4bff34e37def8a90f9194d81bc345c52ba20086athurlow * CDDL HEADER START
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * The contents of this file are subject to the terms of the
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Common Development and Distribution License (the "License").
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * You may not use this file except in compliance with the License.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * See the License for the specific language governing permissions
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * and limitations under the License.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * When distributing Covered Code, include this CDDL HEADER in each
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * If applicable, add the following below this CDDL HEADER, with the
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * fields enclosed by brackets "[]" replaced with your own identifying
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * information: Portions Copyright [yyyy] [name of copyright owner]
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * CDDL HEADER END
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross * Copyright 2009 Sun Microsystems, Inc. All rights reserved.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Use is subject to license terms.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Password Keychain storage mechanism.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * The smb_ptd is a cache of Uid's, User names, passwords and domain names.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * It will be used for storing the password information for a user and will
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * be used to for connections without entering the pasword again if its
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * already keyed in by the user. Its a kind of Key-Chain mechanism
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * implemented by Apple folks.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Information stored in the nodes:
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * UID: Uid of the person who initiated the login request.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * ZoneID: ZoneID of the zone from where the login request is initiated.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Username: Username in the CIFS server.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Srvdom: Domain name/ Server name of the CIFS server.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Password: Password of the user.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * For more information, see smb_pass.h and sys/avl.h
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Information retrieved from the node.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Node/password information can only be retrived with a call
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * to smb_pkey_getpw(). Password never gets copied to the userspace.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * It will be copied to the Kernel data structure smbioc_ossn->ioc_password
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * when needed for doing the "Session Setup". All other calls will return
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * either a success or a failure.
4bff34e37def8a90f9194d81bc345c52ba20086athurlowavl_tree_t smb_ptd; /* AVL password tree descriptor */
4bff34e37def8a90f9194d81bc345c52ba20086athurlowunsigned int smb_list_len = 0; /* No. of elements in the tree. */
4bff34e37def8a90f9194d81bc345c52ba20086athurlowkmutex_t smb_ptd_lock; /* Mutex lock for controlled access */
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * This routine is called by AVL tree calls when they want to find a
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * node, find the next position in the tree to add or for deletion.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Compare nodes from the tree to find the actual node based on
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * The nodes are added sorted on the uid/zoneid/domainname/username
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * We will do this:
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Compare uid's. The owner who stored the node gets access.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Then zoneid to check if the access is from the same zone.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Compare usernames.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * If the above are same, then compare domain/server names.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (-1);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (+1);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (-1);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (+1);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (-1);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (+1);
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross duser = u8_strcmp(pa->username, pb->username, 0,
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (-1);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (+1);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (0);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Initialization of the code that deals with uid and passwords.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow mutex_init(&smb_ptd_lock, NULL, MUTEX_DEFAULT, NULL);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Destroy the full AVL tree.
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross * Called just before unload.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Driver unload calls this to ask if we
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * have any stored passwords
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return ((n) ? EBUSY : 0);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Remove a node from the AVL tree identified by cpid.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (0);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Delete the entries owned by a particular user
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * based on uid. We go through all the nodes and
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * delete the nodes whereever the uid matches.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Also implements "delete all" when uid == -1.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * You must have privilege to use any uid other
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * than your real uid.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Delete the node.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (0);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Add entry or modify existing.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Check for existing entry..
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * If present, delete.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Now, add the new entry.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow cpid = kmem_zalloc(sizeof (smb_passid_t), KM_SLEEP);
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross bcopy(pk->pk_lmhash, cpid->lmhash, SMBIOC_HASH_SZ);
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross bcopy(pk->pk_nthash, cpid->nthash, SMBIOC_HASH_SZ);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * XXX: Instead of calling smb_pkey_check here,
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * should call avl_find directly, and hold the
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * lock across: avl_find, avl_remove, avl_insert.
4bff34e37def8a90f9194d81bc345c52ba20086athurlow /* If it already exists, delete it. */
4bff34e37def8a90f9194d81bc345c52ba20086athurlow if (ret == 0) {
4bff34e37def8a90f9194d81bc345c52ba20086athurlow return (0);
4bff34e37def8a90f9194d81bc345c52ba20086athurlow * Determine if a node with uid,zoneid, uname & dname exists in the tree
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross * given the information, and if found, return the hashes.
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross bcopy(tmp->lmhash, pk->pk_lmhash, SMBIOC_HASH_SZ);
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross bcopy(tmp->nthash, pk->pk_nthash, SMBIOC_HASH_SZ);
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Rosssmb_pkey_ioctl(int cmd, intptr_t arg, int flags, cred_t *cr)
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross /* Make strlen (etc) on these safe. */
613a2f6ba31e891e3d947a356daf5e563d43c1ceGordon Ross /* This is just a hash now. */