2 * Unix Pageant, more or less similar to ssh-agent.
12 #include <sys/types.h>
17 #define PUTTY_DO_GLOBALS /* actually _define_ globals */
23 SockAddr unix_sock_addr(const char *path);
24 Socket new_unix_listener(SockAddr listenaddr, Plug plug);
26 void fatalbox(char *p, ...)
29 fprintf(stderr, "FATAL ERROR: ");
31 vfprintf(stderr, p, ap);
36 void modalfatalbox(char *p, ...)
39 fprintf(stderr, "FATAL ERROR: ");
41 vfprintf(stderr, p, ap);
46 void nonfatal(char *p, ...)
49 fprintf(stderr, "ERROR: ");
51 vfprintf(stderr, p, ap);
55 void connection_fatal(void *frontend, char *p, ...)
58 fprintf(stderr, "FATAL ERROR: ");
60 vfprintf(stderr, p, ap);
65 void cmdline_error(char *p, ...)
68 fprintf(stderr, "pageant: ");
70 vfprintf(stderr, p, ap);
76 FILE *pageant_logfp = NULL;
77 void pageant_log(void *ctx, const char *fmt, va_list ap)
82 fprintf(pageant_logfp, "pageant: ");
83 vfprintf(pageant_logfp, fmt, ap);
84 fprintf(pageant_logfp, "\n");
88 * In Pageant our selects are synchronous, so these functions are
91 int uxsel_input_add(int fd, int rwx) { return 0; }
92 void uxsel_input_remove(int id) { }
97 void random_save_seed(void) {}
98 void random_destroy_seed(void) {}
99 void noise_ultralight(unsigned long data) {}
100 char *platform_default_s(const char *name) { return NULL; }
101 int platform_default_i(const char *name, int def) { return def; }
102 FontSpec *platform_default_fontspec(const char *name) { return fontspec_new(""); }
103 Filename *platform_default_filename(const char *name) { return filename_from_str(""); }
104 char *x_get_default(const char *key) { return NULL; }
105 void log_eventlog(void *handle, const char *event) {}
108 * Short description of parameters.
110 static void usage(void)
112 printf("Pageant: SSH agent\n");
118 static void version(void)
120 printf("pageant: %s\n", ver);
124 void keylist_update(void)
126 /* Nothing needs doing in Unix Pageant */
129 #define PAGEANT_DIR_PREFIX "/tmp/pageant"
131 const char *const appname = "Pageant";
133 static int time_to_die = FALSE;
135 /* Stub functions to permit linking against x11fwd.c. These never get
136 * used, because in LIFE_X11 mode we connect to the X server using a
137 * straightforward Socket and don't try to create an ersatz SSH
139 int sshfwd_write(struct ssh_channel *c, char *data, int len) { return 0; }
140 void sshfwd_write_eof(struct ssh_channel *c) { }
141 void sshfwd_unclean_close(struct ssh_channel *c, const char *err) { }
142 void sshfwd_unthrottle(struct ssh_channel *c, int bufsize) {}
143 Conf *sshfwd_get_conf(struct ssh_channel *c) { return NULL; }
144 void sshfwd_x11_sharing_handover(struct ssh_channel *c,
145 void *share_cs, void *share_chan,
146 const char *peer_addr, int peer_port,
147 int endian, int protomajor, int protominor,
148 const void *initial_data, int initial_len) {}
149 void sshfwd_x11_is_local(struct ssh_channel *c) {}
152 * These functions are part of the plug for our connection to the X
153 * display, so they do get called. They needn't actually do anything,
154 * except that x11_closing has to signal back to the main loop that
155 * it's time to terminate.
157 static void x11_log(Plug p, int type, SockAddr addr, int port,
158 const char *error_msg, int error_code) {}
159 static int x11_receive(Plug plug, int urgent, char *data, int len) {return 0;}
160 static void x11_sent(Plug plug, int bufsize) {}
161 static int x11_closing(Plug plug, const char *error_msg, int error_code,
167 struct X11Connection {
168 const struct plug_function_table *fn;
172 void pageant_print_env(int pid)
174 printf("SSH_AUTH_SOCK=%s; export SSH_AUTH_SOCK;\n"
175 "SSH_AGENT_PID=%d; export SSH_AGENT_PID;\n",
176 socketname, (int)pid);
179 void pageant_fork_and_print_env(int retain_tty)
185 } else if (pid != 0) {
186 pageant_print_env(pid);
191 * Having forked off, we now daemonise ourselves as best we can.
192 * It's good practice in general to setsid() ourself out of any
193 * process group we didn't want to be part of, and to chdir("/")
194 * to avoid holding any directories open that we don't need in
195 * case someone wants to umount them; also, we should definitely
196 * close standard output (because it will very likely be pointing
197 * at a pipe from which some parent process is trying to read our
198 * environment variable dump, so if we hold open another copy of
199 * it then that process will never finish reading). We close
200 * standard input too on general principles, but not standard
201 * error, since we might need to shout a panicky error message
204 if (chdir("/") < 0) {
205 /* should there be an error condition, nothing we can do about
211 /* Get out of our previous process group, to avoid being
212 * blasted by passing signals. But keep our controlling tty,
213 * so we can keep checking to see if we still have one. */
216 /* Do that, but also leave our entire session and detach from
217 * the controlling tty (if any). */
224 void sigchld(int signum)
226 if (write(signalpipe[1], "x", 1) <= 0)
227 /* not much we can do about it */;
230 #define TTY_LIFE_POLL_INTERVAL (TICKSPERSEC * 30)
231 void *dummy_timer_ctx;
232 static void tty_life_timer(void *ctx, unsigned long now)
234 schedule_timer(TTY_LIFE_POLL_INTERVAL, tty_life_timer, &dummy_timer_ctx);
241 KEYACT_CLIENT_DEL_ALL,
243 KEYACT_CLIENT_LIST_FULL,
245 struct cmdline_key_action {
246 struct cmdline_key_action *next;
248 const char *filename;
251 int is_agent_action(keyact action)
253 return action == KEYACT_AGENT_LOAD;
256 struct cmdline_key_action *keyact_head = NULL, *keyact_tail = NULL;
258 void add_keyact(keyact action, const char *filename)
260 struct cmdline_key_action *a = snew(struct cmdline_key_action);
262 a->filename = filename;
265 keyact_tail->next = a;
271 char **exec_args = NULL;
273 LIFE_UNSPEC, LIFE_X11, LIFE_TTY, LIFE_DEBUG, LIFE_PERM, LIFE_EXEC
274 } life = LIFE_UNSPEC;
275 const char *display = NULL;
277 static char *askpass(const char *comment)
279 prompts_t *p = new_prompts(NULL);
283 * FIXME: if we don't have a terminal, and have to do this by X11,
284 * there's a big missing piece.
287 p->to_server = FALSE;
288 p->name = dupstr("Pageant passphrase prompt");
290 dupprintf("Enter passphrase to load key '%s': ", comment),
292 ret = console_get_userpass_input(p, NULL, 0);
296 perror("pageant: unable to read passphrase");
300 char *passphrase = dupstr(p->prompts[0]->result);
306 static int unix_add_keyfile(const char *filename_str)
308 Filename *filename = filename_from_str(filename_str);
315 * Try without a passphrase.
317 status = pageant_add_keyfile(filename, NULL, &err);
318 if (status == PAGEANT_ACTION_OK) {
320 } else if (status == PAGEANT_ACTION_FAILURE) {
321 fprintf(stderr, "pageant: %s: %s\n", filename_str, err);
328 * And now try prompting for a passphrase.
331 char *passphrase = askpass(err);
336 status = pageant_add_keyfile(filename, passphrase, &err);
338 smemclr(passphrase, strlen(passphrase));
342 if (status == PAGEANT_ACTION_OK) {
344 } else if (status == PAGEANT_ACTION_FAILURE) {
345 fprintf(stderr, "pageant: %s: %s\n", filename_str, err);
354 filename_free(filename);
358 void key_list_callback(void *ctx, const char *fingerprint,
359 const char *comment, struct pageant_pubkey *key)
361 printf("%s %s\n", fingerprint, comment);
364 struct key_find_ctx {
366 int match_fp, match_comment;
367 struct pageant_pubkey *found;
371 int match_fingerprint_string(const char *string, const char *fingerprint)
375 /* Find the hash in the fingerprint string. It'll be the word at the end. */
376 hash = strrchr(fingerprint, ' ');
380 /* Now see if the search string is a prefix of the full hash,
381 * neglecting colons and case differences. */
383 while (*string == ':') string++;
384 while (*hash == ':') hash++;
387 if (tolower((unsigned char)*string) != tolower((unsigned char)*hash))
394 void key_find_callback(void *vctx, const char *fingerprint,
395 const char *comment, struct pageant_pubkey *key)
397 struct key_find_ctx *ctx = (struct key_find_ctx *)vctx;
399 if ((ctx->match_comment && !strcmp(ctx->string, comment)) ||
400 (ctx->match_fp && match_fingerprint_string(ctx->string, fingerprint)))
403 ctx->found = pageant_pubkey_copy(key);
408 struct pageant_pubkey *find_key(const char *string, char **retstr)
410 struct key_find_ctx actx, *ctx = &actx;
411 struct pageant_pubkey key_in, *key_ret;
412 int try_file = TRUE, try_fp = TRUE, try_comment = TRUE;
413 int file_errors = FALSE;
416 * Trim off disambiguating prefixes telling us how to interpret
417 * the provided string.
419 if (!strncmp(string, "file:", 5)) {
421 try_fp = try_comment = FALSE;
422 file_errors = TRUE; /* also report failure to load the file */
423 } else if (!strncmp(string, "comment:", 8)) {
425 try_file = try_fp = FALSE;
426 } else if (!strncmp(string, "fp:", 3)) {
428 try_file = try_comment = FALSE;
429 } else if (!strncmp(string, "fingerprint:", 12)) {
431 try_file = try_comment = FALSE;
435 * Try interpreting the string as a key file name.
438 Filename *fn = filename_from_str(string);
439 int keytype = key_type(fn);
440 if (keytype == SSH_KEYTYPE_SSH1 ||
441 keytype == SSH_KEYTYPE_SSH1_PUBLIC) {
444 if (!rsakey_pubblob(fn, &key_in.blob, &key_in.bloblen,
447 *retstr = dupprintf("unable to load file '%s': %s",
455 * If we've successfully loaded the file, stop here - we
456 * already have a key blob and need not go to the agent to
459 key_in.ssh_version = 1;
460 key_ret = pageant_pubkey_copy(&key_in);
464 } else if (keytype == SSH_KEYTYPE_SSH2 ||
465 keytype == SSH_KEYTYPE_SSH2_PUBLIC_RFC4716 ||
466 keytype == SSH_KEYTYPE_SSH2_PUBLIC_OPENSSH) {
469 if ((key_in.blob = ssh2_userkey_loadpub(fn, NULL,
471 NULL, &error)) == NULL) {
473 *retstr = dupprintf("unable to load file '%s': %s",
481 * If we've successfully loaded the file, stop here - we
482 * already have a key blob and need not go to the agent to
485 key_in.ssh_version = 2;
486 key_ret = pageant_pubkey_copy(&key_in);
492 *retstr = dupprintf("unable to load key file '%s': %s",
493 string, key_type_to_str(keytype));
502 * Failing that, go through the keys in the agent, and match
503 * against fingerprints and comments as appropriate.
505 ctx->string = string;
506 ctx->match_fp = try_fp;
507 ctx->match_comment = try_comment;
510 if (pageant_enum_keys(key_find_callback, ctx, retstr) ==
511 PAGEANT_ACTION_FAILURE)
514 if (ctx->nfound == 0) {
515 *retstr = dupstr("no key matched");
518 } else if (ctx->nfound > 1) {
519 *retstr = dupstr("multiple keys matched");
521 pageant_pubkey_free(ctx->found);
529 void run_client(void)
531 const struct cmdline_key_action *act;
532 struct pageant_pubkey *key;
536 if (!agent_exists()) {
537 fprintf(stderr, "pageant: no agent running to talk to\n");
541 for (act = keyact_head; act; act = act->next) {
542 switch (act->action) {
543 case KEYACT_CLIENT_ADD:
544 if (!unix_add_keyfile(act->filename))
547 case KEYACT_CLIENT_LIST:
548 if (pageant_enum_keys(key_list_callback, NULL, &retstr) ==
549 PAGEANT_ACTION_FAILURE) {
550 fprintf(stderr, "pageant: listing keys: %s\n", retstr);
555 case KEYACT_CLIENT_DEL:
557 if (!(key = find_key(act->filename, &retstr)) ||
558 pageant_delete_key(key, &retstr) == PAGEANT_ACTION_FAILURE) {
559 fprintf(stderr, "pageant: deleting key '%s': %s\n",
560 act->filename, retstr);
565 pageant_pubkey_free(key);
567 case KEYACT_CLIENT_DEL_ALL:
568 case KEYACT_CLIENT_LIST_FULL:
569 fprintf(stderr, "NYI\n");
573 assert(0 && "Invalid client action found");
584 char *username, *socketdir;
585 struct pageant_listen_state *pl;
590 int i, fdcount, fdsize, fdstate;
591 int termination_pid = -1;
594 const struct cmdline_key_action *act;
597 fdcount = fdsize = 0;
602 * Start by loading any keys provided on the command line.
604 for (act = keyact_head; act; act = act->next) {
605 assert(act->action == KEYACT_AGENT_LOAD);
606 if (!unix_add_keyfile(act->filename))
613 * Set up a listening socket and run Pageant on it.
615 username = get_username();
616 socketdir = dupprintf("%s.%s", PAGEANT_DIR_PREFIX, username);
618 assert(*socketdir == '/');
619 if ((err = make_dir_and_check_ours(socketdir)) != NULL) {
620 fprintf(stderr, "pageant: %s: %s\n", socketdir, err);
623 socketname = dupprintf("%s/pageant.%d", socketdir, (int)getpid());
624 pl = pageant_listener_new();
625 sock = new_unix_listener(unix_sock_addr(socketname), (Plug)pl);
626 if ((err = sk_socket_error(sock)) != NULL) {
627 fprintf(stderr, "pageant: %s: %s\n", socketname, err);
630 pageant_listener_got_socket(pl, sock);
633 conf_set_int(conf, CONF_proxy_type, PROXY_NONE);
636 * Lifetime preparations.
638 signalpipe[0] = signalpipe[1] = -1;
639 if (life == LIFE_X11) {
640 struct X11Display *disp;
644 struct X11Connection *conn;
646 static const struct plug_function_table fn_table = {
655 display = getenv("DISPLAY");
657 fprintf(stderr, "pageant: no DISPLAY for -X mode\n");
660 disp = x11_setup_display(display, conf);
662 conn = snew(struct X11Connection);
663 conn->fn = &fn_table;
664 s = new_connection(sk_addr_dup(disp->addr),
665 disp->realhost, disp->port,
666 0, 1, 0, 0, (Plug)conn, conf);
667 if ((err = sk_socket_error(s)) != NULL) {
668 fprintf(stderr, "pageant: unable to connect to X server: %s", err);
671 greeting = x11_make_greeting('B', 11, 0, disp->localauthproto,
673 disp->localauthdatalen,
674 NULL, 0, &greetinglen);
675 sk_write(s, greeting, greetinglen);
676 smemclr(greeting, greetinglen);
679 pageant_fork_and_print_env(FALSE);
680 } else if (life == LIFE_TTY) {
681 schedule_timer(TTY_LIFE_POLL_INTERVAL,
682 tty_life_timer, &dummy_timer_ctx);
683 pageant_fork_and_print_env(TRUE);
684 } else if (life == LIFE_PERM) {
685 pageant_fork_and_print_env(FALSE);
686 } else if (life == LIFE_DEBUG) {
687 pageant_print_env(getpid());
688 pageant_logfp = stdout;
689 } else if (life == LIFE_EXEC) {
695 * Set up the pipe we'll use to tell us about SIGCHLD.
697 if (pipe(signalpipe) < 0) {
701 putty_signal(SIGCHLD, sigchld);
707 } else if (pid == 0) {
708 setenv("SSH_AUTH_SOCK", socketname, TRUE);
709 setenv("SSH_AGENT_PID", dupprintf("%d", (int)agentpid), TRUE);
710 execvp(exec_args[0], exec_args);
714 termination_pid = pid;
719 * Now we've decided on our logging arrangements, pass them on to
722 pageant_listener_set_logfn(pl, NULL, pageant_logfp ? pageant_log : NULL);
724 now = GETTICKCOUNT();
726 while (!time_to_die) {
727 fd_set rset, wset, xset;
738 if (signalpipe[0] >= 0) {
739 FD_SET_MAX(signalpipe[0], maxfd, rset);
742 /* Count the currently active fds. */
744 for (fd = first_fd(&fdstate, &rwx); fd >= 0;
745 fd = next_fd(&fdstate, &rwx)) i++;
747 /* Expand the fdlist buffer if necessary. */
750 fdlist = sresize(fdlist, fdsize, int);
754 * Add all currently open fds to the select sets, and store
755 * them in fdlist as well.
758 for (fd = first_fd(&fdstate, &rwx); fd >= 0;
759 fd = next_fd(&fdstate, &rwx)) {
760 fdlist[fdcount++] = fd;
762 FD_SET_MAX(fd, maxfd, rset);
764 FD_SET_MAX(fd, maxfd, wset);
766 FD_SET_MAX(fd, maxfd, xset);
769 if (toplevel_callback_pending()) {
773 ret = select(maxfd, &rset, &wset, &xset, &tv);
774 } else if (run_timers(now, &next)) {
780 now = GETTICKCOUNT();
781 if (now - then > next - then)
785 tv.tv_sec = ticks / 1000;
786 tv.tv_usec = ticks % 1000 * 1000;
787 ret = select(maxfd, &rset, &wset, &xset, &tv);
791 now = GETTICKCOUNT();
793 ret = select(maxfd, &rset, &wset, &xset, NULL);
796 if (ret < 0 && errno == EINTR)
804 if (life == LIFE_TTY) {
806 * Every time we wake up (whether it was due to tty_timer
807 * elapsing or for any other reason), poll to see if we
808 * still have a controlling terminal. If we don't, then
809 * our containing tty session has ended, so it's time to
810 * clean up and leave.
812 int fd = open("/dev/tty", O_RDONLY);
814 if (errno != ENXIO) {
815 perror("/dev/tty: open");
825 for (i = 0; i < fdcount; i++) {
828 * We must process exceptional notifications before
829 * ordinary readability ones, or we may go straight
830 * past the urgent marker.
832 if (FD_ISSET(fd, &xset))
833 select_result(fd, 4);
834 if (FD_ISSET(fd, &rset))
835 select_result(fd, 1);
836 if (FD_ISSET(fd, &wset))
837 select_result(fd, 2);
840 if (signalpipe[0] >= 0 && FD_ISSET(signalpipe[0], &rset)) {
842 if (read(signalpipe[0], c, 1) <= 0)
844 /* ignore its value; it'll be `x' */
848 pid = waitpid(-1, &status, WNOHANG);
851 if (pid == termination_pid)
856 run_toplevel_callbacks();
860 * When we come here, we're terminating, and should clean up our
861 * Unix socket file if possible.
863 if (unlink(socketname) < 0) {
864 fprintf(stderr, "pageant: %s: %s\n", socketname, strerror(errno));
869 int main(int argc, char **argv)
871 int doing_opts = TRUE;
872 keyact curr_keyact = KEYACT_AGENT_LOAD;
875 * Process the command line.
879 if (*p == '-' && doing_opts) {
880 if (!strcmp(p, "-V") || !strcmp(p, "--version")) {
882 } else if (!strcmp(p, "--help")) {
885 } else if (!strcmp(p, "-v")) {
886 pageant_logfp = stderr;
887 } else if (!strcmp(p, "-a")) {
888 curr_keyact = KEYACT_CLIENT_ADD;
889 } else if (!strcmp(p, "-d")) {
890 curr_keyact = KEYACT_CLIENT_DEL;
891 } else if (!strcmp(p, "-D")) {
892 add_keyact(KEYACT_CLIENT_DEL_ALL, NULL);
893 } else if (!strcmp(p, "-l")) {
894 add_keyact(KEYACT_CLIENT_LIST, NULL);
895 } else if (!strcmp(p, "-L")) {
896 add_keyact(KEYACT_CLIENT_LIST_FULL, NULL);
897 } else if (!strcmp(p, "-X")) {
899 } else if (!strcmp(p, "-T")) {
901 } else if (!strcmp(p, "--debug")) {
903 } else if (!strcmp(p, "--permanent")) {
905 } else if (!strcmp(p, "--exec")) {
907 /* Now all subsequent arguments go to the exec command. */
910 argc = 0; /* force end of option processing */
912 fprintf(stderr, "pageant: expected a command "
916 } else if (!strcmp(p, "--")) {
921 * Non-option arguments (apart from those after --exec,
922 * which are treated specially above) are interpreted as
923 * the names of private key files to either add or delete
926 add_keyact(curr_keyact, p);
930 if (life == LIFE_EXEC && !exec_args) {
931 fprintf(stderr, "pageant: expected a command with --exec\n");
936 * Block SIGPIPE, so that we'll get EPIPE individually on
937 * particular network connections that go wrong.
939 putty_signal(SIGPIPE, SIG_IGN);
945 * Now distinguish our two main running modes. Either we're
946 * actually starting up an agent, in which case we should have a
947 * lifetime mode, and no key actions of KEYACT_CLIENT_* type; or
948 * else we're contacting an existing agent to add or remove keys,
949 * in which case we should have no lifetime mode, and no key
950 * actions of KEYACT_AGENT_* type.
953 int has_agent_actions = FALSE;
954 int has_client_actions = FALSE;
955 int has_lifetime = FALSE;
956 const struct cmdline_key_action *act;
958 for (act = keyact_head; act; act = act->next) {
959 if (is_agent_action(act->action))
960 has_agent_actions = TRUE;
962 has_client_actions = TRUE;
964 if (life != LIFE_UNSPEC)
967 if (has_lifetime && has_client_actions) {
968 fprintf(stderr, "pageant: client key actions (-a, -d, -D, -l, -L)"
969 " do not go with an agent lifetime option\n");
972 if (!has_lifetime && has_agent_actions) {
973 fprintf(stderr, "pageant: expected an agent lifetime option with"
974 " bare key file arguments\n");
977 if (!has_lifetime && !has_client_actions) {
978 fprintf(stderr, "pageant: expected an agent lifetime option"
979 " or a client key action\n");
985 } else if (has_client_actions) {