libtommath: Fix possible integer overflow CVE-2023-36328
[heimdal.git] / lib / hdb / dbinfo.c
blob60b11f8cd663aec7b4429d64789c2cce75a33f15
1 /*
2 * Copyright (c) 2005 Kungliga Tekniska Högskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
4 * All rights reserved.
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
8 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of the Institute nor the names of its contributors
18 * may be used to endorse or promote products derived from this software
19 * without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31 * SUCH DAMAGE.
34 #include "hdb_locl.h"
36 struct hdb_dbinfo {
37 char *label;
38 char *realm;
39 char *dbname;
40 char *mkey_file;
41 char *acl_file;
42 char *log_file;
43 const krb5_config_binding *binding;
44 struct hdb_dbinfo *next;
47 static int
48 get_dbinfo(krb5_context context,
49 const krb5_config_binding *db_binding,
50 const char *label,
51 struct hdb_dbinfo **db)
53 struct hdb_dbinfo *di;
54 const char *p;
56 *db = NULL;
58 p = krb5_config_get_string(context, db_binding, "dbname", NULL);
59 if(p == NULL)
60 return 0;
62 di = calloc(1, sizeof(*di));
63 if (di == NULL) {
64 krb5_set_error_message(context, ENOMEM, "malloc: out of memory");
65 return ENOMEM;
67 di->label = strdup(label);
68 di->dbname = strdup(p);
70 p = krb5_config_get_string(context, db_binding, "realm", NULL);
71 if(p)
72 di->realm = strdup(p);
73 p = krb5_config_get_string(context, db_binding, "mkey_file", NULL);
74 if(p)
75 di->mkey_file = strdup(p);
76 p = krb5_config_get_string(context, db_binding, "acl_file", NULL);
77 if(p)
78 di->acl_file = strdup(p);
79 p = krb5_config_get_string(context, db_binding, "log_file", NULL);
80 if(p)
81 di->log_file = strdup(p);
83 di->binding = db_binding;
85 *db = di;
86 return 0;
90 int
91 hdb_get_dbinfo(krb5_context context, struct hdb_dbinfo **dbp)
93 const krb5_config_binding *db_binding;
94 struct hdb_dbinfo *di, **dt, *databases;
95 const char *default_dbname = HDB_DEFAULT_DB;
96 const char *default_mkey = HDB_DB_DIR "/m-key";
97 const char *default_acl = HDB_DB_DIR "/kadmind.acl";
98 const char *p;
99 int ret;
101 *dbp = NULL;
102 dt = NULL;
103 databases = NULL;
105 db_binding = krb5_config_get_list(context, NULL,
106 "kdc",
107 "database",
108 NULL);
109 if (db_binding) {
111 ret = get_dbinfo(context, db_binding, "default", &databases);
112 if (ret == 0 && databases != NULL)
113 dt = &databases->next;
115 for ( ; db_binding != NULL; db_binding = db_binding->next) {
117 if (db_binding->type != krb5_config_list)
118 continue;
120 ret = get_dbinfo(context, db_binding->u.list,
121 db_binding->name, &di);
122 if (ret)
123 krb5_err(context, 1, ret, "failed getting realm");
125 if (di == NULL)
126 continue;
128 if (dt)
129 *dt = di;
130 else {
131 hdb_free_dbinfo(context, &databases);
132 databases = di;
134 dt = &di->next;
139 if (databases == NULL) {
140 /* if there are none specified, create one and use defaults */
141 databases = calloc(1, sizeof(*databases));
142 databases->label = strdup("default");
145 for (di = databases; di; di = di->next) {
146 if (di->dbname == NULL) {
147 di->dbname = strdup(default_dbname);
148 if (di->mkey_file == NULL)
149 di->mkey_file = strdup(default_mkey);
151 if (di->mkey_file == NULL) {
152 p = strrchr(di->dbname, '.');
153 if(p == NULL || strchr(p, '/') != NULL)
154 /* final pathname component does not contain a . */
155 ret = asprintf(&di->mkey_file, "%s.mkey", di->dbname);
156 else
157 /* the filename is something.else, replace .else with
158 .mkey */
159 ret = asprintf(&di->mkey_file, "%.*s.mkey",
160 (int)(p - di->dbname), di->dbname);
161 if (ret == -1) {
162 hdb_free_dbinfo(context, &databases);
163 return ENOMEM;
166 if(di->acl_file == NULL)
167 di->acl_file = strdup(default_acl);
169 *dbp = databases;
170 return 0;
174 struct hdb_dbinfo *
175 hdb_dbinfo_get_next(struct hdb_dbinfo *dbp, struct hdb_dbinfo *dbprevp)
177 if (dbprevp == NULL)
178 return dbp;
179 else
180 return dbprevp->next;
183 const char *
184 hdb_dbinfo_get_label(krb5_context context, struct hdb_dbinfo *dbp)
186 return dbp->label;
189 const char *
190 hdb_dbinfo_get_realm(krb5_context context, struct hdb_dbinfo *dbp)
192 return dbp->realm;
195 const char *
196 hdb_dbinfo_get_dbname(krb5_context context, struct hdb_dbinfo *dbp)
198 return dbp->dbname;
201 const char *
202 hdb_dbinfo_get_mkey_file(krb5_context context, struct hdb_dbinfo *dbp)
204 return dbp->mkey_file;
207 const char *
208 hdb_dbinfo_get_acl_file(krb5_context context, struct hdb_dbinfo *dbp)
210 return dbp->acl_file;
213 const char *
214 hdb_dbinfo_get_log_file(krb5_context context, struct hdb_dbinfo *dbp)
216 return dbp->log_file;
219 const krb5_config_binding *
220 hdb_dbinfo_get_binding(krb5_context context, struct hdb_dbinfo *dbp)
222 return dbp->binding;
225 void
226 hdb_free_dbinfo(krb5_context context, struct hdb_dbinfo **dbp)
228 struct hdb_dbinfo *di, *ndi;
230 for(di = *dbp; di != NULL; di = ndi) {
231 ndi = di->next;
232 free (di->label);
233 free (di->realm);
234 free (di->dbname);
235 free (di->mkey_file);
236 free (di->acl_file);
237 free (di->log_file);
238 free(di);
240 *dbp = NULL;
244 * Return the directory where the hdb database resides.
246 * @param context Kerberos 5 context.
248 * @return string pointing to directory.
251 const char *
252 hdb_db_dir(krb5_context context)
254 const char *p;
256 p = krb5_config_get_string(context, NULL, "hdb", "db-dir", NULL);
257 if (p)
258 return p;
260 return HDB_DB_DIR;
264 * Return the default hdb database resides.
266 * @param context Kerberos 5 context.
268 * @return string pointing to directory.
271 const char *
272 hdb_default_db(krb5_context context)
274 static char *default_hdb = NULL;
275 struct hdb_dbinfo *dbinfo = NULL;
276 struct hdb_dbinfo *d = NULL;
277 const char *s;
279 if (default_hdb)
280 return default_hdb;
282 (void) hdb_get_dbinfo(context, &dbinfo);
283 while ((d = hdb_dbinfo_get_next(dbinfo, d)) != NULL) {
284 if ((s = hdb_dbinfo_get_dbname(context, d)) &&
285 (default_hdb = strdup(s)))
286 break;
289 hdb_free_dbinfo(context, &dbinfo);
290 return default_hdb ? default_hdb : HDB_DEFAULT_DB;