/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release
21 by Teddy Hogeborn
* Makefile (CFLAGS): Changed to use $(WARN), $(DEBUG), $(COVERAGE) and
1
/*  -*- coding: utf-8 -*- */
2
/*
3
 * Mandos plugin runner - Run Mandos plugins
4
 *
28 by Teddy Hogeborn
* server.conf: New file.
5
 * Copyright © 2007-2008 Teddy Hogeborn & Björn Påhlsson
21 by Teddy Hogeborn
* Makefile (CFLAGS): Changed to use $(WARN), $(DEBUG), $(COVERAGE) and
6
 * 
7
 * This program is free software: you can redistribute it and/or
8
 * modify it under the terms of the GNU General Public License as
9
 * published by the Free Software Foundation, either version 3 of the
10
 * License, or (at your option) any later version.
11
 * 
12
 * This program is distributed in the hope that it will be useful, but
13
 * WITHOUT ANY WARRANTY; without even the implied warranty of
14
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
15
 * General Public License for more details.
16
 * 
17
 * You should have received a copy of the GNU General Public License
18
 * along with this program.  If not, see
19
 * <http://www.gnu.org/licenses/>.
20
 * 
28 by Teddy Hogeborn
* server.conf: New file.
21
 * Contact the authors at <mandos@fukt.bsnet.se>.
21 by Teddy Hogeborn
* Makefile (CFLAGS): Changed to use $(WARN), $(DEBUG), $(COVERAGE) and
22
 */
23
13 by Björn Påhlsson
Added following support:
24
#include <stdio.h>	/* popen, fileno */
25
#include <iso646.h>	/* and, or, not */
26
#include <sys/types.h>	/* DIR, opendir, stat, struct stat, waitpid,
27
			   WIFEXITED, WEXITSTATUS, wait */
28
#include <sys/wait.h>	/* wait */
29
#include <dirent.h>	/* DIR, opendir */
30
#include <sys/stat.h>	/* stat, struct stat */
31
#include <unistd.h>	/* stat, struct stat, chdir */
32
#include <stdlib.h>	/* EXIT_FAILURE */
21 by Teddy Hogeborn
* Makefile (CFLAGS): Changed to use $(WARN), $(DEBUG), $(COVERAGE) and
33
#include <sys/select.h>	/* fd_set, select, FD_ZERO, FD_SET,
34
			   FD_ISSET */
13 by Björn Påhlsson
Added following support:
35
#include <string.h>	/* strlen, strcpy, strcat */
36
#include <stdbool.h>	/* true */
37
#include <sys/wait.h>	/* waitpid, WIFEXITED, WEXITSTATUS */
38
#include <errno.h>	/* errno */
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
39
#include <argp.h>	/* argp */
13 by Björn Påhlsson
Added following support:
40
41
struct process;
42
43
typedef struct process{
44
  pid_t pid;
45
  int fd;
46
  char *buffer;
21 by Teddy Hogeborn
* Makefile (CFLAGS): Changed to use $(WARN), $(DEBUG), $(COVERAGE) and
47
  size_t buffer_size;
48
  size_t buffer_length;
13 by Björn Påhlsson
Added following support:
49
  struct process *next;
50
} process;
51
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
52
typedef struct plugin{
53
  char *name; 		/* can be "global" and any plugin name */
54
  char **argv;
55
  int argc;
24.1.5 by Björn Påhlsson
plugbasedclient:
56
  bool disable;
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
57
  struct plugin *next;
58
} plugin;
59
60
plugin *getplugin(char *name, plugin **plugin_list){
61
  for (plugin *p = *plugin_list; p != NULL; p = p->next){
62
    if ((p->name == name)
63
	or (p->name and name and (strcmp(p->name, name) == 0))){
64
      return p;
65
    }
66
  }
67
  /* Create a new plugin */
68
  plugin *new_plugin = malloc(sizeof(plugin));
69
  if (new_plugin == NULL){
70
    perror("malloc");
71
    exit(EXIT_FAILURE);
72
  }
73
  new_plugin->name = name;
74
  new_plugin->argv = malloc(sizeof(char *) * 2);
75
  if (new_plugin->argv == NULL){
76
    perror("malloc");
77
    exit(EXIT_FAILURE);
78
  }
79
  new_plugin->argv[0] = name;
80
  new_plugin->argv[1] = NULL;
81
  new_plugin->argc = 1;
24.1.5 by Björn Påhlsson
plugbasedclient:
82
  new_plugin->disable = false;
83
  new_plugin->next = *plugin_list;
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
84
  /* Append the new plugin to the list */
85
  *plugin_list = new_plugin;
86
  return new_plugin;
87
}
88
89
void addarguments(plugin *p, char *arg){
90
  p->argv[p->argc] = arg;
91
  p->argv = realloc(p->argv, sizeof(char *) * (size_t)(p->argc + 2));
92
  if (p->argv == NULL){
93
    perror("malloc");
94
    exit(EXIT_FAILURE);
95
  }
96
  p->argc++;
97
  p->argv[p->argc] = NULL;
98
}
99
	
13 by Björn Påhlsson
Added following support:
100
#define BUFFER_SIZE 256
101
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
102
const char *argp_program_version =
103
  "plugbasedclient 0.9";
104
const char *argp_program_bug_address =
105
  "<mandos@fukt.bsnet.se>";
106
static char doc[] =
107
  "Mandos plugin runner -- Run Mandos plugins";
108
/* A description of the arguments we accept. */
109
static char args_doc[] = "";
110
13 by Björn Påhlsson
Added following support:
111
int main(int argc, char *argv[]){
24.1.5 by Björn Påhlsson
plugbasedclient:
112
  const char *plugindir = "plugins.d";
113
  size_t d_name_len;
13 by Björn Påhlsson
Added following support:
114
  DIR *dir;
115
  struct dirent *dirst;
116
  struct stat st;
117
  fd_set rfds_orig;
118
  int ret, maxfd = 0;
119
  process *process_list = NULL;
24.1.5 by Björn Påhlsson
plugbasedclient:
120
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
121
  /* The options we understand. */
122
  struct argp_option options[] = {
123
    { .name = "global-options", .key = 'g',
124
      .arg = "option[,option[,...]]", .flags = 0,
125
      .doc = "Options effecting all plugins" },
126
    { .name = "options-for", .key = 'o',
127
      .arg = "plugin:option[,option[,...]]", .flags = 0,
128
      .doc = "Options effecting only specified plugins" },
24.1.5 by Björn Påhlsson
plugbasedclient:
129
    { .name = "disable-plugin", .key = 'd',
130
      .arg = "Plugin[,Plugin[,...]]", .flags = 0,
131
      .doc = "Option to disable specififed plugins" },
132
    { .name = "plugin-dir", .key = 128,
133
      .arg = "Directory", .flags = 0,
134
      .doc = "Option to change directory to search for plugins" },
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
135
    { .name = NULL }
136
  };
137
  
138
  error_t parse_opt (int key, char *arg, struct argp_state *state) {
139
       /* Get the INPUT argument from `argp_parse', which we
140
          know is a pointer to our arguments structure. */
141
    plugin **plugins = state->input;
142
    switch (key) {
143
    case 'g':
144
      if (arg != NULL){
145
	char *p = strtok(arg, ",");
146
	do{
147
	  addarguments(getplugin(NULL, plugins), p);
148
	  p = strtok(NULL, ",");
149
	} while (p);
150
      }
151
      break;
152
    case 'o':
153
      if (arg != NULL){
154
	char *name = strtok(arg, ":");
155
	char *p = strtok(NULL, ":");
156
	p = strtok(p, ",");
157
	do{
158
	  addarguments(getplugin(name, plugins), p);
159
	  p = strtok(NULL, ",");
160
	} while (p);
161
      }
162
      break;
24.1.5 by Björn Påhlsson
plugbasedclient:
163
    case 'd':
164
      if (arg != NULL){
165
	char *p = strtok(arg, ",");
166
	do{
167
	  getplugin(p, plugins)->disable = true;
168
	  p = strtok(NULL, ",");
169
	} while (p);
170
      }
171
      break;
172
    case 128:
173
      plugindir = arg;
174
      break;
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
175
    case ARGP_KEY_ARG:
176
      argp_usage (state);
177
      break;
178
    case ARGP_KEY_END:
179
      break;
180
    default:
181
      return ARGP_ERR_UNKNOWN;
182
    }
183
    return 0;
184
  }
185
186
  plugin *plugin_list = NULL;
187
  
188
  struct argp argp = { .options = options, .parser = parse_opt,
189
		       .args_doc = args_doc, .doc = doc };
190
191
  argp_parse (&argp, argc, argv, 0, 0, &plugin_list);
192
193
/*   for(plugin *p = plugin_list; p != NULL; p=p->next){ */
194
/*     fprintf(stderr, "Plugin: %s has %d arguments\n", p->name ? p->name : "Global", p->argc); */
195
/*     for(char **a = p->argv + 1; *a != NULL; a++){ */
196
/*       fprintf(stderr, "\tArg: %s\n", *a); */
197
/*     } */
198
/*   } */
199
  
200
/*   return 0; */
24.1.5 by Björn Påhlsson
plugbasedclient:
201
13 by Björn Påhlsson
Added following support:
202
  dir = opendir(plugindir);
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
203
  
13 by Björn Påhlsson
Added following support:
204
  if(dir == NULL){
205
    fprintf(stderr, "Can not open directory\n");
206
    return EXIT_FAILURE;
207
  }
208
  
209
  FD_ZERO(&rfds_orig);
210
  
211
  while(true){
212
    dirst = readdir(dir);
213
    
214
    // All directory entries have been processed
215
    if(dirst == NULL){
216
      break;
217
    }
218
    
219
    d_name_len = strlen(dirst->d_name);
220
    
221
    // Ignore dotfiles and backup files
222
    if (dirst->d_name[0] == '.'
223
	or dirst->d_name[d_name_len - 1] == '~'){
224
      continue;
225
    }
14 by Björn Påhlsson
Fixed a overbufferflow bug, thanks to a forgotten \0
226
24.1.5 by Björn Påhlsson
plugbasedclient:
227
    char *filename = malloc(d_name_len + strlen(plugindir) + 2);
13 by Björn Påhlsson
Added following support:
228
    strcpy(filename, plugindir);
229
    strcat(filename, "/");
230
    strcat(filename, dirst->d_name);    
14 by Björn Påhlsson
Fixed a overbufferflow bug, thanks to a forgotten \0
231
13 by Björn Påhlsson
Added following support:
232
    stat(filename, &st);
233
24.1.5 by Björn Påhlsson
plugbasedclient:
234
    if (S_ISREG(st.st_mode)
235
	and (access(filename, X_OK) == 0)
236
	and not (getplugin(dirst->d_name, &plugin_list)->disable)){
13 by Björn Påhlsson
Added following support:
237
      // Starting a new process to be watched
238
      process *new_process = malloc(sizeof(process));
24.1.5 by Björn Påhlsson
plugbasedclient:
239
      int pipefd[2]; 
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
240
      ret = pipe(pipefd);
241
      if (ret == -1){
242
	perror(argv[0]);
243
	goto end;
244
      }
13 by Björn Påhlsson
Added following support:
245
      new_process->pid = fork();
246
      if(new_process->pid == 0){
247
	/* this is the child process */
248
	closedir(dir);
249
	close(pipefd[0]);	/* close unused read end of pipe */
250
	dup2(pipefd[1], STDOUT_FILENO); /* replace our stdout */
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
251
24.1.5 by Björn Påhlsson
plugbasedclient:
252
	plugin *p = getplugin(dirst->d_name, &plugin_list);
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
253
	plugin *g = getplugin(NULL, &plugin_list);
254
	for(char **a = g->argv + 1; *a != NULL; a++){
255
	  addarguments(p, *a);
256
	}
257
	if(execv(filename, p->argv) < 0){
13 by Björn Påhlsson
Added following support:
258
	  perror(argv[0]);
259
	  close(pipefd[1]);
260
	  exit(EXIT_FAILURE);
261
	}
262
	/* no return */
263
      }
264
      close(pipefd[1]);		/* close unused write end of pipe */
265
      new_process->fd = pipefd[0];
266
      new_process->buffer = malloc(BUFFER_SIZE);
267
      if (new_process->buffer == NULL){
268
	perror(argv[0]);
269
	goto end;
270
      }
271
      new_process->buffer_size = BUFFER_SIZE;
272
      new_process->buffer_length = 0;
273
      FD_SET(new_process->fd, &rfds_orig);
274
      
275
      if (maxfd < new_process->fd){
276
	maxfd = new_process->fd;
277
      }
278
      
279
      //List handling
280
      new_process->next = process_list;
281
      process_list = new_process;
282
    }
283
  }
284
  
285
  closedir(dir);
286
  
287
  if (process_list != NULL){
288
    while(true){
289
      fd_set rfds = rfds_orig;
290
      int select_ret = select(maxfd+1, &rfds, NULL, NULL, NULL);
291
      if (select_ret == -1){
292
	perror(argv[0]);
293
	goto end;
294
      }else{	
295
	for(process *process_itr = process_list; process_itr != NULL;
296
	    process_itr = process_itr->next){
297
	  if(FD_ISSET(process_itr->fd, &rfds)){
298
	    if(process_itr->buffer_length + BUFFER_SIZE
299
	       > process_itr->buffer_size){
300
		process_itr->buffer = realloc(process_itr->buffer,
301
					      process_itr->buffer_size
21 by Teddy Hogeborn
* Makefile (CFLAGS): Changed to use $(WARN), $(DEBUG), $(COVERAGE) and
302
					      + (size_t) BUFFER_SIZE);
13 by Björn Påhlsson
Added following support:
303
		if (process_itr->buffer == NULL){
304
		  perror(argv[0]);
305
		  goto end;
306
		}
307
		process_itr->buffer_size += BUFFER_SIZE;
308
	    }
309
	    ret = read(process_itr->fd, process_itr->buffer
310
		       + process_itr->buffer_length, BUFFER_SIZE);
21 by Teddy Hogeborn
* Makefile (CFLAGS): Changed to use $(WARN), $(DEBUG), $(COVERAGE) and
311
	    if(ret < 0){
312
	      /* Read error from this process; ignore it */
313
	      continue;
314
	    }
315
	    process_itr->buffer_length += (size_t) ret;
13 by Björn Påhlsson
Added following support:
316
	    if(ret == 0){
317
	      /* got EOF */
318
	      /* wait for process exit */
319
	      int status;
320
	      waitpid(process_itr->pid, &status, 0);
321
	      if(WIFEXITED(status) and WEXITSTATUS(status) == 0){
24.1.1 by Björn Påhlsson
Added syntax and support for plugbasedclient arguments and how they
322
		for(size_t written = 0;
323
		    written < process_itr->buffer_length;){
324
		  ret = write(STDOUT_FILENO,
325
			      process_itr->buffer + written,
326
			      process_itr->buffer_length - written);
327
		  if(ret < 0){
328
		    perror(argv[0]);
329
		    goto end;
330
		  }
331
		  written += (size_t)ret;
332
		}
13 by Björn Påhlsson
Added following support:
333
		goto end;
334
	      } else {
335
		FD_CLR(process_itr->fd, &rfds_orig);
336
	      }
337
	    }
338
	  }
339
	}
340
      }
341
    }
342
  }
343
  
344
 end:
345
  for(process *process_itr = process_list; process_itr != NULL;
346
      process_itr = process_itr->next){
347
    close(process_itr->fd);
348
    kill(process_itr->pid, SIGTERM);
349
    free(process_itr->buffer);
350
  }
351
  
352
  while(true){
353
    int status;
354
    ret = wait(&status);
355
    if (ret == -1){
356
      if(errno != ECHILD){
357
	perror("wait");
358
      }
359
      break;
360
    }
361
  }  
362
  return EXIT_SUCCESS;
363
}