2 * $Id: uam.c,v 1.24.6.7.2.1 2004-12-07 18:34:15 bfernhomberg Exp $
4 * Copyright (c) 1999 Adrian Sun (asun@zoology.washington.edu)
5 * All Rights Reserved. See COPYRIGHT.
10 #endif /* HAVE_CONFIG_H */
18 #else /* STDC_HEADERS */
22 #endif /* HAVE_STRCHR */
23 char *strchr (), *strrchr ();
25 #define memcpy(d,s,n) bcopy ((s), (d), (n))
26 #define memmove(d,s,n) bcopy ((s), (d), (n))
27 #endif /* ! HAVE_MEMCPY */
28 #endif /* STDC_HEADERS */
32 #endif /* HAVE_UNISTD_H */
35 #endif /* HAVE_FCNTL_H */
37 #include <atalk/logger.h>
38 #include <sys/param.h>
39 #include <sys/socket.h>
43 #endif /* HAVE_DLFCN_H */
45 #include <netinet/in.h>
46 #include <arpa/inet.h>
48 #include <netatalk/endian.h>
49 #include <atalk/asp.h>
50 #include <atalk/dsi.h>
51 #include <atalk/afp.h>
52 #include <atalk/util.h>
55 #include "afp_config.h"
60 #define utf8_encoding() (afp_version >= 30)
62 #define utf8_encoding() (0)
72 /* --- server uam functions -- */
74 extern int uam_setup(const char *path);
77 /* uam_load. uams must have a uam_setup function. */
78 struct uam_mod *uam_load(const char *path, const char *name)
80 char buf[MAXPATHLEN + 1], *p;
85 if ((module = mod_open(path)) == NULL) {
86 LOG(log_error, logtype_afpd, "uam_load(%s): failed to load: %s", name, mod_error());
91 if ((mod = (struct uam_mod *) malloc(sizeof(struct uam_mod))) == NULL) {
92 LOG(log_error, logtype_afpd, "uam_load(%s): malloc failed", name);
96 strlcpy(buf, name, sizeof(buf));
97 if ((p = strchr(buf, '.')))
101 if ((mod->uam_fcn = mod_symbol(module, buf)) == NULL) {
102 LOG(log_error, logtype_afpd, "uam_load(%s): mod_symbol error for symbol %s",
108 if (mod->uam_fcn->uam_type != UAM_MODULE_SERVER) {
109 LOG(log_error, logtype_afpd, "uam_load(%s): attempted to load a non-server module",
114 /* version check would go here */
116 if (!mod->uam_fcn->uam_setup ||
117 ((*mod->uam_fcn->uam_setup)(name) < 0)) {
118 LOG(log_error, logtype_afpd, "uam_load(%s): uam_setup failed", name);
125 mod->uam_module = module;
135 /* unload the module. we check for a cleanup function, but we don't
136 * die if one doesn't exist. however, things are likely to leak without one.
138 void uam_unload(struct uam_mod *mod)
140 if (mod->uam_fcn->uam_cleanup)
141 (*mod->uam_fcn->uam_cleanup)();
144 mod_close(mod->uam_module);
149 /* -- client-side uam functions -- */
151 /* set up stuff for this uam. */
152 int uam_register(const int type, const char *path, const char *name, ...)
161 /* see if it already exists. */
162 if ((uam = auth_uamfind(type, name, strlen(name)))) {
163 if (strcmp(uam->uam_path, path)) {
164 /* it exists, but it's not the same module. */
165 LOG(log_error, logtype_afpd, "uam_register: \"%s\" already loaded by %s",
173 /* allocate space for uam */
174 if ((uam = calloc(1, sizeof(struct uam_obj))) == NULL)
177 uam->uam_name = name;
178 uam->uam_path = strdup(path);
183 case UAM_SERVER_LOGIN_EXT: /* expect four arguments */
184 uam->u.uam_login.login = va_arg(ap, void *);
185 uam->u.uam_login.logincont = va_arg(ap, void *);
186 uam->u.uam_login.logout = va_arg(ap, void *);
187 uam->u.uam_login.login_ext = va_arg(ap, void *);
190 case UAM_SERVER_LOGIN: /* expect three arguments */
191 uam->u.uam_login.login_ext = NULL;
192 uam->u.uam_login.login = va_arg(ap, void *);
193 uam->u.uam_login.logincont = va_arg(ap, void *);
194 uam->u.uam_login.logout = va_arg(ap, void *);
196 case UAM_SERVER_CHANGEPW: /* one argument */
197 uam->u.uam_changepw = va_arg(ap, void *);
199 case UAM_SERVER_PRINTAUTH: /* x arguments */
205 /* attach to other uams */
206 ret = auth_register(type, uam);
217 int uam_register_fn(const int type, const char *path, const char *name, void *fn1, void *fn2,
218 void *fn3, void *fn4)
226 /* see if it already exists. */
227 if ((uam = auth_uamfind(type, name, strlen(name)))) {
228 if (strcmp(uam->uam_path, path)) {
229 /* it exists, but it's not the same module. */
230 LOG(log_error, logtype_afpd, "uam_register: \"%s\" already loaded by %s",
238 /* allocate space for uam */
239 if ((uam = calloc(1, sizeof(struct uam_obj))) == NULL)
242 uam->uam_name = name;
243 uam->uam_path = strdup(path);
247 case UAM_SERVER_LOGIN_EXT: /* expect four arguments */
248 uam->u.uam_login.login_ext = fn4;
249 uam->u.uam_login.login = fn1;
250 uam->u.uam_login.logincont = fn2;
251 uam->u.uam_login.logout = fn3;
253 case UAM_SERVER_LOGIN: /* expect three arguments */
254 uam->u.uam_login.login_ext = NULL;
255 uam->u.uam_login.login = fn1;
256 uam->u.uam_login.logincont = fn2;
257 uam->u.uam_login.logout = fn3;
259 case UAM_SERVER_CHANGEPW: /* one argument */
260 uam->u.uam_changepw = fn1;
262 case UAM_SERVER_PRINTAUTH: /* x arguments */
267 /* attach to other uams */
268 if (auth_register(type, uam) < 0) {
278 void uam_unregister(const int type, const char *name)
285 uam = auth_uamfind(type, name, strlen(name));
286 if (!uam || --uam->uam_count > 0)
289 auth_unregister(uam);
294 /* --- helper functions for plugin uams --- */
296 struct passwd *uam_getname(void *private, char *name, const int len)
298 AFPObj *obj = private;
299 struct passwd *pwent;
300 static char username[256];
301 static char user[256];
302 static char pwname[256];
304 size_t namelen, gecoslen = 0, pwnamelen = 0;
306 if ((pwent = getpwnam(name)))
309 #ifndef NO_REAL_USER_NAME
311 if ( (size_t) -1 == (namelen = convert_string((utf8_encoding())?CH_UTF8_MAC:obj->options.maccharset,
312 CH_UCS2, name, strlen(name), username, sizeof(username))))
316 while ((pwent = getpwent())) {
317 if ((p = strchr(pwent->pw_gecos, ',')))
320 if ((size_t)-1 == ( gecoslen = convert_string(obj->options.unixcharset, CH_UCS2,
321 pwent->pw_gecos, strlen(pwent->pw_gecos), user, sizeof(username))) )
323 if ((size_t)-1 == ( pwnamelen = convert_string(obj->options.unixcharset, CH_UCS2,
324 pwent->pw_name, strlen(pwent->pw_name), pwname, sizeof(username))) )
328 /* check against both the gecos and the name fields. the user
329 * might have just used a different capitalization. */
331 if ( (namelen == gecoslen && strncasecmp_w((ucs2_t*)user, (ucs2_t*)username, len) == 0) ||
332 ( namelen == pwnamelen && strncasecmp_w ( (ucs2_t*) pwname, (ucs2_t*) username, len) == 0)) {
333 strlcpy(name, pwent->pw_name, len);
338 #endif /* ! NO_REAL_USER_NAME */
340 /* os x server doesn't keep anything useful if we do getpwent */
341 return pwent ? getpwnam(name) : NULL;
344 int uam_checkuser(const struct passwd *pwd)
351 #ifndef DISABLE_SHELLCHECK
352 if (!pwd->pw_shell || (*pwd->pw_shell == '\0')) {
353 LOG(log_info, logtype_afpd, "uam_checkuser: User %s does not have a shell", pwd->pw_name);
357 while ((p = getusershell())) {
358 if ( strcmp( p, pwd->pw_shell ) == 0 )
364 LOG(log_info, logtype_afpd, "illegal shell %s for %s", pwd->pw_shell, pwd->pw_name);
367 #endif /* DISABLE_SHELLCHECK */
372 int uam_random_string (AFPObj *obj, char *buf, int len)
378 if ( (len <= 0) || (len % sizeof(result)))
381 /* construct a random number */
382 if ((fd = open("/dev/urandom", O_RDONLY)) < 0) {
387 if (gettimeofday(&tv, &tz) < 0)
389 srandom(tv.tv_sec + (unsigned long) obj + (unsigned long) obj->handle);
390 for (i = 0; i < len; i += sizeof(result)) {
392 memcpy(buf + i, &result, sizeof(result));
395 ret = read(fd, buf, len);
403 /* afp-specific functions */
404 int uam_afpserver_option(void *private, const int what, void *option,
407 AFPObj *obj = private;
408 char **buf = (char **) option; /* most of the options are this */
409 struct session_info **sinfo = (struct session_info **) option;
415 case UAM_OPTION_USERNAME:
416 *buf = (void *) obj->username;
418 *len = sizeof(obj->username) - 1;
421 case UAM_OPTION_GUEST:
422 *buf = (void *) obj->options.guest;
424 *len = strlen(obj->options.guest);
427 case UAM_OPTION_PASSWDOPT:
432 case UAM_PASSWD_FILENAME:
433 *buf = (void *) obj->options.passwdfile;
434 *len = strlen(obj->options.passwdfile);
437 case UAM_PASSWD_MINLENGTH:
438 *((int *) option) = obj->options.passwdminlen;
439 *len = sizeof(obj->options.passwdminlen);
442 case UAM_PASSWD_MAXFAIL:
443 *((int *) option) = obj->options.loginmaxfail;
444 *len = sizeof(obj->options.loginmaxfail);
447 case UAM_PASSWD_EXPIRETIME: /* not implemented */
454 case UAM_OPTION_SIGNATURE:
455 *buf = (void *) (((AFPConfig *)obj->config)->signature);
460 case UAM_OPTION_RANDNUM: /* returns a random number in 4-byte units. */
464 return uam_random_string(obj, option, *len);
467 case UAM_OPTION_HOSTNAME:
468 *buf = (void *) obj->options.hostname;
470 *len = strlen(obj->options.hostname);
473 case UAM_OPTION_PROTOCOL:
474 *buf = (void *) obj->proto;
476 case UAM_OPTION_CLIENTNAME:
478 struct DSI *dsi = obj->handle;
481 hp = gethostbyaddr( (char *) &dsi->client.sin_addr,
482 sizeof( struct in_addr ),
483 dsi->client.sin_family );
485 *buf = (void *) hp->h_name;
487 *buf = (void *) inet_ntoa( dsi->client.sin_addr );
490 case UAM_OPTION_COOKIE:
491 /* it's up to the uam to actually store something useful here.
492 * this just passes back a handle to the cookie. the uam side
493 * needs to do something like **buf = (void *) cookie to store
495 *buf = (void *) &obj->uam_cookie;
497 case UAM_OPTION_KRB5SERVICE:
498 *buf = obj->options.k5service;
500 *len = (*buf)?strlen(*buf):0;
502 case UAM_OPTION_MACCHARSET:
503 *((int *) option) = obj->options.maccharset;
504 *len = sizeof(obj->options.maccharset);
506 case UAM_OPTION_UNIXCHARSET:
507 *((int *) option) = obj->options.unixcharset;
508 *len = sizeof(obj->options.unixcharset);
510 case UAM_OPTION_SESSIONINFO:
511 *sinfo = &(obj->sinfo);
521 /* if we need to maintain a connection, this is how we do it.
522 * because an action pointer gets passed in, we can stream
524 int uam_afp_read(void *handle, char *buf, int *buflen,
525 int (*action)(void *, void *, const int))
527 AFPObj *obj = handle;
533 switch (obj->proto) {
535 if ((len = asp_wrtcont(obj->handle, buf, buflen )) < 0)
536 goto uam_afp_read_err;
537 return action(handle, buf, *buflen);
541 len = dsi_writeinit(obj->handle, buf, *buflen);
542 if (!len || ((len = action(handle, buf, len)) < 0)) {
543 dsi_writeflush(obj->handle);
544 goto uam_afp_read_err;
547 while ((len = (dsi_write(obj->handle, buf, *buflen)))) {
548 if ((len = action(handle, buf, len)) < 0) {
549 dsi_writeflush(obj->handle);
550 goto uam_afp_read_err;
563 void uam_afp_getcmdline( int *ac, char ***av )
565 afp_get_cmdline( ac, av );
568 int uam_sia_validate_user(sia_collect_func_t * collect, int argc, char **argv,
569 char *hostname, char *username, char *tty,
570 int colinput, char *gssapi, char *passphrase)
571 /* A clone of the Tru64 system function sia_validate_user() that calls
572 * sia_ses_authent() rather than sia_ses_reauthent()
573 * Added extra code to take into account suspected SIA bug whereby it clobbers
574 * the signal handler on SIGALRM (tickle) installed by Netatalk/afpd
577 SIAENTITY *entity = NULL;
578 struct sigaction act;
581 if ((rc=sia_ses_init(&entity, argc, argv, hostname, username, tty,
582 colinput, gssapi)) != SIASUCCESS) {
583 LOG(log_error, logtype_afpd, "cannot initialise SIA");
587 /* save old action for restoration later */
588 if (sigaction(SIGALRM, NULL, &act))
589 LOG(log_error, logtype_afpd, "cannot save SIGALRM handler");
591 if ((rc=sia_ses_authent(collect, passphrase, entity)) != SIASUCCESS) {
592 /* restore old action after clobbering by sia_ses_authent() */
593 if (sigaction(SIGALRM, &act, NULL))
594 LOG(log_error, logtype_afpd, "cannot restore SIGALRM handler");
596 LOG(log_info, logtype_afpd, "unsuccessful login for %s",
597 (hostname?hostname:"(null)"));
600 LOG(log_info, logtype_afpd, "successful login for %s",
601 (hostname?hostname:"(null)"));
603 /* restore old action after clobbering by sia_ses_authent() */
604 if (sigaction(SIGALRM, &act, NULL))
605 LOG(log_error, logtype_afpd, "cannot restore SIGALRM handler");
607 sia_ses_release(&entity);
613 /* --- papd-specific functions (just placeholders) --- */
614 void append(void *pf, char *data, int len)