keyfs.c 19 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114
  1. /*
  2. * keyfs
  3. */
  4. #include <u.h>
  5. #include <libc.h>
  6. #include <ctype.h>
  7. #include <authsrv.h>
  8. #include <fcall.h>
  9. #include <bio.h>
  10. #include <mp.h>
  11. #include <libsec.h>
  12. #include "authcmdlib.h"
  13. #pragma varargck type "W" char*
  14. char authkey[8];
  15. typedef struct Fid Fid;
  16. typedef struct User User;
  17. enum {
  18. Qroot,
  19. Quser,
  20. Qkey,
  21. Qsecret,
  22. Qlog,
  23. Qstatus,
  24. Qexpire,
  25. Qwarnings,
  26. Qmax,
  27. Nuser = 512,
  28. MAXBAD = 10, /* max # of bad attempts before disabling the account */
  29. /* file must be randomly addressible, so names have fixed length */
  30. Namelen = ANAMELEN,
  31. };
  32. enum {
  33. Sok,
  34. Sdisabled,
  35. Smax,
  36. };
  37. struct Fid {
  38. int fid;
  39. ulong qtype;
  40. User *user;
  41. int busy;
  42. Fid *next;
  43. };
  44. struct User {
  45. char *name;
  46. char key[DESKEYLEN];
  47. char secret[SECRETLEN];
  48. ulong expire; /* 0 == never */
  49. uchar status;
  50. ulong bad; /* # of consecutive bad authentication attempts */
  51. int ref;
  52. char removed;
  53. uchar warnings;
  54. long purgatory; /* time purgatory ends */
  55. ulong uniq;
  56. User *link;
  57. };
  58. char *qinfo[Qmax] = {
  59. [Qroot] "keys",
  60. [Quser] ".",
  61. [Qkey] "key",
  62. [Qsecret] "secret",
  63. [Qlog] "log",
  64. [Qexpire] "expire",
  65. [Qstatus] "status",
  66. [Qwarnings] "warnings",
  67. };
  68. char *status[Smax] = {
  69. [Sok] "ok",
  70. [Sdisabled] "disabled",
  71. };
  72. Fid *fids;
  73. User *users[Nuser];
  74. char *userkeys;
  75. int nuser;
  76. ulong uniq = 1;
  77. Fcall rhdr,
  78. thdr;
  79. int usepass;
  80. char *warnarg;
  81. uchar mdata[8192 + IOHDRSZ];
  82. int messagesize = sizeof mdata;
  83. int readusers(void);
  84. ulong hash(char*);
  85. Fid *findfid(int);
  86. User *finduser(char*);
  87. User *installuser(char*);
  88. int removeuser(User*);
  89. void insertuser(User*);
  90. void writeusers(void);
  91. void io(int, int);
  92. void *emalloc(ulong);
  93. Qid mkqid(User*, ulong);
  94. int dostat(User*, ulong, void*, int);
  95. int newkeys(void);
  96. void warning(void);
  97. int weirdfmt(Fmt *f);
  98. char *Auth(Fid*), *Attach(Fid*), *Version(Fid*),
  99. *Flush(Fid*), *Walk(Fid*),
  100. *Open(Fid*), *Create(Fid*),
  101. *Read(Fid *), *Write(Fid*), *Clunk(Fid*),
  102. *Remove(Fid *), *Stat(Fid*), *Wstat(Fid*);
  103. char *(*fcalls[])(Fid*) = {
  104. [Tattach] Attach,
  105. [Tauth] Auth,
  106. [Tclunk] Clunk,
  107. [Tcreate] Create,
  108. [Tflush] Flush,
  109. [Topen] Open,
  110. [Tread] Read,
  111. [Tremove] Remove,
  112. [Tstat] Stat,
  113. [Tversion] Version,
  114. [Twalk] Walk,
  115. [Twrite] Write,
  116. [Twstat] Wstat,
  117. };
  118. static void
  119. usage(void)
  120. {
  121. fprint(2, "usage: %s [-p] [-m mtpt] [-w warn] [keyfile]\n", argv0);
  122. exits("usage");
  123. }
  124. void
  125. main(int argc, char *argv[])
  126. {
  127. char *mntpt;
  128. int p[2];
  129. fmtinstall('W', weirdfmt);
  130. mntpt = "/mnt/keys";
  131. ARGBEGIN{
  132. case 'm':
  133. mntpt = EARGF(usage());
  134. break;
  135. case 'p':
  136. usepass = 1;
  137. break;
  138. case 'w':
  139. warnarg = EARGF(usage());
  140. break;
  141. default:
  142. usage();
  143. break;
  144. }ARGEND
  145. argv0 = "keyfs";
  146. userkeys = "/adm/keys";
  147. if(argc > 1)
  148. usage();
  149. if(argc == 1)
  150. userkeys = argv[0];
  151. if(pipe(p) < 0)
  152. error("can't make pipe: %r");
  153. if(usepass) {
  154. getpass(authkey, nil, 0, 0);
  155. } else {
  156. if(!getauthkey(authkey))
  157. print("keyfs: warning: can't read NVRAM\n");
  158. }
  159. switch(rfork(RFPROC|RFNAMEG|RFNOTEG|RFNOWAIT|RFENVG|RFFDG)){
  160. case 0:
  161. close(p[0]);
  162. io(p[1], p[1]);
  163. exits(0);
  164. case -1:
  165. error("fork");
  166. default:
  167. close(p[1]);
  168. if(mount(p[0], -1, mntpt, MREPL|MCREATE, "") < 0)
  169. error("can't mount: %r");
  170. exits(0);
  171. }
  172. }
  173. char *
  174. Flush(Fid *f)
  175. {
  176. USED(f);
  177. return 0;
  178. }
  179. char *
  180. Auth(Fid *)
  181. {
  182. return "keyfs: authentication not required";
  183. }
  184. char *
  185. Attach(Fid *f)
  186. {
  187. if(f->busy)
  188. Clunk(f);
  189. f->user = 0;
  190. f->qtype = Qroot;
  191. f->busy = 1;
  192. thdr.qid = mkqid(f->user, f->qtype);
  193. return 0;
  194. }
  195. char*
  196. Version(Fid*)
  197. {
  198. Fid *f;
  199. for(f = fids; f; f = f->next)
  200. if(f->busy)
  201. Clunk(f);
  202. if(rhdr.msize > sizeof mdata)
  203. thdr.msize = sizeof mdata;
  204. else
  205. thdr.msize = rhdr.msize;
  206. messagesize = thdr.msize;
  207. if(strncmp(rhdr.version, "9P2000", 6) != 0)
  208. return "bad 9P version";
  209. thdr.version = "9P2000";
  210. return 0;
  211. }
  212. char *
  213. Walk(Fid *f)
  214. {
  215. char *name, *err;
  216. int i, j, max;
  217. Fid *nf;
  218. ulong qtype;
  219. User *user;
  220. if(!f->busy)
  221. return "walk of unused fid";
  222. nf = nil;
  223. qtype = f->qtype;
  224. user = f->user;
  225. if(rhdr.fid != rhdr.newfid){
  226. nf = findfid(rhdr.newfid);
  227. if(nf->busy)
  228. return "fid in use";
  229. f = nf; /* walk f */
  230. }
  231. err = nil;
  232. i = 0;
  233. if(rhdr.nwname > 0){
  234. for(; i<rhdr.nwname; i++){
  235. if(i >= MAXWELEM){
  236. err = "too many path name elements";
  237. break;
  238. }
  239. name = rhdr.wname[i];
  240. switch(qtype){
  241. case Qroot:
  242. if(strcmp(name, "..") == 0)
  243. goto Accept;
  244. user = finduser(name);
  245. if(!user)
  246. goto Out;
  247. qtype = Quser;
  248. Accept:
  249. thdr.wqid[i] = mkqid(user, qtype);
  250. break;
  251. case Quser:
  252. if(strcmp(name, "..") == 0) {
  253. qtype = Qroot;
  254. user = 0;
  255. goto Accept;
  256. }
  257. max = Qmax;
  258. for(j = Quser + 1; j < Qmax; j++)
  259. if(strcmp(name, qinfo[j]) == 0){
  260. qtype = j;
  261. break;
  262. }
  263. if(j < max)
  264. goto Accept;
  265. goto Out;
  266. default:
  267. err = "file is not a directory";
  268. goto Out;
  269. }
  270. }
  271. Out:
  272. if(i < rhdr.nwname && err == nil)
  273. err = "file not found";
  274. }
  275. if(err != nil){
  276. return err;
  277. }
  278. /* if we cloned and then completed the walk, update new fid */
  279. if(rhdr.fid != rhdr.newfid && i == rhdr.nwname){
  280. nf->busy = 1;
  281. nf->qtype = qtype;
  282. if(nf->user = user)
  283. nf->user->ref++;
  284. }else if(nf == nil && rhdr.nwname > 0){ /* walk without clone (rare) */
  285. Clunk(f);
  286. f->busy = 1;
  287. f->qtype = qtype;
  288. if(f->user = user)
  289. f->user->ref++;
  290. }
  291. thdr.nwqid = i;
  292. return 0;
  293. }
  294. char *
  295. Clunk(Fid *f)
  296. {
  297. f->busy = 0;
  298. if(f->user && --f->user->ref == 0 && f->user->removed) {
  299. free(f->user->name);
  300. free(f->user);
  301. }
  302. f->user = 0;
  303. return 0;
  304. }
  305. char *
  306. Open(Fid *f)
  307. {
  308. int mode;
  309. if(!f->busy)
  310. return "open of unused fid";
  311. mode = rhdr.mode;
  312. if(f->qtype == Quser && (mode & (OWRITE|OTRUNC)))
  313. return "user already exists";
  314. thdr.qid = mkqid(f->user, f->qtype);
  315. thdr.iounit = messagesize - IOHDRSZ;
  316. return 0;
  317. }
  318. char *
  319. Create(Fid *f)
  320. {
  321. char *name;
  322. long perm;
  323. if(!f->busy)
  324. return "create of unused fid";
  325. name = rhdr.name;
  326. if(f->user){
  327. return "permission denied";
  328. }else{
  329. perm = rhdr.perm;
  330. if(!(perm & DMDIR))
  331. return "permission denied";
  332. if(strcmp(name, "") == 0)
  333. return "empty file name";
  334. if(strlen(name) >= Namelen)
  335. return "file name too long";
  336. if(finduser(name))
  337. return "user already exists";
  338. f->user = installuser(name);
  339. f->user->ref++;
  340. f->qtype = Quser;
  341. }
  342. thdr.qid = mkqid(f->user, f->qtype);
  343. thdr.iounit = messagesize - IOHDRSZ;
  344. writeusers();
  345. return 0;
  346. }
  347. char *
  348. Read(Fid *f)
  349. {
  350. User *u;
  351. char *data;
  352. ulong off, n, m;
  353. int i, j, max;
  354. if(!f->busy)
  355. return "read of unused fid";
  356. n = rhdr.count;
  357. off = rhdr.offset;
  358. thdr.count = 0;
  359. data = thdr.data;
  360. switch(f->qtype){
  361. case Qroot:
  362. j = 0;
  363. for(i = 0; i < Nuser; i++)
  364. for(u = users[i]; u; j += m, u = u->link){
  365. m = dostat(u, Quser, data, n);
  366. if(m <= BIT16SZ)
  367. break;
  368. if(j < off)
  369. continue;
  370. data += m;
  371. n -= m;
  372. }
  373. thdr.count = data - thdr.data;
  374. return 0;
  375. case Quser:
  376. max = Qmax;
  377. max -= Quser + 1;
  378. j = 0;
  379. for(i = 0; i < max; j += m, i++){
  380. m = dostat(f->user, i + Quser + 1, data, n);
  381. if(m <= BIT16SZ)
  382. break;
  383. if(j < off)
  384. continue;
  385. data += m;
  386. n -= m;
  387. }
  388. thdr.count = data - thdr.data;
  389. return 0;
  390. case Qkey:
  391. if(f->user->status != Sok)
  392. return "user disabled";
  393. if(f->user->purgatory > time(0))
  394. return "user in purgatory";
  395. if(f->user->expire != 0 && f->user->expire < time(0))
  396. return "user expired";
  397. if(off != 0)
  398. return 0;
  399. if(n > DESKEYLEN)
  400. n = DESKEYLEN;
  401. memmove(thdr.data, f->user->key, n);
  402. thdr.count = n;
  403. return 0;
  404. case Qsecret:
  405. if(f->user->status != Sok)
  406. return "user disabled";
  407. if(f->user->purgatory > time(0))
  408. return "user in purgatory";
  409. if(f->user->expire != 0 && f->user->expire < time(0))
  410. return "user expired";
  411. if(off != 0)
  412. return 0;
  413. if(n > strlen(f->user->secret))
  414. n = strlen(f->user->secret);
  415. memmove(thdr.data, f->user->secret, n);
  416. thdr.count = n;
  417. return 0;
  418. case Qstatus:
  419. if(off != 0){
  420. thdr.count = 0;
  421. return 0;
  422. }
  423. if(f->user->status == Sok && f->user->expire && f->user->expire < time(0))
  424. sprint(thdr.data, "expired\n");
  425. else
  426. sprint(thdr.data, "%s\n", status[f->user->status]);
  427. thdr.count = strlen(thdr.data);
  428. return 0;
  429. case Qexpire:
  430. if(off != 0){
  431. thdr.count = 0;
  432. return 0;
  433. }
  434. if(!f->user->expire)
  435. strcpy(data, "never\n");
  436. else
  437. sprint(data, "%lud\n", f->user->expire);
  438. if(n > strlen(data))
  439. n = strlen(data);
  440. thdr.count = n;
  441. return 0;
  442. case Qlog:
  443. if(off != 0){
  444. thdr.count = 0;
  445. return 0;
  446. }
  447. sprint(data, "%lud\n", f->user->bad);
  448. if(n > strlen(data))
  449. n = strlen(data);
  450. thdr.count = n;
  451. return 0;
  452. case Qwarnings:
  453. if(off != 0){
  454. thdr.count = 0;
  455. return 0;
  456. }
  457. sprint(data, "%ud\n", f->user->warnings);
  458. if(n > strlen(data))
  459. n = strlen(data);
  460. thdr.count = n;
  461. return 0;
  462. default:
  463. return "permission denied: unknown qid";
  464. }
  465. }
  466. char *
  467. Write(Fid *f)
  468. {
  469. char *data, *p;
  470. ulong n, expire;
  471. int i;
  472. if(!f->busy)
  473. return "permission denied";
  474. n = rhdr.count;
  475. data = rhdr.data;
  476. switch(f->qtype){
  477. case Qkey:
  478. if(n != DESKEYLEN)
  479. return "garbled write data";
  480. memmove(f->user->key, data, DESKEYLEN);
  481. thdr.count = DESKEYLEN;
  482. break;
  483. case Qsecret:
  484. if(n >= SECRETLEN)
  485. return "garbled write data";
  486. memmove(f->user->secret, data, n);
  487. f->user->secret[n] = 0;
  488. thdr.count = n;
  489. break;
  490. case Qstatus:
  491. data[n] = '\0';
  492. if(p = strchr(data, '\n'))
  493. *p = '\0';
  494. for(i = 0; i < Smax; i++)
  495. if(strcmp(data, status[i]) == 0){
  496. f->user->status = i;
  497. break;
  498. }
  499. if(i == Smax)
  500. return "unknown status";
  501. f->user->bad = 0;
  502. thdr.count = n;
  503. break;
  504. case Qexpire:
  505. data[n] = '\0';
  506. if(p = strchr(data, '\n'))
  507. *p = '\0';
  508. else
  509. p = &data[n];
  510. if(strcmp(data, "never") == 0)
  511. expire = 0;
  512. else{
  513. expire = strtoul(data, &data, 10);
  514. if(data != p)
  515. return "bad expiration date";
  516. }
  517. f->user->expire = expire;
  518. f->user->warnings = 0;
  519. thdr.count = n;
  520. break;
  521. case Qlog:
  522. data[n] = '\0';
  523. if(strcmp(data, "good") == 0)
  524. f->user->bad = 0;
  525. else
  526. f->user->bad++;
  527. if(f->user->bad && ((f->user->bad)%MAXBAD) == 0)
  528. f->user->purgatory = time(0) + f->user->bad;
  529. return 0;
  530. case Qwarnings:
  531. data[n] = '\0';
  532. f->user->warnings = strtoul(data, 0, 10);
  533. thdr.count = n;
  534. break;
  535. case Qroot:
  536. case Quser:
  537. default:
  538. return "permission denied";
  539. }
  540. writeusers();
  541. return 0;
  542. }
  543. char *
  544. Remove(Fid *f)
  545. {
  546. if(!f->busy)
  547. return "permission denied";
  548. if(f->qtype == Qwarnings)
  549. f->user->warnings = 0;
  550. else if(f->qtype == Quser)
  551. removeuser(f->user);
  552. else {
  553. Clunk(f);
  554. return "permission denied";
  555. }
  556. Clunk(f);
  557. writeusers();
  558. return 0;
  559. }
  560. char *
  561. Stat(Fid *f)
  562. {
  563. static uchar statbuf[1024];
  564. if(!f->busy)
  565. return "stat on unattached fid";
  566. thdr.nstat = dostat(f->user, f->qtype, statbuf, sizeof statbuf);
  567. if(thdr.nstat <= BIT16SZ)
  568. return "stat buffer too small";
  569. thdr.stat = statbuf;
  570. return 0;
  571. }
  572. char *
  573. Wstat(Fid *f)
  574. {
  575. Dir d;
  576. int n;
  577. char buf[1024];
  578. if(!f->busy || f->qtype != Quser)
  579. return "permission denied";
  580. if(rhdr.nstat > sizeof buf)
  581. return "wstat buffer too big";
  582. if(convM2D(rhdr.stat, rhdr.nstat, &d, buf) == 0)
  583. return "bad stat buffer";
  584. n = strlen(d.name);
  585. if(n == 0 || n >= Namelen)
  586. return "bad user name";
  587. if(finduser(d.name))
  588. return "user already exists";
  589. if(!removeuser(f->user))
  590. return "user previously removed";
  591. free(f->user->name);
  592. f->user->name = strdup(d.name);
  593. if(f->user->name == nil)
  594. error("wstat: malloc failed: %r");
  595. insertuser(f->user);
  596. writeusers();
  597. return 0;
  598. }
  599. Qid
  600. mkqid(User *u, ulong qtype)
  601. {
  602. Qid q;
  603. q.vers = 0;
  604. q.path = qtype;
  605. if(u)
  606. q.path |= u->uniq * 0x100;
  607. if(qtype == Quser || qtype == Qroot)
  608. q.type = QTDIR;
  609. else
  610. q.type = QTFILE;
  611. return q;
  612. }
  613. int
  614. dostat(User *user, ulong qtype, void *p, int n)
  615. {
  616. Dir d;
  617. if(qtype == Quser)
  618. d.name = user->name;
  619. else
  620. d.name = qinfo[qtype];
  621. d.uid = d.gid = d.muid = "auth";
  622. d.qid = mkqid(user, qtype);
  623. if(d.qid.type & QTDIR)
  624. d.mode = 0777|DMDIR;
  625. else
  626. d.mode = 0666;
  627. d.atime = d.mtime = time(0);
  628. d.length = 0;
  629. return convD2M(&d, p, n);
  630. }
  631. int
  632. passline(Biobuf *b, void *vbuf)
  633. {
  634. char *buf = vbuf;
  635. if(Bread(b, buf, KEYDBLEN) != KEYDBLEN)
  636. return 0;
  637. decrypt(authkey, buf, KEYDBLEN);
  638. buf[Namelen-1] = '\0';
  639. return 1;
  640. }
  641. void
  642. randombytes(uchar *p, int len)
  643. {
  644. int i, fd;
  645. fd = open("/dev/random", OREAD);
  646. if(fd < 0){
  647. fprint(2, "keyfs: can't open /dev/random, using rand()\n");
  648. srand(time(0));
  649. for(i = 0; i < len; i++)
  650. p[i] = rand();
  651. return;
  652. }
  653. read(fd, p, len);
  654. close(fd);
  655. }
  656. void
  657. oldCBCencrypt(char *key7, uchar *p, int len)
  658. {
  659. uchar ivec[8];
  660. uchar key[8];
  661. DESstate s;
  662. memset(ivec, 0, 8);
  663. des56to64((uchar*)key7, key);
  664. setupDESstate(&s, key, ivec);
  665. desCBCencrypt((uchar*)p, len, &s);
  666. }
  667. void
  668. oldCBCdecrypt(char *key7, uchar *p, int len)
  669. {
  670. uchar ivec[8];
  671. uchar key[8];
  672. DESstate s;
  673. memset(ivec, 0, 8);
  674. des56to64((uchar*)key7, key);
  675. setupDESstate(&s, key, ivec);
  676. desCBCdecrypt((uchar*)p, len, &s);
  677. }
  678. void
  679. writeusers(void)
  680. {
  681. int fd, i, nu;
  682. User *u;
  683. uchar *p, *buf;
  684. ulong expire;
  685. /* count users */
  686. nu = 0;
  687. for(i = 0; i < Nuser; i++)
  688. for(u = users[i]; u; u = u->link)
  689. nu++;
  690. /* pack into buffer */
  691. buf = malloc(KEYDBOFF + nu*KEYDBLEN);
  692. if(buf == 0){
  693. fprint(2, "keyfs: can't write keys file, out of memory\n");
  694. return;
  695. }
  696. p = buf;
  697. randombytes(p, KEYDBOFF);
  698. p += KEYDBOFF;
  699. for(i = 0; i < Nuser; i++)
  700. for(u = users[i]; u; u = u->link){
  701. strncpy((char*)p, u->name, Namelen);
  702. p += Namelen;
  703. memmove(p, u->key, DESKEYLEN);
  704. p += DESKEYLEN;
  705. *p++ = u->status;
  706. *p++ = u->warnings;
  707. expire = u->expire;
  708. *p++ = expire;
  709. *p++ = expire >> 8;
  710. *p++ = expire >> 16;
  711. *p++ = expire >> 24;
  712. memmove(p, u->secret, SECRETLEN);
  713. p += SECRETLEN;
  714. }
  715. /* encrypt */
  716. oldCBCencrypt(authkey, buf, p - buf);
  717. /* write file */
  718. fd = create(userkeys, OWRITE, 0660);
  719. if(fd < 0){
  720. free(buf);
  721. fprint(2, "keyfs: can't write keys file\n");
  722. return;
  723. }
  724. if(write(fd, buf, p - buf) != (p - buf))
  725. fprint(2, "keyfs: can't write keys file\n");
  726. free(buf);
  727. close(fd);
  728. }
  729. int
  730. weirdfmt(Fmt *f)
  731. {
  732. char *s, *p, *ep, buf[ANAMELEN*4 + 1];
  733. int i, n;
  734. Rune r;
  735. s = va_arg(f->args, char*);
  736. p = buf;
  737. ep = buf + sizeof buf;
  738. for(i = 0; i < ANAMELEN; i += n){
  739. n = chartorune(&r, s + i);
  740. if(r == Runeerror)
  741. p = seprint(p, ep, "[%.2x]", buf[i]);
  742. else if(isascii(r) && iscntrl(r))
  743. p = seprint(p, ep, "[%.2x]", r);
  744. else if(r == ' ' || r == '/')
  745. p = seprint(p, ep, "[%c]", r);
  746. else
  747. p = seprint(p, ep, "%C", r);
  748. }
  749. return fmtstrcpy(f, buf);
  750. }
  751. int
  752. userok(char *user, int nu)
  753. {
  754. int i, n, rv;
  755. Rune r;
  756. char buf[ANAMELEN+1];
  757. memset(buf, 0, sizeof buf);
  758. memmove(buf, user, ANAMELEN);
  759. if(buf[ANAMELEN-1] != 0){
  760. fprint(2, "keyfs: %d: no termination: %W\n", nu, buf);
  761. return -1;
  762. }
  763. rv = 0;
  764. for(i = 0; buf[i]; i += n){
  765. n = chartorune(&r, buf+i);
  766. if(r == Runeerror){
  767. // fprint(2, "keyfs: name %W bad rune byte %d\n", buf, i);
  768. rv = -1;
  769. } else if(isascii(r) && iscntrl(r) || r == ' ' || r == '/'){
  770. // fprint(2, "keyfs: name %W bad char %C\n", buf, r);
  771. rv = -1;
  772. }
  773. }
  774. if(i == 0){
  775. fprint(2, "keyfs: %d: nil name\n", nu);
  776. return -1;
  777. }
  778. if(rv == -1)
  779. fprint(2, "keyfs: %d: bad syntax: %W\n", nu, buf);
  780. return rv;
  781. }
  782. int
  783. readusers(void)
  784. {
  785. int fd, i, n, nu;
  786. uchar *p, *buf, *ep;
  787. User *u;
  788. Dir *d;
  789. /* read file into an array */
  790. fd = open(userkeys, OREAD);
  791. if(fd < 0)
  792. return 0;
  793. d = dirfstat(fd);
  794. if(d == nil){
  795. close(fd);
  796. return 0;
  797. }
  798. buf = malloc(d->length);
  799. if(buf == 0){
  800. close(fd);
  801. free(d);
  802. return 0;
  803. }
  804. n = readn(fd, buf, d->length);
  805. close(fd);
  806. free(d);
  807. if(n != d->length){
  808. free(buf);
  809. return 0;
  810. }
  811. /* decrypt */
  812. n -= n % KEYDBLEN;
  813. oldCBCdecrypt(authkey, buf, n);
  814. /* unpack */
  815. nu = 0;
  816. for(i = KEYDBOFF; i < n; i += KEYDBLEN){
  817. ep = buf + i;
  818. if(userok((char*)ep, i/KEYDBLEN) < 0)
  819. continue;
  820. u = finduser((char*)ep);
  821. if(u == 0)
  822. u = installuser((char*)ep);
  823. memmove(u->key, ep + Namelen, DESKEYLEN);
  824. p = ep + Namelen + DESKEYLEN;
  825. u->status = *p++;
  826. u->warnings = *p++;
  827. if(u->status >= Smax)
  828. fprint(2, "keyfs: warning: bad status in key file\n");
  829. u->expire = p[0] + (p[1]<<8) + (p[2]<<16) + (p[3]<<24);
  830. p += 4;
  831. memmove(u->secret, p, SECRETLEN);
  832. u->secret[SECRETLEN-1] = 0;
  833. nu++;
  834. }
  835. free(buf);
  836. print("%d keys read\n", nu);
  837. return 1;
  838. }
  839. User *
  840. installuser(char *name)
  841. {
  842. User *u;
  843. int h;
  844. h = hash(name);
  845. u = emalloc(sizeof *u);
  846. u->name = strdup(name);
  847. if(u->name == nil)
  848. error("malloc failed: %r");
  849. u->removed = 0;
  850. u->ref = 0;
  851. u->purgatory = 0;
  852. u->expire = 0;
  853. u->status = Sok;
  854. u->bad = 0;
  855. u->warnings = 0;
  856. u->uniq = uniq++;
  857. u->link = users[h];
  858. users[h] = u;
  859. return u;
  860. }
  861. User *
  862. finduser(char *name)
  863. {
  864. User *u;
  865. for(u = users[hash(name)]; u; u = u->link)
  866. if(strcmp(name, u->name) == 0)
  867. return u;
  868. return 0;
  869. }
  870. int
  871. removeuser(User *user)
  872. {
  873. User *u, **last;
  874. char *name;
  875. user->removed = 1;
  876. name = user->name;
  877. last = &users[hash(name)];
  878. for(u = *last; u; u = *last){
  879. if(strcmp(name, u->name) == 0){
  880. *last = u->link;
  881. return 1;
  882. }
  883. last = &u->link;
  884. }
  885. return 0;
  886. }
  887. void
  888. insertuser(User *user)
  889. {
  890. int h;
  891. user->removed = 0;
  892. h = hash(user->name);
  893. user->link = users[h];
  894. users[h] = user;
  895. }
  896. ulong
  897. hash(char *s)
  898. {
  899. ulong h;
  900. h = 0;
  901. while(*s)
  902. h = (h << 1) ^ *s++;
  903. return h % Nuser;
  904. }
  905. Fid *
  906. findfid(int fid)
  907. {
  908. Fid *f, *ff;
  909. ff = 0;
  910. for(f = fids; f; f = f->next)
  911. if(f->fid == fid)
  912. return f;
  913. else if(!ff && !f->busy)
  914. ff = f;
  915. if(ff){
  916. ff->fid = fid;
  917. return ff;
  918. }
  919. f = emalloc(sizeof *f);
  920. f->fid = fid;
  921. f->busy = 0;
  922. f->user = 0;
  923. f->next = fids;
  924. fids = f;
  925. return f;
  926. }
  927. void
  928. io(int in, int out)
  929. {
  930. char *err;
  931. int n;
  932. long now, lastwarning;
  933. /* after restart, let the system settle for 5 mins before warning */
  934. lastwarning = time(0) - 24*60*60 + 5*60;
  935. for(;;){
  936. n = read9pmsg(in, mdata, messagesize);
  937. if(n == 0)
  938. continue;
  939. if(n < 0)
  940. error("mount read %d", n);
  941. if(convM2S(mdata, n, &rhdr) == 0)
  942. continue;
  943. if(newkeys())
  944. readusers();
  945. thdr.data = (char*)mdata + IOHDRSZ;
  946. thdr.fid = rhdr.fid;
  947. if(!fcalls[rhdr.type])
  948. err = "fcall request";
  949. else
  950. err = (*fcalls[rhdr.type])(findfid(rhdr.fid));
  951. thdr.tag = rhdr.tag;
  952. thdr.type = rhdr.type+1;
  953. if(err){
  954. thdr.type = Rerror;
  955. thdr.ename = err;
  956. }
  957. n = convS2M(&thdr, mdata, messagesize);
  958. if(write(out, mdata, n) != n)
  959. error("mount write");
  960. now = time(0);
  961. if(warnarg && (now - lastwarning > 24*60*60)){
  962. syslog(0, "auth", "keyfs starting warnings: %lux %lux",
  963. now, lastwarning);
  964. warning();
  965. lastwarning = now;
  966. }
  967. }
  968. }
  969. int
  970. newkeys(void)
  971. {
  972. Dir *d;
  973. static long ftime;
  974. d = dirstat(userkeys);
  975. if(d == nil)
  976. return 0;
  977. if(d->mtime > ftime){
  978. ftime = d->mtime;
  979. free(d);
  980. return 1;
  981. }
  982. free(d);
  983. return 0;
  984. }
  985. void *
  986. emalloc(ulong n)
  987. {
  988. void *p;
  989. if(p = malloc(n))
  990. return p;
  991. error("out of memory");
  992. return 0; /* not reached */
  993. }
  994. void
  995. warning(void)
  996. {
  997. int i;
  998. char buf[64];
  999. snprint(buf, sizeof buf, "-%s", warnarg);
  1000. switch(rfork(RFPROC|RFNAMEG|RFNOTEG|RFNOWAIT|RFENVG|RFFDG)){
  1001. case 0:
  1002. i = open("/sys/log/auth", OWRITE);
  1003. if(i >= 0){
  1004. dup(i, 2);
  1005. seek(2, 0, 2);
  1006. close(i);
  1007. }
  1008. execl("/bin/auth/warning", "warning", warnarg, nil);
  1009. error("can't exec warning");
  1010. }
  1011. }