2
# -*- mode: python; coding: utf-8 -*-
4
# Mandos server - give out binary blobs to connecting clients.
6
# This program is partly derived from an example program for an Avahi
7
# service publisher, downloaded from
8
# <http://avahi.org/wiki/PythonPublishExample>. This includes the
9
# methods "add", "remove", "server_state_changed",
10
# "entry_group_state_changed", "cleanup", and "activate" in the
11
# "AvahiService" class, and some lines in "main".
14
# Copyright © 2008-2011 Teddy Hogeborn
15
# Copyright © 2008-2011 Björn Påhlsson
17
# This program is free software: you can redistribute it and/or modify
18
# it under the terms of the GNU General Public License as published by
19
# the Free Software Foundation, either version 3 of the License, or
20
# (at your option) any later version.
22
# This program is distributed in the hope that it will be useful,
23
# but WITHOUT ANY WARRANTY; without even the implied warranty of
24
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
25
# GNU General Public License for more details.
27
# You should have received a copy of the GNU General Public License
28
# along with this program. If not, see
29
# <http://www.gnu.org/licenses/>.
31
# Contact the authors at <mandos@fukt.bsnet.se>.
34
from __future__ import (division, absolute_import, print_function,
37
import SocketServer as socketserver
6
from optparse import OptionParser
42
9
import gnutls.crypto
43
10
import gnutls.connection
44
11
import gnutls.errors
45
import gnutls.library.functions
46
import gnutls.library.constants
47
import gnutls.library.types
48
import ConfigParser as configparser
57
import logging.handlers
63
import cPickle as pickle
64
import multiprocessing
71
from dbus.mainloop.glib import DBusGMainLoop
74
import xml.dom.minidom
78
SO_BINDTODEVICE = socket.SO_BINDTODEVICE
79
except AttributeError:
81
from IN import SO_BINDTODEVICE
83
SO_BINDTODEVICE = None
88
#logger = logging.getLogger('mandos')
89
logger = logging.Logger('mandos')
90
syslogger = (logging.handlers.SysLogHandler
91
(facility = logging.handlers.SysLogHandler.LOG_DAEMON,
92
address = str("/dev/log")))
93
syslogger.setFormatter(logging.Formatter
94
('Mandos [%(process)d]: %(levelname)s:'
96
logger.addHandler(syslogger)
98
console = logging.StreamHandler()
99
console.setFormatter(logging.Formatter('%(name)s [%(process)d]:'
102
logger.addHandler(console)
104
class AvahiError(Exception):
105
def __init__(self, value, *args, **kwargs):
107
super(AvahiError, self).__init__(value, *args, **kwargs)
108
def __unicode__(self):
109
return unicode(repr(self.value))
111
class AvahiServiceError(AvahiError):
114
class AvahiGroupError(AvahiError):
118
class AvahiService(object):
119
"""An Avahi (Zeroconf) service.
122
interface: integer; avahi.IF_UNSPEC or an interface index.
123
Used to optionally bind to the specified interface.
124
name: string; Example: 'Mandos'
125
type: string; Example: '_mandos._tcp'.
126
See <http://www.dns-sd.org/ServiceTypes.html>
127
port: integer; what port to announce
128
TXT: list of strings; TXT record for the service
129
domain: string; Domain to publish on, default to .local if empty.
130
host: string; Host to publish records for, default is localhost
131
max_renames: integer; maximum number of renames
132
rename_count: integer; counter so we only rename after collisions
133
a sensible number of times
134
group: D-Bus Entry Group
136
bus: dbus.SystemBus()
138
def __init__(self, interface = avahi.IF_UNSPEC, name = None,
139
servicetype = None, port = None, TXT = None,
140
domain = "", host = "", max_renames = 32768,
141
protocol = avahi.PROTO_UNSPEC, bus = None):
142
self.interface = interface
144
self.type = servicetype
146
self.TXT = TXT if TXT is not None else []
149
self.rename_count = 0
150
self.max_renames = max_renames
151
self.protocol = protocol
152
self.group = None # our entry group
155
self.entry_group_state_changed_match = None
157
"""Derived from the Avahi example code"""
158
if self.rename_count >= self.max_renames:
159
logger.critical("No suitable Zeroconf service name found"
160
" after %i retries, exiting.",
162
raise AvahiServiceError("Too many renames")
163
self.name = unicode(self.server.GetAlternativeServiceName(self.name))
164
logger.info("Changing Zeroconf service name to %r ...",
166
syslogger.setFormatter(logging.Formatter
167
('Mandos (%s) [%%(process)d]:'
168
' %%(levelname)s: %%(message)s'
173
except dbus.exceptions.DBusException as error:
174
logger.critical("DBusException: %s", error)
177
self.rename_count += 1
179
"""Derived from the Avahi example code"""
180
if self.entry_group_state_changed_match is not None:
181
self.entry_group_state_changed_match.remove()
182
self.entry_group_state_changed_match = None
183
if self.group is not None:
186
"""Derived from the Avahi example code"""
188
if self.group is None:
189
self.group = dbus.Interface(
190
self.bus.get_object(avahi.DBUS_NAME,
191
self.server.EntryGroupNew()),
192
avahi.DBUS_INTERFACE_ENTRY_GROUP)
193
self.entry_group_state_changed_match = (
194
self.group.connect_to_signal(
195
'StateChanged', self .entry_group_state_changed))
196
logger.debug("Adding Zeroconf service '%s' of type '%s' ...",
197
self.name, self.type)
198
self.group.AddService(
201
dbus.UInt32(0), # flags
202
self.name, self.type,
203
self.domain, self.host,
204
dbus.UInt16(self.port),
205
avahi.string_array_to_txt_array(self.TXT))
207
def entry_group_state_changed(self, state, error):
208
"""Derived from the Avahi example code"""
209
logger.debug("Avahi entry group state change: %i", state)
211
if state == avahi.ENTRY_GROUP_ESTABLISHED:
212
logger.debug("Zeroconf service established.")
213
elif state == avahi.ENTRY_GROUP_COLLISION:
214
logger.info("Zeroconf service name collision.")
216
elif state == avahi.ENTRY_GROUP_FAILURE:
217
logger.critical("Avahi: Error in group state changed %s",
219
raise AvahiGroupError("State changed: %s"
222
"""Derived from the Avahi example code"""
223
if self.group is not None:
226
except (dbus.exceptions.UnknownMethodException,
227
dbus.exceptions.DBusException) as e:
231
def server_state_changed(self, state, error=None):
232
"""Derived from the Avahi example code"""
233
logger.debug("Avahi server state change: %i", state)
234
bad_states = { avahi.SERVER_INVALID:
235
"Zeroconf server invalid",
236
avahi.SERVER_REGISTERING: None,
237
avahi.SERVER_COLLISION:
238
"Zeroconf server name collision",
239
avahi.SERVER_FAILURE:
240
"Zeroconf server failure" }
241
if state in bad_states:
242
if bad_states[state] is not None:
244
logger.error(bad_states[state])
246
logger.error(bad_states[state] + ": %r", error)
248
elif state == avahi.SERVER_RUNNING:
252
logger.debug("Unknown state: %r", state)
254
logger.debug("Unknown state: %r: %r", state, error)
256
"""Derived from the Avahi example code"""
257
if self.server is None:
258
self.server = dbus.Interface(
259
self.bus.get_object(avahi.DBUS_NAME,
260
avahi.DBUS_PATH_SERVER,
261
follow_name_owner_changes=True),
262
avahi.DBUS_INTERFACE_SERVER)
263
self.server.connect_to_signal("StateChanged",
264
self.server_state_changed)
265
self.server_state_changed(self.server.GetState())
268
def _timedelta_to_milliseconds(td):
269
"Convert a datetime.timedelta() to milliseconds"
270
return ((td.days * 24 * 60 * 60 * 1000)
271
+ (td.seconds * 1000)
272
+ (td.microseconds // 1000))
274
15
class Client(object):
275
"""A representation of a client host served by this server.
278
_approved: bool(); 'None' if not yet approved/disapproved
279
approval_delay: datetime.timedelta(); Time to wait for approval
280
approval_duration: datetime.timedelta(); Duration of one approval
281
checker: subprocess.Popen(); a running checker process used
282
to see if the client lives.
283
'None' if no process is running.
284
checker_callback_tag: a gobject event source tag, or None
285
checker_command: string; External command which is run to check
286
if client lives. %() expansions are done at
287
runtime with vars(self) as dict, so that for
288
instance %(name)s can be used in the command.
289
checker_initiator_tag: a gobject event source tag, or None
290
created: datetime.datetime(); (UTC) object creation
291
current_checker_command: string; current running checker_command
292
disable_hook: If set, called by disable() as disable_hook(self)
293
disable_initiator_tag: a gobject event source tag, or None
295
fingerprint: string (40 or 32 hexadecimal digits); used to
296
uniquely identify the client
297
host: string; available for use by the checker command
298
interval: datetime.timedelta(); How often to start a new checker
299
last_approval_request: datetime.datetime(); (UTC) or None
300
last_checked_ok: datetime.datetime(); (UTC) or None
301
last_enabled: datetime.datetime(); (UTC)
302
name: string; from the config file, used in log messages and
304
secret: bytestring; sent verbatim (over TLS) to client
305
timeout: datetime.timedelta(); How long from last_checked_ok
306
until this client is disabled
307
extended_timeout: extra long timeout when password has been sent
308
runtime_expansions: Allowed attributes for runtime expansion.
309
expires: datetime.datetime(); time (UTC) when a client will be
313
runtime_expansions = ("approval_delay", "approval_duration",
314
"created", "enabled", "fingerprint",
315
"host", "interval", "last_checked_ok",
316
"last_enabled", "name", "timeout")
318
def timeout_milliseconds(self):
319
"Return the 'timeout' attribute in milliseconds"
320
return _timedelta_to_milliseconds(self.timeout)
322
def extended_timeout_milliseconds(self):
323
"Return the 'extended_timeout' attribute in milliseconds"
324
return _timedelta_to_milliseconds(self.extended_timeout)
326
def interval_milliseconds(self):
327
"Return the 'interval' attribute in milliseconds"
328
return _timedelta_to_milliseconds(self.interval)
330
def approval_delay_milliseconds(self):
331
return _timedelta_to_milliseconds(self.approval_delay)
333
def __init__(self, name = None, disable_hook=None, config=None):
334
"""Note: the 'checker' key in 'config' sets the
335
'checker_command' attribute and *not* the 'checker'
16
def __init__(self, name=None, dn=None, password=None,
17
passfile=None, fqdn=None, timeout=None,
340
logger.debug("Creating client %r", self.name)
341
# Uppercase and remove spaces from fingerprint for later
342
# comparison purposes with return value from the fingerprint()
344
self.fingerprint = (config["fingerprint"].upper()
346
logger.debug(" Fingerprint: %s", self.fingerprint)
347
if "secret" in config:
348
self.secret = config["secret"].decode("base64")
349
elif "secfile" in config:
350
with open(os.path.expanduser(os.path.expandvars
351
(config["secfile"])),
353
self.secret = secfile.read()
355
raise TypeError("No secret or secfile for client %s"
357
self.host = config.get("host", "")
358
self.created = datetime.datetime.utcnow()
360
self.last_approval_request = None
361
self.last_enabled = None
362
self.last_checked_ok = None
363
self.timeout = string_to_delta(config["timeout"])
364
self.extended_timeout = string_to_delta(config["extended_timeout"])
365
self.interval = string_to_delta(config["interval"])
366
self.disable_hook = disable_hook
368
self.checker_initiator_tag = None
369
self.disable_initiator_tag = None
371
self.checker_callback_tag = None
372
self.checker_command = config["checker"]
373
self.current_checker_command = None
374
self.last_connect = None
375
self._approved = None
376
self.approved_by_default = config.get("approved_by_default",
378
self.approvals_pending = 0
379
self.approval_delay = string_to_delta(
380
config["approval_delay"])
381
self.approval_duration = string_to_delta(
382
config["approval_duration"])
383
self.changedstate = multiprocessing_manager.Condition(multiprocessing_manager.Lock())
385
def send_changedstate(self):
386
self.changedstate.acquire()
387
self.changedstate.notify_all()
388
self.changedstate.release()
391
"""Start this client's checker and timeout hooks"""
392
if getattr(self, "enabled", False):
395
self.send_changedstate()
396
# Schedule a new checker to be started an 'interval' from now,
397
# and every interval from then on.
398
self.checker_initiator_tag = (gobject.timeout_add
399
(self.interval_milliseconds(),
401
# Schedule a disable() when 'timeout' has passed
402
self.expires = datetime.datetime.utcnow() + self.timeout
403
self.disable_initiator_tag = (gobject.timeout_add
404
(self.timeout_milliseconds(),
407
self.last_enabled = datetime.datetime.utcnow()
408
# Also start a new checker *right now*.
411
def disable(self, quiet=True):
412
"""Disable this client."""
413
if not getattr(self, "enabled", False):
416
self.send_changedstate()
418
logger.info("Disabling client %s", self.name)
419
if getattr(self, "disable_initiator_tag", False):
420
gobject.source_remove(self.disable_initiator_tag)
421
self.disable_initiator_tag = None
423
if getattr(self, "checker_initiator_tag", False):
424
gobject.source_remove(self.checker_initiator_tag)
425
self.checker_initiator_tag = None
427
if self.disable_hook:
428
self.disable_hook(self)
430
# Do not run this again if called by a gobject.timeout_add
434
self.disable_hook = None
437
def checker_callback(self, pid, condition, command):
438
"""The checker has completed, so take appropriate actions."""
439
self.checker_callback_tag = None
441
if os.WIFEXITED(condition):
442
exitstatus = os.WEXITSTATUS(condition)
444
logger.info("Checker for %(name)s succeeded",
448
logger.info("Checker for %(name)s failed",
451
logger.warning("Checker for %(name)s crashed?",
454
def checked_ok(self, timeout=None):
455
"""Bump up the timeout for this client.
457
This should only be called when the client has been seen,
22
self.password = password
24
self.password = open(passfile).readall()
26
print "No Password or Passfile in client config file"
27
# raise RuntimeError XXX
28
self.password = "gazonk"
30
self.created = datetime.datetime.now()
460
32
if timeout is None:
461
timeout = self.timeout
462
self.last_checked_ok = datetime.datetime.utcnow()
463
gobject.source_remove(self.disable_initiator_tag)
464
self.expires = datetime.datetime.utcnow() + timeout
465
self.disable_initiator_tag = (gobject.timeout_add
466
(_timedelta_to_milliseconds(timeout),
469
def need_approval(self):
470
self.last_approval_request = datetime.datetime.utcnow()
472
def start_checker(self):
473
"""Start a new checker subprocess if one is not running.
475
If a checker already exists, leave it running and do
477
# The reason for not killing a running checker is that if we
478
# did that, then if a checker (for some reason) started
479
# running slowly and taking more than 'interval' time, the
480
# client would inevitably timeout, since no checker would get
481
# a chance to run to completion. If we instead leave running
482
# checkers alone, the checker would have to take more time
483
# than 'timeout' for the client to be disabled, which is as it
486
# If a checker exists, make sure it is not a zombie
33
timeout = self.server.options.timeout
34
self.timeout = timeout
36
interval = self.server.options.interval
37
self.interval = interval
38
self.next_check = datetime.datetime.now()
40
def server_bind(self):
41
if self.options.interface:
42
if not hasattr(socket, "SO_BINDTODEVICE"):
43
# From /usr/include/asm-i486/socket.h
44
socket.SO_BINDTODEVICE = 25
488
pid, status = os.waitpid(self.checker.pid, os.WNOHANG)
489
except (AttributeError, OSError) as error:
490
if (isinstance(error, OSError)
491
and error.errno != errno.ECHILD):
46
self.socket.setsockopt(socket.SOL_SOCKET,
47
socket.SO_BINDTODEVICE,
48
self.options.interface)
49
except socket.error, error:
50
if error[0] == errno.EPERM:
51
print "Warning: Denied permission to bind to interface", \
52
self.options.interface
495
logger.warning("Checker was a zombie")
496
gobject.source_remove(self.checker_callback_tag)
497
self.checker_callback(pid, status,
498
self.current_checker_command)
499
# Start a new checker if needed
500
if self.checker is None:
502
# In case checker_command has exactly one % operator
503
command = self.checker_command % self.host
505
# Escape attributes for the shell
506
escaped_attrs = dict(
508
re.escape(unicode(str(getattr(self, attr, "")),
512
self.runtime_expansions)
515
command = self.checker_command % escaped_attrs
516
except TypeError as error:
517
logger.error('Could not format string "%s":'
518
' %s', self.checker_command, error)
519
return True # Try again later
520
self.current_checker_command = command
522
logger.info("Starting checker %r for %s",
524
# We don't need to redirect stdout and stderr, since
525
# in normal mode, that is already done by daemon(),
526
# and in debug mode we don't want to. (Stdin is
527
# always replaced by /dev/null.)
528
self.checker = subprocess.Popen(command,
531
self.checker_callback_tag = (gobject.child_watch_add
533
self.checker_callback,
535
# The checker may have completed before the gobject
536
# watch was added. Check for this.
537
pid, status = os.waitpid(self.checker.pid, os.WNOHANG)
539
gobject.source_remove(self.checker_callback_tag)
540
self.checker_callback(pid, status, command)
541
except OSError as error:
542
logger.error("Failed to start subprocess: %s",
544
# Re-run this periodically if run by gobject.timeout_add
547
def stop_checker(self):
548
"""Force the checker process, if any, to stop."""
549
if self.checker_callback_tag:
550
gobject.source_remove(self.checker_callback_tag)
551
self.checker_callback_tag = None
552
if getattr(self, "checker", None) is None:
554
logger.debug("Stopping checker for %(name)s", vars(self))
556
os.kill(self.checker.pid, signal.SIGTERM)
558
#if self.checker.poll() is None:
559
# os.kill(self.checker.pid, signal.SIGKILL)
560
except OSError as error:
561
if error.errno != errno.ESRCH: # No such process
566
def dbus_service_property(dbus_interface, signature="v",
567
access="readwrite", byte_arrays=False):
568
"""Decorators for marking methods of a DBusObjectWithProperties to
569
become properties on the D-Bus.
571
The decorated method will be called with no arguments by "Get"
572
and with one argument by "Set".
574
The parameters, where they are supported, are the same as
575
dbus.service.method, except there is only "signature", since the
576
type from Get() and the type sent to Set() is the same.
578
# Encoding deeply encoded byte arrays is not supported yet by the
579
# "Set" method, so we fail early here:
580
if byte_arrays and signature != "ay":
581
raise ValueError("Byte arrays not supported for non-'ay'"
582
" signature %r" % signature)
584
func._dbus_is_property = True
585
func._dbus_interface = dbus_interface
586
func._dbus_signature = signature
587
func._dbus_access = access
588
func._dbus_name = func.__name__
589
if func._dbus_name.endswith("_dbus_property"):
590
func._dbus_name = func._dbus_name[:-14]
591
func._dbus_get_args_options = {'byte_arrays': byte_arrays }
596
class DBusPropertyException(dbus.exceptions.DBusException):
597
"""A base class for D-Bus property-related exceptions
599
def __unicode__(self):
600
return unicode(str(self))
603
class DBusPropertyAccessException(DBusPropertyException):
604
"""A property's access permissions disallows an operation.
609
class DBusPropertyNotFound(DBusPropertyException):
610
"""An attempt was made to access a non-existing property.
615
class DBusObjectWithProperties(dbus.service.Object):
616
"""A D-Bus object with properties.
618
Classes inheriting from this can use the dbus_service_property
619
decorator to expose methods as D-Bus properties. It exposes the
620
standard Get(), Set(), and GetAll() methods on the D-Bus.
624
def _is_dbus_property(obj):
625
return getattr(obj, "_dbus_is_property", False)
627
def _get_all_dbus_properties(self):
628
"""Returns a generator of (name, attribute) pairs
630
return ((prop.__get__(self)._dbus_name, prop.__get__(self))
631
for cls in self.__class__.__mro__
632
for name, prop in inspect.getmembers(cls, self._is_dbus_property))
634
def _get_dbus_property(self, interface_name, property_name):
635
"""Returns a bound method if one exists which is a D-Bus
636
property with the specified name and interface.
638
for cls in self.__class__.__mro__:
639
for name, value in inspect.getmembers(cls, self._is_dbus_property):
640
if value._dbus_name == property_name and value._dbus_interface == interface_name:
641
return value.__get__(self)
644
raise DBusPropertyNotFound(self.dbus_object_path + ":"
645
+ interface_name + "."
648
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ss",
650
def Get(self, interface_name, property_name):
651
"""Standard D-Bus property Get() method, see D-Bus standard.
653
prop = self._get_dbus_property(interface_name, property_name)
654
if prop._dbus_access == "write":
655
raise DBusPropertyAccessException(property_name)
657
if not hasattr(value, "variant_level"):
659
return type(value)(value, variant_level=value.variant_level+1)
661
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="ssv")
662
def Set(self, interface_name, property_name, value):
663
"""Standard D-Bus property Set() method, see D-Bus standard.
665
prop = self._get_dbus_property(interface_name, property_name)
666
if prop._dbus_access == "read":
667
raise DBusPropertyAccessException(property_name)
668
if prop._dbus_get_args_options["byte_arrays"]:
669
# The byte_arrays option is not supported yet on
670
# signatures other than "ay".
671
if prop._dbus_signature != "ay":
673
value = dbus.ByteArray(''.join(unichr(byte)
677
@dbus.service.method(dbus.PROPERTIES_IFACE, in_signature="s",
678
out_signature="a{sv}")
679
def GetAll(self, interface_name):
680
"""Standard D-Bus property GetAll() method, see D-Bus
683
Note: Will not include properties with access="write".
686
for name, prop in self._get_all_dbus_properties():
688
and interface_name != prop._dbus_interface):
689
# Interface non-empty but did not match
691
# Ignore write-only properties
692
if prop._dbus_access == "write":
695
if not hasattr(value, "variant_level"):
698
all[name] = type(value)(value, variant_level=
699
value.variant_level+1)
700
return dbus.Dictionary(all, signature="sv")
702
@dbus.service.method(dbus.INTROSPECTABLE_IFACE,
704
path_keyword='object_path',
705
connection_keyword='connection')
706
def Introspect(self, object_path, connection):
707
"""Standard D-Bus method, overloaded to insert property tags.
709
xmlstring = dbus.service.Object.Introspect(self, object_path,
712
document = xml.dom.minidom.parseString(xmlstring)
713
def make_tag(document, name, prop):
714
e = document.createElement("property")
715
e.setAttribute("name", name)
716
e.setAttribute("type", prop._dbus_signature)
717
e.setAttribute("access", prop._dbus_access)
719
for if_tag in document.getElementsByTagName("interface"):
720
for tag in (make_tag(document, name, prop)
722
in self._get_all_dbus_properties()
723
if prop._dbus_interface
724
== if_tag.getAttribute("name")):
725
if_tag.appendChild(tag)
726
# Add the names to the return values for the
727
# "org.freedesktop.DBus.Properties" methods
728
if (if_tag.getAttribute("name")
729
== "org.freedesktop.DBus.Properties"):
730
for cn in if_tag.getElementsByTagName("method"):
731
if cn.getAttribute("name") == "Get":
732
for arg in cn.getElementsByTagName("arg"):
733
if (arg.getAttribute("direction")
735
arg.setAttribute("name", "value")
736
elif cn.getAttribute("name") == "GetAll":
737
for arg in cn.getElementsByTagName("arg"):
738
if (arg.getAttribute("direction")
740
arg.setAttribute("name", "props")
741
xmlstring = document.toxml("utf-8")
743
except (AttributeError, xml.dom.DOMException,
744
xml.parsers.expat.ExpatError) as error:
745
logger.error("Failed to override Introspection method",
750
def datetime_to_dbus (dt, variant_level=0):
751
"""Convert a UTC datetime.datetime() to a D-Bus type."""
753
return dbus.String("", variant_level = variant_level)
754
return dbus.String(dt.isoformat(),
755
variant_level=variant_level)
757
class transitional_dbus_metaclass(DBusObjectWithProperties.__metaclass__):
758
def __new__(mcs, name, bases, attr):
759
for attrname, old_dbusobj in inspect.getmembers(bases[0]):
760
new_interface = getattr(old_dbusobj, "_dbus_interface", "").replace("se.bsnet.fukt.", "se.recompile.")
761
if (getattr(old_dbusobj, "_dbus_is_signal", False)
762
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
763
unwrappedfunc = dict(zip(old_dbusobj.func_code.co_freevars,
764
old_dbusobj.__closure__))["func"].cell_contents
765
newfunc = types.FunctionType(unwrappedfunc.func_code,
766
unwrappedfunc.func_globals,
767
unwrappedfunc.func_name,
768
unwrappedfunc.func_defaults,
769
unwrappedfunc.func_closure)
770
new_dbusfunc = dbus.service.signal(
771
new_interface, old_dbusobj._dbus_signature)(newfunc)
772
attr["_transitional_" + attrname] = new_dbusfunc
774
def fixscope(func1, func2):
775
def newcall(*args, **kwargs):
776
func1(*args, **kwargs)
777
func2(*args, **kwargs)
780
attr[attrname] = fixscope(old_dbusobj, new_dbusfunc)
782
elif (getattr(old_dbusobj, "_dbus_is_method", False)
783
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
784
new_dbusfunc = (dbus.service.method
786
old_dbusobj._dbus_in_signature,
787
old_dbusobj._dbus_out_signature)
789
(old_dbusobj.func_code,
790
old_dbusobj.func_globals,
791
old_dbusobj.func_name,
792
old_dbusobj.func_defaults,
793
old_dbusobj.func_closure)))
795
attr[attrname] = new_dbusfunc
796
elif (getattr(old_dbusobj, "_dbus_is_property", False)
797
and old_dbusobj._dbus_interface.startswith("se.bsnet.fukt.Mandos")):
798
new_dbusfunc = (dbus_service_property
800
old_dbusobj._dbus_signature,
801
old_dbusobj._dbus_access,
802
old_dbusobj._dbus_get_args_options["byte_arrays"])
804
(old_dbusobj.func_code,
805
old_dbusobj.func_globals,
806
old_dbusobj.func_name,
807
old_dbusobj.func_defaults,
808
old_dbusobj.func_closure)))
810
attr[attrname] = new_dbusfunc
811
return type.__new__(mcs, name, bases, attr)
813
class ClientDBus(Client, DBusObjectWithProperties):
814
"""A Client class using D-Bus
817
dbus_object_path: dbus.ObjectPath
818
bus: dbus.SystemBus()
821
runtime_expansions = (Client.runtime_expansions
822
+ ("dbus_object_path",))
824
# dbus.service.Object doesn't use super(), so we can't either.
826
def __init__(self, bus = None, *args, **kwargs):
827
self._approvals_pending = 0
829
Client.__init__(self, *args, **kwargs)
830
# Only now, when this client is initialized, can it show up on
832
client_object_name = unicode(self.name).translate(
835
self.dbus_object_path = (dbus.ObjectPath
836
("/clients/" + client_object_name))
837
DBusObjectWithProperties.__init__(self, self.bus,
838
self.dbus_object_path)
840
def notifychangeproperty(transform_func,
841
dbus_name, type_func=lambda x: x,
843
""" Modify a variable so that its a property that announce its
845
transform_fun: Function that takes a value and transform it to
847
dbus_name: DBus name of the variable
848
type_func: Function that transform the value before sending it
850
variant_level: DBus variant level. default: 1
853
def setter(self, value):
854
old_value = real_value[0]
855
real_value[0] = value
856
if hasattr(self, "dbus_object_path"):
857
if type_func(old_value) != type_func(real_value[0]):
858
dbus_value = transform_func(type_func(real_value[0]),
860
self.PropertyChanged(dbus.String(dbus_name),
863
return property(lambda self: real_value[0], setter)
866
expires = notifychangeproperty(datetime_to_dbus, "Expires")
867
approvals_pending = notifychangeproperty(dbus.Boolean,
870
enabled = notifychangeproperty(dbus.Boolean, "Enabled")
871
last_enabled = notifychangeproperty(datetime_to_dbus,
873
checker = notifychangeproperty(dbus.Boolean, "CheckerRunning",
874
type_func = lambda checker: checker is not None)
875
last_checked_ok = notifychangeproperty(datetime_to_dbus,
877
last_approval_request = notifychangeproperty(datetime_to_dbus,
878
"LastApprovalRequest")
879
approved_by_default = notifychangeproperty(dbus.Boolean,
881
approval_delay = notifychangeproperty(dbus.UInt16, "ApprovalDelay",
882
type_func = _timedelta_to_milliseconds)
883
approval_duration = notifychangeproperty(dbus.UInt16, "ApprovalDuration",
884
type_func = _timedelta_to_milliseconds)
885
host = notifychangeproperty(dbus.String, "Host")
886
timeout = notifychangeproperty(dbus.UInt16, "Timeout",
887
type_func = _timedelta_to_milliseconds)
888
extended_timeout = notifychangeproperty(dbus.UInt16, "ExtendedTimeout",
889
type_func = _timedelta_to_milliseconds)
890
interval = notifychangeproperty(dbus.UInt16, "Interval",
891
type_func = _timedelta_to_milliseconds)
892
checker_command = notifychangeproperty(dbus.String, "Checker")
894
del notifychangeproperty
896
def __del__(self, *args, **kwargs):
898
self.remove_from_connection()
901
if hasattr(DBusObjectWithProperties, "__del__"):
902
DBusObjectWithProperties.__del__(self, *args, **kwargs)
903
Client.__del__(self, *args, **kwargs)
905
def checker_callback(self, pid, condition, command,
907
self.checker_callback_tag = None
909
if os.WIFEXITED(condition):
910
exitstatus = os.WEXITSTATUS(condition)
912
self.CheckerCompleted(dbus.Int16(exitstatus),
913
dbus.Int64(condition),
914
dbus.String(command))
917
self.CheckerCompleted(dbus.Int16(-1),
918
dbus.Int64(condition),
919
dbus.String(command))
921
return Client.checker_callback(self, pid, condition, command,
924
def start_checker(self, *args, **kwargs):
925
old_checker = self.checker
926
if self.checker is not None:
927
old_checker_pid = self.checker.pid
929
old_checker_pid = None
930
r = Client.start_checker(self, *args, **kwargs)
931
# Only if new checker process was started
932
if (self.checker is not None
933
and old_checker_pid != self.checker.pid):
935
self.CheckerStarted(self.current_checker_command)
938
def _reset_approved(self):
939
self._approved = None
942
def approve(self, value=True):
943
self.send_changedstate()
944
self._approved = value
945
gobject.timeout_add(_timedelta_to_milliseconds
946
(self.approval_duration),
947
self._reset_approved)
950
## D-Bus methods, signals & properties
951
_interface = "se.bsnet.fukt.Mandos.Client"
955
# CheckerCompleted - signal
956
@dbus.service.signal(_interface, signature="nxs")
957
def CheckerCompleted(self, exitcode, waitstatus, command):
961
# CheckerStarted - signal
962
@dbus.service.signal(_interface, signature="s")
963
def CheckerStarted(self, command):
967
# PropertyChanged - signal
968
@dbus.service.signal(_interface, signature="sv")
969
def PropertyChanged(self, property, value):
974
@dbus.service.signal(_interface)
977
Is sent after a successful transfer of secret from the Mandos
978
server to mandos-client
983
@dbus.service.signal(_interface, signature="s")
984
def Rejected(self, reason):
988
# NeedApproval - signal
989
@dbus.service.signal(_interface, signature="tb")
990
def NeedApproval(self, timeout, default):
992
return self.need_approval()
997
@dbus.service.method(_interface, in_signature="b")
998
def Approve(self, value):
1001
# CheckedOK - method
1002
@dbus.service.method(_interface)
1003
def CheckedOK(self):
1007
@dbus.service.method(_interface)
1012
# StartChecker - method
1013
@dbus.service.method(_interface)
1014
def StartChecker(self):
1016
self.start_checker()
1019
@dbus.service.method(_interface)
1024
# StopChecker - method
1025
@dbus.service.method(_interface)
1026
def StopChecker(self):
1031
# ApprovalPending - property
1032
@dbus_service_property(_interface, signature="b", access="read")
1033
def ApprovalPending_dbus_property(self):
1034
return dbus.Boolean(bool(self.approvals_pending))
1036
# ApprovedByDefault - property
1037
@dbus_service_property(_interface, signature="b",
1039
def ApprovedByDefault_dbus_property(self, value=None):
1040
if value is None: # get
1041
return dbus.Boolean(self.approved_by_default)
1042
self.approved_by_default = bool(value)
1044
# ApprovalDelay - property
1045
@dbus_service_property(_interface, signature="t",
1047
def ApprovalDelay_dbus_property(self, value=None):
1048
if value is None: # get
1049
return dbus.UInt64(self.approval_delay_milliseconds())
1050
self.approval_delay = datetime.timedelta(0, 0, 0, value)
1052
# ApprovalDuration - property
1053
@dbus_service_property(_interface, signature="t",
1055
def ApprovalDuration_dbus_property(self, value=None):
1056
if value is None: # get
1057
return dbus.UInt64(_timedelta_to_milliseconds(
1058
self.approval_duration))
1059
self.approval_duration = datetime.timedelta(0, 0, 0, value)
1062
@dbus_service_property(_interface, signature="s", access="read")
1063
def Name_dbus_property(self):
1064
return dbus.String(self.name)
1066
# Fingerprint - property
1067
@dbus_service_property(_interface, signature="s", access="read")
1068
def Fingerprint_dbus_property(self):
1069
return dbus.String(self.fingerprint)
1072
@dbus_service_property(_interface, signature="s",
1074
def Host_dbus_property(self, value=None):
1075
if value is None: # get
1076
return dbus.String(self.host)
1079
# Created - property
1080
@dbus_service_property(_interface, signature="s", access="read")
1081
def Created_dbus_property(self):
1082
return dbus.String(datetime_to_dbus(self.created))
1084
# LastEnabled - property
1085
@dbus_service_property(_interface, signature="s", access="read")
1086
def LastEnabled_dbus_property(self):
1087
return datetime_to_dbus(self.last_enabled)
1089
# Enabled - property
1090
@dbus_service_property(_interface, signature="b",
1092
def Enabled_dbus_property(self, value=None):
1093
if value is None: # get
1094
return dbus.Boolean(self.enabled)
1100
# LastCheckedOK - property
1101
@dbus_service_property(_interface, signature="s",
1103
def LastCheckedOK_dbus_property(self, value=None):
1104
if value is not None:
1107
return datetime_to_dbus(self.last_checked_ok)
1109
# Expires - property
1110
@dbus_service_property(_interface, signature="s", access="read")
1111
def Expires_dbus_property(self):
1112
return datetime_to_dbus(self.expires)
1114
# LastApprovalRequest - property
1115
@dbus_service_property(_interface, signature="s", access="read")
1116
def LastApprovalRequest_dbus_property(self):
1117
return datetime_to_dbus(self.last_approval_request)
1119
# Timeout - property
1120
@dbus_service_property(_interface, signature="t",
1122
def Timeout_dbus_property(self, value=None):
1123
if value is None: # get
1124
return dbus.UInt64(self.timeout_milliseconds())
1125
self.timeout = datetime.timedelta(0, 0, 0, value)
1126
if getattr(self, "disable_initiator_tag", None) is None:
1128
# Reschedule timeout
1129
gobject.source_remove(self.disable_initiator_tag)
1130
self.disable_initiator_tag = None
1132
time_to_die = (self.
1133
_timedelta_to_milliseconds((self
1138
if time_to_die <= 0:
1139
# The timeout has passed
1142
self.expires = (datetime.datetime.utcnow()
1143
+ datetime.timedelta(milliseconds = time_to_die))
1144
self.disable_initiator_tag = (gobject.timeout_add
1145
(time_to_die, self.disable))
1147
# ExtendedTimeout - property
1148
@dbus_service_property(_interface, signature="t",
1150
def ExtendedTimeout_dbus_property(self, value=None):
1151
if value is None: # get
1152
return dbus.UInt64(self.extended_timeout_milliseconds())
1153
self.extended_timeout = datetime.timedelta(0, 0, 0, value)
1155
# Interval - property
1156
@dbus_service_property(_interface, signature="t",
1158
def Interval_dbus_property(self, value=None):
1159
if value is None: # get
1160
return dbus.UInt64(self.interval_milliseconds())
1161
self.interval = datetime.timedelta(0, 0, 0, value)
1162
if getattr(self, "checker_initiator_tag", None) is None:
1164
# Reschedule checker run
1165
gobject.source_remove(self.checker_initiator_tag)
1166
self.checker_initiator_tag = (gobject.timeout_add
1167
(value, self.start_checker))
1168
self.start_checker() # Start one now, too
1170
# Checker - property
1171
@dbus_service_property(_interface, signature="s",
1173
def Checker_dbus_property(self, value=None):
1174
if value is None: # get
1175
return dbus.String(self.checker_command)
1176
self.checker_command = value
1178
# CheckerRunning - property
1179
@dbus_service_property(_interface, signature="b",
1181
def CheckerRunning_dbus_property(self, value=None):
1182
if value is None: # get
1183
return dbus.Boolean(self.checker is not None)
1185
self.start_checker()
1189
# ObjectPath - property
1190
@dbus_service_property(_interface, signature="o", access="read")
1191
def ObjectPath_dbus_property(self):
1192
return self.dbus_object_path # is already a dbus.ObjectPath
1195
@dbus_service_property(_interface, signature="ay",
1196
access="write", byte_arrays=True)
1197
def Secret_dbus_property(self, value):
1198
self.secret = str(value)
1203
class ProxyClient(object):
1204
def __init__(self, child_pipe, fpr, address):
1205
self._pipe = child_pipe
1206
self._pipe.send(('init', fpr, address))
1207
if not self._pipe.recv():
1210
def __getattribute__(self, name):
1211
if(name == '_pipe'):
1212
return super(ProxyClient, self).__getattribute__(name)
1213
self._pipe.send(('getattr', name))
1214
data = self._pipe.recv()
1215
if data[0] == 'data':
1217
if data[0] == 'function':
1218
def func(*args, **kwargs):
1219
self._pipe.send(('funcall', name, args, kwargs))
1220
return self._pipe.recv()[1]
1223
def __setattr__(self, name, value):
1224
if(name == '_pipe'):
1225
return super(ProxyClient, self).__setattr__(name, value)
1226
self._pipe.send(('setattr', name, value))
1228
class ClientDBusTransitional(ClientDBus):
1229
__metaclass__ = transitional_dbus_metaclass
1231
class ClientHandler(socketserver.BaseRequestHandler, object):
1232
"""A class to handle client connections.
1234
Instantiated once for each connection to handle it.
1235
Note: This will run in its own forked process."""
1238
with contextlib.closing(self.server.child_pipe) as child_pipe:
1239
logger.info("TCP connection from: %s",
1240
unicode(self.client_address))
1241
logger.debug("Pipe FD: %d",
1242
self.server.child_pipe.fileno())
1244
session = (gnutls.connection
1245
.ClientSession(self.request,
1247
.X509Credentials()))
1249
# Note: gnutls.connection.X509Credentials is really a
1250
# generic GnuTLS certificate credentials object so long as
1251
# no X.509 keys are added to it. Therefore, we can use it
1252
# here despite using OpenPGP certificates.
1254
#priority = ':'.join(("NONE", "+VERS-TLS1.1",
1255
# "+AES-256-CBC", "+SHA1",
1256
# "+COMP-NULL", "+CTYPE-OPENPGP",
1258
# Use a fallback default, since this MUST be set.
1259
priority = self.server.gnutls_priority
1260
if priority is None:
1262
(gnutls.library.functions
1263
.gnutls_priority_set_direct(session._c_object,
1266
# Start communication using the Mandos protocol
1267
# Get protocol number
1268
line = self.request.makefile().readline()
1269
logger.debug("Protocol version: %r", line)
1271
if int(line.strip().split()[0]) > 1:
1273
except (ValueError, IndexError, RuntimeError) as error:
1274
logger.error("Unknown protocol version: %s", error)
1277
# Start GnuTLS connection
1280
except gnutls.errors.GNUTLSError as error:
1281
logger.warning("Handshake failed: %s", error)
1282
# Do not run session.bye() here: the session is not
1283
# established. Just abandon the request.
1285
logger.debug("Handshake succeeded")
1287
approval_required = False
1290
fpr = self.fingerprint(self.peer_certificate
1293
gnutls.errors.GNUTLSError) as error:
1294
logger.warning("Bad certificate: %s", error)
1296
logger.debug("Fingerprint: %s", fpr)
1299
client = ProxyClient(child_pipe, fpr,
1300
self.client_address)
1304
if client.approval_delay:
1305
delay = client.approval_delay
1306
client.approvals_pending += 1
1307
approval_required = True
1310
if not client.enabled:
1311
logger.info("Client %s is disabled",
1313
if self.server.use_dbus:
1315
client.Rejected("Disabled")
1318
if client._approved or not client.approval_delay:
1319
#We are approved or approval is disabled
1321
elif client._approved is None:
1322
logger.info("Client %s needs approval",
1324
if self.server.use_dbus:
1326
client.NeedApproval(
1327
client.approval_delay_milliseconds(),
1328
client.approved_by_default)
1330
logger.warning("Client %s was not approved",
1332
if self.server.use_dbus:
1334
client.Rejected("Denied")
1337
#wait until timeout or approved
1338
#x = float(client._timedelta_to_milliseconds(delay))
1339
time = datetime.datetime.now()
1340
client.changedstate.acquire()
1341
client.changedstate.wait(float(client._timedelta_to_milliseconds(delay) / 1000))
1342
client.changedstate.release()
1343
time2 = datetime.datetime.now()
1344
if (time2 - time) >= delay:
1345
if not client.approved_by_default:
1346
logger.warning("Client %s timed out while"
1347
" waiting for approval",
1349
if self.server.use_dbus:
1351
client.Rejected("Approval timed out")
1356
delay -= time2 - time
1359
while sent_size < len(client.secret):
1361
sent = session.send(client.secret[sent_size:])
1362
except gnutls.errors.GNUTLSError as error:
1363
logger.warning("gnutls send failed")
1365
logger.debug("Sent: %d, remaining: %d",
1366
sent, len(client.secret)
1367
- (sent_size + sent))
1370
logger.info("Sending secret to %s", client.name)
1371
# bump the timeout as if seen
1372
client.checked_ok(client.extended_timeout)
1373
if self.server.use_dbus:
1378
if approval_required:
1379
client.approvals_pending -= 1
1382
except gnutls.errors.GNUTLSError as error:
1383
logger.warning("GnuTLS bye failed")
1386
def peer_certificate(session):
1387
"Return the peer's OpenPGP certificate as a bytestring"
1388
# If not an OpenPGP certificate...
1389
if (gnutls.library.functions
1390
.gnutls_certificate_type_get(session._c_object)
1391
!= gnutls.library.constants.GNUTLS_CRT_OPENPGP):
1392
# ...do the normal thing
1393
return session.peer_certificate
1394
list_size = ctypes.c_uint(1)
1395
cert_list = (gnutls.library.functions
1396
.gnutls_certificate_get_peers
1397
(session._c_object, ctypes.byref(list_size)))
1398
if not bool(cert_list) and list_size.value != 0:
1399
raise gnutls.errors.GNUTLSError("error getting peer"
1401
if list_size.value == 0:
1404
return ctypes.string_at(cert.data, cert.size)
1407
def fingerprint(openpgp):
1408
"Convert an OpenPGP bytestring to a hexdigit fingerprint"
1409
# New GnuTLS "datum" with the OpenPGP public key
1410
datum = (gnutls.library.types
1411
.gnutls_datum_t(ctypes.cast(ctypes.c_char_p(openpgp),
1414
ctypes.c_uint(len(openpgp))))
1415
# New empty GnuTLS certificate
1416
crt = gnutls.library.types.gnutls_openpgp_crt_t()
1417
(gnutls.library.functions
1418
.gnutls_openpgp_crt_init(ctypes.byref(crt)))
1419
# Import the OpenPGP public key into the certificate
1420
(gnutls.library.functions
1421
.gnutls_openpgp_crt_import(crt, ctypes.byref(datum),
1422
gnutls.library.constants
1423
.GNUTLS_OPENPGP_FMT_RAW))
1424
# Verify the self signature in the key
1425
crtverify = ctypes.c_uint()
1426
(gnutls.library.functions
1427
.gnutls_openpgp_crt_verify_self(crt, 0,
1428
ctypes.byref(crtverify)))
1429
if crtverify.value != 0:
1430
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
1431
raise (gnutls.errors.CertificateSecurityError
1433
# New buffer for the fingerprint
1434
buf = ctypes.create_string_buffer(20)
1435
buf_len = ctypes.c_size_t()
1436
# Get the fingerprint from the certificate into the buffer
1437
(gnutls.library.functions
1438
.gnutls_openpgp_crt_get_fingerprint(crt, ctypes.byref(buf),
1439
ctypes.byref(buf_len)))
1440
# Deinit the certificate
1441
gnutls.library.functions.gnutls_openpgp_crt_deinit(crt)
1442
# Convert the buffer to a Python bytestring
1443
fpr = ctypes.string_at(buf, buf_len.value)
1444
# Convert the bytestring to hexadecimal notation
1445
hex_fpr = ''.join("%02X" % ord(char) for char in fpr)
1449
class MultiprocessingMixIn(object):
1450
"""Like socketserver.ThreadingMixIn, but with multiprocessing"""
1451
def sub_process_main(self, request, address):
1453
self.finish_request(request, address)
1455
self.handle_error(request, address)
1456
self.close_request(request)
1458
def process_request(self, request, address):
1459
"""Start a new process to process the request."""
1460
multiprocessing.Process(target = self.sub_process_main,
1461
args = (request, address)).start()
1464
class MultiprocessingMixInWithPipe(MultiprocessingMixIn, object):
1465
""" adds a pipe to the MixIn """
1466
def process_request(self, request, client_address):
1467
"""Overrides and wraps the original process_request().
1469
This function creates a new pipe in self.pipe
1471
parent_pipe, self.child_pipe = multiprocessing.Pipe()
1473
super(MultiprocessingMixInWithPipe,
1474
self).process_request(request, client_address)
1475
self.child_pipe.close()
1476
self.add_pipe(parent_pipe)
1478
def add_pipe(self, parent_pipe):
1479
"""Dummy function; override as necessary"""
1480
raise NotImplementedError
1483
class IPv6_TCPServer(MultiprocessingMixInWithPipe,
1484
socketserver.TCPServer, object):
1485
"""IPv6-capable TCP server. Accepts 'None' as address and/or port
1488
enabled: Boolean; whether this server is activated yet
1489
interface: None or a network interface name (string)
1490
use_ipv6: Boolean; to use IPv6 or not
1492
def __init__(self, server_address, RequestHandlerClass,
1493
interface=None, use_ipv6=True):
1494
self.interface = interface
1496
self.address_family = socket.AF_INET6
1497
socketserver.TCPServer.__init__(self, server_address,
1498
RequestHandlerClass)
1499
def server_bind(self):
1500
"""This overrides the normal server_bind() function
1501
to bind to an interface if one was specified, and also NOT to
1502
bind to an address or port if they were not specified."""
1503
if self.interface is not None:
1504
if SO_BINDTODEVICE is None:
1505
logger.error("SO_BINDTODEVICE does not exist;"
1506
" cannot bind to interface %s",
1510
self.socket.setsockopt(socket.SOL_SOCKET,
1514
except socket.error as error:
1515
if error[0] == errno.EPERM:
1516
logger.error("No permission to"
1517
" bind to interface %s",
1519
elif error[0] == errno.ENOPROTOOPT:
1520
logger.error("SO_BINDTODEVICE not available;"
1521
" cannot bind to interface %s",
1525
# Only bind(2) the socket if we really need to.
1526
if self.server_address[0] or self.server_address[1]:
1527
if not self.server_address[0]:
1528
if self.address_family == socket.AF_INET6:
1529
any_address = "::" # in6addr_any
1531
any_address = socket.INADDR_ANY
1532
self.server_address = (any_address,
1533
self.server_address[1])
1534
elif not self.server_address[1]:
1535
self.server_address = (self.server_address[0],
1537
# if self.interface:
1538
# self.server_address = (self.server_address[0],
1543
return socketserver.TCPServer.server_bind(self)
1546
class MandosServer(IPv6_TCPServer):
1550
clients: set of Client objects
1551
gnutls_priority GnuTLS priority string
1552
use_dbus: Boolean; to emit D-Bus signals or not
1554
Assumes a gobject.MainLoop event loop.
1556
def __init__(self, server_address, RequestHandlerClass,
1557
interface=None, use_ipv6=True, clients=None,
1558
gnutls_priority=None, use_dbus=True):
1559
self.enabled = False
1560
self.clients = clients
1561
if self.clients is None:
1562
self.clients = set()
1563
self.use_dbus = use_dbus
1564
self.gnutls_priority = gnutls_priority
1565
IPv6_TCPServer.__init__(self, server_address,
1566
RequestHandlerClass,
1567
interface = interface,
1568
use_ipv6 = use_ipv6)
1569
def server_activate(self):
1571
return socketserver.TCPServer.server_activate(self)
1574
def add_pipe(self, parent_pipe):
1575
# Call "handle_ipc" for both data and EOF events
1576
gobject.io_add_watch(parent_pipe.fileno(),
1577
gobject.IO_IN | gobject.IO_HUP,
1578
functools.partial(self.handle_ipc,
1579
parent_pipe = parent_pipe))
1581
def handle_ipc(self, source, condition, parent_pipe=None,
1582
client_object=None):
1584
gobject.IO_IN: "IN", # There is data to read.
1585
gobject.IO_OUT: "OUT", # Data can be written (without
1587
gobject.IO_PRI: "PRI", # There is urgent data to read.
1588
gobject.IO_ERR: "ERR", # Error condition.
1589
gobject.IO_HUP: "HUP" # Hung up (the connection has been
1590
# broken, usually for pipes and
1593
conditions_string = ' | '.join(name
1595
condition_names.iteritems()
1596
if cond & condition)
1597
# error or the other end of multiprocessing.Pipe has closed
1598
if condition & (gobject.IO_ERR | condition & gobject.IO_HUP):
1601
# Read a request from the child
1602
request = parent_pipe.recv()
1603
command = request[0]
1605
if command == 'init':
1607
address = request[2]
1609
for c in self.clients:
1610
if c.fingerprint == fpr:
1614
logger.info("Client not found for fingerprint: %s, ad"
1615
"dress: %s", fpr, address)
1618
mandos_dbus_service.ClientNotFound(fpr, address[0])
1619
parent_pipe.send(False)
1622
gobject.io_add_watch(parent_pipe.fileno(),
1623
gobject.IO_IN | gobject.IO_HUP,
1624
functools.partial(self.handle_ipc,
1625
parent_pipe = parent_pipe,
1626
client_object = client))
1627
parent_pipe.send(True)
1628
# remove the old hook in favor of the new above hook on same fileno
1630
if command == 'funcall':
1631
funcname = request[1]
1635
parent_pipe.send(('data', getattr(client_object, funcname)(*args, **kwargs)))
1637
if command == 'getattr':
1638
attrname = request[1]
1639
if callable(client_object.__getattribute__(attrname)):
1640
parent_pipe.send(('function',))
1642
parent_pipe.send(('data', client_object.__getattribute__(attrname)))
1644
if command == 'setattr':
1645
attrname = request[1]
1647
setattr(client_object, attrname, value)
55
return super(type(self), self).server_bind()
58
def init_with_options(self, *args, **kwargs):
59
if "options" in kwargs:
60
self.options = kwargs["options"]
62
if "clients" in kwargs:
63
self.clients = kwargs["clients"]
65
if "credentials" in kwargs:
66
self.credentials = kwargs["credentials"]
67
del kwargs["credentials"]
68
return super(type(self), self).__init__(*args, **kwargs)
71
class udp_handler(SocketServer.DatagramRequestHandler, object):
73
self.wfile.write("Polo")
74
print "UDP request answered"
77
class IPv6_UDPServer(SocketServer.UDPServer, object):
78
__init__ = init_with_options
79
address_family = socket.AF_INET6
80
allow_reuse_address = True
81
server_bind = server_bind
82
def verify_request(self, request, client_address):
83
print "UDP request came"
84
return request[0] == "Marco"
87
class tcp_handler(SocketServer.BaseRequestHandler, object):
89
print "TCP request came"
90
print "Request:", self.request
91
print "Client Address:", self.client_address
92
print "Server:", self.server
93
session = gnutls.connection.ServerSession(self.request,
94
self.server.credentials)
96
if session.peer_certificate:
97
print "DN:", session.peer_certificate.subject
100
except gnutls.errors.CertificateError, error:
101
print "Verify failed", error
105
session.send(dict((client.dn, client.password)
106
for client in self.server.clients)
107
[session.peer_certificate.subject])
109
session.send("gazonk")
113
class IPv6_TCPServer(SocketServer.ForkingTCPServer, object):
114
__init__ = init_with_options
115
address_family = socket.AF_INET6
116
allow_reuse_address = True
117
request_queue_size = 1024
118
server_bind = server_bind
1652
125
def string_to_delta(interval):
1653
126
"""Parse a string and return a datetime.timedelta
1655
128
>>> string_to_delta('7d')
1656
129
datetime.timedelta(7)
1657
130
>>> string_to_delta('60s')
1660
133
datetime.timedelta(0, 3600)
1661
134
>>> string_to_delta('24h')
1662
135
datetime.timedelta(1)
1663
>>> string_to_delta('1w')
136
>>> string_to_delta(u'1w')
1664
137
datetime.timedelta(7)
1665
>>> string_to_delta('5m 30s')
1666
datetime.timedelta(0, 330)
1668
timevalue = datetime.timedelta(0)
1669
for s in interval.split():
1671
suffix = unicode(s[-1])
1674
delta = datetime.timedelta(value)
1676
delta = datetime.timedelta(0, value)
1678
delta = datetime.timedelta(0, 0, 0, 0, value)
1680
delta = datetime.timedelta(0, 0, 0, 0, 0, value)
1682
delta = datetime.timedelta(0, 0, 0, 0, 0, 0, value)
1684
raise ValueError("Unknown suffix %r" % suffix)
1685
except (ValueError, IndexError) as e:
1686
raise ValueError(*(e.args))
1691
def if_nametoindex(interface):
1692
"""Call the C function if_nametoindex(), or equivalent
1694
Note: This function cannot accept a unicode string."""
1695
global if_nametoindex
1697
if_nametoindex = (ctypes.cdll.LoadLibrary
1698
(ctypes.util.find_library("c"))
1700
except (OSError, AttributeError):
1701
logger.warning("Doing if_nametoindex the hard way")
1702
def if_nametoindex(interface):
1703
"Get an interface index the hard way, i.e. using fcntl()"
1704
SIOCGIFINDEX = 0x8933 # From /usr/include/linux/sockios.h
1705
with contextlib.closing(socket.socket()) as s:
1706
ifreq = fcntl.ioctl(s, SIOCGIFINDEX,
1707
struct.pack(str("16s16x"),
1709
interface_index = struct.unpack(str("I"),
1711
return interface_index
1712
return if_nametoindex(interface)
1715
def daemon(nochdir = False, noclose = False):
1716
"""See daemon(3). Standard BSD Unix function.
1718
This should really exist as os.daemon, but it doesn't (yet)."""
1727
# Close all standard open file descriptors
1728
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1729
if not stat.S_ISCHR(os.fstat(null).st_mode):
1730
raise OSError(errno.ENODEV,
1731
"%s not a character device"
1733
os.dup2(null, sys.stdin.fileno())
1734
os.dup2(null, sys.stdout.fileno())
1735
os.dup2(null, sys.stderr.fileno())
140
suffix=unicode(interval[-1])
141
value=int(interval[:-1])
143
delta = datetime.timedelta(value)
145
delta = datetime.timedelta(0, value)
147
delta = datetime.timedelta(0, 0, 0, 0, value)
149
delta = datetime.timedelta(0, 0, 0, 0, 0, value)
151
delta = datetime.timedelta(0, 0, 0, 0, 0, 0, value)
154
except (ValueError, IndexError):
1742
##################################################################
1743
# Parsing of options, both command line and config file
1745
parser = argparse.ArgumentParser()
1746
parser.add_argument("-v", "--version", action="version",
1747
version = "%%(prog)s %s" % version,
1748
help="show version number and exit")
1749
parser.add_argument("-i", "--interface", metavar="IF",
1750
help="Bind to interface IF")
1751
parser.add_argument("-a", "--address",
1752
help="Address to listen for requests on")
1753
parser.add_argument("-p", "--port", type=int,
1754
help="Port number to receive requests on")
1755
parser.add_argument("--check", action="store_true",
1756
help="Run self-test")
1757
parser.add_argument("--debug", action="store_true",
1758
help="Debug mode; run in foreground and log"
1760
parser.add_argument("--debuglevel", metavar="LEVEL",
1761
help="Debug level for stdout output")
1762
parser.add_argument("--priority", help="GnuTLS"
1763
" priority string (see GnuTLS documentation)")
1764
parser.add_argument("--servicename",
1765
metavar="NAME", help="Zeroconf service name")
1766
parser.add_argument("--configdir",
1767
default="/etc/mandos", metavar="DIR",
1768
help="Directory to search for configuration"
1770
parser.add_argument("--no-dbus", action="store_false",
1771
dest="use_dbus", help="Do not provide D-Bus"
1772
" system bus interface")
1773
parser.add_argument("--no-ipv6", action="store_false",
1774
dest="use_ipv6", help="Do not use IPv6")
1775
options = parser.parse_args()
159
parser = OptionParser()
160
parser.add_option("-i", "--interface", type="string",
161
default="eth0", metavar="IF",
162
help="Interface to bind to")
163
parser.add_option("--cert", type="string", default="cert.pem",
165
help="Public key certificate to use")
166
parser.add_option("--key", type="string", default="key.pem",
168
help="Private key to use")
169
parser.add_option("--ca", type="string", default="ca.pem",
171
help="Certificate Authority certificate to use")
172
parser.add_option("--crl", type="string", default="crl.pem",
174
help="Certificate Revokation List to use")
175
parser.add_option("-p", "--port", type="int", default=49001,
176
help="Port number to receive requests on")
177
parser.add_option("--dh", type="int", metavar="BITS",
178
help="DH group to use")
179
parser.add_option("-t", "--timeout", type="string", # Parsed later
181
help="Amount of downtime allowed for clients")
182
parser.add_option("--interval", type="string", # Parsed later
184
help="How often to check that a client is up")
185
parser.add_option("--check", action="store_true", default=False,
186
help="Run self-test")
187
(options, args) = parser.parse_args()
1777
189
if options.check:
1779
191
doctest.testmod()
1782
# Default values for config file for server-global settings
1783
server_defaults = { "interface": "",
1788
"SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP",
1789
"servicename": "Mandos",
1795
# Parse config file for server-global settings
1796
server_config = configparser.SafeConfigParser(server_defaults)
1798
server_config.read(os.path.join(options.configdir,
1800
# Convert the SafeConfigParser object to a dict
1801
server_settings = server_config.defaults()
1802
# Use the appropriate methods on the non-string config options
1803
for option in ("debug", "use_dbus", "use_ipv6"):
1804
server_settings[option] = server_config.getboolean("DEFAULT",
1806
if server_settings["port"]:
1807
server_settings["port"] = server_config.getint("DEFAULT",
1811
# Override the settings from the config file with command line
1813
for option in ("interface", "address", "port", "debug",
1814
"priority", "servicename", "configdir",
1815
"use_dbus", "use_ipv6", "debuglevel"):
1816
value = getattr(options, option)
1817
if value is not None:
1818
server_settings[option] = value
1820
# Force all strings to be unicode
1821
for option in server_settings.keys():
1822
if type(server_settings[option]) is str:
1823
server_settings[option] = unicode(server_settings[option])
1824
# Now we have our good server settings in "server_settings"
1826
##################################################################
1829
debug = server_settings["debug"]
1830
debuglevel = server_settings["debuglevel"]
1831
use_dbus = server_settings["use_dbus"]
1832
use_ipv6 = server_settings["use_ipv6"]
1834
if server_settings["servicename"] != "Mandos":
1835
syslogger.setFormatter(logging.Formatter
1836
('Mandos (%s) [%%(process)d]:'
1837
' %%(levelname)s: %%(message)s'
1838
% server_settings["servicename"]))
1840
# Parse config file with clients
1841
client_defaults = { "timeout": "5m",
1842
"extended_timeout": "15m",
1844
"checker": "fping -q -- %%(host)s",
1846
"approval_delay": "0s",
1847
"approval_duration": "1s",
1849
client_config = configparser.SafeConfigParser(client_defaults)
1850
client_config.read(os.path.join(server_settings["configdir"],
1853
global mandos_dbus_service
1854
mandos_dbus_service = None
1856
tcp_server = MandosServer((server_settings["address"],
1857
server_settings["port"]),
1859
interface=(server_settings["interface"]
1863
server_settings["priority"],
1866
pidfilename = "/var/run/mandos.pid"
1868
pidfile = open(pidfilename, "w")
1870
logger.error("Could not open file %r", pidfilename)
1873
uid = pwd.getpwnam("_mandos").pw_uid
1874
gid = pwd.getpwnam("_mandos").pw_gid
1877
uid = pwd.getpwnam("mandos").pw_uid
1878
gid = pwd.getpwnam("mandos").pw_gid
1881
uid = pwd.getpwnam("nobody").pw_uid
1882
gid = pwd.getpwnam("nobody").pw_gid
1889
except OSError as error:
1890
if error[0] != errno.EPERM:
1893
if not debug and not debuglevel:
1894
syslogger.setLevel(logging.WARNING)
1895
console.setLevel(logging.WARNING)
1897
level = getattr(logging, debuglevel.upper())
1898
syslogger.setLevel(level)
1899
console.setLevel(level)
1902
# Enable all possible GnuTLS debugging
1904
# "Use a log level over 10 to enable all debugging options."
1906
gnutls.library.functions.gnutls_global_set_log_level(11)
1908
@gnutls.library.types.gnutls_log_func
1909
def debug_gnutls(level, string):
1910
logger.debug("GnuTLS: %s", string[:-1])
1912
(gnutls.library.functions
1913
.gnutls_global_set_log_function(debug_gnutls))
1915
# Redirect stdin so all checkers get /dev/null
1916
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
1917
os.dup2(null, sys.stdin.fileno())
1921
# No console logging
1922
logger.removeHandler(console)
1924
# Need to fork before connecting to D-Bus
1926
# Close all input and output, do double fork, etc.
1930
# From the Avahi example code
1931
DBusGMainLoop(set_as_default=True )
1932
main_loop = gobject.MainLoop()
1933
bus = dbus.SystemBus()
1934
# End of Avahi example code
1937
bus_name = dbus.service.BusName("se.recompile.Mandos",
1938
bus, do_not_queue=True)
1939
bus_name_transitional = dbus.service.BusName("se.bsnet.fukt.Mandos",
1940
bus, do_not_queue=True)
1941
except dbus.exceptions.NameExistsException as e:
1942
logger.error(unicode(e) + ", disabling D-Bus")
1944
server_settings["use_dbus"] = False
1945
tcp_server.use_dbus = False
1946
protocol = avahi.PROTO_INET6 if use_ipv6 else avahi.PROTO_INET
1947
service = AvahiService(name = server_settings["servicename"],
1948
servicetype = "_mandos._tcp",
1949
protocol = protocol, bus = bus)
1950
if server_settings["interface"]:
1951
service.interface = (if_nametoindex
1952
(str(server_settings["interface"])))
1954
global multiprocessing_manager
1955
multiprocessing_manager = multiprocessing.Manager()
1957
client_class = Client
1959
client_class = functools.partial(ClientDBusTransitional, bus = bus)
1960
def client_config_items(config, section):
1961
special_settings = {
1962
"approved_by_default":
1963
lambda: config.getboolean(section,
1964
"approved_by_default"),
1966
for name, value in config.items(section):
1968
yield (name, special_settings[name]())
1972
tcp_server.clients.update(set(
1973
client_class(name = section,
1974
config= dict(client_config_items(
1975
client_config, section)))
1976
for section in client_config.sections()))
1977
if not tcp_server.clients:
1978
logger.warning("No clients defined")
1984
pidfile.write(str(pid) + "\n".encode("utf-8"))
1987
logger.error("Could not write to file %r with PID %d",
1990
# "pidfile" was never created
1994
signal.signal(signal.SIGINT, signal.SIG_IGN)
1996
signal.signal(signal.SIGHUP, lambda signum, frame: sys.exit())
1997
signal.signal(signal.SIGTERM, lambda signum, frame: sys.exit())
2000
class MandosDBusService(dbus.service.Object):
2001
"""A D-Bus proxy object"""
2003
dbus.service.Object.__init__(self, bus, "/")
2004
_interface = "se.bsnet.fukt.Mandos"
2006
@dbus.service.signal(_interface, signature="o")
2007
def ClientAdded(self, objpath):
2011
@dbus.service.signal(_interface, signature="ss")
2012
def ClientNotFound(self, fingerprint, address):
2016
@dbus.service.signal(_interface, signature="os")
2017
def ClientRemoved(self, objpath, name):
2021
@dbus.service.method(_interface, out_signature="ao")
2022
def GetAllClients(self):
2024
return dbus.Array(c.dbus_object_path
2025
for c in tcp_server.clients)
2027
@dbus.service.method(_interface,
2028
out_signature="a{oa{sv}}")
2029
def GetAllClientsWithProperties(self):
2031
return dbus.Dictionary(
2032
((c.dbus_object_path, c.GetAll(""))
2033
for c in tcp_server.clients),
2036
@dbus.service.method(_interface, in_signature="o")
2037
def RemoveClient(self, object_path):
2039
for c in tcp_server.clients:
2040
if c.dbus_object_path == object_path:
2041
tcp_server.clients.remove(c)
2042
c.remove_from_connection()
2043
# Don't signal anything except ClientRemoved
2044
c.disable(quiet=True)
2046
self.ClientRemoved(object_path, c.name)
2048
raise KeyError(object_path)
2052
class MandosDBusServiceTransitional(MandosDBusService):
2053
__metaclass__ = transitional_dbus_metaclass
2054
mandos_dbus_service = MandosDBusServiceTransitional()
2057
"Cleanup function; run on exit"
2060
while tcp_server.clients:
2061
client = tcp_server.clients.pop()
2063
client.remove_from_connection()
2064
client.disable_hook = None
2065
# Don't signal anything except ClientRemoved
2066
client.disable(quiet=True)
2069
mandos_dbus_service.ClientRemoved(client.dbus_object_path,
2072
atexit.register(cleanup)
2074
for client in tcp_server.clients:
2077
mandos_dbus_service.ClientAdded(client.dbus_object_path)
2081
tcp_server.server_activate()
2083
# Find out what port we got
2084
service.port = tcp_server.socket.getsockname()[1]
2086
logger.info("Now listening on address %r, port %d,"
2087
" flowinfo %d, scope_id %d"
2088
% tcp_server.socket.getsockname())
2090
logger.info("Now listening on address %r, port %d"
2091
% tcp_server.socket.getsockname())
2093
#service.interface = tcp_server.socket.getsockname()[3]
2096
# From the Avahi example code
2099
except dbus.exceptions.DBusException as error:
2100
logger.critical("DBusException: %s", error)
2103
# End of Avahi example code
2105
gobject.io_add_watch(tcp_server.fileno(), gobject.IO_IN,
2106
lambda *args, **kwargs:
2107
(tcp_server.handle_request
2108
(*args[2:], **kwargs) or True))
2110
logger.debug("Starting main loop")
2112
except AvahiError as error:
2113
logger.critical("AvahiError: %s", error)
2116
except KeyboardInterrupt:
2118
print("", file=sys.stderr)
2119
logger.debug("Server received KeyboardInterrupt")
2120
logger.debug("Server exiting")
2121
# Must run before the D-Bus bus name gets deregistered
2125
if __name__ == '__main__':
194
# Parse the time arguments
196
options.timeout = string_to_delta(options.timeout)
198
parser.error("option --timeout: Unparseable time")
201
options.interval = string_to_delta(options.interval)
203
parser.error("option --interval: Unparseable time")
205
cert = gnutls.crypto.X509Certificate(open(options.cert).read())
206
key = gnutls.crypto.X509PrivateKey(open(options.key).read())
207
ca = gnutls.crypto.X509Certificate(open(options.ca).read())
208
crl = gnutls.crypto.X509CRL(open(options.crl).read())
209
cred = gnutls.connection.X509Credentials(cert, key, [ca], [crl])
213
client_config_object = ConfigParser.SafeConfigParser(defaults)
214
client_config_object.read("mandos-clients.conf")
215
clients = [Client(name=section,
216
**(dict(client_config_object.items(section))))
217
for section in client_config_object.sections()]
219
udp_server = IPv6_UDPServer((in6addr_any, options.port),
223
tcp_server = IPv6_TCPServer((in6addr_any, options.port),
230
in_, out, err = select.select((udp_server,
233
server.handle_request()
236
if __name__ == "__main__":