Reimplement GnuTLS support.
[libpwmd.git] / src / libpwmd.c
blob120215f022cfba54ec02803aba3ce5788129f811
1 /* vim:tw=78:ts=8:sw=4:set ft=c: */
2 /*
3 Copyright (C) 2006, 2007, 2008, 2009, 2010, 2011, 2012
4 Ben Kibbey <bjk@luxsci.net>
6 This file is part of libpwmd.
8 Libpwmd is free software: you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation, either version 2 of the License, or
11 (at your option) any later version.
13 Libpwmd is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with Libpwmd. If not, see <http://www.gnu.org/licenses/>.
21 #ifdef HAVE_CONFIG_H
22 #include <config.h>
23 #endif
25 #include <stdio.h>
26 #include <stdlib.h>
27 #include <unistd.h>
28 #include <err.h>
29 #include <errno.h>
30 #include <ctype.h>
31 #include <string.h>
32 #include <sys/socket.h>
33 #include <sys/un.h>
34 #include <signal.h>
35 #include <stdarg.h>
36 #include <string.h>
37 #include <sys/wait.h>
38 #include <fcntl.h>
39 #include <pwd.h>
40 #include <time.h>
41 #include <sys/types.h>
42 #include <limits.h>
43 #include <sys/select.h>
44 #include <termios.h>
45 #include <libpwmd.h>
47 #ifdef HAVE_ASSUAN_H
48 #include <assuan.h>
49 #endif
51 #ifndef LINE_MAX
52 #define LINE_MAX 2048
53 #endif
55 #include "mem.h"
56 #include "misc.h"
57 #include "types.h"
59 #ifdef WITH_PINENTRY
60 #include "pinentry.h"
61 #endif
63 #if defined(WITH_SSH) || defined(WITH_GNUTLS)
64 #include <sys/types.h>
65 #include <sys/socket.h>
66 #include <netdb.h>
67 #endif
69 #define FINISH(rc) (gpg_err_source(rc) == GPG_ERR_SOURCE_UNKNOWN) \
70 ? gpg_error(rc) : rc
72 typedef struct {
73 size_t len;
74 void *buf;
75 } membuf_t;
77 ssize_t hook_read(assuan_context_t ctx, assuan_fd_t fd, void *data,
78 size_t len)
80 #if defined(WITH_SSH) || defined(WITH_GNUTLS)
81 pwm_t *pwm = assuan_get_pointer(ctx);
83 #ifdef WITH_SSH
84 if (pwm && pwm->tcp && pwm->tcp->ssh)
85 return read_hook_ssh(pwm->tcp->ssh, fd, data, len);
86 #endif
87 #ifdef WITH_GNUTLS
88 if (pwm && pwm->tcp && pwm->tcp->tls)
89 return read_hook_tls(pwm->tcp->tls, fd, data, len);
90 #endif
91 #endif
93 return read((int)fd, data, len);
96 ssize_t hook_write(assuan_context_t ctx, assuan_fd_t fd, const void *data,
97 size_t len)
99 ssize_t wrote;
100 #if defined(WITH_SSH) || defined(WITH_GNUTLS)
101 pwm_t *pwm = assuan_get_pointer(ctx);
103 #ifdef WITH_SSH
104 if (pwm && pwm->tcp && pwm->tcp->ssh)
105 return write_hook_ssh(pwm->tcp->ssh, fd, data, len);
106 #endif
107 #ifdef WITH_GNUTLS
108 if (pwm && pwm->tcp && pwm->tcp->tls)
109 return write_hook_tls(pwm->tcp->tls, fd, data, len);
110 #endif
111 #endif
113 /* libassuan cannot handle EAGAIN when doing writes. */
114 do {
115 wrote = write((int)fd, data, len);
117 if (wrote == -1 && errno == EAGAIN) {
118 usleep(50000);
120 } while (wrote == -1 && errno == EAGAIN);
122 return wrote;
125 pid_t hook_waitpid(assuan_context_t ctx, pid_t pid, int action, int *status,
126 int options)
128 return waitpid(pid, status, options);
131 gpg_error_t pwmd_init()
133 static int initialized;
135 if (initialized)
136 return 0;
138 #ifndef MEM_DEBUG
139 _xmem_init();
140 #endif
141 #ifdef ENABLE_NLS
142 bindtextdomain("libpwmd", LOCALEDIR);
143 #endif
144 #ifdef WITH_SSH
145 libssh2_init(0);
146 #endif
147 #ifdef WITH_GNUTLS
148 gnutls_global_set_mem_functions(pwmd_malloc, pwmd_malloc, NULL,
149 pwmd_realloc, pwmd_free);
150 gnutls_global_init();
151 #endif
152 gpg_err_init();
153 initialized = 1;
154 return 0;
157 gpg_error_t _connect_finalize(pwm_t *pwm)
159 gpg_error_t rc = 0;
160 int active[2];
161 int n = assuan_get_active_fds(pwm->ctx, 0, active, N_ARRAY(active));
163 if (n <= 0)
164 return GPG_ERR_EBADFD;
166 pwm->fd = active[0];
167 #ifdef WITH_PINENTRY
168 pwm->pinentry_pid = -1;
169 #endif
171 if (pwm->name)
172 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "OPTION NAME=%s", pwm->name);
174 return rc;
177 static gpg_error_t connect_uds(pwm_t *pwm, const char *path)
179 char *socketpath = NULL;
180 struct passwd pw;
181 char *pwbuf;
182 gpg_error_t rc;
184 if (!pwm)
185 return GPG_ERR_INV_ARG;
187 pwbuf = _getpwuid(&pw);
188 if (!pwbuf)
189 return gpg_error_from_syserror();
191 if (!path || !*path)
192 socketpath = pwmd_strdup_printf("%s/.pwmd/socket", pw.pw_dir);
193 else
194 socketpath = _expand_homedir((char *)path, &pw);
196 pwmd_free(pwbuf);
197 if (!socketpath)
198 return GPG_ERR_ENOMEM;
200 rc = assuan_socket_connect(pwm->ctx, socketpath, ASSUAN_INVALID_FD, 0);
201 pwmd_free(socketpath);
202 return rc ? rc : _connect_finalize(pwm);
205 static gpg_error_t init_handle(pwm_t *pwm)
207 gpg_error_t rc;
208 static struct assuan_malloc_hooks mhooks = {
209 pwmd_malloc, pwmd_realloc, pwmd_free
211 static struct assuan_system_hooks shooks = {
212 ASSUAN_SYSTEM_HOOKS_VERSION,
213 __assuan_usleep,
214 __assuan_pipe,
215 __assuan_close,
216 hook_read,
217 hook_write,
218 //FIXME
219 NULL, //recvmsg
220 NULL, //sendmsg both are used for FD passing
221 __assuan_spawn,
222 hook_waitpid,
223 __assuan_socketpair,
224 __assuan_socket,
225 __assuan_connect
228 rc = assuan_new_ext(&pwm->ctx, GPG_ERR_SOURCE_DEFAULT, &mhooks, NULL, NULL);
229 if (rc)
230 return rc;
232 assuan_set_pointer(pwm->ctx, pwm);
233 assuan_ctx_set_system_hooks(pwm->ctx, &shooks);
234 return 0;
237 #if defined(WITH_SSH) || defined(WITH_GNUTLS)
238 void free_tcp(struct tcp_s *tcp)
240 if (!tcp)
241 return;
243 #ifdef WITH_SSH
244 _free_ssh_conn(tcp->ssh);
245 #endif
246 #ifdef WITH_GNUTLS
247 tls_free(tcp->tls);
248 #endif
250 pwmd_free(tcp->host);
251 if (tcp->addrs) {
252 freeaddrinfo(tcp->addrs);
253 tcp->addrs = NULL;
256 if (tcp->fd != -1)
257 close(tcp->fd);
259 pwmd_free(tcp);
261 #endif
263 #if defined(WITH_SSH) || defined(WITH_GNUTLS)
264 gpg_error_t tcp_connect_common(pwm_t *pwm)
266 struct addrinfo hints = {0};
267 int n;
268 char portstr[6];
269 gpg_error_t rc = 0;
271 switch (pwm->prot) {
272 case PWMD_IP_ANY:
273 hints.ai_family = AF_UNSPEC;
274 break;
275 case PWMD_IPV4:
276 hints.ai_family = AF_INET;
277 break;
278 case PWMD_IPV6:
279 hints.ai_family = AF_INET6;
280 break;
283 hints.ai_socktype = SOCK_STREAM;
284 snprintf(portstr, sizeof(portstr), "%i", pwm->tcp->port);
285 n = getaddrinfo(pwm->tcp->host, portstr, &hints, &pwm->tcp->addrs);
286 if (n) {
287 fprintf(stderr, "%s\n", gai_strerror(n));
288 return GPG_ERR_UNKNOWN_HOST; //FIXME
291 for (pwm->tcp->addr = pwm->tcp->addrs; pwm->tcp->addr;
292 pwm->tcp->addr = pwm->tcp->addrs->ai_next) {
293 pwm->tcp->fd = socket(pwm->tcp->addr->ai_family, SOCK_STREAM, 0);
294 if (pwm->tcp->fd == -1) {
295 rc = gpg_error_from_syserror();
296 if (pwm->tcp->addr == pwm->tcp->addrs->ai_next)
297 break;
298 continue;
301 if (connect(pwm->tcp->fd, pwm->tcp->addr->ai_addr,
302 sizeof(struct sockaddr)) == -1) {
303 rc = gpg_error_from_syserror();
304 close(pwm->tcp->fd);
305 pwm->tcp->fd = -1;
306 if (pwm->tcp->addr == pwm->tcp->addrs->ai_next)
307 break;
308 continue;
311 rc = 0;
312 break;
315 return rc;
317 #endif
319 gpg_error_t pwmd_connect(pwm_t *pwm, const char *url, ...)
321 const char *p = url;
322 gpg_error_t rc;
324 if (!pwm)
325 return FINISH(GPG_ERR_INV_ARG);
326 else if (!pwm->ctx) {
327 rc = init_handle(pwm);
328 if (rc)
329 return rc;
332 rc = GPG_ERR_UNSUPPORTED_PROTOCOL;
334 if (p && *p == '/')
335 rc = connect_uds(pwm, p);
336 else if (!p || !strncmp(p, "file://", 7)) {
337 if (p)
338 p += 7;
339 rc = connect_uds(pwm, p);
341 else if (!strncmp(p, "ssh://", 6) || !strncmp(p, "ssh6://", 7) ||
342 !strncmp(p, "ssh4://", 7)) {
343 #ifndef WITH_SSH
344 return FINISH(GPG_ERR_NOT_IMPLEMENTED);
345 #else
346 char *host = NULL;
347 int port;
348 char *username = NULL;
350 if (!strncmp(p, "ssh6://", 7)) {
351 pwm->prot = PWMD_IPV6;
352 p += 7;
354 else if (!strncmp(p, "ssh4://", 7)) {
355 pwm->prot = PWMD_IPV4;
356 p += 7;
358 else {
359 pwm->prot = PWMD_IP_ANY;
360 p += 6;
363 /* X11 forwarding is not supported. */
364 pwmd_setopt(pwm, PWMD_OPTION_NO_PINENTRY, 1);
365 rc = _parse_ssh_url(p, &host, &port, &username);
366 if (!rc) {
367 va_list ap;
368 char *identity = NULL;
369 char *knownhosts = NULL;
371 va_start(ap, url);
372 identity = va_arg(ap, char *);
374 if (!identity && !pwm->use_agent)
375 rc = GPG_ERR_INV_ARG;
376 else
377 knownhosts = va_arg(ap, char *);
379 va_end(ap);
381 if (!rc)
382 rc = _do_ssh_connect(pwm, host, port, identity, username,
383 knownhosts);
384 if (!rc) {
385 rc = _connect_finalize(pwm);
386 if (rc) {
387 free_tcp(pwm->tcp);
388 pwm->tcp = NULL;
393 pwmd_free(host);
394 pwmd_free(username);
395 return FINISH(rc);
396 #endif
398 else if (!strncmp(p, "tls://", 6) || !strncmp(p, "tls6://", 7) ||
399 !strncmp(p, "tls4://", 7)) {
400 #ifndef WITH_GNUTLS
401 return FINISH(GPG_ERR_NOT_IMPLEMENTED);
402 #else
403 char *host = NULL;
404 int port;
406 if (!strncmp(p, "tls6://", 7)) {
407 pwm->prot = PWMD_IPV6;
408 p += 7;
410 else if (!strncmp(p, "tls4://", 7)) {
411 pwm->prot = PWMD_IPV4;
412 p += 7;
414 else {
415 pwm->prot = PWMD_IP_ANY;
416 p += 6;
419 /* X11 forwarding is not supported. */
420 pwmd_setopt(pwm, PWMD_OPTION_NO_PINENTRY, 1);
421 rc = _parse_tls_url(p, &host, &port);
422 if (!rc) {
423 va_list ap;
424 char *clientcert = NULL;
425 char *clientkey = NULL;
426 char *cacert = NULL;
427 char *prio = NULL;
429 va_start(ap, url);
430 clientcert = va_arg(ap, char *);
432 if (!clientcert)
433 rc = GPG_ERR_INV_ARG;
434 else {
435 clientkey = va_arg(ap, char *);
436 if (!clientkey)
437 rc = GPG_ERR_INV_ARG;
438 else {
439 cacert = va_arg(ap, char *);
440 if (!cacert)
441 rc = GPG_ERR_INV_ARG;
442 else
443 prio = va_arg(ap, char *);
447 va_end(ap);
449 if (!rc)
450 rc = _do_tls_connect(pwm, host, port, clientcert, clientkey,
451 cacert, prio, pwm->tls_verify);
452 if (!rc) {
453 rc = _connect_finalize(pwm);
454 if (rc) {
455 free_tcp(pwm->tcp);
456 pwm->tcp = NULL;
461 pwmd_free(host);
462 return FINISH(rc);
463 #endif
466 return FINISH(rc);
469 static void disconnect(pwm_t *pwm)
471 if (!pwm || !pwm->ctx)
472 return;
474 assuan_release(pwm->ctx);
475 #if defined(WITH_SSH)
476 free_tcp(pwm->tcp);
477 pwm->tcp = NULL;
478 #endif
479 pwm->ctx = NULL;
480 pwm->fd = -1;
483 void pwmd_close(pwm_t *pwm)
485 if (!pwm)
486 return;
488 disconnect(pwm);
489 pwmd_free(pwm->pinentry_error);
490 pwmd_free(pwm->pinentry_desc);
491 pwmd_free(pwm->pinentry_prompt);
492 pwmd_free(pwm->pinentry_tty);
493 pwmd_free(pwm->pinentry_display);
494 pwmd_free(pwm->pinentry_term);
495 pwmd_free(pwm->pinentry_lcctype);
496 pwmd_free(pwm->pinentry_lcmessages);
497 pwmd_free(pwm->filename);
498 pwmd_free(pwm->name);
500 #if defined(WITH_SSH)
501 free_tcp(pwm->tcp);
502 pwm->tcp = NULL;
503 #endif
505 #ifdef WITH_PINENTRY
506 if (pwm->pctx)
507 _pinentry_disconnect(pwm);
508 #endif
510 pwmd_free(pwm);
513 static gpg_error_t inquire_realloc_cb(void *data, const void *buffer,
514 size_t len)
516 membuf_t *mem = (membuf_t *)data;
517 void *p;
519 if (!buffer)
520 return 0;
522 if ((p = pwmd_realloc(mem->buf, mem->len + len)) == NULL)
523 return gpg_error(GPG_ERR_ENOMEM);
525 mem->buf = p;
526 memcpy((char *)mem->buf + mem->len, buffer, len);
527 mem->len += len;
528 return 0;
531 static gpg_error_t get_password(pwm_t *pwm, char **result, pwmd_pinentry_t w,
532 int echo)
534 char buf[LINE_MAX] = {0}, *p;
535 struct termios told, tnew;
536 char *key = NULL;
538 *result = NULL;
540 if (!isatty(STDIN_FILENO)) {
541 fprintf(stderr, N_("Input is not from a terminal! Failing.\n"));
542 return GPG_ERR_ENOTTY;
545 if (!echo) {
546 if (tcgetattr(STDIN_FILENO, &told) == -1)
547 return gpg_error_from_syserror();
549 memcpy(&tnew, &told, sizeof(struct termios));
550 tnew.c_lflag &= ~(ECHO);
551 tnew.c_lflag |= ICANON|ECHONL;
553 if (tcsetattr(STDIN_FILENO, TCSANOW, &tnew) == -1) {
554 int n = errno;
556 tcsetattr(STDIN_FILENO, TCSANOW, &told);
557 return gpg_error_from_errno(n);
561 switch (w) {
562 case PWMD_PINENTRY_OPEN:
563 fprintf(stderr, N_("Password for %s: "), pwm->filename);
564 break;
565 case PWMD_PINENTRY_OPEN_FAILED:
566 fprintf(stderr, N_("Invalid password. Password for %s: "),
567 pwm->filename);
568 break;
569 case PWMD_PINENTRY_SAVE:
570 fprintf(stderr, N_("New password for %s: "), pwm->filename);
571 break;
572 case PWMD_PINENTRY_SAVE_CONFIRM:
573 fprintf(stderr, N_("Confirm password: "));
574 break;
575 default:
576 break;
579 if ((p = fgets(buf, sizeof(buf), stdin)) == NULL) {
580 tcsetattr(STDIN_FILENO, TCSANOW, &told);
581 return 0;
584 if (!echo)
585 tcsetattr(STDIN_FILENO, TCSANOW, &told);
587 if (feof(stdin)) {
588 clearerr(stdin);
589 return GPG_ERR_CANCELED;
592 p[strlen(p) - 1] = 0;
594 if (buf[0]) {
595 key = pwmd_strdup_printf("%s", p);
596 memset(&buf, 0, sizeof(buf));
598 if (!key)
599 return GPG_ERR_ENOMEM;
602 *result = key;
603 return 0;
606 gpg_error_t pwmd_password(pwm_t *pwm, const char *keyword, char **data,
607 size_t *size)
609 gpg_error_t rc;
610 int new_password = 0;
611 size_t len;
612 char *password = NULL, *newpass = NULL;
613 int error = 0;
615 if (!strcmp(keyword, "NEW_PASSPHRASE"))
616 new_password = 1;
618 if (!new_password && pwm->pinentry_try)
619 error = 1;
621 again:
622 if (pwm->disable_pinentry && !pwm->local_pinentry) {
623 rc = get_password(pwm, &password,
624 new_password ? PWMD_PINENTRY_SAVE : PWMD_PINENTRY_OPEN, 0);
625 if (!rc && new_password)
626 rc = get_password(pwm, &newpass, PWMD_PINENTRY_SAVE_CONFIRM, 0);
628 else {
629 pwmd_pinentry_t which;
631 if (error)
632 which = new_password ? PWMD_PINENTRY_SAVE_FAILED : PWMD_PINENTRY_OPEN_FAILED;
633 else
634 which = new_password ? PWMD_PINENTRY_SAVE : PWMD_PINENTRY_OPEN;
636 rc = pwmd_getpin(pwm, pwm->filename, &password, &len, which);
637 if (!rc && new_password)
638 rc = pwmd_getpin(pwm, pwm->filename, &newpass, &len,
639 PWMD_PINENTRY_SAVE_CONFIRM);
642 if (!rc && new_password) {
643 if ((!password && newpass) || (!newpass && password)
644 || strcmp(newpass, password)) {
645 if (pwm->disable_pinentry)
646 fprintf(stderr, N_("Passphrases do not match.\n"));
648 pwmd_free(password);
649 pwmd_free(newpass);
650 password = newpass = NULL;
651 error = 1;
652 goto again;
656 (void)pwmd_getpin(pwm, pwm->filename, NULL, NULL, PWMD_PINENTRY_CLOSE);
657 pwmd_free(newpass);
658 if (!rc) {
659 // An empty passphrase on a protected key is not allowed by gpg-agent.
660 if (!password && !new_password)
661 rc = GPG_ERR_CANCELED;
662 else {
663 *data = password;
664 *size = password ? strlen(password) : 0;
668 return rc;
671 static gpg_error_t inquire_cb(void *data, const char *keyword)
673 pwm_t *pwm = (pwm_t *)data;
674 gpg_error_t rc = 0;
675 int free_result = 0;
676 char *result = NULL;
678 /* Shouldn't get this far without a callback. */
679 if (!pwm->override_inquire && !pwm->inquire_func)
680 return gpg_error(GPG_ERR_ASS_NO_INQUIRE_CB);
682 for (;;) {
683 size_t len = 0;
684 gpg_error_t arc;
685 int is_password = 0;
686 int new_password = 0;
688 result = NULL;
690 if (!strcmp(keyword, "PASSPHRASE"))
691 is_password = 1;
692 else if (!strcmp(keyword, "NEW_PASSPHRASE"))
693 new_password = 1;
695 if (!pwm->override_inquire && (is_password || new_password)) {
696 free_result = 1;
697 rc = pwmd_password(data, keyword, &result, &len);
698 if (!rc)
699 rc = GPG_ERR_EOF;
701 else
702 rc = pwm->inquire_func(pwm->inquire_data, keyword, rc, &result,
703 &len);
705 cancel:
706 if (rc && gpg_err_code(rc) != GPG_ERR_EOF) {
707 gpg_error_t trc = rc;
709 /* Cancel this inquire. */
710 rc = assuan_send_data(pwm->ctx, NULL, 1);
711 if (!rc) {
712 char *line;
713 size_t len;
715 /* There is a bug (or feature?) in assuan_send_data() that
716 * when cancelling an inquire the next read from the server is
717 * not done until the next command making the next command
718 * fail with GPG_ERR_ASS_UNEXPECTED_CMD.
720 rc = assuan_read_line(pwm->ctx, &line, &len);
722 /* Restore the original error. This differs from the error
723 * returned from the pwmd command (GPG_ERR_CANCELED). This
724 * error is returned to the calling function.
726 if (!rc)
727 rc = trc;
730 break;
733 if (gpg_err_code(rc) == GPG_ERR_EOF || !rc) {
734 if (len <= 0 && !result) {
735 rc = 0;
736 break;
738 else if ((len <= 0 && result) || (len && !result)) {
739 rc = gpg_error(GPG_ERR_INV_ARG);
740 break;
743 if (pwm->inquire_maxlen
744 && pwm->inquire_sent+len > pwm->inquire_maxlen) {
745 rc = gpg_error(GPG_ERR_TOO_LARGE);
746 if (!free_result)
747 rc = pwm->inquire_func(pwm->inquire_data, keyword, rc,
748 &result, &len);
749 goto cancel;
752 arc = assuan_send_data(pwm->ctx, result, len);
753 if (gpg_err_code(rc) == GPG_ERR_EOF) {
754 rc = arc;
755 break;
758 rc = arc;
760 else if (rc)
761 break;
763 if (!rc) {
764 pwm->inquire_sent += len;
766 if (pwm->status_func) {
767 char buf[ASSUAN_LINELENGTH];
769 snprintf(buf, sizeof(buf), "XFER %lu %lu", pwm->inquire_sent,
770 pwm->inquire_total);
771 rc = pwm->status_func(pwm->status_data, buf);
772 if (rc)
773 continue;
778 if (free_result)
779 pwmd_free(result);
781 return rc;
784 static gpg_error_t parse_assuan_line(pwm_t *pwm)
786 gpg_error_t rc;
787 char *line;
788 size_t len;
790 rc = assuan_read_line(pwm->ctx, &line, &len);
791 if (!rc) {
792 if (line[0] == 'O' && line[1] == 'K' &&
793 (line[2] == 0 || line[2] == ' ')) {
795 else if (line[0] == '#') {
797 else if (line[0] == 'S' && (line[1] == 0 || line[1] == ' ')) {
798 if (pwm->status_func) {
799 rc = pwm->status_func(pwm->status_data,
800 line[1] == 0 ? line+1 : line+2);
803 else if (line[0] == 'E' && line[1] == 'R' && line[2] == 'R' &&
804 (line[3] == 0 || line[3] == ' ')) {
805 line += 4;
806 rc = atoi(line);
810 return rc;
813 static void reset_handle_state(pwm_t *pwm, int done)
815 #if defined(WITH_SSH)
816 if (pwm->tcp)
817 pwm->tcp->rc = 0;
819 if (done) {
820 free_tcp(pwm->tcp);
821 pwm->tcp = NULL;
823 #endif
826 static void reset_handle(pwm_t *h)
828 h->fd = -1;
829 #ifdef WITH_PINENTRY
830 if (h->pctx)
831 _pinentry_disconnect(h);
832 #endif
833 reset_handle_state(h, 0);
836 gpg_error_t pwmd_disconnect(pwm_t *pwm)
838 if (!pwm)
839 return FINISH(GPG_ERR_INV_ARG);
841 #if defined(WITH_SSH)
842 if (pwm->fd == -1 && pwm->tcp && pwm->tcp->fd == -1)
843 #else
844 if (pwm->fd == -1)
845 #endif
846 return FINISH(GPG_ERR_INV_STATE);
848 if (pwm->fd != 1)
849 disconnect(pwm);
851 reset_handle(pwm);
852 return 0;
855 /* Note that this should only be called when not in a command. */
856 gpg_error_t pwmd_process(pwm_t *pwm)
858 gpg_error_t rc = 0;
859 fd_set fds;
860 struct timeval tv = {0, 0};
861 int n;
863 if (!pwm)
864 return FINISH(GPG_ERR_INV_ARG);
865 else if (!pwm->ctx)
866 return FINISH(GPG_ERR_INV_STATE);
868 #if defined(WITH_SSH)
869 if (pwm->tcp && pwm->tcp->ssh && pwm->keepalive_interval) {
870 int to;
871 int n = libssh2_keepalive_send(pwm->tcp->ssh->session, &to);
873 if (n)
874 return FINISH(GPG_ERR_ETIMEDOUT);
876 if (pwm->tcp->ssh->keepalive_prev &&
877 to > pwm->tcp->ssh->keepalive_prev) {
878 pwm->tcp->ssh->keepalive_prev = to;
879 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "NOP");
880 if (rc)
881 return FINISH(rc);
883 else
884 pwm->tcp->ssh->keepalive_prev = to;
886 #endif
888 FD_ZERO(&fds);
889 FD_SET(pwm->fd, &fds);
890 n = select(pwm->fd+1, &fds, NULL, NULL, &tv);
892 if (n == -1)
893 return FINISH(gpg_error_from_syserror());
895 if (n > 0) {
896 if (FD_ISSET(pwm->fd, &fds))
897 rc = parse_assuan_line(pwm);
900 while (!rc && assuan_pending_line(pwm->ctx))
901 rc = parse_assuan_line(pwm);
903 return FINISH(rc);
906 static gpg_error_t status_cb(void *data, const char *line)
908 pwm_t *pwm = data;
910 if (!strncmp(line, "INQUIRE_MAXLEN ", 15))
911 pwm->inquire_maxlen = atoi(line+15);
913 if (pwm->status_func)
914 return pwm->status_func(pwm->status_data, line);
916 return 0;
919 gpg_error_t _assuan_command(pwm_t *pwm, assuan_context_t ctx,
920 char **result, size_t *len, const char *cmd)
922 membuf_t data;
923 gpg_error_t rc;
925 if (!cmd || !*cmd)
926 return FINISH(GPG_ERR_INV_ARG);
928 if (strlen(cmd) >= ASSUAN_LINELENGTH+1)
929 return FINISH(GPG_ERR_LINE_TOO_LONG);
931 data.len = 0;
932 data.buf = NULL;
933 rc = assuan_transact(ctx, cmd, inquire_realloc_cb, &data,
934 #ifdef WITH_QUALITY
935 pwm->pctx == ctx ? pwm->_inquire_func : inquire_cb,
936 pwm->pctx == ctx ? pwm->_inquire_data : pwm,
937 #else
938 inquire_cb, pwm,
939 #endif
940 status_cb, pwm);
942 if (rc) {
943 if (data.buf) {
944 pwmd_free(data.buf);
945 data.buf = NULL;
948 else {
949 if (data.buf) {
950 inquire_realloc_cb(&data, "", 1);
952 if (result)
953 *result = (char *)data.buf;
954 else
955 pwmd_free(data.buf);
957 if (len)
958 *len = data.len;
962 pwm->inquire_maxlen = 0;
963 return rc;
966 gpg_error_t pwmd_command_ap(pwm_t *pwm, char **result, size_t *rlen,
967 pwmd_inquire_cb_t func, void *user, const char *cmd, va_list ap)
969 char *buf;
970 size_t len;
971 va_list ap2;
973 if (!pwm || !cmd)
974 return FINISH(GPG_ERR_INV_ARG);
975 if (!pwm->ctx)
976 return FINISH(GPG_ERR_INV_STATE);
979 * C99 allows the dst pointer to be null which will calculate the length
980 * of the would-be result and return it.
982 va_copy(ap2, ap);
983 len = vsnprintf(NULL, 0, cmd, ap)+1;
984 buf = (char *)pwmd_malloc(len);
985 if (!buf) {
986 va_end(ap2);
987 return FINISH(GPG_ERR_ENOMEM);
990 len = vsnprintf(buf, len, cmd, ap2);
991 va_end(ap2);
993 if (buf[strlen(buf)-1] == '\n')
994 buf[strlen(buf)-1] = 0;
995 if (buf[strlen(buf)-1] == '\r')
996 buf[strlen(buf)-1] = 0;
998 pwm->inquire_func = func;
999 pwm->inquire_data = user;
1000 pwm->inquire_sent = 0;
1001 gpg_error_t rc = _assuan_command(pwm, pwm->ctx, result, rlen, buf);
1002 pwmd_free(buf);
1003 return rc;
1006 gpg_error_t pwmd_command(pwm_t *pwm, char **result, size_t *len,
1007 pwmd_inquire_cb_t func, void *user, const char *cmd, ...)
1009 va_list ap;
1011 if (!pwm || !cmd)
1012 return FINISH(GPG_ERR_INV_ARG);
1013 if (!pwm->ctx)
1014 return FINISH(GPG_ERR_INV_STATE);
1016 if (result)
1017 *result = NULL;
1019 va_start(ap, cmd);
1020 gpg_error_t rc = pwmd_command_ap(pwm, result, len, func, user, cmd, ap);
1021 va_end(ap);
1022 return rc;
1025 static gpg_error_t send_pinentry_options(pwm_t *pwm)
1027 gpg_error_t rc;
1029 if (pwm->pinentry_tty) {
1030 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "OPTION TTYNAME=%s", pwm->pinentry_tty);
1031 if (rc)
1032 return rc;
1035 if (pwm->pinentry_term) {
1036 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "OPTION TTYTYPE=%s", pwm->pinentry_term);
1037 if (rc)
1038 return rc;
1041 if (pwm->pinentry_display) {
1042 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "OPTION DISPLAY=%s",
1043 pwm->pinentry_display);
1044 if (rc)
1045 return rc;
1048 if (pwm->pinentry_desc) {
1049 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "OPTION DESC=%s",
1050 pwm->pinentry_desc);
1051 if (rc)
1052 return rc;
1055 if (pwm->pinentry_lcctype) {
1056 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "OPTION LC_CTYPE=%s",
1057 pwm->pinentry_lcctype);
1058 if (rc)
1059 return rc;
1062 if (pwm->pinentry_lcmessages) {
1063 rc = pwmd_command(pwm, NULL, NULL, NULL, NULL, "OPTION LC_MESSAGES=%s",
1064 pwm->pinentry_lcmessages);
1065 if (rc)
1066 return rc;
1069 return 0;
1072 gpg_error_t pwmd_socket_type(pwm_t *pwm, pwmd_socket_t *result)
1074 if (!pwm || !result)
1075 return FINISH(GPG_ERR_INV_ARG);
1077 #if defined(WITH_SSH)
1078 if ((pwm->fd == -1 && (!pwm->tcp || !pwm->tcp->ssh)) ||
1079 (pwm->fd == -1 && pwm->tcp && pwm->tcp->fd == -1))
1080 #else
1081 if (pwm->fd == -1)
1082 #endif
1083 return FINISH(GPG_ERR_INV_STATE);
1085 #if defined(WITH_SSH)
1086 *result = pwm->tcp && pwm->tcp->ssh ? PWMD_SOCKET_SSH : PWMD_SOCKET_LOCAL;
1087 #else
1088 *result = PWMD_SOCKET_LOCAL;
1089 #endif
1090 return 0;
1093 gpg_error_t pwmd_open(pwm_t *pwm, const char *filename, pwmd_inquire_cb_t cb,
1094 void *data)
1096 gpg_error_t rc = 0;
1097 #if defined(WITH_SSH)
1098 int no_pinentry = pwm->disable_pinentry || pwm->tcp || pwm->local_pinentry;
1099 #else
1100 int no_pinentry = pwm->disable_pinentry || pwm->local_pinentry;
1101 #endif
1103 if (!pwm || !filename || !*filename)
1104 return FINISH(GPG_ERR_INV_ARG);
1106 if (!pwm->ctx)
1107 return FINISH(GPG_ERR_INV_STATE);
1109 if (!no_pinentry)
1110 rc = send_pinentry_options(pwm);
1112 if (!rc) {
1113 pwm->pinentry_try = 0;
1114 pwmd_free(pwm->filename);
1115 pwm->filename = pwmd_strdup(filename);
1117 do {
1118 rc = pwmd_command(pwm, NULL, NULL, cb, data, "OPEN %s%s%s",
1119 (pwm->opts & OPT_LOCK_ON_OPEN) ? "--lock " : "",
1120 no_pinentry ? "--no-pinentry " : "", filename);
1121 } while (gpg_err_code(rc) == GPG_ERR_BAD_PASSPHRASE
1122 && no_pinentry && ++pwm->pinentry_try < pwm->pinentry_tries);
1124 pwm->pinentry_try = 0;
1126 if (rc) {
1127 pwmd_free(pwm->filename);
1128 pwm->filename = NULL;
1132 return FINISH(rc);
1135 gpg_error_t pwmd_save(pwm_t *pwm, const char *args, pwmd_inquire_cb_t cb,
1136 void *data)
1138 gpg_error_t rc;
1140 if (!pwm)
1141 return FINISH(GPG_ERR_INV_ARG);
1142 if (!pwm->ctx)
1143 return FINISH(GPG_ERR_INV_STATE);
1145 rc = pwmd_command(pwm, NULL, NULL, cb, data, "SAVE %s",
1146 args ? args : "");
1147 return FINISH(rc);
1150 gpg_error_t pwmd_setopt(pwm_t *pwm, pwmd_option_t opt, ...)
1152 va_list ap;
1153 int n;
1154 char *arg1;
1155 gpg_error_t rc = 0;
1157 if (!pwm)
1158 return FINISH(GPG_ERR_INV_ARG);
1160 va_start(ap, opt);
1162 switch (opt) {
1163 case PWMD_OPTION_LOCK_ON_OPEN:
1164 n = va_arg(ap, int);
1166 if (n < 0 || n > 1)
1167 rc = GPG_ERR_INV_VALUE;
1169 if (n)
1170 pwm->opts |= OPT_LOCK_ON_OPEN;
1171 else
1172 pwm->opts &= ~OPT_LOCK_ON_OPEN;
1174 break;
1175 case PWMD_OPTION_INQUIRE_TOTAL:
1176 pwm->inquire_total = va_arg(ap, size_t);
1177 break;
1178 case PWMD_OPTION_STATUS_CB:
1179 pwm->status_func = va_arg(ap, pwmd_status_cb_t);
1180 break;
1181 case PWMD_OPTION_STATUS_DATA:
1182 pwm->status_data = va_arg(ap, void *);
1183 break;
1184 case PWMD_OPTION_NO_PINENTRY:
1185 n = va_arg(ap, int);
1187 if (n < 0 || n > 1)
1188 rc = GPG_ERR_INV_VALUE;
1189 else
1190 pwm->disable_pinentry = n;
1192 break;
1193 case PWMD_OPTION_LOCAL_PINENTRY:
1194 n = va_arg(ap, int);
1196 if (n < 0 || n > 1)
1197 rc = GPG_ERR_INV_VALUE;
1198 else
1199 pwm->local_pinentry = n;
1201 break;
1202 case PWMD_OPTION_PINENTRY_TIMEOUT:
1203 n = va_arg(ap, int);
1205 if (n < 0)
1206 rc = GPG_ERR_INV_VALUE;
1207 else
1208 pwm->pinentry_timeout = n;
1210 break;
1211 case PWMD_OPTION_PINENTRY_TRIES:
1212 n = va_arg(ap, int);
1213 pwm->pinentry_tries = n;
1214 break;
1215 case PWMD_OPTION_PINENTRY_PATH:
1216 arg1 = va_arg(ap, char *);
1217 pwmd_free(pwm->pinentry_path);
1218 pwm->pinentry_path = arg1 ? _expand_homedir(arg1, NULL) : NULL;
1219 break;
1220 case PWMD_OPTION_PINENTRY_TTY:
1221 arg1 = va_arg(ap, char *);
1222 pwmd_free(pwm->pinentry_tty);
1223 pwm->pinentry_tty = arg1 ? pwmd_strdup(arg1) : NULL;
1224 break;
1225 case PWMD_OPTION_PINENTRY_DISPLAY:
1226 arg1 = va_arg(ap, char *);
1227 pwmd_free(pwm->pinentry_display);
1228 pwm->pinentry_display = arg1 ? pwmd_strdup(arg1) : NULL;
1229 break;
1230 case PWMD_OPTION_PINENTRY_TERM:
1231 arg1 = va_arg(ap, char *);
1232 pwmd_free(pwm->pinentry_term);
1233 pwm->pinentry_term = arg1 ? pwmd_strdup(arg1) : NULL;
1234 break;
1235 case PWMD_OPTION_PINENTRY_ERROR:
1236 arg1 = va_arg(ap, char *);
1237 pwmd_free(pwm->pinentry_error);
1238 pwm->pinentry_error = arg1 ? _percent_escape(arg1) : NULL;
1239 break;
1240 case PWMD_OPTION_PINENTRY_PROMPT:
1241 arg1 = va_arg(ap, char *);
1242 pwmd_free(pwm->pinentry_prompt);
1243 pwm->pinentry_prompt = arg1 ? _percent_escape(arg1) : NULL;
1244 break;
1245 case PWMD_OPTION_PINENTRY_DESC:
1246 arg1 = va_arg(ap, char *);
1247 pwmd_free(pwm->pinentry_desc);
1248 pwm->pinentry_desc = arg1 ? _percent_escape(arg1) : NULL;
1249 break;
1250 case PWMD_OPTION_PINENTRY_LC_CTYPE:
1251 arg1 = va_arg(ap, char *);
1252 pwmd_free(pwm->pinentry_lcctype);
1253 pwm->pinentry_lcctype = arg1 ? pwmd_strdup(arg1) : NULL;
1254 break;
1255 case PWMD_OPTION_PINENTRY_LC_MESSAGES:
1256 arg1 = va_arg(ap, char *);
1257 pwmd_free(pwm->pinentry_lcmessages);
1258 pwm->pinentry_lcmessages = arg1 ? pwmd_strdup(arg1) : NULL;
1259 break;
1260 #ifdef WITH_SSH
1261 case PWMD_OPTION_KNOWNHOST_CB:
1262 pwm->kh_cb = va_arg(ap, pwmd_knownhost_cb_t);
1263 break;
1264 case PWMD_OPTION_KNOWNHOST_DATA:
1265 pwm->kh_data = va_arg(ap, void *);
1266 break;
1267 case PWMD_OPTION_SSH_AGENT:
1268 pwm->use_agent = va_arg(ap, int);
1270 if (pwm->use_agent < 0 || pwm->use_agent > 1) {
1271 pwm->use_agent = 0;
1272 rc = GPG_ERR_INV_VALUE;
1275 break;
1276 case PWMD_OPTION_SSH_TIMEOUT:
1277 pwm->ssh_timeout = va_arg(ap, int);
1279 if (pwm->ssh_timeout < 0) {
1280 pwm->ssh_timeout = 0;
1281 rc = GPG_ERR_INV_VALUE;
1283 else if (pwm->tcp && pwm->tcp->ssh && pwm->tcp->ssh->session)
1284 libssh2_session_set_timeout(pwm->tcp->ssh->session,
1285 pwm->ssh_timeout*1000);
1287 break;
1288 case PWMD_OPTION_SSH_KEEPALIVE:
1289 pwm->keepalive_interval = va_arg(ap, int);
1291 if (pwm->keepalive_interval < 0) {
1292 pwm->keepalive_interval = 0;
1293 rc = GPG_ERR_INV_VALUE;
1295 else if (pwm->tcp && pwm->tcp->ssh && pwm->tcp->ssh->session)
1296 libssh2_keepalive_config(pwm->tcp->ssh->session, 1,
1297 pwm->keepalive_interval);
1299 break;
1300 #else
1301 case PWMD_OPTION_KNOWNHOST_CB:
1302 case PWMD_OPTION_KNOWNHOST_DATA:
1303 case PWMD_OPTION_SSH_AGENT:
1304 case PWMD_OPTION_SSH_TIMEOUT:
1305 rc = GPG_ERR_NOT_IMPLEMENTED;
1306 break;
1307 #endif
1308 #ifdef WITH_GNUTLS
1309 case PWMD_OPTION_TLS_VERIFY:
1310 pwm->tls_verify = va_arg(ap, int);
1312 if (pwm->tls_verify < 0 || pwm->tls_verify > 1) {
1313 pwm->tls_verify = 0;
1314 rc = GPG_ERR_INV_VALUE;
1316 break;
1317 #endif
1318 case PWMD_OPTION_OVERRIDE_INQUIRE:
1319 pwm->override_inquire = va_arg(ap, int);
1321 if (pwm->override_inquire < 0 || pwm->override_inquire > 1) {
1322 pwm->override_inquire = 0;
1323 rc = GPG_ERR_INV_VALUE;
1325 break;
1326 default:
1327 rc = GPG_ERR_UNKNOWN_OPTION;
1328 break;
1331 va_end(ap);
1332 return FINISH(rc);
1335 gpg_error_t pwmd_new(const char *name, pwm_t **pwm)
1337 pwm_t *h = pwmd_calloc(1, sizeof(pwm_t));
1338 gpg_error_t rc;
1340 if (!h)
1341 return FINISH(GPG_ERR_ENOMEM);
1343 if (name) {
1344 h->name = pwmd_strdup(name);
1345 if (!h->name) {
1346 pwmd_free(h);
1347 return FINISH(GPG_ERR_ENOMEM);
1351 reset_handle(h);
1352 h->pinentry_timeout = -30;
1353 h->pinentry_tries = 3;
1354 #if defined(WITH_SSH)
1355 h->prot = PWMD_IP_ANY;
1356 #endif
1358 if (ttyname(STDOUT_FILENO)) {
1359 char buf[256];
1361 ttyname_r(STDOUT_FILENO, buf, sizeof(buf));
1362 h->pinentry_tty = pwmd_strdup(buf);
1363 if (!h->pinentry_tty) {
1364 rc = GPG_ERR_ENOMEM;
1365 goto fail;
1369 if (getenv("TERM") && h->pinentry_tty) {
1370 h->pinentry_term = pwmd_strdup(getenv("TERM"));
1371 if (!h->pinentry_term) {
1372 rc = GPG_ERR_ENOMEM;
1373 goto fail;
1377 if (getenv("DISPLAY")) {
1378 h->pinentry_display = pwmd_strdup(getenv("DISPLAY"));
1379 if (!h->pinentry_display) {
1380 rc = GPG_ERR_ENOMEM;
1381 goto fail;
1385 update_pinentry_settings(h);
1386 *pwm = h;
1387 return 0;
1389 fail:
1390 pwmd_close(h);
1391 return FINISH(rc);
1394 void pwmd_free(void *ptr)
1396 _xfree(ptr);
1399 void *pwmd_malloc(size_t size)
1401 return _xmalloc(size);
1404 void *pwmd_calloc(size_t nmemb, size_t size)
1406 return _xcalloc(nmemb, size);
1409 void *pwmd_realloc(void *ptr, size_t size)
1411 return _xrealloc(ptr, size);
1414 char *pwmd_strdup(const char *str)
1416 return _xstrdup(str);
1419 char *pwmd_strdup_printf(const char *fmt, ...)
1421 va_list ap, ap2;
1422 int len;
1423 char *buf;
1425 if (!fmt)
1426 return NULL;
1428 va_start(ap, fmt);
1429 va_copy(ap2, ap);
1430 len = vsnprintf(NULL, 0, fmt, ap);
1431 va_end(ap);
1432 buf = pwmd_malloc(++len);
1433 if (buf)
1434 vsnprintf(buf, len, fmt, ap2);
1436 va_end(ap2);
1437 return buf;
1440 gpg_error_t pwmd_getpin(pwm_t *pwm, const char *filename, char **result,
1441 size_t *len, pwmd_pinentry_t which)
1443 #ifndef WITH_PINENTRY
1444 return FINISH(GPG_ERR_NOT_IMPLEMENTED);
1445 #else
1446 gpg_error_t rc = _pwmd_getpin(pwm, filename, result, len, which);
1448 return FINISH(rc);
1449 #endif
1452 const char *pwmd_version()
1454 return LIBPWMD_VERSION_STR;
1457 unsigned int pwmd_features()
1459 unsigned int n = 0;
1461 #ifdef WITH_PINENTRY
1462 n |= PWMD_FEATURE_PINENTRY;
1463 #endif
1464 #ifdef WITH_SSH
1465 n |= PWMD_FEATURE_SSH;
1466 #endif
1467 #ifdef WITH_QUALITY
1468 n |= PWMD_FEATURE_CRACK;
1469 #endif
1470 #ifdef WITH_GNUTLS
1471 n |= PWMD_FEATURE_GNUTLS;
1472 #endif
1473 return n;
1476 gpg_error_t pwmd_fd(pwm_t *pwm, int *fd)
1478 if (!pwm || !fd)
1479 return FINISH(GPG_ERR_INV_ARG);
1481 #if defined(WITH_SSH)
1482 if (pwm->tcp && pwm->tcp->fd == -1 && pwm->fd == -1)
1483 return GPG_ERR_INV_STATE;
1485 *fd = pwm->tcp && pwm->tcp->fd != -1 ? pwm->tcp->fd : pwm->fd;
1486 #else
1487 if (pwm->fd == -1)
1488 return FINISH(GPG_ERR_INV_STATE);
1490 *fd = pwm->fd;
1491 #endif
1493 return 0;