2006-12-12 17:52:13 +03:00
/*
Unix SMB / CIFS implementation .
idmap TDB backend
Copyright ( C ) Tim Potter 2000
Copyright ( C ) Jim McDonough < jmcd @ us . ibm . com > 2003
Copyright ( C ) Jeremy Allison 2006
Copyright ( C ) Simo Sorce 2003 - 2006
2008-07-11 19:45:16 +04:00
2006-12-12 17:52:13 +03:00
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-09 23:25:36 +04:00
the Free Software Foundation ; either version 3 of the License , or
2006-12-12 17:52:13 +03:00
( at your option ) any later version .
2008-07-11 19:45:16 +04:00
2006-12-12 17:52:13 +03:00
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
2008-07-11 19:45:16 +04:00
2006-12-12 17:52:13 +03:00
You should have received a copy of the GNU General Public License
2007-07-10 04:52:41 +04:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
2006-12-12 17:52:13 +03:00
*/
# include "includes.h"
# include "winbindd.h"
# undef DBGC_CLASS
# define DBGC_CLASS DBGC_IDMAP
2009-01-22 12:24:40 +03:00
/* idmap version determines auto-conversion - this is the database
structure version specifier . */
# define IDMAP_VERSION 2
2006-12-12 17:52:13 +03:00
/* High water mark keys */
# define HWM_GROUP "GROUP HWM"
# define HWM_USER "USER HWM"
static struct idmap_tdb_state {
/* User and group id pool */
uid_t low_uid , high_uid ; /* Range of uids to allocate */
gid_t low_gid , high_gid ; /* Range of gids to allocate */
} idmap_tdb_state ;
2008-12-16 23:14:36 +03:00
struct convert_fn_state {
struct db_context * db ;
bool failed ;
} ;
2006-12-12 17:52:13 +03:00
/*****************************************************************************
For idmap conversion : convert one record to new format
Ancient versions ( eg 2.2 .3 a ) of winbindd_idmap . tdb mapped DOMAINNAME / rid
instead of the SID .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2008-12-16 23:14:36 +03:00
static int convert_fn ( struct db_record * rec , void * private_data )
2006-12-12 17:52:13 +03:00
{
struct winbindd_domain * domain ;
char * p ;
2008-12-16 23:14:36 +03:00
NTSTATUS status ;
2010-05-21 05:25:01 +04:00
struct dom_sid sid ;
2006-12-12 17:52:13 +03:00
uint32 rid ;
fstring keystr ;
fstring dom_name ;
TDB_DATA key2 ;
2008-12-16 23:14:36 +03:00
struct convert_fn_state * s = ( struct convert_fn_state * ) private_data ;
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
DEBUG ( 10 , ( " Converting %s \n " , ( const char * ) rec - > key . dptr ) ) ;
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
p = strchr ( ( const char * ) rec - > key . dptr , ' / ' ) ;
2006-12-12 17:52:13 +03:00
if ( ! p )
return 0 ;
* p = 0 ;
2008-12-16 23:14:36 +03:00
fstrcpy ( dom_name , ( const char * ) rec - > key . dptr ) ;
2006-12-12 17:52:13 +03:00
* p + + = ' / ' ;
domain = find_domain_from_name ( dom_name ) ;
if ( domain = = NULL ) {
/* We must delete the old record. */
DEBUG ( 0 , ( " Unable to find domain %s \n " , dom_name ) ) ;
2008-12-16 23:14:36 +03:00
DEBUG ( 0 , ( " deleting record %s \n " , ( const char * ) rec - > key . dptr ) ) ;
status = rec - > delete_rec ( rec ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 0 , ( " Unable to delete record %s:%s \n " ,
( const char * ) rec - > key . dptr ,
nt_errstr ( status ) ) ) ;
s - > failed = true ;
2006-12-12 17:52:13 +03:00
return - 1 ;
}
return 0 ;
}
rid = atoi ( p ) ;
2010-01-10 19:39:27 +03:00
sid_compose ( & sid , & domain - > sid , rid ) ;
2006-12-12 17:52:13 +03:00
2007-12-16 00:47:30 +03:00
sid_to_fstring ( keystr , & sid ) ;
2007-03-27 15:01:37 +04:00
key2 = string_term_tdb_data ( keystr ) ;
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
status = dbwrap_store ( s - > db , key2 , rec - > value , TDB_INSERT ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 0 , ( " Unable to add record %s:%s \n " ,
( const char * ) key2 . dptr ,
nt_errstr ( status ) ) ) ;
s - > failed = true ;
2006-12-12 17:52:13 +03:00
return - 1 ;
}
2008-12-16 23:14:36 +03:00
status = dbwrap_store ( s - > db , rec - > value , key2 , TDB_REPLACE ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 0 , ( " Unable to update record %s:%s \n " ,
( const char * ) rec - > value . dptr ,
nt_errstr ( status ) ) ) ;
s - > failed = true ;
2006-12-12 17:52:13 +03:00
return - 1 ;
}
2008-12-16 23:14:36 +03:00
status = rec - > delete_rec ( rec ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 0 , ( " Unable to delete record %s:%s \n " ,
( const char * ) rec - > key . dptr ,
nt_errstr ( status ) ) ) ;
s - > failed = true ;
2006-12-12 17:52:13 +03:00
return - 1 ;
}
return 0 ;
}
/*****************************************************************************
Convert the idmap database from an older version .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2008-12-16 23:14:36 +03:00
static bool idmap_tdb_upgrade ( struct db_context * db )
2006-12-12 17:52:13 +03:00
{
int32 vers ;
2007-10-19 04:40:25 +04:00
bool bigendianheader ;
2008-12-16 23:14:36 +03:00
struct convert_fn_state s ;
2006-12-12 17:52:13 +03:00
2007-04-17 20:06:20 +04:00
DEBUG ( 0 , ( " Upgrading winbindd_idmap.tdb from an old version \n " ) ) ;
2008-12-16 23:14:36 +03:00
bigendianheader = ( db - > get_flags ( db ) & TDB_BIGENDIAN ) ? True : False ;
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
vers = dbwrap_fetch_int32 ( db , " IDMAP_VERSION " ) ;
2006-12-12 17:52:13 +03:00
if ( ( ( vers = = - 1 ) & & bigendianheader ) | | ( IREV ( vers ) = = IDMAP_VERSION ) ) {
/* Arrggghh ! Bytereversed or old big-endian - make order independent ! */
/*
* high and low records were created on a
* big endian machine and will need byte - reversing .
*/
int32 wm ;
2008-12-16 23:14:36 +03:00
wm = dbwrap_fetch_int32 ( db , HWM_USER ) ;
2006-12-12 17:52:13 +03:00
if ( wm ! = - 1 ) {
wm = IREV ( wm ) ;
} else {
wm = idmap_tdb_state . low_uid ;
}
2008-12-16 23:14:36 +03:00
if ( dbwrap_store_int32 ( db , HWM_USER , wm ) = = - 1 ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " Unable to byteswap user hwm in idmap database \n " ) ) ;
return False ;
}
2008-12-16 23:14:36 +03:00
wm = dbwrap_fetch_int32 ( db , HWM_GROUP ) ;
2006-12-12 17:52:13 +03:00
if ( wm ! = - 1 ) {
wm = IREV ( wm ) ;
} else {
wm = idmap_tdb_state . low_gid ;
}
2008-12-16 23:14:36 +03:00
if ( dbwrap_store_int32 ( db , HWM_GROUP , wm ) = = - 1 ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " Unable to byteswap group hwm in idmap database \n " ) ) ;
return False ;
}
}
2008-12-16 23:14:36 +03:00
s . db = db ;
s . failed = false ;
2006-12-12 17:52:13 +03:00
/* the old format stored as DOMAIN/rid - now we store the SID direct */
2008-12-16 23:14:36 +03:00
db - > traverse ( db , convert_fn , & s ) ;
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
if ( s . failed ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " Problem during conversion \n " ) ) ;
return False ;
}
2008-12-16 23:14:36 +03:00
if ( dbwrap_store_int32 ( db , " IDMAP_VERSION " , IDMAP_VERSION ) = = - 1 ) {
2009-07-29 16:45:31 +04:00
DEBUG ( 0 , ( " Unable to store idmap version in databse \n " ) ) ;
2006-12-12 17:52:13 +03:00
return False ;
}
return True ;
}
2009-01-26 15:03:28 +03:00
static NTSTATUS idmap_tdb_load_ranges ( void )
2006-12-12 17:52:13 +03:00
{
2008-12-16 23:14:36 +03:00
uid_t low_uid = 0 ;
uid_t high_uid = 0 ;
gid_t low_gid = 0 ;
gid_t high_gid = 0 ;
2006-12-12 17:52:13 +03:00
2009-01-26 15:03:28 +03:00
if ( ! lp_idmap_uid ( & low_uid , & high_uid ) ) {
DEBUG ( 1 , ( " idmap uid missing \n " ) ) ;
return NT_STATUS_UNSUCCESSFUL ;
}
if ( ! lp_idmap_gid ( & low_gid , & high_gid ) ) {
DEBUG ( 1 , ( " idmap gid missing \n " ) ) ;
return NT_STATUS_UNSUCCESSFUL ;
2008-12-16 23:14:36 +03:00
}
idmap_tdb_state . low_uid = low_uid ;
idmap_tdb_state . high_uid = high_uid ;
idmap_tdb_state . low_gid = low_gid ;
idmap_tdb_state . high_gid = high_gid ;
if ( idmap_tdb_state . high_uid < = idmap_tdb_state . low_uid ) {
DEBUG ( 1 , ( " idmap uid range missing or invalid \n " ) ) ;
2009-01-26 15:03:28 +03:00
return NT_STATUS_UNSUCCESSFUL ;
2008-12-16 23:14:36 +03:00
}
if ( idmap_tdb_state . high_gid < = idmap_tdb_state . low_gid ) {
DEBUG ( 1 , ( " idmap gid range missing or invalid \n " ) ) ;
2009-01-26 15:03:28 +03:00
return NT_STATUS_UNSUCCESSFUL ;
}
return NT_STATUS_OK ;
}
static NTSTATUS idmap_tdb_open_db ( TALLOC_CTX * memctx ,
bool check_config ,
struct db_context * * dbctx )
{
NTSTATUS ret ;
TALLOC_CTX * ctx ;
char * tdbfile = NULL ;
struct db_context * db = NULL ;
int32_t version ;
bool config_error = false ;
ret = idmap_tdb_load_ranges ( ) ;
if ( ! NT_STATUS_IS_OK ( ret ) ) {
2008-12-16 23:14:36 +03:00
config_error = true ;
if ( check_config ) {
2009-01-26 15:03:28 +03:00
return ret ;
2008-12-16 23:14:36 +03:00
}
2006-12-12 17:52:13 +03:00
}
/* use our own context here */
2009-01-26 15:17:49 +03:00
ctx = talloc_stackframe ( ) ;
2006-12-12 17:52:13 +03:00
/* use the old database if present */
2009-01-26 15:17:49 +03:00
tdbfile = state_path ( " winbindd_idmap.tdb " ) ;
2006-12-12 17:52:13 +03:00
if ( ! tdbfile ) {
DEBUG ( 0 , ( " Out of memory! \n " ) ) ;
ret = NT_STATUS_NO_MEMORY ;
goto done ;
}
DEBUG ( 10 , ( " Opening tdbfile %s \n " , tdbfile ) ) ;
/* Open idmap repository */
2008-12-16 23:14:36 +03:00
db = db_open ( ctx , tdbfile , 0 , TDB_DEFAULT , O_RDWR | O_CREAT , 0644 ) ;
if ( ! db ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " Unable to open idmap database \n " ) ) ;
ret = NT_STATUS_UNSUCCESSFUL ;
goto done ;
}
/* check against earlier versions */
2008-12-16 23:14:36 +03:00
version = dbwrap_fetch_int32 ( db , " IDMAP_VERSION " ) ;
2006-12-12 17:52:13 +03:00
if ( version ! = IDMAP_VERSION ) {
2008-12-16 23:14:36 +03:00
if ( config_error ) {
DEBUG ( 0 , ( " Upgrade of IDMAP_VERSION from %d to %d is not "
" possible with incomplete configuration \n " ,
version , IDMAP_VERSION ) ) ;
ret = NT_STATUS_UNSUCCESSFUL ;
goto done ;
}
if ( db - > transaction_start ( db ) ! = 0 ) {
DEBUG ( 0 , ( " Unable to start upgrade transaction! \n " ) ) ;
ret = NT_STATUS_INTERNAL_DB_ERROR ;
goto done ;
}
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
if ( ! idmap_tdb_upgrade ( db ) ) {
db - > transaction_cancel ( db ) ;
2009-07-29 16:43:14 +04:00
DEBUG ( 0 , ( " Unable to open idmap database, it's in an old format, and upgrade failed! \n " ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_INTERNAL_DB_ERROR ;
goto done ;
}
2008-12-16 23:14:36 +03:00
if ( db - > transaction_commit ( db ) ! = 0 ) {
DEBUG ( 0 , ( " Unable to commit upgrade transaction! \n " ) ) ;
ret = NT_STATUS_INTERNAL_DB_ERROR ;
2006-12-12 17:52:13 +03:00
goto done ;
}
}
2008-12-16 23:14:36 +03:00
* dbctx = talloc_move ( memctx , & db ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_OK ;
done :
talloc_free ( ctx ) ;
return ret ;
}
/**********************************************************************
IDMAP ALLOC TDB BACKEND
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2008-12-16 23:14:36 +03:00
static struct db_context * idmap_alloc_db ;
2006-12-12 17:52:13 +03:00
/**********************************
Initialise idmap alloc database .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static NTSTATUS idmap_tdb_alloc_init ( const char * params )
{
2008-12-16 23:14:36 +03:00
int ret ;
NTSTATUS status ;
uint32_t low_uid ;
uint32_t low_gid ;
bool update_uid = false ;
bool update_gid = false ;
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
status = idmap_tdb_open_db ( NULL , true , & idmap_alloc_db ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
DEBUG ( 0 , ( " idmap will be unable to map foreign SIDs: %s \n " ,
nt_errstr ( status ) ) ) ;
return status ;
2006-12-12 17:52:13 +03:00
}
2008-12-16 23:14:36 +03:00
low_uid = dbwrap_fetch_int32 ( idmap_alloc_db , HWM_USER ) ;
if ( low_uid = = - 1 | | low_uid < idmap_tdb_state . low_uid ) {
update_uid = true ;
2006-12-12 17:52:13 +03:00
}
2008-12-16 23:14:36 +03:00
low_gid = dbwrap_fetch_int32 ( idmap_alloc_db , HWM_GROUP ) ;
if ( low_gid = = - 1 | | low_gid < idmap_tdb_state . low_gid ) {
update_gid = true ;
2006-12-12 17:52:13 +03:00
}
2008-12-16 23:14:36 +03:00
if ( ! update_uid & & ! update_gid ) {
return NT_STATUS_OK ;
2006-12-12 17:52:13 +03:00
}
2008-12-16 23:14:36 +03:00
if ( idmap_alloc_db - > transaction_start ( idmap_alloc_db ) ! = 0 ) {
TALLOC_FREE ( idmap_alloc_db ) ;
DEBUG ( 0 , ( " Unable to start upgrade transaction! \n " ) ) ;
return NT_STATUS_INTERNAL_DB_ERROR ;
2008-07-16 18:51:46 +04:00
}
2008-12-16 23:14:36 +03:00
if ( update_uid ) {
ret = dbwrap_store_int32 ( idmap_alloc_db , HWM_USER ,
idmap_tdb_state . low_uid ) ;
if ( ret = = - 1 ) {
idmap_alloc_db - > transaction_cancel ( idmap_alloc_db ) ;
TALLOC_FREE ( idmap_alloc_db ) ;
2008-07-16 18:51:46 +04:00
DEBUG ( 0 , ( " Unable to initialise user hwm in idmap "
" database \n " ) ) ;
return NT_STATUS_INTERNAL_DB_ERROR ;
}
}
2008-12-16 23:14:36 +03:00
if ( update_gid ) {
ret = dbwrap_store_int32 ( idmap_alloc_db , HWM_GROUP ,
idmap_tdb_state . low_gid ) ;
if ( ret = = - 1 ) {
idmap_alloc_db - > transaction_cancel ( idmap_alloc_db ) ;
TALLOC_FREE ( idmap_alloc_db ) ;
2008-07-16 18:51:46 +04:00
DEBUG ( 0 , ( " Unable to initialise group hwm in idmap "
" database \n " ) ) ;
return NT_STATUS_INTERNAL_DB_ERROR ;
2006-12-12 17:52:13 +03:00
}
}
2008-12-16 23:14:36 +03:00
if ( idmap_alloc_db - > transaction_commit ( idmap_alloc_db ) ! = 0 ) {
TALLOC_FREE ( idmap_alloc_db ) ;
DEBUG ( 0 , ( " Unable to commit upgrade transaction! \n " ) ) ;
return NT_STATUS_INTERNAL_DB_ERROR ;
}
2006-12-12 17:52:13 +03:00
return NT_STATUS_OK ;
}
/**********************************
Allocate a new id .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2010-06-16 11:19:21 +04:00
struct idmap_tdb_allocate_id_context {
const char * hwmkey ;
const char * hwmtype ;
uint32_t high_hwm ;
uint32_t hwm ;
} ;
static NTSTATUS idmap_tdb_allocate_id_action ( struct db_context * db ,
void * private_data )
2006-12-12 17:52:13 +03:00
{
2009-07-29 16:16:11 +04:00
NTSTATUS ret ;
2010-06-16 11:19:21 +04:00
struct idmap_tdb_allocate_id_context * state ;
uint32_t hwm ;
state = ( struct idmap_tdb_allocate_id_context * ) private_data ;
hwm = dbwrap_fetch_int32 ( db , state - > hwmkey ) ;
if ( hwm = = - 1 ) {
ret = NT_STATUS_INTERNAL_DB_ERROR ;
goto done ;
}
/* check it is in the range */
if ( hwm > state - > high_hwm ) {
DEBUG ( 1 , ( " Fatal Error: %s range full!! (max: %lu) \n " ,
state - > hwmtype , ( unsigned long ) state - > high_hwm ) ) ;
ret = NT_STATUS_UNSUCCESSFUL ;
goto done ;
}
/* fetch a new id and increment it */
ret = dbwrap_trans_change_uint32_atomic ( db , state - > hwmkey , & hwm , 1 ) ;
if ( ! NT_STATUS_IS_OK ( ret ) ) {
DEBUG ( 0 , ( " Fatal error while fetching a new %s value: %s \n ! " ,
state - > hwmtype , nt_errstr ( ret ) ) ) ;
goto done ;
}
/* recheck it is in the range */
if ( hwm > state - > high_hwm ) {
DEBUG ( 1 , ( " Fatal Error: %s range full!! (max: %lu) \n " ,
state - > hwmtype , ( unsigned long ) state - > high_hwm ) ) ;
ret = NT_STATUS_UNSUCCESSFUL ;
goto done ;
}
ret = NT_STATUS_OK ;
state - > hwm = hwm ;
done :
return ret ;
}
static NTSTATUS idmap_tdb_allocate_id ( struct unixid * xid )
{
2006-12-12 17:52:13 +03:00
const char * hwmkey ;
const char * hwmtype ;
uint32_t high_hwm ;
2010-06-16 11:19:21 +04:00
uint32_t hwm = 0 ;
NTSTATUS status ;
struct idmap_tdb_allocate_id_context state ;
2006-12-12 17:52:13 +03:00
/* Get current high water mark */
switch ( xid - > type ) {
case ID_TYPE_UID :
hwmkey = HWM_USER ;
hwmtype = " UID " ;
high_hwm = idmap_tdb_state . high_uid ;
break ;
case ID_TYPE_GID :
hwmkey = HWM_GROUP ;
hwmtype = " GID " ;
high_hwm = idmap_tdb_state . high_gid ;
break ;
default :
DEBUG ( 2 , ( " Invalid ID type (0x%x) \n " , xid - > type ) ) ;
return NT_STATUS_INVALID_PARAMETER ;
}
2010-06-16 11:19:21 +04:00
state . hwm = hwm ;
state . high_hwm = high_hwm ;
state . hwmtype = hwmtype ;
state . hwmkey = hwmkey ;
2009-01-25 02:48:34 +03:00
2010-06-16 11:19:21 +04:00
status = dbwrap_trans_do ( idmap_alloc_db , idmap_tdb_allocate_id_action ,
& state ) ;
2006-12-12 17:52:13 +03:00
2010-06-16 11:19:21 +04:00
if ( NT_STATUS_IS_OK ( status ) ) {
xid - > id = state . hwm ;
DEBUG ( 10 , ( " New %s = %d \n " , hwmtype , state . hwm ) ) ;
} else {
DEBUG ( 1 , ( " Error allocating a new %s \n " , hwmtype ) ) ;
2006-12-12 17:52:13 +03:00
}
2010-06-16 11:19:21 +04:00
return status ;
2006-12-12 17:52:13 +03:00
}
2010-06-16 11:26:17 +04:00
/**
* Allocate a new unix - ID .
* For now this is for the default idmap domain only .
* Should be extended later on .
*/
static NTSTATUS idmap_tdb_get_new_id ( struct idmap_domain * dom ,
struct unixid * id )
{
NTSTATUS ret ;
if ( ! strequal ( dom - > name , " * " ) ) {
DEBUG ( 3 , ( " idmap_tdb_get_new_id: "
" Refusing allocation of a new unixid for domain'%s'. "
" Currently only supported for the default "
" domain \" * \" . \n " ,
dom - > name ) ) ;
return NT_STATUS_NOT_IMPLEMENTED ;
}
ret = idmap_tdb_allocate_id ( id ) ;
return ret ;
}
2006-12-12 17:52:13 +03:00
/**********************************
Close the alloc tdb
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static NTSTATUS idmap_tdb_alloc_close ( void )
{
2008-12-16 23:14:36 +03:00
TALLOC_FREE ( idmap_alloc_db ) ;
2006-12-12 17:52:13 +03:00
return NT_STATUS_OK ;
}
/**********************************************************************
IDMAP MAPPING TDB BACKEND
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
struct idmap_tdb_context {
2008-12-16 23:14:36 +03:00
struct db_context * db ;
2006-12-12 17:52:13 +03:00
uint32_t filter_low_id ;
uint32_t filter_high_id ;
} ;
/*****************************
Initialise idmap database .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2008-07-13 14:07:40 +04:00
static NTSTATUS idmap_tdb_db_init ( struct idmap_domain * dom , const char * params )
2006-12-12 17:52:13 +03:00
{
NTSTATUS ret ;
struct idmap_tdb_context * ctx ;
2009-05-27 21:14:10 +04:00
DEBUG ( 10 , ( " idmap_tdb_db_init called for domain '%s' \n " , dom - > name ) ) ;
2006-12-12 17:52:13 +03:00
ctx = talloc ( dom , struct idmap_tdb_context ) ;
if ( ! ctx ) {
DEBUG ( 0 , ( " Out of memory! \n " ) ) ;
return NT_STATUS_NO_MEMORY ;
}
2009-05-27 21:12:28 +04:00
if ( strequal ( dom - > name , " * " ) ) {
uid_t low_uid = 0 ;
uid_t high_uid = 0 ;
gid_t low_gid = 0 ;
gid_t high_gid = 0 ;
2006-12-12 17:52:13 +03:00
2009-05-27 21:12:28 +04:00
ctx - > filter_low_id = 0 ;
ctx - > filter_high_id = 0 ;
if ( lp_idmap_uid ( & low_uid , & high_uid ) ) {
ctx - > filter_low_id = low_uid ;
ctx - > filter_high_id = high_uid ;
} else {
DEBUG ( 3 , ( " Warning: 'idmap uid' not set! \n " ) ) ;
}
if ( lp_idmap_gid ( & low_gid , & high_gid ) ) {
if ( ( low_gid ! = low_uid ) | | ( high_gid ! = high_uid ) ) {
DEBUG ( 1 , ( " Warning: 'idmap uid' and 'idmap gid' "
" ranges do not agree -- building "
" intersection \n " ) ) ;
ctx - > filter_low_id = MAX ( ctx - > filter_low_id ,
low_gid ) ;
ctx - > filter_high_id = MIN ( ctx - > filter_high_id ,
high_gid ) ;
}
} else {
DEBUG ( 3 , ( " Warning: 'idmap gid' not set! \n " ) ) ;
}
} else {
char * config_option = NULL ;
const char * range ;
config_option = talloc_asprintf ( ctx , " idmap config %s " , dom - > name ) ;
if ( ! config_option ) {
DEBUG ( 0 , ( " Out of memory! \n " ) ) ;
ret = NT_STATUS_NO_MEMORY ;
goto failed ;
}
range = lp_parm_const_string ( - 1 , config_option , " range " , NULL ) ;
if ( ( ! range ) | |
( sscanf ( range , " %u - %u " , & ctx - > filter_low_id , & ctx - > filter_high_id ) ! = 2 ) )
{
ctx - > filter_low_id = 0 ;
ctx - > filter_high_id = 0 ;
}
talloc_free ( config_option ) ;
2006-12-12 17:52:13 +03:00
}
2009-05-27 21:12:28 +04:00
if ( ctx - > filter_low_id > ctx - > filter_high_id ) {
2006-12-12 17:52:13 +03:00
ctx - > filter_low_id = 0 ;
ctx - > filter_high_id = 0 ;
}
2009-05-27 21:12:28 +04:00
DEBUG ( 10 , ( " idmap_tdb_db_init: filter range %u-%u loaded for domain "
" '%s' \n " , ctx - > filter_low_id , ctx - > filter_high_id , dom - > name ) ) ;
ret = idmap_tdb_open_db ( ctx , false , & ctx - > db ) ;
if ( ! NT_STATUS_IS_OK ( ret ) ) {
goto failed ;
}
2006-12-12 17:52:13 +03:00
dom - > private_data = ctx ;
return NT_STATUS_OK ;
failed :
talloc_free ( ctx ) ;
return ret ;
}
/**********************************
Single id to sid lookup function .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2010-06-17 09:32:12 +04:00
static NTSTATUS idmap_tdb_id_to_sid ( struct idmap_domain * dom , struct id_map * map )
2006-12-12 17:52:13 +03:00
{
NTSTATUS ret ;
2007-03-27 15:01:37 +04:00
TDB_DATA data ;
char * keystr ;
2010-06-17 09:32:12 +04:00
struct idmap_tdb_context * ctx ;
2006-12-12 17:52:13 +03:00
2010-06-17 09:32:12 +04:00
if ( ! dom | | ! map ) {
2006-12-12 17:52:13 +03:00
return NT_STATUS_INVALID_PARAMETER ;
}
2010-06-17 09:32:12 +04:00
ctx = talloc_get_type ( dom - > private_data , struct idmap_tdb_context ) ;
2006-12-12 17:52:13 +03:00
/* apply filters before checking */
2010-06-17 09:42:00 +04:00
if ( ! idmap_unix_id_is_in_range ( map - > xid . id , dom ) ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 5 , ( " Requested id (%u) out of range (%u - %u). Filtered! \n " ,
2010-06-17 09:42:00 +04:00
map - > xid . id , dom - > low_id , dom - > high_id ) ) ;
2006-12-12 17:52:13 +03:00
return NT_STATUS_NONE_MAPPED ;
}
switch ( map - > xid . type ) {
case ID_TYPE_UID :
2007-03-27 15:01:37 +04:00
keystr = talloc_asprintf ( ctx , " UID %lu " , ( unsigned long ) map - > xid . id ) ;
2006-12-12 17:52:13 +03:00
break ;
case ID_TYPE_GID :
2007-03-27 15:01:37 +04:00
keystr = talloc_asprintf ( ctx , " GID %lu " , ( unsigned long ) map - > xid . id ) ;
2006-12-12 17:52:13 +03:00
break ;
default :
DEBUG ( 2 , ( " INVALID unix ID type: 0x02%x \n " , map - > xid . type ) ) ;
return NT_STATUS_INVALID_PARAMETER ;
}
/* final SAFE_FREE safe */
data . dptr = NULL ;
2007-03-27 15:01:37 +04:00
if ( keystr = = NULL ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " Out of memory! \n " ) ) ;
ret = NT_STATUS_NO_MEMORY ;
goto done ;
}
2007-03-27 15:01:37 +04:00
DEBUG ( 10 , ( " Fetching record %s \n " , keystr ) ) ;
2006-12-12 17:52:13 +03:00
/* Check if the mapping exists */
2008-12-16 23:14:36 +03:00
data = dbwrap_fetch_bystring ( ctx - > db , NULL , keystr ) ;
2006-12-12 17:52:13 +03:00
if ( ! data . dptr ) {
2007-03-27 15:01:37 +04:00
DEBUG ( 10 , ( " Record %s not found \n " , keystr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_NONE_MAPPED ;
goto done ;
}
2007-03-29 13:35:51 +04:00
if ( ! string_to_sid ( map - > sid , ( const char * ) data . dptr ) ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 10 , ( " INVALID SID (%s) in record %s \n " ,
2007-03-29 13:35:51 +04:00
( const char * ) data . dptr , keystr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_INTERNAL_DB_ERROR ;
goto done ;
}
2007-03-29 13:35:51 +04:00
DEBUG ( 10 , ( " Found record %s -> %s \n " , keystr , ( const char * ) data . dptr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_OK ;
done :
2008-12-16 23:14:36 +03:00
talloc_free ( data . dptr ) ;
2007-03-27 15:01:37 +04:00
talloc_free ( keystr ) ;
2006-12-12 17:52:13 +03:00
return ret ;
}
/**********************************
Single sid to id lookup function .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2010-06-17 09:35:28 +04:00
static NTSTATUS idmap_tdb_sid_to_id ( struct idmap_domain * dom , struct id_map * map )
2006-12-12 17:52:13 +03:00
{
NTSTATUS ret ;
2007-03-27 15:01:37 +04:00
TDB_DATA data ;
char * keystr ;
2006-12-12 17:52:13 +03:00
unsigned long rec_id = 0 ;
2010-06-17 09:35:28 +04:00
struct idmap_tdb_context * ctx ;
2009-01-23 02:52:28 +03:00
TALLOC_CTX * tmp_ctx = talloc_stackframe ( ) ;
2006-12-12 17:52:13 +03:00
2010-06-17 09:35:28 +04:00
ctx = talloc_get_type ( dom - > private_data , struct idmap_tdb_context ) ;
2009-01-23 02:52:28 +03:00
keystr = sid_string_talloc ( tmp_ctx , map - > sid ) ;
if ( keystr = = NULL ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " Out of memory! \n " ) ) ;
ret = NT_STATUS_NO_MEMORY ;
goto done ;
}
2007-03-27 15:01:37 +04:00
DEBUG ( 10 , ( " Fetching record %s \n " , keystr ) ) ;
2006-12-12 17:52:13 +03:00
/* Check if sid is present in database */
2009-01-23 02:52:28 +03:00
data = dbwrap_fetch_bystring ( ctx - > db , tmp_ctx , keystr ) ;
2006-12-12 17:52:13 +03:00
if ( ! data . dptr ) {
2007-03-27 15:01:37 +04:00
DEBUG ( 10 , ( " Record %s not found \n " , keystr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_NONE_MAPPED ;
goto done ;
}
/* What type of record is this ? */
2007-03-29 13:35:51 +04:00
if ( sscanf ( ( const char * ) data . dptr , " UID %lu " , & rec_id ) = = 1 ) { /* Try a UID record. */
2006-12-12 17:52:13 +03:00
map - > xid . id = rec_id ;
map - > xid . type = ID_TYPE_UID ;
2007-03-29 13:35:51 +04:00
DEBUG ( 10 , ( " Found uid record %s -> %s \n " , keystr , ( const char * ) data . dptr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_OK ;
2007-03-29 13:35:51 +04:00
} else if ( sscanf ( ( const char * ) data . dptr , " GID %lu " , & rec_id ) = = 1 ) { /* Try a GID record. */
2006-12-12 17:52:13 +03:00
map - > xid . id = rec_id ;
map - > xid . type = ID_TYPE_GID ;
2007-03-29 13:35:51 +04:00
DEBUG ( 10 , ( " Found gid record %s -> %s \n " , keystr , ( const char * ) data . dptr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_OK ;
} else { /* Unknown record type ! */
2007-03-29 13:35:51 +04:00
DEBUG ( 2 , ( " Found INVALID record %s -> %s \n " , keystr , ( const char * ) data . dptr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_INTERNAL_DB_ERROR ;
2010-05-17 12:39:00 +04:00
goto done ;
2006-12-12 17:52:13 +03:00
}
/* apply filters before returning result */
2010-06-17 09:42:00 +04:00
if ( ! idmap_unix_id_is_in_range ( map - > xid . id , dom ) ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 5 , ( " Requested id (%u) out of range (%u - %u). Filtered! \n " ,
2010-06-17 09:42:00 +04:00
map - > xid . id , dom - > low_id , dom - > high_id ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_NONE_MAPPED ;
}
done :
2009-01-23 02:52:28 +03:00
talloc_free ( tmp_ctx ) ;
2006-12-12 17:52:13 +03:00
return ret ;
}
/**********************************
lookup a set of unix ids .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static NTSTATUS idmap_tdb_unixids_to_sids ( struct idmap_domain * dom , struct id_map * * ids )
{
struct idmap_tdb_context * ctx ;
NTSTATUS ret ;
int i ;
2009-03-02 09:19:50 +03:00
/* initialize the status to avoid suprise */
for ( i = 0 ; ids [ i ] ; i + + ) {
ids [ i ] - > status = ID_UNKNOWN ;
}
2006-12-12 17:52:13 +03:00
ctx = talloc_get_type ( dom - > private_data , struct idmap_tdb_context ) ;
for ( i = 0 ; ids [ i ] ; i + + ) {
2010-06-17 09:32:12 +04:00
ret = idmap_tdb_id_to_sid ( dom , ids [ i ] ) ;
2006-12-12 17:52:13 +03:00
if ( ! NT_STATUS_IS_OK ( ret ) ) {
/* if it is just a failed mapping continue */
if ( NT_STATUS_EQUAL ( ret , NT_STATUS_NONE_MAPPED ) ) {
/* make sure it is marked as unmapped */
2007-01-14 20:58:24 +03:00
ids [ i ] - > status = ID_UNMAPPED ;
2006-12-12 17:52:13 +03:00
continue ;
}
/* some fatal error occurred, return immediately */
goto done ;
}
/* all ok, id is mapped */
2007-01-14 20:58:24 +03:00
ids [ i ] - > status = ID_MAPPED ;
2006-12-12 17:52:13 +03:00
}
ret = NT_STATUS_OK ;
done :
return ret ;
}
/**********************************
lookup a set of sids .
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static NTSTATUS idmap_tdb_sids_to_unixids ( struct idmap_domain * dom , struct id_map * * ids )
{
struct idmap_tdb_context * ctx ;
NTSTATUS ret ;
int i ;
2009-03-02 09:19:50 +03:00
/* initialize the status to avoid suprise */
for ( i = 0 ; ids [ i ] ; i + + ) {
ids [ i ] - > status = ID_UNKNOWN ;
}
2006-12-12 17:52:13 +03:00
ctx = talloc_get_type ( dom - > private_data , struct idmap_tdb_context ) ;
for ( i = 0 ; ids [ i ] ; i + + ) {
2010-06-17 09:35:28 +04:00
ret = idmap_tdb_sid_to_id ( dom , ids [ i ] ) ;
2006-12-12 17:52:13 +03:00
if ( ! NT_STATUS_IS_OK ( ret ) ) {
/* if it is just a failed mapping continue */
if ( NT_STATUS_EQUAL ( ret , NT_STATUS_NONE_MAPPED ) ) {
/* make sure it is marked as unmapped */
2007-01-14 20:58:24 +03:00
ids [ i ] - > status = ID_UNMAPPED ;
2006-12-12 17:52:13 +03:00
continue ;
}
/* some fatal error occurred, return immediately */
goto done ;
}
/* all ok, id is mapped */
2007-01-14 20:58:24 +03:00
ids [ i ] - > status = ID_MAPPED ;
2006-12-12 17:52:13 +03:00
}
ret = NT_STATUS_OK ;
done :
return ret ;
}
/**********************************
2008-10-28 09:36:36 +03:00
set a mapping .
2006-12-12 17:52:13 +03:00
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2008-10-28 09:36:36 +03:00
static NTSTATUS idmap_tdb_set_mapping ( struct idmap_domain * dom ,
const struct id_map * map )
2006-12-12 17:52:13 +03:00
{
struct idmap_tdb_context * ctx ;
NTSTATUS ret ;
2008-12-16 23:14:36 +03:00
TDB_DATA ksid , kid ;
2007-03-27 15:01:37 +04:00
char * ksidstr , * kidstr ;
2007-12-16 00:00:39 +03:00
fstring tmp ;
2006-12-12 17:52:13 +03:00
if ( ! map | | ! map - > sid ) {
return NT_STATUS_INVALID_PARAMETER ;
}
2007-03-27 15:01:37 +04:00
ksidstr = kidstr = NULL ;
2006-12-12 17:52:13 +03:00
/* TODO: should we filter a set_mapping using low/high filters ? */
2008-10-28 09:36:36 +03:00
2006-12-12 17:52:13 +03:00
ctx = talloc_get_type ( dom - > private_data , struct idmap_tdb_context ) ;
switch ( map - > xid . type ) {
case ID_TYPE_UID :
2008-10-28 09:36:36 +03:00
kidstr = talloc_asprintf ( ctx , " UID %lu " ,
( unsigned long ) map - > xid . id ) ;
2006-12-12 17:52:13 +03:00
break ;
2008-10-28 09:36:36 +03:00
2006-12-12 17:52:13 +03:00
case ID_TYPE_GID :
2008-10-28 09:36:36 +03:00
kidstr = talloc_asprintf ( ctx , " GID %lu " ,
( unsigned long ) map - > xid . id ) ;
2006-12-12 17:52:13 +03:00
break ;
default :
DEBUG ( 2 , ( " INVALID unix ID type: 0x02%x \n " , map - > xid . type ) ) ;
return NT_STATUS_INVALID_PARAMETER ;
}
2007-03-27 15:01:37 +04:00
if ( kidstr = = NULL ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " ERROR: Out of memory! \n " ) ) ;
ret = NT_STATUS_NO_MEMORY ;
goto done ;
}
2007-12-16 00:00:39 +03:00
if ( ( ksidstr = talloc_asprintf (
2007-12-16 00:47:30 +03:00
ctx , " %s " , sid_to_fstring ( tmp , map - > sid ) ) ) = = NULL ) {
2006-12-12 17:52:13 +03:00
DEBUG ( 0 , ( " Out of memory! \n " ) ) ;
ret = NT_STATUS_NO_MEMORY ;
goto done ;
}
2007-03-27 15:01:37 +04:00
DEBUG ( 10 , ( " Storing %s <-> %s map \n " , ksidstr , kidstr ) ) ;
kid = string_term_tdb_data ( kidstr ) ;
ksid = string_term_tdb_data ( ksidstr ) ;
2006-12-12 17:52:13 +03:00
2008-12-16 23:14:36 +03:00
if ( ctx - > db - > transaction_start ( ctx - > db ) ! = 0 ) {
DEBUG ( 0 , ( " Failed to start transaction for %s \n " ,
ksidstr ) ) ;
ret = NT_STATUS_INTERNAL_DB_ERROR ;
goto done ;
2006-12-12 17:52:13 +03:00
}
2008-12-16 23:14:36 +03:00
ret = dbwrap_store ( ctx - > db , ksid , kid , TDB_REPLACE ) ;
if ( ! NT_STATUS_IS_OK ( ret ) ) {
ctx - > db - > transaction_cancel ( ctx - > db ) ;
DEBUG ( 0 , ( " Error storing SID -> ID (%s -> %s): %s \n " ,
ksidstr , kidstr , nt_errstr ( ret ) ) ) ;
goto done ;
2006-12-12 17:52:13 +03:00
}
2008-12-16 23:14:36 +03:00
ret = dbwrap_store ( ctx - > db , kid , ksid , TDB_REPLACE ) ;
if ( ! NT_STATUS_IS_OK ( ret ) ) {
ctx - > db - > transaction_cancel ( ctx - > db ) ;
DEBUG ( 0 , ( " Error storing ID -> SID (%s -> %s): %s \n " ,
kidstr , ksidstr , nt_errstr ( ret ) ) ) ;
2006-12-12 17:52:13 +03:00
goto done ;
}
2008-12-16 23:14:36 +03:00
if ( ctx - > db - > transaction_commit ( ctx - > db ) ! = 0 ) {
DEBUG ( 0 , ( " Failed to commit transaction for (%s -> %s) \n " ,
ksidstr , kidstr ) ) ;
ret = NT_STATUS_INTERNAL_DB_ERROR ;
2006-12-12 17:52:13 +03:00
goto done ;
}
2007-03-27 15:01:37 +04:00
DEBUG ( 10 , ( " Stored %s <-> %s \n " , ksidstr , kidstr ) ) ;
2006-12-12 17:52:13 +03:00
ret = NT_STATUS_OK ;
done :
2007-03-27 15:01:37 +04:00
talloc_free ( ksidstr ) ;
talloc_free ( kidstr ) ;
2006-12-12 17:52:13 +03:00
return ret ;
}
/**********************************
Close the idmap tdb instance
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
static NTSTATUS idmap_tdb_close ( struct idmap_domain * dom )
{
struct idmap_tdb_context * ctx ;
if ( dom - > private_data ) {
ctx = talloc_get_type ( dom - > private_data , struct idmap_tdb_context ) ;
2008-12-16 23:14:36 +03:00
TALLOC_FREE ( ctx - > db ) ;
2006-12-12 17:52:13 +03:00
}
return NT_STATUS_OK ;
}
static struct idmap_methods db_methods = {
. init = idmap_tdb_db_init ,
. unixids_to_sids = idmap_tdb_unixids_to_sids ,
. sids_to_unixids = idmap_tdb_sids_to_unixids ,
2010-06-22 16:41:31 +04:00
. allocate_id = idmap_tdb_get_new_id ,
2006-12-12 17:52:13 +03:00
. close_fn = idmap_tdb_close
} ;
NTSTATUS idmap_tdb_init ( void )
{
2008-07-13 14:07:40 +04:00
DEBUG ( 10 , ( " calling idmap_tdb_init \n " ) ) ;
2006-12-12 17:52:13 +03:00
return smb_register_idmap ( SMB_IDMAP_INTERFACE_VERSION , " tdb " , & db_methods ) ;
}