/* * ***** BEGIN LICENSE BLOCK ***** Copyright (C) 2009-2019 Olof Hagsand Copyright (C) 2020 Olof Hagsand and Rubicon Communications, LLC This file is part of CLIXON. Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. Alternatively, the contents of this file may be used under the terms of the GNU General Public License Version 3 or later (the "GPL"), in which case the provisions of the GPL are applicable instead of those above. If you wish to allow use of your version of this file only under the terms of the GPL, and not to allow others to use your version of this file under the terms of Apache License version 2, indicate your decision by deleting the provisions above and replace them with the notice and other provisions required by the GPL. If you do not delete the provisions above, a recipient may use your version of this file under the terms of any one of the Apache License version 2 or the GPL. ***** END LICENSE BLOCK ***** */ /* * This program should be run as user www-data * * See draft-ietf-netconf-restconf-13.txt [draft] * sudo apt-get install libfcgi-dev * gcc -o fastcgi fastcgi.c -lfcgi * sudo su -c "/www-data/clixon_restconf -D 1 -f /usr/local/etc/example.xml " -s /bin/sh www-data * This is the interface: * api/data/profile=/metric= PUT data:enable= * api/test */ #ifdef HAVE_CONFIG_H #include "clixon_config.h" /* generated by config & autoconf */ #endif #include #include #include #include #include #include #include #include #include #include #include #include #include #include /* chmod */ /* cligen */ #include /* clicon */ #include #include /* Need to be after clixon_xml.h due to attribute format */ /* restconf */ #include "restconf_lib.h" #include "restconf_methods.h" #include "restconf_methods_get.h" #include "restconf_methods_post.h" #include "restconf_stream.h" /* Command line options to be passed to getopt(3) */ #define RESTCONF_OPTS "hD:f:l:p:d:y:a:u:o:" /* RESTCONF enables deployments to specify where the RESTCONF API is located. The client discovers this by getting the "/.well-known/host-meta" resource */ #define RESTCONF_WELL_KNOWN "/.well-known/host-meta" /*! Generic REST method, GET, PUT, DELETE, etc * @param[in] h CLIXON handle * @param[in] r Fastcgi request handle * @param[in] api_path According to restconf (Sec 3.5.1.1 in [draft]) * @param[in] pcvec Vector of path ie DOCUMENT_URI element * @param[in] pi Offset, where to start pcvec * @param[in] qvec Vector of query string (QUERY_STRING) * @param[in] dvec Stream input daat * @param[in] pretty Set to 1 for pretty-printed xml/json output * @param[in] media_in Input media * @param[in] media_out Output media */ static int api_data(clicon_handle h, FCGX_Request *r, char *api_path, cvec *pcvec, int pi, cvec *qvec, char *data, int pretty, restconf_media media_out) { int retval = -1; char *request_method; clicon_debug(1, "%s", __FUNCTION__); request_method = FCGX_GetParam("REQUEST_METHOD", r->envp); clicon_debug(1, "%s method:%s", __FUNCTION__, request_method); if (strcmp(request_method, "OPTIONS")==0) retval = api_data_options(h, r); else if (strcmp(request_method, "HEAD")==0) retval = api_data_head(h, r, api_path, pcvec, pi, qvec, pretty, media_out); else if (strcmp(request_method, "GET")==0) retval = api_data_get(h, r, api_path, pcvec, pi, qvec, pretty, media_out); else if (strcmp(request_method, "POST")==0) retval = api_data_post(h, r, api_path, pi, qvec, data, pretty, media_out); else if (strcmp(request_method, "PUT")==0) retval = api_data_put(h, r, api_path, pcvec, pi, qvec, data, pretty, media_out); else if (strcmp(request_method, "PATCH")==0) retval = api_data_patch(h, r, api_path, pcvec, pi, qvec, data, pretty, media_out); else if (strcmp(request_method, "DELETE")==0) retval = api_data_delete(h, r, api_path, pi, pretty, media_out); else retval = restconf_notfound(r); clicon_debug(1, "%s retval:%d", __FUNCTION__, retval); return retval; } /*! Operations REST method, POST * @param[in] h CLIXON handle * @param[in] r Fastcgi request handle * @param[in] path According to restconf (Sec 3.5.1.1 in [draft]) * @param[in] pcvec Vector of path ie DOCUMENT_URI element * @param[in] pi Offset, where to start pcvec * @param[in] qvec Vector of query string (QUERY_STRING) * @param[in] data Stream input data * @param[in] media_out Output media */ static int api_operations(clicon_handle h, FCGX_Request *r, char *path, cvec *pcvec, int pi, cvec *qvec, char *data, int pretty, restconf_media media_out) { int retval = -1; char *request_method; clicon_debug(1, "%s", __FUNCTION__); request_method = FCGX_GetParam("REQUEST_METHOD", r->envp); clicon_debug(1, "%s method:%s", __FUNCTION__, request_method); if (strcmp(request_method, "GET")==0) retval = api_operations_get(h, r, path, pi, qvec, data, pretty, media_out); else if (strcmp(request_method, "POST")==0) retval = api_operations_post(h, r, path, pi, qvec, data, pretty, media_out); else retval = restconf_notfound(r); return retval; } /*! Determine the root of the RESTCONF API * @param[in] h Clicon handle * @param[in] r Fastcgi request handle * @note Hardcoded to "/restconf" * Return see RFC8040 3.1 and RFC7320 * In line with the best practices defined by [RFC7320], RESTCONF * enables deployments to specify where the RESTCONF API is located. */ static int api_well_known(clicon_handle h, FCGX_Request *r) { clicon_debug(1, "%s", __FUNCTION__); FCGX_FPrintF(r->out, "Cache-Control: no-cache\r\n"); FCGX_FPrintF(r->out, "Content-Type: application/xrd+xml\r\n"); FCGX_FPrintF(r->out, "\r\n"); FCGX_SetExitStatus(200, r->out); /* OK */ FCGX_FPrintF(r->out, "\n"); FCGX_FPrintF(r->out, " \n"); FCGX_FPrintF(r->out, "\r\n"); return 0; } /*! Retrieve the Top-Level API Resource * @param[in] h Clicon handle * @param[in] r Fastcgi request handle * @note Only returns null for operations and data,... * See RFC8040 3.3 */ static int api_root(clicon_handle h, FCGX_Request *r, int pretty, restconf_media media_out) { int retval = -1; cxobj *xt = NULL; cbuf *cb = NULL; yang_stmt *yspec; clicon_debug(1, "%s", __FUNCTION__); if ((yspec = clicon_dbspec_yang(h)) == NULL){ clicon_err(OE_FATAL, 0, "No DB_SPEC"); goto done; } FCGX_SetExitStatus(200, r->out); /* OK */ FCGX_FPrintF(r->out, "Status: 200 OK\r\n"); FCGX_FPrintF(r->out, "Cache-Control: no-cache\r\n"); FCGX_FPrintF(r->out, "Content-Type: %s\r\n", restconf_media_int2str(media_out)); FCGX_FPrintF(r->out, "\r\n"); if (clixon_xml_parse_string("" "2016-06-21", YB_MODULE, yspec, &xt, NULL) < 0) goto done; if ((cb = cbuf_new()) == NULL){ clicon_err(OE_XML, errno, "cbuf_new"); goto done; } if (xml_rootchild(xt, 0, &xt) < 0) goto done; switch (media_out){ case YANG_DATA_XML: if (clicon_xml2cbuf(cb, xt, 0, pretty, -1) < 0) goto done; break; case YANG_DATA_JSON: if (xml2json_cbuf(cb, xt, pretty) < 0) goto done; break; default: break; } FCGX_FPrintF(r->out, "%s", cb?cbuf_get(cb):""); FCGX_FPrintF(r->out, "\r\n\r\n"); retval = 0; done: if (cb) cbuf_free(cb); if (xt) xml_free(xt); return retval; } /*! * See https://tools.ietf.org/html/rfc7895 */ static int api_yang_library_version(clicon_handle h, FCGX_Request *r, int pretty, restconf_media media_out) { int retval = -1; cxobj *xt = NULL; cbuf *cb = NULL; char *ietf_yang_library_revision = "2016-06-21"; /* XXX */ clicon_debug(1, "%s", __FUNCTION__); FCGX_SetExitStatus(200, r->out); /* OK */ FCGX_FPrintF(r->out, "Cache-Control: no-cache\r\n"); FCGX_FPrintF(r->out, "Content-Type: %s\r\n", restconf_media_int2str(media_out)); FCGX_FPrintF(r->out, "\r\n"); if (clixon_xml_parse_va(YB_NONE, NULL, &xt, NULL, "%s", ietf_yang_library_revision) < 0) goto done; if (xml_rootchild(xt, 0, &xt) < 0) goto done; if ((cb = cbuf_new()) == NULL){ goto done; } switch (media_out){ case YANG_DATA_XML: if (clicon_xml2cbuf(cb, xt, 0, pretty, -1) < 0) goto done; break; case YANG_DATA_JSON: if (xml2json_cbuf(cb, xt, pretty) < 0) goto done; break; default: break; } clicon_debug(1, "%s cb%s", __FUNCTION__, cbuf_get(cb)); FCGX_FPrintF(r->out, "%s\n", cb?cbuf_get(cb):""); FCGX_FPrintF(r->out, "\n\n"); retval = 0; done: if (cb) cbuf_free(cb); if (xt) xml_free(xt); return retval; } /*! Process a FastCGI request * @param[in] r Fastcgi request handle */ static int api_restconf(clicon_handle h, FCGX_Request *r) { int retval = -1; char *path; char *query; char *method; char **pvec = NULL; int pn; cvec *qvec = NULL; cvec *dvec = NULL; cvec *pcvec = NULL; /* for rest api */ cbuf *cb = NULL; char *data; int authenticated = 0; char *media_str = NULL; restconf_media media_out = YANG_DATA_JSON; int pretty; cbuf *cbret = NULL; cxobj *xret = NULL; cxobj *xerr; clicon_debug(1, "%s", __FUNCTION__); path = restconf_uripath(r); query = FCGX_GetParam("QUERY_STRING", r->envp); pretty = clicon_option_bool(h, "CLICON_RESTCONF_PRETTY"); /* Get media for output (proactive negotiation) RFC7231 by using * Accept:. This is for methods that have output, such as GET, * operation POST, etc * If accept is * default is yang-json */ if ((media_str = FCGX_GetParam("HTTP_ACCEPT", r->envp)) == NULL){ // retval = restconf_unsupported_media(r); // goto done; } else if ((int)(media_out = restconf_media_str2int(media_str)) == -1){ if (strcmp(media_str, "*/*") == 0) /* catch-all */ media_out = YANG_DATA_JSON; else{ retval = restconf_unsupported_media(r); goto done; } } clicon_debug(1, "%s ACCEPT: %s %s", __FUNCTION__, media_str, restconf_media_int2str(media_out)); if ((pvec = clicon_strsep(path, "/", &pn)) == NULL) goto done; /* Sanity check of path. Should be /restconf/ */ if (pn < 2){ restconf_notfound(r); goto ok; } if (strlen(pvec[0]) != 0){ retval = restconf_notfound(r); goto done; } if (strcmp(pvec[1], RESTCONF_API)){ retval = restconf_notfound(r); goto done; } restconf_test(r, 1); if (pn == 2){ retval = api_root(h, r, pretty, media_out); goto done; } if ((method = pvec[2]) == NULL){ retval = restconf_notfound(r); goto done; } clicon_debug(1, "%s: method=%s", __FUNCTION__, method); if (str2cvec(query, '&', '=', &qvec) < 0) goto done; if (str2cvec(path, '/', '=', &pcvec) < 0) /* rest url eg /album=ricky/foo */ goto done; /* data */ if ((cb = readdata(r)) == NULL) goto done; data = cbuf_get(cb); clicon_debug(1, "%s DATA=%s", __FUNCTION__, data); if (str2cvec(data, '&', '=', &dvec) < 0) goto done; /* If present, check credentials. See "plugin_credentials" in plugin * See RFC 8040 section 2.5 */ if ((authenticated = clixon_plugin_auth(h, r)) < 0) goto done; clicon_debug(1, "%s auth:%d %s", __FUNCTION__, authenticated, clicon_username_get(h)); /* If set but no user, we set a dummy user */ if (authenticated){ if (clicon_username_get(h) == NULL) clicon_username_set(h, "none"); } else{ if (netconf_access_denied_xml(&xret, "protocol", "The requested URL was unauthorized") < 0) goto done; if ((xerr = xpath_first(xret, NULL, "//rpc-error")) != NULL){ if (api_return_err(h, r, xerr, pretty, media_out, 0) < 0) goto done; goto ok; } goto ok; } clicon_debug(1, "%s auth2:%d %s", __FUNCTION__, authenticated, clicon_username_get(h)); if (strcmp(method, "yang-library-version")==0){ if (api_yang_library_version(h, r, pretty, media_out) < 0) goto done; } else if (strcmp(method, "data") == 0){ /* restconf, skip /api/data */ if (api_data(h, r, path, pcvec, 2, qvec, data, pretty, media_out) < 0) goto done; } else if (strcmp(method, "operations") == 0){ /* rpc */ if (api_operations(h, r, path, pcvec, 2, qvec, data, pretty, media_out) < 0) goto done; } else if (strcmp(method, "test") == 0) restconf_test(r, 0); else restconf_notfound(r); ok: retval = 0; done: clicon_debug(1, "%s retval:%d", __FUNCTION__, retval); if (pvec) free(pvec); if (dvec) cvec_free(dvec); if (qvec) cvec_free(qvec); if (pcvec) cvec_free(pcvec); if (cb) cbuf_free(cb); if (cbret) cbuf_free(cbret); if (xret) xml_free(xret); return retval; } /* Need global variable to for signal handler XXX */ static clicon_handle _CLICON_HANDLE = NULL; /*! Signall terminates process */ static void restconf_sig_term(int arg) { static int i=0; if (i++ == 0) clicon_log(LOG_NOTICE, "%s: %s: pid: %u Signal %d", __PROGRAM__, __FUNCTION__, getpid(), arg); else exit(-1); if (_CLICON_HANDLE){ stream_child_freeall(_CLICON_HANDLE); restconf_terminate(_CLICON_HANDLE); } clicon_exit_set(); /* checked in event_loop() */ exit(-1); } /*! Callback for yang extensions ietf-restconf:yang-data * @see ietf-restconf.yang * @param[in] h Clixon handle * @param[in] yext Yang node of extension * @param[in] ys Yang node of (unknown) statement belonging to extension * @retval 0 OK, all callbacks executed OK * @retval -1 Error in one callback */ static int restconf_main_extension_cb(clicon_handle h, yang_stmt *yext, yang_stmt *ys) { int retval = -1; char *extname; char *modname; yang_stmt *ymod; yang_stmt *yc; yang_stmt *yn = NULL; ymod = ys_module(yext); modname = yang_argument_get(ymod); extname = yang_argument_get(yext); if (strcmp(modname, "ietf-restconf") != 0 || strcmp(extname, "yang-data") != 0) goto ok; clicon_debug(1, "%s Enabled extension:%s:%s", __FUNCTION__, modname, extname); if ((yc = yang_find(ys, 0, NULL)) == NULL) goto ok; if ((yn = ys_dup(yc)) == NULL) goto done; if (yn_insert(yang_parent_get(ys), yn) < 0) goto done; ok: retval = 0; done: return retval; } static void restconf_sig_child(int arg) { int status; int pid; if ((pid = waitpid(-1, &status, 0)) != -1 && WIFEXITED(status)) stream_child_free(_CLICON_HANDLE, pid); } /*! Usage help routine * @param[in] argv0 command line * @param[in] h Clicon handle */ static void usage(clicon_handle h, char *argv0) { fprintf(stderr, "usage:%s [options]\n" "where options are\n" "\t-h \t\t Help\n" "\t-D \t Debug level\n" "\t-f \t Configuration file (mandatory)\n" "\t-l > \t Log on (s)yslog, (f)ile (syslog is default)\n" "\t-p \t Yang directory path (see CLICON_YANG_DIR)\n" "\t-d \t Specify restconf plugin directory dir (default: %s)\n" "\t-y \t Load yang spec file (override yang main module)\n" "\t-a UNIX|IPv4|IPv6 Internal backend socket family\n" "\t-u \t Internal socket domain path or IP addr (see -a)\n" "\t-o \"