posix-group-func.c 39 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030
  1. /** Author: Carsten Grzemba [email protected]>
  2. *
  3. * Copyright (C) 2011 contac Datentechnik GmbH
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License as
  7. * published by the Free Software Foundation; version 2 only
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program; if not, write to the Free Software
  16. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  17. $Id: posix-group-func.c 28 2011-05-13 14:35:29Z grzemba $
  18. */
  19. #include <string.h>
  20. #include "posix-wsp-ident.h"
  21. #include "posix-group-func.h"
  22. #include "slapi-plugin.h"
  23. #define MAX_RECURSION_DEPTH (5)
  24. Slapi_Value **
  25. valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
  26. static PRMonitor *memberuid_operation_lock = 0;
  27. void
  28. memberUidLock()
  29. {
  30. PR_EnterMonitor(memberuid_operation_lock);
  31. }
  32. void
  33. memberUidUnlock()
  34. {
  35. PR_ExitMonitor(memberuid_operation_lock);
  36. }
  37. int
  38. memberUidLockInit()
  39. {
  40. return (memberuid_operation_lock = PR_NewMonitor()) != NULL;
  41. }
  42. void
  43. memberUidLockDestroy()
  44. {
  45. PR_DestroyMonitor(memberuid_operation_lock);
  46. memberuid_operation_lock = NULL;
  47. }
  48. void
  49. addDynamicGroupIfNecessary(Slapi_Entry *entry, Slapi_Mods *smods)
  50. {
  51. Slapi_Attr *oc_attr = NULL;
  52. Slapi_Value *voc = slapi_value_new();
  53. slapi_value_init_string(voc, "dynamicGroup");
  54. slapi_entry_attr_find(entry, "objectClass", &oc_attr);
  55. if (slapi_attr_value_find(oc_attr, slapi_value_get_berval(voc)) != 0) {
  56. if (smods) {
  57. slapi_mods_add_string(smods, LDAP_MOD_ADD, "objectClass", "dynamicGroup");
  58. } else {
  59. slapi_entry_add_string(entry, "objectClass", "dynamicGroup");
  60. }
  61. }
  62. slapi_value_free(&voc);
  63. }
  64. Slapi_Entry *
  65. getEntry(const char *udn, char **attrs)
  66. {
  67. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "getEntry: search %s\n", udn);
  68. Slapi_DN *udn_sdn = slapi_sdn_new_dn_byval(udn);
  69. Slapi_Entry *result = NULL;
  70. int rc = slapi_search_internal_get_entry(udn_sdn, attrs, &result, posix_winsync_get_plugin_identity());
  71. slapi_sdn_free(&udn_sdn);
  72. if (rc == 0) {
  73. if (result != NULL) {
  74. return result; /* Must be freed */
  75. } else {
  76. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  77. "getEntry: %s not found\n", udn);
  78. }
  79. } else {
  80. slapi_log_err(SLAPI_LOG_ERR, POSIX_WINSYNC_PLUGIN_NAME,
  81. "getEntry: error searching for uid %s: %d\n", udn, rc);
  82. }
  83. return NULL;
  84. }
  85. /* search the user with DN udn and returns uid*/
  86. char *
  87. searchUid(const char *udn)
  88. {
  89. char *attrs[] = {"uid", "objectclass", NULL};
  90. Slapi_Entry *entry = getEntry(udn,
  91. /* "(|(objectclass=posixAccount)(objectclass=ldapsubentry))", */
  92. attrs);
  93. char *uid = NULL;
  94. if (entry) {
  95. Slapi_Attr *attr = NULL;
  96. Slapi_Value *v = NULL;
  97. if (slapi_entry_attr_find(entry, "uid", &attr) == 0 && hasObjectClass(entry, "posixAccount")) {
  98. slapi_attr_first_value(attr, &v);
  99. uid = slapi_ch_strdup(slapi_value_get_string(v));
  100. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  101. "searchUid: return uid %s\n", uid);
  102. } else {
  103. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  104. "searchUid: uid in %s not found\n", udn);
  105. }
  106. if (uid && posix_winsync_config_get_lowercase()) {
  107. uid = slapi_dn_ignore_case(uid);
  108. }
  109. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  110. "searchUid: About to free entry (%s)\n", udn);
  111. slapi_entry_free(entry);
  112. }
  113. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  114. "searchUid(%s): <==\n", udn);
  115. return uid;
  116. }
  117. int
  118. dn_in_set(const char *uid, char **uids)
  119. {
  120. int i;
  121. Slapi_DN *sdn_uid = NULL;
  122. Slapi_DN *sdn_ul = NULL;
  123. if (uids == NULL || uid == NULL)
  124. return false;
  125. sdn_uid = slapi_sdn_new_dn_byval(uid);
  126. sdn_ul = slapi_sdn_new();
  127. for (i = 0; uids[i]; i++) {
  128. slapi_sdn_set_dn_byref(sdn_ul, uids[i]);
  129. if (slapi_sdn_compare(sdn_uid, sdn_ul) == 0) {
  130. slapi_sdn_free(&sdn_ul);
  131. slapi_sdn_free(&sdn_uid);
  132. return true;
  133. }
  134. slapi_sdn_done(sdn_ul);
  135. }
  136. slapi_sdn_free(&sdn_ul);
  137. slapi_sdn_free(&sdn_uid);
  138. return false;
  139. }
  140. int
  141. uid_in_set(const char *uid, char **uids)
  142. {
  143. int i;
  144. if (uid == NULL)
  145. return false;
  146. for (i = 0; uids != NULL && uids[i] != NULL; i++) {
  147. Slapi_RDN *i_rdn = NULL;
  148. char *i_uid = NULL;
  149. char *t = NULL;
  150. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_set: comp %s %s \n",
  151. uid, uids[i]);
  152. i_rdn = slapi_rdn_new_dn(uids[i]);
  153. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  154. if (strncasecmp(uid, i_uid, 256) == 0) {
  155. slapi_rdn_free(&i_rdn);
  156. return true;
  157. }
  158. }
  159. slapi_rdn_free(&i_rdn);
  160. }
  161. return false;
  162. }
  163. int
  164. uid_in_valueset(const char *uid, Slapi_ValueSet *uids)
  165. {
  166. int i;
  167. Slapi_Value *v = NULL;
  168. if (uid == NULL)
  169. return false;
  170. for (i = slapi_valueset_first_value(uids, &v); i != -1;
  171. i = slapi_valueset_next_value(uids, i, &v)) {
  172. Slapi_RDN *i_rdn = NULL;
  173. char *i_uid = NULL;
  174. char *t = NULL;
  175. const char *uid_i = slapi_value_get_string(v);
  176. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_valueset: comp %s %s \n",
  177. uid, uid_i);
  178. i_rdn = slapi_rdn_new_dn(uid_i);
  179. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  180. if (strncasecmp(uid, i_uid, 256) == 0) {
  181. slapi_rdn_free(&i_rdn);
  182. return true;
  183. }
  184. }
  185. slapi_rdn_free(&i_rdn);
  186. }
  187. return false;
  188. }
  189. /* return 1 if smods already has the given mod - 0 otherwise */
  190. static int
  191. smods_has_mod(Slapi_Mods *smods, int modtype, const char *type, const char *val)
  192. {
  193. int rc = 0;
  194. Slapi_Mod *smod = slapi_mod_new(), *smodp = NULL;
  195. for (smodp = slapi_mods_get_first_smod(smods, smod);
  196. (rc == 0) && smods && (smodp != NULL);
  197. smodp = slapi_mods_get_next_smod(smods, smod)) {
  198. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), type) && ((slapi_mod_get_operation(smod) | LDAP_MOD_BVALUES) == (modtype | LDAP_MOD_BVALUES))) {
  199. /* type and op are equal - see if val is in the mod's list of values */
  200. Slapi_Value *sval = slapi_value_new_string((char *)val);
  201. Slapi_Attr *attr = slapi_attr_new();
  202. struct berval *bvp = NULL;
  203. slapi_attr_init(attr, type);
  204. for (bvp = slapi_mod_get_first_value(smodp); (rc == 0) && (bvp != NULL);
  205. bvp = slapi_mod_get_next_value(smodp)) {
  206. Slapi_Value *modval = slapi_value_new_berval(bvp);
  207. rc = (slapi_value_compare(attr, sval, modval) == 0);
  208. slapi_value_free(&modval);
  209. }
  210. slapi_value_free(&sval);
  211. slapi_attr_free(&attr);
  212. }
  213. }
  214. slapi_mod_free(&smod);
  215. return rc;
  216. }
  217. int
  218. hasObjectClass(Slapi_Entry *entry, const char *objectClass)
  219. {
  220. int rc = 0;
  221. int i;
  222. Slapi_Attr *obj_attr = NULL;
  223. Slapi_Value *value = NULL;
  224. rc = slapi_entry_attr_find(entry, "objectclass", &obj_attr);
  225. if (rc != 0) {
  226. return 0; /* Doesn't have any objectclasses */
  227. }
  228. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  229. "Scanning objectclasses\n");
  230. for (
  231. i = slapi_attr_first_value(obj_attr, &value);
  232. i != -1;
  233. i = slapi_attr_next_value(obj_attr, i, &value)) {
  234. const char *oc = NULL;
  235. oc = slapi_value_get_string(value);
  236. if (strcasecmp(oc, objectClass) == 0) {
  237. return 1; /* Entry has the desired objectclass */
  238. }
  239. }
  240. return 0; /* Doesn't have desired objectclass */
  241. }
  242. void
  243. posix_winsync_foreach_parent(Slapi_Entry *entry, char **attrs, plugin_search_entry_callback callback, void *callback_data)
  244. {
  245. char *cookie = NULL;
  246. Slapi_Backend *be = NULL;
  247. char *value = slapi_entry_get_ndn(entry);
  248. size_t vallen = value ? strlen(value) : 0;
  249. char *filter_escaped_value = slapi_escape_filter_value(value, vallen);
  250. char *filter = slapi_ch_smprintf("(uniqueMember=%s)", filter_escaped_value);
  251. slapi_ch_free_string(&filter_escaped_value);
  252. Slapi_PBlock *search_pb = slapi_pblock_new();
  253. for (be = slapi_get_first_backend(&cookie); be;
  254. be = slapi_get_next_backend(cookie)) {
  255. const Slapi_DN *base_sdn = slapi_be_getsuffix(be, 0);
  256. if (base_sdn == NULL) {
  257. continue;
  258. }
  259. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  260. "posix_winsync_foreach_parent: Searching subtree %s for %s\n",
  261. slapi_sdn_get_dn(base_sdn),
  262. filter);
  263. slapi_search_internal_set_pb(search_pb,
  264. slapi_sdn_get_dn(base_sdn),
  265. LDAP_SCOPE_SUBTREE,
  266. filter,
  267. attrs, 0, NULL, NULL,
  268. posix_winsync_get_plugin_identity(), 0);
  269. slapi_search_internal_callback_pb(search_pb, callback_data, 0, callback, 0);
  270. slapi_pblock_init(search_pb);
  271. }
  272. slapi_pblock_destroy(search_pb);
  273. slapi_ch_free((void **)&cookie);
  274. slapi_ch_free_string(&filter);
  275. }
  276. /* Retrieve nested membership from chains of groups.
  277. * Muid_vs in => any preexisting membership list
  278. * out => the union of the input list and the total membership
  279. * Muid_nested_vs out => the members of muid_vs "out" that weren't in muid_vs "in"
  280. * deletions in => Any elements to NOT consider if members of base_sdn
  281. */
  282. void
  283. getMembershipFromDownward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, Slapi_ValueSet *muid_nested_vs, Slapi_ValueSet *deletions, const Slapi_DN *base_sdn, int depth)
  284. {
  285. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  286. "getMembershipFromDownward: ==>\n");
  287. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  288. "getMembershipFromDownward: entry name: %s\n",
  289. slapi_entry_get_dn_const(entry));
  290. int rc = 0;
  291. Slapi_Attr *um_attr = NULL; /* Entry attributes uniqueMember */
  292. Slapi_Value *uid_value = NULL; /* uniqueMember attribute values */
  293. if (depth >= MAX_RECURSION_DEPTH) {
  294. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  295. "getMembershipFromDownward: recursion limit reached: %d\n", depth);
  296. return;
  297. }
  298. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  299. if (rc != 0 || um_attr == NULL) {
  300. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  301. "getMembershipFromDownward end: attribute uniquemember not found\n");
  302. return;
  303. }
  304. int i;
  305. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  306. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  307. char *attrs[] = {"uniqueMember", "memberUid", "uid", "objectClass", NULL};
  308. const char *uid_dn = slapi_value_get_string(uid_value);
  309. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  310. "getMembershipFromDownward: iterating uniqueMember: %s\n",
  311. uid_dn);
  312. if (deletions && !slapi_sdn_compare(slapi_entry_get_sdn_const(entry), base_sdn)) {
  313. if (slapi_valueset_find(um_attr, deletions, uid_value)) {
  314. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  315. "getMembershipFromDownward: Skipping iteration because of deletion\n");
  316. continue;
  317. }
  318. }
  319. Slapi_Entry *child = getEntry(uid_dn, attrs);
  320. if (!child) {
  321. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  322. "getMembershipFromDownward end: child not found: %s\n", uid_dn);
  323. } else {
  324. /* PosixGroups except for the top one are already fully mapped out */
  325. if ((!hasObjectClass(entry, "posixGroup") || (depth == 0)) &&
  326. (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup"))) {
  327. /* Recurse downward */
  328. getMembershipFromDownward(child, muid_vs, muid_nested_vs, deletions, base_sdn, depth + 1);
  329. }
  330. if (hasObjectClass(child, "posixAccount")) {
  331. Slapi_Attr *uid_attr = NULL;
  332. Slapi_Value *v = NULL;
  333. if (slapi_entry_attr_find(child, "uid", &uid_attr) == 0) {
  334. slapi_attr_first_value(uid_attr, &v);
  335. if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {
  336. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  337. "getMembershipFromDownward: adding member: %s\n",
  338. slapi_value_get_string(v));
  339. slapi_valueset_add_value(muid_vs, v);
  340. slapi_valueset_add_value(muid_nested_vs, v);
  341. }
  342. }
  343. } else if (hasObjectClass(child, "posixGroup")) {
  344. Slapi_Attr *uid_attr = NULL;
  345. Slapi_Value *v = NULL;
  346. if (slapi_entry_attr_find(child, "memberuid", &uid_attr) == 0) {
  347. slapi_attr_first_value(uid_attr, &v);
  348. if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {
  349. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  350. "getMembershipFromDownward: adding member: %s\n",
  351. slapi_value_get_string(v));
  352. slapi_valueset_add_value(muid_vs, v);
  353. slapi_valueset_add_value(muid_nested_vs, v);
  354. }
  355. }
  356. }
  357. slapi_entry_free(child);
  358. }
  359. }
  360. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  361. "getMembershipFromDownward: <==\n");
  362. }
  363. struct propogateMembershipUpwardArgs
  364. {
  365. Slapi_ValueSet *muid_vs;
  366. int depth;
  367. };
  368. /* Forward declaration for next function */
  369. void propogateMembershipUpward(Slapi_Entry *, Slapi_ValueSet *, int);
  370. int
  371. propogateMembershipUpwardCallback(Slapi_Entry *child, void *callback_data)
  372. {
  373. struct propogateMembershipUpwardArgs *args = (struct propogateMembershipUpwardArgs *)(callback_data);
  374. propogateMembershipUpward(child, args->muid_vs, args->depth);
  375. return 0;
  376. }
  377. void
  378. propogateMembershipUpward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, int depth)
  379. {
  380. if (depth >= MAX_RECURSION_DEPTH) {
  381. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  382. "propogateMembershipUpward: recursion limit reached: %d\n", depth);
  383. return;
  384. }
  385. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  386. "propogateMembershipUpward: ==>\n");
  387. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  388. "propogateMembershipUpward: entry name: %s\n",
  389. slapi_entry_get_dn_const(entry));
  390. Slapi_ValueSet *muid_here_vs = NULL;
  391. Slapi_ValueSet *muid_upward_vs = NULL;
  392. /* Get the memberUids at this location, and figure out local changes to memberUid (if any)
  393. * and changes to send upward.
  394. */
  395. if (depth > 0 && hasObjectClass(entry, "posixGroup")) {
  396. int addDynamicGroup = 0;
  397. Slapi_Attr *muid_old_attr = NULL;
  398. Slapi_ValueSet *muid_old_vs = NULL;
  399. int rc = slapi_entry_attr_find(entry, "memberUid", &muid_old_attr);
  400. if (rc != 0 || muid_old_attr == NULL) { /* Found no memberUid list, so create */
  401. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  402. "propogateMembershipUpward: no attribute memberUid\n");
  403. /* There's no values from this entry to add */
  404. muid_upward_vs = muid_vs;
  405. muid_here_vs = muid_vs;
  406. } else {
  407. int i = 0;
  408. Slapi_Value *v = NULL;
  409. /* Eliminate duplicates */
  410. muid_upward_vs = slapi_valueset_new();
  411. muid_here_vs = slapi_valueset_new();
  412. slapi_attr_get_valueset(muid_old_attr, &muid_old_vs);
  413. slapi_valueset_set_valueset(muid_upward_vs, muid_old_vs);
  414. for (i = slapi_valueset_first_value(muid_vs, &v); i != -1;
  415. i = slapi_valueset_next_value(muid_vs, i, &v)) {
  416. if (!slapi_valueset_find(muid_old_attr, muid_old_vs, v)) {
  417. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  418. "propogateMembershipUpward: adding %s to set\n",
  419. slapi_value_get_string(v));
  420. addDynamicGroup = 1;
  421. slapi_valueset_add_value(muid_here_vs, v);
  422. slapi_valueset_add_value(muid_upward_vs, v);
  423. }
  424. }
  425. slapi_valueset_free(muid_old_vs);
  426. }
  427. /* Update this group's membership */
  428. slapi_entry_add_valueset(entry, "memberUid", muid_here_vs);
  429. if (addDynamicGroup) {
  430. addDynamicGroupIfNecessary(entry, NULL);
  431. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_here_vs);
  432. }
  433. } else {
  434. muid_upward_vs = muid_vs;
  435. }
  436. /* Find groups containing this one, recurse
  437. */
  438. char *attrs[] = {"memberUid", "objectClass", NULL};
  439. struct propogateMembershipUpwardArgs data = {muid_upward_vs, depth + 1};
  440. posix_winsync_foreach_parent(entry, attrs, propogateMembershipUpwardCallback, &data);
  441. /* Cleanup */
  442. if (muid_here_vs && muid_here_vs != muid_vs) {
  443. slapi_valueset_free(muid_here_vs);
  444. muid_here_vs = NULL;
  445. }
  446. if (muid_upward_vs && muid_upward_vs != muid_vs) {
  447. slapi_valueset_free(muid_upward_vs);
  448. muid_upward_vs = NULL;
  449. }
  450. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  451. "propogateMembershipUpward: <==\n");
  452. }
  453. struct propogateDeletionsUpwardArgs
  454. {
  455. const Slapi_DN *base_sdn;
  456. Slapi_ValueSet *smod_deluids;
  457. Slapi_ValueSet *del_nested_vs;
  458. int depth;
  459. };
  460. /* Forward declaration for next function */
  461. void propogateDeletionsUpward(Slapi_Entry *, const Slapi_DN *, Slapi_ValueSet *, Slapi_ValueSet *, int);
  462. int
  463. propogateDeletionsUpwardCallback(Slapi_Entry *entry, void *callback_data)
  464. {
  465. struct propogateDeletionsUpwardArgs *args = (struct propogateDeletionsUpwardArgs *)(callback_data);
  466. propogateDeletionsUpward(entry, args->base_sdn, args->smod_deluids, args->del_nested_vs, args->depth);
  467. return 0;
  468. }
  469. void
  470. propogateDeletionsUpward(Slapi_Entry *entry, const Slapi_DN *base_sdn, Slapi_ValueSet *smod_deluids, Slapi_ValueSet *del_nested_vs, int depth)
  471. {
  472. if (smod_deluids == NULL)
  473. return;
  474. if (depth >= MAX_RECURSION_DEPTH) {
  475. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  476. "propogateDeletionsUpward: recursion limit reached: %d\n", depth);
  477. return;
  478. }
  479. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  480. "propogateDeletionsUpward: ==>\n");
  481. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  482. "propogateDeletionsUpward: entry name: %s\n",
  483. slapi_entry_get_dn_const(entry));
  484. char *attrs[] = {"uniqueMember", "memberUid", "objectClass", NULL};
  485. struct propogateDeletionsUpwardArgs data = {base_sdn, smod_deluids, del_nested_vs, depth + 1};
  486. posix_winsync_foreach_parent(entry, attrs, propogateDeletionsUpwardCallback, &data);
  487. Slapi_Attr *muid_attr = NULL;
  488. int rc = slapi_entry_attr_find(entry, "dsOnlyMemberUid", &muid_attr);
  489. if (rc == 0 && muid_attr != NULL) {
  490. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  491. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  492. Slapi_ValueSet *muid_deletions_vs = slapi_valueset_new();
  493. getMembershipFromDownward(entry, muid_vs, muid_nested_vs, smod_deluids, base_sdn, 0);
  494. int i;
  495. Slapi_Value *v;
  496. for (i = slapi_attr_first_value(muid_attr, &v); i != -1;
  497. i = slapi_attr_next_value(muid_attr, i, &v)) {
  498. if (!slapi_valueset_find(muid_attr, muid_vs, v)) {
  499. const char *uid = slapi_value_get_string(v);
  500. if (depth == 0 && !uid_in_valueset(uid, smod_deluids)) {
  501. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  502. "propogateDeletionsUpward: Adding deletion to modlist: %s\n",
  503. slapi_value_get_string(v));
  504. slapi_valueset_add_value(del_nested_vs, v);
  505. } else if (depth > 0) {
  506. slapi_valueset_add_value(muid_deletions_vs, v);
  507. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  508. "propogateDeletionsUpward: Adding deletion to deletion list: %s\n",
  509. slapi_value_get_string(v));
  510. }
  511. }
  512. }
  513. if (depth > 0) {
  514. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  515. "propogateDeletionsUpward: executing deletion list\n");
  516. Slapi_Mods *smods = slapi_mods_new();
  517. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "memberuid", valueset_get_valuearray(muid_deletions_vs));
  518. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "dsonlymemberuid", valueset_get_valuearray(muid_deletions_vs));
  519. Slapi_PBlock *mod_pb = slapi_pblock_new();
  520. slapi_modify_internal_set_pb_ext(mod_pb, slapi_entry_get_sdn(entry), slapi_mods_get_ldapmods_passout(smods), 0, 0,
  521. posix_winsync_get_plugin_identity(), 0);
  522. slapi_modify_internal_pb(mod_pb);
  523. slapi_pblock_destroy(mod_pb);
  524. slapi_mods_free(&smods);
  525. }
  526. slapi_valueset_free(muid_vs);
  527. muid_vs = NULL;
  528. slapi_valueset_free(muid_nested_vs);
  529. muid_nested_vs = NULL;
  530. slapi_valueset_free(muid_deletions_vs);
  531. muid_deletions_vs = NULL;
  532. }
  533. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  534. "propogateDeletionsUpward: <==\n");
  535. }
  536. int
  537. modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify, int newposixgroup)
  538. {
  539. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: ==>\n");
  540. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: Modding %s\n",
  541. slapi_entry_get_dn_const(entry));
  542. int posixGroup = hasObjectClass(entry, "posixGroup");
  543. if (!(posixGroup || hasObjectClass(entry, "ntGroup")) && !newposixgroup) {
  544. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  545. "modGroupMembership end: Not a posixGroup or ntGroup\n");
  546. return 0;
  547. }
  548. Slapi_Mod *smod = NULL;
  549. Slapi_Mod *nextMod = slapi_mod_new();
  550. int del_mod = 0; /* Bool: was there a delete mod? */
  551. char **smod_adduids = NULL;
  552. Slapi_ValueSet *smod_deluids = NULL;
  553. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  554. "modGroupMembership: posixGroup -> look for uniquemember\n");
  555. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  556. slapi_mods_dump(smods, "memberUid - mods dump - initial");
  557. for (smod = slapi_mods_get_first_smod(smods, nextMod); smod; smod = slapi_mods_get_next_smod(smods, nextMod)) {
  558. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), "uniqueMember")) {
  559. struct berval *bv;
  560. int current_del_mod = SLAPI_IS_MOD_DELETE(slapi_mod_get_operation(smod));
  561. if (current_del_mod) {
  562. del_mod = 1;
  563. }
  564. for (bv = slapi_mod_get_first_value(smod); bv;
  565. bv = slapi_mod_get_next_value(smod)) {
  566. Slapi_Value *sv = slapi_value_new();
  567. slapi_value_init_berval(sv, bv); /* copies bv_val */
  568. if (current_del_mod) {
  569. if (!smod_deluids)
  570. smod_deluids = slapi_valueset_new();
  571. slapi_valueset_add_value(smod_deluids, sv);
  572. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  573. "modGroupMembership: add to deluids %s\n",
  574. bv->bv_val);
  575. } else {
  576. slapi_ch_array_add(&smod_adduids,
  577. slapi_ch_strdup(slapi_value_get_string(sv)));
  578. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  579. "modGroupMembership: add to adduids %s\n",
  580. bv->bv_val);
  581. }
  582. slapi_value_free(&sv);
  583. }
  584. }
  585. }
  586. slapi_mod_free(&nextMod);
  587. int muid_rc = 0;
  588. Slapi_Attr *muid_attr = NULL; /* Entry attributes */
  589. Slapi_ValueSet *muid_vs = NULL;
  590. Slapi_Value *uid_value = NULL; /* Attribute values */
  591. Slapi_ValueSet *adduids = slapi_valueset_new();
  592. Slapi_ValueSet *add_nested_vs = slapi_valueset_new();
  593. Slapi_ValueSet *deluids = slapi_valueset_new();
  594. Slapi_ValueSet *del_nested_vs = slapi_valueset_new();
  595. const Slapi_DN *base_sdn = slapi_entry_get_sdn_const(entry);
  596. int j = 0;
  597. if (del_mod || smod_deluids != NULL) {
  598. do { /* Create a context to "break" from */
  599. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  600. if (smod_deluids == NULL) { /* deletion of the last value, deletes the Attribut from entry complete, this operation has no value, so we must look by self */
  601. Slapi_Attr *um_attr = NULL; /* Entry attributes */
  602. int rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  603. if (rc != 0 || um_attr == NULL) {
  604. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  605. "modGroupMembership end: attribute uniquemember not found\n");
  606. break;
  607. }
  608. slapi_attr_get_valueset(um_attr, &smod_deluids);
  609. }
  610. if (muid_rc != 0 || muid_attr == NULL) {
  611. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  612. "modGroupMembership end: attribute memberUid not found\n");
  613. } else if (posix_winsync_config_get_mapMemberUid()) {
  614. /* ...loop for value... */
  615. for (j = slapi_attr_first_value(muid_attr, &uid_value); j != -1;
  616. j = slapi_attr_next_value(muid_attr, j, &uid_value)) {
  617. /* remove from uniquemember: remove from memberUid also */
  618. const char *uid = NULL;
  619. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  620. "modGroupMembership: test dellist \n");
  621. uid = slapi_value_get_string(uid_value);
  622. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  623. "modGroupMembership: test dellist %s\n", uid);
  624. if (uid_in_valueset(uid, smod_deluids)) {
  625. slapi_valueset_add_value(deluids, uid_value);
  626. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  627. "modGroupMembership: add to dellist %s\n", uid);
  628. }
  629. }
  630. }
  631. if (posix_winsync_config_get_mapNestedGrouping()) {
  632. propogateDeletionsUpward(entry, base_sdn, smod_deluids, del_nested_vs, 0);
  633. int i;
  634. Slapi_Value *v;
  635. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  636. i = slapi_valueset_next_value(del_nested_vs, i, &v)) {
  637. slapi_valueset_add_value(deluids, v);
  638. }
  639. }
  640. } while (false);
  641. }
  642. if (smod_adduids != NULL) { /* not MOD_DELETE */
  643. const char *uid_dn = NULL;
  644. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  645. "modGroupMembership: posixGroup -> look for uniquemember\n");
  646. if (muid_rc == 0 && muid_attr == NULL) {
  647. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  648. }
  649. if (muid_rc == 0 && muid_attr != NULL) {
  650. slapi_attr_get_valueset(muid_attr, &muid_vs);
  651. } else {
  652. muid_vs = slapi_valueset_new();
  653. }
  654. if (posix_winsync_config_get_mapMemberUid()) {
  655. for (j = 0; smod_adduids[j]; j++) {
  656. static char *uid = NULL;
  657. uid_dn = smod_adduids[j];
  658. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  659. "modGroupMembership: perform user %s\n", uid_dn);
  660. uid = searchUid(uid_dn);
  661. if (uid == NULL) {
  662. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  663. "modGroupMembership: uid not found for %s, cannot do anything\n",
  664. uid_dn); /* member on longer on server, do nothing */
  665. } else {
  666. Slapi_Value *v = slapi_value_new();
  667. slapi_value_init_string_passin(v, uid);
  668. if (muid_rc == 0 && muid_attr != NULL &&
  669. slapi_valueset_find(muid_attr, muid_vs, v) != NULL) {
  670. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  671. "modGroupMembership: uid found in memberuid list %s nothing to do\n",
  672. uid);
  673. } else {
  674. slapi_valueset_add_value(adduids, v);
  675. slapi_valueset_add_value(muid_vs, v);
  676. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  677. "modGroupMembership: add to modlist %s\n", uid);
  678. }
  679. slapi_value_free(&v); /* also frees uid since it was a passin */
  680. }
  681. }
  682. }
  683. if (posix_winsync_config_get_mapNestedGrouping()) {
  684. for (j = 0; smod_adduids[j]; ++j) {
  685. char *attrs[] = {"uniqueMember", "memberUid", "uid", "objectClass", NULL};
  686. Slapi_Entry *child = getEntry(smod_adduids[j], attrs);
  687. if (child) {
  688. if (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup")) {
  689. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  690. "modGroupMembership: Found mod to add group, adding membership: %s\n",
  691. smod_adduids[j]);
  692. Slapi_ValueSet *muid_tempnested = slapi_valueset_new();
  693. getMembershipFromDownward(child, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  694. slapi_valueset_free(muid_tempnested);
  695. muid_tempnested = NULL;
  696. }
  697. } else {
  698. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  699. "modGroupMembership: entry not found for dn: %s\n",
  700. smod_adduids[j]);
  701. }
  702. }
  703. getMembershipFromDownward(entry, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  704. int i = 0;
  705. Slapi_Value *v = NULL;
  706. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  707. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  708. slapi_valueset_add_value(adduids, v);
  709. }
  710. propogateMembershipUpward(entry, adduids, 0);
  711. }
  712. }
  713. if (posixGroup) {
  714. int addDynamicGroup = 0;
  715. int i;
  716. Slapi_Value *v;
  717. for (i = slapi_valueset_first_value(adduids, &v); i != -1;
  718. i = slapi_valueset_next_value(adduids, i, &v)) {
  719. const char *muid = slapi_value_get_string(v);
  720. if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", muid)) {
  721. *do_modify = 1;
  722. slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", muid);
  723. }
  724. }
  725. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  726. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  727. const char *muid = slapi_value_get_string(v);
  728. if (!smods_has_mod(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid)) {
  729. addDynamicGroup = 1;
  730. *do_modify = 1;
  731. slapi_mods_add_string(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid);
  732. }
  733. }
  734. for (i = slapi_valueset_first_value(deluids, &v); i != -1;
  735. i = slapi_valueset_next_value(deluids, i, &v)) {
  736. const char *muid = slapi_value_get_string(v);
  737. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "memberUid", muid)) {
  738. *do_modify = 1;
  739. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberUid", muid);
  740. }
  741. }
  742. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  743. i = slapi_valueset_next_value(del_nested_vs, i, &v)) {
  744. const char *muid = slapi_value_get_string(v);
  745. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid)) {
  746. *do_modify = 1;
  747. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid);
  748. }
  749. }
  750. if (addDynamicGroup) {
  751. addDynamicGroupIfNecessary(entry, smods);
  752. }
  753. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  754. slapi_mods_dump(smods, "memberUid - mods dump");
  755. posix_winsync_config_set_MOFTaskCreated();
  756. }
  757. slapi_ch_array_free(smod_adduids);
  758. smod_adduids = NULL;
  759. if (smod_deluids)
  760. slapi_valueset_free(smod_deluids);
  761. smod_deluids = NULL;
  762. slapi_valueset_free(adduids);
  763. adduids = NULL;
  764. slapi_valueset_free(deluids);
  765. deluids = NULL;
  766. slapi_valueset_free(add_nested_vs);
  767. add_nested_vs = NULL;
  768. slapi_valueset_free(del_nested_vs);
  769. del_nested_vs = NULL;
  770. if (muid_vs) {
  771. slapi_valueset_free(muid_vs);
  772. muid_vs = NULL;
  773. }
  774. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: <==\n");
  775. return 0;
  776. }
  777. int
  778. addUserToGroupMembership(Slapi_Entry *entry)
  779. {
  780. Slapi_Attr *uid_attr = NULL;
  781. Slapi_Value *v = NULL;
  782. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  783. if (slapi_entry_attr_find(entry, "uid", &uid_attr) == 0) {
  784. slapi_attr_first_value(uid_attr, &v);
  785. if (v) {
  786. slapi_valueset_add_value(muid_vs, v);
  787. }
  788. }
  789. propogateMembershipUpward(entry, muid_vs, 0);
  790. slapi_valueset_free(muid_vs);
  791. muid_vs = NULL;
  792. return 0;
  793. }
  794. int
  795. addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry __attribute__((unused)))
  796. {
  797. int rc = 0;
  798. int i;
  799. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: ==>\n");
  800. int posixGroup = hasObjectClass(entry, "posixGroup");
  801. if (!(posixGroup || hasObjectClass(entry, "ntGroup"))) {
  802. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  803. "addGroupMembership: didn't find posixGroup or ntGroup objectclass\n");
  804. return 0;
  805. }
  806. Slapi_Attr *um_attr = NULL; /* Entry attributes uniquemember */
  807. Slapi_Attr *muid_attr = NULL; /* Entry attributes memebrof */
  808. Slapi_Value *uid_value = NULL; /* uniquemember Attribute values */
  809. Slapi_ValueSet *newvs = NULL;
  810. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  811. "addGroupMembership: posixGroup -> look for uniquemember\n");
  812. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  813. if (rc != 0 || um_attr == NULL) {
  814. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  815. "addGroupMembership end: attribute uniquemember not found\n");
  816. return 0;
  817. }
  818. /* found attribute uniquemember */
  819. rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  820. if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create */
  821. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  822. "addGroupMembership: no attribute memberUid\n");
  823. muid_attr = NULL;
  824. }
  825. newvs = slapi_valueset_new();
  826. /* ...loop for value... */
  827. if (posix_winsync_config_get_mapMemberUid()) {
  828. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  829. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  830. const char *uid_dn = NULL;
  831. static char *uid = NULL;
  832. Slapi_Value *v = NULL;
  833. uid_dn = slapi_value_get_string(uid_value);
  834. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  835. "addGroupMembership: perform member %s\n", uid_dn);
  836. uid = searchUid(uid_dn);
  837. if (uid == NULL) {
  838. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  839. "addGroupMembership: uid not found for %s, cannot do anything\n",
  840. uid_dn); /* member on longer on server, do nothing */
  841. } else {
  842. v = slapi_value_new_string(uid);
  843. slapi_ch_free_string(&uid);
  844. if (slapi_attr_value_find(muid_attr, slapi_value_get_berval(v)) != 0) {
  845. slapi_valueset_add_value(newvs, v);
  846. }
  847. slapi_value_free(&v);
  848. }
  849. }
  850. }
  851. if (posix_winsync_config_get_mapNestedGrouping()) {
  852. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  853. getMembershipFromDownward(entry, newvs, muid_nested_vs, NULL, NULL, 0);
  854. propogateMembershipUpward(entry, newvs, 0);
  855. if (posixGroup) {
  856. addDynamicGroupIfNecessary(entry, NULL);
  857. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_nested_vs);
  858. }
  859. slapi_valueset_free(muid_nested_vs);
  860. muid_nested_vs = NULL;
  861. }
  862. if (posixGroup) {
  863. slapi_entry_add_valueset(entry, "memberUid", newvs);
  864. }
  865. slapi_valueset_free(newvs);
  866. newvs = NULL;
  867. posix_winsync_config_get_MOFTaskCreated();
  868. slapi_log_err(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: <==\n");
  869. return 0;
  870. }