blob: e6f69acda1439a34baae86724ebfd450b5806b7d [file] [log] [blame]
Radek Krejci469aab82012-07-22 18:42:20 +02001/*!
2 * \file mod_netconf.c
3 * \brief NETCONF Apache modul for Netopeer
4 * \author Tomas Cejka <cejkat@cesnet.cz>
5 * \author Radek Krejci <rkrejci@cesnet.cz>
6 * \date 2011
7 * \date 2012
8 */
9/*
10 * Copyright (C) 2011-2012 CESNET
11 *
12 * LICENSE TERMS
13 *
14 * Redistribution and use in source and binary forms, with or without
15 * modification, are permitted provided that the following conditions
16 * are met:
17 * 1. Redistributions of source code must retain the above copyright
18 * notice, this list of conditions and the following disclaimer.
19 * 2. Redistributions in binary form must reproduce the above copyright
20 * notice, this list of conditions and the following disclaimer in
21 * the documentation and/or other materials provided with the
22 * distribution.
23 * 3. Neither the name of the Company nor the names of its contributors
24 * may be used to endorse or promote products derived from this
25 * software without specific prior written permission.
26 *
27 * ALTERNATIVELY, provided that this notice is retained in full, this
28 * product may be distributed under the terms of the GNU General Public
29 * License (GPL) version 2 or later, in which case the provisions
30 * of the GPL apply INSTEAD OF those given above.
31 *
32 * This software is provided ``as is'', and any express or implied
33 * warranties, including, but not limited to, the implied warranties of
34 * merchantability and fitness for a particular purpose are disclaimed.
35 * In no event shall the company or contributors be liable for any
36 * direct, indirect, incidental, special, exemplary, or consequential
37 * damages (including, but not limited to, procurement of substitute
38 * goods or services; loss of use, data, or profits; or business
39 * interruption) however caused and on any theory of liability, whether
40 * in contract, strict liability, or tort (including negligence or
41 * otherwise) arising in any way out of the use of this software, even
42 * if advised of the possibility of such damage.
43 *
44 */
45
46#include "httpd.h"
47#include "http_config.h"
48#include "http_protocol.h"
49#include "http_request.h"
50#include "ap_config.h"
51#include "http_log.h"
52#include "apu.h"
53#include "apr_general.h"
54#include "apr_sha1.h"
55#include "apr_file_io.h"
56
57#include <unixd.h>
58#include <apr_base64.h>
59#include <apr_pools.h>
60#include <apr_general.h>
61#include <apr_hash.h>
62#include <apr_strings.h>
63#include <apr_thread_proc.h>
64#include <apr_signal.h>
65
66#include <sys/types.h>
67#include <sys/socket.h>
68#include <sys/un.h>
69#include <stdlib.h>
70#include <stdio.h>
71#include <poll.h>
72#include <unistd.h>
73#include <string.h>
74#include <errno.h>
75
Radek Krejci8fd1f5e2012-07-24 17:33:36 +020076#include <json/json.h>
77
Radek Krejci469aab82012-07-22 18:42:20 +020078#include <libnetconf.h>
79#include <libxml/tree.h>
80#include <libxml/parser.h>
81
82#define MAX_PROCS 5
Radek Krejci6cb08982012-07-25 18:01:06 +020083#define SOCKET_FILENAME "/tmp/mod_netconf.sock"
Radek Krejci469aab82012-07-22 18:42:20 +020084#define MAX_SOCKET_CL 10
85#define BUFFER_SIZE 4096
86
87/* sleep in master process for non-blocking socket reading */
88#define SLEEP_TIME 200
89
90#ifndef offsetof
91#define offsetof(type, member) ((size_t) ((type *) 0)->member)
92#endif
93
94struct timeval timeout = { 1, 0 };
95
Radek Krejci8fd1f5e2012-07-24 17:33:36 +020096typedef enum MSG_TYPE {
97 REPLY_OK,
98 REPLY_DATA,
99 REPLY_ERROR,
100 MSG_CONNECT,
101 MSG_DISCONNECT,
102 MSG_GET,
103 MSG_GETCONFIG,
104 MSG_EDITCONFIG,
105 MSG_COPYCONFIG,
106 MSG_DELETECONFIG,
107 MSG_LOCK,
108 MSG_UNLOCK,
109 MSG_KILL
110} MSG_TYPE;
111
Radek Krejci469aab82012-07-22 18:42:20 +0200112#define MSG_OK 0
113#define MSG_OPEN 1
114#define MSG_DATA 2
115#define MSG_CLOSE 3
116#define MSG_ERROR 4
117#define MSG_UNKNOWN 5
118
Radek Krejci469aab82012-07-22 18:42:20 +0200119module AP_MODULE_DECLARE_DATA netconf_module;
120
121typedef struct {
Radek Krejci469aab82012-07-22 18:42:20 +0200122 apr_pool_t *pool;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200123 apr_proc_t *forkproc;
124 char* sockname;
Radek Krejcif23850c2012-07-23 16:14:17 +0200125} mod_netconf_cfg;
Radek Krejci469aab82012-07-22 18:42:20 +0200126
127volatile int isterminated = 0;
128
129static char* password;
130
131
132static void signal_handler(int sign)
133{
134 switch (sign) {
135 case SIGTERM:
136 isterminated = 1;
Radek Krejci469aab82012-07-22 18:42:20 +0200137 break;
138 }
139}
140
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200141static char* gen_ncsession_hash( const char* hostname, const char* port, const char* sid)
Radek Krejci469aab82012-07-22 18:42:20 +0200142{
Radek Krejcif23850c2012-07-23 16:14:17 +0200143 unsigned char hash_raw[APR_SHA1_DIGESTSIZE];
144 int i;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200145 char* hash;
Radek Krejcif23850c2012-07-23 16:14:17 +0200146
Radek Krejci469aab82012-07-22 18:42:20 +0200147 apr_sha1_ctx_t sha1_ctx;
148 apr_sha1_init(&sha1_ctx);
149 apr_sha1_update(&sha1_ctx, hostname, strlen(hostname));
150 apr_sha1_update(&sha1_ctx, port, strlen(port));
151 apr_sha1_update(&sha1_ctx, sid, strlen(sid));
Radek Krejcif23850c2012-07-23 16:14:17 +0200152 apr_sha1_final(hash_raw, &sha1_ctx);
Radek Krejci469aab82012-07-22 18:42:20 +0200153
Radek Krejcif23850c2012-07-23 16:14:17 +0200154 /* convert binary hash into hex string, which is printable */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200155 hash = malloc(sizeof(char) * ((2*APR_SHA1_DIGESTSIZE)+1));
Radek Krejcif23850c2012-07-23 16:14:17 +0200156 for (i = 0; i < APR_SHA1_DIGESTSIZE; i++) {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200157 snprintf(hash + (2*i), 3, "%02x", hash_raw[i]);
Radek Krejcif23850c2012-07-23 16:14:17 +0200158 }
159 //hash[2*APR_SHA1_DIGESTSIZE] = 0;
Radek Krejci469aab82012-07-22 18:42:20 +0200160
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200161 return (hash);
Radek Krejci469aab82012-07-22 18:42:20 +0200162}
163
164int netconf_callback_ssh_hostkey_check (const char* hostname, int keytype, const char* fingerprint)
165{
166 /* always approve */
167 return (EXIT_SUCCESS);
168}
169
170char* netconf_callback_sshauth_password (const char* username, const char* hostname)
171{
172 char* buf;
173
174 buf = malloc ((strlen(password) + 1) * sizeof(char));
175 apr_cpystrn(buf, password, strlen(password) + 1);
176
177 return (buf);
178}
179
180void netconf_callback_sshauth_interactive (const char* name,
181 int name_len,
182 const char* instruction,
183 int instruction_len,
184 int num_prompts,
185 const LIBSSH2_USERAUTH_KBDINT_PROMPT* prompts,
186 LIBSSH2_USERAUTH_KBDINT_RESPONSE* responses,
187 void** abstract)
188{
189 int i;
190
191 for (i=0; i<num_prompts; i++) {
192 responses[i].text = malloc ((strlen(password) + 1) * sizeof(char));
193 apr_cpystrn(responses[i].text, password, strlen(password) + 1);
194 responses[i].length = strlen(responses[i].text) + 1;
195 }
196
197 return;
198}
199
Radek Krejcic11fd862012-07-26 12:41:21 +0200200static json_object *err_reply = NULL;
201void netconf_callback_error_process(const char* tag,
202 const char* type,
203 const char* severity,
204 const char* apptag,
205 const char* path,
206 const char* message,
207 const char* attribute,
208 const char* element,
209 const char* ns,
210 const char* sid)
211{
212 err_reply = json_object_new_object();
213 json_object_object_add(err_reply, "type", json_object_new_int(REPLY_ERROR));
214 if (tag) json_object_object_add(err_reply, "error-tag", json_object_new_string(tag));
215 if (type) json_object_object_add(err_reply, "error-type", json_object_new_string(type));
216 if (severity) json_object_object_add(err_reply, "error-severity", json_object_new_string(severity));
217 if (apptag) json_object_object_add(err_reply, "error-app-tag", json_object_new_string(apptag));
218 if (path) json_object_object_add(err_reply, "error-path", json_object_new_string(path));
219 if (message) json_object_object_add(err_reply, "error-message", json_object_new_string(message));
220 if (attribute) json_object_object_add(err_reply, "bad-attribute", json_object_new_string(attribute));
221 if (element) json_object_object_add(err_reply, "bad-element", json_object_new_string(element));
222 if (ns) json_object_object_add(err_reply, "bad-namespace", json_object_new_string(ns));
223 if (sid) json_object_object_add(err_reply, "session-id", json_object_new_string(sid));
224}
225
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200226static char* netconf_connect(server_rec* server, apr_pool_t* pool, apr_hash_t* conns, const char* host, const char* port, const char* user, const char* pass)
Radek Krejci469aab82012-07-22 18:42:20 +0200227{
Radek Krejci469aab82012-07-22 18:42:20 +0200228 struct nc_session* session;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200229 char *sid;
Radek Krejcif23850c2012-07-23 16:14:17 +0200230 char *session_key;
Radek Krejci469aab82012-07-22 18:42:20 +0200231
232 /* connect to the requested NETCONF server */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200233 password = (char*)pass;
234 session = nc_session_connect(host, (unsigned short) atoi (port), user, NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200235
236 /* if connected successful, add session to the list */
237 if (session != NULL) {
238 /* generate hash for the session */
239 sid = nc_session_get_id(session);
Radek Krejcic11fd862012-07-26 12:41:21 +0200240 session_key = gen_ncsession_hash(
241 (host==NULL) ? "localhost" : host,
242 (port==NULL) ? "830" : port,
243 sid);
Radek Krejci469aab82012-07-22 18:42:20 +0200244 free(sid);
Radek Krejcif23850c2012-07-23 16:14:17 +0200245 apr_hash_set(conns, apr_pstrdup(pool, session_key), APR_HASH_KEY_STRING, (void *) session);
Radek Krejci469aab82012-07-22 18:42:20 +0200246 ap_log_error(APLOG_MARK, APLOG_NOTICE, 0, server, "NETCONF session established");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200247 return (session_key);
Radek Krejci469aab82012-07-22 18:42:20 +0200248 } else {
249 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Connection could not be established");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200250 return (NULL);
Radek Krejci469aab82012-07-22 18:42:20 +0200251 }
252
Radek Krejci469aab82012-07-22 18:42:20 +0200253}
254
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200255static int netconf_close(server_rec* server, apr_hash_t* conns, char* session_key)
Radek Krejci469aab82012-07-22 18:42:20 +0200256{
257 struct nc_session *ns = NULL;
Radek Krejci469aab82012-07-22 18:42:20 +0200258
Radek Krejcif23850c2012-07-23 16:14:17 +0200259 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Key in hash to get: %s", session_key);
Radek Krejci469aab82012-07-22 18:42:20 +0200260 ns = (struct nc_session *)apr_hash_get(conns, session_key, APR_HASH_KEY_STRING);
261 if (ns != NULL) {
262 nc_session_close (ns, "NETCONF session closed by client");
263 nc_session_free (ns);
264 ns = NULL;
265
266 /* remove session from the active sessions list */
267 apr_hash_set(conns, session_key, APR_HASH_KEY_STRING, NULL);
268 ap_log_error(APLOG_MARK, APLOG_NOTICE, 0, server, "NETCONF session closed");
Radek Krejcif23850c2012-07-23 16:14:17 +0200269
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200270 return (EXIT_SUCCESS);
Radek Krejci469aab82012-07-22 18:42:20 +0200271 } else {
272 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown session to close");
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200273 return (EXIT_FAILURE);
Radek Krejci469aab82012-07-22 18:42:20 +0200274 }
275}
276
Radek Krejci8e4632a2012-07-26 13:40:34 +0200277static int netconf_op(server_rec* server, apr_hash_t* conns, char* session_key, nc_rpc* rpc)
Radek Krejci469aab82012-07-22 18:42:20 +0200278{
279 struct nc_session *session = NULL;
Radek Krejci035bf4e2012-07-25 10:59:09 +0200280 nc_reply* reply;
281 int retval = EXIT_SUCCESS;
282
Radek Krejci8e4632a2012-07-26 13:40:34 +0200283 /* check requests */
284 if (rpc == NULL) {
285 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: rpc is not created");
286 return (EXIT_FAILURE);
287 }
288
289 /* get session where send the RPC */
Radek Krejci035bf4e2012-07-25 10:59:09 +0200290 session = (struct nc_session *)apr_hash_get(conns, session_key, APR_HASH_KEY_STRING);
291 if (session != NULL) {
Radek Krejci035bf4e2012-07-25 10:59:09 +0200292 /* send the request and get the reply */
293 nc_session_send_rpc (session, rpc);
Radek Krejci035bf4e2012-07-25 10:59:09 +0200294 if (nc_session_recv_reply (session, &reply) == 0) {
Radek Krejci035bf4e2012-07-25 10:59:09 +0200295 if (nc_session_get_status(session) != NC_SESSION_STATUS_WORKING) {
Radek Krejci035bf4e2012-07-25 10:59:09 +0200296 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: receiving rpc-reply failed");
Radek Krejci035bf4e2012-07-25 10:59:09 +0200297 netconf_close(server, conns, session_key);
Radek Krejci035bf4e2012-07-25 10:59:09 +0200298 return (EXIT_FAILURE);
299 }
300
301 /* there is error handled by callback */
302 return (EXIT_FAILURE);
303 }
Radek Krejci035bf4e2012-07-25 10:59:09 +0200304
305 switch (nc_reply_get_type (reply)) {
306 case NC_REPLY_OK:
307 retval = EXIT_SUCCESS;
308 break;
309 default:
310 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: unexpected rpc-reply");
311 retval = EXIT_FAILURE;
312 break;
313 }
314 nc_reply_free(reply);
315 return (retval);
316 } else {
317 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown session to process.");
318 return (EXIT_FAILURE);
319 }
320}
Radek Krejci8e4632a2012-07-26 13:40:34 +0200321static char* netconf_opdata(server_rec* server, apr_hash_t* conns, char* session_key, nc_rpc* rpc)
322{
323 struct nc_session *session = NULL;
324 nc_reply* reply;
325 char* data;
326
327 /* check requests */
328 if (rpc == NULL) {
329 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: rpc is not created");
330 return (NULL);
331 }
332
333 /* get session where send the RPC */
334 session = (struct nc_session *)apr_hash_get(conns, session_key, APR_HASH_KEY_STRING);
335 if (session != NULL) {
336 /* send the request and get the reply */
337 nc_session_send_rpc (session, rpc);
338 if (nc_session_recv_reply (session, &reply) == 0) {
339 nc_rpc_free (rpc);
340 if (nc_session_get_status(session) != NC_SESSION_STATUS_WORKING) {
341 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: receiving rpc-reply failed");
342 netconf_close(server, conns, session_key);
343 return (NULL);
344 }
345
346 /* there is error handled by callback */
347 return (NULL);
348 }
349 nc_rpc_free (rpc);
350
351 switch (nc_reply_get_type (reply)) {
352 case NC_REPLY_DATA:
353 if ((data = nc_reply_get_data (reply)) == NULL) {
354 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: no data from reply");
355 return (NULL);
356 }
357 break;
358 default:
359 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: unexpected rpc-reply");
360 return (NULL);
361 }
362 nc_reply_free(reply);
363
364 return (data);
365 } else {
366 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown session to process.");
367 return (NULL);
368 }
369}
370
371static char* netconf_getconfig(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE source, const char* filter)
372{
373 nc_rpc* rpc;
374 struct nc_filter *f = NULL;
375 char* data = NULL;
376
377 /* create filter if set */
378 if (filter != NULL) {
379 f = nc_filter_new(NC_FILTER_SUBTREE, filter);
380 }
381
382 /* create requests */
383 rpc = nc_rpc_getconfig (source, f);
384 nc_filter_free(f);
385 if (rpc == NULL) {
386 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
387 return (NULL);
388 }
389
390 data = netconf_opdata(server, conns, session_key, rpc);
391 nc_rpc_free (rpc);
392 return (data);
393}
394
395static char* netconf_get(server_rec* server, apr_hash_t* conns, char* session_key, const char* filter)
396{
397 nc_rpc* rpc;
398 struct nc_filter *f = NULL;
399 char* data = NULL;
400
401 /* create filter if set */
402 if (filter != NULL) {
403 f = nc_filter_new(NC_FILTER_SUBTREE, filter);
404 }
405
406 /* create requests */
407 rpc = nc_rpc_get (f);
408 nc_filter_free(f);
409 if (rpc == NULL) {
410 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
411 return (NULL);
412 }
413
414 data = netconf_opdata(server, conns, session_key, rpc);
415 nc_rpc_free (rpc);
416 return (data);
417}
418
419static int netconf_copyconfig(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE source, NC_DATASTORE target, const char* config)
420{
421 nc_rpc* rpc;
422 int retval = EXIT_SUCCESS;
423
424 /* create requests */
425 rpc = nc_rpc_copyconfig(source, target, config);
426 if (rpc == NULL) {
427 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
428 return (EXIT_FAILURE);
429 }
430
431 retval = netconf_op(server, conns, session_key, rpc);
432 nc_rpc_free (rpc);
433 return (retval);
434}
Radek Krejci035bf4e2012-07-25 10:59:09 +0200435
Radek Krejci62ab34b2012-07-26 13:42:05 +0200436static int netconf_editconfig(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE target, NC_EDIT_DEFOP_TYPE defop, NC_EDIT_ERROPT_TYPE erropt, const char* config)
437{
438 nc_rpc* rpc;
439 int retval = EXIT_SUCCESS;
440
441 /* create requests */
442 rpc = nc_rpc_editconfig(target, defop, erropt, config);
443 if (rpc == NULL) {
444 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
445 return (EXIT_FAILURE);
446 }
447
448 retval = netconf_op(server, conns, session_key, rpc);
449 nc_rpc_free (rpc);
450 return (retval);
451}
452
Radek Krejcie34d3eb2012-07-26 15:05:53 +0200453static int netconf_killsession(server_rec* server, apr_hash_t* conns, char* session_key, const char* sid)
454{
455 nc_rpc* rpc;
456 int retval = EXIT_SUCCESS;
457
458 /* create requests */
459 rpc = nc_rpc_killsession(sid);
460 if (rpc == NULL) {
461 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
462 return (EXIT_FAILURE);
463 }
464
465 retval = netconf_op(server, conns, session_key, rpc);
466 nc_rpc_free (rpc);
467 return (retval);
468}
469
Radek Krejci5cd7d422012-07-26 14:50:29 +0200470static int netconf_onlytargetop(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE target, nc_rpc* (*op_func)(NC_DATASTORE))
Radek Krejci2f318372012-07-26 14:22:35 +0200471{
472 nc_rpc* rpc;
473 int retval = EXIT_SUCCESS;
474
475 /* create requests */
Radek Krejci5cd7d422012-07-26 14:50:29 +0200476 rpc = op_func(target);
Radek Krejci2f318372012-07-26 14:22:35 +0200477 if (rpc == NULL) {
478 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "mod_netconf: creating rpc request failed");
479 return (EXIT_FAILURE);
480 }
481
482 retval = netconf_op(server, conns, session_key, rpc);
483 nc_rpc_free (rpc);
484 return (retval);
485}
486
Radek Krejci5cd7d422012-07-26 14:50:29 +0200487static int netconf_deleteconfig(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE target)
488{
489 return (netconf_onlytargetop(server, conns, session_key, target, nc_rpc_deleteconfig));
490}
491
492static int netconf_lock(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE target)
493{
494 return (netconf_onlytargetop(server, conns, session_key, target, nc_rpc_lock));
495}
496
497static int netconf_unlock(server_rec* server, apr_hash_t* conns, char* session_key, NC_DATASTORE target)
498{
499 return (netconf_onlytargetop(server, conns, session_key, target, nc_rpc_unlock));
500}
501
Radek Krejci469aab82012-07-22 18:42:20 +0200502server_rec* clb_print_server;
503int clb_print(const char* msg)
504{
505 ap_log_error(APLOG_MARK, APLOG_INFO, 0, clb_print_server, msg);
506 return (0);
507}
508
Radek Krejcif23850c2012-07-23 16:14:17 +0200509/*
510 * This is actually implementation of NETCONF client
511 * - requests are received from UNIX socket in the predefined format
512 * - results are replied through the same way
513 * - the daemon run as a separate process, but it is started and stopped
514 * automatically by Apache.
515 *
516 */
Radek Krejci469aab82012-07-22 18:42:20 +0200517static void forked_proc(apr_pool_t * pool, server_rec * server)
518{
519 struct sockaddr_un local, remote;
520 int lsock, client;
521 socklen_t len, len2;
522 struct pollfd fds;
523 int status;
Radek Krejciae021c12012-07-25 18:03:52 +0200524 mod_netconf_cfg *cfg;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200525 json_object *request, *reply;
526 int operation;
527 char* session_key, *data;
528 const char *msgtext;
529 const char *host, *port, *user, *pass;
Radek Krejcie34d3eb2012-07-26 15:05:53 +0200530 const char *target, *source, *filter, *config, *defop, *erropt, *sid;
Radek Krejcifa891e72012-07-26 14:04:27 +0200531 NC_DATASTORE ds_type_s, ds_type_t;
Radek Krejci62ab34b2012-07-26 13:42:05 +0200532 NC_EDIT_DEFOP_TYPE defop_type = 0;
533 NC_EDIT_ERROPT_TYPE erropt_type = 0;
Radek Krejci469aab82012-07-22 18:42:20 +0200534
535 apr_hash_t *netconf_sessions_list;
536 char buffer[BUFFER_SIZE];
Radek Krejci469aab82012-07-22 18:42:20 +0200537
Radek Krejcif23850c2012-07-23 16:14:17 +0200538 /* change uid and gid of process for security reasons */
Radek Krejci469aab82012-07-22 18:42:20 +0200539 unixd_setup_child();
540
Radek Krejciae021c12012-07-25 18:03:52 +0200541 cfg = ap_get_module_config(server->module_config, &netconf_module);
542 if (cfg == NULL) {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200543 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Getting mod_netconf configuration failed");
544 return;
545 }
Radek Krejci469aab82012-07-22 18:42:20 +0200546
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200547 /* create listening UNIX socket to accept incoming connections */
Radek Krejci469aab82012-07-22 18:42:20 +0200548 if ((lsock = socket(PF_UNIX, SOCK_STREAM, 0)) == -1) {
549 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Creating socket failed (%s)", strerror(errno));
550 return;
551 }
552
553 local.sun_family = AF_UNIX;
Radek Krejciae021c12012-07-25 18:03:52 +0200554 strncpy(local.sun_path, cfg->sockname, sizeof(local.sun_path));
Radek Krejci469aab82012-07-22 18:42:20 +0200555 unlink(local.sun_path);
556 len = offsetof(struct sockaddr_un, sun_path) + strlen(local.sun_path);
557
558 if (bind(lsock, (struct sockaddr *) &local, len) == -1) {
559 if (errno == EADDRINUSE) {
560 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "mod_netconf socket address already in use");
561 close(lsock);
562 exit(0);
563 }
564 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Binding socket failed (%s)", strerror(errno));
565 close(lsock);
566 return;
567 }
568
569 if (listen(lsock, MAX_SOCKET_CL) == -1) {
570 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Setting up listen socket failed (%s)", strerror(errno));
571 close(lsock);
572 return;
573 }
574
575 /* prepare internal lists */
576 netconf_sessions_list = apr_hash_make(pool);
577
578 /* setup libnetconf's callbacks */
579 nc_verbosity(NC_VERB_DEBUG);
580 clb_print_server = server;
581 nc_callback_print(clb_print);
582 nc_callback_ssh_host_authenticity_check(netconf_callback_ssh_hostkey_check);
583 nc_callback_sshauth_interactive(netconf_callback_sshauth_interactive);
584 nc_callback_sshauth_password(netconf_callback_sshauth_password);
Radek Krejcic11fd862012-07-26 12:41:21 +0200585 nc_callback_error_reply(netconf_callback_error_process);
Radek Krejci469aab82012-07-22 18:42:20 +0200586
587 /* disable publickey authentication */
588 nc_ssh_pref(NC_SSH_AUTH_PUBLIC_KEYS, -1);
589
590 while (isterminated == 0) {
591 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "waiting for another client's request");
592
593 /* open incoming connection if any */
594 len2 = sizeof(remote);
595 client = accept(lsock, (struct sockaddr *) &remote, &len2);
596 if (client == -1 && (errno == EAGAIN || errno == EWOULDBLOCK)) {
597 apr_sleep(SLEEP_TIME);
598 continue;
599 } else if (client == -1 && (errno == EINTR)) {
600 continue;
601 } else if (client == -1) {
602 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Accepting mod_netconf client connection failed (%s)", strerror(errno));
603 continue;
604 }
605 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "client's socket accepted.");
606
607 /* set client's socket as non-blocking */
Radek Krejcif23850c2012-07-23 16:14:17 +0200608 //fcntl(client, F_SETFL, fcntl(client, F_GETFL, 0) | O_NONBLOCK);
Radek Krejci469aab82012-07-22 18:42:20 +0200609
610 while (1) {
611 fds.fd = client;
612 fds.events = POLLIN;
613 fds.revents = 0;
614
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200615 status = poll(&fds, 1, 1000);
Radek Krejci469aab82012-07-22 18:42:20 +0200616
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200617 if (status == 0 || (status == -1 && (errno == EAGAIN || (errno == EINTR && isterminated == 0)))) {
Radek Krejci469aab82012-07-22 18:42:20 +0200618 /* poll was interrupted - check if the isterminated is set and if not, try poll again */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200619 //ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "poll interrupted");
Radek Krejci469aab82012-07-22 18:42:20 +0200620 continue;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200621 } else if (status < 0) {
Radek Krejci469aab82012-07-22 18:42:20 +0200622 /* 0: poll time outed
623 * close socket and ignore this request from the client, it can try it again
624 * -1: poll failed
625 * something wrong happend, close this socket and wait for another request
626 */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200627 //ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "poll failed, status %d(%d: %s)", status, errno, strerror(errno));
Radek Krejci469aab82012-07-22 18:42:20 +0200628 close(client);
629 break;
630 }
631 /* status > 0 */
632
633 /* check the status of the socket */
634
635 /* if nothing to read and POLLHUP (EOF) or POLLERR set */
636 if ((fds.revents & POLLHUP) || (fds.revents & POLLERR)) {
637 /* close client's socket (it's probably already closed by client */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200638 //ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "socket error (%d)", fds.revents);
Radek Krejci469aab82012-07-22 18:42:20 +0200639 close(client);
640 break;
641 }
642
643 if ((len2 = recv(client, buffer, BUFFER_SIZE, 0)) <= 0) {
644 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "receiving failed %d (%s)", errno, strerror(errno));
645 continue;
646 } else {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200647 request = json_tokener_parse(buffer);
648 operation = json_object_get_int(json_object_object_get(request, "type"));
Radek Krejci469aab82012-07-22 18:42:20 +0200649
Radek Krejci035bf4e2012-07-25 10:59:09 +0200650 session_key = (char*) json_object_get_string(json_object_object_get(request, "session"));
651 /* DO NOT FREE session_key HERE, IT IS PART OF REQUEST */
652 if (operation != MSG_CONNECT && session_key == NULL) {
653 reply = json_object_new_object();
654 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
655 json_object_object_add(reply, "error-message", json_object_new_string("Missing session specification."));
656 msgtext = json_object_to_json_string(reply);
657 send(client, msgtext, strlen(msgtext) + 1, 0);
658 json_object_put(reply);
659 /* there is some stupid client, so close the connection to give a chance to some other client */
660 close(client);
661 break;
662 }
663
Radek Krejcifa891e72012-07-26 14:04:27 +0200664 /* get parameters */
665 ds_type_t = -1;
666 if ((target = json_object_get_string(json_object_object_get(request, "target"))) != NULL) {
667 if (strcmp(target, "running") == 0) {
668 ds_type_t = NC_DATASTORE_RUNNING;
669 } else if (strcmp(target, "startup") == 0) {
670 ds_type_t = NC_DATASTORE_STARTUP;
671 } else if (strcmp(target, "candidate") == 0) {
672 ds_type_t = NC_DATASTORE_CANDIDATE;
673 }
674 }
675 ds_type_s = -1;
676 if ((source = json_object_get_string(json_object_object_get(request, "source"))) != NULL) {
677 if (strcmp(source, "running") == 0) {
678 ds_type_s = NC_DATASTORE_RUNNING;
679 } else if (strcmp(source, "startup") == 0) {
680 ds_type_s = NC_DATASTORE_STARTUP;
681 } else if (strcmp(source, "candidate") == 0) {
682 ds_type_s = NC_DATASTORE_CANDIDATE;
683 }
684 }
685
Radek Krejcic11fd862012-07-26 12:41:21 +0200686 /* null global JSON error-reply */
687 err_reply = NULL;
688
689 /* process required operation */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200690 switch (operation) {
691 case MSG_CONNECT:
692 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: Connect");
693
694 host = json_object_get_string(json_object_object_get(request, "host"));
695 port = json_object_get_string(json_object_object_get(request, "port"));
696 user = json_object_get_string(json_object_object_get(request, "user"));
697 pass = json_object_get_string(json_object_object_get(request, "pass"));
698 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "host: %s, port: %s, user: %s", host, port, user);
699 session_key = netconf_connect(server, pool, netconf_sessions_list, host, port, user, pass);
700 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "hash: %s", session_key);
701
702 reply = json_object_new_object();
703 if (session_key == NULL) {
704 /* negative reply */
Radek Krejcic11fd862012-07-26 12:41:21 +0200705 if (err_reply == NULL) {
706 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
707 json_object_object_add(reply, "error-message", json_object_new_string("Connecting NETCONF server failed."));
708 } else {
709 /* use filled err_reply from libnetconf's callback */
710 json_object_put(reply);
711 reply = err_reply;
712 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200713 } else {
714 /* positive reply */
715 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
716 json_object_object_add(reply, "session", json_object_new_string(session_key));
Radek Krejcie31ad212012-07-26 12:51:15 +0200717
718 free(session_key);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200719 }
720
Radek Krejci469aab82012-07-22 18:42:20 +0200721 break;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200722 case MSG_GET:
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200723 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: get-config (session %s)", session_key);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200724
725 filter = json_object_get_string(json_object_object_get(request, "filter"));
726
727 reply = json_object_new_object();
728
729 if ((data = netconf_get(server, netconf_sessions_list, session_key, filter)) == NULL) {
Radek Krejcic11fd862012-07-26 12:41:21 +0200730 if (err_reply == NULL) {
731 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
732 json_object_object_add(reply, "error-message", json_object_new_string("get failed."));
733 } else {
734 /* use filled err_reply from libnetconf's callback */
735 json_object_put(reply);
736 reply = err_reply;
737 }
Radek Krejci035bf4e2012-07-25 10:59:09 +0200738 } else {
739 json_object_object_add(reply, "type", json_object_new_int(REPLY_DATA));
740 json_object_object_add(reply, "data", json_object_new_string(data));
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200741 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200742 break;
743 case MSG_GETCONFIG:
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200744 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: get-config (session %s)", session_key);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200745
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200746 filter = json_object_get_string(json_object_object_get(request, "filter"));
747
Radek Krejci035bf4e2012-07-25 10:59:09 +0200748 reply = json_object_new_object();
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200749
Radek Krejcifa891e72012-07-26 14:04:27 +0200750 if (ds_type_s == -1) {
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200751 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
Radek Krejci035bf4e2012-07-25 10:59:09 +0200752 json_object_object_add(reply, "error-message", json_object_new_string("Invalid source repository type requested."));
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200753 break;
754 }
755
Radek Krejcifa891e72012-07-26 14:04:27 +0200756 if ((data = netconf_getconfig(server, netconf_sessions_list, session_key, ds_type_s, filter)) == NULL) {
Radek Krejcic11fd862012-07-26 12:41:21 +0200757 if (err_reply == NULL) {
758 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
759 json_object_object_add(reply, "error-message", json_object_new_string("get-config failed."));
760 } else {
761 /* use filled err_reply from libnetconf's callback */
762 json_object_put(reply);
763 reply = err_reply;
764 }
Radek Krejci035bf4e2012-07-25 10:59:09 +0200765 } else {
766 json_object_object_add(reply, "type", json_object_new_int(REPLY_DATA));
767 json_object_object_add(reply, "data", json_object_new_string(data));
768 }
769 break;
Radek Krejci62ab34b2012-07-26 13:42:05 +0200770 case MSG_EDITCONFIG:
771 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: edit-config (session %s)", session_key);
772
773 reply = json_object_new_object();
774
775 defop = json_object_get_string(json_object_object_get(request, "default-operation"));
776 if (defop != NULL) {
777 if (strcmp(defop, "merge") == 0) {
778 defop_type = NC_EDIT_DEFOP_MERGE;
779 } else if (strcmp(defop, "replace") == 0) {
780 defop_type = NC_EDIT_DEFOP_REPLACE;
781 } else if (strcmp(defop, "none") == 0) {
782 defop_type = NC_EDIT_DEFOP_NONE;
783 } else {
784 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
785 json_object_object_add(reply, "error-message", json_object_new_string("Invalid default-operation parameter."));
786 break;
787 }
788 } else {
789 defop_type = 0;
790 }
791
792 erropt = json_object_get_string(json_object_object_get(request, "error-option"));
793 if (erropt != NULL) {
794 if (strcmp(erropt, "continue-on-error") == 0) {
795 erropt_type = NC_EDIT_ERROPT_CONT;
796 } else if (strcmp(erropt, "stop-on-error") == 0) {
797 erropt_type = NC_EDIT_ERROPT_STOP;
798 } else if (strcmp(erropt, "rollback-on-error") == 0) {
799 erropt_type = NC_EDIT_ERROPT_ROLLBACK;
800 } else {
801 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
802 json_object_object_add(reply, "error-message", json_object_new_string("Invalid error-option parameter."));
803 break;
804 }
805 } else {
806 erropt_type = 0;
807 }
808
Radek Krejcifa891e72012-07-26 14:04:27 +0200809 if (ds_type_t == -1) {
Radek Krejci62ab34b2012-07-26 13:42:05 +0200810 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
811 json_object_object_add(reply, "error-message", json_object_new_string("Invalid target repository type requested."));
812 break;
813 }
814
815 config = json_object_get_string(json_object_object_get(request, "config"));
816 if (config == NULL) {
817 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
818 json_object_object_add(reply, "error-message", json_object_new_string("Invalid config data parameter."));
819 break;
820 }
821
Radek Krejcifa891e72012-07-26 14:04:27 +0200822 if (netconf_editconfig(server, netconf_sessions_list, session_key, ds_type_t, defop_type, erropt_type, config) != EXIT_SUCCESS) {
Radek Krejci62ab34b2012-07-26 13:42:05 +0200823 if (err_reply == NULL) {
824 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
825 json_object_object_add(reply, "error-message", json_object_new_string("edit-config failed."));
826 } else {
827 /* use filled err_reply from libnetconf's callback */
828 json_object_put(reply);
829 reply = err_reply;
830 }
831 } else {
832 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
833 }
834 break;
Radek Krejci035bf4e2012-07-25 10:59:09 +0200835 case MSG_COPYCONFIG:
836 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: copy-config (session %s)", session_key);
Radek Krejcicebb7af2012-07-26 14:58:12 +0200837 config = NULL;
Radek Krejci035bf4e2012-07-25 10:59:09 +0200838
839 reply = json_object_new_object();
840
Radek Krejcifa891e72012-07-26 14:04:27 +0200841 if (source == NULL) {
842 /* no explicit source specified -> use config data */
843 ds_type_s = NC_DATASTORE_NONE;
Radek Krejciae021c12012-07-25 18:03:52 +0200844 config = json_object_get_string(json_object_object_get(request, "config"));
Radek Krejcifa891e72012-07-26 14:04:27 +0200845 } else if (ds_type_s == -1) {
846 /* source datastore specified, but it is invalid */
847 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
848 json_object_object_add(reply, "error-message", json_object_new_string("Invalid source repository type requested."));
849 break;
Radek Krejci035bf4e2012-07-25 10:59:09 +0200850 }
Radek Krejciae021c12012-07-25 18:03:52 +0200851
Radek Krejcifa891e72012-07-26 14:04:27 +0200852 if (ds_type_t == -1) {
853 /* invalid target datastore specified */
Radek Krejci035bf4e2012-07-25 10:59:09 +0200854 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
855 json_object_object_add(reply, "error-message", json_object_new_string("Invalid target repository type requested."));
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200856 break;
857 }
858
Radek Krejcifa891e72012-07-26 14:04:27 +0200859 if (source == NULL && config == NULL) {
Radek Krejci035bf4e2012-07-25 10:59:09 +0200860 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
Radek Krejcifa891e72012-07-26 14:04:27 +0200861 json_object_object_add(reply, "error-message", json_object_new_string("invalid input parameters - one of source and config is required."));
Radek Krejci035bf4e2012-07-25 10:59:09 +0200862 } else {
Radek Krejcifa891e72012-07-26 14:04:27 +0200863 if (netconf_copyconfig(server, netconf_sessions_list, session_key, ds_type_s, ds_type_t, config) != EXIT_SUCCESS) {
Radek Krejcic11fd862012-07-26 12:41:21 +0200864 if (err_reply == NULL) {
865 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
866 json_object_object_add(reply, "error-message", json_object_new_string("copy-config failed."));
867 } else {
868 /* use filled err_reply from libnetconf's callback */
869 json_object_put(reply);
870 reply = err_reply;
871 }
Radek Krejciae021c12012-07-25 18:03:52 +0200872 } else {
873 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
874 }
Radek Krejci035bf4e2012-07-25 10:59:09 +0200875 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200876 break;
Radek Krejci2f318372012-07-26 14:22:35 +0200877 case MSG_DELETECONFIG:
878 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: delete-config (session %s)", session_key);
Radek Krejci5cd7d422012-07-26 14:50:29 +0200879 /* no break - unifying code */
880 case MSG_LOCK:
881 if (operation == MSG_LOCK) {
882 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: lock (session %s)", session_key);
883 }
884 /* no break - unifying code */
885 case MSG_UNLOCK:
886 if (operation == MSG_UNLOCK) {
887 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: unlock (session %s)", session_key);
888 }
Radek Krejci2f318372012-07-26 14:22:35 +0200889
890 reply = json_object_new_object();
891
892 if (ds_type_t == -1) {
893 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
894 json_object_object_add(reply, "error-message", json_object_new_string("Invalid target repository type requested."));
895 break;
896 }
897
Radek Krejci5cd7d422012-07-26 14:50:29 +0200898 switch(operation) {
899 case MSG_DELETECONFIG:
900 status = netconf_deleteconfig(server, netconf_sessions_list, session_key, ds_type_t);
901 break;
902 case MSG_LOCK:
903 status = netconf_lock(server, netconf_sessions_list, session_key, ds_type_t);
904 break;
905 case MSG_UNLOCK:
906 status = netconf_unlock(server, netconf_sessions_list, session_key, ds_type_t);
907 break;
908 default:
909 status = -1;
910 break;
911 }
912
913 if (status != EXIT_SUCCESS) {
Radek Krejci2f318372012-07-26 14:22:35 +0200914 if (err_reply == NULL) {
915 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
Radek Krejci5cd7d422012-07-26 14:50:29 +0200916 json_object_object_add(reply, "error-message", json_object_new_string("operation failed."));
Radek Krejci2f318372012-07-26 14:22:35 +0200917 } else {
918 /* use filled err_reply from libnetconf's callback */
919 json_object_put(reply);
920 reply = err_reply;
921 }
922 } else {
923 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
924 }
925 break;
Radek Krejcie34d3eb2012-07-26 15:05:53 +0200926 case MSG_KILL:
927 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: kill-session, session %s", session_key);
928
929 sid = json_object_get_string(json_object_object_get(request, "session-id"));
930
931 reply = json_object_new_object();
932
933 if (sid == NULL) {
934 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
935 json_object_object_add(reply, "error-message", json_object_new_string("Missing session-id parameter."));
936 break;
937 }
938
939 if (netconf_killsession(server, netconf_sessions_list, session_key, sid) != EXIT_SUCCESS) {
940 if (err_reply == NULL) {
941 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
942 json_object_object_add(reply, "error-message", json_object_new_string("kill-session failed."));
943 } else {
944 /* use filled err_reply from libnetconf's callback */
945 json_object_put(reply);
946 reply = err_reply;
947 }
948 } else {
949 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
950 }
951 break;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200952 case MSG_DISCONNECT:
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200953 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, server, "Request: Disconnect session %s", session_key);
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200954
955 reply = json_object_new_object();
956 if (netconf_close(server, netconf_sessions_list, session_key) != EXIT_SUCCESS) {
Radek Krejcic11fd862012-07-26 12:41:21 +0200957 if (err_reply == NULL) {
958 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
959 json_object_object_add(reply, "error-message", json_object_new_string("Invalid session identifier."));
960 } else {
961 /* use filled err_reply from libnetconf's callback */
962 json_object_put(reply);
963 reply = err_reply;
964 }
Radek Krejci8fd1f5e2012-07-24 17:33:36 +0200965 } else {
966 json_object_object_add(reply, "type", json_object_new_int(REPLY_OK));
967 }
968 break;
969 default:
970 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Unknown mod_netconf operation requested (%d)", operation);
971 reply = json_object_new_object();
972 json_object_object_add(reply, "type", json_object_new_int(REPLY_ERROR));
973 json_object_object_add(reply, "error-message", json_object_new_string("Operation not supported."));
974 break;
975 }
976 json_object_put(request);
977
978 /* send reply to caller */
979 if (reply != NULL) {
980 msgtext = json_object_to_json_string(reply);
981 send(client, msgtext, strlen(msgtext) + 1, 0);
982 json_object_put(reply);
983 } else {
984 break;
985 }
Radek Krejci469aab82012-07-22 18:42:20 +0200986 }
987 }
988 }
989
990 close(lsock);
991
992 ap_log_error(APLOG_MARK, APLOG_ERR, 0, server, "Exiting from the mod_netconf daemon");
993
994 exit(APR_SUCCESS);
995}
996
Radek Krejcif23850c2012-07-23 16:14:17 +0200997static void *mod_netconf_create_conf(apr_pool_t * pool, server_rec * s)
Radek Krejci469aab82012-07-22 18:42:20 +0200998{
Radek Krejcif23850c2012-07-23 16:14:17 +0200999 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, s, "Init netconf module config");
1000
1001 mod_netconf_cfg *config = apr_pcalloc(pool, sizeof(mod_netconf_cfg));
1002 apr_pool_create(&config->pool, pool);
1003 config->forkproc = NULL;
Radek Krejci8fd1f5e2012-07-24 17:33:36 +02001004 config->sockname = SOCKET_FILENAME;
Radek Krejcif23850c2012-07-23 16:14:17 +02001005
1006 return (void *)config;
Radek Krejci469aab82012-07-22 18:42:20 +02001007}
1008
1009static int mod_netconf_master_init(apr_pool_t * pconf, apr_pool_t * ptemp,
1010 apr_pool_t * plog, server_rec * s)
1011{
Radek Krejcif23850c2012-07-23 16:14:17 +02001012 mod_netconf_cfg *config;
1013 apr_status_t res;
1014
Radek Krejci469aab82012-07-22 18:42:20 +02001015 /* These two help ensure that we only init once. */
1016 void *data;
Radek Krejcif23850c2012-07-23 16:14:17 +02001017 const char *userdata_key = "netconf_ipc_init";
Radek Krejci469aab82012-07-22 18:42:20 +02001018
1019 /*
1020 * The following checks if this routine has been called before.
1021 * This is necessary because the parent process gets initialized
1022 * a couple of times as the server starts up.
1023 */
1024 apr_pool_userdata_get(&data, userdata_key, s->process->pool);
1025 if (!data) {
1026 apr_pool_userdata_set((const void *)1, userdata_key, apr_pool_cleanup_null, s->process->pool);
1027 return (OK);
1028 }
1029
Radek Krejcif23850c2012-07-23 16:14:17 +02001030 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, s, "creating mod_netconf daemon");
1031 config = ap_get_module_config(s->module_config, &netconf_module);
Radek Krejcidfaa6ea2012-07-23 09:04:43 +02001032
Radek Krejcif23850c2012-07-23 16:14:17 +02001033 if (config && config->forkproc == NULL) {
1034 config->forkproc = apr_pcalloc(config->pool, sizeof(apr_proc_t));
1035 res = apr_proc_fork(config->forkproc, config->pool);
Radek Krejci469aab82012-07-22 18:42:20 +02001036 switch (res) {
1037 case APR_INCHILD:
1038 /* set signal handler */
Radek Krejcif23850c2012-07-23 16:14:17 +02001039 apr_signal_init(config->pool);
Radek Krejci469aab82012-07-22 18:42:20 +02001040 apr_signal(SIGTERM, signal_handler);
1041
1042 /* log start of the separated NETCONF communication process */
Radek Krejcif23850c2012-07-23 16:14:17 +02001043 ap_log_error(APLOG_MARK, APLOG_NOTICE, 0, s, "mod_netconf daemon started (PID %d)", getpid());
Radek Krejci469aab82012-07-22 18:42:20 +02001044
1045 /* start main loop providing NETCONF communication */
Radek Krejcif23850c2012-07-23 16:14:17 +02001046 forked_proc(config->pool, s);
Radek Krejci469aab82012-07-22 18:42:20 +02001047
Radek Krejcif23850c2012-07-23 16:14:17 +02001048 /* I never should be here, wtf?!? */
1049 ap_log_error(APLOG_MARK, APLOG_ERR, 0, s, "mod_netconf daemon unexpectedly stopped");
Radek Krejci469aab82012-07-22 18:42:20 +02001050 exit(APR_EGENERAL);
1051 break;
1052 case APR_INPARENT:
1053 /* register child to be killed (SIGTERM) when the module config's pool dies */
Radek Krejcif23850c2012-07-23 16:14:17 +02001054 apr_pool_note_subprocess(config->pool, config->forkproc, APR_KILL_AFTER_TIMEOUT);
Radek Krejci469aab82012-07-22 18:42:20 +02001055 break;
1056 default:
1057 ap_log_error(APLOG_MARK, APLOG_ERR, 0, s, "apr_proc_fork() failed");
1058 break;
1059 }
Radek Krejcif23850c2012-07-23 16:14:17 +02001060 } else {
1061 ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, s, "mod_netconf misses configuration structure");
Radek Krejci469aab82012-07-22 18:42:20 +02001062 }
1063
1064 return OK;
1065}
1066
Radek Krejci469aab82012-07-22 18:42:20 +02001067/**
1068 * Register module hooks
1069 */
1070static void mod_netconf_register_hooks(apr_pool_t * p)
1071{
Radek Krejcif23850c2012-07-23 16:14:17 +02001072 ap_hook_post_config(mod_netconf_master_init, NULL, NULL, APR_HOOK_LAST);
Radek Krejci469aab82012-07-22 18:42:20 +02001073}
1074
Radek Krejci8fd1f5e2012-07-24 17:33:36 +02001075static const char* cfg_set_socket_path(cmd_parms* cmd, void* cfg, const char* arg)
1076{
1077 ((mod_netconf_cfg*)cfg)->sockname = apr_pstrdup(cmd->pool, arg);
1078 return NULL;
1079}
1080
1081static const command_rec netconf_cmds[] = {
1082 AP_INIT_TAKE1("NetconfSocket", cfg_set_socket_path, NULL, OR_ALL, "UNIX socket path for mod_netconf communication."),
1083 {NULL}
1084};
1085
Radek Krejci469aab82012-07-22 18:42:20 +02001086/* Dispatch list for API hooks */
1087module AP_MODULE_DECLARE_DATA netconf_module = {
1088 STANDARD20_MODULE_STUFF,
1089 NULL, /* create per-dir config structures */
1090 NULL, /* merge per-dir config structures */
Radek Krejcif23850c2012-07-23 16:14:17 +02001091 mod_netconf_create_conf, /* create per-server config structures */
Radek Krejci469aab82012-07-22 18:42:20 +02001092 NULL, /* merge per-server config structures */
Radek Krejci8fd1f5e2012-07-24 17:33:36 +02001093 netconf_cmds, /* table of config file commands */
Radek Krejci469aab82012-07-22 18:42:20 +02001094 mod_netconf_register_hooks /* register hooks */
1095};