Mercurial > dropbear
annotate dbutil.c @ 1920:1489449eceb1
Check authorized_keys permissions as the user
This is necessary on NFS with squash root.
Based on work from Chris Dragan
This commit also tidies some trailing whitespace.
Fixes github pull #107
author | Matt Johnston <matt@ucc.asn.au> |
---|---|
date | Wed, 30 Mar 2022 12:56:09 +0800 |
parents | 9382271da9ef |
children | 667937351c31 |
rev | line source |
---|---|
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
1 /* |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
2 * Dropbear - a SSH2 server |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
3 * |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
4 * Copyright (c) 2002,2003 Matt Johnston |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
5 * All rights reserved. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
6 * |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
7 * Permission is hereby granted, free of charge, to any person obtaining a copy |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
8 * of this software and associated documentation files (the "Software"), to deal |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
9 * in the Software without restriction, including without limitation the rights |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
10 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
11 * copies of the Software, and to permit persons to whom the Software is |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
12 * furnished to do so, subject to the following conditions: |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
13 * |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
14 * The above copyright notice and this permission notice shall be included in |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
15 * all copies or substantial portions of the Software. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
16 * |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
17 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
18 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
19 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
20 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
21 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
22 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
23 * SOFTWARE. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
24 * |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
25 * strlcat() is copyright as follows: |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
26 * Copyright (c) 1998 Todd C. Miller <[email protected]> |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
27 * All rights reserved. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
28 * |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
29 * Redistribution and use in source and binary forms, with or without |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
30 * modification, are permitted provided that the following conditions |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
31 * are met: |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
32 * 1. Redistributions of source code must retain the above copyright |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
33 * notice, this list of conditions and the following disclaimer. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
34 * 2. Redistributions in binary form must reproduce the above copyright |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
35 * notice, this list of conditions and the following disclaimer in the |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
36 * documentation and/or other materials provided with the distribution. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
37 * 3. The name of the author may not be used to endorse or promote products |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
38 * derived from this software without specific prior written permission. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
39 * |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
40 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
41 * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
42 * AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
43 * THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
44 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
45 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
46 * OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
47 * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
48 * OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
49 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */ |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
50 |
928
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
51 #include "config.h" |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
52 |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
53 #ifdef __linux__ |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
54 #define _GNU_SOURCE |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
55 /* To call clock_gettime() directly */ |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
56 #include <sys/syscall.h> |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
57 #endif /* __linux */ |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
58 |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
59 #ifdef HAVE_MACH_MACH_TIME_H |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
60 #include <mach/mach_time.h> |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
61 #include <mach/mach.h> |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
62 #endif |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
63 |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
64 #include "includes.h" |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
65 #include "dbutil.h" |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
66 #include "buffer.h" |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
67 #include "session.h" |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
68 #include "atomicio.h" |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
69 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
70 #define MAX_FMT 100 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
71 |
73
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
72 static void generic_dropbear_exit(int exitcode, const char* format, |
614
00eca37e47e8
Add noreturn and format attribute hints for some functions.
Matt Johnston <matt@ucc.asn.au>
parents:
594
diff
changeset
|
73 va_list param) ATTRIB_NORETURN; |
73
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
74 static void generic_dropbear_log(int priority, const char* format, |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
75 va_list param); |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
76 |
614
00eca37e47e8
Add noreturn and format attribute hints for some functions.
Matt Johnston <matt@ucc.asn.au>
parents:
594
diff
changeset
|
77 void (*_dropbear_exit)(int exitcode, const char* format, va_list param) ATTRIB_NORETURN |
73
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
78 = generic_dropbear_exit; |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
79 void (*_dropbear_log)(int priority, const char* format, va_list param) |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
80 = generic_dropbear_log; |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
81 |
1295
750ec4ec4cbe
Convert #ifdef to #if, other build changes
Matt Johnston <matt@ucc.asn.au>
parents:
1283
diff
changeset
|
82 #if DEBUG_TRACE |
94
c85c88500ea6
DEBUG_TRACE now only triggers with -v on the cmdline
Matt Johnston <matt@ucc.asn.au>
parents:
73
diff
changeset
|
83 int debug_trace = 0; |
c85c88500ea6
DEBUG_TRACE now only triggers with -v on the cmdline
Matt Johnston <matt@ucc.asn.au>
parents:
73
diff
changeset
|
84 #endif |
c85c88500ea6
DEBUG_TRACE now only triggers with -v on the cmdline
Matt Johnston <matt@ucc.asn.au>
parents:
73
diff
changeset
|
85 |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
86 #ifndef DISABLE_SYSLOG |
1211
6ecc133fb2ee
Allow setting syslog identifier via startsyslog().
Konstantin Tokarev <ktokarev@smartlabs.tv>
parents:
1134
diff
changeset
|
87 void startsyslog(const char *ident) { |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
88 |
1211
6ecc133fb2ee
Allow setting syslog identifier via startsyslog().
Konstantin Tokarev <ktokarev@smartlabs.tv>
parents:
1134
diff
changeset
|
89 openlog(ident, LOG_PID, LOG_AUTHPRIV); |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
90 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
91 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
92 #endif /* DISABLE_SYSLOG */ |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
93 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
94 /* the "format" string must be <= 100 characters */ |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
95 void dropbear_close(const char* format, ...) { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
96 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
97 va_list param; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
98 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
99 va_start(param, format); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
100 _dropbear_exit(EXIT_SUCCESS, format, param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
101 va_end(param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
102 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
103 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
104 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
105 void dropbear_exit(const char* format, ...) { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
106 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
107 va_list param; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
108 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
109 va_start(param, format); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
110 _dropbear_exit(EXIT_FAILURE, format, param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
111 va_end(param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
112 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
113 |
73
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
114 static void generic_dropbear_exit(int exitcode, const char* format, |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
115 va_list param) { |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
116 |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
117 char fmtbuf[300]; |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
118 |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
119 snprintf(fmtbuf, sizeof(fmtbuf), "Exited: %s", format); |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
120 |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
121 _dropbear_log(LOG_INFO, fmtbuf, param); |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
122 |
1558
2f64cb3d3007
- #if not #ifdef for DROPBEAR_FUZZ
Matt Johnston <matt@ucc.asn.au>
parents:
1511
diff
changeset
|
123 #if DROPBEAR_FUZZ |
1385
6c92e97553f1
Add a flag whether to longjmp, missed that last commit
Matt Johnston <matt@ucc.asn.au>
parents:
1383
diff
changeset
|
124 if (fuzz.do_jmp) { |
1369 | 125 longjmp(fuzz.jmp, 1); |
126 } | |
127 #endif | |
128 | |
73
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
129 exit(exitcode); |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
130 } |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
131 |
241
c5d3ef11155f
* use own assertions which should get logged properly
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
132 void fail_assert(const char* expr, const char* file, int line) { |
594
a98a2138364a
Improve capitalisation for all logged strings
Matt Johnston <matt@ucc.asn.au>
parents:
568
diff
changeset
|
133 dropbear_exit("Failed assertion (%s:%d): `%s'", file, line, expr); |
241
c5d3ef11155f
* use own assertions which should get logged properly
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
134 } |
c5d3ef11155f
* use own assertions which should get logged properly
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
135 |
108
10f4d3319780
- added circular buffering for channels
Matt Johnston <matt@ucc.asn.au>
parents:
107
diff
changeset
|
136 static void generic_dropbear_log(int UNUSED(priority), const char* format, |
73
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
137 va_list param) { |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
138 |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
139 char printbuf[1024]; |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
140 |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
141 vsnprintf(printbuf, sizeof(printbuf), format, param); |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
142 |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
143 fprintf(stderr, "%s\n", printbuf); |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
144 |
0bf5cebe622c
Dropbearkey can now print out pubkey portions
Matt Johnston <matt@ucc.asn.au>
parents:
70
diff
changeset
|
145 } |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
146 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
147 /* this is what can be called to write arbitrary log messages */ |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
148 void dropbear_log(int priority, const char* format, ...) { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
149 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
150 va_list param; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
151 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
152 va_start(param, format); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
153 _dropbear_log(priority, format, param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
154 va_end(param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
155 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
156 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
157 |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
158 #if DEBUG_TRACE |
1016
257f7d5fca97
piggyback data on acks when making connections on linux
Matt Johnston <matt@ucc.asn.au>
parents:
995
diff
changeset
|
159 |
1021
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
160 static double debug_start_time = -1; |
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
161 |
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
162 void debug_start_net() |
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
163 { |
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
164 if (getenv("DROPBEAR_DEBUG_NET_TIMESTAMP")) |
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
165 { |
1250 | 166 /* Timestamps start from first network activity */ |
167 struct timeval tv; | |
168 gettimeofday(&tv, NULL); | |
169 debug_start_time = tv.tv_sec + (tv.tv_usec / 1000000.0); | |
170 TRACE(("Resetting Dropbear TRACE timestamps")) | |
1021
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
171 } |
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
172 } |
24135c8e1d46
Add envirnonment variable for debug timestamps to roughly match
Matt Johnston <matt@ucc.asn.au>
parents:
1018
diff
changeset
|
173 |
1016
257f7d5fca97
piggyback data on acks when making connections on linux
Matt Johnston <matt@ucc.asn.au>
parents:
995
diff
changeset
|
174 static double time_since_start() |
257f7d5fca97
piggyback data on acks when making connections on linux
Matt Johnston <matt@ucc.asn.au>
parents:
995
diff
changeset
|
175 { |
1250 | 176 double nowf; |
177 struct timeval tv; | |
178 gettimeofday(&tv, NULL); | |
179 nowf = tv.tv_sec + (tv.tv_usec / 1000000.0); | |
180 if (debug_start_time < 0) | |
181 { | |
182 debug_start_time = nowf; | |
183 return 0; | |
184 } | |
185 return nowf - debug_start_time; | |
1016
257f7d5fca97
piggyback data on acks when making connections on linux
Matt Johnston <matt@ucc.asn.au>
parents:
995
diff
changeset
|
186 } |
257f7d5fca97
piggyback data on acks when making connections on linux
Matt Johnston <matt@ucc.asn.au>
parents:
995
diff
changeset
|
187 |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
188 static void dropbear_tracelevel(int level, const char *format, va_list param) |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
189 { |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
190 if (debug_trace == 0 || debug_trace < level) { |
94
c85c88500ea6
DEBUG_TRACE now only triggers with -v on the cmdline
Matt Johnston <matt@ucc.asn.au>
parents:
73
diff
changeset
|
191 return; |
c85c88500ea6
DEBUG_TRACE now only triggers with -v on the cmdline
Matt Johnston <matt@ucc.asn.au>
parents:
73
diff
changeset
|
192 } |
c85c88500ea6
DEBUG_TRACE now only triggers with -v on the cmdline
Matt Johnston <matt@ucc.asn.au>
parents:
73
diff
changeset
|
193 |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
194 fprintf(stderr, "TRACE%d (%d) %f: ", level, getpid(), time_since_start()); |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
195 vfprintf(stderr, format, param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
196 fprintf(stderr, "\n"); |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
197 } |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
198 #if (DEBUG_TRACE>=1) |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
199 void dropbear_trace1(const char* format, ...) { |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
200 va_list param; |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
201 |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
202 va_start(param, format); |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
203 dropbear_tracelevel(1, format, param); |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
204 va_end(param); |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
205 } |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
206 #endif |
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
207 #if (DEBUG_TRACE>=2) |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
208 void dropbear_trace2(const char* format, ...) { |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
209 va_list param; |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
210 |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
211 va_start(param, format); |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
212 dropbear_tracelevel(2, format, param); |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
213 va_end(param); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
214 } |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
215 #endif |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
216 #if (DEBUG_TRACE>=3) |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
217 void dropbear_trace3(const char* format, ...) { |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
218 va_list param; |
753
d63ef1e211ea
Take transmit and receive keys into use separately
Matt Johnston <matt@ucc.asn.au>
parents:
731
diff
changeset
|
219 |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
220 va_start(param, format); |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
221 dropbear_tracelevel(3, format, param); |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
222 va_end(param); |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
223 } |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
224 #endif |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
225 #if (DEBUG_TRACE>=4) |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
226 void dropbear_trace4(const char* format, ...) { |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
227 va_list param; |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
228 |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
229 va_start(param, format); |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
230 dropbear_tracelevel(4, format, param); |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
231 va_end(param); |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
232 } |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
233 #endif |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
234 #if (DEBUG_TRACE>=5) |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
235 void dropbear_trace5(const char* format, ...) { |
731
9a5438271556
Move the more verbose TRACE() statements into TRACE2()
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
236 va_list param; |
9a5438271556
Move the more verbose TRACE() statements into TRACE2()
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
237 |
9a5438271556
Move the more verbose TRACE() statements into TRACE2()
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
238 va_start(param, format); |
1898
3f87f7ff1092
Fix building with DEBUG_TRACE = 0
Matt Johnston <matt@ucc.asn.au>
parents:
1893
diff
changeset
|
239 dropbear_tracelevel(5, format, param); |
731
9a5438271556
Move the more verbose TRACE() statements into TRACE2()
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
240 va_end(param); |
9a5438271556
Move the more verbose TRACE() statements into TRACE2()
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
241 } |
1893
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
242 #endif |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
243 #endif |
180e580778df
Added DEBUG1,DEBUG2,DEBUG3 to separate functions while keeping TRACE and TRACE2.
HansH111 <hans@atbas.org>
parents:
1851
diff
changeset
|
244 |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
245 |
547
cf376c696dfc
Make it compile, update for changes in channel structure.
Matt Johnston <matt@ucc.asn.au>
parents:
500
diff
changeset
|
246 /* Connect to a given unix socket. The socket is blocking */ |
1499
2d450c1056e3
options: Complete the transition to numeric toggles (`#if')
Michael Witten <mfwitten@gmail.com>
parents:
1468
diff
changeset
|
247 #if ENABLE_CONNECT_UNIX |
550
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
248 int connect_unix(const char* path) { |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
249 struct sockaddr_un addr; |
225
ca7e76d981d9
- progress towards client agent forwarding
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
250 int fd = -1; |
ca7e76d981d9
- progress towards client agent forwarding
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
251 |
550
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
252 memset((void*)&addr, 0x0, sizeof(addr)); |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
253 addr.sun_family = AF_UNIX; |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
254 strlcpy(addr.sun_path, path, sizeof(addr.sun_path)); |
225
ca7e76d981d9
- progress towards client agent forwarding
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
255 fd = socket(PF_UNIX, SOCK_STREAM, 0); |
550
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
256 if (fd < 0) { |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
257 TRACE(("Failed to open unix socket")) |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
258 return -1; |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
259 } |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
260 if (connect(fd, (struct sockaddr*)&addr, sizeof(addr)) < 0) { |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
261 TRACE(("Failed to connect to '%s' socket", path)) |
615
e3ac0a426bd0
Fix FD leak if connect() fails, found by Klocwork
Matt Johnston <matt@ucc.asn.au>
parents:
614
diff
changeset
|
262 m_close(fd); |
550
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
263 return -1; |
61c3513825b0
Talking to the agent works now. Can't interpret the pubkeys.
Matt Johnston <matt@ucc.asn.au>
parents:
547
diff
changeset
|
264 } |
225
ca7e76d981d9
- progress towards client agent forwarding
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
265 return fd; |
ca7e76d981d9
- progress towards client agent forwarding
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
266 } |
ca7e76d981d9
- progress towards client agent forwarding
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
267 #endif |
ca7e76d981d9
- progress towards client agent forwarding
Matt Johnston <matt@ucc.asn.au>
parents:
198
diff
changeset
|
268 |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
269 /* Sets up a pipe for a, returning three non-blocking file descriptors |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
270 * and the pid. exec_fn is the function that will actually execute the child process, |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
271 * it will be run after the child has fork()ed, and is passed exec_data. |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
272 * If ret_errfd == NULL then stderr will not be captured. |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
273 * ret_pid can be passed as NULL to discard the pid. */ |
1460
58a74cb829b8
Pointer parameter could be declared as pointing to const (callback)
Francois Perrad <francois.perrad@gadz.org>
parents:
1343
diff
changeset
|
274 int spawn_command(void(*exec_fn)(const void *user_data), const void *exec_data, |
482
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
275 int *ret_writefd, int *ret_readfd, int *ret_errfd, pid_t *ret_pid) { |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
276 int infds[2]; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
277 int outfds[2]; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
278 int errfds[2]; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
279 pid_t pid; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
280 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
281 const int FDIN = 0; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
282 const int FDOUT = 1; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
283 |
1740
dfbe947bdf0d
Make wrapfd share a common buffer for all FDs
Matt Johnston <matt@ucc.asn.au>
parents:
1622
diff
changeset
|
284 #if DROPBEAR_FUZZ |
dfbe947bdf0d
Make wrapfd share a common buffer for all FDs
Matt Johnston <matt@ucc.asn.au>
parents:
1622
diff
changeset
|
285 if (fuzz.fuzzing) { |
dfbe947bdf0d
Make wrapfd share a common buffer for all FDs
Matt Johnston <matt@ucc.asn.au>
parents:
1622
diff
changeset
|
286 return fuzz_spawn_command(ret_writefd, ret_readfd, ret_errfd, ret_pid); |
dfbe947bdf0d
Make wrapfd share a common buffer for all FDs
Matt Johnston <matt@ucc.asn.au>
parents:
1622
diff
changeset
|
287 } |
dfbe947bdf0d
Make wrapfd share a common buffer for all FDs
Matt Johnston <matt@ucc.asn.au>
parents:
1622
diff
changeset
|
288 #endif |
dfbe947bdf0d
Make wrapfd share a common buffer for all FDs
Matt Johnston <matt@ucc.asn.au>
parents:
1622
diff
changeset
|
289 |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
290 /* redirect stdin/stdout/stderr */ |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
291 if (pipe(infds) != 0) { |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
292 return DROPBEAR_FAILURE; |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
293 } |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
294 if (pipe(outfds) != 0) { |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
295 return DROPBEAR_FAILURE; |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
296 } |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
297 if (ret_errfd && pipe(errfds) != 0) { |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
298 return DROPBEAR_FAILURE; |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
299 } |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
300 |
1295
750ec4ec4cbe
Convert #ifdef to #if, other build changes
Matt Johnston <matt@ucc.asn.au>
parents:
1283
diff
changeset
|
301 #if DROPBEAR_VFORK |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
302 pid = vfork(); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
303 #else |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
304 pid = fork(); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
305 #endif |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
306 |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
307 if (pid < 0) { |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
308 return DROPBEAR_FAILURE; |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
309 } |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
310 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
311 if (!pid) { |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
312 /* child */ |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
313 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
314 TRACE(("back to normal sigchld")) |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
315 /* Revert to normal sigchld handling */ |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
316 if (signal(SIGCHLD, SIG_DFL) == SIG_ERR) { |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
317 dropbear_exit("signal() error"); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
318 } |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
319 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
320 /* redirect stdin/stdout */ |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
321 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
322 if ((dup2(infds[FDIN], STDIN_FILENO) < 0) || |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
323 (dup2(outfds[FDOUT], STDOUT_FILENO) < 0) || |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
324 (ret_errfd && dup2(errfds[FDOUT], STDERR_FILENO) < 0)) { |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
325 TRACE(("leave noptycommand: error redirecting FDs")) |
594
a98a2138364a
Improve capitalisation for all logged strings
Matt Johnston <matt@ucc.asn.au>
parents:
568
diff
changeset
|
326 dropbear_exit("Child dup2() failure"); |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
327 } |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
328 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
329 close(infds[FDOUT]); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
330 close(infds[FDIN]); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
331 close(outfds[FDIN]); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
332 close(outfds[FDOUT]); |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
333 if (ret_errfd) |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
334 { |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
335 close(errfds[FDIN]); |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
336 close(errfds[FDOUT]); |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
337 } |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
338 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
339 exec_fn(exec_data); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
340 /* not reached */ |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
341 return DROPBEAR_FAILURE; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
342 } else { |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
343 /* parent */ |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
344 close(infds[FDIN]); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
345 close(outfds[FDOUT]); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
346 |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
347 setnonblocking(outfds[FDIN]); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
348 setnonblocking(infds[FDOUT]); |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
349 |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
350 if (ret_errfd) { |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
351 close(errfds[FDOUT]); |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
352 setnonblocking(errfds[FDIN]); |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
353 } |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
354 |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
355 if (ret_pid) { |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
356 *ret_pid = pid; |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
357 } |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
358 |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
359 *ret_writefd = infds[FDOUT]; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
360 *ret_readfd = outfds[FDIN]; |
484
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
361 if (ret_errfd) { |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
362 *ret_errfd = errfds[FDIN]; |
effb4a25b1ae
Don't capture stderr from spawned processes in proxycommand mode
Matt Johnston <matt@ucc.asn.au>
parents:
482
diff
changeset
|
363 } |
481
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
364 return DROPBEAR_SUCCESS; |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
365 } |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
366 } |
357a2e2e9bcc
- Generalise spawn_command function
Matt Johnston <matt@ucc.asn.au>
parents:
433
diff
changeset
|
367 |
482
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
368 /* Runs a command with "sh -c". Will close FDs (except stdin/stdout/stderr) and |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
369 * re-enabled SIGPIPE. If cmd is NULL, will run a login shell. |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
370 */ |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
371 void run_shell_command(const char* cmd, unsigned int maxfd, char* usershell) { |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
372 char * argv[4]; |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
373 char * baseshell = NULL; |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
374 unsigned int i; |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
375 |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
376 baseshell = basename(usershell); |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
377 |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
378 if (cmd != NULL) { |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
379 argv[0] = baseshell; |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
380 } else { |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
381 /* a login shell should be "-bash" for "/bin/bash" etc */ |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
382 int len = strlen(baseshell) + 2; /* 2 for "-" */ |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
383 argv[0] = (char*)m_malloc(len); |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
384 snprintf(argv[0], len, "-%s", baseshell); |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
385 } |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
386 |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
387 if (cmd != NULL) { |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
388 argv[1] = "-c"; |
492
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
389 argv[2] = (char*)cmd; |
482
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
390 argv[3] = NULL; |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
391 } else { |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
392 /* construct a shell of the form "-bash" etc */ |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
393 argv[1] = NULL; |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
394 } |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
395 |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
396 /* Re-enable SIGPIPE for the executed process */ |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
397 if (signal(SIGPIPE, SIG_DFL) == SIG_ERR) { |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
398 dropbear_exit("signal() error"); |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
399 } |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
400 |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
401 /* close file descriptors except stdin/stdout/stderr |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
402 * Need to be sure FDs are closed here to avoid reading files as root */ |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
403 for (i = 3; i <= maxfd; i++) { |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
404 m_close(i); |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
405 } |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
406 |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
407 execv(usershell, argv); |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
408 } |
7ad49f34a122
- Add run_shell_command() function to run a "sh -c" command, handling
Matt Johnston <matt@ucc.asn.au>
parents:
481
diff
changeset
|
409 |
1295
750ec4ec4cbe
Convert #ifdef to #if, other build changes
Matt Johnston <matt@ucc.asn.au>
parents:
1283
diff
changeset
|
410 #if DEBUG_TRACE |
198
65585699d980
* add a "label" argument to printhex()
Matt Johnston <matt@ucc.asn.au>
parents:
173
diff
changeset
|
411 void printhex(const char * label, const unsigned char * buf, int len) { |
1764
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
412 int i, j; |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
413 |
198
65585699d980
* add a "label" argument to printhex()
Matt Johnston <matt@ucc.asn.au>
parents:
173
diff
changeset
|
414 fprintf(stderr, "%s\n", label); |
1764
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
415 /* for each 16 byte line */ |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
416 for (j = 0; j < len; j += 16) { |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
417 const int linelen = MIN(16, len - j); |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
418 |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
419 /* print hex digits */ |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
420 for (i = 0; i < 16; i++) { |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
421 if (i < linelen) { |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
422 fprintf(stderr, "%02x", buf[j+i]); |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
423 } else { |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
424 fprintf(stderr, " "); |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
425 } |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
426 // separator between pairs |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
427 if (i % 2 ==1) { |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
428 fprintf(stderr, " "); |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
429 } |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
430 } |
1764
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
431 |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
432 /* print characters */ |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
433 fprintf(stderr, " "); |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
434 for (i = 0; i < linelen; i++) { |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
435 char c = buf[j+i]; |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
436 if (!isprint(c)) { |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
437 c = '.'; |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
438 } |
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
439 fputc(c, stderr); |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
440 } |
1764
a339b1c4b9f2
Print ascii in printhex too
Matt Johnston <matt@ucc.asn.au>
parents:
1740
diff
changeset
|
441 fprintf(stderr, "\n"); |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
442 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
443 } |
764
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
444 |
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
445 void printmpint(const char *label, mp_int *mp) { |
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
446 buffer *buf = buf_new(1000); |
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
447 buf_putmpint(buf, mp); |
1432 | 448 fprintf(stderr, "%d bits ", mp_count_bits(mp)); |
764
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
449 printhex(label, buf->data, buf->len); |
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
450 buf_free(buf); |
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
451 |
2202e854d187
add printmpint() for debugging
Matt Johnston <matt@ucc.asn.au>
parents:
667
diff
changeset
|
452 } |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
453 #endif |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
454 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
455 /* Strip all control characters from text (a null-terminated string), except |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
456 * for '\n', '\r' and '\t'. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
457 * The result returned is a newly allocated string, this must be free()d after |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
458 * use */ |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
459 char * stripcontrol(const char * text) { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
460 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
461 char * ret; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
462 int len, pos; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
463 int i; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
464 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
465 len = strlen(text); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
466 ret = m_malloc(len+1); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
467 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
468 pos = 0; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
469 for (i = 0; i < len; i++) { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
470 if ((text[i] <= '~' && text[i] >= ' ') /* normal printable range */ |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
471 || text[i] == '\n' || text[i] == '\r' || text[i] == '\t') { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
472 ret[pos] = text[i]; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
473 pos++; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
474 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
475 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
476 ret[pos] = 0x0; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
477 return ret; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
478 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
479 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
480 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
481 /* reads the contents of filename into the buffer buf, from the current |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
482 * position, either to the end of the file, or the buffer being full. |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
483 * Returns DROPBEAR_SUCCESS or DROPBEAR_FAILURE */ |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
484 int buf_readfile(buffer* buf, const char* filename) { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
485 |
357
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
486 int fd = -1; |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
487 int len; |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
488 int maxlen; |
358
e81d3bc1dc78
Forgot variable declaration.
Matt Johnston <matt@ucc.asn.au>
parents:
357
diff
changeset
|
489 int ret = DROPBEAR_FAILURE; |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
490 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
491 fd = open(filename, O_RDONLY); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
492 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
493 if (fd < 0) { |
357
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
494 goto out; |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
495 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
496 |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
497 do { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
498 maxlen = buf->size - buf->pos; |
357
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
499 len = read(fd, buf_getwriteptr(buf, maxlen), maxlen); |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
500 if (len < 0) { |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
501 if (errno == EINTR || errno == EAGAIN) { |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
502 continue; |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
503 } |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
504 goto out; |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
505 } |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
506 buf_incrwritepos(buf, len); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
507 } while (len < maxlen && len > 0); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
508 |
357
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
509 ret = DROPBEAR_SUCCESS; |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
510 |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
511 out: |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
512 if (fd >= 0) { |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
513 m_close(fd); |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
514 } |
9e2ad1023978
Handle failure reading a file (such as a key file)
Matt Johnston <matt@ucc.asn.au>
parents:
335
diff
changeset
|
515 return ret; |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
516 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
517 |
51
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
518 /* get a line from the file into buffer in the style expected for an |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
519 * authkeys file. |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
520 * Will return DROPBEAR_SUCCESS if data is read, or DROPBEAR_FAILURE on EOF.*/ |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
521 /* Only used for ~/.ssh/known_hosts and ~/.ssh/authorized_keys */ |
1295
750ec4ec4cbe
Convert #ifdef to #if, other build changes
Matt Johnston <matt@ucc.asn.au>
parents:
1283
diff
changeset
|
522 #if DROPBEAR_CLIENT || DROPBEAR_SVR_PUBKEY_AUTH |
51
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
523 int buf_getline(buffer * line, FILE * authfile) { |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
524 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
525 int c = EOF; |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
526 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
527 buf_setpos(line, 0); |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
528 buf_setlen(line, 0); |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
529 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
530 while (line->pos < line->size) { |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
531 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
532 c = fgetc(authfile); /*getc() is weird with some uClibc systems*/ |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
533 if (c == EOF || c == '\n' || c == '\r') { |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
534 goto out; |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
535 } |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
536 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
537 buf_putbyte(line, (unsigned char)c); |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
538 } |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
539 |
165
0cfba3034be5
Fixed DEBUG_TRACE macro so that we don't get semicolons left about the place
Matt Johnston <matt@ucc.asn.au>
parents:
161
diff
changeset
|
540 TRACE(("leave getauthline: line too long")) |
51
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
541 /* We return success, but the line length will be zeroed - ie we just |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
542 * ignore that line */ |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
543 buf_setlen(line, 0); |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
544 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
545 out: |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
546 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
547 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
548 /* if we didn't read anything before EOF or error, exit */ |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
549 if (c == EOF && line->pos == 0) { |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
550 return DROPBEAR_FAILURE; |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
551 } else { |
117
e0acad552a92
Read the last line of a file without a finishing '\n' correctly
Matt Johnston <matt@ucc.asn.au>
parents:
109
diff
changeset
|
552 buf_setpos(line, 0); |
51
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
553 return DROPBEAR_SUCCESS; |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
554 } |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
555 |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
556 } |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
557 #endif |
095d689fed16
- Hostkey checking is mostly there, just aren't appending yet.
Matt Johnston <matt@ucc.asn.au>
parents:
45
diff
changeset
|
558 |
277
044bc108b9b3
* Per-IP connection unauthed connection limits
Matt Johnston <matt@ucc.asn.au>
parents:
258
diff
changeset
|
559 /* make sure that the socket closes */ |
044bc108b9b3
* Per-IP connection unauthed connection limits
Matt Johnston <matt@ucc.asn.au>
parents:
258
diff
changeset
|
560 void m_close(int fd) { |
1038
d3925ed45a85
Fix for old compilers, variable declarations at beginning of functions
Thorsten Horstmann <thorsten.horstmann@web.de>
parents:
1022
diff
changeset
|
561 int val; |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
562 |
1453
336cae2238ca
test close < 0, from Marco Wenzel
Matt Johnston <matt@ucc.asn.au>
parents:
1343
diff
changeset
|
563 if (fd < 0) { |
883
ff597bf2cfb0
DROPBEAR_CLI_AUTH_IMMEDIATE fixed, now enabled by default
Matt Johnston <matt@ucc.asn.au>
parents:
871
diff
changeset
|
564 return; |
ff597bf2cfb0
DROPBEAR_CLI_AUTH_IMMEDIATE fixed, now enabled by default
Matt Johnston <matt@ucc.asn.au>
parents:
871
diff
changeset
|
565 } |
ff597bf2cfb0
DROPBEAR_CLI_AUTH_IMMEDIATE fixed, now enabled by default
Matt Johnston <matt@ucc.asn.au>
parents:
871
diff
changeset
|
566 |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
567 do { |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
568 val = close(fd); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
569 } while (val < 0 && errno == EINTR); |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
570 |
277
044bc108b9b3
* Per-IP connection unauthed connection limits
Matt Johnston <matt@ucc.asn.au>
parents:
258
diff
changeset
|
571 if (val < 0 && errno != EBADF) { |
044bc108b9b3
* Per-IP connection unauthed connection limits
Matt Johnston <matt@ucc.asn.au>
parents:
258
diff
changeset
|
572 /* Linux says EIO can happen */ |
044bc108b9b3
* Per-IP connection unauthed connection limits
Matt Johnston <matt@ucc.asn.au>
parents:
258
diff
changeset
|
573 dropbear_exit("Error closing fd %d, %s", fd, strerror(errno)); |
4
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
574 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
575 } |
fe6bca95afa7
Makefile.in contains updated files required
Matt Johnston <matt@ucc.asn.au>
parents:
diff
changeset
|
576 |
109
2e9d1f29c50f
merge of 50be59810e462f9f44f55e421227d6aa0b31982b
Matt Johnston <matt@ucc.asn.au>
parents:
108
diff
changeset
|
577 void setnonblocking(int fd) { |
2e9d1f29c50f
merge of 50be59810e462f9f44f55e421227d6aa0b31982b
Matt Johnston <matt@ucc.asn.au>
parents:
108
diff
changeset
|
578 |
165
0cfba3034be5
Fixed DEBUG_TRACE macro so that we don't get semicolons left about the place
Matt Johnston <matt@ucc.asn.au>
parents:
161
diff
changeset
|
579 TRACE(("setnonblocking: %d", fd)) |
109
2e9d1f29c50f
merge of 50be59810e462f9f44f55e421227d6aa0b31982b
Matt Johnston <matt@ucc.asn.au>
parents:
108
diff
changeset
|
580 |
1558
2f64cb3d3007
- #if not #ifdef for DROPBEAR_FUZZ
Matt Johnston <matt@ucc.asn.au>
parents:
1511
diff
changeset
|
581 #if DROPBEAR_FUZZ |
1383
f03cfe9c76ac
Disable setnonblocking(), get_socket_address(), set_sock_priority()
Matt Johnston <matt@ucc.asn.au>
parents:
1375
diff
changeset
|
582 if (fuzz.fuzzing) { |
f03cfe9c76ac
Disable setnonblocking(), get_socket_address(), set_sock_priority()
Matt Johnston <matt@ucc.asn.au>
parents:
1375
diff
changeset
|
583 return; |
f03cfe9c76ac
Disable setnonblocking(), get_socket_address(), set_sock_priority()
Matt Johnston <matt@ucc.asn.au>
parents:
1375
diff
changeset
|
584 } |
f03cfe9c76ac
Disable setnonblocking(), get_socket_address(), set_sock_priority()
Matt Johnston <matt@ucc.asn.au>
parents:
1375
diff
changeset
|
585 #endif |
f03cfe9c76ac
Disable setnonblocking(), get_socket_address(), set_sock_priority()
Matt Johnston <matt@ucc.asn.au>
parents:
1375
diff
changeset
|
586 |
109
2e9d1f29c50f
merge of 50be59810e462f9f44f55e421227d6aa0b31982b
Matt Johnston <matt@ucc.asn.au>
parents:
108
diff
changeset
|
587 if (fcntl(fd, F_SETFL, O_NONBLOCK) < 0) { |
173
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
588 if (errno == ENODEV) { |
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
589 /* Some devices (like /dev/null redirected in) |
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
590 * can't be set to non-blocking */ |
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
591 TRACE(("ignoring ENODEV for setnonblocking")) |
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
592 } else { |
1383
f03cfe9c76ac
Disable setnonblocking(), get_socket_address(), set_sock_priority()
Matt Johnston <matt@ucc.asn.au>
parents:
1375
diff
changeset
|
593 { |
173
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
594 dropbear_exit("Couldn't set nonblocking"); |
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
595 } |
257f09a63dab
* add SSH_ASKPASS support (based on patch from Paul Whittaker
Matt Johnston <matt@ucc.asn.au>
parents:
172
diff
changeset
|
596 } |
109
2e9d1f29c50f
merge of 50be59810e462f9f44f55e421227d6aa0b31982b
Matt Johnston <matt@ucc.asn.au>
parents:
108
diff
changeset
|
597 } |
165
0cfba3034be5
Fixed DEBUG_TRACE macro so that we don't get semicolons left about the place
Matt Johnston <matt@ucc.asn.au>
parents:
161
diff
changeset
|
598 TRACE(("leave setnonblocking")) |
109
2e9d1f29c50f
merge of 50be59810e462f9f44f55e421227d6aa0b31982b
Matt Johnston <matt@ucc.asn.au>
parents:
108
diff
changeset
|
599 } |
425 | 600 |
601 void disallow_core() { | |
1903
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
602 struct rlimit lim = {0}; |
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
603 if (getrlimit(RLIMIT_CORE, &lim) < 0) { |
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
604 TRACE(("getrlimit(RLIMIT_CORE) failed")); |
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
605 } |
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
606 lim.rlim_cur = 0; |
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
607 if (setrlimit(RLIMIT_CORE, &lim) < 0) { |
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
608 TRACE(("setrlimit(RLIMIT_CORE) failed")); |
9382271da9ef
Only set soft core limit not hard limit
Matt Johnston <matt@ucc.asn.au>
parents:
1898
diff
changeset
|
609 } |
425 | 610 } |
492
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
611 |
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
612 /* Returns DROPBEAR_SUCCESS or DROPBEAR_FAILURE, with the result in *val */ |
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
613 int m_str_to_uint(const char* str, unsigned int *val) { |
864 | 614 unsigned long l; |
1833
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
615 char *endp; |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
616 |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
617 l = strtoul(str, &endp, 10); |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
618 |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
619 if (endp == str || *endp != '\0') { |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
620 // parse error |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
621 return DROPBEAR_FAILURE; |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
622 } |
870f6e386a0b
Partial strings from strtoul should return error
Matt Johnston <matt@codeconstruct.com.au>
parents:
1764
diff
changeset
|
623 |
492
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
624 /* The c99 spec doesn't actually seem to define EINVAL, but most platforms |
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
625 * I've looked at mention it in their manpage */ |
864 | 626 if ((l == 0 && errno == EINVAL) |
627 || (l == ULONG_MAX && errno == ERANGE) | |
628 || (l > UINT_MAX)) { | |
492
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
629 return DROPBEAR_FAILURE; |
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
630 } else { |
864 | 631 *val = l; |
492
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
632 return DROPBEAR_SUCCESS; |
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
633 } |
b956d6151600
Replace calls to strtoul() with a helper m_str_to_uint()
Matt Johnston <matt@ucc.asn.au>
parents:
490
diff
changeset
|
634 } |
817
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
635 |
1134
36557295418e
change DROPBEAR_DEFAULT_CLI_AUTHKEY to just prepend homedir
Matt Johnston <matt@ucc.asn.au>
parents:
1049
diff
changeset
|
636 /* Returns malloced path. inpath beginning with '/' is returned as-is, |
36557295418e
change DROPBEAR_DEFAULT_CLI_AUTHKEY to just prepend homedir
Matt Johnston <matt@ucc.asn.au>
parents:
1049
diff
changeset
|
637 otherwise home directory is prepended */ |
36557295418e
change DROPBEAR_DEFAULT_CLI_AUTHKEY to just prepend homedir
Matt Johnston <matt@ucc.asn.au>
parents:
1049
diff
changeset
|
638 char * expand_homedir_path(const char *inpath) { |
995
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
639 struct passwd *pw = NULL; |
1134
36557295418e
change DROPBEAR_DEFAULT_CLI_AUTHKEY to just prepend homedir
Matt Johnston <matt@ucc.asn.au>
parents:
1049
diff
changeset
|
640 if (inpath[0] != '/') { |
1851
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
641 char *homedir = getenv("HOME"); |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
642 |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
643 if (!homedir) { |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
644 pw = getpwuid(getuid()); |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
645 if (pw) { |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
646 homedir = pw->pw_dir; |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
647 } |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
648 } |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
649 |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
650 if (homedir) { |
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
651 int len = strlen(inpath) + strlen(homedir) + 2; |
995
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
652 char *buf = m_malloc(len); |
1851
7f549ee3df48
Use HOME before /etc/passwd to find id_dropbear (#137)
Matt Robinson <git@nerdoftheherd.com>
parents:
1835
diff
changeset
|
653 snprintf(buf, len, "%s/%s", homedir, inpath); |
995
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
654 return buf; |
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
655 } |
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
656 } |
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
657 |
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
658 /* Fallback */ |
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
659 return m_strdup(inpath); |
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
660 } |
6fb4c010c448
Default client key path ~/.ssh/id_dropbear
Matt Johnston <matt@ucc.asn.au>
parents:
962
diff
changeset
|
661 |
817
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
662 int constant_time_memcmp(const void* a, const void *b, size_t n) |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
663 { |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
664 const char *xa = a, *xb = b; |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
665 uint8_t c = 0; |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
666 size_t i; |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
667 for (i = 0; i < n; i++) |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
668 { |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
669 c |= (xa[i] ^ xb[i]); |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
670 } |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
671 return c; |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
672 } |
a625f9e135a4
Constant time memcmp for the hmac and password crypt
Matt Johnston <matt@ucc.asn.au>
parents:
753
diff
changeset
|
673 |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
674 /* higher-resolution monotonic timestamp, falls back to gettimeofday */ |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
675 void gettime_wrapper(struct timespec *now) { |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
676 struct timeval tv; |
1558
2f64cb3d3007
- #if not #ifdef for DROPBEAR_FUZZ
Matt Johnston <matt@ucc.asn.au>
parents:
1511
diff
changeset
|
677 #if DROPBEAR_FUZZ |
1375
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
678 if (fuzz.fuzzing) { |
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
679 /* time stands still when fuzzing */ |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
680 now->tv_sec = 5; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
681 now->tv_nsec = 0; |
1375
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
682 } |
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
683 #endif |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
684 |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
685 #if defined(HAVE_CLOCK_GETTIME) && defined(CLOCK_MONOTONIC) |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
686 /* POSIX monotonic clock. Newer Linux, BSD, MacOSX >10.12 */ |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
687 if (clock_gettime(CLOCK_MONOTONIC, now) == 0) { |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
688 return; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
689 } |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
690 #endif |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
691 |
952 | 692 #if defined(__linux__) && defined(SYS_clock_gettime) |
1375
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
693 { |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
694 /* Old linux toolchain - kernel might support it but not the build headers */ |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
695 /* Also glibc <2.17 requires -lrt which we neglect to add */ |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
696 static int linux_monotonic_failed = 0; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
697 if (!linux_monotonic_failed) { |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
698 /* CLOCK_MONOTONIC isn't in some headers */ |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
699 int clock_source_monotonic = 1; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
700 if (syscall(SYS_clock_gettime, clock_source_monotonic, now) == 0) { |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
701 return; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
702 } else { |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
703 /* Don't try again */ |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
704 linux_monotonic_failed = 1; |
952 | 705 } |
706 } | |
1375
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
707 } |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
708 #endif /* linux fallback clock_gettime */ |
952 | 709 |
710 #if defined(HAVE_MACH_ABSOLUTE_TIME) | |
1375
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
711 { |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
712 /* OS X pre 10.12, see https://developer.apple.com/library/mac/qa/qa1398/_index.html */ |
930
8f04e36622c0
Fix monotonic_now() on OS X
Matt Johnston <matt@ucc.asn.au>
parents:
928
diff
changeset
|
713 static mach_timebase_info_data_t timebase_info; |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
714 uint64_t scaled_time; |
928
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
715 if (timebase_info.denom == 0) { |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
716 mach_timebase_info(&timebase_info); |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
717 } |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
718 scaled_time = mach_absolute_time() * timebase_info.numer / timebase_info.denom; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
719 now->tv_sec = scaled_time / 1000000000; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
720 now->tv_nsec = scaled_time % 1000000000; |
1375
d8215479a58a
fuzzing has a constant time
Matt Johnston <matt@ucc.asn.au>
parents:
1369
diff
changeset
|
721 } |
952 | 722 #endif /* osx mach_absolute_time */ |
723 | |
928
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
724 /* Fallback for everything else - this will sometimes go backwards */ |
1622
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
725 gettimeofday(&tv, NULL); |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
726 now->tv_sec = tv.tv_sec; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
727 now->tv_nsec = 1000*tv.tv_usec; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
728 } |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
729 |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
730 /* second-resolution monotonic timestamp */ |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
731 time_t monotonic_now() { |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
732 struct timespec ts; |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
733 gettime_wrapper(&ts); |
e11ed628708b
- Add adaptive authentication failure delay
Matt Johnston <matt@ucc.asn.au>
parents:
1575
diff
changeset
|
734 return ts.tv_sec; |
928
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
735 } |
7cd89d4e0335
Add new monotonic_now() wrapper so that timeouts are unaffected by
Matt Johnston <matt@ucc.asn.au>
parents:
883
diff
changeset
|
736 |
1329
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
737 void fsync_parent_dir(const char* fn) { |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
738 #ifdef HAVE_LIBGEN_H |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
739 char *fn_dir = m_strdup(fn); |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
740 char *dir = dirname(fn_dir); |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
741 int dirfd = open(dir, O_RDONLY); |
1024
aac0095dc3b4
work in progress for async connect
Matt Johnston <matt@ucc.asn.au>
parents:
1023
diff
changeset
|
742 |
1329
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
743 if (dirfd != -1) { |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
744 if (fsync(dirfd) != 0) { |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
745 TRACE(("fsync of directory %s failed: %s", dir, strerror(errno))) |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
746 } |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
747 m_close(dirfd); |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
748 } else { |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
749 TRACE(("error opening directory %s for fsync: %s", dir, strerror(errno))) |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
750 } |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
751 |
1575
e75dab5bec71
some linting after fuzz merge (#60)
François Perrad <francois.perrad@gadz.org>
parents:
1559
diff
changeset
|
752 m_free(fn_dir); |
1329
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
753 #endif |
185c14fa504d
Use atomic key generation in all cases
Matt Johnston <matt@ucc.asn.au>
parents:
1319
diff
changeset
|
754 } |
1835
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
755 |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
756 int fd_read_pending(int fd) { |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
757 fd_set fds; |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
758 struct timeval timeout; |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
759 |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
760 DROPBEAR_FD_ZERO(&fds); |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
761 FD_SET(fd, &fds); |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
762 while (1) { |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
763 timeout.tv_sec = 0; |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
764 timeout.tv_usec = 0; |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
765 if (select(fd+1, &fds, NULL, NULL, &timeout) < 0) { |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
766 if (errno == EINTR) { |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
767 continue; |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
768 } |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
769 return 0; |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
770 } |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
771 return FD_ISSET(fd, &fds); |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
772 } |
90ac15aeac43
Bring back recently removed channel->flushing
Matt Johnston <matt@codeconstruct.com.au>
parents:
1833
diff
changeset
|
773 } |