mqhandlers.go 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315
  1. package functions
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "fmt"
  6. "os"
  7. "runtime"
  8. "strings"
  9. "time"
  10. mqtt "github.com/eclipse/paho.mqtt.golang"
  11. "github.com/gravitl/netmaker/logger"
  12. "github.com/gravitl/netmaker/models"
  13. "github.com/gravitl/netmaker/netclient/config"
  14. "github.com/gravitl/netmaker/netclient/local"
  15. "github.com/gravitl/netmaker/netclient/ncutils"
  16. "github.com/gravitl/netmaker/netclient/wireguard"
  17. "github.com/guumaster/hostctl/pkg/file"
  18. "github.com/guumaster/hostctl/pkg/parser"
  19. "github.com/guumaster/hostctl/pkg/types"
  20. "golang.zx2c4.com/wireguard/wgctrl/wgtypes"
  21. )
  22. // All -- mqtt message hander for all ('#') topics
  23. var All mqtt.MessageHandler = func(client mqtt.Client, msg mqtt.Message) {
  24. logger.Log(0, "default message handler -- received message but not handling")
  25. logger.Log(0, "Topic: "+string(msg.Topic()))
  26. //logger.Log(0, "Message: " + string(msg.Payload()))
  27. }
  28. // NodeUpdate -- mqtt message handler for /update/<NodeID> topic
  29. func NodeUpdate(client mqtt.Client, msg mqtt.Message) {
  30. var newNode models.Node
  31. var nodeCfg config.ClientConfig
  32. var network = parseNetworkFromTopic(msg.Topic())
  33. nodeCfg.Network = network
  34. nodeCfg.ReadConfig()
  35. data, dataErr := decryptMsg(&nodeCfg, msg.Payload())
  36. if dataErr != nil {
  37. return
  38. }
  39. err := json.Unmarshal([]byte(data), &newNode)
  40. if err != nil {
  41. logger.Log(0, "error unmarshalling node update data"+err.Error())
  42. return
  43. }
  44. // see if cache hit, if so skip
  45. var currentMessage = read(newNode.Network, lastNodeUpdate)
  46. if currentMessage == string(data) {
  47. return
  48. }
  49. insert(newNode.Network, lastNodeUpdate, string(data)) // store new message in cache
  50. logger.Log(0, "received message to update node "+newNode.Name)
  51. // ensure that OS never changes
  52. newNode.OS = runtime.GOOS
  53. // check if interface needs to delta
  54. ifaceDelta := ncutils.IfaceDelta(&nodeCfg.Node, &newNode)
  55. shouldDNSChange := nodeCfg.Node.DNSOn != newNode.DNSOn
  56. hubChange := nodeCfg.Node.IsHub != newNode.IsHub
  57. keepaliveChange := nodeCfg.Node.PersistentKeepalive != newNode.PersistentKeepalive
  58. nodeCfg.Node = newNode
  59. switch newNode.Action {
  60. case models.NODE_DELETE:
  61. logger.Log(0, "received delete request for %s", nodeCfg.Node.Name)
  62. unsubscribeNode(client, &nodeCfg)
  63. if err = LeaveNetwork(nodeCfg.Node.Network); err != nil {
  64. if !strings.Contains("rpc error", err.Error()) {
  65. logger.Log(0, "failed to leave, please check that local files for network", nodeCfg.Node.Network, "were removed")
  66. return
  67. }
  68. }
  69. logger.Log(0, nodeCfg.Node.Name, " was removed")
  70. return
  71. case models.NODE_UPDATE_KEY:
  72. // == get the current key for node ==
  73. oldPrivateKey, retErr := wireguard.RetrievePrivKey(nodeCfg.Network)
  74. if retErr != nil {
  75. break
  76. }
  77. if err := UpdateKeys(&nodeCfg, client); err != nil {
  78. logger.Log(0, "err updating wireguard keys, reusing last key\n", err.Error())
  79. if key, parseErr := wgtypes.ParseKey(oldPrivateKey); parseErr == nil {
  80. wireguard.StorePrivKey(key.String(), nodeCfg.Network)
  81. nodeCfg.Node.PublicKey = key.PublicKey().String()
  82. }
  83. }
  84. ifaceDelta = true
  85. case models.NODE_FORCE_UPDATE:
  86. ifaceDelta = true
  87. case models.NODE_NOOP:
  88. default:
  89. }
  90. // Save new config
  91. nodeCfg.Node.Action = models.NODE_NOOP
  92. if err := config.Write(&nodeCfg, nodeCfg.Network); err != nil {
  93. logger.Log(0, "error updating node configuration: ", err.Error())
  94. }
  95. nameserver := nodeCfg.Server.CoreDNSAddr
  96. privateKey, err := wireguard.RetrievePrivKey(newNode.Network)
  97. if err != nil {
  98. logger.Log(0, "error reading PrivateKey "+err.Error())
  99. return
  100. }
  101. file := ncutils.GetNetclientPathSpecific() + nodeCfg.Node.Interface + ".conf"
  102. if ifaceDelta { // if a change caused an ifacedelta we need to notify the server to update the peers
  103. if newNode.ListenPort != nodeCfg.Node.LocalListenPort {
  104. if err := wireguard.RemoveConf(newNode.Interface, false); err != nil {
  105. logger.Log(0, "error remove interface", newNode.Interface, err.Error())
  106. }
  107. err = ncutils.ModPort(&newNode)
  108. if err != nil {
  109. logger.Log(0, "error modifying node port on", newNode.Name, "-", err.Error())
  110. return
  111. }
  112. informPortChange(&newNode)
  113. }
  114. if err := wireguard.UpdateWgInterface(file, privateKey, nameserver, newNode); err != nil {
  115. logger.Log(0, "error updating wireguard config "+err.Error())
  116. return
  117. }
  118. if keepaliveChange {
  119. wireguard.UpdateKeepAlive(file, newNode.PersistentKeepalive)
  120. }
  121. logger.Log(0, "applying WG conf to "+file)
  122. if ncutils.IsWindows() {
  123. wireguard.RemoveConfGraceful(nodeCfg.Node.Interface)
  124. }
  125. err = wireguard.ApplyConf(&nodeCfg.Node, nodeCfg.Node.Interface, file)
  126. if err != nil {
  127. logger.Log(0, "error restarting wg after node update -", err.Error())
  128. return
  129. }
  130. time.Sleep(time.Second)
  131. // if newNode.DNSOn == "yes" {
  132. // for _, server := range newNode.NetworkSettings.DefaultServerAddrs {
  133. // if server.IsLeader {
  134. // go local.SetDNSWithRetry(newNode, server.Address)
  135. // break
  136. // }
  137. // }
  138. // }
  139. doneErr := publishSignal(&nodeCfg, ncutils.DONE)
  140. if doneErr != nil {
  141. logger.Log(0, "could not notify server to update peers after interface change")
  142. } else {
  143. logger.Log(0, "signalled finished interface update to server")
  144. }
  145. } else if hubChange {
  146. doneErr := publishSignal(&nodeCfg, ncutils.DONE)
  147. if doneErr != nil {
  148. logger.Log(0, "could not notify server to update peers after hub change")
  149. } else {
  150. logger.Log(0, "signalled finished hub update to server")
  151. }
  152. }
  153. //deal with DNS
  154. if newNode.DNSOn != "yes" && shouldDNSChange && nodeCfg.Node.Interface != "" {
  155. logger.Log(0, "settng DNS off")
  156. if err := removeHostDNS(nodeCfg.Node.Interface, ncutils.IsWindows()); err != nil {
  157. logger.Log(0, "error removing netmaker profile from /etc/hosts "+err.Error())
  158. }
  159. // _, err := ncutils.RunCmd("/usr/bin/resolvectl revert "+nodeCfg.Node.Interface, true)
  160. // if err != nil {
  161. // logger.Log(0, "error applying dns" + err.Error())
  162. // }
  163. }
  164. _ = UpdateLocalListenPort(&nodeCfg)
  165. }
  166. // UpdatePeers -- mqtt message handler for peers/<Network>/<NodeID> topic
  167. func UpdatePeers(client mqtt.Client, msg mqtt.Message) {
  168. var peerUpdate models.PeerUpdate
  169. var network = parseNetworkFromTopic(msg.Topic())
  170. var cfg = config.ClientConfig{}
  171. cfg.Network = network
  172. cfg.ReadConfig()
  173. data, dataErr := decryptMsg(&cfg, msg.Payload())
  174. if dataErr != nil {
  175. return
  176. }
  177. err := json.Unmarshal([]byte(data), &peerUpdate)
  178. if err != nil {
  179. logger.Log(0, "error unmarshalling peer data")
  180. return
  181. }
  182. // see if cached hit, if so skip
  183. var currentMessage = read(peerUpdate.Network, lastPeerUpdate)
  184. if currentMessage == string(data) {
  185. return
  186. }
  187. insert(peerUpdate.Network, lastPeerUpdate, string(data))
  188. // check version
  189. if peerUpdate.ServerVersion != ncutils.Version {
  190. logger.Log(0, "server/client version mismatch server: ", peerUpdate.ServerVersion, " client: ", ncutils.Version)
  191. }
  192. if peerUpdate.ServerVersion != cfg.Server.Version {
  193. logger.Log(1, "updating server version")
  194. cfg.Server.Version = peerUpdate.ServerVersion
  195. config.Write(&cfg, cfg.Network)
  196. }
  197. file := ncutils.GetNetclientPathSpecific() + cfg.Node.Interface + ".conf"
  198. err = wireguard.UpdateWgPeers(file, peerUpdate.Peers)
  199. if err != nil {
  200. logger.Log(0, "error updating wireguard peers"+err.Error())
  201. return
  202. }
  203. queryAddr := cfg.Node.PrimaryAddress()
  204. //err = wireguard.SyncWGQuickConf(cfg.Node.Interface, file)
  205. var iface = cfg.Node.Interface
  206. if ncutils.IsMac() {
  207. iface, err = local.GetMacIface(queryAddr)
  208. if err != nil {
  209. logger.Log(0, "error retrieving mac iface: "+err.Error())
  210. return
  211. }
  212. }
  213. err = wireguard.SetPeers(iface, &cfg.Node, peerUpdate.Peers)
  214. if err != nil {
  215. logger.Log(0, "error syncing wg after peer update: "+err.Error())
  216. return
  217. }
  218. logger.Log(0, "received peer update for node "+cfg.Node.Name+" "+cfg.Node.Network)
  219. if cfg.Node.DNSOn == "yes" {
  220. if err := setHostDNS(peerUpdate.DNS, cfg.Node.Interface, ncutils.IsWindows()); err != nil {
  221. logger.Log(0, "error updating /etc/hosts "+err.Error())
  222. return
  223. }
  224. } else {
  225. if err := removeHostDNS(cfg.Node.Interface, ncutils.IsWindows()); err != nil {
  226. logger.Log(0, "error removing profile from /etc/hosts "+err.Error())
  227. return
  228. }
  229. }
  230. _ = UpdateLocalListenPort(&cfg)
  231. }
  232. func setHostDNS(dns, iface string, windows bool) error {
  233. etchosts := "/etc/hosts"
  234. temp := os.TempDir()
  235. lockfile := temp + "/netclient-lock"
  236. if windows {
  237. etchosts = "c:\\windows\\system32\\drivers\\etc\\hosts"
  238. lockfile = temp + "\\netclient-lock"
  239. }
  240. if _, err := os.Stat(lockfile); !errors.Is(err, os.ErrNotExist) {
  241. return errors.New("/etc/hosts file is locked .... aborting")
  242. }
  243. lock, err := os.Create(lockfile)
  244. if err != nil {
  245. return fmt.Errorf("could not create lock file %w", err)
  246. }
  247. lock.Close()
  248. defer os.Remove(lockfile)
  249. dnsdata := strings.NewReader(dns)
  250. profile, err := parser.ParseProfile(dnsdata)
  251. if err != nil {
  252. return err
  253. }
  254. hosts, err := file.NewFile(etchosts)
  255. if err != nil {
  256. return err
  257. }
  258. profile.Name = strings.ToLower(iface)
  259. profile.Status = types.Enabled
  260. if err := hosts.ReplaceProfile(profile); err != nil {
  261. return err
  262. }
  263. if err := hosts.Flush(); err != nil {
  264. return err
  265. }
  266. return nil
  267. }
  268. func removeHostDNS(iface string, windows bool) error {
  269. etchosts := "/etc/hosts"
  270. temp := os.TempDir()
  271. lockfile := temp + "/netclient-lock"
  272. if windows {
  273. etchosts = "c:\\windows\\system32\\drivers\\etc\\hosts"
  274. lockfile = temp + "\\netclient-lock"
  275. }
  276. if _, err := os.Stat(lockfile); !errors.Is(err, os.ErrNotExist) {
  277. return errors.New("/etc/hosts file is locked .... aborting")
  278. }
  279. lock, err := os.Create(lockfile)
  280. if err != nil {
  281. return fmt.Errorf("could not create lock file %w", err)
  282. }
  283. lock.Close()
  284. defer os.Remove(lockfile)
  285. hosts, err := file.NewFile(etchosts)
  286. if err != nil {
  287. return err
  288. }
  289. if err := hosts.RemoveProfile(strings.ToLower(iface)); err != nil {
  290. if err == types.ErrUnknownProfile {
  291. return nil
  292. }
  293. return err
  294. }
  295. if err := hosts.Flush(); err != nil {
  296. return err
  297. }
  298. return nil
  299. }