/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to network-hooks.d/wireless

  • Committer: Teddy Hogeborn
  • Date: 2012-01-15 21:01:13 UTC
  • Revision ID: teddy@recompile.se-20120115210113-mzpkowq0opshtu30
* mandos.xml (CHECKING): Don't claim that a successful secret request
                         is equivalent to a successful checker.

Show diffs side-by-side

added added

removed removed

Lines of Context:
6
6
# configuration file(s) should be copied into the
7
7
# /etc/mandos/network-hooks.d directory.
8
8
 
9
# Copyright © 2012 Teddy Hogeborn
 
10
# Copyright © 2012 Björn Påhlsson
 
11
9
12
# Copying and distribution of this file, with or without modification,
10
13
# are permitted in any medium without royalty provided the copyright
11
14
# notice and this notice are preserved.  This file is offered as-is,
20
23
 
21
24
CONFIG="$MANDOSNETHOOKDIR/wireless.conf"
22
25
 
 
26
addrtoif(){
 
27
    grep -liFe "$1" /sys/class/net/*/address \
 
28
        | sed -e 's,.*/\([^/]*\)/[^/]*,\1,'
 
29
}
 
30
 
23
31
# Read config file
24
32
if [ -e "$CONFIG" ]; then
25
33
    . "$CONFIG"
27
35
    exit
28
36
fi
29
37
 
30
 
interfaces="`env|sed -n -e 's/^\(MODULE\|IPADDRS\|ROUTES\|WPA_DRIVER\)_\([^=]*\)=.*/\2/p' \"$CONFIG\" |sort -u`"
 
38
ifkeys=`env | sed -n -e 's/^ADDRESS_\([^=]*\)=.*/\1/p' "$CONFIG" \
 
39
    | sort -u`
31
40
 
32
41
# Exit if DEVICE is set and is not any of the wireless interfaces
33
42
if [ -n "$DEVICE" ]; then
34
43
    while :; do
35
 
        for IF in $interfaces; do
36
 
            if [ "$IF" = "$DEVICE" ]; then
 
44
        for KEY in $ifkeys; do
 
45
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
 
46
            INTERFACE=`addrtoif "$ADDRESS"`
 
47
            if [ "$INTERFACE" = "$DEVICE" ]; then
37
48
                break 2
38
49
            fi
39
50
        done
66
77
    start)
67
78
        mkdir -m u=rwx,go= -p "$CTRLDIR"
68
79
        "$wpa_supplicant" -B -g "$CTRL" -p "$CTRLDIR" $WPAS_OPTIONS
69
 
        for INTERFACE in $interfaces; do
70
 
            DRIVER=`eval 'echo "$WPA_DRIVER_'"$INTERFACE"\"`
71
 
            DELAY=`eval 'echo "$DELAY_'"$INTERFACE"\"`
 
80
        for KEY in $ifkeys; do
 
81
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
 
82
            INTERFACE=`addrtoif "$ADDRESS"`
 
83
            DRIVER=`eval 'echo "$WPA_DRIVER_'"$KEY"\"`
 
84
            IFDELAY=`eval 'echo "$DELAY_'"$KEY"\"`
72
85
            "$wpa_cli" -g "$CTRL" interface_add "$INTERFACE" "" \
73
86
                "${DRIVER:-wext}" "$CTRLDIR" > /dev/null \
74
87
                | sed -e '/^OK$/d'
75
 
            NETWORK=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" add_network`
76
 
            eval wpa_interface_"$INTERFACE"
 
88
            NETWORK=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" \
 
89
                add_network`
 
90
            eval wpa_interface_"$KEY"
77
91
            "$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" enable_network \
78
92
                "$NETWORK" | sed -e '/^OK$/d'
79
 
            ( sleep "${DELAY:-$DELAY}" || : ) &
 
93
            sleep "${IFDELAY:-$DELAY}" &
80
94
            sleep=$!
81
95
            while :; do
82
 
                kill -0 $sleep || break
83
 
                STATE=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" status | sed -n -e 's/^wpa_state=//p'`
 
96
                kill -0 $sleep 2>/dev/null || break
 
97
                STATE=`"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" \
 
98
                    status | sed -n -e 's/^wpa_state=//p'`
84
99
                if [ "$STATE" = COMPLETED ]; then
85
 
                    kill $sleep
86
 
                    break
 
100
                    while :; do
 
101
                        kill -0 $sleep 2>/dev/null || break 2
 
102
                        UP=`cat /sys/class/net/"$INTERFACE"/operstate`
 
103
                        if [ "$UP" = up ]; then
 
104
                            kill $sleep 2>/dev/null
 
105
                            break 2
 
106
                        fi
 
107
                        sleep 1
 
108
                    done
87
109
                fi
88
110
                sleep 1
89
111
            done &
90
112
            wait $sleep || :
91
 
            IPADDRS=`eval 'echo "$IPADDRS_'"$INTERFACE"\"`
 
113
            IPADDRS=`eval 'echo "$IPADDRS_'"$KEY"\"`
92
114
            if [ -n "$IPADDRS" ]; then
93
115
                if [ "$IPADDRS" = dhcp ]; then
94
116
                    ipconfig -c dhcp -d "$INTERFACE" || :
99
121
                    done
100
122
                fi
101
123
            fi
102
 
            ROUTES=`eval 'echo "$ROUTES_'"$INTERFACE"\"`
 
124
            ROUTES=`eval 'echo "$ROUTES_'"$KEY"\"`
103
125
            if [ -n "$ROUTES" ]; then
104
126
                for route in $ROUTES; do
105
127
                    "$ip" route add "$route" dev "$BRIDGE"
109
131
        ;;
110
132
    stop)
111
133
        "$wpa_cli" -g "$CTRL" terminate 2>&1 | sed -e '/^OK$/d'
112
 
        for INTERFACE in $interfaces; do
 
134
        for KEY in $ifkeys; do
 
135
            ADDRESS=`eval 'echo "$ADDRESS_'"$KEY"\"`
 
136
            INTERFACE=`addrtoif "$ADDRESS"`
113
137
            "$ip" addr show scope global permanent dev "$INTERFACE" \
114
138
                | while read type addr rest; do
115
139
                case "$type" in
130
154
        if [ "$IPADDRS" = dhcp ]; then
131
155
            echo af_packet
132
156
        fi
133
 
        sed -n -e 's/#.*$//' -e 's/[    ]*$//' -e 's/^MODULE=//p' \
134
 
            "$CONFIG"
 
157
        sed -n -e 's/#.*$//' -e 's/[    ]*$//' \
 
158
            -e 's/^MODULE_[^=]\+=//p' "$CONFIG"
135
159
        ;;
136
160
esac