2009-08-05 00:26:07 +04:00
/*
Unix SMB / CIFS implementation .
async implementation of WINBINDD_GETGROUPS
Copyright ( C ) Volker Lendecke 2009
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation ; either version 3 of the License , or
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
along with this program . If not , see < http : //www.gnu.org/licenses/>.
*/
# include "includes.h"
# include "winbindd.h"
2011-03-30 17:09:10 +04:00
# include "passdb/lookup_sid.h" /* only for LOOKUP_NAME_NO_NSS flag */
2018-11-23 10:55:13 +03:00
# include "libcli/security/dom_sid.h"
2009-08-05 00:26:07 +04:00
struct winbindd_getgroups_state {
struct tevent_context * ev ;
2023-10-20 13:53:10 +03:00
char * namespace ;
char * domname ;
char * username ;
2009-08-05 00:26:07 +04:00
struct dom_sid sid ;
enum lsa_SidType type ;
2022-07-11 22:40:08 +03:00
uint32_t num_sids ;
2009-08-05 00:26:07 +04:00
struct dom_sid * sids ;
2022-07-14 14:19:44 +03:00
uint32_t num_gids ;
2009-08-05 00:26:07 +04:00
gid_t * gids ;
} ;
static void winbindd_getgroups_lookupname_done ( struct tevent_req * subreq ) ;
static void winbindd_getgroups_gettoken_done ( struct tevent_req * subreq ) ;
static void winbindd_getgroups_sid2gid_done ( struct tevent_req * subreq ) ;
struct tevent_req * winbindd_getgroups_send ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
2009-08-16 14:46:55 +04:00
struct winbindd_cli_state * cli ,
2009-08-05 00:26:07 +04:00
struct winbindd_request * request )
{
struct tevent_req * req , * subreq ;
struct winbindd_getgroups_state * state ;
char * domuser , * mapped_user ;
NTSTATUS status ;
2018-04-26 13:17:12 +03:00
bool ok ;
2009-08-05 00:26:07 +04:00
req = tevent_req_create ( mem_ctx , & state ,
struct winbindd_getgroups_state ) ;
if ( req = = NULL ) {
return NULL ;
}
state - > ev = ev ;
/* Ensure null termination */
request - > data . username [ sizeof ( request - > data . username ) - 1 ] = ' \0 ' ;
2021-08-05 11:44:27 +03:00
D_NOTICE ( " [%s (%u)] Winbind external command GETGROUPS start. \n "
" Searching groups for username '%s'. \n " ,
cli - > client_name ,
( unsigned int ) cli - > pid ,
request - > data . username ) ;
2009-08-05 00:26:07 +04:00
domuser = request - > data . username ;
status = normalize_name_unmap ( state , domuser , & mapped_user ) ;
if ( NT_STATUS_IS_OK ( status )
| | NT_STATUS_EQUAL ( status , NT_STATUS_FILE_RENAMED ) ) {
/* normalize_name_unmapped did something */
domuser = mapped_user ;
}
2023-10-20 13:53:10 +03:00
ok = parse_domain_user ( state , domuser ,
& state - > namespace ,
& state - > domname ,
& state - > username ) ;
2018-04-26 13:17:12 +03:00
if ( ! ok ) {
2021-08-05 11:44:27 +03:00
D_WARNING ( " Could not parse domain user: %s \n " , domuser ) ;
2009-08-05 00:26:07 +04:00
tevent_req_nterror ( req , NT_STATUS_INVALID_PARAMETER ) ;
return tevent_req_post ( req , ev ) ;
}
2018-02-22 16:10:28 +03:00
subreq = wb_lookupname_send ( state , ev ,
2018-04-26 13:17:12 +03:00
state - > namespace ,
2018-02-22 16:10:28 +03:00
state - > domname ,
state - > username ,
2009-08-05 00:26:07 +04:00
LOOKUP_NAME_NO_NSS ) ;
if ( tevent_req_nomem ( subreq , req ) ) {
return tevent_req_post ( req , ev ) ;
}
tevent_req_set_callback ( subreq , winbindd_getgroups_lookupname_done ,
req ) ;
return req ;
}
static void winbindd_getgroups_lookupname_done ( struct tevent_req * subreq )
{
struct tevent_req * req = tevent_req_callback_data (
subreq , struct tevent_req ) ;
struct winbindd_getgroups_state * state = tevent_req_data (
req , struct winbindd_getgroups_state ) ;
NTSTATUS status ;
status = wb_lookupname_recv ( subreq , & state - > sid , & state - > type ) ;
TALLOC_FREE ( subreq ) ;
2024-02-16 18:44:57 +03:00
if ( NT_STATUS_IS_OK ( status ) & & state - > type = = SID_NAME_UNKNOWN ) {
status = NT_STATUS_NONE_MAPPED ;
}
2011-05-10 13:05:47 +04:00
if ( tevent_req_nterror ( req , status ) ) {
2009-08-05 00:26:07 +04:00
return ;
}
2017-01-03 17:54:46 +03:00
subreq = wb_gettoken_send ( state , state - > ev , & state - > sid , true ) ;
2009-08-05 00:26:07 +04:00
if ( tevent_req_nomem ( subreq , req ) ) {
return ;
}
tevent_req_set_callback ( subreq , winbindd_getgroups_gettoken_done , req ) ;
}
static void winbindd_getgroups_gettoken_done ( struct tevent_req * subreq )
{
struct tevent_req * req = tevent_req_callback_data (
subreq , struct tevent_req ) ;
struct winbindd_getgroups_state * state = tevent_req_data (
req , struct winbindd_getgroups_state ) ;
NTSTATUS status ;
status = wb_gettoken_recv ( subreq , state , & state - > num_sids ,
& state - > sids ) ;
TALLOC_FREE ( subreq ) ;
2011-05-10 13:05:47 +04:00
if ( tevent_req_nterror ( req , status ) ) {
2009-08-05 00:26:07 +04:00
return ;
}
/*
* Convert the group SIDs to gids . state - > sids [ 0 ] contains the user
2013-07-26 13:32:34 +04:00
* sid . If the idmap backend uses ID_TYPE_BOTH , we might need the
* the id of the user sid in the list of group sids , so map the
* complete token .
2009-08-05 00:26:07 +04:00
*/
2012-11-23 19:54:36 +04:00
subreq = wb_sids2xids_send ( state , state - > ev ,
2013-07-26 14:25:27 +04:00
state - > sids , state - > num_sids ) ;
2009-08-05 00:26:07 +04:00
if ( tevent_req_nomem ( subreq , req ) ) {
return ;
}
tevent_req_set_callback ( subreq , winbindd_getgroups_sid2gid_done , req ) ;
}
static void winbindd_getgroups_sid2gid_done ( struct tevent_req * subreq )
{
struct tevent_req * req = tevent_req_callback_data (
subreq , struct tevent_req ) ;
struct winbindd_getgroups_state * state = tevent_req_data (
req , struct winbindd_getgroups_state ) ;
NTSTATUS status ;
2013-07-26 14:25:27 +04:00
struct unixid * xids ;
2022-07-11 22:40:08 +03:00
uint32_t i ;
2009-08-05 00:26:07 +04:00
2013-07-26 14:25:27 +04:00
xids = talloc_array ( state , struct unixid , state - > num_sids ) ;
if ( tevent_req_nomem ( xids , req ) ) {
return ;
}
for ( i = 0 ; i < state - > num_sids ; i + + ) {
xids [ i ] . type = ID_TYPE_NOT_SPECIFIED ;
xids [ i ] . id = UINT32_MAX ;
}
2012-11-23 19:54:36 +04:00
2015-03-05 22:59:16 +03:00
status = wb_sids2xids_recv ( subreq , xids , state - > num_sids ) ;
2009-08-05 00:26:07 +04:00
TALLOC_FREE ( subreq ) ;
2013-07-26 13:31:41 +04:00
if ( NT_STATUS_EQUAL ( status , NT_STATUS_NONE_MAPPED ) | |
NT_STATUS_EQUAL ( status , STATUS_SOME_UNMAPPED ) )
{
status = NT_STATUS_OK ;
}
if ( tevent_req_nterror ( req , status ) ) {
return ;
}
2013-07-26 14:25:27 +04:00
state - > gids = talloc_array ( state , gid_t , state - > num_sids ) ;
if ( tevent_req_nomem ( state - > gids , req ) ) {
return ;
2012-11-23 19:54:36 +04:00
}
2013-07-26 14:25:27 +04:00
state - > num_gids = 0 ;
2009-08-05 00:26:07 +04:00
2013-07-26 14:25:27 +04:00
for ( i = 0 ; i < state - > num_sids ; i + + ) {
bool include_gid = false ;
2013-07-26 14:26:30 +04:00
const char * debug_missing = NULL ;
2009-08-05 00:26:07 +04:00
2013-07-26 14:25:27 +04:00
switch ( xids [ i ] . type ) {
case ID_TYPE_NOT_SPECIFIED :
2013-07-26 14:26:30 +04:00
debug_missing = " not specified " ;
break ;
2013-07-26 14:25:27 +04:00
case ID_TYPE_UID :
2013-07-26 14:26:30 +04:00
if ( i ! = 0 ) {
debug_missing = " uid " ;
}
2013-07-26 14:25:27 +04:00
break ;
case ID_TYPE_GID :
case ID_TYPE_BOTH :
include_gid = true ;
break ;
2020-09-15 18:26:11 +03:00
case ID_TYPE_WB_REQUIRE_TYPE :
/*
* these are internal between winbindd
* parent and child .
*/
smb_panic ( __location__ ) ;
break ;
2013-07-26 14:25:27 +04:00
}
if ( ! include_gid ) {
2018-11-23 10:55:13 +03:00
struct dom_sid_buf sidbuf ;
2013-07-26 14:26:30 +04:00
if ( debug_missing = = NULL ) {
continue ;
}
2022-07-18 16:28:11 +03:00
D_WARNING ( " WARNING: skipping unix id (% " PRIu32 " ) for sid %s "
2021-08-05 11:44:27 +03:00
" from group list because the idmap type "
" is %s. "
" This might be a security problem when ACLs "
" contain DENY ACEs! \n " ,
( unsigned ) xids [ i ] . id ,
dom_sid_str_buf ( & state - > sids [ i ] , & sidbuf ) ,
debug_missing ) ;
2013-07-26 14:25:27 +04:00
continue ;
}
state - > gids [ state - > num_gids ] = ( gid_t ) xids [ i ] . id ;
state - > num_gids + = 1 ;
2009-08-05 00:26:07 +04:00
}
2013-07-26 14:25:27 +04:00
/*
* This should not fail , as it does not do any reallocation ,
* just updating the talloc size .
*/
state - > gids = talloc_realloc ( state , state - > gids , gid_t , state - > num_gids ) ;
if ( tevent_req_nomem ( state - > gids , req ) ) {
2009-08-05 00:26:07 +04:00
return ;
}
2013-07-26 14:25:27 +04:00
tevent_req_done ( req ) ;
2009-08-05 00:26:07 +04:00
}
NTSTATUS winbindd_getgroups_recv ( struct tevent_req * req ,
struct winbindd_response * response )
{
struct winbindd_getgroups_state * state = tevent_req_data (
req , struct winbindd_getgroups_state ) ;
NTSTATUS status ;
2022-07-14 14:19:44 +03:00
uint32_t i ;
2009-08-05 00:26:07 +04:00
if ( tevent_req_is_nterror ( req , & status ) ) {
2018-12-14 23:09:51 +03:00
struct dom_sid_buf buf ;
2021-08-05 11:44:27 +03:00
D_WARNING ( " Could not convert sid %s: %s \n " ,
2018-12-14 23:09:51 +03:00
dom_sid_str_buf ( & state - > sid , & buf ) ,
2021-08-05 11:44:27 +03:00
nt_errstr ( status ) ) ;
2009-08-05 00:26:07 +04:00
return status ;
}
response - > data . num_entries = state - > num_gids ;
2021-08-05 11:44:27 +03:00
D_NOTICE ( " Winbind external command GETGROUPS end. \n "
2022-07-18 16:28:11 +03:00
" Received % " PRIu32 " entries. \n " ,
2021-08-05 11:44:27 +03:00
response - > data . num_entries ) ;
2022-07-19 17:21:57 +03:00
if ( CHECK_DEBUGLVL ( DBGLVL_NOTICE ) ) {
for ( i = 0 ; i < state - > num_gids ; i + + ) {
D_NOTICE ( " % " PRIu32 " : GID %u \n " , i , state - > gids [ i ] ) ;
}
2021-08-05 11:44:27 +03:00
}
2009-08-05 00:26:07 +04:00
if ( state - > num_gids > 0 ) {
response - > extra_data . data = talloc_move ( response ,
& state - > gids ) ;
response - > length + = state - > num_gids * sizeof ( gid_t ) ;
}
2021-08-05 11:44:27 +03:00
2009-08-05 00:26:07 +04:00
return NT_STATUS_OK ;
}