natstable.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package models
  15. import (
  16. "context"
  17. "yunion.io/x/cloudmux/pkg/cloudprovider"
  18. "yunion.io/x/jsonutils"
  19. "yunion.io/x/pkg/errors"
  20. "yunion.io/x/pkg/util/compare"
  21. "yunion.io/x/pkg/util/netutils"
  22. "yunion.io/x/sqlchemy"
  23. api "yunion.io/x/onecloud/pkg/apis/compute"
  24. "yunion.io/x/onecloud/pkg/cloudcommon/db"
  25. "yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
  26. "yunion.io/x/onecloud/pkg/cloudcommon/db/taskman"
  27. "yunion.io/x/onecloud/pkg/cloudcommon/validators"
  28. "yunion.io/x/onecloud/pkg/httperrors"
  29. "yunion.io/x/onecloud/pkg/mcclient"
  30. "yunion.io/x/onecloud/pkg/util/stringutils2"
  31. )
  32. // +onecloud:swagger-gen-model-singular=natsentry
  33. // +onecloud:swagger-gen-model-plural=natsenties
  34. type SNatSEntryManager struct {
  35. SNatEntryManager
  36. SNetworkResourceBaseManager
  37. }
  38. var NatSEntryManager *SNatSEntryManager
  39. func init() {
  40. NatSEntryManager = &SNatSEntryManager{
  41. SNatEntryManager: NewNatEntryManager(
  42. SNatSEntry{},
  43. "natstables_tbl",
  44. "natsentry",
  45. "natsentries",
  46. ),
  47. }
  48. NatSEntryManager.SetVirtualObject(NatSEntryManager)
  49. }
  50. type SNatSEntry struct {
  51. SNatEntry
  52. SNetworkResourceBase
  53. IP string `charset:"ascii" list:"user" create:"required"`
  54. SourceCIDR string `width:"22" charset:"ascii" list:"user" create:"optional"`
  55. }
  56. func (self *SNatSEntry) GetCloudproviderId() string {
  57. network, err := self.GetNetwork()
  58. if err == nil {
  59. return network.GetCloudproviderId()
  60. }
  61. return ""
  62. }
  63. func (self *SNatSEntry) GetNetwork() (*SNetwork, error) {
  64. if len(self.NetworkId) == 0 {
  65. return nil, nil
  66. }
  67. _network, err := NetworkManager.FetchById(self.NetworkId)
  68. if err != nil {
  69. return nil, err
  70. }
  71. return _network.(*SNetwork), nil
  72. }
  73. // NAT网关的源地址转换规则列表
  74. func (man *SNatSEntryManager) ListItemFilter(
  75. ctx context.Context,
  76. q *sqlchemy.SQuery,
  77. userCred mcclient.TokenCredential,
  78. query api.NatSEntryListInput,
  79. ) (*sqlchemy.SQuery, error) {
  80. q, err := man.SNatEntryManager.ListItemFilter(ctx, q, userCred, query.NatEntryListInput)
  81. if err != nil {
  82. return nil, errors.Wrap(err, "SNatEntryManager.ListItemFilter")
  83. }
  84. netQuery := api.NetworkFilterListInput{
  85. NetworkFilterListBase: query.NetworkFilterListBase,
  86. }
  87. q, err = man.SNetworkResourceBaseManager.ListItemFilter(ctx, q, userCred, netQuery)
  88. if err != nil {
  89. return nil, errors.Wrap(err, "SNetworkResourceBaseManager.ListItemFilter")
  90. }
  91. if len(query.IP) > 0 {
  92. q = q.In("ip", query.IP)
  93. }
  94. if len(query.SourceCIDR) > 0 {
  95. q = q.In("source_cidr", query.SourceCIDR)
  96. }
  97. return q, nil
  98. }
  99. func (manager *SNatSEntryManager) OrderByExtraFields(
  100. ctx context.Context,
  101. q *sqlchemy.SQuery,
  102. userCred mcclient.TokenCredential,
  103. query api.NatSEntryListInput,
  104. ) (*sqlchemy.SQuery, error) {
  105. var err error
  106. q, err = manager.SNatEntryManager.OrderByExtraFields(ctx, q, userCred, query.NatEntryListInput)
  107. if err != nil {
  108. return nil, errors.Wrap(err, "SNatEntryManager.OrderByExtraFields")
  109. }
  110. netQuery := api.NetworkFilterListInput{
  111. NetworkFilterListBase: query.NetworkFilterListBase,
  112. }
  113. q, err = manager.SNetworkResourceBaseManager.OrderByExtraFields(ctx, q, userCred, netQuery)
  114. if err != nil {
  115. return nil, errors.Wrap(err, "SNetworkResourceBaseManager.OrderByExtraFields")
  116. }
  117. return q, nil
  118. }
  119. func (manager *SNatSEntryManager) QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error) {
  120. var err error
  121. q, err = manager.SNatEntryManager.QueryDistinctExtraField(q, field)
  122. if err == nil {
  123. return q, nil
  124. }
  125. q, err = manager.SNetworkResourceBaseManager.QueryDistinctExtraField(q, field)
  126. if err == nil {
  127. return q, nil
  128. }
  129. return q, httperrors.ErrNotFound
  130. }
  131. func (self *SNatSEntry) GetUniqValues() jsonutils.JSONObject {
  132. return jsonutils.Marshal(map[string]string{"natgateway_id": self.NatgatewayId})
  133. }
  134. func (manager *SNatSEntryManager) FetchUniqValues(ctx context.Context, data jsonutils.JSONObject) jsonutils.JSONObject {
  135. natId, _ := data.GetString("natgateway_id")
  136. return jsonutils.Marshal(map[string]string{"natgateway_id": natId})
  137. }
  138. func (manager *SNatSEntryManager) FilterByUniqValues(q *sqlchemy.SQuery, values jsonutils.JSONObject) *sqlchemy.SQuery {
  139. natId, _ := values.GetString("natgateway_id")
  140. if len(natId) > 0 {
  141. q = q.Equals("natgateway_id", natId)
  142. }
  143. return q
  144. }
  145. func (man *SNatSEntryManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential,
  146. ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, input *api.SNatSCreateInput) (*api.SNatSCreateInput, error) {
  147. if len(input.NatgatewayId) == 0 {
  148. return nil, httperrors.NewMissingParameterError("natgateway_id")
  149. }
  150. if len(input.Eip) == 0 {
  151. return nil, httperrors.NewMissingParameterError("eip")
  152. }
  153. if len(input.SourceCidr) == 0 && len(input.NetworkId) == 0 {
  154. return nil, httperrors.NewMissingParameterError("network_id")
  155. }
  156. if len(input.SourceCidr) > 0 && len(input.NetworkId) > 0 {
  157. return nil, httperrors.NewInputParameterError("source_cidr and network_id conflict")
  158. }
  159. _nat, err := validators.ValidateModel(ctx, userCred, NatGatewayManager, &input.NatgatewayId)
  160. if err != nil {
  161. return nil, err
  162. }
  163. nat := _nat.(*SNatGateway)
  164. if len(input.SourceCidr) > 0 {
  165. cidr, err := netutils.NewIPV4Prefix(input.SourceCidr)
  166. if err != nil {
  167. return nil, httperrors.NewInputParameterError("input.SourceCidr")
  168. }
  169. vpc, err := nat.GetVpc()
  170. if err != nil {
  171. return nil, errors.Wrapf(err, "GetVpc")
  172. }
  173. vpcRange, err := netutils.NewIPV4Prefix(vpc.CidrBlock)
  174. if err != nil {
  175. return nil, errors.Wrapf(err, "vpc cidr %s", vpc.CidrBlock)
  176. }
  177. if !vpcRange.ToIPRange().ContainsRange(cidr.ToIPRange()) {
  178. return nil, httperrors.NewInputParameterError("cidr %s is not in range vpc %s", input.SourceCidr, vpc.CidrBlock)
  179. }
  180. } else {
  181. _network, err := validators.ValidateModel(ctx, userCred, NetworkManager, &input.NetworkId)
  182. if err != nil {
  183. return nil, err
  184. }
  185. network := _network.(*SNetwork)
  186. vpc, _ := network.GetVpc()
  187. if vpc == nil {
  188. return nil, httperrors.NewGeneralError(errors.Wrapf(err, "network.GetVpc"))
  189. }
  190. if vpc.Id != nat.VpcId {
  191. return nil, httperrors.NewInputParameterError("network %s not in vpc %s", network.Name, vpc.Name)
  192. }
  193. }
  194. _eip, err := validators.ValidateModel(ctx, userCred, ElasticipManager, &input.Eip)
  195. if err != nil {
  196. return nil, err
  197. }
  198. eip := _eip.(*SElasticip)
  199. input.Ip = eip.IpAddr
  200. // check that eip is suitable
  201. if len(eip.AssociateId) > 0 && eip.AssociateId != input.NatgatewayId {
  202. return nil, httperrors.NewInputParameterError("eip has been binding to another instance")
  203. }
  204. return input, nil
  205. }
  206. func (manager *SNatSEntryManager) SyncNatSTable(
  207. ctx context.Context,
  208. userCred mcclient.TokenCredential,
  209. provider *SCloudprovider,
  210. nat *SNatGateway,
  211. extTable []cloudprovider.ICloudNatSEntry,
  212. xor bool,
  213. ) compare.SyncResult {
  214. syncOwnerId := provider.GetOwnerId()
  215. lockman.LockRawObject(ctx, manager.Keyword(), nat.Id)
  216. defer lockman.ReleaseRawObject(ctx, manager.Keyword(), nat.Id)
  217. result := compare.SyncResult{}
  218. dbNatSTables, err := nat.GetSTable()
  219. if err != nil {
  220. result.Error(err)
  221. return result
  222. }
  223. removed := make([]SNatSEntry, 0)
  224. commondb := make([]SNatSEntry, 0)
  225. commonext := make([]cloudprovider.ICloudNatSEntry, 0)
  226. added := make([]cloudprovider.ICloudNatSEntry, 0)
  227. if err := compare.CompareSets(dbNatSTables, extTable, &removed, &commondb, &commonext, &added); err != nil {
  228. result.Error(err)
  229. return result
  230. }
  231. for i := 0; i < len(removed); i += 1 {
  232. err := removed[i].syncRemoveCloudNatSTable(ctx, userCred)
  233. if err != nil {
  234. result.DeleteError(err)
  235. } else {
  236. result.Delete()
  237. }
  238. }
  239. if !xor {
  240. for i := 0; i < len(commondb); i += 1 {
  241. err := commondb[i].SyncWithCloudNatSTable(ctx, userCred, commonext[i], syncOwnerId, provider)
  242. if err != nil {
  243. result.UpdateError(err)
  244. continue
  245. }
  246. result.Update()
  247. }
  248. }
  249. for i := 0; i < len(added); i += 1 {
  250. _, err := manager.newFromCloudNatSTable(ctx, userCred, syncOwnerId, nat, added[i], provider.Id)
  251. if err != nil {
  252. result.AddError(err)
  253. continue
  254. }
  255. result.Add()
  256. }
  257. return result
  258. }
  259. func (self *SNatSEntry) syncRemoveCloudNatSTable(ctx context.Context, userCred mcclient.TokenCredential) error {
  260. lockman.LockObject(ctx, self)
  261. defer lockman.ReleaseObject(ctx, self)
  262. err := self.ValidateDeleteCondition(ctx, nil)
  263. if err != nil { // cannot delete
  264. return self.SetStatus(ctx, userCred, api.VPC_STATUS_UNKNOWN, "sync to delete")
  265. }
  266. return self.RealDelete(ctx, userCred)
  267. }
  268. func (self *SNatSEntry) SyncWithCloudNatSTable(ctx context.Context, userCred mcclient.TokenCredential, extEntry cloudprovider.ICloudNatSEntry, syncOwnerId mcclient.IIdentityProvider, provider *SCloudprovider) error {
  269. diff, err := db.UpdateWithLock(ctx, self, func() error {
  270. self.Status = extEntry.GetStatus()
  271. self.IP = extEntry.GetIP()
  272. self.SourceCIDR = extEntry.GetSourceCIDR()
  273. if extNetworkId := extEntry.GetNetworkId(); len(extNetworkId) > 0 {
  274. network, err := db.FetchByExternalIdAndManagerId(NetworkManager, extNetworkId, func(q *sqlchemy.SQuery) *sqlchemy.SQuery {
  275. wire := WireManager.Query().SubQuery()
  276. vpc := VpcManager.Query().SubQuery()
  277. return q.Join(wire, sqlchemy.Equals(wire.Field("id"), q.Field("wire_id"))).
  278. Join(vpc, sqlchemy.Equals(vpc.Field("id"), wire.Field("vpc_id"))).
  279. Filter(sqlchemy.Equals(vpc.Field("manager_id"), provider.Id))
  280. })
  281. if err != nil {
  282. return errors.Wrapf(err, "search network by externalId: %s", extNetworkId)
  283. }
  284. self.NetworkId = network.GetId()
  285. }
  286. return nil
  287. })
  288. if err != nil {
  289. return err
  290. }
  291. SyncCloudDomain(userCred, self, syncOwnerId)
  292. if account, _ := provider.GetCloudaccount(); account != nil {
  293. syncMetadata(ctx, userCred, self, extEntry, account.ReadOnly)
  294. }
  295. db.OpsLog.LogSyncUpdate(self, diff, userCred)
  296. return nil
  297. }
  298. func (manager *SNatSEntryManager) newFromCloudNatSTable(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, nat *SNatGateway, extEntry cloudprovider.ICloudNatSEntry, managerId string) (*SNatSEntry, error) {
  299. table := SNatSEntry{}
  300. table.SetModelManager(manager, &table)
  301. table.Status = extEntry.GetStatus()
  302. table.ExternalId = extEntry.GetGlobalId()
  303. table.IsEmulated = extEntry.IsEmulated()
  304. table.NatgatewayId = nat.Id
  305. table.IP = extEntry.GetIP()
  306. table.SourceCIDR = extEntry.GetSourceCIDR()
  307. if extNetworkId := extEntry.GetNetworkId(); len(extNetworkId) > 0 {
  308. network, err := db.FetchByExternalIdAndManagerId(NetworkManager, extNetworkId, func(q *sqlchemy.SQuery) *sqlchemy.SQuery {
  309. wire := WireManager.Query().SubQuery()
  310. vpc := VpcManager.Query().SubQuery()
  311. return q.Join(wire, sqlchemy.Equals(wire.Field("id"), q.Field("wire_id"))).
  312. Join(vpc, sqlchemy.Equals(vpc.Field("id"), wire.Field("vpc_id"))).
  313. Filter(sqlchemy.Equals(vpc.Field("manager_id"), managerId))
  314. })
  315. if err != nil {
  316. return nil, err
  317. }
  318. table.NetworkId = network.GetId()
  319. }
  320. var err = func() error {
  321. lockman.LockRawObject(ctx, manager.Keyword(), "name")
  322. defer lockman.ReleaseRawObject(ctx, manager.Keyword(), "name")
  323. var err error
  324. table.Name, err = db.GenerateName(ctx, manager, ownerId, extEntry.GetName())
  325. if err != nil {
  326. return err
  327. }
  328. return manager.TableSpec().Insert(ctx, &table)
  329. }()
  330. if err != nil {
  331. return nil, errors.Wrapf(err, "Insert")
  332. }
  333. SyncCloudDomain(userCred, &table, ownerId)
  334. syncMetadata(ctx, userCred, &table, extEntry, false)
  335. db.OpsLog.LogEvent(&table, db.ACT_CREATE, table.GetShortDesc(ctx), userCred)
  336. return &table, nil
  337. }
  338. func (manager *SNatSEntryManager) FetchCustomizeColumns(
  339. ctx context.Context,
  340. userCred mcclient.TokenCredential,
  341. query jsonutils.JSONObject,
  342. objs []interface{},
  343. fields stringutils2.SSortedStrings,
  344. isList bool,
  345. ) []api.NatSEntryDetails {
  346. rows := make([]api.NatSEntryDetails, len(objs))
  347. netIds := make([]string, len(objs))
  348. entryRows := manager.SNatEntryManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
  349. for i := range rows {
  350. rows[i] = api.NatSEntryDetails{
  351. NatEntryDetails: entryRows[i],
  352. }
  353. netIds[i] = objs[i].(*SNatSEntry).NetworkId
  354. }
  355. nets := make(map[string]SNetwork)
  356. err := db.FetchStandaloneObjectsByIds(NetworkManager, netIds, &nets)
  357. if err != nil {
  358. return rows
  359. }
  360. for i := range rows {
  361. if net, ok := nets[netIds[i]]; ok {
  362. rows[i].Network = api.SimpleNetwork{
  363. Id: net.Id,
  364. Name: net.Name,
  365. GuestIpStart: net.GuestIpStart,
  366. GuestIpEnd: net.GuestIpEnd,
  367. GuestIp6Start: net.GuestIp6Start,
  368. GuestIp6End: net.GuestIp6End,
  369. }
  370. }
  371. }
  372. return rows
  373. }
  374. func (self *SNatSEntry) PostCreate(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) {
  375. var err = func() error {
  376. task, err := taskman.TaskManager.NewTask(ctx, "SNatSEntryCreateTask", self, userCred, nil, "", "", nil)
  377. if err != nil {
  378. return errors.Wrapf(err, "NewTask")
  379. }
  380. return task.ScheduleRun(nil)
  381. }()
  382. if err != nil {
  383. self.SetStatus(ctx, userCred, api.NAT_STATUS_CREATE_FAILED, err.Error())
  384. return
  385. }
  386. self.SetStatus(ctx, userCred, api.NAT_STATUS_ALLOCATE, "")
  387. }
  388. func (self *SNatSEntry) CustomizeDelete(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) error {
  389. return self.StartDeleteSNatTask(ctx, userCred)
  390. }
  391. func (self *SNatSEntry) StartDeleteSNatTask(ctx context.Context, userCred mcclient.TokenCredential) error {
  392. var err = func() error {
  393. task, err := taskman.TaskManager.NewTask(ctx, "SNatSEntryDeleteTask", self, userCred, nil, "", "", nil)
  394. if err != nil {
  395. return errors.Wrapf(err, "NewTask")
  396. }
  397. return task.ScheduleRun(nil)
  398. }()
  399. if err != nil {
  400. self.SetStatus(ctx, userCred, api.NAT_STATUS_DELETE_FAILED, err.Error())
  401. return err
  402. }
  403. self.SetStatus(ctx, userCred, api.NAT_STATUS_DELETING, "")
  404. return nil
  405. }
  406. func (self *SNatSEntry) GetEip() (*SElasticip, error) {
  407. q := ElasticipManager.Query().Equals("ip_addr", self.IP)
  408. eips := []SElasticip{}
  409. err := db.FetchModelObjects(ElasticipManager, q, &eips)
  410. if err != nil {
  411. return nil, errors.Wrapf(err, "db.FetchModelObjects")
  412. }
  413. if len(eips) == 1 {
  414. return &eips[0], nil
  415. }
  416. if len(eips) == 0 {
  417. return nil, errors.Wrapf(cloudprovider.ErrNotFound, "%v", self.IP)
  418. }
  419. return nil, errors.Wrapf(cloudprovider.ErrDuplicateId, "%v", self.IP)
  420. }