ypldap_dns.c revision 290934
1290931Srodrigc/* $OpenBSD: ypldap_dns.c,v 1.8 2015/01/16 06:40:22 deraadt Exp $ */ 2290931Srodrigc/* $FreeBSD: head/usr.sbin/ypldap/ypldap_dns.c 290934 2015-11-16 16:58:09Z rodrigc $ */ 3290931Srodrigc 4290931Srodrigc/* 5290931Srodrigc * Copyright (c) 2003-2008 Henning Brauer <henning@openbsd.org> 6290931Srodrigc * 7290931Srodrigc * Permission to use, copy, modify, and distribute this software for any 8290931Srodrigc * purpose with or without fee is hereby granted, provided that the above 9290931Srodrigc * copyright notice and this permission notice appear in all copies. 10290931Srodrigc * 11290931Srodrigc * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 12290931Srodrigc * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 13290931Srodrigc * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 14290931Srodrigc * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 15290931Srodrigc * WHATSOEVER RESULTING FROM LOSS OF MIND, USE, DATA OR PROFITS, WHETHER 16290931Srodrigc * IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING 17290931Srodrigc * OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 18290931Srodrigc */ 19290931Srodrigc 20290931Srodrigc#include <sys/types.h> 21290931Srodrigc#include <sys/socket.h> 22290931Srodrigc#include <sys/stat.h> 23290931Srodrigc#include <sys/time.h> 24290931Srodrigc#include <sys/tree.h> 25290931Srodrigc#include <sys/queue.h> 26290931Srodrigc 27290931Srodrigc#include <netinet/in.h> 28290931Srodrigc#include <arpa/nameser.h> 29290931Srodrigc 30290931Srodrigc#include <netdb.h> 31290931Srodrigc#include <pwd.h> 32290931Srodrigc#include <errno.h> 33290931Srodrigc#include <event.h> 34290931Srodrigc#include <resolv.h> 35290931Srodrigc#include <poll.h> 36290931Srodrigc#include <signal.h> 37290931Srodrigc#include <stdlib.h> 38290931Srodrigc#include <string.h> 39290931Srodrigc#include <unistd.h> 40290931Srodrigc#include <limits.h> 41290931Srodrigc 42290931Srodrigc#include "ypldap.h" 43290931Srodrigc 44290931Srodrigcvolatile sig_atomic_t quit_dns = 0; 45290931Srodrigcstruct imsgev *iev_dns; 46290931Srodrigc 47290931Srodrigcvoid dns_dispatch_imsg(int, short, void *); 48290931Srodrigcvoid dns_sig_handler(int, short, void *); 49290931Srodrigcvoid dns_shutdown(void); 50290931Srodrigcint host_dns(const char *s, struct ypldap_addr **hn); 51290931Srodrigc 52290931Srodrigcvoid 53290931Srodrigcdns_sig_handler(int sig, short event, void *p) 54290931Srodrigc{ 55290931Srodrigc switch (sig) { 56290931Srodrigc case SIGINT: 57290931Srodrigc case SIGTERM: 58290931Srodrigc dns_shutdown(); 59290931Srodrigc break; 60290931Srodrigc default: 61290931Srodrigc fatalx("unexpected signal"); 62290931Srodrigc } 63290931Srodrigc} 64290931Srodrigc 65290931Srodrigcvoid 66290931Srodrigcdns_shutdown(void) 67290931Srodrigc{ 68290931Srodrigc log_info("dns engine exiting"); 69290931Srodrigc _exit(0); 70290931Srodrigc} 71290931Srodrigc 72290931Srodrigcpid_t 73290931Srodrigcypldap_dns(int pipe_ntp[2], struct passwd *pw) 74290931Srodrigc{ 75290931Srodrigc pid_t pid; 76290931Srodrigc struct event ev_sigint; 77290931Srodrigc struct event ev_sigterm; 78290931Srodrigc struct event ev_sighup; 79290931Srodrigc struct env env; 80290931Srodrigc 81290931Srodrigc switch (pid = fork()) { 82290931Srodrigc case -1: 83290931Srodrigc fatal("cannot fork"); 84290931Srodrigc break; 85290931Srodrigc case 0: 86290931Srodrigc break; 87290931Srodrigc default: 88290931Srodrigc return (pid); 89290931Srodrigc } 90290931Srodrigc 91290931Srodrigc setproctitle("dns engine"); 92290931Srodrigc close(pipe_ntp[0]); 93290931Srodrigc 94290931Srodrigc if (setgroups(1, &pw->pw_gid) || 95290931Srodrigc setresgid(pw->pw_gid, pw->pw_gid, pw->pw_gid) || 96290931Srodrigc setresuid(pw->pw_uid, pw->pw_uid, pw->pw_uid)) 97290931Srodrigc fatal("can't drop privileges"); 98290931Srodrigc endservent(); 99290931Srodrigc 100290931Srodrigc event_init(); 101290931Srodrigc signal_set(&ev_sigint, SIGINT, dns_sig_handler, NULL); 102290931Srodrigc signal_set(&ev_sigterm, SIGTERM, dns_sig_handler, NULL); 103290931Srodrigc signal_set(&ev_sighup, SIGHUP, dns_sig_handler, NULL); 104290931Srodrigc signal_add(&ev_sigint, NULL); 105290931Srodrigc signal_add(&ev_sigterm, NULL); 106290931Srodrigc signal_add(&ev_sighup, NULL); 107290931Srodrigc 108290931Srodrigc if ((env.sc_iev = calloc(1, sizeof(*env.sc_iev))) == NULL) 109290931Srodrigc fatal(NULL); 110290931Srodrigc 111290931Srodrigc env.sc_iev->events = EV_READ; 112290931Srodrigc env.sc_iev->data = &env; 113290931Srodrigc imsg_init(&env.sc_iev->ibuf, pipe_ntp[1]); 114290931Srodrigc env.sc_iev->handler = dns_dispatch_imsg; 115290931Srodrigc event_set(&env.sc_iev->ev, env.sc_iev->ibuf.fd, env.sc_iev->events, 116290931Srodrigc env.sc_iev->handler, &env); 117290931Srodrigc event_add(&env.sc_iev->ev, NULL); 118290931Srodrigc 119290931Srodrigc event_dispatch(); 120290931Srodrigc dns_shutdown(); 121290931Srodrigc 122290931Srodrigc return (0); 123290931Srodrigc} 124290931Srodrigc 125290931Srodrigcvoid 126290931Srodrigcdns_dispatch_imsg(int fd, short events, void *p) 127290931Srodrigc{ 128290931Srodrigc struct imsg imsg; 129290931Srodrigc int n, cnt; 130290931Srodrigc char *name; 131290931Srodrigc struct ypldap_addr *h, *hn; 132290931Srodrigc struct ibuf *buf; 133290931Srodrigc struct env *env = p; 134290931Srodrigc struct imsgev *iev = env->sc_iev; 135290931Srodrigc struct imsgbuf *ibuf = &iev->ibuf; 136290931Srodrigc int shut = 0; 137290931Srodrigc 138290931Srodrigc if ((events & (EV_READ | EV_WRITE)) == 0) 139290931Srodrigc fatalx("unknown event"); 140290931Srodrigc 141290931Srodrigc if (events & EV_READ) { 142290931Srodrigc if ((n = imsg_read(ibuf)) == -1) 143290931Srodrigc fatal("imsg_read error"); 144290931Srodrigc if (n == 0) 145290931Srodrigc shut = 1; 146290931Srodrigc } 147290931Srodrigc if (events & EV_WRITE) { 148290931Srodrigc if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN) 149290931Srodrigc fatal("msgbuf_write"); 150290931Srodrigc if (n == 0) 151290931Srodrigc shut = 1; 152290931Srodrigc goto done; 153290931Srodrigc } 154290931Srodrigc 155290931Srodrigc for (;;) { 156290931Srodrigc if ((n = imsg_get(ibuf, &imsg)) == -1) 157290931Srodrigc fatal("client_dispatch_imsg: imsg_get error"); 158290931Srodrigc if (n == 0) 159290931Srodrigc break; 160290931Srodrigc 161290931Srodrigc switch (imsg.hdr.type) { 162290931Srodrigc case IMSG_HOST_DNS: 163290931Srodrigc name = imsg.data; 164290931Srodrigc if (imsg.hdr.len < 1 + IMSG_HEADER_SIZE) 165290931Srodrigc fatalx("invalid IMSG_HOST_DNS received"); 166290931Srodrigc imsg.hdr.len -= 1 + IMSG_HEADER_SIZE; 167290931Srodrigc if (name[imsg.hdr.len] != '\0' || 168290931Srodrigc strlen(name) != imsg.hdr.len) 169290931Srodrigc fatalx("invalid IMSG_HOST_DNS received"); 170290931Srodrigc if ((cnt = host_dns(name, &hn)) == -1) 171290931Srodrigc break; 172290931Srodrigc buf = imsg_create(ibuf, IMSG_HOST_DNS, 173290931Srodrigc imsg.hdr.peerid, 0, 174290931Srodrigc cnt * sizeof(struct sockaddr_storage)); 175290931Srodrigc if (buf == NULL) 176290931Srodrigc break; 177290931Srodrigc if (cnt > 0) { 178290931Srodrigc h = hn; 179290931Srodrigc while (h != NULL) { 180290931Srodrigc imsg_add(buf, &h->ss, sizeof(h->ss)); 181290931Srodrigc hn = h->next; 182290931Srodrigc free(h); 183290931Srodrigc h = hn; 184290931Srodrigc } 185290931Srodrigc } 186290931Srodrigc 187290931Srodrigc imsg_close(ibuf, buf); 188290931Srodrigc break; 189290931Srodrigc default: 190290931Srodrigc break; 191290931Srodrigc } 192290931Srodrigc imsg_free(&imsg); 193290931Srodrigc } 194290931Srodrigc 195290931Srodrigcdone: 196290931Srodrigc if (!shut) 197290931Srodrigc imsg_event_add(iev); 198290931Srodrigc else { 199290931Srodrigc /* this pipe is dead, so remove the event handler */ 200290931Srodrigc event_del(&iev->ev); 201290931Srodrigc event_loopexit(NULL); 202290931Srodrigc } 203290931Srodrigc} 204290931Srodrigc 205290931Srodrigcint 206290931Srodrigchost_dns(const char *s, struct ypldap_addr **hn) 207290931Srodrigc{ 208290931Srodrigc struct addrinfo hints, *res0, *res; 209290931Srodrigc int error, cnt = 0; 210290931Srodrigc struct sockaddr_in *sa_in; 211290931Srodrigc struct sockaddr_in6 *sa_in6; 212290931Srodrigc struct ypldap_addr *h, *hh = NULL; 213290931Srodrigc 214290931Srodrigc bzero(&hints, sizeof(hints)); 215290931Srodrigc hints.ai_family = PF_UNSPEC; 216290931Srodrigc hints.ai_socktype = SOCK_DGRAM; /* DUMMY */ 217290931Srodrigc error = getaddrinfo(s, NULL, &hints, &res0); 218290934Srodrigc if (error == EAI_AGAIN || error == EAI_NONAME) 219290931Srodrigc return (0); 220290931Srodrigc if (error) { 221290931Srodrigc log_warnx("could not parse \"%s\": %s", s, 222290931Srodrigc gai_strerror(error)); 223290931Srodrigc return (-1); 224290931Srodrigc } 225290931Srodrigc 226290931Srodrigc for (res = res0; res && cnt < MAX_SERVERS_DNS; res = res->ai_next) { 227290931Srodrigc if (res->ai_family != AF_INET && 228290931Srodrigc res->ai_family != AF_INET6) 229290931Srodrigc continue; 230290931Srodrigc if ((h = calloc(1, sizeof(struct ypldap_addr))) == NULL) 231290931Srodrigc fatal(NULL); 232290931Srodrigc h->ss.ss_family = res->ai_family; 233290931Srodrigc if (res->ai_family == AF_INET) { 234290931Srodrigc sa_in = (struct sockaddr_in *)&h->ss; 235290931Srodrigc sa_in->sin_len = sizeof(struct sockaddr_in); 236290931Srodrigc sa_in->sin_addr.s_addr = ((struct sockaddr_in *) 237290931Srodrigc res->ai_addr)->sin_addr.s_addr; 238290931Srodrigc } else { 239290931Srodrigc sa_in6 = (struct sockaddr_in6 *)&h->ss; 240290931Srodrigc sa_in6->sin6_len = sizeof(struct sockaddr_in6); 241290931Srodrigc memcpy(&sa_in6->sin6_addr, &((struct sockaddr_in6 *) 242290931Srodrigc res->ai_addr)->sin6_addr, sizeof(struct in6_addr)); 243290931Srodrigc } 244290931Srodrigc 245290931Srodrigc h->next = hh; 246290931Srodrigc hh = h; 247290931Srodrigc cnt++; 248290931Srodrigc } 249290931Srodrigc freeaddrinfo(res0); 250290931Srodrigc 251290931Srodrigc *hn = hh; 252290931Srodrigc return (cnt); 253290931Srodrigc} 254