xref: /freebsd/crypto/heimdal/lib/hx509/ks_dir.c (revision 2008043f386721d58158e37e0d7e50df8095942d)
1 /*
2  * Copyright (c) 2006 Kungliga Tekniska Högskolan
3  * (Royal Institute of Technology, Stockholm, Sweden).
4  * All rights reserved.
5  *
6  * Redistribution and use in source and binary forms, with or without
7  * modification, are permitted provided that the following conditions
8  * are met:
9  *
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  *
13  * 2. Redistributions in binary form must reproduce the above copyright
14  *    notice, this list of conditions and the following disclaimer in the
15  *    documentation and/or other materials provided with the distribution.
16  *
17  * 3. Neither the name of the Institute nor the names of its contributors
18  *    may be used to endorse or promote products derived from this software
19  *    without specific prior written permission.
20  *
21  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  */
33 
34 #include "hx_locl.h"
35 #include <dirent.h>
36 
37 /*
38  * The DIR keyset module is strange compared to the other modules
39  * since it does lazy evaluation and really doesn't keep any local
40  * state except for the directory iteration and cert iteration of
41  * files. DIR ignores most errors so that the consumer doesn't get
42  * failes for stray files in directories.
43  */
44 
45 struct dircursor {
46     DIR *dir;
47     hx509_certs certs;
48     void *iter;
49 };
50 
51 /*
52  *
53  */
54 
55 static int
56 dir_init(hx509_context context,
57 	 hx509_certs certs, void **data, int flags,
58 	 const char *residue, hx509_lock lock)
59 {
60     *data = NULL;
61 
62     {
63 	struct stat sb;
64 	int ret;
65 
66 	ret = stat(residue, &sb);
67 	if (ret == -1) {
68 	    hx509_set_error_string(context, 0, ENOENT,
69 				   "No such file %s", residue);
70 	    return ENOENT;
71 	}
72 
73 	if (!S_ISDIR(sb.st_mode)) {
74 	    hx509_set_error_string(context, 0, ENOTDIR,
75 				   "%s is not a directory", residue);
76 	    return ENOTDIR;
77 	}
78     }
79 
80     *data = strdup(residue);
81     if (*data == NULL) {
82 	hx509_clear_error_string(context);
83 	return ENOMEM;
84     }
85 
86     return 0;
87 }
88 
89 static int
90 dir_free(hx509_certs certs, void *data)
91 {
92     free(data);
93     return 0;
94 }
95 
96 static int
97 dir_iter_start(hx509_context context,
98 	       hx509_certs certs, void *data, void **cursor)
99 {
100     struct dircursor *d;
101 
102     *cursor = NULL;
103 
104     d = calloc(1, sizeof(*d));
105     if (d == NULL) {
106 	hx509_clear_error_string(context);
107 	return ENOMEM;
108     }
109 
110     d->dir = opendir(data);
111     if (d->dir == NULL) {
112 	hx509_clear_error_string(context);
113 	free(d);
114 	return errno;
115     }
116     rk_cloexec_dir(d->dir);
117     d->certs = NULL;
118     d->iter = NULL;
119 
120     *cursor = d;
121     return 0;
122 }
123 
124 static int
125 dir_iter(hx509_context context,
126 	 hx509_certs certs, void *data, void *iter, hx509_cert *cert)
127 {
128     struct dircursor *d = iter;
129     int ret = 0;
130 
131     *cert = NULL;
132 
133     do {
134 	struct dirent *dir;
135 	char *fn;
136 
137 	if (d->certs) {
138 	    ret = hx509_certs_next_cert(context, d->certs, d->iter, cert);
139 	    if (ret) {
140 		hx509_certs_end_seq(context, d->certs, d->iter);
141 		d->iter = NULL;
142 		hx509_certs_free(&d->certs);
143 		return ret;
144 	    }
145 	    if (*cert) {
146 		ret = 0;
147 		break;
148 	    }
149 	    hx509_certs_end_seq(context, d->certs, d->iter);
150 	    d->iter = NULL;
151 	    hx509_certs_free(&d->certs);
152 	}
153 
154 	dir = readdir(d->dir);
155 	if (dir == NULL) {
156 	    ret = 0;
157 	    break;
158 	}
159 	if (strcmp(dir->d_name, ".") == 0 || strcmp(dir->d_name, "..") == 0)
160 	    continue;
161 
162 	if (asprintf(&fn, "FILE:%s/%s", (char *)data, dir->d_name) == -1)
163 	    return ENOMEM;
164 
165 	ret = hx509_certs_init(context, fn, 0, NULL, &d->certs);
166 	if (ret == 0) {
167 
168 	    ret = hx509_certs_start_seq(context, d->certs, &d->iter);
169 	    if (ret)
170 	    hx509_certs_free(&d->certs);
171 	}
172 	/* ignore errors */
173 	if (ret) {
174 	    d->certs = NULL;
175 	    ret = 0;
176 	}
177 
178 	free(fn);
179     } while(ret == 0);
180 
181     return ret;
182 }
183 
184 
185 static int
186 dir_iter_end(hx509_context context,
187 	     hx509_certs certs,
188 	     void *data,
189 	     void *cursor)
190 {
191     struct dircursor *d = cursor;
192 
193     if (d->certs) {
194 	hx509_certs_end_seq(context, d->certs, d->iter);
195 	d->iter = NULL;
196 	hx509_certs_free(&d->certs);
197     }
198     closedir(d->dir);
199     free(d);
200     return 0;
201 }
202 
203 
204 static struct hx509_keyset_ops keyset_dir = {
205     "DIR",
206     0,
207     dir_init,
208     NULL,
209     dir_free,
210     NULL,
211     NULL,
212     dir_iter_start,
213     dir_iter,
214     dir_iter_end
215 };
216 
217 void
218 _hx509_ks_dir_register(hx509_context context)
219 {
220     _hx509_ks_register(context, &keyset_dir);
221 }
222