/brz/remove-bazaar

To get this branch, use:
bzr branch http://gegoxaren.bato24.eu/bzr/brz/remove-bazaar
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
1
# Copyright (C) 2005 Robey Pointer <robey@lag.net>
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
2
# Copyright (C) 2005, 2006, 2007 Canonical Ltd
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
3
#
4
# This program is free software; you can redistribute it and/or modify
5
# it under the terms of the GNU General Public License as published by
6
# the Free Software Foundation; either version 2 of the License, or
7
# (at your option) any later version.
8
#
9
# This program is distributed in the hope that it will be useful,
10
# but WITHOUT ANY WARRANTY; without even the implied warranty of
11
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
12
# GNU General Public License for more details.
13
#
14
# You should have received a copy of the GNU General Public License
15
# along with this program; if not, write to the Free Software
16
# Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
17
18
"""Foundation SSH support for SFTP and smart server."""
19
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
20
import errno
1951.1.5 by Andrew Bennetts
Fix some missing imports with a bit of help from pyflakes.
21
import getpass
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
22
import os
23
import socket
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
24
import subprocess
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
25
import sys
26
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
27
from bzrlib import (
28
    config,
29
    errors,
30
    osutils,
31
    trace,
32
    ui,
33
    )
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
34
35
try:
36
    import paramiko
37
except ImportError, e:
2104.5.1 by John Arbash Meinel
Remove the strict dependency on paramiko for ssh access
38
    # If we have an ssh subprocess, we don't strictly need paramiko for all ssh
39
    # access
40
    paramiko = None
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
41
else:
42
    from paramiko.sftp_client import SFTPClient
43
44
45
SYSTEM_HOSTKEYS = {}
46
BZR_HOSTKEYS = {}
47
48
1951.1.5 by Andrew Bennetts
Fix some missing imports with a bit of help from pyflakes.
49
_paramiko_version = getattr(paramiko, '__version_info__', (0, 0, 0))
50
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
51
# Paramiko 1.5 tries to open a socket.AF_UNIX in order to connect
52
# to ssh-agent. That attribute doesn't exist on win32 (it does in cygwin)
53
# so we get an AttributeError exception. So we will not try to
54
# connect to an agent if we are on win32 and using Paramiko older than 1.6
55
_use_ssh_agent = (sys.platform != 'win32' or _paramiko_version >= (1, 6, 0))
56
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
57
58
class SSHVendorManager(object):
59
    """Manager for manage SSH vendors."""
60
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
61
    # Note, although at first sign the class interface seems similar to
2221.5.22 by Dmitry Vasiliev
Updated note about registry.Registry
62
    # bzrlib.registry.Registry it is not possible/convenient to directly use
63
    # the Registry because the class just has "get()" interface instead of the
64
    # Registry's "get(key)".
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
65
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
66
    def __init__(self):
67
        self._ssh_vendors = {}
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
68
        self._cached_ssh_vendor = None
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
69
        self._default_ssh_vendor = None
70
71
    def register_default_vendor(self, vendor):
72
        """Register default SSH vendor."""
73
        self._default_ssh_vendor = vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
74
75
    def register_vendor(self, name, vendor):
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
76
        """Register new SSH vendor by name."""
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
77
        self._ssh_vendors[name] = vendor
78
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
79
    def clear_cache(self):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
80
        """Clear previously cached lookup result."""
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
81
        self._cached_ssh_vendor = None
82
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
83
    def _get_vendor_by_environment(self, environment=None):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
84
        """Return the vendor or None based on BZR_SSH environment variable.
85
86
        :raises UnknownSSH: if the BZR_SSH environment variable contains
87
                            unknown vendor name
88
        """
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
89
        if environment is None:
90
            environment = os.environ
91
        if 'BZR_SSH' in environment:
92
            vendor_name = environment['BZR_SSH']
93
            try:
94
                vendor = self._ssh_vendors[vendor_name]
95
            except KeyError:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
96
                raise errors.UnknownSSH(vendor_name)
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
97
            return vendor
98
        return None
99
100
    def _get_ssh_version_string(self, args):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
101
        """Return SSH version string from the subprocess."""
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
102
        try:
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
103
            p = subprocess.Popen(args,
104
                                 stdout=subprocess.PIPE,
105
                                 stderr=subprocess.PIPE,
106
                                 **os_specific_subprocess_params())
107
            stdout, stderr = p.communicate()
108
        except OSError:
109
            stdout = stderr = ''
110
        return stdout + stderr
111
2772.3.1 by Martin Pool
Fix detection of ssh implementation on Windows
112
    def _get_vendor_by_version_string(self, version, args):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
113
        """Return the vendor or None based on output from the subprocess.
114
115
        :param version: The output of 'ssh -V' like command.
2772.3.1 by Martin Pool
Fix detection of ssh implementation on Windows
116
        :param args: Command line that was run.
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
117
        """
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
118
        vendor = None
119
        if 'OpenSSH' in version:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
120
            trace.mutter('ssh implementation is OpenSSH')
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
121
            vendor = OpenSSHSubprocessVendor()
122
        elif 'SSH Secure Shell' in version:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
123
            trace.mutter('ssh implementation is SSH Corp.')
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
124
            vendor = SSHCorpSubprocessVendor()
2772.3.1 by Martin Pool
Fix detection of ssh implementation on Windows
125
        elif 'plink' in version and args[0] == 'plink':
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
126
            # Checking if "plink" was the executed argument as Windows
127
            # sometimes reports 'ssh -V' incorrectly with 'plink' in it's
128
            # version.  See https://bugs.launchpad.net/bzr/+bug/107155
129
            trace.mutter("ssh implementation is Putty's plink.")
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
130
            vendor = PLinkSubprocessVendor()
131
        return vendor
132
133
    def _get_vendor_by_inspection(self):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
134
        """Return the vendor or None by checking for known SSH implementations."""
2989.2.1 by Alexander Belchenko
Disable detection of plink.exe as possible ssh vendor.
135
        # detection of plink vendor is disabled because of bug #107593
136
        # https://bugs.launchpad.net/bzr/+bug/107593
137
        # who want plink should explicitly enable it with BZR_SSH environment
138
        # variable.
2989.2.3 by Alexander Belchenko
fix test_get_vendor_by_inspection_plink
139
        #~for args in (['ssh', '-V'], ['plink', '-V']):
2989.2.1 by Alexander Belchenko
Disable detection of plink.exe as possible ssh vendor.
140
        for args in (['ssh', '-V'],):
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
141
            version = self._get_ssh_version_string(args)
2767.3.1 by Martin Albisetti
Fixed bug #107155
142
            vendor = self._get_vendor_by_version_string(version, args)
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
143
            if vendor is not None:
144
                return vendor
145
        return None
146
147
    def get_vendor(self, environment=None):
2221.5.15 by Dmitry Vasiliev
Added docstrings for all SSHVendorManager's methods
148
        """Find out what version of SSH is on the system.
149
150
        :raises SSHVendorNotFound: if no any SSH vendor is found
151
        :raises UnknownSSH: if the BZR_SSH environment variable contains
152
                            unknown vendor name
153
        """
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
154
        if self._cached_ssh_vendor is None:
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
155
            vendor = self._get_vendor_by_environment(environment)
156
            if vendor is None:
157
                vendor = self._get_vendor_by_inspection()
158
                if vendor is None:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
159
                    trace.mutter('falling back to default implementation')
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
160
                    vendor = self._default_ssh_vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
161
                    if vendor is None:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
162
                        raise errors.SSHVendorNotFound()
2221.5.8 by Dmitry Vasiliev
Added SSHVendorManager.clear_cache() method
163
            self._cached_ssh_vendor = vendor
164
        return self._cached_ssh_vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
165
166
_ssh_vendor_manager = SSHVendorManager()
167
_get_ssh_vendor = _ssh_vendor_manager.get_vendor
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
168
register_default_ssh_vendor = _ssh_vendor_manager.register_default_vendor
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
169
register_ssh_vendor = _ssh_vendor_manager.register_vendor
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
170
171
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
172
def _ignore_sigint():
173
    # TODO: This should possibly ignore SIGHUP as well, but bzr currently
174
    # doesn't handle it itself.
175
    # <https://launchpad.net/products/bzr/+bug/41433/+index>
176
    import signal
177
    signal.signal(signal.SIGINT, signal.SIG_IGN)
178
179
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
180
class LoopbackSFTP(object):
181
    """Simple wrapper for a socket that pretends to be a paramiko Channel."""
182
183
    def __init__(self, sock):
184
        self.__socket = sock
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
185
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
186
    def send(self, data):
187
        return self.__socket.send(data)
188
189
    def recv(self, n):
190
        return self.__socket.recv(n)
191
192
    def recv_ready(self):
193
        return True
194
195
    def close(self):
196
        self.__socket.close()
197
198
199
class SSHVendor(object):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
200
    """Abstract base class for SSH vendor implementations."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
201
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
202
    def connect_sftp(self, username, password, host, port):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
203
        """Make an SSH connection, and return an SFTPClient.
2221.5.21 by Dmitry Vasiliev
Reverted trailing whitespace removal
204
        
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
205
        :param username: an ascii string
206
        :param password: an ascii string
207
        :param host: a host name as an ascii string
208
        :param port: a port number
209
        :type port: int
210
211
        :raises: ConnectionError if it cannot connect.
212
213
        :rtype: paramiko.sftp_client.SFTPClient
214
        """
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
215
        raise NotImplementedError(self.connect_sftp)
216
217
    def connect_ssh(self, username, password, host, port, command):
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
218
        """Make an SSH connection.
2221.5.21 by Dmitry Vasiliev
Reverted trailing whitespace removal
219
        
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
220
        :returns: something with a `close` method, and a `get_filelike_channels`
221
            method that returns a pair of (read, write) filelike objects.
1951.1.12 by Andrew Bennetts
Cosmetic tweaks.
222
        """
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
223
        raise NotImplementedError(self.connect_ssh)
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
224
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
225
    def _raise_connection_error(self, host, port=None, orig_error=None,
2052.4.4 by John Arbash Meinel
Create a SocketConnectionError to make creating nice errors easier
226
                                msg='Unable to connect to SSH host'):
227
        """Raise a SocketConnectionError with properly formatted host.
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
228
229
        This just unifies all the locations that try to raise ConnectionError,
230
        so that they format things properly.
231
        """
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
232
        raise errors.SocketConnectionError(host=host, port=port, msg=msg,
233
                                           orig_error=orig_error)
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
234
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
235
236
class LoopbackVendor(SSHVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
237
    """SSH "vendor" that connects over a plain TCP socket, not SSH."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
238
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
239
    def connect_sftp(self, username, password, host, port):
240
        sock = socket.socket()
241
        try:
242
            sock.connect((host, port))
243
        except socket.error, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
244
            self._raise_connection_error(host, port=port, orig_error=e)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
245
        return SFTPClient(LoopbackSFTP(sock))
246
1951.1.11 by Andrew Bennetts
Change register_ssh_vendor to take an instance rather than a class.
247
register_ssh_vendor('loopback', LoopbackVendor())
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
248
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
249
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
250
class _ParamikoSSHConnection(object):
251
    def __init__(self, channel):
252
        self.channel = channel
253
254
    def get_filelike_channels(self):
255
        return self.channel.makefile('rb'), self.channel.makefile('wb')
256
257
    def close(self):
258
        return self.channel.close()
259
260
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
261
class ParamikoVendor(SSHVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
262
    """Vendor that uses paramiko."""
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
263
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
264
    def _connect(self, username, password, host, port):
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
265
        global SYSTEM_HOSTKEYS, BZR_HOSTKEYS
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
266
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
267
        load_host_keys()
268
269
        try:
270
            t = paramiko.Transport((host, port or 22))
271
            t.set_log_channel('bzr.paramiko')
272
            t.start_client()
273
        except (paramiko.SSHException, socket.error), e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
274
            self._raise_connection_error(host, port=port, orig_error=e)
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
275
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
276
        server_key = t.get_remote_server_key()
277
        server_key_hex = paramiko.util.hexify(server_key.get_fingerprint())
278
        keytype = server_key.get_name()
1711.9.10 by John Arbash Meinel
Update transport/ssh.py to remove has_key usage
279
        if host in SYSTEM_HOSTKEYS and keytype in SYSTEM_HOSTKEYS[host]:
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
280
            our_server_key = SYSTEM_HOSTKEYS[host][keytype]
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
281
            our_server_key_hex = paramiko.util.hexify(
282
                our_server_key.get_fingerprint())
1711.9.10 by John Arbash Meinel
Update transport/ssh.py to remove has_key usage
283
        elif host in BZR_HOSTKEYS and keytype in BZR_HOSTKEYS[host]:
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
284
            our_server_key = BZR_HOSTKEYS[host][keytype]
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
285
            our_server_key_hex = paramiko.util.hexify(
286
                our_server_key.get_fingerprint())
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
287
        else:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
288
            trace.warning('Adding %s host key for %s: %s'
289
                          % (keytype, host, server_key_hex))
2127.3.1 by Alexander Belchenko
Use BZR_HOSTKEYS.add instead of deprecated dict-like paramiko interface
290
            add = getattr(BZR_HOSTKEYS, 'add', None)
291
            if add is not None: # paramiko >= 1.X.X
292
                BZR_HOSTKEYS.add(host, keytype, server_key)
293
            else:
1551.9.2 by Aaron Bentley
Bugfix for paramiko connections
294
                BZR_HOSTKEYS.setdefault(host, {})[keytype] = server_key
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
295
            our_server_key = server_key
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
296
            our_server_key_hex = paramiko.util.hexify(
297
                our_server_key.get_fingerprint())
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
298
            save_host_keys()
299
        if server_key != our_server_key:
300
            filename1 = os.path.expanduser('~/.ssh/known_hosts')
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
301
            filename2 = osutils.pathjoin(config.config_dir(), 'ssh_host_keys')
302
            raise errors.TransportError(
303
                'Host keys for %s do not match!  %s != %s' %
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
304
                (host, our_server_key_hex, server_key_hex),
305
                ['Try editing %s or %s' % (filename1, filename2)])
306
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
307
        _paramiko_auth(username, password, host, port, t)
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
308
        return t
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
309
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
310
    def connect_sftp(self, username, password, host, port):
311
        t = self._connect(username, password, host, port)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
312
        try:
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
313
            return t.open_sftp_client()
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
314
        except paramiko.SSHException, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
315
            self._raise_connection_error(host, port=port, orig_error=e,
2052.4.4 by John Arbash Meinel
Create a SocketConnectionError to make creating nice errors easier
316
                                         msg='Unable to start sftp client')
2018.1.9 by Andrew Bennetts
Implement ParamikoVendor.connect_ssh
317
318
    def connect_ssh(self, username, password, host, port, command):
319
        t = self._connect(username, password, host, port)
320
        try:
321
            channel = t.open_session()
322
            cmdline = ' '.join(command)
323
            channel.exec_command(cmdline)
324
            return _ParamikoSSHConnection(channel)
325
        except paramiko.SSHException, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
326
            self._raise_connection_error(host, port=port, orig_error=e,
2052.4.4 by John Arbash Meinel
Create a SocketConnectionError to make creating nice errors easier
327
                                         msg='Unable to invoke remote bzr')
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
328
2104.5.1 by John Arbash Meinel
Remove the strict dependency on paramiko for ssh access
329
if paramiko is not None:
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
330
    vendor = ParamikoVendor()
331
    register_ssh_vendor('paramiko', vendor)
332
    register_ssh_vendor('none', vendor)
2221.5.5 by Dmitry Vasiliev
Added 'register_default_vendor' method to the SSHVendorManager
333
    register_default_ssh_vendor(vendor)
3066.2.1 by John Arbash Meinel
We don't require paramiko for bzr+ssh.
334
    _sftp_connection_errors = (EOFError, paramiko.SSHException)
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
335
    del vendor
3066.2.1 by John Arbash Meinel
We don't require paramiko for bzr+ssh.
336
else:
337
    _sftp_connection_errors = (EOFError,)
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
338
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
339
340
class SubprocessVendor(SSHVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
341
    """Abstract base class for vendors that use pipes to a subprocess."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
342
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
343
    def _connect(self, argv):
344
        proc = subprocess.Popen(argv,
345
                                stdin=subprocess.PIPE,
346
                                stdout=subprocess.PIPE,
347
                                **os_specific_subprocess_params())
348
        return SSHSubprocess(proc)
349
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
350
    def connect_sftp(self, username, password, host, port):
351
        try:
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
352
            argv = self._get_vendor_specific_argv(username, host, port,
353
                                                  subsystem='sftp')
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
354
            sock = self._connect(argv)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
355
            return SFTPClient(sock)
3066.2.1 by John Arbash Meinel
We don't require paramiko for bzr+ssh.
356
        except _sftp_connection_errors, e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
357
            self._raise_connection_error(host, port=port, orig_error=e)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
358
        except (OSError, IOError), e:
359
            # If the machine is fast enough, ssh can actually exit
360
            # before we try and send it the sftp request, which
361
            # raises a Broken Pipe
362
            if e.errno not in (errno.EPIPE,):
363
                raise
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
364
            self._raise_connection_error(host, port=port, orig_error=e)
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
365
2018.1.1 by Andrew Bennetts
Make bzr+ssh:// actually work (at least with absolute paths).
366
    def connect_ssh(self, username, password, host, port, command):
367
        try:
368
            argv = self._get_vendor_specific_argv(username, host, port,
369
                                                  command=command)
2018.1.6 by Andrew Bennetts
Remove a little bit of duplication in ssh.py
370
            return self._connect(argv)
371
        except (EOFError), e:
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
372
            self._raise_connection_error(host, port=port, orig_error=e)
2018.1.1 by Andrew Bennetts
Make bzr+ssh:// actually work (at least with absolute paths).
373
        except (OSError, IOError), e:
374
            # If the machine is fast enough, ssh can actually exit
375
            # before we try and send it the sftp request, which
376
            # raises a Broken Pipe
377
            if e.errno not in (errno.EPIPE,):
378
                raise
2052.4.2 by John Arbash Meinel
Refactor all 'raise ConnectionError' into a helper function
379
            self._raise_connection_error(host, port=port, orig_error=e)
2018.1.1 by Andrew Bennetts
Make bzr+ssh:// actually work (at least with absolute paths).
380
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
381
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
382
                                  command=None):
383
        """Returns the argument list to run the subprocess with.
2221.5.21 by Dmitry Vasiliev
Reverted trailing whitespace removal
384
        
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
385
        Exactly one of 'subsystem' and 'command' must be specified.
386
        """
387
        raise NotImplementedError(self._get_vendor_specific_argv)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
388
389
390
class OpenSSHSubprocessVendor(SubprocessVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
391
    """SSH vendor that uses the 'ssh' executable from OpenSSH."""
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
392
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
393
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
394
                                  command=None):
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
395
        assert subsystem is not None or command is not None, (
396
            'Must specify a command or subsystem')
397
        if subsystem is not None:
398
            assert command is None, (
399
                'subsystem and command are mutually exclusive')
400
        args = ['ssh',
401
                '-oForwardX11=no', '-oForwardAgent=no',
402
                '-oClearAllForwardings=yes', '-oProtocol=2',
403
                '-oNoHostAuthenticationForLocalhost=yes']
404
        if port is not None:
405
            args.extend(['-p', str(port)])
406
        if username is not None:
407
            args.extend(['-l', username])
408
        if subsystem is not None:
409
            args.extend(['-s', host, subsystem])
410
        else:
411
            args.extend([host] + command)
412
        return args
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
413
1951.1.11 by Andrew Bennetts
Change register_ssh_vendor to take an instance rather than a class.
414
register_ssh_vendor('openssh', OpenSSHSubprocessVendor())
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
415
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
416
417
class SSHCorpSubprocessVendor(SubprocessVendor):
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
418
    """SSH vendor that uses the 'ssh' executable from SSH Corporation."""
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
419
1951.1.9 by Andrew Bennetts
Add docstrings and tweak method names in ssh.py
420
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
421
                                  command=None):
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
422
        assert subsystem is not None or command is not None, (
423
            'Must specify a command or subsystem')
424
        if subsystem is not None:
425
            assert command is None, (
426
                'subsystem and command are mutually exclusive')
427
        args = ['ssh', '-x']
428
        if port is not None:
429
            args.extend(['-p', str(port)])
430
        if username is not None:
431
            args.extend(['-l', username])
432
        if subsystem is not None:
433
            args.extend(['-s', subsystem, host])
434
        else:
435
            args.extend([host] + command)
436
        return args
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
437
1951.1.11 by Andrew Bennetts
Change register_ssh_vendor to take an instance rather than a class.
438
register_ssh_vendor('ssh', SSHCorpSubprocessVendor())
1951.1.10 by Andrew Bennetts
Move register_ssh_vendor, _ssh_vendor and _get_ssh_vendor into ssh.py
439
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
440
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
441
class PLinkSubprocessVendor(SubprocessVendor):
442
    """SSH vendor that uses the 'plink' executable from Putty."""
443
444
    def _get_vendor_specific_argv(self, username, host, port, subsystem=None,
445
                                  command=None):
446
        assert subsystem is not None or command is not None, (
447
            'Must specify a command or subsystem')
448
        if subsystem is not None:
449
            assert command is None, (
450
                'subsystem and command are mutually exclusive')
451
        args = ['plink', '-x', '-a', '-ssh', '-2']
452
        if port is not None:
453
            args.extend(['-P', str(port)])
454
        if username is not None:
455
            args.extend(['-l', username])
456
        if subsystem is not None:
2221.5.3 by Dmitry Vasiliev
Fixed plink's arguments order. Added tests for such a case.
457
            args.extend(['-s', host, subsystem])
2221.5.1 by Dmitry Vasiliev
Added support for Putty's SSH implementation
458
        else:
459
            args.extend([host] + command)
460
        return args
461
462
register_ssh_vendor('plink', PLinkSubprocessVendor())
463
464
2900.2.8 by Vincent Ladeuil
Make sftp and bzr+ssh aware of authentication config.
465
def _paramiko_auth(username, password, host, port, paramiko_transport):
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
466
    # paramiko requires a username, but it might be none if nothing was supplied
467
    # use the local username, just in case.
468
    # We don't override username, because if we aren't using paramiko,
469
    # the username might be specified in ~/.ssh/config and we don't want to
470
    # force it to something else
471
    # Also, it would mess up the self.relpath() functionality
2900.2.15 by Vincent Ladeuil
AuthenticationConfig can be queried for logins too (first step).
472
    auth = config.AuthenticationConfig()
473
    if username is None:
474
        username = auth.get_user('ssh', host, port=port)
475
        if username is None:
476
            # Default to local user
477
            username = getpass.getuser()
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
478
479
    if _use_ssh_agent:
480
        agent = paramiko.Agent()
481
        for key in agent.get_keys():
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
482
            trace.mutter('Trying SSH agent key %s'
483
                         % paramiko.util.hexify(key.get_fingerprint()))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
484
            try:
485
                paramiko_transport.auth_publickey(username, key)
486
                return
487
            except paramiko.SSHException, e:
488
                pass
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
489
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
490
    # okay, try finding id_rsa or id_dss?  (posix only)
491
    if _try_pkey_auth(paramiko_transport, paramiko.RSAKey, username, 'id_rsa'):
492
        return
493
    if _try_pkey_auth(paramiko_transport, paramiko.DSSKey, username, 'id_dsa'):
494
        return
495
496
    if password:
497
        try:
498
            paramiko_transport.auth_password(username, password)
499
            return
500
        except paramiko.SSHException, e:
501
            pass
502
503
    # give up and ask for a password
2900.2.12 by Vincent Ladeuil
Since all schemes query AuthenticationConfig then prompt user, make that
504
    password = auth.get_password('ssh', host, username, port=port)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
505
    try:
506
        paramiko_transport.auth_password(username, password)
507
    except paramiko.SSHException, e:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
508
        raise errors.ConnectionError(
509
            'Unable to authenticate to SSH host as %s@%s' % (username, host), e)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
510
511
512
def _try_pkey_auth(paramiko_transport, pkey_class, username, filename):
513
    filename = os.path.expanduser('~/.ssh/' + filename)
514
    try:
515
        key = pkey_class.from_private_key_file(filename)
516
        paramiko_transport.auth_publickey(username, key)
517
        return True
518
    except paramiko.PasswordRequiredException:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
519
        password = ui.ui_factory.get_password(
520
            prompt='SSH %(filename)s password', filename=filename)
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
521
        try:
522
            key = pkey_class.from_private_key_file(filename, password)
523
            paramiko_transport.auth_publickey(username, key)
524
            return True
525
        except paramiko.SSHException:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
526
            trace.mutter('SSH authentication via %s key failed.'
527
                         % (os.path.basename(filename),))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
528
    except paramiko.SSHException:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
529
        trace.mutter('SSH authentication via %s key failed.'
530
                     % (os.path.basename(filename),))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
531
    except IOError:
532
        pass
533
    return False
534
535
536
def load_host_keys():
537
    """
538
    Load system host keys (probably doesn't work on windows) and any
539
    "discovered" keys from previous sessions.
540
    """
541
    global SYSTEM_HOSTKEYS, BZR_HOSTKEYS
542
    try:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
543
        SYSTEM_HOSTKEYS = paramiko.util.load_host_keys(
544
            os.path.expanduser('~/.ssh/known_hosts'))
2358.3.1 by Martin Pool
Update some too-general exception blocks
545
    except IOError, e:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
546
        trace.mutter('failed to load system host keys: ' + str(e))
547
    bzr_hostkey_path = osutils.pathjoin(config.config_dir(), 'ssh_host_keys')
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
548
    try:
549
        BZR_HOSTKEYS = paramiko.util.load_host_keys(bzr_hostkey_path)
2358.3.1 by Martin Pool
Update some too-general exception blocks
550
    except IOError, e:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
551
        trace.mutter('failed to load bzr host keys: ' + str(e))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
552
        save_host_keys()
553
554
555
def save_host_keys():
556
    """
557
    Save "discovered" host keys in $(config)/ssh_host_keys/.
558
    """
559
    global SYSTEM_HOSTKEYS, BZR_HOSTKEYS
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
560
    bzr_hostkey_path = osutils.pathjoin(config.config_dir(), 'ssh_host_keys')
561
    config.ensure_config_dir_exists()
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
562
563
    try:
564
        f = open(bzr_hostkey_path, 'w')
565
        f.write('# SSH host keys collected by bzr\n')
566
        for hostname, keys in BZR_HOSTKEYS.iteritems():
567
            for keytype, key in keys.iteritems():
568
                f.write('%s %s %s\n' % (hostname, keytype, key.get_base64()))
569
        f.close()
570
    except IOError, e:
2900.2.18 by Vincent Ladeuil
Previous commits didn't check the test suite enough.
571
        trace.mutter('failed to save bzr host keys: ' + str(e))
1951.1.4 by Andrew Bennetts
Start moving SSH connection code into bzrlib/transport/ssh.py
572
573
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
574
def os_specific_subprocess_params():
575
    """Get O/S specific subprocess parameters."""
576
    if sys.platform == 'win32':
577
        # setting the process group and closing fds is not supported on 
578
        # win32
579
        return {}
580
    else:
581
        # We close fds other than the pipes as the child process does not need 
582
        # them to be open.
583
        #
584
        # We also set the child process to ignore SIGINT.  Normally the signal
585
        # would be sent to every process in the foreground process group, but
586
        # this causes it to be seen only by bzr and not by ssh.  Python will
587
        # generate a KeyboardInterrupt in bzr, and we will then have a chance
588
        # to release locks or do other cleanup over ssh before the connection
589
        # goes away.  
590
        # <https://launchpad.net/products/bzr/+bug/5987>
591
        #
592
        # Running it in a separate process group is not good because then it
593
        # can't get non-echoed input of a password or passphrase.
594
        # <https://launchpad.net/products/bzr/+bug/40508>
595
        return {'preexec_fn': _ignore_sigint,
596
                'close_fds': True,
597
                }
598
1951.1.12 by Andrew Bennetts
Cosmetic tweaks.
599
1951.1.7 by Andrew Bennetts
Move more generic SSH code from sftp.py into ssh.py, and start unifying the connection establishing logic.
600
class SSHSubprocess(object):
601
    """A socket-like object that talks to an ssh subprocess via pipes."""
602
603
    def __init__(self, proc):
604
        self.proc = proc
605
606
    def send(self, data):
607
        return os.write(self.proc.stdin.fileno(), data)
608
609
    def recv_ready(self):
610
        # TODO: jam 20051215 this function is necessary to support the
611
        # pipelined() function. In reality, it probably should use
612
        # poll() or select() to actually return if there is data
613
        # available, otherwise we probably don't get any benefit
614
        return True
615
616
    def recv(self, count):
617
        return os.read(self.proc.stdout.fileno(), count)
618
619
    def close(self):
620
        self.proc.stdin.close()
621
        self.proc.stdout.close()
622
        self.proc.wait()
623
2018.1.1 by Andrew Bennetts
Make bzr+ssh:// actually work (at least with absolute paths).
624
    def get_filelike_channels(self):
625
        return (self.proc.stdout, self.proc.stdin)
2221.5.21 by Dmitry Vasiliev
Reverted trailing whitespace removal
626