9
9
* "browse_callback", and parts of "main".
11
11
* Everything else is
12
* Copyright © 2008-2016 Teddy Hogeborn
13
* Copyright © 2008-2016 Björn Påhlsson
15
* This program is free software: you can redistribute it and/or
16
* modify it under the terms of the GNU General Public License as
17
* published by the Free Software Foundation, either version 3 of the
18
* License, or (at your option) any later version.
20
* This program is distributed in the hope that it will be useful, but
12
* Copyright © 2008-2018 Teddy Hogeborn
13
* Copyright © 2008-2018 Björn Påhlsson
15
* This file is part of Mandos.
17
* Mandos is free software: you can redistribute it and/or modify it
18
* under the terms of the GNU General Public License as published by
19
* the Free Software Foundation, either version 3 of the License, or
20
* (at your option) any later version.
22
* Mandos is distributed in the hope that it will be useful, but
21
23
* WITHOUT ANY WARRANTY; without even the implied warranty of
22
24
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
23
25
* General Public License for more details.
25
27
* You should have received a copy of the GNU General Public License
26
* along with this program. If not, see
27
* <http://www.gnu.org/licenses/>.
28
* along with Mandos. If not, see <http://www.gnu.org/licenses/>.
29
30
* Contact the authors at <mandos@recompile.se>.
47
48
strtof(), abort() */
48
49
#include <stdbool.h> /* bool, false, true */
49
50
#include <string.h> /* strcmp(), strlen(), strerror(),
50
asprintf(), strncpy() */
51
asprintf(), strncpy(), strsignal()
51
53
#include <sys/ioctl.h> /* ioctl */
52
54
#include <sys/types.h> /* socket(), inet_pton(), sockaddr,
53
55
sockaddr_in6, PF_INET6,
354
356
/* Create new GPGME "context" */
355
357
rc = gpgme_new(&(mc->ctx));
356
358
if(rc != GPG_ERR_NO_ERROR){
357
fprintf_plus(stderr, "Mandos plugin mandos-client: "
358
"bad gpgme_new: %s: %s\n", gpgme_strsource(rc),
359
fprintf_plus(stderr, "bad gpgme_new: %s: %s\n",
360
gpgme_strsource(rc), gpgme_strerror(rc));
398
399
/* Create new empty GPGME data buffer for the plaintext */
399
400
rc = gpgme_data_new(&dh_plain);
400
401
if(rc != GPG_ERR_NO_ERROR){
401
fprintf_plus(stderr, "Mandos plugin mandos-client: "
402
"bad gpgme_data_new: %s: %s\n",
402
fprintf_plus(stderr, "bad gpgme_data_new: %s: %s\n",
403
403
gpgme_strsource(rc), gpgme_strerror(rc));
404
404
gpgme_data_release(dh_crypto);
418
418
if(result == NULL){
419
419
fprintf_plus(stderr, "gpgme_op_decrypt_result failed\n");
421
fprintf_plus(stderr, "Unsupported algorithm: %s\n",
422
result->unsupported_algorithm);
423
fprintf_plus(stderr, "Wrong key usage: %u\n",
424
result->wrong_key_usage);
421
if(result->unsupported_algorithm != NULL) {
422
fprintf_plus(stderr, "Unsupported algorithm: %s\n",
423
result->unsupported_algorithm);
425
fprintf_plus(stderr, "Wrong key usage: %s\n",
426
result->wrong_key_usage ? "Yes" : "No");
425
427
if(result->file_name != NULL){
426
428
fprintf_plus(stderr, "File name: %s\n", result->file_name);
1077
1084
bool match = false;
1079
1086
char *interface = NULL;
1080
while((interface=argz_next(mc->interfaces, mc->interfaces_size,
1087
while((interface = argz_next(mc->interfaces,
1088
mc->interfaces_size,
1082
1090
if(if_nametoindex(interface) == (unsigned int)if_index){
1237
1245
with an explicit route added with the server's address.
1239
1247
Avahi bug reference:
1240
http://lists.freedesktop.org/archives/avahi/2010-February/001833.html
1248
https://lists.freedesktop.org/archives/avahi/2010-February/001833.html
1241
1249
https://bugs.debian.org/587961
1940
int devnull = (int)TEMP_FAILURE_RETRY(open("/dev/null", O_RDONLY));
1942
perror_plus("open(\"/dev/null\", O_RDONLY)");
1912
1945
int numhooks = scandirat(hookdir_fd, ".", &direntries,
1913
1946
runnable_hook, alphasort);
1914
1947
if(numhooks == -1){
1915
1948
perror_plus("scandir");
1918
1952
struct dirent *direntry;
1920
int devnull = (int)TEMP_FAILURE_RETRY(open("/dev/null", O_RDONLY));
1922
perror_plus("open(\"/dev/null\", O_RDONLY)");
1925
1954
for(int i = 0; i < numhooks; i++){
1926
1955
direntry = direntries[i];
2184
2213
/* Sleep checking until interface is running.
2185
2214
Check every 0.25s, up to total time of delay */
2186
for(int i=0; i < delay * 4; i++){
2215
for(int i = 0; i < delay * 4; i++){
2187
2216
if(interface_is_running(interface)){
2487
2516
/* Work around Debian bug #633582:
2488
<http://bugs.debian.org/633582> */
2517
<https://bugs.debian.org/633582> */
2490
2519
/* Re-raise privileges */
2491
2520
ret = raise_privileges();
2949
fprintf_plus(stderr, "%s exiting\n", argv[0]);
2978
if(signal_received){
2979
fprintf_plus(stderr, "%s exiting due to signal %d: %s\n",
2980
argv[0], signal_received,
2981
strsignal(signal_received));
2983
fprintf_plus(stderr, "%s exiting\n", argv[0]);
2952
2987
/* Cleanup things */
3004
3039
/* Take down the network interfaces which were brought up */
3006
3041
char *interface = NULL;
3007
while((interface=argz_next(interfaces_to_take_down,
3008
interfaces_to_take_down_size,
3042
while((interface = argz_next(interfaces_to_take_down,
3043
interfaces_to_take_down_size,
3010
3045
ret = take_down_interface(interface);
3063
3099
clean_dir_at(dir_fd, direntries[i]->d_name, level+1);
3102
if((dret == -1) and (errno != ENOENT)){
3067
3103
fprintf_plus(stderr, "unlink(\"%s/%s\"): %s\n", dirname,
3068
3104
direntries[i]->d_name, strerror(errno));
3074
3110
/* need to clean even if 0 because man page doesn't specify */
3075
3111
free(direntries);
3076
if(numentries == -1){
3077
perror_plus("scandirat");
3079
3112
dret = unlinkat(base, dirname, AT_REMOVEDIR);
3080
3113
if(dret == -1 and errno != ENOENT){
3081
3114
perror_plus("rmdir");