common.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431
  1. package functions
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "log"
  9. "net"
  10. "net/http"
  11. "os"
  12. "path/filepath"
  13. "strconv"
  14. "strings"
  15. "time"
  16. "github.com/gravitl/netmaker/logger"
  17. "github.com/gravitl/netmaker/models"
  18. "github.com/gravitl/netmaker/netclient/config"
  19. "github.com/gravitl/netmaker/netclient/daemon"
  20. "github.com/gravitl/netmaker/netclient/local"
  21. "github.com/gravitl/netmaker/netclient/ncutils"
  22. "github.com/gravitl/netmaker/netclient/wireguard"
  23. "github.com/gravitl/netmaker/nm-proxy/manager"
  24. "golang.zx2c4.com/wireguard/wgctrl"
  25. )
  26. // LINUX_APP_DATA_PATH - linux path
  27. const LINUX_APP_DATA_PATH = "/etc/netmaker"
  28. // HTTP_TIMEOUT - timeout in seconds for http requests
  29. const HTTP_TIMEOUT = 30
  30. // HTTPClient - http client to be reused by all
  31. var HTTPClient http.Client
  32. // SetHTTPClient -sets http client with sane default
  33. func SetHTTPClient() {
  34. HTTPClient = http.Client{
  35. Timeout: HTTP_TIMEOUT * time.Second,
  36. }
  37. }
  38. // ListPorts - lists ports of WireGuard devices
  39. func ListPorts() error {
  40. wgclient, err := wgctrl.New()
  41. if err != nil {
  42. return err
  43. }
  44. defer wgclient.Close()
  45. devices, err := wgclient.Devices()
  46. if err != nil {
  47. return err
  48. }
  49. fmt.Println("Here are your ports:")
  50. for _, i := range devices {
  51. fmt.Println(i.ListenPort)
  52. }
  53. return err
  54. }
  55. func getPrivateAddr() (string, error) {
  56. var local string
  57. conn, err := net.Dial("udp", "8.8.8.8:80")
  58. if err == nil {
  59. defer conn.Close()
  60. localAddr := conn.LocalAddr().(*net.UDPAddr)
  61. localIP := localAddr.IP
  62. local = localIP.String()
  63. }
  64. if local == "" {
  65. local, err = getPrivateAddrBackup()
  66. }
  67. if local == "" {
  68. err = errors.New("could not find local ip")
  69. }
  70. if net.ParseIP(local).To16() != nil {
  71. local = "[" + local + "]"
  72. }
  73. return local, err
  74. }
  75. func getPrivateAddrBackup() (string, error) {
  76. ifaces, err := net.Interfaces()
  77. if err != nil {
  78. return "", err
  79. }
  80. var local string
  81. found := false
  82. for _, i := range ifaces {
  83. if i.Flags&net.FlagUp == 0 {
  84. continue // interface down
  85. }
  86. if i.Flags&net.FlagLoopback != 0 {
  87. continue // loopback interface
  88. }
  89. addrs, err := i.Addrs()
  90. if err != nil {
  91. return "", err
  92. }
  93. for _, addr := range addrs {
  94. var ip net.IP
  95. switch v := addr.(type) {
  96. case *net.IPNet:
  97. if !found {
  98. ip = v.IP
  99. local = ip.String()
  100. found = true
  101. }
  102. case *net.IPAddr:
  103. if !found {
  104. ip = v.IP
  105. local = ip.String()
  106. found = true
  107. }
  108. }
  109. }
  110. }
  111. if !found {
  112. err := errors.New("local ip address not found")
  113. return "", err
  114. }
  115. return local, err
  116. }
  117. func getInterfaces() (*[]models.Iface, error) {
  118. ifaces, err := net.Interfaces()
  119. if err != nil {
  120. return nil, err
  121. }
  122. var data []models.Iface
  123. var link models.Iface
  124. for _, iface := range ifaces {
  125. if iface.Flags&net.FlagUp == 0 {
  126. continue // interface down
  127. }
  128. if iface.Flags&net.FlagLoopback != 0 {
  129. continue // loopback interface
  130. }
  131. addrs, err := iface.Addrs()
  132. if err != nil {
  133. return nil, err
  134. }
  135. for _, addr := range addrs {
  136. link.Name = iface.Name
  137. _, cidr, err := net.ParseCIDR(addr.String())
  138. if err != nil {
  139. continue
  140. }
  141. link.Address = *cidr
  142. data = append(data, link)
  143. }
  144. }
  145. return &data, nil
  146. }
  147. // GetNode - gets node locally
  148. func GetNode(network string) models.LegacyNode {
  149. modcfg, err := config.ReadConfig(network)
  150. if err != nil {
  151. log.Fatalf("Error: %v", err)
  152. }
  153. return modcfg.Node
  154. }
  155. // Uninstall - uninstalls networks from client
  156. func Uninstall() error {
  157. networks, err := ncutils.GetSystemNetworks()
  158. if err != nil {
  159. logger.Log(1, "unable to retrieve networks: ", err.Error())
  160. logger.Log(1, "continuing uninstall without leaving networks")
  161. } else {
  162. for _, network := range networks {
  163. err = LeaveNetwork(network)
  164. if err != nil {
  165. logger.Log(1, "encounter issue leaving network", network, ":", err.Error())
  166. }
  167. }
  168. }
  169. err = nil
  170. // clean up OS specific stuff
  171. if ncutils.IsWindows() {
  172. daemon.CleanupWindows()
  173. } else if ncutils.IsMac() {
  174. daemon.CleanupMac()
  175. } else if ncutils.IsLinux() {
  176. daemon.CleanupLinux()
  177. } else if ncutils.IsFreeBSD() {
  178. daemon.CleanupFreebsd()
  179. } else if !ncutils.IsKernel() {
  180. logger.Log(1, "manual cleanup required")
  181. }
  182. return err
  183. }
  184. // LeaveNetwork - client exits a network
  185. func LeaveNetwork(network string) error {
  186. cfg, err := config.ReadConfig(network)
  187. if err != nil {
  188. return err
  189. }
  190. logger.Log(2, "deleting node from server")
  191. if err := deleteNodeFromServer(cfg); err != nil {
  192. logger.Log(0, "error deleting node from server", err.Error())
  193. }
  194. logger.Log(2, "deleting wireguard interface")
  195. if err := deleteLocalNetwork(cfg); err != nil {
  196. logger.Log(0, "error deleting wireguard interface", err.Error())
  197. }
  198. logger.Log(2, "deleting configuration files")
  199. if err := WipeLocal(cfg); err != nil {
  200. logger.Log(0, "error deleting local network files", err.Error())
  201. }
  202. logger.Log(2, "removing dns entries")
  203. if err := removeHostDNS(cfg.Node.Interface, ncutils.IsWindows()); err != nil {
  204. logger.Log(0, "failed to delete dns entries for", cfg.Node.Interface, err.Error())
  205. }
  206. ProxyMgmChan <- &manager.ManagerAction{
  207. Action: manager.DeleteInterface,
  208. Payload: manager.ManagerPayload{
  209. InterfaceName: cfg.Node.Interface,
  210. },
  211. }
  212. logger.Log(2, "restarting daemon")
  213. return daemon.Restart()
  214. }
  215. func deleteNodeFromServer(cfg *config.ClientConfig) error {
  216. node := cfg.Node
  217. if node.IsServer == "yes" {
  218. return errors.New("attempt to delete server node ... not permitted")
  219. }
  220. token, err := Authenticate(cfg)
  221. if err != nil {
  222. return fmt.Errorf("unable to authenticate %w", err)
  223. }
  224. url := "https://" + cfg.Server.API + "/api/nodes/" + cfg.Network + "/" + cfg.Node.ID
  225. response, err := API("", http.MethodDelete, url, token)
  226. if err != nil {
  227. return fmt.Errorf("error deleting node on server: %w", err)
  228. }
  229. if response.StatusCode != http.StatusOK {
  230. bodybytes, _ := io.ReadAll(response.Body)
  231. defer response.Body.Close()
  232. return fmt.Errorf("error deleting node from network %s on server %s %s", cfg.Network, response.Status, string(bodybytes))
  233. }
  234. return nil
  235. }
  236. func deleteLocalNetwork(cfg *config.ClientConfig) error {
  237. wgClient, wgErr := wgctrl.New()
  238. if wgErr != nil {
  239. return wgErr
  240. }
  241. removeIface := cfg.Node.Interface
  242. queryAddr := cfg.Node.PrimaryAddress()
  243. if ncutils.IsMac() {
  244. var macIface string
  245. macIface, wgErr = local.GetMacIface(queryAddr)
  246. if wgErr == nil && removeIface != "" {
  247. removeIface = macIface
  248. }
  249. }
  250. dev, devErr := wgClient.Device(removeIface)
  251. if devErr != nil {
  252. return fmt.Errorf("error flushing routes %w", devErr)
  253. }
  254. local.FlushPeerRoutes(removeIface, queryAddr, dev.Peers[:])
  255. _, cidr, cidrErr := net.ParseCIDR(cfg.NetworkSettings.AddressRange)
  256. if cidrErr != nil {
  257. return fmt.Errorf("error flushing routes %w", cidrErr)
  258. }
  259. local.RemoveCIDRRoute(removeIface, queryAddr, cidr)
  260. return nil
  261. }
  262. // DeleteInterface - delete an interface of a network
  263. func DeleteInterface(ifacename string, postdown string) error {
  264. return wireguard.RemoveConf(ifacename, true)
  265. }
  266. // WipeLocal - wipes local instance
  267. func WipeLocal(cfg *config.ClientConfig) error {
  268. if err := wireguard.RemoveConf(cfg.Node.Interface, true); err == nil {
  269. logger.Log(1, "network:", cfg.Node.Network, "removed WireGuard interface: ", cfg.Node.Interface)
  270. } else if strings.Contains(err.Error(), "does not exist") {
  271. err = nil
  272. }
  273. dir := ncutils.GetNetclientPathSpecific()
  274. fail := false
  275. files, err := filepath.Glob(dir + "*" + cfg.Node.Network)
  276. if err != nil {
  277. logger.Log(0, "no matching files", err.Error())
  278. fail = true
  279. }
  280. for _, file := range files {
  281. if err := os.Remove(file); err != nil {
  282. logger.Log(0, "failed to delete file", file, err.Error())
  283. fail = true
  284. }
  285. }
  286. if cfg.Node.Interface != "" {
  287. if ncutils.FileExists(dir + cfg.Node.Interface + ".conf") {
  288. if err := os.Remove(dir + cfg.Node.Interface + ".conf"); err != nil {
  289. logger.Log(0, err.Error())
  290. fail = true
  291. }
  292. }
  293. }
  294. if fail {
  295. return errors.New("not all files were deleted")
  296. }
  297. return nil
  298. }
  299. // GetNetmakerPath - gets netmaker path locally
  300. func GetNetmakerPath() string {
  301. return LINUX_APP_DATA_PATH
  302. }
  303. // API function to interact with netmaker api endpoints. response from endpoint is returned
  304. func API(data any, method, url, authorization string) (*http.Response, error) {
  305. var request *http.Request
  306. var err error
  307. if data != "" {
  308. payload, err := json.Marshal(data)
  309. if err != nil {
  310. return nil, fmt.Errorf("error encoding data %w", err)
  311. }
  312. request, err = http.NewRequest(method, url, bytes.NewBuffer(payload))
  313. if err != nil {
  314. return nil, fmt.Errorf("error creating http request %w", err)
  315. }
  316. request.Header.Set("Content-Type", "application/json")
  317. } else {
  318. request, err = http.NewRequest(method, url, nil)
  319. if err != nil {
  320. return nil, fmt.Errorf("error creating http request %w", err)
  321. }
  322. }
  323. if authorization != "" {
  324. request.Header.Set("authorization", "Bearer "+authorization)
  325. }
  326. request.Header.Set("requestfrom", "node")
  327. return HTTPClient.Do(request)
  328. }
  329. // Authenticate authenticates with api to permit subsequent interactions with the api
  330. func Authenticate(cfg *config.ClientConfig) (string, error) {
  331. pass, err := os.ReadFile(ncutils.GetNetclientPathSpecific() + "secret-" + cfg.Network)
  332. if err != nil {
  333. return "", fmt.Errorf("could not read secrets file %w", err)
  334. }
  335. data := models.AuthParams{
  336. MacAddress: cfg.Node.MacAddress,
  337. ID: cfg.Node.ID,
  338. Password: string(pass),
  339. }
  340. url := "https://" + cfg.Server.API + "/api/nodes/adm/" + cfg.Network + "/authenticate"
  341. response, err := API(data, http.MethodPost, url, "")
  342. if err != nil {
  343. return "", err
  344. }
  345. defer response.Body.Close()
  346. if response.StatusCode != http.StatusOK {
  347. bodybytes, _ := io.ReadAll(response.Body)
  348. return "", fmt.Errorf("failed to authenticate %s %s", response.Status, string(bodybytes))
  349. }
  350. resp := models.SuccessResponse{}
  351. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  352. return "", fmt.Errorf("error decoding respone %w", err)
  353. }
  354. tokenData := resp.Response.(map[string]interface{})
  355. token := tokenData["AuthToken"]
  356. return token.(string), nil
  357. }
  358. // RegisterWithServer calls the register endpoint with privatekey and commonname - api returns ca and client certificate
  359. func SetServerInfo(cfg *config.ClientConfig) error {
  360. cfg, err := config.ReadConfig(cfg.Network)
  361. if err != nil {
  362. return err
  363. }
  364. url := "https://" + cfg.Server.API + "/api/server/getserverinfo"
  365. logger.Log(1, "server at "+url)
  366. token, err := Authenticate(cfg)
  367. if err != nil {
  368. return err
  369. }
  370. response, err := API("", http.MethodGet, url, token)
  371. if err != nil {
  372. return err
  373. }
  374. if response.StatusCode != http.StatusOK {
  375. return errors.New(response.Status)
  376. }
  377. var resp models.ServerConfig
  378. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  379. return errors.New("unmarshal cert error " + err.Error())
  380. }
  381. // set broker information on register
  382. cfg.Server.Server = resp.Server
  383. cfg.Server.MQPort = resp.MQPort
  384. if err = config.ModServerConfig(&cfg.Server, cfg.Node.Network); err != nil {
  385. logger.Log(0, "error overwriting config with broker information: "+err.Error())
  386. }
  387. return nil
  388. }
  389. func informPortChange(node *models.LegacyNode) {
  390. if node.ListenPort == 0 {
  391. logger.Log(0, "network:", node.Network, "UDP hole punching enabled for node", node.Name)
  392. } else {
  393. logger.Log(0, "network:", node.Network, "node", node.Name, "is using port", strconv.Itoa(int(node.ListenPort)))
  394. }
  395. }