2013-03-20 06:21:16 +01:00
|
|
|
/*
|
|
|
|
* The Qubes OS Project, http://www.qubes-os.org
|
|
|
|
*
|
|
|
|
* Copyright (C) 2010 Rafal Wojtczuk <rafal@invisiblethingslab.com>
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU General Public License
|
|
|
|
* as published by the Free Software Foundation; either version 2
|
|
|
|
* of the License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
* along with this program; if not, write to the Free Software
|
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
#define _GNU_SOURCE
|
|
|
|
#include <sys/socket.h>
|
2015-03-16 21:10:25 +01:00
|
|
|
#include <sys/wait.h>
|
2013-03-20 06:21:16 +01:00
|
|
|
#include <sys/un.h>
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
#include <unistd.h>
|
|
|
|
#include <fcntl.h>
|
|
|
|
#include <string.h>
|
2015-03-16 21:10:25 +01:00
|
|
|
#include "libqrexec-utils.h"
|
2013-03-20 06:21:16 +01:00
|
|
|
#include "qrexec.h"
|
2015-03-16 21:10:25 +01:00
|
|
|
#include "qrexec-agent.h"
|
|
|
|
|
|
|
|
void handle_vchan_error(const char *op)
|
|
|
|
{
|
|
|
|
fprintf(stderr, "Error while vchan %s, exiting\n", op);
|
|
|
|
exit(1);
|
|
|
|
}
|
|
|
|
|
2018-02-16 04:25:56 +01:00
|
|
|
void do_exec(char *cmd __attribute__((__unused__))) {
|
2015-03-16 21:10:25 +01:00
|
|
|
fprintf(stderr, "BUG: do_exec function shouldn't be called!\n");
|
|
|
|
exit(1);
|
|
|
|
}
|
|
|
|
|
|
|
|
int connect_unix_socket(char *path)
|
2013-03-20 06:21:16 +01:00
|
|
|
{
|
2013-12-27 06:06:12 +01:00
|
|
|
int s, len;
|
|
|
|
struct sockaddr_un remote;
|
2013-03-20 06:21:16 +01:00
|
|
|
|
2013-12-27 06:06:12 +01:00
|
|
|
if ((s = socket(AF_UNIX, SOCK_STREAM, 0)) == -1) {
|
|
|
|
perror("socket");
|
|
|
|
return -1;
|
|
|
|
}
|
2013-03-20 06:21:16 +01:00
|
|
|
|
2013-12-27 06:06:12 +01:00
|
|
|
remote.sun_family = AF_UNIX;
|
2015-03-16 21:10:25 +01:00
|
|
|
strncpy(remote.sun_path, path,
|
2013-12-27 06:06:12 +01:00
|
|
|
sizeof(remote.sun_path));
|
|
|
|
len = strlen(remote.sun_path) + sizeof(remote.sun_family);
|
|
|
|
if (connect(s, (struct sockaddr *) &remote, len) == -1) {
|
|
|
|
perror("connect");
|
|
|
|
exit(1);
|
|
|
|
}
|
|
|
|
return s;
|
2013-03-20 06:21:16 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
char *get_program_name(char *prog)
|
|
|
|
{
|
2013-12-27 06:06:12 +01:00
|
|
|
char *basename = rindex(prog, '/');
|
|
|
|
if (basename)
|
|
|
|
return basename + 1;
|
|
|
|
else
|
|
|
|
return prog;
|
2013-03-20 06:21:16 +01:00
|
|
|
}
|
|
|
|
|
2018-02-19 02:08:45 +01:00
|
|
|
/* Target specification with keyword have changed from $... to @... . Convert
|
|
|
|
* the argument appropriately, to avoid breaking user tools.
|
|
|
|
*/
|
|
|
|
void convert_target_name_keyword(char *target)
|
|
|
|
{
|
|
|
|
size_t i;
|
|
|
|
size_t len = strlen(target);
|
|
|
|
|
|
|
|
for (i = 0; i < len; i++)
|
|
|
|
if (target[i] == '$')
|
|
|
|
target[i] = '@';
|
|
|
|
}
|
|
|
|
|
2013-03-20 06:21:16 +01:00
|
|
|
int main(int argc, char **argv)
|
|
|
|
{
|
2013-12-27 06:06:12 +01:00
|
|
|
int trigger_fd;
|
2013-12-27 06:07:33 +01:00
|
|
|
struct trigger_service_params params;
|
2015-03-16 21:10:25 +01:00
|
|
|
struct exec_params exec_params;
|
|
|
|
int ret, i;
|
2015-03-17 14:17:01 +01:00
|
|
|
int start_local_process = 0;
|
2013-12-27 06:06:12 +01:00
|
|
|
char *abs_exec_path;
|
2015-03-20 12:05:48 +01:00
|
|
|
pid_t child_pid = 0;
|
2015-03-16 21:10:25 +01:00
|
|
|
int inpipe[2], outpipe[2];
|
2013-03-20 06:21:16 +01:00
|
|
|
|
2015-03-17 14:17:01 +01:00
|
|
|
if (argc < 3) {
|
2013-12-27 06:06:12 +01:00
|
|
|
fprintf(stderr,
|
2015-03-17 14:17:01 +01:00
|
|
|
"usage: %s target_vmname program_ident [local_program [local program arguments]]\n",
|
2013-12-27 06:06:12 +01:00
|
|
|
argv[0]);
|
|
|
|
exit(1);
|
|
|
|
}
|
2015-03-17 14:17:01 +01:00
|
|
|
if (argc > 3) {
|
|
|
|
start_local_process = 1;
|
|
|
|
}
|
2013-03-20 06:21:16 +01:00
|
|
|
|
2015-03-16 21:10:25 +01:00
|
|
|
trigger_fd = connect_unix_socket(QREXEC_AGENT_TRIGGER_PATH);
|
2013-03-20 06:21:16 +01:00
|
|
|
|
2013-12-27 06:06:12 +01:00
|
|
|
memset(¶ms, 0, sizeof(params));
|
2013-12-27 06:07:33 +01:00
|
|
|
strncpy(params.service_name, argv[2], sizeof(params.service_name));
|
2018-02-19 02:08:45 +01:00
|
|
|
|
|
|
|
convert_target_name_keyword(argv[1]);
|
2013-12-27 06:07:33 +01:00
|
|
|
strncpy(params.target_domain, argv[1],
|
|
|
|
sizeof(params.target_domain));
|
2018-02-19 02:08:45 +01:00
|
|
|
|
2013-12-27 06:07:33 +01:00
|
|
|
snprintf(params.request_id.ident,
|
2015-03-16 21:10:25 +01:00
|
|
|
sizeof(params.request_id.ident), "SOCKET");
|
2013-03-20 06:21:16 +01:00
|
|
|
|
2013-12-27 06:06:12 +01:00
|
|
|
if (write(trigger_fd, ¶ms, sizeof(params)) < 0) {
|
2015-03-16 21:10:25 +01:00
|
|
|
perror("write to agent");
|
|
|
|
exit(1);
|
|
|
|
}
|
|
|
|
ret = read(trigger_fd, &exec_params, sizeof(exec_params));
|
|
|
|
if (ret == 0) {
|
|
|
|
fprintf(stderr, "Request refused\n");
|
2017-06-20 23:41:12 +02:00
|
|
|
exit(126);
|
2015-03-16 21:10:25 +01:00
|
|
|
}
|
|
|
|
if (ret < 0 || ret != sizeof(exec_params)) {
|
|
|
|
perror("read");
|
2013-12-27 06:06:12 +01:00
|
|
|
exit(1);
|
|
|
|
}
|
2014-04-22 00:56:52 +02:00
|
|
|
|
2015-03-17 14:17:01 +01:00
|
|
|
if (start_local_process) {
|
|
|
|
if (socketpair(AF_UNIX, SOCK_STREAM, 0, inpipe) ||
|
|
|
|
socketpair(AF_UNIX, SOCK_STREAM, 0, outpipe)) {
|
|
|
|
perror("socketpair");
|
|
|
|
exit(1);
|
2015-03-16 21:10:25 +01:00
|
|
|
}
|
2016-03-21 13:23:34 +01:00
|
|
|
prepare_child_env();
|
2015-03-17 14:17:01 +01:00
|
|
|
|
|
|
|
switch (child_pid = fork()) {
|
|
|
|
case -1:
|
|
|
|
perror("fork");
|
|
|
|
exit(-1);
|
|
|
|
case 0:
|
|
|
|
close(inpipe[1]);
|
|
|
|
close(outpipe[0]);
|
|
|
|
close(trigger_fd);
|
|
|
|
for (i = 0; i < 3; i++) {
|
|
|
|
if (i != 2 || getenv("PASS_LOCAL_STDERR")) {
|
|
|
|
char *env;
|
|
|
|
if (asprintf(&env, "SAVED_FD_%d=%d", i, dup(i)) < 0) {
|
|
|
|
perror("prepare SAVED_FD_");
|
|
|
|
exit(1);
|
|
|
|
}
|
|
|
|
putenv(env);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
dup2(inpipe[0], 0);
|
|
|
|
dup2(outpipe[1], 1);
|
|
|
|
close(inpipe[0]);
|
|
|
|
close(outpipe[1]);
|
2015-03-16 21:10:25 +01:00
|
|
|
|
2015-03-17 14:17:01 +01:00
|
|
|
abs_exec_path = strdup(argv[3]);
|
|
|
|
argv[3] = get_program_name(argv[3]);
|
|
|
|
execv(abs_exec_path, argv + 3);
|
|
|
|
perror("execv");
|
|
|
|
exit(-1);
|
|
|
|
}
|
2015-03-16 21:10:25 +01:00
|
|
|
close(inpipe[0]);
|
|
|
|
close(outpipe[1]);
|
|
|
|
|
2015-03-17 14:17:01 +01:00
|
|
|
ret = handle_data_client(MSG_SERVICE_CONNECT,
|
|
|
|
exec_params.connect_domain, exec_params.connect_port,
|
|
|
|
inpipe[1], outpipe[0], -1);
|
|
|
|
} else {
|
|
|
|
ret = handle_data_client(MSG_SERVICE_CONNECT,
|
|
|
|
exec_params.connect_domain, exec_params.connect_port,
|
|
|
|
1, 0, -1);
|
2015-03-16 21:10:25 +01:00
|
|
|
}
|
|
|
|
|
2013-12-27 06:06:12 +01:00
|
|
|
close(trigger_fd);
|
2017-06-20 21:40:47 +02:00
|
|
|
if (start_local_process) {
|
|
|
|
if (waitpid(child_pid, &i, 0) != -1) {
|
|
|
|
if (WIFSIGNALED(i))
|
|
|
|
ret = 128 + WTERMSIG(i);
|
|
|
|
else
|
|
|
|
ret = WEXITSTATUS(i);
|
|
|
|
} else {
|
|
|
|
perror("wait for local process");
|
|
|
|
}
|
|
|
|
}
|
2013-03-20 06:21:16 +01:00
|
|
|
|
2015-03-16 21:32:34 +01:00
|
|
|
return ret;
|
2013-03-20 06:21:16 +01:00
|
|
|
}
|