openvpn.init 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254
  1. #!/bin/sh /etc/rc.common
  2. # Copyright (C) 2008-2013 OpenWrt.org
  3. # Copyright (C) 2008 Jo-Philipp Wich
  4. # This is free software, licensed under the GNU General Public License v2.
  5. # See /LICENSE for more information.
  6. START=90
  7. STOP=10
  8. USE_PROCD=1
  9. PROG=/usr/sbin/openvpn
  10. LIST_SEP="
  11. "
  12. UCI_STARTED=
  13. UCI_DISABLED=
  14. append_param() {
  15. local s="$1"
  16. local v="$2"
  17. case "$v" in
  18. *_*_*_*) v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_} ;;
  19. *_*_*) v=${v%%_*}-${v#*_}; v=${v%%_*}-${v#*_} ;;
  20. *_*) v=${v%%_*}-${v#*_} ;;
  21. esac
  22. echo -n "$v" >> "/var/etc/openvpn-$s.conf"
  23. return 0
  24. }
  25. append_bools() {
  26. local p; local v; local s="$1"; shift
  27. for p in $*; do
  28. config_get_bool v "$s" "$p"
  29. [ "$v" = 1 ] && append_param "$s" "$p" && echo >> "/var/etc/openvpn-$s.conf"
  30. done
  31. }
  32. append_params() {
  33. local p; local v; local s="$1"; shift
  34. for p in $*; do
  35. config_get v "$s" "$p"
  36. IFS="$LIST_SEP"
  37. for v in $v; do
  38. [ "$v" = "frames_only" ] && [ "$p" = "compress" ] && unset v && append_param "$s" "$p" && echo >> "/var/etc/openvpn-$s.conf"
  39. [ -n "$v" ] && [ "$p" != "push" ] && append_param "$s" "$p" && echo " $v" >> "/var/etc/openvpn-$s.conf"
  40. [ -n "$v" ] && [ "$p" = "push" ] && append_param "$s" "$p" && echo " \"$v\"" >> "/var/etc/openvpn-$s.conf"
  41. done
  42. unset IFS
  43. done
  44. }
  45. append_list() {
  46. local p; local v; local s="$1"; shift
  47. list_cb_append() {
  48. v="${v}:$1"
  49. }
  50. for p in $*; do
  51. unset v
  52. config_list_foreach "$s" "$p" list_cb_append
  53. [ -n "$v" ] && append_param "$s" "$p" && echo " ${v:1}" >> "/var/etc/openvpn-$s.conf"
  54. done
  55. }
  56. section_enabled() {
  57. config_get_bool enable "$1" 'enable' 0
  58. config_get_bool enabled "$1" 'enabled' 0
  59. [ $enable -gt 0 ] || [ $enabled -gt 0 ]
  60. }
  61. create_temp_file() {
  62. mkdir -p "$(dirname "$1")"
  63. rm -f "$1"
  64. touch "$1"
  65. chown root "$1"
  66. chmod 0600 "$1"
  67. }
  68. openvpn_get_dev() {
  69. local dev dev_type
  70. local name="$1"
  71. local conf="$2"
  72. # Do override only for configurations with config_file
  73. config_get config_file "$name" config
  74. [ -n "$config_file" ] || return
  75. # Check there is someething to override
  76. config_get dev "$name" dev
  77. config_get dev_type "$name" dev_type
  78. [ -n "$dev" ] || return
  79. # If there is a no dev_type, try to guess it
  80. if [ -z "$dev_type" ]; then
  81. . /lib/functions/openvpn.sh
  82. local odev odev_type
  83. get_openvpn_option "$conf" odev dev
  84. get_openvpn_option "$conf" odev_type dev-type
  85. [ -n "$odev_type" ] || odev_type="$odev"
  86. case "$odev_type" in
  87. tun*) dev_type="tun" ;;
  88. tap*) dev_type="tap" ;;
  89. *) return;;
  90. esac
  91. fi
  92. # Return overrides
  93. echo "--dev-type $dev_type --dev $dev"
  94. }
  95. openvpn_get_credentials() {
  96. local name="$1"
  97. local ret=""
  98. config_get cert_password "$name" cert_password
  99. config_get password "$name" password
  100. config_get username "$name" username
  101. if [ -n "$cert_password" ]; then
  102. create_temp_file /var/run/openvpn.$name.pass
  103. echo "$cert_password" > /var/run/openvpn.$name.pass
  104. ret=" --askpass /var/run/openvpn.$name.pass "
  105. fi
  106. if [ -n "$username" ]; then
  107. create_temp_file /var/run/openvpn.$name.userpass
  108. echo "$username" > /var/run/openvpn.$name.userpass
  109. echo "$password" >> /var/run/openvpn.$name.userpass
  110. ret=" --auth-user-pass /var/run/openvpn.$name.userpass "
  111. fi
  112. # Return overrides
  113. echo "$ret"
  114. }
  115. openvpn_add_instance() {
  116. local name="$1"
  117. local dir="$2"
  118. local conf="$3"
  119. local security="$4"
  120. local up="$5"
  121. local down="$6"
  122. procd_open_instance "$name"
  123. procd_set_param command "$PROG" \
  124. --syslog "openvpn($name)" \
  125. --status "/var/run/openvpn.$name.status" \
  126. --cd "$dir" \
  127. --config "$conf" \
  128. --up "/usr/libexec/openvpn-hotplug up $name" \
  129. --down "/usr/libexec/openvpn-hotplug down $name" \
  130. ${up:+--setenv user_up "$up"} \
  131. ${down:+--setenv user_down "$down"} \
  132. --script-security "${security:-2}" \
  133. $(openvpn_get_dev "$name" "$conf") \
  134. $(openvpn_get_credentials "$name" "$conf")
  135. procd_set_param file "$dir/$conf"
  136. procd_set_param term_timeout 15
  137. procd_set_param respawn
  138. procd_append_param respawn 3600
  139. procd_append_param respawn 5
  140. procd_append_param respawn -1
  141. procd_close_instance
  142. }
  143. start_instance() {
  144. local s="$1"
  145. config_get config "$s" config
  146. config="${config:+$(readlink -f "$config")}"
  147. section_enabled "$s" || {
  148. append UCI_DISABLED "$config" "$LIST_SEP"
  149. return 1
  150. }
  151. local up down script_security
  152. config_get up "$s" up
  153. config_get down "$s" down
  154. config_get script_security "$s" script_security
  155. [ ! -d "/var/run" ] && mkdir -p "/var/run"
  156. if [ ! -z "$config" ]; then
  157. append UCI_STARTED "$config" "$LIST_SEP"
  158. [ -n "$up" ] || get_openvpn_option "$config" up up
  159. [ -n "$down" ] || get_openvpn_option "$config" down down
  160. openvpn_add_instance "$s" "${config%/*}" "$config" "$script_security" "$up" "$down"
  161. return
  162. fi
  163. create_temp_file "/var/etc/openvpn-$s.conf"
  164. append_bools "$s" $OPENVPN_BOOLS
  165. append_params "$s" $OPENVPN_PARAMS
  166. append_list "$s" $OPENVPN_LIST
  167. openvpn_add_instance "$s" "/var/etc" "openvpn-$s.conf" "$script_security" "$up" "$down"
  168. }
  169. start_service() {
  170. local instance="$1"
  171. local instance_found=0
  172. config_cb() {
  173. local type="$1"
  174. local name="$2"
  175. if [ "$type" = "openvpn" ]; then
  176. if [ -n "$instance" -a "$instance" = "$name" ]; then
  177. instance_found=1
  178. fi
  179. fi
  180. }
  181. . /lib/functions/openvpn.sh
  182. . /usr/share/openvpn/openvpn.options
  183. config_load 'openvpn'
  184. if [ -n "$instance" ]; then
  185. [ "$instance_found" -gt 0 ] || return
  186. start_instance "$instance"
  187. else
  188. config_foreach start_instance 'openvpn'
  189. local path name up down
  190. for path in /etc/openvpn/*.conf; do
  191. if [ -f "$path" ]; then
  192. name="${path##*/}"; name="${name%.conf}"
  193. # don't start configs again that are already started by uci
  194. if echo "$UCI_STARTED" | grep -qxF "$path"; then
  195. continue
  196. # don't start configs which are set to disabled in uci
  197. elif echo "$UCI_DISABLED" | grep -qxF "$path"; then
  198. logger -t openvpn "$name.conf is disabled in /etc/config/openvpn"
  199. continue
  200. fi
  201. get_openvpn_option "$path" up up || up=""
  202. get_openvpn_option "$path" down down || down=""
  203. openvpn_add_instance "$name" "${path%/*}" "$path" "" "$up" "$down"
  204. fi
  205. done
  206. fi
  207. }
  208. service_triggers() {
  209. procd_add_reload_trigger openvpn
  210. }