common.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428
  1. package functions
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "log"
  9. "net"
  10. "net/http"
  11. "os"
  12. "path/filepath"
  13. "strconv"
  14. "strings"
  15. "time"
  16. "github.com/gravitl/netmaker/logger"
  17. "github.com/gravitl/netmaker/models"
  18. "github.com/gravitl/netmaker/netclient/config"
  19. "github.com/gravitl/netmaker/netclient/daemon"
  20. "github.com/gravitl/netmaker/netclient/local"
  21. "github.com/gravitl/netmaker/netclient/ncutils"
  22. "github.com/gravitl/netmaker/netclient/wireguard"
  23. "golang.zx2c4.com/wireguard/wgctrl"
  24. )
  25. // LINUX_APP_DATA_PATH - linux path
  26. const LINUX_APP_DATA_PATH = "/etc/netmaker"
  27. // HTTP_TIMEOUT - timeout in seconds for http requests
  28. const HTTP_TIMEOUT = 30
  29. // HTTPClient - http client to be reused by all
  30. var HTTPClient http.Client
  31. // SetHTTPClient -sets http client with sane default
  32. func SetHTTPClient() {
  33. HTTPClient = http.Client{
  34. Timeout: HTTP_TIMEOUT * time.Second,
  35. }
  36. }
  37. // ListPorts - lists ports of WireGuard devices
  38. func ListPorts() error {
  39. wgclient, err := wgctrl.New()
  40. if err != nil {
  41. return err
  42. }
  43. defer wgclient.Close()
  44. devices, err := wgclient.Devices()
  45. if err != nil {
  46. return err
  47. }
  48. fmt.Println("Here are your ports:")
  49. for _, i := range devices {
  50. fmt.Println(i.ListenPort)
  51. }
  52. return err
  53. }
  54. func getPrivateAddr() (string, error) {
  55. var local string
  56. conn, err := net.Dial("udp", "8.8.8.8:80")
  57. if err == nil {
  58. defer conn.Close()
  59. localAddr := conn.LocalAddr().(*net.UDPAddr)
  60. localIP := localAddr.IP
  61. local = localIP.String()
  62. }
  63. if local == "" {
  64. local, err = getPrivateAddrBackup()
  65. }
  66. if local == "" {
  67. err = errors.New("could not find local ip")
  68. }
  69. return local, err
  70. }
  71. func getPrivateAddrBackup() (string, error) {
  72. ifaces, err := net.Interfaces()
  73. if err != nil {
  74. return "", err
  75. }
  76. var local string
  77. found := false
  78. for _, i := range ifaces {
  79. if i.Flags&net.FlagUp == 0 {
  80. continue // interface down
  81. }
  82. if i.Flags&net.FlagLoopback != 0 {
  83. continue // loopback interface
  84. }
  85. addrs, err := i.Addrs()
  86. if err != nil {
  87. return "", err
  88. }
  89. for _, addr := range addrs {
  90. var ip net.IP
  91. switch v := addr.(type) {
  92. case *net.IPNet:
  93. if !found {
  94. ip = v.IP
  95. local = ip.String()
  96. found = true
  97. }
  98. case *net.IPAddr:
  99. if !found {
  100. ip = v.IP
  101. local = ip.String()
  102. found = true
  103. }
  104. }
  105. }
  106. }
  107. if !found {
  108. err := errors.New("local ip address not found")
  109. return "", err
  110. }
  111. return local, err
  112. }
  113. // GetNode - gets node locally
  114. func GetNode(network string) models.Node {
  115. modcfg, err := config.ReadConfig(network)
  116. if err != nil {
  117. log.Fatalf("Error: %v", err)
  118. }
  119. return modcfg.Node
  120. }
  121. // Uninstall - uninstalls networks from client
  122. func Uninstall() error {
  123. networks, err := ncutils.GetSystemNetworks()
  124. if err != nil {
  125. logger.Log(1, "unable to retrieve networks: ", err.Error())
  126. logger.Log(1, "continuing uninstall without leaving networks")
  127. } else {
  128. for _, network := range networks {
  129. err = LeaveNetwork(network)
  130. if err != nil {
  131. logger.Log(1, "encounter issue leaving network", network, ":", err.Error())
  132. }
  133. }
  134. }
  135. err = nil
  136. // clean up OS specific stuff
  137. if ncutils.IsWindows() {
  138. daemon.CleanupWindows()
  139. } else if ncutils.IsMac() {
  140. daemon.CleanupMac()
  141. } else if ncutils.IsLinux() {
  142. daemon.CleanupLinux()
  143. } else if ncutils.IsFreeBSD() {
  144. daemon.CleanupFreebsd()
  145. } else if !ncutils.IsKernel() {
  146. logger.Log(1, "manual cleanup required")
  147. }
  148. return err
  149. }
  150. // LeaveNetwork - client exits a network
  151. func LeaveNetwork(network string) error {
  152. cfg, err := config.ReadConfig(network)
  153. if err != nil {
  154. return err
  155. }
  156. if err := deleteNodeFromServer(cfg); err != nil {
  157. logger.Log(0, "error deleting node from server", err.Error())
  158. }
  159. if err := deleteLocalNetwork(cfg); err != nil {
  160. logger.Log(0, "error deleting local network ", err.Error())
  161. }
  162. if err := WipeLocal(cfg); err != nil {
  163. logger.Log(0, "error deleting local network ", err.Error())
  164. }
  165. if err := removeHostDNS(cfg.Node.Interface, ncutils.IsWindows()); err != nil {
  166. logger.Log(0, "failed to delete dns entries for", cfg.Node.Interface, err.Error())
  167. }
  168. //TODO remove keys if last network on server
  169. return daemon.Restart()
  170. }
  171. func deleteNodeFromServer(cfg *config.ClientConfig) error {
  172. node := cfg.Node
  173. if node.IsServer == "yes" {
  174. return errors.New("attempt to delete server node ... not permitted")
  175. }
  176. token, err := Authenticate(cfg)
  177. if err != nil {
  178. return fmt.Errorf("unable to authenticate %w", err)
  179. }
  180. url := "https://" + cfg.Server.API + "/api/nodes/" + cfg.Network + "/" + cfg.Node.ID
  181. response, err := API("", http.MethodDelete, url, token)
  182. if err != nil {
  183. return fmt.Errorf("error deleting node on server: %w", err)
  184. }
  185. if response.StatusCode != http.StatusOK {
  186. bodybytes, _ := io.ReadAll(response.Body)
  187. defer response.Body.Close()
  188. return fmt.Errorf("error deleting node from network %s on server %s %s", cfg.Network, response.Status, string(bodybytes))
  189. }
  190. return nil
  191. }
  192. func deleteLocalNetwork(cfg *config.ClientConfig) error {
  193. wgClient, wgErr := wgctrl.New()
  194. if wgErr != nil {
  195. return wgErr
  196. }
  197. removeIface := cfg.Node.Interface
  198. queryAddr := cfg.Node.PrimaryAddress()
  199. if ncutils.IsMac() {
  200. var macIface string
  201. macIface, wgErr = local.GetMacIface(queryAddr)
  202. if wgErr == nil && removeIface != "" {
  203. removeIface = macIface
  204. }
  205. }
  206. dev, devErr := wgClient.Device(removeIface)
  207. if devErr != nil {
  208. return fmt.Errorf("error flushing routes %w", devErr)
  209. }
  210. local.FlushPeerRoutes(removeIface, queryAddr, dev.Peers[:])
  211. _, cidr, cidrErr := net.ParseCIDR(cfg.NetworkSettings.AddressRange)
  212. if cidrErr != nil {
  213. return fmt.Errorf("error flushing routes %w", cidrErr)
  214. }
  215. local.RemoveCIDRRoute(removeIface, queryAddr, cidr)
  216. return nil
  217. }
  218. // DeleteInterface - delete an interface of a network
  219. func DeleteInterface(ifacename string, postdown string) error {
  220. return wireguard.RemoveConf(ifacename, true)
  221. }
  222. // WipeLocal - wipes local instance
  223. func WipeLocal(cfg *config.ClientConfig) error {
  224. if err := wireguard.RemoveConf(cfg.Node.Interface, true); err == nil {
  225. logger.Log(1, "network:", cfg.Node.Network, "removed WireGuard interface: ", cfg.Node.Interface)
  226. } else if strings.Contains(err.Error(), "does not exist") {
  227. err = nil
  228. }
  229. home := ncutils.GetNetclientPathSpecific()
  230. fail := false
  231. files, err := filepath.Glob(cfg.Node.Network)
  232. if err != nil {
  233. logger.Log(0, "no matching files", err.Error())
  234. fail = true
  235. }
  236. for _, file := range files {
  237. if err := os.Remove(file); err != nil {
  238. logger.Log(0, "failed to delete file", file, err.Error())
  239. fail = true
  240. }
  241. }
  242. // if ncutils.FileExists(home + "netconfig-" + cfg.Node.Network) {
  243. // if err := os.Remove(home + "netconfig-" + cfg.Node.Network); err != nil {
  244. // log.Println("error removing netconfig:")
  245. // log.Println(err.Error())
  246. // fail = true
  247. // }
  248. // }
  249. // if ncutils.FileExists(home + "backup.netconfig-" + cfg.Node.Network) {
  250. // if err := os.Remove(home + "backup.netconfig-" + cfg.Node.Network); err != nil {
  251. // log.Println("error removing backup netconfig:")
  252. // log.Println(err.Error())
  253. // fail = true
  254. // }
  255. // }
  256. // if ncutils.FileExists(home + "nettoken-" + cfg.Node.Network) {
  257. // if err := os.Remove(home + "nettoken-" + cfg.Node.Network); err != nil {
  258. // log.Println("error removing nettoken:")
  259. // log.Println(err.Error())
  260. // fail = true
  261. // }
  262. // }
  263. // if ncutils.FileExists(home + "secret-" + cfg.Node.Network) {
  264. // if err := os.Remove(home + "secret-" + cfg.Node.Network); err != nil {
  265. // log.Println("error removing secret:")
  266. // log.Println(err.Error())
  267. // fail = true
  268. // }
  269. // }
  270. // if ncutils.FileExists(home + "traffic-" + cfg.Node.Network) {
  271. // if err := os.Remove(home + "traffic-" + cfg.Node.Network); err != nil {
  272. // log.Println("error removing traffic key:")
  273. // log.Println(err.Error())
  274. // fail = true
  275. // }
  276. // }
  277. // if ncutils.FileExists(home + "wgkey-" + cfg.Node.Network) {
  278. // if err := os.Remove(home + "wgkey-" + cfg.Node.Network); err != nil {
  279. // log.Println("error removing wgkey:")
  280. // log.Println(err.Error())
  281. // fail = true
  282. // }
  283. // }
  284. if cfg.Node.Interface != "" {
  285. if ncutils.FileExists(home + cfg.Node.Interface + ".conf") {
  286. if err := os.Remove(home + cfg.Node.Interface + ".conf"); err != nil {
  287. log.Println("error removing .conf:")
  288. log.Println(err.Error())
  289. fail = true
  290. }
  291. }
  292. }
  293. if fail {
  294. return errors.New("not all files were deleted")
  295. }
  296. return nil
  297. }
  298. // GetNetmakerPath - gets netmaker path locally
  299. func GetNetmakerPath() string {
  300. return LINUX_APP_DATA_PATH
  301. }
  302. // API function to interact with netmaker api endpoints. response from endpoint is returned
  303. func API(data any, method, url, authorization string) (*http.Response, error) {
  304. var request *http.Request
  305. var err error
  306. if data != "" {
  307. payload, err := json.Marshal(data)
  308. if err != nil {
  309. return nil, fmt.Errorf("error encoding data %w", err)
  310. }
  311. request, err = http.NewRequest(method, url, bytes.NewBuffer(payload))
  312. if err != nil {
  313. return nil, fmt.Errorf("error creating http request %w", err)
  314. }
  315. request.Header.Set("Content-Type", "application/json")
  316. } else {
  317. request, err = http.NewRequest(method, url, nil)
  318. if err != nil {
  319. return nil, fmt.Errorf("error creating http request %w", err)
  320. }
  321. }
  322. if authorization != "" {
  323. request.Header.Set("authorization", "Bearer "+authorization)
  324. }
  325. return HTTPClient.Do(request)
  326. }
  327. // Authenticate authenticates with api to permit subsequent interactions with the api
  328. func Authenticate(cfg *config.ClientConfig) (string, error) {
  329. pass, err := os.ReadFile(ncutils.GetNetclientPathSpecific() + "secret-" + cfg.Network)
  330. if err != nil {
  331. return "", fmt.Errorf("could not read secrets file %w", err)
  332. }
  333. data := models.AuthParams{
  334. MacAddress: cfg.Node.MacAddress,
  335. ID: cfg.Node.ID,
  336. Password: string(pass),
  337. }
  338. url := "https://" + cfg.Server.API + "/api/nodes/adm/" + cfg.Network + "/authenticate"
  339. response, err := API(data, http.MethodPost, url, "")
  340. if err != nil {
  341. return "", err
  342. }
  343. defer response.Body.Close()
  344. if response.StatusCode != http.StatusOK {
  345. bodybytes, _ := io.ReadAll(response.Body)
  346. return "", fmt.Errorf("failed to authenticate %s %s", response.Status, string(bodybytes))
  347. }
  348. resp := models.SuccessResponse{}
  349. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  350. return "", fmt.Errorf("error decoding respone %w", err)
  351. }
  352. tokenData := resp.Response.(map[string]interface{})
  353. token := tokenData["AuthToken"]
  354. return token.(string), nil
  355. }
  356. // RegisterWithServer calls the register endpoint with privatekey and commonname - api returns ca and client certificate
  357. func SetServerInfo(cfg *config.ClientConfig) error {
  358. cfg, err := config.ReadConfig(cfg.Network)
  359. if err != nil {
  360. return err
  361. }
  362. url := "https://" + cfg.Server.API + "/api/server/getserverinfo"
  363. logger.Log(1, "server at "+url)
  364. token, err := Authenticate(cfg)
  365. if err != nil {
  366. return err
  367. }
  368. response, err := API("", http.MethodGet, url, token)
  369. if err != nil {
  370. return err
  371. }
  372. if response.StatusCode != http.StatusOK {
  373. return errors.New(response.Status)
  374. }
  375. var resp models.ServerConfig
  376. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  377. return errors.New("unmarshal cert error " + err.Error())
  378. }
  379. // set broker information on register
  380. cfg.Server.Server = resp.Server
  381. cfg.Server.MQPort = resp.MQPort
  382. if err = config.ModServerConfig(&cfg.Server, cfg.Node.Network); err != nil {
  383. logger.Log(0, "error overwriting config with broker information: "+err.Error())
  384. }
  385. return nil
  386. }
  387. func informPortChange(node *models.Node) {
  388. if node.ListenPort == 0 {
  389. logger.Log(0, "network:", node.Network, "UDP hole punching enabled for node", node.Name)
  390. } else {
  391. logger.Log(0, "network:", node.Network, "node", node.Name, "is using port", strconv.Itoa(int(node.ListenPort)))
  392. }
  393. }