vacm.h 9.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285
  1. /*
  2. * vacm.h
  3. *
  4. * SNMPv3 View-based Access Control Model
  5. *
  6. * Portions of this file are subject to the following copyright(s). See
  7. * the Net-SNMP's COPYING file for more details and other copyrights
  8. * that may apply:
  9. *
  10. * Portions of this file are copyrighted by:
  11. * Copyright (c) 2016 VMware, Inc. All rights reserved.
  12. * Use is subject to license terms specified in the COPYING file
  13. * distributed with the Net-SNMP package.
  14. */
  15. #ifndef VACM_H
  16. #define VACM_H
  17. #ifdef __cplusplus
  18. extern "C" {
  19. #endif
  20. #define VACM_SUCCESS 0
  21. #define VACM_NOSECNAME 1
  22. #define VACM_NOGROUP 2
  23. #define VACM_NOACCESS 3
  24. #define VACM_NOVIEW 4
  25. #define VACM_NOTINVIEW 5
  26. #define VACM_NOSUCHCONTEXT 6
  27. #define VACM_SUBTREE_UNKNOWN 7
  28. #define SECURITYMODEL 1
  29. #define SECURITYNAME 2
  30. #define SECURITYGROUP 3
  31. #define SECURITYSTORAGE 4
  32. #define SECURITYSTATUS 5
  33. #define ACCESSPREFIX 1
  34. #define ACCESSMODEL 2
  35. #define ACCESSLEVEL 3
  36. #define ACCESSMATCH 4
  37. #define ACCESSREAD 5
  38. #define ACCESSWRITE 6
  39. #define ACCESSNOTIFY 7
  40. #define ACCESSSTORAGE 8
  41. #define ACCESSSTATUS 9
  42. #define VACMVIEWSPINLOCK 1
  43. #define VIEWNAME 2
  44. #define VIEWSUBTREE 3
  45. #define VIEWMASK 4
  46. #define VIEWTYPE 5
  47. #define VIEWSTORAGE 6
  48. #define VACMVIEWSTATUS 7
  49. #define VACM_MAX_STRING 32
  50. #define VACMSTRINGLEN 34 /* VACM_MAX_STRING + 2 */
  51. struct vacm_groupEntry {
  52. int securityModel;
  53. char securityName[VACMSTRINGLEN];
  54. char groupName[VACMSTRINGLEN];
  55. int storageType;
  56. int status;
  57. u_long bitMask;
  58. struct vacm_groupEntry *reserved;
  59. struct vacm_groupEntry *next;
  60. };
  61. #define CONTEXT_MATCH_EXACT 1
  62. #define CONTEXT_MATCH_PREFIX 2
  63. /* VIEW ENUMS ---------------------------------------- */
  64. /* SNMPD usage: get/set/send-notification views */
  65. #define VACM_VIEW_READ 0
  66. #define VACM_VIEW_WRITE 1
  67. #define VACM_VIEW_NOTIFY 2
  68. /* SNMPTRAPD usage: log execute and net-access (forward) usage */
  69. #define VACM_VIEW_LOG 3
  70. #define VACM_VIEW_EXECUTE 4
  71. #define VACM_VIEW_NET 5
  72. /* VIEW BIT MASK VALUES-------------------------------- */
  73. /* SNMPD usage: get/set/send-notification views */
  74. #define VACM_VIEW_READ_BIT (1 << VACM_VIEW_READ)
  75. #define VACM_VIEW_WRITE_BIT (1 << VACM_VIEW_WRITE)
  76. #define VACM_VIEW_NOTIFY_BIT (1 << VACM_VIEW_NOTIFY)
  77. /* SNMPTRAPD usage: log execute and net-access (forward) usage */
  78. #define VACM_VIEW_LOG_BIT (1 << VACM_VIEW_LOG)
  79. #define VACM_VIEW_EXECUTE_BIT (1 << VACM_VIEW_EXECUTE)
  80. #define VACM_VIEW_NET_BIT (1 << VACM_VIEW_NET)
  81. #define VACM_VIEW_NO_BITS 0
  82. /* Maximum number of views in the view array */
  83. #define VACM_MAX_VIEWS 8
  84. #define VACM_VIEW_ENUM_NAME "vacmviews"
  85. void init_vacm(void);
  86. struct vacm_accessEntry {
  87. char groupName[VACMSTRINGLEN];
  88. char contextPrefix[VACMSTRINGLEN];
  89. int securityModel;
  90. int securityLevel;
  91. int contextMatch;
  92. char views[VACM_MAX_VIEWS][VACMSTRINGLEN];
  93. int storageType;
  94. int status;
  95. u_long bitMask;
  96. struct vacm_accessEntry *reserved;
  97. struct vacm_accessEntry *next;
  98. };
  99. struct vacm_viewEntry {
  100. char viewName[VACMSTRINGLEN];
  101. oid viewSubtree[MAX_OID_LEN+1]; /* keep len in [0] */
  102. size_t viewSubtreeLen;
  103. u_char viewMask[VACMSTRINGLEN];
  104. size_t viewMaskLen;
  105. int viewType;
  106. int viewStorageType;
  107. int viewStatus;
  108. u_long bitMask;
  109. struct vacm_viewEntry *reserved;
  110. struct vacm_viewEntry *next;
  111. };
  112. NETSNMP_IMPORT
  113. void vacm_destroyViewEntry(const char *, oid *, size_t);
  114. NETSNMP_IMPORT
  115. void vacm_destroyAllViewEntries(void);
  116. #define VACM_MODE_FIND 0
  117. #define VACM_MODE_IGNORE_MASK 1
  118. #define VACM_MODE_CHECK_SUBTREE 2
  119. NETSNMP_IMPORT
  120. struct vacm_viewEntry *vacm_getViewEntry(const char *, oid *, size_t,
  121. int);
  122. /*
  123. * Returns a pointer to the viewEntry with the
  124. * same viewName and viewSubtree
  125. * Returns NULL if that entry does not exist.
  126. */
  127. NETSNMP_IMPORT
  128. int vacm_checkSubtree(const char *, oid *, size_t);
  129. /*
  130. * Check to see if everything within a subtree is in view, not in view,
  131. * or possibly both.
  132. *
  133. * Returns:
  134. * VACM_SUCCESS The OID is included in the view.
  135. * VACM_NOTINVIEW If no entry in the view list includes the
  136. * provided OID, or the OID is explicitly excluded
  137. * from the view.
  138. * VACM_SUBTREE_UNKNOWN The entire subtree has both allowed and
  139. * disallowed portions.
  140. */
  141. NETSNMP_IMPORT
  142. void
  143. vacm_scanViewInit(void);
  144. /*
  145. * Initialized the scan routines so that they will begin at the
  146. * beginning of the list of viewEntries.
  147. *
  148. */
  149. NETSNMP_IMPORT
  150. struct vacm_viewEntry *vacm_scanViewNext(void);
  151. /*
  152. * Returns a pointer to the next viewEntry.
  153. * These entries are returned in no particular order,
  154. * but if N entries exist, N calls to view_scanNext() will
  155. * return all N entries once.
  156. * Returns NULL if all entries have been returned.
  157. * view_scanInit() starts the scan over.
  158. */
  159. NETSNMP_IMPORT
  160. struct vacm_viewEntry *vacm_createViewEntry(const char *, oid *,
  161. size_t);
  162. /*
  163. * Creates a viewEntry with the given index
  164. * and returns a pointer to it.
  165. * The status of this entry is created as invalid.
  166. */
  167. NETSNMP_IMPORT
  168. void vacm_destroyGroupEntry(int, const char *);
  169. NETSNMP_IMPORT
  170. void vacm_destroyAllGroupEntries(void);
  171. NETSNMP_IMPORT
  172. struct vacm_groupEntry *vacm_createGroupEntry(int, const char *);
  173. NETSNMP_IMPORT
  174. struct vacm_groupEntry *vacm_getGroupEntry(int, const char *);
  175. NETSNMP_IMPORT
  176. void vacm_scanGroupInit(void);
  177. NETSNMP_IMPORT
  178. struct vacm_groupEntry *vacm_scanGroupNext(void);
  179. NETSNMP_IMPORT
  180. void vacm_destroyAccessEntry(const char *, const char *,
  181. int, int);
  182. NETSNMP_IMPORT
  183. void vacm_destroyAllAccessEntries(void);
  184. NETSNMP_IMPORT
  185. struct vacm_accessEntry *vacm_createAccessEntry(const char *,
  186. const char *, int,
  187. int);
  188. NETSNMP_IMPORT
  189. struct vacm_accessEntry *vacm_getAccessEntry(const char *,
  190. const char *, int, int);
  191. NETSNMP_IMPORT
  192. void vacm_scanAccessInit(void);
  193. NETSNMP_IMPORT
  194. struct vacm_accessEntry *vacm_scanAccessNext(void);
  195. void vacm_destroySecurityEntry(const char *);
  196. struct vacm_securityEntry *vacm_createSecurityEntry(const char *);
  197. struct vacm_securityEntry *vacm_getSecurityEntry(const char *);
  198. void vacm_scanSecurityInit(void);
  199. struct vacm_securityEntry *vacm_scanSecurityEntry(void);
  200. NETSNMP_IMPORT
  201. int vacm_is_configured(void);
  202. void vacm_save(const char *token, const char *type);
  203. void vacm_save_view(struct vacm_viewEntry *view,
  204. const char *token, const char *type);
  205. void vacm_save_access(struct vacm_accessEntry *access_entry,
  206. const char *token, const char *type);
  207. void vacm_save_auth_access(struct vacm_accessEntry *access_entry,
  208. const char *token, const char *type, int authtype);
  209. void vacm_save_group(struct vacm_groupEntry *group_entry,
  210. const char *token, const char *type);
  211. NETSNMP_IMPORT
  212. void vacm_parse_config_view(const char *token, const char *line);
  213. NETSNMP_IMPORT
  214. void vacm_parse_config_group(const char *token,
  215. const char *line);
  216. NETSNMP_IMPORT
  217. void vacm_parse_config_access(const char *token,
  218. const char *line);
  219. NETSNMP_IMPORT
  220. void vacm_parse_config_auth_access(const char *token,
  221. const char *line);
  222. NETSNMP_IMPORT
  223. int store_vacm(int majorID, int minorID, void *serverarg,
  224. void *clientarg);
  225. NETSNMP_IMPORT
  226. struct vacm_viewEntry *netsnmp_view_get(struct vacm_viewEntry *head,
  227. const char *viewName,
  228. oid * viewSubtree,
  229. size_t viewSubtreeLen, int mode);
  230. NETSNMP_IMPORT
  231. int netsnmp_vacm_simple_usm_add(const char *user, int rw, int authLevel,
  232. const char *view, oid *oidView,
  233. size_t oidViewLen, const char *context);
  234. NETSNMP_IMPORT
  235. int netsnmp_vacm_simple_usm_del(const char *user, int authLevel,
  236. const char *view, oid *oidView,
  237. size_t oidViewLen, const char *context);
  238. #ifdef __cplusplus
  239. }
  240. #endif
  241. #endif /* VACM_H */