nss_mc_group.c revision 287e76479d68db4134274d4a4fca5fe0fbc9a605
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce/*
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * System Security Services Daemon. NSS client interface
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce *
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * Copyright (C) Simo Sorce 2011
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce *
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * This program is free software; you can redistribute it and/or modify
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * it under the terms of the GNU Lesser General Public License as
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * published by the Free Software Foundation; either version 2.1 of the
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * License, or (at your option) any later version.
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce *
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * This program is distributed in the hope that it will be useful,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * but WITHOUT ANY WARRANTY; without even the implied warranty of
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce * GNU Lesser General Public License for more details.
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce *
287e76479d68db4134274d4a4fca5fe0fbc9a605Jan Cholasta * You should have received a copy of the GNU Lesser General Public License
287e76479d68db4134274d4a4fca5fe0fbc9a605Jan Cholasta * along with this program. If not, see <http://www.gnu.org/licenses/>.
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce/* GROUP database NSS interface using mmap cache */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce#include <errno.h>
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce#include <stdio.h>
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce#include <string.h>
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce#include <stdlib.h>
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce#include <sys/mman.h>
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce#include <time.h>
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce#include "nss_mc.h"
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorcestruct sss_cli_mc_ctx gr_mc_ctx = { false, -1, 0, NULL, 0, NULL, 0, NULL, 0 };
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorcestatic errno_t sss_nss_mc_parse_result(struct sss_mc_rec *rec,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct group *result,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce char *buffer, size_t buflen)
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce{
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct sss_mc_grp_data *data;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce time_t expire;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce void *cookie;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce char *membuf;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce size_t memsize;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce int ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce int i;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* additional checks before filling result*/
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce expire = rec->expire;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (expire < time(NULL)) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* entry is now invalid */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return EINVAL;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce data = (struct sss_mc_grp_data *)rec->data;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce memsize = (data->members + 1) * sizeof(char *);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (data->strs_len + memsize > buflen) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ERANGE;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* fill in glibc provided structs */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* copy in buffer */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce membuf = buffer + memsize;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce memcpy(membuf, data->strs, data->strs_len);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* fill in group */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce result->gr_gid = data->gid;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce result->gr_mem = (char **)buffer;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce result->gr_mem[data->members] = NULL;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce cookie = NULL;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_str_ptr_from_buffer(&result->gr_name, &cookie,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce membuf, data->strs_len);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (ret) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_str_ptr_from_buffer(&result->gr_passwd, &cookie,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce membuf, data->strs_len);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (ret) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce for (i = 0; i < data->members; i++) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_str_ptr_from_buffer(&result->gr_mem[i], &cookie,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce membuf, data->strs_len);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (ret) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (cookie != NULL) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return EINVAL;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return 0;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce}
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorceerrno_t sss_nss_mc_getgrnam(const char *name, size_t name_len,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct group *result,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce char *buffer, size_t buflen)
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce{
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct sss_mc_rec *rec = NULL;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct sss_mc_grp_data *data;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce char *rec_name;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce uint32_t hash;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce uint32_t slot;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce int ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_mc_get_ctx("group", &gr_mc_ctx);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (ret) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* hashes are calculated including the NULL terminator */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce hash = sss_nss_mc_hash(&gr_mc_ctx, name, name_len + 1);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce slot = gr_mc_ctx.hash_table[hash];
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (slot > MC_SIZE_TO_SLOTS(gr_mc_ctx.dt_size)) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ENOENT;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce while (slot != MC_INVALID_VAL) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_mc_get_record(&gr_mc_ctx, slot, &rec);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (ret) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce goto done;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* check record matches what we are searching for */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (hash != rec->hash1) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* if name hash does not match we can skip this immediately */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce slot = rec->next;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce continue;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce data = (struct sss_mc_grp_data *)rec->data;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce rec_name = (char *)data + data->name;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (strcmp(name, rec_name) == 0) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce break;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce slot = rec->next;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (slot == MC_INVALID_VAL) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = ENOENT;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce goto done;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_mc_parse_result(rec, result, buffer, buflen);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorcedone:
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce free(rec);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce}
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorceerrno_t sss_nss_mc_getgrgid(gid_t gid,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct group *result,
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce char *buffer, size_t buflen)
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce{
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct sss_mc_rec *rec = NULL;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce struct sss_mc_grp_data *data;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce char gidstr[11];
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce uint32_t hash;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce uint32_t slot;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce int len;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce int ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_mc_get_ctx("group", &gr_mc_ctx);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (ret) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce len = snprintf(gidstr, 11, "%ld", (long)gid);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (len > 10) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return EINVAL;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* hashes are calculated including the NULL terminator */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce hash = sss_nss_mc_hash(&gr_mc_ctx, gidstr, len+1);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce slot = gr_mc_ctx.hash_table[hash];
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (slot > MC_SIZE_TO_SLOTS(gr_mc_ctx.dt_size)) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ENOENT;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce while (slot != MC_INVALID_VAL) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_mc_get_record(&gr_mc_ctx, slot, &rec);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (ret) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce goto done;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* check record matches what we are searching for */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (hash != rec->hash2) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce /* if uid hash does not match we can skip this immediately */
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce slot = rec->next;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce continue;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce data = (struct sss_mc_grp_data *)rec->data;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (gid == data->gid) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce break;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce slot = rec->next;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce if (slot == MC_INVALID_VAL) {
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = ENOENT;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce goto done;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce }
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce ret = sss_nss_mc_parse_result(rec, result, buffer, buflen);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorcedone:
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce free(rec);
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce return ret;
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce}
10eae23e2483733d4ca3c21f15b5bdb3f04c9839Simo Sorce