dnsmasq: add jail support
[openwrt.git] / package / network / services / dnsmasq / files / dnsmasq.init
1 #!/bin/sh /etc/rc.common
2 # Copyright (C) 2007-2012 OpenWrt.org
3
4 START=60
5
6 USE_PROCD=1
7 PROG=/usr/sbin/dnsmasq
8
9 DNS_SERVERS=""
10 DOMAIN=""
11
12 ADD_LOCAL_DOMAIN=1
13 ADD_LOCAL_HOSTNAME=1
14
15 CONFIGFILE="/var/etc/dnsmasq.conf"
16 HOSTFILE="/tmp/hosts/dhcp"
17 TRUSTANCHORSFILE="/usr/share/dnsmasq/trust-anchors.conf"
18
19 xappend() {
20         local value="$1"
21
22         echo "${value#--}" >> $CONFIGFILE
23 }
24
25 dhcp_calc() {
26         local ip="$1"
27         local res=0
28
29         while [ -n "$ip" ]; do
30                 part="${ip%%.*}"
31                 res="$(($res * 256))"
32                 res="$(($res + $part))"
33                 [ "${ip%.*}" != "$ip" ] && ip="${ip#*.}" || ip=
34         done
35         echo "$res"
36 }
37
38 dhcp_check() {
39         local ifname="$1"
40         local stamp="/var/run/dnsmasq.$ifname.dhcp"
41         local rv=0
42
43         [ -s "$stamp" ] && return $(cat "$stamp")
44
45         udhcpc -n -q -s /bin/true -t 1 -i "$ifname" >&- && rv=1 || rv=0
46
47         [ $rv -eq 1 ] && \
48                 logger -t dnsmasq \
49                         "found already running DHCP-server on interface '$ifname'" \
50                         "refusing to start, use 'option force 1' to override"
51
52         echo $rv > "$stamp"
53         return $rv
54 }
55
56 log_once() {
57         pidof dnsmasq >/dev/null || \
58                 logger -t dnsmasq "$@"
59 }
60
61 append_bool() {
62         local section="$1"
63         local option="$2"
64         local value="$3"
65         local _loctmp
66         config_get_bool _loctmp "$section" "$option" 0
67         [ $_loctmp -gt 0 ] && xappend "$value"
68 }
69
70 append_parm() {
71         local section="$1"
72         local option="$2"
73         local switch="$3"
74         local _loctmp
75         config_get _loctmp "$section" "$option"
76         [ -z "$_loctmp" ] && return 0
77         xappend "$switch=$_loctmp"
78 }
79
80 append_server() {
81         xappend "--server=$1"
82 }
83
84 append_address() {
85         xappend "--address=$1"
86 }
87
88 append_ipset() {
89         xappend "--ipset=$1"
90 }
91
92 append_interface() {
93         local ifname=$(uci_get_state network "$1" ifname "$1")
94         xappend "--interface=$ifname"
95 }
96
97 append_notinterface() {
98         local ifname=$(uci_get_state network "$1" ifname "$1")
99         xappend "--except-interface=$ifname"
100 }
101
102 append_addnhosts() {
103         xappend "--addn-hosts=$1"
104 }
105
106 append_bogusnxdomain() {
107         xappend "--bogus-nxdomain=$1"
108 }
109
110 append_pxe_service() {
111         xappend "--pxe-service=$1"
112 }
113
114 dnsmasq() {
115         local cfg="$1"
116         append_bool "$cfg" authoritative "--dhcp-authoritative"
117         append_bool "$cfg" nodaemon "--no-daemon"
118         append_bool "$cfg" domainneeded "--domain-needed"
119         append_bool "$cfg" filterwin2k "--filterwin2k"
120         append_bool "$cfg" nohosts "--no-hosts"
121         append_bool "$cfg" nonegcache "--no-negcache"
122         append_bool "$cfg" strictorder "--strict-order"
123         append_bool "$cfg" logqueries "--log-queries"
124         append_bool "$cfg" noresolv "--no-resolv"
125         append_bool "$cfg" localise_queries "--localise-queries"
126         append_bool "$cfg" readethers "--read-ethers"
127         append_bool "$cfg" dbus "--enable-dbus"
128         append_bool "$cfg" boguspriv "--bogus-priv"
129         append_bool "$cfg" expandhosts "--expand-hosts"
130         append_bool "$cfg" enable_tftp "--enable-tftp"
131         append_bool "$cfg" nonwildcard "--bind-interfaces"
132         append_bool "$cfg" fqdn "--dhcp-fqdn"
133         append_bool "$cfg" proxydnssec "--proxy-dnssec"
134         append_bool "$cfg" localservice "--local-service"
135         append_bool "$cfg" quietdhcp "--quiet-dhcp"
136
137         append_parm "$cfg" dhcpscript "--dhcp-script"
138         append_parm "$cfg" cachesize "--cache-size"
139         append_parm "$cfg" dnsforwardmax "--dns-forward-max"
140         append_parm "$cfg" port "--port"
141         append_parm "$cfg" ednspacket_max "--edns-packet-max"
142         append_parm "$cfg" dhcpleasemax "--dhcp-lease-max"
143         append_parm "$cfg" "queryport" "--query-port"
144         append_parm "$cfg" "domain" "--domain"
145         append_parm "$cfg" "local" "--server"
146         config_list_foreach "$cfg" "server" append_server
147         config_list_foreach "$cfg" "address" append_address
148         config_list_foreach "$cfg" "ipset" append_ipset
149         config_list_foreach "$cfg" "interface" append_interface
150         config_list_foreach "$cfg" "notinterface" append_notinterface
151         config_list_foreach "$cfg" "addnhosts" append_addnhosts
152         config_list_foreach "$cfg" "bogusnxdomain" append_bogusnxdomain
153         append_parm "$cfg" "leasefile" "--dhcp-leasefile"
154         append_parm "$cfg" "resolvfile" "--resolv-file"
155         append_parm "$cfg" "tftp_root" "--tftp-root"
156         append_parm "$cfg" "dhcp_boot" "--dhcp-boot"
157         append_parm "$cfg" "local_ttl" "--local-ttl"
158         append_parm "$cfg" "pxe_prompt" "--pxe-prompt"
159         config_list_foreach "$cfg" "pxe_service" append_pxe_service
160         config_get DOMAIN "$cfg" domain
161
162         config_get_bool ADD_LOCAL_DOMAIN "$cfg" add_local_domain 1
163         config_get_bool ADD_LOCAL_HOSTNAME "$cfg" add_local_hostname 1
164
165         config_get_bool readethers "$cfg" readethers
166         [ "$readethers" = "1" -a \! -e "/etc/ethers" ] && touch /etc/ethers
167
168         config_get leasefile $cfg leasefile
169         [ -n "$leasefile" -a \! -e "$leasefile" ] && touch "$leasefile"
170         config_get_bool cachelocal "$cfg" cachelocal 1
171
172         config_get hostsfile "$cfg" dhcphostsfile
173         [ -e "$hostsfile" ] && xappend "--dhcp-hostsfile=$hostsfile"
174
175         mkdir -p /tmp/hosts /tmp/dnsmasq.d
176         xappend "--addn-hosts=/tmp/hosts"
177         xappend "--conf-dir=/tmp/dnsmasq.d"
178
179         local rebind
180         config_get_bool rebind "$cfg" rebind_protection 1
181         [ $rebind -gt 0 ] && {
182                 log_once \
183                         "DNS rebinding protection is active," \
184                         "will discard upstream RFC1918 responses!"
185                 xappend "--stop-dns-rebind"
186
187                 local rebind_localhost
188                 config_get_bool rebind_localhost "$cfg" rebind_localhost 0
189                 [ $rebind_localhost -gt 0 ] && {
190                         log_once "Allowing 127.0.0.0/8 responses"
191                         xappend "--rebind-localhost-ok"
192                 }
193
194                 append_rebind_domain() {
195                         log_once "Allowing RFC1918 responses for domain $1"
196                         xappend "--rebind-domain-ok=$1"
197                 }
198
199                 config_list_foreach "$cfg" rebind_domain append_rebind_domain
200         }
201
202         config_get_bool dnssec "$cfg" dnssec 0
203         [ "$dnssec" -gt 0 ] && {
204                 xappend "--conf-file=$TRUSTANCHORSFILE"
205                 xappend "--dnssec"
206                 append_bool "$cfg" dnsseccheckunsigned "--dnssec-check-unsigned"
207         }
208
209         dhcp_option_add "$cfg" "" 0
210
211         xappend "--dhcp-broadcast=tag:needs-broadcast"
212
213         echo >> $CONFIGFILE
214 }
215
216 dhcp_subscrid_add() {
217         local cfg="$1"
218
219         config_get networkid "$cfg" networkid
220         [ -n "$networkid" ] || return 0
221
222         config_get subscriberid "$cfg" subscriberid
223         [ -n "$subscriberid" ] || return 0
224
225         xappend "--dhcp-subscrid=$networkid,$subscriberid"
226
227         config_get_bool force "$cfg" force 0
228
229         dhcp_option_add "$cfg" "$networkid" "$force"
230 }
231
232 dhcp_remoteid_add() {
233         local cfg="$1"
234
235         config_get networkid "$cfg" networkid
236         [ -n "$networkid" ] || return 0
237
238         config_get remoteid "$cfg" remoteid
239         [ -n "$remoteid" ] || return 0
240
241         xappend "--dhcp-remoteid=$networkid,$remoteid"
242
243         config_get_bool force "$cfg" force 0
244
245         dhcp_option_add "$cfg" "$networkid" "$force"
246 }
247
248 dhcp_circuitid_add() {
249         local cfg="$1"
250
251         config_get networkid "$cfg" networkid
252         [ -n "$networkid" ] || return 0
253
254         config_get circuitid "$cfg" circuitid
255         [ -n "$circuitid" ] || return 0
256
257         xappend "--dhcp-circuitid=$networkid,$circuitid"
258
259         config_get_bool force "$cfg" force 0
260
261         dhcp_option_add "$cfg" "$networkid" "$force"
262 }
263
264 dhcp_userclass_add() {
265         local cfg="$1"
266
267         config_get networkid "$cfg" networkid
268         [ -n "$networkid" ] || return 0
269
270         config_get userclass "$cfg" userclass
271         [ -n "$userclass" ] || return 0
272
273         xappend "--dhcp-userclass=$networkid,$userclass"
274
275         config_get_bool force "$cfg" force 0
276
277         dhcp_option_add "$cfg" "$networkid" "$force"
278 }
279
280 dhcp_vendorclass_add() {
281         local cfg="$1"
282
283         config_get networkid "$cfg" networkid
284         [ -n "$networkid" ] || return 0
285
286         config_get vendorclass "$cfg" vendorclass
287         [ -n "$vendorclass" ] || return 0
288
289         xappend "--dhcp-vendorclass=$networkid,$vendorclass"
290
291         config_get_bool force "$cfg" force 0
292
293         dhcp_option_add "$cfg" "$networkid" "$force"
294 }
295
296 dhcp_host_add() {
297         local cfg="$1"
298
299         config_get_bool force "$cfg" force 0
300
301         config_get networkid "$cfg" networkid
302         [ -n "$networkid" ] && dhcp_option_add "$cfg" "$networkid" "$force"
303
304         config_get name "$cfg" name
305         config_get ip "$cfg" ip
306         [ -n "$ip" -o -n "$name" ] || return 0
307
308         config_get_bool dns "$cfg" dns 0
309         [ "$dns" = "1" -a -n "$ip" -a -n "$name" ] && {
310                 echo "$ip $name${DOMAIN:+.$DOMAIN}" >> $HOSTFILE
311         }
312
313         config_get mac "$cfg" mac
314         if [ -n "$mac" ]; then
315                 # --dhcp-host=00:20:e0:3b:13:af,192.168.0.199,lap
316                 macs=""
317                 for m in $mac; do append macs "$m" ","; done
318         else
319                 # --dhcp-host=lap,192.168.0.199
320                 [ -n "$name" ] || return 0
321                 macs="$name"
322                 name=""
323         fi
324
325         config_get tag "$cfg" tag
326
327         config_get_bool broadcast "$cfg" broadcast 0
328         [ "$broadcast" = "0" ] && broadcast=
329
330         xappend "--dhcp-host=$macs${networkid:+,net:$networkid}${broadcast:+,set:needs-broadcast}${tag:+,set:$tag}${ip:+,$ip}${name:+,$name}"
331 }
332
333 dhcp_tag_add() {
334         local cfg="$1"
335
336         tag="$cfg"
337
338         [ -n "$tag" ] || return 0
339
340         config_get_bool force "$cfg" force 0
341         [ "$force" = "0" ] && force=
342
343         config_get option "$cfg" dhcp_option
344         for o in $option; do
345                 xappend "--dhcp-option${force:+-force}=tag:$tag,$o"
346         done
347 }
348
349 dhcp_mac_add() {
350         local cfg="$1"
351
352         config_get networkid "$cfg" networkid
353         [ -n "$networkid" ] || return 0
354
355         config_get mac "$cfg" mac
356         [ -n "$mac" ] || return 0
357
358         xappend "--dhcp-mac=$networkid,$mac"
359
360         dhcp_option_add "$cfg" "$networkid"
361 }
362
363 dhcp_boot_add() {
364         local cfg="$1"
365
366         config_get networkid "$cfg" networkid
367
368         config_get filename "$cfg" filename
369         [ -n "$filename" ] || return 0
370
371         config_get servername "$cfg" servername
372         config_get serveraddress "$cfg" serveraddress
373
374         [ -n "$serveraddress" -a ! -n "$servername" ] && return 0
375
376         xappend "--dhcp-boot=${networkid:+net:$networkid,}${filename}${servername:+,$servername}${serveraddress:+,$serveraddress}"
377
378         config_get_bool force "$cfg" force 0
379
380         dhcp_option_add "$cfg" "$networkid" "$force"
381 }
382
383
384 dhcp_add() {
385         local cfg="$1"
386         config_get net "$cfg" interface
387         [ -n "$net" ] || return 0
388
389         config_get dhcpv4 "$cfg" dhcpv4
390         [ "$dhcpv4" != "disabled" ] || return 0
391
392         config_get networkid "$cfg" networkid
393         [ -n "$networkid" ] || networkid="$net"
394
395         network_get_subnet subnet "$net" || return 0
396         network_get_device ifname "$net" || return 0
397         network_get_protocol proto "$net" || return 0
398
399         [ "$cachelocal" = "0" ] && network_get_dnsserver dnsserver "$net" && {
400                 DNS_SERVERS="$DNS_SERVERS $dnsserver"
401         }
402
403         append_bool "$cfg" ignore "--no-dhcp-interface=$ifname" && return 0
404
405         # Do not support non-static interfaces for now
406         [ static = "$proto" ] || return 0
407
408         # Override interface netmask with dhcp config if applicable
409         config_get netmask "$cfg" netmask "${subnet##*/}"
410
411         #check for an already active dhcp server on the interface, unless 'force' is set
412         config_get_bool force "$cfg" force 0
413         [ $force -gt 0 ] || dhcp_check "$ifname" || return 0
414
415         config_get start "$cfg" start
416         config_get limit "$cfg" limit
417         config_get leasetime "$cfg" leasetime
418         config_get options "$cfg" options
419         config_get_bool dynamicdhcp "$cfg" dynamicdhcp 1
420
421         leasetime="${leasetime:-12h}"
422         start="$(dhcp_calc "${start:-100}")"
423         limit="${limit:-150}"
424         [ "$limit" -gt 0 ] && limit=$((limit-1))
425         eval "$(ipcalc.sh "${subnet%%/*}" $netmask $start $limit)"
426         if [ "$dynamicdhcp" = "0" ]; then END="static"; fi
427         xappend "--dhcp-range=$networkid,$START,$END,$NETMASK,$leasetime${options:+ $options}"
428
429         dhcp_option_add "$cfg" "$networkid"
430 }
431
432 dhcp_option_add() {
433         local cfg="$1"
434         local networkid="$2"
435         local force="$3"
436
437         [ "$force" = "0" ] && force=
438
439         config_get dhcp_option "$cfg" dhcp_option
440         for o in $dhcp_option; do
441                 xappend "--dhcp-option${force:+-force}=${networkid:+$networkid,}$o"
442         done
443
444 }
445
446 dhcp_domain_add() {
447         local cfg="$1"
448         local ip name names record
449
450         config_get names "$cfg" name "$2"
451         [ -n "$names" ] || return 0
452
453         config_get ip "$cfg" ip "$3"
454         [ -n "$ip" ] || return 0
455
456         for name in $names; do
457                 record="${record:+$record }$name"
458         done
459
460         echo "$ip $record" >> $HOSTFILE
461 }
462
463 dhcp_srv_add() {
464         local cfg="$1"
465
466         config_get srv "$cfg" srv
467         [ -n "$srv" ] || return 0
468
469         config_get target "$cfg" target
470         [ -n "$target" ] || return 0
471
472         config_get port "$cfg" port
473         [ -n "$port" ] || return 0
474
475         config_get class "$cfg" class
476         config_get weight "$cfg" weight
477
478         local service="$srv,$target,$port${class:+,$class${weight:+,$weight}}"
479
480         xappend "--srv-host=$service"
481 }
482
483 dhcp_mx_add() {
484         local cfg="$1"
485         local domain relay pref
486
487         config_get domain "$cfg" domain
488         [ -n "$domain" ] || return 0
489
490         config_get relay "$cfg" relay
491         [ -n "$relay" ] || return 0
492
493         config_get pref "$cfg" pref 0
494
495         local service="$domain,$relay,$pref"
496
497         xappend "--mx-host=$service"
498 }
499
500 dhcp_cname_add() {
501         local cfg="$1"
502         local cname target
503
504         config_get cname "$cfg" cname
505         [ -n "$cname" ] || return 0
506
507         config_get target "$cfg" target
508         [ -n "$target" ] || return 0
509
510         xappend "--cname=${cname},${target}"
511 }
512
513 dhcp_hostrecord_add() {
514         local cfg="$1"
515         local names addresses record val
516
517         config_get names "$cfg" name "$2"
518         if [ -z "$names" ]; then
519                 return 0
520         fi
521
522         config_get addresses "$cfg" ip "$3"
523         if [ -z "$addresses" ]; then
524                 return 0
525         fi
526
527         for val in $names $addresses; do
528                 record="${record:+$record,}$val"
529         done
530
531         xappend "--host-record=$record"
532 }
533
534 service_triggers()
535 {
536         procd_add_reload_trigger "dhcp"
537 }
538
539 boot() {
540         # Will be launched through hotplug
541         return 0
542 }
543
544 start_service() {
545         include /lib/functions
546
547         config_load dhcp
548
549         procd_open_instance
550         procd_set_param command $PROG -C $CONFIGFILE -d -x /var/run/dnsmasq/dnsmasq.pid
551         procd_set_param file $CONFIGFILE
552         procd_set_param respawn
553
554         procd_add_jail dnsmasq ubus log
555         procd_add_jail_mount $CONFIGFILE $TRUSTANCHORSFILE $HOSTFILE /etc/passwd /dev/urandom /etc/dnsmasq.conf /tmp/dnsmasq.d /tmp/resolv.conf.auto /etc/hosts /etc/ethers
556         procd_add_jail_mount_rw /var/run/dnsmasq/ /tmp/dhcp.leases
557         
558         procd_close_instance
559
560         # before we can call xappend
561         mkdir -p /var/run/dnsmasq/
562         mkdir -p $(dirname $CONFIGFILE)
563         mkdir -p /var/lib/misc
564         touch /tmp/dhcp.leases
565
566
567         echo "# auto-generated config file from /etc/config/dhcp" > $CONFIGFILE
568         echo "# auto-generated config file from /etc/config/dhcp" > $HOSTFILE
569
570         # if we did this last, we could override auto-generated config
571         [ -f /etc/dnsmasq.conf ] && {
572                 xappend "--conf-file=/etc/dnsmasq.conf"
573         }
574
575         args=""
576         config_foreach dnsmasq dnsmasq
577         config_foreach dhcp_host_add host
578         echo >> $CONFIGFILE
579         config_foreach dhcp_boot_add boot
580         config_foreach dhcp_mac_add mac
581         config_foreach dhcp_tag_add tag
582         config_foreach dhcp_vendorclass_add vendorclass
583         config_foreach dhcp_userclass_add userclass
584         config_foreach dhcp_circuitid_add circuitid
585         config_foreach dhcp_remoteid_add remoteid
586         config_foreach dhcp_subscrid_add subscrid
587         config_foreach dhcp_domain_add domain
588         config_foreach dhcp_hostrecord_add hostrecord
589
590         # add own hostname
591         local lanaddr
592         [ $ADD_LOCAL_HOSTNAME -eq 1 ] && network_get_ipaddr lanaddr "lan" && {
593                 local hostname="$(uci_get system @system[0] hostname OpenWrt)"
594                 dhcp_domain_add "" "$hostname" "$lanaddr"
595         }
596
597         echo >> $CONFIGFILE
598         config_foreach dhcp_srv_add srvhost
599         config_foreach dhcp_mx_add mxhost
600         echo >> $CONFIGFILE
601
602         config_get odhcpd_is_active odhcpd maindhcp
603         if [ "$odhcpd_is_active" != "1" ]; then
604                 config_foreach dhcp_add dhcp
605         fi
606
607         echo >> $CONFIGFILE
608         config_foreach dhcp_cname_add cname
609         echo >> $CONFIGFILE
610
611         rm -f /tmp/resolv.conf
612         [ $ADD_LOCAL_DOMAIN -eq 1 ] && [ -n "$DOMAIN" ] && {
613                 echo "search $DOMAIN" >> /tmp/resolv.conf
614         }
615         DNS_SERVERS="$DNS_SERVERS 127.0.0.1"
616         for DNS_SERVER in $DNS_SERVERS ; do
617                 echo "nameserver $DNS_SERVER" >> /tmp/resolv.conf
618         done
619 }
620
621 reload_service() {
622         rc_procd start_service "$@"
623         return 0
624 }
625
626 stop_service() {
627         [ -f /tmp/resolv.conf ] && {
628                 rm -f /tmp/resolv.conf
629                 ln -s /tmp/resolv.conf.auto /tmp/resolv.conf
630         }
631         rm -f /var/run/dnsmasq.*.dhcp
632 }