xref: /titanic_51/usr/src/cmd/krb5/krb5kdc/replay.c (revision 56a424cca6b3f91f31bdab72a4626c48c779fe8b)
17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate  * kdc/replay.c
37c478bd9Sstevel@tonic-gate  *
47c478bd9Sstevel@tonic-gate  * Copyright 1991 by the Massachusetts Institute of Technology.
57c478bd9Sstevel@tonic-gate  * All Rights Reserved.
67c478bd9Sstevel@tonic-gate  *
77c478bd9Sstevel@tonic-gate  * Export of this software from the United States of America may
87c478bd9Sstevel@tonic-gate  *   require a specific license from the United States Government.
97c478bd9Sstevel@tonic-gate  *   It is the responsibility of any person or organization contemplating
107c478bd9Sstevel@tonic-gate  *   export to obtain such a license before exporting.
117c478bd9Sstevel@tonic-gate  *
127c478bd9Sstevel@tonic-gate  * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
137c478bd9Sstevel@tonic-gate  * distribute this software and its documentation for any purpose and
147c478bd9Sstevel@tonic-gate  * without fee is hereby granted, provided that the above copyright
157c478bd9Sstevel@tonic-gate  * notice appear in all copies and that both that copyright notice and
167c478bd9Sstevel@tonic-gate  * this permission notice appear in supporting documentation, and that
177c478bd9Sstevel@tonic-gate  * the name of M.I.T. not be used in advertising or publicity pertaining
187c478bd9Sstevel@tonic-gate  * to distribution of the software without specific, written prior
197c478bd9Sstevel@tonic-gate  * permission.  Furthermore if you modify this software you must label
207c478bd9Sstevel@tonic-gate  * your software as modified software and not distribute it in such a
217c478bd9Sstevel@tonic-gate  * fashion that it might be confused with the original M.I.T. software.
227c478bd9Sstevel@tonic-gate  * M.I.T. makes no representations about the suitability of
237c478bd9Sstevel@tonic-gate  * this software for any purpose.  It is provided "as is" without express
247c478bd9Sstevel@tonic-gate  * or implied warranty.
257c478bd9Sstevel@tonic-gate  *
267c478bd9Sstevel@tonic-gate  *
277c478bd9Sstevel@tonic-gate  * Replay lookaside cache for the KDC, to avoid extra work.
287c478bd9Sstevel@tonic-gate  *
297c478bd9Sstevel@tonic-gate  */
307c478bd9Sstevel@tonic-gate 
317c478bd9Sstevel@tonic-gate 
327c478bd9Sstevel@tonic-gate #pragma ident	"%Z%%M%	%I%	%E% SMI"
337c478bd9Sstevel@tonic-gate 
347c478bd9Sstevel@tonic-gate #include "k5-int.h"
357c478bd9Sstevel@tonic-gate #include "kdc_util.h"
367c478bd9Sstevel@tonic-gate #include "extern.h"
377c478bd9Sstevel@tonic-gate 
387c478bd9Sstevel@tonic-gate #ifndef NOCACHE
397c478bd9Sstevel@tonic-gate 
407c478bd9Sstevel@tonic-gate typedef struct _krb5_kdc_replay_ent {
417c478bd9Sstevel@tonic-gate     struct _krb5_kdc_replay_ent *next;
427c478bd9Sstevel@tonic-gate     int num_hits;
437c478bd9Sstevel@tonic-gate     krb5_int32 timein;
447c478bd9Sstevel@tonic-gate     time_t db_age;
457c478bd9Sstevel@tonic-gate     krb5_data *req_packet;
467c478bd9Sstevel@tonic-gate     krb5_data *reply_packet;
477c478bd9Sstevel@tonic-gate     krb5_address *addr;		/* XXX should these not be pointers? */
487c478bd9Sstevel@tonic-gate } krb5_kdc_replay_ent;
497c478bd9Sstevel@tonic-gate 
507c478bd9Sstevel@tonic-gate static krb5_kdc_replay_ent root_ptr = {0};
517c478bd9Sstevel@tonic-gate 
527c478bd9Sstevel@tonic-gate static int hits = 0;
537c478bd9Sstevel@tonic-gate static int calls = 0;
547c478bd9Sstevel@tonic-gate static int max_hits_per_entry = 0;
557c478bd9Sstevel@tonic-gate static int num_entries = 0;
567c478bd9Sstevel@tonic-gate 
577c478bd9Sstevel@tonic-gate #define STALE_TIME	2*60		/* two minutes */
587c478bd9Sstevel@tonic-gate #define STALE(ptr) ((abs((ptr)->timein - timenow) >= STALE_TIME) ||	\
597c478bd9Sstevel@tonic-gate 		    ((ptr)->db_age != db_age))
607c478bd9Sstevel@tonic-gate 
617c478bd9Sstevel@tonic-gate #define MATCH(ptr) (((ptr)->req_packet->length == inpkt->length) &&	\
627c478bd9Sstevel@tonic-gate 		    !memcmp((ptr)->req_packet->data, inpkt->data,	\
637c478bd9Sstevel@tonic-gate 			    inpkt->length) &&				\
647c478bd9Sstevel@tonic-gate 		    ((ptr)->addr->length == from->address->length) &&	\
657c478bd9Sstevel@tonic-gate 		    !memcmp((ptr)->addr->contents,			\
667c478bd9Sstevel@tonic-gate 			    from->address->contents,			\
677c478bd9Sstevel@tonic-gate 			    from->address->length)&&			\
687c478bd9Sstevel@tonic-gate 		    ((ptr)->db_age == db_age))
697c478bd9Sstevel@tonic-gate /* XXX
707c478bd9Sstevel@tonic-gate    Todo:  quench the size of the queue...
717c478bd9Sstevel@tonic-gate  */
727c478bd9Sstevel@tonic-gate 
737c478bd9Sstevel@tonic-gate /* return TRUE if outpkt is filled in with a packet to reply with,
747c478bd9Sstevel@tonic-gate    FALSE if the caller should do the work */
757c478bd9Sstevel@tonic-gate 
767c478bd9Sstevel@tonic-gate krb5_boolean
77*56a424ccSmp153739 kdc_check_lookaside(krb5_data *inpkt, const krb5_fulladdr *from,
78*56a424ccSmp153739 		    krb5_data **outpkt)
797c478bd9Sstevel@tonic-gate {
807c478bd9Sstevel@tonic-gate     krb5_int32 timenow;
817c478bd9Sstevel@tonic-gate     register krb5_kdc_replay_ent *eptr, *last, *hold;
827c478bd9Sstevel@tonic-gate     time_t db_age;
837c478bd9Sstevel@tonic-gate 
847c478bd9Sstevel@tonic-gate     if (krb5_timeofday(kdc_context, &timenow) ||
857c478bd9Sstevel@tonic-gate 	krb5_db_get_age(kdc_context, 0, &db_age))
867c478bd9Sstevel@tonic-gate 	return FALSE;
877c478bd9Sstevel@tonic-gate 
887c478bd9Sstevel@tonic-gate     calls++;
897c478bd9Sstevel@tonic-gate 
907c478bd9Sstevel@tonic-gate     /* search for a replay entry in the queue, possibly removing
917c478bd9Sstevel@tonic-gate        stale entries while we're here */
927c478bd9Sstevel@tonic-gate 
937c478bd9Sstevel@tonic-gate     if (root_ptr.next) {
947c478bd9Sstevel@tonic-gate 	for (last = &root_ptr, eptr = root_ptr.next;
957c478bd9Sstevel@tonic-gate 	     eptr;
967c478bd9Sstevel@tonic-gate 	     eptr = eptr->next) {
977c478bd9Sstevel@tonic-gate 	    if (MATCH(eptr)) {
987c478bd9Sstevel@tonic-gate 		eptr->num_hits++;
997c478bd9Sstevel@tonic-gate 		hits++;
1007c478bd9Sstevel@tonic-gate 
1017c478bd9Sstevel@tonic-gate 		if (krb5_copy_data(kdc_context, eptr->reply_packet, outpkt))
1027c478bd9Sstevel@tonic-gate 		    return FALSE;
1037c478bd9Sstevel@tonic-gate 		else
1047c478bd9Sstevel@tonic-gate 		    return TRUE;
1057c478bd9Sstevel@tonic-gate 		/* return here, don't bother flushing even if it is stale.
1067c478bd9Sstevel@tonic-gate 		   if we just matched, we may get another retransmit... */
1077c478bd9Sstevel@tonic-gate 	    }
1087c478bd9Sstevel@tonic-gate 	    if (STALE(eptr)) {
1097c478bd9Sstevel@tonic-gate 		/* flush it and collect stats */
1107c478bd9Sstevel@tonic-gate 		max_hits_per_entry = max(max_hits_per_entry, eptr->num_hits);
1117c478bd9Sstevel@tonic-gate 		krb5_free_data(kdc_context, eptr->req_packet);
1127c478bd9Sstevel@tonic-gate 		krb5_free_data(kdc_context, eptr->reply_packet);
1137c478bd9Sstevel@tonic-gate 		krb5_free_address(kdc_context, eptr->addr);
1147c478bd9Sstevel@tonic-gate 		hold = eptr;
1157c478bd9Sstevel@tonic-gate 		last->next = eptr->next;
1167c478bd9Sstevel@tonic-gate 		eptr = last;
1177c478bd9Sstevel@tonic-gate 		free(hold);
1187c478bd9Sstevel@tonic-gate 	    } else {
1197c478bd9Sstevel@tonic-gate 		/* this isn't it, just move along */
1207c478bd9Sstevel@tonic-gate 		last = eptr;
1217c478bd9Sstevel@tonic-gate 	    }
1227c478bd9Sstevel@tonic-gate 	}
1237c478bd9Sstevel@tonic-gate     }
1247c478bd9Sstevel@tonic-gate     return FALSE;
1257c478bd9Sstevel@tonic-gate }
1267c478bd9Sstevel@tonic-gate 
1277c478bd9Sstevel@tonic-gate /* insert a request & reply into the lookaside queue.  assumes it's not
1287c478bd9Sstevel@tonic-gate    already there, and can fail softly due to other weird errors. */
1297c478bd9Sstevel@tonic-gate 
1307c478bd9Sstevel@tonic-gate void
131*56a424ccSmp153739 kdc_insert_lookaside(krb5_data *inpkt, const krb5_fulladdr *from,
132*56a424ccSmp153739 		     krb5_data *outpkt)
1337c478bd9Sstevel@tonic-gate {
1347c478bd9Sstevel@tonic-gate     register krb5_kdc_replay_ent *eptr;
1357c478bd9Sstevel@tonic-gate     krb5_int32 timenow;
1367c478bd9Sstevel@tonic-gate     time_t db_age;
1377c478bd9Sstevel@tonic-gate 
1387c478bd9Sstevel@tonic-gate     if (krb5_timeofday(kdc_context, &timenow) ||
1397c478bd9Sstevel@tonic-gate 	krb5_db_get_age(kdc_context, 0, &db_age))
1407c478bd9Sstevel@tonic-gate 	return;
1417c478bd9Sstevel@tonic-gate 
1427c478bd9Sstevel@tonic-gate     /* this is a new entry */
1437c478bd9Sstevel@tonic-gate     eptr = (krb5_kdc_replay_ent *)calloc(1, sizeof(*eptr));
1447c478bd9Sstevel@tonic-gate     if (!eptr)
1457c478bd9Sstevel@tonic-gate 	return;
1467c478bd9Sstevel@tonic-gate     eptr->timein = timenow;
1477c478bd9Sstevel@tonic-gate     eptr->db_age = db_age;
1487c478bd9Sstevel@tonic-gate     /*
1497c478bd9Sstevel@tonic-gate      * This is going to hurt a lot malloc()-wise due to the need to
1507c478bd9Sstevel@tonic-gate      * allocate memory for the krb5_data and krb5_address elements.
1517c478bd9Sstevel@tonic-gate      * ARGH!
1527c478bd9Sstevel@tonic-gate      */
1537c478bd9Sstevel@tonic-gate     if (krb5_copy_data(kdc_context, inpkt, &eptr->req_packet)) {
1547c478bd9Sstevel@tonic-gate 	free(eptr);
1557c478bd9Sstevel@tonic-gate 	return;
1567c478bd9Sstevel@tonic-gate     }
1577c478bd9Sstevel@tonic-gate     if (krb5_copy_data(kdc_context, outpkt, &eptr->reply_packet)) {
1587c478bd9Sstevel@tonic-gate 	krb5_free_data(kdc_context, eptr->req_packet);
1597c478bd9Sstevel@tonic-gate 	free(eptr);
1607c478bd9Sstevel@tonic-gate 	return;
1617c478bd9Sstevel@tonic-gate     }
1627c478bd9Sstevel@tonic-gate     if (krb5_copy_addr(kdc_context, from->address, &eptr->addr)) {
1637c478bd9Sstevel@tonic-gate 	krb5_free_data(kdc_context, eptr->req_packet);
1647c478bd9Sstevel@tonic-gate 	krb5_free_data(kdc_context, eptr->reply_packet);
1657c478bd9Sstevel@tonic-gate 	free(eptr);
1667c478bd9Sstevel@tonic-gate 	return;
1677c478bd9Sstevel@tonic-gate     }
1687c478bd9Sstevel@tonic-gate     eptr->next = root_ptr.next;
1697c478bd9Sstevel@tonic-gate     root_ptr.next = eptr;
1707c478bd9Sstevel@tonic-gate     num_entries++;
1717c478bd9Sstevel@tonic-gate     return;
1727c478bd9Sstevel@tonic-gate }
1737c478bd9Sstevel@tonic-gate 
174*56a424ccSmp153739 /* frees memory associated with the lookaside queue for memory profiling */
175*56a424ccSmp153739 void
176*56a424ccSmp153739 kdc_free_lookaside(krb5_context kcontext)
177*56a424ccSmp153739 {
178*56a424ccSmp153739     register krb5_kdc_replay_ent *eptr, *last, *hold;
179*56a424ccSmp153739     if (root_ptr.next) {
180*56a424ccSmp153739         for (last = &root_ptr, eptr = root_ptr.next;
181*56a424ccSmp153739 	     eptr; eptr = eptr->next) {
182*56a424ccSmp153739 		krb5_free_data(kcontext, eptr->req_packet);
183*56a424ccSmp153739 		krb5_free_data(kcontext, eptr->reply_packet);
184*56a424ccSmp153739 		krb5_free_address(kcontext, eptr->addr);
185*56a424ccSmp153739 		hold = eptr;
186*56a424ccSmp153739 		last->next = eptr->next;
187*56a424ccSmp153739 		eptr = last;
188*56a424ccSmp153739 		free(hold);
189*56a424ccSmp153739 	}
190*56a424ccSmp153739     }
191*56a424ccSmp153739 }
192*56a424ccSmp153739 
1937c478bd9Sstevel@tonic-gate #endif /* NOCACHE */
194