auth.c 5.65 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
/*
 *  GRUB  --  GRand Unified Bootloader
 *  Copyright (C) 2009  Free Software Foundation, Inc.
 *
 *  GRUB is free software: you can redistribute it and/or modify
 *  it under the terms of the GNU General Public License as published by
 *  the Free Software Foundation, either version 3 of the License, or
 *  (at your option) any later version.
 *
 *  GRUB is distributed in the hope that it will be useful,
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 *  GNU General Public License for more details.
 *
 *  You should have received a copy of the GNU General Public License
 *  along with GRUB.  If not, see <http://www.gnu.org/licenses/>.
 */

#include <grub/auth.h>
#include <grub/list.h>
#include <grub/mm.h>
#include <grub/misc.h>
#include <grub/env.h>
#include <grub/normal.h>
25
#include <grub/time.h>
26
#include <grub/i18n.h>
27 28 29 30

struct grub_auth_user
{
  struct grub_auth_user *next;
31
  struct grub_auth_user **prev;
32 33 34 35 36 37
  char *name;
  grub_auth_callback_t callback;
  void *arg;
  int authenticated;
};

38
static struct grub_auth_user *users = NULL;
39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76

grub_err_t
grub_auth_register_authentication (const char *user,
				   grub_auth_callback_t callback,
				   void *arg)
{
  struct grub_auth_user *cur;

  cur = grub_named_list_find (GRUB_AS_NAMED_LIST (users), user);
  if (!cur)
    cur = grub_zalloc (sizeof (*cur));
  if (!cur)
    return grub_errno;
  cur->callback = callback;
  cur->arg = arg;
  if (! cur->name)
    {
      cur->name = grub_strdup (user);
      if (!cur->name)
	{
	  grub_free (cur);
	  return grub_errno;
	}
      grub_list_push (GRUB_AS_LIST_P (&users), GRUB_AS_LIST (cur));
    }
  return GRUB_ERR_NONE;
}

grub_err_t
grub_auth_unregister_authentication (const char *user)
{
  struct grub_auth_user *cur;
  cur = grub_named_list_find (GRUB_AS_NAMED_LIST (users), user);
  if (!cur)
    return grub_error (GRUB_ERR_BAD_ARGUMENT, "user '%s' not found", user);
  if (!cur->authenticated)
    {
      grub_free (cur->name);
77
      grub_list_remove (GRUB_AS_LIST (cur));
78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124
      grub_free (cur);
    }
  else
    {
      cur->callback = NULL;
      cur->arg = NULL;
    }
  return GRUB_ERR_NONE;
}

grub_err_t
grub_auth_authenticate (const char *user)
{
  struct grub_auth_user *cur;

  cur = grub_named_list_find (GRUB_AS_NAMED_LIST (users), user);
  if (!cur)
    cur = grub_zalloc (sizeof (*cur));
  if (!cur)
    return grub_errno;

  cur->authenticated = 1;

  if (! cur->name)
    {
      cur->name = grub_strdup (user);
      if (!cur->name)
	{
	  grub_free (cur);
	  return grub_errno;
	}
      grub_list_push (GRUB_AS_LIST_P (&users), GRUB_AS_LIST (cur));
    }

  return GRUB_ERR_NONE;
}

grub_err_t
grub_auth_deauthenticate (const char *user)
{
  struct grub_auth_user *cur;
  cur = grub_named_list_find (GRUB_AS_NAMED_LIST (users), user);
  if (!cur)
    return grub_error (GRUB_ERR_BAD_ARGUMENT, "user '%s' not found", user);
  if (!cur->callback)
    {
      grub_free (cur->name);
125
      grub_list_remove (GRUB_AS_LIST (cur));
126 127 128 129 130 131 132 133 134 135 136
      grub_free (cur);
    }
  else
    cur->authenticated = 0;
  return GRUB_ERR_NONE;
}

static int
is_authenticated (const char *userlist)
{
  const char *superusers;
137
  struct grub_auth_user *user;
138 139 140 141 142 143

  superusers = grub_env_get ("superusers");

  if (!superusers)
    return 1;

144
  FOR_LIST_ELEMENTS (user, users)
145 146 147 148 149 150 151 152 153 154
    {
      if (!(user->authenticated))
	continue;

      if ((userlist && grub_strword (userlist, user->name))
	  || grub_strword (superusers, user->name))
	return 1;
    }

  return 0;
155 156
}

157 158 159 160 161 162 163 164
static int
grub_username_get (char buf[], unsigned buf_size)
{
  unsigned cur_len = 0;
  int key;

  while (1)
    {
165
      key = grub_getkey (); 
166 167 168 169 170 171 172 173 174 175 176
      if (key == '\n' || key == '\r')
	break;

      if (key == '\e')
	{
	  cur_len = 0;
	  break;
	}

      if (key == '\b')
	{
177 178 179
	  if (cur_len)
	    {
	      cur_len--;
180
	      grub_printf ("\b \b");
181
	    }
182 183 184 185 186 187 188 189 190
	  continue;
	}

      if (!grub_isprint (key))
	continue;

      if (cur_len + 2 < buf_size)
	{
	  buf[cur_len++] = key;
191
	  grub_printf ("%c", key);
192 193 194 195 196
	}
    }

  grub_memset (buf + cur_len, 0, buf_size - cur_len);

197
  grub_xputs ("\n");
198 199 200 201 202
  grub_refresh ();

  return (key != '\e');
}

203 204 205 206 207
grub_err_t
grub_auth_check_authentication (const char *userlist)
{
  char login[1024];
  struct grub_auth_user *cur = NULL;
208
  static unsigned long punishment_delay = 1;
209
  char entered[GRUB_AUTH_MAX_PASSLEN];
210
  struct grub_auth_user *user;
211 212 213 214

  grub_memset (login, 0, sizeof (login));

  if (is_authenticated (userlist))
215 216 217 218
    {
      punishment_delay = 1;
      return GRUB_ERR_NONE;
    }
219

220 221 222
  grub_puts_ (N_("Enter username: "));

  if (!grub_username_get (login, sizeof (login) - 1))
223
    goto access_denied;
224

225
  grub_puts_ (N_("Enter password: "));
226

227 228
  if (!grub_password_get (entered, GRUB_AUTH_MAX_PASSLEN))
    goto access_denied;
229

230
  FOR_LIST_ELEMENTS (user, users)
231 232 233 234
    {
      if (grub_strcmp (login, user->name) == 0)
	cur = user;
    }
235

236 237
  if (!cur || ! cur->callback)
    goto access_denied;
238

239
  cur->callback (login, entered, cur->arg);
240
  if (is_authenticated (userlist))
241 242 243 244 245 246 247 248 249 250 251
    {
      punishment_delay = 1;
      return GRUB_ERR_NONE;
    }

 access_denied:
  grub_sleep (punishment_delay);

  if (punishment_delay < GRUB_ULONG_MAX / 2)
    punishment_delay *= 2;

252 253
  return GRUB_ACCESS_DENIED;
}
254 255 256 257 258 259 260 261 262 263 264 265 266 267 268

static grub_err_t
grub_cmd_authenticate (struct grub_command *cmd __attribute__ ((unused)),
		       int argc, char **args)
{
  return grub_auth_check_authentication ((argc >= 1) ? args[0] : "");
}

static grub_command_t cmd;

void
grub_normal_auth_init (void)
{
  cmd = grub_register_command ("authenticate",
			       grub_cmd_authenticate,
269 270
			       N_("[USERLIST]"),
			       N_("Check whether user is in USERLIST."));
271 272 273 274 275 276 277 278

}

void
grub_normal_auth_fini (void)
{
  grub_unregister_command (cmd);
}