2015-02-24 20:28:58 +00:00
|
|
|
/*
|
|
|
|
* ZeroTier One - Network Virtualization Everywhere
|
|
|
|
* Copyright (C) 2011-2015 ZeroTier, Inc.
|
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
* the Free Software Foundation, either version 3 of the License, or
|
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
|
2015-04-15 22:12:09 +00:00
|
|
|
#ifndef ZT_SQLITENETWORKCONTROLLER_HPP
|
|
|
|
#define ZT_SQLITENETWORKCONTROLLER_HPP
|
2015-02-24 20:28:58 +00:00
|
|
|
|
|
|
|
#include <stdint.h>
|
2015-03-12 21:03:53 +00:00
|
|
|
|
2015-02-24 20:28:58 +00:00
|
|
|
#include <string>
|
|
|
|
#include <map>
|
|
|
|
#include <vector>
|
2016-08-16 23:46:08 +00:00
|
|
|
#include <set>
|
2016-08-25 18:26:45 +00:00
|
|
|
#include <list>
|
2017-05-02 23:58:51 +00:00
|
|
|
#include <thread>
|
2017-07-14 21:33:36 +00:00
|
|
|
#include <unordered_map>
|
2015-02-24 20:28:58 +00:00
|
|
|
|
2015-02-24 22:17:57 +00:00
|
|
|
#include "../node/Constants.hpp"
|
2016-08-12 18:30:27 +00:00
|
|
|
|
2015-04-15 22:12:09 +00:00
|
|
|
#include "../node/NetworkController.hpp"
|
2015-02-24 22:17:57 +00:00
|
|
|
#include "../node/Mutex.hpp"
|
2016-08-16 21:05:17 +00:00
|
|
|
#include "../node/Utils.hpp"
|
2016-08-25 18:26:45 +00:00
|
|
|
#include "../node/Address.hpp"
|
2016-08-16 23:46:08 +00:00
|
|
|
#include "../node/InetAddress.hpp"
|
2017-04-27 07:59:36 +00:00
|
|
|
#include "../node/NonCopyable.hpp"
|
2016-08-16 21:05:17 +00:00
|
|
|
|
|
|
|
#include "../osdep/OSUtils.hpp"
|
2016-08-25 18:26:45 +00:00
|
|
|
#include "../osdep/Thread.hpp"
|
2016-11-10 21:57:01 +00:00
|
|
|
#include "../osdep/BlockingQueue.hpp"
|
2015-04-21 23:41:35 +00:00
|
|
|
|
2016-08-16 21:05:17 +00:00
|
|
|
#include "../ext/json/json.hpp"
|
2015-10-08 20:25:38 +00:00
|
|
|
|
2016-11-04 22:18:31 +00:00
|
|
|
#include "JSONDB.hpp"
|
|
|
|
|
2015-02-24 22:17:57 +00:00
|
|
|
namespace ZeroTier {
|
2015-02-24 20:28:58 +00:00
|
|
|
|
2015-10-06 22:56:18 +00:00
|
|
|
class Node;
|
|
|
|
|
2017-04-27 07:59:36 +00:00
|
|
|
class EmbeddedNetworkController : public NetworkController,NonCopyable
|
2015-02-24 20:28:58 +00:00
|
|
|
{
|
|
|
|
public:
|
2016-12-15 23:08:47 +00:00
|
|
|
/**
|
|
|
|
* @param node Parent node
|
|
|
|
* @param dbPath Path to store data
|
|
|
|
*/
|
2017-03-02 00:33:34 +00:00
|
|
|
EmbeddedNetworkController(Node *node,const char *dbPath);
|
2016-08-17 17:42:32 +00:00
|
|
|
virtual ~EmbeddedNetworkController();
|
2015-03-13 20:53:15 +00:00
|
|
|
|
2016-11-10 19:54:47 +00:00
|
|
|
virtual void init(const Identity &signingId,Sender *sender);
|
|
|
|
|
|
|
|
virtual void request(
|
|
|
|
uint64_t nwid,
|
2015-02-24 20:28:58 +00:00
|
|
|
const InetAddress &fromAddr,
|
2016-11-10 19:54:47 +00:00
|
|
|
uint64_t requestPacketId,
|
2015-03-18 23:10:48 +00:00
|
|
|
const Identity &identity,
|
2016-11-10 19:54:47 +00:00
|
|
|
const Dictionary<ZT_NETWORKCONFIG_METADATA_DICT_CAPACITY> &metaData);
|
2015-02-24 20:28:58 +00:00
|
|
|
|
2015-05-16 23:09:28 +00:00
|
|
|
unsigned int handleControlPlaneHttpGET(
|
2015-04-21 23:41:35 +00:00
|
|
|
const std::vector<std::string> &path,
|
|
|
|
const std::map<std::string,std::string> &urlArgs,
|
|
|
|
const std::map<std::string,std::string> &headers,
|
|
|
|
const std::string &body,
|
|
|
|
std::string &responseBody,
|
|
|
|
std::string &responseContentType);
|
2015-05-16 23:09:28 +00:00
|
|
|
unsigned int handleControlPlaneHttpPOST(
|
2015-04-21 23:41:35 +00:00
|
|
|
const std::vector<std::string> &path,
|
|
|
|
const std::map<std::string,std::string> &urlArgs,
|
|
|
|
const std::map<std::string,std::string> &headers,
|
|
|
|
const std::string &body,
|
|
|
|
std::string &responseBody,
|
|
|
|
std::string &responseContentType);
|
2015-05-16 23:09:28 +00:00
|
|
|
unsigned int handleControlPlaneHttpDELETE(
|
2015-04-21 23:41:35 +00:00
|
|
|
const std::vector<std::string> &path,
|
|
|
|
const std::map<std::string,std::string> &urlArgs,
|
|
|
|
const std::map<std::string,std::string> &headers,
|
|
|
|
const std::string &body,
|
|
|
|
std::string &responseBody,
|
|
|
|
std::string &responseContentType);
|
|
|
|
|
2017-07-14 20:03:16 +00:00
|
|
|
void handleRemoteTrace(const ZT_RemoteTrace &rt);
|
|
|
|
|
2017-08-16 21:41:42 +00:00
|
|
|
// Called on update via POST or by JSONDB on external update of network or network member records
|
2017-08-16 21:14:49 +00:00
|
|
|
void onNetworkUpdate(const uint64_t networkId);
|
|
|
|
void onNetworkMemberUpdate(const uint64_t networkId,const uint64_t memberId);
|
2017-08-17 20:10:10 +00:00
|
|
|
void onNetworkMemberDeauthorize(const uint64_t networkId,const uint64_t memberId);
|
2017-08-16 21:14:49 +00:00
|
|
|
|
2016-11-10 21:57:01 +00:00
|
|
|
void threadMain()
|
|
|
|
throw();
|
|
|
|
|
2015-02-24 20:28:58 +00:00
|
|
|
private:
|
2016-11-10 21:57:01 +00:00
|
|
|
struct _RQEntry
|
|
|
|
{
|
|
|
|
uint64_t nwid;
|
|
|
|
uint64_t requestPacketId;
|
|
|
|
InetAddress fromAddr;
|
|
|
|
Identity identity;
|
|
|
|
Dictionary<ZT_NETWORKCONFIG_METADATA_DICT_CAPACITY> metaData;
|
2017-05-02 23:58:51 +00:00
|
|
|
enum {
|
2017-07-18 22:36:33 +00:00
|
|
|
RQENTRY_TYPE_REQUEST = 0
|
2017-05-02 23:58:51 +00:00
|
|
|
} type;
|
2016-11-10 21:57:01 +00:00
|
|
|
};
|
2015-10-08 20:25:38 +00:00
|
|
|
|
2017-03-21 13:31:15 +00:00
|
|
|
void _request(uint64_t nwid,const InetAddress &fromAddr,uint64_t requestPacketId,const Identity &identity,const Dictionary<ZT_NETWORKCONFIG_METADATA_DICT_CAPACITY> &metaData);
|
2017-08-31 22:01:21 +00:00
|
|
|
void _startThreads();
|
2017-05-02 23:58:51 +00:00
|
|
|
|
2016-08-18 21:37:56 +00:00
|
|
|
// These init objects with default and static/informational fields
|
|
|
|
inline void _initMember(nlohmann::json &member)
|
|
|
|
{
|
|
|
|
if (!member.count("authorized")) member["authorized"] = false;
|
2016-08-23 20:02:59 +00:00
|
|
|
if (!member.count("ipAssignments")) member["ipAssignments"] = nlohmann::json::array();
|
2016-08-18 21:37:56 +00:00
|
|
|
if (!member.count("activeBridge")) member["activeBridge"] = false;
|
|
|
|
if (!member.count("tags")) member["tags"] = nlohmann::json::array();
|
|
|
|
if (!member.count("capabilities")) member["capabilities"] = nlohmann::json::array();
|
|
|
|
if (!member.count("creationTime")) member["creationTime"] = OSUtils::now();
|
2016-08-25 00:05:43 +00:00
|
|
|
if (!member.count("noAutoAssignIps")) member["noAutoAssignIps"] = false;
|
2016-08-25 23:08:40 +00:00
|
|
|
if (!member.count("revision")) member["revision"] = 0ULL;
|
2016-11-15 22:06:25 +00:00
|
|
|
if (!member.count("lastDeauthorizedTime")) member["lastDeauthorizedTime"] = 0ULL;
|
|
|
|
if (!member.count("lastAuthorizedTime")) member["lastAuthorizedTime"] = 0ULL;
|
2017-08-09 21:37:19 +00:00
|
|
|
if (!member.count("lastAuthorizedCredentialType")) member["lastAuthorizedCredentialType"] = nlohmann::json();
|
|
|
|
if (!member.count("lastAuthorizedCredential")) member["lastAuthorizedCredential"] = nlohmann::json();
|
2017-05-01 22:23:21 +00:00
|
|
|
if (!member.count("vMajor")) member["vMajor"] = -1;
|
|
|
|
if (!member.count("vMinor")) member["vMinor"] = -1;
|
|
|
|
if (!member.count("vRev")) member["vRev"] = -1;
|
|
|
|
if (!member.count("vProto")) member["vProto"] = -1;
|
|
|
|
if (!member.count("physicalAddr")) member["physicalAddr"] = nlohmann::json();
|
2017-07-14 20:03:16 +00:00
|
|
|
if (!member.count("remoteTraceTarget")) member["remoteTraceTarget"] = nlohmann::json();
|
2016-08-18 21:37:56 +00:00
|
|
|
member["objtype"] = "member";
|
|
|
|
}
|
|
|
|
inline void _initNetwork(nlohmann::json &network)
|
|
|
|
{
|
|
|
|
if (!network.count("private")) network["private"] = true;
|
|
|
|
if (!network.count("creationTime")) network["creationTime"] = OSUtils::now();
|
|
|
|
if (!network.count("name")) network["name"] = "";
|
|
|
|
if (!network.count("multicastLimit")) network["multicastLimit"] = (uint64_t)32;
|
2016-11-09 21:26:14 +00:00
|
|
|
if (!network.count("enableBroadcast")) network["enableBroadcast"] = true;
|
2016-08-18 21:37:56 +00:00
|
|
|
if (!network.count("v4AssignMode")) network["v4AssignMode"] = {{"zt",false}};
|
|
|
|
if (!network.count("v6AssignMode")) network["v6AssignMode"] = {{"rfc4193",false},{"zt",false},{"6plane",false}};
|
2017-08-09 21:37:19 +00:00
|
|
|
if (!network.count("authTokens")) network["authTokens"] = {{}};
|
2016-08-18 21:37:56 +00:00
|
|
|
if (!network.count("capabilities")) network["capabilities"] = nlohmann::json::array();
|
2017-02-21 21:27:20 +00:00
|
|
|
if (!network.count("tags")) network["tags"] = nlohmann::json::array();
|
2017-01-19 18:44:26 +00:00
|
|
|
if (!network.count("routes")) network["routes"] = nlohmann::json::array();
|
2016-09-30 20:04:26 +00:00
|
|
|
if (!network.count("ipAssignmentPools")) network["ipAssignmentPools"] = nlohmann::json::array();
|
2017-05-05 00:22:24 +00:00
|
|
|
if (!network.count("mtu")) network["mtu"] = ZT_DEFAULT_MTU;
|
2017-07-14 20:03:16 +00:00
|
|
|
if (!network.count("remoteTraceTarget")) network["remoteTraceTarget"] = nlohmann::json();
|
2016-08-18 21:37:56 +00:00
|
|
|
if (!network.count("rules")) {
|
|
|
|
// If unspecified, rules are set to allow anything and behave like a flat L2 segment
|
2016-10-12 19:30:32 +00:00
|
|
|
network["rules"] = {{
|
2016-08-18 21:37:56 +00:00
|
|
|
{ "not",false },
|
2016-11-04 22:52:01 +00:00
|
|
|
{ "or", false },
|
2016-08-18 21:37:56 +00:00
|
|
|
{ "type","ACTION_ACCEPT" }
|
2016-10-12 19:30:32 +00:00
|
|
|
}};
|
2016-08-18 21:37:56 +00:00
|
|
|
}
|
|
|
|
network["objtype"] = "network";
|
|
|
|
}
|
2017-04-26 13:48:08 +00:00
|
|
|
inline void _addNetworkNonPersistedFields(nlohmann::json &network,uint64_t now,const JSONDB::NetworkSummaryInfo &ns)
|
2016-08-18 19:59:48 +00:00
|
|
|
{
|
|
|
|
network["clock"] = now;
|
2017-04-26 13:48:08 +00:00
|
|
|
network["authorizedMemberCount"] = ns.authorizedMemberCount;
|
|
|
|
network["activeMemberCount"] = ns.activeMemberCount;
|
|
|
|
network["totalMemberCount"] = ns.totalMemberCount;
|
2016-08-16 23:46:08 +00:00
|
|
|
}
|
2017-04-28 02:36:03 +00:00
|
|
|
inline void _removeNetworkNonPersistedFields(nlohmann::json &network)
|
|
|
|
{
|
|
|
|
network.erase("clock");
|
|
|
|
network.erase("authorizedMemberCount");
|
|
|
|
network.erase("activeMemberCount");
|
|
|
|
network.erase("totalMemberCount");
|
2017-05-01 22:23:21 +00:00
|
|
|
// legacy fields
|
|
|
|
network.erase("lastModified");
|
2017-04-28 02:36:03 +00:00
|
|
|
}
|
2017-05-01 20:21:26 +00:00
|
|
|
inline void _addMemberNonPersistedFields(uint64_t nwid,uint64_t nodeId,nlohmann::json &member,uint64_t now)
|
2016-09-29 21:48:39 +00:00
|
|
|
{
|
|
|
|
member["clock"] = now;
|
2017-05-01 20:21:26 +00:00
|
|
|
Mutex::Lock _l(_memberStatus_m);
|
|
|
|
member["online"] = _memberStatus[_MemberStatusKey(nwid,nodeId)].online(now);
|
2016-09-29 21:48:39 +00:00
|
|
|
}
|
2017-04-28 02:36:03 +00:00
|
|
|
inline void _removeMemberNonPersistedFields(nlohmann::json &member)
|
|
|
|
{
|
|
|
|
member.erase("clock");
|
2017-05-01 22:23:21 +00:00
|
|
|
// legacy fields
|
|
|
|
member.erase("recentLog");
|
|
|
|
member.erase("lastModified");
|
|
|
|
member.erase("lastRequestMetaData");
|
2017-04-28 02:36:03 +00:00
|
|
|
}
|
2016-08-16 23:46:08 +00:00
|
|
|
|
2017-03-21 13:31:15 +00:00
|
|
|
const uint64_t _startTime;
|
|
|
|
|
2017-04-25 03:51:02 +00:00
|
|
|
volatile bool _running;
|
2017-03-21 13:31:15 +00:00
|
|
|
BlockingQueue<_RQEntry *> _queue;
|
2017-04-25 02:16:36 +00:00
|
|
|
std::vector<Thread> _threads;
|
2017-07-18 22:36:33 +00:00
|
|
|
volatile uint64_t _lastDumpedStatus;
|
2017-03-21 13:31:15 +00:00
|
|
|
Mutex _threads_m;
|
|
|
|
|
2016-11-04 22:48:23 +00:00
|
|
|
JSONDB _db;
|
|
|
|
|
2016-08-12 18:30:27 +00:00
|
|
|
Node *const _node;
|
2016-08-16 21:05:17 +00:00
|
|
|
std::string _path;
|
2015-07-22 21:01:49 +00:00
|
|
|
|
2016-11-10 19:54:47 +00:00
|
|
|
NetworkController::Sender *_sender;
|
|
|
|
Identity _signingId;
|
2017-07-14 21:33:36 +00:00
|
|
|
std::string _signingIdAddressString;
|
2016-11-10 19:54:47 +00:00
|
|
|
|
2017-05-01 20:21:26 +00:00
|
|
|
struct _MemberStatusKey
|
|
|
|
{
|
|
|
|
_MemberStatusKey() : networkId(0),nodeId(0) {}
|
|
|
|
_MemberStatusKey(const uint64_t nwid,const uint64_t nid) : networkId(nwid),nodeId(nid) {}
|
|
|
|
uint64_t networkId;
|
|
|
|
uint64_t nodeId;
|
|
|
|
inline bool operator==(const _MemberStatusKey &k) const { return ((k.networkId == networkId)&&(k.nodeId == nodeId)); }
|
|
|
|
};
|
|
|
|
struct _MemberStatus
|
|
|
|
{
|
|
|
|
_MemberStatus() : lastRequestTime(0),vMajor(-1),vMinor(-1),vRev(-1),vProto(-1) {}
|
|
|
|
uint64_t lastRequestTime;
|
|
|
|
int vMajor,vMinor,vRev,vProto;
|
|
|
|
Dictionary<ZT_NETWORKCONFIG_METADATA_DICT_CAPACITY> lastRequestMetaData;
|
|
|
|
Identity identity;
|
|
|
|
InetAddress physicalAddr; // last known physical address
|
|
|
|
inline bool online(const uint64_t now) const { return ((now - lastRequestTime) < (ZT_NETWORK_AUTOCONF_DELAY * 2)); }
|
|
|
|
};
|
|
|
|
struct _MemberStatusHash
|
|
|
|
{
|
|
|
|
inline std::size_t operator()(const _MemberStatusKey &networkIdNodeId) const
|
|
|
|
{
|
|
|
|
return (std::size_t)(networkIdNodeId.networkId + networkIdNodeId.nodeId);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
std::unordered_map< _MemberStatusKey,_MemberStatus,_MemberStatusHash > _memberStatus;
|
|
|
|
Mutex _memberStatus_m;
|
2015-02-24 20:28:58 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
} // namespace ZeroTier
|
|
|
|
|
|
|
|
#endif
|