fs.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610
  1. /*
  2. * This file is part of the UCB release of Plan 9. It is subject to the license
  3. * terms in the LICENSE file found in the top-level directory of this
  4. * distribution and at http://akaros.cs.berkeley.edu/files/Plan9License. No
  5. * part of the UCB release of Plan 9, including this file, may be copied,
  6. * modified, propagated, or distributed except according to the terms contained
  7. * in the LICENSE file.
  8. */
  9. #include "dat.h"
  10. int askforkeys = 1;
  11. char *authaddr;
  12. int debug;
  13. int doprivate = 1;
  14. int gflag;
  15. char *owner;
  16. int kflag;
  17. char *mtpt = "/mnt";
  18. Keyring *ring;
  19. char *service;
  20. int sflag;
  21. int uflag;
  22. extern Srv fs;
  23. static void notifyf(void*, char*);
  24. static void private(void);
  25. char Easproto[] = "auth server protocol botch";
  26. char Ebadarg[] = "invalid argument";
  27. char Ebadkey[] = "bad key";
  28. char Enegotiation[] = "negotiation failed, no common protocols or keys";
  29. char Etoolarge[] = "rpc too large";
  30. Proto*
  31. prototab[] =
  32. {
  33. &apop,
  34. &chap,
  35. &cram,
  36. &httpdigest,
  37. &mschap,
  38. &p9any,
  39. &p9cr,
  40. &p9sk1,
  41. &p9sk2,
  42. &pass,
  43. /* &srs, */
  44. &rsa,
  45. &vnc,
  46. &wep,
  47. nil,
  48. };
  49. void
  50. usage(void)
  51. {
  52. fprint(2, "usage: %s [-DSdknpu] [-a authaddr] [-m mtpt] [-s service]\n",
  53. argv0);
  54. fprint(2, "or %s -g 'params'\n", argv0);
  55. exits("usage");
  56. }
  57. void
  58. main(int argc, char **argv)
  59. {
  60. int i, trysecstore;
  61. char err[ERRMAX], *s;
  62. Dir d;
  63. Proto *p;
  64. char *secstorepw;
  65. trysecstore = 1;
  66. secstorepw = nil;
  67. ARGBEGIN{
  68. case 'D':
  69. chatty9p++;
  70. break;
  71. case 'S': /* server: read nvram, no prompting for keys */
  72. askforkeys = 0;
  73. trysecstore = 0;
  74. sflag = 1;
  75. break;
  76. case 'a':
  77. authaddr = EARGF(usage());
  78. break;
  79. case 'd':
  80. debug = 1;
  81. doprivate = 0;
  82. break;
  83. case 'g': /* get: prompt for key for name and domain */
  84. gflag = 1;
  85. break;
  86. case 'k': /* reinitialize nvram */
  87. kflag = 1;
  88. break;
  89. case 'm': /* set default mount point */
  90. mtpt = EARGF(usage());
  91. break;
  92. case 'n':
  93. trysecstore = 0;
  94. break;
  95. case 'p':
  96. doprivate = 0;
  97. break;
  98. case 's': /* set service name */
  99. service = EARGF(usage());
  100. break;
  101. case 'u': /* user: set hostowner */
  102. uflag = 1;
  103. break;
  104. default:
  105. usage();
  106. }ARGEND
  107. if(argc != 0 && !gflag)
  108. usage();
  109. if(doprivate)
  110. private();
  111. initcap();
  112. quotefmtinstall();
  113. fmtinstall('A', _attrfmt);
  114. fmtinstall('N', attrnamefmt);
  115. fmtinstall('H', encodefmt);
  116. ring = emalloc(sizeof(*ring));
  117. notify(notifyf);
  118. if(gflag){
  119. if(argc != 1)
  120. usage();
  121. askuser(argv[0]);
  122. exits(nil);
  123. }
  124. for(i=0; prototab[i]; i++){
  125. p = prototab[i];
  126. if(p->name == nil)
  127. sysfatal("protocol %d has no name", i);
  128. if(p->init == nil)
  129. sysfatal("protocol %s has no init", p->name);
  130. if(p->write == nil)
  131. sysfatal("protocol %s has no write", p->name);
  132. if(p->read == nil)
  133. sysfatal("protocol %s has no read", p->name);
  134. if(p->close == nil)
  135. sysfatal("protocol %s has no close", p->name);
  136. if(p->keyprompt == nil)
  137. p->keyprompt = "";
  138. }
  139. if(sflag){
  140. s = getnvramkey(kflag ? NVwrite : NVwriteonerr, &secstorepw);
  141. if(s == nil)
  142. fprint(2, "factotum warning: cannot read nvram: %r\n");
  143. else if(ctlwrite(s, 0) < 0)
  144. fprint(2, "factotum warning: cannot add nvram key: %r\n");
  145. if(secstorepw != nil)
  146. trysecstore = 1;
  147. if (s != nil) {
  148. memset(s, 0, strlen(s));
  149. free(s);
  150. }
  151. } else if(uflag)
  152. promptforhostowner();
  153. owner = getuser();
  154. if(trysecstore){
  155. if(havesecstore() == 1){
  156. while(secstorefetch(secstorepw) < 0){
  157. rerrstr(err, sizeof err);
  158. if(strcmp(err, "cancel") == 0)
  159. break;
  160. fprint(2, "factotum: secstorefetch: %r\n");
  161. fprint(2, "Enter an empty password to quit.\n");
  162. free(secstorepw);
  163. secstorepw = nil; /* just try nvram pw once */
  164. }
  165. }else{
  166. /*
  167. rerrstr(err, sizeof err);
  168. if(*err)
  169. fprint(2, "factotum: havesecstore: %r\n");
  170. */
  171. }
  172. }
  173. postmountsrv(&fs, service, mtpt, MBEFORE);
  174. if(service){
  175. nulldir(&d);
  176. d.mode = 0666;
  177. s = emalloc(10+strlen(service));
  178. strcpy(s, "/srv/");
  179. strcat(s, service);
  180. if(dirwstat(s, &d) < 0)
  181. fprint(2, "factotum warning: cannot chmod 666 %s: %r\n", s);
  182. free(s);
  183. }
  184. exits(nil);
  185. }
  186. char *pmsg = "Warning! %s can't protect itself from debugging: %r\n";
  187. char *smsg = "Warning! %s can't turn off swapping: %r\n";
  188. /* don't allow other processes to debug us and steal keys */
  189. static void
  190. private(void)
  191. {
  192. int fd;
  193. char buf[64];
  194. snprint(buf, sizeof(buf), "#p/%d/ctl", getpid());
  195. fd = open(buf, OWRITE);
  196. if(fd < 0){
  197. fprint(2, pmsg, argv0);
  198. return;
  199. }
  200. if(fprint(fd, "private") < 0)
  201. fprint(2, pmsg, argv0);
  202. if(fprint(fd, "noswap") < 0)
  203. fprint(2, smsg, argv0);
  204. close(fd);
  205. }
  206. static void
  207. notifyf(void* v, char *s)
  208. {
  209. if(strncmp(s, "interrupt", 9) == 0)
  210. noted(NCONT);
  211. noted(NDFLT);
  212. }
  213. enum
  214. {
  215. Qroot,
  216. Qfactotum,
  217. Qrpc,
  218. Qkeylist,
  219. Qprotolist,
  220. Qconfirm,
  221. Qlog,
  222. Qctl,
  223. Qneedkey,
  224. };
  225. Qid
  226. mkqid(int type, int path)
  227. {
  228. Qid q;
  229. q.type = type;
  230. q.path = path;
  231. q.vers = 0;
  232. return q;
  233. }
  234. static void
  235. fsattach(Req *r)
  236. {
  237. r->fid->qid = mkqid(QTDIR, Qroot);
  238. r->ofcall.qid = r->fid->qid;
  239. respond(r, nil);
  240. }
  241. static struct {
  242. char *name;
  243. int qidpath;
  244. uint32_t perm;
  245. } dirtab[] = {
  246. "confirm", Qconfirm, 0600|DMEXCL, /* we know this is slot #0 below */
  247. "needkey", Qneedkey, 0600|DMEXCL, /* we know this is slot #1 below */
  248. "ctl", Qctl, 0644,
  249. "rpc", Qrpc, 0666,
  250. "proto", Qprotolist, 0444,
  251. "log", Qlog, 0400|DMEXCL,
  252. };
  253. static int inuse[nelem(dirtab)];
  254. int *confirminuse = &inuse[0];
  255. int *needkeyinuse = &inuse[1];
  256. static void
  257. fillstat(Dir *dir, char *name, int type, int path, uint32_t perm)
  258. {
  259. dir->name = estrdup(name);
  260. dir->uid = estrdup(owner);
  261. dir->gid = estrdup(owner);
  262. dir->mode = perm;
  263. dir->length = 0;
  264. dir->qid = mkqid(type, path);
  265. dir->atime = time(0);
  266. dir->mtime = time(0);
  267. dir->muid = estrdup("");
  268. }
  269. static int
  270. rootdirgen(int n, Dir *dir, void* v)
  271. {
  272. if(n > 0)
  273. return -1;
  274. fillstat(dir, "factotum", QTDIR, Qfactotum, DMDIR|0555);
  275. return 0;
  276. }
  277. static int
  278. fsdirgen(int n, Dir *dir, void* v)
  279. {
  280. if(n >= nelem(dirtab))
  281. return -1;
  282. fillstat(dir, dirtab[n].name, 0, dirtab[n].qidpath, dirtab[n].perm);
  283. return 0;
  284. }
  285. static char*
  286. fswalk1(Fid *fid, char *name, Qid *qid)
  287. {
  288. int i;
  289. switch((uint32_t)fid->qid.path){
  290. default:
  291. return "cannot happen";
  292. case Qroot:
  293. if(strcmp(name, "factotum") == 0){
  294. *qid = mkqid(QTDIR, Qfactotum);
  295. fid->qid = *qid;
  296. return nil;
  297. }
  298. if(strcmp(name, "..") == 0){
  299. *qid = fid->qid;
  300. return nil;
  301. }
  302. return "not found";
  303. case Qfactotum:
  304. for(i=0; i<nelem(dirtab); i++)
  305. if(strcmp(name, dirtab[i].name) == 0){
  306. *qid = mkqid(0, dirtab[i].qidpath);
  307. fid->qid = *qid;
  308. return nil;
  309. }
  310. if(strcmp(name, "..") == 0){
  311. *qid = mkqid(QTDIR, Qroot);
  312. fid->qid = *qid;
  313. return nil;
  314. }
  315. return "not found";
  316. }
  317. }
  318. static void
  319. fsstat(Req *r)
  320. {
  321. int i;
  322. uint32_t path;
  323. path = r->fid->qid.path;
  324. if(path == Qroot){
  325. fillstat(&r->d, "/", QTDIR, Qroot, 0555|DMDIR);
  326. respond(r, nil);
  327. return;
  328. }
  329. if(path == Qfactotum){
  330. fillstat(&r->d, "factotum", QTDIR, Qfactotum, 0555|DMDIR);
  331. respond(r, nil);
  332. return;
  333. }
  334. for(i=0; i<nelem(dirtab); i++)
  335. if(dirtab[i].qidpath == path){
  336. fillstat(&r->d, dirtab[i].name, 0, dirtab[i].qidpath, dirtab[i].perm);
  337. respond(r, nil);
  338. return;
  339. }
  340. respond(r, "file not found");
  341. }
  342. static void
  343. fsopen(Req *r)
  344. {
  345. int i, *p, perm;
  346. static int need[4] = {4, 2, 6, 1};
  347. int n;
  348. Fsstate *fss;
  349. p = nil;
  350. for(i=0; i<nelem(dirtab); i++)
  351. if(dirtab[i].qidpath == r->fid->qid.path)
  352. break;
  353. if(i < nelem(dirtab)){
  354. if(dirtab[i].perm & DMEXCL)
  355. p = &inuse[i];
  356. if(strcmp(r->fid->uid, owner) == 0)
  357. perm = dirtab[i].perm>>6;
  358. else
  359. perm = dirtab[i].perm;
  360. }else
  361. perm = 5;
  362. n = need[r->ifcall.mode&3];
  363. if((r->ifcall.mode&~(3|OTRUNC)) || ((perm&n) != n)){
  364. respond(r, "permission denied");
  365. return;
  366. }
  367. if(p){
  368. if(*p){
  369. respond(r, "file in use");
  370. return;
  371. }
  372. (*p)++;
  373. }
  374. r->fid->aux = fss = emalloc(sizeof(Fsstate));
  375. fss->phase = Notstarted;
  376. fss->sysuser = r->fid->uid;
  377. fss->attr = nil;
  378. strcpy(fss->err, "factotum/fs.c no error");
  379. respond(r, nil);
  380. }
  381. static void
  382. fsdestroyfid(Fid *fid)
  383. {
  384. int i;
  385. Fsstate *fss;
  386. if(fid->omode != -1){
  387. for(i=0; i<nelem(dirtab); i++)
  388. if(dirtab[i].qidpath == fid->qid.path)
  389. if(dirtab[i].perm&DMEXCL)
  390. inuse[i] = 0;
  391. }
  392. fss = fid->aux;
  393. if(fss == nil)
  394. return;
  395. if(fss->ps)
  396. (*fss->proto->close)(fss);
  397. _freeattr(fss->attr);
  398. free(fss);
  399. }
  400. static int
  401. readlist(int off, int (*gen)(int, char*, uint, Fsstate*), Req *r,
  402. Fsstate *fss)
  403. {
  404. char *a, *ea;
  405. int n;
  406. a = r->ofcall.data;
  407. ea = a+r->ifcall.count;
  408. for(;;){
  409. n = (*gen)(off, a, ea-a, fss);
  410. if(n == 0){
  411. r->ofcall.count = a - (char*)r->ofcall.data;
  412. return off;
  413. }
  414. a += n;
  415. off++;
  416. }
  417. }
  418. enum { Nearend = 2, }; /* at least room for \n and NUL */
  419. /* result in `a', of `n' bytes maximum */
  420. static int
  421. keylist(int i, char *a, uint n, Fsstate *fss)
  422. {
  423. int wb;
  424. Keyinfo ki;
  425. Key *k;
  426. k = nil;
  427. mkkeyinfo(&ki, fss, nil);
  428. ki.attr = nil;
  429. ki.skip = i;
  430. ki.usedisabled = 1;
  431. if(findkey(&k, &ki, "") != RpcOk)
  432. return 0;
  433. memset(a + n - Nearend, 0, Nearend);
  434. wb = snprint(a, n, "key %A %N\n", k->attr, k->privattr);
  435. closekey(k);
  436. if (wb >= n - 1 && a[n - 2] != '\n' && a[n - 2] != '\0') {
  437. /* line won't fit in `a', so just truncate */
  438. strcpy(a + n - 2, "\n");
  439. return 0;
  440. }
  441. return wb;
  442. }
  443. static int
  444. protolist(int i, char *a, uint n, Fsstate *fss)
  445. {
  446. USED(fss);
  447. if(i >= nelem(prototab)-1)
  448. return 0;
  449. if(strlen(prototab[i]->name)+1 > n)
  450. return 0;
  451. n = strlen(prototab[i]->name)+1;
  452. memmove(a, prototab[i]->name, n-1);
  453. a[n-1] = '\n';
  454. return n;
  455. }
  456. static void
  457. fsread(Req *r)
  458. {
  459. Fsstate *s;
  460. s = r->fid->aux;
  461. switch((uint32_t)r->fid->qid.path){
  462. default:
  463. respond(r, "bug in fsread");
  464. break;
  465. case Qroot:
  466. dirread9p(r, rootdirgen, nil);
  467. respond(r, nil);
  468. break;
  469. case Qfactotum:
  470. dirread9p(r, fsdirgen, nil);
  471. respond(r, nil);
  472. break;
  473. case Qrpc:
  474. rpcread(r);
  475. break;
  476. case Qneedkey:
  477. needkeyread(r);
  478. break;
  479. case Qconfirm:
  480. confirmread(r);
  481. break;
  482. case Qlog:
  483. logread(r);
  484. break;
  485. case Qctl:
  486. s->listoff = readlist(s->listoff, keylist, r, s);
  487. respond(r, nil);
  488. break;
  489. case Qprotolist:
  490. s->listoff = readlist(s->listoff, protolist, r, s);
  491. respond(r, nil);
  492. break;
  493. }
  494. }
  495. static void
  496. fswrite(Req *r)
  497. {
  498. int ret;
  499. char err[ERRMAX], *s;
  500. switch((uint32_t)r->fid->qid.path){
  501. default:
  502. respond(r, "bug in fswrite");
  503. break;
  504. case Qrpc:
  505. rpcwrite(r);
  506. break;
  507. case Qneedkey:
  508. case Qconfirm:
  509. case Qctl:
  510. s = emalloc(r->ifcall.count+1);
  511. memmove(s, r->ifcall.data, r->ifcall.count);
  512. s[r->ifcall.count] = '\0';
  513. switch((uint32_t)r->fid->qid.path){
  514. default:
  515. abort();
  516. case Qneedkey:
  517. ret = needkeywrite(s);
  518. break;
  519. case Qconfirm:
  520. ret = confirmwrite(s);
  521. break;
  522. case Qctl:
  523. ret = ctlwrite(s, 0);
  524. break;
  525. }
  526. free(s);
  527. if(ret < 0){
  528. rerrstr(err, sizeof err);
  529. respond(r, err);
  530. }else{
  531. r->ofcall.count = r->ifcall.count;
  532. respond(r, nil);
  533. }
  534. break;
  535. }
  536. }
  537. static void
  538. fsflush(Req *r)
  539. {
  540. confirmflush(r->oldreq);
  541. needkeyflush(r->oldreq);
  542. logflush(r->oldreq);
  543. respond(r, nil);
  544. }
  545. Srv fs = {
  546. .attach= fsattach,
  547. .walk1= fswalk1,
  548. .open= fsopen,
  549. .read= fsread,
  550. .write= fswrite,
  551. .stat= fsstat,
  552. .flush= fsflush,
  553. .destroyfid= fsdestroyfid,
  554. };