ip.sh 8.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311
  1. #!/bin/bash
  2. # Check ip ownership
  3. is_ip_owner() {
  4. owner=$(grep 'OWNER=' $HESTIA/data/ips/$ip |cut -f 2 -d \')
  5. if [ "$owner" != "$user" ]; then
  6. check_result "$E_FORBIDEN" "$ip is not owned by $user"
  7. fi
  8. }
  9. # Check if ip address is free
  10. is_ip_free() {
  11. if [ -e "$HESTIA/data/ips/$ip" ]; then
  12. check_result "$E_EXISTS" "$ip is already exists"
  13. fi
  14. }
  15. # Check ip address specific value
  16. is_ip_key_empty() {
  17. key="$1"
  18. string=$(cat $HESTIA/data/ips/$ip)
  19. eval $string
  20. eval value="$key"
  21. if [ -n "$value" ] && [ "$value" != '0' ]; then
  22. key="$(echo $key|sed -e "s/\$U_//")"
  23. check_result "$E_EXISTS" "IP is in use / $key = $value"
  24. fi
  25. }
  26. is_ip_rdns_valid() {
  27. local ip="$1"
  28. local network_ip=$(echo $ip | cut -d"." -f1-3)
  29. local awk_ip=$(echo $network_ip | sed 's|\.|/\&\&/|g')
  30. local rev_awk_ip=$(echo $awk_ip | rev)
  31. if [ -z "$rdns" ]; then
  32. local rdns=$(dig +short -x "$ip" | head -n 1 | sed 's/.$//') || unset rdns
  33. fi
  34. if [ -n "$rdns" ] && [ ! $(echo $rdns | awk "/$awk_ip/ || /$rev_awk_ip/") ]; then
  35. echo $rdns
  36. return 0 # True
  37. fi
  38. return 1 # False
  39. }
  40. # Update ip helo for exim
  41. update_ip_helo_value() {
  42. ip="$1"
  43. helo="$2"
  44. natip="$1"
  45. # In case the IP is an NAT use the real ip address
  46. if [ ! -e "$HESTIA/data/ips/$ip" ]; then
  47. ip=$(get_real_ip $ip);
  48. fi
  49. # Create or update ip value
  50. update_ip_value_new 'HELO' "$helo"
  51. # Create mailhelo.conf file if doesn't exist
  52. if [ ! -e "/etc/${MAIL_SYSTEM}/mailhelo.conf" ]; then
  53. touch /etc/${MAIL_SYSTEM}/mailhelo.conf
  54. fi
  55. #Create or update ip:helo pair in mailhelo.conf file
  56. if [ -n "$helo" ]; then
  57. if [ $(cat /etc/${MAIL_SYSTEM}/mailhelo.conf | grep "$natip") ]; then
  58. sed -i "/^$natip:/c $natip:$helo" /etc/${MAIL_SYSTEM}/mailhelo.conf
  59. else
  60. echo $natip:$helo >> /etc/${MAIL_SYSTEM}/mailhelo.conf
  61. fi
  62. else
  63. sed -i "/^$natip:/d" /etc/${MAIL_SYSTEM}/mailhelo.conf
  64. fi
  65. }
  66. delete_ip_helo_value (){
  67. ip=$1
  68. sed -i "/^$ip:/d" /etc/${MAIL_SYSTEM}/mailhelo.conf
  69. }
  70. # Update ip address value
  71. update_ip_value() {
  72. key="$1"
  73. value="$2"
  74. conf="$HESTIA/data/ips/$ip"
  75. str=$(cat $conf)
  76. eval $str
  77. c_key=$(echo "${key//$/}")
  78. eval old="${key}"
  79. old=$(echo "$old" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  80. new=$(echo "$value" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  81. sed -i "$str_number s/$c_key='${old//\*/\\*}'/$c_key='${new//\*/\\*}'/g"\
  82. $conf
  83. }
  84. # New method that is improved on a later date we need to check if we can improve it for other locations
  85. update_ip_value_new() {
  86. key="$1"
  87. value="$2"
  88. conf="$HESTIA/data/ips/$ip"
  89. check_ckey=$(grep "^$key='" $conf)
  90. if [ -z "$check_ckey" ]; then
  91. echo "$key='$value'" >> $conf
  92. else
  93. sed -i "s|^$key=.*|$key='$value'|g" $conf
  94. fi
  95. }
  96. # Get ip name
  97. get_ip_alias() {
  98. ip_name=$(grep "NAME=" $HESTIA/data/ips/$local_ip |cut -f 2 -d \')
  99. if [ -n "$ip_name" ]; then
  100. echo "${1//./-}.$ip_name"
  101. fi
  102. }
  103. # Increase ip value
  104. increase_ip_value() {
  105. sip=${1-ip}
  106. USER=$user
  107. web_key='U_WEB_DOMAINS'
  108. usr_key='U_SYS_USERS'
  109. current_web=$(grep "$web_key=" $HESTIA/data/ips/$sip |cut -f 2 -d \')
  110. current_usr=$(grep "$usr_key=" $HESTIA/data/ips/$sip |cut -f 2 -d \')
  111. if [ -z "$current_web" ]; then
  112. echo "Error: Parsing error"
  113. log_event "$E_PARSING" "$ARGUMENTS"
  114. exit "$E_PARSING"
  115. fi
  116. new_web=$((current_web + 1))
  117. if [ -z "$current_usr" ]; then
  118. new_usr="$USER"
  119. else
  120. check_usr=$(echo -e "${current_usr//,/\\n}" | grep -x "$USER")
  121. if [ -z "$check_usr" ]; then
  122. new_usr="$current_usr,$USER"
  123. else
  124. new_usr="$current_usr"
  125. fi
  126. fi
  127. # Make sure users list does not contain duplicates
  128. new_usr=$(echo "$new_usr" |\
  129. sed "s/,/\n/g"|\
  130. sort -u |\
  131. sed ':a;N;$!ba;s/\n/,/g')
  132. sed -i "s/$web_key='$current_web'/$web_key='$new_web'/g" \
  133. $HESTIA/data/ips/$sip
  134. sed -i "s/$usr_key='$current_usr'/$usr_key='$new_usr'/g" \
  135. $HESTIA/data/ips/$sip
  136. }
  137. # Decrease ip value
  138. decrease_ip_value() {
  139. sip=${1-ip}
  140. USER=$user
  141. web_key='U_WEB_DOMAINS'
  142. usr_key='U_SYS_USERS'
  143. current_web=$(grep "$web_key=" $HESTIA/data/ips/$sip |cut -f 2 -d \')
  144. current_usr=$(grep "$usr_key=" $HESTIA/data/ips/$sip |cut -f 2 -d \')
  145. if [ -z "$current_web" ]; then
  146. check_result $E_PARSING "Parsing error"
  147. fi
  148. new_web=$((current_web - 1))
  149. check_ip=$(grep $sip $USER_DATA/web.conf |wc -l)
  150. if [[ $check_ip = 0 ]]; then
  151. new_usr=$(echo "$current_usr" |\
  152. sed "s/,/\n/g"|\
  153. sed "s/^$user$//g"|\
  154. sed "/^$/d"|\
  155. sort -u |\
  156. sed ':a;N;$!ba;s/\n/,/g')
  157. else
  158. new_usr="$current_usr"
  159. fi
  160. sed -i "s/$web_key='$current_web'/$web_key='$new_web'/g" \
  161. $HESTIA/data/ips/$sip
  162. sed -i "s/$usr_key='$current_usr'/$usr_key='$new_usr'/g" \
  163. $HESTIA/data/ips/$sip
  164. }
  165. # Get ip address value
  166. get_ip_value() {
  167. key="$1"
  168. string=$(cat $HESTIA/data/ips/$ip)
  169. eval $string
  170. eval value="$key"
  171. echo "$value"
  172. }
  173. # Get real ip address
  174. get_real_ip() {
  175. if [ -e "$HESTIA/data/ips/$1" ]; then
  176. echo "$1"
  177. else
  178. nat=$(grep -H "^NAT='$1'" $HESTIA/data/ips/* | head -n1 )
  179. if [ -n "$nat" ]; then
  180. echo "$nat" |cut -f 1 -d : |cut -f 7 -d /
  181. fi
  182. fi
  183. }
  184. # Convert CIDR to netmask
  185. convert_cidr() {
  186. set -- $(( 5 - ($1 / 8) )) 255 255 255 255 \
  187. $(((255 << (8 - ($1 % 8))) & 255 )) 0 0 0
  188. if [[ $1 -gt 1 ]]; then
  189. shift $1
  190. else
  191. shift
  192. fi
  193. echo ${1-0}.${2-0}.${3-0}.${4-0}
  194. }
  195. # Convert netmask to CIDR
  196. convert_netmask() {
  197. nbits=0
  198. IFS=.
  199. for dec in $1 ; do
  200. case $dec in
  201. 255) let nbits+=8;;
  202. 254) let nbits+=7;;
  203. 252) let nbits+=6;;
  204. 248) let nbits+=5;;
  205. 240) let nbits+=4;;
  206. 224) let nbits+=3;;
  207. 192) let nbits+=2;;
  208. 128) let nbits+=1;;
  209. 0);;
  210. esac
  211. done
  212. echo "$nbits"
  213. }
  214. # Calculate broadcast address
  215. get_broadcast() {
  216. OLD_IFS=$IFS
  217. IFS=.
  218. typeset -a I=($1)
  219. typeset -a N=($2)
  220. IFS=$OLD_IFS
  221. echo "$((${I[0]} |\
  222. (255 ^ ${N[0]}))).$((${I[1]} |\
  223. (255 ^ ${N[1]}))).$((${I[2]} |\
  224. (255 ^ ${N[2]}))).$((${I[3]} |\
  225. (255 ^ ${N[3]})))"
  226. }
  227. # Get user ips
  228. get_user_ips() {
  229. dedicated=$(grep -H "OWNER='$user'" $HESTIA/data/ips/*)
  230. dedicated=$(echo "$dedicated" |cut -f 1 -d : |sed 's=.*/==')
  231. shared=$(grep -H -A1 "OWNER='admin'" $HESTIA/data/ips/* |grep shared)
  232. shared=$(echo "$shared" |cut -f 1 -d : |sed 's=.*/==' |cut -f 1 -d \-)
  233. for dedicated_ip in $dedicated; do
  234. shared=$(echo "$shared" |grep -v $dedicated_ip)
  235. done
  236. echo -e "$dedicated\n$shared" |sed "/^$/d"
  237. }
  238. # Get user ip
  239. get_user_ip() {
  240. ip=$(get_user_ips |head -n1)
  241. if [ -z "$ip" ]; then
  242. check_result $E_NOTEXIST "no IP is available"
  243. fi
  244. local_ip=$ip
  245. nat=$(grep "^NAT" $HESTIA/data/ips/$ip |cut -f 2 -d \')
  246. if [ -n "$nat" ]; then
  247. ip=$nat
  248. fi
  249. }
  250. # Validate ip address
  251. is_ip_valid() {
  252. local_ip="$1"
  253. if [ ! -e "$HESTIA/data/ips/$1" ]; then
  254. nat=$(grep -H "^NAT='$1'" $HESTIA/data/ips/*)
  255. if [ -z "$nat" ]; then
  256. check_result "$E_NOTEXIST" "IP $1 doesn't exist"
  257. else
  258. nat=$(echo "$nat" |cut -f1 -d: |cut -f7 -d/)
  259. local_ip=$nat
  260. fi
  261. fi
  262. if [ -n "$2" ]; then
  263. if [ -z "$nat" ]; then
  264. ip_data=$(cat $HESTIA/data/ips/$1)
  265. else
  266. ip_data=$(cat $HESTIA/data/ips/$nat)
  267. fi
  268. ip_owner=$(echo "$ip_data" |grep OWNER= |cut -f2 -d \')
  269. ip_status=$(echo "$ip_data" |grep STATUS= |cut -f2 -d \')
  270. if [ "$ip_owner" != "$user" ] && [ "$ip_status" = 'dedicated' ]; then
  271. check_result "$E_FORBIDEN" "$user user can't use IP $1"
  272. fi
  273. get_user_owner
  274. if [ "$ip_owner" != "$user" ] && [ "$ip_owner" != "$owner" ]; then
  275. check_result "$E_FORBIDEN" "$user user can't use IP $1"
  276. fi
  277. fi
  278. }