17c478bd9Sstevel@tonic-gate /* 27c478bd9Sstevel@tonic-gate * kdc/replay.c 37c478bd9Sstevel@tonic-gate * 47c478bd9Sstevel@tonic-gate * Copyright 1991 by the Massachusetts Institute of Technology. 57c478bd9Sstevel@tonic-gate * All Rights Reserved. 67c478bd9Sstevel@tonic-gate * 77c478bd9Sstevel@tonic-gate * Export of this software from the United States of America may 87c478bd9Sstevel@tonic-gate * require a specific license from the United States Government. 97c478bd9Sstevel@tonic-gate * It is the responsibility of any person or organization contemplating 107c478bd9Sstevel@tonic-gate * export to obtain such a license before exporting. 117c478bd9Sstevel@tonic-gate * 127c478bd9Sstevel@tonic-gate * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and 137c478bd9Sstevel@tonic-gate * distribute this software and its documentation for any purpose and 147c478bd9Sstevel@tonic-gate * without fee is hereby granted, provided that the above copyright 157c478bd9Sstevel@tonic-gate * notice appear in all copies and that both that copyright notice and 167c478bd9Sstevel@tonic-gate * this permission notice appear in supporting documentation, and that 177c478bd9Sstevel@tonic-gate * the name of M.I.T. not be used in advertising or publicity pertaining 187c478bd9Sstevel@tonic-gate * to distribution of the software without specific, written prior 197c478bd9Sstevel@tonic-gate * permission. Furthermore if you modify this software you must label 207c478bd9Sstevel@tonic-gate * your software as modified software and not distribute it in such a 217c478bd9Sstevel@tonic-gate * fashion that it might be confused with the original M.I.T. software. 227c478bd9Sstevel@tonic-gate * M.I.T. makes no representations about the suitability of 237c478bd9Sstevel@tonic-gate * this software for any purpose. It is provided "as is" without express 247c478bd9Sstevel@tonic-gate * or implied warranty. 257c478bd9Sstevel@tonic-gate * 267c478bd9Sstevel@tonic-gate * 277c478bd9Sstevel@tonic-gate * Replay lookaside cache for the KDC, to avoid extra work. 287c478bd9Sstevel@tonic-gate * 297c478bd9Sstevel@tonic-gate */ 307c478bd9Sstevel@tonic-gate 317c478bd9Sstevel@tonic-gate 327c478bd9Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 337c478bd9Sstevel@tonic-gate 347c478bd9Sstevel@tonic-gate #include "k5-int.h" 357c478bd9Sstevel@tonic-gate #include "kdc_util.h" 367c478bd9Sstevel@tonic-gate #include "extern.h" 377c478bd9Sstevel@tonic-gate 387c478bd9Sstevel@tonic-gate #ifndef NOCACHE 397c478bd9Sstevel@tonic-gate 407c478bd9Sstevel@tonic-gate typedef struct _krb5_kdc_replay_ent { 417c478bd9Sstevel@tonic-gate struct _krb5_kdc_replay_ent *next; 427c478bd9Sstevel@tonic-gate int num_hits; 437c478bd9Sstevel@tonic-gate krb5_int32 timein; 447c478bd9Sstevel@tonic-gate time_t db_age; 457c478bd9Sstevel@tonic-gate krb5_data *req_packet; 467c478bd9Sstevel@tonic-gate krb5_data *reply_packet; 477c478bd9Sstevel@tonic-gate krb5_address *addr; /* XXX should these not be pointers? */ 487c478bd9Sstevel@tonic-gate } krb5_kdc_replay_ent; 497c478bd9Sstevel@tonic-gate 507c478bd9Sstevel@tonic-gate static krb5_kdc_replay_ent root_ptr = {0}; 517c478bd9Sstevel@tonic-gate 527c478bd9Sstevel@tonic-gate static int hits = 0; 537c478bd9Sstevel@tonic-gate static int calls = 0; 547c478bd9Sstevel@tonic-gate static int max_hits_per_entry = 0; 557c478bd9Sstevel@tonic-gate static int num_entries = 0; 567c478bd9Sstevel@tonic-gate 577c478bd9Sstevel@tonic-gate #define STALE_TIME 2*60 /* two minutes */ 587c478bd9Sstevel@tonic-gate #define STALE(ptr) ((abs((ptr)->timein - timenow) >= STALE_TIME) || \ 597c478bd9Sstevel@tonic-gate ((ptr)->db_age != db_age)) 607c478bd9Sstevel@tonic-gate 617c478bd9Sstevel@tonic-gate #define MATCH(ptr) (((ptr)->req_packet->length == inpkt->length) && \ 627c478bd9Sstevel@tonic-gate !memcmp((ptr)->req_packet->data, inpkt->data, \ 637c478bd9Sstevel@tonic-gate inpkt->length) && \ 647c478bd9Sstevel@tonic-gate ((ptr)->addr->length == from->address->length) && \ 657c478bd9Sstevel@tonic-gate !memcmp((ptr)->addr->contents, \ 667c478bd9Sstevel@tonic-gate from->address->contents, \ 677c478bd9Sstevel@tonic-gate from->address->length)&& \ 687c478bd9Sstevel@tonic-gate ((ptr)->db_age == db_age)) 697c478bd9Sstevel@tonic-gate /* XXX 707c478bd9Sstevel@tonic-gate Todo: quench the size of the queue... 717c478bd9Sstevel@tonic-gate */ 727c478bd9Sstevel@tonic-gate 737c478bd9Sstevel@tonic-gate /* return TRUE if outpkt is filled in with a packet to reply with, 747c478bd9Sstevel@tonic-gate FALSE if the caller should do the work */ 757c478bd9Sstevel@tonic-gate 767c478bd9Sstevel@tonic-gate krb5_boolean 77*56a424ccSmp153739 kdc_check_lookaside(krb5_data *inpkt, const krb5_fulladdr *from, 78*56a424ccSmp153739 krb5_data **outpkt) 797c478bd9Sstevel@tonic-gate { 807c478bd9Sstevel@tonic-gate krb5_int32 timenow; 817c478bd9Sstevel@tonic-gate register krb5_kdc_replay_ent *eptr, *last, *hold; 827c478bd9Sstevel@tonic-gate time_t db_age; 837c478bd9Sstevel@tonic-gate 847c478bd9Sstevel@tonic-gate if (krb5_timeofday(kdc_context, &timenow) || 857c478bd9Sstevel@tonic-gate krb5_db_get_age(kdc_context, 0, &db_age)) 867c478bd9Sstevel@tonic-gate return FALSE; 877c478bd9Sstevel@tonic-gate 887c478bd9Sstevel@tonic-gate calls++; 897c478bd9Sstevel@tonic-gate 907c478bd9Sstevel@tonic-gate /* search for a replay entry in the queue, possibly removing 917c478bd9Sstevel@tonic-gate stale entries while we're here */ 927c478bd9Sstevel@tonic-gate 937c478bd9Sstevel@tonic-gate if (root_ptr.next) { 947c478bd9Sstevel@tonic-gate for (last = &root_ptr, eptr = root_ptr.next; 957c478bd9Sstevel@tonic-gate eptr; 967c478bd9Sstevel@tonic-gate eptr = eptr->next) { 977c478bd9Sstevel@tonic-gate if (MATCH(eptr)) { 987c478bd9Sstevel@tonic-gate eptr->num_hits++; 997c478bd9Sstevel@tonic-gate hits++; 1007c478bd9Sstevel@tonic-gate 1017c478bd9Sstevel@tonic-gate if (krb5_copy_data(kdc_context, eptr->reply_packet, outpkt)) 1027c478bd9Sstevel@tonic-gate return FALSE; 1037c478bd9Sstevel@tonic-gate else 1047c478bd9Sstevel@tonic-gate return TRUE; 1057c478bd9Sstevel@tonic-gate /* return here, don't bother flushing even if it is stale. 1067c478bd9Sstevel@tonic-gate if we just matched, we may get another retransmit... */ 1077c478bd9Sstevel@tonic-gate } 1087c478bd9Sstevel@tonic-gate if (STALE(eptr)) { 1097c478bd9Sstevel@tonic-gate /* flush it and collect stats */ 1107c478bd9Sstevel@tonic-gate max_hits_per_entry = max(max_hits_per_entry, eptr->num_hits); 1117c478bd9Sstevel@tonic-gate krb5_free_data(kdc_context, eptr->req_packet); 1127c478bd9Sstevel@tonic-gate krb5_free_data(kdc_context, eptr->reply_packet); 1137c478bd9Sstevel@tonic-gate krb5_free_address(kdc_context, eptr->addr); 1147c478bd9Sstevel@tonic-gate hold = eptr; 1157c478bd9Sstevel@tonic-gate last->next = eptr->next; 1167c478bd9Sstevel@tonic-gate eptr = last; 1177c478bd9Sstevel@tonic-gate free(hold); 1187c478bd9Sstevel@tonic-gate } else { 1197c478bd9Sstevel@tonic-gate /* this isn't it, just move along */ 1207c478bd9Sstevel@tonic-gate last = eptr; 1217c478bd9Sstevel@tonic-gate } 1227c478bd9Sstevel@tonic-gate } 1237c478bd9Sstevel@tonic-gate } 1247c478bd9Sstevel@tonic-gate return FALSE; 1257c478bd9Sstevel@tonic-gate } 1267c478bd9Sstevel@tonic-gate 1277c478bd9Sstevel@tonic-gate /* insert a request & reply into the lookaside queue. assumes it's not 1287c478bd9Sstevel@tonic-gate already there, and can fail softly due to other weird errors. */ 1297c478bd9Sstevel@tonic-gate 1307c478bd9Sstevel@tonic-gate void 131*56a424ccSmp153739 kdc_insert_lookaside(krb5_data *inpkt, const krb5_fulladdr *from, 132*56a424ccSmp153739 krb5_data *outpkt) 1337c478bd9Sstevel@tonic-gate { 1347c478bd9Sstevel@tonic-gate register krb5_kdc_replay_ent *eptr; 1357c478bd9Sstevel@tonic-gate krb5_int32 timenow; 1367c478bd9Sstevel@tonic-gate time_t db_age; 1377c478bd9Sstevel@tonic-gate 1387c478bd9Sstevel@tonic-gate if (krb5_timeofday(kdc_context, &timenow) || 1397c478bd9Sstevel@tonic-gate krb5_db_get_age(kdc_context, 0, &db_age)) 1407c478bd9Sstevel@tonic-gate return; 1417c478bd9Sstevel@tonic-gate 1427c478bd9Sstevel@tonic-gate /* this is a new entry */ 1437c478bd9Sstevel@tonic-gate eptr = (krb5_kdc_replay_ent *)calloc(1, sizeof(*eptr)); 1447c478bd9Sstevel@tonic-gate if (!eptr) 1457c478bd9Sstevel@tonic-gate return; 1467c478bd9Sstevel@tonic-gate eptr->timein = timenow; 1477c478bd9Sstevel@tonic-gate eptr->db_age = db_age; 1487c478bd9Sstevel@tonic-gate /* 1497c478bd9Sstevel@tonic-gate * This is going to hurt a lot malloc()-wise due to the need to 1507c478bd9Sstevel@tonic-gate * allocate memory for the krb5_data and krb5_address elements. 1517c478bd9Sstevel@tonic-gate * ARGH! 1527c478bd9Sstevel@tonic-gate */ 1537c478bd9Sstevel@tonic-gate if (krb5_copy_data(kdc_context, inpkt, &eptr->req_packet)) { 1547c478bd9Sstevel@tonic-gate free(eptr); 1557c478bd9Sstevel@tonic-gate return; 1567c478bd9Sstevel@tonic-gate } 1577c478bd9Sstevel@tonic-gate if (krb5_copy_data(kdc_context, outpkt, &eptr->reply_packet)) { 1587c478bd9Sstevel@tonic-gate krb5_free_data(kdc_context, eptr->req_packet); 1597c478bd9Sstevel@tonic-gate free(eptr); 1607c478bd9Sstevel@tonic-gate return; 1617c478bd9Sstevel@tonic-gate } 1627c478bd9Sstevel@tonic-gate if (krb5_copy_addr(kdc_context, from->address, &eptr->addr)) { 1637c478bd9Sstevel@tonic-gate krb5_free_data(kdc_context, eptr->req_packet); 1647c478bd9Sstevel@tonic-gate krb5_free_data(kdc_context, eptr->reply_packet); 1657c478bd9Sstevel@tonic-gate free(eptr); 1667c478bd9Sstevel@tonic-gate return; 1677c478bd9Sstevel@tonic-gate } 1687c478bd9Sstevel@tonic-gate eptr->next = root_ptr.next; 1697c478bd9Sstevel@tonic-gate root_ptr.next = eptr; 1707c478bd9Sstevel@tonic-gate num_entries++; 1717c478bd9Sstevel@tonic-gate return; 1727c478bd9Sstevel@tonic-gate } 1737c478bd9Sstevel@tonic-gate 174*56a424ccSmp153739 /* frees memory associated with the lookaside queue for memory profiling */ 175*56a424ccSmp153739 void 176*56a424ccSmp153739 kdc_free_lookaside(krb5_context kcontext) 177*56a424ccSmp153739 { 178*56a424ccSmp153739 register krb5_kdc_replay_ent *eptr, *last, *hold; 179*56a424ccSmp153739 if (root_ptr.next) { 180*56a424ccSmp153739 for (last = &root_ptr, eptr = root_ptr.next; 181*56a424ccSmp153739 eptr; eptr = eptr->next) { 182*56a424ccSmp153739 krb5_free_data(kcontext, eptr->req_packet); 183*56a424ccSmp153739 krb5_free_data(kcontext, eptr->reply_packet); 184*56a424ccSmp153739 krb5_free_address(kcontext, eptr->addr); 185*56a424ccSmp153739 hold = eptr; 186*56a424ccSmp153739 last->next = eptr->next; 187*56a424ccSmp153739 eptr = last; 188*56a424ccSmp153739 free(hold); 189*56a424ccSmp153739 } 190*56a424ccSmp153739 } 191*56a424ccSmp153739 } 192*56a424ccSmp153739 1937c478bd9Sstevel@tonic-gate #endif /* NOCACHE */ 194