- import of strongswan-2.7.0
- applied patch for charon
This commit is contained in:
@@ -0,0 +1 @@
|
||||
HOSTNAME=sun
|
||||
@@ -0,0 +1,13 @@
|
||||
# /etc/conf.d/net:
|
||||
|
||||
# This is basically the ifconfig argument without the ifconfig $iface
|
||||
#
|
||||
iface_lo="127.0.0.1 netmask 255.0.0.0"
|
||||
iface_eth0="PH_IP_SUN broadcast 192.168.0.255 netmask 255.255.255.0"
|
||||
iface_eth1="PH_IP1_SUN broadcast 10.2.255.255 netmask 255.255.0.0"
|
||||
|
||||
# For setting the default gateway
|
||||
#
|
||||
gateway="eth0/192.168.0.254"
|
||||
|
||||
|
||||
Executable
+80
@@ -0,0 +1,80 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2004 Gentoo Foundation
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
opts="start stop reload"
|
||||
|
||||
depend() {
|
||||
before net
|
||||
need logger
|
||||
}
|
||||
|
||||
start() {
|
||||
ebegin "Starting firewall"
|
||||
|
||||
# enable IP forwarding
|
||||
echo 1 > /proc/sys/net/ipv4/ip_forward
|
||||
|
||||
# default policy is DROP
|
||||
/sbin/iptables -P INPUT DROP
|
||||
/sbin/iptables -P OUTPUT DROP
|
||||
/sbin/iptables -P FORWARD DROP
|
||||
|
||||
# allow esp
|
||||
iptables -A INPUT -i eth0 -p 50 -j ACCEPT
|
||||
iptables -A OUTPUT -o eth0 -p 50 -j ACCEPT
|
||||
|
||||
# allow IKE
|
||||
iptables -A INPUT -i eth0 -p udp --dport 500 -j ACCEPT
|
||||
iptables -A OUTPUT -o eth0 -p udp --sport 500 -j ACCEPT
|
||||
|
||||
# allow NAT-T
|
||||
iptables -A INPUT -i eth0 -p udp --dport 4500 -j ACCEPT
|
||||
iptables -A OUTPUT -o eth0 -p udp --sport 4500 -j ACCEPT
|
||||
|
||||
# allow crl fetch from winnetou
|
||||
iptables -A INPUT -i eth0 -p tcp --sport 80 -s PH_IP_WINNETOU -j ACCEPT
|
||||
iptables -A OUTPUT -o eth0 -p tcp --dport 80 -d PH_IP_WINNETOU -j ACCEPT
|
||||
|
||||
# allow ssh
|
||||
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
|
||||
iptables -A OUTPUT -p tcp --sport 22 -j ACCEPT
|
||||
|
||||
eend $?
|
||||
}
|
||||
|
||||
stop() {
|
||||
ebegin "Stopping firewall"
|
||||
for a in `cat /proc/net/ip_tables_names`; do
|
||||
/sbin/iptables -F -t $a
|
||||
/sbin/iptables -X -t $a
|
||||
|
||||
if [ $a == nat ]; then
|
||||
/sbin/iptables -t nat -P PREROUTING ACCEPT
|
||||
/sbin/iptables -t nat -P POSTROUTING ACCEPT
|
||||
/sbin/iptables -t nat -P OUTPUT ACCEPT
|
||||
elif [ $a == mangle ]; then
|
||||
/sbin/iptables -t mangle -P PREROUTING ACCEPT
|
||||
/sbin/iptables -t mangle -P INPUT ACCEPT
|
||||
/sbin/iptables -t mangle -P FORWARD ACCEPT
|
||||
/sbin/iptables -t mangle -P OUTPUT ACCEPT
|
||||
/sbin/iptables -t mangle -P POSTROUTING ACCEPT
|
||||
elif [ $a == filter ]; then
|
||||
/sbin/iptables -t filter -P INPUT ACCEPT
|
||||
/sbin/iptables -t filter -P FORWARD ACCEPT
|
||||
/sbin/iptables -t filter -P OUTPUT ACCEPT
|
||||
fi
|
||||
done
|
||||
eend $?
|
||||
}
|
||||
|
||||
reload() {
|
||||
ebegin "Flushing firewall"
|
||||
for a in `cat /proc/net/ip_tables_names`; do
|
||||
/sbin/iptables -F -t $a
|
||||
/sbin/iptables -X -t $a
|
||||
done;
|
||||
eend $?
|
||||
start
|
||||
}
|
||||
|
||||
Executable
+314
@@ -0,0 +1,314 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2004 Gentoo Technologies, Inc.
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
#NB: Config is in /etc/conf.d/net
|
||||
|
||||
if [[ -n $NET_DEBUG ]]; then
|
||||
set -x
|
||||
devnull=/dev/stderr
|
||||
else
|
||||
devnull=/dev/null
|
||||
fi
|
||||
|
||||
# For pcmcia users. note that pcmcia must be added to the same
|
||||
# runlevel as the net.* script that needs it.
|
||||
depend() {
|
||||
use hotplug pcmcia
|
||||
}
|
||||
|
||||
checkconfig() {
|
||||
if [[ -z "${ifconfig_IFACE}" ]]; then
|
||||
eerror "Please make sure that /etc/conf.d/net has \$ifconfig_$IFACE set"
|
||||
eerror "(or \$iface_$IFACE for old-style configuration)"
|
||||
return 1
|
||||
fi
|
||||
if [[ -n "${vlans_IFACE}" && ! -x /sbin/vconfig ]]; then
|
||||
eerror "For VLAN (802.1q) support, emerge net-misc/vconfig"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Fix bug 50039 (init.d/net.eth0 localization)
|
||||
# Some other commands in this script might need to be wrapped, but
|
||||
# we'll get them one-by-one. Note that LC_ALL trumps LC_anything_else
|
||||
# according to locale(7)
|
||||
ifconfig() {
|
||||
LC_ALL=C /sbin/ifconfig "$@"
|
||||
}
|
||||
|
||||
# setup_vars: setup variables based on $1 and content of /etc/conf.d/net
|
||||
# The following variables are set, which should be declared local by
|
||||
# the calling routine.
|
||||
# status_IFACE (up or '')
|
||||
# vlans_IFACE (space-separated list)
|
||||
# ifconfig_IFACE (array of ifconfig lines, replaces iface_IFACE)
|
||||
# dhcpcd_IFACE (command-line args for dhcpcd)
|
||||
# routes_IFACE (array of route lines)
|
||||
# inet6_IFACE (array of inet6 lines)
|
||||
# ifconfig_fallback_IFACE (fallback ifconfig if dhcp fails)
|
||||
setup_vars() {
|
||||
local i iface="${1//\./_}"
|
||||
|
||||
status_IFACE="$(ifconfig ${1} 2>${devnull} | gawk '$1 == "UP" {print "up"}')"
|
||||
eval vlans_IFACE=\"\$\{iface_${iface}_vlans\}\"
|
||||
eval ifconfig_IFACE=( \"\$\{ifconfig_$iface\[@\]\}\" )
|
||||
eval dhcpcd_IFACE=\"\$\{dhcpcd_$iface\}\"
|
||||
eval routes_IFACE=( \"\$\{routes_$iface\[@\]\}\" )
|
||||
eval inet6_IFACE=( \"\$\{inet6_$iface\[@\]\}\" )
|
||||
eval ifconfig_fallback_IFACE=( \"\$\{ifconfig_fallback_$iface\[@\]\}\" )
|
||||
|
||||
# BACKWARD COMPATIBILITY: populate the ifconfig_IFACE array
|
||||
# if iface_IFACE is set (fex. iface_eth0 instead of ifconfig_eth0)
|
||||
eval local iface_IFACE=\"\$\{iface_$iface\}\"
|
||||
if [[ -n ${iface_IFACE} && -z ${ifconfig_IFACE} ]]; then
|
||||
# Make sure these get evaluated as arrays
|
||||
local -a aliases broadcasts netmasks
|
||||
|
||||
# Start with the primary interface
|
||||
ifconfig_IFACE=( "${iface_IFACE}" )
|
||||
|
||||
# ..then add aliases
|
||||
eval aliases=( \$\{alias_$iface\} )
|
||||
eval broadcasts=( \$\{broadcast_$iface\} )
|
||||
eval netmasks=( \$\{netmask_$iface\} )
|
||||
for ((i = 0; i < ${#aliases[@]}; i = i + 1)); do
|
||||
ifconfig_IFACE[i+1]="${aliases[i]} ${broadcasts[i]:+broadcast ${broadcasts[i]}} ${netmasks[i]:+netmask ${netmasks[i]}}"
|
||||
done
|
||||
fi
|
||||
|
||||
# BACKWARD COMPATIBILITY: check for space-separated inet6 addresses
|
||||
if [[ ${#inet6_IFACE[@]} == 1 && ${inet6_IFACE} == *' '* ]]; then
|
||||
inet6_IFACE=( ${inet6_IFACE} )
|
||||
fi
|
||||
}
|
||||
|
||||
iface_start() {
|
||||
local IFACE=${1} i x retval
|
||||
checkconfig || return 1
|
||||
|
||||
if [[ ${ifconfig_IFACE} != dhcp ]]; then
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Bringing ${IFACE} up (${i})"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up"
|
||||
fi
|
||||
# ifconfig does not always return failure ..
|
||||
ifconfig ${IFACE} ${ifconfig_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
# Check that eth0 was not brought up by the kernel ...
|
||||
if [[ ${status_IFACE} == up ]]; then
|
||||
einfo "Keeping kernel configuration for ${IFACE}"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up via DHCP"
|
||||
/sbin/dhcpcd ${dhcpcd_IFACE} ${IFACE}
|
||||
retval=$?
|
||||
eend $retval
|
||||
if [[ $retval == 0 ]]; then
|
||||
# DHCP succeeded, show address retrieved
|
||||
i=$(ifconfig ${IFACE} | grep -m1 -o 'inet addr:[^ ]*' |
|
||||
cut -d: -f2)
|
||||
[[ -n ${i} ]] && einfo " ${IFACE} received address ${i}"
|
||||
elif [[ -n "${ifconfig_fallback_IFACE}" ]]; then
|
||||
# DHCP failed, try fallback.
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_fallback_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Using fallback configuration (${i}) for ${IFACE}"
|
||||
else
|
||||
ebegin "Using fallback configuration for ${IFACE}"
|
||||
fi
|
||||
ifconfig ${IFACE} ${ifconfig_fallback_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
return $retval
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if [[ ${#ifconfig_IFACE[@]} -gt 1 ]]; then
|
||||
einfo " Adding aliases"
|
||||
for ((i = 1; i < ${#ifconfig_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE}:${i} (${ifconfig_IFACE[i]%% *})"
|
||||
ifconfig ${IFACE}:${i} ${ifconfig_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
if [[ -n ${inet6_IFACE} ]]; then
|
||||
einfo " Adding inet6 addresses"
|
||||
for ((i = 0; i < ${#inet6_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE} inet6 add ${inet6_IFACE[i]}"
|
||||
ifconfig ${IFACE} inet6 add ${inet6_IFACE[i]} >${devnull}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set static routes
|
||||
if [[ -n ${routes_IFACE} ]]; then
|
||||
einfo " Adding routes"
|
||||
for ((i = 0; i < ${#routes_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${routes_IFACE[i]}"
|
||||
/sbin/route add ${routes_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set default route if applicable to this interface
|
||||
if [[ ${gateway} == ${IFACE}/* ]]; then
|
||||
local ogw=$(/bin/netstat -rn | awk '$1 == "0.0.0.0" {print $2}')
|
||||
local gw=${gateway#*/}
|
||||
if [[ ${ogw} != ${gw} ]]; then
|
||||
ebegin " Setting default gateway ($gw)"
|
||||
|
||||
# First delete any existing route if it was setup by kernel...
|
||||
/sbin/route del default dev ${IFACE} &>${devnull}
|
||||
|
||||
# Second delete old gateway if it was set...
|
||||
/sbin/route del default gw ${ogw} &>${devnull}
|
||||
|
||||
# Third add our new default gateway
|
||||
/sbin/route add default gw ${gw} >${devnull}
|
||||
eend $? || {
|
||||
true # need to have some command in here
|
||||
# Note: This originally called stop, which is obviously
|
||||
# wrong since it's calling with a local version of IFACE.
|
||||
# The below code works correctly to abort configuration of
|
||||
# the interface, but is commented because we're assuming
|
||||
# that default route failure should not cause the interface
|
||||
# to be unconfigured.
|
||||
#local error=$?
|
||||
#ewarn "Aborting configuration of ${IFACE}"
|
||||
#iface_stop ${IFACE}
|
||||
#return ${error}
|
||||
}
|
||||
fi
|
||||
fi
|
||||
|
||||
# Enabling rp_filter causes wacky packets to be auto-dropped by
|
||||
# the kernel. Note that we only do this if it is not set via
|
||||
# /etc/sysctl.conf ...
|
||||
if [[ -e /proc/sys/net/ipv4/conf/${IFACE}/rp_filter && \
|
||||
-z "$(grep -s '^[^#]*rp_filter' /etc/sysctl.conf)" ]]; then
|
||||
echo -n 1 > /proc/sys/net/ipv4/conf/${IFACE}/rp_filter
|
||||
fi
|
||||
}
|
||||
|
||||
# iface_stop: bring down an interface. Don't trust information in
|
||||
# /etc/conf.d/net since the configuration might have changed since
|
||||
# iface_start ran. Instead query for current configuration and bring
|
||||
# down the interface.
|
||||
iface_stop() {
|
||||
local IFACE=${1} i x aliases inet6 count
|
||||
|
||||
# Try to do a simple down (no aliases, no inet6, no dhcp)
|
||||
aliases="$(ifconfig | grep -o "^$IFACE:[0-9]*" | tac)"
|
||||
inet6="$(ifconfig ${IFACE} | awk '$1 == "inet6" {print $2}')"
|
||||
if [[ -z ${aliases} && -z ${inet6} && ! -e /var/run/dhcpcd-${IFACE}.pid ]]; then
|
||||
ebegin "Bringing ${IFACE} down"
|
||||
ifconfig ${IFACE} down &>/dev/null
|
||||
eend 0
|
||||
return 0
|
||||
fi
|
||||
|
||||
einfo "Bringing ${IFACE} down"
|
||||
|
||||
# Stop aliases before primary interface.
|
||||
# Note this must be done in reverse order, since ifconfig eth0:1
|
||||
# will remove eth0:2, etc. It might be sufficient to simply remove
|
||||
# the base interface but we're being safe here.
|
||||
for i in ${aliases} ${IFACE}; do
|
||||
|
||||
# Delete all the inet6 addresses for this interface
|
||||
inet6="$(ifconfig ${i} | awk '$1 == "inet6" {print $3}')"
|
||||
if [[ -n ${inet6} ]]; then
|
||||
einfo " Removing inet6 addresses"
|
||||
for x in ${inet6}; do
|
||||
ebegin " ${IFACE} inet6 del ${x}"
|
||||
ifconfig ${i} inet6 del ${x}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Stop DHCP (should be N/A for aliases)
|
||||
# Don't trust current configuration... investigate ourselves
|
||||
if /sbin/dhcpcd -z ${i} &>${devnull}; then
|
||||
ebegin " Releasing DHCP lease for ${IFACE}"
|
||||
for ((count = 0; count < 9; count = count + 1)); do
|
||||
/sbin/dhcpcd -z ${i} &>${devnull} || break
|
||||
sleep 1
|
||||
done
|
||||
[[ ${count} -lt 9 ]]
|
||||
eend $? "Timed out"
|
||||
fi
|
||||
ebegin " Stopping ${i}"
|
||||
ifconfig ${i} down &>${devnull}
|
||||
eend 0
|
||||
done
|
||||
|
||||
return 0
|
||||
}
|
||||
|
||||
start() {
|
||||
# These variables are set by setup_vars
|
||||
local status_IFACE vlans_IFACE dhcpcd_IFACE
|
||||
local -a ifconfig_IFACE routes_IFACE inet6_IFACE
|
||||
|
||||
# Call user-defined preup function if it exists
|
||||
if [[ $(type -t preup) == function ]]; then
|
||||
einfo "Running preup function"
|
||||
preup ${IFACE} || {
|
||||
eerror "preup ${IFACE} failed"
|
||||
return 1
|
||||
}
|
||||
fi
|
||||
|
||||
# Start the primary interface and aliases
|
||||
setup_vars ${IFACE}
|
||||
iface_start ${IFACE} || return 1
|
||||
|
||||
# Start vlans
|
||||
local vlan
|
||||
for vlan in ${vlans_IFACE}; do
|
||||
/sbin/vconfig add ${IFACE} ${vlan} >${devnull}
|
||||
setup_vars ${IFACE}.${vlan}
|
||||
iface_start ${IFACE}.${vlan}
|
||||
done
|
||||
|
||||
# Call user-defined postup function if it exists
|
||||
if [[ $(type -t postup) == function ]]; then
|
||||
einfo "Running postup function"
|
||||
postup ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
stop() {
|
||||
# Call user-defined predown function if it exists
|
||||
if [[ $(type -t predown) == function ]]; then
|
||||
einfo "Running predown function"
|
||||
predown ${IFACE}
|
||||
fi
|
||||
|
||||
# Don't depend on setup_vars since configuration might have changed.
|
||||
# Investigate current configuration instead.
|
||||
local vlan
|
||||
for vlan in $(ifconfig | grep -o "^${IFACE}\.[^ ]*"); do
|
||||
iface_stop ${vlan}
|
||||
/sbin/vconfig rem ${vlan} >${devnull}
|
||||
done
|
||||
|
||||
iface_stop ${IFACE} || return 1 # always succeeds, btw
|
||||
|
||||
# Call user-defined postdown function if it exists
|
||||
if [[ $(type -t postdown) == function ]]; then
|
||||
einfo "Running postdown function"
|
||||
postdown ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
# vim:ts=4
|
||||
Executable
+314
@@ -0,0 +1,314 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2004 Gentoo Technologies, Inc.
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
#NB: Config is in /etc/conf.d/net
|
||||
|
||||
if [[ -n $NET_DEBUG ]]; then
|
||||
set -x
|
||||
devnull=/dev/stderr
|
||||
else
|
||||
devnull=/dev/null
|
||||
fi
|
||||
|
||||
# For pcmcia users. note that pcmcia must be added to the same
|
||||
# runlevel as the net.* script that needs it.
|
||||
depend() {
|
||||
use hotplug pcmcia
|
||||
}
|
||||
|
||||
checkconfig() {
|
||||
if [[ -z "${ifconfig_IFACE}" ]]; then
|
||||
eerror "Please make sure that /etc/conf.d/net has \$ifconfig_$IFACE set"
|
||||
eerror "(or \$iface_$IFACE for old-style configuration)"
|
||||
return 1
|
||||
fi
|
||||
if [[ -n "${vlans_IFACE}" && ! -x /sbin/vconfig ]]; then
|
||||
eerror "For VLAN (802.1q) support, emerge net-misc/vconfig"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Fix bug 50039 (init.d/net.eth0 localization)
|
||||
# Some other commands in this script might need to be wrapped, but
|
||||
# we'll get them one-by-one. Note that LC_ALL trumps LC_anything_else
|
||||
# according to locale(7)
|
||||
ifconfig() {
|
||||
LC_ALL=C /sbin/ifconfig "$@"
|
||||
}
|
||||
|
||||
# setup_vars: setup variables based on $1 and content of /etc/conf.d/net
|
||||
# The following variables are set, which should be declared local by
|
||||
# the calling routine.
|
||||
# status_IFACE (up or '')
|
||||
# vlans_IFACE (space-separated list)
|
||||
# ifconfig_IFACE (array of ifconfig lines, replaces iface_IFACE)
|
||||
# dhcpcd_IFACE (command-line args for dhcpcd)
|
||||
# routes_IFACE (array of route lines)
|
||||
# inet6_IFACE (array of inet6 lines)
|
||||
# ifconfig_fallback_IFACE (fallback ifconfig if dhcp fails)
|
||||
setup_vars() {
|
||||
local i iface="${1//\./_}"
|
||||
|
||||
status_IFACE="$(ifconfig ${1} 2>${devnull} | gawk '$1 == "UP" {print "up"}')"
|
||||
eval vlans_IFACE=\"\$\{iface_${iface}_vlans\}\"
|
||||
eval ifconfig_IFACE=( \"\$\{ifconfig_$iface\[@\]\}\" )
|
||||
eval dhcpcd_IFACE=\"\$\{dhcpcd_$iface\}\"
|
||||
eval routes_IFACE=( \"\$\{routes_$iface\[@\]\}\" )
|
||||
eval inet6_IFACE=( \"\$\{inet6_$iface\[@\]\}\" )
|
||||
eval ifconfig_fallback_IFACE=( \"\$\{ifconfig_fallback_$iface\[@\]\}\" )
|
||||
|
||||
# BACKWARD COMPATIBILITY: populate the ifconfig_IFACE array
|
||||
# if iface_IFACE is set (fex. iface_eth0 instead of ifconfig_eth0)
|
||||
eval local iface_IFACE=\"\$\{iface_$iface\}\"
|
||||
if [[ -n ${iface_IFACE} && -z ${ifconfig_IFACE} ]]; then
|
||||
# Make sure these get evaluated as arrays
|
||||
local -a aliases broadcasts netmasks
|
||||
|
||||
# Start with the primary interface
|
||||
ifconfig_IFACE=( "${iface_IFACE}" )
|
||||
|
||||
# ..then add aliases
|
||||
eval aliases=( \$\{alias_$iface\} )
|
||||
eval broadcasts=( \$\{broadcast_$iface\} )
|
||||
eval netmasks=( \$\{netmask_$iface\} )
|
||||
for ((i = 0; i < ${#aliases[@]}; i = i + 1)); do
|
||||
ifconfig_IFACE[i+1]="${aliases[i]} ${broadcasts[i]:+broadcast ${broadcasts[i]}} ${netmasks[i]:+netmask ${netmasks[i]}}"
|
||||
done
|
||||
fi
|
||||
|
||||
# BACKWARD COMPATIBILITY: check for space-separated inet6 addresses
|
||||
if [[ ${#inet6_IFACE[@]} == 1 && ${inet6_IFACE} == *' '* ]]; then
|
||||
inet6_IFACE=( ${inet6_IFACE} )
|
||||
fi
|
||||
}
|
||||
|
||||
iface_start() {
|
||||
local IFACE=${1} i x retval
|
||||
checkconfig || return 1
|
||||
|
||||
if [[ ${ifconfig_IFACE} != dhcp ]]; then
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Bringing ${IFACE} up (${i})"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up"
|
||||
fi
|
||||
# ifconfig does not always return failure ..
|
||||
ifconfig ${IFACE} ${ifconfig_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
# Check that eth0 was not brought up by the kernel ...
|
||||
if [[ ${status_IFACE} == up ]]; then
|
||||
einfo "Keeping kernel configuration for ${IFACE}"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up via DHCP"
|
||||
/sbin/dhcpcd ${dhcpcd_IFACE} ${IFACE}
|
||||
retval=$?
|
||||
eend $retval
|
||||
if [[ $retval == 0 ]]; then
|
||||
# DHCP succeeded, show address retrieved
|
||||
i=$(ifconfig ${IFACE} | grep -m1 -o 'inet addr:[^ ]*' |
|
||||
cut -d: -f2)
|
||||
[[ -n ${i} ]] && einfo " ${IFACE} received address ${i}"
|
||||
elif [[ -n "${ifconfig_fallback_IFACE}" ]]; then
|
||||
# DHCP failed, try fallback.
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_fallback_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Using fallback configuration (${i}) for ${IFACE}"
|
||||
else
|
||||
ebegin "Using fallback configuration for ${IFACE}"
|
||||
fi
|
||||
ifconfig ${IFACE} ${ifconfig_fallback_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
return $retval
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if [[ ${#ifconfig_IFACE[@]} -gt 1 ]]; then
|
||||
einfo " Adding aliases"
|
||||
for ((i = 1; i < ${#ifconfig_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE}:${i} (${ifconfig_IFACE[i]%% *})"
|
||||
ifconfig ${IFACE}:${i} ${ifconfig_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
if [[ -n ${inet6_IFACE} ]]; then
|
||||
einfo " Adding inet6 addresses"
|
||||
for ((i = 0; i < ${#inet6_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE} inet6 add ${inet6_IFACE[i]}"
|
||||
ifconfig ${IFACE} inet6 add ${inet6_IFACE[i]} >${devnull}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set static routes
|
||||
if [[ -n ${routes_IFACE} ]]; then
|
||||
einfo " Adding routes"
|
||||
for ((i = 0; i < ${#routes_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${routes_IFACE[i]}"
|
||||
/sbin/route add ${routes_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set default route if applicable to this interface
|
||||
if [[ ${gateway} == ${IFACE}/* ]]; then
|
||||
local ogw=$(/bin/netstat -rn | awk '$1 == "0.0.0.0" {print $2}')
|
||||
local gw=${gateway#*/}
|
||||
if [[ ${ogw} != ${gw} ]]; then
|
||||
ebegin " Setting default gateway ($gw)"
|
||||
|
||||
# First delete any existing route if it was setup by kernel...
|
||||
/sbin/route del default dev ${IFACE} &>${devnull}
|
||||
|
||||
# Second delete old gateway if it was set...
|
||||
/sbin/route del default gw ${ogw} &>${devnull}
|
||||
|
||||
# Third add our new default gateway
|
||||
/sbin/route add default gw ${gw} >${devnull}
|
||||
eend $? || {
|
||||
true # need to have some command in here
|
||||
# Note: This originally called stop, which is obviously
|
||||
# wrong since it's calling with a local version of IFACE.
|
||||
# The below code works correctly to abort configuration of
|
||||
# the interface, but is commented because we're assuming
|
||||
# that default route failure should not cause the interface
|
||||
# to be unconfigured.
|
||||
#local error=$?
|
||||
#ewarn "Aborting configuration of ${IFACE}"
|
||||
#iface_stop ${IFACE}
|
||||
#return ${error}
|
||||
}
|
||||
fi
|
||||
fi
|
||||
|
||||
# Enabling rp_filter causes wacky packets to be auto-dropped by
|
||||
# the kernel. Note that we only do this if it is not set via
|
||||
# /etc/sysctl.conf ...
|
||||
if [[ -e /proc/sys/net/ipv4/conf/${IFACE}/rp_filter && \
|
||||
-z "$(grep -s '^[^#]*rp_filter' /etc/sysctl.conf)" ]]; then
|
||||
echo -n 1 > /proc/sys/net/ipv4/conf/${IFACE}/rp_filter
|
||||
fi
|
||||
}
|
||||
|
||||
# iface_stop: bring down an interface. Don't trust information in
|
||||
# /etc/conf.d/net since the configuration might have changed since
|
||||
# iface_start ran. Instead query for current configuration and bring
|
||||
# down the interface.
|
||||
iface_stop() {
|
||||
local IFACE=${1} i x aliases inet6 count
|
||||
|
||||
# Try to do a simple down (no aliases, no inet6, no dhcp)
|
||||
aliases="$(ifconfig | grep -o "^$IFACE:[0-9]*" | tac)"
|
||||
inet6="$(ifconfig ${IFACE} | awk '$1 == "inet6" {print $2}')"
|
||||
if [[ -z ${aliases} && -z ${inet6} && ! -e /var/run/dhcpcd-${IFACE}.pid ]]; then
|
||||
ebegin "Bringing ${IFACE} down"
|
||||
ifconfig ${IFACE} down &>/dev/null
|
||||
eend 0
|
||||
return 0
|
||||
fi
|
||||
|
||||
einfo "Bringing ${IFACE} down"
|
||||
|
||||
# Stop aliases before primary interface.
|
||||
# Note this must be done in reverse order, since ifconfig eth0:1
|
||||
# will remove eth0:2, etc. It might be sufficient to simply remove
|
||||
# the base interface but we're being safe here.
|
||||
for i in ${aliases} ${IFACE}; do
|
||||
|
||||
# Delete all the inet6 addresses for this interface
|
||||
inet6="$(ifconfig ${i} | awk '$1 == "inet6" {print $3}')"
|
||||
if [[ -n ${inet6} ]]; then
|
||||
einfo " Removing inet6 addresses"
|
||||
for x in ${inet6}; do
|
||||
ebegin " ${IFACE} inet6 del ${x}"
|
||||
ifconfig ${i} inet6 del ${x}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Stop DHCP (should be N/A for aliases)
|
||||
# Don't trust current configuration... investigate ourselves
|
||||
if /sbin/dhcpcd -z ${i} &>${devnull}; then
|
||||
ebegin " Releasing DHCP lease for ${IFACE}"
|
||||
for ((count = 0; count < 9; count = count + 1)); do
|
||||
/sbin/dhcpcd -z ${i} &>${devnull} || break
|
||||
sleep 1
|
||||
done
|
||||
[[ ${count} -lt 9 ]]
|
||||
eend $? "Timed out"
|
||||
fi
|
||||
ebegin " Stopping ${i}"
|
||||
ifconfig ${i} down &>${devnull}
|
||||
eend 0
|
||||
done
|
||||
|
||||
return 0
|
||||
}
|
||||
|
||||
start() {
|
||||
# These variables are set by setup_vars
|
||||
local status_IFACE vlans_IFACE dhcpcd_IFACE
|
||||
local -a ifconfig_IFACE routes_IFACE inet6_IFACE
|
||||
|
||||
# Call user-defined preup function if it exists
|
||||
if [[ $(type -t preup) == function ]]; then
|
||||
einfo "Running preup function"
|
||||
preup ${IFACE} || {
|
||||
eerror "preup ${IFACE} failed"
|
||||
return 1
|
||||
}
|
||||
fi
|
||||
|
||||
# Start the primary interface and aliases
|
||||
setup_vars ${IFACE}
|
||||
iface_start ${IFACE} || return 1
|
||||
|
||||
# Start vlans
|
||||
local vlan
|
||||
for vlan in ${vlans_IFACE}; do
|
||||
/sbin/vconfig add ${IFACE} ${vlan} >${devnull}
|
||||
setup_vars ${IFACE}.${vlan}
|
||||
iface_start ${IFACE}.${vlan}
|
||||
done
|
||||
|
||||
# Call user-defined postup function if it exists
|
||||
if [[ $(type -t postup) == function ]]; then
|
||||
einfo "Running postup function"
|
||||
postup ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
stop() {
|
||||
# Call user-defined predown function if it exists
|
||||
if [[ $(type -t predown) == function ]]; then
|
||||
einfo "Running predown function"
|
||||
predown ${IFACE}
|
||||
fi
|
||||
|
||||
# Don't depend on setup_vars since configuration might have changed.
|
||||
# Investigate current configuration instead.
|
||||
local vlan
|
||||
for vlan in $(ifconfig | grep -o "^${IFACE}\.[^ ]*"); do
|
||||
iface_stop ${vlan}
|
||||
/sbin/vconfig rem ${vlan} >${devnull}
|
||||
done
|
||||
|
||||
iface_stop ${IFACE} || return 1 # always succeeds, btw
|
||||
|
||||
# Call user-defined postdown function if it exists
|
||||
if [[ $(type -t postdown) == function ]]; then
|
||||
einfo "Running postdown function"
|
||||
postdown ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
# vim:ts=4
|
||||
Executable
+37
@@ -0,0 +1,37 @@
|
||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||
|
||||
version 2.0 # conforms to second version of ipsec.conf specification
|
||||
|
||||
config setup
|
||||
plutodebug=control
|
||||
crlcheckinterval=180
|
||||
strictcrlpolicy=no
|
||||
nat_traversal=yes
|
||||
|
||||
conn %default
|
||||
ikelifetime=60m
|
||||
keylife=20m
|
||||
rekeymargin=3m
|
||||
keyingtries=1
|
||||
left=PH_IP_SUN
|
||||
leftcert=sunCert.pem
|
||||
[email protected]
|
||||
leftfirewall=yes
|
||||
|
||||
conn net-net
|
||||
leftsubnet=10.2.0.0/16
|
||||
right=PH_IP_MOON
|
||||
rightsubnet=10.1.0.0/16
|
||||
[email protected]
|
||||
auto=add
|
||||
|
||||
conn host-host
|
||||
right=PH_IP_MOON
|
||||
[email protected]
|
||||
auto=add
|
||||
|
||||
conn nat-t
|
||||
leftsubnet=10.2.0.0/16
|
||||
right=%any
|
||||
rightsubnetwithin=10.1.0.0/16
|
||||
auto=add
|
||||
@@ -0,0 +1,22 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIDtTCCAp2gAwIBAgIBADANBgkqhkiG9w0BAQQFADBFMQswCQYDVQQGEwJDSDEZ
|
||||
MBcGA1UEChMQTGludXggc3Ryb25nU3dhbjEbMBkGA1UEAxMSc3Ryb25nU3dhbiBS
|
||||
b290IENBMB4XDTA0MDkxMDExMDE0NVoXDTE0MDkwODExMDE0NVowRTELMAkGA1UE
|
||||
BhMCQ0gxGTAXBgNVBAoTEExpbnV4IHN0cm9uZ1N3YW4xGzAZBgNVBAMTEnN0cm9u
|
||||
Z1N3YW4gUm9vdCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL/y
|
||||
X2LqPVZuWLPIeknK86xhz6ljd3NNhC2z+P1uoCP3sBMuZiZQEjFzhnKcbXxCeo2f
|
||||
FnvhOOjrrisSuVkzuu82oxXD3fIkzuS7m9V4E10EZzgmKWIf+WuNRfbgAuUINmLc
|
||||
4YGAXBQLPyzpP4Ou48hhz/YQo58Bics6PHy5v34qCVROIXDvqhj91P8g+pS+F21/
|
||||
7P+CH2jRcVIEHZtG8M/PweTPQ95dPzpYd2Ov6SZ/U7EWmbMmT8VcUYn1aChxFmy5
|
||||
gweVBWlkH6MP+1DeE0/tL5c87xo5KCeGK8Tdqpe7sBRC4pPEEHDQciTUvkeuJ1Pr
|
||||
K+1LwdqRxo7HgMRiDw8CAwEAAaOBrzCBrDAPBgNVHRMBAf8EBTADAQH/MAsGA1Ud
|
||||
DwQEAwIBBjAdBgNVHQ4EFgQUXafdcAZRMn7ntm2zteXgYOouTe8wbQYDVR0jBGYw
|
||||
ZIAUXafdcAZRMn7ntm2zteXgYOouTe+hSaRHMEUxCzAJBgNVBAYTAkNIMRkwFwYD
|
||||
VQQKExBMaW51eCBzdHJvbmdTd2FuMRswGQYDVQQDExJzdHJvbmdTd2FuIFJvb3Qg
|
||||
Q0GCAQAwDQYJKoZIhvcNAQEEBQADggEBAJrXTj5gWS37myHHhii9drYwkMFyDHS/
|
||||
lHU8rW/drcnHdus507+qUhNr9SiEAHg4Ywj895UDvT0a1sFaw44QyEa/94iKA8/n
|
||||
+g5kS1IrKvWu3wu8UI3EgzChgHV3cncQlQWbK+FI9Y3Ax1O1np1r+wLptoWpKKKE
|
||||
UxsYcxP9K4Nbyeon0AIHOajUheiL3t6aRc3m0o7VU7Do6S2r+He+1Zq/nRUfFeTy
|
||||
0Atebkn8tmUpPSKWaXkmwpVNrjZ1Qu9umAU+dtJyhzL2zmnyhPC4VqpsKCOp7imy
|
||||
gKZvUIKPm1zyf4T+yjwxwkiX2xVseoM3aKswb1EoZFelHwndU7u0GQ8=
|
||||
-----END CERTIFICATE-----
|
||||
@@ -0,0 +1,24 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIECzCCAvOgAwIBAgIBAjANBgkqhkiG9w0BAQQFADBFMQswCQYDVQQGEwJDSDEZ
|
||||
MBcGA1UEChMQTGludXggc3Ryb25nU3dhbjEbMBkGA1UEAxMSc3Ryb25nU3dhbiBS
|
||||
b290IENBMB4XDTA0MDkxMDExMTU1M1oXDTA5MDkwOTExMTU1M1owRTELMAkGA1UE
|
||||
BhMCQ0gxGTAXBgNVBAoTEExpbnV4IHN0cm9uZ1N3YW4xGzAZBgNVBAMTEnN1bi5z
|
||||
dHJvbmdzd2FuLm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOQ8
|
||||
foB9h5BZ92gA5JkQTJNuoF6FAzoq91Gh7To27/g74p01+SUnsSaBfPmNfGp4avdS
|
||||
Ewy2dWMA/7uj0Dbe8MEKssNztp0JQubp2s7n8mrrQLGsqB6YAS09l75XDjS3yqTC
|
||||
AtH1kD4zAl/j/AyeQBuLR4CyJEmC/rqD3/a+pr42CaljuFBgBRpCTUpU4mlslZSe
|
||||
zv9wu61PwTFxb8VDlBHUd/lwkXThKgU3uEhWRxLahpSldEGmiTTmx30k/XbOMF2n
|
||||
HObEHt5EY9uWRGGbj81ZRWiNk0dNtbpneUHv/NvdWLc591M8cEGEQdWW2XTVbL2G
|
||||
N67q8hdzGgIvb7QJPMcCAwEAAaOCAQQwggEAMAkGA1UdEwQCMAAwCwYDVR0PBAQD
|
||||
AgOoMB0GA1UdDgQWBBQ9xLkyCBbyQmRet0vvV1Fg6z5q2DBtBgNVHSMEZjBkgBRd
|
||||
p91wBlEyfue2bbO15eBg6i5N76FJpEcwRTELMAkGA1UEBhMCQ0gxGTAXBgNVBAoT
|
||||
EExpbnV4IHN0cm9uZ1N3YW4xGzAZBgNVBAMTEnN0cm9uZ1N3YW4gUm9vdCBDQYIB
|
||||
ADAdBgNVHREEFjAUghJzdW4uc3Ryb25nc3dhbi5vcmcwOQYDVR0fBDIwMDAuoCyg
|
||||
KoYoaHR0cDovL2NybC5zdHJvbmdzd2FuLm9yZy9zdHJvbmdzd2FuLmNybDANBgkq
|
||||
hkiG9w0BAQQFAAOCAQEAGQQroiAa0SwwhJprGd7OM+rfBJAGbsa3DPzFCfHX1R7i
|
||||
ZyDs9aph1DK+IgUa377Ev1U7oB0EldpmOoJJugCjtNLfpW3t1RXBERL/QfpO2+VP
|
||||
Wt3SfZ0Oq48jiqB1MVLMZRPCICZEQjT4sJ3HYs5ZuucuvoxeMx3rQ4HxUtHtMD3S
|
||||
5JNMwFFiOXAjyIyrTlb7YuRJTT5hE+Rms8GUQ5Xnt7zKZ7yfoSLFzy0/cLFPdQvE
|
||||
JA7w8crODCZpDgEKVHVyUWuyt1O46N3ydUfDcnKJoQ9HWHm3xCbDex5MHTnvm1lk
|
||||
Stx71CGM7TE6VPy028UlrSw0JqEwCVwstei2cMzwgA==
|
||||
-----END CERTIFICATE-----
|
||||
@@ -0,0 +1,27 @@
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
MIIEowIBAAKCAQEA5Dx+gH2HkFn3aADkmRBMk26gXoUDOir3UaHtOjbv+DvinTX5
|
||||
JSexJoF8+Y18anhq91ITDLZ1YwD/u6PQNt7wwQqyw3O2nQlC5unazufyautAsayo
|
||||
HpgBLT2XvlcONLfKpMIC0fWQPjMCX+P8DJ5AG4tHgLIkSYL+uoPf9r6mvjYJqWO4
|
||||
UGAFGkJNSlTiaWyVlJ7O/3C7rU/BMXFvxUOUEdR3+XCRdOEqBTe4SFZHEtqGlKV0
|
||||
QaaJNObHfST9ds4wXacc5sQe3kRj25ZEYZuPzVlFaI2TR021umd5Qe/8291Ytzn3
|
||||
UzxwQYRB1ZbZdNVsvYY3ruryF3MaAi9vtAk8xwIDAQABAoIBACOnh6OO+KSGSW4H
|
||||
5a47q5rEh2z8nnpxx90KzMJxXp+Ky2X/zoINZ1E6nUlm3u7LDPrB6ZPs1P24ZDrt
|
||||
5lMMFNQzVaXO59I0Zi0ojzQPbAFj6uFWtZTB7j0hCBmGBAQcSh3e6Q3frL7qvQ45
|
||||
0WAvQJiM84iZS63oNt7wRwaG1gmUn/k6j34y4qUkD5FfzGhFkekzDS54bRGwjhTA
|
||||
7XBUPAcsdNoIPcihokgLXwcdA8l6LBGsk48HN7O+CYOdh4xb6oQ4msgPED3pDIMo
|
||||
QRptqcPQ6y1qJaiM/D8SvdX2ZTFm/bh2jlGvcm5sWG8VdSDRqq9r0YCi4KlQzA1g
|
||||
OAyrMeECgYEA9dAVEegvRrFm4V6hC9CAwyS6fiOqx/l0xd354Xv4V6vR6n6rKwDF
|
||||
kv96A4sMH+mdNf6MwzFFCNW9zZV7noEIvAyPAc7jM7t/Hmt5M41DiDe0RJpWKEdQ
|
||||
lEj2qd8FqcY4YVDEH/TdchwIvoWHlD2sykW7eoseCY5mYEoQN4Ciwj8CgYEA7bHv
|
||||
qdaz2SoG9lyj8Mz7XthjYZLeaxKu7cpqP5bqzuRSkVFvib0WKoJfwsewzO5hCHnf
|
||||
8yMD3Wp4Ap2FYoN2XfV/jQyHvlpMlkxv+bU39/HLosdhzKbOJsru9kbBCaARHAVi
|
||||
av3O3JfV2/G+cwR6nPCNjcTsIcqtEpUO7kOfU3kCgYAKYNmy4tm0I2NTmpo0FH6L
|
||||
Pq69CqZ4QPkELaYSNhi7It7/BpAVhbfRyAWPxrwhUMy5beDlkNv4ToXv+yK4A3yp
|
||||
6+HR0rlXAtCQKTt5yLoUMz3iM531n2UwjZAUhf0IOP1CZpWRP9ZlrfdUi/C4eo4k
|
||||
ECOlPeBryN5brGTY4w58IwKBgQC0ukRF2I+qoP/mNg4Yu2KtfM4jlG4072G+P9eF
|
||||
PhSO9p+pCkhKbFD8RWDWUsslJmL09OXIkmkP4zIYmvieLOLFEjLHZi2YGER/SuMg
|
||||
9B74EQsKW5sK5hF9AXOsIaQI04Hu0lFAlHbC11euAiMShOdNiMG4d3ArSVVK+bb+
|
||||
hsAP0QKBgHcJuTJ6dv77evW3MFZPRjFH25pike40PWmSLgCt5PV25DRL2UG0pOut
|
||||
uybN9biQK5v377/3GD7eOL+acxHODjWmmfeEFW0YlJ1oUb/P8NlqsSnHvUoIqa24
|
||||
JmTXS/XzjgxQFFfzo0c1/1JLdG6r5CLTWxHq1EhIOJsowTlrCzX/
|
||||
-----END RSA PRIVATE KEY-----
|
||||
@@ -0,0 +1,8 @@
|
||||
# /etc/ipsec.secrets - strongSwan IPsec secrets file
|
||||
|
||||
: RSA sunKey.pem
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
+314
@@ -0,0 +1,314 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2004 Gentoo Technologies, Inc.
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
#NB: Config is in /etc/conf.d/net
|
||||
|
||||
if [[ -n $NET_DEBUG ]]; then
|
||||
set -x
|
||||
devnull=/dev/stderr
|
||||
else
|
||||
devnull=/dev/null
|
||||
fi
|
||||
|
||||
# For pcmcia users. note that pcmcia must be added to the same
|
||||
# runlevel as the net.* script that needs it.
|
||||
depend() {
|
||||
use hotplug pcmcia
|
||||
}
|
||||
|
||||
checkconfig() {
|
||||
if [[ -z "${ifconfig_IFACE}" ]]; then
|
||||
eerror "Please make sure that /etc/conf.d/net has \$ifconfig_$IFACE set"
|
||||
eerror "(or \$iface_$IFACE for old-style configuration)"
|
||||
return 1
|
||||
fi
|
||||
if [[ -n "${vlans_IFACE}" && ! -x /sbin/vconfig ]]; then
|
||||
eerror "For VLAN (802.1q) support, emerge net-misc/vconfig"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Fix bug 50039 (init.d/net.eth0 localization)
|
||||
# Some other commands in this script might need to be wrapped, but
|
||||
# we'll get them one-by-one. Note that LC_ALL trumps LC_anything_else
|
||||
# according to locale(7)
|
||||
ifconfig() {
|
||||
LC_ALL=C /sbin/ifconfig "$@"
|
||||
}
|
||||
|
||||
# setup_vars: setup variables based on $1 and content of /etc/conf.d/net
|
||||
# The following variables are set, which should be declared local by
|
||||
# the calling routine.
|
||||
# status_IFACE (up or '')
|
||||
# vlans_IFACE (space-separated list)
|
||||
# ifconfig_IFACE (array of ifconfig lines, replaces iface_IFACE)
|
||||
# dhcpcd_IFACE (command-line args for dhcpcd)
|
||||
# routes_IFACE (array of route lines)
|
||||
# inet6_IFACE (array of inet6 lines)
|
||||
# ifconfig_fallback_IFACE (fallback ifconfig if dhcp fails)
|
||||
setup_vars() {
|
||||
local i iface="${1//\./_}"
|
||||
|
||||
status_IFACE="$(ifconfig ${1} 2>${devnull} | gawk '$1 == "UP" {print "up"}')"
|
||||
eval vlans_IFACE=\"\$\{iface_${iface}_vlans\}\"
|
||||
eval ifconfig_IFACE=( \"\$\{ifconfig_$iface\[@\]\}\" )
|
||||
eval dhcpcd_IFACE=\"\$\{dhcpcd_$iface\}\"
|
||||
eval routes_IFACE=( \"\$\{routes_$iface\[@\]\}\" )
|
||||
eval inet6_IFACE=( \"\$\{inet6_$iface\[@\]\}\" )
|
||||
eval ifconfig_fallback_IFACE=( \"\$\{ifconfig_fallback_$iface\[@\]\}\" )
|
||||
|
||||
# BACKWARD COMPATIBILITY: populate the ifconfig_IFACE array
|
||||
# if iface_IFACE is set (fex. iface_eth0 instead of ifconfig_eth0)
|
||||
eval local iface_IFACE=\"\$\{iface_$iface\}\"
|
||||
if [[ -n ${iface_IFACE} && -z ${ifconfig_IFACE} ]]; then
|
||||
# Make sure these get evaluated as arrays
|
||||
local -a aliases broadcasts netmasks
|
||||
|
||||
# Start with the primary interface
|
||||
ifconfig_IFACE=( "${iface_IFACE}" )
|
||||
|
||||
# ..then add aliases
|
||||
eval aliases=( \$\{alias_$iface\} )
|
||||
eval broadcasts=( \$\{broadcast_$iface\} )
|
||||
eval netmasks=( \$\{netmask_$iface\} )
|
||||
for ((i = 0; i < ${#aliases[@]}; i = i + 1)); do
|
||||
ifconfig_IFACE[i+1]="${aliases[i]} ${broadcasts[i]:+broadcast ${broadcasts[i]}} ${netmasks[i]:+netmask ${netmasks[i]}}"
|
||||
done
|
||||
fi
|
||||
|
||||
# BACKWARD COMPATIBILITY: check for space-separated inet6 addresses
|
||||
if [[ ${#inet6_IFACE[@]} == 1 && ${inet6_IFACE} == *' '* ]]; then
|
||||
inet6_IFACE=( ${inet6_IFACE} )
|
||||
fi
|
||||
}
|
||||
|
||||
iface_start() {
|
||||
local IFACE=${1} i x retval
|
||||
checkconfig || return 1
|
||||
|
||||
if [[ ${ifconfig_IFACE} != dhcp ]]; then
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Bringing ${IFACE} up (${i})"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up"
|
||||
fi
|
||||
# ifconfig does not always return failure ..
|
||||
ifconfig ${IFACE} ${ifconfig_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
# Check that eth0 was not brought up by the kernel ...
|
||||
if [[ ${status_IFACE} == up ]]; then
|
||||
einfo "Keeping kernel configuration for ${IFACE}"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up via DHCP"
|
||||
/sbin/dhcpcd ${dhcpcd_IFACE} ${IFACE}
|
||||
retval=$?
|
||||
eend $retval
|
||||
if [[ $retval == 0 ]]; then
|
||||
# DHCP succeeded, show address retrieved
|
||||
i=$(ifconfig ${IFACE} | grep -m1 -o 'inet addr:[^ ]*' |
|
||||
cut -d: -f2)
|
||||
[[ -n ${i} ]] && einfo " ${IFACE} received address ${i}"
|
||||
elif [[ -n "${ifconfig_fallback_IFACE}" ]]; then
|
||||
# DHCP failed, try fallback.
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_fallback_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Using fallback configuration (${i}) for ${IFACE}"
|
||||
else
|
||||
ebegin "Using fallback configuration for ${IFACE}"
|
||||
fi
|
||||
ifconfig ${IFACE} ${ifconfig_fallback_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
return $retval
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if [[ ${#ifconfig_IFACE[@]} -gt 1 ]]; then
|
||||
einfo " Adding aliases"
|
||||
for ((i = 1; i < ${#ifconfig_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE}:${i} (${ifconfig_IFACE[i]%% *})"
|
||||
ifconfig ${IFACE}:${i} ${ifconfig_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
if [[ -n ${inet6_IFACE} ]]; then
|
||||
einfo " Adding inet6 addresses"
|
||||
for ((i = 0; i < ${#inet6_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE} inet6 add ${inet6_IFACE[i]}"
|
||||
ifconfig ${IFACE} inet6 add ${inet6_IFACE[i]} >${devnull}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set static routes
|
||||
if [[ -n ${routes_IFACE} ]]; then
|
||||
einfo " Adding routes"
|
||||
for ((i = 0; i < ${#routes_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${routes_IFACE[i]}"
|
||||
/sbin/route add ${routes_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set default route if applicable to this interface
|
||||
if [[ ${gateway} == ${IFACE}/* ]]; then
|
||||
local ogw=$(/bin/netstat -rn | awk '$1 == "0.0.0.0" {print $2}')
|
||||
local gw=${gateway#*/}
|
||||
if [[ ${ogw} != ${gw} ]]; then
|
||||
ebegin " Setting default gateway ($gw)"
|
||||
|
||||
# First delete any existing route if it was setup by kernel...
|
||||
/sbin/route del default dev ${IFACE} &>${devnull}
|
||||
|
||||
# Second delete old gateway if it was set...
|
||||
/sbin/route del default gw ${ogw} &>${devnull}
|
||||
|
||||
# Third add our new default gateway
|
||||
/sbin/route add default gw ${gw} >${devnull}
|
||||
eend $? || {
|
||||
true # need to have some command in here
|
||||
# Note: This originally called stop, which is obviously
|
||||
# wrong since it's calling with a local version of IFACE.
|
||||
# The below code works correctly to abort configuration of
|
||||
# the interface, but is commented because we're assuming
|
||||
# that default route failure should not cause the interface
|
||||
# to be unconfigured.
|
||||
#local error=$?
|
||||
#ewarn "Aborting configuration of ${IFACE}"
|
||||
#iface_stop ${IFACE}
|
||||
#return ${error}
|
||||
}
|
||||
fi
|
||||
fi
|
||||
|
||||
# Enabling rp_filter causes wacky packets to be auto-dropped by
|
||||
# the kernel. Note that we only do this if it is not set via
|
||||
# /etc/sysctl.conf ...
|
||||
if [[ -e /proc/sys/net/ipv4/conf/${IFACE}/rp_filter && \
|
||||
-z "$(grep -s '^[^#]*rp_filter' /etc/sysctl.conf)" ]]; then
|
||||
echo -n 1 > /proc/sys/net/ipv4/conf/${IFACE}/rp_filter
|
||||
fi
|
||||
}
|
||||
|
||||
# iface_stop: bring down an interface. Don't trust information in
|
||||
# /etc/conf.d/net since the configuration might have changed since
|
||||
# iface_start ran. Instead query for current configuration and bring
|
||||
# down the interface.
|
||||
iface_stop() {
|
||||
local IFACE=${1} i x aliases inet6 count
|
||||
|
||||
# Try to do a simple down (no aliases, no inet6, no dhcp)
|
||||
aliases="$(ifconfig | grep -o "^$IFACE:[0-9]*" | tac)"
|
||||
inet6="$(ifconfig ${IFACE} | awk '$1 == "inet6" {print $2}')"
|
||||
if [[ -z ${aliases} && -z ${inet6} && ! -e /var/run/dhcpcd-${IFACE}.pid ]]; then
|
||||
ebegin "Bringing ${IFACE} down"
|
||||
ifconfig ${IFACE} down &>/dev/null
|
||||
eend 0
|
||||
return 0
|
||||
fi
|
||||
|
||||
einfo "Bringing ${IFACE} down"
|
||||
|
||||
# Stop aliases before primary interface.
|
||||
# Note this must be done in reverse order, since ifconfig eth0:1
|
||||
# will remove eth0:2, etc. It might be sufficient to simply remove
|
||||
# the base interface but we're being safe here.
|
||||
for i in ${aliases} ${IFACE}; do
|
||||
|
||||
# Delete all the inet6 addresses for this interface
|
||||
inet6="$(ifconfig ${i} | awk '$1 == "inet6" {print $3}')"
|
||||
if [[ -n ${inet6} ]]; then
|
||||
einfo " Removing inet6 addresses"
|
||||
for x in ${inet6}; do
|
||||
ebegin " ${IFACE} inet6 del ${x}"
|
||||
ifconfig ${i} inet6 del ${x}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Stop DHCP (should be N/A for aliases)
|
||||
# Don't trust current configuration... investigate ourselves
|
||||
if /sbin/dhcpcd -z ${i} &>${devnull}; then
|
||||
ebegin " Releasing DHCP lease for ${IFACE}"
|
||||
for ((count = 0; count < 9; count = count + 1)); do
|
||||
/sbin/dhcpcd -z ${i} &>${devnull} || break
|
||||
sleep 1
|
||||
done
|
||||
[[ ${count} -lt 9 ]]
|
||||
eend $? "Timed out"
|
||||
fi
|
||||
ebegin " Stopping ${i}"
|
||||
ifconfig ${i} down &>${devnull}
|
||||
eend 0
|
||||
done
|
||||
|
||||
return 0
|
||||
}
|
||||
|
||||
start() {
|
||||
# These variables are set by setup_vars
|
||||
local status_IFACE vlans_IFACE dhcpcd_IFACE
|
||||
local -a ifconfig_IFACE routes_IFACE inet6_IFACE
|
||||
|
||||
# Call user-defined preup function if it exists
|
||||
if [[ $(type -t preup) == function ]]; then
|
||||
einfo "Running preup function"
|
||||
preup ${IFACE} || {
|
||||
eerror "preup ${IFACE} failed"
|
||||
return 1
|
||||
}
|
||||
fi
|
||||
|
||||
# Start the primary interface and aliases
|
||||
setup_vars ${IFACE}
|
||||
iface_start ${IFACE} || return 1
|
||||
|
||||
# Start vlans
|
||||
local vlan
|
||||
for vlan in ${vlans_IFACE}; do
|
||||
/sbin/vconfig add ${IFACE} ${vlan} >${devnull}
|
||||
setup_vars ${IFACE}.${vlan}
|
||||
iface_start ${IFACE}.${vlan}
|
||||
done
|
||||
|
||||
# Call user-defined postup function if it exists
|
||||
if [[ $(type -t postup) == function ]]; then
|
||||
einfo "Running postup function"
|
||||
postup ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
stop() {
|
||||
# Call user-defined predown function if it exists
|
||||
if [[ $(type -t predown) == function ]]; then
|
||||
einfo "Running predown function"
|
||||
predown ${IFACE}
|
||||
fi
|
||||
|
||||
# Don't depend on setup_vars since configuration might have changed.
|
||||
# Investigate current configuration instead.
|
||||
local vlan
|
||||
for vlan in $(ifconfig | grep -o "^${IFACE}\.[^ ]*"); do
|
||||
iface_stop ${vlan}
|
||||
/sbin/vconfig rem ${vlan} >${devnull}
|
||||
done
|
||||
|
||||
iface_stop ${IFACE} || return 1 # always succeeds, btw
|
||||
|
||||
# Call user-defined postdown function if it exists
|
||||
if [[ $(type -t postdown) == function ]]; then
|
||||
einfo "Running postdown function"
|
||||
postdown ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
# vim:ts=4
|
||||
+314
@@ -0,0 +1,314 @@
|
||||
#!/sbin/runscript
|
||||
# Copyright 1999-2004 Gentoo Technologies, Inc.
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
#NB: Config is in /etc/conf.d/net
|
||||
|
||||
if [[ -n $NET_DEBUG ]]; then
|
||||
set -x
|
||||
devnull=/dev/stderr
|
||||
else
|
||||
devnull=/dev/null
|
||||
fi
|
||||
|
||||
# For pcmcia users. note that pcmcia must be added to the same
|
||||
# runlevel as the net.* script that needs it.
|
||||
depend() {
|
||||
use hotplug pcmcia
|
||||
}
|
||||
|
||||
checkconfig() {
|
||||
if [[ -z "${ifconfig_IFACE}" ]]; then
|
||||
eerror "Please make sure that /etc/conf.d/net has \$ifconfig_$IFACE set"
|
||||
eerror "(or \$iface_$IFACE for old-style configuration)"
|
||||
return 1
|
||||
fi
|
||||
if [[ -n "${vlans_IFACE}" && ! -x /sbin/vconfig ]]; then
|
||||
eerror "For VLAN (802.1q) support, emerge net-misc/vconfig"
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Fix bug 50039 (init.d/net.eth0 localization)
|
||||
# Some other commands in this script might need to be wrapped, but
|
||||
# we'll get them one-by-one. Note that LC_ALL trumps LC_anything_else
|
||||
# according to locale(7)
|
||||
ifconfig() {
|
||||
LC_ALL=C /sbin/ifconfig "$@"
|
||||
}
|
||||
|
||||
# setup_vars: setup variables based on $1 and content of /etc/conf.d/net
|
||||
# The following variables are set, which should be declared local by
|
||||
# the calling routine.
|
||||
# status_IFACE (up or '')
|
||||
# vlans_IFACE (space-separated list)
|
||||
# ifconfig_IFACE (array of ifconfig lines, replaces iface_IFACE)
|
||||
# dhcpcd_IFACE (command-line args for dhcpcd)
|
||||
# routes_IFACE (array of route lines)
|
||||
# inet6_IFACE (array of inet6 lines)
|
||||
# ifconfig_fallback_IFACE (fallback ifconfig if dhcp fails)
|
||||
setup_vars() {
|
||||
local i iface="${1//\./_}"
|
||||
|
||||
status_IFACE="$(ifconfig ${1} 2>${devnull} | gawk '$1 == "UP" {print "up"}')"
|
||||
eval vlans_IFACE=\"\$\{iface_${iface}_vlans\}\"
|
||||
eval ifconfig_IFACE=( \"\$\{ifconfig_$iface\[@\]\}\" )
|
||||
eval dhcpcd_IFACE=\"\$\{dhcpcd_$iface\}\"
|
||||
eval routes_IFACE=( \"\$\{routes_$iface\[@\]\}\" )
|
||||
eval inet6_IFACE=( \"\$\{inet6_$iface\[@\]\}\" )
|
||||
eval ifconfig_fallback_IFACE=( \"\$\{ifconfig_fallback_$iface\[@\]\}\" )
|
||||
|
||||
# BACKWARD COMPATIBILITY: populate the ifconfig_IFACE array
|
||||
# if iface_IFACE is set (fex. iface_eth0 instead of ifconfig_eth0)
|
||||
eval local iface_IFACE=\"\$\{iface_$iface\}\"
|
||||
if [[ -n ${iface_IFACE} && -z ${ifconfig_IFACE} ]]; then
|
||||
# Make sure these get evaluated as arrays
|
||||
local -a aliases broadcasts netmasks
|
||||
|
||||
# Start with the primary interface
|
||||
ifconfig_IFACE=( "${iface_IFACE}" )
|
||||
|
||||
# ..then add aliases
|
||||
eval aliases=( \$\{alias_$iface\} )
|
||||
eval broadcasts=( \$\{broadcast_$iface\} )
|
||||
eval netmasks=( \$\{netmask_$iface\} )
|
||||
for ((i = 0; i < ${#aliases[@]}; i = i + 1)); do
|
||||
ifconfig_IFACE[i+1]="${aliases[i]} ${broadcasts[i]:+broadcast ${broadcasts[i]}} ${netmasks[i]:+netmask ${netmasks[i]}}"
|
||||
done
|
||||
fi
|
||||
|
||||
# BACKWARD COMPATIBILITY: check for space-separated inet6 addresses
|
||||
if [[ ${#inet6_IFACE[@]} == 1 && ${inet6_IFACE} == *' '* ]]; then
|
||||
inet6_IFACE=( ${inet6_IFACE} )
|
||||
fi
|
||||
}
|
||||
|
||||
iface_start() {
|
||||
local IFACE=${1} i x retval
|
||||
checkconfig || return 1
|
||||
|
||||
if [[ ${ifconfig_IFACE} != dhcp ]]; then
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Bringing ${IFACE} up (${i})"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up"
|
||||
fi
|
||||
# ifconfig does not always return failure ..
|
||||
ifconfig ${IFACE} ${ifconfig_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
# Check that eth0 was not brought up by the kernel ...
|
||||
if [[ ${status_IFACE} == up ]]; then
|
||||
einfo "Keeping kernel configuration for ${IFACE}"
|
||||
else
|
||||
ebegin "Bringing ${IFACE} up via DHCP"
|
||||
/sbin/dhcpcd ${dhcpcd_IFACE} ${IFACE}
|
||||
retval=$?
|
||||
eend $retval
|
||||
if [[ $retval == 0 ]]; then
|
||||
# DHCP succeeded, show address retrieved
|
||||
i=$(ifconfig ${IFACE} | grep -m1 -o 'inet addr:[^ ]*' |
|
||||
cut -d: -f2)
|
||||
[[ -n ${i} ]] && einfo " ${IFACE} received address ${i}"
|
||||
elif [[ -n "${ifconfig_fallback_IFACE}" ]]; then
|
||||
# DHCP failed, try fallback.
|
||||
# Show the address, but catch if this interface will be inet6 only
|
||||
i=${ifconfig_fallback_IFACE%% *}
|
||||
if [[ ${i} == *.*.*.* ]]; then
|
||||
ebegin "Using fallback configuration (${i}) for ${IFACE}"
|
||||
else
|
||||
ebegin "Using fallback configuration for ${IFACE}"
|
||||
fi
|
||||
ifconfig ${IFACE} ${ifconfig_fallback_IFACE} >${devnull} && \
|
||||
ifconfig ${IFACE} up &>${devnull}
|
||||
eend $? || return $?
|
||||
else
|
||||
return $retval
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if [[ ${#ifconfig_IFACE[@]} -gt 1 ]]; then
|
||||
einfo " Adding aliases"
|
||||
for ((i = 1; i < ${#ifconfig_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE}:${i} (${ifconfig_IFACE[i]%% *})"
|
||||
ifconfig ${IFACE}:${i} ${ifconfig_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
if [[ -n ${inet6_IFACE} ]]; then
|
||||
einfo " Adding inet6 addresses"
|
||||
for ((i = 0; i < ${#inet6_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${IFACE} inet6 add ${inet6_IFACE[i]}"
|
||||
ifconfig ${IFACE} inet6 add ${inet6_IFACE[i]} >${devnull}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set static routes
|
||||
if [[ -n ${routes_IFACE} ]]; then
|
||||
einfo " Adding routes"
|
||||
for ((i = 0; i < ${#routes_IFACE[@]}; i = i + 1)); do
|
||||
ebegin " ${routes_IFACE[i]}"
|
||||
/sbin/route add ${routes_IFACE[i]}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Set default route if applicable to this interface
|
||||
if [[ ${gateway} == ${IFACE}/* ]]; then
|
||||
local ogw=$(/bin/netstat -rn | awk '$1 == "0.0.0.0" {print $2}')
|
||||
local gw=${gateway#*/}
|
||||
if [[ ${ogw} != ${gw} ]]; then
|
||||
ebegin " Setting default gateway ($gw)"
|
||||
|
||||
# First delete any existing route if it was setup by kernel...
|
||||
/sbin/route del default dev ${IFACE} &>${devnull}
|
||||
|
||||
# Second delete old gateway if it was set...
|
||||
/sbin/route del default gw ${ogw} &>${devnull}
|
||||
|
||||
# Third add our new default gateway
|
||||
/sbin/route add default gw ${gw} >${devnull}
|
||||
eend $? || {
|
||||
true # need to have some command in here
|
||||
# Note: This originally called stop, which is obviously
|
||||
# wrong since it's calling with a local version of IFACE.
|
||||
# The below code works correctly to abort configuration of
|
||||
# the interface, but is commented because we're assuming
|
||||
# that default route failure should not cause the interface
|
||||
# to be unconfigured.
|
||||
#local error=$?
|
||||
#ewarn "Aborting configuration of ${IFACE}"
|
||||
#iface_stop ${IFACE}
|
||||
#return ${error}
|
||||
}
|
||||
fi
|
||||
fi
|
||||
|
||||
# Enabling rp_filter causes wacky packets to be auto-dropped by
|
||||
# the kernel. Note that we only do this if it is not set via
|
||||
# /etc/sysctl.conf ...
|
||||
if [[ -e /proc/sys/net/ipv4/conf/${IFACE}/rp_filter && \
|
||||
-z "$(grep -s '^[^#]*rp_filter' /etc/sysctl.conf)" ]]; then
|
||||
echo -n 1 > /proc/sys/net/ipv4/conf/${IFACE}/rp_filter
|
||||
fi
|
||||
}
|
||||
|
||||
# iface_stop: bring down an interface. Don't trust information in
|
||||
# /etc/conf.d/net since the configuration might have changed since
|
||||
# iface_start ran. Instead query for current configuration and bring
|
||||
# down the interface.
|
||||
iface_stop() {
|
||||
local IFACE=${1} i x aliases inet6 count
|
||||
|
||||
# Try to do a simple down (no aliases, no inet6, no dhcp)
|
||||
aliases="$(ifconfig | grep -o "^$IFACE:[0-9]*" | tac)"
|
||||
inet6="$(ifconfig ${IFACE} | awk '$1 == "inet6" {print $2}')"
|
||||
if [[ -z ${aliases} && -z ${inet6} && ! -e /var/run/dhcpcd-${IFACE}.pid ]]; then
|
||||
ebegin "Bringing ${IFACE} down"
|
||||
ifconfig ${IFACE} down &>/dev/null
|
||||
eend 0
|
||||
return 0
|
||||
fi
|
||||
|
||||
einfo "Bringing ${IFACE} down"
|
||||
|
||||
# Stop aliases before primary interface.
|
||||
# Note this must be done in reverse order, since ifconfig eth0:1
|
||||
# will remove eth0:2, etc. It might be sufficient to simply remove
|
||||
# the base interface but we're being safe here.
|
||||
for i in ${aliases} ${IFACE}; do
|
||||
|
||||
# Delete all the inet6 addresses for this interface
|
||||
inet6="$(ifconfig ${i} | awk '$1 == "inet6" {print $3}')"
|
||||
if [[ -n ${inet6} ]]; then
|
||||
einfo " Removing inet6 addresses"
|
||||
for x in ${inet6}; do
|
||||
ebegin " ${IFACE} inet6 del ${x}"
|
||||
ifconfig ${i} inet6 del ${x}
|
||||
eend $?
|
||||
done
|
||||
fi
|
||||
|
||||
# Stop DHCP (should be N/A for aliases)
|
||||
# Don't trust current configuration... investigate ourselves
|
||||
if /sbin/dhcpcd -z ${i} &>${devnull}; then
|
||||
ebegin " Releasing DHCP lease for ${IFACE}"
|
||||
for ((count = 0; count < 9; count = count + 1)); do
|
||||
/sbin/dhcpcd -z ${i} &>${devnull} || break
|
||||
sleep 1
|
||||
done
|
||||
[[ ${count} -lt 9 ]]
|
||||
eend $? "Timed out"
|
||||
fi
|
||||
ebegin " Stopping ${i}"
|
||||
ifconfig ${i} down &>${devnull}
|
||||
eend 0
|
||||
done
|
||||
|
||||
return 0
|
||||
}
|
||||
|
||||
start() {
|
||||
# These variables are set by setup_vars
|
||||
local status_IFACE vlans_IFACE dhcpcd_IFACE
|
||||
local -a ifconfig_IFACE routes_IFACE inet6_IFACE
|
||||
|
||||
# Call user-defined preup function if it exists
|
||||
if [[ $(type -t preup) == function ]]; then
|
||||
einfo "Running preup function"
|
||||
preup ${IFACE} || {
|
||||
eerror "preup ${IFACE} failed"
|
||||
return 1
|
||||
}
|
||||
fi
|
||||
|
||||
# Start the primary interface and aliases
|
||||
setup_vars ${IFACE}
|
||||
iface_start ${IFACE} || return 1
|
||||
|
||||
# Start vlans
|
||||
local vlan
|
||||
for vlan in ${vlans_IFACE}; do
|
||||
/sbin/vconfig add ${IFACE} ${vlan} >${devnull}
|
||||
setup_vars ${IFACE}.${vlan}
|
||||
iface_start ${IFACE}.${vlan}
|
||||
done
|
||||
|
||||
# Call user-defined postup function if it exists
|
||||
if [[ $(type -t postup) == function ]]; then
|
||||
einfo "Running postup function"
|
||||
postup ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
stop() {
|
||||
# Call user-defined predown function if it exists
|
||||
if [[ $(type -t predown) == function ]]; then
|
||||
einfo "Running predown function"
|
||||
predown ${IFACE}
|
||||
fi
|
||||
|
||||
# Don't depend on setup_vars since configuration might have changed.
|
||||
# Investigate current configuration instead.
|
||||
local vlan
|
||||
for vlan in $(ifconfig | grep -o "^${IFACE}\.[^ ]*"); do
|
||||
iface_stop ${vlan}
|
||||
/sbin/vconfig rem ${vlan} >${devnull}
|
||||
done
|
||||
|
||||
iface_stop ${IFACE} || return 1 # always succeeds, btw
|
||||
|
||||
# Call user-defined postdown function if it exists
|
||||
if [[ $(type -t postdown) == function ]]; then
|
||||
einfo "Running postdown function"
|
||||
postdown ${IFACE}
|
||||
fi
|
||||
}
|
||||
|
||||
# vim:ts=4
|
||||
Reference in New Issue
Block a user