main: only purge uci savedirs if not reloading
[project/rpcd.git] / session.c
index 6352354..e390a9b 100644 (file)
--- a/session.c
+++ b/session.c
@@ -1,5 +1,5 @@
 /*
- * luci-rpcd - LuCI UBUS RPC server
+ * rpcd - UBUS RPC server
  *
  *   Copyright (C) 2013 Felix Fietkau <nbd@openwrt.org>
  *   Copyright (C) 2013 Jo-Philipp Wich <jow@openwrt.org>
 #include <libubus.h>
 #include <fnmatch.h>
 
-#include "session.h"
+#include <rpcd/session.h>
 
 static struct avl_tree sessions;
 static struct blob_buf buf;
 
+static LIST_HEAD(create_callbacks);
+static LIST_HEAD(destroy_callbacks);
+
 static const struct blobmsg_policy new_policy = {
        .name = "timeout", .type = BLOBMSG_TYPE_INT32
 };
@@ -57,40 +60,60 @@ static const struct blobmsg_policy get_policy[__RPC_SG_MAX] = {
 
 enum {
        RPC_SA_SID,
+       RPC_SA_SCOPE,
        RPC_SA_OBJECTS,
        __RPC_SA_MAX,
 };
 static const struct blobmsg_policy acl_policy[__RPC_SA_MAX] = {
        [RPC_SA_SID] = { .name = "sid", .type = BLOBMSG_TYPE_STRING },
+       [RPC_SA_SCOPE] = { .name = "scope", .type = BLOBMSG_TYPE_STRING },
        [RPC_SA_OBJECTS] = { .name = "objects", .type = BLOBMSG_TYPE_ARRAY },
 };
 
 enum {
        RPC_SP_SID,
+       RPC_SP_SCOPE,
        RPC_SP_OBJECT,
        RPC_SP_FUNCTION,
        __RPC_SP_MAX,
 };
 static const struct blobmsg_policy perm_policy[__RPC_SP_MAX] = {
        [RPC_SP_SID] = { .name = "sid", .type = BLOBMSG_TYPE_STRING },
+       [RPC_SP_SCOPE] = { .name = "scope", .type = BLOBMSG_TYPE_STRING },
        [RPC_SP_OBJECT] = { .name = "object", .type = BLOBMSG_TYPE_STRING },
        [RPC_SP_FUNCTION] = { .name = "function", .type = BLOBMSG_TYPE_STRING },
 };
 
+enum {
+       RPC_DUMP_SID,
+       RPC_DUMP_TIMEOUT,
+       RPC_DUMP_EXPIRES,
+       RPC_DUMP_ACLS,
+       RPC_DUMP_DATA,
+       __RPC_DUMP_MAX,
+};
+static const struct blobmsg_policy dump_policy[__RPC_DUMP_MAX] = {
+       [RPC_DUMP_SID] = { .name = "sid", .type = BLOBMSG_TYPE_STRING },
+       [RPC_DUMP_TIMEOUT] = { .name = "timeout", .type = BLOBMSG_TYPE_INT32 },
+       [RPC_DUMP_EXPIRES] = { .name = "expires", .type = BLOBMSG_TYPE_INT32 },
+       [RPC_DUMP_ACLS] = { .name = "acls", .type = BLOBMSG_TYPE_TABLE },
+       [RPC_DUMP_DATA] = { .name = "data", .type = BLOBMSG_TYPE_TABLE },
+};
+
 /*
  * Keys in the AVL tree contain all pattern characters up to the first wildcard.
  * To look up entries, start with the last entry that has a key less than or
  * equal to the method name, then work backwards as long as the AVL key still
  * matches its counterpart in the object name
  */
-#define uh_foreach_matching_acl_prefix(_acl, _ses, _obj, _func)                        \
-       for (_acl = avl_find_le_element(&(_ses)->acls, _obj, _acl, avl);        \
-            _acl;                                                              \
-            _acl = avl_is_first(&(ses)->acls, &(_acl)->avl) ? NULL :           \
+#define uh_foreach_matching_acl_prefix(_acl, _avl, _obj, _func)                \
+       for (_acl = avl_find_le_element(_avl, _obj, _acl, avl);                 \
+            _acl;                                                                                                              \
+            _acl = avl_is_first(_avl, &(_acl)->avl) ? NULL :                   \
                    avl_prev_element((_acl), avl))
 
-#define uh_foreach_matching_acl(_acl, _ses, _obj, _func)                       \
-       uh_foreach_matching_acl_prefix(_acl, _ses, _obj, _func)                 \
+#define uh_foreach_matching_acl(_acl, _avl, _obj, _func)                       \
+       uh_foreach_matching_acl_prefix(_acl, _avl, _obj, _func)                 \
                if (!strncmp((_acl)->object, _obj, (_acl)->sort_len) &&         \
                    !fnmatch((_acl)->object, (_obj), FNM_NOESCAPE) &&           \
                    !fnmatch((_acl)->function, (_func), FNM_NOESCAPE))
@@ -128,27 +151,40 @@ static void
 rpc_session_dump_acls(struct rpc_session *ses, struct blob_buf *b)
 {
        struct rpc_session_acl *acl;
+       struct rpc_session_acl_scope *acl_scope;
        const char *lastobj = NULL;
-       void *c = NULL;
+       const char *lastscope = NULL;
+       void *c = NULL, *d = NULL;
 
-       avl_for_each_element(&ses->acls, acl, avl) {
-               if (!lastobj || strcmp(acl->object, lastobj))
+       avl_for_each_element(&ses->acls, acl_scope, avl) {
+               if (!lastscope || strcmp(acl_scope->avl.key, lastscope))
                {
-                       if (c) blobmsg_close_array(b, c);
-                       c = blobmsg_open_array(b, acl->object);
+                       if (c) blobmsg_close_table(b, c);
+                       c = blobmsg_open_table(b, acl_scope->avl.key);
+                       lastobj = NULL;
                }
 
-               blobmsg_add_string(b, NULL, acl->function);
-               lastobj = acl->object;
+               d = NULL;
+
+               avl_for_each_element(&acl_scope->acls, acl, avl) {
+                       if (!lastobj || strcmp(acl->object, lastobj))
+                       {
+                               if (d) blobmsg_close_array(b, d);
+                               d = blobmsg_open_array(b, acl->object);
+                       }
+
+                       blobmsg_add_string(b, NULL, acl->function);
+                       lastobj = acl->object;
+               }
+
+               if (d) blobmsg_close_array(b, d);
        }
 
-       if (c) blobmsg_close_array(b, c);
+       if (c) blobmsg_close_table(b, c);
 }
 
 static void
-rpc_session_dump(struct rpc_session *ses,
-                                        struct ubus_context *ctx,
-                                        struct ubus_request_data *req)
+rpc_session_to_blob(struct rpc_session *ses)
 {
        void *c;
 
@@ -165,6 +201,13 @@ rpc_session_dump(struct rpc_session *ses,
        c = blobmsg_open_table(&buf, "data");
        rpc_session_dump_data(ses, &buf);
        blobmsg_close_table(&buf, c);
+}
+
+static void
+rpc_session_dump(struct rpc_session *ses, struct ubus_context *ctx,
+                 struct ubus_request_data *req)
+{
+       rpc_session_to_blob(ses);
 
        ubus_send_reply(ctx, req, buf.head);
 }
@@ -179,11 +222,22 @@ static void
 rpc_session_destroy(struct rpc_session *ses)
 {
        struct rpc_session_acl *acl, *nacl;
+       struct rpc_session_acl_scope *acl_scope, *nacl_scope;
        struct rpc_session_data *data, *ndata;
+       struct rpc_session_cb *cb;
+
+       list_for_each_entry(cb, &destroy_callbacks, list)
+               cb->cb(ses, cb->priv);
 
        uloop_timeout_cancel(&ses->t);
-       avl_remove_all_elements(&ses->acls, acl, avl, nacl)
-               free(acl);
+
+       avl_for_each_element_safe(&ses->acls, acl_scope, avl, nacl_scope) {
+               avl_remove_all_elements(&acl_scope->acls, acl, avl, nacl)
+                       free(acl);
+
+               avl_delete(&ses->acls, &acl_scope->avl);
+               free(acl_scope);
+       }
 
        avl_remove_all_elements(&ses->data, data, avl, ndata)
                free(data);
@@ -201,25 +255,47 @@ static void rpc_session_timeout(struct uloop_timeout *t)
 }
 
 static struct rpc_session *
-rpc_session_create(int timeout)
+rpc_session_new(void)
 {
        struct rpc_session *ses;
 
        ses = calloc(1, sizeof(*ses));
+
        if (!ses)
                return NULL;
 
-       ses->timeout  = timeout;
-       ses->avl.key  = ses->id;
-       rpc_random(ses->id);
+       ses->avl.key = ses->id;
 
-       avl_insert(&sessions, &ses->avl);
        avl_init(&ses->acls, avl_strcmp, true, NULL);
        avl_init(&ses->data, avl_strcmp, false, NULL);
 
        ses->t.cb = rpc_session_timeout;
+
+       return ses;
+}
+
+static struct rpc_session *
+rpc_session_create(int timeout)
+{
+       struct rpc_session *ses;
+       struct rpc_session_cb *cb;
+
+       ses = rpc_session_new();
+
+       if (!ses)
+               return NULL;
+
+       rpc_random(ses->id);
+
+       ses->timeout = timeout;
+
+       avl_insert(&sessions, &ses->avl);
+
        rpc_touch_session(ses);
 
+       list_for_each_entry(cb, &create_callbacks, list)
+               cb->cb(ses, cb->priv);
+
        return ses;
 }
 
@@ -289,19 +365,36 @@ uh_id_len(const char *str)
 
 static int
 rpc_session_grant(struct rpc_session *ses, struct ubus_context *ctx,
-                  const char *object, const char *function)
+                  const char *scope, const char *object, const char *function)
 {
        struct rpc_session_acl *acl;
-       char *new_obj, *new_func, *new_id;
+       struct rpc_session_acl_scope *acl_scope;
+       char *new_scope, *new_obj, *new_func, *new_id;
        int id_len;
 
        if (!object || !function)
                return UBUS_STATUS_INVALID_ARGUMENT;
 
-       uh_foreach_matching_acl_prefix(acl, ses, object, function) {
-               if (!strcmp(acl->object, object) &&
-                   !strcmp(acl->function, function))
-                       return 0;
+       acl_scope = avl_find_element(&ses->acls, scope, acl_scope, avl);
+
+       if (acl_scope) {
+               uh_foreach_matching_acl_prefix(acl, &acl_scope->acls, object, function) {
+                       if (!strcmp(acl->object, object) &&
+                               !strcmp(acl->function, function))
+                               return 0;
+               }
+       }
+
+       if (!acl_scope) {
+               acl_scope = calloc_a(sizeof(*acl_scope),
+                                    &new_scope, strlen(scope) + 1);
+
+               if (!acl_scope)
+                       return UBUS_STATUS_UNKNOWN_ERROR;
+
+               acl_scope->avl.key = strcpy(new_scope, scope);
+               avl_init(&acl_scope->acls, avl_strcmp, true, NULL);
+               avl_insert(&ses->acls, &acl_scope->avl);
        }
 
        id_len = uh_id_len(object);
@@ -316,22 +409,30 @@ rpc_session_grant(struct rpc_session *ses, struct ubus_context *ctx,
        acl->object = strcpy(new_obj, object);
        acl->function = strcpy(new_func, function);
        acl->avl.key = strncpy(new_id, object, id_len);
-       avl_insert(&ses->acls, &acl->avl);
+       avl_insert(&acl_scope->acls, &acl->avl);
 
        return 0;
 }
 
 static int
 rpc_session_revoke(struct rpc_session *ses, struct ubus_context *ctx,
-                   const char *object, const char *function)
+                   const char *scope, const char *object, const char *function)
 {
        struct rpc_session_acl *acl, *next;
+       struct rpc_session_acl_scope *acl_scope;
        int id_len;
        char *id;
 
+       acl_scope = avl_find_element(&ses->acls, scope, acl_scope, avl);
+
+       if (!acl_scope)
+               return 0;
+
        if (!object && !function) {
-               avl_remove_all_elements(&ses->acls, acl, avl, next)
+               avl_remove_all_elements(&acl_scope->acls, acl, avl, next)
                        free(acl);
+               avl_delete(&ses->acls, &acl_scope->avl);
+               free(acl_scope);
                return 0;
        }
 
@@ -340,9 +441,9 @@ rpc_session_revoke(struct rpc_session *ses, struct ubus_context *ctx,
        strncpy(id, object, id_len);
        id[id_len] = 0;
 
-       acl = avl_find_element(&ses->acls, id, acl, avl);
+       acl = avl_find_element(&acl_scope->acls, id, acl, avl);
        while (acl) {
-               if (!avl_is_last(&ses->acls, &acl->avl))
+               if (!avl_is_last(&acl_scope->acls, &acl->avl))
                        next = avl_next_element(acl, avl);
                else
                        next = NULL;
@@ -352,12 +453,17 @@ rpc_session_revoke(struct rpc_session *ses, struct ubus_context *ctx,
 
                if (!strcmp(acl->object, object) &&
                    !strcmp(acl->function, function)) {
-                       avl_delete(&ses->acls, &acl->avl);
+                       avl_delete(&acl_scope->acls, &acl->avl);
                        free(acl);
                }
                acl = next;
        }
 
+       if (avl_is_empty(&acl_scope->acls)) {
+               avl_delete(&ses->acls, &acl_scope->avl);
+               free(acl_scope);
+       }
+
        return 0;
 }
 
@@ -371,10 +477,11 @@ rpc_handle_acl(struct ubus_context *ctx, struct ubus_object *obj,
        struct blob_attr *tb[__RPC_SA_MAX];
        struct blob_attr *attr, *sattr;
        const char *object, *function;
+       const char *scope = "ubus";
        int rem1, rem2;
 
        int (*cb)(struct rpc_session *ses, struct ubus_context *ctx,
-                 const char *object, const char *function);
+                 const char *scope, const char *object, const char *function);
 
        blobmsg_parse(acl_policy, __RPC_SA_MAX, tb, blob_data(msg), blob_len(msg));
 
@@ -385,13 +492,16 @@ rpc_handle_acl(struct ubus_context *ctx, struct ubus_object *obj,
        if (!ses)
                return UBUS_STATUS_NOT_FOUND;
 
+       if (tb[RPC_SA_SCOPE])
+               scope = blobmsg_data(tb[RPC_SA_SCOPE]);
+
        if (!strcmp(method, "grant"))
                cb = rpc_session_grant;
        else
                cb = rpc_session_revoke;
 
        if (!tb[RPC_SA_OBJECTS])
-               return cb(ses, ctx, NULL, NULL);
+               return cb(ses, ctx, scope, NULL, NULL);
 
        blobmsg_for_each_attr(attr, tb[RPC_SA_OBJECTS], rem1) {
                if (blob_id(attr) != BLOBMSG_TYPE_ARRAY)
@@ -413,19 +523,25 @@ rpc_handle_acl(struct ubus_context *ctx, struct ubus_object *obj,
                }
 
                if (object && function)
-                       cb(ses, ctx, object, function);
+                       cb(ses, ctx, scope, object, function);
        }
 
        return 0;
 }
 
 static bool
-rpc_session_acl_allowed(struct rpc_session *ses, const char *obj, const char *fun)
+rpc_session_acl_allowed(struct rpc_session *ses, const char *scope,
+                        const char *obj, const char *fun)
 {
        struct rpc_session_acl *acl;
+       struct rpc_session_acl_scope *acl_scope;
 
-       uh_foreach_matching_acl(acl, ses, obj, fun)
-               return true;
+       acl_scope = avl_find_element(&ses->acls, scope, acl_scope, avl);
+
+       if (acl_scope) {
+               uh_foreach_matching_acl(acl, &acl_scope->acls, obj, fun)
+                       return true;
+       }
 
        return false;
 }
@@ -437,6 +553,7 @@ rpc_handle_access(struct ubus_context *ctx, struct ubus_object *obj,
 {
        struct rpc_session *ses;
        struct blob_attr *tb[__RPC_SP_MAX];
+       const char *scope = "ubus";
        bool allow;
 
        blobmsg_parse(perm_policy, __RPC_SP_MAX, tb, blob_data(msg), blob_len(msg));
@@ -448,7 +565,10 @@ rpc_handle_access(struct ubus_context *ctx, struct ubus_object *obj,
        if (!ses)
                return UBUS_STATUS_NOT_FOUND;
 
-       allow = rpc_session_acl_allowed(ses,
+       if (tb[RPC_SP_SCOPE])
+               scope = blobmsg_data(tb[RPC_SP_SCOPE]);
+
+       allow = rpc_session_acl_allowed(ses, scope,
                                                                        blobmsg_data(tb[RPC_SP_OBJECT]),
                                                                        blobmsg_data(tb[RPC_SP_FUNCTION]));
 
@@ -459,13 +579,32 @@ rpc_handle_access(struct ubus_context *ctx, struct ubus_object *obj,
        return 0;
 }
 
+static void
+rpc_session_set(struct rpc_session *ses, const char *key, struct blob_attr *val)
+{
+       struct rpc_session_data *data;
+
+       data = avl_find_element(&ses->data, key, data, avl);
+       if (data) {
+               avl_delete(&ses->data, &data->avl);
+               free(data);
+       }
+
+       data = calloc(1, sizeof(*data) + blob_pad_len(val));
+       if (!data)
+               return;
+
+       memcpy(data->attr, val, blob_pad_len(val));
+       data->avl.key = blobmsg_name(data->attr);
+       avl_insert(&ses->data, &data->avl);
+}
+
 static int
 rpc_handle_set(struct ubus_context *ctx, struct ubus_object *obj,
                struct ubus_request_data *req, const char *method,
                struct blob_attr *msg)
 {
        struct rpc_session *ses;
-       struct rpc_session_data *data;
        struct blob_attr *tb[__RPC_SA_MAX];
        struct blob_attr *attr;
        int rem;
@@ -483,19 +622,7 @@ rpc_handle_set(struct ubus_context *ctx, struct ubus_object *obj,
                if (!blobmsg_name(attr)[0])
                        continue;
 
-               data = avl_find_element(&ses->data, blobmsg_name(attr), data, avl);
-               if (data) {
-                       avl_delete(&ses->data, &data->avl);
-                       free(data);
-               }
-
-               data = calloc(1, sizeof(*data) + blob_pad_len(attr));
-               if (!data)
-                       break;
-
-               memcpy(data->attr, attr, blob_pad_len(attr));
-               data->avl.key = blobmsg_name(data->attr);
-               avl_insert(&ses->data, &data->avl);
+               rpc_session_set(ses, blobmsg_name(attr), attr);
        }
 
        return 0;
@@ -611,6 +738,134 @@ rpc_handle_destroy(struct ubus_context *ctx, struct ubus_object *obj,
        return 0;
 }
 
+
+static bool
+rpc_validate_sid(const char *id)
+{
+       if (!id)
+               return false;
+
+       if (strlen(id) != RPC_SID_LEN)
+               return false;
+
+       while (*id)
+               if (!isxdigit(*id++))
+                       return false;
+
+       return true;
+}
+
+static int
+rpc_blob_to_file(const char *path, struct blob_attr *attr)
+{
+       int fd, len;
+
+       fd = open(path, O_WRONLY | O_CREAT | O_EXCL, 0600);
+
+       if (fd < 0)
+               return fd;
+
+       len = write(fd, attr, blob_pad_len(attr));
+
+       close(fd);
+
+       if (len != blob_pad_len(attr))
+       {
+               unlink(path);
+               return -1;
+       }
+
+       return len;
+}
+
+static struct blob_attr *
+rpc_blob_from_file(const char *path)
+{
+       int fd = -1, len;
+       struct stat s;
+       struct blob_attr head, *attr = NULL;
+
+       if (stat(path, &s) || !S_ISREG(s.st_mode))
+               return NULL;
+
+       fd = open(path, O_RDONLY);
+
+       if (fd < 0)
+               goto fail;
+
+       len = read(fd, &head, sizeof(head));
+
+       if (len != sizeof(head) || blob_pad_len(&head) != s.st_size)
+               goto fail;
+
+       attr = calloc(1, s.st_size);
+
+       if (!attr)
+               goto fail;
+
+       memcpy(attr, &head, sizeof(head));
+
+       len += read(fd, (char *)attr + sizeof(head), s.st_size - sizeof(head));
+
+       if (len != blob_pad_len(&head))
+               goto fail;
+
+       return attr;
+
+fail:
+       if (fd >= 0)
+               close(fd);
+
+       if (attr)
+               free(attr);
+
+       return NULL;
+}
+
+static bool
+rpc_session_from_blob(struct blob_attr *attr)
+{
+       int i, rem, rem2, rem3;
+       struct rpc_session *ses;
+       struct blob_attr *tb[__RPC_DUMP_MAX], *scope, *object, *function;
+
+       blobmsg_parse(dump_policy, __RPC_DUMP_MAX, tb,
+                     blob_data(attr), blob_len(attr));
+
+       for (i = 0; i < __RPC_DUMP_MAX; i++)
+               if (!tb[i])
+                       return false;
+
+       ses = rpc_session_new();
+
+       if (!ses)
+               return false;
+
+       memcpy(ses->id, blobmsg_data(tb[RPC_DUMP_SID]), RPC_SID_LEN);
+
+       ses->timeout = blobmsg_get_u32(tb[RPC_DUMP_TIMEOUT]);
+
+       blobmsg_for_each_attr(scope, tb[RPC_DUMP_ACLS], rem) {
+               blobmsg_for_each_attr(object, scope, rem2) {
+                       blobmsg_for_each_attr(function, object, rem3) {
+                               rpc_session_grant(ses, NULL, blobmsg_name(scope),
+                                                            blobmsg_name(object),
+                                                            blobmsg_data(function));
+                       }
+               }
+       }
+
+       blobmsg_for_each_attr(object, tb[RPC_DUMP_DATA], rem) {
+               rpc_session_set(ses, blobmsg_name(object), object);
+       }
+
+       avl_insert(&sessions, &ses->avl);
+
+       uloop_timeout_set(&ses->t, blobmsg_get_u32(tb[RPC_DUMP_EXPIRES]) * 1000);
+
+       return true;
+}
+
 int rpc_session_api_init(struct ubus_context *ctx)
 {
        static const struct ubus_method session_methods[] = {
@@ -639,3 +894,74 @@ int rpc_session_api_init(struct ubus_context *ctx)
 
        return ubus_add_object(ctx, &obj);
 }
+
+bool rpc_session_access(const char *sid, const char *scope,
+                        const char *object, const char *function)
+{
+       struct rpc_session *ses = rpc_session_get(sid);
+
+       if (!ses)
+               return false;
+
+       return rpc_session_acl_allowed(ses, scope, object, function);
+}
+
+void rpc_session_create_cb(struct rpc_session_cb *cb)
+{
+       if (cb && cb->cb)
+               list_add(&cb->list, &create_callbacks);
+}
+
+void rpc_session_destroy_cb(struct rpc_session_cb *cb)
+{
+       if (cb && cb->cb)
+               list_add(&cb->list, &destroy_callbacks);
+}
+
+void rpc_session_freeze(void)
+{
+       struct stat s;
+       struct rpc_session *ses;
+       char path[PATH_MAX];
+
+       if (stat(RPC_SESSION_DIRECTORY, &s))
+               mkdir(RPC_SESSION_DIRECTORY, 0700);
+
+       avl_for_each_element(&sessions, ses, avl) {
+               snprintf(path, sizeof(path) - 1, RPC_SESSION_DIRECTORY "/%s", ses->id);
+               rpc_session_to_blob(ses);
+               rpc_blob_to_file(path, buf.head);
+       }
+}
+
+void rpc_session_thaw(void)
+{
+       DIR *d;
+       char path[PATH_MAX];
+       struct dirent *e;
+       struct blob_attr *attr;
+
+       d = opendir(RPC_SESSION_DIRECTORY);
+
+       if (!d)
+               return;
+
+       while ((e = readdir(d)) != NULL) {
+               if (!rpc_validate_sid(e->d_name))
+                       continue;
+
+               snprintf(path, sizeof(path) - 1,
+                        RPC_SESSION_DIRECTORY "/%s", e->d_name);
+
+               attr = rpc_blob_from_file(path);
+
+               if (attr) {
+                       rpc_session_from_blob(attr);
+                       free(attr);
+               }
+
+               unlink(path);
+       }
+
+       closedir(d);
+}