travelmate: update to 2.0.5
authorDirk Brenken <dev@brenken.org>
Wed, 11 Aug 2021 17:14:56 +0000 (19:14 +0200)
committerDirk Brenken <dev@brenken.org>
Wed, 11 Aug 2021 17:14:56 +0000 (19:14 +0200)
* support the new travelmate option 'macaddr' to use a pre-defined MAC address (per uplink)
* vpn connections are now handled separately for each uplink
* The autoadd-feature for adding open uplinks will now be limited by the 'trm_maxautoadd' option. The default is '5', '0' disables this limitation.
* more code cleanups und optimizations to reduce the repetitive connection handling workload
* bugfixes regarding multiple radio support
* refine cp detection (no longer write and parse an error file)

Signed-off-by: Dirk Brenken <dev@brenken.org>
net/travelmate/Makefile
net/travelmate/files/travelmate.conf
net/travelmate/files/travelmate.init
net/travelmate/files/travelmate.mail
net/travelmate/files/travelmate.sh
net/travelmate/files/travelmate.vpn

index 00caaf467bd362806fb7735bf017822e35ae3e11..fbe3dc6b652bfa399c6d67e7f35d634ed3b17a0a 100644 (file)
@@ -6,7 +6,7 @@
 include $(TOPDIR)/rules.mk
 
 PKG_NAME:=travelmate
-PKG_VERSION:=2.0.4
+PKG_VERSION:=2.0.5
 PKG_RELEASE:=1
 PKG_LICENSE:=GPL-3.0-or-later
 PKG_MAINTAINER:=Dirk Brenken <dev@brenken.org>
index a27265b7b1029737642a488025cb17afa5ca29e0..6e72ca381d7604a903dcb25239a40f0c9d24f56d 100644 (file)
@@ -6,5 +6,4 @@ config travelmate 'global'
        option trm_netcheck '0'
        option trm_autoadd '0'
        option trm_mail '0'
-       option trm_vpn '0'
        option trm_debug '0'
index 2017ba9331b731fd196192d2d79d374c0e6c8c64..4a11cf63ed7202f1c111fad9f4c2bf29d5106d48 100755 (executable)
@@ -8,23 +8,22 @@
 START=25
 USE_PROCD=1
 
-extra_command "scan" "<radio> Scan for available nearby uplinks"
+extra_command "scan" "[<radio>|<ifname>] Scan for available nearby uplinks"
+extra_command "assoc" "[<radio>|<ifname>] Get MAC adresses of associated wlan stations"
 extra_command "setup" "[<iface>] [<zone>] [<metric>] Setup the travelmate uplink interface, by default 'trm_wwan' with firewall zone 'wan' and metric '100'"
 
 trm_init="/etc/init.d/travelmate"
 trm_script="/usr/bin/travelmate.sh"
 trm_pidfile="/var/run/travelmate.pid"
 
-boot()
-{
+boot() {
        if [ -s "${trm_pidfile}" ]; then
                : >"${trm_pidfile}"
        fi
        rc_procd start_service
 }
 
-start_service()
-{
+start_service() {
        if "${trm_init}" enabled; then
                if [ "${action}" = "boot" ]; then
                        return 0
@@ -39,8 +38,7 @@ start_service()
        fi
 }
 
-reload_service()
-{
+reload_service() {
        local ppid pid timeout
 
        timeout="$(uci_get travelmate global trm_timeout)"
@@ -56,13 +54,11 @@ reload_service()
        fi
 }
 
-stop_service()
-{
+stop_service() {
        rc_procd "${trm_script}" stop
 }
 
-status_service()
-{
+status_service() {
        local key keylist value rtfile
 
        rtfile="$(uci_get travelmate global trm_rtfile "/tmp/trm_runtime.json")"
@@ -79,29 +75,29 @@ status_service()
        fi
 }
 
-scan()
-{
-       local result scan_dev radio="${1:-"radio0"}"
+scan() {
+       local result scan_name radio="${1}"
 
-       scan_dev="$(ubus -S call network.wireless status 2>/dev/null | jsonfilter -q -l1 -e "@.${radio}.interfaces[0].ifname")"
-       result="$(iwinfo "${scan_dev:-${radio}}" scan 2>/dev/null |
+       if [ -z "${radio}" ]; then
+               scan_name="$(ubus -S call network.wireless status 2>/dev/null | jsonfilter -q -l1 -e '@[@.up=true].interfaces[0].ifname')"
+       fi
+       result="$(iwinfo "${radio:-${scan_name}}" scan 2>/dev/null |
                awk 'BEGIN{FS="[[:space:]]"}/Address:/{var1=$NF}/ESSID:/{var2="";
                for(i=12;i<=NF;i++)if(var2==""){var2=$i}else{var2=var2" "$i}}/Channel:/{var3=$NF}/Quality:/{split($NF,var0,"/")}/Encryption:/{var4="";
                for(j=12;j<=NF;j++)if(var4==""){var4=$j}else{var4=var4" "$j};printf "    %-11i%-10s%-35s%-20s%s\n",(var0[1]*100/var0[2]),var3,var2,var1,var4}' |
                sort -rn)"
-       printf '%s\n' "::: Available nearby uplinks on '${scan_dev:-${radio}}'"
-       printf '%s\n' ":::"
+       printf "%s\n" "::: Available nearby uplinks on '${radio:-${scan_name}}'"
+       printf "%s\n" ":::"
        if [ -n "${result}" ]; then
-               printf '%-15s%-10s%-35s%-20s%s\n' "    Strength" "Channel" "ESSID" "BSSID" "Encryption"
-               printf '%s\n' "    --------------------------------------------------------------------------------------"
-               printf '%s\n' "${result}"
+               printf "%-15s%-10s%-35s%-20s%s\n" "    Strength" "Channel" "ESSID" "BSSID" "Encryption"
+               printf "%s\n" "    --------------------------------------------------------------------------------------"
+               printf "%s\n" "${result}"
        else
-               printf '%s\n' "::: No scan results"
+               printf "%s\n" "::: Empty resultset"
        fi
 }
 
-setup()
-{
+setup() {
        local iface cnt=0 input="${1:-"trm_wwan"}" zone="${2:-"wan"}" metric="${3:-"100"}"
 
        iface="$(uci_get travelmate global trm_iface)"
@@ -165,8 +161,25 @@ setup()
        fi
 }
 
-service_triggers()
-{
+assoc() {
+       local result assoc_name radio="${1}"
+
+       if [ -z "${radio}" ]; then
+               assoc_name="$(ubus -S call network.wireless status 2>/dev/null | jsonfilter -q -l1 -e '@[@.*.*.config.mode="ap"].interfaces[0].ifname')"
+       fi
+       result="$(iwinfo "${radio:-${assoc_name}}" assoc 2>/dev/null | awk '/^[A-Z0-9:]+/{printf "    %s\n",$1}')"
+       printf "%s\n" "::: Associated wlan stations on '${radio:-${assoc_name}}'"
+       printf "%s\n" ":::"
+       if [ -n "${result}" ]; then
+               printf "%s\n" "    MAC addresses"
+               printf "%s\n" "    -----------------"
+               printf "%s\n" "${result}"
+       else
+               printf "%s\n" "::: Empty resultset"
+       fi
+}
+
+service_triggers() {
        local iface delay
 
        iface="$(uci_get travelmate global trm_iface)"
index ec789625aa90d6c11581fe4678ed1789dcd3741e..10f7da4ca2c476b5e52b16bd713c8215b2e0393c 100755 (executable)
@@ -39,21 +39,21 @@ fi
 #
 sys_info="$(
        strings /etc/banner 2>/dev/null
-       ubus call system board | sed -e 's/\"release\": {//' | sed -e 's/^[ \t]*//' | sed -e 's/[{}\",]//g' | sed -e 's/[ ]/  \t/' | sed '/^$/d' 2>/dev/null
+       ubus call system board | awk 'BEGIN{FS="[{}\"]"}{if($2=="kernel"||$2=="hostname"||$2=="system"||$2=="model"||$2=="description")printf "  + %-12s: %s\n",$2,$4}'
 )"
 trm_info="$(/etc/init.d/travelmate status 2>/dev/null)"
-sta_info="$(jsonfilter -i "${trm_rtfile}" -l1 -e '@.data.station_id')"
+sta_info="$(jsonfilter -i "${trm_rtfile}" -q -l1 -e '@.data.station_id')"
 trm_mailtopic="$(uci_get travelmate global trm_mailtopic "travelmate connection to '${sta_info}'")"
-trm_mailhead="From: ${trm_mailsender}\\nTo: ${trm_mailreceiver}\\nSubject: ${trm_mailtopic}\\nReply-to: ${trm_mailsender}\\nMime-Version: 1.0\\nContent-Type: text/html; charset=UTF-8\\nContent-Disposition: inline\\n\\n"
+trm_mailhead="From: ${trm_mailsender}\nTo: ${trm_mailreceiver}\nSubject: ${trm_mailtopic}\nReply-to: ${trm_mailsender}\nMime-Version: 1.0\nContent-Type: text/html;charset=utf-8\nContent-Disposition: inline\n\n"
 
 # mail body
 #
 trm_mailtext="<html><body><pre style='display:block;font-family:monospace;font-size:1rem;padding:20;background-color:#f3eee5;white-space:pre'>"
-trm_mailtext="${trm_mailtext}\\n<strong>++\\n++ System Information ++\\n++</strong>\\n${sys_info}"
-trm_mailtext="${trm_mailtext}\\n\\n<strong>++\\n++ Travelmate Information ++\\n++</strong>\\n${trm_info}"
+trm_mailtext="${trm_mailtext}\n<strong>++\n++ System Information ++\n++</strong>\n${sys_info}"
+trm_mailtext="${trm_mailtext}\n\n<strong>++\n++ Travelmate Information ++\n++</strong>\n${trm_info}"
 trm_mailtext="${trm_mailtext}</pre></body></html>"
 
 # send mail
 #
 printf "%b" "${trm_mailhead}${trm_mailtext}" 2>/dev/null | "${trm_mailpgm}" ${debug} -a "${trm_mailprofile}" "${trm_mailreceiver}" >/dev/null 2>&1
-"${trm_logger}" -p "info" -t "trm-mail [${$}]" "mail sent to '${trm_mailreceiver}' with rc '${?}'"  2>/dev/null
+"${trm_logger}" -p "info" -t "trm-mail [${$}]" "mail sent to '${trm_mailreceiver}' with rc '${?}'" 2>/dev/null
index cd4313989ee57a99a58adbdb9e16b05a6a230ab7..2bfdbecc99dc6948b0157590d94145380a752757 100755 (executable)
@@ -10,28 +10,29 @@ export LC_ALL=C
 export PATH="/usr/sbin:/usr/bin:/sbin:/bin"
 set -o pipefail
 
-trm_ver="2.0.4"
-trm_enabled=0
-trm_debug=0
+trm_ver="2.0.5"
+trm_enabled="0"
+trm_debug="0"
 trm_iface=""
-trm_captive=1
-trm_proactive=1
-trm_netcheck=0
-trm_autoadd=0
-trm_randomize=0
-trm_mail=0
-trm_vpn=0
+trm_captive="1"
+trm_proactive="1"
+trm_netcheck="0"
+trm_autoadd="0"
+trm_randomize="0"
+trm_mail="0"
 trm_mailpgm="/etc/travelmate/travelmate.mail"
 trm_vpnpgm="/etc/travelmate/travelmate.vpn"
-trm_vpnservice=""
-trm_scanbuffer=1024
-trm_minquality=35
-trm_maxretry=3
-trm_maxwait=30
-trm_timeout=60
+trm_scanbuffer="1024"
+trm_minquality="35"
+trm_maxretry="3"
+trm_maxwait="30"
+trm_maxautoadd="5"
+trm_timeout="60"
+trm_opensta="0"
 trm_radio=""
 trm_connection=""
 trm_wpaflags=""
+trm_uplinkcfg=""
 trm_rtfile="/tmp/trm_runtime.json"
 trm_wifi="$(command -v wifi)"
 trm_fetch="$(command -v curl)"
@@ -49,60 +50,45 @@ trm_action="${1:-"start"}"
 
 # load travelmate environment
 #
-f_env()
-{
+f_env() {
        local IFS check wpa_checks ubus_check result
 
-       # do nothing on stop
-       #
        if [ "${trm_action}" = "stop" ]; then
                return
        fi
 
-       # (re-)initialize global list variables
-       #
-       unset trm_stalist trm_radiolist trm_uplinklist trm_wpaflags trm_activesta
+       unset trm_stalist trm_radiolist trm_uplinklist trm_uplinkcfg trm_wpaflags trm_activesta trm_opensta
 
-       # get system information
-       #
        trm_sysver="$(ubus -S call system board 2>/dev/null | jsonfilter -q -e '@.model' -e '@.release.description' |
-               awk 'BEGIN{ORS=", "}{print $0}' | awk '{print substr($0,1,length($0)-2)}')"
+               awk 'BEGIN{RS="";FS="\n"}{printf "%s, %s",$1,$2}')"
 
-       # check travelmate config
-       #
-       if [ ! -r "/etc/config/travelmate" ] || [ -z "$(uci -q show travelmate.global.trm_vpn)" ]; then
-               f_log "err" "invalid travelmate config, please re-install the package via opkg with the '--force-reinstall --force-maintainer' options"
-       fi
-
-       # load travelmate config
-       #
-       config_cb()
-       {
+       config_cb() {
                local name="${1}" type="${2}"
+
                if [ "${name}" = "travelmate" ] && [ "${type}" = "global" ]; then
-                       option_cb()
-                       {
+                       option_cb() {
                                local option="${1}" value="${2}"
                                eval "${option}=\"${value}\""
                        }
+               elif [ "${name}" = "uplink" ]; then
+                       if [ "$(uci_get "travelmate.${type}.opensta")" = "1" ]; then
+                               eval "trm_opensta=\"$((${trm_opensta:-0} + 1))\""
+                       else
+                               eval "trm_opensta=\"${trm_opensta:-0}\""
+                       fi
                else
-                       option_cb()
-                       {
+                       option_cb() {
                                return 0
                        }
                fi
        }
        config_load travelmate
 
-       # check 'enabled' option
-       #
        if [ "${trm_enabled}" != "1" ]; then
                f_log "info" "travelmate is currently disabled, please set 'trm_enabled' to '1' to use this service"
                /etc/init.d/travelmate stop
        fi
 
-       # check ubus network interface
-       #
        if [ -n "${trm_iface}" ]; then
                ubus_check="$(ubus -t "${trm_maxwait}" wait_for network.wireless network.interface."${trm_iface}" 2>&1)"
                if [ -n "${ubus_check}" ]; then
@@ -114,42 +100,25 @@ f_env()
                /etc/init.d/travelmate stop
        fi
 
-       # check wpa capabilities
-       #
        wpa_checks="sae owe eap suiteb192"
        for check in ${wpa_checks}; do
                if [ -x "${trm_wpa}" ]; then
-                       result="$(
-                               "${trm_wpa}" -v${check} >/dev/null 2>&1
-                               printf "%u" "${?}"
-                       )"
-                       if [ -z "${trm_wpaflags}" ]; then
-                               if [ "${result}" = "0" ]; then
-                                       trm_wpaflags="${check}: $(f_char 1)"
-                               else
-                                       trm_wpaflags="${check}: $(f_char 0)"
-                               fi
+                       if "${trm_wpa}" -v"${check}" >/dev/null 2>&1; then
+                               result="$(f_trim "${result} ${check}: $(f_char 1)")"
                        else
-                               if [ "${result}" = "0" ]; then
-                                       trm_wpaflags="$(f_trim "${trm_wpaflags}, ${check}: $(f_char 1)")"
-                               else
-                                       trm_wpaflags="$(f_trim "${trm_wpaflags}, ${check}: $(f_char 0)")"
-                               fi
+                               result="$(f_trim "${result} ${check}: $(f_char 0)")"
                        fi
                fi
        done
+       trm_wpaflags="$(printf "%s" "${result}" | awk '{printf "%s %s, %s %s, %s %s, %s %s",$1,$2,$3,$4,$5,$6,$7,$8}')"
 
-       # get and enable wifi devices
-       #
        config_load wireless
-       config_foreach f_prepdev wifi-device
+       config_foreach f_setdev "wifi-device"
        if [ -n "$(uci -q changes "wireless")" ]; then
                uci_commit "wireless"
-               f_reconf
+               f_wifi
        fi
 
-       # load json runtime file
-       #
        json_load_file "${trm_rtfile}" >/dev/null 2>&1
 
        if ! json_select data >/dev/null 2>&1; then
@@ -157,13 +126,12 @@ f_env()
                json_init
                json_add_object "data"
        fi
-       f_log "debug" "f_env     ::: wpa_flags: ${trm_wpaflags}, sys_ver: ${trm_sysver}"
+       f_log "debug" "f_env    ::: auto_sta: ${trm_opensta:-"-"}, wpa_flags: ${trm_wpaflags}, sys_ver: ${trm_sysver}"
 }
 
 # trim helper function
 #
-f_trim()
-{
+f_trim() {
        local IFS trim="${1}"
 
        trim="${trim#"${trim%%[![:space:]]*}"}"
@@ -173,9 +141,8 @@ f_trim()
 
 # status helper function
 #
-f_char()
-{
-       local result input="${1}"
+f_char() {
+       local IFS result input="${1}"
 
        if [ "${input}" = "1" ]; then
                result="✔"
@@ -185,11 +152,10 @@ f_char()
        printf "%s" "${result}"
 }
 
-# wifi reconf helper function
+# wifi helper function
 #
-f_reconf()
-{
-       local radio tmp_radio cnt="0"
+f_wifi() {
+       local IFS radio tmp_radio cnt="0"
 
        "${trm_wifi}" reconf
        for radio in ${trm_radiolist}; do
@@ -205,110 +171,103 @@ f_reconf()
                        sleep 1
                done
        done
-       f_log "debug" "f_reconf  ::: radio_list: ${trm_radiolist}, radio: ${radio}, cnt: ${cnt}"
+       f_log "debug" "f_wifi   ::: radio_list: ${trm_radiolist}, radio: ${radio}, cnt: ${cnt}"
 }
 
 # vpn helper function
 #
-f_vpn()
-{
-       local IFS rc action="${1}"
-
-       if [ "${trm_vpn}" = "1" ] && [ -x "${trm_vpnpgm}" ]; then
-               if [ "${action}" = "disable" ] || {
-                       [ "${action}" = "enable" ] && [ ! -f "${trm_vpnfile}" ]
-               }; then
-                       "${trm_vpnpgm}" "${action}" >/dev/null 2>&1
+f_vpn() {
+       local IFS rc vpn vpn_service vpn_iface vpn_action="${1}"
+
+       vpn="$(f_getval "vpn")"
+
+       if [ -n "${vpn}" ] && [ -x "${trm_vpnpgm}" ]; then
+               vpn_service="$(f_getval "vpnservice")"
+               vpn_iface="$(f_getval "vpniface")"
+               if [ -n "${vpn_service}" ] && [ -n "${vpn_iface}" ] &&
+                       { [ "${vpn_action}" = "disable" ] || { [ "${vpn}" = "1" ] && [ "${vpn_action}" = "enable" ] && [ ! -f "${trm_vpnfile}" ]; } ||
+                               { [ "${vpn}" = "0" ] && [ "${vpn_action}" = "enable" ] && [ -f "${trm_vpnfile}" ]; }; }; then
+                       "${trm_vpnpgm}" "${vpn}" "${vpn_action}" "${vpn_service}" "${vpn_iface}" >/dev/null 2>&1
                        rc="${?}"
                fi
-               if [ "${action}" = "enable" ] && [ "${rc}" = "0" ]; then
+               if [ "${vpn}" = "1" ] && [ "${vpn_action}" = "enable" ] && [ "${rc}" = "0" ]; then
                        : >"${trm_vpnfile}"
-               elif [ "${action}" = "disable" ] && [ -f "${trm_vpnfile}" ]; then
+               elif { [ "${vpn}" = "0" ] || [ "${vpn_action}" = "disable" ]; } && [ -f "${trm_vpnfile}" ]; then
                        rm -f "${trm_vpnfile}"
                fi
        fi
-       f_log "debug" "f_vpn     ::: vpn: ${trm_vpn}, vpnservice: ${trm_vpnservice:-"-"}, vpnpgm: ${trm_vpnpgm}, action: ${action}, rc: ${rc:-"-"}"
+       f_log "debug" "f_vpn    ::: vpn_enabled: ${vpn:-"-"}, vpn_action: ${vpn_action}, vpn_service: ${vpn_service:-"-"}, vpn_iface: ${vpn_iface:-"-"}, rc: ${rc:-"-"}, vpn_program: ${trm_vpnpgm}"
 }
 
-# mac randomizer helper function
+# mac helper function
 #
-f_mac()
-{
-       local result ifname action="${1}" section="${2}"
-
-       if [ "${trm_randomize}" = "1" ] && [ "${action}" = "set" ]; then
-               result="$(hexdump -n6 -ve '/1 "%.02X "' /dev/random 2>/dev/null |
-                       awk -v local="2,6,A,E" -v seed="$(date +%s)" 'BEGIN{srand(seed)}NR==1{split(local,b,",");seed=int(rand()*4+1);printf "%s%s:%s:%s:%s:%s:%s",substr($1,0,1),b[seed],$2,$3,$4,$5,$6}')"
-               uci_set "wireless" "${section}" "macaddr" "${result}"
-       else
-               result="$(uci_get "wireless" "${section}" "macaddr")"
-               if [ -z "${result}" ]; then
-                       ifname="$(ubus -S call network.wireless status 2>/dev/null | jsonfilter -q -l1 -e '@.*.interfaces[@.config.mode="sta"].ifname')"
-                       result="$(${trm_iwinfo} "${ifname}" info 2>/dev/null | awk '/Access Point:/{printf "%s",$3}')"
+f_mac() {
+       local IFS result ifname macaddr action="${1}" section="${2}"
+
+       if [ "${action}" = "set" ]; then
+               macaddr="$(f_getval "macaddr")"
+               if [ -n "${macaddr}" ]; then
+                       result="${macaddr}"
+                       uci_set "wireless" "${section}" "macaddr" "${result}"
+               elif [ "${trm_randomize}" = "1" ]; then
+                       result="$(hexdump -n6 -ve '/1 "%.02X "' /dev/random 2>/dev/null |
+                               awk -v local="2,6,A,E" -v seed="$(date +%s)" 'BEGIN{srand(seed)}NR==1{split(local,b,",");seed=int(rand()*4+1);printf "%s%s:%s:%s:%s:%s:%s",substr($1,0,1),b[seed],$2,$3,$4,$5,$6}')"
+                       uci_set "wireless" "${section}" "macaddr" "${result}"
+               else
+                       result="$(uci_get "wireless" "${section}" "macaddr")"
                fi
+       elif [ "${action}" = "get" ]; then
+               result="$(uci_get "wireless" "${section}" "macaddr")"
        fi
        printf "%s" "${result}"
-       f_log "debug" "f_mac     ::: action: ${action:-"-"}, section: ${section:-"-"}, mac: ${result:-"-"}"
+       f_log "debug" "f_mac    ::: action: ${action:-"-"}, section: ${section:-"-"}, macaddr: ${macaddr:-"-"}, result: ${result:-"-"}"
 }
 
-# track/set travelmate connection information
+# set connection information
 #
-f_contrack()
-{
-       local uplink_config radio_config essid_config bssid_config expiry action="${1}" radio="${2}" essid="${3}" bssid="${4}" cnt=0
-
-       while [ "$(
-               uci_get "travelmate" "@uplink[$cnt]" >/dev/null 2>&1
-               echo $?
-       )" = "0" ]; do
-               radio_config="$(uci_get "travelmate" "@uplink[$cnt]" "device")"
-               essid_config="$(uci_get "travelmate" "@uplink[$cnt]" "ssid")"
-               bssid_config="$(uci_get "travelmate" "@uplink[$cnt]" "bssid")"
-               if [ "${radio_config}" = "${radio}" ] && [ "${essid_config}" = "${essid}" ] && [ "${bssid_config}" = "${bssid}" ]; then
-                       uplink_config="@uplink[$cnt]"
-               fi
-               cnt="$((cnt + 1))"
-       done
-       if [ -n "${uplink_config}" ]; then
+f_ctrack() {
+       local IFS expiry action="${1}"
+
+       if [ -n "${trm_uplinkcfg}" ]; then
                case "${action}" in
                        "start")
-                               uci_remove "travelmate" "${uplink_config}" "con_start" 2>/dev/null
-                               uci_remove "travelmate" "${uplink_config}" "con_end" 2>/dev/null
+                               uci_remove "travelmate" "${trm_uplinkcfg}" "con_start" 2>/dev/null
+                               uci_remove "travelmate" "${trm_uplinkcfg}" "con_end" 2>/dev/null
                                if [ -f "${trm_ntpfile}" ]; then
-                                       uci_set "travelmate" "${uplink_config}" "con_start" "$(date "+%Y.%m.%d-%H:%M:%S")"
+                                       uci_set "travelmate" "${trm_uplinkcfg}" "con_start" "$(date "+%Y.%m.%d-%H:%M:%S")"
                                fi
                                ;;
                        "refresh")
-                               if [ -f "${trm_ntpfile}" ] && [ -z "$(uci_get "travelmate" "${uplink_config}" "con_start")" ]; then
-                                       uci_set "travelmate" "${uplink_config}" "con_start" "$(date "+%Y.%m.%d-%H:%M:%S")"
+                               if [ -f "${trm_ntpfile}" ] && [ -z "$(uci_get "travelmate" "${trm_uplinkcfg}" "con_start")" ]; then
+                                       uci_set "travelmate" "${trm_uplinkcfg}" "con_start" "$(date "+%Y.%m.%d-%H:%M:%S")"
                                fi
                                ;;
                        "end")
                                if [ -f "${trm_ntpfile}" ]; then
-                                       uci_set "travelmate" "${uplink_config}" "con_end" "$(date "+%Y.%m.%d-%H:%M:%S")"
+                                       uci_set "travelmate" "${trm_uplinkcfg}" "con_end" "$(date "+%Y.%m.%d-%H:%M:%S")"
                                fi
                                ;;
                        "start_expiry")
                                if [ -f "${trm_ntpfile}" ]; then
-                                       expiry="$(uci_get "travelmate" "${uplink_config}" "con_start_expiry")"
-                                       uci_set "travelmate" "${uplink_config}" "enabled" "0"
-                                       uci_set "travelmate" "${uplink_config}" "con_end" "$(date "+%Y.%m.%d-%H:%M:%S")"
+                                       expiry="$(uci_get "travelmate" "${trm_uplinkcfg}" "con_start_expiry")"
+                                       uci_set "travelmate" "${trm_uplinkcfg}" "enabled" "0"
+                                       uci_set "travelmate" "${trm_uplinkcfg}" "con_end" "$(date "+%Y.%m.%d-%H:%M:%S")"
                                        f_log "info" "uplink '${radio}/${essid}/${bssid:-"-"}' expired after ${expiry} minutes"
                                fi
                                ;;
                        "end_expiry")
                                if [ -f "${trm_ntpfile}" ]; then
-                                       expiry="$(uci_get "travelmate" "${uplink_config}" "con_end_expiry")"
-                                       uci_set "travelmate" "${uplink_config}" "enabled" "1"
-                                       uci_remove "travelmate" "${uplink_config}" "con_start" 2>/dev/null
-                                       uci_remove "travelmate" "${uplink_config}" "con_end" 2>/dev/null
+                                       expiry="$(uci_get "travelmate" "${trm_uplinkcfg}" "con_end_expiry")"
+                                       uci_set "travelmate" "${trm_uplinkcfg}" "enabled" "1"
+                                       uci_remove "travelmate" "${trm_uplinkcfg}" "con_start" 2>/dev/null
+                                       uci_remove "travelmate" "${trm_uplinkcfg}" "con_end" 2>/dev/null
                                        f_log "info" "uplink '${radio}/${essid}/${bssid:-"-"}' re-enabled after ${expiry} minutes"
                                fi
                                ;;
                        "disabled")
-                               uci_set "travelmate" "${uplink_config}" "enabled" "0"
+                               uci_set "travelmate" "${trm_uplinkcfg}" "enabled" "0"
                                if [ -f "${trm_ntpfile}" ]; then
-                                       uci_set "travelmate" "${uplink_config}" "con_end" "$(date "+%Y.%m.%d-%H:%M:%S")"
+                                       uci_set "travelmate" "${trm_uplinkcfg}" "con_end" "$(date "+%Y.%m.%d-%H:%M:%S")"
                                fi
                                ;;
                esac
@@ -319,112 +278,61 @@ f_contrack()
                        fi
                fi
        fi
+       f_log "debug" "f_ctrack ::: action: ${action:-"-"}, uplink_config: ${trm_uplinkcfg:-"-"}"
 }
 
-# get/match travelmate uplink option
+# get uplink config section
 #
-f_uplink()
-{
-       local IFS result t_radio t_essid t_bssid t_option="${1}" w_radio="${2}" w_essid="${3}" w_bssid="${4}" cnt=0
-
-       while [ "$(
-               uci_get "travelmate" "@uplink[$cnt]" >/dev/null 2>&1
-               echo $?
-       )" = "0" ]; do
-               t_radio="$(uci_get "travelmate" "@uplink[$cnt]" "device")"
-               t_essid="$(uci_get "travelmate" "@uplink[$cnt]" "ssid")"
-               t_bssid="$(uci_get "travelmate" "@uplink[$cnt]" "bssid")"
-               if [ -n "${w_radio}" ] && [ -n "${w_essid}" ] &&
-                       [ "${t_radio}" = "${w_radio}" ] && [ "${t_essid}" = "${w_essid}" ] && [ "${t_bssid}" = "${w_bssid}" ]; then
-                       result="$(uci_get "travelmate" "@uplink[$cnt]" "${t_option}")"
+f_getcfg() {
+       local IFS t_radio t_essid t_bssid radio="${1}" essid="${2}" bssid="${3}" cnt="0"
+
+       while uci_get "travelmate" "@uplink[${cnt}]" >/dev/null 2>&1; do
+               t_radio="$(uci_get "travelmate" "@uplink[${cnt}]" "device")"
+               t_essid="$(uci_get "travelmate" "@uplink[${cnt}]" "ssid")"
+               t_bssid="$(uci_get "travelmate" "@uplink[${cnt}]" "bssid")"
+               if [ -n "${radio}" ] && [ -n "${essid}" ] &&
+                       [ "${t_radio}" = "${radio}" ] && [ "${t_essid}" = "${essid}" ] && [ "${t_bssid}" = "${bssid}" ]; then
+                       trm_uplinkcfg="@uplink[${cnt}]"
                        break
                fi
                cnt="$((cnt + 1))"
        done
-       printf "%s" "${result}"
-       f_log "debug" "f_uplink  ::: option: ${t_option}, result: ${result}"
+       f_log "debug" "f_getcfg ::: status: ${status}, section: ${section}, active_sta: ${trm_activesta:-"-"}, uplink_config: ${trm_uplinkcfg:-"-"}"
 }
 
-# prepare the 'wifi-device' sections
+# get travelmate option value in 'uplink' sections
 #
-f_prepdev()
-{
+f_getval() {
+       local IFS result t_option="${1}"
+
+       if [ -n "${trm_uplinkcfg}" ]; then
+               result="$(uci_get "travelmate" "${trm_uplinkcfg}" "${t_option}")"
+               printf "%s" "${result}"
+       fi
+       f_log "debug" "f_getval ::: option: ${t_option:-"-"}, result: ${result:-"-"}, uplink_config: ${trm_uplinkcfg:-"-"}"
+}
+
+# set 'wifi-device' sections
+#
+f_setdev() {
        local IFS disabled radio="${1}"
 
        disabled="$(uci_get "wireless" "${radio}" "disabled")"
        if [ "${disabled}" = "1" ]; then
-               uci_set wireless "${radio}" disabled 0
+               uci_set wireless "${radio}" "disabled" "0"
        fi
 
-       if [ -z "${trm_radio}" ] && ! printf "%s" "${trm_radiolist}" | grep -q "${radio}"; then
+       if [ -n "${trm_radio}" ] && [ -z "${trm_radiolist}" ]; then
+               trm_radiolist="${trm_radio}"
+       elif [ -z "${trm_radio}" ] && ! printf "%s" "${trm_radiolist}" | grep -q "${radio}"; then
                trm_radiolist="$(f_trim "${trm_radiolist} ${radio}")"
-       elif [ -n "${trm_radio}" ] && [ -z "${trm_radiolist}" ]; then
-               trm_radiolist="$(f_trim "$(printf "%s" "${trm_radio}" |
-                       awk '{while(match(tolower($0),/[a-z0-9_]+/)){ORS=" ";print substr(tolower($0),RSTART,RLENGTH);$0=substr($0,RSTART+RLENGTH)}}')")"
-       fi
-       f_log "debug" "f_prepdev ::: trm_radio: ${trm_radio:-"-"}, radio: ${radio}, radio_list: ${trm_radiolist:-"-"}, disabled: ${disabled:-"-"}"
-}
-
-# add open uplink to new 'wifi-iface' section
-#
-f_addif()
-{
-       local IFS uci_cfg offset=1 radio="${1}" essid="${2}"
-
-       config_cb()
-       {
-               local type="${1}" name="${2}"
-               if [ "${type}" = "wifi-iface" ]; then
-                       if [ "$(uci -q get "wireless.${name}.ssid")" = "${essid}" ]; then
-                               offset=0
-                       elif [ "${offset}" != "0" ]; then
-                               offset="$((offset + 1))"
-                       fi
-               fi
-               return "${offset}"
-       }
-       config_load wireless
-
-       if [ "${offset}" != "0" ]; then
-               uci_cfg="trm_uplink${offset}"
-               while [ -n "$(uci -q get "wireless.${uci_cfg}")" ]; do
-                       offset="$((offset + 1))"
-                       uci_cfg="trm_uplink${offset}"
-               done
-               uci -q batch <<-EOC
-                       set wireless."${uci_cfg}"="wifi-iface"
-                       set wireless."${uci_cfg}".mode="sta"
-                       set wireless."${uci_cfg}".network="${trm_iface}"
-                       set wireless."${uci_cfg}".device="${radio}"
-                       set wireless."${uci_cfg}".ssid="${essid}"
-                       set wireless."${uci_cfg}".encryption="none"
-                       set wireless."${uci_cfg}".disabled="1"
-               EOC
-               uci_cfg="$(uci -q add travelmate uplink)"
-               uci -q batch <<-EOC
-                       set travelmate."${uci_cfg}".device="${radio}"
-                       set travelmate."${uci_cfg}".ssid="${essid}"
-                       set travelmate."${uci_cfg}".con_start_expiry="0"
-                       set travelmate."${uci_cfg}".con_end_expiry="0"
-                       set travelmate."${uci_cfg}".enabled="1"
-               EOC
-               if [ -n "$(uci -q changes "travelmate")" ] || [ -n "$(uci -q changes "wireless")" ]; then
-                       uci_commit "travelmate"
-                       uci_commit "wireless"
-                       f_reconf
-                       if [ ! -f "${trm_refreshfile}" ]; then
-                               printf "%s" "ui_reload" >"${trm_refreshfile}"
-                       fi
-                       f_log "info" "open uplink '${radio}/${essid}' added to wireless config"
-               fi
        fi
-       f_log "debug" "f_addif   ::: radio: ${radio:-"-"}, essid: ${essid}, offset: ${offset:-"-"}"
+       f_log "debug" "f_setdev ::: radio: ${radio:-"-"}, radio_list(cnf/cur): ${trm_radio:-"-"}/${trm_radiolist:-"-"}, disabled: ${disabled:-"-"}"
 }
 
-# prepare the 'wifi-iface' sections
+# set 'wifi-iface' sections
 #
-f_prepif()
-{
+f_setif() {
        local IFS mode radio essid bssid disabled status con_start con_end con_start_expiry con_end_expiry section="${1}" proactive="${2}"
 
        mode="$(uci_get "wireless" "${section}" "mode")"
@@ -432,11 +340,14 @@ f_prepif()
        essid="$(uci_get "wireless" "${section}" "ssid")"
        bssid="$(uci_get "wireless" "${section}" "bssid")"
        disabled="$(uci_get "wireless" "${section}" "disabled")"
-       status="$(f_uplink "enabled" "${radio}" "${essid}" "${bssid}")"
-       con_start="$(f_uplink "con_start" "${radio}" "${essid}" "${bssid}")"
-       con_end="$(f_uplink "con_end" "${radio}" "${essid}" "${bssid}")"
-       con_start_expiry="$(f_uplink "con_start_expiry" "${radio}" "${essid}" "${bssid}")"
-       con_end_expiry="$(f_uplink "con_end_expiry" "${radio}" "${essid}" "${bssid}")"
+
+       f_getcfg "${radio}" "${essid}" "${bssid}"
+
+       status="$(f_getval "enabled")"
+       con_start="$(f_getval "con_start")"
+       con_end="$(f_getval "con_end")"
+       con_start_expiry="$(f_getval "con_start_expiry")"
+       con_end_expiry="$(f_getval "con_end_expiry")"
 
        if [ "${status}" = "0" ] && [ -n "${con_end}" ] && [ -n "${con_end_expiry}" ] && [ "${con_end_expiry}" != "0" ]; then
                d1="$(date -d "${con_end}" "+%s")"
@@ -444,7 +355,7 @@ f_prepif()
                d3="$(((d2 - d1) / 60))"
                if [ "${d3}" -ge "${con_end_expiry}" ]; then
                        status="1"
-                       f_contrack "end_expiry" "${radio}" "${essid}" "${bssid}"
+                       f_ctrack "end_expiry"
                fi
        elif [ "${status}" = "1" ] && [ -n "${con_start}" ] && [ -n "${con_start_expiry}" ] && [ "${con_start_expiry}" != "0" ]; then
                d1="$(date -d "${con_start}" "+%s")"
@@ -452,19 +363,13 @@ f_prepif()
                d3="$((d1 + (con_start_expiry * 60)))"
                if [ "${d2}" -gt "${d3}" ]; then
                        status="0"
-                       f_contrack "start_expiry" "${radio}" "${essid}" "${bssid}"
+                       f_ctrack "start_expiry"
                fi
        fi
 
        if [ "${mode}" = "sta" ]; then
-               if [ "${status}" = "0" ] ||
-                       {
-                               {
-                                       [ -z "${disabled}" ] || [ "${disabled}" = "0" ]
-                               } && {
-                                       [ "${proactive}" = "0" ] || [ "${trm_ifstatus}" != "true" ]
-                               }
-                       }; then
+               if [ "${status}" = "0" ] || { { [ -z "${disabled}" ] || [ "${disabled}" = "0" ]; } &&
+                       { [ "${proactive}" = "0" ] || [ "${trm_ifstatus}" != "true" ]; }; }; then
                        uci_set "wireless" "${section}" "disabled" "1"
                elif [ "${disabled}" = "0" ] && [ "${trm_ifstatus}" = "true" ] && [ "${proactive}" = "1" ]; then
                        if [ -z "${trm_activesta}" ]; then
@@ -477,52 +382,113 @@ f_prepif()
                        trm_stalist="$(f_trim "${trm_stalist} ${section}-${radio}")"
                fi
        fi
-       f_log "debug" "f_prepif  ::: status: ${status}, section: ${section}, active_sta: ${trm_activesta:-"-"}"
+       f_log "debug" "f_setif  ::: status: ${status}, section: ${section}, active_sta: ${trm_activesta:-"-"}, uplink_config: ${trm_uplinkcfg:-"-"}"
+}
+
+# add open uplinks
+#
+f_addsta() {
+       local IFS uci_cfg new_uplink="1" offset="1" radio="${1}" essid="${2}"
+
+
+       if [ "${trm_maxautoadd}" = "0" ] || [ "${trm_opensta}" -lt "${trm_maxautoadd}" ]; then
+               config_cb() {
+                       local type="${1}" name="${2}"
+
+                       if [ "${type}" = "wifi-iface" ]; then
+                               if [ "$(uci_get "wireless.${name}.ssid")" = "${essid}" ] &&
+                                       [ "$(uci_get "wireless.${name}.device")" = "${radio}" ]; then
+                                       new_uplink="0"
+                                       return 0
+                               fi
+                               offset=$((offset + 1))
+                       fi
+               }
+               config_load wireless
+       else
+               new_uplink="0"
+       fi
+
+       if [ "${new_uplink}" = "1" ]; then
+               uci_cfg="trm_uplink$((offset + 1))"
+               while [ -n "$(uci_get "wireless.${uci_cfg}")" ]; do
+                       offset="$((offset + 1))"
+                       uci_cfg="trm_uplink${offset}"
+               done
+               uci -q batch <<-EOC
+                       set wireless."${uci_cfg}"="wifi-iface"
+                       set wireless."${uci_cfg}".mode="sta"
+                       set wireless."${uci_cfg}".network="${trm_iface}"
+                       set wireless."${uci_cfg}".device="${radio}"
+                       set wireless."${uci_cfg}".ssid="${essid}"
+                       set wireless."${uci_cfg}".encryption="none"
+                       set wireless."${uci_cfg}".disabled="1"
+               EOC
+               uci_cfg="$(uci -q add travelmate uplink)"
+               uci -q batch <<-EOC
+                       set travelmate."${uci_cfg}".device="${radio}"
+                       set travelmate."${uci_cfg}".ssid="${essid}"
+                       set travelmate."${uci_cfg}".opensta="1"
+                       set travelmate."${uci_cfg}".con_start_expiry="0"
+                       set travelmate."${uci_cfg}".con_end_expiry="0"
+                       set travelmate."${uci_cfg}".enabled="1"
+               EOC
+               if [ -n "$(uci -q changes "travelmate")" ] || [ -n "$(uci -q changes "wireless")" ]; then
+                       trm_opensta="$((trm_opensta + 1))"
+                       uci_commit "travelmate"
+                       uci_commit "wireless"
+                       f_wifi
+                       if [ ! -f "${trm_refreshfile}" ]; then
+                               printf "%s" "ui_reload" >"${trm_refreshfile}"
+                       fi
+                       f_log "info" "open uplink '${radio}/${essid}' added to wireless config"
+               fi
+       fi
+       f_log "debug" "f_addsta ::: radio: ${radio:-"-"}, essid: ${essid}, opensta/maxautoadd: ${trm_opensta:-"-"}/${trm_maxautoadd:-"-"}, new_uplink: ${new_uplink}, offset: ${offset}"
 }
 
 # check net status
 #
-f_net()
-{
-       local IFS err err_rc err_domain raw html_raw html_cp json_raw json_cp json_rc result="net nok"
+f_net() {
+       local IFS err_msg raw html_raw html_cp json_raw json_ec json_rc json_cp json_ed result="net nok"
 
-       raw="$(${trm_fetch} --user-agent "${trm_useragent}" --referer "http://www.example.com" --header "Cache-Control: no-cache, no-store, must-revalidate" --header "Pragma: no-cache" --header "Expires: 0" --write-out "%{json}" --silent --show-error --connect-timeout $((trm_maxwait / 10)) "${trm_captiveurl}" 2>/tmp/trm_fetch.err)"
+       raw="$(${trm_fetch} --user-agent "${trm_useragent}" --referer "http://www.example.com" --header "Cache-Control: no-cache, no-store, must-revalidate" --header "Pragma: no-cache" --header "Expires: 0" --write-out "%{json}" --silent --connect-timeout $((trm_maxwait / 10)) "${trm_captiveurl}")"
        json_raw="${raw#*\{}"
        html_raw="${raw%%\{*}"
-       if [ -s "/tmp/trm_fetch.err" ]; then
-               err="$(awk 'BEGIN{FS="[()'\'' ]"}{printf "%s %s",$3,$(NF-1)}' "/tmp/trm_fetch.err")"
-               err_rc="${err% *}"
-               err_domain="${err#* }"
-               if [ "${err_rc}" = "6" ]; then
-                       if [ -n "${err_domain}" ] && [ "${err_domain}" != "timed" ] && [ "${err_domain}" != "${trm_captiveurl#http*://*}" ]; then
-                               result="net cp '${err_domain}'"
-                       fi
-               fi
-       elif [ -n "${json_raw}" ]; then
-               json_cp="$(printf "%s" "{${json_raw}" | jsonfilter -q -l1 -e '@.redirect_url' | awk 'BEGIN{FS="/"}{printf "%s",$3}')"
+       if [ -n "${json_raw}" ]; then
+               json_ec="$(printf "%s" "{${json_raw}" | jsonfilter -q -l1 -e '@.exitcode')"
                json_rc="$(printf "%s" "{${json_raw}" | jsonfilter -q -l1 -e '@.response_code')"
-               if [ -n "${json_cp}" ]; then
-                       result="net cp '${json_cp}'"
+               json_cp="$(printf "%s" "{${json_raw}" | jsonfilter -q -l1 -e '@.redirect_url' | awk 'BEGIN{FS="/"}{printf "%s",tolower($3)}')"
+               if [ "${json_ec}" = "0" ]; then
+                       if [ -n "${json_cp}" ]; then
+                               result="net cp '${json_cp}'"
+                       else
+                               if [ "${json_rc}" = "200" ] || [ "${json_rc}" = "204" ]; then
+                                       html_cp="$(printf "%s" "${html_raw}" | awk 'match(tolower($0),/^.*<meta[ \t]+http-equiv=["]*refresh.*[ \t;]url=/){print substr(tolower($0),RLENGTH+1)}' | awk 'BEGIN{FS="[:/]"}{printf "%s",$4;exit}')"
+                                       if [ -n "${html_cp}" ]; then
+                                               result="net cp '${html_cp}'"
+                                       else
+                                               result="net ok"
+                                       fi
+                               fi
+                       fi
                else
-                       if [ "${json_rc}" = "200" ] || [ "${json_rc}" = "204" ]; then
-                               html_cp="$(printf "%s" "${html_raw}" | awk 'match(tolower($0),/^.*<meta[ \t]+http-equiv=["]*refresh.*[ \t;]url=/){print substr(tolower($0),RLENGTH+1)}' | awk 'BEGIN{FS="[:/]"}{printf "%s",$4;exit}')"
-                               if [ -n "${html_cp}" ]; then
-                                       result="net cp '${html_cp}'"
-                               else
-                                       result="net ok"
+                       err_msg="$(printf "%s" "{${json_raw}" | jsonfilter -q -l1 -e '@.errormsg')"
+                       json_ed="$(printf "%s" "{${err_msg}" | awk '/([[:alnum:]_-]{1,63}\.)+[[:alpha:]]+$/{printf "%s",tolower($NF)}')"
+                       if [ "${json_ec}" = "6" ]; then
+                               if [ -n "${json_ed}" ] && [ "${json_ed}" != "${trm_captiveurl#http*://*}" ]; then
+                                       result="net cp '${json_ed}'"
                                fi
                        fi
                fi
        fi
-       rm -f "/tmp/trm_fetch.err"
        printf "%s" "${result}"
-       f_log "debug" "f_net     ::: fetch: ${trm_fetch}, timeout: $((trm_maxwait / 6)), url: ${trm_captiveurl}, user_agent: ${trm_useragent}, cp (json/html): ${json_cp:-"-"}/${html_cp:-"-"}, result: ${result}, error: ${err:-"-"}"
+       f_log "debug" "f_net    ::: fetch: ${trm_fetch}, timeout: $((trm_maxwait / 6)), cp (json/html): ${json_cp:-"-"}/${html_cp:-"-"}, result: ${result}, error: ${err_msg:-"-"}, url: ${trm_captiveurl}, user_agent: ${trm_useragent}"
 }
 
 # check interface status
 #
-f_check()
-{
+f_check() {
        local IFS ifname radio dev_status result login_script login_script_args cp_domain wait_time="1" enabled="1" mode="${1}" status="${2}" sta_radio="${3}" sta_essid="${4}" sta_bssid="${5}"
 
        if [ "${mode}" = "initial" ] || [ "${mode}" = "dev" ]; then
@@ -533,20 +499,15 @@ f_check()
                sta_bssid="${station_id##*/}"
                sta_bssid="${sta_bssid//-/}"
        fi
+       f_getcfg "${sta_radio}" "${sta_essid}" "${sta_bssid}"
+
        if [ "${mode}" != "rev" ] && [ -n "${sta_radio}" ] && [ "${sta_radio}" != "-" ] && [ -n "${sta_essid}" ] && [ "${sta_essid}" != "-" ]; then
-               enabled="$(f_uplink "enabled" "${sta_radio}" "${sta_essid}" "${sta_bssid}")"
+               enabled="$(f_getval "enabled")"
        fi
-       if {
-               [ "${mode}" != "initial" ] && [ "${mode}" != "dev" ] && [ "${status}" = "false" ]
-       } ||
-               {
-                       [ "${mode}" = "dev" ] && {
-                               [ "${status}" = "false" ] || {
-                                       [ "${trm_ifstatus}" != "${status}" ] && [ "${enabled}" = "0" ]
-                               }
-                       }
-               }; then
-               f_reconf
+       if { [ "${mode}" != "initial" ] && [ "${mode}" != "dev" ] && [ "${status}" = "false" ]; } ||
+               { [ "${mode}" = "dev" ] && { [ "${status}" = "false" ] ||
+                       { [ "${trm_ifstatus}" != "${status}" ] && [ "${enabled}" = "0" ]; }; }; }; then
+               f_wifi
        fi
        while [ "${wait_time}" -le "${trm_maxwait}" ]; do
                dev_status="$(ubus -S call network.wireless status 2>/dev/null)"
@@ -582,9 +543,9 @@ f_check()
                                                                if [ -n "${cp_domain}" ] && [ "${trm_captive}" = "1" ]; then
                                                                        trm_connection="${result:-"-"}/${trm_ifquality}"
                                                                        f_jsnup
-                                                                       login_script="$(f_uplink "script" "${sta_radio}" "${sta_essid}" "${sta_bssid}")"
+                                                                       login_script="$(f_getval "script")"
                                                                        if [ -x "${login_script}" ]; then
-                                                                               login_script_args="$(f_uplink "script_args" "${sta_radio}" "${sta_essid}" "${sta_bssid}")"
+                                                                               login_script_args="$(f_getval "script_args")"
                                                                                "${login_script}" ${login_script_args} >/dev/null 2>&1
                                                                                rc="${?}"
                                                                                f_log "info" "captive portal login for '${cp_domain}' has been executed with rc '${rc}'"
@@ -611,7 +572,7 @@ f_check()
                                                        f_vpn "disable"
                                                        unset trm_connection
                                                        trm_ifstatus="${status}"
-                                                       f_contrack "end" "${sta_radio}" "${sta_essid}" "${sta_bssid}"
+                                                       f_ctrack "end"
                                                elif [ "${trm_netcheck}" = "1" ] && [ "${result}" = "net nok" ]; then
                                                        f_log "info" "uplink has no internet (existing connection)"
                                                        f_vpn "disable"
@@ -646,16 +607,16 @@ f_check()
                wait_time="$((wait_time + 1))"
                sleep 1
        done
-       f_log "debug" "f_check   ::: mode: ${mode}, name: ${ifname:-"-"}, status: ${trm_ifstatus}, enabled: ${enabled}, connection: ${trm_connection:-"-"}, wait: ${wait_time}, max_wait: ${trm_maxwait}, min_quality: ${trm_minquality}, captive: ${trm_captive}, netcheck: ${trm_netcheck}"
+       f_log "debug" "f_check  ::: mode: ${mode}, name: ${ifname:-"-"}, status: ${trm_ifstatus}, enabled: ${enabled}, connection: ${trm_connection:-"-"}, wait: ${wait_time}, max_wait: ${trm_maxwait}, min_quality: ${trm_minquality}, captive: ${trm_captive}, netcheck: ${trm_netcheck}"
 }
 
 # update runtime information
 #
-f_jsnup()
-{
-       local IFS section last_date last_station sta_iface sta_radio sta_essid sta_bssid sta_mac dev_status last_status status="${trm_ifstatus}" ntp_done="0" vpn_done="0" mail_done="0"
+f_jsnup() {
+       local IFS vpn section last_date last_station sta_iface sta_radio sta_essid sta_bssid sta_mac dev_status last_status status="${trm_ifstatus}" ntp_done="0" vpn_done="0" mail_done="0"
 
        if [ "${status}" = "true" ]; then
+               vpn="$(f_getval "vpn")"
                status="connected (${trm_connection:-"-"})"
                dev_status="$(ubus -S call network.wireless status 2>/dev/null)"
                if [ -n "${dev_status}" ]; then
@@ -672,12 +633,8 @@ f_jsnup()
                json_get_var last_station "station_id"
                json_get_var last_status "travelmate_status"
 
-               if {
-                       [ -f "${trm_ntpfile}" ] && [ ! -s "${trm_ntpfile}" ]
-               } || [ "${last_status}" = "running (not connected)" ] ||
-                       {
-                               [ -n "${last_station}" ] && [ "${last_station}" != "${sta_radio:-"-"}/${sta_essid:-"-"}/${sta_bssid:-"-"}" ]
-                       }; then
+               if { [ -f "${trm_ntpfile}" ] && [ ! -s "${trm_ntpfile}" ]; } || [ "${last_status}" = "running (not connected)" ] ||
+                       { [ -n "${last_station}" ] && [ "${last_station}" != "${sta_radio:-"-"}/${sta_essid:-"-"}/${sta_bssid:-"-"}" ]; }; then
                        last_date="$(date "+%Y.%m.%d-%H:%M:%S")"
                        if [ -f "${trm_ntpfile}" ] && [ ! -s "${trm_ntpfile}" ]; then
                                printf "%s" "${last_date}" >"${trm_ntpfile}"
@@ -697,7 +654,7 @@ f_jsnup()
        if [ -s "${trm_ntpfile}" ]; then
                ntp_done="1"
        fi
-       if [ "${trm_vpn}" = "1" ] && [ -f "${trm_vpnfile}" ]; then
+       if [ "${vpn}" = "1" ] && [ -f "${trm_vpnfile}" ]; then
                vpn_done="1"
        fi
        if [ "${trm_mail}" = "1" ] && [ -f "${trm_mailfile}" ]; then
@@ -718,7 +675,7 @@ f_jsnup()
        if [ "${status%% (net ok/*}" = "connected" ]; then
                f_vpn "enable"
                if [ "${trm_mail}" = "1" ] && [ -x "${trm_mailpgm}" ] && [ "${ntp_done}" = "1" ] && [ "${mail_done}" = "0" ]; then
-                       if [ "${trm_vpn}" = "0" ] || [ "${vpn_done}" = "1" ]; then
+                       if [ -z "${vpn}" ] || [ "${vpn_done}" = "1" ]; then
                                : >"${trm_mailfile}"
                                "${trm_mailpgm}" >/dev/null 2>&1
                        fi
@@ -726,22 +683,19 @@ f_jsnup()
        else
                f_vpn "disable"
        fi
-       f_log "debug" "f_jsnup   ::: section: ${section:-"-"}, status: ${status:-"-"}, sta_iface: ${sta_iface:-"-"}, sta_radio: ${sta_radio:-"-"}, sta_essid: ${sta_essid:-"-"}, sta_bssid: ${sta_bssid:-"-"}, ntp: ${ntp_done}, vpn: ${trm_vpn}/${vpn_done}, mail: ${trm_mail}/${mail_done}"
+       f_log "debug" "f_jsnup  ::: section: ${section:-"-"}, status: ${status:-"-"}, sta_iface: ${sta_iface:-"-"}, sta_radio: ${sta_radio:-"-"}, sta_essid: ${sta_essid:-"-"}, sta_bssid: ${sta_bssid:-"-"}, ntp: ${ntp_done}, vpn: ${vpn:-"0"}/${vpn_done}, mail: ${trm_mail}/${mail_done}"
 }
 
 # write to syslog
 #
-f_log()
-{
+f_log() {
        local IFS class="${1}" log_msg="${2}"
 
-       if [ -n "${log_msg}" ] && {
-               [ "${class}" != "debug" ] || [ "${trm_debug}" = "1" ]
-       }; then
+       if [ -n "${log_msg}" ] && { [ "${class}" != "debug" ] || [ "${trm_debug}" = "1" ]; }; then
                if [ -x "${trm_logger}" ]; then
                        "${trm_logger}" -p "${class}" -t "trm-${trm_ver}[${$}]" "${log_msg}"
                else
-                       printf '%s %s %s\n' "${class}" "trm-${trm_ver}[${$}]" "${log_msg}"
+                       printf "%s %s %s\n" "${class}" "trm-${trm_ver}[${$}]" "${log_msg}"
                fi
                if [ "${class}" = "err" ]; then
                        trm_ifstatus="error"
@@ -754,16 +708,15 @@ f_log()
 
 # main function for connection handling
 #
-f_main()
-{
+f_main() {
        local IFS cnt retrycnt spec scan_dev scan_list scan_essid scan_bssid scan_open scan_quality
        local station_id section sta sta_essid sta_bssid sta_radio sta_iface sta_mac config_essid config_bssid config_radio
 
        f_check "initial" "false"
-       f_log "debug" "f_main    ::: status: ${trm_ifstatus}, proactive: ${trm_proactive}"
+       f_log "debug" "f_main-1 ::: status: ${trm_ifstatus}, proactive: ${trm_proactive}"
        if [ "${trm_ifstatus}" != "true" ] || [ "${trm_proactive}" = "1" ]; then
                config_load wireless
-               config_foreach f_prepif wifi-iface ${trm_proactive}
+               config_foreach f_setif wifi-iface "${trm_proactive}"
                if [ "${trm_ifstatus}" = "true" ] && [ -n "${trm_activesta}" ] && [ "${trm_proactive}" = "1" ]; then
                        json_get_var station_id "station_id"
                        config_radio="${station_id%%/*}"
@@ -772,19 +725,21 @@ f_main()
                        config_bssid="${station_id##*/}"
                        config_bssid="${config_bssid//-/}"
                        f_check "dev" "true"
-                       f_log "debug" "f_main    ::: config_radio: ${config_radio}, config_essid: \"${config_essid}\", config_bssid: ${config_bssid:-"-"}"
+                       f_log "debug" "f_main-2 ::: config_radio: ${config_radio}, config_essid: \"${config_essid}\", config_bssid: ${config_bssid:-"-"}"
                else
                        uci_commit "wireless"
                        f_check "dev" "false"
                fi
-               f_log "debug" "f_main    ::: radio_list: ${trm_radiolist}, sta_list: ${trm_stalist:0:trm_scanbuffer}"
+               f_log "debug" "f_main-3 ::: radio_list: ${trm_radiolist}, sta_list: ${trm_stalist:0:trm_scanbuffer}"
 
                # radio loop
                #
                for radio in ${trm_radiolist}; do
                        if ! printf "%s" "${trm_stalist}" | grep -q "\\-${radio}"; then
-                               f_log "info" "no station on radio '${radio}'"
-                               continue
+                               if [ "${trm_autoadd}" = "0" ]; then
+                                       f_log "info" "no station on radio '${radio}'"
+                                       continue
+                               fi
                        fi
 
                        # station loop
@@ -796,23 +751,26 @@ f_main()
                                sta_bssid="$(uci_get "wireless" "${section}" "bssid")"
                                sta_iface="$(uci_get "wireless" "${section}" "network")"
                                sta_mac="$(f_mac "get" "${section}")"
+
                                if [ -z "${sta_radio}" ] || [ -z "${sta_essid}" ] || [ -z "${sta_iface}" ]; then
                                        f_log "info" "invalid wireless section '${section}'"
                                        continue
                                fi
-                               if [ "${sta_radio}" = "${config_radio}" ] && [ "${sta_essid}" = "${config_essid}" ] && [ "${sta_bssid}" = "${config_bssid}" ]; then
-                                       f_contrack "refresh" "${config_radio}" "${config_essid}" "${config_bssid}"
+
+                               if [ "${radio}" = "${config_radio}" ] && [ "${sta_radio}" = "${config_radio}" ] &&
+                                       [ "${sta_essid}" = "${config_essid}" ] && [ "${sta_bssid}" = "${config_bssid}" ]; then
+                                       f_ctrack "refresh"
                                        f_log "info" "uplink still in range '${config_radio}/${config_essid}/${config_bssid:-"-"}' with mac '${sta_mac:-"-"}'"
                                        break 2
                                fi
-                               f_log "debug" "f_main    ::: sta_radio: ${sta_radio}, sta_essid: \"${sta_essid}\", sta_bssid: ${sta_bssid:-"-"}"
+                               f_log "debug" "f_main-4 ::: sta_radio: ${sta_radio}, sta_essid: \"${sta_essid}\", sta_bssid: ${sta_bssid:-"-"}"
                                if [ -z "${scan_list}" ]; then
                                        scan_dev="$(ubus -S call network.wireless status 2>/dev/null | jsonfilter -q -l1 -e "@.${radio}.interfaces[0].ifname")"
                                        scan_list="$("${trm_iwinfo}" "${scan_dev:-${radio}}" scan 2>/dev/null |
                                                awk 'BEGIN{FS="[[:space:]]"}/Address:/{var1=$NF}/ESSID:/{var2="";for(i=12;i<=NF;i++)if(var2==""){var2=$i}else{var2=var2" "$i};
                                                gsub(/,/,".",var2)}/Quality:/{split($NF,var0,"/")}/Encryption:/{if($NF=="none"){var3="+"}else{var3="-"};printf "%i,%s,%s,%s\n",(var0[1]*100/var0[2]),var1,var2,var3}' |
                                                sort -rn | awk -v buf="${trm_scanbuffer}" 'BEGIN{ORS=","}{print substr($0,1,buf)}')"
-                                       f_log "debug" "f_main    ::: radio: ${radio}, scan_device: ${scan_dev}, scan_buffer: ${trm_scanbuffer}, scan_list: ${scan_list:-"-"}"
+                                       f_log "debug" "f_main-5 ::: radio: ${radio}, scan_device: ${scan_dev}, scan_buffer: ${trm_scanbuffer}, scan_list: ${scan_list:-"-"}"
                                        if [ -z "${scan_list}" ]; then
                                                f_log "info" "no scan results on '${radio}'"
                                                continue 2
@@ -833,52 +791,39 @@ f_main()
                                                scan_open="${spec}"
                                        fi
                                        if [ -n "${scan_quality}" ] && [ -n "${scan_bssid}" ] && [ -n "${scan_essid}" ] && [ -n "${scan_open}" ]; then
+                                               f_log "debug" "f_main-6 ::: radio(sta/scan): ${sta_radio}/${radio}, essid(sta/scan): \"${sta_essid//,/.}\"/${scan_essid}, bssid(sta/scan): ${sta_bssid}/${scan_bssid}, open: ${scan_open}, quality: ${scan_quality}"
                                                if [ "${scan_quality}" -ge "${trm_minquality}" ]; then
-                                                       if {
-                                                               {
-                                                                       [ "${scan_essid}" = "\"${sta_essid//,/.}\"" ] && {
-                                                                               [ -z "${sta_bssid}" ] || [ "${scan_bssid}" = "${sta_bssid}" ]
-                                                                       }
-                                                               } ||
-                                                                       {
-                                                                               [ "${scan_bssid}" = "${sta_bssid}" ] && [ "${scan_essid}" = "unknown" ]
-                                                                       }
-                                                       } && [ "${radio}" = "${sta_radio}" ]; then
+                                                       if { { [ "${scan_essid}" = "\"${sta_essid//,/.}\"" ] && { [ -z "${sta_bssid}" ] || [ "${scan_bssid}" = "${sta_bssid}" ]; }; } ||
+                                                               { [ "${scan_bssid}" = "${sta_bssid}" ] && [ "${scan_essid}" = "unknown" ]; }; } && [ "${radio}" = "${sta_radio}" ]; then
                                                                f_vpn "disable"
-                                                               f_log "debug" "f_main    ::: scan_quality: ${scan_quality}, scan_essid: ${scan_essid}, scan_bssid: ${scan_bssid:-"-"}, scan_open: ${scan_open}"
                                                                if [ -n "${config_radio}" ]; then
                                                                        uci_set "wireless" "${trm_activesta}" "disabled" "1"
                                                                        uci_commit "wireless"
-                                                                       f_contrack "end" "${config_radio}" "${config_essid}" "${config_bssid}"
+                                                                       f_ctrack "end"
                                                                        f_log "info" "uplink connection terminated '${config_radio}/${config_essid}/${config_bssid:-"-"}'"
                                                                        unset trm_connection config_radio config_essid config_bssid
                                                                fi
 
                                                                # retry loop
                                                                #
-                                                               retrycnt=1
-                                                               trm_radio="${sta_radio}"
+                                                               retrycnt="1"
+                                                               f_getcfg "${sta_radio}" "${sta_essid}" "${sta_bssid}"
                                                                while [ "${retrycnt}" -le "${trm_maxretry}" ]; do
-                                                                       if [ "${trm_randomize}" = "1" ]; then
-                                                                               sta_mac="$(f_mac "set" "${section}")"
-                                                                       fi
+                                                                       sta_mac="$(f_mac "set" "${section}")"
                                                                        uci_set "wireless" "${section}" "disabled" "0"
                                                                        f_check "sta" "false" "${sta_radio}" "${sta_essid}" "${sta_bssid}"
                                                                        if [ "${trm_ifstatus}" = "true" ]; then
                                                                                unset IFS scan_list
                                                                                rm -f "${trm_mailfile}"
                                                                                uci_commit "wireless"
-                                                                               f_contrack "start" "${sta_radio}" "${sta_essid}" "${sta_bssid}"
-                                                                               if [ "${trm_randomize}" = "0" ]; then
-                                                                                       sta_mac="$(f_mac "get" "${section}")"
-                                                                               fi
+                                                                               f_ctrack "start"
                                                                                f_log "info" "connected to uplink '${sta_radio}/${sta_essid}/${sta_bssid:-"-"}' with mac '${sta_mac:-"-"}' (${retrycnt}/${trm_maxretry})"
                                                                                return 0
                                                                        else
                                                                                uci -q revert "wireless"
                                                                                f_check "rev" "false"
                                                                                if [ "${retrycnt}" = "${trm_maxretry}" ]; then
-                                                                                       f_contrack "disabled" "${sta_radio}" "${sta_essid}" "${sta_bssid}"
+                                                                                       f_ctrack "disabled"
                                                                                        f_log "info" "uplink has been disabled '${sta_radio}/${sta_essid}/${sta_bssid:-"-"}' (${retrycnt}/${trm_maxretry})"
                                                                                        break 2
                                                                                else
@@ -892,7 +837,7 @@ f_main()
                                                        elif [ "${trm_autoadd}" = "1" ] && [ "${scan_open}" = "+" ] && [ "${scan_essid}" != "unknown" ]; then
                                                                scan_essid="${scan_essid%?}"
                                                                scan_essid="${scan_essid:1}"
-                                                               f_addif "${sta_radio}" "${scan_essid}"
+                                                               f_addsta "${radio}" "${scan_essid}"
                                                        fi
                                                        unset scan_quality scan_bssid scan_essid scan_open
                                                        continue
@@ -925,7 +870,7 @@ if [ "${trm_action}" != "stop" ]; then
 fi
 while true; do
        if [ -z "${trm_action}" ]; then
-               rc=0
+               rc="0"
                while true; do
                        if [ "${rc}" = "0" ]; then
                                f_check "initial" "false"
@@ -935,9 +880,7 @@ while true; do
                        if [ "${rc}" != "0" ]; then
                                f_check "initial" "false"
                        fi
-                       if [ "${rc}" = "0" ] || {
-                               [ "${rc}" != "0" ] && [ "${trm_ifstatus}" = "false" ]
-                       }; then
+                       if [ "${rc}" = "0" ] || { [ "${rc}" != "0" ] && [ "${trm_ifstatus}" = "false" ]; }; then
                                break
                        fi
                done
index 3ee18fea7f48c0266d555b94398ca2ae2a3ce0ae..6db0f3eaea5823514151142a25c4e55dfd049110 100755 (executable)
@@ -15,104 +15,75 @@ set -o pipefail
 # source function library if necessary
 #
 if [ -z "${_C}" ]; then
-    . "/lib/functions.sh"
+       . "/lib/functions.sh"
 fi
 
-vpn_action="${1}"
-trm_vpnservice="$(uci_get travelmate global trm_vpnservice)"
-trm_vpniface="$(uci_get travelmate global trm_vpniface)"
-trm_landevice="$(uci_get travelmate global trm_landevice)"
+vpn="${1}"
+vpn_action="${2}"
+vpn_service="${3}"
+vpn_iface="${4}"
 trm_maxwait="$(uci_get travelmate global trm_maxwait "30")"
 trm_captiveurl="$(uci_get travelmate global trm_captiveurl "http://detectportal.firefox.com")"
 trm_useragent="$(uci_get travelmate global trm_useragent "Mozilla/5.0 (Linux x86_64; rv:90.0) Gecko/20100101 Firefox/90.0")"
-trm_iptrule_accept="FORWARD -i ${trm_landevice} -p tcp  --match multiport --dports 80,443 -j ACCEPT"
-trm_iptrule_drop="FORWARD -i ${trm_landevice} -j DROP"
-trm_iptables="$(command -v iptables)"
 trm_logger="$(command -v logger)"
 trm_fetch="$(command -v curl)"
 
-f_net()
-{
+f_net() {
        local IFS json_rc result="net nok"
 
-       json_rc="$(${trm_fetch} --user-agent "${trm_useragent}" --referer "http://www.example.com" --connect-timeout $((trm_maxwait / 10)) --header "Cache-Control: no-cache, no-store, must-revalidate" --header "Pragma: no-cache" --header "Expires: 0" --write-out "%{response_code}" --silent --show-error --output /dev/null "${trm_captiveurl}")"
+       json_rc="$(${trm_fetch} --user-agent "${trm_useragent}" --referer "http://www.example.com" --connect-timeout $((trm_maxwait / 10)) --header "Cache-Control: no-cache, no-store, must-revalidate" --header "Pragma: no-cache" --header "Expires: 0" --write-out "%{response_code}" --silent --output /dev/null "${trm_captiveurl}")"
        if [ "${json_rc}" = "200" ] || [ "${json_rc}" = "204" ]; then
                result="net ok"
        fi
        printf "%s" "${result}"
 }
 
-if [ -n "${trm_vpnservice}" ] && [ -n "${trm_vpniface}" ] && [ -n "${trm_landevice}" ] && [ -f "/tmp/trm_runtime.json" ]; then
-       status="$(jsonfilter -i "/tmp/trm_runtime.json" -l1 -e '@.data.travelmate_status' 2>/dev/null)"
-       vpn_status="$(ubus -S call network.interface."${trm_vpniface}" status 2>/dev/null | jsonfilter -l1 -e '@.up')"
-       if [ "${vpn_action}" = "disable" ] && [ "${vpn_status}" = "true" ]; then
-               if [ -n "$("${trm_iptables}" "-w $((trm_maxwait / 6))" -C "${trm_iptrule_drop}" 2>&1)" ] &&
-                       [ -n "$("${trm_iptables}" "-w $((trm_maxwait / 6))" -C "${trm_iptrule_accept}" 2>&1)" ]; then
-                       "${trm_iptables}" "-w $((trm_maxwait / 6))" -I "${trm_iptrule_drop}" 2>&1
-                       "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "lan forward blocked for device '${trm_landevice}'"  2>/dev/null
+vpn_status="$(ubus -S call network.interface."${vpn_iface}" status 2>/dev/null | jsonfilter -q -l1 -e '@.up')"
+case "${vpn_service}" in
+       "wireguard")
+               if [ "${vpn_action}" = "enable" ] && [ "${vpn_status:-"false"}" != "true" ]; then
+                       ubus call network.interface."${vpn_iface}" up
                fi
-       fi
-       if [ "${vpn_action}" = "disable" ] && [ "${status%% (net cp *}" = "connected" ]; then
-               if [ -n "$("${trm_iptables}" "-w $((trm_maxwait / 6))" -C "${trm_iptrule_accept}" 2>&1)" ] &&
-                       [ -z "$("${trm_iptables}" "-w $((trm_maxwait / 6))" -C "${trm_iptrule_drop}" 2>&1)" ]; then
-                       "${trm_iptables}" "-w $((trm_maxwait / 6))" -I "${trm_iptrule_accept}" 2>&1
-                       "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "lan forward on ports 80/443 freed for device '${trm_landevice}'"  2>/dev/null
+               if { [ "${vpn}" = "0" ] && [ "${vpn_action}" = "enable" ]; } || { [ "${vpn_action}" = "disable" ] && [ "${vpn_status}" = "true" ]; }; then
+                       ubus call network.interface."${vpn_iface}" down
+                       "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${vpn_service} client connection disabled" 2>/dev/null
                fi
-       fi
-
-       case "${trm_vpnservice}" in
-               "wireguard")
-                       if [ "${vpn_action}" = "enable" ] && [ "${vpn_status}" != "true" ]; then
-                               ubus call network.interface."${trm_vpniface}" up
-                       elif [ "${vpn_action}" = "disable" ] && [ "${vpn_status}" = "true" ]; then
-                               ubus call network.interface."${trm_vpniface}" down
-                               "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${trm_vpnservice} client connection disabled"  2>/dev/null
-                       fi
-                       ;;
-               "openvpn")
-                       if [ "${vpn_action}" = "enable" ] && [ "${vpn_status}" != "true" ]; then
-                               ubus call network.interface."${trm_vpniface}" up
-                               /etc/init.d/openvpn restart >/dev/null 2>&1
-                       elif [ "${vpn_action}" = "disable" ] && [ "${vpn_status}" = "true" ]; then
-                               ubus call network.interface."${trm_vpniface}" down
-                               /etc/init.d/openvpn stop >/dev/null 2>&1
-                               "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${trm_vpnservice} client connection disabled"  2>/dev/null
-                       fi
-                       ;;
-       esac
+               ;;
+       "openvpn")
+               if [ "${vpn_action}" = "enable" ] && [ "${vpn_status:-"false"}" != "true" ]; then
+                       ubus call network.interface."${vpn_iface}" up
+                       /etc/init.d/openvpn restart >/dev/null 2>&1
+               fi
+               if { [ "${vpn}" = "0" ] && [ "${vpn_action}" = "enable" ]; } || { [ "${vpn_action}" = "disable" ] && [ "${vpn_status}" = "true" ]; }; then
+                       ubus call network.interface."${vpn_iface}" down
+                       /etc/init.d/openvpn stop >/dev/null 2>&1
+                       "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${vpn_service} client connection disabled" 2>/dev/null
+               fi
+               ;;
+esac
 
-       if [ "${vpn_action}" = "enable" ] && [ "${vpn_status}" != "true" ]; then
-               cnt=0
-               while true; do
-                       vpn_status="$(ubus -S call network.interface."${trm_vpniface}" status 2>/dev/null | jsonfilter -l1 -e '@.up')"
-                       if [ "${vpn_status}" = "true" ]; then
-                               net_status="$(f_net)"
-                               if [ "${net_status}" = "net ok" ]; then
-                                       "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${trm_vpnservice} client connection enabled"  2>/dev/null
-                                       if [ -z "$("${trm_iptables}" "-w $((trm_maxwait / 6))" -C "${trm_iptrule_drop}" 2>&1)" ]; then
-                                               "${trm_iptables}" "-w $((trm_maxwait / 6))" -D "${trm_iptrule_drop}" 2>&1
-                                               if [ -z "$("${trm_iptables}" "-w $((trm_maxwait / 6))" -C "${trm_iptrule_accept}" 2>&1)" ]; then
-                                                       "${trm_iptables}" "-w $((trm_maxwait / 6))" -D "${trm_iptrule_accept}" 2>&1
-                                               fi
-                                               "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "lan forward freed for device '${trm_landevice}'"  2>/dev/null
-                                       fi
-                                       break
-                               fi
-                       fi
-                       if [ "${cnt}" -ge "$((trm_maxwait / 6))" ]; then
-                               "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${trm_vpnservice} restart failed, lan forward for device '${trm_landevice}' still blocked"  2>/dev/null
-                               ubus call network.interface."${trm_vpniface}" down
-                               exit 2
+if [ "${vpn}" = "1" ] && [ "${vpn_action}" = "enable" ] && [ "${vpn_status:-"false"}" != "true" ]; then
+       cnt=0
+       while true; do
+               vpn_status="$(ubus -S call network.interface."${vpn_iface}" status 2>/dev/null | jsonfilter -q -l1 -e '@.up')"
+               if [ "${vpn_status}" = "true" ]; then
+                       net_status="$(f_net)"
+                       if [ "${net_status}" = "net ok" ]; then
+                               "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${vpn_service} client connection enabled" 2>/dev/null
+                               break
                        fi
-                       sleep 1
-                       cnt="$((cnt + 1))"
-               done
-       fi
-       if [ "${vpn_action}" = "enable" ] && [ "${vpn_status}" = "true" ]; then
-               if [ -f "/etc/init.d/sysntpd" ]; then
-                       /etc/init.d/sysntpd restart >/dev/null 2>&1
                fi
+               if [ "${cnt}" -ge "$((trm_maxwait / 6))" ]; then
+                       "${trm_logger}" -p "info" -t "trm-vpn  [${$}]" "${vpn_service} client connection can't be established" 2>/dev/null
+                       ubus call network.interface."${vpn_iface}" down
+                       exit 1
+               fi
+               sleep 1
+               cnt="$((cnt + 1))"
+       done
+fi
+if [ "${vpn_action}" = "enable" ] && [ "${vpn_status}" = "true" ]; then
+       if [ -f "/etc/init.d/sysntpd" ]; then
+               /etc/init.d/sysntpd restart >/dev/null 2>&1
        fi
-       exit 0
 fi
-exit 1