1#ifndef _FS_CEPH_AUTH_H
2#define _FS_CEPH_AUTH_H
3
4#include <linux/ceph/types.h>
5#include <linux/ceph/buffer.h>
6
7
8
9
10
11
12
13
14struct ceph_auth_client;
15struct ceph_authorizer;
16struct ceph_msg;
17
18struct ceph_auth_handshake {
19 struct ceph_authorizer *authorizer;
20 void *authorizer_buf;
21 size_t authorizer_buf_len;
22 void *authorizer_reply_buf;
23 size_t authorizer_reply_buf_len;
24 int (*sign_message)(struct ceph_auth_handshake *auth,
25 struct ceph_msg *msg);
26 int (*check_message_signature)(struct ceph_auth_handshake *auth,
27 struct ceph_msg *msg);
28};
29
30struct ceph_auth_client_ops {
31 const char *name;
32
33
34
35
36
37 int (*is_authenticated)(struct ceph_auth_client *ac);
38
39
40
41
42
43 int (*should_authenticate)(struct ceph_auth_client *ac);
44
45
46
47
48
49
50 int (*build_request)(struct ceph_auth_client *ac, void *buf, void *end);
51 int (*handle_reply)(struct ceph_auth_client *ac, int result,
52 void *buf, void *end);
53
54
55
56
57
58 int (*create_authorizer)(struct ceph_auth_client *ac, int peer_type,
59 struct ceph_auth_handshake *auth);
60
61 int (*update_authorizer)(struct ceph_auth_client *ac, int peer_type,
62 struct ceph_auth_handshake *auth);
63 int (*verify_authorizer_reply)(struct ceph_auth_client *ac,
64 struct ceph_authorizer *a, size_t len);
65 void (*destroy_authorizer)(struct ceph_auth_client *ac,
66 struct ceph_authorizer *a);
67 void (*invalidate_authorizer)(struct ceph_auth_client *ac,
68 int peer_type);
69
70
71 void (*reset)(struct ceph_auth_client *ac);
72
73 void (*destroy)(struct ceph_auth_client *ac);
74
75 int (*sign_message)(struct ceph_auth_handshake *auth,
76 struct ceph_msg *msg);
77 int (*check_message_signature)(struct ceph_auth_handshake *auth,
78 struct ceph_msg *msg);
79};
80
81struct ceph_auth_client {
82 u32 protocol;
83 void *private;
84 const struct ceph_auth_client_ops *ops;
85
86 bool negotiating;
87 const char *name;
88 u64 global_id;
89 const struct ceph_crypto_key *key;
90 unsigned want_keys;
91
92 struct mutex mutex;
93};
94
95extern struct ceph_auth_client *ceph_auth_init(const char *name,
96 const struct ceph_crypto_key *key);
97extern void ceph_auth_destroy(struct ceph_auth_client *ac);
98
99extern void ceph_auth_reset(struct ceph_auth_client *ac);
100
101extern int ceph_auth_build_hello(struct ceph_auth_client *ac,
102 void *buf, size_t len);
103extern int ceph_handle_auth_reply(struct ceph_auth_client *ac,
104 void *buf, size_t len,
105 void *reply_buf, size_t reply_len);
106extern int ceph_entity_name_encode(const char *name, void **p, void *end);
107
108extern int ceph_build_auth(struct ceph_auth_client *ac,
109 void *msg_buf, size_t msg_len);
110
111extern int ceph_auth_is_authenticated(struct ceph_auth_client *ac);
112extern int ceph_auth_create_authorizer(struct ceph_auth_client *ac,
113 int peer_type,
114 struct ceph_auth_handshake *auth);
115extern void ceph_auth_destroy_authorizer(struct ceph_auth_client *ac,
116 struct ceph_authorizer *a);
117extern int ceph_auth_update_authorizer(struct ceph_auth_client *ac,
118 int peer_type,
119 struct ceph_auth_handshake *a);
120extern int ceph_auth_verify_authorizer_reply(struct ceph_auth_client *ac,
121 struct ceph_authorizer *a,
122 size_t len);
123extern void ceph_auth_invalidate_authorizer(struct ceph_auth_client *ac,
124 int peer_type);
125
126static inline int ceph_auth_sign_message(struct ceph_auth_handshake *auth,
127 struct ceph_msg *msg)
128{
129 if (auth->sign_message)
130 return auth->sign_message(auth, msg);
131 return 0;
132}
133
134static inline
135int ceph_auth_check_message_signature(struct ceph_auth_handshake *auth,
136 struct ceph_msg *msg)
137{
138 if (auth->check_message_signature)
139 return auth->check_message_signature(auth, msg);
140 return 0;
141}
142#endif
143