def InitFleetspeakConfigs( grr_configs: GRRConfigs, mysql_database: str, mysql_username: Optional[str] = None, mysql_password: Optional[str] = None) -> FleetspeakConfigs: """Initializes Fleetspeak server and client configs.""" fs_frontend_port, fs_admin_port = api_helpers.GetFleetspeakPortsFromConfig( grr_configs.server_config) mysql_username = mysql_username or "" mysql_password = mysql_password or "" temp_root = tempfile.mkdtemp(suffix="_fleetspeak") def TempPath(*args): return os.path.join(temp_root, *args) cp = config_pb2.Config(configuration_name="Self-contained testing") cp.components_config.mysql_data_source_name = "%s:%s@tcp(127.0.0.1:3306)/%s" % ( mysql_username, mysql_password, mysql_database) cp.components_config.https_config.listen_address = "localhost:%d" % portpicker.pick_unused_port( ) # TODO(user): Use streaming connections by default. At the moment # a few tests are failing with MySQL errors when streaming is used. cp.components_config.https_config.disable_streaming = True cp.components_config.admin_config.listen_address = ("localhost:%d" % fs_admin_port) cp.public_host_port.append( cp.components_config.https_config.listen_address) cp.server_component_configuration_file = TempPath("server.config") cp.trusted_cert_file = TempPath("trusted_cert.pem") cp.trusted_cert_key_file = TempPath("trusted_cert_key.pem") cp.server_cert_file = TempPath("server_cert.pem") cp.server_cert_key_file = TempPath("server_cert_key.pem") cp.linux_client_configuration_file = TempPath("linux_client.config") cp.windows_client_configuration_file = TempPath("windows_client.config") cp.darwin_client_configuration_file = TempPath("darwin_client.config") built_configurator_config_path = TempPath("configurator.config") with open(built_configurator_config_path, mode="w", encoding="utf-8") as fd: fd.write(text_format.MessageToString(cp)) p = _StartBinary( "fleetspeak-config", ["--logtostderr", "--config", built_configurator_config_path]) if p.wait() != 0: raise ConfigInitializationError( "fleetspeak-config execution failed: {}".format(p.returncode)) # Adjust client config. with open(cp.linux_client_configuration_file, mode="r", encoding="utf-8") as fd: conf_content = fd.read() conf = text_format.Parse(conf_content, client_config_pb2.Config()) conf.filesystem_handler.configuration_directory = temp_root conf.filesystem_handler.state_file = TempPath("client.state") with open(cp.linux_client_configuration_file, mode="w", encoding="utf-8") as fd: fd.write(text_format.MessageToString(conf)) # Write client services configuration. service_conf = system_pb2.ClientServiceConfig(name="GRR", factory="Daemon") payload = daemonservice_config_pb2.Config() payload.argv.extend([ sys.executable, "-u", "-m", "grr_response_client.grr_fs_client", "--config", grr_configs.client_config ]) # TODO(user): remove this condition when Fleetspeak is used as a nanny # on all platforms. if platform.system() == "Windows": payload.monitor_heartbeats = True payload.heartbeat_unresponsive_grace_period_seconds = 45 payload.heartbeat_unresponsive_kill_period_seconds = 15 service_conf.config.Pack(payload) os.mkdir(TempPath("textservices")) with open(TempPath("textservices", "GRR.textproto"), mode="w", encoding="utf-8") as fd: fd.write(text_format.MessageToString(service_conf)) # Server services configuration. service_config = services_pb2.ServiceConfig(name="GRR", factory="GRPC") grpc_config = grpcservice_pb2.Config(target="localhost:%d" % fs_frontend_port, insecure=True) service_config.config.Pack(grpc_config) server_conf = server_pb2.ServerConfig(services=[service_config]) server_conf.broadcast_poll_time.seconds = 1 built_server_services_config_path = TempPath("server.services.config") with open(built_server_services_config_path, mode="w", encoding="utf-8") as fd: fd.write(text_format.MessageToString(server_conf)) return FleetspeakConfigs(cp.server_component_configuration_file, built_server_services_config_path, cp.linux_client_configuration_file)
def _WriteEnabled(self, config): """Applies the in-memory configuration for the use_fleetspeak case.""" service_config = services_pb2.ServiceConfig(name="GRR", factory="GRPC") grpc_config = grpcservice_pb2.Config( target="localhost:{}".format(self.grr_port), insecure=True) service_config.config.Pack(grpc_config) server_conf = server_pb2.ServerConfig(services=[service_config]) server_conf.broadcast_poll_time.seconds = 1 with open(self._ConfigPath("server.services.config"), "w") as f: f.write(text_format.MessageToString(server_conf)) cp = config_pb2.Config() cp.configuration_name = "Fleetspeak" cp.components_config.mysql_data_source_name = ( "{user}:@tcp({host}:{port})/{db}".format( user=self.mysql_username, host=self.mysql_host, port=self.mysql_port, db=self.mysql_database)) cp.components_config.https_config.listen_address = "{}:{}".format( self.external_hostname, self.https_port) cp.components_config.https_config.disable_streaming = True cp.components_config.admin_config.listen_address = "localhost:{}".format( self.admin_port) cp.public_host_port.append(cp.components_config.https_config.listen_address) cp.server_component_configuration_file = self._ConfigPath( "server.components.config") cp.trusted_cert_file = self._ConfigPath("trusted_cert.pem") cp.trusted_cert_key_file = self._ConfigPath("trusted_cert_key.pem") cp.server_cert_file = self._ConfigPath("server_cert.pem") cp.server_cert_key_file = self._ConfigPath("server_cert_key.pem") cp.linux_client_configuration_file = self._ConfigPath("linux_client.config") cp.windows_client_configuration_file = self._ConfigPath( "windows_client.config") cp.darwin_client_configuration_file = self._ConfigPath( "darwin_client.config") p = subprocess.Popen(["fleetspeak-config", "-config", "/dev/stdin"], stdin=subprocess.PIPE) p.communicate(input=text_format.MessageToString(cp).encode()) if p.wait() != 0: raise RuntimeError("fleetspeak-config command failed.") # These modules don't exist on Windows, so importing locally. # pylint: disable=g-import-not-at-top import grp import pwd # pylint: enable=g-import-not-at-top if (os.geteuid() == 0 and pwd.getpwnam("fleetspeak") and grp.getgrnam("fleetspeak")): subprocess.check_call( ["chown", "-R", "fleetspeak:fleetspeak", self._ConfigPath()]) try: os.unlink(self._ConfigPath("disabled")) except FileNotFoundError: pass config.Set("Server.fleetspeak_enabled", True) config.Set("Client.fleetspeak_enabled", True) config.Set("ClientBuilder.fleetspeak_bundled", True) config.Set( "Target:Linux", { "ClientBuilder.fleetspeak_client_config": cp.linux_client_configuration_file }) config.Set( "Target:Windows", { "ClientBuilder.fleetspeak_client_config": cp.windows_client_configuration_file }) config.Set( "Target:Darwin", { "ClientBuilder.fleetspeak_client_config": cp.darwin_client_configuration_file }) config.Set("Server.fleetspeak_server", cp.components_config.admin_config.listen_address) config.Set("FleetspeakFrontend Context", {"Server.fleetspeak_message_listen_address": grpc_config.target})