2018-10-28 00:03:27 +00:00
|
|
|
(* (c) 2018 Hannes Mehnert, all rights reserved *)
|
|
|
|
|
|
|
|
open Lwt.Infix
|
|
|
|
|
2018-11-12 21:11:06 +00:00
|
|
|
let version = `AV3
|
2018-10-28 00:03:27 +00:00
|
|
|
|
|
|
|
let read fd =
|
|
|
|
(* now we busy read and process output *)
|
2018-11-23 19:28:33 +00:00
|
|
|
Logs.debug (fun m -> m "reading tls stream") ;
|
2018-10-28 00:03:27 +00:00
|
|
|
let rec loop () =
|
2018-11-01 00:51:39 +00:00
|
|
|
Vmm_tls_lwt.read_tls fd >>= function
|
|
|
|
| Error _ -> Lwt.return ()
|
|
|
|
| Ok wire ->
|
|
|
|
Vmm_cli.print_result version wire ;
|
|
|
|
loop ()
|
2018-10-28 00:03:27 +00:00
|
|
|
in
|
|
|
|
loop ()
|
|
|
|
|
|
|
|
let key_ids pub issuer =
|
|
|
|
let auth = (Some (X509.key_id issuer), [], None) in
|
|
|
|
[ (false, `Subject_key_id (X509.key_id pub)) ; (false, `Authority_key_id auth) ]
|
|
|
|
|
|
|
|
let timestamps validity =
|
|
|
|
let now = Ptime_clock.now () in
|
|
|
|
match Ptime.add_span now (Ptime.Span.of_int_s validity) with
|
|
|
|
| None -> invalid_arg "span too big - reached end of ptime"
|
|
|
|
| Some exp -> (now, exp)
|
|
|
|
|
|
|
|
let handle (host, port) cert key ca id (cmd : Vmm_commands.t) =
|
|
|
|
Vmm_lwt.read_from_file cert >>= fun cert_cs ->
|
|
|
|
let cert = X509.Encoding.Pem.Certificate.of_pem_cstruct1 cert_cs in
|
|
|
|
Vmm_lwt.read_from_file key >>= fun key_cs ->
|
|
|
|
let key = X509.Encoding.Pem.Private_key.of_pem_cstruct1 key_cs in
|
|
|
|
let tmpkey = Nocrypto.Rsa.generate 4096 in
|
2018-11-11 00:21:12 +00:00
|
|
|
let name = Vmm_core.Name.to_string id in
|
2018-10-28 00:03:27 +00:00
|
|
|
let extensions =
|
|
|
|
[ (true, `Key_usage [ `Digital_signature ; `Key_encipherment ])
|
|
|
|
; (true, `Basic_constraints (false, None))
|
|
|
|
; (true, `Ext_key_usage [`Client_auth]) ;
|
|
|
|
(false, `Unsupported (Vmm_asn.oid, Vmm_asn.cert_extension_to_cstruct (version, cmd))) ] in
|
|
|
|
let csr =
|
|
|
|
let name = [ `CN name ] in
|
|
|
|
X509.CA.request name ~extensions:[`Extensions extensions] (`RSA tmpkey)
|
|
|
|
in
|
|
|
|
let mycert =
|
|
|
|
let valid_from, valid_until = timestamps 300 in
|
|
|
|
let extensions =
|
|
|
|
let capub = match key with `RSA key -> Nocrypto.Rsa.pub_of_priv key in
|
|
|
|
extensions @ key_ids (X509.CA.info csr).X509.CA.public_key (`RSA capub)
|
|
|
|
in
|
|
|
|
let issuer = X509.subject cert in
|
|
|
|
X509.CA.sign csr ~valid_from ~valid_until ~extensions key issuer
|
|
|
|
in
|
|
|
|
let certificates = `Single ([ mycert ; cert ], tmpkey) in
|
|
|
|
X509_lwt.authenticator (`Ca_file ca) >>= fun authenticator ->
|
|
|
|
Lwt_unix.gethostbyname host >>= fun host_entry ->
|
|
|
|
let host_inet_addr = Array.get host_entry.Lwt_unix.h_addr_list 0 in
|
|
|
|
let fd = Lwt_unix.socket host_entry.Lwt_unix.h_addrtype Lwt_unix.SOCK_STREAM 0 in
|
2018-11-23 19:28:33 +00:00
|
|
|
Logs.debug (fun m -> m "connecting to remote host") ;
|
2018-10-29 16:14:51 +00:00
|
|
|
Lwt_unix.connect fd (Lwt_unix.ADDR_INET (host_inet_addr, port)) >>= fun () ->
|
2018-10-28 00:03:27 +00:00
|
|
|
let client = Tls.Config.client ~reneg:true ~certificates ~authenticator () in
|
2018-10-29 16:14:51 +00:00
|
|
|
Tls_lwt.Unix.client_of_fd client (* TODO ~host *) fd >>= fun t ->
|
2018-11-23 19:28:33 +00:00
|
|
|
Logs.debug (fun m -> m "finished tls handshake") ;
|
2018-10-28 00:03:27 +00:00
|
|
|
read t
|
|
|
|
|
|
|
|
let jump endp cert key ca name cmd =
|
2018-11-01 00:51:39 +00:00
|
|
|
`Ok (Lwt_main.run (handle endp cert key ca name cmd))
|
2018-10-28 00:03:27 +00:00
|
|
|
|
2018-10-28 21:14:39 +00:00
|
|
|
let info_policy _ endp cert key ca name =
|
|
|
|
jump endp cert key ca name (`Policy_cmd `Policy_info)
|
2018-10-28 00:03:27 +00:00
|
|
|
|
|
|
|
let remove_policy _ endp cert key ca name =
|
|
|
|
jump endp cert key ca name (`Policy_cmd `Policy_remove)
|
|
|
|
|
|
|
|
let add_policy _ endp cert key ca name vms memory cpus block bridges =
|
2018-10-28 21:14:39 +00:00
|
|
|
let p = Vmm_cli.policy vms memory cpus block bridges in
|
|
|
|
jump endp cert key ca name (`Policy_cmd (`Policy_add p))
|
2018-10-28 00:03:27 +00:00
|
|
|
|
2018-11-13 00:02:05 +00:00
|
|
|
let info_ _ endp cert key ca name =
|
|
|
|
jump endp cert key ca name (`Unikernel_cmd `Unikernel_info)
|
|
|
|
|
2018-10-28 00:03:27 +00:00
|
|
|
let destroy _ endp cert key ca name =
|
2018-11-13 00:02:05 +00:00
|
|
|
jump endp cert key ca name (`Unikernel_cmd `Unikernel_destroy)
|
2018-10-28 00:03:27 +00:00
|
|
|
|
2018-11-13 00:02:05 +00:00
|
|
|
let create _ endp cert key ca force name image cpuid memory argv block network compression =
|
|
|
|
match Vmm_cli.create_vm force image cpuid memory argv block network compression with
|
|
|
|
| Ok cmd -> jump endp cert key ca name (`Unikernel_cmd cmd)
|
2018-10-28 21:14:39 +00:00
|
|
|
| Error (`Msg msg) -> `Error (false, msg)
|
2018-10-28 00:03:27 +00:00
|
|
|
|
|
|
|
let console _ endp cert key ca name since =
|
|
|
|
jump endp cert key ca name (`Console_cmd (`Console_subscribe since))
|
|
|
|
|
|
|
|
let stats _ endp cert key ca name =
|
|
|
|
jump endp cert key ca name (`Stats_cmd `Stats_subscribe)
|
|
|
|
|
|
|
|
let event_log _ endp cert key ca name since =
|
|
|
|
jump endp cert key ca name (`Log_cmd (`Log_subscribe since))
|
|
|
|
|
2018-11-10 00:02:07 +00:00
|
|
|
let block_info _ endp cert key ca block_name =
|
|
|
|
jump endp cert key ca block_name (`Block_cmd `Block_info)
|
|
|
|
|
|
|
|
let block_create _ endp cert key ca block_name block_size =
|
|
|
|
jump endp cert key ca block_name (`Block_cmd (`Block_add block_size))
|
|
|
|
|
|
|
|
let block_destroy _ endp cert key ca block_name =
|
|
|
|
jump endp cert key ca block_name (`Block_cmd `Block_remove)
|
|
|
|
|
2018-10-28 00:03:27 +00:00
|
|
|
let help _ _ man_format cmds = function
|
|
|
|
| None -> `Help (`Pager, None)
|
|
|
|
| Some t when List.mem t cmds -> `Help (man_format, Some t)
|
|
|
|
| Some _ -> List.iter print_endline cmds; `Ok ()
|
|
|
|
|
|
|
|
open Cmdliner
|
|
|
|
open Vmm_cli
|
|
|
|
|
|
|
|
let server_ca =
|
|
|
|
let doc = "The certificate authority used to verify the remote server." in
|
|
|
|
Arg.(value & opt string "cacert.pem" & info [ "server-ca" ] ~doc)
|
|
|
|
|
|
|
|
let ca_cert =
|
|
|
|
let doc = "The certificate authority used to issue the certificate" in
|
|
|
|
Arg.(value & opt string "ca.pem" & info [ "ca" ] ~doc)
|
|
|
|
|
|
|
|
let ca_key =
|
|
|
|
let doc = "The private key of the signing certificate authority" in
|
|
|
|
Arg.(value & opt string "ca.key" & info [ "ca-key" ] ~doc)
|
|
|
|
|
|
|
|
let destination =
|
2018-10-28 23:32:07 +00:00
|
|
|
let doc = "the destination hostname:port to connect to" in
|
2018-10-31 22:41:22 +00:00
|
|
|
Arg.(value & opt host_port ("localhost", 1025) & info [ "d" ; "destination" ] ~doc ~docv:"HOST:PORT")
|
2018-10-28 00:03:27 +00:00
|
|
|
|
|
|
|
let destroy_cmd =
|
|
|
|
let doc = "destroys a virtual machine" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Destroy a virtual machine."]
|
|
|
|
in
|
|
|
|
Term.(ret (const destroy $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ vm_name)),
|
|
|
|
Term.info "destroy" ~doc ~man
|
|
|
|
|
|
|
|
let remove_policy_cmd =
|
|
|
|
let doc = "removes a policy" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Removes a policy."]
|
|
|
|
in
|
|
|
|
Term.(ret (const remove_policy $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ opt_vm_name)),
|
|
|
|
Term.info "remove_policy" ~doc ~man
|
|
|
|
|
|
|
|
let info_cmd =
|
|
|
|
let doc = "information about VMs" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Shows information about VMs."]
|
|
|
|
in
|
|
|
|
Term.(ret (const info_ $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ opt_vm_name)),
|
|
|
|
Term.info "info" ~doc ~man
|
|
|
|
|
|
|
|
let policy_cmd =
|
|
|
|
let doc = "active policies" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Shows information about policies."]
|
|
|
|
in
|
2018-10-28 21:14:39 +00:00
|
|
|
Term.(ret (const info_policy $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ opt_vm_name)),
|
2018-10-28 00:03:27 +00:00
|
|
|
Term.info "policy" ~doc ~man
|
|
|
|
|
|
|
|
let add_policy_cmd =
|
|
|
|
let doc = "Add a policy" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Adds a policy."]
|
|
|
|
in
|
2018-11-10 00:02:07 +00:00
|
|
|
Term.(ret (const add_policy $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ vm_name $ vms $ mem $ cpus $ opt_block_size $ bridge)),
|
2018-10-28 00:03:27 +00:00
|
|
|
Term.info "add_policy" ~doc ~man
|
|
|
|
|
|
|
|
let create_cmd =
|
|
|
|
let doc = "creates a virtual machine" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Creates a virtual machine."]
|
|
|
|
in
|
2018-10-28 22:06:15 +00:00
|
|
|
Term.(ret (const create $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ force $ vm_name $ image $ cpu $ vm_mem $ args $ block $ net $ compress_level)),
|
2018-10-28 00:03:27 +00:00
|
|
|
Term.info "create" ~doc ~man
|
|
|
|
|
|
|
|
let console_cmd =
|
|
|
|
let doc = "console of a VM" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Shows console output of a VM."]
|
|
|
|
in
|
|
|
|
Term.(ret (const console $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ vm_name $ since)),
|
|
|
|
Term.info "console" ~doc ~man
|
|
|
|
|
|
|
|
let stats_cmd =
|
|
|
|
let doc = "statistics of VMs" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Shows statistics of VMs."]
|
|
|
|
in
|
|
|
|
Term.(ret (const stats $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ opt_vm_name)),
|
|
|
|
Term.info "stats" ~doc ~man
|
|
|
|
|
|
|
|
let log_cmd =
|
|
|
|
let doc = "Event log" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Shows event log of VM."]
|
|
|
|
in
|
|
|
|
Term.(ret (const event_log $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ opt_vm_name $ since)),
|
|
|
|
Term.info "log" ~doc ~man
|
|
|
|
|
2018-11-10 00:02:07 +00:00
|
|
|
let block_info_cmd =
|
|
|
|
let doc = "Information about block devices" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Block device information."]
|
|
|
|
in
|
|
|
|
Term.(ret (const block_info $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ opt_block_name)),
|
|
|
|
Term.info "block" ~doc ~man
|
|
|
|
|
|
|
|
let block_create_cmd =
|
|
|
|
let doc = "Create a block device" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Creation of a block device."]
|
|
|
|
in
|
|
|
|
Term.(ret (const block_create $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ block_name $ block_size)),
|
|
|
|
Term.info "create_block" ~doc ~man
|
|
|
|
|
|
|
|
let block_destroy_cmd =
|
|
|
|
let doc = "Destroys a block device" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Destroys a block device."]
|
|
|
|
in
|
|
|
|
Term.(ret (const block_destroy $ setup_log $ destination $ ca_cert $ ca_key $ server_ca $ block_name)),
|
|
|
|
Term.info "destroy_block" ~doc ~man
|
|
|
|
|
2018-10-28 00:03:27 +00:00
|
|
|
let help_cmd =
|
|
|
|
let topic =
|
|
|
|
let doc = "The topic to get help on. `topics' lists the topics." in
|
|
|
|
Arg.(value & pos 0 (some string) None & info [] ~docv:"TOPIC" ~doc)
|
|
|
|
in
|
|
|
|
let doc = "display help about vmmc" in
|
|
|
|
let man =
|
|
|
|
[`S "DESCRIPTION";
|
|
|
|
`P "Prints help about conex commands and subcommands"]
|
|
|
|
in
|
|
|
|
Term.(ret (const help $ setup_log $ destination $ Term.man_format $ Term.choice_names $ topic)),
|
|
|
|
Term.info "help" ~doc ~man
|
|
|
|
|
|
|
|
let default_cmd =
|
|
|
|
let doc = "VMM client and go to bistro" in
|
|
|
|
let man = [
|
|
|
|
`S "DESCRIPTION" ;
|
|
|
|
`P "$(tname) executes the provided subcommand on a remote albatross" ]
|
|
|
|
in
|
|
|
|
Term.(ret (const help $ setup_log $ destination $ Term.man_format $ Term.choice_names $ Term.pure None)),
|
|
|
|
Term.info "vmmc_bistro" ~version:"%%VERSION_NUM%%" ~doc ~man
|
|
|
|
|
2018-11-10 00:02:07 +00:00
|
|
|
let cmds = [ help_cmd ; info_cmd ;
|
|
|
|
policy_cmd ; remove_policy_cmd ; add_policy_cmd ;
|
|
|
|
destroy_cmd ; create_cmd ;
|
|
|
|
block_info_cmd ; block_create_cmd ; block_destroy_cmd ;
|
|
|
|
console_cmd ; stats_cmd ; log_cmd ]
|
2018-10-28 00:03:27 +00:00
|
|
|
|
|
|
|
let () =
|
|
|
|
match Term.eval_choice default_cmd cmds
|
|
|
|
with `Ok () -> exit 0 | _ -> exit 1
|