1 /* $OpenBSD: ypldap.h,v 1.21 2021/01/27 07:21:55 deraadt Exp $ */ 2 3 /* 4 * Copyright (c) 2008 Pierre-Yves Ritschard <pyr@openbsd.org> 5 * 6 * Permission to use, copy, modify, and distribute this software for any 7 * purpose with or without fee is hereby granted, provided that the above 8 * copyright notice and this permission notice appear in all copies. 9 * 10 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 11 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 12 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 13 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 14 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 15 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 16 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 17 */ 18 19 #include <imsg.h> 20 #include <tls.h> 21 22 #define YPLDAP_USER "_ypldap" 23 #define YPLDAP_CONF_FILE "/etc/ypldap.conf" 24 #define DEFAULT_INTERVAL 600 25 #define LINE_WIDTH 1024 26 #define FILTER_WIDTH 128 27 #define ATTR_WIDTH 32 28 29 #define MAX_SERVERS_DNS 8 30 31 enum imsg_type { 32 IMSG_NONE, 33 IMSG_CONF_START, 34 IMSG_CONF_IDM, 35 IMSG_CONF_END, 36 IMSG_START_UPDATE, 37 IMSG_END_UPDATE, 38 IMSG_TRASH_UPDATE, 39 IMSG_PW_ENTRY, 40 IMSG_GRP_ENTRY, 41 IMSG_HOST_DNS 42 }; 43 44 struct ypldap_addr { 45 TAILQ_ENTRY(ypldap_addr) next; 46 struct sockaddr_storage ss; 47 }; 48 TAILQ_HEAD(ypldap_addr_list, ypldap_addr); 49 50 enum privsep_procid { 51 PROC_MAIN, 52 PROC_CLIENT 53 }; 54 extern enum privsep_procid ypldap_process; 55 56 static const char * const log_procnames[] = { 57 "parent", 58 "ldapclient" 59 }; 60 61 struct userent { 62 RB_ENTRY(userent) ue_name_node; 63 RB_ENTRY(userent) ue_uid_node; 64 uid_t ue_uid; 65 char *ue_line; 66 char *ue_netid_line; 67 gid_t ue_gid; 68 }; 69 70 struct groupent { 71 RB_ENTRY(groupent) ge_name_node; 72 RB_ENTRY(groupent) ge_gid_node; 73 gid_t ge_gid; 74 char *ge_line; 75 }; 76 77 enum client_state { 78 STATE_NONE, 79 STATE_DNS_INPROGRESS, 80 STATE_DNS_TEMPFAIL, 81 STATE_DNS_DONE, 82 STATE_LDAP_FAIL, 83 STATE_LDAP_DONE 84 }; 85 86 /* 87 * beck, djm, dlg: pay attention to the struct name 88 */ 89 struct idm { 90 TAILQ_ENTRY(idm) idm_entry; 91 u_int32_t idm_id; 92 char idm_name[HOST_NAME_MAX+1]; 93 #define F_SSL 0x00100000 94 #define F_CONFIGURING 0x00200000 95 #define F_NEEDAUTH 0x00400000 96 #define F_STARTTLS 0x00800000 97 #define F_FIXED_ATTR(n) (1<<n) 98 #define F_LIST(n) (1<<n) 99 enum client_state idm_state; 100 u_int32_t idm_flags; /* lower 20 reserved */ 101 u_int32_t idm_list; 102 struct ypldap_addr_list idm_addr; 103 in_port_t idm_port; 104 char idm_binddn[LINE_WIDTH]; 105 char idm_bindcred[LINE_WIDTH]; 106 char idm_basedn[LINE_WIDTH]; 107 char idm_groupdn[LINE_WIDTH]; 108 #define FILTER_USER 1 109 #define FILTER_GROUP 0 110 char idm_filters[2][FILTER_WIDTH]; 111 #define ATTR_NAME 0 112 #define ATTR_PASSWD 1 113 #define ATTR_UID 2 114 #define ATTR_GID 3 115 #define ATTR_CLASS 4 116 #define ATTR_CHANGE 5 117 #define ATTR_EXPIRE 6 118 #define ATTR_GECOS 7 119 #define ATTR_DIR 8 120 #define ATTR_SHELL 9 121 #define ATTR_GR_NAME 10 122 #define ATTR_GR_PASSWD 11 123 #define ATTR_GR_GID 12 124 #define ATTR_GR_MEMBERS 13 125 #define ATTR_MAX 10 126 #define ATTR_GR_MIN 10 127 #define ATTR_GR_MAX 14 128 char idm_attrs[14][ATTR_WIDTH]; 129 struct env *idm_env; 130 struct tls_config *idm_tls_config; 131 }; 132 133 struct idm_req { 134 union { 135 uid_t ik_uid; 136 uid_t ik_gid; 137 } ir_key; 138 char ir_line[LINE_WIDTH]; 139 }; 140 141 struct imsgev { 142 struct imsgbuf ibuf; 143 void (*handler)(int, short, void *); 144 struct event ev; 145 void *data; 146 short events; 147 }; 148 149 struct env { 150 #define YPLDAP_OPT_VERBOSE 0x01 151 #define YPLDAP_OPT_NOACTION 0x02 152 u_int8_t sc_opts; 153 #define YPMAP_PASSWD_BYNAME 0x00000001 154 #define YPMAP_PASSWD_BYUID 0x00000002 155 #define YPMAP_MASTER_PASSWD_BYNAME 0x00000004 156 #define YPMAP_MASTER_PASSWD_BYUID 0x00000008 157 #define YPMAP_GROUP_BYNAME 0x00000010 158 #define YPMAP_GROUP_BYGID 0x00000020 159 #define YPMAP_NETID_BYNAME 0x00000040 160 u_int32_t sc_flags; 161 162 u_int32_t sc_maxid; 163 164 char sc_domainname[HOST_NAME_MAX+1]; 165 struct timeval sc_conf_tv; 166 struct event sc_conf_ev; 167 char *sc_cafile; 168 TAILQ_HEAD(idm_list, idm) sc_idms; 169 struct imsgev *sc_iev; 170 struct imsgev *sc_iev_dns; 171 172 RB_HEAD(user_name_tree,userent) *sc_user_names; 173 RB_HEAD(user_uid_tree,userent) sc_user_uids; 174 RB_HEAD(group_name_tree,groupent)*sc_group_names; 175 RB_HEAD(group_gid_tree,groupent) sc_group_gids; 176 struct user_name_tree *sc_user_names_t; 177 struct group_name_tree *sc_group_names_t; 178 size_t sc_user_line_len; 179 size_t sc_group_line_len; 180 char *sc_user_lines; 181 char *sc_group_lines; 182 183 struct yp_data *sc_yp; 184 185 int update_trashed; 186 }; 187 188 /* log.c */ 189 void log_init(int); 190 void log_warn(const char *, ...); 191 void log_warnx(const char *, ...); 192 void log_info(const char *, ...); 193 void log_debug(const char *, ...); 194 void logit(int, const char *, ...); 195 void vlog(int, const char *, va_list); 196 __dead void fatal(const char *); 197 __dead void fatalx(const char *); 198 199 /* parse.y */ 200 int parse_config(struct env *, const char *, int); 201 int cmdline_symset(char *); 202 203 /* ldapclient.c */ 204 pid_t ldapclient(int []); 205 206 /* ypldap.c */ 207 void purge_config(struct env *); 208 void imsg_event_add(struct imsgev *); 209 int imsg_compose_event(struct imsgev *, u_int16_t, u_int32_t, 210 pid_t, int, void *, u_int16_t); 211 212 /* entries.c */ 213 void flatten_entries(struct env *); 214 int userent_name_cmp(struct userent *, struct userent *); 215 int userent_uid_cmp(struct userent *, struct userent *); 216 int groupent_name_cmp(struct groupent *, struct groupent *); 217 int groupent_gid_cmp(struct groupent *, struct groupent *); 218 RB_PROTOTYPE( user_name_tree, userent, ue_name_node, userent_name_cmp); 219 RB_PROTOTYPE( user_uid_tree, userent, ue_uid_node, userent_uid_cmp); 220 RB_PROTOTYPE( group_name_tree, groupent, ge_name_node, groupent_name_cmp); 221 RB_PROTOTYPE( group_gid_tree, groupent, ge_gid_node, groupent_gid_cmp); 222 223 /* yp.c */ 224 void yp_init(struct env *); 225 void yp_enable_events(void); 226 227 /* ypldap_dns.c */ 228 pid_t ypldap_dns(int[2], struct passwd *); 229