posix-group-func.c 39 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026
  1. /** Author: Carsten Grzemba [email protected]>
  2. *
  3. * Copyright (C) 2011 contac Datentechnik GmbH
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License as
  7. * published by the Free Software Foundation; version 2 only
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program; if not, write to the Free Software
  16. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  17. $Id: posix-group-func.c 28 2011-05-13 14:35:29Z grzemba $
  18. */
  19. #include <string.h>
  20. #include "posix-wsp-ident.h"
  21. #include "posix-group-func.h"
  22. #include "slapi-plugin.h"
  23. #define MAX_RECURSION_DEPTH (5)
  24. Slapi_Value **
  25. valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
  26. static PRMonitor *memberuid_operation_lock = 0;
  27. void
  28. memberUidLock()
  29. {
  30. PR_EnterMonitor(memberuid_operation_lock);
  31. }
  32. void
  33. memberUidUnlock()
  34. {
  35. PR_ExitMonitor(memberuid_operation_lock);
  36. }
  37. int
  38. memberUidLockInit()
  39. {
  40. return (memberuid_operation_lock = PR_NewMonitor()) != NULL;
  41. }
  42. void
  43. memberUidLockDestroy()
  44. {
  45. PR_DestroyMonitor(memberuid_operation_lock);
  46. memberuid_operation_lock = NULL;
  47. }
  48. void
  49. addDynamicGroupIfNecessary(Slapi_Entry *entry, Slapi_Mods *smods) {
  50. Slapi_Attr *oc_attr = NULL;
  51. Slapi_Value *voc = slapi_value_new();
  52. slapi_value_init_string(voc, "dynamicGroup");
  53. slapi_entry_attr_find(entry, "objectClass", &oc_attr);
  54. if (slapi_attr_value_find(oc_attr, slapi_value_get_berval(voc)) != 0) {
  55. if (smods) {
  56. slapi_mods_add_string(smods, LDAP_MOD_ADD, "objectClass", "dynamicGroup");
  57. } else {
  58. slapi_entry_add_string(entry, "objectClass", "dynamicGroup");
  59. }
  60. }
  61. slapi_value_free(&voc);
  62. }
  63. Slapi_Entry *
  64. getEntry(const char *udn, char **attrs)
  65. {
  66. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "getEntry: search %s\n", udn);
  67. Slapi_DN *udn_sdn = slapi_sdn_new_dn_byval(udn);
  68. Slapi_Entry *result = NULL;
  69. int rc = slapi_search_internal_get_entry(udn_sdn, attrs, &result, posix_winsync_get_plugin_identity());
  70. slapi_sdn_free(&udn_sdn);
  71. if (rc == 0) {
  72. if (result != NULL) {
  73. return result; /* Must be freed */
  74. }
  75. else {
  76. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  77. "getEntry: %s not found\n", udn);
  78. }
  79. }
  80. else {
  81. slapi_log_err(SLAPI_LOG_ERR, POSIX_WINSYNC_PLUGIN_NAME,
  82. "getEntry: error searching for uid %s: %d\n", udn, rc);
  83. }
  84. return NULL;
  85. }
  86. /* search the user with DN udn and returns uid*/
  87. char *
  88. searchUid(const char *udn)
  89. {
  90. char *attrs[] = { "uid", "objectclass", NULL };
  91. Slapi_Entry *entry = getEntry(udn,
  92. /* "(|(objectclass=posixAccount)(objectclass=ldapsubentry))", */
  93. attrs);
  94. char *uid = NULL;
  95. if (entry) {
  96. Slapi_Attr *attr = NULL;
  97. Slapi_Value *v = NULL;
  98. if (slapi_entry_attr_find(entry, "uid", &attr) == 0 && hasObjectClass(entry, "posixAccount")) {
  99. slapi_attr_first_value(attr, &v);
  100. uid = slapi_ch_strdup(slapi_value_get_string(v));
  101. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  102. "searchUid: return uid %s\n", uid);
  103. } else {
  104. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  105. "searchUid: uid in %s not found\n", udn);
  106. }
  107. if (uid && posix_winsync_config_get_lowercase()) {
  108. uid = slapi_dn_ignore_case(uid);
  109. }
  110. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  111. "searchUid: About to free entry (%s)\n", udn);
  112. slapi_entry_free(entry);
  113. }
  114. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  115. "searchUid(%s): <==\n", udn);
  116. return uid;
  117. }
  118. int
  119. dn_in_set(const char* uid, char **uids)
  120. {
  121. int i;
  122. Slapi_DN *sdn_uid = NULL;
  123. Slapi_DN *sdn_ul = NULL;
  124. if (uids == NULL || uid == NULL)
  125. return false;
  126. sdn_uid = slapi_sdn_new_dn_byval(uid);
  127. sdn_ul = slapi_sdn_new();
  128. for (i = 0; uids[i]; i++) {
  129. slapi_sdn_set_dn_byref(sdn_ul, uids[i]);
  130. if (slapi_sdn_compare(sdn_uid, sdn_ul) == 0) {
  131. slapi_sdn_free(&sdn_ul);
  132. slapi_sdn_free(&sdn_uid);
  133. return true;
  134. }
  135. slapi_sdn_done(sdn_ul);
  136. }
  137. slapi_sdn_free(&sdn_ul);
  138. slapi_sdn_free(&sdn_uid);
  139. return false;
  140. }
  141. int
  142. uid_in_set(const char* uid, char **uids)
  143. {
  144. int i;
  145. if (uid == NULL)
  146. return false;
  147. for (i = 0; uids != NULL && uids[i] != NULL; i++) {
  148. Slapi_RDN *i_rdn = NULL;
  149. char *i_uid = NULL;
  150. char *t = NULL;
  151. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_set: comp %s %s \n",
  152. uid, uids[i]);
  153. i_rdn = slapi_rdn_new_dn(uids[i]);
  154. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  155. if (strncasecmp(uid, i_uid, 256) == 0) {
  156. slapi_rdn_free(&i_rdn);
  157. return true;
  158. }
  159. }
  160. slapi_rdn_free(&i_rdn);
  161. }
  162. return false;
  163. }
  164. int
  165. uid_in_valueset(const char* uid, Slapi_ValueSet *uids)
  166. {
  167. int i;
  168. Slapi_Value *v = NULL;
  169. if (uid == NULL)
  170. return false;
  171. for (i = slapi_valueset_first_value(uids, &v); i != -1;
  172. i = slapi_valueset_next_value(uids, i, &v)) {
  173. Slapi_RDN *i_rdn = NULL;
  174. char *i_uid = NULL;
  175. char *t = NULL;
  176. const char *uid_i = slapi_value_get_string(v);
  177. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_valueset: comp %s %s \n",
  178. uid, uid_i);
  179. i_rdn = slapi_rdn_new_dn(uid_i);
  180. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  181. if (strncasecmp(uid, i_uid, 256) == 0) {
  182. slapi_rdn_free(&i_rdn);
  183. return true;
  184. }
  185. }
  186. slapi_rdn_free(&i_rdn);
  187. }
  188. return false;
  189. }
  190. /* return 1 if smods already has the given mod - 0 otherwise */
  191. static int
  192. smods_has_mod(Slapi_Mods *smods, int modtype, const char *type, const char *val)
  193. {
  194. int rc = 0;
  195. Slapi_Mod *smod = slapi_mod_new(), *smodp = NULL;
  196. for (smodp = slapi_mods_get_first_smod(smods, smod);
  197. (rc == 0) && smods && (smodp != NULL);
  198. smodp = slapi_mods_get_next_smod(smods, smod)) {
  199. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), type)
  200. && ((slapi_mod_get_operation(smod) | LDAP_MOD_BVALUES) == (modtype | LDAP_MOD_BVALUES))) {
  201. /* type and op are equal - see if val is in the mod's list of values */
  202. Slapi_Value *sval = slapi_value_new_string((char *) val);
  203. Slapi_Attr *attr = slapi_attr_new();
  204. struct berval *bvp = NULL;
  205. slapi_attr_init(attr, type);
  206. for (bvp = slapi_mod_get_first_value(smodp); (rc == 0) && (bvp != NULL);
  207. bvp = slapi_mod_get_next_value(smodp)) {
  208. Slapi_Value *modval = slapi_value_new_berval(bvp);
  209. rc = (slapi_value_compare(attr, sval, modval) == 0);
  210. slapi_value_free(&modval);
  211. }
  212. slapi_value_free(&sval);
  213. slapi_attr_free(&attr);
  214. }
  215. }
  216. slapi_mod_free(&smod);
  217. return rc;
  218. }
  219. int
  220. hasObjectClass(Slapi_Entry *entry, const char *objectClass)
  221. {
  222. int rc = 0;
  223. int i;
  224. Slapi_Attr *obj_attr = NULL;
  225. Slapi_Value *value = NULL;
  226. rc = slapi_entry_attr_find(entry, "objectclass", &obj_attr);
  227. if (rc != 0) {
  228. return 0; /* Doesn't have any objectclasses */
  229. }
  230. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  231. "Scanning objectclasses\n");
  232. for (
  233. i = slapi_attr_first_value(obj_attr, &value);
  234. i != -1;
  235. i = slapi_attr_next_value(obj_attr, i, &value)
  236. ) {
  237. const char *oc = NULL;
  238. oc = slapi_value_get_string(value);
  239. if (strcasecmp(oc, objectClass) == 0) {
  240. return 1; /* Entry has the desired objectclass */
  241. }
  242. }
  243. return 0; /* Doesn't have desired objectclass */
  244. }
  245. void
  246. posix_winsync_foreach_parent(Slapi_Entry *entry, char **attrs, plugin_search_entry_callback callback, void *callback_data)
  247. {
  248. char *cookie = NULL;
  249. Slapi_Backend *be = NULL;
  250. char *value = slapi_entry_get_ndn(entry);
  251. size_t vallen = value ? strlen(value) : 0;
  252. char *filter_escaped_value = slapi_escape_filter_value(value, vallen);
  253. char *filter = slapi_ch_smprintf("(uniqueMember=%s)", filter_escaped_value);
  254. slapi_ch_free_string(&filter_escaped_value);
  255. Slapi_PBlock *search_pb = slapi_pblock_new();
  256. for (be = slapi_get_first_backend(&cookie); be;
  257. be = slapi_get_next_backend(cookie)) {
  258. const Slapi_DN *base_sdn = slapi_be_getsuffix(be, 0);
  259. if (base_sdn == NULL) {
  260. continue;
  261. }
  262. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  263. "posix_winsync_foreach_parent: Searching subtree %s for %s\n",
  264. slapi_sdn_get_dn(base_sdn),
  265. filter);
  266. slapi_search_internal_set_pb(search_pb,
  267. slapi_sdn_get_dn(base_sdn),
  268. LDAP_SCOPE_SUBTREE,
  269. filter,
  270. attrs, 0, NULL, NULL,
  271. posix_winsync_get_plugin_identity(), 0);
  272. slapi_search_internal_callback_pb(search_pb, callback_data, 0, callback, 0);
  273. slapi_pblock_init(search_pb);
  274. }
  275. slapi_pblock_destroy(search_pb);
  276. slapi_ch_free((void**)&cookie);
  277. slapi_ch_free_string(&filter);
  278. }
  279. /* Retrieve nested membership from chains of groups.
  280. * Muid_vs in => any preexisting membership list
  281. * out => the union of the input list and the total membership
  282. * Muid_nested_vs out => the members of muid_vs "out" that weren't in muid_vs "in"
  283. * deletions in => Any elements to NOT consider if members of base_sdn
  284. */
  285. void
  286. getMembershipFromDownward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, Slapi_ValueSet *muid_nested_vs, Slapi_ValueSet *deletions, const Slapi_DN *base_sdn, int depth)
  287. {
  288. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  289. "getMembershipFromDownward: ==>\n");
  290. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  291. "getMembershipFromDownward: entry name: %s\n",
  292. slapi_entry_get_dn_const(entry));
  293. int rc = 0;
  294. Slapi_Attr *um_attr = NULL; /* Entry attributes uniqueMember */
  295. Slapi_Value *uid_value = NULL; /* uniqueMember attribute values */
  296. if (depth >= MAX_RECURSION_DEPTH) {
  297. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  298. "getMembershipFromDownward: recursion limit reached: %d\n", depth);
  299. return;
  300. }
  301. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  302. if (rc != 0 || um_attr == NULL) {
  303. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  304. "getMembershipFromDownward end: attribute uniquemember not found\n");
  305. return;
  306. }
  307. int i;
  308. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  309. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  310. char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
  311. const char *uid_dn = slapi_value_get_string(uid_value);
  312. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  313. "getMembershipFromDownward: iterating uniqueMember: %s\n",
  314. uid_dn);
  315. if (deletions && !slapi_sdn_compare(slapi_entry_get_sdn_const(entry), base_sdn)) {
  316. if (slapi_valueset_find(um_attr, deletions, uid_value)) {
  317. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  318. "getMembershipFromDownward: Skipping iteration because of deletion\n");
  319. continue;
  320. }
  321. }
  322. Slapi_Entry *child = getEntry(uid_dn, attrs);
  323. if (!child) {
  324. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  325. "getMembershipFromDownward end: child not found: %s\n", uid_dn);
  326. }
  327. else {
  328. /* PosixGroups except for the top one are already fully mapped out */
  329. if ((!hasObjectClass(entry, "posixGroup") || (depth == 0)) &&
  330. (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup"))) {
  331. /* Recurse downward */
  332. getMembershipFromDownward(child, muid_vs, muid_nested_vs, deletions, base_sdn, depth + 1);
  333. }
  334. if (hasObjectClass(child, "posixAccount")) {
  335. Slapi_Attr *uid_attr = NULL;
  336. Slapi_Value *v = NULL;
  337. if (slapi_entry_attr_find(child, "uid", &uid_attr) == 0) {
  338. slapi_attr_first_value(uid_attr, &v);
  339. if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {
  340. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  341. "getMembershipFromDownward: adding member: %s\n",
  342. slapi_value_get_string(v));
  343. slapi_valueset_add_value(muid_vs, v);
  344. slapi_valueset_add_value(muid_nested_vs, v);
  345. }
  346. }
  347. } else if (hasObjectClass(child, "posixGroup")) {
  348. Slapi_Attr *uid_attr = NULL;
  349. Slapi_Value *v = NULL;
  350. if (slapi_entry_attr_find(child, "memberuid", &uid_attr) == 0) {
  351. slapi_attr_first_value(uid_attr, &v);
  352. if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {
  353. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  354. "getMembershipFromDownward: adding member: %s\n",
  355. slapi_value_get_string(v));
  356. slapi_valueset_add_value(muid_vs, v);
  357. slapi_valueset_add_value(muid_nested_vs, v);
  358. }
  359. }
  360. }
  361. slapi_entry_free(child);
  362. }
  363. }
  364. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  365. "getMembershipFromDownward: <==\n");
  366. }
  367. struct propogateMembershipUpwardArgs {
  368. Slapi_ValueSet *muid_vs;
  369. int depth;
  370. };
  371. /* Forward declaration for next function */
  372. void propogateMembershipUpward(Slapi_Entry *, Slapi_ValueSet *, int);
  373. int
  374. propogateMembershipUpwardCallback(Slapi_Entry *child, void *callback_data)
  375. {
  376. struct propogateMembershipUpwardArgs *args = (struct propogateMembershipUpwardArgs *)(callback_data);
  377. propogateMembershipUpward(child, args->muid_vs, args->depth);
  378. return 0;
  379. }
  380. void
  381. propogateMembershipUpward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, int depth)
  382. {
  383. if (depth >= MAX_RECURSION_DEPTH) {
  384. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  385. "propogateMembershipUpward: recursion limit reached: %d\n", depth);
  386. return;
  387. }
  388. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  389. "propogateMembershipUpward: ==>\n");
  390. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  391. "propogateMembershipUpward: entry name: %s\n",
  392. slapi_entry_get_dn_const(entry));
  393. Slapi_ValueSet *muid_here_vs = NULL;
  394. Slapi_ValueSet *muid_upward_vs = NULL;
  395. /* Get the memberUids at this location, and figure out local changes to memberUid (if any)
  396. * and changes to send upward.
  397. */
  398. if (depth > 0 && hasObjectClass(entry, "posixGroup")) {
  399. int addDynamicGroup = 0;
  400. Slapi_Attr *muid_old_attr = NULL;
  401. Slapi_ValueSet *muid_old_vs = NULL;
  402. int rc = slapi_entry_attr_find(entry, "memberUid", &muid_old_attr);
  403. if (rc != 0 || muid_old_attr == NULL) { /* Found no memberUid list, so create */
  404. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  405. "propogateMembershipUpward: no attribute memberUid\n");
  406. /* There's no values from this entry to add */
  407. muid_upward_vs = muid_vs;
  408. muid_here_vs = muid_vs;
  409. }
  410. else {
  411. int i = 0;
  412. Slapi_Value *v = NULL;
  413. /* Eliminate duplicates */
  414. muid_upward_vs = slapi_valueset_new();
  415. muid_here_vs = slapi_valueset_new();
  416. slapi_attr_get_valueset(muid_old_attr, &muid_old_vs);
  417. slapi_valueset_set_valueset(muid_upward_vs, muid_old_vs);
  418. for (i = slapi_valueset_first_value(muid_vs, &v); i != -1;
  419. i = slapi_valueset_next_value(muid_vs, i, &v)) {
  420. if (!slapi_valueset_find(muid_old_attr, muid_old_vs, v)) {
  421. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  422. "propogateMembershipUpward: adding %s to set\n",
  423. slapi_value_get_string(v));
  424. addDynamicGroup = 1;
  425. slapi_valueset_add_value(muid_here_vs, v);
  426. slapi_valueset_add_value(muid_upward_vs, v);
  427. }
  428. }
  429. slapi_valueset_free(muid_old_vs);
  430. }
  431. /* Update this group's membership */
  432. slapi_entry_add_valueset(entry, "memberUid", muid_here_vs);
  433. if (addDynamicGroup) {
  434. addDynamicGroupIfNecessary(entry, NULL);
  435. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_here_vs);
  436. }
  437. }
  438. else {
  439. muid_upward_vs = muid_vs;
  440. }
  441. /* Find groups containing this one, recurse
  442. */
  443. char *attrs[] = {"memberUid", "objectClass", NULL};
  444. struct propogateMembershipUpwardArgs data = {muid_upward_vs, depth + 1};
  445. posix_winsync_foreach_parent(entry, attrs, propogateMembershipUpwardCallback, &data);
  446. /* Cleanup */
  447. if (muid_here_vs && muid_here_vs != muid_vs) {
  448. slapi_valueset_free(muid_here_vs); muid_here_vs = NULL;
  449. }
  450. if (muid_upward_vs && muid_upward_vs != muid_vs) {
  451. slapi_valueset_free(muid_upward_vs); muid_upward_vs = NULL;
  452. }
  453. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  454. "propogateMembershipUpward: <==\n");
  455. }
  456. struct propogateDeletionsUpwardArgs {
  457. const Slapi_DN *base_sdn;
  458. Slapi_ValueSet *smod_deluids;
  459. Slapi_ValueSet *del_nested_vs;
  460. int depth;
  461. };
  462. /* Forward declaration for next function */
  463. void propogateDeletionsUpward(Slapi_Entry *, const Slapi_DN *, Slapi_ValueSet*, Slapi_ValueSet *, int);
  464. int
  465. propogateDeletionsUpwardCallback(Slapi_Entry *entry, void *callback_data)
  466. {
  467. struct propogateDeletionsUpwardArgs *args = (struct propogateDeletionsUpwardArgs *)(callback_data);
  468. propogateDeletionsUpward(entry, args->base_sdn, args->smod_deluids, args->del_nested_vs, args->depth);
  469. return 0;
  470. }
  471. void
  472. propogateDeletionsUpward(Slapi_Entry *entry, const Slapi_DN *base_sdn, Slapi_ValueSet *smod_deluids, Slapi_ValueSet *del_nested_vs, int depth)
  473. {
  474. if (smod_deluids == NULL) return;
  475. if (depth >= MAX_RECURSION_DEPTH) {
  476. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  477. "propogateDeletionsUpward: recursion limit reached: %d\n", depth);
  478. return;
  479. }
  480. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  481. "propogateDeletionsUpward: ==>\n");
  482. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  483. "propogateDeletionsUpward: entry name: %s\n",
  484. slapi_entry_get_dn_const(entry));
  485. char *attrs[] = { "uniqueMember", "memberUid", "objectClass", NULL };
  486. struct propogateDeletionsUpwardArgs data = {base_sdn, smod_deluids, del_nested_vs, depth + 1};
  487. posix_winsync_foreach_parent(entry, attrs, propogateDeletionsUpwardCallback, &data);
  488. Slapi_Attr *muid_attr = NULL;
  489. int rc = slapi_entry_attr_find(entry, "dsOnlyMemberUid", &muid_attr);
  490. if (rc == 0 && muid_attr != NULL) {
  491. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  492. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  493. Slapi_ValueSet *muid_deletions_vs = slapi_valueset_new();
  494. getMembershipFromDownward(entry, muid_vs, muid_nested_vs, smod_deluids, base_sdn, 0);
  495. int i;
  496. Slapi_Value *v;
  497. for (i = slapi_attr_first_value(muid_attr, &v); i != -1;
  498. i = slapi_attr_next_value(muid_attr, i, &v)) {
  499. if (!slapi_valueset_find(muid_attr, muid_vs, v)) {
  500. const char *uid = slapi_value_get_string(v);
  501. if (depth == 0 && !uid_in_valueset(uid, smod_deluids)) {
  502. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  503. "propogateDeletionsUpward: Adding deletion to modlist: %s\n",
  504. slapi_value_get_string(v));
  505. slapi_valueset_add_value(del_nested_vs, v);
  506. }
  507. else if (depth > 0) {
  508. slapi_valueset_add_value(muid_deletions_vs, v);
  509. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  510. "propogateDeletionsUpward: Adding deletion to deletion list: %s\n",
  511. slapi_value_get_string(v));
  512. }
  513. }
  514. }
  515. if (depth > 0) {
  516. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  517. "propogateDeletionsUpward: executing deletion list\n");
  518. Slapi_Mods *smods = slapi_mods_new();
  519. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "memberuid", valueset_get_valuearray(muid_deletions_vs));
  520. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "dsonlymemberuid", valueset_get_valuearray(muid_deletions_vs));
  521. Slapi_PBlock *mod_pb = slapi_pblock_new();
  522. slapi_modify_internal_set_pb_ext(mod_pb, slapi_entry_get_sdn(entry), slapi_mods_get_ldapmods_passout(smods), 0, 0,
  523. posix_winsync_get_plugin_identity(), 0);
  524. slapi_modify_internal_pb(mod_pb);
  525. slapi_pblock_destroy(mod_pb);
  526. slapi_mods_free(&smods);
  527. }
  528. slapi_valueset_free(muid_vs); muid_vs = NULL;
  529. slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;
  530. slapi_valueset_free(muid_deletions_vs); muid_deletions_vs = NULL;
  531. }
  532. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  533. "propogateDeletionsUpward: <==\n");
  534. }
  535. int
  536. modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify, int newposixgroup)
  537. {
  538. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: ==>\n");
  539. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: Modding %s\n",
  540. slapi_entry_get_dn_const(entry));
  541. int posixGroup = hasObjectClass(entry, "posixGroup");
  542. if (!(posixGroup || hasObjectClass(entry, "ntGroup")) && !newposixgroup) {
  543. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  544. "modGroupMembership end: Not a posixGroup or ntGroup\n");
  545. return 0;
  546. }
  547. Slapi_Mod *smod = NULL;
  548. Slapi_Mod *nextMod = slapi_mod_new();
  549. int del_mod = 0; /* Bool: was there a delete mod? */
  550. char **smod_adduids = NULL;
  551. Slapi_ValueSet *smod_deluids = NULL;
  552. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  553. "modGroupMembership: posixGroup -> look for uniquemember\n");
  554. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  555. slapi_mods_dump(smods, "memberUid - mods dump - initial");
  556. for (smod = slapi_mods_get_first_smod(smods, nextMod); smod; smod
  557. = slapi_mods_get_next_smod(smods, nextMod)) {
  558. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), "uniqueMember")) {
  559. struct berval *bv;
  560. int current_del_mod = SLAPI_IS_MOD_DELETE(slapi_mod_get_operation(smod));
  561. if (current_del_mod) {
  562. del_mod = 1;
  563. }
  564. for (bv = slapi_mod_get_first_value(smod); bv;
  565. bv = slapi_mod_get_next_value(smod)) {
  566. Slapi_Value *sv = slapi_value_new();
  567. slapi_value_init_berval(sv, bv); /* copies bv_val */
  568. if (current_del_mod) {
  569. if (!smod_deluids) smod_deluids = slapi_valueset_new();
  570. slapi_valueset_add_value(smod_deluids, sv);
  571. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  572. "modGroupMembership: add to deluids %s\n",
  573. bv->bv_val);
  574. } else {
  575. slapi_ch_array_add(&smod_adduids,
  576. slapi_ch_strdup(slapi_value_get_string(sv)));
  577. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  578. "modGroupMembership: add to adduids %s\n",
  579. bv->bv_val);
  580. }
  581. slapi_value_free(&sv);
  582. }
  583. }
  584. }
  585. slapi_mod_free(&nextMod);
  586. int muid_rc = 0;
  587. Slapi_Attr * muid_attr = NULL; /* Entry attributes */
  588. Slapi_ValueSet *muid_vs = NULL;
  589. Slapi_Value * uid_value = NULL; /* Attribute values */
  590. Slapi_ValueSet *adduids = slapi_valueset_new();
  591. Slapi_ValueSet *add_nested_vs = slapi_valueset_new();
  592. Slapi_ValueSet *deluids = slapi_valueset_new();
  593. Slapi_ValueSet *del_nested_vs = slapi_valueset_new();
  594. const Slapi_DN *base_sdn = slapi_entry_get_sdn_const(entry);
  595. int j = 0;
  596. if (del_mod || smod_deluids != NULL) {
  597. do { /* Create a context to "break" from */
  598. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  599. if (smod_deluids == NULL) { /* deletion of the last value, deletes the Attribut from entry complete, this operation has no value, so we must look by self */
  600. Slapi_Attr * um_attr = NULL; /* Entry attributes */
  601. int rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  602. if (rc != 0 || um_attr == NULL) {
  603. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  604. "modGroupMembership end: attribute uniquemember not found\n");
  605. break;
  606. }
  607. slapi_attr_get_valueset(um_attr, &smod_deluids);
  608. }
  609. if (muid_rc != 0 || muid_attr == NULL) {
  610. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  611. "modGroupMembership end: attribute memberUid not found\n");
  612. }
  613. else if (posix_winsync_config_get_mapMemberUid()) {
  614. /* ...loop for value... */
  615. for (j = slapi_attr_first_value(muid_attr, &uid_value); j != -1;
  616. j = slapi_attr_next_value(muid_attr, j, &uid_value)) {
  617. /* remove from uniquemember: remove from memberUid also */
  618. const char *uid = NULL;
  619. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  620. "modGroupMembership: test dellist \n");
  621. uid = slapi_value_get_string(uid_value);
  622. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  623. "modGroupMembership: test dellist %s\n", uid);
  624. if (uid_in_valueset(uid, smod_deluids)) {
  625. slapi_valueset_add_value(deluids, uid_value);
  626. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  627. "modGroupMembership: add to dellist %s\n", uid);
  628. }
  629. }
  630. }
  631. if (posix_winsync_config_get_mapNestedGrouping()) {
  632. propogateDeletionsUpward(entry, base_sdn, smod_deluids, del_nested_vs, 0);
  633. int i;
  634. Slapi_Value *v;
  635. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  636. i = slapi_valueset_next_value(del_nested_vs, i, &v)) {
  637. slapi_valueset_add_value(deluids, v);
  638. }
  639. }
  640. } while (false);
  641. }
  642. if (smod_adduids != NULL) { /* not MOD_DELETE */
  643. const char *uid_dn = NULL;
  644. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  645. "modGroupMembership: posixGroup -> look for uniquemember\n");
  646. if (muid_rc == 0 && muid_attr == NULL) {
  647. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  648. }
  649. if (muid_rc == 0 && muid_attr != NULL) {
  650. slapi_attr_get_valueset(muid_attr, &muid_vs);
  651. }
  652. else {
  653. muid_vs = slapi_valueset_new();
  654. }
  655. if (posix_winsync_config_get_mapMemberUid()) {
  656. for (j = 0; smod_adduids[j]; j++) {
  657. static char *uid = NULL;
  658. uid_dn = smod_adduids[j];
  659. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  660. "modGroupMembership: perform user %s\n", uid_dn);
  661. uid = searchUid(uid_dn);
  662. if (uid == NULL) {
  663. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  664. "modGroupMembership: uid not found for %s, cannot do anything\n",
  665. uid_dn); /* member on longer on server, do nothing */
  666. } else {
  667. Slapi_Value *v = slapi_value_new();
  668. slapi_value_init_string_passin(v, uid);
  669. if (muid_rc == 0 && muid_attr != NULL &&
  670. slapi_valueset_find(muid_attr, muid_vs, v) != NULL) {
  671. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  672. "modGroupMembership: uid found in memberuid list %s nothing to do\n",
  673. uid);
  674. }
  675. else {
  676. slapi_valueset_add_value(adduids, v);
  677. slapi_valueset_add_value(muid_vs, v);
  678. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  679. "modGroupMembership: add to modlist %s\n", uid);
  680. }
  681. slapi_value_free(&v); /* also frees uid since it was a passin */
  682. }
  683. }
  684. }
  685. if (posix_winsync_config_get_mapNestedGrouping()) {
  686. for (j = 0; smod_adduids[j]; ++j) {
  687. char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
  688. Slapi_Entry *child = getEntry(smod_adduids[j], attrs);
  689. if (child) {
  690. if (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup")) {
  691. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  692. "modGroupMembership: Found mod to add group, adding membership: %s\n",
  693. smod_adduids[j]);
  694. Slapi_ValueSet *muid_tempnested = slapi_valueset_new();
  695. getMembershipFromDownward(child, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  696. slapi_valueset_free(muid_tempnested); muid_tempnested = NULL;
  697. }
  698. }
  699. else {
  700. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  701. "modGroupMembership: entry not found for dn: %s\n",
  702. smod_adduids[j]);
  703. }
  704. }
  705. getMembershipFromDownward(entry, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  706. int i = 0;
  707. Slapi_Value *v = NULL;
  708. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  709. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  710. slapi_valueset_add_value(adduids, v);
  711. }
  712. propogateMembershipUpward(entry, adduids, 0);
  713. }
  714. }
  715. if (posixGroup) {
  716. int addDynamicGroup = 0;
  717. int i;
  718. Slapi_Value *v;
  719. for (i = slapi_valueset_first_value(adduids, &v); i != -1;
  720. i = slapi_valueset_next_value(adduids, i, &v)){
  721. const char *muid = slapi_value_get_string(v);
  722. if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", muid)) {
  723. *do_modify = 1;
  724. slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", muid);
  725. }
  726. }
  727. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  728. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  729. const char *muid = slapi_value_get_string(v);
  730. if (!smods_has_mod(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid)) {
  731. addDynamicGroup = 1;
  732. *do_modify = 1;
  733. slapi_mods_add_string(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid);
  734. }
  735. }
  736. for (i = slapi_valueset_first_value(deluids, &v); i != -1;
  737. i = slapi_valueset_next_value(deluids, i, &v)){
  738. const char *muid = slapi_value_get_string(v);
  739. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "memberUid", muid)) {
  740. *do_modify = 1;
  741. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberUid", muid);
  742. }
  743. }
  744. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  745. i = slapi_valueset_next_value(del_nested_vs, i, &v)){
  746. const char *muid = slapi_value_get_string(v);
  747. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid)) {
  748. *do_modify = 1;
  749. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid);
  750. }
  751. }
  752. if (addDynamicGroup) {
  753. addDynamicGroupIfNecessary(entry, smods);
  754. }
  755. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  756. slapi_mods_dump(smods, "memberUid - mods dump");
  757. posix_winsync_config_set_MOFTaskCreated();
  758. }
  759. slapi_ch_array_free(smod_adduids);
  760. smod_adduids = NULL;
  761. if (smod_deluids) slapi_valueset_free(smod_deluids);
  762. smod_deluids = NULL;
  763. slapi_valueset_free(adduids);
  764. adduids = NULL;
  765. slapi_valueset_free(deluids);
  766. deluids = NULL;
  767. slapi_valueset_free(add_nested_vs); add_nested_vs = NULL;
  768. slapi_valueset_free(del_nested_vs); del_nested_vs = NULL;
  769. if (muid_vs) {
  770. slapi_valueset_free(muid_vs); muid_vs = NULL;
  771. }
  772. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: <==\n");
  773. return 0;
  774. }
  775. int
  776. addUserToGroupMembership(Slapi_Entry *entry)
  777. {
  778. Slapi_Attr *uid_attr = NULL;
  779. Slapi_Value *v = NULL;
  780. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  781. if (slapi_entry_attr_find(entry, "uid", &uid_attr) == 0) {
  782. slapi_attr_first_value(uid_attr, &v);
  783. if (v) {
  784. slapi_valueset_add_value(muid_vs, v);
  785. }
  786. }
  787. propogateMembershipUpward(entry, muid_vs, 0);
  788. slapi_valueset_free(muid_vs); muid_vs = NULL;
  789. return 0;
  790. }
  791. int
  792. addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry)
  793. {
  794. int rc = 0;
  795. int i;
  796. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: ==>\n");
  797. int posixGroup = hasObjectClass(entry, "posixGroup");
  798. if(!(posixGroup || hasObjectClass(entry, "ntGroup"))) {
  799. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  800. "addGroupMembership: didn't find posixGroup or ntGroup objectclass\n");
  801. return 0;
  802. }
  803. Slapi_Attr * um_attr = NULL; /* Entry attributes uniquemember */
  804. Slapi_Attr * muid_attr = NULL; /* Entry attributes memebrof */
  805. Slapi_Value * uid_value = NULL; /* uniquemember Attribute values */
  806. Slapi_ValueSet *newvs = NULL;
  807. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  808. "addGroupMembership: posixGroup -> look for uniquemember\n");
  809. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  810. if (rc != 0 || um_attr == NULL) {
  811. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  812. "addGroupMembership end: attribute uniquemember not found\n");
  813. return 0;
  814. }
  815. /* found attribute uniquemember */
  816. rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  817. if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create */
  818. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  819. "addGroupMembership: no attribute memberUid\n");
  820. muid_attr = NULL;
  821. }
  822. newvs = slapi_valueset_new();
  823. /* ...loop for value... */
  824. if (posix_winsync_config_get_mapMemberUid()) {
  825. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  826. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  827. const char *uid_dn = NULL;
  828. static char *uid = NULL;
  829. Slapi_Value *v = NULL;
  830. uid_dn = slapi_value_get_string(uid_value);
  831. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  832. "addGroupMembership: perform member %s\n", uid_dn);
  833. uid = searchUid(uid_dn);
  834. if (uid == NULL) {
  835. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  836. "addGroupMembership: uid not found for %s, cannot do anything\n",
  837. uid_dn); /* member on longer on server, do nothing */
  838. } else {
  839. v = slapi_value_new_string(uid);
  840. slapi_ch_free_string(&uid);
  841. if (slapi_attr_value_find(muid_attr, slapi_value_get_berval(v)) != 0) {
  842. slapi_valueset_add_value(newvs, v);
  843. }
  844. slapi_value_free(&v);
  845. }
  846. }
  847. }
  848. if (posix_winsync_config_get_mapNestedGrouping()) {
  849. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  850. getMembershipFromDownward(entry, newvs, muid_nested_vs, NULL, NULL, 0);
  851. propogateMembershipUpward(entry, newvs, 0);
  852. if (posixGroup) {
  853. addDynamicGroupIfNecessary(entry, NULL);
  854. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_nested_vs);
  855. }
  856. slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;
  857. }
  858. if (posixGroup) {
  859. slapi_entry_add_valueset(entry, "memberUid", newvs);
  860. }
  861. slapi_valueset_free(newvs); newvs = NULL;
  862. posix_winsync_config_get_MOFTaskCreated();
  863. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: <==\n");
  864. return 0;
  865. }