/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos

  • Committer: Teddy Hogeborn
  • Date: 2019-08-23 22:54:03 UTC
  • Revision ID: teddy@recompile.se-20190823225403-vs9qlglgmbt2sihx
Client Debian package: Remove redundant build dependency

Since "systemd" is now included in "Build-Depends", it should be
removed from "Build-Depends-Indep".

* debian/control (Build-Depends-Indep): Remove "systemd".

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
#!/usr/bin/python3 -bI
2
 
# -*- mode: python; after-save-hook: (lambda () (let ((command (if (fboundp 'file-local-name) (file-local-name (buffer-file-name)) (or (file-remote-p (buffer-file-name) 'localname) (buffer-file-name))))) (if (= (progn (if (get-buffer "*Test*") (kill-buffer "*Test*")) (process-file-shell-command (format "%s --check" (shell-quote-argument command)) nil "*Test*")) 0) (let ((w (get-buffer-window "*Test*"))) (if w (delete-window w))) (progn (with-current-buffer "*Test*" (compilation-mode)) (display-buffer "*Test*" '(display-buffer-in-side-window)))))); coding: utf-8 -*-
 
1
#!/usr/bin/python
 
2
# -*- mode: python; coding: utf-8 -*-
3
3
#
4
4
# Mandos server - give out binary blobs to connecting clients.
5
5
#
77
77
import itertools
78
78
import collections
79
79
import codecs
80
 
import unittest
81
80
 
82
81
import dbus
83
82
import dbus.service
92
91
if sys.version_info.major == 2:
93
92
    __metaclass__ = type
94
93
 
95
 
# Show warnings by default
96
 
if not sys.warnoptions:
97
 
    import warnings
98
 
    warnings.simplefilter("default")
99
 
 
100
94
# Try to find the value of SO_BINDTODEVICE:
101
95
try:
102
96
    # This is where SO_BINDTODEVICE is in Python 3.3 (or 3.4?) and
128
122
if sys.version_info < (3, 2):
129
123
    configparser.Configparser = configparser.SafeConfigParser
130
124
 
131
 
version = "1.8.9"
 
125
version = "1.8.8"
132
126
stored_state_file = "clients.pickle"
133
127
 
134
128
logger = logging.getLogger()
135
 
logging.captureWarnings(True)   # Show warnings via the logging system
136
129
syslogger = None
137
130
 
138
131
try:
203
196
            output = subprocess.check_output(["gpgconf"])
204
197
            for line in output.splitlines():
205
198
                name, text, path = line.split(b":")
206
 
                if name == b"gpg":
 
199
                if name == "gpg":
207
200
                    self.gpg = path
208
201
                    break
209
202
        except OSError as e:
214
207
                          '--force-mdc',
215
208
                          '--quiet']
216
209
        # Only GPG version 1 has the --no-use-agent option.
217
 
        if self.gpg == b"gpg" or self.gpg.endswith(b"/gpg"):
 
210
        if self.gpg == "gpg" or self.gpg.endswith("/gpg"):
218
211
            self.gnupgargs.append("--no-use-agent")
219
212
 
220
213
    def __enter__(self):
1053
1046
        # Read return code from connection (see call_pipe)
1054
1047
        returncode = connection.recv()
1055
1048
        connection.close()
1056
 
        if self.checker is not None:
1057
 
            self.checker.join()
 
1049
        self.checker.join()
1058
1050
        self.checker_callback_tag = None
1059
1051
        self.checker = None
1060
1052
 
1151
1143
                kwargs=popen_args)
1152
1144
            self.checker.start()
1153
1145
            self.checker_callback_tag = GLib.io_add_watch(
1154
 
                GLib.IOChannel.unix_new(pipe[0].fileno()),
1155
 
                GLib.PRIORITY_DEFAULT, GLib.IO_IN,
 
1146
                pipe[0].fileno(), GLib.IO_IN,
1156
1147
                self.checker_callback, pipe[0], command)
1157
1148
        # Re-run this periodically if run by GLib.timeout_add
1158
1149
        return True
2682
2673
    def add_pipe(self, parent_pipe, proc):
2683
2674
        # Call "handle_ipc" for both data and EOF events
2684
2675
        GLib.io_add_watch(
2685
 
            GLib.IOChannel.unix_new(parent_pipe.fileno()),
2686
 
            GLib.PRIORITY_DEFAULT, GLib.IO_IN | GLib.IO_HUP,
 
2676
            parent_pipe.fileno(),
 
2677
            GLib.IO_IN | GLib.IO_HUP,
2687
2678
            functools.partial(self.handle_ipc,
2688
2679
                              parent_pipe=parent_pipe,
2689
2680
                              proc=proc))
2727
2718
                return False
2728
2719
 
2729
2720
            GLib.io_add_watch(
2730
 
                GLib.IOChannel.unix_new(parent_pipe.fileno()),
2731
 
                GLib.PRIORITY_DEFAULT, GLib.IO_IN | GLib.IO_HUP,
 
2721
                parent_pipe.fileno(),
 
2722
                GLib.IO_IN | GLib.IO_HUP,
2732
2723
                functools.partial(self.handle_ipc,
2733
2724
                                  parent_pipe=parent_pipe,
2734
2725
                                  proc=proc,
2766
2757
def rfc3339_duration_to_delta(duration):
2767
2758
    """Parse an RFC 3339 "duration" and return a datetime.timedelta
2768
2759
 
2769
 
    >>> rfc3339_duration_to_delta("P7D") == datetime.timedelta(7)
2770
 
    True
2771
 
    >>> rfc3339_duration_to_delta("PT60S") == datetime.timedelta(0, 60)
2772
 
    True
2773
 
    >>> rfc3339_duration_to_delta("PT60M") == datetime.timedelta(0, 3600)
2774
 
    True
2775
 
    >>> rfc3339_duration_to_delta("PT24H") == datetime.timedelta(1)
2776
 
    True
2777
 
    >>> rfc3339_duration_to_delta("P1W") == datetime.timedelta(7)
2778
 
    True
2779
 
    >>> rfc3339_duration_to_delta("PT5M30S") == datetime.timedelta(0, 330)
2780
 
    True
2781
 
    >>> rfc3339_duration_to_delta("P1DT3M20S") == datetime.timedelta(1, 200)
2782
 
    True
 
2760
    >>> rfc3339_duration_to_delta("P7D")
 
2761
    datetime.timedelta(7)
 
2762
    >>> rfc3339_duration_to_delta("PT60S")
 
2763
    datetime.timedelta(0, 60)
 
2764
    >>> rfc3339_duration_to_delta("PT60M")
 
2765
    datetime.timedelta(0, 3600)
 
2766
    >>> rfc3339_duration_to_delta("PT24H")
 
2767
    datetime.timedelta(1)
 
2768
    >>> rfc3339_duration_to_delta("P1W")
 
2769
    datetime.timedelta(7)
 
2770
    >>> rfc3339_duration_to_delta("PT5M30S")
 
2771
    datetime.timedelta(0, 330)
 
2772
    >>> rfc3339_duration_to_delta("P1DT3M20S")
 
2773
    datetime.timedelta(1, 200)
2783
2774
    """
2784
2775
 
2785
2776
    # Parsing an RFC 3339 duration with regular expressions is not
2865
2856
def string_to_delta(interval):
2866
2857
    """Parse a string and return a datetime.timedelta
2867
2858
 
2868
 
    >>> string_to_delta('7d') == datetime.timedelta(7)
2869
 
    True
2870
 
    >>> string_to_delta('60s') == datetime.timedelta(0, 60)
2871
 
    True
2872
 
    >>> string_to_delta('60m') == datetime.timedelta(0, 3600)
2873
 
    True
2874
 
    >>> string_to_delta('24h') == datetime.timedelta(1)
2875
 
    True
2876
 
    >>> string_to_delta('1w') == datetime.timedelta(7)
2877
 
    True
2878
 
    >>> string_to_delta('5m 30s') == datetime.timedelta(0, 330)
2879
 
    True
 
2859
    >>> string_to_delta('7d')
 
2860
    datetime.timedelta(7)
 
2861
    >>> string_to_delta('60s')
 
2862
    datetime.timedelta(0, 60)
 
2863
    >>> string_to_delta('60m')
 
2864
    datetime.timedelta(0, 3600)
 
2865
    >>> string_to_delta('24h')
 
2866
    datetime.timedelta(1)
 
2867
    >>> string_to_delta('1w')
 
2868
    datetime.timedelta(7)
 
2869
    >>> string_to_delta('5m 30s')
 
2870
    datetime.timedelta(0, 330)
2880
2871
    """
2881
2872
 
2882
2873
    try:
2984
2975
 
2985
2976
    options = parser.parse_args()
2986
2977
 
 
2978
    if options.check:
 
2979
        import doctest
 
2980
        fail_count, test_count = doctest.testmod()
 
2981
        sys.exit(os.EX_OK if fail_count == 0 else 1)
 
2982
 
2987
2983
    # Default values for config file for server-global settings
2988
2984
    if gnutls.has_rawpk:
2989
2985
        priority = ("SECURE128:!CTYPE-X.509:+CTYPE-RAWPK:!RSA"
3252
3248
                             if isinstance(s, bytes)
3253
3249
                             else s) for s in
3254
3250
                            value["client_structure"]]
3255
 
                        # .name, .host, and .checker_command
3256
 
                        for k in ("name", "host", "checker_command"):
 
3251
                        # .name & .host
 
3252
                        for k in ("name", "host"):
3257
3253
                            if isinstance(value[k], bytes):
3258
3254
                                value[k] = value[k].decode("utf-8")
3259
3255
                        if "key_id" not in value:
3269
3265
                        for key, value in
3270
3266
                        bytes_old_client_settings.items()}
3271
3267
                    del bytes_old_client_settings
3272
 
                    # .host and .checker_command
 
3268
                    # .host
3273
3269
                    for value in old_client_settings.values():
3274
 
                        for attribute in ("host", "checker_command"):
3275
 
                            if isinstance(value[attribute], bytes):
3276
 
                                value[attribute] = (value[attribute]
3277
 
                                                    .decode("utf-8"))
 
3270
                        if isinstance(value["host"], bytes):
 
3271
                            value["host"] = (value["host"]
 
3272
                                             .decode("utf-8"))
3278
3273
            os.remove(stored_state_path)
3279
3274
        except IOError as e:
3280
3275
            if e.errno == errno.ENOENT:
3605
3600
                sys.exit(1)
3606
3601
            # End of Avahi example code
3607
3602
 
3608
 
        GLib.io_add_watch(
3609
 
            GLib.IOChannel.unix_new(tcp_server.fileno()),
3610
 
            GLib.PRIORITY_DEFAULT, GLib.IO_IN,
3611
 
            lambda *args, **kwargs: (tcp_server.handle_request
3612
 
                                     (*args[2:], **kwargs) or True))
 
3603
        GLib.io_add_watch(tcp_server.fileno(), GLib.IO_IN,
 
3604
                          lambda *args, **kwargs:
 
3605
                          (tcp_server.handle_request
 
3606
                           (*args[2:], **kwargs) or True))
3613
3607
 
3614
3608
        logger.debug("Starting main loop")
3615
3609
        main_loop.run()
3625
3619
    # Must run before the D-Bus bus name gets deregistered
3626
3620
    cleanup()
3627
3621
 
3628
 
 
3629
 
def should_only_run_tests():
3630
 
    parser = argparse.ArgumentParser(add_help=False)
3631
 
    parser.add_argument("--check", action='store_true')
3632
 
    args, unknown_args = parser.parse_known_args()
3633
 
    run_tests = args.check
3634
 
    if run_tests:
3635
 
        # Remove --check argument from sys.argv
3636
 
        sys.argv[1:] = unknown_args
3637
 
    return run_tests
3638
 
 
3639
 
# Add all tests from doctest strings
3640
 
def load_tests(loader, tests, none):
3641
 
    import doctest
3642
 
    tests.addTests(doctest.DocTestSuite())
3643
 
    return tests
3644
3622
 
3645
3623
if __name__ == '__main__':
3646
 
    try:
3647
 
        if should_only_run_tests():
3648
 
            # Call using ./mandos --check [--verbose]
3649
 
            unittest.main()
3650
 
        else:
3651
 
            main()
3652
 
    finally:
3653
 
        logging.shutdown()
 
3624
    main()