uci-defaults only runs on first boot, so devices updating from ph3 would never generate WG keys. Heartbeat now generates them if missing. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
99 lines
4.1 KiB
Bash
Executable File
99 lines
4.1 KiB
Bash
Executable File
#!/bin/sh
|
|
# Phone-home heartbeat to Parahub cloud
|
|
PARAHUB_API_YGG="http://[200:abb9:5810:37d3:8a4c:98a6:b82b:969a]/api/v1/iot/mesh/heartbeat"
|
|
PARAHUB_API_PUBLIC="https://parahub.io/api/v1/iot/mesh/heartbeat"
|
|
HEARTBEAT_KEY="IqPosrcpTQKSbLHxOG3iLTl_K2MsDxvd"
|
|
|
|
# Read firmware role
|
|
ROLE=$(cat /etc/parahub/role 2>/dev/null || echo "unknown")
|
|
|
|
# Read identity from /etc/parahub/keys
|
|
. /etc/parahub/keys 2>/dev/null
|
|
MAC="${NODE_MAC:-$(cat /sys/class/net/br-lan/address 2>/dev/null)}"
|
|
HOSTNAME="$(uci -q get system.@system[0].hostname)"
|
|
YGG_ADDR="${YGGDRASIL_ADDRESS:-unknown}"
|
|
SSID="${PRIVATE_SSID:-unknown}"
|
|
UPTIME="$(cut -d. -f1 /proc/uptime)"
|
|
|
|
# Get mesh IP (br-private address)
|
|
MESH_IP=$(ip -4 addr show br-private 2>/dev/null | grep -o 'inet [0-9.]*' | cut -d' ' -f2)
|
|
MESH_IP="${MESH_IP:-unknown}"
|
|
|
|
# Generate WireGuard VPS keypair if missing (OTA from pre-VPS firmware)
|
|
if [ "$ROLE" != "bee" ] && [ ! -f /etc/parahub/wg_vps_private.key ] && command -v wg >/dev/null 2>&1; then
|
|
umask 077
|
|
wg genkey > /etc/parahub/wg_vps_private.key
|
|
wg pubkey < /etc/parahub/wg_vps_private.key > /etc/parahub/wg_vps_public.key
|
|
logger -t parahub-heartbeat "Generated VPS WireGuard keypair (OTA migration)"
|
|
fi
|
|
|
|
# Read WireGuard VPS public key (Bumblebee only)
|
|
WG_PUBKEY=""
|
|
if [ -f /etc/parahub/wg_vps_public.key ]; then
|
|
WG_PUBKEY=$(cat /etc/parahub/wg_vps_public.key 2>/dev/null)
|
|
fi
|
|
|
|
# Detect hardware from board_name
|
|
HW=$(cat /tmp/sysinfo/board_name 2>/dev/null)
|
|
case "$HW" in
|
|
glinet,gl-axt1800) HW="axt1800" ;;
|
|
glinet,gl-mt3000) HW="mt3000" ;;
|
|
glinet,gl-mt6000) HW="mt6000" ;;
|
|
xiaomi,redmi-router-ax6s) HW="ax6s" ;;
|
|
asus,rt-ax53u) HW="ax53u" ;;
|
|
glinet,gl-ar300m16) HW="ar300m16" ;;
|
|
cudy,wr3000-v1) HW="wr3000" ;;
|
|
*) HW="${HW:-unknown}" ;;
|
|
esac
|
|
|
|
FW_VERSION=$(cat /etc/parahub/version 2>/dev/null || echo "unknown")
|
|
PAYLOAD="{\"mac\":\"${MAC}\",\"hostname\":\"${HOSTNAME}\",\"yggdrasil_address\":\"${YGG_ADDR}\",\"firmware_version\":\"${FW_VERSION}\",\"hardware_profile\":\"${HW}\",\"uptime\":${UPTIME},\"private_ssid\":\"${SSID}\",\"firmware_role\":\"${ROLE}\",\"mesh_ip\":\"${MESH_IP}\",\"wg_public_key\":\"${WG_PUBKEY}\"}"
|
|
|
|
RESPONSE=""
|
|
|
|
if [ "$ROLE" = "bee" ]; then
|
|
# Bee: no yggdrasil, use public URL only
|
|
RESPONSE=$(curl -s -m 10 -X POST \
|
|
-H "Content-Type: application/json" \
|
|
-H "Authorization: Bearer ${HEARTBEAT_KEY}" \
|
|
-d "$PAYLOAD" \
|
|
"${PARAHUB_API_PUBLIC}" 2>/dev/null)
|
|
else
|
|
# Bumblebee: try yggdrasil first, fallback to public
|
|
if ping6 -c 1 -W 3 200:abb9:5810:37d3:8a4c:98a6:b82b:969a >/dev/null 2>&1; then
|
|
RESPONSE=$(curl -s -m 10 -X POST \
|
|
-H "Content-Type: application/json" \
|
|
-H "Authorization: Bearer ${HEARTBEAT_KEY}" \
|
|
-d "$PAYLOAD" \
|
|
"${PARAHUB_API_YGG}" 2>/dev/null)
|
|
else
|
|
RESPONSE=$(curl -s -m 10 -X POST \
|
|
-H "Content-Type: application/json" \
|
|
-H "Authorization: Bearer ${HEARTBEAT_KEY}" \
|
|
-d "$PAYLOAD" \
|
|
"${PARAHUB_API_PUBLIC}" 2>/dev/null)
|
|
fi
|
|
fi
|
|
|
|
# Sync paid_clients to speed control (Bumblebee only)
|
|
if [ "$ROLE" != "bee" ] && [ -x /usr/bin/parahub-speed-control ] && [ -n "$RESPONSE" ]; then
|
|
PAID_IPS=$(echo "$RESPONSE" | jsonfilter -e '$.paid_clients[*]' 2>/dev/null)
|
|
# Flush and re-add all paid IPs
|
|
parahub-speed-control flush
|
|
for IP in $PAID_IPS; do
|
|
parahub-speed-control add "$IP"
|
|
done
|
|
fi
|
|
|
|
# VPS gateway auto-configuration (Bumblebee only, skip if Mullvad is configured)
|
|
if [ "$ROLE" != "bee" ] && [ -n "$RESPONSE" ] && [ ! -f /etc/parahub/mullvad_account ]; then
|
|
VPS_ENDPOINT=$(echo "$RESPONSE" | jsonfilter -e '$.vps_gateway.endpoint' 2>/dev/null)
|
|
VPS_PUBKEY=$(echo "$RESPONSE" | jsonfilter -e '$.vps_gateway.public_key' 2>/dev/null)
|
|
VPS_IP=$(echo "$RESPONSE" | jsonfilter -e '$.vps_gateway.assigned_ip' 2>/dev/null)
|
|
VPS_KEEPALIVE=$(echo "$RESPONSE" | jsonfilter -e '$.vps_gateway.keepalive' 2>/dev/null)
|
|
|
|
if [ -n "$VPS_ENDPOINT" ] && [ -n "$VPS_PUBKEY" ] && [ -n "$VPS_IP" ]; then
|
|
/usr/bin/parahub-vps-setup "$VPS_ENDPOINT" "$VPS_PUBKEY" "$VPS_IP" "${VPS_KEEPALIVE:-25}"
|
|
fi
|
|
fi
|