common.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417
  1. package functions
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "log"
  9. "net"
  10. "net/http"
  11. "os"
  12. "strings"
  13. "time"
  14. "github.com/gravitl/netmaker/logger"
  15. "github.com/gravitl/netmaker/models"
  16. "github.com/gravitl/netmaker/netclient/config"
  17. "github.com/gravitl/netmaker/netclient/daemon"
  18. "github.com/gravitl/netmaker/netclient/local"
  19. "github.com/gravitl/netmaker/netclient/ncutils"
  20. "github.com/gravitl/netmaker/netclient/wireguard"
  21. "golang.zx2c4.com/wireguard/wgctrl"
  22. )
  23. // LINUX_APP_DATA_PATH - linux path
  24. const LINUX_APP_DATA_PATH = "/etc/netmaker"
  25. // HTTP_TIMEOUT - timeout in seconds for http requests
  26. const HTTP_TIMEOUT = 30
  27. // ListPorts - lists ports of WireGuard devices
  28. func ListPorts() error {
  29. wgclient, err := wgctrl.New()
  30. if err != nil {
  31. return err
  32. }
  33. defer wgclient.Close()
  34. devices, err := wgclient.Devices()
  35. if err != nil {
  36. return err
  37. }
  38. fmt.Println("Here are your ports:")
  39. for _, i := range devices {
  40. fmt.Println(i.ListenPort)
  41. }
  42. return err
  43. }
  44. func getPrivateAddr() (string, error) {
  45. var local string
  46. conn, err := net.Dial("udp", "8.8.8.8:80")
  47. if err == nil {
  48. defer conn.Close()
  49. localAddr := conn.LocalAddr().(*net.UDPAddr)
  50. localIP := localAddr.IP
  51. local = localIP.String()
  52. }
  53. if local == "" {
  54. local, err = getPrivateAddrBackup()
  55. }
  56. if local == "" {
  57. err = errors.New("could not find local ip")
  58. }
  59. return local, err
  60. }
  61. func getPrivateAddrBackup() (string, error) {
  62. ifaces, err := net.Interfaces()
  63. if err != nil {
  64. return "", err
  65. }
  66. var local string
  67. found := false
  68. for _, i := range ifaces {
  69. if i.Flags&net.FlagUp == 0 {
  70. continue // interface down
  71. }
  72. if i.Flags&net.FlagLoopback != 0 {
  73. continue // loopback interface
  74. }
  75. addrs, err := i.Addrs()
  76. if err != nil {
  77. return "", err
  78. }
  79. for _, addr := range addrs {
  80. var ip net.IP
  81. switch v := addr.(type) {
  82. case *net.IPNet:
  83. if !found {
  84. ip = v.IP
  85. local = ip.String()
  86. found = true
  87. }
  88. case *net.IPAddr:
  89. if !found {
  90. ip = v.IP
  91. local = ip.String()
  92. found = true
  93. }
  94. }
  95. }
  96. }
  97. if !found {
  98. err := errors.New("local ip address not found")
  99. return "", err
  100. }
  101. return local, err
  102. }
  103. // GetNode - gets node locally
  104. func GetNode(network string) models.Node {
  105. modcfg, err := config.ReadConfig(network)
  106. if err != nil {
  107. log.Fatalf("Error: %v", err)
  108. }
  109. return modcfg.Node
  110. }
  111. // Uninstall - uninstalls networks from client
  112. func Uninstall() error {
  113. networks, err := ncutils.GetSystemNetworks()
  114. if err != nil {
  115. logger.Log(1, "unable to retrieve networks: ", err.Error())
  116. logger.Log(1, "continuing uninstall without leaving networks")
  117. } else {
  118. for _, network := range networks {
  119. err = LeaveNetwork(network)
  120. if err != nil {
  121. logger.Log(1, "Encounter issue leaving network ", network, ": ", err.Error())
  122. }
  123. }
  124. }
  125. err = nil
  126. // clean up OS specific stuff
  127. if ncutils.IsWindows() {
  128. daemon.CleanupWindows()
  129. } else if ncutils.IsMac() {
  130. daemon.CleanupMac()
  131. } else if ncutils.IsLinux() {
  132. daemon.CleanupLinux()
  133. } else if ncutils.IsFreeBSD() {
  134. daemon.CleanupFreebsd()
  135. } else if !ncutils.IsKernel() {
  136. logger.Log(1, "manual cleanup required")
  137. }
  138. return err
  139. }
  140. // LeaveNetwork - client exits a network
  141. func LeaveNetwork(network string) error {
  142. cfg, err := config.ReadConfig(network)
  143. if err != nil {
  144. return err
  145. }
  146. node := cfg.Node
  147. if node.IsServer != "yes" {
  148. token, err := Authenticate(cfg)
  149. if err != nil {
  150. logger.Log(0, "unable to authenticate: "+err.Error())
  151. } else {
  152. url := "https://" + cfg.Server.API + "/api/nodes/" + cfg.Network + "/" + cfg.Node.ID
  153. response, err := API("", http.MethodDelete, url, token)
  154. if err != nil {
  155. logger.Log(0, "error deleting node on server: "+err.Error())
  156. } else {
  157. if response.StatusCode == http.StatusOK {
  158. logger.Log(0, "deleted node", cfg.Node.Name, " on network ", cfg.Network)
  159. } else {
  160. bodybytes, _ := io.ReadAll(response.Body)
  161. defer response.Body.Close()
  162. logger.Log(0, fmt.Sprintf("error deleting node on server %s %s", response.Status, string(bodybytes)))
  163. }
  164. }
  165. }
  166. }
  167. wgClient, wgErr := wgctrl.New()
  168. if wgErr == nil {
  169. removeIface := cfg.Node.Interface
  170. queryAddr := cfg.Node.PrimaryAddress()
  171. if ncutils.IsMac() {
  172. var macIface string
  173. macIface, wgErr = local.GetMacIface(queryAddr)
  174. if wgErr == nil && removeIface != "" {
  175. removeIface = macIface
  176. }
  177. wgErr = nil
  178. }
  179. dev, devErr := wgClient.Device(removeIface)
  180. if devErr == nil {
  181. local.FlushPeerRoutes(removeIface, queryAddr, dev.Peers[:])
  182. _, cidr, cidrErr := net.ParseCIDR(cfg.NetworkSettings.AddressRange)
  183. if cidrErr == nil {
  184. local.RemoveCIDRRoute(removeIface, queryAddr, cidr)
  185. }
  186. } else {
  187. logger.Log(1, "could not flush peer routes when leaving network, ", cfg.Node.Network)
  188. }
  189. }
  190. err = WipeLocal(node.Network)
  191. if err != nil {
  192. logger.Log(1, "unable to wipe local config")
  193. } else {
  194. logger.Log(1, "removed ", node.Network, " network locally")
  195. }
  196. currentNets, err := ncutils.GetSystemNetworks()
  197. if err != nil || len(currentNets) <= 1 {
  198. daemon.Stop() // stop system daemon if last network
  199. return RemoveLocalInstance(cfg, network)
  200. }
  201. return daemon.Restart()
  202. }
  203. // RemoveLocalInstance - remove all netclient files locally for a network
  204. func RemoveLocalInstance(cfg *config.ClientConfig, networkName string) error {
  205. if cfg.Daemon != "off" {
  206. if ncutils.IsWindows() {
  207. // TODO: Remove job?
  208. } else if ncutils.IsMac() {
  209. //TODO: Delete mac daemon
  210. } else if ncutils.IsFreeBSD() {
  211. daemon.RemoveFreebsdDaemon()
  212. } else {
  213. daemon.RemoveSystemDServices()
  214. }
  215. }
  216. return nil
  217. }
  218. // DeleteInterface - delete an interface of a network
  219. func DeleteInterface(ifacename string, postdown string) error {
  220. return wireguard.RemoveConf(ifacename, true)
  221. }
  222. // WipeLocal - wipes local instance
  223. func WipeLocal(network string) error {
  224. cfg, err := config.ReadConfig(network)
  225. if err != nil {
  226. return err
  227. }
  228. nodecfg := cfg.Node
  229. ifacename := nodecfg.Interface
  230. if ifacename != "" {
  231. if err = wireguard.RemoveConf(ifacename, true); err == nil {
  232. logger.Log(1, "removed WireGuard interface: ", ifacename)
  233. } else if strings.Contains(err.Error(), "does not exist") {
  234. err = nil
  235. }
  236. }
  237. home := ncutils.GetNetclientPathSpecific()
  238. if ncutils.FileExists(home + "netconfig-" + network) {
  239. err = os.Remove(home + "netconfig-" + network)
  240. if err != nil {
  241. log.Println("error removing netconfig:")
  242. log.Println(err.Error())
  243. }
  244. }
  245. if ncutils.FileExists(home + "backup.netconfig-" + network) {
  246. err = os.Remove(home + "backup.netconfig-" + network)
  247. if err != nil {
  248. log.Println("error removing backup netconfig:")
  249. log.Println(err.Error())
  250. }
  251. }
  252. if ncutils.FileExists(home + "nettoken-" + network) {
  253. err = os.Remove(home + "nettoken-" + network)
  254. if err != nil {
  255. log.Println("error removing nettoken:")
  256. log.Println(err.Error())
  257. }
  258. }
  259. if ncutils.FileExists(home + "secret-" + network) {
  260. err = os.Remove(home + "secret-" + network)
  261. if err != nil {
  262. log.Println("error removing secret:")
  263. log.Println(err.Error())
  264. }
  265. }
  266. if ncutils.FileExists(home + "traffic-" + network) {
  267. err = os.Remove(home + "traffic-" + network)
  268. if err != nil {
  269. log.Println("error removing traffic key:")
  270. log.Println(err.Error())
  271. }
  272. }
  273. if ncutils.FileExists(home + "wgkey-" + network) {
  274. err = os.Remove(home + "wgkey-" + network)
  275. if err != nil {
  276. log.Println("error removing wgkey:")
  277. log.Println(err.Error())
  278. }
  279. }
  280. if ncutils.FileExists(home + ifacename + ".conf") {
  281. err = os.Remove(home + ifacename + ".conf")
  282. if err != nil {
  283. log.Println("error removing .conf:")
  284. log.Println(err.Error())
  285. }
  286. }
  287. err = removeHostDNS(ifacename, ncutils.IsWindows())
  288. if err != nil {
  289. logger.Log(0, "failed to delete dns entries for", ifacename, err.Error())
  290. }
  291. return err
  292. }
  293. // GetNetmakerPath - gets netmaker path locally
  294. func GetNetmakerPath() string {
  295. return LINUX_APP_DATA_PATH
  296. }
  297. //API function to interact with netmaker api endpoints. response from endpoint is returned
  298. func API(data any, method, url, authorization string) (*http.Response, error) {
  299. var request *http.Request
  300. var err error
  301. if data != "" {
  302. payload, err := json.Marshal(data)
  303. if err != nil {
  304. return nil, fmt.Errorf("error encoding data %w", err)
  305. }
  306. request, err = http.NewRequest(method, url, bytes.NewBuffer(payload))
  307. if err != nil {
  308. return nil, fmt.Errorf("error creating http request %w", err)
  309. }
  310. request.Header.Set("Content-Type", "application/json")
  311. } else {
  312. request, err = http.NewRequest(method, url, nil)
  313. if err != nil {
  314. return nil, fmt.Errorf("error creating http request %w", err)
  315. }
  316. }
  317. if authorization != "" {
  318. request.Header.Set("authorization", "Bearer "+authorization)
  319. }
  320. client := http.Client{
  321. Timeout: HTTP_TIMEOUT * time.Second,
  322. }
  323. return client.Do(request)
  324. }
  325. // Authenticate authenticates with api to permit subsequent interactions with the api
  326. func Authenticate(cfg *config.ClientConfig) (string, error) {
  327. pass, err := os.ReadFile(ncutils.GetNetclientPathSpecific() + "secret-" + cfg.Network)
  328. if err != nil {
  329. return "", fmt.Errorf("could not read secrets file %w", err)
  330. }
  331. data := models.AuthParams{
  332. MacAddress: cfg.Node.MacAddress,
  333. ID: cfg.Node.ID,
  334. Password: string(pass),
  335. }
  336. url := "https://" + cfg.Server.API + "/api/nodes/adm/" + cfg.Network + "/authenticate"
  337. response, err := API(data, http.MethodPost, url, "")
  338. if err != nil {
  339. return "", err
  340. }
  341. defer response.Body.Close()
  342. if response.StatusCode != http.StatusOK {
  343. bodybytes, _ := io.ReadAll(response.Body)
  344. return "", fmt.Errorf("failed to authenticate %s %s", response.Status, string(bodybytes))
  345. }
  346. resp := models.SuccessResponse{}
  347. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  348. return "", fmt.Errorf("error decoding respone %w", err)
  349. }
  350. tokenData := resp.Response.(map[string]interface{})
  351. token := tokenData["AuthToken"]
  352. return token.(string), nil
  353. }
  354. // RegisterWithServer calls the register endpoint with privatekey and commonname - api returns ca and client certificate
  355. func SetServerInfo(cfg *config.ClientConfig) error {
  356. cfg, err := config.ReadConfig(cfg.Network)
  357. if err != nil {
  358. return err
  359. }
  360. url := "https://" + cfg.Server.API + "/api/server/getserverinfo"
  361. logger.Log(1, "server at "+url)
  362. token, err := Authenticate(cfg)
  363. if err != nil {
  364. return err
  365. }
  366. response, err := API("", http.MethodGet, url, token)
  367. if err != nil {
  368. return err
  369. }
  370. if response.StatusCode != http.StatusOK {
  371. return errors.New(response.Status)
  372. }
  373. var resp models.ServerConfig
  374. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  375. return errors.New("unmarshal cert error " + err.Error())
  376. }
  377. // set broker information on register
  378. cfg.Server.Server = resp.Server
  379. cfg.Server.MQPort = resp.MQPort
  380. if err = config.ModServerConfig(&cfg.Server, cfg.Node.Network); err != nil {
  381. logger.Log(0, "error overwriting config with broker information: "+err.Error())
  382. }
  383. return nil
  384. }