common.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420
  1. package functions
  2. import (
  3. "bytes"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "io"
  8. "log"
  9. "net"
  10. "net/http"
  11. "os"
  12. "strconv"
  13. "strings"
  14. "time"
  15. "github.com/gravitl/netmaker/logger"
  16. "github.com/gravitl/netmaker/models"
  17. "github.com/gravitl/netmaker/netclient/config"
  18. "github.com/gravitl/netmaker/netclient/daemon"
  19. "github.com/gravitl/netmaker/netclient/local"
  20. "github.com/gravitl/netmaker/netclient/ncutils"
  21. "github.com/gravitl/netmaker/netclient/wireguard"
  22. "golang.zx2c4.com/wireguard/wgctrl"
  23. )
  24. // LINUX_APP_DATA_PATH - linux path
  25. const LINUX_APP_DATA_PATH = "/etc/netmaker"
  26. // HTTP_TIMEOUT - timeout in seconds for http requests
  27. const HTTP_TIMEOUT = 30
  28. // HTTPClient - http client to be reused by all
  29. var HTTPClient http.Client
  30. // SetHTTPClient -sets http client with sane default
  31. func SetHTTPClient() {
  32. HTTPClient = http.Client{
  33. Timeout: HTTP_TIMEOUT * time.Second,
  34. }
  35. }
  36. // ListPorts - lists ports of WireGuard devices
  37. func ListPorts() error {
  38. wgclient, err := wgctrl.New()
  39. if err != nil {
  40. return err
  41. }
  42. defer wgclient.Close()
  43. devices, err := wgclient.Devices()
  44. if err != nil {
  45. return err
  46. }
  47. fmt.Println("Here are your ports:")
  48. for _, i := range devices {
  49. fmt.Println(i.ListenPort)
  50. }
  51. return err
  52. }
  53. func getPrivateAddr() (string, error) {
  54. var local string
  55. conn, err := net.Dial("udp", "8.8.8.8:80")
  56. if err == nil {
  57. defer conn.Close()
  58. localAddr := conn.LocalAddr().(*net.UDPAddr)
  59. localIP := localAddr.IP
  60. local = localIP.String()
  61. }
  62. if local == "" {
  63. local, err = getPrivateAddrBackup()
  64. }
  65. if local == "" {
  66. err = errors.New("could not find local ip")
  67. }
  68. return local, err
  69. }
  70. func getPrivateAddrBackup() (string, error) {
  71. ifaces, err := net.Interfaces()
  72. if err != nil {
  73. return "", err
  74. }
  75. var local string
  76. found := false
  77. for _, i := range ifaces {
  78. if i.Flags&net.FlagUp == 0 {
  79. continue // interface down
  80. }
  81. if i.Flags&net.FlagLoopback != 0 {
  82. continue // loopback interface
  83. }
  84. addrs, err := i.Addrs()
  85. if err != nil {
  86. return "", err
  87. }
  88. for _, addr := range addrs {
  89. var ip net.IP
  90. switch v := addr.(type) {
  91. case *net.IPNet:
  92. if !found {
  93. ip = v.IP
  94. local = ip.String()
  95. found = true
  96. }
  97. case *net.IPAddr:
  98. if !found {
  99. ip = v.IP
  100. local = ip.String()
  101. found = true
  102. }
  103. }
  104. }
  105. }
  106. if !found {
  107. err := errors.New("local ip address not found")
  108. return "", err
  109. }
  110. return local, err
  111. }
  112. // GetNode - gets node locally
  113. func GetNode(network string) models.Node {
  114. modcfg, err := config.ReadConfig(network)
  115. if err != nil {
  116. log.Fatalf("Error: %v", err)
  117. }
  118. return modcfg.Node
  119. }
  120. // Uninstall - uninstalls networks from client
  121. func Uninstall() error {
  122. networks, err := ncutils.GetSystemNetworks()
  123. if err != nil {
  124. logger.Log(1, "unable to retrieve networks: ", err.Error())
  125. logger.Log(1, "continuing uninstall without leaving networks")
  126. } else {
  127. for _, network := range networks {
  128. err = LeaveNetwork(network)
  129. if err != nil {
  130. logger.Log(1, "encounter issue leaving network", network, ":", err.Error())
  131. }
  132. }
  133. }
  134. err = nil
  135. // clean up OS specific stuff
  136. if ncutils.IsWindows() {
  137. daemon.CleanupWindows()
  138. } else if ncutils.IsMac() {
  139. daemon.CleanupMac()
  140. } else if ncutils.IsLinux() {
  141. daemon.CleanupLinux()
  142. } else if ncutils.IsFreeBSD() {
  143. daemon.CleanupFreebsd()
  144. } else if !ncutils.IsKernel() {
  145. logger.Log(1, "manual cleanup required")
  146. }
  147. return err
  148. }
  149. // LeaveNetwork - client exits a network
  150. func LeaveNetwork(network string) error {
  151. cfg, err := config.ReadConfig(network)
  152. if err != nil {
  153. return err
  154. }
  155. node := cfg.Node
  156. if node.IsServer != "yes" {
  157. token, err := Authenticate(cfg)
  158. if err != nil {
  159. logger.Log(0, "network:", cfg.Network, "unable to authenticate: "+err.Error())
  160. } else {
  161. url := "https://" + cfg.Server.API + "/api/nodes/" + cfg.Network + "/" + cfg.Node.ID
  162. response, err := API("", http.MethodDelete, url, token)
  163. if err != nil {
  164. logger.Log(0, "network:", cfg.Network, "error deleting node on server: "+err.Error())
  165. } else {
  166. if response.StatusCode == http.StatusOK {
  167. logger.Log(0, "network:", cfg.Network, "deleted node", cfg.Node.Name, ".")
  168. } else {
  169. bodybytes, _ := io.ReadAll(response.Body)
  170. defer response.Body.Close()
  171. logger.Log(0, fmt.Sprintf("network: %s error deleting node on server %s %s", cfg.Network, response.Status, string(bodybytes)))
  172. }
  173. }
  174. }
  175. }
  176. wgClient, wgErr := wgctrl.New()
  177. if wgErr == nil {
  178. removeIface := cfg.Node.Interface
  179. queryAddr := cfg.Node.PrimaryAddress()
  180. if ncutils.IsMac() {
  181. var macIface string
  182. macIface, wgErr = local.GetMacIface(queryAddr)
  183. if wgErr == nil && removeIface != "" {
  184. removeIface = macIface
  185. }
  186. }
  187. dev, devErr := wgClient.Device(removeIface)
  188. if devErr == nil {
  189. local.FlushPeerRoutes(removeIface, queryAddr, dev.Peers[:])
  190. _, cidr, cidrErr := net.ParseCIDR(cfg.NetworkSettings.AddressRange)
  191. if cidrErr == nil {
  192. local.RemoveCIDRRoute(removeIface, queryAddr, cidr)
  193. }
  194. } else {
  195. logger.Log(1, "could not flush peer routes when leaving network,", cfg.Node.Network)
  196. }
  197. }
  198. err = WipeLocal(node.Network)
  199. if err != nil {
  200. logger.Log(1, "network:", node.Network, "unable to wipe local config")
  201. } else {
  202. logger.Log(1, "removed", node.Network, "network locally")
  203. }
  204. return daemon.Restart()
  205. }
  206. // DeleteInterface - delete an interface of a network
  207. func DeleteInterface(ifacename string, postdown string) error {
  208. return wireguard.RemoveConf(ifacename, true)
  209. }
  210. // WipeLocal - wipes local instance
  211. func WipeLocal(network string) error {
  212. var ifacename string
  213. if network == "" {
  214. return errors.New("no network provided")
  215. }
  216. cfg, err := config.ReadConfig(network)
  217. if err == nil {
  218. nodecfg := cfg.Node
  219. ifacename = nodecfg.Interface
  220. if ifacename != "" {
  221. if err = wireguard.RemoveConf(ifacename, true); err == nil {
  222. logger.Log(1, "network:", nodecfg.Network, "removed WireGuard interface: ", ifacename)
  223. } else if strings.Contains(err.Error(), "does not exist") {
  224. err = nil
  225. }
  226. }
  227. } else {
  228. logger.Log(0, "failed to read "+network+" config: ", err.Error())
  229. }
  230. home := ncutils.GetNetclientPathSpecific()
  231. if ncutils.FileExists(home + "netconfig-" + network) {
  232. err = os.Remove(home + "netconfig-" + network)
  233. if err != nil {
  234. log.Println("error removing netconfig:")
  235. log.Println(err.Error())
  236. }
  237. }
  238. if ncutils.FileExists(home + "backup.netconfig-" + network) {
  239. err = os.Remove(home + "backup.netconfig-" + network)
  240. if err != nil {
  241. log.Println("error removing backup netconfig:")
  242. log.Println(err.Error())
  243. }
  244. }
  245. if ncutils.FileExists(home + "nettoken-" + network) {
  246. err = os.Remove(home + "nettoken-" + network)
  247. if err != nil {
  248. log.Println("error removing nettoken:")
  249. log.Println(err.Error())
  250. }
  251. }
  252. if ncutils.FileExists(home + "secret-" + network) {
  253. err = os.Remove(home + "secret-" + network)
  254. if err != nil {
  255. log.Println("error removing secret:")
  256. log.Println(err.Error())
  257. }
  258. }
  259. if ncutils.FileExists(home + "traffic-" + network) {
  260. err = os.Remove(home + "traffic-" + network)
  261. if err != nil {
  262. log.Println("error removing traffic key:")
  263. log.Println(err.Error())
  264. }
  265. }
  266. if ncutils.FileExists(home + "wgkey-" + network) {
  267. err = os.Remove(home + "wgkey-" + network)
  268. if err != nil {
  269. log.Println("error removing wgkey:")
  270. log.Println(err.Error())
  271. }
  272. }
  273. if ifacename != "" {
  274. if ncutils.FileExists(home + ifacename + ".conf") {
  275. err = os.Remove(home + ifacename + ".conf")
  276. if err != nil {
  277. log.Println("error removing .conf:")
  278. log.Println(err.Error())
  279. }
  280. }
  281. err = removeHostDNS(ifacename, ncutils.IsWindows())
  282. if err != nil {
  283. logger.Log(0, "failed to delete dns entries for", ifacename, err.Error())
  284. }
  285. }
  286. return err
  287. }
  288. // GetNetmakerPath - gets netmaker path locally
  289. func GetNetmakerPath() string {
  290. return LINUX_APP_DATA_PATH
  291. }
  292. // API function to interact with netmaker api endpoints. response from endpoint is returned
  293. func API(data any, method, url, authorization string) (*http.Response, error) {
  294. var request *http.Request
  295. var err error
  296. if data != "" {
  297. payload, err := json.Marshal(data)
  298. if err != nil {
  299. return nil, fmt.Errorf("error encoding data %w", err)
  300. }
  301. request, err = http.NewRequest(method, url, bytes.NewBuffer(payload))
  302. if err != nil {
  303. return nil, fmt.Errorf("error creating http request %w", err)
  304. }
  305. request.Header.Set("Content-Type", "application/json")
  306. } else {
  307. request, err = http.NewRequest(method, url, nil)
  308. if err != nil {
  309. return nil, fmt.Errorf("error creating http request %w", err)
  310. }
  311. }
  312. if authorization != "" {
  313. request.Header.Set("authorization", "Bearer "+authorization)
  314. }
  315. return HTTPClient.Do(request)
  316. }
  317. // Authenticate authenticates with api to permit subsequent interactions with the api
  318. func Authenticate(cfg *config.ClientConfig) (string, error) {
  319. pass, err := os.ReadFile(ncutils.GetNetclientPathSpecific() + "secret-" + cfg.Network)
  320. if err != nil {
  321. return "", fmt.Errorf("could not read secrets file %w", err)
  322. }
  323. data := models.AuthParams{
  324. MacAddress: cfg.Node.MacAddress,
  325. ID: cfg.Node.ID,
  326. Password: string(pass),
  327. }
  328. url := "https://" + cfg.Server.API + "/api/nodes/adm/" + cfg.Network + "/authenticate"
  329. response, err := API(data, http.MethodPost, url, "")
  330. if err != nil {
  331. return "", err
  332. }
  333. defer response.Body.Close()
  334. if response.StatusCode != http.StatusOK {
  335. bodybytes, _ := io.ReadAll(response.Body)
  336. return "", fmt.Errorf("failed to authenticate %s %s", response.Status, string(bodybytes))
  337. }
  338. resp := models.SuccessResponse{}
  339. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  340. return "", fmt.Errorf("error decoding respone %w", err)
  341. }
  342. tokenData := resp.Response.(map[string]interface{})
  343. token := tokenData["AuthToken"]
  344. return token.(string), nil
  345. }
  346. // RegisterWithServer calls the register endpoint with privatekey and commonname - api returns ca and client certificate
  347. func SetServerInfo(cfg *config.ClientConfig) error {
  348. cfg, err := config.ReadConfig(cfg.Network)
  349. if err != nil {
  350. return err
  351. }
  352. url := "https://" + cfg.Server.API + "/api/server/getserverinfo"
  353. logger.Log(1, "server at "+url)
  354. token, err := Authenticate(cfg)
  355. if err != nil {
  356. return err
  357. }
  358. response, err := API("", http.MethodGet, url, token)
  359. if err != nil {
  360. return err
  361. }
  362. if response.StatusCode != http.StatusOK {
  363. return errors.New(response.Status)
  364. }
  365. var resp models.ServerConfig
  366. if err := json.NewDecoder(response.Body).Decode(&resp); err != nil {
  367. return errors.New("unmarshal cert error " + err.Error())
  368. }
  369. // set broker information on register
  370. cfg.Server.Server = resp.Server
  371. cfg.Server.MQPort = resp.MQPort
  372. if err = config.ModServerConfig(&cfg.Server, cfg.Node.Network); err != nil {
  373. logger.Log(0, "error overwriting config with broker information: "+err.Error())
  374. }
  375. return nil
  376. }
  377. func informPortChange(node *models.Node) {
  378. if node.ListenPort == 0 {
  379. logger.Log(0, "network:", node.Network, "UDP hole punching enabled for node", node.Name)
  380. } else {
  381. logger.Log(0, "network:", node.Network, "node", node.Name, "is using port", strconv.Itoa(int(node.ListenPort)))
  382. }
  383. }