| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378 | 
							- #!/bin/bash
 - #
 - # .---.                  .              .
 - # |                      |              |
 - # |--- .--. .-.  .-.  .-.|  .-. .--.--. |.-.  .-. .--.  .-.
 - # |    |   (.-' (.-' (   | (   )|  |  | |   )(   )|  | (.-'
 - # '    '     --'  --'  -' -  -' '  '   -' -'   -' '   -  --'
 - #
 - #                    Freedom in the Cloud
 - #
 - # Used to enable or disable batman mesh protocol on wlanX
 - #
 - # License
 - # =======
 - #
 - # Copyright (C) 2015-2016 Bob Mottram <bob@freedombone.net>
 - #
 - # This program is free software: you can redistribute it and/or modify
 - # it under the terms of the GNU Affero General Public License as published by
 - # the Free Software Foundation, either version 3 of the License, or
 - # (at your option) any later version.
 - #
 - # This program is distributed in the hope that it will be useful,
 - # but WITHOUT ANY WARRANTY; without even the implied warranty of
 - # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 - # GNU Affero General Public License for more details.
 - #
 - # You should have received a copy of the GNU Affero General Public License
 - # along with this program.  If not, see <http://www.gnu.org/licenses/>.
 - 
 - PROJECT_NAME='freedombone'
 - COMPLETION_FILE=/root/${PROJECT_NAME}-completed.txt
 - HOTSPOT_PASSPHRASE='mesh'
 - 
 - source /usr/share/${PROJECT_NAME}/utils/${PROJECT_NAME}-utils-wifi
 - 
 - if [[ $1 == "start" ]]; then
 -     # install avahi
 -     sed -i "s|#host-name=.*|host-name=$(hostname)|g" /etc/avahi/avahi-daemon.conf
 -     sed -i "s|host-name=.*|host-name=$(hostname)|g" /etc/avahi/avahi-daemon.conf
 -     sed -i "s|use-ipv4=.*|use-ipv4=yes|g" /etc/avahi/avahi-daemon.conf
 -     sed -i "s|use-ipv6=.*|use-ipv6=no|g" /etc/avahi/avahi-daemon.conf
 -     sed -i "s|#disallow-other-stacks=.*|disallow-other-stacks=yes|g" /etc/avahi/avahi-daemon.conf
 -     sed -i "s|hosts:.*|hosts:          files mdns4_minimal dns mdns4 mdns|g" /etc/nsswitch.conf
 - fi
 - 
 - # Mesh definition
 - WIFI_SSID='mesh'
 - if [ -f $COMPLETION_FILE ]; then
 -     if grep -q "WIFI_SSID:" $COMPLETION_FILE; then
 -         WIFI_SSID=$(cat $COMPLETION_FILE | grep "WIFI_SSID:" | awk -F ':' '{print $2}')
 -     fi
 -     sed -i "s|WIFI_SSID:.*|WIFI_SSID:${WIFI_SSID}|g" $COMPLETION_FILE
 - fi
 - CELLID='any'
 - 
 - CHANNEL=2
 - if [ -f $COMPLETION_FILE ]; then
 -     if grep -q "Wifi channel:" $COMPLETION_FILE; then
 -         CHANNEL=$(cat $COMPLETION_FILE | grep "Wifi channel:" | awk -F ':' '{print $2}')
 -     fi
 -     sed -i "s|Wifi channel:.*|Wifi channel:${CHANNEL}|g" $COMPLETION_FILE
 - fi
 - 
 - ZERONET_PORT=15441
 - IPFS_PORT=4001
 - TOX_PORT=33445
 - TRACKER_PORT=6969
 - LIBREVAULT_PORT=42345
 - TAHOELAFS_PORT=50213
 - 
 - # Ethernet bridge definition (bridged to bat0)
 - BRIDGE=br-mesh
 - BRIDGE_HOTSPOT=br-hotspot
 - IFACE=
 - IFACE_SECONDARY=
 - EIFACE=eth0
 - WLAN_ADAPTORS=$(count_wlan)
 - 
 - if [ $WLAN_ADAPTORS -eq 0 ]; then
 -     echo $'No wlan adaptors found'
 -     exit 0
 - fi
 - 
 - update_wifi_adaptors
 - 
 - if [ ! $IFACE ]; then
 -     echo $'No wlan adaptor'
 -     exit 0
 - fi
 - 
 - if [ -e /etc/default/batctl ]; then
 -     . /etc/default/batctl
 - fi
 - 
 - function global_rate_limit {
 -     if ! grep -q "tcp_challenge_ack_limit" /etc/sysctl.conf; then
 -         echo 'net.ipv4.tcp_challenge_ack_limit = 999999999' >> /etc/sysctl.conf
 -     else
 -         sed -i 's|net.ipv4.tcp_challenge_ack_limit.*|net.ipv4.tcp_challenge_ack_limit = 999999999|g' /etc/sysctl.conf
 -     fi
 -     sysctl -p -q
 - }
 - 
 - function status {
 -     batctl o
 - }
 - 
 - function stop {
 -     if [ -z "$IFACE" ]; then
 -         echo 'error: unable to find wifi interface, not enabling batman-adv mesh'
 -         return
 -     fi
 -     if [ "$EIFACE" ]; then
 -         brctl delif $BRIDGE bat0
 -         brctl delif $BRIDGE $EIFACE
 -         ifconfig $BRIDGE down || true
 -         brctl delbr $BRIDGE
 -         ifconfig $EIFACE down -promisc
 -     fi
 -     if [ $IFACE_SECONDARY ]; then
 -         systemctl stop hostapd
 -         brctl delif $BRIDGE_HOTSPOT bat0
 -         ifconfig $BRIDGE_HOTSPOT down || true
 -         brctl delbr $BRIDGE_HOTSPOT
 -     fi
 - 
 -     avahi-autoipd -k $BRIDGE
 -     avahi-autoipd -k $IFACE
 -     ifconfig bat0 down -promisc
 - 
 -     batctl if del $IFACE
 -     rmmod batman-adv
 -     ifconfig $IFACE mtu 1500
 -     ifconfig $IFACE down
 -     iwconfig $IFACE mode managed
 - 
 -     iptables -D INPUT -p tcp --dport $TRACKER_PORT -j ACCEPT
 -     iptables -D INPUT -p udp --dport $TRACKER_PORT -j ACCEPT
 -     iptables -D INPUT -p tcp --dport 80 -j ACCEPT
 -     iptables -D INPUT -p udp --dport 80 -j ACCEPT
 -     iptables -D INPUT -p tcp --dport 548 -j ACCEPT
 -     iptables -D INPUT -p udp --dport 548 -j ACCEPT
 -     iptables -D INPUT -p tcp --dport 5353 -j ACCEPT
 -     iptables -D INPUT -p udp --dport 5353 -j ACCEPT
 -     iptables -D INPUT -p tcp --dport 5354 -j ACCEPT
 -     iptables -D INPUT -p udp --dport 5354 -j ACCEPT
 -     iptables -D INPUT -p tcp --dport $ZERONET_PORT -j ACCEPT
 -     iptables -D INPUT -p udp --dport $ZERONET_PORT -j ACCEPT
 -     iptables -D INPUT -p tcp --dport $IPFS_PORT -j ACCEPT
 -     iptables -D INPUT -p udp --dport $IPFS_PORT -j ACCEPT
 -     iptables -D INPUT -p tcp --dport $TOX_PORT -j ACCEPT
 -     iptables -D INPUT -p udp --dport $TOX_PORT -j ACCEPT
 -     iptables -D INPUT -p tcp --dport $LIBREVAULT_PORT -j ACCEPT
 -     iptables -D INPUT -p udp --dport $LIBREVAULT_PORT -j ACCEPT
 -     iptables -D INPUT -p tcp --dport $TAHOELAFS_PORT -j ACCEPT
 - 
 -     systemctl restart network-manager
 - }
 - 
 - function verify {
 -     tempfile="$(mktemp)"
 -     batctl o > $tempfile
 -     if grep -q "disabled" $tempfile; then
 -         echo $'B.A.T.M.A.N. not enabled'
 -         rm $tempfile
 -         stop
 -         exit 726835
 -     fi
 -     echo $'B.A.T.M.A.N. is running'
 -     rm $tempfile
 - }
 - 
 - function assign_peer_address {
 -     for i in {1..6}; do
 -         number=$RANDOM
 -         let "number %= 255"
 -         octet=$(echo "obase=16;$number" | bc)
 -         if [ ${#octet} -lt 2 ]; then
 -             octet="0${octet}"
 -         fi
 -         if [ $i -gt 1 ]; then
 -             echo -n ":"
 -         fi
 -         echo -n "${octet}"
 -     done
 -     echo ''
 - }
 - 
 - function start {
 -     if [ -z "$IFACE" ] ; then
 -         echo 'error: unable to find wifi interface, not enabling batman-adv mesh'
 -         exit 723657
 -     fi
 -     echo "info: enabling batman-adv mesh network $WIFI_SSID on $IFACE"
 - 
 -     systemctl stop network-manager
 -     sleep 5
 - 
 -     # remove an avahi service which isn't used
 -     if [ -f /etc/avahi/services/udisks.service ]; then
 -         sudo rm /etc/avahi/services/udisks.service
 -     fi
 - 
 -     global_rate_limit
 - 
 -     # Might have to re-enable wifi
 -     rfkill unblock $(rfkill list|awk -F: "/phy/ {print $1}") || true
 - 
 -     ifconfig $IFACE down
 -     ifconfig $IFACE mtu 1532
 -     ifconfig $IFACE hw ether $(assign_peer_address)
 -     iwconfig $IFACE enc off
 -     iwconfig $IFACE mode ad-hoc essid $WIFI_SSID channel $CHANNEL
 -     sleep 1
 -     iwconfig $IFACE ap $CELLID
 - 
 -     modprobe batman-adv
 -     batctl if add $IFACE
 -     ifconfig $IFACE up
 -     avahi-autoipd --force-bind --daemonize --wait $IFACE
 -     ifconfig bat0 up promisc
 - 
 -     #Use persistent HWAddr
 -     ether_new=$(ifconfig eth0 | grep HWaddr | sed -e "s/.*HWaddr //")
 -     if [ ! -f /var/lib/mesh-node/bat0 ]; then
 -         mkdir /var/lib/mesh-node
 -         echo "${ether_new}" > /var/lib/mesh-node/bat0
 -     else
 -         ether=$(cat /var/lib/mesh-node/bat0)
 -         ifconfig bat0 hw ether ${ether}
 -     fi
 - 
 -     if [ "$EIFACE" ] ; then
 -         brctl addbr $BRIDGE
 -         brctl addif $BRIDGE bat0
 -         brctl addif $BRIDGE $EIFACE
 -         ifconfig bat0 0.0.0.0
 -         ifconfig $EIFACE 0.0.0.0
 -         ifconfig $EIFACE up promisc
 -         ifconfig $BRIDGE up
 -         avahi-autoipd --force-bind --daemonize --wait $BRIDGE
 -     fi
 - 
 -     if [ $IFACE_SECONDARY ]; then
 -         if [[ $IFACE != $IFACE_SECONDARY ]]; then
 -             if [ -d /etc/hostapd ]; then
 -                 # bridge between mesh and wifi hotspot for mobile
 -                 HOTSPOT_NAME=$"${WIFI_SSID}-hotspot"
 -                 ifconfig $IFACE_SECONDARY down
 -                 ifconfig $IFACE_SECONDARY mtu 1500
 -                 ifconfig $IFACE_SECONDARY hw ether $(assign_peer_address)
 -                 iwconfig $IFACE_SECONDARY enc open
 -                 iwconfig $IFACE_SECONDARY mode managed essid $HOTSPOT_NAME channel ${CHANNEL}
 -                 iwconfig $IFACE_SECONDARY ap $CELLID
 - 
 -                 brctl addbr $BRIDGE_HOTSPOT
 -                 brctl addif $BRIDGE_HOTSPOT bat0
 -                 brctl addif $BRIDGE_HOTSPOT $IFACE_SECONDARY
 -                 ifconfig bat0 0.0.0.0
 -                 ifconfig $IFACE_SECONDARY 0.0.0.0
 - 
 -                 sed -i 's|#DAEMON_CONF=.*|DAEMON_CONF="/etc/hostapd/hostapd.conf"|g' /etc/default/hostapd
 - 
 -                 echo "interface=${IFACE_SECONDARY}" > /etc/hostapd/hostapd.conf
 -                 echo "bridge=${BRIDGE_HOTSPOT}" >> /etc/hostapd/hostapd.conf
 -                 echo 'driver=nl80211' >> /etc/hostapd/hostapd.conf
 -                 echo "country_code=UK" >> /etc/hostapd/hostapd.conf
 -                 echo "ssid=$HOTSPOT_NAME" >> /etc/hostapd/hostapd.conf
 -                 echo 'hw_mode=g' >> /etc/hostapd/hostapd.conf
 -                 echo "channel=${CHANNEL}" >> /etc/hostapd/hostapd.conf
 -                 echo 'wpa=2' >> /etc/hostapd/hostapd.conf
 -                 echo "wpa_passphrase=$HOTSPOT_PASSPHRASE" >> /etc/hostapd/hostapd.conf
 -                 echo 'wpa_key_mgmt=WPA-PSK' >> /etc/hostapd/hostapd.conf
 -                 echo 'wpa_pairwise=TKIP' >> /etc/hostapd/hostapd.conf
 -                 echo 'rsn_pairwise=CCMP' >> /etc/hostapd/hostapd.conf
 -                 echo 'auth_algs=1' >> /etc/hostapd/hostapd.conf
 -                 echo 'macaddr_acl=0' >> /etc/hostapd/hostapd.conf
 - 
 -                 ifconfig $BRIDGE_HOTSPOT up
 -                 avahi-autoipd --force-bind --daemonize --wait $BRIDGE_HOTSPOT
 -                 ifconfig $IFACE_SECONDARY up promisc
 -                 #ifconfig $IFACE_SECONDARY auto-dhcp start
 -                 systemctl start hostapd
 -             fi
 -         fi
 -     fi
 - 
 -     iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
 -     iptables -A OUTPUT -p icmp --icmp-type echo-reply -j ACCEPT
 -     iptables -A INPUT -p tcp --dport $TRACKER_PORT -j ACCEPT
 -     iptables -A INPUT -p udp --dport $TRACKER_PORT -j ACCEPT
 -     iptables -A INPUT -p tcp --dport 80 -j ACCEPT
 -     iptables -A INPUT -p udp --dport 80 -j ACCEPT
 -     iptables -A INPUT -p tcp --dport 548 -j ACCEPT
 -     iptables -A INPUT -p udp --dport 548 -j ACCEPT
 -     iptables -A INPUT -p tcp --dport 5353 -j ACCEPT
 -     iptables -A INPUT -p udp --dport 5353 -j ACCEPT
 -     iptables -A INPUT -p tcp --dport 5354 -j ACCEPT
 -     iptables -A INPUT -p udp --dport 5354 -j ACCEPT
 -     iptables -A INPUT -p tcp --dport $ZERONET_PORT -j ACCEPT
 -     iptables -A INPUT -p udp --dport $ZERONET_PORT -j ACCEPT
 -     iptables -A INPUT -p tcp --dport $IPFS_PORT -j ACCEPT
 -     iptables -A INPUT -p tcp --dport $TOX_PORT -j ACCEPT
 -     iptables -A INPUT -p udp --dport $TOX_PORT -j ACCEPT
 -     iptables -A INPUT -p tcp --dport $LIBREVAULT_PORT -j ACCEPT
 -     iptables -A INPUT -p udp --dport $LIBREVAULT_PORT -j ACCEPT
 -     iptables -A INPUT -p tcp --dport $TAHOELAFS_PORT -j ACCEPT
 - 
 -     systemctl restart avahi-daemon
 - 
 -     verify
 - }
 - 
 - function monitor {
 -     if [ -z "$IFACE" ] ; then
 -         echo 'error: unable to find wifi interface, not enabling batman-adv mesh'
 -         exit 723657
 -     fi
 - 
 -     stop
 - 
 -     echo "info: monitoring mesh network $WIFI_SSID on $IFACE"
 - 
 -     systemctl stop network-manager
 -     sleep 5
 - 
 -     global_rate_limit
 - 
 -     # Might have to re-enable wifi
 -     rfkill unblock $(rfkill list|awk -F: "/phy/ {print $1}") || true
 - 
 -     ifconfig $IFACE down
 -     ifconfig $IFACE mtu 1532
 -     ifconfig $IFACE hw ether $(assign_peer_address)
 -     iwconfig $IFACE enc off
 -     iwconfig $IFACE mode monitor channel $CHANNEL
 -     sleep 1
 -     iwconfig $IFACE ap $CELLID
 - 
 -     modprobe batman-adv
 -     batctl if add $IFACE
 -     ifconfig $IFACE up
 -     horst -i $IFACE
 -     start
 - }
 - 
 - if ! grep -q "$IFACE" /proc/net/dev; then
 -     echo 'Interface $IFACE was not found'
 -     stop
 -     exit 1
 - fi
 - 
 - case "$1" in
 -     start|stop|status|monitor)
 -         $1
 -         ;;
 -     restart)
 -         stop
 -         sleep 10
 -         start
 -         ;;
 -     ping)
 -         batctl ping $2
 -         ;;
 -     data)
 -         watch -n1 "batctl s | grep mgmt | grep bytes"
 -         ;;
 -     ls|list)
 -         avahi-browse -atl
 -         ;;
 -     *)
 -         echo "error: invalid parameter $1"
 -         echo 'usage: $0 {start|stop|restart|status|ping|ls|list}'
 -         exit 2
 -         ;;
 - esac
 - exit 0
 
 
  |