|
1 | 1 | package main |
2 | 2 |
|
3 | 3 | import ( |
| 4 | + "encoding/binary" |
4 | 5 | "flag" |
5 | 6 | "fmt" |
6 | 7 | "io" |
@@ -49,63 +50,107 @@ func main() { |
49 | 50 | os.Exit(0) |
50 | 51 | }(sigc) |
51 | 52 |
|
52 | | - // Dynamically pass stdin (i.e. the responses from the host's ssh-agent) to the current |
53 | | - // connected client |
54 | | - conn := &dynamicWriter{} |
55 | | - go func() { |
56 | | - io.Copy(conn, os.Stdin) |
57 | | - l.Close() |
58 | | - os.Exit(0) |
59 | | - }() |
60 | | - |
61 | 53 | for { |
62 | | - c, err := l.Accept() |
| 54 | + conn, err := l.Accept() |
63 | 55 | if err != nil { |
64 | 56 | continue |
65 | 57 | } |
66 | | - if *verbose { |
67 | | - log.Println("Client connected") |
68 | | - } |
69 | | - conn.Lock() |
70 | | - conn.conn = c |
71 | | - conn.Unlock() |
72 | | - |
73 | | - io.Copy(os.Stdout, c) |
74 | | - if *verbose { |
75 | | - log.Println("Client disconnected") |
76 | | - } |
77 | | - |
78 | | - conn.Lock() |
79 | | - c.Close() |
80 | | - conn.conn = nil |
81 | | - conn.Unlock() |
| 58 | + go forwardAgent(conn) |
82 | 59 | } |
83 | 60 | } |
84 | 61 |
|
85 | | -type dynamicWriter struct { |
86 | | - sync.RWMutex |
87 | | - conn io.Writer |
88 | | -} |
| 62 | +var stdioLock = &sync.RWMutex{} |
89 | 63 |
|
90 | | -func (d *dynamicWriter) Write(b []byte) (int, error) { |
| 64 | +// forwardAgent forwards the given connection to the real ssh-agent via stdio. |
| 65 | +func forwardAgent(conn net.Conn) { |
| 66 | + // This forwards each request & response pair in a loop between the connection and stdio. |
| 67 | + // The stdio part of the communication uses a lock to allow multiple clients to communicate in parallel. |
| 68 | + defer conn.Close() |
| 69 | + if *verbose { |
| 70 | + log.Println("Client connected") |
| 71 | + defer log.Println("Client disconnected") |
| 72 | + } |
91 | 73 | for { |
92 | | - d.Lock() |
93 | | - defer d.Unlock() |
94 | | - if d.conn == nil { |
95 | | - if *verbose { |
96 | | - log.Println("Discarding write") |
97 | | - } |
98 | | - return len(b), nil |
| 74 | + if *verbose { |
| 75 | + log.Println("Reading request from connection") |
99 | 76 | } |
100 | | - n, err := d.conn.Write(b) |
101 | | - if err == nil { |
| 77 | + packet, err := readAgentPacket(conn) |
| 78 | + if err != nil { |
102 | 79 | if *verbose { |
103 | | - log.Printf("Wrote %d bytes\n", n) |
| 80 | + log.Println("Error reading request from connection:", err) |
104 | 81 | } |
105 | | - return n, err |
| 82 | + return |
| 83 | + } |
| 84 | + packet, err = sendAgentRequest(packet) |
| 85 | + if err != nil { |
| 86 | + panic(err) |
106 | 87 | } |
107 | 88 | if *verbose { |
108 | | - log.Println("Error during write:", err) |
| 89 | + log.Println("Writing response to connection") |
| 90 | + } |
| 91 | + if _, err := conn.Write(packet); err != nil { |
| 92 | + log.Println("Error writing response to connection:", err) |
| 93 | + return |
109 | 94 | } |
| 95 | + if *verbose { |
| 96 | + log.Println("Finished request-response sequence") |
| 97 | + } |
| 98 | + } |
| 99 | +} |
| 100 | + |
| 101 | +// sendAgentRequest sends an ssh-agent request and returns the respective ssh-agent response. |
| 102 | +func sendAgentRequest(packet []byte) ([]byte, error) { |
| 103 | + if *verbose { |
| 104 | + log.Println("Acquiring stdio lock") |
| 105 | + } |
| 106 | + stdioLock.Lock() |
| 107 | + defer func() { |
| 108 | + if *verbose { |
| 109 | + log.Println("Releasing stdio lock") |
| 110 | + } |
| 111 | + stdioLock.Unlock() |
| 112 | + }() |
| 113 | + if *verbose { |
| 114 | + log.Println("Writing request to stdout") |
| 115 | + } |
| 116 | + if _, err := os.Stdout.Write(packet); err != nil { |
| 117 | + if *verbose { |
| 118 | + log.Println("Error writing request to stdout:", err) |
| 119 | + } |
| 120 | + return nil, err |
| 121 | + } |
| 122 | + if *verbose { |
| 123 | + log.Println("Reading response from stdin") |
| 124 | + } |
| 125 | + packet, err := readAgentPacket(os.Stdin) |
| 126 | + if err != nil { |
| 127 | + if *verbose { |
| 128 | + log.Println("Error reading response from stdin:", err) |
| 129 | + } |
| 130 | + return nil, err |
| 131 | + } |
| 132 | + return packet, nil |
| 133 | +} |
| 134 | + |
| 135 | +const maxPacketSize = 16 << 20 |
| 136 | + |
| 137 | +// readAgentPacket reads a whole ssh-agent packet from the given io.Reader. |
| 138 | +func readAgentPacket(r io.Reader) ([]byte, error) { |
| 139 | + var rawLength [4]byte |
| 140 | + if _, err := io.ReadFull(r, rawLength[:]); err != nil { |
| 141 | + return nil, err |
| 142 | + } |
| 143 | + length := binary.BigEndian.Uint32(rawLength[:]) |
| 144 | + if length == 0 { |
| 145 | + return nil, fmt.Errorf("Packet size is 0") |
| 146 | + } |
| 147 | + if length > maxPacketSize { |
| 148 | + return nil, fmt.Errorf("Packet size of %d is too large", length) |
| 149 | + } |
| 150 | + data := make([]byte, length) |
| 151 | + if _, err := io.ReadFull(r, data); err != nil { |
| 152 | + return nil, err |
110 | 153 | } |
| 154 | + packet := append(rawLength[:], data...) |
| 155 | + return packet, nil |
111 | 156 | } |
0 commit comments