blob: a1475708d9dea8d96b865b5aeadcefaa2d06387e [file] [log] [blame]
Radek Krejci469aab82012-07-22 18:42:20 +02001/*!
2 * \file mod_netconf.c
3 * \brief NETCONF Apache modul for Netopeer
4 * \author Tomas Cejka <cejkat@cesnet.cz>
5 * \author Radek Krejci <rkrejci@cesnet.cz>
6 * \date 2011
7 * \date 2012
8 */
9/*
10 * Copyright (C) 2011-2012 CESNET
11 *
12 * LICENSE TERMS
13 *
14 * Redistribution and use in source and binary forms, with or without
15 * modification, are permitted provided that the following conditions
16 * are met:
17 * 1. Redistributions of source code must retain the above copyright
18 * notice, this list of conditions and the following disclaimer.
19 * 2. Redistributions in binary form must reproduce the above copyright
20 * notice, this list of conditions and the following disclaimer in
21 * the documentation and/or other materials provided with the
22 * distribution.
23 * 3. Neither the name of the Company nor the names of its contributors
24 * may be used to endorse or promote products derived from this
25 * software without specific prior written permission.
26 *
27 * ALTERNATIVELY, provided that this notice is retained in full, this
28 * product may be distributed under the terms of the GNU General Public
29 * License (GPL) version 2 or later, in which case the provisions
30 * of the GPL apply INSTEAD OF those given above.
31 *
32 * This software is provided ``as is'', and any express or implied
33 * warranties, including, but not limited to, the implied warranties of
34 * merchantability and fitness for a particular purpose are disclaimed.
35 * In no event shall the company or contributors be liable for any
36 * direct, indirect, incidental, special, exemplary, or consequential
37 * damages (including, but not limited to, procurement of substitute
38 * goods or services; loss of use, data, or profits; or business
39 * interruption) however caused and on any theory of liability, whether
40 * in contract, strict liability, or tort (including negligence or
41 * otherwise) arising in any way out of the use of this software, even
42 * if advised of the possibility of such damage.
43 *
44 */
45
46#include "httpd.h"
47#include "http_config.h"
48#include "http_protocol.h"
49#include "http_request.h"
50#include "ap_config.h"
51#include "http_log.h"
52#include "apu.h"
53#include "apr_general.h"
54#include "apr_sha1.h"
55#include "apr_file_io.h"
56
57#include <unixd.h>
58#include <apr_base64.h>
59#include <apr_pools.h>
60#include <apr_general.h>
61#include <apr_hash.h>
62#include <apr_strings.h>
63#include <apr_thread_proc.h>
64#include <apr_signal.h>
65
66#include <sys/types.h>
67#include <sys/socket.h>
68#include <sys/un.h>
69#include <stdlib.h>
70#include <stdio.h>
71#include <poll.h>
72#include <unistd.h>
73#include <string.h>
74#include <errno.h>
75
Radek Krejci8fd1f5e2012-07-24 17:33:36 +020076#include <json/json.h>
77
Radek Krejci469aab82012-07-22 18:42:20 +020078#include <libnetconf.h>
79#include <libxml/tree.h>
80#include <libxml/parser.h>
81
82#define MAX_PROCS 5
Radek Krejci6cb08982012-07-25 18:01:06 +020083#define SOCKET_FILENAME "/tmp/mod_netconf.sock"
Radek Krejci469aab82012-07-22 18:42:20 +020084#define MAX_SOCKET_CL 10
85#define BUFFER_SIZE 4096
86
87/* sleep in master process for non-blocking socket reading */
88#define SLEEP_TIME 200
89
90#ifndef offsetof
91#define offsetof(type, member) ((size_t) ((type *) 0)->member)
92#endif
93
94struct timeval timeout = { 1, 0 };
95
Radek Krejci8fd1f5e2012-07-24 17:33:36 +020096typedef enum MSG_TYPE {
97 REPLY_OK,
98 REPLY_DATA,
99 REPLY_ERROR,
100 MSG_CONNECT,
101 MSG_DISCONNECT,
102 MSG_GET,
103 MSG_GETCONFIG,
104 MSG_EDITCONFIG,
105 MSG_COPYCONFIG,
106 MSG_DELETECONFIG,
107 MSG_LOCK,
108 MSG_UNLOCK,
109 MSG_KILL
110} MSG_TYPE;
111
Radek Krejci469aab82012-07-22 18:42:20 +0200112#define MSG_OK 0
113#define MSG_OPEN 1
114#define MSG_DATA 2
115#define MSG_CLOSE 3
116#define MSG_ERROR 4
117#define MSG_UNKNOWN 5
118
Radek Krejci469aab82012-07-22 18:42:20 +0200119module AP_MODULE_DECLARE_DATA netconf_module;
120
121typedef struct {
Radek Krejci469aab82012-07-22 18:42:20 +0200122 apr_pool_t *pool;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200123 apr_proc_t *forkproc;
124 char* sockname;
Radek Krejcif23850c2012-07-23 16:14:17 +0200125} mod_netconf_cfg;
Radek Krejci469aab82012-07-22 18:42:20 +0200126
127volatile int isterminated = 0;
128
129static char* password;
130
131
132static void signal_handler(int sign)
133{
134 switch (sign) {
135 case SIGTERM:
136 isterminated = 1;
Radek Krejci469aab82012-07-22 18:42:20 +0200137 break;
138 }
139}
140
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200141static char* gen_ncsession_hash( const char* hostname, const char* port, const char* sid)
Radek Krejci469aab82012-07-22 18:42:20 +0200142{
Radek Krejcif23850c2012-07-23 16:14:17 +0200143 unsigned char hash_raw[APR_SHA1_DIGESTSIZE];
144 int i;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200145 char* hash;
Radek Krejcif23850c2012-07-23 16:14:17 +0200146
Radek Krejci469aab82012-07-22 18:42:20 +0200147 apr_sha1_ctx_t sha1_ctx;
148 apr_sha1_init(&sha1_ctx);
149 apr_sha1_update(&sha1_ctx, hostname, strlen(hostname));
150 apr_sha1_update(&sha1_ctx, port, strlen(port));
151 apr_sha1_update(&sha1_ctx, sid, strlen(sid));
Radek Krejcif23850c2012-07-23 16:14:17 +0200152 apr_sha1_final(hash_raw, &sha1_ctx);
Radek Krejci469aab82012-07-22 18:42:20 +0200153
Radek Krejcif23850c2012-07-23 16:14:17 +0200154 /* convert binary hash into hex string, which is printable */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200155 hash = malloc(sizeof(char) * ((2*APR_SHA1_DIGESTSIZE)+1));
Radek Krejcif23850c2012-07-23 16:14:17 +0200156 for (i = 0; i < APR_SHA1_DIGESTSIZE; i++) {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200157 snprintf(hash + (2*i), 3, "%02x", hash_raw[i]);
Radek Krejcif23850c2012-07-23 16:14:17 +0200158 }
159 //hash[2*APR_SHA1_DIGESTSIZE] = 0;
Radek Krejci469aab82012-07-22 18:42:20 +0200160
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200161 return (hash);
Radek Krejci469aab82012-07-22 18:42:20 +0200162}
163
164int netconf_callback_ssh_hostkey_check (const char* hostname, int keytype, const char* fingerprint)
165{
166 /* always approve */
167 return (EXIT_SUCCESS);
168}
169
170char* netconf_callback_sshauth_password (const char* username, const char* hostname)
171{
172 char* buf;
173
174 buf = malloc ((strlen(password) + 1) * sizeof(char));
175 apr_cpystrn(buf, password, strlen(password) + 1);
176
177 return (buf);
178}
179
180void netconf_callback_sshauth_interactive (const char* name,
181 int name_len,
182 const char* instruction,
183 int instruction_len,
184 int num_prompts,
185 const LIBSSH2_USERAUTH_KBDINT_PROMPT* prompts,
186 LIBSSH2_USERAUTH_KBDINT_RESPONSE* responses,
187 void** abstract)
188{
189 int i;
190
191 for (i=0; i<num_prompts; i++) {
192 responses[i].text = malloc ((strlen(password) + 1) * sizeof(char));
193 apr_cpystrn(responses[i].text, password, strlen(password) + 1);
194 responses[i].length = strlen(responses[i].text) + 1;
195 }
196
197 return;
198}
199
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200200static char* netconf_connect(server_rec* server, apr_pool_t* pool, apr_hash_t* conns, const char* host, const char* port, const char* user, const char* pass)
Radek Krejci469aab82012-07-22 18:42:20 +0200201{
Radek Krejci469aab82012-07-22 18:42:20 +0200202 struct nc_session* session;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200203 char *sid;
Radek Krejcif23850c2012-07-23 16:14:17 +0200204 char *session_key;
Radek Krejci469aab82012-07-22 18:42:20 +0200205
206 /* connect to the requested NETCONF server */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200207 password = (char*)pass;
208 session = nc_session_connect(host, (unsigned short) atoi (port), user, NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200209
210 /* if connected successful, add session to the list */
211 if (session != NULL) {
212 /* generate hash for the session */
213 sid = nc_session_get_id(session);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200214 session_key = gen_ncsession_hash(host, port, sid);
Radek Krejci469aab82012-07-22 18:42:20 +0200215 free(sid);
Radek Krejcif23850c2012-07-23 16:14:17 +0200216 apr_hash_set(conns, apr_pstrdup(pool, session_key), APR_HASH_KEY_STRING, (void *) session);
Radek Krejci469aab82012-07-22 18:42:20 +0200217 ap_log_error(APLOG_MARK, APLOG_NOTICE, 0, server, "NETCONF session established");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200218 return (session_key);
Radek Krejci469aab82012-07-22 18:42:20 +0200219 } else {
220 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Connection could not be established");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200221 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200222 }
223
Radek Krejci469aab82012-07-22 18:42:20 +0200224}
225
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200226static int netconf_close(server_rec* server, apr_hash_t* conns, char* session_key)
Radek Krejci469aab82012-07-22 18:42:20 +0200227{
228 struct nc_session *ns = NULL;
Radek Krejci469aab82012-07-22 18:42:20 +0200229
Radek Krejcif23850c2012-07-23 16:14:17 +0200230 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Key in hash to get: %s", session_key);
Radek Krejci469aab82012-07-22 18:42:20 +0200231 ns = (struct nc_session *)apr_hash_get(conns, session_key, APR_HASH_KEY_STRING);
232 if (ns != NULL) {
233 nc_session_close (ns, "NETCONF session closed by client");
234 nc_session_free (ns);
235 ns = NULL;
236
237 /* remove session from the active sessions list */
238 apr_hash_set(conns, session_key, APR_HASH_KEY_STRING, NULL);
239 ap_log_error(APLOG_MARK, APLOG_NOTICE, 0, server, "NETCONF session closed");
Radek Krejcif23850c2012-07-23 16:14:17 +0200240
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200241 return (EXIT_SUCCESS);
Radek Krejci469aab82012-07-22 18:42:20 +0200242 } else {
243 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown session to close");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200244 return (EXIT_FAILURE);
Radek Krejci469aab82012-07-22 18:42:20 +0200245 }
246}
247
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200248static char* netconf_getconfig(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE source, const char* filter)
Radek Krejci469aab82012-07-22 18:42:20 +0200249{
250 struct nc_session *session = NULL;
Radek Krejci469aab82012-07-22 18:42:20 +0200251 nc_rpc* rpc;
252 nc_reply* reply;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200253 char* data;
254 struct nc_filter *f = NULL;
Radek Krejci469aab82012-07-22 18:42:20 +0200255
256 session = (struct nc_session *)apr_hash_get(conns, session_key, APR_HASH_KEY_STRING);
257 if (session != NULL) {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200258 /* create filter if set */
259 if (filter != NULL) {
260 f = nc_filter_new(NC_FILTER_SUBTREE, filter);
261 }
262
Radek Krejci469aab82012-07-22 18:42:20 +0200263 /* create requests */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200264 rpc = nc_rpc_getconfig (source, f);
265 nc_filter_free(f);
Radek Krejci469aab82012-07-22 18:42:20 +0200266 if (rpc == NULL) {
267 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200268 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200269 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200270
Radek Krejci469aab82012-07-22 18:42:20 +0200271 /* send the request and get the reply */
272 nc_session_send_rpc (session, rpc);
273 if (nc_session_recv_reply (session, &reply) == 0) {
274 nc_rpc_free (rpc);
275 if (nc_session_get_status(session) != NC_SESSION_STATUS_WORKING) {
276 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: receiving rpc-reply failed");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200277 netconf_close(server, conns, session_key);
278 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200279 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200280
Radek Krejci469aab82012-07-22 18:42:20 +0200281 /* there is error handled by callback */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200282 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200283 }
284 nc_rpc_free (rpc);
285
286 switch (nc_reply_get_type (reply)) {
287 case NC_REPLY_DATA:
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200288 if ((data = nc_reply_get_data (reply)) == NULL) {
289 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: no data from reply");
290 return (NULL);
291 }
Radek Krejci469aab82012-07-22 18:42:20 +0200292 break;
293 default:
294 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: unexpected rpc-reply");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200295 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200296 }
297 nc_reply_free(reply);
298
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200299 return (data);
Radek Krejci469aab82012-07-22 18:42:20 +0200300 } else {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200301 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown session to process.");
302 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200303 }
Radek Krejci469aab82012-07-22 18:42:20 +0200304}
305
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200306static char* netconf_get(server_rec* server, apr_hash_t* conns, char* session_key, const char* filter)
Radek Krejci469aab82012-07-22 18:42:20 +0200307{
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200308 struct nc_session *session = NULL;
309 nc_rpc* rpc;
310 nc_reply* reply;
Radek Krejci035bf4e2012-07-25 10:59:09 +0200311 char* data = NULL;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200312 struct nc_filter *f = NULL;
Radek Krejci469aab82012-07-22 18:42:20 +0200313
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200314 session = (struct nc_session *)apr_hash_get(conns, session_key, APR_HASH_KEY_STRING);
315 if (session != NULL) {
316 /* create filter if set */
317 if (filter != NULL) {
318 f = nc_filter_new(NC_FILTER_SUBTREE, filter);
319 }
Radek Krejci469aab82012-07-22 18:42:20 +0200320
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200321 /* create requests */
322 rpc = nc_rpc_get (f);
323 nc_filter_free(f);
324 if (rpc == NULL) {
325 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
326 return (NULL);
327 }
Radek Krejci469aab82012-07-22 18:42:20 +0200328
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200329 /* send the request and get the reply */
330 nc_session_send_rpc (session, rpc);
331 if (nc_session_recv_reply (session, &reply) == 0) {
332 nc_rpc_free (rpc);
333 if (nc_session_get_status(session) != NC_SESSION_STATUS_WORKING) {
334 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: receiving rpc-reply failed");
335 netconf_close(server, conns, session_key);
336 return (NULL);
337 }
338
339 /* there is error handled by callback */
340 return (NULL);
341 }
342 nc_rpc_free (rpc);
343
344 switch (nc_reply_get_type (reply)) {
345 case NC_REPLY_DATA:
346 if ((data = nc_reply_get_data (reply)) == NULL) {
347 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: no data from reply");
348 return (NULL);
349 }
350 break;
351 default:
352 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: unexpected rpc-reply");
Radek Krejci035bf4e2012-07-25 10:59:09 +0200353 data = NULL; /* error return code */
354 break;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200355 }
356 nc_reply_free(reply);
357
358 return (data);
359 } else {
360 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown session to process.");
361 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200362 }
363}
364
Radek Krejci035bf4e2012-07-25 10:59:09 +0200365static int netconf_copyconfig(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE source, NC_DATASTORE target)
366{
367 struct nc_session *session = NULL;
368 nc_rpc* rpc;
369 nc_reply* reply;
370 int retval = EXIT_SUCCESS;
371
372 session = (struct nc_session *)apr_hash_get(conns, session_key, APR_HASH_KEY_STRING);
373 if (session != NULL) {
374 /* create requests */
375 rpc = nc_rpc_copyconfig(source, target, NULL);
376 if (rpc == NULL) {
377 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
378 return (EXIT_FAILURE);
379 }
Radek Krejci035bf4e2012-07-25 10:59:09 +0200380
381 /* send the request and get the reply */
382 nc_session_send_rpc (session, rpc);
Radek Krejci035bf4e2012-07-25 10:59:09 +0200383 if (nc_session_recv_reply (session, &reply) == 0) {
Radek Krejci035bf4e2012-07-25 10:59:09 +0200384 nc_rpc_free (rpc);
Radek Krejci035bf4e2012-07-25 10:59:09 +0200385 if (nc_session_get_status(session) != NC_SESSION_STATUS_WORKING) {
Radek Krejci035bf4e2012-07-25 10:59:09 +0200386 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: receiving rpc-reply failed");
Radek Krejci035bf4e2012-07-25 10:59:09 +0200387 netconf_close(server, conns, session_key);
Radek Krejci035bf4e2012-07-25 10:59:09 +0200388 return (EXIT_FAILURE);
389 }
390
391 /* there is error handled by callback */
392 return (EXIT_FAILURE);
393 }
Radek Krejci035bf4e2012-07-25 10:59:09 +0200394 nc_rpc_free (rpc);
Radek Krejci035bf4e2012-07-25 10:59:09 +0200395
396 switch (nc_reply_get_type (reply)) {
397 case NC_REPLY_OK:
398 retval = EXIT_SUCCESS;
399 break;
400 default:
401 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: unexpected rpc-reply");
402 retval = EXIT_FAILURE;
403 break;
404 }
405 nc_reply_free(reply);
406 return (retval);
407 } else {
408 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown session to process.");
409 return (EXIT_FAILURE);
410 }
411}
412
Radek Krejci469aab82012-07-22 18:42:20 +0200413server_rec* clb_print_server;
414int clb_print(const char* msg)
415{
416 ap_log_error(APLOG_MARK, APLOG_INFO, 0, clb_print_server, msg);
417 return (0);
418}
419
Radek Krejcif23850c2012-07-23 16:14:17 +0200420/*
421 * This is actually implementation of NETCONF client
422 * - requests are received from UNIX socket in the predefined format
423 * - results are replied through the same way
424 * - the daemon run as a separate process, but it is started and stopped
425 * automatically by Apache.
426 *
427 */
Radek Krejci469aab82012-07-22 18:42:20 +0200428static void forked_proc(apr_pool_t * pool, server_rec * server)
429{
430 struct sockaddr_un local, remote;
431 int lsock, client;
432 socklen_t len, len2;
433 struct pollfd fds;
434 int status;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200435 mod_netconf_cfg *config;
436 json_object *request, *reply;
437 int operation;
438 char* session_key, *data;
439 const char *msgtext;
440 const char *host, *port, *user, *pass;
441 const char *target, *source, *filter;
442 NC_DATASTORE ds_type1, ds_type2;
Radek Krejci469aab82012-07-22 18:42:20 +0200443
444 apr_hash_t *netconf_sessions_list;
445 char buffer[BUFFER_SIZE];
Radek Krejci469aab82012-07-22 18:42:20 +0200446
Radek Krejcif23850c2012-07-23 16:14:17 +0200447 /* change uid and gid of process for security reasons */
Radek Krejci469aab82012-07-22 18:42:20 +0200448 unixd_setup_child();
449
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200450 config = ap_get_module_config(server->module_config, &netconf_module);
451 if (config == NULL) {
452 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Getting mod_netconf configuration failed");
453 return;
454 }
Radek Krejci469aab82012-07-22 18:42:20 +0200455
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200456 /* create listening UNIX socket to accept incoming connections */
Radek Krejci469aab82012-07-22 18:42:20 +0200457 if ((lsock = socket(PF_UNIX, SOCK_STREAM, 0)) == -1) {
458 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Creating socket failed (%s)", strerror(errno));
459 return;
460 }
461
462 local.sun_family = AF_UNIX;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200463 strncpy(local.sun_path, config->sockname, sizeof(local.sun_path));
Radek Krejci469aab82012-07-22 18:42:20 +0200464 unlink(local.sun_path);
465 len = offsetof(struct sockaddr_un, sun_path) + strlen(local.sun_path);
466
467 if (bind(lsock, (struct sockaddr *) &local, len) == -1) {
468 if (errno == EADDRINUSE) {
469 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "mod_netconf socket address already in use");
470 close(lsock);
471 exit(0);
472 }
473 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Binding socket failed (%s)", strerror(errno));
474 close(lsock);
475 return;
476 }
477
478 if (listen(lsock, MAX_SOCKET_CL) == -1) {
479 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Setting up listen socket failed (%s)", strerror(errno));
480 close(lsock);
481 return;
482 }
483
484 /* prepare internal lists */
485 netconf_sessions_list = apr_hash_make(pool);
486
487 /* setup libnetconf's callbacks */
488 nc_verbosity(NC_VERB_DEBUG);
489 clb_print_server = server;
490 nc_callback_print(clb_print);
491 nc_callback_ssh_host_authenticity_check(netconf_callback_ssh_hostkey_check);
492 nc_callback_sshauth_interactive(netconf_callback_sshauth_interactive);
493 nc_callback_sshauth_password(netconf_callback_sshauth_password);
494
495 /* disable publickey authentication */
496 nc_ssh_pref(NC_SSH_AUTH_PUBLIC_KEYS, -1);
497
498 while (isterminated == 0) {
499 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "waiting for another client's request");
500
501 /* open incoming connection if any */
502 len2 = sizeof(remote);
503 client = accept(lsock, (struct sockaddr *) &remote, &len2);
504 if (client == -1 && (errno == EAGAIN || errno == EWOULDBLOCK)) {
505 apr_sleep(SLEEP_TIME);
506 continue;
507 } else if (client == -1 && (errno == EINTR)) {
508 continue;
509 } else if (client == -1) {
510 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Accepting mod_netconf client connection failed (%s)", strerror(errno));
511 continue;
512 }
513 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "client's socket accepted.");
514
515 /* set client's socket as non-blocking */
Radek Krejcif23850c2012-07-23 16:14:17 +0200516 //fcntl(client, F_SETFL, fcntl(client, F_GETFL, 0) | O_NONBLOCK);
Radek Krejci469aab82012-07-22 18:42:20 +0200517
518 while (1) {
519 fds.fd = client;
520 fds.events = POLLIN;
521 fds.revents = 0;
522
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200523 status = poll(&fds, 1, 1000);
Radek Krejci469aab82012-07-22 18:42:20 +0200524
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200525 if (status == 0 || (status == -1 && (errno == EAGAIN || (errno == EINTR && isterminated == 0)))) {
Radek Krejci469aab82012-07-22 18:42:20 +0200526 /* poll was interrupted - check if the isterminated is set and if not, try poll again */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200527 //ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "poll interrupted");
Radek Krejci469aab82012-07-22 18:42:20 +0200528 continue;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200529 } else if (status < 0) {
Radek Krejci469aab82012-07-22 18:42:20 +0200530 /* 0: poll time outed
531 * close socket and ignore this request from the client, it can try it again
532 * -1: poll failed
533 * something wrong happend, close this socket and wait for another request
534 */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200535 //ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "poll failed, status %d(%d: %s)", status, errno, strerror(errno));
Radek Krejci469aab82012-07-22 18:42:20 +0200536 close(client);
537 break;
538 }
539 /* status > 0 */
540
541 /* check the status of the socket */
542
543 /* if nothing to read and POLLHUP (EOF) or POLLERR set */
544 if ((fds.revents & POLLHUP) || (fds.revents & POLLERR)) {
545 /* close client's socket (it's probably already closed by client */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200546 //ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "socket error (%d)", fds.revents);
Radek Krejci469aab82012-07-22 18:42:20 +0200547 close(client);
548 break;
549 }
550
551 if ((len2 = recv(client, buffer, BUFFER_SIZE, 0)) <= 0) {
552 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "receiving failed %d (%s)", errno, strerror(errno));
553 continue;
554 } else {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200555 request = json_tokener_parse(buffer);
556 operation = json_object_get_int(json_object_object_get(request, "type"));
Radek Krejci469aab82012-07-22 18:42:20 +0200557
Radek Krejci035bf4e2012-07-25 10:59:09 +0200558 session_key = (char*) json_object_get_string(json_object_object_get(request, "session"));
559 /* DO NOT FREE session_key HERE, IT IS PART OF REQUEST */
560 if (operation != MSG_CONNECT && session_key == NULL) {
561 reply = json_object_new_object();
562 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
563 json_object_object_add(reply, "error-message", json_object_new_string("Missing session specification."));
564 msgtext = json_object_to_json_string(reply);
565 send(client, msgtext, strlen(msgtext) + 1, 0);
566 json_object_put(reply);
567 /* there is some stupid client, so close the connection to give a chance to some other client */
568 close(client);
569 break;
570 }
571
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200572 switch (operation) {
573 case MSG_CONNECT:
574 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: Connect");
575
576 host = json_object_get_string(json_object_object_get(request, "host"));
577 port = json_object_get_string(json_object_object_get(request, "port"));
578 user = json_object_get_string(json_object_object_get(request, "user"));
579 pass = json_object_get_string(json_object_object_get(request, "pass"));
580 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "host: %s, port: %s, user: %s", host, port, user);
581 session_key = netconf_connect(server, pool, netconf_sessions_list, host, port, user, pass);
582 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "hash: %s", session_key);
583
584 reply = json_object_new_object();
585 if (session_key == NULL) {
586 /* negative reply */
587 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
588 json_object_object_add(reply, "error-message", json_object_new_string("Connecting NETCONF server failed."));
589 } else {
590 /* positive reply */
591 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
592 json_object_object_add(reply, "session", json_object_new_string(session_key));
593 }
594
595 free(session_key);
Radek Krejci469aab82012-07-22 18:42:20 +0200596 break;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200597 case MSG_GET:
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200598 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: get-config (session %s)", session_key);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200599
600 filter = json_object_get_string(json_object_object_get(request, "filter"));
601
602 reply = json_object_new_object();
603
604 if ((data = netconf_get(server, netconf_sessions_list, session_key, filter)) == NULL) {
605 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
Radek Krejci035bf4e2012-07-25 10:59:09 +0200606 json_object_object_add(reply, "error-message", json_object_new_string("get failed."));
607 } else {
608 json_object_object_add(reply, "type", json_object_new_int(REPLY_DATA));
609 json_object_object_add(reply, "data", json_object_new_string(data));
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200610 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200611 break;
612 case MSG_GETCONFIG:
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200613 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: get-config (session %s)", session_key);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200614
615 source = json_object_get_string(json_object_object_get(request, "source"));
616 filter = json_object_get_string(json_object_object_get(request, "filter"));
617
Radek Krejci035bf4e2012-07-25 10:59:09 +0200618 reply = json_object_new_object();
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200619
620 if (strcmp(source, "running") == 0) {
621 ds_type1 = NC_DATASTORE_RUNNING;
622 } else if (strcmp(source, "startup") == 0) {
623 ds_type1 = NC_DATASTORE_STARTUP;
624 } else if (strcmp(source, "candidate") == 0) {
625 ds_type1 = NC_DATASTORE_CANDIDATE;
626 } else {
627 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
Radek Krejci035bf4e2012-07-25 10:59:09 +0200628 json_object_object_add(reply, "error-message", json_object_new_string("Invalid source repository type requested."));
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200629 break;
630 }
631
632 if ((data = netconf_getconfig(server, netconf_sessions_list, session_key, ds_type1, filter)) == NULL) {
633 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
634 json_object_object_add(reply, "error-message", json_object_new_string("get-config failed."));
Radek Krejci035bf4e2012-07-25 10:59:09 +0200635 } else {
636 json_object_object_add(reply, "type", json_object_new_int(REPLY_DATA));
637 json_object_object_add(reply, "data", json_object_new_string(data));
638 }
639 break;
640 case MSG_COPYCONFIG:
641 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: copy-config (session %s)", session_key);
642
643 source = json_object_get_string(json_object_object_get(request, "source"));
644 target = json_object_get_string(json_object_object_get(request, "target"));
645
646 reply = json_object_new_object();
647
648 if (strcmp(source, "running") == 0) {
649 ds_type1 = NC_DATASTORE_RUNNING;
650 } else if (strcmp(source, "startup") == 0) {
651 ds_type1 = NC_DATASTORE_STARTUP;
652 } else if (strcmp(source, "candidate") == 0) {
653 ds_type1 = NC_DATASTORE_CANDIDATE;
654 } else {
655 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
656 json_object_object_add(reply, "error-message", json_object_new_string("Invalid source repository type requested."));
657 break;
658 }
659 if (strcmp(target, "running") == 0) {
660 ds_type2 = NC_DATASTORE_RUNNING;
661 } else if (strcmp(target, "startup") == 0) {
662 ds_type2 = NC_DATASTORE_STARTUP;
663 } else if (strcmp(target, "candidate") == 0) {
664 ds_type2 = NC_DATASTORE_CANDIDATE;
665 } else {
666 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
667 json_object_object_add(reply, "error-message", json_object_new_string("Invalid target repository type requested."));
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200668 break;
669 }
670
Radek Krejci035bf4e2012-07-25 10:59:09 +0200671 if (netconf_copyconfig(server, netconf_sessions_list, session_key, ds_type1, ds_type2) != EXIT_SUCCESS) {
672 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
673 json_object_object_add(reply, "error-message", json_object_new_string("copy-config failed."));
674 } else {
675 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
676 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200677 break;
678 case MSG_DISCONNECT:
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200679 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: Disconnect session %s", session_key);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200680
681 reply = json_object_new_object();
682 if (netconf_close(server, netconf_sessions_list, session_key) != EXIT_SUCCESS) {
683 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
684 json_object_object_add(reply, "error-message", json_object_new_string("Invalid session identifier."));
685 } else {
686 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
687 }
688 break;
689 default:
690 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown mod_netconf operation requested (%d)", operation);
691 reply = json_object_new_object();
692 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
693 json_object_object_add(reply, "error-message", json_object_new_string("Operation not supported."));
694 break;
695 }
696 json_object_put(request);
697
698 /* send reply to caller */
699 if (reply != NULL) {
700 msgtext = json_object_to_json_string(reply);
701 send(client, msgtext, strlen(msgtext) + 1, 0);
702 json_object_put(reply);
703 } else {
704 break;
705 }
Radek Krejci469aab82012-07-22 18:42:20 +0200706 }
707 }
708 }
709
710 close(lsock);
711
712 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Exiting from the mod_netconf daemon");
713
714 exit(APR_SUCCESS);
715}
716
Radek Krejcif23850c2012-07-23 16:14:17 +0200717static void *mod_netconf_create_conf(apr_pool_t * pool, server_rec * s)
Radek Krejci469aab82012-07-22 18:42:20 +0200718{
Radek Krejcif23850c2012-07-23 16:14:17 +0200719 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, s, "Init netconf module config");
720
721 mod_netconf_cfg *config = apr_pcalloc(pool, sizeof(mod_netconf_cfg));
722 apr_pool_create(&config->pool, pool);
723 config->forkproc = NULL;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200724 config->sockname = SOCKET_FILENAME;
Radek Krejcif23850c2012-07-23 16:14:17 +0200725
726 return (void *)config;
Radek Krejci469aab82012-07-22 18:42:20 +0200727}
728
729static int mod_netconf_master_init(apr_pool_t * pconf, apr_pool_t * ptemp,
730 apr_pool_t * plog, server_rec * s)
731{
Radek Krejcif23850c2012-07-23 16:14:17 +0200732 mod_netconf_cfg *config;
733 apr_status_t res;
734
Radek Krejci469aab82012-07-22 18:42:20 +0200735 /* These two help ensure that we only init once. */
736 void *data;
Radek Krejcif23850c2012-07-23 16:14:17 +0200737 const char *userdata_key = "netconf_ipc_init";
Radek Krejci469aab82012-07-22 18:42:20 +0200738
739 /*
740 * The following checks if this routine has been called before.
741 * This is necessary because the parent process gets initialized
742 * a couple of times as the server starts up.
743 */
744 apr_pool_userdata_get(&data, userdata_key, s->process->pool);
745 if (!data) {
746 apr_pool_userdata_set((const void *)1, userdata_key, apr_pool_cleanup_null, s->process->pool);
747 return (OK);
748 }
749
Radek Krejcif23850c2012-07-23 16:14:17 +0200750 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, s, "creating mod_netconf daemon");
751 config = ap_get_module_config(s->module_config, &netconf_module);
Radek Krejcidfaa6ea2012-07-23 09:04:43 +0200752
Radek Krejcif23850c2012-07-23 16:14:17 +0200753 if (config && config->forkproc == NULL) {
754 config->forkproc = apr_pcalloc(config->pool, sizeof(apr_proc_t));
755 res = apr_proc_fork(config->forkproc, config->pool);
Radek Krejci469aab82012-07-22 18:42:20 +0200756 switch (res) {
757 case APR_INCHILD:
758 /* set signal handler */
Radek Krejcif23850c2012-07-23 16:14:17 +0200759 apr_signal_init(config->pool);
Radek Krejci469aab82012-07-22 18:42:20 +0200760 apr_signal(SIGTERM, signal_handler);
761
762 /* log start of the separated NETCONF communication process */
Radek Krejcif23850c2012-07-23 16:14:17 +0200763 ap_log_error(APLOG_MARK, APLOG_NOTICE, 0, s, "mod_netconf daemon started (PID %d)", getpid());
Radek Krejci469aab82012-07-22 18:42:20 +0200764
765 /* start main loop providing NETCONF communication */
Radek Krejcif23850c2012-07-23 16:14:17 +0200766 forked_proc(config->pool, s);
Radek Krejci469aab82012-07-22 18:42:20 +0200767
Radek Krejcif23850c2012-07-23 16:14:17 +0200768 /* I never should be here, wtf?!? */
769 ap_log_error(APLOG_MARK, APLOG_ERR, 0, s, "mod_netconf daemon unexpectedly stopped");
Radek Krejci469aab82012-07-22 18:42:20 +0200770 exit(APR_EGENERAL);
771 break;
772 case APR_INPARENT:
773 /* register child to be killed (SIGTERM) when the module config's pool dies */
Radek Krejcif23850c2012-07-23 16:14:17 +0200774 apr_pool_note_subprocess(config->pool, config->forkproc, APR_KILL_AFTER_TIMEOUT);
Radek Krejci469aab82012-07-22 18:42:20 +0200775 break;
776 default:
777 ap_log_error(APLOG_MARK, APLOG_ERR, 0, s, "apr_proc_fork() failed");
778 break;
779 }
Radek Krejcif23850c2012-07-23 16:14:17 +0200780 } else {
781 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, s, "mod_netconf misses configuration structure");
Radek Krejci469aab82012-07-22 18:42:20 +0200782 }
783
784 return OK;
785}
786
Radek Krejci469aab82012-07-22 18:42:20 +0200787/**
788 * Register module hooks
789 */
790static void mod_netconf_register_hooks(apr_pool_t * p)
791{
Radek Krejcif23850c2012-07-23 16:14:17 +0200792 ap_hook_post_config(mod_netconf_master_init, NULL, NULL, APR_HOOK_LAST);
Radek Krejci469aab82012-07-22 18:42:20 +0200793}
794
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200795static const char* cfg_set_socket_path(cmd_parms* cmd, void* cfg, const char* arg)
796{
797 ((mod_netconf_cfg*)cfg)->sockname = apr_pstrdup(cmd->pool, arg);
798 return NULL;
799}
800
801static const command_rec netconf_cmds[] = {
802 AP_INIT_TAKE1("NetconfSocket", cfg_set_socket_path, NULL, OR_ALL, "UNIX socket path for mod_netconf communication."),
803 {NULL}
804};
805
Radek Krejci469aab82012-07-22 18:42:20 +0200806/* Dispatch list for API hooks */
807module AP_MODULE_DECLARE_DATA netconf_module = {
808 STANDARD20_MODULE_STUFF,
809 NULL, /* create per-dir config structures */
810 NULL, /* merge per-dir config structures */
Radek Krejcif23850c2012-07-23 16:14:17 +0200811 mod_netconf_create_conf, /* create per-server config structures */
Radek Krejci469aab82012-07-22 18:42:20 +0200812 NULL, /* merge per-server config structures */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200813 netconf_cmds, /* table of config file commands */
Radek Krejci469aab82012-07-22 18:42:20 +0200814 mod_netconf_register_hooks /* register hooks */
815};