Code

Added patch from JMG to handle zipped ppds, additionally
[gosa.git] / gosa-si / gosa-si-server
1 #!/usr/bin/perl
2 #===============================================================================
3 #
4 #         FILE:  gosa-sd
5 #
6 #        USAGE:  ./gosa-sd
7 #
8 #  DESCRIPTION:
9 #
10 #      OPTIONS:  ---
11 # REQUIREMENTS:  libconfig-inifiles-perl libcrypt-rijndael-perl libxml-simple-perl 
12 #                libdata-dumper-simple-perl libdbd-sqlite3-perl libnet-ldap-perl
13 #                libpoe-perl
14 #         BUGS:  ---
15 #        NOTES:
16 #       AUTHOR:   (Andreas Rettenberger), <rettenberger@gonicus.de>
17 #      COMPANY:
18 #      VERSION:  1.0
19 #      CREATED:  12.09.2007 08:54:41 CEST
20 #     REVISION:  ---
21 #===============================================================================
24 use strict;
25 use warnings;
26 use Getopt::Long;
27 use Config::IniFiles;
28 use POSIX;
30 use Fcntl;
31 use IO::Socket::INET;
32 use IO::Handle;
33 use IO::Select;
34 use Symbol qw(qualify_to_ref);
35 use Crypt::Rijndael;
36 use MIME::Base64;
37 use Digest::MD5  qw(md5 md5_hex md5_base64);
38 use XML::Simple;
39 use Data::Dumper;
40 use Sys::Syslog qw( :DEFAULT setlogsock);
41 use Cwd;
42 use File::Spec;
43 use File::Basename;
44 use File::Find;
45 use File::Copy;
46 use File::Path;
47 use GOSA::DBsqlite;
48 use GOSA::GosaSupportDaemon;
49 use POE qw(Component::Server::TCP Wheel::Run Filter::Reference);
50 use Net::LDAP;
51 use Net::LDAP::Util qw(:escape);
53 my $modules_path = "/usr/lib/gosa-si/modules";
54 use lib "/usr/lib/gosa-si/modules";
56 # TODO es gibt eine globale funktion get_ldap_handle
57 # - ist in einer session dieses ldap handle schon vorhanden, wird es zurückgegeben
58 # - ist es nicht vorhanden, wird es erzeugt, im heap für spätere ldap anfragen gespeichert und zurückgegeben
59 # - sessions die kein ldap handle brauchen, sollen auch keins haben
60 # - wird eine session geschlossen, muss das ldap verbindung vorher beendet werden
61 our $global_kernel;
63 my (%cfg_defaults, $foreground, $verbose, $ping_timeout);
64 my ($bus_activ, $bus, $msg_to_bus, $bus_cipher);
65 my ($server);
66 my ($gosa_server, $job_queue_timeout, $job_queue_loop_delay);
67 my ($messaging_db_loop_delay);
68 my ($known_modules);
69 my ($pid_file, $procid, $pid, $log_file);
70 my ($arp_activ, $arp_fifo);
71 my ($xml);
72 my $sources_list;
73 my $max_clients;
74 my %repo_files=();
75 my $repo_path;
76 my %repo_dirs=();
77 # variables declared in config file are always set to 'our'
78 our (%cfg_defaults, $log_file, $pid_file, 
79     $server_ip, $server_port, $SIPackages_key, 
80     $arp_activ, $gosa_unit_tag,
81     $GosaPackages_key, $gosa_ip, $gosa_port, $gosa_timeout,
82 );
84 # additional variable which should be globaly accessable
85 our $server_address;
86 our $server_mac_address;
87 our $bus_address;
88 our $gosa_address;
89 our $no_bus;
90 our $no_arp;
91 our $verbose;
92 our $forground;
93 our $cfg_file;
94 #our ($ldap_handle, $ldap_uri, $ldap_base, $ldap_admin_dn, $ldap_admin_password, $ldap_server_dn);
95 our ($ldap_uri, $ldap_base, $ldap_admin_dn, $ldap_admin_password, $ldap_server_dn);
98 # specifies the verbosity of the daemon_log
99 $verbose = 0 ;
101 # if foreground is not null, script will be not forked to background
102 $foreground = 0 ;
104 # specifies the timeout seconds while checking the online status of a registrating client
105 $ping_timeout = 5;
107 $no_bus = 0;
108 $bus_activ = "true";
109 $no_arp = 0;
110 my $packages_list_under_construction = "/tmp/packages_list_creation_in_progress";
111 my @packages_list_statements;
112 my $watch_for_new_jobs_in_progress = 0;
114 our $prg= basename($0);
116 # holds all gosa jobs
117 our $job_db;
118 our $job_queue_tn = 'jobs';
119 my $job_queue_file_name;
120 my @job_queue_col_names = ("id INTEGER PRIMARY KEY", 
121                 "timestamp DEFAULT 'none'", 
122                 "status DEFAULT 'none'", 
123                 "result DEFAULT 'none'", 
124                 "progress DEFAULT 'none'", 
125         "headertag DEFAULT 'none'", 
126                 "targettag DEFAULT 'none'", 
127                 "xmlmessage DEFAULT 'none'", 
128                 "macaddress DEFAULT 'none'",
129                 "plainname DEFAULT 'none'",
130                 );
132 # holds all other gosa-sd as well as the gosa-sd-bus
133 our $known_server_db;
134 our $known_server_tn = "known_server";
135 my $known_server_file_name;
136 my @known_server_col_names = ("hostname", "status", "hostkey", "timestamp");
138 # holds all registrated clients
139 our $known_clients_db;
140 our $known_clients_tn = "known_clients";
141 my $known_clients_file_name;
142 my @known_clients_col_names = ("hostname", "status", "hostkey", "timestamp", "macaddress", "events");
144 # holds all logged in user at each client 
145 our $login_users_db;
146 our $login_users_tn = "login_users";
147 my $login_users_file_name;
148 my @login_users_col_names = ("client", "user", "timestamp");
150 # holds all fai server, the debian release and tag
151 our $fai_server_db;
152 our $fai_server_tn = "fai_server"; 
153 my $fai_server_file_name;
154 our @fai_server_col_names = ("timestamp", "server", "release", "sections", "tag"); 
156 our $fai_release_db;
157 our $fai_release_tn = "fai_release"; 
158 my $fai_release_file_name;
159 our @fai_release_col_names = ("timestamp", "release", "class", "type", "state"); 
161 # holds all packages available from different repositories
162 our $packages_list_db;
163 our $packages_list_tn = "packages_list";
164 my $packages_list_file_name;
165 our @packages_list_col_names = ("distribution", "package", "version", "section", "description", "template", "timestamp");
166 my $outdir = "/tmp/packages_list_db";
167 my $arch = "i386"; 
169 # holds all messages which should be delivered to a user
170 our $messaging_db;
171 our $messaging_tn = "messaging"; 
172 our @messaging_col_names = ("id INTEGER", "subject", "message_from", "message_to", 
173         "flag", "direction", "delivery_time", "message", "timestamp" );
174 my $messaging_file_name;
176 # path to directory to store client install log files
177 our $client_fai_log_dir = "/var/log/fai"; 
179 # queue which stores taskes until one of the $max_children children are ready to process the task
180 my @tasks = qw();
181 my $max_children = 2;
184 %cfg_defaults = (
185 "general" => {
186     "log-file" => [\$log_file, "/var/run/".$prg.".log"],
187     "pid-file" => [\$pid_file, "/var/run/".$prg.".pid"],
188     },
189 "bus" => {
190     "activ" => [\$bus_activ, "true"],
191     },
192 "server" => {
193     "port" => [\$server_port, "20081"],
194     "known-clients" => [\$known_clients_file_name, '/var/lib/gosa-si/clients.db' ],
195     "known-servers" => [\$known_server_file_name, '/var/lib/gosa-si/servers.db'],
196     "login-users" => [\$login_users_file_name, '/var/lib/gosa-si/users.db'],
197     "fai-server" => [\$fai_server_file_name, '/var/lib/gosa-si/fai_server.db'],
198     "fai-release" => [\$fai_release_file_name, '/var/lib/gosa-si/fai_release.db'],
199     "packages-list" => [\$packages_list_file_name, '/var/lib/gosa-si/packages.db'],
200     "messaging" => [\$messaging_file_name, '/var/lib/gosa-si/messaging.db'],
201     "source-list" => [\$sources_list, '/etc/apt/sources.list'],
202     "repo-path" => [\$repo_path, '/srv/www/repository'],
203     "ldap-uri" => [\$ldap_uri, ""],
204     "ldap-base" => [\$ldap_base, ""],
205     "ldap-admin-dn" => [\$ldap_admin_dn, ""],
206     "ldap-admin-password" => [\$ldap_admin_password, ""],
207     "gosa-unit-tag" => [\$gosa_unit_tag, ""],
208     "max-clients" => [\$max_clients, 10],
209     },
210 "GOsaPackages" => {
211     "ip" => [\$gosa_ip, "0.0.0.0"],
212     "port" => [\$gosa_port, "20082"],
213     "job-queue" => [\$job_queue_file_name, '/var/lib/gosa-si/jobs.db'],
214     "job-queue-loop-delay" => [\$job_queue_loop_delay, 3],
215     "messaging-db-loop-delay" => [\$messaging_db_loop_delay, 3],
216     "key" => [\$GosaPackages_key, "none"],
217     },
218 "SIPackages" => {
219     "key" => [\$SIPackages_key, "none"],
220     },
221 );
224 #===  FUNCTION  ================================================================
225 #         NAME:  usage
226 #   PARAMETERS:  nothing
227 #      RETURNS:  nothing
228 #  DESCRIPTION:  print out usage text to STDERR
229 #===============================================================================
230 sub usage {
231     print STDERR << "EOF" ;
232 usage: $prg [-hvf] [-c config]
234            -h        : this (help) message
235            -c <file> : config file
236            -f        : foreground, process will not be forked to background
237            -v        : be verbose (multiple to increase verbosity)
238            -no-bus   : starts $prg without connection to bus
239            -no-arp   : starts $prg without connection to arp module
240  
241 EOF
242     print "\n" ;
246 #===  FUNCTION  ================================================================
247 #         NAME:  read_configfile
248 #   PARAMETERS:  cfg_file - string -
249 #      RETURNS:  nothing
250 #  DESCRIPTION:  read cfg_file and set variables
251 #===============================================================================
252 sub read_configfile {
253     my $cfg;
254     if( defined( $cfg_file) && ( (-s $cfg_file) > 0 )) {
255         if( -r $cfg_file ) {
256             $cfg = Config::IniFiles->new( -file => $cfg_file );
257         } else {
258             print STDERR "Couldn't read config file!\n";
259         }
260     } else {
261         $cfg = Config::IniFiles->new() ;
262     }
263     foreach my $section (keys %cfg_defaults) {
264         foreach my $param (keys %{$cfg_defaults{ $section }}) {
265             my $pinfo = $cfg_defaults{ $section }{ $param };
266             ${@$pinfo[ 0 ]} = $cfg->val( $section, $param, @$pinfo[ 1 ] );
267         }
268     }
272 #===  FUNCTION  ================================================================
273 #         NAME:  logging
274 #   PARAMETERS:  level - string - default 'info'
275 #                msg - string -
276 #                facility - string - default 'LOG_DAEMON'
277 #      RETURNS:  nothing
278 #  DESCRIPTION:  function for logging
279 #===============================================================================
280 sub daemon_log {
281     # log into log_file
282     my( $msg, $level ) = @_;
283     if(not defined $msg) { return }
284     if(not defined $level) { $level = 1 }
285     if(defined $log_file){
286         open(LOG_HANDLE, ">>$log_file");
287         if(not defined open( LOG_HANDLE, ">>$log_file" )) {
288             print STDERR "cannot open $log_file: $!";
289             return }
290             chomp($msg);
291                         $msg =~s/\n//g;   # no newlines are allowed in log messages, this is important for later log parsing
292             if($level <= $verbose){
293                 my ($seconds, $minutes, $hours, $monthday, $month,
294                         $year, $weekday, $yearday, $sommertime) = localtime(time);
295                 $hours = $hours < 10 ? $hours = "0".$hours : $hours;
296                 $minutes = $minutes < 10 ? $minutes = "0".$minutes : $minutes;
297                 $seconds = $seconds < 10 ? $seconds = "0".$seconds : $seconds;
298                 my @monthnames = ("Jan", "Feb", "Mar", "Apr", "May", "Jun", "Jul", "Aug", "Sep", "Oct", "Nov", "Dec");
299                 $month = $monthnames[$month];
300                 $monthday = $monthday < 10 ? $monthday = "0".$monthday : $monthday;
301                 $year+=1900;
302                 my $name = $prg;
304                 my $log_msg = "$month $monthday $hours:$minutes:$seconds $name $msg\n";
305                 print LOG_HANDLE $log_msg;
306                 if( $foreground ) { 
307                     print STDERR $log_msg;
308                 }
309             }
310         close( LOG_HANDLE );
311     }
315 #===  FUNCTION  ================================================================
316 #         NAME:  check_cmdline_param
317 #   PARAMETERS:  nothing
318 #      RETURNS:  nothing
319 #  DESCRIPTION:  validates commandline parameter
320 #===============================================================================
321 sub check_cmdline_param () {
322     my $err_config;
323     my $err_counter = 0;
324         if(not defined($cfg_file)) {
325                 $cfg_file = "/etc/gosa-si/server.conf";
326                 if(! -r $cfg_file) {
327                         $err_config = "please specify a config file";
328                         $err_counter += 1;
329                 }
330     }
331     if( $err_counter > 0 ) {
332         &usage( "", 1 );
333         if( defined( $err_config)) { print STDERR "$err_config\n"}
334         print STDERR "\n";
335         exit( -1 );
336     }
340 #===  FUNCTION  ================================================================
341 #         NAME:  check_pid
342 #   PARAMETERS:  nothing
343 #      RETURNS:  nothing
344 #  DESCRIPTION:  handels pid processing
345 #===============================================================================
346 sub check_pid {
347     $pid = -1;
348     # Check, if we are already running
349     if( open(LOCK_FILE, "<$pid_file") ) {
350         $pid = <LOCK_FILE>;
351         if( defined $pid ) {
352             chomp( $pid );
353             if( -f "/proc/$pid/stat" ) {
354                 my($stat) = `cat /proc/$pid/stat` =~ m/$pid \((.+)\).*/;
355                 if( $stat ) {
356                                         daemon_log("ERROR: Already running",1);
357                     close( LOCK_FILE );
358                     exit -1;
359                 }
360             }
361         }
362         close( LOCK_FILE );
363         unlink( $pid_file );
364     }
366     # create a syslog msg if it is not to possible to open PID file
367     if (not sysopen(LOCK_FILE, $pid_file, O_WRONLY|O_CREAT|O_EXCL, 0644)) {
368         my($msg) = "Couldn't obtain lockfile '$pid_file' ";
369         if (open(LOCK_FILE, '<', $pid_file)
370                 && ($pid = <LOCK_FILE>))
371         {
372             chomp($pid);
373             $msg .= "(PID $pid)\n";
374         } else {
375             $msg .= "(unable to read PID)\n";
376         }
377         if( ! ($foreground) ) {
378             openlog( $0, "cons,pid", "daemon" );
379             syslog( "warning", $msg );
380             closelog();
381         }
382         else {
383             print( STDERR " $msg " );
384         }
385         exit( -1 );
386     }
389 #===  FUNCTION  ================================================================
390 #         NAME:  import_modules
391 #   PARAMETERS:  module_path - string - abs. path to the directory the modules 
392 #                are stored
393 #      RETURNS:  nothing
394 #  DESCRIPTION:  each file in module_path which ends with '.pm' and activation 
395 #                state is on is imported by "require 'file';"
396 #===============================================================================
397 sub import_modules {
398     daemon_log(" ", 1);
400     if (not -e $modules_path) {
401         daemon_log("ERROR: cannot find directory or directory is not readable: $modules_path", 1);   
402     }
404     opendir (DIR, $modules_path) or die "ERROR while loading modules from directory $modules_path : $!\n";
405     while (defined (my $file = readdir (DIR))) {
406         if (not $file =~ /(\S*?).pm$/) {
407             next;
408         }
409                 my $mod_name = $1;
411         if( $file =~ /ArpHandler.pm/ ) {
412             if( $no_arp > 0 ) {
413                 next;
414             }
415         }
416         
417         eval { require $file; };
418         if ($@) {
419             daemon_log("ERROR: gosa-si-server could not load module $file", 1);
420             daemon_log("$@", 5);
421                 } else {
422                         my $info = eval($mod_name.'::get_module_info()');
423                         # Only load module if get_module_info() returns a non-null object
424                         if( $info ) {
425                                 my ($input_address, $input_key, $input, $input_active, $input_type) = @{$info};
426                                 $known_modules->{$mod_name} = $info;
427                                 daemon_log("INFO: module $mod_name loaded", 5);
428                         }
429                 }
430     }   
431     close (DIR);
435 #===  FUNCTION  ================================================================
436 #         NAME:  sig_int_handler
437 #   PARAMETERS:  signal - string - signal arose from system
438 #      RETURNS:  noting
439 #  DESCRIPTION:  handels tasks to be done befor signal becomes active
440 #===============================================================================
441 sub sig_int_handler {
442     my ($signal) = @_;
444 #       if (defined($ldap_handle)) {
445 #               $ldap_handle->disconnect;
446 #       }
447     # TODO alle verbliebenden ldap verbindungen aus allen heaps beenden
448     
450     daemon_log("shutting down gosa-si-server", 1);
451     system("kill `ps -C gosa-si-server -o pid=`");
453 $SIG{INT} = \&sig_int_handler;
456 sub check_key_and_xml_validity {
457     my ($crypted_msg, $module_key, $session_id) = @_;
458     my $msg;
459     my $msg_hash;
460     my $error_string;
461     eval{
462         $msg = &decrypt_msg($crypted_msg, $module_key);
464         if ($msg =~ /<xml>/i){
465             $msg =~ s/\s+/ /g;  # just for better daemon_log
466             daemon_log("$session_id DEBUG: decrypted_msg: \n$msg", 8);
467             $msg_hash = $xml->XMLin($msg, ForceArray=>1);
469             ##############
470             # check header
471             if( not exists $msg_hash->{'header'} ) { die "no header specified"; }
472             my $header_l = $msg_hash->{'header'};
473             if( 1 > @{$header_l} ) { die 'empty header tag'; }
474             if( 1 < @{$header_l} ) { die 'more than one header specified'; }
475             my $header = @{$header_l}[0];
476             if( 0 == length $header) { die 'empty string in header tag'; }
478             ##############
479             # check source
480             if( not exists $msg_hash->{'source'} ) { die "no source specified"; }
481             my $source_l = $msg_hash->{'source'};
482             if( 1 > @{$source_l} ) { die 'empty source tag'; }
483             if( 1 < @{$source_l} ) { die 'more than one source specified'; }
484             my $source = @{$source_l}[0];
485             if( 0 == length $source) { die 'source error'; }
487             ##############
488             # check target
489             if( not exists $msg_hash->{'target'} ) { die "no target specified"; }
490             my $target_l = $msg_hash->{'target'};
491             if( 1 > @{$target_l} ) { die 'empty target tag'; }
492         }
493     };
494     if($@) {
495         daemon_log("$session_id DEBUG: do not understand the message: $@", 7);
496         $msg = undef;
497         $msg_hash = undef;
498     }
500     return ($msg, $msg_hash);
504 sub check_outgoing_xml_validity {
505     my ($msg) = @_;
507     my $msg_hash;
508     eval{
509         $msg_hash = $xml->XMLin($msg, ForceArray=>1);
511         ##############
512         # check header
513         my $header_l = $msg_hash->{'header'};
514         if( 1 != @{$header_l} ) {
515             die 'no or more than one headers specified';
516         }
517         my $header = @{$header_l}[0];
518         if( 0 == length $header) {
519             die 'header has length 0';
520         }
522         ##############
523         # check source
524         my $source_l = $msg_hash->{'source'};
525         if( 1 != @{$source_l} ) {
526             die 'no or more than 1 sources specified';
527         }
528         my $source = @{$source_l}[0];
529         if( 0 == length $source) {
530             die 'source has length 0';
531         }
532         unless( $source =~ /^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}:\d+$/ ||
533                 $source =~ /^GOSA$/i ) {
534             die "source '$source' is neither a complete ip-address with port nor 'GOSA'";
535         }
536         
537         ##############
538         # check target  
539         my $target_l = $msg_hash->{'target'};
540         if( 0 == @{$target_l} ) {
541             die "no targets specified";
542         }
543         foreach my $target (@$target_l) {
544             if( 0 == length $target) {
545                 die "target has length 0";
546             }
547             unless( $target =~ /^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}:\d+$/ ||
548                     $target =~ /^GOSA$/i ||
549                     $target =~ /^\*$/ ||
550                     $target =~ /KNOWN_SERVER/i ||
551                     $target =~ /JOBDB/i ||
552                     $target =~ /^([0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2})$/i ){
553                 die "target '$target' is not a complete ip-address with port or a valid target name or a mac-address";
554             }
555         }
556     };
557     if($@) {
558         daemon_log("WARNING: outgoing msg is not gosa-si envelope conform", 5);
559         daemon_log("$@ ".(defined($msg) && length($msg)>0)?$msg:"Empty Message", 8);
560         $msg_hash = undef;
561     }
563     return ($msg_hash);
567 sub input_from_known_server {
568     my ($input, $remote_ip, $session_id) = @_ ;  
569     my ($msg, $msg_hash, $module);
571     my $sql_statement= "SELECT * FROM known_server";
572     my $query_res = $known_server_db->select_dbentry( $sql_statement ); 
574     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
575         my $host_name = $hit->{hostname};
576         if( not $host_name =~ "^$remote_ip") {
577             next;
578         }
579         my $host_key = $hit->{hostkey};
580         daemon_log("$session_id DEBUG: input_from_known_server: host_name: $host_name", 7);
581         daemon_log("DEBUG: input_from_known_server: host_key: $host_key", 7);
583         # check if module can open msg envelope with module key
584         my ($tmp_msg, $tmp_msg_hash) = &check_key_and_xml_validity($input, $host_key, $session_id);
585         if( (!$tmp_msg) || (!$tmp_msg_hash) ) {
586             daemon_log("$session_id DEBUG: input_from_known_server: deciphering raise error", 7);
587             daemon_log("$@", 8);
588             next;
589         }
590         else {
591             $msg = $tmp_msg;
592             $msg_hash = $tmp_msg_hash;
593             $module = "SIPackages";
594             last;
595         }
596     }
598     if( (!$msg) || (!$msg_hash) || (!$module) ) {
599         daemon_log("$session_id DEBUG: Incoming message is not from a known server", 7);
600     }
601   
602     return ($msg, $msg_hash, $module);
606 sub input_from_known_client {
607     my ($input, $remote_ip, $session_id) = @_ ;  
608     my ($msg, $msg_hash, $module);
610     my $sql_statement= "SELECT * FROM known_clients";
611     my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
612     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
613         my $host_name = $hit->{hostname};
614         if( not $host_name =~ /^$remote_ip:\d*$/) {
615                 next;
616                 }
617         my $host_key = $hit->{hostkey};
618         &daemon_log("$session_id DEBUG: input_from_known_client: host_name: $host_name", 7);
619         &daemon_log("$session_id DEBUG: input_from_known_client: host_key: $host_key", 7);
621         # check if module can open msg envelope with module key
622         ($msg, $msg_hash) = &check_key_and_xml_validity($input, $host_key, $session_id);
624         if( (!$msg) || (!$msg_hash) ) {
625             &daemon_log("$session_id DEGUG: input_from_known_client: deciphering raise error", 7);
626             &daemon_log("$@", 8);
627             next;
628         }
629         else {
630             $module = "SIPackages";
631             last;
632         }
633     }
635     if( (!$msg) || (!$msg_hash) || (!$module) ) {
636         &daemon_log("$session_id DEBUG: Incoming message is not from a known client", 7);
637     }
639     return ($msg, $msg_hash, $module);
643 sub input_from_unknown_host {
644     no strict "refs";
645     my ($input, $session_id) = @_ ;
646     my ($msg, $msg_hash, $module);
647     my $error_string;
648     
649         my %act_modules = %$known_modules;
651         while( my ($mod, $info) = each(%act_modules)) {
653         # check a key exists for this module
654         my $module_key = ${$mod."_key"};
655         if( not defined $module_key ) {
656             if( $mod eq 'ArpHandler' ) {
657                 next;
658             }
659             daemon_log("$session_id ERROR: no key specified in config file for $mod", 1);
660             next;
661         }
662         daemon_log("$session_id DEBUG: $mod: $module_key", 7);
664         # check if module can open msg envelope with module key
665         ($msg, $msg_hash) = &check_key_and_xml_validity($input, $module_key, $session_id);
666         if( (not defined $msg) || (not defined $msg_hash) ) {
667             next;
668         }
669         else {
670             $module = $mod;
671             last;
672         }
673     }
675     if( (!$msg) || (!$msg_hash) || (!$module)) {
676         daemon_log("$session_id DEBUG: Incoming message is not from an unknown host", 7);
677     }
679     return ($msg, $msg_hash, $module);
683 sub create_ciphering {
684     my ($passwd) = @_;
685         if((!defined($passwd)) || length($passwd)==0) {
686                 $passwd = "";
687         }
688     $passwd = substr(md5_hex("$passwd") x 32, 0, 32);
689     my $iv = substr(md5_hex('GONICUS GmbH'),0, 16);
690     my $my_cipher = Crypt::Rijndael->new($passwd , Crypt::Rijndael::MODE_CBC());
691     $my_cipher->set_iv($iv);
692     return $my_cipher;
696 sub encrypt_msg {
697     my ($msg, $key) = @_;
698     my $my_cipher = &create_ciphering($key);
699     my $len;
700     {
701             use bytes;
702             $len= 16-length($msg)%16;
703     }
704     $msg = "\0"x($len).$msg;
705     $msg = $my_cipher->encrypt($msg);
706     chomp($msg = &encode_base64($msg));
707     # there are no newlines allowed inside msg
708     $msg=~ s/\n//g;
709     return $msg;
713 sub decrypt_msg {
715     my ($msg, $key) = @_ ;
716     $msg = &decode_base64($msg);
717     my $my_cipher = &create_ciphering($key);
718     $msg = $my_cipher->decrypt($msg); 
719     $msg =~ s/\0*//g;
720     return $msg;
724 sub get_encrypt_key {
725     my ($target) = @_ ;
726     my $encrypt_key;
727     my $error = 0;
729     # target can be in known_server
730     if( not defined $encrypt_key ) {
731         my $sql_statement= "SELECT * FROM known_server WHERE hostname='$target'";
732         my $query_res = $known_server_db->select_dbentry( $sql_statement ); 
733         while( my ($hit_num, $hit) = each %{ $query_res } ) {    
734             my $host_name = $hit->{hostname};
735             if( $host_name ne $target ) {
736                 next;
737             }
738             $encrypt_key = $hit->{hostkey};
739             last;
740         }
741     }
743     # target can be in known_client
744     if( not defined $encrypt_key ) {
745         my $sql_statement= "SELECT * FROM known_clients WHERE hostname='$target'";
746         my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
747         while( my ($hit_num, $hit) = each %{ $query_res } ) {    
748             my $host_name = $hit->{hostname};
749             if( $host_name ne $target ) {
750                 next;
751             }
752             $encrypt_key = $hit->{hostkey};
753             last;
754         }
755     }
757     return $encrypt_key;
761 #===  FUNCTION  ================================================================
762 #         NAME:  open_socket
763 #   PARAMETERS:  PeerAddr string something like 192.168.1.1 or 192.168.1.1:10000
764 #                [PeerPort] string necessary if port not appended by PeerAddr
765 #      RETURNS:  socket IO::Socket::INET
766 #  DESCRIPTION:  open a socket to PeerAddr
767 #===============================================================================
768 sub open_socket {
769     my ($PeerAddr, $PeerPort) = @_ ;
770     if(defined($PeerPort)){
771         $PeerAddr = $PeerAddr.":".$PeerPort;
772     }
773     my $socket;
774     $socket = new IO::Socket::INET(PeerAddr => $PeerAddr,
775             Porto => "tcp",
776             Type => SOCK_STREAM,
777             Timeout => 5,
778             );
779     if(not defined $socket) {
780         return;
781     }
782 #    &daemon_log("DEBUG: open_socket: $PeerAddr", 7);
783     return $socket;
787 #===  FUNCTION  ================================================================
788 #         NAME:  get_ip 
789 #   PARAMETERS:  interface name (i.e. eth0)
790 #      RETURNS:  (ip address) 
791 #  DESCRIPTION:  Uses ioctl to get ip address directly from system.
792 #===============================================================================
793 sub get_ip {
794         my $ifreq= shift;
795         my $result= "";
796         my $SIOCGIFADDR= 0x8915;       # man 2 ioctl_list
797         my $proto= getprotobyname('ip');
799         socket SOCKET, PF_INET, SOCK_DGRAM, $proto
800                 or die "socket: $!";
802         if(ioctl SOCKET, $SIOCGIFADDR, $ifreq) {
803                 my ($if, $sin)    = unpack 'a16 a16', $ifreq;
804                 my ($port, $addr) = sockaddr_in $sin;
805                 my $ip            = inet_ntoa $addr;
807                 if ($ip && length($ip) > 0) {
808                         $result = $ip;
809                 }
810         }
812         return $result;
816 sub get_local_ip_for_remote_ip {
817         my $remote_ip= shift;
818         my $result="0.0.0.0";
820         if($remote_ip =~ /^(\d\d?\d?\.){3}\d\d?\d?$/) {
821                 if($remote_ip eq "127.0.0.1") {
822                         $result = "127.0.0.1";
823                 } else {
824                         my $PROC_NET_ROUTE= ('/proc/net/route');
826                         open(PROC_NET_ROUTE, "<$PROC_NET_ROUTE")
827                                 or die "Could not open $PROC_NET_ROUTE";
829                         my @ifs = <PROC_NET_ROUTE>;
831                         close(PROC_NET_ROUTE);
833                         # Eat header line
834                         shift @ifs;
835                         chomp @ifs;
836                         foreach my $line(@ifs) {
837                                 my ($Iface,$Destination,$Gateway,$Flags,$RefCnt,$Use,$Metric,$Mask,$MTU,$Window,$IRTT)=split(/\s/, $line);
838                                 my $destination;
839                                 my $mask;
840                                 my ($d,$c,$b,$a)=unpack('a2 a2 a2 a2', $Destination);
841                                 $destination= sprintf("%d.%d.%d.%d", hex($a), hex($b), hex($c), hex($d));
842                                 ($d,$c,$b,$a)=unpack('a2 a2 a2 a2', $Mask);
843                                 $mask= sprintf("%d.%d.%d.%d", hex($a), hex($b), hex($c), hex($d));
844                                 if(new NetAddr::IP($remote_ip)->within(new NetAddr::IP($destination, $mask))) {
845                                         # destination matches route, save mac and exit
846                                         $result= &get_ip($Iface);
847                                         last;
848                                 }
849                         }
850                 }
851         } else {
852                 daemon_log("get_local_ip_for_remote_ip was called with a non-ip parameter: $remote_ip", 1);
853         }
854         return $result;
858 sub send_msg_to_target {
859     my ($msg, $address, $encrypt_key, $msg_header, $session_id) = @_ ;
860     my $error = 0;
861     my $header;
862     my $new_status;
863     my $act_status;
864     my ($sql_statement, $res);
865   
866     if( $msg_header ) {
867         $header = "'$msg_header'-";
868     } else {
869         $header = "";
870     }
872         # Patch the source ip
873         if($msg =~ /<source>0\.0\.0\.0:\d*?<\/source>/) {
874                 my $remote_ip = &get_local_ip_for_remote_ip(sprintf("%s", $address =~ /^([0-9\.]*?):.*$/));
875                 $msg =~ s/<source>(0\.0\.0\.0):(\d*?)<\/source>/<source>$remote_ip:$2<\/source>/s;
876         }
878     # encrypt xml msg
879     my $crypted_msg = &encrypt_msg($msg, $encrypt_key);
881     # opensocket
882     my $socket = &open_socket($address);
883     if( !$socket ) {
884         daemon_log("$session_id ERROR: cannot send ".$header."msg to $address , host not reachable", 1);
885         $error++;
886     }
887     
888     if( $error == 0 ) {
889         # send xml msg
890         print $socket $crypted_msg."\n";
892         daemon_log("$session_id INFO: send ".$header."msg to $address", 5);
893         #daemon_log("DEBUG: message:\n$msg", 9);
894         
895     }
897     # close socket in any case
898     if( $socket ) {
899         close $socket;
900     }
902     if( $error > 0 ) { $new_status = "down"; }
903     else { $new_status = $msg_header; }
906     # known_clients
907     $sql_statement = "SELECT * FROM known_clients WHERE hostname='$address'";
908     $res = $known_clients_db->select_dbentry($sql_statement);
909     if( keys(%$res) > 0) {
910         $act_status = $res->{1}->{'status'};
911         if( $act_status eq "down" ) {
912             $sql_statement = "DELETE FROM known_clients WHERE hostname='$address'";
913             $res = $known_clients_db->del_dbentry($sql_statement);
914             daemon_log("$session_id WARNING: failed 2x to send msg to host '$address', delete host from known_clients", 3);
915         } else { 
916             $sql_statement = "UPDATE known_clients SET status='$new_status' WHERE hostname='$address'";
917             $res = $known_clients_db->update_dbentry($sql_statement);
918             if($new_status eq "down"){
919                 daemon_log("$session_id WARNING: set '$address' from status '$act_status' to '$new_status'", 3);
920             } else {
921                 daemon_log("$session_id INFO: set '$address' from status '$act_status' to '$new_status'", 5);
922             }
923         }
924     }
926     # known_server
927     $sql_statement = "SELECT * FROM known_server WHERE hostname='$address'";
928     $res = $known_server_db->select_dbentry($sql_statement);
929     if( keys(%$res) > 0 ) {
930         $act_status = $res->{1}->{'status'};
931         if( $act_status eq "down" ) {
932             $sql_statement = "DELETE FROM known_server WHERE hostname='$address'";
933             $res = $known_server_db->del_dbentry($sql_statement);
934             daemon_log("$session_id WARNING: failed 2x to a send msg to host '$address', delete host from known_server", 3);
935         } 
936         else { 
937             $sql_statement = "UPDATE known_server SET status='$new_status' WHERE hostname='$address'";
938             $res = $known_server_db->update_dbentry($sql_statement);
939             if($new_status eq "down"){
940                 daemon_log("$session_id WARNING: set '$address' from status '$act_status' to '$new_status'", 3);
941             }
942             else {
943                 daemon_log("$session_id INFO: set '$address' from status '$act_status' to '$new_status'", 5);
944             }
945         }
946     }
947     return $error; 
951 sub update_jobdb_status_for_send_msgs {
952     my ($answer, $error) = @_;
953     if( $answer =~ /<jobdb_id>(\d+)<\/jobdb_id>/ ) {
954         my $jobdb_id = $1;
955             
956         # sending msg faild
957         if( $error ) {
958             if (not $answer =~ /<header>trigger_action_reinstall<\/header>/) {
959                 my $sql_statement = "UPDATE $job_queue_tn ".
960                     "SET status='error', result='can not deliver msg, please consult log file' ".
961                     "WHERE id=$jobdb_id";
962                 my $res = $job_db->update_dbentry($sql_statement);
963             }
965         # sending msg was successful
966         } else {
967             my $sql_statement = "UPDATE $job_queue_tn ".
968                 "SET status='done' ".
969                 "WHERE id=$jobdb_id AND status='processed'";
970             my $res = $job_db->update_dbentry($sql_statement);
971         }
972     }
975 sub _start {
976     my ($kernel) = $_[KERNEL];
977     &trigger_db_loop($kernel);
978     $global_kernel = $kernel;
979         $kernel->yield('create_fai_server_db', $fai_server_tn );
980         $kernel->yield('create_fai_release_db', $fai_release_tn );
981         $kernel->sig(USR1 => "sig_handler");
982         $kernel->sig(USR2 => "create_packages_list_db");
985 sub sig_handler {
986         my ($kernel, $signal) = @_[KERNEL, ARG0] ;
987         daemon_log("0 INFO got signal '$signal'", 1); 
988         $kernel->sig_handled();
989         return;
992 sub next_task {
993     my ($session, $heap) = @_[SESSION, HEAP];
995     while ( keys( %{ $heap->{task} } ) < $max_children ) {
996         my $next_task = shift @tasks;
997         last unless defined $next_task;
999         my $task = POE::Wheel::Run->new(
1000                 Program => sub { process_task($session, $heap, $next_task) },
1001                 StdioFilter => POE::Filter::Reference->new(),
1002                 StdoutEvent  => "task_result",
1003                 StderrEvent  => "task_debug",
1004                 CloseEvent   => "task_done",
1005                );
1007         $heap->{task}->{ $task->ID } = $task;
1008     }
1011 sub handle_task_result {
1012     my ($kernel, $heap, $result) = @_[KERNEL, HEAP, ARG0];
1013     my $client_answer = $result->{'answer'};
1014     if( $client_answer =~ s/session_id=(\d+)$// ) {
1015         my $session_id = $1;
1016         if( defined $session_id ) {
1017             my $session_reference = $kernel->ID_id_to_session($session_id);
1018             if( defined $session_reference ) {
1019                 $heap = $session_reference->get_heap();
1020             }
1021         }
1023         if(exists $heap->{'client'}) {
1024             $heap->{'client'}->put($client_answer);
1025         }
1026     }
1027     $kernel->sig(CHLD => "child_reap");
1030 sub handle_task_debug {
1031     my $result = $_[ARG0];
1032     print STDERR "$result\n";
1035 sub handle_task_done {
1036     my ( $kernel, $heap, $task_id ) = @_[ KERNEL, HEAP, ARG0 ];
1037     delete $heap->{task}->{$task_id};
1038     $kernel->yield("next_task");
1041 sub process_task {
1042     no strict "refs";
1043     my ($session, $heap, $input) = @_;
1044     my $session_id = $session->ID;
1045     my ($msg, $msg_hash, $module);
1046     my $error = 0;
1047     my $answer_l;
1048     my ($answer_header, @answer_target_l, $answer_source);
1049     my $client_answer = "";
1051     daemon_log("", 5); 
1052     daemon_log("$session_id INFO: Incoming msg with session ID $session_id from '".$heap->{'remote_ip'}."'", 5);
1053     #daemon_log("$session_id DEBUG: Incoming msg:\n$input", 9);
1055     ####################
1056     # check incoming msg
1057     # msg is from a new client or gosa
1058     ($msg, $msg_hash, $module) = &input_from_unknown_host($input, $session_id);
1059     # msg is from a gosa-si-server or gosa-si-bus
1060     if(( !$msg ) || ( !$msg_hash ) || ( !$module )){
1061         ($msg, $msg_hash, $module) = &input_from_known_server($input, $heap->{'remote_ip'}, $session_id);
1062     }
1063     # msg is from a gosa-si-client
1064     if(( !$msg ) || ( !$msg_hash ) || ( !$module )){
1065         ($msg, $msg_hash, $module) = &input_from_known_client($input, $heap->{'remote_ip'}, $session_id);
1066     }
1067     # an error occurred
1068     if(( !$msg ) || ( !$msg_hash ) || ( !$module )){
1069         # if an incoming msg could not be decrypted (maybe a wrong key), send client a ping. If the client
1070         # could not understand a msg from its server the client cause a re-registering process
1071         daemon_log("$session_id INFO cannot understand incoming msg, send 'ping'-msg to all host with ip '".$heap->{remote_ip}."' to cause a re-registering of the client if necessary", 5);
1072         my $sql_statement = "SELECT * FROM $main::known_clients_tn WHERE (hostname LIKE '".$heap->{'remote_ip'}."%')";
1073         my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
1074         while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1075             my $host_name = $hit->{'hostname'};
1076             my $host_key = $hit->{'hostkey'};
1077             my $ping_msg = "<xml> <header>gosa_ping</header> <source>$server_address</source> <target>$host_name</target></xml>";
1078             my $error = &send_msg_to_target($ping_msg, $host_name, $host_key, "gosa_ping", $session_id);
1079             &update_jobdb_status_for_send_msgs($ping_msg, $error);
1080         }
1081         $error++;
1082     }
1084     ######################
1085     # process incoming msg
1086     if( $error == 0) {
1087         daemon_log("$session_id INFO: Incoming msg with header '".@{$msg_hash->{'header'}}[0].
1088                                 "' from '".$heap->{'remote_ip'}."'", 5); 
1089         daemon_log("$session_id DEBUG: Processing module ".$module, 7);
1090         $answer_l = &{ $module."::process_incoming_msg" }($msg, $msg_hash, $session_id);
1092         if ( 0 < @{$answer_l} ) {
1093             my $answer_str = join("\n", @{$answer_l});
1094             daemon_log("$session_id DEBUG: $module: Got answer from module: \n".$answer_str,8);
1095         } else {
1096             daemon_log("$session_id DEBUG: $module: Got no answer from module!" ,8);
1097         }
1099     }
1100     if( !$answer_l ) { $error++ };
1102     ########
1103     # answer
1104     if( $error == 0 ) {
1106         foreach my $answer ( @{$answer_l} ) {
1107             # for each answer in answer list
1108             
1109             # check outgoing msg to xml validity
1110             my $answer_hash = &check_outgoing_xml_validity($answer);
1111             if( not defined $answer_hash ) {
1112                 next;
1113             }
1114             
1115             $answer_header = @{$answer_hash->{'header'}}[0];
1116             @answer_target_l = @{$answer_hash->{'target'}};
1117             $answer_source = @{$answer_hash->{'source'}}[0];
1119             # deliver msg to all targets 
1120             foreach my $answer_target ( @answer_target_l ) {
1122                 # targets of msg are all gosa-si-clients in known_clients_db
1123                 if( $answer_target eq "*" ) {
1124                     # answer is for all clients
1125                     my $sql_statement= "SELECT * FROM known_clients";
1126                     my $query_res = $known_clients_db->select_dbentry( $sql_statement ); 
1127                     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1128                         my $host_name = $hit->{hostname};
1129                         my $host_key = $hit->{hostkey};
1130                         my $error = &send_msg_to_target($answer, $host_name, $host_key, $answer_header, $session_id);
1131                         &update_jobdb_status_for_send_msgs($answer, $error);
1132                     }
1133                 }
1135                 # targets of msg are all gosa-si-server in known_server_db
1136                 elsif( $answer_target eq "KNOWN_SERVER" ) {
1137                     # answer is for all server in known_server
1138                     my $sql_statement= "SELECT * FROM known_server";
1139                     my $query_res = $known_server_db->select_dbentry( $sql_statement ); 
1140                     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1141                         my $host_name = $hit->{hostname};
1142                         my $host_key = $hit->{hostkey};
1143                         $answer =~ s/KNOWN_SERVER/$host_name/g;
1144                         my $error = &send_msg_to_target($answer, $host_name, $host_key, $answer_header, $session_id);
1145                         &update_jobdb_status_for_send_msgs($answer, $error);
1146                     }
1147                 }
1149                 # target of msg is GOsa
1150                                 elsif( $answer_target eq "GOSA" ) {
1151                                         my $session_id = ($1) if $answer =~ /<session_id>(\d+?)<\/session_id>/;
1152                                         my $add_on = "";
1153                     if( defined $session_id ) {
1154                         $add_on = ".session_id=$session_id";
1155                     }
1156                     # answer is for GOSA and has to returned to connected client
1157                     my $gosa_answer = &encrypt_msg($answer, $GosaPackages_key);
1158                     $client_answer = $gosa_answer.$add_on;
1159                 }
1161                 # target of msg is job queue at this host
1162                 elsif( $answer_target eq "JOBDB") {
1163                     $answer =~ /<header>(\S+)<\/header>/;   
1164                     my $header;
1165                     if( defined $1 ) { $header = $1; }
1166                     my $error = &send_msg_to_target($answer, $server_address, $GosaPackages_key, $header, $session_id);
1167                     &update_jobdb_status_for_send_msgs($answer, $error);
1168                 }
1170                 # target of msg is a mac address
1171                 elsif( $answer_target =~ /^([0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2}:[0-9a-f]{2})$/i ) {
1172                     daemon_log("$session_id INFO: target is mac address '$answer_target', looking for host in known_clients", 5);
1173                     my $sql_statement = "SELECT * FROM known_clients WHERE macaddress LIKE '$answer_target'";
1174                     my $query_res = $known_clients_db->select_dbentry( $sql_statement );
1175                     my $found_ip_flag = 0;
1176                     while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1177                         my $host_name = $hit->{hostname};
1178                         my $host_key = $hit->{hostkey};
1179                         $answer =~ s/$answer_target/$host_name/g;
1180                         daemon_log("$session_id INFO: found host '$host_name', associated to '$answer_target'", 5);
1181                         my $error = &send_msg_to_target($answer, $host_name, $host_key, $answer_header, $session_id);
1182                         &update_jobdb_status_for_send_msgs($answer, $error);
1183                         $found_ip_flag++ ;
1184                     }   
1185                     if( $found_ip_flag == 0) {
1186                         daemon_log("$session_id WARNING: no host found in known_clients with mac address '$answer_target'", 3);
1187                         if( $bus_activ eq "true" ) { 
1188                             daemon_log("$session_id INFO: try to forward msg '$answer_header' to bus '$bus_address'", 5);
1189                             my $sql_statement = "SELECT * FROM known_server WHERE hostname='$bus_address'";
1190                             my $query_res = $known_server_db->select_dbentry( $sql_statement );
1191                             while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1192                                 my $bus_address = $hit->{hostname};
1193                                 my $bus_key = $hit->{hostkey};
1194                                 my $error = &send_msg_to_target($answer, $bus_address, $bus_key, $answer_header, $session_id);
1195                                 &update_jobdb_status_for_send_msgs($answer, $error);
1196                                 last;
1197                             }
1198                         }
1200                     }
1202                 #  answer is for one specific host   
1203                 } else {
1204                     # get encrypt_key
1205                     my $encrypt_key = &get_encrypt_key($answer_target);
1206                     if( not defined $encrypt_key ) {
1207                         # unknown target, forward msg to bus
1208                         daemon_log("$session_id WARNING: unknown target '$answer_target'", 3);
1209                         if( $bus_activ eq "true" ) { 
1210                             daemon_log("$session_id INFO: try to forward msg '$answer_header' to bus '$bus_address'", 5);
1211                             my $sql_statement = "SELECT * FROM known_server WHERE hostname='$bus_address'";
1212                             my $query_res = $known_server_db->select_dbentry( $sql_statement );
1213                             my $res_length = keys( %{$query_res} );
1214                             if( $res_length == 0 ){
1215                                 daemon_log("$session_id WARNING: send '$answer_header' to '$bus_address' failed, ".
1216                                         "no bus found in known_server", 3);
1217                             }
1218                             else {
1219                                 while( my ($hit_num, $hit) = each %{ $query_res } ) {    
1220                                     my $bus_key = $hit->{hostkey};
1221                                     my $error = &send_msg_to_target($answer, $bus_address, $bus_key, $answer_header,$session_id );
1222                                     &update_jobdb_status_for_send_msgs($answer, $error);
1223                                 }
1224                             }
1225                         }
1226                         next;
1227                     }
1228                     my $error = &send_msg_to_target($answer, $answer_target, $encrypt_key, $answer_header,$session_id);
1229                     &update_jobdb_status_for_send_msgs($answer, $error);
1230                 }
1231             }
1232         }
1233     }
1235     my $filter = POE::Filter::Reference->new();
1236     my %result = ( 
1237             status => "seems ok to me",
1238             answer => $client_answer,
1239             );
1241     my $output = $filter->put( [ \%result ] );
1242     print @$output;
1248 sub trigger_db_loop {
1249         my ($kernel) = @_ ;
1250         $kernel->delay_set('watch_for_new_jobs', $job_queue_loop_delay);
1251         $kernel->delay_set('watch_for_done_jobs', $job_queue_loop_delay); 
1252         $kernel->delay_set('watch_for_new_messages', $messaging_db_loop_delay);
1253     $kernel->delay_set('watch_for_delivery_messages', $messaging_db_loop_delay);
1254         $kernel->delay_set('watch_for_done_messages', $messaging_db_loop_delay);
1258 sub watch_for_done_jobs {
1259     my ($kernel,$heap) = @_[KERNEL, HEAP];
1261     my $sql_statement = "SELECT * FROM ".$job_queue_tn.
1262         " WHERE status='done'";
1263         my $res = $job_db->select_dbentry( $sql_statement );
1265     while( my ($id, $hit) = each %{$res} ) {
1266         my $jobdb_id = $hit->{id};
1267         my $sql_statement = "DELETE FROM $job_queue_tn WHERE id=$jobdb_id"; 
1268         my $res = $job_db->del_dbentry($sql_statement); 
1269     }
1271     $kernel->delay_set('watch_for_done_jobs',$job_queue_loop_delay);
1275 sub watch_for_new_jobs {
1276         if($watch_for_new_jobs_in_progress == 0) {
1277                 $watch_for_new_jobs_in_progress = 1;
1278                 my ($kernel,$heap) = @_[KERNEL, HEAP];
1280                 # check gosa job queue for jobs with executable timestamp
1281                 my $timestamp = &get_time();
1282                 my $sql_statement = "SELECT * FROM $job_queue_tn WHERE status='waiting' AND (CAST (timestamp AS INTEGER)) < $timestamp ORDER BY timestamp";
1283                 my $res = $job_db->exec_statement( $sql_statement );
1285                 # Merge all new jobs that would do the same actions
1286                 my @drops;
1287                 my $hits;
1288                 foreach my $hit (reverse @{$res} ) {
1289                         my $macaddress= lc @{$hit}[8];
1290                         my $headertag= @{$hit}[5];
1291                         if(
1292                                 defined($hits->{$macaddress}) &&
1293                                 defined($hits->{$macaddress}->{$headertag}) &&
1294                                 defined($hits->{$macaddress}->{$headertag}[0])
1295                         ) {
1296                                 push @drops, "DELETE FROM $job_queue_tn WHERE id = $hits->{$macaddress}->{$headertag}[0]";
1297                         }
1298                         $hits->{$macaddress}->{$headertag}= $hit;
1299                 }
1301                 # Delete new jobs with a matching job in state 'processing'
1302                 foreach my $macaddress (keys %{$hits}) {
1303                         foreach my $jobdb_headertag (keys %{$hits->{$macaddress}}) {
1304                                 my $jobdb_id = @{$hits->{$macaddress}->{$jobdb_headertag}}[0];
1305                                 if(defined($jobdb_id)) {
1306                                         my $sql_statement = "SELECT * FROM $job_queue_tn WHERE macaddress LIKE '$macaddress' AND headertag='$jobdb_headertag' AND status='processing'";
1307                                         my $res = $job_db->exec_statement( $sql_statement );
1308                                         foreach my $hit (@{$res}) {
1309                                                 push @drops, "DELETE FROM $job_queue_tn WHERE id=$jobdb_id";
1310                                         }
1311                                 } else {
1312                                         daemon_log("J ERROR: Job without id exists for macaddress $macaddress!", 1);
1313                                 }
1314                         }
1315                 }
1317                 # Commit deletion
1318                 $job_db->exec_statementlist(\@drops);
1320                 # Look for new jobs that could be executed
1321                 foreach my $macaddress (keys %{$hits}) {
1323                         # Look if there is an executing job
1324                         my $sql_statement = "SELECT * FROM $job_queue_tn WHERE macaddress LIKE '$macaddress' AND status='processing'";
1325                         my $res = $job_db->exec_statement( $sql_statement );
1327                         # Skip new jobs for host if there is a processing job
1328                         if(defined($res) and defined @{$res}[0]) {
1329                                 next;
1330                         }
1332                         foreach my $jobdb_headertag (keys %{$hits->{$macaddress}}) {
1333                                 my $jobdb_id = @{$hits->{$macaddress}->{$jobdb_headertag}}[0];
1334                                 if(defined($jobdb_id)) {
1335                                         my $job_msg = @{$hits->{$macaddress}->{$jobdb_headertag}}[7];
1337                                         daemon_log("J DEBUG: its time to execute $job_msg", 7);
1338                                         my $sql_statement = "SELECT * FROM known_clients WHERE macaddress LIKE '$macaddress'";
1339                                         my $res_hash = $known_clients_db->select_dbentry( $sql_statement );
1341                                         # expect macaddress is unique!!!!!!
1342                                         my $target = $res_hash->{1}->{hostname};
1344                                         # change header
1345                                         $job_msg =~ s/<header>job_/<header>gosa_/;
1347                                         # add sqlite_id
1348                                         $job_msg =~ s/<\/xml>$/<jobdb_id>$jobdb_id<\/jobdb_id><\/xml>/;
1350                                         $job_msg =~ /<header>(\S+)<\/header>/;
1351                                         my $header = $1 ;
1352                                         my $func_error = &send_msg_to_target($job_msg, $server_address, $GosaPackages_key, $header, "J");
1354                                         # update status in job queue to 'processing'
1355                                         $sql_statement = "UPDATE $job_queue_tn SET status='processing' WHERE id=$jobdb_id";
1356                                         my $res = $job_db->update_dbentry($sql_statement);
1357 # TODO: abfangen ob alles in ordnung ist oder nicht, wenn nicht error schmeißen                                        
1359                                         # We don't want parallel processing
1360                                         last;
1361                                 }
1362                         }
1363                 }
1365                 $watch_for_new_jobs_in_progress = 0;
1366                 $kernel->delay_set('watch_for_new_jobs', $job_queue_loop_delay);
1367         }
1371 sub watch_for_new_messages {
1372     my ($kernel,$heap) = @_[KERNEL, HEAP];
1373     my @coll_user_msg;   # collection list of outgoing messages
1374     
1375     # check messaging_db for new incoming messages with executable timestamp
1376     my $timestamp = &get_time();
1377     my $sql_statement = "SELECT * FROM $messaging_tn WHERE ( (CAST(timestamp AS INTEGER))<$timestamp AND flag='n' AND direction='in' )";
1378     my $res = $messaging_db->exec_statement( $sql_statement );
1379         foreach my $hit (@{$res}) {
1381         # create outgoing messages
1382         my $message_to = @{$hit}[3];
1384         # translate message_to to plain login name
1385 # TODO implement reciever translation
1386         my @reciever_l = split(/,/, $message_to);  
1387         my $message_id = @{$hit}[0];
1389         #add each outgoing msg to messaging_db
1390         my $reciever;
1391         foreach $reciever (@reciever_l) {
1392             my $sql_statement = "INSERT INTO $messaging_tn (id, subject, message_from, message_to, flag, direction, delivery_time, message, timestamp) ".
1393                 "VALUES ('".
1394                 $message_id."', '".    # id
1395                 @{$hit}[1]."', '".     # subject
1396                 @{$hit}[2]."', '".     # message_from
1397                 $reciever."', '".      # message_to
1398                 "none"."', '".         # flag
1399                 "out"."', '".          # direction
1400                 @{$hit}[6]."', '".     # delivery_time
1401                 @{$hit}[7]."', '".     # message
1402                 $timestamp."'".     # timestamp
1403                 ")";
1404             &daemon_log("M DEBUG: $sql_statement", 1);
1405             my $res = $messaging_db->exec_statement($sql_statement);
1406             &daemon_log("M INFO: message '".@{$hit}[0]."' is prepared for delivery to reciever '$reciever'", 5);
1407         }
1409         # set incoming message to flag d=deliverd
1410         $sql_statement = "UPDATE $messaging_tn SET flag='p' WHERE id='$message_id'"; 
1411         &daemon_log("M DEBUG: $sql_statement", 7);
1412         $res = $messaging_db->update_dbentry($sql_statement);
1413         &daemon_log("M INFO: message '$message_id' is set to flag 'p' (processed)", 5);
1414     }
1416     $kernel->delay_set('watch_for_new_messages', $messaging_db_loop_delay); 
1417     return;
1420 sub watch_for_delivery_messages {
1421     my ($kernel, $heap) = @_[KERNEL, HEAP];
1423     # select outgoing messages
1424     my $sql_statement = "SELECT * FROM $messaging_tn WHERE ( flag='p' AND direction='out' )";
1425     #&daemon_log("0 DEBUG: $sql", 7);
1426     my $res = $messaging_db->exec_statement( $sql_statement );
1427     
1428     # build out msg for each    usr
1429     foreach my $hit (@{$res}) {
1430         my $receiver = @{$hit}[3];
1431         my $msg_id = @{$hit}[0];
1432         my $subject = @{$hit}[1];
1433         my $message = @{$hit}[7];
1435         # resolve usr -> host where usr is logged in
1436         my $sql = "SELECT * FROM $login_users_tn WHERE (user='$receiver')"; 
1437         #&daemon_log("0 DEBUG: $sql", 7);
1438         my $res = $login_users_db->exec_statement($sql);
1440         # reciver is logged in nowhere
1441         if (not ref(@$res[0]) eq "ARRAY") { next; }    
1443         # receiver is logged in at host
1444         my $receiver_host = @{@{$res}[0]}[0];
1446         # fetch key to encrypt msg propperly for usr/host
1447         $sql = "SELECT * FROM $known_clients_tn WHERE (hostname='$receiver_host')";
1448         &daemon_log("0 DEBUG: $sql", 7);
1449         $res = $known_clients_db->exec_statement($sql);
1450         my $receiver_key = @{@{$res}[0]}[2];
1452         my %data = ('subject' => $subject, 'message' => $message, 'usr' => $receiver);
1453         my $out_msg = &build_msg("usr_msg", $server_address, $receiver_host, \%data ); 
1454         my $error_state = &send_msg_to_target($out_msg, $receiver_host, $receiver_key, "usr_msg", 0); 
1456         if ($error_state == 0) {
1457             # set outgoing msg at db to deliverd
1458             my $sql = "UPDATE $messaging_tn SET flag='d' WHERE (id='$msg_id' AND direction='out' AND message_to='$receiver')"; 
1459             &daemon_log("0 DEBUG: $sql", 7);
1460             my $res = $messaging_db->exec_statement($sql); 
1461         }
1462     }
1464     $kernel->delay_set('watch_for_delivery_messages', $messaging_db_loop_delay); 
1465     return;
1469 sub watch_for_done_messages {
1470     my ($kernel,$heap) = @_[KERNEL, HEAP];
1472     my $sql = "SELECT * FROM $messaging_tn WHERE (flag='p' AND direction='in')"; 
1473     #&daemon_log("0 DEBUG: $sql", 7);
1474     my $res = $messaging_db->exec_statement($sql); 
1476     foreach my $hit (@{$res}) {
1477         my $msg_id = @{$hit}[0];
1479         my $sql = "SELECT * FROM $messaging_tn WHERE (id='$msg_id' AND direction='out' AND (NOT flag='s'))"; 
1480         #&daemon_log("0 DEBUG: $sql", 7); 
1481         my $res = $messaging_db->exec_statement($sql);
1483         # not all usr msgs have been seen till now
1484         if ( ref(@$res[0]) eq "ARRAY") { next; }
1485         
1486         $sql = "DELETE FROM $messaging_tn WHERE (id='$msg_id')"; 
1487         #&daemon_log("0 DEBUG: $sql", 7);
1488         $res = $messaging_db->exec_statement($sql);
1489     
1490     }
1492     $kernel->delay_set('watch_for_done_messages', $messaging_db_loop_delay); 
1493     return;
1497 sub get_ldap_handle {
1498         my ($session_id) = @_;
1499         my $heap;
1500         my $ldap_handle;
1502         if (not defined $session_id ) { $session_id = 0 };
1503         if ($session_id =~ /[^0-9]*/) { $session_id = 0 };
1505         if ($session_id == 0) {
1506                 daemon_log("$session_id DEBUG: get_ldap_handle invoked without a session_id, create a new ldap_handle", 7); 
1507                 $ldap_handle = Net::LDAP->new( $ldap_uri );
1508                 $ldap_handle->bind($ldap_admin_dn, password => $ldap_admin_password); 
1510         } else {
1511                 my $session_reference = $global_kernel->ID_id_to_session($session_id);
1512                 if( defined $session_reference ) {
1513                         $heap = $session_reference->get_heap();
1514                 }
1516                 if (not defined $heap) {
1517                         daemon_log("$session_id DEBUG: cannot get heap for session_id '$session_id'", 7); 
1518                         return;
1519                 }
1521                 # TODO: This "if" is nonsense, because it doesn't prove that the
1522                 #       used handle is still valid - or if we've to reconnect...
1523                 #if (not exists $heap->{ldap_handle}) {
1524                         $ldap_handle = Net::LDAP->new( $ldap_uri );
1525                         $ldap_handle->bind($ldap_admin_dn, password => $ldap_admin_password); 
1526                         $heap->{ldap_handle} = $ldap_handle;
1527                 #}
1528         }
1529         return $ldap_handle;
1533 sub change_fai_state {
1534     my ($st, $targets, $session_id) = @_;
1535     $session_id = 0 if not defined $session_id;
1536     # Set FAI state to localboot
1537     my %mapActions= (
1538         reboot    => '',
1539         update    => 'softupdate',
1540         localboot => 'localboot',
1541         reinstall => 'install',
1542         rescan    => '',
1543         wake      => '',
1544         memcheck  => 'memcheck',
1545         sysinfo   => 'sysinfo',
1546         install   => 'install',
1547     );
1549     # Return if this is unknown
1550     if (!exists $mapActions{ $st }){
1551         daemon_log("$session_id ERROR: unknown action '$st', can not translate ot FAIstate", 1); 
1552       return;
1553     }
1555     my $state= $mapActions{ $st };
1557     my $ldap_handle = &get_ldap_handle($session_id);
1558     if( defined($ldap_handle) ) {
1560       # Build search filter for hosts
1561         my $search= "(&(objectClass=GOhard)";
1562         foreach (@{$targets}){
1563             $search.= "(macAddress=$_)";
1564         }
1565         $search.= ")";
1567       # If there's any host inside of the search string, procress them
1568         if (!($search =~ /macAddress/)){
1569             daemon_log("$session_id ERROR: no macAddress found in filter statement for LDAP search: '$search'", 1);    
1570             return;
1571         }
1573       # Perform search for Unit Tag
1574       my $mesg = $ldap_handle->search(
1575           base   => $ldap_base,
1576           scope  => 'sub',
1577           attrs  => ['dn', 'FAIstate', 'objectClass'],
1578           filter => "$search"
1579           );
1581           if ($mesg->count) {
1582                   my @entries = $mesg->entries;
1583                   foreach my $entry (@entries) {
1584                           # Only modify entry if it is not set to '$state'
1585                           if ($entry->get_value("FAIstate") ne "$state"){
1586                                   daemon_log("$session_id INFO: Setting FAIstate to '$state' for ".$entry->dn, 5);
1587                                   my $result;
1588                                   my %tmp = map { $_ => 1 } $entry->get_value("objectClass");
1589                                   if (exists $tmp{'FAIobject'}){
1590                                           if ($state eq ''){
1591                                                   $result= $ldap_handle->modify($entry->dn, changes => [
1592                                                           delete => [ FAIstate => [] ] ]);
1593                                           } else {
1594                                                   $result= $ldap_handle->modify($entry->dn, changes => [
1595                                                           replace => [ FAIstate => $state ] ]);
1596                                           }
1597                                   } elsif ($state ne ''){
1598                                           $result= $ldap_handle->modify($entry->dn, changes => [
1599                                                   add     => [ objectClass => 'FAIobject' ],
1600                                                   add     => [ FAIstate => $state ] ]);
1601                                   }
1603                                   # Errors?
1604                                   if ($result->code){
1605                                           daemon_log("$session_id Error: Setting FAIstate to '$state' for ".$entry->dn. "failed: ".$result->error, 1);
1606                                   }
1607                           } else {
1608                                   daemon_log("$session_id DEBUG FAIstate at host '".$entry->dn."' already at state '$st'", 7); 
1609                           }  
1610                   }
1611           }
1612     # if no ldap handle defined
1613     } else {
1614         daemon_log("$session_id ERROR: no LDAP handle defined for update FAIstate", 1); 
1615     }
1620 sub change_goto_state {
1621     my ($st, $targets, $session_id) = @_;
1622     $session_id = 0  if not defined $session_id;
1624     # Switch on or off?
1625     my $state= $st eq 'active' ? 'active': 'locked';
1627     my $ldap_handle = &get_ldap_handle($session_id);
1628     if( defined($ldap_handle) ) {
1630       # Build search filter for hosts
1631       my $search= "(&(objectClass=GOhard)";
1632       foreach (@{$targets}){
1633         $search.= "(macAddress=$_)";
1634       }
1635       $search.= ")";
1637       # If there's any host inside of the search string, procress them
1638       if (!($search =~ /macAddress/)){
1639         return;
1640       }
1642       # Perform search for Unit Tag
1643       my $mesg = $ldap_handle->search(
1644           base   => $ldap_base,
1645           scope  => 'sub',
1646           attrs  => ['dn', 'gotoMode'],
1647           filter => "$search"
1648           );
1650       if ($mesg->count) {
1651         my @entries = $mesg->entries;
1652         foreach my $entry (@entries) {
1654           # Only modify entry if it is not set to '$state'
1655           if ($entry->get_value("gotoMode") ne $state){
1657             daemon_log("$session_id INFO: Setting gotoMode to '$state' for ".$entry->dn, 5);
1658             my $result;
1659             $result= $ldap_handle->modify($entry->dn, changes => [
1660                                                 replace => [ gotoMode => $state ] ]);
1662             # Errors?
1663             if ($result->code){
1664               &daemon_log("$session_id Error: Setting gotoMode to '$state' for ".$entry->dn. "failed: ".$result->error, 1);
1665             }
1667           }
1668         }
1669       }
1671     }
1675 sub run_create_fai_server_db {
1676     my ($kernel, $session, $heap, $table_name) = @_[KERNEL, SESSION, HEAP, ARG0];
1677     my $session_id = $session->ID;
1678     my $task = POE::Wheel::Run->new(
1679             Program => sub { &create_fai_server_db($table_name,$kernel, undef, $session_id) },
1680             StdoutEvent  => "session_run_result",
1681             StderrEvent  => "session_run_debug",
1682             CloseEvent   => "session_run_done",
1683             );
1685     $heap->{task}->{ $task->ID } = $task;
1686     return;
1690 sub create_fai_server_db {
1691     my ($table_name, $kernel, $dont_create_packages_list, $session_id) = @_;
1692         my $result;
1694         if (not defined $session_id) { $session_id = 0; }
1695     my $ldap_handle = &get_ldap_handle();
1696         if(defined($ldap_handle)) {
1697                 daemon_log("$session_id INFO: create_fai_server_db: start", 5);
1698                 my $mesg= $ldap_handle->search(
1699                         base   => $ldap_base,
1700                         scope  => 'sub',
1701                         attrs  => ['FAIrepository', 'gosaUnitTag'],
1702                         filter => "(&(FAIrepository=*)(objectClass=FAIrepositoryServer))",
1703                 );
1704                 if($mesg->{'resultCode'} == 0 &&
1705                    $mesg->count != 0) {
1706                    foreach my $entry (@{$mesg->{entries}}) {
1707                            if($entry->exists('FAIrepository')) {
1708                                    # Add an entry for each Repository configured for server
1709                                    foreach my $repo(@{$entry->get_value('FAIrepository', asref => 1)}) {
1710                                                    my($tmp_url,$tmp_server,$tmp_release,$tmp_sections) = split(/\|/, $repo);
1711                                                    my $tmp_tag= $entry->get_value('gosaUnitTag') || "";
1712                                                    $result= $fai_server_db->add_dbentry( { 
1713                                                                    table => $table_name,
1714                                                                    primkey => ['server', 'release', 'tag'],
1715                                                                    server => $tmp_url,
1716                                                                    release => $tmp_release,
1717                                                                    sections => $tmp_sections,
1718                                                                    tag => (length($tmp_tag)>0)?$tmp_tag:"",
1719                                                            } );
1720                                            }
1721                                    }
1722                            }
1723                    }
1724                 daemon_log("$session_id INFO: create_fai_server_db: finished", 5);
1726                 # TODO: Find a way to post the 'create_packages_list_db' event
1727                 if(not defined($dont_create_packages_list)) {
1728                         &create_packages_list_db(undef, undef, $session_id);
1729                 }
1730         }       
1731     
1732     $ldap_handle->disconnect;
1733         return $result;
1737 sub run_create_fai_release_db {
1738     my ($session, $heap, $table_name) = @_[SESSION, HEAP, ARG0];
1739         my $session_id = $session->ID;
1740     my $task = POE::Wheel::Run->new(
1741             Program => sub { &create_fai_release_db($table_name, $session_id) },
1742             StdoutEvent  => "session_run_result",
1743             StderrEvent  => "session_run_debug",
1744             CloseEvent   => "session_run_done",
1745             );
1747     $heap->{task}->{ $task->ID } = $task;
1748     return;
1752 sub create_fai_release_db {
1753         my ($table_name, $session_id) = @_;
1754         my $result;
1756     # used for logging
1757     if (not defined $session_id) { $session_id = 0; }
1759     my $ldap_handle = &get_ldap_handle();
1760         if(defined($ldap_handle)) {
1761                 daemon_log("$session_id INFO: create_fai_release_db: start",5);
1762                 my $mesg= $ldap_handle->search(
1763                         base   => $ldap_base,
1764                         scope  => 'sub',
1765                         attrs  => [],
1766                         filter => "(&(objectClass=organizationalUnit)(ou=fai))",
1767                 );
1768                 if($mesg->{'resultCode'} == 0 &&
1769                         $mesg->count != 0) {
1770                         # Walk through all possible FAI container ou's
1771                         my @sql_list;
1772                         my $timestamp= &get_time();
1773                         foreach my $ou (@{$mesg->{entries}}) {
1774                                 my $tmp_classes= resolve_fai_classes($ou->dn, $ldap_handle, $session_id);
1775                                 if(defined($tmp_classes) && ref($tmp_classes) eq 'HASH') {
1776                                         my @tmp_array=get_fai_release_entries($tmp_classes);
1777                                         if(@tmp_array) {
1778                                                 foreach my $entry (@tmp_array) {
1779                                                         if(defined($entry) && ref($entry) eq 'HASH') {
1780                                                                 my $sql= 
1781                                                                 "INSERT INTO $table_name "
1782                                                                 ."(timestamp, release, class, type, state) VALUES ("
1783                                                                 .$timestamp.","
1784                                                                 ."'".$entry->{'release'}."',"
1785                                                                 ."'".$entry->{'class'}."',"
1786                                                                 ."'".$entry->{'type'}."',"
1787                                                                 ."'".$entry->{'state'}."')";
1788                                                                 push @sql_list, $sql;
1789                                                         }
1790                                                 }
1791                                         }
1792                                 }
1793                         }
1795                         daemon_log("$session_id DEBUG: Inserting ".scalar @sql_list." entries to DB",8);
1796                         if(@sql_list) {
1797                                 unshift @sql_list, "VACUUM";
1798                                 unshift @sql_list, "DELETE FROM $table_name";
1799                                 $fai_release_db->exec_statementlist(\@sql_list);
1800                         }
1801                         daemon_log("$session_id DEBUG: Done with inserting",7);
1802                 }
1803                 daemon_log("$session_id INFO: create_fai_release_db: finished",5);
1804         }
1805     $ldap_handle->disconnect;
1806         return $result;
1809 sub get_fai_types {
1810         my $tmp_classes = shift || return undef;
1811         my @result;
1813         foreach my $type(keys %{$tmp_classes}) {
1814                 if(defined($tmp_classes->{$type}[0]) && (!($tmp_classes->{$type}[0] =~ /^.*?removed.*?$/))) {
1815                         my $entry = {
1816                                 type => $type,
1817                                 state => $tmp_classes->{$type}[0],
1818                         };
1819                         push @result, $entry;
1820                 }
1821         }
1823         return @result;
1826 sub get_fai_state {
1827         my $result = "";
1828         my $tmp_classes = shift || return $result;
1830         foreach my $type(keys %{$tmp_classes}) {
1831                 if(defined($tmp_classes->{$type}[0])) {
1832                         $result = $tmp_classes->{$type}[0];
1833                         
1834                 # State is equal for all types in class
1835                         last;
1836                 }
1837         }
1839         return $result;
1842 sub resolve_fai_classes {
1843         my ($fai_base, $ldap_handle, $session_id) = @_;
1844         if (not defined $session_id) { $session_id = 0; }
1845         my $result;
1846         my @possible_fai_classes= ("FAIscript", "FAIhook", "FAIpartitionTable", "FAItemplate", "FAIvariable", "FAIprofile", "FAIpackageList");
1847         my $fai_filter= "(|(&(objectClass=FAIclass)(|(objectClass=".join(")(objectClass=", @possible_fai_classes).")))(objectClass=FAIbranch))";
1848         my $fai_classes;
1850         daemon_log("$session_id DEBUG: Searching for FAI entries in base $fai_base",7);
1851         my $mesg= $ldap_handle->search(
1852                 base   => $fai_base,
1853                 scope  => 'sub',
1854                 attrs  => ['cn','objectClass','FAIstate'],
1855                 filter => $fai_filter,
1856         );
1857         daemon_log("$session_id DEBUG: Found ".$mesg->count()." FAI entries",7);
1859         if($mesg->{'resultCode'} == 0 &&
1860                 $mesg->count != 0) {
1861                 foreach my $entry (@{$mesg->{entries}}) {
1862                         if($entry->exists('cn')) {
1863                                 my $tmp_dn= $entry->dn();
1865                                 # Skip classname and ou dn parts for class
1866                                 my $tmp_release = ($1) if $tmp_dn =~ /^[^,]+,[^,]+,(.*?),$fai_base$/;
1868                                 # Skip classes without releases
1869                                 if((!defined($tmp_release)) || length($tmp_release)==0) {
1870                                         next;
1871                                 }
1873                                 my $tmp_cn= $entry->get_value('cn');
1874                                 my $tmp_state= $entry->get_value('FAIstate');
1876                                 my $tmp_type;
1877                                 # Get FAI type
1878                                 for my $oclass(@{$entry->get_value('objectClass', asref => 1)}) {
1879                                         if(grep $_ eq $oclass, @possible_fai_classes) {
1880                                                 $tmp_type= $oclass;
1881                                                 last;
1882                                         }
1883                                 }
1885                                 if($tmp_release =~ /^.*?,.*?$/ && (!($tmp_release =~ /^.*?\\,.*?$/))) {
1886                                         # A Subrelease
1887                                         my @sub_releases = split(/,/, $tmp_release);
1889                                         # Walk through subreleases and build hash tree
1890                                         my $hash;
1891                                         while(my $tmp_sub_release = pop @sub_releases) {
1892                                                 $hash .= "\{'$tmp_sub_release'\}->";                                            
1893                                         }
1894                                         eval('push @{$fai_classes->'.$hash.'{$tmp_cn}->{$tmp_type}}, (defined($tmp_state) && length($tmp_state)>0)?$tmp_state:"";');
1895                                 } else {
1896                                         # A branch, no subrelease
1897                                         push @{$fai_classes->{$tmp_release}->{$tmp_cn}->{$tmp_type}}, (defined($tmp_state) && length($tmp_state)>0)?$tmp_state:"";
1898                                 }
1899                         } elsif (!$entry->exists('cn')) {
1900                                 my $tmp_dn= $entry->dn();
1901                                 my $tmp_release = ($1) if $tmp_dn =~ /^(.*?),$fai_base$/;
1903                                 # Skip classes without releases
1904                                 if((!defined($tmp_release)) || length($tmp_release)==0) {
1905                                         next;
1906                                 }
1908                                 if($tmp_release =~ /^.*?,.*?$/ && (!($tmp_release =~ /^.*?\\,.*?$/))) {
1909                                         # A Subrelease
1910                                         my @sub_releases= split(/,/, $tmp_release);
1912                                         # Walk through subreleases and build hash tree
1913                                         my $hash;
1914                                         while(my $tmp_sub_release = pop @sub_releases) {
1915                                                 $hash .= "\{'$tmp_sub_release'\}->";                                            
1916                                         }
1917                                         # Remove the last two characters
1918                                         chop($hash);
1919                                         chop($hash);
1921                                         eval('$fai_classes->'.$hash.'= {}');
1922                                 } else {
1923                                         # A branch, no subrelease
1924                                         if(!exists($fai_classes->{$tmp_release})) {
1925                                                 $fai_classes->{$tmp_release} = {};
1926                                         }
1927                                 }
1928                         }
1929                 }
1931                 # The hash is complete, now we can honor the copy-on-write based missing entries
1932                 foreach my $release (keys %$fai_classes) {
1933                         $result->{$release}= deep_copy(apply_fai_inheritance($fai_classes->{$release}));
1934                 }
1935         }
1936         return $result;
1939 sub apply_fai_inheritance {
1940        my $fai_classes = shift || return {};
1941        my $tmp_classes;
1943        # Get the classes from the branch
1944        foreach my $class (keys %{$fai_classes}) {
1945                # Skip subreleases
1946                if($class =~ /^ou=.*$/) {
1947                        next;
1948                } else {
1949                        $tmp_classes->{$class}= deep_copy($fai_classes->{$class});
1950                }
1951        }
1953        # Apply to each subrelease
1954        foreach my $subrelease (keys %{$fai_classes}) {
1955                if($subrelease =~ /ou=/) {
1956                        foreach my $tmp_class (keys %{$tmp_classes}) {
1957                                if(!exists($fai_classes->{$subrelease}->{$tmp_class})) {
1958                                        $fai_classes->{$subrelease}->{$tmp_class} =
1959                                        deep_copy($tmp_classes->{$tmp_class});
1960                                } else {
1961                                        foreach my $type (keys %{$tmp_classes->{$tmp_class}}) {
1962                                                if(!exists($fai_classes->{$subrelease}->{$tmp_class}->{$type})) {
1963                                                        $fai_classes->{$subrelease}->{$tmp_class}->{$type}=
1964                                                        deep_copy($tmp_classes->{$tmp_class}->{$type});
1965                                                }
1966                                        }
1967                                }
1968                        }
1969                }
1970        }
1972        # Find subreleases in deeper levels
1973        foreach my $subrelease (keys %{$fai_classes}) {
1974                if($subrelease =~ /ou=/) {
1975                        foreach my $subsubrelease (keys %{$fai_classes->{$subrelease}}) {
1976                                if($subsubrelease =~ /ou=/) {
1977                                        apply_fai_inheritance($fai_classes->{$subrelease});
1978                                }
1979                        }
1980                }
1981        }
1983        return $fai_classes;
1986 sub get_fai_release_entries {
1987         my $tmp_classes = shift || return;
1988         my $parent = shift || "";
1989         my @result = shift || ();
1991         foreach my $entry (keys %{$tmp_classes}) {
1992                 if(defined($entry)) {
1993                         if($entry =~ /^ou=.*$/) {
1994                                 my $release_name = $entry;
1995                                 $release_name =~ s/ou=//g;
1996                                 if(length($parent)>0) {
1997                                         $release_name = $parent."/".$release_name;
1998                                 }
1999                                 my @bufentries = get_fai_release_entries($tmp_classes->{$entry}, $release_name, @result);
2000                                 foreach my $bufentry(@bufentries) {
2001                                         push @result, $bufentry;
2002                                 }
2003                         } else {
2004                                 my @types = get_fai_types($tmp_classes->{$entry});
2005                                 foreach my $type (@types) {
2006                                         push @result, 
2007                                         {
2008                                                 'class' => $entry,
2009                                                 'type' => $type->{'type'},
2010                                                 'release' => $parent,
2011                                                 'state' => $type->{'state'},
2012                                         };
2013                                 }
2014                         }
2015                 }
2016         }
2018         return @result;
2021 sub deep_copy {
2022         my $this = shift;
2023         if (not ref $this) {
2024                 $this;
2025         } elsif (ref $this eq "ARRAY") {
2026                 [map deep_copy($_), @$this];
2027         } elsif (ref $this eq "HASH") {
2028                 +{map { $_ => deep_copy($this->{$_}) } keys %$this};
2029         } else { die "what type is $_?" }
2033 sub session_run_result {
2034     my ($kernel, $heap, $client_answer) = @_[KERNEL, HEAP, ARG0];    
2035     $kernel->sig(CHLD => "child_reap");
2038 sub session_run_debug {
2039     my $result = $_[ARG0];
2040     print STDERR "$result\n";
2043 sub session_run_done {
2044     my ( $kernel, $heap, $task_id ) = @_[ KERNEL, HEAP, ARG0 ];
2045     delete $heap->{task}->{$task_id};
2049 sub create_sources_list {
2050         my $session_id = shift;
2051         my $ldap_handle = &main::get_ldap_handle;
2052         my $result="/tmp/gosa_si_tmp_sources_list";
2054         # Remove old file
2055         if(stat($result)) {
2056                 unlink($result);
2057                 &main::daemon_log("$session_id DEBUG: remove an old version of '$result'", 7); 
2058         }
2060         my $fh;
2061         open($fh, ">$result");
2062         if (not defined $fh) {
2063                 &main::daemon_log("$session_id DEBUG: cannot open '$result' for writing", 7); 
2064                 return undef;
2065         }
2066         if(defined($main::ldap_server_dn) and length($main::ldap_server_dn) > 0) {
2067                 my $mesg=$ldap_handle->search(
2068                         base    => $main::ldap_server_dn,
2069                         scope   => 'base',
2070                         attrs   => 'FAIrepository',
2071                         filter  => 'objectClass=FAIrepositoryServer'
2072                 );
2073                 if($mesg->count) {
2074                         foreach my $entry(@{$mesg->{'entries'}}) {
2075                                 foreach my $value(@{$entry->get_value('FAIrepository', asref => 1)}) {
2076                                         my ($server, $tag, $release, $sections)= split /\|/, $value;
2077                                         my $line = "deb $server $release";
2078                                         $sections =~ s/,/ /g;
2079                                         $line.= " $sections";
2080                                         print $fh $line."\n";
2081                                 }
2082                         }
2083                 }
2084         } else {
2085                 if (defined $main::ldap_server_dn){
2086                         &main::daemon_log("$session_id ERROR: something wrong with ldap_server_dn '$main::ldap_server_dn', abort create_sources_list", 1); 
2087                 } else {
2088                         &main::daemon_log("$session_id ERROR: no ldap_server_dn found, abort create_sources_list", 1);
2089                 }
2090         }
2091         close($fh);
2093         return $result;
2097 sub run_create_packages_list_db {
2098     my ($session, $heap) = @_[SESSION, HEAP];
2099         my $session_id = $session->ID;
2101         my $task = POE::Wheel::Run->new(
2102                                         Program => sub {&create_packages_list_db(undef, undef, $session_id)},
2103                                         StdoutEvent  => "session_run_result",
2104                                         StderrEvent  => "session_run_debug",
2105                                         CloseEvent   => "session_run_done",
2106                                         );
2107         $heap->{task}->{ $task->ID } = $task;
2111 sub create_packages_list_db {
2112         my ($ldap_handle, $sources_file, $session_id) = @_;
2113         
2114         # it should not be possible to trigger a recreation of packages_list_db
2115         # while packages_list_db is under construction, so set flag packages_list_under_construction
2116         # which is tested befor recreation can be started
2117         if (-r $packages_list_under_construction) {
2118                 daemon_log("$session_id WARNING: packages_list_db is right now under construction, please wait until this process is finished", 3);
2119                 return;
2120         } else {
2121                 daemon_log("$session_id INFO: create_packages_list_db: start", 5); 
2122                 # set packages_list_under_construction to true
2123                 system("touch $packages_list_under_construction");
2124                 @packages_list_statements=();
2125         }
2127         if (not defined $session_id) { $session_id = 0; }
2128         if (not defined $ldap_handle) { 
2129                 $ldap_handle= &get_ldap_handle();
2131                 if (not defined $ldap_handle) {
2132                         daemon_log("$session_id ERROR: no ldap_handle available to create_packages_list_db", 1);
2133                         unlink($packages_list_under_construction);
2134                         return;
2135                 }
2136         }
2137         if (not defined $sources_file) { 
2138                 &main::daemon_log("$session_id INFO: no sources_file given for creating packages list so trigger creation of it", 5); 
2139                 $sources_file = &create_sources_list($session_id);
2140         }
2142         if (not defined $sources_file) {
2143                 &main::daemon_log("$session_id ERROR: no sources_file given under '$sources_file', skip create_packages_list_db", 1); 
2144                 unlink($packages_list_under_construction);
2145                 return;
2146         }
2148         my $line;
2150         open(CONFIG, "<$sources_file") or do {
2151                 daemon_log( "$session_id ERROR: create_packages_list_db: Failed to open '$sources_file'", 1);
2152                 unlink($packages_list_under_construction);
2153                 return;
2154         };
2156         # Read lines
2157         while ($line = <CONFIG>){
2158                 # Unify
2159                 chop($line);
2160                 $line =~ s/^\s+//;
2161                 $line =~ s/^\s+/ /;
2163                 # Strip comments
2164                 $line =~ s/#.*$//g;
2166                 # Skip empty lines
2167                 if ($line =~ /^\s*$/){
2168                         next;
2169                 }
2171                 # Interpret deb line
2172                 if ($line =~ /^deb [^\s]+\s[^\s]+\s[^\s]+/){
2173                         my( $baseurl, $dist, $sections ) = ($line =~ /^deb\s([^\s]+)\s+([^\s]+)\s+(.*)$/);
2174                         my $section;
2175                         foreach $section (split(' ', $sections)){
2176                                 &parse_package_info( $baseurl, $dist, $section, $session_id );
2177                         }
2178                 }
2179         }
2181         close (CONFIG);
2183         find(\&cleanup_and_extract, keys( %repo_dirs ));
2184         unshift @packages_list_statements, "VACUUM";
2185         unshift @packages_list_statements, "DELETE FROM $packages_list_tn";
2186         $packages_list_db->exec_statementlist(\@packages_list_statements);
2187         unlink($packages_list_under_construction);
2188         daemon_log("$session_id INFO: create_packages_list_db: finished", 5); 
2189         return;
2193 sub parse_package_info {
2194     my ($baseurl, $dist, $section, $session_id)= @_;
2195     my ($package);
2196     if (not defined $session_id) { $session_id = 0; }
2197     my ($path) = ($baseurl =~ m%://[^/]*(.*)$%);
2198     $repo_dirs{ "${repo_path}/pool" } = 1;
2200     foreach $package ("Packages.gz"){
2201         daemon_log("$session_id DEBUG: create_packages_list: fetch $baseurl, $dist, $section", 7);
2202         get_package( "$baseurl/dists/$dist/$section/binary-$arch/$package", "$outdir/$dist/$section", $session_id );
2203         parse_package( "$outdir/$dist/$section", $dist, $path, $session_id );
2204     }
2205     
2209 sub get_package {
2210     my ($url, $dest, $session_id)= @_;
2211     if (not defined $session_id) { $session_id = 0; }
2213     my $tpath = dirname($dest);
2214     -d "$tpath" || mkpath "$tpath";
2216     # This is ugly, but I've no time to take a look at "how it works in perl"
2217     if(0 == system("wget '$url' -O '$dest' 2>/dev/null") ) {
2218         system("gunzip -cd '$dest' > '$dest.in'");
2219         daemon_log("$session_id DEBUG: run command: gunzip -cd '$dest' > '$dest.in'", 5);
2220         unlink($dest);
2221         daemon_log("$session_id DEBUG: delete file '$dest'", 5); 
2222     } else {
2223         daemon_log("$session_id ERROR: create_packages_list_db: get_packages: fetching '$url' failed!", 1);
2224     }
2225     return 0;
2229 sub parse_package {
2230     my ($path, $dist, $srv_path, $session_id)= @_;
2231     if (not defined $session_id) { $session_id = 0;}
2232     my ($package, $version, $section, $description);
2233     my $PACKAGES;
2234     my $timestamp = &get_time();
2236     if(not stat("$path.in")) {
2237         daemon_log("$session_id ERROR: create_packages_list: parse_package: file '$path.in' is not readable",1);
2238         return;
2239     }
2241     open($PACKAGES, "<$path.in");
2242     if(not defined($PACKAGES)) {
2243         daemon_log("$session_id ERROR: create_packages_list_db: parse_package: cannot open '$path.in'",1); 
2244         return;
2245     }
2247     # Read lines
2248     while (<$PACKAGES>){
2249         my $line = $_;
2250         # Unify
2251         chop($line);
2253         # Use empty lines as a trigger
2254         if ($line =~ /^\s*$/){
2255             my $sql2 = "INSERT INTO packages_list VALUES ('$dist', '$package', '$version', '$section', '', 'none', '$timestamp')";
2256             my $sql = "INSERT INTO packages_list VALUES ('$dist', '$package', '$version', '$section', '', 'none', '$timestamp')";
2257             push(@packages_list_statements, $sql);
2258             push(@packages_list_statements, $sql2);
2259             $package = "none";
2260             $version = "none";
2261             $section = "none";
2262             $description = "none"; 
2263             next;
2264         }
2266         # Trigger for package name
2267         if ($line =~ /^Package:\s/){
2268             ($package)= ($line =~ /^Package: (.*)$/);
2269             next;
2270         }
2272         # Trigger for version
2273         if ($line =~ /^Version:\s/){
2274             ($version)= ($line =~ /^Version: (.*)$/);
2275             next;
2276         }
2278         # Trigger for description
2279         if ($line =~ /^Description:\s/){
2280             ($description)= ($line =~ /^Description: (.*)$/);
2281             next;
2282         }
2284         # Trigger for section
2285         if ($line =~ /^Section:\s/){
2286             ($section)= ($line =~ /^Section: (.*)$/);
2287             next;
2288         }
2290         # Trigger for filename
2291         if ($line =~ /^Filename:\s/){
2292             my ($filename) = ($line =~ /^Filename: (.*)$/);
2293             store_fileinfo( $package, $filename, $dist, $srv_path, $version, $repo_path );
2294             next;
2295         }
2296     }
2298     close( $PACKAGES );
2299     unlink( "$path.in" );
2300     &main::daemon_log("$session_id DEBUG: unlink '$path.in'", 1); 
2304 sub store_fileinfo {
2305     my( $package, $file, $dist, $path, $vers, $srvdir) = @_;
2307     my %fileinfo = (
2308         'package' => $package,
2309         'dist' => $dist,
2310         'version' => $vers,
2311     );
2313     $repo_files{ "${srvdir}/$file" } = \%fileinfo;
2317 sub cleanup_and_extract {
2318     my $fileinfo = $repo_files{ $File::Find::name };
2320     if( defined $fileinfo ) {
2322         my $dir = "$outdir/$fileinfo->{ 'dist' }/debconf.d";
2323         my $sql;
2324         my $package = $fileinfo->{ 'package' };
2325         my $newver = $fileinfo->{ 'version' };
2327         mkpath($dir);
2328         system( "dpkg -e '$File::Find::name' '$dir/DEBIAN'" );
2330         if( -f "$dir/DEBIAN/templates" ) {
2332             daemon_log("DEBUG: Found debconf templates in '$package' - $newver", 5);
2334             my $tmpl= "";
2335             {
2336                 local $/=undef;
2337                 open FILE, "$dir/DEBIAN/templates";
2338                 $tmpl = &encode_base64(<FILE>);
2339                 close FILE;
2340             }
2341             rmtree("$dir/DEBIAN/templates");
2343             $sql= "update $main::packages_list_tn set template = '$tmpl' where package = '$package' and version = '$newver';";
2345         } else {
2346             $sql= "update $main::packages_list_tn set template = '' where package = '$package' and version = '$newver';";
2347         }
2349         push @packages_list_statements, $sql;
2350     }
2352     return;
2356 #==== MAIN = main ==============================================================
2357 #  parse commandline options
2358 Getopt::Long::Configure( "bundling" );
2359 GetOptions("h|help" => \&usage,
2360         "c|config=s" => \$cfg_file,
2361         "f|foreground" => \$foreground,
2362         "v|verbose+" => \$verbose,
2363         "no-bus+" => \$no_bus,
2364         "no-arp+" => \$no_arp,
2365            );
2367 #  read and set config parameters
2368 &check_cmdline_param ;
2369 &read_configfile;
2370 &check_pid;
2372 $SIG{CHLD} = 'IGNORE';
2374 # forward error messages to logfile
2375 if( ! $foreground ) {
2376   open( STDIN,  '+>/dev/null' );
2377   open( STDOUT, '+>&STDIN'    );
2378   open( STDERR, '+>&STDIN'    );
2381 # Just fork, if we are not in foreground mode
2382 if( ! $foreground ) { 
2383     chdir '/'                 or die "Can't chdir to /: $!";
2384     $pid = fork;
2385     setsid                    or die "Can't start a new session: $!";
2386     umask 0;
2387 } else { 
2388     $pid = $$; 
2391 # Do something useful - put our PID into the pid_file
2392 if( 0 != $pid ) {
2393     open( LOCK_FILE, ">$pid_file" );
2394     print LOCK_FILE "$pid\n";
2395     close( LOCK_FILE );
2396     if( !$foreground ) { 
2397         exit( 0 ) 
2398     };
2401 daemon_log(" ", 1);
2402 daemon_log("$0 started!", 1);
2404 if ($no_bus > 0) {
2405     $bus_activ = "false"
2408 # connect to gosa-si job queue
2409 $job_db = GOSA::DBsqlite->new($job_queue_file_name);
2410 $job_db->create_table($job_queue_tn, \@job_queue_col_names);
2412 # connect to known_clients_db
2413 $known_clients_db = GOSA::DBsqlite->new($known_clients_file_name);
2414 $known_clients_db->create_table($known_clients_tn, \@known_clients_col_names);
2416 # connect to known_server_db
2417 $known_server_db = GOSA::DBsqlite->new($known_server_file_name);
2418 $known_server_db->create_table($known_server_tn, \@known_server_col_names);
2420 # connect to login_usr_db
2421 $login_users_db = GOSA::DBsqlite->new($login_users_file_name);
2422 $login_users_db->create_table($login_users_tn, \@login_users_col_names);
2424 # connect to fai_server_db and fai_release_db
2425 unlink($fai_server_file_name);
2426 $fai_server_db = GOSA::DBsqlite->new($fai_server_file_name);
2427 $fai_server_db->create_table($fai_server_tn, \@fai_server_col_names);
2429 unlink($fai_release_file_name);
2430 $fai_release_db = GOSA::DBsqlite->new($fai_release_file_name);
2431 $fai_release_db->create_table($fai_release_tn, \@fai_release_col_names);
2433 # connect to packages_list_db
2434 unlink($packages_list_file_name);
2435 unlink($packages_list_under_construction);
2436 $packages_list_db = GOSA::DBsqlite->new($packages_list_file_name);
2437 $packages_list_db->create_table($packages_list_tn, \@packages_list_col_names);
2439 # connect to messaging_db
2440 $messaging_db = GOSA::DBsqlite->new($messaging_file_name);
2441 $messaging_db->create_table($messaging_tn, \@messaging_col_names);
2444 # create xml object used for en/decrypting
2445 $xml = new XML::Simple();
2447 # create socket for incoming xml messages
2449 POE::Component::Server::TCP->new(
2450         Port => $server_port,
2451         ClientInput => sub {
2452         my ($kernel, $input) = @_[KERNEL, ARG0];
2453         push(@tasks, $input);
2454         $kernel->yield("next_task");
2455         },
2456     InlineStates => {
2457         next_task => \&next_task,
2458         task_result => \&handle_task_result,
2459         task_done   => \&handle_task_done,
2460         task_debug  => \&handle_task_debug,
2461         child_reap => sub { "Do nothing special. I'm just a comment, but i'm necessary!"  },
2462     }
2463 );
2465 daemon_log("start socket for incoming xml messages at port '$server_port' ", 1);
2467 # create session for repeatedly checking the job queue for jobs
2468 POE::Session->create(
2469         inline_states => {
2470                 _start => \&_start,
2471                 sig_handler => \&sig_handler,
2472         watch_for_new_messages => \&watch_for_new_messages,
2473         watch_for_delivery_messages => \&watch_for_delivery_messages,
2474         watch_for_done_messages => \&watch_for_done_messages,
2475                 watch_for_new_jobs => \&watch_for_new_jobs,
2476         watch_for_done_jobs => \&watch_for_done_jobs,
2477         create_packages_list_db => \&run_create_packages_list_db,
2478         create_fai_server_db => \&run_create_fai_server_db,
2479         create_fai_release_db => \&run_create_fai_release_db,
2480         session_run_result => \&session_run_result,
2481         session_run_debug => \&session_run_debug,
2482         session_run_done => \&session_run_done,
2483         child_reap => sub { "Do nothing special. I'm just a comment, but i'm necessary!"  },
2484         }
2485 );
2488 # import all modules
2489 &import_modules;
2491 # check wether all modules are gosa-si valid passwd check
2493 POE::Kernel->run();
2494 exit;