1/* 2 * Copyright (c) 2006 Kungliga Tekniska Högskolan 3 * (Royal Institute of Technology, Stockholm, Sweden). 4 * All rights reserved. 5 * 6 * Redistribution and use in source and binary forms, with or without 7 * modification, are permitted provided that the following conditions 8 * are met: 9 * 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 13 * 2. Redistributions in binary form must reproduce the above copyright 14 * notice, this list of conditions and the following disclaimer in the 15 * documentation and/or other materials provided with the distribution. 16 * 17 * 3. Neither the name of the Institute nor the names of its contributors 18 * may be used to endorse or promote products derived from this software 19 * without specific prior written permission. 20 * 21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31 * SUCH DAMAGE. 32 */ 33 34#include "hx_locl.h" 35#include <dirent.h> 36 37#ifdef HEIM_KS_DIR 38 39/* 40 * The DIR keyset module is strange compared to the other modules 41 * since it does lazy evaluation and really doesn't keep any local 42 * state except for the directory iteration and cert iteration of 43 * files. DIR ignores most errors so that the consumer doesn't get 44 * failes for stray files in directories. 45 */ 46 47struct dircursor { 48 DIR *dir; 49 hx509_certs certs; 50 void *iter; 51}; 52 53/* 54 * 55 */ 56 57static int 58dir_init(hx509_context context, 59 hx509_certs certs, void **data, int flags, 60 const char *residue, hx509_lock lock) 61{ 62 *data = NULL; 63 64 { 65 struct stat sb; 66 int ret; 67 68 ret = stat(residue, &sb); 69 if (ret == -1) { 70 hx509_set_error_string(context, 0, ENOENT, 71 "No such file %s", residue); 72 return ENOENT; 73 } 74 75 if (!S_ISDIR(sb.st_mode)) { 76 hx509_set_error_string(context, 0, ENOTDIR, 77 "%s is not a directory", residue); 78 return ENOTDIR; 79 } 80 } 81 82 *data = strdup(residue); 83 if (*data == NULL) { 84 hx509_clear_error_string(context); 85 return ENOMEM; 86 } 87 88 return 0; 89} 90 91static int 92dir_free(hx509_certs certs, void *data) 93{ 94 free(data); 95 return 0; 96} 97 98static int 99dir_iter_start(hx509_context context, 100 hx509_certs certs, void *data, void **cursor) 101{ 102 struct dircursor *d; 103 104 *cursor = NULL; 105 106 d = calloc(1, sizeof(*d)); 107 if (d == NULL) { 108 hx509_clear_error_string(context); 109 return ENOMEM; 110 } 111 112 d->dir = opendir(data); 113 if (d->dir == NULL) { 114 hx509_clear_error_string(context); 115 free(d); 116 return errno; 117 } 118 rk_cloexec_dir(d->dir); 119 d->certs = NULL; 120 d->iter = NULL; 121 122 *cursor = d; 123 return 0; 124} 125 126static int 127dir_iter(hx509_context context, 128 hx509_certs certs, void *data, void *iter, hx509_cert *cert) 129{ 130 struct dircursor *d = iter; 131 int ret = 0; 132 133 *cert = NULL; 134 135 do { 136 struct dirent *dir; 137 char *fn; 138 139 if (d->certs) { 140 ret = hx509_certs_next_cert(context, d->certs, d->iter, cert); 141 if (ret) { 142 hx509_certs_end_seq(context, d->certs, d->iter); 143 d->iter = NULL; 144 hx509_certs_free(&d->certs); 145 return ret; 146 } 147 if (*cert) { 148 ret = 0; 149 break; 150 } 151 hx509_certs_end_seq(context, d->certs, d->iter); 152 d->iter = NULL; 153 hx509_certs_free(&d->certs); 154 } 155 156 dir = readdir(d->dir); 157 if (dir == NULL) { 158 ret = 0; 159 break; 160 } 161 if (strcmp(dir->d_name, ".") == 0 || strcmp(dir->d_name, "..") == 0) 162 continue; 163 164 if (asprintf(&fn, "FILE:%s/%s", (char *)data, dir->d_name) == -1) 165 return ENOMEM; 166 167 ret = hx509_certs_init(context, fn, 0, NULL, &d->certs); 168 if (ret == 0) { 169 170 ret = hx509_certs_start_seq(context, d->certs, &d->iter); 171 if (ret) 172 hx509_certs_free(&d->certs); 173 } 174 /* ignore errors */ 175 if (ret) { 176 d->certs = NULL; 177 ret = 0; 178 } 179 180 free(fn); 181 } while(ret == 0); 182 183 return ret; 184} 185 186 187static int 188dir_iter_end(hx509_context context, 189 hx509_certs certs, 190 void *data, 191 void *cursor) 192{ 193 struct dircursor *d = cursor; 194 195 if (d->certs) { 196 hx509_certs_end_seq(context, d->certs, d->iter); 197 d->iter = NULL; 198 hx509_certs_free(&d->certs); 199 } 200 closedir(d->dir); 201 free(d); 202 return 0; 203} 204 205 206static struct hx509_keyset_ops keyset_dir = { 207 "DIR", 208 0, 209 dir_init, 210 NULL, 211 dir_free, 212 NULL, 213 NULL, 214 dir_iter_start, 215 dir_iter, 216 dir_iter_end 217}; 218 219#endif /* HEIM_KS_DIR */ 220 221void 222_hx509_ks_dir_register(hx509_context context) 223{ 224#ifdef HEIM_KS_DIR 225 _hx509_ks_register(context, &keyset_dir); 226#endif 227} 228