BUG-9261: Add basic public key auth to testtool
[netconf.git] / netconf / tools / netconf-testtool / src / main / java / org / opendaylight / netconf / test / tool / NetconfDeviceSimulator.java
1 /*
2  * Copyright (c) 2014 Cisco Systems, Inc. and others.  All rights reserved.
3  *
4  * This program and the accompanying materials are made available under the
5  * terms of the Eclipse Public License v1.0 which accompanies this distribution,
6  * and is available at http://www.eclipse.org/legal/epl-v10.html
7  */
8
9 package org.opendaylight.netconf.test.tool;
10
11 import com.google.common.base.MoreObjects;
12 import com.google.common.base.Optional;
13 import com.google.common.collect.Collections2;
14 import com.google.common.collect.Lists;
15 import com.google.common.collect.Sets;
16 import com.google.common.util.concurrent.CheckedFuture;
17 import com.google.common.util.concurrent.Futures;
18 import com.google.common.util.concurrent.ThreadFactoryBuilder;
19 import io.netty.channel.Channel;
20 import io.netty.channel.ChannelFuture;
21 import io.netty.channel.local.LocalAddress;
22 import io.netty.channel.nio.NioEventLoopGroup;
23 import io.netty.util.HashedWheelTimer;
24 import java.io.Closeable;
25 import java.io.IOException;
26 import java.io.InputStream;
27 import java.net.BindException;
28 import java.net.Inet4Address;
29 import java.net.InetSocketAddress;
30 import java.net.UnknownHostException;
31 import java.nio.file.Files;
32 import java.nio.file.Path;
33 import java.util.List;
34 import java.util.Set;
35 import java.util.concurrent.ExecutionException;
36 import java.util.concurrent.ExecutorService;
37 import java.util.concurrent.Executors;
38 import java.util.concurrent.ScheduledExecutorService;
39 import org.apache.sshd.common.util.ThreadUtils;
40 import org.apache.sshd.server.keyprovider.PEMGeneratorHostKeyProvider;
41 import org.opendaylight.controller.config.util.capability.BasicCapability;
42 import org.opendaylight.controller.config.util.capability.Capability;
43 import org.opendaylight.controller.config.util.capability.YangModuleCapability;
44 import org.opendaylight.netconf.api.monitoring.NetconfMonitoringService;
45 import org.opendaylight.netconf.impl.NetconfServerDispatcherImpl;
46 import org.opendaylight.netconf.impl.NetconfServerSessionNegotiatorFactory;
47 import org.opendaylight.netconf.impl.SessionIdProvider;
48 import org.opendaylight.netconf.impl.osgi.AggregatedNetconfOperationServiceFactory;
49 import org.opendaylight.netconf.mapping.api.NetconfOperationServiceFactory;
50 import org.opendaylight.netconf.monitoring.osgi.NetconfMonitoringActivator;
51 import org.opendaylight.netconf.monitoring.osgi.NetconfMonitoringOperationService;
52 import org.opendaylight.netconf.ssh.SshProxyServer;
53 import org.opendaylight.netconf.ssh.SshProxyServerConfiguration;
54 import org.opendaylight.netconf.ssh.SshProxyServerConfigurationBuilder;
55 import org.opendaylight.netconf.test.tool.config.Configuration;
56 import org.opendaylight.netconf.test.tool.customrpc.SettableOperationProvider;
57 import org.opendaylight.netconf.test.tool.operations.DefaultOperationsCreator;
58 import org.opendaylight.netconf.test.tool.operations.OperationsProvider;
59 import org.opendaylight.netconf.test.tool.rpchandler.SettableOperationRpcProvider;
60 import org.opendaylight.netconf.test.tool.schemacache.SchemaSourceCache;
61 import org.opendaylight.yangtools.yang.common.SimpleDateFormatUtil;
62 import org.opendaylight.yangtools.yang.model.api.Module;
63 import org.opendaylight.yangtools.yang.model.api.SchemaContext;
64 import org.opendaylight.yangtools.yang.model.repo.api.RevisionSourceIdentifier;
65 import org.opendaylight.yangtools.yang.model.repo.api.SchemaResolutionException;
66 import org.opendaylight.yangtools.yang.model.repo.api.SchemaSourceException;
67 import org.opendaylight.yangtools.yang.model.repo.api.SchemaSourceFilter;
68 import org.opendaylight.yangtools.yang.model.repo.api.SchemaSourceRepresentation;
69 import org.opendaylight.yangtools.yang.model.repo.api.SourceIdentifier;
70 import org.opendaylight.yangtools.yang.model.repo.api.YangTextSchemaSource;
71 import org.opendaylight.yangtools.yang.model.repo.spi.PotentialSchemaSource;
72 import org.opendaylight.yangtools.yang.model.repo.spi.SchemaSourceListener;
73 import org.opendaylight.yangtools.yang.model.repo.spi.SchemaSourceProvider;
74 import org.opendaylight.yangtools.yang.model.repo.util.FilesystemSchemaSourceCache;
75 import org.opendaylight.yangtools.yang.parser.repo.SharedSchemaRepository;
76 import org.opendaylight.yangtools.yang.parser.util.TextToASTTransformer;
77 import org.slf4j.Logger;
78 import org.slf4j.LoggerFactory;
79
80 public class NetconfDeviceSimulator implements Closeable {
81
82     private static final Logger LOG = LoggerFactory.getLogger(NetconfDeviceSimulator.class);
83
84     private final NioEventLoopGroup nettyThreadgroup;
85     private final HashedWheelTimer hashedWheelTimer;
86     private final List<Channel> devicesChannels = Lists.newArrayList();
87     private final List<SshProxyServer> sshWrappers = Lists.newArrayList();
88     private final ScheduledExecutorService minaTimerExecutor;
89     private final ExecutorService nioExecutor;
90     private final Configuration configuration;
91     private SchemaContext schemaContext;
92
93     private boolean sendFakeSchema = false;
94
95     public NetconfDeviceSimulator(Configuration configuration) {
96         this.configuration = configuration;
97         this.nettyThreadgroup = new NioEventLoopGroup();
98         this.hashedWheelTimer = new HashedWheelTimer();
99         this.minaTimerExecutor = Executors.newScheduledThreadPool(configuration.getThreadPoolSize(),
100                 new ThreadFactoryBuilder().setNameFormat("netconf-ssh-server-mina-timers-%d").build());
101         this.nioExecutor = ThreadUtils
102                 .newFixedThreadPool("netconf-ssh-server-nio-group", configuration.getThreadPoolSize());
103     }
104
105     private NetconfServerDispatcherImpl createDispatcher(final Set<Capability> capabilities,
106             final SchemaSourceProvider<YangTextSchemaSource> sourceProvider) {
107
108         final Set<Capability> transformedCapabilities = Sets.newHashSet(Collections2.transform(capabilities, input -> {
109             if (sendFakeSchema) {
110                 sendFakeSchema = false;
111                 return new FakeCapability((YangModuleCapability) input);
112             } else {
113                 return input;
114             }
115         }));
116         transformedCapabilities.add(new BasicCapability("urn:ietf:params:netconf:capability:candidate:1.0"));
117         final NetconfMonitoringService monitoringService1 = new DummyMonitoringService(transformedCapabilities);
118         final SessionIdProvider idProvider = new SessionIdProvider();
119
120         final NetconfOperationServiceFactory aggregatedNetconfOperationServiceFactory = createOperationServiceFactory(
121             sourceProvider, transformedCapabilities, monitoringService1, idProvider);
122
123         final Set<String> serverCapabilities = configuration.getCapabilities();
124
125         final NetconfServerSessionNegotiatorFactory serverNegotiatorFactory = new TesttoolNegotiationFactory(
126                 hashedWheelTimer, aggregatedNetconfOperationServiceFactory, idProvider,
127                 configuration.getGenerateConfigsTimeout(),
128                 monitoringService1, serverCapabilities);
129
130         final NetconfServerDispatcherImpl.ServerChannelInitializer serverChannelInitializer =
131             new NetconfServerDispatcherImpl.ServerChannelInitializer(serverNegotiatorFactory);
132         return new NetconfServerDispatcherImpl(serverChannelInitializer, nettyThreadgroup, nettyThreadgroup);
133     }
134
135     private NetconfOperationServiceFactory createOperationServiceFactory(
136             final SchemaSourceProvider<YangTextSchemaSource> sourceProvider,
137             final Set<Capability> transformedCapabilities, final NetconfMonitoringService monitoringService1,
138             final SessionIdProvider idProvider) {
139         final AggregatedNetconfOperationServiceFactory aggregatedNetconfOperationServiceFactory =
140             new AggregatedNetconfOperationServiceFactory();
141
142         final NetconfOperationServiceFactory operationProvider;
143         if (configuration.isMdSal()) {
144             LOG.info("using MdsalOperationProvider.");
145             operationProvider = new MdsalOperationProvider(
146                 idProvider, transformedCapabilities, schemaContext, sourceProvider);
147         } else if (configuration.isXmlConfigurationProvided()) {
148             LOG.info("using SimulatedOperationProvider.");
149             operationProvider = new SimulatedOperationProvider(idProvider, transformedCapabilities,
150                     Optional.fromNullable(configuration.getNotificationFile()),
151                     Optional.fromNullable(configuration.getInitialConfigXMLFile()));
152         } else {
153             LOG.info("using OperationsProvider.");
154             operationProvider = new OperationsProvider(idProvider, transformedCapabilities,
155                 configuration.getOperationsCreator() != null ? configuration.getOperationsCreator()
156                     : DefaultOperationsCreator.getDefaultOperationServiceCreator(idProvider.getCurrentSessionId()));
157         }
158
159
160         final NetconfMonitoringActivator.NetconfMonitoringOperationServiceFactory monitoringService =
161                 new NetconfMonitoringActivator.NetconfMonitoringOperationServiceFactory(
162                         new NetconfMonitoringOperationService(monitoringService1));
163         aggregatedNetconfOperationServiceFactory.onAddNetconfOperationServiceFactory(operationProvider);
164         aggregatedNetconfOperationServiceFactory.onAddNetconfOperationServiceFactory(monitoringService);
165         if (configuration.getRpcConfigFile() != null) {
166             final SettableOperationProvider settableService =
167                     new SettableOperationProvider(configuration.getRpcConfigFile());
168             aggregatedNetconfOperationServiceFactory.onAddNetconfOperationServiceFactory(settableService);
169         } else {
170             final SettableOperationRpcProvider settableService =
171                     new SettableOperationRpcProvider(configuration.getRpcHandler());
172             aggregatedNetconfOperationServiceFactory.onAddNetconfOperationServiceFactory(settableService);
173         }
174         return aggregatedNetconfOperationServiceFactory;
175     }
176
177     public List<Integer> start() {
178         LOG.info("Starting {}, {} simulated devices starting on port {}",
179                 configuration.getDeviceCount(), configuration.isSsh() ? "SSH" : "TCP", configuration.getStartingPort());
180
181         final SharedSchemaRepository schemaRepo = new SharedSchemaRepository("netconf-simulator");
182         final Set<Capability> capabilities = parseSchemasToModuleCapabilities(schemaRepo);
183
184         final NetconfServerDispatcherImpl dispatcher = createDispatcher(capabilities,
185             sourceIdentifier -> schemaRepo.getSchemaSource(sourceIdentifier, YangTextSchemaSource.class));
186
187         int currentPort = configuration.getStartingPort();
188
189         final List<Integer> openDevices = Lists.newArrayList();
190
191         // Generate key to temp folder
192         final PEMGeneratorHostKeyProvider keyPairProvider = getPemGeneratorHostKeyProvider();
193
194         for (int i = 0; i < configuration.getDeviceCount(); i++) {
195             if (currentPort > 65535) {
196                 LOG.warn("Port cannot be greater than 65535, stopping further attempts.");
197                 break;
198             }
199             final InetSocketAddress address = getAddress(configuration.getIp(), currentPort);
200
201             final ChannelFuture server;
202             if (configuration.isSsh()) {
203                 final InetSocketAddress bindingAddress = InetSocketAddress.createUnresolved("0.0.0.0", currentPort);
204                 final LocalAddress tcpLocalAddress = new LocalAddress(address.toString());
205
206                 server = dispatcher.createLocalServer(tcpLocalAddress);
207                 try {
208                     final SshProxyServer sshServer = new SshProxyServer(
209                         minaTimerExecutor, nettyThreadgroup, nioExecutor);
210                     sshServer.bind(getSshConfiguration(bindingAddress, tcpLocalAddress, keyPairProvider));
211                     sshWrappers.add(sshServer);
212                 } catch (final BindException e) {
213                     LOG.warn("Cannot start simulated device on {}, port already in use. Skipping.", address);
214                     // Close local server and continue
215                     server.cancel(true);
216                     if (server.isDone()) {
217                         server.channel().close();
218                     }
219                     continue;
220                 } catch (final IOException e) {
221                     LOG.warn("Cannot start simulated device on {} due to IOException.", address, e);
222                     break;
223                 } finally {
224                     currentPort++;
225                 }
226
227                 try {
228                     server.get();
229                 } catch (final InterruptedException e) {
230                     throw new RuntimeException(e);
231                 } catch (final ExecutionException e) {
232                     LOG.warn("Cannot start ssh simulated device on {}, skipping", address, e);
233                     continue;
234                 }
235
236                 LOG.debug("Simulated SSH device started on {}", address);
237
238             } else {
239                 server = dispatcher.createServer(address);
240                 currentPort++;
241
242                 try {
243                     server.get();
244                 } catch (final InterruptedException e) {
245                     throw new RuntimeException(e);
246                 } catch (final ExecutionException e) {
247                     LOG.warn("Cannot start tcp simulated device on {}, skipping", address, e);
248                     continue;
249                 }
250
251                 LOG.debug("Simulated TCP device started on {}", address);
252             }
253
254             devicesChannels.add(server.channel());
255             openDevices.add(currentPort - 1);
256         }
257
258         if (openDevices.size() == configuration.getDeviceCount()) {
259             LOG.info("All simulated devices started successfully from port {} to {}",
260                     configuration.getStartingPort(), currentPort - 1);
261         } else if (openDevices.size() == 0) {
262             LOG.warn("No simulated devices started.");
263         } else {
264             LOG.warn("Not all simulated devices started successfully. Started devices ar on ports {}", openDevices);
265         }
266
267         return openDevices;
268     }
269
270     private SshProxyServerConfiguration getSshConfiguration(final InetSocketAddress bindingAddress,
271             final LocalAddress tcpLocalAddress, final PEMGeneratorHostKeyProvider keyPairProvider) throws IOException {
272         return new SshProxyServerConfigurationBuilder()
273                 .setBindingAddress(bindingAddress)
274                 .setLocalAddress(tcpLocalAddress)
275                 .setAuthenticator((username, password) -> true)
276                 .setPublickeyAuthenticator(((username, key, session) -> {
277                     LOG.info("Auth with public key: {}", key);
278                     return true;
279                 }))
280                 .setKeyPairProvider(keyPairProvider)
281                 .setIdleTimeout(Integer.MAX_VALUE)
282                 .createSshProxyServerConfiguration();
283     }
284
285     private PEMGeneratorHostKeyProvider getPemGeneratorHostKeyProvider() {
286         try {
287             final Path tempFile = Files.createTempFile("tempKeyNetconfTest", "suffix");
288             return new PEMGeneratorHostKeyProvider(tempFile.toAbsolutePath().toString(), "RSA", 4096);
289         } catch (final IOException e) {
290             LOG.error("Unable to generate PEM key", e);
291             throw new RuntimeException(e);
292         }
293     }
294
295     private Set<Capability> parseSchemasToModuleCapabilities(final SharedSchemaRepository consumer) {
296         final Set<SourceIdentifier> loadedSources = Sets.newHashSet();
297         consumer.registerSchemaSourceListener(TextToASTTransformer.create(consumer, consumer));
298         consumer.registerSchemaSourceListener(new SchemaSourceListener() {
299             @Override
300             public void schemaSourceEncountered(final SchemaSourceRepresentation schemaSourceRepresentation) {}
301
302             @Override
303             public void schemaSourceRegistered(final Iterable<PotentialSchemaSource<?>> potentialSchemaSources) {
304                 for (final PotentialSchemaSource<?> potentialSchemaSource : potentialSchemaSources) {
305                     loadedSources.add(potentialSchemaSource.getSourceIdentifier());
306                 }
307             }
308
309             @Override
310             public void schemaSourceUnregistered(final PotentialSchemaSource<?> potentialSchemaSource) {}
311         });
312
313         if (configuration.getSchemasDir() != null) {
314             LOG.info("Loading models from directory.");
315             final FilesystemSchemaSourceCache<YangTextSchemaSource> cache = new FilesystemSchemaSourceCache<>(
316                 consumer, YangTextSchemaSource.class, configuration.getSchemasDir());
317             consumer.registerSchemaSourceListener(cache);
318         } else if (configuration.getModels() != null) {
319             LOG.info("Loading models from classpath.");
320             final SchemaSourceCache<YangTextSchemaSource> cache = new SchemaSourceCache<>(
321                     consumer, YangTextSchemaSource.class, configuration.getModels());
322             consumer.registerSchemaSourceListener(cache);
323         } else {
324             LOG.info("Custom module loading skipped.");
325         }
326
327         addDefaultSchemas(consumer);
328
329         try {
330             //necessary for creating mdsal data stores and operations
331             this.schemaContext = consumer.createSchemaContextFactory(
332                 SchemaSourceFilter.ALWAYS_ACCEPT)
333                 .createSchemaContext(loadedSources).checkedGet();
334         } catch (final SchemaResolutionException e) {
335             throw new RuntimeException("Cannot parse schema context", e);
336         }
337
338         final Set<Capability> capabilities = Sets.newHashSet();
339
340         for (final Module module : schemaContext.getModules()) {
341             for (final Module subModule : module.getSubmodules()) {
342                 addModuleCapability(consumer, capabilities, subModule);
343             }
344             addModuleCapability(consumer, capabilities, module);
345         }
346         return capabilities;
347     }
348
349     private void addModuleCapability(final SharedSchemaRepository consumer, final Set<Capability> capabilities,
350                                      final Module module) {
351         final SourceIdentifier moduleSourceIdentifier = SourceIdentifier.create(module.getName(),
352                 (SimpleDateFormatUtil.DEFAULT_DATE_REV == module.getRevision() ? Optional.absent() :
353                         Optional.of(module.getQNameModule().getFormattedRevision())));
354         try {
355             final String moduleContent = new String(
356                 consumer.getSchemaSource(moduleSourceIdentifier, YangTextSchemaSource.class).checkedGet().read());
357             capabilities.add(new YangModuleCapability(module, moduleContent));
358             //IOException would be thrown in creating SchemaContext already
359         } catch (SchemaSourceException | IOException e) {
360             throw new RuntimeException("Cannot retrieve schema source for module "
361                 + moduleSourceIdentifier.toString() + " from schema repository", e);
362         }
363     }
364
365     private void addDefaultSchemas(final SharedSchemaRepository consumer) {
366         SourceIdentifier srcId = RevisionSourceIdentifier.create("ietf-netconf-monitoring", "2010-10-04");
367         registerSource(consumer, "/META-INF/yang/ietf-netconf-monitoring.yang", srcId);
368
369         srcId = RevisionSourceIdentifier.create("ietf-netconf-monitoring-extension", "2013-12-10");
370         registerSource(consumer, "/META-INF/yang/ietf-netconf-monitoring-extension.yang", srcId);
371
372         srcId = RevisionSourceIdentifier.create("ietf-yang-types", "2013-07-15");
373         registerSource(consumer, "/META-INF/yang/ietf-yang-types@2013-07-15.yang", srcId);
374
375         srcId = RevisionSourceIdentifier.create("ietf-inet-types", "2013-07-15");
376         registerSource(consumer, "/META-INF/yang/ietf-inet-types@2013-07-15.yang", srcId);
377     }
378
379     private void registerSource(final SharedSchemaRepository consumer, final String resource,
380                                 final SourceIdentifier sourceId) {
381         consumer.registerSchemaSource(new SchemaSourceProvider<SchemaSourceRepresentation>() {
382             @Override
383             public CheckedFuture<? extends SchemaSourceRepresentation, SchemaSourceException> getSource(
384                     final SourceIdentifier sourceIdentifier) {
385                 return Futures.immediateCheckedFuture(new YangTextSchemaSource(sourceId) {
386                     @Override
387                     protected MoreObjects.ToStringHelper addToStringAttributes(
388                             final MoreObjects.ToStringHelper toStringHelper) {
389                         return toStringHelper;
390                     }
391
392                     @Override
393                     public InputStream openStream() throws IOException {
394                         return getClass().getResourceAsStream(resource);
395                     }
396                 });
397             }
398         }, PotentialSchemaSource.create(
399             sourceId, YangTextSchemaSource.class, PotentialSchemaSource.Costs.IMMEDIATE.getValue()));
400     }
401
402     private static InetSocketAddress getAddress(final String ip, final int port) {
403         try {
404             return new InetSocketAddress(Inet4Address.getByName(ip), port);
405         } catch (final UnknownHostException e) {
406             throw new RuntimeException(e);
407         }
408     }
409
410     @Override
411     public void close() {
412         for (final SshProxyServer sshWrapper : sshWrappers) {
413             sshWrapper.close();
414         }
415         for (final Channel deviceCh : devicesChannels) {
416             deviceCh.close();
417         }
418         nettyThreadgroup.shutdownGracefully();
419         minaTimerExecutor.shutdownNow();
420         nioExecutor.shutdownNow();
421     }
422
423 }