206
188
self.group.Commit()
207
189
def entry_group_state_changed(self, state, error):
208
190
"""Derived from the Avahi example code"""
209
logger.debug("Avahi entry group state change: %i", state)
191
logger.debug(u"Avahi state change: %i", state)
211
193
if state == avahi.ENTRY_GROUP_ESTABLISHED:
212
logger.debug("Zeroconf service established.")
194
logger.debug(u"Zeroconf service established.")
213
195
elif state == avahi.ENTRY_GROUP_COLLISION:
214
logger.info("Zeroconf service name collision.")
196
logger.warning(u"Zeroconf service name collision.")
216
198
elif state == avahi.ENTRY_GROUP_FAILURE:
217
logger.critical("Avahi: Error in group state changed %s",
199
logger.critical(u"Avahi: Error in group state changed %s",
219
raise AvahiGroupError("State changed: %s"
201
raise AvahiGroupError(u"State changed: %s"
220
202
% unicode(error))
221
203
def cleanup(self):
222
204
"""Derived from the Avahi example code"""
223
205
if self.group is not None:
226
except (dbus.exceptions.UnknownMethodException,
227
dbus.exceptions.DBusException) as e:
229
207
self.group = None
231
def server_state_changed(self, state, error=None):
208
def server_state_changed(self, state):
232
209
"""Derived from the Avahi example code"""
233
logger.debug("Avahi server state change: %i", state)
234
bad_states = { avahi.SERVER_INVALID:
235
"Zeroconf server invalid",
236
avahi.SERVER_REGISTERING: None,
237
avahi.SERVER_COLLISION:
238
"Zeroconf server name collision",
239
avahi.SERVER_FAILURE:
240
"Zeroconf server failure" }
241
if state in bad_states:
242
if bad_states[state] is not None:
244
logger.error(bad_states[state])
246
logger.error(bad_states[state] + ": %r", error)
210
if state == avahi.SERVER_COLLISION:
211
logger.error(u"Zeroconf server name collision")
248
213
elif state == avahi.SERVER_RUNNING:
252
logger.debug("Unknown state: %r", state)
254
logger.debug("Unknown state: %r: %r", state, error)
255
215
def activate(self):
256
216
"""Derived from the Avahi example code"""
257
217
if self.server is None:
258
218
self.server = dbus.Interface(
259
219
self.bus.get_object(avahi.DBUS_NAME,
260
avahi.DBUS_PATH_SERVER,
261
follow_name_owner_changes=True),
220
avahi.DBUS_PATH_SERVER),
262
221
avahi.DBUS_INTERFACE_SERVER)
263
self.server.connect_to_signal("StateChanged",
222
self.server.connect_to_signal(u"StateChanged",
264
223
self.server_state_changed)
265
224
self.server_state_changed(self.server.GetState())
268
def _timedelta_to_milliseconds(td):
269
"Convert a datetime.timedelta() to milliseconds"
270
return ((td.days * 24 * 60 * 60 * 1000)
271
+ (td.seconds * 1000)
272
+ (td.microseconds // 1000))
274
227
class Client(object):
275
228
"""A representation of a client host served by this server.
278
_approved: bool(); 'None' if not yet approved/disapproved
279
approval_delay: datetime.timedelta(); Time to wait for approval
280
approval_duration: datetime.timedelta(); Duration of one approval
231
name: string; from the config file, used in log messages and
233
fingerprint: string (40 or 32 hexadecimal digits); used to
234
uniquely identify the client
235
secret: bytestring; sent verbatim (over TLS) to client
236
host: string; available for use by the checker command
237
created: datetime.datetime(); (UTC) object creation
238
last_enabled: datetime.datetime(); (UTC)
240
last_checked_ok: datetime.datetime(); (UTC) or None
241
timeout: datetime.timedelta(); How long from last_checked_ok
242
until this client is invalid
243
interval: datetime.timedelta(); How often to start a new checker
244
disable_hook: If set, called by disable() as disable_hook(self)
281
245
checker: subprocess.Popen(); a running checker process used
282
246
to see if the client lives.
283
247
'None' if no process is running.
284
checker_callback_tag: a gobject event source tag, or None
285
checker_command: string; External command which is run to check
286
if client lives. %() expansions are done at
248
checker_initiator_tag: a gobject event source tag, or None
249
disable_initiator_tag: - '' -
250
checker_callback_tag: - '' -
251
checker_command: string; External command which is run to check if
252
client lives. %() expansions are done at
287
253
runtime with vars(self) as dict, so that for
288
254
instance %(name)s can be used in the command.
289
checker_initiator_tag: a gobject event source tag, or None
290
created: datetime.datetime(); (UTC) object creation
291
255
current_checker_command: string; current running checker_command
292
disable_hook: If set, called by disable() as disable_hook(self)
293
disable_initiator_tag: a gobject event source tag, or None
295
fingerprint: string (40 or 32 hexadecimal digits); used to
296
uniquely identify the client
297
host: string; available for use by the checker command
298
interval: datetime.timedelta(); How often to start a new checker
299
last_approval_request: datetime.datetime(); (UTC) or None
300
last_checked_ok: datetime.datetime(); (UTC) or None
301
last_enabled: datetime.datetime(); (UTC)
302
name: string; from the config file, used in log messages and
304
secret: bytestring; sent verbatim (over TLS) to client
305
timeout: datetime.timedelta(); How long from last_checked_ok
306
until this client is disabled
307
extended_timeout: extra long timeout when password has been sent
308
runtime_expansions: Allowed attributes for runtime expansion.
309
expires: datetime.datetime(); time (UTC) when a client will be
313
runtime_expansions = ("approval_delay", "approval_duration",
314
"created", "enabled", "fingerprint",
315
"host", "interval", "last_checked_ok",
316
"last_enabled", "name", "timeout")
259
def _datetime_to_milliseconds(dt):
260
"Convert a datetime.datetime() to milliseconds"
261
return ((dt.days * 24 * 60 * 60 * 1000)
262
+ (dt.seconds * 1000)
263
+ (dt.microseconds // 1000))
318
265
def timeout_milliseconds(self):
319
266
"Return the 'timeout' attribute in milliseconds"
320
return _timedelta_to_milliseconds(self.timeout)
322
def extended_timeout_milliseconds(self):
323
"Return the 'extended_timeout' attribute in milliseconds"
324
return _timedelta_to_milliseconds(self.extended_timeout)
267
return self._datetime_to_milliseconds(self.timeout)
326
269
def interval_milliseconds(self):
327
270
"Return the 'interval' attribute in milliseconds"
328
return _timedelta_to_milliseconds(self.interval)
330
def approval_delay_milliseconds(self):
331
return _timedelta_to_milliseconds(self.approval_delay)
271
return self._datetime_to_milliseconds(self.interval)
333
273
def __init__(self, name = None, disable_hook=None, config=None):
334
274
"""Note: the 'checker' key in 'config' sets the
338
278
if config is None:
340
logger.debug("Creating client %r", self.name)
280
logger.debug(u"Creating client %r", self.name)
341
281
# Uppercase and remove spaces from fingerprint for later
342
282
# comparison purposes with return value from the fingerprint()
344
self.fingerprint = (config["fingerprint"].upper()
346
logger.debug(" Fingerprint: %s", self.fingerprint)
347
if "secret" in config:
348
self.secret = config["secret"].decode("base64")
349
elif "secfile" in config:
350
with open(os.path.expanduser(os.path.expandvars
351
(config["secfile"])),
284
self.fingerprint = (config[u"fingerprint"].upper()
286
logger.debug(u" Fingerprint: %s", self.fingerprint)
287
if u"secret" in config:
288
self.secret = config[u"secret"].decode(u"base64")
289
elif u"secfile" in config:
290
with closing(open(os.path.expanduser
292
(config[u"secfile"])))) as secfile:
353
293
self.secret = secfile.read()
355
raise TypeError("No secret or secfile for client %s"
295
raise TypeError(u"No secret or secfile for client %s"
357
self.host = config.get("host", "")
297
self.host = config.get(u"host", u"")
358
298
self.created = datetime.datetime.utcnow()
359
299
self.enabled = False
360
self.last_approval_request = None
361
300
self.last_enabled = None
362
301
self.last_checked_ok = None
363
self.timeout = string_to_delta(config["timeout"])
364
self.extended_timeout = string_to_delta(config["extended_timeout"])
365
self.interval = string_to_delta(config["interval"])
302
self.timeout = string_to_delta(config[u"timeout"])
303
self.interval = string_to_delta(config[u"interval"])
366
304
self.disable_hook = disable_hook
367
305
self.checker = None
368
306
self.checker_initiator_tag = None
369
307
self.disable_initiator_tag = None
371
308
self.checker_callback_tag = None
372
self.checker_command = config["checker"]
309
self.checker_command = config[u"checker"]
373
310
self.current_checker_command = None
374
311
self.last_connect = None
375
self._approved = None
376
self.approved_by_default = config.get("approved_by_default",
378
self.approvals_pending = 0
379
self.approval_delay = string_to_delta(
380
config["approval_delay"])
381
self.approval_duration = string_to_delta(
382
config["approval_duration"])
383
self.changedstate = multiprocessing_manager.Condition(multiprocessing_manager.Lock())
385
def send_changedstate(self):
386
self.changedstate.acquire()
387
self.changedstate.notify_all()
388
self.changedstate.release()
390
313
def enable(self):
391
314
"""Start this client's checker and timeout hooks"""
392
if getattr(self, "enabled", False):
315
if getattr(self, u"enabled", False):
393
316
# Already enabled
395
self.send_changedstate()
318
self.last_enabled = datetime.datetime.utcnow()
396
319
# Schedule a new checker to be started an 'interval' from now,
397
320
# and every interval from then on.
398
321
self.checker_initiator_tag = (gobject.timeout_add
399
322
(self.interval_milliseconds(),
400
323
self.start_checker))
324
# Also start a new checker *right now*.
401
326
# Schedule a disable() when 'timeout' has passed
402
self.expires = datetime.datetime.utcnow() + self.timeout
403
327
self.disable_initiator_tag = (gobject.timeout_add
404
328
(self.timeout_milliseconds(),
406
330
self.enabled = True
407
self.last_enabled = datetime.datetime.utcnow()
408
# Also start a new checker *right now*.
411
def disable(self, quiet=True):
412
333
"""Disable this client."""
413
334
if not getattr(self, "enabled", False):
416
self.send_changedstate()
418
logger.info("Disabling client %s", self.name)
419
if getattr(self, "disable_initiator_tag", False):
336
logger.info(u"Disabling client %s", self.name)
337
if getattr(self, u"disable_initiator_tag", False):
420
338
gobject.source_remove(self.disable_initiator_tag)
421
339
self.disable_initiator_tag = None
423
if getattr(self, "checker_initiator_tag", False):
340
if getattr(self, u"checker_initiator_tag", False):
424
341
gobject.source_remove(self.checker_initiator_tag)
425
342
self.checker_initiator_tag = None
426
343
self.stop_checker()
549
453
if self.checker_callback_tag:
550
454
gobject.source_remove(self.checker_callback_tag)
551
455
self.checker_callback_tag = None
552
if getattr(self, "checker", None) is None:
456
if getattr(self, u"checker", None) is None:
554
logger.debug("Stopping checker for %(name)s", vars(self))
458
logger.debug(u"Stopping checker for %(name)s", vars(self))
556
460
os.kill(self.checker.pid, signal.SIGTERM)
558
462
#if self.checker.poll() is None:
559
463
# os.kill(self.checker.pid, signal.SIGKILL)
560
except OSError as error:
464
except OSError, error:
561
465
if error.errno != errno.ESRCH: # No such process
563
467
self.checker = None
566
def dbus_service_property(dbus_interface, signature="v",
567
access="readwrite", byte_arrays=False):
568
"""Decorators for marking methods of a DBusObjectWithProperties to
569
become properties on the D-Bus.
571
The decorated method will be called with no arguments by "Get"
572
and with one argument by "Set".
574
The parameters, where they are supported, are the same as
575
dbus.service.method, except there is only "signature", since the
576
type from Get() and the type sent to Set() is the same.
578
# Encoding deeply encoded byte arrays is not supported yet by the
579
# "Set" method, so we fail early here:
580
if byte_arrays and signature != "ay":
581
raise ValueError("Byte arrays not supported for non-'ay'"
582
" signature %r" % signature)
584
func._dbus_is_property = True
585
func._dbus_interface = dbus_interface
586
func._dbus_signature = signature
587
func._dbus_access = access
588
func._dbus_name = func.__name__
589
if func._dbus_name.endswith("_dbus_property"):
590
func._dbus_name = func._dbus_name[:-14]
591
func._dbus_get_args_options = {'byte_arrays': byte_arrays }
596
class DBusPropertyException(dbus.exceptions.DBusException):
597
"""A base class for D-Bus property-related exceptions
599
def __unicode__(self):
600
return unicode(str(self))
603
class DBusPropertyAccessException(DBusPropertyException):
604
"""A property's access permissions disallows an operation.
609
class DBusPropertyNotFound(DBusPropertyException):
610
"""An attempt was made to access a non-existing property.
615
class DBusObjectWithProperties(dbus.service.Object):
616
"""A D-Bus object with properties.
618
Classes inheriting from this can use the dbus_service_property
619
decorator to expose methods as D-Bus properties. It exposes the
620
standard Get(), Set(), and GetAll() methods on the D-Bus.
624
def _is_dbus_property(obj):
625
return getattr(obj, "_dbus_is_property", False)
627
def _get_all_dbus_properties(self):
628
"""Returns a generator of (name, attribute) pairs
630
return ((prop.__get__(self)._dbus_name, prop.__get__(self))
631
for cls in self.__class__.__mro__
632
for name, prop in inspect.getmembers(cls, self._is_dbus_property))
634
def _get_dbus_property(self, interface_name, property_name):
635
"""Returns a bound method if one exists which is a D-Bus
636
property with the specified name and interface.
638
for cls in self.__class__.__mro__:
639
for name, value in inspect.getmembers(cls, self._is_dbus_property):
640
if value._dbus_name == property_name and value._dbus_interface == interface_name:
641
return value.__get__(self)
644
raise DBusPropertyNotFound(self.dbus_object_path + ":"
645
+ interface_name + "."
648
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ss",
650
def Get(self, interface_name, property_name):
651
"""Standard D-Bus property Get() method, see D-Bus standard.
653
prop = self._get_dbus_property(interface_name, property_name)
654
if prop._dbus_access == "write":
655
raise DBusPropertyAccessException(property_name)
657
if not hasattr(value, "variant_level"):
659
return type(value)(value, variant_level=value.variant_level+1)
661
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ssv")
662
def Set(self, interface_name, property_name, value):
663
"""Standard D-Bus property Set() method, see D-Bus standard.
665
prop = self._get_dbus_property(interface_name, property_name)
666
if prop._dbus_access == "read":
667
raise DBusPropertyAccessException(property_name)
668
if prop._dbus_get_args_options["byte_arrays"]:
669
# The byte_arrays option is not supported yet on
670
# signatures other than "ay".
671
if prop._dbus_signature != "ay":
673
value = dbus.ByteArray(''.join(unichr(byte)
677
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="s",
678
out_signature="a{sv}")
679
def GetAll(self, interface_name):
680
"""Standard D-Bus property GetAll() method, see D-Bus
683
Note: Will not include properties with access="write".
686
for name, prop in self._get_all_dbus_properties():
688
and interface_name != prop._dbus_interface):
689
# Interface non-empty but did not match
691
# Ignore write-only properties
692
if prop._dbus_access == "write":
695
if not hasattr(value, "variant_level"):
698
all[name] = type(value)(value, variant_level=
699
value.variant_level+1)
700
return dbus.Dictionary(all, signature="sv")
702
@dbus.service.method(dbus.INTROSPECTABLE_IFACE,
704
path_keyword='object_path',
705
connection_keyword='connection')
706
def Introspect(self, object_path, connection):
707
"""Standard D-Bus method, overloaded to insert property tags.
709
xmlstring = dbus.service.Object.Introspect(self, object_path,
712
document = xml.dom.minidom.parseString(xmlstring)
713
def make_tag(document, name, prop):
714
e = document.createElement("property")
715
e.setAttribute("name", name)
716
e.setAttribute("type", prop._dbus_signature)
717
e.setAttribute("access", prop._dbus_access)
719
for if_tag in document.getElementsByTagName("interface"):
720
for tag in (make_tag(document, name, prop)
722
in self._get_all_dbus_properties()
723
if prop._dbus_interface
724
== if_tag.getAttribute("name")):
725
if_tag.appendChild(tag)
726
# Add the names to the return values for the
727
# "org.freedesktop.DBus.Properties" methods
728
if (if_tag.getAttribute("name")
729
== "org.freedesktop.DBus.Properties"):
730
for cn in if_tag.getElementsByTagName("method"):
731
if cn.getAttribute("name") == "Get":
732
for arg in cn.getElementsByTagName("arg"):
733
if (arg.getAttribute("direction")
735
arg.setAttribute("name", "value")
736
elif cn.getAttribute("name") == "GetAll":
737
for arg in cn.getElementsByTagName("arg"):
738
if (arg.getAttribute("direction")
740
arg.setAttribute("name", "props")
741
xmlstring = document.toxml("utf-8")
743
except (AttributeError, xml.dom.DOMException,
744
xml.parsers.expat.ExpatError) as error:
745
logger.error("Failed to override Introspection method",
750
def datetime_to_dbus (dt, variant_level=0):
751
"""Convert a UTC datetime.datetime() to a D-Bus type."""
753
return dbus.String("", variant_level = variant_level)
754
return dbus.String(dt.isoformat(),
755
variant_level=variant_level)
757
class transitional_dbus_metaclass(DBusObjectWithProperties.__metaclass__):
758
def __new__(mcs, name, bases, attr):
759
for attrname, old_dbusobj in inspect.getmembers(bases[0]):
760
new_interface = getattr(old_dbusobj, "_dbus_interface", "").replace("se.bsnet.fukt.", "se.recompile.")
761
if (getattr(old_dbusobj, "_dbus_is_signal", False)
762
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
763
unwrappedfunc = dict(zip(old_dbusobj.func_code.co_freevars,
764
old_dbusobj.__closure__))["func"].cell_contents
765
newfunc = types.FunctionType(unwrappedfunc.func_code,
766
unwrappedfunc.func_globals,
767
unwrappedfunc.func_name,
768
unwrappedfunc.func_defaults,
769
unwrappedfunc.func_closure)
770
new_dbusfunc = dbus.service.signal(
771
new_interface, old_dbusobj._dbus_signature)(newfunc)
772
attr["_transitional_" + attrname] = new_dbusfunc
774
def fixscope(func1, func2):
775
def newcall(*args, **kwargs):
776
func1(*args, **kwargs)
777
func2(*args, **kwargs)
780
attr[attrname] = fixscope(old_dbusobj, new_dbusfunc)
782
elif (getattr(old_dbusobj, "_dbus_is_method", False)
783
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
784
new_dbusfunc = (dbus.service.method
786
old_dbusobj._dbus_in_signature,
787
old_dbusobj._dbus_out_signature)
789
(old_dbusobj.func_code,
790
old_dbusobj.func_globals,
791
old_dbusobj.func_name,
792
old_dbusobj.func_defaults,
793
old_dbusobj.func_closure)))
795
attr[attrname] = new_dbusfunc
796
elif (getattr(old_dbusobj, "_dbus_is_property", False)
797
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
798
new_dbusfunc = (dbus_service_property
800
old_dbusobj._dbus_signature,
801
old_dbusobj._dbus_access,
802
old_dbusobj._dbus_get_args_options["byte_arrays"])
804
(old_dbusobj.func_code,
805
old_dbusobj.func_globals,
806
old_dbusobj.func_name,
807
old_dbusobj.func_defaults,
808
old_dbusobj.func_closure)))
810
attr[attrname] = new_dbusfunc
811
return type.__new__(mcs, name, bases, attr)
813
class ClientDBus(Client, DBusObjectWithProperties):
469
def still_valid(self):
470
"""Has the timeout not yet passed for this client?"""
471
if not getattr(self, u"enabled", False):
473
now = datetime.datetime.utcnow()
474
if self.last_checked_ok is None:
475
return now < (self.created + self.timeout)
477
return now < (self.last_checked_ok + self.timeout)
480
class ClientDBus(Client, dbus.service.Object):
814
481
"""A Client class using D-Bus
817
484
dbus_object_path: dbus.ObjectPath
818
485
bus: dbus.SystemBus()
821
runtime_expansions = (Client.runtime_expansions
822
+ ("dbus_object_path",))
824
487
# dbus.service.Object doesn't use super(), so we can't either.
826
489
def __init__(self, bus = None, *args, **kwargs):
827
self._approvals_pending = 0
829
491
Client.__init__(self, *args, **kwargs)
830
492
# Only now, when this client is initialized, can it show up on
832
client_object_name = unicode(self.name).translate(
835
494
self.dbus_object_path = (dbus.ObjectPath
836
("/clients/" + client_object_name))
837
DBusObjectWithProperties.__init__(self, self.bus,
838
self.dbus_object_path)
840
def notifychangeproperty(transform_func,
841
dbus_name, type_func=lambda x: x,
843
""" Modify a variable so that its a property that announce its
845
transform_fun: Function that takes a value and transform it to
847
dbus_name: DBus name of the variable
848
type_func: Function that transform the value before sending it
850
variant_level: DBus variant level. default: 1
853
def setter(self, value):
854
old_value = real_value[0]
855
real_value[0] = value
856
if hasattr(self, "dbus_object_path"):
857
if type_func(old_value) != type_func(real_value[0]):
858
dbus_value = transform_func(type_func(real_value[0]),
860
self.PropertyChanged(dbus.String(dbus_name),
863
return property(lambda self: real_value[0], setter)
866
expires = notifychangeproperty(datetime_to_dbus, "Expires")
867
approvals_pending = notifychangeproperty(dbus.Boolean,
870
enabled = notifychangeproperty(dbus.Boolean, "Enabled")
871
last_enabled = notifychangeproperty(datetime_to_dbus,
873
checker = notifychangeproperty(dbus.Boolean, "CheckerRunning",
874
type_func = lambda checker: checker is not None)
875
last_checked_ok = notifychangeproperty(datetime_to_dbus,
877
last_approval_request = notifychangeproperty(datetime_to_dbus,
878
"LastApprovalRequest")
879
approved_by_default = notifychangeproperty(dbus.Boolean,
881
approval_delay = notifychangeproperty(dbus.UInt16, "ApprovalDelay",
882
type_func = _timedelta_to_milliseconds)
883
approval_duration = notifychangeproperty(dbus.UInt16, "ApprovalDuration",
884
type_func = _timedelta_to_milliseconds)
885
host = notifychangeproperty(dbus.String, "Host")
886
timeout = notifychangeproperty(dbus.UInt16, "Timeout",
887
type_func = _timedelta_to_milliseconds)
888
extended_timeout = notifychangeproperty(dbus.UInt16, "ExtendedTimeout",
889
type_func = _timedelta_to_milliseconds)
890
interval = notifychangeproperty(dbus.UInt16, "Interval",
891
type_func = _timedelta_to_milliseconds)
892
checker_command = notifychangeproperty(dbus.String, "Checker")
894
del notifychangeproperty
496
+ self.name.replace(u".", u"_")))
497
dbus.service.Object.__init__(self, self.bus,
498
self.dbus_object_path)
501
def _datetime_to_dbus(dt, variant_level=0):
502
"""Convert a UTC datetime.datetime() to a D-Bus type."""
503
return dbus.String(dt.isoformat(),
504
variant_level=variant_level)
507
oldstate = getattr(self, u"enabled", False)
508
r = Client.enable(self)
509
if oldstate != self.enabled:
511
self.PropertyChanged(dbus.String(u"enabled"),
512
dbus.Boolean(True, variant_level=1))
513
self.PropertyChanged(
514
dbus.String(u"last_enabled"),
515
self._datetime_to_dbus(self.last_enabled,
519
def disable(self, signal = True):
520
oldstate = getattr(self, u"enabled", False)
521
r = Client.disable(self)
522
if signal and oldstate != self.enabled:
524
self.PropertyChanged(dbus.String(u"enabled"),
525
dbus.Boolean(False, variant_level=1))
896
528
def __del__(self, *args, **kwargs):
898
530
self.remove_from_connection()
899
531
except LookupError:
901
if hasattr(DBusObjectWithProperties, "__del__"):
902
DBusObjectWithProperties.__del__(self, *args, **kwargs)
533
if hasattr(dbus.service.Object, u"__del__"):
534
dbus.service.Object.__del__(self, *args, **kwargs)
903
535
Client.__del__(self, *args, **kwargs)
905
537
def checker_callback(self, pid, condition, command,
906
538
*args, **kwargs):
907
539
self.checker_callback_tag = None
908
540
self.checker = None
542
self.PropertyChanged(dbus.String(u"checker_running"),
543
dbus.Boolean(False, variant_level=1))
909
544
if os.WIFEXITED(condition):
910
545
exitstatus = os.WEXITSTATUS(condition)
911
546
# Emit D-Bus signal
933
577
and old_checker_pid != self.checker.pid):
934
578
# Emit D-Bus signal
935
579
self.CheckerStarted(self.current_checker_command)
938
def _reset_approved(self):
939
self._approved = None
942
def approve(self, value=True):
943
self.send_changedstate()
944
self._approved = value
945
gobject.timeout_add(_timedelta_to_milliseconds
946
(self.approval_duration),
947
self._reset_approved)
950
## D-Bus methods, signals & properties
951
_interface = "se.bsnet.fukt.Mandos.Client"
580
self.PropertyChanged(
581
dbus.String(u"checker_running"),
582
dbus.Boolean(True, variant_level=1))
585
def stop_checker(self, *args, **kwargs):
586
old_checker = getattr(self, u"checker", None)
587
r = Client.stop_checker(self, *args, **kwargs)
588
if (old_checker is not None
589
and getattr(self, u"checker", None) is None):
590
self.PropertyChanged(dbus.String(u"checker_running"),
591
dbus.Boolean(False, variant_level=1))
594
## D-Bus methods & signals
595
_interface = u"se.bsnet.fukt.Mandos.Client"
598
@dbus.service.method(_interface)
600
return self.checked_ok()
955
602
# CheckerCompleted - signal
956
@dbus.service.signal(_interface, signature="nxs")
603
@dbus.service.signal(_interface, signature=u"nxs")
957
604
def CheckerCompleted(self, exitcode, waitstatus, command):
961
608
# CheckerStarted - signal
962
@dbus.service.signal(_interface, signature="s")
609
@dbus.service.signal(_interface, signature=u"s")
963
610
def CheckerStarted(self, command):
614
# GetAllProperties - method
615
@dbus.service.method(_interface, out_signature=u"a{sv}")
616
def GetAllProperties(self):
618
return dbus.Dictionary({
619
dbus.String(u"name"):
620
dbus.String(self.name, variant_level=1),
621
dbus.String(u"fingerprint"):
622
dbus.String(self.fingerprint, variant_level=1),
623
dbus.String(u"host"):
624
dbus.String(self.host, variant_level=1),
625
dbus.String(u"created"):
626
self._datetime_to_dbus(self.created,
628
dbus.String(u"last_enabled"):
629
(self._datetime_to_dbus(self.last_enabled,
631
if self.last_enabled is not None
632
else dbus.Boolean(False, variant_level=1)),
633
dbus.String(u"enabled"):
634
dbus.Boolean(self.enabled, variant_level=1),
635
dbus.String(u"last_checked_ok"):
636
(self._datetime_to_dbus(self.last_checked_ok,
638
if self.last_checked_ok is not None
639
else dbus.Boolean (False, variant_level=1)),
640
dbus.String(u"timeout"):
641
dbus.UInt64(self.timeout_milliseconds(),
643
dbus.String(u"interval"):
644
dbus.UInt64(self.interval_milliseconds(),
646
dbus.String(u"checker"):
647
dbus.String(self.checker_command,
649
dbus.String(u"checker_running"):
650
dbus.Boolean(self.checker is not None,
652
dbus.String(u"object_path"):
653
dbus.ObjectPath(self.dbus_object_path,
657
# IsStillValid - method
658
@dbus.service.method(_interface, out_signature=u"b")
659
def IsStillValid(self):
660
return self.still_valid()
967
662
# PropertyChanged - signal
968
@dbus.service.signal(_interface, signature="sv")
663
@dbus.service.signal(_interface, signature=u"sv")
969
664
def PropertyChanged(self, property, value):
668
# ReceivedSecret - signal
974
669
@dbus.service.signal(_interface)
977
Is sent after a successful transfer of secret from the Mandos
978
server to mandos-client
670
def ReceivedSecret(self):
982
674
# Rejected - signal
983
@dbus.service.signal(_interface, signature="s")
984
def Rejected(self, reason):
675
@dbus.service.signal(_interface)
988
# NeedApproval - signal
989
@dbus.service.signal(_interface, signature="tb")
990
def NeedApproval(self, timeout, default):
992
return self.need_approval()
997
@dbus.service.method(_interface, in_signature="b")
998
def Approve(self, value):
1001
# CheckedOK - method
1002
@dbus.service.method(_interface)
1003
def CheckedOK(self):
680
# SetChecker - method
681
@dbus.service.method(_interface, in_signature=u"s")
682
def SetChecker(self, checker):
683
"D-Bus setter method"
684
self.checker_command = checker
686
self.PropertyChanged(dbus.String(u"checker"),
687
dbus.String(self.checker_command,
691
@dbus.service.method(_interface, in_signature=u"s")
692
def SetHost(self, host):
693
"D-Bus setter method"
696
self.PropertyChanged(dbus.String(u"host"),
697
dbus.String(self.host, variant_level=1))
699
# SetInterval - method
700
@dbus.service.method(_interface, in_signature=u"t")
701
def SetInterval(self, milliseconds):
702
self.interval = datetime.timedelta(0, 0, 0, milliseconds)
704
self.PropertyChanged(dbus.String(u"interval"),
705
(dbus.UInt64(self.interval_milliseconds(),
709
@dbus.service.method(_interface, in_signature=u"ay",
711
def SetSecret(self, secret):
712
"D-Bus setter method"
713
self.secret = str(secret)
715
# SetTimeout - method
716
@dbus.service.method(_interface, in_signature=u"t")
717
def SetTimeout(self, milliseconds):
718
self.timeout = datetime.timedelta(0, 0, 0, milliseconds)
720
self.PropertyChanged(dbus.String(u"timeout"),
721
(dbus.UInt64(self.timeout_milliseconds(),
1006
724
# Enable - method
1007
725
@dbus.service.method(_interface)
1026
744
def StopChecker(self):
1027
745
self.stop_checker()
1031
# ApprovalPending - property
1032
@dbus_service_property(_interface, signature="b", access="read")
1033
def ApprovalPending_dbus_property(self):
1034
return dbus.Boolean(bool(self.approvals_pending))
1036
# ApprovedByDefault - property
1037
@dbus_service_property(_interface, signature="b",
1039
def ApprovedByDefault_dbus_property(self, value=None):
1040
if value is None: # get
1041
return dbus.Boolean(self.approved_by_default)
1042
self.approved_by_default = bool(value)
1044
# ApprovalDelay - property
1045
@dbus_service_property(_interface, signature="t",
1047
def ApprovalDelay_dbus_property(self, value=None):
1048
if value is None: # get
1049
return dbus.UInt64(self.approval_delay_milliseconds())
1050
self.approval_delay = datetime.timedelta(0, 0, 0, value)
1052
# ApprovalDuration - property
1053
@dbus_service_property(_interface, signature="t",
1055
def ApprovalDuration_dbus_property(self, value=None):
1056
if value is None: # get
1057
return dbus.UInt64(_timedelta_to_milliseconds(
1058
self.approval_duration))
1059
self.approval_duration = datetime.timedelta(0, 0, 0, value)
1062
@dbus_service_property(_interface, signature="s", access="read")
1063
def Name_dbus_property(self):
1064
return dbus.String(self.name)
1066
# Fingerprint - property
1067
@dbus_service_property(_interface, signature="s", access="read")
1068
def Fingerprint_dbus_property(self):
1069
return dbus.String(self.fingerprint)
1072
@dbus_service_property(_interface, signature="s",
1074
def Host_dbus_property(self, value=None):
1075
if value is None: # get
1076
return dbus.String(self.host)
1079
# Created - property
1080
@dbus_service_property(_interface, signature="s", access="read")
1081
def Created_dbus_property(self):
1082
return dbus.String(datetime_to_dbus(self.created))
1084
# LastEnabled - property
1085
@dbus_service_property(_interface, signature="s", access="read")
1086
def LastEnabled_dbus_property(self):
1087
return datetime_to_dbus(self.last_enabled)
1089
# Enabled - property
1090
@dbus_service_property(_interface, signature="b",
1092
def Enabled_dbus_property(self, value=None):
1093
if value is None: # get
1094
return dbus.Boolean(self.enabled)
1100
# LastCheckedOK - property
1101
@dbus_service_property(_interface, signature="s",
1103
def LastCheckedOK_dbus_property(self, value=None):
1104
if value is not None:
1107
return datetime_to_dbus(self.last_checked_ok)
1109
# Expires - property
1110
@dbus_service_property(_interface, signature="s", access="read")
1111
def Expires_dbus_property(self):
1112
return datetime_to_dbus(self.expires)
1114
# LastApprovalRequest - property
1115
@dbus_service_property(_interface, signature="s", access="read")
1116
def LastApprovalRequest_dbus_property(self):
1117
return datetime_to_dbus(self.last_approval_request)
1119
# Timeout - property
1120
@dbus_service_property(_interface, signature="t",
1122
def Timeout_dbus_property(self, value=None):
1123
if value is None: # get
1124
return dbus.UInt64(self.timeout_milliseconds())
1125
self.timeout = datetime.timedelta(0, 0, 0, value)
1126
if getattr(self, "disable_initiator_tag", None) is None:
1128
# Reschedule timeout
1129
gobject.source_remove(self.disable_initiator_tag)
1130
self.disable_initiator_tag = None
1132
time_to_die = (self.
1133
_timedelta_to_milliseconds((self
1138
if time_to_die <= 0:
1139
# The timeout has passed
1142
self.expires = (datetime.datetime.utcnow()
1143
+ datetime.timedelta(milliseconds = time_to_die))
1144
self.disable_initiator_tag = (gobject.timeout_add
1145
(time_to_die, self.disable))
1147
# ExtendedTimeout - property
1148
@dbus_service_property(_interface, signature="t",
1150
def ExtendedTimeout_dbus_property(self, value=None):
1151
if value is None: # get
1152
return dbus.UInt64(self.extended_timeout_milliseconds())
1153
self.extended_timeout = datetime.timedelta(0, 0, 0, value)
1155
# Interval - property
1156
@dbus_service_property(_interface, signature="t",
1158
def Interval_dbus_property(self, value=None):
1159
if value is None: # get
1160
return dbus.UInt64(self.interval_milliseconds())
1161
self.interval = datetime.timedelta(0, 0, 0, value)
1162
if getattr(self, "checker_initiator_tag", None) is None:
1164
# Reschedule checker run
1165
gobject.source_remove(self.checker_initiator_tag)
1166
self.checker_initiator_tag = (gobject.timeout_add
1167
(value, self.start_checker))
1168
self.start_checker() # Start one now, too
1170
# Checker - property
1171
@dbus_service_property(_interface, signature="s",
1173
def Checker_dbus_property(self, value=None):
1174
if value is None: # get
1175
return dbus.String(self.checker_command)
1176
self.checker_command = value
1178
# CheckerRunning - property
1179
@dbus_service_property(_interface, signature="b",
1181
def CheckerRunning_dbus_property(self, value=None):
1182
if value is None: # get
1183
return dbus.Boolean(self.checker is not None)
1185
self.start_checker()
1189
# ObjectPath - property
1190
@dbus_service_property(_interface, signature="o", access="read")
1191
def ObjectPath_dbus_property(self):
1192
return self.dbus_object_path # is already a dbus.ObjectPath
1195
@dbus_service_property(_interface, signature="ay",
1196
access="write", byte_arrays=True)
1197
def Secret_dbus_property(self, value):
1198
self.secret = str(value)
1203
class ProxyClient(object):
1204
def __init__(self, child_pipe, fpr, address):
1205
self._pipe = child_pipe
1206
self._pipe.send(('init', fpr, address))
1207
if not self._pipe.recv():
1210
def __getattribute__(self, name):
1211
if(name == '_pipe'):
1212
return super(ProxyClient, self).__getattribute__(name)
1213
self._pipe.send(('getattr', name))
1214
data = self._pipe.recv()
1215
if data[0] == 'data':
1217
if data[0] == 'function':
1218
def func(*args, **kwargs):
1219
self._pipe.send(('funcall', name, args, kwargs))
1220
return self._pipe.recv()[1]
1223
def __setattr__(self, name, value):
1224
if(name == '_pipe'):
1225
return super(ProxyClient, self).__setattr__(name, value)
1226
self._pipe.send(('setattr', name, value))
1228
class ClientDBusTransitional(ClientDBus):
1229
__metaclass__ = transitional_dbus_metaclass
1231
750
class ClientHandler(socketserver.BaseRequestHandler, object):
1232
751
"""A class to handle client connections.
1235
754
Note: This will run in its own forked process."""
1237
756
def handle(self):
1238
with contextlib.closing(self.server.child_pipe) as child_pipe:
1239
logger.info("TCP connection from: %s",
1240
unicode(self.client_address))
1241
logger.debug("Pipe FD: %d",
1242
self.server.child_pipe.fileno())
757
logger.info(u"TCP connection from: %s",
758
unicode(self.client_address))
759
logger.debug(u"IPC Pipe FD: %d", self.server.pipe[1])
760
# Open IPC pipe to parent process
761
with closing(os.fdopen(self.server.pipe[1], u"w", 1)) as ipc:
1244
762
session = (gnutls.connection
1245
763
.ClientSession(self.request,
1246
764
gnutls.connection
1247
765
.X509Credentials()))
767
line = self.request.makefile().readline()
768
logger.debug(u"Protocol version: %r", line)
770
if int(line.strip().split()[0]) > 1:
772
except (ValueError, IndexError, RuntimeError), error:
773
logger.error(u"Unknown protocol version: %s", error)
1249
776
# Note: gnutls.connection.X509Credentials is really a
1250
777
# generic GnuTLS certificate credentials object so long as
1251
778
# no X.509 keys are added to it. Therefore, we can use it
1252
779
# here despite using OpenPGP certificates.
1254
#priority = ':'.join(("NONE", "+VERS-TLS1.1",
1255
# "+AES-256-CBC", "+SHA1",
1256
# "+COMP-NULL", "+CTYPE-OPENPGP",
781
#priority = u':'.join((u"NONE", u"+VERS-TLS1.1",
782
# u"+AES-256-CBC", u"+SHA1",
783
# u"+COMP-NULL", u"+CTYPE-OPENPGP",
1258
785
# Use a fallback default, since this MUST be set.
1259
786
priority = self.server.gnutls_priority
1260
787
if priority is None:
1262
789
(gnutls.library.functions
1263
790
.gnutls_priority_set_direct(session._c_object,
1264
791
priority, None))
1266
# Start communication using the Mandos protocol
1267
# Get protocol number
1268
line = self.request.makefile().readline()
1269
logger.debug("Protocol version: %r", line)
1271
if int(line.strip().split()[0]) > 1:
1273
except (ValueError, IndexError, RuntimeError) as error:
1274
logger.error("Unknown protocol version: %s", error)
1277
# Start GnuTLS connection
1279
794
session.handshake()
1280
except gnutls.errors.GNUTLSError as error:
1281
logger.warning("Handshake failed: %s", error)
795
except gnutls.errors.GNUTLSError, error:
796
logger.warning(u"Handshake failed: %s", error)
1282
797
# Do not run session.bye() here: the session is not
1283
798
# established. Just abandon the request.
1285
logger.debug("Handshake succeeded")
1287
approval_required = False
800
logger.debug(u"Handshake succeeded")
1290
fpr = self.fingerprint(self.peer_certificate
1293
gnutls.errors.GNUTLSError) as error:
1294
logger.warning("Bad certificate: %s", error)
1296
logger.debug("Fingerprint: %s", fpr)
1299
client = ProxyClient(child_pipe, fpr,
1300
self.client_address)
1304
if client.approval_delay:
1305
delay = client.approval_delay
1306
client.approvals_pending += 1
1307
approval_required = True
1310
if not client.enabled:
1311
logger.info("Client %s is disabled",
1313
if self.server.use_dbus:
1315
client.Rejected("Disabled")
1318
if client._approved or not client.approval_delay:
1319
#We are approved or approval is disabled
1321
elif client._approved is None:
1322
logger.info("Client %s needs approval",
1324
if self.server.use_dbus:
1326
client.NeedApproval(
1327
client.approval_delay_milliseconds(),
1328
client.approved_by_default)
1330
logger.warning("Client %s was not approved",
1332
if self.server.use_dbus:
1334
client.Rejected("Denied")
1337
#wait until timeout or approved
1338
#x = float(client._timedelta_to_milliseconds(delay))
1339
time = datetime.datetime.now()
1340
client.changedstate.acquire()
1341
client.changedstate.wait(float(client._timedelta_to_milliseconds(delay) / 1000))
1342
client.changedstate.release()
1343
time2 = datetime.datetime.now()
1344
if (time2 - time) >= delay:
1345
if not client.approved_by_default:
1346
logger.warning("Client %s timed out while"
1347
" waiting for approval",
1349
if self.server.use_dbus:
1351
client.Rejected("Approval timed out")
1356
delay -= time2 - time
1359
while sent_size < len(client.secret):
1361
sent = session.send(client.secret[sent_size:])
1362
except gnutls.errors.GNUTLSError as error:
1363
logger.warning("gnutls send failed")
1365
logger.debug("Sent: %d, remaining: %d",
1366
sent, len(client.secret)
1367
- (sent_size + sent))
1370
logger.info("Sending secret to %s", client.name)
1371
# bump the timeout as if seen
1372
client.checked_ok(client.extended_timeout)
1373
if self.server.use_dbus:
802
fpr = self.fingerprint(self.peer_certificate(session))
803
except (TypeError, gnutls.errors.GNUTLSError), error:
804
logger.warning(u"Bad certificate: %s", error)
807
logger.debug(u"Fingerprint: %s", fpr)
1378
if approval_required:
1379
client.approvals_pending -= 1
1382
except gnutls.errors.GNUTLSError as error:
1383
logger.warning("GnuTLS bye failed")
809
for c in self.server.clients:
810
if c.fingerprint == fpr:
814
ipc.write(u"NOTFOUND %s\n" % fpr)
817
# Have to check if client.still_valid(), since it is
818
# possible that the client timed out while establishing
819
# the GnuTLS session.
820
if not client.still_valid():
821
ipc.write(u"INVALID %s\n" % client.name)
824
ipc.write(u"SENDING %s\n" % client.name)
826
while sent_size < len(client.secret):
827
sent = session.send(client.secret[sent_size:])
828
logger.debug(u"Sent: %d, remaining: %d",
829
sent, len(client.secret)
830
- (sent_size + sent))
1386
835
def peer_certificate(session):
1594
1025
for cond, name in
1595
1026
condition_names.iteritems()
1596
1027
if cond & condition)
1597
# error or the other end of multiprocessing.Pipe has closed
1598
if condition & (gobject.IO_ERR | condition & gobject.IO_HUP):
1601
# Read a request from the child
1602
request = parent_pipe.recv()
1603
command = request[0]
1605
if command == 'init':
1607
address = request[2]
1609
for c in self.clients:
1610
if c.fingerprint == fpr:
1614
logger.info("Client not found for fingerprint: %s, ad"
1615
"dress: %s", fpr, address)
1618
mandos_dbus_service.ClientNotFound(fpr, address[0])
1619
parent_pipe.send(False)
1622
gobject.io_add_watch(parent_pipe.fileno(),
1623
gobject.IO_IN | gobject.IO_HUP,
1624
functools.partial(self.handle_ipc,
1625
parent_pipe = parent_pipe,
1626
client_object = client))
1627
parent_pipe.send(True)
1628
# remove the old hook in favor of the new above hook on same fileno
1630
if command == 'funcall':
1631
funcname = request[1]
1635
parent_pipe.send(('data', getattr(client_object, funcname)(*args, **kwargs)))
1637
if command == 'getattr':
1638
attrname = request[1]
1639
if callable(client_object.__getattribute__(attrname)):
1640
parent_pipe.send(('function',))
1642
parent_pipe.send(('data', client_object.__getattribute__(attrname)))
1644
if command == 'setattr':
1645
attrname = request[1]
1647
setattr(client_object, attrname, value)
1028
logger.debug(u"Handling IPC: FD = %d, condition = %s", source,
1031
# Turn the pipe file descriptor into a Python file object
1032
if source not in file_objects:
1033
file_objects[source] = os.fdopen(source, u"r", 1)
1035
# Read a line from the file object
1036
cmdline = file_objects[source].readline()
1037
if not cmdline: # Empty line means end of file
1038
# close the IPC pipe
1039
file_objects[source].close()
1040
del file_objects[source]
1042
# Stop calling this function
1045
logger.debug(u"IPC command: %r", cmdline)
1047
# Parse and act on command
1048
cmd, args = cmdline.rstrip(u"\r\n").split(None, 1)
1050
if cmd == u"NOTFOUND":
1051
logger.warning(u"Client not found for fingerprint: %s",
1055
mandos_dbus_service.ClientNotFound(args)
1056
elif cmd == u"INVALID":
1057
for client in self.clients:
1058
if client.name == args:
1059
logger.warning(u"Client %s is invalid", args)
1065
logger.error(u"Unknown client %s is invalid", args)
1066
elif cmd == u"SENDING":
1067
for client in self.clients:
1068
if client.name == args:
1069
logger.info(u"Sending secret to %s", client.name)
1073
client.ReceivedSecret()
1076
logger.error(u"Sending secret to unknown client %s",
1079
logger.error(u"Unknown IPC command: %r", cmdline)
1081
# Keep calling this function
1652
1085
def string_to_delta(interval):
1653
1086
"""Parse a string and return a datetime.timedelta
1655
>>> string_to_delta('7d')
1088
>>> string_to_delta(u'7d')
1656
1089
datetime.timedelta(7)
1657
>>> string_to_delta('60s')
1090
>>> string_to_delta(u'60s')
1658
1091
datetime.timedelta(0, 60)
1659
>>> string_to_delta('60m')
1092
>>> string_to_delta(u'60m')
1660
1093
datetime.timedelta(0, 3600)
1661
>>> string_to_delta('24h')
1094
>>> string_to_delta(u'24h')
1662
1095
datetime.timedelta(1)
1663
>>> string_to_delta('1w')
1096
>>> string_to_delta(u'1w')
1664
1097
datetime.timedelta(7)
1665
>>> string_to_delta('5m 30s')
1098
>>> string_to_delta(u'5m 30s')
1666
1099
datetime.timedelta(0, 330)
1668
1101
timevalue = datetime.timedelta(0)
1742
##################################################################
1174
######################################################################
1743
1175
# Parsing of options, both command line and config file
1745
parser = argparse.ArgumentParser()
1746
parser.add_argument("-v", "--version", action="version",
1747
version = "%%(prog)s %s" % version,
1748
help="show version number and exit")
1749
parser.add_argument("-i", "--interface", metavar="IF",
1750
help="Bind to interface IF")
1751
parser.add_argument("-a", "--address",
1752
help="Address to listen for requests on")
1753
parser.add_argument("-p", "--port", type=int,
1754
help="Port number to receive requests on")
1755
parser.add_argument("--check", action="store_true",
1756
help="Run self-test")
1757
parser.add_argument("--debug", action="store_true",
1758
help="Debug mode; run in foreground and log"
1760
parser.add_argument("--debuglevel", metavar="LEVEL",
1761
help="Debug level for stdout output")
1762
parser.add_argument("--priority", help="GnuTLS"
1763
" priority string (see GnuTLS documentation)")
1764
parser.add_argument("--servicename",
1765
metavar="NAME", help="Zeroconf service name")
1766
parser.add_argument("--configdir",
1767
default="/etc/mandos", metavar="DIR",
1768
help="Directory to search for configuration"
1770
parser.add_argument("--no-dbus", action="store_false",
1771
dest="use_dbus", help="Do not provide D-Bus"
1772
" system bus interface")
1773
parser.add_argument("--no-ipv6", action="store_false",
1774
dest="use_ipv6", help="Do not use IPv6")
1775
options = parser.parse_args()
1177
parser = optparse.OptionParser(version = "%%prog %s" % version)
1178
parser.add_option("-i", u"--interface", type=u"string",
1179
metavar="IF", help=u"Bind to interface IF")
1180
parser.add_option("-a", u"--address", type=u"string",
1181
help=u"Address to listen for requests on")
1182
parser.add_option("-p", u"--port", type=u"int",
1183
help=u"Port number to receive requests on")
1184
parser.add_option("--check", action=u"store_true",
1185
help=u"Run self-test")
1186
parser.add_option("--debug", action=u"store_true",
1187
help=u"Debug mode; run in foreground and log to"
1189
parser.add_option("--priority", type=u"string", help=u"GnuTLS"
1190
u" priority string (see GnuTLS documentation)")
1191
parser.add_option("--servicename", type=u"string",
1192
metavar=u"NAME", help=u"Zeroconf service name")
1193
parser.add_option("--configdir", type=u"string",
1194
default=u"/etc/mandos", metavar=u"DIR",
1195
help=u"Directory to search for configuration"
1197
parser.add_option("--no-dbus", action=u"store_false",
1198
dest=u"use_dbus", help=u"Do not provide D-Bus"
1199
u" system bus interface")
1200
parser.add_option("--no-ipv6", action=u"store_false",
1201
dest=u"use_ipv6", help=u"Do not use IPv6")
1202
options = parser.parse_args()[0]
1777
1204
if options.check:
1826
1252
##################################################################
1828
1254
# For convenience
1829
debug = server_settings["debug"]
1830
debuglevel = server_settings["debuglevel"]
1831
use_dbus = server_settings["use_dbus"]
1832
use_ipv6 = server_settings["use_ipv6"]
1834
if server_settings["servicename"] != "Mandos":
1255
debug = server_settings[u"debug"]
1256
use_dbus = server_settings[u"use_dbus"]
1257
use_ipv6 = server_settings[u"use_ipv6"]
1260
syslogger.setLevel(logging.WARNING)
1261
console.setLevel(logging.WARNING)
1263
if server_settings[u"servicename"] != u"Mandos":
1835
1264
syslogger.setFormatter(logging.Formatter
1836
('Mandos (%s) [%%(process)d]:'
1837
' %%(levelname)s: %%(message)s'
1838
% server_settings["servicename"]))
1265
(u'Mandos (%s) [%%(process)d]:'
1266
u' %%(levelname)s: %%(message)s'
1267
% server_settings[u"servicename"]))
1840
1269
# Parse config file with clients
1841
client_defaults = { "timeout": "5m",
1842
"extended_timeout": "15m",
1844
"checker": "fping -q -- %%(host)s",
1846
"approval_delay": "0s",
1847
"approval_duration": "1s",
1270
client_defaults = { u"timeout": u"1h",
1272
u"checker": u"fping -q -- %%(host)s",
1849
1275
client_config = configparser.SafeConfigParser(client_defaults)
1850
client_config.read(os.path.join(server_settings["configdir"],
1276
client_config.read(os.path.join(server_settings[u"configdir"],
1853
1279
global mandos_dbus_service
1854
1280
mandos_dbus_service = None
1856
tcp_server = MandosServer((server_settings["address"],
1857
server_settings["port"]),
1282
tcp_server = MandosServer((server_settings[u"address"],
1283
server_settings[u"port"]),
1859
interface=(server_settings["interface"]
1285
interface=server_settings[u"interface"],
1861
1286
use_ipv6=use_ipv6,
1862
1287
gnutls_priority=
1863
server_settings["priority"],
1288
server_settings[u"priority"],
1864
1289
use_dbus=use_dbus)
1866
pidfilename = "/var/run/mandos.pid"
1868
pidfile = open(pidfilename, "w")
1870
logger.error("Could not open file %r", pidfilename)
1290
pidfilename = u"/var/run/mandos.pid"
1292
pidfile = open(pidfilename, u"w")
1294
logger.error(u"Could not open file %r", pidfilename)
1873
uid = pwd.getpwnam("_mandos").pw_uid
1874
gid = pwd.getpwnam("_mandos").pw_gid
1297
uid = pwd.getpwnam(u"_mandos").pw_uid
1298
gid = pwd.getpwnam(u"_mandos").pw_gid
1875
1299
except KeyError:
1877
uid = pwd.getpwnam("mandos").pw_uid
1878
gid = pwd.getpwnam("mandos").pw_gid
1301
uid = pwd.getpwnam(u"mandos").pw_uid
1302
gid = pwd.getpwnam(u"mandos").pw_gid
1879
1303
except KeyError:
1881
uid = pwd.getpwnam("nobody").pw_uid
1882
gid = pwd.getpwnam("nobody").pw_gid
1305
uid = pwd.getpwnam(u"nobody").pw_uid
1306
gid = pwd.getpwnam(u"nobody").pw_gid
1883
1307
except KeyError:
1889
except OSError as error:
1313
except OSError, error:
1890
1314
if error[0] != errno.EPERM:
1893
if not debug and not debuglevel:
1894
syslogger.setLevel(logging.WARNING)
1895
console.setLevel(logging.WARNING)
1897
level = getattr(logging, debuglevel.upper())
1898
syslogger.setLevel(level)
1899
console.setLevel(level)
1317
# Enable all possible GnuTLS debugging
1902
# Enable all possible GnuTLS debugging
1904
1319
# "Use a log level over 10 to enable all debugging options."
1905
1320
# - GnuTLS manual
1906
1321
gnutls.library.functions.gnutls_global_set_log_level(11)
1908
1323
@gnutls.library.types.gnutls_log_func
1909
1324
def debug_gnutls(level, string):
1910
logger.debug("GnuTLS: %s", string[:-1])
1325
logger.debug(u"GnuTLS: %s", string[:-1])
1912
1327
(gnutls.library.functions
1913
1328
.gnutls_global_set_log_function(debug_gnutls))
1915
# Redirect stdin so all checkers get /dev/null
1916
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1917
os.dup2(null, sys.stdin.fileno())
1921
# No console logging
1922
logger.removeHandler(console)
1924
# Need to fork before connecting to D-Bus
1926
# Close all input and output, do double fork, etc.
1929
1330
global main_loop
1930
1331
# From the Avahi example code
1933
1334
bus = dbus.SystemBus()
1934
1335
# End of Avahi example code
1937
bus_name = dbus.service.BusName("se.recompile.Mandos",
1938
bus, do_not_queue=True)
1939
bus_name_transitional = dbus.service.BusName("se.bsnet.fukt.Mandos",
1940
bus, do_not_queue=True)
1941
except dbus.exceptions.NameExistsException as e:
1942
logger.error(unicode(e) + ", disabling D-Bus")
1944
server_settings["use_dbus"] = False
1945
tcp_server.use_dbus = False
1337
bus_name = dbus.service.BusName(u"se.bsnet.fukt.Mandos", bus)
1946
1338
protocol = avahi.PROTO_INET6 if use_ipv6 else avahi.PROTO_INET
1947
service = AvahiService(name = server_settings["servicename"],
1948
servicetype = "_mandos._tcp",
1339
service = AvahiService(name = server_settings[u"servicename"],
1340
servicetype = u"_mandos._tcp",
1949
1341
protocol = protocol, bus = bus)
1950
1342
if server_settings["interface"]:
1951
1343
service.interface = (if_nametoindex
1952
(str(server_settings["interface"])))
1954
global multiprocessing_manager
1955
multiprocessing_manager = multiprocessing.Manager()
1344
(str(server_settings[u"interface"])))
1957
1346
client_class = Client
1959
client_class = functools.partial(ClientDBusTransitional, bus = bus)
1960
def client_config_items(config, section):
1961
special_settings = {
1962
"approved_by_default":
1963
lambda: config.getboolean(section,
1964
"approved_by_default"),
1966
for name, value in config.items(section):
1968
yield (name, special_settings[name]())
1348
client_class = functools.partial(ClientDBus, bus = bus)
1972
1349
tcp_server.clients.update(set(
1973
1350
client_class(name = section,
1974
config= dict(client_config_items(
1975
client_config, section)))
1351
config= dict(client_config.items(section)))
1976
1352
for section in client_config.sections()))
1977
1353
if not tcp_server.clients:
1978
logger.warning("No clients defined")
1354
logger.warning(u"No clients defined")
1357
# Redirect stdin so all checkers get /dev/null
1358
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1359
os.dup2(null, sys.stdin.fileno())
1363
# No console logging
1364
logger.removeHandler(console)
1365
# Close all input and output, do double fork, etc.
1369
with closing(pidfile):
1371
pidfile.write(str(pid) + "\n")
1374
logger.error(u"Could not write to file %r with PID %d",
1377
# "pidfile" was never created
1382
"Cleanup function; run on exit"
1385
while tcp_server.clients:
1386
client = tcp_server.clients.pop()
1387
client.disable_hook = None
1390
atexit.register(cleanup)
1984
pidfile.write(str(pid) + "\n".encode("utf-8"))
1987
logger.error("Could not write to file %r with PID %d",
1990
# "pidfile" was never created
1994
1393
signal.signal(signal.SIGINT, signal.SIG_IGN)
1996
1394
signal.signal(signal.SIGHUP, lambda signum, frame: sys.exit())
1997
1395
signal.signal(signal.SIGTERM, lambda signum, frame: sys.exit())