migrate.js 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318
  1. 'use strict';
  2. var sqlite3 = require('sqlite3').verbose();
  3. var fs = require('fs');
  4. var async = require('async');
  5. function blobToIPv4(b)
  6. {
  7. if (!b)
  8. return null;
  9. if (b.length !== 16)
  10. return null;
  11. return b.readUInt8(12).toString()+'.'+b.readUInt8(13).toString()+'.'+b.readUInt8(14).toString()+'.'+b.readUInt8(15).toString();
  12. }
  13. function blobToIPv6(b)
  14. {
  15. if (!b)
  16. return null;
  17. if (b.length !== 16)
  18. return null;
  19. var s = '';
  20. for(var i=0;i<16;++i) {
  21. var x = b.readUInt8(i).toString(16);
  22. if (x.length === 1)
  23. s += '0';
  24. s += x;
  25. if ((((i+1) & 1) === 0)&&(i !== 15))
  26. s += ':';
  27. }
  28. return s;
  29. }
  30. if (process.argv.length !== 4) {
  31. console.log('ZeroTier Old Sqlite3 Controller DB Migration Utility');
  32. console.log('(c)2017 ZeroTier, Inc. [GPL3]');
  33. console.log('');
  34. console.log('Usage: node migrate.js </path/to/controller.db> </path/to/controller.d>');
  35. console.log('');
  36. console.log('The first argument must be the path to the old Sqlite3 controller.db');
  37. console.log('file. The second must be the path to the EMPTY controller.d database');
  38. console.log('directory for a new (1.1.17 or newer) controller. If this path does');
  39. console.log('not exist it will be created.');
  40. console.log('');
  41. console.log('WARNING: this will ONLY work correctly on a 1.1.14 controller database.');
  42. console.log('If your controller is old you should first upgrade to 1.1.14 and run the');
  43. console.log('controller so that it will brings its Sqlite3 database up to the latest');
  44. console.log('version before running this migration.');
  45. console.log('');
  46. process.exit(1);
  47. }
  48. var oldDbPath = process.argv[2];
  49. var newDbPath = process.argv[3];
  50. console.log('Starting migrate of "'+oldDbPath+'" to "'+newDbPath+'"...');
  51. console.log('');
  52. var old = new sqlite3.Database(oldDbPath);
  53. var networks = {};
  54. var nodeIdentities = {};
  55. var networkCount = 0;
  56. var memberCount = 0;
  57. var routeCount = 0;
  58. var ipAssignmentPoolCount = 0;
  59. var ipAssignmentCount = 0;
  60. var ruleCount = 0;
  61. var oldSchemaVersion = -1;
  62. async.series([function(nextStep) {
  63. old.each('SELECT v from Config WHERE k = \'schemaVersion\'',function(err,row) {
  64. oldSchemaVersion = parseInt(row.v)||-1;
  65. },nextStep);
  66. },function(nextStep) {
  67. if (oldSchemaVersion !== 4) {
  68. console.log('FATAL: this MUST be run on a 1.1.14 controller.db! Upgrade your old');
  69. console.log('controller to 1.1.14 first and run it once to bring its DB up to date.');
  70. return process.exit(1);
  71. }
  72. console.log('Reading networks...');
  73. old.each('SELECT * FROM Network',function(err,row) {
  74. if ((typeof row.id === 'string')&&(row.id.length === 16)) {
  75. var flags = parseInt(row.flags)||0;
  76. networks[row.id] = {
  77. id: row.id,
  78. nwid: row.id,
  79. objtype: 'network',
  80. authTokens: [],
  81. capabilities: [],
  82. creationTime: parseInt(row.creationTime)||0,
  83. enableBroadcast: !!row.enableBroadcast,
  84. ipAssignmentPools: [],
  85. multicastLimit: row.multicastLimit||32,
  86. name: row.name||'',
  87. private: !!row.private,
  88. revision: parseInt(row.revision)||1,
  89. rules: [{ 'type': 'ACTION_ACCEPT' }], // populated later if there are defined rules, otherwise default is allow all
  90. routes: [],
  91. v4AssignMode: {
  92. 'zt': ((flags & 1) !== 0)
  93. },
  94. v6AssignMode: {
  95. '6plane': ((flags & 4) !== 0),
  96. 'rfc4193': ((flags & 2) !== 0),
  97. 'zt': ((flags & 8) !== 0)
  98. },
  99. _members: {} // temporary
  100. };
  101. ++networkCount;
  102. //console.log(networks[row.id]);
  103. }
  104. },nextStep);
  105. },function(nextStep) {
  106. console.log(' '+networkCount+' networks.');
  107. console.log('Reading network route definitions...');
  108. old.each('SELECT * from Route WHERE ipVersion = 4 OR ipVersion = 6',function(err,row) {
  109. var network = networks[row.networkId];
  110. if (network) {
  111. var rt = {
  112. target: (((row.ipVersion == 4) ? blobToIPv4(row.target) : blobToIPv6(row.target))+'/'+row.targetNetmaskBits),
  113. via: ((row.via) ? ((row.ipVersion == 4) ? blobToIPv4(row.via) : blobToIPv6(row.via)) : null)
  114. };
  115. network.routes.push(rt);
  116. ++routeCount;
  117. }
  118. },nextStep);
  119. },function(nextStep) {
  120. console.log(' '+routeCount+' routes in '+networkCount+' networks.');
  121. console.log('Reading IP assignment pools...');
  122. old.each('SELECT * FROM IpAssignmentPool WHERE ipVersion = 4 OR ipVersion = 6',function(err,row) {
  123. var network = networks[row.networkId];
  124. if (network) {
  125. var p = {
  126. ipRangeStart: ((row.ipVersion == 4) ? blobToIPv4(row.ipRangeStart) : blobToIPv6(row.ipRangeStart)),
  127. ipRangeEnd: ((row.ipVersion == 4) ? blobToIPv4(row.ipRangeEnd) : blobToIPv6(row.ipRangeEnd))
  128. };
  129. network.ipAssignmentPools.push(p);
  130. ++ipAssignmentPoolCount;
  131. }
  132. },nextStep);
  133. },function(nextStep) {
  134. console.log(' '+ipAssignmentPoolCount+' IP assignment pools in '+networkCount+' networks.');
  135. console.log('Reading known node identities...');
  136. old.each('SELECT * FROM Node',function(err,row) {
  137. nodeIdentities[row.id] = row.identity;
  138. },nextStep);
  139. },function(nextStep) {
  140. console.log(' '+Object.keys(nodeIdentities).length+' known identities.');
  141. console.log('Reading network members...');
  142. old.each('SELECT * FROM Member',function(err,row) {
  143. var network = networks[row.networkId];
  144. if (network) {
  145. network._members[row.nodeId] = {
  146. id: row.nodeId,
  147. address: row.nodeId,
  148. objtype: 'member',
  149. authorized: !!row.authorized,
  150. activeBridge: !!row.activeBridge,
  151. authHistory: [],
  152. capabilities: [],
  153. creationTime: 0,
  154. identity: nodeIdentities[row.nodeId]||null,
  155. ipAssignments: [],
  156. lastAuthorizedTime: (row.authorized) ? Date.now() : 0,
  157. lastDeauthorizedTime: (row.authorized) ? 0 : Date.now(),
  158. lastRequestMetaData: '',
  159. noAutoAssignIps: false,
  160. nwid: row.networkId,
  161. revision: parseInt(row.memberRevision)||1,
  162. tags: [],
  163. recentLog: []
  164. };
  165. ++memberCount;
  166. //console.log(network._members[row.nodeId]);
  167. }
  168. },nextStep);
  169. },function(nextStep) {
  170. console.log(' '+memberCount+' members of '+networkCount+' networks.');
  171. console.log('Reading static IP assignments...');
  172. old.each('SELECT * FROM IpAssignment WHERE ipVersion = 4 OR ipVersion = 6',function(err,row) {
  173. var network = networks[row.networkId];
  174. if (network) {
  175. var member = network._members[row.nodeId];
  176. if ((member)&&((member.authorized)||(!network['private']))) { // don't mirror assignments to unauthorized members to avoid conflicts
  177. if (row.ipVersion == 4) {
  178. member.ipAssignments.push(blobToIPv4(row.ip));
  179. ++ipAssignmentCount;
  180. } else if (row.ipVersion == 6) {
  181. member.ipAssignments.push(blobToIPv6(row.ip));
  182. ++ipAssignmentCount;
  183. }
  184. }
  185. }
  186. },nextStep);
  187. },function(nextStep) {
  188. // Old versions only supported Ethertype whitelisting, so that's
  189. // all we mirror forward. The other fields were always unused.
  190. console.log(' '+ipAssignmentCount+' IP assignments for '+memberCount+' authorized members of '+networkCount+' networks.');
  191. console.log('Reading allowed Ethernet types (old basic rules)...');
  192. var etherTypesByNetwork = {};
  193. old.each('SELECT DISTINCT networkId,ruleNo,etherType FROM Rule WHERE "action" = \'accept\'',function(err,row) {
  194. if (row.networkId in networks) {
  195. var et = parseInt(row.etherType)||0;
  196. var ets = etherTypesByNetwork[row.networkId];
  197. if (!ets)
  198. etherTypesByNetwork[row.networkId] = [ et ];
  199. else ets.push(et);
  200. }
  201. },function(err) {
  202. if (err) return nextStep(err);
  203. for(var nwid in etherTypesByNetwork) {
  204. var ets = etherTypesByNetwork[nwid].sort();
  205. var network = networks[nwid];
  206. if (network) {
  207. var rules = [];
  208. if (ets.indexOf(0) >= 0) {
  209. // If 0 is in the list, all Ethernet types are allowed so we accept all.
  210. rules.push({ 'type': 'ACTION_ACCEPT' });
  211. } else {
  212. // Otherwise we whitelist.
  213. for(var i=0;i<ets.length;++i) {
  214. rules.push({
  215. 'etherType': ets[i],
  216. 'not': true,
  217. 'or': false,
  218. 'type': 'MATCH_ETHERTYPE'
  219. });
  220. }
  221. rules.push({ 'type': 'ACTION_DROP' });
  222. rules.push({ 'type': 'ACTION_ACCEPT' });
  223. }
  224. network.rules = rules;
  225. ++ruleCount;
  226. }
  227. }
  228. return nextStep(null);
  229. });
  230. }],function(err) {
  231. if (err) {
  232. console.log('FATAL: '+err.toString());
  233. return process.exit(1);
  234. }
  235. console.log(' '+ruleCount+' ethernet type whitelists converted to new format rules.');
  236. old.close();
  237. console.log('Done reading and converting Sqlite3 database! Writing JSONDB files...');
  238. try {
  239. fs.mkdirSync(newDbPath,0o700);
  240. } catch (e) {}
  241. var nwBase = newDbPath+'/network';
  242. try {
  243. fs.mkdirSync(nwBase,0o700);
  244. } catch (e) {}
  245. nwBase = nwBase + '/';
  246. var nwids = Object.keys(networks).sort();
  247. var fileCount = 0;
  248. for(var ni=0;ni<nwids.length;++ni) {
  249. var network = networks[nwids[ni]];
  250. var mids = Object.keys(network._members).sort();
  251. if (mids.length > 0) {
  252. try {
  253. fs.mkdirSync(nwBase+network.id);
  254. } catch (e) {}
  255. var mbase = nwBase+network.id+'/member';
  256. try {
  257. fs.mkdirSync(mbase,0o700);
  258. } catch (e) {}
  259. mbase = mbase + '/';
  260. for(var mi=0;mi<mids.length;++mi) {
  261. var member = network._members[mids[mi]];
  262. fs.writeFileSync(mbase+member.id+'.json',JSON.stringify(member,null,1),{ mode: 0o600 });
  263. ++fileCount;
  264. //console.log(mbase+member.id+'.json');
  265. }
  266. }
  267. delete network._members; // temporary field, not part of actual JSONDB, so don't write
  268. fs.writeFileSync(nwBase+network.id+'.json',JSON.stringify(network,null,1),{ mode: 0o600 });
  269. ++fileCount;
  270. //console.log(nwBase+network.id+'.json');
  271. }
  272. console.log('');
  273. console.log('SUCCESS! Wrote '+fileCount+' JSONDB files.');
  274. console.log('');
  275. console.log('You should still inspect the new DB before going live. Also be sure');
  276. console.log('to "chown -R" and "chgrp -R" the new DB to the user and group under');
  277. console.log('which the ZeroTier One instance acting as controller will be running.');
  278. console.log('The controller must be able to read and write the DB, of course.');
  279. console.log('');
  280. console.log('Have fun!');
  281. return process.exit(0);
  282. });