2 * Copyright (c) 2013 Cisco Systems, Inc. and others. All rights reserved.
4 * This program and the accompanying materials are made available under the
5 * terms of the Eclipse Public License v1.0 which accompanies this distribution,
6 * and is available at http://www.eclipse.org/legal/epl-v10.html
8 package org.opendaylight.controller.netconf.ssh.osgi;
10 import static com.google.common.base.Preconditions.checkState;
12 import com.google.common.base.Preconditions;
14 import java.io.IOException;
15 import java.net.InetSocketAddress;
17 import org.apache.commons.io.FilenameUtils;
18 import org.opendaylight.controller.netconf.auth.AuthConstants;
19 import org.opendaylight.controller.netconf.auth.AuthProvider;
20 import org.opendaylight.controller.netconf.ssh.NetconfSSHServer;
21 import org.opendaylight.controller.netconf.ssh.authentication.PEMGenerator;
22 import org.opendaylight.controller.netconf.util.osgi.NetconfConfigUtil;
23 import org.opendaylight.controller.netconf.util.osgi.NetconfConfigUtil.InfixProp;
24 import org.osgi.framework.BundleActivator;
25 import org.osgi.framework.BundleContext;
26 import org.osgi.framework.ServiceReference;
27 import org.osgi.util.tracker.ServiceTracker;
28 import org.osgi.util.tracker.ServiceTrackerCustomizer;
29 import org.slf4j.Logger;
30 import org.slf4j.LoggerFactory;
32 import com.google.common.base.Optional;
33 import com.google.common.base.Strings;
35 import io.netty.channel.EventLoopGroup;
36 import io.netty.channel.local.LocalAddress;
37 import io.netty.channel.nio.NioEventLoopGroup;
40 * Activator for netconf SSH bundle which creates SSH bridge between netconf client and netconf server. Activator
41 * starts SSH Server in its own thread. This thread is closed when activator calls stop() method. Server opens socket
42 * and listens for client connections. Each client connection creation is handled in separate
43 * {@link org.opendaylight.controller.netconf.ssh.threads.Handshaker} thread.
44 * This thread creates two additional threads {@link org.opendaylight.controller.netconf.ssh.threads.IOThread}
45 * forwarding data from/to client.IOThread closes servers session and server connection when it gets -1 on input stream.
46 * {@link org.opendaylight.controller.netconf.ssh.threads.IOThread}'s run method waits for -1 on input stream to finish.
47 * All threads are daemons.
49 public class NetconfSSHActivator implements BundleActivator {
50 private static final Logger logger = LoggerFactory.getLogger(NetconfSSHActivator.class);
51 private static AuthProviderTracker authProviderTracker;
53 private NetconfSSHServer server;
56 public void start(final BundleContext bundleContext) throws IOException {
57 server = startSSHServer(bundleContext);
61 public void stop(final BundleContext context) throws IOException {
66 if(authProviderTracker != null) {
67 authProviderTracker.stop();
71 private static NetconfSSHServer startSSHServer(final BundleContext bundleContext) throws IOException {
72 final Optional<InetSocketAddress> maybeSshSocketAddress = NetconfConfigUtil.extractNetconfServerAddress(bundleContext,
75 if (maybeSshSocketAddress.isPresent() == false) {
76 logger.trace("SSH bridge not configured");
80 final InetSocketAddress sshSocketAddress = maybeSshSocketAddress.get();
81 logger.trace("Starting netconf SSH bridge at {}", sshSocketAddress);
83 final LocalAddress localAddress = NetconfConfigUtil.getNetconfLocalAddress();
85 final String path = FilenameUtils.separatorsToSystem(NetconfConfigUtil.getPrivateKeyPath(bundleContext));
86 checkState(!Strings.isNullOrEmpty(path), "Path to ssh private key is blank. Reconfigure %s", NetconfConfigUtil.getPrivateKeyKey());
87 final String privateKeyPEMString = PEMGenerator.readOrGeneratePK(new File(path));
89 final EventLoopGroup bossGroup = new NioEventLoopGroup();
90 final NetconfSSHServer server = NetconfSSHServer.start(sshSocketAddress.getPort(), localAddress, bossGroup, privateKeyPEMString.toCharArray());
92 authProviderTracker = new AuthProviderTracker(bundleContext, server);
97 private static Thread runNetconfSshThread(final NetconfSSHServer server) {
98 final Thread serverThread = new Thread(server, "netconf SSH server thread");
99 serverThread.setDaemon(true);
100 serverThread.start();
101 logger.trace("Netconf SSH bridge up and running.");
105 private static class AuthProviderTracker implements ServiceTrackerCustomizer<AuthProvider, AuthProvider> {
106 private final BundleContext bundleContext;
107 private final NetconfSSHServer server;
109 private Integer maxPreference;
110 private Thread sshThread;
111 private final ServiceTracker<AuthProvider, AuthProvider> listenerTracker;
113 public AuthProviderTracker(final BundleContext bundleContext, final NetconfSSHServer server) {
114 this.bundleContext = bundleContext;
115 this.server = server;
116 listenerTracker = new ServiceTracker<>(bundleContext, AuthProvider.class, this);
117 listenerTracker.open();
121 public AuthProvider addingService(final ServiceReference<AuthProvider> reference) {
122 logger.trace("Service {} added", reference);
123 final AuthProvider authService = bundleContext.getService(reference);
124 final Integer newServicePreference = getPreference(reference);
125 if(isBetter(newServicePreference)) {
126 server.setAuthProvider(authService);
127 if(sshThread == null) {
128 sshThread = runNetconfSshThread(server);
134 private Integer getPreference(final ServiceReference<AuthProvider> reference) {
135 final Object preferenceProperty = reference.getProperty(AuthConstants.SERVICE_PREFERENCE_KEY);
136 return preferenceProperty == null ? Integer.MIN_VALUE : Integer.valueOf(preferenceProperty.toString());
139 private boolean isBetter(final Integer newServicePreference) {
140 Preconditions.checkNotNull(newServicePreference);
141 if(maxPreference == null) {
145 return newServicePreference > maxPreference;
149 public void modifiedService(final ServiceReference<AuthProvider> reference, final AuthProvider service) {
150 final AuthProvider authService = bundleContext.getService(reference);
151 final Integer newServicePreference = getPreference(reference);
152 if(isBetter(newServicePreference)) {
153 logger.trace("Replacing modified service {} in netconf SSH.", reference);
154 server.setAuthProvider(authService);
159 public void removedService(final ServiceReference<AuthProvider> reference, final AuthProvider service) {
160 logger.trace("Removing service {} from netconf SSH. " +
161 "SSH won't authenticate users until AuthProvider service will be started.", reference);
162 maxPreference = null;
163 server.setAuthProvider(null);
167 listenerTracker.close();
168 // sshThread should finish normally since sshServer.close stops processing