/*********************************************************/
/* toksvc: a framework-native token broker service */
/* Copyright (C) 2020 Z. Gilboa */
/* Released under GPLv2 and GPLv3; see COPYING.TOKSVC. */
/*********************************************************/
#include <ntapi/ntapi.h>
#include <ntapi/nt_atomic.h>
#include <stdint.h>
#include <toksvc/toksvc.h>
#include "toksvc_init_impl.h"
#include "toksvc_nolibc_impl.h"
#define ARGV_DRIVER
#include "toksvc_version.h"
#include "toksvc_daemon_impl.h"
#include "toksvc_dprintf_impl.h"
#include "toksvc_driver_impl.h"
#include "argv/argv.h"
/* pty integration */
#include <psxtypes/section/freestd.h>
__attr_section_decl__(".freestd")
static const nt_tty_affiliation tty_affiliation
__attr_section__(".freestd")
= NT_TTY_AFFILIATION_DEFAULT;
/* ntapi accessor table */
const ntapi_vtbl * toks_ntapi;
/* daemon */
static struct toks_daemon_ctx toks_daemon_ctx;
static const nt_guid toks_daemon_default_guid = TOKS_PORT_GUID_DAEMON;
static const wchar16_t toks_service_name[6] = TOKS_PORT_NAME_PREFIX;
/* package info */
static const struct toks_source_version toks_src_version = {
TOKS_TAG_VER_MAJOR,
TOKS_TAG_VER_MINOR,
TOKS_TAG_VER_PATCH,
TOKSVC_GIT_VERSION
};
struct toks_driver_ctx_alloc {
struct argv_meta * meta;
struct toks_driver_ctx_impl ctx;
uint64_t guard;
};
struct toks_split_vector {
char ** targv;
char ** eargv;
};
static uint32_t toks_argv_flags(uint32_t flags)
{
uint32_t ret = ARGV_CLONE_VECTOR;
if (flags & TOKS_DRIVER_VERBOSITY_NONE)
ret |= ARGV_VERBOSITY_NONE;
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
ret |= ARGV_VERBOSITY_ERRORS;
if (flags & TOKS_DRIVER_VERBOSITY_STATUS)
ret |= ARGV_VERBOSITY_STATUS;
return ret;
}
static int toks_driver_usage(
const char * program,
const char * arg,
const struct argv_option ** optv,
struct argv_meta * meta)
{
char header[512];
snprintf(header,sizeof(header),
"Usage: %s [options] <file>...\n" "Options:\n",
program);
argv_usage(STDOUT_FILENO,header,optv,arg);
argv_free(meta);
return TOKS_USAGE;
}
static int32_t toks_query_performance_counters_failover(nt_filetime * ticks)
{
(void)ticks;
return 0;
}
static struct toks_driver_ctx_impl * toks_driver_ctx_alloc(
struct argv_meta * meta,
const struct toks_common_ctx * cctx)
{
struct toks_driver_ctx_alloc * ictx;
size_t size;
nt_runtime_data * rtdata;
if (ntapi->tt_get_runtime_data(&rtdata,0))
return 0;
size = sizeof(struct toks_driver_ctx_alloc);
if (!(ictx = calloc(1,size)))
return 0;
if (cctx)
memcpy(&ictx->ctx.cctx,cctx,sizeof(*cctx));
ictx->ctx.ticks.qpc = toks_query_performance_counters_failover;
ictx->ctx.ticks.pcfreq.quad = 0;
ictx->meta = meta;
ictx->ctx.rtdata = rtdata;
return &ictx->ctx;
}
static int toks_get_driver_ctx_fail(struct argv_meta * meta)
{
argv_free(meta);
return -1;
}
#define TOKS_SARGV_ELEMENTS 1024
static int toks_split_argv(
char ** argv,
struct toks_split_vector * sargv)
{
ptrdiff_t argc;
char ** parg;
/* argc */
for (parg=argv; *parg; )
parg++;
if ((argc = parg - argv) >= TOKS_SARGV_ELEMENTS)
return -1;
/* clone argv into targv */
ntapi->tt_aligned_block_memset(
(uintptr_t *)sargv->targv,
0,TOKS_SARGV_ELEMENTS*sizeof(char *));
ntapi->tt_aligned_block_memcpy(
(uintptr_t *)sargv->targv,
(uintptr_t *)argv,
argc*sizeof(char *));
/* eargv */
for (parg=sargv->targv; *parg; parg++) {
if (!(strcmp(*parg,"-e")) || !(strcmp(*parg,"--exec"))) {
sargv->eargv = &argv[parg-sargv->targv];
sargv->eargv++;
*parg = 0;
return 0;
}
}
return 0;
}
int toks_get_driver_ctx(
char ** argv,
char ** envp,
uint32_t flags,
struct toks_driver_ctx ** pctx)
{
int32_t status;
struct toks_driver_ctx_impl * ctx;
struct toks_common_ctx cctx;
struct toks_split_vector sargv;
const struct argv_option * optv[TOKS_OPTV_ELEMENTS];
struct argv_meta * meta;
struct argv_entry * entry;
struct argv_entry * uuid;
struct argv_entry * pid;
struct argv_entry * msecs;
struct toks_token_string key;
size_t keylen;
nt_guid svcguid;
const char * program;
const char * ch;
int ntokens;
int32_t tokpid;
int64_t timeout;
void * hkernel32;
char * targv[TOKS_SARGV_ELEMENTS];
(void)envp;
if (toks_init())
return -1;
argv_optv_init(toks_default_options,optv);
sargv.targv = targv;
sargv.eargv = 0;
if (toks_split_argv(argv,&sargv))
return -1;
if (!(meta = argv_get(
sargv.targv,optv,
toks_argv_flags(flags),
STDERR_FILENO)))
return -1;
if (!(flags & TOKS_DRIVER_MODE_CLIENT))
flags |= TOKS_DRIVER_MODE_SERVER;
uuid = 0;
tokpid = 0;
keylen = 0;
ntokens = 0;
timeout = (-1);
program = argv_program_name(argv[0]);
memset(&cctx,0,sizeof(cctx));
cctx.drvflags = flags;
cctx.eargv = sargv.eargv;
if (!argv[1] && (flags & TOKS_DRIVER_VERBOSITY_USAGE))
return toks_driver_usage(program,0,optv,meta);
for (entry=meta->entries; entry->fopt || entry->arg; entry++) {
if (entry->fopt) {
switch (entry->tag) {
case TAG_HELP:
if (flags & TOKS_DRIVER_VERBOSITY_USAGE)
return toks_driver_usage(program,entry->arg,optv,meta);
case TAG_VERSION:
cctx.drvflags |= TOKS_DRIVER_VERSION;
break;
case TAG_DAEMON:
if (!strcmp("always",entry->arg))
cctx.drvflags |= TOKS_DRIVER_DAEMON_ALWAYS;
else if (!strcmp("never",entry->arg))
cctx.drvflags |= TOKS_DRIVER_DAEMON_NEVER;
break;
case TAG_SYSROOT:
cctx.sysroot = entry->arg;
break;
case TAG_UUID:
uuid = entry;
break;
case TAG_PID:
pid = entry;
for (tokpid=0, ch=entry->arg; *ch && (tokpid>=0); ch++)
if ((*ch < '0') || (*ch >'9'))
tokpid = -1;
else
tokpid = tokpid * 10 + (*ch - '0');
break;
case TAG_TIMEOUT:
msecs = entry;
for (timeout=0, ch=entry->arg; *ch && (timeout>=0); ch++)
if ((*ch < '0') || (*ch >'9'))
timeout = -2;
else if ((ch - entry->arg) > 15)
timeout = -2;
else
timeout = timeout * 10 + (*ch - '0');
break;
case TAG_TOKENS:
for (ntokens=0, ch=entry->arg; *ch && (ntokens>=0); ch++)
if ((*ch < '0') || (*ch >'9'))
ntokens = -1;
else if (ntokens >= 1000)
ntokens = -1;
else
ntokens = ntokens * 10 + (*ch - '0');
break;
case TAG_CONNECT:
cctx.drvflags &= ~(uint64_t)TOKS_DRIVER_MODE_SERVER;
cctx.drvflags |= TOKS_DRIVER_MODE_CLIENT;
break;
case TAG_ACQUIRE:
cctx.drvflags &= ~(uint64_t)TOKS_DRIVER_MODE_SERVER;
cctx.drvflags |= TOKS_DRIVER_MODE_CLIENT;
cctx.drvflags |= TOKS_DRIVER_ACTION_ACQUIRE;
break;
case TAG_RELEASE:
cctx.drvflags &= ~(uint64_t)TOKS_DRIVER_MODE_SERVER;
cctx.drvflags |= TOKS_DRIVER_MODE_CLIENT;
cctx.drvflags |= TOKS_DRIVER_ACTION_RELEASE;
keylen = toks_strlen(entry->arg);
ntapi->tt_generic_memset(
&key,0,sizeof(key));
if (keylen < sizeof(key.token))
ntapi->tt_generic_memcpy(
&key.token,entry->arg,
keylen);
break;
}
} else
/* strict */
return toks_driver_usage(program,0,optv,meta);
}
if ((cctx.drvflags & TOKS_DRIVER_MODE_CLIENT) && (tokpid < 0)) {
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: %s is not a valid process id.",
program,pid->arg);
return toks_get_driver_ctx_fail(meta);
}
if ((cctx.drvflags & TOKS_DRIVER_MODE_CLIENT) && (timeout < (-1))) {
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: %s is not a valid timeout in milliseconds.",
program,msecs->arg);
return toks_get_driver_ctx_fail(meta);
}
if ((cctx.drvflags & TOKS_DRIVER_MODE_SERVER) && (ntokens <= 0)) {
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: number of tokens not set or is invalid.",
program);
return toks_get_driver_ctx_fail(meta);
}
if (uuid && ntapi->tt_string_to_guid_utf8(uuid->arg,&svcguid)) {
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: '%s' is not a valid service guid (did you forget the braces?)",
program,uuid->arg);
return toks_get_driver_ctx_fail(meta);
}
if (cctx.sysroot && toks_open_dir(&cctx.hroot,0,cctx.sysroot,false)) {
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: could not open sysroot directory '%s'",
program,cctx.sysroot);
return toks_get_driver_ctx_fail(meta);
}
if (!(ctx = toks_driver_ctx_alloc(meta,&cctx)))
return toks_get_driver_ctx_fail(meta);
if ((cctx.drvflags & TOKS_DRIVER_ACTION_RELEASE)) {
if (toks_client_str_to_token(&ctx->ctx,&key)) {
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: [%s] is not a valid token.",
program,key.token);
return toks_get_driver_ctx_fail(meta);
}
}
ntapi->tt_guid_copy(
&ctx->uuid,
uuid ? &svcguid : &ctx->rtdata->srv_guid);
if ((toks_ntapi->tt_create_private_event(
&ctx->hevent,
NT_NOTIFICATION_EVENT,
NT_EVENT_NOT_SIGNALED)))
return toks_get_driver_ctx_fail(meta);
if ((ntapi->tt_open_dev_object_directory(
&ctx->hsvcdir,
NT_SEC_READ_CONTROL
| NT_DIRECTORY_QUERY
| NT_DIRECTORY_TRAVERSE
| NT_DIRECTORY_CREATE_OBJECT
| NT_DIRECTORY_CREATE_SUBDIRECTORY,
toks_service_name,
&toks_daemon_default_guid)))
return toks_get_driver_ctx_fail(meta);
if ((hkernel32 = pe_get_kernel32_module_handle()))
if ((ctx->ticks.qpc = pe_get_procedure_address(
hkernel32,"QueryPerformanceCounter")))
ntapi->zw_query_performance_counter(
&(nt_filetime){{0,0}},
&ctx->ticks.pcfreq);
ctx->tokpid = tokpid;
ctx->ntokens = ntokens;
ctx->timeout = timeout;
ctx->ctx.program = program;
ctx->ctx.cctx = &ctx->cctx;
ctx->cctx.uuid = &ctx->uuid;
if (cctx.drvflags & TOKS_DRIVER_MODE_SERVER) {
if (!(ctx->waiters = toks_calloc(
TOKS_MAX_WAITERS,
sizeof(struct toks_waiter))))
return toks_get_driver_ctx_fail(meta);
toks_daemon_ctx.driver_ctx = &ctx->ctx;
toks_daemon_ctx.waiter_base = ctx->waiters;
toks_daemon_ctx.waiter_first = ctx->waiters;
toks_daemon_ctx.waiter_next = ctx->waiters;
toks_daemon_ctx.waiter_cap = &ctx->waiters[TOKS_MAX_WAITERS];
if (!(ctx->tokens = toks_calloc(ntokens,sizeof(*ctx->tokens))))
return toks_get_driver_ctx_fail(meta);
if (toks_daemon_init(&toks_daemon_ctx,&ctx->uuid))
return toks_get_driver_ctx_fail(meta);
}
if (cctx.drvflags & TOKS_DRIVER_MODE_CLIENT) {
switch ((status = toks_client_connect(&ctx->ctx))) {
case NT_STATUS_SUCCESS:
break;
case NT_STATUS_OBJECT_NAME_NOT_FOUND:
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: could not connect "
"(server not running) [0x%x].",
program,status);
return toks_get_driver_ctx_fail(meta);
case NT_STATUS_CONNECTION_REFUSED:
case NT_STATUS_PORT_CONNECTION_REFUSED:
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: could not connect "
"(connection refused) [0x%x].",
program,status);
return toks_get_driver_ctx_fail(meta);
case NT_STATUS_ACCESS_DENIED:
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: could not connect "
"(access denied) [0x%x].",
program,status);
return toks_get_driver_ctx_fail(meta);
default:
if (flags & TOKS_DRIVER_VERBOSITY_ERRORS)
toks_dprintf(STDERR_FILENO,
"%s: error: could not connect "
"(check the system's documentation) [0x%x].",
program,status);
return toks_get_driver_ctx_fail(meta);
}
}
*pctx = &ctx->ctx;
return TOKS_OK;
}
static void toks_free_driver_ctx_impl(struct toks_driver_ctx_alloc * ictx)
{
if (ictx->ctx.hevent)
ntapi->zw_close(ictx->ctx.hevent);
if (ictx->ctx.hsvcdir)
ntapi->zw_close(ictx->ctx.hsvcdir);
if (ictx->ctx.hsvclink)
ntapi->zw_close(ictx->ctx.hsvclink);
if (ictx->ctx.tokens)
toks_free(ictx->ctx.tokens);
if (ictx->ctx.waiters)
toks_free(ictx->ctx.waiters);
argv_free(ictx->meta);
free(ictx);
}
void toks_free_driver_ctx(struct toks_driver_ctx * ctx)
{
struct toks_driver_ctx_alloc * ictx;
uintptr_t addr;
if (ctx) {
addr = (uintptr_t)ctx - offsetof(struct toks_driver_ctx_impl,ctx);
addr = addr - offsetof(struct toks_driver_ctx_alloc,ctx);
ictx = (struct toks_driver_ctx_alloc *)addr;
toks_free_driver_ctx_impl(ictx);
}
}
void toks_driver_set_timeout(struct toks_driver_ctx * dctx, int64_t millisecs)
{
toks_set_driver_timeout(dctx,millisecs);
}
void toks_driver_unset_timeout(struct toks_driver_ctx * dctx)
{
toks_set_driver_timeout(dctx,(-1));
}
const struct toks_source_version * toks_source_version(void)
{
return &toks_src_version;
}