Blame


1 8d1b399b 2021-07-22 op /*
2 8d1b399b 2021-07-22 op * Copyright (c) 2021 Omar Polo <op@omarpolo.com>
3 8d1b399b 2021-07-22 op * Copyright (c) 2018 Florian Obser <florian@openbsd.org>
4 8d1b399b 2021-07-22 op * Copyright (c) 2005 Claudio Jeker <claudio@openbsd.org>
5 8d1b399b 2021-07-22 op * Copyright (c) 2004 Esben Norby <norby@openbsd.org>
6 8d1b399b 2021-07-22 op * Copyright (c) 2003, 2004 Henning Brauer <henning@openbsd.org>
7 8d1b399b 2021-07-22 op *
8 8d1b399b 2021-07-22 op * Permission to use, copy, modify, and distribute this software for any
9 8d1b399b 2021-07-22 op * purpose with or without fee is hereby granted, provided that the above
10 8d1b399b 2021-07-22 op * copyright notice and this permission notice appear in all copies.
11 8d1b399b 2021-07-22 op *
12 8d1b399b 2021-07-22 op * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
13 8d1b399b 2021-07-22 op * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
14 8d1b399b 2021-07-22 op * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
15 8d1b399b 2021-07-22 op * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
16 8d1b399b 2021-07-22 op * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
17 8d1b399b 2021-07-22 op * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
18 8d1b399b 2021-07-22 op * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
19 8d1b399b 2021-07-22 op */
20 8d1b399b 2021-07-22 op
21 8d1b399b 2021-07-22 op #include <sys/socket.h>
22 8d1b399b 2021-07-22 op #include <sys/wait.h>
23 8d1b399b 2021-07-22 op
24 8d1b399b 2021-07-22 op #include <arpa/inet.h>
25 8d1b399b 2021-07-22 op #include <netinet/in.h>
26 8d1b399b 2021-07-22 op
27 8d1b399b 2021-07-22 op #include <errno.h>
28 8d1b399b 2021-07-22 op #include <fcntl.h>
29 8d1b399b 2021-07-22 op #include <pwd.h>
30 8d1b399b 2021-07-22 op #include <signal.h>
31 8d1b399b 2021-07-22 op #include <stdio.h>
32 8d1b399b 2021-07-22 op #include <stdlib.h>
33 8d1b399b 2021-07-22 op #include <string.h>
34 8d1b399b 2021-07-22 op #include <syslog.h>
35 8d1b399b 2021-07-22 op #include <unistd.h>
36 8d1b399b 2021-07-22 op
37 8d1b399b 2021-07-22 op #include "client.h"
38 8d1b399b 2021-07-22 op #include "control.h"
39 8d1b399b 2021-07-22 op #include "kamid.h"
40 8d1b399b 2021-07-22 op #include "listener.h"
41 8d1b399b 2021-07-22 op #include "log.h"
42 8d1b399b 2021-07-22 op #include "sandbox.h"
43 0ca6718e 2021-07-22 op #include "table.h"
44 8d1b399b 2021-07-22 op #include "utils.h"
45 8d1b399b 2021-07-22 op
46 8d1b399b 2021-07-22 op enum kd_process {
47 8d1b399b 2021-07-22 op PROC_MAIN,
48 8d1b399b 2021-07-22 op PROC_LISTENER,
49 8d1b399b 2021-07-22 op PROC_CLIENTCONN,
50 8d1b399b 2021-07-22 op };
51 8d1b399b 2021-07-22 op
52 8d1b399b 2021-07-22 op const char *saved_argv0;
53 8d1b399b 2021-07-22 op static int debug, nflag;
54 8d1b399b 2021-07-22 op int verbose;
55 8d1b399b 2021-07-22 op
56 a97ec9eb 2021-12-23 op __dead void usage(void);
57 8d1b399b 2021-07-22 op
58 8d1b399b 2021-07-22 op void main_sig_handler(int, short, void *);
59 8d1b399b 2021-07-22 op void main_dispatch_listener(int, short, void *);
60 8d1b399b 2021-07-22 op int main_reload(void);
61 8d1b399b 2021-07-22 op int main_imsg_send_config(struct kd_conf *);
62 8d1b399b 2021-07-22 op void main_dispatch_listener(int, short, void *);
63 a97ec9eb 2021-12-23 op __dead void main_shutdown(void);
64 8d1b399b 2021-07-22 op
65 8d1b399b 2021-07-22 op static pid_t start_child(enum kd_process, int, int, int);
66 8d1b399b 2021-07-22 op
67 8d1b399b 2021-07-22 op struct kd_conf *main_conf;
68 8d1b399b 2021-07-22 op static struct imsgev *iev_listener;
69 8d1b399b 2021-07-22 op const char *conffile;
70 8d1b399b 2021-07-22 op pid_t listener_pid;
71 8d1b399b 2021-07-22 op uint32_t cmd_opts;
72 8d1b399b 2021-07-22 op
73 a97ec9eb 2021-12-23 op __dead void
74 8d1b399b 2021-07-22 op usage(void)
75 8d1b399b 2021-07-22 op {
76 8d1b399b 2021-07-22 op fprintf(stderr, "usage: %s [-dnv] [-f file] [-s socket]\n",
77 8d1b399b 2021-07-22 op getprogname());
78 8d1b399b 2021-07-22 op exit(1);
79 8d1b399b 2021-07-22 op }
80 8d1b399b 2021-07-22 op
81 8d1b399b 2021-07-22 op int
82 8d1b399b 2021-07-22 op main(int argc, char **argv)
83 8d1b399b 2021-07-22 op {
84 b841f564 2021-12-18 op struct event ev_sigint, ev_sigterm, ev_sighup;
85 8d1b399b 2021-07-22 op int ch;
86 8d1b399b 2021-07-22 op int listener_flag = 0, client_flag = 0;
87 8d1b399b 2021-07-22 op int pipe_main2listener[2];
88 8d1b399b 2021-07-22 op int control_fd;
89 8d1b399b 2021-07-22 op const char *csock;
90 8d1b399b 2021-07-22 op
91 8d1b399b 2021-07-22 op conffile = KD_CONF_FILE;
92 8d1b399b 2021-07-22 op csock = KD_SOCKET;
93 8d1b399b 2021-07-22 op
94 8d1b399b 2021-07-22 op log_init(1, LOG_DAEMON); /* Log to stderr until deamonized. */
95 8d1b399b 2021-07-22 op log_setverbose(1);
96 8d1b399b 2021-07-22 op
97 8d1b399b 2021-07-22 op saved_argv0 = argv[0];
98 8d1b399b 2021-07-22 op if (saved_argv0 == NULL)
99 8d1b399b 2021-07-22 op saved_argv0 = "kamid";
100 8d1b399b 2021-07-22 op
101 8d1b399b 2021-07-22 op while ((ch = getopt(argc, argv, "D:df:nsT:v")) != -1) {
102 8d1b399b 2021-07-22 op switch (ch) {
103 8d1b399b 2021-07-22 op case 'D':
104 8d1b399b 2021-07-22 op if (cmdline_symset(optarg) == -1)
105 8d1b399b 2021-07-22 op log_warnx("could not parse macro definition %s",
106 8d1b399b 2021-07-22 op optarg);
107 8d1b399b 2021-07-22 op break;
108 8d1b399b 2021-07-22 op case 'd':
109 8d1b399b 2021-07-22 op debug = 1;
110 8d1b399b 2021-07-22 op break;
111 8d1b399b 2021-07-22 op case 'f':
112 8d1b399b 2021-07-22 op conffile = optarg;
113 8d1b399b 2021-07-22 op break;
114 8d1b399b 2021-07-22 op case 'n':
115 8d1b399b 2021-07-22 op nflag = 1;
116 8d1b399b 2021-07-22 op break;
117 8d1b399b 2021-07-22 op case 's':
118 8d1b399b 2021-07-22 op csock = optarg;
119 8d1b399b 2021-07-22 op break;
120 8d1b399b 2021-07-22 op case 'T':
121 8d1b399b 2021-07-22 op switch (*optarg) {
122 8d1b399b 2021-07-22 op case 'c':
123 8d1b399b 2021-07-22 op client_flag = 1;
124 8d1b399b 2021-07-22 op break;
125 8d1b399b 2021-07-22 op case 'l':
126 8d1b399b 2021-07-22 op listener_flag = 1;
127 8d1b399b 2021-07-22 op break;
128 8d1b399b 2021-07-22 op default:
129 8d1b399b 2021-07-22 op fatalx("invalid process spec %c", *optarg);
130 8d1b399b 2021-07-22 op }
131 8d1b399b 2021-07-22 op break;
132 8d1b399b 2021-07-22 op case 'v':
133 8d1b399b 2021-07-22 op verbose = 1;
134 8d1b399b 2021-07-22 op break;
135 8d1b399b 2021-07-22 op default:
136 8d1b399b 2021-07-22 op usage();
137 8d1b399b 2021-07-22 op }
138 8d1b399b 2021-07-22 op }
139 8d1b399b 2021-07-22 op
140 8d1b399b 2021-07-22 op argc -= optind;
141 8d1b399b 2021-07-22 op argv += optind;
142 8d1b399b 2021-07-22 op if (argc > 0 || (listener_flag && client_flag))
143 8d1b399b 2021-07-22 op usage();
144 8d1b399b 2021-07-22 op
145 8d1b399b 2021-07-22 op if (client_flag)
146 8d1b399b 2021-07-22 op client(debug, verbose);
147 8d1b399b 2021-07-22 op else if (listener_flag)
148 8d1b399b 2021-07-22 op listener(debug, verbose);
149 8d1b399b 2021-07-22 op
150 8d1b399b 2021-07-22 op if ((main_conf = parse_config(conffile)) == NULL)
151 8d1b399b 2021-07-22 op exit(1);
152 8d1b399b 2021-07-22 op
153 8d1b399b 2021-07-22 op if (nflag) {
154 d96f10f4 2021-07-22 op fprintf(stderr, "configuration OK\n");
155 8d1b399b 2021-07-22 op exit(0);
156 8d1b399b 2021-07-22 op }
157 8d1b399b 2021-07-22 op
158 8d1b399b 2021-07-22 op /* Check for root privileges. */
159 8d1b399b 2021-07-22 op if (geteuid())
160 8d1b399b 2021-07-22 op fatalx("need root privileges");
161 8d1b399b 2021-07-22 op
162 8d1b399b 2021-07-22 op /* Check for assigned daemon user. */
163 8d1b399b 2021-07-22 op if (getpwnam(KD_USER) == NULL)
164 8d1b399b 2021-07-22 op fatalx("unknown user %s", KD_USER);
165 8d1b399b 2021-07-22 op
166 8d1b399b 2021-07-22 op log_init(debug, LOG_DAEMON);
167 8d1b399b 2021-07-22 op log_setverbose(verbose);
168 8d1b399b 2021-07-22 op
169 8d1b399b 2021-07-22 op if (!debug)
170 8d1b399b 2021-07-22 op daemon(1, 0);
171 8d1b399b 2021-07-22 op
172 8d1b399b 2021-07-22 op log_info("startup");
173 8d1b399b 2021-07-22 op
174 8d1b399b 2021-07-22 op if (socketpair(AF_UNIX, SOCK_STREAM | SOCK_CLOEXEC | SOCK_NONBLOCK,
175 8d1b399b 2021-07-22 op PF_UNSPEC, pipe_main2listener) == -1)
176 8d1b399b 2021-07-22 op fatal("main2listener socketpair");
177 8d1b399b 2021-07-22 op
178 8d1b399b 2021-07-22 op /* Start children. */
179 8d1b399b 2021-07-22 op listener_pid = start_child(PROC_LISTENER, pipe_main2listener[1],
180 8d1b399b 2021-07-22 op debug, verbose);
181 8d1b399b 2021-07-22 op
182 8d1b399b 2021-07-22 op log_procinit("main");
183 8d1b399b 2021-07-22 op
184 8d1b399b 2021-07-22 op event_init();
185 8d1b399b 2021-07-22 op
186 8d1b399b 2021-07-22 op /* Setup signal handler */
187 8d1b399b 2021-07-22 op signal_set(&ev_sigint, SIGINT, main_sig_handler, NULL);
188 8d1b399b 2021-07-22 op signal_set(&ev_sigterm, SIGTERM, main_sig_handler, NULL);
189 8d1b399b 2021-07-22 op signal_set(&ev_sighup, SIGHUP, main_sig_handler, NULL);
190 8d1b399b 2021-07-22 op
191 8d1b399b 2021-07-22 op signal_add(&ev_sigint, NULL);
192 8d1b399b 2021-07-22 op signal_add(&ev_sigterm, NULL);
193 8d1b399b 2021-07-22 op signal_add(&ev_sighup, NULL);
194 8d1b399b 2021-07-22 op
195 8d1b399b 2021-07-22 op signal(SIGCHLD, SIG_IGN);
196 8d1b399b 2021-07-22 op signal(SIGPIPE, SIG_IGN);
197 8d1b399b 2021-07-22 op
198 8d1b399b 2021-07-22 op if ((iev_listener = malloc(sizeof(*iev_listener))) == NULL)
199 8d1b399b 2021-07-22 op fatal(NULL);
200 8d1b399b 2021-07-22 op imsg_init(&iev_listener->ibuf, pipe_main2listener[0]);
201 8d1b399b 2021-07-22 op iev_listener->handler = main_dispatch_listener;
202 8d1b399b 2021-07-22 op
203 8d1b399b 2021-07-22 op /* Setup event handlers for pipes to listener. */
204 8d1b399b 2021-07-22 op iev_listener->events = EV_READ;
205 8d1b399b 2021-07-22 op event_set(&iev_listener->ev, iev_listener->ibuf.fd,
206 8d1b399b 2021-07-22 op iev_listener->events, iev_listener->handler, iev_listener);
207 8d1b399b 2021-07-22 op event_add(&iev_listener->ev, NULL);
208 8d1b399b 2021-07-22 op
209 8d1b399b 2021-07-22 op if ((control_fd = control_init(csock)) == -1)
210 8d1b399b 2021-07-22 op fatalx("control socket setup failed");
211 8d1b399b 2021-07-22 op
212 8d1b399b 2021-07-22 op main_imsg_compose_listener(IMSG_CONTROLFD, control_fd, 0,
213 8d1b399b 2021-07-22 op NULL, 0);
214 8d1b399b 2021-07-22 op main_imsg_send_config(main_conf);
215 8d1b399b 2021-07-22 op
216 8d1b399b 2021-07-22 op sandbox_main();
217 8d1b399b 2021-07-22 op
218 8d1b399b 2021-07-22 op event_dispatch();
219 8d1b399b 2021-07-22 op
220 8d1b399b 2021-07-22 op main_shutdown();
221 8d1b399b 2021-07-22 op return 0;
222 8d1b399b 2021-07-22 op }
223 8d1b399b 2021-07-22 op
224 8d1b399b 2021-07-22 op void
225 8d1b399b 2021-07-22 op main_sig_handler(int sig, short event, void *arg)
226 8d1b399b 2021-07-22 op {
227 8d1b399b 2021-07-22 op /*
228 8d1b399b 2021-07-22 op * Normal signal handler rules don't apply because libevent
229 8d1b399b 2021-07-22 op * decouples for us.
230 8d1b399b 2021-07-22 op */
231 8d1b399b 2021-07-22 op
232 8d1b399b 2021-07-22 op switch (sig) {
233 8d1b399b 2021-07-22 op case SIGTERM:
234 8d1b399b 2021-07-22 op case SIGINT:
235 8d1b399b 2021-07-22 op main_shutdown();
236 8d1b399b 2021-07-22 op break;
237 8d1b399b 2021-07-22 op case SIGHUP:
238 8d1b399b 2021-07-22 op if (main_reload() == -1)
239 8d1b399b 2021-07-22 op log_warnx("configuration reload failed");
240 8d1b399b 2021-07-22 op else
241 8d1b399b 2021-07-22 op log_debug("configuration reloaded");
242 8d1b399b 2021-07-22 op break;
243 8d1b399b 2021-07-22 op default:
244 8d1b399b 2021-07-22 op fatalx("unexpected signal %d", sig);
245 0ca6718e 2021-07-22 op }
246 0ca6718e 2021-07-22 op }
247 0ca6718e 2021-07-22 op
248 0ca6718e 2021-07-22 op static inline struct table *
249 0ca6718e 2021-07-22 op auth_table_by_id(uint32_t id)
250 0ca6718e 2021-07-22 op {
251 0ca6718e 2021-07-22 op struct kd_listen_conf *listen;
252 0ca6718e 2021-07-22 op
253 c25feded 2021-07-26 op STAILQ_FOREACH(listen, &main_conf->listen_head, entry) {
254 0ca6718e 2021-07-22 op if (listen->id == id)
255 0ca6718e 2021-07-22 op return listen->auth_table;
256 8d1b399b 2021-07-22 op }
257 0ca6718e 2021-07-22 op
258 0ca6718e 2021-07-22 op return NULL;
259 8d1b399b 2021-07-22 op }
260 8d1b399b 2021-07-22 op
261 c35679af 2021-12-18 op static inline struct table *
262 c35679af 2021-12-18 op virtual_table_by_id(uint32_t id)
263 c35679af 2021-12-18 op {
264 c35679af 2021-12-18 op struct kd_listen_conf *listen;
265 c35679af 2021-12-18 op
266 c35679af 2021-12-18 op STAILQ_FOREACH(listen, &main_conf->listen_head, entry) {
267 c35679af 2021-12-18 op if (listen->id == id)
268 c35679af 2021-12-18 op return listen->virtual_table;
269 c35679af 2021-12-18 op }
270 c35679af 2021-12-18 op
271 c35679af 2021-12-18 op return NULL;
272 c35679af 2021-12-18 op }
273 c35679af 2021-12-18 op
274 c35679af 2021-12-18 op static inline struct table *
275 c35679af 2021-12-18 op userdata_table_by_id(uint32_t id)
276 c35679af 2021-12-18 op {
277 c35679af 2021-12-18 op struct kd_listen_conf *listen;
278 c35679af 2021-12-18 op
279 c35679af 2021-12-18 op STAILQ_FOREACH(listen, &main_conf->listen_head, entry) {
280 c35679af 2021-12-18 op if (listen->id == id)
281 c35679af 2021-12-18 op return listen->userdata_table;
282 c35679af 2021-12-18 op }
283 c35679af 2021-12-18 op
284 c35679af 2021-12-18 op return NULL;
285 c35679af 2021-12-18 op }
286 c35679af 2021-12-18 op
287 8d1b399b 2021-07-22 op static inline void
288 8d1b399b 2021-07-22 op do_auth_tls(struct imsg *imsg)
289 8d1b399b 2021-07-22 op {
290 c35679af 2021-12-18 op char *username = NULL, *user = NULL, *home = NULL, *local_user;
291 c35679af 2021-12-18 op struct passwd *pw;
292 c35679af 2021-12-18 op struct table *auth, *virt, *userdata;
293 c35679af 2021-12-18 op struct kd_auth_req kauth;
294 c35679af 2021-12-18 op int p[2], free_home = 1;
295 8d1b399b 2021-07-22 op
296 c35679af 2021-12-18 op if (sizeof(kauth) != IMSG_DATA_SIZE(*imsg))
297 0ca6718e 2021-07-22 op fatal("wrong size for IMSG_AUTH_TLS: "
298 0ca6718e 2021-07-22 op "got %lu; want %lu", IMSG_DATA_SIZE(*imsg),
299 c35679af 2021-12-18 op sizeof(kauth));
300 c35679af 2021-12-18 op memcpy(&kauth, imsg->data, sizeof(kauth));
301 0ca6718e 2021-07-22 op
302 c35679af 2021-12-18 op if (memmem(kauth.hash, sizeof(kauth.hash), "", 1) == NULL)
303 0ca6718e 2021-07-22 op fatal("non NUL-terminated hash received");
304 0ca6718e 2021-07-22 op
305 c35679af 2021-12-18 op log_debug("tls id=%u hash=%s", kauth.listen_id, kauth.hash);
306 0ca6718e 2021-07-22 op
307 c35679af 2021-12-18 op if ((auth = auth_table_by_id(kauth.listen_id)) == NULL)
308 0ca6718e 2021-07-22 op fatal("request for invalid listener id %d", imsg->hdr.pid);
309 0ca6718e 2021-07-22 op
310 c35679af 2021-12-18 op virt = virtual_table_by_id(kauth.listen_id);
311 c35679af 2021-12-18 op userdata = userdata_table_by_id(kauth.listen_id);
312 8d1b399b 2021-07-22 op
313 c35679af 2021-12-18 op if (table_lookup(auth, kauth.hash, &username) == -1) {
314 c35679af 2021-12-18 op log_warnx("login failed for hash %s", kauth.hash);
315 8d1b399b 2021-07-22 op goto err;
316 c35679af 2021-12-18 op }
317 c35679af 2021-12-18 op
318 c35679af 2021-12-18 op if (virt != NULL && table_lookup(virt, username, &user) == -1) {
319 c35679af 2021-12-18 op log_warnx("virtual lookup failed for user %s", username);
320 c35679af 2021-12-18 op goto err;
321 c35679af 2021-12-18 op }
322 c35679af 2021-12-18 op
323 c35679af 2021-12-18 op /* the local user */
324 c35679af 2021-12-18 op local_user = user != NULL ? user : username;
325 c35679af 2021-12-18 op
326 c35679af 2021-12-18 op if (user != NULL)
327 e2407c8e 2021-12-18 op log_debug("virtual user %s matched local user %s",
328 c35679af 2021-12-18 op username, user);
329 c35679af 2021-12-18 op else
330 c35679af 2021-12-18 op log_debug("matched local user %s", username);
331 c35679af 2021-12-18 op
332 c35679af 2021-12-18 op if (userdata != NULL && table_lookup(userdata, username, &home)
333 c35679af 2021-12-18 op == -1) {
334 c35679af 2021-12-18 op log_warnx("userdata lookup failed for user %s", username);
335 c35679af 2021-12-18 op goto err;
336 a5b998d7 2021-12-18 op } else if (userdata == NULL) {
337 c35679af 2021-12-18 op if ((pw = getpwnam(local_user)) == NULL) {
338 c35679af 2021-12-18 op log_warnx("getpwnam(%s) failed", local_user);
339 c35679af 2021-12-18 op goto err;
340 c35679af 2021-12-18 op }
341 c35679af 2021-12-18 op
342 c35679af 2021-12-18 op free_home = 0;
343 c35679af 2021-12-18 op home = pw->pw_dir;
344 8d1b399b 2021-07-22 op }
345 8d1b399b 2021-07-22 op
346 c35679af 2021-12-18 op if (user != NULL)
347 c35679af 2021-12-18 op log_debug("matched home %s for virtual user %s",
348 c35679af 2021-12-18 op home, username);
349 c35679af 2021-12-18 op else
350 c35679af 2021-12-18 op log_debug("matched home %s for local user %s",
351 c35679af 2021-12-18 op home, username);
352 c35679af 2021-12-18 op
353 8d1b399b 2021-07-22 op if (socketpair(AF_UNIX, SOCK_STREAM|SOCK_CLOEXEC|SOCK_NONBLOCK,
354 8d1b399b 2021-07-22 op PF_UNSPEC, p) == -1)
355 8d1b399b 2021-07-22 op fatal("socketpair");
356 8d1b399b 2021-07-22 op
357 8d1b399b 2021-07-22 op start_child(PROC_CLIENTCONN, p[1], debug, verbose);
358 8d1b399b 2021-07-22 op
359 8d1b399b 2021-07-22 op main_imsg_compose_listener(IMSG_AUTH, p[0], imsg->hdr.peerid,
360 c35679af 2021-12-18 op local_user, strlen(local_user)+1);
361 8d1b399b 2021-07-22 op main_imsg_compose_listener(IMSG_AUTH_DIR, -1, imsg->hdr.peerid,
362 c35679af 2021-12-18 op home, strlen(home)+1);
363 8d1b399b 2021-07-22 op
364 0ca6718e 2021-07-22 op free(username);
365 c35679af 2021-12-18 op free(user);
366 c35679af 2021-12-18 op if (free_home)
367 c35679af 2021-12-18 op free(home);
368 8d1b399b 2021-07-22 op return;
369 8d1b399b 2021-07-22 op
370 8d1b399b 2021-07-22 op err:
371 0ca6718e 2021-07-22 op free(username);
372 c35679af 2021-12-18 op free(user);
373 c35679af 2021-12-18 op if (free_home)
374 c35679af 2021-12-18 op free(home);
375 8d1b399b 2021-07-22 op main_imsg_compose_listener(IMSG_AUTH, -1, imsg->hdr.peerid,
376 8d1b399b 2021-07-22 op NULL, 0);
377 8d1b399b 2021-07-22 op }
378 8d1b399b 2021-07-22 op
379 8d1b399b 2021-07-22 op void
380 8d1b399b 2021-07-22 op main_dispatch_listener(int fd, short event, void *d)
381 8d1b399b 2021-07-22 op {
382 8d1b399b 2021-07-22 op struct imsgev *iev = d;
383 8d1b399b 2021-07-22 op struct imsgbuf *ibuf;
384 8d1b399b 2021-07-22 op struct imsg imsg;
385 8d1b399b 2021-07-22 op ssize_t n;
386 8d1b399b 2021-07-22 op int shut = 0;
387 8d1b399b 2021-07-22 op
388 8d1b399b 2021-07-22 op ibuf = &iev->ibuf;
389 8d1b399b 2021-07-22 op
390 8d1b399b 2021-07-22 op if (event & EV_READ) {
391 8d1b399b 2021-07-22 op if ((n = imsg_read(ibuf)) == -1 && errno != EAGAIN)
392 8d1b399b 2021-07-22 op fatal("imsg_read error");
393 8d1b399b 2021-07-22 op if (n == 0) /* Connection closed. */
394 8d1b399b 2021-07-22 op shut = 1;
395 8d1b399b 2021-07-22 op }
396 8d1b399b 2021-07-22 op if (event & EV_WRITE) {
397 8d1b399b 2021-07-22 op if ((n = msgbuf_write(&ibuf->w)) == -1 && errno != EAGAIN)
398 8d1b399b 2021-07-22 op fatal("msgbuf_write");
399 8d1b399b 2021-07-22 op if (n == 0) /* Connection closed. */
400 8d1b399b 2021-07-22 op shut = 1;
401 8d1b399b 2021-07-22 op }
402 8d1b399b 2021-07-22 op
403 8d1b399b 2021-07-22 op for (;;) {
404 8d1b399b 2021-07-22 op if ((n = imsg_get(ibuf, &imsg)) == -1)
405 8d1b399b 2021-07-22 op fatal("imsg_get");
406 8d1b399b 2021-07-22 op if (n == 0) /* No more messages. */
407 8d1b399b 2021-07-22 op break;
408 8d1b399b 2021-07-22 op
409 8d1b399b 2021-07-22 op switch (imsg.hdr.type) {
410 8d1b399b 2021-07-22 op case IMSG_AUTH_TLS:
411 8d1b399b 2021-07-22 op do_auth_tls(&imsg);
412 8d1b399b 2021-07-22 op break;
413 8d1b399b 2021-07-22 op default:
414 8d1b399b 2021-07-22 op log_debug("%s: error handling imsg %d", __func__,
415 8d1b399b 2021-07-22 op imsg.hdr.type);
416 8d1b399b 2021-07-22 op break;
417 8d1b399b 2021-07-22 op }
418 8d1b399b 2021-07-22 op imsg_free(&imsg);
419 8d1b399b 2021-07-22 op }
420 8d1b399b 2021-07-22 op if (!shut)
421 8d1b399b 2021-07-22 op imsg_event_add(iev);
422 8d1b399b 2021-07-22 op else {
423 8d1b399b 2021-07-22 op /* This pipe is dead. Remove its event handler. */
424 8d1b399b 2021-07-22 op event_del(&iev->ev);
425 8d1b399b 2021-07-22 op event_loopexit(NULL);
426 8d1b399b 2021-07-22 op }
427 8d1b399b 2021-07-22 op }
428 8d1b399b 2021-07-22 op
429 8d1b399b 2021-07-22 op int
430 8d1b399b 2021-07-22 op main_reload(void)
431 8d1b399b 2021-07-22 op {
432 8d1b399b 2021-07-22 op struct kd_conf *xconf;
433 8d1b399b 2021-07-22 op
434 8d1b399b 2021-07-22 op if ((xconf = parse_config(conffile)) == NULL)
435 8d1b399b 2021-07-22 op return -1;
436 8d1b399b 2021-07-22 op
437 8d1b399b 2021-07-22 op if (main_imsg_send_config(xconf) == -1)
438 8d1b399b 2021-07-22 op return -1;
439 8d1b399b 2021-07-22 op
440 8d1b399b 2021-07-22 op merge_config(main_conf, xconf);
441 8d1b399b 2021-07-22 op
442 8d1b399b 2021-07-22 op return 0;
443 8d1b399b 2021-07-22 op }
444 8d1b399b 2021-07-22 op
445 8d1b399b 2021-07-22 op static inline int
446 8d1b399b 2021-07-22 op make_socket_for(struct kd_listen_conf *l)
447 8d1b399b 2021-07-22 op {
448 8d1b399b 2021-07-22 op struct sockaddr_in addr4;
449 8d1b399b 2021-07-22 op size_t len;
450 8d1b399b 2021-07-22 op int fd, v;
451 8d1b399b 2021-07-22 op
452 8d1b399b 2021-07-22 op memset(&addr4, 0, sizeof(addr4));
453 8d1b399b 2021-07-22 op addr4.sin_family = AF_INET;
454 8d1b399b 2021-07-22 op addr4.sin_port = htons(l->port);
455 8d1b399b 2021-07-22 op addr4.sin_addr.s_addr = INADDR_ANY;
456 8d1b399b 2021-07-22 op
457 8d1b399b 2021-07-22 op if ((fd = socket(AF_INET, SOCK_STREAM, 0)) == -1)
458 8d1b399b 2021-07-22 op fatal("socket");
459 8d1b399b 2021-07-22 op
460 8d1b399b 2021-07-22 op v = 1;
461 8d1b399b 2021-07-22 op if (setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, &v, sizeof(v)) == -1)
462 8d1b399b 2021-07-22 op fatal("setsockopt(SO_REUSEADDR)");
463 8d1b399b 2021-07-22 op
464 8d1b399b 2021-07-22 op v = 1;
465 8d1b399b 2021-07-22 op if (setsockopt(fd, SOL_SOCKET, SO_REUSEPORT, &v, sizeof(v)) == -1)
466 8d1b399b 2021-07-22 op fatal("setsockopt(SO_REUSEPORT)");
467 8d1b399b 2021-07-22 op
468 8d1b399b 2021-07-22 op len = sizeof(addr4);
469 8d1b399b 2021-07-22 op if (bind(fd, (struct sockaddr *)&addr4, len) == -1)
470 8d1b399b 2021-07-22 op fatal("bind(%s, %d)", l->iface, l->port);
471 8d1b399b 2021-07-22 op
472 8d1b399b 2021-07-22 op if (listen(fd, 16) == -1)
473 8d1b399b 2021-07-22 op fatal("l(%s, %d)", l->iface, l->port);
474 8d1b399b 2021-07-22 op
475 8d1b399b 2021-07-22 op return fd;
476 8d1b399b 2021-07-22 op }
477 8d1b399b 2021-07-22 op
478 8d1b399b 2021-07-22 op int
479 8d1b399b 2021-07-22 op main_imsg_send_config(struct kd_conf *xconf)
480 8d1b399b 2021-07-22 op {
481 8d1b399b 2021-07-22 op struct kd_pki_conf *pki;
482 8d1b399b 2021-07-22 op struct kd_listen_conf *listen;
483 8d1b399b 2021-07-22 op
484 8d1b399b 2021-07-22 op #define SEND(type, fd, data, len) do { \
485 8d1b399b 2021-07-22 op if (main_imsg_compose_listener(type, fd, 0, data, len) \
486 8d1b399b 2021-07-22 op == -1) \
487 8d1b399b 2021-07-22 op return -1; \
488 8d1b399b 2021-07-22 op } while (0)
489 8d1b399b 2021-07-22 op
490 8d1b399b 2021-07-22 op /* Send fixed part of config to children. */
491 8d1b399b 2021-07-22 op SEND(IMSG_RECONF_CONF, -1, xconf, sizeof(*xconf));
492 8d1b399b 2021-07-22 op
493 c25feded 2021-07-26 op STAILQ_FOREACH(pki, &xconf->pki_head, entry) {
494 8d1b399b 2021-07-22 op log_debug("sending pki %s", pki->name);
495 8d1b399b 2021-07-22 op SEND(IMSG_RECONF_PKI, -1, pki->name, sizeof(pki->name));
496 8d1b399b 2021-07-22 op SEND(IMSG_RECONF_PKI_CERT, -1, pki->cert, pki->certlen);
497 8d1b399b 2021-07-22 op SEND(IMSG_RECONF_PKI_KEY, -1, pki->key, pki->keylen);
498 8d1b399b 2021-07-22 op }
499 8d1b399b 2021-07-22 op
500 c25feded 2021-07-26 op STAILQ_FOREACH(listen, &xconf->listen_head, entry) {
501 8d1b399b 2021-07-22 op log_debug("sending listen on port %d", listen->port);
502 8d1b399b 2021-07-22 op SEND(IMSG_RECONF_LISTEN, make_socket_for(listen), listen,
503 8d1b399b 2021-07-22 op sizeof(*listen));
504 8d1b399b 2021-07-22 op }
505 8d1b399b 2021-07-22 op
506 8d1b399b 2021-07-22 op SEND(IMSG_RECONF_END, -1, NULL, 0);
507 8d1b399b 2021-07-22 op return 0;
508 8d1b399b 2021-07-22 op
509 8d1b399b 2021-07-22 op #undef SEND
510 8d1b399b 2021-07-22 op }
511 8d1b399b 2021-07-22 op
512 8d1b399b 2021-07-22 op void
513 8d1b399b 2021-07-22 op merge_config(struct kd_conf *conf, struct kd_conf *xconf)
514 8d1b399b 2021-07-22 op {
515 8d1b399b 2021-07-22 op /* do stuff... */
516 8d1b399b 2021-07-22 op
517 8d1b399b 2021-07-22 op free(xconf);
518 8d1b399b 2021-07-22 op }
519 8d1b399b 2021-07-22 op
520 8d1b399b 2021-07-22 op struct kd_conf *
521 8d1b399b 2021-07-22 op config_new_empty(void)
522 8d1b399b 2021-07-22 op {
523 8d1b399b 2021-07-22 op struct kd_conf *xconf;
524 8d1b399b 2021-07-22 op
525 8d1b399b 2021-07-22 op if ((xconf = calloc(1, sizeof(*xconf))) == NULL)
526 8d1b399b 2021-07-22 op fatal(NULL);
527 8d1b399b 2021-07-22 op
528 8d1b399b 2021-07-22 op /* set default values */
529 8d1b399b 2021-07-22 op
530 8d1b399b 2021-07-22 op return xconf;
531 8d1b399b 2021-07-22 op }
532 8d1b399b 2021-07-22 op
533 8d1b399b 2021-07-22 op void
534 8d1b399b 2021-07-22 op config_clear(struct kd_conf *conf)
535 8d1b399b 2021-07-22 op {
536 8d1b399b 2021-07-22 op struct kd_conf *xconf;
537 8d1b399b 2021-07-22 op
538 8d1b399b 2021-07-22 op /* Merge current config with an empty one. */
539 8d1b399b 2021-07-22 op xconf = config_new_empty();
540 8d1b399b 2021-07-22 op merge_config(conf, xconf);
541 8d1b399b 2021-07-22 op
542 8d1b399b 2021-07-22 op free(conf);
543 8d1b399b 2021-07-22 op }
544 8d1b399b 2021-07-22 op
545 a97ec9eb 2021-12-23 op __dead void
546 8d1b399b 2021-07-22 op main_shutdown(void)
547 8d1b399b 2021-07-22 op {
548 8d1b399b 2021-07-22 op pid_t pid;
549 8d1b399b 2021-07-22 op int status;
550 8d1b399b 2021-07-22 op
551 8d1b399b 2021-07-22 op /* close pipes. */
552 8d1b399b 2021-07-22 op config_clear(main_conf);
553 8d1b399b 2021-07-22 op
554 8d1b399b 2021-07-22 op log_debug("waiting for children to terminate");
555 8d1b399b 2021-07-22 op do {
556 8d1b399b 2021-07-22 op pid = wait(&status);
557 8d1b399b 2021-07-22 op if (pid == -1) {
558 8d1b399b 2021-07-22 op if (errno != EINTR && errno != ECHILD)
559 8d1b399b 2021-07-22 op fatal("wait");
560 8d1b399b 2021-07-22 op } else if (WIFSIGNALED(status))
561 8d1b399b 2021-07-22 op log_warnx("%s terminated; signal %d",
562 8d1b399b 2021-07-22 op (pid == listener_pid) ? "logger" : "clientconn",
563 8d1b399b 2021-07-22 op WTERMSIG(status));
564 8d1b399b 2021-07-22 op } while (pid != -1 || (pid == -1 && errno == EINTR));
565 8d1b399b 2021-07-22 op
566 8d1b399b 2021-07-22 op free(iev_listener);
567 8d1b399b 2021-07-22 op
568 8d1b399b 2021-07-22 op log_info("terminating");
569 8d1b399b 2021-07-22 op exit(0);
570 8d1b399b 2021-07-22 op }
571 8d1b399b 2021-07-22 op
572 8d1b399b 2021-07-22 op static pid_t
573 8d1b399b 2021-07-22 op start_child(enum kd_process p, int fd, int debug, int verbose)
574 8d1b399b 2021-07-22 op {
575 8d1b399b 2021-07-22 op const char *argv[5];
576 8d1b399b 2021-07-22 op int argc = 0;
577 8d1b399b 2021-07-22 op pid_t pid;
578 8d1b399b 2021-07-22 op
579 8d1b399b 2021-07-22 op switch (pid = fork()) {
580 8d1b399b 2021-07-22 op case -1:
581 8d1b399b 2021-07-22 op fatal("cannot fork");
582 8d1b399b 2021-07-22 op case 0:
583 8d1b399b 2021-07-22 op break;
584 8d1b399b 2021-07-22 op default:
585 8d1b399b 2021-07-22 op close(fd);
586 8d1b399b 2021-07-22 op return pid;
587 8d1b399b 2021-07-22 op }
588 8d1b399b 2021-07-22 op
589 8d1b399b 2021-07-22 op if (fd != 3) {
590 8d1b399b 2021-07-22 op if (dup2(fd, 3) == -1)
591 8d1b399b 2021-07-22 op fatal("cannot setup imsg fd");
592 8d1b399b 2021-07-22 op } else if (fcntl(F_SETFD, 0) == -1)
593 8d1b399b 2021-07-22 op fatal("cannot setup imsg fd");
594 8d1b399b 2021-07-22 op
595 8d1b399b 2021-07-22 op argv[argc++] = saved_argv0;
596 8d1b399b 2021-07-22 op switch (p) {
597 8d1b399b 2021-07-22 op case PROC_MAIN:
598 8d1b399b 2021-07-22 op fatalx("Can not start main process");
599 8d1b399b 2021-07-22 op case PROC_LISTENER:
600 8d1b399b 2021-07-22 op argv[argc++] = "-Tl";
601 8d1b399b 2021-07-22 op break;
602 8d1b399b 2021-07-22 op case PROC_CLIENTCONN:
603 8d1b399b 2021-07-22 op argv[argc++] = "-Tc";
604 8d1b399b 2021-07-22 op break;
605 8d1b399b 2021-07-22 op }
606 8d1b399b 2021-07-22 op if (debug)
607 8d1b399b 2021-07-22 op argv[argc++] = "-d";
608 8d1b399b 2021-07-22 op if (verbose)
609 8d1b399b 2021-07-22 op argv[argc++] = "-v";
610 8d1b399b 2021-07-22 op argv[argc++] = NULL;
611 8d1b399b 2021-07-22 op
612 8d1b399b 2021-07-22 op /* really? */
613 8d1b399b 2021-07-22 op execvp(saved_argv0, (char *const *)argv);
614 8d1b399b 2021-07-22 op fatal("execvp");
615 8d1b399b 2021-07-22 op }
616 8d1b399b 2021-07-22 op
617 8d1b399b 2021-07-22 op int
618 8d1b399b 2021-07-22 op main_imsg_compose_listener(int type, int fd, uint32_t peerid,
619 8d1b399b 2021-07-22 op const void *data, uint16_t datalen)
620 8d1b399b 2021-07-22 op {
621 8d1b399b 2021-07-22 op if (iev_listener)
622 8d1b399b 2021-07-22 op return imsg_compose_event(iev_listener, type, peerid, 0,
623 8d1b399b 2021-07-22 op fd, data, datalen);
624 8d1b399b 2021-07-22 op else
625 8d1b399b 2021-07-22 op return -1;
626 8d1b399b 2021-07-22 op }