1 /* 2 * This work is licensed under the terms of the GNU GPL, version 2 or later. 3 * See the COPYING file in the top-level directory. 4 */ 5 #include "qemu/osdep.h" 6 7 #include <glib-unix.h> 8 #include <glib/gstdio.h> 9 #include <locale.h> 10 #include <pwd.h> 11 12 #include "qapi/error.h" 13 #include "qga-qapi-commands.h" 14 15 #ifdef QGA_BUILD_UNIT_TEST 16 static struct passwd * 17 test_get_passwd_entry(const gchar *user_name, GError **error) 18 { 19 struct passwd *p; 20 int ret; 21 22 if (!user_name || g_strcmp0(user_name, g_get_user_name())) { 23 g_set_error(error, G_UNIX_ERROR, 0, "Invalid user name"); 24 return NULL; 25 } 26 27 p = g_new0(struct passwd, 1); 28 p->pw_dir = (char *)g_get_home_dir(); 29 p->pw_uid = geteuid(); 30 p->pw_gid = getegid(); 31 32 ret = g_mkdir_with_parents(p->pw_dir, 0700); 33 g_assert(ret == 0); 34 35 return p; 36 } 37 38 #define g_unix_get_passwd_entry_qemu(username, err) \ 39 test_get_passwd_entry(username, err) 40 #endif 41 42 static struct passwd * 43 get_passwd_entry(const char *username, Error **errp) 44 { 45 g_autoptr(GError) err = NULL; 46 struct passwd *p; 47 48 ERRP_GUARD(); 49 50 p = g_unix_get_passwd_entry_qemu(username, &err); 51 if (p == NULL) { 52 error_setg(errp, "failed to lookup user '%s': %s", 53 username, err->message); 54 return NULL; 55 } 56 57 return p; 58 } 59 60 static bool 61 mkdir_for_user(const char *path, const struct passwd *p, 62 mode_t mode, Error **errp) 63 { 64 ERRP_GUARD(); 65 66 if (g_mkdir(path, mode) == -1) { 67 error_setg(errp, "failed to create directory '%s': %s", 68 path, g_strerror(errno)); 69 return false; 70 } 71 72 if (chown(path, p->pw_uid, p->pw_gid) == -1) { 73 error_setg(errp, "failed to set ownership of directory '%s': %s", 74 path, g_strerror(errno)); 75 return false; 76 } 77 78 if (chmod(path, mode) == -1) { 79 error_setg(errp, "failed to set permissions of directory '%s': %s", 80 path, g_strerror(errno)); 81 return false; 82 } 83 84 return true; 85 } 86 87 static bool 88 check_openssh_pub_key(const char *key, Error **errp) 89 { 90 ERRP_GUARD(); 91 92 /* simple sanity-check, we may want more? */ 93 if (!key || key[0] == '#' || strchr(key, '\n')) { 94 error_setg(errp, "invalid OpenSSH public key: '%s'", key); 95 return false; 96 } 97 98 return true; 99 } 100 101 static bool 102 check_openssh_pub_keys(strList *keys, size_t *nkeys, Error **errp) 103 { 104 size_t n = 0; 105 strList *k; 106 107 ERRP_GUARD(); 108 109 for (k = keys; k != NULL; k = k->next) { 110 if (!check_openssh_pub_key(k->value, errp)) { 111 return false; 112 } 113 n++; 114 } 115 116 if (nkeys) { 117 *nkeys = n; 118 } 119 return true; 120 } 121 122 static bool 123 write_authkeys(const char *path, const GStrv keys, 124 const struct passwd *p, Error **errp) 125 { 126 g_autofree char *contents = NULL; 127 g_autoptr(GError) err = NULL; 128 129 ERRP_GUARD(); 130 131 contents = g_strjoinv("\n", keys); 132 if (!g_file_set_contents(path, contents, -1, &err)) { 133 error_setg(errp, "failed to write to '%s': %s", path, err->message); 134 return false; 135 } 136 137 if (chown(path, p->pw_uid, p->pw_gid) == -1) { 138 error_setg(errp, "failed to set ownership of directory '%s': %s", 139 path, g_strerror(errno)); 140 return false; 141 } 142 143 if (chmod(path, 0600) == -1) { 144 error_setg(errp, "failed to set permissions of '%s': %s", 145 path, g_strerror(errno)); 146 return false; 147 } 148 149 return true; 150 } 151 152 static GStrv 153 read_authkeys(const char *path, Error **errp) 154 { 155 g_autoptr(GError) err = NULL; 156 g_autofree char *contents = NULL; 157 158 ERRP_GUARD(); 159 160 if (!g_file_get_contents(path, &contents, NULL, &err)) { 161 error_setg(errp, "failed to read '%s': %s", path, err->message); 162 return NULL; 163 } 164 165 return g_strsplit(contents, "\n", -1); 166 167 } 168 169 void 170 qmp_guest_ssh_add_authorized_keys(const char *username, strList *keys, 171 bool has_reset, bool reset, 172 Error **errp) 173 { 174 g_autofree struct passwd *p = NULL; 175 g_autofree char *ssh_path = NULL; 176 g_autofree char *authkeys_path = NULL; 177 g_auto(GStrv) authkeys = NULL; 178 strList *k; 179 size_t nkeys, nauthkeys; 180 181 ERRP_GUARD(); 182 reset = has_reset && reset; 183 184 if (!check_openssh_pub_keys(keys, &nkeys, errp)) { 185 return; 186 } 187 188 p = get_passwd_entry(username, errp); 189 if (p == NULL) { 190 return; 191 } 192 193 ssh_path = g_build_filename(p->pw_dir, ".ssh", NULL); 194 authkeys_path = g_build_filename(ssh_path, "authorized_keys", NULL); 195 196 if (!reset) { 197 authkeys = read_authkeys(authkeys_path, NULL); 198 } 199 if (authkeys == NULL) { 200 if (!g_file_test(ssh_path, G_FILE_TEST_IS_DIR) && 201 !mkdir_for_user(ssh_path, p, 0700, errp)) { 202 return; 203 } 204 } 205 206 nauthkeys = authkeys ? g_strv_length(authkeys) : 0; 207 authkeys = g_realloc_n(authkeys, nauthkeys + nkeys + 1, sizeof(char *)); 208 memset(authkeys + nauthkeys, 0, (nkeys + 1) * sizeof(char *)); 209 210 for (k = keys; k != NULL; k = k->next) { 211 if (g_strv_contains((const gchar * const *)authkeys, k->value)) { 212 continue; 213 } 214 authkeys[nauthkeys++] = g_strdup(k->value); 215 } 216 217 write_authkeys(authkeys_path, authkeys, p, errp); 218 } 219 220 void 221 qmp_guest_ssh_remove_authorized_keys(const char *username, strList *keys, 222 Error **errp) 223 { 224 g_autofree struct passwd *p = NULL; 225 g_autofree char *authkeys_path = NULL; 226 g_autofree GStrv new_keys = NULL; /* do not own the strings */ 227 g_auto(GStrv) authkeys = NULL; 228 GStrv a; 229 size_t nkeys = 0; 230 231 ERRP_GUARD(); 232 233 if (!check_openssh_pub_keys(keys, NULL, errp)) { 234 return; 235 } 236 237 p = get_passwd_entry(username, errp); 238 if (p == NULL) { 239 return; 240 } 241 242 authkeys_path = g_build_filename(p->pw_dir, ".ssh", 243 "authorized_keys", NULL); 244 if (!g_file_test(authkeys_path, G_FILE_TEST_EXISTS)) { 245 return; 246 } 247 authkeys = read_authkeys(authkeys_path, errp); 248 if (authkeys == NULL) { 249 return; 250 } 251 252 new_keys = g_new0(char *, g_strv_length(authkeys) + 1); 253 for (a = authkeys; *a != NULL; a++) { 254 strList *k; 255 256 for (k = keys; k != NULL; k = k->next) { 257 if (g_str_equal(k->value, *a)) { 258 break; 259 } 260 } 261 if (k != NULL) { 262 continue; 263 } 264 265 new_keys[nkeys++] = *a; 266 } 267 268 write_authkeys(authkeys_path, new_keys, p, errp); 269 } 270 271 272 #ifdef QGA_BUILD_UNIT_TEST 273 #if GLIB_CHECK_VERSION(2, 60, 0) 274 static const strList test_key2 = { 275 .value = (char *)"algo key2 comments" 276 }; 277 278 static const strList test_key1_2 = { 279 .value = (char *)"algo key1 comments", 280 .next = (strList *)&test_key2, 281 }; 282 283 static char * 284 test_get_authorized_keys_path(void) 285 { 286 return g_build_filename(g_get_home_dir(), ".ssh", "authorized_keys", NULL); 287 } 288 289 static void 290 test_authorized_keys_set(const char *contents) 291 { 292 g_autoptr(GError) err = NULL; 293 g_autofree char *path = NULL; 294 int ret; 295 296 path = g_build_filename(g_get_home_dir(), ".ssh", NULL); 297 ret = g_mkdir_with_parents(path, 0700); 298 g_assert(ret == 0); 299 g_free(path); 300 301 path = test_get_authorized_keys_path(); 302 g_file_set_contents(path, contents, -1, &err); 303 g_assert(err == NULL); 304 } 305 306 static void 307 test_authorized_keys_equal(const char *expected) 308 { 309 g_autoptr(GError) err = NULL; 310 g_autofree char *path = NULL; 311 g_autofree char *contents = NULL; 312 313 path = test_get_authorized_keys_path(); 314 g_file_get_contents(path, &contents, NULL, &err); 315 g_assert(err == NULL); 316 317 g_assert(g_strcmp0(contents, expected) == 0); 318 } 319 320 static void 321 test_invalid_user(void) 322 { 323 Error *err = NULL; 324 325 qmp_guest_ssh_add_authorized_keys("", NULL, FALSE, FALSE, &err); 326 error_free_or_abort(&err); 327 328 qmp_guest_ssh_remove_authorized_keys("", NULL, &err); 329 error_free_or_abort(&err); 330 } 331 332 static void 333 test_invalid_key(void) 334 { 335 strList key = { 336 .value = (char *)"not a valid\nkey" 337 }; 338 Error *err = NULL; 339 340 qmp_guest_ssh_add_authorized_keys(g_get_user_name(), &key, 341 FALSE, FALSE, &err); 342 error_free_or_abort(&err); 343 344 qmp_guest_ssh_remove_authorized_keys(g_get_user_name(), &key, &err); 345 error_free_or_abort(&err); 346 } 347 348 static void 349 test_add_keys(void) 350 { 351 Error *err = NULL; 352 353 qmp_guest_ssh_add_authorized_keys(g_get_user_name(), 354 (strList *)&test_key2, 355 FALSE, FALSE, 356 &err); 357 g_assert(err == NULL); 358 359 test_authorized_keys_equal("algo key2 comments"); 360 361 qmp_guest_ssh_add_authorized_keys(g_get_user_name(), 362 (strList *)&test_key1_2, 363 FALSE, FALSE, 364 &err); 365 g_assert(err == NULL); 366 367 /* key2 came first, and should'nt be duplicated */ 368 test_authorized_keys_equal("algo key2 comments\n" 369 "algo key1 comments"); 370 } 371 372 static void 373 test_add_reset_keys(void) 374 { 375 Error *err = NULL; 376 377 qmp_guest_ssh_add_authorized_keys(g_get_user_name(), 378 (strList *)&test_key1_2, 379 FALSE, FALSE, 380 &err); 381 g_assert(err == NULL); 382 383 /* reset with key2 only */ 384 test_authorized_keys_equal("algo key1 comments\n" 385 "algo key2 comments"); 386 387 qmp_guest_ssh_add_authorized_keys(g_get_user_name(), 388 (strList *)&test_key2, 389 TRUE, TRUE, 390 &err); 391 g_assert(err == NULL); 392 393 test_authorized_keys_equal("algo key2 comments"); 394 395 /* empty should clear file */ 396 qmp_guest_ssh_add_authorized_keys(g_get_user_name(), 397 (strList *)NULL, 398 TRUE, TRUE, 399 &err); 400 g_assert(err == NULL); 401 402 test_authorized_keys_equal(""); 403 } 404 405 static void 406 test_remove_keys(void) 407 { 408 Error *err = NULL; 409 static const char *authkeys = 410 "algo key1 comments\n" 411 /* originally duplicated */ 412 "algo key1 comments\n" 413 "# a commented line\n" 414 "algo some-key another\n"; 415 416 test_authorized_keys_set(authkeys); 417 qmp_guest_ssh_remove_authorized_keys(g_get_user_name(), 418 (strList *)&test_key2, &err); 419 g_assert(err == NULL); 420 test_authorized_keys_equal(authkeys); 421 422 qmp_guest_ssh_remove_authorized_keys(g_get_user_name(), 423 (strList *)&test_key1_2, &err); 424 g_assert(err == NULL); 425 test_authorized_keys_equal("# a commented line\n" 426 "algo some-key another\n"); 427 } 428 429 int main(int argc, char *argv[]) 430 { 431 setlocale(LC_ALL, ""); 432 433 g_test_init(&argc, &argv, G_TEST_OPTION_ISOLATE_DIRS, NULL); 434 435 g_test_add_func("/qga/ssh/invalid_user", test_invalid_user); 436 g_test_add_func("/qga/ssh/invalid_key", test_invalid_key); 437 g_test_add_func("/qga/ssh/add_keys", test_add_keys); 438 g_test_add_func("/qga/ssh/add_reset_keys", test_add_reset_keys); 439 g_test_add_func("/qga/ssh/remove_keys", test_remove_keys); 440 441 return g_test_run(); 442 } 443 #else 444 int main(int argc, char *argv[]) 445 { 446 g_test_message("test skipped, needs glib >= 2.60"); 447 return 0; 448 } 449 #endif /* GLIB_2_60 */ 450 #endif /* BUILD_UNIT_TEST */ 451