aboutsummaryrefslogtreecommitdiff
path: root/forged/internal/incoming/ssh/ssh.go
blob: dc03501d60d98314ff178b7805bb40eeaf0c8bde (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89

package ssh

import (
	"context"
	"errors"
	"fmt"
	"os"
	"time"

	gliderssh "github.com/gliderlabs/ssh"
	"go.lindenii.runxiyu.org/forge/forged/internal/common/misc"
	"go.lindenii.runxiyu.org/forge/forged/internal/global"
	gossh "golang.org/x/crypto/ssh"
)

type Server struct {
	gliderServer    *gliderssh.Server
	privkey         gossh.Signer
	net             string
	addr            string
	root            string
	shutdownTimeout uint32
	globalData      *global.GlobalData
}

func New(config Config, globalData *global.GlobalData) (server *Server, err error) {
	server = &Server{
		net:             config.Net,
		addr:            config.Addr,
		root:            config.Root,
		shutdownTimeout: config.ShutdownTimeout,
		globalData:      globalData,
	} //exhaustruct:ignore

	var privkeyBytes []byte

	privkeyBytes, err = os.ReadFile(config.Key)
	if err != nil {
		return server, fmt.Errorf("read SSH private key: %w", err)
	}

	server.privkey, err = gossh.ParsePrivateKey(privkeyBytes)
	if err != nil {
		return server, fmt.Errorf("parse SSH private key: %w", err)
	}

	server.globalData.SSHPubkey = misc.BytesToString(gossh.MarshalAuthorizedKey(server.privkey.PublicKey()))
	server.globalData.SSHFingerprint = gossh.FingerprintSHA256(server.privkey.PublicKey())

	server.gliderServer = &gliderssh.Server{
		Handler:                    handle,
		PublicKeyHandler:           func(ctx gliderssh.Context, key gliderssh.PublicKey) bool { return true },
		KeyboardInteractiveHandler: func(ctx gliderssh.Context, challenge gossh.KeyboardInteractiveChallenge) bool { return true },
	} //exhaustruct:ignore
	server.gliderServer.AddHostKey(server.privkey)

	return server, nil
}

func (server *Server) Run(ctx context.Context) (err error) {
	listener, err := misc.Listen(ctx, server.net, server.addr)
	if err != nil {
		return fmt.Errorf("listen for SSH: %w", err)
	}
	defer func() {
		_ = listener.Close()
	}()

	stop := context.AfterFunc(ctx, func() {
		shCtx, cancel := context.WithTimeout(context.WithoutCancel(ctx), time.Duration(server.shutdownTimeout)*time.Second)
		defer cancel()
		_ = server.gliderServer.Shutdown(shCtx)
		_ = listener.Close()
	})
	defer stop()

	err = server.gliderServer.Serve(listener)
	if err != nil {
		if errors.Is(err, gliderssh.ErrServerClosed) || ctx.Err() != nil {
			return nil
		}
		return fmt.Errorf("serve SSH: %w", err)
	}
	panic("unreachable")
}

func handle(session gliderssh.Session) {
	panic("SSH server handler not implemented yet")
}