Blame


1 0ccf3acb 2022-11-16 stsp /*
2 0ccf3acb 2022-11-16 stsp * Copyright (c) 2022 Stefan Sperling <stsp@openbsd.org>
3 0ccf3acb 2022-11-16 stsp * Copyright (c) 2015 Ted Unangst <tedu@openbsd.org>
4 0ccf3acb 2022-11-16 stsp *
5 0ccf3acb 2022-11-16 stsp * Permission to use, copy, modify, and distribute this software for any
6 0ccf3acb 2022-11-16 stsp * purpose with or without fee is hereby granted, provided that the above
7 0ccf3acb 2022-11-16 stsp * copyright notice and this permission notice appear in all copies.
8 0ccf3acb 2022-11-16 stsp *
9 0ccf3acb 2022-11-16 stsp * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10 0ccf3acb 2022-11-16 stsp * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11 0ccf3acb 2022-11-16 stsp * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12 0ccf3acb 2022-11-16 stsp * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13 0ccf3acb 2022-11-16 stsp * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14 0ccf3acb 2022-11-16 stsp * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15 0ccf3acb 2022-11-16 stsp * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16 0ccf3acb 2022-11-16 stsp */
17 0ccf3acb 2022-11-16 stsp
18 0ccf3acb 2022-11-16 stsp #include <sys/types.h>
19 365cf0f3 2022-12-29 stsp #include <sys/socket.h>
20 0ccf3acb 2022-11-16 stsp #include <sys/queue.h>
21 0ccf3acb 2022-11-16 stsp #include <sys/uio.h>
22 0ccf3acb 2022-11-16 stsp
23 0ccf3acb 2022-11-16 stsp #include <errno.h>
24 0ccf3acb 2022-11-16 stsp #include <event.h>
25 0ccf3acb 2022-11-16 stsp #include <limits.h>
26 0ccf3acb 2022-11-16 stsp #include <pwd.h>
27 0ccf3acb 2022-11-16 stsp #include <grp.h>
28 0ccf3acb 2022-11-16 stsp #include <sha1.h>
29 5822e79e 2023-02-23 op #include <sha2.h>
30 5e25db14 2022-12-29 stsp #include <signal.h>
31 0ccf3acb 2022-11-16 stsp #include <stdint.h>
32 0ccf3acb 2022-11-16 stsp #include <stdio.h>
33 0ccf3acb 2022-11-16 stsp #include <stdlib.h>
34 5e25db14 2022-12-29 stsp #include <string.h>
35 0ccf3acb 2022-11-16 stsp #include <imsg.h>
36 ddbe612c 2022-11-17 stsp #include <unistd.h>
37 0ccf3acb 2022-11-16 stsp
38 0ccf3acb 2022-11-16 stsp #include "got_error.h"
39 5e25db14 2022-12-29 stsp #include "got_path.h"
40 0ccf3acb 2022-11-16 stsp
41 0ccf3acb 2022-11-16 stsp #include "gotd.h"
42 ddbe612c 2022-11-17 stsp #include "log.h"
43 0ccf3acb 2022-11-16 stsp #include "auth.h"
44 0ccf3acb 2022-11-16 stsp
45 5e25db14 2022-12-29 stsp static struct gotd_auth {
46 5e25db14 2022-12-29 stsp pid_t pid;
47 5e25db14 2022-12-29 stsp const char *title;
48 5e25db14 2022-12-29 stsp struct gotd_repo *repo;
49 5e25db14 2022-12-29 stsp } gotd_auth;
50 5e25db14 2022-12-29 stsp
51 5e25db14 2022-12-29 stsp static void auth_shutdown(void);
52 5e25db14 2022-12-29 stsp
53 5e25db14 2022-12-29 stsp static void
54 5e25db14 2022-12-29 stsp auth_sighdlr(int sig, short event, void *arg)
55 5e25db14 2022-12-29 stsp {
56 5e25db14 2022-12-29 stsp /*
57 5e25db14 2022-12-29 stsp * Normal signal handler rules don't apply because libevent
58 5e25db14 2022-12-29 stsp * decouples for us.
59 5e25db14 2022-12-29 stsp */
60 5e25db14 2022-12-29 stsp
61 5e25db14 2022-12-29 stsp switch (sig) {
62 5e25db14 2022-12-29 stsp case SIGHUP:
63 5e25db14 2022-12-29 stsp break;
64 5e25db14 2022-12-29 stsp case SIGUSR1:
65 5e25db14 2022-12-29 stsp break;
66 5e25db14 2022-12-29 stsp case SIGTERM:
67 5e25db14 2022-12-29 stsp case SIGINT:
68 5e25db14 2022-12-29 stsp auth_shutdown();
69 5e25db14 2022-12-29 stsp /* NOTREACHED */
70 5e25db14 2022-12-29 stsp break;
71 5e25db14 2022-12-29 stsp default:
72 5e25db14 2022-12-29 stsp fatalx("unexpected signal");
73 0ccf3acb 2022-11-16 stsp }
74 0ccf3acb 2022-11-16 stsp }
75 0ccf3acb 2022-11-16 stsp
76 0ccf3acb 2022-11-16 stsp static int
77 0ccf3acb 2022-11-16 stsp uidcheck(const char *s, uid_t desired)
78 0ccf3acb 2022-11-16 stsp {
79 0ccf3acb 2022-11-16 stsp uid_t uid;
80 0ccf3acb 2022-11-16 stsp
81 1963be61 2023-04-14 stsp if (gotd_parseuid(s, &uid) != 0)
82 0ccf3acb 2022-11-16 stsp return -1;
83 0ccf3acb 2022-11-16 stsp if (uid != desired)
84 0ccf3acb 2022-11-16 stsp return -1;
85 0ccf3acb 2022-11-16 stsp return 0;
86 0ccf3acb 2022-11-16 stsp }
87 0ccf3acb 2022-11-16 stsp
88 0ccf3acb 2022-11-16 stsp static int
89 0ccf3acb 2022-11-16 stsp parsegid(const char *s, gid_t *gid)
90 0ccf3acb 2022-11-16 stsp {
91 0ccf3acb 2022-11-16 stsp struct group *gr;
92 0ccf3acb 2022-11-16 stsp const char *errstr;
93 0ccf3acb 2022-11-16 stsp
94 0ccf3acb 2022-11-16 stsp if ((gr = getgrnam(s)) != NULL) {
95 0ccf3acb 2022-11-16 stsp *gid = gr->gr_gid;
96 0ccf3acb 2022-11-16 stsp if (*gid == GID_MAX)
97 0ccf3acb 2022-11-16 stsp return -1;
98 0ccf3acb 2022-11-16 stsp return 0;
99 0ccf3acb 2022-11-16 stsp }
100 0ccf3acb 2022-11-16 stsp *gid = strtonum(s, 0, GID_MAX - 1, &errstr);
101 0ccf3acb 2022-11-16 stsp if (errstr)
102 0ccf3acb 2022-11-16 stsp return -1;
103 0ccf3acb 2022-11-16 stsp return 0;
104 0ccf3acb 2022-11-16 stsp }
105 0ccf3acb 2022-11-16 stsp
106 0ccf3acb 2022-11-16 stsp static int
107 0ccf3acb 2022-11-16 stsp match_identifier(const char *identifier, gid_t *groups, int ngroups,
108 0ccf3acb 2022-11-16 stsp uid_t euid, gid_t egid)
109 0ccf3acb 2022-11-16 stsp {
110 0ccf3acb 2022-11-16 stsp int i;
111 0ccf3acb 2022-11-16 stsp
112 0ccf3acb 2022-11-16 stsp if (identifier[0] == ':') {
113 0ccf3acb 2022-11-16 stsp gid_t rgid;
114 0ccf3acb 2022-11-16 stsp if (parsegid(identifier + 1, &rgid) == -1)
115 0ccf3acb 2022-11-16 stsp return 0;
116 ddbe612c 2022-11-17 stsp if (rgid == egid)
117 ddbe612c 2022-11-17 stsp return 1;
118 0ccf3acb 2022-11-16 stsp for (i = 0; i < ngroups; i++) {
119 ddbe612c 2022-11-17 stsp if (rgid == groups[i])
120 0ccf3acb 2022-11-16 stsp break;
121 0ccf3acb 2022-11-16 stsp }
122 0ccf3acb 2022-11-16 stsp if (i == ngroups)
123 0ccf3acb 2022-11-16 stsp return 0;
124 0ccf3acb 2022-11-16 stsp } else if (uidcheck(identifier, euid) != 0)
125 0ccf3acb 2022-11-16 stsp return 0;
126 0ccf3acb 2022-11-16 stsp
127 0ccf3acb 2022-11-16 stsp return 1;
128 0ccf3acb 2022-11-16 stsp }
129 0ccf3acb 2022-11-16 stsp
130 5e25db14 2022-12-29 stsp static const struct got_error *
131 56624d2b 2023-12-27 stsp auth_check(char **username, struct gotd_access_rule_list *rules,
132 56624d2b 2023-12-27 stsp const char *repo_name, uid_t euid, gid_t egid, int required_auth)
133 0ccf3acb 2022-11-16 stsp {
134 0ccf3acb 2022-11-16 stsp struct gotd_access_rule *rule;
135 0ccf3acb 2022-11-16 stsp enum gotd_access access = GOTD_ACCESS_DENIED;
136 ddbe612c 2022-11-17 stsp struct passwd *pw;
137 ddbe612c 2022-11-17 stsp gid_t groups[NGROUPS_MAX];
138 ddbe612c 2022-11-17 stsp int ngroups = NGROUPS_MAX;
139 0ccf3acb 2022-11-16 stsp
140 56624d2b 2023-12-27 stsp *username = NULL;
141 56624d2b 2023-12-27 stsp
142 ddbe612c 2022-11-17 stsp pw = getpwuid(euid);
143 e18d071f 2022-11-20 stsp if (pw == NULL) {
144 e18d071f 2022-11-20 stsp if (errno)
145 e18d071f 2022-11-20 stsp return got_error_from_errno("getpwuid");
146 e18d071f 2022-11-20 stsp else
147 e18d071f 2022-11-20 stsp return got_error_set_errno(EACCES, repo_name);
148 e18d071f 2022-11-20 stsp }
149 ddbe612c 2022-11-17 stsp
150 56624d2b 2023-12-27 stsp *username = strdup(pw->pw_name);
151 56624d2b 2023-12-27 stsp if (*username == NULL)
152 56624d2b 2023-12-27 stsp return got_error_from_errno("strdup");
153 56624d2b 2023-12-27 stsp
154 ddbe612c 2022-11-17 stsp if (getgrouplist(pw->pw_name, pw->pw_gid, groups, &ngroups) == -1)
155 ddbe612c 2022-11-17 stsp log_warnx("group membership list truncated");
156 ddbe612c 2022-11-17 stsp
157 0ccf3acb 2022-11-16 stsp STAILQ_FOREACH(rule, rules, entry) {
158 0ccf3acb 2022-11-16 stsp if (!match_identifier(rule->identifier, groups, ngroups,
159 0ccf3acb 2022-11-16 stsp euid, egid))
160 0ccf3acb 2022-11-16 stsp continue;
161 0ccf3acb 2022-11-16 stsp
162 0ccf3acb 2022-11-16 stsp access = rule->access;
163 0ccf3acb 2022-11-16 stsp if (rule->access == GOTD_ACCESS_PERMITTED &&
164 0ccf3acb 2022-11-16 stsp (rule->authorization & required_auth) != required_auth)
165 0ccf3acb 2022-11-16 stsp access = GOTD_ACCESS_DENIED;
166 0ccf3acb 2022-11-16 stsp }
167 0ccf3acb 2022-11-16 stsp
168 0ccf3acb 2022-11-16 stsp if (access == GOTD_ACCESS_DENIED)
169 0ccf3acb 2022-11-16 stsp return got_error_set_errno(EACCES, repo_name);
170 0ccf3acb 2022-11-16 stsp
171 0ccf3acb 2022-11-16 stsp if (access == GOTD_ACCESS_PERMITTED)
172 0ccf3acb 2022-11-16 stsp return NULL;
173 0ccf3acb 2022-11-16 stsp
174 0ccf3acb 2022-11-16 stsp /* should not happen, this would be a bug */
175 0ccf3acb 2022-11-16 stsp return got_error_msg(GOT_ERR_NOT_IMPL, "bad access rule");
176 0ccf3acb 2022-11-16 stsp }
177 5e25db14 2022-12-29 stsp
178 5e25db14 2022-12-29 stsp static const struct got_error *
179 5e25db14 2022-12-29 stsp recv_authreq(struct imsg *imsg, struct gotd_imsgev *iev)
180 5e25db14 2022-12-29 stsp {
181 5e25db14 2022-12-29 stsp const struct got_error *err;
182 5e25db14 2022-12-29 stsp struct imsgbuf *ibuf = &iev->ibuf;
183 5e25db14 2022-12-29 stsp struct gotd_imsg_auth iauth;
184 5e25db14 2022-12-29 stsp size_t datalen;
185 365cf0f3 2022-12-29 stsp uid_t euid;
186 365cf0f3 2022-12-29 stsp gid_t egid;
187 56624d2b 2023-12-27 stsp char *username = NULL;
188 56624d2b 2023-12-27 stsp size_t len;
189 56624d2b 2023-12-27 stsp const size_t maxlen = MAX_IMSGSIZE - IMSG_HEADER_SIZE;
190 2c52c623 2024-01-30 op int fd = -1;
191 5e25db14 2022-12-29 stsp
192 5e25db14 2022-12-29 stsp log_debug("authentication request received");
193 5e25db14 2022-12-29 stsp
194 5e25db14 2022-12-29 stsp datalen = imsg->hdr.len - IMSG_HEADER_SIZE;
195 5e25db14 2022-12-29 stsp if (datalen != sizeof(iauth))
196 5e25db14 2022-12-29 stsp return got_error(GOT_ERR_PRIVSEP_LEN);
197 5e25db14 2022-12-29 stsp
198 5e25db14 2022-12-29 stsp memcpy(&iauth, imsg->data, datalen);
199 365cf0f3 2022-12-29 stsp
200 2c52c623 2024-01-30 op fd = imsg_get_fd(imsg);
201 2c52c623 2024-01-30 op if (fd == -1)
202 365cf0f3 2022-12-29 stsp return got_error(GOT_ERR_PRIVSEP_NO_FD);
203 365cf0f3 2022-12-29 stsp
204 2c52c623 2024-01-30 op if (getpeereid(fd, &euid, &egid) == -1)
205 365cf0f3 2022-12-29 stsp return got_error_from_errno("getpeerid");
206 5e25db14 2022-12-29 stsp
207 365cf0f3 2022-12-29 stsp if (iauth.euid != euid)
208 365cf0f3 2022-12-29 stsp return got_error(GOT_ERR_UID);
209 365cf0f3 2022-12-29 stsp if (iauth.egid != egid)
210 365cf0f3 2022-12-29 stsp return got_error(GOT_ERR_GID);
211 365cf0f3 2022-12-29 stsp
212 365cf0f3 2022-12-29 stsp log_debug("authenticating uid %d gid %d", euid, egid);
213 365cf0f3 2022-12-29 stsp
214 56624d2b 2023-12-27 stsp err = auth_check(&username, &gotd_auth.repo->rules,
215 56624d2b 2023-12-27 stsp gotd_auth.repo->name, iauth.euid, iauth.egid, iauth.required_auth);
216 5e25db14 2022-12-29 stsp if (err) {
217 5e25db14 2022-12-29 stsp gotd_imsg_send_error(ibuf, PROC_AUTH, iauth.client_id, err);
218 56624d2b 2023-12-27 stsp goto done;
219 5e25db14 2022-12-29 stsp }
220 5e25db14 2022-12-29 stsp
221 56624d2b 2023-12-27 stsp len = strlen(username);
222 56624d2b 2023-12-27 stsp if (len > maxlen)
223 56624d2b 2023-12-27 stsp len = maxlen;
224 5e25db14 2022-12-29 stsp
225 56624d2b 2023-12-27 stsp if (gotd_imsg_compose_event(iev, GOTD_IMSG_ACCESS_GRANTED,
226 56624d2b 2023-12-27 stsp PROC_AUTH, -1, username, len) == -1)
227 56624d2b 2023-12-27 stsp err = got_error_from_errno("imsg compose ACCESS_GRANTED");
228 56624d2b 2023-12-27 stsp done:
229 56624d2b 2023-12-27 stsp free(username);
230 56624d2b 2023-12-27 stsp return err;
231 5e25db14 2022-12-29 stsp }
232 5e25db14 2022-12-29 stsp
233 5e25db14 2022-12-29 stsp static void
234 5e25db14 2022-12-29 stsp auth_dispatch(int fd, short event, void *arg)
235 5e25db14 2022-12-29 stsp {
236 5e25db14 2022-12-29 stsp const struct got_error *err = NULL;
237 5e25db14 2022-12-29 stsp struct gotd_imsgev *iev = arg;
238 5e25db14 2022-12-29 stsp struct imsgbuf *ibuf = &iev->ibuf;
239 5e25db14 2022-12-29 stsp struct imsg imsg;
240 5e25db14 2022-12-29 stsp ssize_t n;
241 5e25db14 2022-12-29 stsp int shut = 0;
242 5e25db14 2022-12-29 stsp
243 5e25db14 2022-12-29 stsp if (event & EV_READ) {
244 5e25db14 2022-12-29 stsp if ((n = imsg_read(ibuf)) == -1 && errno != EAGAIN)
245 5e25db14 2022-12-29 stsp fatal("imsg_read error");
246 5e25db14 2022-12-29 stsp if (n == 0) /* Connection closed. */
247 5e25db14 2022-12-29 stsp shut = 1;
248 5e25db14 2022-12-29 stsp }
249 5e25db14 2022-12-29 stsp
250 5e25db14 2022-12-29 stsp if (event & EV_WRITE) {
251 5e25db14 2022-12-29 stsp n = msgbuf_write(&ibuf->w);
252 5e25db14 2022-12-29 stsp if (n == -1 && errno != EAGAIN)
253 5e25db14 2022-12-29 stsp fatal("msgbuf_write");
254 5e25db14 2022-12-29 stsp if (n == 0) /* Connection closed. */
255 5e25db14 2022-12-29 stsp shut = 1;
256 5e25db14 2022-12-29 stsp }
257 5e25db14 2022-12-29 stsp
258 5e25db14 2022-12-29 stsp for (;;) {
259 5e25db14 2022-12-29 stsp if ((n = imsg_get(ibuf, &imsg)) == -1)
260 5e25db14 2022-12-29 stsp fatal("%s: imsg_get", __func__);
261 5e25db14 2022-12-29 stsp if (n == 0) /* No more messages. */
262 5e25db14 2022-12-29 stsp break;
263 5e25db14 2022-12-29 stsp
264 5e25db14 2022-12-29 stsp switch (imsg.hdr.type) {
265 5e25db14 2022-12-29 stsp case GOTD_IMSG_AUTHENTICATE:
266 5e25db14 2022-12-29 stsp err = recv_authreq(&imsg, iev);
267 5e25db14 2022-12-29 stsp if (err)
268 2ec74a9e 2023-02-08 op log_warnx("%s", err->msg);
269 5e25db14 2022-12-29 stsp break;
270 5e25db14 2022-12-29 stsp default:
271 2ec74a9e 2023-02-08 op log_debug("unexpected imsg %d", imsg.hdr.type);
272 5e25db14 2022-12-29 stsp break;
273 5e25db14 2022-12-29 stsp }
274 5e25db14 2022-12-29 stsp
275 5e25db14 2022-12-29 stsp imsg_free(&imsg);
276 5e25db14 2022-12-29 stsp }
277 5e25db14 2022-12-29 stsp
278 5e25db14 2022-12-29 stsp if (!shut) {
279 5e25db14 2022-12-29 stsp gotd_imsg_event_add(iev);
280 5e25db14 2022-12-29 stsp } else {
281 5e25db14 2022-12-29 stsp /* This pipe is dead. Remove its event handler */
282 5e25db14 2022-12-29 stsp event_del(&iev->ev);
283 5e25db14 2022-12-29 stsp event_loopexit(NULL);
284 5e25db14 2022-12-29 stsp }
285 5e25db14 2022-12-29 stsp }
286 5e25db14 2022-12-29 stsp
287 5e25db14 2022-12-29 stsp void
288 5e25db14 2022-12-29 stsp auth_main(const char *title, struct gotd_repolist *repos,
289 5e25db14 2022-12-29 stsp const char *repo_path)
290 5e25db14 2022-12-29 stsp {
291 5e25db14 2022-12-29 stsp struct gotd_repo *repo = NULL;
292 5e25db14 2022-12-29 stsp struct gotd_imsgev iev;
293 5e25db14 2022-12-29 stsp struct event evsigint, evsigterm, evsighup, evsigusr1;
294 5e25db14 2022-12-29 stsp
295 5e25db14 2022-12-29 stsp gotd_auth.title = title;
296 5e25db14 2022-12-29 stsp gotd_auth.pid = getpid();
297 5e25db14 2022-12-29 stsp TAILQ_FOREACH(repo, repos, entry) {
298 5e25db14 2022-12-29 stsp if (got_path_cmp(repo->path, repo_path,
299 5e25db14 2022-12-29 stsp strlen(repo->path), strlen(repo_path)) == 0)
300 5e25db14 2022-12-29 stsp break;
301 5e25db14 2022-12-29 stsp }
302 5e25db14 2022-12-29 stsp if (repo == NULL)
303 5e25db14 2022-12-29 stsp fatalx("repository %s not found in config", repo_path);
304 5e25db14 2022-12-29 stsp gotd_auth.repo = repo;
305 5e25db14 2022-12-29 stsp
306 5e25db14 2022-12-29 stsp signal_set(&evsigint, SIGINT, auth_sighdlr, NULL);
307 5e25db14 2022-12-29 stsp signal_set(&evsigterm, SIGTERM, auth_sighdlr, NULL);
308 5e25db14 2022-12-29 stsp signal_set(&evsighup, SIGHUP, auth_sighdlr, NULL);
309 5e25db14 2022-12-29 stsp signal_set(&evsigusr1, SIGUSR1, auth_sighdlr, NULL);
310 5e25db14 2022-12-29 stsp signal(SIGPIPE, SIG_IGN);
311 5e25db14 2022-12-29 stsp
312 5e25db14 2022-12-29 stsp signal_add(&evsigint, NULL);
313 5e25db14 2022-12-29 stsp signal_add(&evsigterm, NULL);
314 5e25db14 2022-12-29 stsp signal_add(&evsighup, NULL);
315 5e25db14 2022-12-29 stsp signal_add(&evsigusr1, NULL);
316 5e25db14 2022-12-29 stsp
317 5e25db14 2022-12-29 stsp imsg_init(&iev.ibuf, GOTD_FILENO_MSG_PIPE);
318 5e25db14 2022-12-29 stsp iev.handler = auth_dispatch;
319 5e25db14 2022-12-29 stsp iev.events = EV_READ;
320 5e25db14 2022-12-29 stsp iev.handler_arg = NULL;
321 5e25db14 2022-12-29 stsp event_set(&iev.ev, iev.ibuf.fd, EV_READ, auth_dispatch, &iev);
322 5e25db14 2022-12-29 stsp if (event_add(&iev.ev, NULL) == -1)
323 5e25db14 2022-12-29 stsp fatalx("event add");
324 5e25db14 2022-12-29 stsp
325 5e25db14 2022-12-29 stsp event_dispatch();
326 5e25db14 2022-12-29 stsp
327 5e25db14 2022-12-29 stsp auth_shutdown();
328 5e25db14 2022-12-29 stsp }
329 5e25db14 2022-12-29 stsp
330 5e25db14 2022-12-29 stsp static void
331 5e25db14 2022-12-29 stsp auth_shutdown(void)
332 5e25db14 2022-12-29 stsp {
333 e8d451cc 2024-03-22 stsp log_debug("%s: shutting down", gotd_auth.title);
334 5e25db14 2022-12-29 stsp exit(0);
335 5e25db14 2022-12-29 stsp }