1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
|
/*
* Copyright (C) 2015 John Cripin <blogic@openwrt.org>
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU Lesser General Public License version 2.1
* as published by the Free Software Foundation
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*/
#include <unistd.h>
#include <libubox/blob.h>
#include <libubox/blobmsg.h>
#include "libubus.h"
#include <libubox/avl-cmp.h>
static struct ubus_event_handler acl_event;
static struct ubus_request acl_req;
static struct blob_attr *acl_blob;
static bool acl_query_active;
static bool acl_query_deferred;
static int acl_cmp(const void *k1, const void *k2, void *ptr)
{
const struct ubus_acl_key *key1 = k1;
const struct ubus_acl_key *key2 = k2;
int ret = 0;
if (key1->user && key2->user)
ret = strcmp(key1->user, key2->user);
if (ret)
return ret;
if (key1->group && key2->group)
ret = strcmp(key1->group, key2->group);
if (ret)
return ret;
return strcmp(key1->object, key2->object);
}
AVL_TREE(acl_objects, acl_cmp, true, NULL);
enum {
ACL_OBJ_OBJECT,
ACL_OBJ_USER,
ACL_OBJ_GROUP,
ACL_OBJ_ACL,
__ACL_OBJ_MAX
};
static const struct blobmsg_policy acl_obj_policy[__ACL_OBJ_MAX] = {
[ACL_OBJ_OBJECT] = { .name = "obj", .type = BLOBMSG_TYPE_STRING },
[ACL_OBJ_USER] = { .name = "user", .type = BLOBMSG_TYPE_STRING },
[ACL_OBJ_GROUP] = { .name = "group", .type = BLOBMSG_TYPE_STRING },
[ACL_OBJ_ACL] = { .name = "acl", .type = BLOBMSG_TYPE_TABLE },
};
static void
acl_add(struct blob_attr *obj)
{
struct blob_attr *tb[__ACL_OBJ_MAX];
struct acl_object *acl;
blobmsg_parse(acl_obj_policy, __ACL_OBJ_MAX, tb, blobmsg_data(obj),
blobmsg_data_len(obj));
if (!tb[ACL_OBJ_OBJECT] || !tb[ACL_OBJ_ACL])
return;
if (!tb[ACL_OBJ_USER] && !tb[ACL_OBJ_GROUP])
return;
acl = calloc(1, sizeof(*acl));
if (!acl)
return;
acl->avl.key = &acl->key;
acl->key.object = blobmsg_get_string(tb[ACL_OBJ_OBJECT]);
acl->key.user = blobmsg_get_string(tb[ACL_OBJ_USER]);
acl->key.group = blobmsg_get_string(tb[ACL_OBJ_GROUP]);
acl->acl = tb[ACL_OBJ_ACL];
avl_insert(&acl_objects, &acl->avl);
}
enum {
ACL_POLICY_SEQ,
ACL_POLICY_ACL,
__ACL_POLICY_MAX
};
static const struct blobmsg_policy acl_policy[__ACL_POLICY_MAX] = {
[ACL_POLICY_SEQ] = { .name = "seq", .type = BLOBMSG_TYPE_INT32 },
[ACL_POLICY_ACL] = { .name = "acl", .type = BLOBMSG_TYPE_ARRAY },
};
static void acl_recv_cb(struct ubus_request *req,
int type, struct blob_attr *msg)
{
struct blob_attr *tb[__ACL_POLICY_MAX];
struct blob_attr *cur;
size_t rem;
struct blob_attr *new_blob = blob_memdup(msg);
if (!new_blob)
return;
if (acl_blob) {
struct acl_object *p, *q;
avl_for_each_element_safe(&acl_objects, p, avl, q) {
avl_delete(&acl_objects, &p->avl);
free(p);
}
free(acl_blob);
}
acl_blob = new_blob;
blobmsg_parse(acl_policy, __ACL_POLICY_MAX, tb, blobmsg_data(acl_blob),
blobmsg_data_len(acl_blob));
if (!tb[ACL_POLICY_SEQ] && !tb[ACL_POLICY_ACL])
return;
blobmsg_for_each_attr(cur, tb[ACL_POLICY_ACL], rem)
acl_add(cur);
}
static void acl_query(struct ubus_context *ctx);
static void acl_query_complete_cb(struct ubus_request *req, int ret)
{
struct ubus_context *ctx = req->ctx;
acl_query_active = false;
if (!acl_query_deferred)
return;
acl_query_deferred = false;
acl_query(ctx);
}
static void acl_query(struct ubus_context *ctx)
{
/*
* The same static acl_req is reused for every refresh. Starting a new
* query while the previous one is still linked in ctx->requests would
* have ubus_invoke_async() memset() a live list node and corrupt the
* request list. Defer the refresh until the in-flight query completes;
* the deferred run then fetches the latest ACL state.
*/
if (acl_query_active) {
acl_query_deferred = true;
return;
}
acl_query_active = true;
ubus_invoke_async(ctx, UBUS_SYSTEM_OBJECT_ACL, "query", NULL, &acl_req);
acl_req.data_cb = acl_recv_cb;
acl_req.complete_cb = acl_query_complete_cb;
ubus_complete_request_async(ctx, &acl_req);
}
static void acl_subscribe_cb(struct ubus_context *ctx, struct ubus_event_handler *ev,
const char *type, struct blob_attr *msg)
{
if (strcmp(type, "ubus.acl.sequence"))
return;
acl_query(ctx);
}
int ubus_register_acl(struct ubus_context *ctx)
{
int ret;
acl_event.cb = acl_subscribe_cb;
ret = ubus_register_event_handler(ctx, &acl_event, "ubus.acl.sequence");
if (!ret)
acl_query(ctx);
return ret;
}
|