1ca0716f5SRobert Watson /*-
2*5e386598SRobert Watson * Copyright (c) 2005-2009, 2016 Robert N. M. Watson
3ca0716f5SRobert Watson * All rights reserved.
4ca0716f5SRobert Watson *
5*5e386598SRobert Watson * Portions of this software were developed by BAE Systems, the University of
6*5e386598SRobert Watson * Cambridge Computer Laboratory, and Memorial University under DARPA/AFRL
7*5e386598SRobert Watson * contract FA8650-15-C-7558 ("CADETS"), as part of the DARPA Transparent
8*5e386598SRobert Watson * Computing (TC) research program.
9*5e386598SRobert Watson *
10ca0716f5SRobert Watson * Redistribution and use in source and binary forms, with or without
11ca0716f5SRobert Watson * modification, are permitted provided that the following conditions
12ca0716f5SRobert Watson * are met:
13ca0716f5SRobert Watson * 1. Redistributions of source code must retain the above copyright
14ca0716f5SRobert Watson * notice, this list of conditions and the following disclaimer.
15ca0716f5SRobert Watson * 2. Redistributions in binary form must reproduce the above copyright
16ca0716f5SRobert Watson * notice, this list of conditions and the following disclaimer in the
17ca0716f5SRobert Watson * documentation and/or other materials provided with the distribution.
18ca0716f5SRobert Watson *
19ca0716f5SRobert Watson * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
20ca0716f5SRobert Watson * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21ca0716f5SRobert Watson * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22ca0716f5SRobert Watson * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
23ca0716f5SRobert Watson * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24ca0716f5SRobert Watson * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25ca0716f5SRobert Watson * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26ca0716f5SRobert Watson * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27ca0716f5SRobert Watson * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28ca0716f5SRobert Watson * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29ca0716f5SRobert Watson * SUCH DAMAGE.
30ca0716f5SRobert Watson */
31ca0716f5SRobert Watson
32ca0716f5SRobert Watson #include <bsm/libbsm.h>
33ca0716f5SRobert Watson #include <string.h>
34ca0716f5SRobert Watson #include <err.h>
35ca0716f5SRobert Watson #include <limits.h>
36ca0716f5SRobert Watson #include <stdio.h>
37ca0716f5SRobert Watson #include <stdlib.h>
38ca0716f5SRobert Watson
39ca0716f5SRobert Watson /*
40ca0716f5SRobert Watson * Simple tool to dump various /etc/security databases using the defined APIs.
41ca0716f5SRobert Watson */
42ca0716f5SRobert Watson
43ca0716f5SRobert Watson static void
usage(void)44ca0716f5SRobert Watson usage(void)
45ca0716f5SRobert Watson {
46ca0716f5SRobert Watson
47f4e380b0SRobert Watson fprintf(stderr, "usage: audump [class|class_r|control|event|event_r|"
48ca0716f5SRobert Watson "user|user_r]\n");
49ca0716f5SRobert Watson exit(-1);
50ca0716f5SRobert Watson }
51ca0716f5SRobert Watson
52ca0716f5SRobert Watson static void
audump_class(void)53ca0716f5SRobert Watson audump_class(void)
54ca0716f5SRobert Watson {
55ca0716f5SRobert Watson au_class_ent_t *cp;
56ca0716f5SRobert Watson
57ca0716f5SRobert Watson while ((cp = getauclassent()) != NULL)
58ca0716f5SRobert Watson printf("0x%08x:%s:%s\n", cp->ac_class, cp->ac_name,
59ca0716f5SRobert Watson cp->ac_desc);
60ca0716f5SRobert Watson }
61ca0716f5SRobert Watson
62ca0716f5SRobert Watson static void
audump_class_r(void)63ca0716f5SRobert Watson audump_class_r(void)
64ca0716f5SRobert Watson {
65ca0716f5SRobert Watson char class_ent_name[AU_CLASS_NAME_MAX];
66ca0716f5SRobert Watson char class_ent_desc[AU_CLASS_DESC_MAX];
67ca0716f5SRobert Watson au_class_ent_t c, *cp;
68ca0716f5SRobert Watson
69ca0716f5SRobert Watson bzero(&c, sizeof(c));
70ca0716f5SRobert Watson bzero(class_ent_name, sizeof(class_ent_name));
71ca0716f5SRobert Watson bzero(class_ent_desc, sizeof(class_ent_desc));
72ca0716f5SRobert Watson c.ac_name = class_ent_name;
73ca0716f5SRobert Watson c.ac_desc = class_ent_desc;
74ca0716f5SRobert Watson
75ca0716f5SRobert Watson while ((cp = getauclassent_r(&c)) != NULL)
76ca0716f5SRobert Watson printf("0x%08x:%s:%s\n", cp->ac_class, cp->ac_name,
77ca0716f5SRobert Watson cp->ac_desc);
78ca0716f5SRobert Watson }
79ca0716f5SRobert Watson
80ca0716f5SRobert Watson static void
audump_control(void)81ca0716f5SRobert Watson audump_control(void)
82ca0716f5SRobert Watson {
83bb97b418SRobert Watson char string[PATH_MAX], string2[PATH_MAX];
84*5e386598SRobert Watson int ret, val, qsz;
85bb97b418SRobert Watson long policy;
8606edd2f1SRobert Watson time_t age;
8706edd2f1SRobert Watson size_t size;
88ca0716f5SRobert Watson
89ca0716f5SRobert Watson ret = getacflg(string, PATH_MAX);
90ca0716f5SRobert Watson if (ret == -2)
91ca0716f5SRobert Watson err(-1, "getacflg");
92ca0716f5SRobert Watson if (ret != 0)
93ca0716f5SRobert Watson errx(-1, "getacflg: %d", ret);
94ca0716f5SRobert Watson
95ca0716f5SRobert Watson printf("flags:%s\n", string);
96ca0716f5SRobert Watson
97ca0716f5SRobert Watson ret = getacmin(&val);
98ca0716f5SRobert Watson if (ret == -2)
99ca0716f5SRobert Watson err(-1, "getacmin");
100ca0716f5SRobert Watson if (ret != 0)
101ca0716f5SRobert Watson errx(-1, "getacmin: %d", ret);
102ca0716f5SRobert Watson
103ca0716f5SRobert Watson printf("min:%d\n", val);
104ca0716f5SRobert Watson
105ca0716f5SRobert Watson ret = getacna(string, PATH_MAX);
106ca0716f5SRobert Watson if (ret == -2)
107ca0716f5SRobert Watson err(-1, "getacna");
108ca0716f5SRobert Watson if (ret != 0)
109ca0716f5SRobert Watson errx(-1, "getacna: %d", ret);
110ca0716f5SRobert Watson
111ca0716f5SRobert Watson printf("naflags:%s\n", string);
112ca0716f5SRobert Watson
113ca0716f5SRobert Watson setac();
114ca0716f5SRobert Watson do {
115ca0716f5SRobert Watson ret = getacdir(string, PATH_MAX);
116ca0716f5SRobert Watson if (ret == -1)
117ca0716f5SRobert Watson break;
118ca0716f5SRobert Watson if (ret == -2)
119ca0716f5SRobert Watson err(-1, "getacdir");
120ca0716f5SRobert Watson if (ret != 0)
121ca0716f5SRobert Watson errx(-1, "getacdir: %d", ret);
122ca0716f5SRobert Watson printf("dir:%s\n", string);
123ca0716f5SRobert Watson
124ca0716f5SRobert Watson } while (ret == 0);
125bb97b418SRobert Watson
126bb97b418SRobert Watson ret = getacpol(string, PATH_MAX);
127bb97b418SRobert Watson if (ret != 0)
128bb97b418SRobert Watson err(-1, "getacpol");
129bb97b418SRobert Watson if (au_strtopol(string, &policy) < 0)
130bb97b418SRobert Watson err(-1, "au_strtopol");
131bc168a6cSRobert Watson if (au_poltostr(policy, PATH_MAX, string2) < 0)
132bb97b418SRobert Watson err(-1, "au_poltostr");
133bb97b418SRobert Watson printf("policy:%s\n", string2);
13406edd2f1SRobert Watson
13506edd2f1SRobert Watson ret = getacfilesz(&size);
13606edd2f1SRobert Watson if (ret == -2)
13706edd2f1SRobert Watson err(-1, "getacfilesz");
13806edd2f1SRobert Watson if (ret != 0)
13906edd2f1SRobert Watson err(-1, "getacfilesz: %d", ret);
14006edd2f1SRobert Watson
14106edd2f1SRobert Watson printf("filesz:%ldB\n", size);
14206edd2f1SRobert Watson
143*5e386598SRobert Watson ret = getacqsize(&qsz);
144*5e386598SRobert Watson if (ret == -2)
145*5e386598SRobert Watson err(-1, "getacqsize");
146*5e386598SRobert Watson if (ret != 0)
147*5e386598SRobert Watson err(-1, "getacqzize: %d", ret);
148*5e386598SRobert Watson
149*5e386598SRobert Watson printf("qsize:%d\n", qsz);
15006edd2f1SRobert Watson
15106edd2f1SRobert Watson ret = getachost(string, PATH_MAX);
15206edd2f1SRobert Watson if (ret == -2)
15306edd2f1SRobert Watson err(-1, "getachost");
15406edd2f1SRobert Watson if (ret == -3)
15506edd2f1SRobert Watson err(-1, "getachost: %d", ret);
15606edd2f1SRobert Watson if (ret == 0 && ret != 1)
15706edd2f1SRobert Watson printf("host:%s\n", string);
15806edd2f1SRobert Watson
15906edd2f1SRobert Watson ret = getacexpire(&val, &age, &size);
16006edd2f1SRobert Watson if (ret == -2)
16106edd2f1SRobert Watson err(-1, "getacexpire");
16206edd2f1SRobert Watson if (ret == -1)
16306edd2f1SRobert Watson err(-1, "getacexpire: %d", ret);
16406edd2f1SRobert Watson if (ret == 0 && ret != 1)
16506edd2f1SRobert Watson printf("expire-after:%ldB %s %lds\n", size,
16606edd2f1SRobert Watson val ? "AND" : "OR", age);
167ca0716f5SRobert Watson }
168ca0716f5SRobert Watson
169ca0716f5SRobert Watson static void
printf_classmask(au_class_t classmask)170ca0716f5SRobert Watson printf_classmask(au_class_t classmask)
171ca0716f5SRobert Watson {
172ca0716f5SRobert Watson au_class_ent_t *c;
173ca0716f5SRobert Watson u_int32_t i;
174ca0716f5SRobert Watson int first;
175ca0716f5SRobert Watson
176ca0716f5SRobert Watson first = 1;
177ca0716f5SRobert Watson for (i = 0; i < 32; i++) {
178a743684eSRobert Watson if (classmask & (1 << i)) {
179ca0716f5SRobert Watson if (first)
180ca0716f5SRobert Watson first = 0;
181ca0716f5SRobert Watson else
182ca0716f5SRobert Watson printf(",");
183a743684eSRobert Watson c = getauclassnum(1 << i);
184ca0716f5SRobert Watson if (c != NULL)
185ca0716f5SRobert Watson printf("%s", c->ac_name);
186ca0716f5SRobert Watson else
187a743684eSRobert Watson printf("0x%x", 1 << i);
188ca0716f5SRobert Watson }
189ca0716f5SRobert Watson }
190ca0716f5SRobert Watson }
191ca0716f5SRobert Watson
192ca0716f5SRobert Watson static void
audump_event(void)193ca0716f5SRobert Watson audump_event(void)
194ca0716f5SRobert Watson {
195ca0716f5SRobert Watson au_event_ent_t *ep;
196ca0716f5SRobert Watson
197ca0716f5SRobert Watson while ((ep = getauevent()) != NULL) {
198ca0716f5SRobert Watson printf("%d:%s:%s:", ep->ae_number, ep->ae_name, ep->ae_desc);
199ca0716f5SRobert Watson printf_classmask(ep->ae_class);
200ca0716f5SRobert Watson printf("\n");
201ca0716f5SRobert Watson }
202ca0716f5SRobert Watson }
203ca0716f5SRobert Watson
204ca0716f5SRobert Watson static void
audump_event_r(void)205ca0716f5SRobert Watson audump_event_r(void)
206ca0716f5SRobert Watson {
207ca0716f5SRobert Watson char event_ent_name[AU_EVENT_NAME_MAX];
208ca0716f5SRobert Watson char event_ent_desc[AU_EVENT_DESC_MAX];
209ca0716f5SRobert Watson au_event_ent_t e, *ep;
210ca0716f5SRobert Watson
211ca0716f5SRobert Watson bzero(&e, sizeof(e));
212ca0716f5SRobert Watson bzero(event_ent_name, sizeof(event_ent_name));
213ca0716f5SRobert Watson bzero(event_ent_desc, sizeof(event_ent_desc));
214ca0716f5SRobert Watson e.ae_name = event_ent_name;
215ca0716f5SRobert Watson e.ae_desc = event_ent_desc;
216ca0716f5SRobert Watson
217ca0716f5SRobert Watson while ((ep = getauevent_r(&e)) != NULL) {
218ca0716f5SRobert Watson printf("%d:%s:%s:", ep->ae_number, ep->ae_name, ep->ae_desc);
219ca0716f5SRobert Watson printf_classmask(ep->ae_class);
220ca0716f5SRobert Watson printf("\n");
221ca0716f5SRobert Watson }
222ca0716f5SRobert Watson }
223ca0716f5SRobert Watson
224ca0716f5SRobert Watson static void
audump_user(void)225ca0716f5SRobert Watson audump_user(void)
226ca0716f5SRobert Watson {
227ca0716f5SRobert Watson au_user_ent_t *up;
228ca0716f5SRobert Watson
229ca0716f5SRobert Watson while ((up = getauuserent()) != NULL) {
230ca0716f5SRobert Watson printf("%s:", up->au_name);
231ca0716f5SRobert Watson // printf_classmask(up->au_always);
232ca0716f5SRobert Watson printf(":");
233ca0716f5SRobert Watson // printf_classmask(up->au_never);
234ca0716f5SRobert Watson printf("\n");
235ca0716f5SRobert Watson }
236ca0716f5SRobert Watson }
237ca0716f5SRobert Watson
238ca0716f5SRobert Watson static void
audump_user_r(void)239ca0716f5SRobert Watson audump_user_r(void)
240ca0716f5SRobert Watson {
241ca0716f5SRobert Watson char user_ent_name[AU_USER_NAME_MAX];
242ca0716f5SRobert Watson au_user_ent_t u, *up;
243ca0716f5SRobert Watson
244ca0716f5SRobert Watson bzero(&u, sizeof(u));
245ca0716f5SRobert Watson bzero(user_ent_name, sizeof(user_ent_name));
246ca0716f5SRobert Watson u.au_name = user_ent_name;
247ca0716f5SRobert Watson
248ca0716f5SRobert Watson while ((up = getauuserent_r(&u)) != NULL) {
249ca0716f5SRobert Watson printf("%s:", up->au_name);
250ca0716f5SRobert Watson // printf_classmask(up->au_always);
251ca0716f5SRobert Watson printf(":");
252ca0716f5SRobert Watson // printf_classmask(up->au_never);
253ca0716f5SRobert Watson printf("\n");
254ca0716f5SRobert Watson }
255ca0716f5SRobert Watson }
256ca0716f5SRobert Watson
257ca0716f5SRobert Watson int
main(int argc,char * argv[])258ca0716f5SRobert Watson main(int argc, char *argv[])
259ca0716f5SRobert Watson {
260ca0716f5SRobert Watson
261ca0716f5SRobert Watson if (argc != 2)
262ca0716f5SRobert Watson usage();
263ca0716f5SRobert Watson
264ca0716f5SRobert Watson if (strcmp(argv[1], "class") == 0)
265ca0716f5SRobert Watson audump_class();
266ca0716f5SRobert Watson else if (strcmp(argv[1], "class_r") == 0)
267ca0716f5SRobert Watson audump_class_r();
268ca0716f5SRobert Watson else if (strcmp(argv[1], "control") == 0)
269ca0716f5SRobert Watson audump_control();
270ca0716f5SRobert Watson else if (strcmp(argv[1], "event") == 0)
271ca0716f5SRobert Watson audump_event();
272ca0716f5SRobert Watson else if (strcmp(argv[1], "event_r") == 0)
273ca0716f5SRobert Watson audump_event_r();
274ca0716f5SRobert Watson else if (strcmp(argv[1], "user") == 0)
275ca0716f5SRobert Watson audump_user();
276ca0716f5SRobert Watson else if (strcmp(argv[1], "user_r") == 0)
277ca0716f5SRobert Watson audump_user_r();
278ca0716f5SRobert Watson else
279ca0716f5SRobert Watson usage();
280ca0716f5SRobert Watson
281ca0716f5SRobert Watson return (0);
282ca0716f5SRobert Watson }
283