diff --git a/gl-kit-connect/files/usr/sbin/connect-daemon.sh b/gl-kit-connect/files/usr/sbin/connect-daemon.sh index c694dcf..c725cfb 100644 --- a/gl-kit-connect/files/usr/sbin/connect-daemon.sh +++ b/gl-kit-connect/files/usr/sbin/connect-daemon.sh @@ -78,7 +78,6 @@ start_tailscale() { --accept-routes=false \ --accept-dns=false 2>&1 | while read -r line; do log "tailscale: $line"; done - local ts_ip ts_ip=$("$TAILSCALE_BIN" ip -4 2>/dev/null || echo "unknown") log "tailscale: connected — IP=${ts_ip}" } diff --git a/gl-kit-connect/files/usr/sbin/connect-register.sh b/gl-kit-connect/files/usr/sbin/connect-register.sh index 379c4b1..40d09ef 100644 --- a/gl-kit-connect/files/usr/sbin/connect-register.sh +++ b/gl-kit-connect/files/usr/sbin/connect-register.sh @@ -16,7 +16,7 @@ CURRENT_PORT=$(uci -q get kitconnect.main.tunnel_remote_port 2>/dev/null || echo } echo "Registering device ${DEVICE_ID} with hub ${HUB_HOST}:${HUB_PORT}..." -resp=$(curl -s --connect-timeout 10 "http://${HUB_HOST}:${HUB_PORT}/api/register/${DEVICE_ID}" 2>/dev/null) +resp=$(curl -s --connect-timeout 10 --max-time 15 "http://${HUB_HOST}:${HUB_PORT}/api/register/${DEVICE_ID}" 2>/dev/null) [ -z "$resp" ] && { echo "ERROR: Hub unreachable at ${HUB_HOST}:${HUB_PORT}" diff --git a/gl-kit-connect/files/usr/sbin/connect-wizard.sh b/gl-kit-connect/files/usr/sbin/connect-wizard.sh index 07fd6dc..f96e985 100644 --- a/gl-kit-connect/files/usr/sbin/connect-wizard.sh +++ b/gl-kit-connect/files/usr/sbin/connect-wizard.sh @@ -107,7 +107,7 @@ step "Registering with fleet hub (${HUB_HOST}:${HUB_PORT})..." REG_FLAG="" [ "$FORCE" = "1" ] && REG_FLAG="--force" -resp=$(curl -s --connect-timeout 10 "http://${HUB_HOST}:${HUB_PORT}/api/register/${DEVICE_ID}" 2>/dev/null) || true +resp=$(curl -s --connect-timeout 10 --max-time 15 "http://${HUB_HOST}:${HUB_PORT}/api/register/${DEVICE_ID}" 2>/dev/null) || true if [ -z "$resp" ]; then warn "Hub unreachable — will retry on next daemon start" @@ -127,6 +127,18 @@ else uci commit kitconnect ok "Tailscale key configured" fi + + # Authorize tunnel key with hub (restrict,port-forwarding) + if [ -n "$port" ] && [ "$port" != "0" ] && [ -f /etc/kitconnect/connect_id_ed25519.pub ]; then + PUBKEY=$(awk '{print $1" "$2}' /etc/kitconnect/connect_id_ed25519.pub 2>/dev/null) + if [ -n "$PUBKEY" ]; then + curl -s --connect-timeout 10 --max-time 15 \ + -X POST "http://${HUB_HOST}:${HUB_PORT}/api/authorize-key" \ + -H "Content-Type: application/json" \ + -d "{\"device_id\":\"${DEVICE_ID}\",\"pubkey\":\"${PUBKEY}\"}" \ + >/dev/null 2>&1 && ok "Tunnel key authorized (restrict, port ${port})" || true + fi + fi fi # ── Step 6: Enable & start service ───────────────────────────── diff --git a/kit-connect/bin/connect-register.sh b/kit-connect/bin/connect-register.sh new file mode 100755 index 0000000..bc92234 --- /dev/null +++ b/kit-connect/bin/connect-register.sh @@ -0,0 +1,59 @@ +#!/bin/sh +# connect-register.sh — Standalone hub registration for Synology routers. +# Callable from the wizard, postinst, or manually. +# Usage: connect-register.sh [--force] +# --force Re-register even if already assigned + +HUB_HOST="162.243.83.36" +HUB_PORT="8080" +CONF="/etc/kit-connect/connect.conf" +FORCE=0 +[ "$1" = "--force" ] && FORCE=1 + +DEVICE_ID=$(cat /etc/busrouter/device-id 2>/dev/null || hostname 2>/dev/null | sed 's/[^a-zA-Z0-9_-]//g') +CURRENT_PORT=$(grep '^TUNNEL_REMOTE_PORT=' "$CONF" 2>/dev/null | cut -d= -f2 || echo "0") + +[ "$FORCE" = "1" ] && CURRENT_PORT="0" +[ "$CURRENT_PORT" != "0" ] && { + echo "Already registered (port ${CURRENT_PORT}). Use --force to re-register." + exit 0 +} + +echo "Registering device ${DEVICE_ID} with hub ${HUB_HOST}:${HUB_PORT}..." +resp=$(curl -s --connect-timeout 10 --max-time 15 \ + "http://${HUB_HOST}:${HUB_PORT}/api/register/${DEVICE_ID}" 2>/dev/null) + +[ -z "$resp" ] && { + echo "ERROR: Hub unreachable at ${HUB_HOST}:${HUB_PORT}" + exit 1 +} + +port=$(printf '%s' "$resp" | sed -n 's/.*"tunnel_port"[[:space:]]*:[[:space:]]*\([0-9]*\).*/\1/p') +status=$(printf '%s' "$resp" | sed -n 's/.*"status"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p') + +echo "" +echo " Device: ${DEVICE_ID}" +echo " Status: ${status:-unknown}" +echo " Port: ${port:-none}" +echo "" + +if [ -n "$port" ] && [ "$port" != "0" ]; then + sed -i "s/^TUNNEL_REMOTE_PORT=.*/TUNNEL_REMOTE_PORT=${port}/" "$CONF" 2>/dev/null + echo "Port ${port} saved to ${CONF}." +fi + +# Authorize key with hub +TUNNEL_KEY="/var/packages/kit-connect/target/bin/connect_id_ed25519" +if [ -f "$TUNNEL_KEY" ] && [ -n "$port" ]; then + PUBKEY=$(awk '{print $1" "$2}' "${TUNNEL_KEY}.pub" 2>/dev/null) + if [ -n "$PUBKEY" ]; then + curl -s --connect-timeout 10 --max-time 15 \ + -X POST "http://${HUB_HOST}:${HUB_PORT}/api/authorize-key" \ + -H "Content-Type: application/json" \ + -d "{\"device_id\":\"${DEVICE_ID}\",\"pubkey\":\"${PUBKEY}\"}" \ + >/dev/null 2>&1 || true + echo "Tunnel key sent to hub for authorization." + fi +fi + +if [ "$status" = "new" ]; then echo ""; echo " ✓ Device registered — restart kit-connect to apply"; fi diff --git a/kit-connect/wizard.sh b/kit-connect/wizard.sh index fc665f3..60c189a 100755 --- a/kit-connect/wizard.sh +++ b/kit-connect/wizard.sh @@ -86,7 +86,7 @@ ok "Config written to ${CONF}" # ── Step 4: Register with hub ────────────────────────────────── step "Registering with fleet hub (${HUB_HOST}:${HUB_PORT})..." -resp=$(curl -s --connect-timeout 10 "http://${HUB_HOST}:${HUB_PORT}/api/register/${DEVICE_ID}" 2>/dev/null) || true +resp=$(curl -s --connect-timeout 10 --max-time 15 "http://${HUB_HOST}:${HUB_PORT}/api/register/${DEVICE_ID}" 2>/dev/null) || true if [ -z "$resp" ]; then warn "Hub unreachable — will retry on next daemon start" @@ -105,6 +105,18 @@ else sed -i "s|^TAILSCALE_AUTH_KEY=.*|TAILSCALE_AUTH_KEY=${tskey}|" "$CONF" 2>/dev/null ok "Tailscale key configured" fi + + # ── Authorize tunnel key with hub ────────────────────── + if [ -n "$port" ] && [ "$port" != "0" ] && [ -f /var/packages/kit-connect/target/bin/connect_id_ed25519.pub ]; then + PUBKEY=$(awk '{print $1" "$2}' /var/packages/kit-connect/target/bin/connect_id_ed25519.pub 2>/dev/null) + if [ -n "$PUBKEY" ]; then + curl -s --connect-timeout 10 --max-time 15 \ + -X POST "http://${HUB_HOST}:${HUB_PORT}/api/authorize-key" \ + -H "Content-Type: application/json" \ + -d "{\"device_id\":\"${DEVICE_ID}\",\"pubkey\":\"${PUBKEY}\"}" \ + >/dev/null 2>&1 && ok "Tunnel key authorized (restrict, port ${port})" || true + fi + fi fi # ── Step 5: Dashboard server ─────────────────────────────────── diff --git a/syno-balance/build.sh b/syno-balance/build.sh index 64208d5..c3f82c6 100755 --- a/syno-balance/build.sh +++ b/syno-balance/build.sh @@ -2,22 +2,7 @@ # build.sh — Assemble syno-balance SPK for Synology SRM (noarch) # Output: syno-balance-0.1-0001.spk # TEST BUILD — not for production. -# -# SPK structure (outer tar, UNCOMPRESSED): -# INFO -# PACKAGE_ICON.PNG (64x64) -# PACKAGE_ICON_256.PNG (256x256) -# scripts/ -# postinst -# start-stop-status -# preinst -# preuninst -# postuninst -# conf/ -# privilege -# resource -# package.tgz (gzipped inner tar of bin/ + etc/) -# checksum (md5 of package.tgz) +# Compatible: RT2600ac, RT6600ax, all ipq806x SRM routers. set -e @@ -31,50 +16,32 @@ BUILD_DIR="/tmp/syno-balance-build-$$" echo "=== Building ${PKG_NAME}-${VERSION}.spk (TEST BUILD) ===" -# Clean and create build staging directory rm -rf "$BUILD_DIR" mkdir -p "$BUILD_DIR" -# ── 1. Create inner package.tgz (gzipped tar of bin/ + etc/) ────────── -echo " → Creating package.tgz" -tar -czf "$BUILD_DIR/package.tgz" \ - --format=ustar \ - bin/ \ - etc/ +# Inner package.tgz +tar -czf "$BUILD_DIR/package.tgz" --format=ustar bin/ etc/ -# ── 2. Generate checksum ────────────────────────────────────────────── -echo " → Computing checksum" -md5sum "$BUILD_DIR/package.tgz" | awk '{print $1}' > "$BUILD_DIR/checksum" +# Stage outer SPK +STAGE="$BUILD_DIR/stage" +mkdir -p "$STAGE" +cp INFO PACKAGE_ICON.PNG PACKAGE_ICON_256.PNG "$STAGE/" +cp -r scripts "$STAGE/" +mkdir -p "$STAGE/conf" +cp conf/privilege conf/resource "$STAGE/conf/" +cp "$BUILD_DIR/package.tgz" "$STAGE/" -# ── 3. Assemble outer SPK (UNCOMPRESSED tar) ────────────────────────── -echo " → Assembling SPK" -tar -cf "${OUTPUT}" \ - --format=ustar \ - -C "$SCRIPT_DIR" \ - INFO \ - PACKAGE_ICON.PNG \ - PACKAGE_ICON_256.PNG \ - scripts/ \ - -C "$BUILD_DIR" \ - package.tgz \ - checksum +# Assemble (no checksum — deprecated) +tar -cf "${OUTPUT}" -C "$STAGE" --format=ustar \ + INFO PACKAGE_ICON.PNG PACKAGE_ICON_256.PNG scripts conf package.tgz -# SPK conf/ goes in the outer tar too -tar -rf "${OUTPUT}" \ - --format=ustar \ - -C "$SCRIPT_DIR" \ - conf/privilege \ - conf/resource - -# ── 4. Verify ───────────────────────────────────────────────────────── -echo " → Verifying SPK contents" +echo " → SPK contents:" tar -tf "${OUTPUT}" | sort -SIZE=$(stat -f%z "${OUTPUT}" 2>/dev/null || stat -c%s "${OUTPUT}" 2>/dev/null) +SIZE=$(stat -c%s "${OUTPUT}" 2>/dev/null) echo "" echo "=== Build complete: ${OUTPUT} ===" echo " Size: ${SIZE} bytes" echo " MD5: $(md5sum "${OUTPUT}" | awk '{print $1}')" -# Cleanup rm -rf "$BUILD_DIR"