You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

CachingKeyPairProvider.java 6.9KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227
  1. /*
  2. * Copyright (C) 2018, Thomas Wolf <thomas.wolf@paranor.ch>
  3. * and other copyright owners as documented in the project's IP log.
  4. *
  5. * This program and the accompanying materials are made available
  6. * under the terms of the Eclipse Distribution License v1.0 which
  7. * accompanies this distribution, is reproduced below, and is
  8. * available at http://www.eclipse.org/org/documents/edl-v10.php
  9. *
  10. * All rights reserved.
  11. *
  12. * Redistribution and use in source and binary forms, with or
  13. * without modification, are permitted provided that the following
  14. * conditions are met:
  15. *
  16. * - Redistributions of source code must retain the above copyright
  17. * notice, this list of conditions and the following disclaimer.
  18. *
  19. * - Redistributions in binary form must reproduce the above
  20. * copyright notice, this list of conditions and the following
  21. * disclaimer in the documentation and/or other materials provided
  22. * with the distribution.
  23. *
  24. * - Neither the name of the Eclipse Foundation, Inc. nor the
  25. * names of its contributors may be used to endorse or promote
  26. * products derived from this software without specific prior
  27. * written permission.
  28. *
  29. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND
  30. * CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
  31. * INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  32. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  33. * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
  34. * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  35. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  36. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  37. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  38. * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  39. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  40. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
  41. * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  42. */
  43. package org.eclipse.jgit.internal.transport.sshd;
  44. import static java.text.MessageFormat.format;
  45. import java.io.IOException;
  46. import java.io.InputStream;
  47. import java.nio.file.Files;
  48. import java.nio.file.Path;
  49. import java.security.GeneralSecurityException;
  50. import java.security.InvalidKeyException;
  51. import java.security.KeyPair;
  52. import java.security.PrivateKey;
  53. import java.util.ArrayList;
  54. import java.util.Collection;
  55. import java.util.Collections;
  56. import java.util.Iterator;
  57. import java.util.List;
  58. import java.util.NoSuchElementException;
  59. import java.util.concurrent.CancellationException;
  60. import javax.security.auth.DestroyFailedException;
  61. import org.apache.sshd.common.NamedResource;
  62. import org.apache.sshd.common.config.keys.FilePasswordProvider;
  63. import org.apache.sshd.common.keyprovider.FileKeyPairProvider;
  64. import org.apache.sshd.common.session.SessionContext;
  65. import org.apache.sshd.common.util.io.resource.IoResource;
  66. import org.apache.sshd.common.util.security.SecurityUtils;
  67. import org.eclipse.jgit.transport.sshd.KeyCache;
  68. /**
  69. * A {@link FileKeyPairProvider} that uses an external {@link KeyCache}.
  70. */
  71. public class CachingKeyPairProvider extends FileKeyPairProvider
  72. implements Iterable<KeyPair> {
  73. private final KeyCache cache;
  74. /**
  75. * Creates a new {@link CachingKeyPairProvider} using the given
  76. * {@link KeyCache}. If the cache is {@code null}, this is a simple
  77. * {@link FileKeyPairProvider}.
  78. *
  79. * @param paths
  80. * to load keys from
  81. * @param cache
  82. * to use, may be {@code null} if no external caching is desired
  83. */
  84. public CachingKeyPairProvider(List<Path> paths, KeyCache cache) {
  85. super(paths);
  86. this.cache = cache;
  87. }
  88. @Override
  89. public Iterator<KeyPair> iterator() {
  90. return iterator(null);
  91. }
  92. private Iterator<KeyPair> iterator(SessionContext session) {
  93. Collection<? extends Path> resources = getPaths();
  94. if (resources.isEmpty()) {
  95. return Collections.emptyListIterator();
  96. }
  97. return new CancellingKeyPairIterator(session, resources);
  98. }
  99. @Override
  100. public Iterable<KeyPair> loadKeys(SessionContext session) {
  101. return () -> iterator(session);
  102. }
  103. private KeyPair loadKey(SessionContext session, Path path)
  104. throws IOException, GeneralSecurityException {
  105. if (!Files.exists(path)) {
  106. log.warn(format(SshdText.get().identityFileNotFound, path));
  107. return null;
  108. }
  109. IoResource<Path> resource = getIoResource(session, path);
  110. if (cache == null) {
  111. return loadKey(session, resource, path, getPasswordFinder());
  112. }
  113. Throwable[] t = { null };
  114. KeyPair key = cache.get(path, p -> {
  115. try {
  116. return loadKey(session, resource, p, getPasswordFinder());
  117. } catch (IOException | GeneralSecurityException e) {
  118. t[0] = e;
  119. return null;
  120. }
  121. });
  122. if (t[0] != null) {
  123. if (t[0] instanceof CancellationException) {
  124. throw (CancellationException) t[0];
  125. }
  126. throw new IOException(
  127. format(SshdText.get().keyLoadFailed, resource), t[0]);
  128. }
  129. return key;
  130. }
  131. private KeyPair loadKey(SessionContext session, NamedResource resource,
  132. Path path, FilePasswordProvider passwordProvider)
  133. throws IOException, GeneralSecurityException {
  134. try (InputStream stream = Files.newInputStream(path)) {
  135. Iterable<KeyPair> ids = SecurityUtils.loadKeyPairIdentities(session,
  136. resource, stream, passwordProvider);
  137. if (ids == null) {
  138. throw new InvalidKeyException(
  139. format(SshdText.get().identityFileNoKey, path));
  140. }
  141. Iterator<KeyPair> keys = ids.iterator();
  142. if (!keys.hasNext()) {
  143. throw new InvalidKeyException(format(
  144. SshdText.get().identityFileUnsupportedFormat, path));
  145. }
  146. KeyPair result = keys.next();
  147. if (keys.hasNext()) {
  148. log.warn(format(SshdText.get().identityFileMultipleKeys, path));
  149. keys.forEachRemaining(k -> {
  150. PrivateKey pk = k.getPrivate();
  151. if (pk != null) {
  152. try {
  153. pk.destroy();
  154. } catch (DestroyFailedException e) {
  155. // Ignore
  156. }
  157. }
  158. });
  159. }
  160. return result;
  161. }
  162. }
  163. private class CancellingKeyPairIterator implements Iterator<KeyPair> {
  164. private final SessionContext context;
  165. private final Iterator<Path> paths;
  166. private KeyPair nextItem;
  167. private boolean nextSet;
  168. public CancellingKeyPairIterator(SessionContext session,
  169. Collection<? extends Path> resources) {
  170. List<Path> copy = new ArrayList<>(resources.size());
  171. copy.addAll(resources);
  172. paths = copy.iterator();
  173. context = session;
  174. }
  175. @Override
  176. public boolean hasNext() {
  177. if (nextSet) {
  178. return nextItem != null;
  179. }
  180. nextSet = true;
  181. while (nextItem == null && paths.hasNext()) {
  182. try {
  183. nextItem = loadKey(context, paths.next());
  184. } catch (CancellationException cancelled) {
  185. throw cancelled;
  186. } catch (Exception other) {
  187. log.warn(other.toString());
  188. }
  189. }
  190. return nextItem != null;
  191. }
  192. @Override
  193. public KeyPair next() {
  194. if (!nextSet && !hasNext()) {
  195. throw new NoSuchElementException();
  196. }
  197. KeyPair result = nextItem;
  198. nextItem = null;
  199. nextSet = false;
  200. if (result == null) {
  201. throw new NoSuchElementException();
  202. }
  203. return result;
  204. }
  205. }
  206. }