2010-04-01 18:44:16 +04:00
/*
Unix SMB / CIFS implementation .
async implementation of WINBINDD_PAM_LOGOFF
Copyright ( C ) Volker Lendecke 2010
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation ; either version 3 of the License , or
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
along with this program . If not , see < http : //www.gnu.org/licenses/>.
*/
# include "includes.h"
2022-06-24 15:51:07 +03:00
# include "util/debug.h"
2010-04-01 18:44:16 +04:00
# include "winbindd.h"
2021-01-03 23:53:49 +03:00
# include "lib/global_contexts.h"
2021-06-16 18:39:02 +03:00
# include "librpc/gen_ndr/ndr_winbind_c.h"
2023-10-21 14:13:19 +03:00
# include "lib/util/string_wrappers.h"
2010-04-01 18:44:16 +04:00
struct winbindd_pam_logoff_state {
2021-06-16 18:39:02 +03:00
struct wbint_PamLogOff r ;
2010-04-01 18:44:16 +04:00
} ;
static void winbindd_pam_logoff_done ( struct tevent_req * subreq ) ;
struct tevent_req * winbindd_pam_logoff_send ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
struct winbindd_cli_state * cli ,
struct winbindd_request * request )
{
struct tevent_req * req , * subreq ;
struct winbindd_pam_logoff_state * state ;
struct winbindd_domain * domain ;
2023-10-21 14:13:19 +03:00
char * name_namespace = NULL ;
char * name_domain = NULL ;
char * user = NULL ;
char * logoff_user = NULL ;
2010-04-01 18:44:16 +04:00
uid_t caller_uid ;
2012-03-24 19:00:36 +04:00
gid_t caller_gid ;
2010-04-01 18:44:16 +04:00
int res ;
2018-04-26 18:32:42 +03:00
bool ok ;
2010-04-01 18:44:16 +04:00
req = tevent_req_create ( mem_ctx , & state ,
struct winbindd_pam_logoff_state ) ;
if ( req = = NULL ) {
return NULL ;
}
2022-06-24 15:51:07 +03:00
D_NOTICE ( " [%s (%u)] Winbind external command PAM_LOGOFF start. \n "
" Username '%s' is used during logoff. \n " ,
cli - > client_name ,
( unsigned int ) cli - > pid ,
request - > data . auth . user ) ;
2010-04-01 18:44:16 +04:00
/* Ensure null termination */
/* Ensure null termination */
request - > data . logoff . user [ sizeof ( request - > data . logoff . user ) - 1 ] = ' \0 ' ;
request - > data . logoff . krb5ccname [
sizeof ( request - > data . logoff . krb5ccname ) - 1 ] = ' \0 ' ;
if ( request - > data . logoff . uid = = ( uid_t ) - 1 ) {
goto failed ;
}
2023-10-21 14:13:19 +03:00
logoff_user = request - > data . logoff . user ;
ok = canonicalize_username ( req ,
& logoff_user ,
& name_namespace ,
& name_domain ,
& user ) ;
2018-04-26 18:32:42 +03:00
if ( ! ok ) {
2010-04-01 18:44:16 +04:00
goto failed ;
}
2023-10-21 14:13:19 +03:00
fstrcpy ( request - > data . logoff . user , logoff_user ) ;
2018-04-26 18:32:42 +03:00
domain = find_auth_domain ( request - > flags , name_namespace ) ;
2010-04-01 18:44:16 +04:00
if ( domain = = NULL ) {
goto failed ;
}
caller_uid = ( uid_t ) - 1 ;
2012-03-24 19:00:36 +04:00
res = getpeereid ( cli - > sock , & caller_uid , & caller_gid ) ;
2010-04-01 18:44:16 +04:00
if ( res ! = 0 ) {
2022-06-24 15:51:07 +03:00
D_WARNING ( " winbindd_pam_logoff: failed to check peerid: %s \n " ,
strerror ( errno ) ) ;
2010-04-01 18:44:16 +04:00
goto failed ;
}
switch ( caller_uid ) {
case - 1 :
goto failed ;
case 0 :
/* root must be able to logoff any user - gd */
break ;
default :
if ( caller_uid ! = request - > data . logoff . uid ) {
2022-06-24 15:51:07 +03:00
D_WARNING ( " caller requested invalid uid \n " ) ;
2010-04-01 18:44:16 +04:00
goto failed ;
}
break ;
}
2021-06-16 18:39:02 +03:00
state - > r . in . client_name = talloc_strdup ( state , request - > client_name ) ;
if ( tevent_req_nomem ( state - > r . in . client_name , req ) ) {
return tevent_req_post ( req , ev ) ;
}
state - > r . in . client_pid = request - > pid ;
state - > r . in . flags = request - > flags ;
state - > r . in . user = talloc_strdup ( state , request - > data . logoff . user ) ;
if ( tevent_req_nomem ( state - > r . in . user , req ) ) {
return tevent_req_post ( req , ev ) ;
}
state - > r . in . uid = request - > data . logoff . uid ;
state - > r . in . krb5ccname = talloc_strdup ( state ,
request - > data . logoff . krb5ccname ) ;
if ( tevent_req_nomem ( state - > r . in . krb5ccname , req ) ) {
return tevent_req_post ( req , ev ) ;
}
subreq = dcerpc_wbint_PamLogOff_r_send ( state ,
global_event_context ( ) ,
dom_child_handle ( domain ) ,
& state - > r ) ;
2010-04-01 18:44:16 +04:00
if ( tevent_req_nomem ( subreq , req ) ) {
return tevent_req_post ( req , ev ) ;
}
tevent_req_set_callback ( subreq , winbindd_pam_logoff_done , req ) ;
return req ;
failed :
tevent_req_nterror ( req , NT_STATUS_NO_SUCH_USER ) ;
return tevent_req_post ( req , ev ) ;
}
static void winbindd_pam_logoff_done ( struct tevent_req * subreq )
{
struct tevent_req * req = tevent_req_callback_data (
subreq , struct tevent_req ) ;
struct winbindd_pam_logoff_state * state = tevent_req_data (
req , struct winbindd_pam_logoff_state ) ;
2021-06-16 18:39:02 +03:00
NTSTATUS status ;
2010-04-01 18:44:16 +04:00
2021-06-16 18:39:02 +03:00
status = dcerpc_wbint_PamLogOff_r_recv ( subreq , state ) ;
2010-04-01 18:44:16 +04:00
TALLOC_FREE ( subreq ) ;
2021-06-16 18:39:02 +03:00
if ( tevent_req_nterror ( req , status ) ) {
2010-04-01 18:44:16 +04:00
return ;
}
2021-06-16 18:39:02 +03:00
2010-04-01 18:44:16 +04:00
tevent_req_done ( req ) ;
}
NTSTATUS winbindd_pam_logoff_recv ( struct tevent_req * req ,
struct winbindd_response * response )
{
struct winbindd_pam_logoff_state * state = tevent_req_data (
req , struct winbindd_pam_logoff_state ) ;
2021-06-16 18:39:02 +03:00
NTSTATUS status = NT_STATUS_OK ;
2010-04-01 18:44:16 +04:00
2022-06-24 15:51:07 +03:00
D_NOTICE ( " Winbind external command PAM_LOGOFF end. \n " ) ;
2010-04-01 18:44:16 +04:00
if ( tevent_req_is_nterror ( req , & status ) ) {
set_auth_errors ( response , status ) ;
return status ;
}
2021-06-16 18:39:02 +03:00
2010-04-01 18:44:16 +04:00
response - > result = WINBINDD_PENDING ;
2021-06-16 18:39:02 +03:00
set_auth_errors ( response , state - > r . out . result ) ;
2010-04-18 16:14:43 +04:00
2021-06-16 18:39:02 +03:00
if ( NT_STATUS_IS_OK ( state - > r . out . result ) ) {
winbindd_delete_memory_creds ( state - > r . in . user ) ;
2010-04-18 16:14:43 +04:00
}
2021-06-16 18:39:02 +03:00
return NT_STATUS ( response - > data . auth . nt_status ) ;
2010-04-01 18:44:16 +04:00
}