I dunno what state this is in, but I might want to keep it.

This commit is contained in:
2026-09-02 05:55:59 -04:00
parent 6b02d9d58e
commit 0e27fd9cd5
10 changed files with 1137 additions and 0 deletions
+49
View File
@@ -0,0 +1,49 @@
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: allow_hosts
# REQUIRE: named
# KEYWORD: shutdown
#
. /etc/rc.subr
name="allow_hosts"
desc="Allow hosts by DNS (from local DNS)"
start_cmd='allow_hosts_start'
stop_cmd='allow_hosts_stop'
rcvar='allow_hosts_enable'
load_rc_config 'allow_hosts'
[ -z "$allow_hosts_enable" ] && allow_hosts_enable='NO'
if [ -z "${allow_hosts_rules}" ]
then
echo "Must have a route policy target file"
exit 1
fi
. /etc/router-conf/pf-framework.subr
allow_hosts_start()
{
echo "Running allow hosts"
echo "include \"${allow_hosts_rules}\"" > /etc/router-conf/gen/pf.rules.conf
pfctl -a allow-hosts -f ${allow_hosts_rules}
}
allow_hosts_stop()
{
}
################ Epilogue
run_rc_command "$1"
# vim: ft=bash
+54
View File
@@ -0,0 +1,54 @@
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: clear_route_policy
# BEFORE: pf
# KEYWORD: shutdown
#
. /etc/rc.subr
name="clear_route_policy"
desc="Policy Based Routing Reset"
start_cmd='clear_route_policy_start'
stop_cmd='clear_route_policy_stop'
rcvar='route_policy_enable'
load_rc_config 'route_policy'
[ -z "$route_policy_enable" ] && route_policy_enable='NO'
if [ -z "${route_policy_file}" ]
then
echo "Must have a route policy target file"
exit 1
fi
. /etc/router-conf/pf-framework.subr
clear_route_policy_start()
{
echo "" >/etc/router-conf/gen/pf.rules.conf
pfctl -a allow-hosts -f /dev/null
clear_all_policies
#pfctl -a route-policies -f ${route_policy_file}
}
clear_route_policy_stop()
{
echo "" >/etc/router-conf/gen/pf.rules.conf
pfctl -a allow-hosts -f /dev/null
clear_all_policies
#pfctl -a route-policies -f ${route_policy_file}
}
################ Epilogue
run_rc_command "$1"
# vim: ft=bash
Executable
+56
View File
@@ -0,0 +1,56 @@
#!/bin/sh
# PROVIDE: dhcp6c
# REQUIRE: netif
# BEFORE: NETWORKING
# KEYWORD: shutdown
# Add the following lines to
# /etc/rc.conf.d/dhcp6c /etc/rc.conf.local or /etc/rc.conf
# to enable this service:
#
# dhcp6c_enable (bool): Set to NO by default.
# Set it to YES to enable dhcp6c.
# dhcp6c_config (path): Set to /usr/local/etc/dhcp6c.conf
# by default.
# dhcp6c_dhcp6cctlkey (path): Set to /usr/local/etc/dhcp6cctlkey
# by default.
# dhcp6c_pidfile (path): Set to /var/run/dhcp6c.pid
# by default.
# dhcp6c_interfaces (NIC list): Not defined by default.
# Set it to the network interface(s) where dhcp6c should work on.
# dhcp6c_flags (additional arguments): Not defined by default.
#
. /etc/rc.subr
name="dhcp6c"
rcvar=dhcp6c_enable
command="/usr/local/sbin/${name}"
start_precmd="${name}_precmd"
load_rc_config $name
: ${dhcp6c_enable="NO"}
: ${dhcp6c_config="/usr/local/etc/${name}.conf"}
: ${dhcp6c_dhcp6cctlkey="/usr/local/etc/dhcp6cctlkey"}
: ${dhcp6c_pidfile="/var/run/${name}.pid"}
required_files="${dhcp6c_config}"
pidfile="${dhcp6c_pidfile}"
command_args="${dhcp6c_args} -c ${dhcp6c_config} -p ${dhcp6c_pidfile} ${dhcp6c_interfaces}"
dhcp6c_precmd()
{
if [ -z ${dhcp6c_interfaces} ]; then
warn "dhcp6c_interfaces is not set."
return 1
fi
if [ ! -s ${dhcp6c_dhcp6cctlkey} ]; then
echo "Creating ${dhcp6c_dhcp6cctlkey}"
(umask 077 ; openssl rand -base64 48 > ${dhcp6c_dhcp6cctlkey})
fi
}
run_rc_command "$1"
Executable
+45
View File
@@ -0,0 +1,45 @@
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: fib_setup
# BEFORE: sysctl
#
. /etc/rc.subr
name="fib_setup"
desc="Calculate the fib count"
start_cmd='fib_setup_start'
stop_cmd='fib_setup_stop'
rcvar='fib_setup_enable'
load_rc_config 'fib_setup'
[ -z "$fib_setup_enable" ] && fib_setup_enable='NO'
. /etc/router-conf/pf-framework.subr
fib_setup_start()
{
echo "Running fib_setup"
fib_count=$(( ${max_fib} + 1 ))
cp ${router_conf_dir}/sysctl.conf ${router_conf_dir}/gen/
echo "net.fibs=${fib_count}" >> ${router_conf_dir}/gen/sysctl.conf
}
fib_setup_stop()
{
}
################ Epilogue
run_rc_command "$1"
# vim: ft=bash
+37
View File
@@ -0,0 +1,37 @@
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: generate_isp_dhcp
# REQUIRE: netif
# BEFORE: dhcp6c
# KEYWORD: shutdown
#
. /etc/rc.subr
name='generate_isp_dhcp'
start_cmd='generate_isp_dhcp_start'
stop_cmd='generate_isp_dhcp_stop'
rcvar='generate_isp_dhcp_enable'
load_rc_config 'generate_isp_dhcp'
[ -z "$generate_isp_dhcp_enable" ] && generate_isp_dhcp_enable='YES'
generate_isp_dhcp_start()
{
_emit_dhcpv6
cat ${router_conf_dir}/gen/dhcp6c.*.conf > ${router_conf_dir}/gen/dhcp6c.conf
}
generate_isp_dhcp_stop()
{
}
################ Epilogue
run_rc_command "$1"
# vim: ft=bash
Executable
+142
View File
@@ -0,0 +1,142 @@
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: localnet
# REQUIRE: dhcp6c
# BEFORE: rtadvd named
# KEYWORD: shutdown
#
# This is a bit hacky, but I think I can live with it for now.
#
# The purpose of this script is to generate various ISP prefix dependent files.
#
# Specifically, the DNS (BIND) acls file for handling various views, a local ISP
# range address for the router itself (on a dedicated loopback device), and attach
# the IMP_NET address for this machine to another loopback device.
. /etc/rc.subr
name='localnet'
extra_commands="rebuild_rtadvd_conf rebuild_zoneinfo"
start_cmd='localnet_start'
stop_cmd='localnet_stop'
rebuild_rtadvd_conf_cmd="localnet_build_rtadv"
rebuild_zoneinfo_cmd="localnet_build_zoneinfo"
rcvar='localnet_enable'
load_rc_config 'localnet'
localnet_first_nic="re0.301"
[ -z "$localnet_enable" ] && localnet_enable='NO'
[ -z "$localnet_zoneinfo_enable" ] && localnet_zoneinfo_enable='NO'
localnet_build_zoneinfo()
{
compute_addrs
localnet_build_zoneinfo_impl
}
localnet_build_zoneinfo_impl()
{
if [ $(option_selected localnet_zoneinfo_enable) = "YES" ]
then
build_zoneinfo ${isp_prefix} ${localnet_zoneinfo_subnet} ${router_conf_dir}/namedb/local-machines.defs > ${router_conf_dir}/gen/${localnet_zone_file}
fi
}
localnet_build_acls()
{
gen_acls_dir=${router_conf_dir}/gen/namedb
mkdir -p ${gen_acls_dir}
cat ${router_conf_dir}/namedb/acls.template.conf \
| sed \
-e "s/@ISP_PREFIX@/${isp_prefix}/g" \
-e "s/@ULA_PREFIX@/${secret_ip6_net}/g" \
> ${gen_acls_dir}/acls.conf
}
localnet_build_rtadv()
{
gen_rtadv_dir=${router_conf_dir}/gen
rtadvd_conf=${gen_rtadv_dir}/rtadvd.conf
mkdir -p ${gen_rtadv_dir}
_search_list=$( echo ${rtadvd_dns_search_list} | sed -e 's/ */,/g' -e 's/^,//' -e 's/,$//' )
cat ${router_conf_dir}/rtadvd.template.conf \
| sed \
-e "s/@PREF64_PREFIX@/${rtadvd_pref64_prefix}/" \
-e "s/@DNS_SERVER@/${rtadvd_dns_server}/" \
-e "s/@DNSSL@/${_search_list}/" \
> ${rtadvd_conf}
echo "" >> ${rtadvd_conf}
echo "" >> ${rtadvd_conf}
for interface in ${rtadvd_interfaces}
do
echo "${interface}:tc=settings" >> ${rtadvd_conf}
done
}
compute_addrs() {
# todo: Adjust our ipv6 hint... get from a var?
v6addr=$(ifconfig ${localnet_first_nic} | grep "inet6 [23]...:" | head -1 | awk '{print $2}')
echo "V6 addr is: ${v6addr}"
loop=0
while [ -z "${v6addr}" -a ${loop} -lt 4 ]
do
sleep 5
v6addr=$(ifconfig re0.301 | grep "2600:4040:" | head -1 | awk '{print $2}')
echo "V6 addr is: ${v6addr}"
loop=$(( ${loop} + 1 ))
done
echo "V6 addr is: ${v6addr}"
three_quads=$(echo ${v6addr} | awk -F ':' '{print $1":"$2":"$3}')
echo "First three quads are: ${three_quads}"
last_quad=$(echo ${v6addr} | awk -F ':' '{print $4}')
echo "Last quad is: ${last_quad}"
last_prefix=$(echo ${last_quad} | rev | awk '{print $1"0000"}' | cut -c 3,4 | rev | sed -e 's/^0//')
echo "Last prefix is: ${last_prefix}"
isp_prefix="${three_quads}:${last_prefix}"
base_addr=" inet6 ${isp_prefix}ff::1"
}
localnet_start() {
cp ${router_conf_dir}/resolv.conf.master ${router_conf_dir}/resolv.conf
compute_addrs
ifconfig lo1 create ${base_addr} prefer_source
ifconfig lo3 create inet 198.18.0.1/32
# DO NOT USE prefer_source for this address...
# It will cause confusion for the wireguard tunnels underneath...
# It also could cause DNS recursion to fail -- routing as the nested
# connections...
ifconfig lo2 create inet6 2602:f6a8:1::/64 anycast # DO NOT USE prefer_source
ifconfig lo4 create inet 155.103.215.15/32 anycast
localnet_build_rtadv
localnet_build_acls
localnet_build_zoneinfo_impl
}
localnet_stop() {
compute_addrs
ifconfig lo0 ${base_addr} delete
ifconfig lo1 destroy
ifconfig lo2 destroy
ifconfig lo3 destroy
ifconfig lo4 destroy
}
run_rc_command "$1"
# vim: ft=bash
+92
View File
@@ -0,0 +1,92 @@
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: route_policy
# REQUIRE: wireguard
# KEYWORD: shutdown
#
# This is a bit hacky, but I think I can live with it for now.
#hack
. /etc/rc.subr
name="route_policy"
desc="Policy Based Routing Installer"
start_cmd='route_policy_start'
stop_cmd='route_policy_stop'
rcvar='route_policy_enable'
load_rc_config 'route_policy'
[ -z "$route_policy_enable" ] && route_policy_enable='NO'
if [ -z "${route_policy_file}" ]
then
echo "Must have a route policy target file"
exit 1
fi
. /etc/router-conf/pf-framework.subr
do_all_routes()
{
while [ -n "$1" ]
do
install_route_policy $1
shift 1
done
}
do_all_routes_v4()
{
while [ -n "$1" ]
do
install_route_policy_v4 $1
shift 1
done
}
route_policy_start()
{
clear_all_policies
echo "# This file is generated." >> ${route_policy_file}
echo "# Do not edit." >> ${route_policy_file}
echo "" >> ${route_policy_file}
# TODO: Record the policies one-per-line via a helper loop subroutine?
echo "# (Generated with \`${route_policies}\`, at `date`.)" >> ${route_policy_file}
echo "# (Generated with \`${route_policies_v4}\`, at `date`.)" >> ${route_policy_file}
echo "" >> ${route_policy_file}
echo "" >> ${route_policy_file}
do_all_routes ${route_policies}
do_all_routes_v4 ${route_policies_v4}
echo "" >> ${route_policy_file}
echo -n "# v" >> ${route_policy_file}
echo "im: ft=pf" >> ${route_policy_file}
#pfctl -a "route-policies" -f ${route_policy_file}
#pfctl -f ${pf_rules} # <--- Hack?
/etc/rc.d/pf reload # <---- UGLY hack!!?
}
route_policy_stop()
{
clear_all_policies
}
################ Epilogue
run_rc_command "$1"
# vim: ft=bash
Executable
+77
View File
@@ -0,0 +1,77 @@
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: tayga
# REQUIRE: SERVERS
# KEYWORD: shutdown
#
. /etc/rc.subr
name='tayga'
start_cmd='tayga_start'
stop_cmd='tayga_stop'
rcvar='tayga_enable'
load_rc_config 'tayga'
pidfile="/var/run/${name}.pid"
command="/usr/local/sbin/${name}"
# Confirm necessary variables are set
check_vars() {
[ -z "$tayga_ipv4_addr" ] && err 3 "Must set tayga_ipv4_addr to the address that the tayga server lives on"
[ -z "$tayga_ipv4_endpoint" ] && err 3 "Must set tayga_ipv4_endpoint to the address that the tunnel lives on"
[ -z "$tayga_ipv4_net" ] && err 3 "Must set tayga_ipv4_net to the network that the tunnel lives on"
[ -z "$tayga_ipv6_endpoint" ] && err 3 "Must set tayga_ipv6_endpoint to the address that the tunnel lives on"
[ -z "$tayga_ipv6_net" ] && err 3 "Must set tayga_ipv6_net to the network that the tunnel provides"
}
[ -z "$tayga_config" ] && tayga_config="/usr/local/etc/tayga.conf"
command_args="-p ${pidfile} -c ${tayga_config}"
[ -z "$tayga_enable" ] && tayga_enable='YES'
tayga_start() {
check_vars
"$command" $command_args
while ! ifconfig 'nat64'; do sleep 1; done
ifconfig 'nat64' inet "${tayga_ipv4_endpoint}/32" "${tayga_ipv4_addr}"
if [ ! -z "${tayga_group}" ] ; then ifconfig 'nat64' group ${tayga_group} ; fi
ifconfig 'nat64' inet6 "${tayga_ipv6_endpoint}/128"
#echo Add route 4
route -4 add "${tayga_ipv4_net}" -interface 'nat64'
#echo Add route 6 for endpoint from net
#route -6 add "${tayga_ipv6_endpoint}" -iface 'nat64' #-fib 0-7
route -6 add "${tayga_ipv6_net}" "${tayga_ipv6_endpoint}" #-fib 0-7
#echo Add route 6 for endpoint subnet
route -6 add "${tayga_ipv6_endpoint}/64" "${tayga_ipv6_endpoint}" #-fib 0-7
for prefix in ${tayga_v4_prefixes}
do
route add ${prefix} ${tayga_ipv4_addr} -fib 0-${max_fib}
done
}
tayga_stop() {
if [ -n "$rc_pid" ]; then
check_vars
for prefix in tayga_v4_prefixes
do
route del ${prefix} ${tayga_ipv4_addr} -fib 0-${max_fib}
done
echo 'stopping tayga'
kill -2 "${rc_pid}"
route -6 del "${tayga_ipv6_net}" -interface 'nat64'
route -4 del "${tayga_ipv4_net}" -interface 'nat64'
ifconfig 'nat64' destroy
else
echo "${name} is not running."
fi
}
run_rc_command "$1"