2010-05-17 00:35:22 +02:00
|
|
|
#!/bin/sh
|
|
|
|
#
|
|
|
|
# Script to install Shoreline Firewall Init
|
|
|
|
#
|
2016-02-29 20:03:09 +01:00
|
|
|
# (c) 2000-2016 - Tom Eastep (teastep@shorewall.net)
|
2010-05-23 23:10:50 +02:00
|
|
|
# (c) 2010 - Roberto C. Sanchez (roberto@connexer.com)
|
2010-05-17 00:35:22 +02:00
|
|
|
#
|
|
|
|
# Shorewall documentation is available at http://shorewall.net
|
|
|
|
#
|
2014-01-04 18:48:27 +01:00
|
|
|
# This program is part of Shorewall.
|
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU General Public License as published by the
|
|
|
|
# Free Software Foundation, either version 2 of the license or, at your
|
|
|
|
# option, any later version.
|
|
|
|
#
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
2010-05-17 00:35:22 +02:00
|
|
|
#
|
2014-01-04 18:48:27 +01:00
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program; if not, see <http://www.gnu.org/licenses/>.
|
2010-05-17 00:35:22 +02:00
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program; if not, write to the Free Software
|
|
|
|
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
|
|
|
#
|
|
|
|
|
2011-07-13 16:10:07 +02:00
|
|
|
VERSION=xxx #The Build script inserts the actual version.
|
2016-01-05 00:45:21 +01:00
|
|
|
PRODUCT=shorewall-init
|
|
|
|
Product="Shorewall Init"
|
2010-05-17 00:35:22 +02:00
|
|
|
|
|
|
|
usage() # $1 = exit status
|
|
|
|
{
|
|
|
|
ME=$(basename $0)
|
2012-03-25 16:49:52 +02:00
|
|
|
echo "usage: $ME [ <configuration-file> ]"
|
2010-05-17 00:35:22 +02:00
|
|
|
echo " $ME -v"
|
|
|
|
echo " $ME -h"
|
2014-10-03 16:59:41 +02:00
|
|
|
echo " $ME -n"
|
2010-05-17 00:35:22 +02:00
|
|
|
exit $1
|
|
|
|
}
|
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
fatal_error()
|
|
|
|
{
|
|
|
|
echo " ERROR: $@" >&2
|
|
|
|
exit 1
|
|
|
|
}
|
|
|
|
|
2010-05-17 00:35:22 +02:00
|
|
|
split() {
|
|
|
|
local ifs
|
|
|
|
ifs=$IFS
|
|
|
|
IFS=:
|
|
|
|
set -- $1
|
|
|
|
echo $*
|
|
|
|
IFS=$ifs
|
|
|
|
}
|
|
|
|
|
|
|
|
qt()
|
|
|
|
{
|
|
|
|
"$@" >/dev/null 2>&1
|
|
|
|
}
|
|
|
|
|
|
|
|
mywhich() {
|
|
|
|
local dir
|
|
|
|
|
|
|
|
for dir in $(split $PATH); do
|
|
|
|
if [ -x $dir/$1 ]; then
|
|
|
|
return 0
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
return 2
|
|
|
|
}
|
|
|
|
|
|
|
|
cant_autostart()
|
|
|
|
{
|
|
|
|
echo
|
|
|
|
echo "WARNING: Unable to configure shorewall init to start automatically at boot" >&2
|
|
|
|
}
|
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
install_file() # $1 = source $2 = target $3 = mode
|
2010-05-17 00:35:22 +02:00
|
|
|
{
|
2016-01-05 00:45:21 +01:00
|
|
|
if cp -f $1 $2; then
|
|
|
|
if chmod $3 $2; then
|
|
|
|
if [ -n "$OWNER" ]; then
|
|
|
|
if chown $OWNER:$GROUP $2; then
|
|
|
|
return
|
|
|
|
fi
|
|
|
|
else
|
|
|
|
return 0
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
|
|
|
echo "ERROR: Failed to install $2" >&2
|
|
|
|
exit 1
|
2010-05-17 00:35:22 +02:00
|
|
|
}
|
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
make_directory() # $1 = directory , $2 = mode
|
2010-05-17 00:35:22 +02:00
|
|
|
{
|
2016-01-05 00:45:21 +01:00
|
|
|
mkdir -p $1
|
|
|
|
chmod 0755 $1
|
|
|
|
[ -n "$OWNERSHIP" ] && chown $OWNERSHIP $1
|
2010-05-17 00:35:22 +02:00
|
|
|
}
|
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
require()
|
|
|
|
{
|
|
|
|
eval [ -n "\$$1" ] || fatal_error "Required option $1 not set"
|
|
|
|
}
|
2012-02-23 19:07:02 +01:00
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
#
|
|
|
|
# Change to the directory containing this script
|
|
|
|
#
|
|
|
|
cd "$(dirname $0)"
|
2012-03-24 21:05:39 +01:00
|
|
|
|
2012-02-23 19:07:02 +01:00
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
# Parse the run line
|
2012-02-23 19:07:02 +01:00
|
|
|
#
|
2013-09-09 18:49:32 +02:00
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
finished=0
|
2014-10-03 16:59:41 +02:00
|
|
|
configure=1
|
2010-06-01 15:42:11 +02:00
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
while [ $finished -eq 0 ] ; do
|
2014-10-04 02:07:03 +02:00
|
|
|
option="$1"
|
|
|
|
|
|
|
|
case "$option" in
|
2012-03-24 21:05:39 +01:00
|
|
|
-*)
|
|
|
|
option=${option#-}
|
|
|
|
|
|
|
|
while [ -n "$option" ]; do
|
|
|
|
case $option in
|
|
|
|
h)
|
|
|
|
usage 0
|
|
|
|
;;
|
|
|
|
v)
|
|
|
|
echo "Shorewall-init Firewall Installer Version $VERSION"
|
|
|
|
exit 0
|
|
|
|
;;
|
2014-10-03 16:59:41 +02:00
|
|
|
n*)
|
|
|
|
configure=0
|
|
|
|
option=${option#n}
|
|
|
|
;;
|
2012-03-24 21:05:39 +01:00
|
|
|
*)
|
|
|
|
usage 1
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
|
|
|
|
shift
|
2010-05-17 00:35:22 +02:00
|
|
|
;;
|
|
|
|
*)
|
2012-03-24 21:05:39 +01:00
|
|
|
finished=1
|
2010-05-17 00:35:22 +02:00
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
#
|
|
|
|
# Read the RC file
|
|
|
|
#
|
|
|
|
if [ $# -eq 0 ]; then
|
|
|
|
#
|
|
|
|
# Load packager's settings if any
|
|
|
|
#
|
2012-04-01 02:40:18 +02:00
|
|
|
if [ -f ./shorewallrc ]; then
|
|
|
|
. ./shorewallrc || exit 1
|
2016-12-19 19:25:30 +01:00
|
|
|
file=./shorewallrc
|
2012-04-01 02:40:18 +02:00
|
|
|
elif [ -f ~/.shorewallrc ]; then
|
|
|
|
. ~/.shorewallrc || exit 1
|
2016-12-19 19:25:30 +01:00
|
|
|
file=~/.shorewallrc
|
2012-03-31 23:42:01 +02:00
|
|
|
else
|
2012-03-25 16:49:52 +02:00
|
|
|
fatal_error "No configuration file specified and ~/.shorewallrc not found"
|
2012-03-24 21:05:39 +01:00
|
|
|
fi
|
|
|
|
elif [ $# -eq 1 ]; then
|
|
|
|
file=$1
|
|
|
|
case $file in
|
|
|
|
/*|.*)
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
file=./$file
|
|
|
|
;;
|
|
|
|
esac
|
2010-05-17 00:35:22 +02:00
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
. $file
|
|
|
|
else
|
|
|
|
usage 1
|
|
|
|
fi
|
2011-05-14 14:31:19 +02:00
|
|
|
|
2012-09-02 23:36:11 +02:00
|
|
|
if [ -z "${VARLIB}" ]; then
|
|
|
|
VARLIB=${VARDIR}
|
2012-09-10 20:12:43 +02:00
|
|
|
VARDIR=${VARLIB}/${PRODUCT}
|
2012-09-03 00:51:35 +02:00
|
|
|
elif [ -z "${VARDIR}" ]; then
|
2012-09-10 20:12:43 +02:00
|
|
|
VARDIR=${VARLIB}/${PRODUCT}
|
2012-09-02 23:36:11 +02:00
|
|
|
fi
|
|
|
|
|
|
|
|
for var in SHAREDIR LIBEXECDIR CONFDIR SBINDIR VARLIB VARDIR; do
|
2012-03-24 21:05:39 +01:00
|
|
|
require $var
|
|
|
|
done
|
2011-05-14 14:31:19 +02:00
|
|
|
|
2014-10-04 16:50:30 +02:00
|
|
|
[ -n "$SANDBOX" ] && configure=0
|
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin
|
2012-02-21 21:34:41 +01:00
|
|
|
|
2015-03-24 15:51:56 +01:00
|
|
|
[ $configure -eq 1 ] && ETC=/etc || ETC="${CONFDIR}"
|
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
if [ -z "$BUILD" ]; then
|
2012-02-17 22:22:06 +01:00
|
|
|
case $(uname) in
|
2012-02-22 22:32:10 +01:00
|
|
|
cygwin*)
|
|
|
|
BUILD=cygwin
|
2012-02-17 22:22:06 +01:00
|
|
|
;;
|
|
|
|
Darwin)
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=apple
|
2012-02-17 22:22:06 +01:00
|
|
|
;;
|
|
|
|
*)
|
2013-08-09 02:44:40 +02:00
|
|
|
if [ -f /etc/os-release ]; then
|
2013-10-25 16:08:21 +02:00
|
|
|
eval $(cat /etc/os-release | grep ^ID=)
|
2013-08-09 02:44:40 +02:00
|
|
|
|
|
|
|
case $ID in
|
2014-09-23 12:18:58 +02:00
|
|
|
fedora|rhel|centos|foobar)
|
2013-08-09 02:44:40 +02:00
|
|
|
BUILD=redhat
|
|
|
|
;;
|
2013-10-25 16:08:21 +02:00
|
|
|
debian|ubuntu)
|
2013-08-09 02:44:40 +02:00
|
|
|
BUILD=debian
|
|
|
|
;;
|
|
|
|
opensuse)
|
|
|
|
BUILD=suse
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
BUILD="$ID"
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
elif [ -f /etc/debian_version ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=debian
|
2013-10-25 16:08:21 +02:00
|
|
|
elif [ -f /etc/ubuntu_version ]; then
|
|
|
|
BUILD=debian
|
2013-09-17 17:22:52 +02:00
|
|
|
elif [ -f /etc/gentoo-release ]; then
|
|
|
|
BUILD=gentoo
|
2012-02-17 22:22:06 +01:00
|
|
|
elif [ -f /etc/redhat-release ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=redhat
|
2012-02-18 00:26:02 +01:00
|
|
|
elif [ -f /etc/SuSE-release ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=suse
|
2012-02-17 22:22:06 +01:00
|
|
|
elif [ -f /etc/slackware-version ] ; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=slackware
|
2012-02-17 22:22:06 +01:00
|
|
|
elif [ -f /etc/arch-release ] ; then
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=archlinux
|
2015-12-28 01:47:31 +01:00
|
|
|
elif [ -f ${CONFDIR}/openwrt_release ]; then
|
|
|
|
BUILD=openwrt
|
2012-02-17 22:22:06 +01:00
|
|
|
else
|
2012-02-22 22:32:10 +01:00
|
|
|
BUILD=linux
|
2012-02-17 22:22:06 +01:00
|
|
|
fi
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
fi
|
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
case $BUILD in
|
|
|
|
apple)
|
2016-01-05 00:45:21 +01:00
|
|
|
[ -z "$OWNER" ] && OWNER=root
|
|
|
|
[ -z "$GROUP" ] && GROUP=wheel
|
2012-02-22 22:32:10 +01:00
|
|
|
;;
|
2016-01-05 00:45:21 +01:00
|
|
|
cygwin*|CYGWIN*)
|
|
|
|
OWNER=$(id -un)
|
|
|
|
GROUP=$(id -gn)
|
|
|
|
;;
|
2010-05-17 00:35:22 +02:00
|
|
|
*)
|
2016-01-05 00:45:21 +01:00
|
|
|
if [ $(id -u) -eq 0 ]; then
|
|
|
|
[ -z "$OWNER" ] && OWNER=root
|
|
|
|
[ -z "$GROUP" ] && GROUP=root
|
|
|
|
fi
|
2010-05-17 00:35:22 +02:00
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
[ -n "$OWNER" ] && OWNERSHIP="$OWNER:$GROUP"
|
2010-05-17 00:35:22 +02:00
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
[ -n "$HOST" ] || HOST=$BUILD
|
2012-02-17 22:22:06 +01:00
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
case "$HOST" in
|
|
|
|
debian)
|
2012-02-17 22:22:06 +01:00
|
|
|
echo "Installing Debian-specific configuration..."
|
|
|
|
;;
|
2013-09-17 17:22:52 +02:00
|
|
|
gentoo)
|
|
|
|
echo "Installing Gentoo-specific configuration..."
|
|
|
|
;;
|
2013-08-09 02:44:40 +02:00
|
|
|
redhat)
|
2012-02-21 01:11:28 +01:00
|
|
|
echo "Installing Redhat/Fedora-specific configuration..."
|
2012-02-17 22:22:06 +01:00
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
slackware)
|
2012-02-17 22:22:06 +01:00
|
|
|
echo "Shorewall-init is currently not supported on Slackware" >&2
|
|
|
|
exit 1
|
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
archlinux)
|
2012-02-17 22:22:06 +01:00
|
|
|
echo "Shorewall-init is currently not supported on Arch Linux" >&2
|
|
|
|
exit 1
|
|
|
|
;;
|
2013-08-09 02:44:40 +02:00
|
|
|
suse)
|
2012-02-17 22:22:06 +01:00
|
|
|
echo "Installing SuSE-specific configuration..."
|
|
|
|
;;
|
2015-12-28 01:47:31 +01:00
|
|
|
openwrt)
|
2016-01-05 00:45:21 +01:00
|
|
|
echo "Installing Openwrt-specific configuration..."
|
2015-12-28 01:47:31 +01:00
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
linux)
|
2012-02-17 22:22:06 +01:00
|
|
|
echo "ERROR: Shorewall-init is not supported on this system" >&2
|
2013-09-10 16:37:12 +02:00
|
|
|
exit 1
|
2012-02-17 22:22:06 +01:00
|
|
|
;;
|
|
|
|
*)
|
2012-02-22 22:32:10 +01:00
|
|
|
echo "ERROR: Unsupported HOST distribution: \"$HOST\"" >&2
|
2012-02-17 22:22:06 +01:00
|
|
|
exit 1;
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
|
2012-02-29 17:39:27 +01:00
|
|
|
[ -z "$TARGET" ] && TARGET=$HOST
|
|
|
|
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -n "$DESTDIR" ]; then
|
2016-01-05 00:45:21 +01:00
|
|
|
if [ $(id -u) != 0 ] ; then
|
2010-05-17 00:35:22 +02:00
|
|
|
echo "Not setting file owner/group permissions, not running as root."
|
|
|
|
OWNERSHIP=""
|
|
|
|
fi
|
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
make_directory ${DESTDIR}${INITDIR} 0755
|
2010-05-17 00:35:22 +02:00
|
|
|
fi
|
|
|
|
|
|
|
|
echo "Installing Shorewall Init Version $VERSION"
|
|
|
|
|
|
|
|
#
|
|
|
|
# Check for /usr/share/shorewall-init/version
|
|
|
|
#
|
2012-03-24 21:05:39 +01:00
|
|
|
if [ -f ${DESTDIR}${SHAREDIR}/shorewall-init/version ]; then
|
2010-05-17 00:35:22 +02:00
|
|
|
first_install=""
|
|
|
|
else
|
|
|
|
first_install="Yes"
|
|
|
|
fi
|
|
|
|
|
2012-06-02 17:26:06 +02:00
|
|
|
if [ -n "$DESTDIR" ]; then
|
|
|
|
mkdir -p ${DESTDIR}${CONFDIR}/logrotate.d
|
2016-01-05 00:45:21 +01:00
|
|
|
chmod 0755 ${DESTDIR}${CONFDIR}/logrotate.d
|
2012-06-02 17:26:06 +02:00
|
|
|
fi
|
|
|
|
|
2012-03-24 21:05:39 +01:00
|
|
|
#
|
|
|
|
# Install the Firewall Script
|
|
|
|
#
|
2012-02-23 19:59:10 +01:00
|
|
|
if [ -n "$INITFILE" ]; then
|
2014-10-05 03:49:55 +02:00
|
|
|
mkdir -p ${DESTDIR}${INITDIR}
|
2012-03-24 21:05:39 +01:00
|
|
|
install_file $INITSOURCE ${DESTDIR}${INITDIR}/$INITFILE 0544
|
2012-04-01 19:47:24 +02:00
|
|
|
[ "${SHAREDIR}" = /usr/share ] || eval sed -i \'s\|/usr/share/\|${SHAREDIR}/\|\' ${DESTDIR}${INITDIR}/$INITFILE
|
2012-03-24 21:05:39 +01:00
|
|
|
|
|
|
|
if [ -n "${AUXINITSOURCE}" ]; then
|
|
|
|
install_file $INITSOURCE ${DESTDIR}${INITDIR}/$AUXINITFILE 0544
|
|
|
|
fi
|
2010-05-17 00:35:22 +02:00
|
|
|
|
2013-09-09 17:11:45 +02:00
|
|
|
echo "SysV init script $INITSOURCE installed in ${DESTDIR}${INITDIR}/$INITFILE"
|
2012-02-23 19:59:10 +01:00
|
|
|
fi
|
2012-03-24 21:05:39 +01:00
|
|
|
|
2011-08-23 23:07:44 +02:00
|
|
|
#
|
|
|
|
# Install the .service file
|
|
|
|
#
|
2014-10-13 20:56:26 +02:00
|
|
|
if [ -z "${SERVICEDIR}" ]; then
|
|
|
|
SERVICEDIR="$SYSTEMD"
|
2014-10-08 01:46:16 +02:00
|
|
|
fi
|
|
|
|
|
2014-10-13 20:56:26 +02:00
|
|
|
if [ -n "$SERVICEDIR" ]; then
|
|
|
|
mkdir -p ${DESTDIR}${SERVICEDIR}
|
2013-08-18 23:27:26 +02:00
|
|
|
[ -z "$SERVICEFILE" ] && SERVICEFILE=$PRODUCT.service
|
2016-01-05 00:45:21 +01:00
|
|
|
install_file $SERVICEFILE ${DESTDIR}${SERVICEDIR}/$PRODUCT.service 0644
|
2014-10-13 20:56:26 +02:00
|
|
|
[ ${SBINDIR} != /sbin ] && eval sed -i \'s\|/sbin/\|${SBINDIR}/\|\' ${DESTDIR}${SERVICEDIR}/$PRODUCT.service
|
|
|
|
echo "Service file $SERVICEFILE installed as ${DESTDIR}${SERVICEDIR}/$PRODUCT.service"
|
2014-10-09 19:14:23 +02:00
|
|
|
if [ -n "$DESTDIR" -o $configure -eq 0 ]; then
|
2012-03-24 21:05:39 +01:00
|
|
|
mkdir -p ${DESTDIR}${SBINDIR}
|
2016-01-05 00:45:21 +01:00
|
|
|
chmod 0755 ${DESTDIR}${SBINDIR}
|
2012-02-29 17:39:27 +01:00
|
|
|
fi
|
2016-01-05 00:45:21 +01:00
|
|
|
install_file shorewall-init ${DESTDIR}${SBINDIR}/shorewall-init 0700
|
2013-09-09 16:33:08 +02:00
|
|
|
[ "${SHAREDIR}" = /usr/share ] || eval sed -i \'s\|/usr/share/\|${SHAREDIR}/\|\' ${DESTDIR}${SBINDIR}/shorewall-init
|
2012-03-24 21:05:39 +01:00
|
|
|
echo "CLI installed as ${DESTDIR}${SBINDIR}/shorewall-init"
|
2011-08-23 23:07:44 +02:00
|
|
|
fi
|
|
|
|
|
2010-05-17 00:35:22 +02:00
|
|
|
#
|
|
|
|
# Create /usr/share/shorewall-init if needed
|
|
|
|
#
|
2012-08-17 23:24:52 +02:00
|
|
|
mkdir -p ${DESTDIR}${SHAREDIR}/shorewall-init
|
2016-01-05 00:45:21 +01:00
|
|
|
chmod 0755 ${DESTDIR}${SHAREDIR}/shorewall-init
|
2010-05-17 00:35:22 +02:00
|
|
|
|
2012-06-02 17:26:06 +02:00
|
|
|
#
|
|
|
|
# Install logrotate file
|
|
|
|
#
|
|
|
|
if [ -d ${DESTDIR}${CONFDIR}/logrotate.d ]; then
|
2016-01-05 00:45:21 +01:00
|
|
|
install_file logrotate ${DESTDIR}${CONFDIR}/logrotate.d/$PRODUCT 0644
|
2012-06-02 17:26:06 +02:00
|
|
|
echo "Logrotate file installed as ${DESTDIR}${CONFDIR}/logrotate.d/$PRODUCT"
|
|
|
|
fi
|
|
|
|
|
2010-05-17 00:35:22 +02:00
|
|
|
#
|
|
|
|
# Create the version file
|
|
|
|
#
|
2012-08-17 23:24:52 +02:00
|
|
|
echo "$VERSION" > ${DESTDIR}/${SHAREDIR}/shorewall-init/version
|
2016-01-05 00:45:21 +01:00
|
|
|
chmod 0644 ${DESTDIR}${SHAREDIR}/shorewall-init/version
|
2010-05-17 00:35:22 +02:00
|
|
|
|
|
|
|
#
|
|
|
|
# Remove and create the symbolic link to the init script
|
|
|
|
#
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -z "$DESTDIR" ]; then
|
2012-08-17 23:24:52 +02:00
|
|
|
rm -f ${SHAREDIR}/shorewall-init/init
|
2012-03-24 21:05:39 +01:00
|
|
|
ln -s ${INITDIR}/${INITFILE} ${SHAREDIR}/shorewall-init/init
|
2010-05-17 00:35:22 +02:00
|
|
|
fi
|
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
if [ $HOST = debian ]; then
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -n "${DESTDIR}" ]; then
|
2015-03-24 15:51:56 +01:00
|
|
|
mkdir -p ${DESTDIR}${ETC}/network/if-up.d/
|
|
|
|
mkdir -p ${DESTDIR}${ETC}/network/if-down.d/
|
|
|
|
mkdir -p ${DESTDIR}${ETC}/network/if-post-down.d/
|
2014-10-04 18:00:12 +02:00
|
|
|
elif [ $configure -eq 0 ]; then
|
2014-10-06 01:52:59 +02:00
|
|
|
mkdir -p ${DESTDIR}${CONFDIR}/network/if-up.d/
|
|
|
|
mkdir -p ${DESTDIR}${CONFDIR}/network/if-down.d/
|
|
|
|
mkdir -p ${DESTDIR}${CONFDIR}/network/if-post-down.d/
|
2010-05-24 00:34:42 +02:00
|
|
|
fi
|
|
|
|
|
2014-10-06 01:52:59 +02:00
|
|
|
if [ ! -f ${DESTDIR}${CONFDIR}/default/shorewall-init ]; then
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -n "${DESTDIR}" ]; then
|
(Fwd) [Shorewall-users] Shorewall-lite on OpenWRT
On 7 Jun 2016 at 8:21, Tom Eastep wrote:
> On 06/07/2016 06:40 AM, Matt Darfeuille wrote:
> > On 5 Jun 2016 at 12:53, Tom Eastep wrote:
> >
> >> On 06/05/2016 12:33 PM, Matt Darfeuille wrote:
> >>> On 5 Jun 2016 at 7:57, Tom Eastep wrote:
> >>>
> >>>> On 05/29/2016 02:00 AM, Matt Darfeuille wrote:
> >>>>
> >>>> Hi Matt,
> >>>>
> >>>>>
> >>>>> -------------- Enclosure number 1 ----------------
> >>>>> >From 6ff651108df33ab8be4562caef03a8582e9eac5e Mon Sep 17 00:00:00 2001
> >>>>> From: Matt Darfeuille <matdarf@gmail.com>
> >>>>> Date: Tue, 24 May 2016 13:10:28 +0200
> >>>>> Subject: [PATCH 1/8] Emulate 'ps -p' using grep to work on openwrt
> >>>>>
> >>>>> Signed-off-by: Matt Darfeuille <matdarf@gmail.com>
> >>>>> ---
> >>>>> Shorewall-core/lib.common | 2 +-
> >>>>> 1 file changed, 1 insertion(+), 1 deletion(-)
> >>>>>
> >>>>> diff --git a/Shorewall-core/lib.common b/Shorewall-core/lib.common
> >>>>> index 03ecb2a..fcb02ee 100644
> >>>>> --- a/Shorewall-core/lib.common
> >>>>> +++ b/Shorewall-core/lib.common
> >>>>> @@ -776,7 +776,7 @@ mutex_on()
> >>>>> error_message "WARNING: Stale lockfile ${lockf} removed"
> >>>>> elif [ $lockpid -eq $$ ]; then
> >>>>> return 0
> >>>>> - elif ! qt ps p ${lockpid}; then
> >>>>> + elif ! qt ps | grep -v grep | grep ${lockpid}; then
> >>>>
> >>>> I don't see how this can work -- 'qt ps' will produce no output yet the
> >>>> code pipes into tandem greps.
> >>>>
> >>>> Do you really want this instead?
> >>>>
> >>>> elif ! ps | grep -v grep | qt grep ${lockpid}; then
> >>>>
> >>>
> >>> Oops sorry Tom, that's what I meant(do you want the corrected
> >>> patch?)!
> >>
> >> Yes, please.
> >>
> >
> > Tom, along with correcting this faulty commit I realize, after some
> > more testing, that I've also sent unnecessary commits.
> >
> > Should I revert these 3 commits(git revert ...):
> > Set proper permissions for the LOCKFILE on openwrt
> > 2ded346cb557212389212fd5adcd4c6800edbb62
> > Create lockfile before using openwrt's lock utility
> > 08e8796ff1abc3b24b8bbd40bf5e0a2b36464d61
> > Emulate 'ps -p' using grep to work on openwrt
> > 6ff651108df33ab8be4562caef03a8582e9eac5e
> >
> > or should I simply create new commits that will correct these faulty
> > commits?
> >
> > In other words what's the best way to correct submited commits.
> >
>
> Matt,
>
> Either way is fine.
>
Hopefully these 3 commits will do it(code-fixes.patch):
Patch 1 will correct the error you have point out!
On OpenWRT the lock utility doesn't allow to append the pid of the
currently running script to the LOCKFILE that's why I've simply
deleted that line(patch 2).
I've also reordered the permissions line to be added after the line
that will lock the file specified by the LOCKFILE variable(patch 3).
and two other patches:
While installing shorewall-init using the DESTDIR variable on debian,
'mkdir' would complain if the directory ${DESTDIR}/${etc}/default
already exist; corrected using 'mkdir -p ...'(patch 4).
The last patch will correct a typo in the blacklisting_support
article.
-Matt
-------------- Enclosure number 1 ----------------
>From 1a2ff15c8dc994030e819d2882570d188b99c501 Mon Sep 17 00:00:00 2001
From: Matt Darfeuille <matdarf@gmail.com>
Date: Wed, 8 Jun 2016 09:09:46 +0200
Subject: [PATCH 1/5] Correct pid detection mutex_on()
Signed-off-by: Matt Darfeuille <matdarf@gmail.com>
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2016-06-08 21:17:15 +02:00
|
|
|
mkdir -p ${DESTDIR}${ETC}/default
|
2010-05-24 00:34:42 +02:00
|
|
|
fi
|
|
|
|
|
2015-03-24 15:51:56 +01:00
|
|
|
[ $configure -eq 1 ] || mkdir -p ${DESTDIR}${CONFDIR}/default
|
|
|
|
install_file sysconfig ${DESTDIR}${ETC}/default/shorewall-init 0644
|
2015-11-21 21:53:24 +01:00
|
|
|
echo "sysconfig file installed in ${DESTDIR}${SYSCONFDIR}/${PRODUCT}"
|
2010-05-19 00:30:53 +02:00
|
|
|
fi
|
2013-03-15 21:03:53 +01:00
|
|
|
|
|
|
|
IFUPDOWN=ifupdown.debian.sh
|
2010-05-19 00:30:53 +02:00
|
|
|
else
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -n "$DESTDIR" ]; then
|
2012-03-31 23:42:01 +02:00
|
|
|
mkdir -p ${DESTDIR}${SYSCONFDIR}
|
2010-05-24 00:34:42 +02:00
|
|
|
|
2010-05-27 15:49:49 +02:00
|
|
|
if [ -z "$RPM" ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
if [ $HOST = suse ]; then
|
2015-03-24 15:51:56 +01:00
|
|
|
mkdir -p ${DESTDIR}${ETC}/sysconfig/network/if-up.d
|
|
|
|
mkdir -p ${DESTDIR}${ETC}/sysconfig/network/if-down.d
|
2013-09-17 17:22:52 +02:00
|
|
|
elif [ $HOST = gentoo ]; then
|
|
|
|
# Gentoo does not support if-{up,down}.d
|
2013-10-03 23:06:08 +02:00
|
|
|
/bin/true
|
2016-01-05 00:45:21 +01:00
|
|
|
elif [ $HOST = openwrt ]; then
|
|
|
|
# Not implemented on openwrt
|
|
|
|
/bin/true
|
2010-05-27 15:49:49 +02:00
|
|
|
else
|
2015-03-24 15:51:56 +01:00
|
|
|
mkdir -p ${DESTDIR}/${ETC}/NetworkManager/dispatcher.d
|
2010-05-27 15:49:49 +02:00
|
|
|
fi
|
2010-05-24 00:34:42 +02:00
|
|
|
fi
|
2010-05-17 00:35:22 +02:00
|
|
|
fi
|
|
|
|
|
2013-09-10 17:04:15 +02:00
|
|
|
if [ -n "$SYSCONFFILE" -a ! -f ${DESTDIR}${SYSCONFDIR}/${PRODUCT} ]; then
|
2016-01-05 00:45:21 +01:00
|
|
|
install_file ${SYSCONFFILE} ${DESTDIR}${SYSCONFDIR}/$PRODUCT 0644
|
|
|
|
echo "${SYSCONFFILE} file installed in ${DESTDIR}${SYSCONFDIR}/${PRODUCT}"
|
2013-09-10 17:04:15 +02:00
|
|
|
fi
|
2013-03-15 18:25:32 +01:00
|
|
|
|
|
|
|
[ $HOST = suse ] && IFUPDOWN=ifupdown.suse.sh || IFUPDOWN=ifupdown.fedora.sh
|
2010-05-17 00:35:22 +02:00
|
|
|
fi
|
|
|
|
|
2010-05-23 21:53:56 +02:00
|
|
|
#
|
|
|
|
# Install the ifupdown script
|
|
|
|
#
|
2010-05-24 00:34:42 +02:00
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
if [ $HOST != openwrt ]; then
|
|
|
|
cp $IFUPDOWN ifupdown
|
2012-03-31 23:42:01 +02:00
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
[ "${SHAREDIR}" = /usr/share ] || eval sed -i \'s\|/usr/share/\|${SHAREDIR}/\|\' ifupdown
|
2012-03-31 23:42:01 +02:00
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
mkdir -p ${DESTDIR}${LIBEXECDIR}/shorewall-init
|
2010-05-27 01:45:09 +02:00
|
|
|
|
2016-01-05 00:45:21 +01:00
|
|
|
install_file ifupdown ${DESTDIR}${LIBEXECDIR}/shorewall-init/ifupdown 0544
|
|
|
|
fi
|
2010-05-23 21:53:56 +02:00
|
|
|
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -d ${DESTDIR}/etc/NetworkManager ]; then
|
2015-03-24 15:51:56 +01:00
|
|
|
[ $configure -eq 1 ] || mkdir -p ${DESTDIR}${CONFDIR}/NetworkManager/dispatcher.d/
|
|
|
|
install_file ifupdown ${DESTDIR}${ETC}/NetworkManager/dispatcher.d/01-shorewall 0544
|
2010-05-23 21:53:56 +02:00
|
|
|
fi
|
|
|
|
|
2012-02-22 22:32:10 +01:00
|
|
|
case $HOST in
|
|
|
|
debian)
|
2014-10-04 18:00:12 +02:00
|
|
|
if [ $configure -eq 1 ]; then
|
|
|
|
install_file ifupdown ${DESTDIR}/etc/network/if-up.d/shorewall 0544
|
|
|
|
install_file ifupdown ${DESTDIR}/etc/network/if-down.d/shorewall 0544
|
|
|
|
install_file ifupdown ${DESTDIR}/etc/network/if-post-down.d/shorewall 0544
|
|
|
|
else
|
2014-10-06 01:52:59 +02:00
|
|
|
install_file ifupdown ${DESTDIR}${CONFDIR}/network/if-up.d/shorewall 0544
|
|
|
|
install_file ifupdown ${DESTDIR}${CONFDIR}/network/if-down.d/shorewall 0544
|
|
|
|
install_file ifupdown ${DESTDIR}${CONFDIR}/network/if-post-down.d/shorewall 0544
|
2014-10-04 18:00:12 +02:00
|
|
|
fi
|
2012-02-17 22:22:06 +01:00
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
suse)
|
2012-02-17 22:22:06 +01:00
|
|
|
if [ -z "$RPM" ]; then
|
2014-10-04 18:00:12 +02:00
|
|
|
if [ $configure -eq 0 ]; then
|
|
|
|
mkdir -p ${DESTDIR}${SYSCONFDIR}/network/if-up.d/
|
|
|
|
mkdir -p ${DESTDIR}${SYSCONFDIR}/network/if-down.d/
|
|
|
|
fi
|
|
|
|
|
2012-03-31 23:42:01 +02:00
|
|
|
install_file ifupdown ${DESTDIR}${SYSCONFDIR}/network/if-up.d/shorewall 0544
|
|
|
|
install_file ifupdown ${DESTDIR}${SYSCONFDIR}/network/if-down.d/shorewall 0544
|
2012-02-17 22:22:06 +01:00
|
|
|
fi
|
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
redhat)
|
2013-03-15 18:53:36 +01:00
|
|
|
if [ -z "$DESTDIR" ]; then
|
|
|
|
install_local=
|
|
|
|
|
|
|
|
if [ -f ${SBINDIR}/ifup-local -o -f ${SBINDIR}/ifdown-local ]; then
|
2013-10-14 16:15:08 +02:00
|
|
|
if ! grep -qF Shorewall-based ${SBINDIR}/ifup-local || ! grep -qF Shorewall-based ${SBINDIR}/ifdown-local; then
|
2013-03-15 18:53:36 +01:00
|
|
|
echo "WARNING: ${SBINDIR}/ifup-local and/or ${SBINDIR}/ifdown-local already exist; up/down events will not be handled"
|
|
|
|
else
|
|
|
|
install_local=Yes
|
|
|
|
fi
|
|
|
|
else
|
|
|
|
install_local=Yes
|
|
|
|
fi
|
|
|
|
|
|
|
|
if [ -n "$install_local" ]; then
|
|
|
|
install_file ifupdown ${DESTDIR}${SBINDIR}/ifup-local 0544
|
|
|
|
install_file ifupdown ${DESTDIR}${SBINDIR}/ifdown-local 0544
|
|
|
|
fi
|
2012-02-17 22:22:06 +01:00
|
|
|
fi
|
|
|
|
;;
|
|
|
|
esac
|
2010-05-23 23:44:35 +02:00
|
|
|
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -z "$DESTDIR" ]; then
|
2016-01-05 00:45:21 +01:00
|
|
|
if [ $configure -eq 1 -a -n "first_install" ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
if [ $HOST = debian ]; then
|
2015-12-05 17:31:22 +01:00
|
|
|
if [ -n "$SERVICEDIR" ]; then
|
|
|
|
if systemctl enable ${PRODUCT}.service; then
|
2015-11-21 21:53:24 +01:00
|
|
|
echo "Shorewall Init will start automatically at boot"
|
2015-12-05 17:31:22 +01:00
|
|
|
fi
|
|
|
|
elif mywhich insserv; then
|
2013-10-05 00:54:11 +02:00
|
|
|
if insserv ${INITDIR}/shorewall-init; then
|
2013-09-29 18:28:22 +02:00
|
|
|
echo "Shorewall Init will start automatically at boot"
|
|
|
|
else
|
|
|
|
cant_autostart
|
|
|
|
fi
|
2013-10-25 15:53:51 +02:00
|
|
|
elif mywhich update-rc.d ; then
|
|
|
|
if update-rc.d $PRODUCT enable; then
|
|
|
|
echo "$PRODUCT will start automatically at boot"
|
|
|
|
echo "Set startup=1 in ${CONFDIR}/default/$PRODUCT to enable"
|
|
|
|
else
|
|
|
|
cant_autostart
|
2013-10-25 16:04:03 +02:00
|
|
|
fi
|
2013-09-29 18:28:22 +02:00
|
|
|
else
|
|
|
|
cant_autostart
|
|
|
|
fi
|
2016-01-05 00:45:21 +01:00
|
|
|
elif [ $HOST = openwrt -a -f ${CONFDIR}/rc.common ]; then
|
|
|
|
/etc/init.d/$PRODUCT enable
|
|
|
|
if /etc/init.d/$PRODUCT enabled; then
|
|
|
|
echo "$Product will start automatically at boot"
|
|
|
|
else
|
|
|
|
cant_autostart
|
|
|
|
fi
|
2013-09-17 17:22:52 +02:00
|
|
|
elif [ $HOST = gentoo ]; then
|
|
|
|
# On Gentoo, a service must be enabled manually by the user,
|
|
|
|
# not by the installer
|
2013-10-03 23:06:08 +02:00
|
|
|
/bin/true
|
2010-05-17 00:35:22 +02:00
|
|
|
else
|
2014-10-13 20:56:26 +02:00
|
|
|
if [ -n "$SERVICEDIR" ]; then
|
2012-07-14 23:38:30 +02:00
|
|
|
if systemctl enable shorewall-init.service; then
|
2011-08-23 23:07:44 +02:00
|
|
|
echo "Shorewall Init will start automatically at boot"
|
|
|
|
fi
|
2012-03-24 21:05:39 +01:00
|
|
|
elif [ -x ${SBINDIR}/insserv -o -x /usr${SBINDIR}/insserv ]; then
|
2012-03-31 23:42:01 +02:00
|
|
|
if insserv ${INITDIR}/shorewall-init ; then
|
2010-05-17 00:35:22 +02:00
|
|
|
echo "Shorewall Init will start automatically at boot"
|
|
|
|
else
|
|
|
|
cant_autostart
|
|
|
|
fi
|
2012-03-24 21:05:39 +01:00
|
|
|
elif [ -x ${SBINDIR}/chkconfig -o -x /usr${SBINDIR}/chkconfig ]; then
|
2010-05-17 00:35:22 +02:00
|
|
|
if chkconfig --add shorewall-init ; then
|
|
|
|
echo "Shorewall Init will start automatically in run levels as follows:"
|
|
|
|
chkconfig --list shorewall-init
|
|
|
|
else
|
|
|
|
cant_autostart
|
|
|
|
fi
|
2012-03-24 21:05:39 +01:00
|
|
|
elif [ -x ${SBINDIR}/rc-update ]; then
|
2010-05-17 00:35:22 +02:00
|
|
|
if rc-update add shorewall-init default; then
|
|
|
|
echo "Shorewall Init will start automatically at boot"
|
|
|
|
else
|
|
|
|
cant_autostart
|
|
|
|
fi
|
2015-12-28 01:47:31 +01:00
|
|
|
elif [ $HOST = openwrt -a -f ${CONFDIR}/rc.common ]; then
|
2016-04-24 19:02:14 +02:00
|
|
|
/etc/init.d/$PRODUCT enable
|
2015-12-28 01:47:31 +01:00
|
|
|
if /etc/init.d/shorewall-init enabled; then
|
2016-04-24 19:02:14 +02:00
|
|
|
echo "$Product will start automatically at boot"
|
2015-12-28 01:47:31 +01:00
|
|
|
else
|
|
|
|
cant_autostart
|
|
|
|
fi
|
2012-02-21 21:34:41 +01:00
|
|
|
else
|
2010-05-17 00:35:22 +02:00
|
|
|
cant_autostart
|
|
|
|
fi
|
2010-12-05 01:01:16 +01:00
|
|
|
fi
|
2010-05-17 00:35:22 +02:00
|
|
|
fi
|
2010-05-23 23:10:50 +02:00
|
|
|
else
|
2014-10-03 16:59:41 +02:00
|
|
|
if [ $configure -eq 1 -a -n "$first_install" ]; then
|
2016-06-09 00:56:56 +02:00
|
|
|
if [ $HOST = debian -a -z "$SERVICEDIR" ]; then
|
2010-06-01 15:42:11 +02:00
|
|
|
if [ -n "${DESTDIR}" ]; then
|
|
|
|
mkdir -p ${DESTDIR}/etc/rcS.d
|
2010-05-24 00:34:42 +02:00
|
|
|
fi
|
|
|
|
|
2012-03-31 23:42:01 +02:00
|
|
|
ln -sf ../init.d/shorewall-init ${DESTDIR}${CONFDIR}/rcS.d/S38shorewall-init
|
2010-05-23 23:10:50 +02:00
|
|
|
echo "Shorewall Init will start automatically at boot"
|
|
|
|
fi
|
|
|
|
fi
|
2010-12-05 18:11:08 +01:00
|
|
|
fi
|
2010-12-04 21:06:05 +01:00
|
|
|
|
2012-03-30 21:02:25 +02:00
|
|
|
[ -z "${DESTDIR}" ] && [ ! -f ~/.shorewallrc ] && cp ${SHAREDIR}/shorewall/shorewallrc .
|
|
|
|
|
2015-11-21 21:53:24 +01:00
|
|
|
if [ -d ${DESTDIR}/etc/ppp ]; then
|
2012-02-22 22:32:10 +01:00
|
|
|
case $HOST in
|
|
|
|
debian|suse)
|
2012-02-17 22:22:06 +01:00
|
|
|
for directory in ip-up.d ip-down.d ipv6-up.d ipv6-down.d; do
|
|
|
|
mkdir -p ${DESTDIR}/etc/ppp/$directory #SuSE doesn't create the IPv6 directories
|
2012-03-31 23:42:01 +02:00
|
|
|
cp -fp ${DESTDIR}${LIBEXECDIR}/shorewall-init/ifupdown ${DESTDIR}${CONFDIR}/ppp/$directory/shorewall
|
2012-02-17 22:22:06 +01:00
|
|
|
done
|
|
|
|
;;
|
2012-02-22 22:32:10 +01:00
|
|
|
redhat)
|
2012-02-17 22:22:06 +01:00
|
|
|
#
|
|
|
|
# Must use the dreaded ip_xxx.local file
|
|
|
|
#
|
|
|
|
for file in ip-up.local ip-down.local; do
|
|
|
|
FILE=${DESTDIR}/etc/ppp/$file
|
|
|
|
if [ -f $FILE ]; then
|
2013-10-14 16:15:08 +02:00
|
|
|
if grep -qF Shorewall-based $FILE ; then
|
2012-03-24 21:05:39 +01:00
|
|
|
cp -fp ${DESTDIR}${LIBEXECDIR}/shorewall-init/ifupdown $FILE
|
2012-02-17 22:22:06 +01:00
|
|
|
else
|
|
|
|
echo "$FILE already exists -- ppp devices will not be handled"
|
|
|
|
break
|
|
|
|
fi
|
2010-12-05 18:11:08 +01:00
|
|
|
else
|
2012-03-24 21:05:39 +01:00
|
|
|
cp -fp ${DESTDIR}${LIBEXECDIR}/shorewall-init/ifupdown $FILE
|
2010-12-05 18:11:08 +01:00
|
|
|
fi
|
2012-02-17 22:22:06 +01:00
|
|
|
done
|
|
|
|
;;
|
|
|
|
esac
|
2010-05-17 00:35:22 +02:00
|
|
|
fi
|
|
|
|
#
|
|
|
|
# Report Success
|
|
|
|
#
|
|
|
|
echo "shorewall Init Version $VERSION Installed"
|