Files
n_signer/src/policy.c

1260 lines
43 KiB
C

/* NSIGNER_HEADERLESS_DECLS_BEGIN */
#include <stddef.h>
#include <stdint.h>
#include <sys/types.h>
#include <cJSON.h>
/* from secure_mem.h */
/*
* Secure memory buffer — mlock'd, zeroized on free.
* Used for mnemonic phrases, private keys, and any sensitive material.
*/
typedef struct {
void *data; /* pointer to locked allocation */
size_t size; /* usable size in bytes */
int locked; /* 1 if mlock succeeded */
} secure_buf_t;
/* Allocate a secure buffer of `size` bytes. Returns 0 on success, -1 on failure. */
int secure_buf_alloc(secure_buf_t *buf, size_t size);
/* Zeroize and free a secure buffer. Always succeeds (idempotent). */
void secure_buf_free(secure_buf_t *buf);
/* Zeroize `len` bytes at `ptr` in a way the compiler cannot optimize away. */
void secure_memzero(void *ptr, size_t len);
/* from mnemonic.h */
/* Maximum mnemonic length: 24 words * 10 chars avg + spaces + null = 256 is safe */
#define MNEMONIC_MAX_LEN 256
/*
* Mnemonic state — holds the loaded mnemonic in secure memory.
* Only one mnemonic is active at a time per process.
*/
typedef struct {
secure_buf_t buf; /* secure storage for the mnemonic string */
int loaded; /* 1 if a mnemonic is currently loaded */
int word_count; /* 12, 15, 18, 21, or 24 */
} mnemonic_state_t;
/* Initialize mnemonic state (must be called before use). */
void mnemonic_init(mnemonic_state_t *state);
/* Load a mnemonic string into secure memory. Validates word count (12/15/18/21/24).
* Returns 0 on success, -1 on invalid input, -2 on memory error. */
int mnemonic_load(mnemonic_state_t *state, const char *phrase);
/* Zeroize and unload the mnemonic. Idempotent. */
void mnemonic_unload(mnemonic_state_t *state);
/* Check if a mnemonic is currently loaded. */
int mnemonic_is_loaded(const mnemonic_state_t *state);
/* Get the mnemonic string (only valid while loaded). Returns NULL if not loaded. */
const char *mnemonic_get_phrase(const mnemonic_state_t *state);
/* Generate a new BIP-39 mnemonic phrase (12/15/18/21/24 words) into out.
* Returns 0 on success, -1 on invalid arguments or generation failure. */
int mnemonic_generate(int word_count, char *out, size_t out_len);
/* from role_table.h */
/* Maximum limits */
#define ROLE_NAME_MAX 64
#define ROLE_PATH_MAX 128
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
PURPOSE_NOSTR = 0,
PURPOSE_BITCOIN,
PURPOSE_SSH,
PURPOSE_AGE,
PURPOSE_FIPS,
PURPOSE_PQ_SIG, /* post-quantum signatures (ML-DSA, SLH-DSA) */
PURPOSE_PQ_KEM, /* post-quantum key encapsulation (ML-KEM) */
PURPOSE_UNKNOWN
} role_purpose_t;
/* Curve enum */
typedef enum {
CURVE_SECP256K1 = 0,
CURVE_ED25519,
CURVE_X25519,
CURVE_ML_DSA_65,
CURVE_SLH_DSA_128S,
CURVE_ML_KEM_768,
CURVE_UNKNOWN
} role_curve_t;
/* Selector type — how this role's key is addressed */
typedef enum {
SELECTOR_NOSTR_INDEX, /* uses nostr_index shorthand */
SELECTOR_ROLE_PATH /* uses explicit full path */
} role_selector_type_t;
/* A single role entry */
typedef struct {
char name[ROLE_NAME_MAX];
char purpose_str[ROLE_PURPOSE_MAX];
char curve_str[ROLE_CURVE_MAX];
role_purpose_t purpose;
role_curve_t curve;
role_selector_type_t selector_type;
int nostr_index; /* valid if selector_type == SELECTOR_NOSTR_INDEX */
char role_path[ROLE_PATH_MAX]; /* valid if selector_type == SELECTOR_ROLE_PATH */
char pubkey_hex[ROLE_PUBKEY_HEX_MAX]; /* filled after derivation, empty until then */
int derived; /* 1 if pubkey_hex has been populated */
} role_entry_t;
/* The role table */
typedef struct {
role_entry_t entries[ROLE_TABLE_MAX_ENTRIES];
int count;
} role_table_t;
/* Initialize an empty role table */
void role_table_init(role_table_t *table);
/* Add a role entry. Returns 0 on success, -1 if table full, -2 if name duplicate. */
int role_table_add(role_table_t *table, const role_entry_t *entry);
/* Find a role by name. Returns pointer to entry or NULL. */
role_entry_t *role_table_find_by_name(role_table_t *table, const char *name);
/* Find a role by nostr_index. Returns pointer or NULL. */
role_entry_t *role_table_find_by_nostr_index(role_table_t *table, int index);
/* Find a role by role_path. Returns pointer or NULL. */
role_entry_t *role_table_find_by_path(role_table_t *table, const char *path);
/* Get the default role (named "main"). Returns pointer or NULL if no "main" role. */
role_entry_t *role_table_get_default(role_table_t *table);
/* Parse purpose string to enum */
role_purpose_t role_purpose_from_str(const char *s);
/* Parse curve string to enum */
role_curve_t role_curve_from_str(const char *s);
/* Purpose enum to string */
const char *role_purpose_to_str(role_purpose_t p);
/* Curve enum to string */
const char *role_curve_to_str(role_curve_t c);
/* from selector.h */
/* Error codes for selector resolution */
#define SELECTOR_OK 0
#define SELECTOR_ERR_AMBIGUOUS -1 /* multiple selectors specified */
#define SELECTOR_ERR_NOT_FOUND -2 /* no matching role in table */
#define SELECTOR_ERR_NO_DEFAULT -3 /* no selector given and no "main" role exists */
/* Parsed selector from a request's options object */
typedef struct {
int has_role; /* 1 if "role" field was present */
char role_name[ROLE_NAME_MAX];
int has_nostr_index; /* 1 if "nostr_index" field was present */
int nostr_index;
int has_role_path; /* 1 if "role_path" field was present */
char role_path[ROLE_PATH_MAX];
} selector_request_t;
/* Initialize a selector request (all fields zeroed/unset) */
void selector_request_init(selector_request_t *req);
/*
* Resolve a selector request against the role table.
* On success (returns SELECTOR_OK), *out points to the matched role_entry_t.
* On failure, returns one of the SELECTOR_ERR_* codes and *out is NULL.
*/
int selector_resolve(const selector_request_t *req, role_table_t *table, role_entry_t **out);
/*
* Return a human-readable error string for a selector error code.
*/
const char *selector_strerror(int err);
/* from enforcement.h */
/* Error codes */
#define ENFORCE_OK 0
#define ENFORCE_ERR_PURPOSE -1 /* purpose mismatch */
#define ENFORCE_ERR_CURVE -2 /* curve mismatch */
#define ENFORCE_ERR_UNKNOWN_VERB -3 /* verb not recognized */
#define ENFORCE_ERR_ALGORITHM -4 /* algorithm not valid for verb */
/* New algorithm-based verb defines (algorithm is a parameter, not implicit) */
#define VERB_SIGN "sign"
#define VERB_VERIFY "verify"
#define VERB_ENCAPSULATE "encapsulate"
#define VERB_DECAPSULATE "decapsulate"
#define VERB_DERIVE_SHARED "derive_shared_secret"
#define ENFORCE_ERR_ALGORITHM -4 /* algorithm not valid for verb */
/* New algorithm-based verb defines (algorithm is a parameter, not implicit) */
#define VERB_SIGN "sign"
#define VERB_VERIFY "verify"
#define VERB_ENCAPSULATE "encapsulate"
#define VERB_DECAPSULATE "decapsulate"
#define VERB_DERIVE_SHARED "derive_shared_secret"
/* Known verbs */
#define VERB_SIGN_EVENT "sign_event"
#define VERB_GET_PUBLIC_KEY "get_public_key"
#define VERB_NIP44_ENCRYPT "nip44_encrypt"
#define VERB_NIP44_DECRYPT "nip44_decrypt"
#define VERB_NIP04_ENCRYPT "nip04_encrypt"
#define VERB_NIP04_DECRYPT "nip04_decrypt"
/*
* Check whether `verb` is allowed to execute against `role`.
* Returns ENFORCE_OK if allowed, or an ENFORCE_ERR_* code.
*
* The enforcement rules are:
* - All nostr verbs (sign_event, get_public_key, nip44_*, nip04_*) require:
* purpose == PURPOSE_NOSTR and curve == CURVE_SECP256K1
* - Unknown verbs return ENFORCE_ERR_UNKNOWN_VERB (fail-closed).
*/
int enforce_verb_role(const char *verb, const role_entry_t *role);
/*
* Return a human-readable error string for an enforcement error code.
*/
const char *enforce_strerror(int err);
/* from policy.h */
#define POLICY_MAX_ENTRIES 32
#define POLICY_MAX_VERBS 16
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 160
#define POLICY_MAX_ALGS 16
#define POLICY_MAX_ALGS 16
/* Prompt behavior */
typedef enum {
PROMPT_NEVER = 0,
PROMPT_FIRST_PER_BOOT,
PROMPT_EVERY_REQUEST,
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
char verbs[POLICY_MAX_VERBS][POLICY_VERB_MAX_LEN];
int verb_count;
char roles[POLICY_MAX_ROLES][ROLE_NAME_MAX];
int role_count;
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
/* Algorithm-based (new) */
char algorithms[16][32]; /* algorithm names; POLICY_MAX_ALGS */
int alg_count;
int index_min; /* -1 = any */
int index_max; /* -1 = any */
/* Common */
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
typedef struct {
policy_entry_t entries[POLICY_MAX_ENTRIES];
int count;
} policy_table_t;
/* Policy check result */
#define POLICY_ALLOW 0
#define POLICY_DENY -1
#define POLICY_PROMPT -2 /* would need user confirmation */
#define POLICY_NO_MATCH -3 /* no policy entry matched (fail-closed = deny) */
/* Initialize policy table */
void policy_table_init(policy_table_t *table);
/* Initialize default policy: allow same-uid, deny others */
void policy_init_default(policy_table_t *table, uid_t owner_uid);
/* Add a policy entry. Returns 0 on success, -1 if full. */
int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
/*
* Check whether caller_id is allowed to invoke `verb` on `role_name` with given `purpose`.
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Check whether caller_id is allowed to invoke `verb` with the given
* algorithm and index (algorithm-based policy). Returns POLICY_ALLOW,
* POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH. */
int policy_check_algorithm(const policy_table_t *table, const char *caller_id,
const char *verb, const char *algorithm, int index,
policy_source_t *out_source);
/* Check whether caller_id is allowed to invoke `verb` with the given
* algorithm and index (algorithm-based policy). Returns POLICY_ALLOW,
* POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH. */
int policy_check_algorithm(const policy_table_t *table, const char *caller_id,
const char *verb, const char *algorithm, int index,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
/* Prompt mode to string */
const char *prompt_mode_to_str(prompt_mode_t m);
/* from pq_crypto.h */
/* Algorithm identifiers */
typedef enum {
CRYPTO_ALG_SECP256K1 = 0, /* existing, Nostr */
CRYPTO_ALG_ED25519, /* new, SSH signatures */
CRYPTO_ALG_X25519, /* new, key agreement */
CRYPTO_ALG_ML_DSA_65, /* new, PQ signatures */
CRYPTO_ALG_SLH_DSA_128S, /* new, PQ signatures */
CRYPTO_ALG_ML_KEM_768, /* new, PQ KEM */
CRYPTO_ALG_UNKNOWN
} crypto_alg_t;
/* Key sizes for each algorithm (compile-time constants) */
typedef struct {
size_t priv_key_len;
size_t pub_key_len;
size_t sig_len; /* 0 for KEM */
size_t ciphertext_len; /* 0 for signatures */
size_t shared_secret_len; /* 0 for signatures */
} crypto_alg_sizes_t;
/* Get size info for an algorithm. Returns NULL for CRYPTO_ALG_UNKNOWN. */
const crypto_alg_sizes_t *crypto_alg_get_sizes(crypto_alg_t alg);
/* Map role_curve_t + role_purpose_t to crypto_alg_t.
* Returns CRYPTO_ALG_UNKNOWN for unsupported combinations. */
crypto_alg_t crypto_alg_from_role(role_curve_t curve, role_purpose_t purpose);
/* Convert crypto_alg_t to string. Returns NULL for unknown. */
const char *crypto_alg_to_str(crypto_alg_t alg);
/* Parse string to crypto_alg_t. Returns CRYPTO_ALG_UNKNOWN for unrecognized. */
crypto_alg_t crypto_alg_from_str(const char *s);
/* ed25519: derive keypair from a 32-byte seed.
* priv_out and pub_out must be at least 32 bytes each.
* Returns 0 on success, -1 on error. */
int crypto_ed25519_keygen_from_seed(const unsigned char *seed, size_t seed_len,
unsigned char *priv_out, unsigned char *pub_out);
/* ed25519: sign a message. priv is 32-byte private key.
* sig_out must be at least 64 bytes. Returns 0 on success, -1 on error. */
int crypto_ed25519_sign(const unsigned char *priv, size_t priv_len,
const unsigned char *msg, size_t msg_len,
unsigned char *sig_out, size_t *sig_out_len);
/* ed25519: verify a signature. pub is 32-byte public key.
* Returns 0 on valid, 1 on invalid, -1 on error. */
int crypto_ed25519_verify(const unsigned char *pub, size_t pub_len,
const unsigned char *msg, size_t msg_len,
const unsigned char *sig, size_t sig_len);
/* x25519: derive keypair from a 32-byte seed.
* priv_out and pub_out must be at least 32 bytes each.
* Returns 0 on success, -1 on error. */
int crypto_x25519_keygen_from_seed(const unsigned char *seed, size_t seed_len,
unsigned char *priv_out, unsigned char *pub_out);
/* x25519: derive shared secret from our private key and peer's public key.
* shared_out must be at least 32 bytes. Returns 0 on success, -1 on error. */
int crypto_x25519_ecdh(const unsigned char *our_priv, size_t priv_len,
const unsigned char *peer_pub, size_t pub_len,
unsigned char *shared_out, size_t *shared_out_len);
/* Derive a 32-byte seed from a mnemonic using a BIP-44 path (SLIP-0010).
* seed_out must be at least 32 bytes. Returns 0 on success, -1 on error. */
int crypto_derive_seed_from_mnemonic(const char *mnemonic, const char *path,
unsigned char *seed_out, size_t seed_out_len);
/* ML-DSA-65: generate keypair from a 32-byte seed (deterministic).
* priv_out must be at least 4032 bytes, pub_out at least 1952 bytes.
* Returns 0 on success, -1 on error. */
int crypto_ml_dsa_65_keygen_from_seed(const unsigned char *seed, size_t seed_len,
unsigned char *priv_out, unsigned char *pub_out);
/* ML-DSA-65: sign a message. priv is 4032-byte private key.
* sig_out must be at least 3309 bytes. Returns 0 on success, -1 on error. */
int crypto_ml_dsa_65_sign(const unsigned char *priv, size_t priv_len,
const unsigned char *msg, size_t msg_len,
unsigned char *sig_out, size_t *sig_out_len);
/* ML-DSA-65: verify a signature. pub is 1952-byte public key.
* Returns 0 on valid, 1 on invalid, -1 on error. */
int crypto_ml_dsa_65_verify(const unsigned char *pub, size_t pub_len,
const unsigned char *msg, size_t msg_len,
const unsigned char *sig, size_t sig_len);
/* SLH-DSA-128s: generate keypair from a 32-byte seed (deterministic).
* priv_out must be at least 64 bytes, pub_out at least 32 bytes.
* Returns 0 on success, -1 on error. */
int crypto_slh_dsa_128s_keygen_from_seed(const unsigned char *seed, size_t seed_len,
unsigned char *priv_out, unsigned char *pub_out);
/* SLH-DSA-128s: sign a message. priv is 64-byte private key.
* sig_out must be at least 7856 bytes. Returns 0 on success, -1 on error. */
int crypto_slh_dsa_128s_sign(const unsigned char *priv, size_t priv_len,
const unsigned char *msg, size_t msg_len,
unsigned char *sig_out, size_t *sig_out_len);
/* SLH-DSA-128s: verify a signature. pub is 32-byte public key.
* Returns 0 on valid, 1 on invalid, -1 on error. */
int crypto_slh_dsa_128s_verify(const unsigned char *pub, size_t pub_len,
const unsigned char *msg, size_t msg_len,
const unsigned char *sig, size_t sig_len);
/* ML-KEM-768: generate keypair from a 32-byte seed (deterministic).
* priv_out must be at least 2400 bytes, pub_out at least 1184 bytes.
* Returns 0 on success, -1 on error. */
int crypto_ml_kem_768_keygen_from_seed(const unsigned char *seed, size_t seed_len,
unsigned char *priv_out, unsigned char *pub_out);
/* ML-KEM-768: encapsulate. pub is 1184-byte public key.
* ct_out must be at least 1088 bytes, ss_out at least 32 bytes.
* Returns 0 on success, -1 on error. */
int crypto_ml_kem_768_encaps(const unsigned char *pub, size_t pub_len,
unsigned char *ct_out, unsigned char *ss_out);
/* ML-KEM-768: decapsulate. priv is 2400-byte secret key, ct is 1088-byte ciphertext.
* ss_out must be at least 32 bytes. Returns 0 on success, -1 on error. */
int crypto_ml_kem_768_decaps(const unsigned char *priv, size_t priv_len,
const unsigned char *ct, size_t ct_len,
unsigned char *ss_out);
/* Deterministic PRNG for PQ keygen (replaces PQClean randombytes()). */
void pq_drbg_init(const unsigned char *seed, size_t seed_len);
int pq_drbg_randombytes(unsigned char *buf, size_t len);
void pq_drbg_zeroize(void);
/* from crypto.h */
/* Per-role derived key material (stored in secure memory) */
typedef struct {
secure_buf_t private_key; /* mlock'd, variable size per algorithm */
secure_buf_t public_key; /* mlock'd, variable size per algorithm */
char pubkey_hex[8192]; /* hex-encoded public key (PQ pubkeys are large) */
char npub[128]; /* bech32 npub (secp256k1 only, empty for others) */
crypto_alg_t alg; /* which algorithm this key was derived for */
int valid;
} derived_key_t;
/* Key store — holds derived keys for all roles */
typedef struct {
derived_key_t keys[ROLE_TABLE_MAX_ENTRIES];
int count;
} key_store_t;
/* Derive keys for all roles in the table using the loaded mnemonic.
* Populates key_store and sets role->pubkey_hex and role->derived for each role.
* Only derives for roles with purpose=nostr and curve=secp256k1 (for now).
* Returns number of keys derived, or -1 on error. */
int crypto_derive_all(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic);
/* Get the derived private key for a role (by table index). Returns NULL if not derived. */
const unsigned char *crypto_get_private_key(const key_store_t *store, int role_index);
/* Get the derived public key hex for a role. Returns NULL if not derived. */
const char *crypto_get_pubkey_hex(const key_store_t *store, int role_index);
/* Sign a Nostr event. event_json is the unsigned event JSON string.
* Returns a newly-allocated string containing the signed event JSON, or NULL on error.
* Caller must free() the returned string. */
char *crypto_sign_event(const key_store_t *store, int role_index, const char *event_json);
/* Zeroize all derived keys in the store. */
void crypto_wipe(key_store_t *store);
/* from alg_api.h */
/* Check whether a verb is valid for an algorithm (algorithm-based enforcement).
* Returns ENFORCE_OK, ENFORCE_ERR_ALGORITHM, or ENFORCE_ERR_UNKNOWN_VERB.
* Does NOT check purpose — purpose is irrelevant for the new verbs. */
int enforce_verb_algorithm(const char *verb, crypto_alg_t alg);
/* secp256k1 Schnorr (BIP-340) sign arbitrary bytes.
* priv is 32-byte scalar, pub is 32-byte x-only pubkey, sig_out is 64 bytes.
* Hashes the message with SHA-256 before signing (like Nostr event signing).
* Returns 0 on success, -1 on error. */
int crypto_secp256k1_schnorr_sign(const unsigned char *priv, size_t priv_len,
const unsigned char *msg, size_t msg_len,
unsigned char *sig_out, size_t *sig_out_len);
/* secp256k1 Schnorr (BIP-340) verify.
* pub is 32-byte x-only pubkey, sig is 64 bytes.
* Returns 0 on valid, 1 on invalid, -1 on error. */
int crypto_secp256k1_schnorr_verify(const unsigned char *pub, size_t pub_len,
const unsigned char *msg, size_t msg_len,
const unsigned char *sig, size_t sig_len);
/* secp256k1 ECDSA sign arbitrary bytes.
* priv is 32-byte scalar, sig_out must be at least 64 bytes (compact DER r||s).
* Hashes the message with SHA-256 before signing.
* Returns 0 on success, -1 on error. */
int crypto_secp256k1_ecdsa_sign(const unsigned char *priv, size_t priv_len,
const unsigned char *msg, size_t msg_len,
unsigned char *sig_out, size_t *sig_out_len);
/* secp256k1 ECDSA verify.
* pub is 32-byte x-only pubkey (converted internally to compressed form).
* sig is 64-byte compact (r||s). Returns 0 on valid, 1 on invalid, -1 on error. */
int crypto_secp256k1_ecdsa_verify(const unsigned char *pub, size_t pub_len,
const unsigned char *msg, size_t msg_len,
const unsigned char *sig, size_t sig_len);
/* ---- Algorithm key cache ----
* On-demand key derivation by algorithm+index, separate from the role-based
* key_store. Holds up to ALG_KEY_CACHE_MAX derived keys in secure memory.
* When full, the oldest entry is evicted (FIFO). */
#define ALG_KEY_CACHE_MAX 32
typedef struct {
crypto_alg_t alg;
int index;
secure_buf_t private_key;
secure_buf_t public_key;
char pubkey_hex[8192];
char key_id[17];
int valid;
} alg_key_entry_t;
typedef struct {
alg_key_entry_t entries[ALG_KEY_CACHE_MAX];
int count;
} algorithm_key_cache_t;
/* Initialize an empty cache. */
void alg_key_cache_init(algorithm_key_cache_t *cache);
/* Zeroize and free all entries. Idempotent. */
void alg_key_cache_wipe(algorithm_key_cache_t *cache);
/* Look up a cached entry by (alg, index). Returns NULL if not present. */
const alg_key_entry_t *alg_key_cache_get(algorithm_key_cache_t *cache, crypto_alg_t alg, int index);
/* Derive a key on-demand by (alg, index) and store it in the cache.
* Uses the standard derivation path for the algorithm.
* Returns 0 on success, -1 on error. */
int alg_key_cache_derive(algorithm_key_cache_t *cache, const mnemonic_state_t *mnemonic, crypto_alg_t alg, int index);
/* from dispatcher.h */
/* Dispatcher context — holds references to shared state */
typedef struct {
role_table_t *role_table;
mnemonic_state_t *mnemonic;
key_store_t *key_store;
algorithm_key_cache_t *alg_key_cache; /* algorithm-based on-demand keys */
} dispatcher_ctx_t;
/* Initialize dispatcher context */
void dispatcher_init(dispatcher_ctx_t *ctx, role_table_t *table, mnemonic_state_t *mnemonic, key_store_t *key_store, algorithm_key_cache_t *alg_key_cache);
/*
* Process a JSON-RPC request string and produce a JSON-RPC response string.
*
* The caller owns the returned string and must free() it.
* Returns NULL only on catastrophic allocation failure.
*
* Response format on success:
* { "id": "...", "result": "..." }
*
* Response format on error:
* { "id": "...", "error": { "code": <int>, "message": "..." } }
*
* Error codes:
* -32700 Parse error (invalid JSON)
* -32600 Invalid request (missing id/method/params)
* -32601 Method not found (unknown verb after enforcement)
* -32602 Invalid params
* 1001 ambiguous_role_selector
* 1002 role_not_found
* 1003 no_default_role
* 1004 purpose_mismatch
* 1005 curve_mismatch
* 1006 mnemonic_not_loaded
*/
char *dispatcher_handle_request(dispatcher_ctx_t *ctx, const char *json_request);
/* from server.h */
#define SERVER_SOCKET_NAME_MAX 108
#define SERVER_MAX_MSG_SIZE 16777216
/* Caller identity */
typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[POLICY_CALLER_MAX_LEN]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
typedef struct {
char socket_name[SERVER_SOCKET_NAME_MAX]; /* abstract namespace name (without \0 prefix) */
char last_error[256];
int listen_fd;
int running;
dispatcher_ctx_t *dispatcher;
policy_table_t *policy;
int socket_name_explicit;
} server_ctx_t;
/* Initialize server context. socket_name is the abstract namespace name (e.g. "nsigner").
* socket_name_explicit should be non-zero when provided via --socket-name override. */
void server_init(server_ctx_t *ctx, const char *socket_name, int socket_name_explicit,
dispatcher_ctx_t *dispatcher, policy_table_t *policy);
/* Start listening. Returns 0 on success, -1 on error. */
int server_start(server_ctx_t *ctx);
/* Get human-readable description of last server error. */
const char *server_last_error(const server_ctx_t *ctx);
/* Handle one pending connection (non-blocking). Returns 1 if handled, 0 if nothing pending, -1 on error.
* activity_cb is called with a description string for the TUI activity log. */
typedef void (*server_activity_cb)(const char *message, void *user_data);
int server_handle_one(server_ctx_t *ctx, server_activity_cb cb, void *cb_data);
/* Stop server and close socket */
void server_stop(server_ctx_t *ctx);
/* Extract caller identity from connected fd */
int server_get_caller(int fd, caller_identity_t *out);
/* from socket_name.h */
/*
* Generate random socket name in format: nsigner_<word1>_<word2>
* Returns 0 on success, -1 on error.
*/
int socket_name_random(char *out, size_t out_len);
/* from main.h */
/*
* nsigner main header - version information
*
* Version macros are auto-updated by increment_and_push.sh.
*/
/* Version information (auto-updated by build/version tooling) */
#define NSIGNER_VERSION_MAJOR 0
#define NSIGNER_VERSION_MINOR 0
#define NSIGNER_VERSION_PATCH 2
#define NSIGNER_VERSION "v0.0.2"
/* NSIGNER_HEADERLESS_DECLS_END */
#include <errno.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
static void copy_str(char *dst, size_t dst_sz, const char *src) {
if (dst == NULL || dst_sz == 0) {
return;
}
if (src == NULL) {
dst[0] = '\0';
return;
}
strncpy(dst, src, dst_sz - 1);
dst[dst_sz - 1] = '\0';
}
static int string_in_verbs(const char *needle, char haystack[][POLICY_VERB_MAX_LEN], int count) {
int i;
if (needle == NULL) {
return 0;
}
for (i = 0; i < count; ++i) {
if (strcmp(haystack[i], needle) == 0) {
return 1;
}
}
return 0;
}
static int string_in_roles(const char *needle, char haystack[][ROLE_NAME_MAX], int count) {
int i;
if (needle == NULL) {
return 0;
}
for (i = 0; i < count; ++i) {
if (strcmp(haystack[i], needle) == 0) {
return 1;
}
}
return 0;
}
static int string_in_purposes(const char *needle, char haystack[][ROLE_PURPOSE_MAX], int count) {
int i;
if (needle == NULL) {
return 0;
}
for (i = 0; i < count; ++i) {
if (strcmp(haystack[i], needle) == 0) {
return 1;
}
}
return 0;
}
static int string_in_algorithms(const char *needle, char haystack[][32], int count) {
int i;
if (needle == NULL) {
return 0;
}
for (i = 0; i < count; ++i) {
if (strcmp(haystack[i], needle) == 0 || strcmp(haystack[i], "*") == 0) {
return 1;
}
}
return 0;
}
prompt_mode_t prompt_mode_from_str(const char *s) {
if (s == NULL) {
return PROMPT_DENY;
}
if (strcmp(s, "never") == 0) {
return PROMPT_NEVER;
}
if (strcmp(s, "first_per_boot") == 0) {
return PROMPT_FIRST_PER_BOOT;
}
if (strcmp(s, "every_request") == 0) {
return PROMPT_EVERY_REQUEST;
}
if (strcmp(s, "deny") == 0) {
return PROMPT_DENY;
}
return PROMPT_DENY;
}
const char *prompt_mode_to_str(prompt_mode_t m) {
switch (m) {
case PROMPT_NEVER:
return "never";
case PROMPT_FIRST_PER_BOOT:
return "first_per_boot";
case PROMPT_EVERY_REQUEST:
return "every_request";
case PROMPT_DENY:
default:
return "deny";
}
}
int parse_preapprove_spec(const char *spec, policy_entry_t *out_entry, int *out_nostr_index) {
char *spec_copy;
char *token;
const char *caller = NULL;
const char *role = NULL;
int nostr_index = -1;
int has_role = 0;
int has_nostr_index = 0;
/* Algorithm-based fields */
int has_algorithm = 0;
int has_index = 0;
int alg_index_min = -1;
int alg_index_max = -1;
int verb_count = 0;
if (out_nostr_index != NULL) {
*out_nostr_index = -1;
}
if (spec == NULL || out_entry == NULL) {
fprintf(stderr, "ERROR: invalid --preapprove arguments\n");
return -1;
}
spec_copy = (char *)malloc(strlen(spec) + 1);
if (spec_copy == NULL) {
fprintf(stderr, "ERROR: out of memory parsing --preapprove spec: %s\n", spec);
return -1;
}
memcpy(spec_copy, spec, strlen(spec) + 1);
token = strtok(spec_copy, ",");
while (token != NULL) {
char *eq = strchr(token, '=');
if (eq == NULL || eq == token || eq[1] == '\0') {
fprintf(stderr, "ERROR: invalid --preapprove key=value field: %s\n", spec);
free(spec_copy);
return -1;
}
*eq = '\0';
if (strcmp(token, "caller") == 0) {
caller = eq + 1;
} else if (strcmp(token, "role") == 0) {
role = eq + 1;
has_role = 1;
} else if (strcmp(token, "nostr_index") == 0) {
char *endptr = NULL;
long val;
errno = 0;
val = strtol(eq + 1, &endptr, 10);
if (errno != 0 || endptr == (eq + 1) || *endptr != '\0' || val < 0) {
fprintf(stderr, "ERROR: --preapprove spec has invalid nostr_index= value: %s\n", spec);
free(spec_copy);
return -1;
}
nostr_index = (int)val;
has_nostr_index = 1;
} else if (strcmp(token, "algorithm") == 0) {
/* algorithm=<name> — algorithm-based preapprove */
if (verb_count >= 0 && out_entry->alg_count < 16) {
strncpy(out_entry->algorithms[out_entry->alg_count], eq + 1, 31);
out_entry->algorithms[out_entry->alg_count][31] = '\0';
out_entry->alg_count++;
}
has_algorithm = 1;
} else if (strcmp(token, "index") == 0) {
/* index=<N> or index=<N-M> or index=* */
char *val = eq + 1;
if (strcmp(val, "*") == 0) {
alg_index_min = -1;
alg_index_max = -1;
} else {
char *dash = strchr(val, '-');
if (dash != NULL) {
char *endptr = NULL;
long lo, hi;
*dash = '\0';
errno = 0;
lo = strtol(val, &endptr, 10);
if (errno != 0 || endptr == val || *endptr != '\0' || lo < 0) {
fprintf(stderr, "ERROR: --preapprove spec has invalid index= range: %s\n", spec);
free(spec_copy);
return -1;
}
errno = 0;
hi = strtol(dash + 1, &endptr, 10);
if (errno != 0 || endptr == dash + 1 || *endptr != '\0' || hi < lo) {
fprintf(stderr, "ERROR: --preapprove spec has invalid index= range: %s\n", spec);
free(spec_copy);
return -1;
}
alg_index_min = (int)lo;
alg_index_max = (int)hi;
} else {
char *endptr = NULL;
long val_num;
errno = 0;
val_num = strtol(val, &endptr, 10);
if (errno != 0 || endptr == val || *endptr != '\0' || val_num < 0) {
fprintf(stderr, "ERROR: --preapprove spec has invalid index= value: %s\n", spec);
free(spec_copy);
return -1;
}
alg_index_min = (int)val_num;
alg_index_max = (int)val_num;
}
}
} else if (strcmp(token, "verb") == 0) {
/* verb=<name> — can be repeated or comma-separated within the value.
* Since we split on commas already, each verb= is a single verb. */
if (verb_count < POLICY_MAX_VERBS) {
strncpy(out_entry->verbs[verb_count], eq + 1, POLICY_VERB_MAX_LEN - 1);
out_entry->verbs[verb_count][POLICY_VERB_MAX_LEN - 1] = '\0';
verb_count++;
out_entry->verb_count = verb_count;
}
} else {
fprintf(stderr, "ERROR: unknown --preapprove field '%s' in spec: %s\n", token, spec);
free(spec_copy);
return -1;
}
token = strtok(NULL, ",");
}
if (caller == NULL) {
fprintf(stderr, "ERROR: --preapprove spec missing 'caller=' field: %s\n", spec);
free(spec_copy);
return -1;
}
/* Algorithm-based entries require algorithm= (index= and verb= optional).
* Role-based entries require role= or nostr_index=. The two forms are
* mutually exclusive. */
if (has_algorithm && (has_role || has_nostr_index)) {
fprintf(stderr, "ERROR: --preapprove spec has both algorithm= and role=/nostr_index= (use one form): %s\n", spec);
free(spec_copy);
return -1;
}
if (!has_algorithm && !has_role && !has_nostr_index) {
fprintf(stderr, "ERROR: --preapprove spec must include 'algorithm=' or 'role=' or 'nostr_index=': %s\n", spec);
free(spec_copy);
return -1;
}
if (!has_algorithm && has_role && has_nostr_index) {
fprintf(stderr, "ERROR: --preapprove spec has both 'role=' and 'nostr_index=' (use one): %s\n", spec);
free(spec_copy);
return -1;
}
memset(out_entry, 0, sizeof(*out_entry));
/* Re-set the algorithm/verb fields since memset cleared them. */
/* (We parsed into out_entry before the memset, so re-parse is needed.
* Actually we parsed algorithm/verb into out_entry directly above.
* The memset wiped them. Let's re-apply by re-parsing... but that's
* complex. Instead, save them before memset and restore after.) */
/* Save algorithm-based fields before memset. */
{
char saved_algs[16][32];
int saved_alg_count = 0;
char saved_verbs[POLICY_MAX_VERBS][POLICY_VERB_MAX_LEN];
int saved_verb_count = 0;
int si;
/* We already populated out_entry->algorithms and out_entry->verbs
* during parsing. Save them before the memset below. */
saved_alg_count = out_entry->alg_count;
for (si = 0; si < saved_alg_count; si++) {
memcpy(saved_algs[si], out_entry->algorithms[si], 32);
}
saved_verb_count = out_entry->verb_count;
for (si = 0; si < saved_verb_count; si++) {
memcpy(saved_verbs[si], out_entry->verbs[si], POLICY_VERB_MAX_LEN);
}
memset(out_entry, 0, sizeof(*out_entry));
/* Restore algorithm-based fields. */
out_entry->alg_count = saved_alg_count;
for (si = 0; si < saved_alg_count; si++) {
memcpy(out_entry->algorithms[si], saved_algs[si], 32);
}
out_entry->verb_count = saved_verb_count;
for (si = 0; si < saved_verb_count; si++) {
memcpy(out_entry->verbs[si], saved_verbs[si], POLICY_VERB_MAX_LEN);
}
/* Set index range. */
if (has_algorithm) {
out_entry->index_min = alg_index_min;
out_entry->index_max = alg_index_max;
} else {
out_entry->index_min = -1;
out_entry->index_max = -1;
}
}
strncpy(out_entry->caller, caller, sizeof(out_entry->caller) - 1);
out_entry->caller[sizeof(out_entry->caller) - 1] = '\0';
if (has_algorithm) {
/* Algorithm-based entry: no role needed. */
out_entry->role_count = 0;
} else if (has_role) {
strncpy(out_entry->roles[0], role, sizeof(out_entry->roles[0]) - 1);
out_entry->roles[0][sizeof(out_entry->roles[0]) - 1] = '\0';
out_entry->role_count = 1;
} else {
/* nostr_index-based: map to role name. */
if (nostr_index == 0) {
strncpy(out_entry->roles[0], "main", sizeof(out_entry->roles[0]) - 1);
out_entry->roles[0][sizeof(out_entry->roles[0]) - 1] = '\0';
} else {
(void)snprintf(out_entry->roles[0], sizeof(out_entry->roles[0]), "nostr_idx_%d", nostr_index);
}
out_entry->role_count = 1;
if (out_nostr_index != NULL) {
*out_nostr_index = nostr_index;
}
}
out_entry->prompt = PROMPT_NEVER;
free(spec_copy);
return 0;
}
void policy_table_init(policy_table_t *table) {
if (table == NULL) {
return;
}
memset(table, 0, sizeof(*table));
}
void policy_init_default(policy_table_t *table, uid_t owner_uid) {
policy_entry_t prompt_all;
(void)owner_uid;
if (table == NULL) {
return;
}
policy_table_init(table);
memset(&prompt_all, 0, sizeof(prompt_all));
copy_str(prompt_all.caller, sizeof(prompt_all.caller), "*");
prompt_all.prompt = PROMPT_EVERY_REQUEST;
prompt_all.source = POLICY_SOURCE_DEFAULT;
(void)policy_table_add(table, &prompt_all);
}
int policy_table_add(policy_table_t *table, const policy_entry_t *entry) {
if (table == NULL || entry == NULL) {
return -1;
}
if (table->count >= POLICY_MAX_ENTRIES) {
return -1;
}
table->entries[table->count] = *entry;
table->count++;
return 0;
}
int policy_table_insert_before_last(policy_table_t *table, const policy_entry_t *entry) {
if (table == NULL || entry == NULL) {
return -1;
}
if (table->count >= POLICY_MAX_ENTRIES) {
return -1;
}
if (table->count == 0) {
return policy_table_add(table, entry);
}
table->entries[table->count] = table->entries[table->count - 1];
table->entries[table->count - 1] = *entry;
table->count++;
return 0;
}
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source) {
int i;
if (out_source != NULL) {
*out_source = POLICY_SOURCE_DEFAULT;
}
if (table == NULL || caller_id == NULL || verb == NULL || role_name == NULL || purpose == NULL) {
return POLICY_NO_MATCH;
}
for (i = 0; i < table->count; ++i) {
const policy_entry_t *entry = &table->entries[i];
int caller_ok;
int verb_ok;
int role_ok;
int purpose_ok;
caller_ok = (strcmp(entry->caller, "*") == 0) || (strcmp(entry->caller, caller_id) == 0);
if (!caller_ok) {
continue;
}
verb_ok = (entry->verb_count == 0) || string_in_verbs(verb, (char (*)[POLICY_VERB_MAX_LEN])entry->verbs, entry->verb_count);
if (!verb_ok) {
continue;
}
role_ok = (entry->role_count == 0) || string_in_roles(role_name, (char (*)[ROLE_NAME_MAX])entry->roles, entry->role_count);
if (!role_ok) {
continue;
}
purpose_ok = (entry->purpose_count == 0) || string_in_purposes(purpose, (char (*)[ROLE_PURPOSE_MAX])entry->purposes, entry->purpose_count);
if (!purpose_ok) {
continue;
}
if (out_source != NULL) {
*out_source = entry->source;
}
if (entry->prompt == PROMPT_DENY) {
return POLICY_DENY;
}
if (entry->prompt == PROMPT_NEVER) {
return POLICY_ALLOW;
}
if (out_source != NULL) {
*out_source = POLICY_SOURCE_DEFAULT;
}
return POLICY_PROMPT;
}
return POLICY_NO_MATCH;
}
/* ---- Algorithm-based policy check ----
*
* policy_check_algorithm() checks whether a caller is allowed to invoke
* a verb with a given algorithm and index. Only entries with alg_count > 0
* (algorithm-based entries) are considered. Role-based entries are
* ignored here (they're handled by policy_check()).
*
* Matching criteria:
* - caller matches (exact or "*")
* - verb matches (or verb_count == 0 = any verb)
* - algorithm matches (or alg_count == 0 = any algorithm, or "*" entry)
* - index is within [index_min, index_max] (or index_min == -1 = any)
*/
int policy_check_algorithm(const policy_table_t *table, const char *caller_id,
const char *verb, const char *algorithm, int index,
policy_source_t *out_source) {
int i;
if (out_source != NULL) {
*out_source = POLICY_SOURCE_DEFAULT;
}
if (table == NULL || caller_id == NULL || verb == NULL || algorithm == NULL) {
return POLICY_NO_MATCH;
}
for (i = 0; i < table->count; ++i) {
const policy_entry_t *entry = &table->entries[i];
int caller_ok;
int verb_ok;
int alg_ok;
int index_ok;
/* Only consider algorithm-based entries. */
if (entry->alg_count == 0) {
continue;
}
caller_ok = (strcmp(entry->caller, "*") == 0) || (strcmp(entry->caller, caller_id) == 0);
if (!caller_ok) {
continue;
}
verb_ok = (entry->verb_count == 0) ||
string_in_verbs(verb, (char (*)[POLICY_VERB_MAX_LEN])entry->verbs, entry->verb_count);
if (!verb_ok) {
continue;
}
alg_ok = string_in_algorithms(algorithm,
(char (*)[32])entry->algorithms, entry->alg_count);
if (!alg_ok) {
continue;
}
/* Index check: -1 means any index is allowed. */
if (entry->index_min < 0 || entry->index_max < 0) {
index_ok = 1;
} else {
index_ok = (index >= entry->index_min && index <= entry->index_max);
}
if (!index_ok) {
continue;
}
if (out_source != NULL) {
*out_source = entry->source;
}
if (entry->prompt == PROMPT_DENY) {
return POLICY_DENY;
}
if (entry->prompt == PROMPT_NEVER) {
return POLICY_ALLOW;
}
if (out_source != NULL) {
*out_source = POLICY_SOURCE_DEFAULT;
}
return POLICY_PROMPT;
}
return POLICY_NO_MATCH;
}