2 * support/export/client.c
4 * Maintain list of nfsd clients.
6 * Copyright (C) 1995, 1996 Olaf Kirch <okir@monad.swb.de>
13 #include <sys/types.h>
14 #include <netinet/in.h>
15 #include <arpa/inet.h>
25 /* netgroup stuff never seems to be defined in any header file. Linux is
28 #if !defined(__GLIBC__) || __GLIBC__ < 2
29 extern int innetgr(char *netgr, char *host, char *, char *);
32 static char *add_name(char *old, const char *add);
34 nfs_client *clientlist[MCL_MAXTYPES] = { NULL, };
38 init_addrlist(nfs_client *clp, const struct addrinfo *ai)
45 for (i = 0; (ai != NULL) && (i < NFSCLNT_ADDRMAX); i++) {
46 set_addrlist(clp, i, ai->ai_addr);
54 client_free(nfs_client *clp)
56 free(clp->m_hostname);
61 init_netmask(nfs_client *clp, const char *slash)
63 struct sockaddr_in sin = {
64 .sin_family = AF_INET,
67 if (strchr(slash + 1, '.') != NULL)
68 sin.sin_addr.s_addr = inet_addr(slash + 1);
70 int prefixlen = atoi(slash + 1);
71 if (0 < prefixlen && prefixlen <= 32)
73 htonl((uint32_t)~0 << (32 - prefixlen));
78 set_addrlist_in(clp, 1, &sin);
82 xlog(L_ERROR, "Invalid prefix `%s' for %s", slash + 1, clp->m_hostname);
87 init_subnetwork(nfs_client *clp)
89 struct sockaddr_in sin = {
90 .sin_family = AF_INET,
92 static char slash32[] = "/32";
95 cp = strchr(clp->m_hostname, '/');
100 sin.sin_addr.s_addr = inet_addr(clp->m_hostname);
101 set_addrlist_in(clp, 0, &sin);
104 return init_netmask(clp, cp);
108 client_init(nfs_client *clp, const char *hname, const struct addrinfo *ai)
110 clp->m_hostname = strdup(hname);
111 if (clp->m_hostname == NULL)
118 if (clp->m_type == MCL_SUBNETWORK)
119 return init_subnetwork(clp);
121 init_addrlist(clp, ai);
126 client_add(nfs_client *clp)
130 cpp = &clientlist[clp->m_type];
132 cpp = &((*cpp)->m_next);
137 /* if canonical is set, then we *know* this is already a canonical name
138 * so hostname lookup is avoided.
139 * This is used when reading /proc/fs/nfs/exports
142 client_lookup(char *hname, int canonical)
144 nfs_client *clp = NULL;
146 struct addrinfo *ai = NULL;
148 htype = client_gettype(hname);
150 if (htype == MCL_FQDN && !canonical) {
151 ai = host_addrinfo(hname);
153 xlog(L_ERROR, "Failed to resolve %s", hname);
156 hname = ai->ai_canonname;
158 for (clp = clientlist[htype]; clp; clp = clp->m_next)
159 if (client_check(clp, ai))
162 for (clp = clientlist[htype]; clp; clp = clp->m_next) {
163 if (strcasecmp(hname, clp->m_hostname)==0)
169 clp = calloc(1, sizeof(*clp));
173 if (!client_init(clp, hname, NULL)) {
181 if (htype == MCL_FQDN && clp->m_naddr == 0)
182 init_addrlist(clp, ai);
190 * client_dup - create a copy of an nfs_client
191 * @clp: pointer to nfs_client to copy
192 * @ai: pointer to addrinfo used to initialize the new client's addrlist
194 * Returns a dynamically allocated nfs_client if successful, or
195 * NULL if some problem occurs. Caller must free the returned
196 * nfs_client with free(3).
199 client_dup(const nfs_client *clp, const struct addrinfo *ai)
203 new = (nfs_client *)malloc(sizeof(*new));
206 memcpy(new, clp, sizeof(*new));
207 new->m_type = MCL_FQDN;
208 new->m_hostname = NULL;
210 if (!client_init(new, ai->ai_canonname, ai)) {
219 client_release(nfs_client *clp)
221 if (clp->m_count <= 0)
222 xlog(L_FATAL, "client_free: m_count <= 0!");
229 nfs_client *clp, **head;
232 for (i = 0; i < MCL_MAXTYPES; i++) {
233 head = clientlist + i;
235 *head = (clp = *head)->m_next;
242 * client_resolve - look up an IP address
243 * @sap: pointer to socket address to resolve
245 * Returns an addrinfo structure, or NULL if some problem occurred.
246 * Caller must free the result with freeaddrinfo(3).
249 client_resolve(const struct sockaddr *sap)
251 struct addrinfo *ai = NULL;
253 if (clientlist[MCL_WILDCARD] || clientlist[MCL_NETGROUP])
254 ai = host_reliable_addrinfo(sap);
256 ai = host_numeric_addrinfo(sap);
262 * client_compose - Make a list of cached hostnames that match an IP address
263 * @ai: pointer to addrinfo containing IP address information to match
265 * Gather all known client hostnames that match the IP address, and sort
266 * the result into a comma-separated list.
268 * Returns a '\0'-terminated ASCII string containing a comma-separated
269 * sorted list of client hostnames, or NULL if no client records matched
270 * the IP address or memory could not be allocated. Caller must free the
271 * returned string with free(3).
274 client_compose(const struct addrinfo *ai)
279 for (i = 0 ; i < MCL_MAXTYPES; i++) {
281 for (clp = clientlist[i]; clp ; clp = clp->m_next) {
282 if (!client_check(clp, ai))
284 name = add_name(name, clp->m_hostname);
291 * client_member - check if @name is contained in the list @client
292 * @client: '\0'-terminated ASCII string containing
293 * comma-separated list of hostnames
294 * @name: '\0'-terminated ASCII string containing hostname to look for
296 * Returns 1 if @name was found in @client, otherwise zero is returned.
299 client_member(const char *client, const char *name)
301 size_t l = strlen(name);
304 if (strncmp(client, name, l) == 0 &&
305 (client[l] == ',' || client[l] == '\0'))
307 client = strchr(client, ',');
316 name_cmp(const char *a, const char *b)
318 /* compare strings a and b, but only upto ',' in a */
319 while (*a && *b && *a != ',' && *a == *b)
321 if (!*b && (!*a || *a == ','))
324 if (!*a || *a == ',') return -1;
329 add_name(char *old, const char *add)
331 size_t len = strlen(add) + 2;
334 if (old) len += strlen(old);
342 while (cp && *cp && name_cmp(cp, add) < 0) {
343 /* step cp forward over a name */
344 char *e = strchr(cp, ',');
348 cp = cp + strlen(cp);
350 strncpy(new, old, cp-old);
352 if (cp != old && !*cp)
364 addrs_match4(const struct sockaddr *sa1, const struct sockaddr *sa2)
366 const struct sockaddr_in *si1 = (const struct sockaddr_in *)sa1;
367 const struct sockaddr_in *si2 = (const struct sockaddr_in *)sa2;
369 return si1->sin_addr.s_addr == si2->sin_addr.s_addr;
373 addrs_match(const struct sockaddr *sa1, const struct sockaddr *sa2)
375 if (sa1->sa_family == sa2->sa_family)
376 switch (sa1->sa_family) {
378 return addrs_match4(sa1, sa2);
385 * Check each address listed in @ai against each address
386 * stored in @clp. Return 1 if a match is found, otherwise
390 check_fqdn(const nfs_client *clp, const struct addrinfo *ai)
394 for (; ai; ai = ai->ai_next)
395 for (i = 0; i < clp->m_naddr; i++)
396 if (addrs_match(ai->ai_addr, get_addrlist(clp, i)))
403 mask_match(const uint32_t a, const uint32_t b, const uint32_t m)
405 return ((a ^ b) & m) == 0;
409 check_subnet_v4(const struct sockaddr_in *address,
410 const struct sockaddr_in *mask, const struct addrinfo *ai)
412 for (; ai; ai = ai->ai_next) {
413 struct sockaddr_in *sin = (struct sockaddr_in *)ai->ai_addr;
415 if (sin->sin_family != AF_INET)
418 if (mask_match(address->sin_addr.s_addr,
419 sin->sin_addr.s_addr,
420 mask->sin_addr.s_addr))
427 * Check each address listed in @ai against the subnetwork or
428 * host address stored in @clp. Return 1 if an address in @hp
429 * matches the host address stored in @clp, otherwise zero.
432 check_subnetwork(const nfs_client *clp, const struct addrinfo *ai)
434 switch (get_addrlist(clp, 0)->sa_family) {
436 return check_subnet_v4(get_addrlist_in(clp, 0),
437 get_addrlist_in(clp, 1), ai);
444 * Check if a wildcard nfs_client record matches the canonical name
445 * or the aliases of a host. Return 1 if a match is found, otherwise
449 check_wildcard(const nfs_client *clp, const struct addrinfo *ai)
451 char *cname = clp->m_hostname;
452 char *hname = ai->ai_canonname;
456 if (wildmat(hname, cname))
459 /* See if hname aliases listed in /etc/hosts or nis[+]
460 * match the requested wildcard */
461 hp = gethostbyname(hname);
463 for (ap = hp->h_aliases; *ap; ap++)
464 if (wildmat(*ap, cname))
472 * Check if @ai's hostname or aliases fall in a given netgroup.
473 * Return 1 if @ai represents a host in the netgroup, otherwise
478 check_netgroup(const nfs_client *clp, const struct addrinfo *ai)
480 const char *netgroup = clp->m_hostname + 1;
481 const char *hname = ai->ai_canonname;
482 struct addrinfo *tmp = NULL;
487 /* First, try to match the hostname without
488 * splitting off the domain */
489 if (innetgr(netgroup, hname, NULL, NULL))
492 /* See if hname aliases listed in /etc/hosts or nis[+]
493 * match the requested netgroup */
494 hp = gethostbyname(hname);
496 for (i = 0; hp->h_aliases[i]; i++)
497 if (innetgr(netgroup, hp->h_aliases[i], NULL, NULL))
501 /* If hname is ip address convert to FQDN */
502 tmp = host_pton(hname);
505 if (innetgr(netgroup, hname, NULL, NULL))
509 /* Okay, strip off the domain (if we have one) */
510 dot = strchr(hname, '.');
515 match = innetgr(netgroup, hname, NULL, NULL);
520 #else /* !HAVE_INNETGR */
522 check_netgroup(__attribute__((unused)) const nfs_client *clp,
523 __attribute__((unused)) const struct addrinfo *ai)
527 #endif /* !HAVE_INNETGR */
530 * client_check - check if IP address information matches a cached nfs_client
531 * @clp: pointer to a cached nfs_client record
532 * @ai: pointer to addrinfo to compare it with
534 * Returns 1 if the address information matches the cached nfs_client,
538 client_check(const nfs_client *clp, const struct addrinfo *ai)
540 switch (clp->m_type) {
542 return check_fqdn(clp, ai);
544 return check_subnetwork(clp, ai);
546 return check_wildcard(clp, ai);
548 return check_netgroup(clp, ai);
554 xlog(D_GENERAL, "%s: unrecognized client type: %d",
555 __func__, clp->m_type);
562 client_gettype(char *ident)
566 if (ident[0] == '\0' || strcmp(ident, "*")==0)
567 return MCL_ANONYMOUS;
568 if (strncmp(ident, "gss/", 4) == 0)
570 if (ident[0] == '@') {
572 xlog(L_WARNING, "netgroup support not compiled in");
576 for (sp = ident; *sp; sp++) {
577 if (*sp == '*' || *sp == '?' || *sp == '[')
580 return MCL_SUBNETWORK;
581 if (*sp == '\\' && sp[1])
584 /* check for N.N.N.N */
586 if(!isdigit(*sp) || strtoul(sp, &sp, 10) > 255 || *sp != '.') return MCL_FQDN;
587 sp++; if(!isdigit(*sp) || strtoul(sp, &sp, 10) > 255 || *sp != '.') return MCL_FQDN;
588 sp++; if(!isdigit(*sp) || strtoul(sp, &sp, 10) > 255 || *sp != '.') return MCL_FQDN;
589 sp++; if(!isdigit(*sp) || strtoul(sp, &sp, 10) > 255 || *sp != '\0') return MCL_FQDN;
590 /* we lie here a bit. but technically N.N.N.N == N.N.N.N/32 :) */
591 return MCL_SUBNETWORK;