Node.cpp 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846
  1. /*
  2. * ZeroTier One - Global Peer to Peer Ethernet
  3. * Copyright (C) 2011-2014 ZeroTier Networks LLC
  4. *
  5. * This program is free software: you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License as published by
  7. * the Free Software Foundation, either version 3 of the License, or
  8. * (at your option) any later version.
  9. *
  10. * This program is distributed in the hope that it will be useful,
  11. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  12. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  13. * GNU General Public License for more details.
  14. *
  15. * You should have received a copy of the GNU General Public License
  16. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  17. *
  18. * --
  19. *
  20. * ZeroTier may be used and distributed under the terms of the GPLv3, which
  21. * are available at: http://www.gnu.org/licenses/gpl-3.0.html
  22. *
  23. * If you would like to embed ZeroTier into a commercial application or
  24. * redistribute it in a modified binary form, please contact ZeroTier Networks
  25. * LLC. Start here: http://www.zerotier.com/
  26. */
  27. #include <stdio.h>
  28. #include <stdlib.h>
  29. #include <string.h>
  30. #include <errno.h>
  31. #include <sys/stat.h>
  32. #include <map>
  33. #include <set>
  34. #include <utility>
  35. #include <algorithm>
  36. #include <list>
  37. #include <vector>
  38. #include <string>
  39. #include "Constants.hpp"
  40. #ifdef __WINDOWS__
  41. #include <WinSock2.h>
  42. #include <Windows.h>
  43. #include <ShlObj.h>
  44. #else
  45. #include <fcntl.h>
  46. #include <unistd.h>
  47. #include <signal.h>
  48. #include <sys/file.h>
  49. #endif
  50. #include "../version.h"
  51. #include "Node.hpp"
  52. #include "RuntimeEnvironment.hpp"
  53. #include "Logger.hpp"
  54. #include "Utils.hpp"
  55. #include "Defaults.hpp"
  56. #include "Identity.hpp"
  57. #include "Topology.hpp"
  58. #include "SocketManager.hpp"
  59. #include "Packet.hpp"
  60. #include "Switch.hpp"
  61. #include "EthernetTap.hpp"
  62. #include "CMWC4096.hpp"
  63. #include "NodeConfig.hpp"
  64. #include "Network.hpp"
  65. #include "MulticastGroup.hpp"
  66. #include "Mutex.hpp"
  67. #include "Multicaster.hpp"
  68. #include "Service.hpp"
  69. #include "SoftwareUpdater.hpp"
  70. #include "Buffer.hpp"
  71. #include "IpcConnection.hpp"
  72. #include "AntiRecursion.hpp"
  73. #include "RoutingTable.hpp"
  74. #include "HttpClient.hpp"
  75. namespace ZeroTier {
  76. // ---------------------------------------------------------------------------
  77. struct _NodeControlClientImpl
  78. {
  79. void (*resultHandler)(void *,const char *);
  80. void *arg;
  81. IpcConnection *ipcc;
  82. std::string err;
  83. };
  84. static void _CBipcResultHandler(void *arg,IpcConnection *ipcc,IpcConnection::EventType event,const char *result)
  85. {
  86. if ((event == IpcConnection::IPC_EVENT_COMMAND)&&(result)) {
  87. if (strcmp(result,"200 auth OK"))
  88. ((_NodeControlClientImpl *)arg)->resultHandler(((_NodeControlClientImpl *)arg)->arg,result);
  89. }
  90. }
  91. Node::NodeControlClient::NodeControlClient(const char *hp,void (*resultHandler)(void *,const char *),void *arg,const char *authToken)
  92. throw() :
  93. _impl((void *)new _NodeControlClientImpl)
  94. {
  95. _NodeControlClientImpl *impl = (_NodeControlClientImpl *)_impl;
  96. impl->ipcc = (IpcConnection *)0;
  97. if (!hp)
  98. hp = ZT_DEFAULTS.defaultHomePath.c_str();
  99. std::string at;
  100. if (authToken)
  101. at = authToken;
  102. else if (!Utils::readFile(authTokenDefaultSystemPath(),at)) {
  103. if (!Utils::readFile(authTokenDefaultUserPath(),at)) {
  104. impl->err = "no authentication token specified and authtoken.secret not readable";
  105. return;
  106. }
  107. }
  108. std::string myid;
  109. if (Utils::readFile((std::string(hp) + ZT_PATH_SEPARATOR_S + "identity.public").c_str(),myid)) {
  110. std::string myaddr(myid.substr(0,myid.find(':')));
  111. if (myaddr.length() != 10)
  112. impl->err = "invalid address extracted from identity.public";
  113. else {
  114. try {
  115. impl->resultHandler = resultHandler;
  116. impl->arg = arg;
  117. impl->ipcc = new IpcConnection((std::string(ZT_IPC_ENDPOINT_BASE) + myaddr).c_str(),&_CBipcResultHandler,_impl);
  118. impl->ipcc->printf("auth %s"ZT_EOL_S,at.c_str());
  119. } catch ( ... ) {
  120. impl->ipcc = (IpcConnection *)0;
  121. impl->err = "failure connecting to running ZeroTier One service";
  122. }
  123. }
  124. } else impl->err = "unable to read identity.public";
  125. }
  126. Node::NodeControlClient::~NodeControlClient()
  127. {
  128. if (_impl) {
  129. delete ((_NodeControlClientImpl *)_impl)->ipcc;
  130. delete (_NodeControlClientImpl *)_impl;
  131. }
  132. }
  133. const char *Node::NodeControlClient::error() const
  134. throw()
  135. {
  136. if (((_NodeControlClientImpl *)_impl)->err.length())
  137. return ((_NodeControlClientImpl *)_impl)->err.c_str();
  138. return (const char *)0;
  139. }
  140. void Node::NodeControlClient::send(const char *command)
  141. throw()
  142. {
  143. try {
  144. if (((_NodeControlClientImpl *)_impl)->ipcc)
  145. ((_NodeControlClientImpl *)_impl)->ipcc->printf("%s"ZT_EOL_S,command);
  146. } catch ( ... ) {}
  147. }
  148. std::vector<std::string> Node::NodeControlClient::splitLine(const char *line)
  149. {
  150. return Utils::split(line," ","\\","\"");
  151. }
  152. const char *Node::NodeControlClient::authTokenDefaultUserPath()
  153. {
  154. static std::string dlp;
  155. static Mutex dlp_m;
  156. Mutex::Lock _l(dlp_m);
  157. #ifdef __WINDOWS__
  158. if (!dlp.length()) {
  159. char buf[16384];
  160. if (SUCCEEDED(SHGetFolderPathA(NULL,CSIDL_APPDATA,NULL,0,buf)))
  161. dlp = (std::string(buf) + "\\ZeroTier\\One\\authtoken.secret");
  162. }
  163. #else // not __WINDOWS__
  164. if (!dlp.length()) {
  165. const char *home = getenv("HOME");
  166. if (home) {
  167. #ifdef __APPLE__
  168. dlp = (std::string(home) + "/Library/Application Support/ZeroTier/One/authtoken.secret");
  169. #else
  170. dlp = (std::string(home) + "/.zeroTierOneAuthToken");
  171. #endif
  172. }
  173. }
  174. #endif // __WINDOWS__ or not __WINDOWS__
  175. return dlp.c_str();
  176. }
  177. const char *Node::NodeControlClient::authTokenDefaultSystemPath()
  178. {
  179. static std::string dsp;
  180. static Mutex dsp_m;
  181. Mutex::Lock _l(dsp_m);
  182. if (!dsp.length())
  183. dsp = (ZT_DEFAULTS.defaultHomePath + ZT_PATH_SEPARATOR_S"authtoken.secret");
  184. return dsp.c_str();
  185. }
  186. // ---------------------------------------------------------------------------
  187. struct _NodeImpl
  188. {
  189. RuntimeEnvironment renv;
  190. unsigned int udpPort,tcpPort;
  191. std::string reasonForTerminationStr;
  192. volatile Node::ReasonForTermination reasonForTermination;
  193. volatile bool started;
  194. volatile bool running;
  195. volatile bool resynchronize;
  196. volatile bool disableRootTopologyUpdates;
  197. // This function performs final node tear-down
  198. inline Node::ReasonForTermination terminate()
  199. {
  200. RuntimeEnvironment *_r = &renv;
  201. LOG("terminating: %s",reasonForTerminationStr.c_str());
  202. renv.shutdownInProgress = true;
  203. Thread::sleep(500);
  204. running = false;
  205. #ifndef __WINDOWS__
  206. delete renv.netconfService;
  207. #endif
  208. delete renv.updater; renv.updater = (SoftwareUpdater *)0;
  209. delete renv.nc; renv.nc = (NodeConfig *)0; // shut down all networks, close taps, etc.
  210. delete renv.topology; renv.topology = (Topology *)0; // now we no longer need routing info
  211. delete renv.sm; renv.sm = (SocketManager *)0; // close all sockets
  212. delete renv.sw; renv.sw = (Switch *)0; // order matters less from here down
  213. delete renv.mc; renv.mc = (Multicaster *)0;
  214. delete renv.antiRec; renv.antiRec = (AntiRecursion *)0;
  215. delete renv.http; renv.http = (HttpClient *)0;
  216. delete renv.prng; renv.prng = (CMWC4096 *)0;
  217. delete renv.log; renv.log = (Logger *)0; // but stop logging last of all
  218. return reasonForTermination;
  219. }
  220. inline Node::ReasonForTermination terminateBecause(Node::ReasonForTermination r,const char *rstr)
  221. {
  222. reasonForTerminationStr = rstr;
  223. reasonForTermination = r;
  224. return terminate();
  225. }
  226. };
  227. #ifndef __WINDOWS__ // "services" are not supported on Windows
  228. static void _netconfServiceMessageHandler(void *renv,Service &svc,const Dictionary &msg)
  229. {
  230. if (!renv)
  231. return; // sanity check
  232. const RuntimeEnvironment *_r = (const RuntimeEnvironment *)renv;
  233. try {
  234. //TRACE("from netconf:\n%s",msg.toString().c_str());
  235. const std::string &type = msg.get("type");
  236. if (type == "ready") {
  237. LOG("received 'ready' from netconf.service, sending netconf-init with identity information...");
  238. Dictionary initMessage;
  239. initMessage["type"] = "netconf-init";
  240. initMessage["netconfId"] = _r->identity.toString(true);
  241. _r->netconfService->send(initMessage);
  242. } else if (type == "netconf-response") {
  243. uint64_t inRePacketId = strtoull(msg.get("requestId").c_str(),(char **)0,16);
  244. uint64_t nwid = strtoull(msg.get("nwid").c_str(),(char **)0,16);
  245. Address peerAddress(msg.get("peer").c_str());
  246. if (peerAddress) {
  247. if (msg.contains("error")) {
  248. Packet::ErrorCode errCode = Packet::ERROR_INVALID_REQUEST;
  249. const std::string &err = msg.get("error");
  250. if (err == "OBJ_NOT_FOUND")
  251. errCode = Packet::ERROR_OBJ_NOT_FOUND;
  252. else if (err == "ACCESS_DENIED")
  253. errCode = Packet::ERROR_NETWORK_ACCESS_DENIED_;
  254. Packet outp(peerAddress,_r->identity.address(),Packet::VERB_ERROR);
  255. outp.append((unsigned char)Packet::VERB_NETWORK_CONFIG_REQUEST);
  256. outp.append(inRePacketId);
  257. outp.append((unsigned char)errCode);
  258. outp.append(nwid);
  259. _r->sw->send(outp,true);
  260. } else if (msg.contains("netconf")) {
  261. const std::string &netconf = msg.get("netconf");
  262. if (netconf.length() < 2048) { // sanity check
  263. Packet outp(peerAddress,_r->identity.address(),Packet::VERB_OK);
  264. outp.append((unsigned char)Packet::VERB_NETWORK_CONFIG_REQUEST);
  265. outp.append(inRePacketId);
  266. outp.append(nwid);
  267. outp.append((uint16_t)netconf.length());
  268. outp.append(netconf.data(),netconf.length());
  269. outp.compress();
  270. _r->sw->send(outp,true);
  271. }
  272. }
  273. }
  274. } else if (type == "netconf-push") {
  275. if (msg.contains("to")) {
  276. Dictionary to(msg.get("to")); // key: peer address, value: comma-delimited network list
  277. for(Dictionary::iterator t(to.begin());t!=to.end();++t) {
  278. Address ztaddr(t->first);
  279. if (ztaddr) {
  280. Packet outp(ztaddr,_r->identity.address(),Packet::VERB_NETWORK_CONFIG_REFRESH);
  281. char *saveptr = (char *)0;
  282. // Note: this loop trashes t->second, which is quasi-legal C++ but
  283. // shouldn't break anything as long as we don't try to use 'to'
  284. // for anything interesting after doing this.
  285. for(char *p=Utils::stok(const_cast<char *>(t->second.c_str()),",",&saveptr);(p);p=Utils::stok((char *)0,",",&saveptr)) {
  286. uint64_t nwid = Utils::hexStrToU64(p);
  287. if (nwid) {
  288. if ((outp.size() + sizeof(uint64_t)) >= ZT_UDP_DEFAULT_PAYLOAD_MTU) {
  289. _r->sw->send(outp,true);
  290. outp.reset(ztaddr,_r->identity.address(),Packet::VERB_NETWORK_CONFIG_REFRESH);
  291. }
  292. outp.append(nwid);
  293. }
  294. }
  295. if (outp.payloadLength())
  296. _r->sw->send(outp,true);
  297. }
  298. }
  299. }
  300. }
  301. } catch (std::exception &exc) {
  302. LOG("unexpected exception parsing response from netconf service: %s",exc.what());
  303. } catch ( ... ) {
  304. LOG("unexpected exception parsing response from netconf service: unknown exception");
  305. }
  306. }
  307. #endif // !__WINDOWS__
  308. Node::Node(
  309. const char *hp,
  310. EthernetTapFactory *tf,
  311. RoutingTable *rt,
  312. unsigned int udpPort,
  313. unsigned int tcpPort,
  314. bool resetIdentity)
  315. throw() :
  316. _impl(new _NodeImpl)
  317. {
  318. _NodeImpl *impl = (_NodeImpl *)_impl;
  319. if ((hp)&&(hp[0]))
  320. impl->renv.homePath = hp;
  321. else impl->renv.homePath = ZT_DEFAULTS.defaultHomePath;
  322. impl->renv.tapFactory = tf;
  323. impl->renv.routingTable = rt;
  324. if (resetIdentity) {
  325. // Forget identity and peer database, peer keys, etc.
  326. Utils::rm((impl->renv.homePath + ZT_PATH_SEPARATOR_S + "identity.public").c_str());
  327. Utils::rm((impl->renv.homePath + ZT_PATH_SEPARATOR_S + "identity.secret").c_str());
  328. Utils::rm((impl->renv.homePath + ZT_PATH_SEPARATOR_S + "peers.persist").c_str());
  329. // Truncate network config information in networks.d but leave the files since we
  330. // still want to remember any networks we have joined. This will force those networks
  331. // to be reconfigured with our newly regenerated identity after startup.
  332. std::string networksDotD(impl->renv.homePath + ZT_PATH_SEPARATOR_S + "networks.d");
  333. std::map< std::string,bool > nwfiles(Utils::listDirectory(networksDotD.c_str()));
  334. for(std::map<std::string,bool>::iterator nwf(nwfiles.begin());nwf!=nwfiles.end();++nwf) {
  335. FILE *trun = fopen((networksDotD + ZT_PATH_SEPARATOR_S + nwf->first).c_str(),"w");
  336. if (trun)
  337. fclose(trun);
  338. }
  339. }
  340. impl->udpPort = udpPort & 0xffff;
  341. impl->tcpPort = tcpPort & 0xffff;
  342. impl->reasonForTermination = Node::NODE_RUNNING;
  343. impl->started = false;
  344. impl->running = false;
  345. impl->resynchronize = false;
  346. impl->disableRootTopologyUpdates = false;
  347. }
  348. Node::~Node()
  349. {
  350. delete (_NodeImpl *)_impl;
  351. }
  352. static void _CBztTraffic(const SharedPtr<Socket> &fromSock,void *arg,const InetAddress &from,Buffer<ZT_SOCKET_MAX_MESSAGE_LEN> &data)
  353. {
  354. const RuntimeEnvironment *_r = (const RuntimeEnvironment *)arg;
  355. if ((_r->sw)&&(!_r->shutdownInProgress))
  356. _r->sw->onRemotePacket(fromSock,from,data);
  357. }
  358. static void _cbHandleGetRootTopology(void *arg,int code,const std::string &url,const std::string &body)
  359. {
  360. RuntimeEnvironment *_r = (RuntimeEnvironment *)arg;
  361. if (_r->shutdownInProgress)
  362. return;
  363. if ((code != 200)||(body.length() == 0)) {
  364. TRACE("failed to retrieve %s",url.c_str());
  365. return;
  366. }
  367. try {
  368. Dictionary rt(body);
  369. if (!Topology::authenticateRootTopology(rt)) {
  370. LOG("discarded invalid root topology update from %s (signature check failed)",url.c_str());
  371. return;
  372. }
  373. {
  374. std::string rootTopologyPath(_r->homePath + ZT_PATH_SEPARATOR_S + "root-topology");
  375. std::string rootTopology;
  376. if (Utils::readFile(rootTopologyPath.c_str(),rootTopology)) {
  377. Dictionary alreadyHave(rootTopology);
  378. if (alreadyHave == rt) {
  379. TRACE("retrieved root topology from %s but no change (same as on disk)",url.c_str());
  380. return;
  381. } else if (alreadyHave.signatureTimestamp() > rt.signatureTimestamp()) {
  382. TRACE("retrieved root topology from %s but no change (ours is newer)",url.c_str());
  383. return;
  384. }
  385. }
  386. Utils::writeFile(rootTopologyPath.c_str(),body);
  387. }
  388. _r->topology->setSupernodes(Dictionary(rt.get("supernodes")));
  389. } catch ( ... ) {
  390. LOG("discarded invalid root topology update from %s (format invalid)",url.c_str());
  391. return;
  392. }
  393. }
  394. Node::ReasonForTermination Node::run()
  395. throw()
  396. {
  397. _NodeImpl *impl = (_NodeImpl *)_impl;
  398. RuntimeEnvironment *_r = (RuntimeEnvironment *)&(impl->renv);
  399. impl->started = true;
  400. impl->running = true;
  401. try {
  402. #ifdef ZT_LOG_STDOUT
  403. _r->log = new Logger((const char *)0,(const char *)0,0);
  404. #else
  405. _r->log = new Logger((_r->homePath + ZT_PATH_SEPARATOR_S + "node.log").c_str(),(const char *)0,131072);
  406. #endif
  407. LOG("starting version %s",versionString());
  408. // Create non-crypto PRNG right away in case other code in init wants to use it
  409. _r->prng = new CMWC4096();
  410. // Read identity public and secret, generating if not present
  411. bool gotId = false;
  412. std::string identitySecretPath(_r->homePath + ZT_PATH_SEPARATOR_S + "identity.secret");
  413. std::string identityPublicPath(_r->homePath + ZT_PATH_SEPARATOR_S + "identity.public");
  414. std::string idser;
  415. if (Utils::readFile(identitySecretPath.c_str(),idser))
  416. gotId = _r->identity.fromString(idser);
  417. if ((gotId)&&(!_r->identity.locallyValidate()))
  418. gotId = false;
  419. if (gotId) {
  420. // Make sure identity.public matches identity.secret
  421. idser = std::string();
  422. Utils::readFile(identityPublicPath.c_str(),idser);
  423. std::string pubid(_r->identity.toString(false));
  424. if (idser != pubid) {
  425. if (!Utils::writeFile(identityPublicPath.c_str(),pubid))
  426. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"could not write identity.public (home path not writable?)");
  427. }
  428. } else {
  429. LOG("no identity found or identity invalid, generating one... this might take a few seconds...");
  430. _r->identity.generate();
  431. LOG("generated new identity: %s",_r->identity.address().toString().c_str());
  432. idser = _r->identity.toString(true);
  433. if (!Utils::writeFile(identitySecretPath.c_str(),idser))
  434. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"could not write identity.secret (home path not writable?)");
  435. idser = _r->identity.toString(false);
  436. if (!Utils::writeFile(identityPublicPath.c_str(),idser))
  437. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"could not write identity.public (home path not writable?)");
  438. }
  439. Utils::lockDownFile(identitySecretPath.c_str(),false);
  440. // Make sure networks.d exists
  441. {
  442. std::string networksDotD(_r->homePath + ZT_PATH_SEPARATOR_S + "networks.d");
  443. #ifdef __WINDOWS__
  444. CreateDirectoryA(networksDotD.c_str(),NULL);
  445. #else
  446. mkdir(networksDotD.c_str(),0700);
  447. #endif
  448. }
  449. // Read configuration authentication token, generating if not present
  450. std::string configAuthTokenPath(_r->homePath + ZT_PATH_SEPARATOR_S + "authtoken.secret");
  451. std::string configAuthToken;
  452. if (!Utils::readFile(configAuthTokenPath.c_str(),configAuthToken)) {
  453. configAuthToken = "";
  454. unsigned int sr = 0;
  455. for(unsigned int i=0;i<24;++i) {
  456. Utils::getSecureRandom(&sr,sizeof(sr));
  457. configAuthToken.push_back("abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789"[sr % 62]);
  458. }
  459. if (!Utils::writeFile(configAuthTokenPath.c_str(),configAuthToken))
  460. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"could not write authtoken.secret (home path not writable?)");
  461. }
  462. Utils::lockDownFile(configAuthTokenPath.c_str(),false);
  463. _r->http = new HttpClient();
  464. _r->antiRec = new AntiRecursion();
  465. _r->mc = new Multicaster();
  466. _r->sw = new Switch(_r);
  467. _r->sm = new SocketManager(impl->udpPort,impl->tcpPort,&_CBztTraffic,_r);
  468. _r->topology = new Topology(_r,Utils::fileExists((_r->homePath + ZT_PATH_SEPARATOR_S + "iddb.d").c_str()));
  469. try {
  470. _r->nc = new NodeConfig(_r,configAuthToken.c_str());
  471. } catch (std::exception &exc) {
  472. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"unable to initialize IPC socket: is ZeroTier One already running?");
  473. }
  474. _r->node = this;
  475. #ifdef ZT_AUTO_UPDATE
  476. if (ZT_DEFAULTS.updateLatestNfoURL.length()) {
  477. _r->updater = new SoftwareUpdater(_r);
  478. _r->updater->cleanOldUpdates(); // clean out updates.d on startup
  479. } else {
  480. LOG("WARNING: unable to enable software updates: latest .nfo URL from ZT_DEFAULTS is empty (does this platform actually support software updates?)");
  481. }
  482. #endif
  483. // Initialize root topology from defaults or root-toplogy file in home path on disk
  484. std::string rootTopologyPath(_r->homePath + ZT_PATH_SEPARATOR_S + "root-topology");
  485. std::string rootTopology;
  486. if (!Utils::readFile(rootTopologyPath.c_str(),rootTopology))
  487. rootTopology = ZT_DEFAULTS.defaultRootTopology;
  488. try {
  489. Dictionary rt(rootTopology);
  490. if (Topology::authenticateRootTopology(rt)) {
  491. // Set supernodes if root topology signature is valid
  492. _r->topology->setSupernodes(Dictionary(rt.get("supernodes",""))); // set supernodes from root-topology
  493. // If root-topology contains noupdate=1, disable further updates and only use what was on disk
  494. impl->disableRootTopologyUpdates = (Utils::strToInt(rt.get("noupdate","0").c_str()) > 0);
  495. } else {
  496. // Revert to built-in defaults if root topology fails signature check
  497. LOG("%s failed signature check, using built-in defaults instead",rootTopologyPath.c_str());
  498. Utils::rm(rootTopologyPath.c_str());
  499. _r->topology->setSupernodes(Dictionary(Dictionary(ZT_DEFAULTS.defaultRootTopology).get("supernodes","")));
  500. impl->disableRootTopologyUpdates = false;
  501. }
  502. } catch ( ... ) {
  503. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"invalid root-topology format");
  504. }
  505. } catch (std::bad_alloc &exc) {
  506. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"memory allocation failure");
  507. } catch (std::runtime_error &exc) {
  508. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,exc.what());
  509. } catch ( ... ) {
  510. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"unknown exception during initialization");
  511. }
  512. // Start external service subprocesses, which is only used by special nodes
  513. // right now and isn't available on Windows.
  514. #ifndef __WINDOWS__
  515. try {
  516. std::string netconfServicePath(_r->homePath + ZT_PATH_SEPARATOR_S + "services.d" + ZT_PATH_SEPARATOR_S + "netconf.service");
  517. if (Utils::fileExists(netconfServicePath.c_str())) {
  518. LOG("netconf.d/netconf.service appears to exist, starting...");
  519. _r->netconfService = new Service(_r,"netconf",netconfServicePath.c_str(),&_netconfServiceMessageHandler,_r);
  520. Dictionary initMessage;
  521. initMessage["type"] = "netconf-init";
  522. initMessage["netconfId"] = _r->identity.toString(true);
  523. _r->netconfService->send(initMessage);
  524. }
  525. } catch ( ... ) {
  526. LOG("unexpected exception attempting to start services");
  527. }
  528. #endif
  529. // Core I/O loop
  530. try {
  531. /* Shut down if this file exists but fails to open. This is used on Mac to
  532. * shut down automatically on .app deletion by symlinking this to the
  533. * Info.plist file inside the ZeroTier One application. This causes the
  534. * service to die when the user throws away the app, allowing uninstallation
  535. * in the natural Mac way. */
  536. std::string shutdownIfUnreadablePath(_r->homePath + ZT_PATH_SEPARATOR_S + "shutdownIfUnreadable");
  537. uint64_t lastNetworkAutoconfCheck = Utils::now() - 5000ULL; // check autoconf again after 5s for startup
  538. uint64_t lastPingCheck = 0;
  539. uint64_t lastClean = Utils::now(); // don't need to do this immediately
  540. uint64_t lastNetworkFingerprintCheck = 0;
  541. uint64_t lastMulticastCheck = 0;
  542. uint64_t lastSupernodePingCheck = 0;
  543. uint64_t lastBeacon = 0;
  544. uint64_t lastRootTopologyFetch = 0;
  545. long lastDelayDelta = 0;
  546. uint64_t networkConfigurationFingerprint = 0;
  547. _r->timeOfLastResynchronize = Utils::now();
  548. while (impl->reasonForTermination == NODE_RUNNING) {
  549. /* This is how the service automatically shuts down when the OSX .app is
  550. * thrown in the trash. It's not used on any other platform for now but
  551. * could do similar things. It's disabled on Windows since it doesn't really
  552. * work there. */
  553. #ifdef __UNIX_LIKE__
  554. if (Utils::fileExists(shutdownIfUnreadablePath.c_str(),false)) {
  555. FILE *tmpf = fopen(shutdownIfUnreadablePath.c_str(),"r");
  556. if (!tmpf)
  557. return impl->terminateBecause(Node::NODE_NORMAL_TERMINATION,"shutdownIfUnreadable exists but is not readable");
  558. fclose(tmpf);
  559. }
  560. #endif
  561. uint64_t now = Utils::now();
  562. bool resynchronize = false;
  563. // If it looks like the computer slept and woke, resynchronize.
  564. if (lastDelayDelta >= ZT_SLEEP_WAKE_DETECTION_THRESHOLD) {
  565. resynchronize = true;
  566. LOG("probable suspend/resume detected, pausing a moment for things to settle...");
  567. Thread::sleep(ZT_SLEEP_WAKE_SETTLE_TIME);
  568. }
  569. // If our network environment looks like it changed, resynchronize.
  570. if ((resynchronize)||((now - lastNetworkFingerprintCheck) >= ZT_NETWORK_FINGERPRINT_CHECK_DELAY)) {
  571. lastNetworkFingerprintCheck = now;
  572. uint64_t fp = _r->routingTable->networkEnvironmentFingerprint(_r->nc->networkTapDeviceNames());
  573. if (fp != networkConfigurationFingerprint) {
  574. LOG("netconf fingerprint change: %.16llx != %.16llx, resyncing with network",networkConfigurationFingerprint,fp);
  575. networkConfigurationFingerprint = fp;
  576. resynchronize = true;
  577. }
  578. }
  579. // Supernodes do not resynchronize unless explicitly ordered via SIGHUP.
  580. if ((resynchronize)&&(_r->topology->amSupernode()))
  581. resynchronize = false;
  582. // Check for SIGHUP / force resync.
  583. if (impl->resynchronize) {
  584. impl->resynchronize = false;
  585. resynchronize = true;
  586. LOG("resynchronize forced by user, syncing with network");
  587. }
  588. if (resynchronize) {
  589. _r->tcpTunnelingEnabled = false; // turn off TCP tunneling master switch at first, will be reenabled on persistent UDP failure
  590. _r->timeOfLastResynchronize = now;
  591. }
  592. /* Supernodes are pinged separately and more aggressively. The
  593. * ZT_STARTUP_AGGRO parameter sets a limit on how rapidly they are
  594. * tried, while PingSupernodesThatNeedPing contains the logic for
  595. * determining if they need PING. */
  596. if ((now - lastSupernodePingCheck) >= ZT_STARTUP_AGGRO) {
  597. lastSupernodePingCheck = now;
  598. uint64_t lastReceiveFromAnySupernode = 0; // function object result paramter
  599. _r->topology->eachSupernodePeer(Topology::FindMostRecentDirectReceiveTimestamp(lastReceiveFromAnySupernode));
  600. // Turn on TCP tunneling master switch if we haven't heard anything since before
  601. // the last resynchronize and we've been trying long enough.
  602. uint64_t tlr = _r->timeOfLastResynchronize;
  603. if ((lastReceiveFromAnySupernode < tlr)&&((now - tlr) >= ZT_TCP_TUNNEL_FAILOVER_TIMEOUT)) {
  604. TRACE("network still unreachable after %u ms, TCP TUNNELING ENABLED",(unsigned int)ZT_TCP_TUNNEL_FAILOVER_TIMEOUT);
  605. _r->tcpTunnelingEnabled = true;
  606. }
  607. _r->topology->eachSupernodePeer(Topology::PingSupernodesThatNeedPing(_r,now));
  608. }
  609. if (resynchronize) {
  610. /* Send NOP to all peers on resynchronize, directly to supernodes and
  611. * indirectly to regular nodes (to trigger RENDEZVOUS). Also clear
  612. * learned paths since they're likely no longer valid, and close
  613. * TCP sockets since they're also likely invalid. */
  614. _r->sm->closeTcpSockets();
  615. _r->topology->eachPeer(Topology::ResetActivePeers(_r,now));
  616. } else {
  617. /* Periodically check for changes in our local multicast subscriptions
  618. * and broadcast those changes to directly connected peers. */
  619. if ((now - lastMulticastCheck) >= ZT_MULTICAST_LOCAL_POLL_PERIOD) {
  620. lastMulticastCheck = now;
  621. try {
  622. std::map< SharedPtr<Network>,std::set<MulticastGroup> > toAnnounce;
  623. std::vector< SharedPtr<Network> > networks(_r->nc->networks());
  624. for(std::vector< SharedPtr<Network> >::const_iterator nw(networks.begin());nw!=networks.end();++nw) {
  625. if ((*nw)->updateMulticastGroups())
  626. toAnnounce.insert(std::pair< SharedPtr<Network>,std::set<MulticastGroup> >(*nw,(*nw)->multicastGroups()));
  627. }
  628. if (toAnnounce.size())
  629. _r->sw->announceMulticastGroups(toAnnounce);
  630. } catch (std::exception &exc) {
  631. LOG("unexpected exception announcing multicast groups: %s",exc.what());
  632. } catch ( ... ) {
  633. LOG("unexpected exception announcing multicast groups: (unknown)");
  634. }
  635. }
  636. /* Periodically ping all our non-stale direct peers unless we're a supernode.
  637. * Supernodes only ping each other (which is done above). */
  638. if ((!_r->topology->amSupernode())&&((now - lastPingCheck) >= ZT_PING_CHECK_DELAY)) {
  639. lastPingCheck = now;
  640. try {
  641. _r->topology->eachPeer(Topology::PingPeersThatNeedPing(_r,now));
  642. #ifdef ZT_FIREWALL_OPENER_DELAY
  643. _r->topology->eachPeer(Topology::OpenPeersThatNeedFirewallOpener(_r,now));
  644. #endif
  645. } catch (std::exception &exc) {
  646. LOG("unexpected exception running ping check cycle: %s",exc.what());
  647. } catch ( ... ) {
  648. LOG("unexpected exception running ping check cycle: (unkonwn)");
  649. }
  650. }
  651. }
  652. // Update network configurations when needed.
  653. if ((resynchronize)||((now - lastNetworkAutoconfCheck) >= ZT_NETWORK_AUTOCONF_CHECK_DELAY)) {
  654. lastNetworkAutoconfCheck = now;
  655. std::vector< SharedPtr<Network> > nets(_r->nc->networks());
  656. for(std::vector< SharedPtr<Network> >::iterator n(nets.begin());n!=nets.end();++n) {
  657. if ((now - (*n)->lastConfigUpdate()) >= ZT_NETWORK_AUTOCONF_DELAY)
  658. (*n)->requestConfiguration();
  659. }
  660. }
  661. // Do periodic tasks in submodules.
  662. if ((now - lastClean) >= ZT_DB_CLEAN_PERIOD) {
  663. lastClean = now;
  664. _r->mc->clean();
  665. _r->topology->clean();
  666. _r->nc->clean();
  667. if (_r->updater)
  668. _r->updater->checkIfMaxIntervalExceeded(now);
  669. }
  670. // Send beacons to physical local LANs
  671. if ((resynchronize)||((now - lastBeacon) >= ZT_BEACON_INTERVAL)) {
  672. lastBeacon = now;
  673. char bcn[ZT_PROTO_BEACON_LENGTH];
  674. void *bcnptr = bcn;
  675. *((uint32_t *)(bcnptr)) = _r->prng->next32();
  676. bcnptr = bcn + 4;
  677. *((uint32_t *)(bcnptr)) = _r->prng->next32();
  678. _r->identity.address().copyTo(bcn + ZT_PROTO_BEACON_IDX_ADDRESS,ZT_ADDRESS_LENGTH);
  679. TRACE("sending LAN beacon to %s",ZT_DEFAULTS.v4Broadcast.toString().c_str());
  680. _r->antiRec->logOutgoingZT(bcn,ZT_PROTO_BEACON_LENGTH);
  681. _r->sm->send(ZT_DEFAULTS.v4Broadcast,false,false,bcn,ZT_PROTO_BEACON_LENGTH);
  682. }
  683. // Check for updates to root topology (supernodes) periodically
  684. if ((now - lastRootTopologyFetch) >= ZT_UPDATE_ROOT_TOPOLOGY_CHECK_INTERVAL) {
  685. lastRootTopologyFetch = now;
  686. if (!impl->disableRootTopologyUpdates) {
  687. TRACE("fetching root topology from %s",ZT_DEFAULTS.rootTopologyUpdateURL.c_str());
  688. _r->http->GET(ZT_DEFAULTS.rootTopologyUpdateURL,HttpClient::NO_HEADERS,60,&_cbHandleGetRootTopology,_r);
  689. }
  690. }
  691. // Sleep for loop interval or until something interesting happens.
  692. try {
  693. unsigned long delay = std::min((unsigned long)ZT_MAX_SERVICE_LOOP_INTERVAL,_r->sw->doTimerTasks());
  694. uint64_t start = Utils::now();
  695. _r->sm->poll(delay);
  696. lastDelayDelta = (long)(Utils::now() - start) - (long)delay; // used to detect sleep/wake
  697. } catch (std::exception &exc) {
  698. LOG("unexpected exception running Switch doTimerTasks: %s",exc.what());
  699. } catch ( ... ) {
  700. LOG("unexpected exception running Switch doTimerTasks: (unknown)");
  701. }
  702. }
  703. } catch ( ... ) {
  704. LOG("FATAL: unexpected exception in core loop: unknown exception");
  705. return impl->terminateBecause(Node::NODE_UNRECOVERABLE_ERROR,"unexpected exception during outer main I/O loop");
  706. }
  707. return impl->terminate();
  708. }
  709. const char *Node::reasonForTermination() const
  710. throw()
  711. {
  712. if ((!((_NodeImpl *)_impl)->started)||(((_NodeImpl *)_impl)->running))
  713. return (const char *)0;
  714. return ((_NodeImpl *)_impl)->reasonForTerminationStr.c_str();
  715. }
  716. void Node::terminate(ReasonForTermination reason,const char *reasonText)
  717. throw()
  718. {
  719. ((_NodeImpl *)_impl)->reasonForTermination = reason;
  720. ((_NodeImpl *)_impl)->reasonForTerminationStr = ((reasonText) ? reasonText : "");
  721. ((_NodeImpl *)_impl)->renv.sm->whack();
  722. }
  723. void Node::resync()
  724. throw()
  725. {
  726. ((_NodeImpl *)_impl)->resynchronize = true;
  727. ((_NodeImpl *)_impl)->renv.sm->whack();
  728. }
  729. class _VersionStringMaker
  730. {
  731. public:
  732. char vs[32];
  733. _VersionStringMaker()
  734. {
  735. Utils::snprintf(vs,sizeof(vs),"%d.%d.%d",(int)ZEROTIER_ONE_VERSION_MAJOR,(int)ZEROTIER_ONE_VERSION_MINOR,(int)ZEROTIER_ONE_VERSION_REVISION);
  736. }
  737. ~_VersionStringMaker() {}
  738. };
  739. static const _VersionStringMaker __versionString;
  740. const char *Node::versionString() throw() { return __versionString.vs; }
  741. unsigned int Node::versionMajor() throw() { return ZEROTIER_ONE_VERSION_MAJOR; }
  742. unsigned int Node::versionMinor() throw() { return ZEROTIER_ONE_VERSION_MINOR; }
  743. unsigned int Node::versionRevision() throw() { return ZEROTIER_ONE_VERSION_REVISION; }
  744. } // namespace ZeroTier