9b8dbb47b950ce4f91fc52ebb5774d0f434330dd
[racktables] / upgrade.php
1 <?php
2
3 $relnotes = array
4 (
5 '0.17.0' => "This release requires changes to the configuration file. " .
6 "Move inc/secret.php to local/secret.php and add the following to the file:<br><br>" .
7 "\$user_auth_src = 'database';<br>\$require_local_account = TRUE;<br><br>" .
8 "(and adjust to your needs, if necessary)<br>" .
9 "Another change is the addition of support for file uploads. Files are stored<br>" .
10 "in the database. There are several settings in php.ini which you may need to modify:<br>" .
11 "<ul><li>file_uploads - needs to be On</li>" .
12 "<li>upload_max_filesize - max size for uploaded files</li>" .
13 "<li>post_max_size - max size of all form data submitted via POST (including files)</li></ul><br>" .
14 "Local user accounts used to have 'enabled' flag, which allowed individual blocking and<br>" .
15 "unblocking of each. This flag was dropped in favor of existing mean of access<br>" .
16 "setup (RackCode). An unconditional denying rule is automatically added into RackCode<br>" .
17 "for such blocked account, so the effective security policy remains the same.<br>",
18 );
19
20 // At the moment we assume, that for any two releases we can
21 // sequentally execute all batches, that separate them, and
22 // nothing will break. If this changes one day, the function
23 // below will have to generate smarter upgrade paths, while
24 // the upper layer will remain the same.
25 // Returning an empty array means that no upgrade is necessary.
26 // Returning NULL indicates an error.
27 function getDBUpgradePath ($v1, $v2)
28 {
29 $versionhistory = array
30 (
31 '0.16.4',
32 '0.16.5',
33 '0.16.6',
34 '0.17.0',
35 );
36 if (!in_array ($v1, $versionhistory) or !in_array ($v2, $versionhistory))
37 return NULL;
38 $skip = TRUE;
39 $path = NULL;
40 // Now collect all versions > $v1 and <= $v2
41 foreach ($versionhistory as $v)
42 {
43 if ($skip and $v == $v1)
44 {
45 $skip = FALSE;
46 $path = array();
47 continue;
48 }
49 if ($skip)
50 continue;
51 $path[] = $v;
52 if ($v == $v2)
53 break;
54 }
55 return $path;
56 }
57
58 // Upgrade batches are named exactly as the release where they first appear.
59 // That is simple, but seems sufficient for beginning.
60 function executeUpgradeBatch ($batchid)
61 {
62 $query = array();
63 global $dbxlink;
64 switch ($batchid)
65 {
66 case '0.16.5':
67 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('IPV4_TREE_SHOW_USAGE','yes','string','no','no','Show address usage in IPv4 tree')";
68 $query[] = "update Config set varvalue = '0.16.5' where varname = 'DB_VERSION'";
69 break;
70 case '0.16.6':
71 $query[] = "update Config set varvalue = '0.16.6' where varname = 'DB_VERSION'";
72 break;
73 case '0.17.0':
74 // create tables for storing files (requires InnoDB support)
75 if (!isInnoDBSupported ())
76 {
77 showError ("Cannot upgrade because InnoDB tables are not supported by your MySQL server. See the README for details.", __FILE__);
78 die;
79 }
80
81 $query[] = "alter table Chapter change chapter_no id int(10) unsigned NOT NULL auto_increment";
82 $query[] = "alter table Chapter change chapter_name name char(128) NOT NULL";
83 $query[] = "alter table Chapter drop key chapter_name";
84 $query[] = "alter table Chapter add UNIQUE KEY name (name)";
85 $query[] = "alter table Attribute change attr_id id int(10) unsigned NOT NULL auto_increment";
86 $query[] = "alter table Attribute change attr_type type enum('string','uint','float','dict') default NULL";
87 $query[] = "alter table Attribute change attr_name name char(64) default NULL";
88 $query[] = "alter table Attribute drop key attr_name";
89 $query[] = "alter table Attribute add UNIQUE KEY name (name)";
90 $query[] = "alter table AttributeMap change chapter_no chapter_id int(10) unsigned NOT NULL";
91 $query[] = "alter table Dictionary change chapter_no chapter_id int(10) unsigned NOT NULL";
92 // Many dictionary changes were made... remove all dictvendor entries and install fresh.
93 // Take care not to erase locally added records. 0.16.x ends with max key 797
94 $query[] = 'DELETE FROM Dictionary WHERE ((chapter_id BETWEEN 11 AND 14) or (chapter_id BETWEEN 16 AND 19) ' .
95 'or (chapter_id BETWEEN 21 AND 24)) and dict_key <= 797';
96 $f = fopen ("install/init-dictvendors.sql", 'r');
97 if ($f === FALSE)
98 {
99 showError ("Failed to open install/init-dictvendors.sql for reading");
100 die;
101 }
102 $longq = '';
103 while (!feof ($f))
104 {
105 $line = fgets ($f);
106 if (ereg ('^--', $line))
107 continue;
108 $longq .= $line;
109 }
110 fclose ($f);
111 foreach (explode (";\n", $longq) as $dict_query)
112 {
113 if (empty ($dict_query))
114 continue;
115 $query[] = $dict_query;
116 }
117
118 // schema changes for file management
119 $query[] = "
120 CREATE TABLE `File` (
121 `id` int(10) unsigned NOT NULL auto_increment,
122 `name` char(255) NOT NULL,
123 `type` char(255) NOT NULL,
124 `size` int(10) unsigned NOT NULL,
125 `ctime` datetime NOT NULL,
126 `mtime` datetime NOT NULL,
127 `atime` datetime NOT NULL,
128 `contents` longblob NOT NULL,
129 `comment` text,
130 PRIMARY KEY (`id`),
131 UNIQUE KEY `name` (`name`)
132 ) ENGINE=InnoDB";
133 $query[] = "
134 CREATE TABLE `FileLink` (
135 `id` int(10) unsigned NOT NULL auto_increment,
136 `file_id` int(10) unsigned NOT NULL,
137 `entity_type` enum('ipv4net','ipv4rspool','ipv4vs','object','rack','user') NOT NULL default 'object',
138 `entity_id` int(10) NOT NULL,
139 PRIMARY KEY (`id`),
140 UNIQUE KEY `FileLink-unique` (`file_id`,`entity_type`,`entity_id`),
141 KEY `FileLink-file_id` (`file_id`),
142 CONSTRAINT `FileLink-File_fkey` FOREIGN KEY (`file_id`) REFERENCES `File` (`id`) ON DELETE CASCADE ON UPDATE CASCADE
143 ) ENGINE=InnoDB";
144 $query[] = "ALTER TABLE TagStorage MODIFY COLUMN target_realm enum('file','ipv4net','ipv4rspool','ipv4vs','object','rack','user') NOT NULL default 'object'";
145
146 $query[] = "INSERT INTO `Dictionary` (`chapter_id`, `dict_key`, `dict_value`) VALUES (1,798,'Network security')";
147 $query[] = "INSERT INTO `Dictionary` (`chapter_id`, `dict_key`, `dict_value`) VALUES (1,965,'Wireless')";
148 $query[] = "INSERT INTO `Chapter` (`id`, `sticky`, `name`) VALUES (24,'no','network security models')";
149 $query[] = "INSERT INTO `Chapter` (`id`, `sticky`, `name`) VALUES (25,'no','wireless models')";
150 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,1,0)";
151 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,2,24)";
152 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,3,0)";
153 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,5,0)";
154 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,14,0)";
155 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,16,0)";
156 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,17,0)";
157 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,18,0)";
158 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,20,0)";
159 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,21,0)";
160 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,22,0)";
161 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (798,24,0)";
162 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (965,1,0)";
163 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (965,3,0)";
164 $query[] = "INSERT INTO `AttributeMap` (`objtype_id`, `attr_id`, `chapter_id`) VALUES (965,2,25)";
165 $query[] = "UPDATE Dictionary SET dict_value = 'Network switch' WHERE dict_key = 8";
166 $query[] = 'alter table IPBonds rename to IPv4Allocation';
167 $query[] = 'alter table PortForwarding rename to IPv4NAT';
168 $query[] = 'alter table IPRanges rename to IPv4Network';
169 $query[] = 'alter table IPAddress rename to IPv4Address';
170 $query[] = 'alter table IPLoadBalancer rename to IPv4LB';
171 $query[] = 'alter table IPRSPool rename to IPv4RSPool';
172 $query[] = 'alter table IPRealServer rename to IPv4RS';
173 $query[] = 'alter table IPVirtualService rename to IPv4VS';
174 $query[] = "alter table TagStorage change column target_realm entity_realm enum('file','ipv4net','ipv4vs','ipv4rspool','object','rack','user') NOT NULL default 'object'";
175 $query[] = 'alter table TagStorage change column target_id entity_id int(10) unsigned NOT NULL';
176 $query[] = 'alter table TagStorage drop key entity_tag';
177 $query[] = 'alter table TagStorage drop key target_id';
178 $query[] = 'alter table TagStorage add UNIQUE KEY `entity_tag` (`entity_realm`,`entity_id`,`tag_id`)';
179 $query[] = 'alter table TagStorage add KEY `entity_id` (`entity_id`)';
180 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('PREVIEW_TEXT_MAXCHARS','10240','uint','yes','no','Max chars for text file preview')";
181 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('PREVIEW_TEXT_ROWS','25','uint','yes','no','Rows for text file preview')";
182 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('PREVIEW_TEXT_COLS','80','uint','yes','no','Columns for text file preview')";
183 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('PREVIEW_IMAGE_MAXPXS','320','uint','yes','no','Max pixels per axis for image file preview')";
184 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('VENDOR_SIEVE','','string','yes','no','Vendor sieve configuration')";
185 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('IPV4LB_LISTSRC','{\$typeid_4}','string','yes','no','List source: IPv4 load balancers')";
186 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('IPV4OBJ_LISTSRC','{\$typeid_4} or {\$typeid_7} or {\$typeid_8} or {\$typeid_12} or {\$typeid_445} or {\$typeid_447}','string','yes','no','List source: IPv4-enabled objects')";
187 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('IPV4NAT_LISTSRC','{\$typeid_4} or {\$typeid_7} or {\$typeid_8}','string','yes','no','List source: IPv4 NAT performers')";
188 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('ASSETWARN_LISTSRC','{\$typeid_4} or {\$typeid_7} or {\$typeid_8}','string','yes','no','List source: object, for which asset tag should be set')";
189 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('NAMEWARN_LISTSRC','{\$typeid_4} or {\$typeid_7} or {\$typeid_8}','string','yes','no','List source: object, for which common name should be set')";
190 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('RACKS_PER_ROW','12','unit','yes','no','Racks per row')";
191 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('FILTER_PREDICATE_SIEVE','','string','yes','no','Predicate sieve regex(7)')";
192 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('FILTER_DEFAULT_ANDOR','or','string','no','no','Default list filter boolean operation (or/and)')";
193 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('FILTER_SUGGEST_ANDOR','yes','string','no','no','Suggest and/or selector in list filter')";
194 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('FILTER_SUGGEST_TAGS','yes','string','no','no','Suggest tags in list filter')";
195 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('FILTER_SUGGEST_PREDICATES','yes','string','no','no','Suggest predicates in list filter')";
196 $query[] = "INSERT INTO `Config` (varname, varvalue, vartype, emptyok, is_hidden, description) VALUES ('FILTER_SUGGEST_EXTRA','no','string','no','no','Suggest extra expression in list filter')";
197 $query[] = "delete from Config where varname = 'USER_AUTH_SRC'";
198 $query[] = "delete from Config where varname = 'COOKIE_TTL'";
199 $query[] = "delete from Config where varname = 'rtwidth_0'";
200 $query[] = "delete from Config where varname = 'rtwidth_1'";
201 $query[] = "delete from Config where varname = 'rtwidth_2'";
202 $query[] = "delete from Config where varname = 'NAMEFUL_OBJTYPES'";
203 $query[] = "delete from Config where varname = 'REQUIRE_ASSET_TAG_FOR'";
204 $query[] = "delete from Config where varname = 'IPV4_PERFORMERS'";
205 $query[] = "delete from Config where varname = 'NATV4_PERFORMERS'";
206 $query[] = "alter table TagTree add column valid_realm set('file','ipv4net','ipv4vs','ipv4rspool','object','rack','user') not null default 'file,ipv4net,ipv4vs,ipv4rspool,object,rack,user' after parent_id";
207 $result = $dbxlink->query ("select user_id, user_name, user_realname from UserAccount where user_enabled = 'no'");
208 while ($row = $result->fetch (PDO::FETCH_ASSOC))
209 $query[] = "update Script set script_text = concat('deny {\$userid_${row['user_id']}} # ${row['user_name']} (${row['user_realname']})\n', script_text) where script_name = 'RackCode'";
210 $query[] = "update Script set script_text = NULL where script_name = 'RackCodeCache'";
211 unset ($result);
212 $query[] = "alter table UserAccount drop column user_enabled";
213
214 $query[] = "CREATE TABLE RackRow ( id int(10) unsigned NOT NULL auto_increment, name char(255) NOT NULL, PRIMARY KEY (`id`) ) ENGINE=MyISAM";
215
216 $result = $dbxlink->query ("select dict_key, dict_value from Dictionary where chapter_no = 3");
217 while($row = $result->fetch(PDO::FETCH_NUM))
218 {
219 $query[] = "insert into RackRow set id=${row[0]}, name='${row[1]}'";
220 }
221 $query[] = "delete from Dictionary where chapter_id = 3";
222 $query[] = "delete from Chapter where id = 3";
223 $query[] = "
224 CREATE TABLE `LDAPCache` (
225 `presented_username` char(64) NOT NULL,
226 `successful_hash` char(40) NOT NULL,
227 `first_success` timestamp NOT NULL default CURRENT_TIMESTAMP,
228 `last_retry` timestamp NOT NULL default '0000-00-00 00:00:00',
229 `displayed_name` char(128) default NULL,
230 `memberof` text,
231 UNIQUE KEY `presented_username` (`presented_username`),
232 KEY `scanidx` (`presented_username`,`successful_hash`)
233 ) ENGINE=InnoDB;";
234 $query[] = "alter table UserAccount modify column user_password_hash char(40) NULL";
235 $query[] = 'ALTER TABLE Rack DROP COLUMN deleted';
236 $query[] = 'ALTER TABLE RackHistory DROP COLUMN deleted';
237 $query[] = 'ALTER TABLE RackObject DROP COLUMN deleted';
238 $query[] = 'ALTER TABLE RackObjectHistory DROP COLUMN deleted';
239 $query[] = "UPDATE Config SET varvalue = '0.17.0' WHERE varname = 'DB_VERSION'";
240
241 break;
242 default:
243 showError ("executeUpgradeBatch () failed, because batch '${batchid}' isn't defined", __FILE__);
244 die;
245 break;
246 }
247 $failures = array();
248 echo "<tr><th>Executing batch '${batchid}'</th><td>";
249 foreach ($query as $q)
250 {
251 $result = $dbxlink->query ($q);
252 if ($result == NULL)
253 {
254 $errorInfo = $dbxlink->errorInfo();
255 $failures[] = array ($q, $errorInfo[2]);
256 }
257 }
258 if (!count ($failures))
259 echo "<strong><font color=green>done</font></strong>";
260 else
261 {
262 echo "<strong><font color=red>The following queries failed:</font></strong><br><pre>";
263 foreach ($failures as $f)
264 {
265 list ($q, $i) = $f;
266 echo "${q} -- ${i}\n";
267 }
268 echo "</pre>";
269 }
270 echo '</td></tr>';
271 }
272
273 // ******************************************************************
274 //
275 // Execution starts here
276 //
277 // ******************************************************************
278
279 $root = (empty($_SERVER['HTTPS']) or $_SERVER['HTTPS'] == 'off') ? 'http://' : 'https://';
280 $root .= isset ($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : ($_SERVER['SERVER_NAME'].($_SERVER['SERVER_PORT']=='80'?'':$_SERVER['SERVER_PORT']));
281 $root .= strtr (dirname ($_SERVER['PHP_SELF']), '\\', '/');
282 if (substr ($root, -1) != '/')
283 $root .= '/';
284
285 // The below will be necessary as long as we rely on showError()
286 require_once 'inc/interface.php';
287
288 require_once 'inc/config.php';
289 require_once 'inc/database.php';
290 if (file_exists ('local/secret.php'))
291 require_once 'local/secret.php';
292 elseif (file_exists ('inc/secret.php')) // 0.16.x -> 0.17.x upgrade
293 {
294 require_once 'inc/secret.php';
295 $user_auth_src = getConfigVar ('USER_AUTH_SRC');
296 }
297 else
298 die ("Database connection parameters are read from local/secret.php file, " .
299 "which cannot be found.\nCopy provided config/secret-sample.php to " .
300 "local/secret.php and modify to your setup.\n\nThen reload the page.");
301
302 try
303 {
304 $dbxlink = new PDO ($pdo_dsn, $db_username, $db_password);
305 }
306 catch (PDOException $e)
307 {
308 die ("Database connection failed:\n\n" . $e->getMessage());
309 }
310
311 // Now we need to be sure that the current user is the administrator.
312 // The rest doesn't matter within this context.
313
314 function authenticate_admin ($username, $password)
315 {
316 global $dbxlink;
317 $hash = sha1 ($password);
318 $query = "select count(*) from UserAccount where user_id = 1 and user_name = '${username}' and user_password_hash = '${hash}'";
319 if (($result = $dbxlink->query ($query)) == NULL)
320 die ('SQL query failed in ' . __FUNCTION__);
321 $rows = $result->fetchAll (PDO::FETCH_NUM);
322 return $rows[0][0] == 1;
323 }
324
325 switch ($user_auth_src)
326 {
327 case 'database':
328 case 'ldap': // authenticate against DB as well
329 if
330 (
331 !isset ($_SERVER['PHP_AUTH_USER']) or
332 !strlen ($_SERVER['PHP_AUTH_USER']) or
333 !isset ($_SERVER['PHP_AUTH_PW']) or
334 !strlen ($_SERVER['PHP_AUTH_PW']) or
335 !authenticate_admin (escapeString ($_SERVER['PHP_AUTH_USER']), escapeString ($_SERVER['PHP_AUTH_PW']))
336 )
337 {
338 header ('WWW-Authenticate: Basic realm="RackTables upgrade"');
339 header ('HTTP/1.0 401 Unauthorized');
340 showError ('You must be authenticated as an administrator to complete the upgrade.', __FILE__);
341 die;
342 }
343 break; // cleared
344 case 'httpd':
345 if
346 (
347 !isset ($_SERVER['REMOTE_USER']) or
348 !strlen ($_SERVER['REMOTE_USER'])
349 )
350 {
351 showError ('System misconfiguration. The web-server didn\'t authenticate the user, although ought to do.');
352 die;
353 }
354 break; // cleared
355 default:
356 showError ('authentication source misconfiguration', __FILE__);
357 die;
358 }
359
360 $dbver = getDatabaseVersion();
361 echo '<table border=1>';
362 echo "<tr><th>Current status</th><td>Data version: ${dbver}<br>Code version: " . CODE_VERSION . "</td></tr>\n";
363
364 $path = getDBUpgradePath ($dbver, CODE_VERSION);
365 if ($path === NULL)
366 {
367 echo "<tr><th>Upgrade path</th><td><font color=red>not found</font></td></tr>\n";
368 echo "<tr><th>Summary</th><td>Check README for more information.</td></tr>\n";
369 }
370 else
371 {
372 if (!count ($path))
373 echo "<tr><th>Summary</th><td>Come back later.</td></tr>\n";
374 else
375 {
376 echo "<tr><th>Upgrade path</th><td>${dbver} &rarr; " . implode (' &rarr; ', $path) . "</td></tr>\n";
377 foreach ($path as $batchid)
378 {
379 executeUpgradeBatch ($batchid);
380 if (isset ($relnotes[$batchid]))
381 echo "<tr><th>Release notes for ${batchid}</th><td>" . $relnotes[$batchid] . "</td></tr>\n";
382 }
383 echo "<tr><th>Summary</th><td>Upgrade complete, it is Ok to <a href='${root}'>enter</a> the system.</td></tr>\n";
384 }
385 }
386 echo '</table>';
387
388 ?>