unbound.sh 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930
  1. #!/bin/sh
  2. ##############################################################################
  3. #
  4. # This program is free software; you can redistribute it and/or modify
  5. # it under the terms of the GNU General Public License version 2 as
  6. # published by the Free Software Foundation.
  7. #
  8. # This program is distributed in the hope that it will be useful,
  9. # but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  11. # GNU General Public License for more details.
  12. #
  13. # Copyright (C) 2016 Eric Luehrsen
  14. #
  15. ##############################################################################
  16. #
  17. # This builds the basic UCI components currently supported for Unbound. It is
  18. # intentionally NOT comprehensive and bundles a lot of options. The UCI is to
  19. # be a simpler presentation of the total Unbound conf set.
  20. #
  21. ##############################################################################
  22. UNBOUND_B_CONTROL=0
  23. UNBOUND_B_SLAAC6_MAC=0
  24. UNBOUND_B_DNSSEC=0
  25. UNBOUND_B_DNS64=0
  26. UNBOUND_B_GATE_NAME=0
  27. UNBOUND_B_HIDE_BIND=1
  28. UNBOUND_B_LOCL_BLCK=0
  29. UNBOUND_B_LOCL_SERV=1
  30. UNBOUND_B_MAN_CONF=0
  31. UNBOUND_B_NTP_BOOT=1
  32. UNBOUND_B_PRIV_BLCK=1
  33. UNBOUND_B_QUERY_MIN=0
  34. UNBOUND_B_QRY_MINST=0
  35. UNBOUND_D_DOMAIN_TYPE=static
  36. UNBOUND_D_DHCP_LINK=none
  37. UNBOUND_D_LAN_FQDN=0
  38. UNBOUND_D_PROTOCOL=mixed
  39. UNBOUND_D_RESOURCE=small
  40. UNBOUND_D_RECURSION=passive
  41. UNBOUND_D_WAN_FQDN=0
  42. UNBOUND_IP_DNS64="64:ff9b::/96"
  43. UNBOUND_N_EDNS_SIZE=1280
  44. UNBOUND_N_FWD_PORTS=""
  45. UNBOUND_N_RX_PORT=53
  46. UNBOUND_N_ROOT_AGE=9
  47. UNBOUND_TTL_MIN=120
  48. UNBOUND_TXT_DOMAIN=lan
  49. UNBOUND_TXT_FWD_ZONE=""
  50. UNBOUND_TXT_HOSTNAME=thisrouter
  51. ##############################################################################
  52. UNBOUND_LIBDIR=/usr/lib/unbound
  53. UNBOUND_VARDIR=/var/lib/unbound
  54. UNBOUND_PIDFILE=/var/run/unbound.pid
  55. UNBOUND_SRV_CONF=$UNBOUND_VARDIR/unbound_srv.conf
  56. UNBOUND_EXT_CONF=$UNBOUND_VARDIR/unbound_ext.conf
  57. UNBOUND_DHCP_CONF=$UNBOUND_VARDIR/unbound_dhcp.conf
  58. UNBOUND_CONFFILE=$UNBOUND_VARDIR/unbound.conf
  59. UNBOUND_KEYFILE=$UNBOUND_VARDIR/root.key
  60. UNBOUND_HINTFILE=$UNBOUND_VARDIR/root.hints
  61. UNBOUND_TIMEFILE=$UNBOUND_VARDIR/unbound.time
  62. ##############################################################################
  63. UNBOUND_ANCHOR=/usr/sbin/unbound-anchor
  64. UNBOUND_CONTROL=/usr/sbin/unbound-control
  65. UNBOUND_CONTROL_CFG="$UNBOUND_CONTROL -c $UNBOUND_CONFFILE"
  66. ##############################################################################
  67. . /lib/functions.sh
  68. . /lib/functions/network.sh
  69. . $UNBOUND_LIBDIR/dnsmasq.sh
  70. . $UNBOUND_LIBDIR/iptools.sh
  71. . $UNBOUND_LIBDIR/rootzone.sh
  72. ##############################################################################
  73. copy_dash_update() {
  74. # TODO: remove this function and use builtins when this issues is resovled.
  75. # Due to OpenWrt/LEDE divergence "cp -u" isn't yet universally available.
  76. local filetime keeptime
  77. if [ -f $UNBOUND_KEYFILE.keep ] ; then
  78. # root.key.keep is reused if newest
  79. filetime=$( date -r $UNBOUND_KEYFILE +%s )
  80. keeptime=$( date -r $UNBOUND_KEYFILE.keep +%s )
  81. if [ $keeptime -gt $filetime ] ; then
  82. cp $UNBOUND_KEYFILE.keep $UNBOUND_KEYFILE
  83. fi
  84. rm -f $UNBOUND_KEYFILE.keep
  85. fi
  86. }
  87. ##############################################################################
  88. create_interface_dns() {
  89. local cfg="$1"
  90. local ipcommand logint ignore ifname ifdashname
  91. local name names address addresses
  92. local ulaprefix if_fqdn host_fqdn mode mode_ptr
  93. # Create local-data: references for this hosts interfaces (router).
  94. config_get logint "$cfg" interface
  95. config_get_bool ignore "$cfg" ignore 0
  96. network_get_device ifname "$cfg"
  97. ifdashname="${ifname//./-}"
  98. ipcommand="ip -o address show $ifname"
  99. addresses="$($ipcommand | awk '/inet/{sub(/\/.*/,"",$4); print $4}')"
  100. ulaprefix="$(uci_get network @globals[0] ula_prefix)"
  101. host_fqdn="$UNBOUND_TXT_HOSTNAME.$UNBOUND_TXT_DOMAIN"
  102. if_fqdn="$ifdashname.$host_fqdn"
  103. if [ -z "${ulaprefix%%:/*}" ] ; then
  104. # Nonsense so this option isn't globbed below
  105. ulaprefix="fdno:such:addr::/48"
  106. fi
  107. if [ "$ignore" -gt 0 ] ; then
  108. mode="$UNBOUND_D_WAN_FQDN"
  109. else
  110. mode="$UNBOUND_D_LAN_FQDN"
  111. fi
  112. case "$mode" in
  113. 3)
  114. mode_ptr="$host_fqdn"
  115. names="$host_fqdn $UNBOUND_TXT_HOSTNAME"
  116. ;;
  117. 4)
  118. if [ -z "$ifdashname" ] ; then
  119. # race conditions at init can rarely cause a blank device return
  120. # the record format is invalid and Unbound won't load the conf file
  121. mode_ptr="$host_fqdn"
  122. names="$host_fqdn $UNBOUND_TXT_HOSTNAME"
  123. else
  124. mode_ptr="$if_fqdn"
  125. names="$if_fqdn $host_fqdn $UNBOUND_TXT_HOSTNAME"
  126. fi
  127. ;;
  128. *)
  129. mode_ptr="$UNBOUND_TXT_HOSTNAME"
  130. names="$UNBOUND_TXT_HOSTNAME"
  131. ;;
  132. esac
  133. if [ "$mode" -gt 1 ] ; then
  134. {
  135. for address in $addresses ; do
  136. case $address in
  137. fe80:*|169.254.*)
  138. echo " # note link address $address"
  139. ;;
  140. [1-9a-f]*:*[0-9a-f])
  141. # GA and ULA IP6 for HOST IN AAA records (ip command is robust)
  142. for name in $names ; do
  143. echo " local-data: \"$name. 120 IN AAAA $address\""
  144. done
  145. echo " local-data-ptr: \"$address 120 $mode_ptr\""
  146. ;;
  147. [1-9]*.*[0-9])
  148. # Old fashioned HOST IN A records
  149. for name in $names ; do
  150. echo " local-data: \"$name. 120 IN A $address\""
  151. done
  152. echo " local-data-ptr: \"$address 120 $mode_ptr\""
  153. ;;
  154. esac
  155. done
  156. echo
  157. } >> $UNBOUND_CONFFILE
  158. elif [ "$mode" -gt 0 ] ; then
  159. {
  160. for address in $addresses ; do
  161. case $address in
  162. fe80:*|169.254.*)
  163. echo " # note link address $address"
  164. ;;
  165. "${ulaprefix%%:/*}"*)
  166. # Only this networks ULA and only hostname
  167. echo " local-data: \"$UNBOUND_TXT_HOSTNAME. 120 IN AAAA $address\""
  168. echo " local-data-ptr: \"$address 120 $UNBOUND_TXT_HOSTNAME\""
  169. ;;
  170. [1-9]*.*[0-9])
  171. echo " local-data: \"$UNBOUND_TXT_HOSTNAME. 120 IN A $address\""
  172. echo " local-data-ptr: \"$address 120 $UNBOUND_TXT_HOSTNAME\""
  173. ;;
  174. esac
  175. done
  176. echo
  177. } >> $UNBOUND_CONFFILE
  178. fi
  179. }
  180. ##############################################################################
  181. create_access_control() {
  182. local cfg="$1"
  183. local subnets subnets4 subnets6
  184. local validip4 validip6
  185. network_get_subnets subnets4 "$cfg"
  186. network_get_subnets6 subnets6 "$cfg"
  187. subnets="$subnets4 $subnets6"
  188. if [ -n "$subnets" ] ; then
  189. for subnet in $subnets ; do
  190. validip4=$( valid_subnet4 $subnet )
  191. validip6=$( valid_subnet6 $subnet )
  192. if [ "$validip4" = "ok" -o "$validip6" = "ok" ] ; then
  193. # For each "network" UCI add "access-control:" white list for queries
  194. echo " access-control: $subnet allow" >> $UNBOUND_CONFFILE
  195. fi
  196. done
  197. fi
  198. }
  199. ##############################################################################
  200. create_domain_insecure() {
  201. echo " domain-insecure: \"$1\"" >> $UNBOUND_CONFFILE
  202. }
  203. ##############################################################################
  204. unbound_mkdir() {
  205. local resolvsym=0
  206. local dhcp_origin=$( uci get dhcp.@odhcpd[0].leasefile )
  207. local dhcp_dir=$( dirname "$dhcp_origin" )
  208. local filestuff
  209. if [ ! -x /usr/sbin/dnsmasq -o ! -x /etc/init.d/dnsmasq ] ; then
  210. resolvsym=1
  211. else
  212. /etc/init.d/dnsmasq enabled || resolvsym=1
  213. fi
  214. if [ "$resolvsym" -gt 0 ] ; then
  215. rm -f /tmp/resolv.conf
  216. {
  217. # Set resolver file to local but not if /etc/init.d/dnsmasq will do it.
  218. echo "nameserver 127.0.0.1"
  219. echo "nameserver ::1"
  220. echo "search $UNBOUND_TXT_DOMAIN"
  221. } > /tmp/resolv.conf
  222. fi
  223. if [ "$UNBOUND_D_DHCP_LINK" = "odhcpd" -a ! -d "$dhcp_dir" ] ; then
  224. # make sure odhcpd has a directory to write (not done itself, yet)
  225. mkdir -p "$dhcp_dir"
  226. fi
  227. if [ -f $UNBOUND_KEYFILE ] ; then
  228. filestuff=$( cat $UNBOUND_KEYFILE )
  229. case "$filestuff" in
  230. *"state=2 [ VALID ]"*)
  231. # Lets not lose RFC 5011 tracking if we don't have to
  232. cp -p $UNBOUND_KEYFILE $UNBOUND_KEYFILE.keep
  233. ;;
  234. esac
  235. fi
  236. # Blind copy /etc/ to /var/lib/
  237. mkdir -p $UNBOUND_VARDIR
  238. rm -f $UNBOUND_VARDIR/dhcp_*
  239. touch $UNBOUND_CONFFILE
  240. touch $UNBOUND_SRV_CONF
  241. touch $UNBOUND_EXT_CONF
  242. cp -p /etc/unbound/* $UNBOUND_VARDIR/
  243. if [ ! -f $UNBOUND_HINTFILE ] ; then
  244. if [ -f /usr/share/dns/root.hints ] ; then
  245. # Debian-like package dns-root-data
  246. cp -p /usr/share/dns/root.hints $UNBOUND_HINTFILE
  247. elif [ ! -f "$UNBOUND_TIMEFILE" ] ; then
  248. logger -t unbound -s "iterator will use built-in root hints"
  249. fi
  250. fi
  251. if [ ! -f $UNBOUND_KEYFILE ] ; then
  252. if [ -f /usr/share/dns/root.key ] ; then
  253. # Debian-like package dns-root-data
  254. cp -p /usr/share/dns/root.key $UNBOUND_KEYFILE
  255. elif [ -x $UNBOUND_ANCHOR ] ; then
  256. $UNBOUND_ANCHOR -a $UNBOUND_KEYFILE
  257. elif [ ! -f "$UNBOUND_TIMEFILE" ] ; then
  258. logger -t unbound -s "validator will use built-in trust anchor"
  259. fi
  260. fi
  261. copy_dash_update
  262. # Ensure access and prepare to jail
  263. chown -R unbound:unbound $UNBOUND_VARDIR
  264. chmod 775 $UNBOUND_VARDIR
  265. chmod 664 $UNBOUND_VARDIR/*
  266. }
  267. ##############################################################################
  268. unbound_control() {
  269. if [ "$UNBOUND_B_CONTROL" -gt 0 ] ; then
  270. {
  271. # Enable remote control tool, but only at local host for security
  272. # You can hand write fancier encrypted access with /etc/..._ext.conf
  273. echo "remote-control:"
  274. echo " control-enable: yes"
  275. echo " control-use-cert: no"
  276. echo " control-interface: 127.0.0.1"
  277. echo " control-interface: ::1"
  278. echo
  279. } >> $UNBOUND_CONFFILE
  280. fi
  281. {
  282. # Amend your own extended clauses here like forward zones or disable
  283. # above (local, no encryption) and amend your own remote encrypted control
  284. echo
  285. echo "include: $UNBOUND_EXT_CONF" >> $UNBOUND_CONFFILE
  286. echo
  287. } >> $UNBOUND_CONFFILE
  288. }
  289. ##############################################################################
  290. unbound_conf() {
  291. local cfg="$1"
  292. local rt_mem rt_conn modulestring
  293. {
  294. # Make fresh conf file
  295. echo "# $UNBOUND_CONFFILE generated by UCI $( date )"
  296. echo
  297. } > $UNBOUND_CONFFILE
  298. {
  299. # No threading
  300. echo "server:"
  301. echo " username: unbound"
  302. echo " num-threads: 1"
  303. echo " msg-cache-slabs: 1"
  304. echo " rrset-cache-slabs: 1"
  305. echo " infra-cache-slabs: 1"
  306. echo " key-cache-slabs: 1"
  307. echo
  308. } >> $UNBOUND_CONFFILE
  309. {
  310. # Logging
  311. echo " verbosity: 1"
  312. echo " statistics-interval: 0"
  313. echo " statistics-cumulative: no"
  314. echo " extended-statistics: no"
  315. echo
  316. } >> $UNBOUND_CONFFILE
  317. {
  318. # Interfaces (access contol "option local_service")
  319. echo " interface: 0.0.0.0"
  320. echo " interface: ::0"
  321. echo " outgoing-interface: 0.0.0.0"
  322. echo " outgoing-interface: ::0"
  323. echo
  324. } >> $UNBOUND_CONFFILE
  325. case "$UNBOUND_D_PROTOCOL" in
  326. ip4_only)
  327. {
  328. echo " do-ip4: yes"
  329. echo " do-ip6: no"
  330. } >> $UNBOUND_CONFFILE
  331. ;;
  332. ip6_only)
  333. {
  334. echo " do-ip4: no"
  335. echo " do-ip6: yes"
  336. } >> $UNBOUND_CONFFILE
  337. ;;
  338. ip6_prefer)
  339. {
  340. echo " do-ip4: yes"
  341. echo " do-ip6: yes"
  342. echo " prefer-ip6: yes"
  343. } >> $UNBOUND_CONFFILE
  344. ;;
  345. *)
  346. {
  347. echo " do-ip4: yes"
  348. echo " do-ip6: yes"
  349. } >> $UNBOUND_CONFFILE
  350. ;;
  351. esac
  352. {
  353. # protocol level tuning
  354. echo " edns-buffer-size: $UNBOUND_N_EDNS_SIZE"
  355. echo " msg-buffer-size: 8192"
  356. echo " port: $UNBOUND_N_RX_PORT"
  357. echo " outgoing-port-permit: 10240-65535"
  358. echo
  359. } >> $UNBOUND_CONFFILE
  360. {
  361. # Other harding and options for an embedded router
  362. echo " harden-short-bufsize: yes"
  363. echo " harden-large-queries: yes"
  364. echo " harden-glue: yes"
  365. echo " harden-below-nxdomain: no"
  366. echo " harden-referral-path: no"
  367. echo " use-caps-for-id: no"
  368. echo
  369. } >> $UNBOUND_CONFFILE
  370. {
  371. # Default Files
  372. echo " use-syslog: yes"
  373. echo " chroot: \"$UNBOUND_VARDIR\""
  374. echo " directory: \"$UNBOUND_VARDIR\""
  375. echo " pidfile: \"$UNBOUND_PIDFILE\""
  376. } >> $UNBOUND_CONFFILE
  377. if [ -f "$UNBOUND_HINTFILE" ] ; then
  378. # Optional hints if found
  379. echo " root-hints: \"$UNBOUND_HINTFILE\"" >> $UNBOUND_CONFFILE
  380. fi
  381. if [ "$UNBOUND_B_DNSSEC" -gt 0 -a -f "$UNBOUND_KEYFILE" ] ; then
  382. {
  383. echo " auto-trust-anchor-file: \"$UNBOUND_KEYFILE\""
  384. echo
  385. } >> $UNBOUND_CONFFILE
  386. else
  387. echo >> $UNBOUND_CONFFILE
  388. fi
  389. case "$UNBOUND_D_RESOURCE" in
  390. # Tiny - Unbound's recommended cheap hardware config
  391. tiny) rt_mem=1 ; rt_conn=1 ;;
  392. # Small - Half RRCACHE and open ports
  393. small) rt_mem=8 ; rt_conn=5 ;;
  394. # Medium - Nearly default but with some added balancintg
  395. medium) rt_mem=16 ; rt_conn=10 ;;
  396. # Large - Double medium
  397. large) rt_mem=32 ; rt_conn=10 ;;
  398. # Whatever unbound does
  399. *) rt_mem=0 ; rt_conn=0 ;;
  400. esac
  401. if [ "$rt_mem" -gt 0 ] ; then
  402. {
  403. # Set memory sizing parameters
  404. echo " outgoing-range: $(($rt_conn*64))"
  405. echo " num-queries-per-thread: $(($rt_conn*32))"
  406. echo " outgoing-num-tcp: $(($rt_conn))"
  407. echo " incoming-num-tcp: $(($rt_conn))"
  408. echo " rrset-cache-size: $(($rt_mem*256))k"
  409. echo " msg-cache-size: $(($rt_mem*128))k"
  410. echo " key-cache-size: $(($rt_mem*128))k"
  411. echo " neg-cache-size: $(($rt_mem*64))k"
  412. echo " infra-cache-numhosts: $(($rt_mem*256))"
  413. echo
  414. } >> $UNBOUND_CONFFILE
  415. elif [ ! -f "$UNBOUND_TIMEFILE" ] ; then
  416. logger -t unbound -s "default memory resource consumption"
  417. fi
  418. # Assembly of module-config: options is tricky; order matters
  419. modulestring="iterator"
  420. if [ "$UNBOUND_B_DNSSEC" -gt 0 ] ; then
  421. if [ ! -f "$UNBOUND_TIMEFILE" -a "$UNBOUND_B_NTP_BOOT" -gt 0 ] ; then
  422. # DNSSEC chicken and egg with getting NTP time
  423. echo " val-override-date: -1" >> $UNBOUND_CONFFILE
  424. fi
  425. {
  426. echo " harden-dnssec-stripped: yes"
  427. echo " val-clean-additional: yes"
  428. echo " ignore-cd-flag: yes"
  429. } >> $UNBOUND_CONFFILE
  430. modulestring="validator $modulestring"
  431. fi
  432. if [ "$UNBOUND_B_DNS64" -gt 0 ] ; then
  433. echo " dns64-prefix: $UNBOUND_IP_DNS64" >> $UNBOUND_CONFFILE
  434. modulestring="dns64 $modulestring"
  435. fi
  436. {
  437. # Print final module string
  438. echo " module-config: \"$modulestring\""
  439. echo
  440. } >> $UNBOUND_CONFFILE
  441. if [ "$UNBOUND_B_QRY_MINST" -gt 0 -a "$UNBOUND_B_QUERY_MIN" -gt 0 ] ; then
  442. {
  443. # Some query privacy but "strict" will break some name servers
  444. echo " qname-minimisation: yes"
  445. echo " qname-minimisation-strict: yes"
  446. } >> $UNBOUND_CONFFILE
  447. elif [ "$UNBOUND_B_QUERY_MIN" -gt 0 ] ; then
  448. # Minor improvement on query privacy
  449. echo " qname-minimisation: yes" >> $UNBOUND_CONFFILE
  450. else
  451. echo " qname-minimisation: no" >> $UNBOUND_CONFFILE
  452. fi
  453. case "$UNBOUND_D_RECURSION" in
  454. passive)
  455. {
  456. echo " prefetch: no"
  457. echo " prefetch-key: no"
  458. echo " target-fetch-policy: \"0 0 0 0 0\""
  459. echo
  460. } >> $UNBOUND_CONFFILE
  461. ;;
  462. aggressive)
  463. {
  464. echo " prefetch: yes"
  465. echo " prefetch-key: yes"
  466. echo " target-fetch-policy: \"3 2 1 0 0\""
  467. echo
  468. } >> $UNBOUND_CONFFILE
  469. ;;
  470. *)
  471. if [ ! -f "$UNBOUND_TIMEFILE" ] ; then
  472. logger -t unbound -s "default recursion configuration"
  473. fi
  474. ;;
  475. esac
  476. {
  477. # Reload records more than 10 hours old
  478. # DNSSEC 5 minute bogus cool down before retry
  479. # Adaptive infrastructure info kept for 15 minutes
  480. echo " cache-min-ttl: $UNBOUND_TTL_MIN"
  481. echo " cache-max-ttl: 36000"
  482. echo " val-bogus-ttl: 300"
  483. echo " infra-host-ttl: 900"
  484. echo
  485. } >> $UNBOUND_CONFFILE
  486. if [ "$UNBOUND_B_HIDE_BIND" -gt 0 ] ; then
  487. {
  488. # Block server id and version DNS TXT records
  489. echo " hide-identity: yes"
  490. echo " hide-version: yes"
  491. echo
  492. } >> $UNBOUND_CONFFILE
  493. fi
  494. if [ "$UNBOUND_B_PRIV_BLCK" -gt 0 ] ; then
  495. {
  496. # Remove _upstream_ or global reponses with private addresses.
  497. # Unbounds own "local zone" and "forward zone" may still use these.
  498. # RFC1918, RFC3927, RFC4291, RFC6598, RFC6890
  499. echo " private-address: 10.0.0.0/8"
  500. echo " private-address: 100.64.0.0/10"
  501. echo " private-address: 169.254.0.0/16"
  502. echo " private-address: 172.16.0.0/12"
  503. echo " private-address: 192.168.0.0/16"
  504. echo " private-address: fc00::/8"
  505. echo " private-address: fd00::/8"
  506. echo " private-address: fe80::/10"
  507. } >> $UNBOUND_CONFFILE
  508. fi
  509. if [ "$UNBOUND_B_LOCL_BLCK" -gt 0 ] ; then
  510. {
  511. # Remove DNS reponses from upstream with loopback IP
  512. # Black hole DNS method for ad blocking, so consider...
  513. echo " private-address: 127.0.0.0/8"
  514. echo " private-address: ::1/128"
  515. echo
  516. } >> $UNBOUND_CONFFILE
  517. else
  518. echo >> $UNBOUND_CONFFILE
  519. fi
  520. # Except and accept domains as insecure (DNSSEC); work around broken domains
  521. config_list_foreach "$cfg" "domain_insecure" create_domain_insecure
  522. echo >> $UNBOUND_CONFFILE
  523. }
  524. ##############################################################################
  525. unbound_access() {
  526. # TODO: Unbound 1.6.0 added "tags" and "views", so we can add tags to
  527. # each access-control IP block, and then divert access.
  528. # -- "guest" WIFI will not be allowed to see local zone data
  529. # -- "child" LAN can black whole a list of domains to http~deadpixel
  530. if [ "$UNBOUND_B_LOCL_SERV" -gt 0 ] ; then
  531. # Only respond to queries from which this device has an interface.
  532. # Prevent DNS amplification attacks by not responding to the universe.
  533. config_load network
  534. config_foreach create_access_control interface
  535. {
  536. echo " access-control: 127.0.0.0/8 allow"
  537. echo " access-control: ::1/128 allow"
  538. echo " access-control: fe80::/10 allow"
  539. echo
  540. } >> $UNBOUND_CONFFILE
  541. else
  542. {
  543. echo " access-control: 0.0.0.0/0 allow"
  544. echo " access-control: ::0/0 allow"
  545. echo
  546. } >> $UNBOUND_CONFFILE
  547. fi
  548. {
  549. # Amend your own "server:" stuff here
  550. echo " include: $UNBOUND_SRV_CONF"
  551. echo
  552. } >> $UNBOUND_CONFFILE
  553. }
  554. ##############################################################################
  555. unbound_adblock() {
  556. # TODO: Unbound 1.6.0 added "tags" and "views"; lets work with adblock team
  557. local adb_enabled adb_file
  558. if [ ! -x /usr/bin/adblock.sh -o ! -x /etc/init.d/adblock ] ; then
  559. adb_enabled=0
  560. else
  561. /etc/init.d/adblock enabled && adb_enabled=1 || adb_enabled=0
  562. fi
  563. if [ "$adb_enabled" -gt 0 ] ; then
  564. {
  565. # Pull in your selected openwrt/pacakges/net/adblock generated lists
  566. for adb_file in $UNBOUND_VARDIR/adb_list.* ; do
  567. echo " include: $adb_file"
  568. done
  569. echo
  570. } >> $UNBOUND_CONFFILE
  571. fi
  572. }
  573. ##############################################################################
  574. unbound_hostname() {
  575. if [ -n "$UNBOUND_TXT_DOMAIN" ] ; then
  576. {
  577. # TODO: Unbound 1.6.0 added "tags" and "views" and we could make
  578. # domains by interface to prevent DNS from "guest" to "home"
  579. echo " local-zone: $UNBOUND_TXT_DOMAIN. $UNBOUND_D_DOMAIN_TYPE"
  580. echo " domain-insecure: $UNBOUND_TXT_DOMAIN"
  581. echo " private-domain: $UNBOUND_TXT_DOMAIN"
  582. echo
  583. echo " local-zone: $UNBOUND_TXT_HOSTNAME. $UNBOUND_D_DOMAIN_TYPE"
  584. echo " domain-insecure: $UNBOUND_TXT_HOSTNAME"
  585. echo " private-domain: $UNBOUND_TXT_HOSTNAME"
  586. echo
  587. } >> $UNBOUND_CONFFILE
  588. case "$UNBOUND_D_DOMAIN_TYPE" in
  589. deny|inform_deny|refuse|static)
  590. {
  591. # avoid upstream involvement in RFC6762 like responses (link only)
  592. echo " local-zone: local. $UNBOUND_D_DOMAIN_TYPE"
  593. echo " domain-insecure: local"
  594. echo " private-domain: local"
  595. echo
  596. } >> $UNBOUND_CONFFILE
  597. ;;
  598. esac
  599. if [ "$UNBOUND_D_LAN_FQDN" -gt 0 -o "$UNBOUND_D_WAN_FQDN" -gt 0 ] ; then
  600. config_load dhcp
  601. config_foreach create_interface_dns dhcp
  602. fi
  603. if [ -f "$UNBOUND_DHCP_CONF" ] ; then
  604. {
  605. # Seed DHCP records because dhcp scripts trigger externally
  606. # Incremental Unbound restarts may drop unbound-control add records
  607. echo " include: $UNBOUND_DHCP_CONF"
  608. echo
  609. } >> $UNBOUND_CONFFILE
  610. fi
  611. fi
  612. }
  613. ##############################################################################
  614. unbound_uci() {
  615. local cfg="$1"
  616. local dnsmasqpath hostnm
  617. hostnm="$(uci_get system.@system[0].hostname | awk '{print tolower($0)}')"
  618. UNBOUND_TXT_HOSTNAME=${hostnm:-thisrouter}
  619. config_get_bool UNBOUND_B_SLAAC6_MAC "$cfg" dhcp4_slaac6 0
  620. config_get_bool UNBOUND_B_DNS64 "$cfg" dns64 0
  621. config_get_bool UNBOUND_B_HIDE_BIND "$cfg" hide_binddata 1
  622. config_get_bool UNBOUND_B_LOCL_SERV "$cfg" localservice 1
  623. config_get_bool UNBOUND_B_MAN_CONF "$cfg" manual_conf 0
  624. config_get_bool UNBOUND_B_QUERY_MIN "$cfg" query_minimize 0
  625. config_get_bool UNBOUND_B_QRY_MINST "$cfg" query_min_strict 0
  626. config_get_bool UNBOUND_B_PRIV_BLCK "$cfg" rebind_protection 1
  627. config_get_bool UNBOUND_B_LOCL_BLCK "$cfg" rebind_localhost 0
  628. config_get_bool UNBOUND_B_CONTROL "$cfg" unbound_control 0
  629. config_get_bool UNBOUND_B_DNSSEC "$cfg" validator 0
  630. config_get_bool UNBOUND_B_NTP_BOOT "$cfg" validator_ntp 1
  631. config_get UNBOUND_IP_DNS64 "$cfg" dns64_prefix "64:ff9b::/96"
  632. config_get UNBOUND_N_EDNS_SIZE "$cfg" edns_size 1280
  633. config_get UNBOUND_N_RX_PORT "$cfg" listen_port 53
  634. config_get UNBOUND_N_ROOT_AGE "$cfg" root_age 9
  635. config_get UNBOUND_D_DOMAIN_TYPE "$cfg" domain_type static
  636. config_get UNBOUND_D_DHCP_LINK "$cfg" dhcp_link none
  637. config_get UNBOUND_D_LAN_FQDN "$cfg" add_local_fqdn 0
  638. config_get UNBOUND_D_PROTOCOL "$cfg" protocol mixed
  639. config_get UNBOUND_D_RECURSION "$cfg" recursion passive
  640. config_get UNBOUND_D_RESOURCE "$cfg" resource small
  641. config_get UNBOUND_D_WAN_FQDN "$cfg" add_wan_fqdn 0
  642. config_get UNBOUND_TTL_MIN "$cfg" ttl_min 120
  643. config_get UNBOUND_TXT_DOMAIN "$cfg" domain lan
  644. if [ "$UNBOUND_D_DHCP_LINK" = "none" ] ; then
  645. config_get_bool UNBOUND_B_DNSMASQ "$cfg" dnsmasq_link_dns 0
  646. if [ "$UNBOUND_B_DNSMASQ" -gt 0 ] ; then
  647. UNBOUND_D_DHCP_LINK=dnsmasq
  648. if [ ! -f "$UNBOUND_TIMEFILE" ] ; then
  649. logger -t unbound -s "Please use 'dhcp_link' selector instead"
  650. fi
  651. fi
  652. fi
  653. if [ "$UNBOUND_D_DHCP_LINK" = "dnsmasq" ] ; then
  654. if [ ! -x /usr/sbin/dnsmasq -o ! -x /etc/init.d/dnsmasq ] ; then
  655. UNBOUND_D_DHCP_LINK=none
  656. else
  657. /etc/init.d/dnsmasq enabled || UNBOUND_D_DHCP_LINK=none
  658. fi
  659. if [ "$UNBOUND_D_DHCP_LINK" = "none" -a ! -f "$UNBOUND_TIMEFILE" ] ; then
  660. logger -t unbound -s "cannot forward to dnsmasq"
  661. fi
  662. fi
  663. if [ "$UNBOUND_D_DHCP_LINK" = "odhcpd" ] ; then
  664. if [ ! -x /usr/sbin/odhcpd -o ! -x /etc/init.d/odhcpd ] ; then
  665. UNBOUND_D_DHCP_LINK=none
  666. else
  667. /etc/init.d/odhcpd enabled || UNBOUND_D_DHCP_LINK=none
  668. fi
  669. if [ "$UNBOUND_D_DHCP_LINK" = "none" -a ! -f "$UNBOUND_TIMEFILE" ] ; then
  670. logger -t unbound -s "cannot receive records from odhcpd"
  671. fi
  672. fi
  673. if [ "$UNBOUND_N_EDNS_SIZE" -lt 512 \
  674. -o 4096 -lt "$UNBOUND_N_EDNS_SIZE" ] ; then
  675. # exceeds range, back to default
  676. UNBOUND_N_EDNS_SIZE=1280
  677. fi
  678. if [ "$UNBOUND_N_RX_PORT" -lt 1024 \
  679. -o 10240 -lt "$UNBOUND_N_RX_PORT" ] ; then
  680. # special port or in 5 digits, back to default
  681. UNBOUND_N_RX_PORT=53
  682. fi
  683. if [ "$UNBOUND_TTL_MIN" -gt 1800 ] ; then
  684. # that could have had awful side effects
  685. UNBOUND_TTL_MIN=300
  686. fi
  687. }
  688. ##############################################################################
  689. unbound_start() {
  690. config_load unbound
  691. config_foreach unbound_uci unbound
  692. unbound_mkdir
  693. if [ "$UNBOUND_B_MAN_CONF" -eq 0 ] ; then
  694. unbound_conf
  695. unbound_access
  696. unbound_adblock
  697. if [ "$UNBOUND_D_DHCP_LINK" = "dnsmasq" ] ; then
  698. dnsmasq_link
  699. else
  700. unbound_hostname
  701. fi
  702. unbound_control
  703. fi
  704. }
  705. ##############################################################################
  706. unbound_stop() {
  707. local resolvsym=0
  708. rootzone_update
  709. if [ ! -x /usr/sbin/dnsmasq -o ! -x /etc/init.d/dnsmasq ] ; then
  710. resolvsym=1
  711. else
  712. /etc/init.d/dnsmasq enabled || resolvsym=1
  713. fi
  714. if [ "$resolvsym" -gt 0 ] ; then
  715. # set resolver file to normal, but don't stomp on dnsmasq
  716. rm -f /tmp/resolv.conf
  717. ln -s /tmp/resolv.conf.auto /tmp/resolv.conf
  718. fi
  719. }
  720. ##############################################################################