Commit 05bacf6f authored by vieira's avatar vieira Committed by Brian May

Use argparse for command line options

Fixes the kind of problems reported on #75 but does break the command
line "API" (hopefully).
parent dea3f219
try:
from sshuttle.version import version as __version__
except ImportError:
__version__ = "unknown"
...@@ -2,198 +2,47 @@ import sys ...@@ -2,198 +2,47 @@ import sys
import re import re
import socket import socket
import sshuttle.helpers as helpers import sshuttle.helpers as helpers
import sshuttle.options as options
import sshuttle.client as client import sshuttle.client as client
import sshuttle.firewall as firewall import sshuttle.firewall as firewall
import sshuttle.hostwatch as hostwatch import sshuttle.hostwatch as hostwatch
import sshuttle.ssyslog as ssyslog import sshuttle.ssyslog as ssyslog
from sshuttle.options import parser
from sshuttle.helpers import family_ip_tuple, log, Fatal from sshuttle.helpers import family_ip_tuple, log, Fatal
# 1.2.3.4/5 or just 1.2.3.4
def parse_subnet4(s):
m = re.match(r'(\d+)(?:\.(\d+)\.(\d+)\.(\d+))?(?:/(\d+))?$', s)
if not m:
raise Fatal('%r is not a valid IP subnet format' % s)
(a, b, c, d, width) = m.groups()
(a, b, c, d) = (int(a or 0), int(b or 0), int(c or 0), int(d or 0))
if width is None:
width = 32
else:
width = int(width)
if a > 255 or b > 255 or c > 255 or d > 255:
raise Fatal('%d.%d.%d.%d has numbers > 255' % (a, b, c, d))
if width > 32:
raise Fatal('*/%d is greater than the maximum of 32' % width)
return(socket.AF_INET, '%d.%d.%d.%d' % (a, b, c, d), width)
# 1:2::3/64 or just 1:2::3
def parse_subnet6(s):
m = re.match(r'(?:([a-fA-F\d:]+))?(?:/(\d+))?$', s)
if not m:
raise Fatal('%r is not a valid IP subnet format' % s)
(net, width) = m.groups()
if width is None:
width = 128
else:
width = int(width)
if width > 128:
raise Fatal('*/%d is greater than the maximum of 128' % width)
return(socket.AF_INET6, net, width)
# Subnet file, supporting empty lines and hash-started comment lines
def parse_subnet_file(s):
try:
handle = open(s, 'r')
except OSError:
raise Fatal('Unable to open subnet file: %s' % s)
raw_config_lines = handle.readlines()
config_lines = []
for line_no, line in enumerate(raw_config_lines):
line = line.strip()
if len(line) == 0:
continue
if line[0] == '#':
continue
config_lines.append(line)
return config_lines
# list of:
# 1.2.3.4/5 or just 1.2.3.4
# 1:2::3/64 or just 1:2::3
def parse_subnets(subnets_str):
subnets = []
for s in subnets_str:
if ':' in s:
subnet = parse_subnet6(s)
else:
subnet = parse_subnet4(s)
subnets.append(subnet)
return subnets
# 1.2.3.4:567 or just 1.2.3.4 or just 567
def parse_ipport4(s):
s = str(s)
m = re.match(r'(?:(\d+)\.(\d+)\.(\d+)\.(\d+))?(?::)?(?:(\d+))?$', s)
if not m:
raise Fatal('%r is not a valid IP:port format' % s)
(a, b, c, d, port) = m.groups()
(a, b, c, d, port) = (int(a or 0), int(b or 0), int(c or 0), int(d or 0),
int(port or 0))
if a > 255 or b > 255 or c > 255 or d > 255:
raise Fatal('%d.%d.%d.%d has numbers > 255' % (a, b, c, d))
if port > 65535:
raise Fatal('*:%d is greater than the maximum of 65535' % port)
if a is None:
a = b = c = d = 0
return ('%d.%d.%d.%d' % (a, b, c, d), port)
# [1:2::3]:456 or [1:2::3] or 456
def parse_ipport6(s):
s = str(s)
m = re.match(r'(?:\[([^]]*)])?(?::)?(?:(\d+))?$', s)
if not m:
raise Fatal('%s is not a valid IP:port format' % s)
(ip, port) = m.groups()
(ip, port) = (ip or '::', int(port or 0))
return (ip, port)
def parse_list(list):
return re.split(r'[\s,]+', list.strip()) if list else []
optspec = """
sshuttle [-l [ip:]port] [-r [username@]sshserver[:port]] <subnets...>
sshuttle --firewall <port> <subnets...>
sshuttle --hostwatch
--
l,listen= transproxy to this ip address and port number
H,auto-hosts scan for remote hostnames and update local /etc/hosts
N,auto-nets automatically determine subnets to route
dns capture local DNS requests and forward to the remote DNS server
ns-hosts= capture and forward remote DNS requests to the following servers
method= auto, nat, tproxy or pf
python= path to python interpreter on the remote server
r,remote= ssh hostname (and optional username) of remote sshuttle server
x,exclude= exclude this subnet (can be used more than once)
X,exclude-from= exclude the subnets in a file (whitespace separated)
v,verbose increase debug message verbosity
V,version print the sshuttle version number and exit
e,ssh-cmd= the command to use to connect to the remote [ssh]
seed-hosts= with -H, use these hostnames for initial scan (comma-separated)
no-latency-control sacrifice latency to improve bandwidth benchmarks
wrap= restart counting channel numbers after this number (for testing)
disable-ipv6 disables ipv6 support
D,daemon run in the background as a daemon
s,subnets= file where the subnets are stored, instead of on the command line
syslog send log messages to syslog (default if you use --daemon)
pidfile= pidfile name (only if using --daemon) [./sshuttle.pid]
server (internal use only)
firewall (internal use only)
hostwatch (internal use only)
"""
def main(): def main():
o = options.Options(optspec) opt = parser.parse_args()
(opt, flags, extra) = o.parse(sys.argv[1:])
if opt.version:
from sshuttle.version import version
print(version)
return 0
if opt.daemon: if opt.daemon:
opt.syslog = 1 opt.syslog = 1
if opt.wrap: if opt.wrap:
import sshuttle.ssnet as ssnet import sshuttle.ssnet as ssnet
ssnet.MAX_CHANNEL = int(opt.wrap) ssnet.MAX_CHANNEL = opt.wrap
helpers.verbose = opt.verbose or 0 helpers.verbose = opt.verbose
try: try:
if opt.firewall: if opt.firewall:
if len(extra) != 0: if opt.subnets:
o.fatal('exactly zero arguments expected') parser.error('exactly zero arguments expected')
return firewall.main(opt.method, opt.syslog) return firewall.main(opt.method, opt.syslog)
elif opt.hostwatch: elif opt.hostwatch:
return hostwatch.hw_main(extra) return hostwatch.hw_main(opt.subnets)
else: else:
if len(extra) < 1 and not opt.auto_nets and not opt.subnets: includes = opt.subnets_from_file or opt.subnets
o.fatal('at least one subnet, subnet file, or -N expected') excludes = opt.exclude
includes = extra if not includes and not opt.auto_nets:
excludes = ['127.0.0.0/8'] parser.error('at least one subnet, subnet file, or -N expected')
for k, v in flags:
if k in ('-x', '--exclude'):
excludes.append(v)
if k in ('-X', '--exclude-from'):
excludes += open(v).read().split()
remotename = opt.remote remotename = opt.remote
if remotename == '' or remotename == '-': if remotename == '' or remotename == '-':
remotename = None remotename = None
nslist = [family_ip_tuple(ns) for ns in parse_list(opt.ns_hosts)] nslist = [family_ip_tuple(ns) for ns in opt.ns_hosts]
if opt.seed_hosts and not opt.auto_hosts: if opt.seed_hosts and not opt.auto_hosts:
o.fatal('--seed-hosts only works if you also use -H') parser.error('--seed-hosts only works if you also use -H')
if opt.seed_hosts: if opt.seed_hosts:
sh = re.split(r'[\s,]+', (opt.seed_hosts or "").strip()) sh = re.split(r'[\s,]+', (opt.seed_hosts or "").strip())
elif opt.auto_hosts: elif opt.auto_hosts:
sh = [] sh = []
else: else:
sh = None sh = None
if opt.subnets:
includes = parse_subnet_file(opt.subnets)
if not opt.method:
method_name = "auto"
elif opt.method in ["auto", "nat", "tproxy", "pf"]:
method_name = opt.method
else:
o.fatal("method_name %s not supported" % opt.method)
if opt.listen: if opt.listen:
ipport_v6 = None ipport_v6 = None
ipport_v4 = None ipport_v4 = None
...@@ -218,11 +67,11 @@ def main(): ...@@ -218,11 +67,11 @@ def main():
opt.latency_control, opt.latency_control,
opt.dns, opt.dns,
nslist, nslist,
method_name, opt.method,
sh, sh,
opt.auto_nets, opt.auto_nets,
parse_subnets(includes), includes,
parse_subnets(excludes), excludes,
opt.daemon, opt.pidfile) opt.daemon, opt.pidfile)
if return_code == 0: if return_code == 0:
......
"""Command-line options parser.
With the help of an options spec string, easily parse command-line options.
"""
import sys
import os
import textwrap
import getopt
import re import re
import struct import socket
from argparse import ArgumentParser, Action, ArgumentTypeError as Fatal
from sshuttle import __version__
class OptDict: from sshuttle.helpers import family_ip_tuple
def __init__(self): # 1.2.3.4/5 or just 1.2.3.4
self._opts = {} def parse_subnet4(s):
m = re.match(r'(\d+)(?:\.(\d+)\.(\d+)\.(\d+))?(?:/(\d+))?$', s)
def __setitem__(self, k, v): if not m:
if k.startswith('no-') or k.startswith('no_'): raise Fatal('%r is not a valid IP subnet format' % s)
k = k[3:] (a, b, c, d, width) = m.groups()
v = not v (a, b, c, d) = (int(a or 0), int(b or 0), int(c or 0), int(d or 0))
self._opts[k] = v if width is None:
width = 32
def __getitem__(self, k): else:
if k.startswith('no-') or k.startswith('no_'): width = int(width)
return not self._opts[k[3:]] if a > 255 or b > 255 or c > 255 or d > 255:
return self._opts[k] raise Fatal('%d.%d.%d.%d has numbers > 255' % (a, b, c, d))
if width > 32:
def __getattr__(self, k): raise Fatal('*/%d is greater than the maximum of 32' % width)
return self[k] return(socket.AF_INET, '%d.%d.%d.%d' % (a, b, c, d), width)
def _default_onabort(msg): # 1:2::3/64 or just 1:2::3
sys.exit(97) def parse_subnet6(s):
m = re.match(r'(?:([a-fA-F\d:]+))?(?:/(\d+))?$', s)
if not m:
def _intify(v): raise Fatal('%r is not a valid IP subnet format' % s)
(net, width) = m.groups()
if width is None:
width = 128
else:
width = int(width)
if width > 128:
raise Fatal('*/%d is greater than the maximum of 128' % width)
return(socket.AF_INET6, net, width)
# Subnet file, supporting empty lines and hash-started comment lines
def parse_subnet_file(s):
try: try:
vv = int(v or '') handle = open(s, 'r')
if str(vv) == v: except OSError:
return vv raise Fatal('Unable to open subnet file: %s' % s)
except ValueError:
pass raw_config_lines = handle.readlines()
return v subnets = []
for line_no, line in enumerate(raw_config_lines):
line = line.strip()
def _atoi(v): if len(line) == 0:
try: continue
return int(v or 0) if line[0] == '#':
except ValueError: continue
return 0 subnets.append(parse_subnet(line))
return subnets
def _remove_negative_kv(k, v):
if k.startswith('no-') or k.startswith('no_'):
return k[3:], not v # 1.2.3.4/5 or just 1.2.3.4
return k, v # 1:2::3/64 or just 1:2::3
def parse_subnet(subnet_str):
if ':' in subnet_str:
def _remove_negative_k(k): return parse_subnet6(subnet_str)
return _remove_negative_kv(k, None)[0] else:
return parse_subnet4(subnet_str)
def _tty_width():
if not hasattr(sys.stderr, "fileno"): # 1.2.3.4:567 or just 1.2.3.4 or just 567
return _atoi(os.environ.get('WIDTH')) or 70 def parse_ipport4(s):
s = struct.pack("HHHH", 0, 0, 0, 0) s = str(s)
try: m = re.match(r'(?:(\d+)\.(\d+)\.(\d+)\.(\d+))?(?::)?(?:(\d+))?$', s)
import fcntl if not m:
import termios raise Fatal('%r is not a valid IP:port format' % s)
s = fcntl.ioctl(sys.stderr.fileno(), termios.TIOCGWINSZ, s) (a, b, c, d, port) = m.groups()
except (IOError, ImportError): (a, b, c, d, port) = (int(a or 0), int(b or 0), int(c or 0), int(d or 0),
return _atoi(os.environ.get('WIDTH')) or 70 int(port or 0))
(ysize, xsize, ypix, xpix) = struct.unpack('HHHH', s) if a > 255 or b > 255 or c > 255 or d > 255:
return xsize or 70 raise Fatal('%d.%d.%d.%d has numbers > 255' % (a, b, c, d))
if port > 65535:
raise Fatal('*:%d is greater than the maximum of 65535' % port)
class Options: if a is None:
a = b = c = d = 0
"""Option parser. return ('%d.%d.%d.%d' % (a, b, c, d), port)
When constructed, two strings are mandatory. The first one is the command
name showed before error messages. The second one is a string called an
optspec that specifies the synopsis and option flags and their description. # [1:2::3]:456 or [1:2::3] or 456
For more information about optspecs, consult the bup-options(1) man page. def parse_ipport6(s):
s = str(s)
Two optional arguments specify an alternative parsing function and an m = re.match(r'(?:\[([^]]*)])?(?::)?(?:(\d+))?$', s)
alternative behaviour on abort (after having output the usage string). if not m:
raise Fatal('%s is not a valid IP:port format' % s)
By default, the parser function is getopt.gnu_getopt, and the abort (ip, port) = m.groups()
behaviour is to exit the program. (ip, port) = (ip or '::', int(port or 0))
""" return (ip, port)
def __init__(self, optspec, optfunc=getopt.gnu_getopt,
onabort=_default_onabort): def parse_list(list):
self.optspec = optspec return re.split(r'[\s,]+', list.strip()) if list else []
self._onabort = onabort
self.optfunc = optfunc
self._aliases = {} class Concat(Action):
self._shortopts = 'h?' def __init__(self, option_strings, dest, nargs=None, **kwargs):
self._longopts = ['help'] if nargs is not None:
self._hasparms = {} raise ValueError("nargs not supported")
self._defaults = {} super(Concat, self).__init__(option_strings, dest, **kwargs)
self._usagestr = self._gen_usage()
def __call__(self, parser, namespace, values, option_string=None):
def _gen_usage(self): curr_value = getattr(namespace, self.dest, [])
out = [] setattr(namespace, self.dest, curr_value + values)
lines = self.optspec.strip().split('\n')
lines.reverse()
first_syn = True parser = ArgumentParser(
while lines: prog="sshuttle",
l = lines.pop() usage="%(prog)s [-l [ip:]port] [-r [user@]sshserver[:port]] <subnets...>"
if l == '--': )
break parser.add_argument(
out.append('%s: %s\n' % (first_syn and 'usage' or ' or', l)) "subnets",
first_syn = False metavar="IP/MASK [IP/MASK...]",
out.append('\n') nargs="*",
last_was_option = False type=parse_subnet,
while lines: help="""
l = lines.pop() capture and forward traffic to these subnets (whitespace separated)
if l.startswith(' '): """
out.append('%s%s\n' % (last_was_option and '\n' or '', )
l.lstrip())) parser.add_argument(
last_was_option = False "-l", "--listen",
elif l: metavar="[IP:]PORT",
(flags, extra) = l.split(' ', 1) help="""
extra = extra.strip() transproxy to this ip address and port number
if flags.endswith('='): """
flags = flags[:-1] )
has_parm = 1 parser.add_argument(
else: "-H", "--auto-hosts",
has_parm = 0 action="store_true",
g = re.search(r'\[([^\]]*)\]$', extra) help="""
if g: scan for remote hostnames and update local /etc/hosts
defval = g.group(1) """
else: )
defval = None parser.add_argument(
flagl = flags.split(',') "-N", "--auto-nets",
flagl_nice = [] action="store_true",
for _f in flagl: help="""
f, dvi = _remove_negative_kv(_f, _intify(defval)) automatically determine subnets to route
self._aliases[f] = _remove_negative_k(flagl[0]) """
self._hasparms[f] = has_parm )
self._defaults[f] = dvi parser.add_argument(
if len(f) == 1: "--dns",
self._shortopts += f + (has_parm and ':' or '') action="store_true",
flagl_nice.append('-' + f) help="""
else: capture local DNS requests and forward to the remote DNS server
f_nice = re.sub(r'\W', '_', f) """
self._aliases[f_nice] = _remove_negative_k(flagl[0]) )
self._longopts.append(f + (has_parm and '=' or '')) parser.add_argument(
self._longopts.append('no-' + f) "--ns-hosts",
flagl_nice.append('--' + _f) metavar="IP[,IP]",
flags_nice = ', '.join(flagl_nice) default=[],
if has_parm: type=parse_list,
flags_nice += ' ...' help="""
prefix = ' %-20s ' % flags_nice capture and forward DNS requests made to the following servers
argtext = '\n'.join(textwrap.wrap(extra, width=_tty_width(), """
initial_indent=prefix, )
subsequent_indent=' ' * 28)) parser.add_argument(
out.append(argtext + '\n') "--method",
last_was_option = True choices=["auto", "nat", "tproxy", "pf"],
else: metavar="TYPE",
out.append('\n') default="auto",
last_was_option = False help="""
return ''.join(out).rstrip() + '\n' %(choices)s
"""
def usage(self, msg=""): )
"""Print usage string to stderr and abort.""" parser.add_argument(
sys.stderr.write(self._usagestr) "--python",
e = self._onabort and self._onabort(msg) or None metavar="PATH",
if e: help="""
raise e path to python interpreter on the remote server
"""
def fatal(self, s): )
"""Print an error message to stderr and abort with usage string.""" parser.add_argument(
msg = 'error: %s\n' % s "-r", "--remote",
sys.stderr.write(msg) metavar="[USERNAME@]ADDR[:PORT]",
return self.usage(msg) help="""
ssh hostname (and optional username) of remote %(prog)s server
def parse(self, args): """
"""Parse a list of arguments and return (options, flags, extra). )
parser.add_argument(
In the returned tuple, "options" is an OptDict with known options, "-x", "--exclude",
"flags" is a list of option flags that were used on the command-line, metavar="IP/MASK",
and "extra" is a list of positional arguments. action="append",
""" default=[parse_subnet('127.0.0.1/8')],
try: type=parse_subnet,
(flags, extra) = self.optfunc( help="""
args, self._shortopts, self._longopts) exclude this subnet (can be used more than once)
except getopt.GetoptError as e: """
self.fatal(e) )
parser.add_argument(
opt = OptDict() "-X", "--exclude-from",
metavar="PATH",
for k, v in self._defaults.items(): action=Concat,
k = self._aliases[k] dest="exclude",
opt[k] = v type=parse_subnet_file,
help="""
for (k, v) in flags: exclude the subnets in a file (whitespace separated)
k = k.lstrip('-') """
if k in ('h', '?', 'help'): )
self.usage() parser.add_argument(
if k.startswith('no-'): "-v", "--verbose",
k = self._aliases[k[3:]] action="count",
v = 0 default=0,
else: help="""
k = self._aliases[k] increase debug message verbosity
if not self._hasparms[k]: """
assert(v == '') )
v = (opt._opts.get(k) or 0) + 1 parser.add_argument(
else: "-V", "--version",
v = _intify(v) action="version",
opt[k] = v version=__version__,
for (f1, f2) in self._aliases.items(): help="""
opt[f1] = opt._opts.get(f2) print the %(prog)s version number and exit
return (opt, flags, extra) """
)
parser.add_argument(
"-e", "--ssh-cmd",
metavar="CMD",
default="ssh",
help="""
the command to use to connect to the remote [%(default)s]
"""
)
parser.add_argument(
"--seed-hosts",
metavar="HOSTNAME[,HOSTNAME]",
default=[],
help="""
with -H, use these hostnames for initial scan (comma-separated)
"""
)
parser.add_argument(
"--no-latency-control",
action="store_false",
dest="latency_control",
help="""
sacrifice latency to improve bandwidth benchmarks
"""
)
parser.add_argument(
"--wrap",
metavar="NUM",
type=int,
help="""
restart counting channel numbers after this number (for testing)
"""
)
parser.add_argument(
"--disable-ipv6",
action="store_true",
help="""
disable IPv6 support
"""
)
parser.add_argument(
"-D", "--daemon",
action="store_true",
help="""
run in the background as a daemon
"""
)
parser.add_argument(
"-s", "--subnets",
metavar="PATH",
dest="subnets_from_file",
type=parse_subnet_file,
help="""
file where the subnets are stored, instead of on the command line
"""
)
parser.add_argument(
"--syslog",
action="store_true",
help="""
send log messages to syslog (default if you use --daemon)
"""
)
parser.add_argument(
"--pidfile",
metavar="PATH",
default="./sshuttle.pid",
help="""
pidfile name (only if using --daemon) [%(default)s]
"""
)
parser.add_argument(
"--server",
action="store_true",
help="""
(internal use only)
"""
)
parser.add_argument(
"--firewall",
action="store_true",
help="""
(internal use only)
"""
)
parser.add_argument(
"--hostwatch",
action="store_true",
help="""
(internal use only)
"""
)
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment