2017-10-31 16:15:19 +01:00
|
|
|
#!/bin/bash
|
2017-11-30 16:23:50 +01:00
|
|
|
# SPDX-License-Identifier: GPL-2.0
|
|
|
|
#
|
2020-01-02 19:52:25 +01:00
|
|
|
# Copyright (C) 2015-2020 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
|
2017-11-30 16:23:50 +01:00
|
|
|
|
2017-10-31 16:15:19 +01:00
|
|
|
set -e
|
|
|
|
shopt -s nocasematch
|
|
|
|
shopt -s extglob
|
|
|
|
export LC_ALL=C
|
|
|
|
|
|
|
|
CONFIG_FILE="$1"
|
2018-01-10 02:37:03 +01:00
|
|
|
[[ $CONFIG_FILE =~ ^[a-zA-Z0-9_=+.-]{1,15}$ ]] && CONFIG_FILE="/etc/wireguard/$CONFIG_FILE.conf"
|
|
|
|
[[ $CONFIG_FILE =~ /?([a-zA-Z0-9_=+.-]{1,15})\.conf$ ]]
|
2017-10-31 16:15:19 +01:00
|
|
|
INTERFACE="${BASH_REMATCH[1]}"
|
|
|
|
|
|
|
|
process_peer() {
|
2017-11-09 06:12:06 +01:00
|
|
|
[[ $PEER_SECTION -ne 1 || -z $PUBLIC_KEY || -z $ENDPOINT ]] && return 0
|
2019-11-27 13:30:43 +01:00
|
|
|
[[ $(wg show "$INTERFACE" latest-handshakes) =~ ${PUBLIC_KEY//+/\\+}\ ([0-9]+) ]] || return 0
|
2022-01-04 13:07:49 +01:00
|
|
|
(( ($EPOCHSECONDS - ${BASH_REMATCH[1]}) > 135 )) || return 0
|
2017-11-09 06:12:06 +01:00
|
|
|
wg set "$INTERFACE" peer "$PUBLIC_KEY" endpoint "$ENDPOINT"
|
|
|
|
reset_peer_section
|
2017-10-31 16:15:19 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
reset_peer_section() {
|
2017-11-09 06:12:06 +01:00
|
|
|
PEER_SECTION=0
|
|
|
|
PUBLIC_KEY=""
|
|
|
|
ENDPOINT=""
|
2017-10-31 16:15:19 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
reset_peer_section
|
|
|
|
while read -r line || [[ -n $line ]]; do
|
2018-02-16 20:10:25 +01:00
|
|
|
stripped="${line%%\#*}"
|
|
|
|
key="${stripped%%=*}"; key="${key##*([[:space:]])}"; key="${key%%*([[:space:]])}"
|
|
|
|
value="${stripped#*=}"; value="${value##*([[:space:]])}"; value="${value%%*([[:space:]])}"
|
2017-11-09 06:12:06 +01:00
|
|
|
[[ $key == "["* ]] && { process_peer; reset_peer_section; }
|
|
|
|
[[ $key == "[Peer]" ]] && PEER_SECTION=1
|
|
|
|
if [[ $PEER_SECTION -eq 1 ]]; then
|
|
|
|
case "$key" in
|
|
|
|
PublicKey) PUBLIC_KEY="$value"; continue ;;
|
|
|
|
Endpoint) ENDPOINT="$value"; continue ;;
|
|
|
|
esac
|
|
|
|
fi
|
2017-10-31 16:15:19 +01:00
|
|
|
done < "$CONFIG_FILE"
|
|
|
|
process_peer
|