memberof.c 56 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164
  1. /** BEGIN COPYRIGHT BLOCK
  2. * This Program is free software; you can redistribute it and/or modify it under
  3. * the terms of the GNU General Public License as published by the Free Software
  4. * Foundation; version 2 of the License.
  5. *
  6. * This Program is distributed in the hope that it will be useful, but WITHOUT
  7. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  8. * FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
  9. *
  10. * You should have received a copy of the GNU General Public License along with
  11. * this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
  12. * Place, Suite 330, Boston, MA 02111-1307 USA.
  13. *
  14. * In addition, as a special exception, Red Hat, Inc. gives You the additional
  15. * right to link the code of this Program with code not covered under the GNU
  16. * General Public License ("Non-GPL Code") and to distribute linked combinations
  17. * including the two, subject to the limitations in this paragraph. Non-GPL Code
  18. * permitted under this exception must only link to the code of this Program
  19. * through those well defined interfaces identified in the file named EXCEPTION
  20. * found in the source code files (the "Approved Interfaces"). The files of
  21. * Non-GPL Code may instantiate templates or use macros or inline functions from
  22. * the Approved Interfaces without causing the resulting work to be covered by
  23. * the GNU General Public License. Only Red Hat, Inc. may make changes or
  24. * additions to the list of Approved Interfaces. You must obey the GNU General
  25. * Public License in all respects for all of the Program code and other code used
  26. * in conjunction with the Program except the Non-GPL Code covered by this
  27. * exception. If you modify this file, you may extend this exception to your
  28. * version of the file, but you are not obligated to do so. If you do not wish to
  29. * provide this exception without modification, you must delete this exception
  30. * statement from your version and license this file solely under the GPL without
  31. * exception.
  32. *
  33. * Authors:
  34. * Pete Rowley <[email protected]>
  35. *
  36. * Copyright (C) 2007 Red Hat, Inc.
  37. * All rights reserved.
  38. * END COPYRIGHT BLOCK
  39. **/
  40. /* The memberof plugin updates the memberof attribute of entries
  41. * based on modifications performed on groupofuniquenames entries
  42. *
  43. * In addition the plugin provides a DS task that may be started
  44. * administrative clients and that creates the initial memberof
  45. * list for imported entries and/or fixes the memberof list of
  46. * existing entries that have inconsistent state (for example,
  47. * if the memberof attribute was incorrectly edited directly)
  48. *
  49. * To start the memberof task add an entry like:
  50. *
  51. * dn: cn=mytask, cn=memberof task, cn=tasks, cn=config
  52. * objectClass: top
  53. * objectClass: extensibleObject
  54. * cn: mytask
  55. * basedn: dc=example, dc=com
  56. * filter: (uid=test4)
  57. *
  58. * where "basedn" is required and refers to the top most node to perform the
  59. * task on, and where "filter" is an optional attribute that provides a filter
  60. * describing the entries to be worked on
  61. */
  62. #ifdef HAVE_CONFIG_H
  63. # include <config.h>
  64. #endif
  65. #include "slapi-plugin.h"
  66. #include "dirver.h"
  67. #include <dirlite_strings.h> /* PLUGIN_MAGIC_VENDOR_STR */
  68. #include "string.h"
  69. #include "nspr.h"
  70. #include "memberof.h"
  71. static Slapi_PluginDesc pdesc = { "memberof", PLUGIN_MAGIC_VENDOR_STR,
  72. PRODUCTTEXT, "memberof plugin" };
  73. static void* _PluginID = NULL;
  74. static Slapi_Mutex *memberof_operation_lock = 0;
  75. MemberOfConfig *qsortConfig = 0;
  76. typedef struct _memberofstringll
  77. {
  78. const char *dn;
  79. void *next;
  80. } memberofstringll;
  81. typedef struct _memberof_get_groups_data
  82. {
  83. MemberOfConfig *config;
  84. Slapi_Value *memberdn_val;
  85. Slapi_ValueSet **groupvals;
  86. } memberof_get_groups_data;
  87. /*** function prototypes ***/
  88. /* exported functions */
  89. int memberof_postop_init(Slapi_PBlock *pb );
  90. /* plugin callbacks */
  91. static int memberof_postop_del(Slapi_PBlock *pb );
  92. static int memberof_postop_modrdn(Slapi_PBlock *pb );
  93. static int memberof_postop_modify(Slapi_PBlock *pb );
  94. static int memberof_postop_add(Slapi_PBlock *pb );
  95. static int memberof_postop_start(Slapi_PBlock *pb);
  96. static int memberof_postop_close(Slapi_PBlock *pb);
  97. /* supporting cast */
  98. static int memberof_oktodo(Slapi_PBlock *pb);
  99. static char *memberof_getdn(Slapi_PBlock *pb);
  100. static int memberof_modop_one(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  101. char *op_this, char *op_to);
  102. static int memberof_modop_one_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  103. char *group_dn, char *op_this, char *op_to, memberofstringll *stack);
  104. static int memberof_add_one(Slapi_PBlock *pb, MemberOfConfig *config, char *addthis,
  105. char *addto);
  106. static int memberof_del_one(Slapi_PBlock *pb, MemberOfConfig *config, char *delthis,
  107. char *delfrom);
  108. static int memberof_mod_smod_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  109. char *groupdn, Slapi_Mod *smod);
  110. static int memberof_add_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  111. char *groupdn, Slapi_Mod *smod);
  112. static int memberof_del_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  113. char *groupdn, Slapi_Mod *smod);
  114. static int memberof_mod_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  115. char *groupdn, Slapi_Attr *attr);
  116. static int memberof_mod_attr_list_r(Slapi_PBlock *pb, MemberOfConfig *config,
  117. int mod, char *group_dn, char *op_this, Slapi_Attr *attr, memberofstringll *stack);
  118. static int memberof_add_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  119. char *groupdn, Slapi_Attr *attr);
  120. static int memberof_del_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  121. char *groupdn, Slapi_Attr *attr);
  122. static int memberof_moddn_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  123. char *pre_dn, char *post_dn, Slapi_Attr *attr);
  124. static int memberof_replace_list(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn);
  125. static void memberof_set_plugin_id(void * plugin_id);
  126. static void *memberof_get_plugin_id();
  127. static int memberof_compare(MemberOfConfig *config, const void *a, const void *b);
  128. static int memberof_qsort_compare(const void *a, const void *b);
  129. static void memberof_load_array(Slapi_Value **array, Slapi_Attr *attr);
  130. static int memberof_del_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config, char *dn);
  131. static int memberof_call_foreach_dn(Slapi_PBlock *pb, char *dn,
  132. char *type, plugin_search_entry_callback callback, void *callback_data);
  133. static int memberof_is_direct_member(MemberOfConfig *config, Slapi_Value *groupdn,
  134. Slapi_Value *memberdn);
  135. static Slapi_ValueSet *memberof_get_groups(MemberOfConfig *config, char *memberdn);
  136. static int memberof_get_groups_r(MemberOfConfig *config, char *memberdn,
  137. memberof_get_groups_data *data);
  138. static int memberof_get_groups_callback(Slapi_Entry *e, void *callback_data);
  139. static int memberof_test_membership(Slapi_PBlock *pb, MemberOfConfig *config,
  140. char *group_dn);
  141. static int memberof_test_membership_callback(Slapi_Entry *e, void *callback_data);
  142. static int memberof_del_dn_type_callback(Slapi_Entry *e, void *callback_data);
  143. static int memberof_replace_dn_type_callback(Slapi_Entry *e, void *callback_data);
  144. static int memberof_replace_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config,
  145. char *pre_dn, char *post_dn);
  146. static int memberof_modop_one_replace_r(Slapi_PBlock *pb, MemberOfConfig *config,
  147. int mod_op, char *group_dn, char *op_this, char *replace_with, char *op_to,
  148. memberofstringll *stack);
  149. static int memberof_task_add(Slapi_PBlock *pb, Slapi_Entry *e,
  150. Slapi_Entry *eAfter, int *returncode, char *returntext,
  151. void *arg);
  152. static void memberof_task_destructor(Slapi_Task *task);
  153. static const char *fetch_attr(Slapi_Entry *e, const char *attrname,
  154. const char *default_val);
  155. static void memberof_fixup_task_thread(void *arg);
  156. static int memberof_fix_memberof(MemberOfConfig *config, char *dn, char *filter_str);
  157. static int memberof_fix_memberof_callback(Slapi_Entry *e, void *callback_data);
  158. /*** implementation ***/
  159. /*** exported functions ***/
  160. /*
  161. * memberof_postop_init()
  162. *
  163. * Register plugin call backs
  164. *
  165. */
  166. int
  167. memberof_postop_init(Slapi_PBlock *pb)
  168. {
  169. int ret = 0;
  170. char *memberof_plugin_identity = 0;
  171. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  172. "--> memberof_postop_init\n" );
  173. /*
  174. * Get plugin identity and stored it for later use
  175. * Used for internal operations
  176. */
  177. slapi_pblock_get (pb, SLAPI_PLUGIN_IDENTITY, &memberof_plugin_identity);
  178. PR_ASSERT (memberof_plugin_identity);
  179. memberof_set_plugin_id(memberof_plugin_identity);
  180. if ( slapi_pblock_set( pb, SLAPI_PLUGIN_VERSION,
  181. SLAPI_PLUGIN_VERSION_01 ) != 0 ||
  182. slapi_pblock_set( pb, SLAPI_PLUGIN_DESCRIPTION,
  183. (void *)&pdesc ) != 0 ||
  184. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_DELETE_FN,
  185. (void *) memberof_postop_del ) != 0 ||
  186. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_MODRDN_FN,
  187. (void *) memberof_postop_modrdn ) != 0 ||
  188. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_MODIFY_FN,
  189. (void *) memberof_postop_modify ) != 0 ||
  190. slapi_pblock_set( pb, SLAPI_PLUGIN_POST_ADD_FN,
  191. (void *) memberof_postop_add ) != 0 ||
  192. slapi_pblock_set(pb, SLAPI_PLUGIN_START_FN,
  193. (void *) memberof_postop_start ) != 0 ||
  194. slapi_pblock_set(pb, SLAPI_PLUGIN_CLOSE_FN,
  195. (void *) memberof_postop_close ) != 0)
  196. {
  197. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  198. "memberof_postop_init failed\n" );
  199. ret = -1;
  200. }
  201. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  202. "<-- memberof_postop_init\n" );
  203. return ret;
  204. }
  205. /*
  206. * memberof_postop_start()
  207. *
  208. * Do plugin start up stuff
  209. *
  210. */
  211. int memberof_postop_start(Slapi_PBlock *pb)
  212. {
  213. int rc = 0;
  214. Slapi_Entry *config_e = NULL; /* entry containing plugin config */
  215. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  216. "--> memberof_postop_start\n" );
  217. memberof_operation_lock = slapi_new_mutex();
  218. if(0 == memberof_operation_lock)
  219. {
  220. rc = -1;
  221. goto bail;
  222. }
  223. if ( slapi_pblock_get( pb, SLAPI_ADD_ENTRY, &config_e ) != 0 ) {
  224. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  225. "missing config entry\n" );
  226. rc = -1;
  227. goto bail;
  228. }
  229. if (( rc = memberof_config( config_e )) != LDAP_SUCCESS ) {
  230. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  231. "configuration failed (%s)\n", ldap_err2string( rc ));
  232. return( -1 );
  233. }
  234. rc = slapi_task_register_handler("memberof task", memberof_task_add);
  235. if(rc)
  236. {
  237. goto bail;
  238. }
  239. /*
  240. * TODO: start up operation actor thread
  241. * need to get to a point where server failure
  242. * or shutdown doesn't hose our operations
  243. * so we should create a task entry that contains
  244. * all required information to complete the operation
  245. * then the tasks can be restarted safely if
  246. * interrupted
  247. */
  248. bail:
  249. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  250. "<-- memberof_postop_start\n" );
  251. return rc;
  252. }
  253. /*
  254. * memberof_postop_close()
  255. *
  256. * Do plugin shut down stuff
  257. *
  258. */
  259. int memberof_postop_close(Slapi_PBlock *pb)
  260. {
  261. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  262. "--> memberof_postop_close\n" );
  263. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  264. "<-- memberof_postop_close\n" );
  265. return 0;
  266. }
  267. /*
  268. * memberof_postop_del()
  269. *
  270. * All entries with a memberOf attribute that contains the group DN get retrieved
  271. * and have the their memberOf attribute regenerated (it is far too complex and
  272. * error prone to attempt to change only those dn values involved in this case -
  273. * mainly because the deleted group may itself be a member of other groups which
  274. * may be members of other groups etc. in a big recursive mess involving dependency
  275. * chains that must be created and traversed in order to decide if an entry should
  276. * really have those groups removed too)
  277. */
  278. int memberof_postop_del(Slapi_PBlock *pb)
  279. {
  280. int ret = 0;
  281. MemberOfConfig configCopy = {0, 0, 0, 0};
  282. char *dn;
  283. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  284. "--> memberof_postop_del\n" );
  285. if(memberof_oktodo(pb) && (dn = memberof_getdn(pb)))
  286. {
  287. struct slapi_entry *e = NULL;
  288. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &e );
  289. /* We need to get the config lock first. Trying to get the
  290. * config lock after we already hold the op lock can cause
  291. * a deadlock. */
  292. memberof_rlock_config();
  293. /* copy config so it doesn't change out from under us */
  294. memberof_copy_config(&configCopy, memberof_get_config());
  295. memberof_unlock_config();
  296. /* get the memberOf operation lock */
  297. memberof_lock();
  298. /* remove this group DN from the
  299. * membership lists of groups
  300. */
  301. memberof_del_dn_from_groups(pb, &configCopy, dn);
  302. /* is the entry of interest as a group? */
  303. if(e && !slapi_filter_test_simple(e, configCopy.group_filter))
  304. {
  305. Slapi_Attr *attr = 0;
  306. if(0 == slapi_entry_attr_find(e, configCopy.groupattr, &attr))
  307. {
  308. memberof_del_attr_list(pb, &configCopy, dn, attr);
  309. }
  310. }
  311. memberof_unlock();
  312. memberof_free_config(&configCopy);
  313. }
  314. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  315. "<-- memberof_postop_del\n" );
  316. return ret;
  317. }
  318. typedef struct _memberof_del_dn_data
  319. {
  320. char *dn;
  321. char *type;
  322. } memberof_del_dn_data;
  323. int memberof_del_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config, char *dn)
  324. {
  325. memberof_del_dn_data data = {dn, config->groupattr};
  326. return memberof_call_foreach_dn(pb, dn,
  327. config->groupattr, memberof_del_dn_type_callback, &data);
  328. }
  329. int memberof_del_dn_type_callback(Slapi_Entry *e, void *callback_data)
  330. {
  331. int rc = 0;
  332. LDAPMod mod;
  333. LDAPMod *mods[2];
  334. char *val[2];
  335. Slapi_PBlock *mod_pb = 0;
  336. mod_pb = slapi_pblock_new();
  337. mods[0] = &mod;
  338. mods[1] = 0;
  339. val[0] = ((memberof_del_dn_data *)callback_data)->dn;
  340. val[1] = 0;
  341. mod.mod_op = LDAP_MOD_DELETE;
  342. mod.mod_type = ((memberof_del_dn_data *)callback_data)->type;
  343. mod.mod_values = val;
  344. slapi_modify_internal_set_pb(
  345. mod_pb, slapi_entry_get_dn(e),
  346. mods, 0, 0,
  347. memberof_get_plugin_id(), 0);
  348. slapi_modify_internal_pb(mod_pb);
  349. slapi_pblock_get(mod_pb,
  350. SLAPI_PLUGIN_INTOP_RESULT,
  351. &rc);
  352. slapi_pblock_destroy(mod_pb);
  353. return rc;
  354. }
  355. /*
  356. * Does a callback search of "type=dn" under the db suffix that "dn" is in.
  357. * If "dn" is a user, you'd want "type" to be "member". If "dn" is a group,
  358. * you could want type to be either "member" or "memberOf" depending on the
  359. * case.
  360. */
  361. int memberof_call_foreach_dn(Slapi_PBlock *pb, char *dn,
  362. char *type, plugin_search_entry_callback callback, void *callback_data)
  363. {
  364. int rc = 0;
  365. Slapi_PBlock *search_pb = slapi_pblock_new();
  366. Slapi_Backend *be = 0;
  367. Slapi_DN *sdn = 0;
  368. Slapi_DN *base_sdn = 0;
  369. char *filter_str = 0;
  370. /* get the base dn for the backend we are in
  371. (we don't support having members and groups in
  372. different backends - issues with offline / read only backends)
  373. */
  374. sdn = slapi_sdn_new_dn_byref(dn);
  375. be = slapi_be_select(sdn);
  376. if(be)
  377. {
  378. base_sdn = (Slapi_DN*)slapi_be_getsuffix(be,0);
  379. }
  380. if(base_sdn)
  381. {
  382. filter_str = slapi_ch_smprintf("(%s=%s)", type, dn);
  383. }
  384. if(filter_str)
  385. {
  386. slapi_search_internal_set_pb(search_pb, slapi_sdn_get_dn(base_sdn),
  387. LDAP_SCOPE_SUBTREE, filter_str, 0, 0,
  388. 0, 0,
  389. memberof_get_plugin_id(),
  390. 0);
  391. slapi_search_internal_callback_pb(search_pb,
  392. callback_data,
  393. 0, callback,
  394. 0);
  395. }
  396. slapi_sdn_free(&sdn);
  397. slapi_pblock_destroy(search_pb);
  398. slapi_ch_free_string(&filter_str);
  399. return rc;
  400. }
  401. /*
  402. * memberof_postop_modrdn()
  403. *
  404. * All entries with a memberOf attribute that contains the old group DN get retrieved
  405. * and have the old group DN deleted and the new group DN added to their memberOf attribute
  406. */
  407. int memberof_postop_modrdn(Slapi_PBlock *pb)
  408. {
  409. int ret = 0;
  410. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  411. "--> memberof_postop_modrdn\n" );
  412. if(memberof_oktodo(pb))
  413. {
  414. MemberOfConfig *mainConfig = 0;
  415. MemberOfConfig configCopy = {0, 0, 0, 0};
  416. struct slapi_entry *pre_e = NULL;
  417. struct slapi_entry *post_e = NULL;
  418. char *pre_dn = 0;
  419. char *post_dn = 0;
  420. int interested = 0;
  421. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &pre_e );
  422. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &post_e );
  423. if(pre_e && post_e)
  424. {
  425. pre_dn = slapi_entry_get_ndn(pre_e);
  426. post_dn = slapi_entry_get_ndn(post_e);
  427. }
  428. /* is the entry of interest? */
  429. memberof_rlock_config();
  430. mainConfig = memberof_get_config();
  431. if(pre_dn && post_dn &&
  432. !slapi_filter_test_simple(post_e, mainConfig->group_filter))
  433. {
  434. interested = 1;
  435. /* copy config so it doesn't change out from under us */
  436. memberof_copy_config(&configCopy, mainConfig);
  437. }
  438. memberof_unlock_config();
  439. if(interested)
  440. {
  441. Slapi_Attr *attr = 0;
  442. memberof_lock();
  443. /* get a list of member attributes present in the group
  444. * entry that is being renamed. */
  445. if(0 == slapi_entry_attr_find(post_e, configCopy.groupattr, &attr))
  446. {
  447. memberof_moddn_attr_list(pb, &configCopy, pre_dn, post_dn, attr);
  448. }
  449. /* modrdn must change the dns in groups that have
  450. * this group as a member.
  451. */
  452. memberof_replace_dn_from_groups(pb, &configCopy, pre_dn, post_dn);
  453. memberof_unlock();
  454. memberof_free_config(&configCopy);
  455. }
  456. }
  457. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  458. "<-- memberof_postop_modrdn\n" );
  459. return ret;
  460. }
  461. typedef struct _replace_dn_data
  462. {
  463. char *pre_dn;
  464. char *post_dn;
  465. char *type;
  466. } replace_dn_data;
  467. int memberof_replace_dn_from_groups(Slapi_PBlock *pb, MemberOfConfig *config,
  468. char *pre_dn, char *post_dn)
  469. {
  470. replace_dn_data data = {pre_dn, post_dn, config->groupattr};
  471. return memberof_call_foreach_dn(pb, pre_dn, config->groupattr,
  472. memberof_replace_dn_type_callback, &data);
  473. }
  474. int memberof_replace_dn_type_callback(Slapi_Entry *e, void *callback_data)
  475. {
  476. int rc = 0;
  477. LDAPMod delmod;
  478. LDAPMod addmod;
  479. LDAPMod *mods[3];
  480. char *delval[2];
  481. char *addval[2];
  482. Slapi_PBlock *mod_pb = 0;
  483. mod_pb = slapi_pblock_new();
  484. mods[0] = &delmod;
  485. mods[1] = &addmod;
  486. mods[2] = 0;
  487. delval[0] = ((replace_dn_data *)callback_data)->pre_dn;
  488. delval[1] = 0;
  489. delmod.mod_op = LDAP_MOD_DELETE;
  490. delmod.mod_type = ((replace_dn_data *)callback_data)->type;
  491. delmod.mod_values = delval;
  492. addval[0] = ((replace_dn_data *)callback_data)->post_dn;
  493. addval[1] = 0;
  494. addmod.mod_op = LDAP_MOD_ADD;
  495. addmod.mod_type = ((replace_dn_data *)callback_data)->type;
  496. addmod.mod_values = addval;
  497. slapi_modify_internal_set_pb(
  498. mod_pb, slapi_entry_get_dn(e),
  499. mods, 0, 0,
  500. memberof_get_plugin_id(), 0);
  501. slapi_modify_internal_pb(mod_pb);
  502. slapi_pblock_get(mod_pb,
  503. SLAPI_PLUGIN_INTOP_RESULT,
  504. &rc);
  505. slapi_pblock_destroy(mod_pb);
  506. return rc;
  507. }
  508. /*
  509. * memberof_postop_modify()
  510. *
  511. * Added members are retrieved and have the group DN added to their memberOf attribute
  512. * Deleted members are retrieved and have the group DN deleted from their memberOf attribute
  513. * On replace of the membership attribute values:
  514. * 1. Sort old and new values
  515. * 2. Iterate through both lists at same time
  516. * 3. Any value not in old list but in new list - add group DN to memberOf attribute
  517. * 4. Any value in old list but not in new list - remove group DN from memberOf attribute
  518. *
  519. * Note: this will suck for large groups but nonetheless is optimal (it's linear) given
  520. * current restrictions i.e. originally adding members in sorted order would allow
  521. * us to sort one list only (the new one) but that is under server control, not this plugin
  522. */
  523. int memberof_postop_modify(Slapi_PBlock *pb)
  524. {
  525. int ret = 0;
  526. char *dn = 0;
  527. Slapi_Mods *smods = 0;
  528. Slapi_Mod *smod = 0;
  529. LDAPMod **mods;
  530. Slapi_Mod *next_mod = 0;
  531. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  532. "--> memberof_postop_modify\n" );
  533. if(memberof_oktodo(pb) &&
  534. (dn = memberof_getdn(pb)))
  535. {
  536. int config_copied = 0;
  537. MemberOfConfig *mainConfig = 0;
  538. MemberOfConfig configCopy = {0, 0, 0, 0};
  539. /* get the mod set */
  540. slapi_pblock_get(pb, SLAPI_MODIFY_MODS, &mods);
  541. smods = slapi_mods_new();
  542. slapi_mods_init_byref(smods, mods);
  543. next_mod = slapi_mod_new();
  544. smod = slapi_mods_get_first_smod(smods, next_mod);
  545. while(smod)
  546. {
  547. int interested = 0;
  548. char *type = (char *)slapi_mod_get_type(smod);
  549. /* We only want to copy the config if we encounter an
  550. * operation that we need to act on. We also want to
  551. * only copy the config the first time it's needed so
  552. * it remains the same for all mods in the operation,
  553. * despite any config changes that may be made. */
  554. if (!config_copied)
  555. {
  556. memberof_rlock_config();
  557. mainConfig = memberof_get_config();
  558. if(slapi_attr_types_equivalent(type, mainConfig->groupattr))
  559. {
  560. interested = 1;
  561. /* copy config so it doesn't change out from under us */
  562. memberof_copy_config(&configCopy, mainConfig);
  563. config_copied = 1;
  564. }
  565. memberof_unlock_config();
  566. } else {
  567. if(slapi_attr_types_equivalent(type, configCopy.groupattr))
  568. {
  569. interested = 1;
  570. }
  571. }
  572. if(interested)
  573. {
  574. int op = slapi_mod_get_operation(smod);
  575. memberof_lock();
  576. /* the modify op decides the function */
  577. switch(op & ~LDAP_MOD_BVALUES)
  578. {
  579. case LDAP_MOD_ADD:
  580. {
  581. /* add group DN to targets */
  582. memberof_add_smod_list(pb, &configCopy, dn, smod);
  583. break;
  584. }
  585. case LDAP_MOD_DELETE:
  586. {
  587. /* If there are no values in the smod, we should
  588. * just do a replace instead. The user is just
  589. * trying to delete all members from this group
  590. * entry, which the replace code deals with. */
  591. if (slapi_mod_get_num_values(smod) == 0)
  592. {
  593. memberof_replace_list(pb, &configCopy, dn);
  594. }
  595. else
  596. {
  597. /* remove group DN from target values in smod*/
  598. memberof_del_smod_list(pb, &configCopy, dn, smod);
  599. }
  600. break;
  601. }
  602. case LDAP_MOD_REPLACE:
  603. {
  604. /* replace current values */
  605. memberof_replace_list(pb, &configCopy, dn);
  606. break;
  607. }
  608. default:
  609. {
  610. slapi_log_error(
  611. SLAPI_LOG_PLUGIN,
  612. MEMBEROF_PLUGIN_SUBSYSTEM,
  613. "memberof_postop_modify: unknown mod type\n" );
  614. break;
  615. }
  616. }
  617. memberof_unlock();
  618. }
  619. slapi_mod_done(next_mod);
  620. smod = slapi_mods_get_next_smod(smods, next_mod);
  621. }
  622. if (config_copied)
  623. {
  624. memberof_free_config(&configCopy);
  625. }
  626. slapi_mod_free(&next_mod);
  627. slapi_mods_free(&smods);
  628. }
  629. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  630. "<-- memberof_postop_modify\n" );
  631. return ret;
  632. }
  633. /*
  634. * memberof_postop_add()
  635. *
  636. * All members in the membership attribute of the new entry get retrieved
  637. * and have the group DN added to their memberOf attribute
  638. */
  639. int memberof_postop_add(Slapi_PBlock *pb)
  640. {
  641. int ret = 0;
  642. int interested = 0;
  643. char *dn = 0;
  644. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  645. "--> memberof_postop_add\n" );
  646. if(memberof_oktodo(pb) && (dn = memberof_getdn(pb)))
  647. {
  648. MemberOfConfig *mainConfig = 0;
  649. MemberOfConfig configCopy = {0, 0, 0, 0};
  650. struct slapi_entry *e = NULL;
  651. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &e );
  652. /* is the entry of interest? */
  653. memberof_rlock_config();
  654. mainConfig = memberof_get_config();
  655. if(e && !slapi_filter_test_simple(e, mainConfig->group_filter))
  656. {
  657. interested = 1;
  658. /* copy config so it doesn't change out from under us */
  659. memberof_copy_config(&configCopy, mainConfig);
  660. }
  661. memberof_unlock_config();
  662. if(interested)
  663. {
  664. Slapi_Attr *attr = 0;
  665. memberof_lock();
  666. if(0 == slapi_entry_attr_find(e, configCopy.groupattr, &attr))
  667. {
  668. memberof_add_attr_list(pb, &configCopy, dn, attr);
  669. }
  670. memberof_unlock();
  671. memberof_free_config(&configCopy);
  672. }
  673. }
  674. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  675. "<-- memberof_postop_add\n" );
  676. return ret;
  677. }
  678. /*** Support functions ***/
  679. /*
  680. * memberof_oktodo()
  681. *
  682. * Check that the op succeeded
  683. * Note: we also respond to replicated ops so we don't test for that
  684. * this does require that the memberOf attribute not be replicated
  685. * and this means that memberof is consistent with local state
  686. * not the network system state
  687. *
  688. */
  689. int memberof_oktodo(Slapi_PBlock *pb)
  690. {
  691. int ret = 1;
  692. int oprc = 0;
  693. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  694. "--> memberof_postop_oktodo\n" );
  695. if(slapi_pblock_get(pb, SLAPI_PLUGIN_OPRETURN, &oprc) != 0)
  696. {
  697. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  698. "memberof_postop_oktodo: could not get parameters\n" );
  699. ret = -1;
  700. }
  701. /* this plugin should only execute if the operation succeeded
  702. */
  703. if(oprc != 0)
  704. {
  705. ret = 0;
  706. }
  707. slapi_log_error( SLAPI_LOG_TRACE, MEMBEROF_PLUGIN_SUBSYSTEM,
  708. "<-- memberof_postop_oktodo\n" );
  709. return ret;
  710. }
  711. /*
  712. * memberof_getdn()
  713. *
  714. * Get dn of target entry
  715. *
  716. */
  717. char *memberof_getdn(Slapi_PBlock *pb)
  718. {
  719. char *dn = 0;
  720. slapi_pblock_get(pb, SLAPI_TARGET_DN, &dn);
  721. return dn;
  722. }
  723. /*
  724. * memberof_modop_one()
  725. *
  726. * Perform op on memberof attribute of op_to using op_this as the value
  727. * However, if op_to happens to be a group, we must arrange for the group
  728. * members to have the mod performed on them instead, and we must take
  729. * care to not recurse when we have visted a group before
  730. *
  731. * Also, we must not delete entries that are a member of the group
  732. */
  733. int memberof_modop_one(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  734. char *op_this, char *op_to)
  735. {
  736. return memberof_modop_one_r(pb, config, mod_op, op_this, op_this, op_to, 0);
  737. }
  738. /* memberof_modop_one_r()
  739. *
  740. * recursive function to perform above (most things don't need the replace arg)
  741. */
  742. int memberof_modop_one_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod_op,
  743. char *group_dn, char *op_this, char *op_to, memberofstringll *stack)
  744. {
  745. return memberof_modop_one_replace_r(
  746. pb, config, mod_op, group_dn, op_this, 0, op_to, stack);
  747. }
  748. /* memberof_modop_one_replace_r()
  749. *
  750. * recursive function to perform above (with added replace arg)
  751. */
  752. int memberof_modop_one_replace_r(Slapi_PBlock *pb, MemberOfConfig *config,
  753. int mod_op, char *group_dn, char *op_this, char *replace_with,
  754. char *op_to, memberofstringll *stack)
  755. {
  756. int rc = 0;
  757. LDAPMod mod;
  758. LDAPMod replace_mod;
  759. LDAPMod *mods[3];
  760. char *val[2];
  761. char *replace_val[2];
  762. Slapi_PBlock *mod_pb = 0;
  763. char *attrlist[2] = {config->groupattr,0};
  764. Slapi_DN *op_to_sdn = 0;
  765. Slapi_Entry *e = 0;
  766. memberofstringll *ll = 0;
  767. char *op_str = 0;
  768. Slapi_Value *to_dn_val = slapi_value_new_string(op_to);
  769. Slapi_Value *this_dn_val = slapi_value_new_string(op_this);
  770. /* determine if this is a group op or single entry */
  771. op_to_sdn = slapi_sdn_new_dn_byref(op_to);
  772. slapi_search_internal_get_entry( op_to_sdn, attrlist,
  773. &e, memberof_get_plugin_id());
  774. if(!e)
  775. {
  776. /* In the case of a delete, we need to worry about the
  777. * missing entry being a nested group. There's a small
  778. * window where another thread may have deleted a nested
  779. * group that our group_dn entry refers to. This has the
  780. * potential of us missing some indirect member entries
  781. * that need to be updated. */
  782. if(LDAP_MOD_DELETE == mod_op)
  783. {
  784. Slapi_PBlock *search_pb = slapi_pblock_new();
  785. Slapi_DN *base_sdn = 0;
  786. Slapi_Backend *be = 0;
  787. char *filter_str = 0;
  788. int n_entries = 0;
  789. /* We can't tell for sure if the op_to entry is a
  790. * user or a group since the entry doesn't exist
  791. * anymore. We can safely ignore the missing entry
  792. * if no other entries have a memberOf attribute that
  793. * points to the missing entry. */
  794. be = slapi_be_select(op_to_sdn);
  795. if(be)
  796. {
  797. base_sdn = (Slapi_DN*)slapi_be_getsuffix(be,0);
  798. }
  799. if(base_sdn)
  800. {
  801. filter_str = slapi_ch_smprintf("(%s=%s)",
  802. config->memberof_attr, op_to);
  803. }
  804. if(filter_str)
  805. {
  806. slapi_search_internal_set_pb(search_pb, slapi_sdn_get_dn(base_sdn),
  807. LDAP_SCOPE_SUBTREE, filter_str, 0, 0, 0, 0,
  808. memberof_get_plugin_id(), 0);
  809. if (slapi_search_internal_pb(search_pb))
  810. {
  811. /* get result and log an error */
  812. int res = 0;
  813. slapi_pblock_get(search_pb, SLAPI_PLUGIN_INTOP_RESULT, &res);
  814. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  815. "memberof_modop_one_replace_r: error searching for members: "
  816. "%d", res);
  817. } else {
  818. slapi_pblock_get(search_pb, SLAPI_NENTRIES, &n_entries);
  819. if(n_entries > 0)
  820. {
  821. /* We want to fixup the membership for the
  822. * entries that referred to the missing group
  823. * entry. This will fix the references to
  824. * the missing group as well as the group
  825. * represented by op_this. */
  826. memberof_test_membership(pb, config, op_to);
  827. }
  828. }
  829. slapi_free_search_results_internal(search_pb);
  830. slapi_ch_free_string(&filter_str);
  831. }
  832. slapi_pblock_destroy(search_pb);
  833. }
  834. goto bail;
  835. }
  836. if(LDAP_MOD_DELETE == mod_op)
  837. {
  838. op_str = "DELETE";
  839. }
  840. else if(LDAP_MOD_ADD == mod_op)
  841. {
  842. op_str = "ADD";
  843. }
  844. else if(LDAP_MOD_REPLACE == mod_op)
  845. {
  846. op_str = "REPLACE";
  847. }
  848. else
  849. {
  850. op_str = "UNKNOWN";
  851. }
  852. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  853. "memberof_modop_one_replace_r: %s %s in %s\n"
  854. ,op_str, op_this, op_to);
  855. if(!slapi_filter_test_simple(e, config->group_filter))
  856. {
  857. /* group */
  858. Slapi_Value *ll_dn_val = 0;
  859. Slapi_Attr *members = 0;
  860. ll = stack;
  861. /* have we been here before? */
  862. while(ll)
  863. {
  864. ll_dn_val = slapi_value_new_string(ll->dn);
  865. if(0 == memberof_compare(config, &ll_dn_val, &to_dn_val))
  866. {
  867. slapi_value_free(&ll_dn_val);
  868. /* someone set up infinitely
  869. recursive groups - bail out */
  870. slapi_log_error( SLAPI_LOG_PLUGIN,
  871. MEMBEROF_PLUGIN_SUBSYSTEM,
  872. "memberof_modop_one_replace_r: group recursion"
  873. " detected in %s\n"
  874. ,op_to);
  875. goto bail;
  876. }
  877. slapi_value_free(&ll_dn_val);
  878. ll = ll->next;
  879. }
  880. /* do op on group */
  881. slapi_log_error( SLAPI_LOG_PLUGIN,
  882. MEMBEROF_PLUGIN_SUBSYSTEM,
  883. "memberof_modop_one_replace_r: descending into group %s\n",
  884. op_to);
  885. /* Add the nested group's DN to the stack so we can detect loops later. */
  886. ll = (memberofstringll*)slapi_ch_malloc(sizeof(memberofstringll));
  887. ll->dn = op_to;
  888. ll->next = stack;
  889. slapi_entry_attr_find( e, config->groupattr, &members );
  890. if(members)
  891. {
  892. memberof_mod_attr_list_r(pb, config, mod_op, group_dn, op_this, members, ll);
  893. }
  894. {
  895. /* crazyness follows:
  896. * strict-aliasing doesn't like the required cast
  897. * to void for slapi_ch_free so we are made to
  898. * juggle to get a normal thing done
  899. */
  900. void *pll = ll;
  901. slapi_ch_free(&pll);
  902. ll = 0;
  903. }
  904. }
  905. /* continue with operation */
  906. {
  907. /* We want to avoid listing a group as a memberOf itself
  908. * in case someone set up a circular grouping.
  909. */
  910. if (0 == memberof_compare(config, &this_dn_val, &to_dn_val))
  911. {
  912. const char *strval = "NULL";
  913. if (this_dn_val) {
  914. strval = slapi_value_get_string(this_dn_val);
  915. }
  916. slapi_log_error( SLAPI_LOG_PLUGIN,
  917. MEMBEROF_PLUGIN_SUBSYSTEM,
  918. "memberof_modop_one_replace_r: not processing memberOf "
  919. "operations on self entry: %s\n", strval);
  920. goto bail;
  921. }
  922. /* For add and del modify operations, we just regenerate the
  923. * memberOf attribute. */
  924. if(LDAP_MOD_DELETE == mod_op || LDAP_MOD_ADD == mod_op)
  925. {
  926. /* find parent groups and replace our member attr */
  927. memberof_fix_memberof_callback(e, config);
  928. } else {
  929. /* single entry - do mod */
  930. mod_pb = slapi_pblock_new();
  931. mods[0] = &mod;
  932. if(LDAP_MOD_REPLACE == mod_op)
  933. {
  934. mods[1] = &replace_mod;
  935. mods[2] = 0;
  936. }
  937. else
  938. {
  939. mods[1] = 0;
  940. }
  941. val[0] = op_this;
  942. val[1] = 0;
  943. mod.mod_op = LDAP_MOD_REPLACE == mod_op?LDAP_MOD_DELETE:mod_op;
  944. mod.mod_type = config->memberof_attr;
  945. mod.mod_values = val;
  946. if(LDAP_MOD_REPLACE == mod_op)
  947. {
  948. replace_val[0] = replace_with;
  949. replace_val[1] = 0;
  950. replace_mod.mod_op = LDAP_MOD_ADD;
  951. replace_mod.mod_type = config->memberof_attr;
  952. replace_mod.mod_values = replace_val;
  953. }
  954. slapi_modify_internal_set_pb(
  955. mod_pb, op_to,
  956. mods, 0, 0,
  957. memberof_get_plugin_id(), 0);
  958. slapi_modify_internal_pb(mod_pb);
  959. slapi_pblock_get(mod_pb,
  960. SLAPI_PLUGIN_INTOP_RESULT,
  961. &rc);
  962. slapi_pblock_destroy(mod_pb);
  963. }
  964. }
  965. bail:
  966. slapi_sdn_free(&op_to_sdn);
  967. slapi_value_free(&to_dn_val);
  968. slapi_value_free(&this_dn_val);
  969. slapi_entry_free(e);
  970. return rc;
  971. }
  972. /*
  973. * memberof_add_one()
  974. *
  975. * Add addthis DN to the memberof attribute of addto
  976. *
  977. */
  978. int memberof_add_one(Slapi_PBlock *pb, MemberOfConfig *config, char *addthis, char *addto)
  979. {
  980. return memberof_modop_one(pb, config, LDAP_MOD_ADD, addthis, addto);
  981. }
  982. /*
  983. * memberof_del_one()
  984. *
  985. * Delete delthis DN from the memberof attribute of delfrom
  986. *
  987. */
  988. int memberof_del_one(Slapi_PBlock *pb, MemberOfConfig *config, char *delthis, char *delfrom)
  989. {
  990. return memberof_modop_one(pb, config, LDAP_MOD_DELETE, delthis, delfrom);
  991. }
  992. /*
  993. * memberof_mod_smod_list()
  994. *
  995. * Perform mod for group DN to the memberof attribute of the list of targets
  996. *
  997. */
  998. int memberof_mod_smod_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  999. char *group_dn, Slapi_Mod *smod)
  1000. {
  1001. int rc = 0;
  1002. struct berval *bv = slapi_mod_get_first_value(smod);
  1003. int last_size = 0;
  1004. char *last_str = 0;
  1005. while(bv)
  1006. {
  1007. char *dn_str = 0;
  1008. if(last_size > bv->bv_len)
  1009. {
  1010. dn_str = last_str;
  1011. }
  1012. else
  1013. {
  1014. int the_size = (bv->bv_len * 2) + 1;
  1015. if(last_str)
  1016. slapi_ch_free_string(&last_str);
  1017. dn_str = (char*)slapi_ch_malloc(the_size);
  1018. last_str = dn_str;
  1019. last_size = the_size;
  1020. }
  1021. memset(dn_str, 0, last_size);
  1022. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1023. memberof_modop_one(pb, config, mod, group_dn, dn_str);
  1024. bv = slapi_mod_get_next_value(smod);
  1025. }
  1026. if(last_str)
  1027. slapi_ch_free_string(&last_str);
  1028. return rc;
  1029. }
  1030. /*
  1031. * memberof_add_smod_list()
  1032. *
  1033. * Add group DN to the memberof attribute of the list of targets
  1034. *
  1035. */
  1036. int memberof_add_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1037. char *groupdn, Slapi_Mod *smod)
  1038. {
  1039. return memberof_mod_smod_list(pb, config, LDAP_MOD_ADD, groupdn, smod);
  1040. }
  1041. /*
  1042. * memberof_del_smod_list()
  1043. *
  1044. * Remove group DN from the memberof attribute of the list of targets
  1045. *
  1046. */
  1047. int memberof_del_smod_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1048. char *groupdn, Slapi_Mod *smod)
  1049. {
  1050. return memberof_mod_smod_list(pb, config, LDAP_MOD_DELETE, groupdn, smod);
  1051. }
  1052. /**
  1053. * Plugin identity mgmt
  1054. */
  1055. void memberof_set_plugin_id(void * plugin_id)
  1056. {
  1057. _PluginID=plugin_id;
  1058. }
  1059. void * memberof_get_plugin_id()
  1060. {
  1061. return _PluginID;
  1062. }
  1063. /*
  1064. * memberof_mod_attr_list()
  1065. *
  1066. * Perform mod for group DN to the memberof attribute of the list of targets
  1067. *
  1068. */
  1069. int memberof_mod_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  1070. char *group_dn, Slapi_Attr *attr)
  1071. {
  1072. return memberof_mod_attr_list_r(pb, config, mod, group_dn, group_dn, attr, 0);
  1073. }
  1074. int memberof_mod_attr_list_r(Slapi_PBlock *pb, MemberOfConfig *config, int mod,
  1075. char *group_dn, char *op_this, Slapi_Attr *attr, memberofstringll *stack)
  1076. {
  1077. int rc = 0;
  1078. Slapi_Value *val = 0;
  1079. Slapi_Value *op_this_val = 0;
  1080. int last_size = 0;
  1081. char *last_str = 0;
  1082. int hint = slapi_attr_first_value(attr, &val);
  1083. op_this_val = slapi_value_new_string(op_this);
  1084. while(val)
  1085. {
  1086. char *dn_str = 0;
  1087. struct berval *bv = 0;
  1088. /* We don't want to process a memberOf operation on ourselves. */
  1089. if(0 != memberof_compare(config, &val, &op_this_val))
  1090. {
  1091. bv = (struct berval *)slapi_value_get_berval(val);
  1092. if(last_size > bv->bv_len)
  1093. {
  1094. dn_str = last_str;
  1095. }
  1096. else
  1097. {
  1098. int the_size = (bv->bv_len * 2) + 1;
  1099. if(last_str)
  1100. slapi_ch_free_string(&last_str);
  1101. dn_str = (char*)slapi_ch_malloc(the_size);
  1102. last_str = dn_str;
  1103. last_size = the_size;
  1104. }
  1105. memset(dn_str, 0, last_size);
  1106. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1107. /* If we're doing a replace (as we would in the MODRDN case), we need
  1108. * to specify the new group DN value */
  1109. if(mod == LDAP_MOD_REPLACE)
  1110. {
  1111. memberof_modop_one_replace_r(pb, config, mod, group_dn, op_this,
  1112. group_dn, dn_str, stack);
  1113. }
  1114. else
  1115. {
  1116. memberof_modop_one_r(pb, config, mod, group_dn, op_this, dn_str, stack);
  1117. }
  1118. }
  1119. hint = slapi_attr_next_value(attr, hint, &val);
  1120. }
  1121. slapi_value_free(&op_this_val);
  1122. if(last_str)
  1123. slapi_ch_free_string(&last_str);
  1124. return rc;
  1125. }
  1126. /*
  1127. * memberof_add_attr_list()
  1128. *
  1129. * Add group DN to the memberof attribute of the list of targets
  1130. *
  1131. */
  1132. int memberof_add_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, char *groupdn,
  1133. Slapi_Attr *attr)
  1134. {
  1135. return memberof_mod_attr_list(pb, config, LDAP_MOD_ADD, groupdn, attr);
  1136. }
  1137. /*
  1138. * memberof_del_attr_list()
  1139. *
  1140. * Remove group DN from the memberof attribute of the list of targets
  1141. *
  1142. */
  1143. int memberof_del_attr_list(Slapi_PBlock *pb, MemberOfConfig *config, char *groupdn,
  1144. Slapi_Attr *attr)
  1145. {
  1146. return memberof_mod_attr_list(pb, config, LDAP_MOD_DELETE, groupdn, attr);
  1147. }
  1148. /*
  1149. * memberof_moddn_attr_list()
  1150. *
  1151. * Perform mod for group DN to the memberof attribute of the list of targets
  1152. *
  1153. */
  1154. int memberof_moddn_attr_list(Slapi_PBlock *pb, MemberOfConfig *config,
  1155. char *pre_dn, char *post_dn, Slapi_Attr *attr)
  1156. {
  1157. int rc = 0;
  1158. Slapi_Value *val = 0;
  1159. int last_size = 0;
  1160. char *last_str = 0;
  1161. int hint = slapi_attr_first_value(attr, &val);
  1162. while(val)
  1163. {
  1164. char *dn_str = 0;
  1165. struct berval *bv = (struct berval *)slapi_value_get_berval(val);
  1166. if(last_size > bv->bv_len)
  1167. {
  1168. dn_str = last_str;
  1169. }
  1170. else
  1171. {
  1172. int the_size = (bv->bv_len * 2) + 1;
  1173. if(last_str)
  1174. slapi_ch_free_string(&last_str);
  1175. dn_str = (char*)slapi_ch_malloc(the_size);
  1176. last_str = dn_str;
  1177. last_size = the_size;
  1178. }
  1179. memset(dn_str, 0, last_size);
  1180. strncpy(dn_str, bv->bv_val, (size_t)bv->bv_len);
  1181. memberof_modop_one_replace_r(pb, config, LDAP_MOD_REPLACE,
  1182. post_dn, pre_dn, post_dn, dn_str, 0);
  1183. hint = slapi_attr_next_value(attr, hint, &val);
  1184. }
  1185. if(last_str)
  1186. slapi_ch_free_string(&last_str);
  1187. return rc;
  1188. }
  1189. /* memberof_get_groups()
  1190. *
  1191. * Gets a list of all groups that an entry is a member of.
  1192. * This is done by looking only at member attribute values.
  1193. * A Slapi_ValueSet* is returned. It is up to the caller to
  1194. * free it.
  1195. */
  1196. Slapi_ValueSet *memberof_get_groups(MemberOfConfig *config, char *memberdn)
  1197. {
  1198. Slapi_Value *memberdn_val = slapi_value_new_string(memberdn);
  1199. Slapi_ValueSet *groupvals = slapi_valueset_new();
  1200. memberof_get_groups_data data = {config, memberdn_val, &groupvals};
  1201. memberof_get_groups_r(config, memberdn, &data);
  1202. slapi_value_free(&memberdn_val);
  1203. return groupvals;
  1204. }
  1205. int memberof_get_groups_r(MemberOfConfig *config, char *memberdn, memberof_get_groups_data *data)
  1206. {
  1207. /* Search for member=<memberdn>
  1208. * For each match, add it to the list, recurse and do same search */
  1209. return memberof_call_foreach_dn(NULL, memberdn, config->groupattr,
  1210. memberof_get_groups_callback, data);
  1211. }
  1212. /* memberof_get_groups_callback()
  1213. *
  1214. * Callback to perform work of memberof_get_groups()
  1215. */
  1216. int memberof_get_groups_callback(Slapi_Entry *e, void *callback_data)
  1217. {
  1218. char *group_dn = slapi_entry_get_dn(e);
  1219. Slapi_Value *group_dn_val = 0;
  1220. Slapi_ValueSet *groupvals = *((memberof_get_groups_data*)callback_data)->groupvals;
  1221. /* get the DN of the group */
  1222. group_dn_val = slapi_value_new_string(group_dn);
  1223. /* check if e is the same as our original member entry */
  1224. if (0 == memberof_compare(((memberof_get_groups_data*)callback_data)->config,
  1225. &((memberof_get_groups_data*)callback_data)->memberdn_val, &group_dn_val))
  1226. {
  1227. /* A recursive group caused us to find our original
  1228. * entry we passed to memberof_get_groups(). We just
  1229. * skip processing this entry. */
  1230. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1231. "memberof_get_groups_callback: group recursion"
  1232. " detected in %s\n" ,group_dn);
  1233. slapi_value_free(&group_dn_val);
  1234. goto bail;
  1235. }
  1236. /* have we been here before? */
  1237. if (groupvals &&
  1238. slapi_valueset_find(((memberof_get_groups_data*)callback_data)->config->group_slapiattr,
  1239. groupvals, group_dn_val))
  1240. {
  1241. /* we either hit a recursive grouping, or an entry is
  1242. * a member of a group through multiple paths. Either
  1243. * way, we can just skip processing this entry since we've
  1244. * already gone through this part of the grouping hierarchy. */
  1245. slapi_log_error( SLAPI_LOG_PLUGIN, MEMBEROF_PLUGIN_SUBSYSTEM,
  1246. "memberof_get_groups_callback: possible group recursion"
  1247. " detected in %s\n" ,group_dn);
  1248. slapi_value_free(&group_dn_val);
  1249. goto bail;
  1250. }
  1251. /* Push group_dn_val into the valueset. This memory is now owned
  1252. * by the valueset. */
  1253. slapi_valueset_add_value_ext(groupvals, group_dn_val, SLAPI_VALUE_FLAG_PASSIN);
  1254. /* now recurse to find parent groups of e */
  1255. memberof_get_groups_r(((memberof_get_groups_data*)callback_data)->config,
  1256. group_dn, callback_data);
  1257. bail:
  1258. return 0;
  1259. }
  1260. /* memberof_is_direct_member()
  1261. *
  1262. * tests for direct membership of memberdn in group groupdn
  1263. * returns non-zero when true, zero otherwise
  1264. */
  1265. int memberof_is_direct_member(MemberOfConfig *config, Slapi_Value *groupdn,
  1266. Slapi_Value *memberdn)
  1267. {
  1268. int rc = 0;
  1269. Slapi_DN *sdn = 0;
  1270. char *attrlist[2] = {config->groupattr,0};
  1271. Slapi_Entry *group_e = 0;
  1272. Slapi_Attr *attr = 0;
  1273. sdn = slapi_sdn_new_dn_byref(slapi_value_get_string(groupdn));
  1274. slapi_search_internal_get_entry(sdn, attrlist,
  1275. &group_e, memberof_get_plugin_id());
  1276. if(group_e)
  1277. {
  1278. slapi_entry_attr_find(group_e, config->groupattr, &attr );
  1279. if(attr)
  1280. {
  1281. rc = 0 == slapi_attr_value_find(
  1282. attr, slapi_value_get_berval(memberdn));
  1283. }
  1284. slapi_entry_free(group_e);
  1285. }
  1286. slapi_sdn_free(&sdn);
  1287. return rc;
  1288. }
  1289. /* memberof_test_membership()
  1290. *
  1291. * Finds all entries who are a "memberOf" the group
  1292. * represented by "group_dn". For each matching entry, we
  1293. * call memberof_test_membership_callback().
  1294. *
  1295. * for each attribute in the memberof attribute
  1296. * determine if the entry is still a member.
  1297. *
  1298. * test each for direct membership
  1299. * move groups entry is memberof to member group
  1300. * test remaining groups for membership in member groups
  1301. * iterate until a pass fails to move a group over to member groups
  1302. * remaining groups should be deleted
  1303. */
  1304. int memberof_test_membership(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn)
  1305. {
  1306. return memberof_call_foreach_dn(pb, group_dn, config->memberof_attr,
  1307. memberof_test_membership_callback , config);
  1308. }
  1309. /*
  1310. * memberof_test_membership_callback()
  1311. *
  1312. * A callback function to do the work of memberof_test_membership().
  1313. * Note that this not only tests membership, but updates the memberOf
  1314. * attributes in the entry to be correct.
  1315. */
  1316. int memberof_test_membership_callback(Slapi_Entry *e, void *callback_data)
  1317. {
  1318. int rc = 0;
  1319. Slapi_Attr *attr = 0;
  1320. int total = 0;
  1321. Slapi_Value **member_array = 0;
  1322. Slapi_Value **candidate_array = 0;
  1323. Slapi_Value *entry_dn = 0;
  1324. MemberOfConfig *config = (MemberOfConfig *)callback_data;
  1325. entry_dn = slapi_value_new_string(slapi_entry_get_dn(e));
  1326. if(0 == entry_dn)
  1327. {
  1328. goto bail;
  1329. }
  1330. /* divide groups into member and non-member lists */
  1331. slapi_entry_attr_find(e, config->memberof_attr, &attr );
  1332. if(attr)
  1333. {
  1334. slapi_attr_get_numvalues( attr, &total);
  1335. if(total)
  1336. {
  1337. Slapi_Value *val = 0;
  1338. int hint = 0;
  1339. int c_index = 0;
  1340. int m_index = 0;
  1341. int member_found = 1;
  1342. int outer_index = 0;
  1343. candidate_array =
  1344. (Slapi_Value**)
  1345. slapi_ch_malloc(sizeof(Slapi_Value*)*total);
  1346. memset(candidate_array, 0, sizeof(Slapi_Value*)*total);
  1347. member_array =
  1348. (Slapi_Value**)
  1349. slapi_ch_malloc(sizeof(Slapi_Value*)*total);
  1350. memset(member_array, 0, sizeof(Slapi_Value*)*total);
  1351. hint = slapi_attr_first_value(attr, &val);
  1352. while(val)
  1353. {
  1354. /* test for direct membership */
  1355. if(memberof_is_direct_member(config, val, entry_dn))
  1356. {
  1357. /* it is a member */
  1358. member_array[m_index] = val;
  1359. m_index++;
  1360. }
  1361. else
  1362. {
  1363. /* not a member, still a candidate */
  1364. candidate_array[c_index] = val;
  1365. c_index++;
  1366. }
  1367. hint = slapi_attr_next_value(attr, hint, &val);
  1368. }
  1369. /* now iterate over members testing for membership
  1370. in candidate groups and moving candidates to members
  1371. when successful, quit when a full iteration adds no
  1372. new members
  1373. */
  1374. while(member_found)
  1375. {
  1376. member_found = 0;
  1377. /* For each group that this entry is a verified member of, see if
  1378. * any of the candidate groups are members. If they are, add them
  1379. * to the list of verified groups that this entry is a member of.
  1380. */
  1381. while(outer_index < m_index)
  1382. {
  1383. int inner_index = 0;
  1384. while(inner_index < c_index)
  1385. {
  1386. /* Check for a special value in this position
  1387. * that indicates that the candidate was moved
  1388. * to the member array. */
  1389. if((void*)1 ==
  1390. candidate_array[inner_index])
  1391. {
  1392. /* was moved, skip */
  1393. inner_index++;
  1394. continue;
  1395. }
  1396. if(memberof_is_direct_member(
  1397. config,
  1398. candidate_array[inner_index],
  1399. member_array[outer_index]))
  1400. {
  1401. member_array[m_index] =
  1402. candidate_array
  1403. [inner_index];
  1404. m_index++;
  1405. candidate_array[inner_index] =
  1406. (void*)1;
  1407. member_found = 1;
  1408. }
  1409. inner_index++;
  1410. }
  1411. outer_index++;
  1412. }
  1413. }
  1414. /* here we are left only with values to delete
  1415. from the memberof attribute in the candidate list
  1416. */
  1417. outer_index = 0;
  1418. while(outer_index < c_index)
  1419. {
  1420. /* Check for a special value in this position
  1421. * that indicates that the candidate was moved
  1422. * to the member array. */
  1423. if((void*)1 == candidate_array[outer_index])
  1424. {
  1425. /* item moved, skip */
  1426. outer_index++;
  1427. continue;
  1428. }
  1429. memberof_del_one(
  1430. 0, config,
  1431. (char*)slapi_value_get_string(
  1432. candidate_array[outer_index]),
  1433. (char*)slapi_value_get_string(entry_dn));
  1434. outer_index++;
  1435. }
  1436. {
  1437. /* crazyness follows:
  1438. * strict-aliasing doesn't like the required cast
  1439. * to void for slapi_ch_free so we are made to
  1440. * juggle to get a normal thing done
  1441. */
  1442. void *pmember_array = member_array;
  1443. void *pcandidate_array = candidate_array;
  1444. slapi_ch_free(&pcandidate_array);
  1445. slapi_ch_free(&pmember_array);
  1446. candidate_array = 0;
  1447. member_array = 0;
  1448. }
  1449. }
  1450. }
  1451. bail:
  1452. slapi_value_free(&entry_dn);
  1453. return rc;
  1454. }
  1455. /*
  1456. * memberof_replace_list()
  1457. *
  1458. * Perform replace the group DN list in the memberof attribute of the list of targets
  1459. *
  1460. */
  1461. int memberof_replace_list(Slapi_PBlock *pb, MemberOfConfig *config, char *group_dn)
  1462. {
  1463. struct slapi_entry *pre_e = NULL;
  1464. struct slapi_entry *post_e = NULL;
  1465. Slapi_Attr *pre_attr = 0;
  1466. Slapi_Attr *post_attr = 0;
  1467. slapi_pblock_get( pb, SLAPI_ENTRY_PRE_OP, &pre_e );
  1468. slapi_pblock_get( pb, SLAPI_ENTRY_POST_OP, &post_e );
  1469. if(pre_e && post_e)
  1470. {
  1471. slapi_entry_attr_find( pre_e, config->groupattr, &pre_attr );
  1472. slapi_entry_attr_find( post_e, config->groupattr, &post_attr );
  1473. }
  1474. if(pre_attr || post_attr)
  1475. {
  1476. int pre_total = 0;
  1477. int post_total = 0;
  1478. Slapi_Value **pre_array = 0;
  1479. Slapi_Value **post_array = 0;
  1480. int pre_index = 0;
  1481. int post_index = 0;
  1482. /* create arrays of values */
  1483. if(pre_attr)
  1484. {
  1485. slapi_attr_get_numvalues( pre_attr, &pre_total);
  1486. }
  1487. if(post_attr)
  1488. {
  1489. slapi_attr_get_numvalues( post_attr, &post_total);
  1490. }
  1491. /* Stash a plugin global pointer here and have memberof_qsort_compare
  1492. * use it. We have to do this because we use memberof_qsort_compare
  1493. * as the comparator function for qsort, which requires the function
  1494. * to only take two void* args. This is thread-safe since we only
  1495. * store and use the pointer while holding the memberOf operation
  1496. * lock. */
  1497. qsortConfig = config;
  1498. if(pre_total)
  1499. {
  1500. pre_array =
  1501. (Slapi_Value**)
  1502. slapi_ch_malloc(sizeof(Slapi_Value*)*pre_total);
  1503. memberof_load_array(pre_array, pre_attr);
  1504. qsort(
  1505. pre_array,
  1506. pre_total,
  1507. sizeof(Slapi_Value*),
  1508. memberof_qsort_compare);
  1509. }
  1510. if(post_total)
  1511. {
  1512. post_array =
  1513. (Slapi_Value**)
  1514. slapi_ch_malloc(sizeof(Slapi_Value*)*post_total);
  1515. memberof_load_array(post_array, post_attr);
  1516. qsort(
  1517. post_array,
  1518. post_total,
  1519. sizeof(Slapi_Value*),
  1520. memberof_qsort_compare);
  1521. }
  1522. qsortConfig = 0;
  1523. /* work through arrays, following these rules:
  1524. in pre, in post, do nothing
  1525. in pre, not in post, delete from entry
  1526. not in pre, in post, add to entry
  1527. */
  1528. while(pre_index < pre_total || post_index < post_total)
  1529. {
  1530. if(pre_index == pre_total)
  1531. {
  1532. /* add the rest of post */
  1533. memberof_add_one(
  1534. pb, config,
  1535. group_dn,
  1536. (char*)slapi_value_get_string(
  1537. post_array[post_index]));
  1538. post_index++;
  1539. }
  1540. else if(post_index == post_total)
  1541. {
  1542. /* delete the rest of pre */
  1543. memberof_del_one(
  1544. pb, config,
  1545. group_dn,
  1546. (char*)slapi_value_get_string(
  1547. pre_array[pre_index]));
  1548. pre_index++;
  1549. }
  1550. else
  1551. {
  1552. /* decide what to do */
  1553. int cmp = memberof_compare(
  1554. config,
  1555. &(pre_array[pre_index]),
  1556. &(post_array[post_index]));
  1557. if(cmp < 0)
  1558. {
  1559. /* delete pre array */
  1560. memberof_del_one(
  1561. pb, config,
  1562. group_dn,
  1563. (char*)slapi_value_get_string(
  1564. pre_array[pre_index]));
  1565. pre_index++;
  1566. }
  1567. else if(cmp > 0)
  1568. {
  1569. /* add post array */
  1570. memberof_add_one(
  1571. pb, config,
  1572. group_dn,
  1573. (char*)slapi_value_get_string(
  1574. post_array[post_index]));
  1575. post_index++;
  1576. }
  1577. else
  1578. {
  1579. /* do nothing, advance */
  1580. pre_index++;
  1581. post_index++;
  1582. }
  1583. }
  1584. }
  1585. slapi_ch_free((void **)&pre_array);
  1586. slapi_ch_free((void **)&post_array);
  1587. }
  1588. return 0;
  1589. }
  1590. /* memberof_load_array()
  1591. *
  1592. * put attribute values in array structure
  1593. */
  1594. void memberof_load_array(Slapi_Value **array, Slapi_Attr *attr)
  1595. {
  1596. Slapi_Value *val = 0;
  1597. int hint = slapi_attr_first_value(attr, &val);
  1598. while(val)
  1599. {
  1600. *array = val;
  1601. array++;
  1602. hint = slapi_attr_next_value(attr, hint, &val);
  1603. }
  1604. }
  1605. /* memberof_compare()
  1606. *
  1607. * compare two attr values
  1608. */
  1609. int memberof_compare(MemberOfConfig *config, const void *a, const void *b)
  1610. {
  1611. Slapi_Value *val1 = *((Slapi_Value **)a);
  1612. Slapi_Value *val2 = *((Slapi_Value **)b);
  1613. return slapi_attr_value_cmp(
  1614. config->group_slapiattr,
  1615. slapi_value_get_berval(val1),
  1616. slapi_value_get_berval(val2));
  1617. }
  1618. /* memberof_qsort_compare()
  1619. *
  1620. * This is a version of memberof_compare that uses a plugin
  1621. * global copy of the config. We'd prefer to pass in a copy
  1622. * of config that is local to the running thread, but we can't
  1623. * do this since qsort is using us as a comparator function.
  1624. * We should only use this function when using qsort, and only
  1625. * when the memberOf lock is acquired.
  1626. */
  1627. int memberof_qsort_compare(const void *a, const void *b)
  1628. {
  1629. Slapi_Value *val1 = *((Slapi_Value **)a);
  1630. Slapi_Value *val2 = *((Slapi_Value **)b);
  1631. return slapi_attr_value_cmp(
  1632. qsortConfig->group_slapiattr,
  1633. slapi_value_get_berval(val1),
  1634. slapi_value_get_berval(val2));
  1635. }
  1636. void memberof_lock()
  1637. {
  1638. slapi_lock_mutex(memberof_operation_lock);
  1639. }
  1640. void memberof_unlock()
  1641. {
  1642. slapi_unlock_mutex(memberof_operation_lock);
  1643. }
  1644. typedef struct _task_data
  1645. {
  1646. char *dn;
  1647. char *filter_str;
  1648. } task_data;
  1649. void memberof_fixup_task_thread(void *arg)
  1650. {
  1651. MemberOfConfig configCopy = {0, 0, 0, 0};
  1652. Slapi_Task *task = (Slapi_Task *)arg;
  1653. task_data *td = NULL;
  1654. int rc = 0;
  1655. /* Fetch our task data from the task */
  1656. td = (task_data *)slapi_task_get_data(task);
  1657. slapi_task_begin(task, 1);
  1658. slapi_task_log_notice(task, "Memberof task starts (arg: %s) ...\n",
  1659. td->filter_str);
  1660. /* We need to get the config lock first. Trying to get the
  1661. * config lock after we already hold the op lock can cause
  1662. * a deadlock. */
  1663. memberof_rlock_config();
  1664. /* copy config so it doesn't change out from under us */
  1665. memberof_copy_config(&configCopy, memberof_get_config());
  1666. memberof_unlock_config();
  1667. /* get the memberOf operation lock */
  1668. memberof_lock();
  1669. /* do real work */
  1670. rc = memberof_fix_memberof(&configCopy, td->dn, td->filter_str);
  1671. /* release the memberOf operation lock */
  1672. memberof_unlock();
  1673. memberof_free_config(&configCopy);
  1674. slapi_task_log_notice(task, "Memberof task finished.");
  1675. slapi_task_log_status(task, "Memberof task finished.");
  1676. slapi_task_inc_progress(task);
  1677. /* this will queue the destruction of the task */
  1678. slapi_task_finish(task, rc);
  1679. }
  1680. /* extract a single value from the entry (as a string) -- if it's not in the
  1681. * entry, the default will be returned (which can be NULL).
  1682. * you do not need to free anything returned by this.
  1683. */
  1684. const char *fetch_attr(Slapi_Entry *e, const char *attrname,
  1685. const char *default_val)
  1686. {
  1687. Slapi_Attr *attr;
  1688. Slapi_Value *val = NULL;
  1689. if (slapi_entry_attr_find(e, attrname, &attr) != 0)
  1690. return default_val;
  1691. slapi_attr_first_value(attr, &val);
  1692. return slapi_value_get_string(val);
  1693. }
  1694. int memberof_task_add(Slapi_PBlock *pb, Slapi_Entry *e,
  1695. Slapi_Entry *eAfter, int *returncode, char *returntext,
  1696. void *arg)
  1697. {
  1698. PRThread *thread = NULL;
  1699. int rv = SLAPI_DSE_CALLBACK_OK;
  1700. task_data *mytaskdata = NULL;
  1701. Slapi_Task *task = NULL;
  1702. const char *filter;
  1703. const char *dn = 0;
  1704. *returncode = LDAP_SUCCESS;
  1705. /* get arg(s) */
  1706. if ((dn = fetch_attr(e, "basedn", 0)) == NULL)
  1707. {
  1708. *returncode = LDAP_OBJECT_CLASS_VIOLATION;
  1709. rv = SLAPI_DSE_CALLBACK_ERROR;
  1710. goto out;
  1711. }
  1712. if ((filter = fetch_attr(e, "filter", "(objectclass=inetuser)")) == NULL)
  1713. {
  1714. *returncode = LDAP_OBJECT_CLASS_VIOLATION;
  1715. rv = SLAPI_DSE_CALLBACK_ERROR;
  1716. goto out;
  1717. }
  1718. /* setup our task data */
  1719. mytaskdata = (task_data*)slapi_ch_malloc(sizeof(task_data));
  1720. if (mytaskdata == NULL)
  1721. {
  1722. *returncode = LDAP_OPERATIONS_ERROR;
  1723. rv = SLAPI_DSE_CALLBACK_ERROR;
  1724. goto out;
  1725. }
  1726. mytaskdata->dn = slapi_ch_strdup(dn);
  1727. mytaskdata->filter_str = slapi_ch_strdup(filter);
  1728. /* allocate new task now */
  1729. task = slapi_new_task(slapi_entry_get_ndn(e));
  1730. /* register our destructor for cleaning up our private data */
  1731. slapi_task_set_destructor_fn(task, memberof_task_destructor);
  1732. /* Stash a pointer to our data in the task */
  1733. slapi_task_set_data(task, mytaskdata);
  1734. /* start the sample task as a separate thread */
  1735. thread = PR_CreateThread(PR_USER_THREAD, memberof_fixup_task_thread,
  1736. (void *)task, PR_PRIORITY_NORMAL, PR_GLOBAL_THREAD,
  1737. PR_UNJOINABLE_THREAD, SLAPD_DEFAULT_THREAD_STACKSIZE);
  1738. if (thread == NULL)
  1739. {
  1740. slapi_log_error( SLAPI_LOG_FATAL, MEMBEROF_PLUGIN_SUBSYSTEM,
  1741. "unable to create task thread!\n");
  1742. *returncode = LDAP_OPERATIONS_ERROR;
  1743. rv = SLAPI_DSE_CALLBACK_ERROR;
  1744. slapi_task_finish(task, *returncode);
  1745. } else {
  1746. rv = SLAPI_DSE_CALLBACK_OK;
  1747. }
  1748. out:
  1749. return rv;
  1750. }
  1751. void
  1752. memberof_task_destructor(Slapi_Task *task)
  1753. {
  1754. if (task) {
  1755. task_data *mydata = (task_data *)slapi_task_get_data(task);
  1756. if (mydata) {
  1757. slapi_ch_free_string(&mydata->dn);
  1758. slapi_ch_free_string(&mydata->filter_str);
  1759. /* Need to cast to avoid a compiler warning */
  1760. slapi_ch_free((void **)&mydata);
  1761. }
  1762. }
  1763. }
  1764. int memberof_fix_memberof(MemberOfConfig *config, char *dn, char *filter_str)
  1765. {
  1766. int rc = 0;
  1767. Slapi_PBlock *search_pb = slapi_pblock_new();
  1768. slapi_search_internal_set_pb(search_pb, dn,
  1769. LDAP_SCOPE_SUBTREE, filter_str, 0, 0,
  1770. 0, 0,
  1771. memberof_get_plugin_id(),
  1772. 0);
  1773. rc = slapi_search_internal_callback_pb(search_pb,
  1774. config,
  1775. 0, memberof_fix_memberof_callback,
  1776. 0);
  1777. slapi_pblock_destroy(search_pb);
  1778. return rc;
  1779. }
  1780. /* memberof_fix_memberof_callback()
  1781. * Add initial and/or fix up broken group list in entry
  1782. *
  1783. * 1. Remove all present memberOf values
  1784. * 2. Add direct group membership memberOf values
  1785. * 3. Add indirect group membership memberOf values
  1786. */
  1787. int memberof_fix_memberof_callback(Slapi_Entry *e, void *callback_data)
  1788. {
  1789. int rc = 0;
  1790. char *dn = slapi_entry_get_dn(e);
  1791. MemberOfConfig *config = (MemberOfConfig *)callback_data;
  1792. memberof_del_dn_data del_data = {0, config->memberof_attr};
  1793. Slapi_ValueSet *groups = 0;
  1794. /* get a list of all of the groups this user belongs to */
  1795. groups = memberof_get_groups(config, dn);
  1796. /* If we found some groups, replace the existing memberOf attribute
  1797. * with the found values. */
  1798. if (groups && slapi_valueset_count(groups))
  1799. {
  1800. Slapi_PBlock *mod_pb = slapi_pblock_new();
  1801. Slapi_Value *val = 0;
  1802. Slapi_Mod *smod;
  1803. LDAPMod **mods = (LDAPMod **) slapi_ch_malloc(2 * sizeof(LDAPMod *));
  1804. int hint = 0;
  1805. smod = slapi_mod_new();
  1806. slapi_mod_init(smod, 0);
  1807. slapi_mod_set_operation(smod, LDAP_MOD_REPLACE | LDAP_MOD_BVALUES);
  1808. slapi_mod_set_type(smod, config->memberof_attr);
  1809. /* Loop through all of our values and add them to smod */
  1810. hint = slapi_valueset_first_value(groups, &val);
  1811. while (val)
  1812. {
  1813. /* this makes a copy of the berval */
  1814. slapi_mod_add_value(smod, slapi_value_get_berval(val));
  1815. hint = slapi_valueset_next_value(groups, hint, &val);
  1816. }
  1817. mods[0] = slapi_mod_get_ldapmod_passout(smod);
  1818. mods[1] = 0;
  1819. slapi_modify_internal_set_pb(
  1820. mod_pb, dn, mods, 0, 0,
  1821. memberof_get_plugin_id(), 0);
  1822. slapi_modify_internal_pb(mod_pb);
  1823. slapi_pblock_get(mod_pb, SLAPI_PLUGIN_INTOP_RESULT, &rc);
  1824. ldap_mods_free(mods, 1);
  1825. slapi_mod_free(&smod);
  1826. slapi_pblock_destroy(mod_pb);
  1827. } else {
  1828. /* No groups were found, so remove the memberOf attribute
  1829. * from this entry. */
  1830. memberof_del_dn_type_callback(e, &del_data);
  1831. }
  1832. slapi_valueset_free(groups);
  1833. return rc;
  1834. }