2003-01-10 18:33:35 +00:00
|
|
|
/*
|
|
|
|
* ux_x11.c: fetch local auth data for X forwarding.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <ctype.h>
|
|
|
|
#include <unistd.h>
|
2004-05-31 14:01:52 +00:00
|
|
|
#include <assert.h>
|
2008-11-17 18:38:09 +00:00
|
|
|
#include <stdlib.h>
|
2009-01-05 01:01:58 +00:00
|
|
|
#include <errno.h>
|
2018-10-20 21:42:17 +00:00
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/stat.h>
|
2008-11-17 18:38:09 +00:00
|
|
|
|
2003-01-10 18:33:35 +00:00
|
|
|
#include "putty.h"
|
2004-05-31 14:01:52 +00:00
|
|
|
#include "ssh.h"
|
2008-11-17 18:38:09 +00:00
|
|
|
#include "network.h"
|
2003-01-10 18:33:35 +00:00
|
|
|
|
Post-release destabilisation! Completely remove the struct type
'Config' in putty.h, which stores all PuTTY's settings and includes an
arbitrary length limit on every single one of those settings which is
stored in string form. In place of it is 'Conf', an opaque data type
everywhere outside the new file conf.c, which stores a list of (key,
value) pairs in which every key contains an integer identifying a
configuration setting, and for some of those integers the key also
contains extra parts (so that, for instance, CONF_environmt is a
string-to-string mapping). Everywhere that a Config was previously
used, a Conf is now; everywhere there was a Config structure copy,
conf_copy() is called; every lookup, adjustment, load and save
operation on a Config has been rewritten; and there's a mechanism for
serialising a Conf into a binary blob and back for use with Duplicate
Session.
User-visible effects of this change _should_ be minimal, though I
don't doubt I've introduced one or two bugs here and there which will
eventually be found. The _intended_ visible effects of this change are
that all arbitrary limits on configuration strings and lists (e.g.
limit on number of port forwardings) should now disappear; that list
boxes in the configuration will now be displayed in a sorted order
rather than the arbitrary order in which they were added to the list
(since the underlying data structure is now a sorted tree234 rather
than an ad-hoc comma-separated string); and one more specific change,
which is that local and dynamic port forwardings on the same port
number are now mutually exclusive in the configuration (putting 'D' in
the key rather than the value was a mistake in the first place).
One other reorganisation as a result of this is that I've moved all
the dialog.c standard handlers (dlg_stdeditbox_handler and friends)
out into config.c, because I can't really justify calling them generic
any more. When they took a pointer to an arbitrary structure type and
the offset of a field within that structure, they were independent of
whether that structure was a Config or something completely different,
but now they really do expect to talk to a Conf, which can _only_ be
used for PuTTY configuration, so I've renamed them all things like
conf_editbox_handler and moved them out of the nominally independent
dialog-box management module into the PuTTY-specific config.c.
[originally from svn r9214]
2011-07-14 18:52:21 +00:00
|
|
|
void platform_get_x11_auth(struct X11Display *disp, Conf *conf)
|
2003-01-10 18:33:35 +00:00
|
|
|
{
|
2008-11-17 18:38:09 +00:00
|
|
|
char *xauthfile;
|
|
|
|
int needs_free;
|
2003-01-10 18:33:35 +00:00
|
|
|
|
2008-11-17 18:38:09 +00:00
|
|
|
/*
|
|
|
|
* Find the .Xauthority file.
|
|
|
|
*/
|
|
|
|
needs_free = FALSE;
|
|
|
|
xauthfile = getenv("XAUTHORITY");
|
|
|
|
if (!xauthfile) {
|
|
|
|
xauthfile = getenv("HOME");
|
|
|
|
if (xauthfile) {
|
|
|
|
xauthfile = dupcat(xauthfile, "/.Xauthority", NULL);
|
|
|
|
needs_free = TRUE;
|
|
|
|
}
|
|
|
|
}
|
2003-01-10 18:33:35 +00:00
|
|
|
|
2008-11-17 18:38:09 +00:00
|
|
|
if (xauthfile) {
|
|
|
|
x11_get_auth_from_authfile(disp, xauthfile);
|
|
|
|
if (needs_free)
|
|
|
|
sfree(xauthfile);
|
2003-01-10 18:33:35 +00:00
|
|
|
}
|
|
|
|
}
|
2008-11-17 18:38:09 +00:00
|
|
|
|
|
|
|
const int platform_uses_x11_unix_by_default = TRUE;
|
2018-10-20 21:42:17 +00:00
|
|
|
|
|
|
|
int platform_make_x11_server(Plug *plug, const char *progname, int mindisp,
|
|
|
|
const char *screen_number_suffix,
|
|
|
|
ptrlen authproto, ptrlen authdata,
|
|
|
|
Socket **sockets, Conf *conf)
|
|
|
|
{
|
|
|
|
char *tmpdir;
|
|
|
|
char *authfilename = NULL;
|
|
|
|
strbuf *authfiledata = NULL;
|
|
|
|
char *unix_path = NULL;
|
|
|
|
|
|
|
|
SockAddr *a_tcp = NULL, *a_unix = NULL;
|
|
|
|
|
|
|
|
int authfd;
|
|
|
|
FILE *authfp;
|
|
|
|
|
|
|
|
int displayno;
|
|
|
|
|
|
|
|
authfiledata = strbuf_new();
|
|
|
|
|
|
|
|
int nsockets = 0;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Look for a free TCP port to run our server on.
|
|
|
|
*/
|
|
|
|
for (displayno = mindisp;; displayno++) {
|
|
|
|
const char *err;
|
|
|
|
int tcp_port = displayno + 6000;
|
|
|
|
int addrtype = ADDRTYPE_IPV4;
|
|
|
|
|
|
|
|
sockets[nsockets] = new_listener(
|
|
|
|
NULL, tcp_port, plug, FALSE, conf, addrtype);
|
|
|
|
|
|
|
|
err = sk_socket_error(sockets[nsockets]);
|
|
|
|
if (!err) {
|
|
|
|
char *hostname = get_hostname();
|
|
|
|
if (hostname) {
|
|
|
|
char *canonicalname = NULL;
|
|
|
|
a_tcp = name_lookup(hostname, tcp_port, &canonicalname,
|
|
|
|
conf, addrtype, NULL, "");
|
|
|
|
sfree(canonicalname);
|
|
|
|
}
|
|
|
|
sfree(hostname);
|
|
|
|
nsockets++;
|
|
|
|
break; /* success! */
|
|
|
|
} else {
|
|
|
|
sk_close(sockets[nsockets]);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!strcmp(err, strerror(EADDRINUSE))) /* yuck! */
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (a_tcp) {
|
|
|
|
x11_format_auth_for_authfile(
|
|
|
|
BinarySink_UPCAST(authfiledata),
|
|
|
|
a_tcp, displayno, authproto, authdata);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Try to establish the Unix-domain analogue. That may or may not
|
|
|
|
* work - file permissions in /tmp may prevent it, for example -
|
|
|
|
* but it's worth a try, and we don't consider it a fatal error if
|
|
|
|
* it doesn't work.
|
|
|
|
*/
|
|
|
|
unix_path = dupprintf("/tmp/.X11-unix/X%d", displayno);
|
|
|
|
a_unix = unix_sock_addr(unix_path);
|
|
|
|
|
|
|
|
sockets[nsockets] = new_unix_listener(a_unix, plug);
|
|
|
|
if (!sk_socket_error(sockets[nsockets])) {
|
|
|
|
x11_format_auth_for_authfile(
|
|
|
|
BinarySink_UPCAST(authfiledata),
|
|
|
|
a_unix, displayno, authproto, authdata);
|
|
|
|
nsockets++;
|
|
|
|
} else {
|
|
|
|
sk_close(sockets[nsockets]);
|
|
|
|
sfree(unix_path);
|
|
|
|
unix_path = NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Decide where the authority data will be written.
|
|
|
|
*/
|
|
|
|
|
|
|
|
tmpdir = getenv("TMPDIR");
|
|
|
|
if (!tmpdir || !*tmpdir)
|
|
|
|
tmpdir = "/tmp";
|
|
|
|
|
|
|
|
authfilename = dupcat(tmpdir, "/", progname, "-Xauthority-XXXXXX");
|
|
|
|
|
|
|
|
{
|
|
|
|
int oldumask = umask(077);
|
|
|
|
authfd = mkstemp(authfilename);
|
|
|
|
umask(oldumask);
|
|
|
|
}
|
|
|
|
if (authfd < 0) {
|
|
|
|
while (nsockets-- > 0)
|
|
|
|
sk_close(sockets[nsockets]);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Spawn a subprocess which will try to reliably delete our
|
|
|
|
* auth file when we terminate, in case we die unexpectedly.
|
|
|
|
*/
|
|
|
|
{
|
|
|
|
int cleanup_pipe[2];
|
|
|
|
pid_t pid;
|
|
|
|
|
|
|
|
/* Don't worry if pipe or fork fails; it's not _that_ critical. */
|
|
|
|
if (!pipe(cleanup_pipe)) {
|
|
|
|
if ((pid = fork()) == 0) {
|
|
|
|
int buf[1024];
|
|
|
|
/*
|
|
|
|
* Our parent process holds the writing end of
|
|
|
|
* this pipe, and writes nothing to it. Hence,
|
|
|
|
* we expect read() to return EOF as soon as
|
|
|
|
* that process terminates.
|
|
|
|
*/
|
|
|
|
setpgid(0, 0);
|
|
|
|
close(cleanup_pipe[1]);
|
|
|
|
close(authfd);
|
|
|
|
while (read(cleanup_pipe[0], buf, sizeof(buf)) > 0);
|
|
|
|
unlink(authfilename);
|
|
|
|
if (unix_path)
|
|
|
|
unlink(unix_path);
|
|
|
|
_exit(0);
|
|
|
|
} else if (pid < 0) {
|
|
|
|
close(cleanup_pipe[0]);
|
|
|
|
close(cleanup_pipe[1]);
|
|
|
|
} else {
|
|
|
|
close(cleanup_pipe[0]);
|
|
|
|
cloexec(cleanup_pipe[1]);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
authfp = fdopen(authfd, "wb");
|
|
|
|
fwrite(authfiledata->u, 1, authfiledata->len, authfp);
|
|
|
|
fclose(authfp);
|
|
|
|
|
|
|
|
{
|
|
|
|
char *display = dupprintf(":%d%s", displayno, screen_number_suffix);
|
|
|
|
conf_set_str_str(conf, CONF_environmt, "DISPLAY", display);
|
|
|
|
sfree(display);
|
|
|
|
}
|
|
|
|
conf_set_str_str(conf, CONF_environmt, "XAUTHORITY", authfilename);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* FIXME: return at least the DISPLAY and XAUTHORITY env settings,
|
|
|
|
* and perhaps also the display number
|
|
|
|
*/
|
|
|
|
|
|
|
|
out:
|
|
|
|
if (a_tcp)
|
|
|
|
sk_addr_free(a_tcp);
|
|
|
|
if (a_unix)
|
|
|
|
sk_addr_free(a_unix);
|
|
|
|
sfree(authfilename);
|
|
|
|
strbuf_free(authfiledata);
|
|
|
|
sfree(unix_path);
|
|
|
|
return nsockets;
|
|
|
|
}
|