posix-group-func.c 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484
  1. /** Author: Carsten Grzemba [email protected]>
  2. *
  3. * Copyright (C) 2011 contac Datentechnik GmbH
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License as
  7. * published by the Free Software Foundation; version 2 only
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program; if not, write to the Free Software
  16. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  17. $Id: posix-group-func.c 28 2011-05-13 14:35:29Z grzemba $
  18. */
  19. #include "slapi-plugin.h"
  20. #include <string.h>
  21. #include <nspr.h>
  22. #include "posix-wsp-ident.h"
  23. Slapi_Value **
  24. valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
  25. static PRMonitor *memberuid_operation_lock = 0;
  26. void
  27. memberUidLock()
  28. {
  29. PR_EnterMonitor(memberuid_operation_lock);
  30. }
  31. void
  32. memberUidUnlock()
  33. {
  34. PR_ExitMonitor(memberuid_operation_lock);
  35. }
  36. int
  37. memberUidLockInit()
  38. {
  39. return (memberuid_operation_lock = PR_NewMonitor()) != NULL;
  40. }
  41. /* search the user with DN udn and returns uid*/
  42. char *
  43. searchUid(const char *udn)
  44. {
  45. Slapi_PBlock *int_search_pb = slapi_pblock_new();
  46. Slapi_Entry **entries = NULL;
  47. char *attrs[] = { "uid", NULL };
  48. char *uid = NULL;
  49. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "search Uid: search %s\n", udn);
  50. slapi_search_internal_set_pb(int_search_pb, udn, LDAP_SCOPE_BASE,
  51. "(|(objectclass=posixAccount)(objectclass=ldapsubentry))", attrs,
  52. 0 /* attrsonly */, NULL /* controls */, NULL /* uniqueid */,
  53. posix_winsync_get_plugin_identity(), 0 /* actions */);
  54. if (slapi_search_internal_pb(int_search_pb)) {
  55. /* get result and log an error */
  56. int res = 0;
  57. slapi_pblock_get(int_search_pb, SLAPI_PLUGIN_INTOP_RESULT, &res);
  58. slapi_log_error(SLAPI_LOG_FATAL, POSIX_WINSYNC_PLUGIN_NAME,
  59. "searchUid: error searching for uid: %d", res);
  60. } else {
  61. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "searchUid: searched %s\n",
  62. udn);
  63. slapi_pblock_get(int_search_pb, SLAPI_PLUGIN_INTOP_SEARCH_ENTRIES, &entries);
  64. if (NULL != entries && NULL != entries[0]) {
  65. Slapi_Attr *attr = NULL;
  66. Slapi_Value *v = NULL;
  67. if (slapi_entry_attr_find(entries[0], "uid", &attr) == 0) {
  68. slapi_attr_first_value(attr, &v);
  69. uid = slapi_ch_strdup(slapi_value_get_string(v));
  70. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  71. "searchUid: return uid %s\n", uid);
  72. /* slapi_value_free(&v); */
  73. } else {
  74. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  75. "searchUid: uid in %s not found\n", udn);
  76. }
  77. slapi_free_search_results_internal(int_search_pb);
  78. slapi_pblock_destroy(int_search_pb);
  79. if (uid && posix_winsync_config_get_lowercase()) {
  80. return slapi_dn_ignore_case(uid);
  81. }
  82. return uid;
  83. }
  84. }
  85. slapi_free_search_results_internal(int_search_pb);
  86. slapi_pblock_destroy(int_search_pb);
  87. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  88. "searchUid: posix user %s not found\n", udn);
  89. return NULL;
  90. }
  91. int
  92. dn_in_set(const char* uid, char **uids)
  93. {
  94. int i;
  95. Slapi_DN *sdn_uid = NULL;
  96. Slapi_DN *sdn_ul = NULL;
  97. if (uids == NULL || uid == NULL)
  98. return false;
  99. sdn_uid = slapi_sdn_new_dn_byval(uid);
  100. sdn_ul = slapi_sdn_new();
  101. for (i = 0; uids[i]; i++) {
  102. slapi_sdn_set_dn_byref(sdn_ul, uids[i]);
  103. if (slapi_sdn_compare(sdn_uid, sdn_ul) == 0) {
  104. slapi_sdn_free(&sdn_ul);
  105. slapi_sdn_free(&sdn_uid);
  106. return true;
  107. }
  108. slapi_sdn_done(sdn_ul);
  109. }
  110. slapi_sdn_free(&sdn_ul);
  111. slapi_sdn_free(&sdn_uid);
  112. return false;
  113. }
  114. int
  115. uid_in_set(const char* uid, char **uids)
  116. {
  117. int i;
  118. if (uid == NULL)
  119. return false;
  120. for (i = 0; uids != NULL && uids[i] != NULL; i++) {
  121. Slapi_RDN *i_rdn = NULL;
  122. char *i_uid = NULL;
  123. char *t = NULL;
  124. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_set: comp %s %s \n",
  125. uid, uids[i]);
  126. i_rdn = slapi_rdn_new_dn(uids[i]);
  127. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  128. if (strncasecmp(uid, i_uid, 256) == 0) {
  129. slapi_rdn_free(&i_rdn);
  130. return true;
  131. }
  132. }
  133. slapi_rdn_free(&i_rdn);
  134. }
  135. return false;
  136. }
  137. /* return 1 if smods already has the given mod - 0 otherwise */
  138. static int
  139. smods_has_mod(Slapi_Mods *smods, int modtype, const char *type, const char *val)
  140. {
  141. int rc = 0;
  142. Slapi_Mod *smod = slapi_mod_new(), *smodp = NULL;
  143. for (smodp = slapi_mods_get_first_smod(smods, smod);
  144. (rc == 0) && smods && (smodp != NULL);
  145. smodp = slapi_mods_get_next_smod(smods, smod)) {
  146. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), type)
  147. && ((slapi_mod_get_operation(smod) | LDAP_MOD_BVALUES) == (modtype | LDAP_MOD_BVALUES))) {
  148. /* type and op are equal - see if val is in the mod's list of values */
  149. Slapi_Value *sval = slapi_value_new_string((char *) val);
  150. Slapi_Attr *attr = slapi_attr_new();
  151. struct berval *bvp = NULL;
  152. slapi_attr_init(attr, type);
  153. for (bvp = slapi_mod_get_first_value(smodp); (rc == 0) && (bvp != NULL);
  154. bvp = slapi_mod_get_next_value(smodp)) {
  155. Slapi_Value *modval = slapi_value_new_berval(bvp);
  156. rc = (slapi_value_compare(attr, sval, modval) == 0);
  157. slapi_value_free(&modval);
  158. }
  159. slapi_value_free(&sval);
  160. slapi_attr_free(&attr);
  161. }
  162. }
  163. slapi_mod_free(&smod);
  164. return rc;
  165. }
  166. int
  167. isPosixGroup(Slapi_Entry *entry)
  168. {
  169. int rc = 0;
  170. int i;
  171. Slapi_Attr *obj_attr = NULL;
  172. Slapi_Value *value = NULL;
  173. rc = slapi_entry_attr_find(entry, "objectclass", &obj_attr);
  174. if (rc != 0) {
  175. return 0; /* Doesn't have any objectclasses */
  176. }
  177. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  178. "add/mod-GroupMembership scan objectclasses\n");
  179. for (
  180. i = slapi_attr_first_value(obj_attr, &value);
  181. i != -1;
  182. i = slapi_attr_next_value(obj_attr, i, &value)
  183. ) {
  184. const char *oc = NULL;
  185. oc = slapi_value_get_string(value);
  186. if (strncasecmp(oc, "posixGroup", 11) == 0) {
  187. return 1; /* Entry has objectclass posixGroup */
  188. }
  189. }
  190. return 0; /* Doesn't have objectclass "posixGroup" */
  191. }
  192. int
  193. modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify)
  194. {
  195. int rc = 0;
  196. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: ==>\n");
  197. if (!isPosixGroup(entry)) {
  198. return 0;
  199. }
  200. Slapi_Mod *smod = NULL;
  201. Slapi_Mod *nextMod = slapi_mod_new();
  202. int del_mod = 0; /* Bool: was there a delete mod? */
  203. char **smod_adduids = NULL;
  204. char **smod_deluids = NULL;
  205. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  206. "modGroupMembership: posixGroup -> look for uniquemember\n");
  207. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  208. slapi_mods_dump(smods, "memberUid - mods dump - initial");
  209. for (smod = slapi_mods_get_first_smod(smods, nextMod); smod; smod
  210. = slapi_mods_get_next_smod(smods, nextMod)) {
  211. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), "uniqueMember")) {
  212. struct berval *bv;
  213. for (bv = slapi_mod_get_first_value(smod); bv;
  214. bv = slapi_mod_get_next_value(smod)) {
  215. Slapi_Value *sv = slapi_value_new();
  216. slapi_value_init_berval(sv, bv); /* copies bv_val */
  217. if (SLAPI_IS_MOD_DELETE(slapi_mod_get_operation(smod))) {
  218. del_mod = 1;
  219. slapi_ch_array_add(&smod_deluids,
  220. slapi_ch_strdup(slapi_value_get_string(sv)));
  221. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  222. "modGroupMembership: add to deluids %s\n",
  223. bv->bv_val);
  224. } else {
  225. slapi_ch_array_add(&smod_adduids,
  226. slapi_ch_strdup(slapi_value_get_string(sv)));
  227. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  228. "modGroupMembership: add to adduids %s\n",
  229. bv->bv_val);
  230. }
  231. slapi_value_free(&sv);
  232. }
  233. }
  234. }
  235. slapi_mod_free(&nextMod);
  236. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  237. "modGroupMembership: entry is posixGroup\n");
  238. Slapi_Attr * muid_attr = NULL; /* Entry attributes */
  239. Slapi_Value * uid_value = NULL; /* Attribute values */
  240. char **adduids = NULL;
  241. char **moduids = NULL;
  242. char **deluids = NULL;
  243. int doModify = false;
  244. int j = 0;
  245. if (del_mod || smod_deluids != NULL) {
  246. do { /* Create a context to "break" from */
  247. Slapi_Attr * mu_attr = NULL; /* Entry attributes */
  248. rc = slapi_entry_attr_find(entry, "memberUid", &mu_attr);
  249. if (rc != 0 || mu_attr == NULL) {
  250. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  251. "modGroupMembership end: attribute memberUid not found\n");
  252. break;
  253. }
  254. /* found attribute uniquemember */
  255. if (smod_deluids == NULL) { /* deletion of the last value, deletes the Attribut from entry complete, this operation has no value, so we must look by self */
  256. Slapi_Attr * um_attr = NULL; /* Entry attributes */
  257. Slapi_Value * uid_dn_value = NULL; /* Attribute values */
  258. int rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  259. if (rc != 0 || um_attr == NULL) {
  260. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  261. "modGroupMembership end: attribute uniquemember not found\n");
  262. break;
  263. }
  264. /* found attribute uniquemember */
  265. /* ...loop for value... */
  266. for (j = slapi_attr_first_value(um_attr, &uid_dn_value); j != -1;
  267. j = slapi_attr_next_value(um_attr, j, &uid_dn_value)) {
  268. slapi_ch_array_add(&smod_deluids,
  269. slapi_ch_strdup(slapi_value_get_string(uid_dn_value)));
  270. }
  271. }
  272. /* ...loop for value... */
  273. for (j = slapi_attr_first_value(mu_attr, &uid_value); j != -1;
  274. j = slapi_attr_next_value(mu_attr, j, &uid_value)) {
  275. /* remove from uniquemember: remove from memberUid also */
  276. const char *uid = NULL;
  277. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  278. "modGroupMembership: test dellist \n");
  279. uid = slapi_value_get_string(uid_value);
  280. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  281. "modGroupMembership: test dellist %s\n", uid);
  282. if (uid_in_set(uid, smod_deluids)) {
  283. slapi_ch_array_add(&deluids, slapi_ch_strdup(uid));
  284. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  285. "modGroupMembership: add to dellist %s\n", uid);
  286. doModify = true;
  287. }
  288. }
  289. } while (false);
  290. }
  291. if (smod_adduids != NULL) { /* not MOD_DELETE */
  292. const char *uid_dn = NULL;
  293. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  294. "modGroupMembership: posixGroup -> look for uniquemember\n");
  295. /* found attribute uniquemember */
  296. for (j = 0; smod_adduids[j]; j++) {
  297. static char *uid = NULL;
  298. uid_dn = smod_adduids[j];
  299. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  300. "modGroupMembership: perform user %s\n", uid_dn);
  301. uid = searchUid(uid_dn);
  302. if (uid == NULL) {
  303. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  304. "modGroupMembership: uid not found for %s, cannot do anything\n",
  305. uid_dn); /* member on longer on server, do nothing */
  306. } else {
  307. rc |= slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  308. if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create */
  309. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  310. "modGroupMembership: no attribute memberUid, add with %s \n",
  311. uid_dn);
  312. slapi_ch_array_add(&adduids, uid);
  313. uid = NULL; /* adduids now owns uid */
  314. doModify = true;
  315. } else { /* Found a memberUid list, so modify */
  316. Slapi_ValueSet *vs = NULL;
  317. Slapi_Value *v = slapi_value_new();
  318. slapi_value_init_string_passin(v, uid);
  319. slapi_attr_get_valueset(muid_attr, &vs);
  320. if (slapi_valueset_find(muid_attr, vs, v) != NULL) { /* already exist, all ok */
  321. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  322. "modGroupMembership: uid found in memberuid list %s nothing to do\n",
  323. uid);
  324. } else {
  325. slapi_ch_array_add(&moduids, uid);
  326. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  327. "modGroupMembership: add to modlist %s\n", uid);
  328. uid = NULL; /* adduids now owns uid */
  329. /* have to clear out v otherwise slapi_value_free will also free uid */
  330. slapi_value_init_berval(v, NULL);
  331. doModify = true;
  332. }
  333. slapi_value_free(&v); /* also frees uid since it was a passin */
  334. slapi_valueset_free(vs); vs = NULL;
  335. }
  336. }
  337. }
  338. }
  339. if (doModify) {
  340. int i;
  341. for (i = 0; adduids && adduids[i]; i++) {
  342. if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", adduids[i])) {
  343. slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", adduids[i]);
  344. }
  345. }
  346. for (i = 0; moduids && moduids[i]; i++) {
  347. if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", moduids[i])) {
  348. slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", moduids[i]);
  349. }
  350. }
  351. for (i = 0; deluids && deluids[i]; i++) {
  352. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "memberUid", deluids[i])) {
  353. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberUid", deluids[i]);
  354. }
  355. }
  356. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  357. slapi_mods_dump(smods, "memberUid - mods dump");
  358. *do_modify = 1;
  359. posix_winsync_config_set_MOFTaskCreated();
  360. }
  361. slapi_ch_array_free(smod_adduids);
  362. smod_adduids = NULL;
  363. slapi_ch_array_free(adduids);
  364. adduids = NULL;
  365. slapi_ch_array_free(smod_deluids);
  366. smod_deluids = NULL;
  367. slapi_ch_array_free(deluids);
  368. deluids = NULL;
  369. slapi_ch_array_free(moduids);
  370. moduids = NULL;
  371. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: <==\n");
  372. return 0;
  373. }
  374. int
  375. addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry)
  376. {
  377. int rc = 0;
  378. int i;
  379. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: ==>\n");
  380. if(!isPosixGroup(entry)) {
  381. return 0;
  382. }
  383. Slapi_Attr * um_attr = NULL; /* Entry attributes uniquemember */
  384. Slapi_Attr * muid_attr = NULL; /* Entry attributes memebrof */
  385. Slapi_Value * uid_value = NULL; /* uniquemember Attribute values */
  386. Slapi_ValueSet *newvs = NULL;
  387. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  388. "addGroupMembership: posixGroup -> look for uniquemember\n");
  389. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  390. if (rc != 0 || um_attr == NULL) {
  391. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  392. "addGroupMembership end: attribute uniquemember not found\n");
  393. return 0;
  394. }
  395. /* found attribute uniquemember */
  396. rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  397. if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create */
  398. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  399. "addGroupMembership: no attribute memberUid\n");
  400. }
  401. newvs = slapi_valueset_new();
  402. /* ...loop for value... */
  403. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  404. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  405. const char *uid_dn = NULL;
  406. static char *uid = NULL;
  407. Slapi_Value *v = NULL;
  408. uid_dn = slapi_value_get_string(uid_value);
  409. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  410. "addGroupMembership: perform member %s\n", uid_dn);
  411. uid = searchUid(uid_dn);
  412. if (uid == NULL) {
  413. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  414. "addGroupMembership: uid not found for %s, cannot do anything\n",
  415. uid_dn); /* member on longer on server, do nothing */
  416. } else {
  417. v = slapi_value_new_string(uid);
  418. slapi_ch_free_string(&uid);
  419. if (slapi_attr_value_find(muid_attr, slapi_value_get_berval(v)) != 0) {
  420. slapi_valueset_add_value(newvs, v);
  421. }
  422. slapi_value_free(&v);
  423. }
  424. }
  425. slapi_entry_add_valueset(entry, "memberUid", newvs);
  426. slapi_valueset_free(newvs);
  427. posix_winsync_config_get_MOFTaskCreated();
  428. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: <==\n");
  429. return 0;
  430. }