2014-04-10 22:20:58 +04:00
// Copyright 2014 The Gogs Authors. All rights reserved.
2016-12-21 15:13:17 +03:00
// Copyright 2016 The Gitea Authors. All rights reserved.
2014-04-10 22:20:58 +04:00
// Use of this source code is governed by a MIT-style
// license that can be found in the LICENSE file.
2014-05-02 05:21:46 +04:00
package cmd
2014-04-10 22:20:58 +04:00
import (
2016-12-26 04:16:37 +03:00
"encoding/json"
2014-04-10 22:20:58 +04:00
"fmt"
2019-06-01 18:00:21 +03:00
"net/http"
"net/url"
2014-04-10 22:20:58 +04:00
"os"
"os/exec"
2020-02-05 12:40:35 +03:00
"regexp"
2019-06-01 18:00:21 +03:00
"strconv"
2014-04-10 22:20:58 +04:00
"strings"
2014-08-10 02:40:10 +04:00
"time"
2014-04-10 22:20:58 +04:00
2016-11-10 19:24:48 +03:00
"code.gitea.io/gitea/models"
2020-03-09 22:56:18 +03:00
"code.gitea.io/gitea/modules/lfs"
2016-11-10 19:24:48 +03:00
"code.gitea.io/gitea/modules/log"
2018-08-07 21:49:18 +03:00
"code.gitea.io/gitea/modules/pprof"
2017-04-19 06:45:01 +03:00
"code.gitea.io/gitea/modules/private"
2016-11-10 19:24:48 +03:00
"code.gitea.io/gitea/modules/setting"
2017-04-12 10:44:54 +03:00
2016-12-26 04:16:37 +03:00
"github.com/dgrijalva/jwt-go"
2019-08-23 19:40:30 +03:00
"github.com/unknwon/com"
2016-11-10 01:18:22 +03:00
"github.com/urfave/cli"
2014-04-10 22:20:58 +04:00
)
2015-02-16 17:38:01 +03:00
const (
2016-12-26 04:16:37 +03:00
lfsAuthenticateVerb = "git-lfs-authenticate"
2015-02-16 17:38:01 +03:00
)
2016-11-04 14:42:18 +03:00
// CmdServ represents the available serv sub-command.
2014-04-10 22:20:58 +04:00
var CmdServ = cli . Command {
2014-05-05 08:55:17 +04:00
Name : "serv" ,
Usage : "This command should only be called by SSH shell" ,
Description : ` Serv provide access auth for repositories ` ,
Action : runServ ,
2015-02-05 13:12:37 +03:00
Flags : [ ] cli . Flag {
2018-08-07 21:49:18 +03:00
cli . BoolFlag {
Name : "enable-pprof" ,
} ,
2019-12-25 18:44:57 +03:00
cli . BoolFlag {
Name : "debug" ,
} ,
2015-02-05 13:12:37 +03:00
} ,
2014-04-10 22:20:58 +04:00
}
2019-12-25 18:44:57 +03:00
func setup ( logPath string , debug bool ) {
if ! debug {
_ = log . DelLogger ( "console" )
}
2015-09-17 06:08:46 +03:00
setting . NewContext ( )
2019-12-25 18:44:57 +03:00
if debug {
setting . ProdMode = false
}
2014-05-22 05:37:13 +04:00
}
2014-04-10 22:20:58 +04:00
func parseCmd ( cmd string ) ( string , string ) {
ss := strings . SplitN ( cmd , " " , 2 )
if len ( ss ) != 2 {
return "" , ""
}
2015-02-16 17:38:01 +03:00
return ss [ 0 ] , strings . Replace ( ss [ 1 ] , "'/" , "'" , 1 )
2014-04-10 22:20:58 +04:00
}
2014-05-22 05:37:13 +04:00
var (
2015-11-24 06:32:07 +03:00
allowedCommands = map [ string ] models . AccessMode {
2016-11-07 19:20:37 +03:00
"git-upload-pack" : models . AccessModeRead ,
"git-upload-archive" : models . AccessModeRead ,
"git-receive-pack" : models . AccessModeWrite ,
2016-12-26 04:16:37 +03:00
lfsAuthenticateVerb : models . AccessModeNone ,
2014-05-22 05:37:13 +04:00
}
2020-02-05 12:40:35 +03:00
alphaDashDotPattern = regexp . MustCompile ( ` [^\w-\.] ` )
2014-05-22 05:37:13 +04:00
)
2015-08-06 17:48:11 +03:00
func fail ( userMessage , logMessage string , args ... interface { } ) {
2016-12-21 15:13:17 +03:00
fmt . Fprintln ( os . Stderr , "Gitea:" , userMessage )
2015-11-08 22:31:49 +03:00
if len ( logMessage ) > 0 {
2015-11-24 06:33:24 +03:00
if ! setting . ProdMode {
2015-11-30 18:00:52 +03:00
fmt . Fprintf ( os . Stderr , logMessage + "\n" , args ... )
2015-11-24 06:33:24 +03:00
}
2015-11-08 22:31:49 +03:00
}
os . Exit ( 1 )
2015-08-06 17:48:11 +03:00
}
2016-05-12 21:32:28 +03:00
func runServ ( c * cli . Context ) error {
2019-06-01 18:00:21 +03:00
// FIXME: This needs to internationalised
2019-12-25 18:44:57 +03:00
setup ( "serv.log" , c . Bool ( "debug" ) )
2014-04-10 22:20:58 +04:00
2016-02-28 04:48:39 +03:00
if setting . SSH . Disabled {
2016-12-21 15:13:17 +03:00
println ( "Gitea: SSH has been disabled" )
2016-05-12 21:32:28 +03:00
return nil
2016-02-22 05:55:59 +03:00
}
2015-02-13 08:58:46 +03:00
if len ( c . Args ( ) ) < 1 {
2019-06-12 22:41:28 +03:00
if err := cli . ShowSubcommandHelp ( c ) ; err != nil {
fmt . Printf ( "error showing subcommand help: %v\n" , err )
}
2017-04-12 10:44:54 +03:00
return nil
2015-02-09 13:32:42 +03:00
}
2015-02-16 17:38:01 +03:00
2019-06-01 18:00:21 +03:00
keys := strings . Split ( c . Args ( ) [ 0 ] , "-" )
if len ( keys ) != 2 || keys [ 0 ] != "key" {
fail ( "Key ID format error" , "Invalid key argument: %s" , c . Args ( ) [ 0 ] )
}
keyID := com . StrTo ( keys [ 1 ] ) . MustInt64 ( )
2014-04-10 22:20:58 +04:00
cmd := os . Getenv ( "SSH_ORIGINAL_COMMAND" )
2015-08-05 06:14:17 +03:00
if len ( cmd ) == 0 {
2019-06-01 18:00:21 +03:00
key , user , err := private . ServNoCommand ( keyID )
if err != nil {
fail ( "Internal error" , "Failed to check provided key: %v" , err )
}
if key . Type == models . KeyTypeDeploy {
println ( "Hi there! You've successfully authenticated with the deploy key named " + key . Name + ", but Gitea does not provide shell access." )
} else {
2019-08-11 15:15:58 +03:00
println ( "Hi there, " + user . Name + "! You've successfully authenticated with the key named " + key . Name + ", but Gitea does not provide shell access." )
2019-06-01 18:00:21 +03:00
}
2016-12-21 15:13:17 +03:00
println ( "If this is unexpected, please log in with password and setup Gitea under another user." )
2016-05-12 21:32:28 +03:00
return nil
2014-04-10 22:20:58 +04:00
}
verb , args := parseCmd ( cmd )
2016-12-26 04:16:37 +03:00
var lfsVerb string
if verb == lfsAuthenticateVerb {
if ! setting . LFS . StartServer {
fail ( "Unknown git command" , "LFS authentication request over SSH denied, LFS support is disabled" )
}
2017-03-22 13:43:28 +03:00
argsSplit := strings . Split ( args , " " )
if len ( argsSplit ) >= 2 {
2016-12-26 04:16:37 +03:00
args = strings . TrimSpace ( argsSplit [ 0 ] )
lfsVerb = strings . TrimSpace ( argsSplit [ 1 ] )
}
}
2015-11-09 19:39:03 +03:00
repoPath := strings . ToLower ( strings . Trim ( args , "'" ) )
2014-04-10 22:20:58 +04:00
rr := strings . SplitN ( repoPath , "/" , 2 )
if len ( rr ) != 2 {
2015-06-18 14:01:05 +03:00
fail ( "Invalid repository path" , "Invalid repository path: %v" , args )
2014-04-10 22:20:58 +04:00
}
2017-02-25 17:54:40 +03:00
2015-12-01 04:45:55 +03:00
username := strings . ToLower ( rr [ 0 ] )
reponame := strings . ToLower ( strings . TrimSuffix ( rr [ 1 ] , ".git" ) )
2020-02-05 12:40:35 +03:00
if alphaDashDotPattern . MatchString ( reponame ) {
fail ( "Invalid repo name" , "Invalid repo name: %s" , reponame )
}
2018-08-07 21:49:18 +03:00
if setting . EnablePprof || c . Bool ( "enable-pprof" ) {
if err := os . MkdirAll ( setting . PprofDataPath , os . ModePerm ) ; err != nil {
fail ( "Error while trying to create PPROF_DATA_PATH" , "Error while trying to create PPROF_DATA_PATH: %v" , err )
}
2019-06-01 18:00:21 +03:00
stopCPUProfiler , err := pprof . DumpCPUProfileForUsername ( setting . PprofDataPath , username )
if err != nil {
fail ( "Internal Server Error" , "Unable to start CPU profile: %v" , err )
}
2018-08-07 21:49:18 +03:00
defer func ( ) {
stopCPUProfiler ( )
2019-06-01 18:00:21 +03:00
err := pprof . DumpMemProfileForUsername ( setting . PprofDataPath , username )
if err != nil {
fail ( "Internal Server Error" , "Unable to dump Mem Profile: %v" , err )
}
2018-08-07 21:49:18 +03:00
} ( )
}
2015-11-24 06:32:07 +03:00
requestedMode , has := allowedCommands [ verb ]
2015-02-16 17:38:01 +03:00
if ! has {
fail ( "Unknown git command" , "Unknown git command %s" , verb )
}
2014-04-10 22:20:58 +04:00
2016-12-26 04:16:37 +03:00
if verb == lfsAuthenticateVerb {
if lfsVerb == "upload" {
requestedMode = models . AccessModeWrite
2017-03-22 13:43:28 +03:00
} else if lfsVerb == "download" {
2016-12-26 04:16:37 +03:00
requestedMode = models . AccessModeRead
2017-03-22 13:43:28 +03:00
} else {
2017-06-05 10:49:46 +03:00
fail ( "Unknown LFS verb" , "Unknown lfs verb %s" , lfsVerb )
2016-12-26 04:16:37 +03:00
}
}
2019-06-01 18:00:21 +03:00
results , err := private . ServCommand ( keyID , username , reponame , requestedMode , verb , lfsVerb )
if err != nil {
if private . IsErrServCommand ( err ) {
errServCommand := err . ( private . ErrServCommand )
if errServCommand . StatusCode != http . StatusInternalServerError {
2019-06-03 11:07:03 +03:00
fail ( "Unauthorized" , "%s" , errServCommand . Error ( ) )
2019-06-01 18:00:21 +03:00
} else {
2019-06-03 11:07:03 +03:00
fail ( "Internal Server Error" , "%s" , errServCommand . Error ( ) )
2015-08-05 06:14:17 +03:00
}
2014-04-10 22:20:58 +04:00
}
2019-06-03 11:07:03 +03:00
fail ( "Internal Server Error" , "%s" , err . Error ( ) )
2014-04-10 22:20:58 +04:00
}
2019-06-01 18:00:21 +03:00
os . Setenv ( models . EnvRepoIsWiki , strconv . FormatBool ( results . IsWiki ) )
os . Setenv ( models . EnvRepoName , results . RepoName )
os . Setenv ( models . EnvRepoUsername , results . OwnerName )
2019-06-11 04:13:24 +03:00
os . Setenv ( models . EnvPusherName , results . UserName )
2019-06-01 18:00:21 +03:00
os . Setenv ( models . EnvPusherID , strconv . FormatInt ( results . UserID , 10 ) )
os . Setenv ( models . ProtectedBranchRepoID , strconv . FormatInt ( results . RepoID , 10 ) )
2019-07-01 04:18:13 +03:00
os . Setenv ( models . ProtectedBranchPRID , fmt . Sprintf ( "%d" , 0 ) )
2019-10-21 11:21:45 +03:00
os . Setenv ( models . EnvIsDeployKey , fmt . Sprintf ( "%t" , results . IsDeployKey ) )
os . Setenv ( models . EnvKeyID , fmt . Sprintf ( "%d" , results . KeyID ) )
2014-04-10 22:20:58 +04:00
2016-12-26 04:16:37 +03:00
//LFS token authentication
if verb == lfsAuthenticateVerb {
2019-06-01 18:00:21 +03:00
url := fmt . Sprintf ( "%s%s/%s.git/info/lfs" , setting . AppURL , url . PathEscape ( results . OwnerName ) , url . PathEscape ( results . RepoName ) )
2016-12-26 04:16:37 +03:00
now := time . Now ( )
2020-03-09 22:56:18 +03:00
claims := lfs . Claims {
StandardClaims : jwt . StandardClaims {
ExpiresAt : now . Add ( setting . LFS . HTTPAuthExpiry ) . Unix ( ) ,
NotBefore : now . Unix ( ) ,
} ,
RepoID : results . RepoID ,
Op : lfsVerb ,
UserID : results . UserID ,
2018-01-27 19:48:15 +03:00
}
token := jwt . NewWithClaims ( jwt . SigningMethodHS256 , claims )
2016-12-26 04:16:37 +03:00
// Sign and get the complete encoded token as a string using the secret
tokenString , err := token . SignedString ( setting . LFS . JWTSecretBytes )
if err != nil {
fail ( "Internal error" , "Failed to sign JWT token: %v" , err )
}
tokenAuthentication := & models . LFSTokenResponse {
Header : make ( map [ string ] string ) ,
Href : url ,
}
tokenAuthentication . Header [ "Authorization" ] = fmt . Sprintf ( "Bearer %s" , tokenString )
enc := json . NewEncoder ( os . Stdout )
err = enc . Encode ( tokenAuthentication )
if err != nil {
fail ( "Internal error" , "Failed to encode LFS json response: %v" , err )
}
return nil
}
2015-11-24 06:32:07 +03:00
// Special handle for Windows.
if setting . IsWindows {
verb = strings . Replace ( verb , "-" , " " , 1 )
}
2014-10-01 15:40:48 +04:00
var gitcmd * exec . Cmd
verbs := strings . Split ( verb , " " )
if len ( verbs ) == 2 {
gitcmd = exec . Command ( verbs [ 0 ] , verbs [ 1 ] , repoPath )
} else {
gitcmd = exec . Command ( verb , repoPath )
}
2017-03-17 07:59:42 +03:00
2014-05-26 04:11:25 +04:00
gitcmd . Dir = setting . RepoRootPath
2014-04-10 22:20:58 +04:00
gitcmd . Stdout = os . Stdout
gitcmd . Stdin = os . Stdin
gitcmd . Stderr = os . Stderr
2014-07-26 08:24:27 +04:00
if err = gitcmd . Run ( ) ; err != nil {
2015-06-18 14:01:05 +03:00
fail ( "Internal error" , "Failed to execute git command: %v" , err )
2014-04-10 22:20:58 +04:00
}
2014-06-28 19:56:41 +04:00
2015-08-06 17:48:11 +03:00
// Update user key activity.
2019-06-01 18:00:21 +03:00
if results . KeyID > 0 {
if err = private . UpdatePublicKeyInRepo ( results . KeyID , results . RepoID ) ; err != nil {
fail ( "Internal error" , "UpdatePublicKeyInRepo: %v" , err )
2015-08-05 06:14:17 +03:00
}
2014-08-10 02:40:10 +04:00
}
2016-05-12 21:32:28 +03:00
return nil
2014-04-10 22:20:58 +04:00
}