| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447 | /* * Copyright (c)2019 ZeroTier, Inc. * * Use of this software is governed by the Business Source License included * in the LICENSE.TXT file in the project's root directory. * * Change Date: 2026-01-01 * * On the date above, in accordance with the Business Source License, use * of this software will be governed by version 2.0 of the Apache License. *//****/#include "LFDB.hpp"#ifdef CMAKE_BUILD#include "httplib.h"#else#include "../ext/cpp-httplib/httplib.h"#endif#include "../osdep/OSUtils.hpp"#include <chrono>#include <iostream>#include <sstream>#include <thread>namespace ZeroTier {LFDB::LFDB(const Identity& myId, const char* path, const char* lfOwnerPrivate, const char* lfOwnerPublic, const char* lfNodeHost, int lfNodePort, bool storeOnlineState)	: DB()	, _myId(myId)	, _lfOwnerPrivate((lfOwnerPrivate) ? lfOwnerPrivate : "")	, _lfOwnerPublic((lfOwnerPublic) ? lfOwnerPublic : "")	, _lfNodeHost((lfNodeHost) ? lfNodeHost : "127.0.0.1")	, _lfNodePort(((lfNodePort > 0) && (lfNodePort < 65536)) ? lfNodePort : 9980)	, _running(true)	, _ready(false)	, _storeOnlineState(storeOnlineState){	_syncThread = std::thread([this]() {		char controllerAddress[24];		const uint64_t controllerAddressInt = _myId.address().toInt();		_myId.address().toString(controllerAddress);		std::string networksSelectorName("com.zerotier.controller.lfdb:");		networksSelectorName.append(controllerAddress);		networksSelectorName.append("/network");		// LF record masking key is the first 32 bytes of SHA512(controller private key) in hex,		// hiding record values from anything but the controller or someone who has its key.		uint8_t sha512pk[64];		_myId.sha512PrivateKey(sha512pk);		char maskingKey[128];		Utils::hex(sha512pk, 32, maskingKey);		httplib::Client htcli(_lfNodeHost.c_str(), _lfNodePort);		int64_t timeRangeStart = 0;		while (_running.load()) {			{				std::lock_guard<std::mutex> sl(_state_l);				for (auto ns = _state.begin(); ns != _state.end(); ++ns) {					if (ns->second.dirty) {						nlohmann::json network;						if (get(ns->first, network)) {							nlohmann::json newrec, selector0;							selector0["Name"] = networksSelectorName;							selector0["Ordinal"] = ns->first;							newrec["Selectors"].push_back(selector0);							newrec["Value"] = network.dump();							newrec["OwnerPrivate"] = _lfOwnerPrivate;							newrec["MaskingKey"] = maskingKey;							newrec["PulseIfUnchanged"] = true;							try {								auto resp = htcli.Post("/makerecord", newrec.dump(), "application/json");								if (resp) {									if (resp->status == 200) {										ns->second.dirty = false;										// printf("SET network %.16llx %s\n",ns->first,resp->body.c_str());									}									else {										fprintf(stderr, "ERROR: LFDB: %d from node (create/update network): %s" ZT_EOL_S, resp->status, resp->body.c_str());									}								}								else {									fprintf(stderr, "ERROR: LFDB: node is offline" ZT_EOL_S);								}							}							catch (std::exception& e) {								fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (create/update network): %s" ZT_EOL_S, e.what());							}							catch (...) {								fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (create/update network): unknown exception" ZT_EOL_S);							}						}					}					for (auto ms = ns->second.members.begin(); ms != ns->second.members.end(); ++ms) {						if ((_storeOnlineState) && (ms->second.lastOnlineDirty) && (ms->second.lastOnlineAddress)) {							nlohmann::json newrec, selector0, selector1, selectors, ip;							char tmp[1024], tmp2[128];							OSUtils::ztsnprintf(tmp, sizeof(tmp), "com.zerotier.controller.lfdb:%s/network/%.16llx/online", controllerAddress, (unsigned long long)ns->first);							ms->second.lastOnlineAddress.toIpString(tmp2);							selector0["Name"] = tmp;							selector0["Ordinal"] = ms->first;							selector1["Name"] = tmp2;							selector1["Ordinal"] = 0;							selectors.push_back(selector0);							selectors.push_back(selector1);							newrec["Selectors"] = selectors;							const uint8_t* const rawip = (const uint8_t*)ms->second.lastOnlineAddress.rawIpData();							switch (ms->second.lastOnlineAddress.ss_family) {								case AF_INET:									for (int j = 0; j < 4; ++j)										ip.push_back((unsigned int)rawip[j]);									break;								case AF_INET6:									for (int j = 0; j < 16; ++j)										ip.push_back((unsigned int)rawip[j]);									break;								default:									ip = tmp2;	 // should never happen since only IP transport is currently supported									break;							}							newrec["Value"] = ip;							newrec["OwnerPrivate"] = _lfOwnerPrivate;							newrec["MaskingKey"] = maskingKey;							newrec["Timestamp"] = ms->second.lastOnlineTime;							newrec["PulseIfUnchanged"] = true;							try {								auto resp = htcli.Post("/makerecord", newrec.dump(), "application/json");								if (resp) {									if (resp->status == 200) {										ms->second.lastOnlineDirty = false;										// printf("SET member online %.16llx %.10llx %s\n",ns->first,ms->first,resp->body.c_str());									}									else {										fprintf(stderr, "ERROR: LFDB: %d from node (create/update member online status): %s" ZT_EOL_S, resp->status, resp->body.c_str());									}								}								else {									fprintf(stderr, "ERROR: LFDB: node is offline" ZT_EOL_S);								}							}							catch (std::exception& e) {								fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (create/update member online status): %s" ZT_EOL_S, e.what());							}							catch (...) {								fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (create/update member online status): unknown exception" ZT_EOL_S);							}						}						if (ms->second.dirty) {							nlohmann::json network, member;							if (get(ns->first, network, ms->first, member)) {								nlohmann::json newrec, selector0, selector1, selectors;								selector0["Name"] = networksSelectorName;								selector0["Ordinal"] = ns->first;								selector1["Name"] = "member";								selector1["Ordinal"] = ms->first;								selectors.push_back(selector0);								selectors.push_back(selector1);								newrec["Selectors"] = selectors;								newrec["Value"] = member.dump();								newrec["OwnerPrivate"] = _lfOwnerPrivate;								newrec["MaskingKey"] = maskingKey;								newrec["PulseIfUnchanged"] = true;								try {									auto resp = htcli.Post("/makerecord", newrec.dump(), "application/json");									if (resp) {										if (resp->status == 200) {											ms->second.dirty = false;											// printf("SET member %.16llx %.10llx %s\n",ns->first,ms->first,resp->body.c_str());										}										else {											fprintf(stderr, "ERROR: LFDB: %d from node (create/update member): %s" ZT_EOL_S, resp->status, resp->body.c_str());										}									}									else {										fprintf(stderr, "ERROR: LFDB: node is offline" ZT_EOL_S);									}								}								catch (std::exception& e) {									fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (create/update member): %s" ZT_EOL_S, e.what());								}								catch (...) {									fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (create/update member): unknown exception" ZT_EOL_S);								}							}						}					}				}			}			try {				std::ostringstream query;				query << "{"						 "\"Ranges\":[{"						 "\"Name\":\""					  << networksSelectorName					  << "\","						 "\"Range\":[0,18446744073709551615]"						 "}],"						 "\"TimeRange\":["					  << timeRangeStart					  << ",9223372036854775807],"						 "\"MaskingKey\":\""					  << maskingKey					  << "\","						 "\"Owners\":[\""					  << _lfOwnerPublic					  << "\"]"						 "}";				auto resp = htcli.Post("/query", query.str(), "application/json");				if (resp) {					if (resp->status == 200) {						nlohmann::json results(OSUtils::jsonParse(resp->body));						if ((results.is_array()) && (! results.empty())) {							for (std::size_t ri = 0; ri < results.size(); ++ri) {								nlohmann::json& rset = results[ri];								if ((rset.is_array()) && (! rset.empty())) {									nlohmann::json& result = rset[0];									if (result.is_object()) {										nlohmann::json& record = result["Record"];										if (record.is_object()) {											const std::string recordValue = result["Value"];											// printf("GET network %s\n",recordValue.c_str());											nlohmann::json network(OSUtils::jsonParse(recordValue));											if (network.is_object()) {												const std::string idstr = network["id"];												const uint64_t id = Utils::hexStrToU64(idstr.c_str());												if ((id >> 24) == controllerAddressInt) {	// sanity check													nlohmann::json oldNetwork;													if ((timeRangeStart > 0) && (get(id, oldNetwork))) {														const uint64_t revision = network["revision"];														const uint64_t prevRevision = oldNetwork["revision"];														if (prevRevision < revision) {															_networkChanged(oldNetwork, network, timeRangeStart > 0);														}													}													else {														nlohmann::json nullJson;														_networkChanged(nullJson, network, timeRangeStart > 0);													}												}											}										}									}								}							}						}					}					else {						fprintf(stderr, "ERROR: LFDB: %d from node (check for network updates): %s" ZT_EOL_S, resp->status, resp->body.c_str());					}				}				else {					fprintf(stderr, "ERROR: LFDB: node is offline" ZT_EOL_S);				}			}			catch (std::exception& e) {				fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (check for network updates): %s" ZT_EOL_S, e.what());			}			catch (...) {				fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (check for network updates): unknown exception" ZT_EOL_S);			}			try {				std::ostringstream query;				query << "{"						 "\"Ranges\":[{"						 "\"Name\":\""					  << networksSelectorName					  << "\","						 "\"Range\":[0,18446744073709551615]"						 "},{"						 "\"Name\":\"member\","						 "\"Range\":[0,18446744073709551615]"						 "}],"						 "\"TimeRange\":["					  << timeRangeStart					  << ",9223372036854775807],"						 "\"MaskingKey\":\""					  << maskingKey					  << "\","						 "\"Owners\":[\""					  << _lfOwnerPublic					  << "\"]"						 "}";				auto resp = htcli.Post("/query", query.str(), "application/json");				if (resp) {					if (resp->status == 200) {						nlohmann::json results(OSUtils::jsonParse(resp->body));						if ((results.is_array()) && (! results.empty())) {							for (std::size_t ri = 0; ri < results.size(); ++ri) {								nlohmann::json& rset = results[ri];								if ((rset.is_array()) && (! rset.empty())) {									nlohmann::json& result = rset[0];									if (result.is_object()) {										nlohmann::json& record = result["Record"];										if (record.is_object()) {											const std::string recordValue = result["Value"];											// printf("GET member %s\n",recordValue.c_str());											nlohmann::json member(OSUtils::jsonParse(recordValue));											if (member.is_object()) {												const std::string nwidstr = member["nwid"];												const std::string idstr = member["id"];												const uint64_t nwid = Utils::hexStrToU64(nwidstr.c_str());												const uint64_t id = Utils::hexStrToU64(idstr.c_str());												if ((id) && ((nwid >> 24) == controllerAddressInt)) {	// sanity check													nlohmann::json network, oldMember;													if ((timeRangeStart > 0) && (get(nwid, network, id, oldMember))) {														const uint64_t revision = member["revision"];														const uint64_t prevRevision = oldMember["revision"];														if (prevRevision < revision)															_memberChanged(oldMember, member, timeRangeStart > 0);													}													else if (hasNetwork(nwid)) {														nlohmann::json nullJson;														_memberChanged(nullJson, member, timeRangeStart > 0);													}												}											}										}									}								}							}						}					}					else {						fprintf(stderr, "ERROR: LFDB: %d from node (check for member updates): %s" ZT_EOL_S, resp->status, resp->body.c_str());					}				}				else {					fprintf(stderr, "ERROR: LFDB: node is offline" ZT_EOL_S);				}			}			catch (std::exception& e) {				fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (check for member updates): %s" ZT_EOL_S, e.what());			}			catch (...) {				fprintf(stderr, "ERROR: LFDB: unexpected exception querying node (check for member updates): unknown exception" ZT_EOL_S);			}			timeRangeStart = time(nullptr) - 120;	// start next query 2m before now to avoid losing updates			_ready.store(true);			for (int k = 0; k < 4; ++k) {	// 2s delay between queries for remotely modified networks or members				if (! _running.load())					return;				std::this_thread::sleep_for(std::chrono::milliseconds(500));			}		}	});}LFDB::~LFDB(){	_running.store(false);	_syncThread.join();}bool LFDB::waitForReady(){	while (! _ready.load()) {		std::this_thread::sleep_for(std::chrono::milliseconds(500));	}	return true;}bool LFDB::isReady(){	return (_ready.load());}bool LFDB::save(nlohmann::json& record, bool notifyListeners){	bool modified = false;	const std::string objtype = record["objtype"];	if (objtype == "network") {		const uint64_t nwid = OSUtils::jsonIntHex(record["id"], 0ULL);		if (nwid) {			nlohmann::json old;			get(nwid, old);			if ((! old.is_object()) || (! _compareRecords(old, record))) {				record["revision"] = OSUtils::jsonInt(record["revision"], 0ULL) + 1ULL;				_networkChanged(old, record, notifyListeners);				{					std::lock_guard<std::mutex> l(_state_l);					_state[nwid].dirty = true;				}				modified = true;			}		}	}	else if (objtype == "member") {		const uint64_t nwid = OSUtils::jsonIntHex(record["nwid"], 0ULL);		const uint64_t id = OSUtils::jsonIntHex(record["id"], 0ULL);		if ((id) && (nwid)) {			nlohmann::json network, old;			get(nwid, network, id, old);			if ((! old.is_object()) || (! _compareRecords(old, record))) {				record["revision"] = OSUtils::jsonInt(record["revision"], 0ULL) + 1ULL;				_memberChanged(old, record, notifyListeners);				{					std::lock_guard<std::mutex> l(_state_l);					_state[nwid].members[id].dirty = true;				}				modified = true;			}		}	}	return modified;}void LFDB::eraseNetwork(const uint64_t networkId){	// TODO}void LFDB::eraseMember(const uint64_t networkId, const uint64_t memberId){	// TODO}void LFDB::nodeIsOnline(const uint64_t networkId, const uint64_t memberId, const InetAddress& physicalAddress, const char* osArch){	std::lock_guard<std::mutex> l(_state_l);	auto nw = _state.find(networkId);	if (nw != _state.end()) {		auto m = nw->second.members.find(memberId);		if (m != nw->second.members.end()) {			m->second.lastOnlineTime = OSUtils::now();			if (physicalAddress)				m->second.lastOnlineAddress = physicalAddress;			m->second.lastOnlineDirty = true;		}	}}void LFDB::nodeIsOnline(const uint64_t networkId, const uint64_t memberId, const InetAddress& physicalAddress){	this->nodeIsOnline(networkId, memberId, physicalAddress, "unknown/unknown");}}	// namespace ZeroTier
 |