1290931Srodrigc/* $OpenBSD: ldapclient.c,v 1.31 2014/11/16 23:24:44 tedu Exp $ */
2290931Srodrigc/* $FreeBSD: stable/11/usr.sbin/ypldap/ldapclient.c 309872 2016-12-12 02:24:54Z araujo $ */
3290931Srodrigc
4290931Srodrigc/*
5290931Srodrigc * Copyright (c) 2008 Alexander Schrijver <aschrijver@openbsd.org>
6290931Srodrigc * Copyright (c) 2008 Pierre-Yves Ritschard <pyr@openbsd.org>
7290931Srodrigc *
8290931Srodrigc * Permission to use, copy, modify, and distribute this software for any
9290931Srodrigc * purpose with or without fee is hereby granted, provided that the above
10290931Srodrigc * copyright notice and this permission notice appear in all copies.
11290931Srodrigc *
12290931Srodrigc * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
13290931Srodrigc * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
14290931Srodrigc * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
15290931Srodrigc * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
16290931Srodrigc * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17290931Srodrigc * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18290931Srodrigc * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19290931Srodrigc */
20290931Srodrigc
21290931Srodrigc#include <sys/types.h>
22290931Srodrigc#include <sys/param.h>
23290931Srodrigc#include <sys/queue.h>
24290931Srodrigc#include <sys/socket.h>
25290931Srodrigc#include <sys/tree.h>
26290931Srodrigc
27290931Srodrigc#include <netinet/in.h>
28290931Srodrigc#include <arpa/inet.h>
29290931Srodrigc
30290931Srodrigc#include <netdb.h>
31290931Srodrigc#include <errno.h>
32290931Srodrigc#include <err.h>
33290931Srodrigc#include <event.h>
34290931Srodrigc#include <fcntl.h>
35290931Srodrigc#include <unistd.h>
36290931Srodrigc#include <pwd.h>
37290942Srodrigc#include <signal.h>
38290931Srodrigc#include <stdio.h>
39290931Srodrigc#include <stdlib.h>
40290931Srodrigc#include <string.h>
41290931Srodrigc
42290931Srodrigc#include "aldap.h"
43290931Srodrigc#include "ypldap.h"
44290931Srodrigc
45290931Srodrigcvoid    client_sig_handler(int, short, void *);
46290931Srodrigcvoid	client_dispatch_dns(int, short, void *);
47290931Srodrigcvoid    client_dispatch_parent(int, short, void *);
48290931Srodrigcvoid    client_shutdown(void);
49290931Srodrigcvoid    client_connect(int, short, void *);
50290931Srodrigcvoid    client_configure(struct env *);
51290931Srodrigcvoid    client_periodic_update(int, short, void *);
52290931Srodrigcint	client_build_req(struct idm *, struct idm_req *, struct aldap_message *,
53290931Srodrigc	    int, int);
54290931Srodrigcint	client_search_idm(struct env *, struct idm *, struct aldap *,
55290931Srodrigc	    char **, char *, int, int, enum imsg_type);
56290931Srodrigcint	client_try_idm(struct env *, struct idm *);
57290931Srodrigcint	client_addr_init(struct idm *);
58290931Srodrigcint	client_addr_free(struct idm *);
59290931Srodrigc
60297907Saraujostruct aldap	*client_aldap_open(struct ypldap_addr_list *);
61290931Srodrigc
62290931Srodrigc/*
63290931Srodrigc * dummy wrapper to provide aldap_init with its fd's.
64290931Srodrigc */
65290931Srodrigcstruct aldap *
66297907Saraujoclient_aldap_open(struct ypldap_addr_list *addr)
67290931Srodrigc{
68290931Srodrigc	int			 fd = -1;
69290931Srodrigc	struct ypldap_addr	 *p;
70290931Srodrigc
71297907Saraujo	TAILQ_FOREACH(p, addr, next) {
72290931Srodrigc		char			 hbuf[NI_MAXHOST], sbuf[NI_MAXSERV];
73290931Srodrigc		struct sockaddr		*sa = (struct sockaddr *)&p->ss;
74290931Srodrigc
75290940Srodrigc		if (getnameinfo(sa, sa->sa_len, hbuf, sizeof(hbuf), sbuf,
76290931Srodrigc			sizeof(sbuf), NI_NUMERICHOST | NI_NUMERICSERV))
77290931Srodrigc				errx(1, "could not get numeric hostname");
78290931Srodrigc
79290931Srodrigc		if ((fd = socket(sa->sa_family, SOCK_STREAM, 0)) < 0)
80290931Srodrigc			return NULL;
81290931Srodrigc
82290940Srodrigc		if (connect(fd, sa, sa->sa_len) == 0)
83290931Srodrigc			break;
84290931Srodrigc
85290931Srodrigc		warn("connect to %s port %s (%s) failed", hbuf, sbuf, "tcp");
86290931Srodrigc		close(fd);
87290931Srodrigc	}
88290931Srodrigc
89290931Srodrigc	if (fd == -1)
90290931Srodrigc		return NULL;
91290931Srodrigc
92290931Srodrigc	return aldap_init(fd);
93290931Srodrigc}
94290931Srodrigc
95290931Srodrigcint
96290931Srodrigcclient_addr_init(struct idm *idm)
97290931Srodrigc{
98290931Srodrigc        struct sockaddr_in      *sa_in;
99290931Srodrigc        struct sockaddr_in6     *sa_in6;
100290931Srodrigc        struct ypldap_addr         *h;
101290931Srodrigc
102297907Saraujo	TAILQ_FOREACH(h, &idm->idm_addr, next) {
103290931Srodrigc                switch (h->ss.ss_family) {
104290931Srodrigc                case AF_INET:
105290931Srodrigc                        sa_in = (struct sockaddr_in *)&h->ss;
106290931Srodrigc                        if (ntohs(sa_in->sin_port) == 0)
107290931Srodrigc                                sa_in->sin_port = htons(LDAP_PORT);
108290931Srodrigc                        idm->idm_state = STATE_DNS_DONE;
109290931Srodrigc                        break;
110290931Srodrigc                case AF_INET6:
111290931Srodrigc                        sa_in6 = (struct sockaddr_in6 *)&h->ss;
112290931Srodrigc                        if (ntohs(sa_in6->sin6_port) == 0)
113290931Srodrigc                                sa_in6->sin6_port = htons(LDAP_PORT);
114290931Srodrigc                        idm->idm_state = STATE_DNS_DONE;
115290931Srodrigc                        break;
116290931Srodrigc                default:
117290931Srodrigc                        fatalx("king bula sez: wrong AF in client_addr_init");
118290931Srodrigc                        /* not reached */
119290931Srodrigc                }
120290931Srodrigc        }
121290931Srodrigc
122290931Srodrigc        return (0);
123290931Srodrigc}
124290931Srodrigc
125290931Srodrigcint
126290931Srodrigcclient_addr_free(struct idm *idm)
127290931Srodrigc{
128297907Saraujo        struct ypldap_addr         *h;
129290931Srodrigc
130297907Saraujo	while (!TAILQ_EMPTY(&idm->idm_addr)) {
131297907Saraujo		h = TAILQ_FIRST(&idm->idm_addr);
132297907Saraujo		TAILQ_REMOVE(&idm->idm_addr, h, next);
133290931Srodrigc		free(h);
134290931Srodrigc	}
135290931Srodrigc
136290931Srodrigc	return (0);
137290931Srodrigc}
138290931Srodrigc
139290931Srodrigcvoid
140290931Srodrigcclient_sig_handler(int sig, short event, void *p)
141290931Srodrigc{
142290931Srodrigc	switch (sig) {
143290931Srodrigc	case SIGINT:
144290931Srodrigc	case SIGTERM:
145290931Srodrigc		client_shutdown();
146290931Srodrigc		break;
147290931Srodrigc	default:
148290931Srodrigc		fatalx("unexpected signal");
149290931Srodrigc	}
150290931Srodrigc}
151290931Srodrigc
152290931Srodrigcvoid
153290931Srodrigcclient_dispatch_dns(int fd, short events, void *p)
154290931Srodrigc{
155290931Srodrigc	struct imsg		 imsg;
156290931Srodrigc	u_int16_t		 dlen;
157290931Srodrigc	u_char			*data;
158290931Srodrigc	struct ypldap_addr	*h;
159290931Srodrigc	int			 n, wait_cnt = 0;
160290931Srodrigc	struct idm		*idm;
161290931Srodrigc	int			 shut = 0;
162290931Srodrigc
163290931Srodrigc	struct env		*env = p;
164290931Srodrigc	struct imsgev		*iev = env->sc_iev_dns;
165290931Srodrigc	struct imsgbuf		*ibuf = &iev->ibuf;
166290931Srodrigc
167290931Srodrigc	if ((events & (EV_READ | EV_WRITE)) == 0)
168290931Srodrigc		fatalx("unknown event");
169290931Srodrigc
170290931Srodrigc	if (events & EV_READ) {
171292270Saraujo		if ((n = imsg_read(ibuf)) == -1 && errno != EAGAIN)
172290931Srodrigc			fatal("imsg_read error");
173290931Srodrigc		if (n == 0)
174290931Srodrigc			shut = 1;
175290931Srodrigc	}
176290931Srodrigc	if (events & EV_WRITE) {
177290931Srodrigc		if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN)
178290931Srodrigc			fatal("msgbuf_write");
179290931Srodrigc		if (n == 0)
180290931Srodrigc			shut = 1;
181290931Srodrigc		goto done;
182290931Srodrigc	}
183290931Srodrigc
184290931Srodrigc	for (;;) {
185290931Srodrigc		if ((n = imsg_get(ibuf, &imsg)) == -1)
186290931Srodrigc			fatal("client_dispatch_dns: imsg_get error");
187290931Srodrigc		if (n == 0)
188290931Srodrigc			break;
189290931Srodrigc
190290931Srodrigc		switch (imsg.hdr.type) {
191290931Srodrigc		case IMSG_HOST_DNS:
192290931Srodrigc			TAILQ_FOREACH(idm, &env->sc_idms, idm_entry)
193290931Srodrigc				if (idm->idm_id == imsg.hdr.peerid)
194290931Srodrigc					break;
195290931Srodrigc			if (idm == NULL) {
196290931Srodrigc				log_warnx("IMSG_HOST_DNS with invalid peerID");
197290931Srodrigc				break;
198290931Srodrigc			}
199297907Saraujo			if (!TAILQ_EMPTY(&idm->idm_addr)) {
200297907Saraujo				log_warnx("IMSG_HOST_DNS but addrs set!");
201290931Srodrigc				break;
202290931Srodrigc			}
203290931Srodrigc
204290931Srodrigc			dlen = imsg.hdr.len - IMSG_HEADER_SIZE;
205290931Srodrigc			if (dlen == 0) {	/* no data -> temp error */
206290931Srodrigc				idm->idm_state = STATE_DNS_TEMPFAIL;
207290931Srodrigc				break;
208290931Srodrigc			}
209290931Srodrigc
210290931Srodrigc			data = (u_char *)imsg.data;
211290931Srodrigc			while (dlen >= sizeof(struct sockaddr_storage)) {
212297907Saraujo				if ((h = calloc(1, sizeof(*h))) == NULL)
213290931Srodrigc					fatal(NULL);
214290931Srodrigc				memcpy(&h->ss, data, sizeof(h->ss));
215297907Saraujo				TAILQ_INSERT_HEAD(&idm->idm_addr, h, next);
216290931Srodrigc
217290931Srodrigc				data += sizeof(h->ss);
218290931Srodrigc				dlen -= sizeof(h->ss);
219290931Srodrigc			}
220290931Srodrigc			if (dlen != 0)
221290931Srodrigc				fatalx("IMSG_HOST_DNS: dlen != 0");
222290931Srodrigc
223290931Srodrigc			client_addr_init(idm);
224290931Srodrigc
225290931Srodrigc			break;
226290931Srodrigc		default:
227290931Srodrigc			break;
228290931Srodrigc		}
229290931Srodrigc		imsg_free(&imsg);
230290931Srodrigc	}
231290931Srodrigc
232290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
233290931Srodrigc		if (client_try_idm(env, idm) == -1)
234290931Srodrigc			idm->idm_state = STATE_LDAP_FAIL;
235290931Srodrigc
236290931Srodrigc		if (idm->idm_state < STATE_LDAP_DONE)
237290931Srodrigc			wait_cnt++;
238290931Srodrigc	}
239290931Srodrigc	if (wait_cnt == 0)
240290931Srodrigc		imsg_compose_event(env->sc_iev, IMSG_END_UPDATE, 0, 0, -1,
241290931Srodrigc		    NULL, 0);
242290931Srodrigc
243290931Srodrigcdone:
244290931Srodrigc	if (!shut)
245290931Srodrigc		imsg_event_add(iev);
246290931Srodrigc	else {
247290931Srodrigc		/* this pipe is dead, so remove the event handler */
248290931Srodrigc		event_del(&iev->ev);
249290931Srodrigc		event_loopexit(NULL);
250290931Srodrigc	}
251290931Srodrigc}
252290931Srodrigc
253290931Srodrigcvoid
254290931Srodrigcclient_dispatch_parent(int fd, short events, void *p)
255290931Srodrigc{
256290931Srodrigc	int			 n;
257290931Srodrigc	int			 shut = 0;
258290931Srodrigc	struct imsg		 imsg;
259290931Srodrigc	struct env		*env = p;
260290931Srodrigc	struct imsgev		*iev = env->sc_iev;
261290931Srodrigc	struct imsgbuf		*ibuf = &iev->ibuf;
262290931Srodrigc
263290931Srodrigc	if ((events & (EV_READ | EV_WRITE)) == 0)
264290931Srodrigc		fatalx("unknown event");
265290931Srodrigc
266290931Srodrigc	if (events & EV_READ) {
267292270Saraujo		if ((n = imsg_read(ibuf)) == -1 && errno != EAGAIN)
268290931Srodrigc			fatal("imsg_read error");
269290931Srodrigc		if (n == 0)
270290931Srodrigc			shut = 1;
271290931Srodrigc	}
272290931Srodrigc	if (events & EV_WRITE) {
273290931Srodrigc		if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN)
274290931Srodrigc			fatal("msgbuf_write");
275290931Srodrigc		if (n == 0)
276290931Srodrigc			shut = 1;
277290931Srodrigc		goto done;
278290931Srodrigc	}
279290931Srodrigc
280290931Srodrigc	for (;;) {
281290931Srodrigc		if ((n = imsg_get(ibuf, &imsg)) == -1)
282290931Srodrigc			fatal("client_dispatch_parent: imsg_get error");
283290931Srodrigc		if (n == 0)
284290931Srodrigc			break;
285290931Srodrigc
286290931Srodrigc		switch (imsg.hdr.type) {
287290931Srodrigc		case IMSG_CONF_START: {
288290931Srodrigc			struct env	params;
289290931Srodrigc
290290931Srodrigc			if (env->sc_flags & F_CONFIGURING) {
291290931Srodrigc				log_warnx("configuration already in progress");
292290931Srodrigc				break;
293290931Srodrigc			}
294290931Srodrigc			memcpy(&params, imsg.data, sizeof(params));
295290931Srodrigc			log_debug("configuration starting");
296290931Srodrigc			env->sc_flags |= F_CONFIGURING;
297290931Srodrigc			purge_config(env);
298290931Srodrigc			memcpy(&env->sc_conf_tv, &params.sc_conf_tv,
299290931Srodrigc			    sizeof(env->sc_conf_tv));
300290931Srodrigc			env->sc_flags |= params.sc_flags;
301290931Srodrigc			break;
302290931Srodrigc		}
303290931Srodrigc		case IMSG_CONF_IDM: {
304290931Srodrigc			struct idm	*idm;
305290931Srodrigc
306290931Srodrigc			if (!(env->sc_flags & F_CONFIGURING))
307290931Srodrigc				break;
308290931Srodrigc			if ((idm = calloc(1, sizeof(*idm))) == NULL)
309290931Srodrigc				fatal(NULL);
310290931Srodrigc			memcpy(idm, imsg.data, sizeof(*idm));
311290931Srodrigc			idm->idm_env = env;
312290931Srodrigc			TAILQ_INSERT_TAIL(&env->sc_idms, idm, idm_entry);
313290931Srodrigc			break;
314290931Srodrigc		}
315290931Srodrigc		case IMSG_CONF_END:
316290931Srodrigc			env->sc_flags &= ~F_CONFIGURING;
317290931Srodrigc			log_debug("applying configuration");
318290931Srodrigc			client_configure(env);
319290931Srodrigc			break;
320290931Srodrigc		default:
321290931Srodrigc			log_debug("client_dispatch_parent: unexpect imsg %d",
322290931Srodrigc			    imsg.hdr.type);
323290931Srodrigc
324290931Srodrigc			break;
325290931Srodrigc		}
326290931Srodrigc		imsg_free(&imsg);
327290931Srodrigc	}
328290931Srodrigc
329290931Srodrigcdone:
330290931Srodrigc	if (!shut)
331290931Srodrigc		imsg_event_add(iev);
332290931Srodrigc	else {
333290931Srodrigc		/* this pipe is dead, so remove the event handler */
334290931Srodrigc		event_del(&iev->ev);
335290931Srodrigc		event_loopexit(NULL);
336290931Srodrigc	}
337290931Srodrigc}
338290931Srodrigc
339290931Srodrigcvoid
340290931Srodrigcclient_shutdown(void)
341290931Srodrigc{
342290931Srodrigc	log_info("ldap client exiting");
343290931Srodrigc	_exit(0);
344290931Srodrigc}
345290931Srodrigc
346290931Srodrigcpid_t
347290931Srodrigcldapclient(int pipe_main2client[2])
348290931Srodrigc{
349290931Srodrigc	pid_t            pid, dns_pid;
350290931Srodrigc	int              pipe_dns[2];
351290931Srodrigc	struct passwd	*pw;
352290931Srodrigc	struct event	 ev_sigint;
353290931Srodrigc	struct event	 ev_sigterm;
354290931Srodrigc	struct env	 env;
355290931Srodrigc
356290931Srodrigc	switch (pid = fork()) {
357290931Srodrigc	case -1:
358290931Srodrigc		fatal("cannot fork");
359290931Srodrigc		break;
360290931Srodrigc	case 0:
361290931Srodrigc		break;
362290931Srodrigc	default:
363290931Srodrigc		return (pid);
364290931Srodrigc	}
365290931Srodrigc
366309872Saraujo	memset(&env, 0, sizeof(env));
367290931Srodrigc	TAILQ_INIT(&env.sc_idms);
368290931Srodrigc
369292273Saraujo	if ((pw = getpwnam(YPLDAP_USER)) == NULL)
370290931Srodrigc		fatal("getpwnam");
371290931Srodrigc
372290931Srodrigc	if (socketpair(AF_UNIX, SOCK_STREAM, PF_UNSPEC, pipe_dns) == -1)
373290931Srodrigc		fatal("socketpair");
374290931Srodrigc	dns_pid = ypldap_dns(pipe_dns, pw);
375290931Srodrigc	close(pipe_dns[1]);
376290931Srodrigc
377290931Srodrigc#ifndef DEBUG
378290931Srodrigc	if (chroot(pw->pw_dir) == -1)
379290931Srodrigc		fatal("chroot");
380290931Srodrigc	if (chdir("/") == -1)
381290931Srodrigc		fatal("chdir");
382290931Srodrigc#else
383290931Srodrigc#warning disabling chrooting in DEBUG mode
384290931Srodrigc#endif
385290931Srodrigc	setproctitle("ldap client");
386290931Srodrigc	ypldap_process = PROC_CLIENT;
387290931Srodrigc
388290931Srodrigc#ifndef DEBUG
389290931Srodrigc	if (setgroups(1, &pw->pw_gid) ||
390290931Srodrigc	    setresgid(pw->pw_gid, pw->pw_gid, pw->pw_gid) ||
391290931Srodrigc	    setresuid(pw->pw_uid, pw->pw_uid, pw->pw_uid))
392290931Srodrigc		fatal("cannot drop privileges");
393290931Srodrigc#else
394290931Srodrigc#warning disabling privilege revocation in DEBUG mode
395290931Srodrigc#endif
396290931Srodrigc
397290931Srodrigc	event_init();
398290931Srodrigc	signal(SIGPIPE, SIG_IGN);
399290931Srodrigc	signal_set(&ev_sigint, SIGINT, client_sig_handler, NULL);
400290931Srodrigc	signal_set(&ev_sigterm, SIGTERM, client_sig_handler, NULL);
401290931Srodrigc	signal_add(&ev_sigint, NULL);
402290931Srodrigc	signal_add(&ev_sigterm, NULL);
403290931Srodrigc
404290931Srodrigc	close(pipe_main2client[0]);
405290931Srodrigc	if ((env.sc_iev = calloc(1, sizeof(*env.sc_iev))) == NULL)
406290931Srodrigc		fatal(NULL);
407290931Srodrigc	if ((env.sc_iev_dns = calloc(1, sizeof(*env.sc_iev_dns))) == NULL)
408290931Srodrigc		fatal(NULL);
409290931Srodrigc
410290931Srodrigc	env.sc_iev->events = EV_READ;
411290931Srodrigc	env.sc_iev->data = &env;
412290931Srodrigc	imsg_init(&env.sc_iev->ibuf, pipe_main2client[1]);
413290931Srodrigc	env.sc_iev->handler = client_dispatch_parent;
414290931Srodrigc	event_set(&env.sc_iev->ev, env.sc_iev->ibuf.fd, env.sc_iev->events,
415290931Srodrigc	    env.sc_iev->handler, &env);
416290931Srodrigc	event_add(&env.sc_iev->ev, NULL);
417290931Srodrigc
418290931Srodrigc	env.sc_iev_dns->events = EV_READ;
419290931Srodrigc	env.sc_iev_dns->data = &env;
420290931Srodrigc	imsg_init(&env.sc_iev_dns->ibuf, pipe_dns[0]);
421290931Srodrigc	env.sc_iev_dns->handler = client_dispatch_dns;
422290931Srodrigc	event_set(&env.sc_iev_dns->ev, env.sc_iev_dns->ibuf.fd,
423290931Srodrigc	    env.sc_iev_dns->events, env.sc_iev_dns->handler, &env);
424290931Srodrigc	event_add(&env.sc_iev_dns->ev, NULL);
425290931Srodrigc
426290931Srodrigc	event_dispatch();
427290931Srodrigc	client_shutdown();
428290931Srodrigc
429290931Srodrigc	return (0);
430290931Srodrigc
431290931Srodrigc}
432290931Srodrigc
433290931Srodrigcint
434290931Srodrigcclient_build_req(struct idm *idm, struct idm_req *ir, struct aldap_message *m,
435290931Srodrigc    int min_attr, int max_attr)
436290931Srodrigc{
437290931Srodrigc	char	**ldap_attrs;
438290931Srodrigc	int	 i, k;
439290931Srodrigc
440309872Saraujo	memset(ir, 0, sizeof(*ir));
441290931Srodrigc	for (i = min_attr; i < max_attr; i++) {
442290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i)) {
443290931Srodrigc			if (strlcat(ir->ir_line, idm->idm_attrs[i],
444290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
445290931Srodrigc				/*
446290931Srodrigc				 * entry yields a line > 1024, trash it.
447290931Srodrigc				 */
448290931Srodrigc				return (-1);
449290931Srodrigc
450290931Srodrigc			if (i == ATTR_UID) {
451290931Srodrigc				ir->ir_key.ik_uid = strtonum(
452290931Srodrigc				    idm->idm_attrs[i], 0,
453290931Srodrigc				    UID_MAX, NULL);
454290931Srodrigc			} else if (i == ATTR_GR_GID) {
455290931Srodrigc				ir->ir_key.ik_gid = strtonum(
456290931Srodrigc				    idm->idm_attrs[i], 0,
457290931Srodrigc				    GID_MAX, NULL);
458290931Srodrigc			}
459290931Srodrigc		} else if (idm->idm_list & F_LIST(i)) {
460290931Srodrigc			aldap_match_attr(m, idm->idm_attrs[i], &ldap_attrs);
461290931Srodrigc			for (k = 0; k >= 0 && ldap_attrs && ldap_attrs[k] != NULL; k++) {
462290931Srodrigc				/* XXX: Fail when attributes have illegal characters e.g. ',' */
463290931Srodrigc				if (strlcat(ir->ir_line, ldap_attrs[k],
464290931Srodrigc				    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
465290931Srodrigc					continue;
466290931Srodrigc				if (ldap_attrs[k+1] != NULL)
467290931Srodrigc					if (strlcat(ir->ir_line, ",",
468290931Srodrigc						    sizeof(ir->ir_line))
469290931Srodrigc					    >= sizeof(ir->ir_line)) {
470290931Srodrigc						aldap_free_attr(ldap_attrs);
471290931Srodrigc						return (-1);
472290931Srodrigc					}
473290931Srodrigc			}
474290931Srodrigc			aldap_free_attr(ldap_attrs);
475290931Srodrigc		} else {
476290931Srodrigc			if (aldap_match_attr(m, idm->idm_attrs[i], &ldap_attrs) == -1)
477290931Srodrigc				return (-1);
478290931Srodrigc			if (strlcat(ir->ir_line, ldap_attrs[0],
479290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line)) {
480290931Srodrigc				aldap_free_attr(ldap_attrs);
481290931Srodrigc				return (-1);
482290931Srodrigc			}
483290931Srodrigc			if (i == ATTR_UID) {
484290931Srodrigc				ir->ir_key.ik_uid = strtonum(
485290931Srodrigc				    ldap_attrs[0], 0, UID_MAX, NULL);
486290931Srodrigc			} else if (i == ATTR_GR_GID) {
487290931Srodrigc				ir->ir_key.ik_uid = strtonum(
488290931Srodrigc				    ldap_attrs[0], 0, GID_MAX, NULL);
489290931Srodrigc			}
490290931Srodrigc			aldap_free_attr(ldap_attrs);
491290931Srodrigc		}
492290931Srodrigc
493290931Srodrigc		if (i + 1 != max_attr)
494290931Srodrigc			if (strlcat(ir->ir_line, ":",
495290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
496290931Srodrigc				return (-1);
497290931Srodrigc	}
498290931Srodrigc
499290931Srodrigc	return (0);
500290931Srodrigc}
501290931Srodrigc
502290931Srodrigcint
503290931Srodrigcclient_search_idm(struct env *env, struct idm *idm, struct aldap *al,
504290931Srodrigc    char **attrs, char *filter, int min_attr, int max_attr,
505290931Srodrigc    enum imsg_type type)
506290931Srodrigc{
507290931Srodrigc	struct idm_req		 ir;
508290931Srodrigc	struct aldap_message	*m;
509290931Srodrigc	struct aldap_page_control *pg = NULL;
510290931Srodrigc	const char		*errstr;
511290931Srodrigc	char			*dn;
512290931Srodrigc
513290931Srodrigc	dn = idm->idm_basedn;
514290931Srodrigc	if (type == IMSG_GRP_ENTRY && idm->idm_groupdn[0] != '\0')
515290931Srodrigc		dn = idm->idm_groupdn;
516290931Srodrigc
517290931Srodrigc	do {
518290931Srodrigc		if (aldap_search(al, dn, LDAP_SCOPE_SUBTREE,
519290931Srodrigc		    filter, attrs, 0, 0, 0, pg) == -1) {
520290931Srodrigc			aldap_get_errno(al, &errstr);
521290931Srodrigc			log_debug("%s", errstr);
522290931Srodrigc			return (-1);
523290931Srodrigc		}
524290931Srodrigc
525290931Srodrigc		if (pg != NULL) {
526290931Srodrigc			aldap_freepage(pg);
527290931Srodrigc			pg = NULL;
528290931Srodrigc		}
529290931Srodrigc
530290931Srodrigc		while ((m = aldap_parse(al)) != NULL) {
531290931Srodrigc			if (al->msgid != m->msgid) {
532290931Srodrigc				goto fail;
533290931Srodrigc			}
534290931Srodrigc
535290931Srodrigc			if (m->message_type == LDAP_RES_SEARCH_RESULT) {
536290931Srodrigc				if (m->page != NULL && m->page->cookie_len != 0)
537290931Srodrigc					pg = m->page;
538290931Srodrigc				else
539290931Srodrigc					pg = NULL;
540290931Srodrigc
541290931Srodrigc				aldap_freemsg(m);
542290931Srodrigc				break;
543290931Srodrigc			}
544290931Srodrigc
545290931Srodrigc			if (m->message_type != LDAP_RES_SEARCH_ENTRY) {
546290931Srodrigc				goto fail;
547290931Srodrigc			}
548290931Srodrigc
549290931Srodrigc			if (client_build_req(idm, &ir, m, min_attr, max_attr) == 0)
550290931Srodrigc				imsg_compose_event(env->sc_iev, type, 0, 0, -1,
551290931Srodrigc				    &ir, sizeof(ir));
552290931Srodrigc
553290931Srodrigc			aldap_freemsg(m);
554290931Srodrigc		}
555290931Srodrigc	} while (pg != NULL);
556290931Srodrigc
557290931Srodrigc	return (0);
558290931Srodrigc
559290931Srodrigcfail:
560290931Srodrigc	aldap_freemsg(m);
561290931Srodrigc	if (pg != NULL) {
562290931Srodrigc		aldap_freepage(pg);
563290931Srodrigc	}
564290931Srodrigc
565290931Srodrigc	return (-1);
566290931Srodrigc}
567290931Srodrigc
568290931Srodrigcint
569290931Srodrigcclient_try_idm(struct env *env, struct idm *idm)
570290931Srodrigc{
571290931Srodrigc	const char		*where;
572290931Srodrigc	char			*attrs[ATTR_MAX+1];
573290931Srodrigc	int			 i, j;
574290931Srodrigc	struct aldap_message	*m;
575290931Srodrigc	struct aldap		*al;
576290931Srodrigc
577290931Srodrigc	where = "connect";
578297907Saraujo	if ((al = client_aldap_open(&idm->idm_addr)) == NULL)
579290931Srodrigc		return (-1);
580290931Srodrigc
581290931Srodrigc	if (idm->idm_flags & F_NEEDAUTH) {
582290931Srodrigc		where = "binding";
583290931Srodrigc		if (aldap_bind(al, idm->idm_binddn, idm->idm_bindcred) == -1)
584290931Srodrigc			goto bad;
585290931Srodrigc
586290931Srodrigc		where = "parsing";
587290931Srodrigc		if ((m = aldap_parse(al)) == NULL)
588290931Srodrigc			goto bad;
589290931Srodrigc		where = "verifying msgid";
590290931Srodrigc		if (al->msgid != m->msgid) {
591290931Srodrigc			aldap_freemsg(m);
592290931Srodrigc			goto bad;
593290931Srodrigc		}
594290931Srodrigc		aldap_freemsg(m);
595290931Srodrigc	}
596290931Srodrigc
597309872Saraujo	memset(attrs, 0, sizeof(attrs));
598290931Srodrigc	for (i = 0, j = 0; i < ATTR_MAX; i++) {
599290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i))
600290931Srodrigc			continue;
601290931Srodrigc		attrs[j++] = idm->idm_attrs[i];
602290931Srodrigc	}
603290931Srodrigc	attrs[j] = NULL;
604290931Srodrigc
605290931Srodrigc	/*
606290931Srodrigc	 * build password line.
607290931Srodrigc	 */
608290931Srodrigc	where = "search";
609290931Srodrigc	log_debug("searching password entries");
610290931Srodrigc	if (client_search_idm(env, idm, al, attrs,
611290931Srodrigc	    idm->idm_filters[FILTER_USER], 0, ATTR_MAX, IMSG_PW_ENTRY) == -1)
612290931Srodrigc		goto bad;
613290931Srodrigc
614309872Saraujo	memset(attrs, 0, sizeof(attrs));
615290931Srodrigc	for (i = ATTR_GR_MIN, j = 0; i < ATTR_GR_MAX; i++) {
616290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i))
617290931Srodrigc			continue;
618290931Srodrigc		attrs[j++] = idm->idm_attrs[i];
619290931Srodrigc	}
620290931Srodrigc	attrs[j] = NULL;
621290931Srodrigc
622290931Srodrigc	/*
623290931Srodrigc	 * build group line.
624290931Srodrigc	 */
625290931Srodrigc	where = "search";
626290931Srodrigc	log_debug("searching group entries");
627290931Srodrigc	if (client_search_idm(env, idm, al, attrs,
628290931Srodrigc	    idm->idm_filters[FILTER_GROUP], ATTR_GR_MIN, ATTR_GR_MAX,
629290931Srodrigc	    IMSG_GRP_ENTRY) == -1)
630290931Srodrigc		goto bad;
631290931Srodrigc
632290931Srodrigc	aldap_close(al);
633290931Srodrigc
634290931Srodrigc	idm->idm_state = STATE_LDAP_DONE;
635290931Srodrigc
636290931Srodrigc	return (0);
637290931Srodrigcbad:
638290931Srodrigc	aldap_close(al);
639290931Srodrigc	log_debug("directory %s errored out in %s", idm->idm_name, where);
640290931Srodrigc	return (-1);
641290931Srodrigc}
642290931Srodrigc
643290931Srodrigcvoid
644290931Srodrigcclient_periodic_update(int fd, short event, void *p)
645290931Srodrigc{
646290931Srodrigc	struct env	*env = p;
647290931Srodrigc
648290931Srodrigc	struct idm	*idm;
649290931Srodrigc	int		 fail_cnt = 0;
650290931Srodrigc
651290931Srodrigc	/* If LDAP isn't finished, notify the master process to trash the
652290931Srodrigc	 * update. */
653290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
654290931Srodrigc		if (idm->idm_state < STATE_LDAP_DONE)
655290931Srodrigc			fail_cnt++;
656290931Srodrigc
657290931Srodrigc		idm->idm_state = STATE_NONE;
658290931Srodrigc
659290931Srodrigc		client_addr_free(idm);
660290931Srodrigc	}
661290931Srodrigc	if (fail_cnt > 0) {
662290931Srodrigc		log_debug("trash the update");
663290931Srodrigc		imsg_compose_event(env->sc_iev, IMSG_TRASH_UPDATE, 0, 0, -1,
664290931Srodrigc		    NULL, 0);
665290931Srodrigc	}
666290931Srodrigc
667290931Srodrigc	client_configure(env);
668290931Srodrigc}
669290931Srodrigc
670290931Srodrigcvoid
671290931Srodrigcclient_configure(struct env *env)
672290931Srodrigc{
673290931Srodrigc	struct timeval	 tv;
674290931Srodrigc	struct idm	*idm;
675290931Srodrigc        u_int16_t        dlen;
676290931Srodrigc
677290931Srodrigc	log_debug("connecting to directories");
678290931Srodrigc
679290931Srodrigc	imsg_compose_event(env->sc_iev, IMSG_START_UPDATE, 0, 0, -1, NULL, 0);
680290931Srodrigc
681290931Srodrigc	/* Start the DNS lookups */
682290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
683290931Srodrigc		dlen = strlen(idm->idm_name) + 1;
684290931Srodrigc		imsg_compose_event(env->sc_iev_dns, IMSG_HOST_DNS, idm->idm_id,
685290931Srodrigc		    0, -1, idm->idm_name, dlen);
686290931Srodrigc	}
687290931Srodrigc
688290931Srodrigc	tv.tv_sec = env->sc_conf_tv.tv_sec;
689290931Srodrigc	tv.tv_usec = env->sc_conf_tv.tv_usec;
690290931Srodrigc	evtimer_set(&env->sc_conf_ev, client_periodic_update, env);
691290931Srodrigc	evtimer_add(&env->sc_conf_ev, &tv);
692290931Srodrigc}
693