#!/bin/bash # # .---. . . # | | | # |--- .--. .-. .-. .-.| .-. .--.--. |.-. .-. .--. .-. # | | (.-' (.-' ( | ( )| | | | )( )| | (.-' # ' ' --' --' -' - -' ' ' -' -' -' ' - --' # # Freedom in the Cloud # # Used to enable or disable batman mesh protocol on wlanX # # License # ======= # # Copyright (C) 2015-2016 Bob Mottram # # This program is free software: you can redistribute it and/or modify # it under the terms of the GNU Affero General Public License as published by # the Free Software Foundation, either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU Affero General Public License for more details. # # You should have received a copy of the GNU Affero General Public License # along with this program. If not, see . PROJECT_NAME='freedombone' COMPLETION_FILE=/root/${PROJECT_NAME}-completed.txt HOTSPOT_PASSPHRASE='mesh' source /usr/share/${PROJECT_NAME}/utils/${PROJECT_NAME}-utils-wifi if [[ $1 == "start" ]]; then # install avahi sed -i "s|#host-name=.*|host-name=$(hostname)|g" /etc/avahi/avahi-daemon.conf sed -i "s|host-name=.*|host-name=$(hostname)|g" /etc/avahi/avahi-daemon.conf sed -i "s|use-ipv4=.*|use-ipv4=yes|g" /etc/avahi/avahi-daemon.conf sed -i "s|use-ipv6=.*|use-ipv6=no|g" /etc/avahi/avahi-daemon.conf sed -i "s|#disallow-other-stacks=.*|disallow-other-stacks=yes|g" /etc/avahi/avahi-daemon.conf sed -i "s|hosts:.*|hosts: files mdns4_minimal dns mdns4 mdns|g" /etc/nsswitch.conf fi # Mesh definition WIFI_SSID='mesh' if [ -f $COMPLETION_FILE ]; then if grep -q "WIFI_SSID:" $COMPLETION_FILE; then WIFI_SSID=$(cat $COMPLETION_FILE | grep "WIFI_SSID:" | awk -F ':' '{print $2}') fi sed -i "s|WIFI_SSID:.*|WIFI_SSID:${WIFI_SSID}|g" $COMPLETION_FILE fi CELLID='any' CHANNEL=2 HOTSPOT_CHANNEL=6 if [ -f $COMPLETION_FILE ]; then if grep -q "Wifi channel:" $COMPLETION_FILE; then CHANNEL=$(cat $COMPLETION_FILE | grep "Wifi channel:" | awk -F ':' '{print $2}') fi sed -i "s|Wifi channel:.*|Wifi channel:${CHANNEL}|g" $COMPLETION_FILE fi ZERONET_PORT=15441 IPFS_PORT=4001 TOX_PORT=33445 TRACKER_PORT=6969 LIBREVAULT_PORT=42345 TAHOELAFS_PORT=50213 # Ethernet bridge definition (bridged to bat0) BRIDGE=br-mesh BRIDGE_HOTSPOT=br-hotspot IFACE= IFACE_SECONDARY= EIFACE=eth0 WLAN_ADAPTORS=$(count_wlan) if [ $WLAN_ADAPTORS -eq 0 ]; then echo $'No wlan adaptors found' exit 0 fi update_wifi_adaptors if [ ! $IFACE ]; then echo $'No wlan adaptor' exit 0 fi if [ -e /etc/default/batctl ]; then . /etc/default/batctl fi function global_rate_limit { if ! grep -q "tcp_challenge_ack_limit" /etc/sysctl.conf; then echo 'net.ipv4.tcp_challenge_ack_limit = 999999999' >> /etc/sysctl.conf else sed -i 's|net.ipv4.tcp_challenge_ack_limit.*|net.ipv4.tcp_challenge_ack_limit = 999999999|g' /etc/sysctl.conf fi sysctl -p -q } function status { batctl o } function stop { if [ -z "$IFACE" ]; then echo 'error: unable to find wifi interface, not enabling batman-adv mesh' return fi if [ "$EIFACE" ]; then brctl delif $BRIDGE bat0 brctl delif $BRIDGE $EIFACE ifconfig $BRIDGE down || true brctl delbr $BRIDGE ifconfig $EIFACE down -promisc fi if [ $IFACE_SECONDARY ]; then systemctl stop hostapd brctl delif $BRIDGE_HOTSPOT bat0 ifconfig $BRIDGE_HOTSPOT down || true brctl delbr $BRIDGE_HOTSPOT fi avahi-autoipd -k $BRIDGE avahi-autoipd -k $IFACE ifconfig bat0 down -promisc batctl if del $IFACE rmmod batman-adv ifconfig $IFACE mtu 1500 ifconfig $IFACE down iwconfig $IFACE mode managed iptables -D INPUT -p tcp --dport $TRACKER_PORT -j ACCEPT iptables -D INPUT -p udp --dport $TRACKER_PORT -j ACCEPT iptables -D INPUT -p tcp --dport 80 -j ACCEPT iptables -D INPUT -p udp --dport 80 -j ACCEPT iptables -D INPUT -p tcp --dport 548 -j ACCEPT iptables -D INPUT -p udp --dport 548 -j ACCEPT iptables -D INPUT -p tcp --dport 5353 -j ACCEPT iptables -D INPUT -p udp --dport 5353 -j ACCEPT iptables -D INPUT -p tcp --dport 5354 -j ACCEPT iptables -D INPUT -p udp --dport 5354 -j ACCEPT iptables -D INPUT -p tcp --dport $ZERONET_PORT -j ACCEPT iptables -D INPUT -p udp --dport $ZERONET_PORT -j ACCEPT iptables -D INPUT -p tcp --dport $IPFS_PORT -j ACCEPT iptables -D INPUT -p udp --dport $IPFS_PORT -j ACCEPT iptables -D INPUT -p tcp --dport $TOX_PORT -j ACCEPT iptables -D INPUT -p udp --dport $TOX_PORT -j ACCEPT iptables -D INPUT -p tcp --dport $LIBREVAULT_PORT -j ACCEPT iptables -D INPUT -p udp --dport $LIBREVAULT_PORT -j ACCEPT iptables -D INPUT -p tcp --dport $TAHOELAFS_PORT -j ACCEPT systemctl restart network-manager } function verify { tempfile="$(mktemp)" batctl o > $tempfile if grep -q "disabled" $tempfile; then echo $'B.A.T.M.A.N. not enabled' rm $tempfile stop exit 726835 fi echo $'B.A.T.M.A.N. is running' rm $tempfile } function assign_peer_address { for i in {1..6}; do number=$RANDOM let "number %= 255" octet=$(echo "obase=16;$number" | bc) if [ ${#octet} -lt 2 ]; then octet="0${octet}" fi if [ $i -gt 1 ]; then echo -n ":" fi echo -n "${octet}" done echo '' } function start { if [ -z "$IFACE" ] ; then echo 'error: unable to find wifi interface, not enabling batman-adv mesh' exit 723657 fi echo "info: enabling batman-adv mesh network $WIFI_SSID on $IFACE" systemctl stop network-manager sleep 5 # remove an avahi service which isn't used if [ -f /etc/avahi/services/udisks.service ]; then sudo rm /etc/avahi/services/udisks.service fi global_rate_limit # Might have to re-enable wifi rfkill unblock $(rfkill list|awk -F: "/phy/ {print $1}") || true ifconfig $IFACE down ifconfig $IFACE mtu 1532 ifconfig $IFACE hw ether $(assign_peer_address) iwconfig $IFACE enc off iwconfig $IFACE mode ad-hoc essid $WIFI_SSID channel $CHANNEL sleep 1 iwconfig $IFACE ap $CELLID modprobe batman-adv batctl if add $IFACE ifconfig $IFACE up avahi-autoipd --force-bind --daemonize --wait $IFACE ifconfig bat0 up promisc #Use persistent HWAddr ether_new=$(ifconfig eth0 | grep HWaddr | sed -e "s/.*HWaddr //") if [ ! -f /var/lib/mesh-node/bat0 ]; then mkdir /var/lib/mesh-node echo "${ether_new}" > /var/lib/mesh-node/bat0 else ether=$(cat /var/lib/mesh-node/bat0) ifconfig bat0 hw ether ${ether} fi if [ "$EIFACE" ] ; then brctl addbr $BRIDGE brctl addif $BRIDGE bat0 brctl addif $BRIDGE $EIFACE ifconfig bat0 0.0.0.0 ifconfig $EIFACE 0.0.0.0 ifconfig $EIFACE up promisc ifconfig $BRIDGE up avahi-autoipd --force-bind --daemonize --wait $BRIDGE fi if [ $IFACE_SECONDARY ]; then if [[ $IFACE != $IFACE_SECONDARY ]]; then if [ -d /etc/hostapd ]; then # bridge between mesh and wifi hotspot for mobile HOTSPOT_NAME=$"${WIFI_SSID}-hotspot" ifconfig $IFACE_SECONDARY down ifconfig $IFACE_SECONDARY mtu 1500 ifconfig $IFACE_SECONDARY hw ether $(assign_peer_address) iwconfig $IFACE_SECONDARY enc open iwconfig $IFACE_SECONDARY mode managed essid $HOTSPOT_NAME channel ${HOTSPOT_CHANNEL} iwconfig $IFACE_SECONDARY ap $CELLID brctl addbr $BRIDGE_HOTSPOT brctl addif $BRIDGE_HOTSPOT bat0 brctl addif $BRIDGE_HOTSPOT $IFACE_SECONDARY ifconfig bat0 0.0.0.0 ifconfig $IFACE_SECONDARY 0.0.0.0 sed -i 's|#DAEMON_CONF=.*|DAEMON_CONF="/etc/hostapd/hostapd.conf"|g' /etc/default/hostapd echo "interface=${IFACE_SECONDARY}" > /etc/hostapd/hostapd.conf echo "bridge=${BRIDGE_HOTSPOT}" >> /etc/hostapd/hostapd.conf echo 'driver=nl80211' >> /etc/hostapd/hostapd.conf echo "country_code=UK" >> /etc/hostapd/hostapd.conf echo "ssid=$HOTSPOT_NAME" >> /etc/hostapd/hostapd.conf echo 'hw_mode=g' >> /etc/hostapd/hostapd.conf echo "channel=${HOTSPOT_CHANNEL}" >> /etc/hostapd/hostapd.conf echo 'wpa=2' >> /etc/hostapd/hostapd.conf echo "wpa_passphrase=$HOTSPOT_PASSPHRASE" >> /etc/hostapd/hostapd.conf echo 'wpa_key_mgmt=WPA-PSK' >> /etc/hostapd/hostapd.conf echo 'wpa_pairwise=TKIP' >> /etc/hostapd/hostapd.conf echo 'rsn_pairwise=CCMP' >> /etc/hostapd/hostapd.conf echo 'auth_algs=1' >> /etc/hostapd/hostapd.conf echo 'macaddr_acl=0' >> /etc/hostapd/hostapd.conf ifconfig $BRIDGE_HOTSPOT up avahi-autoipd --force-bind --daemonize --wait $BRIDGE_HOTSPOT ifconfig $IFACE_SECONDARY up promisc #ifconfig $IFACE_SECONDARY auto-dhcp start systemctl start hostapd fi fi fi iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT iptables -A OUTPUT -p icmp --icmp-type echo-reply -j ACCEPT iptables -A INPUT -p tcp --dport $TRACKER_PORT -j ACCEPT iptables -A INPUT -p udp --dport $TRACKER_PORT -j ACCEPT iptables -A INPUT -p tcp --dport 80 -j ACCEPT iptables -A INPUT -p udp --dport 80 -j ACCEPT iptables -A INPUT -p tcp --dport 548 -j ACCEPT iptables -A INPUT -p udp --dport 548 -j ACCEPT iptables -A INPUT -p tcp --dport 5353 -j ACCEPT iptables -A INPUT -p udp --dport 5353 -j ACCEPT iptables -A INPUT -p tcp --dport 5354 -j ACCEPT iptables -A INPUT -p udp --dport 5354 -j ACCEPT iptables -A INPUT -p tcp --dport $ZERONET_PORT -j ACCEPT iptables -A INPUT -p udp --dport $ZERONET_PORT -j ACCEPT iptables -A INPUT -p tcp --dport $IPFS_PORT -j ACCEPT iptables -A INPUT -p tcp --dport $TOX_PORT -j ACCEPT iptables -A INPUT -p udp --dport $TOX_PORT -j ACCEPT iptables -A INPUT -p tcp --dport $LIBREVAULT_PORT -j ACCEPT iptables -A INPUT -p udp --dport $LIBREVAULT_PORT -j ACCEPT iptables -A INPUT -p tcp --dport $TAHOELAFS_PORT -j ACCEPT systemctl restart avahi-daemon verify } function monitor { if [ -z "$IFACE" ] ; then echo 'error: unable to find wifi interface, not enabling batman-adv mesh' exit 723657 fi stop echo "info: monitoring mesh network $WIFI_SSID on $IFACE" systemctl stop network-manager sleep 5 global_rate_limit # Might have to re-enable wifi rfkill unblock $(rfkill list|awk -F: "/phy/ {print $1}") || true ifconfig $IFACE down ifconfig $IFACE mtu 1532 ifconfig $IFACE hw ether $(assign_peer_address) iwconfig $IFACE enc off iwconfig $IFACE mode monitor channel $CHANNEL sleep 1 iwconfig $IFACE ap $CELLID modprobe batman-adv batctl if add $IFACE ifconfig $IFACE up horst -i $IFACE start } if ! grep -q "$IFACE" /proc/net/dev; then echo 'Interface $IFACE was not found' stop exit 1 fi case "$1" in start|stop|status|monitor) $1 ;; restart) stop sleep 10 start ;; ping) batctl ping $2 ;; data) watch -n1 "batctl s | grep mgmt | grep bytes" ;; ls|list) avahi-browse -atl ;; *) echo "error: invalid parameter $1" echo 'usage: $0 {start|stop|restart|status|ping|ls|list}' exit 2 ;; esac exit 0