sssd 2.9.4
data_provider.h
1/*
2 SSSD
3
4 Data Provider, private header file
5
6 Copyright (C) Simo Sorce <ssorce@redhat.com> 2008
7
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
12
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
17
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
20*/
21
22#ifndef __DATA_PROVIDER_H__
23#define __DATA_PROVIDER_H__
24
25#include "config.h"
26
27#include <stdint.h>
28#include <sys/un.h>
29#include <errno.h>
30#include <stdbool.h>
31#ifdef USE_KEYRING
32#include <sys/types.h>
33#include <keyutils.h>
34#endif
35#include <talloc.h>
36#include <tevent.h>
37#include <ldb.h>
38#include <dbus/dbus.h>
39
40#include "util/util.h"
41#include "confdb/confdb.h"
42#include "sss_client/sss_cli.h"
43#include "util/authtok.h"
44#include "util/sss_pam_data.h"
45#include "providers/data_provider_req.h"
46
47#define DATA_PROVIDER_VERSION 0x0001
48
111 /* end of group pamHandler */
112
113#define DP_ERR_DECIDE -1
114#define DP_ERR_OK 0
115#define DP_ERR_OFFLINE 1
116#define DP_ERR_TIMEOUT 2
117#define DP_ERR_FATAL 3
118
119#define BE_FILTER_NAME 1
120#define BE_FILTER_IDNUM 2
121#define BE_FILTER_ENUM 3
122#define BE_FILTER_SECID 4
123#define BE_FILTER_UUID 5
124#define BE_FILTER_CERT 6
125#define BE_FILTER_WILDCARD 7
126#define BE_FILTER_ADDR 8
127
128#define DP_SEC_ID "secid"
129#define DP_CERT "cert"
130/* sizeof() counts the trailing \0 so we must subtract 1 for the string
131 * length */
132#define DP_SEC_ID_LEN (sizeof(DP_SEC_ID) - 1)
133#define DP_CERT_LEN (sizeof(DP_CERT) - 1)
134
135#define DP_WILDCARD "wildcard"
136#define DP_WILDCARD_LEN (sizeof(DP_WILDCARD) - 1)
137
138#define EXTRA_NAME_IS_UPN "U"
139#define EXTRA_INPUT_MAYBE_WITH_VIEW "V"
140
141/* from dp_auth_util.c */
142#define SSS_SERVER_INFO 0x80000000
143
144#define SSS_KRB5_INFO 0x40000000
145#define SSS_LDAP_INFO 0x20000000
146#define SSS_PROXY_INFO 0x10000000
147
148#define SSS_KRB5_INFO_TGT_LIFETIME (SSS_SERVER_INFO|SSS_KRB5_INFO|0x01)
149#define SSS_KRB5_INFO_UPN (SSS_SERVER_INFO|SSS_KRB5_INFO|0x02)
150
151bool dp_pack_pam_request(DBusMessage *msg, struct pam_data *pd);
152bool dp_unpack_pam_request(DBusMessage *msg, TALLOC_CTX *mem_ctx,
153 struct pam_data **new_pd, DBusError *dbus_error);
154
155bool dp_pack_pam_response(DBusMessage *msg, struct pam_data *pd);
156bool dp_unpack_pam_response(DBusMessage *msg, struct pam_data *pd,
157 DBusError *dbus_error);
158
159void dp_id_callback(DBusPendingCall *pending, void *ptr);
160
161#ifdef BUILD_FILES_PROVIDER
162/* Reserved filter name for request which waits until the files provider finishes mirroring
163 * the file content
164 */
165#define DP_REQ_OPT_FILES_INITGR "files_initgr_request"
166#endif
167
168/* Helpers */
169
170#define NULL_STRING { .string = NULL }
171#define NULL_BLOB { .blob = { NULL, 0 } }
172#define NULL_NUMBER { .number = 0 }
173#define BOOL_FALSE { .boolean = false }
174#define BOOL_TRUE { .boolean = true }
175
176enum dp_opt_type {
177 DP_OPT_STRING,
178 DP_OPT_BLOB,
179 DP_OPT_NUMBER,
180 DP_OPT_BOOL
181};
182
183struct dp_opt_blob {
184 uint8_t *data;
185 size_t length;
186};
187
188union dp_opt_value {
189 const char *cstring;
190 char *string;
191 struct dp_opt_blob blob;
192 int number;
193 bool boolean;
194};
195
196struct dp_option {
197 const char *opt_name;
198 enum dp_opt_type type;
199 union dp_opt_value def_val;
200 union dp_opt_value val;
201};
202
203#define DP_OPTION_TERMINATOR { NULL, 0, NULL_STRING, NULL_STRING }
204
205void dp_option_inherit_match(char **inherit_opt_list,
206 int option,
207 struct dp_option *parent_opts,
208 struct dp_option *subdom_opts);
209
210void dp_option_inherit(int option,
211 struct dp_option *parent_opts,
212 struct dp_option *subdom_opts);
213
214int dp_get_options(TALLOC_CTX *memctx,
215 struct confdb_ctx *cdb,
216 const char *conf_path,
217 struct dp_option *def_opts,
218 int num_opts,
219 struct dp_option **_opts);
220
221int dp_copy_options(TALLOC_CTX *memctx,
222 struct dp_option *src_opts,
223 int num_opts,
224 struct dp_option **_opts);
225
226int dp_copy_defaults(TALLOC_CTX *memctx,
227 struct dp_option *src_opts,
228 int num_opts,
229 struct dp_option **_opts);
230
231const char *_dp_opt_get_cstring(struct dp_option *opts,
232 int id, const char *location);
233char *_dp_opt_get_string(struct dp_option *opts,
234 int id, const char *location);
235struct dp_opt_blob _dp_opt_get_blob(struct dp_option *opts,
236 int id, const char *location);
237int _dp_opt_get_int(struct dp_option *opts,
238 int id, const char *location);
239bool _dp_opt_get_bool(struct dp_option *opts,
240 int id, const char *location);
241#define dp_opt_get_cstring(o, i) _dp_opt_get_cstring(o, i, __FUNCTION__)
242#define dp_opt_get_string(o, i) _dp_opt_get_string(o, i, __FUNCTION__)
243#define dp_opt_get_blob(o, i) _dp_opt_get_blob(o, i, __FUNCTION__)
244#define dp_opt_get_int(o, i) _dp_opt_get_int(o, i, __FUNCTION__)
245#define dp_opt_get_bool(o, i) _dp_opt_get_bool(o, i, __FUNCTION__)
246
247int _dp_opt_set_string(struct dp_option *opts, int id,
248 const char *s, const char *location);
249int _dp_opt_set_blob(struct dp_option *opts, int id,
250 struct dp_opt_blob b, const char *location);
251int _dp_opt_set_int(struct dp_option *opts, int id,
252 int i, const char *location);
253int _dp_opt_set_bool(struct dp_option *opts, int id,
254 bool b, const char *location);
255#define dp_opt_set_string(o, i, v) _dp_opt_set_string(o, i, v, __FUNCTION__)
256#define dp_opt_set_blob(o, i, v) _dp_opt_set_blob(o, i, v, __FUNCTION__)
257#define dp_opt_set_int(o, i, v) _dp_opt_set_int(o, i, v, __FUNCTION__)
258#define dp_opt_set_bool(o, i, v) _dp_opt_set_bool(o, i, v, __FUNCTION__)
259
260/* Generic Data Provider options */
261
262/* Resolver DP options */
263enum dp_res_opts {
264 DP_RES_OPT_FAMILY_ORDER,
265 DP_RES_OPT_RESOLVER_TIMEOUT,
266 DP_RES_OPT_RESOLVER_OP_TIMEOUT,
267 DP_RES_OPT_RESOLVER_SERVER_TIMEOUT,
268 DP_RES_OPT_RESOLVER_USE_SEARCH_LIST,
269 DP_RES_OPT_DNS_DOMAIN,
270
271 DP_RES_OPTS /* attrs counter */
272};
273
274#endif /* __DATA_PROVIDER_ */