hdb-mdb.c revision 1.2.14.2 1 1.2.14.2 snj /* $NetBSD: hdb-mdb.c,v 1.2.14.2 2017/08/20 05:44:19 snj Exp $ */
2 1.2.14.2 snj
3 1.2.14.2 snj /*
4 1.2.14.2 snj * Copyright (c) 1997 - 2006 Kungliga Tekniska Hgskolan
5 1.2.14.2 snj * (Royal Institute of Technology, Stockholm, Sweden).
6 1.2.14.2 snj * Copyright (c) 2011 - Howard Chu, Symas Corp.
7 1.2.14.2 snj * All rights reserved.
8 1.2.14.2 snj *
9 1.2.14.2 snj * Redistribution and use in source and binary forms, with or without
10 1.2.14.2 snj * modification, are permitted provided that the following conditions
11 1.2.14.2 snj * are met:
12 1.2.14.2 snj *
13 1.2.14.2 snj * 1. Redistributions of source code must retain the above copyright
14 1.2.14.2 snj * notice, this list of conditions and the following disclaimer.
15 1.2.14.2 snj *
16 1.2.14.2 snj * 2. Redistributions in binary form must reproduce the above copyright
17 1.2.14.2 snj * notice, this list of conditions and the following disclaimer in the
18 1.2.14.2 snj * documentation and/or other materials provided with the distribution.
19 1.2.14.2 snj *
20 1.2.14.2 snj * 3. Neither the name of the Institute nor the names of its contributors
21 1.2.14.2 snj * may be used to endorse or promote products derived from this software
22 1.2.14.2 snj * without specific prior written permission.
23 1.2.14.2 snj *
24 1.2.14.2 snj * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
25 1.2.14.2 snj * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 1.2.14.2 snj * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
27 1.2.14.2 snj * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
28 1.2.14.2 snj * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
29 1.2.14.2 snj * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
30 1.2.14.2 snj * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
31 1.2.14.2 snj * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
32 1.2.14.2 snj * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
33 1.2.14.2 snj * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34 1.2.14.2 snj * SUCH DAMAGE.
35 1.2.14.2 snj */
36 1.2.14.2 snj
37 1.2.14.2 snj #include "hdb_locl.h"
38 1.2.14.2 snj
39 1.2.14.2 snj #if HAVE_LMDB
40 1.2.14.2 snj
41 1.2.14.2 snj /* LMDB */
42 1.2.14.2 snj
43 1.2.14.2 snj #include <lmdb.h>
44 1.2.14.2 snj
45 1.2.14.2 snj #define KILO 1024
46 1.2.14.2 snj
47 1.2.14.2 snj typedef struct mdb_info {
48 1.2.14.2 snj MDB_env *e;
49 1.2.14.2 snj MDB_txn *t;
50 1.2.14.2 snj MDB_dbi d;
51 1.2.14.2 snj MDB_cursor *c;
52 1.2.14.2 snj } mdb_info;
53 1.2.14.2 snj
54 1.2.14.2 snj static krb5_error_code
55 1.2.14.2 snj DB_close(krb5_context context, HDB *db)
56 1.2.14.2 snj {
57 1.2.14.2 snj mdb_info *mi = (mdb_info *)db->hdb_db;
58 1.2.14.2 snj
59 1.2.14.2 snj mdb_cursor_close(mi->c);
60 1.2.14.2 snj mdb_txn_abort(mi->t);
61 1.2.14.2 snj mdb_env_close(mi->e);
62 1.2.14.2 snj mi->c = 0;
63 1.2.14.2 snj mi->t = 0;
64 1.2.14.2 snj mi->e = 0;
65 1.2.14.2 snj return 0;
66 1.2.14.2 snj }
67 1.2.14.2 snj
68 1.2.14.2 snj static krb5_error_code
69 1.2.14.2 snj DB_destroy(krb5_context context, HDB *db)
70 1.2.14.2 snj {
71 1.2.14.2 snj krb5_error_code ret;
72 1.2.14.2 snj
73 1.2.14.2 snj ret = hdb_clear_master_key (context, db);
74 1.2.14.2 snj free(db->hdb_name);
75 1.2.14.2 snj free(db->hdb_db);
76 1.2.14.2 snj free(db);
77 1.2.14.2 snj return ret;
78 1.2.14.2 snj }
79 1.2.14.2 snj
80 1.2.14.2 snj static krb5_error_code
81 1.2.14.2 snj DB_lock(krb5_context context, HDB *db, int operation)
82 1.2.14.2 snj {
83 1.2.14.2 snj db->lock_count++;
84 1.2.14.2 snj return 0;
85 1.2.14.2 snj }
86 1.2.14.2 snj
87 1.2.14.2 snj static krb5_error_code
88 1.2.14.2 snj DB_unlock(krb5_context context, HDB *db)
89 1.2.14.2 snj {
90 1.2.14.2 snj if (db->lock_count > 1) {
91 1.2.14.2 snj db->lock_count--;
92 1.2.14.2 snj return 0;
93 1.2.14.2 snj }
94 1.2.14.2 snj heim_assert(db->lock_count == 1, "HDB lock/unlock sequence does not match");
95 1.2.14.2 snj db->lock_count--;
96 1.2.14.2 snj return 0;
97 1.2.14.2 snj }
98 1.2.14.2 snj
99 1.2.14.2 snj
100 1.2.14.2 snj static krb5_error_code
101 1.2.14.2 snj DB_seq(krb5_context context, HDB *db,
102 1.2.14.2 snj unsigned flags, hdb_entry_ex *entry, int flag)
103 1.2.14.2 snj {
104 1.2.14.2 snj mdb_info *mi = db->hdb_db;
105 1.2.14.2 snj MDB_val key, value;
106 1.2.14.2 snj krb5_data key_data, data;
107 1.2.14.2 snj int code;
108 1.2.14.2 snj
109 1.2.14.2 snj key.mv_size = 0;
110 1.2.14.2 snj value.mv_size = 0;
111 1.2.14.2 snj code = mdb_cursor_get(mi->c, &key, &value, flag);
112 1.2.14.2 snj if (code == MDB_NOTFOUND)
113 1.2.14.2 snj return HDB_ERR_NOENTRY;
114 1.2.14.2 snj if (code)
115 1.2.14.2 snj return code;
116 1.2.14.2 snj
117 1.2.14.2 snj key_data.data = key.mv_data;
118 1.2.14.2 snj key_data.length = key.mv_size;
119 1.2.14.2 snj data.data = value.mv_data;
120 1.2.14.2 snj data.length = value.mv_size;
121 1.2.14.2 snj memset(entry, 0, sizeof(*entry));
122 1.2.14.2 snj if (hdb_value2entry(context, &data, &entry->entry))
123 1.2.14.2 snj return DB_seq(context, db, flags, entry, MDB_NEXT);
124 1.2.14.2 snj if (db->hdb_master_key_set && (flags & HDB_F_DECRYPT)) {
125 1.2.14.2 snj code = hdb_unseal_keys (context, db, &entry->entry);
126 1.2.14.2 snj if (code)
127 1.2.14.2 snj hdb_free_entry (context, entry);
128 1.2.14.2 snj }
129 1.2.14.2 snj if (entry->entry.principal == NULL) {
130 1.2.14.2 snj entry->entry.principal = malloc(sizeof(*entry->entry.principal));
131 1.2.14.2 snj if (entry->entry.principal == NULL) {
132 1.2.14.2 snj hdb_free_entry (context, entry);
133 1.2.14.2 snj krb5_set_error_message(context, ENOMEM, "malloc: out of memory");
134 1.2.14.2 snj return ENOMEM;
135 1.2.14.2 snj } else {
136 1.2.14.2 snj hdb_key2principal(context, &key_data, entry->entry.principal);
137 1.2.14.2 snj }
138 1.2.14.2 snj }
139 1.2.14.2 snj return 0;
140 1.2.14.2 snj }
141 1.2.14.2 snj
142 1.2.14.2 snj
143 1.2.14.2 snj static krb5_error_code
144 1.2.14.2 snj DB_firstkey(krb5_context context, HDB *db, unsigned flags, hdb_entry_ex *entry)
145 1.2.14.2 snj {
146 1.2.14.2 snj mdb_info *mi = db->hdb_db;
147 1.2.14.2 snj int code;
148 1.2.14.2 snj
149 1.2.14.2 snj /* Always start with a fresh cursor to pick up latest DB state */
150 1.2.14.2 snj if (mi->t)
151 1.2.14.2 snj mdb_txn_abort(mi->t);
152 1.2.14.2 snj
153 1.2.14.2 snj code = mdb_txn_begin(mi->e, NULL, MDB_RDONLY, &mi->t);
154 1.2.14.2 snj if (code)
155 1.2.14.2 snj return code;
156 1.2.14.2 snj
157 1.2.14.2 snj code = mdb_cursor_open(mi->t, mi->d, &mi->c);
158 1.2.14.2 snj if (code)
159 1.2.14.2 snj return code;
160 1.2.14.2 snj
161 1.2.14.2 snj return DB_seq(context, db, flags, entry, MDB_FIRST);
162 1.2.14.2 snj }
163 1.2.14.2 snj
164 1.2.14.2 snj
165 1.2.14.2 snj static krb5_error_code
166 1.2.14.2 snj DB_nextkey(krb5_context context, HDB *db, unsigned flags, hdb_entry_ex *entry)
167 1.2.14.2 snj {
168 1.2.14.2 snj return DB_seq(context, db, flags, entry, MDB_NEXT);
169 1.2.14.2 snj }
170 1.2.14.2 snj
171 1.2.14.2 snj static krb5_error_code
172 1.2.14.2 snj DB_rename(krb5_context context, HDB *db, const char *new_name)
173 1.2.14.2 snj {
174 1.2.14.2 snj int ret;
175 1.2.14.2 snj char *old, *new;
176 1.2.14.2 snj
177 1.2.14.2 snj if (strncmp(new_name, "mdb:", sizeof("mdb:") - 1) == 0)
178 1.2.14.2 snj new_name += sizeof("mdb:") - 1;
179 1.2.14.2 snj else if (strncmp(new_name, "lmdb:", sizeof("lmdb:") - 1) == 0)
180 1.2.14.2 snj new_name += sizeof("lmdb:") - 1;
181 1.2.14.2 snj if (asprintf(&old, "%s.mdb", db->hdb_name) == -1)
182 1.2.14.2 snj return ENOMEM;
183 1.2.14.2 snj if (asprintf(&new, "%s.mdb", new_name) == -1) {
184 1.2.14.2 snj free(old);
185 1.2.14.2 snj return ENOMEM;
186 1.2.14.2 snj }
187 1.2.14.2 snj ret = rename(old, new);
188 1.2.14.2 snj free(old);
189 1.2.14.2 snj free(new);
190 1.2.14.2 snj if(ret)
191 1.2.14.2 snj return errno;
192 1.2.14.2 snj
193 1.2.14.2 snj free(db->hdb_name);
194 1.2.14.2 snj db->hdb_name = strdup(new_name);
195 1.2.14.2 snj return 0;
196 1.2.14.2 snj }
197 1.2.14.2 snj
198 1.2.14.2 snj static krb5_error_code
199 1.2.14.2 snj DB__get(krb5_context context, HDB *db, krb5_data key, krb5_data *reply)
200 1.2.14.2 snj {
201 1.2.14.2 snj mdb_info *mi = (mdb_info*)db->hdb_db;
202 1.2.14.2 snj MDB_txn *txn;
203 1.2.14.2 snj MDB_val k, v;
204 1.2.14.2 snj int code;
205 1.2.14.2 snj
206 1.2.14.2 snj k.mv_data = key.data;
207 1.2.14.2 snj k.mv_size = key.length;
208 1.2.14.2 snj
209 1.2.14.2 snj code = mdb_txn_begin(mi->e, NULL, MDB_RDONLY, &txn);
210 1.2.14.2 snj if (code)
211 1.2.14.2 snj return code;
212 1.2.14.2 snj
213 1.2.14.2 snj code = mdb_get(txn, mi->d, &k, &v);
214 1.2.14.2 snj if (code == 0)
215 1.2.14.2 snj krb5_data_copy(reply, v.mv_data, v.mv_size);
216 1.2.14.2 snj mdb_txn_abort(txn);
217 1.2.14.2 snj if(code == MDB_NOTFOUND)
218 1.2.14.2 snj return HDB_ERR_NOENTRY;
219 1.2.14.2 snj return code;
220 1.2.14.2 snj }
221 1.2.14.2 snj
222 1.2.14.2 snj static krb5_error_code
223 1.2.14.2 snj DB__put(krb5_context context, HDB *db, int replace,
224 1.2.14.2 snj krb5_data key, krb5_data value)
225 1.2.14.2 snj {
226 1.2.14.2 snj mdb_info *mi = (mdb_info*)db->hdb_db;
227 1.2.14.2 snj MDB_txn *txn;
228 1.2.14.2 snj MDB_val k, v;
229 1.2.14.2 snj int code;
230 1.2.14.2 snj
231 1.2.14.2 snj k.mv_data = key.data;
232 1.2.14.2 snj k.mv_size = key.length;
233 1.2.14.2 snj v.mv_data = value.data;
234 1.2.14.2 snj v.mv_size = value.length;
235 1.2.14.2 snj
236 1.2.14.2 snj code = mdb_txn_begin(mi->e, NULL, 0, &txn);
237 1.2.14.2 snj if (code)
238 1.2.14.2 snj return code;
239 1.2.14.2 snj
240 1.2.14.2 snj code = mdb_put(txn, mi->d, &k, &v, replace ? 0 : MDB_NOOVERWRITE);
241 1.2.14.2 snj if (code)
242 1.2.14.2 snj mdb_txn_abort(txn);
243 1.2.14.2 snj else
244 1.2.14.2 snj code = mdb_txn_commit(txn);
245 1.2.14.2 snj if(code == MDB_KEYEXIST)
246 1.2.14.2 snj return HDB_ERR_EXISTS;
247 1.2.14.2 snj return code;
248 1.2.14.2 snj }
249 1.2.14.2 snj
250 1.2.14.2 snj static krb5_error_code
251 1.2.14.2 snj DB__del(krb5_context context, HDB *db, krb5_data key)
252 1.2.14.2 snj {
253 1.2.14.2 snj mdb_info *mi = (mdb_info*)db->hdb_db;
254 1.2.14.2 snj MDB_txn *txn;
255 1.2.14.2 snj MDB_val k;
256 1.2.14.2 snj krb5_error_code code;
257 1.2.14.2 snj
258 1.2.14.2 snj k.mv_data = key.data;
259 1.2.14.2 snj k.mv_size = key.length;
260 1.2.14.2 snj
261 1.2.14.2 snj code = mdb_txn_begin(mi->e, NULL, 0, &txn);
262 1.2.14.2 snj if (code)
263 1.2.14.2 snj return code;
264 1.2.14.2 snj
265 1.2.14.2 snj code = mdb_del(txn, mi->d, &k, NULL);
266 1.2.14.2 snj if (code)
267 1.2.14.2 snj mdb_txn_abort(txn);
268 1.2.14.2 snj else
269 1.2.14.2 snj code = mdb_txn_commit(txn);
270 1.2.14.2 snj if(code == MDB_NOTFOUND)
271 1.2.14.2 snj return HDB_ERR_NOENTRY;
272 1.2.14.2 snj return code;
273 1.2.14.2 snj }
274 1.2.14.2 snj
275 1.2.14.2 snj static krb5_error_code
276 1.2.14.2 snj DB_open(krb5_context context, HDB *db, int flags, mode_t mode)
277 1.2.14.2 snj {
278 1.2.14.2 snj mdb_info *mi = (mdb_info *)db->hdb_db;
279 1.2.14.2 snj MDB_txn *txn;
280 1.2.14.2 snj char *fn;
281 1.2.14.2 snj krb5_error_code ret;
282 1.2.14.2 snj int myflags = MDB_NOSUBDIR, tmp;
283 1.2.14.2 snj
284 1.2.14.2 snj if((flags & O_ACCMODE) == O_RDONLY)
285 1.2.14.2 snj myflags |= MDB_RDONLY;
286 1.2.14.2 snj
287 1.2.14.2 snj if (asprintf(&fn, "%s.mdb", db->hdb_name) == -1)
288 1.2.14.2 snj return krb5_enomem(context);
289 1.2.14.2 snj if (mdb_env_create(&mi->e)) {
290 1.2.14.2 snj free(fn);
291 1.2.14.2 snj return krb5_enomem(context);
292 1.2.14.2 snj }
293 1.2.14.2 snj
294 1.2.14.2 snj tmp = krb5_config_get_int_default(context, NULL, 0, "kdc",
295 1.2.14.2 snj "hdb-mdb-maxreaders", NULL);
296 1.2.14.2 snj if (tmp) {
297 1.2.14.2 snj ret = mdb_env_set_maxreaders(mi->e, tmp);
298 1.2.14.2 snj if (ret) {
299 1.2.14.2 snj free(fn);
300 1.2.14.2 snj krb5_set_error_message(context, ret, "setting maxreaders on %s: %s",
301 1.2.14.2 snj db->hdb_name, mdb_strerror(ret));
302 1.2.14.2 snj return ret;
303 1.2.14.2 snj }
304 1.2.14.2 snj }
305 1.2.14.2 snj
306 1.2.14.2 snj tmp = krb5_config_get_int_default(context, NULL, 0, "kdc",
307 1.2.14.2 snj "hdb-mdb-mapsize", NULL);
308 1.2.14.2 snj if (tmp) {
309 1.2.14.2 snj size_t maps = tmp;
310 1.2.14.2 snj maps *= KILO;
311 1.2.14.2 snj ret = mdb_env_set_mapsize(mi->e, maps);
312 1.2.14.2 snj if (ret) {
313 1.2.14.2 snj free(fn);
314 1.2.14.2 snj krb5_set_error_message(context, ret, "setting mapsize on %s: %s",
315 1.2.14.2 snj db->hdb_name, mdb_strerror(ret));
316 1.2.14.2 snj return ret;
317 1.2.14.2 snj }
318 1.2.14.2 snj }
319 1.2.14.2 snj
320 1.2.14.2 snj ret = mdb_env_open(mi->e, fn, myflags, mode);
321 1.2.14.2 snj free(fn);
322 1.2.14.2 snj if (ret) {
323 1.2.14.2 snj fail:
324 1.2.14.2 snj mdb_env_close(mi->e);
325 1.2.14.2 snj mi->e = 0;
326 1.2.14.2 snj krb5_set_error_message(context, ret, "opening %s: %s",
327 1.2.14.2 snj db->hdb_name, mdb_strerror(ret));
328 1.2.14.2 snj return ret;
329 1.2.14.2 snj }
330 1.2.14.2 snj
331 1.2.14.2 snj ret = mdb_txn_begin(mi->e, NULL, MDB_RDONLY, &txn);
332 1.2.14.2 snj if (ret)
333 1.2.14.2 snj goto fail;
334 1.2.14.2 snj
335 1.2.14.2 snj ret = mdb_open(txn, NULL, 0, &mi->d);
336 1.2.14.2 snj mdb_txn_abort(txn);
337 1.2.14.2 snj if (ret)
338 1.2.14.2 snj goto fail;
339 1.2.14.2 snj
340 1.2.14.2 snj if((flags & O_ACCMODE) == O_RDONLY)
341 1.2.14.2 snj ret = hdb_check_db_format(context, db);
342 1.2.14.2 snj else
343 1.2.14.2 snj ret = hdb_init_db(context, db);
344 1.2.14.2 snj if(ret == HDB_ERR_NOENTRY)
345 1.2.14.2 snj return 0;
346 1.2.14.2 snj if (ret) {
347 1.2.14.2 snj DB_close(context, db);
348 1.2.14.2 snj krb5_set_error_message(context, ret, "hdb_open: failed %s database %s",
349 1.2.14.2 snj (flags & O_ACCMODE) == O_RDONLY ?
350 1.2.14.2 snj "checking format of" : "initialize",
351 1.2.14.2 snj db->hdb_name);
352 1.2.14.2 snj }
353 1.2.14.2 snj
354 1.2.14.2 snj return ret;
355 1.2.14.2 snj }
356 1.2.14.2 snj
357 1.2.14.2 snj krb5_error_code
358 1.2.14.2 snj hdb_mdb_create(krb5_context context, HDB **db,
359 1.2.14.2 snj const char *filename)
360 1.2.14.2 snj {
361 1.2.14.2 snj *db = calloc(1, sizeof(**db));
362 1.2.14.2 snj if (*db == NULL) {
363 1.2.14.2 snj krb5_set_error_message(context, ENOMEM, "malloc: out of memory");
364 1.2.14.2 snj return ENOMEM;
365 1.2.14.2 snj }
366 1.2.14.2 snj
367 1.2.14.2 snj (*db)->hdb_db = calloc(1, sizeof(mdb_info));
368 1.2.14.2 snj if ((*db)->hdb_db == NULL) {
369 1.2.14.2 snj free(*db);
370 1.2.14.2 snj *db = NULL;
371 1.2.14.2 snj krb5_set_error_message(context, ENOMEM, "malloc: out of memory");
372 1.2.14.2 snj return ENOMEM;
373 1.2.14.2 snj }
374 1.2.14.2 snj (*db)->hdb_name = strdup(filename);
375 1.2.14.2 snj if ((*db)->hdb_name == NULL) {
376 1.2.14.2 snj free((*db)->hdb_db);
377 1.2.14.2 snj free(*db);
378 1.2.14.2 snj *db = NULL;
379 1.2.14.2 snj krb5_set_error_message(context, ENOMEM, "malloc: out of memory");
380 1.2.14.2 snj return ENOMEM;
381 1.2.14.2 snj }
382 1.2.14.2 snj (*db)->hdb_master_key_set = 0;
383 1.2.14.2 snj (*db)->hdb_openp = 0;
384 1.2.14.2 snj (*db)->hdb_capability_flags = HDB_CAP_F_HANDLE_ENTERPRISE_PRINCIPAL;
385 1.2.14.2 snj (*db)->hdb_open = DB_open;
386 1.2.14.2 snj (*db)->hdb_close = DB_close;
387 1.2.14.2 snj (*db)->hdb_fetch_kvno = _hdb_fetch_kvno;
388 1.2.14.2 snj (*db)->hdb_store = _hdb_store;
389 1.2.14.2 snj (*db)->hdb_remove = _hdb_remove;
390 1.2.14.2 snj (*db)->hdb_firstkey = DB_firstkey;
391 1.2.14.2 snj (*db)->hdb_nextkey= DB_nextkey;
392 1.2.14.2 snj (*db)->hdb_lock = DB_lock;
393 1.2.14.2 snj (*db)->hdb_unlock = DB_unlock;
394 1.2.14.2 snj (*db)->hdb_rename = DB_rename;
395 1.2.14.2 snj (*db)->hdb__get = DB__get;
396 1.2.14.2 snj (*db)->hdb__put = DB__put;
397 1.2.14.2 snj (*db)->hdb__del = DB__del;
398 1.2.14.2 snj (*db)->hdb_destroy = DB_destroy;
399 1.2.14.2 snj return 0;
400 1.2.14.2 snj }
401 1.2.14.2 snj #endif /* HAVE_LMDB */
402