2 * Copyright 2005, 2006 Kai Blin
4 * This library is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU Lesser General Public
6 * License as published by the Free Software Foundation; either
7 * version 2.1 of the License, or (at your option) any later version.
9 * This library is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12 * Lesser General Public License for more details.
14 * You should have received a copy of the GNU Lesser General Public
15 * License along with this library; if not, write to the Free Software
16 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
18 * A dispatcher to run ntlm_auth for wine's sspi module.
22 #include "wine/port.h"
28 #include <sys/types.h>
29 #ifdef HAVE_SYS_WAIT_H
32 #ifdef HAVE_SYS_ERRNO_H
33 #include <sys/errno.h>
41 #include "secur32_priv.h"
42 #include "wine/debug.h"
44 #define INITIAL_BUFFER_SIZE 200
46 WINE_DEFAULT_DEBUG_CHANNEL(ntlm);
48 SECURITY_STATUS fork_helper(PNegoHelper *new_helper, const char *prog,
57 TRACE("%s ", debugstr_a(prog));
58 for(i = 0; argv[i] != NULL; ++i)
60 TRACE("%s ", debugstr_a(argv[i]));
65 if (pipe2( pipe_in, O_CLOEXEC ) < 0 )
68 if( pipe(pipe_in) < 0 ) return SEC_E_INTERNAL_ERROR;
69 fcntl( pipe_in[0], F_SETFD, FD_CLOEXEC );
70 fcntl( pipe_in[1], F_SETFD, FD_CLOEXEC );
73 if (pipe2( pipe_out, O_CLOEXEC ) < 0 )
76 if( pipe(pipe_out) < 0 )
80 return SEC_E_INTERNAL_ERROR;
82 fcntl( pipe_out[0], F_SETFD, FD_CLOEXEC );
83 fcntl( pipe_out[1], F_SETFD, FD_CLOEXEC );
86 if (!(helper = HeapAlloc(GetProcessHeap(),0, sizeof(NegoHelper))))
92 return SEC_E_INSUFFICIENT_MEMORY;
95 helper->helper_pid = fork();
97 if(helper->helper_pid == -1)
103 HeapFree( GetProcessHeap(), 0, helper );
104 return SEC_E_INTERNAL_ERROR;
107 if(helper->helper_pid == 0)
109 /* We're in the child now */
110 dup2(pipe_out[0], 0);
120 /* Whoops, we shouldn't get here. Big badaboom.*/
121 write(STDOUT_FILENO, "BH\n", 3);
126 *new_helper = helper;
127 helper->major = helper->minor = helper->micro = -1;
128 helper->com_buf = NULL;
129 helper->com_buf_size = 0;
130 helper->com_buf_offset = 0;
131 helper->session_key = NULL;
132 helper->neg_flags = 0;
133 helper->crypt.ntlm.a4i = NULL;
134 helper->crypt.ntlm2.send_a4i = NULL;
135 helper->crypt.ntlm2.recv_a4i = NULL;
136 helper->crypt.ntlm2.send_sign_key = NULL;
137 helper->crypt.ntlm2.send_seal_key = NULL;
138 helper->crypt.ntlm2.recv_sign_key = NULL;
139 helper->crypt.ntlm2.recv_seal_key = NULL;
140 helper->pipe_in = pipe_in[0];
142 helper->pipe_out = pipe_out[1];
148 ERR( "no fork support on this platform\n" );
149 return SEC_E_INTERNAL_ERROR;
153 static SECURITY_STATUS read_line(PNegoHelper helper, int *offset_len)
158 if(helper->com_buf == NULL)
160 TRACE("Creating a new buffer for the helper\n");
161 if((helper->com_buf = HeapAlloc(GetProcessHeap(), 0, INITIAL_BUFFER_SIZE)) == NULL)
162 return SEC_E_INSUFFICIENT_MEMORY;
164 /* Created a new buffer, size is INITIAL_BUFFER_SIZE, offset is 0 */
165 helper->com_buf_size = INITIAL_BUFFER_SIZE;
166 helper->com_buf_offset = 0;
171 TRACE("offset = %d, size = %d\n", helper->com_buf_offset, helper->com_buf_size);
172 if(helper->com_buf_offset + INITIAL_BUFFER_SIZE > helper->com_buf_size)
174 /* increment buffer size in INITIAL_BUFFER_SIZE steps */
175 char *buf = HeapReAlloc(GetProcessHeap(), 0, helper->com_buf,
176 helper->com_buf_size + INITIAL_BUFFER_SIZE);
177 TRACE("Resizing buffer!\n");
178 if (!buf) return SEC_E_INSUFFICIENT_MEMORY;
179 helper->com_buf_size += INITIAL_BUFFER_SIZE;
180 helper->com_buf = buf;
182 if((read_size = read(helper->pipe_in, helper->com_buf + helper->com_buf_offset,
183 helper->com_buf_size - helper->com_buf_offset)) <= 0)
185 return SEC_E_INTERNAL_ERROR;
188 TRACE("read_size = %d, read: %s\n", read_size,
189 debugstr_a(helper->com_buf + helper->com_buf_offset));
190 helper->com_buf_offset += read_size;
191 newline = memchr(helper->com_buf, '\n', helper->com_buf_offset);
192 }while(newline == NULL);
194 /* Now, if there's a newline character, and we read more than that newline,
195 * we have to store the offset so we can preserve the additional data.*/
196 if( newline != helper->com_buf + helper->com_buf_offset)
198 TRACE("offset_len is calculated from %p - %p\n",
199 (helper->com_buf + helper->com_buf_offset), newline+1);
200 /* the length of the offset is the number of chars after the newline */
201 *offset_len = (helper->com_buf + helper->com_buf_offset) - (newline + 1);
213 static SECURITY_STATUS preserve_unused(PNegoHelper helper, int offset_len)
215 TRACE("offset_len = %d\n", offset_len);
219 memmove(helper->com_buf, helper->com_buf + helper->com_buf_offset,
221 helper->com_buf_offset = offset_len;
225 helper->com_buf_offset = 0;
228 TRACE("helper->com_buf_offset was set to: %d\n", helper->com_buf_offset);
232 SECURITY_STATUS run_helper(PNegoHelper helper, char *buffer,
233 unsigned int max_buflen, int *buflen)
236 SECURITY_STATUS sec_status = SEC_E_OK;
238 TRACE("In helper: sending %s\n", debugstr_a(buffer));
241 write(helper->pipe_out, buffer, lstrlenA(buffer));
242 write(helper->pipe_out, "\n", 1);
244 if((sec_status = read_line(helper, &offset_len)) != SEC_E_OK)
249 TRACE("In helper: received %s\n", debugstr_a(helper->com_buf));
250 *buflen = lstrlenA(helper->com_buf);
252 if( *buflen > max_buflen)
254 ERR("Buffer size too small(%d given, %d required) dropping data!\n",
255 max_buflen, *buflen);
256 return SEC_E_BUFFER_TOO_SMALL;
261 return SEC_E_ILLEGAL_MESSAGE;
264 /* We only get ERR if the input size is too big. On a GENSEC error,
265 * ntlm_auth will return BH */
266 if(strncmp(helper->com_buf, "ERR", 3) == 0)
268 return SEC_E_INVALID_TOKEN;
271 memcpy(buffer, helper->com_buf, *buflen+1);
273 sec_status = preserve_unused(helper, offset_len);
278 void cleanup_helper(PNegoHelper helper)
281 TRACE("Killing helper %p\n", helper);
285 HeapFree(GetProcessHeap(), 0, helper->com_buf);
287 /* closing stdin will terminate ntlm_auth */
288 close(helper->pipe_out);
289 close(helper->pipe_in);
292 if (helper->helper_pid > 0) /* reap child */
296 wret = waitpid(helper->helper_pid, NULL, 0);
297 } while (wret < 0 && errno == EINTR);
301 HeapFree(GetProcessHeap(), 0, helper);
304 void check_version(PNegoHelper helper)
308 int major = 0, minor = 0, micro = 0, ret;
310 TRACE("Checking version of helper\n");
313 int len = read(helper->pipe_in, temp, sizeof(temp)-1);
316 if((newline = memchr(temp, '\n', len)) != NULL)
321 TRACE("Exact version is %s\n", debugstr_a(temp));
322 ret = sscanf(temp, "Version %d.%d.%d", &major, &minor, µ);
325 ERR("Failed to get the helper version.\n");
326 helper->major = helper->minor = helper->micro = -1;
330 TRACE("Version recognized: %d.%d.%d\n", major, minor, micro);
331 helper->major = major;
332 helper->minor = minor;
333 helper->micro = micro;