xref: /OK3568_Linux_fs/kernel/net/sunrpc/auth_unix.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * linux/net/sunrpc/auth_unix.c
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * UNIX-style authentication; no AUTH_SHORT support
6*4882a593Smuzhiyun  *
7*4882a593Smuzhiyun  * Copyright (C) 1996, Olaf Kirch <okir@monad.swb.de>
8*4882a593Smuzhiyun  */
9*4882a593Smuzhiyun 
10*4882a593Smuzhiyun #include <linux/slab.h>
11*4882a593Smuzhiyun #include <linux/types.h>
12*4882a593Smuzhiyun #include <linux/sched.h>
13*4882a593Smuzhiyun #include <linux/module.h>
14*4882a593Smuzhiyun #include <linux/mempool.h>
15*4882a593Smuzhiyun #include <linux/sunrpc/clnt.h>
16*4882a593Smuzhiyun #include <linux/sunrpc/auth.h>
17*4882a593Smuzhiyun #include <linux/user_namespace.h>
18*4882a593Smuzhiyun 
19*4882a593Smuzhiyun 
20*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_SUNRPC_DEBUG)
21*4882a593Smuzhiyun # define RPCDBG_FACILITY	RPCDBG_AUTH
22*4882a593Smuzhiyun #endif
23*4882a593Smuzhiyun 
24*4882a593Smuzhiyun static struct rpc_auth		unix_auth;
25*4882a593Smuzhiyun static const struct rpc_credops	unix_credops;
26*4882a593Smuzhiyun static mempool_t		*unix_pool;
27*4882a593Smuzhiyun 
28*4882a593Smuzhiyun static struct rpc_auth *
unx_create(const struct rpc_auth_create_args * args,struct rpc_clnt * clnt)29*4882a593Smuzhiyun unx_create(const struct rpc_auth_create_args *args, struct rpc_clnt *clnt)
30*4882a593Smuzhiyun {
31*4882a593Smuzhiyun 	refcount_inc(&unix_auth.au_count);
32*4882a593Smuzhiyun 	return &unix_auth;
33*4882a593Smuzhiyun }
34*4882a593Smuzhiyun 
35*4882a593Smuzhiyun static void
unx_destroy(struct rpc_auth * auth)36*4882a593Smuzhiyun unx_destroy(struct rpc_auth *auth)
37*4882a593Smuzhiyun {
38*4882a593Smuzhiyun }
39*4882a593Smuzhiyun 
40*4882a593Smuzhiyun /*
41*4882a593Smuzhiyun  * Lookup AUTH_UNIX creds for current process
42*4882a593Smuzhiyun  */
43*4882a593Smuzhiyun static struct rpc_cred *
unx_lookup_cred(struct rpc_auth * auth,struct auth_cred * acred,int flags)44*4882a593Smuzhiyun unx_lookup_cred(struct rpc_auth *auth, struct auth_cred *acred, int flags)
45*4882a593Smuzhiyun {
46*4882a593Smuzhiyun 	struct rpc_cred *ret = mempool_alloc(unix_pool, GFP_NOFS);
47*4882a593Smuzhiyun 
48*4882a593Smuzhiyun 	rpcauth_init_cred(ret, acred, auth, &unix_credops);
49*4882a593Smuzhiyun 	ret->cr_flags = 1UL << RPCAUTH_CRED_UPTODATE;
50*4882a593Smuzhiyun 	return ret;
51*4882a593Smuzhiyun }
52*4882a593Smuzhiyun 
53*4882a593Smuzhiyun static void
unx_free_cred_callback(struct rcu_head * head)54*4882a593Smuzhiyun unx_free_cred_callback(struct rcu_head *head)
55*4882a593Smuzhiyun {
56*4882a593Smuzhiyun 	struct rpc_cred *rpc_cred = container_of(head, struct rpc_cred, cr_rcu);
57*4882a593Smuzhiyun 
58*4882a593Smuzhiyun 	put_cred(rpc_cred->cr_cred);
59*4882a593Smuzhiyun 	mempool_free(rpc_cred, unix_pool);
60*4882a593Smuzhiyun }
61*4882a593Smuzhiyun 
62*4882a593Smuzhiyun static void
unx_destroy_cred(struct rpc_cred * cred)63*4882a593Smuzhiyun unx_destroy_cred(struct rpc_cred *cred)
64*4882a593Smuzhiyun {
65*4882a593Smuzhiyun 	call_rcu(&cred->cr_rcu, unx_free_cred_callback);
66*4882a593Smuzhiyun }
67*4882a593Smuzhiyun 
68*4882a593Smuzhiyun /*
69*4882a593Smuzhiyun  * Match credentials against current the auth_cred.
70*4882a593Smuzhiyun  */
71*4882a593Smuzhiyun static int
unx_match(struct auth_cred * acred,struct rpc_cred * cred,int flags)72*4882a593Smuzhiyun unx_match(struct auth_cred *acred, struct rpc_cred *cred, int flags)
73*4882a593Smuzhiyun {
74*4882a593Smuzhiyun 	unsigned int groups = 0;
75*4882a593Smuzhiyun 	unsigned int i;
76*4882a593Smuzhiyun 
77*4882a593Smuzhiyun 	if (cred->cr_cred == acred->cred)
78*4882a593Smuzhiyun 		return 1;
79*4882a593Smuzhiyun 
80*4882a593Smuzhiyun 	if (!uid_eq(cred->cr_cred->fsuid, acred->cred->fsuid) || !gid_eq(cred->cr_cred->fsgid, acred->cred->fsgid))
81*4882a593Smuzhiyun 		return 0;
82*4882a593Smuzhiyun 
83*4882a593Smuzhiyun 	if (acred->cred->group_info != NULL)
84*4882a593Smuzhiyun 		groups = acred->cred->group_info->ngroups;
85*4882a593Smuzhiyun 	if (groups > UNX_NGROUPS)
86*4882a593Smuzhiyun 		groups = UNX_NGROUPS;
87*4882a593Smuzhiyun 	if (cred->cr_cred->group_info == NULL)
88*4882a593Smuzhiyun 		return groups == 0;
89*4882a593Smuzhiyun 	if (groups != cred->cr_cred->group_info->ngroups)
90*4882a593Smuzhiyun 		return 0;
91*4882a593Smuzhiyun 
92*4882a593Smuzhiyun 	for (i = 0; i < groups ; i++)
93*4882a593Smuzhiyun 		if (!gid_eq(cred->cr_cred->group_info->gid[i], acred->cred->group_info->gid[i]))
94*4882a593Smuzhiyun 			return 0;
95*4882a593Smuzhiyun 	return 1;
96*4882a593Smuzhiyun }
97*4882a593Smuzhiyun 
98*4882a593Smuzhiyun /*
99*4882a593Smuzhiyun  * Marshal credentials.
100*4882a593Smuzhiyun  * Maybe we should keep a cached credential for performance reasons.
101*4882a593Smuzhiyun  */
102*4882a593Smuzhiyun static int
unx_marshal(struct rpc_task * task,struct xdr_stream * xdr)103*4882a593Smuzhiyun unx_marshal(struct rpc_task *task, struct xdr_stream *xdr)
104*4882a593Smuzhiyun {
105*4882a593Smuzhiyun 	struct rpc_clnt	*clnt = task->tk_client;
106*4882a593Smuzhiyun 	struct rpc_cred	*cred = task->tk_rqstp->rq_cred;
107*4882a593Smuzhiyun 	__be32		*p, *cred_len, *gidarr_len;
108*4882a593Smuzhiyun 	int		i;
109*4882a593Smuzhiyun 	struct group_info *gi = cred->cr_cred->group_info;
110*4882a593Smuzhiyun 	struct user_namespace *userns = clnt->cl_cred ?
111*4882a593Smuzhiyun 		clnt->cl_cred->user_ns : &init_user_ns;
112*4882a593Smuzhiyun 
113*4882a593Smuzhiyun 	/* Credential */
114*4882a593Smuzhiyun 
115*4882a593Smuzhiyun 	p = xdr_reserve_space(xdr, 3 * sizeof(*p));
116*4882a593Smuzhiyun 	if (!p)
117*4882a593Smuzhiyun 		goto marshal_failed;
118*4882a593Smuzhiyun 	*p++ = rpc_auth_unix;
119*4882a593Smuzhiyun 	cred_len = p++;
120*4882a593Smuzhiyun 	*p++ = xdr_zero;	/* stamp */
121*4882a593Smuzhiyun 	if (xdr_stream_encode_opaque(xdr, clnt->cl_nodename,
122*4882a593Smuzhiyun 				     clnt->cl_nodelen) < 0)
123*4882a593Smuzhiyun 		goto marshal_failed;
124*4882a593Smuzhiyun 	p = xdr_reserve_space(xdr, 3 * sizeof(*p));
125*4882a593Smuzhiyun 	if (!p)
126*4882a593Smuzhiyun 		goto marshal_failed;
127*4882a593Smuzhiyun 	*p++ = cpu_to_be32(from_kuid_munged(userns, cred->cr_cred->fsuid));
128*4882a593Smuzhiyun 	*p++ = cpu_to_be32(from_kgid_munged(userns, cred->cr_cred->fsgid));
129*4882a593Smuzhiyun 
130*4882a593Smuzhiyun 	gidarr_len = p++;
131*4882a593Smuzhiyun 	if (gi)
132*4882a593Smuzhiyun 		for (i = 0; i < UNX_NGROUPS && i < gi->ngroups; i++)
133*4882a593Smuzhiyun 			*p++ = cpu_to_be32(from_kgid_munged(userns, gi->gid[i]));
134*4882a593Smuzhiyun 	*gidarr_len = cpu_to_be32(p - gidarr_len - 1);
135*4882a593Smuzhiyun 	*cred_len = cpu_to_be32((p - cred_len - 1) << 2);
136*4882a593Smuzhiyun 	p = xdr_reserve_space(xdr, (p - gidarr_len - 1) << 2);
137*4882a593Smuzhiyun 	if (!p)
138*4882a593Smuzhiyun 		goto marshal_failed;
139*4882a593Smuzhiyun 
140*4882a593Smuzhiyun 	/* Verifier */
141*4882a593Smuzhiyun 
142*4882a593Smuzhiyun 	p = xdr_reserve_space(xdr, 2 * sizeof(*p));
143*4882a593Smuzhiyun 	if (!p)
144*4882a593Smuzhiyun 		goto marshal_failed;
145*4882a593Smuzhiyun 	*p++ = rpc_auth_null;
146*4882a593Smuzhiyun 	*p   = xdr_zero;
147*4882a593Smuzhiyun 
148*4882a593Smuzhiyun 	return 0;
149*4882a593Smuzhiyun 
150*4882a593Smuzhiyun marshal_failed:
151*4882a593Smuzhiyun 	return -EMSGSIZE;
152*4882a593Smuzhiyun }
153*4882a593Smuzhiyun 
154*4882a593Smuzhiyun /*
155*4882a593Smuzhiyun  * Refresh credentials. This is a no-op for AUTH_UNIX
156*4882a593Smuzhiyun  */
157*4882a593Smuzhiyun static int
unx_refresh(struct rpc_task * task)158*4882a593Smuzhiyun unx_refresh(struct rpc_task *task)
159*4882a593Smuzhiyun {
160*4882a593Smuzhiyun 	set_bit(RPCAUTH_CRED_UPTODATE, &task->tk_rqstp->rq_cred->cr_flags);
161*4882a593Smuzhiyun 	return 0;
162*4882a593Smuzhiyun }
163*4882a593Smuzhiyun 
164*4882a593Smuzhiyun static int
unx_validate(struct rpc_task * task,struct xdr_stream * xdr)165*4882a593Smuzhiyun unx_validate(struct rpc_task *task, struct xdr_stream *xdr)
166*4882a593Smuzhiyun {
167*4882a593Smuzhiyun 	struct rpc_auth *auth = task->tk_rqstp->rq_cred->cr_auth;
168*4882a593Smuzhiyun 	__be32 *p;
169*4882a593Smuzhiyun 	u32 size;
170*4882a593Smuzhiyun 
171*4882a593Smuzhiyun 	p = xdr_inline_decode(xdr, 2 * sizeof(*p));
172*4882a593Smuzhiyun 	if (!p)
173*4882a593Smuzhiyun 		return -EIO;
174*4882a593Smuzhiyun 	switch (*p++) {
175*4882a593Smuzhiyun 	case rpc_auth_null:
176*4882a593Smuzhiyun 	case rpc_auth_unix:
177*4882a593Smuzhiyun 	case rpc_auth_short:
178*4882a593Smuzhiyun 		break;
179*4882a593Smuzhiyun 	default:
180*4882a593Smuzhiyun 		return -EIO;
181*4882a593Smuzhiyun 	}
182*4882a593Smuzhiyun 	size = be32_to_cpup(p);
183*4882a593Smuzhiyun 	if (size > RPC_MAX_AUTH_SIZE)
184*4882a593Smuzhiyun 		return -EIO;
185*4882a593Smuzhiyun 	p = xdr_inline_decode(xdr, size);
186*4882a593Smuzhiyun 	if (!p)
187*4882a593Smuzhiyun 		return -EIO;
188*4882a593Smuzhiyun 
189*4882a593Smuzhiyun 	auth->au_verfsize = XDR_QUADLEN(size) + 2;
190*4882a593Smuzhiyun 	auth->au_rslack = XDR_QUADLEN(size) + 2;
191*4882a593Smuzhiyun 	auth->au_ralign = XDR_QUADLEN(size) + 2;
192*4882a593Smuzhiyun 	return 0;
193*4882a593Smuzhiyun }
194*4882a593Smuzhiyun 
rpc_init_authunix(void)195*4882a593Smuzhiyun int __init rpc_init_authunix(void)
196*4882a593Smuzhiyun {
197*4882a593Smuzhiyun 	unix_pool = mempool_create_kmalloc_pool(16, sizeof(struct rpc_cred));
198*4882a593Smuzhiyun 	return unix_pool ? 0 : -ENOMEM;
199*4882a593Smuzhiyun }
200*4882a593Smuzhiyun 
rpc_destroy_authunix(void)201*4882a593Smuzhiyun void rpc_destroy_authunix(void)
202*4882a593Smuzhiyun {
203*4882a593Smuzhiyun 	mempool_destroy(unix_pool);
204*4882a593Smuzhiyun }
205*4882a593Smuzhiyun 
206*4882a593Smuzhiyun const struct rpc_authops authunix_ops = {
207*4882a593Smuzhiyun 	.owner		= THIS_MODULE,
208*4882a593Smuzhiyun 	.au_flavor	= RPC_AUTH_UNIX,
209*4882a593Smuzhiyun 	.au_name	= "UNIX",
210*4882a593Smuzhiyun 	.create		= unx_create,
211*4882a593Smuzhiyun 	.destroy	= unx_destroy,
212*4882a593Smuzhiyun 	.lookup_cred	= unx_lookup_cred,
213*4882a593Smuzhiyun };
214*4882a593Smuzhiyun 
215*4882a593Smuzhiyun static
216*4882a593Smuzhiyun struct rpc_auth		unix_auth = {
217*4882a593Smuzhiyun 	.au_cslack	= UNX_CALLSLACK,
218*4882a593Smuzhiyun 	.au_rslack	= NUL_REPLYSLACK,
219*4882a593Smuzhiyun 	.au_verfsize	= NUL_REPLYSLACK,
220*4882a593Smuzhiyun 	.au_ops		= &authunix_ops,
221*4882a593Smuzhiyun 	.au_flavor	= RPC_AUTH_UNIX,
222*4882a593Smuzhiyun 	.au_count	= REFCOUNT_INIT(1),
223*4882a593Smuzhiyun };
224*4882a593Smuzhiyun 
225*4882a593Smuzhiyun static
226*4882a593Smuzhiyun const struct rpc_credops unix_credops = {
227*4882a593Smuzhiyun 	.cr_name	= "AUTH_UNIX",
228*4882a593Smuzhiyun 	.crdestroy	= unx_destroy_cred,
229*4882a593Smuzhiyun 	.crmatch	= unx_match,
230*4882a593Smuzhiyun 	.crmarshal	= unx_marshal,
231*4882a593Smuzhiyun 	.crwrap_req	= rpcauth_wrap_req_encode,
232*4882a593Smuzhiyun 	.crrefresh	= unx_refresh,
233*4882a593Smuzhiyun 	.crvalidate	= unx_validate,
234*4882a593Smuzhiyun 	.crunwrap_resp	= rpcauth_unwrap_resp_decode,
235*4882a593Smuzhiyun };
236