Compare commits

..
65 Commits
Author SHA1 Message Date
Frank Denis 2647aadad8 Re-enable JS for the feedback form 2012-10-03 10:08:45 -07:00
Frank Denis 6020eb8505 Grammar 2012-10-03 08:37:13 -07:00
Frank Denis d5f551de8a 0.18 2012-10-03 08:21:43 -07:00
Frank Denis 1c8e2e4fa1 Update release notes. 2012-10-03 08:15:28 -07:00
Frank Denis 093ab54300 Explain that a tool like dig(1) shouldn't be use in order to check if
an exception works.
2012-10-03 05:51:42 -07:00
Frank Denis d15252db40 Keep everything sorted, thanks. 2012-10-02 11:26:54 -07:00
Frank Denis 50dc9a9382 Add freebox.fr to the list of exceptions for things like mafreebox.freebox.fr 2012-10-02 11:25:33 -07:00
Frank Denis 75d3983289 Change "enable OpenDNS" to "always use OpenDNS" and
"enable FamilyShield" to "always use FamilyShield" in the
preference pane, too, in order to be in line with the
menu bar.
Suggested by G.D. Wolfman, thanks!
2012-10-02 07:14:59 -07:00
Frank Denis 24227488db Use 0.17.1 in the package. 2012-10-02 07:14:10 -07:00
Frank Denis cbfa42cb3a Moving on. Next will be 0.18 2012-09-29 15:22:55 +02:00
Frank Denis 2f6ab604fc Use static resolvers, if provided, in order to resolve names bypassing OpenDNS 2012-09-29 15:08:44 +02:00
Frank Denis 7bea3fbc63 Rename DNSCrypt-OSX.mpkg to DNSCrypt.mpkg in order to make Sparkle happy 2012-09-29 14:55:35 +02:00
Frank Denis a790696cdc names => domains 2012-09-29 14:40:02 +02:00
Frank Denis e9ef33c652 Invert the logic, save 2 bytes, yay. 2012-09-28 22:42:43 +02:00
Frank Denis 0bc15a0b7d Typo 2012-09-28 22:35:11 +02:00
Frank Denis 4ee0bee8bf Add entries for dnscrypt-proxy and hostip to the application firewall. 2012-09-28 21:51:45 +02:00
Frank Denis 1953182435 Add README.markdown 2012-09-28 19:07:16 +02:00
Frank Denis dfb93446e6 Not -dev any more 2012-09-28 18:48:46 +02:00
Frank Denis 982c9de99f Use opendns/welcome/ to that people know if they are using OpenDNS or not.
Switch to https by the way.
2012-09-28 18:42:07 +02:00
Frank Denis 26c4efbfd8 0.17 will be released today. 2012-09-28 00:52:38 +02:00
Frank Denis 3b6db0ef37 Remove old exceptions 2012-09-28 00:47:33 +02:00
Frank Denis 5e16b57247 DOMAINS_EXCEPTIONS_FILE => EXCEPTIONS_FILE 2012-09-28 00:17:59 +02:00
Frank Denis 92a8b0b097 Handle exceptions 2012-09-27 23:13:40 +02:00
Frank Denis fde1ebff46 domains-exceptions -> exceptions 2012-09-27 23:13:26 +02:00
Frank Denis 1dc4493321 Add update-exceptions.sh 2012-09-27 22:49:23 +02:00
Frank Denis 7b6f59025e Add a default background color for the help page. 2012-09-27 15:28:38 +02:00
Frank Denis 9193375610 Make the help webview opaque. 2012-09-27 15:22:47 +02:00
Frank Denis ce39c0b767 Move the "uninstall" button to the left, because having it at the same place
as the "help" button is probably a terrible idea.
2012-09-27 15:15:39 +02:00
Frank Denis 1a40da6a28 Define less capabilities for webviews 2012-09-27 15:10:18 +02:00
Frank Denis c5037615fb Update the release notes. 2012-09-27 15:01:59 +02:00
Frank Denis f1b8f2bfa6 Help for the advanced settings pane. 2012-09-27 14:44:56 +02:00
Frank Denis 22cbc2809b Never block opendns.com 2012-09-27 14:40:59 +02:00
Frank Denis 08e745dc2b Revert "Prepare a window for the "help" button."
This reverts commit 8048d73038.
2012-09-27 02:44:46 +02:00
Frank Denis 1369f07a58 Remove the query log file after a reboot. 2012-09-26 16:57:54 +02:00
Frank Denis 7a2e79b04e Let the uninstaller remove /var/log/dnscrypt-query.log 2012-09-26 16:50:05 +02:00
Frank Denis 8048d73038 Prepare a window for the "help" button. 2012-09-26 16:48:38 +02:00
Frank Denis f9728ffd45 Improve the way plugin files are parsed. One option per line. 2012-09-26 14:29:39 +02:00
Frank Denis 9ffa57ba8d Replace wrappers with symlinks 2012-09-26 14:26:10 +02:00
Frank Denis 6fb79a786d Remove alarmer/dnscrypt-proxy/hostip wrappers 2012-09-26 14:25:30 +02:00
Frank Denis 74c860fdfb Fix --ips vs --domains 2012-09-26 11:38:15 +02:00
Frank Denis 3234989005 Temporary files should die as soon as possible. 2012-09-26 11:35:48 +02:00
Frank Denis 7b976aaa33 Remove empty blacklist-domains and/or blacklist-ips files. 2012-09-26 11:34:20 +02:00
Frank Denis 11969f98da Call update-(ips|domains) when blacklists are updated. 2012-09-26 11:18:45 +02:00
Frank Denis 951b3df6a9 Rename switch-blacklist-(ips|domains)-on.sh to update-(ips|domains).sh 2012-09-26 11:18:25 +02:00
Frank Denis 0388eb87d8 Add scripts for switching IPs and domains blacklists on and off. 2012-09-26 11:12:59 +02:00
Frank Denis 582c1eb9a7 Read/write IPs and domains blacklists. 2012-09-26 10:41:07 +02:00
Frank Denis b5578e94e1 Add network settings lock-in support. 2012-09-26 00:07:33 +02:00
Frank Denis 3782b2851b Add network settings lock-in scripts. 2012-09-26 00:00:46 +02:00
Frank Denis 901537f8d5 Enable "View log" button. 2012-09-25 23:10:16 +02:00
Frank Denis b8c538e4aa Add query logging 2012-09-25 23:02:09 +02:00
Frank Denis f16b2c2717 Add support for advanced parental controls, move the whole thing to 0.17 beta. 2012-09-25 22:40:45 +02:00
Frank Denis 578362d2f3 No need to be so verbose. 2012-09-25 21:16:22 +02:00
Frank Denis 8786d2df3a Add the user interface version and the dnscrypt version to feedback messages.
Requested by the OpenDNS support team.
2012-09-25 21:13:35 +02:00
Frank Denis 8ef1d62cbd Typo 2012-09-25 02:17:35 +02:00
Frank Denis 052febc509 Set static resolvers from the preferences pane. 2012-09-24 09:33:38 +02:00
Frank Denis e889c387e1 Disable all checkboxes by default. 2012-09-24 08:46:46 +02:00
Frank Denis 97350f2207 Rephrase 2012-09-24 08:46:15 +02:00
Frank Denis 55cd65f0ad Add set-static-resolvers.sh 2012-09-24 08:45:58 +02:00
Frank Denis 9f10b681dc Change tab ids 2012-09-23 23:54:24 +02:00
Frank Denis df1e23bef7 Slightly change the way plugin-related control files are handled.
A plugins.enabled file is required for plugins to be enabled.
The content of that file is concatened with optional plugin-*.enabled files
in order to build the list of enabled plugins.
Using shell globbing for that is utterly disgusting. I couldn't agree more.
2012-09-23 23:16:36 +02:00
Frank Denis f5678bdd45 Add the path to libldns to the paths the linker will look at. 2012-09-23 22:15:14 +02:00
Frank Denis 507a09aa47 Ship a copy of libldns. 2012-09-23 22:09:48 +02:00
Frank Denis c381885f6a Bundle the uninstaller with the preference pane. Suggested by ScienceGuy, thanks! 2012-09-21 23:06:39 +02:00
Frank Denis 4112c0c19a Regen 2012-09-20 00:29:12 +02:00
Frank Denis 796b767e47 September 7th, 2012 was a Friday. 2012-09-20 00:28:50 +02:00
47 changed files with 2382 additions and 80 deletions
@@ -17,11 +17,11 @@
<key>CFBundlePackageType</key>
<string>APPL</string>
<key>CFBundleShortVersionString</key>
<string>0.16 (beta)</string>
<string>0.18 (beta)</string>
<key>CFBundleSignature</key>
<string>????</string>
<key>CFBundleVersion</key>
<string>0.16</string>
<string>0.18</string>
<key>LSApplicationCategoryType</key>
<string>public.app-category.utilities</string>
<key>LSMinimumSystemVersion</key>
@@ -441,6 +441,200 @@
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array>
<dict>
<key>CHILDREN</key>
<array>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_blocking.la</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_blocking.so</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_opendns_deviceid.la</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_opendns_deviceid.so</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_opendns_parental_control.la</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_opendns_parental_control.so</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_opendns_set_client_ip.la</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_ldns_opendns_set_client_ip.so</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_logging.la</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array/>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>/usr/local/lib/dnscrypt-proxy/libdcplugin_example_logging.so</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>3</integer>
<key>UID</key>
<integer>0</integer>
</dict>
</array>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>dnscrypt-proxy</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>2</integer>
<key>UID</key>
<integer>0</integer>
</dict>
</array>
<key>GID</key>
<integer>0</integer>
<key>PATH</key>
<string>lib</string>
<key>PATH_TYPE</key>
<integer>0</integer>
<key>PERMISSIONS</key>
<integer>493</integer>
<key>TYPE</key>
<integer>2</integer>
<key>UID</key>
<integer>0</integer>
</dict>
<dict>
<key>CHILDREN</key>
<array>
@@ -634,7 +828,7 @@
<key>USE_HFS+_COMPRESSION</key>
<true/>
<key>VERSION</key>
<string>1.1.0.2</string>
<string>1.1.0.4</string>
</dict>
<key>UUID</key>
<string>7F7D70AB-F7A2-4027-8304-3063C7B9532F</string>
@@ -1241,7 +1435,7 @@
<key>USE_HFS+_COMPRESSION</key>
<true/>
<key>VERSION</key>
<string>0.16</string>
<string>0.18</string>
</dict>
<key>TYPE</key>
<integer>0</integer>
@@ -1734,7 +1928,7 @@
<key>USE_HFS+_COMPRESSION</key>
<true/>
<key>VERSION</key>
<string>0.16</string>
<string>0.18</string>
</dict>
<key>TYPE</key>
<integer>0</integer>
+11 -6
View File
@@ -1,26 +1,31 @@
#! /bin/sh
VERSION='0.16'
VERSION='0.18'
cd build || exit 1
[ -d DNSCrypt.mpkg ] || exit 1
(
cd DNSCrypt.mpkg/Contents/Packages || exit 1
for pkg in *pkg; do
for pkg in *pkg ; do
rm -fr "x-${pkg}"
mv "$pkg" "x-${pkg}"
productsign --sign 'Developer ID Installer' "x-${pkg}" "$pkg"
rm -fr "x-${pkg}"
done
)
rm -fr DNSCrypt-OSX.mpkg
rm -fr DNSCrypt-OSX.mpkg DNSCrypt-unsigned.mpkg
productsign --sign 'Developer ID Application' DNSCrypt.mpkg DNSCrypt-OSX.mpkg
zip -9 -r "dnscrypt-osx-client-${VERSION}.zip" DNSCrypt-OSX.mpkg
mv DNSCrypt.mpkg DNSCrypt-unsigned.mpkg
mv DNSCrypt-OSX.mpkg DNSCrypt.mpkg
zip -9 -r "dnscrypt-osx-client-${VERSION}.zip" DNSCrypt.mpkg
rm -fr dnscrypt-pkg
rm -f "dnscrypt-osx-client-${VERSION}.dmg"
mkdir dnscrypt-pkg
mv DNSCrypt-OSX.mpkg dnscrypt-pkg
mv DNSCrypt.mpkg dnscrypt-pkg
hdiutil create "dnscrypt-osx-client-${VERSION}.dmg" -srcfolder dnscrypt-pkg
mv dnscrypt-pkg/DNSCrypt-OSX.mpkg .
mv dnscrypt-pkg/DNSCrypt.mpkg .
rm -fr dnscrypt-pkg
rm -fr DNSCrypt-unsigned.mpkg
@@ -17,11 +17,11 @@
<key>CFBundlePackageType</key>
<string>BNDL</string>
<key>CFBundleShortVersionString</key>
<string>0.16</string>
<string>0.18</string>
<key>CFBundleSignature</key>
<string>????</string>
<key>CFBundleVersion</key>
<string>0.16</string>
<string>0.18</string>
<key>NSHumanReadableCopyright</key>
<string>Copyright © 2011-2012 OpenDNS Inc. All rights reserved.</string>
<key>NSMainNibFile</key>
+26 -2
View File
@@ -9,15 +9,21 @@
#import <PreferencePanes/PreferencePanes.h>
#import <WebKit/WebKit.h>
#define kDNSCRYPT_PACKAGE_VERSION @"0.16"
#define kDNSCRYPT_PACKAGE_VERSION @"0.18"
#define kDNSCRYPT_PREFPANE_APP_PATH @"/Library/PreferencePanes/DNSCrypt.prefPane"
#define kDNSCRYPT_USR_BASE_DIR kDNSCRYPT_PREFPANE_APP_PATH @"/Contents/Resources/usr"
#define kDNSCRIPT_BIN_BASE_DIR kDNSCRYPT_USR_BASE_DIR @"/bin"
#define kDNSCRIPT_SCRIPTS_BASE_DIR kDNSCRYPT_USR_BASE_DIR @"/scripts"
#define kDNSCRYPT_VAR_BASE_DIR @"/Library/Application Support/DNSCrypt"
#define kDNSCRYPT_CONTROL_DIR kDNSCRYPT_VAR_BASE_DIR @"/control"
#define kOPENDNS_URL @"http://www.opendns.com"
#define kDNSCRYPT_QUERY_LOG_FILE @"/var/log/dnscrypt-query.log"
#define kDNSCRYPT_BLACKLIST_IPS_TMP_FILE kDNSCRYPT_CONTROL_DIR @"/blacklist-ips.tmp"
#define kDNSCRYPT_BLACKLIST_DOMAINS_TMP_FILE kDNSCRYPT_CONTROL_DIR @"/blacklist-domains.tmp"
#define kDNSCRYPT_EXCEPTIONS_TMP_FILE kDNSCRYPT_CONTROL_DIR @"/exceptions.tmp"
#define kOPENDNS_URL @"https://www.opendns.com/welcome/"
#define kBUNDLE_IDENTIFIER @"com.opendns.osx.DNSCrypt"
@@ -48,6 +54,14 @@ typedef enum {
@property (nonatomic, retain) IBOutlet WebView *releaseNotesWebView;
@property (nonatomic, retain) IBOutlet WebView *feedbackWebView;
@property (nonatomic, retain) IBOutlet WebView *aboutWebView;
@property (nonatomic, retain) IBOutlet NSTextFieldCell *staticResolversTextField;
@property (nonatomic, retain) IBOutlet NSButton *parentalControlsButton;
@property (nonatomic, retain) IBOutlet NSButtonCell *queryLoggingButton;
@property (nonatomic, retain) IBOutlet NSButton *lockinButton;
@property (nonatomic, retain) IBOutlet NSTextField *blacklistIPsTextField;
@property (nonatomic, retain) IBOutlet NSTextField *blacklistDomainsTextField;
@property (nonatomic, retain) IBOutlet NSTextField *exceptionsTextField;
@property (nonatomic, retain) IBOutlet WebView *helpWebView;
- (void) mainViewDidLoad;
@@ -57,5 +71,15 @@ typedef enum {
- (IBAction)fallbackButtonPressed:(NSButton *)sender;
- (IBAction)openDNSLinkPushed:(NSButton *)sender;
- (IBAction)uninstallPushed:(NSButton *)sender;
- (IBAction)staticResolversTextFieldChanged:(NSTextField *)sender;
- (IBAction)parentalControlsButtonPressed:(NSButtonCell *)sender;
- (IBAction)queryLoggingButtonPressed:(NSButtonCell *)sender;
- (IBAction)viewLogButtonPushed:(NSButton *)sender;
- (IBAction)lockinButtonPressed:(NSButton *)sender;
- (IBAction)blacklistIPsUpdated:(NSTextField *)sender;
- (IBAction)blacklistDomainsUpdated:(NSTextField *)sender;
- (IBAction)exceptionsUpdated:(NSTextField *)sender;
- (IBAction)helpButtonPressed:(NSButton *)sender;
@end
+197 -2
View File
@@ -12,12 +12,18 @@
@synthesize tabView = _tabView;
@synthesize aboutTabViewItem = _aboutTabViewItem;
@synthesize releaseNotesTabViewItem = _releaseNotesTabViewItem;
@synthesize previewNotesWebView = _previewNotesWebView;
@synthesize releaseNotesWebView = _releaseNotesWebView;
@synthesize feedbackWebView = _feedbackWebView;
@synthesize aboutWebView = _aboutWebView;
@synthesize staticResolversTextField = _staticResolversTextField;
@synthesize parentalControlsButton = _parentalControlsButton;
@synthesize queryLoggingButton = _queryLoggingButton;
@synthesize lockinButton = _lockinButton;
@synthesize blacklistIPsTextField = _blacklistIPsTextField;
@synthesize blacklistDomainsTextField = _blacklistDomainsTextField;
@synthesize helpWebView = _helpWebView;
@synthesize exceptionsTextField = _exceptionsTextField;
@synthesize dnscryptButton = _dnscryptButton;
@synthesize opendnsButton = _opendnsButton;
@synthesize fallbackButton = _fallbackButton;
@@ -82,6 +88,33 @@ DNSConfigurationState currentState = kDNS_CONFIGURATION_UNKNOWN;
if ([res isEqualToString: @"yes"]) {
[_fallbackButton setState: 1];
}
res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && exec ./get-static-resolvers.sh", nil]];
[_staticResolversTextField setStringValue: res];
res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && exec ./get-parental-controls-status.sh", nil]];
if ([res isEqualToString: @"yes"]) {
[_parentalControlsButton setState: 1];
}
res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && exec ./get-query-logging-status.sh", nil]];
if ([res isEqualToString: @"yes"]) {
[_queryLoggingButton setState: 1];
}
res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && exec ./get-lockin-status.sh", nil]];
if ([res isEqualToString: @"yes"]) {
[_lockinButton setState: 1];
}
NSString *fileContent;
fileContent = [NSString stringWithContentsOfFile: kDNSCRYPT_BLACKLIST_IPS_TMP_FILE encoding:NSUTF8StringEncoding error: nil];
if (fileContent != nil) {
[_blacklistIPsTextField setStringValue: fileContent];
}
fileContent = [NSString stringWithContentsOfFile: kDNSCRYPT_BLACKLIST_DOMAINS_TMP_FILE encoding:NSUTF8StringEncoding error: nil];
if (fileContent != nil) {
[_blacklistDomainsTextField setStringValue: fileContent];
}
fileContent = [NSString stringWithContentsOfFile: kDNSCRYPT_EXCEPTIONS_TMP_FILE encoding:NSUTF8StringEncoding error: nil];
if (fileContent != nil) {
[_exceptionsTextField setStringValue: fileContent];
}
}
- (void) updateLedStatus
@@ -268,6 +301,18 @@ DNSConfigurationState currentState = kDNS_CONFIGURATION_UNKNOWN;
[self performSelector: @selector(waitForUpdate) withObject: self afterDelay:kREFRESH_DELAY];
}
- (void) webView:(WebView *)sender didFinishLoadForFrame:(WebFrame *)frame {
if (sender != _feedbackWebView) {
return;
}
NSString *res;
res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"/usr/local/sbin/dnscrypt-proxy --version | head -n 1", nil]];
NSCharacterSet *charset = [NSCharacterSet characterSetWithCharactersInString: @"\r\n<>'"];
res = [[res componentsSeparatedByCharactersInSet: charset] componentsJoinedByString: @" "];
NSString *script = [NSString stringWithFormat: @"document.querySelector('textarea[name=feedback]').value='\\n\\n\\n--\\nOpenDNS user interface for OSX " kDNSCRYPT_PACKAGE_VERSION "\\n%@'", res];
[sender stringByEvaluatingJavaScriptFromString: script];
}
- (void) mainViewDidLoad
{
currentState = kDNS_CONFIGURATION_UNKNOWN;
@@ -299,6 +344,7 @@ DNSConfigurationState currentState = kDNS_CONFIGURATION_UNKNOWN;
[_feedbackWebView setDrawsBackground:false];
[_feedbackWebView setShouldUpdateWhileOffscreen:true];
[_feedbackWebView setUIDelegate:self];
[_feedbackWebView setFrameLoadDelegate: self];
NSString *feedbackURLText = @"http://dnscrypt.opendns.com/feedback.php";
[[_feedbackWebView mainFrame] loadRequest:[NSURLRequest requestWithURL:[NSURL URLWithString:feedbackURLText]]];
@@ -328,6 +374,17 @@ DNSConfigurationState currentState = kDNS_CONFIGURATION_UNKNOWN;
} else {
[[_aboutWebView mainFrame] loadRequest:[NSURLRequest requestWithURL: aboutURL]];
}
[_helpWebView setDrawsBackground:false];
[_helpWebView setShouldUpdateWhileOffscreen:false];
[_helpWebView setUIDelegate:self];
NSURL *helpURL;
NSString *helpURLPath = [[NSBundle bundleForClass: [self class]] pathForResource: @"help" ofType: @"html" inDirectory: @"html"];
if (! helpURLPath || ! (helpURL = [NSURL fileURLWithPath: helpURLPath])) {
assert(0);
} else {
[[_helpWebView mainFrame] loadRequest:[NSURLRequest requestWithURL: helpURL]];
}
}
- (NSArray *)webView:(WebView *)sender contextMenuItemsForElement:(NSDictionary *)element
@@ -342,5 +399,143 @@ DNSConfigurationState currentState = kDNS_CONFIGURATION_UNKNOWN;
[[NSWorkspace sharedWorkspace] openURL:[NSURL URLWithString: kOPENDNS_URL]];
}
- (IBAction)uninstallPushed:(NSButton *)sender {
[self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_BIN_BASE_DIR @"' && /usr/bin/open ./Uninstall.app", nil]];
}
- (IBAction)staticResolversTextFieldChanged:(NSTextField *)sender {
NSString *staticResolvers = sender.stringValue;
NSCharacterSet *charset = [[NSCharacterSet characterSetWithCharactersInString: @"0123456789abcdefABCDEF:. "] invertedSet];
staticResolvers = [[staticResolvers componentsSeparatedByCharactersInSet: charset] componentsJoinedByString: @" "];
sender.stringValue = staticResolvers;
setenv("STATIC_RESOLVERS", [staticResolvers UTF8String], 1);
[self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && exec ./set-static-resolvers.sh \"$STATIC_RESOLVERS\"", staticResolvers, nil]];
}
- (BOOL) setParentalControlsOn {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./switch-parental-controls-on.sh", nil]];
(void) res;
return TRUE;
}
- (BOOL) setParentalControlsOff {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./switch-parental-controls-off.sh", nil]];
(void) res;
return TRUE;
}
- (IBAction)parentalControlsButtonPressed:(NSButtonCell *)sender {
if (sender.state != 0) {
[self setParentalControlsOn];
} else {
[self setParentalControlsOff];
}
}
- (BOOL) setQueryLoggingOn {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./switch-query-logging-on.sh", nil]];
(void) res;
return TRUE;
}
- (BOOL) setQueryLoggingOff {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./switch-query-logging-off.sh", nil]];
(void) res;
return TRUE;
}
- (IBAction)queryLoggingButtonPressed:(NSButtonCell *)sender {
if (sender.state != 0) {
[self setQueryLoggingOn];
} else {
[self setQueryLoggingOff];
}
}
- (IBAction)viewLogButtonPushed:(NSButton *)sender {
[self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"open /Applications/Utilities/Console.app " kDNSCRYPT_QUERY_LOG_FILE " || open " kDNSCRYPT_QUERY_LOG_FILE, nil]];
}
- (BOOL) setLockinOn {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./switch-lockin-on.sh", nil]];
(void) res;
return TRUE;
}
- (BOOL) setLockinOff {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./switch-lockin-off.sh", nil]];
(void) res;
return TRUE;
}
- (IBAction)lockinButtonPressed:(NSButton *)sender {
if (sender.state != 0) {
[self setLockinOn];
} else {
[self setLockinOff];
}
}
- (BOOL) updateBlacklistIPs {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./update-blacklist-ips.sh", nil]];
(void) res;
return TRUE;
}
- (IBAction)blacklistIPsUpdated:(NSTextField *)sender {
NSString *content = sender.stringValue;
if ([content writeToFile: kDNSCRYPT_BLACKLIST_IPS_TMP_FILE atomically: YES encoding: NSUTF8StringEncoding error: nil] != YES) {
return;
}
[self updateBlacklistIPs];
}
- (BOOL) updateBlacklistDomains {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./update-blacklist-domains.sh", nil]];
(void) res;
return TRUE;
}
- (IBAction)blacklistDomainsUpdated:(NSTextField *)sender {
NSString *content = sender.stringValue;
if ([content writeToFile: kDNSCRYPT_BLACKLIST_DOMAINS_TMP_FILE atomically: YES encoding: NSUTF8StringEncoding error: nil] != YES) {
return;
}
[self updateBlacklistDomains];
}
- (BOOL) updateExceptions {
[self showSpinners];
NSString *res = [self fromCommand: @"/bin/ksh" withArguments: [NSArray arrayWithObjects: @"-c", @"cd '" kDNSCRIPT_SCRIPTS_BASE_DIR @"' && ./create-ticket.sh && ./update-exceptions.sh", nil]];
(void) res;
return TRUE;
}
- (IBAction)exceptionsUpdated:(NSTextField *)sender {
NSString *content = sender.stringValue;
if ([content writeToFile: kDNSCRYPT_EXCEPTIONS_TMP_FILE atomically: YES encoding: NSUTF8StringEncoding error: nil] != YES) {
return;
}
[self updateExceptions];
}
- (IBAction)helpButtonPressed:(NSButton *)sender {
if (_helpWebView.isHidden) {
[_helpWebView setHidden: NO];
[_helpWebView setAlphaValue: 0.0];
[_helpWebView.animator setAlphaValue: 1.0];
[_helpWebView setDrawsBackground: TRUE];
} else {
[_helpWebView setHidden: YES];
}
}
@end
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,140 @@
!!! 5
%html{lang: "en"}
%head
%meta{charset: "utf-8"}
%title Help (advanced settings)
%style{type: "text/css"}
:sass
html
background: #e4e4e4
body
font:
family: arial, helvetica, sans-serif
margin: 1em
h1
margin: 0
%body
%h1 Help(advanced settings)
%section
%h2 Static DNS servers
%p
If you are not using DHCP and want a statically configured set
of default DNS resolvers, enter their IP addresses in this box.
%p
Separate them with spaces.
%section
%h2 Advanced parental controls
%p
When using DNSCrypt, this will block the following list of OpenDNS
categories: lingerie/bikini, adult themes, nudity,
pornography, proxy/anonymizer, sexuality and tasteless.
%p
If you have an OpenDNS account and network settings defined
for your current location, the network settings will override the
advanced parental controls. Having an OpenDNS account allows
finer granularity access controls, building reports and more.
%section
%h2 Log DNS queries
%p
As a tool designed to protect your privacy, the DNSCrypt proxy does
not log anything about your DNS queries. Nothing about them will be
saved to disk ever, and log messages are intentionally kept as generic
as possible.
%p
However, you still may want to look at the DNS queries sent by
your system. This can be useful in order to spot suspicious
activity and to refine your domain blacklists and whitelists.
%p
Checking the "Log DNS queries" box dumps all DNS queries sent
by your computer to a file named /var/log/dnscrypt-query.log
%p
The "View log" button opens it with the log viewer application
so that you can watch it in real time.
%section
%h2 Lock-in the current network settings
%p
If you have an OpenDNS account, and OpenDNS network settings
defined for your current location, you can make these
persistent.
%p
Checking this box will make the user interface remember what
your current network is.
%p
If you are roaming, the settings for this network will still be
used, no matter what actual network you are connected to.
%p
That way, you can stay protected from botnets, malware,
phishing and block unwanted content, even when using public
Wi-Fi hotspots.
%p
This feature is currently not compatible with the OpenDNS IP
updater. If your ISP assigns dynamic IP addresses, use either
the OpenDNS IP updater or the DNSCrypt lock-in feature, but not both.
%section
%h2 IP addresses blocking
%p
A response to a query containing at least one IP address
listed here will be blocked.
%p
This make it easy to block spam sources, hosting services and content
providers using a lot of different domain names for a single service.
%p
This can also be useful in order to block DNS rebinding
attacks, even for non-private network spaces.
%p
IP addresses can be IPv4 and IPv6 addresses, and must be
separated with spaces.
%section
%h2 Names blocking
%p
This is a list of domain names to be blocked.
%p
It doesn't affect your OpenDNS network settings. This is a
local blacklist, applied in addition to your OpenDNS settings.
%p
"example.com" will only match this specific name, not
"www.example.com".
%p
But wildcards are also supported. "*.example.com" will match
any name ending with ".example.com" whereas "ads.*" will match
any name beginning with "ads."
%p
Wildcards can also perform substring matching. "*xxx*" will
match any name containing the string "xxx".
%p
Patterns to be blocked should be separated with spaces, and
the blocking takes effect immediately after you hit the Return
key. Flushing your DNS cache is not required.
%p
This feature is only enabled when using DNSCrypt.
%section
%h2 Exceptions - bypassing OpenDNS for some specific names
%p
Some domain names should not be resolved by a third-party DNS
resolver, that may not know about them.
%p
This includes local domain names provided by home routers
(like "routerlogin.net"), local domain names provided by
operating systems and applications (like ".local" or ".lan"),
local domain names served by appliances like st-top boxes, and
internal domains used in corporate networks.
%p
Domains listed here will bypass DNSCrypt in order to be sent
to the default resolvers.
%p
Do
%strong not
use a tool like hostip(8), drill(1), unbound-host(1), dig(1) or host(1)
in order to check that an exception rule works.
%p
These tools use their own resolution mechanisms that have nothing
to do with how others apps on your system are resolving names.
%p
They don't use the OSX-specific stub resolver, they don't use
the system-wide DNS cache, they have bugs and limitations that the OS
doesn't have (and the opposite is also true), and they don't know a
thing about specific resolvers that have to be used for specific
domains.
%p
Use actual apps, or even a command like ping(8).
@@ -0,0 +1,181 @@
<!DOCTYPE html>
<html lang='en'>
<head>
<meta charset='utf-8' />
<title>Help (advanced settings)</title>
<style type='text/css'>
html {
background: #e4e4e4; }
body {
font-family: arial, helvetica, sans-serif;
margin: 1em; }
h1 {
margin: 0; }
</style>
</head>
<body>
<h1>Help(advanced settings)</h1>
<section>
<h2>Static DNS servers</h2>
<p>
If you are not using DHCP and want a statically configured set
of default DNS resolvers, enter their IP addresses in this box.
</p>
<p>
Separate them with spaces.
</p>
</section>
<section>
<h2>Advanced parental controls</h2>
<p>
When using DNSCrypt, this will block the following list of OpenDNS
categories: lingerie/bikini, adult themes, nudity,
pornography, proxy/anonymizer, sexuality and tasteless.
</p>
<p>
If you have an OpenDNS account and network settings defined
for your current location, the network settings will override the
advanced parental controls. Having an OpenDNS account allows
finer granularity access controls, building reports and more.
</p>
</section>
<section>
<h2>Log DNS queries</h2>
<p>
As a tool designed to protect your privacy, the DNSCrypt proxy does
not log anything about your DNS queries. Nothing about them will be
saved to disk ever, and log messages are intentionally kept as generic
as possible.
</p>
<p>
However, you still may want to look at the DNS queries sent by
your system. This can be useful in order to spot suspicious
activity and to refine your domain blacklists and whitelists.
</p>
<p>
Checking the "Log DNS queries" box dumps all DNS queries sent
by your computer to a file named /var/log/dnscrypt-query.log
</p>
<p>
The "View log" button opens it with the log viewer application
so that you can watch it in real time.
</p>
</section>
<section>
<h2>Lock-in the current network settings</h2>
<p>
If you have an OpenDNS account, and OpenDNS network settings
defined for your current location, you can make these
persistent.
</p>
<p>
Checking this box will make the user interface remember what
your current network is.
</p>
<p>
If you are roaming, the settings for this network will still be
used, no matter what actual network you are connected to.
</p>
<p>
That way, you can stay protected from botnets, malware,
phishing and block unwanted content, even when using public
Wi-Fi hotspots.
</p>
<p>
This feature is currently not compatible with the OpenDNS IP
updater. If your ISP assigns dynamic IP addresses, use either
the OpenDNS IP updater or the DNSCrypt lock-in feature, but not both.
</p>
</section>
<section>
<h2>IP addresses blocking</h2>
<p>
A response to a query containing at least one IP address
listed here will be blocked.
</p>
<p>
This make it easy to block spam sources, hosting services and content
providers using a lot of different domain names for a single service.
</p>
<p>
This can also be useful in order to block DNS rebinding
attacks, even for non-private network spaces.
</p>
<p>
IP addresses can be IPv4 and IPv6 addresses, and must be
separated with spaces.
</p>
</section>
<section>
<h2>Names blocking</h2>
<p>
This is a list of domain names to be blocked.
</p>
<p>
It doesn't affect your OpenDNS network settings. This is a
local blacklist, applied in addition to your OpenDNS settings.
</p>
<p>
"example.com" will only match this specific name, not
"www.example.com".
</p>
<p>
But wildcards are also supported. "*.example.com" will match
any name ending with ".example.com" whereas "ads.*" will match
any name beginning with "ads."
</p>
<p>
Wildcards can also perform substring matching. "*xxx*" will
match any name containing the string "xxx".
</p>
<p>
Patterns to be blocked should be separated with spaces, and
the blocking takes effect immediately after you hit the Return
key. Flushing your DNS cache is not required.
</p>
<p>
This feature is only enabled when using DNSCrypt.
</p>
</section>
<section>
<h2>Exceptions - bypassing OpenDNS for some specific names</h2>
<p>
Some domain names should not be resolved by a third-party DNS
resolver, that may not know about them.
</p>
<p>
This includes local domain names provided by home routers
(like "routerlogin.net"), local domain names provided by
operating systems and applications (like ".local" or ".lan"),
local domain names served by appliances like st-top boxes, and
internal domains used in corporate networks.
</p>
<p>
Domains listed here will bypass DNSCrypt in order to be sent
to the default resolvers.
</p>
<p>
Do
<strong>not</strong>
use a tool like hostip(8), drill(1), unbound-host(1), dig(1) or host(1)
in order to check that an exception rule works.
</p>
<p>
These tools use their own resolution mechanisms that have nothing
to do with how others apps on your system are resolving names.
</p>
<p>
They don't use the OSX-specific stub resolver, they don't use
the system-wide DNS cache, they have bugs and limitations that the OS
doesn't have (and the opposite is also true), and they don't know a
thing about specific resolvers that have to be used for specific
domains.
</p>
<p>
Use actual apps, or even a command like ping(8).
</p>
</section>
</body>
</html>
@@ -21,6 +21,48 @@
%body
%h1 Release Notes for the user interface
%article
%h2 Version 0.18
%time Wed, 3 Oct 2012
%ul
%li
freebox.fr has been added to the default list of domains
for which DNSCrypt should be bypassed.
%li
If a static resolvers set has been specified, this will now be
used for exceptions instead of DHCP-provided servers.
%li
Minor cosmetic fixes and documentation improvements have been
made.
%article
%h2 Version 0.17
%time Fri, 28 Sep 2012
%ul
%li dnscrypt-proxy has been updated to 1.1.0-final.
%li The uninstaller is now bundled with the preference pane.
%li
Static default DNS resolvers can now be used instead of
having them provided by a DHCP server.
%li Advanced parental controls.
%li
Logging: outgoing queries can now be logged and displayed in
real time.
%li
OpenDNS networks settings lock-in: use your own network
settings no matter what actual network you are connected to.
Now, you can stay protected from botnets, malware, phishing, and
block unwanted content, even when using public Wi-Fi hotspots.
%li
IP-based blocking: DNS responses containing IP addresses
present in a user-defined set of addresses can be blocked.
%li
Pattern-based name blocking: block domain names matching
suffixes, prefixes and substrings.
%li
A list of exceptions that should bypass DNSCrypt and be
resolved by a local server can be now specified.
%article
%h2 Version 0.16 released!
%time Wed, 19 Sep 2012
@@ -38,7 +80,7 @@
%article
%h2 Version 0.15 released!
%time Wed, 07 Sep 2012
%time Fri, 07 Sep 2012
%ul
%li dnscrypt-proxy has been updated to 1.1.0-RC1
%li
@@ -23,6 +23,59 @@
</head>
<body>
<h1>Release Notes for the user interface</h1>
<article>
<h2>Version 0.18</h2>
<time>Wed, 3 Oct 2012</time>
<ul>
<li>
freebox.fr has been added to the default list of domains
for which DNSCrypt should be bypassed.
</li>
<li>
If a static resolvers set has been specified, this will now be
used for exceptions instead of DHCP-provided servers.
</li>
<li>
Minor cosmetic fixes and documentation improvements have been
made.
</li>
</ul>
</article>
<article>
<h2>Version 0.17</h2>
<time>Fri, 28 Sep 2012</time>
<ul>
<li>dnscrypt-proxy has been updated to 1.1.0-final.</li>
<li>The uninstaller is now bundled with the preference pane.</li>
<li>
Static default DNS resolvers can now be used instead of
having them provided by a DHCP server.
</li>
<li>Advanced parental controls.</li>
<li>
Logging: outgoing queries can now be logged and displayed in
real time.
</li>
<li>
OpenDNS networks settings lock-in: use your own network
settings no matter what actual network you are connected to.
Now, you can stay protected from botnets, malware, phishing, and
block unwanted content, even when using public Wi-Fi hotspots.
</li>
<li>
IP-based blocking: DNS responses containing IP addresses
present in a user-defined set of addresses can be blocked.
</li>
<li>
Pattern-based name blocking: block domain names matching
suffixes, prefixes and substrings.
</li>
<li>
A list of exceptions that should bypass DNSCrypt and be
resolved by a local server can be now specified.
</li>
</ul>
</article>
<article>
<h2>Version 0.16 released!</h2>
<time>Wed, 19 Sep 2012</time>
@@ -43,7 +96,7 @@
</article>
<article>
<h2>Version 0.15 released!</h2>
<time>Wed, 07 Sep 2012</time>
<time>Fri, 07 Sep 2012</time>
<ul>
<li>dnscrypt-proxy has been updated to 1.1.0-RC1</li>
<li>
@@ -0,0 +1,46 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>CFBundleAllowMixedLocalizations</key>
<true/>
<key>CFBundleDevelopmentRegion</key>
<string>English</string>
<key>CFBundleExecutable</key>
<string>applet</string>
<key>CFBundleIconFile</key>
<string>applet</string>
<key>CFBundleIdentifier</key>
<string>com.apple.ScriptEditor.id.Uninstall</string>
<key>CFBundleInfoDictionaryVersion</key>
<string>6.0</string>
<key>CFBundleName</key>
<string>Uninstall</string>
<key>CFBundlePackageType</key>
<string>APPL</string>
<key>CFBundleSignature</key>
<string>aplt</string>
<key>LSMinimumSystemVersionByArchitecture</key>
<dict>
<key>x86_64</key>
<string>10.6</string>
</dict>
<key>LSRequiresCarbon</key>
<true/>
<key>WindowState</key>
<dict>
<key>dividerCollapsed</key>
<false/>
<key>eventLogLevel</key>
<integer>-1</integer>
<key>name</key>
<string>ScriptWindowState</string>
<key>positionOfDivider</key>
<real>333</real>
<key>savedFrame</key>
<string>68 149 602 597 0 0 1366 746 </string>
<key>selectedTabView</key>
<string>result</string>
</dict>
</dict>
</plist>
Binary file not shown.

After

Width:  |  Height:  |  Size: 362 B

@@ -0,0 +1,4 @@
{\rtf1\ansi\ansicpg1252\cocoartf1187\cocoasubrtf340
{\fonttbl}
{\colortbl;\red255\green255\blue255;}
}
@@ -1,3 +0,0 @@
#! /bin/sh
exec /usr/local/bin/alarmer $*
@@ -0,0 +1 @@
/usr/local/bin/alarmer
@@ -1,3 +0,0 @@
#! /bin/sh
exec /usr/local/sbin/dnscrypt-proxy $*
@@ -0,0 +1 @@
/usr/local/sbin/dnscrypt-proxy
@@ -1,3 +0,0 @@
#! /bin/sh
exec /usr/local/bin/hostip $*
@@ -0,0 +1 @@
/usr/local/bin/hostip
Binary file not shown.
@@ -0,0 +1 @@
libldns.1.dylib
@@ -2,4 +2,8 @@
. ./common.inc
rm -f "$QUERY_LOG_FILE"
./clear-fw.sh
exec ./handle-control-change.sh --boot
@@ -0,0 +1,15 @@
#! /bin/sh
. ./common.inc
exec >/dev/null
exec 2>&1
SOCKETFILTERFW='/usr/libexec/ApplicationFirewall/socketfilterfw'
[ -x "$SOCKETFILTERFW" ] || exit 0
"$SOCKETFILTERFW" --add /usr/local/sbin/dnscrypt-proxy
"$SOCKETFILTERFW" --unblockapp /usr/local/sbin/dnscrypt-proxy
"$SOCKETFILTERFW" --add /usr/local/bin/hostip
"$SOCKETFILTERFW" --unblockapp /usr/local/bin/hostip
@@ -15,10 +15,23 @@ FAMILYSHIELD_FILE="${CONTROL_DIR}/familyshield"
INSECURE_OPENDNS_FILE="${CONTROL_DIR}/insecure-opendns"
FALLBACK_FILE="${CONTROL_DIR}/fallback"
HANDLERS_LOCK_FILE="/var/run/dnscrypt-handlers.lock"
DOMAINS_EXCEPTIONS_FILE="${CONTROL_DIR}/domains-exceptions"
DNSCRYPT_PROXY_PLUGINS_FILE="${CONTROL_DIR}/plugins"
DNSCRYPT_PROXY_PLUGINS_BASE_FILE="${CONTROL_DIR}/plugin"
STATIC_RESOLVERS_FILE="${CONTROL_DIR}/static-resolvers"
PLUGINS_ENABLED_FILE="${CONTROL_DIR}/plugins.enabled"
PARENTAL_CONTROLS_FILE="${CONTROL_DIR}/plugin-parental-controls.enabled"
QUERY_LOGGING_FILE="${CONTROL_DIR}/plugin-query-logging.enabled"
LOCKIN_FILE="${CONTROL_DIR}/plugin-lockin.enabled"
BLOCKING_FILE="${CONTROL_DIR}/plugin-blocking.enabled"
QUERY_LOG_FILE="/var/log/dnscrypt-query.log"
BLACKLIST_IPS_FILE="${CONTROL_DIR}/blacklist-ips"
BLACKLIST_IPS_TMP_FILE="${BLACKLIST_IPS_FILE}.tmp"
BLACKLIST_DOMAINS_FILE="${CONTROL_DIR}/blacklist-domains"
BLACKLIST_DOMAINS_TMP_FILE="${BLACKLIST_DOMAINS_FILE}.tmp"
EXCEPTIONS_FILE="${CONTROL_DIR}/exceptions"
EXCEPTIONS_TMP_FILE="${EXCEPTIONS_FILE}.tmp"
INTERFACE_UNBOUND="127.0.0.53"
INTERFACE_UNBOUND_MASK="24"
INTERFACE_PROXY="127.0.0.54"
@@ -27,7 +40,7 @@ INTERFACE_PROBES="127.0.0.55"
INTERFACE_PROBES_MASK="24"
DOMAINS_EXCEPTIONS='
fritz.box intranet lan localdomain nowtv.com private routerlogin.net
freebox.fr fritz.box intranet lan localdomain nowtv.com private routerlogin.net
'
export PATH="${DNSCRYPT_USR_BASE_DIR}/bin:${DNSCRYPT_USR_BASE_DIR}/scripts:$PATH"
@@ -4,8 +4,8 @@ RESOLVER_DIR='/etc/resolver'
. ./common.inc
[ -r "$DOMAINS_EXCEPTIONS_FILE" ] &&
DOMAINS_EXCEPTIONS="$(cat "$DOMAINS_EXCEPTIONS_FILE") $DOMAINS_EXCEPTIONS"
[ -r "$EXCEPTIONS_FILE" ] &&
DOMAINS_EXCEPTIONS="$(cat "$EXCEPTIONS_FILE") $DOMAINS_EXCEPTIONS"
get_gw() {
route -n get default | while read line; do
@@ -22,13 +22,32 @@ get_dhcp_dns() {
cat "${STATES_DIR}/dhcp-dns" 2> /dev/null
}
name_servers=$(get_dhcp_dns || get_gw)
remove_old_exceptions() {
local found
find -x "$RESOLVER_DIR" -type f -print | {
while read file; do
found='no'
for domain in $DOMAINS_EXCEPTIONS; do
[ "$file" = "${RESOLVER_DIR}/${domain}" ] && found='yes' && break
done
[ "$found" = 'no' ] || continue
fgrep -ci 'automatically generated by the dnscrypt user interface' \
$file > /dev/null 2>&1 || continue
rm -f "$file"
done
}
}
name_servers=$(./get-static-resolvers.sh || get_dhcp_dns || get_gw)
[ x"$name_servers" = 'x' ] && exit 0
default_domain=$(./get-current-default-domain.sh)
mkdir -p "$RESOLVER_DIR" || exit 1
remove_old_exceptions
name_server="$gw"
for domain in $DOMAINS_EXCEPTIONS; do
if [ x"$default_domain" != 'x' ]; then
@@ -4,8 +4,8 @@ RESOLVER_DIR='/etc/resolver'
. ./common.inc
[ -r "$DOMAINS_EXCEPTIONS_FILE" ] &&
DOMAINS_EXCEPTIONS="$(cat "$DOMAINS_EXCEPTIONS_FILE") $DOMAINS_EXCEPTIONS"
[ -r "$EXCEPTIONS_FILE" ] &&
DOMAINS_EXCEPTIONS="$(cat "$EXCEPTIONS_FILE") $DOMAINS_EXCEPTIONS"
for domain in $DOMAINS_EXCEPTIONS; do
rm -f "${RESOLVER_DIR}/${domain}"
@@ -0,0 +1,9 @@
#! /bin/sh
. ./common.inc
if [ -e "$LOCKIN_FILE" ]; then
echo 'yes'
else
echo 'no'
fi
@@ -0,0 +1,9 @@
#! /bin/sh
. ./common.inc
if [ -e "$PARENTAL_CONTROLS_FILE" ]; then
echo 'yes'
else
echo 'no'
fi
@@ -0,0 +1,9 @@
#! /bin/sh
. ./common.inc
if [ -e "$QUERY_LOGGING_FILE" ]; then
echo 'yes'
else
echo 'no'
fi
@@ -0,0 +1,7 @@
#! /bin/sh
. ./common.inc
[ -r "$STATIC_RESOLVERS_FILE" ] && cat "$STATIC_RESOLVERS_FILE" && exit 0
exit 1
@@ -0,0 +1,17 @@
#! /bin/sh
. ./common.inc
args="$*"
[ $# -lt 1 ] && exit 1
servers=''
for server in $args; do
servers="${servers} ${server}"
done
if [ "$servers" = "" ]; then
rm -f "$STATIC_RESOLVERS_FILE"
else
echo "$servers" | sed 's/^ *//;s/ *$//' > "$STATIC_RESOLVERS_FILE"
fi
@@ -2,6 +2,9 @@
. ./common.inc
DNSCRYPT_LIB_BASE_DIR="${DNSCRYPT_USR_BASE_DIR}/lib"
export DYLD_LIBRARY_PATH="${DNSCRYPT_LIB_BASE_DIR}:${DYLD_LIBRARY_PATH}"
init_interfaces
mkdir -p -- "$DNSCRYPT_VAR_BASE_DIR" || exit 1
@@ -19,10 +22,6 @@ mkdir -p -- "$DESCRIPTIONS_DIR" || exit 1
PID_DIR="${PROBES_BASE_DIR}/pids" || exit 1
mkdir -p -- "$PID_DIR" || exit 1
DNSCRYPT_PROXY_PLUGINS=""
[ -r "$DNSCRYPT_PROXY_PLUGINS_FILE" ] &&
DNSCRYPT_PROXY_PLUGINS="$(cat "$DNSCRYPT_PROXY_PLUGINS_FILE")"
try_resolver() {
local priority="$1"
shift
@@ -51,6 +50,20 @@ try_resolver() {
done
}
get_plugin_args() {
cat "$DNSCRYPT_PROXY_PLUGINS_BASE_FILE"[s-]*.enabled | { \
local plugin_args=''
local quoted_line
while read line; do
case "$line" in
libdcplugin_*) plugin_args="${plugin_args} --plugin=${line}" ;;
esac
done
echo "$plugin_args"
}
}
./stop-dnscrypt-proxy.sh
ping6 -c 1 2620:0:ccc::2 > /dev/null 2>&1
@@ -84,7 +97,7 @@ if [ x"$ipv6_supported" = "xyes" ]; then
wait_pids="$wait_pids $!"
try_resolver 5002 'OpenDNS IPv6 using DNSCrypt on TCP port 443' \
"--resolver-address=[2620:0:ccc::2]:443 --tcp-only" &
wait_pids="$wait_pids $!"
wait_pids="$wait_pids $!"
try_resolver 5003 'OpenDNS IPv6 using DNSCrypt on TCP port 53' \
"--resolver-address=[2620:0:ccc::2]:53 --tcp-only" &
wait_pids="$wait_pids $!"
@@ -94,13 +107,13 @@ try_resolver 5004 'OpenDNS using DNSCrypt on UDP port 443' \
wait_pids="$wait_pids $!"
try_resolver 5005 'OpenDNS using DNSCrypt on UDP port 53' \
"--resolver-address=208.67.220.220:53" &
wait_pids="$wait_pids $!"
wait_pids="$wait_pids $!"
try_resolver 5006 'OpenDNS using DNSCrypt on TCP port 443' \
"--resolver-address=208.67.220.220:443 --tcp-only" &
wait_pids="$wait_pids $!"
wait_pids="$wait_pids $!"
try_resolver 5007 'OpenDNS using DNSCrypt on TCP port 53' \
"--resolver-address=208.67.220.220:53 --tcp-only" &
wait_pids="$wait_pids $!"
wait_pids="$wait_pids $!"
for pid in $wait_pids; do
wait $pid
@@ -111,11 +124,11 @@ done
[ x"$best_file" = "x" ] && exit 1
plugins_args=''
for plugin in $DNSCRYPT_PROXY_PLUGINS; do
plugin_args="${plugin_args} --plugin=${plugin}"
done
if [ -r "${DNSCRYPT_PROXY_PLUGINS_BASE_FILE}s.enabled" ]; then
plugin_args=$(get_plugin_args)
fi
best_args=$(cat "${RES_DIR}/${best_file}")
eval dnscrypt-proxy $best_args --local-address="$INTERFACE_PROXY" \
--pidfile="$PROXY_PID_FILE" --user=daemon --daemonize $plugin_args
@@ -0,0 +1,5 @@
#! /bin/sh
. ./common.inc
exec rm -f "$BLOCKING_FILE"
@@ -0,0 +1,17 @@
#! /bin/sh
. ./common.inc
plugin_args=''
[ -s "$BLACKLIST_IPS_FILE" ] && \
plugin_args="${plugin_args},--ips='${BLACKLIST_IPS_FILE}'"
[ -s "$BLACKLIST_DOMAINS_FILE" ] && \
plugin_args="${plugin_args},--domains='${BLACKLIST_DOMAINS_FILE}'"
[ -z "$plugin_args" ] && exec ./switch-blacklists-off.sh
echo "libdcplugin_example_ldns_blocking.la${plugin_args}" > \
"$BLOCKING_FILE"
touch "$PLUGINS_ENABLED_FILE"
@@ -0,0 +1,7 @@
#! /bin/sh
. ./common.inc
rm -f "$LOCKIN_FILE"
touch "$LOCKIN_ENABLED_FILE"
@@ -0,0 +1,42 @@
#! /bin/sh
. ./common.inc
get_opendns_config() {
exec dig +tries=3 +time=3 +short txt debug.opendns.com @208.67.222.222
}
get_client_ip() {
local client_ip=''
local has_thing_id='false'
while read line; do
case "$line" in
\"id\ *) has_thing_id='true' ;;
\"source\ *) client_ip=$(echo "$line" | cut -d' ' -f2 | cut -d ':' -f1) ;;
esac
done
[ x"$client_ip" != 'x' ] && echo "$client_ip" | egrep '^[0-9.]{1,15}$'
}
hex_ip() {
local dec="$1"
local hex=''
local OIFS="$IFS"
local p
IFS='.'
for p in $dec; do
hex="${hex}$(printf '%02x' $p)"
done
IFS="$OIFS"
echo "$hex"
}
client_ip=$(get_opendns_config | get_client_ip) || exit 1
client_ip_hex=$(hex_ip "$client_ip")
echo "libdcplugin_example_ldns_opendns_set_client_ip.la,${client_ip_hex}" > \
"$LOCKIN_FILE"
touch "$PLUGINS_ENABLED_FILE"
@@ -0,0 +1,7 @@
#! /bin/sh
. ./common.inc
rm -f "$PARENTAL_CONTROLS_FILE"
@@ -0,0 +1,8 @@
#! /bin/sh
. ./common.inc
echo 'libdcplugin_example_ldns_opendns_parental_control.la' > \
"$PARENTAL_CONTROLS_FILE"
touch "$PLUGINS_ENABLED_FILE"
@@ -0,0 +1,6 @@
#! /bin/sh
. ./common.inc
rm -f "$QUERY_LOGGING_FILE"
@@ -0,0 +1,8 @@
#! /bin/sh
. ./common.inc
echo "libdcplugin_example_logging.la,${QUERY_LOG_FILE}" > \
"$QUERY_LOGGING_FILE"
touch "$PLUGINS_ENABLED_FILE"
@@ -0,0 +1,14 @@
#! /bin/sh
. ./common.inc
if [ ! -s "$BLACKLIST_DOMAINS_TMP_FILE" ]; then
rm -f "$BLACKLIST_DOMAINS_FILE" "$BLACKLIST_DOMAINS_TMP_FILE"
exec ./switch-blacklists-on.sh
fi
tr -s '[:blank:]' '\n' < "$BLACKLIST_DOMAINS_TMP_FILE" | \
egrep -vi 'opendns[.]com$' > "${BLACKLIST_DOMAINS_TMP_FILE}~" &&
mv "${BLACKLIST_DOMAINS_TMP_FILE}~" "$BLACKLIST_DOMAINS_FILE"
exec ./switch-blacklists-on.sh
@@ -0,0 +1,14 @@
#! /bin/sh
. ./common.inc
if [ ! -s "$BLACKLIST_IPS_TMP_FILE" ]; then
rm -f "$BLACKLIST_IPS_FILE" "$BLACKLIST_IPS_TMP_FILE"
exec ./switch-blacklists-on.sh
fi
tr -s '[:blank:]' '\n' \
< "$BLACKLIST_IPS_TMP_FILE" > "${BLACKLIST_IPS_TMP_FILE}~" &&
mv "${BLACKLIST_IPS_TMP_FILE}~" "$BLACKLIST_IPS_FILE"
exec ./switch-blacklists-on.sh
@@ -0,0 +1,12 @@
#! /bin/sh
. ./common.inc
if [ ! -s "$EXCEPTIONS_TMP_FILE" ]; then
rm -f "$EXCEPTIONS_FILE" "$EXCEPTIONS_TMP_FILE"
exit 0
fi
tr -s '[:blank:]' '\n' < "$EXCEPTIONS_TMP_FILE" | \
egrep -i '^\s*[0-9a-z_.-]+\s*$' > "${EXCEPTIONS_TMP_FILE}~" &&
mv "${EXCEPTIONS_TMP_FILE}~" "$EXCEPTIONS_FILE"
Binary file not shown.
+28
View File
@@ -0,0 +1,28 @@
OpenDNS user interface for DNSCrypt (preview release)
=====================================================
DNS is one of the fundamental building blocks of the Internet. It's
used any time you visit a website, send an email, have an IM
conversation or do anything else online. While OpenDNS has provided
world-class security using DNS for years, the underlying DNS protocol
has not been secure enough for our comfort.
The "last mile" is the portion of your Internet connection between
your computer and your ISP.
DNSCrypt is a way of securing the "last mile" of DNS traffic and
resolving an entire class of serious security concerns with the DNS
protocol.
There have been numerous examples of tampering, or man-in-the-middle
attacks, and snooping of DNS traffic at the last mile and it
represents a serious security risk that we've always wanted to fix.
In the same way the SSL turns HTTP web traffic into HTTPS encrypted
Web traffic, DNSCrypt turns regular DNS traffic into authenticated and
encrypted DNS traffic that is secure from eavesdropping and
man-in-the-middle attacks.
It doesn't require any changes to domain names or how they work, it
simply provides a method for securely encrypting communication between
our customers and our DNS servers in our data centers.