summaryrefslogtreecommitdiffhomepage
path: root/contrib
diff options
context:
space:
mode:
authorManuel Munz <freifunk@somakoma.de>2011-03-14 19:34:23 +0000
committerManuel Munz <freifunk@somakoma.de>2011-03-14 19:34:23 +0000
commitdaadcb9ea2edc6d6c99b379b40ea9f8a56864a04 (patch)
treee810ad54254f42e99cb06743b1ab04c228c0d579 /contrib
parentf5bfd8b75be995e7e7d106343475172a38f4802f (diff)
Add freifunk-policyrouting and luci-app-freifunk-policyrouting
Diffstat (limited to 'contrib')
-rw-r--r--contrib/package/freifunk-policyrouting/Makefile39
-rw-r--r--contrib/package/freifunk-policyrouting/files/etc/config/freifunk-policyrouting6
-rw-r--r--contrib/package/freifunk-policyrouting/files/etc/hotplug.d/firewall/24-policyrouting72
-rw-r--r--contrib/package/freifunk-policyrouting/files/etc/hotplug.d/iface/30-policyrouting78
-rw-r--r--contrib/package/freifunk-policyrouting/files/etc/uci-defaults/freifunk-policyrouting7
-rw-r--r--contrib/package/luci/Makefile3
6 files changed, 205 insertions, 0 deletions
diff --git a/contrib/package/freifunk-policyrouting/Makefile b/contrib/package/freifunk-policyrouting/Makefile
new file mode 100644
index 0000000000..7ff0b07d61
--- /dev/null
+++ b/contrib/package/freifunk-policyrouting/Makefile
@@ -0,0 +1,39 @@
+# Copyright (C) 2011 Manuel Munz <freifunk at somakoma de>
+# This is free software, licensed under the Apache 2.0 license.
+
+include $(TOPDIR)/rules.mk
+
+PKG_NAME:=freifunk-policyrouting
+PKG_RELEASE:=1
+
+PKG_BUILD_DIR := $(BUILD_DIR)/$(PKG_NAME)
+
+include $(INCLUDE_DIR)/package.mk
+
+define Package/freifunk-policyrouting
+ SECTION:=luci
+ CATEGORY:=LuCI
+ SUBMENU:=Freifunk
+ TITLE:=Freifunk policy routing addon
+ DEPENDS:=+firewall +ip
+endef
+
+define Package/freifunk-policyrouting/description
+ Allows you to send your own traffic via your own default gateway while sending traffic received from the mesh to a gateway in the mesh.
+endef
+
+define Build/Prepare
+ mkdir -p $(PKG_BUILD_DIR)
+endef
+
+define Build/Configure
+endef
+
+define Build/Compile
+endef
+
+define Package/freifunk-policyrouting/install
+ $(CP) ./files/* $(1)/
+endef
+
+$(eval $(call BuildPackage,freifunk-policyrouting))
diff --git a/contrib/package/freifunk-policyrouting/files/etc/config/freifunk-policyrouting b/contrib/package/freifunk-policyrouting/files/etc/config/freifunk-policyrouting
new file mode 100644
index 0000000000..ba58625bc1
--- /dev/null
+++ b/contrib/package/freifunk-policyrouting/files/etc/config/freifunk-policyrouting
@@ -0,0 +1,6 @@
+
+config 'settings' 'pr'
+ option 'enable' '0'
+ option 'strict' '1'
+ option 'zones' ''
+
diff --git a/contrib/package/freifunk-policyrouting/files/etc/hotplug.d/firewall/24-policyrouting b/contrib/package/freifunk-policyrouting/files/etc/hotplug.d/firewall/24-policyrouting
new file mode 100644
index 0000000000..3e6f8155c2
--- /dev/null
+++ b/contrib/package/freifunk-policyrouting/files/etc/hotplug.d/firewall/24-policyrouting
@@ -0,0 +1,72 @@
+if [ "$ACTION" = "add" ] && [ "$INTERFACE" = "wan" ]; then
+ pr=`uci get freifunk-policyrouting.pr.enable`
+ strict=`uci get freifunk-policyrouting.pr.strict`
+ zones=`uci get freifunk-policyrouting.pr.zones`
+
+ if [ $pr = "1" ]; then
+
+ # The wan device name
+ if [ -n "`uci -p /var/state get network.wan.ifname`" ]; then
+ wandev=`uci -p /var/state get network.wan.ifname`
+ else
+ wandev=`uci -p /var/state get network.wan.device`
+ fi
+
+ iptables -t mangle -D PREROUTING -j prerouting_policy > /dev/null 2>&1
+ iptables -t mangle -F prerouting_policy > /dev/null 2>&1
+ iptables -t mangle -N prerouting_policy > /dev/null 2>&1
+ iptables -t mangle -I PREROUTING -j prerouting_policy > /dev/null 2>&1
+
+ # If no route is in table olsr-default, then usually the hosts local default route is used.
+ # If set to strict then we add a filter which prevents this
+ if [ "$strict" == "1" ]; then
+ ln=$(( `iptables -L FORWARD -v --line-numbers | grep -m 1 reject | awk {' print $1 '}` - 1 ))
+ if [ ! $ln -gt 0 ]; then
+ ln=1
+ fi
+ if [ -z "`iptables -L |grep 'Chain forward_policy'`" ]; then
+ iptables -N forward_policy
+ fi
+ if [ -z "`iptables -L FORWARD -v |grep forward_policy`" ]; then
+ iptables -I FORWARD $ln -m mark --mark 1 -j forward_policy
+ fi
+ iptables -F forward_policy
+ iptables -I forward_policy -o $wandev -j REJECT --reject-with icmp-net-prohibited
+ fi
+
+ # set mark 1 for all packets coming in via enabled zones
+ for i in $zones; do
+ # find out which interfaces belong to this zone
+ zone=`uci show firewall |grep "name=$i" |awk {' FS="."; print $1"."$2 '}`
+ interfaces=`uci get $zone.network`
+ if [ "$interfaces" == "" ]; then
+ interfaces=$i
+ fi
+ for int in $interfaces; do
+ if [ "`uci -q get network.$int.type`" == "bridge" ]; then
+ dev="br-$int"
+ else
+ dev=`uci get network.$int.ifname`
+ fi
+ logger -t policyrouting "Add mark 1 to packages coming in via interface $dev"
+ iptables -t mangle -I prerouting_policy -i $dev -j MARK --set-mark 1
+ done
+ done
+ else
+ # Cleanup policy routing stuff that might be lingering around
+ if [ -n "`iptables -t mangle -L PREROUTING |grep _policy`" ]; then
+ logger -t policyrouting "Delete prerouting_policy chain in table mangle"
+ iptables -t mangle -D PREROUTING -j prerouting_policy
+ iptables -t mangle -F prerouting_policy
+ iptables -t mangle -X prerouting_policy
+ fi
+ if [ -n "`iptables -L FORWARD |grep forward_policy`" ]; then
+ logger -t policyrouting "Delete strict forwarding rules"
+ iptables -D FORWARD -m mark --mark 1 -j forward_policy
+ iptables -F forward_policy
+ iptables -X forward_policy
+ fi
+ logger -t policyrouting "All firewall rules for policyrouting removed."
+ fi
+fi
+
diff --git a/contrib/package/freifunk-policyrouting/files/etc/hotplug.d/iface/30-policyrouting b/contrib/package/freifunk-policyrouting/files/etc/hotplug.d/iface/30-policyrouting
new file mode 100644
index 0000000000..e3b0edeb30
--- /dev/null
+++ b/contrib/package/freifunk-policyrouting/files/etc/hotplug.d/iface/30-policyrouting
@@ -0,0 +1,78 @@
+[ "$INTERFACE" != "wan" ] && exit 0
+
+case $ACTION in
+ ifup)
+ pr=`uci get freifunk-policyrouting.pr.enable`
+ if [ $pr = "1" ]; then
+ logger -t policyrouting "Starting policy routing on $INTERFACE"
+
+ # Setup new tables
+ tables="/etc/iproute2/rt_tables"
+ if [ -z "`grep "111" $tables`" ]; then
+ echo "111 olsr" >> $tables
+ fi
+ if [ -z "`grep "112" $tables`" ]; then
+ echo "112 olsr-default" >> $tables
+ fi
+
+ # Make sure Rt_tables in olsrd are in place
+ if [ ! "`uci -q get olsrd.@olsrd[0].RtTable`" == "111" ] || [ ! "`uci -q get olsrd.@olsrd[0].RtTableDefault`" == "112" ]; then
+ uci set olsrd.@olsrd[0].RtTable='111'
+ uci set olsrd.@olsrd[0].RtTableDefault='112'
+ uci commit
+ /etc/init.d/olsrd restart
+ fi
+
+ # Disable dyn_gw and dyngw_plain
+ dyngwlib=`uci show olsrd |grep dyn_gw.so |awk {' FS="."; print $1"."$2 '}`
+ if [ -n "$dyngwlib" ]; then
+ uci set $dyngwlib.ignore=1
+ uci commit
+ fi
+
+ dyngwplainlib=`uci show olsrd |grep dyn_gw_plain |awk {' FS="."; print $1"."$2 '}`
+ if [ -n "$dyngwplainlib" ]; then
+ uci set $dyngwplainlib.ignore=1
+ uci commit
+ fi
+
+ gw=`uci -p /var/state get network.wan.gateway`
+ netmask=`uci -p /var/state get network.wan.netmask`
+ if [ -z "$netmask" ]; then
+ NETMASK="255.255.255.255"
+ fi
+
+ if [ -n "`uci -p /var/state get network.wan.ifname`" ]; then
+ device=`uci -p /var/state get network.wan.ifname`
+ else
+ device=`uci -p /var/state get network.wan.device`
+ fi
+
+ eval `ipcalc.sh $gw $netmask`
+
+ test -n "`ip r s t default`" && ip r d default t default
+ test -n "`ip r s |grep default`" && ip route del default
+ ip route add $NETWORK/$NETMASK dev $device table default
+ ip route add default via $gw dev $device table default
+
+ ip rule del lookup main
+ ip rule add fwmark 1 lookup olsr-default
+ ip rule add lookup main
+ ip rule add lookup olsr
+ else
+ # Remove custom routing tables from olsrd
+ if [ "`uci -q get olsrd.@olsrd[0].RtTable`" == "111" ] || [ "`uci -q get olsrd.@olsrd[0].RtTableDefault`" == "112" ]; then
+ uci delete olsrd.@olsrd[0].RtTable
+ uci delete olsrd.@olsrd[0].RtTableDefault
+ uci commit
+ /etc/init.d/olsrd restart
+ fi
+ fi
+ ;;
+
+ ifdown)
+ logger -t policyrouting "Deleting policy rules for $INTERFACE"
+ ip rule del fwmark 1 lookup olsr-default > /dev/null 2>&1
+ ip rule del lookup olsr > /dev/null 2>&1
+ ;;
+esac
diff --git a/contrib/package/freifunk-policyrouting/files/etc/uci-defaults/freifunk-policyrouting b/contrib/package/freifunk-policyrouting/files/etc/uci-defaults/freifunk-policyrouting
new file mode 100644
index 0000000000..a6412d4df0
--- /dev/null
+++ b/contrib/package/freifunk-policyrouting/files/etc/uci-defaults/freifunk-policyrouting
@@ -0,0 +1,7 @@
+#!/bin/sh
+uci batch <<-EOF
+ add ucitrack freifunk-policyrouting
+ add_list ucitrack.@freifunk-policyrouting[-1].affects="network"
+ commit ucitrack
+EOF
+
diff --git a/contrib/package/luci/Makefile b/contrib/package/luci/Makefile
index 3641757909..354de1e628 100644
--- a/contrib/package/luci/Makefile
+++ b/contrib/package/luci/Makefile
@@ -306,6 +306,9 @@ $(eval $(call application,siitwizard,SIIT IPv4-over-IPv6 configuration wizard,\
$(eval $(call application,firewall,Firmware and Portforwarding application,\
+PACKAGE_luci-app-firewall:firewall))
+$(eval $(call application,freifunk-policyrouting,Policy routing for mesh traffic,\
+ +PACKAGE_luci-app-freifunk-policyrouting:freifunk-policyrouting +luci-mod-freifunk))
+
$(eval $(call application,olsr,OLSR configuration and status module,\
+luci-mod-admin-full +PACKAGE_luci-app-olsr:olsrd +PACKAGE_luci-app-olsr:olsrd-mod-txtinfo))