1 /* GDBus - GLib D-Bus Library
3 * Copyright (C) 2008-2010 Red Hat, Inc.
5 * This library is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU Lesser General Public
7 * License as published by the Free Software Foundation; either
8 * version 2 of the License, or (at your option) any later version.
10 * This library is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 * Lesser General Public License for more details.
15 * You should have received a copy of the GNU Lesser General
16 * Public License along with this library; if not, write to the
17 * Free Software Foundation, Inc., 59 Temple Place, Suite 330,
18 * Boston, MA 02111-1307, USA.
20 * Author: David Zeuthen <davidz@redhat.com>
25 #include "gdbusauth.h"
27 #include "gdbusauthmechanismanon.h"
28 #include "gdbusauthmechanismexternal.h"
29 #include "gdbusauthmechanismsha1.h"
30 #include "gdbusauthobserver.h"
32 #include "gdbuserror.h"
33 #include "gdbusutils.h"
34 #include "gioenumtypes.h"
35 #include "gcredentials.h"
36 #include "gdbusprivate.h"
37 #include "giostream.h"
38 #include "gdatainputstream.h"
39 #include "gdataoutputstream.h"
42 #include "gnetworking.h"
43 #include "gunixconnection.h"
44 #include "gunixcredentialsmessage.h"
50 debug_print (const gchar *message, ...)
52 if (G_UNLIKELY (_g_dbus_debug_authentication ()))
59 _g_dbus_debug_print_lock ();
61 va_start (var_args, message);
62 s = g_strdup_vprintf (message, var_args);
65 str = g_string_new (NULL);
66 for (n = 0; s[n] != '\0'; n++)
68 if (G_UNLIKELY (s[n] == '\r'))
69 g_string_append (str, "\\r");
70 else if (G_UNLIKELY (s[n] == '\n'))
71 g_string_append (str, "\\n");
73 g_string_append_c (str, s[n]);
75 g_print ("GDBus-debug:Auth: %s\n", str->str);
76 g_string_free (str, TRUE);
79 _g_dbus_debug_print_unlock ();
90 static void mechanism_free (Mechanism *m);
92 struct _GDBusAuthPrivate
96 /* A list of available Mechanism, sorted according to priority */
97 GList *available_mechanisms;
106 G_DEFINE_TYPE (GDBusAuth, _g_dbus_auth, G_TYPE_OBJECT);
108 /* ---------------------------------------------------------------------------------------------------- */
111 _g_dbus_auth_finalize (GObject *object)
113 GDBusAuth *auth = G_DBUS_AUTH (object);
115 if (auth->priv->stream != NULL)
116 g_object_unref (auth->priv->stream);
117 g_list_free_full (auth->priv->available_mechanisms, (GDestroyNotify) mechanism_free);
119 if (G_OBJECT_CLASS (_g_dbus_auth_parent_class)->finalize != NULL)
120 G_OBJECT_CLASS (_g_dbus_auth_parent_class)->finalize (object);
124 _g_dbus_auth_get_property (GObject *object,
129 GDBusAuth *auth = G_DBUS_AUTH (object);
134 g_value_set_object (value, auth->priv->stream);
138 G_OBJECT_WARN_INVALID_PROPERTY_ID (object, prop_id, pspec);
144 _g_dbus_auth_set_property (GObject *object,
149 GDBusAuth *auth = G_DBUS_AUTH (object);
154 auth->priv->stream = g_value_dup_object (value);
158 G_OBJECT_WARN_INVALID_PROPERTY_ID (object, prop_id, pspec);
164 _g_dbus_auth_class_init (GDBusAuthClass *klass)
166 GObjectClass *gobject_class;
168 g_type_class_add_private (klass, sizeof (GDBusAuthPrivate));
170 gobject_class = G_OBJECT_CLASS (klass);
171 gobject_class->get_property = _g_dbus_auth_get_property;
172 gobject_class->set_property = _g_dbus_auth_set_property;
173 gobject_class->finalize = _g_dbus_auth_finalize;
175 g_object_class_install_property (gobject_class,
177 g_param_spec_object ("stream",
179 P_("The underlying GIOStream used for I/O"),
183 G_PARAM_CONSTRUCT_ONLY |
184 G_PARAM_STATIC_NAME |
185 G_PARAM_STATIC_BLURB |
186 G_PARAM_STATIC_NICK));
190 mechanism_free (Mechanism *m)
196 add_mechanism (GDBusAuth *auth,
197 GDBusAuthObserver *observer,
198 GType mechanism_type)
202 name = _g_dbus_auth_mechanism_get_name (mechanism_type);
203 if (observer == NULL || g_dbus_auth_observer_allow_mechanism (observer, name))
206 m = g_new0 (Mechanism, 1);
208 m->priority = _g_dbus_auth_mechanism_get_priority (mechanism_type);
209 m->gtype = mechanism_type;
210 auth->priv->available_mechanisms = g_list_prepend (auth->priv->available_mechanisms, m);
215 mech_compare_func (Mechanism *a, Mechanism *b)
218 /* ensure deterministic order */
219 ret = b->priority - a->priority;
221 ret = g_strcmp0 (b->name, a->name);
226 _g_dbus_auth_init (GDBusAuth *auth)
228 auth->priv = G_TYPE_INSTANCE_GET_PRIVATE (auth, G_TYPE_DBUS_AUTH, GDBusAuthPrivate);
233 _g_dbus_auth_add_mechs (GDBusAuth *auth,
234 GDBusAuthObserver *observer)
236 /* TODO: trawl extension points */
237 add_mechanism (auth, observer, G_TYPE_DBUS_AUTH_MECHANISM_ANON);
238 add_mechanism (auth, observer, G_TYPE_DBUS_AUTH_MECHANISM_SHA1);
239 add_mechanism (auth, observer, G_TYPE_DBUS_AUTH_MECHANISM_EXTERNAL);
241 auth->priv->available_mechanisms = g_list_sort (auth->priv->available_mechanisms,
242 (GCompareFunc) mech_compare_func);
246 find_mech_by_name (GDBusAuth *auth,
254 for (l = auth->priv->available_mechanisms; l != NULL; l = l->next)
256 Mechanism *m = l->data;
257 if (g_strcmp0 (name, m->name) == 0)
269 _g_dbus_auth_new (GIOStream *stream)
271 return g_object_new (G_TYPE_DBUS_AUTH,
276 /* ---------------------------------------------------------------------------------------------------- */
277 /* like g_data_input_stream_read_line() but sets error if there's no content to read */
279 _my_g_data_input_stream_read_line (GDataInputStream *dis,
280 gsize *out_line_length,
281 GCancellable *cancellable,
286 g_return_val_if_fail (error == NULL || *error == NULL, NULL);
288 ret = g_data_input_stream_read_line (dis,
292 if (ret == NULL && error != NULL && *error == NULL)
294 g_set_error_literal (error,
297 _("Unexpected lack of content trying to read a line"));
303 /* This function is to avoid situations like this
305 * BEGIN\r\nl\0\0\1...
307 * e.g. where we read into the first D-Bus message while waiting for
308 * the final line from the client (TODO: file bug against gio for
312 _my_g_input_stream_read_line_safe (GInputStream *i,
313 gsize *out_line_length,
314 GCancellable *cancellable,
320 gboolean last_was_cr;
322 str = g_string_new (NULL);
327 num_read = g_input_stream_read (i,
336 if (error != NULL && *error == NULL)
338 g_set_error_literal (error,
341 _("Unexpected lack of content trying to (safely) read a line"));
346 g_string_append_c (str, (gint) c);
351 g_assert (str->len >= 2);
352 g_string_set_size (str, str->len - 2);
356 last_was_cr = (c == 0x0d);
360 if (out_line_length != NULL)
361 *out_line_length = str->len;
362 return g_string_free (str, FALSE);
365 g_assert (error == NULL || *error != NULL);
366 g_string_free (str, TRUE);
370 /* ---------------------------------------------------------------------------------------------------- */
373 append_nibble (GString *s, gint val)
375 g_string_append_c (s, val >= 10 ? ('a' + val - 10) : ('0' + val));
379 hexdecode (const gchar *str,
388 s = g_string_new (NULL);
390 for (n = 0; str[n] != '\0'; n += 2)
396 upper_nibble = g_ascii_xdigit_value (str[n]);
397 lower_nibble = g_ascii_xdigit_value (str[n + 1]);
398 if (upper_nibble == -1 || lower_nibble == -1)
403 "Error hexdecoding string `%s' around position %d",
407 value = (upper_nibble<<4) | lower_nibble;
408 g_string_append_c (s, value);
411 ret = g_string_free (s, FALSE);
416 g_string_free (s, TRUE);
422 hexencode (const gchar *str)
427 s = g_string_new (NULL);
428 for (n = 0; str[n] != '\0'; n++)
434 val = ((const guchar *) str)[n];
435 upper_nibble = val >> 4;
436 lower_nibble = val & 0x0f;
438 append_nibble (s, upper_nibble);
439 append_nibble (s, lower_nibble);
442 return g_string_free (s, FALSE);
445 /* ---------------------------------------------------------------------------------------------------- */
447 static GDBusAuthMechanism *
448 client_choose_mech_and_send_initial_response (GDBusAuth *auth,
449 GCredentials *credentials_that_were_sent,
450 const gchar* const *supported_auth_mechs,
451 GPtrArray *attempted_auth_mechs,
452 GDataOutputStream *dos,
453 GCancellable *cancellable,
456 GDBusAuthMechanism *mech;
457 GType auth_mech_to_use_gtype;
460 gchar *initial_response;
461 gsize initial_response_len;
468 debug_print ("CLIENT: Trying to choose mechanism");
470 /* find an authentication mechanism to try, if any */
471 auth_mech_to_use_gtype = (GType) 0;
472 for (n = 0; supported_auth_mechs[n] != NULL; n++)
474 gboolean attempted_already;
475 attempted_already = FALSE;
476 for (m = 0; m < attempted_auth_mechs->len; m++)
478 if (g_strcmp0 (supported_auth_mechs[n], attempted_auth_mechs->pdata[m]) == 0)
480 attempted_already = TRUE;
484 if (!attempted_already)
486 auth_mech_to_use_gtype = find_mech_by_name (auth, supported_auth_mechs[n]);
487 if (auth_mech_to_use_gtype != (GType) 0)
492 if (auth_mech_to_use_gtype == (GType) 0)
498 debug_print ("CLIENT: Exhausted all available mechanisms");
500 available = g_strjoinv (", ", (gchar **) supported_auth_mechs);
502 tried_str = g_string_new (NULL);
503 for (n = 0; n < attempted_auth_mechs->len; n++)
506 g_string_append (tried_str, ", ");
507 g_string_append (tried_str, attempted_auth_mechs->pdata[n]);
512 _("Exhausted all available authentication mechanisms (tried: %s) (available: %s)"),
515 g_string_free (tried_str, TRUE);
520 /* OK, decided on a mechanism - let's do this thing */
521 mech = g_object_new (auth_mech_to_use_gtype,
522 "stream", auth->priv->stream,
523 "credentials", credentials_that_were_sent,
525 debug_print ("CLIENT: Trying mechanism `%s'", _g_dbus_auth_mechanism_get_name (auth_mech_to_use_gtype));
526 g_ptr_array_add (attempted_auth_mechs, (gpointer) _g_dbus_auth_mechanism_get_name (auth_mech_to_use_gtype));
528 /* the auth mechanism may not be supported
529 * (for example, EXTERNAL only works if credentials were exchanged)
531 if (!_g_dbus_auth_mechanism_is_supported (mech))
533 debug_print ("CLIENT: Mechanism `%s' says it is not supported", _g_dbus_auth_mechanism_get_name (auth_mech_to_use_gtype));
534 g_object_unref (mech);
539 initial_response_len = -1;
540 initial_response = _g_dbus_auth_mechanism_client_initiate (mech,
541 &initial_response_len);
543 g_printerr ("using auth mechanism with name `%s' of type `%s' with initial response `%s'\n",
544 _g_dbus_auth_mechanism_get_name (auth_mech_to_use_gtype),
545 g_type_name (G_TYPE_FROM_INSTANCE (mech)),
548 if (initial_response != NULL)
550 //g_printerr ("initial_response = `%s'\n", initial_response);
551 encoded = hexencode (initial_response);
552 s = g_strdup_printf ("AUTH %s %s\r\n",
553 _g_dbus_auth_mechanism_get_name (auth_mech_to_use_gtype),
555 g_free (initial_response);
560 s = g_strdup_printf ("AUTH %s\r\n", _g_dbus_auth_mechanism_get_name (auth_mech_to_use_gtype));
562 debug_print ("CLIENT: writing `%s'", s);
563 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
565 g_object_unref (mech);
577 /* ---------------------------------------------------------------------------------------------------- */
581 CLIENT_STATE_WAITING_FOR_DATA,
582 CLIENT_STATE_WAITING_FOR_OK,
583 CLIENT_STATE_WAITING_FOR_REJECT,
584 CLIENT_STATE_WAITING_FOR_AGREE_UNIX_FD
588 _g_dbus_auth_run_client (GDBusAuth *auth,
589 GDBusAuthObserver *observer,
590 GDBusCapabilityFlags offered_capabilities,
591 GDBusCapabilityFlags *out_negotiated_capabilities,
592 GCancellable *cancellable,
596 GDataInputStream *dis;
597 GDataOutputStream *dos;
598 GCredentials *credentials;
602 gchar **supported_auth_mechs;
603 GPtrArray *attempted_auth_mechs;
604 GDBusAuthMechanism *mech;
606 GDBusCapabilityFlags negotiated_capabilities;
608 debug_print ("CLIENT: initiating");
610 _g_dbus_auth_add_mechs (auth, observer);
613 supported_auth_mechs = NULL;
614 attempted_auth_mechs = g_ptr_array_new ();
616 negotiated_capabilities = 0;
619 dis = G_DATA_INPUT_STREAM (g_data_input_stream_new (g_io_stream_get_input_stream (auth->priv->stream)));
620 dos = G_DATA_OUTPUT_STREAM (g_data_output_stream_new (g_io_stream_get_output_stream (auth->priv->stream)));
621 g_filter_input_stream_set_close_base_stream (G_FILTER_INPUT_STREAM (dis), FALSE);
622 g_filter_output_stream_set_close_base_stream (G_FILTER_OUTPUT_STREAM (dos), FALSE);
624 g_data_input_stream_set_newline_type (dis, G_DATA_STREAM_NEWLINE_TYPE_CR_LF);
627 if (G_IS_UNIX_CONNECTION (auth->priv->stream))
629 credentials = g_credentials_new ();
630 if (!g_unix_connection_send_credentials (G_UNIX_CONNECTION (auth->priv->stream),
637 if (!g_data_output_stream_put_byte (dos, '\0', cancellable, error))
641 if (!g_data_output_stream_put_byte (dos, '\0', cancellable, error))
645 if (credentials != NULL)
647 if (G_UNLIKELY (_g_dbus_debug_authentication ()))
649 s = g_credentials_to_string (credentials);
650 debug_print ("CLIENT: sent credentials `%s'", s);
656 debug_print ("CLIENT: didn't send any credentials");
659 /* TODO: to reduce roundtrips, try to pick an auth mechanism to start with */
661 /* Get list of supported authentication mechanisms */
663 debug_print ("CLIENT: writing `%s'", s);
664 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
666 state = CLIENT_STATE_WAITING_FOR_REJECT;
672 case CLIENT_STATE_WAITING_FOR_REJECT:
673 debug_print ("CLIENT: WaitingForReject");
674 line = _my_g_data_input_stream_read_line (dis, &line_length, cancellable, error);
677 debug_print ("CLIENT: WaitingForReject, read '%s'", line);
680 if (!g_str_has_prefix (line, "REJECTED "))
685 "In WaitingForReject: Expected `REJECTED am1 am2 ... amN', got `%s'",
690 if (supported_auth_mechs == NULL)
692 supported_auth_mechs = g_strsplit (line + sizeof ("REJECTED ") - 1, " ", 0);
694 for (n = 0; supported_auth_mechs != NULL && supported_auth_mechs[n] != NULL; n++)
695 g_printerr ("supported_auth_mechs[%d] = `%s'\n", n, supported_auth_mechs[n]);
699 mech = client_choose_mech_and_send_initial_response (auth,
701 (const gchar* const *) supported_auth_mechs,
702 attempted_auth_mechs,
708 if (_g_dbus_auth_mechanism_client_get_state (mech) == G_DBUS_AUTH_MECHANISM_STATE_WAITING_FOR_DATA)
709 state = CLIENT_STATE_WAITING_FOR_DATA;
711 state = CLIENT_STATE_WAITING_FOR_OK;
714 case CLIENT_STATE_WAITING_FOR_OK:
715 debug_print ("CLIENT: WaitingForOK");
716 line = _my_g_data_input_stream_read_line (dis, &line_length, cancellable, error);
719 debug_print ("CLIENT: WaitingForOK, read `%s'", line);
720 if (g_str_has_prefix (line, "OK "))
722 if (!g_dbus_is_guid (line + 3))
727 "Invalid OK response `%s'",
732 ret_guid = g_strdup (line + 3);
735 if (offered_capabilities & G_DBUS_CAPABILITY_FLAGS_UNIX_FD_PASSING)
737 s = "NEGOTIATE_UNIX_FD\r\n";
738 debug_print ("CLIENT: writing `%s'", s);
739 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
741 state = CLIENT_STATE_WAITING_FOR_AGREE_UNIX_FD;
746 debug_print ("CLIENT: writing `%s'", s);
747 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
749 /* and we're done! */
753 else if (g_str_has_prefix (line, "REJECTED "))
755 goto choose_mechanism;
759 /* TODO: handle other valid responses */
763 "In WaitingForOk: unexpected response `%s'",
770 case CLIENT_STATE_WAITING_FOR_AGREE_UNIX_FD:
771 debug_print ("CLIENT: WaitingForAgreeUnixFD");
772 line = _my_g_data_input_stream_read_line (dis, &line_length, cancellable, error);
775 debug_print ("CLIENT: WaitingForAgreeUnixFD, read=`%s'", line);
776 if (g_strcmp0 (line, "AGREE_UNIX_FD") == 0)
779 negotiated_capabilities |= G_DBUS_CAPABILITY_FLAGS_UNIX_FD_PASSING;
781 debug_print ("CLIENT: writing `%s'", s);
782 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
784 /* and we're done! */
787 else if (g_str_has_prefix (line, "ERROR") && (line[5] == 0 || g_ascii_isspace (line[5])))
789 //g_strstrip (line + 5); g_debug ("bah, no unix_fd: `%s'", line + 5);
792 debug_print ("CLIENT: writing `%s'", s);
793 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
795 /* and we're done! */
800 /* TODO: handle other valid responses */
804 "In WaitingForAgreeUnixFd: unexpected response `%s'",
811 case CLIENT_STATE_WAITING_FOR_DATA:
812 debug_print ("CLIENT: WaitingForData");
813 line = _my_g_data_input_stream_read_line (dis, &line_length, cancellable, error);
816 debug_print ("CLIENT: WaitingForData, read=`%s'", line);
817 if (g_str_has_prefix (line, "DATA "))
821 gsize decoded_data_len = 0;
823 encoded = g_strdup (line + 5);
825 g_strstrip (encoded);
826 decoded_data = hexdecode (encoded, &decoded_data_len, error);
828 if (decoded_data == NULL)
830 g_prefix_error (error, "DATA response is malformed: ");
831 /* invalid encoding, disconnect! */
834 _g_dbus_auth_mechanism_client_data_receive (mech, decoded_data, decoded_data_len);
835 g_free (decoded_data);
837 if (_g_dbus_auth_mechanism_client_get_state (mech) == G_DBUS_AUTH_MECHANISM_STATE_HAVE_DATA_TO_SEND)
842 data = _g_dbus_auth_mechanism_client_data_send (mech, &data_len);
843 encoded_data = hexencode (data);
844 s = g_strdup_printf ("DATA %s\r\n", encoded_data);
845 g_free (encoded_data);
847 debug_print ("CLIENT: writing `%s'", s);
848 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
855 state = CLIENT_STATE_WAITING_FOR_OK;
857 else if (g_str_has_prefix (line, "REJECTED "))
859 /* could be the chosen authentication method just doesn't work. Try
862 goto choose_mechanism;
869 "In WaitingForData: unexpected response `%s'",
877 g_assert_not_reached ();
881 }; /* main authentication client loop */
885 g_object_unref (mech);
886 g_ptr_array_unref (attempted_auth_mechs);
887 g_strfreev (supported_auth_mechs);
888 g_object_unref (dis);
889 g_object_unref (dos);
891 /* ensure return value is NULL if error is set */
892 if (error != NULL && *error != NULL)
898 if (ret_guid != NULL)
900 if (out_negotiated_capabilities != NULL)
901 *out_negotiated_capabilities = negotiated_capabilities;
904 if (credentials != NULL)
905 g_object_unref (credentials);
907 debug_print ("CLIENT: Done, authenticated=%d", ret_guid != NULL);
912 /* ---------------------------------------------------------------------------------------------------- */
915 get_auth_mechanisms (GDBusAuth *auth,
916 gboolean allow_anonymous,
919 const gchar *separator)
925 str = g_string_new (prefix);
927 for (l = auth->priv->available_mechanisms; l != NULL; l = l->next)
929 Mechanism *m = l->data;
931 if (!allow_anonymous && g_strcmp0 (m->name, "ANONYMOUS") == 0)
935 g_string_append (str, separator);
936 g_string_append (str, m->name);
940 g_string_append (str, suffix);
941 return g_string_free (str, FALSE);
947 SERVER_STATE_WAITING_FOR_AUTH,
948 SERVER_STATE_WAITING_FOR_DATA,
949 SERVER_STATE_WAITING_FOR_BEGIN
953 _g_dbus_auth_run_server (GDBusAuth *auth,
954 GDBusAuthObserver *observer,
956 gboolean allow_anonymous,
957 GDBusCapabilityFlags offered_capabilities,
958 GDBusCapabilityFlags *out_negotiated_capabilities,
959 GCredentials **out_received_credentials,
960 GCancellable *cancellable,
965 GDataInputStream *dis;
966 GDataOutputStream *dos;
971 GDBusAuthMechanism *mech;
973 GDBusCapabilityFlags negotiated_capabilities;
974 GCredentials *credentials;
976 debug_print ("SERVER: initiating");
978 _g_dbus_auth_add_mechs (auth, observer);
984 negotiated_capabilities = 0;
987 if (!g_dbus_is_guid (guid))
992 "The given guid `%s' is not valid",
997 dis = G_DATA_INPUT_STREAM (g_data_input_stream_new (g_io_stream_get_input_stream (auth->priv->stream)));
998 dos = G_DATA_OUTPUT_STREAM (g_data_output_stream_new (g_io_stream_get_output_stream (auth->priv->stream)));
999 g_filter_input_stream_set_close_base_stream (G_FILTER_INPUT_STREAM (dis), FALSE);
1000 g_filter_output_stream_set_close_base_stream (G_FILTER_OUTPUT_STREAM (dos), FALSE);
1002 g_data_input_stream_set_newline_type (dis, G_DATA_STREAM_NEWLINE_TYPE_CR_LF);
1004 /* first read the NUL-byte (TODO: read credentials if using a unix domain socket) */
1006 if (G_IS_UNIX_CONNECTION (auth->priv->stream))
1009 credentials = g_unix_connection_receive_credentials (G_UNIX_CONNECTION (auth->priv->stream),
1012 if (credentials == NULL && !g_error_matches (local_error, G_IO_ERROR, G_IO_ERROR_NOT_SUPPORTED))
1014 g_propagate_error (error, local_error);
1021 byte = g_data_input_stream_read_byte (dis, cancellable, &local_error);
1022 byte = byte; /* To avoid -Wunused-but-set-variable */
1023 if (local_error != NULL)
1025 g_propagate_error (error, local_error);
1031 byte = g_data_input_stream_read_byte (dis, cancellable, &local_error);
1032 byte = byte; /* To avoid -Wunused-but-set-variable */
1033 if (local_error != NULL)
1035 g_propagate_error (error, local_error);
1039 if (credentials != NULL)
1041 if (G_UNLIKELY (_g_dbus_debug_authentication ()))
1043 s = g_credentials_to_string (credentials);
1044 debug_print ("SERVER: received credentials `%s'", s);
1050 debug_print ("SERVER: didn't receive any credentials");
1053 state = SERVER_STATE_WAITING_FOR_AUTH;
1058 case SERVER_STATE_WAITING_FOR_AUTH:
1059 debug_print ("SERVER: WaitingForAuth");
1060 line = _my_g_data_input_stream_read_line (dis, &line_length, cancellable, error);
1061 debug_print ("SERVER: WaitingForAuth, read `%s'", line);
1064 if (g_strcmp0 (line, "AUTH") == 0)
1066 s = get_auth_mechanisms (auth, allow_anonymous, "REJECTED ", "\r\n", " ");
1067 debug_print ("SERVER: writing `%s'", s);
1068 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1076 else if (g_str_has_prefix (line, "AUTH "))
1079 const gchar *encoded;
1080 const gchar *mech_name;
1081 GType auth_mech_to_use_gtype;
1083 tokens = g_strsplit (line, " ", 0);
1086 switch (g_strv_length (tokens))
1089 /* no initial response */
1090 mech_name = tokens[1];
1095 /* initial response */
1096 mech_name = tokens[1];
1097 encoded = tokens[2];
1104 "Unexpected line `%s' while in WaitingForAuth state",
1106 g_strfreev (tokens);
1110 /* TODO: record that the client has attempted to use this mechanism */
1111 //g_debug ("client is trying `%s'", mech_name);
1113 auth_mech_to_use_gtype = find_mech_by_name (auth, mech_name);
1114 if ((auth_mech_to_use_gtype == (GType) 0) ||
1115 (!allow_anonymous && g_strcmp0 (mech_name, "ANONYMOUS") == 0))
1117 /* We don't support this auth mechanism */
1118 g_strfreev (tokens);
1119 s = get_auth_mechanisms (auth, allow_anonymous, "REJECTED ", "\r\n", " ");
1120 debug_print ("SERVER: writing `%s'", s);
1121 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1128 /* stay in WAITING FOR AUTH */
1129 state = SERVER_STATE_WAITING_FOR_AUTH;
1133 gchar *initial_response;
1134 gsize initial_response_len;
1136 mech = g_object_new (auth_mech_to_use_gtype,
1137 "stream", auth->priv->stream,
1138 "credentials", credentials,
1141 initial_response = NULL;
1142 initial_response_len = 0;
1143 if (encoded != NULL)
1145 initial_response = hexdecode (encoded, &initial_response_len, error);
1146 if (initial_response == NULL)
1148 g_prefix_error (error, "Initial response is malformed: ");
1149 /* invalid encoding, disconnect! */
1150 g_strfreev (tokens);
1155 _g_dbus_auth_mechanism_server_initiate (mech,
1157 initial_response_len);
1158 g_free (initial_response);
1159 g_strfreev (tokens);
1162 switch (_g_dbus_auth_mechanism_server_get_state (mech))
1164 case G_DBUS_AUTH_MECHANISM_STATE_ACCEPTED:
1165 if (observer != NULL &&
1166 !g_dbus_auth_observer_authorize_authenticated_peer (observer,
1171 g_set_error_literal (error,
1174 _("Cancelled via GDBusAuthObserver::authorize-authenticated-peer"));
1179 s = g_strdup_printf ("OK %s\r\n", guid);
1180 debug_print ("SERVER: writing `%s'", s);
1181 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1187 state = SERVER_STATE_WAITING_FOR_BEGIN;
1191 case G_DBUS_AUTH_MECHANISM_STATE_REJECTED:
1192 s = get_auth_mechanisms (auth, allow_anonymous, "REJECTED ", "\r\n", " ");
1193 debug_print ("SERVER: writing `%s'", s);
1194 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1200 state = SERVER_STATE_WAITING_FOR_AUTH;
1203 case G_DBUS_AUTH_MECHANISM_STATE_WAITING_FOR_DATA:
1204 state = SERVER_STATE_WAITING_FOR_DATA;
1207 case G_DBUS_AUTH_MECHANISM_STATE_HAVE_DATA_TO_SEND:
1211 gchar *encoded_data;
1212 data = _g_dbus_auth_mechanism_server_data_send (mech, &data_len);
1213 encoded_data = hexencode (data);
1214 s = g_strdup_printf ("DATA %s\r\n", encoded_data);
1215 g_free (encoded_data);
1217 debug_print ("SERVER: writing `%s'", s);
1218 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1230 g_assert_not_reached ();
1240 "Unexpected line `%s' while in WaitingForAuth state",
1247 case SERVER_STATE_WAITING_FOR_DATA:
1248 debug_print ("SERVER: WaitingForData");
1249 line = _my_g_data_input_stream_read_line (dis, &line_length, cancellable, error);
1250 debug_print ("SERVER: WaitingForData, read `%s'", line);
1253 if (g_str_has_prefix (line, "DATA "))
1256 gchar *decoded_data;
1257 gsize decoded_data_len = 0;
1259 encoded = g_strdup (line + 5);
1261 g_strstrip (encoded);
1262 decoded_data = hexdecode (encoded, &decoded_data_len, error);
1264 if (decoded_data == NULL)
1266 g_prefix_error (error, "DATA response is malformed: ");
1267 /* invalid encoding, disconnect! */
1270 _g_dbus_auth_mechanism_server_data_receive (mech, decoded_data, decoded_data_len);
1271 g_free (decoded_data);
1272 /* oh man, this goto-crap is so ugly.. really need to rewrite the state machine */
1280 "Unexpected line `%s' while in WaitingForData state",
1286 case SERVER_STATE_WAITING_FOR_BEGIN:
1287 debug_print ("SERVER: WaitingForBegin");
1288 /* Use extremely slow (but reliable) line reader - this basically
1289 * does a recvfrom() system call per character
1291 * (the problem with using GDataInputStream's read_line is that because of
1292 * buffering it might start reading into the first D-Bus message that
1293 * appears after "BEGIN\r\n"....)
1295 line = _my_g_input_stream_read_line_safe (g_io_stream_get_input_stream (auth->priv->stream),
1299 debug_print ("SERVER: WaitingForBegin, read `%s'", line);
1302 if (g_strcmp0 (line, "BEGIN") == 0)
1309 else if (g_strcmp0 (line, "NEGOTIATE_UNIX_FD") == 0)
1312 if (offered_capabilities & G_DBUS_CAPABILITY_FLAGS_UNIX_FD_PASSING)
1314 negotiated_capabilities |= G_DBUS_CAPABILITY_FLAGS_UNIX_FD_PASSING;
1315 s = "AGREE_UNIX_FD\r\n";
1316 debug_print ("SERVER: writing `%s'", s);
1317 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1322 s = "ERROR \"fd passing not offered\"\r\n";
1323 debug_print ("SERVER: writing `%s'", s);
1324 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1330 g_debug ("Unexpected line `%s' while in WaitingForBegin state", line);
1332 s = "ERROR \"Unknown Command\"\r\n";
1333 debug_print ("SERVER: writing `%s'", s);
1334 if (!g_data_output_stream_put_string (dos, s, cancellable, error))
1340 g_assert_not_reached ();
1346 g_set_error_literal (error,
1349 "Not implemented (server)");
1353 g_object_unref (mech);
1355 g_object_unref (dis);
1357 g_object_unref (dos);
1359 /* ensure return value is FALSE if error is set */
1360 if (error != NULL && *error != NULL)
1367 if (out_negotiated_capabilities != NULL)
1368 *out_negotiated_capabilities = negotiated_capabilities;
1369 if (out_received_credentials != NULL)
1370 *out_received_credentials = credentials != NULL ? g_object_ref (credentials) : NULL;
1373 if (credentials != NULL)
1374 g_object_unref (credentials);
1376 debug_print ("SERVER: Done, authenticated=%d", ret);
1381 /* ---------------------------------------------------------------------------------------------------- */