Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1 | package ipc |
| 2 | |
| 3 | import ( |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 4 | "errors" |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 5 | "fmt" |
| 6 | "io" |
Cosmos Nicolaou | bae615a | 2014-08-27 23:32:31 -0700 | [diff] [blame] | 7 | "net" |
Asim Shankar | b54d764 | 2014-06-05 13:08:04 -0700 | [diff] [blame] | 8 | "reflect" |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 9 | "strings" |
| 10 | "sync" |
| 11 | "time" |
| 12 | |
Jiri Simsa | 6ac9522 | 2015-02-23 16:11:49 -0800 | [diff] [blame] | 13 | "v.io/v23/config" |
| 14 | "v.io/v23/context" |
| 15 | "v.io/v23/ipc" |
| 16 | "v.io/v23/naming" |
David Why Use Two When One Will Do Presotto | d424c21 | 2015-02-25 11:05:26 -0800 | [diff] [blame] | 17 | "v.io/v23/naming/ns" |
Jiri Simsa | 6ac9522 | 2015-02-23 16:11:49 -0800 | [diff] [blame] | 18 | "v.io/v23/options" |
| 19 | "v.io/v23/security" |
| 20 | "v.io/v23/services/security/access" |
| 21 | "v.io/v23/vdl" |
| 22 | "v.io/v23/verror" |
Jiri Simsa | 6ac9522 | 2015-02-23 16:11:49 -0800 | [diff] [blame] | 23 | "v.io/v23/vom" |
| 24 | "v.io/v23/vtrace" |
Jiri Simsa | 337af23 | 2015-02-27 14:36:46 -0800 | [diff] [blame] | 25 | "v.io/x/lib/vlog" |
Matt Rosencrantz | dbc1be2 | 2015-02-28 15:15:49 -0800 | [diff] [blame] | 26 | "v.io/x/ref/profiles/internal/ipc/stream" |
Cosmos Nicolaou | f889c73 | 2014-10-16 20:46:54 -0700 | [diff] [blame] | 27 | |
Matt Rosencrantz | 9d3278a | 2015-03-11 14:58:34 -0700 | [diff] [blame^] | 28 | "v.io/x/lib/netstate" |
Jiri Simsa | ffceefa | 2015-02-28 11:03:34 -0800 | [diff] [blame] | 29 | "v.io/x/ref/lib/stats" |
Matt Rosencrantz | dbc1be2 | 2015-02-28 15:15:49 -0800 | [diff] [blame] | 30 | "v.io/x/ref/profiles/internal/ipc/stream/vc" |
Matt Rosencrantz | 86ba1a1 | 2015-03-09 13:19:02 -0700 | [diff] [blame] | 31 | "v.io/x/ref/profiles/internal/lib/publisher" |
Matt Rosencrantz | dbc1be2 | 2015-02-28 15:15:49 -0800 | [diff] [blame] | 32 | inaming "v.io/x/ref/profiles/internal/naming" |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 33 | |
Todd Wang | ff73e1f | 2015-02-10 21:45:52 -0800 | [diff] [blame] | 34 | // TODO(cnicolaou): finish verror2 -> verror transition, in particular |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 35 | // for communicating from server to client. |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 36 | ) |
| 37 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 38 | // state for each requested listen address |
| 39 | type listenState struct { |
| 40 | protocol, address string |
| 41 | ln stream.Listener |
| 42 | lep naming.Endpoint |
| 43 | lnerr, eperr error |
| 44 | roaming bool |
| 45 | // We keep track of all of the endpoints, the port and a copy of |
| 46 | // the original listen endpoint for use with roaming network changes. |
| 47 | ieps []*inaming.Endpoint // list of currently active eps |
| 48 | port string // port to use for creating new eps |
| 49 | protoIEP inaming.Endpoint // endpoint to use as template for new eps (includes rid, versions etc) |
| 50 | } |
| 51 | |
| 52 | // state for each requested proxy |
| 53 | type proxyState struct { |
| 54 | endpoint naming.Endpoint |
Mike Burrows | dc6b360 | 2015-02-05 15:52:12 -0800 | [diff] [blame] | 55 | err error |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 56 | } |
| 57 | |
| 58 | type dhcpState struct { |
| 59 | name string |
| 60 | publisher *config.Publisher |
| 61 | stream *config.Stream |
| 62 | ch chan config.Setting // channel to receive dhcp settings over |
| 63 | err error // error status. |
| 64 | watchers map[chan<- ipc.NetworkChange]struct{} |
| 65 | } |
| 66 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 67 | type server struct { |
| 68 | sync.Mutex |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 69 | // context used by the server to make internal RPCs, error messages etc. |
| 70 | ctx *context.T |
Matt Rosencrantz | 1094d06 | 2015-01-30 06:43:12 -0800 | [diff] [blame] | 71 | cancel context.CancelFunc // function to cancel the above context. |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 72 | state serverState // track state of the server. |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 73 | streamMgr stream.Manager // stream manager to listen for new flows. |
| 74 | publisher publisher.Publisher // publisher to publish mounttable mounts. |
| 75 | listenerOpts []stream.ListenerOpt // listener opts for Listen. |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 76 | dhcpState *dhcpState // dhcpState, nil if not using dhcp |
Suharsh Sivakumar | 59c423c | 2015-03-11 14:06:03 -0700 | [diff] [blame] | 77 | principal security.Principal |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 78 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 79 | // maps that contain state on listeners. |
| 80 | listenState map[*listenState]struct{} |
| 81 | listeners map[stream.Listener]struct{} |
| 82 | |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 83 | // state of proxies keyed by the name of the proxy |
| 84 | proxies map[string]proxyState |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 85 | |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 86 | // all endpoints generated and returned by this server |
| 87 | endpoints []naming.Endpoint |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 88 | |
| 89 | disp ipc.Dispatcher // dispatcher to serve RPCs |
| 90 | dispReserved ipc.Dispatcher // dispatcher for reserved methods |
| 91 | active sync.WaitGroup // active goroutines we've spawned. |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 92 | stoppedChan chan struct{} // closed when the server has been stopped. |
| 93 | preferredProtocols []string // protocols to use when resolving proxy name to endpoint. |
Jungho Ahn | 25545d3 | 2015-01-26 15:14:14 -0800 | [diff] [blame] | 94 | // We cache the IP networks on the device since it is not that cheap to read |
| 95 | // network interfaces through os syscall. |
| 96 | // TODO(jhahn): Add monitoring the network interface changes. |
| 97 | ipNets []*net.IPNet |
David Why Use Two When One Will Do Presotto | d424c21 | 2015-02-25 11:05:26 -0800 | [diff] [blame] | 98 | ns ns.Namespace |
Jungho Ahn | 25545d3 | 2015-01-26 15:14:14 -0800 | [diff] [blame] | 99 | servesMountTable bool |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 100 | |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 101 | // TODO(cnicolaou): add roaming stats to ipcStats |
Matt Rosencrantz | 5f98d94 | 2015-01-08 13:48:30 -0800 | [diff] [blame] | 102 | stats *ipcStats // stats for this server. |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 103 | } |
| 104 | |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 105 | type serverState int |
| 106 | |
| 107 | const ( |
| 108 | initialized serverState = iota |
| 109 | listening |
| 110 | serving |
| 111 | publishing |
| 112 | stopping |
| 113 | stopped |
| 114 | ) |
| 115 | |
| 116 | // Simple state machine for the server implementation. |
| 117 | type next map[serverState]bool |
| 118 | type transitions map[serverState]next |
| 119 | |
| 120 | var ( |
| 121 | states = transitions{ |
| 122 | initialized: next{listening: true, stopping: true}, |
| 123 | listening: next{listening: true, serving: true, stopping: true}, |
| 124 | serving: next{publishing: true, stopping: true}, |
| 125 | publishing: next{publishing: true, stopping: true}, |
| 126 | stopping: next{}, |
| 127 | stopped: next{}, |
| 128 | } |
| 129 | |
| 130 | externalStates = map[serverState]ipc.ServerState{ |
| 131 | initialized: ipc.ServerInit, |
| 132 | listening: ipc.ServerActive, |
| 133 | serving: ipc.ServerActive, |
| 134 | publishing: ipc.ServerActive, |
| 135 | stopping: ipc.ServerStopping, |
| 136 | stopped: ipc.ServerStopped, |
| 137 | } |
| 138 | ) |
| 139 | |
| 140 | func (s *server) allowed(next serverState, method string) error { |
| 141 | if states[s.state][next] { |
| 142 | s.state = next |
| 143 | return nil |
| 144 | } |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 145 | return verror.New(verror.ErrBadState, s.ctx, fmt.Sprintf("%s called out of order or more than once", method)) |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 146 | } |
| 147 | |
| 148 | func (s *server) isStopState() bool { |
| 149 | return s.state == stopping || s.state == stopped |
| 150 | } |
| 151 | |
Benjamin Prosnitz | fdfbf7b | 2014-10-08 09:47:21 -0700 | [diff] [blame] | 152 | var _ ipc.Server = (*server)(nil) |
| 153 | |
Suharsh Sivakumar | 59c423c | 2015-03-11 14:06:03 -0700 | [diff] [blame] | 154 | func InternalNewServer(ctx *context.T, streamMgr stream.Manager, ns ns.Namespace, client ipc.Client, principal security.Principal, opts ...ipc.ServerOpt) (ipc.Server, error) { |
Matt Rosencrantz | 1094d06 | 2015-01-30 06:43:12 -0800 | [diff] [blame] | 155 | ctx, cancel := context.WithRootCancel(ctx) |
Matt Rosencrantz | 5f98d94 | 2015-01-08 13:48:30 -0800 | [diff] [blame] | 156 | ctx, _ = vtrace.SetNewSpan(ctx, "NewServer") |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 157 | statsPrefix := naming.Join("ipc", "server", "routing-id", streamMgr.RoutingID().String()) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 158 | s := &server{ |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 159 | ctx: ctx, |
| 160 | cancel: cancel, |
| 161 | streamMgr: streamMgr, |
Suharsh Sivakumar | 59c423c | 2015-03-11 14:06:03 -0700 | [diff] [blame] | 162 | principal: principal, |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 163 | publisher: publisher.New(ctx, ns, publishPeriod), |
| 164 | listenState: make(map[*listenState]struct{}), |
| 165 | listeners: make(map[stream.Listener]struct{}), |
| 166 | proxies: make(map[string]proxyState), |
| 167 | stoppedChan: make(chan struct{}), |
| 168 | ipNets: ipNetworks(), |
| 169 | ns: ns, |
| 170 | stats: newIPCStats(statsPrefix), |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 171 | } |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 172 | var ( |
Suharsh Sivakumar | 0891858 | 2015-03-03 15:16:36 -0800 | [diff] [blame] | 173 | blessings security.Blessings |
| 174 | dischargeExpiryBuffer = vc.DefaultServerDischargeExpiryBuffer |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 175 | ) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 176 | for _, opt := range opts { |
Bogdan Caprita | 187269b | 2014-05-13 19:59:46 -0700 | [diff] [blame] | 177 | switch opt := opt.(type) { |
| 178 | case stream.ListenerOpt: |
| 179 | // Collect all ServerOpts that are also ListenerOpts. |
| 180 | s.listenerOpts = append(s.listenerOpts, opt) |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 181 | switch opt := opt.(type) { |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 182 | case options.ServerBlessings: |
| 183 | blessings = opt.Blessings |
Suharsh Sivakumar | 0891858 | 2015-03-03 15:16:36 -0800 | [diff] [blame] | 184 | case vc.DischargeExpiryBuffer: |
| 185 | dischargeExpiryBuffer = time.Duration(opt) |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 186 | } |
Asim Shankar | cc04421 | 2014-10-15 23:25:26 -0700 | [diff] [blame] | 187 | case options.ServesMountTable: |
Cosmos Nicolaou | e6e87f1 | 2014-06-03 14:29:10 -0700 | [diff] [blame] | 188 | s.servesMountTable = bool(opt) |
Suharsh Sivakumar | d7a6519 | 2015-01-27 22:57:15 -0800 | [diff] [blame] | 189 | case ReservedNameDispatcher: |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 190 | s.dispReserved = opt.Dispatcher |
Nicolas LaCasse | 55a10f3 | 2014-11-26 13:25:53 -0800 | [diff] [blame] | 191 | case PreferredServerResolveProtocols: |
| 192 | s.preferredProtocols = []string(opt) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 193 | } |
| 194 | } |
Suharsh Sivakumar | 0891858 | 2015-03-03 15:16:36 -0800 | [diff] [blame] | 195 | // Make dischargeExpiryBuffer shorter than the VC discharge buffer to ensure we have fetched |
| 196 | // the discharges by the time the VC asks for them.` |
| 197 | dc := InternalNewDischargeClient(ctx, client, dischargeExpiryBuffer-(5*time.Second)) |
Suharsh Sivakumar | 1b6683e | 2014-12-30 13:00:38 -0800 | [diff] [blame] | 198 | s.listenerOpts = append(s.listenerOpts, dc) |
Benjamin Prosnitz | 9284a00 | 2015-02-23 14:57:25 -0800 | [diff] [blame] | 199 | s.listenerOpts = append(s.listenerOpts, vc.DialContext{ctx}) |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 200 | blessingsStatsName := naming.Join(statsPrefix, "security", "blessings") |
Asim Shankar | 2bf7b1e | 2015-02-27 00:45:12 -0800 | [diff] [blame] | 201 | // TODO(caprita): revist printing the blessings with %s, and |
| 202 | // instead expose them as a list. |
| 203 | stats.NewString(blessingsStatsName).Set(fmt.Sprintf("%s", blessings)) |
| 204 | if principal != nil { // principal should have been passed in, but just in case. |
Bogdan Caprita | e737631 | 2014-11-10 13:13:17 -0800 | [diff] [blame] | 205 | stats.NewStringFunc(blessingsStatsName, func() string { |
| 206 | return fmt.Sprintf("%s (default)", principal.BlessingStore().Default()) |
| 207 | }) |
| 208 | } |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 209 | return s, nil |
| 210 | } |
| 211 | |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 212 | func (s *server) Status() ipc.ServerStatus { |
| 213 | status := ipc.ServerStatus{} |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 214 | defer vlog.LogCall()() |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 215 | s.Lock() |
| 216 | defer s.Unlock() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 217 | status.State = externalStates[s.state] |
| 218 | status.ServesMountTable = s.servesMountTable |
| 219 | status.Mounts = s.publisher.Status() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 220 | status.Endpoints = []naming.Endpoint{} |
| 221 | for ls, _ := range s.listenState { |
| 222 | if ls.eperr != nil { |
| 223 | status.Errors = append(status.Errors, ls.eperr) |
| 224 | } |
| 225 | if ls.lnerr != nil { |
| 226 | status.Errors = append(status.Errors, ls.lnerr) |
| 227 | } |
| 228 | for _, iep := range ls.ieps { |
| 229 | status.Endpoints = append(status.Endpoints, iep) |
| 230 | } |
| 231 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 232 | status.Proxies = make([]ipc.ProxyStatus, 0, len(s.proxies)) |
| 233 | for k, v := range s.proxies { |
| 234 | status.Proxies = append(status.Proxies, ipc.ProxyStatus{k, v.endpoint, v.err}) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 235 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 236 | return status |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 237 | } |
| 238 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 239 | func (s *server) WatchNetwork(ch chan<- ipc.NetworkChange) { |
| 240 | defer vlog.LogCall()() |
| 241 | s.Lock() |
| 242 | defer s.Unlock() |
| 243 | if s.dhcpState != nil { |
| 244 | s.dhcpState.watchers[ch] = struct{}{} |
| 245 | } |
| 246 | } |
| 247 | |
| 248 | func (s *server) UnwatchNetwork(ch chan<- ipc.NetworkChange) { |
| 249 | defer vlog.LogCall()() |
| 250 | s.Lock() |
| 251 | defer s.Unlock() |
| 252 | if s.dhcpState != nil { |
| 253 | delete(s.dhcpState.watchers, ch) |
| 254 | } |
| 255 | } |
| 256 | |
Robin Thellend | 92b65a4 | 2014-12-17 14:30:16 -0800 | [diff] [blame] | 257 | // resolveToEndpoint resolves an object name or address to an endpoint. |
| 258 | func (s *server) resolveToEndpoint(address string) (string, error) { |
Asim Shankar | aae3180 | 2015-01-22 11:59:42 -0800 | [diff] [blame] | 259 | var resolved *naming.MountEntry |
| 260 | var err error |
Asim Shankar | dee311d | 2014-08-01 17:41:31 -0700 | [diff] [blame] | 261 | if s.ns != nil { |
Asim Shankar | aae3180 | 2015-01-22 11:59:42 -0800 | [diff] [blame] | 262 | if resolved, err = s.ns.Resolve(s.ctx, address); err != nil { |
Asim Shankar | dee311d | 2014-08-01 17:41:31 -0700 | [diff] [blame] | 263 | return "", err |
| 264 | } |
| 265 | } else { |
Asim Shankar | aae3180 | 2015-01-22 11:59:42 -0800 | [diff] [blame] | 266 | // Fake a namespace resolution |
| 267 | resolved = &naming.MountEntry{Servers: []naming.MountedServer{ |
| 268 | {Server: address}, |
| 269 | }} |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 270 | } |
Nicolas LaCasse | 55a10f3 | 2014-11-26 13:25:53 -0800 | [diff] [blame] | 271 | // An empty set of protocols means all protocols... |
Jungho Ahn | 25545d3 | 2015-01-26 15:14:14 -0800 | [diff] [blame] | 272 | if resolved.Servers, err = filterAndOrderServers(resolved.Servers, s.preferredProtocols, s.ipNets); err != nil { |
Nicolas LaCasse | 55a10f3 | 2014-11-26 13:25:53 -0800 | [diff] [blame] | 273 | return "", err |
| 274 | } |
Asim Shankar | aae3180 | 2015-01-22 11:59:42 -0800 | [diff] [blame] | 275 | for _, n := range resolved.Names() { |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 276 | address, suffix := naming.SplitAddressName(n) |
David Why Use Two When One Will Do Presotto | adf0ca1 | 2014-11-13 10:49:01 -0800 | [diff] [blame] | 277 | if suffix != "" { |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 278 | continue |
| 279 | } |
Asim Shankar | aae3180 | 2015-01-22 11:59:42 -0800 | [diff] [blame] | 280 | if ep, err := inaming.NewEndpoint(address); err == nil { |
| 281 | return ep.String(), nil |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 282 | } |
| 283 | } |
Asim Shankar | dee311d | 2014-08-01 17:41:31 -0700 | [diff] [blame] | 284 | return "", fmt.Errorf("unable to resolve %q to an endpoint", address) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 285 | } |
| 286 | |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 287 | // getPossbileAddrs returns an appropriate set of addresses that could be used |
| 288 | // to contact the supplied protocol, host, port parameters using the supplied |
| 289 | // chooser function. It returns an indication of whether the supplied address |
| 290 | // was fully specified or not, returning false if the address was fully |
| 291 | // specified, and true if it was not. |
| 292 | func getPossibleAddrs(protocol, host, port string, chooser ipc.AddressChooser) ([]ipc.Address, bool, error) { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 293 | |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 294 | ip := net.ParseIP(host) |
| 295 | if ip == nil { |
| 296 | return nil, false, fmt.Errorf("failed to parse %q as an IP host", host) |
| 297 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 298 | |
| 299 | addrFromIP := func(ip net.IP) ipc.Address { |
| 300 | return &netstate.AddrIfc{ |
| 301 | Addr: &net.IPAddr{IP: ip}, |
| 302 | } |
| 303 | } |
| 304 | |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 305 | if ip.IsUnspecified() { |
| 306 | if chooser != nil { |
| 307 | // Need to find a usable IP address since the call to listen |
| 308 | // didn't specify one. |
| 309 | if addrs, err := netstate.GetAccessibleIPs(); err == nil { |
Cosmos Nicolaou | d70e1fc | 2014-12-16 14:20:39 -0800 | [diff] [blame] | 310 | a, err := chooser(protocol, addrs) |
| 311 | if err == nil && len(a) > 0 { |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 312 | return a, true, nil |
| 313 | } |
| 314 | } |
| 315 | } |
| 316 | // We don't have a chooser, so we just return the address the |
| 317 | // underlying system has chosen. |
| 318 | return []ipc.Address{addrFromIP(ip)}, true, nil |
| 319 | } |
| 320 | return []ipc.Address{addrFromIP(ip)}, false, nil |
| 321 | } |
| 322 | |
| 323 | // createEndpoints creates appropriate inaming.Endpoint instances for |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 324 | // all of the externally accessible network addresses that can be used |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 325 | // to reach this server. |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 326 | func (s *server) createEndpoints(lep naming.Endpoint, chooser ipc.AddressChooser) ([]*inaming.Endpoint, string, bool, error) { |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 327 | iep, ok := lep.(*inaming.Endpoint) |
| 328 | if !ok { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 329 | return nil, "", false, fmt.Errorf("internal type conversion error for %T", lep) |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 330 | } |
| 331 | if !strings.HasPrefix(iep.Protocol, "tcp") && |
| 332 | !strings.HasPrefix(iep.Protocol, "ws") { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 333 | // If not tcp, ws, or wsh, just return the endpoint we were given. |
| 334 | return []*inaming.Endpoint{iep}, "", false, nil |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 335 | } |
| 336 | |
| 337 | host, port, err := net.SplitHostPort(iep.Address) |
| 338 | if err != nil { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 339 | return nil, "", false, err |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 340 | } |
Cosmos Nicolaou | d70e1fc | 2014-12-16 14:20:39 -0800 | [diff] [blame] | 341 | addrs, unspecified, err := getPossibleAddrs(iep.Protocol, host, port, chooser) |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 342 | if err != nil { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 343 | return nil, port, false, err |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 344 | } |
| 345 | ieps := make([]*inaming.Endpoint, 0, len(addrs)) |
| 346 | for _, addr := range addrs { |
| 347 | n, err := inaming.NewEndpoint(lep.String()) |
| 348 | if err != nil { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 349 | return nil, port, false, err |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 350 | } |
| 351 | n.IsMountTable = s.servesMountTable |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 352 | n.Address = net.JoinHostPort(addr.Address().String(), port) |
| 353 | ieps = append(ieps, n) |
| 354 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 355 | return ieps, port, unspecified, nil |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 356 | } |
| 357 | |
| 358 | func (s *server) Listen(listenSpec ipc.ListenSpec) ([]naming.Endpoint, error) { |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 359 | defer vlog.LogCall()() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 360 | useProxy := len(listenSpec.Proxy) > 0 |
| 361 | if !useProxy && len(listenSpec.Addrs) == 0 { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 362 | return nil, verror.New(verror.ErrBadArg, s.ctx, "ListenSpec contains no proxy or addresses to listen on") |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 363 | } |
| 364 | |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 365 | s.Lock() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 366 | defer s.Unlock() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 367 | |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 368 | if err := s.allowed(listening, "Listen"); err != nil { |
| 369 | return nil, err |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 370 | } |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 371 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 372 | // Start the proxy as early as possible, ignore duplicate requests |
| 373 | // for the same proxy. |
| 374 | if _, inuse := s.proxies[listenSpec.Proxy]; useProxy && !inuse { |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 375 | // We have a goroutine for listening on proxy connections. |
Cosmos Nicolaou | eef1fab | 2014-11-11 18:23:41 -0800 | [diff] [blame] | 376 | s.active.Add(1) |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 377 | go func() { |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 378 | s.proxyListenLoop(listenSpec.Proxy) |
| 379 | s.active.Done() |
| 380 | }() |
| 381 | } |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 382 | |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 383 | roaming := false |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 384 | lnState := make([]*listenState, 0, len(listenSpec.Addrs)) |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 385 | for _, addr := range listenSpec.Addrs { |
| 386 | if len(addr.Address) > 0 { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 387 | // Listen if we have a local address to listen on. |
| 388 | ls := &listenState{ |
| 389 | protocol: addr.Protocol, |
| 390 | address: addr.Address, |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 391 | } |
Suharsh Sivakumar | 59c423c | 2015-03-11 14:06:03 -0700 | [diff] [blame] | 392 | ls.ln, ls.lep, ls.lnerr = s.streamMgr.Listen(addr.Protocol, addr.Address, s.principal, s.listenerOpts...) |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 393 | lnState = append(lnState, ls) |
| 394 | if ls.lnerr != nil { |
Asim Shankar | 7171a25 | 2015-03-07 14:41:40 -0800 | [diff] [blame] | 395 | vlog.VI(2).Infof("Listen(%q, %q, ...) failed: %v", addr.Protocol, addr.Address, ls.lnerr) |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 396 | continue |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 397 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 398 | ls.ieps, ls.port, ls.roaming, ls.eperr = s.createEndpoints(ls.lep, listenSpec.AddressChooser) |
| 399 | if ls.roaming && ls.eperr == nil { |
| 400 | ls.protoIEP = *ls.lep.(*inaming.Endpoint) |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 401 | roaming = true |
| 402 | } |
| 403 | } |
| 404 | } |
| 405 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 406 | found := false |
| 407 | for _, ls := range lnState { |
| 408 | if ls.ln != nil { |
| 409 | found = true |
| 410 | break |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 411 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 412 | } |
| 413 | if !found && !useProxy { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 414 | return nil, verror.New(verror.ErrBadArg, s.ctx, "failed to create any listeners") |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 415 | } |
| 416 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 417 | if roaming && s.dhcpState == nil && listenSpec.StreamPublisher != nil { |
| 418 | // Create a dhcp listener if we haven't already done so. |
| 419 | dhcp := &dhcpState{ |
| 420 | name: listenSpec.StreamName, |
| 421 | publisher: listenSpec.StreamPublisher, |
| 422 | watchers: make(map[chan<- ipc.NetworkChange]struct{}), |
| 423 | } |
| 424 | s.dhcpState = dhcp |
| 425 | dhcp.ch = make(chan config.Setting, 10) |
| 426 | dhcp.stream, dhcp.err = dhcp.publisher.ForkStream(dhcp.name, dhcp.ch) |
| 427 | if dhcp.err == nil { |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 428 | // We have a goroutine to listen for dhcp changes. |
| 429 | s.active.Add(1) |
| 430 | go func() { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 431 | s.dhcpLoop(dhcp.ch) |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 432 | s.active.Done() |
| 433 | }() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 434 | } |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 435 | } |
| 436 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 437 | eps := make([]naming.Endpoint, 0, 10) |
| 438 | for _, ls := range lnState { |
| 439 | s.listenState[ls] = struct{}{} |
| 440 | if ls.ln != nil { |
| 441 | // We have a goroutine per listener to accept new flows. |
| 442 | // Each flow is served from its own goroutine. |
| 443 | s.active.Add(1) |
| 444 | go func(ln stream.Listener, ep naming.Endpoint) { |
| 445 | s.listenLoop(ln, ep) |
| 446 | s.active.Done() |
| 447 | }(ls.ln, ls.lep) |
| 448 | } |
| 449 | |
| 450 | for _, iep := range ls.ieps { |
| 451 | s.publisher.AddServer(iep.String(), s.servesMountTable) |
| 452 | eps = append(eps, iep) |
| 453 | } |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 454 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 455 | |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 456 | return eps, nil |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 457 | } |
| 458 | |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 459 | func (s *server) reconnectAndPublishProxy(proxy string) (*inaming.Endpoint, stream.Listener, error) { |
Robin Thellend | 92b65a4 | 2014-12-17 14:30:16 -0800 | [diff] [blame] | 460 | resolved, err := s.resolveToEndpoint(proxy) |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 461 | if err != nil { |
| 462 | return nil, nil, fmt.Errorf("Failed to resolve proxy %q (%v)", proxy, err) |
| 463 | } |
Suharsh Sivakumar | 59c423c | 2015-03-11 14:06:03 -0700 | [diff] [blame] | 464 | ln, ep, err := s.streamMgr.Listen(inaming.Network, resolved, s.principal, s.listenerOpts...) |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 465 | if err != nil { |
| 466 | return nil, nil, fmt.Errorf("failed to listen on %q: %s", resolved, err) |
| 467 | } |
| 468 | iep, ok := ep.(*inaming.Endpoint) |
| 469 | if !ok { |
| 470 | ln.Close() |
| 471 | return nil, nil, fmt.Errorf("internal type conversion error for %T", ep) |
| 472 | } |
| 473 | s.Lock() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 474 | s.proxies[proxy] = proxyState{iep, nil} |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 475 | s.Unlock() |
Robin Thellend | e22920e | 2015-02-05 17:15:50 -0800 | [diff] [blame] | 476 | iep.IsMountTable = s.servesMountTable |
Cosmos Nicolaou | 8bd8e10 | 2015-01-13 21:52:53 -0800 | [diff] [blame] | 477 | s.publisher.AddServer(iep.String(), s.servesMountTable) |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 478 | return iep, ln, nil |
| 479 | } |
| 480 | |
| 481 | func (s *server) proxyListenLoop(proxy string) { |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 482 | const ( |
| 483 | min = 5 * time.Millisecond |
| 484 | max = 5 * time.Minute |
| 485 | ) |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 486 | |
| 487 | iep, ln, err := s.reconnectAndPublishProxy(proxy) |
| 488 | if err != nil { |
| 489 | vlog.VI(1).Infof("Failed to connect to proxy: %s", err) |
| 490 | } |
| 491 | // the initial connection maybe have failed, but we enter the retry |
| 492 | // loop anyway so that we will continue to try and connect to the |
| 493 | // proxy. |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 494 | s.Lock() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 495 | if s.isStopState() { |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 496 | s.Unlock() |
| 497 | return |
| 498 | } |
| 499 | s.Unlock() |
| 500 | |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 501 | for { |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 502 | if ln != nil && iep != nil { |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 503 | err := s.listenLoop(ln, iep) |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 504 | // The listener is done, so: |
| 505 | // (1) Unpublish its name |
Cosmos Nicolaou | 8bd8e10 | 2015-01-13 21:52:53 -0800 | [diff] [blame] | 506 | s.publisher.RemoveServer(iep.String()) |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 507 | s.Lock() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 508 | if err != nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 509 | s.proxies[proxy] = proxyState{iep, verror.New(verror.ErrNoServers, s.ctx, err)} |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 510 | } else { |
Asim Shankar | 7171a25 | 2015-03-07 14:41:40 -0800 | [diff] [blame] | 511 | // err will be nil if we're stopping. |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 512 | s.proxies[proxy] = proxyState{iep, nil} |
| 513 | s.Unlock() |
| 514 | return |
| 515 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 516 | s.Unlock() |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 517 | } |
| 518 | |
| 519 | s.Lock() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 520 | if s.isStopState() { |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 521 | s.Unlock() |
| 522 | return |
| 523 | } |
| 524 | s.Unlock() |
| 525 | |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 526 | // (2) Reconnect to the proxy unless the server has been stopped |
| 527 | backoff := min |
| 528 | ln = nil |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 529 | for { |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 530 | select { |
| 531 | case <-time.After(backoff): |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 532 | if backoff = backoff * 2; backoff > max { |
| 533 | backoff = max |
| 534 | } |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 535 | case <-s.stoppedChan: |
| 536 | return |
| 537 | } |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 538 | // (3) reconnect, publish new address |
| 539 | if iep, ln, err = s.reconnectAndPublishProxy(proxy); err != nil { |
| 540 | vlog.VI(1).Infof("Failed to reconnect to proxy %q: %s", proxy, err) |
| 541 | } else { |
| 542 | vlog.VI(1).Infof("Reconnected to proxy %q, %s", proxy, iep) |
| 543 | break |
| 544 | } |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 545 | } |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 546 | } |
| 547 | } |
| 548 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 549 | // addListener adds the supplied listener taking care to |
| 550 | // check to see if we're already stopping. It returns true |
| 551 | // if the listener was added. |
| 552 | func (s *server) addListener(ln stream.Listener) bool { |
| 553 | s.Lock() |
| 554 | defer s.Unlock() |
| 555 | if s.isStopState() { |
| 556 | return false |
| 557 | } |
| 558 | s.listeners[ln] = struct{}{} |
| 559 | return true |
| 560 | } |
| 561 | |
| 562 | // rmListener removes the supplied listener taking care to |
| 563 | // check if we're already stopping. It returns true if the |
| 564 | // listener was removed. |
| 565 | func (s *server) rmListener(ln stream.Listener) bool { |
| 566 | s.Lock() |
| 567 | defer s.Unlock() |
| 568 | if s.isStopState() { |
| 569 | return false |
| 570 | } |
| 571 | delete(s.listeners, ln) |
| 572 | return true |
| 573 | } |
| 574 | |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 575 | func (s *server) listenLoop(ln stream.Listener, ep naming.Endpoint) error { |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 576 | defer vlog.VI(1).Infof("ipc: Stopped listening on %s", ep) |
Cosmos Nicolaou | eef1fab | 2014-11-11 18:23:41 -0800 | [diff] [blame] | 577 | var calls sync.WaitGroup |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 578 | |
| 579 | if !s.addListener(ln) { |
| 580 | // We're stopping. |
| 581 | return nil |
| 582 | } |
| 583 | |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 584 | defer func() { |
Cosmos Nicolaou | eef1fab | 2014-11-11 18:23:41 -0800 | [diff] [blame] | 585 | calls.Wait() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 586 | s.rmListener(ln) |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 587 | }() |
| 588 | for { |
| 589 | flow, err := ln.Accept() |
| 590 | if err != nil { |
Todd Wang | 03fee96 | 2014-12-08 19:33:10 -0800 | [diff] [blame] | 591 | vlog.VI(10).Infof("ipc: Accept on %v failed: %v", ep, err) |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 592 | return err |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 593 | } |
Cosmos Nicolaou | eef1fab | 2014-11-11 18:23:41 -0800 | [diff] [blame] | 594 | calls.Add(1) |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 595 | go func(flow stream.Flow) { |
Todd Wang | 34ed4c6 | 2014-11-26 15:15:52 -0800 | [diff] [blame] | 596 | defer calls.Done() |
| 597 | fs, err := newFlowServer(flow, s) |
| 598 | if err != nil { |
Todd Wang | 03fee96 | 2014-12-08 19:33:10 -0800 | [diff] [blame] | 599 | vlog.Errorf("newFlowServer on %v failed: %v", ep, err) |
Todd Wang | 34ed4c6 | 2014-11-26 15:15:52 -0800 | [diff] [blame] | 600 | return |
| 601 | } |
| 602 | if err := fs.serve(); err != nil { |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 603 | // TODO(caprita): Logging errors here is too spammy. For example, "not |
| 604 | // authorized" errors shouldn't be logged as server errors. |
Cosmos Nicolaou | 93dd88b | 2015-02-19 15:10:53 -0800 | [diff] [blame] | 605 | // TODO(cnicolaou): revisit this when verror2 transition is |
| 606 | // done. |
Cosmos Nicolaou | 1534b3f | 2014-12-10 15:30:00 -0800 | [diff] [blame] | 607 | if err != io.EOF { |
Cosmos Nicolaou | 93dd88b | 2015-02-19 15:10:53 -0800 | [diff] [blame] | 608 | vlog.VI(2).Infof("Flow serve on %v failed: %v", ep, err) |
Cosmos Nicolaou | 1534b3f | 2014-12-10 15:30:00 -0800 | [diff] [blame] | 609 | } |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 610 | } |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 611 | }(flow) |
| 612 | } |
| 613 | } |
| 614 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 615 | func (s *server) dhcpLoop(ch chan config.Setting) { |
| 616 | defer vlog.VI(1).Infof("ipc: Stopped listen for dhcp changes") |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 617 | vlog.VI(2).Infof("ipc: dhcp loop") |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 618 | for setting := range ch { |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 619 | if setting == nil { |
| 620 | return |
| 621 | } |
| 622 | switch v := setting.Value().(type) { |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 623 | case []ipc.Address: |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 624 | s.Lock() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 625 | if s.isStopState() { |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 626 | s.Unlock() |
| 627 | return |
| 628 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 629 | var err error |
| 630 | var changed []naming.Endpoint |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 631 | switch setting.Name() { |
| 632 | case ipc.NewAddrsSetting: |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 633 | changed = s.addAddresses(v) |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 634 | case ipc.RmAddrsSetting: |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 635 | changed, err = s.removeAddresses(v) |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 636 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 637 | change := ipc.NetworkChange{ |
| 638 | Time: time.Now(), |
| 639 | State: externalStates[s.state], |
| 640 | Setting: setting, |
| 641 | Changed: changed, |
| 642 | Error: err, |
| 643 | } |
| 644 | vlog.VI(2).Infof("ipc: dhcp: change %v", change) |
| 645 | for ch, _ := range s.dhcpState.watchers { |
| 646 | select { |
| 647 | case ch <- change: |
| 648 | default: |
| 649 | } |
| 650 | } |
| 651 | s.Unlock() |
| 652 | default: |
| 653 | vlog.Errorf("ipc: dhcpLoop: unhandled setting type %T", v) |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 654 | } |
| 655 | } |
| 656 | } |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 657 | |
| 658 | func getHost(address ipc.Address) string { |
| 659 | host, _, err := net.SplitHostPort(address.Address().String()) |
| 660 | if err == nil { |
| 661 | return host |
| 662 | } |
| 663 | return address.Address().String() |
| 664 | |
| 665 | } |
| 666 | |
| 667 | // Remove all endpoints that have the same host address as the supplied |
| 668 | // address parameter. |
| 669 | func (s *server) removeAddresses(addresses []ipc.Address) ([]naming.Endpoint, error) { |
| 670 | var removed []naming.Endpoint |
| 671 | for _, address := range addresses { |
| 672 | host := getHost(address) |
| 673 | for ls, _ := range s.listenState { |
| 674 | if ls != nil && ls.roaming && len(ls.ieps) > 0 { |
| 675 | remaining := make([]*inaming.Endpoint, 0, len(ls.ieps)) |
| 676 | for _, iep := range ls.ieps { |
| 677 | lnHost, _, err := net.SplitHostPort(iep.Address) |
| 678 | if err != nil { |
| 679 | lnHost = iep.Address |
| 680 | } |
| 681 | if lnHost == host { |
| 682 | vlog.VI(2).Infof("ipc: dhcp removing: %s", iep) |
| 683 | removed = append(removed, iep) |
| 684 | s.publisher.RemoveServer(iep.String()) |
| 685 | continue |
| 686 | } |
| 687 | remaining = append(remaining, iep) |
| 688 | } |
| 689 | ls.ieps = remaining |
| 690 | } |
| 691 | } |
| 692 | } |
| 693 | return removed, nil |
| 694 | } |
| 695 | |
| 696 | // Add new endpoints for the new address. There is no way to know with |
| 697 | // 100% confidence which new endpoints to publish without shutting down |
| 698 | // all network connections and reinitializing everything from scratch. |
| 699 | // Instead, we find all roaming listeners with at least one endpoint |
| 700 | // and create a new endpoint with the same port as the existing ones |
| 701 | // but with the new address supplied to us to by the dhcp code. As |
| 702 | // an additional safeguard we reject the new address if it is not |
| 703 | // externally accessible. |
| 704 | // This places the onus on the dhcp/roaming code that sends us addresses |
| 705 | // to ensure that those addresses are externally reachable. |
| 706 | func (s *server) addAddresses(addresses []ipc.Address) []naming.Endpoint { |
| 707 | var added []naming.Endpoint |
| 708 | for _, address := range addresses { |
| 709 | if !netstate.IsAccessibleIP(address) { |
| 710 | return added |
| 711 | } |
| 712 | host := getHost(address) |
| 713 | for ls, _ := range s.listenState { |
| 714 | if ls != nil && ls.roaming { |
| 715 | niep := ls.protoIEP |
| 716 | niep.Address = net.JoinHostPort(host, ls.port) |
| 717 | ls.ieps = append(ls.ieps, &niep) |
| 718 | vlog.VI(2).Infof("ipc: dhcp adding: %s", niep) |
| 719 | s.publisher.AddServer(niep.String(), s.servesMountTable) |
| 720 | added = append(added, &niep) |
| 721 | } |
| 722 | } |
| 723 | } |
| 724 | return added |
| 725 | } |
Cosmos Nicolaou | ef323db | 2014-09-07 22:13:28 -0700 | [diff] [blame] | 726 | |
Bogdan Caprita | 7590a6d | 2015-01-08 13:43:40 -0800 | [diff] [blame] | 727 | type leafDispatcher struct { |
| 728 | invoker ipc.Invoker |
| 729 | auth security.Authorizer |
| 730 | } |
| 731 | |
| 732 | func (d leafDispatcher) Lookup(suffix string) (interface{}, security.Authorizer, error) { |
| 733 | if suffix != "" { |
Todd Wang | ff73e1f | 2015-02-10 21:45:52 -0800 | [diff] [blame] | 734 | return nil, nil, ipc.NewErrUnknownSuffix(nil, suffix) |
Bogdan Caprita | 7590a6d | 2015-01-08 13:43:40 -0800 | [diff] [blame] | 735 | } |
| 736 | return d.invoker, d.auth, nil |
| 737 | } |
| 738 | |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 739 | func (s *server) Serve(name string, obj interface{}, authorizer security.Authorizer) error { |
Cosmos Nicolaou | 8bd8e10 | 2015-01-13 21:52:53 -0800 | [diff] [blame] | 740 | defer vlog.LogCall()() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 741 | if obj == nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 742 | return verror.New(verror.ErrBadArg, s.ctx, "nil object") |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 743 | } |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 744 | invoker, err := objectToInvoker(obj) |
| 745 | if err != nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 746 | return verror.New(verror.ErrBadArg, s.ctx, fmt.Sprintf("bad object: %v", err)) |
Cosmos Nicolaou | 61c96c7 | 2014-11-03 11:57:56 -0800 | [diff] [blame] | 747 | } |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 748 | return s.ServeDispatcher(name, &leafDispatcher{invoker, authorizer}) |
Cosmos Nicolaou | 61c96c7 | 2014-11-03 11:57:56 -0800 | [diff] [blame] | 749 | } |
| 750 | |
| 751 | func (s *server) ServeDispatcher(name string, disp ipc.Dispatcher) error { |
Cosmos Nicolaou | 8bd8e10 | 2015-01-13 21:52:53 -0800 | [diff] [blame] | 752 | defer vlog.LogCall()() |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 753 | if disp == nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 754 | return verror.New(verror.ErrBadArg, s.ctx, "nil dispatcher") |
Cosmos Nicolaou | fdc838b | 2014-06-30 21:44:27 -0700 | [diff] [blame] | 755 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 756 | s.Lock() |
| 757 | defer s.Unlock() |
| 758 | if err := s.allowed(serving, "Serve or ServeDispatcher"); err != nil { |
| 759 | return err |
Cosmos Nicolaou | fdc838b | 2014-06-30 21:44:27 -0700 | [diff] [blame] | 760 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 761 | vtrace.GetSpan(s.ctx).Annotate("Serving under name: " + name) |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 762 | s.disp = disp |
Cosmos Nicolaou | fdc838b | 2014-06-30 21:44:27 -0700 | [diff] [blame] | 763 | if len(name) > 0 { |
| 764 | s.publisher.AddName(name) |
| 765 | } |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 766 | return nil |
| 767 | } |
| 768 | |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 769 | func (s *server) AddName(name string) error { |
Cosmos Nicolaou | 8bd8e10 | 2015-01-13 21:52:53 -0800 | [diff] [blame] | 770 | defer vlog.LogCall()() |
Ali Ghassemi | 3c6db7b | 2014-11-10 17:20:26 -0800 | [diff] [blame] | 771 | if len(name) == 0 { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 772 | return verror.New(verror.ErrBadArg, s.ctx, "name is empty") |
Ali Ghassemi | 3c6db7b | 2014-11-10 17:20:26 -0800 | [diff] [blame] | 773 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 774 | s.Lock() |
| 775 | defer s.Unlock() |
| 776 | if err := s.allowed(publishing, "AddName"); err != nil { |
| 777 | return err |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 778 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 779 | vtrace.GetSpan(s.ctx).Annotate("Serving under name: " + name) |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 780 | s.publisher.AddName(name) |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 781 | return nil |
| 782 | } |
| 783 | |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 784 | func (s *server) RemoveName(name string) { |
Cosmos Nicolaou | 8bd8e10 | 2015-01-13 21:52:53 -0800 | [diff] [blame] | 785 | defer vlog.LogCall()() |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 786 | s.Lock() |
| 787 | defer s.Unlock() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 788 | if err := s.allowed(publishing, "RemoveName"); err != nil { |
| 789 | return |
| 790 | } |
Matt Rosencrantz | 5f98d94 | 2015-01-08 13:48:30 -0800 | [diff] [blame] | 791 | vtrace.GetSpan(s.ctx).Annotate("Removed name: " + name) |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 792 | s.publisher.RemoveName(name) |
Cosmos Nicolaou | 92dba58 | 2014-11-05 17:24:10 -0800 | [diff] [blame] | 793 | } |
| 794 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 795 | func (s *server) Stop() error { |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 796 | defer vlog.LogCall()() |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 797 | s.Lock() |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 798 | if s.isStopState() { |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 799 | s.Unlock() |
| 800 | return nil |
| 801 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 802 | s.state = stopping |
Asim Shankar | 0ea02ab | 2014-06-09 11:39:24 -0700 | [diff] [blame] | 803 | close(s.stoppedChan) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 804 | s.Unlock() |
| 805 | |
Robin Thellend | df42823 | 2014-10-06 12:50:44 -0700 | [diff] [blame] | 806 | // Delete the stats object. |
| 807 | s.stats.stop() |
| 808 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 809 | // Note, It's safe to Stop/WaitForStop on the publisher outside of the |
| 810 | // server lock, since publisher is safe for concurrent access. |
| 811 | |
| 812 | // Stop the publisher, which triggers unmounting of published names. |
| 813 | s.publisher.Stop() |
| 814 | // Wait for the publisher to be done unmounting before we can proceed to |
| 815 | // close the listeners (to minimize the number of mounted names pointing |
| 816 | // to endpoint that are no longer serving). |
| 817 | // |
| 818 | // TODO(caprita): See if make sense to fail fast on rejecting |
| 819 | // connections once listeners are closed, and parallelize the publisher |
| 820 | // and listener shutdown. |
| 821 | s.publisher.WaitForStop() |
| 822 | |
| 823 | s.Lock() |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 824 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 825 | // Close all listeners. No new flows will be accepted, while in-flight |
| 826 | // flows will continue until they terminate naturally. |
| 827 | nListeners := len(s.listeners) |
| 828 | errCh := make(chan error, nListeners) |
Cosmos Nicolaou | bc74314 | 2014-10-06 21:27:18 -0700 | [diff] [blame] | 829 | |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 830 | for ln, _ := range s.listeners { |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 831 | go func(ln stream.Listener) { |
| 832 | errCh <- ln.Close() |
| 833 | }(ln) |
Cosmos Nicolaou | ae8dd21 | 2014-12-13 23:43:08 -0800 | [diff] [blame] | 834 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 835 | |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 836 | drain := func(ch chan config.Setting) { |
| 837 | for { |
| 838 | select { |
| 839 | case v := <-ch: |
| 840 | if v == nil { |
| 841 | return |
| 842 | } |
| 843 | default: |
| 844 | close(ch) |
| 845 | return |
| 846 | } |
| 847 | } |
| 848 | } |
| 849 | |
| 850 | if dhcp := s.dhcpState; dhcp != nil { |
Cosmos Nicolaou | aceb8d9 | 2015-02-05 20:44:02 -0800 | [diff] [blame] | 851 | // TODO(cnicolaou,caprita): investigate not having to close and drain |
| 852 | // the channel here. It's a little awkward right now since we have to |
| 853 | // be careful to not close the channel in two places, i.e. here and |
| 854 | // and from the publisher's Shutdown method. |
| 855 | if err := dhcp.publisher.CloseFork(dhcp.name, dhcp.ch); err == nil { |
| 856 | drain(dhcp.ch) |
| 857 | } |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 858 | } |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 859 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 860 | s.Unlock() |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 861 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 862 | var firstErr error |
| 863 | for i := 0; i < nListeners; i++ { |
| 864 | if err := <-errCh; err != nil && firstErr == nil { |
| 865 | firstErr = err |
| 866 | } |
| 867 | } |
| 868 | // At this point, we are guaranteed that no new requests are going to be |
| 869 | // accepted. |
| 870 | |
| 871 | // Wait for the publisher and active listener + flows to finish. |
Cosmos Nicolaou | 1b3594d | 2015-02-01 10:05:03 -0800 | [diff] [blame] | 872 | done := make(chan struct{}, 1) |
| 873 | go func() { s.active.Wait(); done <- struct{}{} }() |
| 874 | |
| 875 | select { |
| 876 | case <-done: |
| 877 | case <-time.After(5 * time.Minute): |
| 878 | vlog.Errorf("Listener Close Error: %v", firstErr) |
| 879 | vlog.Errorf("Timedout waiting for goroutines to stop: listeners: %d", nListeners, len(s.listeners)) |
| 880 | for ln, _ := range s.listeners { |
| 881 | vlog.Errorf("Listener: %p", ln) |
| 882 | } |
| 883 | for ls, _ := range s.listenState { |
| 884 | vlog.Errorf("ListenState: %v", ls) |
| 885 | } |
| 886 | <-done |
| 887 | } |
Cosmos Nicolaou | 9388ae4 | 2014-11-10 10:57:15 -0800 | [diff] [blame] | 888 | |
Cosmos Nicolaou | fdc838b | 2014-06-30 21:44:27 -0700 | [diff] [blame] | 889 | s.Lock() |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 890 | defer s.Unlock() |
Cosmos Nicolaou | fdc838b | 2014-06-30 21:44:27 -0700 | [diff] [blame] | 891 | s.disp = nil |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 892 | if firstErr != nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 893 | return verror.New(verror.ErrInternal, s.ctx, firstErr) |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 894 | } |
Cosmos Nicolaou | 9fbe7d2 | 2015-01-25 22:13:13 -0800 | [diff] [blame] | 895 | s.state = stopped |
Matt Rosencrantz | 1094d06 | 2015-01-30 06:43:12 -0800 | [diff] [blame] | 896 | s.cancel() |
Cosmos Nicolaou | 28dabfc | 2014-12-15 22:51:07 -0800 | [diff] [blame] | 897 | return nil |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 898 | } |
| 899 | |
| 900 | // flowServer implements the RPC server-side protocol for a single RPC, over a |
| 901 | // flow that's already connected to the client. |
| 902 | type flowServer struct { |
Matt Rosencrantz | 4f8ac60 | 2014-12-29 14:42:48 -0800 | [diff] [blame] | 903 | *context.T |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 904 | server *server // ipc.Server that this flow server belongs to |
| 905 | disp ipc.Dispatcher // ipc.Dispatcher that will serve RPCs on this flow |
Todd Wang | 3425a90 | 2015-01-21 18:43:59 -0800 | [diff] [blame] | 906 | dec *vom.Decoder // to decode requests and args from the client |
| 907 | enc *vom.Encoder // to encode responses and results to the client |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 908 | flow stream.Flow // underlying flow |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 909 | |
Asim Shankar | 220a015 | 2014-10-30 21:21:09 -0700 | [diff] [blame] | 910 | // Fields filled in during the server invocation. |
Suharsh Sivakumar | 380bf34 | 2015-02-27 15:38:27 -0800 | [diff] [blame] | 911 | clientBlessings security.Blessings |
| 912 | ackBlessings bool |
| 913 | grantedBlessings security.Blessings |
| 914 | method, suffix string |
| 915 | tags []*vdl.Value |
| 916 | discharges map[string]security.Discharge |
| 917 | starttime time.Time |
| 918 | endStreamArgs bool // are the stream args at EOF? |
| 919 | allowDebug bool // true if the caller is permitted to view debug information. |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 920 | } |
| 921 | |
Benjamin Prosnitz | fdfbf7b | 2014-10-08 09:47:21 -0700 | [diff] [blame] | 922 | var _ ipc.Stream = (*flowServer)(nil) |
| 923 | |
Todd Wang | 34ed4c6 | 2014-11-26 15:15:52 -0800 | [diff] [blame] | 924 | func newFlowServer(flow stream.Flow, server *server) (*flowServer, error) { |
Cosmos Nicolaou | dcba93d | 2014-07-30 11:09:26 -0700 | [diff] [blame] | 925 | server.Lock() |
| 926 | disp := server.disp |
| 927 | server.Unlock() |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 928 | |
Todd Wang | 34ed4c6 | 2014-11-26 15:15:52 -0800 | [diff] [blame] | 929 | fs := &flowServer{ |
| 930 | T: server.ctx, |
| 931 | server: server, |
| 932 | disp: disp, |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 933 | flow: flow, |
| 934 | discharges: make(map[string]security.Discharge), |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 935 | } |
Todd Wang | f519f8f | 2015-01-21 10:07:41 -0800 | [diff] [blame] | 936 | var err error |
Todd Wang | 3425a90 | 2015-01-21 18:43:59 -0800 | [diff] [blame] | 937 | if fs.dec, err = vom.NewDecoder(flow); err != nil { |
Todd Wang | f519f8f | 2015-01-21 10:07:41 -0800 | [diff] [blame] | 938 | flow.Close() |
| 939 | return nil, err |
| 940 | } |
Todd Wang | 8e17bff | 2015-02-18 11:18:56 -0800 | [diff] [blame] | 941 | if fs.enc, err = vom.NewEncoder(flow); err != nil { |
Todd Wang | f519f8f | 2015-01-21 10:07:41 -0800 | [diff] [blame] | 942 | flow.Close() |
| 943 | return nil, err |
Todd Wang | 34ed4c6 | 2014-11-26 15:15:52 -0800 | [diff] [blame] | 944 | } |
| 945 | return fs, nil |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 946 | } |
| 947 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 948 | func (fs *flowServer) serve() error { |
| 949 | defer fs.flow.Close() |
Matt Rosencrantz | 8689793 | 2014-10-02 09:34:34 -0700 | [diff] [blame] | 950 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 951 | results, err := fs.processRequest() |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 952 | |
Matt Rosencrantz | 5f98d94 | 2015-01-08 13:48:30 -0800 | [diff] [blame] | 953 | vtrace.GetSpan(fs.T).Finish() |
Matt Rosencrantz | 1fa3277 | 2014-10-28 11:31:46 -0700 | [diff] [blame] | 954 | |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 955 | var traceResponse vtrace.Response |
| 956 | if fs.allowDebug { |
Matt Rosencrantz | 2803fe9 | 2015-03-09 15:26:32 -0700 | [diff] [blame] | 957 | traceResponse = vtrace.GetResponse(fs.T) |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 958 | } |
| 959 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 960 | // Respond to the client with the response header and positional results. |
| 961 | response := ipc.Response{ |
| 962 | Error: err, |
| 963 | EndStreamResults: true, |
| 964 | NumPosResults: uint64(len(results)), |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 965 | TraceResponse: traceResponse, |
Suharsh Sivakumar | 720b704 | 2014-12-22 17:33:23 -0800 | [diff] [blame] | 966 | AckBlessings: fs.ackBlessings, |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 967 | } |
| 968 | if err := fs.enc.Encode(response); err != nil { |
Cosmos Nicolaou | 1534b3f | 2014-12-10 15:30:00 -0800 | [diff] [blame] | 969 | if err == io.EOF { |
| 970 | return err |
| 971 | } |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 972 | return fmt.Errorf("ipc: response encoding failed: %v", err) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 973 | } |
| 974 | if response.Error != nil { |
| 975 | return response.Error |
| 976 | } |
| 977 | for ix, res := range results { |
Todd Wang | f519f8f | 2015-01-21 10:07:41 -0800 | [diff] [blame] | 978 | if err := fs.enc.Encode(res); err != nil { |
Cosmos Nicolaou | 1534b3f | 2014-12-10 15:30:00 -0800 | [diff] [blame] | 979 | if err == io.EOF { |
| 980 | return err |
| 981 | } |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 982 | return fmt.Errorf("ipc: result #%d [%T=%v] encoding failed: %v", ix, res, res, err) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 983 | } |
| 984 | } |
| 985 | // TODO(ashankar): Should unread data from the flow be drained? |
| 986 | // |
| 987 | // Reason to do so: |
Matt Rosencrantz | dbc1be2 | 2015-02-28 15:15:49 -0800 | [diff] [blame] | 988 | // The common stream.Flow implementation (veyron/profiles/internal/ipc/stream/vc/reader.go) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 989 | // uses iobuf.Slices backed by an iobuf.Pool. If the stream is not drained, these |
| 990 | // slices will not be returned to the pool leading to possibly increased memory usage. |
| 991 | // |
| 992 | // Reason to not do so: |
| 993 | // Draining here will conflict with any Reads on the flow in a separate goroutine |
| 994 | // (for example, see TestStreamReadTerminatedByServer in full_test.go). |
| 995 | // |
| 996 | // For now, go with the reason to not do so as having unread data in the stream |
| 997 | // should be a rare case. |
| 998 | return nil |
| 999 | } |
| 1000 | |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1001 | func (fs *flowServer) readIPCRequest() (*ipc.Request, error) { |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1002 | // Set a default timeout before reading from the flow. Without this timeout, |
| 1003 | // a client that sends no request or a partial request will retain the flow |
| 1004 | // indefinitely (and lock up server resources). |
Matt Rosencrantz | 8689793 | 2014-10-02 09:34:34 -0700 | [diff] [blame] | 1005 | initTimer := newTimer(defaultCallTimeout) |
| 1006 | defer initTimer.Stop() |
| 1007 | fs.flow.SetDeadline(initTimer.C) |
| 1008 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1009 | // Decode the initial request. |
| 1010 | var req ipc.Request |
| 1011 | if err := fs.dec.Decode(&req); err != nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 1012 | return nil, verror.New(verror.ErrBadProtocol, fs.T, newErrBadRequest(fs.T, err)) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1013 | } |
Matt Rosencrantz | 8689793 | 2014-10-02 09:34:34 -0700 | [diff] [blame] | 1014 | return &req, nil |
| 1015 | } |
| 1016 | |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1017 | func (fs *flowServer) processRequest() ([]interface{}, error) { |
Asim Shankar | 0cad083 | 2014-11-04 01:27:38 -0800 | [diff] [blame] | 1018 | fs.starttime = time.Now() |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1019 | req, err := fs.readIPCRequest() |
| 1020 | if err != nil { |
Matt Rosencrantz | 1fa3277 | 2014-10-28 11:31:46 -0700 | [diff] [blame] | 1021 | // We don't know what the ipc call was supposed to be, but we'll create |
| 1022 | // a placeholder span so we can capture annotations. |
Matt Rosencrantz | 5f98d94 | 2015-01-08 13:48:30 -0800 | [diff] [blame] | 1023 | fs.T, _ = vtrace.SetNewSpan(fs.T, fmt.Sprintf("\"%s\".UNKNOWN", fs.Name())) |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1024 | return nil, err |
Matt Rosencrantz | 8689793 | 2014-10-02 09:34:34 -0700 | [diff] [blame] | 1025 | } |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1026 | fs.method = req.Method |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1027 | fs.suffix = strings.TrimLeft(req.Suffix, "/") |
Matt Rosencrantz | 8689793 | 2014-10-02 09:34:34 -0700 | [diff] [blame] | 1028 | |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 1029 | // TODO(mattr): Currently this allows users to trigger trace collection |
| 1030 | // on the server even if they will not be allowed to collect the |
Matt Rosencrantz | 3197d6c | 2014-11-06 09:53:22 -0800 | [diff] [blame] | 1031 | // results later. This might be considered a DOS vector. |
| 1032 | spanName := fmt.Sprintf("\"%s\".%s", fs.Name(), fs.Method()) |
Matt Rosencrantz | 18da037 | 2015-02-12 16:04:56 -0800 | [diff] [blame] | 1033 | fs.T, _ = vtrace.SetContinuedTrace(fs.T, spanName, req.TraceRequest) |
Matt Rosencrantz | 137b8d2 | 2014-08-18 09:56:15 -0700 | [diff] [blame] | 1034 | |
Matt Rosencrantz | 137b8d2 | 2014-08-18 09:56:15 -0700 | [diff] [blame] | 1035 | var cancel context.CancelFunc |
Todd Wang | f6a0688 | 2015-02-27 17:38:01 -0800 | [diff] [blame] | 1036 | if !req.Deadline.IsZero() { |
| 1037 | fs.T, cancel = context.WithDeadline(fs.T, req.Deadline.Time) |
Matt Rosencrantz | 137b8d2 | 2014-08-18 09:56:15 -0700 | [diff] [blame] | 1038 | } else { |
Matt Rosencrantz | 89445a4 | 2015-01-05 13:32:37 -0800 | [diff] [blame] | 1039 | fs.T, cancel = context.WithCancel(fs.T) |
Matt Rosencrantz | 137b8d2 | 2014-08-18 09:56:15 -0700 | [diff] [blame] | 1040 | } |
Matt Rosencrantz | 8689793 | 2014-10-02 09:34:34 -0700 | [diff] [blame] | 1041 | fs.flow.SetDeadline(fs.Done()) |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1042 | go fs.cancelContextOnClose(cancel) |
Matt Rosencrantz | 137b8d2 | 2014-08-18 09:56:15 -0700 | [diff] [blame] | 1043 | |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1044 | // Initialize security: blessings, discharges, etc. |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1045 | if err := fs.initSecurity(req); err != nil { |
| 1046 | return nil, err |
Andres Erbsen | b7f95f3 | 2014-07-07 12:07:56 -0700 | [diff] [blame] | 1047 | } |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1048 | // Lookup the invoker. |
Todd Wang | ebb3b01 | 2015-02-09 21:59:05 -0800 | [diff] [blame] | 1049 | invoker, auth, err := fs.lookup(fs.suffix, &fs.method) |
| 1050 | if err != nil { |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1051 | return nil, err |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1052 | } |
| 1053 | // Prepare invoker and decode args. |
| 1054 | numArgs := int(req.NumPosArgs) |
Robin Thellend | b16d716 | 2014-11-07 13:47:26 -0800 | [diff] [blame] | 1055 | argptrs, tags, err := invoker.Prepare(fs.method, numArgs) |
Asim Shankar | 0cad083 | 2014-11-04 01:27:38 -0800 | [diff] [blame] | 1056 | fs.tags = tags |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1057 | if err != nil { |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1058 | return nil, err |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1059 | } |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1060 | if called, want := req.NumPosArgs, uint64(len(argptrs)); called != want { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 1061 | return nil, verror.New(verror.ErrBadProtocol, fs.T, newErrBadNumInputArgs(fs.T, fs.suffix, fs.method, called, want)) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1062 | } |
| 1063 | for ix, argptr := range argptrs { |
| 1064 | if err := fs.dec.Decode(argptr); err != nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 1065 | return nil, verror.New(verror.ErrBadProtocol, fs.T, newErrBadInputArg(fs.T, fs.suffix, fs.method, uint64(ix), err)) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1066 | } |
| 1067 | } |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1068 | // Check application's authorization policy. |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1069 | if err := authorize(fs, auth); err != nil { |
| 1070 | return nil, err |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1071 | } |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1072 | // Check if the caller is permitted to view debug information. |
Asim Shankar | 6888519 | 2014-11-26 12:48:35 -0800 | [diff] [blame] | 1073 | // TODO(mattr): Is access.Debug the right thing to check? |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1074 | fs.allowDebug = authorize(debugContext{fs}, auth) == nil |
| 1075 | // Invoke the method. |
Robin Thellend | b16d716 | 2014-11-07 13:47:26 -0800 | [diff] [blame] | 1076 | results, err := invoker.Invoke(fs.method, fs, argptrs) |
| 1077 | fs.server.stats.record(fs.method, time.Since(fs.starttime)) |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1078 | return results, err |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1079 | } |
| 1080 | |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1081 | func (fs *flowServer) cancelContextOnClose(cancel context.CancelFunc) { |
| 1082 | // Ensure that the context gets cancelled if the flow is closed |
| 1083 | // due to a network error, or client cancellation. |
| 1084 | select { |
| 1085 | case <-fs.flow.Closed(): |
| 1086 | // Here we remove the contexts channel as a deadline to the flow. |
| 1087 | // We do this to ensure clients get a consistent error when they read/write |
| 1088 | // after the flow is closed. Since the flow is already closed, it doesn't |
| 1089 | // matter that the context is also cancelled. |
| 1090 | fs.flow.SetDeadline(nil) |
| 1091 | cancel() |
| 1092 | case <-fs.Done(): |
Robin Thellend | c26c32e | 2014-10-06 17:44:04 -0700 | [diff] [blame] | 1093 | } |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1094 | } |
| 1095 | |
| 1096 | // lookup returns the invoker and authorizer responsible for serving the given |
| 1097 | // name and method. The suffix is stripped of any leading slashes. If it begins |
| 1098 | // with ipc.DebugKeyword, we use the internal debug dispatcher to look up the |
| 1099 | // invoker. Otherwise, and we use the server's dispatcher. The suffix and method |
| 1100 | // value may be modified to match the actual suffix and method to use. |
Todd Wang | ebb3b01 | 2015-02-09 21:59:05 -0800 | [diff] [blame] | 1101 | func (fs *flowServer) lookup(suffix string, method *string) (ipc.Invoker, security.Authorizer, error) { |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1102 | if naming.IsReserved(*method) { |
| 1103 | // All reserved methods are trapped and handled here, by removing the |
| 1104 | // reserved prefix and invoking them on reservedMethods. E.g. "__Glob" |
| 1105 | // invokes reservedMethods.Glob. |
| 1106 | *method = naming.StripReserved(*method) |
| 1107 | return reservedInvoker(fs.disp, fs.server.dispReserved), &acceptAllAuthorizer{}, nil |
| 1108 | } |
| 1109 | disp := fs.disp |
| 1110 | if naming.IsReserved(suffix) { |
| 1111 | disp = fs.server.dispReserved |
Robin Thellend | d24f084 | 2014-09-23 10:27:29 -0700 | [diff] [blame] | 1112 | } |
| 1113 | if disp != nil { |
Robin Thellend | a02fe8f | 2014-11-19 09:58:29 -0800 | [diff] [blame] | 1114 | obj, auth, err := disp.Lookup(suffix) |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1115 | switch { |
| 1116 | case err != nil: |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1117 | return nil, nil, err |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1118 | case obj != nil: |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 1119 | invoker, err := objectToInvoker(obj) |
| 1120 | if err != nil { |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 1121 | return nil, nil, verror.New(verror.ErrInternal, fs.T, "invalid received object", err) |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 1122 | } |
| 1123 | return invoker, auth, nil |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1124 | } |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1125 | } |
Todd Wang | ff73e1f | 2015-02-10 21:45:52 -0800 | [diff] [blame] | 1126 | return nil, nil, ipc.NewErrUnknownSuffix(nil, suffix) |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1127 | } |
| 1128 | |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 1129 | func objectToInvoker(obj interface{}) (ipc.Invoker, error) { |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1130 | if obj == nil { |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 1131 | return nil, errors.New("nil object") |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1132 | } |
| 1133 | if invoker, ok := obj.(ipc.Invoker); ok { |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 1134 | return invoker, nil |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1135 | } |
Bogdan Caprita | 9592d9f | 2015-01-08 22:15:16 -0800 | [diff] [blame] | 1136 | return ipc.ReflectInvoker(obj) |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1137 | } |
| 1138 | |
Todd Wang | 9548d85 | 2015-02-10 16:15:59 -0800 | [diff] [blame] | 1139 | func (fs *flowServer) initSecurity(req *ipc.Request) error { |
Ankur | b905dae | 2015-03-04 12:38:20 -0800 | [diff] [blame] | 1140 | // LocalPrincipal is nil which means we are operating under |
| 1141 | // VCSecurityNone. |
| 1142 | if fs.flow.LocalPrincipal() == nil { |
| 1143 | return nil |
| 1144 | } |
| 1145 | |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1146 | // If additional credentials are provided, make them available in the context |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1147 | // Detect unusable blessings now, rather then discovering they are unusable on |
| 1148 | // first use. |
| 1149 | // |
| 1150 | // TODO(ashankar,ataly): Potential confused deputy attack: The client provides |
| 1151 | // the server's identity as the blessing. Figure out what we want to do about |
| 1152 | // this - should servers be able to assume that a blessing is something that |
| 1153 | // does not have the authorizations that the server's own identity has? |
Ankur | b905dae | 2015-03-04 12:38:20 -0800 | [diff] [blame] | 1154 | if got, want := req.GrantedBlessings.PublicKey(), fs.flow.LocalPrincipal().PublicKey(); got != nil && !reflect.DeepEqual(got, want) { |
| 1155 | return verror.New(verror.ErrNoAccess, fs.T, fmt.Sprintf("blessing granted not bound to this server(%v vs %v)", got, want)) |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1156 | } |
Asim Shankar | b07ec69 | 2015-02-27 23:40:44 -0800 | [diff] [blame] | 1157 | fs.grantedBlessings = req.GrantedBlessings |
Ankur | b905dae | 2015-03-04 12:38:20 -0800 | [diff] [blame] | 1158 | |
Asim Shankar | b07ec69 | 2015-02-27 23:40:44 -0800 | [diff] [blame] | 1159 | var err error |
| 1160 | if fs.clientBlessings, err = serverDecodeBlessings(fs.flow.VCDataCache(), req.Blessings, fs.server.stats); err != nil { |
Suharsh Sivakumar | 720b704 | 2014-12-22 17:33:23 -0800 | [diff] [blame] | 1161 | // When the server can't access the blessings cache, the client is not following |
| 1162 | // protocol, so the server closes the VCs corresponding to the client endpoint. |
| 1163 | // TODO(suharshs,toddw): Figure out a way to only shutdown the current VC, instead |
| 1164 | // of all VCs connected to the RemoteEndpoint. |
| 1165 | fs.server.streamMgr.ShutdownEndpoint(fs.RemoteEndpoint()) |
Jiri Simsa | 074bf36 | 2015-02-17 09:29:45 -0800 | [diff] [blame] | 1166 | return verror.New(verror.ErrBadProtocol, fs.T, newErrBadBlessingsCache(fs.T, err)) |
Suharsh Sivakumar | 720b704 | 2014-12-22 17:33:23 -0800 | [diff] [blame] | 1167 | } |
Ankur | b905dae | 2015-03-04 12:38:20 -0800 | [diff] [blame] | 1168 | // Verify that the blessings sent by the client in the request have the same public |
| 1169 | // key as those sent by the client during VC establishment. |
| 1170 | if got, want := fs.clientBlessings.PublicKey(), fs.flow.RemoteBlessings().PublicKey(); got != nil && !reflect.DeepEqual(got, want) { |
| 1171 | return verror.New(verror.ErrNoAccess, fs.T, fmt.Sprintf("blessings sent with the request are bound to a different public key (%v) from the blessing used during VC establishment (%v)", got, want)) |
| 1172 | } |
Asim Shankar | 2bf7b1e | 2015-02-27 00:45:12 -0800 | [diff] [blame] | 1173 | fs.ackBlessings = true |
Suharsh Sivakumar | 720b704 | 2014-12-22 17:33:23 -0800 | [diff] [blame] | 1174 | |
Asim Shankar | 3ad0b8a | 2015-02-25 00:37:21 -0800 | [diff] [blame] | 1175 | for _, d := range req.Discharges { |
Asim Shankar | 0864282 | 2015-03-02 21:21:09 -0800 | [diff] [blame] | 1176 | fs.discharges[d.ID()] = d |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1177 | } |
| 1178 | return nil |
Robin Thellend | c26c32e | 2014-10-06 17:44:04 -0700 | [diff] [blame] | 1179 | } |
| 1180 | |
| 1181 | type acceptAllAuthorizer struct{} |
| 1182 | |
Matt Rosencrantz | 5c7ed21 | 2015-02-27 22:42:35 -0800 | [diff] [blame] | 1183 | func (acceptAllAuthorizer) Authorize(security.Call) error { |
Robin Thellend | c26c32e | 2014-10-06 17:44:04 -0700 | [diff] [blame] | 1184 | return nil |
| 1185 | } |
| 1186 | |
Matt Rosencrantz | 9dce9b2 | 2015-03-02 10:48:37 -0800 | [diff] [blame] | 1187 | func authorize(call ipc.ServerCall, auth security.Authorizer) error { |
| 1188 | if call.LocalPrincipal() == nil { |
Todd Wang | 5739dda | 2014-11-16 22:44:02 -0800 | [diff] [blame] | 1189 | // LocalPrincipal is nil means that the server wanted to avoid |
| 1190 | // authentication, and thus wanted to skip authorization as well. |
| 1191 | return nil |
| 1192 | } |
Asim Shankar | 8f05c22 | 2014-10-06 22:08:19 -0700 | [diff] [blame] | 1193 | if auth == nil { |
Asim Shankar | 0c73fbf | 2014-10-31 15:34:02 -0700 | [diff] [blame] | 1194 | auth = defaultAuthorizer{} |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1195 | } |
Matt Rosencrantz | 9dce9b2 | 2015-03-02 10:48:37 -0800 | [diff] [blame] | 1196 | if err := auth.Authorize(call); err != nil { |
Asim Shankar | a5457f0 | 2014-10-24 23:23:07 -0700 | [diff] [blame] | 1197 | // TODO(ataly, ashankar): For privacy reasons, should we hide the authorizer error? |
Matt Rosencrantz | 9dce9b2 | 2015-03-02 10:48:37 -0800 | [diff] [blame] | 1198 | return verror.New(verror.ErrNoAccess, call.Context(), newErrBadAuth(call.Context(), call.Suffix(), call.Method(), err)) |
Asim Shankar | a5457f0 | 2014-10-24 23:23:07 -0700 | [diff] [blame] | 1199 | } |
| 1200 | return nil |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1201 | } |
| 1202 | |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 1203 | // debugContext is a context which wraps another context but always returns |
Asim Shankar | 6888519 | 2014-11-26 12:48:35 -0800 | [diff] [blame] | 1204 | // the debug tag. |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 1205 | type debugContext struct { |
Matt Rosencrantz | 5c7ed21 | 2015-02-27 22:42:35 -0800 | [diff] [blame] | 1206 | ipc.ServerCall |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 1207 | } |
| 1208 | |
Todd Wang | b31da59 | 2015-02-20 12:50:39 -0800 | [diff] [blame] | 1209 | func (debugContext) MethodTags() []*vdl.Value { |
| 1210 | return []*vdl.Value{vdl.ValueOf(access.Debug)} |
Asim Shankar | 6888519 | 2014-11-26 12:48:35 -0800 | [diff] [blame] | 1211 | } |
Matt Rosencrantz | 9fe6082 | 2014-09-12 10:09:53 -0700 | [diff] [blame] | 1212 | |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1213 | // Send implements the ipc.Stream method. |
| 1214 | func (fs *flowServer) Send(item interface{}) error { |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1215 | defer vlog.LogCall()() |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1216 | // The empty response header indicates what follows is a streaming result. |
| 1217 | if err := fs.enc.Encode(ipc.Response{}); err != nil { |
| 1218 | return err |
| 1219 | } |
| 1220 | return fs.enc.Encode(item) |
| 1221 | } |
| 1222 | |
| 1223 | // Recv implements the ipc.Stream method. |
| 1224 | func (fs *flowServer) Recv(itemptr interface{}) error { |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1225 | defer vlog.LogCall()() |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1226 | var req ipc.Request |
| 1227 | if err := fs.dec.Decode(&req); err != nil { |
| 1228 | return err |
| 1229 | } |
| 1230 | if req.EndStreamArgs { |
| 1231 | fs.endStreamArgs = true |
| 1232 | return io.EOF |
| 1233 | } |
| 1234 | return fs.dec.Decode(itemptr) |
| 1235 | } |
| 1236 | |
Matt Rosencrantz | 5c7ed21 | 2015-02-27 22:42:35 -0800 | [diff] [blame] | 1237 | // Implementations of ipc.ServerCall methods. |
Jiri Simsa | 5293dcb | 2014-05-10 09:56:38 -0700 | [diff] [blame] | 1238 | |
Ankur | edd74ee | 2015-03-04 16:38:45 -0800 | [diff] [blame] | 1239 | func (fs *flowServer) LocalDischarges() map[string]security.Discharge { |
| 1240 | //nologcall |
| 1241 | return fs.flow.LocalDischarges() |
| 1242 | } |
Asim Shankar | 2519cc1 | 2014-11-10 21:16:53 -0800 | [diff] [blame] | 1243 | func (fs *flowServer) RemoteDischarges() map[string]security.Discharge { |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1244 | //nologcall |
| 1245 | return fs.discharges |
| 1246 | } |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1247 | func (fs *flowServer) Server() ipc.Server { |
| 1248 | //nologcall |
| 1249 | return fs.server |
| 1250 | } |
Asim Shankar | 0cad083 | 2014-11-04 01:27:38 -0800 | [diff] [blame] | 1251 | func (fs *flowServer) Timestamp() time.Time { |
| 1252 | //nologcall |
| 1253 | return fs.starttime |
| 1254 | } |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1255 | func (fs *flowServer) Method() string { |
| 1256 | //nologcall |
| 1257 | return fs.method |
| 1258 | } |
Todd Wang | b31da59 | 2015-02-20 12:50:39 -0800 | [diff] [blame] | 1259 | func (fs *flowServer) MethodTags() []*vdl.Value { |
Asim Shankar | 0cad083 | 2014-11-04 01:27:38 -0800 | [diff] [blame] | 1260 | //nologcall |
| 1261 | return fs.tags |
| 1262 | } |
Matt Rosencrantz | 4f8ac60 | 2014-12-29 14:42:48 -0800 | [diff] [blame] | 1263 | func (fs *flowServer) Context() *context.T { |
Matt Rosencrantz | 04d197c | 2014-12-12 08:39:25 -0800 | [diff] [blame] | 1264 | return fs.T |
| 1265 | } |
Cosmos Nicolaou | fdc838b | 2014-06-30 21:44:27 -0700 | [diff] [blame] | 1266 | |
Benjamin Prosnitz | 9284a00 | 2015-02-23 14:57:25 -0800 | [diff] [blame] | 1267 | func (fs *flowServer) VanadiumContext() *context.T { |
| 1268 | return fs.T |
| 1269 | } |
| 1270 | |
Matt Rosencrantz | 5c7ed21 | 2015-02-27 22:42:35 -0800 | [diff] [blame] | 1271 | // TODO(cnicolaou): remove Name from ipc.ServerCall and all of |
Cosmos Nicolaou | fdc838b | 2014-06-30 21:44:27 -0700 | [diff] [blame] | 1272 | // its implementations |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1273 | func (fs *flowServer) Name() string { |
| 1274 | //nologcall |
| 1275 | return fs.suffix |
| 1276 | } |
| 1277 | func (fs *flowServer) Suffix() string { |
| 1278 | //nologcall |
| 1279 | return fs.suffix |
| 1280 | } |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1281 | func (fs *flowServer) LocalPrincipal() security.Principal { |
| 1282 | //nologcall |
Asim Shankar | 8f05c22 | 2014-10-06 22:08:19 -0700 | [diff] [blame] | 1283 | return fs.flow.LocalPrincipal() |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1284 | } |
| 1285 | func (fs *flowServer) LocalBlessings() security.Blessings { |
| 1286 | //nologcall |
Asim Shankar | 8f05c22 | 2014-10-06 22:08:19 -0700 | [diff] [blame] | 1287 | return fs.flow.LocalBlessings() |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1288 | } |
| 1289 | func (fs *flowServer) RemoteBlessings() security.Blessings { |
| 1290 | //nologcall |
Asim Shankar | 2bf7b1e | 2015-02-27 00:45:12 -0800 | [diff] [blame] | 1291 | if !fs.clientBlessings.IsZero() { |
Suharsh Sivakumar | 720b704 | 2014-12-22 17:33:23 -0800 | [diff] [blame] | 1292 | return fs.clientBlessings |
| 1293 | } |
Asim Shankar | 8f05c22 | 2014-10-06 22:08:19 -0700 | [diff] [blame] | 1294 | return fs.flow.RemoteBlessings() |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1295 | } |
Suharsh Sivakumar | 380bf34 | 2015-02-27 15:38:27 -0800 | [diff] [blame] | 1296 | func (fs *flowServer) GrantedBlessings() security.Blessings { |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1297 | //nologcall |
Suharsh Sivakumar | 380bf34 | 2015-02-27 15:38:27 -0800 | [diff] [blame] | 1298 | return fs.grantedBlessings |
Mehrdad Afshari | cd9852b | 2014-09-26 11:07:35 -0700 | [diff] [blame] | 1299 | } |
| 1300 | func (fs *flowServer) LocalEndpoint() naming.Endpoint { |
| 1301 | //nologcall |
| 1302 | return fs.flow.LocalEndpoint() |
| 1303 | } |
| 1304 | func (fs *flowServer) RemoteEndpoint() naming.Endpoint { |
| 1305 | //nologcall |
| 1306 | return fs.flow.RemoteEndpoint() |
| 1307 | } |