45
14
import gnutls.library.functions
46
15
import gnutls.library.constants
47
16
import gnutls.library.types
48
import ConfigParser as configparser
57
import logging.handlers
63
import cPickle as pickle
64
import multiprocessing
71
28
from dbus.mainloop.glib import DBusGMainLoop
74
import xml.dom.minidom
78
SO_BINDTODEVICE = socket.SO_BINDTODEVICE
79
except AttributeError:
81
from IN import SO_BINDTODEVICE
83
SO_BINDTODEVICE = None
88
#logger = logging.getLogger('mandos')
32
import logging.handlers
34
# logghandler.setFormatter(logging.Formatter('%(levelname)s %(message)s')
89
36
logger = logging.Logger('mandos')
90
syslogger = (logging.handlers.SysLogHandler
91
(facility = logging.handlers.SysLogHandler.LOG_DAEMON,
92
address = str("/dev/log")))
93
syslogger.setFormatter(logging.Formatter
94
('Mandos [%(process)d]: %(levelname)s:'
96
logger.addHandler(syslogger)
98
console = logging.StreamHandler()
99
console.setFormatter(logging.Formatter('%(name)s [%(process)d]:'
102
logger.addHandler(console)
104
class AvahiError(Exception):
105
def __init__(self, value, *args, **kwargs):
107
super(AvahiError, self).__init__(value, *args, **kwargs)
108
def __unicode__(self):
109
return unicode(repr(self.value))
111
class AvahiServiceError(AvahiError):
114
class AvahiGroupError(AvahiError):
118
class AvahiService(object):
119
"""An Avahi (Zeroconf) service.
122
interface: integer; avahi.IF_UNSPEC or an interface index.
123
Used to optionally bind to the specified interface.
124
name: string; Example: 'Mandos'
125
type: string; Example: '_mandos._tcp'.
126
See <http://www.dns-sd.org/ServiceTypes.html>
127
port: integer; what port to announce
128
TXT: list of strings; TXT record for the service
129
domain: string; Domain to publish on, default to .local if empty.
130
host: string; Host to publish records for, default is localhost
131
max_renames: integer; maximum number of renames
132
rename_count: integer; counter so we only rename after collisions
133
a sensible number of times
134
group: D-Bus Entry Group
136
bus: dbus.SystemBus()
138
def __init__(self, interface = avahi.IF_UNSPEC, name = None,
139
servicetype = None, port = None, TXT = None,
140
domain = "", host = "", max_renames = 32768,
141
protocol = avahi.PROTO_UNSPEC, bus = None):
142
self.interface = interface
144
self.type = servicetype
146
self.TXT = TXT if TXT is not None else []
149
self.rename_count = 0
150
self.max_renames = max_renames
151
self.protocol = protocol
152
self.group = None # our entry group
155
self.entry_group_state_changed_match = None
157
"""Derived from the Avahi example code"""
158
if self.rename_count >= self.max_renames:
159
logger.critical("No suitable Zeroconf service name found"
160
" after %i retries, exiting.",
162
raise AvahiServiceError("Too many renames")
163
self.name = unicode(self.server.GetAlternativeServiceName(self.name))
164
logger.info("Changing Zeroconf service name to %r ...",
166
syslogger.setFormatter(logging.Formatter
167
('Mandos (%s) [%%(process)d]:'
168
' %%(levelname)s: %%(message)s'
173
except dbus.exceptions.DBusException as error:
174
logger.critical("DBusException: %s", error)
177
self.rename_count += 1
179
"""Derived from the Avahi example code"""
180
if self.entry_group_state_changed_match is not None:
181
self.entry_group_state_changed_match.remove()
182
self.entry_group_state_changed_match = None
183
if self.group is not None:
186
"""Derived from the Avahi example code"""
188
if self.group is None:
189
self.group = dbus.Interface(
190
self.bus.get_object(avahi.DBUS_NAME,
191
self.server.EntryGroupNew()),
192
avahi.DBUS_INTERFACE_ENTRY_GROUP)
193
self.entry_group_state_changed_match = (
194
self.group.connect_to_signal(
195
'StateChanged', self .entry_group_state_changed))
196
logger.debug("Adding Zeroconf service '%s' of type '%s' ...",
197
self.name, self.type)
198
self.group.AddService(
201
dbus.UInt32(0), # flags
202
self.name, self.type,
203
self.domain, self.host,
204
dbus.UInt16(self.port),
205
avahi.string_array_to_txt_array(self.TXT))
207
def entry_group_state_changed(self, state, error):
208
"""Derived from the Avahi example code"""
209
logger.debug("Avahi entry group state change: %i", state)
211
if state == avahi.ENTRY_GROUP_ESTABLISHED:
212
logger.debug("Zeroconf service established.")
213
elif state == avahi.ENTRY_GROUP_COLLISION:
214
logger.info("Zeroconf service name collision.")
216
elif state == avahi.ENTRY_GROUP_FAILURE:
217
logger.critical("Avahi: Error in group state changed %s",
219
raise AvahiGroupError("State changed: %s"
222
"""Derived from the Avahi example code"""
223
if self.group is not None:
226
except (dbus.exceptions.UnknownMethodException,
227
dbus.exceptions.DBusException) as e:
231
def server_state_changed(self, state, error=None):
232
"""Derived from the Avahi example code"""
233
logger.debug("Avahi server state change: %i", state)
234
bad_states = { avahi.SERVER_INVALID:
235
"Zeroconf server invalid",
236
avahi.SERVER_REGISTERING: None,
237
avahi.SERVER_COLLISION:
238
"Zeroconf server name collision",
239
avahi.SERVER_FAILURE:
240
"Zeroconf server failure" }
241
if state in bad_states:
242
if bad_states[state] is not None:
244
logger.error(bad_states[state])
246
logger.error(bad_states[state] + ": %r", error)
248
elif state == avahi.SERVER_RUNNING:
252
logger.debug("Unknown state: %r", state)
254
logger.debug("Unknown state: %r: %r", state, error)
256
"""Derived from the Avahi example code"""
257
if self.server is None:
258
self.server = dbus.Interface(
259
self.bus.get_object(avahi.DBUS_NAME,
260
avahi.DBUS_PATH_SERVER,
261
follow_name_owner_changes=True),
262
avahi.DBUS_INTERFACE_SERVER)
263
self.server.connect_to_signal("StateChanged",
264
self.server_state_changed)
265
self.server_state_changed(self.server.GetState())
268
def _timedelta_to_milliseconds(td):
269
"Convert a datetime.timedelta() to milliseconds"
270
return ((td.days * 24 * 60 * 60 * 1000)
271
+ (td.seconds * 1000)
272
+ (td.microseconds // 1000))
37
logger.addHandler(logging.handlers.SysLogHandler(facility = logging.handlers.SysLogHandler.LOG_DAEMON))
39
# This variable is used to optionally bind to a specified interface.
40
# It is a global variable to fit in with the other variables from the
41
# Avahi server example code.
42
serviceInterface = avahi.IF_UNSPEC
43
# From the Avahi server example code:
44
serviceName = "Mandos"
45
serviceType = "_mandos._tcp" # http://www.dns-sd.org/ServiceTypes.html
46
servicePort = None # Not known at startup
47
serviceTXT = [] # TXT record for the service
48
domain = "" # Domain to publish on, default to .local
49
host = "" # Host to publish records for, default to localhost
50
group = None #our entry group
51
rename_count = 12 # Counter so we only rename after collisions a
52
# sensible number of times
53
# End of Avahi example code
274
56
class Client(object):
275
57
"""A representation of a client host served by this server.
278
_approved: bool(); 'None' if not yet approved/disapproved
279
approval_delay: datetime.timedelta(); Time to wait for approval
280
approval_duration: datetime.timedelta(); Duration of one approval
281
checker: subprocess.Popen(); a running checker process used
282
to see if the client lives.
283
'None' if no process is running.
284
checker_callback_tag: a gobject event source tag, or None
285
checker_command: string; External command which is run to check
286
if client lives. %() expansions are done at
59
name: string; from the config file, used in log messages
60
fingerprint: string (40 or 32 hexadecimal digits); used to
61
uniquely identify the client
62
secret: bytestring; sent verbatim (over TLS) to client
63
fqdn: string (FQDN); available for use by the checker command
64
created: datetime.datetime()
65
last_seen: datetime.datetime() or None if not yet seen
66
timeout: datetime.timedelta(); How long from last_seen until
67
this client is invalid
68
interval: datetime.timedelta(); How often to start a new checker
69
stop_hook: If set, called by stop() as stop_hook(self)
70
checker: subprocess.Popen(); a running checker process used
71
to see if the client lives.
72
Is None if no process is running.
73
checker_initiator_tag: a gobject event source tag, or None
74
stop_initiator_tag: - '' -
75
checker_callback_tag: - '' -
76
checker_command: string; External command which is run to check if
77
client lives. %()s expansions are done at
287
78
runtime with vars(self) as dict, so that for
288
79
instance %(name)s can be used in the command.
289
checker_initiator_tag: a gobject event source tag, or None
290
created: datetime.datetime(); (UTC) object creation
291
current_checker_command: string; current running checker_command
292
disable_hook: If set, called by disable() as disable_hook(self)
293
disable_initiator_tag: a gobject event source tag, or None
295
fingerprint: string (40 or 32 hexadecimal digits); used to
296
uniquely identify the client
297
host: string; available for use by the checker command
298
interval: datetime.timedelta(); How often to start a new checker
299
last_approval_request: datetime.datetime(); (UTC) or None
300
last_checked_ok: datetime.datetime(); (UTC) or None
301
last_enabled: datetime.datetime(); (UTC)
302
name: string; from the config file, used in log messages and
304
secret: bytestring; sent verbatim (over TLS) to client
305
timeout: datetime.timedelta(); How long from last_checked_ok
306
until this client is disabled
307
extended_timeout: extra long timeout when password has been sent
308
runtime_expansions: Allowed attributes for runtime expansion.
309
expires: datetime.datetime(); time (UTC) when a client will be
81
_timeout: Real variable for 'timeout'
82
_interval: Real variable for 'interval'
83
_timeout_milliseconds: Used by gobject.timeout_add()
84
_interval_milliseconds: - '' -
313
runtime_expansions = ("approval_delay", "approval_duration",
314
"created", "enabled", "fingerprint",
315
"host", "interval", "last_checked_ok",
316
"last_enabled", "name", "timeout")
318
def timeout_milliseconds(self):
319
"Return the 'timeout' attribute in milliseconds"
320
return _timedelta_to_milliseconds(self.timeout)
322
def extended_timeout_milliseconds(self):
323
"Return the 'extended_timeout' attribute in milliseconds"
324
return _timedelta_to_milliseconds(self.extended_timeout)
326
def interval_milliseconds(self):
327
"Return the 'interval' attribute in milliseconds"
328
return _timedelta_to_milliseconds(self.interval)
330
def approval_delay_milliseconds(self):
331
return _timedelta_to_milliseconds(self.approval_delay)
333
def __init__(self, name = None, disable_hook=None, config=None):
334
"""Note: the 'checker' key in 'config' sets the
335
'checker_command' attribute and *not* the 'checker'
86
def _set_timeout(self, timeout):
87
"Setter function for 'timeout' attribute"
88
self._timeout = timeout
89
self._timeout_milliseconds = ((self.timeout.days
90
* 24 * 60 * 60 * 1000)
91
+ (self.timeout.seconds * 1000)
92
+ (self.timeout.microseconds
94
timeout = property(lambda self: self._timeout,
97
def _set_interval(self, interval):
98
"Setter function for 'interval' attribute"
99
self._interval = interval
100
self._interval_milliseconds = ((self.interval.days
101
* 24 * 60 * 60 * 1000)
102
+ (self.interval.seconds
104
+ (self.interval.microseconds
106
interval = property(lambda self: self._interval,
109
def __init__(self, name=None, options=None, stop_hook=None,
110
fingerprint=None, secret=None, secfile=None, fqdn=None,
111
timeout=None, interval=-1, checker=None):
340
logger.debug("Creating client %r", self.name)
341
# Uppercase and remove spaces from fingerprint for later
342
# comparison purposes with return value from the fingerprint()
344
self.fingerprint = (config["fingerprint"].upper()
346
logger.debug(" Fingerprint: %s", self.fingerprint)
347
if "secret" in config:
348
self.secret = config["secret"].decode("base64")
349
elif "secfile" in config:
350
with open(os.path.expanduser(os.path.expandvars
351
(config["secfile"])),
353
self.secret = secfile.read()
355
raise TypeError("No secret or secfile for client %s"
357
self.host = config.get("host", "")
358
self.created = datetime.datetime.utcnow()
360
self.last_approval_request = None
361
self.last_enabled = None
362
self.last_checked_ok = None
363
self.timeout = string_to_delta(config["timeout"])
364
self.extended_timeout = string_to_delta(config["extended_timeout"])
365
self.interval = string_to_delta(config["interval"])
366
self.disable_hook = disable_hook
113
# Uppercase and remove spaces from fingerprint
114
# for later comparison purposes with return value of
115
# the fingerprint() function
116
self.fingerprint = fingerprint.upper().replace(u" ", u"")
118
self.secret = secret.decode(u"base64")
121
self.secret = sf.read()
124
raise RuntimeError(u"No secret or secfile for client %s"
126
self.fqdn = fqdn # string
127
self.created = datetime.datetime.now()
128
self.last_seen = None
130
timeout = options.timeout
131
self.timeout = timeout
133
interval = options.interval
135
interval = string_to_delta(interval)
136
self.interval = interval
137
self.stop_hook = stop_hook
367
138
self.checker = None
368
139
self.checker_initiator_tag = None
369
self.disable_initiator_tag = None
140
self.stop_initiator_tag = None
371
141
self.checker_callback_tag = None
372
self.checker_command = config["checker"]
373
self.current_checker_command = None
374
self.last_connect = None
375
self._approved = None
376
self.approved_by_default = config.get("approved_by_default",
378
self.approvals_pending = 0
379
self.approval_delay = string_to_delta(
380
config["approval_delay"])
381
self.approval_duration = string_to_delta(
382
config["approval_duration"])
383
self.changedstate = multiprocessing_manager.Condition(multiprocessing_manager.Lock())
385
def send_changedstate(self):
386
self.changedstate.acquire()
387
self.changedstate.notify_all()
388
self.changedstate.release()
391
"""Start this client's checker and timeout hooks"""
392
if getattr(self, "enabled", False):
395
self.send_changedstate()
142
self.check_command = checker
144
"""Start this clients checker and timeout hooks"""
396
145
# Schedule a new checker to be started an 'interval' from now,
397
146
# and every interval from then on.
398
self.checker_initiator_tag = (gobject.timeout_add
399
(self.interval_milliseconds(),
401
# Schedule a disable() when 'timeout' has passed
402
self.expires = datetime.datetime.utcnow() + self.timeout
403
self.disable_initiator_tag = (gobject.timeout_add
404
(self.timeout_milliseconds(),
407
self.last_enabled = datetime.datetime.utcnow()
147
self.checker_initiator_tag = gobject.timeout_add\
148
(self._interval_milliseconds,
408
150
# Also start a new checker *right now*.
409
151
self.start_checker()
411
def disable(self, quiet=True):
412
"""Disable this client."""
413
if not getattr(self, "enabled", False):
416
self.send_changedstate()
418
logger.info("Disabling client %s", self.name)
419
if getattr(self, "disable_initiator_tag", False):
420
gobject.source_remove(self.disable_initiator_tag)
421
self.disable_initiator_tag = None
423
if getattr(self, "checker_initiator_tag", False):
152
# Schedule a stop() when 'timeout' has passed
153
self.stop_initiator_tag = gobject.timeout_add\
154
(self._timeout_milliseconds,
158
The possibility that this client might be restarted is left
159
open, but not currently used."""
160
logger.debug(u"Stopping client %s", self.name)
162
if self.stop_initiator_tag:
163
gobject.source_remove(self.stop_initiator_tag)
164
self.stop_initiator_tag = None
165
if self.checker_initiator_tag:
424
166
gobject.source_remove(self.checker_initiator_tag)
425
167
self.checker_initiator_tag = None
426
168
self.stop_checker()
427
if self.disable_hook:
428
self.disable_hook(self)
430
171
# Do not run this again if called by a gobject.timeout_add
433
173
def __del__(self):
434
self.disable_hook = None
437
def checker_callback(self, pid, condition, command):
174
# Some code duplication here and in stop()
175
if hasattr(self, "stop_initiator_tag") \
176
and self.stop_initiator_tag:
177
gobject.source_remove(self.stop_initiator_tag)
178
self.stop_initiator_tag = None
179
if hasattr(self, "checker_initiator_tag") \
180
and self.checker_initiator_tag:
181
gobject.source_remove(self.checker_initiator_tag)
182
self.checker_initiator_tag = None
184
def checker_callback(self, pid, condition):
438
185
"""The checker has completed, so take appropriate actions."""
439
self.checker_callback_tag = None
441
if os.WIFEXITED(condition):
442
exitstatus = os.WEXITSTATUS(condition)
444
logger.info("Checker for %(name)s succeeded",
448
logger.info("Checker for %(name)s failed",
451
logger.warning("Checker for %(name)s crashed?",
186
now = datetime.datetime.now()
187
if os.WIFEXITED(condition) \
188
and (os.WEXITSTATUS(condition) == 0):
189
logger.debug(u"Checker for %(name)s succeeded",
192
gobject.source_remove(self.stop_initiator_tag)
193
self.stop_initiator_tag = gobject.timeout_add\
194
(self._timeout_milliseconds,
196
if not os.WIFEXITED(condition):
197
logger.warning(u"Checker for %(name)s crashed?",
454
def checked_ok(self, timeout=None):
455
"""Bump up the timeout for this client.
457
This should only be called when the client has been seen,
461
timeout = self.timeout
462
self.last_checked_ok = datetime.datetime.utcnow()
463
gobject.source_remove(self.disable_initiator_tag)
464
self.expires = datetime.datetime.utcnow() + timeout
465
self.disable_initiator_tag = (gobject.timeout_add
466
(_timedelta_to_milliseconds(timeout),
469
def need_approval(self):
470
self.last_approval_request = datetime.datetime.utcnow()
200
logger.debug(u"Checker for %(name)s failed",
203
self.checker_callback_tag = None
472
204
def start_checker(self):
473
205
"""Start a new checker subprocess if one is not running.
475
206
If a checker already exists, leave it running and do
477
# The reason for not killing a running checker is that if we
478
# did that, then if a checker (for some reason) started
479
# running slowly and taking more than 'interval' time, the
480
# client would inevitably timeout, since no checker would get
481
# a chance to run to completion. If we instead leave running
482
# checkers alone, the checker would have to take more time
483
# than 'timeout' for the client to be disabled, which is as it
486
# If a checker exists, make sure it is not a zombie
488
pid, status = os.waitpid(self.checker.pid, os.WNOHANG)
489
except (AttributeError, OSError) as error:
490
if (isinstance(error, OSError)
491
and error.errno != errno.ECHILD):
495
logger.warning("Checker was a zombie")
496
gobject.source_remove(self.checker_callback_tag)
497
self.checker_callback(pid, status,
498
self.current_checker_command)
499
# Start a new checker if needed
500
208
if self.checker is None:
209
logger.debug(u"Starting checker for %s",
502
# In case checker_command has exactly one % operator
503
command = self.checker_command % self.host
212
command = self.check_command % self.fqdn
504
213
except TypeError:
505
# Escape attributes for the shell
506
escaped_attrs = dict(
508
re.escape(unicode(str(getattr(self, attr, "")),
512
self.runtime_expansions)
214
escaped_attrs = dict((key, re.escape(str(val)))
216
vars(self).iteritems())
515
command = self.checker_command % escaped_attrs
516
except TypeError as error:
517
logger.error('Could not format string "%s":'
518
' %s', self.checker_command, error)
218
command = self.check_command % escaped_attrs
219
except TypeError, error:
220
logger.critical(u'Could not format string "%s": %s',
221
self.check_command, error)
519
222
return True # Try again later
520
self.current_checker_command = command
522
logger.info("Starting checker %r for %s",
524
# We don't need to redirect stdout and stderr, since
525
# in normal mode, that is already done by daemon(),
526
# and in debug mode we don't want to. (Stdin is
527
# always replaced by /dev/null.)
528
self.checker = subprocess.Popen(command,
531
self.checker_callback_tag = (gobject.child_watch_add
533
self.checker_callback,
535
# The checker may have completed before the gobject
536
# watch was added. Check for this.
537
pid, status = os.waitpid(self.checker.pid, os.WNOHANG)
539
gobject.source_remove(self.checker_callback_tag)
540
self.checker_callback(pid, status, command)
541
except OSError as error:
542
logger.error("Failed to start subprocess: %s",
224
self.checker = subprocess.\
226
stdout=subprocess.PIPE,
227
close_fds=True, shell=True,
229
self.checker_callback_tag = gobject.\
230
child_watch_add(self.checker.pid,
233
except subprocess.OSError, error:
234
logger.error(u"Failed to start subprocess: %s",
544
236
# Re-run this periodically if run by gobject.timeout_add
547
238
def stop_checker(self):
548
239
"""Force the checker process, if any, to stop."""
549
if self.checker_callback_tag:
550
gobject.source_remove(self.checker_callback_tag)
551
self.checker_callback_tag = None
552
if getattr(self, "checker", None) is None:
240
if not hasattr(self, "checker") or self.checker is None:
554
logger.debug("Stopping checker for %(name)s", vars(self))
556
os.kill(self.checker.pid, signal.SIGTERM)
558
#if self.checker.poll() is None:
559
# os.kill(self.checker.pid, signal.SIGKILL)
560
except OSError as error:
561
if error.errno != errno.ESRCH: # No such process
566
def dbus_service_property(dbus_interface, signature="v",
567
access="readwrite", byte_arrays=False):
568
"""Decorators for marking methods of a DBusObjectWithProperties to
569
become properties on the D-Bus.
571
The decorated method will be called with no arguments by "Get"
572
and with one argument by "Set".
574
The parameters, where they are supported, are the same as
575
dbus.service.method, except there is only "signature", since the
576
type from Get() and the type sent to Set() is the same.
578
# Encoding deeply encoded byte arrays is not supported yet by the
579
# "Set" method, so we fail early here:
580
if byte_arrays and signature != "ay":
581
raise ValueError("Byte arrays not supported for non-'ay'"
582
" signature %r" % signature)
584
func._dbus_is_property = True
585
func._dbus_interface = dbus_interface
586
func._dbus_signature = signature
587
func._dbus_access = access
588
func._dbus_name = func.__name__
589
if func._dbus_name.endswith("_dbus_property"):
590
func._dbus_name = func._dbus_name[:-14]
591
func._dbus_get_args_options = {'byte_arrays': byte_arrays }
596
class DBusPropertyException(dbus.exceptions.DBusException):
597
"""A base class for D-Bus property-related exceptions
599
def __unicode__(self):
600
return unicode(str(self))
603
class DBusPropertyAccessException(DBusPropertyException):
604
"""A property's access permissions disallows an operation.
609
class DBusPropertyNotFound(DBusPropertyException):
610
"""An attempt was made to access a non-existing property.
615
class DBusObjectWithProperties(dbus.service.Object):
616
"""A D-Bus object with properties.
618
Classes inheriting from this can use the dbus_service_property
619
decorator to expose methods as D-Bus properties. It exposes the
620
standard Get(), Set(), and GetAll() methods on the D-Bus.
624
def _is_dbus_property(obj):
625
return getattr(obj, "_dbus_is_property", False)
627
def _get_all_dbus_properties(self):
628
"""Returns a generator of (name, attribute) pairs
630
return ((prop.__get__(self)._dbus_name, prop.__get__(self))
631
for cls in self.__class__.__mro__
632
for name, prop in inspect.getmembers(cls, self._is_dbus_property))
634
def _get_dbus_property(self, interface_name, property_name):
635
"""Returns a bound method if one exists which is a D-Bus
636
property with the specified name and interface.
638
for cls in self.__class__.__mro__:
639
for name, value in inspect.getmembers(cls, self._is_dbus_property):
640
if value._dbus_name == property_name and value._dbus_interface == interface_name:
641
return value.__get__(self)
644
raise DBusPropertyNotFound(self.dbus_object_path + ":"
645
+ interface_name + "."
649
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ss",
651
def Get(self, interface_name, property_name):
652
"""Standard D-Bus property Get() method, see D-Bus standard.
654
prop = self._get_dbus_property(interface_name, property_name)
655
if prop._dbus_access == "write":
656
raise DBusPropertyAccessException(property_name)
658
if not hasattr(value, "variant_level"):
660
return type(value)(value, variant_level=value.variant_level+1)
662
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ssv")
663
def Set(self, interface_name, property_name, value):
664
"""Standard D-Bus property Set() method, see D-Bus standard.
666
prop = self._get_dbus_property(interface_name, property_name)
667
if prop._dbus_access == "read":
668
raise DBusPropertyAccessException(property_name)
669
if prop._dbus_get_args_options["byte_arrays"]:
670
# The byte_arrays option is not supported yet on
671
# signatures other than "ay".
672
if prop._dbus_signature != "ay":
674
value = dbus.ByteArray(''.join(unichr(byte)
678
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="s",
679
out_signature="a{sv}")
680
def GetAll(self, interface_name):
681
"""Standard D-Bus property GetAll() method, see D-Bus
684
Note: Will not include properties with access="write".
687
for name, prop in self._get_all_dbus_properties():
689
and interface_name != prop._dbus_interface):
690
# Interface non-empty but did not match
692
# Ignore write-only properties
693
if prop._dbus_access == "write":
696
if not hasattr(value, "variant_level"):
699
all[name] = type(value)(value, variant_level=
700
value.variant_level+1)
701
return dbus.Dictionary(all, signature="sv")
703
@dbus.service.method(dbus.INTROSPECTABLE_IFACE,
705
path_keyword='object_path',
706
connection_keyword='connection')
707
def Introspect(self, object_path, connection):
708
"""Standard D-Bus method, overloaded to insert property tags.
710
xmlstring = dbus.service.Object.Introspect(self, object_path,
713
document = xml.dom.minidom.parseString(xmlstring)
714
def make_tag(document, name, prop):
715
e = document.createElement("property")
716
e.setAttribute("name", name)
717
e.setAttribute("type", prop._dbus_signature)
718
e.setAttribute("access", prop._dbus_access)
720
for if_tag in document.getElementsByTagName("interface"):
721
for tag in (make_tag(document, name, prop)
723
in self._get_all_dbus_properties()
724
if prop._dbus_interface
725
== if_tag.getAttribute("name")):
726
if_tag.appendChild(tag)
727
# Add the names to the return values for the
728
# "org.freedesktop.DBus.Properties" methods
729
if (if_tag.getAttribute("name")
730
== "org.freedesktop.DBus.Properties"):
731
for cn in if_tag.getElementsByTagName("method"):
732
if cn.getAttribute("name") == "Get":
733
for arg in cn.getElementsByTagName("arg"):
734
if (arg.getAttribute("direction")
736
arg.setAttribute("name", "value")
737
elif cn.getAttribute("name") == "GetAll":
738
for arg in cn.getElementsByTagName("arg"):
739
if (arg.getAttribute("direction")
741
arg.setAttribute("name", "props")
742
xmlstring = document.toxml("utf-8")
744
except (AttributeError, xml.dom.DOMException,
745
xml.parsers.expat.ExpatError) as error:
746
logger.error("Failed to override Introspection method",
751
def datetime_to_dbus (dt, variant_level=0):
752
"""Convert a UTC datetime.datetime() to a D-Bus type."""
754
return dbus.String("", variant_level = variant_level)
755
return dbus.String(dt.isoformat(),
756
variant_level=variant_level)
758
class transitional_dbus_metaclass(DBusObjectWithProperties.__metaclass__):
759
def __new__(mcs, name, bases, attr):
760
for attrname, old_dbusobj in inspect.getmembers(bases[0]):
761
new_interface = getattr(old_dbusobj, "_dbus_interface", "").replace("se.bsnet.fukt.", "se.recompile.")
762
if (getattr(old_dbusobj, "_dbus_is_signal", False)
763
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
764
unwrappedfunc = dict(zip(old_dbusobj.func_code.co_freevars,
765
old_dbusobj.__closure__))["func"].cell_contents
766
newfunc = types.FunctionType(unwrappedfunc.func_code,
767
unwrappedfunc.func_globals,
768
unwrappedfunc.func_name,
769
unwrappedfunc.func_defaults,
770
unwrappedfunc.func_closure)
771
new_dbusfunc = dbus.service.signal(
772
new_interface, old_dbusobj._dbus_signature)(newfunc)
773
attr["_transitional_" + attrname] = new_dbusfunc
775
def fixscope(func1, func2):
776
def newcall(*args, **kwargs):
777
func1(*args, **kwargs)
778
func2(*args, **kwargs)
781
attr[attrname] = fixscope(old_dbusobj, new_dbusfunc)
783
elif (getattr(old_dbusobj, "_dbus_is_method", False)
784
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
785
new_dbusfunc = (dbus.service.method
787
old_dbusobj._dbus_in_signature,
788
old_dbusobj._dbus_out_signature)
790
(old_dbusobj.func_code,
791
old_dbusobj.func_globals,
792
old_dbusobj.func_name,
793
old_dbusobj.func_defaults,
794
old_dbusobj.func_closure)))
796
attr[attrname] = new_dbusfunc
797
elif (getattr(old_dbusobj, "_dbus_is_property", False)
798
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
799
new_dbusfunc = (dbus_service_property
801
old_dbusobj._dbus_signature,
802
old_dbusobj._dbus_access,
803
old_dbusobj._dbus_get_args_options["byte_arrays"])
805
(old_dbusobj.func_code,
806
old_dbusobj.func_globals,
807
old_dbusobj.func_name,
808
old_dbusobj.func_defaults,
809
old_dbusobj.func_closure)))
811
attr[attrname] = new_dbusfunc
812
return type.__new__(mcs, name, bases, attr)
814
class ClientDBus(Client, DBusObjectWithProperties):
815
"""A Client class using D-Bus
818
dbus_object_path: dbus.ObjectPath
819
bus: dbus.SystemBus()
822
runtime_expansions = (Client.runtime_expansions
823
+ ("dbus_object_path",))
825
# dbus.service.Object doesn't use super(), so we can't either.
827
def __init__(self, bus = None, *args, **kwargs):
828
self._approvals_pending = 0
830
Client.__init__(self, *args, **kwargs)
831
# Only now, when this client is initialized, can it show up on
833
client_object_name = unicode(self.name).translate(
836
self.dbus_object_path = (dbus.ObjectPath
837
("/clients/" + client_object_name))
838
DBusObjectWithProperties.__init__(self, self.bus,
839
self.dbus_object_path)
841
def notifychangeproperty(transform_func,
842
dbus_name, type_func=lambda x: x,
844
""" Modify a variable so that its a property that announce its
846
transform_fun: Function that takes a value and transform it to
848
dbus_name: DBus name of the variable
849
type_func: Function that transform the value before sending it
851
variant_level: DBus variant level. default: 1
854
def setter(self, value):
855
old_value = real_value[0]
856
real_value[0] = value
857
if hasattr(self, "dbus_object_path"):
858
if type_func(old_value) != type_func(real_value[0]):
859
dbus_value = transform_func(type_func(real_value[0]),
861
self.PropertyChanged(dbus.String(dbus_name),
864
return property(lambda self: real_value[0], setter)
867
expires = notifychangeproperty(datetime_to_dbus, "Expires")
868
approvals_pending = notifychangeproperty(dbus.Boolean,
871
enabled = notifychangeproperty(dbus.Boolean, "Enabled")
872
last_enabled = notifychangeproperty(datetime_to_dbus,
874
checker = notifychangeproperty(dbus.Boolean, "CheckerRunning",
875
type_func = lambda checker: checker is not None)
876
last_checked_ok = notifychangeproperty(datetime_to_dbus,
878
last_approval_request = notifychangeproperty(datetime_to_dbus,
879
"LastApprovalRequest")
880
approved_by_default = notifychangeproperty(dbus.Boolean,
882
approval_delay = notifychangeproperty(dbus.UInt16, "ApprovalDelay",
883
type_func = _timedelta_to_milliseconds)
884
approval_duration = notifychangeproperty(dbus.UInt16, "ApprovalDuration",
885
type_func = _timedelta_to_milliseconds)
886
host = notifychangeproperty(dbus.String, "Host")
887
timeout = notifychangeproperty(dbus.UInt16, "Timeout",
888
type_func = _timedelta_to_milliseconds)
889
extended_timeout = notifychangeproperty(dbus.UInt16, "ExtendedTimeout",
890
type_func = _timedelta_to_milliseconds)
891
interval = notifychangeproperty(dbus.UInt16, "Interval",
892
type_func = _timedelta_to_milliseconds)
893
checker_command = notifychangeproperty(dbus.String, "Checker")
895
del notifychangeproperty
897
def __del__(self, *args, **kwargs):
899
self.remove_from_connection()
902
if hasattr(DBusObjectWithProperties, "__del__"):
903
DBusObjectWithProperties.__del__(self, *args, **kwargs)
904
Client.__del__(self, *args, **kwargs)
906
def checker_callback(self, pid, condition, command,
242
gobject.source_remove(self.checker_callback_tag)
908
243
self.checker_callback_tag = None
244
os.kill(self.checker.pid, signal.SIGTERM)
245
if self.checker.poll() is None:
246
os.kill(self.checker.pid, signal.SIGKILL)
909
247
self.checker = None
910
if os.WIFEXITED(condition):
911
exitstatus = os.WEXITSTATUS(condition)
913
self.CheckerCompleted(dbus.Int16(exitstatus),
914
dbus.Int64(condition),
915
dbus.String(command))
918
self.CheckerCompleted(dbus.Int16(-1),
919
dbus.Int64(condition),
920
dbus.String(command))
922
return Client.checker_callback(self, pid, condition, command,
925
def start_checker(self, *args, **kwargs):
926
old_checker = self.checker
927
if self.checker is not None:
928
old_checker_pid = self.checker.pid
930
old_checker_pid = None
931
r = Client.start_checker(self, *args, **kwargs)
932
# Only if new checker process was started
933
if (self.checker is not None
934
and old_checker_pid != self.checker.pid):
936
self.CheckerStarted(self.current_checker_command)
939
def _reset_approved(self):
940
self._approved = None
943
def approve(self, value=True):
944
self.send_changedstate()
945
self._approved = value
946
gobject.timeout_add(_timedelta_to_milliseconds
947
(self.approval_duration),
948
self._reset_approved)
951
## D-Bus methods, signals & properties
952
_interface = "se.bsnet.fukt.Mandos.Client"
956
# CheckerCompleted - signal
957
@dbus.service.signal(_interface, signature="nxs")
958
def CheckerCompleted(self, exitcode, waitstatus, command):
962
# CheckerStarted - signal
963
@dbus.service.signal(_interface, signature="s")
964
def CheckerStarted(self, command):
968
# PropertyChanged - signal
969
@dbus.service.signal(_interface, signature="sv")
970
def PropertyChanged(self, property, value):
975
@dbus.service.signal(_interface)
978
Is sent after a successful transfer of secret from the Mandos
979
server to mandos-client
984
@dbus.service.signal(_interface, signature="s")
985
def Rejected(self, reason):
989
# NeedApproval - signal
990
@dbus.service.signal(_interface, signature="tb")
991
def NeedApproval(self, timeout, default):
993
return self.need_approval()
998
@dbus.service.method(_interface, in_signature="b")
999
def Approve(self, value):
1002
# CheckedOK - method
1003
@dbus.service.method(_interface)
1004
def CheckedOK(self):
1008
@dbus.service.method(_interface)
1013
# StartChecker - method
1014
@dbus.service.method(_interface)
1015
def StartChecker(self):
1017
self.start_checker()
1020
@dbus.service.method(_interface)
1025
# StopChecker - method
1026
@dbus.service.method(_interface)
1027
def StopChecker(self):
1032
# ApprovalPending - property
1033
@dbus_service_property(_interface, signature="b", access="read")
1034
def ApprovalPending_dbus_property(self):
1035
return dbus.Boolean(bool(self.approvals_pending))
1037
# ApprovedByDefault - property
1038
@dbus_service_property(_interface, signature="b",
1040
def ApprovedByDefault_dbus_property(self, value=None):
1041
if value is None: # get
1042
return dbus.Boolean(self.approved_by_default)
1043
self.approved_by_default = bool(value)
1045
# ApprovalDelay - property
1046
@dbus_service_property(_interface, signature="t",
1048
def ApprovalDelay_dbus_property(self, value=None):
1049
if value is None: # get
1050
return dbus.UInt64(self.approval_delay_milliseconds())
1051
self.approval_delay = datetime.timedelta(0, 0, 0, value)
1053
# ApprovalDuration - property
1054
@dbus_service_property(_interface, signature="t",
1056
def ApprovalDuration_dbus_property(self, value=None):
1057
if value is None: # get
1058
return dbus.UInt64(_timedelta_to_milliseconds(
1059
self.approval_duration))
1060
self.approval_duration = datetime.timedelta(0, 0, 0, value)
1063
@dbus_service_property(_interface, signature="s", access="read")
1064
def Name_dbus_property(self):
1065
return dbus.String(self.name)
1067
# Fingerprint - property
1068
@dbus_service_property(_interface, signature="s", access="read")
1069
def Fingerprint_dbus_property(self):
1070
return dbus.String(self.fingerprint)
1073
@dbus_service_property(_interface, signature="s",
1075
def Host_dbus_property(self, value=None):
1076
if value is None: # get
1077
return dbus.String(self.host)
1080
# Created - property
1081
@dbus_service_property(_interface, signature="s", access="read")
1082
def Created_dbus_property(self):
1083
return dbus.String(datetime_to_dbus(self.created))
1085
# LastEnabled - property
1086
@dbus_service_property(_interface, signature="s", access="read")
1087
def LastEnabled_dbus_property(self):
1088
return datetime_to_dbus(self.last_enabled)
1090
# Enabled - property
1091
@dbus_service_property(_interface, signature="b",
1093
def Enabled_dbus_property(self, value=None):
1094
if value is None: # get
1095
return dbus.Boolean(self.enabled)
1101
# LastCheckedOK - property
1102
@dbus_service_property(_interface, signature="s",
1104
def LastCheckedOK_dbus_property(self, value=None):
1105
if value is not None:
1108
return datetime_to_dbus(self.last_checked_ok)
1110
# Expires - property
1111
@dbus_service_property(_interface, signature="s", access="read")
1112
def Expires_dbus_property(self):
1113
return datetime_to_dbus(self.expires)
1115
# LastApprovalRequest - property
1116
@dbus_service_property(_interface, signature="s", access="read")
1117
def LastApprovalRequest_dbus_property(self):
1118
return datetime_to_dbus(self.last_approval_request)
1120
# Timeout - property
1121
@dbus_service_property(_interface, signature="t",
1123
def Timeout_dbus_property(self, value=None):
1124
if value is None: # get
1125
return dbus.UInt64(self.timeout_milliseconds())
1126
self.timeout = datetime.timedelta(0, 0, 0, value)
1127
if getattr(self, "disable_initiator_tag", None) is None:
1129
# Reschedule timeout
1130
gobject.source_remove(self.disable_initiator_tag)
1131
self.disable_initiator_tag = None
1133
time_to_die = (self.
1134
_timedelta_to_milliseconds((self
1139
if time_to_die <= 0:
1140
# The timeout has passed
1143
self.expires = (datetime.datetime.utcnow()
1144
+ datetime.timedelta(milliseconds = time_to_die))
1145
self.disable_initiator_tag = (gobject.timeout_add
1146
(time_to_die, self.disable))
1148
# ExtendedTimeout - property
1149
@dbus_service_property(_interface, signature="t",
1151
def ExtendedTimeout_dbus_property(self, value=None):
1152
if value is None: # get
1153
return dbus.UInt64(self.extended_timeout_milliseconds())
1154
self.extended_timeout = datetime.timedelta(0, 0, 0, value)
1156
# Interval - property
1157
@dbus_service_property(_interface, signature="t",
1159
def Interval_dbus_property(self, value=None):
1160
if value is None: # get
1161
return dbus.UInt64(self.interval_milliseconds())
1162
self.interval = datetime.timedelta(0, 0, 0, value)
1163
if getattr(self, "checker_initiator_tag", None) is None:
1165
# Reschedule checker run
1166
gobject.source_remove(self.checker_initiator_tag)
1167
self.checker_initiator_tag = (gobject.timeout_add
1168
(value, self.start_checker))
1169
self.start_checker() # Start one now, too
1171
# Checker - property
1172
@dbus_service_property(_interface, signature="s",
1174
def Checker_dbus_property(self, value=None):
1175
if value is None: # get
1176
return dbus.String(self.checker_command)
1177
self.checker_command = value
1179
# CheckerRunning - property
1180
@dbus_service_property(_interface, signature="b",
1182
def CheckerRunning_dbus_property(self, value=None):
1183
if value is None: # get
1184
return dbus.Boolean(self.checker is not None)
1186
self.start_checker()
1190
# ObjectPath - property
1191
@dbus_service_property(_interface, signature="o", access="read")
1192
def ObjectPath_dbus_property(self):
1193
return self.dbus_object_path # is already a dbus.ObjectPath
1196
@dbus_service_property(_interface, signature="ay",
1197
access="write", byte_arrays=True)
1198
def Secret_dbus_property(self, value):
1199
self.secret = str(value)
1204
class ProxyClient(object):
1205
def __init__(self, child_pipe, fpr, address):
1206
self._pipe = child_pipe
1207
self._pipe.send(('init', fpr, address))
1208
if not self._pipe.recv():
1211
def __getattribute__(self, name):
1212
if(name == '_pipe'):
1213
return super(ProxyClient, self).__getattribute__(name)
1214
self._pipe.send(('getattr', name))
1215
data = self._pipe.recv()
1216
if data[0] == 'data':
1218
if data[0] == 'function':
1219
def func(*args, **kwargs):
1220
self._pipe.send(('funcall', name, args, kwargs))
1221
return self._pipe.recv()[1]
1224
def __setattr__(self, name, value):
1225
if(name == '_pipe'):
1226
return super(ProxyClient, self).__setattr__(name, value)
1227
self._pipe.send(('setattr', name, value))
1229
class ClientDBusTransitional(ClientDBus):
1230
__metaclass__ = transitional_dbus_metaclass
1232
class ClientHandler(socketserver.BaseRequestHandler, object):
1233
"""A class to handle client connections.
1235
Instantiated once for each connection to handle it.
248
def still_valid(self, now=None):
249
"""Has the timeout not yet passed for this client?"""
251
now = datetime.datetime.now()
252
if self.last_seen is None:
253
return now < (self.created + self.timeout)
255
return now < (self.last_seen + self.timeout)
258
def peer_certificate(session):
259
# If not an OpenPGP certificate...
260
if gnutls.library.functions.gnutls_certificate_type_get\
261
(session._c_object) \
262
!= gnutls.library.constants.GNUTLS_CRT_OPENPGP:
263
# ...do the normal thing
264
return session.peer_certificate
265
list_size = ctypes.c_uint()
266
cert_list = gnutls.library.functions.gnutls_certificate_get_peers\
267
(session._c_object, ctypes.byref(list_size))
268
if list_size.value == 0:
271
return ctypes.string_at(cert.data, cert.size)
274
def fingerprint(openpgp):
275
# New empty GnuTLS certificate
276
crt = gnutls.library.types.gnutls_openpgp_crt_t()
277
gnutls.library.functions.gnutls_openpgp_crt_init\
279
# New GnuTLS "datum" with the OpenPGP public key
280
datum = gnutls.library.types.gnutls_datum_t\
281
(ctypes.cast(ctypes.c_char_p(openpgp),
282
ctypes.POINTER(ctypes.c_ubyte)),
283
ctypes.c_uint(len(openpgp)))
284
# Import the OpenPGP public key into the certificate
285
ret = gnutls.library.functions.gnutls_openpgp_crt_import\
288
gnutls.library.constants.GNUTLS_OPENPGP_FMT_RAW)
289
# New buffer for the fingerprint
290
buffer = ctypes.create_string_buffer(20)
291
buffer_length = ctypes.c_size_t()
292
# Get the fingerprint from the certificate into the buffer
293
gnutls.library.functions.gnutls_openpgp_crt_get_fingerprint\
294
(crt, ctypes.byref(buffer), ctypes.byref(buffer_length))
295
# Deinit the certificate
296
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
297
# Convert the buffer to a Python bytestring
298
fpr = ctypes.string_at(buffer, buffer_length.value)
299
# Convert the bytestring to hexadecimal notation
300
hex_fpr = u''.join(u"%02X" % ord(char) for char in fpr)
304
class tcp_handler(SocketServer.BaseRequestHandler, object):
305
"""A TCP request handler class.
306
Instantiated by IPv6_TCPServer for each request to handle it.
1236
307
Note: This will run in its own forked process."""
1238
309
def handle(self):
1239
with contextlib.closing(self.server.child_pipe) as child_pipe:
1240
logger.info("TCP connection from: %s",
1241
unicode(self.client_address))
1242
logger.debug("Pipe FD: %d",
1243
self.server.child_pipe.fileno())
1245
session = (gnutls.connection
1246
.ClientSession(self.request,
1248
.X509Credentials()))
1250
# Note: gnutls.connection.X509Credentials is really a
1251
# generic GnuTLS certificate credentials object so long as
1252
# no X.509 keys are added to it. Therefore, we can use it
1253
# here despite using OpenPGP certificates.
1255
#priority = ':'.join(("NONE", "+VERS-TLS1.1",
1256
# "+AES-256-CBC", "+SHA1",
1257
# "+COMP-NULL", "+CTYPE-OPENPGP",
1259
# Use a fallback default, since this MUST be set.
1260
priority = self.server.gnutls_priority
1261
if priority is None:
1263
(gnutls.library.functions
1264
.gnutls_priority_set_direct(session._c_object,
1267
# Start communication using the Mandos protocol
1268
# Get protocol number
1269
line = self.request.makefile().readline()
1270
logger.debug("Protocol version: %r", line)
1272
if int(line.strip().split()[0]) > 1:
1274
except (ValueError, IndexError, RuntimeError) as error:
1275
logger.error("Unknown protocol version: %s", error)
1278
# Start GnuTLS connection
1281
except gnutls.errors.GNUTLSError as error:
1282
logger.warning("Handshake failed: %s", error)
1283
# Do not run session.bye() here: the session is not
1284
# established. Just abandon the request.
1286
logger.debug("Handshake succeeded")
1288
approval_required = False
1291
fpr = self.fingerprint(self.peer_certificate
1294
gnutls.errors.GNUTLSError) as error:
1295
logger.warning("Bad certificate: %s", error)
1297
logger.debug("Fingerprint: %s", fpr)
1300
client = ProxyClient(child_pipe, fpr,
1301
self.client_address)
1305
if client.approval_delay:
1306
delay = client.approval_delay
1307
client.approvals_pending += 1
1308
approval_required = True
1311
if not client.enabled:
1312
logger.info("Client %s is disabled",
1314
if self.server.use_dbus:
1316
client.Rejected("Disabled")
1319
if client._approved or not client.approval_delay:
1320
#We are approved or approval is disabled
1322
elif client._approved is None:
1323
logger.info("Client %s needs approval",
1325
if self.server.use_dbus:
1327
client.NeedApproval(
1328
client.approval_delay_milliseconds(),
1329
client.approved_by_default)
1331
logger.warning("Client %s was not approved",
1333
if self.server.use_dbus:
1335
client.Rejected("Denied")
1338
#wait until timeout or approved
1339
#x = float(client._timedelta_to_milliseconds(delay))
1340
time = datetime.datetime.now()
1341
client.changedstate.acquire()
1342
client.changedstate.wait(float(client._timedelta_to_milliseconds(delay) / 1000))
1343
client.changedstate.release()
1344
time2 = datetime.datetime.now()
1345
if (time2 - time) >= delay:
1346
if not client.approved_by_default:
1347
logger.warning("Client %s timed out while"
1348
" waiting for approval",
1350
if self.server.use_dbus:
1352
client.Rejected("Approval timed out")
1357
delay -= time2 - time
1360
while sent_size < len(client.secret):
1362
sent = session.send(client.secret[sent_size:])
1363
except gnutls.errors.GNUTLSError as error:
1364
logger.warning("gnutls send failed")
1366
logger.debug("Sent: %d, remaining: %d",
1367
sent, len(client.secret)
1368
- (sent_size + sent))
1371
logger.info("Sending secret to %s", client.name)
1372
# bump the timeout as if seen
1373
client.checked_ok(client.extended_timeout)
1374
if self.server.use_dbus:
1379
if approval_required:
1380
client.approvals_pending -= 1
1383
except gnutls.errors.GNUTLSError as error:
1384
logger.warning("GnuTLS bye failed")
1387
def peer_certificate(session):
1388
"Return the peer's OpenPGP certificate as a bytestring"
1389
# If not an OpenPGP certificate...
1390
if (gnutls.library.functions
1391
.gnutls_certificate_type_get(session._c_object)
1392
!= gnutls.library.constants.GNUTLS_CRT_OPENPGP):
1393
# ...do the normal thing
1394
return session.peer_certificate
1395
list_size = ctypes.c_uint(1)
1396
cert_list = (gnutls.library.functions
1397
.gnutls_certificate_get_peers
1398
(session._c_object, ctypes.byref(list_size)))
1399
if not bool(cert_list) and list_size.value != 0:
1400
raise gnutls.errors.GNUTLSError("error getting peer"
1402
if list_size.value == 0:
1405
return ctypes.string_at(cert.data, cert.size)
1408
def fingerprint(openpgp):
1409
"Convert an OpenPGP bytestring to a hexdigit fingerprint"
1410
# New GnuTLS "datum" with the OpenPGP public key
1411
datum = (gnutls.library.types
1412
.gnutls_datum_t(ctypes.cast(ctypes.c_char_p(openpgp),
1415
ctypes.c_uint(len(openpgp))))
1416
# New empty GnuTLS certificate
1417
crt = gnutls.library.types.gnutls_openpgp_crt_t()
1418
(gnutls.library.functions
1419
.gnutls_openpgp_crt_init(ctypes.byref(crt)))
1420
# Import the OpenPGP public key into the certificate
1421
(gnutls.library.functions
1422
.gnutls_openpgp_crt_import(crt, ctypes.byref(datum),
1423
gnutls.library.constants
1424
.GNUTLS_OPENPGP_FMT_RAW))
1425
# Verify the self signature in the key
1426
crtverify = ctypes.c_uint()
1427
(gnutls.library.functions
1428
.gnutls_openpgp_crt_verify_self(crt, 0,
1429
ctypes.byref(crtverify)))
1430
if crtverify.value != 0:
1431
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
1432
raise (gnutls.errors.CertificateSecurityError
1434
# New buffer for the fingerprint
1435
buf = ctypes.create_string_buffer(20)
1436
buf_len = ctypes.c_size_t()
1437
# Get the fingerprint from the certificate into the buffer
1438
(gnutls.library.functions
1439
.gnutls_openpgp_crt_get_fingerprint(crt, ctypes.byref(buf),
1440
ctypes.byref(buf_len)))
1441
# Deinit the certificate
1442
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
1443
# Convert the buffer to a Python bytestring
1444
fpr = ctypes.string_at(buf, buf_len.value)
1445
# Convert the bytestring to hexadecimal notation
1446
hex_fpr = ''.join("%02X" % ord(char) for char in fpr)
1450
class MultiprocessingMixIn(object):
1451
"""Like socketserver.ThreadingMixIn, but with multiprocessing"""
1452
def sub_process_main(self, request, address):
1454
self.finish_request(request, address)
1456
self.handle_error(request, address)
1457
self.close_request(request)
1459
def process_request(self, request, address):
1460
"""Start a new process to process the request."""
1461
multiprocessing.Process(target = self.sub_process_main,
1462
args = (request, address)).start()
1465
class MultiprocessingMixInWithPipe(MultiprocessingMixIn, object):
1466
""" adds a pipe to the MixIn """
1467
def process_request(self, request, client_address):
1468
"""Overrides and wraps the original process_request().
1470
This function creates a new pipe in self.pipe
1472
parent_pipe, self.child_pipe = multiprocessing.Pipe()
1474
super(MultiprocessingMixInWithPipe,
1475
self).process_request(request, client_address)
1476
self.child_pipe.close()
1477
self.add_pipe(parent_pipe)
1479
def add_pipe(self, parent_pipe):
1480
"""Dummy function; override as necessary"""
1481
raise NotImplementedError
1484
class IPv6_TCPServer(MultiprocessingMixInWithPipe,
1485
socketserver.TCPServer, object):
1486
"""IPv6-capable TCP server. Accepts 'None' as address and/or port
310
logger.debug(u"TCP connection from: %s",
311
unicode(self.client_address))
312
session = gnutls.connection.ClientSession(self.request,
316
#priority = ':'.join(("NONE", "+VERS-TLS1.1", "+AES-256-CBC",
317
# "+SHA1", "+COMP-NULL", "+CTYPE-OPENPGP",
319
priority = "SECURE256"
321
gnutls.library.functions.gnutls_priority_set_direct\
322
(session._c_object, priority, None);
326
except gnutls.errors.GNUTLSError, error:
327
logger.debug(u"Handshake failed: %s", error)
328
# Do not run session.bye() here: the session is not
329
# established. Just abandon the request.
332
fpr = fingerprint(peer_certificate(session))
333
except (TypeError, gnutls.errors.GNUTLSError), error:
334
logger.debug(u"Bad certificate: %s", error)
337
logger.debug(u"Fingerprint: %s", fpr)
340
if c.fingerprint == fpr:
343
# Have to check if client.still_valid(), since it is possible
344
# that the client timed out while establishing the GnuTLS
346
if (not client) or (not client.still_valid()):
348
logger.debug(u"Client %(name)s is invalid",
351
logger.debug(u"Client not found for fingerprint: %s",
356
while sent_size < len(client.secret):
357
sent = session.send(client.secret[sent_size:])
358
logger.debug(u"Sent: %d, remaining: %d",
359
sent, len(client.secret)
360
- (sent_size + sent))
365
class IPv6_TCPServer(SocketServer.ForkingTCPServer, object):
366
"""IPv6 TCP server. Accepts 'None' as address and/or port.
1489
enabled: Boolean; whether this server is activated yet
1490
interface: None or a network interface name (string)
1491
use_ipv6: Boolean; to use IPv6 or not
368
options: Command line options
369
clients: Set() of Client objects
1493
def __init__(self, server_address, RequestHandlerClass,
1494
interface=None, use_ipv6=True):
1495
self.interface = interface
1497
self.address_family = socket.AF_INET6
1498
socketserver.TCPServer.__init__(self, server_address,
1499
RequestHandlerClass)
371
address_family = socket.AF_INET6
372
def __init__(self, *args, **kwargs):
373
if "options" in kwargs:
374
self.options = kwargs["options"]
375
del kwargs["options"]
376
if "clients" in kwargs:
377
self.clients = kwargs["clients"]
378
del kwargs["clients"]
379
return super(type(self), self).__init__(*args, **kwargs)
1500
380
def server_bind(self):
1501
381
"""This overrides the normal server_bind() function
1502
382
to bind to an interface if one was specified, and also NOT to
1503
383
bind to an address or port if they were not specified."""
1504
if self.interface is not None:
1505
if SO_BINDTODEVICE is None:
1506
logger.error("SO_BINDTODEVICE does not exist;"
1507
" cannot bind to interface %s",
1511
self.socket.setsockopt(socket.SOL_SOCKET,
1515
except socket.error as error:
1516
if error[0] == errno.EPERM:
1517
logger.error("No permission to"
1518
" bind to interface %s",
1520
elif error[0] == errno.ENOPROTOOPT:
1521
logger.error("SO_BINDTODEVICE not available;"
1522
" cannot bind to interface %s",
384
if self.options.interface:
385
if not hasattr(socket, "SO_BINDTODEVICE"):
386
# From /usr/include/asm-i486/socket.h
387
socket.SO_BINDTODEVICE = 25
389
self.socket.setsockopt(socket.SOL_SOCKET,
390
socket.SO_BINDTODEVICE,
391
self.options.interface)
392
except socket.error, error:
393
if error[0] == errno.EPERM:
394
logger.warning(u"No permission to"
395
u" bind to interface %s",
396
self.options.interface)
1526
399
# Only bind(2) the socket if we really need to.
1527
400
if self.server_address[0] or self.server_address[1]:
1528
401
if not self.server_address[0]:
1529
if self.address_family == socket.AF_INET6:
1530
any_address = "::" # in6addr_any
1532
any_address = socket.INADDR_ANY
1533
self.server_address = (any_address,
403
self.server_address = (in6addr_any,
1534
404
self.server_address[1])
1535
elif not self.server_address[1]:
405
elif self.server_address[1] is None:
1536
406
self.server_address = (self.server_address[0],
1538
# if self.interface:
1539
# self.server_address = (self.server_address[0],
1544
return socketserver.TCPServer.server_bind(self)
1547
class MandosServer(IPv6_TCPServer):
1551
clients: set of Client objects
1552
gnutls_priority GnuTLS priority string
1553
use_dbus: Boolean; to emit D-Bus signals or not
1555
Assumes a gobject.MainLoop event loop.
1557
def __init__(self, server_address, RequestHandlerClass,
1558
interface=None, use_ipv6=True, clients=None,
1559
gnutls_priority=None, use_dbus=True):
1560
self.enabled = False
1561
self.clients = clients
1562
if self.clients is None:
1563
self.clients = set()
1564
self.use_dbus = use_dbus
1565
self.gnutls_priority = gnutls_priority
1566
IPv6_TCPServer.__init__(self, server_address,
1567
RequestHandlerClass,
1568
interface = interface,
1569
use_ipv6 = use_ipv6)
1570
def server_activate(self):
1572
return socketserver.TCPServer.server_activate(self)
1575
def add_pipe(self, parent_pipe):
1576
# Call "handle_ipc" for both data and EOF events
1577
gobject.io_add_watch(parent_pipe.fileno(),
1578
gobject.IO_IN | gobject.IO_HUP,
1579
functools.partial(self.handle_ipc,
1580
parent_pipe = parent_pipe))
1582
def handle_ipc(self, source, condition, parent_pipe=None,
1583
client_object=None):
1585
gobject.IO_IN: "IN", # There is data to read.
1586
gobject.IO_OUT: "OUT", # Data can be written (without
1588
gobject.IO_PRI: "PRI", # There is urgent data to read.
1589
gobject.IO_ERR: "ERR", # Error condition.
1590
gobject.IO_HUP: "HUP" # Hung up (the connection has been
1591
# broken, usually for pipes and
1594
conditions_string = ' | '.join(name
1596
condition_names.iteritems()
1597
if cond & condition)
1598
# error or the other end of multiprocessing.Pipe has closed
1599
if condition & (gobject.IO_ERR | condition & gobject.IO_HUP):
1602
# Read a request from the child
1603
request = parent_pipe.recv()
1604
command = request[0]
1606
if command == 'init':
1608
address = request[2]
1610
for c in self.clients:
1611
if c.fingerprint == fpr:
1615
logger.info("Client not found for fingerprint: %s, ad"
1616
"dress: %s", fpr, address)
1619
mandos_dbus_service.ClientNotFound(fpr, address[0])
1620
parent_pipe.send(False)
1623
gobject.io_add_watch(parent_pipe.fileno(),
1624
gobject.IO_IN | gobject.IO_HUP,
1625
functools.partial(self.handle_ipc,
1626
parent_pipe = parent_pipe,
1627
client_object = client))
1628
parent_pipe.send(True)
1629
# remove the old hook in favor of the new above hook on same fileno
1631
if command == 'funcall':
1632
funcname = request[1]
1636
parent_pipe.send(('data', getattr(client_object, funcname)(*args, **kwargs)))
1638
if command == 'getattr':
1639
attrname = request[1]
1640
if callable(client_object.__getattribute__(attrname)):
1641
parent_pipe.send(('function',))
1643
parent_pipe.send(('data', client_object.__getattribute__(attrname)))
1645
if command == 'setattr':
1646
attrname = request[1]
1648
setattr(client_object, attrname, value)
408
return super(type(self), self).server_bind()
1653
411
def string_to_delta(interval):
1654
412
"""Parse a string and return a datetime.timedelta
1656
414
>>> string_to_delta('7d')
1657
415
datetime.timedelta(7)
1658
416
>>> string_to_delta('60s')
1661
419
datetime.timedelta(0, 3600)
1662
420
>>> string_to_delta('24h')
1663
421
datetime.timedelta(1)
1664
>>> string_to_delta('1w')
422
>>> string_to_delta(u'1w')
1665
423
datetime.timedelta(7)
1666
>>> string_to_delta('5m 30s')
1667
datetime.timedelta(0, 330)
1669
timevalue = datetime.timedelta(0)
1670
for s in interval.split():
1672
suffix = unicode(s[-1])
1675
delta = datetime.timedelta(value)
1677
delta = datetime.timedelta(0, value)
1679
delta = datetime.timedelta(0, 0, 0, 0, value)
1681
delta = datetime.timedelta(0, 0, 0, 0, 0, value)
1683
delta = datetime.timedelta(0, 0, 0, 0, 0, 0, value)
1685
raise ValueError("Unknown suffix %r" % suffix)
1686
except (ValueError, IndexError) as e:
1687
raise ValueError(*(e.args))
426
suffix=unicode(interval[-1])
427
value=int(interval[:-1])
429
delta = datetime.timedelta(value)
431
delta = datetime.timedelta(0, value)
433
delta = datetime.timedelta(0, 0, 0, 0, value)
435
delta = datetime.timedelta(0, 0, 0, 0, 0, value)
437
delta = datetime.timedelta(0, 0, 0, 0, 0, 0, value)
440
except (ValueError, IndexError):
446
"""From the Avahi server example code"""
447
global group, serviceName, serviceType, servicePort, serviceTXT, \
450
group = dbus.Interface(
451
bus.get_object( avahi.DBUS_NAME,
452
server.EntryGroupNew()),
453
avahi.DBUS_INTERFACE_ENTRY_GROUP)
454
group.connect_to_signal('StateChanged',
455
entry_group_state_changed)
456
logger.debug(u"Adding service '%s' of type '%s' ...",
457
serviceName, serviceType)
460
serviceInterface, # interface
461
avahi.PROTO_INET6, # protocol
462
dbus.UInt32(0), # flags
463
serviceName, serviceType,
465
dbus.UInt16(servicePort),
466
avahi.string_array_to_txt_array(serviceTXT))
470
def remove_service():
471
"""From the Avahi server example code"""
474
if not group is None:
478
def server_state_changed(state):
479
"""From the Avahi server example code"""
480
if state == avahi.SERVER_COLLISION:
481
logger.warning(u"Server name collision")
483
elif state == avahi.SERVER_RUNNING:
487
def entry_group_state_changed(state, error):
488
"""From the Avahi server example code"""
489
global serviceName, server, rename_count
491
logger.debug(u"state change: %i", state)
493
if state == avahi.ENTRY_GROUP_ESTABLISHED:
494
logger.debug(u"Service established.")
495
elif state == avahi.ENTRY_GROUP_COLLISION:
497
rename_count = rename_count - 1
499
name = server.GetAlternativeServiceName(name)
500
logger.warning(u"Service name collision, "
501
u"changing name to '%s' ...", name)
506
logger.error(u"No suitable service name found "
507
u"after %i retries, exiting.",
510
elif state == avahi.ENTRY_GROUP_FAILURE:
511
logger.error(u"Error in group state changed %s",
1692
517
def if_nametoindex(interface):
1693
"""Call the C function if_nametoindex(), or equivalent
1695
Note: This function cannot accept a unicode string."""
1696
global if_nametoindex
518
"""Call the C function if_nametoindex()"""
1698
if_nametoindex = (ctypes.cdll.LoadLibrary
1699
(ctypes.util.find_library("c"))
520
libc = ctypes.cdll.LoadLibrary("libc.so.6")
521
return libc.if_nametoindex(interface)
1701
522
except (OSError, AttributeError):
1702
logger.warning("Doing if_nametoindex the hard way")
1703
def if_nametoindex(interface):
1704
"Get an interface index the hard way, i.e. using fcntl()"
1705
SIOCGIFINDEX = 0x8933 # From /usr/include/linux/sockios.h
1706
with contextlib.closing(socket.socket()) as s:
1707
ifreq = fcntl.ioctl(s, SIOCGIFINDEX,
1708
struct.pack(str("16s16x"),
1710
interface_index = struct.unpack(str("I"),
1712
return interface_index
1713
return if_nametoindex(interface)
1716
def daemon(nochdir = False, noclose = False):
1717
"""See daemon(3). Standard BSD Unix function.
1719
This should really exist as os.daemon, but it doesn't (yet)."""
1728
# Close all standard open file descriptors
1729
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1730
if not stat.S_ISCHR(os.fstat(null).st_mode):
1731
raise OSError(errno.ENODEV,
1732
"%s not a character device"
1734
os.dup2(null, sys.stdin.fileno())
1735
os.dup2(null, sys.stdout.fileno())
1736
os.dup2(null, sys.stderr.fileno())
1743
##################################################################
1744
# Parsing of options, both command line and config file
1746
parser = argparse.ArgumentParser()
1747
parser.add_argument("-v", "--version", action="version",
1748
version = "%%(prog)s %s" % version,
1749
help="show version number and exit")
1750
parser.add_argument("-i", "--interface", metavar="IF",
1751
help="Bind to interface IF")
1752
parser.add_argument("-a", "--address",
1753
help="Address to listen for requests on")
1754
parser.add_argument("-p", "--port", type=int,
1755
help="Port number to receive requests on")
1756
parser.add_argument("--check", action="store_true",
1757
help="Run self-test")
1758
parser.add_argument("--debug", action="store_true",
1759
help="Debug mode; run in foreground and log"
1761
parser.add_argument("--debuglevel", metavar="LEVEL",
1762
help="Debug level for stdout output")
1763
parser.add_argument("--priority", help="GnuTLS"
1764
" priority string (see GnuTLS documentation)")
1765
parser.add_argument("--servicename",
1766
metavar="NAME", help="Zeroconf service name")
1767
parser.add_argument("--configdir",
1768
default="/etc/mandos", metavar="DIR",
1769
help="Directory to search for configuration"
1771
parser.add_argument("--no-dbus", action="store_false",
1772
dest="use_dbus", help="Do not provide D-Bus"
1773
" system bus interface")
1774
parser.add_argument("--no-ipv6", action="store_false",
1775
dest="use_ipv6", help="Do not use IPv6")
1776
options = parser.parse_args()
523
if "struct" not in sys.modules:
525
if "fcntl" not in sys.modules:
527
SIOCGIFINDEX = 0x8933 # From /usr/include/linux/sockios.h
529
ifreq = fcntl.ioctl(s, SIOCGIFINDEX,
530
struct.pack("16s16x", interface))
532
interface_index = struct.unpack("I", ifreq[16:20])[0]
533
return interface_index
536
if __name__ == '__main__':
537
parser = OptionParser()
538
parser.add_option("-i", "--interface", type="string",
539
default=None, metavar="IF",
540
help="Bind to interface IF")
541
parser.add_option("--cert", type="string", default="cert.pem",
543
help="Public key certificate PEM file to use")
544
parser.add_option("--key", type="string", default="key.pem",
546
help="Private key PEM file to use")
547
parser.add_option("--ca", type="string", default="ca.pem",
549
help="Certificate Authority certificate PEM file to use")
550
parser.add_option("--crl", type="string", default="crl.pem",
552
help="Certificate Revokation List PEM file to use")
553
parser.add_option("-p", "--port", type="int", default=None,
554
help="Port number to receive requests on")
555
parser.add_option("--timeout", type="string", # Parsed later
557
help="Amount of downtime allowed for clients")
558
parser.add_option("--interval", type="string", # Parsed later
560
help="How often to check that a client is up")
561
parser.add_option("--check", action="store_true", default=False,
562
help="Run self-test")
563
parser.add_option("--debug", action="store_true", default=False,
565
(options, args) = parser.parse_args()
1778
567
if options.check:
1780
569
doctest.testmod()
1783
# Default values for config file for server-global settings
1784
server_defaults = { "interface": "",
1789
"SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP",
1790
"servicename": "Mandos",
1796
# Parse config file for server-global settings
1797
server_config = configparser.SafeConfigParser(server_defaults)
1799
server_config.read(os.path.join(options.configdir,
1801
# Convert the SafeConfigParser object to a dict
1802
server_settings = server_config.defaults()
1803
# Use the appropriate methods on the non-string config options
1804
for option in ("debug", "use_dbus", "use_ipv6"):
1805
server_settings[option] = server_config.getboolean("DEFAULT",
1807
if server_settings["port"]:
1808
server_settings["port"] = server_config.getint("DEFAULT",
1812
# Override the settings from the config file with command line
1814
for option in ("interface", "address", "port", "debug",
1815
"priority", "servicename", "configdir",
1816
"use_dbus", "use_ipv6", "debuglevel"):
1817
value = getattr(options, option)
1818
if value is not None:
1819
server_settings[option] = value
1821
# Force all strings to be unicode
1822
for option in server_settings.keys():
1823
if type(server_settings[option]) is str:
1824
server_settings[option] = unicode(server_settings[option])
1825
# Now we have our good server settings in "server_settings"
1827
##################################################################
1830
debug = server_settings["debug"]
1831
debuglevel = server_settings["debuglevel"]
1832
use_dbus = server_settings["use_dbus"]
1833
use_ipv6 = server_settings["use_ipv6"]
1835
if server_settings["servicename"] != "Mandos":
1836
syslogger.setFormatter(logging.Formatter
1837
('Mandos (%s) [%%(process)d]:'
1838
' %%(levelname)s: %%(message)s'
1839
% server_settings["servicename"]))
1841
# Parse config file with clients
1842
client_defaults = { "timeout": "5m",
1843
"extended_timeout": "15m",
1845
"checker": "fping -q -- %%(host)s",
1847
"approval_delay": "0s",
1848
"approval_duration": "1s",
1850
client_config = configparser.SafeConfigParser(client_defaults)
1851
client_config.read(os.path.join(server_settings["configdir"],
1854
global mandos_dbus_service
1855
mandos_dbus_service = None
1857
tcp_server = MandosServer((server_settings["address"],
1858
server_settings["port"]),
1860
interface=(server_settings["interface"]
1864
server_settings["priority"],
1867
pidfilename = "/var/run/mandos.pid"
1869
pidfile = open(pidfilename, "w")
1871
logger.error("Could not open file %r", pidfilename)
1874
uid = pwd.getpwnam("_mandos").pw_uid
1875
gid = pwd.getpwnam("_mandos").pw_gid
1878
uid = pwd.getpwnam("mandos").pw_uid
1879
gid = pwd.getpwnam("mandos").pw_gid
1882
uid = pwd.getpwnam("nobody").pw_uid
1883
gid = pwd.getpwnam("nobody").pw_gid
1890
except OSError as error:
1891
if error[0] != errno.EPERM:
1894
if not debug and not debuglevel:
1895
syslogger.setLevel(logging.WARNING)
1896
console.setLevel(logging.WARNING)
1898
level = getattr(logging, debuglevel.upper())
1899
syslogger.setLevel(level)
1900
console.setLevel(level)
1903
# Enable all possible GnuTLS debugging
1905
# "Use a log level over 10 to enable all debugging options."
1907
gnutls.library.functions.gnutls_global_set_log_level(11)
1909
@gnutls.library.types.gnutls_log_func
1910
def debug_gnutls(level, string):
1911
logger.debug("GnuTLS: %s", string[:-1])
1913
(gnutls.library.functions
1914
.gnutls_global_set_log_function(debug_gnutls))
1916
# Redirect stdin so all checkers get /dev/null
1917
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1918
os.dup2(null, sys.stdin.fileno())
1922
# No console logging
1923
logger.removeHandler(console)
1925
# Need to fork before connecting to D-Bus
1927
# Close all input and output, do double fork, etc.
1931
# From the Avahi example code
572
# Parse the time arguments
574
options.timeout = string_to_delta(options.timeout)
576
parser.error("option --timeout: Unparseable time")
578
options.interval = string_to_delta(options.interval)
580
parser.error("option --interval: Unparseable time")
583
defaults = { "checker": "sleep 1; fping -q -- %%(fqdn)s" }
584
client_config = ConfigParser.SafeConfigParser(defaults)
585
#client_config.readfp(open("secrets.conf"), "secrets.conf")
586
client_config.read("mandos-clients.conf")
588
# From the Avahi server example code
1932
589
DBusGMainLoop(set_as_default=True )
1933
590
main_loop = gobject.MainLoop()
1934
591
bus = dbus.SystemBus()
1935
# End of Avahi example code
1938
bus_name = dbus.service.BusName("se.bsnet.fukt.Mandos",
1939
bus, do_not_queue=True)
1940
bus_name2 = dbus.service.BusName("se.recompile.Mandos",
1941
bus, do_not_queue=True)
1942
except dbus.exceptions.NameExistsException as e:
1943
logger.error(unicode(e) + ", disabling D-Bus")
1945
server_settings["use_dbus"] = False
1946
tcp_server.use_dbus = False
1947
protocol = avahi.PROTO_INET6 if use_ipv6 else avahi.PROTO_INET
1948
service = AvahiService(name = server_settings["servicename"],
1949
servicetype = "_mandos._tcp",
1950
protocol = protocol, bus = bus)
1951
if server_settings["interface"]:
1952
service.interface = (if_nametoindex
1953
(str(server_settings["interface"])))
1955
global multiprocessing_manager
1956
multiprocessing_manager = multiprocessing.Manager()
1958
client_class = Client
1960
client_class = functools.partial(ClientDBusTransitional, bus = bus)
1961
def client_config_items(config, section):
1962
special_settings = {
1963
"approved_by_default":
1964
lambda: config.getboolean(section,
1965
"approved_by_default"),
1967
for name, value in config.items(section):
1969
yield (name, special_settings[name]())
1973
tcp_server.clients.update(set(
1974
client_class(name = section,
1975
config= dict(client_config_items(
1976
client_config, section)))
1977
for section in client_config.sections()))
1978
if not tcp_server.clients:
1979
logger.warning("No clients defined")
1985
pidfile.write(str(pid) + "\n".encode("utf-8"))
1988
logger.error("Could not write to file %r with PID %d",
1991
# "pidfile" was never created
1995
signal.signal(signal.SIGINT, signal.SIG_IGN)
1997
signal.signal(signal.SIGHUP, lambda signum, frame: sys.exit())
1998
signal.signal(signal.SIGTERM, lambda signum, frame: sys.exit())
2001
class MandosDBusService(dbus.service.Object):
2002
"""A D-Bus proxy object"""
2004
dbus.service.Object.__init__(self, bus, "/")
2005
_interface = "se.bsnet.fukt.Mandos"
2007
@dbus.service.signal(_interface, signature="o")
2008
def ClientAdded(self, objpath):
2012
@dbus.service.signal(_interface, signature="ss")
2013
def ClientNotFound(self, fingerprint, address):
2017
@dbus.service.signal(_interface, signature="os")
2018
def ClientRemoved(self, objpath, name):
2022
@dbus.service.method(_interface, out_signature="ao")
2023
def GetAllClients(self):
2025
return dbus.Array(c.dbus_object_path
2026
for c in tcp_server.clients)
2028
@dbus.service.method(_interface,
2029
out_signature="a{oa{sv}}")
2030
def GetAllClientsWithProperties(self):
2032
return dbus.Dictionary(
2033
((c.dbus_object_path, c.GetAll(""))
2034
for c in tcp_server.clients),
2037
@dbus.service.method(_interface, in_signature="o")
2038
def RemoveClient(self, object_path):
2040
for c in tcp_server.clients:
2041
if c.dbus_object_path == object_path:
2042
tcp_server.clients.remove(c)
2043
c.remove_from_connection()
2044
# Don't signal anything except ClientRemoved
2045
c.disable(quiet=True)
2047
self.ClientRemoved(object_path, c.name)
2049
raise KeyError(object_path)
2053
class MandosDBusServiceTransitional(MandosDBusService):
2054
__metaclass__ = transitional_dbus_metaclass
2055
mandos_dbus_service = MandosDBusServiceTransitional()
2058
"Cleanup function; run on exit"
2061
while tcp_server.clients:
2062
client = tcp_server.clients.pop()
2064
client.remove_from_connection()
2065
client.disable_hook = None
2066
# Don't signal anything except ClientRemoved
2067
client.disable(quiet=True)
2070
mandos_dbus_service.ClientRemoved(client.dbus_object_path,
2073
atexit.register(cleanup)
2075
for client in tcp_server.clients:
2078
mandos_dbus_service.ClientAdded(client.dbus_object_path)
2082
tcp_server.server_activate()
2084
# Find out what port we got
2085
service.port = tcp_server.socket.getsockname()[1]
2087
logger.info("Now listening on address %r, port %d,"
2088
" flowinfo %d, scope_id %d"
2089
% tcp_server.socket.getsockname())
2091
logger.info("Now listening on address %r, port %d"
2092
% tcp_server.socket.getsockname())
2094
#service.interface = tcp_server.socket.getsockname()[3]
592
server = dbus.Interface(
593
bus.get_object( avahi.DBUS_NAME, avahi.DBUS_PATH_SERVER ),
594
avahi.DBUS_INTERFACE_SERVER )
595
# End of Avahi example code
597
debug = options.debug
600
def remove_from_clients(client):
601
clients.remove(client)
603
logger.debug(u"No clients left, exiting")
606
clients.update(Set(Client(name=section, options=options,
607
stop_hook = remove_from_clients,
608
**(dict(client_config\
610
for section in client_config.sections()))
611
for client in clients:
614
tcp_server = IPv6_TCPServer((None, options.port),
618
# Find out what random port we got
619
servicePort = tcp_server.socket.getsockname()[1]
620
logger.debug(u"Now listening on port %d", servicePort)
622
if options.interface is not None:
623
serviceInterface = if_nametoindex(options.interface)
625
# From the Avahi server example code
626
server.connect_to_signal("StateChanged", server_state_changed)
627
server_state_changed(server.GetState())
628
# End of Avahi example code
630
gobject.io_add_watch(tcp_server.fileno(), gobject.IO_IN,
631
lambda *args, **kwargs:
632
tcp_server.handle_request(*args[2:],
2097
# From the Avahi example code
2100
except dbus.exceptions.DBusException as error:
2101
logger.critical("DBusException: %s", error)
2104
# End of Avahi example code
2106
gobject.io_add_watch(tcp_server.fileno(), gobject.IO_IN,
2107
lambda *args, **kwargs:
2108
(tcp_server.handle_request
2109
(*args[2:], **kwargs) or True))
2111
logger.debug("Starting main loop")
2113
except AvahiError as error:
2114
logger.critical("AvahiError: %s", error)
2117
636
except KeyboardInterrupt:
2119
print("", file=sys.stderr)
2120
logger.debug("Server received KeyboardInterrupt")
2121
logger.debug("Server exiting")
2122
# Must run before the D-Bus bus name gets deregistered
2126
if __name__ == '__main__':
641
# From the Avahi server example code
642
if not group is None:
644
# End of Avahi example code
646
for client in clients:
647
client.stop_hook = None