dsdb-schema: Print clear debug message when we find a OID in our local DB we cannot...
[Samba/gebeck_regimport.git] / source4 / dsdb / schema / schema_prefixmap.c
blob270e6bebd988fd15e46eecf324522d9747dcfb8f
1 /*
2 Unix SMB/CIFS implementation.
4 DRS::prefixMap implementation
6 Copyright (C) Kamen Mazdrashki <kamen.mazdrashki@postpath.com> 2009
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #include "includes.h"
23 #include "dsdb/samdb/samdb.h"
24 #include "librpc/gen_ndr/ndr_drsuapi.h"
25 #include "librpc/gen_ndr/ndr_drsblobs.h"
26 #include "../lib/util/asn1.h"
29 /**
30 * Determine range type for supplied ATTID
32 enum dsdb_attid_type dsdb_pfm_get_attid_type(uint32_t attid)
34 if (attid <= 0x7FFFFFFF) {
35 return DSDB_ATTID_TYPE_PFM;
37 else if (attid <= 0xBFFFFFFF) {
38 return DSDB_ATTID_TYPE_INTID;
40 else if (attid <= 0xFFFEFFFF) {
41 return DSDB_ATTID_TYPE_RESERVED;
43 else {
44 return DSDB_ATTID_TYPE_INTERNAL;
48 /**
49 * Allocates schema_prefixMap object in supplied memory context
51 static struct dsdb_schema_prefixmap *_dsdb_schema_prefixmap_talloc(TALLOC_CTX *mem_ctx,
52 uint32_t length)
54 struct dsdb_schema_prefixmap *pfm;
56 pfm = talloc_zero(mem_ctx, struct dsdb_schema_prefixmap);
57 if (!pfm) {
58 return NULL;
61 pfm->length = length;
62 pfm->prefixes = talloc_zero_array(pfm, struct dsdb_schema_prefixmap_oid,
63 pfm->length);
64 if (!pfm->prefixes) {
65 talloc_free(pfm);
66 return NULL;
69 return pfm;
72 /**
73 * Initial prefixMap creation according to:
74 * [MS-DRSR] section 5.12.2
76 WERROR dsdb_schema_pfm_new(TALLOC_CTX *mem_ctx, struct dsdb_schema_prefixmap **_pfm)
78 uint32_t i;
79 struct dsdb_schema_prefixmap *pfm;
80 const struct {
81 uint32_t id;
82 const char *oid_prefix;
83 } pfm_init_data[] = {
84 {.id=0x00000000, .oid_prefix="2.5.4"},
85 {.id=0x00000001, .oid_prefix="2.5.6"},
86 {.id=0x00000002, .oid_prefix="1.2.840.113556.1.2"},
87 {.id=0x00000003, .oid_prefix="1.2.840.113556.1.3"},
88 {.id=0x00000004, .oid_prefix="2.16.840.1.101.2.2.1"},
89 {.id=0x00000005, .oid_prefix="2.16.840.1.101.2.2.3"},
90 {.id=0x00000006, .oid_prefix="2.16.840.1.101.2.1.5"},
91 {.id=0x00000007, .oid_prefix="2.16.840.1.101.2.1.4"},
92 {.id=0x00000008, .oid_prefix="2.5.5"},
93 {.id=0x00000009, .oid_prefix="1.2.840.113556.1.4"},
94 {.id=0x0000000A, .oid_prefix="1.2.840.113556.1.5"},
95 {.id=0x00000013, .oid_prefix="0.9.2342.19200300.100"},
96 {.id=0x00000014, .oid_prefix="2.16.840.1.113730.3"},
97 {.id=0x00000015, .oid_prefix="0.9.2342.19200300.100.1"},
98 {.id=0x00000016, .oid_prefix="2.16.840.1.113730.3.1"},
99 {.id=0x00000017, .oid_prefix="1.2.840.113556.1.5.7000"},
100 {.id=0x00000018, .oid_prefix="2.5.21"},
101 {.id=0x00000019, .oid_prefix="2.5.18"},
102 {.id=0x0000001A, .oid_prefix="2.5.20"},
105 /* allocate mem for prefix map */
106 pfm = _dsdb_schema_prefixmap_talloc(mem_ctx, ARRAY_SIZE(pfm_init_data));
107 W_ERROR_HAVE_NO_MEMORY(pfm);
109 /* build prefixes */
110 for (i = 0; i < pfm->length; i++) {
111 if (!ber_write_partial_OID_String(pfm, &pfm->prefixes[i].bin_oid, pfm_init_data[i].oid_prefix)) {
112 talloc_free(pfm);
113 return WERR_INTERNAL_ERROR;
115 pfm->prefixes[i].id = pfm_init_data[i].id;
118 *_pfm = pfm;
120 return WERR_OK;
124 struct dsdb_schema_prefixmap *dsdb_schema_pfm_copy_shallow(TALLOC_CTX *mem_ctx,
125 const struct dsdb_schema_prefixmap *pfm)
127 uint32_t i;
128 struct dsdb_schema_prefixmap *pfm_copy;
130 pfm_copy = _dsdb_schema_prefixmap_talloc(mem_ctx, pfm->length);
131 if (!pfm_copy) {
132 return NULL;
134 for (i = 0; i < pfm_copy->length; i++) {
135 pfm_copy->prefixes[i] = pfm->prefixes[i];
138 return pfm_copy;
142 * Adds oid to prefix map.
143 * On success returns ID for newly added index
144 * or ID of existing entry that matches oid
145 * Reference: [MS-DRSR] section 5.12.2
147 * \param pfm prefixMap
148 * \param bin_oid OID prefix to be added to prefixMap
149 * \param pfm_id Location where to store prefixMap entry ID
151 static WERROR _dsdb_schema_pfm_add_entry(struct dsdb_schema_prefixmap *pfm, DATA_BLOB bin_oid, uint32_t *_idx)
153 uint32_t i;
154 struct dsdb_schema_prefixmap_oid * pfm_entry;
155 struct dsdb_schema_prefixmap_oid * prefixes_new;
157 /* dup memory for bin-oid prefix to be added */
158 bin_oid = data_blob_dup_talloc(pfm, bin_oid);
159 W_ERROR_HAVE_NO_MEMORY(bin_oid.data);
161 /* make room for new entry */
162 prefixes_new = talloc_realloc(pfm, pfm->prefixes, struct dsdb_schema_prefixmap_oid, pfm->length + 1);
163 if (!prefixes_new) {
164 talloc_free(bin_oid.data);
165 return WERR_NOMEM;
167 pfm->prefixes = prefixes_new;
169 /* make new unique ID in prefixMap */
170 pfm_entry = &pfm->prefixes[pfm->length];
171 pfm_entry->id = 0;
172 for (i = 0; i < pfm->length; i++) {
173 if (pfm_entry->id < pfm->prefixes[i].id)
174 pfm_entry->id = pfm->prefixes[i].id;
177 /* add new bin-oid prefix */
178 pfm_entry->id++;
179 pfm_entry->bin_oid = bin_oid;
181 *_idx = pfm->length;
182 pfm->length++;
184 return WERR_OK;
189 * Make partial binary OID for supplied OID.
190 * Reference: [MS-DRSR] section 5.12.2
192 static WERROR _dsdb_pfm_make_binary_oid(const char *full_oid, TALLOC_CTX *mem_ctx,
193 DATA_BLOB *_bin_oid, uint32_t *_last_subid)
195 uint32_t last_subid;
196 const char *oid_subid;
198 /* make last sub-identifier value */
199 oid_subid = strrchr(full_oid, '.');
200 if (!oid_subid) {
201 return WERR_INVALID_PARAMETER;
203 oid_subid++;
204 last_subid = strtoul(oid_subid, NULL, 10);
206 /* encode oid in BER format */
207 if (!ber_write_OID_String(mem_ctx, _bin_oid, full_oid)) {
208 DEBUG(0,("ber_write_OID_String() failed for %s\n", full_oid));
209 return WERR_INTERNAL_ERROR;
212 /* get the prefix of the OID */
213 if (last_subid < 128) {
214 _bin_oid->length -= 1;
215 } else {
216 _bin_oid->length -= 2;
219 /* return last_value if requested */
220 if (_last_subid) {
221 *_last_subid = last_subid;
224 return WERR_OK;
228 * Lookup partial-binary-oid in prefixMap
230 WERROR dsdb_schema_pfm_find_binary_oid(const struct dsdb_schema_prefixmap *pfm,
231 DATA_BLOB bin_oid,
232 uint32_t *_idx)
234 uint32_t i;
236 for (i = 0; i < pfm->length; i++) {
237 if (pfm->prefixes[i].bin_oid.length != bin_oid.length) {
238 continue;
241 if (memcmp(pfm->prefixes[i].bin_oid.data, bin_oid.data, bin_oid.length) == 0) {
242 if (_idx) {
243 *_idx = i;
245 return WERR_OK;
249 return WERR_NOT_FOUND;
253 * Lookup full-oid in prefixMap
254 * Note: this may be slow.
256 WERROR dsdb_schema_pfm_find_oid(const struct dsdb_schema_prefixmap *pfm,
257 const char *full_oid,
258 uint32_t *_idx)
260 WERROR werr;
261 DATA_BLOB bin_oid;
263 ZERO_STRUCT(bin_oid);
265 /* make partial-binary-oid to look for */
266 werr = _dsdb_pfm_make_binary_oid(full_oid, NULL, &bin_oid, NULL);
267 W_ERROR_NOT_OK_RETURN(werr);
269 /* lookup the partial-oid */
270 werr = dsdb_schema_pfm_find_binary_oid(pfm, bin_oid, _idx);
272 data_blob_free(&bin_oid);
274 return werr;
278 * Make ATTID for given OID
279 * If OID is not in prefixMap, new prefix
280 * may be added depending on 'can_change_pfm' flag
281 * Reference: [MS-DRSR] section 5.12.2
283 static WERROR dsdb_schema_pfm_make_attid_impl(struct dsdb_schema_prefixmap *pfm,
284 const char *oid,
285 bool can_change_pfm,
286 uint32_t *attid)
288 WERROR werr;
289 uint32_t idx;
290 uint32_t lo_word, hi_word;
291 uint32_t last_subid;
292 DATA_BLOB bin_oid;
294 if (!pfm) {
295 return WERR_INVALID_PARAMETER;
297 if (!oid) {
298 return WERR_INVALID_PARAMETER;
301 werr = _dsdb_pfm_make_binary_oid(oid, pfm, &bin_oid, &last_subid);
302 W_ERROR_NOT_OK_RETURN(werr);
304 /* search the prefix in the prefix table, if none found, add
305 * one entry for new prefix.
307 werr = dsdb_schema_pfm_find_binary_oid(pfm, bin_oid, &idx);
308 if (W_ERROR_IS_OK(werr)) {
309 /* free memory allocated for bin_oid */
310 data_blob_free(&bin_oid);
311 } else {
312 /* return error in read-only mode */
313 if (!can_change_pfm) {
314 DEBUG(0, ("Unable to convert %s to an attid, and can_change_pfm=false!\n", oid));
315 return werr;
318 /* entry does not exists, add it */
319 werr = _dsdb_schema_pfm_add_entry(pfm, bin_oid, &idx);
320 W_ERROR_NOT_OK_RETURN(werr);
323 /* compose the attid */
324 lo_word = last_subid % 16384; /* actually get lower 14 bits: lo_word & 0x3FFF */
325 if (last_subid >= 16384) {
326 /* mark it so that it is known to not be the whole lastValue
327 * This will raise 16-th bit*/
328 lo_word += 32768;
330 hi_word = pfm->prefixes[idx].id;
332 /* make ATTID:
333 * HIWORD is prefixMap id
334 * LOWORD is truncated binary-oid */
335 *attid = (hi_word * 65536) + lo_word;
337 return WERR_OK;
341 * Make ATTID for given OID
342 * Reference: [MS-DRSR] section 5.12.2
344 * Note: This function may change prefixMap if prefix
345 * for supplied 'oid' doesn't exists yet.
346 * It is recommended to be used mostly when caller
347 * want to add new prefixes.
348 * Otherwise dsdb_schema_pfm_attid_from_oid() should be used.
350 WERROR dsdb_schema_pfm_make_attid(struct dsdb_schema_prefixmap *pfm,
351 const char *oid,
352 uint32_t *attid)
354 return dsdb_schema_pfm_make_attid_impl(pfm, oid, true, attid);
358 * Make ATTID for given OID
359 * Reference: [MS-DRSR] section 5.12.2
361 WERROR dsdb_schema_pfm_attid_from_oid(struct dsdb_schema_prefixmap *pfm,
362 const char *oid,
363 uint32_t *attid)
365 return dsdb_schema_pfm_make_attid_impl(pfm, oid, false, attid);
369 * Make OID for given ATTID.
370 * Reference: [MS-DRSR] section 5.12.2
372 WERROR dsdb_schema_pfm_oid_from_attid(const struct dsdb_schema_prefixmap *pfm,
373 uint32_t attid,
374 TALLOC_CTX *mem_ctx, const char **_oid)
376 uint32_t i;
377 uint32_t hi_word, lo_word;
378 DATA_BLOB bin_oid = {NULL, 0};
379 char *oid;
380 struct dsdb_schema_prefixmap_oid *pfm_entry;
381 WERROR werr = WERR_OK;
383 /* sanity check for attid requested */
384 if (dsdb_pfm_get_attid_type(attid) != DSDB_ATTID_TYPE_PFM) {
385 return WERR_INVALID_PARAMETER;
388 /* crack attid value */
389 hi_word = attid >> 16;
390 lo_word = attid & 0xFFFF;
392 /* locate corRespoNding prefixMap entry */
393 pfm_entry = NULL;
394 for (i = 0; i < pfm->length; i++) {
395 if (hi_word == pfm->prefixes[i].id) {
396 pfm_entry = &pfm->prefixes[i];
397 break;
401 if (!pfm_entry) {
402 DEBUG(1,("Failed to find prefixMap entry for ATTID = 0x%08X (%d)\n",
403 attid, attid));
404 return WERR_DS_NO_ATTRIBUTE_OR_VALUE;
407 /* copy oid prefix making enough room */
408 bin_oid.length = pfm_entry->bin_oid.length + 2;
409 bin_oid.data = talloc_array(mem_ctx, uint8_t, bin_oid.length);
410 W_ERROR_HAVE_NO_MEMORY(bin_oid.data);
411 memcpy(bin_oid.data, pfm_entry->bin_oid.data, pfm_entry->bin_oid.length);
413 if (lo_word < 128) {
414 bin_oid.length = bin_oid.length - 1;
415 bin_oid.data[bin_oid.length-1] = lo_word;
417 else {
418 if (lo_word >= 32768) {
419 lo_word -= 32768;
421 bin_oid.data[bin_oid.length-2] = (0x80 | ((lo_word>>7) & 0x7f));
422 bin_oid.data[bin_oid.length-1] = lo_word & 0x7f;
425 if (!ber_read_OID_String(mem_ctx, bin_oid, &oid)) {
426 DEBUG(0,("ber_read_OID_String() failed for %s\n",
427 hex_encode_talloc(bin_oid.data, bin_oid.data, bin_oid.length)));
428 werr = WERR_INTERNAL_ERROR;
431 /* free locally allocated memory */
432 talloc_free(bin_oid.data);
434 *_oid = oid;
436 return werr;
441 * Verifies drsuapi mappings.
443 static WERROR _dsdb_drsuapi_pfm_verify(const struct drsuapi_DsReplicaOIDMapping_Ctr *ctr,
444 bool have_schema_info)
446 uint32_t i;
447 uint32_t num_mappings;
448 struct drsuapi_DsReplicaOIDMapping *mapping;
450 /* check input params */
451 if (!ctr) {
452 return WERR_INVALID_PARAMETER;
454 if (!ctr->mappings) {
455 return WERR_INVALID_PARAMETER;
457 num_mappings = ctr->num_mappings;
459 if (have_schema_info) {
460 DATA_BLOB blob;
462 if (ctr->num_mappings < 2) {
463 return WERR_INVALID_PARAMETER;
466 /* check last entry for being special */
467 mapping = &ctr->mappings[ctr->num_mappings - 1];
468 if (mapping->id_prefix != 0) {
469 return WERR_INVALID_PARAMETER;
472 /* verify schemaInfo blob is valid one */
473 blob = data_blob_const(mapping->oid.binary_oid, mapping->oid.length);
474 if (!dsdb_schema_info_blob_is_valid(&blob)) {
475 return WERR_INVALID_PARAMETER;
478 /* get number of read mappings in the map */
479 num_mappings--;
482 /* now, verify rest of entries for being at least not null */
483 for (i = 0; i < num_mappings; i++) {
484 mapping = &ctr->mappings[i];
485 if (!mapping->oid.length) {
486 return WERR_INVALID_PARAMETER;
488 if (!mapping->oid.binary_oid) {
489 return WERR_INVALID_PARAMETER;
491 /* check it is not the special entry */
492 if (*mapping->oid.binary_oid == 0xFF) {
493 return WERR_INVALID_PARAMETER;
497 return WERR_OK;
501 * Convert drsuapi_ prefix map to prefixMap internal presentation.
503 * \param ctr Pointer to drsuapi_DsReplicaOIDMapping_Ctr which represents drsuapi_ prefixMap
504 * \param have_schema_info if drsuapi_prefixMap have schem_info in it or not
505 * \param mem_ctx TALLOC_CTX to make allocations in
506 * \param _pfm Out pointer to hold newly created prefixMap
507 * \param _schema_info Out param to store schema_info to. If NULL, schema_info is not decoded
509 WERROR dsdb_schema_pfm_from_drsuapi_pfm(const struct drsuapi_DsReplicaOIDMapping_Ctr *ctr,
510 bool have_schema_info,
511 TALLOC_CTX *mem_ctx,
512 struct dsdb_schema_prefixmap **_pfm,
513 const char **_schema_info)
515 WERROR werr;
516 uint32_t i;
517 DATA_BLOB blob;
518 uint32_t num_mappings;
519 struct dsdb_schema_prefixmap *pfm;
521 if (!_pfm) {
522 return WERR_INVALID_PARAMETER;
526 * error out if schema_info is requested
527 * but it is not in the drsuapi_prefixMap
529 if (_schema_info && !have_schema_info) {
530 return WERR_INVALID_PARAMETER;
533 /* verify drsuapi_pefixMap */
534 werr =_dsdb_drsuapi_pfm_verify(ctr, have_schema_info);
535 W_ERROR_NOT_OK_RETURN(werr);
537 /* allocate mem for prefix map */
538 num_mappings = ctr->num_mappings;
539 if (have_schema_info) {
540 num_mappings--;
542 pfm = _dsdb_schema_prefixmap_talloc(mem_ctx, num_mappings);
543 W_ERROR_HAVE_NO_MEMORY(pfm);
545 /* copy entries from drsuapi_prefixMap */
546 for (i = 0; i < pfm->length; i++) {
547 blob = data_blob_talloc(pfm,
548 ctr->mappings[i].oid.binary_oid,
549 ctr->mappings[i].oid.length);
550 if (!blob.data) {
551 talloc_free(pfm);
552 return WERR_NOMEM;
554 pfm->prefixes[i].id = ctr->mappings[i].id_prefix;
555 pfm->prefixes[i].bin_oid = blob;
558 /* fetch schema_info if requested */
559 if (_schema_info) {
560 /* by this time, i should have this value,
561 * but set it here for clarity */
562 i = ctr->num_mappings - 1;
564 *_schema_info = hex_encode_talloc(mem_ctx,
565 ctr->mappings[i].oid.binary_oid,
566 ctr->mappings[i].oid.length);
567 if (!*_schema_info) {
568 talloc_free(pfm);
569 return WERR_NOMEM;
573 /* schema_prefixMap created successfully */
574 *_pfm = pfm;
576 return WERR_OK;
580 * Convert drsuapi_ prefix map to prefixMap internal presentation.
582 * \param pfm Schema prefixMap to be converted
583 * \param schema_info schema_info string - if NULL, we don't need it
584 * \param mem_ctx TALLOC_CTX to make allocations in
585 * \param _ctr Out pointer to drsuapi_DsReplicaOIDMapping_Ctr prefix map structure
587 WERROR dsdb_drsuapi_pfm_from_schema_pfm(const struct dsdb_schema_prefixmap *pfm,
588 const char *schema_info,
589 TALLOC_CTX *mem_ctx,
590 struct drsuapi_DsReplicaOIDMapping_Ctr **_ctr)
592 uint32_t i;
593 DATA_BLOB blob;
594 struct drsuapi_DsReplicaOIDMapping_Ctr *ctr;
596 if (!_ctr) {
597 return WERR_INVALID_PARAMETER;
599 if (!pfm) {
600 return WERR_INVALID_PARAMETER;
602 if (pfm->length == 0) {
603 return WERR_INVALID_PARAMETER;
606 /* allocate memory for the structure */
607 ctr = talloc_zero(mem_ctx, struct drsuapi_DsReplicaOIDMapping_Ctr);
608 W_ERROR_HAVE_NO_MEMORY(ctr);
610 ctr->num_mappings = (schema_info ? pfm->length + 1 : pfm->length);
611 ctr->mappings = talloc_array(ctr, struct drsuapi_DsReplicaOIDMapping, ctr->num_mappings);
612 if (!ctr->mappings) {
613 talloc_free(ctr);
614 return WERR_NOMEM;
617 /* copy entries from schema_prefixMap */
618 for (i = 0; i < pfm->length; i++) {
619 blob = data_blob_dup_talloc(ctr, pfm->prefixes[i].bin_oid);
620 if (!blob.data) {
621 talloc_free(ctr);
622 return WERR_NOMEM;
624 ctr->mappings[i].id_prefix = pfm->prefixes[i].id;
625 ctr->mappings[i].oid.length = blob.length;
626 ctr->mappings[i].oid.binary_oid = blob.data;
629 /* make schema_info entry if needed */
630 if (schema_info) {
631 /* by this time, i should have this value,
632 * but set it here for clarity */
633 i = ctr->num_mappings - 1;
635 blob = strhex_to_data_blob(ctr, schema_info);
636 if (!blob.data) {
637 talloc_free(ctr);
638 return WERR_NOMEM;
641 ctr->mappings[i].id_prefix = 0;
642 ctr->mappings[i].oid.length = blob.length;
643 ctr->mappings[i].oid.binary_oid = blob.data;
646 /* drsuapi_prefixMap constructed successfully */
647 *_ctr = ctr;
649 return WERR_OK;
653 * Verifies schema prefixMap and drsuapi prefixMap are same.
654 * Note that we just need to verify pfm contains prefixes
655 * from ctr, not that those prefixes has same id_prefix.
657 WERROR dsdb_schema_pfm_contains_drsuapi_pfm(const struct dsdb_schema_prefixmap *pfm,
658 const struct drsuapi_DsReplicaOIDMapping_Ctr *ctr)
660 WERROR werr;
661 uint32_t i;
662 uint32_t idx;
663 DATA_BLOB bin_oid;
665 /* verify drsuapi_pefixMap */
666 werr = _dsdb_drsuapi_pfm_verify(ctr, true);
667 W_ERROR_NOT_OK_RETURN(werr);
669 /* check pfm contains every entry from ctr, except the last one */
670 for (i = 0; i < ctr->num_mappings - 1; i++) {
671 bin_oid.length = ctr->mappings[i].oid.length;
672 bin_oid.data = ctr->mappings[i].oid.binary_oid;
674 werr = dsdb_schema_pfm_find_binary_oid(pfm, bin_oid, &idx);
675 if (!W_ERROR_IS_OK(werr)) {
676 return WERR_DS_DRA_SCHEMA_MISMATCH;
680 return WERR_OK;