memberof.c 56 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158
  1. /** BEGIN COPYRIGHT BLOCK
  2. * This Program is free software; you can redistribute it and/or modify it under
  3. * the terms of the GNU General Public License as published by the Free Software
  4. * Foundation; version 2 of the License.
  5. *
  6. * This Program is distributed in the hope that it will be useful, but WITHOUT
  7. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  8. * FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
  9. *
  10. * You should have received a copy of the GNU General Public License along with
  11. * this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
  12. * Place, Suite 330, Boston, MA 02111-1307 USA.
  13. *
  14. * In addition, as a special exception, Red Hat, Inc. gives You the additional
  15. * right to link the code of this Program with code not covered under the GNU
  16. * General Public License ("Non-GPL Code") and to distribute linked combinations
  17. * including the two, subject to the limitations in this paragraph. Non-GPL Code
  18. * permitted under this exception must only link to the code of this Program
  19. * through those well defined interfaces identified in the file named EXCEPTION
  20. * found in the source code files (the "Approved Interfaces"). The files of
  21. * Non-GPL Code may instantiate templates or use macros or inline functions from
  22. * the Approved Interfaces without causing the resulting work to be covered by
  23. * the GNU General Public License. Only Red Hat, Inc. may make changes or
  24. * additions to the list of Approved Interfaces. You must obey the GNU General
  25. * Public License in all respects for all of the Program code and other code used
  26. * in conjunction with the Program except the Non-GPL Code covered by this
  27. * exception. If you modify this file, you may extend this exception to your
  28. * version of the file, but you are not obligated to do so. If you do not wish to
  29. * provide this exception without modification, you must delete this exception
  30. * statement from your version and license this file solely under the GPL without
  31. * exception.
  32. *
  33. * Authors:
  34. * Pete Rowley <[email protected]>
  35. *
  36. * Copyright (C) 2007 Red Hat, Inc.
  37. * All rights reserved.
  38. * END COPYRIGHT BLOCK
  39. **/
  40. /* The memberof plugin updates the memberof attribute of entries
  41. * based on modifications performed on groupofuniquenames entries
  42. *
  43. * In addition the plugin provides a DS task that may be started
  44. * administrative clients and that creates the initial memberof
  45. * list for imported entries and/or fixes the memberof list of
  46. * existing entries that have inconsistent state (for example,
  47. * if the memberof attribute was incorrectly edited directly)
  48. *
  49. * To start the memberof task add an entry like:
  50. *
  51. * dn: cn=mytask, cn=memberof task, cn=tasks, cn=config
  52. * objectClass: top
  53. * objectClass: extensibleObject
  54. * cn: mytask
  55. * basedn: dc=example, dc=com
  56. * filter: (uid=test4)
  57. *
  58. * where "basedn" is required and refers to the top most node to perform the
  59. * task on, and where "filter" is an optional attribute that provides a filter
  60. * describing the entries to be worked on
  61. */
  62. #ifdef HAVE_CONFIG_H
  63. # include <config.h>
  64. #endif
  65. #include "slapi-plugin.h"
  66. #include "dirver.h"
  67. #include <dirlite_strings.h> /* PLUGIN_MAGIC_VENDOR_STR */
  68. #include "string.h"
  69. #include "nspr.h"
  70. #include "memberof.h"
  71. static Slapi_PluginDesc pdesc = { "memberof", PLUGIN_MAGIC_VENDOR_STR,
  72. PRODUCTTEXT, "memberof plugin" };
  73. static void* _PluginID = NULL;
  74. static Slapi_Mutex *memberof_operation_lock = 0;
  75. MemberOfConfig *qsortConfig = 0;
  76. typedef struct _memberofstringll
  77. {
  78. const char *dn;
  79. void *next;
  80. } memberofstringll;
  81. typedef struct _memberof_get_groups_data
  82. {
  83. MemberOfConfig *config;
  84. Slapi_Value *memberdn_val;
  85. Slapi_ValueSet **groupvals;
  86. } memberof_get_groups_data;
  87. /*** function prototypes ***/
  88. /* exported functions */
  89. int memberof_postop_init(Slapi_PBlock *pb );
  90. /* plugin callbacks */
  91. static int memberof_postop_del(Slapi_PBlock *pb );
  92. static int memberof_postop_modrdn(Slapi_PBlock *pb );
  93. static int memberof_postop_modify(Slapi_PBlock *pb );
  94. static int memberof_postop_add(Slapi_PBlock *pb );
  95. static int memberof_postop_start(Slapi_PBlock *pb);
  96. static int memberof_postop_close(Slapi_PBlock *pb);
  97. /* supporting cast */
  98. static int memberof_oktodo(Slapi_PBlock *pb);
  99. static char *memberof_getdn(Slapi_PBlock *pb);
  100. static int memberof_modop_one(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  101. char *op_this, char *op_to);
  102. static int memberof_modop_one_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  103. char *group_dn, char *op_this, char *op_to, memberofstringll *stack);
  104. static int memberof_add_one(Slapi_PBlock *pb, MemberOfConfig *config, char *addthis,
  105. char *addto);
  106. static int memberof_del_one(Slapi_PBlock *pb, MemberOfConfig *config, char *delthis,
  107. char *delfrom);
  108. static int memberof_mod_smod_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  109. char *groupdn, Slapi_Mod *smod);
  110. static int memberof_add_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  111. char *groupdn, Slapi_Mod *smod);
  112. static int memberof_del_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  113. char *groupdn, Slapi_Mod *smod);
  114. static int memberof_mod_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  115. char *groupdn, Slapi_Attr *attr);
  116. static int memberof_mod_attr_list_r(Slapi_PBlock *pb, MemberOfConfig *config,
  117. int mod, char *group_dn, char *op_this, Slapi_Attr *attr, memberofstringll *stack);
  118. static int memberof_add_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  119. char *groupdn, Slapi_Attr *attr);
  120. static int memberof_del_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  121. char *groupdn, Slapi_Attr *attr);
  122. static int memberof_moddn_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  123. char *pre_dn, char *post_dn, Slapi_Attr *attr);
  124. static int memberof_replace_list(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn);
  125. static void memberof_set_plugin_id(void * plugin_id);
  126. static void *memberof_get_plugin_id();
  127. static int memberof_compare(MemberOfConfig *config, const void *a, const void *b);
  128. static int memberof_qsort_compare(const void *a, const void *b);
  129. static void memberof_load_array(Slapi_Value **array, Slapi_Attr *attr);
  130. static int memberof_del_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config, char *dn);
  131. static int memberof_call_foreach_dn(Slapi_PBlock *pb, char *dn,
  132. char *type, plugin_search_entry_callback callback, void *callback_data);
  133. static int memberof_is_direct_member(MemberOfConfig *config, Slapi_Value *groupdn,
  134. Slapi_Value *memberdn);
  135. static Slapi_ValueSet *memberof_get_groups(MemberOfConfig *config, char *memberdn);
  136. static int memberof_get_groups_r(MemberOfConfig *config, char *memberdn,
  137. memberof_get_groups_data *data);
  138. static int memberof_get_groups_callback(Slapi_Entry *e, void *callback_data);
  139. static int memberof_test_membership(Slapi_PBlock *pb, MemberOfConfig *config,
  140. char *group_dn);
  141. static int memberof_test_membership_callback(Slapi_Entry *e, void *callback_data);
  142. static int memberof_del_dn_type_callback(Slapi_Entry *e, void *callback_data);
  143. static int memberof_replace_dn_type_callback(Slapi_Entry *e, void *callback_data);
  144. static int memberof_replace_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config,
  145. char *pre_dn, char *post_dn);
  146. static int memberof_modop_one_replace_r(Slapi_PBlock *pb, MemberOfConfig *config,
  147. int mod_op, char *group_dn, char *op_this, char *replace_with, char *op_to,
  148. memberofstringll *stack);
  149. static int memberof_task_add(Slapi_PBlock *pb, Slapi_Entry *e,
  150. Slapi_Entry *eAfter, int *returncode, char *returntext,
  151. void *arg);
  152. static void memberof_task_destructor(Slapi_Task *task);
  153. static const char *fetch_attr(Slapi_Entry *e, const char *attrname,
  154. const char *default_val);
  155. static void memberof_fixup_task_thread(void *arg);
  156. static int memberof_fix_memberof(MemberOfConfig *config, char *dn, char *filter_str);
  157. static int memberof_fix_memberof_callback(Slapi_Entry *e, void *callback_data);
  158. /*** implementation ***/
  159. /*** exported functions ***/
  160. /*
  161. * memberof_postop_init()
  162. *
  163. * Register plugin call backs
  164. *
  165. */
  166. int
  167. memberof_postop_init(Slapi_PBlock *pb)
  168. {
  169. int ret = 0;
  170. char *memberof_plugin_identity = 0;
  171. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  172. "--> memberof_postop_init\n" );
  173. /*
  174. * Get plugin identity and stored it for later use
  175. * Used for internal operations
  176. */
  177. slapi_pblock_get (pb, SLAPI_PLUGIN_IDENTITY, &memberof_plugin_identity);
  178. PR_ASSERT (memberof_plugin_identity);
  179. memberof_set_plugin_id(memberof_plugin_identity);
  180. if ( slapi_pblock_set( pb, SLAPI_PLUGIN_VERSION,
  181. SLAPI_PLUGIN_VERSION_01 ) != 0 ||
  182. slapi_pblock_set( pb, SLAPI_PLUGIN_DESCRIPTION,
  183. (void *)&pdesc ) != 0 ||
  184. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_DELETE_FN,
  185. (void *) memberof_postop_del ) != 0 ||
  186. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_MODRDN_FN,
  187. (void *) memberof_postop_modrdn ) != 0 ||
  188. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_MODIFY_FN,
  189. (void *) memberof_postop_modify ) != 0 ||
  190. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_ADD_FN,
  191. (void *) memberof_postop_add ) != 0 ||
  192. slapi_pblock_set(pb, SLAPI_PLUGIN_START_FN,
  193. (void *) memberof_postop_start ) != 0 ||
  194. slapi_pblock_set(pb, SLAPI_PLUGIN_CLOSE_FN,
  195. (void *) memberof_postop_close ) != 0)
  196. {
  197. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  198. "memberof_postop_init failed\n" );
  199. ret = -1;
  200. }
  201. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  202. "<-- memberof_postop_init\n" );
  203. return ret;
  204. }
  205. /*
  206. * memberof_postop_start()
  207. *
  208. * Do plugin start up stuff
  209. *
  210. */
  211. int memberof_postop_start(Slapi_PBlock *pb)
  212. {
  213. int rc = 0;
  214. Slapi_Entry *config_e = NULL; /* entry containing plugin config */
  215. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  216. "--> memberof_postop_start\n" );
  217. memberof_operation_lock = slapi_new_mutex();
  218. if(0 == memberof_operation_lock)
  219. {
  220. rc = -1;
  221. goto bail;
  222. }
  223. if ( slapi_pblock_get( pb, SLAPI_ADD_ENTRY, &config_e ) != 0 ) {
  224. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  225. "missing config entry\n" );
  226. rc = -1;
  227. goto bail;
  228. }
  229. if (( rc = memberof_config( config_e )) != LDAP_SUCCESS ) {
  230. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  231. "configuration failed (%s)\n", ldap_err2string( rc ));
  232. return( -1 );
  233. }
  234. rc = slapi_task_register_handler("memberof task", memberof_task_add);
  235. if(rc)
  236. {
  237. goto bail;
  238. }
  239. /*
  240. * TODO: start up operation actor thread
  241. * need to get to a point where server failure
  242. * or shutdown doesn't hose our operations
  243. * so we should create a task entry that contains
  244. * all required information to complete the operation
  245. * then the tasks can be restarted safely if
  246. * interrupted
  247. */
  248. bail:
  249. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  250. "<-- memberof_postop_start\n" );
  251. return rc;
  252. }
  253. /*
  254. * memberof_postop_close()
  255. *
  256. * Do plugin shut down stuff
  257. *
  258. */
  259. int memberof_postop_close(Slapi_PBlock *pb)
  260. {
  261. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  262. "--> memberof_postop_close\n" );
  263. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  264. "<-- memberof_postop_close\n" );
  265. return 0;
  266. }
  267. /*
  268. * memberof_postop_del()
  269. *
  270. * All entries with a memberOf attribute that contains the group DN get retrieved
  271. * and have the their memberOf attribute regenerated (it is far too complex and
  272. * error prone to attempt to change only those dn values involved in this case -
  273. * mainly because the deleted group may itself be a member of other groups which
  274. * may be members of other groups etc. in a big recursive mess involving dependency
  275. * chains that must be created and traversed in order to decide if an entry should
  276. * really have those groups removed too)
  277. */
  278. int memberof_postop_del(Slapi_PBlock *pb)
  279. {
  280. int ret = 0;
  281. MemberOfConfig configCopy = {0, 0, 0, 0};
  282. char *dn;
  283. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  284. "--> memberof_postop_del\n" );
  285. if(memberof_oktodo(pb) && (dn = memberof_getdn(pb)))
  286. {
  287. struct slapi_entry *e = NULL;
  288. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &e );
  289. /* We need to get the config lock first. Trying to get the
  290. * config lock after we already hold the op lock can cause
  291. * a deadlock. */
  292. memberof_rlock_config();
  293. /* copy config so it doesn't change out from under us */
  294. memberof_copy_config(&configCopy, memberof_get_config());
  295. memberof_unlock_config();
  296. /* get the memberOf operation lock */
  297. memberof_lock();
  298. /* remove this group DN from the
  299. * membership lists of groups
  300. */
  301. memberof_del_dn_from_groups(pb, &configCopy, dn);
  302. /* is the entry of interest as a group? */
  303. if(e && !slapi_filter_test_simple(e, configCopy.group_filter))
  304. {
  305. Slapi_Attr *attr = 0;
  306. if(0 == slapi_entry_attr_find(e, configCopy.groupattr, &attr))
  307. {
  308. memberof_del_attr_list(pb, &configCopy, dn, attr);
  309. }
  310. }
  311. memberof_unlock();
  312. memberof_free_config(&configCopy);
  313. }
  314. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  315. "<-- memberof_postop_del\n" );
  316. return ret;
  317. }
  318. typedef struct _memberof_del_dn_data
  319. {
  320. char *dn;
  321. char *type;
  322. } memberof_del_dn_data;
  323. int memberof_del_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config, char *dn)
  324. {
  325. memberof_del_dn_data data = {dn, config->groupattr};
  326. return memberof_call_foreach_dn(pb, dn,
  327. config->groupattr, memberof_del_dn_type_callback, &data);
  328. }
  329. int memberof_del_dn_type_callback(Slapi_Entry *e, void *callback_data)
  330. {
  331. int rc = 0;
  332. LDAPMod mod;
  333. LDAPMod *mods[2];
  334. char *val[2];
  335. Slapi_PBlock *mod_pb = 0;
  336. mod_pb = slapi_pblock_new();
  337. mods[0] = &mod;
  338. mods[1] = 0;
  339. val[0] = ((memberof_del_dn_data *)callback_data)->dn;
  340. val[1] = 0;
  341. mod.mod_op = LDAP_MOD_DELETE;
  342. mod.mod_type = ((memberof_del_dn_data *)callback_data)->type;
  343. mod.mod_values = val;
  344. slapi_modify_internal_set_pb(
  345. mod_pb, slapi_entry_get_dn(e),
  346. mods, 0, 0,
  347. memberof_get_plugin_id(), 0);
  348. slapi_modify_internal_pb(mod_pb);
  349. slapi_pblock_get(mod_pb,
  350. SLAPI_PLUGIN_INTOP_RESULT,
  351. &rc);
  352. slapi_pblock_destroy(mod_pb);
  353. return rc;
  354. }
  355. /*
  356. * Does a callback search of "type=dn" under the db suffix that "dn" is in.
  357. * If "dn" is a user, you'd want "type" to be "member". If "dn" is a group,
  358. * you could want type to be either "member" or "memberOf" depending on the
  359. * case.
  360. */
  361. int memberof_call_foreach_dn(Slapi_PBlock *pb, char *dn,
  362. char *type, plugin_search_entry_callback callback, void *callback_data)
  363. {
  364. int rc = 0;
  365. Slapi_PBlock *search_pb = slapi_pblock_new();
  366. Slapi_Backend *be = 0;
  367. Slapi_DN *sdn = 0;
  368. Slapi_DN *base_sdn = 0;
  369. char *filter_str = 0;
  370. /* get the base dn for the backend we are in
  371. (we don't support having members and groups in
  372. different backends - issues with offline / read only backends)
  373. */
  374. sdn = slapi_sdn_new_dn_byref(dn);
  375. be = slapi_be_select(sdn);
  376. if(be)
  377. {
  378. base_sdn = (Slapi_DN*)slapi_be_getsuffix(be,0);
  379. }
  380. if(base_sdn)
  381. {
  382. filter_str = slapi_ch_smprintf("(%s=%s)", type, dn);
  383. }
  384. if(filter_str)
  385. {
  386. slapi_search_internal_set_pb(search_pb, slapi_sdn_get_dn(base_sdn),
  387. LDAP_SCOPE_SUBTREE, filter_str, 0, 0,
  388. 0, 0,
  389. memberof_get_plugin_id(),
  390. 0);
  391. slapi_search_internal_callback_pb(search_pb,
  392. callback_data,
  393. 0, callback,
  394. 0);
  395. }
  396. slapi_sdn_free(&sdn);
  397. slapi_pblock_destroy(search_pb);
  398. slapi_ch_free_string(&filter_str);
  399. return rc;
  400. }
  401. /*
  402. * memberof_postop_modrdn()
  403. *
  404. * All entries with a memberOf attribute that contains the old group DN get retrieved
  405. * and have the old group DN deleted and the new group DN added to their memberOf attribute
  406. */
  407. int memberof_postop_modrdn(Slapi_PBlock *pb)
  408. {
  409. int ret = 0;
  410. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  411. "--> memberof_postop_modrdn\n" );
  412. if(memberof_oktodo(pb))
  413. {
  414. MemberOfConfig *mainConfig = 0;
  415. MemberOfConfig configCopy = {0, 0, 0, 0};
  416. struct slapi_entry *pre_e = NULL;
  417. struct slapi_entry *post_e = NULL;
  418. char *pre_dn = 0;
  419. char *post_dn = 0;
  420. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &pre_e );
  421. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &post_e );
  422. if(pre_e && post_e)
  423. {
  424. pre_dn = slapi_entry_get_ndn(pre_e);
  425. post_dn = slapi_entry_get_ndn(post_e);
  426. }
  427. /* copy config so it doesn't change out from under us */
  428. memberof_rlock_config();
  429. mainConfig = memberof_get_config();
  430. memberof_copy_config(&configCopy, mainConfig);
  431. memberof_unlock_config();
  432. memberof_lock();
  433. /* update any downstream members */
  434. if(pre_dn && post_dn &&
  435. !slapi_filter_test_simple(post_e, configCopy.group_filter))
  436. {
  437. Slapi_Attr *attr = 0;
  438. /* get a list of member attributes present in the group
  439. * entry that is being renamed. */
  440. if(0 == slapi_entry_attr_find(post_e, configCopy.groupattr, &attr))
  441. {
  442. memberof_moddn_attr_list(pb, &configCopy, pre_dn, post_dn, attr);
  443. }
  444. }
  445. /* It's possible that this is an entry who is a member
  446. * of other group entries. We need to update any member
  447. * attributes to refer to the new name. */
  448. memberof_replace_dn_from_groups(pb, &configCopy, pre_dn, post_dn);
  449. memberof_unlock();
  450. memberof_free_config(&configCopy);
  451. }
  452. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  453. "<-- memberof_postop_modrdn\n" );
  454. return ret;
  455. }
  456. typedef struct _replace_dn_data
  457. {
  458. char *pre_dn;
  459. char *post_dn;
  460. char *type;
  461. } replace_dn_data;
  462. int memberof_replace_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config,
  463. char *pre_dn, char *post_dn)
  464. {
  465. replace_dn_data data = {pre_dn, post_dn, config->groupattr};
  466. return memberof_call_foreach_dn(pb, pre_dn, config->groupattr,
  467. memberof_replace_dn_type_callback, &data);
  468. }
  469. int memberof_replace_dn_type_callback(Slapi_Entry *e, void *callback_data)
  470. {
  471. int rc = 0;
  472. LDAPMod delmod;
  473. LDAPMod addmod;
  474. LDAPMod *mods[3];
  475. char *delval[2];
  476. char *addval[2];
  477. Slapi_PBlock *mod_pb = 0;
  478. mod_pb = slapi_pblock_new();
  479. mods[0] = &delmod;
  480. mods[1] = &addmod;
  481. mods[2] = 0;
  482. delval[0] = ((replace_dn_data *)callback_data)->pre_dn;
  483. delval[1] = 0;
  484. delmod.mod_op = LDAP_MOD_DELETE;
  485. delmod.mod_type = ((replace_dn_data *)callback_data)->type;
  486. delmod.mod_values = delval;
  487. addval[0] = ((replace_dn_data *)callback_data)->post_dn;
  488. addval[1] = 0;
  489. addmod.mod_op = LDAP_MOD_ADD;
  490. addmod.mod_type = ((replace_dn_data *)callback_data)->type;
  491. addmod.mod_values = addval;
  492. slapi_modify_internal_set_pb(
  493. mod_pb, slapi_entry_get_dn(e),
  494. mods, 0, 0,
  495. memberof_get_plugin_id(), 0);
  496. slapi_modify_internal_pb(mod_pb);
  497. slapi_pblock_get(mod_pb,
  498. SLAPI_PLUGIN_INTOP_RESULT,
  499. &rc);
  500. slapi_pblock_destroy(mod_pb);
  501. return rc;
  502. }
  503. /*
  504. * memberof_postop_modify()
  505. *
  506. * Added members are retrieved and have the group DN added to their memberOf attribute
  507. * Deleted members are retrieved and have the group DN deleted from their memberOf attribute
  508. * On replace of the membership attribute values:
  509. * 1. Sort old and new values
  510. * 2. Iterate through both lists at same time
  511. * 3. Any value not in old list but in new list - add group DN to memberOf attribute
  512. * 4. Any value in old list but not in new list - remove group DN from memberOf attribute
  513. *
  514. * Note: this will suck for large groups but nonetheless is optimal (it's linear) given
  515. * current restrictions i.e. originally adding members in sorted order would allow
  516. * us to sort one list only (the new one) but that is under server control, not this plugin
  517. */
  518. int memberof_postop_modify(Slapi_PBlock *pb)
  519. {
  520. int ret = 0;
  521. char *dn = 0;
  522. Slapi_Mods *smods = 0;
  523. Slapi_Mod *smod = 0;
  524. LDAPMod **mods;
  525. Slapi_Mod *next_mod = 0;
  526. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  527. "--> memberof_postop_modify\n" );
  528. if(memberof_oktodo(pb) &&
  529. (dn = memberof_getdn(pb)))
  530. {
  531. int config_copied = 0;
  532. MemberOfConfig *mainConfig = 0;
  533. MemberOfConfig configCopy = {0, 0, 0, 0};
  534. /* get the mod set */
  535. slapi_pblock_get(pb, SLAPI_MODIFY_MODS, &mods);
  536. smods = slapi_mods_new();
  537. slapi_mods_init_byref(smods, mods);
  538. next_mod = slapi_mod_new();
  539. smod = slapi_mods_get_first_smod(smods, next_mod);
  540. while(smod)
  541. {
  542. int interested = 0;
  543. char *type = (char *)slapi_mod_get_type(smod);
  544. /* We only want to copy the config if we encounter an
  545. * operation that we need to act on. We also want to
  546. * only copy the config the first time it's needed so
  547. * it remains the same for all mods in the operation,
  548. * despite any config changes that may be made. */
  549. if (!config_copied)
  550. {
  551. memberof_rlock_config();
  552. mainConfig = memberof_get_config();
  553. if(slapi_attr_types_equivalent(type, mainConfig->groupattr))
  554. {
  555. interested = 1;
  556. /* copy config so it doesn't change out from under us */
  557. memberof_copy_config(&configCopy, mainConfig);
  558. config_copied = 1;
  559. }
  560. memberof_unlock_config();
  561. } else {
  562. if(slapi_attr_types_equivalent(type, configCopy.groupattr))
  563. {
  564. interested = 1;
  565. }
  566. }
  567. if(interested)
  568. {
  569. int op = slapi_mod_get_operation(smod);
  570. memberof_lock();
  571. /* the modify op decides the function */
  572. switch(op & ~LDAP_MOD_BVALUES)
  573. {
  574. case LDAP_MOD_ADD:
  575. {
  576. /* add group DN to targets */
  577. memberof_add_smod_list(pb, &configCopy, dn, smod);
  578. break;
  579. }
  580. case LDAP_MOD_DELETE:
  581. {
  582. /* If there are no values in the smod, we should
  583. * just do a replace instead. The user is just
  584. * trying to delete all members from this group
  585. * entry, which the replace code deals with. */
  586. if (slapi_mod_get_num_values(smod) == 0)
  587. {
  588. memberof_replace_list(pb, &configCopy, dn);
  589. }
  590. else
  591. {
  592. /* remove group DN from target values in smod*/
  593. memberof_del_smod_list(pb, &configCopy, dn, smod);
  594. }
  595. break;
  596. }
  597. case LDAP_MOD_REPLACE:
  598. {
  599. /* replace current values */
  600. memberof_replace_list(pb, &configCopy, dn);
  601. break;
  602. }
  603. default:
  604. {
  605. slapi_log_error(
  606. SLAPI_LOG_PLUGIN,
  607. MEMBEROF_PLUGIN_SUBSYSTEM,
  608. "memberof_postop_modify: unknown mod type\n" );
  609. break;
  610. }
  611. }
  612. memberof_unlock();
  613. }
  614. slapi_mod_done(next_mod);
  615. smod = slapi_mods_get_next_smod(smods, next_mod);
  616. }
  617. if (config_copied)
  618. {
  619. memberof_free_config(&configCopy);
  620. }
  621. slapi_mod_free(&next_mod);
  622. slapi_mods_free(&smods);
  623. }
  624. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  625. "<-- memberof_postop_modify\n" );
  626. return ret;
  627. }
  628. /*
  629. * memberof_postop_add()
  630. *
  631. * All members in the membership attribute of the new entry get retrieved
  632. * and have the group DN added to their memberOf attribute
  633. */
  634. int memberof_postop_add(Slapi_PBlock *pb)
  635. {
  636. int ret = 0;
  637. int interested = 0;
  638. char *dn = 0;
  639. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  640. "--> memberof_postop_add\n" );
  641. if(memberof_oktodo(pb) && (dn = memberof_getdn(pb)))
  642. {
  643. MemberOfConfig *mainConfig = 0;
  644. MemberOfConfig configCopy = {0, 0, 0, 0};
  645. struct slapi_entry *e = NULL;
  646. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &e );
  647. /* is the entry of interest? */
  648. memberof_rlock_config();
  649. mainConfig = memberof_get_config();
  650. if(e && !slapi_filter_test_simple(e, mainConfig->group_filter))
  651. {
  652. interested = 1;
  653. /* copy config so it doesn't change out from under us */
  654. memberof_copy_config(&configCopy, mainConfig);
  655. }
  656. memberof_unlock_config();
  657. if(interested)
  658. {
  659. Slapi_Attr *attr = 0;
  660. memberof_lock();
  661. if(0 == slapi_entry_attr_find(e, configCopy.groupattr, &attr))
  662. {
  663. memberof_add_attr_list(pb, &configCopy, dn, attr);
  664. }
  665. memberof_unlock();
  666. memberof_free_config(&configCopy);
  667. }
  668. }
  669. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  670. "<-- memberof_postop_add\n" );
  671. return ret;
  672. }
  673. /*** Support functions ***/
  674. /*
  675. * memberof_oktodo()
  676. *
  677. * Check that the op succeeded
  678. * Note: we also respond to replicated ops so we don't test for that
  679. * this does require that the memberOf attribute not be replicated
  680. * and this means that memberof is consistent with local state
  681. * not the network system state
  682. *
  683. */
  684. int memberof_oktodo(Slapi_PBlock *pb)
  685. {
  686. int ret = 1;
  687. int oprc = 0;
  688. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  689. "--> memberof_postop_oktodo\n" );
  690. if(slapi_pblock_get(pb, SLAPI_PLUGIN_OPRETURN, &oprc) != 0)
  691. {
  692. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  693. "memberof_postop_oktodo: could not get parameters\n" );
  694. ret = -1;
  695. }
  696. /* this plugin should only execute if the operation succeeded
  697. */
  698. if(oprc != 0)
  699. {
  700. ret = 0;
  701. }
  702. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  703. "<-- memberof_postop_oktodo\n" );
  704. return ret;
  705. }
  706. /*
  707. * memberof_getdn()
  708. *
  709. * Get dn of target entry
  710. *
  711. */
  712. char *memberof_getdn(Slapi_PBlock *pb)
  713. {
  714. char *dn = 0;
  715. slapi_pblock_get(pb, SLAPI_TARGET_DN, &dn);
  716. return dn;
  717. }
  718. /*
  719. * memberof_modop_one()
  720. *
  721. * Perform op on memberof attribute of op_to using op_this as the value
  722. * However, if op_to happens to be a group, we must arrange for the group
  723. * members to have the mod performed on them instead, and we must take
  724. * care to not recurse when we have visted a group before
  725. *
  726. * Also, we must not delete entries that are a member of the group
  727. */
  728. int memberof_modop_one(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  729. char *op_this, char *op_to)
  730. {
  731. return memberof_modop_one_r(pb, config, mod_op, op_this, op_this, op_to, 0);
  732. }
  733. /* memberof_modop_one_r()
  734. *
  735. * recursive function to perform above (most things don't need the replace arg)
  736. */
  737. int memberof_modop_one_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  738. char *group_dn, char *op_this, char *op_to, memberofstringll *stack)
  739. {
  740. return memberof_modop_one_replace_r(
  741. pb, config, mod_op, group_dn, op_this, 0, op_to, stack);
  742. }
  743. /* memberof_modop_one_replace_r()
  744. *
  745. * recursive function to perform above (with added replace arg)
  746. */
  747. int memberof_modop_one_replace_r(Slapi_PBlock *pb, MemberOfConfig *config,
  748. int mod_op, char *group_dn, char *op_this, char *replace_with,
  749. char *op_to, memberofstringll *stack)
  750. {
  751. int rc = 0;
  752. LDAPMod mod;
  753. LDAPMod replace_mod;
  754. LDAPMod *mods[3];
  755. char *val[2];
  756. char *replace_val[2];
  757. Slapi_PBlock *mod_pb = 0;
  758. char *attrlist[2] = {config->groupattr,0};
  759. Slapi_DN *op_to_sdn = 0;
  760. Slapi_Entry *e = 0;
  761. memberofstringll *ll = 0;
  762. char *op_str = 0;
  763. Slapi_Value *to_dn_val = slapi_value_new_string(op_to);
  764. Slapi_Value *this_dn_val = slapi_value_new_string(op_this);
  765. /* determine if this is a group op or single entry */
  766. op_to_sdn = slapi_sdn_new_dn_byref(op_to);
  767. slapi_search_internal_get_entry( op_to_sdn, attrlist,
  768. &e, memberof_get_plugin_id());
  769. if(!e)
  770. {
  771. /* In the case of a delete, we need to worry about the
  772. * missing entry being a nested group. There's a small
  773. * window where another thread may have deleted a nested
  774. * group that our group_dn entry refers to. This has the
  775. * potential of us missing some indirect member entries
  776. * that need to be updated. */
  777. if(LDAP_MOD_DELETE == mod_op)
  778. {
  779. Slapi_PBlock *search_pb = slapi_pblock_new();
  780. Slapi_DN *base_sdn = 0;
  781. Slapi_Backend *be = 0;
  782. char *filter_str = 0;
  783. int n_entries = 0;
  784. /* We can't tell for sure if the op_to entry is a
  785. * user or a group since the entry doesn't exist
  786. * anymore. We can safely ignore the missing entry
  787. * if no other entries have a memberOf attribute that
  788. * points to the missing entry. */
  789. be = slapi_be_select(op_to_sdn);
  790. if(be)
  791. {
  792. base_sdn = (Slapi_DN*)slapi_be_getsuffix(be,0);
  793. }
  794. if(base_sdn)
  795. {
  796. filter_str = slapi_ch_smprintf("(%s=%s)",
  797. config->memberof_attr, op_to);
  798. }
  799. if(filter_str)
  800. {
  801. slapi_search_internal_set_pb(search_pb, slapi_sdn_get_dn(base_sdn),
  802. LDAP_SCOPE_SUBTREE, filter_str, 0, 0, 0, 0,
  803. memberof_get_plugin_id(), 0);
  804. if (slapi_search_internal_pb(search_pb))
  805. {
  806. /* get result and log an error */
  807. int res = 0;
  808. slapi_pblock_get(search_pb, SLAPI_PLUGIN_INTOP_RESULT, &res);
  809. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  810. "memberof_modop_one_replace_r: error searching for members: "
  811. "%d", res);
  812. } else {
  813. slapi_pblock_get(search_pb, SLAPI_NENTRIES, &n_entries);
  814. if(n_entries > 0)
  815. {
  816. /* We want to fixup the membership for the
  817. * entries that referred to the missing group
  818. * entry. This will fix the references to
  819. * the missing group as well as the group
  820. * represented by op_this. */
  821. memberof_test_membership(pb, config, op_to);
  822. }
  823. }
  824. slapi_free_search_results_internal(search_pb);
  825. slapi_ch_free_string(&filter_str);
  826. }
  827. slapi_pblock_destroy(search_pb);
  828. }
  829. goto bail;
  830. }
  831. if(LDAP_MOD_DELETE == mod_op)
  832. {
  833. op_str = "DELETE";
  834. }
  835. else if(LDAP_MOD_ADD == mod_op)
  836. {
  837. op_str = "ADD";
  838. }
  839. else if(LDAP_MOD_REPLACE == mod_op)
  840. {
  841. op_str = "REPLACE";
  842. }
  843. else
  844. {
  845. op_str = "UNKNOWN";
  846. }
  847. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  848. "memberof_modop_one_replace_r: %s %s in %s\n"
  849. ,op_str, op_this, op_to);
  850. if(!slapi_filter_test_simple(e, config->group_filter))
  851. {
  852. /* group */
  853. Slapi_Value *ll_dn_val = 0;
  854. Slapi_Attr *members = 0;
  855. ll = stack;
  856. /* have we been here before? */
  857. while(ll)
  858. {
  859. ll_dn_val = slapi_value_new_string(ll->dn);
  860. if(0 == memberof_compare(config, &ll_dn_val, &to_dn_val))
  861. {
  862. slapi_value_free(&ll_dn_val);
  863. /* someone set up infinitely
  864. recursive groups - bail out */
  865. slapi_log_error( SLAPI_LOG_PLUGIN,
  866. MEMBEROF_PLUGIN_SUBSYSTEM,
  867. "memberof_modop_one_replace_r: group recursion"
  868. " detected in %s\n"
  869. ,op_to);
  870. goto bail;
  871. }
  872. slapi_value_free(&ll_dn_val);
  873. ll = ll->next;
  874. }
  875. /* do op on group */
  876. slapi_log_error( SLAPI_LOG_PLUGIN,
  877. MEMBEROF_PLUGIN_SUBSYSTEM,
  878. "memberof_modop_one_replace_r: descending into group %s\n",
  879. op_to);
  880. /* Add the nested group's DN to the stack so we can detect loops later. */
  881. ll = (memberofstringll*)slapi_ch_malloc(sizeof(memberofstringll));
  882. ll->dn = op_to;
  883. ll->next = stack;
  884. slapi_entry_attr_find( e, config->groupattr, &members );
  885. if(members)
  886. {
  887. memberof_mod_attr_list_r(pb, config, mod_op, group_dn, op_this, members, ll);
  888. }
  889. {
  890. /* crazyness follows:
  891. * strict-aliasing doesn't like the required cast
  892. * to void for slapi_ch_free so we are made to
  893. * juggle to get a normal thing done
  894. */
  895. void *pll = ll;
  896. slapi_ch_free(&pll);
  897. ll = 0;
  898. }
  899. }
  900. /* continue with operation */
  901. {
  902. /* We want to avoid listing a group as a memberOf itself
  903. * in case someone set up a circular grouping.
  904. */
  905. if (0 == memberof_compare(config, &this_dn_val, &to_dn_val))
  906. {
  907. const char *strval = "NULL";
  908. if (this_dn_val) {
  909. strval = slapi_value_get_string(this_dn_val);
  910. }
  911. slapi_log_error( SLAPI_LOG_PLUGIN,
  912. MEMBEROF_PLUGIN_SUBSYSTEM,
  913. "memberof_modop_one_replace_r: not processing memberOf "
  914. "operations on self entry: %s\n", strval);
  915. goto bail;
  916. }
  917. /* For add and del modify operations, we just regenerate the
  918. * memberOf attribute. */
  919. if(LDAP_MOD_DELETE == mod_op || LDAP_MOD_ADD == mod_op)
  920. {
  921. /* find parent groups and replace our member attr */
  922. memberof_fix_memberof_callback(e, config);
  923. } else {
  924. /* single entry - do mod */
  925. mod_pb = slapi_pblock_new();
  926. mods[0] = &mod;
  927. if(LDAP_MOD_REPLACE == mod_op)
  928. {
  929. mods[1] = &replace_mod;
  930. mods[2] = 0;
  931. }
  932. else
  933. {
  934. mods[1] = 0;
  935. }
  936. val[0] = op_this;
  937. val[1] = 0;
  938. mod.mod_op = LDAP_MOD_REPLACE == mod_op?LDAP_MOD_DELETE:mod_op;
  939. mod.mod_type = config->memberof_attr;
  940. mod.mod_values = val;
  941. if(LDAP_MOD_REPLACE == mod_op)
  942. {
  943. replace_val[0] = replace_with;
  944. replace_val[1] = 0;
  945. replace_mod.mod_op = LDAP_MOD_ADD;
  946. replace_mod.mod_type = config->memberof_attr;
  947. replace_mod.mod_values = replace_val;
  948. }
  949. slapi_modify_internal_set_pb(
  950. mod_pb, op_to,
  951. mods, 0, 0,
  952. memberof_get_plugin_id(), 0);
  953. slapi_modify_internal_pb(mod_pb);
  954. slapi_pblock_get(mod_pb,
  955. SLAPI_PLUGIN_INTOP_RESULT,
  956. &rc);
  957. slapi_pblock_destroy(mod_pb);
  958. }
  959. }
  960. bail:
  961. slapi_sdn_free(&op_to_sdn);
  962. slapi_value_free(&to_dn_val);
  963. slapi_value_free(&this_dn_val);
  964. slapi_entry_free(e);
  965. return rc;
  966. }
  967. /*
  968. * memberof_add_one()
  969. *
  970. * Add addthis DN to the memberof attribute of addto
  971. *
  972. */
  973. int memberof_add_one(Slapi_PBlock *pb, MemberOfConfig *config, char *addthis, char *addto)
  974. {
  975. return memberof_modop_one(pb, config, LDAP_MOD_ADD, addthis, addto);
  976. }
  977. /*
  978. * memberof_del_one()
  979. *
  980. * Delete delthis DN from the memberof attribute of delfrom
  981. *
  982. */
  983. int memberof_del_one(Slapi_PBlock *pb, MemberOfConfig *config, char *delthis, char *delfrom)
  984. {
  985. return memberof_modop_one(pb, config, LDAP_MOD_DELETE, delthis, delfrom);
  986. }
  987. /*
  988. * memberof_mod_smod_list()
  989. *
  990. * Perform mod for group DN to the memberof attribute of the list of targets
  991. *
  992. */
  993. int memberof_mod_smod_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  994. char *group_dn, Slapi_Mod *smod)
  995. {
  996. int rc = 0;
  997. struct berval *bv = slapi_mod_get_first_value(smod);
  998. int last_size = 0;
  999. char *last_str = 0;
  1000. while(bv)
  1001. {
  1002. char *dn_str = 0;
  1003. if(last_size > bv->bv_len)
  1004. {
  1005. dn_str = last_str;
  1006. }
  1007. else
  1008. {
  1009. int the_size = (bv->bv_len * 2) + 1;
  1010. if(last_str)
  1011. slapi_ch_free_string(&last_str);
  1012. dn_str = (char*)slapi_ch_malloc(the_size);
  1013. last_str = dn_str;
  1014. last_size = the_size;
  1015. }
  1016. memset(dn_str, 0, last_size);
  1017. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1018. memberof_modop_one(pb, config, mod, group_dn, dn_str);
  1019. bv = slapi_mod_get_next_value(smod);
  1020. }
  1021. if(last_str)
  1022. slapi_ch_free_string(&last_str);
  1023. return rc;
  1024. }
  1025. /*
  1026. * memberof_add_smod_list()
  1027. *
  1028. * Add group DN to the memberof attribute of the list of targets
  1029. *
  1030. */
  1031. int memberof_add_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1032. char *groupdn, Slapi_Mod *smod)
  1033. {
  1034. return memberof_mod_smod_list(pb, config, LDAP_MOD_ADD, groupdn, smod);
  1035. }
  1036. /*
  1037. * memberof_del_smod_list()
  1038. *
  1039. * Remove group DN from the memberof attribute of the list of targets
  1040. *
  1041. */
  1042. int memberof_del_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1043. char *groupdn, Slapi_Mod *smod)
  1044. {
  1045. return memberof_mod_smod_list(pb, config, LDAP_MOD_DELETE, groupdn, smod);
  1046. }
  1047. /**
  1048. * Plugin identity mgmt
  1049. */
  1050. void memberof_set_plugin_id(void * plugin_id)
  1051. {
  1052. _PluginID=plugin_id;
  1053. }
  1054. void * memberof_get_plugin_id()
  1055. {
  1056. return _PluginID;
  1057. }
  1058. /*
  1059. * memberof_mod_attr_list()
  1060. *
  1061. * Perform mod for group DN to the memberof attribute of the list of targets
  1062. *
  1063. */
  1064. int memberof_mod_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  1065. char *group_dn, Slapi_Attr *attr)
  1066. {
  1067. return memberof_mod_attr_list_r(pb, config, mod, group_dn, group_dn, attr, 0);
  1068. }
  1069. int memberof_mod_attr_list_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  1070. char *group_dn, char *op_this, Slapi_Attr *attr, memberofstringll *stack)
  1071. {
  1072. int rc = 0;
  1073. Slapi_Value *val = 0;
  1074. Slapi_Value *op_this_val = 0;
  1075. int last_size = 0;
  1076. char *last_str = 0;
  1077. int hint = slapi_attr_first_value(attr, &val);
  1078. op_this_val = slapi_value_new_string(op_this);
  1079. while(val)
  1080. {
  1081. char *dn_str = 0;
  1082. struct berval *bv = 0;
  1083. /* We don't want to process a memberOf operation on ourselves. */
  1084. if(0 != memberof_compare(config, &val, &op_this_val))
  1085. {
  1086. bv = (struct berval *)slapi_value_get_berval(val);
  1087. if(last_size > bv->bv_len)
  1088. {
  1089. dn_str = last_str;
  1090. }
  1091. else
  1092. {
  1093. int the_size = (bv->bv_len * 2) + 1;
  1094. if(last_str)
  1095. slapi_ch_free_string(&last_str);
  1096. dn_str = (char*)slapi_ch_malloc(the_size);
  1097. last_str = dn_str;
  1098. last_size = the_size;
  1099. }
  1100. memset(dn_str, 0, last_size);
  1101. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1102. /* If we're doing a replace (as we would in the MODRDN case), we need
  1103. * to specify the new group DN value */
  1104. if(mod == LDAP_MOD_REPLACE)
  1105. {
  1106. memberof_modop_one_replace_r(pb, config, mod, group_dn, op_this,
  1107. group_dn, dn_str, stack);
  1108. }
  1109. else
  1110. {
  1111. memberof_modop_one_r(pb, config, mod, group_dn, op_this, dn_str, stack);
  1112. }
  1113. }
  1114. hint = slapi_attr_next_value(attr, hint, &val);
  1115. }
  1116. slapi_value_free(&op_this_val);
  1117. if(last_str)
  1118. slapi_ch_free_string(&last_str);
  1119. return rc;
  1120. }
  1121. /*
  1122. * memberof_add_attr_list()
  1123. *
  1124. * Add group DN to the memberof attribute of the list of targets
  1125. *
  1126. */
  1127. int memberof_add_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, char *groupdn,
  1128. Slapi_Attr *attr)
  1129. {
  1130. return memberof_mod_attr_list(pb, config, LDAP_MOD_ADD, groupdn, attr);
  1131. }
  1132. /*
  1133. * memberof_del_attr_list()
  1134. *
  1135. * Remove group DN from the memberof attribute of the list of targets
  1136. *
  1137. */
  1138. int memberof_del_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, char *groupdn,
  1139. Slapi_Attr *attr)
  1140. {
  1141. return memberof_mod_attr_list(pb, config, LDAP_MOD_DELETE, groupdn, attr);
  1142. }
  1143. /*
  1144. * memberof_moddn_attr_list()
  1145. *
  1146. * Perform mod for group DN to the memberof attribute of the list of targets
  1147. *
  1148. */
  1149. int memberof_moddn_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1150. char *pre_dn, char *post_dn, Slapi_Attr *attr)
  1151. {
  1152. int rc = 0;
  1153. Slapi_Value *val = 0;
  1154. int last_size = 0;
  1155. char *last_str = 0;
  1156. int hint = slapi_attr_first_value(attr, &val);
  1157. while(val)
  1158. {
  1159. char *dn_str = 0;
  1160. struct berval *bv = (struct berval *)slapi_value_get_berval(val);
  1161. if(last_size > bv->bv_len)
  1162. {
  1163. dn_str = last_str;
  1164. }
  1165. else
  1166. {
  1167. int the_size = (bv->bv_len * 2) + 1;
  1168. if(last_str)
  1169. slapi_ch_free_string(&last_str);
  1170. dn_str = (char*)slapi_ch_malloc(the_size);
  1171. last_str = dn_str;
  1172. last_size = the_size;
  1173. }
  1174. memset(dn_str, 0, last_size);
  1175. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1176. memberof_modop_one_replace_r(pb, config, LDAP_MOD_REPLACE,
  1177. post_dn, pre_dn, post_dn, dn_str, 0);
  1178. hint = slapi_attr_next_value(attr, hint, &val);
  1179. }
  1180. if(last_str)
  1181. slapi_ch_free_string(&last_str);
  1182. return rc;
  1183. }
  1184. /* memberof_get_groups()
  1185. *
  1186. * Gets a list of all groups that an entry is a member of.
  1187. * This is done by looking only at member attribute values.
  1188. * A Slapi_ValueSet* is returned. It is up to the caller to
  1189. * free it.
  1190. */
  1191. Slapi_ValueSet *memberof_get_groups(MemberOfConfig *config, char *memberdn)
  1192. {
  1193. Slapi_Value *memberdn_val = slapi_value_new_string(memberdn);
  1194. Slapi_ValueSet *groupvals = slapi_valueset_new();
  1195. memberof_get_groups_data data = {config, memberdn_val, &groupvals};
  1196. memberof_get_groups_r(config, memberdn, &data);
  1197. slapi_value_free(&memberdn_val);
  1198. return groupvals;
  1199. }
  1200. int memberof_get_groups_r(MemberOfConfig *config, char *memberdn, memberof_get_groups_data *data)
  1201. {
  1202. /* Search for member=<memberdn>
  1203. * For each match, add it to the list, recurse and do same search */
  1204. return memberof_call_foreach_dn(NULL, memberdn, config->groupattr,
  1205. memberof_get_groups_callback, data);
  1206. }
  1207. /* memberof_get_groups_callback()
  1208. *
  1209. * Callback to perform work of memberof_get_groups()
  1210. */
  1211. int memberof_get_groups_callback(Slapi_Entry *e, void *callback_data)
  1212. {
  1213. char *group_dn = slapi_entry_get_dn(e);
  1214. Slapi_Value *group_dn_val = 0;
  1215. Slapi_ValueSet *groupvals = *((memberof_get_groups_data*)callback_data)->groupvals;
  1216. /* get the DN of the group */
  1217. group_dn_val = slapi_value_new_string(group_dn);
  1218. /* check if e is the same as our original member entry */
  1219. if (0 == memberof_compare(((memberof_get_groups_data*)callback_data)->config,
  1220. &((memberof_get_groups_data*)callback_data)->memberdn_val, &group_dn_val))
  1221. {
  1222. /* A recursive group caused us to find our original
  1223. * entry we passed to memberof_get_groups(). We just
  1224. * skip processing this entry. */
  1225. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1226. "memberof_get_groups_callback: group recursion"
  1227. " detected in %s\n" ,group_dn);
  1228. slapi_value_free(&group_dn_val);
  1229. goto bail;
  1230. }
  1231. /* have we been here before? */
  1232. if (groupvals &&
  1233. slapi_valueset_find(((memberof_get_groups_data*)callback_data)->config->group_slapiattr,
  1234. groupvals, group_dn_val))
  1235. {
  1236. /* we either hit a recursive grouping, or an entry is
  1237. * a member of a group through multiple paths. Either
  1238. * way, we can just skip processing this entry since we've
  1239. * already gone through this part of the grouping hierarchy. */
  1240. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1241. "memberof_get_groups_callback: possible group recursion"
  1242. " detected in %s\n" ,group_dn);
  1243. slapi_value_free(&group_dn_val);
  1244. goto bail;
  1245. }
  1246. /* Push group_dn_val into the valueset. This memory is now owned
  1247. * by the valueset. */
  1248. slapi_valueset_add_value_ext(groupvals, group_dn_val, SLAPI_VALUE_FLAG_PASSIN);
  1249. /* now recurse to find parent groups of e */
  1250. memberof_get_groups_r(((memberof_get_groups_data*)callback_data)->config,
  1251. group_dn, callback_data);
  1252. bail:
  1253. return 0;
  1254. }
  1255. /* memberof_is_direct_member()
  1256. *
  1257. * tests for direct membership of memberdn in group groupdn
  1258. * returns non-zero when true, zero otherwise
  1259. */
  1260. int memberof_is_direct_member(MemberOfConfig *config, Slapi_Value *groupdn,
  1261. Slapi_Value *memberdn)
  1262. {
  1263. int rc = 0;
  1264. Slapi_DN *sdn = 0;
  1265. char *attrlist[2] = {config->groupattr,0};
  1266. Slapi_Entry *group_e = 0;
  1267. Slapi_Attr *attr = 0;
  1268. sdn = slapi_sdn_new_dn_byref(slapi_value_get_string(groupdn));
  1269. slapi_search_internal_get_entry(sdn, attrlist,
  1270. &group_e, memberof_get_plugin_id());
  1271. if(group_e)
  1272. {
  1273. slapi_entry_attr_find(group_e, config->groupattr, &attr );
  1274. if(attr)
  1275. {
  1276. rc = 0 == slapi_attr_value_find(
  1277. attr, slapi_value_get_berval(memberdn));
  1278. }
  1279. slapi_entry_free(group_e);
  1280. }
  1281. slapi_sdn_free(&sdn);
  1282. return rc;
  1283. }
  1284. /* memberof_test_membership()
  1285. *
  1286. * Finds all entries who are a "memberOf" the group
  1287. * represented by "group_dn". For each matching entry, we
  1288. * call memberof_test_membership_callback().
  1289. *
  1290. * for each attribute in the memberof attribute
  1291. * determine if the entry is still a member.
  1292. *
  1293. * test each for direct membership
  1294. * move groups entry is memberof to member group
  1295. * test remaining groups for membership in member groups
  1296. * iterate until a pass fails to move a group over to member groups
  1297. * remaining groups should be deleted
  1298. */
  1299. int memberof_test_membership(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn)
  1300. {
  1301. return memberof_call_foreach_dn(pb, group_dn, config->memberof_attr,
  1302. memberof_test_membership_callback , config);
  1303. }
  1304. /*
  1305. * memberof_test_membership_callback()
  1306. *
  1307. * A callback function to do the work of memberof_test_membership().
  1308. * Note that this not only tests membership, but updates the memberOf
  1309. * attributes in the entry to be correct.
  1310. */
  1311. int memberof_test_membership_callback(Slapi_Entry *e, void *callback_data)
  1312. {
  1313. int rc = 0;
  1314. Slapi_Attr *attr = 0;
  1315. int total = 0;
  1316. Slapi_Value **member_array = 0;
  1317. Slapi_Value **candidate_array = 0;
  1318. Slapi_Value *entry_dn = 0;
  1319. MemberOfConfig *config = (MemberOfConfig *)callback_data;
  1320. entry_dn = slapi_value_new_string(slapi_entry_get_dn(e));
  1321. if(0 == entry_dn)
  1322. {
  1323. goto bail;
  1324. }
  1325. /* divide groups into member and non-member lists */
  1326. slapi_entry_attr_find(e, config->memberof_attr, &attr );
  1327. if(attr)
  1328. {
  1329. slapi_attr_get_numvalues( attr, &total);
  1330. if(total)
  1331. {
  1332. Slapi_Value *val = 0;
  1333. int hint = 0;
  1334. int c_index = 0;
  1335. int m_index = 0;
  1336. int member_found = 1;
  1337. int outer_index = 0;
  1338. candidate_array =
  1339. (Slapi_Value**)
  1340. slapi_ch_malloc(sizeof(Slapi_Value*)*total);
  1341. memset(candidate_array, 0, sizeof(Slapi_Value*)*total);
  1342. member_array =
  1343. (Slapi_Value**)
  1344. slapi_ch_malloc(sizeof(Slapi_Value*)*total);
  1345. memset(member_array, 0, sizeof(Slapi_Value*)*total);
  1346. hint = slapi_attr_first_value(attr, &val);
  1347. while(val)
  1348. {
  1349. /* test for direct membership */
  1350. if(memberof_is_direct_member(config, val, entry_dn))
  1351. {
  1352. /* it is a member */
  1353. member_array[m_index] = val;
  1354. m_index++;
  1355. }
  1356. else
  1357. {
  1358. /* not a member, still a candidate */
  1359. candidate_array[c_index] = val;
  1360. c_index++;
  1361. }
  1362. hint = slapi_attr_next_value(attr, hint, &val);
  1363. }
  1364. /* now iterate over members testing for membership
  1365. in candidate groups and moving candidates to members
  1366. when successful, quit when a full iteration adds no
  1367. new members
  1368. */
  1369. while(member_found)
  1370. {
  1371. member_found = 0;
  1372. /* For each group that this entry is a verified member of, see if
  1373. * any of the candidate groups are members. If they are, add them
  1374. * to the list of verified groups that this entry is a member of.
  1375. */
  1376. while(outer_index < m_index)
  1377. {
  1378. int inner_index = 0;
  1379. while(inner_index < c_index)
  1380. {
  1381. /* Check for a special value in this position
  1382. * that indicates that the candidate was moved
  1383. * to the member array. */
  1384. if((void*)1 ==
  1385. candidate_array[inner_index])
  1386. {
  1387. /* was moved, skip */
  1388. inner_index++;
  1389. continue;
  1390. }
  1391. if(memberof_is_direct_member(
  1392. config,
  1393. candidate_array[inner_index],
  1394. member_array[outer_index]))
  1395. {
  1396. member_array[m_index] =
  1397. candidate_array
  1398. [inner_index];
  1399. m_index++;
  1400. candidate_array[inner_index] =
  1401. (void*)1;
  1402. member_found = 1;
  1403. }
  1404. inner_index++;
  1405. }
  1406. outer_index++;
  1407. }
  1408. }
  1409. /* here we are left only with values to delete
  1410. from the memberof attribute in the candidate list
  1411. */
  1412. outer_index = 0;
  1413. while(outer_index < c_index)
  1414. {
  1415. /* Check for a special value in this position
  1416. * that indicates that the candidate was moved
  1417. * to the member array. */
  1418. if((void*)1 == candidate_array[outer_index])
  1419. {
  1420. /* item moved, skip */
  1421. outer_index++;
  1422. continue;
  1423. }
  1424. memberof_del_one(
  1425. 0, config,
  1426. (char*)slapi_value_get_string(
  1427. candidate_array[outer_index]),
  1428. (char*)slapi_value_get_string(entry_dn));
  1429. outer_index++;
  1430. }
  1431. {
  1432. /* crazyness follows:
  1433. * strict-aliasing doesn't like the required cast
  1434. * to void for slapi_ch_free so we are made to
  1435. * juggle to get a normal thing done
  1436. */
  1437. void *pmember_array = member_array;
  1438. void *pcandidate_array = candidate_array;
  1439. slapi_ch_free(&pcandidate_array);
  1440. slapi_ch_free(&pmember_array);
  1441. candidate_array = 0;
  1442. member_array = 0;
  1443. }
  1444. }
  1445. }
  1446. bail:
  1447. slapi_value_free(&entry_dn);
  1448. return rc;
  1449. }
  1450. /*
  1451. * memberof_replace_list()
  1452. *
  1453. * Perform replace the group DN list in the memberof attribute of the list of targets
  1454. *
  1455. */
  1456. int memberof_replace_list(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn)
  1457. {
  1458. struct slapi_entry *pre_e = NULL;
  1459. struct slapi_entry *post_e = NULL;
  1460. Slapi_Attr *pre_attr = 0;
  1461. Slapi_Attr *post_attr = 0;
  1462. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &pre_e );
  1463. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &post_e );
  1464. if(pre_e && post_e)
  1465. {
  1466. slapi_entry_attr_find( pre_e, config->groupattr, &pre_attr );
  1467. slapi_entry_attr_find( post_e, config->groupattr, &post_attr );
  1468. }
  1469. if(pre_attr || post_attr)
  1470. {
  1471. int pre_total = 0;
  1472. int post_total = 0;
  1473. Slapi_Value **pre_array = 0;
  1474. Slapi_Value **post_array = 0;
  1475. int pre_index = 0;
  1476. int post_index = 0;
  1477. /* create arrays of values */
  1478. if(pre_attr)
  1479. {
  1480. slapi_attr_get_numvalues( pre_attr, &pre_total);
  1481. }
  1482. if(post_attr)
  1483. {
  1484. slapi_attr_get_numvalues( post_attr, &post_total);
  1485. }
  1486. /* Stash a plugin global pointer here and have memberof_qsort_compare
  1487. * use it. We have to do this because we use memberof_qsort_compare
  1488. * as the comparator function for qsort, which requires the function
  1489. * to only take two void* args. This is thread-safe since we only
  1490. * store and use the pointer while holding the memberOf operation
  1491. * lock. */
  1492. qsortConfig = config;
  1493. if(pre_total)
  1494. {
  1495. pre_array =
  1496. (Slapi_Value**)
  1497. slapi_ch_malloc(sizeof(Slapi_Value*)*pre_total);
  1498. memberof_load_array(pre_array, pre_attr);
  1499. qsort(
  1500. pre_array,
  1501. pre_total,
  1502. sizeof(Slapi_Value*),
  1503. memberof_qsort_compare);
  1504. }
  1505. if(post_total)
  1506. {
  1507. post_array =
  1508. (Slapi_Value**)
  1509. slapi_ch_malloc(sizeof(Slapi_Value*)*post_total);
  1510. memberof_load_array(post_array, post_attr);
  1511. qsort(
  1512. post_array,
  1513. post_total,
  1514. sizeof(Slapi_Value*),
  1515. memberof_qsort_compare);
  1516. }
  1517. qsortConfig = 0;
  1518. /* work through arrays, following these rules:
  1519. in pre, in post, do nothing
  1520. in pre, not in post, delete from entry
  1521. not in pre, in post, add to entry
  1522. */
  1523. while(pre_index < pre_total || post_index < post_total)
  1524. {
  1525. if(pre_index == pre_total)
  1526. {
  1527. /* add the rest of post */
  1528. memberof_add_one(
  1529. pb, config,
  1530. group_dn,
  1531. (char*)slapi_value_get_string(
  1532. post_array[post_index]));
  1533. post_index++;
  1534. }
  1535. else if(post_index == post_total)
  1536. {
  1537. /* delete the rest of pre */
  1538. memberof_del_one(
  1539. pb, config,
  1540. group_dn,
  1541. (char*)slapi_value_get_string(
  1542. pre_array[pre_index]));
  1543. pre_index++;
  1544. }
  1545. else
  1546. {
  1547. /* decide what to do */
  1548. int cmp = memberof_compare(
  1549. config,
  1550. &(pre_array[pre_index]),
  1551. &(post_array[post_index]));
  1552. if(cmp < 0)
  1553. {
  1554. /* delete pre array */
  1555. memberof_del_one(
  1556. pb, config,
  1557. group_dn,
  1558. (char*)slapi_value_get_string(
  1559. pre_array[pre_index]));
  1560. pre_index++;
  1561. }
  1562. else if(cmp > 0)
  1563. {
  1564. /* add post array */
  1565. memberof_add_one(
  1566. pb, config,
  1567. group_dn,
  1568. (char*)slapi_value_get_string(
  1569. post_array[post_index]));
  1570. post_index++;
  1571. }
  1572. else
  1573. {
  1574. /* do nothing, advance */
  1575. pre_index++;
  1576. post_index++;
  1577. }
  1578. }
  1579. }
  1580. slapi_ch_free((void **)&pre_array);
  1581. slapi_ch_free((void **)&post_array);
  1582. }
  1583. return 0;
  1584. }
  1585. /* memberof_load_array()
  1586. *
  1587. * put attribute values in array structure
  1588. */
  1589. void memberof_load_array(Slapi_Value **array, Slapi_Attr *attr)
  1590. {
  1591. Slapi_Value *val = 0;
  1592. int hint = slapi_attr_first_value(attr, &val);
  1593. while(val)
  1594. {
  1595. *array = val;
  1596. array++;
  1597. hint = slapi_attr_next_value(attr, hint, &val);
  1598. }
  1599. }
  1600. /* memberof_compare()
  1601. *
  1602. * compare two attr values
  1603. */
  1604. int memberof_compare(MemberOfConfig *config, const void *a, const void *b)
  1605. {
  1606. Slapi_Value *val1 = *((Slapi_Value **)a);
  1607. Slapi_Value *val2 = *((Slapi_Value **)b);
  1608. return slapi_attr_value_cmp(
  1609. config->group_slapiattr,
  1610. slapi_value_get_berval(val1),
  1611. slapi_value_get_berval(val2));
  1612. }
  1613. /* memberof_qsort_compare()
  1614. *
  1615. * This is a version of memberof_compare that uses a plugin
  1616. * global copy of the config. We'd prefer to pass in a copy
  1617. * of config that is local to the running thread, but we can't
  1618. * do this since qsort is using us as a comparator function.
  1619. * We should only use this function when using qsort, and only
  1620. * when the memberOf lock is acquired.
  1621. */
  1622. int memberof_qsort_compare(const void *a, const void *b)
  1623. {
  1624. Slapi_Value *val1 = *((Slapi_Value **)a);
  1625. Slapi_Value *val2 = *((Slapi_Value **)b);
  1626. return slapi_attr_value_cmp(
  1627. qsortConfig->group_slapiattr,
  1628. slapi_value_get_berval(val1),
  1629. slapi_value_get_berval(val2));
  1630. }
  1631. void memberof_lock()
  1632. {
  1633. slapi_lock_mutex(memberof_operation_lock);
  1634. }
  1635. void memberof_unlock()
  1636. {
  1637. slapi_unlock_mutex(memberof_operation_lock);
  1638. }
  1639. typedef struct _task_data
  1640. {
  1641. char *dn;
  1642. char *filter_str;
  1643. } task_data;
  1644. void memberof_fixup_task_thread(void *arg)
  1645. {
  1646. MemberOfConfig configCopy = {0, 0, 0, 0};
  1647. Slapi_Task *task = (Slapi_Task *)arg;
  1648. task_data *td = NULL;
  1649. int rc = 0;
  1650. /* Fetch our task data from the task */
  1651. td = (task_data *)slapi_task_get_data(task);
  1652. slapi_task_begin(task, 1);
  1653. slapi_task_log_notice(task, "Memberof task starts (arg: %s) ...\n",
  1654. td->filter_str);
  1655. /* We need to get the config lock first. Trying to get the
  1656. * config lock after we already hold the op lock can cause
  1657. * a deadlock. */
  1658. memberof_rlock_config();
  1659. /* copy config so it doesn't change out from under us */
  1660. memberof_copy_config(&configCopy, memberof_get_config());
  1661. memberof_unlock_config();
  1662. /* get the memberOf operation lock */
  1663. memberof_lock();
  1664. /* do real work */
  1665. rc = memberof_fix_memberof(&configCopy, td->dn, td->filter_str);
  1666. /* release the memberOf operation lock */
  1667. memberof_unlock();
  1668. memberof_free_config(&configCopy);
  1669. slapi_task_log_notice(task, "Memberof task finished.");
  1670. slapi_task_log_status(task, "Memberof task finished.");
  1671. slapi_task_inc_progress(task);
  1672. /* this will queue the destruction of the task */
  1673. slapi_task_finish(task, rc);
  1674. }
  1675. /* extract a single value from the entry (as a string) -- if it's not in the
  1676. * entry, the default will be returned (which can be NULL).
  1677. * you do not need to free anything returned by this.
  1678. */
  1679. const char *fetch_attr(Slapi_Entry *e, const char *attrname,
  1680. const char *default_val)
  1681. {
  1682. Slapi_Attr *attr;
  1683. Slapi_Value *val = NULL;
  1684. if (slapi_entry_attr_find(e, attrname, &attr) != 0)
  1685. return default_val;
  1686. slapi_attr_first_value(attr, &val);
  1687. return slapi_value_get_string(val);
  1688. }
  1689. int memberof_task_add(Slapi_PBlock *pb, Slapi_Entry *e,
  1690. Slapi_Entry *eAfter, int *returncode, char *returntext,
  1691. void *arg)
  1692. {
  1693. PRThread *thread = NULL;
  1694. int rv = SLAPI_DSE_CALLBACK_OK;
  1695. task_data *mytaskdata = NULL;
  1696. Slapi_Task *task = NULL;
  1697. const char *filter;
  1698. const char *dn = 0;
  1699. *returncode = LDAP_SUCCESS;
  1700. /* get arg(s) */
  1701. if ((dn = fetch_attr(e, "basedn", 0)) == NULL)
  1702. {
  1703. *returncode = LDAP_OBJECT_CLASS_VIOLATION;
  1704. rv = SLAPI_DSE_CALLBACK_ERROR;
  1705. goto out;
  1706. }
  1707. if ((filter = fetch_attr(e, "filter", "(objectclass=inetuser)")) == NULL)
  1708. {
  1709. *returncode = LDAP_OBJECT_CLASS_VIOLATION;
  1710. rv = SLAPI_DSE_CALLBACK_ERROR;
  1711. goto out;
  1712. }
  1713. /* setup our task data */
  1714. mytaskdata = (task_data*)slapi_ch_malloc(sizeof(task_data));
  1715. if (mytaskdata == NULL)
  1716. {
  1717. *returncode = LDAP_OPERATIONS_ERROR;
  1718. rv = SLAPI_DSE_CALLBACK_ERROR;
  1719. goto out;
  1720. }
  1721. mytaskdata->dn = slapi_ch_strdup(dn);
  1722. mytaskdata->filter_str = slapi_ch_strdup(filter);
  1723. /* allocate new task now */
  1724. task = slapi_new_task(slapi_entry_get_ndn(e));
  1725. /* register our destructor for cleaning up our private data */
  1726. slapi_task_set_destructor_fn(task, memberof_task_destructor);
  1727. /* Stash a pointer to our data in the task */
  1728. slapi_task_set_data(task, mytaskdata);
  1729. /* start the sample task as a separate thread */
  1730. thread = PR_CreateThread(PR_USER_THREAD, memberof_fixup_task_thread,
  1731. (void *)task, PR_PRIORITY_NORMAL, PR_GLOBAL_THREAD,
  1732. PR_UNJOINABLE_THREAD, SLAPD_DEFAULT_THREAD_STACKSIZE);
  1733. if (thread == NULL)
  1734. {
  1735. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  1736. "unable to create task thread!\n");
  1737. *returncode = LDAP_OPERATIONS_ERROR;
  1738. rv = SLAPI_DSE_CALLBACK_ERROR;
  1739. slapi_task_finish(task, *returncode);
  1740. } else {
  1741. rv = SLAPI_DSE_CALLBACK_OK;
  1742. }
  1743. out:
  1744. return rv;
  1745. }
  1746. void
  1747. memberof_task_destructor(Slapi_Task *task)
  1748. {
  1749. if (task) {
  1750. task_data *mydata = (task_data *)slapi_task_get_data(task);
  1751. if (mydata) {
  1752. slapi_ch_free_string(&mydata->dn);
  1753. slapi_ch_free_string(&mydata->filter_str);
  1754. /* Need to cast to avoid a compiler warning */
  1755. slapi_ch_free((void **)&mydata);
  1756. }
  1757. }
  1758. }
  1759. int memberof_fix_memberof(MemberOfConfig *config, char *dn, char *filter_str)
  1760. {
  1761. int rc = 0;
  1762. Slapi_PBlock *search_pb = slapi_pblock_new();
  1763. slapi_search_internal_set_pb(search_pb, dn,
  1764. LDAP_SCOPE_SUBTREE, filter_str, 0, 0,
  1765. 0, 0,
  1766. memberof_get_plugin_id(),
  1767. 0);
  1768. rc = slapi_search_internal_callback_pb(search_pb,
  1769. config,
  1770. 0, memberof_fix_memberof_callback,
  1771. 0);
  1772. slapi_pblock_destroy(search_pb);
  1773. return rc;
  1774. }
  1775. /* memberof_fix_memberof_callback()
  1776. * Add initial and/or fix up broken group list in entry
  1777. *
  1778. * 1. Remove all present memberOf values
  1779. * 2. Add direct group membership memberOf values
  1780. * 3. Add indirect group membership memberOf values
  1781. */
  1782. int memberof_fix_memberof_callback(Slapi_Entry *e, void *callback_data)
  1783. {
  1784. int rc = 0;
  1785. char *dn = slapi_entry_get_dn(e);
  1786. MemberOfConfig *config = (MemberOfConfig *)callback_data;
  1787. memberof_del_dn_data del_data = {0, config->memberof_attr};
  1788. Slapi_ValueSet *groups = 0;
  1789. /* get a list of all of the groups this user belongs to */
  1790. groups = memberof_get_groups(config, dn);
  1791. /* If we found some groups, replace the existing memberOf attribute
  1792. * with the found values. */
  1793. if (groups && slapi_valueset_count(groups))
  1794. {
  1795. Slapi_PBlock *mod_pb = slapi_pblock_new();
  1796. Slapi_Value *val = 0;
  1797. Slapi_Mod *smod;
  1798. LDAPMod **mods = (LDAPMod **) slapi_ch_malloc(2 * sizeof(LDAPMod *));
  1799. int hint = 0;
  1800. smod = slapi_mod_new();
  1801. slapi_mod_init(smod, 0);
  1802. slapi_mod_set_operation(smod, LDAP_MOD_REPLACE | LDAP_MOD_BVALUES);
  1803. slapi_mod_set_type(smod, config->memberof_attr);
  1804. /* Loop through all of our values and add them to smod */
  1805. hint = slapi_valueset_first_value(groups, &val);
  1806. while (val)
  1807. {
  1808. /* this makes a copy of the berval */
  1809. slapi_mod_add_value(smod, slapi_value_get_berval(val));
  1810. hint = slapi_valueset_next_value(groups, hint, &val);
  1811. }
  1812. mods[0] = slapi_mod_get_ldapmod_passout(smod);
  1813. mods[1] = 0;
  1814. slapi_modify_internal_set_pb(
  1815. mod_pb, dn, mods, 0, 0,
  1816. memberof_get_plugin_id(), 0);
  1817. slapi_modify_internal_pb(mod_pb);
  1818. slapi_pblock_get(mod_pb, SLAPI_PLUGIN_INTOP_RESULT, &rc);
  1819. ldap_mods_free(mods, 1);
  1820. slapi_mod_free(&smod);
  1821. slapi_pblock_destroy(mod_pb);
  1822. } else {
  1823. /* No groups were found, so remove the memberOf attribute
  1824. * from this entry. */
  1825. memberof_del_dn_type_callback(e, &del_data);
  1826. }
  1827. slapi_valueset_free(groups);
  1828. return rc;
  1829. }