711cf75f796b7f06c8ae9eba9611f224c1e01c54
[people/stevee/network.git] / src / network
1 #!/bin/bash
2 ###############################################################################
3 #                                                                             #
4 # IPFire.org - A linux based firewall                                         #
5 # Copyright (C) 2010  Michael Tremer & Christian Schmidt                      #
6 #                                                                             #
7 # This program is free software: you can redistribute it and/or modify        #
8 # it under the terms of the GNU General Public License as published by        #
9 # the Free Software Foundation, either version 3 of the License, or           #
10 # (at your option) any later version.                                         #
11 #                                                                             #
12 # This program is distributed in the hope that it will be useful,             #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of              #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the               #
15 # GNU General Public License for more details.                                #
16 #                                                                             #
17 # You should have received a copy of the GNU General Public License           #
18 # along with this program.  If not, see <http://www.gnu.org/licenses/>.       #
19 #                                                                             #
20 ###############################################################################
21
22 # Parse the command line
23 while [ $# -gt 0 ]; do
24         case "${1}" in
25                 -d|--debug)
26                         DEBUG=1
27                         ;;
28                 *)
29                         action=${1}
30                         ;;
31         esac
32         shift
33         [ -n "${action}" ] && break
34 done
35
36 . /usr/lib/network/functions
37
38 # Read network settings
39 network_settings_read
40
41 cli_settings() {
42         if cli_help_requested $@; then
43                 cli_show_man network-settings
44                 exit ${EXIT_OK}
45         fi
46
47         if [ -n "${1}" ]; then
48                 network_settings_set $@
49                 network_settings_write
50         else
51                 network_settings_print
52         fi
53 }
54
55 cli_device() {
56         if cli_help_requested $@; then
57                 cli_show_man network-device
58                 exit ${EXIT_OK}
59         fi
60
61         local action="${1}"
62         shift
63
64         case "${action}" in
65                 list)
66                         cli_device_list $@
67                         ;;
68                 *)
69                         local device="${action}"
70                         action="${1}"
71                         shift
72
73                         if ! isset device; then
74                                 cli_show_man network-device
75                                 return ${EXIT_ERROR}
76                         fi
77
78                         assert device_exists ${device}
79
80                         case "${action}" in
81                                 discover)
82                                         cli_device_discover ${device} $@
83                                         ;;
84                                 identify)
85                                         device_identify "${device}" $@
86                                         ;;
87                                 monitor)
88                                         cli_device_monitor "${device}" $@
89                                         ;;
90                                 status)
91                                         cli_device_status ${device}
92                                         ;;
93                                 unlock)
94                                         cli_device_serial_unlock ${device} $@
95                                         ;;
96                                 ussd)
97                                         cli_device_send_ussd_command "${device}" $@
98                                         ;;
99                                 *)
100                                         cli_show_man network-device
101                                         ;;
102                         esac
103                         ;;
104         esac
105
106         return ${EXIT_OK}
107 }
108
109 cli_device_status() {
110         local device="${1}"
111         assert isset device
112
113         # Disable debugging output here.
114         local log_disable_stdout=${LOG_DISABLE_STDOUT}
115         LOG_DISABLE_STDOUT="true"
116
117         # Save the type of the device for later.
118         local type=$(device_get_type ${device})
119
120         cli_headline 1 "Device status: ${device}"
121         cli_print_fmt1 1 "Name"         "${device}"
122
123         # Handle special devices
124         case "${type}" in
125                 phy)
126                         cli_device_status_phy "${device}"
127                         return $?
128                         ;;
129                 serial)
130                         cli_device_status_serial "${device}"
131                         return $?
132                         ;;
133         esac
134
135         # Print the device status.
136         device_is_up ${device} &>/dev/null
137         local status=$?
138
139         case "${status}" in
140                 ${EXIT_TRUE})
141                         status="${CLR_GREEN_B}UP${CLR_RESET}"
142                         ;;
143                 ${EXIT_FALSE})
144                         status="${CLR_RED_B}DOWN${CLR_RESET}"
145                         ;;
146         esac
147
148         cli_print_fmt1 1 "Status"       "${status}"
149         cli_print_fmt1 1 "Type"         "${type}"
150
151         # Ethernet-compatible?
152         device_is_ethernet_compatible "${device}" &>/dev/null
153         cli_print_fmt1 1 "Ethernet-compatible" "$(cli_print_bool $?)"
154
155         cli_print_fmt1 1 "Address"      "$(device_get_address ${device})"
156         cli_space
157
158         # Print the link speed for ethernet devices.
159         if device_is_up ${device} &>/dev/null; then
160                 local link="$(device_get_link_string "${device}")"
161                 if isset link; then
162                         cli_print_fmt1 1 "Link" "${link}"
163                 fi
164         fi
165
166         cli_print_fmt1 1 "MTU"          "$(device_get_mtu ${device})"
167         cli_space
168
169         # Print device statistics.
170         cli_device_stats 2 ${device}
171
172         # Print some more information.
173         device_has_carrier ${device} &>/dev/null
174         cli_print_fmt1 1 "Has carrier?" "$(cli_print_bool $?)"
175
176         device_is_promisc ${device} &>/dev/null
177         cli_print_fmt1 1 "Promisc"      "$(cli_print_bool $?)"
178
179         # Supports multiqueue?
180         if device_supports_multiqueue ${device}; then
181                 cli_print_fmt1 1 "Multiqueue" "Supported"
182         fi
183         cli_space
184
185         cli_device_show_queues 2 ${device}
186
187         # Print all vlan devices.
188         local vlans=$(device_get_vlans ${device})
189         if [ -n "${vlans}" ]; then
190                 cli_headline 2 "VLAN devices"
191
192                 local vlan
193                 for vlan in ${vlans}; do
194                         cli_print 2 "* %-6s - %s" "${vlan}" "$(device_get_address ${vlan})"
195                 done
196                 cli_space
197         fi
198
199         case "${type}" in
200                 wireless*)
201                         local phy="$(device_get_phy "${device}")"
202                         if isset phy; then
203                                 cli_headline 2 "PHY"
204                                 cli_print_fmt1 2 "Name" "${phy}"
205                                 cli_print_fmt1 2 "Address" "$(phy_get_address "${phy}")"
206                                 cli_space
207                         fi
208                         ;;
209         esac
210
211         # Reset the logging level.
212         LOG_DISABLE_STDOUT=${log_disable_stdout}
213 }
214
215 cli_device_status_serial() {
216         local device=${1}
217         assert device_is_serial ${device}
218
219         serial_is_locked ${device} &>/dev/null
220         local locked=$?
221
222         cli_print_fmt1 1 "Locked" "$(cli_print_bool ${locked})"
223         cli_space
224
225         # Cannot go on when the device is locked.
226         [ ${locked} -eq ${EXIT_TRUE} ] && return ${EXIT_OK}
227
228         cli_print_fmt1 1 "Manufacturer" \
229                 "$(modem_get_manufacturer ${device})"
230         cli_print_fmt1 1 "Model" \
231                 "$(modem_get_model ${device})"
232         cli_print_fmt1 1 "Software version" \
233                 "$(modem_get_software_version ${device})"
234
235         # Mobile
236         if modem_is_mobile "${device}"; then
237                 cli_print_fmt1 1 "IMEI" \
238                         "$(modem_get_device_imei ${device})"
239         fi
240         cli_space
241
242         if modem_is_mobile "${device}"; then
243                 modem_mobile_network_status "${device}" 2
244                 cli_space
245         fi
246 }
247
248 cli_device_status_phy() {
249         local phy="${1}"
250         assert phy_exists "${phy}"
251
252         local address="$(phy_get_address "${phy}")"
253         cli_print_fmt1 1 "Address" "${address}"
254         cli_space
255
256         local devices="$(phy_get_devices "${phy}")"
257         if isset devices; then
258                 cli_headline 2 "Soft interfaces"
259
260                 local device
261                 for device in ${devices}; do
262                         cli_print 2 "* %s" "${device}"
263                 done
264                 cli_space
265         fi
266
267         return ${EXIT_OK}
268 }
269
270 cli_device_discover() {
271         local device=${1}
272         shift
273
274         # This can only be executed for ethernet (or compatible) devices
275         if ! device_is_ethernet_compatible "${device}"; then
276                 return ${EXIT_OK}
277         fi
278
279         local raw
280
281         while [ $# -gt 0 ]; do
282                 case "${1}" in
283                         --raw)
284                                 raw=1
285                                 ;;
286                 esac
287                 shift
288         done
289
290         local up
291         device_is_up ${device} && up=1
292         device_set_up ${device}
293
294         enabled raw || echo "${device}"
295
296         local hook
297         local out
298         local ret
299         for hook in $(hook_zone_get_all); do
300                 out=$(hook_zone_exec ${hook} discover ${device})
301                 ret=$?
302
303                 [ ${ret} -eq ${DISCOVER_NOT_SUPPORTED} ] && continue
304
305                 if enabled raw; then
306                         case "${ret}" in
307                                 ${DISCOVER_OK})
308                                         echo "${hook}: OK"
309                                         local line
310                                         while read line; do
311                                                 echo "${hook}: ${line}"
312                                         done <<<"${out}"
313                                         ;;
314
315                                 ${DISCOVER_ERROR})
316                                         echo "${hook}: FAILED"
317                                         ;;
318                         esac
319                 else
320                         case "${ret}" in
321                                 ${DISCOVER_OK})
322                                         echo "  ${hook} was successful."
323                                         local line
324                                         while read line; do
325                                                 echo "  ${line}"
326                                         done <<<"${out}"
327                                         ;;
328
329                                 ${DISCOVER_ERROR})
330                                         echo "  ${hook} failed."
331                                         ;;
332                         esac
333                 fi
334         done
335
336         echo # New line
337
338         [ "${up}" = "1" ] || device_set_down ${device}
339 }
340
341 cli_device_serial_unlock() {
342         if cli_help_requested $@; then
343                 cli_show_man network-device
344                 exit ${EXIT_OK}
345         fi
346
347         local device=${1}
348         assert isset device
349
350         if ! device_is_serial ${device}; then
351                 error "${device} is not a serial device."
352                 error "Unlocking is only supported for serial devices."
353                 exit ${EXIT_ERROR}
354         fi
355
356         # Read the current state of the SIM card.
357         modem_sim_status ${device} &>/dev/null
358         local sim_status_code=$?
359
360         # If the SIM card is already unlocked, we don't need to do anything.
361         if [ ${sim_status_code} -eq ${EXIT_SIM_READY} ]; then
362                 print "The SIM card is already unlocked."
363                 exit ${EXIT_OK}
364
365         # If the SIM card is in an unknown state, we cannot do anything.
366         elif [ ${sim_status_code} -eq ${EXIT_SIM_UNKNOWN} ]; then
367                 error "The SIM card is in an unknown state."
368                 exit ${EXIT_ERROR}
369         fi
370
371         # Ask for the code.
372         local code=${2}
373         local require_new_pin="false"
374         local new_pin
375
376         while ! isinteger code; do
377                 local message
378                 case "${sim_status_code}" in
379                         ${EXIT_SIM_PIN})
380                                 message="Please enter PIN:"
381                                 ;;
382                         ${EXIT_SIM_PUK})
383                                 message="Please enter PUK:"
384                                 require_new_pin="true"
385                                 ;;
386                 esac
387                 assert isset message
388
389                 echo -n "${message} "
390                 read -s code
391                 echo # Print newline.
392
393                 if enabled require_new_pin; then
394                         local i new_pin2
395                         for i in 0 1; do
396                                 case "${i}" in
397                                         0)
398                                                 message="Please enter a new PIN code:"
399                                                 ;;
400                                         1)
401                                                 message="Please confirm the new PIN code:"
402                                                 ;;
403                                 esac
404
405                                 echo -n "${message} "
406                                 read -s new_pin2
407                                 echo # Print newline.
408
409                                 if [ -n "${new_pin}" ]; then
410                                         if [ "${new_pin}" != "${new_pin2}" ]; then
411                                                 error "The entered PIN codes did not match."
412                                                 exit ${EXIT_ERROR}
413                                         fi
414                                 else
415                                         new_pin=${new_pin2}
416                                 fi
417                         done
418                 fi
419         done
420
421         # Trying to unlock the SIM card.
422         modem_sim_unlock ${device} ${code} ${new_pin}
423
424         exit $?
425 }
426
427 cli_device_send_ussd_command() {
428         local device="${1}"
429         assert isset device
430         shift
431
432         local command
433         local timeout
434
435         while [ $# -gt 0 ]; do
436                 case "${1}" in
437                         --timeout=*)
438                                 timeout="$(cli_get_val "${1}")"
439                                 ;;
440                         *)
441                                 if isset command; then
442                                         warning "Unrecognized argument: ${1}"
443                                 else
444                                         command="${1}"
445                                 fi
446                                 ;;
447                 esac
448                 shift
449         done
450
451         assert device_is_serial "${device}"
452
453         local args
454         if isset timeout; then
455                 args="${args} --timeout=${timeout}"
456         fi
457
458         modem_ussd_send_command "${device}" "${command}" ${args}
459         exit $?
460 }
461
462 cli_device_monitor() {
463         local device="${1}"
464         assert isset device
465
466         if ! device_is_wireless "${device}"; then
467                 error "This action only works with wireless devices. Exiting."
468                 exit ${EXIT_ERROR}
469         fi
470
471         wireless_monitor "${device}"
472         exit $?
473 }
474
475 cli_device_list() {
476         local device
477         for device in $(device_list); do
478                 cli_device_status "${device}"
479         done
480
481         exit ${EXIT_OK}
482 }
483
484 cli_hostname() {
485         if cli_help_requested $@; then
486                 cli_show_man network
487                 exit ${EXIT_OK}
488         fi
489
490         local hostname=${1}
491
492         if [ -n "${hostname}" ]; then
493                 config_hostname ${hostname}
494                 log INFO "Hostname was set to '${hostname}'."
495                 log INFO "Changes do only take affect after reboot."
496                 exit ${EXIT_OK}
497         fi
498
499         echo "$(config_hostname)"
500         exit ${EXIT_OK}
501 }
502
503 cli_port() {
504         if cli_help_requested $@; then
505                 cli_show_man network-port
506                 exit ${EXIT_OK}
507         fi
508
509         local action
510         local port
511
512         if port_exists ${1}; then
513                 port=${1}
514                 action=${2}
515                 shift 2
516
517                 case "${action}" in
518                         edit|create|remove|up|down|status|identify)
519                                 port_${action} "${port}" $@
520                                 ;;
521                         color)
522                                 color_cli "port" "${port}" $@
523                                 ;;
524                         description)
525                                 description_cli "port" "${port}" $@
526                                 ;;
527                         *)
528                                 error "Unrecognized argument: ${action}"
529                                 exit ${EXIT_ERROR}
530                                 ;;
531                 esac
532         else
533                 action=${1}
534                 shift
535
536                 case "${action}" in
537                         new|destroy)
538                                 port_${action} $@
539                                 ;;
540                         *)
541                                 error "Unrecognized argument: ${action}"
542                                 exit ${EXIT_ERROR}
543                                 ;;
544                 esac
545         fi
546 }
547
548 cli_zone() {
549         if cli_help_requested $@; then
550                 cli_show_man network-zone
551                 exit ${EXIT_OK}
552         fi
553
554         local action
555         local zone
556
557         if zone_exists ${1}; then
558                 zone=${1}
559                 action=${2}
560                 shift 2
561
562                 # Action aliases
563                 case "${action}" in
564                         start|reload)
565                                 action="up"
566                                 ;;
567                         stop)
568                                 action="down"
569                                 ;;
570                         show)
571                                 action="status"
572                                 ;;
573                 esac
574
575                 case "${action}" in
576                         port)
577                                 cli_zone_port "${zone}" $@
578                                 ;;
579                         rename)
580                                 cli_zone_rename "${zone}" $@
581                                 ;;
582                         config|disable|down|edit|enable|identify|status|up)
583                                 zone_${action} ${zone} $@
584                                 ;;
585                         color)
586                                 color_cli "zone" "${zone}" $@
587                                 ;;
588                         description)
589                                 description_cli "zone" ${zone} $@
590                                 ;;
591                         *)
592                                 error "Unrecognized argument: ${action}"
593                                 cli_show_man network-zone
594                                 exit ${EXIT_ERROR}
595                                 ;;
596                 esac
597         else
598                 action=${1}
599                 shift
600
601                 case "${action}" in
602                         new)
603                                 cli_zone_new $@
604                                 ;;
605                         destroy)
606                                 cli_zone_destroy $@
607                                 ;;
608                         ""|*)
609                                 if [ -n "${action}" ]; then
610                                         error "Unrecognized argument: '${action}'"
611                                         echo
612                                 fi
613
614                                 cli_show_man network-zone
615                                 exit ${EXIT_ERROR}
616                                 ;;
617                 esac
618         fi
619 }
620
621 cli_zone_new() {
622         if cli_help_requested $@ || [ $# -lt 2 ]; then
623                 cli_show_man network-zone-new
624                 exit ${EXIT_OK}
625         fi
626
627         zone_new $@
628 }
629
630 # Removes a zone either immediately, if it is currently down,
631 # or adds a tag that the removal will be done when the zone
632 # is brought down the next time.
633 cli_zone_destroy() {
634         if cli_help_requested $@; then
635                 cli_show_man network-zone
636                 exit ${EXIT_OK}
637         fi
638
639         local zone="${1}"
640         assert zone_exists "${zone}"
641
642         if zone_is_up ${zone}; then
643                 echo "Zone '${zone}' is up and will be removed when it goes down the next time."
644                 zone_destroy "${zone}"
645         else
646                 echo "Removing zone '${zone}' now..."
647                 zone_destroy_now "${zone}"
648         fi
649
650         exit ${EXIT_OK}
651 }
652
653 cli_zone_port() {
654         if cli_help_requested $@; then
655                 cli_show_man network-zone-port
656                 exit ${EXIT_OK}
657         fi
658
659         local zone="${1}"
660         assert zone_exists "${zone}"
661
662         if port_exists "${2}"; then
663                 local port="${2}"
664                 local action="${3}"
665                 shift 3
666
667                 case "${action}" in
668                         edit)
669                                 zone_port_edit "${zone}" "${port}" $@
670                                 ;;
671                         *)
672                                 error "Unrecognised argument: ${action}"
673                                 exit ${EXIT_ERROR}
674                                 ;;
675                 esac
676         else
677                 local action="${2}"
678                 shift 2
679
680                 case "${action}" in
681                         attach)
682                                 zone_port_attach "${zone}" $@
683                                 ;;
684                         detach)
685                                 zone_port_detach "${zone}" $@
686                                 ;;
687                         *)
688                                 error "Unrecognised argument: ${action}"
689                                 exit ${EXIT_ERROR}
690                                 ;;
691                 esac
692         fi
693
694         exit ${EXIT_OK}
695 }
696
697 cli_zone_rename() {
698         if cli_help_requested $@; then
699                 cli_show_man network-zone
700                 exit ${EXIT_OK}
701         fi
702
703         local zone="${1}"
704         local name="${2}"
705         shift 2
706
707         if ! isset name; then
708                 error "You need to pass a new name"
709                 exit ${EXIT_ERROR}
710         fi
711
712         if ! zone_name_is_valid "${name}"; then
713                 error "Invalid new zone name: ${name}"
714                 exit ${EXIT_ERROR}
715         fi
716
717         # Check if the zone exists
718         if ! zone_exists "${zone}"; then
719                 error "Zone ${zone} does not exist"
720                 exit ${EXIT_ERROR}
721         fi
722
723         # Check if a zone with the new name already exists
724         if zone_exists "${name}"; then
725                 error "Zone ${name} already exists"
726                 exit ${EXIT_ERROR}
727         fi
728
729         # Rename
730         if ! zone_rename "${zone}" "${name}"; then
731                 error "Could not rename zone ${zone} to ${name}"
732                 exit ${EXIT_ERROR}
733         fi
734
735         exit ${EXIT_OK}
736 }
737
738 cli_list_hooks() {
739         local type=${1}
740         shift
741
742         if cli_help_requested $@; then
743                 cli_show_man network-zone
744                 exit ${EXIT_OK}
745         fi
746
747         local hook_dir=$(hook_dir ${type})
748         local hook
749
750         for hook in ${hook_dir}/*; do
751                 hook=$(basename ${hook})
752                 if hook_exists ${type} ${hook}; then
753                         echo "${hook}"
754                 fi
755         done | sort -u
756 }
757
758 cli_dhcpd() {
759         local proto=${1}
760         shift
761
762         if cli_help_requested $@; then
763                 cli_show_man network-dhcp
764                 exit ${EXIT_OK}
765         fi
766
767         local action=${1}
768         shift
769
770         case "${action}" in
771                 edit)
772                         dhcpd_edit ${proto} $@
773                         ;;
774                 start)
775                         dhcpd_start ${proto}
776
777                         # Make this permanent
778                         dhcpd_enable ${proto}
779                         ;;
780                 stop)
781                         dhcpd_stop ${proto}
782
783                         # Make this permanent
784                         dhcpd_disable ${proto}
785                         ;;
786                 restart|reload)
787                         dhcpd_reload ${proto}
788                         ;;
789                 subnet)
790                         cli_dhcpd_subnet ${proto} $@
791                         ;;
792                 show|"")
793                         cli_dhcpd_show ${proto} $@
794                         ;;
795                 *)
796                         error "Unrecognized action: ${action}"
797                         cli_run_help network dhcpvN
798
799                         exit ${EXIT_ERROR}
800                         ;;
801         esac
802
803         exit ${EXIT_OK}
804 }
805
806 cli_dhcpd_show() {
807         local proto=${1}
808         assert isset proto
809
810         local settings=$(dhcpd_settings ${proto})
811         assert isset settings
812
813         local ${settings}
814         dhcpd_global_settings_read ${proto}
815
816         cli_headline 1 "Dynamic Host Configuration Protocol Daemon for ${proto/ip/IP}"
817
818         case "${proto}" in
819                 ipv6)
820                         cli_headline 2 "Lease times"
821                         if isinteger VALID_LIFETIME; then
822                                 cli_print_fmt1 2 "Valid lifetime" "$(format_time ${VALID_LIFETIME})"
823                         fi
824
825                         if isinteger PREFERRED_LIFETIME; then
826                                 cli_print_fmt1 2 "Preferred lifetime" "$(format_time ${PREFERRED_LIFETIME})"
827                         fi
828
829                         cli_space
830                         ;;
831                 ipv4)
832                         cli_print_fmt1 1 "Authoritative" $(cli_print_enabled AUTHORITATIVE)
833                         cli_space
834
835                         cli_headline 2 "Lease times"
836                         cli_print_fmt1 2 "Default lease time" "$(format_time ${DEFAULT_LEASE_TIME})"
837                         cli_print_fmt1 2 "Max. lease time" "$(format_time ${MAX_LEASE_TIME})"
838
839                         if isset MIN_LEASE_TIME; then
840                                 cli_print_fmt1 2 "Min. lease time" "$(format_time ${MIN_LEASE_TIME})"
841                         fi
842
843                         cli_space
844                         ;;
845         esac
846
847         # Read the options.
848         local -A options
849         dhcpd_global_options_read ${proto}
850
851         # Print the options if any.
852         if [ ${#options[*]} -gt 0 ]; then
853                 cli_headline 2 "Options"
854
855                 local option
856                 for option in $(dhcpd_options ${proto}); do
857                         [ -n "${options[${option}]}" ] || continue
858
859                         cli_print_fmt1 2 \
860                                 "${option}" "${options[${option}]}"
861                 done
862                 cli_space
863         fi
864
865         # Subnets.
866         local subnets=$(dhcpd_subnet_list ${proto})
867         if [ -n "${subnets}" ]; then
868                 cli_headline 2 "Subnets"
869                 local subnet
870                 for subnet in ${subnets}; do
871                         cli_dhcpd_subnet_show ${proto} ${subnet} 2
872                 done
873         fi
874 }
875
876 cli_dhcpd_subnet() {
877         assert [ $# -ge 1 ]
878
879         local proto=${1}
880         shift
881
882         if cli_help_requested $@; then
883                 cli_show_man network-dhcp-subnet
884                 exit ${EXIT_OK}
885         fi
886
887         local action=${1}
888         shift
889
890         case "${action}" in
891                 new)
892                         dhcpd_subnet_new ${proto} $@
893                         ;;
894                 remove)
895                         dhcpd_subnet_remove ${proto} $@
896                         ;;
897                 *:*/*|*.*.*.*/*)
898                         local subnet=${action}
899
900                         if ! dhcpd_subnet_exists ${proto} ${subnet}; then
901                                 error "Subnet ${subnet} does not exist"
902                                 return ${EXIT_ERROR}
903                         fi
904
905                         # Update the action.
906                         action=${1}
907                         shift
908
909                         case "${action}" in
910                                 edit)
911                                         dhcpd_subnet_edit ${proto} ${subnet} $@
912                                         local ret=$?
913
914                                         if [ ${ret} -eq ${EXIT_OK} ]; then
915                                                 dhcpd_reload ${proto}
916                                         fi
917                                         exit ${ret}
918                                         ;;
919                                 range)
920                                         cli_dhcpd_subnet_range ${proto} ${subnet} $@
921                                         exit $?
922                                         ;;
923                                 show)
924                                         cli_dhcpd_subnet_show ${proto} ${subnet} $@
925                                         exit $?
926                                         ;;
927                                 options)
928                                         cli_dhcpd_subnet_options ${proto} ${subnet} $@
929                                         exit $?
930                                         ;;
931                                 *)
932                                         error "Unrecognized action: ${action}"
933                                         cli_run_help network dhcpvN subnet
934                                         exit ${EXIT_ERROR}
935                                         ;;
936                         esac
937                         ;;
938                 show)
939                         local subnet
940                         for subnet in $(dhcpd_subnet_list ${proto}); do
941                                 cli_dhcpd_subnet_show ${proto} ${subnet}
942                         done
943                         ;;
944                 *)
945                         error "Unrecognized action: ${action}"
946                         cli_run_help network dhcpvN subnet
947
948                         exit ${EXIT_ERROR}
949                         ;;
950         esac
951
952         exit ${EXIT_OK}
953 }
954
955 cli_dhcpd_subnet_range() {
956         assert [ $# -ge 2 ]
957
958         local proto=${1}
959         local subnet=${2}
960         local action=${3}
961         shift 3
962
963         case "${action}" in
964                 new)
965                         dhcpd_subnet_range_new ${proto} ${subnet} $@ || exit ${EXIT_ERROR}
966                         ;;
967                 remove)
968                         dhcpd_subnet_range_remove ${proto} ${subnet} $@ || exit ${EXIT_ERROR}
969                         ;;
970                 *)
971                         error "Unrecognized action: ${action}"
972                         cli_run_help network dhcpvN subnet range
973                         exit ${EXIT_ERROR}
974                         ;;
975         esac
976
977         dhcpd_reload ${proto}
978         return ${EXIT_OK}
979 }
980
981 cli_dhcpd_subnet_show() {
982         assert [ $# -ge 2 -a $# -le 3 ]
983
984         local proto=${1}
985         local subnet=${2}
986
987         local level=${3}
988         isset level || level=0
989
990         local $(dhcpd_subnet_settings ${proto})
991
992         # Read in configuration settings.
993         dhcpd_subnet_read ${proto} ${subnet}
994
995         cli_headline $(( ${level} + 1 )) "DHCP Subnet Declaration"
996         cli_print_fmt1 $(( ${level} + 1 )) \
997                 "Subnet" "${ADDRESS}/${PREFIX}"
998         cli_space
999
1000         # Read the options.
1001         local -A options
1002         dhcpd_subnet_options_read "${proto}" "${subnet}"
1003
1004         # Print the options if any.
1005         if [ ${#options[*]} -gt 0 ]; then
1006                 cli_headline $(( ${level} + 2 )) "Options"
1007
1008                 local option
1009                 for option in $(dhcpd_subnet_options_list ${proto}); do
1010                         [ -n "${options[${option}]}" ] || continue
1011
1012                         cli_print_fmt1 $(( ${level} + 2 )) \
1013                                 "${option}" "${options[${option}]}"
1014                 done
1015                 cli_space
1016         fi
1017
1018         # Ranges.
1019         cli_headline $(( ${level} + 2 )) "Ranges"
1020
1021         local ranges=$(dhcpd_subnet_range_list ${proto} ${subnet})
1022         if isset ranges; then
1023                 local range $(dhcpd_subnet_range_settings ${proto})
1024                 for range in ${ranges}; do
1025                         dhcpd_subnet_range_read ${proto} ${subnet} ${range}
1026
1027                         cli_print $(( ${level} + 2 )) "%s - %s" ${START} ${END}
1028                 done
1029         else
1030                 cli_print $(( ${level} + 2 )) "No ranges have been defined."
1031         fi
1032
1033         cli_space
1034 }
1035
1036 cli_dhcpd_subnet_options() {
1037         assert [ $# -ge 2 ]
1038
1039         local proto=${1}
1040         local subnet=${2}
1041
1042         local key val
1043         while [ $# -gt 0 ]; do
1044                 case "${1}" in
1045                         *=*)
1046                                 key=$(cli_get_key ${1})
1047                                 val=$(cli_get_val ${1})
1048
1049                                 dhcpd_subnet_option_set ${proto} ${subnet} ${key} ${val}
1050                 esac
1051                 shift
1052         done
1053 }
1054
1055 cli_start() {
1056         if cli_help_requested $@; then
1057                 cli_show_man network
1058                 exit ${EXIT_OK}
1059         fi
1060
1061         local zones=$(zones_get $@)
1062
1063         local zone
1064         for zone in ${zones}; do
1065                 zone_start ${zone} &
1066         done
1067
1068         wait # until everything is settled
1069 }
1070
1071 cli_stop() {
1072         if cli_help_requested $@; then
1073                 cli_show_man network
1074                 exit ${EXIT_OK}
1075         fi
1076
1077         local zones=$(zones_get $@)
1078
1079         local zone
1080         for zone in ${zones}; do
1081                 zone_stop ${zone} &
1082         done
1083
1084         wait # until everything is settled
1085 }
1086
1087 cli_restart() {
1088         if cli_help_requested $@; then
1089                 cli_show_man network
1090                 exit ${EXIT_OK}
1091         fi
1092
1093         cli_stop $@
1094
1095         # Give the system some time to calm down
1096         sleep ${TIMEOUT_RESTART}
1097
1098         cli_start $@
1099 }
1100
1101 cli_status() {
1102         if cli_help_requested $@; then
1103                 cli_show_man network
1104                 exit ${EXIT_OK}
1105         fi
1106
1107         # When dumping status information, the debug
1108         # mode clutters the console which is not what we want.
1109         # Logging on the console is disabled for a short time.
1110         local log_disable_stdout=${LOG_DISABLE_STDOUT}
1111         LOG_DISABLE_STDOUT="true"
1112
1113         local zones=$(zones_get $@)
1114
1115         local zone
1116         for zone in ${zones}; do
1117                 zone_status ${zone}
1118         done
1119
1120         # Reset logging.
1121         LOG_DISABLE_STDOUT=${log_disable_stdout}
1122 }
1123
1124 cli_reset() {
1125         if cli_help_requested $@; then
1126                 cli_show_man network
1127                 exit ${EXIT_OK}
1128         fi
1129
1130         warning_log "Will reset the whole network configuration!!!"
1131         # Force mode is disabled by default
1132         local force=0
1133
1134         while [ $# -gt 0 ]; do
1135                 case "${1}" in
1136                         --force|-f)
1137                                 force=1
1138                                 ;;
1139                 esac
1140                 shift
1141         done
1142
1143         # If we are not running in force mode, we ask the user if he does know
1144         # what he is doing.
1145         if ! enabled force; then
1146                 if ! cli_yesno "Do you really want to reset the whole network configuration?"; then
1147                         exit ${EXIT_ERROR}
1148                 fi
1149         fi
1150
1151         # Destroy all IPsec VPN connections
1152         local connection
1153         for connection in $(ipsec_list_connections); do
1154                 ipsec_connection_destroy "${connection}"
1155         done
1156
1157         # Stop strongswan
1158         ipsec_strongswan_autostart
1159
1160         # Destroy all user-defined security policies
1161         local secpol
1162         for secpol in $(vpn_security_policies_list_user); do
1163                 vpn_security_policies_destroy "${secpol}"
1164         done
1165
1166         local zone
1167         for zone in $(zones_get --all); do
1168                 zone_destroy_now "${zone}"
1169         done
1170
1171         local port
1172         for port in $(ports_get --all); do
1173                 port_destroy "${port}"
1174         done
1175
1176         # Flush all DNS servers.
1177         dns_server_flush
1178
1179         # Re-run the initialization functions
1180         init_run
1181
1182         exit ${EXIT_OK}
1183 }
1184
1185 # Help function: will show the default man page to the user.
1186 # Optionally, there are two arguments taken, the type of hook
1187 # and which hook should be shown.
1188 cli_help() {
1189         local cmd=${1}
1190         shift
1191
1192         case "${cmd}" in
1193                 zone|port|config)
1194                         local type=${cmd}
1195                         local hook=${1}
1196
1197                         # List all hooks if requested
1198                         if [ "${hook}" = "list-hooks" ]; then
1199                                 cli_list_hooks ${type}
1200                                 return ${EXIT_OK}
1201                         fi
1202
1203                         if ! hook_exists ${type} ${hook}; then
1204                                 error "No hook with name '${hook}' could be found"
1205                                 exit "${EXIT_ERROR}"
1206                         fi
1207
1208                         hook_exec ${type} ${hook} help
1209                         ;;
1210
1211                 # In all other cases show the default man page
1212                 *)
1213                         cli_show_man network
1214                         return ${EXIT_OK}
1215                         ;;
1216         esac
1217
1218         return ${EXIT_ERROR}
1219 }
1220
1221 cli_dns_server() {
1222         if cli_help_requested $@; then
1223                 cli_show_man network-dns-server
1224                 exit ${EXIT_OK}
1225         fi
1226
1227         # Get the command.
1228         local cmd=${1}; shift
1229         if [ -z "${cmd}" ]; then
1230                 cli_show_man network-dns-server
1231                 exit ${EXIT_ERROR}
1232         fi
1233
1234         # Get the new server to process (if any).
1235         local server=${1}
1236         local priority=${2}
1237
1238         case "${cmd}" in
1239                 list)
1240                         dns_server_show
1241                         exit ${EXIT_OK}
1242                         ;;
1243                 add)
1244                         if dns_server_exists ${server}; then
1245                                 error "DNS server '${server}' already exists!"
1246                                 exit ${EXIT_ERROR}
1247                         fi
1248
1249                         log INFO "Adding new DNS server: ${server}"
1250                         dns_server_add ${server} ${priority}
1251                         ;;
1252                 remove)
1253                         if ! dns_server_exists ${server}; then
1254                                 error "DNS server '${server}' does not exist!"
1255                                 exit ${EXIT_ERROR}
1256                         fi
1257
1258                         log INFO "Removing DNS server: ${server}"
1259                         dns_server_remove ${server} ${priority}
1260                         ;;
1261                 update)
1262                         # Just run the update afterwards.
1263                         ;;
1264                 *)
1265                         error "No such command: ${cmd}"
1266                         exit ${EXIT_ERROR}
1267         esac
1268
1269         # Update the local DNS configuration after changes have been made.
1270         dns_server_update
1271
1272         exit ${EXIT_OK}
1273 }
1274
1275 cli_raw() {
1276         local cmd="${1}"
1277         assert isset cmd
1278         shift
1279
1280         case "${cmd}" in
1281                 db-dump)
1282                         db_dump
1283                         ;;
1284                 ipsec-connection-exists)
1285                         ipsec_connection_exists $@
1286                         ;;
1287                 list-devices)
1288                         device_list
1289                         ;;
1290                 list-dhcpd-ranges-of-subnet)
1291                         dhcpd_subnet_range_list $@
1292                         ;;
1293                 list-dhcpd-settings)
1294                         dhcpd_global_settings_list $@
1295                         ;;
1296                 list-dhcpd-subnets)
1297                         dhcpd_subnet_list $@
1298                         ;;
1299                 list-dhcpd-subnet-options)
1300                         dhcpd_subnet_options_list $@
1301                         ;;
1302                 list-dns-servers)
1303                         dns_server_list
1304                         ;;
1305                 list-free-ports)
1306                         port_list_free
1307                         ;;
1308                 list-hooks)
1309                         hook_list $@
1310                         ;;
1311                 list-ipsec-connections)
1312                         ipsec_list_connections
1313                         ;;
1314                 list-ports)
1315                         port_list
1316                         ;;
1317                 list-ports-of-zone)
1318                         zone_get_ports $@
1319                         ;;
1320                 list-vpn-security-policies-all)
1321                         vpn_security_policies_list_all
1322                         ;;
1323                 list-settings)
1324                         network_settings_list
1325                         ;;
1326                 list-zones)
1327                         zones_get_all
1328                         ;;
1329                 list-next-free-zones)
1330                         zones_get_next_free
1331                         ;;
1332                 list-zone-config-ids)
1333                         zone_config_list_ids $@
1334                         ;;
1335                 list-zone-config-hids)
1336                         zone_config_list_hids $@
1337                         ;;
1338                 vpn-security-policy-exists)
1339                         vpn_security_policy_exists $@
1340                         ;;
1341                 zone-name-is-valid)
1342                         zone_name_is_valid $@
1343                         ;;
1344                 zone-config-id-is-valid)
1345                         zone_config_id_is_valid $@
1346                         ;;
1347                 zone-config-hid-is-valid)
1348                         zone_config_hid_is_valid $@
1349                         ;;
1350                 *)
1351                         error "No such command: ${cmd}"
1352                         exit ${EXIT_ERROR}
1353                         ;;
1354         esac
1355
1356         exit ${EXIT_OK}
1357 }
1358
1359 # Process the given action
1360 case "${action}" in
1361         init)
1362                 init_run
1363                 ;;
1364
1365         settings|hostname|port|device|zone|start|stop|restart|status|reset|route|vpn)
1366                 cli_${action} $@
1367                 ;;
1368
1369         # DHCP server configuration (automatically detects which protocol to use).
1370         dhcpv6|dhcpv4)
1371                 cli_dhcpd ${action/dhcp/ip} $@
1372                 ;;
1373
1374         # DNS server configuration.
1375         dns-server)
1376                 cli_dns_server $@
1377                 ;;
1378
1379         ""|help|--help|-h)
1380                 cli_help $@
1381                 ;;
1382
1383         raw)
1384                 cli_raw $@
1385                 ;;
1386
1387         *)
1388                 error "Invalid command given: ${action}"
1389                 cli_usage "network help"
1390                 exit ${EXIT_CONF_ERROR}
1391                 ;;
1392 esac
1393
1394 exit ${EXIT_OK}