r14421: This does two things
[Samba.git] / source / nsswitch / winbindd_async.c
blob1581b7c272024e738a2066a968b576051f72ea21
1 /*
2 Unix SMB/CIFS implementation.
4 Async helpers for blocking functions
6 Copyright (C) Volker Lendecke 2005
7 Copyright (C) Volker Lendecke 2006
9 The helpers always consist of three functions:
11 * A request setup function that takes the necessary parameters together
12 with a continuation function that is to be called upon completion
14 * A private continuation function that is internal only. This is to be
15 called by the lower-level functions in do_async(). Its only task is to
16 properly call the continuation function named above.
18 * A worker function that is called inside the appropriate child process.
20 This program is free software; you can redistribute it and/or modify
21 it under the terms of the GNU General Public License as published by
22 the Free Software Foundation; either version 2 of the License, or
23 (at your option) any later version.
25 This program is distributed in the hope that it will be useful,
26 but WITHOUT ANY WARRANTY; without even the implied warranty of
27 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
28 GNU General Public License for more details.
30 You should have received a copy of the GNU General Public License
31 along with this program; if not, write to the Free Software
32 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
35 #include "includes.h"
36 #include "winbindd.h"
38 #undef DBGC_CLASS
39 #define DBGC_CLASS DBGC_WINBIND
41 struct do_async_state {
42 TALLOC_CTX *mem_ctx;
43 struct winbindd_request request;
44 struct winbindd_response response;
45 void (*cont)(TALLOC_CTX *mem_ctx,
46 BOOL success,
47 struct winbindd_response *response,
48 void *c, void *private_data);
49 void *c, *private_data;
52 static void do_async_recv(void *private_data, BOOL success)
54 struct do_async_state *state =
55 talloc_get_type_abort(private_data, struct do_async_state);
57 state->cont(state->mem_ctx, success, &state->response,
58 state->c, state->private_data);
61 static void do_async(TALLOC_CTX *mem_ctx, struct winbindd_child *child,
62 const struct winbindd_request *request,
63 void (*cont)(TALLOC_CTX *mem_ctx, BOOL success,
64 struct winbindd_response *response,
65 void *c, void *private_data),
66 void *c, void *private_data)
68 struct do_async_state *state;
70 state = TALLOC_P(mem_ctx, struct do_async_state);
71 if (state == NULL) {
72 DEBUG(0, ("talloc failed\n"));
73 cont(mem_ctx, False, NULL, c, private_data);
74 return;
77 state->mem_ctx = mem_ctx;
78 state->request = *request;
79 state->request.length = sizeof(state->request);
80 state->cont = cont;
81 state->c = c;
82 state->private_data = private_data;
84 async_request(mem_ctx, child, &state->request,
85 &state->response, do_async_recv, state);
88 void do_async_domain(TALLOC_CTX *mem_ctx, struct winbindd_domain *domain,
89 const struct winbindd_request *request,
90 void (*cont)(TALLOC_CTX *mem_ctx, BOOL success,
91 struct winbindd_response *response,
92 void *c, void *private_data),
93 void *c, void *private_data)
95 struct do_async_state *state;
97 state = TALLOC_P(mem_ctx, struct do_async_state);
98 if (state == NULL) {
99 DEBUG(0, ("talloc failed\n"));
100 cont(mem_ctx, False, NULL, c, private_data);
101 return;
104 state->mem_ctx = mem_ctx;
105 state->request = *request;
106 state->request.length = sizeof(state->request);
107 state->cont = cont;
108 state->c = c;
109 state->private_data = private_data;
111 async_domain_request(mem_ctx, domain, &state->request,
112 &state->response, do_async_recv, state);
115 static void idmap_set_mapping_recv(TALLOC_CTX *mem_ctx, BOOL success,
116 struct winbindd_response *response,
117 void *c, void *private_data)
119 void (*cont)(void *priv, BOOL succ) = c;
121 if (!success) {
122 DEBUG(5, ("Could not trigger idmap_set_mapping\n"));
123 cont(private_data, False);
124 return;
127 if (response->result != WINBINDD_OK) {
128 DEBUG(5, ("idmap_set_mapping returned an error\n"));
129 cont(private_data, False);
130 return;
133 cont(private_data, True);
136 void idmap_set_mapping_async(TALLOC_CTX *mem_ctx, const DOM_SID *sid,
137 unid_t id, int id_type,
138 void (*cont)(void *private_data, BOOL success),
139 void *private_data)
141 struct winbindd_request request;
142 ZERO_STRUCT(request);
143 request.cmd = WINBINDD_DUAL_IDMAPSET;
144 if (id_type == ID_USERID)
145 request.data.dual_idmapset.uid = id.uid;
146 else
147 request.data.dual_idmapset.gid = id.gid;
148 request.data.dual_idmapset.type = id_type;
149 sid_to_string(request.data.dual_idmapset.sid, sid);
151 do_async(mem_ctx, idmap_child(), &request, idmap_set_mapping_recv,
152 cont, private_data);
155 enum winbindd_result winbindd_dual_idmapset(struct winbindd_domain *domain,
156 struct winbindd_cli_state *state)
158 DOM_SID sid;
159 unid_t id;
160 NTSTATUS result;
162 DEBUG(3, ("[%5lu]: dual_idmapset\n", (unsigned long)state->pid));
164 if (!string_to_sid(&sid, state->request.data.dual_idmapset.sid))
165 return WINBINDD_ERROR;
167 if (state->request.data.dual_idmapset.type == ID_USERID)
168 id.uid = state->request.data.dual_idmapset.uid;
169 else
170 id.gid = state->request.data.dual_idmapset.gid;
172 result = idmap_set_mapping(&sid, id,
173 state->request.data.dual_idmapset.type);
174 return NT_STATUS_IS_OK(result) ? WINBINDD_OK : WINBINDD_ERROR;
177 static void idmap_sid2uid_recv(TALLOC_CTX *mem_ctx, BOOL success,
178 struct winbindd_response *response,
179 void *c, void *private_data);
181 void idmap_sid2uid_async(TALLOC_CTX *mem_ctx, const DOM_SID *sid, BOOL alloc,
182 void (*cont)(void *private_data, BOOL success, uid_t uid),
183 void *private_data)
185 struct winbindd_request request;
186 ZERO_STRUCT(request);
187 request.cmd = WINBINDD_DUAL_SID2UID;
188 sid_to_string(request.data.dual_sid2id.sid, sid);
189 request.data.dual_sid2id.alloc = alloc;
190 do_async(mem_ctx, idmap_child(), &request, idmap_sid2uid_recv,
191 cont, private_data);
194 enum winbindd_result winbindd_dual_sid2uid(struct winbindd_domain *domain,
195 struct winbindd_cli_state *state)
197 DOM_SID sid;
198 NTSTATUS result;
200 DEBUG(3, ("[%5lu]: sid to uid %s\n", (unsigned long)state->pid,
201 state->request.data.dual_sid2id.sid));
203 if (!string_to_sid(&sid, state->request.data.dual_sid2id.sid)) {
204 DEBUG(1, ("Could not get convert sid %s from string\n",
205 state->request.data.dual_sid2id.sid));
206 return WINBINDD_ERROR;
209 /* Find uid for this sid and return it, possibly ask the slow remote
210 * idmap */
212 result = idmap_sid_to_uid(&sid, &(state->response.data.uid),
213 state->request.data.dual_sid2id.alloc ?
214 0 : ID_QUERY_ONLY);
216 return NT_STATUS_IS_OK(result) ? WINBINDD_OK : WINBINDD_ERROR;
219 static void idmap_sid2uid_recv(TALLOC_CTX *mem_ctx, BOOL success,
220 struct winbindd_response *response,
221 void *c, void *private_data)
223 void (*cont)(void *priv, BOOL succ, uid_t uid) = c;
225 if (!success) {
226 DEBUG(5, ("Could not trigger sid2uid\n"));
227 cont(private_data, False, 0);
228 return;
231 if (response->result != WINBINDD_OK) {
232 DEBUG(5, ("sid2uid returned an error\n"));
233 cont(private_data, False, 0);
234 return;
237 cont(private_data, True, response->data.uid);
240 static void uid2name_recv(TALLOC_CTX *mem_ctx, BOOL success,
241 struct winbindd_response *response,
242 void *c, void *private_data);
244 void winbindd_uid2name_async(TALLOC_CTX *mem_ctx, uid_t uid,
245 void (*cont)(void *private_data, BOOL success,
246 const char *name),
247 void *private_data)
249 struct winbindd_request request;
250 ZERO_STRUCT(request);
251 request.cmd = WINBINDD_DUAL_UID2NAME;
252 request.data.uid = uid;
253 do_async(mem_ctx, idmap_child(), &request, uid2name_recv,
254 cont, private_data);
257 enum winbindd_result winbindd_dual_uid2name(struct winbindd_domain *domain,
258 struct winbindd_cli_state *state)
260 struct passwd *pw;
262 DEBUG(3, ("[%5lu]: uid2name %lu\n", (unsigned long)state->pid,
263 (unsigned long)state->request.data.uid));
265 pw = getpwuid(state->request.data.uid);
266 if (pw == NULL) {
267 DEBUG(5, ("User %lu not found\n",
268 (unsigned long)state->request.data.uid));
269 return WINBINDD_ERROR;
272 fstrcpy(state->response.data.name.name, pw->pw_name);
273 return WINBINDD_OK;
276 static void uid2name_recv(TALLOC_CTX *mem_ctx, BOOL success,
277 struct winbindd_response *response,
278 void *c, void *private_data)
280 void (*cont)(void *priv, BOOL succ, const char *name) = c;
282 if (!success) {
283 DEBUG(5, ("Could not trigger uid2name\n"));
284 cont(private_data, False, NULL);
285 return;
288 if (response->result != WINBINDD_OK) {
289 DEBUG(5, ("uid2name returned an error\n"));
290 cont(private_data, False, NULL);
291 return;
294 cont(private_data, True, response->data.name.name);
297 static void name2uid_recv(TALLOC_CTX *mem_ctx, BOOL success,
298 struct winbindd_response *response,
299 void *c, void *private_data);
301 static void winbindd_name2uid_async(TALLOC_CTX *mem_ctx, const char *name,
302 void (*cont)(void *private_data, BOOL success,
303 uid_t uid),
304 void *private_data)
306 struct winbindd_request request;
307 ZERO_STRUCT(request);
308 request.cmd = WINBINDD_DUAL_NAME2UID;
309 fstrcpy(request.data.username, name);
310 do_async(mem_ctx, idmap_child(), &request, name2uid_recv,
311 cont, private_data);
314 enum winbindd_result winbindd_dual_name2uid(struct winbindd_domain *domain,
315 struct winbindd_cli_state *state)
317 struct passwd *pw;
319 /* Ensure null termination */
320 state->request.data.username
321 [sizeof(state->request.data.username)-1] = '\0';
323 DEBUG(3, ("[%5lu]: name2uid %s\n", (unsigned long)state->pid,
324 state->request.data.username));
326 pw = getpwnam(state->request.data.username);
327 if (pw == NULL) {
328 return WINBINDD_ERROR;
331 state->response.data.uid = pw->pw_uid;
332 return WINBINDD_OK;
335 static void name2uid_recv(TALLOC_CTX *mem_ctx, BOOL success,
336 struct winbindd_response *response,
337 void *c, void *private_data)
339 void (*cont)(void *priv, BOOL succ, uid_t uid) = c;
341 if (!success) {
342 DEBUG(5, ("Could not trigger name2uid\n"));
343 cont(private_data, False, 0);
344 return;
347 if (response->result != WINBINDD_OK) {
348 DEBUG(5, ("name2uid returned an error\n"));
349 cont(private_data, False, 0);
350 return;
353 cont(private_data, True, response->data.uid);
356 static void idmap_sid2gid_recv(TALLOC_CTX *mem_ctx, BOOL success,
357 struct winbindd_response *response,
358 void *c, void *private_data);
360 void idmap_sid2gid_async(TALLOC_CTX *mem_ctx, const DOM_SID *sid, BOOL alloc,
361 void (*cont)(void *private_data, BOOL success, gid_t gid),
362 void *private_data)
364 struct winbindd_request request;
365 ZERO_STRUCT(request);
366 request.cmd = WINBINDD_DUAL_SID2GID;
367 sid_to_string(request.data.dual_sid2id.sid, sid);
369 DEBUG(7,("idmap_sid2gid_async: Resolving %s to a gid\n",
370 request.data.dual_sid2id.sid));
372 request.data.dual_sid2id.alloc = alloc;
373 do_async(mem_ctx, idmap_child(), &request, idmap_sid2gid_recv,
374 cont, private_data);
377 enum winbindd_result winbindd_dual_sid2gid(struct winbindd_domain *domain,
378 struct winbindd_cli_state *state)
380 DOM_SID sid;
381 NTSTATUS result;
383 DEBUG(3, ("[%5lu]: sid to gid %s\n", (unsigned long)state->pid,
384 state->request.data.dual_sid2id.sid));
386 if (!string_to_sid(&sid, state->request.data.dual_sid2id.sid)) {
387 DEBUG(1, ("Could not get convert sid %s from string\n",
388 state->request.data.dual_sid2id.sid));
389 return WINBINDD_ERROR;
392 /* Find gid for this sid and return it, possibly ask the slow remote
393 * idmap */
395 result = idmap_sid_to_gid(&sid, &(state->response.data.gid),
396 state->request.data.dual_sid2id.alloc ?
397 0 : ID_QUERY_ONLY);
399 /* If the lookup failed, the perhaps we need to look
400 at the passdb for local groups */
402 if ( !NT_STATUS_IS_OK(result) ) {
403 if ( sid_to_gid( &sid, &(state->response.data.gid) ) ) {
404 result = NT_STATUS_OK;
408 return NT_STATUS_IS_OK(result) ? WINBINDD_OK : WINBINDD_ERROR;
411 static void idmap_sid2gid_recv(TALLOC_CTX *mem_ctx, BOOL success,
412 struct winbindd_response *response,
413 void *c, void *private_data)
415 void (*cont)(void *priv, BOOL succ, gid_t gid) = c;
417 if (!success) {
418 DEBUG(5, ("Could not trigger sid2gid\n"));
419 cont(private_data, False, 0);
420 return;
423 if (response->result != WINBINDD_OK) {
424 DEBUG(5, ("sid2gid returned an error\n"));
425 cont(private_data, False, 0);
426 return;
429 cont(private_data, True, response->data.gid);
432 static void gid2name_recv(TALLOC_CTX *mem_ctx, BOOL success,
433 struct winbindd_response *response,
434 void *c, void *private_data)
436 void (*cont)(void *priv, BOOL succ, const char *name) = c;
438 if (!success) {
439 DEBUG(5, ("Could not trigger gid2name\n"));
440 cont(private_data, False, NULL);
441 return;
444 if (response->result != WINBINDD_OK) {
445 DEBUG(5, ("gid2name returned an error\n"));
446 cont(private_data, False, NULL);
447 return;
450 cont(private_data, True, response->data.name.name);
453 void winbindd_gid2name_async(TALLOC_CTX *mem_ctx, gid_t gid,
454 void (*cont)(void *private_data, BOOL success,
455 const char *name),
456 void *private_data)
458 struct winbindd_request request;
459 ZERO_STRUCT(request);
460 request.cmd = WINBINDD_DUAL_GID2NAME;
461 request.data.gid = gid;
462 do_async(mem_ctx, idmap_child(), &request, gid2name_recv,
463 cont, private_data);
466 enum winbindd_result winbindd_dual_gid2name(struct winbindd_domain *domain,
467 struct winbindd_cli_state *state)
469 struct group *gr;
471 DEBUG(3, ("[%5lu]: gid2name %lu\n", (unsigned long)state->pid,
472 (unsigned long)state->request.data.gid));
474 gr = getgrgid(state->request.data.gid);
475 if (gr == NULL)
476 return WINBINDD_ERROR;
478 fstrcpy(state->response.data.name.name, gr->gr_name);
479 return WINBINDD_OK;
482 static void name2gid_recv(TALLOC_CTX *mem_ctx, BOOL success,
483 struct winbindd_response *response,
484 void *c, void *private_data);
486 static void winbindd_name2gid_async(TALLOC_CTX *mem_ctx, const char *name,
487 void (*cont)(void *private_data, BOOL success,
488 gid_t gid),
489 void *private_data)
491 struct winbindd_request request;
492 ZERO_STRUCT(request);
493 request.cmd = WINBINDD_DUAL_NAME2GID;
494 fstrcpy(request.data.groupname, name);
495 do_async(mem_ctx, idmap_child(), &request, name2gid_recv,
496 cont, private_data);
499 enum winbindd_result winbindd_dual_name2gid(struct winbindd_domain *domain,
500 struct winbindd_cli_state *state)
502 struct group *gr;
504 /* Ensure null termination */
505 state->request.data.groupname
506 [sizeof(state->request.data.groupname)-1] = '\0';
508 DEBUG(3, ("[%5lu]: name2gid %s\n", (unsigned long)state->pid,
509 state->request.data.groupname));
511 gr = getgrnam(state->request.data.groupname);
512 if (gr == NULL) {
513 return WINBINDD_ERROR;
516 state->response.data.gid = gr->gr_gid;
517 return WINBINDD_OK;
520 static void name2gid_recv(TALLOC_CTX *mem_ctx, BOOL success,
521 struct winbindd_response *response,
522 void *c, void *private_data)
524 void (*cont)(void *priv, BOOL succ, gid_t gid) = c;
526 if (!success) {
527 DEBUG(5, ("Could not trigger name2gid\n"));
528 cont(private_data, False, 0);
529 return;
532 if (response->result != WINBINDD_OK) {
533 DEBUG(5, ("name2gid returned an error\n"));
534 cont(private_data, False, 0);
535 return;
538 cont(private_data, True, response->data.gid);
542 static void lookupsid_recv(TALLOC_CTX *mem_ctx, BOOL success,
543 struct winbindd_response *response,
544 void *c, void *private_data)
546 void (*cont)(void *priv, BOOL succ, const char *dom_name,
547 const char *name, enum SID_NAME_USE type) = c;
549 if (!success) {
550 DEBUG(5, ("Could not trigger lookupsid\n"));
551 cont(private_data, False, NULL, NULL, SID_NAME_UNKNOWN);
552 return;
555 if (response->result != WINBINDD_OK) {
556 DEBUG(5, ("lookupsid returned an error\n"));
557 cont(private_data, False, NULL, NULL, SID_NAME_UNKNOWN);
558 return;
561 cont(private_data, True, response->data.name.dom_name,
562 response->data.name.name, response->data.name.type);
565 void winbindd_lookupsid_async(TALLOC_CTX *mem_ctx, const DOM_SID *sid,
566 void (*cont)(void *private_data, BOOL success,
567 const char *dom_name,
568 const char *name,
569 enum SID_NAME_USE type),
570 void *private_data)
572 struct winbindd_domain *domain;
573 struct winbindd_request request;
575 domain = find_lookup_domain_from_sid(sid);
576 if (domain == NULL) {
577 DEBUG(5, ("Could not find domain for sid %s\n",
578 sid_string_static(sid)));
579 cont(private_data, False, NULL, NULL, SID_NAME_UNKNOWN);
580 return;
583 ZERO_STRUCT(request);
584 request.cmd = WINBINDD_LOOKUPSID;
585 fstrcpy(request.data.sid, sid_string_static(sid));
587 do_async_domain(mem_ctx, domain, &request, lookupsid_recv,
588 cont, private_data);
591 enum winbindd_result winbindd_dual_lookupsid(struct winbindd_domain *domain,
592 struct winbindd_cli_state *state)
594 enum SID_NAME_USE type;
595 DOM_SID sid;
596 fstring name;
597 fstring dom_name;
599 /* Ensure null termination */
600 state->request.data.sid[sizeof(state->request.data.sid)-1]='\0';
602 DEBUG(3, ("[%5lu]: lookupsid %s\n", (unsigned long)state->pid,
603 state->request.data.sid));
605 /* Lookup sid from PDC using lsa_lookup_sids() */
607 if (!string_to_sid(&sid, state->request.data.sid)) {
608 DEBUG(5, ("%s not a SID\n", state->request.data.sid));
609 return WINBINDD_ERROR;
612 /* Lookup the sid */
614 if (!winbindd_lookup_name_by_sid(state->mem_ctx, &sid, dom_name, name,
615 &type)) {
616 return WINBINDD_ERROR;
619 fstrcpy(state->response.data.name.dom_name, dom_name);
620 fstrcpy(state->response.data.name.name, name);
621 state->response.data.name.type = type;
623 return WINBINDD_OK;
626 static void lookupname_recv(TALLOC_CTX *mem_ctx, BOOL success,
627 struct winbindd_response *response,
628 void *c, void *private_data)
630 void (*cont)(void *priv, BOOL succ, const DOM_SID *sid,
631 enum SID_NAME_USE type) = c;
632 DOM_SID sid;
634 if (!success) {
635 DEBUG(5, ("Could not trigger lookup_name\n"));
636 cont(private_data, False, NULL, SID_NAME_UNKNOWN);
637 return;
640 if (response->result != WINBINDD_OK) {
641 DEBUG(5, ("lookup_name returned an error\n"));
642 cont(private_data, False, NULL, SID_NAME_UNKNOWN);
643 return;
646 if (!string_to_sid(&sid, response->data.sid.sid)) {
647 DEBUG(0, ("Could not convert string %s to sid\n",
648 response->data.sid.sid));
649 cont(private_data, False, NULL, SID_NAME_UNKNOWN);
650 return;
653 cont(private_data, True, &sid, response->data.sid.type);
656 void winbindd_lookupname_async(TALLOC_CTX *mem_ctx, const char *dom_name,
657 const char *name,
658 void (*cont)(void *private_data, BOOL success,
659 const DOM_SID *sid,
660 enum SID_NAME_USE type),
661 void *private_data)
663 struct winbindd_request request;
664 struct winbindd_domain *domain;
666 domain = find_lookup_domain_from_name(dom_name);
668 if (domain == NULL) {
669 DEBUG(5, ("Could not find domain for name %s\n", dom_name));
670 cont(private_data, False, NULL, SID_NAME_UNKNOWN);
671 return;
674 ZERO_STRUCT(request);
675 request.cmd = WINBINDD_LOOKUPNAME;
676 fstrcpy(request.data.name.dom_name, dom_name);
677 fstrcpy(request.data.name.name, name);
679 do_async_domain(mem_ctx, domain, &request, lookupname_recv,
680 cont, private_data);
683 enum winbindd_result winbindd_dual_lookupname(struct winbindd_domain *domain,
684 struct winbindd_cli_state *state)
686 enum SID_NAME_USE type;
687 char *name_domain, *name_user;
688 DOM_SID sid;
689 char *p;
691 /* Ensure null termination */
692 state->request.data.sid[sizeof(state->request.data.name.dom_name)-1]='\0';
694 /* Ensure null termination */
695 state->request.data.sid[sizeof(state->request.data.name.name)-1]='\0';
697 /* cope with the name being a fully qualified name */
698 p = strstr(state->request.data.name.name, lp_winbind_separator());
699 if (p) {
700 *p = 0;
701 name_domain = state->request.data.name.name;
702 name_user = p+1;
703 } else {
704 name_domain = state->request.data.name.dom_name;
705 name_user = state->request.data.name.name;
708 DEBUG(3, ("[%5lu]: lookupname %s%s%s\n", (unsigned long)state->pid,
709 name_domain, lp_winbind_separator(), name_user));
711 /* Lookup name from PDC using lsa_lookup_names() */
712 if (!winbindd_lookup_sid_by_name(state->mem_ctx, domain, name_domain,
713 name_user, &sid, &type)) {
714 return WINBINDD_ERROR;
717 sid_to_string(state->response.data.sid.sid, &sid);
718 state->response.data.sid.type = type;
720 return WINBINDD_OK;
723 BOOL print_sidlist(TALLOC_CTX *mem_ctx, const DOM_SID *sids,
724 size_t num_sids, char **result, ssize_t *len)
726 size_t i;
727 size_t buflen = 0;
729 *len = 0;
730 *result = NULL;
731 for (i=0; i<num_sids; i++) {
732 sprintf_append(mem_ctx, result, len, &buflen,
733 "%s\n", sid_string_static(&sids[i]));
736 if ((num_sids != 0) && (*result == NULL)) {
737 return False;
740 return True;
743 BOOL parse_sidlist(TALLOC_CTX *mem_ctx, char *sidstr,
744 DOM_SID **sids, size_t *num_sids)
746 char *p, *q;
748 p = sidstr;
749 if (p == NULL)
750 return False;
752 while (p[0] != '\0') {
753 DOM_SID sid;
754 q = strchr(p, '\n');
755 if (q == NULL) {
756 DEBUG(0, ("Got invalid sidstr: %s\n", p));
757 return False;
759 *q = '\0';
760 q += 1;
761 if (!string_to_sid(&sid, p)) {
762 DEBUG(0, ("Could not parse sid %s\n", p));
763 return False;
765 add_sid_to_array(mem_ctx, &sid, sids, num_sids);
766 p = q;
768 return True;
771 BOOL print_ridlist(TALLOC_CTX *mem_ctx, uint32 *rids, size_t num_rids,
772 char **result, ssize_t *len)
774 size_t i;
775 size_t buflen = 0;
777 *len = 0;
778 *result = NULL;
779 for (i=0; i<num_rids; i++) {
780 sprintf_append(mem_ctx, result, len, &buflen,
781 "%ld\n", rids[i]);
784 if ((num_rids != 0) && (*result == NULL)) {
785 return False;
788 return True;
791 BOOL parse_ridlist(TALLOC_CTX *mem_ctx, char *ridstr,
792 uint32 **sids, size_t *num_rids)
794 char *p;
796 p = ridstr;
797 if (p == NULL)
798 return False;
800 while (p[0] != '\0') {
801 uint32 rid;
802 char *q;
803 rid = strtoul(p, &q, 10);
804 if (*q != '\n') {
805 DEBUG(0, ("Got invalid ridstr: %s\n", p));
806 return False;
808 p = q+1;
809 ADD_TO_ARRAY(mem_ctx, uint32, rid, sids, num_rids);
811 return True;
814 static void getsidaliases_recv(TALLOC_CTX *mem_ctx, BOOL success,
815 struct winbindd_response *response,
816 void *c, void *private_data)
818 void (*cont)(void *priv, BOOL succ,
819 DOM_SID *aliases, size_t num_aliases) = c;
820 char *aliases_str;
821 DOM_SID *sids = NULL;
822 size_t num_sids = 0;
824 if (!success) {
825 DEBUG(5, ("Could not trigger getsidaliases\n"));
826 cont(private_data, success, NULL, 0);
827 return;
830 if (response->result != WINBINDD_OK) {
831 DEBUG(5, ("getsidaliases returned an error\n"));
832 cont(private_data, False, NULL, 0);
833 return;
836 aliases_str = response->extra_data;
838 if (aliases_str == NULL) {
839 DEBUG(10, ("getsidaliases return 0 SIDs\n"));
840 cont(private_data, True, NULL, 0);
841 return;
844 if (!parse_sidlist(mem_ctx, aliases_str, &sids, &num_sids)) {
845 DEBUG(0, ("Could not parse sids\n"));
846 cont(private_data, False, NULL, 0);
847 return;
850 SAFE_FREE(response->extra_data);
852 cont(private_data, True, sids, num_sids);
855 void winbindd_getsidaliases_async(struct winbindd_domain *domain,
856 TALLOC_CTX *mem_ctx,
857 const DOM_SID *sids, size_t num_sids,
858 void (*cont)(void *private_data,
859 BOOL success,
860 const DOM_SID *aliases,
861 size_t num_aliases),
862 void *private_data)
864 struct winbindd_request request;
865 char *sidstr = NULL;
866 ssize_t len;
868 if (num_sids == 0) {
869 cont(private_data, True, NULL, 0);
870 return;
873 if (!print_sidlist(mem_ctx, sids, num_sids, &sidstr, &len)) {
874 cont(private_data, False, NULL, 0);
875 return;
878 ZERO_STRUCT(request);
879 request.cmd = WINBINDD_DUAL_GETSIDALIASES;
880 request.extra_len = len;
881 request.extra_data = sidstr;
883 do_async_domain(mem_ctx, domain, &request, getsidaliases_recv,
884 cont, private_data);
887 enum winbindd_result winbindd_dual_getsidaliases(struct winbindd_domain *domain,
888 struct winbindd_cli_state *state)
890 DOM_SID *sids = NULL;
891 size_t num_sids = 0;
892 char *sidstr;
893 ssize_t len;
894 size_t i;
895 uint32 num_aliases;
896 uint32 *alias_rids;
897 NTSTATUS result;
899 DEBUG(3, ("[%5lu]: getsidaliases\n", (unsigned long)state->pid));
901 sidstr = state->request.extra_data;
902 if (sidstr == NULL)
903 sidstr = talloc_strdup(state->mem_ctx, "\n"); /* No SID */
905 DEBUG(10, ("Sidlist: %s\n", sidstr));
907 if (!parse_sidlist(state->mem_ctx, sidstr, &sids, &num_sids)) {
908 DEBUG(0, ("Could not parse SID list: %s\n", sidstr));
909 return WINBINDD_ERROR;
912 num_aliases = 0;
913 alias_rids = NULL;
915 result = domain->methods->lookup_useraliases(domain,
916 state->mem_ctx,
917 num_sids, sids,
918 &num_aliases,
919 &alias_rids);
921 if (!NT_STATUS_IS_OK(result)) {
922 DEBUG(3, ("Could not lookup_useraliases: %s\n",
923 nt_errstr(result)));
924 return WINBINDD_ERROR;
927 num_sids = 0;
928 sids = NULL;
930 DEBUG(10, ("Got %d aliases\n", num_aliases));
932 for (i=0; i<num_aliases; i++) {
933 DOM_SID sid;
934 DEBUGADD(10, (" rid %d\n", alias_rids[i]));
935 sid_copy(&sid, &domain->sid);
936 sid_append_rid(&sid, alias_rids[i]);
937 add_sid_to_array(state->mem_ctx, &sid, &sids, &num_sids);
940 if (!print_sidlist(NULL, sids, num_sids,
941 (char **)&state->response.extra_data, &len)) {
942 DEBUG(0, ("Could not print_sidlist\n"));
943 return WINBINDD_ERROR;
946 if (state->response.extra_data != NULL) {
947 DEBUG(10, ("aliases_list: %s\n",
948 (char *)state->response.extra_data));
949 state->response.length += len+1;
952 return WINBINDD_OK;
955 struct gettoken_state {
956 TALLOC_CTX *mem_ctx;
957 DOM_SID user_sid;
958 struct winbindd_domain *alias_domain;
959 struct winbindd_domain *builtin_domain;
960 DOM_SID *sids;
961 size_t num_sids;
962 void (*cont)(void *private_data, BOOL success, DOM_SID *sids, size_t num_sids);
963 void *private_data;
966 static void gettoken_recvdomgroups(TALLOC_CTX *mem_ctx, BOOL success,
967 struct winbindd_response *response,
968 void *c, void *private_data);
969 static void gettoken_recvaliases(void *private_data, BOOL success,
970 const DOM_SID *aliases,
971 size_t num_aliases);
974 void winbindd_gettoken_async(TALLOC_CTX *mem_ctx, const DOM_SID *user_sid,
975 void (*cont)(void *private_data, BOOL success,
976 DOM_SID *sids, size_t num_sids),
977 void *private_data)
979 struct winbindd_domain *domain;
980 struct winbindd_request request;
981 struct gettoken_state *state;
983 state = TALLOC_P(mem_ctx, struct gettoken_state);
984 if (state == NULL) {
985 DEBUG(0, ("talloc failed\n"));
986 cont(private_data, False, NULL, 0);
987 return;
990 state->mem_ctx = mem_ctx;
991 sid_copy(&state->user_sid, user_sid);
992 state->alias_domain = find_our_domain();
993 state->builtin_domain = find_builtin_domain();
994 state->cont = cont;
995 state->private_data = private_data;
997 domain = find_domain_from_sid_noinit(user_sid);
998 if (domain == NULL) {
999 DEBUG(5, ("Could not find domain from SID %s\n",
1000 sid_string_static(user_sid)));
1001 cont(private_data, False, NULL, 0);
1002 return;
1005 ZERO_STRUCT(request);
1006 request.cmd = WINBINDD_GETUSERDOMGROUPS;
1007 fstrcpy(request.data.sid, sid_string_static(user_sid));
1009 do_async_domain(mem_ctx, domain, &request, gettoken_recvdomgroups,
1010 NULL, state);
1013 static void gettoken_recvdomgroups(TALLOC_CTX *mem_ctx, BOOL success,
1014 struct winbindd_response *response,
1015 void *c, void *private_data)
1017 struct gettoken_state *state =
1018 talloc_get_type_abort(private_data, struct gettoken_state);
1019 char *sids_str;
1021 if (!success) {
1022 DEBUG(10, ("Could not get domain groups\n"));
1023 state->cont(state->private_data, False, NULL, 0);
1024 return;
1027 sids_str = response->extra_data;
1029 if (sids_str == NULL) {
1030 /* This could be normal if we are dealing with a
1031 local user and local groups */
1033 if ( !sid_check_is_in_our_domain( &state->user_sid ) ) {
1034 DEBUG(10, ("Received no domain groups\n"));
1035 state->cont(state->private_data, True, NULL, 0);
1036 return;
1040 state->sids = NULL;
1041 state->num_sids = 0;
1043 add_sid_to_array(mem_ctx, &state->user_sid, &state->sids,
1044 &state->num_sids);
1046 if (sids_str && !parse_sidlist(mem_ctx, sids_str, &state->sids,
1047 &state->num_sids)) {
1048 DEBUG(0, ("Could not parse sids\n"));
1049 state->cont(state->private_data, False, NULL, 0);
1050 return;
1053 SAFE_FREE(response->extra_data);
1055 if (state->alias_domain == NULL) {
1056 DEBUG(10, ("Don't expand domain local groups\n"));
1057 state->cont(state->private_data, True, state->sids,
1058 state->num_sids);
1059 return;
1062 winbindd_getsidaliases_async(state->alias_domain, mem_ctx,
1063 state->sids, state->num_sids,
1064 gettoken_recvaliases, state);
1067 static void gettoken_recvaliases(void *private_data, BOOL success,
1068 const DOM_SID *aliases,
1069 size_t num_aliases)
1071 struct gettoken_state *state = private_data;
1072 size_t i;
1074 if (!success) {
1075 DEBUG(10, ("Could not receive domain local groups\n"));
1076 state->cont(state->private_data, False, NULL, 0);
1077 return;
1080 for (i=0; i<num_aliases; i++)
1081 add_sid_to_array(state->mem_ctx, &aliases[i],
1082 &state->sids, &state->num_sids);
1084 if (state->builtin_domain != NULL) {
1085 struct winbindd_domain *builtin_domain = state->builtin_domain;
1086 DEBUG(10, ("Expanding our own local groups\n"));
1087 state->builtin_domain = NULL;
1088 winbindd_getsidaliases_async(builtin_domain, state->mem_ctx,
1089 state->sids, state->num_sids,
1090 gettoken_recvaliases, state);
1091 return;
1094 state->cont(state->private_data, True, state->sids, state->num_sids);
1097 struct sid2uid_state {
1098 TALLOC_CTX *mem_ctx;
1099 DOM_SID sid;
1100 char *username;
1101 uid_t uid;
1102 void (*cont)(void *private_data, BOOL success, uid_t uid);
1103 void *private_data;
1106 static void sid2uid_lookup_sid_recv(void *private_data, BOOL success,
1107 const char *dom_name, const char *name,
1108 enum SID_NAME_USE type);
1109 static void sid2uid_noalloc_recv(void *private_data, BOOL success, uid_t uid);
1110 static void sid2uid_alloc_recv(void *private_data, BOOL success, uid_t uid);
1111 static void sid2uid_name2uid_recv(void *private_data, BOOL success, uid_t uid);
1112 static void sid2uid_set_mapping_recv(void *private_data, BOOL success);
1114 void winbindd_sid2uid_async(TALLOC_CTX *mem_ctx, const DOM_SID *sid,
1115 void (*cont)(void *private_data, BOOL success,
1116 uid_t uid),
1117 void *private_data)
1119 struct sid2uid_state *state;
1120 NTSTATUS result;
1121 uid_t uid;
1123 if (idmap_proxyonly()) {
1124 DEBUG(10, ("idmap proxy only\n"));
1125 cont(private_data, False, 0);
1126 return;
1129 /* Query only the local tdb, everything else might possibly block */
1131 result = idmap_sid_to_uid(sid, &uid, ID_QUERY_ONLY|ID_CACHE_ONLY);
1133 if (NT_STATUS_IS_OK(result)) {
1134 cont(private_data, True, uid);
1135 return;
1138 state = TALLOC_P(mem_ctx, struct sid2uid_state);
1139 if (state == NULL) {
1140 DEBUG(0, ("talloc failed\n"));
1141 cont(private_data, False, 0);
1142 return;
1145 state->mem_ctx = mem_ctx;
1146 state->sid = *sid;
1147 state->cont = cont;
1148 state->private_data = private_data;
1150 /* Let's see if it's really a user before allocating a uid */
1152 winbindd_lookupsid_async(mem_ctx, sid, sid2uid_lookup_sid_recv, state);
1155 static void sid2uid_lookup_sid_recv(void *private_data, BOOL success,
1156 const char *dom_name, const char *name,
1157 enum SID_NAME_USE type)
1159 struct sid2uid_state *state =
1160 talloc_get_type_abort(private_data, struct sid2uid_state);
1162 if (!success) {
1163 DEBUG(5, ("Could not trigger lookup_sid\n"));
1164 state->cont(state->private_data, False, 0);
1165 return;
1168 if ((type != SID_NAME_USER) && (type != SID_NAME_COMPUTER)) {
1169 DEBUG(5, ("SID is not a user\n"));
1170 state->cont(state->private_data, False, 0);
1171 return;
1174 state->username = talloc_strdup(state->mem_ctx, name);
1176 /* Ask the possibly blocking remote IDMAP */
1178 idmap_sid2uid_async(state->mem_ctx, &state->sid, False,
1179 sid2uid_noalloc_recv, state);
1182 static void sid2uid_noalloc_recv(void *private_data, BOOL success, uid_t uid)
1184 struct sid2uid_state *state =
1185 talloc_get_type_abort(private_data, struct sid2uid_state);
1187 if (success) {
1188 DEBUG(10, ("found uid for sid %s in remote backend\n",
1189 sid_string_static(&state->sid)));
1190 state->cont(state->private_data, True, uid);
1191 return;
1194 if (lp_winbind_trusted_domains_only() &&
1195 (sid_compare_domain(&state->sid, &find_our_domain()->sid) == 0)) {
1196 DEBUG(10, ("Trying to go via nss\n"));
1197 winbindd_name2uid_async(state->mem_ctx, state->username,
1198 sid2uid_name2uid_recv, state);
1199 return;
1202 /* To be done: Here we're going to try the unixinfo pipe */
1204 /* Now allocate a uid */
1206 idmap_sid2uid_async(state->mem_ctx, &state->sid, True,
1207 sid2uid_alloc_recv, state);
1210 static void sid2uid_alloc_recv(void *private_data, BOOL success, uid_t uid)
1212 struct sid2uid_state *state =
1213 talloc_get_type_abort(private_data, struct sid2uid_state);
1215 if (!success) {
1216 DEBUG(5, ("Could not allocate uid\n"));
1217 state->cont(state->private_data, False, 0);
1218 return;
1221 state->cont(state->private_data, True, uid);
1224 static void sid2uid_name2uid_recv(void *private_data, BOOL success, uid_t uid)
1226 struct sid2uid_state *state =
1227 talloc_get_type_abort(private_data, struct sid2uid_state);
1228 unid_t id;
1230 if (!success) {
1231 DEBUG(5, ("Could not find uid for name %s\n",
1232 state->username));
1233 state->cont(state->private_data, False, 0);
1234 return;
1237 state->uid = uid;
1239 id.uid = uid;
1240 idmap_set_mapping_async(state->mem_ctx, &state->sid, id, ID_USERID,
1241 sid2uid_set_mapping_recv, state);
1244 static void sid2uid_set_mapping_recv(void *private_data, BOOL success)
1246 struct sid2uid_state *state =
1247 talloc_get_type_abort(private_data, struct sid2uid_state);
1249 if (!success) {
1250 DEBUG(5, ("Could not set ID mapping for sid %s\n",
1251 sid_string_static(&state->sid)));
1252 state->cont(state->private_data, False, 0);
1253 return;
1256 state->cont(state->private_data, True, state->uid);
1259 struct sid2gid_state {
1260 TALLOC_CTX *mem_ctx;
1261 DOM_SID sid;
1262 char *groupname;
1263 gid_t gid;
1264 void (*cont)(void *private_data, BOOL success, gid_t gid);
1265 void *private_data;
1268 static void sid2gid_lookup_sid_recv(void *private_data, BOOL success,
1269 const char *dom_name, const char *name,
1270 enum SID_NAME_USE type);
1271 static void sid2gid_noalloc_recv(void *private_data, BOOL success, gid_t gid);
1272 static void sid2gid_alloc_recv(void *private_data, BOOL success, gid_t gid);
1273 static void sid2gid_name2gid_recv(void *private_data, BOOL success, gid_t gid);
1274 static void sid2gid_set_mapping_recv(void *private_data, BOOL success);
1276 void winbindd_sid2gid_async(TALLOC_CTX *mem_ctx, const DOM_SID *sid,
1277 void (*cont)(void *private_data, BOOL success,
1278 gid_t gid),
1279 void *private_data)
1281 struct sid2gid_state *state;
1282 NTSTATUS result;
1283 gid_t gid;
1285 if (idmap_proxyonly()) {
1286 DEBUG(10, ("idmap proxy only\n"));
1287 cont(private_data, False, 0);
1288 return;
1291 /* Query only the local tdb, everything else might possibly block */
1293 result = idmap_sid_to_gid(sid, &gid, ID_QUERY_ONLY|ID_CACHE_ONLY);
1295 if (NT_STATUS_IS_OK(result)) {
1296 cont(private_data, True, gid);
1297 return;
1300 state = TALLOC_P(mem_ctx, struct sid2gid_state);
1301 if (state == NULL) {
1302 DEBUG(0, ("talloc failed\n"));
1303 cont(private_data, False, 0);
1304 return;
1307 state->mem_ctx = mem_ctx;
1308 state->sid = *sid;
1309 state->cont = cont;
1310 state->private_data = private_data;
1312 /* Let's see if it's really a user before allocating a gid */
1314 winbindd_lookupsid_async(mem_ctx, sid, sid2gid_lookup_sid_recv, state);
1317 static void sid2gid_lookup_sid_recv(void *private_data, BOOL success,
1318 const char *dom_name, const char *name,
1319 enum SID_NAME_USE type)
1321 struct sid2gid_state *state =
1322 talloc_get_type_abort(private_data, struct sid2gid_state);
1324 if (!success) {
1325 DEBUG(5, ("Could not trigger lookup_sid\n"));
1326 state->cont(state->private_data, False, 0);
1327 return;
1330 if (((type != SID_NAME_DOM_GRP) && (type != SID_NAME_ALIAS) &&
1331 (type != SID_NAME_WKN_GRP))) {
1332 DEBUG(5, ("SID is not a group\n"));
1333 state->cont(state->private_data, False, 0);
1334 return;
1337 state->groupname = talloc_strdup(state->mem_ctx, name);
1339 /* Ask the possibly blocking remote IDMAP and allocate */
1341 idmap_sid2gid_async(state->mem_ctx, &state->sid, False,
1342 sid2gid_noalloc_recv, state);
1345 static void sid2gid_noalloc_recv(void *private_data, BOOL success, gid_t gid)
1347 struct sid2gid_state *state =
1348 talloc_get_type_abort(private_data, struct sid2gid_state);
1350 if (success) {
1351 DEBUG(10, ("found gid for sid %s in remote backend\n",
1352 sid_string_static(&state->sid)));
1353 state->cont(state->private_data, True, gid);
1354 return;
1357 if (lp_winbind_trusted_domains_only() &&
1358 (sid_compare_domain(&state->sid, &find_our_domain()->sid) == 0)) {
1359 DEBUG(10, ("Trying to go via nss\n"));
1360 winbindd_name2gid_async(state->mem_ctx, state->groupname,
1361 sid2gid_name2gid_recv, state);
1362 return;
1365 /* To be done: Here we're going to try the unixinfo pipe */
1367 /* Now allocate a gid */
1369 idmap_sid2gid_async(state->mem_ctx, &state->sid, True,
1370 sid2gid_alloc_recv, state);
1373 static void sid2gid_alloc_recv(void *private_data, BOOL success, gid_t gid)
1375 struct sid2gid_state *state =
1376 talloc_get_type_abort(private_data, struct sid2gid_state);
1378 if (!success) {
1379 DEBUG(5, ("Could not allocate gid\n"));
1380 state->cont(state->private_data, False, 0);
1381 return;
1384 state->cont(state->private_data, True, gid);
1387 static void sid2gid_name2gid_recv(void *private_data, BOOL success, gid_t gid)
1389 struct sid2gid_state *state =
1390 talloc_get_type_abort(private_data, struct sid2gid_state);
1391 unid_t id;
1393 if (!success) {
1394 DEBUG(5, ("Could not find gid for name %s\n",
1395 state->groupname));
1396 state->cont(state->private_data, False, 0);
1397 return;
1400 state->gid = gid;
1402 id.gid = gid;
1403 idmap_set_mapping_async(state->mem_ctx, &state->sid, id, ID_GROUPID,
1404 sid2gid_set_mapping_recv, state);
1407 static void sid2gid_set_mapping_recv(void *private_data, BOOL success)
1409 struct sid2gid_state *state =
1410 talloc_get_type_abort(private_data, struct sid2gid_state);
1412 if (!success) {
1413 DEBUG(5, ("Could not set ID mapping for sid %s\n",
1414 sid_string_static(&state->sid)));
1415 state->cont(state->private_data, False, 0);
1416 return;
1419 state->cont(state->private_data, True, state->gid);
1422 static void query_user_recv(TALLOC_CTX *mem_ctx, BOOL success,
1423 struct winbindd_response *response,
1424 void *c, void *private_data)
1426 void (*cont)(void *priv, BOOL succ, const char *acct_name,
1427 const char *full_name, const char *homedir,
1428 const char *shell, uint32 group_rid) = c;
1430 if (!success) {
1431 DEBUG(5, ("Could not trigger query_user\n"));
1432 cont(private_data, False, NULL, NULL, NULL, NULL, -1);
1433 return;
1436 cont(private_data, True, response->data.user_info.acct_name,
1437 response->data.user_info.full_name,
1438 response->data.user_info.homedir,
1439 response->data.user_info.shell,
1440 response->data.user_info.group_rid);
1443 void query_user_async(TALLOC_CTX *mem_ctx, struct winbindd_domain *domain,
1444 const DOM_SID *sid,
1445 void (*cont)(void *private_data, BOOL success,
1446 const char *acct_name,
1447 const char *full_name,
1448 const char *homedir,
1449 const char *shell,
1450 uint32 group_rid),
1451 void *private_data)
1453 struct winbindd_request request;
1454 ZERO_STRUCT(request);
1455 request.cmd = WINBINDD_DUAL_USERINFO;
1456 sid_to_string(request.data.sid, sid);
1457 do_async_domain(mem_ctx, domain, &request, query_user_recv,
1458 cont, private_data);