mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
The shipped fips.yaml comment and the package README told users to bind physical port names and never a bridge name such as br-lan, while the shipped lan entry itself binds br-lan. A lab test settled which is right: with a two-member Linux bridge, a socket on br-lan forms links and carries traffic, while a socket on a bridge member port sends frames but never forms a link, because the bridge takes the frames that arrive on its members. br_netfilter does not change that, unloaded or loaded with its call hooks off or on. Correct the comment and the README rule to say: bind the LAN bridge, never one of its member ports; ports outside any bridge bind by their own name. Which ports the bridge holds depends on the board (on x86/64 OpenWrt eth0 is the LAN port and eth1 the WAN port), so the README describes the members by board type and points at `bridge link`, which lists them. A DSA switch with hardware bridge offload was not covered and needs a check on a router. fips-bridge.conf, the package Makefile, 90-fips-setup and the README said kmod-br-netfilter is needed for the Ethernet transport to receive frames on bridge member ports. They now say what the module and the sysctl file actually do (load br_netfilter with its IP, IPv6 and ARP call hooks off) and that they do not make member ports usable. The dependency, the sysctl file and the module load are kept as shipped; their removal waits on a check on a router. The shipped configuration is unchanged.
139 lines
6.1 KiB
Bash
139 lines
6.1 KiB
Bash
#!/bin/sh
|
|
# FIPS first-boot setup — runs once after package installation.
|
|
# Configures the firewall and kernel modules for FIPS operation.
|
|
# The UCI defaults mechanism runs it once and deletes it when it ends with
|
|
# status 0.
|
|
#
|
|
# It is executed by the package's postinst, but sourced, not executed, by
|
|
# OpenWrt's default_postinst for a package built from the SDK feed and by the
|
|
# first-boot uci-defaults run after a sysupgrade. Nothing here may exit early,
|
|
# change directory or set shell options, and it must end with status 0: a
|
|
# non-zero status leaves the script in place to run again on every boot.
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# 1. Kernel modules
|
|
# ---------------------------------------------------------------------------
|
|
|
|
# kmod-tun is listed as a package dependency, but ensure the module is loaded.
|
|
modprobe tun 2>/dev/null || true
|
|
echo "tun" > /etc/modules.d/tun
|
|
|
|
# br_netfilter is loaded with its call hooks off (fips-bridge.conf). It does
|
|
# not make a bridge member port usable for the Ethernet transport: a lab
|
|
# test found a member-port socket never forms a link either way, so the
|
|
# shipped config binds the LAN bridge. Its removal waits on a router check.
|
|
modprobe br_netfilter 2>/dev/null || true
|
|
echo "br_netfilter" > /etc/modules.d/br-netfilter
|
|
|
|
# Apply the sysctl settings shipped in /etc/sysctl.d/fips-bridge.conf now
|
|
# (the file will be applied automatically on subsequent boots).
|
|
sysctl -p /etc/sysctl.d/fips-bridge.conf 2>/dev/null || true
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# 2. Firewall — add fips0 to the lan zone (fw4 / UCI)
|
|
# ---------------------------------------------------------------------------
|
|
# fw4 (nftables) matches zones by device name, so adding fips0 as a 'device'
|
|
# to the lan zone makes all traffic on the TUN interface accepted without
|
|
# needing raw nft rules in the base chains.
|
|
|
|
z=0
|
|
while uci -q get "firewall.@zone[$z]" >/dev/null 2>&1; do
|
|
if [ "$(uci -q get "firewall.@zone[$z].name" 2>/dev/null)" = "lan" ]; then
|
|
uci -q del_list "firewall.@zone[$z].device=fips0" 2>/dev/null || true
|
|
uci add_list "firewall.@zone[$z].device=fips0"
|
|
break
|
|
fi
|
|
z=$((z + 1))
|
|
done
|
|
|
|
# Install a firewall include so /etc/fips/firewall.sh is re-applied on every
|
|
# firewall reload (belt-and-suspenders for iptables-based OpenWrt builds).
|
|
FOUND=0
|
|
j=0
|
|
while uci -q get "firewall.@include[$j]" >/dev/null 2>&1; do
|
|
if [ "$(uci -q get "firewall.@include[$j].path" 2>/dev/null)" = "/etc/fips/firewall.sh" ]; then
|
|
FOUND=1
|
|
break
|
|
fi
|
|
j=$((j + 1))
|
|
done
|
|
if [ "$FOUND" = "0" ]; then
|
|
uci add firewall include
|
|
uci set "firewall.@include[-1].path=/etc/fips/firewall.sh"
|
|
uci set "firewall.@include[-1].reload=1"
|
|
fi
|
|
|
|
uci commit firewall
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# 3. dnsmasq UCI registration
|
|
# ---------------------------------------------------------------------------
|
|
# This UCI entry is what forwards .fips queries to the daemon: OpenWrt's
|
|
# dnsmasq init script builds its config from UCI and loads no directory under
|
|
# /etc. The daemon's DNS responder binds ::1. The 127.0.0.1 del_list removes
|
|
# the entry older packages added. While fips-gateway runs, its init script
|
|
# points this entry at the gateway's DNS port instead. The two del_lists after
|
|
# the first remove the gateway's entry for its old default port, left behind
|
|
# by a gateway that stopped without its init script's stop running.
|
|
|
|
uci -q del_list dhcp.@dnsmasq[0].server="/fips/127.0.0.1#5354" 2>/dev/null || true
|
|
uci -q del_list dhcp.@dnsmasq[0].server="/fips/::1#5353" 2>/dev/null || true
|
|
uci -q del_list dhcp.@dnsmasq[0].server="/fips/127.0.0.1#5353" 2>/dev/null || true
|
|
uci -q del_list dhcp.@dnsmasq[0].server="/fips/::1#5354" 2>/dev/null || true
|
|
uci add_list dhcp.@dnsmasq[0].server="/fips/::1#5354"
|
|
uci -q del_list dhcp.@dnsmasq[0].rebind_domain="fips" 2>/dev/null || true
|
|
uci add_list dhcp.@dnsmasq[0].rebind_domain="fips"
|
|
uci commit dhcp
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# 4. Gateway prerequisites
|
|
# ---------------------------------------------------------------------------
|
|
# Load conntrack module (needed for /proc/net/nf_conntrack session counting).
|
|
modprobe nf_conntrack 2>/dev/null || true
|
|
grep -qxF 'nf_conntrack' /etc/modules.d/nf-conntrack 2>/dev/null || \
|
|
echo "nf_conntrack" > /etc/modules.d/nf-conntrack
|
|
|
|
# Apply gateway sysctls (proxy_ndp + IPv6 forwarding).
|
|
# These are harmless even if the gateway is not enabled — forwarding is
|
|
# typically already on for a router, and proxy_ndp has no effect until
|
|
# proxy NDP entries are actually added.
|
|
sysctl -p /etc/sysctl.d/fips-gateway.conf 2>/dev/null || true
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# 5. Gateway DNS listen port
|
|
# ---------------------------------------------------------------------------
|
|
# Every release up to 0.5.1 shipped the gateway's DNS listener on 5353, the
|
|
# mDNS port, which the daemon's LAN rendezvous can hold. fips.yaml is a
|
|
# conffile and fips-ap-setup edits it, so an upgrade keeps the old line.
|
|
# Rewrite exactly that shipped line, four-space indent and nothing after the
|
|
# closing quote, inside the top-level gateway block, to the line a fresh
|
|
# install ships. Any other value is left as configured; the gateway warns at
|
|
# startup when it is still on the mDNS port.
|
|
#
|
|
# Runs last, and cannot fail the script: see the note at the top.
|
|
fips_migrate_gateway_dns_listen() {
|
|
local cfg=/etc/fips/fips.yaml
|
|
local old=' listen: "[::1]:5353"'
|
|
local new=' # listen: "[::1]:5365" # the default; the init script points dnsmasq at this port'
|
|
local msg='fips: moved gateway.dns.listen off the mDNS port 5353 to the default [::1]:5365'
|
|
|
|
if [ -f "$cfg" ] && grep -qxF "$old" "$cfg" 2>/dev/null; then
|
|
if awk -v old="$old" -v new="$new" '
|
|
/^[A-Za-z_]/ { top = $1 }
|
|
top == "gateway:" && $0 == old { print new; changed = 1; next }
|
|
{ print }
|
|
END { exit changed ? 0 : 1 }
|
|
' "$cfg" > "$cfg.tmp" 2>/dev/null &&
|
|
chmod 600 "$cfg.tmp" 2>/dev/null &&
|
|
mv -f "$cfg.tmp" "$cfg" 2>/dev/null; then
|
|
logger -t fips "$msg" 2>/dev/null || true
|
|
echo "$msg"
|
|
else
|
|
rm -f "$cfg.tmp" 2>/dev/null || true
|
|
fi
|
|
fi
|
|
}
|
|
fips_migrate_gateway_dns_listen
|
|
|
|
exit 0
|