<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/> <meta http-equiv="X-UA-Compatible" content="IE=9"/> <meta name="generator" content="Doxygen 1.8.8"/> <title>pcsc-lite: auth.c Source File</title> <link href="tabs.css" rel="stylesheet" type="text/css"/> <script type="text/javascript" src="jquery.js"></script> <script type="text/javascript" src="dynsections.js"></script> <link href="doxygen.css" rel="stylesheet" type="text/css" /> </head> <body> <div id="top"><!-- do not remove this div, it is closed by doxygen! --> <div id="titlearea"> <table cellspacing="0" cellpadding="0"> <tbody> <tr style="height: 56px;"> <td style="padding-left: 0.5em;"> <div id="projectname">pcsc-lite  <span id="projectnumber">1.8.11</span> </div> </td> </tr> </tbody> </table> </div> <!-- end header part --> <!-- Generated by Doxygen 1.8.8 --> <div id="navrow1" class="tabs"> <ul class="tablist"> <li><a href="index.html"><span>Main Page</span></a></li> <li><a href="modules.html"><span>Modules</span></a></li> <li><a href="annotated.html"><span>Data Structures</span></a></li> <li class="current"><a href="files.html"><span>Files</span></a></li> </ul> </div> <div id="navrow2" class="tabs2"> <ul class="tablist"> <li><a href="files.html"><span>File List</span></a></li> <li><a href="globals.html"><span>Globals</span></a></li> </ul> </div> <div id="nav-path" class="navpath"> <ul> <li class="navelem"><a class="el" href="dir_68267d1309a1af8e8297ef4c3efbcdba.html">src</a></li> </ul> </div> </div><!-- top --> <div class="header"> <div class="headertitle"> <div class="title">auth.c</div> </div> </div><!--header--> <div class="contents"> <a href="auth_8c.html">Go to the documentation of this file.</a><div class="fragment"><div class="line"><a name="l00001"></a><span class="lineno"> 1</span> <span class="comment">/*</span></div> <div class="line"><a name="l00002"></a><span class="lineno"> 2</span> <span class="comment"> * MUSCLE SmartCard Development ( http://pcsclite.alioth.debian.org/pcsclite.html )</span></div> <div class="line"><a name="l00003"></a><span class="lineno"> 3</span> <span class="comment"> *</span></div> <div class="line"><a name="l00004"></a><span class="lineno"> 4</span> <span class="comment"> * Copyright (C) 2013 Red Hat</span></div> <div class="line"><a name="l00005"></a><span class="lineno"> 5</span> <span class="comment"> *</span></div> <div class="line"><a name="l00006"></a><span class="lineno"> 6</span> <span class="comment"> * All rights reserved.</span></div> <div class="line"><a name="l00007"></a><span class="lineno"> 7</span> <span class="comment"> * Redistribution and use in source and binary forms, with or without</span></div> <div class="line"><a name="l00008"></a><span class="lineno"> 8</span> <span class="comment"> * modification, are permitted provided that the following conditions</span></div> <div class="line"><a name="l00009"></a><span class="lineno"> 9</span> <span class="comment"> * are met:</span></div> <div class="line"><a name="l00010"></a><span class="lineno"> 10</span> <span class="comment"> *</span></div> <div class="line"><a name="l00011"></a><span class="lineno"> 11</span> <span class="comment"> * 1. Redistributions of source code must retain the above copyright</span></div> <div class="line"><a name="l00012"></a><span class="lineno"> 12</span> <span class="comment"> * notice, this list of conditions and the following disclaimer.</span></div> <div class="line"><a name="l00013"></a><span class="lineno"> 13</span> <span class="comment"> *</span></div> <div class="line"><a name="l00014"></a><span class="lineno"> 14</span> <span class="comment"> * 2. Redistributions in binary form must reproduce the above copyright</span></div> <div class="line"><a name="l00015"></a><span class="lineno"> 15</span> <span class="comment"> * notice, this list of conditions and the following disclaimer in the</span></div> <div class="line"><a name="l00016"></a><span class="lineno"> 16</span> <span class="comment"> * documentation and/or other materials provided with the distribution.</span></div> <div class="line"><a name="l00017"></a><span class="lineno"> 17</span> <span class="comment"> *</span></div> <div class="line"><a name="l00018"></a><span class="lineno"> 18</span> <span class="comment"> * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS</span></div> <div class="line"><a name="l00019"></a><span class="lineno"> 19</span> <span class="comment"> * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT</span></div> <div class="line"><a name="l00020"></a><span class="lineno"> 20</span> <span class="comment"> * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS</span></div> <div class="line"><a name="l00021"></a><span class="lineno"> 21</span> <span class="comment"> * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE</span></div> <div class="line"><a name="l00022"></a><span class="lineno"> 22</span> <span class="comment"> * COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,</span></div> <div class="line"><a name="l00023"></a><span class="lineno"> 23</span> <span class="comment"> * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,</span></div> <div class="line"><a name="l00024"></a><span class="lineno"> 24</span> <span class="comment"> * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS</span></div> <div class="line"><a name="l00025"></a><span class="lineno"> 25</span> <span class="comment"> * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED</span></div> <div class="line"><a name="l00026"></a><span class="lineno"> 26</span> <span class="comment"> * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,</span></div> <div class="line"><a name="l00027"></a><span class="lineno"> 27</span> <span class="comment"> * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF</span></div> <div class="line"><a name="l00028"></a><span class="lineno"> 28</span> <span class="comment"> * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH</span></div> <div class="line"><a name="l00029"></a><span class="lineno"> 29</span> <span class="comment"> * DAMAGE.</span></div> <div class="line"><a name="l00030"></a><span class="lineno"> 30</span> <span class="comment"> *</span></div> <div class="line"><a name="l00031"></a><span class="lineno"> 31</span> <span class="comment"> * Author: Nikos Mavrogiannopoulos <nmav@redhat.com></span></div> <div class="line"><a name="l00032"></a><span class="lineno"> 32</span> <span class="comment"> */</span></div> <div class="line"><a name="l00033"></a><span class="lineno"> 33</span> </div> <div class="line"><a name="l00042"></a><span class="lineno"> 42</span> <span class="preprocessor">#include "config.h"</span></div> <div class="line"><a name="l00043"></a><span class="lineno"> 43</span> <span class="preprocessor">#define _GNU_SOURCE</span></div> <div class="line"><a name="l00044"></a><span class="lineno"> 44</span> <span class="preprocessor">#include <sys/types.h></span></div> <div class="line"><a name="l00045"></a><span class="lineno"> 45</span> <span class="preprocessor">#include <sys/socket.h></span></div> <div class="line"><a name="l00046"></a><span class="lineno"> 46</span> <span class="preprocessor">#include <sys/ioctl.h></span></div> <div class="line"><a name="l00047"></a><span class="lineno"> 47</span> <span class="preprocessor">#include <sys/un.h></span></div> <div class="line"><a name="l00048"></a><span class="lineno"> 48</span> <span class="preprocessor">#include <stdio.h></span></div> <div class="line"><a name="l00049"></a><span class="lineno"> 49</span> <span class="preprocessor">#include "<a class="code" href="debuglog_8h.html">debuglog.h</a>"</span></div> <div class="line"><a name="l00050"></a><span class="lineno"> 50</span> </div> <div class="line"><a name="l00051"></a><span class="lineno"> 51</span> <span class="preprocessor">#include <errno.h></span></div> <div class="line"><a name="l00052"></a><span class="lineno"> 52</span> </div> <div class="line"><a name="l00053"></a><span class="lineno"> 53</span> <span class="preprocessor">#if defined(HAVE_POLKIT) && defined(SO_PEERCRED)</span></div> <div class="line"><a name="l00054"></a><span class="lineno"> 54</span> </div> <div class="line"><a name="l00055"></a><span class="lineno"> 55</span> <span class="preprocessor">#include <polkit/polkit.h></span></div> <div class="line"><a name="l00056"></a><span class="lineno"> 56</span> </div> <div class="line"><a name="l00057"></a><span class="lineno"> 57</span> <span class="comment">/* Returns non zero when the client is authorized */</span></div> <div class="line"><a name="l00058"></a><span class="lineno"> 58</span> <span class="keywordtype">unsigned</span> IsClientAuthorized(<span class="keywordtype">int</span> socket, <span class="keyword">const</span> <span class="keywordtype">char</span>* action, <span class="keyword">const</span> <span class="keywordtype">char</span>* reader)</div> <div class="line"><a name="l00059"></a><span class="lineno"> 59</span> {</div> <div class="line"><a name="l00060"></a><span class="lineno"> 60</span>  <span class="keyword">struct </span>ucred cr;</div> <div class="line"><a name="l00061"></a><span class="lineno"> 61</span>  socklen_t cr_len;</div> <div class="line"><a name="l00062"></a><span class="lineno"> 62</span>  <span class="keywordtype">int</span> ret;</div> <div class="line"><a name="l00063"></a><span class="lineno"> 63</span>  PolkitSubject *subject;</div> <div class="line"><a name="l00064"></a><span class="lineno"> 64</span>  PolkitAuthority *authority;</div> <div class="line"><a name="l00065"></a><span class="lineno"> 65</span>  PolkitAuthorizationResult *result;</div> <div class="line"><a name="l00066"></a><span class="lineno"> 66</span>  PolkitDetails *details;</div> <div class="line"><a name="l00067"></a><span class="lineno"> 67</span>  GError *error = NULL;</div> <div class="line"><a name="l00068"></a><span class="lineno"> 68</span>  <span class="keywordtype">char</span> action_name[128];</div> <div class="line"><a name="l00069"></a><span class="lineno"> 69</span> </div> <div class="line"><a name="l00070"></a><span class="lineno"> 70</span>  snprintf(action_name, <span class="keyword">sizeof</span>(action_name), <span class="stringliteral">"org.debian.pcsc-lite.%s"</span>, action);</div> <div class="line"><a name="l00071"></a><span class="lineno"> 71</span> </div> <div class="line"><a name="l00072"></a><span class="lineno"> 72</span>  cr_len = <span class="keyword">sizeof</span>(cr);</div> <div class="line"><a name="l00073"></a><span class="lineno"> 73</span>  ret = getsockopt(socket, SOL_SOCKET, SO_PEERCRED, &cr, &cr_len);</div> <div class="line"><a name="l00074"></a><span class="lineno"> 74</span>  <span class="keywordflow">if</span> (ret == -1)</div> <div class="line"><a name="l00075"></a><span class="lineno"> 75</span>  {</div> <div class="line"><a name="l00076"></a><span class="lineno"> 76</span>  <span class="keywordtype">int</span> e = errno;</div> <div class="line"><a name="l00077"></a><span class="lineno"> 77</span>  Log2(PCSC_LOG_CRITICAL,</div> <div class="line"><a name="l00078"></a><span class="lineno"> 78</span>  <span class="stringliteral">"Error obtaining client process credentials: %s"</span>, strerror(e));</div> <div class="line"><a name="l00079"></a><span class="lineno"> 79</span>  <span class="keywordflow">return</span> 0;</div> <div class="line"><a name="l00080"></a><span class="lineno"> 80</span>  }</div> <div class="line"><a name="l00081"></a><span class="lineno"> 81</span> </div> <div class="line"><a name="l00082"></a><span class="lineno"> 82</span>  authority = polkit_authority_get_sync(NULL, NULL);</div> <div class="line"><a name="l00083"></a><span class="lineno"> 83</span>  <span class="keywordflow">if</span> (authority == NULL)</div> <div class="line"><a name="l00084"></a><span class="lineno"> 84</span>  {</div> <div class="line"><a name="l00085"></a><span class="lineno"> 85</span>  Log1(PCSC_LOG_CRITICAL, <span class="stringliteral">"polkit_authority_get_sync failed"</span>);</div> <div class="line"><a name="l00086"></a><span class="lineno"> 86</span>  <span class="keywordflow">return</span> 0;</div> <div class="line"><a name="l00087"></a><span class="lineno"> 87</span>  }</div> <div class="line"><a name="l00088"></a><span class="lineno"> 88</span> </div> <div class="line"><a name="l00089"></a><span class="lineno"> 89</span>  subject = polkit_unix_process_new_for_owner(cr.pid, 0, cr.uid);</div> <div class="line"><a name="l00090"></a><span class="lineno"> 90</span>  <span class="keywordflow">if</span> (subject == NULL)</div> <div class="line"><a name="l00091"></a><span class="lineno"> 91</span>  {</div> <div class="line"><a name="l00092"></a><span class="lineno"> 92</span>  Log1(PCSC_LOG_CRITICAL, <span class="stringliteral">"polkit_unix_process_new_for_owner failed"</span>);</div> <div class="line"><a name="l00093"></a><span class="lineno"> 93</span>  ret = 0;</div> <div class="line"><a name="l00094"></a><span class="lineno"> 94</span>  <span class="keywordflow">goto</span> cleanup1;</div> <div class="line"><a name="l00095"></a><span class="lineno"> 95</span>  }</div> <div class="line"><a name="l00096"></a><span class="lineno"> 96</span> </div> <div class="line"><a name="l00097"></a><span class="lineno"> 97</span>  details = polkit_details_new();</div> <div class="line"><a name="l00098"></a><span class="lineno"> 98</span>  <span class="keywordflow">if</span> (details == NULL)</div> <div class="line"><a name="l00099"></a><span class="lineno"> 99</span>  {</div> <div class="line"><a name="l00100"></a><span class="lineno"> 100</span>  Log1(PCSC_LOG_CRITICAL, <span class="stringliteral">"polkit_details_new failed"</span>);</div> <div class="line"><a name="l00101"></a><span class="lineno"> 101</span>  ret = 0;</div> <div class="line"><a name="l00102"></a><span class="lineno"> 102</span>  <span class="keywordflow">goto</span> cleanup0;</div> <div class="line"><a name="l00103"></a><span class="lineno"> 103</span>  }</div> <div class="line"><a name="l00104"></a><span class="lineno"> 104</span> </div> <div class="line"><a name="l00105"></a><span class="lineno"> 105</span>  <span class="keywordflow">if</span> (reader != NULL)</div> <div class="line"><a name="l00106"></a><span class="lineno"> 106</span>  polkit_details_insert(details, <span class="stringliteral">"reader"</span>, reader);</div> <div class="line"><a name="l00107"></a><span class="lineno"> 107</span> </div> <div class="line"><a name="l00108"></a><span class="lineno"> 108</span>  result = polkit_authority_check_authorization_sync(authority, subject,</div> <div class="line"><a name="l00109"></a><span class="lineno"> 109</span>  action_name, details,</div> <div class="line"><a name="l00110"></a><span class="lineno"> 110</span>  POLKIT_CHECK_AUTHORIZATION_FLAGS_NONE,</div> <div class="line"><a name="l00111"></a><span class="lineno"> 111</span>  NULL,</div> <div class="line"><a name="l00112"></a><span class="lineno"> 112</span>  &error);</div> <div class="line"><a name="l00113"></a><span class="lineno"> 113</span> </div> <div class="line"><a name="l00114"></a><span class="lineno"> 114</span>  <span class="keywordflow">if</span> (result == NULL)</div> <div class="line"><a name="l00115"></a><span class="lineno"> 115</span>  {</div> <div class="line"><a name="l00116"></a><span class="lineno"> 116</span>  Log2(PCSC_LOG_CRITICAL, <span class="stringliteral">"Error in authorization: %s"</span>, error->message);</div> <div class="line"><a name="l00117"></a><span class="lineno"> 117</span>  g_error_free(error);</div> <div class="line"><a name="l00118"></a><span class="lineno"> 118</span>  ret = 0;</div> <div class="line"><a name="l00119"></a><span class="lineno"> 119</span>  }</div> <div class="line"><a name="l00120"></a><span class="lineno"> 120</span>  <span class="keywordflow">else</span></div> <div class="line"><a name="l00121"></a><span class="lineno"> 121</span>  {</div> <div class="line"><a name="l00122"></a><span class="lineno"> 122</span>  <span class="keywordflow">if</span> (polkit_authorization_result_get_is_authorized(result))</div> <div class="line"><a name="l00123"></a><span class="lineno"> 123</span>  {</div> <div class="line"><a name="l00124"></a><span class="lineno"> 124</span>  ret = 1;</div> <div class="line"><a name="l00125"></a><span class="lineno"> 125</span>  }</div> <div class="line"><a name="l00126"></a><span class="lineno"> 126</span>  <span class="keywordflow">else</span></div> <div class="line"><a name="l00127"></a><span class="lineno"> 127</span>  {</div> <div class="line"><a name="l00128"></a><span class="lineno"> 128</span>  ret = 0;</div> <div class="line"><a name="l00129"></a><span class="lineno"> 129</span>  }</div> <div class="line"><a name="l00130"></a><span class="lineno"> 130</span>  }</div> <div class="line"><a name="l00131"></a><span class="lineno"> 131</span> </div> <div class="line"><a name="l00132"></a><span class="lineno"> 132</span>  <span class="keywordflow">if</span> (ret == 0)</div> <div class="line"><a name="l00133"></a><span class="lineno"> 133</span>  {</div> <div class="line"><a name="l00134"></a><span class="lineno"> 134</span>  Log4(PCSC_LOG_CRITICAL,</div> <div class="line"><a name="l00135"></a><span class="lineno"> 135</span>  <span class="stringliteral">"Process %u (user: %u) is NOT authorized for action: %s"</span>,</div> <div class="line"><a name="l00136"></a><span class="lineno"> 136</span>  (<span class="keywordtype">unsigned</span>)cr.pid, (<span class="keywordtype">unsigned</span>)cr.uid, action);</div> <div class="line"><a name="l00137"></a><span class="lineno"> 137</span>  }</div> <div class="line"><a name="l00138"></a><span class="lineno"> 138</span> </div> <div class="line"><a name="l00139"></a><span class="lineno"> 139</span>  g_object_unref(subject);</div> <div class="line"><a name="l00140"></a><span class="lineno"> 140</span> cleanup0:</div> <div class="line"><a name="l00141"></a><span class="lineno"> 141</span>  g_object_unref(details);</div> <div class="line"><a name="l00142"></a><span class="lineno"> 142</span> cleanup1:</div> <div class="line"><a name="l00143"></a><span class="lineno"> 143</span>  g_object_unref(authority);</div> <div class="line"><a name="l00144"></a><span class="lineno"> 144</span> </div> <div class="line"><a name="l00145"></a><span class="lineno"> 145</span>  <span class="keywordflow">return</span> ret;</div> <div class="line"><a name="l00146"></a><span class="lineno"> 146</span> }</div> <div class="line"><a name="l00147"></a><span class="lineno"> 147</span> </div> <div class="line"><a name="l00148"></a><span class="lineno"> 148</span> <span class="preprocessor">#else</span></div> <div class="line"><a name="l00149"></a><span class="lineno"> 149</span> </div> <div class="line"><a name="l00150"></a><span class="lineno"> 150</span> <span class="keywordtype">int</span> IsClientAuthorized(<span class="keywordtype">int</span> socket, <span class="keyword">const</span> <span class="keywordtype">char</span>* action, <span class="keyword">const</span> <span class="keywordtype">char</span>* reader)</div> <div class="line"><a name="l00151"></a><span class="lineno"> 151</span> {</div> <div class="line"><a name="l00152"></a><span class="lineno"> 152</span>  <span class="keywordflow">return</span> 1;</div> <div class="line"><a name="l00153"></a><span class="lineno"> 153</span> }</div> <div class="line"><a name="l00154"></a><span class="lineno"> 154</span> </div> <div class="line"><a name="l00155"></a><span class="lineno"> 155</span> <span class="preprocessor">#endif</span></div> <div class="ttc" id="debuglog_8h_html"><div class="ttname"><a href="debuglog_8h.html">debuglog.h</a></div><div class="ttdoc">This handles debugging. </div></div> </div><!-- fragment --></div><!-- contents --> <!-- start footer part --> <hr class="footer"/><address class="footer"><small> Generated on Wed Oct 15 2014 11:57:56 for pcsc-lite by  <a href="http://www.doxygen.org/index.html"> <img class="footer" src="doxygen.png" alt="doxygen"/> </a> 1.8.8 </small></address> </body> </html>