1*0Sstevel@tonic-gate /* 2*0Sstevel@tonic-gate * CDDL HEADER START 3*0Sstevel@tonic-gate * 4*0Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5*0Sstevel@tonic-gate * Common Development and Distribution License, Version 1.0 only 6*0Sstevel@tonic-gate * (the "License"). You may not use this file except in compliance 7*0Sstevel@tonic-gate * with the License. 8*0Sstevel@tonic-gate * 9*0Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 10*0Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 11*0Sstevel@tonic-gate * See the License for the specific language governing permissions 12*0Sstevel@tonic-gate * and limitations under the License. 13*0Sstevel@tonic-gate * 14*0Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 15*0Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 16*0Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 17*0Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 18*0Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 19*0Sstevel@tonic-gate * 20*0Sstevel@tonic-gate * CDDL HEADER END 21*0Sstevel@tonic-gate */ 22*0Sstevel@tonic-gate /* 23*0Sstevel@tonic-gate * Copyright 2004 Sun Microsystems, Inc. All rights reserved. 24*0Sstevel@tonic-gate * Use is subject to license terms. 25*0Sstevel@tonic-gate */ 26*0Sstevel@tonic-gate 27*0Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 28*0Sstevel@tonic-gate 29*0Sstevel@tonic-gate #include <stdlib.h> 30*0Sstevel@tonic-gate #include <sys/types.h> 31*0Sstevel@tonic-gate #include <nss_dbdefs.h> 32*0Sstevel@tonic-gate #include <rpc/trace.h> 33*0Sstevel@tonic-gate #include <string.h> 34*0Sstevel@tonic-gate #include <bsm/libbsm.h> 35*0Sstevel@tonic-gate #include <secdb.h> 36*0Sstevel@tonic-gate 37*0Sstevel@tonic-gate 38*0Sstevel@tonic-gate /* externs from parse.c */ 39*0Sstevel@tonic-gate extern char *_strtok_escape(char *, char *, char **); 40*0Sstevel@tonic-gate 41*0Sstevel@tonic-gate static int auuser_stayopen; 42*0Sstevel@tonic-gate 43*0Sstevel@tonic-gate /* 44*0Sstevel@tonic-gate * Unsynchronized, but it affects only 45*0Sstevel@tonic-gate * efficiency, not correctness 46*0Sstevel@tonic-gate */ 47*0Sstevel@tonic-gate 48*0Sstevel@tonic-gate static DEFINE_NSS_DB_ROOT(db_root); 49*0Sstevel@tonic-gate static DEFINE_NSS_GETENT(context); 50*0Sstevel@tonic-gate 51*0Sstevel@tonic-gate 52*0Sstevel@tonic-gate void 53*0Sstevel@tonic-gate _nss_initf_auuser(nss_db_params_t *p) 54*0Sstevel@tonic-gate { 55*0Sstevel@tonic-gate trace1(TR__nss_initf_auuser, 0); 56*0Sstevel@tonic-gate p->name = NSS_DBNAM_AUDITUSER; 57*0Sstevel@tonic-gate p->config_name = NSS_DBNAM_PASSWD; /* use config for "passwd" */ 58*0Sstevel@tonic-gate p->default_config = NSS_DEFCONF_AUDITUSER; 59*0Sstevel@tonic-gate trace1(TR__nss_initf_auuser, 1); 60*0Sstevel@tonic-gate } 61*0Sstevel@tonic-gate 62*0Sstevel@tonic-gate 63*0Sstevel@tonic-gate /* 64*0Sstevel@tonic-gate * Return values: 0 = success, 1 = parse error, 2 = erange ... 65*0Sstevel@tonic-gate * The structure pointer passed in is a structure in the caller's space 66*0Sstevel@tonic-gate * wherein the field pointers would be set to areas in the buffer if 67*0Sstevel@tonic-gate * need be. instring and buffer should be separate areas. 68*0Sstevel@tonic-gate */ 69*0Sstevel@tonic-gate int 70*0Sstevel@tonic-gate str2auuser(const char *instr, int lenstr, void *ent, char *buffer, int buflen) 71*0Sstevel@tonic-gate { 72*0Sstevel@tonic-gate char *last = (char *)NULL; 73*0Sstevel@tonic-gate char *sep = KV_TOKEN_DELIMIT; 74*0Sstevel@tonic-gate au_user_str_t *au_user = (au_user_str_t *)ent; 75*0Sstevel@tonic-gate 76*0Sstevel@tonic-gate trace3(TR_str2auuser, 0, lenstr, buflen); 77*0Sstevel@tonic-gate if ((instr >= buffer && (buffer + buflen) > instr) || 78*0Sstevel@tonic-gate (buffer >= instr && (instr + lenstr) > buffer)) { 79*0Sstevel@tonic-gate trace3(TR_str2auuser, 1, lenstr, buflen); 80*0Sstevel@tonic-gate return (NSS_STR_PARSE_PARSE); 81*0Sstevel@tonic-gate } 82*0Sstevel@tonic-gate if (lenstr >= buflen) { 83*0Sstevel@tonic-gate trace3(TR_str2auuser, 1, lenstr, buflen); 84*0Sstevel@tonic-gate return (NSS_STR_PARSE_ERANGE); 85*0Sstevel@tonic-gate } 86*0Sstevel@tonic-gate strncpy(buffer, instr, buflen); 87*0Sstevel@tonic-gate /* 88*0Sstevel@tonic-gate * Remove newline that nis (yp_match) puts at the 89*0Sstevel@tonic-gate * end of the entry it retrieves from the map. 90*0Sstevel@tonic-gate */ 91*0Sstevel@tonic-gate if (buffer[lenstr] == '\n') { 92*0Sstevel@tonic-gate buffer[lenstr] = '\0'; 93*0Sstevel@tonic-gate } 94*0Sstevel@tonic-gate 95*0Sstevel@tonic-gate au_user->au_name = _strtok_escape(buffer, sep, &last); 96*0Sstevel@tonic-gate au_user->au_always = _strtok_escape(NULL, sep, &last); 97*0Sstevel@tonic-gate au_user->au_never = _strtok_escape(NULL, sep, &last); 98*0Sstevel@tonic-gate 99*0Sstevel@tonic-gate return (0); 100*0Sstevel@tonic-gate } 101*0Sstevel@tonic-gate 102*0Sstevel@tonic-gate 103*0Sstevel@tonic-gate void 104*0Sstevel@tonic-gate _setauuser(void) 105*0Sstevel@tonic-gate { 106*0Sstevel@tonic-gate trace1(TR_setauuser, 0); 107*0Sstevel@tonic-gate auuser_stayopen = 0; 108*0Sstevel@tonic-gate nss_setent(&db_root, _nss_initf_auuser, &context); 109*0Sstevel@tonic-gate trace1(TR_setauuser, 0); 110*0Sstevel@tonic-gate } 111*0Sstevel@tonic-gate 112*0Sstevel@tonic-gate 113*0Sstevel@tonic-gate int 114*0Sstevel@tonic-gate _endauuser(void) 115*0Sstevel@tonic-gate { 116*0Sstevel@tonic-gate trace1(TR_endauuser, 0); 117*0Sstevel@tonic-gate auuser_stayopen = 0; 118*0Sstevel@tonic-gate nss_endent(&db_root, _nss_initf_auuser, &context); 119*0Sstevel@tonic-gate nss_delete(&db_root); 120*0Sstevel@tonic-gate trace1(TR_endauuser, 0); 121*0Sstevel@tonic-gate return (0); 122*0Sstevel@tonic-gate } 123*0Sstevel@tonic-gate 124*0Sstevel@tonic-gate 125*0Sstevel@tonic-gate au_user_str_t * 126*0Sstevel@tonic-gate _getauuserent(au_user_str_t *result, char *buffer, int buflen, int *h_errnop) 127*0Sstevel@tonic-gate { 128*0Sstevel@tonic-gate nss_XbyY_args_t arg; 129*0Sstevel@tonic-gate nss_status_t res; 130*0Sstevel@tonic-gate 131*0Sstevel@tonic-gate trace2(TR_getauuser, 0, buflen); 132*0Sstevel@tonic-gate NSS_XbyY_INIT(&arg, result, buffer, buflen, str2auuser); 133*0Sstevel@tonic-gate res = nss_getent(&db_root, _nss_initf_auuser, &context, &arg); 134*0Sstevel@tonic-gate arg.status = res; 135*0Sstevel@tonic-gate *h_errnop = arg.h_errno; 136*0Sstevel@tonic-gate trace2(TR_getauuser, 1, buflen); 137*0Sstevel@tonic-gate return ((au_user_str_t *)NSS_XbyY_FINI(&arg)); 138*0Sstevel@tonic-gate } 139*0Sstevel@tonic-gate 140*0Sstevel@tonic-gate 141*0Sstevel@tonic-gate au_user_str_t * 142*0Sstevel@tonic-gate _getauusernam(const char *name, au_user_str_t *result, char *buffer, 143*0Sstevel@tonic-gate int buflen, int *errnop) 144*0Sstevel@tonic-gate { 145*0Sstevel@tonic-gate nss_XbyY_args_t arg; 146*0Sstevel@tonic-gate nss_status_t res; 147*0Sstevel@tonic-gate 148*0Sstevel@tonic-gate trace2(TR_getauusernam, 0, buflen); 149*0Sstevel@tonic-gate if (result == NULL) { 150*0Sstevel@tonic-gate *errnop = AUDITUSER_PARSE_ERANGE; 151*0Sstevel@tonic-gate return (NULL); 152*0Sstevel@tonic-gate } 153*0Sstevel@tonic-gate NSS_XbyY_INIT(&arg, result, buffer, buflen, str2auuser); 154*0Sstevel@tonic-gate arg.key.name = name; 155*0Sstevel@tonic-gate arg.stayopen = auuser_stayopen; 156*0Sstevel@tonic-gate arg.h_errno = AUDITUSER_NOT_FOUND; 157*0Sstevel@tonic-gate res = nss_search(&db_root, _nss_initf_auuser, 158*0Sstevel@tonic-gate NSS_DBOP_AUDITUSER_BYNAME, &arg); 159*0Sstevel@tonic-gate arg.status = res; 160*0Sstevel@tonic-gate *errnop = arg.h_errno; 161*0Sstevel@tonic-gate trace2(TR_getauusernam, 1, buflen); 162*0Sstevel@tonic-gate return ((au_user_str_t *)NSS_XbyY_FINI(&arg)); 163*0Sstevel@tonic-gate } 164