posix-group-func.c 39 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020
  1. /** Author: Carsten Grzemba [email protected]>
  2. *
  3. * Copyright (C) 2011 contac Datentechnik GmbH
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License as
  7. * published by the Free Software Foundation; version 2 only
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program; if not, write to the Free Software
  16. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  17. $Id: posix-group-func.c 28 2011-05-13 14:35:29Z grzemba $
  18. */
  19. #include <string.h>
  20. #include <nspr.h>
  21. #include "slapi-plugin.h"
  22. #include "posix-wsp-ident.h"
  23. #define MAX_RECURSION_DEPTH (5)
  24. Slapi_Value **
  25. valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
  26. static int hasObjectClass(Slapi_Entry *entry, const char *objectClass);
  27. static PRMonitor *memberuid_operation_lock = 0;
  28. void
  29. memberUidLock()
  30. {
  31. PR_EnterMonitor(memberuid_operation_lock);
  32. }
  33. void
  34. memberUidUnlock()
  35. {
  36. PR_ExitMonitor(memberuid_operation_lock);
  37. }
  38. int
  39. memberUidLockInit()
  40. {
  41. return (memberuid_operation_lock = PR_NewMonitor()) != NULL;
  42. }
  43. void
  44. addDynamicGroupIfNecessary(Slapi_Entry *entry, Slapi_Mods *smods) {
  45. Slapi_Attr *oc_attr = NULL;
  46. Slapi_Value *voc = slapi_value_new();
  47. slapi_value_init_string(voc, "dynamicGroup");
  48. slapi_entry_attr_find(entry, "objectClass", &oc_attr);
  49. if (slapi_attr_value_find(oc_attr, slapi_value_get_berval(voc)) != 0) {
  50. if (smods) {
  51. slapi_mods_add_string(smods, LDAP_MOD_ADD, "objectClass", "dynamicGroup");
  52. } else {
  53. slapi_entry_add_string(entry, "objectClass", "dynamicGroup");
  54. }
  55. }
  56. slapi_value_free(&voc);
  57. }
  58. Slapi_Entry *
  59. getEntry(const char *udn, char **attrs)
  60. {
  61. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "getEntry: search %s\n", udn);
  62. Slapi_DN *udn_sdn = slapi_sdn_new_dn_byval(udn);
  63. Slapi_Entry *result = NULL;
  64. int rc = slapi_search_internal_get_entry(udn_sdn, attrs, &result, posix_winsync_get_plugin_identity());
  65. slapi_sdn_free(&udn_sdn);
  66. if (rc == 0) {
  67. if (result != NULL) {
  68. return result; /* Must be freed */
  69. }
  70. else {
  71. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  72. "getEntry: %s not found\n", udn);
  73. }
  74. }
  75. else {
  76. slapi_log_error(SLAPI_LOG_FATAL, POSIX_WINSYNC_PLUGIN_NAME,
  77. "getEntry: error searching for uid: %d\n", rc);
  78. }
  79. return NULL;
  80. }
  81. /* search the user with DN udn and returns uid*/
  82. char *
  83. searchUid(const char *udn)
  84. {
  85. char *attrs[] = { "uid", "objectclass", NULL };
  86. Slapi_Entry *entry = getEntry(udn,
  87. /* "(|(objectclass=posixAccount)(objectclass=ldapsubentry))", */
  88. attrs);
  89. char *uid = NULL;
  90. if (entry) {
  91. Slapi_Attr *attr = NULL;
  92. Slapi_Value *v = NULL;
  93. if (slapi_entry_attr_find(entry, "uid", &attr) == 0 && hasObjectClass(entry, "posixAccount")) {
  94. slapi_attr_first_value(attr, &v);
  95. uid = slapi_ch_strdup(slapi_value_get_string(v));
  96. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  97. "searchUid: return uid %s\n", uid);
  98. } else {
  99. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  100. "searchUid: uid in %s not found\n", udn);
  101. }
  102. if (uid && posix_winsync_config_get_lowercase()) {
  103. uid = slapi_dn_ignore_case(uid);
  104. }
  105. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  106. "searchUid: About to free entry (%s)\n", udn);
  107. slapi_entry_free(entry);
  108. }
  109. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  110. "searchUid(%s): <==\n", udn);
  111. return uid;
  112. }
  113. int
  114. dn_in_set(const char* uid, char **uids)
  115. {
  116. int i;
  117. Slapi_DN *sdn_uid = NULL;
  118. Slapi_DN *sdn_ul = NULL;
  119. if (uids == NULL || uid == NULL)
  120. return false;
  121. sdn_uid = slapi_sdn_new_dn_byval(uid);
  122. sdn_ul = slapi_sdn_new();
  123. for (i = 0; uids[i]; i++) {
  124. slapi_sdn_set_dn_byref(sdn_ul, uids[i]);
  125. if (slapi_sdn_compare(sdn_uid, sdn_ul) == 0) {
  126. slapi_sdn_free(&sdn_ul);
  127. slapi_sdn_free(&sdn_uid);
  128. return true;
  129. }
  130. slapi_sdn_done(sdn_ul);
  131. }
  132. slapi_sdn_free(&sdn_ul);
  133. slapi_sdn_free(&sdn_uid);
  134. return false;
  135. }
  136. int
  137. uid_in_set(const char* uid, char **uids)
  138. {
  139. int i;
  140. if (uid == NULL)
  141. return false;
  142. for (i = 0; uids != NULL && uids[i] != NULL; i++) {
  143. Slapi_RDN *i_rdn = NULL;
  144. char *i_uid = NULL;
  145. char *t = NULL;
  146. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_set: comp %s %s \n",
  147. uid, uids[i]);
  148. i_rdn = slapi_rdn_new_dn(uids[i]);
  149. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  150. if (strncasecmp(uid, i_uid, 256) == 0) {
  151. slapi_rdn_free(&i_rdn);
  152. return true;
  153. }
  154. }
  155. slapi_rdn_free(&i_rdn);
  156. }
  157. return false;
  158. }
  159. int
  160. uid_in_valueset(const char* uid, Slapi_ValueSet *uids)
  161. {
  162. int i;
  163. Slapi_Value *v = NULL;
  164. if (uid == NULL)
  165. return false;
  166. for (i = slapi_valueset_first_value(uids, &v); i != -1;
  167. i = slapi_valueset_next_value(uids, i, &v)) {
  168. Slapi_RDN *i_rdn = NULL;
  169. char *i_uid = NULL;
  170. char *t = NULL;
  171. const char *uid_i = slapi_value_get_string(v);
  172. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_valueset: comp %s %s \n",
  173. uid, uid_i);
  174. i_rdn = slapi_rdn_new_dn(uid_i);
  175. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  176. if (strncasecmp(uid, i_uid, 256) == 0) {
  177. slapi_rdn_free(&i_rdn);
  178. return true;
  179. }
  180. }
  181. slapi_rdn_free(&i_rdn);
  182. }
  183. return false;
  184. }
  185. /* return 1 if smods already has the given mod - 0 otherwise */
  186. static int
  187. smods_has_mod(Slapi_Mods *smods, int modtype, const char *type, const char *val)
  188. {
  189. int rc = 0;
  190. Slapi_Mod *smod = slapi_mod_new(), *smodp = NULL;
  191. for (smodp = slapi_mods_get_first_smod(smods, smod);
  192. (rc == 0) && smods && (smodp != NULL);
  193. smodp = slapi_mods_get_next_smod(smods, smod)) {
  194. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), type)
  195. && ((slapi_mod_get_operation(smod) | LDAP_MOD_BVALUES) == (modtype | LDAP_MOD_BVALUES))) {
  196. /* type and op are equal - see if val is in the mod's list of values */
  197. Slapi_Value *sval = slapi_value_new_string((char *) val);
  198. Slapi_Attr *attr = slapi_attr_new();
  199. struct berval *bvp = NULL;
  200. slapi_attr_init(attr, type);
  201. for (bvp = slapi_mod_get_first_value(smodp); (rc == 0) && (bvp != NULL);
  202. bvp = slapi_mod_get_next_value(smodp)) {
  203. Slapi_Value *modval = slapi_value_new_berval(bvp);
  204. rc = (slapi_value_compare(attr, sval, modval) == 0);
  205. slapi_value_free(&modval);
  206. }
  207. slapi_value_free(&sval);
  208. slapi_attr_free(&attr);
  209. }
  210. }
  211. slapi_mod_free(&smod);
  212. return rc;
  213. }
  214. static int
  215. hasObjectClass(Slapi_Entry *entry, const char *objectClass)
  216. {
  217. int rc = 0;
  218. int i;
  219. Slapi_Attr *obj_attr = NULL;
  220. Slapi_Value *value = NULL;
  221. rc = slapi_entry_attr_find(entry, "objectclass", &obj_attr);
  222. if (rc != 0) {
  223. return 0; /* Doesn't have any objectclasses */
  224. }
  225. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  226. "Scanning objectclasses\n");
  227. for (
  228. i = slapi_attr_first_value(obj_attr, &value);
  229. i != -1;
  230. i = slapi_attr_next_value(obj_attr, i, &value)
  231. ) {
  232. const char *oc = NULL;
  233. oc = slapi_value_get_string(value);
  234. if (strcasecmp(oc, objectClass) == 0) {
  235. return 1; /* Entry has the desired objectclass */
  236. }
  237. }
  238. return 0; /* Doesn't have desired objectclass */
  239. }
  240. void
  241. posix_winsync_foreach_parent(Slapi_Entry *entry, char **attrs, plugin_search_entry_callback callback, void *callback_data)
  242. {
  243. char *cookie = NULL;
  244. Slapi_Backend *be = NULL;
  245. char *value = slapi_entry_get_ndn(entry);
  246. size_t vallen = value ? strlen(value) : 0;
  247. char *filter_escaped_value = slapi_escape_filter_value(value, vallen);
  248. char *filter = slapi_ch_smprintf("(uniqueMember=%s)", filter_escaped_value);
  249. slapi_ch_free_string(&filter_escaped_value);
  250. Slapi_PBlock *search_pb = slapi_pblock_new();
  251. for (be = slapi_get_first_backend(&cookie); be;
  252. be = slapi_get_next_backend(cookie)) {
  253. const Slapi_DN *base_sdn = slapi_be_getsuffix(be, 0);
  254. if (base_sdn == NULL) {
  255. continue;
  256. }
  257. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  258. "posix_winsync_foreach_parent: Searching subtree %s for %s\n",
  259. slapi_sdn_get_dn(base_sdn),
  260. filter);
  261. slapi_search_internal_set_pb(search_pb,
  262. slapi_sdn_get_dn(base_sdn),
  263. LDAP_SCOPE_SUBTREE,
  264. filter,
  265. attrs, 0, NULL, NULL,
  266. posix_winsync_get_plugin_identity(), 0);
  267. slapi_search_internal_callback_pb(search_pb, callback_data, 0, callback, 0);
  268. slapi_pblock_init(search_pb);
  269. }
  270. slapi_pblock_destroy(search_pb);
  271. slapi_ch_free((void**)&cookie);
  272. slapi_ch_free_string(&filter);
  273. }
  274. /* Retrieve nested membership from chains of groups.
  275. * Muid_vs in => any preexisting membership list
  276. * out => the union of the input list and the total membership
  277. * Muid_nested_vs out => the members of muid_vs "out" that weren't in muid_vs "in"
  278. * deletions in => Any elements to NOT consider if members of base_sdn
  279. */
  280. void
  281. getMembershipFromDownward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, Slapi_ValueSet *muid_nested_vs, Slapi_ValueSet *deletions, const Slapi_DN *base_sdn, int depth)
  282. {
  283. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  284. "getMembershipFromDownward: ==>\n");
  285. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  286. "getMembershipFromDownward: entry name: %s\n",
  287. slapi_entry_get_dn_const(entry));
  288. int rc = 0;
  289. Slapi_Attr *um_attr = NULL; /* Entry attributes uniqueMember */
  290. Slapi_Value *uid_value = NULL; /* uniqueMember attribute values */
  291. if (depth >= MAX_RECURSION_DEPTH) {
  292. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  293. "getMembershipFromDownward: recursion limit reached: %d\n", depth);
  294. return;
  295. }
  296. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  297. if (rc != 0 || um_attr == NULL) {
  298. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  299. "getMembershipFromDownward end: attribute uniquemember not found\n");
  300. return;
  301. }
  302. int i;
  303. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  304. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  305. char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
  306. const char *uid_dn = slapi_value_get_string(uid_value);
  307. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  308. "getMembershipFromDownward: iterating uniqueMember: %s\n",
  309. uid_dn);
  310. if (deletions && !slapi_sdn_compare(slapi_entry_get_sdn_const(entry), base_sdn)) {
  311. if (slapi_valueset_find(um_attr, deletions, uid_value)) {
  312. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  313. "getMembershipFromDownward: Skipping iteration because of deletion\n");
  314. continue;
  315. }
  316. }
  317. Slapi_Entry *child = getEntry(uid_dn, attrs);
  318. if (!child) {
  319. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  320. "getMembershipFromDownward end: child not found: %s\n", uid_dn);
  321. }
  322. else {
  323. /* PosixGroups except for the top one are already fully mapped out */
  324. if ((!hasObjectClass(entry, "posixGroup") || (depth == 0)) &&
  325. (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup"))) {
  326. /* Recurse downward */
  327. getMembershipFromDownward(child, muid_vs, muid_nested_vs, deletions, base_sdn, depth + 1);
  328. }
  329. if (hasObjectClass(child, "posixAccount")) {
  330. Slapi_Attr *uid_attr = NULL;
  331. Slapi_Value *v = NULL;
  332. if (slapi_entry_attr_find(child, "uid", &uid_attr) == 0) {
  333. slapi_attr_first_value(uid_attr, &v);
  334. if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {
  335. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  336. "getMembershipFromDownward: adding member: %s\n",
  337. slapi_value_get_string(v));
  338. slapi_valueset_add_value(muid_vs, v);
  339. slapi_valueset_add_value(muid_nested_vs, v);
  340. }
  341. }
  342. } else if (hasObjectClass(child, "posixGroup")) {
  343. Slapi_Attr *uid_attr = NULL;
  344. Slapi_Value *v = NULL;
  345. if (slapi_entry_attr_find(child, "memberuid", &uid_attr) == 0) {
  346. slapi_attr_first_value(uid_attr, &v);
  347. if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {
  348. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  349. "getMembershipFromDownward: adding member: %s\n",
  350. slapi_value_get_string(v));
  351. slapi_valueset_add_value(muid_vs, v);
  352. slapi_valueset_add_value(muid_nested_vs, v);
  353. }
  354. }
  355. }
  356. slapi_entry_free(child);
  357. }
  358. }
  359. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  360. "getMembershipFromDownward: <==\n");
  361. }
  362. struct propogateMembershipUpwardArgs {
  363. Slapi_ValueSet *muid_vs;
  364. int depth;
  365. };
  366. /* Forward declaration for next function */
  367. void propogateMembershipUpward(Slapi_Entry *, Slapi_ValueSet *, int);
  368. int
  369. propogateMembershipUpwardCallback(Slapi_Entry *child, void *callback_data)
  370. {
  371. struct propogateMembershipUpwardArgs *args = (struct propogateMembershipUpwardArgs *)(callback_data);
  372. propogateMembershipUpward(child, args->muid_vs, args->depth);
  373. return 0;
  374. }
  375. void
  376. propogateMembershipUpward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, int depth)
  377. {
  378. if (depth >= MAX_RECURSION_DEPTH) {
  379. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  380. "propogateMembershipUpward: recursion limit reached: %d\n", depth);
  381. return;
  382. }
  383. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  384. "propogateMembershipUpward: ==>\n");
  385. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  386. "propogateMembershipUpward: entry name: %s\n",
  387. slapi_entry_get_dn_const(entry));
  388. Slapi_ValueSet *muid_here_vs = NULL;
  389. Slapi_ValueSet *muid_upward_vs = NULL;
  390. /* Get the memberUids at this location, and figure out local changes to memberUid (if any)
  391. * and changes to send upward.
  392. */
  393. if (depth > 0 && hasObjectClass(entry, "posixGroup")) {
  394. int addDynamicGroup = 0;
  395. Slapi_Attr *muid_old_attr = NULL;
  396. Slapi_ValueSet *muid_old_vs = NULL;
  397. int rc = slapi_entry_attr_find(entry, "memberUid", &muid_old_attr);
  398. if (rc != 0 || muid_old_attr == NULL) { /* Found no memberUid list, so create */
  399. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  400. "propogateMembershipUpward: no attribute memberUid\n");
  401. /* There's no values from this entry to add */
  402. muid_upward_vs = muid_vs;
  403. muid_here_vs = muid_vs;
  404. }
  405. else {
  406. int i = 0;
  407. Slapi_Value *v = NULL;
  408. /* Eliminate duplicates */
  409. muid_upward_vs = slapi_valueset_new();
  410. muid_here_vs = slapi_valueset_new();
  411. slapi_attr_get_valueset(muid_old_attr, &muid_old_vs);
  412. slapi_valueset_set_valueset(muid_upward_vs, muid_old_vs);
  413. for (i = slapi_valueset_first_value(muid_vs, &v); i != -1;
  414. i = slapi_valueset_next_value(muid_vs, i, &v)) {
  415. if (!slapi_valueset_find(muid_old_attr, muid_old_vs, v)) {
  416. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  417. "propogateMembershipUpward: adding %s to set\n",
  418. slapi_value_get_string(v));
  419. addDynamicGroup = 1;
  420. slapi_valueset_add_value(muid_here_vs, v);
  421. slapi_valueset_add_value(muid_upward_vs, v);
  422. }
  423. }
  424. slapi_valueset_free(muid_old_vs);
  425. }
  426. /* Update this group's membership */
  427. slapi_entry_add_valueset(entry, "memberUid", muid_here_vs);
  428. if (addDynamicGroup) {
  429. addDynamicGroupIfNecessary(entry, NULL);
  430. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_here_vs);
  431. }
  432. }
  433. else {
  434. muid_upward_vs = muid_vs;
  435. }
  436. /* Find groups containing this one, recurse
  437. */
  438. char *attrs[] = {"memberUid", "objectClass", NULL};
  439. struct propogateMembershipUpwardArgs data = {muid_upward_vs, depth + 1};
  440. posix_winsync_foreach_parent(entry, attrs, propogateMembershipUpwardCallback, &data);
  441. /* Cleanup */
  442. if (muid_here_vs && muid_here_vs != muid_vs) {
  443. slapi_valueset_free(muid_here_vs); muid_here_vs = NULL;
  444. }
  445. if (muid_upward_vs && muid_upward_vs != muid_vs) {
  446. slapi_valueset_free(muid_upward_vs); muid_upward_vs = NULL;
  447. }
  448. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  449. "propogateMembershipUpward: <==\n");
  450. }
  451. struct propogateDeletionsUpwardArgs {
  452. const Slapi_DN *base_sdn;
  453. Slapi_ValueSet *smod_deluids;
  454. Slapi_ValueSet *del_nested_vs;
  455. int depth;
  456. };
  457. /* Forward declaration for next function */
  458. void propogateDeletionsUpward(Slapi_Entry *, const Slapi_DN *, Slapi_ValueSet*, Slapi_ValueSet *, int);
  459. int
  460. propogateDeletionsUpwardCallback(Slapi_Entry *entry, void *callback_data)
  461. {
  462. struct propogateDeletionsUpwardArgs *args = (struct propogateDeletionsUpwardArgs *)(callback_data);
  463. propogateDeletionsUpward(entry, args->base_sdn, args->smod_deluids, args->del_nested_vs, args->depth);
  464. return 0;
  465. }
  466. void
  467. propogateDeletionsUpward(Slapi_Entry *entry, const Slapi_DN *base_sdn, Slapi_ValueSet *smod_deluids, Slapi_ValueSet *del_nested_vs, int depth)
  468. {
  469. if (smod_deluids == NULL) return;
  470. if (depth >= MAX_RECURSION_DEPTH) {
  471. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  472. "propogateDeletionsUpward: recursion limit reached: %d\n", depth);
  473. return;
  474. }
  475. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  476. "propogateDeletionsUpward: ==>\n");
  477. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  478. "propogateDeletionsUpward: entry name: %s\n",
  479. slapi_entry_get_dn_const(entry));
  480. char *attrs[] = { "uniqueMember", "memberUid", "objectClass", NULL };
  481. struct propogateDeletionsUpwardArgs data = {base_sdn, smod_deluids, del_nested_vs, depth + 1};
  482. posix_winsync_foreach_parent(entry, attrs, propogateDeletionsUpwardCallback, &data);
  483. Slapi_Attr *muid_attr = NULL;
  484. int rc = slapi_entry_attr_find(entry, "dsOnlyMemberUid", &muid_attr);
  485. if (rc == 0 && muid_attr != NULL) {
  486. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  487. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  488. Slapi_ValueSet *muid_deletions_vs = slapi_valueset_new();
  489. getMembershipFromDownward(entry, muid_vs, muid_nested_vs, smod_deluids, base_sdn, 0);
  490. int i;
  491. Slapi_Value *v;
  492. for (i = slapi_attr_first_value(muid_attr, &v); i != -1;
  493. i = slapi_attr_next_value(muid_attr, i, &v)) {
  494. if (!slapi_valueset_find(muid_attr, muid_vs, v)) {
  495. const char *uid = slapi_value_get_string(v);
  496. if (depth == 0 && !uid_in_valueset(uid, smod_deluids)) {
  497. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  498. "propogateDeletionsUpward: Adding deletion to modlist: %s\n",
  499. slapi_value_get_string(v));
  500. slapi_valueset_add_value(del_nested_vs, v);
  501. }
  502. else if (depth > 0) {
  503. slapi_valueset_add_value(muid_deletions_vs, v);
  504. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  505. "propogateDeletionsUpward: Adding deletion to deletion list: %s\n",
  506. slapi_value_get_string(v));
  507. }
  508. }
  509. }
  510. if (depth > 0) {
  511. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  512. "propogateDeletionsUpward: executing deletion list\n");
  513. Slapi_Mods *smods = slapi_mods_new();
  514. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "memberuid", valueset_get_valuearray(muid_deletions_vs));
  515. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "dsonlymemberuid", valueset_get_valuearray(muid_deletions_vs));
  516. Slapi_PBlock *mod_pb = slapi_pblock_new();
  517. slapi_modify_internal_set_pb_ext(mod_pb, slapi_entry_get_sdn(entry), slapi_mods_get_ldapmods_passout(smods), 0, 0,
  518. posix_winsync_get_plugin_identity(), 0);
  519. slapi_modify_internal_pb(mod_pb);
  520. slapi_pblock_destroy(mod_pb);
  521. slapi_mods_free(&smods);
  522. }
  523. slapi_valueset_free(muid_vs); muid_vs = NULL;
  524. slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;
  525. slapi_valueset_free(muid_deletions_vs); muid_deletions_vs = NULL;
  526. }
  527. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  528. "propogateDeletionsUpward: <==\n");
  529. }
  530. int
  531. modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify, int newposixgroup)
  532. {
  533. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: ==>\n");
  534. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: Modding %s\n",
  535. slapi_entry_get_dn_const(entry));
  536. int posixGroup = hasObjectClass(entry, "posixGroup");
  537. if (!(posixGroup || hasObjectClass(entry, "ntGroup")) && !newposixgroup) {
  538. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  539. "modGroupMembership end: Not a posixGroup or ntGroup\n");
  540. return 0;
  541. }
  542. Slapi_Mod *smod = NULL;
  543. Slapi_Mod *nextMod = slapi_mod_new();
  544. int del_mod = 0; /* Bool: was there a delete mod? */
  545. char **smod_adduids = NULL;
  546. Slapi_ValueSet *smod_deluids = NULL;
  547. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  548. "modGroupMembership: posixGroup -> look for uniquemember\n");
  549. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  550. slapi_mods_dump(smods, "memberUid - mods dump - initial");
  551. for (smod = slapi_mods_get_first_smod(smods, nextMod); smod; smod
  552. = slapi_mods_get_next_smod(smods, nextMod)) {
  553. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), "uniqueMember")) {
  554. struct berval *bv;
  555. int current_del_mod = SLAPI_IS_MOD_DELETE(slapi_mod_get_operation(smod));
  556. if (current_del_mod) {
  557. del_mod = 1;
  558. }
  559. for (bv = slapi_mod_get_first_value(smod); bv;
  560. bv = slapi_mod_get_next_value(smod)) {
  561. Slapi_Value *sv = slapi_value_new();
  562. slapi_value_init_berval(sv, bv); /* copies bv_val */
  563. if (current_del_mod) {
  564. if (!smod_deluids) smod_deluids = slapi_valueset_new();
  565. slapi_valueset_add_value(smod_deluids, sv);
  566. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  567. "modGroupMembership: add to deluids %s\n",
  568. bv->bv_val);
  569. } else {
  570. slapi_ch_array_add(&smod_adduids,
  571. slapi_ch_strdup(slapi_value_get_string(sv)));
  572. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  573. "modGroupMembership: add to adduids %s\n",
  574. bv->bv_val);
  575. }
  576. slapi_value_free(&sv);
  577. }
  578. }
  579. }
  580. slapi_mod_free(&nextMod);
  581. int muid_rc = 0;
  582. Slapi_Attr * muid_attr = NULL; /* Entry attributes */
  583. Slapi_ValueSet *muid_vs = NULL;
  584. Slapi_Value * uid_value = NULL; /* Attribute values */
  585. Slapi_ValueSet *adduids = slapi_valueset_new();
  586. Slapi_ValueSet *add_nested_vs = slapi_valueset_new();
  587. Slapi_ValueSet *deluids = slapi_valueset_new();
  588. Slapi_ValueSet *del_nested_vs = slapi_valueset_new();
  589. const Slapi_DN *base_sdn = slapi_entry_get_sdn_const(entry);
  590. int j = 0;
  591. if (del_mod || smod_deluids != NULL) {
  592. do { /* Create a context to "break" from */
  593. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  594. if (smod_deluids == NULL) { /* deletion of the last value, deletes the Attribut from entry complete, this operation has no value, so we must look by self */
  595. Slapi_Attr * um_attr = NULL; /* Entry attributes */
  596. int rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  597. if (rc != 0 || um_attr == NULL) {
  598. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  599. "modGroupMembership end: attribute uniquemember not found\n");
  600. break;
  601. }
  602. slapi_attr_get_valueset(um_attr, &smod_deluids);
  603. }
  604. if (muid_rc != 0 || muid_attr == NULL) {
  605. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  606. "modGroupMembership end: attribute memberUid not found\n");
  607. }
  608. else if (posix_winsync_config_get_mapMemberUid()) {
  609. /* ...loop for value... */
  610. for (j = slapi_attr_first_value(muid_attr, &uid_value); j != -1;
  611. j = slapi_attr_next_value(muid_attr, j, &uid_value)) {
  612. /* remove from uniquemember: remove from memberUid also */
  613. const char *uid = NULL;
  614. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  615. "modGroupMembership: test dellist \n");
  616. uid = slapi_value_get_string(uid_value);
  617. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  618. "modGroupMembership: test dellist %s\n", uid);
  619. if (uid_in_valueset(uid, smod_deluids)) {
  620. slapi_valueset_add_value(deluids, uid_value);
  621. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  622. "modGroupMembership: add to dellist %s\n", uid);
  623. }
  624. }
  625. }
  626. if (posix_winsync_config_get_mapNestedGrouping()) {
  627. propogateDeletionsUpward(entry, base_sdn, smod_deluids, del_nested_vs, 0);
  628. int i;
  629. Slapi_Value *v;
  630. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  631. i = slapi_valueset_next_value(del_nested_vs, i, &v)) {
  632. slapi_valueset_add_value(deluids, v);
  633. }
  634. }
  635. } while (false);
  636. }
  637. if (smod_adduids != NULL) { /* not MOD_DELETE */
  638. const char *uid_dn = NULL;
  639. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  640. "modGroupMembership: posixGroup -> look for uniquemember\n");
  641. if (muid_rc == 0 && muid_attr == NULL) {
  642. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  643. }
  644. if (muid_rc == 0 && muid_attr != NULL) {
  645. slapi_attr_get_valueset(muid_attr, &muid_vs);
  646. }
  647. else {
  648. muid_vs = slapi_valueset_new();
  649. }
  650. if (posix_winsync_config_get_mapMemberUid()) {
  651. for (j = 0; smod_adduids[j]; j++) {
  652. static char *uid = NULL;
  653. uid_dn = smod_adduids[j];
  654. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  655. "modGroupMembership: perform user %s\n", uid_dn);
  656. uid = searchUid(uid_dn);
  657. if (uid == NULL) {
  658. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  659. "modGroupMembership: uid not found for %s, cannot do anything\n",
  660. uid_dn); /* member on longer on server, do nothing */
  661. } else {
  662. Slapi_Value *v = slapi_value_new();
  663. slapi_value_init_string_passin(v, uid);
  664. if (muid_rc == 0 && muid_attr != NULL &&
  665. slapi_valueset_find(muid_attr, muid_vs, v) != NULL) {
  666. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  667. "modGroupMembership: uid found in memberuid list %s nothing to do\n",
  668. uid);
  669. }
  670. else {
  671. slapi_valueset_add_value(adduids, v);
  672. slapi_valueset_add_value(muid_vs, v);
  673. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  674. "modGroupMembership: add to modlist %s\n", uid);
  675. }
  676. slapi_value_free(&v); /* also frees uid since it was a passin */
  677. }
  678. }
  679. }
  680. if (posix_winsync_config_get_mapNestedGrouping()) {
  681. for (j = 0; smod_adduids[j]; ++j) {
  682. char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
  683. Slapi_Entry *child = getEntry(smod_adduids[j], attrs);
  684. if (child) {
  685. if (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup")) {
  686. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  687. "modGroupMembership: Found mod to add group, adding membership: %s\n",
  688. smod_adduids[j]);
  689. Slapi_ValueSet *muid_tempnested = slapi_valueset_new();
  690. getMembershipFromDownward(child, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  691. slapi_valueset_free(muid_tempnested); muid_tempnested = NULL;
  692. }
  693. }
  694. else {
  695. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  696. "modGroupMembership: entry not found for dn: %s\n",
  697. smod_adduids[j]);
  698. }
  699. }
  700. getMembershipFromDownward(entry, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  701. int i = 0;
  702. Slapi_Value *v = NULL;
  703. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  704. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  705. slapi_valueset_add_value(adduids, v);
  706. }
  707. propogateMembershipUpward(entry, adduids, 0);
  708. }
  709. }
  710. if (posixGroup) {
  711. int addDynamicGroup = 0;
  712. int i;
  713. Slapi_Value *v;
  714. for (i = slapi_valueset_first_value(adduids, &v); i != -1;
  715. i = slapi_valueset_next_value(adduids, i, &v)){
  716. const char *muid = slapi_value_get_string(v);
  717. if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", muid)) {
  718. *do_modify = 1;
  719. slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", muid);
  720. }
  721. }
  722. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  723. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  724. const char *muid = slapi_value_get_string(v);
  725. if (!smods_has_mod(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid)) {
  726. addDynamicGroup = 1;
  727. *do_modify = 1;
  728. slapi_mods_add_string(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid);
  729. }
  730. }
  731. for (i = slapi_valueset_first_value(deluids, &v); i != -1;
  732. i = slapi_valueset_next_value(deluids, i, &v)){
  733. const char *muid = slapi_value_get_string(v);
  734. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "memberUid", muid)) {
  735. *do_modify = 1;
  736. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberUid", muid);
  737. }
  738. }
  739. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  740. i = slapi_valueset_next_value(del_nested_vs, i, &v)){
  741. const char *muid = slapi_value_get_string(v);
  742. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid)) {
  743. *do_modify = 1;
  744. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid);
  745. }
  746. }
  747. if (addDynamicGroup) {
  748. addDynamicGroupIfNecessary(entry, smods);
  749. }
  750. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  751. slapi_mods_dump(smods, "memberUid - mods dump");
  752. posix_winsync_config_set_MOFTaskCreated();
  753. }
  754. slapi_ch_array_free(smod_adduids);
  755. smod_adduids = NULL;
  756. if (smod_deluids) slapi_valueset_free(smod_deluids);
  757. smod_deluids = NULL;
  758. slapi_valueset_free(adduids);
  759. adduids = NULL;
  760. slapi_valueset_free(deluids);
  761. deluids = NULL;
  762. slapi_valueset_free(add_nested_vs); add_nested_vs = NULL;
  763. slapi_valueset_free(del_nested_vs); del_nested_vs = NULL;
  764. if (muid_vs) {
  765. slapi_valueset_free(muid_vs); muid_vs = NULL;
  766. }
  767. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: <==\n");
  768. return 0;
  769. }
  770. int
  771. addUserToGroupMembership(Slapi_Entry *entry)
  772. {
  773. Slapi_Attr *uid_attr = NULL;
  774. Slapi_Value *v = NULL;
  775. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  776. if (slapi_entry_attr_find(entry, "uid", &uid_attr) == 0) {
  777. slapi_attr_first_value(uid_attr, &v);
  778. if (v) {
  779. slapi_valueset_add_value(muid_vs, v);
  780. }
  781. }
  782. propogateMembershipUpward(entry, muid_vs, 0);
  783. slapi_valueset_free(muid_vs); muid_vs = NULL;
  784. return 0;
  785. }
  786. int
  787. addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry)
  788. {
  789. int rc = 0;
  790. int i;
  791. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: ==>\n");
  792. int posixGroup = hasObjectClass(entry, "posixGroup");
  793. if(!(posixGroup || hasObjectClass(entry, "ntGroup"))) {
  794. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  795. "addGroupMembership: didn't find posixGroup or ntGroup objectclass\n");
  796. return 0;
  797. }
  798. Slapi_Attr * um_attr = NULL; /* Entry attributes uniquemember */
  799. Slapi_Attr * muid_attr = NULL; /* Entry attributes memebrof */
  800. Slapi_Value * uid_value = NULL; /* uniquemember Attribute values */
  801. Slapi_ValueSet *newvs = NULL;
  802. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  803. "addGroupMembership: posixGroup -> look for uniquemember\n");
  804. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  805. if (rc != 0 || um_attr == NULL) {
  806. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  807. "addGroupMembership end: attribute uniquemember not found\n");
  808. return 0;
  809. }
  810. /* found attribute uniquemember */
  811. rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  812. if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create */
  813. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  814. "addGroupMembership: no attribute memberUid\n");
  815. muid_attr = NULL;
  816. }
  817. newvs = slapi_valueset_new();
  818. /* ...loop for value... */
  819. if (posix_winsync_config_get_mapMemberUid()) {
  820. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  821. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  822. const char *uid_dn = NULL;
  823. static char *uid = NULL;
  824. Slapi_Value *v = NULL;
  825. uid_dn = slapi_value_get_string(uid_value);
  826. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  827. "addGroupMembership: perform member %s\n", uid_dn);
  828. uid = searchUid(uid_dn);
  829. if (uid == NULL) {
  830. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  831. "addGroupMembership: uid not found for %s, cannot do anything\n",
  832. uid_dn); /* member on longer on server, do nothing */
  833. } else {
  834. v = slapi_value_new_string(uid);
  835. slapi_ch_free_string(&uid);
  836. if (slapi_attr_value_find(muid_attr, slapi_value_get_berval(v)) != 0) {
  837. slapi_valueset_add_value(newvs, v);
  838. }
  839. slapi_value_free(&v);
  840. }
  841. }
  842. }
  843. if (posix_winsync_config_get_mapNestedGrouping()) {
  844. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  845. getMembershipFromDownward(entry, newvs, muid_nested_vs, NULL, NULL, 0);
  846. propogateMembershipUpward(entry, newvs, 0);
  847. if (posixGroup) {
  848. addDynamicGroupIfNecessary(entry, NULL);
  849. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_nested_vs);
  850. }
  851. slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;
  852. }
  853. if (posixGroup) {
  854. slapi_entry_add_valueset(entry, "memberUid", newvs);
  855. }
  856. slapi_valueset_free(newvs); newvs = NULL;
  857. posix_winsync_config_get_MOFTaskCreated();
  858. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: <==\n");
  859. return 0;
  860. }