summaryrefslogtreecommitdiffstats
path: root/tv/3modules/wwan.nix
blob: a60d314fd2ee96c2a098ca1d85b484dcb0b6c6b6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
with import ./lib;
{ config, pkgs, ... }: {
  options = {
    tv.wwan.enable = mkEnableOption "tv.wwan";
    tv.wwan.apn = mkOption {
      type = with types; filename;
    };
    tv.wwan.device = mkOption {
      type = with types; pathname;
      default = "/dev/cdc-wdm0";
    };
    tv.wwan.interface = mkOption {
      type = with types; nullOr filename;
      default = null;
    };
    tv.wwan.operators = mkOption {
      type = with types; listOf username;
      default = [];
    };
    tv.wwan.secrets = mkOption {
      type = with types; pathname;
      default = toString <secrets/wwan.json>;
      # format: {"pin1":number}
    };
  };
  config = let
    cfg = config.tv.wwan;
  in mkIf cfg.enable {
    nixpkgs.overlays = singleton (self: super: {
      uqmi-wrapper = pkgs.symlinkJoin {
        name = "uqmi-wrapper";
        paths = [
          (pkgs.writeDashBin "uqmi" ''
            exec ${pkgs.uqmi}/bin/uqmi --device=${cfg.device} "$@"
          '')
          pkgs.uqmi
        ];
      };
    });
    systemd.services.wwan = {
      environment = {
        SECRETS = "%d/secrets";
      };
      path = [
        pkgs.busybox
        pkgs.coreutils
        pkgs.iproute2
        pkgs.jq
        pkgs.uqmi-wrapper
        (pkgs.writeDashBin "get-interface" (
          if cfg.interface != null then /* sh */ ''
            echo ${cfg.interface}
          '' else /* sh */ ''
            exec ${pkgs.libqmi}/bin/qmicli -d ${cfg.device} -p --get-wwan-iface
          ''
        ))
      ];
      serviceConfig = {
        LoadCredential = [
          "secrets:${cfg.secrets}"
        ];
        Type = "oneshot";
        RemainAfterExit = true;
        SyslogIdentifier = "wwan";
        ExecStart = pkgs.writeDash "tv.wwan.start.sh" ''
          set -efu

          interface=$(get-interface)

          pin1_status=$(
            uqmi --uim-get-sim-state |
            jq -r '"\(.pin1_status)/\(.pin1_verify_tries)"'
          )
          case $pin1_status in
            verified/*)
              :
              ;;
            not_verified/3)
              pin1=$(jq .pin1 "$SECRETS")
              echo "verifying PIN1" >&2
              if ! uqmi --uim-verify-pin1 "$pin1"; then
                echo "error: failed to verify PIN1" >&2
                exit 1
              fi
              ;;
            not_verified/*)
              echo "error: not trying to verify PIN1: not enough tries left" >&2
              echo \
                  "please check your configuration in ${cfg.secrets}" \
                  " and verify if manually using:" \
                  " ${pkgs.uqmi}/bin/uqmi -d $device --uim-veriy-pin1 XXXX" \
                  >&2
              exit 1
          esac

          raw_ip_path=/sys/class/net/$interface/qmi/raw_ip
          raw_ip=$(cat "$raw_ip_path")
          if [ "$raw_ip" != Y ]; then
            echo "enabling raw-ip" >&2
            if ! echo Y > "$raw_ip_path"; then
              echo "error: failed to enable raw-ip" >&2
              exit 1
            fi
          fi

          operating_mode=$(uqmi --get-device-operating-mode | tr -d \")
          case $operating_mode in
            online)
              :
              ;;
            persistent_low_power|low_power)
              echo "settings device operating mode to online" >&2
              uqmi --set-device-operating-mode online
              operating_mode=$(uqmi --get-device-operating-mode | tr -d \")
              if test "$operating_mode" != online; then
                echo "error: failed to set device operating mode to online" >&2
                exit 1
              fi
              ;;
            *)
              echo "error: don't know how to change device operating mode to online: $operating_mode" >&2
              exit 1
          esac

          ip link set dev "$interface" up

          data_status=$(uqmi --get-data-status | tr -d \")
          case $data_status in
            connected)
              :
              ;;
            disconnected)
              echo "starting network (APN=${cfg.apn})" >&2
              sleep 1
              uqmi \
                  --start-network \
                  --autoconnect \
                  --apn ${cfg.apn} \
                  --ip-family ipv4
              sleep 1
              ;;
            *)
              echo "error: unsupported data status: $data_status" >&2
              exit 1
          esac

          udhcpc -q -f -n -i "$interface"
        '';
        Restart = "on-failure";
        ExecStop = pkgs.writeDash "tv.wwan.stop.sh" ''
          set -efu

          interface=$(get-interface)

          ip link set dev "$interface" down
          uqmi --stop-network 0xFFFFFFFF --autoconnect
          uqmi --sync
          uqmi --set-device-operating-mode persistent_low_power
        '';
      };
    };
    users.users.root.packages = [
      pkgs.uqmi-wrapper
    ];
    tv.systemd.services.wwan.operators = cfg.operators;
  };
}