Blame SOURCES/0080-auto-reporting-add-options-to-specify-auth-type.patch

06486d
From 2b16db2fea5552225437ac7d622706b597b7a71d Mon Sep 17 00:00:00 2001
06486d
From: Jakub Filak <jfilak@redhat.com>
06486d
Date: Fri, 19 Dec 2014 00:41:16 +0100
06486d
Subject: [ABRT PATCH 80/82] auto-reporting: add options to specify auth type
06486d
06486d
See abrt-auto-reporting man page for more details about this commit.
06486d
06486d
Related: #1174833
06486d
06486d
Signed-off-by: Jakub Filak <jfilak@redhat.com>
06486d
---
06486d
 doc/abrt-auto-reporting.txt      |  41 ++++++-
06486d
 src/daemon/abrt-auto-reporting.c | 258 ++++++++++++++++++++++++++++++++++++---
06486d
 2 files changed, 280 insertions(+), 19 deletions(-)
06486d
06486d
diff --git a/doc/abrt-auto-reporting.txt b/doc/abrt-auto-reporting.txt
06486d
index 1cc534e..2a27945 100644
06486d
--- a/doc/abrt-auto-reporting.txt
06486d
+++ b/doc/abrt-auto-reporting.txt
06486d
@@ -3,11 +3,14 @@ abrt-auto-reporting(1)
06486d
 
06486d
 NAME
06486d
 ----
06486d
-abrt-auto-reporting - Get or modify a value of the auto reporting option
06486d
+abrt-auto-reporting - Get or modify the auto reporting option values
06486d
 
06486d
 SYNOPSIS
06486d
 --------
06486d
-'abrt-auto-reporting' [-v] [ enabled | yes | 1 | disabled | no | 0 ]
06486d
+'abrt-auto-reporting' [-v] [ enabled | yes | 1 | on | disabled | no | 0 | off ]
06486d
+                      [ [--anonymous] |
06486d
+                        [--username USERNAME [--password PASSWORD] ] |
06486d
+                        [--certificate SOURCE] ]
06486d
 
06486d
 DESCRIPTION
06486d
 -----------
06486d
@@ -23,6 +26,9 @@ process and will be persistent.
06486d
    ABRT uploads an uReport which was generated for a detected problem
06486d
    immediately after the detection phase.
06486d
 
06486d
+Reads and saves the authentication configuration options in
06486d
+/etc/libreport/plugins/ureport.conf and /etc/libreport/plugins/rhtsupport.conf
06486d
+
06486d
 uReport description
06486d
 ~~~~~~~~~~~~~~~~~~~
06486d
 ABRT supports uReports for four types of crashes: crashes of C/C++ programs
06486d
@@ -51,6 +57,14 @@ for kernel oopses::
06486d
     these are list of loaded kernel modules, list of taint flags, and full text
06486d
     of the kernel oops.
06486d
 
06486d
+The authenticated uReports also contains *hostname* and *machineid* to enable a
06486d
+server side filtering at https://access.redhat.com/.
06486d
+
06486d
+The authenticated uReports have the benefit of rich server replies which may
06486d
+include a solution for the submitted crash. The authentication is done using
06486d
+either Red Hat Subscription Certificates or Red Hat Customer Portal
06486d
+credentials.
06486d
+
06486d
 'Warning':
06486d
 The full text of a kernel oops might contain information like the
06486d
 identification of the host hardware type. You should disable the autoreporting
06486d
@@ -62,9 +76,30 @@ OPTIONS
06486d
 -v, --verbose::
06486d
    Be more verbose. Can be given multiple times.
06486d
 
06486d
+-a, --anonymous::
06486d
+   Turns the authentication off by clearing both 'SSLClientAuth' and 'HTTPAuth'
06486d
+   configuration options in /etc/libreport/plugins/ureport.conf
06486d
+
06486d
+-u, --username USERNAME::
06486d
+   Turns HTTP Authentication on by setting 'HTTPAuth' configuration option to
06486d
+   *rhts-credentials* in /etc/libreport/plugins/ureport.conf and storing
06486d
+   USERNAME and PASSWORD in /etc/libreport/plugins/rhtsupport.conf
06486d
+   Also turns the SSL Client Authentication off, because these methods cannot
06486d
+   be used together.
06486d
+
06486d
+-p, --password PASSWORD::
06486d
+   Password for HTTP Authentication. If not provided, a prompt asking for it
06486d
+   will be issued.
06486d
+
06486d
+-c, --certificate SOURCE::
06486d
+   Turns SSL Client Authentication on by setting 'SSLClientAuth' configuration
06486d
+   option to SOURCE in /etc/libreport/plugins/ureport.conf.
06486d
+   Also turns the HTTP Authentication off, because these methods cannot
06486d
+   be used together.
06486d
+
06486d
 SEE ALSO
06486d
 --------
06486d
-abrt.conf(5)
06486d
+abrt.conf(5), ureport.conf(5), rhtsupport.conf(5)
06486d
 
06486d
 AUTHORS
06486d
 -------
06486d
diff --git a/src/daemon/abrt-auto-reporting.c b/src/daemon/abrt-auto-reporting.c
06486d
index 0909bed..f50c4c2 100644
06486d
--- a/src/daemon/abrt-auto-reporting.c
06486d
+++ b/src/daemon/abrt-auto-reporting.c
06486d
@@ -17,6 +17,7 @@
06486d
 */
06486d
 
06486d
 #include "libabrt.h"
06486d
+#include "client.h"
06486d
 
06486d
 #include <stdio.h>
06486d
 
06486d
@@ -26,13 +27,24 @@
06486d
 #define STATE_MANUAL "disabled"
06486d
 #define STATE_AUTO "enabled"
06486d
 
06486d
-const char *const REPORTING_STATES[6][2] = {
06486d
+#define RHTS_NAME "rhtsupport.conf"
06486d
+#define RHTS_USERNAME_OPTION "Login"
06486d
+#define RHTS_PASSWORD_OPTION "Password"
06486d
+
06486d
+#define UREPORT_NAME "ureport.conf"
06486d
+#define UREPORT_HTTP_AUTH_OPTION "HTTPAuth"
06486d
+#define UREPORT_CLIENT_AUTH_OPTION "SSLClientAuth"
06486d
+#define UREPORT_RTHS_CREDENTIALS_AUTH "rhts-credentials"
06486d
+
06486d
+const char *const REPORTING_STATES[8][2] = {
06486d
     {STATE_MANUAL, "no" },
06486d
     {STATE_AUTO,   "yes"},
06486d
     {"no",         "no" },
06486d
     {"yes",        "yes"},
06486d
     {"0",          "no" },
06486d
     {"1",          "yes"},
06486d
+    {"off",        "no" },
06486d
+    {"on",         "yes"},
06486d
 };
06486d
 
06486d
 static int
06486d
@@ -52,6 +64,77 @@ set_abrt_reporting(map_string_t *conf, const char *opt_value)
06486d
     return 1;
06486d
 }
06486d
 
06486d
+static int
06486d
+set_ureport_http_auth(map_string_t *conf, const char *opt_value)
06486d
+{
06486d
+    const char *const cur_value = get_map_string_item_or_NULL(conf, UREPORT_HTTP_AUTH_OPTION);
06486d
+
06486d
+    if (cur_value == NULL || strcmp(cur_value, opt_value) != 0)
06486d
+    {
06486d
+        replace_map_string_item(conf, xstrdup(UREPORT_HTTP_AUTH_OPTION), xstrdup(opt_value));
06486d
+        remove_map_string_item(conf, UREPORT_CLIENT_AUTH_OPTION);
06486d
+
06486d
+        return save_plugin_conf_file(UREPORT_NAME, conf);
06486d
+    }
06486d
+
06486d
+    /* No changes needed -> success */
06486d
+    return 1;
06486d
+}
06486d
+
06486d
+static int
06486d
+set_ureport_client_auth(map_string_t *conf, const char *opt_value)
06486d
+{
06486d
+    const char *const cur_value = get_map_string_item_or_NULL(conf, UREPORT_CLIENT_AUTH_OPTION);
06486d
+
06486d
+    if (cur_value == NULL || strcmp(cur_value, opt_value) != 0)
06486d
+    {
06486d
+        replace_map_string_item(conf, xstrdup(UREPORT_CLIENT_AUTH_OPTION), xstrdup(opt_value));
06486d
+        remove_map_string_item(conf, UREPORT_HTTP_AUTH_OPTION);
06486d
+
06486d
+        return save_plugin_conf_file(UREPORT_NAME, conf);
06486d
+    }
06486d
+
06486d
+    /* No changes needed -> success */
06486d
+    return 1;
06486d
+}
06486d
+
06486d
+static int
06486d
+clear_ureport_auth(map_string_t *conf)
06486d
+{
06486d
+    const char *const http_cur_value = get_map_string_item_or_NULL(conf, UREPORT_HTTP_AUTH_OPTION);
06486d
+    const char *const ssl_cur_value = get_map_string_item_or_NULL(conf, UREPORT_CLIENT_AUTH_OPTION);
06486d
+
06486d
+    if (http_cur_value != NULL || ssl_cur_value != NULL)
06486d
+    {
06486d
+        remove_map_string_item(conf, UREPORT_HTTP_AUTH_OPTION);
06486d
+        remove_map_string_item(conf, UREPORT_CLIENT_AUTH_OPTION);
06486d
+
06486d
+        return save_plugin_conf_file(UREPORT_NAME, conf);
06486d
+    }
06486d
+
06486d
+    /* No changes needed -> success */
06486d
+    return 1;
06486d
+}
06486d
+
06486d
+static int
06486d
+set_rhts_credentials(map_string_t *conf, const char *username, const char *password)
06486d
+{
06486d
+    const char *const username_cur_value = get_map_string_item_or_NULL(conf, RHTS_USERNAME_OPTION);
06486d
+    const char *const password_cur_value = get_map_string_item_or_NULL(conf, RHTS_PASSWORD_OPTION);
06486d
+
06486d
+    if (  (username_cur_value == NULL || strcmp(username_cur_value, username) != 0)
06486d
+       || (password_cur_value == NULL || strcmp(password_cur_value, password) != 0))
06486d
+    {
06486d
+        replace_map_string_item(conf, xstrdup(RHTS_USERNAME_OPTION), xstrdup(username));
06486d
+        replace_map_string_item(conf, xstrdup(RHTS_PASSWORD_OPTION), xstrdup(password));
06486d
+
06486d
+        return save_plugin_conf_file(RHTS_NAME, conf);
06486d
+    }
06486d
+
06486d
+    /* No changes needed -> success */
06486d
+    return 1;
06486d
+}
06486d
+
06486d
 static const char *
06486d
 get_abrt_reporting(map_string_t *conf)
06486d
 {
06486d
@@ -60,6 +143,18 @@ get_abrt_reporting(map_string_t *conf)
06486d
     return REPORTING_STATES[index][0];
06486d
 }
06486d
 
06486d
+static const char *
06486d
+get_ureport_http_auth(map_string_t *conf)
06486d
+{
06486d
+    return get_map_string_item_or_NULL(conf, UREPORT_HTTP_AUTH_OPTION);
06486d
+}
06486d
+
06486d
+static const char *
06486d
+get_ureport_client_auth(map_string_t *conf)
06486d
+{
06486d
+    return get_map_string_item_or_NULL(conf, UREPORT_CLIENT_AUTH_OPTION);
06486d
+}
06486d
+
06486d
 int main(int argc, char *argv[])
06486d
 {
06486d
     setlocale(LC_ALL, "");
06486d
@@ -78,7 +173,8 @@ int main(int argc, char *argv[])
06486d
 
06486d
     abrt_init(argv);
06486d
     const char *program_usage_string = _(
06486d
-            "& [ "STATE_MANUAL" | "STATE_AUTO" | yes | no | 1 | 0 ]\n"
06486d
+            "& [ "STATE_MANUAL" | "STATE_AUTO" | yes | no | 1 | 0 ] \\\n"
06486d
+            "  [[--anonymous] | [--username USERNAME [--password PASSWORD]] | [--certificate SOURCE]]\n"
06486d
             "\n"
06486d
             "Get or modify a value of the auto-reporting option. The changes will take\n"
06486d
             "effect immediately and will be persistent.\n"
06486d
@@ -94,36 +190,72 @@ int main(int argc, char *argv[])
06486d
             "contains identification of the operating system, versions of the RPM packages\n"
06486d
             "involved in the crash, and whether the program ran under a root user.\n"
06486d
             "\n"
06486d
-            "See abrt-auto-reporting(1) for more details.\n"
06486d
+            "See abrt-auto-reporting(1), reporter-ureport(1) and reporter-rhtsupport(1)\n"
06486d
+            "for more details.\n"
06486d
     );
06486d
 
06486d
+    enum {
06486d
+        OPT_v = 1 << 0,
06486d
+        OPT_a = 1 << 1,
06486d
+        OPT_u = 1 << 2,
06486d
+        OPT_p = 1 << 3,
06486d
+        OPT_c = 1 << 4,
06486d
+    };
06486d
+
06486d
+    bool anonymous = false;
06486d
+    const char *username = NULL;
06486d
+    const char *password = NULL;
06486d
+    const char *certificate = NULL;
06486d
+
06486d
     /* Keep enum above and order of options below in sync! */
06486d
     struct options program_options[] = {
06486d
         OPT__VERBOSE(&g_verbose),
06486d
+        OPT_BOOL  (  'a', "anonymous",   &anonymous,               _("Turns the authentication off")),
06486d
+        OPT_STRING(  'u', "username",    &username,    "USERNAME", _("Red Hat Support user name")),
06486d
+        OPT_STRING(  'p', "password",    &password,    "PASSWORD", _("Red Hat Support password, if not given, a prompt for it will be issued")),
06486d
+        OPT_STRING(  'c', "certificate", &certificate, "SOURCE",   _("uReport SSL certificate paths or certificate type")),
06486d
         OPT_END()
06486d
     };
06486d
 
06486d
-    const unsigned optind = parse_opts(argc, argv, program_options, program_usage_string);
06486d
+    const unsigned opts = parse_opts(argc, argv, program_options, program_usage_string);
06486d
 
06486d
     argv += optind;
06486d
     argc -= optind;
06486d
 
06486d
-    if (argc > 2)
06486d
+    if ((opts & OPT_p) && !(opts & OPT_u))
06486d
     {
06486d
-        error_msg(_("Invalid number of arguments"));
06486d
+        error_msg(_("You also need to specify --username for --password"));
06486d
         show_usage_and_die(program_usage_string, program_options);
06486d
     }
06486d
 
06486d
-    int exit_code = EXIT_FAILURE;
06486d
+    if ((opts & OPT_u) && (opts & OPT_c))
06486d
+    {
06486d
+        error_msg(_("You can use either --username or --certificate"));
06486d
+        show_usage_and_die(program_usage_string, program_options);
06486d
+    }
06486d
 
06486d
-    map_string_t *conf = new_map_string();
06486d
-    if (!load_abrt_conf_file(CONF_NAME, conf))
06486d
-        goto finito;
06486d
+    if ((opts & OPT_u) && (opts & OPT_a))
06486d
+    {
06486d
+        error_msg(_("You can use either --username or --anonymous"));
06486d
+        show_usage_and_die(program_usage_string, program_options);
06486d
+    }
06486d
+
06486d
+    if ((opts & OPT_a) && (opts & OPT_c))
06486d
+    {
06486d
+        error_msg(_("You can use either --anonymous or --certificate"));
06486d
+        show_usage_and_die(program_usage_string, program_options);
06486d
+    }
06486d
+
06486d
+    if (argc > 1)
06486d
+    {
06486d
+        error_msg(_("Invalid number of arguments"));
06486d
+        show_usage_and_die(program_usage_string, program_options);
06486d
+    }
06486d
 
06486d
-    if (argc == 2)
06486d
+    const char *opt_value = NULL;
06486d
+    if (argc == 1)
06486d
     {
06486d
-        const char *const new_value = argv[1];
06486d
-        const char *opt_value = NULL;
06486d
+        const char *const new_value = argv[0];
06486d
         for (int i = 0; i < sizeof(REPORTING_STATES)/sizeof(REPORTING_STATES[0]); ++i)
06486d
         {
06486d
             if (strcasecmp(new_value, REPORTING_STATES[i][0]) == 0)
06486d
@@ -138,15 +270,109 @@ int main(int argc, char *argv[])
06486d
             error_msg(_("Unknown option value: '%s'\n"), new_value);
06486d
             show_usage_and_die(program_usage_string, program_options);
06486d
         }
06486d
+    }
06486d
+
06486d
+    int exit_code = EXIT_FAILURE;
06486d
+
06486d
+    map_string_t *conf = new_map_string();
06486d
+    map_string_t *rhts_conf = new_map_string();
06486d
+    map_string_t *rhts_conf_bck = NULL;
06486d
+    map_string_t *ureport_conf = new_map_string();
06486d
+    map_string_t *ureport_conf_bck = NULL;
06486d
+
06486d
+    if (!load_abrt_conf_file(CONF_NAME, conf))
06486d
+        goto finito;
06486d
 
06486d
-        exit_code = set_abrt_reporting(conf, opt_value) ? EXIT_SUCCESS : EXIT_FAILURE;
06486d
+    if (!load_plugin_conf_file(RHTS_NAME, rhts_conf, false))
06486d
         goto finito;
06486d
+
06486d
+    if (!load_plugin_conf_file(UREPORT_NAME, ureport_conf, false))
06486d
+        goto finito;
06486d
+
06486d
+    if ((opts & OPT_a))
06486d
+    {
06486d
+        ureport_conf_bck = clone_map_string(ureport_conf);
06486d
+
06486d
+        if (!clear_ureport_auth(ureport_conf))
06486d
+            goto finito;
06486d
+    }
06486d
+
06486d
+    if ((opts & OPT_u))
06486d
+    {
06486d
+        char *tmp_password = NULL;
06486d
+        if (!(opts & OPT_p))
06486d
+        {
06486d
+            password = tmp_password = ask_password(_("Password:"));
06486d
+            if (tmp_password == NULL)
06486d
+            {
06486d
+                error_msg(_("Cannot continue without password\n"));
06486d
+                goto finito;
06486d
+            }
06486d
+        }
06486d
+
06486d
+        ureport_conf_bck = clone_map_string(ureport_conf);
06486d
+
06486d
+        if (!set_ureport_http_auth(ureport_conf, UREPORT_RTHS_CREDENTIALS_AUTH))
06486d
+            goto finito;
06486d
+
06486d
+        rhts_conf_bck = clone_map_string(rhts_conf);
06486d
+
06486d
+        if (!set_rhts_credentials(rhts_conf, username, password))
06486d
+        {
06486d
+            save_plugin_conf_file(UREPORT_NAME, ureport_conf_bck);
06486d
+            goto finito;
06486d
+        }
06486d
+
06486d
+        free(tmp_password);
06486d
+    }
06486d
+
06486d
+    if ((opts & OPT_c))
06486d
+    {
06486d
+        ureport_conf_bck = clone_map_string(ureport_conf);
06486d
+
06486d
+        if (!set_ureport_client_auth(ureport_conf, certificate))
06486d
+            goto finito;
06486d
+    }
06486d
+
06486d
+    if (argc == 0)
06486d
+    {
06486d
+        printf("%s", get_abrt_reporting(conf));
06486d
+        exit_code = EXIT_SUCCESS;
06486d
+
06486d
+        if (g_verbose >= 1)
06486d
+        {
06486d
+            const char *tmp = get_ureport_http_auth(ureport_conf);
06486d
+            if (tmp != NULL)
06486d
+                /* Print only the part before ':' of a string like "username:password" */
06486d
+                printf(" %s (%*s)", _("HTTP Authenticated auto reporting"), (int)(strchrnul(tmp, ':') - tmp), tmp);
06486d
+            else if ((tmp = get_ureport_client_auth(ureport_conf)) != NULL)
06486d
+                printf(" %s (%s)", _("SSL Client Authenticated auto reporting"), tmp);
06486d
+            else
06486d
+                printf(" %s", _("anonymous auto reporting"));
06486d
+        }
06486d
+
06486d
+        putchar('\n');
06486d
+
06486d
+        goto finito;
06486d
+    }
06486d
+
06486d
+    exit_code = set_abrt_reporting(conf, opt_value) ? EXIT_SUCCESS : EXIT_FAILURE;
06486d
+
06486d
+    if (exit_code == EXIT_FAILURE)
06486d
+    {
06486d
+        if (ureport_conf_bck != NULL)
06486d
+            save_plugin_conf_file(UREPORT_NAME, ureport_conf_bck);
06486d
+
06486d
+        if (rhts_conf_bck != NULL)
06486d
+            save_plugin_conf_file(RHTS_NAME, rhts_conf_bck);
06486d
     }
06486d
 
06486d
-    printf("%s\n", get_abrt_reporting(conf));
06486d
-    exit_code = EXIT_SUCCESS;
06486d
 
06486d
 finito:
06486d
+    free_map_string(ureport_conf);
06486d
+    free_map_string(ureport_conf_bck);
06486d
+    free_map_string(rhts_conf);
06486d
+    free_map_string(rhts_conf_bck);
06486d
     free_map_string(conf);
06486d
     return exit_code;
06486d
 }
06486d
-- 
06486d
1.8.3.1
06486d