From 14ec5781354ad07a2d39d59d4a1a4d56a53da9754bd4561b6aaa5a0b30e6b8c5 Mon Sep 17 00:00:00 2001 From: ADAM David Alan Martin Date: Mon, 31 Aug 2026 09:21:44 -0400 Subject: [PATCH] Tayga configuration can be generated. This facilitates more configuration being authoritatively in `rc.conf`. --- defaults/rc.conf | 40 ++++++++++++++++++++++++++++++++++++ rc.d/generate_tayga | 48 ++++++++++++++++++++++++++++++++++++++++++++ rc.subr | 5 +++++ templates/tayga.conf | 14 +++++++++++++ 4 files changed, 107 insertions(+) create mode 100755 rc.d/generate_tayga create mode 100644 templates/tayga.conf diff --git a/defaults/rc.conf b/defaults/rc.conf index bcb54ea..e7edde4 100644 --- a/defaults/rc.conf +++ b/defaults/rc.conf @@ -56,4 +56,44 @@ allow_hosts_rules="${rc_router_gen_dir}/pf.rules.conf" rtsold_flags="-F" +################### +## Tayga options ## +################### +tayga_enable="NO" +tayga_config="${rc_router_gen_dir}/tayga.conf" +tayga_device="nat64" + +# The Tayga defaults for 6to4 make a few weird +# assumptions -- you're okay with using 6to4 space +# and you do not explicitly enable Class E on FreeBSD +# Otherwise `240.0.0.0/8` makes a heck of a lot more sense. + +# For Tayga, we use the old 6to4 space. +# It's mostly unused these days, and it's a similar purpose +tayga_ipv4_addr="192.88.99.1" +tayga_ipv4_endpoint="192.88.99.129" + +# For Tayga, we use the lower half of the 6to4 space for the +# 6to4 space as the pool. +tayga_ipv4_net="192.88.99.0/25" + +# This variable can be set to a list of prefixes that get directed to +# Tayga for routing. This is exceptionally useful to redirect v4 +# addresses to v6-only hosts, thus simplifying the v4 compat story +# for v6-only hosts. Instead of dual stack throughout, just route +# v4 addresses and ranges for "pseudo-dual-stack" hosts here. +# This is especially useful to conserve and publish personal v4 public +# allocations. The first and last of any range can be used, thus +# reclaiming much of your limited v4 space utility. +tayga_v4_prefixes="" + +tayga_group="internal group tayga" + +# We claim the address right after the end of the 32-bit slice. +# A different addrss could be taken, but this seemed somewhat safe. +tayga_ipv6_endpoint="64:ff9b::1:0:0" +tayga_ipv6_net="64:ff9b::/96" # The default NAT64 prefix + +tayga_data_dir="/var/db/tayga" + # vim: ft=bash diff --git a/rc.d/generate_tayga b/rc.d/generate_tayga new file mode 100755 index 0000000..af3aeb4 --- /dev/null +++ b/rc.d/generate_tayga @@ -0,0 +1,48 @@ +#!/bin/sh +# +# PROVIDE: generate_tayga +# REQUIRE: netif +# BEFORE: tayga +# KEYWORD: shutdown +# + +. ${RC_ROUTER_HARNESS}/etc/rc.subr + +name='generate_tayga' + +start_cmd='generate_tayga_start' +stop_cmd='generate_tayga_stop' +rcvar='generate_tayga_enable' + +load_rc_config 'generate_tayga' + +generate_tayga_start() +{ + gen_tayga_dir=${rc_router_gen_dir} + tayga_conf=${gen_tayga_dir}/tayga.conf + cat ${rc_router_dir}/templates/tayga.conf \ + | sed \ + -e "s;@TAYGA_DEVICE@;${tayga_device};" \ + -e "s;@TAYGA_IPV4_ADDR@;${tayga_ipv4_addr};" \ + -e "s;@TAYGA_IPV6_ENDPOINT@;${tayga_ipv6_endpoint};" \ + -e "s;@TAYGA_IPV6_NET@;${tayga_ipv6_net};" \ + -e "s;@TAYGA_IPV4_NET@;${tayga_ipv4_net};" \ + -e "s;@TAYGA_DATA_DIR@;${tayga_data_dir};" \ + > ${tayga_conf} + + for mapping in ${tayga_mappings} + do + echo "map ${mapping}" | sed -e 's/->/ /' >> ${tayga_conf} + done +} + +generate_tayga_stop() +{ + true +} + +################ Epilogue + +run_rc_command "$1" + +# vim: ft=bash diff --git a/rc.subr b/rc.subr index 643d474..0a55169 100755 --- a/rc.subr +++ b/rc.subr @@ -650,6 +650,11 @@ load_isp_hints() done } +add_tayga_map() +{ + tayga_mappings="${tayga_mappings} ${1}->${2}" +} + _rc_router_epilogue() { rtsold_flags="${rtsold_flags} ${ipv6_isp_interfaces}" diff --git a/templates/tayga.conf b/templates/tayga.conf new file mode 100644 index 0000000..c632e83 --- /dev/null +++ b/templates/tayga.conf @@ -0,0 +1,14 @@ +tun-device @TAYGA_DEVICE@ + +ipv4-addr @TAYGA_IPV4_ADDR@ + +ipv6-addr @TAYGA_IPV6_ENDPOINT@ + +prefix @TAYGA_IPV6_NET@ + +dynamic-pool @TAYGA_IPV4_NET@ + +data-dir @TAYGA_DATA_DIR@ + + +# Maps (These get set via `tayga_map` command):