summaryrefslogtreecommitdiff
path: root/apt-pkg/contrib/netrc.cc
blob: 9c40aec054631566a9f8aa86cd411d65b195332f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
// -*- mode: cpp; mode: fold -*-
// Description								/*{{{*/
// $Id: netrc.c,v 1.38 2007-11-07 09:21:35 bagder Exp $
/* ######################################################################

   netrc file parser - returns the login and password of a give host in
                       a specified netrc-type file

   Originally written by Daniel Stenberg, <daniel@haxx.se>, et al. and
   placed into the Public Domain, do with it what you will.

   ##################################################################### */
									/*}}}*/
#include <config.h>

#include <apt-pkg/configuration.h>
#include <apt-pkg/error.h>
#include <apt-pkg/fileutl.h>
#include <apt-pkg/strutl.h>

#include <iostream>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <stddef.h>
#include <pwd.h>

#include "netrc.h"

using std::string;

/* Get user and password from .netrc when given a machine name */

enum {
  NOTHING,
  HOSTFOUND,    /* the 'machine' keyword was found */
  HOSTCOMPLETE, /* the machine name following the keyword was found too */
  HOSTVALID,    /* this is "our" machine! */
  HOSTEND /* LAST enum */
};

/* make sure we have room for at least this size: */
#define LOGINSIZE 256
#define PASSWORDSIZE 256
#define NETRC DOT_CHAR "netrc"

/* returns -1 on failure, 0 if the host is found, 1 is the host isn't found */
static int parsenetrc_string (char *host, std::string &login, std::string &password, char *netrcfile = NULL)
{
  FILE *file;
  int retcode = 1;
  int specific_login = (login.empty() == false);
  bool netrc_alloc = false;

  if (!netrcfile) {
    char const * home = getenv ("HOME"); /* portable environment reader */

    if (!home) {
      struct passwd *pw;
      pw = getpwuid (geteuid ());
      if(pw)
        home = pw->pw_dir;
    }

    if (!home)
      return -1;

    if (asprintf (&netrcfile, "%s%s%s", home, DIR_CHAR, NETRC) == -1 || netrcfile == NULL)
      return -1;
    else
      netrc_alloc = true;
  }

  file = fopen (netrcfile, "r");
  if(file) {
    char *tok;
    char *tok_buf;
    bool done = false;
    char *netrcbuffer = NULL;
    size_t netrcbuffer_size = 0;

    int state = NOTHING;
    char state_login = 0;        /* Found a login keyword */
    char state_password = 0;     /* Found a password keyword */
    int state_our_login = false;  /* With specific_login,
				     found *our* login name */

    while (!done && getline(&netrcbuffer, &netrcbuffer_size, file) != -1) {
      tok = strtok_r (netrcbuffer, " \t\n", &tok_buf);
      while (!done && tok) {
        if(login.empty() == false && password.empty() == false) {
          done = true;
          break;
        }

        switch(state) {
        case NOTHING:
          if (!strcasecmp ("machine", tok)) {
            /* the next tok is the machine name, this is in itself the
               delimiter that starts the stuff entered for this machine,
               after this we need to search for 'login' and
               'password'. */
            state = HOSTFOUND;
          }
          break;
        case HOSTFOUND:
	   /* extended definition of a "machine" if we have a "/"
	      we match the start of the string (host.startswith(token) */
	  if ((strchr(host, '/') && strstr(host, tok) == host) ||
	      (!strcasecmp (host, tok))) {
            /* and yes, this is our host! */
            state = HOSTVALID;
            retcode = 0; /* we did find our host */
          }
          else
            /* not our host */
            state = NOTHING;
          break;
        case HOSTVALID:
          /* we are now parsing sub-keywords regarding "our" host */
          if (state_login) {
            if (specific_login)
              state_our_login = !strcasecmp (login.c_str(), tok);
            else
              login = tok;
            state_login = 0;
          } else if (state_password) {
            if (state_our_login || !specific_login)
              password = tok;
            state_password = 0;
          } else if (!strcasecmp ("login", tok))
            state_login = 1;
          else if (!strcasecmp ("password", tok))
            state_password = 1;
          else if(!strcasecmp ("machine", tok)) {
            /* ok, there's machine here go => */
            state = HOSTFOUND;
            state_our_login = false;
          }
          break;
        } /* switch (state) */

        tok = strtok_r (NULL, " \t\n", &tok_buf);
      } /* while(tok) */
    } /* while getline() */

    free(netrcbuffer);
    fclose(file);
  }

  if (netrc_alloc)
    free(netrcfile);

  return retcode;
}

void maybe_add_auth (URI &Uri, string NetRCFile)
{
  if (_config->FindB("Debug::Acquire::netrc", false) == true)
     std::clog << "maybe_add_auth: " << (string)Uri 
	       << " " << NetRCFile << std::endl;
  if (Uri.Password.empty () == true || Uri.User.empty () == true)
  {
    if (NetRCFile.empty () == false)
    {
       std::string login, password;
      char *netrcfile = strdup(NetRCFile.c_str());

      // first check for a generic host based netrc entry
      char *host = strdup(Uri.Host.c_str());
      if (host && parsenetrc_string(host, login, password, netrcfile) == 0)
      {
	 if (_config->FindB("Debug::Acquire::netrc", false) == true)
	    std::clog << "host: " << host 
		      << " user: " << login
		      << " pass-size: " << password.size()
		      << std::endl;
        Uri.User = login;
        Uri.Password = password;
	free(netrcfile);
	free(host);
	return;
      }
      free(host);

      // if host did not work, try Host+Path next, this will trigger
      // a lookup uri.startswith(host) in the netrc file parser (because
      // of the "/"
      char *hostpath = strdup((Uri.Host + Uri.Path).c_str());
      if (hostpath && parsenetrc_string(hostpath, login, password, netrcfile) == 0)
      {
	 if (_config->FindB("Debug::Acquire::netrc", false) == true)
	    std::clog << "hostpath: " << hostpath
		      << " user: " << login
		      << " pass-size: " << password.size()
		      << std::endl;
	 Uri.User = login;
	 Uri.Password = password;
      }
      free(netrcfile);
      free(hostpath);
    }
  }
}

/* Check if we are authorized. */
bool IsAuthorized(pkgCache::PkgFileIterator const I)
{
  std::vector<std::string> authconfs;
   if (authconfs.empty())
   {
      _error->PushToStack();
      auto const netrc = _config->FindFile("Dir::Etc::netrc");
      if (not netrc.empty())
	 authconfs.push_back(netrc);

      auto const netrcparts = _config->FindDir("Dir::Etc::netrcparts");
      if (not netrcparts.empty())
      {
	 for (auto const &netrc : GetListOfFilesInDir(netrcparts, "conf", true, true))
	    authconfs.push_back(netrc);
      }
      _error->RevertToStack();
   }

   // FIXME: Use the full base url
   URI uri(std::string("http://") + I.Site() + "/");
   for (auto &authconf : authconfs)
   {
      maybe_add_auth(uri, authconf);

      if (not uri.User.empty() || not uri.Password.empty())
	 return true;
   }

   return false;
}

#ifdef DEBUG
int main(int argc, char* argv[])
{
  char login[64] = "";
  char password[64] = "";

  if(argc < 2)
    return -1;

  if(0 == parsenetrc (argv[1], login, password, argv[2])) {
    printf("HOST: %s LOGIN: %s PASSWORD: %s\n", argv[1], login, password);
  }
}
#endif