예제 #1
0
def InitFleetspeakConfigs(
        grr_configs: GRRConfigs,
        mysql_database: str,
        mysql_username: Optional[str] = None,
        mysql_password: Optional[str] = None) -> FleetspeakConfigs:
    """Initializes Fleetspeak server and client configs."""

    fs_frontend_port, fs_admin_port = api_helpers.GetFleetspeakPortsFromConfig(
        grr_configs.server_config)

    mysql_username = mysql_username or ""
    mysql_password = mysql_password or ""

    temp_root = tempfile.mkdtemp(suffix="_fleetspeak")

    def TempPath(*args):
        return os.path.join(temp_root, *args)

    cp = config_pb2.Config(configuration_name="Self-contained testing")
    cp.components_config.mysql_data_source_name = "%s:%s@tcp(127.0.0.1:3306)/%s" % (
        mysql_username, mysql_password, mysql_database)
    cp.components_config.https_config.listen_address = "localhost:%d" % portpicker.pick_unused_port(
    )
    # TODO(user): Use streaming connections by default. At the moment
    # a few tests are failing with MySQL errors when streaming is used.
    cp.components_config.https_config.disable_streaming = True
    cp.components_config.admin_config.listen_address = ("localhost:%d" %
                                                        fs_admin_port)
    cp.public_host_port.append(
        cp.components_config.https_config.listen_address)
    cp.server_component_configuration_file = TempPath("server.config")
    cp.trusted_cert_file = TempPath("trusted_cert.pem")
    cp.trusted_cert_key_file = TempPath("trusted_cert_key.pem")
    cp.server_cert_file = TempPath("server_cert.pem")
    cp.server_cert_key_file = TempPath("server_cert_key.pem")
    cp.linux_client_configuration_file = TempPath("linux_client.config")
    cp.windows_client_configuration_file = TempPath("windows_client.config")
    cp.darwin_client_configuration_file = TempPath("darwin_client.config")

    built_configurator_config_path = TempPath("configurator.config")
    with open(built_configurator_config_path, mode="w",
              encoding="utf-8") as fd:
        fd.write(text_format.MessageToString(cp))

    p = _StartBinary(
        "fleetspeak-config",
        ["--logtostderr", "--config", built_configurator_config_path])
    if p.wait() != 0:
        raise ConfigInitializationError(
            "fleetspeak-config execution failed: {}".format(p.returncode))

    # Adjust client config.
    with open(cp.linux_client_configuration_file, mode="r",
              encoding="utf-8") as fd:
        conf_content = fd.read()
    conf = text_format.Parse(conf_content, client_config_pb2.Config())
    conf.filesystem_handler.configuration_directory = temp_root
    conf.filesystem_handler.state_file = TempPath("client.state")
    with open(cp.linux_client_configuration_file, mode="w",
              encoding="utf-8") as fd:
        fd.write(text_format.MessageToString(conf))

    # Write client services configuration.
    service_conf = system_pb2.ClientServiceConfig(name="GRR", factory="Daemon")
    payload = daemonservice_config_pb2.Config()
    payload.argv.extend([
        sys.executable, "-u", "-m", "grr_response_client.grr_fs_client",
        "--config", grr_configs.client_config
    ])

    # TODO(user): remove this condition when Fleetspeak is used as a nanny
    # on all platforms.
    if platform.system() == "Windows":
        payload.monitor_heartbeats = True
        payload.heartbeat_unresponsive_grace_period_seconds = 45
        payload.heartbeat_unresponsive_kill_period_seconds = 15
    service_conf.config.Pack(payload)

    os.mkdir(TempPath("textservices"))
    with open(TempPath("textservices", "GRR.textproto"),
              mode="w",
              encoding="utf-8") as fd:
        fd.write(text_format.MessageToString(service_conf))

    # Server services configuration.
    service_config = services_pb2.ServiceConfig(name="GRR", factory="GRPC")
    grpc_config = grpcservice_pb2.Config(target="localhost:%d" %
                                         fs_frontend_port,
                                         insecure=True)
    service_config.config.Pack(grpc_config)
    server_conf = server_pb2.ServerConfig(services=[service_config])
    server_conf.broadcast_poll_time.seconds = 1

    built_server_services_config_path = TempPath("server.services.config")
    with open(built_server_services_config_path, mode="w",
              encoding="utf-8") as fd:
        fd.write(text_format.MessageToString(server_conf))

    return FleetspeakConfigs(cp.server_component_configuration_file,
                             built_server_services_config_path,
                             cp.linux_client_configuration_file)
예제 #2
0
  def _WriteEnabled(self, config):
    """Applies the in-memory configuration for the use_fleetspeak case."""

    service_config = services_pb2.ServiceConfig(name="GRR", factory="GRPC")
    grpc_config = grpcservice_pb2.Config(
        target="localhost:{}".format(self.grr_port), insecure=True)
    service_config.config.Pack(grpc_config)
    server_conf = server_pb2.ServerConfig(services=[service_config])
    server_conf.broadcast_poll_time.seconds = 1

    with open(self._ConfigPath("server.services.config"), "w") as f:
      f.write(text_format.MessageToString(server_conf))

    cp = config_pb2.Config()
    cp.configuration_name = "Fleetspeak"
    cp.components_config.mysql_data_source_name = (
        "{user}:@tcp({host}:{port})/{db}".format(
            user=self.mysql_username,
            host=self.mysql_host,
            port=self.mysql_port,
            db=self.mysql_database))
    cp.components_config.https_config.listen_address = "{}:{}".format(
        self.external_hostname, self.https_port)
    cp.components_config.https_config.disable_streaming = True
    cp.components_config.admin_config.listen_address = "localhost:{}".format(
        self.admin_port)
    cp.public_host_port.append(cp.components_config.https_config.listen_address)
    cp.server_component_configuration_file = self._ConfigPath(
        "server.components.config")
    cp.trusted_cert_file = self._ConfigPath("trusted_cert.pem")
    cp.trusted_cert_key_file = self._ConfigPath("trusted_cert_key.pem")
    cp.server_cert_file = self._ConfigPath("server_cert.pem")
    cp.server_cert_key_file = self._ConfigPath("server_cert_key.pem")
    cp.linux_client_configuration_file = self._ConfigPath("linux_client.config")
    cp.windows_client_configuration_file = self._ConfigPath(
        "windows_client.config")
    cp.darwin_client_configuration_file = self._ConfigPath(
        "darwin_client.config")

    p = subprocess.Popen(["fleetspeak-config", "-config", "/dev/stdin"],
                         stdin=subprocess.PIPE)
    p.communicate(input=text_format.MessageToString(cp).encode())
    if p.wait() != 0:
      raise RuntimeError("fleetspeak-config command failed.")

    # These modules don't exist on Windows, so importing locally.
    # pylint: disable=g-import-not-at-top
    import grp
    import pwd
    # pylint: enable=g-import-not-at-top

    if (os.geteuid() == 0 and pwd.getpwnam("fleetspeak") and
        grp.getgrnam("fleetspeak")):
      subprocess.check_call(
          ["chown", "-R", "fleetspeak:fleetspeak",
           self._ConfigPath()])

    try:
      os.unlink(self._ConfigPath("disabled"))
    except FileNotFoundError:
      pass

    config.Set("Server.fleetspeak_enabled", True)
    config.Set("Client.fleetspeak_enabled", True)
    config.Set("ClientBuilder.fleetspeak_bundled", True)
    config.Set(
        "Target:Linux", {
            "ClientBuilder.fleetspeak_client_config":
                cp.linux_client_configuration_file
        })
    config.Set(
        "Target:Windows", {
            "ClientBuilder.fleetspeak_client_config":
                cp.windows_client_configuration_file
        })
    config.Set(
        "Target:Darwin", {
            "ClientBuilder.fleetspeak_client_config":
                cp.darwin_client_configuration_file
        })
    config.Set("Server.fleetspeak_server",
               cp.components_config.admin_config.listen_address)
    config.Set("FleetspeakFrontend Context",
               {"Server.fleetspeak_message_listen_address": grpc_config.target})