ldapclient.c revision 290940
1290931Srodrigc/* $OpenBSD: ldapclient.c,v 1.31 2014/11/16 23:24:44 tedu Exp $ */
2290931Srodrigc/* $FreeBSD: head/usr.sbin/ypldap/ldapclient.c 290940 2015-11-16 17:11:11Z rodrigc $ */
3290931Srodrigc
4290931Srodrigc/*
5290931Srodrigc * Copyright (c) 2008 Alexander Schrijver <aschrijver@openbsd.org>
6290931Srodrigc * Copyright (c) 2008 Pierre-Yves Ritschard <pyr@openbsd.org>
7290931Srodrigc *
8290931Srodrigc * Permission to use, copy, modify, and distribute this software for any
9290931Srodrigc * purpose with or without fee is hereby granted, provided that the above
10290931Srodrigc * copyright notice and this permission notice appear in all copies.
11290931Srodrigc *
12290931Srodrigc * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
13290931Srodrigc * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
14290931Srodrigc * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
15290931Srodrigc * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
16290931Srodrigc * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17290931Srodrigc * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18290931Srodrigc * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19290931Srodrigc */
20290931Srodrigc
21290931Srodrigc#include <sys/types.h>
22290931Srodrigc#include <sys/param.h>
23290931Srodrigc#include <sys/queue.h>
24290931Srodrigc#include <sys/socket.h>
25290931Srodrigc#include <sys/tree.h>
26290931Srodrigc
27290931Srodrigc#include <netinet/in.h>
28290931Srodrigc#include <arpa/inet.h>
29290931Srodrigc
30290931Srodrigc#include <netdb.h>
31290931Srodrigc#include <errno.h>
32290931Srodrigc#include <err.h>
33290931Srodrigc#include <event.h>
34290931Srodrigc#include <fcntl.h>
35290931Srodrigc#include <unistd.h>
36290931Srodrigc#include <pwd.h>
37290931Srodrigc#include <stdio.h>
38290931Srodrigc#include <stdlib.h>
39290931Srodrigc#include <string.h>
40290931Srodrigc
41290931Srodrigc#include "aldap.h"
42290931Srodrigc#include "ypldap.h"
43290931Srodrigc
44290931Srodrigcvoid    client_sig_handler(int, short, void *);
45290931Srodrigcvoid	client_dispatch_dns(int, short, void *);
46290931Srodrigcvoid    client_dispatch_parent(int, short, void *);
47290931Srodrigcvoid    client_shutdown(void);
48290931Srodrigcvoid    client_connect(int, short, void *);
49290931Srodrigcvoid    client_configure(struct env *);
50290931Srodrigcvoid    client_periodic_update(int, short, void *);
51290931Srodrigcint	client_build_req(struct idm *, struct idm_req *, struct aldap_message *,
52290931Srodrigc	    int, int);
53290931Srodrigcint	client_search_idm(struct env *, struct idm *, struct aldap *,
54290931Srodrigc	    char **, char *, int, int, enum imsg_type);
55290931Srodrigcint	client_try_idm(struct env *, struct idm *);
56290931Srodrigcint	client_addr_init(struct idm *);
57290931Srodrigcint	client_addr_free(struct idm *);
58290931Srodrigc
59290931Srodrigcstruct aldap	*client_aldap_open(struct ypldap_addr *);
60290931Srodrigc
61290931Srodrigc/*
62290931Srodrigc * dummy wrapper to provide aldap_init with its fd's.
63290931Srodrigc */
64290931Srodrigcstruct aldap *
65290931Srodrigcclient_aldap_open(struct ypldap_addr *addr)
66290931Srodrigc{
67290931Srodrigc	int			 fd = -1;
68290931Srodrigc	struct ypldap_addr	 *p;
69290931Srodrigc
70290931Srodrigc	for (p = addr; p != NULL; p = p->next) {
71290931Srodrigc		char			 hbuf[NI_MAXHOST], sbuf[NI_MAXSERV];
72290931Srodrigc		struct sockaddr		*sa = (struct sockaddr *)&p->ss;
73290931Srodrigc
74290940Srodrigc		if (getnameinfo(sa, sa->sa_len, hbuf, sizeof(hbuf), sbuf,
75290931Srodrigc			sizeof(sbuf), NI_NUMERICHOST | NI_NUMERICSERV))
76290931Srodrigc				errx(1, "could not get numeric hostname");
77290931Srodrigc
78290931Srodrigc		if ((fd = socket(sa->sa_family, SOCK_STREAM, 0)) < 0)
79290931Srodrigc			return NULL;
80290931Srodrigc
81290940Srodrigc		if (connect(fd, sa, sa->sa_len) == 0)
82290931Srodrigc			break;
83290931Srodrigc
84290931Srodrigc		warn("connect to %s port %s (%s) failed", hbuf, sbuf, "tcp");
85290931Srodrigc		close(fd);
86290931Srodrigc	}
87290931Srodrigc
88290931Srodrigc	if (fd == -1)
89290931Srodrigc		return NULL;
90290931Srodrigc
91290931Srodrigc	return aldap_init(fd);
92290931Srodrigc}
93290931Srodrigc
94290931Srodrigcint
95290931Srodrigcclient_addr_init(struct idm *idm)
96290931Srodrigc{
97290931Srodrigc        struct sockaddr_in      *sa_in;
98290931Srodrigc        struct sockaddr_in6     *sa_in6;
99290931Srodrigc        struct ypldap_addr         *h;
100290931Srodrigc
101290931Srodrigc        for (h = idm->idm_addr; h != NULL; h = h->next) {
102290931Srodrigc                switch (h->ss.ss_family) {
103290931Srodrigc                case AF_INET:
104290931Srodrigc                        sa_in = (struct sockaddr_in *)&h->ss;
105290931Srodrigc                        if (ntohs(sa_in->sin_port) == 0)
106290931Srodrigc                                sa_in->sin_port = htons(LDAP_PORT);
107290931Srodrigc                        idm->idm_state = STATE_DNS_DONE;
108290931Srodrigc                        break;
109290931Srodrigc                case AF_INET6:
110290931Srodrigc                        sa_in6 = (struct sockaddr_in6 *)&h->ss;
111290931Srodrigc                        if (ntohs(sa_in6->sin6_port) == 0)
112290931Srodrigc                                sa_in6->sin6_port = htons(LDAP_PORT);
113290931Srodrigc                        idm->idm_state = STATE_DNS_DONE;
114290931Srodrigc                        break;
115290931Srodrigc                default:
116290931Srodrigc                        fatalx("king bula sez: wrong AF in client_addr_init");
117290931Srodrigc                        /* not reached */
118290931Srodrigc                }
119290931Srodrigc        }
120290931Srodrigc
121290931Srodrigc        return (0);
122290931Srodrigc}
123290931Srodrigc
124290931Srodrigcint
125290931Srodrigcclient_addr_free(struct idm *idm)
126290931Srodrigc{
127290931Srodrigc        struct ypldap_addr         *h, *p;
128290931Srodrigc
129290931Srodrigc	if (idm->idm_addr == NULL)
130290931Srodrigc		return (-1);
131290931Srodrigc
132290931Srodrigc	for (h = idm->idm_addr; h != NULL; h = p) {
133290931Srodrigc		p = h->next;
134290931Srodrigc		free(h);
135290931Srodrigc	}
136290931Srodrigc
137290931Srodrigc	idm->idm_addr = NULL;
138290931Srodrigc
139290931Srodrigc	return (0);
140290931Srodrigc}
141290931Srodrigc
142290931Srodrigcvoid
143290931Srodrigcclient_sig_handler(int sig, short event, void *p)
144290931Srodrigc{
145290931Srodrigc	switch (sig) {
146290931Srodrigc	case SIGINT:
147290931Srodrigc	case SIGTERM:
148290931Srodrigc		client_shutdown();
149290931Srodrigc		break;
150290931Srodrigc	default:
151290931Srodrigc		fatalx("unexpected signal");
152290931Srodrigc	}
153290931Srodrigc}
154290931Srodrigc
155290931Srodrigcvoid
156290931Srodrigcclient_dispatch_dns(int fd, short events, void *p)
157290931Srodrigc{
158290931Srodrigc	struct imsg		 imsg;
159290931Srodrigc	u_int16_t		 dlen;
160290931Srodrigc	u_char			*data;
161290931Srodrigc	struct ypldap_addr	*h;
162290931Srodrigc	int			 n, wait_cnt = 0;
163290931Srodrigc	struct idm		*idm;
164290931Srodrigc	int			 shut = 0;
165290931Srodrigc
166290931Srodrigc	struct env		*env = p;
167290931Srodrigc	struct imsgev		*iev = env->sc_iev_dns;
168290931Srodrigc	struct imsgbuf		*ibuf = &iev->ibuf;
169290931Srodrigc
170290931Srodrigc	if ((events & (EV_READ | EV_WRITE)) == 0)
171290931Srodrigc		fatalx("unknown event");
172290931Srodrigc
173290931Srodrigc	if (events & EV_READ) {
174290931Srodrigc		if ((n = imsg_read(ibuf)) == -1)
175290931Srodrigc			fatal("imsg_read error");
176290931Srodrigc		if (n == 0)
177290931Srodrigc			shut = 1;
178290931Srodrigc	}
179290931Srodrigc	if (events & EV_WRITE) {
180290931Srodrigc		if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN)
181290931Srodrigc			fatal("msgbuf_write");
182290931Srodrigc		if (n == 0)
183290931Srodrigc			shut = 1;
184290931Srodrigc		goto done;
185290931Srodrigc	}
186290931Srodrigc
187290931Srodrigc	for (;;) {
188290931Srodrigc		if ((n = imsg_get(ibuf, &imsg)) == -1)
189290931Srodrigc			fatal("client_dispatch_dns: imsg_get error");
190290931Srodrigc		if (n == 0)
191290931Srodrigc			break;
192290931Srodrigc
193290931Srodrigc		switch (imsg.hdr.type) {
194290931Srodrigc		case IMSG_HOST_DNS:
195290931Srodrigc			TAILQ_FOREACH(idm, &env->sc_idms, idm_entry)
196290931Srodrigc				if (idm->idm_id == imsg.hdr.peerid)
197290931Srodrigc					break;
198290931Srodrigc			if (idm == NULL) {
199290931Srodrigc				log_warnx("IMSG_HOST_DNS with invalid peerID");
200290931Srodrigc				break;
201290931Srodrigc			}
202290931Srodrigc			if (idm->idm_addr != NULL) {
203290931Srodrigc				log_warnx("IMSG_HOST_DNS but addr != NULL!");
204290931Srodrigc				break;
205290931Srodrigc			}
206290931Srodrigc
207290931Srodrigc			dlen = imsg.hdr.len - IMSG_HEADER_SIZE;
208290931Srodrigc			if (dlen == 0) {	/* no data -> temp error */
209290931Srodrigc				idm->idm_state = STATE_DNS_TEMPFAIL;
210290931Srodrigc				break;
211290931Srodrigc			}
212290931Srodrigc
213290931Srodrigc			data = (u_char *)imsg.data;
214290931Srodrigc			while (dlen >= sizeof(struct sockaddr_storage)) {
215290931Srodrigc				if ((h = calloc(1, sizeof(struct ypldap_addr))) ==
216290931Srodrigc				    NULL)
217290931Srodrigc					fatal(NULL);
218290931Srodrigc				memcpy(&h->ss, data, sizeof(h->ss));
219290931Srodrigc
220290931Srodrigc				if (idm->idm_addr == NULL)
221290931Srodrigc					h->next = NULL;
222290931Srodrigc				else
223290931Srodrigc					h->next = idm->idm_addr;
224290931Srodrigc
225290931Srodrigc				idm->idm_addr = h;
226290931Srodrigc
227290931Srodrigc				data += sizeof(h->ss);
228290931Srodrigc				dlen -= sizeof(h->ss);
229290931Srodrigc			}
230290931Srodrigc			if (dlen != 0)
231290931Srodrigc				fatalx("IMSG_HOST_DNS: dlen != 0");
232290931Srodrigc
233290931Srodrigc			client_addr_init(idm);
234290931Srodrigc
235290931Srodrigc			break;
236290931Srodrigc		default:
237290931Srodrigc			break;
238290931Srodrigc		}
239290931Srodrigc		imsg_free(&imsg);
240290931Srodrigc	}
241290931Srodrigc
242290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
243290931Srodrigc		if (client_try_idm(env, idm) == -1)
244290931Srodrigc			idm->idm_state = STATE_LDAP_FAIL;
245290931Srodrigc
246290931Srodrigc		if (idm->idm_state < STATE_LDAP_DONE)
247290931Srodrigc			wait_cnt++;
248290931Srodrigc	}
249290931Srodrigc	if (wait_cnt == 0)
250290931Srodrigc		imsg_compose_event(env->sc_iev, IMSG_END_UPDATE, 0, 0, -1,
251290931Srodrigc		    NULL, 0);
252290931Srodrigc
253290931Srodrigcdone:
254290931Srodrigc	if (!shut)
255290931Srodrigc		imsg_event_add(iev);
256290931Srodrigc	else {
257290931Srodrigc		/* this pipe is dead, so remove the event handler */
258290931Srodrigc		event_del(&iev->ev);
259290931Srodrigc		event_loopexit(NULL);
260290931Srodrigc	}
261290931Srodrigc}
262290931Srodrigc
263290931Srodrigcvoid
264290931Srodrigcclient_dispatch_parent(int fd, short events, void *p)
265290931Srodrigc{
266290931Srodrigc	int			 n;
267290931Srodrigc	int			 shut = 0;
268290931Srodrigc	struct imsg		 imsg;
269290931Srodrigc	struct env		*env = p;
270290931Srodrigc	struct imsgev		*iev = env->sc_iev;
271290931Srodrigc	struct imsgbuf		*ibuf = &iev->ibuf;
272290931Srodrigc
273290931Srodrigc	if ((events & (EV_READ | EV_WRITE)) == 0)
274290931Srodrigc		fatalx("unknown event");
275290931Srodrigc
276290931Srodrigc	if (events & EV_READ) {
277290931Srodrigc		if ((n = imsg_read(ibuf)) == -1)
278290931Srodrigc			fatal("imsg_read error");
279290931Srodrigc		if (n == 0)
280290931Srodrigc			shut = 1;
281290931Srodrigc	}
282290931Srodrigc	if (events & EV_WRITE) {
283290931Srodrigc		if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN)
284290931Srodrigc			fatal("msgbuf_write");
285290931Srodrigc		if (n == 0)
286290931Srodrigc			shut = 1;
287290931Srodrigc		goto done;
288290931Srodrigc	}
289290931Srodrigc
290290931Srodrigc	for (;;) {
291290931Srodrigc		if ((n = imsg_get(ibuf, &imsg)) == -1)
292290931Srodrigc			fatal("client_dispatch_parent: imsg_get error");
293290931Srodrigc		if (n == 0)
294290931Srodrigc			break;
295290931Srodrigc
296290931Srodrigc		switch (imsg.hdr.type) {
297290931Srodrigc		case IMSG_CONF_START: {
298290931Srodrigc			struct env	params;
299290931Srodrigc
300290931Srodrigc			if (env->sc_flags & F_CONFIGURING) {
301290931Srodrigc				log_warnx("configuration already in progress");
302290931Srodrigc				break;
303290931Srodrigc			}
304290931Srodrigc			memcpy(&params, imsg.data, sizeof(params));
305290931Srodrigc			log_debug("configuration starting");
306290931Srodrigc			env->sc_flags |= F_CONFIGURING;
307290931Srodrigc			purge_config(env);
308290931Srodrigc			memcpy(&env->sc_conf_tv, &params.sc_conf_tv,
309290931Srodrigc			    sizeof(env->sc_conf_tv));
310290931Srodrigc			env->sc_flags |= params.sc_flags;
311290931Srodrigc			break;
312290931Srodrigc		}
313290931Srodrigc		case IMSG_CONF_IDM: {
314290931Srodrigc			struct idm	*idm;
315290931Srodrigc
316290931Srodrigc			if (!(env->sc_flags & F_CONFIGURING))
317290931Srodrigc				break;
318290931Srodrigc			if ((idm = calloc(1, sizeof(*idm))) == NULL)
319290931Srodrigc				fatal(NULL);
320290931Srodrigc			memcpy(idm, imsg.data, sizeof(*idm));
321290931Srodrigc			idm->idm_env = env;
322290931Srodrigc			TAILQ_INSERT_TAIL(&env->sc_idms, idm, idm_entry);
323290931Srodrigc			break;
324290931Srodrigc		}
325290931Srodrigc		case IMSG_CONF_END:
326290931Srodrigc			env->sc_flags &= ~F_CONFIGURING;
327290931Srodrigc			log_debug("applying configuration");
328290931Srodrigc			client_configure(env);
329290931Srodrigc			break;
330290931Srodrigc		default:
331290931Srodrigc			log_debug("client_dispatch_parent: unexpect imsg %d",
332290931Srodrigc			    imsg.hdr.type);
333290931Srodrigc
334290931Srodrigc			break;
335290931Srodrigc		}
336290931Srodrigc		imsg_free(&imsg);
337290931Srodrigc	}
338290931Srodrigc
339290931Srodrigcdone:
340290931Srodrigc	if (!shut)
341290931Srodrigc		imsg_event_add(iev);
342290931Srodrigc	else {
343290931Srodrigc		/* this pipe is dead, so remove the event handler */
344290931Srodrigc		event_del(&iev->ev);
345290931Srodrigc		event_loopexit(NULL);
346290931Srodrigc	}
347290931Srodrigc}
348290931Srodrigc
349290931Srodrigcvoid
350290931Srodrigcclient_shutdown(void)
351290931Srodrigc{
352290931Srodrigc	log_info("ldap client exiting");
353290931Srodrigc	_exit(0);
354290931Srodrigc}
355290931Srodrigc
356290931Srodrigcpid_t
357290931Srodrigcldapclient(int pipe_main2client[2])
358290931Srodrigc{
359290931Srodrigc	pid_t            pid, dns_pid;
360290931Srodrigc	int              pipe_dns[2];
361290931Srodrigc	struct passwd	*pw;
362290931Srodrigc	struct event	 ev_sigint;
363290931Srodrigc	struct event	 ev_sigterm;
364290931Srodrigc	struct env	 env;
365290931Srodrigc
366290931Srodrigc	switch (pid = fork()) {
367290931Srodrigc	case -1:
368290931Srodrigc		fatal("cannot fork");
369290931Srodrigc		break;
370290931Srodrigc	case 0:
371290931Srodrigc		break;
372290931Srodrigc	default:
373290931Srodrigc		return (pid);
374290931Srodrigc	}
375290931Srodrigc
376290931Srodrigc	bzero(&env, sizeof(env));
377290931Srodrigc	TAILQ_INIT(&env.sc_idms);
378290931Srodrigc
379290931Srodrigc	if ((pw = getpwnam(YPLDAP_USER)) == NULL)
380290931Srodrigc		fatal("getpwnam");
381290931Srodrigc
382290931Srodrigc	if (socketpair(AF_UNIX, SOCK_STREAM, PF_UNSPEC, pipe_dns) == -1)
383290931Srodrigc		fatal("socketpair");
384290931Srodrigc	dns_pid = ypldap_dns(pipe_dns, pw);
385290931Srodrigc	close(pipe_dns[1]);
386290931Srodrigc
387290931Srodrigc#ifndef DEBUG
388290931Srodrigc	if (chroot(pw->pw_dir) == -1)
389290931Srodrigc		fatal("chroot");
390290931Srodrigc	if (chdir("/") == -1)
391290931Srodrigc		fatal("chdir");
392290931Srodrigc#else
393290931Srodrigc#warning disabling chrooting in DEBUG mode
394290931Srodrigc#endif
395290931Srodrigc	setproctitle("ldap client");
396290931Srodrigc	ypldap_process = PROC_CLIENT;
397290931Srodrigc
398290931Srodrigc#ifndef DEBUG
399290931Srodrigc	if (setgroups(1, &pw->pw_gid) ||
400290931Srodrigc	    setresgid(pw->pw_gid, pw->pw_gid, pw->pw_gid) ||
401290931Srodrigc	    setresuid(pw->pw_uid, pw->pw_uid, pw->pw_uid))
402290931Srodrigc		fatal("cannot drop privileges");
403290931Srodrigc#else
404290931Srodrigc#warning disabling privilege revocation in DEBUG mode
405290931Srodrigc#endif
406290931Srodrigc
407290931Srodrigc	event_init();
408290931Srodrigc	signal(SIGPIPE, SIG_IGN);
409290931Srodrigc	signal_set(&ev_sigint, SIGINT, client_sig_handler, NULL);
410290931Srodrigc	signal_set(&ev_sigterm, SIGTERM, client_sig_handler, NULL);
411290931Srodrigc	signal_add(&ev_sigint, NULL);
412290931Srodrigc	signal_add(&ev_sigterm, NULL);
413290931Srodrigc
414290931Srodrigc	close(pipe_main2client[0]);
415290931Srodrigc	if ((env.sc_iev = calloc(1, sizeof(*env.sc_iev))) == NULL)
416290931Srodrigc		fatal(NULL);
417290931Srodrigc	if ((env.sc_iev_dns = calloc(1, sizeof(*env.sc_iev_dns))) == NULL)
418290931Srodrigc		fatal(NULL);
419290931Srodrigc
420290931Srodrigc	env.sc_iev->events = EV_READ;
421290931Srodrigc	env.sc_iev->data = &env;
422290931Srodrigc	imsg_init(&env.sc_iev->ibuf, pipe_main2client[1]);
423290931Srodrigc	env.sc_iev->handler = client_dispatch_parent;
424290931Srodrigc	event_set(&env.sc_iev->ev, env.sc_iev->ibuf.fd, env.sc_iev->events,
425290931Srodrigc	    env.sc_iev->handler, &env);
426290931Srodrigc	event_add(&env.sc_iev->ev, NULL);
427290931Srodrigc
428290931Srodrigc	env.sc_iev_dns->events = EV_READ;
429290931Srodrigc	env.sc_iev_dns->data = &env;
430290931Srodrigc	imsg_init(&env.sc_iev_dns->ibuf, pipe_dns[0]);
431290931Srodrigc	env.sc_iev_dns->handler = client_dispatch_dns;
432290931Srodrigc	event_set(&env.sc_iev_dns->ev, env.sc_iev_dns->ibuf.fd,
433290931Srodrigc	    env.sc_iev_dns->events, env.sc_iev_dns->handler, &env);
434290931Srodrigc	event_add(&env.sc_iev_dns->ev, NULL);
435290931Srodrigc
436290931Srodrigc	event_dispatch();
437290931Srodrigc	client_shutdown();
438290931Srodrigc
439290931Srodrigc	return (0);
440290931Srodrigc
441290931Srodrigc}
442290931Srodrigc
443290931Srodrigcint
444290931Srodrigcclient_build_req(struct idm *idm, struct idm_req *ir, struct aldap_message *m,
445290931Srodrigc    int min_attr, int max_attr)
446290931Srodrigc{
447290931Srodrigc	char	**ldap_attrs;
448290931Srodrigc	int	 i, k;
449290931Srodrigc
450290931Srodrigc	bzero(ir, sizeof(*ir));
451290931Srodrigc	for (i = min_attr; i < max_attr; i++) {
452290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i)) {
453290931Srodrigc			if (strlcat(ir->ir_line, idm->idm_attrs[i],
454290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
455290931Srodrigc				/*
456290931Srodrigc				 * entry yields a line > 1024, trash it.
457290931Srodrigc				 */
458290931Srodrigc				return (-1);
459290931Srodrigc
460290931Srodrigc			if (i == ATTR_UID) {
461290931Srodrigc				ir->ir_key.ik_uid = strtonum(
462290931Srodrigc				    idm->idm_attrs[i], 0,
463290931Srodrigc				    UID_MAX, NULL);
464290931Srodrigc			} else if (i == ATTR_GR_GID) {
465290931Srodrigc				ir->ir_key.ik_gid = strtonum(
466290931Srodrigc				    idm->idm_attrs[i], 0,
467290931Srodrigc				    GID_MAX, NULL);
468290931Srodrigc			}
469290931Srodrigc		} else if (idm->idm_list & F_LIST(i)) {
470290931Srodrigc			aldap_match_attr(m, idm->idm_attrs[i], &ldap_attrs);
471290931Srodrigc			for (k = 0; k >= 0 && ldap_attrs && ldap_attrs[k] != NULL; k++) {
472290931Srodrigc				/* XXX: Fail when attributes have illegal characters e.g. ',' */
473290931Srodrigc				if (strlcat(ir->ir_line, ldap_attrs[k],
474290931Srodrigc				    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
475290931Srodrigc					continue;
476290931Srodrigc				if (ldap_attrs[k+1] != NULL)
477290931Srodrigc					if (strlcat(ir->ir_line, ",",
478290931Srodrigc						    sizeof(ir->ir_line))
479290931Srodrigc					    >= sizeof(ir->ir_line)) {
480290931Srodrigc						aldap_free_attr(ldap_attrs);
481290931Srodrigc						return (-1);
482290931Srodrigc					}
483290931Srodrigc			}
484290931Srodrigc			aldap_free_attr(ldap_attrs);
485290931Srodrigc		} else {
486290931Srodrigc			if (aldap_match_attr(m, idm->idm_attrs[i], &ldap_attrs) == -1)
487290931Srodrigc				return (-1);
488290931Srodrigc			if (ldap_attrs[0] == NULL)
489290931Srodrigc				return (-1);
490290931Srodrigc			if (strlcat(ir->ir_line, ldap_attrs[0],
491290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line)) {
492290931Srodrigc				aldap_free_attr(ldap_attrs);
493290931Srodrigc				return (-1);
494290931Srodrigc			}
495290931Srodrigc			if (i == ATTR_UID) {
496290931Srodrigc				ir->ir_key.ik_uid = strtonum(
497290931Srodrigc				    ldap_attrs[0], 0, UID_MAX, NULL);
498290931Srodrigc			} else if (i == ATTR_GR_GID) {
499290931Srodrigc				ir->ir_key.ik_uid = strtonum(
500290931Srodrigc				    ldap_attrs[0], 0, GID_MAX, NULL);
501290931Srodrigc			}
502290931Srodrigc			aldap_free_attr(ldap_attrs);
503290931Srodrigc		}
504290931Srodrigc
505290931Srodrigc		if (i + 1 != max_attr)
506290931Srodrigc			if (strlcat(ir->ir_line, ":",
507290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
508290931Srodrigc				return (-1);
509290931Srodrigc	}
510290931Srodrigc
511290931Srodrigc	return (0);
512290931Srodrigc}
513290931Srodrigc
514290931Srodrigcint
515290931Srodrigcclient_search_idm(struct env *env, struct idm *idm, struct aldap *al,
516290931Srodrigc    char **attrs, char *filter, int min_attr, int max_attr,
517290931Srodrigc    enum imsg_type type)
518290931Srodrigc{
519290931Srodrigc	struct idm_req		 ir;
520290931Srodrigc	struct aldap_message	*m;
521290931Srodrigc	struct aldap_page_control *pg = NULL;
522290931Srodrigc	const char		*errstr;
523290931Srodrigc	char			*dn;
524290931Srodrigc
525290931Srodrigc	dn = idm->idm_basedn;
526290931Srodrigc	if (type == IMSG_GRP_ENTRY && idm->idm_groupdn[0] != '\0')
527290931Srodrigc		dn = idm->idm_groupdn;
528290931Srodrigc
529290931Srodrigc	do {
530290931Srodrigc		if (aldap_search(al, dn, LDAP_SCOPE_SUBTREE,
531290931Srodrigc		    filter, attrs, 0, 0, 0, pg) == -1) {
532290931Srodrigc			aldap_get_errno(al, &errstr);
533290931Srodrigc			log_debug("%s", errstr);
534290931Srodrigc			return (-1);
535290931Srodrigc		}
536290931Srodrigc
537290931Srodrigc		if (pg != NULL) {
538290931Srodrigc			aldap_freepage(pg);
539290931Srodrigc			pg = NULL;
540290931Srodrigc		}
541290931Srodrigc
542290931Srodrigc		while ((m = aldap_parse(al)) != NULL) {
543290931Srodrigc			if (al->msgid != m->msgid) {
544290931Srodrigc				goto fail;
545290931Srodrigc			}
546290931Srodrigc
547290931Srodrigc			if (m->message_type == LDAP_RES_SEARCH_RESULT) {
548290931Srodrigc				if (m->page != NULL && m->page->cookie_len != 0)
549290931Srodrigc					pg = m->page;
550290931Srodrigc				else
551290931Srodrigc					pg = NULL;
552290931Srodrigc
553290931Srodrigc				aldap_freemsg(m);
554290931Srodrigc				break;
555290931Srodrigc			}
556290931Srodrigc
557290931Srodrigc			if (m->message_type != LDAP_RES_SEARCH_ENTRY) {
558290931Srodrigc				goto fail;
559290931Srodrigc			}
560290931Srodrigc
561290931Srodrigc			if (client_build_req(idm, &ir, m, min_attr, max_attr) == 0)
562290931Srodrigc				imsg_compose_event(env->sc_iev, type, 0, 0, -1,
563290931Srodrigc				    &ir, sizeof(ir));
564290931Srodrigc
565290931Srodrigc			aldap_freemsg(m);
566290931Srodrigc		}
567290931Srodrigc	} while (pg != NULL);
568290931Srodrigc
569290931Srodrigc	return (0);
570290931Srodrigc
571290931Srodrigcfail:
572290931Srodrigc	aldap_freemsg(m);
573290931Srodrigc	if (pg != NULL) {
574290931Srodrigc		aldap_freepage(pg);
575290931Srodrigc	}
576290931Srodrigc
577290931Srodrigc	return (-1);
578290931Srodrigc}
579290931Srodrigc
580290931Srodrigcint
581290931Srodrigcclient_try_idm(struct env *env, struct idm *idm)
582290931Srodrigc{
583290931Srodrigc	const char		*where;
584290931Srodrigc	char			*attrs[ATTR_MAX+1];
585290931Srodrigc	int			 i, j;
586290931Srodrigc	struct aldap_message	*m;
587290931Srodrigc	struct aldap		*al;
588290931Srodrigc
589290931Srodrigc	where = "connect";
590290931Srodrigc	if ((al = client_aldap_open(idm->idm_addr)) == NULL)
591290931Srodrigc		return (-1);
592290931Srodrigc
593290931Srodrigc	if (idm->idm_flags & F_NEEDAUTH) {
594290931Srodrigc		where = "binding";
595290931Srodrigc		if (aldap_bind(al, idm->idm_binddn, idm->idm_bindcred) == -1)
596290931Srodrigc			goto bad;
597290931Srodrigc
598290931Srodrigc		where = "parsing";
599290931Srodrigc		if ((m = aldap_parse(al)) == NULL)
600290931Srodrigc			goto bad;
601290931Srodrigc		where = "verifying msgid";
602290931Srodrigc		if (al->msgid != m->msgid) {
603290931Srodrigc			aldap_freemsg(m);
604290931Srodrigc			goto bad;
605290931Srodrigc		}
606290931Srodrigc		aldap_freemsg(m);
607290931Srodrigc	}
608290931Srodrigc
609290931Srodrigc	bzero(attrs, sizeof(attrs));
610290931Srodrigc	for (i = 0, j = 0; i < ATTR_MAX; i++) {
611290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i))
612290931Srodrigc			continue;
613290931Srodrigc		attrs[j++] = idm->idm_attrs[i];
614290931Srodrigc	}
615290931Srodrigc	attrs[j] = NULL;
616290931Srodrigc
617290931Srodrigc	/*
618290931Srodrigc	 * build password line.
619290931Srodrigc	 */
620290931Srodrigc	where = "search";
621290931Srodrigc	log_debug("searching password entries");
622290931Srodrigc	if (client_search_idm(env, idm, al, attrs,
623290931Srodrigc	    idm->idm_filters[FILTER_USER], 0, ATTR_MAX, IMSG_PW_ENTRY) == -1)
624290931Srodrigc		goto bad;
625290931Srodrigc
626290931Srodrigc	bzero(attrs, sizeof(attrs));
627290931Srodrigc	for (i = ATTR_GR_MIN, j = 0; i < ATTR_GR_MAX; i++) {
628290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i))
629290931Srodrigc			continue;
630290931Srodrigc		attrs[j++] = idm->idm_attrs[i];
631290931Srodrigc	}
632290931Srodrigc	attrs[j] = NULL;
633290931Srodrigc
634290931Srodrigc	/*
635290931Srodrigc	 * build group line.
636290931Srodrigc	 */
637290931Srodrigc	where = "search";
638290931Srodrigc	log_debug("searching group entries");
639290931Srodrigc	if (client_search_idm(env, idm, al, attrs,
640290931Srodrigc	    idm->idm_filters[FILTER_GROUP], ATTR_GR_MIN, ATTR_GR_MAX,
641290931Srodrigc	    IMSG_GRP_ENTRY) == -1)
642290931Srodrigc		goto bad;
643290931Srodrigc
644290931Srodrigc	aldap_close(al);
645290931Srodrigc
646290931Srodrigc	idm->idm_state = STATE_LDAP_DONE;
647290931Srodrigc
648290931Srodrigc	return (0);
649290931Srodrigcbad:
650290931Srodrigc	aldap_close(al);
651290931Srodrigc	log_debug("directory %s errored out in %s", idm->idm_name, where);
652290931Srodrigc	return (-1);
653290931Srodrigc}
654290931Srodrigc
655290931Srodrigcvoid
656290931Srodrigcclient_periodic_update(int fd, short event, void *p)
657290931Srodrigc{
658290931Srodrigc	struct env	*env = p;
659290931Srodrigc
660290931Srodrigc	struct idm	*idm;
661290931Srodrigc	int		 fail_cnt = 0;
662290931Srodrigc
663290931Srodrigc	/* If LDAP isn't finished, notify the master process to trash the
664290931Srodrigc	 * update. */
665290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
666290931Srodrigc		if (idm->idm_state < STATE_LDAP_DONE)
667290931Srodrigc			fail_cnt++;
668290931Srodrigc
669290931Srodrigc		idm->idm_state = STATE_NONE;
670290931Srodrigc
671290931Srodrigc		client_addr_free(idm);
672290931Srodrigc	}
673290931Srodrigc	if (fail_cnt > 0) {
674290931Srodrigc		log_debug("trash the update");
675290931Srodrigc		imsg_compose_event(env->sc_iev, IMSG_TRASH_UPDATE, 0, 0, -1,
676290931Srodrigc		    NULL, 0);
677290931Srodrigc	}
678290931Srodrigc
679290931Srodrigc	client_configure(env);
680290931Srodrigc}
681290931Srodrigc
682290931Srodrigcvoid
683290931Srodrigcclient_configure(struct env *env)
684290931Srodrigc{
685290931Srodrigc	struct timeval	 tv;
686290931Srodrigc	struct idm	*idm;
687290931Srodrigc        u_int16_t        dlen;
688290931Srodrigc
689290931Srodrigc	log_debug("connecting to directories");
690290931Srodrigc
691290931Srodrigc	imsg_compose_event(env->sc_iev, IMSG_START_UPDATE, 0, 0, -1, NULL, 0);
692290931Srodrigc
693290931Srodrigc	/* Start the DNS lookups */
694290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
695290931Srodrigc		dlen = strlen(idm->idm_name) + 1;
696290931Srodrigc		imsg_compose_event(env->sc_iev_dns, IMSG_HOST_DNS, idm->idm_id,
697290931Srodrigc		    0, -1, idm->idm_name, dlen);
698290931Srodrigc	}
699290931Srodrigc
700290931Srodrigc	tv.tv_sec = env->sc_conf_tv.tv_sec;
701290931Srodrigc	tv.tv_usec = env->sc_conf_tv.tv_usec;
702290931Srodrigc	evtimer_set(&env->sc_conf_ev, client_periodic_update, env);
703290931Srodrigc	evtimer_add(&env->sc_conf_ev, &tv);
704290931Srodrigc}
705