34
34
from __future__ import (division, absolute_import, print_function,
38
from future_builtins import *
37
from future_builtins import *
43
40
import SocketServer as socketserver
121
119
return interface_index
124
def copy_function(func):
125
"""Make a copy of a function"""
126
if sys.version_info.major == 2:
127
return types.FunctionType(func.func_code,
133
return types.FunctionType(func.__code__,
140
122
def initlogger(debug, level=logging.WARNING):
141
123
"""init logger and add loglevel"""
174
156
output = subprocess.check_output(["gpgconf"])
175
157
for line in output.splitlines():
176
name, text, path = line.split(b":")
158
name, text, path = line.split(":")
177
159
if name == "gpg":
256
238
raise PGPError(err)
257
239
return decrypted_plaintext
259
# Pretend that we have an Avahi module
261
"""This isn't so much a class as it is a module-like namespace.
262
It is instantiated once, and simulates having an Avahi module."""
263
IF_UNSPEC = -1 # avahi-common/address.h
264
PROTO_UNSPEC = -1 # avahi-common/address.h
265
PROTO_INET = 0 # avahi-common/address.h
266
PROTO_INET6 = 1 # avahi-common/address.h
267
DBUS_NAME = "org.freedesktop.Avahi"
268
DBUS_INTERFACE_ENTRY_GROUP = DBUS_NAME + ".EntryGroup"
269
DBUS_INTERFACE_SERVER = DBUS_NAME + ".Server"
270
DBUS_PATH_SERVER = "/"
271
def string_array_to_txt_array(self, t):
272
return dbus.Array((dbus.ByteArray(s.encode("utf-8"))
273
for s in t), signature="ay")
274
ENTRY_GROUP_ESTABLISHED = 2 # avahi-common/defs.h
275
ENTRY_GROUP_COLLISION = 3 # avahi-common/defs.h
276
ENTRY_GROUP_FAILURE = 4 # avahi-common/defs.h
277
SERVER_INVALID = 0 # avahi-common/defs.h
278
SERVER_REGISTERING = 1 # avahi-common/defs.h
279
SERVER_RUNNING = 2 # avahi-common/defs.h
280
SERVER_COLLISION = 3 # avahi-common/defs.h
281
SERVER_FAILURE = 4 # avahi-common/defs.h
284
242
class AvahiError(Exception):
285
243
def __init__(self, value, *args, **kwargs):
490
448
_library = ctypes.cdll.LoadLibrary(
491
449
ctypes.util.find_library("gnutls"))
492
_need_version = b"3.3.0"
450
_need_version = "3.3.0"
493
451
def __init__(self):
494
452
# Need to use class name "GnuTLS" here, since this method is
495
453
# called before the assignment to the "gnutls" global variable
529
487
openpgp_crt_t = ctypes.POINTER(openpgp_crt_int)
530
488
openpgp_crt_fmt_t = ctypes.c_int # gnutls/openpgp.h
531
489
log_func = ctypes.CFUNCTYPE(None, ctypes.c_int, ctypes.c_char_p)
532
credentials_type_t = ctypes.c_int
490
credentials_type_t = ctypes.c_int #
533
491
transport_ptr_t = ctypes.c_void_p
534
492
close_request_t = ctypes.c_int
757
715
checker: subprocess.Popen(); a running checker process used
758
716
to see if the client lives.
759
717
'None' if no process is running.
760
checker_callback_tag: a GObject event source tag, or None
718
checker_callback_tag: a gobject event source tag, or None
761
719
checker_command: string; External command which is run to check
762
720
if client lives. %() expansions are done at
763
721
runtime with vars(self) as dict, so that for
764
722
instance %(name)s can be used in the command.
765
checker_initiator_tag: a GObject event source tag, or None
723
checker_initiator_tag: a gobject event source tag, or None
766
724
created: datetime.datetime(); (UTC) object creation
767
725
client_structure: Object describing what attributes a client has
768
726
and is used for storing the client at exit
769
727
current_checker_command: string; current running checker_command
770
disable_initiator_tag: a GObject event source tag, or None
728
disable_initiator_tag: a gobject event source tag, or None
772
730
fingerprint: string (40 or 32 hexadecimal digits); used to
773
731
uniquely identify the client
836
794
client["fingerprint"] = (section["fingerprint"].upper()
837
795
.replace(" ", ""))
838
796
if "secret" in section:
839
client["secret"] = codecs.decode(section["secret"]
797
client["secret"] = section["secret"].decode("base64")
842
798
elif "secfile" in section:
843
799
with open(os.path.expanduser(os.path.expandvars
844
800
(section["secfile"])),
897
853
self.changedstate = multiprocessing_manager.Condition(
898
854
multiprocessing_manager.Lock())
899
855
self.client_structure = [attr
900
for attr in self.__dict__.keys()
856
for attr in self.__dict__.iterkeys()
901
857
if not attr.startswith("_")]
902
858
self.client_structure.append("client_structure")
930
886
logger.info("Disabling client %s", self.name)
931
887
if getattr(self, "disable_initiator_tag", None) is not None:
932
GObject.source_remove(self.disable_initiator_tag)
888
gobject.source_remove(self.disable_initiator_tag)
933
889
self.disable_initiator_tag = None
934
890
self.expires = None
935
891
if getattr(self, "checker_initiator_tag", None) is not None:
936
GObject.source_remove(self.checker_initiator_tag)
892
gobject.source_remove(self.checker_initiator_tag)
937
893
self.checker_initiator_tag = None
938
894
self.stop_checker()
939
895
self.enabled = False
941
897
self.send_changedstate()
942
# Do not run this again if called by a GObject.timeout_add
898
# Do not run this again if called by a gobject.timeout_add
945
901
def __del__(self):
949
905
# Schedule a new checker to be started an 'interval' from now,
950
906
# and every interval from then on.
951
907
if self.checker_initiator_tag is not None:
952
GObject.source_remove(self.checker_initiator_tag)
953
self.checker_initiator_tag = GObject.timeout_add(
908
gobject.source_remove(self.checker_initiator_tag)
909
self.checker_initiator_tag = gobject.timeout_add(
954
910
int(self.interval.total_seconds() * 1000),
955
911
self.start_checker)
956
912
# Schedule a disable() when 'timeout' has passed
957
913
if self.disable_initiator_tag is not None:
958
GObject.source_remove(self.disable_initiator_tag)
959
self.disable_initiator_tag = GObject.timeout_add(
914
gobject.source_remove(self.disable_initiator_tag)
915
self.disable_initiator_tag = gobject.timeout_add(
960
916
int(self.timeout.total_seconds() * 1000), self.disable)
961
917
# Also start a new checker *right now*.
962
918
self.start_checker()
998
954
if timeout is None:
999
955
timeout = self.timeout
1000
956
if self.disable_initiator_tag is not None:
1001
GObject.source_remove(self.disable_initiator_tag)
957
gobject.source_remove(self.disable_initiator_tag)
1002
958
self.disable_initiator_tag = None
1003
959
if getattr(self, "enabled", False):
1004
self.disable_initiator_tag = GObject.timeout_add(
960
self.disable_initiator_tag = gobject.timeout_add(
1005
961
int(timeout.total_seconds() * 1000), self.disable)
1006
962
self.expires = datetime.datetime.utcnow() + timeout
1062
1018
args = (pipe[1], subprocess.call, command),
1063
1019
kwargs = popen_args)
1064
1020
self.checker.start()
1065
self.checker_callback_tag = GObject.io_add_watch(
1066
pipe[0].fileno(), GObject.IO_IN,
1021
self.checker_callback_tag = gobject.io_add_watch(
1022
pipe[0].fileno(), gobject.IO_IN,
1067
1023
self.checker_callback, pipe[0], command)
1068
# Re-run this periodically if run by GObject.timeout_add
1024
# Re-run this periodically if run by gobject.timeout_add
1071
1027
def stop_checker(self):
1072
1028
"""Force the checker process, if any, to stop."""
1073
1029
if self.checker_callback_tag:
1074
GObject.source_remove(self.checker_callback_tag)
1030
gobject.source_remove(self.checker_callback_tag)
1075
1031
self.checker_callback_tag = None
1076
1032
if getattr(self, "checker", None) is None:
1551
1507
interface_names.add(alt_interface)
1552
1508
# Is this a D-Bus signal?
1553
1509
if getattr(attribute, "_dbus_is_signal", False):
1554
# Extract the original non-method undecorated
1555
# function by black magic
1556
1510
if sys.version_info.major == 2:
1511
# Extract the original non-method undecorated
1512
# function by black magic
1557
1513
nonmethod_func = (dict(
1558
1514
zip(attribute.func_code.co_freevars,
1559
1515
attribute.__closure__))
1560
1516
["func"].cell_contents)
1562
nonmethod_func = (dict(
1563
zip(attribute.__code__.co_freevars,
1564
attribute.__closure__))
1565
["func"].cell_contents)
1518
nonmethod_func = attribute
1566
1519
# Create a new, but exactly alike, function
1567
1520
# object, and decorate it to be a new D-Bus signal
1568
1521
# with the alternate D-Bus interface name
1569
new_function = copy_function(nonmethod_func)
1522
if sys.version_info.major == 2:
1523
new_function = types.FunctionType(
1524
nonmethod_func.func_code,
1525
nonmethod_func.func_globals,
1526
nonmethod_func.func_name,
1527
nonmethod_func.func_defaults,
1528
nonmethod_func.func_closure)
1530
new_function = types.FunctionType(
1531
nonmethod_func.__code__,
1532
nonmethod_func.__globals__,
1533
nonmethod_func.__name__,
1534
nonmethod_func.__defaults__,
1535
nonmethod_func.__closure__)
1570
1536
new_function = (dbus.service.signal(
1572
1538
attribute._dbus_signature)(new_function))
1612
1578
attribute._dbus_in_signature,
1613
1579
attribute._dbus_out_signature)
1614
(copy_function(attribute)))
1580
(types.FunctionType(attribute.func_code,
1581
attribute.func_globals,
1582
attribute.func_name,
1583
attribute.func_defaults,
1584
attribute.func_closure)))
1615
1585
# Copy annotations, if any
1617
1587
attr[attrname]._dbus_annotations = dict(
1629
1599
attribute._dbus_access,
1630
1600
attribute._dbus_get_args_options
1631
1601
["byte_arrays"])
1632
(copy_function(attribute)))
1602
(types.FunctionType(
1603
attribute.func_code,
1604
attribute.func_globals,
1605
attribute.func_name,
1606
attribute.func_defaults,
1607
attribute.func_closure)))
1633
1608
# Copy annotations, if any
1635
1610
attr[attrname]._dbus_annotations = dict(
1644
1619
# to the class.
1645
1620
attr[attrname] = (
1646
1621
dbus_interface_annotations(alt_interface)
1647
(copy_function(attribute)))
1622
(types.FunctionType(attribute.func_code,
1623
attribute.func_globals,
1624
attribute.func_name,
1625
attribute.func_defaults,
1626
attribute.func_closure)))
1649
1628
# Deprecate all alternate interfaces
1650
1629
iname="_AlternateDBusNames_interface_annotation{}"
1663
1642
if interface_names:
1664
1643
# Replace the class with a new subclass of it with
1665
1644
# methods, signals, etc. as created above.
1666
if sys.version_info.major == 2:
1667
cls = type(b"{}Alternate".format(cls.__name__),
1670
cls = type("{}Alternate".format(cls.__name__),
1645
cls = type(b"{}Alternate".format(cls.__name__),
1833
1808
def approve(self, value=True):
1834
1809
self.approved = value
1835
GObject.timeout_add(int(self.approval_duration.total_seconds()
1810
gobject.timeout_add(int(self.approval_duration.total_seconds()
1836
1811
* 1000), self._reset_approved)
1837
1812
self.send_changedstate()
2049
2024
if (getattr(self, "disable_initiator_tag", None)
2052
GObject.source_remove(self.disable_initiator_tag)
2053
self.disable_initiator_tag = GObject.timeout_add(
2027
gobject.source_remove(self.disable_initiator_tag)
2028
self.disable_initiator_tag = gobject.timeout_add(
2054
2029
int((self.expires - now).total_seconds() * 1000),
2077
2052
if self.enabled:
2078
2053
# Reschedule checker run
2079
GObject.source_remove(self.checker_initiator_tag)
2080
self.checker_initiator_tag = GObject.timeout_add(
2054
gobject.source_remove(self.checker_initiator_tag)
2055
self.checker_initiator_tag = gobject.timeout_add(
2081
2056
value, self.start_checker)
2082
2057
self.start_checker() # Start one now, too
2487
2462
gnutls_priority GnuTLS priority string
2488
2463
use_dbus: Boolean; to emit D-Bus signals or not
2490
Assumes a GObject.MainLoop event loop.
2465
Assumes a gobject.MainLoop event loop.
2493
2468
def __init__(self, server_address, RequestHandlerClass,
2519
2494
def add_pipe(self, parent_pipe, proc):
2520
2495
# Call "handle_ipc" for both data and EOF events
2521
GObject.io_add_watch(
2496
gobject.io_add_watch(
2522
2497
parent_pipe.fileno(),
2523
GObject.IO_IN | GObject.IO_HUP,
2498
gobject.IO_IN | gobject.IO_HUP,
2524
2499
functools.partial(self.handle_ipc,
2525
2500
parent_pipe = parent_pipe,
2531
2506
client_object=None):
2532
2507
# error, or the other end of multiprocessing.Pipe has closed
2533
if condition & (GObject.IO_ERR | GObject.IO_HUP):
2508
if condition & (gobject.IO_ERR | gobject.IO_HUP):
2534
2509
# Wait for other process to exit
2557
2532
parent_pipe.send(False)
2560
GObject.io_add_watch(
2535
gobject.io_add_watch(
2561
2536
parent_pipe.fileno(),
2562
GObject.IO_IN | GObject.IO_HUP,
2537
gobject.IO_IN | gobject.IO_HUP,
2563
2538
functools.partial(self.handle_ipc,
2564
2539
parent_pipe = parent_pipe,
2947
2922
logger.error("Could not open file %r", pidfilename,
2950
for name, group in (("_mandos", "_mandos"),
2951
("mandos", "mandos"),
2952
("nobody", "nogroup")):
2925
for name in ("_mandos", "mandos", "nobody"):
2954
2927
uid = pwd.getpwnam(name).pw_uid
2955
gid = pwd.getpwnam(group).pw_gid
2928
gid = pwd.getpwnam(name).pw_gid
2957
2930
except KeyError:
2966
logger.debug("Did setuid/setgid to {}:{}".format(uid,
2968
2938
except OSError as error:
2969
logger.warning("Failed to setuid/setgid to {}:{}: {}"
2970
.format(uid, gid, os.strerror(error.errno)))
2971
2939
if error.errno != errno.EPERM:
2995
2963
# Close all input and output, do double fork, etc.
2998
# multiprocessing will use threads, so before we use GObject we
2999
# need to inform GObject that threads will be used.
3000
GObject.threads_init()
2966
# multiprocessing will use threads, so before we use gobject we
2967
# need to inform gobject that threads will be used.
2968
gobject.threads_init()
3002
2970
global main_loop
3003
2971
# From the Avahi example code
3004
2972
DBusGMainLoop(set_as_default=True)
3005
main_loop = GObject.MainLoop()
2973
main_loop = gobject.MainLoop()
3006
2974
bus = dbus.SystemBus()
3007
2975
# End of Avahi example code
3052
3020
if server_settings["restore"]:
3054
3022
with open(stored_state_path, "rb") as stored_state:
3055
if sys.version_info.major == 2:
3056
clients_data, old_client_settings = pickle.load(
3059
bytes_clients_data, bytes_old_client_settings = (
3060
pickle.load(stored_state, encoding = "bytes"))
3061
### Fix bytes to strings
3064
clients_data = { (key.decode("utf-8")
3065
if isinstance(key, bytes)
3068
bytes_clients_data.items() }
3069
for key in clients_data:
3070
value = { (k.decode("utf-8")
3071
if isinstance(k, bytes) else k): v
3073
clients_data[key].items() }
3074
clients_data[key] = value
3076
value["client_structure"] = [
3078
if isinstance(s, bytes)
3080
value["client_structure"] ]
3082
for k in ("name", "host"):
3083
if isinstance(value[k], bytes):
3084
value[k] = value[k].decode("utf-8")
3085
## old_client_settings
3087
old_client_settings = {
3088
(key.decode("utf-8")
3089
if isinstance(key, bytes)
3092
bytes_old_client_settings.items() }
3094
for value in old_client_settings.values():
3095
value["host"] = value["host"].decode("utf-8")
3023
clients_data, old_client_settings = pickle.load(
3096
3025
os.remove(stored_state_path)
3097
3026
except IOError as e:
3098
3027
if e.errno == errno.ENOENT:
3248
3177
return dbus.Dictionary(
3249
3178
{ c.dbus_object_path: c.GetAll(
3250
3179
"se.recompile.Mandos.Client")
3251
for c in tcp_server.clients.values() },
3180
for c in tcp_server.clients.itervalues() },
3252
3181
signature="oa{sv}")
3254
3183
@dbus.service.method(_interface, in_signature="o")
3255
3184
def RemoveClient(self, object_path):
3257
for c in tcp_server.clients.values():
3186
for c in tcp_server.clients.itervalues():
3258
3187
if c.dbus_object_path == object_path:
3259
3188
del tcp_server.clients[c.name]
3260
3189
c.remove_from_connection()
3320
3249
# removed/edited, old secret will thus be unrecovable.
3322
3251
with PGPEngine() as pgp:
3323
for client in tcp_server.clients.values():
3252
for client in tcp_server.clients.itervalues():
3324
3253
key = client_settings[client.name]["secret"]
3325
3254
client.encrypted_secret = pgp.encrypt(client.secret,
3350
3279
prefix='clients-',
3351
3280
dir=os.path.dirname(stored_state_path),
3352
3281
delete=False) as stored_state:
3353
pickle.dump((clients, client_settings), stored_state,
3282
pickle.dump((clients, client_settings), stored_state)
3355
3283
tempname = stored_state.name
3356
3284
os.rename(tempname, stored_state_path)
3357
3285
except (IOError, OSError) as e:
3418
3346
# End of Avahi example code
3420
GObject.io_add_watch(tcp_server.fileno(), GObject.IO_IN,
3348
gobject.io_add_watch(tcp_server.fileno(), gobject.IO_IN,
3421
3349
lambda *args, **kwargs:
3422
3350
(tcp_server.handle_request
3423
3351
(*args[2:], **kwargs) or True))