3 # Restricts rsync to subdirectory declared in .ssh/authorized_keys. See
4 # the rrsync man page for details of how to make use of this script.
6 # NOTE: install python3 braceexpand to support brace expansion in the args!
8 # Originally a perl script by: Joe Smith <js-cgi@inwap.com> 30-Sep-2004
9 # Python version by: Wayne Davison <wayne@opencoder.net>
11 # You may configure these 2 values to your liking. See also the section of
12 # short & long options if you want to disable any options that rsync accepts.
13 RSYNC = '/usr/bin/rsync'
14 LOGFILE = 'rrsync.log' # NOTE: the file must exist for a line to be appended!
16 # The following options are mainly the options that a client rsync can send
17 # to the server, and usually just in the one option format that the stock
18 # rsync produces. However, there are some additional convenience options
19 # added as well, and thus a few options are present in both the short and
20 # long lists (such as --group, --owner, and --perms).
22 # NOTE when disabling: check for both a short & long version of the option!
24 ### START of options data produced by the cull-options script. ###
26 # To disable a short-named option, add its letter to this string:
29 # These are also disabled when the restricted dir is not "/":
30 short_disabled_subdir = 'KLk'
32 # These are all possible short options that we will accept (when not disabled above):
33 short_no_arg = 'ACDEHIJKLNORSUWXbcdgklmnopqrstuvxyz' # DO NOT REMOVE ANY
34 short_with_num = '@B' # DO NOT REMOVE ANY
36 # To disable a long-named option, change its value to a -1. The values mean:
37 # 0 = the option has no arg; 1 = the arg doesn't need any checking; 2 = only
38 # check the arg when receiving; and 3 = always check the arg.
49 'compress-threads': 1,
52 'copy-unsafe-links': 0,
62 'delete-missing-args': 0,
77 'ignore-missing-args': 0,
104 'one-file-system': 0,
105 'only-write-batch': 1,
113 'remove-sent-files': 0,
114 'remove-source-files': 0,
133 ### END of options data produced by the cull-options script. ###
135 import os, sys, re, argparse, glob, socket, time, subprocess
136 from argparse import RawTextHelpFormatter
139 from braceexpand import braceexpand
141 braceexpand = lambda x: [ DE_BACKSLASH_RE.sub(r'\1', x) ]
143 HAS_DOT_DOT_RE = re.compile(r'(^|/)\.\.(/|$)')
144 LONG_OPT_RE = re.compile(r'^--([^=]+)(?:=(.*))?$')
145 DE_BACKSLASH_RE = re.compile(r'\\(.)')
148 if not os.path.isdir(args.dir):
149 die("Restricted directory does not exist!")
151 # The format of the environment variables set by sshd:
152 # SSH_ORIGINAL_COMMAND:
153 # rsync --server -vlogDtpre.iLsfxCIvu --etc . ARG # push
154 # rsync --server --sender -vlogDtpre.iLsfxCIvu --etc . ARGS # pull
155 # SSH_CONNECTION (client_ip client_port server_ip server_port):
156 # 192.168.1.100 64106 192.168.1.2 22
158 command = os.environ.get('SSH_ORIGINAL_COMMAND', None)
160 die("Not invoked via sshd")
161 if command == 'true':
162 # Allow checking connectivity with "ssh <host> true". (For example,
163 # rsbackup uses this.)
165 command = command.split(' ', 2)
166 if command[0:1] != ['rsync']:
167 die("SSH_ORIGINAL_COMMAND does not run rsync")
168 if command[1:2] != ['--server']:
169 die("--server option is not the first arg")
170 command = '' if len(command) < 3 else command[2]
173 am_sender = command.startswith("--sender ") # Restrictive on purpose!
174 if args.ro and not am_sender:
175 die("sending to read-only server is not allowed")
176 if args.wo and am_sender:
177 die("reading from write-only server is not allowed")
179 if args.wo or not am_sender:
180 long_opts['sender'] = -1
182 for opt in long_opts:
183 if opt.startswith(('remove', 'delete')):
186 long_opts['log-file'] = -1
189 global short_disabled
190 short_disabled += short_disabled_subdir
192 short_no_arg_re = short_no_arg
193 short_with_num_re = short_with_num
195 for ltr in short_disabled:
196 short_no_arg_re = short_no_arg_re.replace(ltr, '')
197 short_with_num_re = short_with_num_re.replace(ltr, '')
198 short_disabled_re = re.compile(r'^-[%s]*([%s])' % (short_no_arg_re, short_disabled))
199 short_no_arg_re = re.compile(r'^-(?=.)[%s]*(e\d*\.\w*)?$' % short_no_arg_re)
200 short_with_num_re = re.compile(r'^-[%s]\d+$' % short_with_num_re)
202 log_fh = open(LOGFILE, 'a') if os.path.isfile(LOGFILE) else None
207 die('unable to chdir to restricted dir:', str(e))
209 rsync_opts = [ '--server' ]
211 saw_the_dot_arg = False
212 last_opt = check_type = None
214 for arg in re.findall(r'(?:[^\s\\]+|\\.[^\s\\]*)+', command):
216 rsync_opts.append(validated_arg(last_opt, arg, check_type))
218 elif saw_the_dot_arg:
219 # NOTE: an arg that starts with a '-' is safe due to our use of "--" in the cmd tuple.
221 b_e = braceexpand(arg) # Also removes backslashes
222 except: # Handle errors such as unbalanced braces by just de-backslashing the arg:
223 b_e = [ DE_BACKSLASH_RE.sub(r'\1', arg) ]
225 rsync_args += validated_arg('arg', xarg, wild=True)
226 else: # parsing the option args
228 saw_the_dot_arg = True
230 rsync_opts.append(arg)
231 if short_no_arg_re.match(arg) or short_with_num_re.match(arg):
234 m = LONG_OPT_RE.match(arg)
238 ct = long_opts.get(opt, None)
240 break # Generate generic failure due to unfinished arg parsing
245 if opt_arg is not None:
246 rsync_opts[-1] = opt + '=' + validated_arg(opt, opt_arg, ct)
253 m = short_disabled_re.match(arg)
256 opt = '-' + m.group(1)
259 die("option", opt, "has been disabled on this server.")
260 break # Generate a generic failure
262 if not saw_the_dot_arg:
263 die("invalid rsync-command syntax or options")
266 rsync_opts.append('--munge-links')
268 if args.no_overwrite:
269 rsync_opts.append('--ignore-existing')
274 cmd = (RSYNC, *rsync_opts, '--', '.', *rsync_args)
277 now = time.localtime()
278 host = os.environ.get('SSH_CONNECTION', 'unknown').split()[0] # Drop everything after the IP addr
279 if host.startswith('::ffff:'):
282 host = socket.gethostbyaddr(socket.inet_aton(host))
285 log_fh.write("%02d:%02d:%02d %-16s %s\n" % (now.tm_hour, now.tm_min, now.tm_sec, host, str(cmd)))
288 # NOTE: This assumes that the rsync protocol will not be maliciously hijacked.
290 os.execlp(RSYNC, *cmd)
291 die("execlp(", RSYNC, *cmd, ') failed')
292 child = subprocess.run(cmd)
293 if child.returncode != 0:
294 sys.exit(child.returncode)
297 def validated_arg(opt, arg, typ=3, wild=False):
298 if opt != 'arg': # arg values already have their backslashes removed.
299 arg = DE_BACKSLASH_RE.sub(r'\1', arg)
302 if arg.startswith('./'):
304 arg = arg.replace('//', '/')
305 is_absolute_arg = args.absolute and opt == 'arg' and args.dir != '/' and (arg == args.dir or arg.startswith(args.dir_slash))
306 if not is_absolute_arg:
307 arg = arg.lstrip('/')
309 if HAS_DOT_DOT_RE.search(arg):
310 die("do not use .. in", opt, "(anchor the path at the root of your restricted dir)")
321 if args.dir != '/' and arg != '.' and (typ == 3 or (typ == 2 and not am_sender)):
322 arg_has_trailing_slash = arg.endswith('/')
323 if arg_has_trailing_slash:
326 arg_has_trailing_slash_dot = arg.endswith('/.')
327 if arg_has_trailing_slash_dot:
329 real_arg = os.path.realpath(arg)
330 if arg != real_arg and not real_arg.startswith(args.dir_slash):
331 if not (is_absolute_arg and real_arg == args.dir):
332 die('unsafe arg:', orig_arg, [arg, real_arg])
333 if arg_has_trailing_slash:
335 elif arg_has_trailing_slash_dot:
337 if is_absolute_arg and arg == args.dir:
339 elif opt == 'arg' and arg.startswith(args.dir_slash):
340 arg = arg[args.dir_slash_len:]
345 return ret if wild else ret[0]
348 def lock_or_die(dirname):
351 lock_handle = os.open(dirname, os.O_RDONLY)
353 fcntl.flock(lock_handle, fcntl.LOCK_EX | fcntl.LOCK_NB)
355 die('Another instance of rrsync is already accessing this directory.')
359 print(sys.argv[0], 'error:', *msg, file=sys.stderr)
360 if sys.stdin.isatty():
361 arg_parser.print_help(sys.stderr)
365 # This class displays the --help to the user on argparse error IFF they're running it interactively.
366 class OurArgParser(argparse.ArgumentParser):
367 def error(self, msg):
371 if __name__ == '__main__':
372 our_desc = """Use "man rrsync" to learn how to restrict ssh users to using a restricted rsync command."""
373 arg_parser = OurArgParser(description=our_desc, add_help=False)
374 only_group = arg_parser.add_mutually_exclusive_group()
375 only_group.add_argument('-ro', action='store_true', help="Allow only reading from the DIR. Implies -no-del and -no-lock.")
376 only_group.add_argument('-wo', action='store_true', help="Allow only writing to the DIR.")
377 arg_parser.add_argument('-munge', action='store_true', help="Enable rsync's --munge-links on the server side.")
378 arg_parser.add_argument('-absolute', action='store_true', help="Allow transfer args to use absolute server paths under DIR.")
379 arg_parser.add_argument('-no-del', action='store_true', help="Disable rsync's --delete* and --remove* options.")
380 arg_parser.add_argument('-no-lock', action='store_true', help="Avoid the single-run (per-user) lock check.")
381 arg_parser.add_argument('-no-overwrite', action='store_true', help="Prevent overwriting existing files by enforcing --ignore-existing")
382 arg_parser.add_argument('-help', '-h', action='help', help="Output this help message and exit.")
383 arg_parser.add_argument('dir', metavar='DIR', help="The restricted directory to use.")
384 args = arg_parser.parse_args()
385 args.dir = os.path.realpath(args.dir)
386 args.dir_slash = args.dir + '/'
387 args.dir_slash_len = len(args.dir_slash)
390 elif not args.no_lock:
391 lock_or_die(args.dir)