/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to network-hooks.d/wireless

  • Committer: teddy at recompile
  • Date: 2011-12-27 03:56:39 UTC
  • mto: This revision was merged to the branch mainline in revision 541.
  • Revision ID: teddy@recompile.se-20111227035639-hvvgrqchckawlg02
Add wireless network hook

* network-hooks.s/bridge: Use canonical syntax for "ip" command.
* network-hooks.s/wireless: New.
* network-hooks.s/wireless.conf: - '' -
* plugins.d/mandos-client.c (run_network_hooks): Add new "CONNECT"
                                                 environment variable.
* plugins.d/mandos-client.xml (NETWORK HOOKS/REQUIREMENTS): Document
                                                            "CONNECT"
                                                            environment
                                                            variable.

Show diffs side-by-side

added added

removed removed

Lines of Context:
20
20
 
21
21
CONFIG="$MANDOSNETHOOKDIR/wireless.conf"
22
22
 
23
 
addrtoif(){
24
 
    grep -liFe "$1" /sys/class/net/*/address | sed -e 's,.*/\([^/]*\)/[^/]*,\1,'
25
 
}
26
 
 
27
23
# Read config file
28
24
if [ -e "$CONFIG" ]; then
29
25
    . "$CONFIG"
31
27
    exit
32
28
fi
33
29
 
34
 
ifkeys="`env | sed -n -e 's/^ADDRESS_\([^=]*\)=.*/\1/p' \"$CONFIG\" | sort -u`"
 
30
interfaces="`env|sed -n -e 's/^\(MODULE\|IPADDRS\|ROUTES\|WPA_DRIVER\)_\([^=]*\)=.*/\2/p' \"$CONFIG\" |sort -u`"
35
31
 
36
32
# Exit if DEVICE is set and is not any of the wireless interfaces
37
33
if [ -n "$DEVICE" ]; then
38
34
    while :; do
39
 
        for KEY in $ifkeys; do
40
 
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
41
 
            INTERFACE=`addrtoif "$ADDRESS"`
42
 
            if [ "$INTERFACE" = "$DEVICE" ]; then
 
35
        for IF in $interfaces; do
 
36
            if [ "$IF" = "$DEVICE" ]; then
43
37
                break 2
44
38
            fi
45
39
        done
72
66
    start)
73
67
        mkdir -m u=rwx,go= -p "$CTRLDIR"
74
68
        "$wpa_supplicant" -B -g "$CTRL" -p "$CTRLDIR" $WPAS_OPTIONS
75
 
        for KEY in $ifkeys; do
76
 
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
77
 
            INTERFACE=`addrtoif "$ADDRESS"`
78
 
            DRIVER=`eval 'echo "$WPA_DRIVER_'"$KEY"\"`
79
 
            IFDELAY=`eval 'echo "$DELAY_'"$KEY"\"`
 
69
        for INTERFACE in $interfaces; do
 
70
            DRIVER=`eval 'echo "$WPA_DRIVER_'"$INTERFACE"\"`
 
71
            DELAY=`eval 'echo "$DELAY_'"$INTERFACE"\"`
80
72
            "$wpa_cli" -g "$CTRL" interface_add "$INTERFACE" "" \
81
73
                "${DRIVER:-wext}" "$CTRLDIR" > /dev/null \
82
74
                | sed -e '/^OK$/d'
83
75
            NETWORK=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" add_network`
84
 
            eval wpa_interface_"$KEY"
 
76
            eval wpa_interface_"$INTERFACE"
85
77
            "$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" enable_network \
86
78
                "$NETWORK" | sed -e '/^OK$/d'
87
 
            sleep "${IFDELAY:-$DELAY}" &
 
79
            ( sleep "${DELAY:-$DELAY}" || : ) &
88
80
            sleep=$!
89
81
            while :; do
90
 
                kill -0 $sleep 2>/dev/null || break
 
82
                kill -0 $sleep || break
91
83
                STATE=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" status | sed -n -e 's/^wpa_state=//p'`
92
84
                if [ "$STATE" = COMPLETED ]; then
93
 
                    while :; do
94
 
                        kill -0 $sleep 2>/dev/null || break 2
95
 
                        UP=`cat /sys/class/net/"$INTERFACE"/operstate`
96
 
                        if [ "$UP" = up ]; then
97
 
                            kill $sleep 2>/dev/null
98
 
                            break 2
99
 
                        fi
100
 
                        sleep 1
101
 
                    done
 
85
                    kill $sleep
 
86
                    break
102
87
                fi
103
88
                sleep 1
104
89
            done &
105
90
            wait $sleep || :
106
 
            IPADDRS=`eval 'echo "$IPADDRS_'"$KEY"\"`
 
91
            IPADDRS=`eval 'echo "$IPADDRS_'"$INTERFACE"\"`
107
92
            if [ -n "$IPADDRS" ]; then
108
93
                if [ "$IPADDRS" = dhcp ]; then
109
94
                    ipconfig -c dhcp -d "$INTERFACE" || :
114
99
                    done
115
100
                fi
116
101
            fi
117
 
            ROUTES=`eval 'echo "$ROUTES_'"$KEY"\"`
 
102
            ROUTES=`eval 'echo "$ROUTES_'"$INTERFACE"\"`
118
103
            if [ -n "$ROUTES" ]; then
119
104
                for route in $ROUTES; do
120
105
                    "$ip" route add "$route" dev "$BRIDGE"
124
109
        ;;
125
110
    stop)
126
111
        "$wpa_cli" -g "$CTRL" terminate 2>&1 | sed -e '/^OK$/d'
127
 
        for KEY in $ifkeys; do
128
 
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
129
 
            INTERFACE=`addrtoif "$ADDRESS"`
 
112
        for INTERFACE in $interfaces; do
130
113
            "$ip" addr show scope global permanent dev "$INTERFACE" \
131
114
                | while read type addr rest; do
132
115
                case "$type" in
147
130
        if [ "$IPADDRS" = dhcp ]; then
148
131
            echo af_packet
149
132
        fi
150
 
        sed -n -e 's/#.*$//' -e 's/[    ]*$//' \
151
 
            -e 's/^MODULE_[^=]\+=//p' "$CONFIG"
 
133
        sed -n -e 's/#.*$//' -e 's/[    ]*$//' -e 's/^MODULE=//p' \
 
134
            "$CONFIG"
152
135
        ;;
153
136
esac