xref: /freebsd/sys/rpc/authunix_prot.c (revision 29363fb446372cb3f10bc98664e9767c53fbb457)
1dfdcada3SDoug Rabson /*	$NetBSD: authunix_prot.c,v 1.12 2000/01/22 22:19:17 mycroft Exp $	*/
2dfdcada3SDoug Rabson 
32e322d37SHiroki Sato /*-
4*51369649SPedro F. Giffuni  * SPDX-License-Identifier: BSD-3-Clause
5*51369649SPedro F. Giffuni  *
62e322d37SHiroki Sato  * Copyright (c) 2009, Sun Microsystems, Inc.
72e322d37SHiroki Sato  * All rights reserved.
8dfdcada3SDoug Rabson  *
92e322d37SHiroki Sato  * Redistribution and use in source and binary forms, with or without
102e322d37SHiroki Sato  * modification, are permitted provided that the following conditions are met:
112e322d37SHiroki Sato  * - Redistributions of source code must retain the above copyright notice,
122e322d37SHiroki Sato  *   this list of conditions and the following disclaimer.
132e322d37SHiroki Sato  * - Redistributions in binary form must reproduce the above copyright notice,
142e322d37SHiroki Sato  *   this list of conditions and the following disclaimer in the documentation
152e322d37SHiroki Sato  *   and/or other materials provided with the distribution.
162e322d37SHiroki Sato  * - Neither the name of Sun Microsystems, Inc. nor the names of its
172e322d37SHiroki Sato  *   contributors may be used to endorse or promote products derived
182e322d37SHiroki Sato  *   from this software without specific prior written permission.
19dfdcada3SDoug Rabson  *
202e322d37SHiroki Sato  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
212e322d37SHiroki Sato  * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
222e322d37SHiroki Sato  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
232e322d37SHiroki Sato  * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
242e322d37SHiroki Sato  * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
252e322d37SHiroki Sato  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
262e322d37SHiroki Sato  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
272e322d37SHiroki Sato  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
282e322d37SHiroki Sato  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
292e322d37SHiroki Sato  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
302e322d37SHiroki Sato  * POSSIBILITY OF SUCH DAMAGE.
31dfdcada3SDoug Rabson  */
32dfdcada3SDoug Rabson 
33dfdcada3SDoug Rabson #include <sys/cdefs.h>
34dfdcada3SDoug Rabson /*
35dfdcada3SDoug Rabson  * authunix_prot.c
36dfdcada3SDoug Rabson  * XDR for UNIX style authentication parameters for RPC
37dfdcada3SDoug Rabson  *
38dfdcada3SDoug Rabson  * Copyright (C) 1984, Sun Microsystems, Inc.
39dfdcada3SDoug Rabson  */
40dfdcada3SDoug Rabson 
41dfdcada3SDoug Rabson #include <sys/param.h>
4276ca6f88SJamie Gritton #include <sys/jail.h>
43dfdcada3SDoug Rabson #include <sys/kernel.h>
44dfdcada3SDoug Rabson #include <sys/systm.h>
45dfdcada3SDoug Rabson #include <sys/ucred.h>
46dfdcada3SDoug Rabson 
47dfdcada3SDoug Rabson #include <rpc/types.h>
48dfdcada3SDoug Rabson #include <rpc/xdr.h>
49dfdcada3SDoug Rabson #include <rpc/auth.h>
50dfdcada3SDoug Rabson 
51ee31b83aSDoug Rabson #include <rpc/rpc_com.h>
52dfdcada3SDoug Rabson 
53dfdcada3SDoug Rabson /* gids compose part of a credential; there may not be more than 16 of them */
54dfdcada3SDoug Rabson #define NGRPS 16
55dfdcada3SDoug Rabson 
56dfdcada3SDoug Rabson /*
57dfdcada3SDoug Rabson  * XDR for unix authentication parameters.
58dfdcada3SDoug Rabson  */
59dfdcada3SDoug Rabson bool_t
xdr_authunix_parms(XDR * xdrs,uint32_t * time,struct xucred * cred)60dfdcada3SDoug Rabson xdr_authunix_parms(XDR *xdrs, uint32_t *time, struct xucred *cred)
61dfdcada3SDoug Rabson {
62dfdcada3SDoug Rabson 	uint32_t namelen;
63dfdcada3SDoug Rabson 	uint32_t ngroups, i;
64dfdcada3SDoug Rabson 	uint32_t junk;
6576ca6f88SJamie Gritton 	char hostbuf[MAXHOSTNAMELEN];
66dfdcada3SDoug Rabson 
67dfdcada3SDoug Rabson 	if (xdrs->x_op == XDR_ENCODE) {
68c675522fSDoug Rabson 		/*
69c675522fSDoug Rabson 		 * Restrict name length to 255 according to RFC 1057.
70c675522fSDoug Rabson 		 */
7176ca6f88SJamie Gritton 		getcredhostname(NULL, hostbuf, sizeof(hostbuf));
7276ca6f88SJamie Gritton 		namelen = strlen(hostbuf);
73c675522fSDoug Rabson 		if (namelen > 255)
74c675522fSDoug Rabson 			namelen = 255;
75dfdcada3SDoug Rabson 	} else {
76dfdcada3SDoug Rabson 		namelen = 0;
77dfdcada3SDoug Rabson 	}
78dfdcada3SDoug Rabson 	junk = 0;
79dfdcada3SDoug Rabson 
80dfdcada3SDoug Rabson 	if (!xdr_uint32_t(xdrs, time)
81dfdcada3SDoug Rabson 	    || !xdr_uint32_t(xdrs, &namelen))
82dfdcada3SDoug Rabson 		return (FALSE);
83dfdcada3SDoug Rabson 
84dfdcada3SDoug Rabson 	/*
85dfdcada3SDoug Rabson 	 * Ignore the hostname on decode.
86dfdcada3SDoug Rabson 	 */
87dfdcada3SDoug Rabson 	if (xdrs->x_op == XDR_ENCODE) {
8876ca6f88SJamie Gritton 		if (!xdr_opaque(xdrs, hostbuf, namelen))
89dfdcada3SDoug Rabson 			return (FALSE);
90dfdcada3SDoug Rabson 	} else {
91dfdcada3SDoug Rabson 		xdr_setpos(xdrs, xdr_getpos(xdrs) + RNDUP(namelen));
92dfdcada3SDoug Rabson 	}
93dfdcada3SDoug Rabson 
94dfdcada3SDoug Rabson 	if (!xdr_uint32_t(xdrs, &cred->cr_uid))
95dfdcada3SDoug Rabson 		return (FALSE);
96dfdcada3SDoug Rabson 	if (!xdr_uint32_t(xdrs, &cred->cr_groups[0]))
97dfdcada3SDoug Rabson 		return (FALSE);
98dfdcada3SDoug Rabson 
99dfdcada3SDoug Rabson 	if (xdrs->x_op == XDR_ENCODE) {
100dfdcada3SDoug Rabson 		ngroups = cred->cr_ngroups - 1;
101dfdcada3SDoug Rabson 		if (ngroups > NGRPS)
102dfdcada3SDoug Rabson 			ngroups = NGRPS;
103dfdcada3SDoug Rabson 	}
104dfdcada3SDoug Rabson 
105dfdcada3SDoug Rabson 	if (!xdr_uint32_t(xdrs, &ngroups))
106dfdcada3SDoug Rabson 		return (FALSE);
107dfdcada3SDoug Rabson 	for (i = 0; i < ngroups; i++) {
108412f9500SBrooks Davis 		if (i + 1 < ngroups_max + 1) {
109dfdcada3SDoug Rabson 			if (!xdr_uint32_t(xdrs, &cred->cr_groups[i + 1]))
110dfdcada3SDoug Rabson 				return (FALSE);
111dfdcada3SDoug Rabson 		} else {
112dfdcada3SDoug Rabson 			if (!xdr_uint32_t(xdrs, &junk))
113dfdcada3SDoug Rabson 				return (FALSE);
114dfdcada3SDoug Rabson 		}
115dfdcada3SDoug Rabson 	}
116dfdcada3SDoug Rabson 
117dfdcada3SDoug Rabson 	if (xdrs->x_op == XDR_DECODE) {
118412f9500SBrooks Davis 		if (ngroups + 1 > ngroups_max + 1)
119412f9500SBrooks Davis 			cred->cr_ngroups = ngroups_max + 1;
120dfdcada3SDoug Rabson 		else
121dfdcada3SDoug Rabson 			cred->cr_ngroups = ngroups + 1;
122dfdcada3SDoug Rabson 	}
123dfdcada3SDoug Rabson 
124dfdcada3SDoug Rabson 	return (TRUE);
125dfdcada3SDoug Rabson }
126