#!/bin/bash
#
# ifdown-ipv6
#
#@-INF@# RedHat 6.2 + 7.x
#@-INF@#
#@-INF@# directory: /etc/sysconfig/network-scripts
#@-INF@#
#@-INF@# permissions: 755
#@-INF@#
#@-INF@# description: Brings down IPv6 for an interface
#
#@+RH7@# Taken from:
# (P) & (C) 2000-2002 by Peter Bieringer <pb@bieringer.de>
#
#  You will find more information in the IPv6-HowTo for Linux at
#   http://www.bieringer.de/linux/IPv6/
#
# RHL integration assistance by Pekka Savola <pekkas@netcore.fi>
#
# Version 2002-01-06b
#
# Uses following information from /etc/sysconfig/network:
#  NETWORKING_IPV6=yes|no: controls IPv6 initialization (global setting)
#
# Uses following information from /etc/sysconfig/network-scripts/ifcfg-$1:
#  DEVICE=<device>
#  IPV6INIT=yes|no: controls IPv6 configuration for this interface
#
# Optional for 6to4 tunneling:
#  IPV6TO4_RELAY=<ipv4address>: IPv4 address of the remote 6to4 relay [default: 192.88.99.1]
#  IPV6TO4_ROUTING="eth0-:f101::0/64 eth1-:f102::0/64": information to setup local subnetting
#  IPV6TO4_SETUP_METHOD=sit0|tun6to4: generic tunnel or dedicated tunnel usage (default)
#
# Optional for 6to4 tunneling or ppp links to trigger radvd:
#  IPV6_CONTROL_RADVD=yes|no: controls radvd triggering [optional]
#  IPV6_RADVD_PIDFILE=<file>: PID file of radvd for sending signals, default is "/var/run/radvd/radvd.pid" [optional]
#
#  Required version of radvd to use 6to4 prefix recalculation
#   0.6.2p3 or newer supporting option "Base6to4Interface"
#  Required version of radvd to use dynamic ppp links
#   0.7.0 + fixes or newer
#
#@-INF@#  This script is now explicitly GPL'ed (20001125, Peter Bieringer)
#@-INF@#   http://www.gnu.org/copyleft/gpl.html
#@-INF@#
#@-INF@#  Suggestions, comments and improvements are welcome!
#@-INF@#
#@-INF@# Changes to:
#@-INF@#  20000703 :initial for a new layout
#@-INF@#  20000704 :add test for static route file
#@-INF@#  20000723 :fix bug in static route selection
#@-INF@#  20000731 :fix misnamed function 'forwarding-ipv6-route' -> 'forwarding-ipv6'
#@-INF@#  20000816 :fix because "network-functions-ipv6" function names are changed
#@-INF@#  20001125 :explicitly GPL'ed
#@-INF@#  20001130 :remove not needed copyright reference to RedHat
#@-INF@#  20010202 :Backpatch changes done in Rawhide/initscripts-5.60-1.src.rpm by others
#@-INF@#            Tag several lines for easier stripping of unnecessary lines 
#@-INF@#            Enable support for IPV6ADDR_SECONDARIES (a list of IPv6 addresses)
#@-INF@#             remove IPV6ADDR_0 + IPV6ADDR_1 support 
#@-INF@#             prefixlength can be directly specified on IPv6 address
#@-INF@#  20010203 :Remove obsolete tunnel entries, add cleanup call at the end
#@-INF@#  20010208 :Remove backward compatibility for extra prefix length
#@-INF@#  20010304 :Add 6to4 setup support
#@-INF@#  20010309 :Review 6to4 setup support, takes IPv4 address from device first
#@-INF@#  20010310 :Cleanup for RH7 (line tagging)
#@-INF@#  20010310a:Shutdown IPv6 regardless of switches (to make sure the config is removed)
#@-INF@#  20010310b:Shutdown IPv6 really regardless (take data from ifconfig and route)
#@-INF@#  20010315 :Shutdown 6to4 config also regardless (take data from ifconfig and route)
#@-INF@#  20010418 :Remove IPV6TO4_RELAY_DEFAULT usage (not really used)
#@-INF@#  20010429 :Unsuccessful "test_ipv6" skips IPv6 initialization 
#@-INF@#  20010430 :Minor review
#@-INF@#  20010430a:Review "test_ipv6", use option "testonly", exit code set to 0
#@-INF@#  20010501 :Add radvd control code from ip-up.6to4
#@-INF@#  20010501a:Adapt forwarding control to kernel behavior
#@-INF@#  20010505 :Untag some lines on "network-functions-ipv6" exists check
#@-INF@#            Add some sysctls
#@-INF@#  20010507 :Major cosmetic review (change tabsize to 8 and cleanups)
#@-INF@#  20010519 :Remove setting of *.router_solicitations in proc
#@-INF@#  20010520b:Cosmetic fixes
#@-INF@#  20010522 :Tagging fixes
#@-INF@#  20010522d:Cosmetic fixes
#@-INF@#  20010614 :Delete old 6to4 routes, even if IPV6TO4_RELAY was changed
#@-INF@#  20010614a:Add support IPV6TO4_RELAY can be also a IPv6to4 address (not working at the moment because of missing kernel implementation)
#@-INF@#  20010707 :Cosmetic fix
#@-INF@#  20010715 :Minor review, triggered by Pekka Savola
#@-INF@#  20010731 :LC_ALL review
#@-INF@#  20010904 :Check for existing keys on using sysctl to skip error message about unknown keys
#@-INF@#  20011124b:Generalize handling of radvd trigger to use it also for dynamic ppp links
#@-INF@#           :Important: options renamed: IPV6TO4_CONTROL_RADVD -> IPV6_CONTROL_RADVD, IPV6TO4_RADVD_PIDFILE -> IPV6_RADVD_PIDFILE
#@-INF@#  20011124c:Adapt function names after renaming in libary
#@-INF@#  20020101 :Add support for dedicated 6to4 tunnel device (default now)
#@-INF@#  20020103 :IPV6TO4_RELAY get a default now, if not specified
#@-INF@#  20020103a:Spell checking, add compatibility mode for *RADVD* to use old values also
#@-INF@#  20020104 :Review 6to4 setup, don't shut down non related 6to4 dedicated tunnels
#@-INF@#  20020104a:Use "ipv6_get_ipv4addr_of_tunnel" instead of simple "ip" call, don't shutdown non related 6to4 using sit0
#@-INF@#  20020105 :Remove static routes support for 6to4, use "ipv6_get_ipv4addr_of_device" now instead of "ifconfig"
#@-INF@#  20020106 :Minor cleanup
#@-INF@#  20020106a:Review log text
#@-INF@#  20020106b:Revert log style to 20020106 one

# Filter tags (for stripping, empty lines following if all is stripped) #@-INF@#
#  #@-DEB@#  : Additional debug code
#  #@-INF@#  : Additional information
#  #@-RH7@#  : Not necessary for RedHat 7.x
#  #@+RH7@#  : Necessary for RedHat 7.x

[ -f /etc/sysconfig/network ] || exit 1											#@-RH7@#
. /etc/sysconfig/network 

cd /etc/sysconfig/network-scripts
[ -f network-functions ] || exit 1											#@-RH7@#
. network-functions 

CONFIG=$1
[ -f "$CONFIG" ] || CONFIG=ifcfg-$CONFIG
source_config                                                                   

# Test whether IPv6 should be configured, else stop
[ "${NETWORKING_IPV6}" = "yes" ] || exit 0

if [ ! -f /etc/sysconfig/network-scripts/network-functions-ipv6 ]; then
	# IPv6 setup isn't well												#@-RH7@#
	echo $"You have enabled IPv6 in '/etc/sysconfig/network'"							#@-RH7@#
	echo $" by setting 'NETWORKING_IPV6' to 'yes', but"								#@-RH7@#
	echo $" file '/etc/sysconfig/network-scripts/network-functions-ipv6'"						#@-RH7@#
	echo $"is missing"												#@-RH7@#
	exit 1
fi

# Source IPv6 helper functions
. /etc/sysconfig/network-scripts/network-functions-ipv6

# Test version of /etc/sysconfig/network-scripts/network-functions-ipv6							#@-RH7@#
versioncurrent="`getversion_ipv6_functions`"										#@-RH7@#
versionneeded="20020106"												#@-RH7@#
if [ $versioncurrent -lt $versionneeded ]; then										#@-RH7@#
	echo $"'/etc/sysconfig/network-scripts/network-functions-ipv6' has version '$versioncurrent', but '$0' needs version '$versionneeded' or higher, so please update"   #@-RH7@#
	exit 1														#@-RH7@#
fi															#@-RH7@#

# IPv6 test, no module loaded, exit if system is not IPv6-ready
ipv6_test testonly || exit 0

# Test device status
ipv6_test_device_status $DEVICE
if [ "$?" = 2 ]; then
	# device doesn't exist
	exit 1
fi

# Switch some sysctls to secure mode
sysctl -w net.ipv6.conf.$DEVICE.forwarding=0 >/dev/null
sysctl -w net.ipv6.conf.$DEVICE.accept_ra=0 >/dev/null
sysctl -w net.ipv6.conf.$DEVICE.accept_redirects=0 >/dev/null

# Shutdown of 6to4, if configured
valid6to4config="yes"
if [ -z "$IPV6TO4_RELAY" ]; then
	IPV6TO4_RELAY="192.88.99.1"
fi

# Check method
if [ -z "$IPV6TO4_SETUP_METHOD" ]; then
	tundev="tun6to4"
elif [ "$IPV6TO4_SETUP_METHOD" = "tun6to4" ]; then
	tundev="tun6to4"
elif [ "$IPV6TO4_SETUP_METHOD" = "sit0" ]; then
	tundev="sit0"
else
	echo $"Unsupported 6to4 tunneling setup method '$IPV6TO4_SETUP_METHOD'"
	valid6to4config="no"
fi

# Get IPv4 address from interface
if [ ! -z "$IPV6TO4_IPV4ADDR" ]; then
	# Take special configured from config file (precedence 1)
	ipv4addr="$IPV6TO4_IPV4ADDR"
	echo $"Overwrite 6to4 address with '$ipv4addr'"                                                        #@-RH7@#
else
	# Get IPv4 address from interface first (has precedence 2)
	ipv4addr="`ipv6_get_ipv4addr_of_device $DEVICE`"
	if [ -z "$ipv4addr" ]; then
		# Take configured from config file (precedence 3)
		ipv4addr="$IPADDR"
	fi
fi

# Check against configured 6to4 tunnel to see if this interface was used before
if [ "$IPV6TO4_SETUP_METHOD" = "tun6to4" ]; then
	# Get local IPv4 address of dedicated tunnel
	ipv4addr6to4local="`ipv6_get_ipv4addr_of_tunnel tun6to4 local`"
	if [ "$ipv4addr" != "$ipv4addr6to4local" ]; then
		# IPv4 address of interface does't match local tunnel address, interface was not used for current 6to4 setup
		valid6to4config="no"
	fi
elif [ "$IPV6TO4_SETUP_METHOD" = "sit0" ]; then
	# Generate 6to4 prefix of given IPv4 address	
	prefix6to4local="`ipv6_create_6to4_prefix $ipv4addr`"
	# Check for prefix exists on device
	ipv6_test_addrprefix_exists_on_device sit0 $prefix6to4local
	if [ $? != 0 ]; then
		# IPv6to4 prefix not on generic tunnel device, interface was not used for current 6to4 setup
		valid6to4config="no"
	fi
fi

# Control running radvd
if [ "$IPV6_CONTROL_RADVD" = "yes" -o "$IPV6TO4_CONTROL_RADVD" = "yes" ]; then
	radvdpidfile="$IPV6_RADVD_PIDFILE"
	if [ -z "$pidfile" ]; then
		radvdpidfile="$IPV6TO4_RADVD_PIDFILE"
	fi

	if [ "$valid6to4config" = "yes" ]; then
		ipv6_trigger_radvd 6to4 $radvdpidfile
	else
		ipv6_trigger_radvd ppp $radvdpidfile
	fi
fi

# Shutdown of 6to4, if configured
if [ "$valid6to4config" = "yes" ]; then
	if [ ! -z "$IPV6TO4_ROUTING" ]; then
		# Delete routes to local networks
		for devsuf in $IPV6TO4_ROUTING; do
			dev="`echo $devsuf | awk -F- '{ print $1 }'`"
			ipv6_cleanup_routes $dev ::
		done
	fi

	# Detect type of address, whether it is IPv4 or IPv6
	if ipv6_test_ipv6_addr_valid $IPV6TO4_RELAY quiet; then
		# IPv6 address is a 6to4										#@-RH7@#
		relay6to4type="ipv6"
	fi

	if [ "$tundev" = "sit0" ]; then
		# Delete all static IPv6to4 routes
		if [ "$relay6to4type" = "ipv6" ]; then	
			ipv6_cleanup_routes $tundev $IPV6TO4_RELAY
		else
			ipv6_cleanup_routes $tundev ::$IPV6TO4_RELAY
		fi
	fi

	# Delete all configured 6to4 address
	ipv6_cleanup_6to4_tunnels $tundev 
fi

# Delete all current configured IPv6 addresses on this interface 
ipv6_cleanup_device $DEVICE
