blob: 0a81e2c82f579608454131794f92f8145c9e09bc (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
|
#!/bin/sh
#
# $FreeBSD$
#
# PROVIDE: local_unbound
# REQUIRE: FILESYSTEMS netif resolv
# BEFORE: NETWORKING
# KEYWORD: shutdown
. /etc/rc.subr
name="local_unbound"
desc="local caching forwarding resolver"
rcvar="local_unbound_enable"
command="/usr/sbin/unbound"
extra_commands="anchor configtest reload setup"
start_precmd="local_unbound_prestart"
start_postcmd="local_unbound_poststart"
reload_precmd="local_unbound_configtest"
anchor_cmd="local_unbound_anchor"
configtest_cmd="local_unbound_configtest"
setup_cmd="local_unbound_setup"
pidfile="/var/run/${name}.pid"
load_rc_config $name
: ${local_unbound_workdir:=/var/unbound}
: ${local_unbound_config:=${local_unbound_workdir}/unbound.conf}
: ${local_unbound_flags:="-c ${local_unbound_config}"}
: ${local_unbound_forwardconf:=${local_unbound_workdir}/forward.conf}
: ${local_unbound_anchor:=${local_unbound_workdir}/root.key}
: ${local_unbound_forwarders:=}
do_as_unbound()
{
echo "$@" | su -m unbound
}
#
# Retrieve or update the DNSSEC root anchor
#
local_unbound_anchor()
{
do_as_unbound /usr/sbin/unbound-anchor -a ${local_unbound_anchor}
# we can't trust the exit code - check if the file exists
[ -f ${local_unbound_anchor} ]
}
#
# Check the unbound configuration file
#
local_unbound_configtest()
{
do_as_unbound /usr/sbin/unbound-checkconf ${local_unbound_config}
}
#
# Create the unbound configuration file and update resolv.conf to
# point to unbound.
#
local_unbound_setup()
{
echo "Performing initial setup."
/usr/sbin/local-unbound-setup -n \
-u unbound \
-w ${local_unbound_workdir} \
-c ${local_unbound_config} \
-f ${local_unbound_forwardconf} \
-a ${local_unbound_anchor} \
${local_unbound_forwarders}
}
#
# Before starting, check that the configuration file and root anchor
# exist. If not, attempt to generate them.
#
local_unbound_prestart()
{
# Create configuration file
if [ ! -f ${local_unbound_config} ] ; then
run_rc_command setup
fi
# Retrieve DNSSEC root key
if [ ! -f ${local_unbound_anchor} ] ; then
run_rc_command anchor
fi
}
#
# After starting, wait for Unbound to report that it is ready to avoid
# race conditions with services which require functioning DNS.
#
local_unbound_poststart()
{
local retry=5
echo -n "Waiting for nameserver to start..."
until "${command}-control" status | grep -q "is running" ; do
if [ $((retry -= 1)) -eq 0 ] ; then
echo " giving up"
return 1
fi
echo -n "."
sleep 1
done
echo " good"
}
load_rc_config $name
run_rc_command "$1"
|