xref: /titanic_54/usr/src/cmd/ldapcachemgr/cachemgr.c (revision 7ddae043d774fb34a5d9f3b11a0e7bcaba3e85ae)
17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate  * CDDL HEADER START
37c478bd9Sstevel@tonic-gate  *
47c478bd9Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
5cb5caa98Sdjl  * Common Development and Distribution License (the "License").
6cb5caa98Sdjl  * You may not use this file except in compliance with the License.
77c478bd9Sstevel@tonic-gate  *
87c478bd9Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
97c478bd9Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
107c478bd9Sstevel@tonic-gate  * See the License for the specific language governing permissions
117c478bd9Sstevel@tonic-gate  * and limitations under the License.
127c478bd9Sstevel@tonic-gate  *
137c478bd9Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
147c478bd9Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
157c478bd9Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
167c478bd9Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
177c478bd9Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
187c478bd9Sstevel@tonic-gate  *
197c478bd9Sstevel@tonic-gate  * CDDL HEADER END
207c478bd9Sstevel@tonic-gate  */
217c478bd9Sstevel@tonic-gate /*
22*7ddae043Siz202018  * Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
237c478bd9Sstevel@tonic-gate  * Use is subject to license terms.
247c478bd9Sstevel@tonic-gate  */
257c478bd9Sstevel@tonic-gate 
267c478bd9Sstevel@tonic-gate #pragma ident	"%Z%%M%	%I%	%E% SMI"
277c478bd9Sstevel@tonic-gate 
287c478bd9Sstevel@tonic-gate /*
297c478bd9Sstevel@tonic-gate  * Simple doors ldap cache daemon
307c478bd9Sstevel@tonic-gate  */
317c478bd9Sstevel@tonic-gate 
327c478bd9Sstevel@tonic-gate #include <stdio.h>
337c478bd9Sstevel@tonic-gate #include <stdlib.h>
347c478bd9Sstevel@tonic-gate #include <signal.h>
357c478bd9Sstevel@tonic-gate #include <door.h>
367c478bd9Sstevel@tonic-gate #include <time.h>
377c478bd9Sstevel@tonic-gate #include <string.h>
38*7ddae043Siz202018 #include <strings.h>
397c478bd9Sstevel@tonic-gate #include <libintl.h>
407c478bd9Sstevel@tonic-gate #include <sys/stat.h>
417c478bd9Sstevel@tonic-gate #include <sys/time.h>
427c478bd9Sstevel@tonic-gate #include <sys/wait.h>
437c478bd9Sstevel@tonic-gate #include <stdlib.h>
447c478bd9Sstevel@tonic-gate #include <errno.h>
457c478bd9Sstevel@tonic-gate #include <pthread.h>
467c478bd9Sstevel@tonic-gate #include <thread.h>
477c478bd9Sstevel@tonic-gate #include <stdarg.h>
487c478bd9Sstevel@tonic-gate #include <fcntl.h>
497c478bd9Sstevel@tonic-gate #include <assert.h>
507c478bd9Sstevel@tonic-gate #include <unistd.h>
517c478bd9Sstevel@tonic-gate #include <memory.h>
527c478bd9Sstevel@tonic-gate #include <sys/types.h>
537c478bd9Sstevel@tonic-gate #include <syslog.h>
547c478bd9Sstevel@tonic-gate #include <locale.h>	/* LC_ALL */
55*7ddae043Siz202018 
56*7ddae043Siz202018 #include <alloca.h>
57*7ddae043Siz202018 #include <ucontext.h>
58*7ddae043Siz202018 
597c478bd9Sstevel@tonic-gate #include "cachemgr.h"
607c478bd9Sstevel@tonic-gate 
617c478bd9Sstevel@tonic-gate static void	detachfromtty();
627c478bd9Sstevel@tonic-gate admin_t		current_admin;
637c478bd9Sstevel@tonic-gate static int	will_become_server;
647c478bd9Sstevel@tonic-gate 
657c478bd9Sstevel@tonic-gate static void switcher(void *cookie, char *argp, size_t arg_size,
667c478bd9Sstevel@tonic-gate 			door_desc_t *dp, uint_t n_desc);
677c478bd9Sstevel@tonic-gate static void usage(char *s);
687c478bd9Sstevel@tonic-gate static int cachemgr_set_lf(admin_t *ptr, char *logfile);
697c478bd9Sstevel@tonic-gate static int client_getadmin(admin_t *ptr);
70*7ddae043Siz202018 static int setadmin(ldap_call_t *ptr);
717c478bd9Sstevel@tonic-gate static  int client_setadmin(admin_t *ptr);
727c478bd9Sstevel@tonic-gate static int client_showstats(admin_t *ptr);
737c478bd9Sstevel@tonic-gate 
747c478bd9Sstevel@tonic-gate #ifdef SLP
757c478bd9Sstevel@tonic-gate int			use_slp = 0;
767c478bd9Sstevel@tonic-gate static unsigned int	refresh = 10800;	/* dynamic discovery interval */
777c478bd9Sstevel@tonic-gate #endif /* SLP */
787c478bd9Sstevel@tonic-gate 
797c478bd9Sstevel@tonic-gate static ldap_stat_t *
807c478bd9Sstevel@tonic-gate getcacheptr(char *s)
817c478bd9Sstevel@tonic-gate {
827c478bd9Sstevel@tonic-gate 	static const char *caches[1] = {"ldap"};
837c478bd9Sstevel@tonic-gate 
847c478bd9Sstevel@tonic-gate 	if (strncmp(caches[0], s, strlen(caches[0])) == 0)
857c478bd9Sstevel@tonic-gate 		return (&current_admin.ldap_stat);
867c478bd9Sstevel@tonic-gate 
877c478bd9Sstevel@tonic-gate 	return (NULL);
887c478bd9Sstevel@tonic-gate }
897c478bd9Sstevel@tonic-gate 
907c478bd9Sstevel@tonic-gate char *
917c478bd9Sstevel@tonic-gate getcacheopt(char *s)
927c478bd9Sstevel@tonic-gate {
937c478bd9Sstevel@tonic-gate 	while (*s && *s != ',')
947c478bd9Sstevel@tonic-gate 		s++;
957c478bd9Sstevel@tonic-gate 	return ((*s == ',') ? (s + 1) : NULL);
967c478bd9Sstevel@tonic-gate }
977c478bd9Sstevel@tonic-gate 
987c478bd9Sstevel@tonic-gate /*
997c478bd9Sstevel@tonic-gate  *  This is here to prevent the ldap_cachemgr becomes
1007c478bd9Sstevel@tonic-gate  *  daemonlized to early to soon during boot time.
1017c478bd9Sstevel@tonic-gate  *  This causes problems during boot when automounter
1027c478bd9Sstevel@tonic-gate  *  and others try to use libsldap before ldap_cachemgr
1037c478bd9Sstevel@tonic-gate  *  finishes walking the server list.
1047c478bd9Sstevel@tonic-gate  */
1057c478bd9Sstevel@tonic-gate static void
1067c478bd9Sstevel@tonic-gate sig_ok_to_exit(int signo)
1077c478bd9Sstevel@tonic-gate {
1087c478bd9Sstevel@tonic-gate 	if (signo == SIGUSR1) {
1097c478bd9Sstevel@tonic-gate 		logit("sig_ok_to_exit(): parent exiting...\n");
1107c478bd9Sstevel@tonic-gate 		exit(0);
1117c478bd9Sstevel@tonic-gate 	} else {
1127c478bd9Sstevel@tonic-gate 		logit("sig_ok_to_exit(): invalid signal(%d) received.\n",
1137c478bd9Sstevel@tonic-gate 		    signo);
1147c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR, gettext("ldap_cachemgr: "
1157c478bd9Sstevel@tonic-gate 		    "invalid signal(%d) received."), signo);
1167c478bd9Sstevel@tonic-gate 		exit(1);
1177c478bd9Sstevel@tonic-gate 	}
1187c478bd9Sstevel@tonic-gate }
1197c478bd9Sstevel@tonic-gate #define	LDAP_TABLES		1	/* ldap */
1207c478bd9Sstevel@tonic-gate #define	TABLE_THREADS		10
1217c478bd9Sstevel@tonic-gate #define	COMMON_THREADS		20
1227c478bd9Sstevel@tonic-gate #define	CACHE_MISS_THREADS	(COMMON_THREADS + LDAP_TABLES * TABLE_THREADS)
1237c478bd9Sstevel@tonic-gate #define	CACHE_HIT_THREADS	20
1247c478bd9Sstevel@tonic-gate #define	MAX_SERVER_THREADS	(CACHE_HIT_THREADS + CACHE_MISS_THREADS)
1257c478bd9Sstevel@tonic-gate 
1267c478bd9Sstevel@tonic-gate static sema_t common_sema;
1277c478bd9Sstevel@tonic-gate static sema_t ldap_sema;
1287c478bd9Sstevel@tonic-gate static thread_key_t lookup_state_key;
1297c478bd9Sstevel@tonic-gate 
1307c478bd9Sstevel@tonic-gate static void
1317c478bd9Sstevel@tonic-gate initialize_lookup_clearance()
1327c478bd9Sstevel@tonic-gate {
1337c478bd9Sstevel@tonic-gate 	(void) thr_keycreate(&lookup_state_key, NULL);
1347c478bd9Sstevel@tonic-gate 	(void) sema_init(&common_sema, COMMON_THREADS, USYNC_THREAD, 0);
1357c478bd9Sstevel@tonic-gate 	(void) sema_init(&ldap_sema, TABLE_THREADS, USYNC_THREAD, 0);
1367c478bd9Sstevel@tonic-gate }
1377c478bd9Sstevel@tonic-gate 
1387c478bd9Sstevel@tonic-gate int
1397c478bd9Sstevel@tonic-gate get_clearance(int callnumber)
1407c478bd9Sstevel@tonic-gate {
1417c478bd9Sstevel@tonic-gate 	sema_t	*table_sema = NULL;
1427c478bd9Sstevel@tonic-gate 	char	*tab;
1437c478bd9Sstevel@tonic-gate 
1447c478bd9Sstevel@tonic-gate 	if (sema_trywait(&common_sema) == 0) {
1457c478bd9Sstevel@tonic-gate 		(void) thr_setspecific(lookup_state_key, NULL);
1467c478bd9Sstevel@tonic-gate 		return (0);
1477c478bd9Sstevel@tonic-gate 	}
1487c478bd9Sstevel@tonic-gate 
1497c478bd9Sstevel@tonic-gate 	switch (callnumber) {
1507c478bd9Sstevel@tonic-gate 		case GETLDAPCONFIG:
1517c478bd9Sstevel@tonic-gate 			tab = "ldap";
1527c478bd9Sstevel@tonic-gate 			table_sema = &ldap_sema;
1537c478bd9Sstevel@tonic-gate 			break;
1547c478bd9Sstevel@tonic-gate 		default:
1557c478bd9Sstevel@tonic-gate 			logit("Internal Error: get_clearance\n");
1567c478bd9Sstevel@tonic-gate 			break;
1577c478bd9Sstevel@tonic-gate 	}
1587c478bd9Sstevel@tonic-gate 
1597c478bd9Sstevel@tonic-gate 	if (sema_trywait(table_sema) == 0) {
1607c478bd9Sstevel@tonic-gate 		(void) thr_setspecific(lookup_state_key, (void*)1);
1617c478bd9Sstevel@tonic-gate 		return (0);
1627c478bd9Sstevel@tonic-gate 	}
1637c478bd9Sstevel@tonic-gate 
1647c478bd9Sstevel@tonic-gate 	if (current_admin.debug_level >= DBG_CANT_FIND) {
1657c478bd9Sstevel@tonic-gate 		logit("get_clearance: throttling load for %s table\n", tab);
1667c478bd9Sstevel@tonic-gate 	}
1677c478bd9Sstevel@tonic-gate 
1687c478bd9Sstevel@tonic-gate 	return (-1);
1697c478bd9Sstevel@tonic-gate }
1707c478bd9Sstevel@tonic-gate 
1717c478bd9Sstevel@tonic-gate int
1727c478bd9Sstevel@tonic-gate release_clearance(int callnumber)
1737c478bd9Sstevel@tonic-gate {
1747c478bd9Sstevel@tonic-gate 	int	which;
1757c478bd9Sstevel@tonic-gate 	sema_t	*table_sema = NULL;
1767c478bd9Sstevel@tonic-gate 
1777c478bd9Sstevel@tonic-gate 	(void) thr_getspecific(lookup_state_key, (void**)&which);
1787c478bd9Sstevel@tonic-gate 	if (which == 0) /* from common pool */ {
1797c478bd9Sstevel@tonic-gate 		(void) sema_post(&common_sema);
1807c478bd9Sstevel@tonic-gate 		return (0);
1817c478bd9Sstevel@tonic-gate 	}
1827c478bd9Sstevel@tonic-gate 
1837c478bd9Sstevel@tonic-gate 	switch (callnumber) {
1847c478bd9Sstevel@tonic-gate 		case GETLDAPCONFIG:
1857c478bd9Sstevel@tonic-gate 			table_sema = &ldap_sema;
1867c478bd9Sstevel@tonic-gate 			break;
1877c478bd9Sstevel@tonic-gate 		default:
1887c478bd9Sstevel@tonic-gate 			logit("Internal Error: release_clearance\n");
1897c478bd9Sstevel@tonic-gate 			break;
1907c478bd9Sstevel@tonic-gate 	}
1917c478bd9Sstevel@tonic-gate 	(void) sema_post(table_sema);
1927c478bd9Sstevel@tonic-gate 
1937c478bd9Sstevel@tonic-gate 	return (0);
1947c478bd9Sstevel@tonic-gate }
1957c478bd9Sstevel@tonic-gate 
1967c478bd9Sstevel@tonic-gate 
1977c478bd9Sstevel@tonic-gate static mutex_t		create_lock;
1987c478bd9Sstevel@tonic-gate static int		num_servers = 0;
1997c478bd9Sstevel@tonic-gate static thread_key_t	server_key;
2007c478bd9Sstevel@tonic-gate 
2017c478bd9Sstevel@tonic-gate 
2027c478bd9Sstevel@tonic-gate /*
2037c478bd9Sstevel@tonic-gate  * Bind a TSD value to a server thread. This enables the destructor to
2047c478bd9Sstevel@tonic-gate  * be called if/when this thread exits.  This would be a programming error,
2057c478bd9Sstevel@tonic-gate  * but better safe than sorry.
2067c478bd9Sstevel@tonic-gate  */
2077c478bd9Sstevel@tonic-gate 
2087c478bd9Sstevel@tonic-gate /*ARGSUSED*/
2097c478bd9Sstevel@tonic-gate static void *
2107c478bd9Sstevel@tonic-gate server_tsd_bind(void *arg)
2117c478bd9Sstevel@tonic-gate {
2127c478bd9Sstevel@tonic-gate 	static void	*value = 0;
2137c478bd9Sstevel@tonic-gate 
2147c478bd9Sstevel@tonic-gate 	/*
2157c478bd9Sstevel@tonic-gate 	 * disable cancellation to prevent hangs when server
2167c478bd9Sstevel@tonic-gate 	 * threads disappear
2177c478bd9Sstevel@tonic-gate 	 */
2187c478bd9Sstevel@tonic-gate 
2197c478bd9Sstevel@tonic-gate 	(void) thr_setspecific(server_key, value);
220cb5caa98Sdjl 	(void) door_return(NULL, 0, NULL, 0);
2217c478bd9Sstevel@tonic-gate 
2227c478bd9Sstevel@tonic-gate 	return (value);
2237c478bd9Sstevel@tonic-gate }
2247c478bd9Sstevel@tonic-gate 
2257c478bd9Sstevel@tonic-gate /*
2267c478bd9Sstevel@tonic-gate  * Server threads are created here.
2277c478bd9Sstevel@tonic-gate  */
2287c478bd9Sstevel@tonic-gate 
2297c478bd9Sstevel@tonic-gate /*ARGSUSED*/
2307c478bd9Sstevel@tonic-gate static void
2317c478bd9Sstevel@tonic-gate server_create(door_info_t *dip)
2327c478bd9Sstevel@tonic-gate {
2337c478bd9Sstevel@tonic-gate 	(void) mutex_lock(&create_lock);
2347c478bd9Sstevel@tonic-gate 	if (++num_servers > MAX_SERVER_THREADS) {
2357c478bd9Sstevel@tonic-gate 		num_servers--;
2367c478bd9Sstevel@tonic-gate 		(void) mutex_unlock(&create_lock);
2377c478bd9Sstevel@tonic-gate 		return;
2387c478bd9Sstevel@tonic-gate 	}
2397c478bd9Sstevel@tonic-gate 	(void) mutex_unlock(&create_lock);
2407c478bd9Sstevel@tonic-gate 	(void) thr_create(NULL, 0, server_tsd_bind, NULL,
2417c478bd9Sstevel@tonic-gate 	    THR_BOUND|THR_DETACHED, NULL);
2427c478bd9Sstevel@tonic-gate }
2437c478bd9Sstevel@tonic-gate 
2447c478bd9Sstevel@tonic-gate /*
2457c478bd9Sstevel@tonic-gate  * Server thread are destroyed here
2467c478bd9Sstevel@tonic-gate  */
2477c478bd9Sstevel@tonic-gate 
2487c478bd9Sstevel@tonic-gate /*ARGSUSED*/
2497c478bd9Sstevel@tonic-gate static void
2507c478bd9Sstevel@tonic-gate server_destroy(void *arg)
2517c478bd9Sstevel@tonic-gate {
2527c478bd9Sstevel@tonic-gate 	(void) mutex_lock(&create_lock);
2537c478bd9Sstevel@tonic-gate 	num_servers--;
2547c478bd9Sstevel@tonic-gate 	(void) mutex_unlock(&create_lock);
2557c478bd9Sstevel@tonic-gate }
2567c478bd9Sstevel@tonic-gate 
257a506a34cSth160488 int
2587c478bd9Sstevel@tonic-gate main(int argc, char ** argv)
2597c478bd9Sstevel@tonic-gate {
2607c478bd9Sstevel@tonic-gate 	int			did;
2617c478bd9Sstevel@tonic-gate 	int			opt;
2627c478bd9Sstevel@tonic-gate 	int			errflg = 0;
2637c478bd9Sstevel@tonic-gate 	int			showstats = 0;
2647c478bd9Sstevel@tonic-gate 	int			doset = 0;
2657c478bd9Sstevel@tonic-gate 	int			dofg = 0;
2667c478bd9Sstevel@tonic-gate 	struct stat		buf;
2677c478bd9Sstevel@tonic-gate 	sigset_t		myset;
2687c478bd9Sstevel@tonic-gate 	struct sigaction	sighupaction;
2697c478bd9Sstevel@tonic-gate 	static void		client_killserver();
2707c478bd9Sstevel@tonic-gate 	int			debug_level = 0;
2717c478bd9Sstevel@tonic-gate 
2727c478bd9Sstevel@tonic-gate 	/* setup for localization */
2737c478bd9Sstevel@tonic-gate 	(void) setlocale(LC_ALL, "");
2747c478bd9Sstevel@tonic-gate 	(void) textdomain(TEXT_DOMAIN);
2757c478bd9Sstevel@tonic-gate 
2767c478bd9Sstevel@tonic-gate 	openlog("ldap_cachemgr", LOG_PID, LOG_DAEMON);
2777c478bd9Sstevel@tonic-gate 
2787c478bd9Sstevel@tonic-gate 	if (chdir(NSLDAPDIRECTORY) < 0) {
2797c478bd9Sstevel@tonic-gate 		(void) fprintf(stderr, gettext("chdir(\"%s\") failed: %s\n"),
2807c478bd9Sstevel@tonic-gate 		    NSLDAPDIRECTORY, strerror(errno));
2817c478bd9Sstevel@tonic-gate 		exit(1);
2827c478bd9Sstevel@tonic-gate 	}
2837c478bd9Sstevel@tonic-gate 
2847c478bd9Sstevel@tonic-gate 	/*
2857c478bd9Sstevel@tonic-gate 	 * Correctly set file mode creation mask, so to make the new files
2867c478bd9Sstevel@tonic-gate 	 * created for door calls being readable by all.
2877c478bd9Sstevel@tonic-gate 	 */
2887c478bd9Sstevel@tonic-gate 	(void) umask(0);
2897c478bd9Sstevel@tonic-gate 
2907c478bd9Sstevel@tonic-gate 	/*
2917c478bd9Sstevel@tonic-gate 	 *  Special case non-root user here -	he/she/they/it can just print
2927c478bd9Sstevel@tonic-gate 	 *					stats
2937c478bd9Sstevel@tonic-gate 	 */
2947c478bd9Sstevel@tonic-gate 
2957c478bd9Sstevel@tonic-gate 	if (geteuid()) {
2967c478bd9Sstevel@tonic-gate 		if (argc != 2 || strcmp(argv[1], "-g")) {
2977c478bd9Sstevel@tonic-gate 			(void) fprintf(stderr,
2987c478bd9Sstevel@tonic-gate 			    gettext("Must be root to use any option "
2997c478bd9Sstevel@tonic-gate 			    "other than -g.\n\n"));
3007c478bd9Sstevel@tonic-gate 			usage(argv[0]);
3017c478bd9Sstevel@tonic-gate 		}
3027c478bd9Sstevel@tonic-gate 
3037c478bd9Sstevel@tonic-gate 		if ((__ns_ldap_cache_ping() != SUCCESS) ||
3047c478bd9Sstevel@tonic-gate 		    (client_getadmin(&current_admin) != 0)) {
3057c478bd9Sstevel@tonic-gate 			(void) fprintf(stderr,
3067c478bd9Sstevel@tonic-gate 			    gettext("%s doesn't appear to be running.\n"),
3077c478bd9Sstevel@tonic-gate 			    argv[0]);
3087c478bd9Sstevel@tonic-gate 			exit(1);
3097c478bd9Sstevel@tonic-gate 		}
3107c478bd9Sstevel@tonic-gate 		(void) client_showstats(&current_admin);
3117c478bd9Sstevel@tonic-gate 		exit(0);
3127c478bd9Sstevel@tonic-gate 	}
3137c478bd9Sstevel@tonic-gate 
3147c478bd9Sstevel@tonic-gate 
3157c478bd9Sstevel@tonic-gate 
3167c478bd9Sstevel@tonic-gate 	/*
3177c478bd9Sstevel@tonic-gate 	 *  Determine if there is already a daemon running
3187c478bd9Sstevel@tonic-gate 	 */
3197c478bd9Sstevel@tonic-gate 
3207c478bd9Sstevel@tonic-gate 	will_become_server = (__ns_ldap_cache_ping() != SUCCESS);
3217c478bd9Sstevel@tonic-gate 
3227c478bd9Sstevel@tonic-gate 	/*
3237c478bd9Sstevel@tonic-gate 	 *  load normal config file
3247c478bd9Sstevel@tonic-gate 	 */
3257c478bd9Sstevel@tonic-gate 
3267c478bd9Sstevel@tonic-gate 	if (will_become_server) {
3277c478bd9Sstevel@tonic-gate 		static const ldap_stat_t defaults = {
3287c478bd9Sstevel@tonic-gate 			0,		/* stat */
3297c478bd9Sstevel@tonic-gate 			DEFAULTTTL};	/* ttl */
3307c478bd9Sstevel@tonic-gate 
3317c478bd9Sstevel@tonic-gate 		current_admin.ldap_stat = defaults;
3327c478bd9Sstevel@tonic-gate 		(void) strcpy(current_admin.logfile, LOGFILE);
3337c478bd9Sstevel@tonic-gate 	} else {
3347c478bd9Sstevel@tonic-gate 		if (client_getadmin(&current_admin)) {
3357c478bd9Sstevel@tonic-gate 			(void) fprintf(stderr, gettext("Cannot contact %s "
3367c478bd9Sstevel@tonic-gate 			    "properly(?)\n"), argv[0]);
3377c478bd9Sstevel@tonic-gate 			exit(1);
3387c478bd9Sstevel@tonic-gate 		}
3397c478bd9Sstevel@tonic-gate 	}
3407c478bd9Sstevel@tonic-gate 
3417c478bd9Sstevel@tonic-gate #ifndef SLP
3427c478bd9Sstevel@tonic-gate 	while ((opt = getopt(argc, argv, "fKgl:r:d:")) != EOF) {
3437c478bd9Sstevel@tonic-gate #else
3447c478bd9Sstevel@tonic-gate 	while ((opt = getopt(argc, argv, "fKgs:l:r:d:")) != EOF) {
3457c478bd9Sstevel@tonic-gate #endif /* SLP */
3467c478bd9Sstevel@tonic-gate 		ldap_stat_t	*cache;
3477c478bd9Sstevel@tonic-gate 
3487c478bd9Sstevel@tonic-gate 		switch (opt) {
3497c478bd9Sstevel@tonic-gate 		case 'K':
3507c478bd9Sstevel@tonic-gate 			client_killserver();
3517c478bd9Sstevel@tonic-gate 			exit(0);
3527c478bd9Sstevel@tonic-gate 			break;
3537c478bd9Sstevel@tonic-gate 		case 'g':
3547c478bd9Sstevel@tonic-gate 			showstats++;
3557c478bd9Sstevel@tonic-gate 			break;
3567c478bd9Sstevel@tonic-gate 		case 'f':
3577c478bd9Sstevel@tonic-gate 			dofg++;
3587c478bd9Sstevel@tonic-gate 			break;
3597c478bd9Sstevel@tonic-gate 		case 'r':
3607c478bd9Sstevel@tonic-gate 			doset++;
3617c478bd9Sstevel@tonic-gate 			cache = getcacheptr("ldap");
3627c478bd9Sstevel@tonic-gate 			if (!optarg) {
3637c478bd9Sstevel@tonic-gate 				errflg++;
3647c478bd9Sstevel@tonic-gate 				break;
3657c478bd9Sstevel@tonic-gate 			}
3667c478bd9Sstevel@tonic-gate 			cache->ldap_ttl = atoi(optarg);
3677c478bd9Sstevel@tonic-gate 			break;
3687c478bd9Sstevel@tonic-gate 		case 'l':
3697c478bd9Sstevel@tonic-gate 			doset++;
3707c478bd9Sstevel@tonic-gate 			(void) strlcpy(current_admin.logfile,
3717c478bd9Sstevel@tonic-gate 			    optarg, sizeof (current_admin.logfile));
3727c478bd9Sstevel@tonic-gate 			break;
3737c478bd9Sstevel@tonic-gate 		case 'd':
3747c478bd9Sstevel@tonic-gate 			doset++;
3757c478bd9Sstevel@tonic-gate 			debug_level = atoi(optarg);
3767c478bd9Sstevel@tonic-gate 			break;
3777c478bd9Sstevel@tonic-gate #ifdef SLP
3787c478bd9Sstevel@tonic-gate 		case 's':	/* undocumented: use dynamic (SLP) config */
3797c478bd9Sstevel@tonic-gate 			use_slp = 1;
3807c478bd9Sstevel@tonic-gate 			break;
3817c478bd9Sstevel@tonic-gate #endif /* SLP */
3827c478bd9Sstevel@tonic-gate 		default:
3837c478bd9Sstevel@tonic-gate 			errflg++;
3847c478bd9Sstevel@tonic-gate 			break;
3857c478bd9Sstevel@tonic-gate 		}
3867c478bd9Sstevel@tonic-gate 	}
3877c478bd9Sstevel@tonic-gate 
3887c478bd9Sstevel@tonic-gate 	if (errflg)
3897c478bd9Sstevel@tonic-gate 		usage(argv[0]);
3907c478bd9Sstevel@tonic-gate 
3917c478bd9Sstevel@tonic-gate 	/*
3927c478bd9Sstevel@tonic-gate 	 * will not show statistics if no daemon running
3937c478bd9Sstevel@tonic-gate 	 */
3947c478bd9Sstevel@tonic-gate 	if (will_become_server && showstats) {
3957c478bd9Sstevel@tonic-gate 		(void) fprintf(stderr,
3967c478bd9Sstevel@tonic-gate 		    gettext("%s doesn't appear to be running.\n"),
3977c478bd9Sstevel@tonic-gate 		    argv[0]);
3987c478bd9Sstevel@tonic-gate 		exit(1);
3997c478bd9Sstevel@tonic-gate 	}
4007c478bd9Sstevel@tonic-gate 
4017c478bd9Sstevel@tonic-gate 	if (!will_become_server) {
4027c478bd9Sstevel@tonic-gate 		if (showstats) {
4037c478bd9Sstevel@tonic-gate 			(void) client_showstats(&current_admin);
4047c478bd9Sstevel@tonic-gate 		}
4057c478bd9Sstevel@tonic-gate 		if (doset) {
4067c478bd9Sstevel@tonic-gate 			current_admin.debug_level = debug_level;
4077c478bd9Sstevel@tonic-gate 			if (client_setadmin(&current_admin) < 0) {
4087c478bd9Sstevel@tonic-gate 				(void) fprintf(stderr,
4097c478bd9Sstevel@tonic-gate 				    gettext("Error during admin call\n"));
4107c478bd9Sstevel@tonic-gate 				exit(1);
4117c478bd9Sstevel@tonic-gate 			}
4127c478bd9Sstevel@tonic-gate 		}
4137c478bd9Sstevel@tonic-gate 		if (!showstats && !doset) {
4147c478bd9Sstevel@tonic-gate 			(void) fprintf(stderr,
4157c478bd9Sstevel@tonic-gate 			gettext("%s already running....use '%s "
4167c478bd9Sstevel@tonic-gate 			    "-K' to stop\n"), argv[0], argv[0]);
4177c478bd9Sstevel@tonic-gate 		}
4187c478bd9Sstevel@tonic-gate 		exit(0);
4197c478bd9Sstevel@tonic-gate 	}
4207c478bd9Sstevel@tonic-gate 
4217c478bd9Sstevel@tonic-gate 	/*
4227c478bd9Sstevel@tonic-gate 	 *   daemon from here on
4237c478bd9Sstevel@tonic-gate 	 */
4247c478bd9Sstevel@tonic-gate 
4257c478bd9Sstevel@tonic-gate 	if (debug_level) {
4267c478bd9Sstevel@tonic-gate 		/*
4277c478bd9Sstevel@tonic-gate 		 * we're debugging...
4287c478bd9Sstevel@tonic-gate 		 */
4297c478bd9Sstevel@tonic-gate 		if (strlen(current_admin.logfile) == 0)
4307c478bd9Sstevel@tonic-gate 			/*
4317c478bd9Sstevel@tonic-gate 			 * no specified log file
4327c478bd9Sstevel@tonic-gate 			 */
4337c478bd9Sstevel@tonic-gate 			(void) strcpy(current_admin.logfile, LOGFILE);
4347c478bd9Sstevel@tonic-gate 		else
4357c478bd9Sstevel@tonic-gate 			(void) cachemgr_set_lf(&current_admin,
4367c478bd9Sstevel@tonic-gate 			    current_admin.logfile);
4377c478bd9Sstevel@tonic-gate 		/*
4387c478bd9Sstevel@tonic-gate 		 * validate the range of debug level number
4397c478bd9Sstevel@tonic-gate 		 * and set the number to current_admin.debug_level
4407c478bd9Sstevel@tonic-gate 		 */
4417c478bd9Sstevel@tonic-gate 		if (cachemgr_set_dl(&current_admin, debug_level) < 0) {
4427c478bd9Sstevel@tonic-gate 				/*
4437c478bd9Sstevel@tonic-gate 				 * print error messages to the screen
4447c478bd9Sstevel@tonic-gate 				 * cachemgr_set_dl prints msgs to cachemgr.log
4457c478bd9Sstevel@tonic-gate 				 * only
4467c478bd9Sstevel@tonic-gate 				 */
4477c478bd9Sstevel@tonic-gate 				(void) fprintf(stderr,
4487c478bd9Sstevel@tonic-gate 				gettext("Incorrect Debug Level: %d\n"
4497c478bd9Sstevel@tonic-gate 				"It should be between %d and %d\n"),
4507c478bd9Sstevel@tonic-gate 				    debug_level, DBG_OFF, MAXDEBUG);
4517c478bd9Sstevel@tonic-gate 			exit(-1);
4527c478bd9Sstevel@tonic-gate 		}
4537c478bd9Sstevel@tonic-gate 	} else {
4547c478bd9Sstevel@tonic-gate 		if (strlen(current_admin.logfile) == 0)
4557c478bd9Sstevel@tonic-gate 			(void) strcpy(current_admin.logfile, "/dev/null");
4567c478bd9Sstevel@tonic-gate 			(void) cachemgr_set_lf(&current_admin,
4577c478bd9Sstevel@tonic-gate 			    current_admin.logfile);
4587c478bd9Sstevel@tonic-gate 	}
4597c478bd9Sstevel@tonic-gate 
4607c478bd9Sstevel@tonic-gate 	if (dofg == 0)
4617c478bd9Sstevel@tonic-gate 		detachfromtty(argv[0]);
4627c478bd9Sstevel@tonic-gate 
4637c478bd9Sstevel@tonic-gate 	/*
4647c478bd9Sstevel@tonic-gate 	 * perform some initialization
4657c478bd9Sstevel@tonic-gate 	 */
4667c478bd9Sstevel@tonic-gate 
4677c478bd9Sstevel@tonic-gate 	initialize_lookup_clearance();
4687c478bd9Sstevel@tonic-gate 
4697c478bd9Sstevel@tonic-gate 	if (getldap_init() != 0)
4707c478bd9Sstevel@tonic-gate 		exit(-1);
4717c478bd9Sstevel@tonic-gate 
4727c478bd9Sstevel@tonic-gate 	/*
4737c478bd9Sstevel@tonic-gate 	 * Establish our own server thread pool
4747c478bd9Sstevel@tonic-gate 	 */
4757c478bd9Sstevel@tonic-gate 
476cb5caa98Sdjl 	(void) door_server_create(server_create);
4777c478bd9Sstevel@tonic-gate 	if (thr_keycreate(&server_key, server_destroy) != 0) {
4787c478bd9Sstevel@tonic-gate 		logit("thr_keycreate() call failed\n");
4797c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR,
4807c478bd9Sstevel@tonic-gate 		    gettext("ldap_cachemgr: thr_keycreate() call failed"));
4817c478bd9Sstevel@tonic-gate 		perror("thr_keycreate");
4827c478bd9Sstevel@tonic-gate 		exit(-1);
4837c478bd9Sstevel@tonic-gate 	}
4847c478bd9Sstevel@tonic-gate 
4857c478bd9Sstevel@tonic-gate 	/*
4867c478bd9Sstevel@tonic-gate 	 * Create a door
4877c478bd9Sstevel@tonic-gate 	 */
4887c478bd9Sstevel@tonic-gate 
4897c478bd9Sstevel@tonic-gate 	if ((did = door_create(switcher, LDAP_CACHE_DOOR_COOKIE,
4907c478bd9Sstevel@tonic-gate 	    DOOR_UNREF | DOOR_REFUSE_DESC | DOOR_NO_CANCEL)) < 0) {
4917c478bd9Sstevel@tonic-gate 		logit("door_create() call failed\n");
4927c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR, gettext(
4937c478bd9Sstevel@tonic-gate 		    "ldap_cachemgr: door_create() call failed"));
4947c478bd9Sstevel@tonic-gate 		perror("door_create");
4957c478bd9Sstevel@tonic-gate 		exit(-1);
4967c478bd9Sstevel@tonic-gate 	}
4977c478bd9Sstevel@tonic-gate 
4987c478bd9Sstevel@tonic-gate 	/*
4997c478bd9Sstevel@tonic-gate 	 * bind to file system
5007c478bd9Sstevel@tonic-gate 	 */
5017c478bd9Sstevel@tonic-gate 
5027c478bd9Sstevel@tonic-gate 	if (stat(LDAP_CACHE_DOOR, &buf) < 0) {
5037c478bd9Sstevel@tonic-gate 		int	newfd;
5047c478bd9Sstevel@tonic-gate 
5057c478bd9Sstevel@tonic-gate 		if ((newfd = creat(LDAP_CACHE_DOOR, 0444)) < 0) {
5067c478bd9Sstevel@tonic-gate 			logit("Cannot create %s:%s\n",
5077c478bd9Sstevel@tonic-gate 			    LDAP_CACHE_DOOR,
5087c478bd9Sstevel@tonic-gate 			    strerror(errno));
5097c478bd9Sstevel@tonic-gate 			exit(1);
5107c478bd9Sstevel@tonic-gate 		}
5117c478bd9Sstevel@tonic-gate 		(void) close(newfd);
5127c478bd9Sstevel@tonic-gate 	}
5137c478bd9Sstevel@tonic-gate 
5147c478bd9Sstevel@tonic-gate 	if (fattach(did, LDAP_CACHE_DOOR) < 0) {
5157c478bd9Sstevel@tonic-gate 		if ((errno != EBUSY) ||
5167c478bd9Sstevel@tonic-gate 		    (fdetach(LDAP_CACHE_DOOR) <  0) ||
5177c478bd9Sstevel@tonic-gate 		    (fattach(did, LDAP_CACHE_DOOR) < 0)) {
5187c478bd9Sstevel@tonic-gate 			logit("fattach() call failed\n");
5197c478bd9Sstevel@tonic-gate 			syslog(LOG_ERR, gettext(
5207c478bd9Sstevel@tonic-gate 			    "ldap_cachemgr: fattach() call failed"));
5217c478bd9Sstevel@tonic-gate 			perror("fattach");
5227c478bd9Sstevel@tonic-gate 			exit(2);
5237c478bd9Sstevel@tonic-gate 		}
5247c478bd9Sstevel@tonic-gate 	}
5257c478bd9Sstevel@tonic-gate 
5267c478bd9Sstevel@tonic-gate 	/* catch SIGHUP revalid signals */
5277c478bd9Sstevel@tonic-gate 	sighupaction.sa_handler = getldap_revalidate;
5287c478bd9Sstevel@tonic-gate 	sighupaction.sa_flags = 0;
5297c478bd9Sstevel@tonic-gate 	(void) sigemptyset(&sighupaction.sa_mask);
5307c478bd9Sstevel@tonic-gate 	(void) sigemptyset(&myset);
5317c478bd9Sstevel@tonic-gate 	(void) sigaddset(&myset, SIGHUP);
5327c478bd9Sstevel@tonic-gate 
5337c478bd9Sstevel@tonic-gate 	if (sigaction(SIGHUP, &sighupaction, NULL) < 0) {
5347c478bd9Sstevel@tonic-gate 		logit("sigaction() call failed\n");
5357c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR,
5367c478bd9Sstevel@tonic-gate 		    gettext("ldap_cachemgr: sigaction() call failed"));
5377c478bd9Sstevel@tonic-gate 		perror("sigaction");
5387c478bd9Sstevel@tonic-gate 		exit(1);
5397c478bd9Sstevel@tonic-gate 	}
5407c478bd9Sstevel@tonic-gate 
5417c478bd9Sstevel@tonic-gate 	if (thr_sigsetmask(SIG_BLOCK, &myset, NULL) < 0) {
5427c478bd9Sstevel@tonic-gate 		logit("thr_sigsetmask() call failed\n");
5437c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR,
5447c478bd9Sstevel@tonic-gate 		    gettext("ldap_cachemgr: thr_sigsetmask() call failed"));
5457c478bd9Sstevel@tonic-gate 		perror("thr_sigsetmask");
5467c478bd9Sstevel@tonic-gate 		exit(1);
5477c478bd9Sstevel@tonic-gate 	}
5487c478bd9Sstevel@tonic-gate 
5497c478bd9Sstevel@tonic-gate 	/*
5507c478bd9Sstevel@tonic-gate 	 *  kick off revalidate threads only if ttl != 0
5517c478bd9Sstevel@tonic-gate 	 */
5527c478bd9Sstevel@tonic-gate 
5537c478bd9Sstevel@tonic-gate 	if (thr_create(NULL, NULL, (void *(*)(void*))getldap_refresh,
5547c478bd9Sstevel@tonic-gate 	    0, 0, NULL) != 0) {
5557c478bd9Sstevel@tonic-gate 		logit("thr_create() call failed\n");
5567c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR,
5577c478bd9Sstevel@tonic-gate 		    gettext("ldap_cachemgr: thr_create() call failed"));
5587c478bd9Sstevel@tonic-gate 		perror("thr_create");
5597c478bd9Sstevel@tonic-gate 		exit(1);
5607c478bd9Sstevel@tonic-gate 	}
5617c478bd9Sstevel@tonic-gate 
5627c478bd9Sstevel@tonic-gate 	/*
5637c478bd9Sstevel@tonic-gate 	 *  kick off the thread which refreshes the server info
5647c478bd9Sstevel@tonic-gate 	 */
5657c478bd9Sstevel@tonic-gate 
5667c478bd9Sstevel@tonic-gate 	if (thr_create(NULL, NULL, (void *(*)(void*))getldap_serverInfo_refresh,
5677c478bd9Sstevel@tonic-gate 	    0, 0, NULL) != 0) {
5687c478bd9Sstevel@tonic-gate 		logit("thr_create() call failed\n");
5697c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR,
5707c478bd9Sstevel@tonic-gate 		    gettext("ldap_cachemgr: thr_create() call failed"));
5717c478bd9Sstevel@tonic-gate 		perror("thr_create");
5727c478bd9Sstevel@tonic-gate 		exit(1);
5737c478bd9Sstevel@tonic-gate 	}
5747c478bd9Sstevel@tonic-gate 
5757c478bd9Sstevel@tonic-gate #ifdef SLP
5767c478bd9Sstevel@tonic-gate 	if (use_slp) {
5777c478bd9Sstevel@tonic-gate 		/* kick off SLP discovery thread */
5787c478bd9Sstevel@tonic-gate 		if (thr_create(NULL, NULL, (void *(*)(void *))discover,
5797c478bd9Sstevel@tonic-gate 		    (void *)&refresh, 0, NULL) != 0) {
5807c478bd9Sstevel@tonic-gate 			logit("thr_create() call failed\n");
5817c478bd9Sstevel@tonic-gate 			syslog(LOG_ERR, gettext("ldap_cachemgr: thr_create() "
5827c478bd9Sstevel@tonic-gate 			    "call failed"));
5837c478bd9Sstevel@tonic-gate 			perror("thr_create");
5847c478bd9Sstevel@tonic-gate 			exit(1);
5857c478bd9Sstevel@tonic-gate 		}
5867c478bd9Sstevel@tonic-gate 	}
5877c478bd9Sstevel@tonic-gate #endif /* SLP */
5887c478bd9Sstevel@tonic-gate 
5897c478bd9Sstevel@tonic-gate 	if (thr_sigsetmask(SIG_UNBLOCK, &myset, NULL) < 0) {
5907c478bd9Sstevel@tonic-gate 		logit("thr_sigsetmask() call failed\n");
5917c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR,
5927c478bd9Sstevel@tonic-gate 		    gettext("ldap_cachemgr: the_sigsetmask() call failed"));
5937c478bd9Sstevel@tonic-gate 		perror("thr_sigsetmask");
5947c478bd9Sstevel@tonic-gate 		exit(1);
5957c478bd9Sstevel@tonic-gate 	}
5967c478bd9Sstevel@tonic-gate 
5977c478bd9Sstevel@tonic-gate 	/*CONSTCOND*/
5987c478bd9Sstevel@tonic-gate 	while (1) {
5997c478bd9Sstevel@tonic-gate 		(void) pause();
6007c478bd9Sstevel@tonic-gate 	}
601cb5caa98Sdjl 	/* NOTREACHED */
602cb5caa98Sdjl 	/*LINTED E_FUNC_HAS_NO_RETURN_STMT*/
6037c478bd9Sstevel@tonic-gate }
6047c478bd9Sstevel@tonic-gate 
6057c478bd9Sstevel@tonic-gate 
606*7ddae043Siz202018 /*
607*7ddae043Siz202018  * Before calling the alloca() function we have to be sure that we won't get
608*7ddae043Siz202018  * beyond the stack. Since we don't know the precise layout of the stack,
609*7ddae043Siz202018  * the address of an automatic of the function gives us a rough idea, plus/minus
610*7ddae043Siz202018  * a bit. We also need a bit more of stackspace after the call to be able
611*7ddae043Siz202018  * to call further functions. Even something as simple as making a system call
612*7ddae043Siz202018  * from within this function can take ~100 Bytes of stackspace.
613*7ddae043Siz202018  */
614*7ddae043Siz202018 #define	SAFETY_BUFFER 32 * 1024 /* 32KB */
615*7ddae043Siz202018 
616*7ddae043Siz202018 static
617*7ddae043Siz202018 size_t
618*7ddae043Siz202018 get_data_size(LineBuf *config_info, int *err_code)
619*7ddae043Siz202018 {
620*7ddae043Siz202018 	size_t		configSize = sizeof (ldap_return_t);
621*7ddae043Siz202018 	dataunion	*buf = NULL; /* For the 'sizeof' purpose */
622*7ddae043Siz202018 
623*7ddae043Siz202018 	if (config_info->str != NULL &&
624*7ddae043Siz202018 	    config_info->len >= sizeof (buf->data.ldap_ret.ldap_u.config)) {
625*7ddae043Siz202018 		configSize = sizeof (buf->space) +
626*7ddae043Siz202018 		    config_info->len -
627*7ddae043Siz202018 		    sizeof (buf->data.ldap_ret.ldap_u.config);
628*7ddae043Siz202018 
629*7ddae043Siz202018 		if (!stack_inbounds((char *)&buf -
630*7ddae043Siz202018 		    (configSize + SAFETY_BUFFER))) {
631*7ddae043Siz202018 			/*
632*7ddae043Siz202018 			 * We do not have enough space on the stack
633*7ddae043Siz202018 			 * to accomodate the whole DUAProfile
634*7ddae043Siz202018 			 */
635*7ddae043Siz202018 			logit("The DUAProfile is too big. There is not enough "
636*7ddae043Siz202018 			    "space to process it. Ignoring it.\n");
637*7ddae043Siz202018 			syslog(LOG_ERR, gettext("ldap_cachemgr: The DUAProfile "
638*7ddae043Siz202018 			    "is too big. There is not enough space "
639*7ddae043Siz202018 			    "to process it. Ignoring it."));
640*7ddae043Siz202018 
641*7ddae043Siz202018 			*err_code = SERVERERROR;
642*7ddae043Siz202018 
643*7ddae043Siz202018 			free(config_info->str);
644*7ddae043Siz202018 			config_info->str = NULL;
645*7ddae043Siz202018 			config_info->len = 0;
646*7ddae043Siz202018 			configSize = sizeof (ldap_return_t);
647*7ddae043Siz202018 		}
648*7ddae043Siz202018 	}
649*7ddae043Siz202018 
650*7ddae043Siz202018 	return (configSize);
651*7ddae043Siz202018 }
652*7ddae043Siz202018 
6537c478bd9Sstevel@tonic-gate /*ARGSUSED*/
6547c478bd9Sstevel@tonic-gate static void
6557c478bd9Sstevel@tonic-gate switcher(void *cookie, char *argp, size_t arg_size,
6567c478bd9Sstevel@tonic-gate     door_desc_t *dp, uint_t n_desc)
6577c478bd9Sstevel@tonic-gate {
658*7ddae043Siz202018 #define	GETSIZE 1000
659*7ddae043Siz202018 #define	ALLOCATE 1001
660*7ddae043Siz202018 #define	PREPARE  1002
661*7ddae043Siz202018 
6627c478bd9Sstevel@tonic-gate 	ldap_call_t	*ptr = (ldap_call_t *)argp;
6637c478bd9Sstevel@tonic-gate 	door_cred_t	dc;
6647c478bd9Sstevel@tonic-gate 
665*7ddae043Siz202018 	LineBuf		configInfo;
666*7ddae043Siz202018 	dataunion	*buf = NULL;
667*7ddae043Siz202018 	/*
668*7ddae043Siz202018 	 * By default the size of  a buffer to be passed down to a client
669*7ddae043Siz202018 	 * is equal to the size of the ldap_return_t structure. We need
670*7ddae043Siz202018 	 * a bigger buffer in a few cases.
671*7ddae043Siz202018 	 */
672*7ddae043Siz202018 	size_t		configSize = sizeof (ldap_return_t);
673*7ddae043Siz202018 	int		ldapErrno = 0, state, leave = 0;
674*7ddae043Siz202018 	struct {
675*7ddae043Siz202018 		void	*begin;
676*7ddae043Siz202018 		size_t	size;
677*7ddae043Siz202018 		uint8_t	destroy;
678*7ddae043Siz202018 	} dataSource;
679*7ddae043Siz202018 
6807c478bd9Sstevel@tonic-gate 	if (argp == DOOR_UNREF_DATA) {
6817c478bd9Sstevel@tonic-gate 		logit("Door Slam... invalid door param\n");
6827c478bd9Sstevel@tonic-gate 		syslog(LOG_ERR, gettext("ldap_cachemgr: Door Slam... "
6837c478bd9Sstevel@tonic-gate 		    "invalid door param"));
6847c478bd9Sstevel@tonic-gate 		(void) printf(gettext("Door Slam... invalid door param\n"));
6857c478bd9Sstevel@tonic-gate 		exit(0);
6867c478bd9Sstevel@tonic-gate 	}
6877c478bd9Sstevel@tonic-gate 
6887c478bd9Sstevel@tonic-gate 	if (ptr == NULL) { /* empty door call */
6897c478bd9Sstevel@tonic-gate 		(void) door_return(NULL, 0, 0, 0); /* return the favor */
6907c478bd9Sstevel@tonic-gate 	}
6917c478bd9Sstevel@tonic-gate 
692*7ddae043Siz202018 	bzero(&dataSource, sizeof (dataSource));
693*7ddae043Siz202018 
694*7ddae043Siz202018 	/*
695*7ddae043Siz202018 	 * We presume that sizeof (ldap_return_t) bytes are always available
696*7ddae043Siz202018 	 * on the stack
697*7ddae043Siz202018 	 */
698*7ddae043Siz202018 	state = ptr->ldap_callnumber;
699*7ddae043Siz202018 
700*7ddae043Siz202018 	/*
701*7ddae043Siz202018 	 * The common behavior of the state machine below is as follows:
702*7ddae043Siz202018 	 *
703*7ddae043Siz202018 	 * Each incoming request is processed in several steps.
704*7ddae043Siz202018 	 *
705*7ddae043Siz202018 	 * First stage is specific for a particular request. It can be
706*7ddae043Siz202018 	 * an error check or gathering data or empty. See the actual comments
707*7ddae043Siz202018 	 * for the requests. For the GETLDAPCONFIG, GETLDAPSERVER, GETCACHESTAT,
708*7ddae043Siz202018 	 * and GETCACHE there is an additional substage calculating the size of
709*7ddae043Siz202018 	 * the data being passed to a door client.
710*7ddae043Siz202018 	 * The next step is obligatory. It allocates a buffer which will be
711*7ddae043Siz202018 	 * passed down to the door_return() routine.
712*7ddae043Siz202018 	 * The last (also obligatory) step sets the return code and, if a data
713*7ddae043Siz202018 	 * is available for the transfer and no errors have occurred, copies
714*7ddae043Siz202018 	 * the data to the buffer.
715*7ddae043Siz202018 	 *
716*7ddae043Siz202018 	 * After the state machine has finished, the door_return() function
717*7ddae043Siz202018 	 * is called unconditionally
718*7ddae043Siz202018 	 */
719*7ddae043Siz202018 	while (!leave) {
720*7ddae043Siz202018 		switch (state) {
7217c478bd9Sstevel@tonic-gate 		case NULLCALL:
722*7ddae043Siz202018 			/*
723*7ddae043Siz202018 			 * Just a 'ping'. Use the default size
724*7ddae043Siz202018 			 * of the buffer and set the
725*7ddae043Siz202018 			 * 'OK' error code.
726*7ddae043Siz202018 			 */
727*7ddae043Siz202018 			state = ALLOCATE;
7287c478bd9Sstevel@tonic-gate 			break;
7297c478bd9Sstevel@tonic-gate 		case GETLDAPCONFIG:
730*7ddae043Siz202018 			/*
731*7ddae043Siz202018 			 * Get the current LDAP configuration.
732*7ddae043Siz202018 			 * Since this is dynamic data and its size can exceed
733*7ddae043Siz202018 			 * the size of ldap_return_t, the next step will
734*7ddae043Siz202018 			 * calculate who much space exactly is required.
735*7ddae043Siz202018 			 */
736*7ddae043Siz202018 			getldap_lookup(&configInfo, ptr);
737*7ddae043Siz202018 
738*7ddae043Siz202018 			state = GETSIZE;
739*7ddae043Siz202018 			break;
740*7ddae043Siz202018 		case GETLDAPSERVER:
741*7ddae043Siz202018 			/*
742*7ddae043Siz202018 			 * Get the root DSE for a next server in the list.
743*7ddae043Siz202018 			 * Since this is dynamic data and its size can exceed
744*7ddae043Siz202018 			 * the size of ldap_return_t, the next step will
745*7ddae043Siz202018 			 * calculate who much space exactly is required.
746*7ddae043Siz202018 			 */
747*7ddae043Siz202018 			getldap_getserver(&configInfo, ptr);
748*7ddae043Siz202018 
749*7ddae043Siz202018 			state = GETSIZE;
750*7ddae043Siz202018 			break;
751*7ddae043Siz202018 		case GETCACHESTAT:
752*7ddae043Siz202018 			/*
753*7ddae043Siz202018 			 * Get the cache stattistics.
754*7ddae043Siz202018 			 * Since this is dynamic data and its size can exceed
755*7ddae043Siz202018 			 * the size of ldap_return_t, the next step will
756*7ddae043Siz202018 			 * calculate how much space exactly is required.
757*7ddae043Siz202018 			 */
758*7ddae043Siz202018 			getldap_get_cacheStat(&configInfo);
759*7ddae043Siz202018 
760*7ddae043Siz202018 			state = GETSIZE;
7617c478bd9Sstevel@tonic-gate 			break;
7627c478bd9Sstevel@tonic-gate 		case GETADMIN:
763*7ddae043Siz202018 			/*
764*7ddae043Siz202018 			 * Get current configuration and statistics.
765*7ddae043Siz202018 			 * The size of the statistics structure is less then
766*7ddae043Siz202018 			 * sizeof (ldap_return_t). So specify the source
767*7ddae043Siz202018 			 * where to take the info and proceed with the memory
768*7ddae043Siz202018 			 * allocation.
769*7ddae043Siz202018 			 */
770*7ddae043Siz202018 			state = ALLOCATE;
771*7ddae043Siz202018 
772*7ddae043Siz202018 			if (ldapErrno == 0) {
773*7ddae043Siz202018 				dataSource.begin = &current_admin;
774*7ddae043Siz202018 				dataSource.size = sizeof (current_admin);
775*7ddae043Siz202018 				dataSource.destroy = 0;
776*7ddae043Siz202018 			}
777*7ddae043Siz202018 
7787c478bd9Sstevel@tonic-gate 			break;
7797c478bd9Sstevel@tonic-gate 		case SETADMIN:
7807c478bd9Sstevel@tonic-gate 		case KILLSERVER:
781*7ddae043Siz202018 			/*
782*7ddae043Siz202018 			 * Process the request and proceed with the default
783*7ddae043Siz202018 			 * buffer allocation.
784*7ddae043Siz202018 			 */
785*7ddae043Siz202018 			if (door_cred(&dc) == 0) {
786*7ddae043Siz202018 				switch (ptr->ldap_callnumber) {
787*7ddae043Siz202018 				case KILLSERVER:
788*7ddae043Siz202018 					logit("ldap_cachemgr received "
789*7ddae043Siz202018 					    "KILLSERVER cmd from pid %ld, "
790*7ddae043Siz202018 					    "uid %ld, euid %ld\n",
7917c478bd9Sstevel@tonic-gate 					    dc.dc_pid, dc.dc_ruid, dc.dc_euid);
7927c478bd9Sstevel@tonic-gate 					exit(0);
7937c478bd9Sstevel@tonic-gate 					break;
794*7ddae043Siz202018 				case SETADMIN:
795*7ddae043Siz202018 					if (dc.dc_euid != 0) {
796*7ddae043Siz202018 						logit("SETADMIN call failed "
797*7ddae043Siz202018 						    "(cred): "
798*7ddae043Siz202018 						    "caller pid %ld, uid %ld, "
799*7ddae043Siz202018 						    "euid %ld\n",
800*7ddae043Siz202018 						    dc.dc_pid,
801*7ddae043Siz202018 						    dc.dc_ruid,
802*7ddae043Siz202018 						    dc.dc_euid);
803*7ddae043Siz202018 						ldapErrno = -1;
804*7ddae043Siz202018 						break;
805*7ddae043Siz202018 					}
806*7ddae043Siz202018 					/* Yes, if a client's effective uid */
807*7ddae043Siz202018 					/* is noty defined, continue */
808*7ddae043Siz202018 					/* with setadmin() */
809*7ddae043Siz202018 				default:
810*7ddae043Siz202018 					ldapErrno = setadmin(ptr);
811*7ddae043Siz202018 					break;
812*7ddae043Siz202018 				}
813*7ddae043Siz202018 			} else {
814*7ddae043Siz202018 				logit("door_cred() call failed\n");
815*7ddae043Siz202018 				syslog(LOG_ERR, gettext("ldap_cachemgr: "
816*7ddae043Siz202018 				    "door_cred() call failed"));
817*7ddae043Siz202018 				perror("door_cred");
818*7ddae043Siz202018 				ldapErrno = -1;
819*7ddae043Siz202018 			}
820*7ddae043Siz202018 
821*7ddae043Siz202018 			state = ALLOCATE;
8227c478bd9Sstevel@tonic-gate 			break;
8237c478bd9Sstevel@tonic-gate 		case GETCACHE:
824*7ddae043Siz202018 			/*
825*7ddae043Siz202018 			 * Get the cache stattistics.
826*7ddae043Siz202018 			 * Since this is dynamic data and its size can exceed
827*7ddae043Siz202018 			 * the size of ldap_return_t, the next step will
828*7ddae043Siz202018 			 * calculate how much space exactly is required.
829*7ddae043Siz202018 			 */
830*7ddae043Siz202018 			getldap_get_cacheData(&configInfo, ptr);
831*7ddae043Siz202018 
832*7ddae043Siz202018 			state = GETSIZE;
8337c478bd9Sstevel@tonic-gate 			break;
8347c478bd9Sstevel@tonic-gate 		case SETCACHE:
835*7ddae043Siz202018 			/*
836*7ddae043Siz202018 			 * Process the request and proceed with the default
837*7ddae043Siz202018 			 * buffer allocation.
838*7ddae043Siz202018 			 */
839*7ddae043Siz202018 			ldapErrno = getldap_set_cacheData(ptr);
840*7ddae043Siz202018 
8417c478bd9Sstevel@tonic-gate 			current_admin.ldap_stat.ldap_numbercalls++;
842*7ddae043Siz202018 
843*7ddae043Siz202018 			state = ALLOCATE;
8447c478bd9Sstevel@tonic-gate 			break;
8457c478bd9Sstevel@tonic-gate 		default:
846*7ddae043Siz202018 			/*
847*7ddae043Siz202018 			 * This means an unknown request type. Proceed with
848*7ddae043Siz202018 			 * the default buffer allocation.
849*7ddae043Siz202018 			 */
8507c478bd9Sstevel@tonic-gate 			logit("Unknown ldap service door call op %d\n",
8517c478bd9Sstevel@tonic-gate 			    ptr->ldap_callnumber);
852*7ddae043Siz202018 			ldapErrno = -99;
853*7ddae043Siz202018 
854*7ddae043Siz202018 			state = ALLOCATE;
855*7ddae043Siz202018 			break;
856*7ddae043Siz202018 		case GETSIZE:
857*7ddae043Siz202018 			/*
858*7ddae043Siz202018 			 * This stage calculates how much data will be
859*7ddae043Siz202018 			 * passed down to the client, checks if there is
860*7ddae043Siz202018 			 * enough space on the stack to accommodate the data,
861*7ddae043Siz202018 			 * increases the value of the configSize variable
862*7ddae043Siz202018 			 * if necessary and specifies the data source.
863*7ddae043Siz202018 			 * In case of any error occurred ldapErrno will be set
864*7ddae043Siz202018 			 * appropriately.
865*7ddae043Siz202018 			 */
866*7ddae043Siz202018 			if (configInfo.str == NULL) {
867*7ddae043Siz202018 				ldapErrno = -1;
868*7ddae043Siz202018 			}
869*7ddae043Siz202018 
870*7ddae043Siz202018 			configSize = get_data_size(&configInfo, &ldapErrno);
871*7ddae043Siz202018 
872*7ddae043Siz202018 			if (ldapErrno == 0) {
873*7ddae043Siz202018 				dataSource.begin = configInfo.str;
874*7ddae043Siz202018 				dataSource.size = configInfo.len;
875*7ddae043Siz202018 				dataSource.destroy = 1;
876*7ddae043Siz202018 			}
877*7ddae043Siz202018 
878*7ddae043Siz202018 			current_admin.ldap_stat.ldap_numbercalls++;
879*7ddae043Siz202018 
880*7ddae043Siz202018 			state = ALLOCATE;
881*7ddae043Siz202018 			break;
882*7ddae043Siz202018 		case ALLOCATE:
883*7ddae043Siz202018 			/*
884*7ddae043Siz202018 			 * Allocate a buffer of the calculated (or default) size
885*7ddae043Siz202018 			 * and proceed with populating it with data.
886*7ddae043Siz202018 			 */
887*7ddae043Siz202018 			buf = (dataunion *) alloca(configSize);
888*7ddae043Siz202018 
889*7ddae043Siz202018 			state = PREPARE;
890*7ddae043Siz202018 			break;
891*7ddae043Siz202018 		case PREPARE:
892*7ddae043Siz202018 			/*
893*7ddae043Siz202018 			 * Set a return code and, if a data source is specified,
894*7ddae043Siz202018 			 * copy data from the source to the buffer.
895*7ddae043Siz202018 			 */
896*7ddae043Siz202018 			buf->data.ldap_ret.ldap_errno = ldapErrno;
897*7ddae043Siz202018 			buf->data.ldap_ret.ldap_return_code = ldapErrno;
898*7ddae043Siz202018 			buf->data.ldap_ret.ldap_bufferbytesused = configSize;
899*7ddae043Siz202018 
900*7ddae043Siz202018 			if (dataSource.begin != NULL) {
901*7ddae043Siz202018 				(void) memcpy(buf->data.ldap_ret.ldap_u.config,
902*7ddae043Siz202018 				    dataSource.begin,
903*7ddae043Siz202018 				    dataSource.size);
904*7ddae043Siz202018 				if (dataSource.destroy) {
905*7ddae043Siz202018 					free(dataSource.begin);
906*7ddae043Siz202018 				}
907*7ddae043Siz202018 			}
908*7ddae043Siz202018 
909*7ddae043Siz202018 			/*
910*7ddae043Siz202018 			 * Leave the state machine and send the data
911*7ddae043Siz202018 			 * to the client.
912*7ddae043Siz202018 			 */
913*7ddae043Siz202018 			leave = 1;
9147c478bd9Sstevel@tonic-gate 			break;
9157c478bd9Sstevel@tonic-gate 		}
916*7ddae043Siz202018 	}
917*7ddae043Siz202018 
918*7ddae043Siz202018 	(void) door_return((char *)&buf->data,
919*7ddae043Siz202018 	    buf->data.ldap_ret.ldap_bufferbytesused,
920*7ddae043Siz202018 	    NULL,
921*7ddae043Siz202018 	    0);
922*7ddae043Siz202018 #undef	GETSIZE
923*7ddae043Siz202018 #undef	ALLOCATE
924*7ddae043Siz202018 #undef	PREPARE
9257c478bd9Sstevel@tonic-gate }
9267c478bd9Sstevel@tonic-gate 
9277c478bd9Sstevel@tonic-gate static void
9287c478bd9Sstevel@tonic-gate usage(char *s)
9297c478bd9Sstevel@tonic-gate {
9307c478bd9Sstevel@tonic-gate 	(void) fprintf(stderr,
9317c478bd9Sstevel@tonic-gate 	    gettext("Usage: %s [-d debug_level] [-l logfilename]\n"), s);
9327c478bd9Sstevel@tonic-gate 	(void) fprintf(stderr, gettext("	[-K] "
9337c478bd9Sstevel@tonic-gate 	    "[-r revalidate_interval] "));
9347c478bd9Sstevel@tonic-gate #ifndef SLP
9357c478bd9Sstevel@tonic-gate 	(void) fprintf(stderr, gettext("	[-g]\n"));
9367c478bd9Sstevel@tonic-gate #else
9377c478bd9Sstevel@tonic-gate 	(void) fprintf(stderr, gettext("	[-g] [-s]\n"));
9387c478bd9Sstevel@tonic-gate #endif /* SLP */
9397c478bd9Sstevel@tonic-gate 	exit(1);
9407c478bd9Sstevel@tonic-gate }
9417c478bd9Sstevel@tonic-gate 
9427c478bd9Sstevel@tonic-gate 
9437c478bd9Sstevel@tonic-gate static int	logfd = -1;
9447c478bd9Sstevel@tonic-gate 
9457c478bd9Sstevel@tonic-gate static int
9467c478bd9Sstevel@tonic-gate cachemgr_set_lf(admin_t *ptr, char *logfile)
9477c478bd9Sstevel@tonic-gate {
9487c478bd9Sstevel@tonic-gate 	int	newlogfd;
9497c478bd9Sstevel@tonic-gate 
9507c478bd9Sstevel@tonic-gate 	/*
9517c478bd9Sstevel@tonic-gate 	 *  we don't really want to try and open the log file
9527c478bd9Sstevel@tonic-gate 	 *  /dev/null since that will fail w/ our security fixes
9537c478bd9Sstevel@tonic-gate 	 */
9547c478bd9Sstevel@tonic-gate 
9557c478bd9Sstevel@tonic-gate 	if (logfile == NULL || *logfile == 0) {
9567c478bd9Sstevel@tonic-gate 		/*EMPTY*/;
9577c478bd9Sstevel@tonic-gate 	} else if (strcmp(logfile, "/dev/null") == 0) {
9587c478bd9Sstevel@tonic-gate 		(void) strcpy(current_admin.logfile, "/dev/null");
9597c478bd9Sstevel@tonic-gate 		(void) close(logfd);
9607c478bd9Sstevel@tonic-gate 		logfd = -1;
9617c478bd9Sstevel@tonic-gate 	} else {
9627c478bd9Sstevel@tonic-gate 		if ((newlogfd =
9637c478bd9Sstevel@tonic-gate 		    open(logfile, O_EXCL|O_WRONLY|O_CREAT, 0644)) < 0) {
9647c478bd9Sstevel@tonic-gate 			/*
9657c478bd9Sstevel@tonic-gate 			 * File already exists... now we need to get cute
9667c478bd9Sstevel@tonic-gate 			 * since opening a file in a world-writeable directory
9677c478bd9Sstevel@tonic-gate 			 * safely is hard = it could be a hard link or a
9687c478bd9Sstevel@tonic-gate 			 * symbolic link to a system file.
9697c478bd9Sstevel@tonic-gate 			 *
9707c478bd9Sstevel@tonic-gate 			 */
9717c478bd9Sstevel@tonic-gate 			struct stat	before;
9727c478bd9Sstevel@tonic-gate 
9737c478bd9Sstevel@tonic-gate 			if (lstat(logfile, &before) < 0) {
9747c478bd9Sstevel@tonic-gate 				logit("Cannot open new logfile \"%s\": %sn",
9757c478bd9Sstevel@tonic-gate 				    logfile, strerror(errno));
9767c478bd9Sstevel@tonic-gate 				return (-1);
9777c478bd9Sstevel@tonic-gate 			}
9787c478bd9Sstevel@tonic-gate 			if (S_ISREG(before.st_mode) &&	/* no symbolic links */
9797c478bd9Sstevel@tonic-gate 			    (before.st_nlink == 1) &&	/* no hard links */
9807c478bd9Sstevel@tonic-gate 			    (before.st_uid == 0)) {	/* owned by root */
9817c478bd9Sstevel@tonic-gate 				if ((newlogfd =
9827c478bd9Sstevel@tonic-gate 				    open(logfile,
9837c478bd9Sstevel@tonic-gate 				    O_APPEND|O_WRONLY, 0644)) < 0) {
9847c478bd9Sstevel@tonic-gate 					logit("Cannot open new logfile "
9857c478bd9Sstevel@tonic-gate 					    "\"%s\": %s\n",
9867c478bd9Sstevel@tonic-gate 					    logfile, strerror(errno));
9877c478bd9Sstevel@tonic-gate 					return (-1);
9887c478bd9Sstevel@tonic-gate 				}
9897c478bd9Sstevel@tonic-gate 			} else {
9907c478bd9Sstevel@tonic-gate 				logit("Cannot use specified logfile "
9917c478bd9Sstevel@tonic-gate 				    "\"%s\": file is/has links or isn't "
9927c478bd9Sstevel@tonic-gate 				    "owned by root\n", logfile);
9937c478bd9Sstevel@tonic-gate 				return (-1);
9947c478bd9Sstevel@tonic-gate 			}
9957c478bd9Sstevel@tonic-gate 		}
9967c478bd9Sstevel@tonic-gate 		(void) strlcpy(ptr->logfile, logfile, sizeof (ptr->logfile));
9977c478bd9Sstevel@tonic-gate 		(void) close(logfd);
9987c478bd9Sstevel@tonic-gate 		logfd = newlogfd;
9997c478bd9Sstevel@tonic-gate 		logit("Starting ldap_cachemgr, logfile %s\n", logfile);
10007c478bd9Sstevel@tonic-gate 	}
10017c478bd9Sstevel@tonic-gate 	return (0);
10027c478bd9Sstevel@tonic-gate }
10037c478bd9Sstevel@tonic-gate 
10047c478bd9Sstevel@tonic-gate /*PRINTFLIKE1*/
10057c478bd9Sstevel@tonic-gate void
10067c478bd9Sstevel@tonic-gate logit(char *format, ...)
10077c478bd9Sstevel@tonic-gate {
10087c478bd9Sstevel@tonic-gate 	static mutex_t	loglock;
10097c478bd9Sstevel@tonic-gate 	struct timeval	tv;
10107c478bd9Sstevel@tonic-gate 	char		buffer[BUFSIZ];
10117c478bd9Sstevel@tonic-gate 	va_list		ap;
10127c478bd9Sstevel@tonic-gate 
10137c478bd9Sstevel@tonic-gate 	va_start(ap, format);
10147c478bd9Sstevel@tonic-gate 
10157c478bd9Sstevel@tonic-gate 	if (logfd >= 0) {
10167c478bd9Sstevel@tonic-gate 		int	safechars;
10177c478bd9Sstevel@tonic-gate 
10187c478bd9Sstevel@tonic-gate 		(void) gettimeofday(&tv, NULL);
10197c478bd9Sstevel@tonic-gate 		(void) ctime_r(&tv.tv_sec, buffer, BUFSIZ);
10207c478bd9Sstevel@tonic-gate 		(void) snprintf(buffer+19, BUFSIZE, ".%.4ld	",
10217c478bd9Sstevel@tonic-gate 		    tv.tv_usec/100);
10227c478bd9Sstevel@tonic-gate 		safechars = sizeof (buffer) - 30;
10237c478bd9Sstevel@tonic-gate 		if (vsnprintf(buffer+25, safechars, format, ap) > safechars)
10247c478bd9Sstevel@tonic-gate 			(void) strcat(buffer, "...\n");
10257c478bd9Sstevel@tonic-gate 		(void) mutex_lock(&loglock);
10267c478bd9Sstevel@tonic-gate 		(void) write(logfd, buffer, strlen(buffer));
10277c478bd9Sstevel@tonic-gate 		(void) mutex_unlock(&loglock);
10287c478bd9Sstevel@tonic-gate 	}
10297c478bd9Sstevel@tonic-gate 	va_end(ap);
10307c478bd9Sstevel@tonic-gate }
10317c478bd9Sstevel@tonic-gate 
10327c478bd9Sstevel@tonic-gate 
10337c478bd9Sstevel@tonic-gate static int
10347c478bd9Sstevel@tonic-gate client_getadmin(admin_t *ptr)
10357c478bd9Sstevel@tonic-gate {
10367c478bd9Sstevel@tonic-gate 	dataunion		u;
10377c478bd9Sstevel@tonic-gate 	ldap_data_t	*dptr;
10387c478bd9Sstevel@tonic-gate 	int		ndata;
10397c478bd9Sstevel@tonic-gate 	int		adata;
10407c478bd9Sstevel@tonic-gate 
10417c478bd9Sstevel@tonic-gate 	u.data.ldap_call.ldap_callnumber = GETADMIN;
10427c478bd9Sstevel@tonic-gate 	ndata = sizeof (u);
10437c478bd9Sstevel@tonic-gate 	adata = sizeof (u.data);
10447c478bd9Sstevel@tonic-gate 	dptr = &u.data;
10457c478bd9Sstevel@tonic-gate 
10467c478bd9Sstevel@tonic-gate 	if (__ns_ldap_trydoorcall(&dptr, &ndata, &adata) != SUCCESS) {
10477c478bd9Sstevel@tonic-gate 		return (-1);
10487c478bd9Sstevel@tonic-gate 	}
10497c478bd9Sstevel@tonic-gate 	(void) memcpy(ptr, dptr->ldap_ret.ldap_u.buff, sizeof (*ptr));
10507c478bd9Sstevel@tonic-gate 
10517c478bd9Sstevel@tonic-gate 	return (0);
10527c478bd9Sstevel@tonic-gate }
10537c478bd9Sstevel@tonic-gate 
10547c478bd9Sstevel@tonic-gate 
10557c478bd9Sstevel@tonic-gate static int
1056*7ddae043Siz202018 setadmin(ldap_call_t *ptr)
10577c478bd9Sstevel@tonic-gate {
10587c478bd9Sstevel@tonic-gate 	admin_t	*new;
10597c478bd9Sstevel@tonic-gate 
10607c478bd9Sstevel@tonic-gate 	new = (admin_t *)ptr->ldap_u.domainname;
10617c478bd9Sstevel@tonic-gate 
10627c478bd9Sstevel@tonic-gate 	/*
10637c478bd9Sstevel@tonic-gate 	 *  global admin stuff
10647c478bd9Sstevel@tonic-gate 	 */
10657c478bd9Sstevel@tonic-gate 
10667c478bd9Sstevel@tonic-gate 	if ((cachemgr_set_lf(&current_admin, new->logfile) < 0) ||
10677c478bd9Sstevel@tonic-gate 	    cachemgr_set_dl(&current_admin, new->debug_level) < 0) {
10687c478bd9Sstevel@tonic-gate 		return (-1);
10697c478bd9Sstevel@tonic-gate 	}
10707c478bd9Sstevel@tonic-gate 
10717c478bd9Sstevel@tonic-gate 	if (cachemgr_set_ttl(&current_admin.ldap_stat,
10727c478bd9Sstevel@tonic-gate 	    "ldap",
10737c478bd9Sstevel@tonic-gate 	    new->ldap_stat.ldap_ttl) < 0) {
10747c478bd9Sstevel@tonic-gate 		return (-1);
10757c478bd9Sstevel@tonic-gate 	}
10767c478bd9Sstevel@tonic-gate 
10777c478bd9Sstevel@tonic-gate 	return (0);
10787c478bd9Sstevel@tonic-gate }
10797c478bd9Sstevel@tonic-gate 
10807c478bd9Sstevel@tonic-gate 
10817c478bd9Sstevel@tonic-gate static void
10827c478bd9Sstevel@tonic-gate client_killserver()
10837c478bd9Sstevel@tonic-gate {
10847c478bd9Sstevel@tonic-gate 	dataunion		u;
10857c478bd9Sstevel@tonic-gate 	ldap_data_t		*dptr;
10867c478bd9Sstevel@tonic-gate 	int			ndata;
10877c478bd9Sstevel@tonic-gate 	int			adata;
10887c478bd9Sstevel@tonic-gate 
10897c478bd9Sstevel@tonic-gate 	u.data.ldap_call.ldap_callnumber = KILLSERVER;
10907c478bd9Sstevel@tonic-gate 	ndata = sizeof (u);
10917c478bd9Sstevel@tonic-gate 	adata = sizeof (ldap_call_t);
10927c478bd9Sstevel@tonic-gate 	dptr = &u.data;
10937c478bd9Sstevel@tonic-gate 
10947c478bd9Sstevel@tonic-gate 	__ns_ldap_trydoorcall(&dptr, &ndata, &adata);
10957c478bd9Sstevel@tonic-gate }
10967c478bd9Sstevel@tonic-gate 
10977c478bd9Sstevel@tonic-gate 
10987c478bd9Sstevel@tonic-gate static int
10997c478bd9Sstevel@tonic-gate client_setadmin(admin_t *ptr)
11007c478bd9Sstevel@tonic-gate {
11017c478bd9Sstevel@tonic-gate 	dataunion		u;
11027c478bd9Sstevel@tonic-gate 	ldap_data_t		*dptr;
11037c478bd9Sstevel@tonic-gate 	int			ndata;
11047c478bd9Sstevel@tonic-gate 	int			adata;
11057c478bd9Sstevel@tonic-gate 
11067c478bd9Sstevel@tonic-gate 	u.data.ldap_call.ldap_callnumber = SETADMIN;
11077c478bd9Sstevel@tonic-gate 	(void) memcpy(u.data.ldap_call.ldap_u.domainname, ptr, sizeof (*ptr));
11087c478bd9Sstevel@tonic-gate 	ndata = sizeof (u);
11097c478bd9Sstevel@tonic-gate 	adata = sizeof (*ptr);
11107c478bd9Sstevel@tonic-gate 	dptr = &u.data;
11117c478bd9Sstevel@tonic-gate 
11127c478bd9Sstevel@tonic-gate 	if (__ns_ldap_trydoorcall(&dptr, &ndata, &adata) != SUCCESS) {
11137c478bd9Sstevel@tonic-gate 		return (-1);
11147c478bd9Sstevel@tonic-gate 	}
11157c478bd9Sstevel@tonic-gate 
11167c478bd9Sstevel@tonic-gate 	return (0);
11177c478bd9Sstevel@tonic-gate }
11187c478bd9Sstevel@tonic-gate 
11197c478bd9Sstevel@tonic-gate static int
11207c478bd9Sstevel@tonic-gate client_showstats(admin_t *ptr)
11217c478bd9Sstevel@tonic-gate {
11227c478bd9Sstevel@tonic-gate 	dataunion	u;
11237c478bd9Sstevel@tonic-gate 	ldap_data_t	*dptr;
11247c478bd9Sstevel@tonic-gate 	int		ndata;
11257c478bd9Sstevel@tonic-gate 	int		adata;
11267c478bd9Sstevel@tonic-gate 	char		*rbuf, *sptr, *rest;
11277c478bd9Sstevel@tonic-gate 
11287c478bd9Sstevel@tonic-gate 	/*
11297c478bd9Sstevel@tonic-gate 	 * print admin data
11307c478bd9Sstevel@tonic-gate 	 */
11317c478bd9Sstevel@tonic-gate 	(void) printf(gettext("\ncachemgr configuration:\n"));
11327c478bd9Sstevel@tonic-gate 	(void) printf(gettext("server debug level %10d\n"), ptr->debug_level);
11337c478bd9Sstevel@tonic-gate 	(void) printf(gettext("server log file\t\"%s\"\n"), ptr->logfile);
11347c478bd9Sstevel@tonic-gate 	(void) printf(gettext("number of calls to ldapcachemgr %10d\n"),
11357c478bd9Sstevel@tonic-gate 	    ptr->ldap_stat.ldap_numbercalls);
11367c478bd9Sstevel@tonic-gate 
11377c478bd9Sstevel@tonic-gate 	/*
11387c478bd9Sstevel@tonic-gate 	 * get cache data statistics
11397c478bd9Sstevel@tonic-gate 	 */
11407c478bd9Sstevel@tonic-gate 	u.data.ldap_call.ldap_callnumber = GETCACHESTAT;
11417c478bd9Sstevel@tonic-gate 	ndata = sizeof (u);
11427c478bd9Sstevel@tonic-gate 	adata = sizeof (ldap_call_t);
11437c478bd9Sstevel@tonic-gate 	dptr = &u.data;
11447c478bd9Sstevel@tonic-gate 
11457c478bd9Sstevel@tonic-gate 	if (__ns_ldap_trydoorcall(&dptr, &ndata, &adata) != SUCCESS) {
11467c478bd9Sstevel@tonic-gate 		(void) printf(
11477c478bd9Sstevel@tonic-gate 		    gettext("\nCache data statistics not available!\n"));
11487c478bd9Sstevel@tonic-gate 		return (0);
11497c478bd9Sstevel@tonic-gate 	}
11507c478bd9Sstevel@tonic-gate 
11517c478bd9Sstevel@tonic-gate 	/*
11527c478bd9Sstevel@tonic-gate 	 * print cache data statistics line by line
11537c478bd9Sstevel@tonic-gate 	 */
11547c478bd9Sstevel@tonic-gate 	(void) printf(gettext("\ncachemgr cache data statistics:\n"));
11557c478bd9Sstevel@tonic-gate 	rbuf = dptr->ldap_ret.ldap_u.buff;
11567c478bd9Sstevel@tonic-gate 	sptr = strtok_r(rbuf, DOORLINESEP, &rest);
11577c478bd9Sstevel@tonic-gate 	for (;;) {
11587c478bd9Sstevel@tonic-gate 		(void) printf("%s\n", sptr);
11597c478bd9Sstevel@tonic-gate 		sptr = strtok_r(NULL, DOORLINESEP, &rest);
11607c478bd9Sstevel@tonic-gate 		if (sptr == NULL)
11617c478bd9Sstevel@tonic-gate 			break;
11627c478bd9Sstevel@tonic-gate 	}
11637c478bd9Sstevel@tonic-gate 	return (0);
11647c478bd9Sstevel@tonic-gate }
11657c478bd9Sstevel@tonic-gate 
11667c478bd9Sstevel@tonic-gate 
11677c478bd9Sstevel@tonic-gate /*
11687c478bd9Sstevel@tonic-gate  * detach from tty
11697c478bd9Sstevel@tonic-gate  */
11707c478bd9Sstevel@tonic-gate static void
11717c478bd9Sstevel@tonic-gate detachfromtty(char *pgm)
11727c478bd9Sstevel@tonic-gate {
11737c478bd9Sstevel@tonic-gate 	int 	status;
11747c478bd9Sstevel@tonic-gate 	pid_t	pid, wret;
11757c478bd9Sstevel@tonic-gate 
11767c478bd9Sstevel@tonic-gate 	(void) close(0);
11777c478bd9Sstevel@tonic-gate 	(void) close(1);
11787c478bd9Sstevel@tonic-gate 	/*
11797c478bd9Sstevel@tonic-gate 	 * Block the SIGUSR1 signal
11807c478bd9Sstevel@tonic-gate 	 * just in case that the child
11817c478bd9Sstevel@tonic-gate 	 * process may run faster than
11827c478bd9Sstevel@tonic-gate 	 * the parent process and
11837c478bd9Sstevel@tonic-gate 	 * send this signal before
11847c478bd9Sstevel@tonic-gate 	 * the signal handler is ready
11857c478bd9Sstevel@tonic-gate 	 * in the parent process.
11867c478bd9Sstevel@tonic-gate 	 * This error will cause the parent
11877c478bd9Sstevel@tonic-gate 	 * to exit with the User Signal 1
11887c478bd9Sstevel@tonic-gate 	 * exit code (144).
11897c478bd9Sstevel@tonic-gate 	 */
11907c478bd9Sstevel@tonic-gate 	(void) sighold(SIGUSR1);
11917c478bd9Sstevel@tonic-gate 	pid = fork1();
11927c478bd9Sstevel@tonic-gate 	switch (pid) {
11937c478bd9Sstevel@tonic-gate 		case (pid_t)-1:
11947c478bd9Sstevel@tonic-gate 			logit("detachfromtty(): fork1() call failed\n");
11957c478bd9Sstevel@tonic-gate 			(void) fprintf(stderr,
11967c478bd9Sstevel@tonic-gate 			    gettext("%s: fork1() call failed.\n"),
11977c478bd9Sstevel@tonic-gate 			    pgm);
11987c478bd9Sstevel@tonic-gate 			syslog(LOG_ERR,
11997c478bd9Sstevel@tonic-gate 			    gettext("ldap_cachemgr: fork1() call failed."));
12007c478bd9Sstevel@tonic-gate 			exit(1);
12017c478bd9Sstevel@tonic-gate 			break;
12027c478bd9Sstevel@tonic-gate 		case 0:
12037c478bd9Sstevel@tonic-gate 			/*
12047c478bd9Sstevel@tonic-gate 			 * child process does not
12057c478bd9Sstevel@tonic-gate 			 * need to worry about
12067c478bd9Sstevel@tonic-gate 			 * the SIGUSR1 signal
12077c478bd9Sstevel@tonic-gate 			 */
12087c478bd9Sstevel@tonic-gate 			(void) sigrelse(SIGUSR1);
12097c478bd9Sstevel@tonic-gate 			(void) close(2);
12107c478bd9Sstevel@tonic-gate 			break;
12117c478bd9Sstevel@tonic-gate 		default:
12127c478bd9Sstevel@tonic-gate 			/*
12137c478bd9Sstevel@tonic-gate 			 * Wait forever until the child process
12147c478bd9Sstevel@tonic-gate 			 * has exited, or has signalled that at
12157c478bd9Sstevel@tonic-gate 			 * least one server in the server list
12167c478bd9Sstevel@tonic-gate 			 * is up.
12177c478bd9Sstevel@tonic-gate 			 */
12187c478bd9Sstevel@tonic-gate 			if (signal(SIGUSR1, sig_ok_to_exit) == SIG_ERR) {
12197c478bd9Sstevel@tonic-gate 				logit("detachfromtty(): "
12207c478bd9Sstevel@tonic-gate 				    "can't set up signal handler to "
12217c478bd9Sstevel@tonic-gate 				    " catch SIGUSR1.\n");
12227c478bd9Sstevel@tonic-gate 				(void) fprintf(stderr,
12237c478bd9Sstevel@tonic-gate 				    gettext("%s: signal() call failed.\n"),
12247c478bd9Sstevel@tonic-gate 				    pgm);
12257c478bd9Sstevel@tonic-gate 				syslog(LOG_ERR, gettext("ldap_cachemgr: "
12267c478bd9Sstevel@tonic-gate 				    "can't set up signal handler to "
12277c478bd9Sstevel@tonic-gate 				    " catch SIGUSR1."));
12287c478bd9Sstevel@tonic-gate 				exit(1);
12297c478bd9Sstevel@tonic-gate 			}
12307c478bd9Sstevel@tonic-gate 
12317c478bd9Sstevel@tonic-gate 			/*
12327c478bd9Sstevel@tonic-gate 			 * now unblock the SIGUSR1 signal
12337c478bd9Sstevel@tonic-gate 			 * to handle the pending or
12347c478bd9Sstevel@tonic-gate 			 * soon to arrive SIGUSR1 signal
12357c478bd9Sstevel@tonic-gate 			 */
12367c478bd9Sstevel@tonic-gate 			(void) sigrelse(SIGUSR1);
12377c478bd9Sstevel@tonic-gate 			wret = waitpid(pid, &status, 0);
12387c478bd9Sstevel@tonic-gate 
12397c478bd9Sstevel@tonic-gate 			if (wret == -1) {
12407c478bd9Sstevel@tonic-gate 				logit("detachfromtty(): "
12417c478bd9Sstevel@tonic-gate 				    "waitpid() call failed\n");
12427c478bd9Sstevel@tonic-gate 				(void) fprintf(stderr,
12437c478bd9Sstevel@tonic-gate 				    gettext("%s: waitpid() call failed.\n"),
12447c478bd9Sstevel@tonic-gate 				    pgm);
12457c478bd9Sstevel@tonic-gate 				syslog(LOG_ERR,
12467c478bd9Sstevel@tonic-gate 				    gettext("ldap_cachemgr: waitpid() "
12477c478bd9Sstevel@tonic-gate 				    "call failed."));
12487c478bd9Sstevel@tonic-gate 				exit(1);
12497c478bd9Sstevel@tonic-gate 			}
12507c478bd9Sstevel@tonic-gate 			if (wret != pid) {
12517c478bd9Sstevel@tonic-gate 				logit("detachfromtty(): "
12527c478bd9Sstevel@tonic-gate 				    "waitpid() returned %ld when "
12537c478bd9Sstevel@tonic-gate 				    "child pid was %ld\n",
12547c478bd9Sstevel@tonic-gate 				    wret, pid);
12557c478bd9Sstevel@tonic-gate 				(void) fprintf(stderr,
12567c478bd9Sstevel@tonic-gate 				    gettext(
12577c478bd9Sstevel@tonic-gate 				    "%s: waitpid() returned %ld when "
12587c478bd9Sstevel@tonic-gate 				    "child pid was %ld.\n"),
12597c478bd9Sstevel@tonic-gate 				    pgm, wret, pid);
12607c478bd9Sstevel@tonic-gate 				syslog(LOG_ERR,
12617c478bd9Sstevel@tonic-gate 				    gettext("ldap_cachemgr: waitpid() "
12627c478bd9Sstevel@tonic-gate 				    "returned different "
12637c478bd9Sstevel@tonic-gate 				    "child pid."));
12647c478bd9Sstevel@tonic-gate 				exit(1);
12657c478bd9Sstevel@tonic-gate 			}
12667c478bd9Sstevel@tonic-gate 
12677c478bd9Sstevel@tonic-gate 			/* evaluate return status */
12687c478bd9Sstevel@tonic-gate 			if (WIFEXITED(status)) {
12697c478bd9Sstevel@tonic-gate 				if (WEXITSTATUS(status) == 0) {
12707c478bd9Sstevel@tonic-gate 					exit(0);
12717c478bd9Sstevel@tonic-gate 				}
12727c478bd9Sstevel@tonic-gate 				logit("detachfromtty(): "
12737c478bd9Sstevel@tonic-gate 				    "child failed (rc = %d).\n",
12747c478bd9Sstevel@tonic-gate 				    WEXITSTATUS(status));
12757c478bd9Sstevel@tonic-gate 				(void) fprintf(stderr,
12767c478bd9Sstevel@tonic-gate 				    gettext("%s: failed. Please see "
12777c478bd9Sstevel@tonic-gate 				    "syslog for details.\n"),
12787c478bd9Sstevel@tonic-gate 				    pgm);
12797c478bd9Sstevel@tonic-gate 				syslog(LOG_ERR,
12807c478bd9Sstevel@tonic-gate 				    gettext("ldap_cachemgr: failed "
12817c478bd9Sstevel@tonic-gate 				    "(rc = %d)."),
12827c478bd9Sstevel@tonic-gate 				    WEXITSTATUS(status));
12837c478bd9Sstevel@tonic-gate 			} else if (WIFSIGNALED(status)) {
12847c478bd9Sstevel@tonic-gate 				logit("detachfromtty(): "
12857c478bd9Sstevel@tonic-gate 				    "child terminated by signal %d.\n",
12867c478bd9Sstevel@tonic-gate 				    WTERMSIG(status));
12877c478bd9Sstevel@tonic-gate 				(void) fprintf(stderr,
12887c478bd9Sstevel@tonic-gate 				gettext("%s: terminated by signal %d.\n"),
12897c478bd9Sstevel@tonic-gate 				    pgm, WTERMSIG(status));
12907c478bd9Sstevel@tonic-gate 				syslog(LOG_ERR,
12917c478bd9Sstevel@tonic-gate 				    gettext("ldap_cachemgr: terminated by "
12927c478bd9Sstevel@tonic-gate 				    "signal %d.\n"),
12937c478bd9Sstevel@tonic-gate 				    WTERMSIG(status));
12947c478bd9Sstevel@tonic-gate 			} else if (WCOREDUMP(status)) {
12957c478bd9Sstevel@tonic-gate 				logit("detachfromtty(): child core dumped.\n"),
12967c478bd9Sstevel@tonic-gate 				    (void) fprintf(stderr,
12977c478bd9Sstevel@tonic-gate 				    gettext("%s: core dumped.\n"),
12987c478bd9Sstevel@tonic-gate 				    pgm);
12997c478bd9Sstevel@tonic-gate 				syslog(LOG_ERR,
13007c478bd9Sstevel@tonic-gate 				    gettext("ldap_cachemgr: "
13017c478bd9Sstevel@tonic-gate 				    "core dumped.\n"));
13027c478bd9Sstevel@tonic-gate 			}
13037c478bd9Sstevel@tonic-gate 
13047c478bd9Sstevel@tonic-gate 			exit(1);
13057c478bd9Sstevel@tonic-gate 	}
13067c478bd9Sstevel@tonic-gate 	(void) setsid();
13077c478bd9Sstevel@tonic-gate 	if (open("/dev/null", O_RDWR, 0) != -1) {
13087c478bd9Sstevel@tonic-gate 		(void) dup(0);
13097c478bd9Sstevel@tonic-gate 		(void) dup(0);
13107c478bd9Sstevel@tonic-gate 	}
13117c478bd9Sstevel@tonic-gate }
1312