/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to network-hooks.d/wireless

  • Committer: teddy at recompile
  • Date: 2011-12-31 13:25:58 UTC
  • mto: This revision was merged to the branch mainline in revision 541.
  • Revision ID: teddy@recompile.se-20111231132558-z0dh7qgofgctmgri
* network-hooks.s/bridge: Don't use interface names directly; search
                          for interface names using their address.
  (addrtoif): New function.
* network-hooks.s/bridge.conf (PORTS): Removed.
  (PORT_ADDRESSES): New.
* network-hooks.s/wireless: Don't use interface names directly; search
                            for interface names using their address.
  (addrtoif): New function.
* network-hooks.s/wireless.conf: Specify address.

Show diffs side-by-side

added added

removed removed

Lines of Context:
6
6
# configuration file(s) should be copied into the
7
7
# /etc/mandos/network-hooks.d directory.
8
8
9
 
# Copyright © 2012 Teddy Hogeborn
10
 
# Copyright © 2012 Björn Påhlsson
11
 
12
9
# Copying and distribution of this file, with or without modification,
13
10
# are permitted in any medium without royalty provided the copyright
14
11
# notice and this notice are preserved.  This file is offered as-is,
24
21
CONFIG="$MANDOSNETHOOKDIR/wireless.conf"
25
22
 
26
23
addrtoif(){
27
 
    grep -liFe "$1" /sys/class/net/*/address \
28
 
        | sed -e 's,.*/\([^/]*\)/[^/]*,\1,'
 
24
    grep -liFe "$1" /sys/class/net/*/address | sed -e 's,.*/\([^/]*\)/[^/]*,\1,'
29
25
}
30
26
 
31
27
# Read config file
35
31
    exit
36
32
fi
37
33
 
38
 
ifkeys=`sed -n -e 's/^ADDRESS_\([^=]*\)=.*/\1/p' "$CONFIG" | sort -u`
 
34
ifkeys="`env | sed -n -e 's/^ADDRESS_\([^=]*\)=.*/\1/p' \"$CONFIG\" | sort -u`"
39
35
 
40
36
# Exit if DEVICE is set and is not any of the wireless interfaces
41
37
if [ -n "$DEVICE" ]; then
43
39
        for KEY in $ifkeys; do
44
40
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
45
41
            INTERFACE=`addrtoif "$ADDRESS"`
46
 
            
47
 
            case "$DEVICE" in
48
 
                *,"$INTERFACE"|*,"$INTERFACE",*|"$INTERFACE",*|"$INTERFACE")
49
 
                    break 2;;
50
 
            esac
 
42
            if [ "$INTERFACE" = "$DEVICE" ]; then
 
43
                break 2
 
44
            fi
51
45
        done
52
46
        exit
53
47
    done
74
68
    WPAS_OPTIONS="-P$PIDFILE $WPAS_OPTIONS"
75
69
fi
76
70
 
77
 
do_start(){
78
 
    mkdir -m u=rwx,go= -p "$CTRLDIR"
79
 
    "$wpa_supplicant" -B -g "$CTRL" -p "$CTRLDIR" $WPAS_OPTIONS
80
 
    for KEY in $ifkeys; do
81
 
        ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
82
 
        INTERFACE=`addrtoif "$ADDRESS"`
83
 
        DRIVER=`eval 'echo "$WPA_DRIVER_'"$KEY"\"`
84
 
        IFDELAY=`eval 'echo "$DELAY_'"$KEY"\"`
85
 
        "$wpa_cli" -g "$CTRL" interface_add "$INTERFACE" "" \
86
 
            "${DRIVER:-wext}" "$CTRLDIR" > /dev/null \
87
 
            | sed -e '/^OK$/d'
88
 
        NETWORK=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" add_network`
89
 
        eval wpa_interface_"$KEY"
90
 
        "$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" enable_network \
91
 
            "$NETWORK" | sed -e '/^OK$/d'
92
 
        sleep "${IFDELAY:-$DELAY}" &
93
 
        sleep=$!
94
 
        while :; do
95
 
            kill -0 $sleep 2>/dev/null || break
96
 
            STATE=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" status \
97
 
                | sed -n -e 's/^wpa_state=//p'`
98
 
            if [ "$STATE" = COMPLETED ]; then
99
 
                while :; do
100
 
                    kill -0 $sleep 2>/dev/null || break 2
101
 
                    UP=`cat /sys/class/net/"$INTERFACE"/operstate`
102
 
                    if [ "$UP" = up ]; then
103
 
                        kill $sleep 2>/dev/null
104
 
                        break 2
105
 
                    fi
106
 
                    sleep 1
107
 
                done
108
 
            fi
109
 
            sleep 1
110
 
        done &
111
 
        wait $sleep || :
112
 
        IPADDRS=`eval 'echo "$IPADDRS_'"$KEY"\"`
113
 
        if [ -n "$IPADDRS" ]; then
114
 
            if [ "$IPADDRS" = dhcp ]; then
115
 
                ipconfig -c dhcp -d "$INTERFACE" || :
116
 
                #dhclient "$INTERFACE"
117
 
            else
118
 
                for ipaddr in $IPADDRS; do
119
 
                    "$ip" addr add "$ipaddr" dev "$INTERFACE"
120
 
                done
121
 
            fi
122
 
        fi
123
 
        ROUTES=`eval 'echo "$ROUTES_'"$KEY"\"`
124
 
        if [ -n "$ROUTES" ]; then
125
 
            for route in $ROUTES; do
126
 
                "$ip" route add "$route" dev "$INTERFACE"
127
 
            done
128
 
        fi
129
 
    done
130
 
}
131
 
 
132
 
do_stop(){
133
 
    "$wpa_cli" -g "$CTRL" terminate 2>&1 | sed -e '/^OK$/d'
134
 
    for KEY in $ifkeys; do
135
 
        ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
136
 
        INTERFACE=`addrtoif "$ADDRESS"`
137
 
        "$ip" addr show scope global permanent dev "$INTERFACE" \
138
 
            | while read type addr rest; do
 
71
case "${MODE:-$1}" in
 
72
    start)
 
73
        mkdir -m u=rwx,go= -p "$CTRLDIR"
 
74
        "$wpa_supplicant" -B -g "$CTRL" -p "$CTRLDIR" $WPAS_OPTIONS
 
75
        for KEY in $ifkeys; do
 
76
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
 
77
            INTERFACE=`addrtoif "$ADDRESS"`
 
78
            DRIVER=`eval 'echo "$WPA_DRIVER_'"$KEY"\"`
 
79
            IFDELAY=`eval 'echo "$DELAY_'"$KEY"\"`
 
80
            "$wpa_cli" -g "$CTRL" interface_add "$INTERFACE" "" \
 
81
                "${DRIVER:-wext}" "$CTRLDIR" > /dev/null \
 
82
                | sed -e '/^OK$/d'
 
83
            NETWORK=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" add_network`
 
84
            eval wpa_interface_"$KEY"
 
85
            "$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" enable_network \
 
86
                "$NETWORK" | sed -e '/^OK$/d'
 
87
            sleep "${IFDELAY:-$DELAY}" &
 
88
            sleep=$!
 
89
            while :; do
 
90
                kill -0 $sleep 2>/dev/null || break
 
91
                STATE=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" status | sed -n -e 's/^wpa_state=//p'`
 
92
                if [ "$STATE" = COMPLETED ]; then
 
93
                    while :; do
 
94
                        kill -0 $sleep 2>/dev/null || break 2
 
95
                        UP=`cat /sys/class/net/"$INTERFACE"/operstate`
 
96
                        if [ "$UP" = up ]; then
 
97
                            kill $sleep 2>/dev/null
 
98
                            break 2
 
99
                        fi
 
100
                        sleep 1
 
101
                    done
 
102
                fi
 
103
                sleep 1
 
104
            done &
 
105
            wait $sleep || :
 
106
            IPADDRS=`eval 'echo "$IPADDRS_'"$KEY"\"`
 
107
            if [ -n "$IPADDRS" ]; then
 
108
                if [ "$IPADDRS" = dhcp ]; then
 
109
                    ipconfig -c dhcp -d "$INTERFACE" || :
 
110
                    #dhclient "$INTERFACE"
 
111
                else
 
112
                    for ipaddr in $IPADDRS; do
 
113
                        "$ip" addr add "$ipaddr" dev "$INTERFACE"
 
114
                    done
 
115
                fi
 
116
            fi
 
117
            ROUTES=`eval 'echo "$ROUTES_'"$KEY"\"`
 
118
            if [ -n "$ROUTES" ]; then
 
119
                for route in $ROUTES; do
 
120
                    "$ip" route add "$route" dev "$BRIDGE"
 
121
                done
 
122
            fi
 
123
        done
 
124
        ;;
 
125
    stop)
 
126
        "$wpa_cli" -g "$CTRL" terminate 2>&1 | sed -e '/^OK$/d'
 
127
        for KEY in $ifkeys; do
 
128
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
 
129
            INTERFACE=`addrtoif "$ADDRESS"`
 
130
            "$ip" addr show scope global permanent dev "$INTERFACE" \
 
131
                | while read type addr rest; do
139
132
                case "$type" in
140
133
                    inet|inet6)
141
134
                        "$ip" addr del "$addr" dev "$INTERFACE"
142
135
                        ;;
143
136
                esac
144
137
            done
145
 
        "$ip" link set dev "$INTERFACE" down
146
 
    done
147
 
}
148
 
 
149
 
case "${MODE:-$1}" in
150
 
    start|stop)
151
 
        do_"${MODE:-$1}"
 
138
            "$ip" link set dev "$INTERFACE" down
 
139
        done
152
140
        ;;
153
141
    files)
154
142
        echo "$wpa_supplicant"