~bzr-pqm/bzr/bzr.dev

5594.1.1 by Vincent Ladeuil
Fix socketpair-based SSH transport leaking socket into other child processes
1
# Copyright (C) 2006-2011 Robey Pointer <robey@lag.net>
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
2
# Copyright (C) 2005, 2006, 2007 Canonical Ltd
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
3
#
4
# This program is free software; you can redistribute it and/or modify
5
# it under the terms of the GNU General Public License as published by
6
# the Free Software Foundation; either version 2 of the License, or
7
# (at your option) any later version.
8
#
9
# This program is distributed in the hope that it will be useful,
10
# but WITHOUT ANY WARRANTY; without even the implied warranty of
11
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12
# GNU General Public License for more details.
13
#
14
# You should have received a copy of the GNU General Public License
15
# along with this program; if not, write to the Free Software
4183.7.1 by Sabin Iacob
update FSF mailing address
16
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
17
6379.6.7 by Jelmer Vernooij
Move importing from future until after doc string, otherwise the doc string will disappear.
18
"""Foundation SSH support for SFTP and smart server."""
19
6379.6.3 by Jelmer Vernooij
Use absolute_import.
20
from __future__ import absolute_import
21
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
22
import errno
4304.2.1 by Vincent Ladeuil
Fix bug #367726 by reverting some default user handling introduced
23
import getpass
4555.1.1 by John Arbash Meinel
Fix bug #375867, check if password is a supported auth type
24
import logging
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
25
import os
26
import socket
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
27
import subprocess
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
28
import sys
6603.3.1 by Andrew Starr-Bochicchio
Use hexlify() from binascii directly as paramiko removed hexify().
29
from binascii import hexlify
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
30
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
31
from bzrlib import (
32
    config,
33
    errors,
34
    osutils,
35
    trace,
36
    ui,
37
    )
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
38
39
try:
40
    import paramiko
41
except ImportError, e:
2104.5.1 by John Arbash Meinel
Remove the strict dependency on paramiko for ssh access
42
    # If we have an ssh subprocess, we don't strictly need paramiko for all ssh
43
    # access
44
    paramiko = None
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
45
else:
46
    from paramiko.sftp_client import SFTPClient
47
48
49
SYSTEM_HOSTKEYS = {}
50
BZR_HOSTKEYS = {}
51
52
1951.1.5 by Andrew Bennetts
Fix some missing imports with a bit of help from pyflakes.
53
_paramiko_version = getattr(paramiko, '__version_info__', (0, 0, 0))
54
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
55
# Paramiko 1.5 tries to open a socket.AF_UNIX in order to connect
56
# to ssh-agent. That attribute doesn't exist on win32 (it does in cygwin)
57
# so we get an AttributeError exception. So we will not try to
58
# connect to an agent if we are on win32 and using Paramiko older than 1.6
59
_use_ssh_agent = (sys.platform != 'win32' or _paramiko_version >= (1, 6, 0))
60
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
61
62
class SSHVendorManager(object):
63
    """Manager for manage SSH vendors."""
64
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
65
    # Note, although at first sign the class interface seems similar to
2221.5.22 by Dmitry Vasiliev
Updated note about registry.Registry
66
    # bzrlib.registry.Registry it is not possible/convenient to directly use
67
    # the Registry because the class just has "get()" interface instead of the
68
    # Registry's "get(key)".
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
69
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
70
    def __init__(self):
71
        self._ssh_vendors = {}
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
72
        self._cached_ssh_vendor = None
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
73
        self._default_ssh_vendor = None
74
75
    def register_default_vendor(self, vendor):
76
        """Register default SSH vendor."""
77
        self._default_ssh_vendor = vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
78
79
    def register_vendor(self, name, vendor):
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
80
        """Register new SSH vendor by name."""
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
81
        self._ssh_vendors[name] = vendor
82
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
83
    def clear_cache(self):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
84
        """Clear previously cached lookup result."""
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
85
        self._cached_ssh_vendor = None
86
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
87
    def _get_vendor_by_environment(self, environment=None):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
88
        """Return the vendor or None based on BZR_SSH environment variable.
89
90
        :raises UnknownSSH: if the BZR_SSH environment variable contains
91
                            unknown vendor name
92
        """
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
93
        if environment is None:
94
            environment = os.environ
95
        if 'BZR_SSH' in environment:
96
            vendor_name = environment['BZR_SSH']
97
            try:
98
                vendor = self._ssh_vendors[vendor_name]
99
            except KeyError:
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
100
                vendor = self._get_vendor_from_path(vendor_name)
101
                if vendor is None:
102
                    raise errors.UnknownSSH(vendor_name)
103
                vendor.executable_path = vendor_name
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
104
            return vendor
105
        return None
106
107
    def _get_ssh_version_string(self, args):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
108
        """Return SSH version string from the subprocess."""
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
109
        try:
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
110
            p = subprocess.Popen(args,
111
                                 stdout=subprocess.PIPE,
112
                                 stderr=subprocess.PIPE,
113
                                 **os_specific_subprocess_params())
114
            stdout, stderr = p.communicate()
115
        except OSError:
116
            stdout = stderr = ''
117
        return stdout + stderr
118
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
119
    def _get_vendor_by_version_string(self, version, progname):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
120
        """Return the vendor or None based on output from the subprocess.
121
122
        :param version: The output of 'ssh -V' like command.
2772.3.1 by Martin Pool
Fix detection of ssh implementation on Windows
123
        :param args: Command line that was run.
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
124
        """
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
125
        vendor = None
126
        if 'OpenSSH' in version:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
127
            trace.mutter('ssh implementation is OpenSSH')
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
128
            vendor = OpenSSHSubprocessVendor()
129
        elif 'SSH Secure Shell' in version:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
130
            trace.mutter('ssh implementation is SSH Corp.')
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
131
            vendor = SSHCorpSubprocessVendor()
5444.2.3 by Matthew Gordon
Added missing check for GNU lsh in _get_vendor_by_version_string().
132
        elif 'lsh' in version:
133
            trace.mutter('ssh implementation is GNU lsh.')
134
            vendor = LSHSubprocessVendor()
4595.17.2 by Martin
Merge bzr.dev 4789 to resolve conflict from the disabling of plink auto-detection, and relocate NEWS
135
        # As plink user prompts are not handled currently, don't auto-detect
136
        # it by inspection below, but keep this vendor detection for if a path
137
        # is given in BZR_SSH. See https://bugs.launchpad.net/bugs/414743
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
138
        elif 'plink' in version and progname == 'plink':
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
139
            # Checking if "plink" was the executed argument as Windows
5448.2.1 by Martin
Fix some "its" vs. "it's" spelling confusion in bzrlib code... also, ahem, a name in the NEWS file
140
            # sometimes reports 'ssh -V' incorrectly with 'plink' in its
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
141
            # version.  See https://bugs.launchpad.net/bzr/+bug/107155
142
            trace.mutter("ssh implementation is Putty's plink.")
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
143
            vendor = PLinkSubprocessVendor()
144
        return vendor
145
146
    def _get_vendor_by_inspection(self):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
147
        """Return the vendor or None by checking for known SSH implementations."""
4595.17.2 by Martin
Merge bzr.dev 4789 to resolve conflict from the disabling of plink auto-detection, and relocate NEWS
148
        version = self._get_ssh_version_string(['ssh', '-V'])
149
        return self._get_vendor_by_version_string(version, "ssh")
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
150
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
151
    def _get_vendor_from_path(self, path):
152
        """Return the vendor or None using the program at the given path"""
153
        version = self._get_ssh_version_string([path, '-V'])
154
        return self._get_vendor_by_version_string(version, 
155
            os.path.splitext(os.path.basename(path))[0])
156
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
157
    def get_vendor(self, environment=None):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
158
        """Find out what version of SSH is on the system.
159
160
        :raises SSHVendorNotFound: if no any SSH vendor is found
161
        :raises UnknownSSH: if the BZR_SSH environment variable contains
162
                            unknown vendor name
163
        """
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
164
        if self._cached_ssh_vendor is None:
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
165
            vendor = self._get_vendor_by_environment(environment)
166
            if vendor is None:
167
                vendor = self._get_vendor_by_inspection()
168
                if vendor is None:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
169
                    trace.mutter('falling back to default implementation')
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
170
                    vendor = self._default_ssh_vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
171
                    if vendor is None:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
172
                        raise errors.SSHVendorNotFound()
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
173
            self._cached_ssh_vendor = vendor
174
        return self._cached_ssh_vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
175
176
_ssh_vendor_manager = SSHVendorManager()
177
_get_ssh_vendor = _ssh_vendor_manager.get_vendor
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
178
register_default_ssh_vendor = _ssh_vendor_manager.register_default_vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
179
register_ssh_vendor = _ssh_vendor_manager.register_vendor
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
180
181
5050.2.1 by Martin
Drive-by fix for breakin killing off ssh child processes
182
def _ignore_signals():
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
183
    # TODO: This should possibly ignore SIGHUP as well, but bzr currently
184
    # doesn't handle it itself.
185
    # <https://launchpad.net/products/bzr/+bug/41433/+index>
186
    import signal
187
    signal.signal(signal.SIGINT, signal.SIG_IGN)
5050.2.1 by Martin
Drive-by fix for breakin killing off ssh child processes
188
    # GZ 2010-02-19: Perhaps make this check if breakin is installed instead
189
    if signal.getsignal(signal.SIGQUIT) != signal.SIG_DFL:
190
        signal.signal(signal.SIGQUIT, signal.SIG_IGN)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
191
192
3353.1.3 by Andrew Bennetts
Always adapt sockets to look like paramiko Channels before passing them to paramiko's SFTPClient.
193
class SocketAsChannelAdapter(object):
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
194
    """Simple wrapper for a socket that pretends to be a paramiko Channel."""
195
196
    def __init__(self, sock):
197
        self.__socket = sock
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
198
3353.1.2 by Andrew Bennetts
Add get_name to LoopbackSFTP. Makes the current tests pass with current paramiko.
199
    def get_name(self):
3353.1.3 by Andrew Bennetts
Always adapt sockets to look like paramiko Channels before passing them to paramiko's SFTPClient.
200
        return "bzr SocketAsChannelAdapter"
3943.8.1 by Marius Kruger
remove all trailing whitespace from bzr source
201
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
202
    def send(self, data):
203
        return self.__socket.send(data)
204
205
    def recv(self, n):
3353.1.3 by Andrew Bennetts
Always adapt sockets to look like paramiko Channels before passing them to paramiko's SFTPClient.
206
        try:
207
            return self.__socket.recv(n)
208
        except socket.error, e:
209
            if e.args[0] in (errno.EPIPE, errno.ECONNRESET, errno.ECONNABORTED,
210
                             errno.EBADF):
211
                # Connection has closed.  Paramiko expects an empty string in
212
                # this case, not an exception.
213
                return ''
214
            raise
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
215
216
    def recv_ready(self):
3353.1.3 by Andrew Bennetts
Always adapt sockets to look like paramiko Channels before passing them to paramiko's SFTPClient.
217
        # TODO: jam 20051215 this function is necessary to support the
218
        # pipelined() function. In reality, it probably should use
219
        # poll() or select() to actually return if there is data
220
        # available, otherwise we probably don't get any benefit
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
221
        return True
222
223
    def close(self):
224
        self.__socket.close()
225
226
227
class SSHVendor(object):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
228
    """Abstract base class for SSH vendor implementations."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
229
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
230
    def connect_sftp(self, username, password, host, port):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
231
        """Make an SSH connection, and return an SFTPClient.
3943.8.1 by Marius Kruger
remove all trailing whitespace from bzr source
232
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
233
        :param username: an ascii string
234
        :param password: an ascii string
235
        :param host: a host name as an ascii string
236
        :param port: a port number
237
        :type port: int
238
239
        :raises: ConnectionError if it cannot connect.
240
241
        :rtype: paramiko.sftp_client.SFTPClient
242
        """
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
243
        raise NotImplementedError(self.connect_sftp)
244
245
    def connect_ssh(self, username, password, host, port, command):
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
246
        """Make an SSH connection.
3943.8.1 by Marius Kruger
remove all trailing whitespace from bzr source
247
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
248
        :returns: an SSHConnection.
1951.1.12 by Andrew Bennetts
Cosmetic tweaks.
249
        """
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
250
        raise NotImplementedError(self.connect_ssh)
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
251
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
252
    def _raise_connection_error(self, host, port=None, orig_error=None,
2052.4.4 by John Arbash Meinel
Create a SocketConnectionError to make creating nice errors easier
253
                                msg='Unable to connect to SSH host'):
254
        """Raise a SocketConnectionError with properly formatted host.
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
255
256
        This just unifies all the locations that try to raise ConnectionError,
257
        so that they format things properly.
258
        """
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
259
        raise errors.SocketConnectionError(host=host, port=port, msg=msg,
260
                                           orig_error=orig_error)
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
261
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
262
263
class LoopbackVendor(SSHVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
264
    """SSH "vendor" that connects over a plain TCP socket, not SSH."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
265
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
266
    def connect_sftp(self, username, password, host, port):
267
        sock = socket.socket()
268
        try:
269
            sock.connect((host, port))
270
        except socket.error, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
271
            self._raise_connection_error(host, port=port, orig_error=e)
3353.1.3 by Andrew Bennetts
Always adapt sockets to look like paramiko Channels before passing them to paramiko's SFTPClient.
272
        return SFTPClient(SocketAsChannelAdapter(sock))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
273
1951.1.11 by Andrew Bennetts
Change register_ssh_vendor to take an instance rather than a class.
274
register_ssh_vendor('loopback', LoopbackVendor())
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
275
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
276
277
class ParamikoVendor(SSHVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
278
    """Vendor that uses paramiko."""
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
279
6603.3.1 by Andrew Starr-Bochicchio
Use hexlify() from binascii directly as paramiko removed hexify().
280
    def _hexify(self, s):
281
        return hexlify(s).upper()
282
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
283
    def _connect(self, username, password, host, port):
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
284
        global SYSTEM_HOSTKEYS, BZR_HOSTKEYS
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
285
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
286
        load_host_keys()
287
288
        try:
289
            t = paramiko.Transport((host, port or 22))
290
            t.set_log_channel('bzr.paramiko')
291
            t.start_client()
292
        except (paramiko.SSHException, socket.error), e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
293
            self._raise_connection_error(host, port=port, orig_error=e)
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
294
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
295
        server_key = t.get_remote_server_key()
6603.3.1 by Andrew Starr-Bochicchio
Use hexlify() from binascii directly as paramiko removed hexify().
296
        server_key_hex = self._hexify(server_key.get_fingerprint())
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
297
        keytype = server_key.get_name()
1711.9.10 by John Arbash Meinel
Update transport/ssh.py to remove has_key usage
298
        if host in SYSTEM_HOSTKEYS and keytype in SYSTEM_HOSTKEYS[host]:
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
299
            our_server_key = SYSTEM_HOSTKEYS[host][keytype]
6603.3.1 by Andrew Starr-Bochicchio
Use hexlify() from binascii directly as paramiko removed hexify().
300
            our_server_key_hex = self._hexify(our_server_key.get_fingerprint())
1711.9.10 by John Arbash Meinel
Update transport/ssh.py to remove has_key usage
301
        elif host in BZR_HOSTKEYS and keytype in BZR_HOSTKEYS[host]:
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
302
            our_server_key = BZR_HOSTKEYS[host][keytype]
6603.3.1 by Andrew Starr-Bochicchio
Use hexlify() from binascii directly as paramiko removed hexify().
303
            our_server_key_hex = self._hexify(our_server_key.get_fingerprint())
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
304
        else:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
305
            trace.warning('Adding %s host key for %s: %s'
306
                          % (keytype, host, server_key_hex))
2127.3.1 by Alexander Belchenko
Use BZR_HOSTKEYS.add instead of deprecated dict-like paramiko interface
307
            add = getattr(BZR_HOSTKEYS, 'add', None)
308
            if add is not None: # paramiko >= 1.X.X
309
                BZR_HOSTKEYS.add(host, keytype, server_key)
310
            else:
1551.9.2 by Aaron Bentley
Bugfix for paramiko connections
311
                BZR_HOSTKEYS.setdefault(host, {})[keytype] = server_key
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
312
            our_server_key = server_key
6603.3.1 by Andrew Starr-Bochicchio
Use hexlify() from binascii directly as paramiko removed hexify().
313
            our_server_key_hex = self._hexify(our_server_key.get_fingerprint())
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
314
            save_host_keys()
315
        if server_key != our_server_key:
316
            filename1 = os.path.expanduser('~/.ssh/known_hosts')
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
317
            filename2 = osutils.pathjoin(config.config_dir(), 'ssh_host_keys')
318
            raise errors.TransportError(
319
                'Host keys for %s do not match!  %s != %s' %
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
320
                (host, our_server_key_hex, server_key_hex),
321
                ['Try editing %s or %s' % (filename1, filename2)])
322
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
323
        _paramiko_auth(username, password, host, port, t)
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
324
        return t
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
325
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
326
    def connect_sftp(self, username, password, host, port):
327
        t = self._connect(username, password, host, port)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
328
        try:
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
329
            return t.open_sftp_client()
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
330
        except paramiko.SSHException, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
331
            self._raise_connection_error(host, port=port, orig_error=e,
2052.4.4 by John Arbash Meinel
Create a SocketConnectionError to make creating nice errors easier
332
                                         msg='Unable to start sftp client')
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
333
334
    def connect_ssh(self, username, password, host, port, command):
335
        t = self._connect(username, password, host, port)
336
        try:
337
            channel = t.open_session()
338
            cmdline = ' '.join(command)
339
            channel.exec_command(cmdline)
340
            return _ParamikoSSHConnection(channel)
341
        except paramiko.SSHException, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
342
            self._raise_connection_error(host, port=port, orig_error=e,
2052.4.4 by John Arbash Meinel
Create a SocketConnectionError to make creating nice errors easier
343
                                         msg='Unable to invoke remote bzr')
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
344
5430.6.1 by Andrew Bennetts
Simplify connect_sftp/ssh error handling, hopefully resolving intermittent test failure in test_bad_connection_ssh.
345
_ssh_connection_errors = (EOFError, OSError, IOError, socket.error)
2104.5.1 by John Arbash Meinel
Remove the strict dependency on paramiko for ssh access
346
if paramiko is not None:
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
347
    vendor = ParamikoVendor()
348
    register_ssh_vendor('paramiko', vendor)
349
    register_ssh_vendor('none', vendor)
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
350
    register_default_ssh_vendor(vendor)
5430.6.1 by Andrew Bennetts
Simplify connect_sftp/ssh error handling, hopefully resolving intermittent test failure in test_bad_connection_ssh.
351
    _ssh_connection_errors += (paramiko.SSHException,)
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
352
    del vendor
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
353
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
354
355
class SubprocessVendor(SSHVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
356
    """Abstract base class for vendors that use pipes to a subprocess."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
357
6331.5.1 by Martin Packman
Stop requiring a bzr subprocess in bt.test_sftp_transport for ssh connection error test
358
    # In general stderr should be inherited from the parent process so prompts
359
    # are visible on the terminal. This can be overriden to another file for
360
    # tests, but beware of using PIPE which may hang due to not being read.
361
    _stderr_target = None
362
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
363
    def _connect(self, argv):
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
364
        # Attempt to make a socketpair to use as stdin/stdout for the SSH
365
        # subprocess.  We prefer sockets to pipes because they support
366
        # non-blocking short reads, allowing us to optimistically read 64k (or
367
        # whatever) chunks.
368
        try:
369
            my_sock, subproc_sock = socket.socketpair()
5582.6.1 by Max Bowsher
Fix socketpair-based SSH transport leaking socket into other child processes.
370
            osutils.set_fd_cloexec(my_sock)
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
371
        except (AttributeError, socket.error):
372
            # This platform doesn't support socketpair(), so just use ordinary
373
            # pipes instead.
374
            stdin = stdout = subprocess.PIPE
5050.54.3 by Max Bowsher
Also close the subprocess side of the socketpair within bzrlib.
375
            my_sock, subproc_sock = None, None
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
376
        else:
377
            stdin = stdout = subproc_sock
378
        proc = subprocess.Popen(argv, stdin=stdin, stdout=stdout,
6331.5.1 by Martin Packman
Stop requiring a bzr subprocess in bt.test_sftp_transport for ssh connection error test
379
                                stderr=self._stderr_target,
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
380
                                **os_specific_subprocess_params())
5050.54.3 by Max Bowsher
Also close the subprocess side of the socketpair within bzrlib.
381
        if subproc_sock is not None:
382
            subproc_sock.close()
383
        return SSHSubprocessConnection(proc, sock=my_sock)
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
384
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
385
    def connect_sftp(self, username, password, host, port):
386
        try:
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
387
            argv = self._get_vendor_specific_argv(username, host, port,
388
                                                  subsystem='sftp')
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
389
            sock = self._connect(argv)
3353.1.3 by Andrew Bennetts
Always adapt sockets to look like paramiko Channels before passing them to paramiko's SFTPClient.
390
            return SFTPClient(SocketAsChannelAdapter(sock))
5430.6.1 by Andrew Bennetts
Simplify connect_sftp/ssh error handling, hopefully resolving intermittent test failure in test_bad_connection_ssh.
391
        except _ssh_connection_errors, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
392
            self._raise_connection_error(host, port=port, orig_error=e)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
393
2018.1.1 by Andrew Bennetts
Make bzr+ssh:// actually work (at least with absolute paths).
394
    def connect_ssh(self, username, password, host, port, command):
395
        try:
396
            argv = self._get_vendor_specific_argv(username, host, port,
397
                                                  command=command)
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
398
            return self._connect(argv)
5430.6.1 by Andrew Bennetts
Simplify connect_sftp/ssh error handling, hopefully resolving intermittent test failure in test_bad_connection_ssh.
399
        except _ssh_connection_errors, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
400
            self._raise_connection_error(host, port=port, orig_error=e)
2018.1.1 by Andrew Bennetts
Make bzr+ssh:// actually work (at least with absolute paths).
401
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
402
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
403
                                  command=None):
404
        """Returns the argument list to run the subprocess with.
3943.8.1 by Marius Kruger
remove all trailing whitespace from bzr source
405
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
406
        Exactly one of 'subsystem' and 'command' must be specified.
407
        """
408
        raise NotImplementedError(self._get_vendor_specific_argv)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
409
410
411
class OpenSSHSubprocessVendor(SubprocessVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
412
    """SSH vendor that uses the 'ssh' executable from OpenSSH."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
413
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
414
    executable_path = 'ssh'
415
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
416
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
417
                                  command=None):
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
418
        args = [self.executable_path,
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
419
                '-oForwardX11=no', '-oForwardAgent=no',
5459.4.1 by Neil Martinsen-Burrell
dont force openssh to use protocol=2
420
                '-oClearAllForwardings=yes',
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
421
                '-oNoHostAuthenticationForLocalhost=yes']
422
        if port is not None:
423
            args.extend(['-p', str(port)])
424
        if username is not None:
425
            args.extend(['-l', username])
426
        if subsystem is not None:
427
            args.extend(['-s', host, subsystem])
428
        else:
429
            args.extend([host] + command)
430
        return args
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
431
1951.1.11 by Andrew Bennetts
Change register_ssh_vendor to take an instance rather than a class.
432
register_ssh_vendor('openssh', OpenSSHSubprocessVendor())
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
433
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
434
435
class SSHCorpSubprocessVendor(SubprocessVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
436
    """SSH vendor that uses the 'ssh' executable from SSH Corporation."""
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
437
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
438
    executable_path = 'ssh'
439
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
440
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
441
                                  command=None):
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
442
        args = [self.executable_path, '-x']
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
443
        if port is not None:
444
            args.extend(['-p', str(port)])
445
        if username is not None:
446
            args.extend(['-l', username])
447
        if subsystem is not None:
448
            args.extend(['-s', subsystem, host])
449
        else:
450
            args.extend([host] + command)
451
        return args
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
452
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
453
register_ssh_vendor('sshcorp', SSHCorpSubprocessVendor())
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
454
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
455
5444.2.1 by Matthew Gordon
Added GNU lsh support to supported SSH vendors.
456
class LSHSubprocessVendor(SubprocessVendor):
457
    """SSH vendor that uses the 'lsh' executable from GNU"""
458
459
    executable_path = 'lsh'
460
461
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
462
                                  command=None):
463
        args = [self.executable_path]
464
        if port is not None:
465
            args.extend(['-p', str(port)])
466
        if username is not None:
467
            args.extend(['-l', username])
468
        if subsystem is not None:
469
            args.extend(['--subsystem', subsystem, host])
470
        else:
471
            args.extend([host] + command)
472
        return args
473
474
register_ssh_vendor('lsh', LSHSubprocessVendor())
475
476
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
477
class PLinkSubprocessVendor(SubprocessVendor):
478
    """SSH vendor that uses the 'plink' executable from Putty."""
479
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
480
    executable_path = 'plink'
481
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
482
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
483
                                  command=None):
4595.17.1 by Martin
Add ability to give a path to a particular ssh client in BZR_SSH envvar
484
        args = [self.executable_path, '-x', '-a', '-ssh', '-2', '-batch']
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
485
        if port is not None:
486
            args.extend(['-P', str(port)])
487
        if username is not None:
488
            args.extend(['-l', username])
489
        if subsystem is not None:
2221.5.3 by Dmitry Vasiliev
Fixed plink's arguments order. Added tests for such a case.
490
            args.extend(['-s', host, subsystem])
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
491
        else:
492
            args.extend([host] + command)
493
        return args
494
495
register_ssh_vendor('plink', PLinkSubprocessVendor())
496
497
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
498
def _paramiko_auth(username, password, host, port, paramiko_transport):
4222.3.4 by Jelmer Vernooij
Default to getpass.getuser() in AuthenticationConfig.get_user(), but allow
499
    auth = config.AuthenticationConfig()
3777.1.5 by Aaron Bentley
Remove AuthenticationConfig handling from Paramiko SSHVendor
500
    # paramiko requires a username, but it might be none if nothing was
501
    # supplied.  If so, use the local username.
2900.2.15 by Vincent Ladeuil
AuthenticationConfig can be queried for logins too (first step).
502
    if username is None:
4304.2.1 by Vincent Ladeuil
Fix bug #367726 by reverting some default user handling introduced
503
        username = auth.get_user('ssh', host, port=port,
504
                                 default=getpass.getuser())
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
505
    if _use_ssh_agent:
506
        agent = paramiko.Agent()
507
        for key in agent.get_keys():
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
508
            trace.mutter('Trying SSH agent key %s'
6603.3.1 by Andrew Starr-Bochicchio
Use hexlify() from binascii directly as paramiko removed hexify().
509
                         % self._hexify(key.get_fingerprint()))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
510
            try:
511
                paramiko_transport.auth_publickey(username, key)
512
                return
513
            except paramiko.SSHException, e:
514
                pass
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
515
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
516
    # okay, try finding id_rsa or id_dss?  (posix only)
517
    if _try_pkey_auth(paramiko_transport, paramiko.RSAKey, username, 'id_rsa'):
518
        return
519
    if _try_pkey_auth(paramiko_transport, paramiko.DSSKey, username, 'id_dsa'):
520
        return
521
4555.1.1 by John Arbash Meinel
Fix bug #375867, check if password is a supported auth type
522
    # If we have gotten this far, we are about to try for passwords, do an
523
    # auth_none check to see if it is even supported.
524
    supported_auth_types = []
525
    try:
526
        # Note that with paramiko <1.7.5 this logs an INFO message:
527
        #    Authentication type (none) not permitted.
528
        # So we explicitly disable the logging level for this action
529
        old_level = paramiko_transport.logger.level
530
        paramiko_transport.logger.setLevel(logging.WARNING)
531
        try:
532
            paramiko_transport.auth_none(username)
533
        finally:
534
            paramiko_transport.logger.setLevel(old_level)
535
    except paramiko.BadAuthenticationType, e:
536
        # Supported methods are in the exception
537
        supported_auth_types = e.allowed_types
538
    except paramiko.SSHException, e:
539
        # Don't know what happened, but just ignore it
540
        pass
4634.56.1 by Andrew Bennetts
Try paramiko's auth_password if the server supports 'keyboard-interactive' auth, even if it doesn't support 'password'.
541
    # We treat 'keyboard-interactive' and 'password' auth methods identically,
542
    # because Paramiko's auth_password method will automatically try
543
    # 'keyboard-interactive' auth (using the password as the response) if
544
    # 'password' auth is not available.  Apparently some Debian and Gentoo
545
    # OpenSSH servers require this.
546
    # XXX: It's possible for a server to require keyboard-interactive auth that
547
    # requires something other than a single password, but we currently don't
548
    # support that.
549
    if ('password' not in supported_auth_types and
550
        'keyboard-interactive' not in supported_auth_types):
4555.1.1 by John Arbash Meinel
Fix bug #375867, check if password is a supported auth type
551
        raise errors.ConnectionError('Unable to authenticate to SSH host as'
4555.1.3 by John Arbash Meinel
Reformat the errors so they aren't so long.
552
            '\n  %s@%s\nsupported auth types: %s'
4555.1.1 by John Arbash Meinel
Fix bug #375867, check if password is a supported auth type
553
            % (username, host, supported_auth_types))
554
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
555
    if password:
556
        try:
557
            paramiko_transport.auth_password(username, password)
558
            return
559
        except paramiko.SSHException, e:
560
            pass
561
562
    # give up and ask for a password
2900.2.12 by Vincent Ladeuil
Since all schemes query AuthenticationConfig then prompt user, make that
563
    password = auth.get_password('ssh', host, username, port=port)
4555.1.1 by John Arbash Meinel
Fix bug #375867, check if password is a supported auth type
564
    # get_password can still return None, which means we should not prompt
565
    if password is not None:
566
        try:
567
            paramiko_transport.auth_password(username, password)
568
        except paramiko.SSHException, e:
4555.1.3 by John Arbash Meinel
Reformat the errors so they aren't so long.
569
            raise errors.ConnectionError(
570
                'Unable to authenticate to SSH host as'
571
                '\n  %s@%s\n' % (username, host), e)
4555.1.1 by John Arbash Meinel
Fix bug #375867, check if password is a supported auth type
572
    else:
4555.1.3 by John Arbash Meinel
Reformat the errors so they aren't so long.
573
        raise errors.ConnectionError('Unable to authenticate to SSH host as'
574
                                     '  %s@%s' % (username, host))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
575
576
577
def _try_pkey_auth(paramiko_transport, pkey_class, username, filename):
578
    filename = os.path.expanduser('~/.ssh/' + filename)
579
    try:
580
        key = pkey_class.from_private_key_file(filename)
581
        paramiko_transport.auth_publickey(username, key)
582
        return True
583
    except paramiko.PasswordRequiredException:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
584
        password = ui.ui_factory.get_password(
5863.6.1 by Jelmer Vernooij
Require a unicode prompt to be passed into all methods that prompt.
585
            prompt=u'SSH %(filename)s password',
586
            filename=filename.decode(osutils._fs_enc))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
587
        try:
588
            key = pkey_class.from_private_key_file(filename, password)
589
            paramiko_transport.auth_publickey(username, key)
590
            return True
591
        except paramiko.SSHException:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
592
            trace.mutter('SSH authentication via %s key failed.'
593
                         % (os.path.basename(filename),))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
594
    except paramiko.SSHException:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
595
        trace.mutter('SSH authentication via %s key failed.'
596
                     % (os.path.basename(filename),))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
597
    except IOError:
598
        pass
599
    return False
600
601
602
def load_host_keys():
603
    """
604
    Load system host keys (probably doesn't work on windows) and any
605
    "discovered" keys from previous sessions.
606
    """
607
    global SYSTEM_HOSTKEYS, BZR_HOSTKEYS
608
    try:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
609
        SYSTEM_HOSTKEYS = paramiko.util.load_host_keys(
610
            os.path.expanduser('~/.ssh/known_hosts'))
2358.3.1 by Martin Pool
Update some too-general exception blocks
611
    except IOError, e:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
612
        trace.mutter('failed to load system host keys: ' + str(e))
613
    bzr_hostkey_path = osutils.pathjoin(config.config_dir(), 'ssh_host_keys')
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
614
    try:
615
        BZR_HOSTKEYS = paramiko.util.load_host_keys(bzr_hostkey_path)
2358.3.1 by Martin Pool
Update some too-general exception blocks
616
    except IOError, e:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
617
        trace.mutter('failed to load bzr host keys: ' + str(e))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
618
        save_host_keys()
619
620
621
def save_host_keys():
622
    """
623
    Save "discovered" host keys in $(config)/ssh_host_keys/.
624
    """
625
    global SYSTEM_HOSTKEYS, BZR_HOSTKEYS
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
626
    bzr_hostkey_path = osutils.pathjoin(config.config_dir(), 'ssh_host_keys')
627
    config.ensure_config_dir_exists()
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
628
629
    try:
630
        f = open(bzr_hostkey_path, 'w')
631
        f.write('# SSH host keys collected by bzr\n')
632
        for hostname, keys in BZR_HOSTKEYS.iteritems():
633
            for keytype, key in keys.iteritems():
634
                f.write('%s %s %s\n' % (hostname, keytype, key.get_base64()))
635
        f.close()
636
    except IOError, e:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
637
        trace.mutter('failed to save bzr host keys: ' + str(e))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
638
639
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
640
def os_specific_subprocess_params():
641
    """Get O/S specific subprocess parameters."""
642
    if sys.platform == 'win32':
3943.8.1 by Marius Kruger
remove all trailing whitespace from bzr source
643
        # setting the process group and closing fds is not supported on
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
644
        # win32
645
        return {}
646
    else:
3943.8.1 by Marius Kruger
remove all trailing whitespace from bzr source
647
        # We close fds other than the pipes as the child process does not need
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
648
        # them to be open.
649
        #
650
        # We also set the child process to ignore SIGINT.  Normally the signal
651
        # would be sent to every process in the foreground process group, but
652
        # this causes it to be seen only by bzr and not by ssh.  Python will
653
        # generate a KeyboardInterrupt in bzr, and we will then have a chance
654
        # to release locks or do other cleanup over ssh before the connection
3943.8.1 by Marius Kruger
remove all trailing whitespace from bzr source
655
        # goes away.
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
656
        # <https://launchpad.net/products/bzr/+bug/5987>
657
        #
658
        # Running it in a separate process group is not good because then it
659
        # can't get non-echoed input of a password or passphrase.
660
        # <https://launchpad.net/products/bzr/+bug/40508>
5050.2.1 by Martin
Drive-by fix for breakin killing off ssh child processes
661
        return {'preexec_fn': _ignore_signals,
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
662
                'close_fds': True,
663
                }
664
4824.1.1 by Andrew Bennetts
Terminate SSHSubprocesses when no refs to them are left, in case .close is never called.
665
import weakref
666
_subproc_weakrefs = set()
667
5050.54.1 by Max Bowsher
Do close the socket used for stdin/out to a ssh subprocess.
668
def _close_ssh_proc(proc, sock):
5050.30.1 by Andrew Bennetts
Fix AttributeError in _close_ssh_proc.
669
    """Carefully close stdin/stdout and reap the SSH process.
670
671
    If the pipes are already closed and/or the process has already been
672
    wait()ed on, that's ok, and no error is raised.  The goal is to do our best
673
    to clean up (whether or not a clean up was already tried).
674
    """
5050.54.1 by Max Bowsher
Do close the socket used for stdin/out to a ssh subprocess.
675
    funcs = []
676
    for closeable in (proc.stdin, proc.stdout, sock):
677
        # We expect that either proc (a subprocess.Popen) will have stdin and
678
        # stdout streams to close, or that we will have been passed a socket to
679
        # close, with the option not in use being None.
680
        if closeable is not None:
681
            funcs.append(closeable.close)
682
    funcs.append(proc.wait)
683
    for func in funcs:
684
        try:
685
            func()
4824.1.1 by Andrew Bennetts
Terminate SSHSubprocesses when no refs to them are left, in case .close is never called.
686
        except OSError:
5050.30.1 by Andrew Bennetts
Fix AttributeError in _close_ssh_proc.
687
            # It's ok for the pipe to already be closed, or the process to
688
            # already be finished.
689
            continue
4824.1.1 by Andrew Bennetts
Terminate SSHSubprocesses when no refs to them are left, in case .close is never called.
690
1951.1.12 by Andrew Bennetts
Cosmetic tweaks.
691
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
692
class SSHConnection(object):
693
    """Abstract base class for SSH connections."""
694
695
    def get_sock_or_pipes(self):
696
        """Returns a (kind, io_object) pair.
697
698
        If kind == 'socket', then io_object is a socket.
699
700
        If kind == 'pipes', then io_object is a pair of file-like objects
701
        (read_from, write_to).
702
        """
703
        raise NotImplementedError(self.get_sock_or_pipes)
704
705
    def close(self):
706
        raise NotImplementedError(self.close)
707
708
709
class SSHSubprocessConnection(SSHConnection):
5284.5.3 by Andrew Bennetts
Docstring tweaks.
710
    """A connection to an ssh subprocess via pipes or a socket.
711
712
    This class is also socket-like enough to be used with
713
    SocketAsChannelAdapter (it has 'send' and 'recv' methods).
714
    """
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
715
716
    def __init__(self, proc, sock=None):
717
        """Constructor.
718
719
        :param proc: a subprocess.Popen
720
        :param sock: if proc.stdin/out is a socket from a socketpair, then sock
721
            should bzrlib's half of that socketpair.  If not passed, proc's
722
            stdin/out is assumed to be ordinary pipes.
723
        """
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
724
        self.proc = proc
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
725
        self._sock = sock
4824.1.1 by Andrew Bennetts
Terminate SSHSubprocesses when no refs to them are left, in case .close is never called.
726
        # Add a weakref to proc that will attempt to do the same as self.close
727
        # to avoid leaving processes lingering indefinitely.
728
        def terminate(ref):
729
            _subproc_weakrefs.remove(ref)
5050.54.1 by Max Bowsher
Do close the socket used for stdin/out to a ssh subprocess.
730
            _close_ssh_proc(proc, sock)
4824.1.1 by Andrew Bennetts
Terminate SSHSubprocesses when no refs to them are left, in case .close is never called.
731
        _subproc_weakrefs.add(weakref.ref(self, terminate))
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
732
733
    def send(self, data):
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
734
        if self._sock is not None:
735
            return self._sock.send(data)
736
        else:
737
            return os.write(self.proc.stdin.fileno(), data)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
738
739
    def recv(self, count):
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
740
        if self._sock is not None:
5303.1.1 by Vincent Ladeuil
Fix typo: recv() on sockets, read() on files ;)
741
            return self._sock.recv(count)
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
742
        else:
743
            return os.read(self.proc.stdout.fileno(), count)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
744
745
    def close(self):
5050.54.1 by Max Bowsher
Do close the socket used for stdin/out to a ssh subprocess.
746
        _close_ssh_proc(self.proc, self._sock)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
747
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
748
    def get_sock_or_pipes(self):
749
        if self._sock is not None:
750
            return 'socket', self._sock
751
        else:
752
            return 'pipes', (self.proc.stdout, self.proc.stdin)
753
754
755
class _ParamikoSSHConnection(SSHConnection):
5284.5.3 by Andrew Bennetts
Docstring tweaks.
756
    """An SSH connection via paramiko."""
757
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
758
    def __init__(self, channel):
759
        self.channel = channel
760
761
    def get_sock_or_pipes(self):
5284.5.2 by Andrew Bennetts
Use the socket-medium with paramiko connections as well as socketpair-to-subprocess connections, as quick inspection of the paramiko source suggests it handles EINTR ok.
762
        return ('socket', self.channel)
5284.5.1 by Andrew Bennetts
Use socketpairs (rather than pipes) for SSH subprocesses where possible, and formalise some internal APIs a little more.
763
764
    def close(self):
765
        return self.channel.close()
766
2221.5.21 by Dmitry Vasiliev
Reverted trailing whitespace removal
767