common.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420
  1. package functions
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "log"
  9. "net"
  10. "net/http"
  11. "os"
  12. "strconv"
  13. "strings"
  14. "github.com/gravitl/netmaker/logger"
  15. "github.com/gravitl/netmaker/models"
  16. "github.com/gravitl/netmaker/netclient/config"
  17. "github.com/gravitl/netmaker/netclient/daemon"
  18. "github.com/gravitl/netmaker/netclient/local"
  19. "github.com/gravitl/netmaker/netclient/ncutils"
  20. "github.com/gravitl/netmaker/netclient/wireguard"
  21. "golang.zx2c4.com/wireguard/wgctrl"
  22. )
  23. // LINUX_APP_DATA_PATH - linux path
  24. const LINUX_APP_DATA_PATH = "/etc/netmaker"
  25. // ListPorts - lists ports of WireGuard devices
  26. func ListPorts() error {
  27. wgclient, err := wgctrl.New()
  28. if err != nil {
  29. return err
  30. }
  31. defer wgclient.Close()
  32. devices, err := wgclient.Devices()
  33. if err != nil {
  34. return err
  35. }
  36. fmt.Println("Here are your ports:")
  37. for _, i := range devices {
  38. fmt.Println(i.ListenPort)
  39. }
  40. return err
  41. }
  42. func getPrivateAddr() (string, error) {
  43. var local string
  44. conn, err := net.Dial("udp", "8.8.8.8:80")
  45. if err == nil {
  46. defer conn.Close()
  47. localAddr := conn.LocalAddr().(*net.UDPAddr)
  48. localIP := localAddr.IP
  49. local = localIP.String()
  50. }
  51. if local == "" {
  52. local, err = getPrivateAddrBackup()
  53. }
  54. if local == "" {
  55. err = errors.New("could not find local ip")
  56. }
  57. return local, err
  58. }
  59. func getPrivateAddrBackup() (string, error) {
  60. ifaces, err := net.Interfaces()
  61. if err != nil {
  62. return "", err
  63. }
  64. var local string
  65. found := false
  66. for _, i := range ifaces {
  67. if i.Flags&net.FlagUp == 0 {
  68. continue // interface down
  69. }
  70. if i.Flags&net.FlagLoopback != 0 {
  71. continue // loopback interface
  72. }
  73. addrs, err := i.Addrs()
  74. if err != nil {
  75. return "", err
  76. }
  77. for _, addr := range addrs {
  78. var ip net.IP
  79. switch v := addr.(type) {
  80. case *net.IPNet:
  81. if !found {
  82. ip = v.IP
  83. local = ip.String()
  84. found = true
  85. }
  86. case *net.IPAddr:
  87. if !found {
  88. ip = v.IP
  89. local = ip.String()
  90. found = true
  91. }
  92. }
  93. }
  94. }
  95. if !found {
  96. err := errors.New("local ip address not found")
  97. return "", err
  98. }
  99. return local, err
  100. }
  101. // GetNode - gets node locally
  102. func GetNode(network string) models.Node {
  103. modcfg, err := config.ReadConfig(network)
  104. if err != nil {
  105. log.Fatalf("Error: %v", err)
  106. }
  107. return modcfg.Node
  108. }
  109. // Uninstall - uninstalls networks from client
  110. func Uninstall() error {
  111. networks, err := ncutils.GetSystemNetworks()
  112. if err != nil {
  113. logger.Log(1, "unable to retrieve networks: ", err.Error())
  114. logger.Log(1, "continuing uninstall without leaving networks")
  115. } else {
  116. for _, network := range networks {
  117. err = LeaveNetwork(network)
  118. if err != nil {
  119. logger.Log(1, "Encounter issue leaving network ", network, ": ", err.Error())
  120. }
  121. }
  122. }
  123. err = nil
  124. // clean up OS specific stuff
  125. if ncutils.IsWindows() {
  126. daemon.CleanupWindows()
  127. } else if ncutils.IsMac() {
  128. daemon.CleanupMac()
  129. } else if ncutils.IsLinux() {
  130. daemon.CleanupLinux()
  131. } else if ncutils.IsFreeBSD() {
  132. daemon.CleanupFreebsd()
  133. } else if !ncutils.IsKernel() {
  134. logger.Log(1, "manual cleanup required")
  135. }
  136. return err
  137. }
  138. // LeaveNetwork - client exits a network
  139. func LeaveNetwork(network string) error {
  140. cfg, err := config.ReadConfig(network)
  141. if err != nil {
  142. return err
  143. }
  144. node := cfg.Node
  145. if node.IsServer != "yes" {
  146. token, err := Authenticate(cfg)
  147. if err != nil {
  148. logger.Log(0, "unable to authenticate: "+err.Error())
  149. } else {
  150. url := "https://" + cfg.Server.API + "/api/nodes/" + cfg.Network + "/" + cfg.Node.ID
  151. response, err := API("", http.MethodDelete, url, token)
  152. if err != nil {
  153. logger.Log(0, "error deleting node on server: "+err.Error())
  154. } else {
  155. if response.StatusCode == http.StatusOK {
  156. logger.Log(0, "deleted node", cfg.Node.Name, " on network ", cfg.Network)
  157. } else {
  158. bodybytes, _ := io.ReadAll(response.Body)
  159. defer response.Body.Close()
  160. logger.Log(0, fmt.Sprintf("error deleting node on server %s %s", response.Status, string(bodybytes)))
  161. }
  162. }
  163. }
  164. }
  165. wgClient, wgErr := wgctrl.New()
  166. if wgErr == nil {
  167. removeIface := cfg.Node.Interface
  168. queryAddr := cfg.Node.PrimaryAddress()
  169. if ncutils.IsMac() {
  170. var macIface string
  171. macIface, wgErr = local.GetMacIface(queryAddr)
  172. if wgErr == nil && removeIface != "" {
  173. removeIface = macIface
  174. }
  175. wgErr = nil
  176. }
  177. dev, devErr := wgClient.Device(removeIface)
  178. if devErr == nil {
  179. local.FlushPeerRoutes(removeIface, queryAddr, dev.Peers[:])
  180. _, cidr, cidrErr := net.ParseCIDR(cfg.NetworkSettings.AddressRange)
  181. if cidrErr == nil {
  182. local.RemoveCIDRRoute(removeIface, queryAddr, cidr)
  183. }
  184. } else {
  185. logger.Log(1, "could not flush peer routes when leaving network, ", cfg.Node.Network)
  186. }
  187. }
  188. err = WipeLocal(node.Network)
  189. if err != nil {
  190. logger.Log(1, "unable to wipe local config")
  191. } else {
  192. logger.Log(1, "removed ", node.Network, " network locally")
  193. }
  194. currentNets, err := ncutils.GetSystemNetworks()
  195. if err != nil || len(currentNets) <= 1 {
  196. daemon.Stop() // stop system daemon if last network
  197. return RemoveLocalInstance(cfg, network)
  198. }
  199. return daemon.Restart()
  200. }
  201. // RemoveLocalInstance - remove all netclient files locally for a network
  202. func RemoveLocalInstance(cfg *config.ClientConfig, networkName string) error {
  203. if cfg.Daemon != "off" {
  204. if ncutils.IsWindows() {
  205. // TODO: Remove job?
  206. } else if ncutils.IsMac() {
  207. //TODO: Delete mac daemon
  208. } else if ncutils.IsFreeBSD() {
  209. daemon.RemoveFreebsdDaemon()
  210. } else {
  211. daemon.RemoveSystemDServices()
  212. }
  213. }
  214. return nil
  215. }
  216. // DeleteInterface - delete an interface of a network
  217. func DeleteInterface(ifacename string, postdown string) error {
  218. return wireguard.RemoveConf(ifacename, true)
  219. }
  220. // WipeLocal - wipes local instance
  221. func WipeLocal(network string) error {
  222. cfg, err := config.ReadConfig(network)
  223. if err != nil {
  224. return err
  225. }
  226. nodecfg := cfg.Node
  227. ifacename := nodecfg.Interface
  228. if ifacename != "" {
  229. if err = wireguard.RemoveConf(ifacename, true); err == nil {
  230. logger.Log(1, "removed WireGuard interface: ", ifacename)
  231. } else if strings.Contains(err.Error(), "does not exist") {
  232. err = nil
  233. }
  234. }
  235. home := ncutils.GetNetclientPathSpecific()
  236. if ncutils.FileExists(home + "netconfig-" + network) {
  237. err = os.Remove(home + "netconfig-" + network)
  238. if err != nil {
  239. log.Println("error removing netconfig:")
  240. log.Println(err.Error())
  241. }
  242. }
  243. if ncutils.FileExists(home + "backup.netconfig-" + network) {
  244. err = os.Remove(home + "backup.netconfig-" + network)
  245. if err != nil {
  246. log.Println("error removing backup netconfig:")
  247. log.Println(err.Error())
  248. }
  249. }
  250. if ncutils.FileExists(home + "nettoken-" + network) {
  251. err = os.Remove(home + "nettoken-" + network)
  252. if err != nil {
  253. log.Println("error removing nettoken:")
  254. log.Println(err.Error())
  255. }
  256. }
  257. if ncutils.FileExists(home + "secret-" + network) {
  258. err = os.Remove(home + "secret-" + network)
  259. if err != nil {
  260. log.Println("error removing secret:")
  261. log.Println(err.Error())
  262. }
  263. }
  264. if ncutils.FileExists(home + "traffic-" + network) {
  265. err = os.Remove(home + "traffic-" + network)
  266. if err != nil {
  267. log.Println("error removing traffic key:")
  268. log.Println(err.Error())
  269. }
  270. }
  271. if ncutils.FileExists(home + "wgkey-" + network) {
  272. err = os.Remove(home + "wgkey-" + network)
  273. if err != nil {
  274. log.Println("error removing wgkey:")
  275. log.Println(err.Error())
  276. }
  277. }
  278. if ncutils.FileExists(home + ifacename + ".conf") {
  279. err = os.Remove(home + ifacename + ".conf")
  280. if err != nil {
  281. log.Println("error removing .conf:")
  282. log.Println(err.Error())
  283. }
  284. }
  285. err = removeHostDNS(ifacename, ncutils.IsWindows())
  286. if err != nil {
  287. logger.Log(0, "failed to delete dns entries for", ifacename, err.Error())
  288. }
  289. return err
  290. }
  291. // GetNetmakerPath - gets netmaker path locally
  292. func GetNetmakerPath() string {
  293. return LINUX_APP_DATA_PATH
  294. }
  295. //API function to interact with netmaker api endpoints. response from endpoint is returned
  296. func API(data any, method, url, authorization string) (*http.Response, error) {
  297. var request *http.Request
  298. var err error
  299. if data != "" {
  300. payload, err := json.Marshal(data)
  301. if err != nil {
  302. return nil, fmt.Errorf("error encoding data %w", err)
  303. }
  304. request, err = http.NewRequest(method, url, bytes.NewBuffer(payload))
  305. if err != nil {
  306. return nil, fmt.Errorf("error creating http request %w", err)
  307. }
  308. request.Header.Set("Content-Type", "application/json")
  309. } else {
  310. request, err = http.NewRequest(method, url, nil)
  311. if err != nil {
  312. return nil, fmt.Errorf("error creating http request %w", err)
  313. }
  314. }
  315. if authorization != "" {
  316. request.Header.Set("authorization", "Bearer "+authorization)
  317. }
  318. client := http.Client{}
  319. return client.Do(request)
  320. }
  321. // Authenticate authenticates with api to permit subsequent interactions with the api
  322. func Authenticate(cfg *config.ClientConfig) (string, error) {
  323. pass, err := os.ReadFile(ncutils.GetNetclientPathSpecific() + "secret-" + cfg.Network)
  324. if err != nil {
  325. return "", fmt.Errorf("could not read secrets file %w", err)
  326. }
  327. data := models.AuthParams{
  328. MacAddress: cfg.Node.MacAddress,
  329. ID: cfg.Node.ID,
  330. Password: string(pass),
  331. }
  332. url := "https://" + cfg.Server.API + "/api/nodes/adm/" + cfg.Network + "/authenticate"
  333. response, err := API(data, http.MethodPost, url, "")
  334. if err != nil {
  335. return "", err
  336. }
  337. defer response.Body.Close()
  338. if response.StatusCode != http.StatusOK {
  339. bodybytes, _ := io.ReadAll(response.Body)
  340. return "", fmt.Errorf("failed to authenticate %s %s", response.Status, string(bodybytes))
  341. }
  342. resp := models.SuccessResponse{}
  343. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  344. return "", fmt.Errorf("error decoding respone %w", err)
  345. }
  346. tokenData := resp.Response.(map[string]interface{})
  347. token := tokenData["AuthToken"]
  348. return token.(string), nil
  349. }
  350. // RegisterWithServer calls the register endpoint with privatekey and commonname - api returns ca and client certificate
  351. func SetServerInfo(cfg *config.ClientConfig) error {
  352. cfg, err := config.ReadConfig(cfg.Network)
  353. if err != nil {
  354. return err
  355. }
  356. url := "https://" + cfg.Server.API + "/api/server/getserverinfo"
  357. logger.Log(1, "server at "+url)
  358. token, err := Authenticate(cfg)
  359. if err != nil {
  360. return err
  361. }
  362. response, err := API("", http.MethodGet, url, token)
  363. if err != nil {
  364. return err
  365. }
  366. if response.StatusCode != http.StatusOK {
  367. return errors.New(response.Status)
  368. }
  369. var resp models.ServerConfig
  370. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  371. return errors.New("unmarshal cert error " + err.Error())
  372. }
  373. // set broker information on register
  374. cfg.Server.Server = resp.Server
  375. cfg.Server.MQPort = resp.MQPort
  376. if err = config.ModServerConfig(&cfg.Server, cfg.Node.Network); err != nil {
  377. logger.Log(0, "error overwriting config with broker information: "+err.Error())
  378. }
  379. return nil
  380. }
  381. func informPortChange(node *models.Node) {
  382. if node.ListenPort == 0 {
  383. logger.Log(0, "UDP hole punching enabled for node", node.Name)
  384. } else {
  385. logger.Log(0, "node", node.Name, "is using port", strconv.Itoa(int(node.ListenPort)))
  386. }
  387. }