1 /* vim:tw=78:ts=8:sw=4:set ft=c: */
3 Copyright (C) 2006-2008 Ben Kibbey <bjk@luxsci.net>
5 This program is free software; you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation; either version 2 of the License, or
8 (at your option) any later version.
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 GNU General Public License for more details.
15 You should have received a copy of the GNU General Public License
16 along with this program; if not, write to the Free Software
17 Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
26 #include <sys/socket.h>
35 #include <sys/types.h>
52 #define N_(msgid) dgettext("libpwmd", msgid)
58 #define xrealloc realloc
59 #define xmalloc malloc
60 #define xstrdup strdup
61 #define xcalloc calloc
68 static int gelapsed
, gtimeout
;
69 static gpg_error_t
pinentry_command(pwm_t
*pwm
, char **result
, const char *cmd
);
70 static gpg_error_t global_error
;
74 const char *pwmd_strerror(gpg_error_t e
)
76 gpg_err_code_t code
= gpg_err_code(e
);
78 if (code
>= GPG_ERR_USER_1
&& code
< gpg_err_code(EPWMD_MAX
)) {
82 return N_("Unknown error");
84 return N_("No cache slots available");
86 return N_("Recursion loop");
88 return N_("No file is open");
90 return N_("General LibXML error");
92 return N_("File modified");
96 return gpg_strerror(e
);
99 gpg_error_t
pwmd_init()
102 bindtextdomain("libpwmd", LOCALEDIR
);
105 assuan_set_malloc_hooks(xmalloc
, xrealloc
, xfree
);
106 assuan_set_assuan_err_source(GPG_ERR_SOURCE_DEFAULT
);
110 pwm_t
*pwmd_connect(const char *path
, gpg_error_t
*error
)
113 char *socketpath
= NULL
;
116 assuan_context_t ctx
;
120 pw
= getpwuid(getuid());
121 socketpath
= (char *)xmalloc(strlen(pw
->pw_dir
) + strlen("/.pwmd/socket") + 1);
122 sprintf(socketpath
, "%s/.pwmd/socket", pw
->pw_dir
);
125 socketpath
= xstrdup(path
);
127 rc
= assuan_socket_connect_ext(&ctx
, socketpath
, -1, 0);
135 if ((pwm
= (pwm_t
*)xcalloc(1, sizeof(pwm_t
))) == NULL
) {
136 *error
= gpg_error_from_errno(errno
);
137 assuan_disconnect(ctx
);
144 pwm
->pinentry_tries
= 3;
152 void pwmd_close(pwm_t
*pwm
)
158 assuan_disconnect(pwm
->ctx
);
161 xfree(pwm
->password
);
172 if (pwm
->pinentry_tty
)
173 xfree(pwm
->pinentry_tty
);
175 if (pwm
->pinentry_display
)
176 xfree(pwm
->pinentry_display
);
178 if (pwm
->pinentry_term
)
179 xfree(pwm
->pinentry_term
);
182 xfree(pwm
->filename
);
187 static int mem_realloc_cb(void *data
, const void *buffer
, size_t len
)
189 membuf_t
*mem
= (membuf_t
*)data
;
195 if ((p
= xrealloc(mem
->buf
, mem
->len
+ len
)) == NULL
)
199 memcpy((char *)mem
->buf
+ mem
->len
, buffer
, len
);
204 void pwmd_free_result(void *data
)
209 static int _inquire_cb(void *data
, const char *keyword
)
211 pwm_t
*pwm
= (pwm_t
*)data
;
214 /* Shouldn't get this far without a callback. */
215 if (!pwm
->inquire_func
)
216 return GPG_ERR_INV_ARG
;
223 rc
= pwm
->inquire_func(pwm
->inquire_data
, keyword
, rc
, &result
, &len
);
224 rc
= gpg_err_code(rc
);
226 if (rc
== GPG_ERR_EOF
|| !rc
) {
227 if (len
<= 0 || !result
|| !*result
) {
232 arc
= assuan_send_data(pwm
->ctx
, result
, len
);
234 if (rc
== GPG_ERR_EOF
) {
248 static gpg_error_t
assuan_command(pwm_t
*pwm
, assuan_context_t ctx
,
249 char **result
, const char *cmd
)
257 rc
= assuan_transact(ctx
, cmd
, mem_realloc_cb
, &data
, _inquire_cb
, pwm
,
258 pwm
->status_func
, pwm
->status_data
);
268 mem_realloc_cb(&data
, "", 1);
269 *result
= (char *)data
.buf
;
273 return gpg_err_code(rc
);
276 gpg_error_t
pwmd_inquire(pwm_t
*pwm
, const char *cmd
, pwmd_inquire_fn fn
,
279 if (!pwm
|| !cmd
|| !fn
)
280 return GPG_ERR_INV_ARG
;
282 pwm
->inquire_func
= fn
;
283 pwm
->inquire_data
= data
;
284 return assuan_command(pwm
, pwm
->ctx
, NULL
, cmd
);
287 gpg_error_t
pwmd_terminate_pinentry(pwm_t
*pwm
)
290 return GPG_ERR_NOT_IMPLEMENTED
;
292 if (!pwm
|| pwm
->pid
== -1)
293 return GPG_ERR_INV_ARG
;
295 if (kill(pwm
->pid
, 0) == 0) {
296 if (kill(pwm
->pid
, SIGTERM
) == -1) {
297 if (kill(pwm
->pid
, SIGKILL
) == -1)
298 return gpg_error_from_errno(errno
);
301 pwm
->pin_error
= GPG_ERR_TIMEOUT
;
304 return gpg_error_from_errno(errno
);
311 static gpg_error_t
set_pinentry_strings(pwm_t
*pwm
, int which
)
314 char tmp
[ASSUAN_LINELENGTH
];
318 pwm
->title
= xstrdup(N_("LibPWMD"));
321 pwm
->prompt
= xstrdup(N_("Password:"));
323 if (!pwm
->desc
&& !which
)
324 pwm
->desc
= xstrdup(N_("Enter a password."));
327 snprintf(tmp
, sizeof(tmp
), "SETERROR %s", N_("Invalid password, please try again."));
330 else if (which
== 2) {
331 snprintf(tmp
, sizeof(tmp
), "SETERROR %s", N_("Please type the password again for confirmation."));
335 buf
= (char *)xmalloc(strlen("SETERROR ") + strlen(pwm
->desc
) + 1);
336 sprintf(buf
, "SETERROR %s", pwm
->desc
);
339 error
= pinentry_command(pwm
, NULL
, buf
);
345 buf
= (char *)xmalloc(strlen("SETPROMPT ") + strlen(pwm
->prompt
) + 1);
346 sprintf(buf
, "SETPROMPT %s", pwm
->prompt
);
347 error
= pinentry_command(pwm
, NULL
, buf
);
353 buf
= (char *)xmalloc(strlen("SETDESC ") + strlen(pwm
->title
) + 1);
354 sprintf(buf
, "SETDESC %s", pwm
->title
);
355 error
= pinentry_command(pwm
, NULL
, buf
);
360 static void update_pinentry_settings(pwm_t
*pwm
)
364 struct passwd
*pw
= getpwuid(getuid());
367 snprintf(buf
, sizeof(buf
), "%s/.pwmd/pinentry.conf", pw
->pw_dir
);
369 if ((fp
= fopen(buf
, "r")) == NULL
)
372 while ((p
= fgets(buf
, sizeof(buf
), fp
)) != NULL
) {
373 char name
[32], val
[256];
375 if (sscanf(p
, " %31[a-zA-Z] = %255s", name
, val
) != 2)
378 if (strcasecmp(name
, "TTYNAME") == 0) {
379 xfree(pwm
->pinentry_tty
);
380 pwm
->pinentry_tty
= xstrdup(val
);
382 else if (strcasecmp(name
, "TTYTYPE") == 0) {
383 xfree(pwm
->pinentry_term
);
384 pwm
->pinentry_term
= xstrdup(val
);
386 else if (strcasecmp(name
, "DISPLAY") == 0) {
387 xfree(pwm
->pinentry_display
);
388 pwm
->pinentry_display
= xstrdup(val
);
390 else if (strcasecmp(name
, "PATH") == 0) {
391 xfree(pwm
->pinentry_path
);
392 pwm
->pinentry_path
= xstrdup(val
);
399 static gpg_error_t
launch_pinentry(pwm_t
*pwm
)
402 assuan_context_t ctx
;
403 int child_list
[] = {-1};
404 char *display
= getenv("DISPLAY");
406 int have_display
= 0;
409 update_pinentry_settings(pwm
);
411 if (pwm
->pinentry_display
|| display
)
414 tty
= pwm
->pinentry_tty
? pwm
->pinentry_tty
: ttyname(STDOUT_FILENO
);
417 return gpg_error_from_errno(errno
);
420 if (!have_display
&& !tty
)
421 return GPG_ERR_ENOTTY
;
423 argv
[0] = "pinentry";
424 argv
[1] = have_display
? "--display" : "--ttyname";
425 argv
[2] = have_display
? pwm
->pinentry_display
? pwm
->pinentry_display
: display
: tty
;
429 argv
[3] = "--ttytype";
430 argv
[4] = pwm
->pinentry_term
? pwm
->pinentry_term
: getenv("TERM");
434 rc
= assuan_pipe_connect(&ctx
, pwm
->pinentry_path
? pwm
->pinentry_path
: PINENTRY_PATH
, argv
, child_list
);
439 pwm
->pid
= assuan_get_pid(ctx
);
441 return set_pinentry_strings(pwm
, 0);
444 static gpg_error_t
pinentry_command(pwm_t
*pwm
, char **result
, const char *cmd
)
449 n
= launch_pinentry(pwm
);
455 return assuan_command(pwm
, pwm
->pctx
, result
, cmd
);
458 static void pinentry_disconnect(pwm_t
*pwm
)
461 assuan_disconnect(pwm
->pctx
);
468 * Only called from a child process.
470 static void catchsig(int sig
)
474 if (gelapsed
++ >= gtimeout
) {
475 global_error
= pwmd_terminate_pinentry(gpwm
);
478 global_error
= GPG_ERR_TIMEOUT
;
490 static char *percent_escape(const char *atext
)
492 const unsigned char *s
;
493 int len
= strlen(atext
) * 3 + 1;
494 char *buf
= (char *)xmalloc(len
), *p
= buf
;
499 for (s
=(const unsigned char *)atext
; *s
; s
++) {
501 sprintf (p
, "%%%02X", *s
);
513 static gpg_error_t
send_command(pwm_t
*pwm
, char **result
, const char *cmd
)
516 return GPG_ERR_INV_ARG
;
518 return assuan_command(pwm
, pwm
->ctx
, result
, cmd
);
522 * Avoid sending the BYE command here. libassuan will close the file
523 * descriptor and release the assuan context. Use pwmd_close() instead.
525 gpg_error_t
pwmd_command(pwm_t
*pwm
, char **result
, const char *cmd
, ...)
533 return GPG_ERR_INV_ARG
;
540 len
= vsnprintf(NULL
, 0, cmd
, ap
);
541 buf
= (char *)xmalloc(len
+ 1);
542 len
= vsnprintf(buf
, len
+ 1, cmd
, ap
);
544 error
= send_command(pwm
, result
, buf
);
550 static gpg_error_t
do_getpin(pwm_t
*pwm
, char **result
)
553 signal(SIGALRM
, catchsig
);
558 return pinentry_command(pwm
, result
, "GETPIN");
561 static gpg_error_t
getpin(pwm_t
*pwm
, char **result
, int *try_n
, int which
)
563 int pin_try
= *try_n
;
570 error
= set_pinentry_strings(pwm
, which
);
573 pinentry_disconnect(pwm
);
578 if (pwm
->pinentry_tries
-1 != pin_try
) {
579 error
= set_pinentry_strings(pwm
, 1);
582 pinentry_disconnect(pwm
);
588 error
= do_getpin(pwm
, result
);
591 * Since there was input cancel any timeout.
596 if (error
== GPG_ERR_ASS_CANCELED
|| error
== ASSUAN_Canceled
)
597 return GPG_ERR_ASS_CANCELED
;
599 if (pin_try
!= -1 && pin_try
--)
603 pinentry_disconnect(pwm
);
613 gpg_error_t
pwmd_open_nb_finalize(pwm_t
*pwm
, pwmd_nb_status_t
*pw
)
619 return GPG_ERR_NOT_IMPLEMENTED
;
622 if (!pwm
|| !pw
|| !pw
->filename
[0])
623 return GPG_ERR_INV_ARG
;
632 error
= pwmd_command(pwm
, &result
, "ISCACHED %s", pw
->filename
);
638 xfree(pwm
->filename
);
640 pwm
->filename
= xstrdup(pw
->filename
);
641 memset(pw
, 0, sizeof(pwmd_nb_status_t
));
645 memset(pw
, 0, sizeof(pwmd_nb_status_t
));
649 static gpg_error_t
do_open_command(pwm_t
*pwm
, const char *filename
, char *password
)
651 char buf
[ASSUAN_LINELENGTH
];
655 snprintf(buf
, sizeof(buf
), "OPEN %s %s", filename
, password
? password
: "");
656 error
= send_command(pwm
, &result
, buf
);
657 memset(buf
, 0, sizeof(buf
));
665 static int do_pwmd_open(pwm_t
*pwm
, gpg_error_t
*error
, const char *filename
,
669 char *password
= NULL
;
675 if (!pwm
|| !filename
|| !*filename
) {
676 *error
= GPG_ERR_INV_ARG
;
681 pin_try
= pwm
->pinentry_tries
- 1;
685 * Avoid calling pinentry if the password is cached on the server or if
686 * this is a new file.
688 *error
= pwmd_command(pwm
, &result
, "GETCONFIG data_directory");
693 snprintf(path
, sizeof(path
), "%s/%s", result
, filename
);
694 pwmd_free_result(result
);
696 if (access(path
, R_OK
) == -1) {
700 *error
= gpg_error_from_errno(errno
);
704 *error
= pwmd_command(pwm
, &result
, "ISCACHED %s", filename
);
706 if (*error
== EPWMD_CACHE_NOT_FOUND
) {
708 password
= pwm
->passfunc(pwm
, pwm
->passdata
);
712 if (*error
== EPWMD_CACHE_NOT_FOUND
) {
715 * Get the password from pinentry.
717 if (pwm
->use_pinentry
) {
719 * Nonblocking is wanted. fork() then return a file descriptor
720 * that the client can use to read() from.
728 *error
= gpg_error_from_syserror();
737 strncpy(pw
.filename
, filename
, sizeof(pw
.filename
));
738 pw
.filename
[sizeof(pw
.filename
)-1] = 0;
748 *error
= getpin(pwm
, &password
, &pin_try
, 0);
753 pinentry_disconnect(pwm
);
755 if (gtimeout
&& gelapsed
>= gtimeout
)
756 *error
= GPG_ERR_TIMEOUT
;
759 write(p
[1], &pw
, sizeof(pw
));
765 * Don't count the time it takes to open the file
766 * which may have many iterations.
768 signal(SIGALRM
, SIG_DFL
);
769 *error
= do_open_command(pwm
, filename
, password
);
772 signal(SIGALRM
, catchsig
);
774 if (pwm
->pctx
&& *error
== EPWMD_BADKEY
) {
776 goto getpin_nb_again
;
781 pinentry_disconnect(pwm
);
783 write(p
[1], &pw
, sizeof(pw
));
788 *error
= gpg_error_from_syserror();
801 *error
= getpin(pwm
, &password
, &pin_try
, 1);
805 pinentry_disconnect(pwm
);
807 if (pwm
->pin_error
) {
808 *error
= pwm
->pin_error
;
818 * Not using pinentry and the file was not found
822 if (pwm
->password
== NULL
) {
828 password
= pwm
->password
;
838 *error
= do_open_command(pwm
, filename
, password
);
841 * Keep the user defined password set with pwmd_setopt(). The password may
842 * be needed later (pwmd_save()) depending on the pwmd file cache settings.
844 if (password
&& password
!= pwm
->password
)
848 if (pwm
->pctx
&& *error
== EPWMD_BADKEY
) {
852 pinentry_disconnect(pwm
);
859 xfree(pwm
->filename
);
861 pwm
->filename
= xstrdup(filename
);
865 * The file is cached or the file is a new file.
868 return *error
? -1 : -2;
870 return *error
? 1 : 0;
873 gpg_error_t
pwmd_open(pwm_t
*pwm
, const char *filename
)
877 do_pwmd_open(pwm
, &error
, filename
, 0, 0);
881 int pwmd_open_nb(pwm_t
*pwm
, gpg_error_t
*error
, const char *filename
,
885 *error
= GPG_ERR_NOT_IMPLEMENTED
;
888 return do_pwmd_open(pwm
, error
, filename
, 1, timeout
);
893 static gpg_error_t
do_save_getpin(pwm_t
*pwm
, char **password
)
901 error
= getpin(pwm
, &result
, &pin_try
, confirm
? 2 : 0);
905 pinentry_disconnect(pwm
);
918 if (strcmp(*password
, result
)) {
921 pinentry_disconnect(pwm
);
922 error
= EPWMD_BADKEY
;
927 pinentry_disconnect(pwm
);
932 static gpg_error_t
do_save_command(pwm_t
*pwm
, char *password
)
934 char buf
[ASSUAN_LINELENGTH
];
938 snprintf(buf
, sizeof(buf
), "SAVE %s", password
? password
: "");
939 error
= send_command(pwm
, &result
, buf
);
940 memset(&buf
, 0, sizeof(buf
));
948 gpg_error_t
pwmd_save_nb_finalize(pwm_t
*pwm
, pwmd_nb_status_t
*pw
)
953 return GPG_ERR_NOT_IMPLEMENTED
;
956 if (!pwm
|| !pw
|| !pw
->filename
[0])
957 return GPG_ERR_INV_ARG
;
963 memset(pw
, 0, sizeof(pwmd_nb_status_t
));
967 memset(pw
, 0, sizeof(pwmd_nb_status_t
));
971 static int do_pwmd_save(pwm_t
*pwm
, gpg_error_t
*error
, int nb
)
974 char *password
= NULL
;
977 *error
= GPG_ERR_INV_ARG
;
981 if (pwm
->use_pinentry
|| pwm
->passfunc
) {
982 *error
= pwmd_command(pwm
, &result
, "ISCACHED %s", pwm
->filename
);
984 if (*error
== EPWMD_CACHE_NOT_FOUND
) {
986 if (pwm
->use_pinentry
) {
993 *error
= gpg_error_from_syserror();
1002 strncpy(pw
.filename
, pwm
->filename
, sizeof(pw
.filename
));
1003 pw
.filename
[sizeof(pw
.filename
)-1] = 0;
1008 *error
= do_save_getpin(pwm
, &password
);
1009 } while (*error
== EPWMD_BADKEY
);
1013 pinentry_disconnect(pwm
);
1016 write(p
[1], &pw
, sizeof(pw
));
1021 *error
= do_save_command(pwm
, password
);
1022 pinentry_disconnect(pwm
);
1024 write(p
[1], &pw
, sizeof(pw
));
1029 *error
= gpg_error_from_syserror();
1041 *error
= do_save_getpin(pwm
, &password
);
1049 password
= (*pwm
->passfunc
)(pwm
, pwm
->passdata
);
1060 password
= pwm
->password
;
1062 *error
= do_save_command(pwm
, password
);
1064 if (password
&& password
!= pwm
->password
)
1068 return *error
? -1 : -2;
1070 return *error
? 1 : 0;
1073 int pwmd_save_nb(pwm_t
*pwm
, gpg_error_t
*error
)
1075 #ifndef USE_PINENTRY
1076 *error
= GPG_ERR_NOT_IMPLEMENTED
;
1079 return do_pwmd_save(pwm
, error
, 1);
1083 gpg_error_t
pwmd_save(pwm_t
*pwm
)
1087 do_pwmd_save(pwm
, &error
, 0);
1091 gpg_error_t
pwmd_setopt(pwm_t
*pwm
, pwmd_option_t opt
, ...)
1095 int n
= va_arg(ap
, int);
1099 gpg_error_t error
= 0;
1102 return GPG_ERR_INV_ARG
;
1107 case PWMD_OPTION_STATUS_FUNC
:
1108 pwm
->status_func
= va_arg(ap
, pwmd_status_fn
);
1110 case PWMD_OPTION_STATUS_DATA
:
1111 pwm
->status_data
= va_arg(ap
, void *);
1113 case PWMD_OPTION_PASSWORD_FUNC
:
1114 pwm
->passfunc
= va_arg(ap
, pwmd_password_fn
);
1116 case PWMD_OPTION_PASSWORD_DATA
:
1117 pwm
->passdata
= va_arg(ap
, void *);
1119 case PWMD_OPTION_PASSWORD
:
1120 arg1
= va_arg(ap
, char *);
1123 xfree(pwm
->password
);
1125 pwm
->password
= xstrdup(arg1
);
1128 case PWMD_OPTION_PINENTRY
:
1129 n
= va_arg(ap
, int);
1131 if (n
!= 0 && n
!= 1) {
1133 error
= GPG_ERR_INV_VALUE
;
1136 pwm
->use_pinentry
= n
;
1137 error
= pwmd_command(pwm
, &result
, "OPTION PINENTRY=%i",
1138 !pwm
->use_pinentry
);
1141 case PWMD_OPTION_PINENTRY_TRIES
:
1142 n
= va_arg(ap
, int);
1146 error
= GPG_ERR_INV_VALUE
;
1149 pwm
->pinentry_tries
= n
;
1151 case PWMD_OPTION_PINENTRY_PATH
:
1152 if (pwm
->pinentry_path
)
1153 xfree(pwm
->pinentry_path
);
1155 pwm
->pinentry_path
= xstrdup(va_arg(ap
, char *));
1157 case PWMD_OPTION_PINENTRY_TTY
:
1158 if (pwm
->pinentry_tty
)
1159 xfree(pwm
->pinentry_tty
);
1161 pwm
->pinentry_tty
= xstrdup(va_arg(ap
, char *));
1163 case PWMD_OPTION_PINENTRY_DISPLAY
:
1164 if (pwm
->pinentry_display
)
1165 xfree(pwm
->pinentry_display
);
1167 pwm
->pinentry_display
= xstrdup(va_arg(ap
, char *));
1169 case PWMD_OPTION_PINENTRY_TERM
:
1170 if (pwm
->pinentry_term
)
1171 xfree(pwm
->pinentry_term
);
1173 pwm
->pinentry_term
= xstrdup(va_arg(ap
, char *));
1175 case PWMD_OPTION_PINENTRY_TITLE
:
1178 pwm
->title
= percent_escape(va_arg(ap
, char *));
1180 case PWMD_OPTION_PINENTRY_PROMPT
:
1183 pwm
->prompt
= percent_escape(va_arg(ap
, char *));
1185 case PWMD_OPTION_PINENTRY_DESC
:
1188 pwm
->desc
= percent_escape(va_arg(ap
, char *));
1191 case PWMD_OPTION_PINENTRY
:
1192 case PWMD_OPTION_PINENTRY_TRIES
:
1193 case PWMD_OPTION_PINENTRY_PATH
:
1194 case PWMD_OPTION_PINENTRY_TTY
:
1195 case PWMD_OPTION_PINENTRY_DISPLAY
:
1196 case PWMD_OPTION_PINENTRY_TERM
:
1197 case PWMD_OPTION_PINENTRY_TITLE
:
1198 case PWMD_OPTION_PINENTRY_PROMPT
:
1199 case PWMD_OPTION_PINENTRY_DESC
:
1200 error
= GPG_ERR_NOT_IMPLEMENTED
;
1204 error
= GPG_ERR_NOT_IMPLEMENTED
;