19 #include <libxml/relaxng.h> 20 #include <libxslt/xslt.h> 21 #include <libxslt/transform.h> 22 #include <libxslt/security.h> 23 #include <libxslt/xsltutils.h> 33 #define SCHEMA_ZERO { .v = { 0, 0 } } 35 #define schema_scanf(s, prefix, version, suffix) \ 36 sscanf((s), prefix "%hhu.%hhu" suffix, &((version).v[0]), &((version).v[1])) 38 #define schema_strdup_printf(prefix, version, suffix) \ 39 crm_strdup_printf(prefix "%u.%u" suffix, (version).v[0], (version).v[1]) 43 xmlRelaxNGValidCtxtPtr valid;
44 xmlRelaxNGParserCtxtPtr parser;
45 } relaxng_ctx_cache_t;
59 char *transform_enter;
60 bool transform_onleave;
63 static struct schema_s *known_schemas = NULL;
64 static int xml_schema_max = 0;
65 static bool silent_logging = FALSE;
68 xml_log(
int priority,
const char *fmt, ...)
72 xml_log(
int priority, const
char *fmt, ...)
77 if (silent_logging == FALSE) {
85 xml_latest_schema_index(
void)
87 return xml_schema_max - 3;
91 xml_minimum_schema_index(
void)
97 best = xml_latest_schema_index();
98 for (lpc = best; lpc > 0; lpc--) {
99 if (known_schemas[lpc].
version.v[0]
100 < known_schemas[best].version.v[0]) {
106 best = xml_latest_schema_index();
118 version_from_filename(
const char *filename, schema_version_t *
version)
126 schema_filter(
const struct dirent *a)
131 if (strstr(a->d_name,
"pacemaker-") != a->d_name) {
137 }
else if (!version_from_filename(a->d_name, &
version)) {
149 schema_sort(
const struct dirent **a,
const struct dirent **b)
154 if (!version_from_filename(a[0]->d_name, &a_version)
155 || !version_from_filename(b[0]->d_name, &b_version)) {
160 for (
int i = 0; i < 2; ++i) {
161 if (a_version.v[i] < b_version.v[i]) {
163 }
else if (a_version.v[i] > b_version.v[i]) {
179 const char *
name,
const char *transform,
180 const char *transform_enter,
bool transform_onleave,
183 int last = xml_schema_max;
184 bool have_version = FALSE;
187 known_schemas = pcmk__realloc(known_schemas,
188 xml_schema_max *
sizeof(
struct schema_s));
190 memset(known_schemas+last, 0,
sizeof(
struct schema_s));
191 known_schemas[last].validator = validator;
192 known_schemas[last].after_transform = after_transform;
194 for (
int i = 0; i < 2; ++i) {
195 known_schemas[last].version.v[i] =
version->v[i];
205 known_schemas[last].name = strdup(
name);
209 known_schemas[last].transform = strdup(transform);
211 if (transform_enter) {
212 known_schemas[last].transform_enter = strdup(transform_enter);
214 known_schemas[last].transform_onleave = transform_onleave;
215 if (after_transform == 0) {
216 after_transform = xml_schema_max;
218 known_schemas[last].after_transform = after_transform;
220 if (known_schemas[last].after_transform < 0) {
221 crm_debug(
"Added supported schema %d: %s",
222 last, known_schemas[last].
name);
224 }
else if (known_schemas[last].transform) {
225 crm_debug(
"Added supported schema %d: %s (upgrades to %d with %s.xsl)",
226 last, known_schemas[last].
name,
227 known_schemas[last].after_transform,
228 known_schemas[last].transform);
231 crm_debug(
"Added supported schema %d: %s (upgrades to %d)",
232 last, known_schemas[last].
name,
233 known_schemas[last].after_transform);
266 add_schema_by_version(
const schema_version_t *
version,
int next,
267 bool transform_expected)
269 bool transform_onleave = FALSE;
273 *transform_upgrade = NULL,
274 *transform_enter = NULL;
277 if (transform_expected) {
284 if (!transform_expected) {
287 }
else if (stat(xslt, &s) == 0) {
293 if (stat(xslt, &s) != 0) {
295 crm_debug(
"Upgrade-enter transform %s.xsl not found", xslt);
297 free(transform_enter);
298 transform_enter = strdup(
"upgrade-enter");
301 if (stat(xslt, &s) != 0) {
302 crm_debug(
"Upgrade-enter transform %s.xsl not found, either", xslt);
310 memcpy(strrchr(xslt,
'-') + 1,
"leave",
sizeof(
"leave") - 1);
311 transform_onleave = (stat(xslt, &s) == 0);
314 free(transform_enter);
315 transform_enter = NULL;
319 crm_err(
"Upgrade transform %s not found", xslt);
321 free(transform_upgrade);
322 transform_upgrade = NULL;
328 transform_upgrade, transform_enter, transform_onleave, next);
330 free(transform_upgrade);
331 free(transform_enter);
337 wrap_libxslt(
bool finalize)
339 static xsltSecurityPrefsPtr secprefs;
345 secprefs = xsltNewSecurityPrefs();
346 ret = xsltSetSecurityPrefs(secprefs, XSLT_SECPREF_WRITE_FILE,
348 | xsltSetSecurityPrefs(secprefs, XSLT_SECPREF_CREATE_DIRECTORY,
350 | xsltSetSecurityPrefs(secprefs, XSLT_SECPREF_READ_NETWORK,
352 | xsltSetSecurityPrefs(secprefs, XSLT_SECPREF_WRITE_NETWORK,
358 xsltFreeSecurityPrefs(secprefs);
364 xsltCleanupGlobals();
380 struct dirent **namelist = NULL;
385 max = scandir(base, &namelist, schema_filter, schema_sort);
392 for (lpc = 0; lpc < max; lpc++) {
393 bool transform_expected = FALSE;
397 if (!version_from_filename(namelist[lpc]->d_name, &
version)) {
399 crm_err(
"Skipping schema '%s': could not parse version",
400 namelist[lpc]->d_name);
403 if ((lpc + 1) < max) {
406 if (version_from_filename(namelist[lpc+1]->d_name, &next_version)
407 && (
version.v[0] < next_version.v[0])) {
408 transform_expected = TRUE;
414 if (add_schema_by_version(&
version, next, transform_expected)
420 for (lpc = 0; lpc < max; lpc++) {
427 NULL, NULL, FALSE, -1);
430 NULL, NULL, FALSE, -1);
435 relaxng_invalid_stderr(
void *userData, xmlErrorPtr error)
455 crm_err(
"Structured error: line=%d, level=%d %s", error->line, error->level, error->message);
460 validate_with_relaxng(xmlDocPtr doc, gboolean to_logs,
const char *relaxng_file,
461 relaxng_ctx_cache_t **cached_ctx)
464 gboolean valid = TRUE;
465 relaxng_ctx_cache_t *ctx = NULL;
468 CRM_CHECK(relaxng_file != NULL,
return FALSE);
470 if (cached_ctx && *cached_ctx) {
474 crm_debug(
"Creating RNG parser context");
475 ctx = calloc(1,
sizeof(relaxng_ctx_cache_t));
477 xmlLoadExtDtdDefaultValue = 1;
478 ctx->parser = xmlRelaxNGNewParserCtxt(relaxng_file);
479 CRM_CHECK(ctx->parser != NULL,
goto cleanup);
482 xmlRelaxNGSetParserErrors(ctx->parser,
483 (xmlRelaxNGValidityErrorFunc) xml_log,
484 (xmlRelaxNGValidityWarningFunc) xml_log,
485 GUINT_TO_POINTER(LOG_ERR));
487 xmlRelaxNGSetParserErrors(ctx->parser,
488 (xmlRelaxNGValidityErrorFunc) fprintf,
489 (xmlRelaxNGValidityWarningFunc) fprintf,
493 ctx->rng = xmlRelaxNGParse(ctx->parser);
495 crm_err(
"Could not find/parse %s", relaxng_file);
498 ctx->valid = xmlRelaxNGNewValidCtxt(ctx->rng);
499 CRM_CHECK(ctx->valid != NULL,
goto cleanup);
502 xmlRelaxNGSetValidErrors(ctx->valid,
503 (xmlRelaxNGValidityErrorFunc) xml_log,
504 (xmlRelaxNGValidityWarningFunc) xml_log,
505 GUINT_TO_POINTER(LOG_ERR));
507 xmlRelaxNGSetValidErrors(ctx->valid,
508 (xmlRelaxNGValidityErrorFunc) fprintf,
509 (xmlRelaxNGValidityWarningFunc) fprintf,
517 xmlLineNumbersDefault(1);
518 rc = xmlRelaxNGValidateDoc(ctx->valid, doc);
523 crm_err(
"Internal libxml error during validation");
532 if (ctx->parser != NULL) {
533 xmlRelaxNGFreeParserCtxt(ctx->parser);
535 if (ctx->valid != NULL) {
536 xmlRelaxNGFreeValidCtxt(ctx->valid);
538 if (ctx->rng != NULL) {
539 xmlRelaxNGFree(ctx->rng);
555 relaxng_ctx_cache_t *ctx = NULL;
557 for (lpc = 0; lpc < xml_schema_max; lpc++) {
559 switch (known_schemas[lpc].validator) {
563 ctx = (relaxng_ctx_cache_t *) known_schemas[lpc].cache;
567 if (ctx->parser != NULL) {
568 xmlRelaxNGFreeParserCtxt(ctx->parser);
570 if (ctx->valid != NULL) {
571 xmlRelaxNGFreeValidCtxt(ctx->valid);
573 if (ctx->rng != NULL) {
574 xmlRelaxNGFree(ctx->rng);
577 known_schemas[lpc].cache = NULL;
580 free(known_schemas[lpc].
name);
581 free(known_schemas[lpc].transform);
582 free(known_schemas[lpc].transform_enter);
585 known_schemas = NULL;
591 validate_with(xmlNode *xml,
int method, gboolean to_logs)
593 xmlDocPtr doc = NULL;
594 gboolean valid = FALSE;
608 known_schemas[method].
name);
610 crm_trace(
"Validating with: %s (type=%d)",
611 crm_str(file), known_schemas[method].validator);
612 switch (known_schemas[method].validator) {
615 validate_with_relaxng(doc, to_logs, file,
616 (relaxng_ctx_cache_t **) & (known_schemas[method].cache));
619 crm_err(
"Unknown validator type: %d",
620 known_schemas[method].validator);
629 validate_with_silent(xmlNode *xml,
int method)
631 bool rc, sl_backup = silent_logging;
632 silent_logging = TRUE;
633 rc = validate_with(xml, method, TRUE);
634 silent_logging = sl_backup;
639 dump_file(
const char *filename)
647 fp = fopen(filename,
"r");
649 crm_perror(LOG_ERR,
"Could not open %s for reading", filename);
653 fprintf(stderr,
"%4d ", ++line);
659 }
else if (ch ==
'\n') {
660 fprintf(stderr,
"\n%4d ", ++line);
676 char *filename = NULL;
680 umask(S_IWGRP | S_IWOTH | S_IROTH);
681 fd = mkstemp(filename);
686 doc = xmlParseFile(filename);
687 xml = xmlDocGetRootElement(doc);
698 validate_xml(xmlNode *xml_blob,
const char *validation, gboolean to_logs)
702 if (validation == NULL) {
706 if (validation == NULL) {
710 for (lpc = 0; lpc < xml_schema_max; lpc++) {
711 if (validate_with(xml_blob, lpc, FALSE)) {
714 known_schemas[lpc].
name);
715 crm_info(
"XML validated against %s", known_schemas[lpc].
name);
716 if(known_schemas[lpc].after_transform == 0) {
728 }
else if (
version < xml_schema_max) {
729 return validate_with(xml_blob,
version, to_logs);
732 crm_err(
"Unknown validator: %s", validation);
737 cib_upgrade_err(
void *ctx,
const char *fmt, ...)
764 cib_upgrade_err(
void *ctx, const
char *fmt, ...)
770 const char *fmt_iter = fmt;
771 uint8_t msg_log_level = LOG_WARNING;
772 const unsigned * log_level = (
const unsigned *) ctx;
776 } scan_state = escan_seennothing;
781 while (!found && *fmt_iter !=
'\0') {
783 switch (*fmt_iter++) {
785 if (scan_state == escan_seennothing) {
786 scan_state = escan_seenpercent;
787 }
else if (scan_state == escan_seenpercent) {
788 scan_state = escan_seennothing;
792 if (scan_state == escan_seenpercent) {
793 scan_state = escan_seennothing;
794 arg_cur = va_arg(aq,
char *);
795 if (arg_cur != NULL) {
796 switch (arg_cur[0]) {
798 if (!strncmp(arg_cur,
"WARNING: ",
799 sizeof(
"WARNING: ") - 1)) {
800 msg_log_level = LOG_WARNING;
803 memmove(arg_cur, arg_cur +
sizeof(
"WARNING: ") - 1,
804 strlen(arg_cur +
sizeof(
"WARNING: ") - 1) + 1);
809 if (!strncmp(arg_cur,
"INFO: ",
810 sizeof(
"INFO: ") - 1)) {
811 msg_log_level = LOG_INFO;
814 memmove(arg_cur, arg_cur +
sizeof(
"INFO: ") - 1,
815 strlen(arg_cur +
sizeof(
"INFO: ") - 1) + 1);
820 if (!strncmp(arg_cur,
"DEBUG: ",
821 sizeof(
"DEBUG: ") - 1)) {
822 msg_log_level = LOG_DEBUG;
825 memmove(arg_cur, arg_cur +
sizeof(
"DEBUG: ") - 1,
826 strlen(arg_cur +
sizeof(
"DEBUG: ") - 1) + 1);
834 case '#':
case '-':
case ' ':
case '+':
case '\'':
case 'I':
case '.':
835 case '0':
case '1':
case '2':
case '3':
case '4':
836 case '5':
case '6':
case '7':
case '8':
case '9':
853 if (scan_state == escan_seenpercent) {
854 (void) va_arg(aq,
void *);
855 scan_state = escan_seennothing;
859 scan_state = escan_seennothing;
864 if (log_level != NULL) {
867 if (*log_level + 4 >= msg_log_level) {
868 vfprintf(stderr, fmt, ap);
893 #ifndef PCMK_SCHEMAS_EMERGENCY_XSLT 894 #define PCMK_SCHEMAS_EMERGENCY_XSLT 1 898 apply_transformation(xmlNode *xml,
const char *transform, gboolean to_logs)
902 xmlDocPtr res = NULL;
903 xmlDocPtr doc = NULL;
904 xsltStylesheet *xslt = NULL;
905 #if PCMK_SCHEMAS_EMERGENCY_XSLT != 0 906 xmlChar *emergency_result;
907 int emergency_txt_len;
916 xmlLoadExtDtdDefaultValue = 1;
917 xmlSubstituteEntitiesDefault(1);
921 xsltSetGenericErrorFunc(NULL, cib_upgrade_err);
926 xslt = xsltParseStylesheetFile((
pcmkXmlStr) xform);
929 res = xsltApplyStylesheet(xslt, doc, NULL);
932 xsltSetGenericErrorFunc(NULL, NULL);
935 #if PCMK_SCHEMAS_EMERGENCY_XSLT != 0 936 emergency_res = xsltSaveResultToString(&emergency_result,
937 &emergency_txt_len, res, xslt);
939 CRM_CHECK(emergency_res == 0,
goto cleanup);
940 out =
string2xml((
const char *) emergency_result);
941 free(emergency_result);
943 out = xmlDocGetRootElement(res);
948 xsltFreeStylesheet(xslt);
963 apply_upgrade(xmlNode *xml,
const struct schema_s *schema, gboolean to_logs)
965 bool transform_onleave = schema->transform_onleave;
966 char *transform_leave;
967 xmlNode *upgrade = NULL,
970 if (schema->transform_enter) {
971 crm_debug(
"Upgrading %s-style configuration, pre-upgrade phase with %s.xsl",
972 schema->name, schema->transform_enter);
973 upgrade = apply_transformation(xml, schema->transform_enter, to_logs);
974 if (upgrade == NULL) {
975 crm_warn(
"Upgrade-enter transformation %s.xsl failed",
976 schema->transform_enter);
977 transform_onleave = FALSE;
980 if (upgrade == NULL) {
984 crm_debug(
"Upgrading %s-style configuration, main phase with %s.xsl",
985 schema->name, schema->transform);
986 final = apply_transformation(upgrade, schema->transform, to_logs);
987 if (upgrade != xml) {
992 if (
final != NULL && transform_onleave) {
996 transform_leave = strdup(schema->transform_enter);
998 memcpy(strrchr(transform_leave,
'-') + 1,
"leave",
sizeof(
"leave") - 1);
999 crm_debug(
"Upgrading %s-style configuration, post-upgrade phase with %s.xsl",
1000 schema->name, transform_leave);
1001 final = apply_transformation(upgrade, transform_leave, to_logs);
1002 if (
final == NULL) {
1003 crm_warn(
"Upgrade-leave transformation %s.xsl failed", transform_leave);
1008 free(transform_leave);
1017 if (version < 0 || version >= xml_schema_max) {
1020 return known_schemas[
version].name;
1031 for (; lpc < xml_schema_max; lpc++) {
1044 xmlNode *xml = NULL;
1046 int max_stable_schemas = xml_latest_schema_index();
1047 int lpc = 0, match = -1, rc =
pcmk_ok;
1050 CRM_CHECK(best != NULL,
return -EINVAL);
1053 CRM_CHECK(xml_blob != NULL,
return -EINVAL);
1054 CRM_CHECK(*xml_blob != NULL,
return -EINVAL);
1059 if (value != NULL) {
1063 if (lpc >= 0 && transform == FALSE) {
1066 }
else if (lpc < 0) {
1072 if (match >= max_stable_schemas) {
1079 while (lpc <= max_stable_schemas) {
1080 crm_debug(
"Testing '%s' validation (%d of %d)",
1081 known_schemas[lpc].
name ? known_schemas[lpc].
name :
"<unset>",
1082 lpc, max_stable_schemas);
1084 if (validate_with(xml, lpc, to_logs) == FALSE) {
1086 crm_info(
"Configuration not valid for schema: %s",
1087 known_schemas[lpc].
name);
1091 known_schemas[lpc].
name ? known_schemas[lpc].
name :
"<unset>");
1101 crm_debug(
"Configuration valid for schema: %s",
1102 known_schemas[next].
name);
1112 if (rc ==
pcmk_ok && transform) {
1113 xmlNode *upgrade = NULL;
1114 next = known_schemas[lpc].after_transform;
1121 }
else if (max > 0 && (lpc == max || next > max)) {
1122 crm_trace(
"Upgrade limit reached at %s (lpc=%d, next=%d, max=%d)",
1123 known_schemas[lpc].
name, lpc, next, max);
1126 }
else if (known_schemas[lpc].transform == NULL
1132 || validate_with_silent(xml, next)) {
1133 crm_debug(
"%s-style configuration is also valid for %s",
1134 known_schemas[lpc].
name, known_schemas[next].
name);
1139 crm_debug(
"Upgrading %s-style configuration to %s with %s.xsl",
1140 known_schemas[lpc].
name, known_schemas[next].
name,
1141 known_schemas[lpc].transform);
1143 upgrade = apply_upgrade(xml, &known_schemas[lpc], to_logs);
1144 if (upgrade == NULL) {
1145 crm_err(
"Transformation %s.xsl failed",
1146 known_schemas[lpc].transform);
1149 }
else if (validate_with(upgrade, next, to_logs)) {
1150 crm_info(
"Transformation %s.xsl successful",
1151 known_schemas[lpc].transform);
1159 crm_err(
"Transformation %s.xsl did not produce a valid configuration",
1160 known_schemas[lpc].transform);
1169 if (transform == FALSE || rc !=
pcmk_ok) {
1175 if (*best > match && *best) {
1176 crm_info(
"%s the configuration from %s to %s",
1177 transform?
"Transformed":
"Upgraded",
1178 value ? value :
"<none>", known_schemas[*best].
name);
1192 char *
const orig_value = strdup(value == NULL ?
"(none)" : value);
1196 int min_version = xml_minimum_schema_index();
1200 xmlNode *converted = NULL;
1209 if (
version < orig_version || orig_version == -1) {
1213 "schema %s) to at least %s because it " 1214 "does not validate with any schema from " 1221 fprintf(stderr,
"Cannot upgrade configuration (claiming " 1222 "schema %s) to at least %s because it " 1223 "does not validate with any schema from " 1234 "schema %s) to at least %s because it " 1235 "would not upgrade past %s",
1240 fprintf(stderr,
"Cannot upgrade configuration (claiming " 1241 "schema %s) to at least %s because it " 1242 "would not upgrade past %s\n",
1258 if (
version < xml_latest_schema_index()) {
1261 "internally upgraded to acceptable (but " 1262 "not most recent) %s",
1267 crm_info(
"Configuration with schema %s was internally " 1268 "upgraded to latest version %s",
1278 "(enabling is encouraged and prevents common " 1279 "misconfigurations)");
1282 fprintf(stderr,
"Schema validation of configuration is disabled " 1283 "(enabling is encouraged and prevents common " 1284 "misconfigurations)\n");
char * pcmk__xml_artefact_root(enum pcmk__xml_artefact_ns ns)
#define CRM_CHECK(expr, failure_action)
#define pcmk_err_schema_validation
void crm_schema_init(void)
#define crm_notice(fmt, args...)
#define schema_strdup_printf(prefix, version, suffix)
#define pcmk__config_warn(fmt...)
#define schema_scanf(s, prefix, version, suffix)
#define pcmk__config_err(fmt...)
#define pcmk_err_transform_failed
const char * crm_xml_add(xmlNode *node, const char *name, const char *value)
Create an XML attribute with specified name and value.
char * strerror(int errnum)
xmlNode * string2xml(const char *input)
xmlDoc * getDocPtr(xmlNode *node)
xmlNode * copy_xml(xmlNode *src_node)
#define crm_warn(fmt, args...)
int get_schema_version(const char *name)
#define crm_debug(fmt, args...)
char * crm_element_value_copy(const xmlNode *data, const char *name)
Retrieve a copy of the value of an XML attribute.
const char * crm_element_value(const xmlNode *data, const char *name)
Retrieve the value of an XML attribute.
#define PCMK__XML_LOG_BASE(priority, dechunk, postemit, prefix, fmt, ap)
Base for directing lib{xml2,xslt} log into standard libqb backend.
void crm_schema_cleanup(void)
#define crm_trace(fmt, args...)
char * crm_strdup_printf(char const *format,...) G_GNUC_PRINTF(1
const char * get_schema_name(int version)
Wrappers for and extensions to libxml2.
#define XML_ATTR_VALIDATION
void free_xml(xmlNode *child)
gboolean validate_xml_verbose(xmlNode *xml_blob)
const xmlChar * pcmkXmlStr
gboolean validate_xml(xmlNode *xml_blob, const char *validation, gboolean to_logs)
unsigned int crm_log_level
#define crm_perror(level, fmt, args...)
Send a system error message to both the log and stderr.
#define crm_err(fmt, args...)
const char * pcmk__get_tmpdir(void)
#define crm_log_xml_info(xml, text)
gboolean cli_config_update(xmlNode **xml, int *best_version, gboolean to_logs)
int update_validation(xmlNode **xml_blob, int *best, int max, gboolean transform, gboolean to_logs)
Update CIB XML to most recent schema version.
int write_xml_fd(xmlNode *xml_node, const char *filename, int fd, gboolean compress)
Write XML to a file descriptor.
char * pcmk__xml_artefact_path(enum pcmk__xml_artefact_ns ns, const char *filespec)
#define crm_info(fmt, args...)
bool pcmk__ends_with_ext(const char *s, const char *match)
const char * xml_latest_schema(void)