1
/* -*- coding: utf-8 -*- */
3
* Mandos-client - get and decrypt data from a Mandos server
5
* This program is partly derived from an example program for an Avahi
6
* service browser, downloaded from
7
* <http://avahi.org/browser/examples/core-browse-services.c>. This
8
* includes the following functions: "resolve_callback",
9
* "browse_callback", and parts of "main".
12
* Copyright © 2008-2014 Teddy Hogeborn
13
* Copyright © 2008-2014 Björn Påhlsson
15
* This program is free software: you can redistribute it and/or
16
* modify it under the terms of the GNU General Public License as
17
* published by the Free Software Foundation, either version 3 of the
18
* License, or (at your option) any later version.
20
* This program is distributed in the hope that it will be useful, but
21
* WITHOUT ANY WARRANTY; without even the implied warranty of
22
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
23
* General Public License for more details.
25
* You should have received a copy of the GNU General Public License
26
* along with this program. If not, see
27
* <http://www.gnu.org/licenses/>.
29
* Contact the authors at <mandos@recompile.se>.
32
/* Needed by GPGME, specifically gpgme_data_seek() */
33
#ifndef _LARGEFILE_SOURCE
34
#define _LARGEFILE_SOURCE
36
#ifndef _FILE_OFFSET_BITS
37
#define _FILE_OFFSET_BITS 64
40
#define _GNU_SOURCE /* TEMP_FAILURE_RETRY(), asprintf() */
42
#include <stdio.h> /* fprintf(), stderr, fwrite(),
43
stdout, ferror(), remove() */
44
#include <stdint.h> /* uint16_t, uint32_t, intptr_t */
45
#include <stddef.h> /* NULL, size_t, ssize_t */
46
#include <stdlib.h> /* free(), EXIT_SUCCESS, srand(),
48
#include <stdbool.h> /* bool, false, true */
49
#include <string.h> /* memset(), strcmp(), strlen(),
50
strerror(), asprintf(), strcpy() */
51
#include <sys/ioctl.h> /* ioctl */
52
#include <sys/types.h> /* socket(), inet_pton(), sockaddr,
53
sockaddr_in6, PF_INET6,
54
SOCK_STREAM, uid_t, gid_t, open(),
56
#include <sys/stat.h> /* open(), S_ISREG */
57
#include <sys/socket.h> /* socket(), struct sockaddr_in6,
58
inet_pton(), connect(),
60
#include <fcntl.h> /* open() */
61
#include <dirent.h> /* opendir(), struct dirent, readdir()
63
#include <inttypes.h> /* PRIu16, PRIdMAX, intmax_t,
65
#include <errno.h> /* perror(), errno,
66
program_invocation_short_name */
67
#include <time.h> /* nanosleep(), time(), sleep() */
68
#include <net/if.h> /* ioctl, ifreq, SIOCGIFFLAGS, IFF_UP,
69
SIOCSIFFLAGS, if_indextoname(),
70
if_nametoindex(), IF_NAMESIZE */
71
#include <netinet/in.h> /* IN6_IS_ADDR_LINKLOCAL,
72
INET_ADDRSTRLEN, INET6_ADDRSTRLEN
74
#include <unistd.h> /* close(), SEEK_SET, off_t, write(),
75
getuid(), getgid(), seteuid(),
76
setgid(), pause(), _exit() */
77
#include <arpa/inet.h> /* inet_pton(), htons() */
78
#include <iso646.h> /* not, or, and */
79
#include <argp.h> /* struct argp_option, error_t, struct
80
argp_state, struct argp,
81
argp_parse(), ARGP_KEY_ARG,
82
ARGP_KEY_END, ARGP_ERR_UNKNOWN */
83
#include <signal.h> /* sigemptyset(), sigaddset(),
84
sigaction(), SIGTERM, sig_atomic_t,
86
#include <sysexits.h> /* EX_OSERR, EX_USAGE, EX_UNAVAILABLE,
87
EX_NOHOST, EX_IOERR, EX_PROTOCOL */
88
#include <sys/wait.h> /* waitpid(), WIFEXITED(),
89
WEXITSTATUS(), WTERMSIG() */
90
#include <grp.h> /* setgroups() */
91
#include <argz.h> /* argz_add_sep(), argz_next(),
92
argz_delete(), argz_append(),
93
argz_stringify(), argz_add(),
95
#include <netdb.h> /* getnameinfo(), NI_NUMERICHOST,
96
EAI_SYSTEM, gai_strerror() */
99
#include <sys/klog.h> /* klogctl() */
100
#endif /* __linux__ */
103
/* All Avahi types, constants and functions
106
#include <avahi-core/core.h>
107
#include <avahi-core/lookup.h>
108
#include <avahi-core/log.h>
109
#include <avahi-common/simple-watch.h>
110
#include <avahi-common/malloc.h>
111
#include <avahi-common/error.h>
114
#include <gnutls/gnutls.h> /* All GnuTLS types, constants and
117
init_gnutls_session(),
119
#include <gnutls/openpgp.h>
120
/* gnutls_certificate_set_openpgp_key_file(),
121
GNUTLS_OPENPGP_FMT_BASE64 */
124
#include <gpgme.h> /* All GPGME types, constants and
127
GPGME_PROTOCOL_OpenPGP,
130
#define BUFFER_SIZE 256
132
#define PATHDIR "/conf/conf.d/mandos"
133
#define SECKEY "seckey.txt"
134
#define PUBKEY "pubkey.txt"
135
#define HOOKDIR "/lib/mandos/network-hooks.d"
138
static const char mandos_protocol_version[] = "1";
139
const char *argp_program_version = "mandos-client " VERSION;
140
const char *argp_program_bug_address = "<mandos@recompile.se>";
141
static const char sys_class_net[] = "/sys/class/net";
142
char *connect_to = NULL;
143
const char *hookdir = HOOKDIR;
147
/* Doubly linked list that need to be circularly linked when used */
148
typedef struct server{
151
AvahiIfIndex if_index;
153
struct timespec last_seen;
158
/* Used for passing in values through the Avahi callback functions */
161
gnutls_certificate_credentials_t cred;
162
unsigned int dh_bits;
163
gnutls_dh_params_t dh_params;
164
const char *priority;
166
server *current_server;
168
size_t interfaces_size;
171
/* global so signal handler can reach it*/
172
AvahiSimplePoll *simple_poll;
174
sig_atomic_t quit_now = 0;
175
int signal_received = 0;
177
/* Function to use when printing errors */
178
void perror_plus(const char *print_text){
180
fprintf(stderr, "Mandos plugin %s: ",
181
program_invocation_short_name);
186
__attribute__((format (gnu_printf, 2, 3), nonnull))
187
int fprintf_plus(FILE *stream, const char *format, ...){
189
va_start (ap, format);
191
TEMP_FAILURE_RETRY(fprintf(stream, "Mandos plugin %s: ",
192
program_invocation_short_name));
193
return (int)TEMP_FAILURE_RETRY(vfprintf(stream, format, ap));
197
* Make additional room in "buffer" for at least BUFFER_SIZE more
198
* bytes. "buffer_capacity" is how much is currently allocated,
199
* "buffer_length" is how much is already used.
201
__attribute__((nonnull, warn_unused_result))
202
size_t incbuffer(char **buffer, size_t buffer_length,
203
size_t buffer_capacity){
204
if(buffer_length + BUFFER_SIZE > buffer_capacity){
205
char *new_buf = realloc(*buffer, buffer_capacity + BUFFER_SIZE);
207
int old_errno = errno;
214
buffer_capacity += BUFFER_SIZE;
216
return buffer_capacity;
219
/* Add server to set of servers to retry periodically */
220
__attribute__((nonnull, warn_unused_result))
221
bool add_server(const char *ip, in_port_t port, AvahiIfIndex if_index,
222
int af, server **current_server){
224
server *new_server = malloc(sizeof(server));
225
if(new_server == NULL){
226
perror_plus("malloc");
229
*new_server = (server){ .ip = strdup(ip),
231
.if_index = if_index,
233
if(new_server->ip == NULL){
234
perror_plus("strdup");
237
ret = clock_gettime(CLOCK_MONOTONIC, &(new_server->last_seen));
239
perror_plus("clock_gettime");
242
/* Special case of first server */
243
if(*current_server == NULL){
244
new_server->next = new_server;
245
new_server->prev = new_server;
246
*current_server = new_server;
248
/* Place the new server last in the list */
249
new_server->next = *current_server;
250
new_server->prev = (*current_server)->prev;
251
new_server->prev->next = new_server;
252
(*current_server)->prev = new_server;
260
__attribute__((nonnull, warn_unused_result))
261
static bool init_gpgme(const char * const seckey,
262
const char * const pubkey,
263
const char * const tempdir,
266
gpgme_engine_info_t engine_info;
269
* Helper function to insert pub and seckey to the engine keyring.
271
bool import_key(const char * const filename){
274
gpgme_data_t pgp_data;
276
fd = (int)TEMP_FAILURE_RETRY(open(filename, O_RDONLY));
282
rc = gpgme_data_new_from_fd(&pgp_data, fd);
283
if(rc != GPG_ERR_NO_ERROR){
284
fprintf_plus(stderr, "bad gpgme_data_new_from_fd: %s: %s\n",
285
gpgme_strsource(rc), gpgme_strerror(rc));
289
rc = gpgme_op_import(mc->ctx, pgp_data);
290
if(rc != GPG_ERR_NO_ERROR){
291
fprintf_plus(stderr, "bad gpgme_op_import: %s: %s\n",
292
gpgme_strsource(rc), gpgme_strerror(rc));
296
ret = (int)TEMP_FAILURE_RETRY(close(fd));
298
perror_plus("close");
300
gpgme_data_release(pgp_data);
305
fprintf_plus(stderr, "Initializing GPGME\n");
309
gpgme_check_version(NULL);
310
rc = gpgme_engine_check_version(GPGME_PROTOCOL_OpenPGP);
311
if(rc != GPG_ERR_NO_ERROR){
312
fprintf_plus(stderr, "bad gpgme_engine_check_version: %s: %s\n",
313
gpgme_strsource(rc), gpgme_strerror(rc));
317
/* Set GPGME home directory for the OpenPGP engine only */
318
rc = gpgme_get_engine_info(&engine_info);
319
if(rc != GPG_ERR_NO_ERROR){
320
fprintf_plus(stderr, "bad gpgme_get_engine_info: %s: %s\n",
321
gpgme_strsource(rc), gpgme_strerror(rc));
324
while(engine_info != NULL){
325
if(engine_info->protocol == GPGME_PROTOCOL_OpenPGP){
326
gpgme_set_engine_info(GPGME_PROTOCOL_OpenPGP,
327
engine_info->file_name, tempdir);
330
engine_info = engine_info->next;
332
if(engine_info == NULL){
333
fprintf_plus(stderr, "Could not set GPGME home dir to %s\n",
338
/* Create new GPGME "context" */
339
rc = gpgme_new(&(mc->ctx));
340
if(rc != GPG_ERR_NO_ERROR){
341
fprintf_plus(stderr, "Mandos plugin mandos-client: "
342
"bad gpgme_new: %s: %s\n", gpgme_strsource(rc),
347
if(not import_key(pubkey) or not import_key(seckey)){
355
* Decrypt OpenPGP data.
356
* Returns -1 on error
358
__attribute__((nonnull, warn_unused_result))
359
static ssize_t pgp_packet_decrypt(const char *cryptotext,
363
gpgme_data_t dh_crypto, dh_plain;
366
size_t plaintext_capacity = 0;
367
ssize_t plaintext_length = 0;
370
fprintf_plus(stderr, "Trying to decrypt OpenPGP data\n");
373
/* Create new GPGME data buffer from memory cryptotext */
374
rc = gpgme_data_new_from_mem(&dh_crypto, cryptotext, crypto_size,
376
if(rc != GPG_ERR_NO_ERROR){
377
fprintf_plus(stderr, "bad gpgme_data_new_from_mem: %s: %s\n",
378
gpgme_strsource(rc), gpgme_strerror(rc));
382
/* Create new empty GPGME data buffer for the plaintext */
383
rc = gpgme_data_new(&dh_plain);
384
if(rc != GPG_ERR_NO_ERROR){
385
fprintf_plus(stderr, "Mandos plugin mandos-client: "
386
"bad gpgme_data_new: %s: %s\n",
387
gpgme_strsource(rc), gpgme_strerror(rc));
388
gpgme_data_release(dh_crypto);
392
/* Decrypt data from the cryptotext data buffer to the plaintext
394
rc = gpgme_op_decrypt(mc->ctx, dh_crypto, dh_plain);
395
if(rc != GPG_ERR_NO_ERROR){
396
fprintf_plus(stderr, "bad gpgme_op_decrypt: %s: %s\n",
397
gpgme_strsource(rc), gpgme_strerror(rc));
398
plaintext_length = -1;
400
gpgme_decrypt_result_t result;
401
result = gpgme_op_decrypt_result(mc->ctx);
403
fprintf_plus(stderr, "gpgme_op_decrypt_result failed\n");
405
fprintf_plus(stderr, "Unsupported algorithm: %s\n",
406
result->unsupported_algorithm);
407
fprintf_plus(stderr, "Wrong key usage: %u\n",
408
result->wrong_key_usage);
409
if(result->file_name != NULL){
410
fprintf_plus(stderr, "File name: %s\n", result->file_name);
412
gpgme_recipient_t recipient;
413
recipient = result->recipients;
414
while(recipient != NULL){
415
fprintf_plus(stderr, "Public key algorithm: %s\n",
416
gpgme_pubkey_algo_name
417
(recipient->pubkey_algo));
418
fprintf_plus(stderr, "Key ID: %s\n", recipient->keyid);
419
fprintf_plus(stderr, "Secret key available: %s\n",
420
recipient->status == GPG_ERR_NO_SECKEY
422
recipient = recipient->next;
430
fprintf_plus(stderr, "Decryption of OpenPGP data succeeded\n");
433
/* Seek back to the beginning of the GPGME plaintext data buffer */
434
if(gpgme_data_seek(dh_plain, (off_t)0, SEEK_SET) == -1){
435
perror_plus("gpgme_data_seek");
436
plaintext_length = -1;
442
plaintext_capacity = incbuffer(plaintext,
443
(size_t)plaintext_length,
445
if(plaintext_capacity == 0){
446
perror_plus("incbuffer");
447
plaintext_length = -1;
451
ret = gpgme_data_read(dh_plain, *plaintext + plaintext_length,
453
/* Print the data, if any */
459
perror_plus("gpgme_data_read");
460
plaintext_length = -1;
463
plaintext_length += ret;
467
fprintf_plus(stderr, "Decrypted password is: ");
468
for(ssize_t i = 0; i < plaintext_length; i++){
469
fprintf(stderr, "%02hhX ", (*plaintext)[i]);
471
fprintf(stderr, "\n");
476
/* Delete the GPGME cryptotext data buffer */
477
gpgme_data_release(dh_crypto);
479
/* Delete the GPGME plaintext data buffer */
480
gpgme_data_release(dh_plain);
481
return plaintext_length;
484
__attribute__((warn_unused_result))
485
static const char *safer_gnutls_strerror(int value){
486
const char *ret = gnutls_strerror(value);
492
/* GnuTLS log function callback */
493
__attribute__((nonnull))
494
static void debuggnutls(__attribute__((unused)) int level,
496
fprintf_plus(stderr, "GnuTLS: %s", string);
499
__attribute__((nonnull, warn_unused_result))
500
static int init_gnutls_global(const char *pubkeyfilename,
501
const char *seckeyfilename,
506
fprintf_plus(stderr, "Initializing GnuTLS\n");
509
ret = gnutls_global_init();
510
if(ret != GNUTLS_E_SUCCESS){
511
fprintf_plus(stderr, "GnuTLS global_init: %s\n",
512
safer_gnutls_strerror(ret));
517
/* "Use a log level over 10 to enable all debugging options."
520
gnutls_global_set_log_level(11);
521
gnutls_global_set_log_function(debuggnutls);
524
/* OpenPGP credentials */
525
ret = gnutls_certificate_allocate_credentials(&mc->cred);
526
if(ret != GNUTLS_E_SUCCESS){
527
fprintf_plus(stderr, "GnuTLS memory error: %s\n",
528
safer_gnutls_strerror(ret));
529
gnutls_global_deinit();
534
fprintf_plus(stderr, "Attempting to use OpenPGP public key %s and"
535
" secret key %s as GnuTLS credentials\n",
540
ret = gnutls_certificate_set_openpgp_key_file
541
(mc->cred, pubkeyfilename, seckeyfilename,
542
GNUTLS_OPENPGP_FMT_BASE64);
543
if(ret != GNUTLS_E_SUCCESS){
545
"Error[%d] while reading the OpenPGP key pair ('%s',"
546
" '%s')\n", ret, pubkeyfilename, seckeyfilename);
547
fprintf_plus(stderr, "The GnuTLS error is: %s\n",
548
safer_gnutls_strerror(ret));
552
/* GnuTLS server initialization */
553
ret = gnutls_dh_params_init(&mc->dh_params);
554
if(ret != GNUTLS_E_SUCCESS){
555
fprintf_plus(stderr, "Error in GnuTLS DH parameter"
556
" initialization: %s\n",
557
safer_gnutls_strerror(ret));
560
ret = gnutls_dh_params_generate2(mc->dh_params, mc->dh_bits);
561
if(ret != GNUTLS_E_SUCCESS){
562
fprintf_plus(stderr, "Error in GnuTLS prime generation: %s\n",
563
safer_gnutls_strerror(ret));
567
gnutls_certificate_set_dh_params(mc->cred, mc->dh_params);
573
gnutls_certificate_free_credentials(mc->cred);
574
gnutls_global_deinit();
575
gnutls_dh_params_deinit(mc->dh_params);
579
__attribute__((nonnull, warn_unused_result))
580
static int init_gnutls_session(gnutls_session_t *session,
583
/* GnuTLS session creation */
585
ret = gnutls_init(session, GNUTLS_SERVER);
589
} while(ret == GNUTLS_E_INTERRUPTED or ret == GNUTLS_E_AGAIN);
590
if(ret != GNUTLS_E_SUCCESS){
592
"Error in GnuTLS session initialization: %s\n",
593
safer_gnutls_strerror(ret));
599
ret = gnutls_priority_set_direct(*session, mc->priority, &err);
601
gnutls_deinit(*session);
604
} while(ret == GNUTLS_E_INTERRUPTED or ret == GNUTLS_E_AGAIN);
605
if(ret != GNUTLS_E_SUCCESS){
606
fprintf_plus(stderr, "Syntax error at: %s\n", err);
607
fprintf_plus(stderr, "GnuTLS error: %s\n",
608
safer_gnutls_strerror(ret));
609
gnutls_deinit(*session);
615
ret = gnutls_credentials_set(*session, GNUTLS_CRD_CERTIFICATE,
618
gnutls_deinit(*session);
621
} while(ret == GNUTLS_E_INTERRUPTED or ret == GNUTLS_E_AGAIN);
622
if(ret != GNUTLS_E_SUCCESS){
623
fprintf_plus(stderr, "Error setting GnuTLS credentials: %s\n",
624
safer_gnutls_strerror(ret));
625
gnutls_deinit(*session);
629
/* ignore client certificate if any. */
630
gnutls_certificate_server_set_request(*session, GNUTLS_CERT_IGNORE);
632
gnutls_dh_set_prime_bits(*session, mc->dh_bits);
637
/* Avahi log function callback */
638
static void empty_log(__attribute__((unused)) AvahiLogLevel level,
639
__attribute__((unused)) const char *txt){}
641
/* Called when a Mandos server is found */
642
__attribute__((nonnull, warn_unused_result))
643
static int start_mandos_communication(const char *ip, in_port_t port,
644
AvahiIfIndex if_index,
645
int af, mandos_context *mc){
646
int ret, tcp_sd = -1;
648
struct sockaddr_storage to;
650
char *decrypted_buffer = NULL;
651
size_t buffer_length = 0;
652
size_t buffer_capacity = 0;
655
gnutls_session_t session;
656
int pf; /* Protocol family */
673
fprintf_plus(stderr, "Bad address family: %d\n", af);
678
/* If the interface is specified and we have a list of interfaces */
679
if(if_index != AVAHI_IF_UNSPEC and mc->interfaces != NULL){
680
/* Check if the interface is one of the interfaces we are using */
683
char *interface = NULL;
684
while((interface=argz_next(mc->interfaces, mc->interfaces_size,
686
if(if_nametoindex(interface) == (unsigned int)if_index){
693
/* This interface does not match any in the list, so we don't
694
connect to the server */
696
char interface[IF_NAMESIZE];
697
if(if_indextoname((unsigned int)if_index, interface) == NULL){
698
perror_plus("if_indextoname");
700
fprintf_plus(stderr, "Skipping server on non-used interface"
702
if_indextoname((unsigned int)if_index,
710
ret = init_gnutls_session(&session, mc);
716
fprintf_plus(stderr, "Setting up a TCP connection to %s, port %"
717
PRIuMAX "\n", ip, (uintmax_t)port);
720
tcp_sd = socket(pf, SOCK_STREAM, 0);
723
perror_plus("socket");
733
memset(&to, 0, sizeof(to));
735
((struct sockaddr_in6 *)&to)->sin6_family = (sa_family_t)af;
736
ret = inet_pton(af, ip, &((struct sockaddr_in6 *)&to)->sin6_addr);
738
((struct sockaddr_in *)&to)->sin_family = (sa_family_t)af;
739
ret = inet_pton(af, ip, &((struct sockaddr_in *)&to)->sin_addr);
743
perror_plus("inet_pton");
749
fprintf_plus(stderr, "Bad address: %s\n", ip);
754
((struct sockaddr_in6 *)&to)->sin6_port = htons(port);
755
if(IN6_IS_ADDR_LINKLOCAL
756
(&((struct sockaddr_in6 *)&to)->sin6_addr)){
757
if(if_index == AVAHI_IF_UNSPEC){
758
fprintf_plus(stderr, "An IPv6 link-local address is"
759
" incomplete without a network interface\n");
763
/* Set the network interface number as scope */
764
((struct sockaddr_in6 *)&to)->sin6_scope_id = (uint32_t)if_index;
767
((struct sockaddr_in *)&to)->sin_port = htons(port);
776
if(af == AF_INET6 and if_index != AVAHI_IF_UNSPEC){
777
char interface[IF_NAMESIZE];
778
if(if_indextoname((unsigned int)if_index, interface) == NULL){
779
perror_plus("if_indextoname");
781
fprintf_plus(stderr, "Connection to: %s%%%s, port %" PRIuMAX
782
"\n", ip, interface, (uintmax_t)port);
785
fprintf_plus(stderr, "Connection to: %s, port %" PRIuMAX "\n",
786
ip, (uintmax_t)port);
788
char addrstr[(INET_ADDRSTRLEN > INET6_ADDRSTRLEN) ?
789
INET_ADDRSTRLEN : INET6_ADDRSTRLEN] = "";
791
ret = getnameinfo((struct sockaddr *)&to,
792
sizeof(struct sockaddr_in6),
793
addrstr, sizeof(addrstr), NULL, 0,
796
ret = getnameinfo((struct sockaddr *)&to,
797
sizeof(struct sockaddr_in),
798
addrstr, sizeof(addrstr), NULL, 0,
801
if(ret == EAI_SYSTEM){
802
perror_plus("getnameinfo");
803
} else if(ret != 0) {
804
fprintf_plus(stderr, "getnameinfo: %s", gai_strerror(ret));
805
} else if(strcmp(addrstr, ip) != 0){
806
fprintf_plus(stderr, "Canonical address form: %s\n", addrstr);
816
ret = connect(tcp_sd, (struct sockaddr *)&to,
817
sizeof(struct sockaddr_in6));
819
ret = connect(tcp_sd, (struct sockaddr *)&to, /* IPv4 */
820
sizeof(struct sockaddr_in));
823
if((errno != ECONNREFUSED and errno != ENETUNREACH) or debug){
825
perror_plus("connect");
836
const char *out = mandos_protocol_version;
839
size_t out_size = strlen(out);
840
ret = (int)TEMP_FAILURE_RETRY(write(tcp_sd, out + written,
841
out_size - written));
844
perror_plus("write");
848
written += (size_t)ret;
849
if(written < out_size){
852
if(out == mandos_protocol_version){
867
fprintf_plus(stderr, "Establishing TLS session with %s\n", ip);
875
/* This casting via intptr_t is to eliminate warning about casting
876
an int to a pointer type. This is exactly how the GnuTLS Guile
877
function "set-session-transport-fd!" does it. */
878
gnutls_transport_set_ptr(session,
879
(gnutls_transport_ptr_t)(intptr_t)tcp_sd);
887
ret = gnutls_handshake(session);
892
} while(ret == GNUTLS_E_AGAIN or ret == GNUTLS_E_INTERRUPTED);
894
if(ret != GNUTLS_E_SUCCESS){
896
fprintf_plus(stderr, "*** GnuTLS Handshake failed ***\n");
903
/* Read OpenPGP packet that contains the wanted password */
906
fprintf_plus(stderr, "Retrieving OpenPGP encrypted password from"
917
buffer_capacity = incbuffer(&buffer, buffer_length,
919
if(buffer_capacity == 0){
921
perror_plus("incbuffer");
931
sret = gnutls_record_recv(session, buffer+buffer_length,
938
case GNUTLS_E_INTERRUPTED:
941
case GNUTLS_E_REHANDSHAKE:
943
ret = gnutls_handshake(session);
949
} while(ret == GNUTLS_E_AGAIN or ret == GNUTLS_E_INTERRUPTED);
951
fprintf_plus(stderr, "*** GnuTLS Re-handshake failed "
959
fprintf_plus(stderr, "Unknown error while reading data from"
960
" encrypted session with Mandos server\n");
961
gnutls_bye(session, GNUTLS_SHUT_RDWR);
966
buffer_length += (size_t) sret;
971
fprintf_plus(stderr, "Closing TLS session\n");
980
ret = gnutls_bye(session, GNUTLS_SHUT_RDWR);
985
} while(ret == GNUTLS_E_AGAIN or ret == GNUTLS_E_INTERRUPTED);
987
if(buffer_length > 0){
988
ssize_t decrypted_buffer_size;
989
decrypted_buffer_size = pgp_packet_decrypt(buffer, buffer_length,
990
&decrypted_buffer, mc);
991
if(decrypted_buffer_size >= 0){
994
while(written < (size_t) decrypted_buffer_size){
1000
ret = (int)fwrite(decrypted_buffer + written, 1,
1001
(size_t)decrypted_buffer_size - written,
1003
if(ret == 0 and ferror(stdout)){
1006
fprintf_plus(stderr, "Error writing encrypted data: %s\n",
1012
written += (size_t)ret;
1018
/* Shutdown procedure */
1023
free(decrypted_buffer);
1026
ret = (int)TEMP_FAILURE_RETRY(close(tcp_sd));
1032
perror_plus("close");
1034
gnutls_deinit(session);
1044
__attribute__((nonnull))
1045
static void resolve_callback(AvahiSServiceResolver *r,
1046
AvahiIfIndex interface,
1047
AvahiProtocol proto,
1048
AvahiResolverEvent event,
1052
const char *host_name,
1053
const AvahiAddress *address,
1055
AVAHI_GCC_UNUSED AvahiStringList *txt,
1056
AVAHI_GCC_UNUSED AvahiLookupResultFlags
1063
/* Called whenever a service has been resolved successfully or
1072
case AVAHI_RESOLVER_FAILURE:
1073
fprintf_plus(stderr, "(Avahi Resolver) Failed to resolve service "
1074
"'%s' of type '%s' in domain '%s': %s\n", name, type,
1076
avahi_strerror(avahi_server_errno
1077
(((mandos_context*)mc)->server)));
1080
case AVAHI_RESOLVER_FOUND:
1082
char ip[AVAHI_ADDRESS_STR_MAX];
1083
avahi_address_snprint(ip, sizeof(ip), address);
1085
fprintf_plus(stderr, "Mandos server \"%s\" found on %s (%s, %"
1086
PRIdMAX ") on port %" PRIu16 "\n", name,
1087
host_name, ip, (intmax_t)interface, port);
1089
int ret = start_mandos_communication(ip, (in_port_t)port,
1091
avahi_proto_to_af(proto),
1094
avahi_simple_poll_quit(simple_poll);
1096
if(not add_server(ip, (in_port_t)port, interface,
1097
avahi_proto_to_af(proto),
1098
&((mandos_context*)mc)->current_server)){
1099
fprintf_plus(stderr, "Failed to add server \"%s\" to server"
1105
avahi_s_service_resolver_free(r);
1108
static void browse_callback(AvahiSServiceBrowser *b,
1109
AvahiIfIndex interface,
1110
AvahiProtocol protocol,
1111
AvahiBrowserEvent event,
1115
AVAHI_GCC_UNUSED AvahiLookupResultFlags
1122
/* Called whenever a new services becomes available on the LAN or
1123
is removed from the LAN */
1131
case AVAHI_BROWSER_FAILURE:
1133
fprintf_plus(stderr, "(Avahi browser) %s\n",
1134
avahi_strerror(avahi_server_errno
1135
(((mandos_context*)mc)->server)));
1136
avahi_simple_poll_quit(simple_poll);
1139
case AVAHI_BROWSER_NEW:
1140
/* We ignore the returned Avahi resolver object. In the callback
1141
function we free it. If the Avahi server is terminated before
1142
the callback function is called the Avahi server will free the
1145
if(avahi_s_service_resolver_new(((mandos_context*)mc)->server,
1146
interface, protocol, name, type,
1147
domain, protocol, 0,
1148
resolve_callback, mc) == NULL)
1149
fprintf_plus(stderr, "Avahi: Failed to resolve service '%s':"
1151
avahi_strerror(avahi_server_errno
1152
(((mandos_context*)mc)->server)));
1155
case AVAHI_BROWSER_REMOVE:
1158
case AVAHI_BROWSER_ALL_FOR_NOW:
1159
case AVAHI_BROWSER_CACHE_EXHAUSTED:
1161
fprintf_plus(stderr, "No Mandos server found, still"
1168
/* Signal handler that stops main loop after SIGTERM */
1169
static void handle_sigterm(int sig){
1174
signal_received = sig;
1175
int old_errno = errno;
1176
/* set main loop to exit */
1177
if(simple_poll != NULL){
1178
avahi_simple_poll_quit(simple_poll);
1183
__attribute__((nonnull, warn_unused_result))
1184
bool get_flags(const char *ifname, struct ifreq *ifr){
1188
int s = socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP);
1191
perror_plus("socket");
1195
strcpy(ifr->ifr_name, ifname);
1196
ret = ioctl(s, SIOCGIFFLAGS, ifr);
1200
perror_plus("ioctl SIOCGIFFLAGS");
1208
__attribute__((nonnull, warn_unused_result))
1209
bool good_flags(const char *ifname, const struct ifreq *ifr){
1211
/* Reject the loopback device */
1212
if(ifr->ifr_flags & IFF_LOOPBACK){
1214
fprintf_plus(stderr, "Rejecting loopback interface \"%s\"\n",
1219
/* Accept point-to-point devices only if connect_to is specified */
1220
if(connect_to != NULL and (ifr->ifr_flags & IFF_POINTOPOINT)){
1222
fprintf_plus(stderr, "Accepting point-to-point interface"
1223
" \"%s\"\n", ifname);
1227
/* Otherwise, reject non-broadcast-capable devices */
1228
if(not (ifr->ifr_flags & IFF_BROADCAST)){
1230
fprintf_plus(stderr, "Rejecting non-broadcast interface"
1231
" \"%s\"\n", ifname);
1235
/* Reject non-ARP interfaces (including dummy interfaces) */
1236
if(ifr->ifr_flags & IFF_NOARP){
1238
fprintf_plus(stderr, "Rejecting non-ARP interface \"%s\"\n",
1244
/* Accept this device */
1246
fprintf_plus(stderr, "Interface \"%s\" is good\n", ifname);
1252
* This function determines if a directory entry in /sys/class/net
1253
* corresponds to an acceptable network device.
1254
* (This function is passed to scandir(3) as a filter function.)
1256
__attribute__((nonnull, warn_unused_result))
1257
int good_interface(const struct dirent *if_entry){
1258
if(if_entry->d_name[0] == '.'){
1263
if(not get_flags(if_entry->d_name, &ifr)){
1265
fprintf_plus(stderr, "Failed to get flags for interface "
1266
"\"%s\"\n", if_entry->d_name);
1271
if(not good_flags(if_entry->d_name, &ifr)){
1278
* This function determines if a network interface is up.
1280
__attribute__((nonnull, warn_unused_result))
1281
bool interface_is_up(const char *interface){
1283
if(not get_flags(interface, &ifr)){
1285
fprintf_plus(stderr, "Failed to get flags for interface "
1286
"\"%s\"\n", interface);
1291
return (bool)(ifr.ifr_flags & IFF_UP);
1295
* This function determines if a network interface is running
1297
__attribute__((nonnull, warn_unused_result))
1298
bool interface_is_running(const char *interface){
1300
if(not get_flags(interface, &ifr)){
1302
fprintf_plus(stderr, "Failed to get flags for interface "
1303
"\"%s\"\n", interface);
1308
return (bool)(ifr.ifr_flags & IFF_RUNNING);
1311
__attribute__((nonnull, pure, warn_unused_result))
1312
int notdotentries(const struct dirent *direntry){
1313
/* Skip "." and ".." */
1314
if(direntry->d_name[0] == '.'
1315
and (direntry->d_name[1] == '\0'
1316
or (direntry->d_name[1] == '.'
1317
and direntry->d_name[2] == '\0'))){
1323
/* Is this directory entry a runnable program? */
1324
__attribute__((nonnull, warn_unused_result))
1325
int runnable_hook(const struct dirent *direntry){
1330
if((direntry->d_name)[0] == '\0'){
1335
sret = strspn(direntry->d_name, "ABCDEFGHIJKLMNOPQRSTUVWXYZ"
1336
"abcdefghijklmnopqrstuvwxyz"
1339
if((direntry->d_name)[sret] != '\0'){
1340
/* Contains non-allowed characters */
1342
fprintf_plus(stderr, "Ignoring hook \"%s\" with bad name\n",
1348
char *fullname = NULL;
1349
ret = asprintf(&fullname, "%s/%s", hookdir, direntry->d_name);
1351
perror_plus("asprintf");
1355
ret = stat(fullname, &st);
1358
perror_plus("Could not stat hook");
1363
if(not (S_ISREG(st.st_mode))){
1364
/* Not a regular file */
1366
fprintf_plus(stderr, "Ignoring hook \"%s\" - not a file\n",
1371
if(not (st.st_mode & (S_IXUSR | S_IXGRP | S_IXOTH))){
1372
/* Not executable */
1374
fprintf_plus(stderr, "Ignoring hook \"%s\" - not executable\n",
1380
fprintf_plus(stderr, "Hook \"%s\" is acceptable\n",
1386
__attribute__((nonnull, warn_unused_result))
1387
int avahi_loop_with_timeout(AvahiSimplePoll *s, int retry_interval,
1388
mandos_context *mc){
1390
struct timespec now;
1391
struct timespec waited_time;
1392
intmax_t block_time;
1395
if(mc->current_server == NULL){
1397
fprintf_plus(stderr, "Wait until first server is found."
1400
ret = avahi_simple_poll_iterate(s, -1);
1403
fprintf_plus(stderr, "Check current_server if we should run"
1406
/* the current time */
1407
ret = clock_gettime(CLOCK_MONOTONIC, &now);
1409
perror_plus("clock_gettime");
1412
/* Calculating in ms how long time between now and server
1413
who we visted longest time ago. Now - last seen. */
1414
waited_time.tv_sec = (now.tv_sec
1415
- mc->current_server->last_seen.tv_sec);
1416
waited_time.tv_nsec = (now.tv_nsec
1417
- mc->current_server->last_seen.tv_nsec);
1418
/* total time is 10s/10,000ms.
1419
Converting to s from ms by dividing by 1,000,
1420
and ns to ms by dividing by 1,000,000. */
1421
block_time = ((retry_interval
1422
- ((intmax_t)waited_time.tv_sec * 1000))
1423
- ((intmax_t)waited_time.tv_nsec / 1000000));
1426
fprintf_plus(stderr, "Blocking for %" PRIdMAX " ms\n",
1430
if(block_time <= 0){
1431
ret = start_mandos_communication(mc->current_server->ip,
1432
mc->current_server->port,
1433
mc->current_server->if_index,
1434
mc->current_server->af, mc);
1436
avahi_simple_poll_quit(s);
1439
ret = clock_gettime(CLOCK_MONOTONIC,
1440
&mc->current_server->last_seen);
1442
perror_plus("clock_gettime");
1445
mc->current_server = mc->current_server->next;
1446
block_time = 0; /* Call avahi to find new Mandos
1447
servers, but don't block */
1450
ret = avahi_simple_poll_iterate(s, (int)block_time);
1453
if(ret > 0 or errno != EINTR){
1454
return (ret != 1) ? ret : 0;
1460
/* Set effective uid to 0, return errno */
1461
__attribute__((warn_unused_result))
1462
error_t raise_privileges(void){
1463
error_t old_errno = errno;
1464
error_t ret_errno = 0;
1465
if(seteuid(0) == -1){
1467
perror_plus("seteuid");
1473
/* Set effective and real user ID to 0. Return errno. */
1474
__attribute__((warn_unused_result))
1475
error_t raise_privileges_permanently(void){
1476
error_t old_errno = errno;
1477
error_t ret_errno = raise_privileges();
1482
if(setuid(0) == -1){
1484
perror_plus("seteuid");
1490
/* Set effective user ID to unprivileged saved user ID */
1491
__attribute__((warn_unused_result))
1492
error_t lower_privileges(void){
1493
error_t old_errno = errno;
1494
error_t ret_errno = 0;
1495
if(seteuid(uid) == -1){
1497
perror_plus("seteuid");
1503
/* Lower privileges permanently */
1504
__attribute__((warn_unused_result))
1505
error_t lower_privileges_permanently(void){
1506
error_t old_errno = errno;
1507
error_t ret_errno = 0;
1508
if(setuid(uid) == -1){
1510
perror_plus("setuid");
1516
__attribute__((nonnull))
1517
void run_network_hooks(const char *mode, const char *interface,
1519
struct dirent **direntries;
1520
int numhooks = scandir(hookdir, &direntries, runnable_hook,
1523
if(errno == ENOENT){
1525
fprintf_plus(stderr, "Network hook directory \"%s\" not"
1526
" found\n", hookdir);
1529
perror_plus("scandir");
1532
struct dirent *direntry;
1534
int devnull = open("/dev/null", O_RDONLY);
1535
for(int i = 0; i < numhooks; i++){
1536
direntry = direntries[i];
1537
char *fullname = NULL;
1538
ret = asprintf(&fullname, "%s/%s", hookdir, direntry->d_name);
1540
perror_plus("asprintf");
1544
fprintf_plus(stderr, "Running network hook \"%s\"\n",
1547
pid_t hook_pid = fork();
1550
/* Raise privileges */
1551
if(raise_privileges_permanently() != 0){
1552
perror_plus("Failed to raise privileges");
1559
perror_plus("setgid");
1562
/* Reset supplementary groups */
1564
ret = setgroups(0, NULL);
1566
perror_plus("setgroups");
1569
ret = dup2(devnull, STDIN_FILENO);
1571
perror_plus("dup2(devnull, STDIN_FILENO)");
1574
ret = close(devnull);
1576
perror_plus("close");
1579
ret = dup2(STDERR_FILENO, STDOUT_FILENO);
1581
perror_plus("dup2(STDERR_FILENO, STDOUT_FILENO)");
1584
ret = setenv("MANDOSNETHOOKDIR", hookdir, 1);
1586
perror_plus("setenv");
1589
ret = setenv("DEVICE", interface, 1);
1591
perror_plus("setenv");
1594
ret = setenv("VERBOSITY", debug ? "1" : "0", 1);
1596
perror_plus("setenv");
1599
ret = setenv("MODE", mode, 1);
1601
perror_plus("setenv");
1605
ret = asprintf(&delaystring, "%f", (double)delay);
1607
perror_plus("asprintf");
1610
ret = setenv("DELAY", delaystring, 1);
1613
perror_plus("setenv");
1617
if(connect_to != NULL){
1618
ret = setenv("CONNECT", connect_to, 1);
1620
perror_plus("setenv");
1624
if(execl(fullname, direntry->d_name, mode, NULL) == -1){
1625
perror_plus("execl");
1626
_exit(EXIT_FAILURE);
1630
if(TEMP_FAILURE_RETRY(waitpid(hook_pid, &status, 0)) == -1){
1631
perror_plus("waitpid");
1635
if(WIFEXITED(status)){
1636
if(WEXITSTATUS(status) != 0){
1637
fprintf_plus(stderr, "Warning: network hook \"%s\" exited"
1638
" with status %d\n", direntry->d_name,
1639
WEXITSTATUS(status));
1643
} else if(WIFSIGNALED(status)){
1644
fprintf_plus(stderr, "Warning: network hook \"%s\" died by"
1645
" signal %d\n", direntry->d_name,
1650
fprintf_plus(stderr, "Warning: network hook \"%s\""
1651
" crashed\n", direntry->d_name);
1658
fprintf_plus(stderr, "Network hook \"%s\" ran successfully\n",
1666
__attribute__((nonnull, warn_unused_result))
1667
error_t bring_up_interface(const char *const interface,
1669
error_t old_errno = errno;
1671
struct ifreq network;
1672
unsigned int if_index = if_nametoindex(interface);
1674
fprintf_plus(stderr, "No such interface: \"%s\"\n", interface);
1684
if(not interface_is_up(interface)){
1685
error_t ret_errno = 0, ioctl_errno = 0;
1686
if(not get_flags(interface, &network)){
1688
fprintf_plus(stderr, "Failed to get flags for interface "
1689
"\"%s\"\n", interface);
1693
network.ifr_flags |= IFF_UP; /* set flag */
1695
int sd = socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP);
1698
perror_plus("socket");
1704
ret = (int)TEMP_FAILURE_RETRY(close(sd));
1706
perror_plus("close");
1713
fprintf_plus(stderr, "Bringing up interface \"%s\"\n",
1717
/* Raise privileges */
1718
ret_errno = raise_privileges();
1720
perror_plus("Failed to raise privileges");
1725
bool restore_loglevel = false;
1727
/* Lower kernel loglevel to KERN_NOTICE to avoid KERN_INFO
1728
messages about the network interface to mess up the prompt */
1729
ret_linux = klogctl(8, NULL, 5);
1730
if(ret_linux == -1){
1731
perror_plus("klogctl");
1733
restore_loglevel = true;
1736
#endif /* __linux__ */
1737
int ret_setflags = ioctl(sd, SIOCSIFFLAGS, &network);
1738
ioctl_errno = errno;
1740
if(restore_loglevel){
1741
ret_linux = klogctl(7, NULL, 0);
1742
if(ret_linux == -1){
1743
perror_plus("klogctl");
1746
#endif /* __linux__ */
1748
/* If raise_privileges() succeeded above */
1750
/* Lower privileges */
1751
ret_errno = lower_privileges();
1754
perror_plus("Failed to lower privileges");
1758
/* Close the socket */
1759
ret = (int)TEMP_FAILURE_RETRY(close(sd));
1761
perror_plus("close");
1764
if(ret_setflags == -1){
1765
errno = ioctl_errno;
1766
perror_plus("ioctl SIOCSIFFLAGS +IFF_UP");
1771
fprintf_plus(stderr, "Interface \"%s\" is already up; good\n",
1775
/* Sleep checking until interface is running.
1776
Check every 0.25s, up to total time of delay */
1777
for(int i=0; i < delay * 4; i++){
1778
if(interface_is_running(interface)){
1781
struct timespec sleeptime = { .tv_nsec = 250000000 };
1782
ret = nanosleep(&sleeptime, NULL);
1783
if(ret == -1 and errno != EINTR){
1784
perror_plus("nanosleep");
1792
__attribute__((nonnull, warn_unused_result))
1793
error_t take_down_interface(const char *const interface){
1794
error_t old_errno = errno;
1795
struct ifreq network;
1796
unsigned int if_index = if_nametoindex(interface);
1798
fprintf_plus(stderr, "No such interface: \"%s\"\n", interface);
1802
if(interface_is_up(interface)){
1803
error_t ret_errno = 0, ioctl_errno = 0;
1804
if(not get_flags(interface, &network) and debug){
1806
fprintf_plus(stderr, "Failed to get flags for interface "
1807
"\"%s\"\n", interface);
1811
network.ifr_flags &= ~(short)IFF_UP; /* clear flag */
1813
int sd = socket(PF_INET6, SOCK_DGRAM, IPPROTO_IP);
1816
perror_plus("socket");
1822
fprintf_plus(stderr, "Taking down interface \"%s\"\n",
1826
/* Raise privileges */
1827
ret_errno = raise_privileges();
1829
perror_plus("Failed to raise privileges");
1832
int ret_setflags = ioctl(sd, SIOCSIFFLAGS, &network);
1833
ioctl_errno = errno;
1835
/* If raise_privileges() succeeded above */
1837
/* Lower privileges */
1838
ret_errno = lower_privileges();
1841
perror_plus("Failed to lower privileges");
1845
/* Close the socket */
1846
int ret = (int)TEMP_FAILURE_RETRY(close(sd));
1848
perror_plus("close");
1851
if(ret_setflags == -1){
1852
errno = ioctl_errno;
1853
perror_plus("ioctl SIOCSIFFLAGS -IFF_UP");
1858
fprintf_plus(stderr, "Interface \"%s\" is already down; odd\n",
1866
int main(int argc, char *argv[]){
1867
mandos_context mc = { .server = NULL, .dh_bits = 1024,
1868
.priority = "SECURE256:!CTYPE-X.509:"
1869
"+CTYPE-OPENPGP", .current_server = NULL,
1870
.interfaces = NULL, .interfaces_size = 0 };
1871
AvahiSServiceBrowser *sb = NULL;
1876
int exitcode = EXIT_SUCCESS;
1877
char *interfaces_to_take_down = NULL;
1878
size_t interfaces_to_take_down_size = 0;
1879
char run_tempdir[] = "/run/tmp/mandosXXXXXX";
1880
char old_tempdir[] = "/tmp/mandosXXXXXX";
1881
char *tempdir = NULL;
1882
AvahiIfIndex if_index = AVAHI_IF_UNSPEC;
1883
const char *seckey = PATHDIR "/" SECKEY;
1884
const char *pubkey = PATHDIR "/" PUBKEY;
1885
char *interfaces_hooks = NULL;
1887
bool gnutls_initialized = false;
1888
bool gpgme_initialized = false;
1890
double retry_interval = 10; /* 10s between trying a server and
1891
retrying the same server again */
1893
struct sigaction old_sigterm_action = { .sa_handler = SIG_DFL };
1894
struct sigaction sigterm_action = { .sa_handler = handle_sigterm };
1899
/* Lower any group privileges we might have, just to be safe */
1903
perror_plus("setgid");
1906
/* Lower user privileges (temporarily) */
1910
perror_plus("seteuid");
1918
struct argp_option options[] = {
1919
{ .name = "debug", .key = 128,
1920
.doc = "Debug mode", .group = 3 },
1921
{ .name = "connect", .key = 'c',
1922
.arg = "ADDRESS:PORT",
1923
.doc = "Connect directly to a specific Mandos server",
1925
{ .name = "interface", .key = 'i',
1927
.doc = "Network interface that will be used to search for"
1930
{ .name = "seckey", .key = 's',
1932
.doc = "OpenPGP secret key file base name",
1934
{ .name = "pubkey", .key = 'p',
1936
.doc = "OpenPGP public key file base name",
1938
{ .name = "dh-bits", .key = 129,
1940
.doc = "Bit length of the prime number used in the"
1941
" Diffie-Hellman key exchange",
1943
{ .name = "priority", .key = 130,
1945
.doc = "GnuTLS priority string for the TLS handshake",
1947
{ .name = "delay", .key = 131,
1949
.doc = "Maximum delay to wait for interface startup",
1951
{ .name = "retry", .key = 132,
1953
.doc = "Retry interval used when denied by the Mandos server",
1955
{ .name = "network-hook-dir", .key = 133,
1957
.doc = "Directory where network hooks are located",
1960
* These reproduce what we would get without ARGP_NO_HELP
1962
{ .name = "help", .key = '?',
1963
.doc = "Give this help list", .group = -1 },
1964
{ .name = "usage", .key = -3,
1965
.doc = "Give a short usage message", .group = -1 },
1966
{ .name = "version", .key = 'V',
1967
.doc = "Print program version", .group = -1 },
1971
error_t parse_opt(int key, char *arg,
1972
struct argp_state *state){
1975
case 128: /* --debug */
1978
case 'c': /* --connect */
1981
case 'i': /* --interface */
1982
ret_errno = argz_add_sep(&mc.interfaces, &mc.interfaces_size,
1985
argp_error(state, "%s", strerror(ret_errno));
1988
case 's': /* --seckey */
1991
case 'p': /* --pubkey */
1994
case 129: /* --dh-bits */
1996
tmpmax = strtoimax(arg, &tmp, 10);
1997
if(errno != 0 or tmp == arg or *tmp != '\0'
1998
or tmpmax != (typeof(mc.dh_bits))tmpmax){
1999
argp_error(state, "Bad number of DH bits");
2001
mc.dh_bits = (typeof(mc.dh_bits))tmpmax;
2003
case 130: /* --priority */
2006
case 131: /* --delay */
2008
delay = strtof(arg, &tmp);
2009
if(errno != 0 or tmp == arg or *tmp != '\0'){
2010
argp_error(state, "Bad delay");
2012
case 132: /* --retry */
2014
retry_interval = strtod(arg, &tmp);
2015
if(errno != 0 or tmp == arg or *tmp != '\0'
2016
or (retry_interval * 1000) > INT_MAX
2017
or retry_interval < 0){
2018
argp_error(state, "Bad retry interval");
2021
case 133: /* --network-hook-dir */
2025
* These reproduce what we would get without ARGP_NO_HELP
2027
case '?': /* --help */
2028
argp_state_help(state, state->out_stream,
2029
(ARGP_HELP_STD_HELP | ARGP_HELP_EXIT_ERR)
2030
& ~(unsigned int)ARGP_HELP_EXIT_OK);
2031
case -3: /* --usage */
2032
argp_state_help(state, state->out_stream,
2033
ARGP_HELP_USAGE | ARGP_HELP_EXIT_ERR);
2034
case 'V': /* --version */
2035
fprintf_plus(state->out_stream, "%s\n", argp_program_version);
2036
exit(argp_err_exit_status);
2039
return ARGP_ERR_UNKNOWN;
2044
struct argp argp = { .options = options, .parser = parse_opt,
2046
.doc = "Mandos client -- Get and decrypt"
2047
" passwords from a Mandos server" };
2048
ret = argp_parse(&argp, argc, argv,
2049
ARGP_IN_ORDER | ARGP_NO_HELP, 0, NULL);
2056
perror_plus("argp_parse");
2057
exitcode = EX_OSERR;
2060
exitcode = EX_USAGE;
2066
/* Work around Debian bug #633582:
2067
<http://bugs.debian.org/633582> */
2069
/* Re-raise privileges */
2070
ret_errno = raise_privileges();
2073
perror_plus("Failed to raise privileges");
2077
if(strcmp(seckey, PATHDIR "/" SECKEY) == 0){
2078
int seckey_fd = open(seckey, O_RDONLY);
2079
if(seckey_fd == -1){
2080
perror_plus("open");
2082
ret = (int)TEMP_FAILURE_RETRY(fstat(seckey_fd, &st));
2084
perror_plus("fstat");
2086
if(S_ISREG(st.st_mode)
2087
and st.st_uid == 0 and st.st_gid == 0){
2088
ret = fchown(seckey_fd, uid, gid);
2090
perror_plus("fchown");
2094
TEMP_FAILURE_RETRY(close(seckey_fd));
2098
if(strcmp(pubkey, PATHDIR "/" PUBKEY) == 0){
2099
int pubkey_fd = open(pubkey, O_RDONLY);
2100
if(pubkey_fd == -1){
2101
perror_plus("open");
2103
ret = (int)TEMP_FAILURE_RETRY(fstat(pubkey_fd, &st));
2105
perror_plus("fstat");
2107
if(S_ISREG(st.st_mode)
2108
and st.st_uid == 0 and st.st_gid == 0){
2109
ret = fchown(pubkey_fd, uid, gid);
2111
perror_plus("fchown");
2115
TEMP_FAILURE_RETRY(close(pubkey_fd));
2119
/* Lower privileges */
2120
ret_errno = lower_privileges();
2123
perror_plus("Failed to lower privileges");
2128
/* Remove invalid interface names (except "none") */
2130
char *interface = NULL;
2131
while((interface = argz_next(mc.interfaces, mc.interfaces_size,
2133
if(strcmp(interface, "none") != 0
2134
and if_nametoindex(interface) == 0){
2135
if(interface[0] != '\0'){
2136
fprintf_plus(stderr, "Not using nonexisting interface"
2137
" \"%s\"\n", interface);
2139
argz_delete(&mc.interfaces, &mc.interfaces_size, interface);
2145
/* Run network hooks */
2147
if(mc.interfaces != NULL){
2148
interfaces_hooks = malloc(mc.interfaces_size);
2149
if(interfaces_hooks == NULL){
2150
perror_plus("malloc");
2153
memcpy(interfaces_hooks, mc.interfaces, mc.interfaces_size);
2154
argz_stringify(interfaces_hooks, mc.interfaces_size, (int)',');
2156
run_network_hooks("start", interfaces_hooks != NULL ?
2157
interfaces_hooks : "", delay);
2161
avahi_set_log_function(empty_log);
2164
/* Initialize Avahi early so avahi_simple_poll_quit() can be called
2165
from the signal handler */
2166
/* Initialize the pseudo-RNG for Avahi */
2167
srand((unsigned int) time(NULL));
2168
simple_poll = avahi_simple_poll_new();
2169
if(simple_poll == NULL){
2170
fprintf_plus(stderr,
2171
"Avahi: Failed to create simple poll object.\n");
2172
exitcode = EX_UNAVAILABLE;
2176
sigemptyset(&sigterm_action.sa_mask);
2177
ret = sigaddset(&sigterm_action.sa_mask, SIGINT);
2179
perror_plus("sigaddset");
2180
exitcode = EX_OSERR;
2183
ret = sigaddset(&sigterm_action.sa_mask, SIGHUP);
2185
perror_plus("sigaddset");
2186
exitcode = EX_OSERR;
2189
ret = sigaddset(&sigterm_action.sa_mask, SIGTERM);
2191
perror_plus("sigaddset");
2192
exitcode = EX_OSERR;
2195
/* Need to check if the handler is SIG_IGN before handling:
2196
| [[info:libc:Initial Signal Actions]] |
2197
| [[info:libc:Basic Signal Handling]] |
2199
ret = sigaction(SIGINT, NULL, &old_sigterm_action);
2201
perror_plus("sigaction");
2204
if(old_sigterm_action.sa_handler != SIG_IGN){
2205
ret = sigaction(SIGINT, &sigterm_action, NULL);
2207
perror_plus("sigaction");
2208
exitcode = EX_OSERR;
2212
ret = sigaction(SIGHUP, NULL, &old_sigterm_action);
2214
perror_plus("sigaction");
2217
if(old_sigterm_action.sa_handler != SIG_IGN){
2218
ret = sigaction(SIGHUP, &sigterm_action, NULL);
2220
perror_plus("sigaction");
2221
exitcode = EX_OSERR;
2225
ret = sigaction(SIGTERM, NULL, &old_sigterm_action);
2227
perror_plus("sigaction");
2230
if(old_sigterm_action.sa_handler != SIG_IGN){
2231
ret = sigaction(SIGTERM, &sigterm_action, NULL);
2233
perror_plus("sigaction");
2234
exitcode = EX_OSERR;
2239
/* If no interfaces were specified, make a list */
2240
if(mc.interfaces == NULL){
2241
struct dirent **direntries;
2242
/* Look for any good interfaces */
2243
ret = scandir(sys_class_net, &direntries, good_interface,
2246
/* Add all found interfaces to interfaces list */
2247
for(int i = 0; i < ret; ++i){
2248
ret_errno = argz_add(&mc.interfaces, &mc.interfaces_size,
2249
direntries[i]->d_name);
2252
perror_plus("argz_add");
2256
fprintf_plus(stderr, "Will use interface \"%s\"\n",
2257
direntries[i]->d_name);
2263
fprintf_plus(stderr, "Could not find a network interface\n");
2264
exitcode = EXIT_FAILURE;
2269
/* Bring up interfaces which are down, and remove any "none"s */
2271
char *interface = NULL;
2272
while((interface = argz_next(mc.interfaces, mc.interfaces_size,
2274
/* If interface name is "none", stop bringing up interfaces.
2275
Also remove all instances of "none" from the list */
2276
if(strcmp(interface, "none") == 0){
2277
argz_delete(&mc.interfaces, &mc.interfaces_size,
2280
while((interface = argz_next(mc.interfaces,
2281
mc.interfaces_size, interface))){
2282
if(strcmp(interface, "none") == 0){
2283
argz_delete(&mc.interfaces, &mc.interfaces_size,
2290
bool interface_was_up = interface_is_up(interface);
2291
errno = bring_up_interface(interface, delay);
2292
if(not interface_was_up){
2294
perror_plus("Failed to bring up interface");
2296
errno = argz_add(&interfaces_to_take_down,
2297
&interfaces_to_take_down_size,
2300
perror_plus("argz_add");
2305
if(debug and (interfaces_to_take_down == NULL)){
2306
fprintf_plus(stderr, "No interfaces were brought up\n");
2310
/* If we only got one interface, explicitly use only that one */
2311
if(argz_count(mc.interfaces, mc.interfaces_size) == 1){
2313
fprintf_plus(stderr, "Using only interface \"%s\"\n",
2316
if_index = (AvahiIfIndex)if_nametoindex(mc.interfaces);
2323
ret = init_gnutls_global(pubkey, seckey, &mc);
2325
fprintf_plus(stderr, "init_gnutls_global failed\n");
2326
exitcode = EX_UNAVAILABLE;
2329
gnutls_initialized = true;
2336
/* Try /run/tmp before /tmp */
2337
tempdir = mkdtemp(run_tempdir);
2338
if(tempdir == NULL and errno == ENOENT){
2340
fprintf_plus(stderr, "Tempdir %s did not work, trying %s\n",
2341
run_tempdir, old_tempdir);
2343
tempdir = mkdtemp(old_tempdir);
2345
if(tempdir == NULL){
2346
perror_plus("mkdtemp");
2354
if(not init_gpgme(pubkey, seckey, tempdir, &mc)){
2355
fprintf_plus(stderr, "init_gpgme failed\n");
2356
exitcode = EX_UNAVAILABLE;
2359
gpgme_initialized = true;
2366
if(connect_to != NULL){
2367
/* Connect directly, do not use Zeroconf */
2368
/* (Mainly meant for debugging) */
2369
char *address = strrchr(connect_to, ':');
2371
if(address == NULL){
2372
fprintf_plus(stderr, "No colon in address\n");
2373
exitcode = EX_USAGE;
2383
tmpmax = strtoimax(address+1, &tmp, 10);
2384
if(errno != 0 or tmp == address+1 or *tmp != '\0'
2385
or tmpmax != (in_port_t)tmpmax){
2386
fprintf_plus(stderr, "Bad port number\n");
2387
exitcode = EX_USAGE;
2395
port = (in_port_t)tmpmax;
2397
/* Colon in address indicates IPv6 */
2399
if(strchr(connect_to, ':') != NULL){
2401
/* Accept [] around IPv6 address - see RFC 5952 */
2402
if(connect_to[0] == '[' and address[-1] == ']')
2410
address = connect_to;
2416
while(not quit_now){
2417
ret = start_mandos_communication(address, port, if_index, af,
2419
if(quit_now or ret == 0){
2423
fprintf_plus(stderr, "Retrying in %d seconds\n",
2424
(int)retry_interval);
2426
sleep((unsigned int)retry_interval);
2430
exitcode = EXIT_SUCCESS;
2441
AvahiServerConfig config;
2442
/* Do not publish any local Zeroconf records */
2443
avahi_server_config_init(&config);
2444
config.publish_hinfo = 0;
2445
config.publish_addresses = 0;
2446
config.publish_workstation = 0;
2447
config.publish_domain = 0;
2449
/* Allocate a new server */
2450
mc.server = avahi_server_new(avahi_simple_poll_get(simple_poll),
2451
&config, NULL, NULL, &ret_errno);
2453
/* Free the Avahi configuration data */
2454
avahi_server_config_free(&config);
2457
/* Check if creating the Avahi server object succeeded */
2458
if(mc.server == NULL){
2459
fprintf_plus(stderr, "Failed to create Avahi server: %s\n",
2460
avahi_strerror(ret_errno));
2461
exitcode = EX_UNAVAILABLE;
2469
/* Create the Avahi service browser */
2470
sb = avahi_s_service_browser_new(mc.server, if_index,
2471
AVAHI_PROTO_UNSPEC, "_mandos._tcp",
2472
NULL, 0, browse_callback,
2475
fprintf_plus(stderr, "Failed to create service browser: %s\n",
2476
avahi_strerror(avahi_server_errno(mc.server)));
2477
exitcode = EX_UNAVAILABLE;
2485
/* Run the main loop */
2488
fprintf_plus(stderr, "Starting Avahi loop search\n");
2491
ret = avahi_loop_with_timeout(simple_poll,
2492
(int)(retry_interval * 1000), &mc);
2494
fprintf_plus(stderr, "avahi_loop_with_timeout exited %s\n",
2495
(ret == 0) ? "successfully" : "with error");
2501
fprintf_plus(stderr, "%s exiting\n", argv[0]);
2504
/* Cleanup things */
2505
free(mc.interfaces);
2508
avahi_s_service_browser_free(sb);
2510
if(mc.server != NULL)
2511
avahi_server_free(mc.server);
2513
if(simple_poll != NULL)
2514
avahi_simple_poll_free(simple_poll);
2516
if(gnutls_initialized){
2517
gnutls_certificate_free_credentials(mc.cred);
2518
gnutls_global_deinit();
2519
gnutls_dh_params_deinit(mc.dh_params);
2522
if(gpgme_initialized){
2523
gpgme_release(mc.ctx);
2526
/* Cleans up the circular linked list of Mandos servers the client
2528
if(mc.current_server != NULL){
2529
mc.current_server->prev->next = NULL;
2530
while(mc.current_server != NULL){
2531
server *next = mc.current_server->next;
2532
free(mc.current_server);
2533
mc.current_server = next;
2537
/* Re-raise privileges */
2539
ret_errno = raise_privileges();
2541
perror_plus("Failed to raise privileges");
2544
/* Run network hooks */
2545
run_network_hooks("stop", interfaces_hooks != NULL ?
2546
interfaces_hooks : "", delay);
2548
/* Take down the network interfaces which were brought up */
2550
char *interface = NULL;
2551
while((interface=argz_next(interfaces_to_take_down,
2552
interfaces_to_take_down_size,
2554
ret_errno = take_down_interface(interface);
2557
perror_plus("Failed to take down interface");
2560
if(debug and (interfaces_to_take_down == NULL)){
2561
fprintf_plus(stderr, "No interfaces needed to be taken"
2567
ret_errno = lower_privileges_permanently();
2569
perror_plus("Failed to lower privileges permanently");
2573
free(interfaces_to_take_down);
2574
free(interfaces_hooks);
2576
/* Removes the GPGME temp directory and all files inside */
2577
if(tempdir != NULL){
2578
struct dirent **direntries = NULL;
2579
struct dirent *direntry = NULL;
2580
int numentries = scandir(tempdir, &direntries, notdotentries,
2583
for(int i = 0; i < numentries; i++){
2584
direntry = direntries[i];
2585
char *fullname = NULL;
2586
ret = asprintf(&fullname, "%s/%s", tempdir,
2589
perror_plus("asprintf");
2592
ret = remove(fullname);
2594
fprintf_plus(stderr, "remove(\"%s\"): %s\n", fullname,
2601
/* need to clean even if 0 because man page doesn't specify */
2603
if(numentries == -1){
2604
perror_plus("scandir");
2606
ret = rmdir(tempdir);
2607
if(ret == -1 and errno != ENOENT){
2608
perror_plus("rmdir");
2613
sigemptyset(&old_sigterm_action.sa_mask);
2614
old_sigterm_action.sa_handler = SIG_DFL;
2615
ret = (int)TEMP_FAILURE_RETRY(sigaction(signal_received,
2616
&old_sigterm_action,
2619
perror_plus("sigaction");
2622
ret = raise(signal_received);
2623
} while(ret != 0 and errno == EINTR);
2625
perror_plus("raise");
2628
TEMP_FAILURE_RETRY(pause());