memberof.c 66 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458
  1. /** BEGIN COPYRIGHT BLOCK
  2. * This Program is free software; you can redistribute it and/or modify it under
  3. * the terms of the GNU General Public License as published by the Free Software
  4. * Foundation; version 2 of the License.
  5. *
  6. * This Program is distributed in the hope that it will be useful, but WITHOUT
  7. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  8. * FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
  9. *
  10. * You should have received a copy of the GNU General Public License along with
  11. * this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
  12. * Place, Suite 330, Boston, MA 02111-1307 USA.
  13. *
  14. * In addition, as a special exception, Red Hat, Inc. gives You the additional
  15. * right to link the code of this Program with code not covered under the GNU
  16. * General Public License ("Non-GPL Code") and to distribute linked combinations
  17. * including the two, subject to the limitations in this paragraph. Non-GPL Code
  18. * permitted under this exception must only link to the code of this Program
  19. * through those well defined interfaces identified in the file named EXCEPTION
  20. * found in the source code files (the "Approved Interfaces"). The files of
  21. * Non-GPL Code may instantiate templates or use macros or inline functions from
  22. * the Approved Interfaces without causing the resulting work to be covered by
  23. * the GNU General Public License. Only Red Hat, Inc. may make changes or
  24. * additions to the list of Approved Interfaces. You must obey the GNU General
  25. * Public License in all respects for all of the Program code and other code used
  26. * in conjunction with the Program except the Non-GPL Code covered by this
  27. * exception. If you modify this file, you may extend this exception to your
  28. * version of the file, but you are not obligated to do so. If you do not wish to
  29. * provide this exception without modification, you must delete this exception
  30. * statement from your version and license this file solely under the GPL without
  31. * exception.
  32. *
  33. * Authors:
  34. * Pete Rowley <[email protected]>
  35. * Nathan Kinder <[email protected]>
  36. *
  37. * Copyright (C) 2010 Red Hat, Inc.
  38. * All rights reserved.
  39. * END COPYRIGHT BLOCK
  40. **/
  41. /* The memberof plugin updates the memberof attribute of entries
  42. * based on modifications performed on groupofuniquenames entries
  43. *
  44. * In addition the plugin provides a DS task that may be started
  45. * administrative clients and that creates the initial memberof
  46. * list for imported entries and/or fixes the memberof list of
  47. * existing entries that have inconsistent state (for example,
  48. * if the memberof attribute was incorrectly edited directly)
  49. *
  50. * To start the memberof task add an entry like:
  51. *
  52. * dn: cn=mytask, cn=memberof task, cn=tasks, cn=config
  53. * objectClass: top
  54. * objectClass: extensibleObject
  55. * cn: mytask
  56. * basedn: dc=example, dc=com
  57. * filter: (uid=test4)
  58. *
  59. * where "basedn" is required and refers to the top most node to perform the
  60. * task on, and where "filter" is an optional attribute that provides a filter
  61. * describing the entries to be worked on
  62. */
  63. #ifdef HAVE_CONFIG_H
  64. # include <config.h>
  65. #endif
  66. #include "slapi-plugin.h"
  67. #include "string.h"
  68. #include "nspr.h"
  69. #include "memberof.h"
  70. static Slapi_PluginDesc pdesc = { "memberof", VENDOR,
  71. DS_PACKAGE_VERSION, "memberof plugin" };
  72. static void* _PluginID = NULL;
  73. static PRMonitor *memberof_operation_lock = 0;
  74. MemberOfConfig *qsortConfig = 0;
  75. static int g_plugin_started = 0;
  76. typedef struct _memberofstringll
  77. {
  78. const char *dn;
  79. void *next;
  80. } memberofstringll;
  81. typedef struct _memberof_get_groups_data
  82. {
  83. MemberOfConfig *config;
  84. Slapi_Value *memberdn_val;
  85. Slapi_ValueSet **groupvals;
  86. void *txn;
  87. } memberof_get_groups_data;
  88. /*** function prototypes ***/
  89. /* exported functions */
  90. int memberof_postop_init(Slapi_PBlock *pb );
  91. static int memberof_internal_postop_init(Slapi_PBlock *pb);
  92. /* plugin callbacks */
  93. static int memberof_postop_del(Slapi_PBlock *pb );
  94. static int memberof_postop_modrdn(Slapi_PBlock *pb );
  95. static int memberof_postop_modify(Slapi_PBlock *pb );
  96. static int memberof_postop_add(Slapi_PBlock *pb );
  97. static int memberof_postop_start(Slapi_PBlock *pb);
  98. static int memberof_postop_close(Slapi_PBlock *pb);
  99. /* supporting cast */
  100. static int memberof_oktodo(Slapi_PBlock *pb);
  101. static char *memberof_getdn(Slapi_PBlock *pb);
  102. static int memberof_modop_one(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  103. char *op_this, char *op_to, void *txn);
  104. static int memberof_modop_one_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  105. char *group_dn, char *op_this, char *op_to, memberofstringll *stack, void *txn);
  106. static int memberof_add_one(Slapi_PBlock *pb, MemberOfConfig *config, char *addthis,
  107. char *addto, void *txn);
  108. static int memberof_del_one(Slapi_PBlock *pb, MemberOfConfig *config, char *delthis,
  109. char *delfrom, void *txn);
  110. static int memberof_mod_smod_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  111. char *groupdn, Slapi_Mod *smod, void *txn);
  112. static int memberof_add_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  113. char *groupdn, Slapi_Mod *smod, void *txn);
  114. static int memberof_del_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  115. char *groupdn, Slapi_Mod *smod, void *txn);
  116. static int memberof_mod_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  117. char *groupdn, Slapi_Attr *attr, void *txn);
  118. static int memberof_mod_attr_list_r(Slapi_PBlock *pb, MemberOfConfig *config,
  119. int mod, char *group_dn, char *op_this, Slapi_Attr *attr, memberofstringll *stack, void *txn);
  120. static int memberof_add_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  121. char *groupdn, Slapi_Attr *attr, void *txn);
  122. static int memberof_del_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  123. char *groupdn, Slapi_Attr *attr, void *txn);
  124. static int memberof_moddn_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  125. char *pre_dn, char *post_dn, Slapi_Attr *attr, void *txn);
  126. static int memberof_replace_list(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn, void *txn);
  127. static void memberof_set_plugin_id(void * plugin_id);
  128. static void *memberof_get_plugin_id();
  129. static int memberof_compare(MemberOfConfig *config, const void *a, const void *b);
  130. static int memberof_qsort_compare(const void *a, const void *b);
  131. static void memberof_load_array(Slapi_Value **array, Slapi_Attr *attr);
  132. static void memberof_del_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config, char *dn, void *txn);
  133. static int memberof_call_foreach_dn(Slapi_PBlock *pb, char *dn,
  134. char **types, plugin_search_entry_callback callback, void *callback_data, void *txn);
  135. static int memberof_is_direct_member(MemberOfConfig *config, Slapi_Value *groupdn,
  136. Slapi_Value *memberdn, void *txn);
  137. static int memberof_is_grouping_attr(char *type, MemberOfConfig *config);
  138. static Slapi_ValueSet *memberof_get_groups(MemberOfConfig *config, char *memberdn, void *txn);
  139. static int memberof_get_groups_r(MemberOfConfig *config, char *memberdn,
  140. memberof_get_groups_data *data, void *txn);
  141. static int memberof_get_groups_callback(Slapi_Entry *e, void *callback_data);
  142. static int memberof_test_membership(Slapi_PBlock *pb, MemberOfConfig *config,
  143. char *group_dn, void *txn);
  144. static int memberof_test_membership_callback(Slapi_Entry *e, void *callback_data);
  145. static int memberof_del_dn_type_callback(Slapi_Entry *e, void *callback_data);
  146. static int memberof_replace_dn_type_callback(Slapi_Entry *e, void *callback_data);
  147. static void memberof_replace_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config,
  148. char *pre_dn, char *post_dn, void *txn);
  149. static int memberof_modop_one_replace_r(Slapi_PBlock *pb, MemberOfConfig *config,
  150. int mod_op, char *group_dn, char *op_this, char *replace_with, char *op_to,
  151. memberofstringll *stack, void *txn);
  152. static int memberof_task_add(Slapi_PBlock *pb, Slapi_Entry *e,
  153. Slapi_Entry *eAfter, int *returncode, char *returntext,
  154. void *arg);
  155. static void memberof_task_destructor(Slapi_Task *task);
  156. static const char *fetch_attr(Slapi_Entry *e, const char *attrname,
  157. const char *default_val);
  158. static void memberof_fixup_task_thread(void *arg);
  159. static int memberof_fix_memberof(MemberOfConfig *config, char *dn, char *filter_str, void *txn);
  160. static int memberof_fix_memberof_callback(Slapi_Entry *e, void *callback_data);
  161. /*** implementation ***/
  162. /*** exported functions ***/
  163. /*
  164. * memberof_postop_init()
  165. *
  166. * Register plugin call backs
  167. *
  168. */
  169. int
  170. memberof_postop_init(Slapi_PBlock *pb)
  171. {
  172. int ret = 0;
  173. char *memberof_plugin_identity = 0;
  174. Slapi_Entry *plugin_entry = NULL;
  175. char *plugin_type = NULL;
  176. int usetxn = 0;
  177. int delfn = SLAPI_PLUGIN_POST_DELETE_FN;
  178. int mdnfn = SLAPI_PLUGIN_POST_MODRDN_FN;
  179. int modfn = SLAPI_PLUGIN_POST_MODIFY_FN;
  180. int addfn = SLAPI_PLUGIN_POST_ADD_FN;
  181. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  182. "--> memberof_postop_init\n" );
  183. /* get args */
  184. if ((slapi_pblock_get(pb, SLAPI_PLUGIN_CONFIG_ENTRY, &plugin_entry) == 0) &&
  185. plugin_entry &&
  186. (plugin_type = slapi_entry_attr_get_charptr(plugin_entry, "nsslapd-plugintype")) &&
  187. plugin_type && strstr(plugin_type, "betxn")) {
  188. usetxn = 1;
  189. delfn = SLAPI_PLUGIN_BE_TXN_POST_DELETE_FN;
  190. mdnfn = SLAPI_PLUGIN_BE_TXN_POST_MODRDN_FN;
  191. modfn = SLAPI_PLUGIN_BE_TXN_POST_MODIFY_FN;
  192. addfn = SLAPI_PLUGIN_BE_TXN_POST_ADD_FN;
  193. }
  194. slapi_ch_free_string(&plugin_type);
  195. /*
  196. * Get plugin identity and stored it for later use
  197. * Used for internal operations
  198. */
  199. slapi_pblock_get (pb, SLAPI_PLUGIN_IDENTITY, &memberof_plugin_identity);
  200. PR_ASSERT (memberof_plugin_identity);
  201. memberof_set_plugin_id(memberof_plugin_identity);
  202. ret = ( slapi_pblock_set( pb, SLAPI_PLUGIN_VERSION,
  203. SLAPI_PLUGIN_VERSION_01 ) != 0 ||
  204. slapi_pblock_set( pb, SLAPI_PLUGIN_DESCRIPTION,
  205. (void *)&pdesc ) != 0 ||
  206. slapi_pblock_set( pb, delfn, (void *) memberof_postop_del ) != 0 ||
  207. slapi_pblock_set( pb, mdnfn, (void *) memberof_postop_modrdn ) != 0 ||
  208. slapi_pblock_set( pb, modfn, (void *) memberof_postop_modify ) != 0 ||
  209. slapi_pblock_set( pb, addfn, (void *) memberof_postop_add ) != 0 ||
  210. slapi_pblock_set(pb, SLAPI_PLUGIN_START_FN,
  211. (void *) memberof_postop_start ) != 0 ||
  212. slapi_pblock_set(pb, SLAPI_PLUGIN_CLOSE_FN,
  213. (void *) memberof_postop_close ) != 0 );
  214. if (!ret && !usetxn &&
  215. slapi_register_plugin("internalpostoperation", /* op type */
  216. 1, /* Enabled */
  217. "memberof_postop_init", /* this function desc */
  218. memberof_internal_postop_init, /* init func */
  219. MEMBEROF_INT_PREOP_DESC, /* plugin desc */
  220. NULL, /* ? */
  221. memberof_plugin_identity /* access control */))
  222. {
  223. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  224. "memberof_postop_init failed\n" );
  225. ret = -1;
  226. }
  227. else if (ret)
  228. {
  229. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  230. "memberof_postop_init failed\n" );
  231. ret = -1;
  232. }
  233. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  234. "<-- memberof_postop_init\n" );
  235. return ret;
  236. }
  237. static int
  238. memberof_internal_postop_init(Slapi_PBlock *pb)
  239. {
  240. int status = 0;
  241. if (slapi_pblock_set(pb, SLAPI_PLUGIN_VERSION,
  242. SLAPI_PLUGIN_VERSION_01) != 0 ||
  243. slapi_pblock_set(pb, SLAPI_PLUGIN_DESCRIPTION,
  244. (void *) &pdesc) != 0 ||
  245. slapi_pblock_set(pb, SLAPI_PLUGIN_INTERNAL_POST_DELETE_FN,
  246. (void *) memberof_postop_del) != 0 ||
  247. slapi_pblock_set( pb, SLAPI_PLUGIN_INTERNAL_POST_MODRDN_FN,
  248. (void *) memberof_postop_modrdn ) != 0 ||
  249. slapi_pblock_set( pb, SLAPI_PLUGIN_INTERNAL_POST_MODIFY_FN,
  250. (void *) memberof_postop_modify ) != 0 ||
  251. slapi_pblock_set( pb, SLAPI_PLUGIN_INTERNAL_POST_ADD_FN,
  252. (void *) memberof_postop_add ) != 0) {
  253. slapi_log_error(SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  254. "memberof_internal_postop_init: failed to register plugin\n");
  255. status = -1;
  256. }
  257. return status;
  258. }
  259. /*
  260. * memberof_postop_start()
  261. *
  262. * Do plugin start up stuff
  263. *
  264. */
  265. int memberof_postop_start(Slapi_PBlock *pb)
  266. {
  267. int rc = 0;
  268. Slapi_Entry *config_e = NULL; /* entry containing plugin config */
  269. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  270. "--> memberof_postop_start\n" );
  271. /* Check if we're already started */
  272. if (g_plugin_started) {
  273. goto bail;
  274. }
  275. memberof_operation_lock = PR_NewMonitor();
  276. if(0 == memberof_operation_lock)
  277. {
  278. rc = -1;
  279. goto bail;
  280. }
  281. if ( slapi_pblock_get( pb, SLAPI_ADD_ENTRY, &config_e ) != 0 ) {
  282. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  283. "missing config entry\n" );
  284. rc = -1;
  285. goto bail;
  286. }
  287. if (( rc = memberof_config( config_e )) != LDAP_SUCCESS ) {
  288. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  289. "configuration failed (%s)\n", ldap_err2string( rc ));
  290. return( -1 );
  291. }
  292. rc = slapi_task_register_handler("memberof task", memberof_task_add);
  293. if(rc)
  294. {
  295. goto bail;
  296. }
  297. g_plugin_started = 1;
  298. /*
  299. * TODO: start up operation actor thread
  300. * need to get to a point where server failure
  301. * or shutdown doesn't hose our operations
  302. * so we should create a task entry that contains
  303. * all required information to complete the operation
  304. * then the tasks can be restarted safely if
  305. * interrupted
  306. */
  307. bail:
  308. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  309. "<-- memberof_postop_start\n" );
  310. return rc;
  311. }
  312. /*
  313. * memberof_postop_close()
  314. *
  315. * Do plugin shut down stuff
  316. *
  317. */
  318. int memberof_postop_close(Slapi_PBlock *pb)
  319. {
  320. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  321. "--> memberof_postop_close\n" );
  322. g_plugin_started = 0;
  323. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  324. "<-- memberof_postop_close\n" );
  325. return 0;
  326. }
  327. /*
  328. * memberof_postop_del()
  329. *
  330. * All entries with a memberOf attribute that contains the group DN get retrieved
  331. * and have the their memberOf attribute regenerated (it is far too complex and
  332. * error prone to attempt to change only those dn values involved in this case -
  333. * mainly because the deleted group may itself be a member of other groups which
  334. * may be members of other groups etc. in a big recursive mess involving dependency
  335. * chains that must be created and traversed in order to decide if an entry should
  336. * really have those groups removed too)
  337. */
  338. int memberof_postop_del(Slapi_PBlock *pb)
  339. {
  340. int ret = 0;
  341. MemberOfConfig configCopy = {0, 0, 0, 0};
  342. char *dn;
  343. void *caller_id = NULL;
  344. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  345. "--> memberof_postop_del\n" );
  346. /* We don't want to process internal modify
  347. * operations that originate from this plugin. */
  348. slapi_pblock_get(pb, SLAPI_PLUGIN_IDENTITY, &caller_id);
  349. if (caller_id == memberof_get_plugin_id()) {
  350. /* Just return without processing */
  351. return 0;
  352. }
  353. if(memberof_oktodo(pb) && (dn = memberof_getdn(pb)))
  354. {
  355. struct slapi_entry *e = NULL;
  356. void *txn = NULL;
  357. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &e );
  358. slapi_pblock_get( pb, SLAPI_TXN, &txn );
  359. /* We need to get the config lock first. Trying to get the
  360. * config lock after we already hold the op lock can cause
  361. * a deadlock. */
  362. memberof_rlock_config();
  363. /* copy config so it doesn't change out from under us */
  364. memberof_copy_config(&configCopy, memberof_get_config());
  365. memberof_unlock_config();
  366. /* get the memberOf operation lock */
  367. memberof_lock();
  368. /* remove this DN from the
  369. * membership lists of groups
  370. */
  371. memberof_del_dn_from_groups(pb, &configCopy, dn, txn);
  372. /* is the entry of interest as a group? */
  373. if(e && configCopy.group_filter && !slapi_filter_test_simple(e, configCopy.group_filter))
  374. {
  375. int i = 0;
  376. Slapi_Attr *attr = 0;
  377. /* Loop through to find each grouping attribute separately. */
  378. for (i = 0; configCopy.groupattrs[i]; i++)
  379. {
  380. if (0 == slapi_entry_attr_find(e, configCopy.groupattrs[i], &attr))
  381. {
  382. memberof_del_attr_list(pb, &configCopy, dn, attr, txn);
  383. }
  384. }
  385. }
  386. memberof_unlock();
  387. memberof_free_config(&configCopy);
  388. }
  389. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  390. "<-- memberof_postop_del\n" );
  391. return ret;
  392. }
  393. typedef struct _memberof_del_dn_data
  394. {
  395. char *dn;
  396. char *type;
  397. void *txn;
  398. } memberof_del_dn_data;
  399. /* Deletes a member dn from all groups that refer to it. */
  400. static void
  401. memberof_del_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config, char *dn, void *txn)
  402. {
  403. int i = 0;
  404. char *groupattrs[2] = {0, 0};
  405. /* Loop through each grouping attribute to find groups that have
  406. * dn as a member. For any matches, delete the dn value from the
  407. * same grouping attribute. */
  408. for (i = 0; config->groupattrs[i]; i++)
  409. {
  410. memberof_del_dn_data data = {dn, config->groupattrs[i], txn};
  411. groupattrs[0] = config->groupattrs[i];
  412. memberof_call_foreach_dn(pb, dn, groupattrs,
  413. memberof_del_dn_type_callback, &data, txn);
  414. }
  415. }
  416. int memberof_del_dn_type_callback(Slapi_Entry *e, void *callback_data)
  417. {
  418. int rc = 0;
  419. LDAPMod mod;
  420. LDAPMod *mods[2];
  421. char *val[2];
  422. Slapi_PBlock *mod_pb = 0;
  423. mod_pb = slapi_pblock_new();
  424. mods[0] = &mod;
  425. mods[1] = 0;
  426. val[0] = ((memberof_del_dn_data *)callback_data)->dn;
  427. val[1] = 0;
  428. mod.mod_op = LDAP_MOD_DELETE;
  429. mod.mod_type = ((memberof_del_dn_data *)callback_data)->type;
  430. mod.mod_values = val;
  431. slapi_modify_internal_set_pb_ext(
  432. mod_pb, slapi_entry_get_sdn(e),
  433. mods, 0, 0,
  434. memberof_get_plugin_id(), 0);
  435. slapi_pblock_set(mod_pb, SLAPI_TXN, ((memberof_del_dn_data *)callback_data)->txn);
  436. slapi_modify_internal_pb(mod_pb);
  437. slapi_pblock_get(mod_pb,
  438. SLAPI_PLUGIN_INTOP_RESULT,
  439. &rc);
  440. slapi_pblock_destroy(mod_pb);
  441. return rc;
  442. }
  443. /*
  444. * Does a callback search of "type=dn" under the db suffix that "dn" is in.
  445. * If "dn" is a user, you'd want "type" to be "member". If "dn" is a group,
  446. * you could want type to be either "member" or "memberOf" depending on the
  447. * case.
  448. */
  449. int memberof_call_foreach_dn(Slapi_PBlock *pb, char *dn,
  450. char **types, plugin_search_entry_callback callback, void *callback_data, void *txn)
  451. {
  452. int rc = 0;
  453. Slapi_PBlock *search_pb = slapi_pblock_new();
  454. Slapi_Backend *be = 0;
  455. Slapi_DN *sdn = 0;
  456. Slapi_DN *base_sdn = 0;
  457. char *filter_str = 0;
  458. int num_types = 0;
  459. int types_name_len = 0;
  460. int dn_len = 0;
  461. int i = 0;
  462. slapi_pblock_set(search_pb, SLAPI_TXN, txn);
  463. /* get the base dn for the backend we are in
  464. (we don't support having members and groups in
  465. different backends - issues with offline / read only backends)
  466. */
  467. sdn = slapi_sdn_new_dn_byref(dn);
  468. be = slapi_be_select(sdn);
  469. if(be)
  470. {
  471. base_sdn = (Slapi_DN*)slapi_be_getsuffix(be,0);
  472. }
  473. if(base_sdn)
  474. {
  475. /* Find the length of the dn */
  476. dn_len = strlen(dn);
  477. /* Count the number of types. */
  478. for (num_types = 0; types && types[num_types]; num_types++)
  479. {
  480. /* Add up the total length of all attribute names.
  481. * We need to know this for building the filter. */
  482. types_name_len += strlen(types[num_types]);
  483. }
  484. /* Build the search filter. */
  485. if (num_types > 1)
  486. {
  487. int bytes_out = 0;
  488. int filter_str_len = types_name_len + (num_types * (3 + dn_len)) + 4;
  489. /* Allocate enough space for the filter */
  490. filter_str = slapi_ch_malloc(filter_str_len);
  491. /* Add beginning of filter. */
  492. bytes_out = snprintf(filter_str, filter_str_len - bytes_out, "(|");
  493. /* Add filter section for each type. */
  494. for (i = 0; types[i]; i++)
  495. {
  496. bytes_out += snprintf(filter_str + bytes_out, filter_str_len - bytes_out,
  497. "(%s=%s)", types[i], dn);
  498. }
  499. /* Add end of filter. */
  500. snprintf(filter_str + bytes_out, filter_str_len - bytes_out, ")");
  501. }
  502. else if (num_types == 1)
  503. {
  504. filter_str = slapi_ch_smprintf("(%s=%s)", types[0], dn);
  505. }
  506. }
  507. if(filter_str)
  508. {
  509. slapi_search_internal_set_pb(search_pb, slapi_sdn_get_dn(base_sdn),
  510. LDAP_SCOPE_SUBTREE, filter_str, 0, 0,
  511. 0, 0,
  512. memberof_get_plugin_id(),
  513. 0);
  514. slapi_search_internal_callback_pb(search_pb,
  515. callback_data,
  516. 0, callback,
  517. 0);
  518. }
  519. slapi_sdn_free(&sdn);
  520. slapi_pblock_destroy(search_pb);
  521. slapi_ch_free_string(&filter_str);
  522. return rc;
  523. }
  524. /*
  525. * memberof_postop_modrdn()
  526. *
  527. * All entries with a memberOf attribute that contains the old group DN get retrieved
  528. * and have the old group DN deleted and the new group DN added to their memberOf attribute
  529. */
  530. int memberof_postop_modrdn(Slapi_PBlock *pb)
  531. {
  532. int ret = 0;
  533. void *caller_id = NULL;
  534. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  535. "--> memberof_postop_modrdn\n" );
  536. /* We don't want to process internal modify
  537. * operations that originate from this plugin. */
  538. slapi_pblock_get(pb, SLAPI_PLUGIN_IDENTITY, &caller_id);
  539. if (caller_id == memberof_get_plugin_id()) {
  540. /* Just return without processing */
  541. return 0;
  542. }
  543. if(memberof_oktodo(pb))
  544. {
  545. MemberOfConfig *mainConfig = 0;
  546. MemberOfConfig configCopy = {0, 0, 0, 0};
  547. struct slapi_entry *pre_e = NULL;
  548. struct slapi_entry *post_e = NULL;
  549. char *pre_dn = 0;
  550. char *post_dn = 0;
  551. void *txn = NULL;
  552. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &pre_e );
  553. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &post_e );
  554. slapi_pblock_get( pb, SLAPI_TXN, &txn );
  555. if(pre_e && post_e)
  556. {
  557. pre_dn = slapi_entry_get_ndn(pre_e);
  558. post_dn = slapi_entry_get_ndn(post_e);
  559. }
  560. /* copy config so it doesn't change out from under us */
  561. memberof_rlock_config();
  562. mainConfig = memberof_get_config();
  563. memberof_copy_config(&configCopy, mainConfig);
  564. memberof_unlock_config();
  565. memberof_lock();
  566. /* update any downstream members */
  567. if(pre_dn && post_dn && configCopy.group_filter &&
  568. !slapi_filter_test_simple(post_e, configCopy.group_filter))
  569. {
  570. int i = 0;
  571. Slapi_Attr *attr = 0;
  572. /* get a list of member attributes present in the group
  573. * entry that is being renamed. */
  574. for (i = 0; configCopy.groupattrs[i]; i++)
  575. {
  576. if(0 == slapi_entry_attr_find(post_e, configCopy.groupattrs[i], &attr))
  577. {
  578. if(memberof_moddn_attr_list(pb, &configCopy, pre_dn, post_dn, attr, txn) != 0){
  579. break;
  580. }
  581. }
  582. }
  583. }
  584. /* It's possible that this is an entry who is a member
  585. * of other group entries. We need to update any member
  586. * attributes to refer to the new name. */
  587. if (pre_dn && post_dn) {
  588. memberof_replace_dn_from_groups(pb, &configCopy, pre_dn, post_dn, txn);
  589. }
  590. memberof_unlock();
  591. memberof_free_config(&configCopy);
  592. }
  593. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  594. "<-- memberof_postop_modrdn\n" );
  595. return ret;
  596. }
  597. typedef struct _replace_dn_data
  598. {
  599. char *pre_dn;
  600. char *post_dn;
  601. char *type;
  602. void *txn;
  603. } replace_dn_data;
  604. /* Finds any groups that have pre_dn as a member and modifies them to
  605. * to use post_dn instead. */
  606. static void
  607. memberof_replace_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config,
  608. char *pre_dn, char *post_dn, void *txn)
  609. {
  610. int i = 0;
  611. char *groupattrs[2] = {0, 0};
  612. /* Loop through each grouping attribute to find groups that have
  613. * pre_dn as a member. For any matches, replace pre_dn with post_dn
  614. * using the same grouping attribute. */
  615. for (i = 0; config->groupattrs[i]; i++)
  616. {
  617. replace_dn_data data = {pre_dn, post_dn, config->groupattrs[i], txn};
  618. groupattrs[0] = config->groupattrs[i];
  619. memberof_call_foreach_dn(pb, pre_dn, groupattrs,
  620. memberof_replace_dn_type_callback, &data, txn);
  621. }
  622. }
  623. int memberof_replace_dn_type_callback(Slapi_Entry *e, void *callback_data)
  624. {
  625. int rc = 0;
  626. LDAPMod delmod;
  627. LDAPMod addmod;
  628. LDAPMod *mods[3];
  629. char *delval[2];
  630. char *addval[2];
  631. Slapi_PBlock *mod_pb = 0;
  632. mod_pb = slapi_pblock_new();
  633. mods[0] = &delmod;
  634. mods[1] = &addmod;
  635. mods[2] = 0;
  636. delval[0] = ((replace_dn_data *)callback_data)->pre_dn;
  637. delval[1] = 0;
  638. delmod.mod_op = LDAP_MOD_DELETE;
  639. delmod.mod_type = ((replace_dn_data *)callback_data)->type;
  640. delmod.mod_values = delval;
  641. addval[0] = ((replace_dn_data *)callback_data)->post_dn;
  642. addval[1] = 0;
  643. addmod.mod_op = LDAP_MOD_ADD;
  644. addmod.mod_type = ((replace_dn_data *)callback_data)->type;
  645. addmod.mod_values = addval;
  646. slapi_modify_internal_set_pb_ext(
  647. mod_pb, slapi_entry_get_sdn(e),
  648. mods, 0, 0,
  649. memberof_get_plugin_id(), 0);
  650. slapi_pblock_set(mod_pb, SLAPI_TXN, ((replace_dn_data *)callback_data)->txn);
  651. slapi_modify_internal_pb(mod_pb);
  652. slapi_pblock_get(mod_pb,
  653. SLAPI_PLUGIN_INTOP_RESULT,
  654. &rc);
  655. slapi_pblock_destroy(mod_pb);
  656. return rc;
  657. }
  658. /*
  659. * memberof_postop_modify()
  660. *
  661. * Added members are retrieved and have the group DN added to their memberOf attribute
  662. * Deleted members are retrieved and have the group DN deleted from their memberOf attribute
  663. * On replace of the membership attribute values:
  664. * 1. Sort old and new values
  665. * 2. Iterate through both lists at same time
  666. * 3. Any value not in old list but in new list - add group DN to memberOf attribute
  667. * 4. Any value in old list but not in new list - remove group DN from memberOf attribute
  668. *
  669. * Note: this will suck for large groups but nonetheless is optimal (it's linear) given
  670. * current restrictions i.e. originally adding members in sorted order would allow
  671. * us to sort one list only (the new one) but that is under server control, not this plugin
  672. */
  673. int memberof_postop_modify(Slapi_PBlock *pb)
  674. {
  675. int ret = 0;
  676. char *dn = 0;
  677. Slapi_Mods *smods = 0;
  678. Slapi_Mod *smod = 0;
  679. LDAPMod **mods;
  680. Slapi_Mod *next_mod = 0;
  681. void *caller_id = NULL;
  682. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  683. "--> memberof_postop_modify\n" );
  684. /* We don't want to process internal modify
  685. * operations that originate from this plugin. */
  686. slapi_pblock_get(pb, SLAPI_PLUGIN_IDENTITY, &caller_id);
  687. if (caller_id == memberof_get_plugin_id()) {
  688. /* Just return without processing */
  689. return 0;
  690. }
  691. if(memberof_oktodo(pb) &&
  692. (dn = memberof_getdn(pb)))
  693. {
  694. int config_copied = 0;
  695. MemberOfConfig *mainConfig = 0;
  696. MemberOfConfig configCopy = {0, 0, 0, 0};
  697. void *txn = NULL;
  698. slapi_pblock_get(pb, SLAPI_TXN, &txn);
  699. /* get the mod set */
  700. slapi_pblock_get(pb, SLAPI_MODIFY_MODS, &mods);
  701. smods = slapi_mods_new();
  702. slapi_mods_init_byref(smods, mods);
  703. next_mod = slapi_mod_new();
  704. smod = slapi_mods_get_first_smod(smods, next_mod);
  705. while(smod)
  706. {
  707. int interested = 0;
  708. char *type = (char *)slapi_mod_get_type(smod);
  709. /* We only want to copy the config if we encounter an
  710. * operation that we need to act on. We also want to
  711. * only copy the config the first time it's needed so
  712. * it remains the same for all mods in the operation,
  713. * despite any config changes that may be made. */
  714. if (!config_copied)
  715. {
  716. memberof_rlock_config();
  717. mainConfig = memberof_get_config();
  718. if (memberof_is_grouping_attr(type, mainConfig))
  719. {
  720. interested = 1;
  721. /* copy config so it doesn't change out from under us */
  722. memberof_copy_config(&configCopy, mainConfig);
  723. config_copied = 1;
  724. }
  725. memberof_unlock_config();
  726. } else {
  727. if (memberof_is_grouping_attr(type, &configCopy))
  728. {
  729. interested = 1;
  730. }
  731. }
  732. if(interested)
  733. {
  734. int op = slapi_mod_get_operation(smod);
  735. memberof_lock();
  736. /* the modify op decides the function */
  737. switch(op & ~LDAP_MOD_BVALUES)
  738. {
  739. case LDAP_MOD_ADD:
  740. {
  741. /* add group DN to targets */
  742. memberof_add_smod_list(pb, &configCopy, dn, smod, txn);
  743. break;
  744. }
  745. case LDAP_MOD_DELETE:
  746. {
  747. /* If there are no values in the smod, we should
  748. * just do a replace instead. The user is just
  749. * trying to delete all members from this group
  750. * entry, which the replace code deals with. */
  751. if (slapi_mod_get_num_values(smod) == 0)
  752. {
  753. memberof_replace_list(pb, &configCopy, dn, txn);
  754. }
  755. else
  756. {
  757. /* remove group DN from target values in smod*/
  758. memberof_del_smod_list(pb, &configCopy, dn, smod, txn);
  759. }
  760. break;
  761. }
  762. case LDAP_MOD_REPLACE:
  763. {
  764. /* replace current values */
  765. memberof_replace_list(pb, &configCopy, dn, txn);
  766. break;
  767. }
  768. default:
  769. {
  770. slapi_log_error(
  771. SLAPI_LOG_PLUGIN,
  772. MEMBEROF_PLUGIN_SUBSYSTEM,
  773. "memberof_postop_modify: unknown mod type\n" );
  774. break;
  775. }
  776. }
  777. memberof_unlock();
  778. }
  779. slapi_mod_done(next_mod);
  780. smod = slapi_mods_get_next_smod(smods, next_mod);
  781. }
  782. if (config_copied)
  783. {
  784. memberof_free_config(&configCopy);
  785. }
  786. slapi_mod_free(&next_mod);
  787. slapi_mods_free(&smods);
  788. }
  789. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  790. "<-- memberof_postop_modify\n" );
  791. return ret;
  792. }
  793. /*
  794. * memberof_postop_add()
  795. *
  796. * All members in the membership attribute of the new entry get retrieved
  797. * and have the group DN added to their memberOf attribute
  798. */
  799. int memberof_postop_add(Slapi_PBlock *pb)
  800. {
  801. int ret = 0;
  802. int interested = 0;
  803. char *dn = 0;
  804. void *caller_id = NULL;
  805. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  806. "--> memberof_postop_add\n" );
  807. /* We don't want to process internal modify
  808. * operations that originate from this plugin. */
  809. slapi_pblock_get(pb, SLAPI_PLUGIN_IDENTITY, &caller_id);
  810. if (caller_id == memberof_get_plugin_id()) {
  811. /* Just return without processing */
  812. return 0;
  813. }
  814. if(memberof_oktodo(pb) && (dn = memberof_getdn(pb)))
  815. {
  816. MemberOfConfig *mainConfig = 0;
  817. MemberOfConfig configCopy = {0, 0, 0, 0};
  818. struct slapi_entry *e = NULL;
  819. void *txn = NULL;
  820. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &e );
  821. slapi_pblock_get( pb, SLAPI_TXN, &txn );
  822. /* is the entry of interest? */
  823. memberof_rlock_config();
  824. mainConfig = memberof_get_config();
  825. if(e && mainConfig && mainConfig->group_filter &&
  826. !slapi_filter_test_simple(e, mainConfig->group_filter))
  827. {
  828. interested = 1;
  829. /* copy config so it doesn't change out from under us */
  830. memberof_copy_config(&configCopy, mainConfig);
  831. }
  832. memberof_unlock_config();
  833. if(interested)
  834. {
  835. int i = 0;
  836. Slapi_Attr *attr = 0;
  837. memberof_lock();
  838. for (i = 0; configCopy.groupattrs[i]; i++)
  839. {
  840. if(0 == slapi_entry_attr_find(e, configCopy.groupattrs[i], &attr))
  841. {
  842. memberof_add_attr_list(pb, &configCopy, dn, attr, txn);
  843. }
  844. }
  845. memberof_unlock();
  846. memberof_free_config(&configCopy);
  847. }
  848. }
  849. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  850. "<-- memberof_postop_add\n" );
  851. return ret;
  852. }
  853. /*** Support functions ***/
  854. /*
  855. * memberof_oktodo()
  856. *
  857. * Check that the op succeeded
  858. * Note: we also respond to replicated ops so we don't test for that
  859. * this does require that the memberOf attribute not be replicated
  860. * and this means that memberof is consistent with local state
  861. * not the network system state
  862. *
  863. */
  864. int memberof_oktodo(Slapi_PBlock *pb)
  865. {
  866. int ret = 1;
  867. int oprc = 0;
  868. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  869. "--> memberof_postop_oktodo\n" );
  870. if (!g_plugin_started) {
  871. ret = 0;
  872. goto bail;
  873. }
  874. if(slapi_pblock_get(pb, SLAPI_PLUGIN_OPRETURN, &oprc) != 0)
  875. {
  876. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  877. "memberof_postop_oktodo: could not get parameters\n" );
  878. ret = -1;
  879. }
  880. /* this plugin should only execute if the operation succeeded
  881. */
  882. if(oprc != 0)
  883. {
  884. ret = 0;
  885. }
  886. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  887. "<-- memberof_postop_oktodo\n" );
  888. bail:
  889. return ret;
  890. }
  891. /*
  892. * memberof_getdn()
  893. *
  894. * Get dn of target entry
  895. *
  896. */
  897. char *memberof_getdn(Slapi_PBlock *pb)
  898. {
  899. const char *dn = 0;
  900. Slapi_DN *sdn = NULL;
  901. slapi_pblock_get(pb, SLAPI_TARGET_SDN, &sdn);
  902. dn = slapi_sdn_get_dn(sdn);
  903. return (char *)dn;
  904. }
  905. /*
  906. * memberof_modop_one()
  907. *
  908. * Perform op on memberof attribute of op_to using op_this as the value
  909. * However, if op_to happens to be a group, we must arrange for the group
  910. * members to have the mod performed on them instead, and we must take
  911. * care to not recurse when we have visted a group before
  912. *
  913. * Also, we must not delete entries that are a member of the group
  914. */
  915. int memberof_modop_one(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  916. char *op_this, char *op_to, void *txn)
  917. {
  918. return memberof_modop_one_r(pb, config, mod_op, op_this, op_this, op_to, 0, txn);
  919. }
  920. /* memberof_modop_one_r()
  921. *
  922. * recursive function to perform above (most things don't need the replace arg)
  923. */
  924. int memberof_modop_one_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  925. char *group_dn, char *op_this, char *op_to, memberofstringll *stack, void *txn)
  926. {
  927. return memberof_modop_one_replace_r(
  928. pb, config, mod_op, group_dn, op_this, 0, op_to, stack, txn);
  929. }
  930. struct fix_memberof_callback_data {
  931. MemberOfConfig *config;
  932. void *txn;
  933. };
  934. /* memberof_modop_one_replace_r()
  935. *
  936. * recursive function to perform above (with added replace arg)
  937. */
  938. int memberof_modop_one_replace_r(Slapi_PBlock *pb, MemberOfConfig *config,
  939. int mod_op, char *group_dn, char *op_this, char *replace_with,
  940. char *op_to, memberofstringll *stack, void *txn)
  941. {
  942. int rc = 0;
  943. LDAPMod mod;
  944. LDAPMod replace_mod;
  945. LDAPMod *mods[3];
  946. char *val[2];
  947. char *replace_val[2];
  948. Slapi_PBlock *mod_pb = 0;
  949. Slapi_DN *op_to_sdn = 0;
  950. Slapi_Entry *e = 0;
  951. memberofstringll *ll = 0;
  952. char *op_str = 0;
  953. Slapi_Value *to_dn_val = slapi_value_new_string(op_to);
  954. Slapi_Value *this_dn_val = slapi_value_new_string(op_this);
  955. if (config == NULL) {
  956. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  957. "memberof_modop_one_replace_r: NULL config parameter");
  958. goto bail;
  959. }
  960. /* determine if this is a group op or single entry */
  961. op_to_sdn = slapi_sdn_new_dn_byref(op_to);
  962. slapi_search_internal_get_entry_ext( op_to_sdn, config->groupattrs,
  963. &e, memberof_get_plugin_id(), txn);
  964. if(!e)
  965. {
  966. /* In the case of a delete, we need to worry about the
  967. * missing entry being a nested group. There's a small
  968. * window where another thread may have deleted a nested
  969. * group that our group_dn entry refers to. This has the
  970. * potential of us missing some indirect member entries
  971. * that need to be updated. */
  972. if(LDAP_MOD_DELETE == mod_op)
  973. {
  974. Slapi_PBlock *search_pb = slapi_pblock_new();
  975. Slapi_DN *base_sdn = 0;
  976. Slapi_Backend *be = 0;
  977. char *filter_str = 0;
  978. int n_entries = 0;
  979. /* We can't tell for sure if the op_to entry is a
  980. * user or a group since the entry doesn't exist
  981. * anymore. We can safely ignore the missing entry
  982. * if no other entries have a memberOf attribute that
  983. * points to the missing entry. */
  984. be = slapi_be_select(op_to_sdn);
  985. if(be)
  986. {
  987. base_sdn = (Slapi_DN*)slapi_be_getsuffix(be,0);
  988. }
  989. if(base_sdn)
  990. {
  991. filter_str = slapi_ch_smprintf("(%s=%s)",
  992. config->memberof_attr, op_to);
  993. }
  994. if(filter_str)
  995. {
  996. slapi_search_internal_set_pb(search_pb, slapi_sdn_get_dn(base_sdn),
  997. LDAP_SCOPE_SUBTREE, filter_str, 0, 0, 0, 0,
  998. memberof_get_plugin_id(), 0);
  999. slapi_pblock_set(search_pb, SLAPI_TXN, txn);
  1000. if (slapi_search_internal_pb(search_pb))
  1001. {
  1002. /* get result and log an error */
  1003. int res = 0;
  1004. slapi_pblock_get(search_pb, SLAPI_PLUGIN_INTOP_RESULT, &res);
  1005. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  1006. "memberof_modop_one_replace_r: error searching for members: "
  1007. "%d", res);
  1008. } else {
  1009. slapi_pblock_get(search_pb, SLAPI_NENTRIES, &n_entries);
  1010. if(n_entries > 0)
  1011. {
  1012. /* We want to fixup the membership for the
  1013. * entries that referred to the missing group
  1014. * entry. This will fix the references to
  1015. * the missing group as well as the group
  1016. * represented by op_this. */
  1017. memberof_test_membership(pb, config, op_to, txn);
  1018. }
  1019. }
  1020. slapi_free_search_results_internal(search_pb);
  1021. slapi_ch_free_string(&filter_str);
  1022. }
  1023. slapi_pblock_destroy(search_pb);
  1024. }
  1025. goto bail;
  1026. }
  1027. if(LDAP_MOD_DELETE == mod_op)
  1028. {
  1029. op_str = "DELETE";
  1030. }
  1031. else if(LDAP_MOD_ADD == mod_op)
  1032. {
  1033. op_str = "ADD";
  1034. }
  1035. else if(LDAP_MOD_REPLACE == mod_op)
  1036. {
  1037. op_str = "REPLACE";
  1038. }
  1039. else
  1040. {
  1041. op_str = "UNKNOWN";
  1042. }
  1043. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1044. "memberof_modop_one_replace_r: %s %s in %s\n"
  1045. ,op_str, op_this, op_to);
  1046. if(config->group_filter && !slapi_filter_test_simple(e, config->group_filter))
  1047. {
  1048. /* group */
  1049. Slapi_Value *ll_dn_val = 0;
  1050. Slapi_Attr *members = 0;
  1051. int i = 0;
  1052. ll = stack;
  1053. /* have we been here before? */
  1054. while(ll)
  1055. {
  1056. ll_dn_val = slapi_value_new_string(ll->dn);
  1057. if(0 == memberof_compare(config, &ll_dn_val, &to_dn_val))
  1058. {
  1059. slapi_value_free(&ll_dn_val);
  1060. /* someone set up infinitely
  1061. recursive groups - bail out */
  1062. slapi_log_error( SLAPI_LOG_PLUGIN,
  1063. MEMBEROF_PLUGIN_SUBSYSTEM,
  1064. "memberof_modop_one_replace_r: group recursion"
  1065. " detected in %s\n"
  1066. ,op_to);
  1067. goto bail;
  1068. }
  1069. slapi_value_free(&ll_dn_val);
  1070. ll = ll->next;
  1071. }
  1072. /* do op on group */
  1073. slapi_log_error( SLAPI_LOG_PLUGIN,
  1074. MEMBEROF_PLUGIN_SUBSYSTEM,
  1075. "memberof_modop_one_replace_r: descending into group %s\n",
  1076. op_to);
  1077. /* Add the nested group's DN to the stack so we can detect loops later. */
  1078. ll = (memberofstringll*)slapi_ch_malloc(sizeof(memberofstringll));
  1079. ll->dn = op_to;
  1080. ll->next = stack;
  1081. /* Go through each grouping attribute one at a time. */
  1082. for (i = 0; config->groupattrs[i]; i++)
  1083. {
  1084. slapi_entry_attr_find( e, config->groupattrs[i], &members );
  1085. if(members)
  1086. {
  1087. if(memberof_mod_attr_list_r(pb, config, mod_op, group_dn, op_this, members, ll, txn) != 0){
  1088. rc = -1;
  1089. goto bail;
  1090. }
  1091. }
  1092. }
  1093. {
  1094. /* crazyness follows:
  1095. * strict-aliasing doesn't like the required cast
  1096. * to void for slapi_ch_free so we are made to
  1097. * juggle to get a normal thing done
  1098. */
  1099. void *pll = ll;
  1100. slapi_ch_free(&pll);
  1101. ll = 0;
  1102. }
  1103. }
  1104. /* continue with operation */
  1105. {
  1106. /* We want to avoid listing a group as a memberOf itself
  1107. * in case someone set up a circular grouping.
  1108. */
  1109. if (0 == memberof_compare(config, &this_dn_val, &to_dn_val))
  1110. {
  1111. const char *strval = "NULL";
  1112. if (this_dn_val) {
  1113. strval = slapi_value_get_string(this_dn_val);
  1114. }
  1115. slapi_log_error( SLAPI_LOG_PLUGIN,
  1116. MEMBEROF_PLUGIN_SUBSYSTEM,
  1117. "memberof_modop_one_replace_r: not processing memberOf "
  1118. "operations on self entry: %s\n", strval);
  1119. goto bail;
  1120. }
  1121. /* For add and del modify operations, we just regenerate the
  1122. * memberOf attribute. */
  1123. if(LDAP_MOD_DELETE == mod_op || LDAP_MOD_ADD == mod_op)
  1124. {
  1125. /* find parent groups and replace our member attr */
  1126. struct fix_memberof_callback_data cb_data = {config, txn};
  1127. memberof_fix_memberof_callback(e, &cb_data);
  1128. } else {
  1129. /* single entry - do mod */
  1130. mod_pb = slapi_pblock_new();
  1131. mods[0] = &mod;
  1132. if(LDAP_MOD_REPLACE == mod_op)
  1133. {
  1134. mods[1] = &replace_mod;
  1135. mods[2] = 0;
  1136. }
  1137. else
  1138. {
  1139. mods[1] = 0;
  1140. }
  1141. val[0] = op_this;
  1142. val[1] = 0;
  1143. mod.mod_op = LDAP_MOD_REPLACE == mod_op?LDAP_MOD_DELETE:mod_op;
  1144. mod.mod_type = config->memberof_attr;
  1145. mod.mod_values = val;
  1146. if(LDAP_MOD_REPLACE == mod_op)
  1147. {
  1148. replace_val[0] = replace_with;
  1149. replace_val[1] = 0;
  1150. replace_mod.mod_op = LDAP_MOD_ADD;
  1151. replace_mod.mod_type = config->memberof_attr;
  1152. replace_mod.mod_values = replace_val;
  1153. }
  1154. slapi_modify_internal_set_pb(
  1155. mod_pb, op_to,
  1156. mods, 0, 0,
  1157. memberof_get_plugin_id(), 0);
  1158. slapi_pblock_set(mod_pb, SLAPI_TXN, txn);
  1159. slapi_modify_internal_pb(mod_pb);
  1160. slapi_pblock_get(mod_pb,
  1161. SLAPI_PLUGIN_INTOP_RESULT,
  1162. &rc);
  1163. slapi_pblock_destroy(mod_pb);
  1164. }
  1165. }
  1166. bail:
  1167. slapi_sdn_free(&op_to_sdn);
  1168. slapi_value_free(&to_dn_val);
  1169. slapi_value_free(&this_dn_val);
  1170. slapi_entry_free(e);
  1171. return rc;
  1172. }
  1173. /*
  1174. * memberof_add_one()
  1175. *
  1176. * Add addthis DN to the memberof attribute of addto
  1177. *
  1178. */
  1179. int memberof_add_one(Slapi_PBlock *pb, MemberOfConfig *config, char *addthis, char *addto, void *txn)
  1180. {
  1181. return memberof_modop_one(pb, config, LDAP_MOD_ADD, addthis, addto, txn);
  1182. }
  1183. /*
  1184. * memberof_del_one()
  1185. *
  1186. * Delete delthis DN from the memberof attribute of delfrom
  1187. *
  1188. */
  1189. int memberof_del_one(Slapi_PBlock *pb, MemberOfConfig *config, char *delthis, char *delfrom, void *txn)
  1190. {
  1191. return memberof_modop_one(pb, config, LDAP_MOD_DELETE, delthis, delfrom, txn);
  1192. }
  1193. /*
  1194. * memberof_mod_smod_list()
  1195. *
  1196. * Perform mod for group DN to the memberof attribute of the list of targets
  1197. *
  1198. */
  1199. int memberof_mod_smod_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  1200. char *group_dn, Slapi_Mod *smod, void *txn)
  1201. {
  1202. int rc = 0;
  1203. struct berval *bv = slapi_mod_get_first_value(smod);
  1204. int last_size = 0;
  1205. char *last_str = 0;
  1206. while(bv)
  1207. {
  1208. char *dn_str = 0;
  1209. if(last_size > bv->bv_len)
  1210. {
  1211. dn_str = last_str;
  1212. }
  1213. else
  1214. {
  1215. int the_size = (bv->bv_len * 2) + 1;
  1216. if(last_str)
  1217. slapi_ch_free_string(&last_str);
  1218. dn_str = (char*)slapi_ch_malloc(the_size);
  1219. last_str = dn_str;
  1220. last_size = the_size;
  1221. }
  1222. memset(dn_str, 0, last_size);
  1223. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1224. memberof_modop_one(pb, config, mod, group_dn, dn_str, txn);
  1225. bv = slapi_mod_get_next_value(smod);
  1226. }
  1227. if(last_str)
  1228. slapi_ch_free_string(&last_str);
  1229. return rc;
  1230. }
  1231. /*
  1232. * memberof_add_smod_list()
  1233. *
  1234. * Add group DN to the memberof attribute of the list of targets
  1235. *
  1236. */
  1237. int memberof_add_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1238. char *groupdn, Slapi_Mod *smod, void *txn)
  1239. {
  1240. return memberof_mod_smod_list(pb, config, LDAP_MOD_ADD, groupdn, smod, txn);
  1241. }
  1242. /*
  1243. * memberof_del_smod_list()
  1244. *
  1245. * Remove group DN from the memberof attribute of the list of targets
  1246. *
  1247. */
  1248. int memberof_del_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1249. char *groupdn, Slapi_Mod *smod, void *txn)
  1250. {
  1251. return memberof_mod_smod_list(pb, config, LDAP_MOD_DELETE, groupdn, smod, txn);
  1252. }
  1253. /**
  1254. * Plugin identity mgmt
  1255. */
  1256. void memberof_set_plugin_id(void * plugin_id)
  1257. {
  1258. _PluginID=plugin_id;
  1259. }
  1260. void * memberof_get_plugin_id()
  1261. {
  1262. return _PluginID;
  1263. }
  1264. /*
  1265. * memberof_mod_attr_list()
  1266. *
  1267. * Perform mod for group DN to the memberof attribute of the list of targets
  1268. *
  1269. */
  1270. int memberof_mod_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  1271. char *group_dn, Slapi_Attr *attr, void *txn)
  1272. {
  1273. return memberof_mod_attr_list_r(pb, config, mod, group_dn, group_dn, attr, 0, txn);
  1274. }
  1275. int memberof_mod_attr_list_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  1276. char *group_dn, char *op_this, Slapi_Attr *attr, memberofstringll *stack, void *txn)
  1277. {
  1278. int rc = 0;
  1279. Slapi_Value *val = 0;
  1280. Slapi_Value *op_this_val = 0;
  1281. int last_size = 0;
  1282. char *last_str = 0;
  1283. int hint = slapi_attr_first_value(attr, &val);
  1284. op_this_val = slapi_value_new_string(op_this);
  1285. while(val)
  1286. {
  1287. char *dn_str = 0;
  1288. struct berval *bv = 0;
  1289. /* We don't want to process a memberOf operation on ourselves. */
  1290. if(0 != memberof_compare(config, &val, &op_this_val))
  1291. {
  1292. bv = (struct berval *)slapi_value_get_berval(val);
  1293. if(last_size > bv->bv_len)
  1294. {
  1295. dn_str = last_str;
  1296. }
  1297. else
  1298. {
  1299. int the_size = (bv->bv_len * 2) + 1;
  1300. if(last_str)
  1301. slapi_ch_free_string(&last_str);
  1302. dn_str = (char*)slapi_ch_malloc(the_size);
  1303. last_str = dn_str;
  1304. last_size = the_size;
  1305. }
  1306. memset(dn_str, 0, last_size);
  1307. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1308. /* If we're doing a replace (as we would in the MODRDN case), we need
  1309. * to specify the new group DN value */
  1310. if(mod == LDAP_MOD_REPLACE)
  1311. {
  1312. memberof_modop_one_replace_r(pb, config, mod, group_dn, op_this,
  1313. group_dn, dn_str, stack, txn);
  1314. }
  1315. else
  1316. {
  1317. memberof_modop_one_r(pb, config, mod, group_dn, op_this, dn_str, stack, txn);
  1318. }
  1319. }
  1320. hint = slapi_attr_next_value(attr, hint, &val);
  1321. }
  1322. slapi_value_free(&op_this_val);
  1323. if(last_str)
  1324. slapi_ch_free_string(&last_str);
  1325. return rc;
  1326. }
  1327. /*
  1328. * memberof_add_attr_list()
  1329. *
  1330. * Add group DN to the memberof attribute of the list of targets
  1331. *
  1332. */
  1333. int memberof_add_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, char *groupdn,
  1334. Slapi_Attr *attr, void *txn)
  1335. {
  1336. return memberof_mod_attr_list(pb, config, LDAP_MOD_ADD, groupdn, attr, txn);
  1337. }
  1338. /*
  1339. * memberof_del_attr_list()
  1340. *
  1341. * Remove group DN from the memberof attribute of the list of targets
  1342. *
  1343. */
  1344. int memberof_del_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, char *groupdn,
  1345. Slapi_Attr *attr, void *txn)
  1346. {
  1347. return memberof_mod_attr_list(pb, config, LDAP_MOD_DELETE, groupdn, attr, txn);
  1348. }
  1349. /*
  1350. * memberof_moddn_attr_list()
  1351. *
  1352. * Perform mod for group DN to the memberof attribute of the list of targets
  1353. *
  1354. */
  1355. int memberof_moddn_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1356. char *pre_dn, char *post_dn, Slapi_Attr *attr, void *txn)
  1357. {
  1358. int rc = 0;
  1359. Slapi_Value *val = 0;
  1360. int last_size = 0;
  1361. char *last_str = 0;
  1362. int hint = slapi_attr_first_value(attr, &val);
  1363. while(val)
  1364. {
  1365. char *dn_str = 0;
  1366. struct berval *bv = (struct berval *)slapi_value_get_berval(val);
  1367. if(last_size > bv->bv_len)
  1368. {
  1369. dn_str = last_str;
  1370. }
  1371. else
  1372. {
  1373. int the_size = (bv->bv_len * 2) + 1;
  1374. if(last_str)
  1375. slapi_ch_free_string(&last_str);
  1376. dn_str = (char*)slapi_ch_malloc(the_size);
  1377. last_str = dn_str;
  1378. last_size = the_size;
  1379. }
  1380. memset(dn_str, 0, last_size);
  1381. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1382. memberof_modop_one_replace_r(pb, config, LDAP_MOD_REPLACE,
  1383. post_dn, pre_dn, post_dn, dn_str, 0, txn);
  1384. hint = slapi_attr_next_value(attr, hint, &val);
  1385. }
  1386. if(last_str)
  1387. slapi_ch_free_string(&last_str);
  1388. return rc;
  1389. }
  1390. /* memberof_get_groups()
  1391. *
  1392. * Gets a list of all groups that an entry is a member of.
  1393. * This is done by looking only at member attribute values.
  1394. * A Slapi_ValueSet* is returned. It is up to the caller to
  1395. * free it.
  1396. */
  1397. Slapi_ValueSet *memberof_get_groups(MemberOfConfig *config, char *memberdn, void *txn)
  1398. {
  1399. Slapi_Value *memberdn_val = slapi_value_new_string(memberdn);
  1400. Slapi_ValueSet *groupvals = slapi_valueset_new();
  1401. memberof_get_groups_data data = {config, memberdn_val, &groupvals, txn};
  1402. memberof_get_groups_r(config, memberdn, &data, txn);
  1403. slapi_value_free(&memberdn_val);
  1404. return groupvals;
  1405. }
  1406. int memberof_get_groups_r(MemberOfConfig *config, char *memberdn, memberof_get_groups_data *data, void *txn)
  1407. {
  1408. /* Search for any grouping attributes that point to memberdn.
  1409. * For each match, add it to the list, recurse and do same search */
  1410. return memberof_call_foreach_dn(NULL, memberdn, config->groupattrs,
  1411. memberof_get_groups_callback, data, txn);
  1412. }
  1413. /* memberof_get_groups_callback()
  1414. *
  1415. * Callback to perform work of memberof_get_groups()
  1416. */
  1417. int memberof_get_groups_callback(Slapi_Entry *e, void *callback_data)
  1418. {
  1419. char *group_dn = slapi_entry_get_dn(e);
  1420. Slapi_Value *group_dn_val = 0;
  1421. Slapi_ValueSet *groupvals = *((memberof_get_groups_data*)callback_data)->groupvals;
  1422. int rc = 0;
  1423. if(g_get_shutdown()){
  1424. rc = -1;
  1425. goto bail;
  1426. }
  1427. if (!groupvals)
  1428. {
  1429. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1430. "memberof_get_groups_callback: NULL groupvals\n");
  1431. rc = -1;
  1432. goto bail;
  1433. }
  1434. /* get the DN of the group */
  1435. group_dn_val = slapi_value_new_string(group_dn);
  1436. /* check if e is the same as our original member entry */
  1437. if (0 == memberof_compare(((memberof_get_groups_data*)callback_data)->config,
  1438. &((memberof_get_groups_data*)callback_data)->memberdn_val, &group_dn_val))
  1439. {
  1440. /* A recursive group caused us to find our original
  1441. * entry we passed to memberof_get_groups(). We just
  1442. * skip processing this entry. */
  1443. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1444. "memberof_get_groups_callback: group recursion"
  1445. " detected in %s\n" ,group_dn);
  1446. slapi_value_free(&group_dn_val);
  1447. goto bail;
  1448. }
  1449. /* Have we been here before? Note that we don't loop through all of the group_slapiattrs
  1450. * in config. We only need this attribute for it's syntax so the comparison can be
  1451. * performed. Since all of the grouping attributes are validated to use the Dinstinguished
  1452. * Name syntax, we can safely just use the first group_slapiattr. */
  1453. if (groupvals && slapi_valueset_find(
  1454. ((memberof_get_groups_data*)callback_data)->config->group_slapiattrs[0], groupvals, group_dn_val))
  1455. {
  1456. /* we either hit a recursive grouping, or an entry is
  1457. * a member of a group through multiple paths. Either
  1458. * way, we can just skip processing this entry since we've
  1459. * already gone through this part of the grouping hierarchy. */
  1460. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1461. "memberof_get_groups_callback: possible group recursion"
  1462. " detected in %s\n" ,group_dn);
  1463. slapi_value_free(&group_dn_val);
  1464. goto bail;
  1465. }
  1466. /* Push group_dn_val into the valueset. This memory is now owned
  1467. * by the valueset. */
  1468. slapi_valueset_add_value_ext(groupvals, group_dn_val, SLAPI_VALUE_FLAG_PASSIN);
  1469. /* now recurse to find parent groups of e */
  1470. memberof_get_groups_r(((memberof_get_groups_data*)callback_data)->config,
  1471. group_dn, callback_data, ((memberof_get_groups_data*)callback_data)->txn);
  1472. bail:
  1473. return rc;
  1474. }
  1475. /* memberof_is_direct_member()
  1476. *
  1477. * tests for direct membership of memberdn in group groupdn
  1478. * returns non-zero when true, zero otherwise
  1479. */
  1480. int memberof_is_direct_member(MemberOfConfig *config, Slapi_Value *groupdn,
  1481. Slapi_Value *memberdn, void *txn)
  1482. {
  1483. int rc = 0;
  1484. Slapi_DN *sdn = 0;
  1485. Slapi_Entry *group_e = 0;
  1486. Slapi_Attr *attr = 0;
  1487. int i = 0;
  1488. sdn = slapi_sdn_new_dn_byref(slapi_value_get_string(groupdn));
  1489. slapi_search_internal_get_entry_ext(sdn, config->groupattrs,
  1490. &group_e, memberof_get_plugin_id(), txn);
  1491. if(group_e)
  1492. {
  1493. /* See if memberdn is referred to by any of the group attributes. */
  1494. for (i = 0; config->groupattrs[i]; i++)
  1495. {
  1496. slapi_entry_attr_find(group_e, config->groupattrs[i], &attr );
  1497. if(attr && (0 == slapi_attr_value_find(attr, slapi_value_get_berval(memberdn))))
  1498. {
  1499. rc = 1;
  1500. break;
  1501. }
  1502. }
  1503. slapi_entry_free(group_e);
  1504. }
  1505. slapi_sdn_free(&sdn);
  1506. return rc;
  1507. }
  1508. /* memberof_is_grouping_attr()
  1509. *
  1510. * Checks if a supplied attribute is one of the configured
  1511. * grouping attributes.
  1512. *
  1513. * Returns non-zero when true, zero otherwise.
  1514. */
  1515. static int memberof_is_grouping_attr(char *type, MemberOfConfig *config)
  1516. {
  1517. int match = 0;
  1518. int i = 0;
  1519. for (i = 0; config && config->groupattrs[i]; i++)
  1520. {
  1521. match = slapi_attr_types_equivalent(type, config->groupattrs[i]);
  1522. if (match)
  1523. {
  1524. /* If we found a match, we're done. */
  1525. break;
  1526. }
  1527. }
  1528. return match;
  1529. }
  1530. struct test_membership_cb_data {
  1531. MemberOfConfig *config;
  1532. void *txn;
  1533. };
  1534. /* memberof_test_membership()
  1535. *
  1536. * Finds all entries who are a "memberOf" the group
  1537. * represented by "group_dn". For each matching entry, we
  1538. * call memberof_test_membership_callback().
  1539. *
  1540. * for each attribute in the memberof attribute
  1541. * determine if the entry is still a member.
  1542. *
  1543. * test each for direct membership
  1544. * move groups entry is memberof to member group
  1545. * test remaining groups for membership in member groups
  1546. * iterate until a pass fails to move a group over to member groups
  1547. * remaining groups should be deleted
  1548. */
  1549. int memberof_test_membership(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn, void *txn)
  1550. {
  1551. char *attrs[2] = {config->memberof_attr, 0};
  1552. struct test_membership_cb_data cb_data = {config, txn};
  1553. return memberof_call_foreach_dn(pb, group_dn, attrs,
  1554. memberof_test_membership_callback , &cb_data, txn);
  1555. }
  1556. /*
  1557. * memberof_test_membership_callback()
  1558. *
  1559. * A callback function to do the work of memberof_test_membership().
  1560. * Note that this not only tests membership, but updates the memberOf
  1561. * attributes in the entry to be correct.
  1562. */
  1563. int memberof_test_membership_callback(Slapi_Entry *e, void *callback_data)
  1564. {
  1565. int rc = 0;
  1566. Slapi_Attr *attr = 0;
  1567. int total = 0;
  1568. Slapi_Value **member_array = 0;
  1569. Slapi_Value **candidate_array = 0;
  1570. Slapi_Value *entry_dn = 0;
  1571. struct test_membership_cb_data *cb_data = (struct test_membership_cb_data *)callback_data;
  1572. MemberOfConfig *config = cb_data->config;
  1573. entry_dn = slapi_value_new_string(slapi_entry_get_dn(e));
  1574. if(0 == entry_dn)
  1575. {
  1576. goto bail;
  1577. }
  1578. /* divide groups into member and non-member lists */
  1579. slapi_entry_attr_find(e, config->memberof_attr, &attr );
  1580. if(attr)
  1581. {
  1582. slapi_attr_get_numvalues( attr, &total);
  1583. if(total)
  1584. {
  1585. Slapi_Value *val = 0;
  1586. int hint = 0;
  1587. int c_index = 0;
  1588. int m_index = 0;
  1589. int member_found = 1;
  1590. int outer_index = 0;
  1591. candidate_array =
  1592. (Slapi_Value**)
  1593. slapi_ch_malloc(sizeof(Slapi_Value*)*total);
  1594. memset(candidate_array, 0, sizeof(Slapi_Value*)*total);
  1595. member_array =
  1596. (Slapi_Value**)
  1597. slapi_ch_malloc(sizeof(Slapi_Value*)*total);
  1598. memset(member_array, 0, sizeof(Slapi_Value*)*total);
  1599. hint = slapi_attr_first_value(attr, &val);
  1600. while(val)
  1601. {
  1602. /* test for direct membership */
  1603. if(memberof_is_direct_member(config, val, entry_dn, cb_data->txn))
  1604. {
  1605. /* it is a member */
  1606. member_array[m_index] = val;
  1607. m_index++;
  1608. }
  1609. else
  1610. {
  1611. /* not a member, still a candidate */
  1612. candidate_array[c_index] = val;
  1613. c_index++;
  1614. }
  1615. hint = slapi_attr_next_value(attr, hint, &val);
  1616. }
  1617. /* now iterate over members testing for membership
  1618. in candidate groups and moving candidates to members
  1619. when successful, quit when a full iteration adds no
  1620. new members
  1621. */
  1622. while(member_found)
  1623. {
  1624. member_found = 0;
  1625. /* For each group that this entry is a verified member of, see if
  1626. * any of the candidate groups are members. If they are, add them
  1627. * to the list of verified groups that this entry is a member of.
  1628. */
  1629. while(outer_index < m_index)
  1630. {
  1631. int inner_index = 0;
  1632. while(inner_index < c_index)
  1633. {
  1634. /* Check for a special value in this position
  1635. * that indicates that the candidate was moved
  1636. * to the member array. */
  1637. if((void*)1 ==
  1638. candidate_array[inner_index])
  1639. {
  1640. /* was moved, skip */
  1641. inner_index++;
  1642. continue;
  1643. }
  1644. if(memberof_is_direct_member(
  1645. config,
  1646. candidate_array[inner_index],
  1647. member_array[outer_index], cb_data->txn))
  1648. {
  1649. member_array[m_index] =
  1650. candidate_array
  1651. [inner_index];
  1652. m_index++;
  1653. candidate_array[inner_index] =
  1654. (void*)1;
  1655. member_found = 1;
  1656. }
  1657. inner_index++;
  1658. }
  1659. outer_index++;
  1660. }
  1661. }
  1662. /* here we are left only with values to delete
  1663. from the memberof attribute in the candidate list
  1664. */
  1665. outer_index = 0;
  1666. while(outer_index < c_index)
  1667. {
  1668. /* Check for a special value in this position
  1669. * that indicates that the candidate was moved
  1670. * to the member array. */
  1671. if((void*)1 == candidate_array[outer_index])
  1672. {
  1673. /* item moved, skip */
  1674. outer_index++;
  1675. continue;
  1676. }
  1677. memberof_del_one(
  1678. 0, config,
  1679. (char*)slapi_value_get_string(
  1680. candidate_array[outer_index]),
  1681. (char*)slapi_value_get_string(entry_dn), cb_data->txn);
  1682. outer_index++;
  1683. }
  1684. {
  1685. /* crazyness follows:
  1686. * strict-aliasing doesn't like the required cast
  1687. * to void for slapi_ch_free so we are made to
  1688. * juggle to get a normal thing done
  1689. */
  1690. void *pmember_array = member_array;
  1691. void *pcandidate_array = candidate_array;
  1692. slapi_ch_free(&pcandidate_array);
  1693. slapi_ch_free(&pmember_array);
  1694. candidate_array = 0;
  1695. member_array = 0;
  1696. }
  1697. }
  1698. }
  1699. bail:
  1700. slapi_value_free(&entry_dn);
  1701. return rc;
  1702. }
  1703. /*
  1704. * memberof_replace_list()
  1705. *
  1706. * Perform replace the group DN list in the memberof attribute of the list of targets
  1707. *
  1708. */
  1709. int memberof_replace_list(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn, void *txn)
  1710. {
  1711. struct slapi_entry *pre_e = NULL;
  1712. struct slapi_entry *post_e = NULL;
  1713. Slapi_Attr *pre_attr = 0;
  1714. Slapi_Attr *post_attr = 0;
  1715. int i = 0;
  1716. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &pre_e );
  1717. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &post_e );
  1718. for (i = 0; config && config->groupattrs[i]; i++)
  1719. {
  1720. if(pre_e && post_e)
  1721. {
  1722. slapi_entry_attr_find( pre_e, config->groupattrs[i], &pre_attr );
  1723. slapi_entry_attr_find( post_e, config->groupattrs[i], &post_attr );
  1724. }
  1725. if(pre_attr || post_attr)
  1726. {
  1727. int pre_total = 0;
  1728. int post_total = 0;
  1729. Slapi_Value **pre_array = 0;
  1730. Slapi_Value **post_array = 0;
  1731. int pre_index = 0;
  1732. int post_index = 0;
  1733. /* create arrays of values */
  1734. if(pre_attr)
  1735. {
  1736. slapi_attr_get_numvalues( pre_attr, &pre_total);
  1737. }
  1738. if(post_attr)
  1739. {
  1740. slapi_attr_get_numvalues( post_attr, &post_total);
  1741. }
  1742. /* Stash a plugin global pointer here and have memberof_qsort_compare
  1743. * use it. We have to do this because we use memberof_qsort_compare
  1744. * as the comparator function for qsort, which requires the function
  1745. * to only take two void* args. This is thread-safe since we only
  1746. * store and use the pointer while holding the memberOf operation
  1747. * lock. */
  1748. qsortConfig = config;
  1749. if(pre_total)
  1750. {
  1751. pre_array =
  1752. (Slapi_Value**)
  1753. slapi_ch_malloc(sizeof(Slapi_Value*)*pre_total);
  1754. memberof_load_array(pre_array, pre_attr);
  1755. qsort(
  1756. pre_array,
  1757. pre_total,
  1758. sizeof(Slapi_Value*),
  1759. memberof_qsort_compare);
  1760. }
  1761. if(post_total)
  1762. {
  1763. post_array =
  1764. (Slapi_Value**)
  1765. slapi_ch_malloc(sizeof(Slapi_Value*)*post_total);
  1766. memberof_load_array(post_array, post_attr);
  1767. qsort(
  1768. post_array,
  1769. post_total,
  1770. sizeof(Slapi_Value*),
  1771. memberof_qsort_compare);
  1772. }
  1773. qsortConfig = 0;
  1774. /* work through arrays, following these rules:
  1775. in pre, in post, do nothing
  1776. in pre, not in post, delete from entry
  1777. not in pre, in post, add to entry
  1778. */
  1779. while(pre_index < pre_total || post_index < post_total)
  1780. {
  1781. if(pre_index == pre_total)
  1782. {
  1783. /* add the rest of post */
  1784. memberof_add_one(
  1785. pb, config,
  1786. group_dn,
  1787. (char*)slapi_value_get_string(
  1788. post_array[post_index]), txn);
  1789. post_index++;
  1790. }
  1791. else if(post_index == post_total)
  1792. {
  1793. /* delete the rest of pre */
  1794. memberof_del_one(
  1795. pb, config,
  1796. group_dn,
  1797. (char*)slapi_value_get_string(
  1798. pre_array[pre_index]), txn);
  1799. pre_index++;
  1800. }
  1801. else
  1802. {
  1803. /* decide what to do */
  1804. int cmp = memberof_compare(
  1805. config,
  1806. &(pre_array[pre_index]),
  1807. &(post_array[post_index]));
  1808. if(cmp < 0)
  1809. {
  1810. /* delete pre array */
  1811. memberof_del_one(
  1812. pb, config,
  1813. group_dn,
  1814. (char*)slapi_value_get_string(
  1815. pre_array[pre_index]), txn);
  1816. pre_index++;
  1817. }
  1818. else if(cmp > 0)
  1819. {
  1820. /* add post array */
  1821. memberof_add_one(
  1822. pb, config,
  1823. group_dn,
  1824. (char*)slapi_value_get_string(
  1825. post_array[post_index]), txn);
  1826. post_index++;
  1827. }
  1828. else
  1829. {
  1830. /* do nothing, advance */
  1831. pre_index++;
  1832. post_index++;
  1833. }
  1834. }
  1835. }
  1836. slapi_ch_free((void **)&pre_array);
  1837. slapi_ch_free((void **)&post_array);
  1838. }
  1839. }
  1840. return 0;
  1841. }
  1842. /* memberof_load_array()
  1843. *
  1844. * put attribute values in array structure
  1845. */
  1846. void memberof_load_array(Slapi_Value **array, Slapi_Attr *attr)
  1847. {
  1848. Slapi_Value *val = 0;
  1849. int hint = slapi_attr_first_value(attr, &val);
  1850. while(val)
  1851. {
  1852. *array = val;
  1853. array++;
  1854. hint = slapi_attr_next_value(attr, hint, &val);
  1855. }
  1856. }
  1857. /* memberof_compare()
  1858. *
  1859. * compare two attr values
  1860. */
  1861. int memberof_compare(MemberOfConfig *config, const void *a, const void *b)
  1862. {
  1863. Slapi_Value *val1 = *((Slapi_Value **)a);
  1864. Slapi_Value *val2 = *((Slapi_Value **)b);
  1865. /* We only need to provide a Slapi_Attr here for it's syntax. We
  1866. * already validated all grouping attributes to use the Distinguished
  1867. * Name syntax, so we can safely just use the first attr. */
  1868. return slapi_attr_value_cmp(
  1869. config->group_slapiattrs[0],
  1870. slapi_value_get_berval(val1),
  1871. slapi_value_get_berval(val2));
  1872. }
  1873. /* memberof_qsort_compare()
  1874. *
  1875. * This is a version of memberof_compare that uses a plugin
  1876. * global copy of the config. We'd prefer to pass in a copy
  1877. * of config that is local to the running thread, but we can't
  1878. * do this since qsort is using us as a comparator function.
  1879. * We should only use this function when using qsort, and only
  1880. * when the memberOf lock is acquired.
  1881. */
  1882. int memberof_qsort_compare(const void *a, const void *b)
  1883. {
  1884. Slapi_Value *val1 = *((Slapi_Value **)a);
  1885. Slapi_Value *val2 = *((Slapi_Value **)b);
  1886. /* We only need to provide a Slapi_Attr here for it's syntax. We
  1887. * already validated all grouping attributes to use the Distinguished
  1888. * Name syntax, so we can safely just use the first attr. */
  1889. return slapi_attr_value_cmp(
  1890. qsortConfig->group_slapiattrs[0],
  1891. slapi_value_get_berval(val1),
  1892. slapi_value_get_berval(val2));
  1893. }
  1894. void memberof_lock()
  1895. {
  1896. PR_EnterMonitor(memberof_operation_lock);
  1897. }
  1898. void memberof_unlock()
  1899. {
  1900. PR_ExitMonitor(memberof_operation_lock);
  1901. }
  1902. typedef struct _task_data
  1903. {
  1904. char *dn;
  1905. char *filter_str;
  1906. } task_data;
  1907. void memberof_fixup_task_thread(void *arg)
  1908. {
  1909. MemberOfConfig configCopy = {0, 0, 0, 0};
  1910. Slapi_Task *task = (Slapi_Task *)arg;
  1911. task_data *td = NULL;
  1912. int rc = 0;
  1913. /* Fetch our task data from the task */
  1914. td = (task_data *)slapi_task_get_data(task);
  1915. slapi_task_begin(task, 1);
  1916. slapi_task_log_notice(task, "Memberof task starts (arg: %s) ...\n",
  1917. td->filter_str);
  1918. /* We need to get the config lock first. Trying to get the
  1919. * config lock after we already hold the op lock can cause
  1920. * a deadlock. */
  1921. memberof_rlock_config();
  1922. /* copy config so it doesn't change out from under us */
  1923. memberof_copy_config(&configCopy, memberof_get_config());
  1924. memberof_unlock_config();
  1925. /* get the memberOf operation lock */
  1926. memberof_lock();
  1927. /* do real work */
  1928. rc = memberof_fix_memberof(&configCopy, td->dn, td->filter_str, NULL /* no txn? */);
  1929. /* release the memberOf operation lock */
  1930. memberof_unlock();
  1931. memberof_free_config(&configCopy);
  1932. slapi_task_log_notice(task, "Memberof task finished.");
  1933. slapi_task_log_status(task, "Memberof task finished.");
  1934. slapi_task_inc_progress(task);
  1935. /* this will queue the destruction of the task */
  1936. slapi_task_finish(task, rc);
  1937. }
  1938. /* extract a single value from the entry (as a string) -- if it's not in the
  1939. * entry, the default will be returned (which can be NULL).
  1940. * you do not need to free anything returned by this.
  1941. */
  1942. const char *fetch_attr(Slapi_Entry *e, const char *attrname,
  1943. const char *default_val)
  1944. {
  1945. Slapi_Attr *attr;
  1946. Slapi_Value *val = NULL;
  1947. if (slapi_entry_attr_find(e, attrname, &attr) != 0)
  1948. return default_val;
  1949. slapi_attr_first_value(attr, &val);
  1950. return slapi_value_get_string(val);
  1951. }
  1952. int memberof_task_add(Slapi_PBlock *pb, Slapi_Entry *e,
  1953. Slapi_Entry *eAfter, int *returncode, char *returntext,
  1954. void *arg)
  1955. {
  1956. PRThread *thread = NULL;
  1957. int rv = SLAPI_DSE_CALLBACK_OK;
  1958. task_data *mytaskdata = NULL;
  1959. Slapi_Task *task = NULL;
  1960. const char *filter;
  1961. const char *dn = 0;
  1962. *returncode = LDAP_SUCCESS;
  1963. /* get arg(s) */
  1964. if ((dn = fetch_attr(e, "basedn", 0)) == NULL)
  1965. {
  1966. *returncode = LDAP_OBJECT_CLASS_VIOLATION;
  1967. rv = SLAPI_DSE_CALLBACK_ERROR;
  1968. goto out;
  1969. }
  1970. if ((filter = fetch_attr(e, "filter", "(objectclass=inetuser)")) == NULL)
  1971. {
  1972. *returncode = LDAP_OBJECT_CLASS_VIOLATION;
  1973. rv = SLAPI_DSE_CALLBACK_ERROR;
  1974. goto out;
  1975. }
  1976. /* setup our task data */
  1977. mytaskdata = (task_data*)slapi_ch_malloc(sizeof(task_data));
  1978. if (mytaskdata == NULL)
  1979. {
  1980. *returncode = LDAP_OPERATIONS_ERROR;
  1981. rv = SLAPI_DSE_CALLBACK_ERROR;
  1982. goto out;
  1983. }
  1984. mytaskdata->dn = slapi_ch_strdup(dn);
  1985. mytaskdata->filter_str = slapi_ch_strdup(filter);
  1986. /* allocate new task now */
  1987. task = slapi_new_task(slapi_entry_get_ndn(e));
  1988. /* register our destructor for cleaning up our private data */
  1989. slapi_task_set_destructor_fn(task, memberof_task_destructor);
  1990. /* Stash a pointer to our data in the task */
  1991. slapi_task_set_data(task, mytaskdata);
  1992. /* start the sample task as a separate thread */
  1993. thread = PR_CreateThread(PR_USER_THREAD, memberof_fixup_task_thread,
  1994. (void *)task, PR_PRIORITY_NORMAL, PR_GLOBAL_THREAD,
  1995. PR_UNJOINABLE_THREAD, SLAPD_DEFAULT_THREAD_STACKSIZE);
  1996. if (thread == NULL)
  1997. {
  1998. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  1999. "unable to create task thread!\n");
  2000. *returncode = LDAP_OPERATIONS_ERROR;
  2001. rv = SLAPI_DSE_CALLBACK_ERROR;
  2002. slapi_task_finish(task, *returncode);
  2003. } else {
  2004. rv = SLAPI_DSE_CALLBACK_OK;
  2005. }
  2006. out:
  2007. return rv;
  2008. }
  2009. void
  2010. memberof_task_destructor(Slapi_Task *task)
  2011. {
  2012. if (task) {
  2013. task_data *mydata = (task_data *)slapi_task_get_data(task);
  2014. if (mydata) {
  2015. slapi_ch_free_string(&mydata->dn);
  2016. slapi_ch_free_string(&mydata->filter_str);
  2017. /* Need to cast to avoid a compiler warning */
  2018. slapi_ch_free((void **)&mydata);
  2019. }
  2020. }
  2021. }
  2022. int memberof_fix_memberof(MemberOfConfig *config, char *dn, char *filter_str, void *txn)
  2023. {
  2024. int rc = 0;
  2025. struct fix_memberof_callback_data cb_data = {config, txn};
  2026. Slapi_PBlock *search_pb = slapi_pblock_new();
  2027. slapi_search_internal_set_pb(search_pb, dn,
  2028. LDAP_SCOPE_SUBTREE, filter_str, 0, 0,
  2029. 0, 0,
  2030. memberof_get_plugin_id(),
  2031. 0);
  2032. slapi_pblock_set(search_pb, SLAPI_TXN, txn);
  2033. rc = slapi_search_internal_callback_pb(search_pb,
  2034. &cb_data,
  2035. 0, memberof_fix_memberof_callback,
  2036. 0);
  2037. slapi_pblock_destroy(search_pb);
  2038. return rc;
  2039. }
  2040. /* memberof_fix_memberof_callback()
  2041. * Add initial and/or fix up broken group list in entry
  2042. *
  2043. * 1. Remove all present memberOf values
  2044. * 2. Add direct group membership memberOf values
  2045. * 3. Add indirect group membership memberOf values
  2046. */
  2047. int memberof_fix_memberof_callback(Slapi_Entry *e, void *callback_data)
  2048. {
  2049. int rc = 0;
  2050. char *dn = slapi_entry_get_dn(e);
  2051. Slapi_DN *sdn = slapi_entry_get_sdn(e);
  2052. struct fix_memberof_callback_data *cb_data = (struct fix_memberof_callback_data *)callback_data;
  2053. MemberOfConfig *config = cb_data->config;
  2054. memberof_del_dn_data del_data = {0, config->memberof_attr, cb_data->txn};
  2055. Slapi_ValueSet *groups = 0;
  2056. /* get a list of all of the groups this user belongs to */
  2057. groups = memberof_get_groups(config, dn, cb_data->txn);
  2058. /* If we found some groups, replace the existing memberOf attribute
  2059. * with the found values. */
  2060. if (groups && slapi_valueset_count(groups))
  2061. {
  2062. Slapi_PBlock *mod_pb = slapi_pblock_new();
  2063. Slapi_Value *val = 0;
  2064. Slapi_Mod *smod;
  2065. LDAPMod **mods = (LDAPMod **) slapi_ch_malloc(2 * sizeof(LDAPMod *));
  2066. int hint = 0;
  2067. smod = slapi_mod_new();
  2068. slapi_mod_init(smod, 0);
  2069. slapi_mod_set_operation(smod, LDAP_MOD_REPLACE | LDAP_MOD_BVALUES);
  2070. slapi_mod_set_type(smod, config->memberof_attr);
  2071. /* Loop through all of our values and add them to smod */
  2072. hint = slapi_valueset_first_value(groups, &val);
  2073. while (val)
  2074. {
  2075. /* this makes a copy of the berval */
  2076. slapi_mod_add_value(smod, slapi_value_get_berval(val));
  2077. hint = slapi_valueset_next_value(groups, hint, &val);
  2078. }
  2079. mods[0] = slapi_mod_get_ldapmod_passout(smod);
  2080. mods[1] = 0;
  2081. slapi_modify_internal_set_pb_ext(
  2082. mod_pb, sdn, mods, 0, 0,
  2083. memberof_get_plugin_id(), 0);
  2084. slapi_pblock_set(mod_pb, SLAPI_TXN, cb_data->txn);
  2085. slapi_modify_internal_pb(mod_pb);
  2086. slapi_pblock_get(mod_pb, SLAPI_PLUGIN_INTOP_RESULT, &rc);
  2087. ldap_mods_free(mods, 1);
  2088. slapi_mod_free(&smod);
  2089. slapi_pblock_destroy(mod_pb);
  2090. } else {
  2091. /* No groups were found, so remove the memberOf attribute
  2092. * from this entry. */
  2093. memberof_del_dn_type_callback(e, &del_data);
  2094. }
  2095. slapi_valueset_free(groups);
  2096. return rc;
  2097. }