2012-09-26 16:53:48 -07:00
/*
2002-01-30 06:08:46 +00:00
Unix SMB / CIFS implementation .
2000-05-09 11:43:00 +00:00
Winbind daemon for ntdom nss module
2002-11-07 07:17:09 +00:00
Copyright ( C ) by Tim Potter 2000 - 2002
2002-07-15 10:35:28 +00:00
Copyright ( C ) Andrew Tridgell 2002
2003-04-14 03:53:58 +00:00
Copyright ( C ) Jelmer Vernooij 2003
2005-06-08 22:10:34 +00:00
Copyright ( C ) Volker Lendecke 2004
2008-11-26 14:01:22 +01:00
2000-05-09 11:43:00 +00:00
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-09 19:25:36 +00:00
the Free Software Foundation ; either version 3 of the License , or
2000-05-09 11:43:00 +00:00
( at your option ) any later version .
2008-11-26 14:01:22 +01:00
2000-05-09 11:43:00 +00:00
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
2008-11-26 14:01:22 +01:00
2000-05-09 11:43:00 +00:00
You should have received a copy of the GNU General Public License
2007-07-10 00:52:41 +00:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
2000-05-09 11:43:00 +00:00
*/
2003-11-12 01:51:10 +00:00
# include "includes.h"
2010-08-05 10:49:53 +02:00
# include "popt_common.h"
2000-05-09 11:43:00 +00:00
# include "winbindd.h"
2010-08-18 12:42:49 +02:00
# include "nsswitch/winbind_client.h"
2011-02-17 00:43:05 +01:00
# include "nsswitch/wb_reqtrans.h"
2011-05-02 13:21:53 +02:00
# include "ntdomain.h"
2010-07-02 10:17:44 +02:00
# include "../librpc/gen_ndr/srv_lsa.h"
# include "../librpc/gen_ndr/srv_samr.h"
2010-08-05 02:25:37 +02:00
# include "secrets.h"
2013-12-17 20:06:14 +01:00
# include "rpc_client/cli_netlogon.h"
2010-08-18 18:13:42 +02:00
# include "idmap.h"
2011-01-31 17:25:55 +01:00
# include "lib/addrchange.h"
2011-03-25 02:28:05 +01:00
# include "auth.h"
2011-03-24 15:31:06 +01:00
# include "messages.h"
2012-07-19 16:36:18 -07:00
# include "../lib/util/pidfile.h"
2013-10-17 15:16:19 +02:00
# include "util_cluster.h"
2014-05-06 13:39:12 +12:00
# include "source4/lib/messaging/irpc.h"
# include "source4/lib/messaging/messaging.h"
# include "lib/param/param.h"
2015-06-25 08:59:20 +03:00
# include "lib/async_req/async_sock.h"
2016-11-29 15:41:27 +00:00
# include "libsmb/samlogon_cache.h"
2017-07-24 16:12:45 -07:00
# include "libcli/auth/netlogon_creds_cli.h"
2000-05-09 11:43:00 +00:00
2006-04-20 13:51:43 +00:00
# undef DBGC_CLASS
# define DBGC_CLASS DBGC_WINBIND
2015-07-06 21:29:17 +03:00
# define SCRUB_CLIENTS_INTERVAL 5
2010-08-23 00:53:40 +01:00
static bool client_is_idle ( struct winbindd_cli_state * state ) ;
2009-05-25 20:28:38 +02:00
static void remove_client ( struct winbindd_cli_state * state ) ;
2015-06-22 06:38:04 +03:00
static void winbindd_setup_max_fds ( void ) ;
2009-05-25 20:28:38 +02:00
2009-03-12 10:12:58 +01:00
static bool opt_nocache = False ;
2007-10-18 17:40:25 -07:00
static bool interactive = False ;
2000-05-09 11:43:00 +00:00
2007-10-18 17:40:25 -07:00
extern bool override_logfile ;
2004-09-21 09:07:42 +00:00
2014-05-06 13:39:12 +12:00
struct imessaging_context * winbind_imessaging_context ( void )
{
static struct imessaging_context * msg = NULL ;
2015-10-12 17:21:55 +02:00
struct messaging_context * msg_ctx ;
struct server_id myself ;
2014-05-06 13:39:12 +12:00
struct loadparm_context * lp_ctx ;
if ( msg ! = NULL ) {
return msg ;
}
2015-10-12 17:21:55 +02:00
msg_ctx = server_messaging_context ( ) ;
if ( msg_ctx = = NULL ) {
smb_panic ( " server_messaging_context failed \n " ) ;
}
myself = messaging_server_id ( msg_ctx ) ;
2014-05-06 13:39:12 +12:00
lp_ctx = loadparm_init_s3 ( NULL , loadparm_s3_helpers ( ) ) ;
if ( lp_ctx = = NULL ) {
smb_panic ( " Could not load smb.conf to init winbindd's imessaging context. \n " ) ;
}
/*
* Note we MUST use the NULL context here , not the autofree context ,
* to avoid side effects in forked children exiting .
*/
2017-11-17 11:35:19 +01:00
msg = imessaging_init ( NULL , lp_ctx , myself , server_event_context ( ) ) ;
2014-05-06 13:39:12 +12:00
talloc_unlink ( NULL , lp_ctx ) ;
if ( msg = = NULL ) {
smb_panic ( " Could not init winbindd's messaging context. \n " ) ;
}
return msg ;
}
2000-05-09 11:43:00 +00:00
/* Reload configuration */
2008-11-03 12:36:34 -08:00
static bool reload_services_file ( const char * lfile )
2000-05-09 11:43:00 +00:00
{
2007-10-18 17:40:25 -07:00
bool ret ;
2000-05-09 11:43:00 +00:00
2001-05-07 04:32:40 +00:00
if ( lp_loaded ( ) ) {
2014-01-15 17:29:57 +13:00
char * fname = lp_next_configfile ( talloc_tos ( ) ) ;
2001-05-07 04:32:40 +00:00
2008-10-17 12:48:19 +02:00
if ( file_exist ( fname ) & & ! strcsequal ( fname , get_dyn_CONFIGFILE ( ) ) ) {
2007-12-10 11:30:37 -08:00
set_dyn_CONFIGFILE ( fname ) ;
2001-05-07 04:32:40 +00:00
}
2012-05-31 15:06:58 -07:00
TALLOC_FREE ( fname ) ;
2001-05-07 04:32:40 +00:00
}
2008-07-17 20:10:18 -07:00
/* if this is a child, restore the logfile to the special
name - < domain > , idmap , etc . */
2008-11-03 12:36:34 -08:00
if ( lfile & & * lfile ) {
lp_set_logfile ( lfile ) ;
2008-07-17 20:10:18 -07:00
}
2000-05-09 11:43:00 +00:00
reopen_logs ( ) ;
2011-07-28 11:04:53 +02:00
ret = lp_load_global ( get_dyn_CONFIGFILE ( ) ) ;
2000-05-09 11:43:00 +00:00
reopen_logs ( ) ;
load_interfaces ( ) ;
2015-06-22 06:38:04 +03:00
winbindd_setup_max_fds ( ) ;
2000-05-09 11:43:00 +00:00
return ( ret ) ;
}
2003-07-15 17:21:21 +00:00
2001-11-14 06:18:13 +00:00
static void winbindd_status ( void )
2000-05-09 11:43:00 +00:00
{
2001-05-07 04:32:40 +00:00
struct winbindd_cli_state * tmp ;
2001-11-14 06:18:13 +00:00
DEBUG ( 0 , ( " winbindd status: \n " ) ) ;
2001-05-07 04:32:40 +00:00
/* Print client state information */
2008-11-26 14:01:22 +01:00
2002-11-02 01:36:42 +00:00
DEBUG ( 0 , ( " \t %d clients currently active \n " , winbindd_num_clients ( ) ) ) ;
2008-11-26 14:01:22 +01:00
2002-11-02 01:36:42 +00:00
if ( DEBUGLEVEL > = 2 & & winbindd_num_clients ( ) ) {
2001-05-07 04:32:40 +00:00
DEBUG ( 2 , ( " \t client list: \n " ) ) ;
2002-11-02 01:36:42 +00:00
for ( tmp = winbindd_client_list ( ) ; tmp ; tmp = tmp - > next ) {
2010-08-23 00:53:40 +01:00
DEBUGADD ( 2 , ( " \t \t pid %lu, sock %d (%s) \n " ,
( unsigned long ) tmp - > pid , tmp - > sock ,
client_is_idle ( tmp ) ? " idle " : " active " ) ) ;
2001-05-07 04:32:40 +00:00
}
}
}
2000-05-09 11:43:00 +00:00
/* Flush client cache */
2001-11-15 03:23:15 +00:00
static void flush_caches ( void )
2000-05-09 11:43:00 +00:00
{
2003-06-21 04:05:01 +00:00
/* We need to invalidate cached user list entries on a SIGHUP
otherwise cached access denied errors due to restrict anonymous
hang around until the sequence number changes . */
2008-01-07 10:59:14 +01:00
if ( ! wcache_invalidate_cache ( ) ) {
2007-11-26 11:44:30 +01:00
DEBUG ( 0 , ( " invalidating the cache failed; revalidate the cache \n " ) ) ;
2008-04-10 11:53:53 +02:00
if ( ! winbindd_cache_validate_and_initialize ( ) ) {
2007-11-26 11:44:30 +01:00
exit ( 1 ) ;
}
}
2000-05-09 11:43:00 +00:00
}
2010-02-09 16:35:40 +08:00
static void flush_caches_noinit ( void )
{
/*
* We need to invalidate cached user list entries on a SIGHUP
* otherwise cached access denied errors due to restrict anonymous
* hang around until the sequence number changes .
* NB
* Skip uninitialized domains when flush cache .
* If domain is not initialized , it means it is never
* used or never become online . look , wcache_invalidate_cache ( )
* - > get_cache ( ) - > init_dc_connection ( ) . It causes a lot of traffic
* for unused domains and large traffic for primay domain ' s DC if there
* are many domains . .
*/
if ( ! wcache_invalidate_cache_noinit ( ) ) {
DEBUG ( 0 , ( " invalidating the cache failed; revalidate the cache \n " ) ) ;
if ( ! winbindd_cache_validate_and_initialize ( ) ) {
exit ( 1 ) ;
}
}
}
2000-05-09 11:43:00 +00:00
/* Handle the signal by unlinking socket and exiting */
2008-05-30 17:52:54 -07:00
static void terminate ( bool is_parent )
2000-05-09 11:43:00 +00:00
{
2008-05-30 17:52:54 -07:00
if ( is_parent ) {
/* When parent goes away we should
* remove the socket file . Not so
* when children terminate .
*/
char * path = NULL ;
2007-10-10 15:34:30 -05:00
2008-05-30 17:52:54 -07:00
if ( asprintf ( & path , " %s/%s " ,
2013-10-11 13:34:13 +13:00
lp_winbindd_socket_directory ( ) , WINBINDD_SOCKET_NAME ) > 0 ) {
2008-05-30 17:52:54 -07:00
unlink ( path ) ;
SAFE_FREE ( path ) ;
}
2007-11-20 17:18:16 -08:00
}
2005-06-08 22:10:34 +00:00
2007-02-20 19:57:14 +00:00
idmap_close ( ) ;
2008-11-26 14:01:22 +01:00
2009-07-13 17:04:29 +02:00
gencache_stabilize ( ) ;
2017-07-24 16:12:45 -07:00
netlogon_creds_cli_close_global_db ( ) ;
2005-06-08 22:10:34 +00:00
#if 0
if ( interactive ) {
TALLOC_CTX * mem_ctx = talloc_init ( " end_description " ) ;
char * description = talloc_describe_all ( mem_ctx ) ;
DEBUG ( 3 , ( " tallocs left: \n %s \n " , description ) ) ;
talloc_destroy ( mem_ctx ) ;
}
# endif
2009-06-18 11:45:57 +02:00
if ( is_parent ) {
2014-02-03 15:57:21 +13:00
pidfile_unlink ( lp_pid_directory ( ) , " winbindd " ) ;
2009-06-18 11:45:57 +02:00
}
2001-05-07 04:32:40 +00:00
exit ( 0 ) ;
}
2000-05-09 11:43:00 +00:00
2009-01-22 14:54:21 +01:00
static void winbindd_sig_term_handler ( struct tevent_context * ev ,
struct tevent_signal * se ,
int signum ,
int count ,
void * siginfo ,
void * private_data )
{
bool * is_parent = talloc_get_type_abort ( private_data , bool ) ;
DEBUG ( 0 , ( " Got sig[%d] terminate (is_parent=%d) \n " ,
signum , ( int ) * is_parent ) ) ;
terminate ( * is_parent ) ;
}
2001-11-14 21:49:30 +00:00
2012-03-02 18:22:10 +11:00
/*
handle stdin becoming readable when we are in - - foreground mode
*/
static void winbindd_stdin_handler ( struct tevent_context * ev ,
struct tevent_fd * fde ,
uint16_t flags ,
void * private_data )
{
char c ;
if ( read ( 0 , & c , 1 ) ! = 1 ) {
bool * is_parent = talloc_get_type_abort ( private_data , bool ) ;
2012-09-26 16:53:48 -07:00
2012-03-02 18:22:10 +11:00
/* we have reached EOF on stdin, which means the
parent has exited . Shutdown the server */
DEBUG ( 0 , ( " EOF on stdin (is_parent=%d) \n " ,
( int ) * is_parent ) ) ;
terminate ( * is_parent ) ;
}
}
2009-01-22 14:54:21 +01:00
bool winbindd_setup_sig_term_handler ( bool parent )
2001-11-14 21:49:30 +00:00
{
2009-01-22 14:54:21 +01:00
struct tevent_signal * se ;
bool * is_parent ;
2017-11-17 11:35:19 +01:00
is_parent = talloc ( server_event_context ( ) , bool ) ;
2009-01-22 14:54:21 +01:00
if ( ! is_parent ) {
return false ;
}
* is_parent = parent ;
2017-11-17 11:35:19 +01:00
se = tevent_add_signal ( server_event_context ( ) ,
2009-01-22 14:54:21 +01:00
is_parent ,
SIGTERM , 0 ,
winbindd_sig_term_handler ,
is_parent ) ;
if ( ! se ) {
DEBUG ( 0 , ( " failed to setup SIGTERM handler " ) ) ;
talloc_free ( is_parent ) ;
return false ;
}
2017-11-17 11:35:19 +01:00
se = tevent_add_signal ( server_event_context ( ) ,
2009-01-22 14:54:21 +01:00
is_parent ,
SIGINT , 0 ,
winbindd_sig_term_handler ,
is_parent ) ;
if ( ! se ) {
DEBUG ( 0 , ( " failed to setup SIGINT handler " ) ) ;
talloc_free ( is_parent ) ;
return false ;
}
2017-11-17 11:35:19 +01:00
se = tevent_add_signal ( server_event_context ( ) ,
2009-01-22 14:54:21 +01:00
is_parent ,
SIGQUIT , 0 ,
winbindd_sig_term_handler ,
is_parent ) ;
if ( ! se ) {
DEBUG ( 0 , ( " failed to setup SIGINT handler " ) ) ;
talloc_free ( is_parent ) ;
return false ;
}
return true ;
2001-11-14 21:49:30 +00:00
}
2012-03-02 18:22:10 +11:00
bool winbindd_setup_stdin_handler ( bool parent , bool foreground )
{
bool * is_parent ;
if ( foreground ) {
2013-06-10 13:33:40 -07:00
struct stat st ;
2017-11-17 11:35:19 +01:00
is_parent = talloc ( server_event_context ( ) , bool ) ;
2012-03-02 18:22:10 +11:00
if ( ! is_parent ) {
return false ;
}
2012-09-26 16:53:48 -07:00
2012-03-02 18:22:10 +11:00
* is_parent = parent ;
/* if we are running in the foreground then look for
EOF on stdin , and exit if it happens . This allows
us to die if the parent process dies
2013-06-10 13:33:40 -07:00
Only do this on a pipe or socket , no other device .
2012-03-02 18:22:10 +11:00
*/
2013-06-10 13:33:40 -07:00
if ( fstat ( 0 , & st ) ! = 0 ) {
return false ;
}
if ( S_ISFIFO ( st . st_mode ) | | S_ISSOCK ( st . st_mode ) ) {
2017-11-17 11:35:19 +01:00
tevent_add_fd ( server_event_context ( ) ,
2013-06-10 13:33:40 -07:00
is_parent ,
0 ,
TEVENT_FD_READ ,
winbindd_stdin_handler ,
is_parent ) ;
}
2012-03-02 18:22:10 +11:00
}
2012-09-26 16:53:48 -07:00
2012-03-02 18:22:10 +11:00
return true ;
}
2009-01-22 14:54:21 +01:00
static void winbindd_sig_hup_handler ( struct tevent_context * ev ,
struct tevent_signal * se ,
int signum ,
int count ,
void * siginfo ,
void * private_data )
{
const char * file = ( const char * ) private_data ;
DEBUG ( 1 , ( " Reloading services after SIGHUP \n " ) ) ;
2010-02-09 16:35:40 +08:00
flush_caches_noinit ( ) ;
2009-01-22 14:54:21 +01:00
reload_services_file ( file ) ;
}
2000-05-09 11:43:00 +00:00
2009-01-22 14:54:21 +01:00
bool winbindd_setup_sig_hup_handler ( const char * lfile )
2001-05-07 04:32:40 +00:00
{
2009-01-22 14:54:21 +01:00
struct tevent_signal * se ;
char * file = NULL ;
if ( lfile ) {
2017-11-17 11:35:19 +01:00
file = talloc_strdup ( server_event_context ( ) ,
2009-01-22 14:54:21 +01:00
lfile ) ;
if ( ! file ) {
return false ;
}
}
2017-11-17 11:35:19 +01:00
se = tevent_add_signal ( server_event_context ( ) ,
server_event_context ( ) ,
2009-01-22 14:54:21 +01:00
SIGHUP , 0 ,
winbindd_sig_hup_handler ,
file ) ;
if ( ! se ) {
return false ;
}
return true ;
2000-05-09 11:43:00 +00:00
}
2009-01-22 14:54:21 +01:00
static void winbindd_sig_chld_handler ( struct tevent_context * ev ,
struct tevent_signal * se ,
int signum ,
int count ,
void * siginfo ,
void * private_data )
{
pid_t pid ;
2016-02-16 15:46:06 +01:00
while ( ( pid = waitpid ( - 1 , NULL , WNOHANG ) ) > 0 ) {
2009-01-22 14:54:21 +01:00
winbind_child_died ( pid ) ;
}
}
2000-05-09 11:43:00 +00:00
2009-01-22 14:54:21 +01:00
static bool winbindd_setup_sig_chld_handler ( void )
2000-05-09 11:43:00 +00:00
{
2009-01-22 14:54:21 +01:00
struct tevent_signal * se ;
2017-11-17 11:35:19 +01:00
se = tevent_add_signal ( server_event_context ( ) ,
server_event_context ( ) ,
2009-01-22 14:54:21 +01:00
SIGCHLD , 0 ,
winbindd_sig_chld_handler ,
NULL ) ;
if ( ! se ) {
return false ;
}
return true ;
2000-05-09 11:43:00 +00:00
}
2009-01-22 14:54:21 +01:00
static void winbindd_sig_usr2_handler ( struct tevent_context * ev ,
struct tevent_signal * se ,
int signum ,
int count ,
void * siginfo ,
void * private_data )
{
2010-08-23 00:53:39 +01:00
winbindd_status ( ) ;
2009-01-22 14:54:21 +01:00
}
2005-06-08 22:10:34 +00:00
2009-01-22 14:54:21 +01:00
static bool winbindd_setup_sig_usr2_handler ( void )
2004-07-21 04:24:30 +00:00
{
2009-01-22 14:54:21 +01:00
struct tevent_signal * se ;
2017-11-17 11:35:19 +01:00
se = tevent_add_signal ( server_event_context ( ) ,
server_event_context ( ) ,
2009-03-04 17:26:57 -08:00
SIGUSR2 , 0 ,
2009-01-22 14:54:21 +01:00
winbindd_sig_usr2_handler ,
NULL ) ;
if ( ! se ) {
return false ;
}
return true ;
2004-07-21 04:24:30 +00:00
}
2003-07-15 17:21:21 +00:00
/* React on 'smbcontrol winbindd reload-config' in the same way as on SIGHUP*/
2007-05-16 14:45:09 +00:00
static void msg_reload_services ( struct messaging_context * msg ,
void * private_data ,
uint32_t msg_type ,
struct server_id server_id ,
DATA_BLOB * data )
2003-07-15 17:21:21 +00:00
{
/* Flush various caches */
flush_caches ( ) ;
2008-07-17 20:10:18 -07:00
reload_services_file ( ( const char * ) private_data ) ;
2003-07-15 17:21:21 +00:00
}
/* React on 'smbcontrol winbindd shutdown' in the same way as on SIGTERM*/
2007-05-16 14:45:09 +00:00
static void msg_shutdown ( struct messaging_context * msg ,
void * private_data ,
uint32_t msg_type ,
struct server_id server_id ,
DATA_BLOB * data )
2003-07-15 17:21:21 +00:00
{
2009-01-22 14:54:21 +01:00
/* only the parent waits for this message */
DEBUG ( 0 , ( " Got shutdown message \n " ) ) ;
terminate ( true ) ;
2003-07-15 17:21:21 +00:00
}
2007-08-31 15:24:43 +00:00
static void winbind_msg_validate_cache ( struct messaging_context * msg_ctx ,
void * private_data ,
uint32_t msg_type ,
struct server_id server_id ,
DATA_BLOB * data )
{
2015-05-02 21:07:06 -07:00
uint8_t ret ;
2007-09-02 00:32:57 +00:00
pid_t child_pid ;
2011-04-29 12:53:13 +02:00
NTSTATUS status ;
2007-08-31 15:24:43 +00:00
DEBUG ( 10 , ( " winbindd_msg_validate_cache: got validate-cache "
" message. \n " ) ) ;
2007-09-02 00:32:57 +00:00
/*
* call the validation code from a child :
* so we don ' t block the main winbindd and the validation
* code can safely use fork / waitpid . . .
*/
2012-03-24 20:17:08 +01:00
child_pid = fork ( ) ;
2007-09-02 00:32:57 +00:00
if ( child_pid = = - 1 ) {
DEBUG ( 1 , ( " winbind_msg_validate_cache: Could not fork: %s \n " ,
strerror ( errno ) ) ) ;
return ;
}
if ( child_pid ! = 0 ) {
/* parent */
DEBUG ( 5 , ( " winbind_msg_validate_cache: child created with "
2009-02-23 16:22:43 -08:00
" pid %d. \n " , ( int ) child_pid ) ) ;
2007-09-02 00:32:57 +00:00
return ;
}
/* child */
2011-04-29 12:53:13 +02:00
status = winbindd_reinit_after_fork ( NULL , NULL ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 1 , ( " winbindd_reinit_after_fork failed: %s \n " ,
nt_errstr ( status ) ) ) ;
2010-04-01 16:23:06 +02:00
_exit ( 0 ) ;
}
2007-09-02 00:32:57 +00:00
2010-04-08 12:45:54 +02:00
/* install default SIGCHLD handler: validation code uses fork/waitpid */
CatchSignal ( SIGCHLD , SIG_DFL ) ;
2017-12-20 17:42:45 +01:00
setproctitle ( " validate cache child " ) ;
2015-05-02 21:07:06 -07:00
ret = ( uint8_t ) winbindd_validate_cache_nobackup ( ) ;
2007-08-31 15:24:43 +00:00
DEBUG ( 10 , ( " winbindd_msg_validata_cache: got return value %d \n " , ret ) ) ;
messaging_send_buf ( msg_ctx , server_id , MSG_WINBIND_VALIDATE_CACHE , & ret ,
( size_t ) 1 ) ;
2007-09-02 00:32:57 +00:00
_exit ( 0 ) ;
2007-08-31 15:24:43 +00:00
}
2005-06-20 13:42:29 +00:00
static struct winbindd_dispatch_table {
enum winbindd_cmd cmd ;
void ( * fn ) ( struct winbindd_cli_state * state ) ;
const char * winbindd_cmd_name ;
} dispatch_table [ ] = {
2008-11-26 14:01:22 +01:00
2001-05-07 04:32:40 +00:00
/* Enumeration functions */
2000-05-09 11:43:00 +00:00
2005-06-08 22:10:34 +00:00
{ WINBINDD_LIST_TRUSTDOM , winbindd_list_trusted_domains ,
" LIST_TRUSTDOM " } ,
2000-05-09 11:43:00 +00:00
2001-05-07 04:32:40 +00:00
/* Miscellaneous */
2000-05-09 11:43:00 +00:00
2002-01-10 11:28:14 +00:00
{ WINBINDD_INFO , winbindd_info , " INFO " } ,
2005-06-08 22:10:34 +00:00
{ WINBINDD_INTERFACE_VERSION , winbindd_interface_version ,
" INTERFACE_VERSION " } ,
2002-01-26 09:55:38 +00:00
{ WINBINDD_DOMAIN_NAME , winbindd_domain_name , " DOMAIN_NAME " } ,
2004-01-04 11:51:31 +00:00
{ WINBINDD_DOMAIN_INFO , winbindd_domain_info , " DOMAIN_INFO " } ,
2011-01-10 17:25:00 +01:00
{ WINBINDD_DC_INFO , winbindd_dc_info , " DC_INFO " } ,
2003-01-28 12:07:02 +00:00
{ WINBINDD_NETBIOS_NAME , winbindd_netbios_name , " NETBIOS_NAME " } ,
2005-06-08 22:10:34 +00:00
{ WINBINDD_PRIV_PIPE_DIR , winbindd_priv_pipe_dir ,
" WINBINDD_PRIV_PIPE_DIR " } ,
2000-05-09 11:43:00 +00:00
2006-08-19 01:04:54 +00:00
/* Credential cache access */
{ WINBINDD_CCACHE_NTLMAUTH , winbindd_ccache_ntlm_auth , " NTLMAUTH " } ,
2010-01-09 20:20:36 +01:00
{ WINBINDD_CCACHE_SAVE , winbindd_ccache_save , " CCACHE_SAVE " } ,
2006-08-19 01:04:54 +00:00
2001-05-07 04:32:40 +00:00
/* End of list */
2000-05-09 11:43:00 +00:00
2001-11-14 04:44:36 +00:00
{ WINBINDD_NUM_CMDS , NULL , " NONE " }
2001-05-07 04:32:40 +00:00
} ;
2000-05-09 11:43:00 +00:00
2009-05-16 12:00:07 +02:00
struct winbindd_async_dispatch_table {
enum winbindd_cmd cmd ;
const char * cmd_name ;
struct tevent_req * ( * send_req ) ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
2009-08-16 12:46:55 +02:00
struct winbindd_cli_state * cli ,
2009-05-16 12:00:07 +02:00
struct winbindd_request * request ) ;
2009-07-31 16:16:24 +02:00
NTSTATUS ( * recv_req ) ( struct tevent_req * req ,
struct winbindd_response * presp ) ;
2009-05-16 12:00:07 +02:00
} ;
static struct winbindd_async_dispatch_table async_nonpriv_table [ ] = {
2009-05-16 12:00:34 +02:00
{ WINBINDD_PING , " PING " ,
wb_ping_send , wb_ping_recv } ,
2009-08-04 06:57:13 -04:00
{ WINBINDD_LOOKUPSID , " LOOKUPSID " ,
winbindd_lookupsid_send , winbindd_lookupsid_recv } ,
2011-03-08 14:31:44 +01:00
{ WINBINDD_LOOKUPSIDS , " LOOKUPSIDS " ,
winbindd_lookupsids_send , winbindd_lookupsids_recv } ,
2009-08-04 07:29:03 -04:00
{ WINBINDD_LOOKUPNAME , " LOOKUPNAME " ,
winbindd_lookupname_send , winbindd_lookupname_recv } ,
2011-03-23 18:29:45 +01:00
{ WINBINDD_SIDS_TO_XIDS , " SIDS_TO_XIDS " ,
winbindd_sids_to_xids_send , winbindd_sids_to_xids_recv } ,
2015-08-14 17:15:33 +02:00
{ WINBINDD_XIDS_TO_SIDS , " XIDS_TO_SIDS " ,
winbindd_xids_to_sids_send , winbindd_xids_to_sids_recv } ,
2009-08-04 15:35:24 -04:00
{ WINBINDD_GETPWSID , " GETPWSID " ,
winbindd_getpwsid_send , winbindd_getpwsid_recv } ,
2009-08-04 15:37:54 -04:00
{ WINBINDD_GETPWNAM , " GETPWNAM " ,
winbindd_getpwnam_send , winbindd_getpwnam_recv } ,
2009-08-04 15:41:40 -04:00
{ WINBINDD_GETPWUID , " GETPWUID " ,
winbindd_getpwuid_send , winbindd_getpwuid_recv } ,
2009-08-04 15:58:45 -04:00
{ WINBINDD_GETSIDALIASES , " GETSIDALIASES " ,
winbindd_getsidaliases_send , winbindd_getsidaliases_recv } ,
2009-08-04 16:20:18 -04:00
{ WINBINDD_GETUSERDOMGROUPS , " GETUSERDOMGROUPS " ,
winbindd_getuserdomgroups_send , winbindd_getuserdomgroups_recv } ,
2009-08-04 16:26:07 -04:00
{ WINBINDD_GETGROUPS , " GETGROUPS " ,
winbindd_getgroups_send , winbindd_getgroups_recv } ,
2009-08-15 13:23:57 +02:00
{ WINBINDD_SHOW_SEQUENCE , " SHOW_SEQUENCE " ,
winbindd_show_sequence_send , winbindd_show_sequence_recv } ,
2009-08-16 12:13:00 +02:00
{ WINBINDD_GETGRGID , " GETGRGID " ,
winbindd_getgrgid_send , winbindd_getgrgid_recv } ,
2009-08-16 12:23:31 +02:00
{ WINBINDD_GETGRNAM , " GETGRNAM " ,
winbindd_getgrnam_send , winbindd_getgrnam_recv } ,
2009-08-27 14:55:41 +02:00
{ WINBINDD_GETUSERSIDS , " GETUSERSIDS " ,
winbindd_getusersids_send , winbindd_getusersids_recv } ,
2009-08-27 17:11:24 +02:00
{ WINBINDD_LOOKUPRIDS , " LOOKUPRIDS " ,
winbindd_lookuprids_send , winbindd_lookuprids_recv } ,
2009-08-17 23:13:48 +02:00
{ WINBINDD_SETPWENT , " SETPWENT " ,
winbindd_setpwent_send , winbindd_setpwent_recv } ,
{ WINBINDD_GETPWENT , " GETPWENT " ,
winbindd_getpwent_send , winbindd_getpwent_recv } ,
{ WINBINDD_ENDPWENT , " ENDPWENT " ,
winbindd_endpwent_send , winbindd_endpwent_recv } ,
2009-08-25 23:02:44 +02:00
{ WINBINDD_DSGETDCNAME , " DSGETDCNAME " ,
winbindd_dsgetdcname_send , winbindd_dsgetdcname_recv } ,
2009-08-26 12:27:32 +02:00
{ WINBINDD_GETDCNAME , " GETDCNAME " ,
winbindd_getdcname_send , winbindd_getdcname_recv } ,
2009-08-27 23:33:45 +02:00
{ WINBINDD_SETGRENT , " SETGRENT " ,
winbindd_setgrent_send , winbindd_setgrent_recv } ,
{ WINBINDD_GETGRENT , " GETGRENT " ,
winbindd_getgrent_send , winbindd_getgrent_recv } ,
{ WINBINDD_ENDGRENT , " ENDGRENT " ,
winbindd_endgrent_send , winbindd_endgrent_recv } ,
2009-08-29 16:05:02 +02:00
{ WINBINDD_LIST_USERS , " LIST_USERS " ,
winbindd_list_users_send , winbindd_list_users_recv } ,
2009-08-29 17:17:47 +02:00
{ WINBINDD_LIST_GROUPS , " LIST_GROUPS " ,
winbindd_list_groups_send , winbindd_list_groups_recv } ,
2009-09-06 09:32:34 +02:00
{ WINBINDD_CHECK_MACHACC , " CHECK_MACHACC " ,
winbindd_check_machine_acct_send , winbindd_check_machine_acct_recv } ,
2009-12-21 21:50:43 +01:00
{ WINBINDD_PING_DC , " PING_DC " ,
winbindd_ping_dc_send , winbindd_ping_dc_recv } ,
2010-03-29 17:52:38 +02:00
{ WINBINDD_PAM_AUTH , " PAM_AUTH " ,
winbindd_pam_auth_send , winbindd_pam_auth_recv } ,
2010-04-01 16:44:16 +02:00
{ WINBINDD_PAM_LOGOFF , " PAM_LOGOFF " ,
winbindd_pam_logoff_send , winbindd_pam_logoff_recv } ,
2010-04-01 12:35:14 +02:00
{ WINBINDD_PAM_CHAUTHTOK , " PAM_CHAUTHTOK " ,
winbindd_pam_chauthtok_send , winbindd_pam_chauthtok_recv } ,
2010-04-20 11:11:19 +02:00
{ WINBINDD_PAM_CHNG_PSWD_AUTH_CRAP , " PAM_CHNG_PSWD_AUTH_CRAP " ,
winbindd_pam_chng_pswd_auth_crap_send ,
winbindd_pam_chng_pswd_auth_crap_recv } ,
2011-06-20 22:18:48 +02:00
{ WINBINDD_WINS_BYIP , " WINS_BYIP " ,
2011-06-05 11:30:43 +02:00
winbindd_wins_byip_send , winbindd_wins_byip_recv } ,
2011-06-14 23:51:10 +02:00
{ WINBINDD_WINS_BYNAME , " WINS_BYNAME " ,
winbindd_wins_byname_send , winbindd_wins_byname_recv } ,
2009-05-16 12:00:34 +02:00
2009-05-16 12:00:07 +02:00
{ 0 , NULL , NULL , NULL }
} ;
2009-08-30 09:41:43 +02:00
static struct winbindd_async_dispatch_table async_priv_table [ ] = {
{ WINBINDD_ALLOCATE_UID , " ALLOCATE_UID " ,
winbindd_allocate_uid_send , winbindd_allocate_uid_recv } ,
2009-08-30 09:46:34 +02:00
{ WINBINDD_ALLOCATE_GID , " ALLOCATE_GID " ,
winbindd_allocate_gid_send , winbindd_allocate_gid_recv } ,
2009-10-06 18:26:33 +02:00
{ WINBINDD_CHANGE_MACHACC , " CHANGE_MACHACC " ,
winbindd_change_machine_acct_send , winbindd_change_machine_acct_recv } ,
2010-03-30 23:02:36 +02:00
{ WINBINDD_PAM_AUTH_CRAP , " PAM_AUTH_CRAP " ,
winbindd_pam_auth_crap_send , winbindd_pam_auth_crap_recv } ,
2009-08-30 09:41:43 +02:00
{ 0 , NULL , NULL , NULL }
} ;
2009-05-16 12:00:07 +02:00
static void wb_request_done ( struct tevent_req * req ) ;
2001-05-07 04:32:40 +00:00
static void process_request ( struct winbindd_cli_state * state )
2000-05-09 11:43:00 +00:00
{
2005-06-08 22:10:34 +00:00
struct winbindd_dispatch_table * table = dispatch_table ;
2009-05-16 12:00:07 +02:00
struct winbindd_async_dispatch_table * atable ;
2000-05-09 11:43:00 +00:00
2010-05-24 10:11:23 +10:00
state - > mem_ctx = talloc_named ( state , 0 , " winbind request " ) ;
2005-06-08 22:10:34 +00:00
if ( state - > mem_ctx = = NULL )
return ;
2007-06-04 23:51:19 +00:00
/* Remember who asked us. */
2009-05-07 22:46:27 +02:00
state - > pid = state - > request - > pid ;
2007-06-04 23:51:19 +00:00
2010-03-05 11:16:12 +01:00
state - > cmd_name = " unknown request " ;
state - > recv_fn = NULL ;
2015-07-13 21:33:41 +03:00
/* client is newest */
winbindd_promote_client ( state ) ;
2010-03-05 11:16:12 +01:00
2001-05-07 04:32:40 +00:00
/* Process command */
2000-05-09 11:43:00 +00:00
2009-05-16 12:00:07 +02:00
for ( atable = async_nonpriv_table ; atable - > send_req ; atable + = 1 ) {
if ( state - > request - > cmd = = atable - > cmd ) {
break ;
}
}
2009-08-30 09:41:43 +02:00
if ( ( atable - > send_req = = NULL ) & & state - > privileged ) {
for ( atable = async_priv_table ; atable - > send_req ;
atable + = 1 ) {
if ( state - > request - > cmd = = atable - > cmd ) {
break ;
}
}
}
2009-05-16 12:00:07 +02:00
if ( atable - > send_req ! = NULL ) {
struct tevent_req * req ;
2010-03-05 11:16:12 +01:00
state - > cmd_name = atable - > cmd_name ;
state - > recv_fn = atable - > recv_req ;
DEBUG ( 10 , ( " process_request: Handling async request %d:%s \n " ,
( int ) state - > pid , state - > cmd_name ) ) ;
2009-05-16 12:00:07 +02:00
2017-11-17 11:35:19 +01:00
req = atable - > send_req ( state - > mem_ctx , server_event_context ( ) ,
2009-08-16 12:46:55 +02:00
state , state - > request ) ;
2009-05-16 12:00:07 +02:00
if ( req = = NULL ) {
DEBUG ( 0 , ( " process_request: atable->send failed for "
" %s \n " , atable - > cmd_name ) ) ;
request_error ( state ) ;
return ;
}
tevent_req_set_callback ( req , wb_request_done , state ) ;
return ;
}
2009-06-14 12:58:19 +02:00
state - > response = talloc_zero ( state - > mem_ctx ,
struct winbindd_response ) ;
if ( state - > response = = NULL ) {
DEBUG ( 10 , ( " talloc failed \n " ) ) ;
remove_client ( state ) ;
return ;
}
state - > response - > result = WINBINDD_PENDING ;
state - > response - > length = sizeof ( struct winbindd_response ) ;
2001-05-07 04:32:40 +00:00
for ( table = dispatch_table ; table - > fn ; table + + ) {
2009-05-07 22:46:27 +02:00
if ( state - > request - > cmd = = table - > cmd ) {
2005-06-08 22:10:34 +00:00
DEBUG ( 10 , ( " process_request: request fn %s \n " ,
table - > winbindd_cmd_name ) ) ;
2010-03-05 11:16:12 +01:00
state - > cmd_name = table - > winbindd_cmd_name ;
2005-06-20 13:42:29 +00:00
table - > fn ( state ) ;
2001-05-07 04:32:40 +00:00
break ;
}
}
2000-05-09 11:43:00 +00:00
2005-06-08 22:10:34 +00:00
if ( ! table - > fn ) {
DEBUG ( 10 , ( " process_request: unknown request fn number %d \n " ,
2009-05-07 22:46:27 +02:00
( int ) state - > request - > cmd ) ) ;
2005-06-20 13:42:29 +00:00
request_error ( state ) ;
2005-06-08 22:10:34 +00:00
}
}
2009-05-16 12:00:07 +02:00
static void wb_request_done ( struct tevent_req * req )
{
struct winbindd_cli_state * state = tevent_req_callback_data (
req , struct winbindd_cli_state ) ;
NTSTATUS status ;
2010-03-22 15:29:19 +01:00
state - > response = talloc_zero ( state - > mem_ctx ,
struct winbindd_response ) ;
2009-07-31 16:16:24 +02:00
if ( state - > response = = NULL ) {
2010-03-05 11:16:12 +01:00
DEBUG ( 0 , ( " wb_request_done[%d:%s]: talloc_zero failed - removing client \n " ,
( int ) state - > pid , state - > cmd_name ) ) ;
2009-07-31 16:16:24 +02:00
remove_client ( state ) ;
return ;
}
state - > response - > result = WINBINDD_PENDING ;
state - > response - > length = sizeof ( struct winbindd_response ) ;
status = state - > recv_fn ( req , state - > response ) ;
2009-05-16 12:00:07 +02:00
TALLOC_FREE ( req ) ;
2010-03-05 11:16:12 +01:00
DEBUG ( 10 , ( " wb_request_done[%d:%s]: %s \n " ,
( int ) state - > pid , state - > cmd_name , nt_errstr ( status ) ) ) ;
2009-05-16 12:00:07 +02:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
request_error ( state ) ;
2009-07-31 16:16:24 +02:00
return ;
2009-05-16 12:00:07 +02:00
}
request_ok ( state ) ;
}
2005-06-08 22:10:34 +00:00
/*
* This is the main event loop of winbind requests . It goes through a
* state - machine of 3 read / write requests , 4 if you have extra data to send .
*
* An idle winbind client has a read request of 4 bytes outstanding ,
* finalizing function is request_len_recv , checking the length . request_recv
* then processes the packet . The processing function then at some point has
* to call request_finished which schedules sending the response .
*/
2005-06-20 13:42:29 +00:00
static void request_finished ( struct winbindd_cli_state * state ) ;
2005-06-08 22:10:34 +00:00
2009-05-09 20:04:27 +02:00
static void winbind_client_request_read ( struct tevent_req * req ) ;
static void winbind_client_response_written ( struct tevent_req * req ) ;
2015-06-25 08:59:20 +03:00
static void winbind_client_activity ( struct tevent_req * req ) ;
2009-05-09 20:04:27 +02:00
static void request_finished ( struct winbindd_cli_state * state )
2005-06-08 22:10:34 +00:00
{
2009-05-09 20:04:27 +02:00
struct tevent_req * req ;
2005-06-08 22:10:34 +00:00
2015-06-25 08:59:20 +03:00
/* free client socket monitoring request */
TALLOC_FREE ( state - > io_req ) ;
2009-05-09 20:04:27 +02:00
TALLOC_FREE ( state - > request ) ;
2005-06-08 22:10:34 +00:00
2017-11-17 11:35:19 +01:00
req = wb_resp_write_send ( state , server_event_context ( ) ,
2009-05-09 20:04:27 +02:00
state - > out_queue , state - > sock ,
2009-06-14 12:41:46 +02:00
state - > response ) ;
2009-05-09 20:04:27 +02:00
if ( req = = NULL ) {
2010-03-05 11:16:12 +01:00
DEBUG ( 10 , ( " request_finished[%d:%s]: wb_resp_write_send() failed \n " ,
( int ) state - > pid , state - > cmd_name ) ) ;
2009-05-25 20:28:38 +02:00
remove_client ( state ) ;
2005-06-08 22:10:34 +00:00
return ;
}
2009-05-09 20:04:27 +02:00
tevent_req_set_callback ( req , winbind_client_response_written , state ) ;
2015-05-18 13:17:40 +02:00
state - > io_req = req ;
2005-06-08 22:10:34 +00:00
}
2009-05-09 20:04:27 +02:00
static void winbind_client_response_written ( struct tevent_req * req )
2005-06-08 22:10:34 +00:00
{
2009-05-09 20:04:27 +02:00
struct winbindd_cli_state * state = tevent_req_callback_data (
req , struct winbindd_cli_state ) ;
ssize_t ret ;
int err ;
2005-06-08 22:10:34 +00:00
2015-05-18 13:17:40 +02:00
state - > io_req = NULL ;
2009-05-09 20:04:27 +02:00
ret = wb_resp_write_recv ( req , & err ) ;
TALLOC_FREE ( req ) ;
if ( ret = = - 1 ) {
2009-09-21 02:42:35 +02:00
close ( state - > sock ) ;
state - > sock = - 1 ;
2010-03-05 11:16:12 +01:00
DEBUG ( 2 , ( " Could not write response[%d:%s] to client: %s \n " ,
( int ) state - > pid , state - > cmd_name , strerror ( err ) ) ) ;
2009-05-25 20:28:38 +02:00
remove_client ( state ) ;
2005-06-08 22:10:34 +00:00
return ;
}
2010-04-01 12:54:31 +02:00
DEBUG ( 10 , ( " winbind_client_response_written[%d:%s]: delivered response "
" to client \n " , ( int ) state - > pid , state - > cmd_name ) ) ;
2010-03-05 11:16:12 +01:00
2009-05-09 20:04:27 +02:00
TALLOC_FREE ( state - > mem_ctx ) ;
2009-07-26 20:20:50 +02:00
state - > response = NULL ;
2010-03-05 11:16:12 +01:00
state - > cmd_name = " no request " ;
state - > recv_fn = NULL ;
2005-06-08 22:10:34 +00:00
2017-11-17 11:35:19 +01:00
req = wb_req_read_send ( state , server_event_context ( ) , state - > sock ,
2009-05-09 20:04:27 +02:00
WINBINDD_MAX_EXTRA_DATA ) ;
if ( req = = NULL ) {
2009-05-25 20:28:38 +02:00
remove_client ( state ) ;
2005-06-08 22:10:34 +00:00
return ;
}
2009-05-09 20:04:27 +02:00
tevent_req_set_callback ( req , winbind_client_request_read , state ) ;
2015-05-18 13:17:40 +02:00
state - > io_req = req ;
2005-06-08 22:10:34 +00:00
}
2005-06-20 13:42:29 +00:00
void request_error ( struct winbindd_cli_state * state )
{
2009-06-14 12:41:46 +02:00
SMB_ASSERT ( state - > response - > result = = WINBINDD_PENDING ) ;
state - > response - > result = WINBINDD_ERROR ;
2005-06-20 13:42:29 +00:00
request_finished ( state ) ;
}
void request_ok ( struct winbindd_cli_state * state )
{
2009-06-14 12:41:46 +02:00
SMB_ASSERT ( state - > response - > result = = WINBINDD_PENDING ) ;
state - > response - > result = WINBINDD_OK ;
2005-06-20 13:42:29 +00:00
request_finished ( state ) ;
}
2001-05-07 04:32:40 +00:00
/* Process a new connection by adding it to the client connection list */
2000-05-09 11:43:00 +00:00
2010-05-14 13:11:48 +10:00
static void new_connection ( int listen_sock , bool privileged )
2000-05-09 11:43:00 +00:00
{
2010-05-14 13:11:48 +10:00
struct sockaddr_un sunaddr ;
2001-05-07 04:32:40 +00:00
struct winbindd_cli_state * state ;
2009-05-09 20:04:27 +02:00
struct tevent_req * req ;
2010-05-14 13:11:48 +10:00
socklen_t len ;
int sock ;
/* Accept connection */
len = sizeof ( sunaddr ) ;
2011-03-03 15:31:04 +01:00
sock = accept ( listen_sock , ( struct sockaddr * ) ( void * ) & sunaddr , & len ) ;
2010-05-14 13:11:48 +10:00
2011-03-03 15:31:04 +01:00
if ( sock = = - 1 ) {
if ( errno ! = EINTR ) {
2012-12-12 12:55:45 +01:00
DEBUG ( 0 , ( " Failed to accept socket - %s \n " ,
2011-03-03 15:31:04 +01:00
strerror ( errno ) ) ) ;
}
2010-05-14 13:11:48 +10:00
return ;
2011-03-03 15:31:04 +01:00
}
2017-12-11 09:58:59 +13:00
smb_set_close_on_exec ( sock ) ;
2010-05-14 13:11:48 +10:00
DEBUG ( 6 , ( " accepted socket %d \n " , sock ) ) ;
2008-11-26 14:01:22 +01:00
2001-05-07 04:32:40 +00:00
/* Create new connection structure */
2008-11-26 14:01:22 +01:00
2011-06-07 11:44:43 +10:00
if ( ( state = talloc_zero ( NULL , struct winbindd_cli_state ) ) = = NULL ) {
2010-05-14 13:11:48 +10:00
close ( sock ) ;
2001-05-07 04:32:40 +00:00
return ;
2007-02-08 00:28:25 +00:00
}
2008-11-26 14:01:22 +01:00
2010-05-14 13:11:48 +10:00
state - > sock = sock ;
2003-02-28 00:25:55 +00:00
2009-05-09 20:04:27 +02:00
state - > out_queue = tevent_queue_create ( state , " winbind client reply " ) ;
if ( state - > out_queue = = NULL ) {
2010-05-14 13:11:48 +10:00
close ( sock ) ;
2009-05-09 20:04:27 +02:00
TALLOC_FREE ( state ) ;
return ;
}
2003-04-07 07:32:51 +00:00
state - > privileged = privileged ;
2003-03-24 09:54:13 +00:00
2017-11-17 11:35:19 +01:00
req = wb_req_read_send ( state , server_event_context ( ) , state - > sock ,
2009-05-09 20:04:27 +02:00
WINBINDD_MAX_EXTRA_DATA ) ;
if ( req = = NULL ) {
TALLOC_FREE ( state ) ;
2010-05-14 13:11:48 +10:00
close ( sock ) ;
2009-05-09 20:04:27 +02:00
return ;
}
tevent_req_set_callback ( req , winbind_client_request_read , state ) ;
2015-05-18 13:17:40 +02:00
state - > io_req = req ;
2005-06-08 22:10:34 +00:00
2001-05-07 04:32:40 +00:00
/* Add to connection list */
2008-11-26 14:01:22 +01:00
2002-11-02 01:36:42 +00:00
winbindd_add_client ( state ) ;
2001-05-07 04:32:40 +00:00
}
2000-05-09 11:43:00 +00:00
2009-05-09 20:04:27 +02:00
static void winbind_client_request_read ( struct tevent_req * req )
{
struct winbindd_cli_state * state = tevent_req_callback_data (
req , struct winbindd_cli_state ) ;
ssize_t ret ;
int err ;
2015-05-18 13:17:40 +02:00
state - > io_req = NULL ;
2009-05-09 20:04:27 +02:00
ret = wb_req_read_recv ( req , state , & state - > request , & err ) ;
2009-07-24 19:03:45 -04:00
TALLOC_FREE ( req ) ;
2009-05-09 20:04:27 +02:00
if ( ret = = - 1 ) {
2009-12-26 18:00:32 +01:00
if ( err = = EPIPE ) {
DEBUG ( 6 , ( " closing socket %d, client exited \n " ,
state - > sock ) ) ;
} else {
DEBUG ( 2 , ( " Could not read client request from fd %d: "
" %s \n " , state - > sock , strerror ( err ) ) ) ;
}
2009-09-21 02:42:35 +02:00
close ( state - > sock ) ;
state - > sock = - 1 ;
2009-05-25 20:28:38 +02:00
remove_client ( state ) ;
2009-05-09 20:04:27 +02:00
return ;
}
2015-06-25 08:59:20 +03:00
2017-11-17 11:35:19 +01:00
req = wait_for_read_send ( state , server_event_context ( ) , state - > sock ,
2015-06-25 10:12:37 +03:00
true ) ;
2015-06-25 08:59:20 +03:00
if ( req = = NULL ) {
DEBUG ( 0 , ( " winbind_client_request_read[%d:%s]: "
" wait_for_read_send failed - removing client \n " ,
( int ) state - > pid , state - > cmd_name ) ) ;
remove_client ( state ) ;
return ;
}
tevent_req_set_callback ( req , winbind_client_activity , state ) ;
state - > io_req = req ;
2009-05-09 20:04:27 +02:00
process_request ( state ) ;
}
2015-06-25 08:59:20 +03:00
static void winbind_client_activity ( struct tevent_req * req )
{
struct winbindd_cli_state * state =
tevent_req_callback_data ( req , struct winbindd_cli_state ) ;
int err ;
2015-06-25 10:12:37 +03:00
bool has_data ;
2015-06-25 08:59:20 +03:00
2015-06-25 10:12:37 +03:00
has_data = wait_for_read_recv ( req , & err ) ;
if ( has_data ) {
DEBUG ( 0 , ( " winbind_client_activity[%d:%s]: "
" unexpected data from client - removing client \n " ,
( int ) state - > pid , state - > cmd_name ) ) ;
} else {
if ( err = = EPIPE ) {
DEBUG ( 6 , ( " winbind_client_activity[%d:%s]: "
" client has closed connection - removing "
" client \n " ,
( int ) state - > pid , state - > cmd_name ) ) ;
} else {
DEBUG ( 2 , ( " winbind_client_activity[%d:%s]: "
" client socket error (%s) - removing "
" client \n " ,
( int ) state - > pid , state - > cmd_name ,
strerror ( err ) ) ) ;
}
}
2015-06-25 08:59:20 +03:00
remove_client ( state ) ;
}
2001-05-07 04:32:40 +00:00
/* Remove a client connection from client connection list */
2000-05-09 11:43:00 +00:00
2001-05-07 04:32:40 +00:00
static void remove_client ( struct winbindd_cli_state * state )
{
2008-10-27 14:28:44 +01:00
char c = 0 ;
2008-11-28 19:53:59 +01:00
int nwritten ;
2008-10-27 14:28:44 +01:00
2001-05-07 04:32:40 +00:00
/* It's a dead client - hold a funeral */
2008-11-26 14:01:22 +01:00
2006-10-04 16:18:36 +00:00
if ( state = = NULL ) {
return ;
}
2008-10-27 14:28:44 +01:00
2015-05-18 13:17:40 +02:00
/*
* We need to remove a pending wb_req_read_ *
* or wb_resp_write_ * request before closing the
* socket .
*
* This is important as they might have used tevent_add_fd ( ) and we
* use the epoll * backend on linux . So we must remove the tevent_fd
* before closing the fd .
*
* Otherwise we might hit a race with close_conns_after_fork ( ) ( via
* winbindd_reinit_after_fork ( ) ) where a file description
* is still open in a child , which means it ' s still active in
* the parents epoll queue , but the related tevent_fd is already
* already gone in the parent .
*
* See bug # 11141.
*/
TALLOC_FREE ( state - > io_req ) ;
2009-09-21 02:42:35 +02:00
if ( state - > sock ! = - 1 ) {
/* tell client, we are closing ... */
nwritten = write ( state - > sock , & c , sizeof ( c ) ) ;
if ( nwritten = = - 1 ) {
2009-05-22 03:22:52 +08:00
DEBUG ( 2 , ( " final write to client failed: %s \n " ,
2009-09-21 02:42:35 +02:00
strerror ( errno ) ) ) ;
2009-05-22 03:22:52 +08:00
}
2008-10-27 14:28:44 +01:00
2009-09-21 02:42:35 +02:00
/* Close socket */
2008-11-26 14:01:22 +01:00
2009-09-21 02:42:35 +02:00
close ( state - > sock ) ;
state - > sock = - 1 ;
}
2008-11-26 14:01:22 +01:00
2008-07-24 14:46:43 +02:00
TALLOC_FREE ( state - > mem_ctx ) ;
2005-06-08 22:10:34 +00:00
2006-10-04 16:18:36 +00:00
/* Remove from list and free */
2008-11-26 14:01:22 +01:00
2006-10-04 16:18:36 +00:00
winbindd_remove_client ( state ) ;
TALLOC_FREE ( state ) ;
2001-05-07 04:32:40 +00:00
}
2000-05-09 11:43:00 +00:00
2010-08-23 00:53:40 +01:00
/* Is a client idle? */
static bool client_is_idle ( struct winbindd_cli_state * state ) {
2012-08-20 14:51:28 -07:00
return ( state - > request = = NULL & &
state - > response = = NULL & &
2010-08-23 00:53:40 +01:00
! state - > pwent_state & & ! state - > grent_state ) ;
}
2003-02-28 00:25:55 +00:00
/* Shutdown client connection which has been idle for the longest time */
2007-10-18 17:40:25 -07:00
static bool remove_idle_client ( void )
2003-02-28 00:25:55 +00:00
{
struct winbindd_cli_state * state , * remove_state = NULL ;
int nidle = 0 ;
for ( state = winbindd_client_list ( ) ; state ; state = state - > next ) {
2010-08-23 00:53:40 +01:00
if ( client_is_idle ( state ) ) {
2003-02-28 00:25:55 +00:00
nidle + + ;
2015-07-13 21:42:57 +03:00
/* list is sorted by access time */
remove_state = state ;
2003-02-28 00:25:55 +00:00
}
}
if ( remove_state ) {
DEBUG ( 5 , ( " Found %d idle client connections, shutting down sock %d, pid %u \n " ,
nidle , remove_state - > sock , ( unsigned int ) remove_state - > pid ) ) ;
remove_client ( remove_state ) ;
return True ;
}
return False ;
}
2014-07-25 12:46:46 -07:00
/*
* Terminate all clients whose requests have taken longer than
* " winbind request timeout " seconds to process , or have been
* idle for more than " winbind request timeout " seconds .
*/
static void remove_timed_out_clients ( void )
{
2015-07-13 21:42:57 +03:00
struct winbindd_cli_state * state , * prev = NULL ;
2014-07-25 12:46:46 -07:00
time_t curr_time = time ( NULL ) ;
int timeout_val = lp_winbind_request_timeout ( ) ;
2015-07-13 21:42:57 +03:00
for ( state = winbindd_client_list_tail ( ) ; state ; state = prev ) {
2014-07-25 12:46:46 -07:00
time_t expiry_time ;
2015-07-13 21:42:57 +03:00
prev = winbindd_client_list_prev ( state ) ;
2014-07-25 12:46:46 -07:00
expiry_time = state - > last_access + timeout_val ;
2017-03-09 17:50:01 +01:00
if ( curr_time < = expiry_time ) {
2015-07-13 21:42:57 +03:00
/* list is sorted, previous clients in
list are newer */
break ;
2014-07-25 12:46:46 -07:00
}
2017-03-09 17:50:01 +01:00
if ( client_is_idle ( state ) ) {
DEBUG ( 5 , ( " Idle client timed out, "
" shutting down sock %d, pid %u \n " ,
state - > sock ,
( unsigned int ) state - > pid ) ) ;
} else {
DEBUG ( 5 , ( " Client request timed out, "
" shutting down sock %d, pid %u \n " ,
state - > sock ,
( unsigned int ) state - > pid ) ) ;
}
remove_client ( state ) ;
2014-07-25 12:46:46 -07:00
}
}
2015-07-06 21:29:17 +03:00
static void winbindd_scrub_clients_handler ( struct tevent_context * ev ,
struct tevent_timer * te ,
struct timeval current_time ,
void * private_data )
{
remove_timed_out_clients ( ) ;
if ( tevent_add_timer ( ev , ev ,
timeval_current_ofs ( SCRUB_CLIENTS_INTERVAL , 0 ) ,
winbindd_scrub_clients_handler , NULL ) = = NULL ) {
DEBUG ( 0 , ( " winbindd: failed to reschedule client scrubber \n " ) ) ;
exit ( 1 ) ;
}
}
2009-03-16 17:27:30 +01:00
struct winbindd_listen_state {
bool privileged ;
int fd ;
} ;
static void winbindd_listen_fde_handler ( struct tevent_context * ev ,
struct tevent_fd * fde ,
uint16_t flags ,
void * private_data )
{
struct winbindd_listen_state * s = talloc_get_type_abort ( private_data ,
struct winbindd_listen_state ) ;
2010-09-14 16:43:39 -07:00
while ( winbindd_num_clients ( ) > lp_winbind_max_clients ( ) - 1 ) {
2009-03-16 17:27:30 +01:00
DEBUG ( 5 , ( " winbindd: Exceeding %d client "
" connections, removing idle "
2010-09-14 16:43:39 -07:00
" connection. \n " , lp_winbind_max_clients ( ) ) ) ;
2009-03-16 17:27:30 +01:00
if ( ! remove_idle_client ( ) ) {
DEBUG ( 0 , ( " winbindd: Exceeding %d "
" client connections, no idle "
" connection found \n " ,
2010-09-14 16:43:39 -07:00
lp_winbind_max_clients ( ) ) ) ;
2009-03-16 17:27:30 +01:00
break ;
}
}
2014-07-25 12:46:46 -07:00
remove_timed_out_clients ( ) ;
2009-03-16 17:27:30 +01:00
new_connection ( s - > fd , s - > privileged ) ;
}
2010-05-17 19:34:32 +10:00
/*
* Winbindd socket accessor functions
*/
char * get_winbind_priv_pipe_dir ( void )
{
2011-06-20 10:13:09 +10:00
return state_path ( WINBINDD_PRIV_SOCKET_SUBDIR ) ;
2010-05-17 19:34:32 +10:00
}
2015-06-22 06:38:04 +03:00
static void winbindd_setup_max_fds ( void )
{
int num_fds = MAX_OPEN_FUDGEFACTOR ;
int actual_fds ;
num_fds + = lp_winbind_max_clients ( ) ;
/* Add some more to account for 2 sockets open
when the client transitions from unprivileged
to privileged socket
*/
num_fds + = lp_winbind_max_clients ( ) / 10 ;
/* Add one socket per child process
( yeah there are child processes other than the
domain children but only domain children can vary
with configuration
*/
num_fds + = lp_winbind_max_domain_connections ( ) *
( lp_allow_trusted_domains ( ) ? WINBIND_MAX_DOMAINS_HINT : 1 ) ;
actual_fds = set_maxfiles ( num_fds ) ;
if ( actual_fds < num_fds ) {
DEBUG ( 1 , ( " winbindd_setup_max_fds: Information only: "
" requested %d open files, %d are available. \n " ,
num_fds , actual_fds ) ) ;
}
}
2009-03-16 17:27:30 +01:00
static bool winbindd_setup_listeners ( void )
{
struct winbindd_listen_state * pub_state = NULL ;
struct winbindd_listen_state * priv_state = NULL ;
2009-05-25 20:31:59 +02:00
struct tevent_fd * fde ;
2011-08-29 09:49:22 +02:00
int rc ;
2014-11-02 20:21:36 +01:00
char * socket_path ;
2009-03-16 17:27:30 +01:00
2017-11-17 11:35:19 +01:00
pub_state = talloc ( server_event_context ( ) ,
2009-03-16 17:27:30 +01:00
struct winbindd_listen_state ) ;
if ( ! pub_state ) {
goto failed ;
}
pub_state - > privileged = false ;
2010-05-17 19:34:32 +10:00
pub_state - > fd = create_pipe_sock (
2013-10-11 13:34:13 +13:00
lp_winbindd_socket_directory ( ) , WINBINDD_SOCKET_NAME , 0755 ) ;
2009-03-16 17:27:30 +01:00
if ( pub_state - > fd = = - 1 ) {
goto failed ;
}
2011-08-29 09:49:22 +02:00
rc = listen ( pub_state - > fd , 5 ) ;
if ( rc < 0 ) {
goto failed ;
}
2009-03-16 17:27:30 +01:00
2017-11-17 11:35:19 +01:00
fde = tevent_add_fd ( server_event_context ( ) , pub_state , pub_state - > fd ,
2009-05-25 20:31:59 +02:00
TEVENT_FD_READ , winbindd_listen_fde_handler ,
pub_state ) ;
if ( fde = = NULL ) {
2009-03-16 17:27:30 +01:00
close ( pub_state - > fd ) ;
goto failed ;
}
2009-05-25 20:31:59 +02:00
tevent_fd_set_auto_close ( fde ) ;
2009-03-16 17:27:30 +01:00
2017-11-17 11:35:19 +01:00
priv_state = talloc ( server_event_context ( ) ,
2009-03-16 17:27:30 +01:00
struct winbindd_listen_state ) ;
if ( ! priv_state ) {
goto failed ;
}
2014-11-02 20:21:36 +01:00
socket_path = get_winbind_priv_pipe_dir ( ) ;
if ( socket_path = = NULL ) {
goto failed ;
}
2009-03-16 17:27:30 +01:00
priv_state - > privileged = true ;
2010-05-17 19:34:32 +10:00
priv_state - > fd = create_pipe_sock (
2014-11-02 20:21:36 +01:00
socket_path , WINBINDD_SOCKET_NAME , 0750 ) ;
TALLOC_FREE ( socket_path ) ;
2009-03-16 17:27:30 +01:00
if ( priv_state - > fd = = - 1 ) {
goto failed ;
}
2011-08-29 09:49:22 +02:00
rc = listen ( priv_state - > fd , 5 ) ;
if ( rc < 0 ) {
goto failed ;
}
2009-03-16 17:27:30 +01:00
2017-11-17 11:35:19 +01:00
fde = tevent_add_fd ( server_event_context ( ) , priv_state ,
2009-05-25 20:31:59 +02:00
priv_state - > fd , TEVENT_FD_READ ,
winbindd_listen_fde_handler , priv_state ) ;
if ( fde = = NULL ) {
2009-03-16 17:27:30 +01:00
close ( priv_state - > fd ) ;
goto failed ;
}
2009-05-25 20:31:59 +02:00
tevent_fd_set_auto_close ( fde ) ;
2009-03-16 17:27:30 +01:00
2017-11-17 11:35:19 +01:00
winbindd_scrub_clients_handler ( server_event_context ( ) , NULL ,
2015-07-06 21:29:17 +03:00
timeval_current ( ) , NULL ) ;
2009-03-16 17:27:30 +01:00
return true ;
failed :
TALLOC_FREE ( pub_state ) ;
TALLOC_FREE ( priv_state ) ;
return false ;
}
2009-03-12 10:12:58 +01:00
bool winbindd_use_idmap_cache ( void )
{
return ! opt_nocache ;
}
bool winbindd_use_cache ( void )
{
return ! opt_nocache ;
}
2012-10-19 18:09:21 +02:00
static void winbindd_register_handlers ( struct messaging_context * msg_ctx ,
bool foreground )
2010-05-11 21:37:30 +10:00
{
2017-11-29 16:02:28 +01:00
bool scan_trusts = true ;
2014-05-06 17:00:09 +12:00
NTSTATUS status ;
2010-05-11 21:37:30 +10:00
/* Setup signal handlers */
if ( ! winbindd_setup_sig_term_handler ( true ) )
exit ( 1 ) ;
2012-03-02 18:22:10 +11:00
if ( ! winbindd_setup_stdin_handler ( true , foreground ) )
exit ( 1 ) ;
2010-05-11 21:37:30 +10:00
if ( ! winbindd_setup_sig_hup_handler ( NULL ) )
exit ( 1 ) ;
if ( ! winbindd_setup_sig_chld_handler ( ) )
exit ( 1 ) ;
if ( ! winbindd_setup_sig_usr2_handler ( ) )
exit ( 1 ) ;
CatchSignal ( SIGPIPE , SIG_IGN ) ; /* Ignore sigpipe */
/*
* Ensure all cache and idmap caches are consistent
* and initialized before we startup .
*/
if ( ! winbindd_cache_validate_and_initialize ( ) ) {
exit ( 1 ) ;
}
/* React on 'smbcontrol winbindd reload-config' in the same way
as to SIGHUP signal */
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_SMB_CONF_UPDATED , msg_reload_services ) ;
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_SHUTDOWN , msg_shutdown ) ;
/* Handle online/offline messages. */
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_WINBIND_OFFLINE , winbind_msg_offline ) ;
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_WINBIND_ONLINE , winbind_msg_online ) ;
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_WINBIND_ONLINESTATUS , winbind_msg_onlinestatus ) ;
2013-10-10 10:02:27 +02:00
/* Handle domain online/offline messages for domains */
2017-11-17 11:42:34 +01:00
messaging_register ( server_messaging_context ( ) , NULL ,
2013-10-10 10:02:27 +02:00
MSG_WINBIND_DOMAIN_OFFLINE , winbind_msg_domain_offline ) ;
2017-11-17 11:42:34 +01:00
messaging_register ( server_messaging_context ( ) , NULL ,
2013-10-10 10:02:27 +02:00
MSG_WINBIND_DOMAIN_ONLINE , winbind_msg_domain_online ) ;
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_DUMP_EVENT_LIST , winbind_msg_dump_event_list ) ;
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_WINBIND_VALIDATE_CACHE ,
winbind_msg_validate_cache ) ;
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_WINBIND_DUMP_DOMAIN_LIST ,
winbind_msg_dump_domain_list ) ;
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-09-29 12:17:05 +02:00
MSG_WINBIND_IP_DROPPED ,
winbind_msg_ip_dropped_parent ) ;
2010-05-11 21:37:30 +10:00
/* Register handler for MSG_DEBUG. */
2012-10-19 18:09:21 +02:00
messaging_register ( msg_ctx , NULL ,
2010-05-11 21:37:30 +10:00
MSG_DEBUG ,
winbind_msg_debug ) ;
netsamlogon_cache_init ( ) ; /* Non-critical */
/* clear the cached list of trusted domains */
wcache_tdc_clear ( ) ;
if ( ! init_domain_list ( ) ) {
DEBUG ( 0 , ( " unable to initialize domain list \n " ) ) ;
exit ( 1 ) ;
}
init_idmap_child ( ) ;
init_locator_child ( ) ;
smb_nscd_flush_user_cache ( ) ;
smb_nscd_flush_group_cache ( ) ;
2017-11-29 16:02:28 +01:00
if ( ! lp_winbind_scan_trusted_domains ( ) ) {
scan_trusts = false ;
}
2017-11-29 16:02:28 +01:00
if ( ! lp_allow_trusted_domains ( ) ) {
scan_trusts = false ;
}
if ( IS_DC ) {
scan_trusts = false ;
}
if ( scan_trusts ) {
2017-11-17 11:35:19 +01:00
if ( tevent_add_timer ( server_event_context ( ) , NULL , timeval_zero ( ) ,
2011-04-06 13:52:42 -07:00
rescan_trusted_domains , NULL ) = = NULL ) {
DEBUG ( 0 , ( " Could not trigger rescan_trusted_domains() \n " ) ) ;
exit ( 1 ) ;
}
2010-05-11 21:37:30 +10:00
}
2014-05-08 14:46:06 +12:00
status = wb_irpc_register ( ) ;
2014-05-06 17:00:09 +12:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
2014-05-08 14:46:06 +12:00
DEBUG ( 0 , ( " Could not register IRPC handlers \n " ) ) ;
2014-05-06 17:00:09 +12:00
exit ( 1 ) ;
}
2010-05-11 21:37:30 +10:00
}
2011-01-31 17:25:55 +01:00
struct winbindd_addrchanged_state {
struct addrchange_context * ctx ;
struct tevent_context * ev ;
struct messaging_context * msg_ctx ;
} ;
static void winbindd_addr_changed ( struct tevent_req * req ) ;
static void winbindd_init_addrchange ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
struct messaging_context * msg_ctx )
{
struct winbindd_addrchanged_state * state ;
struct tevent_req * req ;
NTSTATUS status ;
state = talloc ( mem_ctx , struct winbindd_addrchanged_state ) ;
if ( state = = NULL ) {
DEBUG ( 10 , ( " talloc failed \n " ) ) ;
return ;
}
state - > ev = ev ;
state - > msg_ctx = msg_ctx ;
status = addrchange_context_create ( state , & state - > ctx ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 10 , ( " addrchange_context_create failed: %s \n " ,
nt_errstr ( status ) ) ) ;
TALLOC_FREE ( state ) ;
return ;
}
req = addrchange_send ( state , ev , state - > ctx ) ;
if ( req = = NULL ) {
2011-02-04 12:29:42 +01:00
DEBUG ( 0 , ( " addrchange_send failed \n " ) ) ;
2011-01-31 17:25:55 +01:00
TALLOC_FREE ( state ) ;
2011-02-04 12:29:42 +01:00
return ;
2011-01-31 17:25:55 +01:00
}
tevent_req_set_callback ( req , winbindd_addr_changed , state ) ;
}
static void winbindd_addr_changed ( struct tevent_req * req )
{
struct winbindd_addrchanged_state * state = tevent_req_callback_data (
req , struct winbindd_addrchanged_state ) ;
enum addrchange_type type ;
struct sockaddr_storage addr ;
NTSTATUS status ;
status = addrchange_recv ( req , & type , & addr ) ;
TALLOC_FREE ( req ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 10 , ( " addrchange_recv failed: %s, stop listening \n " ,
nt_errstr ( status ) ) ) ;
TALLOC_FREE ( state ) ;
2011-02-04 12:29:42 +01:00
return ;
2011-01-31 17:25:55 +01:00
}
if ( type = = ADDRCHANGE_DEL ) {
char addrstr [ INET6_ADDRSTRLEN ] ;
DATA_BLOB blob ;
print_sockaddr ( addrstr , sizeof ( addrstr ) , & addr ) ;
DEBUG ( 3 , ( " winbindd: kernel (AF_NETLINK) dropped ip %s \n " ,
addrstr ) ) ;
blob = data_blob_const ( addrstr , strlen ( addrstr ) + 1 ) ;
status = messaging_send ( state - > msg_ctx ,
messaging_server_id ( state - > msg_ctx ) ,
MSG_WINBIND_IP_DROPPED , & blob ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
2011-02-04 12:29:42 +01:00
DEBUG ( 10 , ( " messaging_send failed: %s - ignoring \n " ,
2011-01-31 17:25:55 +01:00
nt_errstr ( status ) ) ) ;
}
}
req = addrchange_send ( state , state - > ev , state - > ctx ) ;
if ( req = = NULL ) {
2011-02-04 12:29:42 +01:00
DEBUG ( 0 , ( " addrchange_send failed \n " ) ) ;
2011-01-31 17:25:55 +01:00
TALLOC_FREE ( state ) ;
2011-02-04 12:29:42 +01:00
return ;
2011-01-31 17:25:55 +01:00
}
tevent_req_set_callback ( req , winbindd_addr_changed , state ) ;
}
2000-05-09 11:43:00 +00:00
/* Main function */
2014-02-26 20:16:26 +01:00
int main ( int argc , const char * * argv )
2000-05-09 11:43:00 +00:00
{
2007-10-19 11:38:36 -07:00
static bool is_daemon = False ;
static bool Fork = True ;
static bool log_stdout = False ;
static bool no_process_group = False ;
enum {
OPT_DAEMON = 1000 ,
OPT_FORK ,
OPT_NO_PROCESS_GROUP ,
OPT_LOG_STDOUT
} ;
2003-04-14 03:53:58 +00:00
struct poptOption long_options [ ] = {
POPT_AUTOHELP
2007-10-19 11:38:36 -07:00
{ " stdout " , ' S ' , POPT_ARG_NONE , NULL , OPT_LOG_STDOUT , " Log to stdout " } ,
{ " foreground " , ' F ' , POPT_ARG_NONE , NULL , OPT_FORK , " Daemon in foreground mode " } ,
{ " no-process-group " , 0 , POPT_ARG_NONE , NULL , OPT_NO_PROCESS_GROUP , " Don't create a new process group " } ,
{ " daemon " , ' D ' , POPT_ARG_NONE , NULL , OPT_DAEMON , " Become a daemon (default) " } ,
2007-10-10 15:34:30 -05:00
{ " interactive " , ' i ' , POPT_ARG_NONE , NULL , ' i ' , " Interactive mode " } ,
2007-10-19 11:38:36 -07:00
{ " no-caching " , ' n ' , POPT_ARG_NONE , NULL , ' n ' , " Disable caching " } ,
2003-04-14 03:53:58 +00:00
POPT_COMMON_SAMBA
POPT_TABLEEND
} ;
poptContext pc ;
2002-03-14 02:15:08 +00:00
int opt ;
2010-09-24 18:45:52 +02:00
TALLOC_CTX * frame ;
2010-07-04 16:28:13 +02:00
NTSTATUS status ;
2012-12-13 17:29:39 +01:00
bool ok ;
2001-05-07 04:32:40 +00:00
2017-12-20 17:42:45 +01:00
setproctitle_init ( argc , discard_const ( argv ) , environ ) ;
2010-09-24 18:45:52 +02:00
/*
* Do this before any other talloc operation
*/
talloc_enable_null_tracking ( ) ;
frame = talloc_stackframe ( ) ;
2013-06-17 17:25:41 -07:00
/*
* We want total control over the permissions on created files ,
* so set our umask to 0.
*/
umask ( 0 ) ;
2011-07-18 17:07:25 +10:00
setup_logging ( " winbindd " , DEBUG_DEFAULT_STDOUT ) ;
2001-11-21 23:00:59 +00:00
/* glibc (?) likes to print "User defined signal 1" and exit if a
2002-03-26 22:33:06 +00:00
SIGUSR [ 12 ] is received before a handler is installed */
2001-11-15 03:23:15 +00:00
2002-03-26 22:33:06 +00:00
CatchSignal ( SIGUSR1 , SIG_IGN ) ;
2002-01-10 06:20:03 +00:00
CatchSignal ( SIGUSR2 , SIG_IGN ) ;
2001-11-15 03:23:15 +00:00
2011-03-22 14:05:23 +11:00
fault_setup ( ) ;
2012-07-18 15:07:23 +09:30
dump_core_setup ( " winbindd " , lp_logfile ( talloc_tos ( ) ) ) ;
2001-12-21 02:23:38 +00:00
2015-03-21 20:00:06 +01:00
smb_init_locale ( ) ;
2005-12-28 21:10:11 +00:00
2001-11-14 21:49:30 +00:00
/* Initialise for running in non-root mode */
2001-10-05 00:20:06 +00:00
2001-07-08 18:25:19 +00:00
sec_init ( ) ;
2001-05-08 03:52:07 +00:00
2003-04-14 03:53:58 +00:00
set_remote_machine_name ( " winbindd " , False ) ;
2001-05-07 04:32:40 +00:00
/* Set environment variable so we don't recursively call ourselves.
This may also be useful interactively . */
2001-10-05 00:20:06 +00:00
2006-04-02 19:45:42 +00:00
if ( ! winbind_off ( ) ) {
2006-04-02 06:25:11 +00:00
DEBUG ( 0 , ( " Failed to disable recusive winbindd calls. Exiting. \n " ) ) ;
exit ( 1 ) ;
}
2001-05-07 04:32:40 +00:00
/* Initialise samba/rpc client stuff */
2014-02-26 20:16:26 +01:00
pc = poptGetContext ( " winbindd " , argc , argv , long_options , 0 ) ;
2007-08-21 14:22:16 +00:00
while ( ( opt = poptGetNextOpt ( pc ) ) ! = - 1 ) {
switch ( opt ) {
2007-10-10 15:34:30 -05:00
/* Don't become a daemon */
2007-10-19 11:38:36 -07:00
case OPT_DAEMON :
2007-10-10 15:34:30 -05:00
is_daemon = True ;
break ;
case ' i ' :
interactive = True ;
log_stdout = True ;
Fork = False ;
break ;
2007-10-19 11:38:36 -07:00
case OPT_FORK :
Fork = false ;
break ;
case OPT_NO_PROCESS_GROUP :
no_process_group = true ;
break ;
case OPT_LOG_STDOUT :
log_stdout = true ;
break ;
case ' n ' :
opt_nocache = true ;
break ;
2007-08-21 14:22:16 +00:00
default :
2007-08-22 12:06:27 +00:00
d_fprintf ( stderr , " \n Invalid option %s: %s \n \n " ,
2007-08-21 14:22:16 +00:00
poptBadOption ( pc , 0 ) , poptStrerror ( opt ) ) ;
2007-08-22 12:06:27 +00:00
poptPrintUsage ( pc , stderr , 0 ) ;
2007-08-21 14:22:16 +00:00
exit ( 1 ) ;
}
}
2007-04-20 18:34:33 +00:00
2012-06-11 10:23:51 -07:00
/* We call dump_core_setup one more time because the command line can
* set the log file or the log - basename and this will influence where
* cores are stored . Without this call get_dyn_LOGFILEBASE will be
* the default value derived from build ' s prefix . For EOM this value
* is often not related to the path where winbindd is actually run
* in production .
*/
2012-07-18 15:07:23 +09:30
dump_core_setup ( " winbindd " , lp_logfile ( talloc_tos ( ) ) ) ;
2007-10-10 15:34:30 -05:00
if ( is_daemon & & interactive ) {
d_fprintf ( stderr , " \n ERROR: "
" Option -i|--interactive is not allowed together with -D|--daemon \n \n " ) ;
poptPrintUsage ( pc , stderr , 0 ) ;
exit ( 1 ) ;
2001-05-07 04:32:40 +00:00
}
2000-05-09 11:43:00 +00:00
2007-10-10 15:34:30 -05:00
if ( log_stdout & & Fork ) {
d_fprintf ( stderr , " \n ERROR: "
" Can't log to stdout (-S) unless daemon is in foreground +(-F) or interactive (-i) \n \n " ) ;
2003-04-14 03:53:58 +00:00
poptPrintUsage ( pc , stderr , 0 ) ;
2003-01-03 17:39:30 +00:00
exit ( 1 ) ;
}
2007-08-22 12:06:27 +00:00
poptFreeContext ( pc ) ;
2004-09-21 09:07:42 +00:00
if ( ! override_logfile ) {
2008-11-03 12:36:34 -08:00
char * lfile = NULL ;
if ( asprintf ( & lfile , " %s/log.winbindd " ,
2007-12-10 11:30:37 -08:00
get_dyn_LOGFILEBASE ( ) ) > 0 ) {
2008-11-03 12:36:34 -08:00
lp_set_logfile ( lfile ) ;
SAFE_FREE ( lfile ) ;
2007-11-20 17:18:16 -08:00
}
2004-09-21 09:07:42 +00:00
}
2011-07-18 17:07:25 +10:00
2010-10-29 14:19:32 +11:00
if ( log_stdout ) {
setup_logging ( " winbindd " , DEBUG_STDOUT ) ;
} else {
setup_logging ( " winbindd " , DEBUG_FILE ) ;
}
2001-05-07 04:32:40 +00:00
reopen_logs ( ) ;
2000-05-09 11:43:00 +00:00
2009-01-15 22:27:52 +01:00
DEBUG ( 0 , ( " winbindd version %s started. \n " , samba_version_string ( ) ) ) ;
2007-10-30 15:44:27 +01:00
DEBUGADD ( 0 , ( " %s \n " , COPYRIGHT_STARTUP_MESSAGE ) ) ;
2001-12-20 18:37:43 +00:00
2008-04-15 10:57:16 +02:00
if ( ! lp_load_initial_only ( get_dyn_CONFIGFILE ( ) ) ) {
2011-03-23 11:22:15 +11:00
DEBUG ( 0 , ( " error opening config file '%s' \n " , get_dyn_CONFIGFILE ( ) ) ) ;
2008-04-15 10:57:16 +02:00
exit ( 1 ) ;
}
2012-06-11 10:23:51 -07:00
/* After parsing the configuration file we setup the core path one more time
* as the log file might have been set in the configuration and cores ' s
* path is by default basename ( lp_logfile ( ) ) .
*/
2012-07-18 15:07:23 +09:30
dump_core_setup ( " winbindd " , lp_logfile ( talloc_tos ( ) ) ) ;
2008-04-15 10:57:16 +02:00
2014-03-28 14:35:21 +13:00
if ( lp_server_role ( ) = = ROLE_ACTIVE_DIRECTORY_DC
& & ! lp_parm_bool ( - 1 , " server role check " , " inhibit " , false ) ) {
2012-08-22 21:01:16 +10:00
DEBUG ( 0 , ( " server role = 'active directory domain controller' not compatible with running the winbindd binary. \n " ) ) ;
DEBUGADD ( 0 , ( " You should start 'samba' instead, and it will control starting the internal AD DC winbindd implementation, which is not the same as this one \n " ) ) ;
exit ( 1 ) ;
}
2013-10-17 15:16:19 +02:00
if ( ! cluster_probe_ok ( ) ) {
exit ( 1 ) ;
2013-01-31 11:15:09 +01:00
}
2008-04-15 10:57:16 +02:00
/* Initialise messaging system */
2017-11-17 11:42:34 +01:00
if ( server_messaging_context ( ) = = NULL ) {
2008-04-15 10:57:16 +02:00
exit ( 1 ) ;
}
2008-07-17 20:10:18 -07:00
if ( ! reload_services_file ( NULL ) ) {
2001-12-20 18:37:43 +00:00
DEBUG ( 0 , ( " error opening config file \n " ) ) ;
exit ( 1 ) ;
}
2016-12-12 10:05:39 +01:00
{
size_t i ;
const char * idmap_backend ;
const char * invalid_backends [ ] = {
" ad " , " rfc2307 " , " rid " ,
} ;
idmap_backend = lp_idmap_default_backend ( ) ;
for ( i = 0 ; i < ARRAY_SIZE ( invalid_backends ) ; i + + ) {
ok = strequal ( idmap_backend , invalid_backends [ i ] ) ;
if ( ok ) {
DBG_ERR ( " FATAL: Invalid idmap backend %s "
" configured as the default backend! \n " ,
idmap_backend ) ;
exit ( 1 ) ;
}
}
}
2014-07-27 19:18:09 +02:00
ok = directory_create_or_exist ( lp_lock_directory ( ) , 0755 ) ;
2012-12-13 17:29:39 +01:00
if ( ! ok ) {
DEBUG ( 0 , ( " Failed to create directory %s for lock files - %s \n " ,
2014-02-03 15:46:08 +13:00
lp_lock_directory ( ) , strerror ( errno ) ) ) ;
2012-12-13 17:29:39 +01:00
exit ( 1 ) ;
2006-09-02 02:04:41 +00:00
}
2014-07-27 19:18:09 +02:00
ok = directory_create_or_exist ( lp_pid_directory ( ) , 0755 ) ;
2012-12-13 17:29:39 +01:00
if ( ! ok ) {
DEBUG ( 0 , ( " Failed to create directory %s for pid files - %s \n " ,
2014-02-03 15:57:21 +13:00
lp_pid_directory ( ) , strerror ( errno ) ) ) ;
2012-12-13 17:29:39 +01:00
exit ( 1 ) ;
2012-03-06 20:58:37 -05:00
}
2001-12-20 18:37:43 +00:00
/* Setup names. */
2002-01-22 00:35:05 +00:00
2002-11-12 23:20:50 +00:00
if ( ! init_names ( ) )
exit ( 1 ) ;
2000-05-09 11:43:00 +00:00
2003-05-06 02:32:47 +00:00
load_interfaces ( ) ;
if ( ! secrets_init ( ) ) {
DEBUG ( 0 , ( " Could not initialize domain trust account secrets. Giving up \n " ) ) ;
return False ;
}
2013-12-17 20:06:14 +01:00
status = rpccli_pre_open_netlogon_creds ( ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 0 , ( " rpccli_pre_open_netlogon_creds() - %s \n " ,
nt_errstr ( status ) ) ) ;
exit ( 1 ) ;
}
2003-05-06 02:32:47 +00:00
/* Unblock all signals we are interested in as they may have been
blocked by the parent process . */
BlockSignals ( False , SIGINT ) ;
BlockSignals ( False , SIGQUIT ) ;
BlockSignals ( False , SIGTERM ) ;
BlockSignals ( False , SIGUSR1 ) ;
BlockSignals ( False , SIGUSR2 ) ;
BlockSignals ( False , SIGHUP ) ;
2004-07-21 04:24:30 +00:00
BlockSignals ( False , SIGCHLD ) ;
2003-05-06 02:32:47 +00:00
2007-10-10 15:34:30 -05:00
if ( ! interactive )
2010-03-26 11:17:37 +01:00
become_daemon ( Fork , no_process_group , log_stdout ) ;
2000-05-09 11:43:00 +00:00
2014-02-03 15:57:21 +13:00
pidfile_create ( lp_pid_directory ( ) , " winbindd " ) ;
2002-09-25 15:19:00 +00:00
2001-12-30 01:46:38 +00:00
# if HAVE_SETPGID
/*
* If we ' re interactive we want to set our own process group for
* signal management .
*/
2007-10-10 15:34:30 -05:00
if ( interactive & & ! no_process_group )
2001-12-30 01:46:38 +00:00
setpgid ( ( pid_t ) 0 , ( pid_t ) 0 ) ;
# endif
2005-11-05 04:21:55 +00:00
TimeInit ( ) ;
2010-05-13 17:07:15 +10:00
/* Don't use winbindd_reinit_after_fork here as
* we ' re just starting up and haven ' t created any
* winbindd - specific resources we must free yet . JRA .
*/
2017-11-17 11:42:34 +01:00
status = reinit_after_fork ( server_messaging_context ( ) ,
2017-11-17 11:35:19 +01:00
server_event_context ( ) ,
2015-09-23 11:14:05 -07:00
false , NULL ) ;
2010-07-04 16:28:13 +02:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
2014-03-26 11:45:21 +02:00
exit_daemon ( " Winbindd reinit_after_fork() failed " , map_errno_from_nt_status ( status ) ) ;
2010-05-13 17:07:15 +10:00
}
2012-03-15 16:29:27 +01:00
/*
* Do not initialize the parent - child - pipe before becoming
* a daemon : this is used to detect a died parent in the child
* process .
*/
status = init_before_fork ( ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
2014-03-26 11:45:21 +02:00
exit_daemon ( nt_errstr ( status ) , map_errno_from_nt_status ( status ) ) ;
2012-03-15 16:29:27 +01:00
}
2017-11-17 11:42:34 +01:00
winbindd_register_handlers ( server_messaging_context ( ) , ! Fork ) ;
2006-03-16 13:37:23 +00:00
2017-11-17 11:42:34 +01:00
if ( ! messaging_parent_dgm_cleanup_init ( server_messaging_context ( ) ) ) {
2014-04-18 15:09:28 -07:00
exit ( 1 ) ;
}
2012-05-14 10:37:59 +02:00
status = init_system_session_info ( ) ;
2011-02-19 20:05:07 +01:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
2014-03-26 11:45:21 +02:00
exit_daemon ( " Winbindd failed to setup system user info " , map_errno_from_nt_status ( status ) ) ;
2010-05-27 12:06:24 +02:00
}
2010-10-15 17:58:39 +02:00
rpc_lsarpc_init ( NULL ) ;
rpc_samr_init ( NULL ) ;
2017-11-17 11:35:19 +01:00
winbindd_init_addrchange ( NULL , server_event_context ( ) ,
2017-11-17 11:42:34 +01:00
server_messaging_context ( ) ) ;
2011-01-31 17:25:55 +01:00
2009-03-16 17:27:30 +01:00
/* setup listen sockets */
if ( ! winbindd_setup_listeners ( ) ) {
2014-03-26 11:45:21 +02:00
exit_daemon ( " Winbindd failed to setup listeners " , EPIPE ) ;
2009-03-16 17:27:30 +01:00
}
2007-10-10 15:34:30 -05:00
2014-05-06 13:39:12 +12:00
irpc_add_name ( winbind_imessaging_context ( ) , " winbind_server " ) ;
2007-11-15 14:19:52 -08:00
TALLOC_FREE ( frame ) ;
2014-03-25 12:53:04 +02:00
if ( ! interactive ) {
daemon_ready ( " winbindd " ) ;
}
2017-11-21 03:44:12 -07:00
gpupdate_init ( ) ;
2009-03-16 17:27:30 +01:00
/* Loop waiting for requests */
2007-10-10 15:34:30 -05:00
while ( 1 ) {
2007-11-15 14:19:52 -08:00
frame = talloc_stackframe ( ) ;
2009-03-16 16:14:20 +01:00
2017-11-17 11:35:19 +01:00
if ( tevent_loop_once ( server_event_context ( ) ) = = - 1 ) {
2009-05-25 22:40:09 +02:00
DEBUG ( 1 , ( " tevent_loop_once() failed: %s \n " ,
strerror ( errno ) ) ) ;
return 1 ;
}
2009-03-16 16:14:20 +01:00
2007-10-10 15:34:30 -05:00
TALLOC_FREE ( frame ) ;
}
2000-05-09 11:43:00 +00:00
2001-05-07 04:32:40 +00:00
return 0 ;
2000-05-09 11:43:00 +00:00
}