1
0

posix-group-func.c 39 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018
  1. /** Author: Carsten Grzemba [email protected]>
  2. *
  3. * Copyright (C) 2011 contac Datentechnik GmbH
  4. *
  5. * This program is free software; you can redistribute it and/or
  6. * modify it under the terms of the GNU General Public License as
  7. * published by the Free Software Foundation; version 2 only
  8. *
  9. * This program is distributed in the hope that it will be useful,
  10. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  12. * GNU General Public License for more details.
  13. *
  14. * You should have received a copy of the GNU General Public License
  15. * along with this program; if not, write to the Free Software
  16. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  17. $Id: posix-group-func.c 28 2011-05-13 14:35:29Z grzemba $
  18. */
  19. #include "slapi-plugin.h"
  20. #include "slapi-private.h"
  21. #include <string.h>
  22. #include <nspr.h>
  23. #include "posix-wsp-ident.h"
  24. #define MAX_RECURSION_DEPTH (5)
  25. Slapi_Value **
  26. valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
  27. static int hasObjectClass(Slapi_Entry *entry, const char *objectClass);
  28. static PRMonitor *memberuid_operation_lock = 0;
  29. void
  30. memberUidLock()
  31. {
  32. PR_EnterMonitor(memberuid_operation_lock);
  33. }
  34. void
  35. memberUidUnlock()
  36. {
  37. PR_ExitMonitor(memberuid_operation_lock);
  38. }
  39. int
  40. memberUidLockInit()
  41. {
  42. return (memberuid_operation_lock = PR_NewMonitor()) != NULL;
  43. }
  44. void
  45. addDynamicGroupIfNecessary(Slapi_Entry *entry, Slapi_Mods *smods) {
  46. Slapi_Attr *oc_attr = NULL;
  47. Slapi_Value *voc = slapi_value_new();
  48. slapi_value_init_string(voc, "dynamicGroup");
  49. slapi_entry_attr_find(entry, "objectClass", &oc_attr);
  50. if (slapi_attr_value_find(oc_attr, slapi_value_get_berval(voc)) != 0) {
  51. if (smods) {
  52. slapi_mods_add_string(smods, LDAP_MOD_ADD, "objectClass", "dynamicGroup");
  53. }
  54. else {
  55. smods = slapi_mods_new();
  56. slapi_mods_add_string(smods, LDAP_MOD_ADD, "objectClass", "dynamicGroup");
  57. Slapi_PBlock *mod_pb = slapi_pblock_new();
  58. slapi_modify_internal_set_pb_ext(mod_pb, slapi_entry_get_sdn(entry), slapi_mods_get_ldapmods_passout(smods), 0, 0,
  59. posix_winsync_get_plugin_identity(), 0);
  60. slapi_modify_internal_pb(mod_pb);
  61. slapi_pblock_destroy(mod_pb);
  62. slapi_mods_free(&smods);
  63. }
  64. }
  65. slapi_value_free(&voc);
  66. }
  67. Slapi_Entry *
  68. getEntry(const char *udn, char **attrs)
  69. {
  70. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "getEntry: search %s\n", udn);
  71. Slapi_DN *udn_sdn = slapi_sdn_new_dn_byval(udn);
  72. Slapi_Entry *result = NULL;
  73. int rc = slapi_search_internal_get_entry(udn_sdn, attrs, &result, posix_winsync_get_plugin_identity());
  74. slapi_sdn_free(&udn_sdn);
  75. if (rc == 0) {
  76. if (result != NULL) {
  77. return result; /* Must be freed */
  78. }
  79. else {
  80. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  81. "getEntry: %s not found\n", udn);
  82. }
  83. }
  84. else {
  85. slapi_log_error(SLAPI_LOG_FATAL, POSIX_WINSYNC_PLUGIN_NAME,
  86. "getEntry: error searching for uid: %d", rc);
  87. }
  88. return NULL;
  89. }
  90. /* search the user with DN udn and returns uid*/
  91. char *
  92. searchUid(const char *udn)
  93. {
  94. char *attrs[] = { "uid", "objectclass", NULL };
  95. Slapi_Entry *entry = getEntry(udn,
  96. /* "(|(objectclass=posixAccount)(objectclass=ldapsubentry))", */
  97. attrs);
  98. char *uid = NULL;
  99. if (entry) {
  100. Slapi_Attr *attr = NULL;
  101. Slapi_Value *v = NULL;
  102. if (slapi_entry_attr_find(entry, "uid", &attr) == 0 && hasObjectClass(entry, "posixAccount")) {
  103. slapi_attr_first_value(attr, &v);
  104. uid = slapi_ch_strdup(slapi_value_get_string(v));
  105. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  106. "searchUid: return uid %s\n", uid);
  107. } else {
  108. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  109. "searchUid: uid in %s not found\n", udn);
  110. }
  111. if (uid && posix_winsync_config_get_lowercase()) {
  112. uid = slapi_dn_ignore_case(uid);
  113. }
  114. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  115. "searchUid: About to free entry (%s)\n", udn);
  116. slapi_entry_free(entry);
  117. }
  118. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  119. "searchUid(%s): <==\n", udn);
  120. return uid;
  121. }
  122. int
  123. dn_in_set(const char* uid, char **uids)
  124. {
  125. int i;
  126. Slapi_DN *sdn_uid = NULL;
  127. Slapi_DN *sdn_ul = NULL;
  128. if (uids == NULL || uid == NULL)
  129. return false;
  130. sdn_uid = slapi_sdn_new_dn_byval(uid);
  131. sdn_ul = slapi_sdn_new();
  132. for (i = 0; uids[i]; i++) {
  133. slapi_sdn_set_dn_byref(sdn_ul, uids[i]);
  134. if (slapi_sdn_compare(sdn_uid, sdn_ul) == 0) {
  135. slapi_sdn_free(&sdn_ul);
  136. slapi_sdn_free(&sdn_uid);
  137. return true;
  138. }
  139. slapi_sdn_done(sdn_ul);
  140. }
  141. slapi_sdn_free(&sdn_ul);
  142. slapi_sdn_free(&sdn_uid);
  143. return false;
  144. }
  145. int
  146. uid_in_set(const char* uid, char **uids)
  147. {
  148. int i;
  149. if (uid == NULL)
  150. return false;
  151. for (i = 0; uids != NULL && uids[i] != NULL; i++) {
  152. Slapi_RDN *i_rdn = NULL;
  153. char *i_uid = NULL;
  154. char *t = NULL;
  155. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_set: comp %s %s \n",
  156. uid, uids[i]);
  157. i_rdn = slapi_rdn_new_dn(uids[i]);
  158. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  159. if (strncasecmp(uid, i_uid, 256) == 0) {
  160. slapi_rdn_free(&i_rdn);
  161. return true;
  162. }
  163. }
  164. slapi_rdn_free(&i_rdn);
  165. }
  166. return false;
  167. }
  168. int
  169. uid_in_valueset(const char* uid, Slapi_ValueSet *uids)
  170. {
  171. int i;
  172. Slapi_Value *v = NULL;
  173. if (uid == NULL)
  174. return false;
  175. for (i = slapi_valueset_first_value(uids, &v); i != -1;
  176. i = slapi_valueset_next_value(uids, i, &v)) {
  177. Slapi_RDN *i_rdn = NULL;
  178. char *i_uid = NULL;
  179. char *t = NULL;
  180. const char *uid_i = slapi_value_get_string(v);
  181. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_valueset: comp %s %s \n",
  182. uid, uid_i);
  183. i_rdn = slapi_rdn_new_dn(uid_i);
  184. if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
  185. if (strncasecmp(uid, i_uid, 256) == 0) {
  186. slapi_rdn_free(&i_rdn);
  187. return true;
  188. }
  189. }
  190. slapi_rdn_free(&i_rdn);
  191. }
  192. return false;
  193. }
  194. /* return 1 if smods already has the given mod - 0 otherwise */
  195. static int
  196. smods_has_mod(Slapi_Mods *smods, int modtype, const char *type, const char *val)
  197. {
  198. int rc = 0;
  199. Slapi_Mod *smod = slapi_mod_new(), *smodp = NULL;
  200. for (smodp = slapi_mods_get_first_smod(smods, smod);
  201. (rc == 0) && smods && (smodp != NULL);
  202. smodp = slapi_mods_get_next_smod(smods, smod)) {
  203. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), type)
  204. && ((slapi_mod_get_operation(smod) | LDAP_MOD_BVALUES) == (modtype | LDAP_MOD_BVALUES))) {
  205. /* type and op are equal - see if val is in the mod's list of values */
  206. Slapi_Value *sval = slapi_value_new_string((char *) val);
  207. Slapi_Attr *attr = slapi_attr_new();
  208. struct berval *bvp = NULL;
  209. slapi_attr_init(attr, type);
  210. for (bvp = slapi_mod_get_first_value(smodp); (rc == 0) && (bvp != NULL);
  211. bvp = slapi_mod_get_next_value(smodp)) {
  212. Slapi_Value *modval = slapi_value_new_berval(bvp);
  213. rc = (slapi_value_compare(attr, sval, modval) == 0);
  214. slapi_value_free(&modval);
  215. }
  216. slapi_value_free(&sval);
  217. slapi_attr_free(&attr);
  218. }
  219. }
  220. slapi_mod_free(&smod);
  221. return rc;
  222. }
  223. static int
  224. hasObjectClass(Slapi_Entry *entry, const char *objectClass)
  225. {
  226. int rc = 0;
  227. int i;
  228. Slapi_Attr *obj_attr = NULL;
  229. Slapi_Value *value = NULL;
  230. rc = slapi_entry_attr_find(entry, "objectclass", &obj_attr);
  231. if (rc != 0) {
  232. return 0; /* Doesn't have any objectclasses */
  233. }
  234. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  235. "Scanning objectclasses\n");
  236. for (
  237. i = slapi_attr_first_value(obj_attr, &value);
  238. i != -1;
  239. i = slapi_attr_next_value(obj_attr, i, &value)
  240. ) {
  241. const char *oc = NULL;
  242. oc = slapi_value_get_string(value);
  243. if (strcasecmp(oc, objectClass) == 0) {
  244. return 1; /* Entry has the desired objectclass */
  245. }
  246. }
  247. return 0; /* Doesn't have desired objectclass */
  248. }
  249. void
  250. posix_winsync_foreach_parent(Slapi_Entry *entry, char **attrs, plugin_search_entry_callback callback, void *callback_data)
  251. {
  252. char *cookie = NULL;
  253. Slapi_Backend *be = NULL;
  254. char *value = slapi_entry_get_ndn(entry);
  255. size_t vallen = value ? strlen(value) : 0;
  256. char *filter_escaped_value = slapi_escape_filter_value(value, vallen);
  257. char *filter = slapi_ch_smprintf("(uniqueMember=%s)", filter_escaped_value);
  258. slapi_ch_free_string(&filter_escaped_value);
  259. Slapi_PBlock *search_pb = slapi_pblock_new();
  260. for (be = slapi_get_first_backend(&cookie); be;
  261. be = slapi_get_next_backend(cookie)) {
  262. const Slapi_DN *base_sdn = slapi_be_getsuffix(be, 0);
  263. if (base_sdn == NULL) {
  264. continue;
  265. }
  266. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  267. "posix_winsync_foreach_parent: Searching subtree %s for %s\n",
  268. slapi_sdn_get_dn(base_sdn),
  269. filter);
  270. slapi_search_internal_set_pb(search_pb,
  271. slapi_sdn_get_dn(base_sdn),
  272. LDAP_SCOPE_SUBTREE,
  273. filter,
  274. attrs, 0, NULL, NULL,
  275. posix_winsync_get_plugin_identity(), 0);
  276. slapi_search_internal_callback_pb(search_pb, callback_data, 0, callback, 0);
  277. slapi_pblock_init(search_pb);
  278. }
  279. slapi_pblock_destroy(search_pb);
  280. slapi_ch_free((void**)&cookie);
  281. slapi_ch_free_string(&filter);
  282. }
  283. /* Retrieve nested membership from chains of groups.
  284. * Muid_vs in => any preexisting membership list
  285. * out => the union of the input list and the total membership
  286. * Muid_nested_vs out => the members of muid_vs "out" that weren't in muid_vs "in"
  287. * deletions in => Any elements to NOT consider if members of base_sdn
  288. */
  289. void
  290. getMembershipFromDownward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, Slapi_ValueSet *muid_nested_vs, Slapi_ValueSet *deletions, const Slapi_DN *base_sdn, int depth)
  291. {
  292. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  293. "getMembershipFromDownward: ==>\n");
  294. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  295. "getMembershipFromDownward: entry name: %s\n",
  296. slapi_entry_get_dn_const(entry));
  297. int rc = 0;
  298. Slapi_Attr *um_attr = NULL; /* Entry attributes uniqueMember */
  299. Slapi_Value *uid_value = NULL; /* uniqueMember attribute values */
  300. if (depth >= MAX_RECURSION_DEPTH) {
  301. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  302. "getMembershipFromDownward: recursion limit reached: %d\n", depth);
  303. return;
  304. }
  305. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  306. if (rc != 0 || um_attr == NULL) {
  307. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  308. "getMembershipFromDownward end: attribute uniquemember not found\n");
  309. return;
  310. }
  311. int i;
  312. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  313. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  314. char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
  315. const char *uid_dn = slapi_value_get_string(uid_value);
  316. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  317. "getMembershipFromDownward: iterating uniqueMember: %s\n",
  318. uid_dn);
  319. if (deletions && !slapi_sdn_compare(slapi_entry_get_sdn_const(entry), base_sdn)) {
  320. if (slapi_valueset_find(um_attr, deletions, uid_value)) {
  321. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  322. "getMembershipFromDownward: Skipping iteration because of deletion\n");
  323. continue;
  324. }
  325. }
  326. Slapi_Entry *child = getEntry(uid_dn, attrs);
  327. if (!child) {
  328. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  329. "getMembershipFromDownward end: child not found: %s\n", uid_dn);
  330. }
  331. else {
  332. /* PosixGroups except for the top one are already fully mapped out */
  333. if ((!hasObjectClass(entry, "posixGroup") || depth == 0) &&
  334. (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup"))) {
  335. /* Recurse downward */
  336. getMembershipFromDownward(child, muid_vs, muid_nested_vs, deletions, base_sdn, depth + 1);
  337. }
  338. if (hasObjectClass(child, "posixAccount")) {
  339. Slapi_Attr *uid_attr = NULL;
  340. Slapi_Value *v = NULL;
  341. if (slapi_entry_attr_find(child, "uid", &uid_attr) == 0) {
  342. slapi_attr_first_value(uid_attr, &v);
  343. if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {
  344. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  345. "getMembershipFromDownward: adding member: %s\n",
  346. slapi_value_get_string(v));
  347. slapi_valueset_add_value(muid_vs, v);
  348. slapi_valueset_add_value(muid_nested_vs, v);
  349. }
  350. }
  351. }
  352. slapi_entry_free(child);
  353. }
  354. }
  355. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  356. "getMembershipFromDownward: <==\n");
  357. }
  358. struct propogateMembershipUpwardArgs {
  359. Slapi_ValueSet *muid_vs;
  360. int depth;
  361. };
  362. /* Forward declaration for next function */
  363. void propogateMembershipUpward(Slapi_Entry *, Slapi_ValueSet *, int);
  364. int
  365. propogateMembershipUpwardCallback(Slapi_Entry *child, void *callback_data)
  366. {
  367. struct propogateMembershipUpwardArgs *args = (struct propogateMembershipUpwardArgs *)(callback_data);
  368. propogateMembershipUpward(child, args->muid_vs, args->depth);
  369. return 0;
  370. }
  371. void
  372. propogateMembershipUpward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, int depth)
  373. {
  374. if (depth >= MAX_RECURSION_DEPTH) {
  375. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  376. "propogateMembershipUpward: recursion limit reached: %d\n", depth);
  377. return;
  378. }
  379. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  380. "propogateMembershipUpward: ==>\n");
  381. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  382. "propogateMembershipUpward: entry name: %s\n",
  383. slapi_entry_get_dn_const(entry));
  384. Slapi_ValueSet *muid_here_vs = NULL;
  385. Slapi_ValueSet *muid_upward_vs = NULL;
  386. /* Get the memberUids at this location, and figure out local changes to memberUid (if any)
  387. * and changes to send upward.
  388. */
  389. if (depth > 0 && hasObjectClass(entry, "posixGroup")) {
  390. int addDynamicGroup = 0;
  391. Slapi_Attr *muid_old_attr = NULL;
  392. Slapi_ValueSet *muid_old_vs = NULL;
  393. int rc = slapi_entry_attr_find(entry, "memberUid", &muid_old_attr);
  394. if (rc != 0 || muid_old_attr == NULL) { /* Found no memberUid list, so create */
  395. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  396. "propogateMembershipUpward: no attribute memberUid\n");
  397. /* There's no values from this entry to add */
  398. muid_upward_vs = muid_vs;
  399. muid_here_vs = muid_vs;
  400. }
  401. else {
  402. int i = 0;
  403. Slapi_Value *v = NULL;
  404. /* Eliminate duplicates */
  405. muid_upward_vs = slapi_valueset_new();
  406. muid_here_vs = slapi_valueset_new();
  407. slapi_attr_get_valueset(muid_old_attr, &muid_old_vs);
  408. slapi_valueset_set_valueset(muid_upward_vs, muid_old_vs);
  409. for (i = slapi_valueset_first_value(muid_vs, &v); i != -1;
  410. i = slapi_valueset_next_value(muid_vs, i, &v)) {
  411. if (!slapi_valueset_find(muid_old_attr, muid_old_vs, v)) {
  412. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  413. "propogateMembershipUpward: adding %s to set\n",
  414. slapi_value_get_string(v));
  415. addDynamicGroup = 1;
  416. slapi_valueset_add_value(muid_here_vs, v);
  417. slapi_valueset_add_value(muid_upward_vs, v);
  418. }
  419. }
  420. slapi_valueset_free(muid_old_vs);
  421. }
  422. /* Update this group's membership */
  423. slapi_entry_add_valueset(entry, "memberUid", muid_here_vs);
  424. if (addDynamicGroup) {
  425. addDynamicGroupIfNecessary(entry, NULL);
  426. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_here_vs);
  427. }
  428. }
  429. else {
  430. muid_upward_vs = muid_vs;
  431. }
  432. /* Find groups containing this one, recurse
  433. */
  434. char *attrs[] = {"memberUid", "objectClass", NULL};
  435. struct propogateMembershipUpwardArgs data = {muid_upward_vs, depth + 1};
  436. posix_winsync_foreach_parent(entry, attrs, propogateMembershipUpwardCallback, &data);
  437. /* Cleanup */
  438. if (muid_here_vs && muid_here_vs != muid_vs) {
  439. slapi_valueset_free(muid_here_vs); muid_here_vs = NULL;
  440. }
  441. if (muid_upward_vs && muid_upward_vs != muid_vs) {
  442. slapi_valueset_free(muid_upward_vs); muid_upward_vs = NULL;
  443. }
  444. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  445. "propogateMembershipUpward: <==\n");
  446. }
  447. struct propogateDeletionsUpwardArgs {
  448. const Slapi_DN *base_sdn;
  449. Slapi_ValueSet *smod_deluids;
  450. Slapi_ValueSet *del_nested_vs;
  451. int depth;
  452. };
  453. /* Forward declaration for next function */
  454. void propogateDeletionsUpward(Slapi_Entry *, const Slapi_DN *, Slapi_ValueSet*, Slapi_ValueSet *, int);
  455. int
  456. propogateDeletionsUpwardCallback(Slapi_Entry *entry, void *callback_data)
  457. {
  458. struct propogateDeletionsUpwardArgs *args = (struct propogateDeletionsUpwardArgs *)(callback_data);
  459. propogateDeletionsUpward(entry, args->base_sdn, args->smod_deluids, args->del_nested_vs, args->depth);
  460. return 0;
  461. }
  462. void
  463. propogateDeletionsUpward(Slapi_Entry *entry, const Slapi_DN *base_sdn, Slapi_ValueSet *smod_deluids, Slapi_ValueSet *del_nested_vs, int depth)
  464. {
  465. if (smod_deluids == NULL) return;
  466. if (depth >= MAX_RECURSION_DEPTH) {
  467. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  468. "propogateDeletionsUpward: recursion limit reached: %d\n", depth);
  469. return;
  470. }
  471. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  472. "propogateDeletionsUpward: ==>\n");
  473. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  474. "propogateDeletionsUpward: entry name: %s\n",
  475. slapi_entry_get_dn_const(entry));
  476. char *attrs[] = { "uniqueMember", "memberUid", "objectClass", NULL };
  477. struct propogateDeletionsUpwardArgs data = {base_sdn, smod_deluids, del_nested_vs, depth + 1};
  478. posix_winsync_foreach_parent(entry, attrs, propogateDeletionsUpwardCallback, &data);
  479. Slapi_Attr *muid_attr = NULL;
  480. int rc = slapi_entry_attr_find(entry, "dsOnlyMemberUid", &muid_attr);
  481. if (rc == 0 && muid_attr != NULL) {
  482. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  483. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  484. Slapi_ValueSet *muid_deletions_vs = slapi_valueset_new();
  485. getMembershipFromDownward(entry, muid_vs, muid_nested_vs, smod_deluids, base_sdn, 0);
  486. int i;
  487. Slapi_Value *v;
  488. for (i = slapi_attr_first_value(muid_attr, &v); i != -1;
  489. i = slapi_attr_next_value(muid_attr, i, &v)) {
  490. if (!slapi_valueset_find(muid_attr, muid_vs, v)) {
  491. const char *uid = slapi_value_get_string(v);
  492. if (depth == 0 && !uid_in_valueset(uid, smod_deluids)) {
  493. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  494. "propogateDeletionsUpward: Adding deletion to modlist: %s\n",
  495. slapi_value_get_string(v));
  496. slapi_valueset_add_value(del_nested_vs, v);
  497. }
  498. else if (depth > 0) {
  499. slapi_valueset_add_value(muid_deletions_vs, v);
  500. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  501. "propogateDeletionsUpward: Adding deletion to deletion list: %s\n",
  502. slapi_value_get_string(v));
  503. }
  504. }
  505. }
  506. if (depth > 0) {
  507. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  508. "propogateDeletionsUpward: executing deletion list\n");
  509. Slapi_Mods *smods = slapi_mods_new();
  510. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "memberuid", valueset_get_valuearray(muid_deletions_vs));
  511. slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "dsonlymemberuid", valueset_get_valuearray(muid_deletions_vs));
  512. Slapi_PBlock *mod_pb = slapi_pblock_new();
  513. slapi_modify_internal_set_pb_ext(mod_pb, slapi_entry_get_sdn(entry), slapi_mods_get_ldapmods_passout(smods), 0, 0,
  514. posix_winsync_get_plugin_identity(), 0);
  515. slapi_modify_internal_pb(mod_pb);
  516. slapi_pblock_destroy(mod_pb);
  517. slapi_mods_free(&smods);
  518. }
  519. slapi_valueset_free(muid_vs); muid_vs = NULL;
  520. slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;
  521. slapi_valueset_free(muid_deletions_vs); muid_deletions_vs = NULL;
  522. }
  523. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  524. "propogateDeletionsUpward: <==\n");
  525. }
  526. int
  527. modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify, int newposixgroup)
  528. {
  529. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: ==>\n");
  530. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: Modding %s\n",
  531. slapi_entry_get_dn_const(entry));
  532. int posixGroup = hasObjectClass(entry, "posixGroup");
  533. if (!(posixGroup || hasObjectClass(entry, "ntGroup")) && !newposixgroup) {
  534. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  535. "modGroupMembership end: Not a posixGroup or ntGroup\n");
  536. return 0;
  537. }
  538. Slapi_Mod *smod = NULL;
  539. Slapi_Mod *nextMod = slapi_mod_new();
  540. int del_mod = 0; /* Bool: was there a delete mod? */
  541. char **smod_adduids = NULL;
  542. Slapi_ValueSet *smod_deluids = NULL;
  543. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  544. "modGroupMembership: posixGroup -> look for uniquemember\n");
  545. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  546. slapi_mods_dump(smods, "memberUid - mods dump - initial");
  547. for (smod = slapi_mods_get_first_smod(smods, nextMod); smod; smod
  548. = slapi_mods_get_next_smod(smods, nextMod)) {
  549. if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), "uniqueMember")) {
  550. struct berval *bv;
  551. int current_del_mod = SLAPI_IS_MOD_DELETE(slapi_mod_get_operation(smod));
  552. if (current_del_mod) {
  553. del_mod = 1;
  554. }
  555. for (bv = slapi_mod_get_first_value(smod); bv;
  556. bv = slapi_mod_get_next_value(smod)) {
  557. Slapi_Value *sv = slapi_value_new();
  558. slapi_value_init_berval(sv, bv); /* copies bv_val */
  559. if (current_del_mod) {
  560. if (!smod_deluids) smod_deluids = slapi_valueset_new();
  561. slapi_valueset_add_value(smod_deluids, sv);
  562. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  563. "modGroupMembership: add to deluids %s\n",
  564. bv->bv_val);
  565. } else {
  566. slapi_ch_array_add(&smod_adduids,
  567. slapi_ch_strdup(slapi_value_get_string(sv)));
  568. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  569. "modGroupMembership: add to adduids %s\n",
  570. bv->bv_val);
  571. }
  572. slapi_value_free(&sv);
  573. }
  574. }
  575. }
  576. slapi_mod_free(&nextMod);
  577. int muid_rc = 0;
  578. Slapi_Attr * muid_attr = NULL; /* Entry attributes */
  579. Slapi_ValueSet *muid_vs = NULL;
  580. Slapi_Value * uid_value = NULL; /* Attribute values */
  581. Slapi_ValueSet *adduids = slapi_valueset_new();
  582. Slapi_ValueSet *add_nested_vs = slapi_valueset_new();
  583. Slapi_ValueSet *deluids = slapi_valueset_new();
  584. Slapi_ValueSet *del_nested_vs = slapi_valueset_new();
  585. const Slapi_DN *base_sdn = slapi_entry_get_sdn_const(entry);
  586. int j = 0;
  587. if (del_mod || smod_deluids != NULL) {
  588. do { /* Create a context to "break" from */
  589. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  590. if (smod_deluids == NULL) { /* deletion of the last value, deletes the Attribut from entry complete, this operation has no value, so we must look by self */
  591. Slapi_Attr * um_attr = NULL; /* Entry attributes */
  592. int rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  593. if (rc != 0 || um_attr == NULL) {
  594. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  595. "modGroupMembership end: attribute uniquemember not found\n");
  596. break;
  597. }
  598. slapi_attr_get_valueset(um_attr, &smod_deluids);
  599. }
  600. if (muid_rc != 0 || muid_attr == NULL) {
  601. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  602. "modGroupMembership end: attribute memberUid not found\n");
  603. }
  604. else if (posix_winsync_config_get_mapMemberUid()) {
  605. /* ...loop for value... */
  606. for (j = slapi_attr_first_value(muid_attr, &uid_value); j != -1;
  607. j = slapi_attr_next_value(muid_attr, j, &uid_value)) {
  608. /* remove from uniquemember: remove from memberUid also */
  609. const char *uid = NULL;
  610. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  611. "modGroupMembership: test dellist \n");
  612. uid = slapi_value_get_string(uid_value);
  613. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  614. "modGroupMembership: test dellist %s\n", uid);
  615. if (uid_in_valueset(uid, smod_deluids)) {
  616. slapi_valueset_add_value(deluids, uid_value);
  617. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  618. "modGroupMembership: add to dellist %s\n", uid);
  619. }
  620. }
  621. }
  622. if (posix_winsync_config_get_mapNestedGrouping()) {
  623. propogateDeletionsUpward(entry, base_sdn, smod_deluids, del_nested_vs, 0);
  624. int i;
  625. Slapi_Value *v;
  626. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  627. i = slapi_valueset_next_value(del_nested_vs, i, &v)) {
  628. slapi_valueset_add_value(deluids, v);
  629. }
  630. }
  631. } while (false);
  632. }
  633. if (smod_adduids != NULL) { /* not MOD_DELETE */
  634. const char *uid_dn = NULL;
  635. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  636. "modGroupMembership: posixGroup -> look for uniquemember\n");
  637. if (muid_rc == 0 && muid_attr == NULL) {
  638. muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  639. }
  640. if (muid_rc == 0 && muid_attr != NULL) {
  641. slapi_attr_get_valueset(muid_attr, &muid_vs);
  642. }
  643. else {
  644. muid_vs = slapi_valueset_new();
  645. }
  646. if (posix_winsync_config_get_mapMemberUid()) {
  647. for (j = 0; smod_adduids[j]; j++) {
  648. static char *uid = NULL;
  649. uid_dn = smod_adduids[j];
  650. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  651. "modGroupMembership: perform user %s\n", uid_dn);
  652. uid = searchUid(uid_dn);
  653. if (uid == NULL) {
  654. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  655. "modGroupMembership: uid not found for %s, cannot do anything\n",
  656. uid_dn); /* member on longer on server, do nothing */
  657. } else {
  658. Slapi_Value *v = slapi_value_new();
  659. slapi_value_init_string_passin(v, uid);
  660. if (muid_rc == 0 && muid_attr != NULL &&
  661. slapi_valueset_find(muid_attr, muid_vs, v) != NULL) {
  662. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  663. "modGroupMembership: uid found in memberuid list %s nothing to do\n",
  664. uid);
  665. }
  666. else {
  667. slapi_valueset_add_value(adduids, v);
  668. slapi_valueset_add_value(muid_vs, v);
  669. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  670. "modGroupMembership: add to modlist %s\n", uid);
  671. }
  672. slapi_value_free(&v); /* also frees uid since it was a passin */
  673. }
  674. }
  675. }
  676. if (posix_winsync_config_get_mapNestedGrouping()) {
  677. for (j = 0; smod_adduids[j]; ++j) {
  678. char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
  679. Slapi_Entry *child = getEntry(smod_adduids[j], attrs);
  680. if (child) {
  681. if (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup")) {
  682. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  683. "modGroupMembership: Found mod to add group, adding membership: %s\n",
  684. smod_adduids[j]);
  685. Slapi_ValueSet *muid_tempnested = slapi_valueset_new();
  686. getMembershipFromDownward(child, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  687. slapi_valueset_free(muid_tempnested); muid_tempnested = NULL;
  688. }
  689. }
  690. else {
  691. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  692. "modGroupMembership: entry not found for dn: %s\n",
  693. smod_adduids[j]);
  694. }
  695. }
  696. getMembershipFromDownward(entry, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
  697. int i = 0;
  698. Slapi_Value *v = NULL;
  699. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  700. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  701. slapi_valueset_add_value(adduids, v);
  702. }
  703. propogateMembershipUpward(entry, adduids, 0);
  704. }
  705. }
  706. if (posixGroup) {
  707. int addDynamicGroup = 0;
  708. int i;
  709. Slapi_Value *v;
  710. for (i = slapi_valueset_first_value(adduids, &v); i != -1;
  711. i = slapi_valueset_next_value(adduids, i, &v)){
  712. const char *muid = slapi_value_get_string(v);
  713. if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", muid)) {
  714. *do_modify = 1;
  715. slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", muid);
  716. }
  717. }
  718. for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
  719. i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
  720. const char *muid = slapi_value_get_string(v);
  721. if (!smods_has_mod(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid)) {
  722. addDynamicGroup = 1;
  723. *do_modify = 1;
  724. slapi_mods_add_string(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid);
  725. }
  726. }
  727. for (i = slapi_valueset_first_value(deluids, &v); i != -1;
  728. i = slapi_valueset_next_value(deluids, i, &v)){
  729. const char *muid = slapi_value_get_string(v);
  730. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "memberUid", muid)) {
  731. *do_modify = 1;
  732. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberUid", muid);
  733. }
  734. }
  735. for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
  736. i = slapi_valueset_next_value(del_nested_vs, i, &v)){
  737. const char *muid = slapi_value_get_string(v);
  738. if (!smods_has_mod(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid)) {
  739. *do_modify = 1;
  740. slapi_mods_add_string(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid);
  741. }
  742. }
  743. if (addDynamicGroup) {
  744. addDynamicGroupIfNecessary(entry, smods);
  745. }
  746. if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
  747. slapi_mods_dump(smods, "memberUid - mods dump");
  748. posix_winsync_config_set_MOFTaskCreated();
  749. }
  750. slapi_ch_array_free(smod_adduids);
  751. smod_adduids = NULL;
  752. if (smod_deluids) slapi_valueset_free(smod_deluids);
  753. smod_deluids = NULL;
  754. slapi_valueset_free(adduids);
  755. adduids = NULL;
  756. slapi_valueset_free(deluids);
  757. deluids = NULL;
  758. slapi_valueset_free(add_nested_vs); add_nested_vs = NULL;
  759. slapi_valueset_free(del_nested_vs); del_nested_vs = NULL;
  760. if (muid_vs) {
  761. slapi_valueset_free(muid_vs); muid_vs = NULL;
  762. }
  763. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: <==\n");
  764. return 0;
  765. }
  766. int
  767. addUserToGroupMembership(Slapi_Entry *entry)
  768. {
  769. Slapi_Attr *uid_attr = NULL;
  770. Slapi_Value *v = NULL;
  771. Slapi_ValueSet *muid_vs = slapi_valueset_new();
  772. if (slapi_entry_attr_find(entry, "uid", &uid_attr) == 0) {
  773. slapi_attr_first_value(uid_attr, &v);
  774. if (v) {
  775. slapi_valueset_add_value(muid_vs, v);
  776. }
  777. }
  778. propogateMembershipUpward(entry, muid_vs, 0);
  779. slapi_valueset_free(muid_vs); muid_vs = NULL;
  780. return 0;
  781. }
  782. int
  783. addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry)
  784. {
  785. int rc = 0;
  786. int i;
  787. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: ==>\n");
  788. int posixGroup = hasObjectClass(entry, "posixGroup");
  789. if(!(posixGroup || hasObjectClass(entry, "ntGroup"))) {
  790. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  791. "addGroupMembership: didn't find posixGroup or ntGroup objectclass\n");
  792. return 0;
  793. }
  794. Slapi_Attr * um_attr = NULL; /* Entry attributes uniquemember */
  795. Slapi_Attr * muid_attr = NULL; /* Entry attributes memebrof */
  796. Slapi_Value * uid_value = NULL; /* uniquemember Attribute values */
  797. Slapi_ValueSet *newvs = NULL;
  798. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  799. "addGroupMembership: posixGroup -> look for uniquemember\n");
  800. rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
  801. if (rc != 0 || um_attr == NULL) {
  802. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  803. "addGroupMembership end: attribute uniquemember not found\n");
  804. return 0;
  805. }
  806. /* found attribute uniquemember */
  807. rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
  808. if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create */
  809. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  810. "addGroupMembership: no attribute memberUid\n");
  811. muid_attr = NULL;
  812. }
  813. newvs = slapi_valueset_new();
  814. /* ...loop for value... */
  815. if (posix_winsync_config_get_mapMemberUid()) {
  816. for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
  817. i = slapi_attr_next_value(um_attr, i, &uid_value)) {
  818. const char *uid_dn = NULL;
  819. static char *uid = NULL;
  820. Slapi_Value *v = NULL;
  821. uid_dn = slapi_value_get_string(uid_value);
  822. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  823. "addGroupMembership: perform member %s\n", uid_dn);
  824. uid = searchUid(uid_dn);
  825. if (uid == NULL) {
  826. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
  827. "addGroupMembership: uid not found for %s, cannot do anything\n",
  828. uid_dn); /* member on longer on server, do nothing */
  829. } else {
  830. v = slapi_value_new_string(uid);
  831. slapi_ch_free_string(&uid);
  832. if (slapi_attr_value_find(muid_attr, slapi_value_get_berval(v)) != 0) {
  833. slapi_valueset_add_value(newvs, v);
  834. }
  835. slapi_value_free(&v);
  836. }
  837. }
  838. }
  839. if (posix_winsync_config_get_mapNestedGrouping()) {
  840. Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
  841. getMembershipFromDownward(entry, newvs, muid_nested_vs, NULL, NULL, 0);
  842. propogateMembershipUpward(entry, newvs, 0);
  843. if (posixGroup) {
  844. addDynamicGroupIfNecessary(entry, NULL);
  845. slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_nested_vs);
  846. }
  847. slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;
  848. }
  849. if (posixGroup) {
  850. slapi_entry_add_valueset(entry, "memberUid", newvs);
  851. }
  852. slapi_valueset_free(newvs); newvs = NULL;
  853. posix_winsync_config_get_MOFTaskCreated();
  854. slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: <==\n");
  855. return 0;
  856. }