2 * Copyright (c) 2014 Cisco Systems, Inc. and others. All rights reserved.
4 * This program and the accompanying materials are made available under the
5 * terms of the Eclipse Public License v1.0 which accompanies this distribution,
6 * and is available at http://www.eclipse.org/legal/epl-v10.html
9 package org.opendaylight.controller.netconf.ssh;
11 import com.google.common.collect.Lists;
12 import io.netty.channel.EventLoopGroup;
13 import java.io.IOException;
14 import java.nio.channels.AsynchronousChannelGroup;
15 import java.util.HashMap;
17 import java.util.concurrent.ExecutorService;
18 import java.util.concurrent.ScheduledExecutorService;
19 import java.util.concurrent.TimeUnit;
20 import org.apache.sshd.SshServer;
21 import org.apache.sshd.common.FactoryManager;
22 import org.apache.sshd.common.NamedFactory;
23 import org.apache.sshd.common.RuntimeSshException;
24 import org.apache.sshd.common.io.IoAcceptor;
25 import org.apache.sshd.common.io.IoConnector;
26 import org.apache.sshd.common.io.IoHandler;
27 import org.apache.sshd.common.io.IoServiceFactory;
28 import org.apache.sshd.common.io.IoServiceFactoryFactory;
29 import org.apache.sshd.common.io.nio2.Nio2Acceptor;
30 import org.apache.sshd.common.io.nio2.Nio2Connector;
31 import org.apache.sshd.common.io.nio2.Nio2ServiceFactoryFactory;
32 import org.apache.sshd.common.util.CloseableUtils;
33 import org.apache.sshd.server.Command;
34 import org.apache.sshd.server.ServerFactoryManager;
37 * Proxy SSH server that just delegates decrypted content to a delegate server within same VM.
38 * Implemented using Apache Mina SSH lib.
40 public class SshProxyServer implements AutoCloseable {
42 private final SshServer sshServer;
43 private final ScheduledExecutorService minaTimerExecutor;
44 private final EventLoopGroup clientGroup;
45 private final IoServiceFactoryFactory nioServiceWithPoolFactoryFactory;
47 public SshProxyServer(final ScheduledExecutorService minaTimerExecutor, final EventLoopGroup clientGroup, final ExecutorService nioExecutor) {
48 this.minaTimerExecutor = minaTimerExecutor;
49 this.clientGroup = clientGroup;
50 this.nioServiceWithPoolFactoryFactory = new NioServiceWithPoolFactory.NioServiceWithPoolFactoryFactory(nioExecutor);
51 this.sshServer = SshServer.setUpDefaultServer();
54 public void bind(final SshProxyServerConfiguration sshProxyServerConfiguration) throws IOException {
55 sshServer.setHost(sshProxyServerConfiguration.getBindingAddress().getHostString());
56 sshServer.setPort(sshProxyServerConfiguration.getBindingAddress().getPort());
58 sshServer.setPasswordAuthenticator(sshProxyServerConfiguration.getAuthenticator());
59 sshServer.setKeyPairProvider(sshProxyServerConfiguration.getKeyPairProvider());
61 sshServer.setIoServiceFactoryFactory(nioServiceWithPoolFactoryFactory);
62 sshServer.setScheduledExecutorService(minaTimerExecutor);
63 sshServer.setProperties(getProperties(sshProxyServerConfiguration));
65 final RemoteNetconfCommand.NetconfCommandFactory netconfCommandFactory =
66 new RemoteNetconfCommand.NetconfCommandFactory(clientGroup, sshProxyServerConfiguration.getLocalAddress());
67 sshServer.setSubsystemFactories(Lists.<NamedFactory<Command>>newArrayList(netconfCommandFactory));
71 private static Map<String, String> getProperties(final SshProxyServerConfiguration sshProxyServerConfiguration) {
72 return new HashMap<String, String>()
75 put(ServerFactoryManager.IDLE_TIMEOUT, String.valueOf(sshProxyServerConfiguration.getIdleTimeout()));
76 // TODO make auth timeout configurable on its own
77 put(ServerFactoryManager.AUTH_TIMEOUT, String.valueOf(sshProxyServerConfiguration.getIdleTimeout()));
86 } catch (final InterruptedException e) {
87 throw new RuntimeException("Interrupted while stopping sshServer", e);
89 sshServer.close(true);
94 * Based on Nio2ServiceFactory with one addition: injectable executor
96 private static final class NioServiceWithPoolFactory extends CloseableUtils.AbstractCloseable implements IoServiceFactory {
98 private final FactoryManager manager;
99 private final AsynchronousChannelGroup group;
101 public NioServiceWithPoolFactory(final FactoryManager manager, final ExecutorService executor) {
102 this.manager = manager;
104 group = AsynchronousChannelGroup.withThreadPool(executor);
105 } catch (final IOException e) {
106 throw new RuntimeSshException(e);
110 public IoConnector createConnector(final IoHandler handler) {
111 return new Nio2Connector(manager, handler, group);
114 public IoAcceptor createAcceptor(final IoHandler handler) {
115 return new Nio2Acceptor(manager, handler, group);
119 protected void doCloseImmediately() {
122 group.awaitTermination(5, TimeUnit.SECONDS);
123 } catch (final Exception e) {
124 log.debug("Exception caught while closing channel group", e);
126 super.doCloseImmediately();
130 private static final class NioServiceWithPoolFactoryFactory extends Nio2ServiceFactoryFactory {
132 private final ExecutorService nioExecutor;
134 private NioServiceWithPoolFactoryFactory(final ExecutorService nioExecutor) {
135 this.nioExecutor = nioExecutor;
139 public IoServiceFactory create(final FactoryManager manager) {
140 return new NioServiceWithPoolFactory(manager, nioExecutor);