2014-04-10 22:20:58 +04:00
// Copyright 2014 The Gogs Authors. All rights reserved.
// Use of this source code is governed by a MIT-style
// license that can be found in the LICENSE file.
2014-05-02 05:21:46 +04:00
package cmd
2014-04-10 22:20:58 +04:00
import (
2015-10-26 16:16:24 +03:00
"crypto/tls"
2014-04-10 22:20:58 +04:00
"fmt"
"os"
"os/exec"
2014-06-29 18:31:46 +04:00
"path/filepath"
2014-04-10 22:20:58 +04:00
"strings"
2014-08-10 02:40:10 +04:00
"time"
2014-04-10 22:20:58 +04:00
2014-07-26 08:24:27 +04:00
"github.com/Unknwon/com"
2014-08-10 02:40:10 +04:00
"github.com/codegangsta/cli"
2016-02-21 02:13:12 +03:00
gouuid "github.com/satori/go.uuid"
2014-07-26 08:24:27 +04:00
2014-04-10 22:20:58 +04:00
"github.com/gogits/gogs/models"
2015-12-15 01:06:54 +03:00
"github.com/gogits/gogs/modules/base"
2015-07-25 16:32:04 +03:00
"github.com/gogits/gogs/modules/httplib"
2014-06-20 09:14:54 +04:00
"github.com/gogits/gogs/modules/log"
2014-05-26 04:11:25 +04:00
"github.com/gogits/gogs/modules/setting"
2014-04-10 22:20:58 +04:00
)
2015-02-16 17:38:01 +03:00
const (
2015-03-01 06:24:53 +03:00
_ACCESS_DENIED_MESSAGE = "Repository does not exist or you do not have access"
2015-02-16 17:38:01 +03:00
)
2014-04-10 22:20:58 +04:00
var CmdServ = cli . Command {
2014-05-05 08:55:17 +04:00
Name : "serv" ,
Usage : "This command should only be called by SSH shell" ,
Description : ` Serv provide access auth for repositories ` ,
Action : runServ ,
2015-02-05 13:12:37 +03:00
Flags : [ ] cli . Flag {
2015-11-16 01:07:44 +03:00
stringFlag ( "config, c" , "custom/conf/app.ini" , "Custom configuration file path" ) ,
2015-02-05 13:12:37 +03:00
} ,
2014-04-10 22:20:58 +04:00
}
2014-05-22 05:37:13 +04:00
func setup ( logPath string ) {
2015-09-17 06:08:46 +03:00
setting . NewContext ( )
2014-06-29 18:31:46 +04:00
log . NewGitLogger ( filepath . Join ( setting . LogRootPath , logPath ) )
2015-02-07 18:46:57 +03:00
2015-09-17 06:08:46 +03:00
models . LoadConfigs ( )
2014-05-22 05:37:13 +04:00
2015-09-17 06:08:46 +03:00
if setting . UseSQLite3 || setting . UseTiDB {
2014-06-20 09:14:54 +04:00
workDir , _ := setting . WorkDir ( )
2014-05-26 04:11:25 +04:00
os . Chdir ( workDir )
2014-05-22 05:37:13 +04:00
}
models . SetEngine ( )
}
2014-04-10 22:20:58 +04:00
func parseCmd ( cmd string ) ( string , string ) {
ss := strings . SplitN ( cmd , " " , 2 )
if len ( ss ) != 2 {
return "" , ""
}
2015-02-16 17:38:01 +03:00
return ss [ 0 ] , strings . Replace ( ss [ 1 ] , "'/" , "'" , 1 )
2014-04-10 22:20:58 +04:00
}
2014-05-22 05:37:13 +04:00
var (
2015-11-24 06:32:07 +03:00
allowedCommands = map [ string ] models . AccessMode {
2015-02-16 17:38:01 +03:00
"git-upload-pack" : models . ACCESS_MODE_READ ,
"git-upload-archive" : models . ACCESS_MODE_READ ,
"git-receive-pack" : models . ACCESS_MODE_WRITE ,
2014-05-22 05:37:13 +04:00
}
)
2015-08-06 17:48:11 +03:00
func fail ( userMessage , logMessage string , args ... interface { } ) {
fmt . Fprintln ( os . Stderr , "Gogs:" , userMessage )
2015-11-08 22:31:49 +03:00
if len ( logMessage ) > 0 {
2015-11-24 06:33:24 +03:00
if ! setting . ProdMode {
2015-11-30 18:00:52 +03:00
fmt . Fprintf ( os . Stderr , logMessage + "\n" , args ... )
2015-11-24 06:33:24 +03:00
}
2015-11-08 22:31:49 +03:00
log . GitLogger . Fatal ( 3 , logMessage , args ... )
return
}
log . GitLogger . Close ( )
os . Exit ( 1 )
2015-08-06 17:48:11 +03:00
}
2015-12-15 01:06:54 +03:00
func handleUpdateTask ( uuid string , user , repoUser * models . User , reponame string , isWiki bool ) {
2015-11-05 05:57:10 +03:00
task , err := models . GetUpdateTaskByUUID ( uuid )
if err != nil {
if models . IsErrUpdateTaskNotExist ( err ) {
log . GitLogger . Trace ( "No update task is presented: %s" , uuid )
return
}
log . GitLogger . Fatal ( 2 , "GetUpdateTaskByUUID: %v" , err )
2015-12-01 04:45:55 +03:00
} else if err = models . DeleteUpdateTaskByUUID ( uuid ) ; err != nil {
log . GitLogger . Fatal ( 2 , "DeleteUpdateTaskByUUID: %v" , err )
2015-11-05 05:57:10 +03:00
}
2015-12-01 04:45:55 +03:00
if isWiki {
return
2015-11-05 05:57:10 +03:00
}
2016-02-18 06:47:06 +03:00
if err = models . PushUpdate ( models . PushUpdateOptions {
RefName : task . RefName ,
OldCommitID : task . OldCommitID ,
NewCommitID : task . NewCommitID ,
PusherID : user . Id ,
PusherName : user . Name ,
RepoUserName : repoUser . Name ,
RepoName : reponame ,
} ) ; err != nil {
2015-12-01 04:45:55 +03:00
log . GitLogger . Error ( 2 , "Update: %v" , err )
2015-11-05 05:57:10 +03:00
}
// Ask for running deliver hook and test pull request tasks.
2015-12-17 10:28:47 +03:00
reqURL := setting . LocalURL + repoUser . Name + "/" + reponame + "/tasks/trigger?branch=" +
2015-12-15 01:06:54 +03:00
strings . TrimPrefix ( task . RefName , "refs/heads/" ) + "&secret=" + base . EncodeMD5 ( repoUser . Salt )
2015-11-05 05:57:10 +03:00
log . GitLogger . Trace ( "Trigger task: %s" , reqURL )
resp , err := httplib . Head ( reqURL ) . SetTLSClientConfig ( & tls . Config {
InsecureSkipVerify : true ,
} ) . Response ( )
if err == nil {
resp . Body . Close ( )
if resp . StatusCode / 100 != 2 {
log . GitLogger . Error ( 2 , "Fail to trigger task: not 2xx response code" )
}
} else {
log . GitLogger . Error ( 2 , "Fail to trigger task: %v" , err )
}
}
2016-05-12 21:32:28 +03:00
func runServ ( c * cli . Context ) error {
2015-02-13 08:58:46 +03:00
if c . IsSet ( "config" ) {
setting . CustomConf = c . String ( "config" )
2015-02-05 13:12:37 +03:00
}
2016-02-22 05:55:59 +03:00
2014-06-20 09:14:54 +04:00
setup ( "serv.log" )
2014-04-10 22:20:58 +04:00
2016-02-28 04:48:39 +03:00
if setting . SSH . Disabled {
2016-02-22 05:55:59 +03:00
println ( "Gogs: SSH has been disabled" )
2016-05-12 21:32:28 +03:00
return nil
2016-02-22 05:55:59 +03:00
}
2015-02-13 08:58:46 +03:00
if len ( c . Args ( ) ) < 1 {
2015-06-18 14:01:05 +03:00
fail ( "Not enough arguments" , "Not enough arguments" )
2015-02-09 13:32:42 +03:00
}
2015-02-16 17:38:01 +03:00
2014-04-10 22:20:58 +04:00
cmd := os . Getenv ( "SSH_ORIGINAL_COMMAND" )
2015-08-05 06:14:17 +03:00
if len ( cmd ) == 0 {
println ( "Hi there, You've successfully authenticated, but Gogs does not provide shell access." )
println ( "If this is unexpected, please log in with password and setup Gogs under another user." )
2016-05-12 21:32:28 +03:00
return nil
2014-04-10 22:20:58 +04:00
}
verb , args := parseCmd ( cmd )
2015-11-09 19:39:03 +03:00
repoPath := strings . ToLower ( strings . Trim ( args , "'" ) )
2014-04-10 22:20:58 +04:00
rr := strings . SplitN ( repoPath , "/" , 2 )
if len ( rr ) != 2 {
2015-06-18 14:01:05 +03:00
fail ( "Invalid repository path" , "Invalid repository path: %v" , args )
2014-04-10 22:20:58 +04:00
}
2015-12-01 04:45:55 +03:00
username := strings . ToLower ( rr [ 0 ] )
reponame := strings . ToLower ( strings . TrimSuffix ( rr [ 1 ] , ".git" ) )
isWiki := false
if strings . HasSuffix ( reponame , ".wiki" ) {
isWiki = true
reponame = reponame [ : len ( reponame ) - 5 ]
}
2014-04-10 22:20:58 +04:00
2015-12-01 04:45:55 +03:00
repoUser , err := models . GetUserByName ( username )
2014-04-10 22:20:58 +04:00
if err != nil {
2015-08-05 06:14:17 +03:00
if models . IsErrUserNotExist ( err ) {
2015-12-01 04:45:55 +03:00
fail ( "Repository owner does not exist" , "Unregistered owner: %s" , username )
2014-05-22 05:37:13 +04:00
}
2015-12-15 01:06:54 +03:00
fail ( "Internal error" , "Failed to get repository owner (%s): %v" , username , err )
2014-04-10 22:20:58 +04:00
}
2015-12-01 04:45:55 +03:00
repo , err := models . GetRepositoryByName ( repoUser . Id , reponame )
2015-02-05 16:29:08 +03:00
if err != nil {
2015-03-16 11:04:27 +03:00
if models . IsErrRepoNotExist ( err ) {
2015-12-01 04:45:55 +03:00
fail ( _ACCESS_DENIED_MESSAGE , "Repository does not exist: %s/%s" , repoUser . Name , reponame )
2015-02-05 16:29:08 +03:00
}
2015-06-18 14:01:05 +03:00
fail ( "Internal error" , "Failed to get repository: %v" , err )
2015-02-05 16:29:08 +03:00
}
2015-11-24 06:32:07 +03:00
requestedMode , has := allowedCommands [ verb ]
2015-02-16 17:38:01 +03:00
if ! has {
fail ( "Unknown git command" , "Unknown git command %s" , verb )
}
2014-04-10 22:20:58 +04:00
2015-11-08 22:31:49 +03:00
// Prohibit push to mirror repositories.
if requestedMode > models . ACCESS_MODE_READ && repo . IsMirror {
fail ( "mirror repository is read-only" , "" )
}
2015-08-05 06:14:17 +03:00
// Allow anonymous clone for public repositories.
var (
keyID int64
user * models . User
)
if requestedMode == models . ACCESS_MODE_WRITE || repo . IsPrivate {
keys := strings . Split ( c . Args ( ) [ 0 ] , "-" )
if len ( keys ) != 2 {
2015-11-09 00:59:56 +03:00
fail ( "Key ID format error" , "Invalid key argument: %s" , c . Args ( ) [ 0 ] )
2015-08-05 06:14:17 +03:00
}
2015-08-06 17:48:11 +03:00
key , err := models . GetPublicKeyByID ( com . StrTo ( keys [ 1 ] ) . MustInt64 ( ) )
2015-08-05 06:14:17 +03:00
if err != nil {
2015-11-09 00:59:56 +03:00
fail ( "Invalid key ID" , "Invalid key ID[%s]: %v" , c . Args ( ) [ 0 ] , err )
2015-08-05 06:14:17 +03:00
}
2015-08-06 17:48:11 +03:00
keyID = key . ID
2015-08-05 06:14:17 +03:00
2015-08-06 17:48:11 +03:00
// Check deploy key or user key.
if key . Type == models . KEY_TYPE_DEPLOY {
if key . Mode < requestedMode {
fail ( "Key permission denied" , "Cannot push with deployment key: %d" , key . ID )
}
// Check if this deploy key belongs to current repository.
2015-08-08 17:43:14 +03:00
if ! models . HasDeployKey ( key . ID , repo . ID ) {
2015-12-31 05:29:30 +03:00
fail ( "Key access denied" , "Deploy key access denied: [key_id: %d, repo_id: %d]" , key . ID , repo . ID )
2015-08-06 17:48:11 +03:00
}
2015-08-05 06:14:17 +03:00
2015-08-06 17:48:11 +03:00
// Update deploy key activity.
2015-08-08 17:43:14 +03:00
deployKey , err := models . GetDeployKeyByRepo ( key . ID , repo . ID )
2015-08-06 17:48:11 +03:00
if err != nil {
fail ( "Internal error" , "GetDeployKey: %v" , err )
}
deployKey . Updated = time . Now ( )
if err = models . UpdateDeployKey ( deployKey ) ; err != nil {
fail ( "Internal error" , "UpdateDeployKey: %v" , err )
}
} else {
2015-11-05 05:57:10 +03:00
user , err = models . GetUserByKeyID ( key . ID )
2015-08-06 17:48:11 +03:00
if err != nil {
fail ( "internal error" , "Failed to get user by key ID(%d): %v" , keyID , err )
}
mode , err := models . AccessLevel ( user , repo )
if err != nil {
fail ( "Internal error" , "Fail to check access: %v" , err )
} else if mode < requestedMode {
clientMessage := _ACCESS_DENIED_MESSAGE
if mode >= models . ACCESS_MODE_READ {
clientMessage = "You do not have sufficient authorization for this action"
}
fail ( clientMessage ,
"User %s does not have level %v access to repository %s" ,
user . Name , requestedMode , repoPath )
2015-08-05 06:14:17 +03:00
}
2014-04-10 22:20:58 +04:00
}
}
2016-02-21 02:13:12 +03:00
uuid := gouuid . NewV4 ( ) . String ( )
2014-06-28 19:56:41 +04:00
os . Setenv ( "uuid" , uuid )
2014-04-10 22:20:58 +04:00
2015-11-24 06:32:07 +03:00
// Special handle for Windows.
if setting . IsWindows {
verb = strings . Replace ( verb , "-" , " " , 1 )
}
2014-10-01 15:40:48 +04:00
var gitcmd * exec . Cmd
verbs := strings . Split ( verb , " " )
if len ( verbs ) == 2 {
gitcmd = exec . Command ( verbs [ 0 ] , verbs [ 1 ] , repoPath )
} else {
gitcmd = exec . Command ( verb , repoPath )
}
2014-05-26 04:11:25 +04:00
gitcmd . Dir = setting . RepoRootPath
2014-04-10 22:20:58 +04:00
gitcmd . Stdout = os . Stdout
gitcmd . Stdin = os . Stdin
gitcmd . Stderr = os . Stderr
2014-07-26 08:24:27 +04:00
if err = gitcmd . Run ( ) ; err != nil {
2015-06-18 14:01:05 +03:00
fail ( "Internal error" , "Failed to execute git command: %v" , err )
2014-04-10 22:20:58 +04:00
}
2014-06-28 19:56:41 +04:00
2015-02-16 17:38:01 +03:00
if requestedMode == models . ACCESS_MODE_WRITE {
2015-12-15 01:06:54 +03:00
handleUpdateTask ( uuid , user , repoUser , reponame , isWiki )
2015-07-25 16:32:04 +03:00
}
2015-08-06 17:48:11 +03:00
// Update user key activity.
2015-08-05 06:14:17 +03:00
if keyID > 0 {
2015-08-06 17:48:11 +03:00
key , err := models . GetPublicKeyByID ( keyID )
2015-08-05 06:14:17 +03:00
if err != nil {
fail ( "Internal error" , "GetPublicKeyById: %v" , err )
}
key . Updated = time . Now ( )
if err = models . UpdatePublicKey ( key ) ; err != nil {
fail ( "Internal error" , "UpdatePublicKey: %v" , err )
}
2014-08-10 02:40:10 +04:00
}
2016-05-12 21:32:28 +03:00
return nil
2014-04-10 22:20:58 +04:00
}