57
import logging.handlers
59
from contextlib import closing
65
31
from dbus.mainloop.glib import DBusGMainLoop
35
import logging.handlers
71
37
logger = logging.Logger('mandos')
72
syslogger = (logging.handlers.SysLogHandler
73
(facility = logging.handlers.SysLogHandler.LOG_DAEMON,
74
address = "/dev/log"))
75
syslogger.setFormatter(logging.Formatter
76
('Mandos [%(process)d]: %(levelname)s:'
38
syslogger = logging.handlers.SysLogHandler\
39
(facility = logging.handlers.SysLogHandler.LOG_DAEMON)
40
syslogger.setFormatter(logging.Formatter\
41
('%(levelname)s: %(message)s'))
78
42
logger.addHandler(syslogger)
80
console = logging.StreamHandler()
81
console.setFormatter(logging.Formatter('%(name)s [%(process)d]:'
82
' %(levelname)s: %(message)s'))
83
logger.addHandler(console)
85
class AvahiError(Exception):
86
def __init__(self, value, *args, **kwargs):
88
super(AvahiError, self).__init__(value, *args, **kwargs)
89
def __unicode__(self):
90
return unicode(repr(self.value))
92
class AvahiServiceError(AvahiError):
95
class AvahiGroupError(AvahiError):
99
class AvahiService(object):
100
"""An Avahi (Zeroconf) service.
102
interface: integer; avahi.IF_UNSPEC or an interface index.
103
Used to optionally bind to the specified interface.
104
name: string; Example: 'Mandos'
105
type: string; Example: '_mandos._tcp'.
106
See <http://www.dns-sd.org/ServiceTypes.html>
107
port: integer; what port to announce
108
TXT: list of strings; TXT record for the service
109
domain: string; Domain to publish on, default to .local if empty.
110
host: string; Host to publish records for, default is localhost
111
max_renames: integer; maximum number of renames
112
rename_count: integer; counter so we only rename after collisions
113
a sensible number of times
115
def __init__(self, interface = avahi.IF_UNSPEC, name = None,
116
servicetype = None, port = None, TXT = None,
117
domain = "", host = "", max_renames = 32768,
118
protocol = avahi.PROTO_UNSPEC):
119
self.interface = interface
121
self.type = servicetype
123
self.TXT = TXT if TXT is not None else []
126
self.rename_count = 0
127
self.max_renames = max_renames
128
self.protocol = protocol
130
"""Derived from the Avahi example code"""
131
if self.rename_count >= self.max_renames:
132
logger.critical(u"No suitable Zeroconf service name found"
133
u" after %i retries, exiting.",
135
raise AvahiServiceError(u"Too many renames")
136
self.name = server.GetAlternativeServiceName(self.name)
137
logger.info(u"Changing Zeroconf service name to %r ...",
139
syslogger.setFormatter(logging.Formatter
140
('Mandos (%s) [%%(process)d]:'
141
' %%(levelname)s: %%(message)s'
145
self.rename_count += 1
147
"""Derived from the Avahi example code"""
148
if group is not None:
151
"""Derived from the Avahi example code"""
154
group = dbus.Interface(bus.get_object
156
server.EntryGroupNew()),
157
avahi.DBUS_INTERFACE_ENTRY_GROUP)
158
group.connect_to_signal('StateChanged',
159
entry_group_state_changed)
160
logger.debug(u"Adding Zeroconf service '%s' of type '%s' ...",
161
service.name, service.type)
163
self.interface, # interface
164
self.protocol, # protocol
165
dbus.UInt32(0), # flags
166
self.name, self.type,
167
self.domain, self.host,
168
dbus.UInt16(self.port),
169
avahi.string_array_to_txt_array(self.TXT))
172
# From the Avahi example code:
173
group = None # our entry group
45
# This variable is used to optionally bind to a specified interface.
46
# It is a global variable to fit in with the other variables from the
47
# Avahi server example code.
48
serviceInterface = avahi.IF_UNSPEC
49
# From the Avahi server example code:
50
serviceName = "Mandos"
51
serviceType = "_mandos._tcp" # http://www.dns-sd.org/ServiceTypes.html
52
servicePort = None # Not known at startup
53
serviceTXT = [] # TXT record for the service
54
domain = "" # Domain to publish on, default to .local
55
host = "" # Host to publish records for, default to localhost
56
group = None #our entry group
57
rename_count = 12 # Counter so we only rename after collisions a
58
# sensible number of times
174
59
# End of Avahi example code
177
def _datetime_to_dbus(dt, variant_level=0):
178
"""Convert a UTC datetime.datetime() to a D-Bus type."""
179
return dbus.String(dt.isoformat(), variant_level=variant_level)
182
62
class Client(object):
183
63
"""A representation of a client host served by this server.
185
name: string; from the config file, used in log messages and
65
name: string; from the config file, used in log messages
187
66
fingerprint: string (40 or 32 hexadecimal digits); used to
188
67
uniquely identify the client
189
secret: bytestring; sent verbatim (over TLS) to client
190
host: string; available for use by the checker command
191
created: datetime.datetime(); (UTC) object creation
192
last_enabled: datetime.datetime(); (UTC)
194
last_checked_ok: datetime.datetime(); (UTC) or None
195
timeout: datetime.timedelta(); How long from last_checked_ok
196
until this client is invalid
197
interval: datetime.timedelta(); How often to start a new checker
198
disable_hook: If set, called by disable() as disable_hook(self)
199
checker: subprocess.Popen(); a running checker process used
200
to see if the client lives.
201
'None' if no process is running.
68
secret: bytestring; sent verbatim (over TLS) to client
69
fqdn: string (FQDN); available for use by the checker command
70
created: datetime.datetime()
71
last_seen: datetime.datetime() or None if not yet seen
72
timeout: datetime.timedelta(); How long from last_seen until
73
this client is invalid
74
interval: datetime.timedelta(); How often to start a new checker
75
stop_hook: If set, called by stop() as stop_hook(self)
76
checker: subprocess.Popen(); a running checker process used
77
to see if the client lives.
78
Is None if no process is running.
202
79
checker_initiator_tag: a gobject event source tag, or None
203
disable_initiator_tag: - '' -
80
stop_initiator_tag: - '' -
204
81
checker_callback_tag: - '' -
205
82
checker_command: string; External command which is run to check if
206
client lives. %() expansions are done at
83
client lives. %()s expansions are done at
207
84
runtime with vars(self) as dict, so that for
208
85
instance %(name)s can be used in the command.
209
current_checker_command: string; current running checker_command
87
_timeout: Real variable for 'timeout'
88
_interval: Real variable for 'interval'
89
_timeout_milliseconds: Used by gobject.timeout_add()
90
_interval_milliseconds: - '' -
211
def timeout_milliseconds(self):
212
"Return the 'timeout' attribute in milliseconds"
213
return ((self.timeout.days * 24 * 60 * 60 * 1000)
214
+ (self.timeout.seconds * 1000)
215
+ (self.timeout.microseconds // 1000))
217
def interval_milliseconds(self):
218
"Return the 'interval' attribute in milliseconds"
219
return ((self.interval.days * 24 * 60 * 60 * 1000)
220
+ (self.interval.seconds * 1000)
221
+ (self.interval.microseconds // 1000))
223
def __init__(self, name = None, disable_hook=None, config=None):
224
"""Note: the 'checker' key in 'config' sets the
225
'checker_command' attribute and *not* the 'checker'
92
def _set_timeout(self, timeout):
93
"Setter function for 'timeout' attribute"
94
self._timeout = timeout
95
self._timeout_milliseconds = ((self.timeout.days
96
* 24 * 60 * 60 * 1000)
97
+ (self.timeout.seconds * 1000)
98
+ (self.timeout.microseconds
100
timeout = property(lambda self: self._timeout,
103
def _set_interval(self, interval):
104
"Setter function for 'interval' attribute"
105
self._interval = interval
106
self._interval_milliseconds = ((self.interval.days
107
* 24 * 60 * 60 * 1000)
108
+ (self.interval.seconds
110
+ (self.interval.microseconds
112
interval = property(lambda self: self._interval,
115
def __init__(self, name=None, options=None, stop_hook=None,
116
fingerprint=None, secret=None, secfile=None,
117
fqdn=None, timeout=None, interval=-1, checker=None):
230
logger.debug(u"Creating client %r", self.name)
231
# Uppercase and remove spaces from fingerprint for later
232
# comparison purposes with return value from the fingerprint()
234
self.fingerprint = (config["fingerprint"].upper()
236
logger.debug(u" Fingerprint: %s", self.fingerprint)
237
if "secret" in config:
238
self.secret = config["secret"].decode(u"base64")
239
elif "secfile" in config:
240
with closing(open(os.path.expanduser
242
(config["secfile"])))) as secfile:
243
self.secret = secfile.read()
245
raise TypeError(u"No secret or secfile for client %s"
247
self.host = config.get("host", "")
248
self.created = datetime.datetime.utcnow()
250
self.last_enabled = None
251
self.last_checked_ok = None
252
self.timeout = string_to_delta(config["timeout"])
253
self.interval = string_to_delta(config["interval"])
254
self.disable_hook = disable_hook
119
# Uppercase and remove spaces from fingerprint
120
# for later comparison purposes with return value of
121
# the fingerprint() function
122
self.fingerprint = fingerprint.upper().replace(u" ", u"")
124
self.secret = secret.decode(u"base64")
127
self.secret = sf.read()
130
raise RuntimeError(u"No secret or secfile for client %s"
132
self.fqdn = fqdn # string
133
self.created = datetime.datetime.now()
134
self.last_seen = None
136
self.timeout = options.timeout
138
self.timeout = string_to_delta(timeout)
140
self.interval = options.interval
142
self.interval = string_to_delta(interval)
143
self.stop_hook = stop_hook
255
144
self.checker = None
256
145
self.checker_initiator_tag = None
257
self.disable_initiator_tag = None
146
self.stop_initiator_tag = None
258
147
self.checker_callback_tag = None
259
self.checker_command = config["checker"]
260
self.current_checker_command = None
261
self.last_connect = None
264
"""Start this client's checker and timeout hooks"""
265
self.last_enabled = datetime.datetime.utcnow()
148
self.check_command = checker
150
"""Start this clients checker and timeout hooks"""
266
151
# Schedule a new checker to be started an 'interval' from now,
267
152
# and every interval from then on.
268
self.checker_initiator_tag = (gobject.timeout_add
269
(self.interval_milliseconds(),
153
self.checker_initiator_tag = gobject.timeout_add\
154
(self._interval_milliseconds,
271
156
# Also start a new checker *right now*.
272
157
self.start_checker()
273
# Schedule a disable() when 'timeout' has passed
274
self.disable_initiator_tag = (gobject.timeout_add
275
(self.timeout_milliseconds(),
280
"""Disable this client."""
281
if not getattr(self, "enabled", False):
283
logger.info(u"Disabling client %s", self.name)
284
if getattr(self, "disable_initiator_tag", False):
285
gobject.source_remove(self.disable_initiator_tag)
286
self.disable_initiator_tag = None
287
if getattr(self, "checker_initiator_tag", False):
158
# Schedule a stop() when 'timeout' has passed
159
self.stop_initiator_tag = gobject.timeout_add\
160
(self._timeout_milliseconds,
164
The possibility that this client might be restarted is left
165
open, but not currently used."""
166
logger.debug(u"Stopping client %s", self.name)
168
if self.stop_initiator_tag:
169
gobject.source_remove(self.stop_initiator_tag)
170
self.stop_initiator_tag = None
171
if self.checker_initiator_tag:
288
172
gobject.source_remove(self.checker_initiator_tag)
289
173
self.checker_initiator_tag = None
290
174
self.stop_checker()
291
if self.disable_hook:
292
self.disable_hook(self)
294
177
# Do not run this again if called by a gobject.timeout_add
297
179
def __del__(self):
298
self.disable_hook = None
301
def checker_callback(self, pid, condition, command):
180
# Some code duplication here and in stop()
181
if hasattr(self, "stop_initiator_tag") \
182
and self.stop_initiator_tag:
183
gobject.source_remove(self.stop_initiator_tag)
184
self.stop_initiator_tag = None
185
if hasattr(self, "checker_initiator_tag") \
186
and self.checker_initiator_tag:
187
gobject.source_remove(self.checker_initiator_tag)
188
self.checker_initiator_tag = None
190
def checker_callback(self, pid, condition):
302
191
"""The checker has completed, so take appropriate actions."""
303
self.checker_callback_tag = None
305
if os.WIFEXITED(condition):
306
exitstatus = os.WEXITSTATUS(condition)
308
logger.info(u"Checker for %(name)s succeeded",
312
logger.info(u"Checker for %(name)s failed",
192
now = datetime.datetime.now()
193
if os.WIFEXITED(condition) \
194
and (os.WEXITSTATUS(condition) == 0):
195
logger.debug(u"Checker for %(name)s succeeded",
198
gobject.source_remove(self.stop_initiator_tag)
199
self.stop_initiator_tag = gobject.timeout_add\
200
(self._timeout_milliseconds,
202
elif not os.WIFEXITED(condition):
315
203
logger.warning(u"Checker for %(name)s crashed?",
318
def checked_ok(self):
319
"""Bump up the timeout for this client.
320
This should only be called when the client has been seen,
323
self.last_checked_ok = datetime.datetime.utcnow()
324
gobject.source_remove(self.disable_initiator_tag)
325
self.disable_initiator_tag = (gobject.timeout_add
326
(self.timeout_milliseconds(),
206
logger.debug(u"Checker for %(name)s failed",
209
self.checker_callback_tag = None
329
210
def start_checker(self):
330
211
"""Start a new checker subprocess if one is not running.
331
212
If a checker already exists, leave it running and do
333
# The reason for not killing a running checker is that if we
334
# did that, then if a checker (for some reason) started
335
# running slowly and taking more than 'interval' time, the
336
# client would inevitably timeout, since no checker would get
337
# a chance to run to completion. If we instead leave running
338
# checkers alone, the checker would have to take more time
339
# than 'timeout' for the client to be declared invalid, which
340
# is as it should be.
342
# If a checker exists, make sure it is not a zombie
343
if self.checker is not None:
344
pid, status = os.waitpid(self.checker.pid, os.WNOHANG)
346
logger.warning("Checker was a zombie")
347
gobject.source_remove(self.checker_callback_tag)
348
self.checker_callback(pid, status,
349
self.current_checker_command)
350
# Start a new checker if needed
351
214
if self.checker is None:
353
# In case checker_command has exactly one % operator
354
command = self.checker_command % self.host
216
command = self.check_command % self.fqdn
355
217
except TypeError:
356
# Escape attributes for the shell
357
218
escaped_attrs = dict((key, re.escape(str(val)))
359
220
vars(self).iteritems())
361
command = self.checker_command % escaped_attrs
222
command = self.check_command % escaped_attrs
362
223
except TypeError, error:
363
logger.error(u'Could not format string "%s":'
364
u' %s', self.checker_command, error)
224
logger.critical(u'Could not format string "%s":'
225
u' %s', self.check_command, error)
365
226
return True # Try again later
366
self.current_checker_command = command
368
logger.info(u"Starting checker %r for %s",
370
# We don't need to redirect stdout and stderr, since
371
# in normal mode, that is already done by daemon(),
372
# and in debug mode we don't want to. (Stdin is
373
# always replaced by /dev/null.)
374
self.checker = subprocess.Popen(command,
377
self.checker_callback_tag = (gobject.child_watch_add
379
self.checker_callback,
381
# The checker may have completed before the gobject
382
# watch was added. Check for this.
383
pid, status = os.waitpid(self.checker.pid, os.WNOHANG)
385
gobject.source_remove(self.checker_callback_tag)
386
self.checker_callback(pid, status, command)
387
except OSError, error:
228
logger.debug(u"Starting checker %r for %s",
230
self.checker = subprocess.\
232
close_fds=True, shell=True,
234
self.checker_callback_tag = gobject.child_watch_add\
236
self.checker_callback)
237
except subprocess.OSError, error:
388
238
logger.error(u"Failed to start subprocess: %s",
390
240
# Re-run this periodically if run by gobject.timeout_add
393
242
def stop_checker(self):
394
243
"""Force the checker process, if any, to stop."""
395
if self.checker_callback_tag:
396
gobject.source_remove(self.checker_callback_tag)
397
self.checker_callback_tag = None
398
if getattr(self, "checker", None) is None:
244
if not hasattr(self, "checker") or self.checker is None:
400
logger.debug(u"Stopping checker for %(name)s", vars(self))
402
os.kill(self.checker.pid, signal.SIGTERM)
404
#if self.checker.poll() is None:
405
# os.kill(self.checker.pid, signal.SIGKILL)
406
except OSError, error:
407
if error.errno != errno.ESRCH: # No such process
246
gobject.source_remove(self.checker_callback_tag)
247
self.checker_callback_tag = None
248
os.kill(self.checker.pid, signal.SIGTERM)
249
if self.checker.poll() is None:
250
os.kill(self.checker.pid, signal.SIGKILL)
409
251
self.checker = None
411
def still_valid(self):
252
def still_valid(self, now=None):
412
253
"""Has the timeout not yet passed for this client?"""
413
if not getattr(self, "enabled", False):
415
now = datetime.datetime.utcnow()
416
if self.last_checked_ok is None:
255
now = datetime.datetime.now()
256
if self.last_seen is None:
417
257
return now < (self.created + self.timeout)
419
return now < (self.last_checked_ok + self.timeout)
422
class ClientDBus(Client, dbus.service.Object):
423
"""A Client class using D-Bus
425
dbus_object_path: dbus.ObjectPath ; only set if self.use_dbus
427
# dbus.service.Object doesn't use super(), so we can't either.
429
def __init__(self, *args, **kwargs):
430
Client.__init__(self, *args, **kwargs)
431
# Only now, when this client is initialized, can it show up on
433
self.dbus_object_path = (dbus.ObjectPath
435
+ self.name.replace(".", "_")))
436
dbus.service.Object.__init__(self, bus,
437
self.dbus_object_path)
439
oldstate = getattr(self, "enabled", False)
440
r = Client.enable(self)
441
if oldstate != self.enabled:
443
self.PropertyChanged(dbus.String(u"enabled"),
444
dbus.Boolean(True, variant_level=1))
445
self.PropertyChanged(dbus.String(u"last_enabled"),
446
(_datetime_to_dbus(self.last_enabled,
450
def disable(self, signal = True):
451
oldstate = getattr(self, "enabled", False)
452
r = Client.disable(self)
453
if signal and oldstate != self.enabled:
455
self.PropertyChanged(dbus.String(u"enabled"),
456
dbus.Boolean(False, variant_level=1))
459
def __del__(self, *args, **kwargs):
461
self.remove_from_connection()
464
if hasattr(dbus.service.Object, "__del__"):
465
dbus.service.Object.__del__(self, *args, **kwargs)
466
Client.__del__(self, *args, **kwargs)
468
def checker_callback(self, pid, condition, command,
470
self.checker_callback_tag = None
473
self.PropertyChanged(dbus.String(u"checker_running"),
474
dbus.Boolean(False, variant_level=1))
475
if os.WIFEXITED(condition):
476
exitstatus = os.WEXITSTATUS(condition)
478
self.CheckerCompleted(dbus.Int16(exitstatus),
479
dbus.Int64(condition),
480
dbus.String(command))
483
self.CheckerCompleted(dbus.Int16(-1),
484
dbus.Int64(condition),
485
dbus.String(command))
487
return Client.checker_callback(self, pid, condition, command,
490
def checked_ok(self, *args, **kwargs):
491
r = Client.checked_ok(self, *args, **kwargs)
493
self.PropertyChanged(
494
dbus.String(u"last_checked_ok"),
495
(_datetime_to_dbus(self.last_checked_ok,
499
def start_checker(self, *args, **kwargs):
500
old_checker = self.checker
501
if self.checker is not None:
502
old_checker_pid = self.checker.pid
504
old_checker_pid = None
505
r = Client.start_checker(self, *args, **kwargs)
506
# Only if new checker process was started
507
if (self.checker is not None
508
and old_checker_pid != self.checker.pid):
510
self.CheckerStarted(self.current_checker_command)
511
self.PropertyChanged(
512
dbus.String("checker_running"),
513
dbus.Boolean(True, variant_level=1))
516
def stop_checker(self, *args, **kwargs):
517
old_checker = getattr(self, "checker", None)
518
r = Client.stop_checker(self, *args, **kwargs)
519
if (old_checker is not None
520
and getattr(self, "checker", None) is None):
521
self.PropertyChanged(dbus.String(u"checker_running"),
522
dbus.Boolean(False, variant_level=1))
525
## D-Bus methods & signals
526
_interface = u"se.bsnet.fukt.Mandos.Client"
529
CheckedOK = dbus.service.method(_interface)(checked_ok)
530
CheckedOK.__name__ = "CheckedOK"
532
# CheckerCompleted - signal
533
@dbus.service.signal(_interface, signature="nxs")
534
def CheckerCompleted(self, exitcode, waitstatus, command):
538
# CheckerStarted - signal
539
@dbus.service.signal(_interface, signature="s")
540
def CheckerStarted(self, command):
544
# GetAllProperties - method
545
@dbus.service.method(_interface, out_signature="a{sv}")
546
def GetAllProperties(self):
548
return dbus.Dictionary({
550
dbus.String(self.name, variant_level=1),
551
dbus.String("fingerprint"):
552
dbus.String(self.fingerprint, variant_level=1),
554
dbus.String(self.host, variant_level=1),
555
dbus.String("created"):
556
_datetime_to_dbus(self.created, variant_level=1),
557
dbus.String("last_enabled"):
558
(_datetime_to_dbus(self.last_enabled,
560
if self.last_enabled is not None
561
else dbus.Boolean(False, variant_level=1)),
562
dbus.String("enabled"):
563
dbus.Boolean(self.enabled, variant_level=1),
564
dbus.String("last_checked_ok"):
565
(_datetime_to_dbus(self.last_checked_ok,
567
if self.last_checked_ok is not None
568
else dbus.Boolean (False, variant_level=1)),
569
dbus.String("timeout"):
570
dbus.UInt64(self.timeout_milliseconds(),
572
dbus.String("interval"):
573
dbus.UInt64(self.interval_milliseconds(),
575
dbus.String("checker"):
576
dbus.String(self.checker_command,
578
dbus.String("checker_running"):
579
dbus.Boolean(self.checker is not None,
581
dbus.String("object_path"):
582
dbus.ObjectPath(self.dbus_object_path,
586
# IsStillValid - method
587
@dbus.service.method(_interface, out_signature="b")
588
def IsStillValid(self):
589
return self.still_valid()
591
# PropertyChanged - signal
592
@dbus.service.signal(_interface, signature="sv")
593
def PropertyChanged(self, property, value):
597
# ReceivedSecret - signal
598
@dbus.service.signal(_interface)
599
def ReceivedSecret(self):
604
@dbus.service.signal(_interface)
609
# SetChecker - method
610
@dbus.service.method(_interface, in_signature="s")
611
def SetChecker(self, checker):
612
"D-Bus setter method"
613
self.checker_command = checker
615
self.PropertyChanged(dbus.String(u"checker"),
616
dbus.String(self.checker_command,
620
@dbus.service.method(_interface, in_signature="s")
621
def SetHost(self, host):
622
"D-Bus setter method"
625
self.PropertyChanged(dbus.String(u"host"),
626
dbus.String(self.host, variant_level=1))
628
# SetInterval - method
629
@dbus.service.method(_interface, in_signature="t")
630
def SetInterval(self, milliseconds):
631
self.interval = datetime.timedelta(0, 0, 0, milliseconds)
633
self.PropertyChanged(dbus.String(u"interval"),
634
(dbus.UInt64(self.interval_milliseconds(),
638
@dbus.service.method(_interface, in_signature="ay",
640
def SetSecret(self, secret):
641
"D-Bus setter method"
642
self.secret = str(secret)
644
# SetTimeout - method
645
@dbus.service.method(_interface, in_signature="t")
646
def SetTimeout(self, milliseconds):
647
self.timeout = datetime.timedelta(0, 0, 0, milliseconds)
649
self.PropertyChanged(dbus.String(u"timeout"),
650
(dbus.UInt64(self.timeout_milliseconds(),
654
Enable = dbus.service.method(_interface)(enable)
655
Enable.__name__ = "Enable"
657
# StartChecker - method
658
@dbus.service.method(_interface)
659
def StartChecker(self):
664
@dbus.service.method(_interface)
669
# StopChecker - method
670
StopChecker = dbus.service.method(_interface)(stop_checker)
671
StopChecker.__name__ = "StopChecker"
676
class TCP_handler(SocketServer.BaseRequestHandler, object):
259
return now < (self.last_seen + self.timeout)
262
def peer_certificate(session):
263
"Return an OpenPGP data packet string for the peer's certificate"
264
# If not an OpenPGP certificate...
265
if gnutls.library.functions.gnutls_certificate_type_get\
266
(session._c_object) \
267
!= gnutls.library.constants.GNUTLS_CRT_OPENPGP:
268
# ...do the normal thing
269
return session.peer_certificate
270
list_size = ctypes.c_uint()
271
cert_list = gnutls.library.functions.gnutls_certificate_get_peers\
272
(session._c_object, ctypes.byref(list_size))
273
if list_size.value == 0:
276
return ctypes.string_at(cert.data, cert.size)
279
def fingerprint(openpgp):
280
"Convert an OpenPGP data string to a hexdigit fingerprint string"
281
# New empty GnuTLS certificate
282
crt = gnutls.library.types.gnutls_openpgp_crt_t()
283
gnutls.library.functions.gnutls_openpgp_crt_init\
285
# New GnuTLS "datum" with the OpenPGP public key
286
datum = gnutls.library.types.gnutls_datum_t\
287
(ctypes.cast(ctypes.c_char_p(openpgp),
288
ctypes.POINTER(ctypes.c_ubyte)),
289
ctypes.c_uint(len(openpgp)))
290
# Import the OpenPGP public key into the certificate
291
ret = gnutls.library.functions.gnutls_openpgp_crt_import\
294
gnutls.library.constants.GNUTLS_OPENPGP_FMT_RAW)
295
# New buffer for the fingerprint
296
buffer = ctypes.create_string_buffer(20)
297
buffer_length = ctypes.c_size_t()
298
# Get the fingerprint from the certificate into the buffer
299
gnutls.library.functions.gnutls_openpgp_crt_get_fingerprint\
300
(crt, ctypes.byref(buffer), ctypes.byref(buffer_length))
301
# Deinit the certificate
302
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
303
# Convert the buffer to a Python bytestring
304
fpr = ctypes.string_at(buffer, buffer_length.value)
305
# Convert the bytestring to hexadecimal notation
306
hex_fpr = u''.join(u"%02X" % ord(char) for char in fpr)
310
class tcp_handler(SocketServer.BaseRequestHandler, object):
677
311
"""A TCP request handler class.
678
312
Instantiated by IPv6_TCPServer for each request to handle it.
679
313
Note: This will run in its own forked process."""
681
315
def handle(self):
682
logger.info(u"TCP connection from: %s",
683
unicode(self.client_address))
684
logger.debug(u"IPC Pipe FD: %d", self.server.pipe[1])
685
# Open IPC pipe to parent process
686
with closing(os.fdopen(self.server.pipe[1], "w", 1)) as ipc:
687
session = (gnutls.connection
688
.ClientSession(self.request,
692
line = self.request.makefile().readline()
693
logger.debug(u"Protocol version: %r", line)
695
if int(line.strip().split()[0]) > 1:
697
except (ValueError, IndexError, RuntimeError), error:
698
logger.error(u"Unknown protocol version: %s", error)
701
# Note: gnutls.connection.X509Credentials is really a
702
# generic GnuTLS certificate credentials object so long as
703
# no X.509 keys are added to it. Therefore, we can use it
704
# here despite using OpenPGP certificates.
706
#priority = ':'.join(("NONE", "+VERS-TLS1.1",
707
# "+AES-256-CBC", "+SHA1",
708
# "+COMP-NULL", "+CTYPE-OPENPGP",
710
# Use a fallback default, since this MUST be set.
711
priority = self.server.settings.get("priority", "NORMAL")
712
(gnutls.library.functions
713
.gnutls_priority_set_direct(session._c_object,
718
except gnutls.errors.GNUTLSError, error:
719
logger.warning(u"Handshake failed: %s", error)
720
# Do not run session.bye() here: the session is not
721
# established. Just abandon the request.
723
logger.debug(u"Handshake succeeded")
725
fpr = self.fingerprint(self.peer_certificate(session))
726
except (TypeError, gnutls.errors.GNUTLSError), error:
727
logger.warning(u"Bad certificate: %s", error)
730
logger.debug(u"Fingerprint: %s", fpr)
732
for c in self.server.clients:
733
if c.fingerprint == fpr:
316
logger.debug(u"TCP connection from: %s",
317
unicode(self.client_address))
318
session = gnutls.connection.ClientSession(self.request,
322
#priority = ':'.join(("NONE", "+VERS-TLS1.1", "+AES-256-CBC",
323
# "+SHA1", "+COMP-NULL", "+CTYPE-OPENPGP",
325
priority = "SECURE256"
327
gnutls.library.functions.gnutls_priority_set_direct\
328
(session._c_object, priority, None);
332
except gnutls.errors.GNUTLSError, error:
333
logger.debug(u"Handshake failed: %s", error)
334
# Do not run session.bye() here: the session is not
335
# established. Just abandon the request.
338
fpr = fingerprint(peer_certificate(session))
339
except (TypeError, gnutls.errors.GNUTLSError), error:
340
logger.debug(u"Bad certificate: %s", error)
343
logger.debug(u"Fingerprint: %s", fpr)
346
if c.fingerprint == fpr:
349
# Have to check if client.still_valid(), since it is possible
350
# that the client timed out while establishing the GnuTLS
352
if (not client) or (not client.still_valid()):
354
logger.debug(u"Client %(name)s is invalid",
737
ipc.write("NOTFOUND %s\n" % fpr)
740
# Have to check if client.still_valid(), since it is
741
# possible that the client timed out while establishing
742
# the GnuTLS session.
743
if not client.still_valid():
744
ipc.write("INVALID %s\n" % client.name)
747
ipc.write("SENDING %s\n" % client.name)
749
while sent_size < len(client.secret):
750
sent = session.send(client.secret[sent_size:])
751
logger.debug(u"Sent: %d, remaining: %d",
752
sent, len(client.secret)
753
- (sent_size + sent))
357
logger.debug(u"Client not found for fingerprint: %s",
758
def peer_certificate(session):
759
"Return the peer's OpenPGP certificate as a bytestring"
760
# If not an OpenPGP certificate...
761
if (gnutls.library.functions
762
.gnutls_certificate_type_get(session._c_object)
763
!= gnutls.library.constants.GNUTLS_CRT_OPENPGP):
764
# ...do the normal thing
765
return session.peer_certificate
766
list_size = ctypes.c_uint(1)
767
cert_list = (gnutls.library.functions
768
.gnutls_certificate_get_peers
769
(session._c_object, ctypes.byref(list_size)))
770
if not bool(cert_list) and list_size.value != 0:
771
raise gnutls.errors.GNUTLSError("error getting peer"
773
if list_size.value == 0:
776
return ctypes.string_at(cert.data, cert.size)
779
def fingerprint(openpgp):
780
"Convert an OpenPGP bytestring to a hexdigit fingerprint"
781
# New GnuTLS "datum" with the OpenPGP public key
782
datum = (gnutls.library.types
783
.gnutls_datum_t(ctypes.cast(ctypes.c_char_p(openpgp),
786
ctypes.c_uint(len(openpgp))))
787
# New empty GnuTLS certificate
788
crt = gnutls.library.types.gnutls_openpgp_crt_t()
789
(gnutls.library.functions
790
.gnutls_openpgp_crt_init(ctypes.byref(crt)))
791
# Import the OpenPGP public key into the certificate
792
(gnutls.library.functions
793
.gnutls_openpgp_crt_import(crt, ctypes.byref(datum),
794
gnutls.library.constants
795
.GNUTLS_OPENPGP_FMT_RAW))
796
# Verify the self signature in the key
797
crtverify = ctypes.c_uint()
798
(gnutls.library.functions
799
.gnutls_openpgp_crt_verify_self(crt, 0,
800
ctypes.byref(crtverify)))
801
if crtverify.value != 0:
802
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
803
raise (gnutls.errors.CertificateSecurityError
805
# New buffer for the fingerprint
806
buf = ctypes.create_string_buffer(20)
807
buf_len = ctypes.c_size_t()
808
# Get the fingerprint from the certificate into the buffer
809
(gnutls.library.functions
810
.gnutls_openpgp_crt_get_fingerprint(crt, ctypes.byref(buf),
811
ctypes.byref(buf_len)))
812
# Deinit the certificate
813
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
814
# Convert the buffer to a Python bytestring
815
fpr = ctypes.string_at(buf, buf_len.value)
816
# Convert the bytestring to hexadecimal notation
817
hex_fpr = u''.join(u"%02X" % ord(char) for char in fpr)
821
class ForkingMixInWithPipe(SocketServer.ForkingMixIn, object):
822
"""Like SocketServer.ForkingMixIn, but also pass a pipe.
823
Assumes a gobject.MainLoop event loop.
825
def process_request(self, request, client_address):
826
"""This overrides and wraps the original process_request().
827
This function creates a new pipe in self.pipe
829
self.pipe = os.pipe()
830
super(ForkingMixInWithPipe,
831
self).process_request(request, client_address)
832
os.close(self.pipe[1]) # close write end
833
# Call "handle_ipc" for both data and EOF events
834
gobject.io_add_watch(self.pipe[0],
835
gobject.IO_IN | gobject.IO_HUP,
837
def handle_ipc(source, condition):
838
"""Dummy function; override as necessary"""
843
class IPv6_TCPServer(ForkingMixInWithPipe,
844
SocketServer.TCPServer, object):
845
"""IPv6-capable TCP server. Accepts 'None' as address and/or port
362
while sent_size < len(client.secret):
363
sent = session.send(client.secret[sent_size:])
364
logger.debug(u"Sent: %d, remaining: %d",
365
sent, len(client.secret)
366
- (sent_size + sent))
371
class IPv6_TCPServer(SocketServer.ForkingTCPServer, object):
372
"""IPv6 TCP server. Accepts 'None' as address and/or port.
847
settings: Server settings
374
options: Command line options
848
375
clients: Set() of Client objects
849
enabled: Boolean; whether this server is activated yet
851
377
address_family = socket.AF_INET6
852
378
def __init__(self, *args, **kwargs):
853
if "settings" in kwargs:
854
self.settings = kwargs["settings"]
855
del kwargs["settings"]
379
if "options" in kwargs:
380
self.options = kwargs["options"]
381
del kwargs["options"]
856
382
if "clients" in kwargs:
857
383
self.clients = kwargs["clients"]
858
384
del kwargs["clients"]
859
if "use_ipv6" in kwargs:
860
if not kwargs["use_ipv6"]:
861
self.address_family = socket.AF_INET
862
del kwargs["use_ipv6"]
864
super(IPv6_TCPServer, self).__init__(*args, **kwargs)
385
return super(type(self), self).__init__(*args, **kwargs)
865
386
def server_bind(self):
866
387
"""This overrides the normal server_bind() function
867
388
to bind to an interface if one was specified, and also NOT to
868
389
bind to an address or port if they were not specified."""
869
if self.settings["interface"]:
870
# 25 is from /usr/include/asm-i486/socket.h
871
SO_BINDTODEVICE = getattr(socket, "SO_BINDTODEVICE", 25)
390
if self.options.interface:
391
if not hasattr(socket, "SO_BINDTODEVICE"):
392
# From /usr/include/asm-i486/socket.h
393
socket.SO_BINDTODEVICE = 25
873
395
self.socket.setsockopt(socket.SOL_SOCKET,
875
self.settings["interface"])
396
socket.SO_BINDTODEVICE,
397
self.options.interface)
876
398
except socket.error, error:
877
399
if error[0] == errno.EPERM:
878
logger.error(u"No permission to"
879
u" bind to interface %s",
880
self.settings["interface"])
400
logger.warning(u"No permission to"
401
u" bind to interface %s",
402
self.options.interface)
883
405
# Only bind(2) the socket if we really need to.
884
406
if self.server_address[0] or self.server_address[1]:
885
407
if not self.server_address[0]:
886
if self.address_family == socket.AF_INET6:
887
any_address = "::" # in6addr_any
889
any_address = socket.INADDR_ANY
890
self.server_address = (any_address,
409
self.server_address = (in6addr_any,
891
410
self.server_address[1])
892
elif not self.server_address[1]:
411
elif self.server_address[1] is None:
893
412
self.server_address = (self.server_address[0],
895
# if self.settings["interface"]:
896
# self.server_address = (self.server_address[0],
902
return super(IPv6_TCPServer, self).server_bind()
903
def server_activate(self):
905
return super(IPv6_TCPServer, self).server_activate()
908
def handle_ipc(self, source, condition, file_objects={}):
910
gobject.IO_IN: "IN", # There is data to read.
911
gobject.IO_OUT: "OUT", # Data can be written (without
913
gobject.IO_PRI: "PRI", # There is urgent data to read.
914
gobject.IO_ERR: "ERR", # Error condition.
915
gobject.IO_HUP: "HUP" # Hung up (the connection has been
916
# broken, usually for pipes and
919
conditions_string = ' | '.join(name
921
condition_names.iteritems()
923
logger.debug("Handling IPC: FD = %d, condition = %s", source,
926
# Turn the pipe file descriptor into a Python file object
927
if source not in file_objects:
928
file_objects[source] = os.fdopen(source, "r", 1)
930
# Read a line from the file object
931
cmdline = file_objects[source].readline()
932
if not cmdline: # Empty line means end of file
934
file_objects[source].close()
935
del file_objects[source]
937
# Stop calling this function
940
logger.debug("IPC command: %r", cmdline)
942
# Parse and act on command
943
cmd, args = cmdline.rstrip("\r\n").split(None, 1)
945
if cmd == "NOTFOUND":
946
logger.warning(u"Client not found for fingerprint: %s",
948
if self.settings["use_dbus"]:
950
mandos_dbus_service.ClientNotFound(args)
951
elif cmd == "INVALID":
952
for client in self.clients:
953
if client.name == args:
954
logger.warning(u"Client %s is invalid", args)
955
if self.settings["use_dbus"]:
960
logger.error(u"Unknown client %s is invalid", args)
961
elif cmd == "SENDING":
962
for client in self.clients:
963
if client.name == args:
964
logger.info(u"Sending secret to %s", client.name)
966
if self.settings["use_dbus"]:
968
client.ReceivedSecret()
971
logger.error(u"Sending secret to unknown client %s",
974
logger.error("Unknown IPC command: %r", cmdline)
976
# Keep calling this function
414
return super(type(self), self).server_bind()
980
417
def string_to_delta(interval):
981
418
"""Parse a string and return a datetime.timedelta
983
420
>>> string_to_delta('7d')
984
421
datetime.timedelta(7)
985
422
>>> string_to_delta('60s')
1090
######################################################################
1091
# Parsing of options, both command line and config file
1093
parser = optparse.OptionParser(version = "%%prog %s" % version)
561
def killme(status = 0):
562
logger.debug("Stopping server with exit status %d", status)
564
if main_loop_started:
570
if __name__ == '__main__':
572
main_loop_started = False
573
parser = OptionParser()
1094
574
parser.add_option("-i", "--interface", type="string",
1095
metavar="IF", help="Bind to interface IF")
1096
parser.add_option("-a", "--address", type="string",
1097
help="Address to listen for requests on")
1098
parser.add_option("-p", "--port", type="int",
575
default=None, metavar="IF",
576
help="Bind to interface IF")
577
parser.add_option("-p", "--port", type="int", default=None,
1099
578
help="Port number to receive requests on")
1100
parser.add_option("--check", action="store_true",
579
parser.add_option("--timeout", type="string", # Parsed later
581
help="Amount of downtime allowed for clients")
582
parser.add_option("--interval", type="string", # Parsed later
584
help="How often to check that a client is up")
585
parser.add_option("--check", action="store_true", default=False,
1101
586
help="Run self-test")
1102
parser.add_option("--debug", action="store_true",
1103
help="Debug mode; run in foreground and log to"
1105
parser.add_option("--priority", type="string", help="GnuTLS"
1106
" priority string (see GnuTLS documentation)")
1107
parser.add_option("--servicename", type="string", metavar="NAME",
1108
help="Zeroconf service name")
1109
parser.add_option("--configdir", type="string",
1110
default="/etc/mandos", metavar="DIR",
1111
help="Directory to search for configuration"
1113
parser.add_option("--no-dbus", action="store_false",
1115
help="Do not provide D-Bus system bus"
1117
parser.add_option("--no-ipv6", action="store_false",
1118
dest="use_ipv6", help="Do not use IPv6")
1119
options = parser.parse_args()[0]
587
parser.add_option("--debug", action="store_true", default=False,
589
(options, args) = parser.parse_args()
1121
591
if options.check:
1123
593
doctest.testmod()
1126
# Default values for config file for server-global settings
1127
server_defaults = { "interface": "",
1132
"SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP",
1133
"servicename": "Mandos",
1138
# Parse config file for server-global settings
1139
server_config = ConfigParser.SafeConfigParser(server_defaults)
1141
server_config.read(os.path.join(options.configdir, "mandos.conf"))
1142
# Convert the SafeConfigParser object to a dict
1143
server_settings = server_config.defaults()
1144
# Use the appropriate methods on the non-string config options
1145
server_settings["debug"] = server_config.getboolean("DEFAULT",
1147
server_settings["use_dbus"] = server_config.getboolean("DEFAULT",
1149
server_settings["use_ipv6"] = server_config.getboolean("DEFAULT",
1151
if server_settings["port"]:
1152
server_settings["port"] = server_config.getint("DEFAULT",
1156
# Override the settings from the config file with command line
1158
for option in ("interface", "address", "port", "debug",
1159
"priority", "servicename", "configdir",
1160
"use_dbus", "use_ipv6"):
1161
value = getattr(options, option)
1162
if value is not None:
1163
server_settings[option] = value
1165
# Now we have our good server settings in "server_settings"
1167
##################################################################
1170
debug = server_settings["debug"]
1171
use_dbus = server_settings["use_dbus"]
1172
use_ipv6 = server_settings["use_ipv6"]
1175
syslogger.setLevel(logging.WARNING)
1176
console.setLevel(logging.WARNING)
1178
if server_settings["servicename"] != "Mandos":
1179
syslogger.setFormatter(logging.Formatter
1180
('Mandos (%s) [%%(process)d]:'
1181
' %%(levelname)s: %%(message)s'
1182
% server_settings["servicename"]))
1184
# Parse config file with clients
1185
client_defaults = { "timeout": "1h",
1187
"checker": "fping -q -- %%(host)s",
1190
client_config = ConfigParser.SafeConfigParser(client_defaults)
1191
client_config.read(os.path.join(server_settings["configdir"],
1194
global mandos_dbus_service
1195
mandos_dbus_service = None
1198
tcp_server = IPv6_TCPServer((server_settings["address"],
1199
server_settings["port"]),
1201
settings=server_settings,
1202
clients=clients, use_ipv6=use_ipv6)
1203
pidfilename = "/var/run/mandos.pid"
1205
pidfile = open(pidfilename, "w")
1207
logger.error("Could not open file %r", pidfilename)
1210
uid = pwd.getpwnam("_mandos").pw_uid
1211
gid = pwd.getpwnam("_mandos").pw_gid
1214
uid = pwd.getpwnam("mandos").pw_uid
1215
gid = pwd.getpwnam("mandos").pw_gid
1218
uid = pwd.getpwnam("nobody").pw_uid
1219
gid = pwd.getpwnam("nogroup").pw_gid
1226
except OSError, error:
1227
if error[0] != errno.EPERM:
1230
# Enable all possible GnuTLS debugging
1232
# "Use a log level over 10 to enable all debugging options."
1234
gnutls.library.functions.gnutls_global_set_log_level(11)
1236
@gnutls.library.types.gnutls_log_func
1237
def debug_gnutls(level, string):
1238
logger.debug("GnuTLS: %s", string[:-1])
1240
(gnutls.library.functions
1241
.gnutls_global_set_log_function(debug_gnutls))
1244
protocol = avahi.PROTO_INET6 if use_ipv6 else avahi.PROTO_INET
1245
service = AvahiService(name = server_settings["servicename"],
1246
servicetype = "_mandos._tcp",
1247
protocol = protocol)
1248
if server_settings["interface"]:
1249
service.interface = (if_nametoindex
1250
(server_settings["interface"]))
1255
# From the Avahi example code
596
# Parse the time arguments
598
options.timeout = string_to_delta(options.timeout)
600
parser.error("option --timeout: Unparseable time")
602
options.interval = string_to_delta(options.interval)
604
parser.error("option --interval: Unparseable time")
607
defaults = { "checker": "fping -q -- %%(fqdn)s" }
608
client_config = ConfigParser.SafeConfigParser(defaults)
609
#client_config.readfp(open("secrets.conf"), "secrets.conf")
610
client_config.read("mandos-clients.conf")
612
# From the Avahi server example code
1256
613
DBusGMainLoop(set_as_default=True )
1257
614
main_loop = gobject.MainLoop()
1258
615
bus = dbus.SystemBus()
1259
server = dbus.Interface(bus.get_object(avahi.DBUS_NAME,
1260
avahi.DBUS_PATH_SERVER),
1261
avahi.DBUS_INTERFACE_SERVER)
616
server = dbus.Interface(
617
bus.get_object( avahi.DBUS_NAME, avahi.DBUS_PATH_SERVER ),
618
avahi.DBUS_INTERFACE_SERVER )
1262
619
# End of Avahi example code
1264
bus_name = dbus.service.BusName(u"se.bsnet.fukt.Mandos", bus)
1266
client_class = Client
1268
client_class = ClientDBus
1270
client_class(name = section,
1271
config= dict(client_config.items(section)))
1272
for section in client_config.sections()))
1274
logger.warning(u"No clients defined")
621
debug = options.debug
1277
# Redirect stdin so all checkers get /dev/null
1278
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1279
os.dup2(null, sys.stdin.fileno())
1283
# No console logging
1284
logger.removeHandler(console)
1285
# Close all input and output, do double fork, etc.
1289
with closing(pidfile):
1291
pidfile.write(str(pid) + "\n")
1294
logger.error(u"Could not write to file %r with PID %d",
1297
# "pidfile" was never created
624
console = logging.StreamHandler()
625
# console.setLevel(logging.DEBUG)
626
console.setFormatter(logging.Formatter\
627
('%(levelname)s: %(message)s'))
628
logger.addHandler(console)
632
def remove_from_clients(client):
633
clients.remove(client)
635
logger.debug(u"No clients left, exiting")
638
clients.update(Set(Client(name=section, options=options,
639
stop_hook = remove_from_clients,
640
**(dict(client_config\
642
for section in client_config.sections()))
1302
648
"Cleanup function; run on exit"
1304
# From the Avahi example code
650
# From the Avahi server example code
1305
651
if not group is None:
1308
654
# End of Avahi example code
1311
client = clients.pop()
1312
client.disable_hook = None
656
for client in clients:
657
client.stop_hook = None
1315
660
atexit.register(cleanup)
1318
663
signal.signal(signal.SIGINT, signal.SIG_IGN)
1319
signal.signal(signal.SIGHUP, lambda signum, frame: sys.exit())
1320
signal.signal(signal.SIGTERM, lambda signum, frame: sys.exit())
1323
class MandosDBusService(dbus.service.Object):
1324
"""A D-Bus proxy object"""
1326
dbus.service.Object.__init__(self, bus, "/")
1327
_interface = u"se.bsnet.fukt.Mandos"
1329
@dbus.service.signal(_interface, signature="oa{sv}")
1330
def ClientAdded(self, objpath, properties):
1334
@dbus.service.signal(_interface, signature="s")
1335
def ClientNotFound(self, fingerprint):
1339
@dbus.service.signal(_interface, signature="os")
1340
def ClientRemoved(self, objpath, name):
1344
@dbus.service.method(_interface, out_signature="ao")
1345
def GetAllClients(self):
1347
return dbus.Array(c.dbus_object_path for c in clients)
1349
@dbus.service.method(_interface, out_signature="a{oa{sv}}")
1350
def GetAllClientsWithProperties(self):
1352
return dbus.Dictionary(
1353
((c.dbus_object_path, c.GetAllProperties())
1357
@dbus.service.method(_interface, in_signature="o")
1358
def RemoveClient(self, object_path):
1361
if c.dbus_object_path == object_path:
1363
c.remove_from_connection()
1364
# Don't signal anything except ClientRemoved
1365
c.disable(signal=False)
1367
self.ClientRemoved(object_path, c.name)
1373
mandos_dbus_service = MandosDBusService()
664
signal.signal(signal.SIGHUP, lambda signum, frame: killme())
665
signal.signal(signal.SIGTERM, lambda signum, frame: killme())
1375
667
for client in clients:
1378
mandos_dbus_service.ClientAdded(client.dbus_object_path,
1379
client.GetAllProperties())
1383
tcp_server.server_activate()
1385
# Find out what port we got
1386
service.port = tcp_server.socket.getsockname()[1]
1388
logger.info(u"Now listening on address %r, port %d,"
1389
" flowinfo %d, scope_id %d"
1390
% tcp_server.socket.getsockname())
1392
logger.info(u"Now listening on address %r, port %d"
1393
% tcp_server.socket.getsockname())
1395
#service.interface = tcp_server.socket.getsockname()[3]
1398
# From the Avahi example code
1399
server.connect_to_signal("StateChanged", server_state_changed)
1401
server_state_changed(server.GetState())
1402
except dbus.exceptions.DBusException, error:
1403
logger.critical(u"DBusException: %s", error)
1405
# End of Avahi example code
1407
gobject.io_add_watch(tcp_server.fileno(), gobject.IO_IN,
1408
lambda *args, **kwargs:
1409
(tcp_server.handle_request
1410
(*args[2:], **kwargs) or True))
1412
logger.debug(u"Starting main loop")
670
tcp_server = IPv6_TCPServer((None, options.port),
674
# Find out what random port we got
675
servicePort = tcp_server.socket.getsockname()[1]
676
logger.debug(u"Now listening on port %d", servicePort)
678
if options.interface is not None:
679
serviceInterface = if_nametoindex(options.interface)
681
# From the Avahi server example code
682
server.connect_to_signal("StateChanged", server_state_changed)
684
server_state_changed(server.GetState())
685
except dbus.exceptions.DBusException, error:
686
logger.critical(u"DBusException: %s", error)
688
# End of Avahi example code
690
gobject.io_add_watch(tcp_server.fileno(), gobject.IO_IN,
691
lambda *args, **kwargs:
692
tcp_server.handle_request(*args[2:],
695
main_loop_started = True
1414
except AvahiError, error:
1415
logger.critical(u"AvahiError: %s", error)
1417
697
except KeyboardInterrupt:
1420
logger.debug("Server received KeyboardInterrupt")
1421
logger.debug("Server exiting")
1423
if __name__ == '__main__':