Development
This commit is contained in:
parent
e2573fbf12
commit
f0504f802e
8 changed files with 67 additions and 66 deletions
|
|
@ -264,6 +264,7 @@
|
|||
"vlans": [
|
||||
{
|
||||
"name": "trusted",
|
||||
"vlan_id": 1,
|
||||
"subnet": "192.168.1.0",
|
||||
"subnet_mask": 24,
|
||||
"is_vpn": false,
|
||||
|
|
@ -368,6 +369,7 @@
|
|||
},
|
||||
{
|
||||
"name": "iot",
|
||||
"vlan_id": 10,
|
||||
"subnet": "192.168.10.0",
|
||||
"subnet_mask": 24,
|
||||
"is_vpn": false,
|
||||
|
|
@ -472,6 +474,7 @@
|
|||
},
|
||||
{
|
||||
"name": "guest",
|
||||
"vlan_id": 20,
|
||||
"subnet": "192.168.20.0",
|
||||
"subnet_mask": 24,
|
||||
"is_vpn": false,
|
||||
|
|
@ -534,6 +537,7 @@
|
|||
},
|
||||
{
|
||||
"name": "kids",
|
||||
"vlan_id": 30,
|
||||
"subnet": "192.168.30.0",
|
||||
"subnet_mask": 24,
|
||||
"is_vpn": false,
|
||||
|
|
@ -611,6 +615,7 @@
|
|||
},
|
||||
{
|
||||
"name": "vpn",
|
||||
"vlan_id": 40,
|
||||
"subnet": "192.168.40.0",
|
||||
"subnet_mask": 24,
|
||||
"is_vpn": true,
|
||||
|
|
|
|||
|
|
@ -99,7 +99,7 @@ from validation import (
|
|||
VALID_PROTOCOLS, VALID_BLOCKLIST_FORMATS,
|
||||
int_range, domainname,
|
||||
is_wg, is_dynamic_ip,
|
||||
derive_vlan_id, derive_interface, validate_config,
|
||||
derive_interface, validate_config,
|
||||
)
|
||||
|
||||
PRODUCT_NAME = "routlin"
|
||||
|
|
@ -210,7 +210,7 @@ def resolve_vlan_options(vlan):
|
|||
}
|
||||
|
||||
def is_physical(vlan):
|
||||
return derive_vlan_id(vlan.get("subnet", ""), vlan.get("subnet_mask", 24)) == 1
|
||||
return vlan.get("vlan_id") == 1
|
||||
|
||||
def networkd_stem(vlan):
|
||||
return f"10-{PRODUCT_NAME}-{vlan['name']}"
|
||||
|
|
@ -329,7 +329,7 @@ def apply_networkd(data, dry_run=False, only_if_changed=False):
|
|||
If only_if_changed=True, write files only when content differs from disk
|
||||
and skip the networkd reload if nothing changed. Used by --apply mode.
|
||||
"""
|
||||
all_vlan_ids = [derive_vlan_id(v.get('subnet', ''), v.get('subnet_mask', 24)) for v in data["vlans"] if not is_wg(v)]
|
||||
all_vlan_ids = [v.get('vlan_id') for v in data["vlans"] if not is_wg(v)]
|
||||
managed_ifaces = [derive_interface(v, data) for v in data["vlans"]]
|
||||
changed = False
|
||||
|
||||
|
|
@ -347,7 +347,7 @@ def apply_networkd(data, dry_run=False, only_if_changed=False):
|
|||
if is_wg(vlan):
|
||||
continue
|
||||
iface = derive_interface(vlan, data)
|
||||
vid = derive_vlan_id(vlan.get('subnet', ''), vlan.get('subnet_mask', 24))
|
||||
vid = vlan.get('vlan_id')
|
||||
stem = networkd_stem(vlan)
|
||||
|
||||
if not is_physical(vlan):
|
||||
|
|
@ -453,7 +453,7 @@ def build_vlan_dnsmasq_conf(vlan, data, iface):
|
|||
|
||||
line("# Generated by core.py -- do not edit manually.")
|
||||
line("# Edit config.json and re-run: sudo python3 core.py --apply")
|
||||
line(f"# VLAN: {name} (vlan_id={derive_vlan_id(vlan.get('subnet', ''), vlan.get('subnet_mask', 24))})")
|
||||
line(f"# VLAN: {name} (vlan_id={vlan.get('vlan_id')})")
|
||||
line()
|
||||
line(f"pid-file={vlan_pid_file(vlan)}")
|
||||
if not is_wg(vlan):
|
||||
|
|
@ -1872,7 +1872,7 @@ def build_radius_users(data):
|
|||
]
|
||||
|
||||
for vlan in data["vlans"]:
|
||||
vlan_id = derive_vlan_id(vlan.get('subnet', ''), vlan.get('subnet_mask', 24))
|
||||
vlan_id = vlan.get('vlan_id')
|
||||
for r in vlan.get("reservations", []):
|
||||
if r.get("enabled") is not True:
|
||||
continue
|
||||
|
|
@ -1888,7 +1888,7 @@ def build_radius_users(data):
|
|||
"",
|
||||
]
|
||||
|
||||
default_id = derive_vlan_id(default_vlan.get('subnet', ''), default_vlan.get('subnet_mask', 24))
|
||||
default_id = default_vlan.get('vlan_id')
|
||||
lines += [
|
||||
f"# Default -- unknown MACs land on VLAN {default_id} ({default_vlan['name']})",
|
||||
"DEFAULT Auth-Type := Accept",
|
||||
|
|
@ -2913,7 +2913,7 @@ def cmd_apply(data, dry_run=False):
|
|||
print(f" Would write: {RADIUS_USERS_FILE}")
|
||||
print(f" {total_macs} MAC reservation(s)")
|
||||
if default_vlan:
|
||||
print(f" DEFAULT -> VLAN {derive_vlan_id(default_vlan.get('subnet', ''), default_vlan.get('subnet_mask', 24))} ({default_vlan['name']})")
|
||||
print(f" DEFAULT -> VLAN {default_vlan.get('vlan_id')} ({default_vlan['name']})")
|
||||
print(f" Would ensure freeradius is running")
|
||||
if avahi_enabled(data):
|
||||
print()
|
||||
|
|
|
|||
|
|
@ -20,7 +20,7 @@ import sys
|
|||
from datetime import datetime, timezone
|
||||
from pathlib import Path
|
||||
|
||||
from validation import derive_interface, derive_vlan_id, is_wg
|
||||
from validation import derive_interface, is_wg
|
||||
|
||||
# ===================================================================
|
||||
# Constants (mirror core.py - no import to avoid circular dependency)
|
||||
|
|
@ -295,7 +295,7 @@ def check_configurations(data):
|
|||
# --- VLAN sub-interfaces ---
|
||||
for vlan in non_wg:
|
||||
iface = derive_interface(vlan, data)
|
||||
vid = derive_vlan_id(vlan.get("subnet", ""), vlan.get("subnet_mask", 24))
|
||||
vid = vlan.get("vlan_id")
|
||||
state = _iface_operstate(iface)
|
||||
id_ = f"iface_{vlan['name']}"
|
||||
name = f"interface {iface}"
|
||||
|
|
@ -348,7 +348,7 @@ def check_configurations(data):
|
|||
# --- systemd-networkd files ---
|
||||
for vlan in non_wg:
|
||||
iface = derive_interface(vlan, data)
|
||||
vid = derive_vlan_id(vlan.get("subnet", ""), vlan.get("subnet_mask", 24))
|
||||
vid = vlan.get("vlan_id")
|
||||
net = NETWORKD_DIR / f"10-{PRODUCT_NAME}-{vlan['name']}.network"
|
||||
results.append(file_ok(f"networkd_net_{vlan['name']}",
|
||||
f"networkd {net.name}", net))
|
||||
|
|
|
|||
|
|
@ -286,16 +286,10 @@ def derive_interface(vlan, data):
|
|||
lan = data.get('network_interfaces', {}).get('lan_interface', 'eth0')
|
||||
if is_wg(vlan):
|
||||
wg_vlans = [v for v in data.get('vlans', []) if is_wg(v)]
|
||||
wg_sorted = sorted(
|
||||
wg_vlans,
|
||||
key=lambda v: (
|
||||
derive_vlan_id(v.get('subnet', ''), v.get('subnet_mask', 24)) is None,
|
||||
derive_vlan_id(v.get('subnet', ''), v.get('subnet_mask', 24)) or 0,
|
||||
)
|
||||
)
|
||||
wg_sorted = sorted(wg_vlans, key=lambda v: (v.get('vlan_id') is None, v.get('vlan_id') or 0))
|
||||
idx = next((i for i, v in enumerate(wg_sorted) if v is vlan), 0)
|
||||
return f'wg{idx}'
|
||||
vid = derive_vlan_id(vlan.get('subnet', ''), vlan.get('subnet_mask', 24))
|
||||
vid = vlan.get('vlan_id')
|
||||
return lan if vid == 1 else f'{lan}.{vid}'
|
||||
|
||||
|
||||
|
|
@ -314,12 +308,9 @@ def validate_config(data):
|
|||
# Pre-compute per-VLAN vlan_ids and interface names without mutating data
|
||||
_lan = data.get("network_interfaces", {}).get("lan_interface", "eth0")
|
||||
_all_vlans = data.get("vlans", [])
|
||||
_derived_ids = [
|
||||
derive_vlan_id(_v.get("subnet", ""), _v.get("subnet_mask", 24))
|
||||
for _v in _all_vlans
|
||||
]
|
||||
_stored_ids = [_v.get("vlan_id") for _v in _all_vlans]
|
||||
_wg_sorted = sorted(
|
||||
[(i, _derived_ids[i]) for i, _v in enumerate(_all_vlans) if is_wg(_v)],
|
||||
[(i, _stored_ids[i]) for i, _v in enumerate(_all_vlans) if is_wg(_v)],
|
||||
key=lambda x: (x[1] is None, x[1] or 0)
|
||||
)
|
||||
_wg_order = {orig_i: wg_idx for wg_idx, (orig_i, _) in enumerate(_wg_sorted)}
|
||||
|
|
@ -328,7 +319,7 @@ def validate_config(data):
|
|||
if is_wg(_vlan):
|
||||
vlan_ifaces.append(f"wg{_wg_order[i]}")
|
||||
else:
|
||||
_vid = _derived_ids[i]
|
||||
_vid = _stored_ids[i]
|
||||
vlan_ifaces.append(_lan if _vid == 1 else f"{_lan}.{_vid}")
|
||||
|
||||
# upstream_dns block ============================================
|
||||
|
|
@ -377,10 +368,13 @@ def validate_config(data):
|
|||
vlan_networks = {} # iface -> IPv4Network (used for NAT section)
|
||||
|
||||
for i, (vlan, iface) in enumerate(zip(_all_vlans, vlan_ifaces)):
|
||||
vlan_id = _derived_ids[i]
|
||||
vlan_id = _stored_ids[i]
|
||||
name = vlan.get("name", "?")
|
||||
label = f"vlan '{name}' (id={vlan_id})"
|
||||
|
||||
if vlan_id is None or not isinstance(vlan_id, int) or not (1 <= vlan_id <= 4094):
|
||||
errors.append(f"vlan '{name}': vlan_id must be an integer 1–4094 (got {vlan_id!r}).")
|
||||
|
||||
if name in seen_names:
|
||||
errors.append(f"{label}: duplicate vlan name '{name}' "
|
||||
f"(also used by id={seen_names[name]}).")
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue