2
0

networks.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635
  1. package logic
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "fmt"
  6. "net"
  7. "regexp"
  8. "sort"
  9. "strings"
  10. "sync"
  11. "time"
  12. "github.com/c-robinson/iplib"
  13. validator "github.com/go-playground/validator/v10"
  14. "github.com/google/uuid"
  15. "github.com/gravitl/netmaker/database"
  16. "github.com/gravitl/netmaker/logger"
  17. "github.com/gravitl/netmaker/logic/acls/nodeacls"
  18. "github.com/gravitl/netmaker/models"
  19. "github.com/gravitl/netmaker/servercfg"
  20. "github.com/gravitl/netmaker/validation"
  21. "golang.org/x/exp/slog"
  22. )
  23. var (
  24. networkMutex = &sync.RWMutex{}
  25. networkCacheMutex = &sync.RWMutex{}
  26. networkCacheMap = make(map[string]models.Network)
  27. allocatedIpMap = make(map[string]map[string]net.IP)
  28. )
  29. // SetAllocatedIpMap - set allocated ip map for networks
  30. func SetAllocatedIpMap() error {
  31. logger.Log(0, "start setting up allocated ip map")
  32. if allocatedIpMap == nil {
  33. allocatedIpMap = map[string]map[string]net.IP{}
  34. }
  35. currentNetworks, err := GetNetworks()
  36. if err != nil {
  37. return err
  38. }
  39. for _, v := range currentNetworks {
  40. pMap := map[string]net.IP{}
  41. netName := v.NetID
  42. //nodes
  43. nodes, err := GetNetworkNodes(netName)
  44. if err != nil {
  45. slog.Error("could not load node for network", netName, "error", err.Error())
  46. } else {
  47. for _, n := range nodes {
  48. if n.Address.IP != nil {
  49. pMap[n.Address.IP.String()] = n.Address.IP
  50. }
  51. if n.Address6.IP != nil {
  52. pMap[n.Address6.IP.String()] = n.Address6.IP
  53. }
  54. }
  55. }
  56. //extClients
  57. extClients, err := GetNetworkExtClients(netName)
  58. if err != nil {
  59. slog.Error("could not load extClient for network", netName, "error", err.Error())
  60. } else {
  61. for _, extClient := range extClients {
  62. if extClient.Address != "" {
  63. pMap[extClient.Address] = net.ParseIP(extClient.Address)
  64. }
  65. if extClient.Address6 != "" {
  66. pMap[extClient.Address6] = net.ParseIP(extClient.Address6)
  67. }
  68. }
  69. }
  70. allocatedIpMap[netName] = pMap
  71. }
  72. logger.Log(0, "setting up allocated ip map done")
  73. return nil
  74. }
  75. // ClearAllocatedIpMap - set allocatedIpMap to nil
  76. func ClearAllocatedIpMap() {
  77. allocatedIpMap = nil
  78. }
  79. func AddIpToAllocatedIpMap(networkName string, ip net.IP) {
  80. networkCacheMutex.Lock()
  81. allocatedIpMap[networkName][ip.String()] = ip
  82. networkCacheMutex.Unlock()
  83. }
  84. func RemoveIpFromAllocatedIpMap(networkName string, ip string) {
  85. networkCacheMutex.Lock()
  86. delete(allocatedIpMap[networkName], ip)
  87. networkCacheMutex.Unlock()
  88. }
  89. // AddNetworkToAllocatedIpMap - add network to allocated ip map when network is added
  90. func AddNetworkToAllocatedIpMap(networkName string) {
  91. networkCacheMutex.Lock()
  92. allocatedIpMap[networkName] = map[string]net.IP{}
  93. networkCacheMutex.Unlock()
  94. }
  95. // RemoveNetworkFromAllocatedIpMap - remove network from allocated ip map when network is deleted
  96. func RemoveNetworkFromAllocatedIpMap(networkName string) {
  97. networkCacheMutex.Lock()
  98. delete(allocatedIpMap, networkName)
  99. networkCacheMutex.Unlock()
  100. }
  101. func getNetworksFromCache() (networks []models.Network) {
  102. networkCacheMutex.RLock()
  103. for _, network := range networkCacheMap {
  104. networks = append(networks, network)
  105. }
  106. networkCacheMutex.RUnlock()
  107. return
  108. }
  109. func deleteNetworkFromCache(key string) {
  110. networkCacheMutex.Lock()
  111. delete(networkCacheMap, key)
  112. networkCacheMutex.Unlock()
  113. }
  114. func getNetworkFromCache(key string) (network models.Network, ok bool) {
  115. networkCacheMutex.RLock()
  116. network, ok = networkCacheMap[key]
  117. networkCacheMutex.RUnlock()
  118. return
  119. }
  120. func storeNetworkInCache(key string, network models.Network) {
  121. networkCacheMutex.Lock()
  122. networkCacheMap[key] = network
  123. networkCacheMutex.Unlock()
  124. }
  125. // GetNetworks - returns all networks from database
  126. func GetNetworks() ([]models.Network, error) {
  127. var networks []models.Network
  128. if servercfg.CacheEnabled() {
  129. networks := getNetworksFromCache()
  130. if len(networks) != 0 {
  131. return networks, nil
  132. }
  133. }
  134. collection, err := database.FetchRecords(database.NETWORKS_TABLE_NAME)
  135. if err != nil {
  136. return networks, err
  137. }
  138. for _, value := range collection {
  139. var network models.Network
  140. if err := json.Unmarshal([]byte(value), &network); err != nil {
  141. return networks, err
  142. }
  143. // add network our array
  144. networks = append(networks, network)
  145. if servercfg.CacheEnabled() {
  146. storeNetworkInCache(network.NetID, network)
  147. }
  148. }
  149. return networks, err
  150. }
  151. // DeleteNetwork - deletes a network
  152. func DeleteNetwork(network string) error {
  153. // remove ACL for network
  154. err := nodeacls.DeleteACLContainer(nodeacls.NetworkID(network))
  155. if err != nil {
  156. logger.Log(1, "failed to remove the node acls during network delete for network,", network)
  157. }
  158. // Delete default network enrollment key
  159. keys, _ := GetAllEnrollmentKeys()
  160. for _, key := range keys {
  161. if key.Tags[0] == network {
  162. if key.Default {
  163. DeleteEnrollmentKey(key.Value, true)
  164. break
  165. }
  166. }
  167. }
  168. nodeCount, err := GetNetworkNonServerNodeCount(network)
  169. if nodeCount == 0 || database.IsEmptyRecord(err) {
  170. // delete server nodes first then db records
  171. err = database.DeleteRecord(database.NETWORKS_TABLE_NAME, network)
  172. if err != nil {
  173. return err
  174. }
  175. if servercfg.CacheEnabled() {
  176. deleteNetworkFromCache(network)
  177. }
  178. return nil
  179. }
  180. return errors.New("node check failed. All nodes must be deleted before deleting network")
  181. }
  182. // CreateNetwork - creates a network in database
  183. func CreateNetwork(network models.Network) (models.Network, error) {
  184. networkMutex.Lock()
  185. defer networkMutex.Unlock()
  186. network.NetID = fmt.Sprintf("%d", time.Now().Unix())
  187. if network.AddressRange != "" {
  188. normalizedRange, err := NormalizeCIDR(network.AddressRange)
  189. if err != nil {
  190. return models.Network{}, err
  191. }
  192. network.AddressRange = normalizedRange
  193. }
  194. if network.AddressRange6 != "" {
  195. normalizedRange, err := NormalizeCIDR(network.AddressRange6)
  196. if err != nil {
  197. return models.Network{}, err
  198. }
  199. network.AddressRange6 = normalizedRange
  200. }
  201. if !IsNetworkCIDRUnique(network.GetNetworkNetworkCIDR4(), network.GetNetworkNetworkCIDR6()) {
  202. return models.Network{}, errors.New("network cidr already in use")
  203. }
  204. network.SetDefaults()
  205. network.SetNodesLastModified()
  206. network.SetNetworkLastModified()
  207. network.Name = strings.ReplaceAll(network.Name, " ", "-")
  208. err := ValidateNetwork(&network, false)
  209. if err != nil {
  210. //logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
  211. return models.Network{}, err
  212. }
  213. data, err := json.Marshal(&network)
  214. if err != nil {
  215. return models.Network{}, err
  216. }
  217. if err = database.Insert(network.NetID, string(data), database.NETWORKS_TABLE_NAME); err != nil {
  218. return models.Network{}, err
  219. }
  220. if servercfg.CacheEnabled() {
  221. storeNetworkInCache(network.NetID, network)
  222. }
  223. _, _ = CreateEnrollmentKey(
  224. 0,
  225. time.Time{},
  226. []string{network.NetID},
  227. []string{network.Name},
  228. []models.TagID{},
  229. true,
  230. uuid.Nil,
  231. true,
  232. )
  233. return network, nil
  234. }
  235. // GetNetworkNonServerNodeCount - get number of network non server nodes
  236. func GetNetworkNonServerNodeCount(networkName string) (int, error) {
  237. nodes, err := GetNetworkNodes(networkName)
  238. return len(nodes), err
  239. }
  240. func IsNetworkCIDRUnique(cidr4 *net.IPNet, cidr6 *net.IPNet) bool {
  241. networks, err := GetNetworks()
  242. if err != nil {
  243. return database.IsEmptyRecord(err)
  244. }
  245. for _, network := range networks {
  246. if intersect(network.GetNetworkNetworkCIDR4(), cidr4) ||
  247. intersect(network.GetNetworkNetworkCIDR6(), cidr6) {
  248. return false
  249. }
  250. }
  251. return true
  252. }
  253. func intersect(n1, n2 *net.IPNet) bool {
  254. if n1 == nil || n2 == nil {
  255. return false
  256. }
  257. return n2.Contains(n1.IP) || n1.Contains(n2.IP)
  258. }
  259. // GetParentNetwork - get parent network
  260. func GetParentNetwork(networkname string) (models.Network, error) {
  261. var network models.Network
  262. if servercfg.CacheEnabled() {
  263. if network, ok := getNetworkFromCache(networkname); ok {
  264. return network, nil
  265. }
  266. }
  267. networkData, err := database.FetchRecord(database.NETWORKS_TABLE_NAME, networkname)
  268. if err != nil {
  269. return network, err
  270. }
  271. if err = json.Unmarshal([]byte(networkData), &network); err != nil {
  272. return models.Network{}, err
  273. }
  274. return network, nil
  275. }
  276. // GetNetworkSettings - get parent network
  277. func GetNetworkSettings(networkname string) (models.Network, error) {
  278. var network models.Network
  279. if servercfg.CacheEnabled() {
  280. if network, ok := getNetworkFromCache(networkname); ok {
  281. return network, nil
  282. }
  283. }
  284. networkData, err := database.FetchRecord(database.NETWORKS_TABLE_NAME, networkname)
  285. if err != nil {
  286. return network, err
  287. }
  288. if err = json.Unmarshal([]byte(networkData), &network); err != nil {
  289. return models.Network{}, err
  290. }
  291. return network, nil
  292. }
  293. // UniqueAddress - get a unique ipv4 address
  294. func UniqueAddress(networkName string, reverse bool) (net.IP, error) {
  295. add := net.IP{}
  296. var network models.Network
  297. network, err := GetParentNetwork(networkName)
  298. if err != nil {
  299. logger.Log(0, "UniqueAddressServer encountered an error")
  300. return add, err
  301. }
  302. if network.IsIPv4 == "no" {
  303. return add, fmt.Errorf("IPv4 not active on network " + networkName)
  304. }
  305. //ensure AddressRange is valid
  306. if _, _, err := net.ParseCIDR(network.AddressRange); err != nil {
  307. logger.Log(0, "UniqueAddress encountered an error")
  308. return add, err
  309. }
  310. net4 := iplib.Net4FromStr(network.AddressRange)
  311. newAddrs := net4.FirstAddress()
  312. if reverse {
  313. newAddrs = net4.LastAddress()
  314. }
  315. ipAllocated := allocatedIpMap[networkName]
  316. for {
  317. if _, ok := ipAllocated[newAddrs.String()]; !ok {
  318. return newAddrs, nil
  319. }
  320. if reverse {
  321. newAddrs, err = net4.PreviousIP(newAddrs)
  322. } else {
  323. newAddrs, err = net4.NextIP(newAddrs)
  324. }
  325. if err != nil {
  326. break
  327. }
  328. }
  329. return add, errors.New("ERROR: No unique addresses available. Check network subnet")
  330. }
  331. // IsIPUnique - checks if an IP is unique
  332. func IsIPUnique(network string, ip string, tableName string, isIpv6 bool) bool {
  333. isunique := true
  334. if tableName == database.NODES_TABLE_NAME {
  335. nodes, err := GetNetworkNodes(network)
  336. if err != nil {
  337. return isunique
  338. }
  339. for _, node := range nodes {
  340. if isIpv6 {
  341. if node.Address6.IP.String() == ip && node.Network == network {
  342. return false
  343. }
  344. } else {
  345. if node.Address.IP.String() == ip && node.Network == network {
  346. return false
  347. }
  348. }
  349. }
  350. } else if tableName == database.EXT_CLIENT_TABLE_NAME {
  351. extClients, err := GetNetworkExtClients(network)
  352. if err != nil {
  353. return isunique
  354. }
  355. for _, extClient := range extClients { // filter
  356. if isIpv6 {
  357. if (extClient.Address6 == ip) && extClient.Network == network {
  358. return false
  359. }
  360. } else {
  361. if (extClient.Address == ip) && extClient.Network == network {
  362. return false
  363. }
  364. }
  365. }
  366. }
  367. return isunique
  368. }
  369. // UniqueAddress6 - see if ipv6 address is unique
  370. func UniqueAddress6(networkName string, reverse bool) (net.IP, error) {
  371. add := net.IP{}
  372. var network models.Network
  373. network, err := GetParentNetwork(networkName)
  374. if err != nil {
  375. fmt.Println("Network Not Found")
  376. return add, err
  377. }
  378. if network.IsIPv6 == "no" {
  379. return add, fmt.Errorf("IPv6 not active on network " + networkName)
  380. }
  381. //ensure AddressRange is valid
  382. if _, _, err := net.ParseCIDR(network.AddressRange6); err != nil {
  383. return add, err
  384. }
  385. net6 := iplib.Net6FromStr(network.AddressRange6)
  386. newAddrs, err := net6.NextIP(net6.FirstAddress())
  387. if reverse {
  388. newAddrs, err = net6.PreviousIP(net6.LastAddress())
  389. }
  390. if err != nil {
  391. return add, err
  392. }
  393. ipAllocated := allocatedIpMap[networkName]
  394. for {
  395. if _, ok := ipAllocated[newAddrs.String()]; !ok {
  396. return newAddrs, nil
  397. }
  398. if reverse {
  399. newAddrs, err = net6.PreviousIP(newAddrs)
  400. } else {
  401. newAddrs, err = net6.NextIP(newAddrs)
  402. }
  403. if err != nil {
  404. break
  405. }
  406. }
  407. return add, errors.New("ERROR: No unique IPv6 addresses available. Check network subnet")
  408. }
  409. // IsNetworkNameUnique - checks to see if any other networks have the same name (id)
  410. func IsNetworkNameUnique(network *models.Network) (bool, error) {
  411. isunique := true
  412. dbs, err := GetNetworks()
  413. if err != nil && !database.IsEmptyRecord(err) {
  414. return false, err
  415. }
  416. for i := 0; i < len(dbs); i++ {
  417. if network.Name == dbs[i].Name {
  418. isunique = false
  419. }
  420. }
  421. return isunique, nil
  422. }
  423. // UpdateNetwork - updates a network with another network's fields
  424. func UpdateNetwork(currentNetwork *models.Network, newNetwork *models.Network) (bool, bool, bool, error) {
  425. newNetwork.Name = strings.ReplaceAll(newNetwork.Name, " ", "-")
  426. if err := ValidateNetwork(newNetwork, true); err != nil {
  427. return false, false, false, err
  428. }
  429. if newNetwork.NetID == currentNetwork.NetID {
  430. hasrangeupdate4 := newNetwork.AddressRange != currentNetwork.AddressRange
  431. hasrangeupdate6 := newNetwork.AddressRange6 != currentNetwork.AddressRange6
  432. hasholepunchupdate := newNetwork.DefaultUDPHolePunch != currentNetwork.DefaultUDPHolePunch
  433. newNetwork.SetNetworkLastModified()
  434. data, err := json.Marshal(newNetwork)
  435. if err != nil {
  436. return false, false, false, err
  437. }
  438. err = database.Insert(newNetwork.NetID, string(data), database.NETWORKS_TABLE_NAME)
  439. if err == nil {
  440. if servercfg.CacheEnabled() {
  441. storeNetworkInCache(newNetwork.NetID, *newNetwork)
  442. }
  443. }
  444. return hasrangeupdate4, hasrangeupdate6, hasholepunchupdate, err
  445. }
  446. // copy values
  447. return false, false, false, errors.New("failed to update network " + newNetwork.NetID + ", cannot change netid.")
  448. }
  449. func UpsertNetwork(net *models.Network) error {
  450. net.SetNetworkLastModified()
  451. data, err := json.Marshal(net)
  452. if err != nil {
  453. return err
  454. }
  455. err = database.Insert(net.NetID, string(data), database.NETWORKS_TABLE_NAME)
  456. if err == nil {
  457. if servercfg.CacheEnabled() {
  458. storeNetworkInCache(net.NetID, *net)
  459. }
  460. }
  461. return nil
  462. }
  463. func GetNetworkByName(name string) (network models.Network, err error) {
  464. networksData, err := database.FetchRecords(database.NETWORKS_TABLE_NAME)
  465. if err != nil {
  466. return network, err
  467. }
  468. for _, networkData := range networksData {
  469. if err = json.Unmarshal([]byte(networkData), &network); err != nil {
  470. return models.Network{}, err
  471. }
  472. if network.Name == name {
  473. return network, nil
  474. }
  475. }
  476. return network, errors.New("network not found")
  477. }
  478. // GetNetwork - gets a network from database
  479. func GetNetwork(networkID string) (models.Network, error) {
  480. var network models.Network
  481. if servercfg.CacheEnabled() {
  482. if network, ok := getNetworkFromCache(networkID); ok {
  483. return network, nil
  484. }
  485. }
  486. networkData, err := database.FetchRecord(database.NETWORKS_TABLE_NAME, networkID)
  487. if err != nil {
  488. return network, err
  489. }
  490. if err = json.Unmarshal([]byte(networkData), &network); err != nil {
  491. return models.Network{}, err
  492. }
  493. return network, nil
  494. }
  495. // IsNetworkNameValid - checks if a netid of a network uses valid characters
  496. func IsNetworkNameValid(network *models.Network) bool {
  497. re := regexp.MustCompile(`^[A-Za-z0-9-]+$`)
  498. return re.MatchString(network.Name)
  499. }
  500. // Validate - validates fields of an network struct
  501. func ValidateNetwork(network *models.Network, isUpdate bool) error {
  502. v := validator.New()
  503. isFieldUnique, _ := IsNetworkNameUnique(network)
  504. if !isFieldUnique {
  505. return errors.New("duplicate network name")
  506. }
  507. if !IsNetworkNameValid(network) {
  508. return errors.New("invalid input. Only uppercase letters (A-Z), lowercase letters (a-z), numbers (0-9), and the minus sign (-) are allowed")
  509. }
  510. _ = v.RegisterValidation("checkyesorno", func(fl validator.FieldLevel) bool {
  511. return validation.CheckYesOrNo(fl)
  512. })
  513. err := v.Struct(network)
  514. if err != nil {
  515. for _, e := range err.(validator.ValidationErrors) {
  516. fmt.Println(e)
  517. }
  518. }
  519. return err
  520. }
  521. // SaveNetwork - save network struct to database
  522. func SaveNetwork(network *models.Network) error {
  523. data, err := json.Marshal(network)
  524. if err != nil {
  525. return err
  526. }
  527. if err := database.Insert(network.NetID, string(data), database.NETWORKS_TABLE_NAME); err != nil {
  528. return err
  529. }
  530. if servercfg.CacheEnabled() {
  531. storeNetworkInCache(network.NetID, *network)
  532. }
  533. return nil
  534. }
  535. // NetworkExists - check if network exists
  536. func NetworkExists(name string) (bool, error) {
  537. var network string
  538. var err error
  539. if servercfg.CacheEnabled() {
  540. if _, ok := getNetworkFromCache(name); ok {
  541. return ok, nil
  542. }
  543. }
  544. if network, err = database.FetchRecord(database.NETWORKS_TABLE_NAME, name); err != nil {
  545. return false, err
  546. }
  547. return len(network) > 0, nil
  548. }
  549. // SortNetworks - Sorts slice of Networks by their NetID alphabetically with numbers first
  550. func SortNetworks(unsortedNetworks []models.Network) {
  551. sort.Slice(unsortedNetworks, func(i, j int) bool {
  552. return unsortedNetworks[i].NetID < unsortedNetworks[j].NetID
  553. })
  554. }
  555. // == Private ==
  556. var addressLock = &sync.Mutex{}