2 * luci-rpcd - LuCI UBUS RPC server
4 * Copyright (C) 2013 Felix Fietkau <nbd@openwrt.org>
5 * Copyright (C) 2013 Jo-Philipp Wich <jow@openwrt.org>
7 * Permission to use, copy, modify, and/or distribute this software for any
8 * purpose with or without fee is hereby granted, provided that the above
9 * copyright notice and this permission notice appear in all copies.
11 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
12 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
13 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
14 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
15 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
20 #include <libubox/avl-cmp.h>
21 #include <libubox/utils.h>
27 static struct avl_tree sessions;
28 static struct blob_buf buf;
30 static const struct blobmsg_policy new_policy = {
31 .name = "timeout", .type = BLOBMSG_TYPE_INT32
34 static const struct blobmsg_policy sid_policy = {
35 .name = "sid", .type = BLOBMSG_TYPE_STRING
43 static const struct blobmsg_policy set_policy[__RPC_SS_MAX] = {
44 [RPC_SS_SID] = { .name = "sid", .type = BLOBMSG_TYPE_STRING },
45 [RPC_SS_VALUES] = { .name = "values", .type = BLOBMSG_TYPE_TABLE },
53 static const struct blobmsg_policy get_policy[__RPC_SG_MAX] = {
54 [RPC_SG_SID] = { .name = "sid", .type = BLOBMSG_TYPE_STRING },
55 [RPC_SG_KEYS] = { .name = "keys", .type = BLOBMSG_TYPE_ARRAY },
63 static const struct blobmsg_policy acl_policy[__RPC_SA_MAX] = {
64 [RPC_SA_SID] = { .name = "sid", .type = BLOBMSG_TYPE_STRING },
65 [RPC_SA_OBJECTS] = { .name = "objects", .type = BLOBMSG_TYPE_ARRAY },
74 static const struct blobmsg_policy perm_policy[__RPC_SP_MAX] = {
75 [RPC_SP_SID] = { .name = "sid", .type = BLOBMSG_TYPE_STRING },
76 [RPC_SP_OBJECT] = { .name = "object", .type = BLOBMSG_TYPE_STRING },
77 [RPC_SP_FUNCTION] = { .name = "function", .type = BLOBMSG_TYPE_STRING },
81 * Keys in the AVL tree contain all pattern characters up to the first wildcard.
82 * To look up entries, start with the last entry that has a key less than or
83 * equal to the method name, then work backwards as long as the AVL key still
84 * matches its counterpart in the object name
86 #define uh_foreach_matching_acl_prefix(_acl, _ses, _obj, _func) \
87 for (_acl = avl_find_le_element(&(_ses)->acls, _obj, _acl, avl); \
89 _acl = avl_is_first(&(ses)->acls, &(_acl)->avl) ? NULL : \
90 avl_prev_element((_acl), avl))
92 #define uh_foreach_matching_acl(_acl, _ses, _obj, _func) \
93 uh_foreach_matching_acl_prefix(_acl, _ses, _obj, _func) \
94 if (!strncmp((_acl)->object, _obj, (_acl)->sort_len) && \
95 !fnmatch((_acl)->object, (_obj), FNM_NOESCAPE) && \
96 !fnmatch((_acl)->function, (_func), FNM_NOESCAPE))
99 rpc_random(char *dest)
101 unsigned char buf[16] = { 0 };
105 f = fopen("/dev/urandom", "r");
109 fread(buf, 1, sizeof(buf), f);
112 for (i = 0; i < sizeof(buf); i++)
113 sprintf(dest + (i<<1), "%02x", buf[i]);
117 rpc_session_dump_data(struct rpc_session *ses, struct blob_buf *b)
119 struct rpc_session_data *d;
121 avl_for_each_element(&ses->data, d, avl) {
122 blobmsg_add_field(b, blobmsg_type(d->attr), blobmsg_name(d->attr),
123 blobmsg_data(d->attr), blobmsg_data_len(d->attr));
128 rpc_session_dump_acls(struct rpc_session *ses, struct blob_buf *b)
130 struct rpc_session_acl *acl;
131 const char *lastobj = NULL;
134 avl_for_each_element(&ses->acls, acl, avl) {
135 if (!lastobj || strcmp(acl->object, lastobj))
137 if (c) blobmsg_close_array(b, c);
138 c = blobmsg_open_array(b, acl->object);
141 blobmsg_add_string(b, NULL, acl->function);
142 lastobj = acl->object;
145 if (c) blobmsg_close_array(b, c);
149 rpc_session_dump(struct rpc_session *ses,
150 struct ubus_context *ctx,
151 struct ubus_request_data *req)
155 blob_buf_init(&buf, 0);
157 blobmsg_add_string(&buf, "sid", ses->id);
158 blobmsg_add_u32(&buf, "timeout", ses->timeout);
159 blobmsg_add_u32(&buf, "expires", uloop_timeout_remaining(&ses->t) / 1000);
161 c = blobmsg_open_table(&buf, "acls");
162 rpc_session_dump_acls(ses, &buf);
163 blobmsg_close_table(&buf, c);
165 c = blobmsg_open_table(&buf, "data");
166 rpc_session_dump_data(ses, &buf);
167 blobmsg_close_table(&buf, c);
169 ubus_send_reply(ctx, req, buf.head);
173 rpc_touch_session(struct rpc_session *ses)
175 uloop_timeout_set(&ses->t, ses->timeout * 1000);
179 rpc_session_destroy(struct rpc_session *ses)
181 struct rpc_session_acl *acl, *nacl;
182 struct rpc_session_data *data, *ndata;
184 uloop_timeout_cancel(&ses->t);
185 avl_remove_all_elements(&ses->acls, acl, avl, nacl)
188 avl_remove_all_elements(&ses->data, data, avl, ndata)
191 avl_delete(&sessions, &ses->avl);
195 static void rpc_session_timeout(struct uloop_timeout *t)
197 struct rpc_session *ses;
199 ses = container_of(t, struct rpc_session, t);
200 rpc_session_destroy(ses);
203 static struct rpc_session *
204 rpc_session_create(int timeout)
206 struct rpc_session *ses;
208 ses = calloc(1, sizeof(*ses));
212 ses->timeout = timeout;
213 ses->avl.key = ses->id;
216 avl_insert(&sessions, &ses->avl);
217 avl_init(&ses->acls, avl_strcmp, true, NULL);
218 avl_init(&ses->data, avl_strcmp, false, NULL);
220 ses->t.cb = rpc_session_timeout;
221 rpc_touch_session(ses);
226 static struct rpc_session *
227 rpc_session_get(const char *id)
229 struct rpc_session *ses;
231 ses = avl_find_element(&sessions, id, ses, avl);
235 rpc_touch_session(ses);
240 rpc_handle_create(struct ubus_context *ctx, struct ubus_object *obj,
241 struct ubus_request_data *req, const char *method,
242 struct blob_attr *msg)
244 struct rpc_session *ses;
245 struct blob_attr *tb;
246 int timeout = RPC_DEFAULT_SESSION_TIMEOUT;
248 blobmsg_parse(&new_policy, 1, &tb, blob_data(msg), blob_len(msg));
250 timeout = blobmsg_get_u32(tb);
252 ses = rpc_session_create(timeout);
254 rpc_session_dump(ses, ctx, req);
260 rpc_handle_list(struct ubus_context *ctx, struct ubus_object *obj,
261 struct ubus_request_data *req, const char *method,
262 struct blob_attr *msg)
264 struct rpc_session *ses;
265 struct blob_attr *tb;
267 blobmsg_parse(&sid_policy, 1, &tb, blob_data(msg), blob_len(msg));
270 avl_for_each_element(&sessions, ses, avl)
271 rpc_session_dump(ses, ctx, req);
275 ses = rpc_session_get(blobmsg_data(tb));
277 return UBUS_STATUS_NOT_FOUND;
279 rpc_session_dump(ses, ctx, req);
285 uh_id_len(const char *str)
287 return strcspn(str, "*?[");
291 rpc_session_grant(struct rpc_session *ses, struct ubus_context *ctx,
292 const char *object, const char *function)
294 struct rpc_session_acl *acl;
295 char *new_obj, *new_func, *new_id;
298 if (!object || !function)
299 return UBUS_STATUS_INVALID_ARGUMENT;
301 uh_foreach_matching_acl_prefix(acl, ses, object, function) {
302 if (!strcmp(acl->object, object) &&
303 !strcmp(acl->function, function))
307 id_len = uh_id_len(object);
308 acl = calloc_a(sizeof(*acl),
309 &new_obj, strlen(object) + 1,
310 &new_func, strlen(function) + 1,
311 &new_id, id_len + 1);
314 return UBUS_STATUS_UNKNOWN_ERROR;
316 acl->object = strcpy(new_obj, object);
317 acl->function = strcpy(new_func, function);
318 acl->avl.key = strncpy(new_id, object, id_len);
319 avl_insert(&ses->acls, &acl->avl);
325 rpc_session_revoke(struct rpc_session *ses, struct ubus_context *ctx,
326 const char *object, const char *function)
328 struct rpc_session_acl *acl, *next;
332 if (!object && !function) {
333 avl_remove_all_elements(&ses->acls, acl, avl, next)
338 id_len = uh_id_len(object);
339 id = alloca(id_len + 1);
340 strncpy(id, object, id_len);
343 acl = avl_find_element(&ses->acls, id, acl, avl);
345 if (!avl_is_last(&ses->acls, &acl->avl))
346 next = avl_next_element(acl, avl);
350 if (strcmp(id, acl->avl.key) != 0)
353 if (!strcmp(acl->object, object) &&
354 !strcmp(acl->function, function)) {
355 avl_delete(&ses->acls, &acl->avl);
366 rpc_handle_acl(struct ubus_context *ctx, struct ubus_object *obj,
367 struct ubus_request_data *req, const char *method,
368 struct blob_attr *msg)
370 struct rpc_session *ses;
371 struct blob_attr *tb[__RPC_SA_MAX];
372 struct blob_attr *attr, *sattr;
373 const char *object, *function;
376 int (*cb)(struct rpc_session *ses, struct ubus_context *ctx,
377 const char *object, const char *function);
379 blobmsg_parse(acl_policy, __RPC_SA_MAX, tb, blob_data(msg), blob_len(msg));
382 return UBUS_STATUS_INVALID_ARGUMENT;
384 ses = rpc_session_get(blobmsg_data(tb[RPC_SA_SID]));
386 return UBUS_STATUS_NOT_FOUND;
388 if (!strcmp(method, "grant"))
389 cb = rpc_session_grant;
391 cb = rpc_session_revoke;
393 if (!tb[RPC_SA_OBJECTS])
394 return cb(ses, ctx, NULL, NULL);
396 blobmsg_for_each_attr(attr, tb[RPC_SA_OBJECTS], rem1) {
397 if (blob_id(attr) != BLOBMSG_TYPE_ARRAY)
403 blobmsg_for_each_attr(sattr, attr, rem2) {
404 if (blob_id(sattr) != BLOBMSG_TYPE_STRING)
408 object = blobmsg_data(sattr);
410 function = blobmsg_data(sattr);
415 if (object && function)
416 cb(ses, ctx, object, function);
423 rpc_session_acl_allowed(struct rpc_session *ses, const char *obj, const char *fun)
425 struct rpc_session_acl *acl;
427 uh_foreach_matching_acl(acl, ses, obj, fun)
434 rpc_handle_access(struct ubus_context *ctx, struct ubus_object *obj,
435 struct ubus_request_data *req, const char *method,
436 struct blob_attr *msg)
438 struct rpc_session *ses;
439 struct blob_attr *tb[__RPC_SP_MAX];
442 blobmsg_parse(perm_policy, __RPC_SP_MAX, tb, blob_data(msg), blob_len(msg));
444 if (!tb[RPC_SP_SID] || !tb[RPC_SP_OBJECT] || !tb[RPC_SP_FUNCTION])
445 return UBUS_STATUS_INVALID_ARGUMENT;
447 ses = rpc_session_get(blobmsg_data(tb[RPC_SP_SID]));
449 return UBUS_STATUS_NOT_FOUND;
451 allow = rpc_session_acl_allowed(ses,
452 blobmsg_data(tb[RPC_SP_OBJECT]),
453 blobmsg_data(tb[RPC_SP_FUNCTION]));
455 blob_buf_init(&buf, 0);
456 blobmsg_add_u8(&buf, "access", allow);
457 ubus_send_reply(ctx, req, buf.head);
463 rpc_handle_set(struct ubus_context *ctx, struct ubus_object *obj,
464 struct ubus_request_data *req, const char *method,
465 struct blob_attr *msg)
467 struct rpc_session *ses;
468 struct rpc_session_data *data;
469 struct blob_attr *tb[__RPC_SA_MAX];
470 struct blob_attr *attr;
473 blobmsg_parse(set_policy, __RPC_SS_MAX, tb, blob_data(msg), blob_len(msg));
475 if (!tb[RPC_SS_SID] || !tb[RPC_SS_VALUES])
476 return UBUS_STATUS_INVALID_ARGUMENT;
478 ses = rpc_session_get(blobmsg_data(tb[RPC_SS_SID]));
480 return UBUS_STATUS_NOT_FOUND;
482 blobmsg_for_each_attr(attr, tb[RPC_SS_VALUES], rem) {
483 if (!blobmsg_name(attr)[0])
486 data = avl_find_element(&ses->data, blobmsg_name(attr), data, avl);
488 avl_delete(&ses->data, &data->avl);
492 data = calloc(1, sizeof(*data) + blob_pad_len(attr));
496 memcpy(data->attr, attr, blob_pad_len(attr));
497 data->avl.key = blobmsg_name(data->attr);
498 avl_insert(&ses->data, &data->avl);
505 rpc_handle_get(struct ubus_context *ctx, struct ubus_object *obj,
506 struct ubus_request_data *req, const char *method,
507 struct blob_attr *msg)
509 struct rpc_session *ses;
510 struct rpc_session_data *data;
511 struct blob_attr *tb[__RPC_SA_MAX];
512 struct blob_attr *attr;
516 blobmsg_parse(get_policy, __RPC_SG_MAX, tb, blob_data(msg), blob_len(msg));
519 return UBUS_STATUS_INVALID_ARGUMENT;
521 ses = rpc_session_get(blobmsg_data(tb[RPC_SG_SID]));
523 return UBUS_STATUS_NOT_FOUND;
525 blob_buf_init(&buf, 0);
526 c = blobmsg_open_table(&buf, "values");
529 blobmsg_for_each_attr(attr, tb[RPC_SG_KEYS], rem) {
530 if (blob_id(attr) != BLOBMSG_TYPE_STRING)
533 data = avl_find_element(&ses->data, blobmsg_data(attr), data, avl);
537 blobmsg_add_field(&buf, blobmsg_type(data->attr),
538 blobmsg_name(data->attr),
539 blobmsg_data(data->attr),
540 blobmsg_data_len(data->attr));
543 rpc_session_dump_data(ses, &buf);
545 blobmsg_close_table(&buf, c);
546 ubus_send_reply(ctx, req, buf.head);
552 rpc_handle_unset(struct ubus_context *ctx, struct ubus_object *obj,
553 struct ubus_request_data *req, const char *method,
554 struct blob_attr *msg)
556 struct rpc_session *ses;
557 struct rpc_session_data *data, *ndata;
558 struct blob_attr *tb[__RPC_SA_MAX];
559 struct blob_attr *attr;
562 blobmsg_parse(get_policy, __RPC_SG_MAX, tb, blob_data(msg), blob_len(msg));
565 return UBUS_STATUS_INVALID_ARGUMENT;
567 ses = rpc_session_get(blobmsg_data(tb[RPC_SG_SID]));
569 return UBUS_STATUS_NOT_FOUND;
571 if (!tb[RPC_SG_KEYS]) {
572 avl_remove_all_elements(&ses->data, data, avl, ndata)
577 blobmsg_for_each_attr(attr, tb[RPC_SG_KEYS], rem) {
578 if (blob_id(attr) != BLOBMSG_TYPE_STRING)
581 data = avl_find_element(&ses->data, blobmsg_data(attr), data, avl);
585 avl_delete(&ses->data, &data->avl);
593 rpc_handle_destroy(struct ubus_context *ctx, struct ubus_object *obj,
594 struct ubus_request_data *req, const char *method,
595 struct blob_attr *msg)
597 struct rpc_session *ses;
598 struct blob_attr *tb;
600 blobmsg_parse(&sid_policy, 1, &tb, blob_data(msg), blob_len(msg));
603 return UBUS_STATUS_INVALID_ARGUMENT;
605 ses = rpc_session_get(blobmsg_data(tb));
607 return UBUS_STATUS_NOT_FOUND;
609 rpc_session_destroy(ses);
614 int rpc_session_api_init(struct ubus_context *ctx)
616 static const struct ubus_method session_methods[] = {
617 UBUS_METHOD("create", rpc_handle_create, &new_policy),
618 UBUS_METHOD("list", rpc_handle_list, &sid_policy),
619 UBUS_METHOD("grant", rpc_handle_acl, acl_policy),
620 UBUS_METHOD("revoke", rpc_handle_acl, acl_policy),
621 UBUS_METHOD("access", rpc_handle_access, perm_policy),
622 UBUS_METHOD("set", rpc_handle_set, set_policy),
623 UBUS_METHOD("get", rpc_handle_get, get_policy),
624 UBUS_METHOD("unset", rpc_handle_unset, get_policy),
625 UBUS_METHOD("destroy", rpc_handle_destroy, &sid_policy),
628 static struct ubus_object_type session_type =
629 UBUS_OBJECT_TYPE("luci-rpc-session", session_methods);
631 static struct ubus_object obj = {
633 .type = &session_type,
634 .methods = session_methods,
635 .n_methods = ARRAY_SIZE(session_methods),
638 avl_init(&sessions, avl_strcmp, false, NULL);
640 return ubus_add_object(ctx, &obj);