Defines | |
#define | DBUS_AUTH_IN_END_STATE(auth) ((auth)->state->handler == NULL) |
Functions | |
DBusAuth * | _dbus_auth_server_new (void) |
Creates a new auth conversation object for the server side. | |
DBusAuth * | _dbus_auth_client_new (void) |
Creates a new auth conversation object for the client side. | |
DBusAuth * | _dbus_auth_ref (DBusAuth *auth) |
Increments the refcount of an auth object. | |
void | _dbus_auth_unref (DBusAuth *auth) |
Decrements the refcount of an auth object. | |
dbus_bool_t | _dbus_auth_set_mechanisms (DBusAuth *auth, const char **mechanisms) |
Sets an array of authentication mechanism names that we are willing to use. | |
DBusAuthState | _dbus_auth_do_work (DBusAuth *auth) |
Analyzes buffered input and moves the auth conversation forward, returning the new state of the auth conversation. | |
dbus_bool_t | _dbus_auth_get_bytes_to_send (DBusAuth *auth, const DBusString **str) |
Gets bytes that need to be sent to the peer we're conversing with. | |
void | _dbus_auth_bytes_sent (DBusAuth *auth, int bytes_sent) |
Notifies the auth conversation object that the given number of bytes of the outgoing buffer have been written out. | |
void | _dbus_auth_get_buffer (DBusAuth *auth, DBusString **buffer) |
Get a buffer to be used for reading bytes from the peer we're conversing with. | |
void | _dbus_auth_return_buffer (DBusAuth *auth, DBusString *buffer, int bytes_read) |
Returns a buffer with new data read into it. | |
void | _dbus_auth_get_unused_bytes (DBusAuth *auth, const DBusString **str) |
Returns leftover bytes that were not used as part of the auth conversation. | |
void | _dbus_auth_delete_unused_bytes (DBusAuth *auth) |
Gets rid of unused bytes returned by _dbus_auth_get_unused_bytes() after we've gotten them and successfully moved them elsewhere. | |
dbus_bool_t | _dbus_auth_needs_encoding (DBusAuth *auth) |
Called post-authentication, indicates whether we need to encode the message stream with _dbus_auth_encode_data() prior to sending it to the peer. | |
dbus_bool_t | _dbus_auth_encode_data (DBusAuth *auth, const DBusString *plaintext, DBusString *encoded) |
Called post-authentication, encodes a block of bytes for sending to the peer. | |
dbus_bool_t | _dbus_auth_needs_decoding (DBusAuth *auth) |
Called post-authentication, indicates whether we need to decode the message stream with _dbus_auth_decode_data() after receiving it from the peer. | |
dbus_bool_t | _dbus_auth_decode_data (DBusAuth *auth, const DBusString *encoded, DBusString *plaintext) |
Called post-authentication, decodes a block of bytes received from the peer. | |
void | _dbus_auth_set_credentials (DBusAuth *auth, const DBusCredentials *credentials) |
Sets credentials received via reliable means from the operating system. | |
void | _dbus_auth_get_identity (DBusAuth *auth, DBusCredentials *credentials) |
Gets the identity we authorized the client as. | |
dbus_bool_t | _dbus_auth_set_context (DBusAuth *auth, const DBusString *context) |
Sets the "authentication context" which scopes cookies with the DBUS_COOKIE_SHA1 auth mechanism for example. |
DBusAuth manages the authentication negotiation when a connection is first established, and also manage any encryption used over a connection.
DBusAuth really needs to be rewritten as an explicit state machine. Right now it's too hard to prove to yourself by inspection that it works.
right now sometimes both ends will block waiting for input from the other end, e.g. if there's an error during DBUS_COOKIE_SHA1.
the cookie keyring needs to be cached globally not just per-auth (which raises threadsafety issues too)
grep FIXME in dbus-auth.c
|
Referenced by _dbus_auth_delete_unused_bytes(), _dbus_auth_do_work(), and _dbus_auth_get_unused_bytes(). |
|
Notifies the auth conversation object that the given number of bytes of the outgoing buffer have been written out.
References _dbus_string_delete(), _dbus_string_get_const_data(), and DBUS_AUTH_NAME. |
|
Creates a new auth conversation object for the client side. See doc/dbus-sasl-profile.txt for full details on what this object does.
References _dbus_auth_unref(), NULL, side, and state. Referenced by _dbus_transport_init_base(). |
|
Called post-authentication, decodes a block of bytes received from the peer. If no encoding was negotiated, just copies the bytes (you can avoid this by checking _dbus_auth_needs_decoding()).
References _dbus_assert, _dbus_auth_needs_decoding(), _dbus_string_copy(), _dbus_string_get_length(), DBusAuthMechanismHandler::client_decode_func, DBUS_AUTH_IS_CLIENT, FALSE, mech, DBusAuthMechanismHandler::server_decode_func, and state. |
|
Gets rid of unused bytes returned by _dbus_auth_get_unused_bytes() after we've gotten them and successfully moved them elsewhere.
References _dbus_string_set_length(), DBUS_AUTH_IN_END_STATE, and incoming. |
|
Analyzes buffered input and moves the auth conversation forward, returning the new state of the auth conversation.
References _dbus_string_get_length(), DBUS_AUTH_IN_END_STATE, DBUS_AUTH_NAME, FALSE, incoming, needed_memory, outgoing, and state. Referenced by _dbus_transport_get_dispatch_status(), and _dbus_transport_get_is_authenticated(). |
|
Called post-authentication, encodes a block of bytes for sending to the peer. If no encoding was negotiated, just copies the bytes (you can avoid this by checking _dbus_auth_needs_encoding()).
References _dbus_assert, _dbus_auth_needs_encoding(), _dbus_string_copy(), _dbus_string_get_length(), DBusAuthMechanismHandler::client_encode_func, DBUS_AUTH_IS_CLIENT, FALSE, mech, DBusAuthMechanismHandler::server_encode_func, and state. |
|
Get a buffer to be used for reading bytes from the peer we're conversing with. Bytes should be appended to this buffer.
References _dbus_assert, buffer_outstanding, incoming, NULL, and TRUE. |
|
Gets bytes that need to be sent to the peer we're conversing with. After writing some bytes, _dbus_auth_bytes_sent() must be called to notify the auth object that they were written.
References _dbus_assert, _dbus_string_get_length(), FALSE, NULL, outgoing, and TRUE. |
|
Gets the identity we authorized the client as. Apps may have different policies as to what identities they allow.
References _dbus_credentials_clear(), authorized_identity, and state. Referenced by _dbus_transport_get_is_authenticated(), _dbus_transport_get_unix_process_id(), and _dbus_transport_get_unix_user(). |
|
Returns leftover bytes that were not used as part of the auth conversation. These bytes will be part of the message stream instead. This function may not be called until authentication has succeeded.
References DBUS_AUTH_IN_END_STATE, and incoming. |
|
Called post-authentication, indicates whether we need to decode the message stream with _dbus_auth_decode_data() after receiving it from the peer.
References DBusAuthMechanismHandler::client_decode_func, DBUS_AUTH_IS_CLIENT, FALSE, mech, NULL, DBusAuthMechanismHandler::server_decode_func, and state. Referenced by _dbus_auth_decode_data(). |
|
Called post-authentication, indicates whether we need to encode the message stream with _dbus_auth_encode_data() prior to sending it to the peer.
References DBusAuthMechanismHandler::client_encode_func, DBUS_AUTH_IS_CLIENT, FALSE, mech, NULL, DBusAuthMechanismHandler::server_encode_func, and state. Referenced by _dbus_auth_encode_data(). |
|
Increments the refcount of an auth object.
References _dbus_assert, NULL, and refcount. |
|
Returns a buffer with new data read into it.
References _dbus_assert, buffer_outstanding, FALSE, and incoming. |
|
Creates a new auth conversation object for the server side. See doc/dbus-sasl-profile.txt for full details on what this object does.
References DBUS_AUTH_SERVER, DBusAuthServer::failures, DBusAuthServer::max_failures, NULL, side, and state. Referenced by _dbus_transport_init_base(). |
|
Sets the "authentication context" which scopes cookies with the DBUS_COOKIE_SHA1 auth mechanism for example.
References _dbus_string_get_length(), _dbus_string_replace_len(), and context. |
|
Sets credentials received via reliable means from the operating system.
References credentials. |
|
Sets an array of authentication mechanism names that we are willing to use.
References _dbus_dup_string_array(), allowed_mechs, dbus_free_string_array(), FALSE, NULL, and TRUE. Referenced by _dbus_transport_set_auth_mechanisms(). |
|
Decrements the refcount of an auth object.
References _dbus_assert, _dbus_keyring_unref(), _dbus_list_clear(), _dbus_string_free(), allowed_mechs, challenge, context, DBUS_AUTH_CLIENT, DBUS_AUTH_IS_CLIENT, dbus_free(), dbus_free_string_array(), identity, incoming, keyring, NULL, outgoing, and refcount. Referenced by _dbus_auth_client_new(), _dbus_transport_finalize_base(), and _dbus_transport_init_base(). |