aboutsummaryrefslogtreecommitdiffstats
path: root/org.eclipse.jgit.ssh.apache/src/org/eclipse/jgit/internal/signing/ssh/OpenSshKrl.java
blob: 7993def90c8e964d31a720a1ec0ec35dc517fbb1 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
/*
 * Copyright (C) 2024, Thomas Wolf <twolf@apache.org> and others
 *
 * This program and the accompanying materials are made available under the
 * terms of the Eclipse Distribution License v. 1.0 which is available at
 * https://www.eclipse.org/org/documents/edl-v10.php.
 *
 * SPDX-License-Identifier: BSD-3-Clause
 */
package org.eclipse.jgit.internal.signing.ssh;

import java.io.BufferedInputStream;
import java.io.BufferedReader;
import java.io.IOException;
import java.io.InputStream;
import java.io.InputStreamReader;
import java.nio.charset.StandardCharsets;
import java.nio.file.Files;
import java.nio.file.NoSuchFileException;
import java.nio.file.Path;
import java.security.PublicKey;
import java.util.Arrays;
import java.util.HashSet;
import java.util.Set;

import org.apache.sshd.common.config.keys.OpenSshCertificate;
import org.apache.sshd.common.config.keys.PublicKeyEntry;
import org.apache.sshd.common.util.io.ModifiableFileWatcher;
import org.eclipse.jgit.util.IO;

/**
 * An implementation of an OpenSSH key revocation list (KRL), either a binary
 * KRL or a simple list of public keys.
 */
class OpenSshKrl extends ModifiableFileWatcher {

	private static record State(Set<String> keys, OpenSshBinaryKrl krl) {
		// Empty
	}

	private State state;

	public OpenSshKrl(Path path) {
		super(path);
		state = new State(Set.of(), null);
	}

	public boolean isRevoked(PublicKey key) throws IOException {
		State current = refresh();
		return isRevoked(current, key);
	}

	private boolean isRevoked(State current, PublicKey key) {
		if (key instanceof OpenSshCertificate cert) {
			OpenSshBinaryKrl krl = current.krl();
			if (krl != null && krl.isRevoked(cert)) {
				return true;
			}
			if (isRevoked(current, cert.getCaPubKey())
					|| isRevoked(current, cert.getCertPubKey())) {
				return true;
			}
			return false;
		}
		OpenSshBinaryKrl krl = current.krl();
		if (krl != null) {
			return krl.isRevoked(key);
		}
		return current.keys().contains(PublicKeyEntry.toString(key));
	}

	private synchronized State refresh() throws IOException {
		if (checkReloadRequired()) {
			updateReloadAttributes();
			try {
				state = reload(getPath());
			} catch (NoSuchFileException e) {
				// File disappeared
				resetReloadAttributes();
				state = new State(Set.of(), null);
			}
		}
		return state;
	}

	private static State reload(Path path) throws IOException {
		try (BufferedInputStream in = new BufferedInputStream(
				Files.newInputStream(path))) {
			byte[] magic = new byte[OpenSshBinaryKrl.MAGIC.length];
			in.mark(magic.length);
			IO.readFully(in, magic);
			if (Arrays.equals(magic, OpenSshBinaryKrl.MAGIC)) {
				return new State(null, OpenSshBinaryKrl.load(in, true));
			}
			// Otherwise try reading it textually
			in.reset();
			return loadTextKrl(in);
		}
	}

	private static State loadTextKrl(InputStream in) throws IOException {
		Set<String> keys = new HashSet<>();
		try (BufferedReader r = new BufferedReader(
				new InputStreamReader(in, StandardCharsets.UTF_8))) {
			String line;
			for (;;) {
				line = r.readLine();
				if (line == null) {
					break;
				}
				line = line.strip();
				if (line.isEmpty() || line.charAt(0) == '#') {
					continue;
				}
				keys.add(AllowedSigners.parsePublicKey(line, 0));
			}
		}
		return new State(keys, null);
	}
}