
        uci:save("freifunk")
 end
 
-node = f:field(Value, "node", "Knoten")
+node = f:field(Value, "node", "Knoten", "3. Teil der IP-Adresse")
 node.rmempty = true
 node:depends("wifi", "1")
 for i=1, 51 do
@@ -77,14 +77,14 @@ end
 
 client = f:field(Flag, "client", "WLAN-DHCP anbieten")
 client:depends("wifi", "1")
+client.rmempty = true
 
 
 olsr = f:field(Flag, "olsr", "OLSR einrichten")
+olsr.rmempty = true
 
-share = f:field(ListValue, "sharenet", "Eigenen Internetzugang freigeben")
-share:value("maybe", "-- keine Aktion --")
-share:value("yes", "einschalten")
-share:value("no", "ausschalten")
+share = f:field(Flag, "sharenet", "Eigenen Internetzugang freigeben")
+share.rmempty = true
 
 
 
@@ -114,17 +114,22 @@ function main.write(self, section, value)
        if value == "0" then
                return
        end
-       
+
        local device = dev:formvalue(section)
+       local community, external
 
        -- Collect IP-Address
        local inet = net:formvalue(section)
        local isubnet = subnet:formvalue(section)
        local inode = node:formvalue(section)
-       
+
        -- Invalidate fields
        if not inet then
                net.tag_missing[section] = true
+       else
+               community = inet
+               external  = uci:get("freifunk", community, "external") or ""
+               inet = uci:get("freifunk", community, "prefix") or inet
        end
        if not isubnet then
                subnet.tag_missing[section] = true
@@ -132,54 +137,100 @@ function main.write(self, section, value)
        if not inode then
                node.tag_missing[section] = true
        end
-       
+
        if not inet or not isubnet or not inode then
                return
        end
-       
+
        local ip = "%s.%s.%s" % {inet, isubnet, inode}
-       
-       
+
+
        -- Cleanup
        tools.wifi_delete_ifaces(device)
        tools.network_remove_interface(device)
        tools.firewall_zone_remove_interface("freifunk", device)
-               
-       
+
+       -- Tune community settings
+       if community and uci:get("freifunk", community) then
+               uci:tset("freifunk", "community", uci:get_all("freifunk", community))
+       end
+
        -- Tune wifi device
-       local devconfig = _strip_internals(uci:get_all("freifunk", "wifi_device"))
+       local devconfig = uci:get_all("freifunk", "wifi_device")
+       util.update(devconfig, uci:get_all(external, "wifi_device") or {})
        uci:tset("wireless", device, devconfig)
-       
+
        -- Create wifi iface
-       local ifconfig = _strip_internals(uci:get_all("freifunk", "wifi_iface"))
+       local ifconfig = uci:get_all("freifunk", "wifi_iface")
+       util.update(ifconfig, uci:get_all(external, "wifi_iface") or {})
        ifconfig.device = device
+       ifconfig.network = device
+       ifconfig.ssid = uci:get("freifunk", community, "ssid")
        uci:section("wireless", "wifi-iface", nil, ifconfig)
-       
+
        -- Save wifi
-       uci:save("wireless")    
-       
+       uci:save("wireless")
+
        -- Create firewall zone and add default rules (first time)
-       local newzone = tools.firewall_create_zone("freifunk", "DROP", "ACCEPT", "DROP", true)
+       local newzone = tools.firewall_create_zone("freifunk", "REJECT", "ACCEPT", "REJECT", true)
        if newzone then
                uci:foreach("freifunk", "fw_forwarding", function(section)
-                       uci:section("firewall", "forwarding", nil, _strip_internals(section))
+                       uci:section("firewall", "forwarding", nil, section)
                end)
-               
+               uci:foreach(external, "fw_forwarding", function(section)
+                       uci:section("firewall", "forwarding", nil, section)
+               end)
+
                uci:foreach("freifunk", "fw_rule", function(section)
-                       uci:section("firewall", "rule", nil, _strip_internals(section))
+                       uci:section("firewall", "rule", nil, section)
                end)
-               
-               uci:save("firewall")
+               uci:foreach(external, "fw_rule", function(section)
+                       uci:section("firewall", "rule", nil, section)
+               end)
+       end
+
+       -- Enforce firewall include
+       local has_include = false
+       uci:foreach("firewall", "include",
+               function(section)
+                       if section.path == "/etc/firewall.freifunk" then
+                               has_include = true
+                       end
+               end)
+
+       if not has_include then
+               uci:section("firewall", "include", nil,
+                       { path = "/etc/firewall.freifunk" })
        end
-       
-       
+
+       -- Allow state: invalid packets
+       uci:foreach("firewall", "defaults",
+               function(section)
+                       uci:set("firewall", section[".name"], "drop_invalid", "0")
+               end)
+
+       -- Prepare advanced config
+       local has_advanced = false
+       uci:foreach("firewall", "advanced",
+               function(section) has_advanced = true end)
+
+       if not has_advanced then
+               uci:section("firewall", "advanced", nil,
+                       { tcp_ecn = "0" })
+       end
+
+       uci:save("firewall")
+
+
        -- Crate network interface
-       local netconfig = _strip_internals(uci:get_all("freifunk", "interface"))
+       local netconfig = uci:get_all("freifunk", "interface")
+       util.update(netconfig, uci:get_all(external, "interface") or {})
+       netconfig.proto = "static"
        netconfig.ipaddr = ip
        uci:section("network", "interface", device, netconfig)
-       
+
        uci:save("network")
-       
+
        tools.firewall_zone_add_interface("freifunk", device)
 end
 
@@ -188,28 +239,30 @@ function olsr.write(self, section, value)
        if value == "0" then
                return
        end
-       
+
+
        local device = dev:formvalue(section)
-       
+
+       local community = net:formvalue(section)
+       local external  = community and uci:get("freifunk", community, "external") or ""
+
        -- Delete old interface
-       uci:delete_all("freifunk", "Interface", {Interface=device})
-       
+       uci:delete_all("olsrd", "Interface", {interface=device})
+
        -- Write new interface
-       local olsrbase = _strip_internals(uci:get_all("freifunk", "olsr_interface"))
-       olsrbase.Interface = device
-       uci:section("olsr", "Interface", nil, olsrbase)
-       uci:save("olsr")
+       local olsrbase = uci:get_all("freifunk", "olsr_interface")
+       util.update(olsrbase, uci:get_all(external, "olsr_interface") or {})
+       olsrbase.interface = device
+       olsrbase.ignore    = "0"
+       uci:section("olsrd", "Interface", nil, olsrbase)
+       uci:save("olsrd")
 end
 
 
 function share.write(self, section, value)
-       if value == "maybe" then
-               return
-       end
-       
        uci:delete_all("firewall", "forwarding", {src="freifunk", dest="wan"})
-       
-       if value == "yes" then
+
+       if value == "1" then
                uci:section("firewall", "forwarding", nil, {src="freifunk", dest="wan"})
        end
        uci:save("firewall")
@@ -220,50 +273,81 @@ function client.write(self, section, value)
        if value == "0" then
                return
        end
-       
+
        local device = dev:formvalue(section)
 
        -- Collect IP-Address
        local inet = net:formvalue(section)
        local isubnet = subnet:formvalue(section)
        local inode = node:formvalue(section)
-       
+
        if not inet or not isubnet or not inode then
                return
        end
-       
-       local dhcpbeg = 48 + tonumber(inode) * 4 
+       local community = inet
+       local external  = community and uci:get("freifunk", community, "external") or ""
+       inet = uci:get("freifunk", community, "prefix") or inet
+
+       local dhcpbeg = 48 + tonumber(inode) * 4
        local dclient = "%s.%s.%s" % {inet:gsub("^[0-9]+", "10"), isubnet, dhcpbeg}
        local limit = dhcpbeg < 252 and 3 or 2
-       
+
        -- Delete old alias
        uci:delete("network", device .. "dhcp")
-       
+
        -- Create alias
-       local aliasbase = _strip_internals(uci:get_all("freifunk", "alias"))
+       local aliasbase = uci:get_all("freifunk", "alias")
+       util.update(aliasbase, uci:get_all(external, "alias") or {})
        aliasbase.interface = device
        aliasbase.ipaddr = dclient
        aliasbase.proto = "static"
        uci:section("network", "alias", device .. "dhcp", aliasbase)
        uci:save("network")
-       
-       
+
+
        -- Create dhcp
-       local dhcpbase = _strip_internals(uci:get_all("freifunk", "dhcp"))
+       local dhcpbase = uci:get_all("freifunk", "dhcp")
+       util.update(dhcpbase, uci:get_all(external, "dhcp") or {})
        dhcpbase.interface = device .. "dhcp"
        dhcpbase.start = dhcpbeg
        dhcpbase.limit = limit
 
        uci:section("dhcp", "dhcp", device .. "dhcp", dhcpbase)
        uci:save("dhcp")
-       
-       
+
+       uci:delete_all("firewall", "rule", {
+               src="freifunk",
+               proto="udp",
+               src_port="68",
+               dest_port="67"
+       })
+       uci:section("firewall", "rule", nil, {
+               src="freifunk",
+               proto="udp",
+               src_port="68",
+               dest_port="67",
+               target="ACCEPT"
+       })
+       uci:delete_all("firewall", "rule", {
+               src="freifunk",
+               proto="tcp",
+               dest_port="8082",
+       })
+       uci:section("firewall", "rule", nil, {
+               src="freifunk",
+               proto="tcp",
+               dest_port="8082",
+               target="ACCEPT"
+       })
+
+
+
        -- Delete old splash
        uci:delete_all("luci_splash", "iface", {net=device, zone="freifunk"})
-       
+
        -- Register splash
        uci:section("luci_splash", "iface", nil, {net=device, zone="freifunk"})
        uci:save("luci_splash")
 end
 
-return f
\ No newline at end of file
+return f