6to4: don't start if detected local IPv4 address is RFC1918, allows people to deploy...
authorJo-Philipp Wich <jow@openwrt.org>
Sun, 12 Jun 2011 18:59:40 +0000 (18:59 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Sun, 12 Jun 2011 18:59:40 +0000 (18:59 +0000)
SVN-Revision: 27160

package/6to4/Makefile
package/6to4/files/6to4.sh

index c10657011896d9c6b3bef27e4c3b1de8e7ff115a..a6f3315a4ae656274ee16c572ee39a28627e750b 100644 (file)
@@ -8,7 +8,7 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=6to4
-PKG_VERSION:=3
+PKG_VERSION:=4
 PKG_RELEASE:=1
 
 include $(INCLUDE_DIR)/package.mk
index 65f4ffa5c2613f731f11f1fbd2b60f05b13907ea..6e85914b434190f72475647342dc6a984cf272f2 100755 (executable)
@@ -1,5 +1,5 @@
 # 6to4.sh - IPv6-in-IPv4 tunnel backend
-# Copyright (c) 2010 OpenWrt.org
+# Copyright (c) 2010-2011 OpenWrt.org
 
 find_6to4_wanif() {
        local if=$(ip -4 r l e 0.0.0.0/0); if="${if#default* dev }"; if="${if%% *}"
@@ -18,6 +18,15 @@ find_6to4_prefix() {
        printf "2002:%02x%02x:%02x%02x\n" $1 $2 $3 $4
 }
 
+test_6to4_rfc1918()
+{
+       local oIFS="$IFS"; IFS="."; set -- $1; IFS="$oIFS"
+       [ $1 -eq  10 ] && return 0
+       [ $1 -eq 192 ] && [ $2 -eq 168 ] && return 0
+       [ $1 -eq 172 ] && [ $2 -ge  16 ] && [ $2 -le  31 ] && return 0
+       return 1
+}
+
 set_6to4_radvd_interface() {
        local cfgid="$1"
        local lanif="${2:-lan}"
@@ -136,6 +145,11 @@ setup_interface_6to4() {
                }
        }
 
+       test_6to4_rfc1918 "$local4" && {
+               logger -t "$link" "Local wan ip $local4 is private - aborting"
+               return
+       }
+
        [ -n "$local4" ] && {
                logger -t "$link" "Starting ..."