#!/bin/sh /etc/rc.common
#
# Opennet Firmware
# 
# Copyright 2010 Rene Ejury <opennet@absorb.it>
# 
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
# 
#   http://www.apache.org/licenses/LICENSE-2.0
# 

START=21

. /usr/bin/on-helper.sh

start() {
	if [ -z "$(uci -q get network.free)" ]; then
		local batch
		
		# configure opennet dhcp/wifidog wifi
		append batch "set network.free=interface${N}"
		append batch "set network.free.ifname=none${N}"
		append batch "set network.free.type=bridge${N}"
		
        # while reconfiguring, on_id is usually not set. Anyway, just try to read it...
        on_id=$(uci -q get on-core.settings.on_id)
        free_ipschema=$(uci -q get on-wifidog.defaults.free_ipschema)
		free_netmask=$(uci -q get on-wifidog.defaults.free_netmask)
		if [ -n "$on_id" ]; then
			free_ipaddr=$(get_on_ip $on_id $free_ipschema 0)
            append batch "set network.free.proto=static${N}"
            append batch "set network.free.netmask=${free_netmask}${N}"
            append batch "set network.free.defaultroute=0${N}"
            append batch "set network.free.peerdns=0${N}"
            append batch "set network.free.ipaddr=${free_ipaddr}${N}"
		else
			append batch "set network.free.proto=none${N}"
		fi

		free_ipaddr_first=$(get_on_ip "0.1" $free_ipschema 0)
		append batch "set network.0=alias${N}"
		append batch "set network.0.proto=static${N}"
		append batch "set network.0.interface=free${N}"
		append batch "set network.0.ipaddr=${free_ipaddr_first}${N}"
		append batch "set network.0.netmask=${free_netmask}${N}"

		append batch "set firewall.zone_free=zone${N}"
		append batch "set firewall.zone_free.name=free${N}"
		append batch "set firewall.zone_free.network=free${N}"
		append batch "set firewall.zone_free.forward=ACCEPT${N}"
		append batch "set firewall.zone_free.input=ACCEPT${N}"
		append batch "set firewall.zone_free.output=ACCEPT${N}"

		append batch "set dhcp.@dnsmasq[0].nonwildcard=1${N}"

		echo "$batch${N}commit network${N}commit dhcp${N}" | uci -q batch

		section=$(uci add firewall forwarding)
		uci set firewall.$section.src='free'
		uci set firewall.$section.dest='on_vpn'

		section=$(uci add firewall forwarding)
		uci set firewall.$section.src='local'
		uci set firewall.$section.dest='free'

		section=$(uci add firewall redirect)
		uci set firewall.$section.src='opennet'
		uci set firewall.$section.proto='udp'
		uci set firewall.$section.src_dport='67'
		uci set firewall.$section.target='DNAT'
		uci set firewall.$section.src_port='67'
		if [ -n "$free_ipaddr" ]; then
			uci set firewall.$section.dest_ip=${free_ipaddr}
		fi
		uci commit firewall
	fi

	wifidog_by_gateway=$(openssl x509 -in /etc/openvpn/opennet_user/on_aps.crt \
		-subject -nameopt multiline -noout 2>/dev/null | awk '/commonName/ && /wifidog/ {print $3}')
	if [ -n "$wifidog_by_gateway" ]; then
		rm -f /etc/wifidog.conf		# this disables wifidog
	else
		ln -sf /etc/etc_presets/wifidog.conf /etc/wifidog.conf
	fi

	awk '{if ($1 != "if" || $2 == "tun0" || $4 != "true") print;}' /etc/etc_presets/dhcp-fwd.conf >/tmp/dhcp-fwd.conf
	for network in $(uci -q get firewall.zone_opennet.network); do
		ifname=$(uci -q get network.$network.ifname)
		if [ -n "$ifname" ] && [ "$ifname" != "none" ]; then
			echo "if $ifname false true true" >>/tmp/dhcp-fwd.conf
		fi
	done
	mv /tmp/dhcp-fwd.conf /etc/dhcp-fwd.conf

    exit 0
}
