1 | /********************************************************************\ |
---|
2 | * BitlBee -- An IRC to other IM-networks gateway * |
---|
3 | * * |
---|
4 | * Copyright 2002-2006 Wilmer van der Gaast and others * |
---|
5 | \********************************************************************/ |
---|
6 | |
---|
7 | /* Storage backend that uses an XMLish format for all data. */ |
---|
8 | |
---|
9 | /* |
---|
10 | This program is free software; you can redistribute it and/or modify |
---|
11 | it under the terms of the GNU General Public License as published by |
---|
12 | the Free Software Foundation; either version 2 of the License, or |
---|
13 | (at your option) any later version. |
---|
14 | |
---|
15 | This program is distributed in the hope that it will be useful, |
---|
16 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
---|
17 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
---|
18 | GNU General Public License for more details. |
---|
19 | |
---|
20 | You should have received a copy of the GNU General Public License with |
---|
21 | the Debian GNU/Linux distribution in /usr/share/common-licenses/GPL; |
---|
22 | if not, write to the Free Software Foundation, Inc., 59 Temple Place, |
---|
23 | Suite 330, Boston, MA 02111-1307 USA |
---|
24 | */ |
---|
25 | |
---|
26 | #define BITLBEE_CORE |
---|
27 | #include "bitlbee.h" |
---|
28 | #include "base64.h" |
---|
29 | #include "rc4.h" |
---|
30 | #include "md5.h" |
---|
31 | |
---|
32 | typedef enum |
---|
33 | { |
---|
34 | XML_PASS_CHECK_ONLY = -1, |
---|
35 | XML_PASS_UNKNOWN = 0, |
---|
36 | XML_PASS_WRONG, |
---|
37 | XML_PASS_OK |
---|
38 | } xml_pass_st; |
---|
39 | |
---|
40 | /* To make it easier later when extending the format: */ |
---|
41 | #define XML_FORMAT_VERSION 1 |
---|
42 | |
---|
43 | struct xml_parsedata |
---|
44 | { |
---|
45 | irc_t *irc; |
---|
46 | char *current_setting; |
---|
47 | account_t *current_account; |
---|
48 | char *given_nick; |
---|
49 | char *given_pass; |
---|
50 | xml_pass_st pass_st; |
---|
51 | }; |
---|
52 | |
---|
53 | static char *xml_attr( const gchar **attr_names, const gchar **attr_values, const gchar *key ) |
---|
54 | { |
---|
55 | int i; |
---|
56 | |
---|
57 | for( i = 0; attr_names[i]; i ++ ) |
---|
58 | if( g_strcasecmp( attr_names[i], key ) == 0 ) |
---|
59 | return (char*) attr_values[i]; |
---|
60 | |
---|
61 | return NULL; |
---|
62 | } |
---|
63 | |
---|
64 | static void xml_destroy_xd( gpointer data ) |
---|
65 | { |
---|
66 | struct xml_parsedata *xd = data; |
---|
67 | |
---|
68 | g_free( xd->given_nick ); |
---|
69 | g_free( xd->given_pass ); |
---|
70 | g_free( xd ); |
---|
71 | } |
---|
72 | |
---|
73 | static void xml_start_element( GMarkupParseContext *ctx, const gchar *element_name, const gchar **attr_names, const gchar **attr_values, gpointer data, GError **error ) |
---|
74 | { |
---|
75 | struct xml_parsedata *xd = data; |
---|
76 | irc_t *irc = xd->irc; |
---|
77 | |
---|
78 | if( g_strcasecmp( element_name, "user" ) == 0 ) |
---|
79 | { |
---|
80 | char *nick = xml_attr( attr_names, attr_values, "nick" ); |
---|
81 | char *pass = xml_attr( attr_names, attr_values, "password" ); |
---|
82 | md5_byte_t *pass_dec = NULL; |
---|
83 | |
---|
84 | if( !nick || !pass ) |
---|
85 | { |
---|
86 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
87 | "Missing attributes for %s element", element_name ); |
---|
88 | } |
---|
89 | else if( base64_decode( pass, &pass_dec ) != 21 ) |
---|
90 | { |
---|
91 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
92 | "Error while decoding password attribute" ); |
---|
93 | } |
---|
94 | else |
---|
95 | { |
---|
96 | md5_byte_t pass_md5[16]; |
---|
97 | md5_state_t md5_state; |
---|
98 | int i; |
---|
99 | |
---|
100 | md5_init( &md5_state ); |
---|
101 | md5_append( &md5_state, (md5_byte_t*) xd->given_pass, strlen( xd->given_pass ) ); |
---|
102 | md5_append( &md5_state, (md5_byte_t*) pass_dec + 16, 5 ); /* Hmmm, salt! */ |
---|
103 | md5_finish( &md5_state, pass_md5 ); |
---|
104 | |
---|
105 | for( i = 0; i < 16; i ++ ) |
---|
106 | { |
---|
107 | if( pass_dec[i] != pass_md5[i] ) |
---|
108 | { |
---|
109 | xd->pass_st = XML_PASS_WRONG; |
---|
110 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
111 | "Password mismatch" ); |
---|
112 | break; |
---|
113 | } |
---|
114 | } |
---|
115 | |
---|
116 | /* If we reached the end of the loop, it was a match! */ |
---|
117 | if( i == 16 ) |
---|
118 | { |
---|
119 | if( xd->pass_st != XML_PASS_CHECK_ONLY ) |
---|
120 | xd->pass_st = XML_PASS_OK; |
---|
121 | } |
---|
122 | } |
---|
123 | |
---|
124 | g_free( pass_dec ); |
---|
125 | } |
---|
126 | else if( xd->pass_st < XML_PASS_OK ) |
---|
127 | { |
---|
128 | /* Let's not parse anything else if we only have to check |
---|
129 | the password. */ |
---|
130 | } |
---|
131 | else if( g_strcasecmp( element_name, "account" ) == 0 ) |
---|
132 | { |
---|
133 | char *protocol, *handle, *server, *password = NULL, *autoconnect; |
---|
134 | char *pass_b64 = NULL, *pass_rc4 = NULL; |
---|
135 | int pass_len; |
---|
136 | struct prpl *prpl = NULL; |
---|
137 | |
---|
138 | handle = xml_attr( attr_names, attr_values, "handle" ); |
---|
139 | pass_b64 = xml_attr( attr_names, attr_values, "password" ); |
---|
140 | server = xml_attr( attr_names, attr_values, "server" ); |
---|
141 | autoconnect = xml_attr( attr_names, attr_values, "autoconnect" ); |
---|
142 | |
---|
143 | protocol = xml_attr( attr_names, attr_values, "protocol" ); |
---|
144 | if( protocol ) |
---|
145 | prpl = find_protocol( protocol ); |
---|
146 | |
---|
147 | if( !handle || !pass_b64 || !protocol ) |
---|
148 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
149 | "Missing attributes for %s element", element_name ); |
---|
150 | else if( !prpl ) |
---|
151 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
152 | "Unknown protocol: %s", protocol ); |
---|
153 | else if( ( pass_len = base64_decode( pass_b64, (unsigned char**) &pass_rc4 ) ) && |
---|
154 | rc4_decode( (unsigned char*) pass_rc4, pass_len, |
---|
155 | (unsigned char**) &password, xd->given_pass ) ) |
---|
156 | { |
---|
157 | xd->current_account = account_add( irc, prpl, handle, password ); |
---|
158 | if( server ) |
---|
159 | xd->current_account->server = g_strdup( server ); |
---|
160 | if( autoconnect ) |
---|
161 | /* Return value doesn't matter, since account_add() already sets |
---|
162 | a default! */ |
---|
163 | sscanf( autoconnect, "%d", &xd->current_account->auto_connect ); |
---|
164 | } |
---|
165 | else |
---|
166 | { |
---|
167 | /* Actually the _decode functions don't even return error codes, |
---|
168 | but maybe they will later... */ |
---|
169 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
170 | "Error while decrypting account password" ); |
---|
171 | } |
---|
172 | |
---|
173 | g_free( pass_rc4 ); |
---|
174 | g_free( password ); |
---|
175 | } |
---|
176 | else if( g_strcasecmp( element_name, "setting" ) == 0 ) |
---|
177 | { |
---|
178 | if( xd->current_account == NULL ) |
---|
179 | { |
---|
180 | char *setting; |
---|
181 | |
---|
182 | if( xd->current_setting ) |
---|
183 | { |
---|
184 | g_free( xd->current_setting ); |
---|
185 | xd->current_setting = NULL; |
---|
186 | } |
---|
187 | |
---|
188 | if( ( setting = xml_attr( attr_names, attr_values, "name" ) ) ) |
---|
189 | xd->current_setting = g_strdup( setting ); |
---|
190 | else |
---|
191 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
192 | "Missing attributes for %s element", element_name ); |
---|
193 | } |
---|
194 | } |
---|
195 | else if( g_strcasecmp( element_name, "buddy" ) == 0 ) |
---|
196 | { |
---|
197 | char *handle, *nick; |
---|
198 | |
---|
199 | handle = xml_attr( attr_names, attr_values, "handle" ); |
---|
200 | nick = xml_attr( attr_names, attr_values, "nick" ); |
---|
201 | |
---|
202 | if( xd->current_account && handle && nick ) |
---|
203 | { |
---|
204 | nick_set( irc, handle, xd->current_account->prpl, nick ); |
---|
205 | } |
---|
206 | else |
---|
207 | { |
---|
208 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_INVALID_CONTENT, |
---|
209 | "Missing attributes for %s element", element_name ); |
---|
210 | } |
---|
211 | } |
---|
212 | else |
---|
213 | { |
---|
214 | g_set_error( error, G_MARKUP_ERROR, G_MARKUP_ERROR_UNKNOWN_ELEMENT, |
---|
215 | "Unkown element: %s", element_name ); |
---|
216 | } |
---|
217 | } |
---|
218 | |
---|
219 | static void xml_end_element( GMarkupParseContext *ctx, const gchar *element_name, gpointer data, GError **error ) |
---|
220 | { |
---|
221 | struct xml_parsedata *xd = data; |
---|
222 | |
---|
223 | if( g_strcasecmp( element_name, "setting" ) == 0 && xd->current_setting ) |
---|
224 | { |
---|
225 | g_free( xd->current_setting ); |
---|
226 | xd->current_setting = NULL; |
---|
227 | } |
---|
228 | else if( g_strcasecmp( element_name, "account" ) == 0 ) |
---|
229 | { |
---|
230 | xd->current_account = NULL; |
---|
231 | } |
---|
232 | } |
---|
233 | |
---|
234 | static void xml_text( GMarkupParseContext *ctx, const gchar *text, gsize text_len, gpointer data, GError **error ) |
---|
235 | { |
---|
236 | struct xml_parsedata *xd = data; |
---|
237 | irc_t *irc = xd->irc; |
---|
238 | |
---|
239 | if( xd->pass_st < XML_PASS_OK ) |
---|
240 | { |
---|
241 | /* Let's not parse anything else if we only have to check |
---|
242 | the password, or if we didn't get the chance to check it |
---|
243 | yet. */ |
---|
244 | } |
---|
245 | else if( g_strcasecmp( g_markup_parse_context_get_element( ctx ), "setting" ) == 0 && |
---|
246 | xd->current_setting && xd->current_account == NULL ) |
---|
247 | { |
---|
248 | set_setstr( irc, xd->current_setting, (char*) text ); |
---|
249 | g_free( xd->current_setting ); |
---|
250 | xd->current_setting = NULL; |
---|
251 | } |
---|
252 | } |
---|
253 | |
---|
254 | GMarkupParser xml_parser = |
---|
255 | { |
---|
256 | xml_start_element, |
---|
257 | xml_end_element, |
---|
258 | xml_text, |
---|
259 | NULL, |
---|
260 | NULL |
---|
261 | }; |
---|
262 | |
---|
263 | static void xml_init( void ) |
---|
264 | { |
---|
265 | if( access( global.conf->configdir, F_OK ) != 0 ) |
---|
266 | log_message( LOGLVL_WARNING, "The configuration directory %s does not exist. Configuration won't be saved.", CONFIG ); |
---|
267 | else if( access( global.conf->configdir, R_OK ) != 0 || access( global.conf->configdir, W_OK ) != 0 ) |
---|
268 | log_message( LOGLVL_WARNING, "Permission problem: Can't read/write from/to %s.", global.conf->configdir ); |
---|
269 | } |
---|
270 | |
---|
271 | static storage_status_t xml_load_real( const char *my_nick, const char *password, irc_t *irc, xml_pass_st action ) |
---|
272 | { |
---|
273 | GMarkupParseContext *ctx; |
---|
274 | struct xml_parsedata *xd; |
---|
275 | char *fn, buf[512]; |
---|
276 | GError *gerr = NULL; |
---|
277 | int fd, st; |
---|
278 | |
---|
279 | if( irc && irc->status & USTATUS_IDENTIFIED ) |
---|
280 | return( 1 ); |
---|
281 | |
---|
282 | xd = g_new0( struct xml_parsedata, 1 ); |
---|
283 | xd->irc = irc; |
---|
284 | xd->given_nick = g_strdup( my_nick ); |
---|
285 | xd->given_pass = g_strdup( password ); |
---|
286 | xd->pass_st = action; |
---|
287 | nick_lc( xd->given_nick ); |
---|
288 | |
---|
289 | fn = g_strdup_printf( "%s%s%s", global.conf->configdir, xd->given_nick, ".xml" ); |
---|
290 | if( ( fd = open( fn, O_RDONLY ) ) < 0 ) |
---|
291 | { |
---|
292 | xml_destroy_xd( xd ); |
---|
293 | g_free( fn ); |
---|
294 | return STORAGE_NO_SUCH_USER; |
---|
295 | } |
---|
296 | g_free( fn ); |
---|
297 | |
---|
298 | ctx = g_markup_parse_context_new( &xml_parser, 0, xd, xml_destroy_xd ); |
---|
299 | |
---|
300 | while( ( st = read( fd, buf, sizeof( buf ) ) ) > 0 ) |
---|
301 | { |
---|
302 | if( !g_markup_parse_context_parse( ctx, buf, st, &gerr ) || gerr ) |
---|
303 | { |
---|
304 | xml_pass_st pass_st = xd->pass_st; |
---|
305 | |
---|
306 | g_markup_parse_context_free( ctx ); |
---|
307 | close( fd ); |
---|
308 | |
---|
309 | if( pass_st == XML_PASS_WRONG ) |
---|
310 | { |
---|
311 | g_clear_error( &gerr ); |
---|
312 | return STORAGE_INVALID_PASSWORD; |
---|
313 | } |
---|
314 | else |
---|
315 | { |
---|
316 | if( gerr && irc ) |
---|
317 | irc_usermsg( irc, "Error from XML-parser: %s", gerr->message ); |
---|
318 | |
---|
319 | g_clear_error( &gerr ); |
---|
320 | return STORAGE_OTHER_ERROR; |
---|
321 | } |
---|
322 | } |
---|
323 | } |
---|
324 | /* Just to be sure... */ |
---|
325 | g_clear_error( &gerr ); |
---|
326 | |
---|
327 | g_markup_parse_context_free( ctx ); |
---|
328 | close( fd ); |
---|
329 | |
---|
330 | if( action == XML_PASS_CHECK_ONLY ) |
---|
331 | return STORAGE_OK; |
---|
332 | |
---|
333 | irc->status |= USTATUS_IDENTIFIED; |
---|
334 | |
---|
335 | return STORAGE_OK; |
---|
336 | } |
---|
337 | |
---|
338 | static storage_status_t xml_load( const char *my_nick, const char *password, irc_t *irc ) |
---|
339 | { |
---|
340 | return xml_load_real( my_nick, password, irc, XML_PASS_UNKNOWN ); |
---|
341 | } |
---|
342 | |
---|
343 | static storage_status_t xml_check_pass( const char *my_nick, const char *password ) |
---|
344 | { |
---|
345 | /* This is a little bit risky because we have to pass NULL for the |
---|
346 | irc_t argument. This *should* be fine, if I didn't miss anything... */ |
---|
347 | return xml_load_real( my_nick, password, NULL, XML_PASS_CHECK_ONLY ); |
---|
348 | } |
---|
349 | |
---|
350 | static int xml_printf( int fd, char *fmt, ... ) |
---|
351 | { |
---|
352 | va_list params; |
---|
353 | char *out; |
---|
354 | int len; |
---|
355 | |
---|
356 | va_start( params, fmt ); |
---|
357 | out = g_markup_vprintf_escaped( fmt, params ); |
---|
358 | va_end( params ); |
---|
359 | |
---|
360 | len = strlen( out ); |
---|
361 | len -= write( fd, out, len ); |
---|
362 | g_free( out ); |
---|
363 | |
---|
364 | return len == 0; |
---|
365 | } |
---|
366 | |
---|
367 | static storage_status_t xml_save( irc_t *irc, int overwrite ) |
---|
368 | { |
---|
369 | char path[512], *path2, *pass_buf = NULL; |
---|
370 | set_t *set; |
---|
371 | nick_t *nick; |
---|
372 | account_t *acc; |
---|
373 | int fd; |
---|
374 | md5_byte_t pass_md5[21]; |
---|
375 | md5_state_t md5_state; |
---|
376 | |
---|
377 | if( irc->password == NULL ) |
---|
378 | { |
---|
379 | irc_usermsg( irc, "Please register yourself if you want to save your settings." ); |
---|
380 | return STORAGE_OTHER_ERROR; |
---|
381 | } |
---|
382 | |
---|
383 | g_snprintf( path, sizeof( path ) - 2, "%s%s%s", global.conf->configdir, irc->nick, ".xml" ); |
---|
384 | |
---|
385 | if( !overwrite && access( path, F_OK ) != -1 ) |
---|
386 | return STORAGE_ALREADY_EXISTS; |
---|
387 | |
---|
388 | strcat( path, "~" ); |
---|
389 | if( ( fd = open( path, O_WRONLY | O_CREAT, 0600 ) ) < 0 ) |
---|
390 | { |
---|
391 | irc_usermsg( irc, "Error while opening configuration file." ); |
---|
392 | return STORAGE_OTHER_ERROR; |
---|
393 | } |
---|
394 | |
---|
395 | /* Generate a salted md5sum of the password. Use 5 bytes for the salt |
---|
396 | (to prevent dictionary lookups of passwords) to end up with a 21- |
---|
397 | byte password hash, more convenient for base64 encoding. */ |
---|
398 | random_bytes( pass_md5 + 16, 5 ); |
---|
399 | md5_init( &md5_state ); |
---|
400 | md5_append( &md5_state, (md5_byte_t*) irc->password, strlen( irc->password ) ); |
---|
401 | md5_append( &md5_state, pass_md5 + 16, 5 ); /* Add the salt. */ |
---|
402 | md5_finish( &md5_state, pass_md5 ); |
---|
403 | /* Save the hash in base64-encoded form. */ |
---|
404 | pass_buf = base64_encode( (char*) pass_md5, 21 ); |
---|
405 | |
---|
406 | if( !xml_printf( fd, "<user nick=\"%s\" password=\"%s\" version=\"%d\">\n", irc->nick, pass_buf, XML_FORMAT_VERSION ) ) |
---|
407 | goto write_error; |
---|
408 | |
---|
409 | g_free( pass_buf ); |
---|
410 | |
---|
411 | for( set = irc->set; set; set = set->next ) |
---|
412 | if( set->value && set->def ) |
---|
413 | if( !xml_printf( fd, "\t<setting name=\"%s\">%s</setting>\n", set->key, set->value ) ) |
---|
414 | goto write_error; |
---|
415 | |
---|
416 | for( acc = irc->accounts; acc; acc = acc->next ) |
---|
417 | { |
---|
418 | char *pass_rc4, *pass_b64; |
---|
419 | int pass_len; |
---|
420 | |
---|
421 | pass_len = rc4_encode( (unsigned char*) acc->pass, strlen( acc->pass ), (unsigned char**) &pass_rc4, irc->password ); |
---|
422 | pass_b64 = base64_encode( pass_rc4, pass_len ); |
---|
423 | |
---|
424 | if( !xml_printf( fd, "\t<account protocol=\"%s\" handle=\"%s\" password=\"%s\" autoconnect=\"%d\"", acc->prpl->name, acc->user, pass_b64, acc->auto_connect ) ) |
---|
425 | { |
---|
426 | g_free( pass_rc4 ); |
---|
427 | g_free( pass_b64 ); |
---|
428 | goto write_error; |
---|
429 | } |
---|
430 | g_free( pass_rc4 ); |
---|
431 | g_free( pass_b64 ); |
---|
432 | |
---|
433 | if( acc->server && acc->server[0] && !xml_printf( fd, " server=\"%s\"", acc->server ) ) |
---|
434 | goto write_error; |
---|
435 | if( !xml_printf( fd, ">\n" ) ) |
---|
436 | goto write_error; |
---|
437 | |
---|
438 | for( nick = irc->nicks; nick; nick = nick->next ) |
---|
439 | if( nick->proto == acc->prpl ) |
---|
440 | if( !xml_printf( fd, "\t\t<buddy handle=\"%s\" nick=\"%s\" />\n", nick->handle, nick->nick ) ) |
---|
441 | goto write_error; |
---|
442 | |
---|
443 | if( !xml_printf( fd, "\t</account>\n" ) ) |
---|
444 | goto write_error; |
---|
445 | } |
---|
446 | |
---|
447 | if( !xml_printf( fd, "</user>\n" ) ) |
---|
448 | goto write_error; |
---|
449 | |
---|
450 | close( fd ); |
---|
451 | |
---|
452 | path2 = g_strndup( path, strlen( path ) - 1 ); |
---|
453 | if( rename( path, path2 ) != 0 ) |
---|
454 | { |
---|
455 | irc_usermsg( irc, "Error while renaming temporary configuration file." ); |
---|
456 | |
---|
457 | g_free( path2 ); |
---|
458 | unlink( path ); |
---|
459 | |
---|
460 | return STORAGE_OTHER_ERROR; |
---|
461 | } |
---|
462 | |
---|
463 | g_free( path2 ); |
---|
464 | |
---|
465 | return STORAGE_OK; |
---|
466 | |
---|
467 | write_error: |
---|
468 | g_free( pass_buf ); |
---|
469 | |
---|
470 | irc_usermsg( irc, "Write error. Disk full?" ); |
---|
471 | close( fd ); |
---|
472 | |
---|
473 | return STORAGE_OTHER_ERROR; |
---|
474 | } |
---|
475 | |
---|
476 | static storage_status_t xml_remove( const char *nick, const char *password ) |
---|
477 | { |
---|
478 | char s[512]; |
---|
479 | storage_status_t status; |
---|
480 | |
---|
481 | status = xml_check_pass( nick, password ); |
---|
482 | if( status != STORAGE_OK ) |
---|
483 | return status; |
---|
484 | |
---|
485 | g_snprintf( s, 511, "%s%s%s", global.conf->configdir, nick, ".xml" ); |
---|
486 | if( unlink( s ) == -1 ) |
---|
487 | return STORAGE_OTHER_ERROR; |
---|
488 | |
---|
489 | return STORAGE_OK; |
---|
490 | } |
---|
491 | |
---|
492 | storage_t storage_xml = { |
---|
493 | .name = "xml", |
---|
494 | .init = xml_init, |
---|
495 | .check_pass = xml_check_pass, |
---|
496 | .remove = xml_remove, |
---|
497 | .load = xml_load, |
---|
498 | .save = xml_save |
---|
499 | }; |
---|