1 /*	$NetBSD: gss_display_status.c,v 1.3 2023/06/19 21:41:43 christos Exp $	*/
2 
3 /*-
4  * Copyright (c) 2005 Doug Rabson
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  *
28  *	$FreeBSD: src/lib/libgssapi/gss_display_status.c,v 1.1 2005/12/29 14:40:20 dfr Exp $
29  */
30 /*
31  * Copyright (c) 1998 - 2005 Kungliga Tekniska Högskolan
32  * (Royal Institute of Technology, Stockholm, Sweden).
33  * All rights reserved.
34  *
35  * Redistribution and use in source and binary forms, with or without
36  * modification, are permitted provided that the following conditions
37  * are met:
38  *
39  * 1. Redistributions of source code must retain the above copyright
40  *    notice, this list of conditions and the following disclaimer.
41  *
42  * 2. Redistributions in binary form must reproduce the above copyright
43  *    notice, this list of conditions and the following disclaimer in the
44  *    documentation and/or other materials provided with the distribution.
45  *
46  * 3. Neither the name of the Institute nor the names of its contributors
47  *    may be used to endorse or promote products derived from this software
48  *    without specific prior written permission.
49  *
50  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
51  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
52  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
53  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
54  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
55  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
56  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
57  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
58  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
59  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
60  * SUCH DAMAGE.
61  */
62 
63 #include "mech_locl.h"
64 
65 static const char *
calling_error(OM_uint32 v)66 calling_error(OM_uint32 v)
67 {
68     static const char *msgs[] = {
69 	NULL,			/* 0 */
70 	"A required input parameter could not be read.", /*  */
71 	"A required output parameter could not be written.", /*  */
72 	"A parameter was malformed"
73     };
74 
75     v >>= GSS_C_CALLING_ERROR_OFFSET;
76 
77     if (v == 0)
78 	return "";
79     else if (v >= sizeof(msgs)/sizeof(*msgs))
80 	return "unknown calling error";
81     else
82 	return msgs[v];
83 }
84 
85 static const char *
routine_error(OM_uint32 v)86 routine_error(OM_uint32 v)
87 {
88     static const char *msgs[] = {
89 	"Function completed successfully",			/* 0 */
90 	"An unsupported mechanism was requested",
91 	"An invalid name was supplied",
92 	"A supplied name was of an unsupported type",
93 	"Incorrect channel bindings were supplied",
94 	"An invalid status code was supplied",
95 	"A token had an invalid MIC",
96 	"No credentials were supplied, or the credentials were unavailable or inaccessible.",
97 	"No context has been established",
98 	"A token was invalid",
99 	"A credential was invalid",
100 	"The referenced credentials have expired",
101 	"The context has expired",
102 	"Miscellaneous failure (see text)",
103 	"The quality-of-protection requested could not be provide",
104 	"The operation is forbidden by local security policy",
105 	"The operation or option is not available",
106 	"The requested credential element already exists",
107 	"The provided name was not a mechanism name.",
108     };
109 
110     v >>= GSS_C_ROUTINE_ERROR_OFFSET;
111 
112     if (v >= sizeof(msgs)/sizeof(*msgs))
113 	return "unknown routine error";
114     else
115 	return msgs[v];
116 }
117 
118 static const char *
supplementary_error(OM_uint32 v)119 supplementary_error(OM_uint32 v)
120 {
121     static const char *msgs[] = {
122 	"normal completion",
123 	"continuation call to routine required",
124 	"duplicate per-message token detected",
125 	"timed-out per-message token detected",
126 	"reordered (early) per-message token detected",
127 	"skipped predecessor token(s) detected"
128     };
129 
130     v >>= GSS_C_SUPPLEMENTARY_OFFSET;
131 
132     if (v >= sizeof(msgs)/sizeof(*msgs))
133 	return "unknown routine error";
134     else
135 	return msgs[v];
136 }
137 
138 /**
139  * Convert a GSS-API status code to text
140  *
141  * @param minor_status     minor status code
142  * @param status_value     status value to convert
143  * @param status_type      One of:
144  *                         GSS_C_GSS_CODE - status_value is a GSS status code,
145  *                         GSS_C_MECH_CODE - status_value is a mechanism status code
146  * @param mech_type        underlying mechanism. Use GSS_C_NO_OID to obtain the
147  *                         system default.
148  * @param message_context  state information to extract further messages from the
149  *                         status_value
150  * @param status_string    the allocated text representation. Release with
151  *                         gss_release_buffer()
152  *
153  * @returns a gss_error code.
154  *
155  * @ingroup gssapi
156  */
157 GSSAPI_LIB_FUNCTION OM_uint32 GSSAPI_LIB_CALL
gss_display_status(OM_uint32 * minor_status,OM_uint32 status_value,int status_type,const gss_OID mech_type,OM_uint32 * message_context,gss_buffer_t status_string)158 gss_display_status(OM_uint32 *minor_status,
159     OM_uint32 status_value,
160     int status_type,
161     const gss_OID mech_type,
162     OM_uint32 *message_context,
163     gss_buffer_t status_string)
164 {
165 	OM_uint32 major_status;
166 
167 	_mg_buffer_zero(status_string);
168 	*message_context = 0;
169 
170 	major_status = _gss_mg_get_error(mech_type, status_type,
171 					 status_value, status_string);
172 	if (major_status == GSS_S_COMPLETE) {
173 
174 	    *message_context = 0;
175 	    *minor_status = 0;
176 	    return GSS_S_COMPLETE;
177 	}
178 
179 	*minor_status = 0;
180 	switch (status_type) {
181 	case GSS_C_GSS_CODE: {
182 	    	char *buf = NULL;
183 		int e;
184 
185 		if (GSS_SUPPLEMENTARY_INFO(status_value))
186 		    e = asprintf(&buf, "%s", supplementary_error(
187 		        GSS_SUPPLEMENTARY_INFO(status_value)));
188 		else
189 		    e = asprintf (&buf, "%s %s",
190 		        calling_error(GSS_CALLING_ERROR(status_value)),
191 			routine_error(GSS_ROUTINE_ERROR(status_value)));
192 
193 		if (e < 0 || buf == NULL)
194 		    break;
195 
196 		status_string->length = strlen(buf);
197 		status_string->value  = buf;
198 
199 		return GSS_S_COMPLETE;
200 	}
201 	case GSS_C_MECH_CODE: {
202 		OM_uint32 maj_junk, min_junk;
203 		gss_buffer_desc oid;
204 		char *buf = NULL;
205 		int e;
206 
207 		maj_junk = gss_oid_to_str(&min_junk, mech_type, &oid);
208 		if (maj_junk != GSS_S_COMPLETE) {
209 		    oid.value = rk_UNCONST("unknown");
210 		    oid.length = 7;
211 		}
212 
213 		e = asprintf (&buf, "unknown mech-code %lu for mech %.*s",
214 			  (unsigned long)status_value,
215 			  (int)oid.length, (char *)oid.value);
216 		if (maj_junk == GSS_S_COMPLETE)
217 		    gss_release_buffer(&min_junk, &oid);
218 
219 		if (e < 0 || buf == NULL)
220 		    break;
221 
222 		status_string->length = strlen(buf);
223 		status_string->value  = buf;
224 
225 		return GSS_S_COMPLETE;
226 	}
227 	}
228 	_mg_buffer_zero(status_string);
229 	return (GSS_S_BAD_STATUS);
230 }
231