1 /* Copyright (C) 1997-2023 Free Software Foundation, Inc.
2 This file is part of the GNU C Library.
4 The GNU C Library is free software; you can redistribute it and/or
5 modify it under the terms of the GNU Lesser General Public
6 License as published by the Free Software Foundation; either
7 version 2.1 of the License, or (at your option) any later version.
9 The GNU C Library is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12 Lesser General Public License for more details.
14 You should have received a copy of the GNU Lesser General Public
15 License along with the GNU C Library; if not, see
16 <https://www.gnu.org/licenses/>. */
24 #include <rpcsvc/nis.h>
25 #include <sys/socket.h>
28 #include <netinet/in.h>
29 #include <arpa/inet.h>
30 #include <libc-lock.h>
33 #include "nis_intern.h"
35 #include <shlib-compat.h>
37 static const struct timeval RPCTIMEOUT
= {10, 0};
38 static const struct timeval UDPTIMEOUT
= {5, 0};
40 extern u_short
__pmap_getnisport (struct sockaddr_in
*address
, u_long program
,
41 u_long version
, u_int protocol
);
44 inetstr2int (const char *str
)
47 for (size_t i
= 0; str
[i
] != '\0'; ++i
)
48 if (str
[i
] == '.' && __builtin_expect (++j
== 4, 0))
52 return inet_addr (memcpy (buffer
, str
, i
));
55 return inet_addr (str
);
59 __nisbind_destroy (dir_binding
*bind
)
61 if (bind
->clnt
!= NULL
)
64 auth_destroy (bind
->clnt
->cl_auth
);
65 clnt_destroy (bind
->clnt
);
68 libnsl_hidden_nolink_def (__nisbind_destroy
, GLIBC_2_1
)
71 __nisbind_next (dir_binding
*bind
)
73 if (bind
->clnt
!= NULL
)
76 auth_destroy (bind
->clnt
->cl_auth
);
77 clnt_destroy (bind
->clnt
);
81 if (bind
->trys
>= bind
->server_len
)
84 for (u_int j
= bind
->current_ep
+ 1;
85 j
< bind
->server_val
[bind
->server_used
].ep
.ep_len
; ++j
)
86 if (strcmp (bind
->server_val
[bind
->server_used
].ep
.ep_val
[j
].family
,
88 if (bind
->server_val
[bind
->server_used
].ep
.ep_val
[j
].proto
[0] == '-')
96 if (bind
->server_used
>= bind
->server_len
)
97 bind
->server_used
= 0;
99 for (u_int j
= 0; j
< bind
->server_val
[bind
->server_used
].ep
.ep_len
; ++j
)
100 if (strcmp (bind
->server_val
[bind
->server_used
].ep
.ep_val
[j
].family
,
102 if (bind
->server_val
[bind
->server_used
].ep
.ep_val
[j
].proto
[0] == '-')
104 bind
->current_ep
= j
;
110 libnsl_hidden_nolink_def (__nisbind_next
, GLIBC_2_1
)
112 static struct ckey_cache_entry
114 struct in_addr inaddr
;
116 unsigned int protocol
;
119 static size_t ckey_cache_size
;
120 static size_t ckey_cache_allocated
;
121 static pid_t ckey_cache_pid
;
122 static uid_t ckey_cache_euid
;
123 __libc_lock_define_initialized (static, ckey_cache_lock
)
126 get_ckey (des_block
*ckey
, struct sockaddr_in
*addr
, unsigned int protocol
)
129 pid_t pid
= getpid ();
130 uid_t euid
= geteuid ();
133 __libc_lock_lock (ckey_cache_lock
);
135 if (ckey_cache_pid
!= pid
|| ckey_cache_euid
!= euid
)
138 ckey_cache_pid
= pid
;
139 ckey_cache_euid
= euid
;
142 for (i
= 0; i
< ckey_cache_size
; ++i
)
143 if (ckey_cache
[i
].port
== addr
->sin_port
144 && ckey_cache
[i
].protocol
== protocol
145 && memcmp (&ckey_cache
[i
].inaddr
, &addr
->sin_addr
,
146 sizeof (addr
->sin_addr
)) == 0)
148 *ckey
= ckey_cache
[i
].ckey
;
153 if (!ret
&& key_gendes (ckey
) >= 0)
156 /* Don't grow the cache indefinitely. */
157 if (ckey_cache_size
== 256)
159 if (ckey_cache_size
== ckey_cache_allocated
)
161 size_t size
= ckey_cache_allocated
? ckey_cache_allocated
* 2 : 16;
162 struct ckey_cache_entry
*new_cache
163 = realloc (ckey_cache
, size
* sizeof (*ckey_cache
));
164 if (new_cache
!= NULL
)
166 ckey_cache
= new_cache
;
167 ckey_cache_allocated
= size
;
170 ckey_cache
[ckey_cache_size
].inaddr
= addr
->sin_addr
;
171 ckey_cache
[ckey_cache_size
].port
= addr
->sin_port
;
172 ckey_cache
[ckey_cache_size
].protocol
= protocol
;
173 ckey_cache
[ckey_cache_size
++].ckey
= *ckey
;
176 __libc_lock_unlock (ckey_cache_lock
);
181 __nisbind_connect (dir_binding
*dbp
)
189 serv
= &dbp
->server_val
[dbp
->server_used
];
191 memset (&dbp
->addr
, '\0', sizeof (dbp
->addr
));
192 dbp
->addr
.sin_family
= AF_INET
;
194 dbp
->addr
.sin_addr
.s_addr
=
195 inetstr2int (serv
->ep
.ep_val
[dbp
->current_ep
].uaddr
);
197 if (dbp
->addr
.sin_addr
.s_addr
== INADDR_NONE
)
200 /* Check, if the host is online and rpc.nisd is running. Much faster
201 then the clnt*_create functions: */
202 port
= __pmap_getnisport (&dbp
->addr
, NIS_PROG
, NIS_VERSION
,
203 dbp
->use_udp
? IPPROTO_UDP
: IPPROTO_TCP
);
207 dbp
->addr
.sin_port
= htons (port
);
208 dbp
->socket
= RPC_ANYSOCK
;
210 dbp
->clnt
= clntudp_create (&dbp
->addr
, NIS_PROG
, NIS_VERSION
,
211 UDPTIMEOUT
, &dbp
->socket
);
213 dbp
->clnt
= clnttcp_create (&dbp
->addr
, NIS_PROG
, NIS_VERSION
,
216 if (dbp
->clnt
== NULL
)
219 clnt_control (dbp
->clnt
, CLSET_TIMEOUT
, (caddr_t
) &RPCTIMEOUT
);
220 /* If the program exists, close the socket */
221 if (fcntl (dbp
->socket
, F_SETFD
, 1) == -1)
222 perror ("fcntl: F_SETFD");
226 if (serv
->key_type
== NIS_PK_DH
)
228 char netname
[MAXNETNAMELEN
+ 1];
232 p
= stpcpy (netname
, "unix@");
233 strncpy (p
, serv
->name
, MAXNETNAMELEN
- 5);
234 netname
[MAXNETNAMELEN
] = '\0';
235 dbp
->clnt
->cl_auth
= NULL
;
236 if (get_ckey (&ckey
, &dbp
->addr
,
237 dbp
->use_udp
? IPPROTO_UDP
: IPPROTO_TCP
))
239 authdes_pk_create (netname
, &serv
->pkey
, 300, NULL
, &ckey
);
240 if (!dbp
->clnt
->cl_auth
)
241 dbp
->clnt
->cl_auth
= authunix_create_default ();
244 dbp
->clnt
->cl_auth
= authunix_create_default ();
249 libnsl_hidden_nolink_def (__nisbind_connect
, GLIBC_2_1
)
252 __nisbind_create (dir_binding
*dbp
, const nis_server
*serv_val
,
253 unsigned int serv_len
, unsigned int server_used
,
254 unsigned int current_ep
, unsigned int flags
)
258 dbp
->server_len
= serv_len
;
259 dbp
->server_val
= (nis_server
*)serv_val
;
261 if (flags
& USE_DGRAM
)
264 dbp
->use_udp
= FALSE
;
266 if (flags
& NO_AUTHINFO
)
267 dbp
->use_auth
= FALSE
;
269 dbp
->use_auth
= TRUE
;
271 if (flags
& MASTER_ONLY
)
272 dbp
->master_only
= TRUE
;
274 dbp
->master_only
= FALSE
;
276 /* We try the first server */
280 if (server_used
== ~0)
282 if (__nis_findfastest (dbp
) < 1)
283 return NIS_NAMEUNREACHABLE
;
287 dbp
->server_used
= server_used
;
288 dbp
->current_ep
= current_ep
;
293 libnsl_hidden_nolink_def (__nisbind_create
, GLIBC_2_1
)
295 /* __nisbind_connect (dbp) must be run before calling this function !
296 So we could use the same binding twice */
298 __do_niscall3 (dir_binding
*dbp
, u_long prog
, xdrproc_t xargs
, caddr_t req
,
299 xdrproc_t xres
, caddr_t resp
, unsigned int flags
, nis_cb
*cb
)
301 enum clnt_stat result
;
305 return NIS_NAMEUNREACHABLE
;
310 result
= clnt_call (dbp
->clnt
, prog
, xargs
, req
, xres
, resp
, RPCTIMEOUT
);
312 if (result
!= RPC_SUCCESS
)
313 retcode
= NIS_RPCERROR
;
319 if ((((nis_result
*)resp
)->status
== NIS_CBRESULTS
)
322 __nis_do_callback (dbp
, &((nis_result
*) resp
)->cookie
, cb
);
325 /* Yes, the missing break is correct. If we doesn't have to
326 start a callback, look if we have to search another server */
337 if (((nis_result
*)resp
)->status
== NIS_SYSTEMERROR
338 || ((nis_result
*)resp
)->status
== NIS_NOSUCHNAME
339 || ((nis_result
*)resp
)->status
== NIS_NOT_ME
)
342 if (__nisbind_next (dbp
) == NIS_SUCCESS
)
344 while (__nisbind_connect (dbp
) != NIS_SUCCESS
)
346 if (__nisbind_next (dbp
) != NIS_SUCCESS
)
351 break; /* No more servers to search in */
355 case NIS_FINDDIRECTORY
:
356 if (((fd_result
*)resp
)->status
== NIS_SYSTEMERROR
357 || ((fd_result
*)resp
)->status
== NIS_NOSUCHNAME
358 || ((fd_result
*)resp
)->status
== NIS_NOT_ME
)
361 case NIS_DUMPLOG
: /* log_result */
363 if (((log_result
*)resp
)->lr_status
== NIS_SYSTEMERROR
364 || ((log_result
*)resp
)->lr_status
== NIS_NOSUCHNAME
365 || ((log_result
*)resp
)->lr_status
== NIS_NOT_ME
)
371 retcode
= NIS_SUCCESS
;
374 while ((flags
& HARD_LOOKUP
) && retcode
== NIS_RPCERROR
);
378 libnsl_hidden_nolink_def (__do_niscall3
, GLIBC_PRIVATE
)
382 __do_niscall2 (const nis_server
*server
, u_int server_len
, u_long prog
,
383 xdrproc_t xargs
, caddr_t req
, xdrproc_t xres
, caddr_t resp
,
384 unsigned int flags
, nis_cb
*cb
)
389 if (flags
& MASTER_ONLY
)
392 status
= __nisbind_create (&dbp
, server
, server_len
, ~0, ~0, flags
);
393 if (status
!= NIS_SUCCESS
)
396 while (__nisbind_connect (&dbp
) != NIS_SUCCESS
)
397 if (__nisbind_next (&dbp
) != NIS_SUCCESS
)
398 return NIS_NAMEUNREACHABLE
;
400 status
= __do_niscall3 (&dbp
, prog
, xargs
, req
, xres
, resp
, flags
, cb
);
402 __nisbind_destroy (&dbp
);
408 static directory_obj
*
409 rec_dirsearch (const_nis_name name
, directory_obj
*dir
, nis_error
*status
)
414 switch (nis_dir_cmp (name
, dir
->do_name
))
417 *status
= NIS_SUCCESS
;
420 /* NOT_SEQUENTIAL means, go one up and try it there ! */
422 { /* We need data from a parent domain */
424 const char *ndomain
= __nis_domain_of (dir
->do_name
);
426 /* The root server of our domain is a replica of the parent
427 domain ! (Now I understand why a root server must be a
428 replica of the parent domain) */
429 fd_res
= __nis_finddirectory (dir
, ndomain
);
432 nis_free_directory (dir
);
433 *status
= NIS_NOMEMORY
;
436 *status
= fd_res
->status
;
437 if (fd_res
->status
!= NIS_SUCCESS
)
439 /* Try the current directory obj, maybe it works */
440 __free_fdresult (fd_res
);
443 nis_free_directory (dir
);
444 obj
= calloc (1, sizeof (directory_obj
));
447 __free_fdresult (fd_res
);
448 *status
= NIS_NOMEMORY
;
451 xdrmem_create (&xdrs
, fd_res
->dir_data
.dir_data_val
,
452 fd_res
->dir_data
.dir_data_len
, XDR_DECODE
);
453 _xdr_directory_obj (&xdrs
, obj
);
455 __free_fdresult (fd_res
);
457 /* We have found a NIS+ server serving ndomain, now
458 let us search for "name" */
459 return rec_dirsearch (name
, obj
, status
);
465 size_t namelen
= strlen (name
);
466 char leaf
[namelen
+ 3];
467 char domain
[namelen
+ 3];
471 strcpy (domain
, name
);
475 if (domain
[0] == '\0')
477 nis_free_directory (dir
);
480 nis_leaf_of_r (domain
, leaf
, sizeof (leaf
));
481 ndomain
= __nis_domain_of (domain
);
482 memmove (domain
, ndomain
, strlen (ndomain
) + 1);
484 while (nis_dir_cmp (domain
, dir
->do_name
) != SAME_NAME
);
486 cp
= strchr (leaf
, '\0');
490 fd_res
= __nis_finddirectory (dir
, leaf
);
493 nis_free_directory (dir
);
494 *status
= NIS_NOMEMORY
;
497 *status
= fd_res
->status
;
498 if (fd_res
->status
!= NIS_SUCCESS
)
500 /* Try the current directory object, maybe it works */
501 __free_fdresult (fd_res
);
504 nis_free_directory (dir
);
505 obj
= calloc (1, sizeof (directory_obj
));
508 __free_fdresult (fd_res
);
509 *status
= NIS_NOMEMORY
;
512 xdrmem_create (&xdrs
, fd_res
->dir_data
.dir_data_val
,
513 fd_res
->dir_data
.dir_data_len
, XDR_DECODE
);
514 _xdr_directory_obj (&xdrs
, obj
);
516 __free_fdresult (fd_res
);
517 /* We have found a NIS+ server serving ndomain, now
518 let us search for "name" */
519 return rec_dirsearch (name
, obj
, status
);
523 nis_free_directory (dir
);
524 *status
= NIS_BADNAME
;
527 nis_free_directory (dir
);
532 /* We try to query the current server for the searched object,
533 maybe he know about it ? */
534 static directory_obj
*
535 first_shoot (const_nis_name name
, directory_obj
*dir
)
537 directory_obj
*obj
= NULL
;
541 if (nis_dir_cmp (name
, dir
->do_name
) == SAME_NAME
)
544 fd_res
= __nis_finddirectory (dir
, name
);
547 if (fd_res
->status
== NIS_SUCCESS
548 && (obj
= calloc (1, sizeof (directory_obj
))) != NULL
)
550 xdrmem_create (&xdrs
, fd_res
->dir_data
.dir_data_val
,
551 fd_res
->dir_data
.dir_data_len
, XDR_DECODE
);
552 _xdr_directory_obj (&xdrs
, obj
);
555 if (strcmp (dir
->do_name
, obj
->do_name
) != 0)
557 nis_free_directory (obj
);
562 __free_fdresult (fd_res
);
565 nis_free_directory (dir
);
570 static struct nis_server_cache
575 unsigned int server_used
;
576 unsigned int current_ep
;
579 } *nis_server_cache
[16];
580 static time_t nis_cold_start_mtime
;
581 __libc_lock_define_initialized (static, nis_server_cache_lock
)
583 static directory_obj
*
584 nis_server_cache_search (const_nis_name name
, int search_parent
,
585 unsigned int *server_used
, unsigned int *current_ep
,
586 struct timespec
*now
)
588 directory_obj
*ret
= NULL
;
594 int saved_errno
= errno
;
595 if (stat64 ("/var/nis/NIS_COLD_START", &st
) < 0)
596 st
.st_mtime
= nis_cold_start_mtime
+ 1;
597 __set_errno (saved_errno
);
599 __libc_lock_lock (nis_server_cache_lock
);
601 for (i
= 0; i
< 16; ++i
)
602 if (nis_server_cache
[i
] == NULL
)
604 else if (st
.st_mtime
!= nis_cold_start_mtime
605 || now
->tv_sec
> nis_server_cache
[i
]->expires
)
607 free (nis_server_cache
[i
]);
608 nis_server_cache
[i
] = NULL
;
610 else if (nis_server_cache
[i
]->search_parent
== search_parent
611 && strcmp (nis_server_cache
[i
]->name
, name
) == 0)
613 ret
= calloc (1, sizeof (directory_obj
));
617 addr
= strchr (nis_server_cache
[i
]->name
, '\0') + 8;
618 addr
= (char *) ((uintptr_t) addr
& ~(uintptr_t) 7);
619 xdrmem_create (&xdrs
, addr
, nis_server_cache
[i
]->size
, XDR_DECODE
);
620 if (!_xdr_directory_obj (&xdrs
, ret
))
625 free (nis_server_cache
[i
]);
626 nis_server_cache
[i
] = NULL
;
630 *server_used
= nis_server_cache
[i
]->server_used
;
631 *current_ep
= nis_server_cache
[i
]->current_ep
;
635 nis_cold_start_mtime
= st
.st_mtime
;
637 __libc_lock_unlock (nis_server_cache_lock
);
642 nis_server_cache_add (const_nis_name name
, int search_parent
,
643 directory_obj
*dir
, unsigned int server_used
,
644 unsigned int current_ep
, struct timespec
*now
)
646 struct nis_server_cache
**loc
;
647 struct nis_server_cache
*new;
648 struct nis_server_cache
*old
;
657 size
= xdr_sizeof ((xdrproc_t
) _xdr_directory_obj
, (char *) dir
);
658 new = calloc (1, sizeof (*new) + strlen (name
) + 8 + size
);
661 new->search_parent
= search_parent
;
663 new->expires
= now
->tv_sec
+ dir
->do_ttl
;
665 new->server_used
= server_used
;
666 new->current_ep
= current_ep
;
667 addr
= stpcpy (new->name
, name
) + 8;
668 addr
= (char *) ((uintptr_t) addr
& ~(uintptr_t) 7);
670 xdrmem_create(&xdrs
, addr
, size
, XDR_ENCODE
);
671 if (!_xdr_directory_obj (&xdrs
, dir
))
679 __libc_lock_lock (nis_server_cache_lock
);
681 /* Choose which entry should be evicted from the cache. */
682 loc
= &nis_server_cache
[0];
685 for (i
= 1; i
< 16; ++i
)
686 if (nis_server_cache
[i
] == NULL
)
688 loc
= &nis_server_cache
[i
];
691 else if ((*loc
)->uses
> nis_server_cache
[i
]->uses
692 || ((*loc
)->uses
== nis_server_cache
[i
]->uses
693 && (*loc
)->expires
> nis_server_cache
[i
]->expires
))
694 loc
= &nis_server_cache
[i
];
699 __libc_lock_unlock (nis_server_cache_lock
);
704 __nisfind_server (const_nis_name name
, int search_parent
,
705 directory_obj
**dir
, dir_binding
*dbp
, unsigned int flags
)
707 nis_error result
= NIS_SUCCESS
;
711 unsigned int server_used
= ~0;
712 unsigned int current_ep
= ~0;
720 clock_gettime (CLOCK_REALTIME
, &ts
);
722 if ((flags
& NO_CACHE
) == 0)
723 *dir
= nis_server_cache_search (name
, search_parent
, &server_used
,
727 unsigned int server_len
= (*dir
)->do_servers
.do_servers_len
;
728 if (flags
& MASTER_ONLY
)
731 if (server_used
!= 0)
737 result
= __nisbind_create (dbp
, (*dir
)->do_servers
.do_servers_val
,
738 server_len
, server_used
, current_ep
, flags
);
739 if (result
!= NIS_SUCCESS
)
741 nis_free_directory (*dir
);
747 int saved_errno
= errno
;
748 *dir
= readColdStartFile ();
749 __set_errno (saved_errno
);
751 /* No /var/nis/NIS_COLD_START->no NIS+ installed. */
754 /* Try at first, if servers in "dir" know our object */
755 const char *search_name
= name
;
757 search_name
= __nis_domain_of (name
);
758 obj
= first_shoot (search_name
, *dir
);
761 obj
= rec_dirsearch (search_name
, *dir
, &status
);
766 if (result
== NIS_SUCCESS
)
768 unsigned int server_len
= obj
->do_servers
.do_servers_len
;
769 if (flags
& MASTER_ONLY
)
771 result
= __nisbind_create (dbp
, obj
->do_servers
.do_servers_val
,
772 server_len
, ~0, ~0, flags
);
773 if (result
== NIS_SUCCESS
)
775 if ((flags
& MASTER_ONLY
) == 0
776 || obj
->do_servers
.do_servers_len
== 1)
778 server_used
= dbp
->server_used
;
779 current_ep
= dbp
->current_ep
;
781 if ((flags
& NO_CACHE
) == 0)
782 nis_server_cache_add (name
, search_parent
, obj
,
783 server_used
, current_ep
, &ts
);
787 nis_free_directory (obj
);
799 __prepare_niscall (const_nis_name name
, directory_obj
**dirp
,
800 dir_binding
*bptrp
, unsigned int flags
)
802 nis_error retcode
= __nisfind_server (name
, 1, dirp
, bptrp
, flags
);
803 if (__glibc_unlikely (retcode
!= NIS_SUCCESS
))
807 if (__nisbind_connect (bptrp
) == NIS_SUCCESS
)
809 while (__nisbind_next (bptrp
) == NIS_SUCCESS
);
811 __nisbind_destroy (bptrp
);
812 memset (bptrp
, '\0', sizeof (*bptrp
));
814 retcode
= NIS_NAMEUNREACHABLE
;
815 nis_free_directory (*dirp
);
820 libnsl_hidden_nolink_def (__prepare_niscall
, GLIBC_PRIVATE
)
824 __do_niscall (const_nis_name name
, u_long prog
, xdrproc_t xargs
,
825 caddr_t req
, xdrproc_t xres
, caddr_t resp
, unsigned int flags
,
829 directory_obj
*dir
= NULL
;
830 int saved_errno
= errno
;
832 nis_error retcode
= __prepare_niscall (name
, &dir
, &bptr
, flags
);
833 if (retcode
== NIS_SUCCESS
)
835 retcode
= __do_niscall3 (&bptr
, prog
, xargs
, req
, xres
, resp
, flags
, cb
);
837 __nisbind_destroy (&bptr
);
839 nis_free_directory (dir
);
842 __set_errno (saved_errno
);