common.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426
  1. package functions
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "log"
  9. "net"
  10. "net/http"
  11. "os"
  12. "strconv"
  13. "strings"
  14. "time"
  15. "github.com/gravitl/netmaker/logger"
  16. "github.com/gravitl/netmaker/models"
  17. "github.com/gravitl/netmaker/netclient/config"
  18. "github.com/gravitl/netmaker/netclient/daemon"
  19. "github.com/gravitl/netmaker/netclient/local"
  20. "github.com/gravitl/netmaker/netclient/ncutils"
  21. "github.com/gravitl/netmaker/netclient/wireguard"
  22. "golang.zx2c4.com/wireguard/wgctrl"
  23. )
  24. // LINUX_APP_DATA_PATH - linux path
  25. const LINUX_APP_DATA_PATH = "/etc/netmaker"
  26. // HTTP_TIMEOUT - timeout in seconds for http requests
  27. const HTTP_TIMEOUT = 30
  28. // ListPorts - lists ports of WireGuard devices
  29. func ListPorts() error {
  30. wgclient, err := wgctrl.New()
  31. if err != nil {
  32. return err
  33. }
  34. defer wgclient.Close()
  35. devices, err := wgclient.Devices()
  36. if err != nil {
  37. return err
  38. }
  39. fmt.Println("Here are your ports:")
  40. for _, i := range devices {
  41. fmt.Println(i.ListenPort)
  42. }
  43. return err
  44. }
  45. func getPrivateAddr() (string, error) {
  46. var local string
  47. conn, err := net.Dial("udp", "8.8.8.8:80")
  48. if err == nil {
  49. defer conn.Close()
  50. localAddr := conn.LocalAddr().(*net.UDPAddr)
  51. localIP := localAddr.IP
  52. local = localIP.String()
  53. }
  54. if local == "" {
  55. local, err = getPrivateAddrBackup()
  56. }
  57. if local == "" {
  58. err = errors.New("could not find local ip")
  59. }
  60. return local, err
  61. }
  62. func getPrivateAddrBackup() (string, error) {
  63. ifaces, err := net.Interfaces()
  64. if err != nil {
  65. return "", err
  66. }
  67. var local string
  68. found := false
  69. for _, i := range ifaces {
  70. if i.Flags&net.FlagUp == 0 {
  71. continue // interface down
  72. }
  73. if i.Flags&net.FlagLoopback != 0 {
  74. continue // loopback interface
  75. }
  76. addrs, err := i.Addrs()
  77. if err != nil {
  78. return "", err
  79. }
  80. for _, addr := range addrs {
  81. var ip net.IP
  82. switch v := addr.(type) {
  83. case *net.IPNet:
  84. if !found {
  85. ip = v.IP
  86. local = ip.String()
  87. found = true
  88. }
  89. case *net.IPAddr:
  90. if !found {
  91. ip = v.IP
  92. local = ip.String()
  93. found = true
  94. }
  95. }
  96. }
  97. }
  98. if !found {
  99. err := errors.New("local ip address not found")
  100. return "", err
  101. }
  102. return local, err
  103. }
  104. // GetNode - gets node locally
  105. func GetNode(network string) models.Node {
  106. modcfg, err := config.ReadConfig(network)
  107. if err != nil {
  108. log.Fatalf("Error: %v", err)
  109. }
  110. return modcfg.Node
  111. }
  112. // Uninstall - uninstalls networks from client
  113. func Uninstall() error {
  114. networks, err := ncutils.GetSystemNetworks()
  115. if err != nil {
  116. logger.Log(1, "unable to retrieve networks: ", err.Error())
  117. logger.Log(1, "continuing uninstall without leaving networks")
  118. } else {
  119. for _, network := range networks {
  120. err = LeaveNetwork(network)
  121. if err != nil {
  122. logger.Log(1, "Encounter issue leaving network ", network, ": ", err.Error())
  123. }
  124. }
  125. }
  126. err = nil
  127. // clean up OS specific stuff
  128. if ncutils.IsWindows() {
  129. daemon.CleanupWindows()
  130. } else if ncutils.IsMac() {
  131. daemon.CleanupMac()
  132. } else if ncutils.IsLinux() {
  133. daemon.CleanupLinux()
  134. } else if ncutils.IsFreeBSD() {
  135. daemon.CleanupFreebsd()
  136. } else if !ncutils.IsKernel() {
  137. logger.Log(1, "manual cleanup required")
  138. }
  139. return err
  140. }
  141. // LeaveNetwork - client exits a network
  142. func LeaveNetwork(network string) error {
  143. cfg, err := config.ReadConfig(network)
  144. if err != nil {
  145. return err
  146. }
  147. node := cfg.Node
  148. if node.IsServer != "yes" {
  149. token, err := Authenticate(cfg)
  150. if err != nil {
  151. logger.Log(0, "unable to authenticate: "+err.Error())
  152. } else {
  153. url := "https://" + cfg.Server.API + "/api/nodes/" + cfg.Network + "/" + cfg.Node.ID
  154. response, err := API("", http.MethodDelete, url, token)
  155. if err != nil {
  156. logger.Log(0, "error deleting node on server: "+err.Error())
  157. } else {
  158. if response.StatusCode == http.StatusOK {
  159. logger.Log(0, "deleted node", cfg.Node.Name, " on network ", cfg.Network)
  160. } else {
  161. bodybytes, _ := io.ReadAll(response.Body)
  162. defer response.Body.Close()
  163. logger.Log(0, fmt.Sprintf("error deleting node on server %s %s", response.Status, string(bodybytes)))
  164. }
  165. }
  166. }
  167. }
  168. wgClient, wgErr := wgctrl.New()
  169. if wgErr == nil {
  170. removeIface := cfg.Node.Interface
  171. queryAddr := cfg.Node.PrimaryAddress()
  172. if ncutils.IsMac() {
  173. var macIface string
  174. macIface, wgErr = local.GetMacIface(queryAddr)
  175. if wgErr == nil && removeIface != "" {
  176. removeIface = macIface
  177. }
  178. wgErr = nil
  179. }
  180. dev, devErr := wgClient.Device(removeIface)
  181. if devErr == nil {
  182. local.FlushPeerRoutes(removeIface, queryAddr, dev.Peers[:])
  183. _, cidr, cidrErr := net.ParseCIDR(cfg.NetworkSettings.AddressRange)
  184. if cidrErr == nil {
  185. local.RemoveCIDRRoute(removeIface, queryAddr, cidr)
  186. }
  187. } else {
  188. logger.Log(1, "could not flush peer routes when leaving network, ", cfg.Node.Network)
  189. }
  190. }
  191. err = WipeLocal(node.Network)
  192. if err != nil {
  193. logger.Log(1, "unable to wipe local config")
  194. } else {
  195. logger.Log(1, "removed ", node.Network, " network locally")
  196. }
  197. currentNets, err := ncutils.GetSystemNetworks()
  198. if err != nil || len(currentNets) <= 1 {
  199. daemon.Stop() // stop system daemon if last network
  200. return RemoveLocalInstance(cfg, network)
  201. }
  202. return daemon.Restart()
  203. }
  204. // RemoveLocalInstance - remove all netclient files locally for a network
  205. func RemoveLocalInstance(cfg *config.ClientConfig, networkName string) error {
  206. if cfg.Daemon != "off" {
  207. if ncutils.IsWindows() {
  208. // TODO: Remove job?
  209. } else if ncutils.IsMac() {
  210. //TODO: Delete mac daemon
  211. } else if ncutils.IsFreeBSD() {
  212. daemon.RemoveFreebsdDaemon()
  213. } else {
  214. daemon.RemoveSystemDServices()
  215. }
  216. }
  217. return nil
  218. }
  219. // DeleteInterface - delete an interface of a network
  220. func DeleteInterface(ifacename string, postdown string) error {
  221. return wireguard.RemoveConf(ifacename, true)
  222. }
  223. // WipeLocal - wipes local instance
  224. func WipeLocal(network string) error {
  225. cfg, err := config.ReadConfig(network)
  226. if err != nil {
  227. return err
  228. }
  229. nodecfg := cfg.Node
  230. ifacename := nodecfg.Interface
  231. if ifacename != "" {
  232. if err = wireguard.RemoveConf(ifacename, true); err == nil {
  233. logger.Log(1, "removed WireGuard interface: ", ifacename)
  234. } else if strings.Contains(err.Error(), "does not exist") {
  235. err = nil
  236. }
  237. }
  238. home := ncutils.GetNetclientPathSpecific()
  239. if ncutils.FileExists(home + "netconfig-" + network) {
  240. err = os.Remove(home + "netconfig-" + network)
  241. if err != nil {
  242. log.Println("error removing netconfig:")
  243. log.Println(err.Error())
  244. }
  245. }
  246. if ncutils.FileExists(home + "backup.netconfig-" + network) {
  247. err = os.Remove(home + "backup.netconfig-" + network)
  248. if err != nil {
  249. log.Println("error removing backup netconfig:")
  250. log.Println(err.Error())
  251. }
  252. }
  253. if ncutils.FileExists(home + "nettoken-" + network) {
  254. err = os.Remove(home + "nettoken-" + network)
  255. if err != nil {
  256. log.Println("error removing nettoken:")
  257. log.Println(err.Error())
  258. }
  259. }
  260. if ncutils.FileExists(home + "secret-" + network) {
  261. err = os.Remove(home + "secret-" + network)
  262. if err != nil {
  263. log.Println("error removing secret:")
  264. log.Println(err.Error())
  265. }
  266. }
  267. if ncutils.FileExists(home + "traffic-" + network) {
  268. err = os.Remove(home + "traffic-" + network)
  269. if err != nil {
  270. log.Println("error removing traffic key:")
  271. log.Println(err.Error())
  272. }
  273. }
  274. if ncutils.FileExists(home + "wgkey-" + network) {
  275. err = os.Remove(home + "wgkey-" + network)
  276. if err != nil {
  277. log.Println("error removing wgkey:")
  278. log.Println(err.Error())
  279. }
  280. }
  281. if ncutils.FileExists(home + ifacename + ".conf") {
  282. err = os.Remove(home + ifacename + ".conf")
  283. if err != nil {
  284. log.Println("error removing .conf:")
  285. log.Println(err.Error())
  286. }
  287. }
  288. err = removeHostDNS(ifacename, ncutils.IsWindows())
  289. if err != nil {
  290. logger.Log(0, "failed to delete dns entries for", ifacename, err.Error())
  291. }
  292. return err
  293. }
  294. // GetNetmakerPath - gets netmaker path locally
  295. func GetNetmakerPath() string {
  296. return LINUX_APP_DATA_PATH
  297. }
  298. //API function to interact with netmaker api endpoints. response from endpoint is returned
  299. func API(data any, method, url, authorization string) (*http.Response, error) {
  300. var request *http.Request
  301. var err error
  302. if data != "" {
  303. payload, err := json.Marshal(data)
  304. if err != nil {
  305. return nil, fmt.Errorf("error encoding data %w", err)
  306. }
  307. request, err = http.NewRequest(method, url, bytes.NewBuffer(payload))
  308. if err != nil {
  309. return nil, fmt.Errorf("error creating http request %w", err)
  310. }
  311. request.Header.Set("Content-Type", "application/json")
  312. } else {
  313. request, err = http.NewRequest(method, url, nil)
  314. if err != nil {
  315. return nil, fmt.Errorf("error creating http request %w", err)
  316. }
  317. }
  318. if authorization != "" {
  319. request.Header.Set("authorization", "Bearer "+authorization)
  320. }
  321. client := http.Client{
  322. Timeout: HTTP_TIMEOUT * time.Second,
  323. }
  324. return client.Do(request)
  325. }
  326. // Authenticate authenticates with api to permit subsequent interactions with the api
  327. func Authenticate(cfg *config.ClientConfig) (string, error) {
  328. pass, err := os.ReadFile(ncutils.GetNetclientPathSpecific() + "secret-" + cfg.Network)
  329. if err != nil {
  330. return "", fmt.Errorf("could not read secrets file %w", err)
  331. }
  332. data := models.AuthParams{
  333. MacAddress: cfg.Node.MacAddress,
  334. ID: cfg.Node.ID,
  335. Password: string(pass),
  336. }
  337. url := "https://" + cfg.Server.API + "/api/nodes/adm/" + cfg.Network + "/authenticate"
  338. response, err := API(data, http.MethodPost, url, "")
  339. if err != nil {
  340. return "", err
  341. }
  342. defer response.Body.Close()
  343. if response.StatusCode != http.StatusOK {
  344. bodybytes, _ := io.ReadAll(response.Body)
  345. return "", fmt.Errorf("failed to authenticate %s %s", response.Status, string(bodybytes))
  346. }
  347. resp := models.SuccessResponse{}
  348. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  349. return "", fmt.Errorf("error decoding respone %w", err)
  350. }
  351. tokenData := resp.Response.(map[string]interface{})
  352. token := tokenData["AuthToken"]
  353. return token.(string), nil
  354. }
  355. // RegisterWithServer calls the register endpoint with privatekey and commonname - api returns ca and client certificate
  356. func SetServerInfo(cfg *config.ClientConfig) error {
  357. cfg, err := config.ReadConfig(cfg.Network)
  358. if err != nil {
  359. return err
  360. }
  361. url := "https://" + cfg.Server.API + "/api/server/getserverinfo"
  362. logger.Log(1, "server at "+url)
  363. token, err := Authenticate(cfg)
  364. if err != nil {
  365. return err
  366. }
  367. response, err := API("", http.MethodGet, url, token)
  368. if err != nil {
  369. return err
  370. }
  371. if response.StatusCode != http.StatusOK {
  372. return errors.New(response.Status)
  373. }
  374. var resp models.ServerConfig
  375. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  376. return errors.New("unmarshal cert error " + err.Error())
  377. }
  378. // set broker information on register
  379. cfg.Server.Server = resp.Server
  380. cfg.Server.MQPort = resp.MQPort
  381. if err = config.ModServerConfig(&cfg.Server, cfg.Node.Network); err != nil {
  382. logger.Log(0, "error overwriting config with broker information: "+err.Error())
  383. }
  384. return nil
  385. }
  386. func informPortChange(node *models.Node) {
  387. if node.ListenPort == 0 {
  388. logger.Log(0, "UDP hole punching enabled for node", node.Name)
  389. } else {
  390. logger.Log(0, "node", node.Name, "is using port", strconv.Itoa(int(node.ListenPort)))
  391. }
  392. }