mqhandlers.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368
  1. package functions
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "fmt"
  6. "net"
  7. "os"
  8. "runtime"
  9. "strings"
  10. "time"
  11. mqtt "github.com/eclipse/paho.mqtt.golang"
  12. "github.com/gravitl/netmaker/logger"
  13. "github.com/gravitl/netmaker/models"
  14. "github.com/gravitl/netmaker/netclient/config"
  15. "github.com/gravitl/netmaker/netclient/local"
  16. "github.com/gravitl/netmaker/netclient/ncutils"
  17. "github.com/gravitl/netmaker/netclient/wireguard"
  18. "github.com/gravitl/netmaker/nm-proxy/manager"
  19. "github.com/guumaster/hostctl/pkg/file"
  20. "github.com/guumaster/hostctl/pkg/parser"
  21. "github.com/guumaster/hostctl/pkg/types"
  22. "golang.zx2c4.com/wireguard/wgctrl/wgtypes"
  23. )
  24. // All -- mqtt message hander for all ('#') topics
  25. var All mqtt.MessageHandler = func(client mqtt.Client, msg mqtt.Message) {
  26. logger.Log(0, "default message handler -- received message but not handling")
  27. logger.Log(0, "topic: "+string(msg.Topic()))
  28. //logger.Log(0, "Message: " + string(msg.Payload()))
  29. }
  30. func ProxyUpdate(client mqtt.Client, msg mqtt.Message) {
  31. var nodeCfg config.ClientConfig
  32. var proxyUpdate manager.ManagerAction
  33. var network = strings.Split(msg.Topic(), "/")[2]
  34. nodeCfg.Network = network
  35. nodeCfg.ReadConfig()
  36. data, dataErr := decryptMsg(&nodeCfg, msg.Payload())
  37. if dataErr != nil {
  38. return
  39. }
  40. err := json.Unmarshal([]byte(data), &proxyUpdate)
  41. if err != nil {
  42. logger.Log(0, "error unmarshalling node update data"+err.Error())
  43. return
  44. }
  45. logger.Log(0, "---------> recieved a proxy update")
  46. ProxyMgmChan <- &proxyUpdate
  47. }
  48. // NodeUpdate -- mqtt message handler for /update/<NodeID> topic
  49. func NodeUpdate(client mqtt.Client, msg mqtt.Message) {
  50. var newNode models.Node
  51. var nodeCfg config.ClientConfig
  52. var network = parseNetworkFromTopic(msg.Topic())
  53. nodeCfg.Network = network
  54. nodeCfg.ReadConfig()
  55. data, dataErr := decryptMsg(&nodeCfg, msg.Payload())
  56. if dataErr != nil {
  57. return
  58. }
  59. err := json.Unmarshal([]byte(data), &newNode)
  60. if err != nil {
  61. logger.Log(0, "error unmarshalling node update data"+err.Error())
  62. return
  63. }
  64. // see if cache hit, if so skip
  65. var currentMessage = read(newNode.Network, lastNodeUpdate)
  66. if currentMessage == string(data) {
  67. return
  68. }
  69. insert(newNode.Network, lastNodeUpdate, string(data)) // store new message in cache
  70. logger.Log(0, "network:", newNode.Network, "received message to update node "+newNode.Name)
  71. // ensure that OS never changes
  72. newNode.OS = runtime.GOOS
  73. // check if interface needs to delta
  74. ifaceDelta := ncutils.IfaceDelta(&nodeCfg.Node, &newNode)
  75. shouldDNSChange := nodeCfg.Node.DNSOn != newNode.DNSOn
  76. hubChange := nodeCfg.Node.IsHub != newNode.IsHub
  77. keepaliveChange := nodeCfg.Node.PersistentKeepalive != newNode.PersistentKeepalive
  78. nodeCfg.Node = newNode
  79. switch newNode.Action {
  80. case models.NODE_DELETE:
  81. logger.Log(0, "network:", nodeCfg.Node.Network, " received delete request for %s", nodeCfg.Node.Name)
  82. unsubscribeNode(client, &nodeCfg)
  83. if err = LeaveNetwork(nodeCfg.Node.Network); err != nil {
  84. if !strings.Contains("rpc error", err.Error()) {
  85. logger.Log(0, "failed to leave, please check that local files for network", nodeCfg.Node.Network, "were removed")
  86. return
  87. }
  88. }
  89. logger.Log(0, nodeCfg.Node.Name, "was removed from network", nodeCfg.Node.Network)
  90. return
  91. case models.NODE_UPDATE_KEY:
  92. // == get the current key for node ==
  93. oldPrivateKey, retErr := wireguard.RetrievePrivKey(nodeCfg.Network)
  94. if retErr != nil {
  95. break
  96. }
  97. if err := UpdateKeys(&nodeCfg, client); err != nil {
  98. logger.Log(0, "err updating wireguard keys, reusing last key\n", err.Error())
  99. if key, parseErr := wgtypes.ParseKey(oldPrivateKey); parseErr == nil {
  100. wireguard.StorePrivKey(key.String(), nodeCfg.Network)
  101. nodeCfg.Node.PublicKey = key.PublicKey().String()
  102. }
  103. }
  104. ifaceDelta = true
  105. case models.NODE_FORCE_UPDATE:
  106. ifaceDelta = true
  107. case models.NODE_NOOP:
  108. default:
  109. }
  110. // Save new config
  111. nodeCfg.Node.Action = models.NODE_NOOP
  112. if err := config.Write(&nodeCfg, nodeCfg.Network); err != nil {
  113. logger.Log(0, nodeCfg.Node.Network, "error updating node configuration: ", err.Error())
  114. }
  115. nameserver := nodeCfg.Server.CoreDNSAddr
  116. privateKey, err := wireguard.RetrievePrivKey(newNode.Network)
  117. if err != nil {
  118. logger.Log(0, "error reading PrivateKey "+err.Error())
  119. return
  120. }
  121. file := ncutils.GetNetclientPathSpecific() + nodeCfg.Node.Interface + ".conf"
  122. if newNode.ListenPort != nodeCfg.Node.LocalListenPort {
  123. if err := wireguard.RemoveConf(newNode.Interface, false); err != nil {
  124. logger.Log(0, "error remove interface", newNode.Interface, err.Error())
  125. }
  126. err = ncutils.ModPort(&newNode)
  127. if err != nil {
  128. logger.Log(0, "network:", nodeCfg.Node.Network, "error modifying node port on", newNode.Name, "-", err.Error())
  129. return
  130. }
  131. ifaceDelta = true
  132. informPortChange(&newNode)
  133. }
  134. if err := wireguard.UpdateWgInterface(file, privateKey, nameserver, newNode); err != nil {
  135. logger.Log(0, "error updating wireguard config "+err.Error())
  136. return
  137. }
  138. if keepaliveChange {
  139. wireguard.UpdateKeepAlive(file, newNode.PersistentKeepalive)
  140. }
  141. logger.Log(0, "applying WG conf to "+file)
  142. err = wireguard.ApplyConf(&nodeCfg.Node, nodeCfg.Node.Interface, file)
  143. if err != nil {
  144. logger.Log(0, "error restarting wg after node update -", err.Error())
  145. return
  146. }
  147. time.Sleep(time.Second)
  148. // if newNode.DNSOn == "yes" {
  149. // for _, server := range newNode.NetworkSettings.DefaultServerAddrs {
  150. // if server.IsLeader {
  151. // go local.SetDNSWithRetry(newNode, server.Address)
  152. // break
  153. // }
  154. // }
  155. // }
  156. ProxyMgmChan <- &manager.ManagerAction{
  157. Action: manager.AddInterface,
  158. Payload: manager.ManagerPayload{
  159. IsRelayed: newNode.IsRelay == "yes",
  160. },
  161. }
  162. if ifaceDelta { // if a change caused an ifacedelta we need to notify the server to update the peers
  163. doneErr := publishSignal(&nodeCfg, ncutils.DONE)
  164. if doneErr != nil {
  165. logger.Log(0, "network:", nodeCfg.Node.Network, "could not notify server to update peers after interface change")
  166. } else {
  167. logger.Log(0, "network:", nodeCfg.Node.Network, "signalled finished interface update to server")
  168. }
  169. } else if hubChange {
  170. doneErr := publishSignal(&nodeCfg, ncutils.DONE)
  171. if doneErr != nil {
  172. logger.Log(0, "network:", nodeCfg.Node.Network, "could not notify server to update peers after hub change")
  173. } else {
  174. logger.Log(0, "network:", nodeCfg.Node.Network, "signalled finished hub update to server")
  175. }
  176. }
  177. //deal with DNS
  178. if newNode.DNSOn != "yes" && shouldDNSChange && nodeCfg.Node.Interface != "" {
  179. logger.Log(0, "network:", nodeCfg.Node.Network, "settng DNS off")
  180. if err := removeHostDNS(nodeCfg.Node.Interface, ncutils.IsWindows()); err != nil {
  181. logger.Log(0, "network:", nodeCfg.Node.Network, "error removing netmaker profile from /etc/hosts "+err.Error())
  182. }
  183. // _, err := ncutils.RunCmd("/usr/bin/resolvectl revert "+nodeCfg.Node.Interface, true)
  184. // if err != nil {
  185. // logger.Log(0, "error applying dns" + err.Error())
  186. // }
  187. }
  188. _ = UpdateLocalListenPort(&nodeCfg)
  189. }
  190. // UpdatePeers -- mqtt message handler for peers/<Network>/<NodeID> topic
  191. func UpdatePeers(client mqtt.Client, msg mqtt.Message) {
  192. var peerUpdate models.PeerUpdate
  193. var network = parseNetworkFromTopic(msg.Topic())
  194. var cfg = config.ClientConfig{}
  195. cfg.Network = network
  196. cfg.ReadConfig()
  197. data, dataErr := decryptMsg(&cfg, msg.Payload())
  198. if dataErr != nil {
  199. return
  200. }
  201. err := json.Unmarshal([]byte(data), &peerUpdate)
  202. if err != nil {
  203. logger.Log(0, "error unmarshalling peer data")
  204. return
  205. }
  206. // see if cached hit, if so skip
  207. var currentMessage = read(peerUpdate.Network, lastPeerUpdate)
  208. if currentMessage == string(data) {
  209. return
  210. }
  211. insert(peerUpdate.Network, lastPeerUpdate, string(data))
  212. // check version
  213. if peerUpdate.ServerVersion != ncutils.Version {
  214. logger.Log(0, "server/client version mismatch server: ", peerUpdate.ServerVersion, " client: ", ncutils.Version)
  215. }
  216. if peerUpdate.ServerVersion != cfg.Server.Version {
  217. logger.Log(1, "updating server version")
  218. cfg.Server.Version = peerUpdate.ServerVersion
  219. config.Write(&cfg, cfg.Network)
  220. }
  221. file := ncutils.GetNetclientPathSpecific() + cfg.Node.Interface + ".conf"
  222. internetGateway, err := wireguard.UpdateWgPeers(file, peerUpdate.Peers)
  223. if err != nil {
  224. logger.Log(0, "error updating wireguard peers"+err.Error())
  225. return
  226. }
  227. //check if internet gateway has changed
  228. oldGateway, err := net.ResolveUDPAddr("udp", cfg.Node.InternetGateway)
  229. // note: may want to remove second part (oldGateway == &net.UDPAddr{})
  230. // since it's a pointer, will never be true
  231. if err != nil || (oldGateway == &net.UDPAddr{}) {
  232. oldGateway = nil
  233. }
  234. if (internetGateway == nil && oldGateway != nil) || (internetGateway != nil && internetGateway.String() != oldGateway.String()) {
  235. cfg.Node.InternetGateway = internetGateway.String()
  236. if err := config.ModNodeConfig(&cfg.Node); err != nil {
  237. logger.Log(0, "failed to save internet gateway", err.Error())
  238. }
  239. if err := wireguard.ApplyConf(&cfg.Node, cfg.Node.Interface, file); err != nil {
  240. logger.Log(0, "error applying internet gateway", err.Error())
  241. }
  242. UpdateLocalListenPort(&cfg)
  243. return
  244. }
  245. queryAddr := cfg.Node.PrimaryAddress()
  246. //err = wireguard.SyncWGQuickConf(cfg.Node.Interface, file)
  247. var iface = cfg.Node.Interface
  248. if ncutils.IsMac() {
  249. iface, err = local.GetMacIface(queryAddr)
  250. if err != nil {
  251. logger.Log(0, "error retrieving mac iface: "+err.Error())
  252. return
  253. }
  254. }
  255. err = wireguard.SetPeers(iface, &cfg.Node, peerUpdate.Peers)
  256. if err != nil {
  257. logger.Log(0, "error syncing wg after peer update: "+err.Error())
  258. return
  259. }
  260. ProxyMgmChan <- &manager.ManagerAction{
  261. Action: manager.AddInterface,
  262. Payload: manager.ManagerPayload{
  263. InterfaceName: cfg.Node.Interface,
  264. Peers: peerUpdate.Peers,
  265. IsRelayed: peerUpdate.IsRelayed,
  266. RelayedTo: peerUpdate.RelayTo,
  267. },
  268. }
  269. logger.Log(0, "network:", cfg.Node.Network, "received peer update for node "+cfg.Node.Name+" "+cfg.Node.Network)
  270. if cfg.Node.DNSOn == "yes" {
  271. if err := setHostDNS(peerUpdate.DNS, cfg.Node.Interface, ncutils.IsWindows()); err != nil {
  272. logger.Log(0, "network:", cfg.Node.Network, "error updating /etc/hosts "+err.Error())
  273. return
  274. }
  275. } else {
  276. if err := removeHostDNS(cfg.Node.Interface, ncutils.IsWindows()); err != nil {
  277. logger.Log(0, "network:", cfg.Node.Network, "error removing profile from /etc/hosts "+err.Error())
  278. return
  279. }
  280. }
  281. _ = UpdateLocalListenPort(&cfg)
  282. }
  283. func setHostDNS(dns, iface string, windows bool) error {
  284. etchosts := "/etc/hosts"
  285. temp := os.TempDir()
  286. lockfile := temp + "/netclient-lock"
  287. if windows {
  288. etchosts = "c:\\windows\\system32\\drivers\\etc\\hosts"
  289. lockfile = temp + "\\netclient-lock"
  290. }
  291. if _, err := os.Stat(lockfile); !errors.Is(err, os.ErrNotExist) {
  292. return errors.New("/etc/hosts file is locked .... aborting")
  293. }
  294. lock, err := os.Create(lockfile)
  295. if err != nil {
  296. return fmt.Errorf("could not create lock file %w", err)
  297. }
  298. lock.Close()
  299. defer os.Remove(lockfile)
  300. dnsdata := strings.NewReader(dns)
  301. profile, err := parser.ParseProfile(dnsdata)
  302. if err != nil {
  303. return err
  304. }
  305. hosts, err := file.NewFile(etchosts)
  306. if err != nil {
  307. return err
  308. }
  309. profile.Name = strings.ToLower(iface)
  310. profile.Status = types.Enabled
  311. if err := hosts.ReplaceProfile(profile); err != nil {
  312. return err
  313. }
  314. if err := hosts.Flush(); err != nil {
  315. return err
  316. }
  317. return nil
  318. }
  319. func removeHostDNS(iface string, windows bool) error {
  320. etchosts := "/etc/hosts"
  321. temp := os.TempDir()
  322. lockfile := temp + "/netclient-lock"
  323. if windows {
  324. etchosts = "c:\\windows\\system32\\drivers\\etc\\hosts"
  325. lockfile = temp + "\\netclient-lock"
  326. }
  327. if _, err := os.Stat(lockfile); !errors.Is(err, os.ErrNotExist) {
  328. return errors.New("/etc/hosts file is locked .... aborting")
  329. }
  330. lock, err := os.Create(lockfile)
  331. if err != nil {
  332. return fmt.Errorf("could not create lock file %w", err)
  333. }
  334. lock.Close()
  335. defer os.Remove(lockfile)
  336. hosts, err := file.NewFile(etchosts)
  337. if err != nil {
  338. return err
  339. }
  340. if err := hosts.RemoveProfile(strings.ToLower(iface)); err != nil {
  341. if err == types.ErrUnknownProfile {
  342. return nil
  343. }
  344. return err
  345. }
  346. if err := hosts.Flush(); err != nil {
  347. return err
  348. }
  349. return nil
  350. }