dsdb: Allow dsdb_find_dn_by_guid to show deleted DNs
[Samba/id10ts.git] / source4 / dsdb / kcc / kcc_drs_replica_info.c
blobac22312a0cecacc43d7ec11743da7f035bd1cecb
1 /*
2 Unix SMB/CIFS implementation.
4 DRS Replica Information
6 Copyright (C) Erick Nogueira do Nascimento 2009-2010
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
23 #include "includes.h"
24 #include "dsdb/samdb/samdb.h"
25 #include "dsdb/common/proto.h"
26 #include "auth/auth.h"
27 #include "smbd/service.h"
28 #include "lib/events/events.h"
29 #include "lib/messaging/irpc.h"
30 #include "dsdb/kcc/kcc_service.h"
31 #include <ldb_errors.h>
32 #include "../lib/util/dlinklist.h"
33 #include "librpc/gen_ndr/ndr_misc.h"
34 #include "librpc/gen_ndr/ndr_drsuapi.h"
35 #include "librpc/gen_ndr/ndr_drsblobs.h"
36 #include "param/param.h"
37 #include "dsdb/common/util.h"
41 get the stamp values for the linked attribute 'linked_attr_name' of the object 'dn'
43 static WERROR get_linked_attribute_value_stamp(TALLOC_CTX *mem_ctx, struct ldb_context *samdb,
44 struct ldb_dn *dn, const char *linked_attr_name,
45 uint32_t *attr_version, NTTIME *attr_change_time, uint32_t *attr_orig_usn)
47 struct ldb_result *res;
48 int ret;
49 const char *attrs[2];
50 struct ldb_dn *attr_ext_dn;
51 NTSTATUS ntstatus;
53 attrs[0] = linked_attr_name;
54 attrs[1] = NULL;
56 ret = dsdb_search_dn(samdb, mem_ctx, &res, dn, attrs,
57 DSDB_SEARCH_SHOW_EXTENDED_DN | DSDB_SEARCH_REVEAL_INTERNALS);
58 if (ret != LDB_SUCCESS) {
59 DEBUG(0, (__location__ ": Failed search for attribute %s on %s",
60 linked_attr_name, ldb_dn_get_linearized(dn)));
61 return WERR_INTERNAL_ERROR;
64 attr_ext_dn = ldb_msg_find_attr_as_dn(samdb, mem_ctx, res->msgs[0], linked_attr_name);
65 if (!attr_ext_dn) {
66 DEBUG(0, (__location__ ": Failed search for attribute %s on %s",
67 linked_attr_name, ldb_dn_get_linearized(dn)));
68 return WERR_INTERNAL_ERROR;
71 DEBUG(0, ("linked_attr_name = %s, attr_ext_dn = %s", linked_attr_name,
72 ldb_dn_get_extended_linearized(mem_ctx, attr_ext_dn, 1)));
74 ntstatus = dsdb_get_extended_dn_uint32(attr_ext_dn, attr_version, "RMD_VERSION");
75 if (!NT_STATUS_IS_OK(ntstatus)) {
76 DEBUG(0, (__location__ ": Could not extract component %s from dn \"%s\"",
77 "RMD_VERSION", ldb_dn_get_extended_linearized(mem_ctx, attr_ext_dn, 1)));
78 return WERR_INTERNAL_ERROR;
81 ntstatus = dsdb_get_extended_dn_nttime(attr_ext_dn, attr_change_time, "RMD_CHANGETIME");
82 if (!NT_STATUS_IS_OK(ntstatus)) {
83 DEBUG(0, (__location__ ": Could not extract component %s from dn \"%s\"",
84 "RMD_CHANGETIME", ldb_dn_get_extended_linearized(mem_ctx, attr_ext_dn, 1)));
85 return WERR_INTERNAL_ERROR;
88 ntstatus = dsdb_get_extended_dn_uint32(attr_ext_dn, attr_version, "RMD_ORIGINATING_USN");
89 if (!NT_STATUS_IS_OK(ntstatus)) {
90 DEBUG(0, (__location__ ": Could not extract component %s from dn \"%s\"",
91 "RMD_ORIGINATING_USN", ldb_dn_get_extended_linearized(mem_ctx, attr_ext_dn, 1)));
92 return WERR_INTERNAL_ERROR;
95 return WERR_OK;
98 static WERROR get_repl_prop_metadata_ctr(TALLOC_CTX *mem_ctx,
99 struct ldb_context *samdb,
100 struct ldb_dn *dn,
101 struct replPropertyMetaDataBlob *obj_metadata_ctr)
103 int ret;
104 struct ldb_result *res;
105 const char *attrs[] = { "replPropertyMetaData", NULL };
106 const struct ldb_val *omd_value;
107 enum ndr_err_code ndr_err;
109 ret = ldb_search(samdb, mem_ctx, &res, dn, LDB_SCOPE_BASE, attrs, NULL);
110 if (ret != LDB_SUCCESS || res->count != 1) {
111 DEBUG(0, (__location__ ": Failed search for replPropertyMetaData attribute on %s",
112 ldb_dn_get_linearized(dn)));
113 return WERR_INTERNAL_ERROR;
116 omd_value = ldb_msg_find_ldb_val(res->msgs[0], "replPropertyMetaData");
117 if (!omd_value) {
118 DEBUG(0,(__location__ ": Object %s does not have a replPropertyMetaData attribute\n",
119 ldb_dn_get_linearized(dn)));
120 talloc_free(res);
121 return WERR_INTERNAL_ERROR;
124 ndr_err = ndr_pull_struct_blob(omd_value, mem_ctx,
125 obj_metadata_ctr,
126 (ndr_pull_flags_fn_t)ndr_pull_replPropertyMetaDataBlob);
127 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
128 DEBUG(0,(__location__ ": Failed to parse replPropertyMetaData for %s\n",
129 ldb_dn_get_linearized(dn)));
130 talloc_free(res);
131 return WERR_INTERNAL_ERROR;
134 talloc_free(res);
135 return WERR_OK;
139 get the DN of the nTDSDSA object from the configuration partition
140 whose invocationId is 'invocation_id'
141 put the value on 'dn_str'
143 static WERROR get_dn_from_invocation_id(TALLOC_CTX *mem_ctx,
144 struct ldb_context *samdb,
145 struct GUID *invocation_id,
146 const char **dn_str)
148 char *invocation_id_str;
149 const char *attrs_invocation[] = { NULL };
150 struct ldb_message *msg;
151 int ret;
153 invocation_id_str = GUID_string(mem_ctx, invocation_id);
154 W_ERROR_HAVE_NO_MEMORY(invocation_id_str);
156 ret = dsdb_search_one(samdb, invocation_id_str, &msg, ldb_get_config_basedn(samdb), LDB_SCOPE_SUBTREE,
157 attrs_invocation, 0, "(&(objectClass=nTDSDSA)(invocationId=%s))", invocation_id_str);
158 if (ret != LDB_SUCCESS) {
159 DEBUG(0, (__location__ ": Failed search for the object DN under %s whose invocationId is %s",
160 invocation_id_str, ldb_dn_get_linearized(ldb_get_config_basedn(samdb))));
161 talloc_free(invocation_id_str);
162 return WERR_INTERNAL_ERROR;
165 *dn_str = ldb_dn_alloc_linearized(mem_ctx, msg->dn);
166 talloc_free(invocation_id_str);
167 return WERR_OK;
171 get metadata version 2 info for a specified object DN
173 static WERROR kccdrs_replica_get_info_obj_metadata2(TALLOC_CTX *mem_ctx,
174 struct ldb_context *samdb,
175 struct drsuapi_DsReplicaGetInfo *r,
176 union drsuapi_DsReplicaInfo *reply,
177 struct ldb_dn *dn,
178 uint32_t base_index)
180 WERROR status;
181 struct replPropertyMetaDataBlob omd_ctr;
182 struct replPropertyMetaData1 *attr;
183 struct drsuapi_DsReplicaObjMetaData2Ctr *metadata2;
184 const struct dsdb_schema *schema;
186 uint32_t i, j;
188 DEBUG(0, ("kccdrs_replica_get_info_obj_metadata2() called\n"));
190 if (!dn) {
191 return WERR_INVALID_PARAMETER;
194 if (!ldb_dn_validate(dn)) {
195 return WERR_DS_DRA_BAD_DN;
198 status = get_repl_prop_metadata_ctr(mem_ctx, samdb, dn, &omd_ctr);
199 W_ERROR_NOT_OK_RETURN(status);
201 schema = dsdb_get_schema(samdb, reply);
202 if (!schema) {
203 DEBUG(0,(__location__": Failed to get the schema\n"));
204 return WERR_INTERNAL_ERROR;
207 reply->objmetadata2 = talloc_zero(mem_ctx, struct drsuapi_DsReplicaObjMetaData2Ctr);
208 W_ERROR_HAVE_NO_MEMORY(reply->objmetadata2);
209 metadata2 = reply->objmetadata2;
210 metadata2->enumeration_context = 0;
212 /* For each replicated attribute of the object */
213 for (i = 0, j = 0; i < omd_ctr.ctr.ctr1.count; i++) {
214 const struct dsdb_attribute *schema_attr;
215 uint32_t attr_version;
216 NTTIME attr_change_time;
217 uint32_t attr_originating_usn;
220 attr := attrsSeq[i]
221 s := AttrStamp(object, attr)
223 /* get a reference to the attribute on 'omd_ctr' */
224 attr = &omd_ctr.ctr.ctr1.array[j];
226 schema_attr = dsdb_attribute_by_attributeID_id(schema, attr->attid);
228 DEBUG(0, ("attribute_id = %d, attribute_name: %s\n", attr->attid, schema_attr->lDAPDisplayName));
231 if (attr in Link Attributes of object and
232 dwInVersion = 2 and DS_REPL_INFO_FLAG_IMPROVE_LINKED_ATTRS in msgIn.ulFlags)
234 if (schema_attr &&
235 schema_attr->linkID != 0 && /* Checks if attribute is a linked attribute */
236 (schema_attr->linkID % 2) == 0 && /* is it a forward link? only forward links have the LinkValueStamp */
237 r->in.level == 2 &&
238 (r->in.req->req2.flags & DRSUAPI_DS_LINKED_ATTRIBUTE_FLAG_ACTIVE)) /* on MS-DRSR it is DS_REPL_INFO_FLAG_IMPROVE_LINKED_ATTRS */
241 ls := LinkValueStamp of the most recent
242 value change in object!attr
244 status = get_linked_attribute_value_stamp(mem_ctx, samdb, dn, schema_attr->lDAPDisplayName,
245 &attr_version, &attr_change_time, &attr_originating_usn);
246 W_ERROR_NOT_OK_RETURN(status);
249 Aligning to MS-DRSR 4.1.13.3:
250 's' on the doc is 'attr->originating_change_time' here
251 'ls' on the doc is 'attr_change_time' here
254 /* if (ls is more recent than s (based on order in which the change was applied on server)) then */
255 if (attr_change_time > attr->originating_change_time) {
257 Improve the stamp with the link value stamp.
258 s.dwVersion := ls.dwVersion
259 s.timeChanged := ls.timeChanged
260 s.uuidOriginating := NULLGUID
261 s.usnOriginating := ls.usnOriginating
263 attr->version = attr_version;
264 attr->originating_change_time = attr_change_time;
265 attr->originating_invocation_id = GUID_zero();
266 attr->originating_usn = attr_originating_usn;
270 if (i < base_index) {
271 continue;
274 metadata2->array = talloc_realloc(mem_ctx, metadata2->array,
275 struct drsuapi_DsReplicaObjMetaData2, j + 1);
276 W_ERROR_HAVE_NO_MEMORY(metadata2->array);
277 metadata2->array[j].attribute_name = schema_attr->lDAPDisplayName;
278 metadata2->array[j].local_usn = attr->local_usn;
279 metadata2->array[j].originating_change_time = attr->originating_change_time;
280 metadata2->array[j].originating_invocation_id = attr->originating_invocation_id;
281 metadata2->array[j].originating_usn = attr->originating_usn;
282 metadata2->array[j].version = attr->version;
285 originating_dsa_dn := GetDNFromInvocationID(originating_invocation_id)
286 GetDNFromInvocationID() should return the DN of the nTDSDSAobject that has the specified invocation ID
287 See MS-DRSR 4.1.13.3 and 4.1.13.2.1
289 status = get_dn_from_invocation_id(mem_ctx, samdb,
290 &attr->originating_invocation_id,
291 &metadata2->array[j].originating_dsa_dn);
292 W_ERROR_NOT_OK_RETURN(status);
293 j++;
294 metadata2->count = j;
298 return WERR_OK;
302 get cursors info for a specified DN
304 static WERROR kccdrs_replica_get_info_cursors(TALLOC_CTX *mem_ctx,
305 struct ldb_context *samdb,
306 struct drsuapi_DsReplicaGetInfo *r,
307 union drsuapi_DsReplicaInfo *reply,
308 struct ldb_dn *dn)
310 int ret;
312 if (!ldb_dn_validate(dn)) {
313 return WERR_INVALID_PARAMETER;
315 reply->cursors = talloc(mem_ctx, struct drsuapi_DsReplicaCursorCtr);
316 W_ERROR_HAVE_NO_MEMORY(reply->cursors);
318 reply->cursors->reserved = 0;
320 ret = dsdb_load_udv_v1(samdb, dn, reply->cursors, &reply->cursors->array, &reply->cursors->count);
321 if (ret != LDB_SUCCESS) {
322 return WERR_DS_DRA_BAD_NC;
324 return WERR_OK;
328 get cursors2 info for a specified DN
330 static WERROR kccdrs_replica_get_info_cursors2(TALLOC_CTX *mem_ctx,
331 struct ldb_context *samdb,
332 struct drsuapi_DsReplicaGetInfo *r,
333 union drsuapi_DsReplicaInfo *reply,
334 struct ldb_dn *dn)
336 int ret;
338 if (!ldb_dn_validate(dn)) {
339 return WERR_INVALID_PARAMETER;
341 reply->cursors2 = talloc(mem_ctx, struct drsuapi_DsReplicaCursor2Ctr);
342 W_ERROR_HAVE_NO_MEMORY(reply->cursors2);
344 ret = dsdb_load_udv_v2(samdb, dn, reply->cursors2, &reply->cursors2->array, &reply->cursors2->count);
345 if (ret != LDB_SUCCESS) {
346 return WERR_DS_DRA_BAD_NC;
349 reply->cursors2->enumeration_context = reply->cursors2->count;
350 return WERR_OK;
354 get pending ops info for a specified DN
356 static WERROR kccdrs_replica_get_info_pending_ops(TALLOC_CTX *mem_ctx,
357 struct ldb_context *samdb,
358 struct drsuapi_DsReplicaGetInfo *r,
359 union drsuapi_DsReplicaInfo *reply,
360 struct ldb_dn *dn)
362 struct timeval now = timeval_current();
364 if (!ldb_dn_validate(dn)) {
365 return WERR_INVALID_PARAMETER;
367 reply->pendingops = talloc(mem_ctx, struct drsuapi_DsReplicaOpCtr);
368 W_ERROR_HAVE_NO_MEMORY(reply->pendingops);
370 /* claim no pending ops for now */
371 reply->pendingops->time = timeval_to_nttime(&now);
372 reply->pendingops->count = 0;
373 reply->pendingops->array = NULL;
375 return WERR_OK;
378 struct ncList {
379 struct ldb_dn *dn;
380 struct ncList *prev, *next;
384 Fill 'master_nc_list' with the master ncs hosted by this server
386 static WERROR get_master_ncs(TALLOC_CTX *mem_ctx, struct ldb_context *samdb,
387 const char *ntds_guid_str, struct ncList **master_nc_list)
389 const char *post_2003_attrs[] = { "msDS-hasMasterNCs", "hasPartialReplicaNCs", NULL };
390 const char *pre_2003_attrs[] = { "hasMasterNCs", "hasPartialReplicaNCs", NULL };
391 const char **attrs = post_2003_attrs;
392 struct ldb_result *res;
393 struct ncList *nc_list = NULL;
394 struct ncList *nc_list_elem;
395 int ret;
396 unsigned int i;
397 char *nc_str;
399 /* In W2003 and greater, msDS-hasMasterNCs attribute lists the writable NC replicas */
400 ret = ldb_search(samdb, mem_ctx, &res, ldb_get_config_basedn(samdb),
401 LDB_SCOPE_DEFAULT, post_2003_attrs, "(objectguid=%s)", ntds_guid_str);
403 if (ret != LDB_SUCCESS) {
404 DEBUG(0,(__location__ ": Failed objectguid search - %s\n", ldb_errstring(samdb)));
406 attrs = post_2003_attrs;
407 ret = ldb_search(samdb, mem_ctx, &res, ldb_get_config_basedn(samdb),
408 LDB_SCOPE_DEFAULT, pre_2003_attrs, "(objectguid=%s)", ntds_guid_str);
411 if (ret != LDB_SUCCESS) {
412 DEBUG(0,(__location__ ": Failed objectguid search - %s\n", ldb_errstring(samdb)));
413 return WERR_INTERNAL_ERROR;
416 if (res->count == 0) {
417 DEBUG(0,(__location__ ": Failed: objectguid=%s not found\n", ntds_guid_str));
418 return WERR_INTERNAL_ERROR;
421 for (i = 0; i < res->count; i++) {
422 struct ldb_message_element *msg_elem;
423 unsigned int k, a;
425 for (a=0; attrs[a]; a++) {
426 msg_elem = ldb_msg_find_element(res->msgs[i], attrs[a]);
427 if (!msg_elem || msg_elem->num_values == 0) {
428 continue;
431 for (k = 0; k < msg_elem->num_values; k++) {
432 /* copy the string on msg_elem->values[k]->data to nc_str */
433 nc_str = talloc_strndup(mem_ctx, (char *)msg_elem->values[k].data, msg_elem->values[k].length);
434 W_ERROR_HAVE_NO_MEMORY(nc_str);
436 nc_list_elem = talloc_zero(mem_ctx, struct ncList);
437 W_ERROR_HAVE_NO_MEMORY(nc_list_elem);
438 nc_list_elem->dn = ldb_dn_new(mem_ctx, samdb, nc_str);
439 W_ERROR_HAVE_NO_MEMORY(nc_list_elem);
440 DLIST_ADD(nc_list, nc_list_elem);
445 *master_nc_list = nc_list;
446 return WERR_OK;
450 Fill 'nc_list' with the ncs list. (MS-DRSR 4.1.13.3)
451 if the object dn is specified, fill 'nc_list' only with this dn
452 otherwise, fill 'nc_list' with all master ncs hosted by this server
454 static WERROR get_ncs_list(TALLOC_CTX *mem_ctx,
455 struct ldb_context *samdb,
456 struct kccsrv_service *service,
457 const char *object_dn_str,
458 struct ncList **nc_list)
460 WERROR status;
461 struct ncList *nc_list_elem;
462 struct ldb_dn *nc_dn;
464 if (object_dn_str != NULL) {
465 /* ncs := { object_dn } */
466 *nc_list = NULL;
467 nc_dn = ldb_dn_new(mem_ctx, samdb, object_dn_str);
468 nc_list_elem = talloc_zero(mem_ctx, struct ncList);
469 W_ERROR_HAVE_NO_MEMORY(nc_list_elem);
470 nc_list_elem->dn = nc_dn;
471 DLIST_ADD_END(*nc_list, nc_list_elem, struct ncList*);
472 } else {
473 /* ncs := getNCs() from ldb database.
474 * getNCs() must return an array containing
475 * the DSNames of all NCs hosted by this
476 * server.
478 char *ntds_guid_str = GUID_string(mem_ctx, &service->ntds_guid);
479 W_ERROR_HAVE_NO_MEMORY(ntds_guid_str);
480 status = get_master_ncs(mem_ctx, samdb, ntds_guid_str, nc_list);
481 W_ERROR_NOT_OK_RETURN(status);
484 return WERR_OK;
488 Copy the fields from 'reps1' to 'reps2', leaving zeroed the fields on
489 'reps2' that aren't available on 'reps1'.
491 static WERROR copy_repsfrom_1_to_2(TALLOC_CTX *mem_ctx,
492 struct repsFromTo2 **reps2,
493 struct repsFromTo1 *reps1)
495 struct repsFromTo2* reps;
497 reps = talloc_zero(mem_ctx, struct repsFromTo2);
498 W_ERROR_HAVE_NO_MEMORY(reps);
500 reps->blobsize = reps1->blobsize;
501 reps->consecutive_sync_failures = reps1->consecutive_sync_failures;
502 reps->last_attempt = reps1->last_attempt;
503 reps->last_success = reps1->last_success;
504 reps->result_last_attempt = reps1->result_last_attempt;
505 reps->other_info = talloc_zero(mem_ctx, struct repsFromTo2OtherInfo);
506 W_ERROR_HAVE_NO_MEMORY(reps->other_info);
507 reps->other_info->dns_name1 = reps1->other_info->dns_name;
508 reps->replica_flags = reps1->replica_flags;
509 memcpy(reps->schedule, reps1->schedule, sizeof(reps1->schedule));
510 reps->reserved = reps1->reserved;
511 reps->highwatermark = reps1->highwatermark;
512 reps->source_dsa_obj_guid = reps1->source_dsa_obj_guid;
513 reps->source_dsa_invocation_id = reps1->source_dsa_invocation_id;
514 reps->transport_guid = reps1->transport_guid;
516 *reps2 = reps;
517 return WERR_OK;
520 static WERROR fill_neighbor_from_repsFrom(TALLOC_CTX *mem_ctx,
521 struct ldb_context *samdb,
522 struct ldb_dn *nc_dn,
523 struct drsuapi_DsReplicaNeighbour *neigh,
524 struct repsFromTo2 *reps_from)
526 struct ldb_dn *source_dsa_dn;
527 int ret;
528 struct ldb_dn *transport_obj_dn = NULL;
530 neigh->source_dsa_address = reps_from->other_info->dns_name1;
531 neigh->replica_flags = reps_from->replica_flags;
532 neigh->last_attempt = reps_from->last_attempt;
533 neigh->source_dsa_obj_guid = reps_from->source_dsa_obj_guid;
535 ret = dsdb_find_dn_by_guid(samdb, mem_ctx, &reps_from->source_dsa_obj_guid,
536 DSDB_SEARCH_SHOW_RECYCLED,
537 &source_dsa_dn);
539 if (ret != LDB_SUCCESS) {
540 DEBUG(0,(__location__ ": Failed to find DN for neighbor GUID %s\n",
541 GUID_string(mem_ctx, &reps_from->source_dsa_obj_guid)));
542 return WERR_DS_DRA_INTERNAL_ERROR;
545 neigh->source_dsa_obj_dn = ldb_dn_get_linearized(source_dsa_dn);
546 neigh->naming_context_dn = ldb_dn_get_linearized(nc_dn);
548 if (dsdb_find_guid_by_dn(samdb, nc_dn,
549 &neigh->naming_context_obj_guid)
550 != LDB_SUCCESS) {
551 return WERR_DS_DRA_INTERNAL_ERROR;
554 if (!GUID_all_zero(&reps_from->transport_guid)) {
555 ret = dsdb_find_dn_by_guid(samdb, mem_ctx, &reps_from->transport_guid,
556 DSDB_SEARCH_SHOW_RECYCLED,
557 &transport_obj_dn);
558 if (ret != LDB_SUCCESS) {
559 return WERR_DS_DRA_INTERNAL_ERROR;
563 neigh->transport_obj_dn = ldb_dn_get_linearized(transport_obj_dn);
564 neigh->source_dsa_invocation_id = reps_from->source_dsa_invocation_id;
565 neigh->transport_obj_guid = reps_from->transport_guid;
566 neigh->highest_usn = reps_from->highwatermark.highest_usn;
567 neigh->tmp_highest_usn = reps_from->highwatermark.tmp_highest_usn;
568 neigh->last_success = reps_from->last_success;
569 neigh->result_last_attempt = reps_from->result_last_attempt;
570 neigh->consecutive_sync_failures = reps_from->consecutive_sync_failures;
571 neigh->reserved = 0; /* Unused. MUST be 0. */
573 return WERR_OK;
577 Get the inbound neighbours of this DC
578 See details on MS-DRSR 4.1.13.3, for infoType DS_REPL_INFO_NEIGHBORS
580 static WERROR kccdrs_replica_get_info_neighbours(TALLOC_CTX *mem_ctx,
581 struct kccsrv_service *service,
582 struct ldb_context *samdb,
583 struct drsuapi_DsReplicaGetInfo *r,
584 union drsuapi_DsReplicaInfo *reply,
585 uint32_t base_index,
586 struct GUID req_src_dsa_guid,
587 const char *object_dn_str)
589 WERROR status;
590 uint32_t i, j;
591 struct ldb_dn *nc_dn = NULL;
592 struct ncList *p_nc_list = NULL;
593 struct repsFromToBlob *reps_from_blob = NULL;
594 struct repsFromTo2 *reps_from = NULL;
595 uint32_t c_reps_from;
596 uint32_t i_rep;
597 struct ncList *nc_list = NULL;
599 status = get_ncs_list(mem_ctx, samdb, service, object_dn_str, &nc_list);
600 W_ERROR_NOT_OK_RETURN(status);
602 i = j = 0;
604 reply->neighbours = talloc_zero(mem_ctx, struct drsuapi_DsReplicaNeighbourCtr);
605 W_ERROR_HAVE_NO_MEMORY(reply->neighbours);
606 reply->neighbours->reserved = 0;
607 reply->neighbours->count = 0;
609 /* foreach nc in ncs */
610 for (p_nc_list = nc_list; p_nc_list != NULL; p_nc_list = p_nc_list->next) {
612 nc_dn = p_nc_list->dn;
614 /* load the nc's repsFromTo blob */
615 status = dsdb_loadreps(samdb, mem_ctx, nc_dn, "repsFrom",
616 &reps_from_blob, &c_reps_from);
617 W_ERROR_NOT_OK_RETURN(status);
619 /* foreach r in nc!repsFrom */
620 for (i_rep = 0; i_rep < c_reps_from; i_rep++) {
622 /* put all info on reps_from */
623 if (reps_from_blob[i_rep].version == 1) {
624 status = copy_repsfrom_1_to_2(mem_ctx, &reps_from,
625 &reps_from_blob[i_rep].ctr.ctr1);
626 W_ERROR_NOT_OK_RETURN(status);
627 } else { /* reps_from->version == 2 */
628 reps_from = &reps_from_blob[i_rep].ctr.ctr2;
631 if (GUID_all_zero(&req_src_dsa_guid) ||
632 GUID_compare(&req_src_dsa_guid, &reps_from->source_dsa_obj_guid) == 0)
635 if (i >= base_index) {
636 struct drsuapi_DsReplicaNeighbour neigh;
637 ZERO_STRUCT(neigh);
638 status = fill_neighbor_from_repsFrom(mem_ctx, samdb,
639 nc_dn, &neigh,
640 reps_from);
641 W_ERROR_NOT_OK_RETURN(status);
643 /* append the neighbour to the neighbours array */
644 reply->neighbours->array = talloc_realloc(mem_ctx,
645 reply->neighbours->array,
646 struct drsuapi_DsReplicaNeighbour,
647 reply->neighbours->count + 1);
648 reply->neighbours->array[reply->neighbours->count] = neigh;
649 reply->neighbours->count++;
650 j++;
653 i++;
658 return WERR_OK;
661 static WERROR fill_neighbor_from_repsTo(TALLOC_CTX *mem_ctx,
662 struct ldb_context *samdb, struct ldb_dn *nc_dn,
663 struct drsuapi_DsReplicaNeighbour *neigh,
664 struct repsFromTo2 *reps_to)
666 int ret;
667 struct ldb_dn *source_dsa_dn;
669 neigh->source_dsa_address = reps_to->other_info->dns_name1;
670 neigh->replica_flags = reps_to->replica_flags;
671 neigh->last_attempt = reps_to->last_attempt;
672 neigh->source_dsa_obj_guid = reps_to->source_dsa_obj_guid;
674 ret = dsdb_find_dn_by_guid(samdb, mem_ctx,
675 &reps_to->source_dsa_obj_guid,
676 DSDB_SEARCH_SHOW_RECYCLED,
677 &source_dsa_dn);
678 if (ret != LDB_SUCCESS) {
679 DEBUG(0,(__location__ ": Failed to find DN for neighbor GUID %s\n",
680 GUID_string(mem_ctx, &reps_to->source_dsa_obj_guid)));
681 return WERR_DS_DRA_INTERNAL_ERROR;
684 neigh->source_dsa_obj_dn = ldb_dn_get_linearized(source_dsa_dn);
685 neigh->naming_context_dn = ldb_dn_get_linearized(nc_dn);
687 ret = dsdb_find_guid_by_dn(samdb, nc_dn,
688 &neigh->naming_context_obj_guid);
689 if (ret != LDB_SUCCESS) {
690 DEBUG(0,(__location__ ": Failed to find GUID for DN %s\n",
691 ldb_dn_get_linearized(nc_dn)));
692 return WERR_DS_DRA_INTERNAL_ERROR;
695 neigh->last_success = reps_to->last_success;
696 neigh->result_last_attempt = reps_to->result_last_attempt;
697 neigh->consecutive_sync_failures = reps_to->consecutive_sync_failures;
698 return WERR_OK;
702 Get the outbound neighbours of this DC
703 See details on MS-DRSR 4.1.13.3, for infoType DS_REPL_INFO_REPSTO
705 static WERROR kccdrs_replica_get_info_repsto(TALLOC_CTX *mem_ctx,
706 struct kccsrv_service *service,
707 struct ldb_context *samdb,
708 struct drsuapi_DsReplicaGetInfo *r,
709 union drsuapi_DsReplicaInfo *reply,
710 uint32_t base_index,
711 struct GUID req_src_dsa_guid,
712 const char *object_dn_str)
714 WERROR status;
715 uint32_t i, j;
716 struct ncList *p_nc_list = NULL;
717 struct ldb_dn *nc_dn = NULL;
718 struct repsFromToBlob *reps_to_blob;
719 struct repsFromTo2 *reps_to;
720 uint32_t c_reps_to;
721 uint32_t i_rep;
722 struct ncList *nc_list = NULL;
724 status = get_ncs_list(mem_ctx, samdb, service, object_dn_str, &nc_list);
725 W_ERROR_NOT_OK_RETURN(status);
727 i = j = 0;
729 reply->repsto = talloc_zero(mem_ctx, struct drsuapi_DsReplicaNeighbourCtr);
730 W_ERROR_HAVE_NO_MEMORY(reply->repsto);
731 reply->repsto->reserved = 0;
732 reply->repsto->count = 0;
734 /* foreach nc in ncs */
735 for (p_nc_list = nc_list; p_nc_list != NULL; p_nc_list = p_nc_list->next) {
737 nc_dn = p_nc_list->dn;
739 status = dsdb_loadreps(samdb, mem_ctx, nc_dn, "repsTo",
740 &reps_to_blob, &c_reps_to);
741 W_ERROR_NOT_OK_RETURN(status);
743 /* foreach r in nc!repsTo */
744 for (i_rep = 0; i_rep < c_reps_to; i_rep++) {
745 struct drsuapi_DsReplicaNeighbour neigh;
746 ZERO_STRUCT(neigh);
748 /* put all info on reps_to */
749 if (reps_to_blob[i_rep].version == 1) {
750 status = copy_repsfrom_1_to_2(mem_ctx,
751 &reps_to,
752 &reps_to_blob[i_rep].ctr.ctr1);
753 W_ERROR_NOT_OK_RETURN(status);
754 } else { /* reps_to->version == 2 */
755 reps_to = &reps_to_blob[i_rep].ctr.ctr2;
758 if (i >= base_index) {
759 status = fill_neighbor_from_repsTo(mem_ctx,
760 samdb, nc_dn,
761 &neigh, reps_to);
762 W_ERROR_NOT_OK_RETURN(status);
764 /* append the neighbour to the neighbours array */
765 reply->repsto->array = talloc_realloc(mem_ctx,
766 reply->repsto->array,
767 struct drsuapi_DsReplicaNeighbour,
768 reply->repsto->count + 1);
769 reply->repsto->array[reply->repsto->count++] = neigh;
770 j++;
772 i++;
776 return WERR_OK;
779 NTSTATUS kccdrs_replica_get_info(struct irpc_message *msg,
780 struct drsuapi_DsReplicaGetInfo *req)
782 WERROR status;
783 struct drsuapi_DsReplicaGetInfoRequest1 *req1;
784 struct drsuapi_DsReplicaGetInfoRequest2 *req2;
785 uint32_t base_index;
786 union drsuapi_DsReplicaInfo *reply;
787 struct GUID req_src_dsa_guid;
788 const char *object_dn_str = NULL;
789 struct kccsrv_service *service;
790 struct ldb_context *samdb;
791 TALLOC_CTX *mem_ctx;
792 enum drsuapi_DsReplicaInfoType info_type;
794 service = talloc_get_type(msg->private_data, struct kccsrv_service);
795 samdb = service->samdb;
796 mem_ctx = talloc_new(msg);
797 NT_STATUS_HAVE_NO_MEMORY(mem_ctx);
799 #if 0
800 NDR_PRINT_IN_DEBUG(drsuapi_DsReplicaGetInfo, req);
801 #endif
803 /* check request version */
804 if (req->in.level != DRSUAPI_DS_REPLICA_GET_INFO &&
805 req->in.level != DRSUAPI_DS_REPLICA_GET_INFO2)
807 DEBUG(1,(__location__ ": Unsupported DsReplicaGetInfo level %u\n",
808 req->in.level));
809 status = WERR_REVISION_MISMATCH;
810 goto done;
813 if (req->in.level == DRSUAPI_DS_REPLICA_GET_INFO) {
814 req1 = &req->in.req->req1;
815 base_index = 0;
816 info_type = req1->info_type;
817 object_dn_str = req1->object_dn;
818 req_src_dsa_guid = req1->source_dsa_guid;
819 } else { /* r->in.level == DRSUAPI_DS_REPLICA_GET_INFO2 */
820 req2 = &req->in.req->req2;
821 if (req2->enumeration_context == 0xffffffff) {
822 /* no more data is available */
823 status = WERR_NO_MORE_ITEMS; /* on MS-DRSR it is ERROR_NO_MORE_ITEMS */
824 goto done;
827 base_index = req2->enumeration_context;
828 info_type = req2->info_type;
829 object_dn_str = req2->object_dn;
830 req_src_dsa_guid = req2->source_dsa_guid;
833 reply = req->out.info;
834 *req->out.info_type = info_type;
836 /* Based on the infoType requested, retrieve the corresponding
837 * information and construct the response message */
838 switch (info_type) {
840 case DRSUAPI_DS_REPLICA_INFO_NEIGHBORS:
841 status = kccdrs_replica_get_info_neighbours(mem_ctx, service, samdb, req,
842 reply, base_index, req_src_dsa_guid,
843 object_dn_str);
844 break;
845 case DRSUAPI_DS_REPLICA_INFO_REPSTO:
846 status = kccdrs_replica_get_info_repsto(mem_ctx, service, samdb, req,
847 reply, base_index, req_src_dsa_guid,
848 object_dn_str);
849 break;
850 case DRSUAPI_DS_REPLICA_INFO_CURSORS: /* On MS-DRSR it is DS_REPL_INFO_CURSORS_FOR_NC */
851 status = kccdrs_replica_get_info_cursors(mem_ctx, samdb, req, reply,
852 ldb_dn_new(mem_ctx, samdb, object_dn_str));
853 break;
854 case DRSUAPI_DS_REPLICA_INFO_CURSORS2: /* On MS-DRSR it is DS_REPL_INFO_CURSORS_2_FOR_NC */
855 status = kccdrs_replica_get_info_cursors2(mem_ctx, samdb, req, reply,
856 ldb_dn_new(mem_ctx, samdb, object_dn_str));
857 break;
858 case DRSUAPI_DS_REPLICA_INFO_PENDING_OPS:
859 status = kccdrs_replica_get_info_pending_ops(mem_ctx, samdb, req, reply,
860 ldb_dn_new(mem_ctx, samdb, object_dn_str));
861 break;
862 case DRSUAPI_DS_REPLICA_INFO_CURSORS3: /* On MS-DRSR it is DS_REPL_INFO_CURSORS_3_FOR_NC */
863 status = WERR_NOT_SUPPORTED;
864 break;
865 case DRSUAPI_DS_REPLICA_INFO_UPTODATE_VECTOR_V1: /* On MS-DRSR it is DS_REPL_INFO_UPTODATE_VECTOR_V1 */
866 status = WERR_NOT_SUPPORTED;
867 break;
868 case DRSUAPI_DS_REPLICA_INFO_OBJ_METADATA: /* On MS-DRSR it is DS_REPL_INFO_METADATA_FOR_OBJ */
870 * It should be too complicated to filter the metadata2 to remove the additional data
871 * as metadata2 is a superset of metadata
873 status = WERR_NOT_SUPPORTED;
874 break;
875 case DRSUAPI_DS_REPLICA_INFO_OBJ_METADATA2: /* On MS-DRSR it is DS_REPL_INFO_METADATA_FOR_OBJ */
876 status = kccdrs_replica_get_info_obj_metadata2(mem_ctx, samdb, req, reply,
877 ldb_dn_new(mem_ctx, samdb, object_dn_str), base_index);
878 break;
879 case DRSUAPI_DS_REPLICA_INFO_ATTRIBUTE_VALUE_METADATA: /* On MS-DRSR it is DS_REPL_INFO_METADATA_FOR_ATTR_VALUE */
880 status = WERR_NOT_SUPPORTED;
881 break;
882 case DRSUAPI_DS_REPLICA_INFO_ATTRIBUTE_VALUE_METADATA2: /* On MS-DRSR it is DS_REPL_INFO_METADATA_2_FOR_ATTR_VALUE */
883 status = WERR_NOT_SUPPORTED;
884 break;
885 case DRSUAPI_DS_REPLICA_INFO_KCC_DSA_CONNECT_FAILURES: /* On MS-DRSR it is DS_REPL_INFO_KCC_DSA_CONNECT_FAILURES */
886 status = WERR_NOT_SUPPORTED;
887 break;
888 case DRSUAPI_DS_REPLICA_INFO_KCC_DSA_LINK_FAILURES: /* On MS-DRSR it is DS_REPL_INFO_KCC_LINK_FAILURES */
889 status = WERR_NOT_SUPPORTED;
890 break;
891 case DRSUAPI_DS_REPLICA_INFO_CLIENT_CONTEXTS: /* On MS-DRSR it is DS_REPL_INFO_CLIENT_CONTEXTS */
892 status = WERR_NOT_SUPPORTED;
893 break;
894 case DRSUAPI_DS_REPLICA_INFO_SERVER_OUTGOING_CALLS: /* On MS-DRSR it is DS_REPL_INFO_SERVER_OUTGOING_CALLS */
895 status = WERR_NOT_SUPPORTED;
896 break;
897 default:
898 DEBUG(1,(__location__ ": Unsupported DsReplicaGetInfo info_type %u\n",
899 info_type));
900 status = WERR_INVALID_LEVEL;
901 break;
904 done:
905 /* put the status on the result field of the reply */
906 req->out.result = status;
907 #if 0
908 NDR_PRINT_OUT_DEBUG(drsuapi_DsReplicaGetInfo, req);
909 #endif
910 return NT_STATUS_OK;