hbac_evaluator.c revision e0c86d21388bffe2e3919e780780c40d96186abb
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/*
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync SSSD
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync IPA Backend Module -- Access control
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Authors:
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sumit Bose <sbose@redhat.com>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Stephen Gallagher <sgallagh@redhat.com>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Copyright (C) 2011 Red Hat
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync This program is free software; you can redistribute it and/or modify
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync it under the terms of the GNU General Public License as published by
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync the Free Software Foundation; either version 3 of the License, or
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (at your option) any later version.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync This program is distributed in the hope that it will be useful,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync but WITHOUT ANY WARRANTY; without even the implied warranty of
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync GNU General Public License for more details.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync You should have received a copy of the GNU General Public License
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync along with this program. If not, see <http://www.gnu.org/licenses/>.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync*/
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#include "config.h" /* for HAVE_FUNCTION_ATTRIBUTE_FORMAT in "ipa_hbac.h" */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#include <stdlib.h>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#include <string.h>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#include <errno.h>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#include "ipa_hbac.h"
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#include "sss_utf8.h"
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#ifndef HAVE_ERRNO_T
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#define HAVE_ERRNO_T
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsynctypedef int errno_t;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#endif
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#ifndef EOK
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#define EOK 0
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#endif
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* HBAC logging system */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* debug macro */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync#define HBAC_DEBUG(level, format, ...) do { \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (hbac_debug_fn != NULL) { \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_debug_fn(__FILE__, __LINE__, __FUNCTION__, \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync level, format, ##__VA_ARGS__); \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync } \
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync} while (0)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* static pointer to external logging function */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic hbac_debug_fn_t hbac_debug_fn = NULL;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* setup function for external logging function */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncvoid hbac_enable_debug(hbac_debug_fn_t external_debug_fn)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync{
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_debug_fn = external_debug_fn;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync}
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* auxiliary function for hbac_request_element logging */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic void hbac_request_element_debug_print(struct hbac_request_element *el,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync const char *label);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* auxiliary function for hbac_eval_req logging */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic void hbac_req_debug_print(struct hbac_eval_req *req);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* auxiliary function for hbac_rule_element logging */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic void hbac_rule_element_debug_print(struct hbac_rule_element *el,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync const char *label);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* auxiliary function for hbac_rule logging */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic void hbac_rule_debug_print(struct hbac_rule *rule);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync/* Placeholder structure for future HBAC time-based
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync * evaluation rules
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstruct hbac_time_rules {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync int not_yet_implemented;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync};
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncenum hbac_eval_result_int {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_EVAL_MATCH_ERROR = -1,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_EVAL_MATCHED,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_EVAL_UNMATCHED
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync};
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic bool hbac_rule_element_is_complete(struct hbac_rule_element *el)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync{
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (el == NULL) return false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (el->category == HBAC_CATEGORY_ALL) return true;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (el->names == NULL && el->groups == NULL) return false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if ((el->names && el->names[0] != NULL)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync || (el->groups && el->groups[0] != NULL))
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return true;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* If other categories are added, handle them here */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync}
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncbool hbac_rule_is_complete(struct hbac_rule *rule, uint32_t *missing_attrs)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync{
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync bool complete = true;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *missing_attrs = 0;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (rule == NULL) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* No rule passed in? */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* Make sure we have all elements */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!hbac_rule_element_is_complete(rule->users)) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync complete = false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *missing_attrs |= HBAC_RULE_ELEMENT_USERS;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!hbac_rule_element_is_complete(rule->services)) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync complete = false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *missing_attrs |= HBAC_RULE_ELEMENT_SERVICES;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!hbac_rule_element_is_complete(rule->targethosts)) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync complete = false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *missing_attrs |= HBAC_RULE_ELEMENT_TARGETHOSTS;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!hbac_rule_element_is_complete(rule->srchosts)) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync complete = false;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *missing_attrs |= HBAC_RULE_ELEMENT_SOURCEHOSTS;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return complete;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync}
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncenum hbac_eval_result_int hbac_evaluate_rule(struct hbac_rule *rule,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync struct hbac_eval_req *hbac_req,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync enum hbac_error_code *error);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncenum hbac_eval_result hbac_evaluate(struct hbac_rule **rules,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync struct hbac_eval_req *hbac_req,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync struct hbac_info **info)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync{
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync uint32_t i;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync enum hbac_error_code ret;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync enum hbac_eval_result result = HBAC_EVAL_DENY;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync enum hbac_eval_result_int intermediate_result;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_INFO, "[< hbac_evaluate()\n");
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_req_debug_print(hbac_req);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (info) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *info = malloc(sizeof(struct hbac_info));
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!*info) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_ERROR, "Out of memory.\n");
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_OOM;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (*info)->code = HBAC_ERROR_UNKNOWN;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (*info)->rule_name = NULL;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync for (i = 0; rules[i]; i++) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_rule_debug_print(rules[i]);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync intermediate_result = hbac_evaluate_rule(rules[i], hbac_req, &ret);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (intermediate_result == HBAC_EVAL_UNMATCHED) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* This rule did not match at all. Skip it */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_INFO, "The rule [%s] did not match.\n",
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync rules[i]->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync continue;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync } else if (intermediate_result == HBAC_EVAL_MATCHED) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_INFO, "ALLOWED by rule [%s].\n", rules[i]->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync result = HBAC_EVAL_ALLOW;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (info) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (*info)->code = HBAC_SUCCESS;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (*info)->rule_name = strdup(rules[i]->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!(*info)->rule_name) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_ERROR, "Out of memory.\n");
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync result = HBAC_EVAL_ERROR;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (*info)->code = HBAC_ERROR_OUT_OF_MEMORY;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync break;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync } else {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* An error occurred processing this rule */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_ERROR,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync "Error %d occurred during evaluating of rule [%s].\n",
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync ret, rules[i]->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync result = HBAC_EVAL_ERROR;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (info) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (*info)->code = ret;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (*info)->rule_name = strdup(rules[i]->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* Explicitly not checking the result of strdup(), since if
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync * it's NULL, we can't do anything anyway.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync goto done;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* If we've reached the end of the loop, we have either set the
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync * result to ALLOW explicitly or we'll stick with the default DENY.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncdone:
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_INFO, "hbac_evaluate() >]\n");
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return result;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync}
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic errno_t hbac_evaluate_element(struct hbac_rule_element *rule_el,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync struct hbac_request_element *req_el,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync bool *matched);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncenum hbac_eval_result_int hbac_evaluate_rule(struct hbac_rule *rule,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync struct hbac_eval_req *hbac_req,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync enum hbac_error_code *error)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync{
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync errno_t ret;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync bool matched;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!rule->enabled) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_INFO, "Rule [%s] is not enabled\n", rule->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_UNMATCHED;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* Make sure we have all elements */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (!rule->users
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync || !rule->services
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync || !rule->targethosts
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync || !rule->srchosts) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_INFO,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync "Rule [%s] cannot be parsed, some elements are empty\n",
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync rule->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *error = HBAC_ERROR_UNPARSEABLE_RULE;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_MATCH_ERROR;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* Check users */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync ret = hbac_evaluate_element(rule->users,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_req->user,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync &matched);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (ret != EOK) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_ERROR,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync "Cannot parse user elements of rule [%s]\n", rule->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *error = HBAC_ERROR_UNPARSEABLE_RULE;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_MATCH_ERROR;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync } else if (!matched) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_UNMATCHED;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* Check services */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync ret = hbac_evaluate_element(rule->services,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_req->service,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync &matched);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (ret != EOK) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_ERROR,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync "Cannot parse service elements of rule [%s]\n", rule->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *error = HBAC_ERROR_UNPARSEABLE_RULE;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_MATCH_ERROR;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync } else if (!matched) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_UNMATCHED;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* Check target hosts */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync ret = hbac_evaluate_element(rule->targethosts,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_req->targethost,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync &matched);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (ret != EOK) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_ERROR,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync "Cannot parse targethost elements of rule [%s]\n",
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync rule->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *error = HBAC_ERROR_UNPARSEABLE_RULE;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_MATCH_ERROR;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync } else if (!matched) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_UNMATCHED;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync /* Check source hosts */
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync ret = hbac_evaluate_element(rule->srchosts,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync hbac_req->srchost,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync &matched);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (ret != EOK) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync HBAC_DEBUG(HBAC_DBG_ERROR,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync "Cannot parse srchost elements of rule [%s]\n",
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync rule->name);
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync *error = HBAC_ERROR_UNPARSEABLE_RULE;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_MATCH_ERROR;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync } else if (!matched) {
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_UNMATCHED;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync }
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync return HBAC_EVAL_MATCHED;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync}
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsyncstatic errno_t hbac_evaluate_element(struct hbac_rule_element *rule_el,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync struct hbac_request_element *req_el,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync bool *matched)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync{
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync size_t i, j;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync const uint8_t *rule_name;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync const uint8_t *req_name;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync int ret;
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync if (rule_el->category & HBAC_CATEGORY_ALL) {
*matched = true;
return EOK;
}
/* First check the name list */
if (rule_el->names) {
for (i = 0; rule_el->names[i]; i++) {
if (req_el->name != NULL) {
rule_name = (const uint8_t *) rule_el->names[i];
req_name = (const uint8_t *) req_el->name;
/* Do a case-insensitive comparison. */
ret = sss_utf8_case_eq(rule_name, req_name);
if (ret != EOK && ret != ENOMATCH) {
return ret;
} else if (ret == EOK) {
*matched = true;
return EOK;
}
}
}
}
if (rule_el->groups) {
/* Not found in the name list
* Check for group membership
*/
for (i = 0; rule_el->groups[i]; i++) {
rule_name = (const uint8_t *) rule_el->groups[i];
for (j = 0; req_el->groups[j]; j++) {
req_name = (const uint8_t *) req_el->groups[j];
/* Do a case-insensitive comparison. */
ret = sss_utf8_case_eq(rule_name, req_name);
if (ret != EOK && ret != ENOMATCH) {
return ret;
} else if (ret == EOK) {
*matched = true;
return EOK;
}
}
}
}
/* Not found in groups either */
*matched = false;
return EOK;
}
const char *hbac_result_string(enum hbac_eval_result result)
{
switch (result) {
case HBAC_EVAL_ALLOW:
return "HBAC_EVAL_ALLOW";
case HBAC_EVAL_DENY:
return "HBAC_EVAL_DENY";
case HBAC_EVAL_ERROR:
return "HBAC_EVAL_ERROR";
case HBAC_EVAL_OOM:
return "Could not allocate memory for hbac_info object";
}
return "HBAC_EVAL_ERROR";
}
void hbac_free_info(struct hbac_info *info)
{
if (info == NULL) return;
free(info->rule_name);
free(info);
}
const char *hbac_error_string(enum hbac_error_code code)
{
switch (code) {
case HBAC_SUCCESS:
return "Success";
case HBAC_ERROR_NOT_IMPLEMENTED:
return "Function is not yet implemented";
case HBAC_ERROR_OUT_OF_MEMORY:
return "Out of memory";
case HBAC_ERROR_UNPARSEABLE_RULE:
return "Rule could not be evaluated";
case HBAC_ERROR_UNKNOWN:
default:
return "Unknown error code";
}
}
static void hbac_request_element_debug_print(struct hbac_request_element *el,
const char *label)
{
int i;
if (el) {
if (el->name) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t%s [%s]\n", label, el->name);
}
if (el->groups) {
if (el->groups[0]) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t%s_group:\n", label);
for (i = 0; el->groups[i]; i++) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t\t[%s]\n", el->groups[i]);
}
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t%s_group (none)\n", label);
}
}
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t%s (none)\n", label);
}
}
static void hbac_req_debug_print(struct hbac_eval_req *req)
{
HBAC_DEBUG(HBAC_DBG_TRACE, "\tREQUEST:\n");
if (req) {
struct tm *local_time = NULL;
size_t ret;
const size_t buff_size = 100;
char time_buff[buff_size];
hbac_request_element_debug_print(req->service, "service");
hbac_request_element_debug_print(req->user, "user");
hbac_request_element_debug_print(req->targethost, "targethost");
hbac_request_element_debug_print(req->srchost, "srchost");
local_time = localtime(&req->request_time);
if (local_time == NULL) {
return;
}
ret = strftime(time_buff, buff_size, "%Y-%m-%d %H:%M:%S", local_time);
if (ret <= 0) {
return;
}
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\trequest time %s\n", time_buff);
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tRequest is EMPTY.\n");
}
}
static void hbac_rule_element_debug_print(struct hbac_rule_element *el,
const char *label)
{
int i;
if (el) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\tcategory [%#x] [%s]\n", el->category,
(el->category == HBAC_CATEGORY_ALL) ? "ALL" : "NONE");
if (el->names) {
if (el->names[0]) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t%s_names:\n", label);
for (i = 0; el->names[i]; i++) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t\t[%s]\n", el->names[i]);
}
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t%s_names (none)\n", label);
}
}
if (el->groups) {
if (el->groups[0]) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t%s_groups:\n", label);
for (i = 0; el->groups[i]; i++) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t\t[%s]\n", el->groups[i]);
}
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\t\t%s_groups (none)\n", label);
}
}
}
}
static void hbac_rule_debug_print(struct hbac_rule *rule)
{
if (rule) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tRULE [%s] [%s]:\n",
rule->name, (rule->enabled) ? "ENABLED" : "DISABLED");
if (rule->services) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tservices:\n");
hbac_rule_element_debug_print(rule->services, "services");
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tservices (none)\n");
}
if (rule->users) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tusers:\n");
hbac_rule_element_debug_print(rule->users, "users");
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tusers (none)\n");
}
if (rule->targethosts) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\ttargethosts:\n");
hbac_rule_element_debug_print(rule->targethosts, "targethosts");
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\ttargethosts (none)\n");
}
if (rule->srchosts) {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tsrchosts:\n");
hbac_rule_element_debug_print(rule->srchosts, "srchosts");
} else {
HBAC_DEBUG(HBAC_DBG_TRACE, "\tsrchosts (none)\n");
}
}
}