ldapclient.c revision 290942
1290931Srodrigc/* $OpenBSD: ldapclient.c,v 1.31 2014/11/16 23:24:44 tedu Exp $ */
2290931Srodrigc/* $FreeBSD: head/usr.sbin/ypldap/ldapclient.c 290942 2015-11-16 17:28:04Z rodrigc $ */
3290931Srodrigc
4290931Srodrigc/*
5290931Srodrigc * Copyright (c) 2008 Alexander Schrijver <aschrijver@openbsd.org>
6290931Srodrigc * Copyright (c) 2008 Pierre-Yves Ritschard <pyr@openbsd.org>
7290931Srodrigc *
8290931Srodrigc * Permission to use, copy, modify, and distribute this software for any
9290931Srodrigc * purpose with or without fee is hereby granted, provided that the above
10290931Srodrigc * copyright notice and this permission notice appear in all copies.
11290931Srodrigc *
12290931Srodrigc * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
13290931Srodrigc * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
14290931Srodrigc * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
15290931Srodrigc * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
16290931Srodrigc * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17290931Srodrigc * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18290931Srodrigc * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19290931Srodrigc */
20290931Srodrigc
21290931Srodrigc#include <sys/types.h>
22290931Srodrigc#include <sys/param.h>
23290931Srodrigc#include <sys/queue.h>
24290931Srodrigc#include <sys/socket.h>
25290931Srodrigc#include <sys/tree.h>
26290931Srodrigc
27290931Srodrigc#include <netinet/in.h>
28290931Srodrigc#include <arpa/inet.h>
29290931Srodrigc
30290931Srodrigc#include <netdb.h>
31290931Srodrigc#include <errno.h>
32290931Srodrigc#include <err.h>
33290931Srodrigc#include <event.h>
34290931Srodrigc#include <fcntl.h>
35290931Srodrigc#include <unistd.h>
36290931Srodrigc#include <pwd.h>
37290942Srodrigc#include <signal.h>
38290931Srodrigc#include <stdio.h>
39290931Srodrigc#include <stdlib.h>
40290931Srodrigc#include <string.h>
41290931Srodrigc
42290931Srodrigc#include "aldap.h"
43290931Srodrigc#include "ypldap.h"
44290931Srodrigc
45290931Srodrigcvoid    client_sig_handler(int, short, void *);
46290931Srodrigcvoid	client_dispatch_dns(int, short, void *);
47290931Srodrigcvoid    client_dispatch_parent(int, short, void *);
48290931Srodrigcvoid    client_shutdown(void);
49290931Srodrigcvoid    client_connect(int, short, void *);
50290931Srodrigcvoid    client_configure(struct env *);
51290931Srodrigcvoid    client_periodic_update(int, short, void *);
52290931Srodrigcint	client_build_req(struct idm *, struct idm_req *, struct aldap_message *,
53290931Srodrigc	    int, int);
54290931Srodrigcint	client_search_idm(struct env *, struct idm *, struct aldap *,
55290931Srodrigc	    char **, char *, int, int, enum imsg_type);
56290931Srodrigcint	client_try_idm(struct env *, struct idm *);
57290931Srodrigcint	client_addr_init(struct idm *);
58290931Srodrigcint	client_addr_free(struct idm *);
59290931Srodrigc
60290931Srodrigcstruct aldap	*client_aldap_open(struct ypldap_addr *);
61290931Srodrigc
62290931Srodrigc/*
63290931Srodrigc * dummy wrapper to provide aldap_init with its fd's.
64290931Srodrigc */
65290931Srodrigcstruct aldap *
66290931Srodrigcclient_aldap_open(struct ypldap_addr *addr)
67290931Srodrigc{
68290931Srodrigc	int			 fd = -1;
69290931Srodrigc	struct ypldap_addr	 *p;
70290931Srodrigc
71290931Srodrigc	for (p = addr; p != NULL; p = p->next) {
72290931Srodrigc		char			 hbuf[NI_MAXHOST], sbuf[NI_MAXSERV];
73290931Srodrigc		struct sockaddr		*sa = (struct sockaddr *)&p->ss;
74290931Srodrigc
75290940Srodrigc		if (getnameinfo(sa, sa->sa_len, hbuf, sizeof(hbuf), sbuf,
76290931Srodrigc			sizeof(sbuf), NI_NUMERICHOST | NI_NUMERICSERV))
77290931Srodrigc				errx(1, "could not get numeric hostname");
78290931Srodrigc
79290931Srodrigc		if ((fd = socket(sa->sa_family, SOCK_STREAM, 0)) < 0)
80290931Srodrigc			return NULL;
81290931Srodrigc
82290940Srodrigc		if (connect(fd, sa, sa->sa_len) == 0)
83290931Srodrigc			break;
84290931Srodrigc
85290931Srodrigc		warn("connect to %s port %s (%s) failed", hbuf, sbuf, "tcp");
86290931Srodrigc		close(fd);
87290931Srodrigc	}
88290931Srodrigc
89290931Srodrigc	if (fd == -1)
90290931Srodrigc		return NULL;
91290931Srodrigc
92290931Srodrigc	return aldap_init(fd);
93290931Srodrigc}
94290931Srodrigc
95290931Srodrigcint
96290931Srodrigcclient_addr_init(struct idm *idm)
97290931Srodrigc{
98290931Srodrigc        struct sockaddr_in      *sa_in;
99290931Srodrigc        struct sockaddr_in6     *sa_in6;
100290931Srodrigc        struct ypldap_addr         *h;
101290931Srodrigc
102290931Srodrigc        for (h = idm->idm_addr; h != NULL; h = h->next) {
103290931Srodrigc                switch (h->ss.ss_family) {
104290931Srodrigc                case AF_INET:
105290931Srodrigc                        sa_in = (struct sockaddr_in *)&h->ss;
106290931Srodrigc                        if (ntohs(sa_in->sin_port) == 0)
107290931Srodrigc                                sa_in->sin_port = htons(LDAP_PORT);
108290931Srodrigc                        idm->idm_state = STATE_DNS_DONE;
109290931Srodrigc                        break;
110290931Srodrigc                case AF_INET6:
111290931Srodrigc                        sa_in6 = (struct sockaddr_in6 *)&h->ss;
112290931Srodrigc                        if (ntohs(sa_in6->sin6_port) == 0)
113290931Srodrigc                                sa_in6->sin6_port = htons(LDAP_PORT);
114290931Srodrigc                        idm->idm_state = STATE_DNS_DONE;
115290931Srodrigc                        break;
116290931Srodrigc                default:
117290931Srodrigc                        fatalx("king bula sez: wrong AF in client_addr_init");
118290931Srodrigc                        /* not reached */
119290931Srodrigc                }
120290931Srodrigc        }
121290931Srodrigc
122290931Srodrigc        return (0);
123290931Srodrigc}
124290931Srodrigc
125290931Srodrigcint
126290931Srodrigcclient_addr_free(struct idm *idm)
127290931Srodrigc{
128290931Srodrigc        struct ypldap_addr         *h, *p;
129290931Srodrigc
130290931Srodrigc	if (idm->idm_addr == NULL)
131290931Srodrigc		return (-1);
132290931Srodrigc
133290931Srodrigc	for (h = idm->idm_addr; h != NULL; h = p) {
134290931Srodrigc		p = h->next;
135290931Srodrigc		free(h);
136290931Srodrigc	}
137290931Srodrigc
138290931Srodrigc	idm->idm_addr = NULL;
139290931Srodrigc
140290931Srodrigc	return (0);
141290931Srodrigc}
142290931Srodrigc
143290931Srodrigcvoid
144290931Srodrigcclient_sig_handler(int sig, short event, void *p)
145290931Srodrigc{
146290931Srodrigc	switch (sig) {
147290931Srodrigc	case SIGINT:
148290931Srodrigc	case SIGTERM:
149290931Srodrigc		client_shutdown();
150290931Srodrigc		break;
151290931Srodrigc	default:
152290931Srodrigc		fatalx("unexpected signal");
153290931Srodrigc	}
154290931Srodrigc}
155290931Srodrigc
156290931Srodrigcvoid
157290931Srodrigcclient_dispatch_dns(int fd, short events, void *p)
158290931Srodrigc{
159290931Srodrigc	struct imsg		 imsg;
160290931Srodrigc	u_int16_t		 dlen;
161290931Srodrigc	u_char			*data;
162290931Srodrigc	struct ypldap_addr	*h;
163290931Srodrigc	int			 n, wait_cnt = 0;
164290931Srodrigc	struct idm		*idm;
165290931Srodrigc	int			 shut = 0;
166290931Srodrigc
167290931Srodrigc	struct env		*env = p;
168290931Srodrigc	struct imsgev		*iev = env->sc_iev_dns;
169290931Srodrigc	struct imsgbuf		*ibuf = &iev->ibuf;
170290931Srodrigc
171290931Srodrigc	if ((events & (EV_READ | EV_WRITE)) == 0)
172290931Srodrigc		fatalx("unknown event");
173290931Srodrigc
174290931Srodrigc	if (events & EV_READ) {
175290931Srodrigc		if ((n = imsg_read(ibuf)) == -1)
176290931Srodrigc			fatal("imsg_read error");
177290931Srodrigc		if (n == 0)
178290931Srodrigc			shut = 1;
179290931Srodrigc	}
180290931Srodrigc	if (events & EV_WRITE) {
181290931Srodrigc		if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN)
182290931Srodrigc			fatal("msgbuf_write");
183290931Srodrigc		if (n == 0)
184290931Srodrigc			shut = 1;
185290931Srodrigc		goto done;
186290931Srodrigc	}
187290931Srodrigc
188290931Srodrigc	for (;;) {
189290931Srodrigc		if ((n = imsg_get(ibuf, &imsg)) == -1)
190290931Srodrigc			fatal("client_dispatch_dns: imsg_get error");
191290931Srodrigc		if (n == 0)
192290931Srodrigc			break;
193290931Srodrigc
194290931Srodrigc		switch (imsg.hdr.type) {
195290931Srodrigc		case IMSG_HOST_DNS:
196290931Srodrigc			TAILQ_FOREACH(idm, &env->sc_idms, idm_entry)
197290931Srodrigc				if (idm->idm_id == imsg.hdr.peerid)
198290931Srodrigc					break;
199290931Srodrigc			if (idm == NULL) {
200290931Srodrigc				log_warnx("IMSG_HOST_DNS with invalid peerID");
201290931Srodrigc				break;
202290931Srodrigc			}
203290931Srodrigc			if (idm->idm_addr != NULL) {
204290931Srodrigc				log_warnx("IMSG_HOST_DNS but addr != NULL!");
205290931Srodrigc				break;
206290931Srodrigc			}
207290931Srodrigc
208290931Srodrigc			dlen = imsg.hdr.len - IMSG_HEADER_SIZE;
209290931Srodrigc			if (dlen == 0) {	/* no data -> temp error */
210290931Srodrigc				idm->idm_state = STATE_DNS_TEMPFAIL;
211290931Srodrigc				break;
212290931Srodrigc			}
213290931Srodrigc
214290931Srodrigc			data = (u_char *)imsg.data;
215290931Srodrigc			while (dlen >= sizeof(struct sockaddr_storage)) {
216290931Srodrigc				if ((h = calloc(1, sizeof(struct ypldap_addr))) ==
217290931Srodrigc				    NULL)
218290931Srodrigc					fatal(NULL);
219290931Srodrigc				memcpy(&h->ss, data, sizeof(h->ss));
220290931Srodrigc
221290931Srodrigc				if (idm->idm_addr == NULL)
222290931Srodrigc					h->next = NULL;
223290931Srodrigc				else
224290931Srodrigc					h->next = idm->idm_addr;
225290931Srodrigc
226290931Srodrigc				idm->idm_addr = h;
227290931Srodrigc
228290931Srodrigc				data += sizeof(h->ss);
229290931Srodrigc				dlen -= sizeof(h->ss);
230290931Srodrigc			}
231290931Srodrigc			if (dlen != 0)
232290931Srodrigc				fatalx("IMSG_HOST_DNS: dlen != 0");
233290931Srodrigc
234290931Srodrigc			client_addr_init(idm);
235290931Srodrigc
236290931Srodrigc			break;
237290931Srodrigc		default:
238290931Srodrigc			break;
239290931Srodrigc		}
240290931Srodrigc		imsg_free(&imsg);
241290931Srodrigc	}
242290931Srodrigc
243290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
244290931Srodrigc		if (client_try_idm(env, idm) == -1)
245290931Srodrigc			idm->idm_state = STATE_LDAP_FAIL;
246290931Srodrigc
247290931Srodrigc		if (idm->idm_state < STATE_LDAP_DONE)
248290931Srodrigc			wait_cnt++;
249290931Srodrigc	}
250290931Srodrigc	if (wait_cnt == 0)
251290931Srodrigc		imsg_compose_event(env->sc_iev, IMSG_END_UPDATE, 0, 0, -1,
252290931Srodrigc		    NULL, 0);
253290931Srodrigc
254290931Srodrigcdone:
255290931Srodrigc	if (!shut)
256290931Srodrigc		imsg_event_add(iev);
257290931Srodrigc	else {
258290931Srodrigc		/* this pipe is dead, so remove the event handler */
259290931Srodrigc		event_del(&iev->ev);
260290931Srodrigc		event_loopexit(NULL);
261290931Srodrigc	}
262290931Srodrigc}
263290931Srodrigc
264290931Srodrigcvoid
265290931Srodrigcclient_dispatch_parent(int fd, short events, void *p)
266290931Srodrigc{
267290931Srodrigc	int			 n;
268290931Srodrigc	int			 shut = 0;
269290931Srodrigc	struct imsg		 imsg;
270290931Srodrigc	struct env		*env = p;
271290931Srodrigc	struct imsgev		*iev = env->sc_iev;
272290931Srodrigc	struct imsgbuf		*ibuf = &iev->ibuf;
273290931Srodrigc
274290931Srodrigc	if ((events & (EV_READ | EV_WRITE)) == 0)
275290931Srodrigc		fatalx("unknown event");
276290931Srodrigc
277290931Srodrigc	if (events & EV_READ) {
278290931Srodrigc		if ((n = imsg_read(ibuf)) == -1)
279290931Srodrigc			fatal("imsg_read error");
280290931Srodrigc		if (n == 0)
281290931Srodrigc			shut = 1;
282290931Srodrigc	}
283290931Srodrigc	if (events & EV_WRITE) {
284290931Srodrigc		if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN)
285290931Srodrigc			fatal("msgbuf_write");
286290931Srodrigc		if (n == 0)
287290931Srodrigc			shut = 1;
288290931Srodrigc		goto done;
289290931Srodrigc	}
290290931Srodrigc
291290931Srodrigc	for (;;) {
292290931Srodrigc		if ((n = imsg_get(ibuf, &imsg)) == -1)
293290931Srodrigc			fatal("client_dispatch_parent: imsg_get error");
294290931Srodrigc		if (n == 0)
295290931Srodrigc			break;
296290931Srodrigc
297290931Srodrigc		switch (imsg.hdr.type) {
298290931Srodrigc		case IMSG_CONF_START: {
299290931Srodrigc			struct env	params;
300290931Srodrigc
301290931Srodrigc			if (env->sc_flags & F_CONFIGURING) {
302290931Srodrigc				log_warnx("configuration already in progress");
303290931Srodrigc				break;
304290931Srodrigc			}
305290931Srodrigc			memcpy(&params, imsg.data, sizeof(params));
306290931Srodrigc			log_debug("configuration starting");
307290931Srodrigc			env->sc_flags |= F_CONFIGURING;
308290931Srodrigc			purge_config(env);
309290931Srodrigc			memcpy(&env->sc_conf_tv, &params.sc_conf_tv,
310290931Srodrigc			    sizeof(env->sc_conf_tv));
311290931Srodrigc			env->sc_flags |= params.sc_flags;
312290931Srodrigc			break;
313290931Srodrigc		}
314290931Srodrigc		case IMSG_CONF_IDM: {
315290931Srodrigc			struct idm	*idm;
316290931Srodrigc
317290931Srodrigc			if (!(env->sc_flags & F_CONFIGURING))
318290931Srodrigc				break;
319290931Srodrigc			if ((idm = calloc(1, sizeof(*idm))) == NULL)
320290931Srodrigc				fatal(NULL);
321290931Srodrigc			memcpy(idm, imsg.data, sizeof(*idm));
322290931Srodrigc			idm->idm_env = env;
323290931Srodrigc			TAILQ_INSERT_TAIL(&env->sc_idms, idm, idm_entry);
324290931Srodrigc			break;
325290931Srodrigc		}
326290931Srodrigc		case IMSG_CONF_END:
327290931Srodrigc			env->sc_flags &= ~F_CONFIGURING;
328290931Srodrigc			log_debug("applying configuration");
329290931Srodrigc			client_configure(env);
330290931Srodrigc			break;
331290931Srodrigc		default:
332290931Srodrigc			log_debug("client_dispatch_parent: unexpect imsg %d",
333290931Srodrigc			    imsg.hdr.type);
334290931Srodrigc
335290931Srodrigc			break;
336290931Srodrigc		}
337290931Srodrigc		imsg_free(&imsg);
338290931Srodrigc	}
339290931Srodrigc
340290931Srodrigcdone:
341290931Srodrigc	if (!shut)
342290931Srodrigc		imsg_event_add(iev);
343290931Srodrigc	else {
344290931Srodrigc		/* this pipe is dead, so remove the event handler */
345290931Srodrigc		event_del(&iev->ev);
346290931Srodrigc		event_loopexit(NULL);
347290931Srodrigc	}
348290931Srodrigc}
349290931Srodrigc
350290931Srodrigcvoid
351290931Srodrigcclient_shutdown(void)
352290931Srodrigc{
353290931Srodrigc	log_info("ldap client exiting");
354290931Srodrigc	_exit(0);
355290931Srodrigc}
356290931Srodrigc
357290931Srodrigcpid_t
358290931Srodrigcldapclient(int pipe_main2client[2])
359290931Srodrigc{
360290931Srodrigc	pid_t            pid, dns_pid;
361290931Srodrigc	int              pipe_dns[2];
362290931Srodrigc	struct passwd	*pw;
363290931Srodrigc	struct event	 ev_sigint;
364290931Srodrigc	struct event	 ev_sigterm;
365290931Srodrigc	struct env	 env;
366290931Srodrigc
367290931Srodrigc	switch (pid = fork()) {
368290931Srodrigc	case -1:
369290931Srodrigc		fatal("cannot fork");
370290931Srodrigc		break;
371290931Srodrigc	case 0:
372290931Srodrigc		break;
373290931Srodrigc	default:
374290931Srodrigc		return (pid);
375290931Srodrigc	}
376290931Srodrigc
377290931Srodrigc	bzero(&env, sizeof(env));
378290931Srodrigc	TAILQ_INIT(&env.sc_idms);
379290931Srodrigc
380290931Srodrigc	if ((pw = getpwnam(YPLDAP_USER)) == NULL)
381290931Srodrigc		fatal("getpwnam");
382290931Srodrigc
383290931Srodrigc	if (socketpair(AF_UNIX, SOCK_STREAM, PF_UNSPEC, pipe_dns) == -1)
384290931Srodrigc		fatal("socketpair");
385290931Srodrigc	dns_pid = ypldap_dns(pipe_dns, pw);
386290931Srodrigc	close(pipe_dns[1]);
387290931Srodrigc
388290931Srodrigc#ifndef DEBUG
389290931Srodrigc	if (chroot(pw->pw_dir) == -1)
390290931Srodrigc		fatal("chroot");
391290931Srodrigc	if (chdir("/") == -1)
392290931Srodrigc		fatal("chdir");
393290931Srodrigc#else
394290931Srodrigc#warning disabling chrooting in DEBUG mode
395290931Srodrigc#endif
396290931Srodrigc	setproctitle("ldap client");
397290931Srodrigc	ypldap_process = PROC_CLIENT;
398290931Srodrigc
399290931Srodrigc#ifndef DEBUG
400290931Srodrigc	if (setgroups(1, &pw->pw_gid) ||
401290931Srodrigc	    setresgid(pw->pw_gid, pw->pw_gid, pw->pw_gid) ||
402290931Srodrigc	    setresuid(pw->pw_uid, pw->pw_uid, pw->pw_uid))
403290931Srodrigc		fatal("cannot drop privileges");
404290931Srodrigc#else
405290931Srodrigc#warning disabling privilege revocation in DEBUG mode
406290931Srodrigc#endif
407290931Srodrigc
408290931Srodrigc	event_init();
409290931Srodrigc	signal(SIGPIPE, SIG_IGN);
410290931Srodrigc	signal_set(&ev_sigint, SIGINT, client_sig_handler, NULL);
411290931Srodrigc	signal_set(&ev_sigterm, SIGTERM, client_sig_handler, NULL);
412290931Srodrigc	signal_add(&ev_sigint, NULL);
413290931Srodrigc	signal_add(&ev_sigterm, NULL);
414290931Srodrigc
415290931Srodrigc	close(pipe_main2client[0]);
416290931Srodrigc	if ((env.sc_iev = calloc(1, sizeof(*env.sc_iev))) == NULL)
417290931Srodrigc		fatal(NULL);
418290931Srodrigc	if ((env.sc_iev_dns = calloc(1, sizeof(*env.sc_iev_dns))) == NULL)
419290931Srodrigc		fatal(NULL);
420290931Srodrigc
421290931Srodrigc	env.sc_iev->events = EV_READ;
422290931Srodrigc	env.sc_iev->data = &env;
423290931Srodrigc	imsg_init(&env.sc_iev->ibuf, pipe_main2client[1]);
424290931Srodrigc	env.sc_iev->handler = client_dispatch_parent;
425290931Srodrigc	event_set(&env.sc_iev->ev, env.sc_iev->ibuf.fd, env.sc_iev->events,
426290931Srodrigc	    env.sc_iev->handler, &env);
427290931Srodrigc	event_add(&env.sc_iev->ev, NULL);
428290931Srodrigc
429290931Srodrigc	env.sc_iev_dns->events = EV_READ;
430290931Srodrigc	env.sc_iev_dns->data = &env;
431290931Srodrigc	imsg_init(&env.sc_iev_dns->ibuf, pipe_dns[0]);
432290931Srodrigc	env.sc_iev_dns->handler = client_dispatch_dns;
433290931Srodrigc	event_set(&env.sc_iev_dns->ev, env.sc_iev_dns->ibuf.fd,
434290931Srodrigc	    env.sc_iev_dns->events, env.sc_iev_dns->handler, &env);
435290931Srodrigc	event_add(&env.sc_iev_dns->ev, NULL);
436290931Srodrigc
437290931Srodrigc	event_dispatch();
438290931Srodrigc	client_shutdown();
439290931Srodrigc
440290931Srodrigc	return (0);
441290931Srodrigc
442290931Srodrigc}
443290931Srodrigc
444290931Srodrigcint
445290931Srodrigcclient_build_req(struct idm *idm, struct idm_req *ir, struct aldap_message *m,
446290931Srodrigc    int min_attr, int max_attr)
447290931Srodrigc{
448290931Srodrigc	char	**ldap_attrs;
449290931Srodrigc	int	 i, k;
450290931Srodrigc
451290931Srodrigc	bzero(ir, sizeof(*ir));
452290931Srodrigc	for (i = min_attr; i < max_attr; i++) {
453290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i)) {
454290931Srodrigc			if (strlcat(ir->ir_line, idm->idm_attrs[i],
455290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
456290931Srodrigc				/*
457290931Srodrigc				 * entry yields a line > 1024, trash it.
458290931Srodrigc				 */
459290931Srodrigc				return (-1);
460290931Srodrigc
461290931Srodrigc			if (i == ATTR_UID) {
462290931Srodrigc				ir->ir_key.ik_uid = strtonum(
463290931Srodrigc				    idm->idm_attrs[i], 0,
464290931Srodrigc				    UID_MAX, NULL);
465290931Srodrigc			} else if (i == ATTR_GR_GID) {
466290931Srodrigc				ir->ir_key.ik_gid = strtonum(
467290931Srodrigc				    idm->idm_attrs[i], 0,
468290931Srodrigc				    GID_MAX, NULL);
469290931Srodrigc			}
470290931Srodrigc		} else if (idm->idm_list & F_LIST(i)) {
471290931Srodrigc			aldap_match_attr(m, idm->idm_attrs[i], &ldap_attrs);
472290931Srodrigc			for (k = 0; k >= 0 && ldap_attrs && ldap_attrs[k] != NULL; k++) {
473290931Srodrigc				/* XXX: Fail when attributes have illegal characters e.g. ',' */
474290931Srodrigc				if (strlcat(ir->ir_line, ldap_attrs[k],
475290931Srodrigc				    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
476290931Srodrigc					continue;
477290931Srodrigc				if (ldap_attrs[k+1] != NULL)
478290931Srodrigc					if (strlcat(ir->ir_line, ",",
479290931Srodrigc						    sizeof(ir->ir_line))
480290931Srodrigc					    >= sizeof(ir->ir_line)) {
481290931Srodrigc						aldap_free_attr(ldap_attrs);
482290931Srodrigc						return (-1);
483290931Srodrigc					}
484290931Srodrigc			}
485290931Srodrigc			aldap_free_attr(ldap_attrs);
486290931Srodrigc		} else {
487290931Srodrigc			if (aldap_match_attr(m, idm->idm_attrs[i], &ldap_attrs) == -1)
488290931Srodrigc				return (-1);
489290931Srodrigc			if (ldap_attrs[0] == NULL)
490290931Srodrigc				return (-1);
491290931Srodrigc			if (strlcat(ir->ir_line, ldap_attrs[0],
492290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line)) {
493290931Srodrigc				aldap_free_attr(ldap_attrs);
494290931Srodrigc				return (-1);
495290931Srodrigc			}
496290931Srodrigc			if (i == ATTR_UID) {
497290931Srodrigc				ir->ir_key.ik_uid = strtonum(
498290931Srodrigc				    ldap_attrs[0], 0, UID_MAX, NULL);
499290931Srodrigc			} else if (i == ATTR_GR_GID) {
500290931Srodrigc				ir->ir_key.ik_uid = strtonum(
501290931Srodrigc				    ldap_attrs[0], 0, GID_MAX, NULL);
502290931Srodrigc			}
503290931Srodrigc			aldap_free_attr(ldap_attrs);
504290931Srodrigc		}
505290931Srodrigc
506290931Srodrigc		if (i + 1 != max_attr)
507290931Srodrigc			if (strlcat(ir->ir_line, ":",
508290931Srodrigc			    sizeof(ir->ir_line)) >= sizeof(ir->ir_line))
509290931Srodrigc				return (-1);
510290931Srodrigc	}
511290931Srodrigc
512290931Srodrigc	return (0);
513290931Srodrigc}
514290931Srodrigc
515290931Srodrigcint
516290931Srodrigcclient_search_idm(struct env *env, struct idm *idm, struct aldap *al,
517290931Srodrigc    char **attrs, char *filter, int min_attr, int max_attr,
518290931Srodrigc    enum imsg_type type)
519290931Srodrigc{
520290931Srodrigc	struct idm_req		 ir;
521290931Srodrigc	struct aldap_message	*m;
522290931Srodrigc	struct aldap_page_control *pg = NULL;
523290931Srodrigc	const char		*errstr;
524290931Srodrigc	char			*dn;
525290931Srodrigc
526290931Srodrigc	dn = idm->idm_basedn;
527290931Srodrigc	if (type == IMSG_GRP_ENTRY && idm->idm_groupdn[0] != '\0')
528290931Srodrigc		dn = idm->idm_groupdn;
529290931Srodrigc
530290931Srodrigc	do {
531290931Srodrigc		if (aldap_search(al, dn, LDAP_SCOPE_SUBTREE,
532290931Srodrigc		    filter, attrs, 0, 0, 0, pg) == -1) {
533290931Srodrigc			aldap_get_errno(al, &errstr);
534290931Srodrigc			log_debug("%s", errstr);
535290931Srodrigc			return (-1);
536290931Srodrigc		}
537290931Srodrigc
538290931Srodrigc		if (pg != NULL) {
539290931Srodrigc			aldap_freepage(pg);
540290931Srodrigc			pg = NULL;
541290931Srodrigc		}
542290931Srodrigc
543290931Srodrigc		while ((m = aldap_parse(al)) != NULL) {
544290931Srodrigc			if (al->msgid != m->msgid) {
545290931Srodrigc				goto fail;
546290931Srodrigc			}
547290931Srodrigc
548290931Srodrigc			if (m->message_type == LDAP_RES_SEARCH_RESULT) {
549290931Srodrigc				if (m->page != NULL && m->page->cookie_len != 0)
550290931Srodrigc					pg = m->page;
551290931Srodrigc				else
552290931Srodrigc					pg = NULL;
553290931Srodrigc
554290931Srodrigc				aldap_freemsg(m);
555290931Srodrigc				break;
556290931Srodrigc			}
557290931Srodrigc
558290931Srodrigc			if (m->message_type != LDAP_RES_SEARCH_ENTRY) {
559290931Srodrigc				goto fail;
560290931Srodrigc			}
561290931Srodrigc
562290931Srodrigc			if (client_build_req(idm, &ir, m, min_attr, max_attr) == 0)
563290931Srodrigc				imsg_compose_event(env->sc_iev, type, 0, 0, -1,
564290931Srodrigc				    &ir, sizeof(ir));
565290931Srodrigc
566290931Srodrigc			aldap_freemsg(m);
567290931Srodrigc		}
568290931Srodrigc	} while (pg != NULL);
569290931Srodrigc
570290931Srodrigc	return (0);
571290931Srodrigc
572290931Srodrigcfail:
573290931Srodrigc	aldap_freemsg(m);
574290931Srodrigc	if (pg != NULL) {
575290931Srodrigc		aldap_freepage(pg);
576290931Srodrigc	}
577290931Srodrigc
578290931Srodrigc	return (-1);
579290931Srodrigc}
580290931Srodrigc
581290931Srodrigcint
582290931Srodrigcclient_try_idm(struct env *env, struct idm *idm)
583290931Srodrigc{
584290931Srodrigc	const char		*where;
585290931Srodrigc	char			*attrs[ATTR_MAX+1];
586290931Srodrigc	int			 i, j;
587290931Srodrigc	struct aldap_message	*m;
588290931Srodrigc	struct aldap		*al;
589290931Srodrigc
590290931Srodrigc	where = "connect";
591290931Srodrigc	if ((al = client_aldap_open(idm->idm_addr)) == NULL)
592290931Srodrigc		return (-1);
593290931Srodrigc
594290931Srodrigc	if (idm->idm_flags & F_NEEDAUTH) {
595290931Srodrigc		where = "binding";
596290931Srodrigc		if (aldap_bind(al, idm->idm_binddn, idm->idm_bindcred) == -1)
597290931Srodrigc			goto bad;
598290931Srodrigc
599290931Srodrigc		where = "parsing";
600290931Srodrigc		if ((m = aldap_parse(al)) == NULL)
601290931Srodrigc			goto bad;
602290931Srodrigc		where = "verifying msgid";
603290931Srodrigc		if (al->msgid != m->msgid) {
604290931Srodrigc			aldap_freemsg(m);
605290931Srodrigc			goto bad;
606290931Srodrigc		}
607290931Srodrigc		aldap_freemsg(m);
608290931Srodrigc	}
609290931Srodrigc
610290931Srodrigc	bzero(attrs, sizeof(attrs));
611290931Srodrigc	for (i = 0, j = 0; i < ATTR_MAX; i++) {
612290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i))
613290931Srodrigc			continue;
614290931Srodrigc		attrs[j++] = idm->idm_attrs[i];
615290931Srodrigc	}
616290931Srodrigc	attrs[j] = NULL;
617290931Srodrigc
618290931Srodrigc	/*
619290931Srodrigc	 * build password line.
620290931Srodrigc	 */
621290931Srodrigc	where = "search";
622290931Srodrigc	log_debug("searching password entries");
623290931Srodrigc	if (client_search_idm(env, idm, al, attrs,
624290931Srodrigc	    idm->idm_filters[FILTER_USER], 0, ATTR_MAX, IMSG_PW_ENTRY) == -1)
625290931Srodrigc		goto bad;
626290931Srodrigc
627290931Srodrigc	bzero(attrs, sizeof(attrs));
628290931Srodrigc	for (i = ATTR_GR_MIN, j = 0; i < ATTR_GR_MAX; i++) {
629290931Srodrigc		if (idm->idm_flags & F_FIXED_ATTR(i))
630290931Srodrigc			continue;
631290931Srodrigc		attrs[j++] = idm->idm_attrs[i];
632290931Srodrigc	}
633290931Srodrigc	attrs[j] = NULL;
634290931Srodrigc
635290931Srodrigc	/*
636290931Srodrigc	 * build group line.
637290931Srodrigc	 */
638290931Srodrigc	where = "search";
639290931Srodrigc	log_debug("searching group entries");
640290931Srodrigc	if (client_search_idm(env, idm, al, attrs,
641290931Srodrigc	    idm->idm_filters[FILTER_GROUP], ATTR_GR_MIN, ATTR_GR_MAX,
642290931Srodrigc	    IMSG_GRP_ENTRY) == -1)
643290931Srodrigc		goto bad;
644290931Srodrigc
645290931Srodrigc	aldap_close(al);
646290931Srodrigc
647290931Srodrigc	idm->idm_state = STATE_LDAP_DONE;
648290931Srodrigc
649290931Srodrigc	return (0);
650290931Srodrigcbad:
651290931Srodrigc	aldap_close(al);
652290931Srodrigc	log_debug("directory %s errored out in %s", idm->idm_name, where);
653290931Srodrigc	return (-1);
654290931Srodrigc}
655290931Srodrigc
656290931Srodrigcvoid
657290931Srodrigcclient_periodic_update(int fd, short event, void *p)
658290931Srodrigc{
659290931Srodrigc	struct env	*env = p;
660290931Srodrigc
661290931Srodrigc	struct idm	*idm;
662290931Srodrigc	int		 fail_cnt = 0;
663290931Srodrigc
664290931Srodrigc	/* If LDAP isn't finished, notify the master process to trash the
665290931Srodrigc	 * update. */
666290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
667290931Srodrigc		if (idm->idm_state < STATE_LDAP_DONE)
668290931Srodrigc			fail_cnt++;
669290931Srodrigc
670290931Srodrigc		idm->idm_state = STATE_NONE;
671290931Srodrigc
672290931Srodrigc		client_addr_free(idm);
673290931Srodrigc	}
674290931Srodrigc	if (fail_cnt > 0) {
675290931Srodrigc		log_debug("trash the update");
676290931Srodrigc		imsg_compose_event(env->sc_iev, IMSG_TRASH_UPDATE, 0, 0, -1,
677290931Srodrigc		    NULL, 0);
678290931Srodrigc	}
679290931Srodrigc
680290931Srodrigc	client_configure(env);
681290931Srodrigc}
682290931Srodrigc
683290931Srodrigcvoid
684290931Srodrigcclient_configure(struct env *env)
685290931Srodrigc{
686290931Srodrigc	struct timeval	 tv;
687290931Srodrigc	struct idm	*idm;
688290931Srodrigc        u_int16_t        dlen;
689290931Srodrigc
690290931Srodrigc	log_debug("connecting to directories");
691290931Srodrigc
692290931Srodrigc	imsg_compose_event(env->sc_iev, IMSG_START_UPDATE, 0, 0, -1, NULL, 0);
693290931Srodrigc
694290931Srodrigc	/* Start the DNS lookups */
695290931Srodrigc	TAILQ_FOREACH(idm, &env->sc_idms, idm_entry) {
696290931Srodrigc		dlen = strlen(idm->idm_name) + 1;
697290931Srodrigc		imsg_compose_event(env->sc_iev_dns, IMSG_HOST_DNS, idm->idm_id,
698290931Srodrigc		    0, -1, idm->idm_name, dlen);
699290931Srodrigc	}
700290931Srodrigc
701290931Srodrigc	tv.tv_sec = env->sc_conf_tv.tv_sec;
702290931Srodrigc	tv.tv_usec = env->sc_conf_tv.tv_usec;
703290931Srodrigc	evtimer_set(&env->sc_conf_ev, client_periodic_update, env);
704290931Srodrigc	evtimer_add(&env->sc_conf_ev, &tv);
705290931Srodrigc}
706