| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382 | 
							- /*
 
-  * ZeroTier One - Network Virtualization Everywhere
 
-  * Copyright (C) 2011-2019  ZeroTier, Inc.  https://www.zerotier.com/
 
-  *
 
-  * This program is free software: you can redistribute it and/or modify
 
-  * it under the terms of the GNU General Public License as published by
 
-  * the Free Software Foundation, either version 3 of the License, or
 
-  * (at your option) any later version.
 
-  *
 
-  * This program is distributed in the hope that it will be useful,
 
-  * but WITHOUT ANY WARRANTY; without even the implied warranty of
 
-  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 
-  * GNU General Public License for more details.
 
-  *
 
-  * You should have received a copy of the GNU General Public License
 
-  * along with this program. If not, see <http://www.gnu.org/licenses/>.
 
-  *
 
-  * --
 
-  *
 
-  * You can be released from the requirements of the license by purchasing
 
-  * a commercial license. Buying such a license is mandatory as soon as you
 
-  * develop commercial closed-source software that incorporates or links
 
-  * directly against ZeroTier software without disclosing the source code
 
-  * of your own application.
 
-  */
 
- #include "LFDB.hpp"
 
- #include <thread>
 
- #include <chrono>
 
- #include <iostream>
 
- #include <sstream>
 
- #include "../osdep/OSUtils.hpp"
 
- #include "../ext/cpp-httplib/httplib.h"
 
- namespace ZeroTier
 
- {
 
- LFDB::LFDB(const Identity &myId,const char *path,const char *lfOwnerPrivate,const char *lfOwnerPublic,const char *lfNodeHost,int lfNodePort,bool storeOnlineState) :
 
- 	DB(myId,path),
 
- 	_myId(myId),
 
- 	_lfOwnerPrivate((lfOwnerPrivate) ? lfOwnerPrivate : ""),
 
- 	_lfOwnerPublic((lfOwnerPublic) ? lfOwnerPublic : ""),
 
- 	_lfNodeHost((lfNodeHost) ? lfNodeHost : "127.0.0.1"),
 
- 	_lfNodePort(((lfNodePort > 0)&&(lfNodePort < 65536)) ? lfNodePort : 9980),
 
- 	_running(true),
 
- 	_ready(false),
 
- 	_storeOnlineState(storeOnlineState)
 
- {
 
- 	_syncThread = std::thread([this]() {
 
- 		char controllerAddress[24];
 
- 		const uint64_t controllerAddressInt = _myId.address().toInt();
 
- 		_myId.address().toString(controllerAddress);
 
- 		std::string networksSelectorName("com.zerotier.controller.lfdb:"); networksSelectorName.append(controllerAddress); networksSelectorName.append("/network");
 
- 		std::string membersSelectorName("com.zerotier.controller.lfdb:"); membersSelectorName.append(controllerAddress); membersSelectorName.append("/member");
 
- 		// LF record masking key is the first 32 bytes of SHA512(controller private key) in hex,
 
- 		// hiding record values from anything but the controller or someone who has its key.
 
- 		uint8_t sha512pk[64];
 
- 		_myId.sha512PrivateKey(sha512pk);
 
- 		char maskingKey [128];
 
- 		Utils::hex(sha512pk,32,maskingKey);
 
- 		httplib::Client htcli(_lfNodeHost.c_str(),_lfNodePort,600);
 
- 		int64_t timeRangeStart = 0;
 
- 		while (_running) {
 
- 			{
 
- 				std::lock_guard<std::mutex> sl(_state_l);
 
- 				for(auto ns=_state.begin();ns!=_state.end();++ns) {
 
- 					if (ns->second.dirty) {
 
- 						nlohmann::json network;
 
- 						if (get(ns->first,network)) {
 
- 							nlohmann::json newrec,selector0;
 
- 							selector0["Name"] = networksSelectorName;
 
- 							selector0["Ordinal"] = ns->first;
 
- 							newrec["Selectors"].push_back(selector0);
 
- 							newrec["Value"] = network.dump();
 
- 							newrec["OwnerPrivate"] = _lfOwnerPrivate;
 
- 							newrec["MaskingKey"] = maskingKey;
 
- 							newrec["PulseIfUnchanged"] = true;
 
- 							auto resp = htcli.Post("/makerecord",newrec.dump(),"application/json");
 
- 							if (resp) {
 
- 								if (resp->status == 200) {
 
- 									ns->second.dirty = false;
 
- 									printf("SET network %.16llx %s\n",ns->first,resp->body.c_str());
 
- 								} else {
 
- 									fprintf(stderr,"ERROR: LFDB: %d from node (create/update network): %s" ZT_EOL_S,resp->status,resp->body.c_str());
 
- 								}
 
- 							} else {
 
- 								fprintf(stderr,"ERROR: LFDB: node is offline" ZT_EOL_S);
 
- 							}
 
- 						}
 
- 					}
 
- 					for(auto ms=ns->second.members.begin();ms!=ns->second.members.end();++ms) {
 
- 						if ((_storeOnlineState)&&(ms->second.lastOnlineDirty)&&(ms->second.lastOnlineAddress)) {
 
- 							nlohmann::json newrec,selector0,selector1,selectors,ip;
 
- 							char tmp[1024],tmp2[128];
 
- 							OSUtils::ztsnprintf(tmp,sizeof(tmp),"com.zerotier.controller.lfdb:%s/network/%.16llx/online",controllerAddress,(unsigned long long)ns->first);
 
- 							ms->second.lastOnlineAddress.toIpString(tmp2);
 
- 							selector0["Name"] = tmp;
 
- 							selector0["Ordinal"] = ms->first;
 
- 							selector1["Name"] = tmp2;
 
- 							selector1["Ordinal"] = 0;
 
- 							selectors.push_back(selector0);
 
- 							selectors.push_back(selector1);
 
- 							newrec["Selectors"] = selectors;
 
- 							const uint8_t *const rawip = (const uint8_t *)ms->second.lastOnlineAddress.rawIpData();
 
- 							switch(ms->second.lastOnlineAddress) {
 
- 								case AF_INET:
 
- 									for(int j=0;j<4;++j)
 
- 										ip.push_back((unsigned int)rawip[j]);
 
- 									break;
 
- 								case AF_INET6:
 
- 									for(int j=0;j<16;++j)
 
- 										ip.push_back((unsigned int)rawip[j]);
 
- 									break;
 
- 								default:
 
- 									ip = tmp2; // should never happen since only IP transport is currently supported
 
- 									break;
 
- 							}
 
- 							newrec["Value"] = ip;
 
- 							newrec["OwnerPrivate"] = _lfOwnerPrivate;
 
- 							newrec["MaskingKey"] = maskingKey;
 
- 							newrec["Timestamp"] = ms->second.lastOnlineTime;
 
- 							newrec["PulseIfUnchanged"] = true;
 
- 							auto resp = htcli.Post("/makerecord",newrec.dump(),"application/json");
 
- 							if (resp) {
 
- 								if (resp->status == 200) {
 
- 									ms->second.lastOnlineDirty = false;
 
- 									printf("SET member online %.16llx %.10llx %s\n",ns->first,ms->first,resp->body.c_str());
 
- 								} else {
 
- 									fprintf(stderr,"ERROR: LFDB: %d from node (create/update member online status): %s" ZT_EOL_S,resp->status,resp->body.c_str());
 
- 								}
 
- 							} else {
 
- 								fprintf(stderr,"ERROR: LFDB: node is offline" ZT_EOL_S);
 
- 							}
 
- 						}
 
- 						if (ms->second.dirty) {
 
- 							nlohmann::json network,member;
 
- 							if (get(ns->first,network,ms->first,member)) {
 
- 								nlohmann::json newrec,selector0,selector1,selectors;
 
- 								selector0["Name"] = networksSelectorName;
 
- 								selector0["Ordinal"] = ns->first;
 
- 								selector1["Name"] = membersSelectorName;
 
- 								selector1["Ordinal"] = ms->first;
 
- 								selectors.push_back(selector0);
 
- 								selectors.push_back(selector1);
 
- 								newrec["Selectors"] = selectors;
 
- 								newrec["Value"] = member.dump();
 
- 								newrec["OwnerPrivate"] = _lfOwnerPrivate;
 
- 								newrec["MaskingKey"] = maskingKey;
 
- 								newrec["PulseIfUnchanged"] = true;
 
- 								auto resp = htcli.Post("/makerecord",newrec.dump(),"application/json");
 
- 								if (resp) {
 
- 									if (resp->status == 200) {
 
- 										ms->second.dirty = false;
 
- 										printf("SET member %.16llx %.10llx %s\n",ns->first,ms->first,resp->body.c_str());
 
- 									} else {
 
- 										fprintf(stderr,"ERROR: LFDB: %d from node (create/update member): %s" ZT_EOL_S,resp->status,resp->body.c_str());
 
- 									}
 
- 								} else {
 
- 									fprintf(stderr,"ERROR: LFDB: node is offline" ZT_EOL_S);
 
- 								}
 
- 							}
 
- 						}
 
- 					}
 
- 				}
 
- 			}
 
- 			{
 
- 				std::ostringstream query;
 
- 				query
 
- 					<< '{'
 
- 						<< "\"Ranges\":[{"
 
- 							<< "\"Name\":\"" << networksSelectorName << "\","
 
- 							<< "\"Range\":[0,18446744073709551615]"
 
- 						<< "}],"
 
- 						<< "\"TimeRange\":[" << timeRangeStart << ",18446744073709551615],"
 
- 						<< "\"MaskingKey\":\"" << maskingKey << "\","
 
- 						<< "\"Owners\":[\"" << _lfOwnerPublic << "\"]"
 
- 					<< '}';
 
- 				auto resp = htcli.Post("/query",query.str(),"application/json");
 
- 				if (resp) {
 
- 					if (resp->status == 200) {
 
- 						nlohmann::json results(OSUtils::jsonParse(resp->body));
 
- 						if ((results.is_array())&&(results.size() > 0)) {
 
- 							for(std::size_t ri=0;ri<results.size();++ri) {
 
- 								nlohmann::json &rset = results[ri];
 
- 								if ((rset.is_array())&&(rset.size() > 0)) {
 
- 									nlohmann::json &result = rset[0];
 
- 									if (result.is_object()) {
 
- 										nlohmann::json &record = result["Record"];
 
- 										if (record.is_object()) {
 
- 											const std::string recordValue = result["Value"];
 
- 											printf("GET network %s\n",recordValue.c_str());
 
- 											nlohmann::json network(OSUtils::jsonParse(recordValue));
 
- 											if (network.is_object()) {
 
- 												const std::string idstr = network["id"];
 
- 												const uint64_t id = Utils::hexStrToU64(idstr.c_str());
 
- 												if ((id >> 24) == controllerAddressInt) {
 
- 													std::lock_guard<std::mutex> sl(_state_l);
 
- 													_NetworkState &ns = _state[id];
 
- 													if (!ns.dirty) {
 
- 														nlohmann::json nullJson;
 
- 														_networkChanged(nullJson,network,false);
 
- 													}
 
- 												}
 
- 											}
 
- 										}
 
- 									}
 
- 								}
 
- 							}
 
- 						}
 
- 					} else {
 
- 						fprintf(stderr,"ERROR: LFDB: %d from node: %s" ZT_EOL_S,resp->status,resp->body.c_str());
 
- 					}
 
- 				} else {
 
- 					fprintf(stderr,"ERROR: LFDB: node is offline" ZT_EOL_S);
 
- 				}
 
- 			}
 
- 			{
 
- 				std::ostringstream query;
 
- 				query
 
- 					<< '{'
 
- 						<< "\"Ranges\":[{"
 
- 							<< "\"Name\":\"" << networksSelectorName << "\","
 
- 							<< "\"Range\":[0,18446744073709551615]"
 
- 						<< "},{"
 
- 							<< "\"Name\":\"" << membersSelectorName << "\","
 
- 							<< "\"Range\":[0,18446744073709551615]"
 
- 						<< "}],"
 
- 						<< "\"TimeRange\":[" << timeRangeStart << ",18446744073709551615],"
 
- 						<< "\"MaskingKey\":\"" << maskingKey << "\","
 
- 						<< "\"Owners\":[\"" << _lfOwnerPublic << "\"]"
 
- 					<< '}';
 
- 				auto resp = htcli.Post("/query",query.str(),"application/json");
 
- 				if (resp) {
 
- 					if (resp->status == 200) {
 
- 						nlohmann::json results(OSUtils::jsonParse(resp->body));
 
- 						if ((results.is_array())&&(results.size() > 0)) {
 
- 							for(std::size_t ri=0;ri<results.size();++ri) {
 
- 								nlohmann::json &rset = results[ri];
 
- 								if ((rset.is_array())&&(rset.size() > 0)) {
 
- 									nlohmann::json &result = rset[0];
 
- 									if (result.is_object()) {
 
- 										nlohmann::json &record = result["Record"];
 
- 										if (record.is_object()) {
 
- 											const std::string recordValue = result["Value"];
 
- 											printf("GET member %s\n",recordValue.c_str());
 
- 											nlohmann::json member(OSUtils::jsonParse(recordValue));
 
- 											if (member.is_object()) {
 
- 												const std::string nwidstr = member["nwid"];
 
- 												const std::string idstr = member["id"];
 
- 												const uint64_t nwid = Utils::hexStrToU64(nwidstr.c_str());
 
- 												const uint64_t id = Utils::hexStrToU64(idstr.c_str());
 
- 												if ((id)&&((nwid >> 24) == controllerAddressInt)) {
 
- 													std::lock_guard<std::mutex> sl(_state_l);
 
- 													auto ns = _state.find(nwid);
 
- 													if (ns != _state.end()) {
 
- 														_MemberState &ms = ns->second.members[id];
 
- 														if (!ms.dirty) {
 
- 															nlohmann::json nullJson;
 
- 															_memberChanged(nullJson,member,false);
 
- 														}
 
- 													}
 
- 												}
 
- 											}
 
- 										}
 
- 									}
 
- 								}
 
- 							}
 
- 						}
 
- 					} else {
 
- 						fprintf(stderr,"ERROR: LFDB: %d from node: %s" ZT_EOL_S,resp->status,resp->body.c_str());
 
- 					}
 
- 				} else {
 
- 					fprintf(stderr,"ERROR: LFDB: node is offline" ZT_EOL_S);
 
- 				}
 
- 			}
 
- 			timeRangeStart = time(nullptr) - 120; // start next query 2m before now to avoid losing updates
 
- 			_ready = true;
 
- 			for(int k=0;k<20;++k) { // 2s delay between queries for remotely modified networks or members
 
- 				if (!_running)
 
- 					return;
 
- 				std::this_thread::sleep_for(std::chrono::milliseconds(100));
 
- 			}
 
- 		}
 
- 	});
 
- }
 
- LFDB::~LFDB()
 
- {
 
- 	_running = false;
 
- 	_syncThread.join();
 
- }
 
- bool LFDB::waitForReady()
 
- {
 
- 	while (!_ready) {
 
- 		std::this_thread::sleep_for(std::chrono::milliseconds(100));
 
- 	}
 
- 	return true;
 
- }
 
- bool LFDB::isReady()
 
- {
 
- 	return (_ready);
 
- }
 
- void LFDB::save(nlohmann::json *orig,nlohmann::json &record)
 
- {
 
- 	if (orig) {
 
- 		if (*orig != record) {
 
- 			record["revision"] = OSUtils::jsonInt(record["revision"],0ULL) + 1;
 
- 		}
 
- 	} else {
 
- 		record["revision"] = 1;
 
- 	}
 
- 	const std::string objtype = record["objtype"];
 
- 	if (objtype == "network") {
 
- 		const uint64_t nwid = OSUtils::jsonIntHex(record["id"],0ULL);
 
- 		if (nwid) {
 
- 			nlohmann::json old;
 
- 			get(nwid,old);
 
- 			if ((!old.is_object())||(old != record)) {
 
- 				_networkChanged(old,record,true);
 
- 				{
 
- 					std::lock_guard<std::mutex> l(_state_l);
 
- 					_state[nwid].dirty = true;
 
- 				}
 
- 			}
 
- 		}
 
- 	} else if (objtype == "member") {
 
- 		const uint64_t nwid = OSUtils::jsonIntHex(record["nwid"],0ULL);
 
- 		const uint64_t id = OSUtils::jsonIntHex(record["id"],0ULL);
 
- 		if ((id)&&(nwid)) {
 
- 			nlohmann::json network,old;
 
- 			get(nwid,network,id,old);
 
- 			if ((!old.is_object())||(old != record)) {
 
- 				_memberChanged(old,record,true);
 
- 				{
 
- 					std::lock_guard<std::mutex> l(_state_l);
 
- 					_state[nwid].members[id].dirty = true;
 
- 				}
 
- 			}
 
- 		}
 
- 	}
 
- }
 
- void LFDB::eraseNetwork(const uint64_t networkId)
 
- {
 
- 	// TODO
 
- }
 
- void LFDB::eraseMember(const uint64_t networkId,const uint64_t memberId)
 
- {
 
- 	// TODO
 
- }
 
- void LFDB::nodeIsOnline(const uint64_t networkId,const uint64_t memberId,const InetAddress &physicalAddress)
 
- {
 
- 	std::lock_guard<std::mutex> l(_state_l);
 
- 	auto nw = _state.find(networkId);
 
- 	if (nw != _state.end()) {
 
- 		auto m = nw->second.members.find(memberId);
 
- 		if (m != nw->second.members.end()) {
 
- 			m->second.lastOnlineTime = OSUtils::now();
 
- 			if (physicalAddress)
 
- 				m->second.lastOnlineAddress = physicalAddress;
 
- 			m->second.lastOnlineDirty = true;
 
- 		}
 
- 	}
 
- }
 
- } // namespace ZeroTier
 
 
  |