auth.c 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198
  1. #include <u.h>
  2. #include <libc.h>
  3. #include <auth.h>
  4. #include <fcall.h>
  5. #include <thread.h>
  6. #include <9p.h>
  7. typedef struct Afid Afid;
  8. struct Afid
  9. {
  10. AuthRpc *rpc;
  11. char *uname;
  12. char *aname;
  13. int authok;
  14. int afd;
  15. };
  16. static uvlong authgen = 1ULL<<63;
  17. void
  18. auth9p(Req *r)
  19. {
  20. char *spec;
  21. Afid *afid;
  22. afid = emalloc9p(sizeof(Afid));
  23. afid->afd = open("/mnt/factotum/rpc", ORDWR);
  24. if(afid->afd < 0)
  25. goto error;
  26. if((afid->rpc = auth_allocrpc(afid->afd)) == nil)
  27. goto error;
  28. if(r->ifcall.uname[0] == 0)
  29. goto error;
  30. afid->uname = estrdup9p(r->ifcall.uname);
  31. afid->aname = estrdup9p(r->ifcall.aname);
  32. spec = r->srv->keyspec;
  33. if(spec == nil)
  34. spec = "proto=p9any role=server";
  35. if(auth_rpc(afid->rpc, "start", spec, strlen(spec)) != ARok)
  36. goto error;
  37. r->afid->qid.type = QTAUTH;
  38. r->afid->qid.path = ++authgen;
  39. r->afid->qid.vers = 0;
  40. r->afid->omode = ORDWR;
  41. r->ofcall.qid = r->afid->qid;
  42. r->afid->aux = afid;
  43. respond(r, nil);
  44. return;
  45. error:
  46. if(afid->rpc)
  47. auth_freerpc(afid->rpc);
  48. if(afid->uname)
  49. free(afid->uname);
  50. if(afid->aname)
  51. free(afid->aname);
  52. if(afid->afd >= 0)
  53. close(afid->afd);
  54. free(afid);
  55. responderror(r);
  56. }
  57. static int
  58. _authread(Afid *afid, void *data, int count)
  59. {
  60. AuthInfo *ai;
  61. switch(auth_rpc(afid->rpc, "read", nil, 0)){
  62. case ARdone:
  63. ai = auth_getinfo(afid->rpc);
  64. if(ai == nil)
  65. return -1;
  66. auth_freeAI(ai);
  67. if(chatty9p)
  68. fprint(2, "authenticate %s/%s: ok\n", afid->uname, afid->aname);
  69. afid->authok = 1;
  70. return 0;
  71. case ARok:
  72. if(count < afid->rpc->narg){
  73. werrstr("authread count too small");
  74. return -1;
  75. }
  76. count = afid->rpc->narg;
  77. memmove(data, afid->rpc->arg, count);
  78. return count;
  79. case ARphase:
  80. default:
  81. werrstr("authrpc botch");
  82. return -1;
  83. }
  84. }
  85. void
  86. authread(Req *r)
  87. {
  88. int n;
  89. Afid *afid;
  90. Fid *fid;
  91. fid = r->fid;
  92. afid = fid->aux;
  93. if(afid == nil || r->fid->qid.type != QTAUTH){
  94. respond(r, "not an auth fid");
  95. return;
  96. }
  97. n = _authread(afid, r->ofcall.data, r->ifcall.count);
  98. if(n < 0){
  99. responderror(r);
  100. return;
  101. }
  102. r->ofcall.count = n;
  103. respond(r, nil);
  104. }
  105. void
  106. authwrite(Req *r)
  107. {
  108. Afid *afid;
  109. Fid *fid;
  110. fid = r->fid;
  111. afid = fid->aux;
  112. if(afid == nil || r->fid->qid.type != QTAUTH){
  113. respond(r, "not an auth fid");
  114. return;
  115. }
  116. if(auth_rpc(afid->rpc, "write", r->ifcall.data, r->ifcall.count) != ARok){
  117. responderror(r);
  118. return;
  119. }
  120. r->ofcall.count = r->ifcall.count;
  121. respond(r, nil);
  122. }
  123. void
  124. authdestroy(Fid *fid)
  125. {
  126. Afid *afid;
  127. if((fid->qid.type & QTAUTH) && (afid = fid->aux) != nil){
  128. if(afid->rpc)
  129. auth_freerpc(afid->rpc);
  130. close(afid->afd);
  131. free(afid->uname);
  132. free(afid->aname);
  133. free(afid);
  134. fid->aux = nil;
  135. }
  136. }
  137. int
  138. authattach(Req *r)
  139. {
  140. Afid *afid;
  141. char buf[ERRMAX];
  142. if(r->afid == nil){
  143. respond(r, "not authenticated");
  144. return -1;
  145. }
  146. afid = r->afid->aux;
  147. if((r->afid->qid.type&QTAUTH) == 0 || afid == nil){
  148. respond(r, "not an auth fid");
  149. return -1;
  150. }
  151. if(!afid->authok){
  152. if(_authread(afid, buf, 0) < 0){
  153. responderror(r);
  154. return -1;
  155. }
  156. }
  157. if(strcmp(afid->uname, r->ifcall.uname) != 0){
  158. snprint(buf, sizeof buf, "auth uname mismatch: %s vs %s",
  159. afid->uname, r->ifcall.uname);
  160. respond(r, buf);
  161. return -1;
  162. }
  163. if(strcmp(afid->aname, r->ifcall.aname) != 0){
  164. snprint(buf, sizeof buf, "auth aname mismatch: %s vs %s",
  165. afid->aname, r->ifcall.aname);
  166. respond(r, buf);
  167. return -1;
  168. }
  169. return 0;
  170. }