Add TTL function

This commit is contained in:
iamromulan
2024-07-20 20:59:20 -04:00
parent 0c5a7e99d4
commit ae95ad41c6

View File

@@ -19,6 +19,7 @@ SIMPLE_FIREWALL_SYSTEMD_DIR="$SIMPLE_FIREWALL_DIR/systemd"
# AT Command Script Variables and Functions # AT Command Script Variables and Functions
DEVICE_FILE="/dev/smd7" DEVICE_FILE="/dev/smd7"
TIMEOUT=4 # Set a timeout for the response TIMEOUT=4 # Set a timeout for the response
# Function to remount file system as read-write # Function to remount file system as read-write
remount_rw() { remount_rw() {
mount -o remount,rw / mount -o remount,rw /
@@ -69,7 +70,7 @@ wait_for_response() {
elapsed_time=$((current_time - start_time)) elapsed_time=$((current_time - start_time))
if [ "$elapsed_time" -ge "$TIMEOUT" ]; then if [ "$elapsed_time" -ge "$TIMEOUT" ]; then
echo -e "\e[1;31mError: Response timed out.\e[0m" # Red echo -e "\e[1;31mError: Response timed out.\e[0m" # Red
echo -e "\e[1;32mIf the responce takes longer than a second or 2 to respond this will not work\e[0m" # Green echo -e "\e[1;32mIf the response takes longer than a second or 2 to respond this will not work\e[0m" # Green
echo -e "\e[1;36mType install to install the better version of this that will work.\e[0m" # Cyan echo -e "\e[1;36mType install to install the better version of this that will work.\e[0m" # Cyan
return 1 return 1
fi fi
@@ -100,6 +101,13 @@ send_at_commands() {
fi fi
} }
overlay_check() {
if ! grep -qs '/real_rootfs ' /proc/mounts; then
echo -e "\e[31mYou have not ran Option 2 yet!!! Please run option 2!!\e[0m"
return 1
fi
}
basic_55x_setup() { basic_55x_setup() {
# Check if neither /etc nor /real_rootfs is mounted # Check if neither /etc nor /real_rootfs is mounted
if ! grep -qs '/etc ' /proc/mounts && ! grep -qs '/real_rootfs ' /proc/mounts; then if ! grep -qs '/etc ' /proc/mounts && ! grep -qs '/real_rootfs ' /proc/mounts; then
@@ -139,6 +147,65 @@ echo "Visit https://github.com/iamromulan for more!"
echo -e "\e[0m" echo -e "\e[0m"
} }
ttl_setup() {
local ttl_file="/etc/firewall.user.ttl"
local lan_utils_script="/etc/data/lanUtils.sh"
local combine_function="util_combine_iptable_rules"
local temp_file="/tmp/temp_firewall_user_ttl"
overlay_check || return
if [ -f "$ttl_file" ]; then
while true; do
echo "Would you like to edit the TTL settings? (yes to continue, exit to quit):"
read -r response
if [ "$response" = "exit" ]; then
echo "Exiting..."
break
elif [ "$response" = "yes" ]; then
if [ ! -s "$ttl_file" ]; then
echo -e "\e[31mTTL is not enabled\e[0m"
else
ipv4_ttl=$(grep 'iptables -t mangle -A POSTROUTING' "$ttl_file" | awk '{print $10}')
ipv6_ttl=$(grep 'ip6tables -t mangle -A POSTROUTING' "$ttl_file" | awk '{print $10}')
echo -e "\e[32mCurrent IPv4 TTL: $ipv4_ttl\e[0m"
echo -e "\e[32mCurrent IPv6 TTL: $ipv6_ttl\e[0m"
fi
echo -e "\e[32mType 0 to disable TTL\e[0m"
echo "Enter the TTL value (number only):"
read -r ttl_value
if ! [[ "$ttl_value" =~ ^[0-9]+$ ]]; then
echo "Invalid input, please enter a number."
else
if [ "$ttl_value" -eq 0 ]; then
echo "Disabling TTL..."
> "$ttl_file"
else
echo "Setting TTL to $ttl_value..."
echo "iptables -t mangle -A POSTROUTING -o rmnet+ -j TTL --ttl-set $ttl_value" > "$ttl_file"
echo "ip6tables -t mangle -A POSTROUTING -o rmnet+ -j HL --hl-set $ttl_value" >> "$ttl_file"
fi
/bin/bash "$lan_utils_script"
fi
fi
done
else
echo "Creating $ttl_file..."
touch "$ttl_file"
echo "Modifying $combine_function in $lan_utils_script..."
# Backup the original script
cp "$lan_utils_script" "${lan_utils_script}.bak"
# Check if the function already includes the ttl_firewall_file line
if ! grep -q "local ttl_firewall_file" "$lan_utils_script"; then
awk -v RS= -v ORS="\n\n" "/$combine_function/ {sub(/}/, \" local ttl_firewall_file=/etc/firewall.user.ttl\n\n #cleanup\n cat /dev/null > \$firewall_file\n\n #combine separate files to /etc/firewall.user\n if [ -f \\\"\$nat_firewall_file\\\" ]; then\n cat \$nat_firewall_file >> \$firewall_file\n fi\n if [ -f \\\"\$porttrigger_firewall_file\\\" ]; then\n cat \$porttrigger_firewall_file >> \$firewall_file\n fi\n if [ -f \\\"\$tcpmss_firewall_filev4\\\" ]; then\n cat \$tcpmss_firewall_filev4 >> \$firewall_file\n fi\n if [ -f \\\"\$tcpmss_firewall_filev6\\\" ]; then\n cat \$tcpmss_firewall_filev6 >> \$firewall_file\n fi\n if [ -f \\\"\$ttl_firewall_file\\\" ]; then\n cat \$ttl_firewall_file >> \$firewall_file\n fi\n}\");} 1" "$lan_utils_script" > "$temp_file" && mv "$temp_file" "$lan_utils_script"
fi
ttl_setup
fi
}
# Function for Tailscale Submenu # Function for Tailscale Submenu
tailscale_menu() { tailscale_menu() {
while true; do while true; do
@@ -163,7 +230,6 @@ echo -e "\e[1;31m2) Installing tailscale from opkg\e[0m"
opkg install tailscale opkg install tailscale
echo -e "\e[1;32mTailscale has been updated/installed.\e[0m" echo -e "\e[1;32mTailscale has been updated/installed.\e[0m"
echo -e "\e[1;31mTailscale is not up to date!.\e[0m" echo -e "\e[1;31mTailscale is not up to date!.\e[0m"
# Add logic here later for an up-to-date installation
echo -e "\e[1;32mReplace the tailscale and tailscaled binaries with the new ones and run tailscale update.\e[0m" echo -e "\e[1;32mReplace the tailscale and tailscaled binaries with the new ones and run tailscale update.\e[0m"
} }
@@ -182,12 +248,8 @@ configure_tailscale() {
read -p "Enter your choice: " config_choice read -p "Enter your choice: " config_choice
case $config_choice in case $config_choice in
1) 1) echo -e "\e[38;5;196mNot for the 551 yet\e[0m" # Red ;;
echo -e "\e[38;5;196mNot for the 551 yet\e[0m" # Red 2) echo -e "\e[38;5;196mNot for the 551 yet\e[0m" # Red ;;
;;
2)
echo -e "\e[38;5;196mNot for the 551 yet\e[0m" # Red
;;
3) tailscale up --accept-dns=false --reset ;; 3) tailscale up --accept-dns=false --reset ;;
4) tailscale up --ssh --accept-dns=false --reset ;; 4) tailscale up --ssh --accept-dns=false --reset ;;
5) tailscale up --accept-dns=false --reset ;; 5) tailscale up --accept-dns=false --reset ;;
@@ -199,7 +261,6 @@ configure_tailscale() {
done done
} }
# Main menu # Main menu
while true; do while true; do
echo " .%+: " echo " .%+: "
@@ -266,52 +327,26 @@ echo " :+##+. "
echo "Welcome to iamromulan's rcPCIe Toolkit script for Quectel RM55x Series modems!" echo "Welcome to iamromulan's rcPCIe Toolkit script for Quectel RM55x Series modems!"
echo "Visit https://github.com/iamromulan for more!" echo "Visit https://github.com/iamromulan for more!"
echo -e "\e[0m" echo -e "\e[0m"
echo -e "\e[91mThis is a test version of the toolit for the new RM550/551 modems\e[0m" # Light Red echo -e "\e[91mThis is a test version of the toolkit for the new RM550/551 modems\e[0m" # Light Red
echo "Select an option:" echo "Select an option:"
echo -e "\e[0m" echo -e "\e[0m"
echo -e "\e[96m1) Send AT Commands\e[0m" # Cyan echo -e "\e[96m1) Send AT Commands\e[0m" # Cyan
echo -e "\e[92m2) First time setup/run me after a flash!\e[0m" # Green echo -e "\e[92m2) First time setup/run me after a flash!\e[0m" # Green
echo -e "\e[94m3) Set root password\e[0m" # Light Blue echo -e "\e[94m3) TTL Setup\e[0m" # Light Blue
echo -e "\e[94m4) Tailscale Management\e[0m" # Light Blue echo -e "\e[94m4) Set root password\e[0m" # Light Blue
echo -e "\e[92m5) Install Speedtest.net CLI app (speedtest command)\e[0m" # Light Green echo -e "\e[94m5) Tailscale Management\e[0m" # Light Blue
echo -e "\e[93m6) Exit\e[0m" # Yellow (repeated color for exit option) echo -e "\e[92m6) Install Speedtest.net CLI app (speedtest command)\e[0m" # Light Green
echo -e "\e[93m7) Exit\e[0m" # Yellow (repeated color for exit option)
read -p "Enter your choice: " choice read -p "Enter your choice: " choice
case $choice in case $choice in
1) 1) send_at_commands ;;
send_at_commands 2) remount_rw; basic_55x_setup ;;
;; 3) overlay_check || continue; ttl_setup ;;
2) 4) overlay_check || continue; set_root_passwd ;;
remount_rw 5) tailscale_menu ;;
basic_55x_setup 6)
;; overlay_check || continue
98)
# Blank
;;
3)
set_root_passwd
;;
97)
# Blank
;;
96)
# Blank
;;
4)
tailscale_menu
;;
95)
# Blank
;;
94)
# Blank
;;
93)
# Blank
;;
5)
echo -e "\e[1;32mInstalling Speedtest.net CLI (speedtest command)\e[0m" echo -e "\e[1;32mInstalling Speedtest.net CLI (speedtest command)\e[0m"
# Add Logic to confirm we are overlayed over the larger /data # Add Logic to confirm we are overlayed over the larger /data
cd /usr/bin cd /usr/bin
@@ -323,21 +358,10 @@ echo " :+##+. "
echo -e "\e[1;32mSpeedtest CLI (speedtest command) installed!!\e[0m" echo -e "\e[1;32mSpeedtest CLI (speedtest command) installed!!\e[0m"
echo -e "\e[1;32mTry running the command 'speedtest'\e[0m" echo -e "\e[1;32mTry running the command 'speedtest'\e[0m"
echo -e "\e[1;32mNote that it will not work unless you login to the root account first\e[0m" echo -e "\e[1;32mNote that it will not work unless you login to the root account first\e[0m"
echo -e "\e[1;32mNormaly only an issue in adb, ttyd and ssh you are forced to login\e[0m" echo -e "\e[1;32mNormally only an issue in adb, ttyd, and ssh you are forced to login\e[0m"
echo -e "\e[1;32mIf in adb just type login and then try to run the speedtest command\e[0m" echo -e "\e[1;32mIf in adb just type login and then try to run the speedtest command\e[0m"
;; ;;
92) 7) echo -e "\e[1;32mGoodbye!\e[0m"; break ;;
# Blank *) echo -e "\e[1;31mInvalid option\e[0m" ;;
;;
91)
# Blank
;;
6)
echo -e "\e[1;32mGoodbye!\e[0m"
break
;;
*)
echo -e "\e[1;31mInvalid option\e[0m"
;;
esac esac
done done