256
124
self.rename_count = 0
257
125
self.max_renames = max_renames
258
self.protocol = protocol
259
self.group = None # our entry group
262
self.entry_group_state_changed_match = None
263
126
def rename(self):
264
127
"""Derived from the Avahi example code"""
265
128
if self.rename_count >= self.max_renames:
266
logger.critical("No suitable Zeroconf service name found"
267
" after %i retries, exiting.",
129
logger.critical(u"No suitable Zeroconf service name found"
130
u" after %i retries, exiting.",
268
131
self.rename_count)
269
132
raise AvahiServiceError("Too many renames")
270
self.name = unicode(self.server
271
.GetAlternativeServiceName(self.name))
272
logger.info("Changing Zeroconf service name to %r ...",
133
self.name = server.GetAlternativeServiceName(self.name)
134
logger.info(u"Changing Zeroconf service name to %r ...",
136
syslogger.setFormatter(logging.Formatter
137
('Mandos (%s): %%(levelname)s:'
138
' %%(message)s' % self.name))
277
except dbus.exceptions.DBusException as error:
278
logger.critical("DBusException: %s", error)
281
141
self.rename_count += 1
282
142
def remove(self):
283
143
"""Derived from the Avahi example code"""
284
if self.entry_group_state_changed_match is not None:
285
self.entry_group_state_changed_match.remove()
286
self.entry_group_state_changed_match = None
287
if self.group is not None:
144
if group is not None:
290
147
"""Derived from the Avahi example code"""
292
if self.group is None:
293
self.group = dbus.Interface(
294
self.bus.get_object(avahi.DBUS_NAME,
295
self.server.EntryGroupNew()),
296
avahi.DBUS_INTERFACE_ENTRY_GROUP)
297
self.entry_group_state_changed_match = (
298
self.group.connect_to_signal(
299
'StateChanged', self.entry_group_state_changed))
300
logger.debug("Adding Zeroconf service '%s' of type '%s' ...",
301
self.name, self.type)
302
self.group.AddService(
305
dbus.UInt32(0), # flags
306
self.name, self.type,
307
self.domain, self.host,
308
dbus.UInt16(self.port),
309
avahi.string_array_to_txt_array(self.TXT))
311
def entry_group_state_changed(self, state, error):
312
"""Derived from the Avahi example code"""
313
logger.debug("Avahi entry group state change: %i", state)
315
if state == avahi.ENTRY_GROUP_ESTABLISHED:
316
logger.debug("Zeroconf service established.")
317
elif state == avahi.ENTRY_GROUP_COLLISION:
318
logger.info("Zeroconf service name collision.")
320
elif state == avahi.ENTRY_GROUP_FAILURE:
321
logger.critical("Avahi: Error in group state changed %s",
323
raise AvahiGroupError("State changed: %s"
326
"""Derived from the Avahi example code"""
327
if self.group is not None:
330
except (dbus.exceptions.UnknownMethodException,
331
dbus.exceptions.DBusException):
335
def server_state_changed(self, state, error=None):
336
"""Derived from the Avahi example code"""
337
logger.debug("Avahi server state change: %i", state)
338
bad_states = { avahi.SERVER_INVALID:
339
"Zeroconf server invalid",
340
avahi.SERVER_REGISTERING: None,
341
avahi.SERVER_COLLISION:
342
"Zeroconf server name collision",
343
avahi.SERVER_FAILURE:
344
"Zeroconf server failure" }
345
if state in bad_states:
346
if bad_states[state] is not None:
348
logger.error(bad_states[state])
350
logger.error(bad_states[state] + ": %r", error)
352
elif state == avahi.SERVER_RUNNING:
356
logger.debug("Unknown state: %r", state)
358
logger.debug("Unknown state: %r: %r", state, error)
360
"""Derived from the Avahi example code"""
361
if self.server is None:
362
self.server = dbus.Interface(
363
self.bus.get_object(avahi.DBUS_NAME,
364
avahi.DBUS_PATH_SERVER,
365
follow_name_owner_changes=True),
366
avahi.DBUS_INTERFACE_SERVER)
367
self.server.connect_to_signal("StateChanged",
368
self.server_state_changed)
369
self.server_state_changed(self.server.GetState())
371
class AvahiServiceToSyslog(AvahiService):
373
"""Add the new name to the syslog messages"""
374
ret = AvahiService.rename(self)
375
syslogger.setFormatter(logging.Formatter
376
('Mandos (%s) [%%(process)d]:'
377
' %%(levelname)s: %%(message)s'
381
def timedelta_to_milliseconds(td):
382
"Convert a datetime.timedelta() to milliseconds"
383
return ((td.days * 24 * 60 * 60 * 1000)
384
+ (td.seconds * 1000)
385
+ (td.microseconds // 1000))
387
class Client(object):
150
group = dbus.Interface(bus.get_object
152
server.EntryGroupNew()),
153
avahi.DBUS_INTERFACE_ENTRY_GROUP)
154
group.connect_to_signal('StateChanged',
155
entry_group_state_changed)
156
logger.debug(u"Adding Zeroconf service '%s' of type '%s' ...",
157
service.name, service.type)
159
self.interface, # interface
160
avahi.PROTO_INET6, # protocol
161
dbus.UInt32(0), # flags
162
self.name, self.type,
163
self.domain, self.host,
164
dbus.UInt16(self.port),
165
avahi.string_array_to_txt_array(self.TXT))
168
# From the Avahi example code:
169
group = None # our entry group
170
# End of Avahi example code
173
def _datetime_to_dbus_struct(dt, variant_level=0):
174
"""Convert a UTC datetime.datetime() to a D-Bus struct.
175
The format is special to this application, since we could not find
176
any other standard way."""
177
return dbus.Struct((dbus.Int16(dt.year),
181
dbus.Byte(dt.minute),
182
dbus.Byte(dt.second),
183
dbus.UInt32(dt.microsecond)),
185
variant_level=variant_level)
188
class Client(dbus.service.Object):
388
189
"""A representation of a client host served by this server.
391
approved: bool(); 'None' if not yet approved/disapproved
392
approval_delay: datetime.timedelta(); Time to wait for approval
393
approval_duration: datetime.timedelta(); Duration of one approval
191
name: string; from the config file, used in log messages
192
fingerprint: string (40 or 32 hexadecimal digits); used to
193
uniquely identify the client
194
secret: bytestring; sent verbatim (over TLS) to client
195
host: string; available for use by the checker command
196
created: datetime.datetime(); (UTC) object creation
197
last_started: datetime.datetime(); (UTC)
199
last_checked_ok: datetime.datetime(); (UTC) or None
200
timeout: datetime.timedelta(); How long from last_checked_ok
201
until this client is invalid
202
interval: datetime.timedelta(); How often to start a new checker
203
stop_hook: If set, called by stop() as stop_hook(self)
394
204
checker: subprocess.Popen(); a running checker process used
395
205
to see if the client lives.
396
206
'None' if no process is running.
397
checker_callback_tag: a gobject event source tag, or None
398
checker_command: string; External command which is run to check
399
if client lives. %() expansions are done at
207
checker_initiator_tag: a gobject event source tag, or None
208
stop_initiator_tag: - '' -
209
checker_callback_tag: - '' -
210
checker_command: string; External command which is run to check if
211
client lives. %() expansions are done at
400
212
runtime with vars(self) as dict, so that for
401
213
instance %(name)s can be used in the command.
402
checker_initiator_tag: a gobject event source tag, or None
403
created: datetime.datetime(); (UTC) object creation
404
client_structure: Object describing what attributes a client has
405
and is used for storing the client at exit
406
current_checker_command: string; current running checker_command
407
disable_initiator_tag: a gobject event source tag, or None
409
fingerprint: string (40 or 32 hexadecimal digits); used to
410
uniquely identify the client
411
host: string; available for use by the checker command
412
interval: datetime.timedelta(); How often to start a new checker
413
last_approval_request: datetime.datetime(); (UTC) or None
414
last_checked_ok: datetime.datetime(); (UTC) or None
415
last_checker_status: integer between 0 and 255 reflecting exit
416
status of last checker. -1 reflects crashed
418
last_enabled: datetime.datetime(); (UTC) or None
419
name: string; from the config file, used in log messages and
421
secret: bytestring; sent verbatim (over TLS) to client
422
timeout: datetime.timedelta(); How long from last_checked_ok
423
until this client is disabled
424
extended_timeout: extra long timeout when password has been sent
425
runtime_expansions: Allowed attributes for runtime expansion.
426
expires: datetime.datetime(); time (UTC) when a client will be
214
dbus_object_path: dbus.ObjectPath
216
_timeout: Real variable for 'timeout'
217
_interval: Real variable for 'interval'
218
_timeout_milliseconds: Used when calling gobject.timeout_add()
219
_interval_milliseconds: - '' -
430
runtime_expansions = ("approval_delay", "approval_duration",
431
"created", "enabled", "fingerprint",
432
"host", "interval", "last_checked_ok",
433
"last_enabled", "name", "timeout")
434
client_defaults = { "timeout": "5m",
435
"extended_timeout": "15m",
437
"checker": "fping -q -- %%(host)s",
439
"approval_delay": "0s",
440
"approval_duration": "1s",
441
"approved_by_default": "True",
445
def timeout_milliseconds(self):
446
"Return the 'timeout' attribute in milliseconds"
447
return timedelta_to_milliseconds(self.timeout)
449
def extended_timeout_milliseconds(self):
450
"Return the 'extended_timeout' attribute in milliseconds"
451
return timedelta_to_milliseconds(self.extended_timeout)
453
def interval_milliseconds(self):
454
"Return the 'interval' attribute in milliseconds"
455
return timedelta_to_milliseconds(self.interval)
457
def approval_delay_milliseconds(self):
458
return timedelta_to_milliseconds(self.approval_delay)
461
def config_parser(config):
462
""" Construct a new dict of client settings of this form:
463
{ client_name: {setting_name: value, ...}, ...}
464
with exceptions for any special settings as defined above"""
466
for client_name in config.sections():
467
section = dict(config.items(client_name))
468
client = settings[client_name] = {}
470
client["host"] = section["host"]
471
# Reformat values from string types to Python types
472
client["approved_by_default"] = config.getboolean(
473
client_name, "approved_by_default")
474
client["enabled"] = config.getboolean(client_name, "enabled")
476
client["fingerprint"] = (section["fingerprint"].upper()
478
if "secret" in section:
479
client["secret"] = section["secret"].decode("base64")
480
elif "secfile" in section:
481
with open(os.path.expanduser(os.path.expandvars
482
(section["secfile"])),
484
client["secret"] = secfile.read()
486
raise TypeError("No secret or secfile for section %s"
488
client["timeout"] = string_to_delta(section["timeout"])
489
client["extended_timeout"] = string_to_delta(
490
section["extended_timeout"])
491
client["interval"] = string_to_delta(section["interval"])
492
client["approval_delay"] = string_to_delta(
493
section["approval_delay"])
494
client["approval_duration"] = string_to_delta(
495
section["approval_duration"])
496
client["checker_command"] = section["checker"]
497
client["last_approval_request"] = None
498
client["last_checked_ok"] = None
499
client["last_checker_status"] = None
500
if client["enabled"]:
501
client["last_enabled"] = datetime.datetime.utcnow()
502
client["expires"] = (datetime.datetime.utcnow()
505
client["last_enabled"] = None
506
client["expires"] = None
511
def __init__(self, settings, name = None):
221
def _set_timeout(self, timeout):
222
"Setter function for the 'timeout' attribute"
223
self._timeout = timeout
224
self._timeout_milliseconds = ((self.timeout.days
225
* 24 * 60 * 60 * 1000)
226
+ (self.timeout.seconds * 1000)
227
+ (self.timeout.microseconds
230
self.PropertyChanged(dbus.String(u"timeout"),
231
(dbus.UInt64(self._timeout_milliseconds,
233
timeout = property(lambda self: self._timeout, _set_timeout)
236
def _set_interval(self, interval):
237
"Setter function for the 'interval' attribute"
238
self._interval = interval
239
self._interval_milliseconds = ((self.interval.days
240
* 24 * 60 * 60 * 1000)
241
+ (self.interval.seconds
243
+ (self.interval.microseconds
246
self.PropertyChanged(dbus.String(u"interval"),
247
(dbus.UInt64(self._interval_milliseconds,
249
interval = property(lambda self: self._interval, _set_interval)
252
def __init__(self, name = None, stop_hook=None, config=None):
512
253
"""Note: the 'checker' key in 'config' sets the
513
254
'checker_command' attribute and *not* the 'checker'
256
self.dbus_object_path = (dbus.ObjectPath
258
+ name.replace(".", "_")))
259
dbus.service.Object.__init__(self, bus,
260
self.dbus_object_path)
516
# adding all client settings
517
for setting, value in settings.iteritems():
518
setattr(self, setting, value)
520
logger.debug("Creating client %r", self.name)
264
logger.debug(u"Creating client %r", self.name)
521
265
# Uppercase and remove spaces from fingerprint for later
522
266
# comparison purposes with return value from the fingerprint()
524
logger.debug(" Fingerprint: %s", self.fingerprint)
525
self.created = settings.get("created", datetime.datetime.utcnow())
527
# attributes specific for this server instance
268
self.fingerprint = (config["fingerprint"].upper()
270
logger.debug(u" Fingerprint: %s", self.fingerprint)
271
if "secret" in config:
272
self.secret = config["secret"].decode(u"base64")
273
elif "secfile" in config:
274
with closing(open(os.path.expanduser
276
(config["secfile"])))) as secfile:
277
self.secret = secfile.read()
279
raise TypeError(u"No secret or secfile for client %s"
281
self.host = config.get("host", "")
282
self.created = datetime.datetime.utcnow()
284
self.last_started = None
285
self.last_checked_ok = None
286
self.timeout = string_to_delta(config["timeout"])
287
self.interval = string_to_delta(config["interval"])
288
self.stop_hook = stop_hook
528
289
self.checker = None
529
290
self.checker_initiator_tag = None
530
self.disable_initiator_tag = None
291
self.stop_initiator_tag = None
531
292
self.checker_callback_tag = None
532
self.current_checker_command = None
534
self.approvals_pending = 0
535
self.changedstate = (multiprocessing_manager
536
.Condition(multiprocessing_manager
538
self.client_structure = [attr for attr in
539
self.__dict__.iterkeys()
540
if not attr.startswith("_")]
541
self.client_structure.append("client_structure")
543
for name, t in inspect.getmembers(type(self),
547
if not name.startswith("_"):
548
self.client_structure.append(name)
550
# Send notice to process children that client state has changed
551
def send_changedstate(self):
552
with self.changedstate:
553
self.changedstate.notify_all()
293
self.checker_command = config["checker"]
556
296
"""Start this client's checker and timeout hooks"""
557
if getattr(self, "enabled", False):
560
self.send_changedstate()
561
self.expires = datetime.datetime.utcnow() + self.timeout
563
self.last_enabled = datetime.datetime.utcnow()
566
def disable(self, quiet=True):
567
"""Disable this client."""
568
if not getattr(self, "enabled", False):
571
self.send_changedstate()
573
logger.info("Disabling client %s", self.name)
574
if getattr(self, "disable_initiator_tag", False):
575
gobject.source_remove(self.disable_initiator_tag)
576
self.disable_initiator_tag = None
578
if getattr(self, "checker_initiator_tag", False):
579
gobject.source_remove(self.checker_initiator_tag)
580
self.checker_initiator_tag = None
583
# Do not run this again if called by a gobject.timeout_add
589
def init_checker(self):
297
self.last_started = datetime.datetime.utcnow()
590
298
# Schedule a new checker to be started an 'interval' from now,
591
299
# and every interval from then on.
592
300
self.checker_initiator_tag = (gobject.timeout_add
593
(self.interval_milliseconds(),
301
(self._interval_milliseconds,
594
302
self.start_checker))
595
# Schedule a disable() when 'timeout' has passed
596
self.disable_initiator_tag = (gobject.timeout_add
597
(self.timeout_milliseconds(),
599
303
# Also start a new checker *right now*.
600
304
self.start_checker()
305
# Schedule a stop() when 'timeout' has passed
306
self.stop_initiator_tag = (gobject.timeout_add
307
(self._timeout_milliseconds,
311
self.PropertyChanged(dbus.String(u"started"),
312
dbus.Boolean(True, variant_level=1))
313
self.PropertyChanged(dbus.String(u"last_started"),
314
(_datetime_to_dbus_struct
315
(self.last_started, variant_level=1)))
318
"""Stop this client."""
319
if not getattr(self, "started", False):
321
logger.info(u"Stopping client %s", self.name)
322
if getattr(self, "stop_initiator_tag", False):
323
gobject.source_remove(self.stop_initiator_tag)
324
self.stop_initiator_tag = None
325
if getattr(self, "checker_initiator_tag", False):
326
gobject.source_remove(self.checker_initiator_tag)
327
self.checker_initiator_tag = None
333
self.PropertyChanged(dbus.String(u"started"),
334
dbus.Boolean(False, variant_level=1))
335
# Do not run this again if called by a gobject.timeout_add
339
self.stop_hook = None
602
342
def checker_callback(self, pid, condition, command):
603
343
"""The checker has completed, so take appropriate actions."""
604
344
self.checker_callback_tag = None
605
345
self.checker = None
606
if os.WIFEXITED(condition):
607
self.last_checker_status = os.WEXITSTATUS(condition)
608
if self.last_checker_status == 0:
609
logger.info("Checker for %(name)s succeeded",
613
logger.info("Checker for %(name)s failed",
616
self.last_checker_status = -1
617
logger.warning("Checker for %(name)s crashed?",
347
self.PropertyChanged(dbus.String(u"checker_running"),
348
dbus.Boolean(False, variant_level=1))
349
if (os.WIFEXITED(condition)
350
and (os.WEXITSTATUS(condition) == 0)):
351
logger.info(u"Checker for %(name)s succeeded",
354
self.CheckerCompleted(dbus.Boolean(True),
355
dbus.UInt16(condition),
356
dbus.String(command))
358
elif not os.WIFEXITED(condition):
359
logger.warning(u"Checker for %(name)s crashed?",
362
self.CheckerCompleted(dbus.Boolean(False),
363
dbus.UInt16(condition),
364
dbus.String(command))
366
logger.info(u"Checker for %(name)s failed",
369
self.CheckerCompleted(dbus.Boolean(False),
370
dbus.UInt16(condition),
371
dbus.String(command))
620
def checked_ok(self, timeout=None):
373
def bump_timeout(self):
621
374
"""Bump up the timeout for this client.
623
375
This should only be called when the client has been seen,
627
timeout = self.timeout
628
378
self.last_checked_ok = datetime.datetime.utcnow()
629
if self.disable_initiator_tag is not None:
630
gobject.source_remove(self.disable_initiator_tag)
631
if getattr(self, "enabled", False):
632
self.disable_initiator_tag = (gobject.timeout_add
633
(timedelta_to_milliseconds
634
(timeout), self.disable))
635
self.expires = datetime.datetime.utcnow() + timeout
637
def need_approval(self):
638
self.last_approval_request = datetime.datetime.utcnow()
379
gobject.source_remove(self.stop_initiator_tag)
380
self.stop_initiator_tag = (gobject.timeout_add
381
(self._timeout_milliseconds,
383
self.PropertyChanged(dbus.String(u"last_checked_ok"),
384
(_datetime_to_dbus_struct
385
(self.last_checked_ok,
640
388
def start_checker(self):
641
389
"""Start a new checker subprocess if one is not running.
643
390
If a checker already exists, leave it running and do
645
392
# The reason for not killing a running checker is that if we
719
443
self.checker_callback_tag = None
720
444
if getattr(self, "checker", None) is None:
722
logger.debug("Stopping checker for %(name)s", vars(self))
446
logger.debug(u"Stopping checker for %(name)s", vars(self))
724
448
os.kill(self.checker.pid, signal.SIGTERM)
726
450
#if self.checker.poll() is None:
727
451
# os.kill(self.checker.pid, signal.SIGKILL)
728
except OSError as error:
452
except OSError, error:
729
453
if error.errno != errno.ESRCH: # No such process
731
455
self.checker = None
734
def dbus_service_property(dbus_interface, signature="v",
735
access="readwrite", byte_arrays=False):
736
"""Decorators for marking methods of a DBusObjectWithProperties to
737
become properties on the D-Bus.
739
The decorated method will be called with no arguments by "Get"
740
and with one argument by "Set".
742
The parameters, where they are supported, are the same as
743
dbus.service.method, except there is only "signature", since the
744
type from Get() and the type sent to Set() is the same.
746
# Encoding deeply encoded byte arrays is not supported yet by the
747
# "Set" method, so we fail early here:
748
if byte_arrays and signature != "ay":
749
raise ValueError("Byte arrays not supported for non-'ay'"
750
" signature %r" % signature)
752
func._dbus_is_property = True
753
func._dbus_interface = dbus_interface
754
func._dbus_signature = signature
755
func._dbus_access = access
756
func._dbus_name = func.__name__
757
if func._dbus_name.endswith("_dbus_property"):
758
func._dbus_name = func._dbus_name[:-14]
759
func._dbus_get_args_options = {'byte_arrays': byte_arrays }
764
class DBusPropertyException(dbus.exceptions.DBusException):
765
"""A base class for D-Bus property-related exceptions
767
def __unicode__(self):
768
return unicode(str(self))
771
class DBusPropertyAccessException(DBusPropertyException):
772
"""A property's access permissions disallows an operation.
777
class DBusPropertyNotFound(DBusPropertyException):
778
"""An attempt was made to access a non-existing property.
783
class DBusObjectWithProperties(dbus.service.Object):
784
"""A D-Bus object with properties.
786
Classes inheriting from this can use the dbus_service_property
787
decorator to expose methods as D-Bus properties. It exposes the
788
standard Get(), Set(), and GetAll() methods on the D-Bus.
792
def _is_dbus_property(obj):
793
return getattr(obj, "_dbus_is_property", False)
795
def _get_all_dbus_properties(self):
796
"""Returns a generator of (name, attribute) pairs
798
return ((prop.__get__(self)._dbus_name, prop.__get__(self))
799
for cls in self.__class__.__mro__
801
inspect.getmembers(cls, self._is_dbus_property))
803
def _get_dbus_property(self, interface_name, property_name):
804
"""Returns a bound method if one exists which is a D-Bus
805
property with the specified name and interface.
807
for cls in self.__class__.__mro__:
808
for name, value in (inspect.getmembers
809
(cls, self._is_dbus_property)):
810
if (value._dbus_name == property_name
811
and value._dbus_interface == interface_name):
812
return value.__get__(self)
815
raise DBusPropertyNotFound(self.dbus_object_path + ":"
816
+ interface_name + "."
819
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ss",
821
def Get(self, interface_name, property_name):
822
"""Standard D-Bus property Get() method, see D-Bus standard.
824
prop = self._get_dbus_property(interface_name, property_name)
825
if prop._dbus_access == "write":
826
raise DBusPropertyAccessException(property_name)
828
if not hasattr(value, "variant_level"):
830
return type(value)(value, variant_level=value.variant_level+1)
832
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ssv")
833
def Set(self, interface_name, property_name, value):
834
"""Standard D-Bus property Set() method, see D-Bus standard.
836
prop = self._get_dbus_property(interface_name, property_name)
837
if prop._dbus_access == "read":
838
raise DBusPropertyAccessException(property_name)
839
if prop._dbus_get_args_options["byte_arrays"]:
840
# The byte_arrays option is not supported yet on
841
# signatures other than "ay".
842
if prop._dbus_signature != "ay":
844
value = dbus.ByteArray(''.join(unichr(byte)
848
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="s",
849
out_signature="a{sv}")
850
def GetAll(self, interface_name):
851
"""Standard D-Bus property GetAll() method, see D-Bus
854
Note: Will not include properties with access="write".
857
for name, prop in self._get_all_dbus_properties():
859
and interface_name != prop._dbus_interface):
860
# Interface non-empty but did not match
862
# Ignore write-only properties
863
if prop._dbus_access == "write":
866
if not hasattr(value, "variant_level"):
867
properties[name] = value
869
properties[name] = type(value)(value, variant_level=
870
value.variant_level+1)
871
return dbus.Dictionary(properties, signature="sv")
873
@dbus.service.method(dbus.INTROSPECTABLE_IFACE,
875
path_keyword='object_path',
876
connection_keyword='connection')
877
def Introspect(self, object_path, connection):
878
"""Standard D-Bus method, overloaded to insert property tags.
880
xmlstring = dbus.service.Object.Introspect(self, object_path,
883
document = xml.dom.minidom.parseString(xmlstring)
884
def make_tag(document, name, prop):
885
e = document.createElement("property")
886
e.setAttribute("name", name)
887
e.setAttribute("type", prop._dbus_signature)
888
e.setAttribute("access", prop._dbus_access)
890
for if_tag in document.getElementsByTagName("interface"):
891
for tag in (make_tag(document, name, prop)
893
in self._get_all_dbus_properties()
894
if prop._dbus_interface
895
== if_tag.getAttribute("name")):
896
if_tag.appendChild(tag)
897
# Add the names to the return values for the
898
# "org.freedesktop.DBus.Properties" methods
899
if (if_tag.getAttribute("name")
900
== "org.freedesktop.DBus.Properties"):
901
for cn in if_tag.getElementsByTagName("method"):
902
if cn.getAttribute("name") == "Get":
903
for arg in cn.getElementsByTagName("arg"):
904
if (arg.getAttribute("direction")
906
arg.setAttribute("name", "value")
907
elif cn.getAttribute("name") == "GetAll":
908
for arg in cn.getElementsByTagName("arg"):
909
if (arg.getAttribute("direction")
911
arg.setAttribute("name", "props")
912
xmlstring = document.toxml("utf-8")
914
except (AttributeError, xml.dom.DOMException,
915
xml.parsers.expat.ExpatError) as error:
916
logger.error("Failed to override Introspection method",
921
def datetime_to_dbus (dt, variant_level=0):
922
"""Convert a UTC datetime.datetime() to a D-Bus type."""
924
return dbus.String("", variant_level = variant_level)
925
return dbus.String(dt.isoformat(),
926
variant_level=variant_level)
929
class AlternateDBusNamesMetaclass(DBusObjectWithProperties
931
"""Applied to an empty subclass of a D-Bus object, this metaclass
932
will add additional D-Bus attributes matching a certain pattern.
934
def __new__(mcs, name, bases, attr):
935
# Go through all the base classes which could have D-Bus
936
# methods, signals, or properties in them
937
for base in (b for b in bases
938
if issubclass(b, dbus.service.Object)):
939
# Go though all attributes of the base class
940
for attrname, attribute in inspect.getmembers(base):
941
# Ignore non-D-Bus attributes, and D-Bus attributes
942
# with the wrong interface name
943
if (not hasattr(attribute, "_dbus_interface")
944
or not attribute._dbus_interface
945
.startswith("se.recompile.Mandos")):
947
# Create an alternate D-Bus interface name based on
949
alt_interface = (attribute._dbus_interface
950
.replace("se.recompile.Mandos",
951
"se.bsnet.fukt.Mandos"))
952
# Is this a D-Bus signal?
953
if getattr(attribute, "_dbus_is_signal", False):
954
# Extract the original non-method function by
956
nonmethod_func = (dict(
957
zip(attribute.func_code.co_freevars,
958
attribute.__closure__))["func"]
960
# Create a new, but exactly alike, function
961
# object, and decorate it to be a new D-Bus signal
962
# with the alternate D-Bus interface name
963
new_function = (dbus.service.signal
965
attribute._dbus_signature)
967
nonmethod_func.func_code,
968
nonmethod_func.func_globals,
969
nonmethod_func.func_name,
970
nonmethod_func.func_defaults,
971
nonmethod_func.func_closure)))
972
# Define a creator of a function to call both the
973
# old and new functions, so both the old and new
974
# signals gets sent when the function is called
975
def fixscope(func1, func2):
976
"""This function is a scope container to pass
977
func1 and func2 to the "call_both" function
978
outside of its arguments"""
979
def call_both(*args, **kwargs):
980
"""This function will emit two D-Bus
981
signals by calling func1 and func2"""
982
func1(*args, **kwargs)
983
func2(*args, **kwargs)
985
# Create the "call_both" function and add it to
987
attr[attrname] = fixscope(attribute,
989
# Is this a D-Bus method?
990
elif getattr(attribute, "_dbus_is_method", False):
991
# Create a new, but exactly alike, function
992
# object. Decorate it to be a new D-Bus method
993
# with the alternate D-Bus interface name. Add it
995
attr[attrname] = (dbus.service.method
997
attribute._dbus_in_signature,
998
attribute._dbus_out_signature)
1000
(attribute.func_code,
1001
attribute.func_globals,
1002
attribute.func_name,
1003
attribute.func_defaults,
1004
attribute.func_closure)))
1005
# Is this a D-Bus property?
1006
elif getattr(attribute, "_dbus_is_property", False):
1007
# Create a new, but exactly alike, function
1008
# object, and decorate it to be a new D-Bus
1009
# property with the alternate D-Bus interface
1010
# name. Add it to the class.
1011
attr[attrname] = (dbus_service_property
1013
attribute._dbus_signature,
1014
attribute._dbus_access,
1016
._dbus_get_args_options
1019
(attribute.func_code,
1020
attribute.func_globals,
1021
attribute.func_name,
1022
attribute.func_defaults,
1023
attribute.func_closure)))
1024
return type.__new__(mcs, name, bases, attr)
1027
class ClientDBus(Client, DBusObjectWithProperties):
1028
"""A Client class using D-Bus
1031
dbus_object_path: dbus.ObjectPath
1032
bus: dbus.SystemBus()
1035
runtime_expansions = (Client.runtime_expansions
1036
+ ("dbus_object_path",))
1038
# dbus.service.Object doesn't use super(), so we can't either.
1040
def __init__(self, bus = None, *args, **kwargs):
1042
Client.__init__(self, *args, **kwargs)
1043
self._approvals_pending = 0
1045
self._approvals_pending = 0
1046
# Only now, when this client is initialized, can it show up on
1048
client_object_name = unicode(self.name).translate(
1049
{ord("."): ord("_"),
1050
ord("-"): ord("_")})
1051
self.dbus_object_path = (dbus.ObjectPath
1052
("/clients/" + client_object_name))
1053
DBusObjectWithProperties.__init__(self, self.bus,
1054
self.dbus_object_path)
1056
def notifychangeproperty(transform_func,
1057
dbus_name, type_func=lambda x: x,
1059
""" Modify a variable so that it's a property which announces
1060
its changes to DBus.
1062
transform_fun: Function that takes a value and a variant_level
1063
and transforms it to a D-Bus type.
1064
dbus_name: D-Bus name of the variable
1065
type_func: Function that transform the value before sending it
1066
to the D-Bus. Default: no transform
1067
variant_level: D-Bus variant level. Default: 1
1069
attrname = "_{0}".format(dbus_name)
1070
def setter(self, value):
1071
if hasattr(self, "dbus_object_path"):
1072
if (not hasattr(self, attrname) or
1073
type_func(getattr(self, attrname, None))
1074
!= type_func(value)):
1075
dbus_value = transform_func(type_func(value),
1078
self.PropertyChanged(dbus.String(dbus_name),
1080
setattr(self, attrname, value)
1082
return property(lambda self: getattr(self, attrname), setter)
1085
expires = notifychangeproperty(datetime_to_dbus, "Expires")
1086
approvals_pending = notifychangeproperty(dbus.Boolean,
1089
enabled = notifychangeproperty(dbus.Boolean, "Enabled")
1090
last_enabled = notifychangeproperty(datetime_to_dbus,
1092
checker = notifychangeproperty(dbus.Boolean, "CheckerRunning",
1093
type_func = lambda checker:
1094
checker is not None)
1095
last_checked_ok = notifychangeproperty(datetime_to_dbus,
1097
last_approval_request = notifychangeproperty(
1098
datetime_to_dbus, "LastApprovalRequest")
1099
approved_by_default = notifychangeproperty(dbus.Boolean,
1100
"ApprovedByDefault")
1101
approval_delay = notifychangeproperty(dbus.UInt64,
1104
timedelta_to_milliseconds)
1105
approval_duration = notifychangeproperty(
1106
dbus.UInt64, "ApprovalDuration",
1107
type_func = timedelta_to_milliseconds)
1108
host = notifychangeproperty(dbus.String, "Host")
1109
timeout = notifychangeproperty(dbus.UInt64, "Timeout",
1111
timedelta_to_milliseconds)
1112
extended_timeout = notifychangeproperty(
1113
dbus.UInt64, "ExtendedTimeout",
1114
type_func = timedelta_to_milliseconds)
1115
interval = notifychangeproperty(dbus.UInt64,
1118
timedelta_to_milliseconds)
1119
checker_command = notifychangeproperty(dbus.String, "Checker")
1121
del notifychangeproperty
1123
def __del__(self, *args, **kwargs):
1125
self.remove_from_connection()
1128
if hasattr(DBusObjectWithProperties, "__del__"):
1129
DBusObjectWithProperties.__del__(self, *args, **kwargs)
1130
Client.__del__(self, *args, **kwargs)
1132
def checker_callback(self, pid, condition, command,
1134
self.checker_callback_tag = None
1136
if os.WIFEXITED(condition):
1137
exitstatus = os.WEXITSTATUS(condition)
1139
self.CheckerCompleted(dbus.Int16(exitstatus),
1140
dbus.Int64(condition),
1141
dbus.String(command))
1144
self.CheckerCompleted(dbus.Int16(-1),
1145
dbus.Int64(condition),
1146
dbus.String(command))
1148
return Client.checker_callback(self, pid, condition, command,
1151
def start_checker(self, *args, **kwargs):
1152
old_checker = self.checker
1153
if self.checker is not None:
1154
old_checker_pid = self.checker.pid
1156
old_checker_pid = None
1157
r = Client.start_checker(self, *args, **kwargs)
1158
# Only if new checker process was started
1159
if (self.checker is not None
1160
and old_checker_pid != self.checker.pid):
1162
self.CheckerStarted(self.current_checker_command)
1165
def _reset_approved(self):
1166
self.approved = None
1169
def approve(self, value=True):
1170
self.send_changedstate()
1171
self.approved = value
1172
gobject.timeout_add(timedelta_to_milliseconds
1173
(self.approval_duration),
1174
self._reset_approved)
1177
## D-Bus methods, signals & properties
1178
_interface = "se.recompile.Mandos.Client"
456
self.PropertyChanged(dbus.String(u"checker_running"),
457
dbus.Boolean(False, variant_level=1))
459
def still_valid(self):
460
"""Has the timeout not yet passed for this client?"""
461
if not getattr(self, "started", False):
463
now = datetime.datetime.utcnow()
464
if self.last_checked_ok is None:
465
return now < (self.created + self.timeout)
467
return now < (self.last_checked_ok + self.timeout)
469
## D-Bus methods & signals
470
_interface = u"org.mandos_system.Mandos.Client"
472
# BumpTimeout - method
473
BumpTimeout = dbus.service.method(_interface)(bump_timeout)
474
BumpTimeout.__name__ = "BumpTimeout"
1182
476
# CheckerCompleted - signal
1183
@dbus.service.signal(_interface, signature="nxs")
1184
def CheckerCompleted(self, exitcode, waitstatus, command):
477
@dbus.service.signal(_interface, signature="bqs")
478
def CheckerCompleted(self, success, condition, command):
1251
576
self.start_checker()
1254
579
@dbus.service.method(_interface)
1259
584
# StopChecker - method
1260
@dbus.service.method(_interface)
1261
def StopChecker(self):
1266
# ApprovalPending - property
1267
@dbus_service_property(_interface, signature="b", access="read")
1268
def ApprovalPending_dbus_property(self):
1269
return dbus.Boolean(bool(self.approvals_pending))
1271
# ApprovedByDefault - property
1272
@dbus_service_property(_interface, signature="b",
1274
def ApprovedByDefault_dbus_property(self, value=None):
1275
if value is None: # get
1276
return dbus.Boolean(self.approved_by_default)
1277
self.approved_by_default = bool(value)
1279
# ApprovalDelay - property
1280
@dbus_service_property(_interface, signature="t",
1282
def ApprovalDelay_dbus_property(self, value=None):
1283
if value is None: # get
1284
return dbus.UInt64(self.approval_delay_milliseconds())
1285
self.approval_delay = datetime.timedelta(0, 0, 0, value)
1287
# ApprovalDuration - property
1288
@dbus_service_property(_interface, signature="t",
1290
def ApprovalDuration_dbus_property(self, value=None):
1291
if value is None: # get
1292
return dbus.UInt64(timedelta_to_milliseconds(
1293
self.approval_duration))
1294
self.approval_duration = datetime.timedelta(0, 0, 0, value)
1297
@dbus_service_property(_interface, signature="s", access="read")
1298
def Name_dbus_property(self):
1299
return dbus.String(self.name)
1301
# Fingerprint - property
1302
@dbus_service_property(_interface, signature="s", access="read")
1303
def Fingerprint_dbus_property(self):
1304
return dbus.String(self.fingerprint)
1307
@dbus_service_property(_interface, signature="s",
1309
def Host_dbus_property(self, value=None):
1310
if value is None: # get
1311
return dbus.String(self.host)
1312
self.host = unicode(value)
1314
# Created - property
1315
@dbus_service_property(_interface, signature="s", access="read")
1316
def Created_dbus_property(self):
1317
return datetime_to_dbus(self.created)
1319
# LastEnabled - property
1320
@dbus_service_property(_interface, signature="s", access="read")
1321
def LastEnabled_dbus_property(self):
1322
return datetime_to_dbus(self.last_enabled)
1324
# Enabled - property
1325
@dbus_service_property(_interface, signature="b",
1327
def Enabled_dbus_property(self, value=None):
1328
if value is None: # get
1329
return dbus.Boolean(self.enabled)
1335
# LastCheckedOK - property
1336
@dbus_service_property(_interface, signature="s",
1338
def LastCheckedOK_dbus_property(self, value=None):
1339
if value is not None:
1342
return datetime_to_dbus(self.last_checked_ok)
1344
# Expires - property
1345
@dbus_service_property(_interface, signature="s", access="read")
1346
def Expires_dbus_property(self):
1347
return datetime_to_dbus(self.expires)
1349
# LastApprovalRequest - property
1350
@dbus_service_property(_interface, signature="s", access="read")
1351
def LastApprovalRequest_dbus_property(self):
1352
return datetime_to_dbus(self.last_approval_request)
1354
# Timeout - property
1355
@dbus_service_property(_interface, signature="t",
1357
def Timeout_dbus_property(self, value=None):
1358
if value is None: # get
1359
return dbus.UInt64(self.timeout_milliseconds())
1360
self.timeout = datetime.timedelta(0, 0, 0, value)
1361
if getattr(self, "disable_initiator_tag", None) is None:
1363
# Reschedule timeout
1364
gobject.source_remove(self.disable_initiator_tag)
1365
self.disable_initiator_tag = None
1367
time_to_die = timedelta_to_milliseconds((self
1372
if time_to_die <= 0:
1373
# The timeout has passed
1376
self.expires = (datetime.datetime.utcnow()
1377
+ datetime.timedelta(milliseconds =
1379
self.disable_initiator_tag = (gobject.timeout_add
1380
(time_to_die, self.disable))
1382
# ExtendedTimeout - property
1383
@dbus_service_property(_interface, signature="t",
1385
def ExtendedTimeout_dbus_property(self, value=None):
1386
if value is None: # get
1387
return dbus.UInt64(self.extended_timeout_milliseconds())
1388
self.extended_timeout = datetime.timedelta(0, 0, 0, value)
1390
# Interval - property
1391
@dbus_service_property(_interface, signature="t",
1393
def Interval_dbus_property(self, value=None):
1394
if value is None: # get
1395
return dbus.UInt64(self.interval_milliseconds())
1396
self.interval = datetime.timedelta(0, 0, 0, value)
1397
if getattr(self, "checker_initiator_tag", None) is None:
1400
# Reschedule checker run
1401
gobject.source_remove(self.checker_initiator_tag)
1402
self.checker_initiator_tag = (gobject.timeout_add
1403
(value, self.start_checker))
1404
self.start_checker() # Start one now, too
1406
# Checker - property
1407
@dbus_service_property(_interface, signature="s",
1409
def Checker_dbus_property(self, value=None):
1410
if value is None: # get
1411
return dbus.String(self.checker_command)
1412
self.checker_command = unicode(value)
1414
# CheckerRunning - property
1415
@dbus_service_property(_interface, signature="b",
1417
def CheckerRunning_dbus_property(self, value=None):
1418
if value is None: # get
1419
return dbus.Boolean(self.checker is not None)
1421
self.start_checker()
1425
# ObjectPath - property
1426
@dbus_service_property(_interface, signature="o", access="read")
1427
def ObjectPath_dbus_property(self):
1428
return self.dbus_object_path # is already a dbus.ObjectPath
1431
@dbus_service_property(_interface, signature="ay",
1432
access="write", byte_arrays=True)
1433
def Secret_dbus_property(self, value):
1434
self.secret = str(value)
585
StopChecker = dbus.service.method(_interface)(stop_checker)
586
StopChecker.__name__ = "StopChecker"
1439
class ProxyClient(object):
1440
def __init__(self, child_pipe, fpr, address):
1441
self._pipe = child_pipe
1442
self._pipe.send(('init', fpr, address))
1443
if not self._pipe.recv():
1446
def __getattribute__(self, name):
1448
return super(ProxyClient, self).__getattribute__(name)
1449
self._pipe.send(('getattr', name))
1450
data = self._pipe.recv()
1451
if data[0] == 'data':
1453
if data[0] == 'function':
1454
def func(*args, **kwargs):
1455
self._pipe.send(('funcall', name, args, kwargs))
1456
return self._pipe.recv()[1]
1459
def __setattr__(self, name, value):
1461
return super(ProxyClient, self).__setattr__(name, value)
1462
self._pipe.send(('setattr', name, value))
1465
class ClientDBusTransitional(ClientDBus):
1466
__metaclass__ = AlternateDBusNamesMetaclass
1469
class ClientHandler(socketserver.BaseRequestHandler, object):
1470
"""A class to handle client connections.
1472
Instantiated once for each connection to handle it.
591
def peer_certificate(session):
592
"Return the peer's OpenPGP certificate as a bytestring"
593
# If not an OpenPGP certificate...
594
if (gnutls.library.functions
595
.gnutls_certificate_type_get(session._c_object)
596
!= gnutls.library.constants.GNUTLS_CRT_OPENPGP):
597
# ...do the normal thing
598
return session.peer_certificate
599
list_size = ctypes.c_uint()
600
cert_list = (gnutls.library.functions
601
.gnutls_certificate_get_peers
602
(session._c_object, ctypes.byref(list_size)))
603
if list_size.value == 0:
606
return ctypes.string_at(cert.data, cert.size)
609
def fingerprint(openpgp):
610
"Convert an OpenPGP bytestring to a hexdigit fingerprint string"
611
# New GnuTLS "datum" with the OpenPGP public key
612
datum = (gnutls.library.types
613
.gnutls_datum_t(ctypes.cast(ctypes.c_char_p(openpgp),
616
ctypes.c_uint(len(openpgp))))
617
# New empty GnuTLS certificate
618
crt = gnutls.library.types.gnutls_openpgp_crt_t()
619
(gnutls.library.functions
620
.gnutls_openpgp_crt_init(ctypes.byref(crt)))
621
# Import the OpenPGP public key into the certificate
622
(gnutls.library.functions
623
.gnutls_openpgp_crt_import(crt, ctypes.byref(datum),
624
gnutls.library.constants
625
.GNUTLS_OPENPGP_FMT_RAW))
626
# Verify the self signature in the key
627
crtverify = ctypes.c_uint()
628
(gnutls.library.functions
629
.gnutls_openpgp_crt_verify_self(crt, 0, ctypes.byref(crtverify)))
630
if crtverify.value != 0:
631
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
632
raise gnutls.errors.CertificateSecurityError("Verify failed")
633
# New buffer for the fingerprint
634
buf = ctypes.create_string_buffer(20)
635
buf_len = ctypes.c_size_t()
636
# Get the fingerprint from the certificate into the buffer
637
(gnutls.library.functions
638
.gnutls_openpgp_crt_get_fingerprint(crt, ctypes.byref(buf),
639
ctypes.byref(buf_len)))
640
# Deinit the certificate
641
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
642
# Convert the buffer to a Python bytestring
643
fpr = ctypes.string_at(buf, buf_len.value)
644
# Convert the bytestring to hexadecimal notation
645
hex_fpr = u''.join(u"%02X" % ord(char) for char in fpr)
649
class TCP_handler(SocketServer.BaseRequestHandler, object):
650
"""A TCP request handler class.
651
Instantiated by IPv6_TCPServer for each request to handle it.
1473
652
Note: This will run in its own forked process."""
1475
654
def handle(self):
1476
with contextlib.closing(self.server.child_pipe) as child_pipe:
1477
logger.info("TCP connection from: %s",
1478
unicode(self.client_address))
1479
logger.debug("Pipe FD: %d",
1480
self.server.child_pipe.fileno())
1482
session = (gnutls.connection
1483
.ClientSession(self.request,
1485
.X509Credentials()))
1487
# Note: gnutls.connection.X509Credentials is really a
1488
# generic GnuTLS certificate credentials object so long as
1489
# no X.509 keys are added to it. Therefore, we can use it
1490
# here despite using OpenPGP certificates.
1492
#priority = ':'.join(("NONE", "+VERS-TLS1.1",
1493
# "+AES-256-CBC", "+SHA1",
1494
# "+COMP-NULL", "+CTYPE-OPENPGP",
1496
# Use a fallback default, since this MUST be set.
1497
priority = self.server.gnutls_priority
1498
if priority is None:
1500
(gnutls.library.functions
1501
.gnutls_priority_set_direct(session._c_object,
1504
# Start communication using the Mandos protocol
1505
# Get protocol number
1506
line = self.request.makefile().readline()
1507
logger.debug("Protocol version: %r", line)
1509
if int(line.strip().split()[0]) > 1:
1511
except (ValueError, IndexError, RuntimeError) as error:
1512
logger.error("Unknown protocol version: %s", error)
1515
# Start GnuTLS connection
1518
except gnutls.errors.GNUTLSError as error:
1519
logger.warning("Handshake failed: %s", error)
1520
# Do not run session.bye() here: the session is not
1521
# established. Just abandon the request.
1523
logger.debug("Handshake succeeded")
1525
approval_required = False
1528
fpr = self.fingerprint(self.peer_certificate
1531
gnutls.errors.GNUTLSError) as error:
1532
logger.warning("Bad certificate: %s", error)
1534
logger.debug("Fingerprint: %s", fpr)
1537
client = ProxyClient(child_pipe, fpr,
1538
self.client_address)
1542
if self.server.use_dbus:
1544
client.NewRequest(str(self.client_address))
1546
if client.approval_delay:
1547
delay = client.approval_delay
1548
client.approvals_pending += 1
1549
approval_required = True
1552
if not client.enabled:
1553
logger.info("Client %s is disabled",
1555
if self.server.use_dbus:
1557
client.Rejected("Disabled")
1560
if client.approved or not client.approval_delay:
1561
#We are approved or approval is disabled
1563
elif client.approved is None:
1564
logger.info("Client %s needs approval",
1566
if self.server.use_dbus:
1568
client.NeedApproval(
1569
client.approval_delay_milliseconds(),
1570
client.approved_by_default)
1572
logger.warning("Client %s was not approved",
1574
if self.server.use_dbus:
1576
client.Rejected("Denied")
1579
#wait until timeout or approved
1580
time = datetime.datetime.now()
1581
client.changedstate.acquire()
1582
(client.changedstate.wait
1583
(float(client.timedelta_to_milliseconds(delay)
1585
client.changedstate.release()
1586
time2 = datetime.datetime.now()
1587
if (time2 - time) >= delay:
1588
if not client.approved_by_default:
1589
logger.warning("Client %s timed out while"
1590
" waiting for approval",
1592
if self.server.use_dbus:
1594
client.Rejected("Approval timed out")
1599
delay -= time2 - time
1602
while sent_size < len(client.secret):
1604
sent = session.send(client.secret[sent_size:])
1605
except gnutls.errors.GNUTLSError as error:
1606
logger.warning("gnutls send failed")
1608
logger.debug("Sent: %d, remaining: %d",
1609
sent, len(client.secret)
1610
- (sent_size + sent))
1613
logger.info("Sending secret to %s", client.name)
1614
# bump the timeout using extended_timeout
1615
client.checked_ok(client.extended_timeout)
1616
if self.server.use_dbus:
1621
if approval_required:
1622
client.approvals_pending -= 1
1625
except gnutls.errors.GNUTLSError as error:
1626
logger.warning("GnuTLS bye failed")
1629
def peer_certificate(session):
1630
"Return the peer's OpenPGP certificate as a bytestring"
1631
# If not an OpenPGP certificate...
1632
if (gnutls.library.functions
1633
.gnutls_certificate_type_get(session._c_object)
1634
!= gnutls.library.constants.GNUTLS_CRT_OPENPGP):
1635
# ...do the normal thing
1636
return session.peer_certificate
1637
list_size = ctypes.c_uint(1)
1638
cert_list = (gnutls.library.functions
1639
.gnutls_certificate_get_peers
1640
(session._c_object, ctypes.byref(list_size)))
1641
if not bool(cert_list) and list_size.value != 0:
1642
raise gnutls.errors.GNUTLSError("error getting peer"
1644
if list_size.value == 0:
1647
return ctypes.string_at(cert.data, cert.size)
1650
def fingerprint(openpgp):
1651
"Convert an OpenPGP bytestring to a hexdigit fingerprint"
1652
# New GnuTLS "datum" with the OpenPGP public key
1653
datum = (gnutls.library.types
1654
.gnutls_datum_t(ctypes.cast(ctypes.c_char_p(openpgp),
1657
ctypes.c_uint(len(openpgp))))
1658
# New empty GnuTLS certificate
1659
crt = gnutls.library.types.gnutls_openpgp_crt_t()
1660
(gnutls.library.functions
1661
.gnutls_openpgp_crt_init(ctypes.byref(crt)))
1662
# Import the OpenPGP public key into the certificate
1663
(gnutls.library.functions
1664
.gnutls_openpgp_crt_import(crt, ctypes.byref(datum),
1665
gnutls.library.constants
1666
.GNUTLS_OPENPGP_FMT_RAW))
1667
# Verify the self signature in the key
1668
crtverify = ctypes.c_uint()
1669
(gnutls.library.functions
1670
.gnutls_openpgp_crt_verify_self(crt, 0,
1671
ctypes.byref(crtverify)))
1672
if crtverify.value != 0:
1673
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
1674
raise (gnutls.errors.CertificateSecurityError
1676
# New buffer for the fingerprint
1677
buf = ctypes.create_string_buffer(20)
1678
buf_len = ctypes.c_size_t()
1679
# Get the fingerprint from the certificate into the buffer
1680
(gnutls.library.functions
1681
.gnutls_openpgp_crt_get_fingerprint(crt, ctypes.byref(buf),
1682
ctypes.byref(buf_len)))
1683
# Deinit the certificate
1684
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
1685
# Convert the buffer to a Python bytestring
1686
fpr = ctypes.string_at(buf, buf_len.value)
1687
# Convert the bytestring to hexadecimal notation
1688
hex_fpr = binascii.hexlify(fpr).upper()
1692
class MultiprocessingMixIn(object):
1693
"""Like socketserver.ThreadingMixIn, but with multiprocessing"""
1694
def sub_process_main(self, request, address):
1696
self.finish_request(request, address)
1698
self.handle_error(request, address)
1699
self.close_request(request)
1701
def process_request(self, request, address):
1702
"""Start a new process to process the request."""
1703
proc = multiprocessing.Process(target = self.sub_process_main,
1710
class MultiprocessingMixInWithPipe(MultiprocessingMixIn, object):
1711
""" adds a pipe to the MixIn """
1712
def process_request(self, request, client_address):
1713
"""Overrides and wraps the original process_request().
1715
This function creates a new pipe in self.pipe
1717
parent_pipe, self.child_pipe = multiprocessing.Pipe()
1719
proc = MultiprocessingMixIn.process_request(self, request,
1721
self.child_pipe.close()
1722
self.add_pipe(parent_pipe, proc)
1724
def add_pipe(self, parent_pipe, proc):
1725
"""Dummy function; override as necessary"""
1726
raise NotImplementedError
1729
class IPv6_TCPServer(MultiprocessingMixInWithPipe,
1730
socketserver.TCPServer, object):
1731
"""IPv6-capable TCP server. Accepts 'None' as address and/or port
655
logger.info(u"TCP connection from: %s",
656
unicode(self.client_address))
657
session = (gnutls.connection
658
.ClientSession(self.request,
662
line = self.request.makefile().readline()
663
logger.debug(u"Protocol version: %r", line)
665
if int(line.strip().split()[0]) > 1:
667
except (ValueError, IndexError, RuntimeError), error:
668
logger.error(u"Unknown protocol version: %s", error)
671
# Note: gnutls.connection.X509Credentials is really a generic
672
# GnuTLS certificate credentials object so long as no X.509
673
# keys are added to it. Therefore, we can use it here despite
674
# using OpenPGP certificates.
676
#priority = ':'.join(("NONE", "+VERS-TLS1.1", "+AES-256-CBC",
677
# "+SHA1", "+COMP-NULL", "+CTYPE-OPENPGP",
679
# Use a fallback default, since this MUST be set.
680
priority = self.server.settings.get("priority", "NORMAL")
681
(gnutls.library.functions
682
.gnutls_priority_set_direct(session._c_object,
687
except gnutls.errors.GNUTLSError, error:
688
logger.warning(u"Handshake failed: %s", error)
689
# Do not run session.bye() here: the session is not
690
# established. Just abandon the request.
693
fpr = fingerprint(peer_certificate(session))
694
except (TypeError, gnutls.errors.GNUTLSError), error:
695
logger.warning(u"Bad certificate: %s", error)
698
logger.debug(u"Fingerprint: %s", fpr)
699
for c in self.server.clients:
700
if c.fingerprint == fpr:
704
logger.warning(u"Client not found for fingerprint: %s",
708
# Have to check if client.still_valid(), since it is possible
709
# that the client timed out while establishing the GnuTLS
711
if not client.still_valid():
712
logger.warning(u"Client %(name)s is invalid",
716
## This won't work here, since we're in a fork.
717
# client.bump_timeout()
719
while sent_size < len(client.secret):
720
sent = session.send(client.secret[sent_size:])
721
logger.debug(u"Sent: %d, remaining: %d",
722
sent, len(client.secret)
723
- (sent_size + sent))
728
class IPv6_TCPServer(SocketServer.ForkingMixIn,
729
SocketServer.TCPServer, object):
730
"""IPv6 TCP server. Accepts 'None' as address and/or port.
732
settings: Server settings
733
clients: Set() of Client objects
1734
734
enabled: Boolean; whether this server is activated yet
1735
interface: None or a network interface name (string)
1736
use_ipv6: Boolean; to use IPv6 or not
1738
def __init__(self, server_address, RequestHandlerClass,
1739
interface=None, use_ipv6=True):
1740
self.interface = interface
1742
self.address_family = socket.AF_INET6
1743
socketserver.TCPServer.__init__(self, server_address,
1744
RequestHandlerClass)
736
address_family = socket.AF_INET6
737
def __init__(self, *args, **kwargs):
738
if "settings" in kwargs:
739
self.settings = kwargs["settings"]
740
del kwargs["settings"]
741
if "clients" in kwargs:
742
self.clients = kwargs["clients"]
743
del kwargs["clients"]
745
super(IPv6_TCPServer, self).__init__(*args, **kwargs)
1745
746
def server_bind(self):
1746
747
"""This overrides the normal server_bind() function
1747
748
to bind to an interface if one was specified, and also NOT to
1748
749
bind to an address or port if they were not specified."""
1749
if self.interface is not None:
1750
if SO_BINDTODEVICE is None:
1751
logger.error("SO_BINDTODEVICE does not exist;"
1752
" cannot bind to interface %s",
1756
self.socket.setsockopt(socket.SOL_SOCKET,
1760
except socket.error as error:
1761
if error[0] == errno.EPERM:
1762
logger.error("No permission to"
1763
" bind to interface %s",
1765
elif error[0] == errno.ENOPROTOOPT:
1766
logger.error("SO_BINDTODEVICE not available;"
1767
" cannot bind to interface %s",
750
if self.settings["interface"]:
751
# 25 is from /usr/include/asm-i486/socket.h
752
SO_BINDTODEVICE = getattr(socket, "SO_BINDTODEVICE", 25)
754
self.socket.setsockopt(socket.SOL_SOCKET,
756
self.settings["interface"])
757
except socket.error, error:
758
if error[0] == errno.EPERM:
759
logger.error(u"No permission to"
760
u" bind to interface %s",
761
self.settings["interface"])
1771
764
# Only bind(2) the socket if we really need to.
1772
765
if self.server_address[0] or self.server_address[1]:
1773
766
if not self.server_address[0]:
1774
if self.address_family == socket.AF_INET6:
1775
any_address = "::" # in6addr_any
1777
any_address = socket.INADDR_ANY
1778
self.server_address = (any_address,
768
self.server_address = (in6addr_any,
1779
769
self.server_address[1])
1780
770
elif not self.server_address[1]:
1781
771
self.server_address = (self.server_address[0],
1783
# if self.interface:
773
# if self.settings["interface"]:
1784
774
# self.server_address = (self.server_address[0],
1787
777
# if_nametoindex
1789
return socketserver.TCPServer.server_bind(self)
1792
class MandosServer(IPv6_TCPServer):
1796
clients: set of Client objects
1797
gnutls_priority GnuTLS priority string
1798
use_dbus: Boolean; to emit D-Bus signals or not
1800
Assumes a gobject.MainLoop event loop.
1802
def __init__(self, server_address, RequestHandlerClass,
1803
interface=None, use_ipv6=True, clients=None,
1804
gnutls_priority=None, use_dbus=True):
1805
self.enabled = False
1806
self.clients = clients
1807
if self.clients is None:
1809
self.use_dbus = use_dbus
1810
self.gnutls_priority = gnutls_priority
1811
IPv6_TCPServer.__init__(self, server_address,
1812
RequestHandlerClass,
1813
interface = interface,
1814
use_ipv6 = use_ipv6)
780
return super(IPv6_TCPServer, self).server_bind()
1815
781
def server_activate(self):
1816
782
if self.enabled:
1817
return socketserver.TCPServer.server_activate(self)
783
return super(IPv6_TCPServer, self).server_activate()
1819
784
def enable(self):
1820
785
self.enabled = True
1822
def add_pipe(self, parent_pipe, proc):
1823
# Call "handle_ipc" for both data and EOF events
1824
gobject.io_add_watch(parent_pipe.fileno(),
1825
gobject.IO_IN | gobject.IO_HUP,
1826
functools.partial(self.handle_ipc,
1831
def handle_ipc(self, source, condition, parent_pipe=None,
1832
proc = None, client_object=None):
1834
gobject.IO_IN: "IN", # There is data to read.
1835
gobject.IO_OUT: "OUT", # Data can be written (without
1837
gobject.IO_PRI: "PRI", # There is urgent data to read.
1838
gobject.IO_ERR: "ERR", # Error condition.
1839
gobject.IO_HUP: "HUP" # Hung up (the connection has been
1840
# broken, usually for pipes and
1843
conditions_string = ' | '.join(name
1845
condition_names.iteritems()
1846
if cond & condition)
1847
# error, or the other end of multiprocessing.Pipe has closed
1848
if condition & (gobject.IO_ERR | condition & gobject.IO_HUP):
1849
# Wait for other process to exit
1853
# Read a request from the child
1854
request = parent_pipe.recv()
1855
command = request[0]
1857
if command == 'init':
1859
address = request[2]
1861
for c in self.clients.itervalues():
1862
if c.fingerprint == fpr:
1866
logger.info("Client not found for fingerprint: %s, ad"
1867
"dress: %s", fpr, address)
1870
mandos_dbus_service.ClientNotFound(fpr,
1872
parent_pipe.send(False)
1875
gobject.io_add_watch(parent_pipe.fileno(),
1876
gobject.IO_IN | gobject.IO_HUP,
1877
functools.partial(self.handle_ipc,
1883
parent_pipe.send(True)
1884
# remove the old hook in favor of the new above hook on
1887
if command == 'funcall':
1888
funcname = request[1]
1892
parent_pipe.send(('data', getattr(client_object,
1896
if command == 'getattr':
1897
attrname = request[1]
1898
if callable(client_object.__getattribute__(attrname)):
1899
parent_pipe.send(('function',))
1901
parent_pipe.send(('data', client_object
1902
.__getattribute__(attrname)))
1904
if command == 'setattr':
1905
attrname = request[1]
1907
setattr(client_object, attrname, value)
1912
788
def string_to_delta(interval):
1913
789
"""Parse a string and return a datetime.timedelta
1915
791
>>> string_to_delta('7d')
1916
792
datetime.timedelta(7)
1917
793
>>> string_to_delta('60s')
2030
930
"SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP",
2031
931
"servicename": "Mandos",
2036
"statedir": "/var/lib/mandos"
2039
934
# Parse config file for server-global settings
2040
server_config = configparser.SafeConfigParser(server_defaults)
935
server_config = ConfigParser.SafeConfigParser(server_defaults)
2041
936
del server_defaults
2042
server_config.read(os.path.join(options.configdir,
937
server_config.read(os.path.join(options.configdir, "mandos.conf"))
2044
938
# Convert the SafeConfigParser object to a dict
2045
939
server_settings = server_config.defaults()
2046
# Use the appropriate methods on the non-string config options
2047
for option in ("debug", "use_dbus", "use_ipv6"):
2048
server_settings[option] = server_config.getboolean("DEFAULT",
2050
if server_settings["port"]:
2051
server_settings["port"] = server_config.getint("DEFAULT",
940
# Use getboolean on the boolean config option
941
server_settings["debug"] = (server_config.getboolean
942
("DEFAULT", "debug"))
2053
943
del server_config
2055
945
# Override the settings from the config file with command line
2056
946
# options, if set.
2057
947
for option in ("interface", "address", "port", "debug",
2058
"priority", "servicename", "configdir",
2059
"use_dbus", "use_ipv6", "debuglevel", "restore",
948
"priority", "servicename", "configdir"):
2061
949
value = getattr(options, option)
2062
950
if value is not None:
2063
951
server_settings[option] = value
2065
# Force all strings to be unicode
2066
for option in server_settings.keys():
2067
if type(server_settings[option]) is str:
2068
server_settings[option] = unicode(server_settings[option])
2069
953
# Now we have our good server settings in "server_settings"
2071
##################################################################
2074
955
debug = server_settings["debug"]
2075
debuglevel = server_settings["debuglevel"]
2076
use_dbus = server_settings["use_dbus"]
2077
use_ipv6 = server_settings["use_ipv6"]
2078
stored_state_path = os.path.join(server_settings["statedir"],
2082
initlogger(debug, logging.DEBUG)
2087
level = getattr(logging, debuglevel.upper())
2088
initlogger(debug, level)
958
syslogger.setLevel(logging.WARNING)
959
console.setLevel(logging.WARNING)
2090
961
if server_settings["servicename"] != "Mandos":
2091
962
syslogger.setFormatter(logging.Formatter
2092
('Mandos (%s) [%%(process)d]:'
2093
' %%(levelname)s: %%(message)s'
963
('Mandos (%s): %%(levelname)s:'
2094
965
% server_settings["servicename"]))
2096
967
# Parse config file with clients
2097
client_config = configparser.SafeConfigParser(Client.client_defaults)
968
client_defaults = { "timeout": "1h",
970
"checker": "fping -q -- %(host)s",
973
client_config = ConfigParser.SafeConfigParser(client_defaults)
2098
974
client_config.read(os.path.join(server_settings["configdir"],
2099
975
"clients.conf"))
2101
global mandos_dbus_service
2102
mandos_dbus_service = None
2104
tcp_server = MandosServer((server_settings["address"],
2105
server_settings["port"]),
2107
interface=(server_settings["interface"]
2111
server_settings["priority"],
2114
pidfilename = "/var/run/mandos.pid"
2116
pidfile = open(pidfilename, "w")
2118
logger.error("Could not open file %r", pidfilename)
978
tcp_server = IPv6_TCPServer((server_settings["address"],
979
server_settings["port"]),
981
settings=server_settings,
983
pidfilename = "/var/run/mandos.pid"
985
pidfile = open(pidfilename, "w")
986
except IOError, error:
987
logger.error("Could not open file %r", pidfilename)
2121
990
uid = pwd.getpwnam("_mandos").pw_uid
2122
gid = pwd.getpwnam("_mandos").pw_gid
2123
991
except KeyError:
2125
993
uid = pwd.getpwnam("mandos").pw_uid
2126
gid = pwd.getpwnam("mandos").pw_gid
2127
994
except KeyError:
2129
996
uid = pwd.getpwnam("nobody").pw_uid
2130
gid = pwd.getpwnam("nobody").pw_gid
2131
997
except KeyError:
1000
gid = pwd.getpwnam("_mandos").pw_gid
1003
gid = pwd.getpwnam("mandos").pw_gid
1006
gid = pwd.getpwnam("nogroup").pw_gid
2137
except OSError as error:
1012
except OSError, error:
2138
1013
if error[0] != errno.EPERM:
2142
# Enable all possible GnuTLS debugging
2144
# "Use a log level over 10 to enable all debugging options."
2146
gnutls.library.functions.gnutls_global_set_log_level(11)
2148
@gnutls.library.types.gnutls_log_func
2149
def debug_gnutls(level, string):
2150
logger.debug("GnuTLS: %s", string[:-1])
2152
(gnutls.library.functions
2153
.gnutls_global_set_log_function(debug_gnutls))
2155
# Redirect stdin so all checkers get /dev/null
2156
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
2157
os.dup2(null, sys.stdin.fileno())
2161
# Need to fork before connecting to D-Bus
2163
# Close all input and output, do double fork, etc.
2166
gobject.threads_init()
1017
service = AvahiService(name = server_settings["servicename"],
1018
servicetype = "_mandos._tcp", )
1019
if server_settings["interface"]:
1020
service.interface = (if_nametoindex
1021
(server_settings["interface"]))
2168
1023
global main_loop
2169
1026
# From the Avahi example code
2170
1027
DBusGMainLoop(set_as_default=True )
2171
1028
main_loop = gobject.MainLoop()
2172
1029
bus = dbus.SystemBus()
1030
server = dbus.Interface(bus.get_object(avahi.DBUS_NAME,
1031
avahi.DBUS_PATH_SERVER),
1032
avahi.DBUS_INTERFACE_SERVER)
2173
1033
# End of Avahi example code
2176
bus_name = dbus.service.BusName("se.recompile.Mandos",
2177
bus, do_not_queue=True)
2178
old_bus_name = (dbus.service.BusName
2179
("se.bsnet.fukt.Mandos", bus,
2181
except dbus.exceptions.NameExistsException as e:
2182
logger.error(unicode(e) + ", disabling D-Bus")
2184
server_settings["use_dbus"] = False
2185
tcp_server.use_dbus = False
2186
protocol = avahi.PROTO_INET6 if use_ipv6 else avahi.PROTO_INET
2187
service = AvahiServiceToSyslog(name =
2188
server_settings["servicename"],
2189
servicetype = "_mandos._tcp",
2190
protocol = protocol, bus = bus)
2191
if server_settings["interface"]:
2192
service.interface = (if_nametoindex
2193
(str(server_settings["interface"])))
2195
global multiprocessing_manager
2196
multiprocessing_manager = multiprocessing.Manager()
2198
client_class = Client
2200
client_class = functools.partial(ClientDBusTransitional,
2203
client_settings = Client.config_parser(client_config)
2204
old_client_settings = {}
2207
# Get client data and settings from last running state.
2208
if server_settings["restore"]:
2210
with open(stored_state_path, "rb") as stored_state:
2211
clients_data, old_client_settings = (pickle.load
2213
os.remove(stored_state_path)
2214
except IOError as e:
2215
logger.warning("Could not load persistent state: {0}"
2217
if e.errno != errno.ENOENT:
2219
except EOFError as e:
2220
logger.warning("Could not load persistent state: "
2221
"EOFError: {0}".format(e))
2223
with PGPEngine() as pgp:
2224
for client_name, client in clients_data.iteritems():
2225
# Decide which value to use after restoring saved state.
2226
# We have three different values: Old config file,
2227
# new config file, and saved state.
2228
# New config value takes precedence if it differs from old
2229
# config value, otherwise use saved state.
2230
for name, value in client_settings[client_name].items():
2232
# For each value in new config, check if it
2233
# differs from the old config value (Except for
2234
# the "secret" attribute)
2235
if (name != "secret" and
2236
value != old_client_settings[client_name]
2238
client[name] = value
2242
# Clients who has passed its expire date can still be
2243
# enabled if its last checker was successful. Clients
2244
# whose checker failed before we stored its state is
2245
# assumed to have failed all checkers during downtime.
2246
if client["enabled"]:
2247
if datetime.datetime.utcnow() >= client["expires"]:
2248
if not client["last_checked_ok"]:
2250
"disabling client {0} - Client never "
2251
"performed a successfull checker"
2252
.format(client["name"]))
2253
client["enabled"] = False
2254
elif client["last_checker_status"] != 0:
2256
"disabling client {0} - Client "
2257
"last checker failed with error code {1}"
2258
.format(client["name"],
2259
client["last_checker_status"]))
2260
client["enabled"] = False
2262
client["expires"] = (datetime.datetime
2264
+ client["timeout"])
2267
client["secret"] = (
2268
pgp.decrypt(client["encrypted_secret"],
2269
client_settings[client_name]
2272
# If decryption fails, we use secret from new settings
2273
logger.debug("Failed to decrypt {0} old secret"
2274
.format(client_name))
2275
client["secret"] = (
2276
client_settings[client_name]["secret"])
2279
# Add/remove clients based on new changes made to config
2280
for client_name in set(old_client_settings) - set(client_settings):
2281
del clients_data[client_name]
2282
for client_name in set(client_settings) - set(old_client_settings):
2283
clients_data[client_name] = client_settings[client_name]
2285
# Create clients all clients
2286
for client_name, client in clients_data.iteritems():
2287
tcp_server.clients[client_name] = client_class(
2288
name = client_name, settings = client)
2290
if not tcp_server.clients:
2291
logger.warning("No clients defined")
1034
bus_name = dbus.service.BusName(u"org.mandos-system.Mandos", bus)
1036
clients.update(Set(Client(name = section,
1038
= dict(client_config.items(section)))
1039
for section in client_config.sections()))
1041
logger.critical(u"No clients defined")
1045
# Redirect stdin so all checkers get /dev/null
1046
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1047
os.dup2(null, sys.stdin.fileno())
1051
# No console logging
1052
logger.removeHandler(console)
1053
# Close all input and output, do double fork, etc.
1058
pidfile.write(str(pid) + "\n")
1062
logger.error(u"Could not write to file %r with PID %d",
1065
# "pidfile" was never created
1070
"Cleanup function; run on exit"
1072
# From the Avahi example code
1073
if not group is None:
1076
# End of Avahi example code
1079
client = clients.pop()
1080
client.stop_hook = None
1083
atexit.register(cleanup)
2297
pidfile.write(str(pid) + "\n".encode("utf-8"))
2300
logger.error("Could not write to file %r with PID %d",
2303
# "pidfile" was never created
2306
1086
signal.signal(signal.SIGINT, signal.SIG_IGN)
2308
1087
signal.signal(signal.SIGHUP, lambda signum, frame: sys.exit())
2309
1088
signal.signal(signal.SIGTERM, lambda signum, frame: sys.exit())
2312
class MandosDBusService(dbus.service.Object):
2313
"""A D-Bus proxy object"""
2315
dbus.service.Object.__init__(self, bus, "/")
2316
_interface = "se.recompile.Mandos"
2318
@dbus.service.signal(_interface, signature="o")
2319
def ClientAdded(self, objpath):
2323
@dbus.service.signal(_interface, signature="ss")
2324
def ClientNotFound(self, fingerprint, address):
2328
@dbus.service.signal(_interface, signature="os")
2329
def ClientRemoved(self, objpath, name):
2333
@dbus.service.method(_interface, out_signature="ao")
2334
def GetAllClients(self):
2336
return dbus.Array(c.dbus_object_path
2338
tcp_server.clients.itervalues())
2340
@dbus.service.method(_interface,
2341
out_signature="a{oa{sv}}")
2342
def GetAllClientsWithProperties(self):
2344
return dbus.Dictionary(
2345
((c.dbus_object_path, c.GetAll(""))
2346
for c in tcp_server.clients.itervalues()),
2349
@dbus.service.method(_interface, in_signature="o")
2350
def RemoveClient(self, object_path):
2352
for c in tcp_server.clients.itervalues():
2353
if c.dbus_object_path == object_path:
2354
del tcp_server.clients[c.name]
2355
c.remove_from_connection()
2356
# Don't signal anything except ClientRemoved
2357
c.disable(quiet=True)
2359
self.ClientRemoved(object_path, c.name)
2361
raise KeyError(object_path)
2365
class MandosDBusServiceTransitional(MandosDBusService):
2366
__metaclass__ = AlternateDBusNamesMetaclass
2367
mandos_dbus_service = MandosDBusServiceTransitional()
2370
"Cleanup function; run on exit"
2373
multiprocessing.active_children()
2374
if not (tcp_server.clients or client_settings):
2377
# Store client before exiting. Secrets are encrypted with key
2378
# based on what config file has. If config file is
2379
# removed/edited, old secret will thus be unrecovable.
2381
with PGPEngine() as pgp:
2382
for client in tcp_server.clients.itervalues():
2383
key = client_settings[client.name]["secret"]
2384
client.encrypted_secret = pgp.encrypt(client.secret,
2388
# A list of attributes that can not be pickled
2390
exclude = set(("bus", "changedstate", "secret",
2392
for name, typ in (inspect.getmembers
2393
(dbus.service.Object)):
2396
client_dict["encrypted_secret"] = (client
2398
for attr in client.client_structure:
2399
if attr not in exclude:
2400
client_dict[attr] = getattr(client, attr)
2402
clients[client.name] = client_dict
2403
del client_settings[client.name]["secret"]
2406
tempfd, tempname = tempfile.mkstemp(suffix=".pickle",
2409
(stored_state_path))
2410
with os.fdopen(tempfd, "wb") as stored_state:
2411
pickle.dump((clients, client_settings), stored_state)
2412
os.rename(tempname, stored_state_path)
2413
except (IOError, OSError) as e:
2414
logger.warning("Could not save persistent state: {0}"
2421
if e.errno not in set((errno.ENOENT, errno.EACCES,
2425
# Delete all clients, and settings from config
2426
while tcp_server.clients:
2427
name, client = tcp_server.clients.popitem()
2429
client.remove_from_connection()
2430
# Don't signal anything except ClientRemoved
2431
client.disable(quiet=True)
2434
mandos_dbus_service.ClientRemoved(client
2437
client_settings.clear()
2439
atexit.register(cleanup)
2441
for client in tcp_server.clients.itervalues():
2444
mandos_dbus_service.ClientAdded(client.dbus_object_path)
2445
# Need to initiate checking of clients
2447
client.init_checker()
1090
class MandosServer(dbus.service.Object):
1091
"""A D-Bus proxy object"""
1093
dbus.service.Object.__init__(self, bus,
1095
_interface = u"org.mandos_system.Mandos"
1097
@dbus.service.signal(_interface, signature="oa{sv}")
1098
def ClientAdded(self, objpath, properties):
1102
@dbus.service.signal(_interface, signature="o")
1103
def ClientRemoved(self, objpath):
1107
@dbus.service.method(_interface, out_signature="ao")
1108
def GetAllClients(self):
1109
return dbus.Array(c.dbus_object_path for c in clients)
1111
@dbus.service.method(_interface, out_signature="a{oa{sv}}")
1112
def GetAllClientsWithProperties(self):
1113
return dbus.Dictionary(
1114
((c.dbus_object_path, c.GetAllProperties())
1118
@dbus.service.method(_interface, in_signature="o")
1119
def RemoveClient(self, object_path):
1121
if c.dbus_object_path == object_path:
1129
mandos_server = MandosServer()
1131
for client in clients:
1133
mandos_server.ClientAdded(client.dbus_object_path,
1134
client.GetAllProperties())
2449
1137
tcp_server.enable()
2450
1138
tcp_server.server_activate()
2452
1140
# Find out what port we got
2453
1141
service.port = tcp_server.socket.getsockname()[1]
2455
logger.info("Now listening on address %r, port %d,"
2456
" flowinfo %d, scope_id %d"
2457
% tcp_server.socket.getsockname())
2459
logger.info("Now listening on address %r, port %d"
2460
% tcp_server.socket.getsockname())
1142
logger.info(u"Now listening on address %r, port %d, flowinfo %d,"
1143
u" scope_id %d" % tcp_server.socket.getsockname())
2462
1145
#service.interface = tcp_server.socket.getsockname()[3]
2465
1148
# From the Avahi example code
1149
server.connect_to_signal("StateChanged", server_state_changed)
2468
except dbus.exceptions.DBusException as error:
2469
logger.critical("DBusException: %s", error)
1151
server_state_changed(server.GetState())
1152
except dbus.exceptions.DBusException, error:
1153
logger.critical(u"DBusException: %s", error)
2472
1155
# End of Avahi example code