Code

Fix for detecting empty tags that are required.
[gosa.git] / gosa-si / gosa-si-server
1 #!/usr/bin/perl
2 #===============================================================================
3 #
4 #         FILE:  gosa-sd
5 #
6 #        USAGE:  ./gosa-sd
7 #
8 #  DESCRIPTION:
9 #
10 #      OPTIONS:  ---
11 # REQUIREMENTS:  libconfig-inifiles-perl libcrypt-rijndael-perl libxml-simple-perl 
12 #                libdata-dumper-simple-perl libdbd-sqlite3-perl libnet-ldap-perl
13 #                libpoe-perl
14 #         BUGS:  ---
15 #        NOTES:
16 #       AUTHOR:   (Andreas Rettenberger), <rettenberger@gonicus.de>
17 #      COMPANY:
18 #      VERSION:  1.0
19 #      CREATED:  12.09.2007 08:54:41 CEST
20 #     REVISION:  ---
21 #===============================================================================
24 # TODO
25 #
26 # max_children wird momentan nicht mehr verwendet, jede eingehende nachricht bekommt ein eigenes POE child
28 use strict;
29 use warnings;
30 use Getopt::Long;
31 use Config::IniFiles;
32 use POSIX;
34 use Fcntl;
35 use IO::Socket::INET;
36 use IO::Handle;
37 use IO::Select;
38 use Symbol qw(qualify_to_ref);
39 use Crypt::Rijndael;
40 use MIME::Base64;
41 use Digest::MD5  qw(md5 md5_hex md5_base64);
42 use XML::Simple;
43 use Data::Dumper;
44 use Sys::Syslog qw( :DEFAULT setlogsock);
45 use Cwd;
46 use File::Spec;
47 use File::Basename;
48 use File::Find;
49 use File::Copy;
50 use File::Path;
51 use GOSA::GosaSupportDaemon;
52 use POE qw(Component::Server::TCP Wheel::Run Filter::Reference);
53 use Net::LDAP;
54 use Net::LDAP::Util qw(:escape);
55 use Time::HiRes qw( usleep);
57 my $db_module = "DBsqlite";
58 {
59 no strict "refs";
60 require ("GOSA/".$db_module.".pm");
61 ("GOSA/".$db_module)->import;
62 daemon_log("0 INFO: importing database module '$db_module'", 1);
63 }
65 my $modules_path = "/usr/lib/gosa-si/modules";
66 use lib "/usr/lib/gosa-si/modules";
68 # revision number of server and program name
69 my $server_version = '$HeadURL: https://oss.gonicus.de/repositories/gosa/trunk/gosa-si/gosa-si-server $:$Rev: 10826 $';
70 my $server_headURL;
71 my $server_revision;
72 my $server_status;
73 our $prg= basename($0);
75 our $global_kernel;
76 my ($foreground, $ping_timeout);
77 my ($server);
78 my ($gosa_server, $job_queue_timeout, $job_queue_loop_delay);
79 my ($messaging_db_loop_delay);
80 my ($procid, $pid);
81 my ($arp_fifo);
82 my ($xml);
83 my $sources_list;
84 my $max_clients;
85 my %repo_files=();
86 my $repo_path;
87 my %repo_dirs=();
89 # Variables declared in config file are always set to 'our'
90 our (%cfg_defaults, $log_file, $pid_file, 
91     $server_ip, $server_port, $ClientPackages_key, $dns_lookup,
92     $arp_activ, $gosa_unit_tag,
93     $GosaPackages_key, $gosa_timeout,
94     $foreign_server_string, $server_domain, $ServerPackages_key, $foreign_servers_register_delay,
95     $wake_on_lan_passwd, $job_synchronization, $modified_jobs_loop_delay,
96     $arp_enabled, $arp_interface,
97     $opsi_enabled, $opsi_server, $opsi_admin, $opsi_password,
98                 $new_systems_ou,
99 );
101 # additional variable which should be globaly accessable
102 our $server_address;
103 our $server_mac_address;
104 our $gosa_address;
105 our $no_arp;
106 our $verbose;
107 our $forground;
108 our $cfg_file;
109 our ($ldap_uri, $ldap_base, $ldap_admin_dn, $ldap_admin_password, $ldap_server_dn);
110 our ($mysql_username, $mysql_password, $mysql_database, $mysql_host);
111 our $known_modules;
112 our $root_uid;
113 our $adm_gid;
116 # specifies the verbosity of the daemon_log
117 $verbose = 0 ;
119 # if foreground is not null, script will be not forked to background
120 $foreground = 0 ;
122 # specifies the timeout seconds while checking the online status of a registrating client
123 $ping_timeout = 5;
125 $no_arp = 0;
126 my $packages_list_under_construction = "/tmp/packages_list_creation_in_progress";
127 my @packages_list_statements;
128 my $watch_for_new_jobs_in_progress = 0;
130 # holds all incoming decrypted messages
131 our $incoming_db;
132 our $incoming_tn = 'incoming';
133 my $incoming_file_name;
134 my @incoming_col_names = ("id INTEGER PRIMARY KEY auto_increment",
135         "timestamp VARCHAR(14) DEFAULT 'none'", 
136         "headertag VARCHAR(255) DEFAULT 'none'",
137         "targettag VARCHAR(255) DEFAULT 'none'",
138         "xmlmessage TEXT",
139         "module VARCHAR(255) DEFAULT 'none'",
140         "sessionid VARCHAR(255) DEFAULT '0'",
141 );
143 # holds all gosa jobs
144 our $job_db;
145 our $job_queue_tn = 'jobs';
146 my $job_queue_file_name;
147 my @job_queue_col_names = ("id INTEGER PRIMARY KEY auto_increment",
148         "timestamp VARCHAR(14) DEFAULT 'none'", 
149         "status VARCHAR(255) DEFAULT 'none'", 
150         "result TEXT",
151         "progress VARCHAR(255) DEFAULT 'none'",
152         "headertag VARCHAR(255) DEFAULT 'none'",
153         "targettag VARCHAR(255) DEFAULT 'none'", 
154         "xmlmessage TEXT", 
155         "macaddress VARCHAR(17) DEFAULT 'none'",
156         "plainname VARCHAR(255) DEFAULT 'none'",
157         "siserver VARCHAR(255) DEFAULT 'none'",
158         "modified INTEGER DEFAULT '0'",
159 );
161 # holds all other gosa-si-server
162 our $known_server_db;
163 our $known_server_tn = "known_server";
164 my $known_server_file_name;
165 my @known_server_col_names = ("hostname VARCHAR(255)", "macaddress VARCHAR(17)", "status VARCHAR(255)", "hostkey VARCHAR(255)", "loaded_modules TEXT", "timestamp VARCHAR(14)");
167 # holds all registrated clients
168 our $known_clients_db;
169 our $known_clients_tn = "known_clients";
170 my $known_clients_file_name;
171 my @known_clients_col_names = ("hostname VARCHAR(255)", "status VARCHAR(255)", "hostkey VARCHAR(255)", "timestamp VARCHAR(14)", "macaddress VARCHAR(17)", "events TEXT", "keylifetime VARCHAR(255)");
173 # holds all registered clients at a foreign server
174 our $foreign_clients_db;
175 our $foreign_clients_tn = "foreign_clients"; 
176 my $foreign_clients_file_name;
177 my @foreign_clients_col_names = ("hostname VARCHAR(255)", "macaddress VARCHAR(17)", "regserver VARCHAR(255)", "timestamp VARCHAR(14)");
179 # holds all logged in user at each client 
180 our $login_users_db;
181 our $login_users_tn = "login_users";
182 my $login_users_file_name;
183 my @login_users_col_names = ("client VARCHAR(255)", "user VARCHAR(255)", "timestamp VARCHAR(14)");
185 # holds all fai server, the debian release and tag
186 our $fai_server_db;
187 our $fai_server_tn = "fai_server"; 
188 my $fai_server_file_name;
189 our @fai_server_col_names = ("timestamp VARCHAR(14)", "server VARCHAR(255)", "fai_release VARCHAR(255)", "sections VARCHAR(255)", "tag VARCHAR(255)"); 
191 our $fai_release_db;
192 our $fai_release_tn = "fai_release"; 
193 my $fai_release_file_name;
194 our @fai_release_col_names = ("timestamp VARCHAR(14)", "fai_release VARCHAR(255)", "class VARCHAR(255)", "type VARCHAR(255)", "state VARCHAR(255)"); 
196 # holds all packages available from different repositories
197 our $packages_list_db;
198 our $packages_list_tn = "packages_list";
199 my $packages_list_file_name;
200 our @packages_list_col_names = ("distribution VARCHAR(255)", "package VARCHAR(255)", "version VARCHAR(255)", "section VARCHAR(255)", "description TEXT", "template LONGBLOB", "timestamp VARCHAR(14)");
201 my $outdir = "/tmp/packages_list_db";
202 my $arch = "i386"; 
204 # holds all messages which should be delivered to a user
205 our $messaging_db;
206 our $messaging_tn = "messaging"; 
207 our @messaging_col_names = ("id INTEGER", "subject TEXT", "message_from VARCHAR(255)", "message_to VARCHAR(255)", 
208         "flag VARCHAR(255)", "direction VARCHAR(255)", "delivery_time VARCHAR(255)", "message TEXT", "timestamp VARCHAR(14)" );
209 my $messaging_file_name;
211 # path to directory to store client install log files
212 our $client_fai_log_dir = "/var/log/fai"; 
214 # queue which stores taskes until one of the $max_children children are ready to process the task
215 #my @tasks = qw();
216 my @msgs_to_decrypt = qw();
217 my $max_children = 2;
220 # loop delay for job queue to look for opsi jobs
221 my $job_queue_opsi_delay = 10;
222 our $opsi_client;
223 our $opsi_url;
224  
225 # Lifetime of logged in user information. If no update information comes after n seconds, 
226 # the user is expeceted to be no longer logged in or the host is no longer running. Because
227 # of this, the user is deleted from login_users_db
228 our $logged_in_user_date_of_expiry = 600;
231 %cfg_defaults = (
232 "general" => {
233     "log-file" => [\$log_file, "/var/run/".$prg.".log"],
234     "pid-file" => [\$pid_file, "/var/run/".$prg.".pid"],
235     },
236 "server" => {
237     "ip"                    => [\$server_ip, "0.0.0.0"],
238     "port"                  => [\$server_port, "20081"],
239     "known-clients"         => [\$known_clients_file_name, '/var/lib/gosa-si/clients.db' ],
240     "known-servers"         => [\$known_server_file_name, '/var/lib/gosa-si/servers.db'],
241     "incoming"              => [\$incoming_file_name, '/var/lib/gosa-si/incoming.db'],
242     "login-users"           => [\$login_users_file_name, '/var/lib/gosa-si/users.db'],
243     "fai-server"            => [\$fai_server_file_name, '/var/lib/gosa-si/fai_server.db'],
244     "fai-release"           => [\$fai_release_file_name, '/var/lib/gosa-si/fai_release.db'],
245     "packages-list"         => [\$packages_list_file_name, '/var/lib/gosa-si/packages.db'],
246     "messaging"             => [\$messaging_file_name, '/var/lib/gosa-si/messaging.db'],
247     "foreign-clients"       => [\$foreign_clients_file_name, '/var/lib/gosa-si/foreign_clients.db'],
248     "source-list"           => [\$sources_list, '/etc/apt/sources.list'],
249     "repo-path"             => [\$repo_path, '/srv/www/repository'],
250     "ldap-uri"              => [\$ldap_uri, ""],
251     "ldap-base"             => [\$ldap_base, ""],
252     "ldap-admin-dn"         => [\$ldap_admin_dn, ""],
253     "ldap-admin-password"   => [\$ldap_admin_password, ""],
254     "gosa-unit-tag"         => [\$gosa_unit_tag, ""],
255     "max-clients"           => [\$max_clients, 10],
256     "wol-password"          => [\$wake_on_lan_passwd, ""],
257                 "mysql-username"        => [\$mysql_username, "gosa_si"],
258                 "mysql-password"        => [\$mysql_password, ""],
259                 "mysql-database"        => [\$mysql_database, "gosa_si"],
260                 "mysql-host"            => [\$mysql_host, "127.0.0.1"],
261     },
262 "GOsaPackages" => {
263     "job-queue" => [\$job_queue_file_name, '/var/lib/gosa-si/jobs.db'],
264     "job-queue-loop-delay" => [\$job_queue_loop_delay, 3],
265     "messaging-db-loop-delay" => [\$messaging_db_loop_delay, 3],
266     "key" => [\$GosaPackages_key, "none"],
267                 "new-systems-ou" => [\$new_systems_ou, 'ou=workstations,ou=systems'],
268     },
269 "ClientPackages" => {
270     "key" => [\$ClientPackages_key, "none"],
271     "user-date-of-expiry" => [\$logged_in_user_date_of_expiry, 600],
272     },
273 "ServerPackages"=> {
274     "address"      => [\$foreign_server_string, ""],
275     "dns-lookup"            => [\$dns_lookup, "true"],
276     "domain"  => [\$server_domain, ""],
277     "key"     => [\$ServerPackages_key, "none"],
278     "key-lifetime" => [\$foreign_servers_register_delay, 120],
279     "job-synchronization-enabled" => [\$job_synchronization, "true"],
280     "synchronization-loop" => [\$modified_jobs_loop_delay, 5],
281     },
282 "ArpHandler" => {
283     "enabled"   => [\$arp_enabled, "true"],
284     "interface" => [\$arp_interface, "all"],
285         },
286 "Opsi" => {
287     "enabled"  => [\$opsi_enabled, "false"], 
288     "server"   => [\$opsi_server, "localhost"],
289     "admin"    => [\$opsi_admin, "opsi-admin"],
290     "password" => [\$opsi_password, "secret"],
291    },
293 );
296 #===  FUNCTION  ================================================================
297 #         NAME:  usage
298 #   PARAMETERS:  nothing
299 #      RETURNS:  nothing
300 #  DESCRIPTION:  print out usage text to STDERR
301 #===============================================================================
302 sub usage {
303     print STDERR << "EOF" ;
304 usage: $prg [-hvf] [-c config]
306            -h        : this (help) message
307            -c <file> : config file
308            -f        : foreground, process will not be forked to background
309            -v        : be verbose (multiple to increase verbosity)
310            -no-arp   : starts $prg without connection to arp module
311  
312 EOF
313     print "\n" ;
317 #===  FUNCTION  ================================================================
318 #         NAME:  logging
319 #   PARAMETERS:  level - string - default 'info'
320 #                msg - string -
321 #                facility - string - default 'LOG_DAEMON'
322 #      RETURNS:  nothing
323 #  DESCRIPTION:  function for logging
324 #===============================================================================
325 sub daemon_log {
326     # log into log_file
327     my( $msg, $level ) = @_;
328     if(not defined $msg) { return }
329     if(not defined $level) { $level = 1 }
330     if(defined $log_file){
331         open(LOG_HANDLE, ">>$log_file");
332         if(not defined open( LOG_HANDLE, ">>$log_file" )) {
333             print STDERR "cannot open $log_file: $!";
334             return 
335         }
336         chomp($msg);
337         #$msg =~s/\n//g;   # no newlines are allowed in log messages, this is important for later log parsing
338         if($level <= $verbose){
339             my ($seconds, $minutes, $hours, $monthday, $month,
340                     $year, $weekday, $yearday, $sommertime) = localtime(time);
341             $hours = $hours < 10 ? $hours = "0".$hours : $hours;
342             $minutes = $minutes < 10 ? $minutes = "0".$minutes : $minutes;
343             $seconds = $seconds < 10 ? $seconds = "0".$seconds : $seconds;
344             my @monthnames = ("Jan", "Feb", "Mar", "Apr", "May", "Jun", "Jul", "Aug", "Sep", "Oct", "Nov", "Dec");
345             $month = $monthnames[$month];
346             $monthday = $monthday < 10 ? $monthday = "0".$monthday : $monthday;
347             $year+=1900;
348             my $name = $prg;
350             my $log_msg = "$month $monthday $hours:$minutes:$seconds $name $msg\n";
351             print LOG_HANDLE $log_msg;
352             if( $foreground ) { 
353                 print STDERR $log_msg;
354             }
355         }
356         close( LOG_HANDLE );
357     }
361 #===  FUNCTION  ================================================================
362 #         NAME:  check_cmdline_param
363 #   PARAMETERS:  nothing
364 #      RETURNS:  nothing
365 #  DESCRIPTION:  validates commandline parameter
366 #===============================================================================
367 sub check_cmdline_param () {
368     my $err_config;
369     my $err_counter = 0;
370         if(not defined($cfg_file)) {
371                 $cfg_file = "/etc/gosa-si/server.conf";
372                 if(! -r $cfg_file) {
373                         $err_config = "please specify a config file";
374                         $err_counter += 1;
375                 }
376     }
377     if( $err_counter > 0 ) {
378         &usage( "", 1 );
379         if( defined( $err_config)) { print STDERR "$err_config\n"}
380         print STDERR "\n";
381         exit( -1 );
382     }
386 #===  FUNCTION  ================================================================
387 #         NAME:  check_pid
388 #   PARAMETERS:  nothing
389 #      RETURNS:  nothing
390 #  DESCRIPTION:  handels pid processing
391 #===============================================================================
392 sub check_pid {
393     $pid = -1;
394     # Check, if we are already running
395     if( open(LOCK_FILE, "<$pid_file") ) {
396         $pid = <LOCK_FILE>;
397         if( defined $pid ) {
398             chomp( $pid );
399             if( -f "/proc/$pid/stat" ) {
400                 my($stat) = `cat /proc/$pid/stat` =~ m/$pid \((.+)\).*/;
401                 if( $stat ) {
402                                         daemon_log("ERROR: Already running",1);
403                     close( LOCK_FILE );
404                     exit -1;
405                 }
406             }
407         }
408         close( LOCK_FILE );
409         unlink( $pid_file );
410     }
412     # create a syslog msg if it is not to possible to open PID file
413     if (not sysopen(LOCK_FILE, $pid_file, O_WRONLY|O_CREAT|O_EXCL, 0644)) {
414         my($msg) = "Couldn't obtain lockfile '$pid_file' ";
415         if (open(LOCK_FILE, '<', $pid_file)
416                 && ($pid = <LOCK_FILE>))
417         {
418             chomp($pid);
419             $msg .= "(PID $pid)\n";
420         } else {
421             $msg .= "(unable to read PID)\n";
422         }
423         if( ! ($foreground) ) {
424             openlog( $0, "cons,pid", "daemon" );
425             syslog( "warning", $msg );
426             closelog();
427         }
428         else {
429             print( STDERR " $msg " );
430         }
431         exit( -1 );
432     }
435 #===  FUNCTION  ================================================================
436 #         NAME:  import_modules
437 #   PARAMETERS:  module_path - string - abs. path to the directory the modules 
438 #                are stored
439 #      RETURNS:  nothing
440 #  DESCRIPTION:  each file in module_path which ends with '.pm' and activation 
441 #                state is on is imported by "require 'file';"
442 #===============================================================================
443 sub import_modules {
444     daemon_log(" ", 1);
446     if (not -e $modules_path) {
447         daemon_log("0 ERROR: cannot find directory or directory is not readable: $modules_path", 1);   
448     }
450     opendir (DIR, $modules_path) or die "ERROR while loading modules from directory $modules_path : $!\n";
451     while (defined (my $file = readdir (DIR))) {
452         if (not $file =~ /(\S*?).pm$/) {
453             next;
454         }
455                 my $mod_name = $1;
457         # ArpHandler switch
458         if( $file =~ /ArpHandler.pm/ ) {
459             if( $arp_enabled eq "false" ) { next; }
460         }
461         
462         eval { require $file; };
463         if ($@) {
464             daemon_log("0 ERROR: gosa-si-server could not load module $file", 1);
465             daemon_log("$@", 1);
466             exit;
467                 } else {
468                         my $info = eval($mod_name.'::get_module_info()');
469                         # Only load module if get_module_info() returns a non-null object
470                         if( $info ) {
471                                 my ($input_address, $input_key, $event_hash) = @{$info};
472                                 $known_modules->{$mod_name} = $info;
473                                 daemon_log("0 INFO: module $mod_name loaded", 5);
474                         }
475                 }
476     }   
478     close (DIR);
481 #===  FUNCTION  ================================================================
482 #         NAME:  password_check
483 #   PARAMETERS:  nothing
484 #      RETURNS:  nothing
485 #  DESCRIPTION:  escalates an critical error if two modules exist which are avaialable by 
486 #                the same password
487 #===============================================================================
488 sub password_check {
489     my $passwd_hash = {};
490     while (my ($mod_name, $mod_info) = each %$known_modules) {
491         my $mod_passwd = @$mod_info[1];
492         if (not defined $mod_passwd) { next; }
493         if (not exists $passwd_hash->{$mod_passwd}) {
494             $passwd_hash->{$mod_passwd} = $mod_name;
496         # escalates critical error
497         } else {
498             &daemon_log("0 ERROR: two loaded modules do have the same password. Please modify the 'key'-parameter in config file");
499             &daemon_log("0 ERROR: module='$mod_name' and module='".$passwd_hash->{$mod_passwd}."'");
500             exit( -1 );
501         }
502     }
507 #===  FUNCTION  ================================================================
508 #         NAME:  sig_int_handler
509 #   PARAMETERS:  signal - string - signal arose from system
510 #      RETURNS:  nothing
511 #  DESCRIPTION:  handels tasks to be done befor signal becomes active
512 #===============================================================================
513 sub sig_int_handler {
514     my ($signal) = @_;
516 #       if (defined($ldap_handle)) {
517 #               $ldap_handle->disconnect;
518 #       }
519     # TODO alle verbliebenden ldap verbindungen aus allen heaps beenden
520     
522     daemon_log("shutting down gosa-si-server", 1);
523     system("kill `ps -C gosa-si-server -o pid=`");
525 $SIG{INT} = \&sig_int_handler;
528 sub check_key_and_xml_validity {
529     my ($crypted_msg, $module_key, $session_id) = @_;
530     my $msg;
531     my $msg_hash;
532     my $error_string;
533     eval{
534         $msg = &decrypt_msg($crypted_msg, $module_key);
536         if ($msg =~ /<xml>/i){
537             $msg =~ s/\s+/ /g;  # just for better daemon_log
538             daemon_log("$session_id DEBUG: decrypted_msg: \n$msg", 9);
539             $msg_hash = $xml->XMLin($msg, ForceArray=>1);
541             ##############
542             # check header
543             if( not exists $msg_hash->{'header'} ) { die "no header specified"; }
544             my $header_l = $msg_hash->{'header'};
545             if( (1 > @{$header_l}) || ( ( 'HASH' eq ref @{$header_l}[0]) && (1 > keys %{@{$header_l}[0]}) ) ) { die 'empty header tag'; }
546             if( 1 < @{$header_l} ) { die 'more than one header specified'; }
547             my $header = @{$header_l}[0];
548             if( 0 == length $header) { die 'empty string in header tag'; }
550             ##############
551             # check source
552             if( not exists $msg_hash->{'source'} ) { die "no source specified"; }
553             my $source_l = $msg_hash->{'source'};
554             if( (1 > @{$source_l}) || ( ( 'HASH' eq ref @{$source_l}[0]) && (1 > keys %{@{$source_l}[0]}) ) ) { die 'empty source tag'; }
555             if( 1 < @{$source_l} ) { die 'more than one source specified'; }
556             my $source = @{$source_l}[0];
557             if( 0 == length $source) { die 'source error'; }
559             ##############
560             # check target
561             if( not exists $msg_hash->{'target'} ) { die "no target specified"; }
562             my $target_l = $msg_hash->{'target'};
563             if( (1 > @{$target_l}) || ( ('HASH' eq ref @{$target_l}[0]) && (1 > keys %{@{$target_l}[0]}) ) ) { die 'empty target tag'; }
564         }
565     };
566     if($@) {
567         daemon_log("$session_id ERROR: do not understand the message: $@", 1);
568         $msg = undef;
569         $msg_hash = undef;
570     }
572     return ($msg, $msg_hash);
576 sub check_outgoing_xml_validity {
577     my ($msg, $session_id) = @_;
579     my $msg_hash;
580     eval{
581         $msg_hash = $xml->XMLin($msg, ForceArray=>1);
583         ##############
584         # check header
585         my $header_l = $msg_hash->{'header'};
586         if( 1 != @{$header_l} ) {
587             die 'no or more than one headers specified';
588         }
589         my $header = @{$header_l}[0];
590         if( 0 == length $header) {
591             die 'header has length 0';
592         }
594         ##############
595         # check source
596         my $source_l = $msg_hash->{'source'};
597         if( 1 != @{$source_l} ) {
598             die 'no or more than 1 sources specified';
599         }
600         my $source = @{$source_l}[0];
601         if( 0 == length $source) {
602             die 'source has length 0';
603         }
605                                 # Check if source contains hostname instead of ip address
606                                 if(not $source =~ /^[a-z0-9\.]+:\d+$/i) {
607                                                 my ($hostname,$port) = split(/:/, $source);
608                                                 my $ip_address = inet_ntoa(scalar gethostbyname($hostname));
609                                                 if(defined($ip_address) && $ip_address =~ /^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}/ && $port =~ /^\d+$/) {
610                                                         # Write ip address to $source variable
611                                                         $source = "$ip_address:$port";
612                                                 }
613                                 }
614         unless( $source =~ /^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}:\d+$/ ||
615                 $source =~ /^GOSA$/i) {
616             die "source '$source' is neither a complete ip-address with port nor 'GOSA'";
617         }
618         
619         ##############
620         # check target  
621         my $target_l = $msg_hash->{'target'};
622         if( 0 == @{$target_l} ) {
623             die "no targets specified";
624         }
625         foreach my $target (@$target_l) {
626             if( 0 == length $target) {
627                 die "target has length 0";
628             }
629             unless( $target =~ /^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}:\d+$/ ||
630                     $target =~ /^GOSA$/i ||
631                     $target =~ /^\*$/ ||
632                     $target =~ /KNOWN_SERVER/i ||
633                     $target =~ /JOBDB/i ||
634                     $target =~ /^([0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2})$/i ){
635                 die "target '$target' is not a complete ip-address with port or a valid target name or a mac-address";
636             }
637         }
638     };
639     if($@) {
640         daemon_log("$session_id ERROR: outgoing msg is not gosa-si envelope conform: $@", 1);
641         daemon_log("$@ ".(defined($msg) && length($msg)>0)?$msg:"Empty Message", 1);
642         $msg_hash = undef;
643     }
645     return ($msg_hash);
649 sub input_from_known_server {
650     my ($input, $remote_ip, $session_id) = @_ ;  
651     my ($msg, $msg_hash, $module);
653     my $sql_statement= "SELECT * FROM known_server";
654     my $query_res = $known_server_db->select_dbentry( $sql_statement ); 
656     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
657         my $host_name = $hit->{hostname};
658         if( not $host_name =~ "^$remote_ip") {
659             next;
660         }
661         my $host_key = $hit->{hostkey};
662         daemon_log("$session_id DEBUG: input_from_known_server: host_name: $host_name", 7);
663         daemon_log("$session_id DEBUG: input_from_known_server: host_key: $host_key", 7);
665         # check if module can open msg envelope with module key
666         my ($tmp_msg, $tmp_msg_hash) = &check_key_and_xml_validity($input, $host_key, $session_id);
667         if( (!$tmp_msg) || (!$tmp_msg_hash) ) {
668             daemon_log("$session_id DEBUG: input_from_known_server: deciphering raise error", 7);
669             daemon_log("$@", 8);
670             next;
671         }
672         else {
673             $msg = $tmp_msg;
674             $msg_hash = $tmp_msg_hash;
675             $module = "ServerPackages";
676             daemon_log("$session_id DEBUG: check_key_and_xml_validity... ok", 7);
677             last;
678         }
679     }
681     if( (!$msg) || (!$msg_hash) || (!$module) ) {
682         daemon_log("$session_id DEBUG: Incoming message is not from a known server", 7);
683     }
684   
685     return ($msg, $msg_hash, $module);
689 sub input_from_known_client {
690     my ($input, $remote_ip, $session_id) = @_ ;  
691     my ($msg, $msg_hash, $module);
693     my $sql_statement= "SELECT * FROM known_clients";
694     my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
695     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
696         my $host_name = $hit->{hostname};
697         if( not $host_name =~ /^$remote_ip:\d*$/) {
698                 next;
699                 }
700         my $host_key = $hit->{hostkey};
701         &daemon_log("$session_id DEBUG: input_from_known_client: host_name: $host_name", 7);
702         &daemon_log("$session_id DEBUG: input_from_known_client: host_key: $host_key", 7);
704         # check if module can open msg envelope with module key
705         ($msg, $msg_hash) = &check_key_and_xml_validity($input, $host_key, $session_id);
707         if( (!$msg) || (!$msg_hash) ) {
708             &daemon_log("$session_id DEGUG: input_from_known_client: deciphering raise error", 7);
709             &daemon_log("$@", 8);
710             next;
711         }
712         else {
713             $module = "ClientPackages";
714             daemon_log("$session_id DEBUG: check_key_and_xml_validity... ok", 7);
715             last;
716         }
717     }
719     if( (!$msg) || (!$msg_hash) || (!$module) ) {
720         &daemon_log("$session_id DEBUG: Incoming message is not from a known client", 7);
721     }
723     return ($msg, $msg_hash, $module);
727 sub input_from_unknown_host {
728         no strict "refs";
729         my ($input, $session_id) = @_ ;
730         my ($msg, $msg_hash, $module);
731         my $error_string;
733         my %act_modules = %$known_modules;
735         while( my ($mod, $info) = each(%act_modules)) {
737                 # check a key exists for this module
738                 my $module_key = ${$mod."_key"};
739                 if( not defined $module_key ) {
740                         if( $mod eq 'ArpHandler' ) {
741                                 next;
742                         }
743                         daemon_log("$session_id ERROR: no key specified in config file for $mod", 1);
744                         next;
745                 }
746                 daemon_log("$session_id DEBUG: $mod: $module_key", 7);
748                 # check if module can open msg envelope with module key
749                 ($msg, $msg_hash) = &check_key_and_xml_validity($input, $module_key, $session_id);
750                 if( (not defined $msg) || (not defined $msg_hash) ) {
751                         next;
752                 } else {
753                         $module = $mod;
754             daemon_log("$session_id DEBUG: check_key_and_xml_validity... ok", 7);
755                         last;
756                 }
757         }
759         if( (!$msg) || (!$msg_hash) || (!$module)) {
760                 daemon_log("$session_id DEBUG: Incoming message is not from an unknown host", 7);
761         }
763         return ($msg, $msg_hash, $module);
767 sub create_ciphering {
768     my ($passwd) = @_;
769         if((!defined($passwd)) || length($passwd)==0) {
770                 $passwd = "";
771         }
772     $passwd = substr(md5_hex("$passwd") x 32, 0, 32);
773     my $iv = substr(md5_hex('GONICUS GmbH'),0, 16);
774     my $my_cipher = Crypt::Rijndael->new($passwd , Crypt::Rijndael::MODE_CBC());
775     $my_cipher->set_iv($iv);
776     return $my_cipher;
780 sub encrypt_msg {
781     my ($msg, $key) = @_;
782     my $my_cipher = &create_ciphering($key);
783     my $len;
784     {
785             use bytes;
786             $len= 16-length($msg)%16;
787     }
788     $msg = "\0"x($len).$msg;
789     $msg = $my_cipher->encrypt($msg);
790     chomp($msg = &encode_base64($msg));
791     # there are no newlines allowed inside msg
792     $msg=~ s/\n//g;
793     return $msg;
797 sub decrypt_msg {
799     my ($msg, $key) = @_ ;
800     $msg = &decode_base64($msg);
801     my $my_cipher = &create_ciphering($key);
802     $msg = $my_cipher->decrypt($msg); 
803     $msg =~ s/\0*//g;
804     return $msg;
808 sub get_encrypt_key {
809     my ($target) = @_ ;
810     my $encrypt_key;
811     my $error = 0;
813     # target can be in known_server
814     if( not defined $encrypt_key ) {
815         my $sql_statement= "SELECT * FROM known_server WHERE hostname='$target'";
816         my $query_res = $known_server_db->select_dbentry( $sql_statement ); 
817         while( my ($hit_num, $hit) = each %{ $query_res } ) {    
818             my $host_name = $hit->{hostname};
819             if( $host_name ne $target ) {
820                 next;
821             }
822             $encrypt_key = $hit->{hostkey};
823             last;
824         }
825     }
827     # target can be in known_client
828     if( not defined $encrypt_key ) {
829         my $sql_statement= "SELECT * FROM known_clients WHERE hostname='$target'";
830         my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
831         while( my ($hit_num, $hit) = each %{ $query_res } ) {    
832             my $host_name = $hit->{hostname};
833             if( $host_name ne $target ) {
834                 next;
835             }
836             $encrypt_key = $hit->{hostkey};
837             last;
838         }
839     }
841     return $encrypt_key;
845 #===  FUNCTION  ================================================================
846 #         NAME:  open_socket
847 #   PARAMETERS:  PeerAddr string something like 192.168.1.1 or 192.168.1.1:10000
848 #                [PeerPort] string necessary if port not appended by PeerAddr
849 #      RETURNS:  socket IO::Socket::INET
850 #  DESCRIPTION:  open a socket to PeerAddr
851 #===============================================================================
852 sub open_socket {
853     my ($PeerAddr, $PeerPort) = @_ ;
854     if(defined($PeerPort)){
855         $PeerAddr = $PeerAddr.":".$PeerPort;
856     }
857     my $socket;
858     $socket = new IO::Socket::INET(PeerAddr => $PeerAddr,
859             Porto => "tcp",
860             Type => SOCK_STREAM,
861             Timeout => 5,
862             );
863     if(not defined $socket) {
864         return;
865     }
866 #    &daemon_log("DEBUG: open_socket: $PeerAddr", 7);
867     return $socket;
871 #sub get_local_ip_for_remote_ip {
872 #       my $remote_ip= shift;
873 #       my $result="0.0.0.0";
875 #       if($remote_ip =~ /^(\d\d?\d?\.){3}\d\d?\d?$/) {
876 #               if($remote_ip eq "127.0.0.1") {
877 #                       $result = "127.0.0.1";
878 #               } else {
879 #                       my $PROC_NET_ROUTE= ('/proc/net/route');
881 #                       open(PROC_NET_ROUTE, "<$PROC_NET_ROUTE")
882 #                               or die "Could not open $PROC_NET_ROUTE";
884 #                       my @ifs = <PROC_NET_ROUTE>;
886 #                       close(PROC_NET_ROUTE);
888 #                       # Eat header line
889 #                       shift @ifs;
890 #                       chomp @ifs;
891 #                       foreach my $line(@ifs) {
892 #                               my ($Iface,$Destination,$Gateway,$Flags,$RefCnt,$Use,$Metric,$Mask,$MTU,$Window,$IRTT)=split(/\s/, $line);
893 #                               my $destination;
894 #                               my $mask;
895 #                               my ($d,$c,$b,$a)=unpack('a2 a2 a2 a2', $Destination);
896 #                               $destination= sprintf("%d.%d.%d.%d", hex($a), hex($b), hex($c), hex($d));
897 #                               ($d,$c,$b,$a)=unpack('a2 a2 a2 a2', $Mask);
898 #                               $mask= sprintf("%d.%d.%d.%d", hex($a), hex($b), hex($c), hex($d));
899 #                               if(new NetAddr::IP($remote_ip)->within(new NetAddr::IP($destination, $mask))) {
900 #                                       # destination matches route, save mac and exit
901 #                                       $result= &get_ip($Iface);
902 #                                       last;
903 #                               }
904 #                       }
905 #               }
906 #       } else {
907 #               daemon_log("0 WARNING: get_local_ip_for_remote_ip() was called with a non-ip parameter: '$remote_ip'", 1);
908 #       }
909 #       return $result;
910 #}
913 sub send_msg_to_target {
914     my ($msg, $address, $encrypt_key, $msg_header, $session_id) = @_ ;
915     my $error = 0;
916     my $header;
917     my $timestamp = &get_time();
918     my $new_status;
919     my $act_status;
920     my ($sql_statement, $res);
921   
922     if( $msg_header ) {
923         $header = "'$msg_header'-";
924     } else {
925         $header = "";
926     }
928         # Patch the source ip
929         if($msg =~ /<source>0\.0\.0\.0:\d*?<\/source>/) {
930                 my $remote_ip = &get_local_ip_for_remote_ip(sprintf("%s", $address =~ /^([0-9\.]*?):.*$/));
931                 $msg =~ s/<source>(0\.0\.0\.0):(\d*?)<\/source>/<source>$remote_ip:$2<\/source>/s;
932         }
934     # encrypt xml msg
935     my $crypted_msg = &encrypt_msg($msg, $encrypt_key);
937     # opensocket
938     my $socket = &open_socket($address);
939     if( !$socket ) {
940         daemon_log("$session_id WARNING: cannot send ".$header."msg to $address , host not reachable", 3);
941         $error++;
942     }
943     
944     if( $error == 0 ) {
945         # send xml msg
946         print $socket $crypted_msg."\n";
948         daemon_log("$session_id INFO: send ".$header."msg to $address", 5);
949         daemon_log("$session_id DEBUG: message:\n$msg", 9);
950         
951     }
953     # close socket in any case
954     if( $socket ) {
955         close $socket;
956     }
958     if( $error > 0 ) { $new_status = "down"; }
959     else { $new_status = $msg_header; }
962     # known_clients
963     $sql_statement = "SELECT * FROM $known_clients_tn WHERE hostname='$address'";
964     $res = $known_clients_db->select_dbentry($sql_statement);
965     if( keys(%$res) == 1) {
966         $act_status = exists $res->{1}->{'status'} ? $res->{1}->{'status'} : "";
967         if ($act_status eq "down" && $new_status eq "down") {
968             $sql_statement = "DELETE FROM known_clients WHERE hostname='$address'";
969             $res = $known_clients_db->del_dbentry($sql_statement);
970             daemon_log("$session_id WARNING: failed 2x to send msg to host '$address', delete host from known_clients", 3);
971         } else { 
972             $sql_statement = "UPDATE known_clients SET status='$new_status', timestamp='$timestamp' WHERE hostname='$address'";
973             $res = $known_clients_db->update_dbentry($sql_statement);
974             if($new_status eq "down"){
975                 daemon_log("$session_id WARNING: set '$address' from status '$act_status' to '$new_status'", 3);
976             } else {
977                 daemon_log("$session_id INFO: set '$address' from status '$act_status' to '$new_status'", 5);
978             }
979         }
980     }
982     # known_server
983     $sql_statement = "SELECT * FROM $known_server_tn WHERE hostname='$address'";
984     $res = $known_server_db->select_dbentry($sql_statement);
985     if( keys(%$res) == 1) {
986         $act_status = exists $res->{1}->{'status'} ? $res->{1}->{'status'} : "";
987         if ($act_status eq "down" && $new_status eq "down") {
988             $sql_statement = "DELETE FROM known_server WHERE hostname='$address'";
989             $res = $known_server_db->del_dbentry($sql_statement);
990             daemon_log("$session_id WARNING: failed 2x to send a message to host '$address', delete host from known_server", 3);
991         } 
992         else { 
993             $sql_statement = "UPDATE known_server SET status='$new_status', timestamp='$timestamp' WHERE hostname='$address'";
994             $res = $known_server_db->update_dbentry($sql_statement);
995             if($new_status eq "down"){
996                 daemon_log("$session_id WARNING: set '$address' from status '$act_status' to '$new_status'", 3);
997             } else {
998                 daemon_log("$session_id INFO: set '$address' from status '$act_status' to '$new_status'", 5);
999             }
1000         }
1001     }
1002     return $error; 
1006 sub update_jobdb_status_for_send_msgs {
1007     my ($answer, $error) = @_;
1008     if( $answer =~ /<jobdb_id>(\d+)<\/jobdb_id>/ ) {
1009         my $jobdb_id = $1;
1010             
1011         # sending msg faild
1012         if( $error ) {
1013             if (not $answer =~ /<header>trigger_action_reinstall<\/header>/) {
1014                 my $sql_statement = "UPDATE $job_queue_tn ".
1015                     "SET status='error', result='can not deliver msg, please consult log file' ".
1016                     "WHERE id=$jobdb_id";
1017                 my $res = $job_db->update_dbentry($sql_statement);
1018             }
1020         # sending msg was successful
1021         } else {
1022             my $sql_statement = "UPDATE $job_queue_tn ".
1023                 "SET status='done' ".
1024                 "WHERE id=$jobdb_id AND status='processed'";
1025             my $res = $job_db->update_dbentry($sql_statement);
1026         }
1027     }
1031 sub sig_handler {
1032         my ($kernel, $signal) = @_[KERNEL, ARG0] ;
1033         daemon_log("0 INFO got signal '$signal'", 1); 
1034         $kernel->sig_handled();
1035         return;
1039 sub msg_to_decrypt {
1040         my ($kernel, $session, $heap) = @_[KERNEL, SESSION, HEAP];
1041         my $session_id = $session->ID;
1042         my ($msg, $msg_hash, $module);
1043         my $error = 0;
1045         # hole neue msg aus @msgs_to_decrypt
1046         my $next_msg = shift @msgs_to_decrypt;
1048         # msg is from a new client or gosa
1049         ($msg, $msg_hash, $module) = &input_from_unknown_host($next_msg, $session_id);
1051         # msg is from a gosa-si-server
1052         if(( !$msg ) || ( !$msg_hash ) || ( !$module )){
1053                 ($msg, $msg_hash, $module) = &input_from_known_server($next_msg, $heap->{'remote_ip'}, $session_id);
1054         }
1055         # msg is from a gosa-si-client
1056         if(( !$msg ) || ( !$msg_hash ) || ( !$module )){
1057                 ($msg, $msg_hash, $module) = &input_from_known_client($next_msg, $heap->{'remote_ip'}, $session_id);
1058         }
1059         # an error occurred
1060         if(( !$msg ) || ( !$msg_hash ) || ( !$module )){
1061                 # if an incoming msg could not be decrypted (maybe a wrong key), send client a ping. If the client
1062                 # could not understand a msg from its server the client cause a re-registering process
1063                 daemon_log("$session_id WARNING cannot understand incoming msg, send 'ping'-msg to all host with ip '".$heap->{remote_ip}.
1064                         "' to cause a re-registering of the client if necessary", 3);
1065                 my $sql_statement = "SELECT * FROM $main::known_clients_tn WHERE (hostname LIKE '".$heap->{'remote_ip'}."%')";
1066                 my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
1067                 while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1068                         my $host_name = $hit->{'hostname'};
1069                         my $host_key = $hit->{'hostkey'};
1070                         my $ping_msg = "<xml> <header>gosa_ping</header> <source>$server_address</source> <target>$host_name</target></xml>";
1071                         my $error = &send_msg_to_target($ping_msg, $host_name, $host_key, "gosa_ping", $session_id);
1072                         &update_jobdb_status_for_send_msgs($ping_msg, $error);
1073                 }
1074                 $error++;
1075         }
1078         my $header;
1079         my $target;
1080         my $source;
1081         my $done = 0;
1082         my $sql;
1083         my $res;
1085         # check whether this message should be processed here
1086         if ($error == 0) {
1087                 $header = @{$msg_hash->{'header'}}[0];
1088                 $target = @{$msg_hash->{'target'}}[0];
1089                 $source = @{$msg_hash->{'source'}}[0];
1090                 my $not_found_in_known_clients_db = 0;
1091                 my $not_found_in_known_server_db = 0;
1092                 my $not_found_in_foreign_clients_db = 0;
1093                 my $local_address;
1094                 my $local_mac;
1095                 my ($target_ip, $target_port) = split(':', $target);
1097                 # Determine the local ip address if target is an ip address
1098                 if ($target =~ /^\d+\.\d+\.\d+\.\d+:\d+$/) {
1099                         $local_address = &get_local_ip_for_remote_ip($target_ip).":$server_port";
1100                 } else {
1101                         $local_address = $server_address;
1102                 }
1104                 # Determine the local mac address if target is a mac address
1105                 if ($target =~ /^([0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2})$/i) {
1106                         my $loc_ip = &get_local_ip_for_remote_ip($heap->{'remote_ip'});
1107                         my $network_interface= &get_interface_for_ip($loc_ip);
1108                         $local_mac = &get_mac_for_interface($network_interface);
1109                 } else {
1110                         $local_mac = $server_mac_address;
1111                 }
1113                 # target and source is equal to GOSA -> process here
1114                 if (not $done) {
1115                         if ($target eq "GOSA" && $source eq "GOSA") {
1116                                 $done = 1;                    
1117                                 &daemon_log("$session_id DEBUG: target and source is 'GOSA' -> process here", 7);
1118                         }
1119                 }
1121                 # target is own address without forward_to_gosa-tag -> process here
1122                 if (not $done) {
1123                         #if ((($target eq $local_address) || ($target eq $local_mac) ) && (not exists $msg_hash->{'forward_to_gosa'})) {
1124                         if (($target eq $local_address) && (not exists $msg_hash->{'forward_to_gosa'})) {
1125                                 $done = 1;
1126                                 if ($source eq "GOSA") {
1127                                         $msg =~ s/<\/xml>/<forward_to_gosa>$local_address,$session_id<\/forward_to_gosa><\/xml>/;
1128                                 }
1129                                 &daemon_log("$session_id DEBUG: target is own address without forward_to_gosa-tag -> process here", 7);
1130                         }
1131                 }
1133                 # target is a client address in known_clients -> process here
1134                 if (not $done) {
1135                         $sql = "SELECT * FROM $known_clients_tn WHERE (hostname='$target' OR macaddress LIKE '$target')"; 
1136                         $res = $known_clients_db->select_dbentry($sql);
1137                         if (keys(%$res) > 0) {
1138                                 $done = 1; 
1139                                 my $hostname = $res->{1}->{'hostname'};
1140                                 $msg =~ s/<target>$target<\/target>/<target>$hostname<\/target>/;
1141                                 my $local_address = &get_local_ip_for_remote_ip($target_ip).":$server_port";
1142                                 if ($source eq "GOSA") {
1143                                         $msg =~ s/<\/xml>/<forward_to_gosa>$local_address,$session_id<\/forward_to_gosa><\/xml>/;
1144                                 }
1145                                 &daemon_log("$session_id DEBUG: target is a client address in known_clients -> process here", 7);
1147                         } else {
1148                                 $not_found_in_known_clients_db = 1;
1149                         }
1150                 }
1152                 # target ist own address with forward_to_gosa-tag not pointing to myself -> process here
1153                 if (not $done) {
1154                         my $forward_to_gosa =  @{$msg_hash->{'forward_to_gosa'}}[0];
1155                         my $gosa_at;
1156                         my $gosa_session_id;
1157                         if (($target eq $local_address) && (defined $forward_to_gosa)){
1158                                 my ($gosa_at, $gosa_session_id) = split(/,/, $forward_to_gosa);
1159                                 if ($gosa_at ne $local_address) {
1160                                         $done = 1;
1161                                         &daemon_log("$session_id DEBUG: target is own address with forward_to_gosa-tag not pointing to myself -> process here", 7); 
1162                                 }
1163                         }
1164                 }
1166                 # if message should be processed here -> add message to incoming_db
1167                 if ($done) {
1168                         # if a job or a gosa message comes from a foreign server, fake module to GosaPackages
1169                         # so gosa-si-server knows how to process this kind of messages
1170                         if ($header =~ /^gosa_/ || $header =~ /^job_/) {
1171                                 $module = "GosaPackages";
1172                         }
1174                         my $res = $incoming_db->add_dbentry( {table=>$incoming_tn,
1175                                         primkey=>[],
1176                                         headertag=>$header,
1177                                         targettag=>$target,
1178                                         xmlmessage=>&encode_base64($msg),
1179                                         timestamp=>&get_time,
1180                                         module=>$module,
1181                                         sessionid=>$session_id,
1182                                 } );
1184                 }
1186                 # target is own address with forward_to_gosa-tag pointing at myself -> forward to gosa
1187                 if (not $done) {
1188                         my $forward_to_gosa =  @{$msg_hash->{'forward_to_gosa'}}[0];
1189                         my $gosa_at;
1190                         my $gosa_session_id;
1191                         if (($target eq $local_address) && (defined $forward_to_gosa)){
1192                                 my ($gosa_at, $gosa_session_id) = split(/,/, $forward_to_gosa);
1193                                 if ($gosa_at eq $local_address) {
1194                                         my $session_reference = $kernel->ID_id_to_session($gosa_session_id);
1195                                         if( defined $session_reference ) {
1196                                                 $heap = $session_reference->get_heap();
1197                                         }
1198                                         if(exists $heap->{'client'}) {
1199                                                 $msg = &encrypt_msg($msg, $GosaPackages_key);
1200                                                 $heap->{'client'}->put($msg);
1201                                                 &daemon_log("$session_id INFO: incoming '$header' message forwarded to GOsa", 5); 
1202                                         }
1203                                         $done = 1;
1204                                         &daemon_log("$session_id DEBUG: target is own address with forward_to_gosa-tag pointing at myself -> forward to gosa", 7);
1205                                 }
1206                         }
1208                 }
1210                 # target is a client address in foreign_clients -> forward to registration server
1211                 if (not $done) {
1212                         $sql = "SELECT * FROM $foreign_clients_tn WHERE (hostname='$target' OR macaddress LIKE '$target')";
1213                         $res = $foreign_clients_db->select_dbentry($sql);
1214                         if (keys(%$res) > 0) {
1215                                 my $hostname = $res->{1}->{'hostname'};
1216                                 my ($host_ip, $host_port) = split(/:/, $hostname);
1217                                 my $local_address =  &get_local_ip_for_remote_ip($host_ip).":$server_port";
1218                                 my $regserver = $res->{1}->{'regserver'};
1219                                 my $sql = "SELECT * FROM $known_server_tn WHERE hostname='$regserver'"; 
1220                                 my $res = $known_server_db->select_dbentry($sql);
1221                                 if (keys(%$res) > 0) {
1222                                         my $regserver_key = $res->{1}->{'hostkey'};
1223                                         $msg =~ s/<source>GOSA<\/source>/<source>$local_address<\/source>/;
1224                                         $msg =~ s/<target>$target<\/target>/<target>$hostname<\/target>/;
1225                                         if ($source eq "GOSA") {
1226                                                 $msg =~ s/<\/xml>/<forward_to_gosa>$local_address,$session_id<\/forward_to_gosa><\/xml>/;
1227                                         }
1228                                         &send_msg_to_target($msg, $regserver, $regserver_key, $header, $session_id);
1229                                 }
1230                                 $done = 1;
1231                                 &daemon_log("$session_id DEBUG: target is a client address in foreign_clients -> forward to registration server", 7);
1232                         } else {
1233                                 $not_found_in_foreign_clients_db = 1;
1234                         }
1235                 }
1237                 # target is a server address -> forward to server
1238                 if (not $done) {
1239                         $sql = "SELECT * FROM $known_server_tn WHERE (hostname='$target' OR macaddress LIKE '$target')";
1240                         $res = $known_server_db->select_dbentry($sql);
1241                         if (keys(%$res) > 0) {
1242                                 my $hostkey = $res->{1}->{'hostkey'};
1244                                 if ($source eq "GOSA") {
1245                                         $msg =~ s/<source>GOSA<\/source>/<source>$local_address<\/source>/;
1246                                         $msg =~ s/<\/xml>/<forward_to_gosa>$local_address,$session_id<\/forward_to_gosa><\/xml>/;
1248                                 }
1250                                 &send_msg_to_target($msg, $target, $hostkey, $header, $session_id);
1251                                 $done = 1;
1252                                 &daemon_log("$session_id DEBUG: target is a server address -> forward to server", 7);
1253                         } else {
1254                                 $not_found_in_known_server_db = 1;
1255                         }
1256                 }
1259                 # target is not in foreign_clients_db, known_server_db or known_clients_db, maybe it is a complete new one -> process here
1260                 if ( $not_found_in_foreign_clients_db 
1261                         && $not_found_in_known_server_db
1262                         && $not_found_in_known_clients_db) {
1263                         &daemon_log("$session_id DEBUG: target is not in foreign_clients_db, known_server_db or known_clients_db, maybe it is a complete new one -> process here", 7);
1264                         my $res = $incoming_db->add_dbentry( {table=>$incoming_tn,
1265                                         primkey=>[],
1266                                         headertag=>$header,
1267                                         targettag=>$target,
1268                                         xmlmessage=>&encode_base64($msg),
1269                                         timestamp=>&get_time,
1270                                         module=>$module,
1271                                         sessionid=>$session_id,
1272                                 } );
1273                         $done = 1;
1274                 }
1277                 if (not $done) {
1278                         daemon_log("$session_id ERROR: do not know what to do with this message: $msg", 1);
1279                         if ($source eq "GOSA") {
1280                                 my %data = ('error_msg' => &encode_base64($msg), 'error_string' => "Do not know what to do with this message!");
1281                                 my $error_msg = &build_msg("error", $local_address, "GOSA", \%data ); 
1283                                 my $session_reference = $kernel->ID_id_to_session($session_id);
1284                                 if( defined $session_reference ) {
1285                                         $heap = $session_reference->get_heap();
1286                                 }
1287                                 if(exists $heap->{'client'}) {
1288                                         $error_msg = &encrypt_msg($error_msg, $GosaPackages_key);
1289                                         $heap->{'client'}->put($error_msg);
1290                                 }
1291                         }
1292                 }
1294         }
1296         return;
1300 sub next_task {
1301     my ($session, $heap, $task) = @_[SESSION, HEAP, ARG0];
1302     my $running_task = POE::Wheel::Run->new(
1303             Program => sub { process_task($session, $heap, $task) },
1304             StdioFilter => POE::Filter::Reference->new(),
1305             StdoutEvent  => "task_result",
1306             StderrEvent  => "task_debug",
1307             CloseEvent   => "task_done",
1308             );
1309     $heap->{task}->{ $running_task->ID } = $running_task;
1312 sub handle_task_result {
1313     my ($kernel, $heap, $result) = @_[KERNEL, HEAP, ARG0];
1314     my $client_answer = $result->{'answer'};
1315     if( $client_answer =~ s/session_id=(\d+)$// ) {
1316         my $session_id = $1;
1317         if( defined $session_id ) {
1318             my $session_reference = $kernel->ID_id_to_session($session_id);
1319             if( defined $session_reference ) {
1320                 $heap = $session_reference->get_heap();
1321             }
1322         }
1324         if(exists $heap->{'client'}) {
1325             $heap->{'client'}->put($client_answer);
1326         }
1327     }
1328     $kernel->sig(CHLD => "child_reap");
1331 sub handle_task_debug {
1332     my $result = $_[ARG0];
1333     print STDERR "$result\n";
1336 sub handle_task_done {
1337     my ( $kernel, $heap, $task_id ) = @_[ KERNEL, HEAP, ARG0 ];
1338     delete $heap->{task}->{$task_id};
1341 sub process_task {
1342     no strict "refs";
1343     #CHECK: Not @_[...]?
1344     my ($session, $heap, $task) = @_;
1345     my $error = 0;
1346     my $answer_l;
1347     my ($answer_header, @answer_target_l, $answer_source);
1348     my $client_answer = "";
1350     # prepare all variables needed to process message
1351     #my $msg = $task->{'xmlmessage'};
1352     my $msg = &decode_base64($task->{'xmlmessage'});
1353     my $incoming_id = $task->{'id'};
1354     my $module = $task->{'module'};
1355     my $header =  $task->{'headertag'};
1356     my $session_id = $task->{'sessionid'};
1357                 my $msg_hash;
1358                 eval {
1359         $msg_hash = $xml->XMLin($msg, ForceArray=>1);
1360                 }; 
1361                 daemon_log("ERROR: XML failure '$@'") if ($@);
1362     my $source = @{$msg_hash->{'source'}}[0];
1363     
1364     # set timestamp of incoming client uptodate, so client will not 
1365     # be deleted from known_clients because of expiration
1366     my $act_time = &get_time();
1367     my $sql = "UPDATE $known_clients_tn SET timestamp='$act_time' WHERE hostname='$source'"; 
1368     my $res = $known_clients_db->exec_statement($sql);
1370     ######################
1371     # process incoming msg
1372     if( $error == 0) {
1373         daemon_log("$session_id INFO: Incoming msg (session_id=$session_id) with header '".@{$msg_hash->{'header'}}[0]."'", 5); 
1374         daemon_log("$session_id DEBUG: Processing module ".$module, 7);
1375         $answer_l = &{ $module."::process_incoming_msg" }($msg, $msg_hash, $session_id);
1377         if ( 0 < @{$answer_l} ) {
1378             my $answer_str = join("\n", @{$answer_l});
1379             while ($answer_str =~ /<header>(\w+)<\/header>/g) {
1380                 daemon_log("$session_id INFO: got answer message with header '$1'", 5);
1381             }
1382             daemon_log("$session_id DEBUG: $module: got answer from module: \n".$answer_str,9);
1383         } else {
1384             daemon_log("$session_id DEBUG: $module: got no answer from module!" ,7);
1385         }
1387     }
1388     if( !$answer_l ) { $error++ };
1390     ########
1391     # answer
1392     if( $error == 0 ) {
1394         foreach my $answer ( @{$answer_l} ) {
1395             # check outgoing msg to xml validity
1396             my $answer_hash = &check_outgoing_xml_validity($answer, $session_id);
1397             if( not defined $answer_hash ) { next; }
1398             
1399             $answer_header = @{$answer_hash->{'header'}}[0];
1400             @answer_target_l = @{$answer_hash->{'target'}};
1401             $answer_source = @{$answer_hash->{'source'}}[0];
1403             # deliver msg to all targets 
1404             foreach my $answer_target ( @answer_target_l ) {
1406                 # targets of msg are all gosa-si-clients in known_clients_db
1407                 if( $answer_target eq "*" ) {
1408                     # answer is for all clients
1409                     my $sql_statement= "SELECT * FROM known_clients";
1410                     my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
1411                     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1412                         my $host_name = $hit->{hostname};
1413                         my $host_key = $hit->{hostkey};
1414                         my $error = &send_msg_to_target($answer, $host_name, $host_key, $answer_header, $session_id);
1415                         &update_jobdb_status_for_send_msgs($answer, $error);
1416                     }
1417                 }
1419                 # targets of msg are all gosa-si-server in known_server_db
1420                 elsif( $answer_target eq "KNOWN_SERVER" ) {
1421                     # answer is for all server in known_server
1422                     my $sql_statement= "SELECT * FROM $known_server_tn";
1423                     my $query_res = $known_server_db->select_dbentry( $sql_statement ); 
1424                     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1425                         my $host_name = $hit->{hostname};
1426                         my $host_key = $hit->{hostkey};
1427                         $answer =~ s/<target>\S+<\/target>/<target>$host_name<\/target>/g;
1428                         my $error = &send_msg_to_target($answer, $host_name, $host_key, $answer_header, $session_id);
1429                         &update_jobdb_status_for_send_msgs($answer, $error);
1430                     }
1431                 }
1433                 # target of msg is GOsa
1434                                 elsif( $answer_target eq "GOSA" ) {
1435                                         my $session_id = ($1) if $answer =~ /<session_id>(\d+?)<\/session_id>/;
1436                                         my $add_on = "";
1437                     if( defined $session_id ) {
1438                         $add_on = ".session_id=$session_id";
1439                     }
1440                     # answer is for GOSA and has to returned to connected client
1441                     my $gosa_answer = &encrypt_msg($answer, $GosaPackages_key);
1442                     $client_answer = $gosa_answer.$add_on;
1443                 }
1445                 # target of msg is job queue at this host
1446                 elsif( $answer_target eq "JOBDB") {
1447                     $answer =~ /<header>(\S+)<\/header>/;   
1448                     my $header;
1449                     if( defined $1 ) { $header = $1; }
1450                     my $error = &send_msg_to_target($answer, $server_address, $GosaPackages_key, $header, $session_id);
1451                     &update_jobdb_status_for_send_msgs($answer, $error);
1452                 }
1454                 # Target of msg is a mac address
1455                 elsif( $answer_target =~ /^([0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2})$/i ) {
1456                     daemon_log("$session_id INFO: target is mac address '$answer_target', looking for host in known_clients and foreign_clients", 5);
1457                     my $sql_statement = "SELECT * FROM known_clients WHERE macaddress LIKE '$answer_target'";
1458                     my $query_res = $known_clients_db->select_dbentry( $sql_statement );
1459                     my $found_ip_flag = 0;
1460                     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1461                         my $host_name = $hit->{hostname};
1462                         my $host_key = $hit->{hostkey};
1463                         $answer =~ s/$answer_target/$host_name/g;
1464                         daemon_log("$session_id INFO: found host '$host_name', associated to '$answer_target'", 5);
1465                         my $error = &send_msg_to_target($answer, $host_name, $host_key, $answer_header, $session_id);
1466                         &update_jobdb_status_for_send_msgs($answer, $error);
1467                         $found_ip_flag++ ;
1468                     }   
1469                     if ($found_ip_flag == 0) {
1470                         my $sql = "SELECT * FROM $foreign_clients_tn WHERE macaddress LIKE '$answer_target'";
1471                         my $res = $foreign_clients_db->select_dbentry($sql);
1472                         while( my ($hit_num, $hit) = each %{ $res } ) {
1473                             my $host_name = $hit->{hostname};
1474                             my $reg_server = $hit->{regserver};
1475                             daemon_log("$session_id INFO: found host '$host_name' with mac '$answer_target', registered at '$reg_server'", 5);
1476                             
1477                             # Fetch key for reg_server
1478                             my $reg_server_key;
1479                             my $sql = "SELECT * FROM $known_server_tn WHERE hostname='$reg_server'";
1480                             my $res = $known_server_db->select_dbentry($sql);
1481                             if (exists $res->{1}) {
1482                                 $reg_server_key = $res->{1}->{'hostkey'}; 
1483                             } else {
1484                                 daemon_log("$session_id ERROR: cannot find hostkey for '$host_name' in '$known_server_tn'", 1); 
1485                                 daemon_log("$session_id ERROR: unable to forward answer to correct registration server, processing is aborted!", 1); 
1486                                 $reg_server_key = undef;
1487                             }
1489                             # Send answer to server where client is registered
1490                             if (defined $reg_server_key) {
1491                                 $answer =~ s/$answer_target/$host_name/g;
1492                                 my $error = &send_msg_to_target($answer, $reg_server, $reg_server_key, $answer_header, $session_id);
1493                                 &update_jobdb_status_for_send_msgs($answer, $error);
1494                                 $found_ip_flag++ ;
1495                             }
1496                         }
1497                     }
1498                     if( $found_ip_flag == 0) {
1499                         daemon_log("$session_id WARNING: no host found in known_clients with mac address '$answer_target'", 3);
1500                     }
1502                 # Answer is for one specific host   
1503                 } else {
1504                     # get encrypt_key
1505                     my $encrypt_key = &get_encrypt_key($answer_target);
1506                     if( not defined $encrypt_key ) {
1507                         # unknown target
1508                         daemon_log("$session_id WARNING: unknown target '$answer_target'", 3);
1509                         next;
1510                     }
1511                     my $error = &send_msg_to_target($answer, $answer_target, $encrypt_key, $answer_header,$session_id);
1512                     &update_jobdb_status_for_send_msgs($answer, $error);
1513                 }
1514             }
1515         }
1516     }
1518     my $filter = POE::Filter::Reference->new();
1519     my %result = ( 
1520             status => "seems ok to me",
1521             answer => $client_answer,
1522             );
1524     my $output = $filter->put( [ \%result ] );
1525     print @$output;
1530 sub session_start {
1531     my ($kernel) = $_[KERNEL];
1532     $global_kernel = $kernel;
1533     $kernel->yield('register_at_foreign_servers');
1534         $kernel->yield('create_fai_server_db', $fai_server_tn );
1535         $kernel->yield('create_fai_release_db', $fai_release_tn );
1536     $kernel->yield('watch_for_next_tasks');
1537         $kernel->sig(USR1 => "sig_handler");
1538         $kernel->sig(USR2 => "recreate_packages_db");
1539         $kernel->delay_set('watch_for_new_jobs', $job_queue_loop_delay);
1540         $kernel->delay_set('watch_for_done_jobs', $job_queue_loop_delay); 
1541     $kernel->delay_set('watch_for_modified_jobs', $modified_jobs_loop_delay); 
1542         $kernel->delay_set('watch_for_new_messages', $messaging_db_loop_delay);
1543     $kernel->delay_set('watch_for_delivery_messages', $messaging_db_loop_delay);
1544         $kernel->delay_set('watch_for_done_messages', $messaging_db_loop_delay);
1545     $kernel->delay_set('watch_for_old_known_clients', $job_queue_loop_delay);
1547     # Start opsi check
1548     if ($opsi_enabled eq "true") {
1549         $kernel->delay_set('watch_for_opsi_jobs', $job_queue_opsi_delay); 
1550     }
1555 sub watch_for_done_jobs {
1556     #CHECK: $heap for what?
1557     my ($kernel,$heap) = @_[KERNEL, HEAP];
1559     my $sql_statement = "SELECT * FROM ".$job_queue_tn." WHERE ((status='done') AND (modified='0'))";
1560         my $res = $job_db->select_dbentry( $sql_statement );
1562     while( my ($id, $hit) = each %{$res} ) {
1563         my $jobdb_id = $hit->{id};
1564         my $sql_statement = "DELETE FROM $job_queue_tn WHERE id=$jobdb_id"; 
1565         my $res = $job_db->del_dbentry($sql_statement); 
1566     }
1568     $kernel->delay_set('watch_for_done_jobs',$job_queue_loop_delay);
1572 sub watch_for_opsi_jobs {
1573     my ($kernel) = $_[KERNEL];
1575     # This is not very nice to look for opsi install jobs, but headertag has to be trigger_action_reinstall. The only way to identify a 
1576     # opsi install job is to parse the xml message. There is still the correct header.
1577     my $sql_statement = "SELECT * FROM ".$job_queue_tn." WHERE ((xmlmessage LIKE '%opsi_install_client</header>%') AND (status='processing') AND (siserver='localhost'))";
1578         my $res = $job_db->select_dbentry( $sql_statement );
1580     # Ask OPSI for an update of the running jobs
1581     while (my ($id, $hit) = each %$res ) {
1582         # Determine current parameters of the job
1583         my $hostId = $hit->{'plainname'};
1584         my $macaddress = $hit->{'macaddress'};
1585         my $progress = $hit->{'progress'};
1587         my $result= {};
1588         
1589         # For hosts, only return the products that are or get installed
1590         my $callobj;
1591         $callobj = {
1592             method  => 'getProductStates_hash',
1593             params  => [ $hostId ],
1594             id  => 1,
1595         };
1596         
1597         my $hres = $opsi_client->call($opsi_url, $callobj);
1598         #my ($hres_err, $hres_err_string) = &check_opsi_res($hres);
1599         if (not &check_opsi_res($hres)) {
1600             my $htmp= $hres->result->{$hostId};
1601         
1602             # Check state != not_installed or action == setup -> load and add
1603             my $products= 0;
1604             my $installed= 0;
1605             my $installing = 0;
1606             my $error= 0;  
1607             my @installed_list;
1608             my @error_list;
1609             my $act_status = "none";
1610             foreach my $product (@{$htmp}){
1612                 if ($product->{'installationStatus'} ne "not_installed" or
1613                         $product->{'actionRequest'} eq "setup"){
1615                     # Increase number of products for this host
1616                     $products++;
1617         
1618                     if ($product->{'installationStatus'} eq "failed"){
1619                         $result->{$product->{'productId'}}= "error";
1620                         unshift(@error_list, $product->{'productId'});
1621                         $error++;
1622                     }
1623                     if ($product->{'installationStatus'} eq "installed" && $product->{'actionRequest'}  eq "none"){
1624                         $result->{$product->{'productId'}}= "installed";
1625                         unshift(@installed_list, $product->{'productId'});
1626                         $installed++;
1627                     }
1628                     if ($product->{'installationStatus'} eq "installing"){
1629                         $result->{$product->{'productId'}}= "installing";
1630                         $installing++;
1631                         $act_status = "installing - ".$product->{'productId'};
1632                     }
1633                 }
1634             }
1635         
1636             # Estimate "rough" progress, avoid division by zero
1637             if ($products == 0) {
1638                 $result->{'progress'}= 0;
1639             } else {
1640                 $result->{'progress'}= int($installed * 100 / $products);
1641             }
1643             # Set updates in job queue
1644             if ((not $error) && (not $installing) && ($installed)) {
1645                 $act_status = "installed - ".join(", ", @installed_list);
1646             }
1647             if ($error) {
1648                 $act_status = "error - ".join(", ", @error_list);
1649             }
1650             if ($progress ne $result->{'progress'} ) {
1651                 # Updating progress and result 
1652                 my $update_statement = "UPDATE $job_queue_tn SET modified='1', progress='".$result->{'progress'}."', result='$act_status' WHERE macaddress='$macaddress' AND siserver='localhost'";
1653                 my $update_res = $job_db->update_dbentry($update_statement);
1654             }
1655             if ($progress eq 100) { 
1656                 # Updateing status
1657                 my $done_statement = "UPDATE $job_queue_tn SET modified='1', ";
1658                 if ($error) {
1659                     $done_statement .= "status='error'";
1660                 } else {
1661                     $done_statement .= "status='done'";
1662                 }
1663                 $done_statement .= " WHERE macaddress='$macaddress' AND siserver='localhost'";
1664                 my $done_res = $job_db->update_dbentry($done_statement);
1665             }
1668         }
1669     }
1671     $kernel->delay_set('watch_for_opsi_jobs', $job_queue_opsi_delay);
1675 # If a job got an update or was modified anyway, send to all other si-server an update message of this jobs.
1676 sub watch_for_modified_jobs {
1677     my ($kernel,$heap) = @_[KERNEL, HEAP];
1679     my $sql_statement = "SELECT * FROM $job_queue_tn WHERE ((siserver='localhost') AND (modified='1'))"; 
1680     my $res = $job_db->select_dbentry( $sql_statement );
1681     
1682     # if db contains no jobs which should be update, do nothing
1683     if (keys %$res != 0) {
1685         if ($job_synchronization  eq "true") {
1686             # make out of the db result a gosa-si message   
1687             my $update_msg = &db_res2si_msg ($res, "foreign_job_updates", "KNOWN_SERVER", "MY_LOCAL_ADDRESS");
1688  
1689             # update all other SI-server
1690             &inform_all_other_si_server($update_msg);
1691         }
1693         # set jobs all jobs to modified = 0, wait until the next modification for updates of other si-server
1694         $sql_statement = "UPDATE $job_queue_tn SET modified='0' ";
1695         $res = $job_db->update_dbentry($sql_statement);
1696     }
1698     $kernel->delay_set('watch_for_modified_jobs', $modified_jobs_loop_delay);
1702 sub watch_for_new_jobs {
1703         if($watch_for_new_jobs_in_progress == 0) {
1704                 $watch_for_new_jobs_in_progress = 1;
1705                 my ($kernel,$heap) = @_[KERNEL, HEAP];
1707                 # check gosa job quaeue for jobs with executable timestamp
1708                 my $timestamp = &get_time();
1709                 my $sql_statement = "SELECT * FROM $job_queue_tn WHERE status='waiting' AND (CAST(timestamp AS UNSIGNED)) < $timestamp ORDER BY timestamp";
1710                 my $res = $job_db->exec_statement( $sql_statement );
1712                 # Merge all new jobs that would do the same actions
1713                 my @drops;
1714                 my $hits;
1715                 foreach my $hit (reverse @{$res} ) {
1716                         my $macaddress= lc @{$hit}[8];
1717                         my $headertag= @{$hit}[5];
1718                         if(
1719                                 defined($hits->{$macaddress}) &&
1720                                 defined($hits->{$macaddress}->{$headertag}) &&
1721                                 defined($hits->{$macaddress}->{$headertag}[0])
1722                         ) {
1723                                 push @drops, "DELETE FROM $job_queue_tn WHERE id = $hits->{$macaddress}->{$headertag}[0]";
1724                         }
1725                         $hits->{$macaddress}->{$headertag}= $hit;
1726                 }
1728                 # Delete new jobs with a matching job in state 'processing'
1729                 foreach my $macaddress (keys %{$hits}) {
1730                         foreach my $jobdb_headertag (keys %{$hits->{$macaddress}}) {
1731                                 my $jobdb_id = @{$hits->{$macaddress}->{$jobdb_headertag}}[0];
1732                                 if(defined($jobdb_id)) {
1733                                         my $sql_statement = "SELECT * FROM $job_queue_tn WHERE macaddress LIKE '$macaddress' AND headertag='$jobdb_headertag' AND status='processing'";
1734                                         my $res = $job_db->exec_statement( $sql_statement );
1735                                         foreach my $hit (@{$res}) {
1736                                                 push @drops, "DELETE FROM $job_queue_tn WHERE id=$jobdb_id";
1737                                         }
1738                                 } else {
1739                                         daemon_log("J ERROR: Job without id exists for macaddress $macaddress!", 1);
1740                                 }
1741                         }
1742                 }
1744                 # Commit deletion
1745                 $job_db->exec_statementlist(\@drops);
1747                 # Look for new jobs that could be executed
1748                 foreach my $macaddress (keys %{$hits}) {
1750                         # Look if there is an executing job
1751                         my $sql_statement = "SELECT * FROM $job_queue_tn WHERE macaddress LIKE '$macaddress' AND status='processing'";
1752                         my $res = $job_db->exec_statement( $sql_statement );
1754                         # Skip new jobs for host if there is a processing job
1755                         if(defined($res) and defined @{$res}[0]) {
1756                                 # Prevent race condition if there is a trigger_activate job waiting and a goto-activation job processing
1757                                 my $row = @{$res}[0] if (ref $res eq 'ARRAY');
1758                                 if(@{$row}[5] eq 'trigger_action_reinstall') {
1759                                         my $sql_statement_2 =  "SELECT * FROM $job_queue_tn WHERE macaddress LIKE '$macaddress' AND status='waiting' AND headertag = 'trigger_activate_new'"; 
1760                                         my $res_2 = $job_db->exec_statement( $sql_statement_2 );
1761                                         if(defined($res_2) and defined @{$res_2}[0]) {
1762                                                 # Set status from goto-activation to 'waiting' and update timestamp
1763                                                 $job_db->exec_statement("UPDATE $job_queue_tn SET status='waiting' WHERE macaddress LIKE '$macaddress' AND headertag = 'trigger_action_reinstall'");
1764                                                 $job_db->exec_statement("UPDATE $job_queue_tn SET timestamp='".&get_time(30)."' WHERE macaddress LIKE '$macaddress' AND headertag = 'trigger_action_reinstall'");
1765                                         }
1766                                 }
1767                                 next;
1768                         }
1770                         foreach my $jobdb_headertag (keys %{$hits->{$macaddress}}) {
1771                                 my $jobdb_id = @{$hits->{$macaddress}->{$jobdb_headertag}}[0];
1772                                 if(defined($jobdb_id)) {
1773                                         my $job_msg = @{$hits->{$macaddress}->{$jobdb_headertag}}[7];
1775                                         daemon_log("J DEBUG: its time to execute $job_msg", 7);
1776                                         my $sql_statement = "SELECT * FROM known_clients WHERE macaddress LIKE '$macaddress'";
1777                                         my $res_hash = $known_clients_db->select_dbentry( $sql_statement );
1779                                         # expect macaddress is unique!!!!!!
1780                                         my $target = $res_hash->{1}->{hostname};
1782                                         # change header
1783                                         $job_msg =~ s/<header>job_/<header>gosa_/;
1785                                         # add sqlite_id
1786                                         $job_msg =~ s/<\/xml>$/<jobdb_id>$jobdb_id<\/jobdb_id><\/xml>/;
1788                                         $job_msg =~ /<header>(\S+)<\/header>/;
1789                                         my $header = $1 ;
1790                                         my $func_error = &send_msg_to_target($job_msg, $server_address, $GosaPackages_key, $header, "J");
1792                                         # update status in job queue to 'processing'
1793                                         $sql_statement = "UPDATE $job_queue_tn SET status='processing' WHERE id=$jobdb_id";
1794                                         my $res = $job_db->update_dbentry($sql_statement);
1795 # TODO: abfangen ob alles in ordnung ist oder nicht, wenn nicht error schmeißen                                        
1797                                         # We don't want parallel processing
1798                                         last;
1799                                 }
1800                         }
1801                 }
1803                 $watch_for_new_jobs_in_progress = 0;
1804                 $kernel->delay_set('watch_for_new_jobs', $job_queue_loop_delay);
1805         }
1809 sub watch_for_new_messages {
1810     my ($kernel,$heap) = @_[KERNEL, HEAP];
1811     my @coll_user_msg;   # collection list of outgoing messages
1812     
1813     # check messaging_db for new incoming messages with executable timestamp
1814     my $timestamp = &get_time();
1815     my $sql_statement = "SELECT * FROM $messaging_tn WHERE ( (CAST(timestamp AS UNSIGNED))<$timestamp AND flag='n' AND direction='in' )";
1816     my $res = $messaging_db->exec_statement( $sql_statement );
1817         foreach my $hit (@{$res}) {
1819         # create outgoing messages
1820         my $message_to = @{$hit}[3];
1821         # translate message_to to plain login name
1822         my @message_to_l = split(/,/, $message_to);  
1823                 my %receiver_h; 
1824                 foreach my $receiver (@message_to_l) {
1825                         if ($receiver =~ /^u_([\s\S]*)$/) {
1826                                 $receiver_h{$1} = 0;
1827                         } elsif ($receiver =~ /^g_([\s\S]*)$/) {
1828                                 my $group_name = $1;
1829                                 # fetch all group members from ldap and add them to receiver hash
1830                                 my $ldap_handle = &get_ldap_handle();
1831                                 if (defined $ldap_handle) {
1832                                                 my $mesg = $ldap_handle->search(
1833                                                                                 base => $ldap_base,
1834                                                                                 scope => 'sub',
1835                                                                                 attrs => ['memberUid'],
1836                                                                                 filter => "cn=$group_name",
1837                                                                                 );
1838                                                 if ($mesg->count) {
1839                                                                 my @entries = $mesg->entries;
1840                                                                 foreach my $entry (@entries) {
1841                                                                                 my @receivers= $entry->get_value("memberUid");
1842                                                                                 foreach my $receiver (@receivers) { 
1843                                                                                                 $receiver_h{$1} = 0;
1844                                                                                 }
1845                                                                 }
1846                                                 } 
1847                                                 # translating errors ?
1848                                                 if ($mesg->code) {
1849                                                                 daemon_log("M ERROR: unable to translate group '$group_name' to user list for message delivery: $mesg->error", 1);
1850                                                 }
1851                                 # ldap handle error ?           
1852                                 } else {
1853                                         daemon_log("M ERROR: unable to translate group '$group_name' to user list for message delivery: no ldap handle available", 1);
1854                                 }
1855                         } else {
1856                                 my $sbjct = &encode_base64(@{$hit}[1]);
1857                                 my $msg = &encode_base64(@{$hit}[7]);
1858                                 &daemon_log("M WARNING: unknown receiver '$receiver' for a user-message '$sbjct - $msg'", 3); 
1859                         }
1860                 }
1861                 my @receiver_l = keys(%receiver_h);
1863         my $message_id = @{$hit}[0];
1865         #add each outgoing msg to messaging_db
1866         my $receiver;
1867         foreach $receiver (@receiver_l) {
1868             my $sql_statement = "INSERT INTO $messaging_tn (id, subject, message_from, message_to, flag, direction, delivery_time, message, timestamp) ".
1869                 "VALUES ('".
1870                 $message_id."', '".    # id
1871                 @{$hit}[1]."', '".     # subject
1872                 @{$hit}[2]."', '".     # message_from
1873                 $receiver."', '".      # message_to
1874                 "none"."', '".         # flag
1875                 "out"."', '".          # direction
1876                 @{$hit}[6]."', '".     # delivery_time
1877                 @{$hit}[7]."', '".     # message
1878                 $timestamp."'".     # timestamp
1879                 ")";
1880             &daemon_log("M DEBUG: $sql_statement", 1);
1881             my $res = $messaging_db->exec_statement($sql_statement);
1882             &daemon_log("M INFO: message '".@{$hit}[0]."' is prepared for delivery to receiver '$receiver'", 5);
1883         }
1885         # set incoming message to flag d=deliverd
1886         $sql_statement = "UPDATE $messaging_tn SET flag='p' WHERE id='$message_id'"; 
1887         &daemon_log("M DEBUG: $sql_statement", 7);
1888         $res = $messaging_db->update_dbentry($sql_statement);
1889         &daemon_log("M INFO: message '$message_id' is set to flag 'p' (processed)", 5);
1890     }
1892     $kernel->delay_set('watch_for_new_messages', $messaging_db_loop_delay); 
1893     return;
1896 sub watch_for_delivery_messages {
1897     my ($kernel, $heap) = @_[KERNEL, HEAP];
1899     # select outgoing messages
1900     my $sql_statement = "SELECT * FROM $messaging_tn WHERE ( flag='p' AND direction='out' )";
1901     #&daemon_log("0 DEBUG: $sql", 7);
1902     my $res = $messaging_db->exec_statement( $sql_statement );
1903     
1904     # build out msg for each    usr
1905     foreach my $hit (@{$res}) {
1906         my $receiver = @{$hit}[3];
1907         my $msg_id = @{$hit}[0];
1908         my $subject = @{$hit}[1];
1909         my $message = @{$hit}[7];
1911         # resolve usr -> host where usr is logged in
1912         my $sql = "SELECT * FROM $login_users_tn WHERE (user='$receiver')"; 
1913         #&daemon_log("0 DEBUG: $sql", 7);
1914         my $res = $login_users_db->exec_statement($sql);
1916         # reciver is logged in nowhere
1917         if (not ref(@$res[0]) eq "ARRAY") { next; }    
1919                 my $send_succeed = 0;
1920                 foreach my $hit (@$res) {
1921                                 my $receiver_host = @$hit[0];
1922                 my $delivered2host = 0;
1923                                 &daemon_log("M DEBUG: user '$receiver' is logged in at host '$receiver_host'", 7);
1925                                 # Looking for host in know_clients_db 
1926                                 my $sql = "SELECT * FROM $known_clients_tn WHERE (hostname='$receiver_host')";
1927                                 my $res = $known_clients_db->exec_statement($sql);
1929                 # Host is known in known_clients_db
1930                 if (ref(@$res[0]) eq "ARRAY") {
1931                     my $receiver_key = @{@{$res}[0]}[2];
1932                     my %data = ('subject' => $subject, 'message' => $message, 'usr' => $receiver);
1933                     my $out_msg = &build_msg("usr_msg", $server_address, $receiver_host, \%data ); 
1934                     my $error = &send_msg_to_target($out_msg, $receiver_host, $receiver_key, "usr_msg", 0); 
1935                     if ($error == 0 ) {
1936                         $send_succeed++ ;
1937                         $delivered2host++ ;
1938                         &daemon_log("M DEBUG: send message for user '$receiver' to host '$receiver_host'", 7); 
1939                     } else {
1940                         &daemon_log("M DEBUG: cannot send message for user '$receiver' to host '$receiver_host'", 7); 
1941                     }
1942                 }
1943                 
1944                 # Message already send, do not need to do anything more, otherwise ...
1945                 if ($delivered2host) { next;}
1946     
1947                 # ...looking for host in foreign_clients_db
1948                 $sql = "SELECT * FROM $foreign_clients_tn WHERE (hostname='$receiver_host')";
1949                 $res = $foreign_clients_db->exec_statement($sql);
1950   
1951                                 # Host is known in foreign_clients_db 
1952                                 if (ref(@$res[0]) eq "ARRAY") { 
1953                     my $registration_server = @{@{$res}[0]}[2];
1954                     
1955                     # Fetch encryption key for registration server
1956                     my $sql = "SELECT * FROM $known_server_tn WHERE (hostname='$registration_server')";
1957                     my $res = $known_server_db->exec_statement($sql);
1958                     if (ref(@$res[0]) eq "ARRAY") { 
1959                         my $registration_server_key = @{@{$res}[0]}[3];
1960                         my %data = ('subject' => $subject, 'message' => $message, 'usr' => $receiver);
1961                         my $out_msg = &build_msg("usr_msg", $server_address, $receiver_host, \%data ); 
1962                         my $error = &send_msg_to_target($out_msg, $registration_server, $registration_server_key, "usr_msg", 0); 
1963                         if ($error == 0 ) {
1964                             $send_succeed++ ;
1965                             $delivered2host++ ;
1966                             &daemon_log("M DEBUG: send message for user '$receiver' to server '$registration_server'", 7); 
1967                         } else {
1968                             &daemon_log("M ERROR: cannot send message for user '$receiver' to server '$registration_server'", 1); 
1969                         }
1971                     } else {
1972                         &daemon_log("M ERROR: host '$receiver_host' is reported to be ".
1973                                 "registrated at server '$registration_server', ".
1974                                 "but no data available in known_server_db ", 1); 
1975                     }
1976                 }
1977                 
1978                 if (not $delivered2host) {
1979                     &daemon_log("M ERROR: unable to send user message to host '$receiver_host'", 1);
1980                 }
1981                 }
1983                 if ($send_succeed) {
1984                                 # set outgoing msg at db to deliverd
1985                                 my $sql = "UPDATE $messaging_tn SET flag='d' WHERE (id='$msg_id' AND direction='out' AND message_to='$receiver')"; 
1986                                 my $res = $messaging_db->exec_statement($sql); 
1987                 &daemon_log("M INFO: send message for user '$receiver' to logged in hosts", 5);
1988                 } else {
1989             &daemon_log("M WARNING: failed to deliver message for user '$receiver'", 3); 
1990         }
1991         }
1993     $kernel->delay_set('watch_for_delivery_messages', $messaging_db_loop_delay); 
1994     return;
1998 sub watch_for_done_messages {
1999     my ($kernel,$heap) = @_[KERNEL, HEAP];
2001     my $sql = "SELECT * FROM $messaging_tn WHERE (flag='p' AND direction='in')"; 
2002     #&daemon_log("0 DEBUG: $sql", 7);
2003     my $res = $messaging_db->exec_statement($sql); 
2005     foreach my $hit (@{$res}) {
2006         my $msg_id = @{$hit}[0];
2008         my $sql = "SELECT * FROM $messaging_tn WHERE (id='$msg_id' AND direction='out' AND (NOT flag='s'))"; 
2009         #&daemon_log("0 DEBUG: $sql", 7); 
2010         my $res = $messaging_db->exec_statement($sql);
2012         # not all usr msgs have been seen till now
2013         if ( ref(@$res[0]) eq "ARRAY") { next; }
2014         
2015         $sql = "DELETE FROM $messaging_tn WHERE (id='$msg_id')"; 
2016         #&daemon_log("0 DEBUG: $sql", 7);
2017         $res = $messaging_db->exec_statement($sql);
2018     
2019     }
2021     $kernel->delay_set('watch_for_done_messages', $messaging_db_loop_delay); 
2022     return;
2026 sub watch_for_old_known_clients {
2027     my ($kernel,$heap) = @_[KERNEL, HEAP];
2029     my $sql_statement = "SELECT * FROM $known_clients_tn";
2030     my $res = $known_clients_db->select_dbentry( $sql_statement );
2032     my $act_time = int(&get_time());
2034     while ( my ($hit_num, $hit) = each %$res) {
2035         my $expired_timestamp = int($hit->{'timestamp'});
2036         $expired_timestamp =~ /(\d{4})(\d\d)(\d\d)(\d\d)(\d\d)(\d\d)/;
2037         my $dt = DateTime->new( year   => $1,
2038                 month  => $2,
2039                 day    => $3,
2040                 hour   => $4,
2041                 minute => $5,
2042                 second => $6,
2043                 );
2045         $dt->add( seconds => 2 * int($hit->{'keylifetime'}) );
2046         $expired_timestamp = $dt->ymd('').$dt->hms('');
2047         if ($act_time > $expired_timestamp) {
2048             my $hostname = $hit->{'hostname'};
2049             my $del_sql = "DELETE FROM $known_clients_tn WHERE hostname='$hostname'"; 
2050             my $del_res = $known_clients_db->exec_statement($del_sql);
2052             &main::daemon_log("0 INFO: timestamp '".$hit->{'timestamp'}."' of client '$hostname' is expired('$expired_timestamp'), client will be deleted from known_clients_db", 5);
2053         }
2055     }
2057     $kernel->delay_set('watch_for_old_known_clients', $job_queue_loop_delay);
2061 sub watch_for_next_tasks {
2062     my ($kernel,$heap) = @_[KERNEL, HEAP];
2064     my $sql = "SELECT * FROM $incoming_tn";
2065     my $res = $incoming_db->select_dbentry($sql);
2066     
2067     while ( my ($hit_num, $hit) = each %$res) {
2068         my $headertag = $hit->{'headertag'};
2069         if ($headertag =~ /^answer_(\d+)/) {
2070             # do not start processing, this message is for a still running POE::Wheel
2071             next;
2072         }
2073         my $message_id = $hit->{'id'};
2074         my $session_id = $hit->{'sessionid'};
2075         &daemon_log("$session_id DEBUG: start processing for message with incoming id: '$message_id'", 7);
2076         $kernel->yield('next_task', $hit);
2078         my $sql = "DELETE FROM $incoming_tn WHERE id=$message_id";
2079         my $res = $incoming_db->exec_statement($sql);
2080     }
2082     $kernel->delay_set('watch_for_next_tasks', 1); 
2086 sub get_ldap_handle {
2087         my ($session_id) = @_;
2088         my $heap;
2089         my $ldap_handle;
2091         if (not defined $session_id ) { $session_id = 0 };
2092         if ($session_id =~ /[^0-9]*/) { $session_id = 0 };
2094         if ($session_id == 0) {
2095                 daemon_log("$session_id DEBUG: get_ldap_handle invoked without a session_id, create a new ldap_handle", 7); 
2096                 $ldap_handle = Net::LDAP->new( $ldap_uri );
2097                 if (defined $ldap_handle) {
2098                         $ldap_handle->bind($ldap_admin_dn, password => $ldap_admin_password) or daemon_log("$session_id ERROR: Bind to LDAP $ldap_uri as $ldap_admin_dn failed!"); 
2099                 } else {
2100                         daemon_log("$session_id ERROR: creation of a new LDAP handle failed (ldap_uri '$ldap_uri')");
2101                 }
2103         } else {
2104                 my $session_reference = $global_kernel->ID_id_to_session($session_id);
2105                 if( defined $session_reference ) {
2106                         $heap = $session_reference->get_heap();
2107                 }
2109                 if (not defined $heap) {
2110                         daemon_log("$session_id DEBUG: cannot get heap for session_id '$session_id'", 7); 
2111                         return;
2112                 }
2114                 # TODO: This "if" is nonsense, because it doesn't prove that the
2115                 #       used handle is still valid - or if we've to reconnect...
2116                 #if (not exists $heap->{ldap_handle}) {
2117                         $ldap_handle = Net::LDAP->new( $ldap_uri );
2118                         $ldap_handle->bind($ldap_admin_dn, password => $ldap_admin_password) or daemon_log("$session_id ERROR: Bind to LDAP $ldap_uri as $ldap_admin_dn failed!"); 
2119                         $heap->{ldap_handle} = $ldap_handle;
2120                 #}
2121         }
2122         return $ldap_handle;
2126 sub change_fai_state {
2127     my ($st, $targets, $session_id) = @_;
2128     $session_id = 0 if not defined $session_id;
2129     # Set FAI state to localboot
2130     my %mapActions= (
2131         reboot    => '',
2132         update    => 'softupdate',
2133         localboot => 'localboot',
2134         reinstall => 'install',
2135         rescan    => '',
2136         wake      => '',
2137         memcheck  => 'memcheck',
2138         sysinfo   => 'sysinfo',
2139         install   => 'install',
2140     );
2142     # Return if this is unknown
2143     if (!exists $mapActions{ $st }){
2144         daemon_log("$session_id ERROR: unknown action '$st', can not translate ot FAIstate", 1); 
2145       return;
2146     }
2148     my $state= $mapActions{ $st };
2150     my $ldap_handle = &get_ldap_handle($session_id);
2151     if( defined($ldap_handle) ) {
2153       # Build search filter for hosts
2154         my $search= "(&(objectClass=GOhard)";
2155         foreach (@{$targets}){
2156             $search.= "(macAddress=$_)";
2157         }
2158         $search.= ")";
2160       # If there's any host inside of the search string, procress them
2161         if (!($search =~ /macAddress/)){
2162             daemon_log("$session_id ERROR: no macAddress found in filter statement for LDAP search: '$search'", 1);    
2163             return;
2164         }
2166       # Perform search for Unit Tag
2167       my $mesg = $ldap_handle->search(
2168           base   => $ldap_base,
2169           scope  => 'sub',
2170           attrs  => ['dn', 'FAIstate', 'objectClass'],
2171           filter => "$search"
2172           );
2174           if ($mesg->count) {
2175                   my @entries = $mesg->entries;
2176                   if (0 == @entries) {
2177                                   daemon_log("$session_id ERROR: ldap search failed: ldap_base=$ldap_base, filter=$search", 1); 
2178                   }
2180                   foreach my $entry (@entries) {
2181                           # Only modify entry if it is not set to '$state'
2182                           if ($entry->get_value("FAIstate") ne "$state"){
2183                                   daemon_log("$session_id INFO: Setting FAIstate to '$state' for ".$entry->dn, 5);
2184                                   my $result;
2185                                   my %tmp = map { $_ => 1 } $entry->get_value("objectClass");
2186                                   if (exists $tmp{'FAIobject'}){
2187                                           if ($state eq ''){
2188                                                   $result= $ldap_handle->modify($entry->dn, changes => [
2189                                                           delete => [ FAIstate => [] ] ]);
2190                                           } else {
2191                                                   $result= $ldap_handle->modify($entry->dn, changes => [
2192                                                           replace => [ FAIstate => $state ] ]);
2193                                           }
2194                                   } elsif ($state ne ''){
2195                                           $result= $ldap_handle->modify($entry->dn, changes => [
2196                                                   add     => [ objectClass => 'FAIobject' ],
2197                                                   add     => [ FAIstate => $state ] ]);
2198                                   }
2200                                   # Errors?
2201                                   if ($result->code){
2202                                           daemon_log("$session_id Error: Setting FAIstate to '$state' for ".$entry->dn. "failed: ".$result->error, 1);
2203                                   }
2204                           } else {
2205                                   daemon_log("$session_id DEBUG FAIstate at host '".$entry->dn."' already at state '$st'", 7); 
2206                           }  
2207                   }
2208           } else {
2209                 daemon_log("$session_id ERROR: LDAP search failed: ldap_base=$ldap_base, filter=$search", 1);
2210           }
2212     # if no ldap handle defined
2213     } else {
2214         daemon_log("$session_id ERROR: no LDAP handle defined for update FAIstate", 1); 
2215     }
2217         return;
2221 sub change_goto_state {
2222     my ($st, $targets, $session_id) = @_;
2223     $session_id = 0  if not defined $session_id;
2225     # Switch on or off?
2226     my $state= $st eq 'active' ? 'active': 'locked';
2228     my $ldap_handle = &get_ldap_handle($session_id);
2229     if( defined($ldap_handle) ) {
2231       # Build search filter for hosts
2232       my $search= "(&(objectClass=GOhard)";
2233       foreach (@{$targets}){
2234         $search.= "(macAddress=$_)";
2235       }
2236       $search.= ")";
2238       # If there's any host inside of the search string, procress them
2239       if (!($search =~ /macAddress/)){
2240         return;
2241       }
2243       # Perform search for Unit Tag
2244       my $mesg = $ldap_handle->search(
2245           base   => $ldap_base,
2246           scope  => 'sub',
2247           attrs  => ['dn', 'gotoMode'],
2248           filter => "$search"
2249           );
2251       if ($mesg->count) {
2252         my @entries = $mesg->entries;
2253         foreach my $entry (@entries) {
2255           # Only modify entry if it is not set to '$state'
2256           if ($entry->get_value("gotoMode") ne $state){
2258             daemon_log("$session_id INFO: Setting gotoMode to '$state' for ".$entry->dn, 5);
2259             my $result;
2260             $result= $ldap_handle->modify($entry->dn, changes => [
2261                                                 replace => [ gotoMode => $state ] ]);
2263             # Errors?
2264             if ($result->code){
2265               &daemon_log("$session_id Error: Setting gotoMode to '$state' for ".$entry->dn. "failed: ".$result->error, 1);
2266             }
2268           }
2269         }
2270       } else {
2271                 daemon_log("$session_id ERROR: LDAP search failed in function change_goto_state: ldap_base=$ldap_base, filter=$search", 1);
2272           }
2274     }
2278 sub run_recreate_packages_db {
2279     my ($kernel, $session, $heap) = @_[KERNEL, SESSION, HEAP];
2280     my $session_id = $session->ID;
2281         &main::daemon_log("$session_id INFO: Recreating FAI Packages DB ('$fai_release_tn', '$fai_server_tn', '$packages_list_tn')", 5);
2282         $kernel->yield('create_fai_release_db', $fai_release_tn);
2283         $kernel->yield('create_fai_server_db', $fai_server_tn);
2284         return;
2288 sub run_create_fai_server_db {
2289     my ($kernel, $session, $heap, $table_name) = @_[KERNEL, SESSION, HEAP, ARG0];
2290     my $session_id = $session->ID;
2291     my $task = POE::Wheel::Run->new(
2292             Program => sub { &create_fai_server_db($table_name,$kernel, undef, $session_id) },
2293             StdoutEvent  => "session_run_result",
2294             StderrEvent  => "session_run_debug",
2295             CloseEvent   => "session_run_done",
2296             );
2298     $heap->{task}->{ $task->ID } = $task;
2299     return;
2303 sub create_fai_server_db {
2304         my ($table_name, $kernel, $dont_create_packages_list, $session_id) = @_;
2305         my $result;
2307         if (not defined $session_id) { $session_id = 0; }
2308         my $ldap_handle = &get_ldap_handle();
2309         if(defined($ldap_handle)) {
2310                 daemon_log("$session_id INFO: create_fai_server_db: start", 5);
2311                 my $mesg= $ldap_handle->search(
2312                         base   => $ldap_base,
2313                         scope  => 'sub',
2314                         attrs  => ['FAIrepository', 'gosaUnitTag'],
2315                         filter => "(&(FAIrepository=*)(objectClass=FAIrepositoryServer))",
2316                 );
2317                 if($mesg->{'resultCode'} == 0 &&
2318                         $mesg->count != 0) {
2319                         foreach my $entry (@{$mesg->{entries}}) {
2320                                 if($entry->exists('FAIrepository')) {
2321                                         # Add an entry for each Repository configured for server
2322                                         foreach my $repo(@{$entry->get_value('FAIrepository', asref => 1)}) {
2323                                                 my($tmp_url,$tmp_server,$tmp_release,$tmp_sections) = split(/\|/, $repo);
2324                                                 my $tmp_tag= $entry->get_value('gosaUnitTag') || "";
2325                                                 $result= $fai_server_db->add_dbentry( { 
2326                                                                 table => $table_name,
2327                                                                 primkey => ['server', 'fai_release', 'tag'],
2328                                                                 server => $tmp_url,
2329                                                                 fai_release => $tmp_release,
2330                                                                 sections => $tmp_sections,
2331                                                                 tag => (length($tmp_tag)>0)?$tmp_tag:"",
2332                                                         } );
2333                                         }
2334                                 }
2335                         }
2336                 }
2337                 daemon_log("$session_id INFO: create_fai_server_db: finished", 5);
2339                 # TODO: Find a way to post the 'create_packages_list_db' event
2340                 if(not defined($dont_create_packages_list)) {
2341                         &create_packages_list_db(undef, undef, $session_id);
2342                 }
2343         }       
2345         $ldap_handle->disconnect;
2346         return $result;
2350 sub run_create_fai_release_db {
2351         my ($session, $heap, $table_name) = @_[SESSION, HEAP, ARG0];
2352         my $session_id = $session->ID;
2353         my $task = POE::Wheel::Run->new(
2354                 Program => sub { &create_fai_release_db($table_name, $session_id) },
2355                 StdoutEvent  => "session_run_result",
2356                 StderrEvent  => "session_run_debug",
2357                 CloseEvent   => "session_run_done",
2358         );
2360         $heap->{task}->{ $task->ID } = $task;
2361         return;
2365 sub create_fai_release_db {
2366         my ($table_name, $session_id) = @_;
2367         my $result;
2369         # used for logging
2370         if (not defined $session_id) { $session_id = 0; }
2372         my $ldap_handle = &get_ldap_handle();
2373         if(defined($ldap_handle)) {
2374                 daemon_log("$session_id INFO: create_fai_release_db: start",5);
2375                 my $mesg= $ldap_handle->search(
2376                         base   => $ldap_base,
2377                         scope  => 'sub',
2378                         attrs  => [],
2379                         filter => "(&(objectClass=organizationalUnit)(ou=fai))",
2380                 );
2381                 if($mesg->{'resultCode'} == 0 &&
2382                         $mesg->count != 0) {
2383                         # Walk through all possible FAI container ou's
2384                         my @sql_list;
2385                         my $timestamp= &get_time();
2386                         foreach my $ou (@{$mesg->{entries}}) {
2387                                 my $tmp_classes= resolve_fai_classes($ou->dn, $ldap_handle, $session_id);
2388                                 if(defined($tmp_classes) && ref($tmp_classes) eq 'HASH') {
2389                                         my @tmp_array=get_fai_release_entries($tmp_classes);
2390                                         if(@tmp_array) {
2391                                                 foreach my $entry (@tmp_array) {
2392                                                         if(defined($entry) && ref($entry) eq 'HASH') {
2393                                                                 my $sql= 
2394                                                                 "INSERT INTO $table_name "
2395                                                                 ."(timestamp, fai_release, class, type, state) VALUES ("
2396                                                                 .$timestamp.","
2397                                                                 ."'".$entry->{'release'}."',"
2398                                                                 ."'".$entry->{'class'}."',"
2399                                                                 ."'".$entry->{'type'}."',"
2400                                                                 ."'".$entry->{'state'}."')";
2401                                                                 push @sql_list, $sql;
2402                                                         }
2403                                                 }
2404                                         }
2405                                 }
2406                         }
2408                         daemon_log("$session_id DEBUG: Inserting ".scalar @sql_list." entries to DB",8);
2409                         if(@sql_list) {
2410                                 unshift @sql_list, "DELETE FROM $table_name";
2411                                 $fai_release_db->exec_statementlist(\@sql_list);
2412                         }
2413                         daemon_log("$session_id DEBUG: Done with inserting",7);
2414                 }
2415                 daemon_log("$session_id INFO: create_fai_release_db: finished",5);
2416         }
2417         $ldap_handle->disconnect;
2418         return $result;
2421 sub get_fai_types {
2422         my $tmp_classes = shift || return undef;
2423         my @result;
2425         foreach my $type(keys %{$tmp_classes}) {
2426                 if(defined($tmp_classes->{$type}[0]) && (!($tmp_classes->{$type}[0] =~ /^.*?removed.*?$/))) {
2427                         my $entry = {
2428                                 type => $type,
2429                                 state => $tmp_classes->{$type}[0],
2430                         };
2431                         push @result, $entry;
2432                 }
2433         }
2435         return @result;
2438 sub get_fai_state {
2439         my $result = "";
2440         my $tmp_classes = shift || return $result;
2442         foreach my $type(keys %{$tmp_classes}) {
2443                 if(defined($tmp_classes->{$type}[0])) {
2444                         $result = $tmp_classes->{$type}[0];
2445                         
2446                 # State is equal for all types in class
2447                         last;
2448                 }
2449         }
2451         return $result;
2454 sub resolve_fai_classes {
2455         my ($fai_base, $ldap_handle, $session_id) = @_;
2456         if (not defined $session_id) { $session_id = 0; }
2457         my $result;
2458         my @possible_fai_classes= ("FAIscript", "FAIhook", "FAIpartitionTable", "FAItemplate", "FAIvariable", "FAIprofile", "FAIpackageList");
2459         my $fai_filter= "(|(&(objectClass=FAIclass)(|(objectClass=".join(")(objectClass=", @possible_fai_classes).")))(objectClass=FAIbranch))";
2460         my $fai_classes;
2462         daemon_log("$session_id DEBUG: Searching for FAI entries in base $fai_base",7);
2463         my $mesg= $ldap_handle->search(
2464                 base   => $fai_base,
2465                 scope  => 'sub',
2466                 attrs  => ['cn','objectClass','FAIstate'],
2467                 filter => $fai_filter,
2468         );
2469         daemon_log("$session_id DEBUG: Found ".$mesg->count()." FAI entries",7);
2471         if($mesg->{'resultCode'} == 0 &&
2472                 $mesg->count != 0) {
2473                 foreach my $entry (@{$mesg->{entries}}) {
2474                         if($entry->exists('cn')) {
2475                                 my $tmp_dn= $entry->dn();
2477                                 # Skip classname and ou dn parts for class
2478                                 my $tmp_release = ($1) if $tmp_dn =~ /^[^,]+,[^,]+,(.*?),$fai_base$/;
2480                                 # Skip classes without releases
2481                                 if((!defined($tmp_release)) || length($tmp_release)==0) {
2482                                         next;
2483                                 }
2485                                 my $tmp_cn= $entry->get_value('cn');
2486                                 my $tmp_state= $entry->get_value('FAIstate');
2488                                 my $tmp_type;
2489                                 # Get FAI type
2490                                 for my $oclass(@{$entry->get_value('objectClass', asref => 1)}) {
2491                                         if(grep $_ eq $oclass, @possible_fai_classes) {
2492                                                 $tmp_type= $oclass;
2493                                                 last;
2494                                         }
2495                                 }
2497                                 if($tmp_release =~ /^.*?,.*?$/ && (!($tmp_release =~ /^.*?\\,.*?$/))) {
2498                                         # A Subrelease
2499                                         my @sub_releases = split(/,/, $tmp_release);
2501                                         # Walk through subreleases and build hash tree
2502                                         my $hash;
2503                                         while(my $tmp_sub_release = pop @sub_releases) {
2504                                                 $hash .= "\{'$tmp_sub_release'\}->";                                            
2505                                         }
2506                                         eval('push @{$fai_classes->'.$hash.'{$tmp_cn}->{$tmp_type}}, (defined($tmp_state) && length($tmp_state)>0)?$tmp_state:"";');
2507                                 } else {
2508                                         # A branch, no subrelease
2509                                         push @{$fai_classes->{$tmp_release}->{$tmp_cn}->{$tmp_type}}, (defined($tmp_state) && length($tmp_state)>0)?$tmp_state:"";
2510                                 }
2511                         } elsif (!$entry->exists('cn')) {
2512                                 my $tmp_dn= $entry->dn();
2513                                 my $tmp_release = ($1) if $tmp_dn =~ /^(.*?),$fai_base$/;
2515                                 # Skip classes without releases
2516                                 if((!defined($tmp_release)) || length($tmp_release)==0) {
2517                                         next;
2518                                 }
2520                                 if($tmp_release =~ /^.*?,.*?$/ && (!($tmp_release =~ /^.*?\\,.*?$/))) {
2521                                         # A Subrelease
2522                                         my @sub_releases= split(/,/, $tmp_release);
2524                                         # Walk through subreleases and build hash tree
2525                                         my $hash;
2526                                         while(my $tmp_sub_release = pop @sub_releases) {
2527                                                 $hash .= "\{'$tmp_sub_release'\}->";                                            
2528                                         }
2529                                         # Remove the last two characters
2530                                         chop($hash);
2531                                         chop($hash);
2533                                         eval('$fai_classes->'.$hash.'= {}');
2534                                 } else {
2535                                         # A branch, no subrelease
2536                                         if(!exists($fai_classes->{$tmp_release})) {
2537                                                 $fai_classes->{$tmp_release} = {};
2538                                         }
2539                                 }
2540                         }
2541                 }
2543                 # The hash is complete, now we can honor the copy-on-write based missing entries
2544                 foreach my $release (keys %$fai_classes) {
2545                         $result->{$release}= deep_copy(apply_fai_inheritance($fai_classes->{$release}));
2546                 }
2547         }
2548         return $result;
2551 sub apply_fai_inheritance {
2552        my $fai_classes = shift || return {};
2553        my $tmp_classes;
2555        # Get the classes from the branch
2556        foreach my $class (keys %{$fai_classes}) {
2557                # Skip subreleases
2558                if($class =~ /^ou=.*$/) {
2559                        next;
2560                } else {
2561                        $tmp_classes->{$class}= deep_copy($fai_classes->{$class});
2562                }
2563        }
2565        # Apply to each subrelease
2566        foreach my $subrelease (keys %{$fai_classes}) {
2567                if($subrelease =~ /ou=/) {
2568                        foreach my $tmp_class (keys %{$tmp_classes}) {
2569                                if(!exists($fai_classes->{$subrelease}->{$tmp_class})) {
2570                                        $fai_classes->{$subrelease}->{$tmp_class} =
2571                                        deep_copy($tmp_classes->{$tmp_class});
2572                                } else {
2573                                        foreach my $type (keys %{$tmp_classes->{$tmp_class}}) {
2574                                                if(!exists($fai_classes->{$subrelease}->{$tmp_class}->{$type})) {
2575                                                        $fai_classes->{$subrelease}->{$tmp_class}->{$type}=
2576                                                        deep_copy($tmp_classes->{$tmp_class}->{$type});
2577                                                }
2578                                        }
2579                                }
2580                        }
2581                }
2582        }
2584        # Find subreleases in deeper levels
2585        foreach my $subrelease (keys %{$fai_classes}) {
2586                if($subrelease =~ /ou=/) {
2587                        foreach my $subsubrelease (keys %{$fai_classes->{$subrelease}}) {
2588                                if($subsubrelease =~ /ou=/) {
2589                                        apply_fai_inheritance($fai_classes->{$subrelease});
2590                                }
2591                        }
2592                }
2593        }
2595        return $fai_classes;
2598 sub get_fai_release_entries {
2599         my $tmp_classes = shift || return;
2600         my $parent = shift || "";
2601         my @result = shift || ();
2603         foreach my $entry (keys %{$tmp_classes}) {
2604                 if(defined($entry)) {
2605                         if($entry =~ /^ou=.*$/) {
2606                                 my $release_name = $entry;
2607                                 $release_name =~ s/ou=//g;
2608                                 if(length($parent)>0) {
2609                                         $release_name = $parent."/".$release_name;
2610                                 }
2611                                 my @bufentries = get_fai_release_entries($tmp_classes->{$entry}, $release_name, @result);
2612                                 foreach my $bufentry(@bufentries) {
2613                                         push @result, $bufentry;
2614                                 }
2615                         } else {
2616                                 my @types = get_fai_types($tmp_classes->{$entry});
2617                                 foreach my $type (@types) {
2618                                         push @result, 
2619                                         {
2620                                                 'class' => $entry,
2621                                                 'type' => $type->{'type'},
2622                                                 'release' => $parent,
2623                                                 'state' => $type->{'state'},
2624                                         };
2625                                 }
2626                         }
2627                 }
2628         }
2630         return @result;
2633 sub deep_copy {
2634         my $this = shift;
2635         if (not ref $this) {
2636                 $this;
2637         } elsif (ref $this eq "ARRAY") {
2638                 [map deep_copy($_), @$this];
2639         } elsif (ref $this eq "HASH") {
2640                 +{map { $_ => deep_copy($this->{$_}) } keys %$this};
2641         } else { die "what type is $_?" }
2645 sub session_run_result {
2646     my ($kernel, $heap, $client_answer) = @_[KERNEL, HEAP, ARG0];    
2647     $kernel->sig(CHLD => "child_reap");
2650 sub session_run_debug {
2651     my $result = $_[ARG0];
2652     print STDERR "$result\n";
2655 sub session_run_done {
2656     my ( $kernel, $heap, $task_id ) = @_[ KERNEL, HEAP, ARG0 ];
2657     delete $heap->{task}->{$task_id};
2661 sub create_sources_list {
2662         my $session_id = shift;
2663         my $ldap_handle = &main::get_ldap_handle;
2664         my $result="/tmp/gosa_si_tmp_sources_list";
2666         # Remove old file
2667         if(stat($result)) {
2668                 unlink($result);
2669                 &main::daemon_log("$session_id DEBUG: remove an old version of '$result'", 7); 
2670         }
2672         my $fh;
2673         open($fh, ">$result");
2674         if (not defined $fh) {
2675                 &main::daemon_log("$session_id DEBUG: cannot open '$result' for writing", 7); 
2676                 return undef;
2677         }
2678         if(defined($main::ldap_server_dn) and length($main::ldap_server_dn) > 0) {
2679                 my $mesg=$ldap_handle->search(
2680                         base    => $main::ldap_server_dn,
2681                         scope   => 'base',
2682                         attrs   => 'FAIrepository',
2683                         filter  => 'objectClass=FAIrepositoryServer'
2684                 );
2685                 if($mesg->count) {
2686                         foreach my $entry(@{$mesg->{'entries'}}) {
2687                                 foreach my $value(@{$entry->get_value('FAIrepository', asref => 1)}) {
2688                                         my ($server, $tag, $release, $sections)= split /\|/, $value;
2689                                         my $line = "deb $server $release";
2690                                         $sections =~ s/,/ /g;
2691                                         $line.= " $sections";
2692                                         print $fh $line."\n";
2693                                 }
2694                         }
2695                 }
2696         } else {
2697                 if (defined $main::ldap_server_dn){
2698                         &main::daemon_log("$session_id ERROR: something wrong with ldap_server_dn '$main::ldap_server_dn', abort create_sources_list", 1); 
2699                 } else {
2700                         &main::daemon_log("$session_id ERROR: no ldap_server_dn found, abort create_sources_list", 1);
2701                 }
2702         }
2703         close($fh);
2705         return $result;
2709 sub run_create_packages_list_db {
2710     my ($kernel, $session, $heap) = @_[KERNEL, SESSION, HEAP];
2711         my $session_id = $session->ID;
2713         my $task = POE::Wheel::Run->new(
2714                                         Priority => +20,
2715                                         Program => sub {&create_packages_list_db(undef, undef, $session_id)},
2716                                         StdoutEvent  => "session_run_result",
2717                                         StderrEvent  => "session_run_debug",
2718                                         CloseEvent   => "session_run_done",
2719                                         );
2720         $heap->{task}->{ $task->ID } = $task;
2724 sub create_packages_list_db {
2725         my ($ldap_handle, $sources_file, $session_id) = @_;
2726         
2727         # it should not be possible to trigger a recreation of packages_list_db
2728         # while packages_list_db is under construction, so set flag packages_list_under_construction
2729         # which is tested befor recreation can be started
2730         if (-r $packages_list_under_construction) {
2731                 daemon_log("$session_id WARNING: packages_list_db is right now under construction, please wait until this process is finished", 3);
2732                 return;
2733         } else {
2734                 daemon_log("$session_id INFO: create_packages_list_db: start", 5); 
2735                 # set packages_list_under_construction to true
2736                 system("touch $packages_list_under_construction");
2737                 @packages_list_statements=();
2738         }
2740         if (not defined $session_id) { $session_id = 0; }
2741         if (not defined $ldap_handle) { 
2742                 $ldap_handle= &get_ldap_handle();
2744                 if (not defined $ldap_handle) {
2745                         daemon_log("$session_id ERROR: no ldap_handle available to create_packages_list_db", 1);
2746                         unlink($packages_list_under_construction);
2747                         return;
2748                 }
2749         }
2750         if (not defined $sources_file) { 
2751                 &main::daemon_log("$session_id INFO: no sources_file given for creating packages list so trigger creation of it", 5); 
2752                 $sources_file = &create_sources_list($session_id);
2753         }
2755         if (not defined $sources_file) {
2756                 &main::daemon_log("$session_id ERROR: no sources_file given under '$sources_file', skip create_packages_list_db", 1); 
2757                 unlink($packages_list_under_construction);
2758                 return;
2759         }
2761         my $line;
2763         open(CONFIG, "<$sources_file") or do {
2764                 daemon_log( "$session_id ERROR: create_packages_list_db: Failed to open '$sources_file'", 1);
2765                 unlink($packages_list_under_construction);
2766                 return;
2767         };
2769         # Read lines
2770         while ($line = <CONFIG>){
2771                 # Unify
2772                 chop($line);
2773                 $line =~ s/^\s+//;
2774                 $line =~ s/^\s+/ /;
2776                 # Strip comments
2777                 $line =~ s/#.*$//g;
2779                 # Skip empty lines
2780                 if ($line =~ /^\s*$/){
2781                         next;
2782                 }
2784                 # Interpret deb line
2785                 if ($line =~ /^deb [^\s]+\s[^\s]+\s[^\s]+/){
2786                         my( $baseurl, $dist, $sections ) = ($line =~ /^deb\s([^\s]+)\s+([^\s]+)\s+(.*)$/);
2787                         my $section;
2788                         foreach $section (split(' ', $sections)){
2789                                 &parse_package_info( $baseurl, $dist, $section, $session_id );
2790                         }
2791                 }
2792         }
2794         close (CONFIG);
2797         if(keys(%repo_dirs)) {
2798                 find(\&cleanup_and_extract, keys( %repo_dirs ));
2799                 &main::strip_packages_list_statements();
2800                 $packages_list_db->exec_statementlist(\@packages_list_statements);
2801         }
2802         unlink($packages_list_under_construction);
2803         daemon_log("$session_id INFO: create_packages_list_db: finished", 5); 
2804         return;
2807 # This function should do some intensive task to minimize the db-traffic
2808 sub strip_packages_list_statements {
2809     my @existing_entries= @{$packages_list_db->exec_statement("SELECT * FROM $main::packages_list_tn")};
2810         my @new_statement_list=();
2811         my $hash;
2812         my $insert_hash;
2813         my $update_hash;
2814         my $delete_hash;
2815         my $local_timestamp=get_time();
2817         foreach my $existing_entry (@existing_entries) {
2818                 $hash->{@{$existing_entry}[0]}->{@{$existing_entry}[1]}->{@{$existing_entry}[2]}= $existing_entry;
2819         }
2821         foreach my $statement (@packages_list_statements) {
2822                 if($statement =~ /^INSERT/i) {
2823                         # Assign the values from the insert statement
2824                         my ($distribution,$package,$version,$section,$description,$template,$timestamp) = ($1,$2,$3,$4,$5,$6,$7) if $statement =~ 
2825                         /^INSERT\s+?INTO\s+?$main::packages_list_tn\s+?VALUES\s*?\('(.*?)',\s*?'(.*?)',\s*?'(.*?)',\s*?'(.*?)',\s*?'(.*?)',\s*?'(.*?)',\s*?'(.*?)'\s*?\)$/si;
2826                         if(exists($hash->{$distribution}->{$package}->{$version})) {
2827                                 # If section or description has changed, update the DB
2828                                 if( 
2829                                         (! (@{$hash->{$distribution}->{$package}->{$version}}[3] eq $section)) or 
2830                                         (! (@{$hash->{$distribution}->{$package}->{$version}}[4] eq $description))
2831                                 ) {
2832                                         @{$update_hash->{$distribution}->{$package}->{$version}} = ($distribution,$package,$version,$section,$description,undef);
2833                                 }
2834                         } else {
2835                                 # Insert a non-existing entry to db
2836                                 @{$insert_hash->{$distribution}->{$package}->{$version}} = ($distribution,$package,$version,$section,$description,$template);
2837                         }
2838                 } elsif ($statement =~ /^UPDATE/i) {
2839                         my ($template,$package,$version) = ($1,$2,$3) if $statement =~
2840                         /^update\s+?$main::packages_list_tn\s+?set\s+?template\s*?=\s*?'(.*?)'\s+?where\s+?package\s*?=\s*?'(.*?)'\s+?and\s+?version\s*?=\s*?'(.*?)'\s*?;$/si;
2841                         foreach my $distribution (keys %{$hash}) {
2842                                 if(exists($insert_hash->{$distribution}->{$package}->{$version})) {
2843                                         # update the insertion hash to execute only one query per package (insert instead insert+update)
2844                                         @{$insert_hash->{$distribution}->{$package}->{$version}}[5]= $template;
2845                                 } elsif(exists($hash->{$distribution}->{$package}->{$version})) {
2846                                         if( ! (@{$hash->{$distribution}->{$package}->{$version}}[5] eq $template)) {
2847                                                 my $section;
2848                                                 my $description;
2849                                                 if(defined(@{$update_hash->{$distribution}->{$package}->{$version}}[3]) and
2850                                                         length(@{$update_hash->{$distribution}->{$package}->{$version}}[3]) > 0 ) {
2851                                                         $section= @{$update_hash->{$distribution}->{$package}->{$version}}[3];
2852                                                 }
2853                                                 if(defined(@{$update_hash->{$distribution}->{$package}->{$version}}[4])) {
2854                                                         $description= @{$update_hash->{$distribution}->{$package}->{$version}}[4];
2855                                                 }
2856                                                 @{$update_hash->{$distribution}->{$package}->{$version}} = ($distribution,$package,$version,$section,$description,$template);
2857                                         }
2858                                 }
2859                         }
2860                 }
2861         }
2863         # TODO: Check for orphaned entries
2865         # unroll the insert_hash
2866         foreach my $distribution (keys %{$insert_hash}) {
2867                 foreach my $package (keys %{$insert_hash->{$distribution}}) {
2868                         foreach my $version (keys %{$insert_hash->{$distribution}->{$package}}) {
2869                                 push @new_statement_list, "INSERT INTO $main::packages_list_tn VALUES ('$distribution','$package','$version',"
2870                                 ."'@{$insert_hash->{$distribution}->{$package}->{$version}}[3]',"
2871                                 ."'@{$insert_hash->{$distribution}->{$package}->{$version}}[4]',"
2872                                 ."'@{$insert_hash->{$distribution}->{$package}->{$version}}[5]',"
2873                                 ."'$local_timestamp')";
2874                         }
2875                 }
2876         }
2878         # unroll the update hash
2879         foreach my $distribution (keys %{$update_hash}) {
2880                 foreach my $package (keys %{$update_hash->{$distribution}}) {
2881                         foreach my $version (keys %{$update_hash->{$distribution}->{$package}}) {
2882                                 my $set = "";
2883                                 if(defined(@{$update_hash->{$distribution}->{$package}->{$version}}[3])) {
2884                                         $set .= "section = '@{$update_hash->{$distribution}->{$package}->{$version}}[3]', ";
2885                                 }
2886                                 if(defined(@{$update_hash->{$distribution}->{$package}->{$version}}[4])) {
2887                                         $set .= "description = '@{$update_hash->{$distribution}->{$package}->{$version}}[4]', ";
2888                                 }
2889                                 if(defined(@{$update_hash->{$distribution}->{$package}->{$version}}[5])) {
2890                                         $set .= "template = '@{$update_hash->{$distribution}->{$package}->{$version}}[5]', ";
2891                                 }
2892                                 if(defined($set) and length($set) > 0) {
2893                                         $set .= "timestamp = '$local_timestamp'";
2894                                 } else {
2895                                         next;
2896                                 }
2897                                 push @new_statement_list, 
2898                                         "UPDATE $main::packages_list_tn SET $set WHERE"
2899                                         ." distribution = '$distribution'"
2900                                         ." AND package = '$package'"
2901                                         ." AND version = '$version'";
2902                         }
2903                 }
2904         }
2906         @packages_list_statements = @new_statement_list;
2910 sub parse_package_info {
2911     my ($baseurl, $dist, $section, $session_id)= @_;
2912     my ($package);
2913     if (not defined $session_id) { $session_id = 0; }
2914     my ($path) = ($baseurl =~ m%://[^/]*(.*)$%);
2915     $repo_dirs{ "${repo_path}/pool" } = 1;
2917     foreach $package ("Packages.gz"){
2918         daemon_log("$session_id DEBUG: create_packages_list: fetch $baseurl, $dist, $section", 7);
2919         get_package( "$baseurl/dists/$dist/$section/binary-$arch/$package", "$outdir/$dist/$section", $session_id );
2920         parse_package( "$outdir/$dist/$section", $dist, $path, $session_id );
2921     }
2922     
2926 sub get_package {
2927     my ($url, $dest, $session_id)= @_;
2928     if (not defined $session_id) { $session_id = 0; }
2930     my $tpath = dirname($dest);
2931     -d "$tpath" || mkpath "$tpath";
2933     # This is ugly, but I've no time to take a look at "how it works in perl"
2934     if(0 == system("wget '$url' -O '$dest' 2>/dev/null") ) {
2935         system("gunzip -cd '$dest' > '$dest.in'");
2936         daemon_log("$session_id DEBUG: run command: gunzip -cd '$dest' > '$dest.in'", 5);
2937         unlink($dest);
2938         daemon_log("$session_id DEBUG: delete file '$dest'", 5); 
2939     } else {
2940         daemon_log("$session_id ERROR: create_packages_list_db: get_packages: fetching '$url' failed!", 1);
2941     }
2942     return 0;
2946 sub parse_package {
2947     my ($path, $dist, $srv_path, $session_id)= @_;
2948     if (not defined $session_id) { $session_id = 0;}
2949     my ($package, $version, $section, $description);
2950     my $PACKAGES;
2951     my $timestamp = &get_time();
2953     if(not stat("$path.in")) {
2954         daemon_log("$session_id ERROR: create_packages_list: parse_package: file '$path.in' is not readable",1);
2955         return;
2956     }
2958     open($PACKAGES, "<$path.in");
2959     if(not defined($PACKAGES)) {
2960         daemon_log("$session_id ERROR: create_packages_list_db: parse_package: cannot open '$path.in'",1); 
2961         return;
2962     }
2964     # Read lines
2965     while (<$PACKAGES>){
2966         my $line = $_;
2967         # Unify
2968         chop($line);
2970         # Use empty lines as a trigger
2971         if ($line =~ /^\s*$/){
2972             my $sql = "INSERT INTO packages_list VALUES ('$dist', '$package', '$version', '$section', '$description', '', '$timestamp')";
2973             push(@packages_list_statements, $sql);
2974             $package = "none";
2975             $version = "none";
2976             $section = "none";
2977             $description = "none"; 
2978             next;
2979         }
2981         # Trigger for package name
2982         if ($line =~ /^Package:\s/){
2983             ($package)= ($line =~ /^Package: (.*)$/);
2984             next;
2985         }
2987         # Trigger for version
2988         if ($line =~ /^Version:\s/){
2989             ($version)= ($line =~ /^Version: (.*)$/);
2990             next;
2991         }
2993         # Trigger for description
2994         if ($line =~ /^Description:\s/){
2995             ($description)= &encode_base64(($line =~ /^Description: (.*)$/));
2996             next;
2997         }
2999         # Trigger for section
3000         if ($line =~ /^Section:\s/){
3001             ($section)= ($line =~ /^Section: (.*)$/);
3002             next;
3003         }
3005         # Trigger for filename
3006         if ($line =~ /^Filename:\s/){
3007             my ($filename) = ($line =~ /^Filename: (.*)$/);
3008             store_fileinfo( $package, $filename, $dist, $srv_path, $version, $repo_path );
3009             next;
3010         }
3011     }
3013     close( $PACKAGES );
3014     unlink( "$path.in" );
3018 sub store_fileinfo {
3019     my( $package, $file, $dist, $path, $vers, $srvdir) = @_;
3021     my %fileinfo = (
3022         'package' => $package,
3023         'dist' => $dist,
3024         'version' => $vers,
3025     );
3027     $repo_files{ "${srvdir}/$file" } = \%fileinfo;
3031 sub cleanup_and_extract {
3032         my $fileinfo = $repo_files{ $File::Find::name };
3034         if( defined $fileinfo ) {
3035                 my $dir = "$outdir/$fileinfo->{ 'dist' }/debconf.d";
3036                 my $sql;
3037                 my $package = $fileinfo->{ 'package' };
3038                 my $newver = $fileinfo->{ 'version' };
3040                 mkpath($dir);
3041                 system( "dpkg -e '$File::Find::name' '$dir/DEBIAN'" );
3043                 if( -f "$dir/DEBIAN/templates" ) {
3045                         daemon_log("DEBUG: Found debconf templates in '$package' - $newver", 7);
3047                         my $tmpl= ""; {
3048                                 local $/=undef;
3049                                 open FILE, "$dir/DEBIAN/templates";
3050                                 $tmpl = &encode_base64(<FILE>);
3051                                 close FILE;
3052                         }
3053                         rmtree("$dir/DEBIAN/templates");
3055                         $sql= "update $main::packages_list_tn set template = '$tmpl' where package = '$package' and version = '$newver';";
3056                         push @packages_list_statements, $sql;
3057                 }
3058         }
3060         return;
3064 sub register_at_foreign_servers {   
3065     my ($kernel) = $_[KERNEL];
3067     # hole alle bekannten server aus known_server_db
3068     my $server_sql = "SELECT * FROM $known_server_tn";
3069     my $server_res = $known_server_db->exec_statement($server_sql);
3071     # no entries in known_server_db
3072     if (not ref(@$server_res[0]) eq "ARRAY") { 
3073         # TODO
3074     }
3076     # detect already connected clients
3077     my $client_sql = "SELECT * FROM $known_clients_tn"; 
3078     my $client_res = $known_clients_db->exec_statement($client_sql);
3080     # send my server details to all other gosa-si-server within the network
3081     foreach my $hit (@$server_res) {
3082         my $hostname = @$hit[0];
3083         my $hostkey = &create_passwd;
3085         # add already connected clients to registration message 
3086         my $myhash = &create_xml_hash('new_server', $server_address, $hostname);
3087         &add_content2xml_hash($myhash, 'key', $hostkey);
3088         map(&add_content2xml_hash($myhash, 'client', @{$_}[0].",".@{$_}[4]), @$client_res);
3090         # add locally loaded gosa-si modules to registration message
3091         my $loaded_modules = {};
3092         while (my ($package, $pck_info) = each %$known_modules) {
3093                                                 next if ((!defined(@$pck_info[2])) || (!(ref (@$pck_info[2]) eq 'HASH')));
3094                                                 foreach my $act_module (keys(%{@$pck_info[2]})) {
3095                                                         $loaded_modules->{$act_module} = ""; 
3096                                                 }
3097         }
3099         map(&add_content2xml_hash($myhash, "loaded_modules", $_), keys(%$loaded_modules));
3101         # add macaddress to registration message
3102         my ($host_ip, $host_port) = split(/:/, $hostname);
3103         my $local_ip = &get_local_ip_for_remote_ip($host_ip);
3104         my $network_interface= &get_interface_for_ip($local_ip);
3105         my $host_mac = &get_mac_for_interface($network_interface);
3106         &add_content2xml_hash($myhash, 'macaddress', $host_mac);
3107         
3108         # build registration message and send it
3109         my $foreign_server_msg = &create_xml_string($myhash);
3110         my $error = &send_msg_to_target($foreign_server_msg, $hostname, $ServerPackages_key, "new_server", 0); 
3111     }
3112     
3113     $kernel->delay_set("register_at_foreign_servers", $foreign_servers_register_delay); 
3114     return;
3118 #==== MAIN = main ==============================================================
3119 #  parse commandline options
3120 Getopt::Long::Configure( "bundling" );
3121 GetOptions("h|help" => \&usage,
3122         "c|config=s" => \$cfg_file,
3123         "f|foreground" => \$foreground,
3124         "v|verbose+" => \$verbose,
3125         "no-arp+" => \$no_arp,
3126            );
3128 #  read and set config parameters
3129 &check_cmdline_param ;
3130 &read_configfile($cfg_file, %cfg_defaults);
3131 &check_pid;
3133 $SIG{CHLD} = 'IGNORE';
3135 # forward error messages to logfile
3136 if( ! $foreground ) {
3137   open( STDIN,  '+>/dev/null' );
3138   open( STDOUT, '+>&STDIN'    );
3139   open( STDERR, '+>&STDIN'    );
3142 # Just fork, if we are not in foreground mode
3143 if( ! $foreground ) { 
3144     chdir '/'                 or die "Can't chdir to /: $!";
3145     $pid = fork;
3146     setsid                    or die "Can't start a new session: $!";
3147     umask 0;
3148 } else { 
3149     $pid = $$; 
3152 # Do something useful - put our PID into the pid_file
3153 if( 0 != $pid ) {
3154     open( LOCK_FILE, ">$pid_file" );
3155     print LOCK_FILE "$pid\n";
3156     close( LOCK_FILE );
3157     if( !$foreground ) { 
3158         exit( 0 ) 
3159     };
3162 # parse head url and revision from svn
3163 my $server_status_hash = { 'developmental'=>'revision', 'stable'=>'release'};
3164 $server_version =~ /^\$HeadURL: (\S+) \$:\$Rev: (\d+) \$$/;
3165 $server_headURL = defined $1 ? $1 : 'unknown' ;
3166 $server_revision = defined $2 ? $2 : 'unknown' ;
3167 if ($server_headURL =~ /\/tag\// || 
3168         $server_headURL =~ /\/branches\// ) {
3169     $server_status = "stable"; 
3170 } else {
3171     $server_status = "developmental" ;
3174 # Prepare log file
3175 $root_uid = getpwnam('root');
3176 $adm_gid = getgrnam('adm');
3177 chmod(0640, $log_file);
3178 chown($root_uid, $adm_gid, $log_file);
3179 chown($root_uid, $adm_gid, "/var/lib/gosa-si");
3181 daemon_log(" ", 1);
3182 daemon_log("$0 started!", 1);
3183 daemon_log("status: $server_status", 1);
3184 daemon_log($server_status_hash->{$server_status}.": $server_revision", 1); 
3187     no strict "refs";
3189     if ($db_module eq "DBmysql") {
3190         # connect to incoming_db
3191         $incoming_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3193         # connect to gosa-si job queue
3194         $job_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3196         # connect to known_clients_db
3197         $known_clients_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3199         # connect to foreign_clients_db
3200         $foreign_clients_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3202         # connect to known_server_db
3203         $known_server_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3205         # connect to login_usr_db
3206         $login_users_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3208         # connect to fai_server_db 
3209         $fai_server_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3211         # connect to fai_release_db
3212         $fai_release_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3214         # connect to packages_list_db
3215         $packages_list_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3217         # connect to messaging_db
3218         $messaging_db = ("GOSA::".$db_module)->new($main::mysql_database, $main::mysql_host, $main::mysql_username, $main::mysql_password);
3220     } elsif ($db_module eq "DBsqlite") {
3221         # connect to incoming_db
3222         unlink($incoming_file_name);
3223         $incoming_db = GOSA::DBsqlite->new($incoming_file_name);
3224         
3225         # connect to gosa-si job queue
3226         unlink($job_queue_file_name);  ## just for debugging
3227         $job_db = GOSA::DBsqlite->new($job_queue_file_name);
3228         chmod(0660, $job_queue_file_name);
3229         chown($root_uid, $adm_gid, $job_queue_file_name);
3230         
3231         # connect to known_clients_db
3232         unlink($known_clients_file_name);   ## just for debugging
3233         $known_clients_db = GOSA::DBsqlite->new($known_clients_file_name);
3234         chmod(0660, $known_clients_file_name);
3235         chown($root_uid, $adm_gid, $known_clients_file_name);
3236         
3237         # connect to foreign_clients_db
3238         unlink($foreign_clients_file_name);
3239         $foreign_clients_db = GOSA::DBsqlite->new($foreign_clients_file_name);
3240         chmod(0660, $foreign_clients_file_name);
3241         chown($root_uid, $adm_gid, $foreign_clients_file_name);
3242         
3243         # connect to known_server_db
3244         unlink($known_server_file_name);
3245         $known_server_db = GOSA::DBsqlite->new($known_server_file_name);
3246         chmod(0660, $known_server_file_name);
3247         chown($root_uid, $adm_gid, $known_server_file_name);
3248         
3249         # connect to login_usr_db
3250         unlink($login_users_file_name);
3251         $login_users_db = GOSA::DBsqlite->new($login_users_file_name);
3252         chmod(0660, $login_users_file_name);
3253         chown($root_uid, $adm_gid, $login_users_file_name);
3254         
3255         # connect to fai_server_db
3256         unlink($fai_server_file_name);
3257         $fai_server_db = GOSA::DBsqlite->new($fai_server_file_name);
3258         chmod(0660, $fai_server_file_name);
3259         chown($root_uid, $adm_gid, $fai_server_file_name);
3260         
3261         # connect to fai_release_db
3262         unlink($fai_release_file_name);
3263         $fai_release_db = GOSA::DBsqlite->new($fai_release_file_name);
3264         chmod(0660, $fai_release_file_name);
3265         chown($root_uid, $adm_gid, $fai_release_file_name);
3266         
3267         # connect to packages_list_db
3268         #unlink($packages_list_file_name);
3269         unlink($packages_list_under_construction);
3270         $packages_list_db = GOSA::DBsqlite->new($packages_list_file_name);
3271         chmod(0660, $packages_list_file_name);
3272         chown($root_uid, $adm_gid, $packages_list_file_name);
3273         
3274         # connect to messaging_db
3275         unlink($messaging_file_name);
3276         $messaging_db = GOSA::DBsqlite->new($messaging_file_name);
3277         chmod(0660, $messaging_file_name);
3278         chown($root_uid, $adm_gid, $messaging_file_name);
3279     }
3282 # Creating tables
3283 $messaging_db->create_table($messaging_tn, \@messaging_col_names);
3284 $packages_list_db->create_table($packages_list_tn, \@packages_list_col_names);
3285 $fai_release_db->create_table($fai_release_tn, \@fai_release_col_names);
3286 $fai_server_db->create_table($fai_server_tn, \@fai_server_col_names);
3287 $login_users_db->create_table($login_users_tn, \@login_users_col_names);
3288 $known_server_db->create_table($known_server_tn, \@known_server_col_names);
3289 $foreign_clients_db->create_table($foreign_clients_tn, \@foreign_clients_col_names);
3290 $known_clients_db->create_table($known_clients_tn, \@known_clients_col_names);
3291 $incoming_db->create_table($incoming_tn, \@incoming_col_names);
3292 $job_db->create_table($job_queue_tn, \@job_queue_col_names);
3295 # create xml object used for en/decrypting
3296 $xml = new XML::Simple();
3299 # foreign servers 
3300 my @foreign_server_list;
3302 # add foreign server from cfg file
3303 if ($foreign_server_string ne "") {
3304     my @cfg_foreign_server_list = split(",", $foreign_server_string);
3305     foreach my $foreign_server (@cfg_foreign_server_list) {
3306         push(@foreign_server_list, $foreign_server);
3307     }
3309     daemon_log("0 INFO: found foreign server in config file: ".join(", ", @foreign_server_list), 5);
3312 # Perform a DNS lookup for server registration if flag is true
3313 if ($dns_lookup eq "true") {
3314     # Add foreign server from dns
3315     my @tmp_servers;
3316     if (not $server_domain) {
3317         # Try our DNS Searchlist
3318         for my $domain(get_dns_domains()) {
3319             chomp($domain);
3320             my ($tmp_domains, $error_string) = &get_server_addresses($domain);
3321             if(@$tmp_domains) {
3322                 for my $tmp_server(@$tmp_domains) {
3323                     push @tmp_servers, $tmp_server;
3324                 }
3325             }
3326         }
3327         if(@tmp_servers && length(@tmp_servers)==0) {
3328             daemon_log("0 WARNING: no foreign gosa-si-server found in DNS for domain '$server_domain'", 3);
3329         }
3330     } else {
3331         @tmp_servers = &get_server_addresses($server_domain);
3332         if( 0 == @tmp_servers ) {
3333             daemon_log("0 WARNING: no foreign gosa-si-server found in DNS for domain '$server_domain'", 3);
3334         }
3335     }
3337     daemon_log("0 INFO: found foreign server via DNS ".join(", ", @tmp_servers), 5);    
3339     foreach my $server (@tmp_servers) { 
3340         unshift(@foreign_server_list, $server); 
3341     }
3342 } else {
3343     daemon_log("0 INFO: DNS lookup for server registration is disabled", 5);
3347 # eliminate duplicate entries
3348 @foreign_server_list = &del_doubles(@foreign_server_list);
3349 my $all_foreign_server = join(", ", @foreign_server_list);
3350 daemon_log("0 INFO: found foreign server in config file and DNS: '$all_foreign_server'", 5);
3352 # add all found foreign servers to known_server
3353 my $act_timestamp = &get_time();
3354 foreach my $foreign_server (@foreign_server_list) {
3356         # do not add myself to known_server_db
3357         if (&is_local($foreign_server)) { next; }
3358         ######################################
3360     my $res = $known_server_db->add_dbentry( {table=>$known_server_tn, 
3361             primkey=>['hostname'],
3362             hostname=>$foreign_server,
3363             macaddress=>"",
3364             status=>'not_jet_registered',
3365             hostkey=>"none",
3366             loaded_modules => "none", 
3367             timestamp=>$act_timestamp,
3368             } );
3372 # Import all modules
3373 &import_modules;
3375 # Check wether all modules are gosa-si valid passwd check
3376 &password_check;
3378 # Prepare for using Opsi 
3379 if ($opsi_enabled eq "true") {
3380     use JSON::RPC::Client;
3381     use XML::Quote qw(:all);
3382     $opsi_url= "https://".$opsi_admin.":".$opsi_password."@".$opsi_server.":4447/rpc";
3383     $opsi_client = new JSON::RPC::Client;
3387 POE::Component::Server::TCP->new(
3388         Alias => "TCP_SERVER",
3389         Port => $server_port,
3390         ClientInput => sub {
3391                 my ($kernel, $input, $heap, $session) = @_[KERNEL, ARG0, HEAP, SESSION];
3392         my $session_id = $session->ID;
3393         my $remote_ip = $heap->{'remote_ip'};
3394                 push(@msgs_to_decrypt, $input);
3395         &daemon_log("$session_id DEBUG: incoming message from '$remote_ip'", 7);
3396                 $kernel->yield("msg_to_decrypt");
3397         },
3398         InlineStates => {
3399                 msg_to_decrypt => \&msg_to_decrypt,
3400                 next_task => \&next_task,
3401                 task_result => \&handle_task_result,
3402                 task_done   => \&handle_task_done,
3403                 task_debug  => \&handle_task_debug,
3404                 child_reap => sub { "Do nothing special. I'm just a comment, but i'm necessary!"  },
3405         }
3406 );
3408 daemon_log("0 INFO: start socket for incoming xml messages at port '$server_port' ", 1);
3410 # create session for repeatedly checking the job queue for jobs
3411 POE::Session->create(
3412         inline_states => {
3413                 _start => \&session_start,
3414         register_at_foreign_servers => \&register_at_foreign_servers,
3415         sig_handler => \&sig_handler,
3416         next_task => \&next_task,
3417         task_result => \&handle_task_result,
3418         task_done   => \&handle_task_done,
3419         task_debug  => \&handle_task_debug,
3420         watch_for_next_tasks => \&watch_for_next_tasks,
3421         watch_for_new_messages => \&watch_for_new_messages,
3422         watch_for_delivery_messages => \&watch_for_delivery_messages,
3423         watch_for_done_messages => \&watch_for_done_messages,
3424                 watch_for_new_jobs => \&watch_for_new_jobs,
3425         watch_for_modified_jobs => \&watch_for_modified_jobs,
3426         watch_for_done_jobs => \&watch_for_done_jobs,
3427         watch_for_opsi_jobs => \&watch_for_opsi_jobs,
3428         watch_for_old_known_clients => \&watch_for_old_known_clients,
3429         create_packages_list_db => \&run_create_packages_list_db,
3430         create_fai_server_db => \&run_create_fai_server_db,
3431         create_fai_release_db => \&run_create_fai_release_db,
3432                 recreate_packages_db => \&run_recreate_packages_db,
3433         session_run_result => \&session_run_result,
3434         session_run_debug => \&session_run_debug,
3435         session_run_done => \&session_run_done,
3436         child_reap => sub { "Do nothing special. I'm just a comment, but i'm necessary!"  },
3437         }
3438 );
3441 POE::Kernel->run();
3442 exit;