2 Unix SMB/CIFS implementation.
4 Windows NT Domain nsswitch module
6 Copyright (C) Tim Potter 2000
8 This library is free software; you can redistribute it and/or
9 modify it under the terms of the GNU Lesser General Public
10 License as published by the Free Software Foundation; either
11 version 3 of the License, or (at your option) any later version.
13 This library is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Library General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #include "winbind_client.h"
29 static pthread_mutex_t winbind_nss_mutex
= PTHREAD_MUTEX_INITIALIZER
;
32 /* Maximum number of users to pass back over the unix domain socket
33 per call. This is not a static limit on the total number of users
34 or groups returned in total. */
36 #define MAX_GETPWENT_USERS 250
37 #define MAX_GETGRENT_USERS 250
39 NSS_STATUS
_nss_winbind_setpwent(void);
40 NSS_STATUS
_nss_winbind_endpwent(void);
41 NSS_STATUS
_nss_winbind_getpwent_r(struct passwd
*result
, char *buffer
,
42 size_t buflen
, int *errnop
);
43 NSS_STATUS
_nss_winbind_getpwuid_r(uid_t uid
, struct passwd
*result
,
44 char *buffer
, size_t buflen
, int *errnop
);
45 NSS_STATUS
_nss_winbind_getpwnam_r(const char *name
, struct passwd
*result
,
46 char *buffer
, size_t buflen
, int *errnop
);
47 NSS_STATUS
_nss_winbind_setgrent(void);
48 NSS_STATUS
_nss_winbind_endgrent(void);
49 NSS_STATUS
_nss_winbind_getgrent_r(struct group
*result
, char *buffer
,
50 size_t buflen
, int *errnop
);
51 NSS_STATUS
_nss_winbind_getgrlst_r(struct group
*result
, char *buffer
,
52 size_t buflen
, int *errnop
);
53 NSS_STATUS
_nss_winbind_getgrnam_r(const char *name
, struct group
*result
,
54 char *buffer
, size_t buflen
, int *errnop
);
55 NSS_STATUS
_nss_winbind_getgrgid_r(gid_t gid
, struct group
*result
, char *buffer
,
56 size_t buflen
, int *errnop
);
57 NSS_STATUS
_nss_winbind_initgroups_dyn(char *user
, gid_t group
, long int *start
,
58 long int *size
, gid_t
**groups
,
59 long int limit
, int *errnop
);
60 NSS_STATUS
_nss_winbind_getusersids(const char *user_sid
, char **group_sids
,
61 int *num_groups
, char *buffer
, size_t buf_size
,
63 NSS_STATUS
_nss_winbind_nametosid(const char *name
, char **sid
, char *buffer
,
64 size_t buflen
, int *errnop
);
65 NSS_STATUS
_nss_winbind_sidtoname(const char *sid
, char **name
, char *buffer
,
66 size_t buflen
, int *errnop
);
67 NSS_STATUS
_nss_winbind_sidtouid(const char *sid
, uid_t
*uid
, int *errnop
);
68 NSS_STATUS
_nss_winbind_sidtogid(const char *sid
, gid_t
*gid
, int *errnop
);
69 NSS_STATUS
_nss_winbind_uidtosid(uid_t uid
, char **sid
, char *buffer
,
70 size_t buflen
, int *errnop
);
71 NSS_STATUS
_nss_winbind_gidtosid(gid_t gid
, char **sid
, char *buffer
,
72 size_t buflen
, int *errnop
);
74 /*************************************************************************
75 ************************************************************************/
78 static const char *nss_err_str(NSS_STATUS ret
)
81 case NSS_STATUS_TRYAGAIN
:
82 return "NSS_STATUS_TRYAGAIN";
83 case NSS_STATUS_SUCCESS
:
84 return "NSS_STATUS_SUCCESS";
85 case NSS_STATUS_NOTFOUND
:
86 return "NSS_STATUS_NOTFOUND";
87 case NSS_STATUS_UNAVAIL
:
88 return "NSS_STATUS_UNAVAIL";
89 #ifdef NSS_STATUS_RETURN
90 case NSS_STATUS_RETURN
:
91 return "NSS_STATUS_RETURN";
94 return "UNKNOWN RETURN CODE!!!!!!!";
99 /* Prototypes from wb_common.c */
101 /* Allocate some space from the nss static buffer. The buffer and buflen
102 are the pointers passed in by the C library to the _nss_ntdom_*
105 static char *get_static(char **buffer
, size_t *buflen
, size_t len
)
109 /* Error check. We return false if things aren't set up right, or
110 there isn't enough buffer space left. */
112 if ((buffer
== NULL
) || (buflen
== NULL
) || (*buflen
< len
)) {
116 /* Return an index into the static buffer */
125 /* I've copied the strtok() replacement function next_token_Xalloc() from
126 lib/util_str.c as I really don't want to have to link in any other
127 objects if I can possibly avoid it. */
129 static bool next_token_alloc(const char **ptr
,
146 /* default to simple separators */
151 /* find the first non sep char */
152 while (*s
&& strchr(sep
,*s
)) {
161 /* When restarting we need to go from here. */
164 /* Work out the length needed. */
165 for (quoted
= false; *s
&&
166 (quoted
|| !strchr(sep
,*s
)); s
++) {
174 /* We started with len = 1 so we have space for the nul. */
175 *pp_buff
= (char *)malloc(len
);
180 /* copy over the token */
183 for (quoted
= false; *s
&&
184 (quoted
|| !strchr(sep
,*s
)); s
++) {
192 *ptr
= (*s
) ? s
+1 : s
;
198 /* Fill a pwent structure from a winbindd_response structure. We use
199 the static data passed to us by libc to put strings and stuff in.
200 Return NSS_STATUS_TRYAGAIN if we run out of memory. */
202 static NSS_STATUS
fill_pwent(struct passwd
*result
,
203 struct winbindd_pw
*pw
,
204 char **buffer
, size_t *buflen
)
208 if ((result
->pw_name
=
209 get_static(buffer
, buflen
, strlen(pw
->pw_name
) + 1)) == NULL
) {
213 return NSS_STATUS_TRYAGAIN
;
216 strcpy(result
->pw_name
, pw
->pw_name
);
220 if ((result
->pw_passwd
=
221 get_static(buffer
, buflen
, strlen(pw
->pw_passwd
) + 1)) == NULL
) {
225 return NSS_STATUS_TRYAGAIN
;
228 strcpy(result
->pw_passwd
, pw
->pw_passwd
);
232 result
->pw_uid
= pw
->pw_uid
;
233 result
->pw_gid
= pw
->pw_gid
;
237 if ((result
->pw_gecos
=
238 get_static(buffer
, buflen
, strlen(pw
->pw_gecos
) + 1)) == NULL
) {
242 return NSS_STATUS_TRYAGAIN
;
245 strcpy(result
->pw_gecos
, pw
->pw_gecos
);
249 if ((result
->pw_dir
=
250 get_static(buffer
, buflen
, strlen(pw
->pw_dir
) + 1)) == NULL
) {
254 return NSS_STATUS_TRYAGAIN
;
257 strcpy(result
->pw_dir
, pw
->pw_dir
);
261 if ((result
->pw_shell
=
262 get_static(buffer
, buflen
, strlen(pw
->pw_shell
) + 1)) == NULL
) {
266 return NSS_STATUS_TRYAGAIN
;
269 strcpy(result
->pw_shell
, pw
->pw_shell
);
271 /* The struct passwd for Solaris has some extra fields which must
272 be initialised or nscd crashes. */
274 #if HAVE_PASSWD_PW_COMMENT
275 result
->pw_comment
= "";
278 #if HAVE_PASSWD_PW_AGE
282 return NSS_STATUS_SUCCESS
;
285 /* Fill a grent structure from a winbindd_response structure. We use
286 the static data passed to us by libc to put strings and stuff in.
287 Return NSS_STATUS_TRYAGAIN if we run out of memory. */
289 static NSS_STATUS
fill_grent(struct group
*result
, struct winbindd_gr
*gr
,
290 const char *gr_mem
, char **buffer
, size_t *buflen
)
298 if ((result
->gr_name
=
299 get_static(buffer
, buflen
, strlen(gr
->gr_name
) + 1)) == NULL
) {
303 return NSS_STATUS_TRYAGAIN
;
306 strcpy(result
->gr_name
, gr
->gr_name
);
310 if ((result
->gr_passwd
=
311 get_static(buffer
, buflen
, strlen(gr
->gr_passwd
) + 1)) == NULL
) {
314 return NSS_STATUS_TRYAGAIN
;
317 strcpy(result
->gr_passwd
, gr
->gr_passwd
);
321 result
->gr_gid
= gr
->gr_gid
;
323 /* Group membership */
329 /* this next value is a pointer to a pointer so let's align it */
331 /* Calculate number of extra bytes needed to align on pointer size boundry */
332 if ((i
= (unsigned long)(*buffer
) % sizeof(char*)) != 0)
333 i
= sizeof(char*) - i
;
335 if ((tst
= get_static(buffer
, buflen
, ((gr
->num_gr_mem
+ 1) *
336 sizeof(char *)+i
))) == NULL
) {
340 return NSS_STATUS_TRYAGAIN
;
342 result
->gr_mem
= (char **)(tst
+ i
);
344 if (gr
->num_gr_mem
== 0) {
348 *(result
->gr_mem
) = NULL
;
349 return NSS_STATUS_SUCCESS
;
352 /* Start looking at extra data */
356 while(next_token_alloc((const char **)&gr_mem
, &name
, ",")) {
357 /* Allocate space for member */
358 if (((result
->gr_mem
)[i
] =
359 get_static(buffer
, buflen
, strlen(name
) + 1)) == NULL
) {
362 return NSS_STATUS_TRYAGAIN
;
364 strcpy((result
->gr_mem
)[i
], name
);
371 (result
->gr_mem
)[i
] = NULL
;
373 return NSS_STATUS_SUCCESS
;
380 static struct winbindd_response getpwent_response
;
382 static int ndx_pw_cache
; /* Current index into pwd cache */
383 static int num_pw_cache
; /* Current size of pwd cache */
385 /* Rewind "file pointer" to start of ntdom password database */
388 _nss_winbind_setpwent(void)
392 fprintf(stderr
, "[%5d]: setpwent\n", getpid());
396 pthread_mutex_lock(&winbind_nss_mutex
);
399 if (num_pw_cache
> 0) {
400 ndx_pw_cache
= num_pw_cache
= 0;
401 winbindd_free_response(&getpwent_response
);
404 ret
= winbindd_request_response(NULL
, WINBINDD_SETPWENT
, NULL
, NULL
);
406 fprintf(stderr
, "[%5d]: setpwent returns %s (%d)\n", getpid(),
407 nss_err_str(ret
), ret
);
411 pthread_mutex_unlock(&winbind_nss_mutex
);
416 /* Close ntdom password database "file pointer" */
419 _nss_winbind_endpwent(void)
423 fprintf(stderr
, "[%5d]: endpwent\n", getpid());
427 pthread_mutex_lock(&winbind_nss_mutex
);
430 if (num_pw_cache
> 0) {
431 ndx_pw_cache
= num_pw_cache
= 0;
432 winbindd_free_response(&getpwent_response
);
435 ret
= winbindd_request_response(NULL
, WINBINDD_ENDPWENT
, NULL
, NULL
);
437 fprintf(stderr
, "[%5d]: endpwent returns %s (%d)\n", getpid(),
438 nss_err_str(ret
), ret
);
442 pthread_mutex_unlock(&winbind_nss_mutex
);
448 /* Fetch the next password entry from ntdom password database */
451 _nss_winbind_getpwent_r(struct passwd
*result
, char *buffer
,
452 size_t buflen
, int *errnop
)
455 struct winbindd_request request
;
456 static int called_again
;
459 fprintf(stderr
, "[%5d]: getpwent\n", getpid());
463 pthread_mutex_lock(&winbind_nss_mutex
);
466 /* Return an entry from the cache if we have one, or if we are
467 called again because we exceeded our static buffer. */
469 if ((ndx_pw_cache
< num_pw_cache
) || called_again
) {
473 /* Else call winbindd to get a bunch of entries */
475 if (num_pw_cache
> 0) {
476 winbindd_free_response(&getpwent_response
);
479 ZERO_STRUCT(request
);
480 ZERO_STRUCT(getpwent_response
);
482 request
.data
.num_entries
= MAX_GETPWENT_USERS
;
484 ret
= winbindd_request_response(NULL
, WINBINDD_GETPWENT
, &request
,
487 if (ret
== NSS_STATUS_SUCCESS
) {
488 struct winbindd_pw
*pw_cache
;
493 num_pw_cache
= getpwent_response
.data
.num_entries
;
495 /* Return a result */
499 pw_cache
= (struct winbindd_pw
*)
500 getpwent_response
.extra_data
.data
;
502 /* Check data is valid */
504 if (pw_cache
== NULL
) {
505 ret
= NSS_STATUS_NOTFOUND
;
509 ret
= fill_pwent(result
, &pw_cache
[ndx_pw_cache
],
512 /* Out of memory - try again */
514 if (ret
== NSS_STATUS_TRYAGAIN
) {
516 *errnop
= errno
= ERANGE
;
521 called_again
= false;
524 /* If we've finished with this lot of results free cache */
526 if (ndx_pw_cache
== num_pw_cache
) {
527 ndx_pw_cache
= num_pw_cache
= 0;
528 winbindd_free_response(&getpwent_response
);
533 fprintf(stderr
, "[%5d]: getpwent returns %s (%d)\n", getpid(),
534 nss_err_str(ret
), ret
);
538 pthread_mutex_unlock(&winbind_nss_mutex
);
543 /* Return passwd struct from uid */
546 _nss_winbind_getpwuid_r(uid_t uid
, struct passwd
*result
, char *buffer
,
547 size_t buflen
, int *errnop
)
550 static struct winbindd_response response
;
551 struct winbindd_request request
;
552 static int keep_response
;
555 fprintf(stderr
, "[%5d]: getpwuid_r %d\n", getpid(), (unsigned int)uid
);
559 pthread_mutex_lock(&winbind_nss_mutex
);
562 /* If our static buffer needs to be expanded we are called again */
563 if (!keep_response
|| uid
!= response
.data
.pw
.pw_uid
) {
565 /* Call for the first time */
567 ZERO_STRUCT(response
);
568 ZERO_STRUCT(request
);
570 request
.data
.uid
= uid
;
572 ret
= winbindd_request_response(NULL
, WINBINDD_GETPWUID
, &request
, &response
);
574 if (ret
== NSS_STATUS_SUCCESS
) {
575 ret
= fill_pwent(result
, &response
.data
.pw
,
578 if (ret
== NSS_STATUS_TRYAGAIN
) {
579 keep_response
= true;
580 *errnop
= errno
= ERANGE
;
587 /* We've been called again */
589 ret
= fill_pwent(result
, &response
.data
.pw
, &buffer
, &buflen
);
591 if (ret
== NSS_STATUS_TRYAGAIN
) {
592 *errnop
= errno
= ERANGE
;
596 keep_response
= false;
600 winbindd_free_response(&response
);
605 fprintf(stderr
, "[%5d]: getpwuid %d returns %s (%d)\n", getpid(),
606 (unsigned int)uid
, nss_err_str(ret
), ret
);
610 pthread_mutex_unlock(&winbind_nss_mutex
);
616 /* Return passwd struct from username */
618 _nss_winbind_getpwnam_r(const char *name
, struct passwd
*result
, char *buffer
,
619 size_t buflen
, int *errnop
)
622 static struct winbindd_response response
;
623 struct winbindd_request request
;
624 static int keep_response
;
627 fprintf(stderr
, "[%5d]: getpwnam_r %s\n", getpid(), name
);
631 pthread_mutex_lock(&winbind_nss_mutex
);
634 /* If our static buffer needs to be expanded we are called again */
636 if (!keep_response
|| strcmp(name
,response
.data
.pw
.pw_name
) != 0) {
638 /* Call for the first time */
640 ZERO_STRUCT(response
);
641 ZERO_STRUCT(request
);
643 strncpy(request
.data
.username
, name
,
644 sizeof(request
.data
.username
) - 1);
645 request
.data
.username
646 [sizeof(request
.data
.username
) - 1] = '\0';
648 ret
= winbindd_request_response(NULL
, WINBINDD_GETPWNAM
, &request
, &response
);
650 if (ret
== NSS_STATUS_SUCCESS
) {
651 ret
= fill_pwent(result
, &response
.data
.pw
, &buffer
,
654 if (ret
== NSS_STATUS_TRYAGAIN
) {
655 keep_response
= true;
656 *errnop
= errno
= ERANGE
;
663 /* We've been called again */
665 ret
= fill_pwent(result
, &response
.data
.pw
, &buffer
, &buflen
);
667 if (ret
== NSS_STATUS_TRYAGAIN
) {
668 keep_response
= true;
669 *errnop
= errno
= ERANGE
;
673 keep_response
= false;
677 winbindd_free_response(&response
);
680 fprintf(stderr
, "[%5d]: getpwnam %s returns %s (%d)\n", getpid(),
681 name
, nss_err_str(ret
), ret
);
685 pthread_mutex_unlock(&winbind_nss_mutex
);
692 * NSS group functions
695 static struct winbindd_response getgrent_response
;
697 static int ndx_gr_cache
; /* Current index into grp cache */
698 static int num_gr_cache
; /* Current size of grp cache */
700 /* Rewind "file pointer" to start of ntdom group database */
703 _nss_winbind_setgrent(void)
707 fprintf(stderr
, "[%5d]: setgrent\n", getpid());
711 pthread_mutex_lock(&winbind_nss_mutex
);
714 if (num_gr_cache
> 0) {
715 ndx_gr_cache
= num_gr_cache
= 0;
716 winbindd_free_response(&getgrent_response
);
719 ret
= winbindd_request_response(NULL
, WINBINDD_SETGRENT
, NULL
, NULL
);
721 fprintf(stderr
, "[%5d]: setgrent returns %s (%d)\n", getpid(),
722 nss_err_str(ret
), ret
);
726 pthread_mutex_unlock(&winbind_nss_mutex
);
732 /* Close "file pointer" for ntdom group database */
735 _nss_winbind_endgrent(void)
739 fprintf(stderr
, "[%5d]: endgrent\n", getpid());
743 pthread_mutex_lock(&winbind_nss_mutex
);
746 if (num_gr_cache
> 0) {
747 ndx_gr_cache
= num_gr_cache
= 0;
748 winbindd_free_response(&getgrent_response
);
751 ret
= winbindd_request_response(NULL
, WINBINDD_ENDGRENT
, NULL
, NULL
);
753 fprintf(stderr
, "[%5d]: endgrent returns %s (%d)\n", getpid(),
754 nss_err_str(ret
), ret
);
758 pthread_mutex_unlock(&winbind_nss_mutex
);
764 /* Get next entry from ntdom group database */
767 winbind_getgrent(enum winbindd_cmd cmd
,
768 struct group
*result
,
769 char *buffer
, size_t buflen
, int *errnop
)
772 static struct winbindd_request request
;
773 static int called_again
;
777 fprintf(stderr
, "[%5d]: getgrent\n", getpid());
781 pthread_mutex_lock(&winbind_nss_mutex
);
784 /* Return an entry from the cache if we have one, or if we are
785 called again because we exceeded our static buffer. */
787 if ((ndx_gr_cache
< num_gr_cache
) || called_again
) {
791 /* Else call winbindd to get a bunch of entries */
793 if (num_gr_cache
> 0) {
794 winbindd_free_response(&getgrent_response
);
797 ZERO_STRUCT(request
);
798 ZERO_STRUCT(getgrent_response
);
800 request
.data
.num_entries
= MAX_GETGRENT_USERS
;
802 ret
= winbindd_request_response(NULL
, cmd
, &request
,
805 if (ret
== NSS_STATUS_SUCCESS
) {
806 struct winbindd_gr
*gr_cache
;
812 num_gr_cache
= getgrent_response
.data
.num_entries
;
814 /* Return a result */
818 gr_cache
= (struct winbindd_gr
*)
819 getgrent_response
.extra_data
.data
;
821 /* Check data is valid */
823 if (gr_cache
== NULL
) {
824 ret
= NSS_STATUS_NOTFOUND
;
828 /* Fill group membership. The offset into the extra data
829 for the group membership is the reported offset plus the
830 size of all the winbindd_gr records returned. */
832 mem_ofs
= gr_cache
[ndx_gr_cache
].gr_mem_ofs
+
833 num_gr_cache
* sizeof(struct winbindd_gr
);
835 ret
= fill_grent(result
, &gr_cache
[ndx_gr_cache
],
836 ((char *)getgrent_response
.extra_data
.data
)+mem_ofs
,
839 /* Out of memory - try again */
841 if (ret
== NSS_STATUS_TRYAGAIN
) {
843 *errnop
= errno
= ERANGE
;
848 called_again
= false;
851 /* If we've finished with this lot of results free cache */
853 if (ndx_gr_cache
== num_gr_cache
) {
854 ndx_gr_cache
= num_gr_cache
= 0;
855 winbindd_free_response(&getgrent_response
);
860 fprintf(stderr
, "[%5d]: getgrent returns %s (%d)\n", getpid(),
861 nss_err_str(ret
), ret
);
865 pthread_mutex_unlock(&winbind_nss_mutex
);
873 _nss_winbind_getgrent_r(struct group
*result
,
874 char *buffer
, size_t buflen
, int *errnop
)
876 return winbind_getgrent(WINBINDD_GETGRENT
, result
, buffer
, buflen
, errnop
);
880 _nss_winbind_getgrlst_r(struct group
*result
,
881 char *buffer
, size_t buflen
, int *errnop
)
883 return winbind_getgrent(WINBINDD_GETGRLST
, result
, buffer
, buflen
, errnop
);
886 /* Return group struct from group name */
889 _nss_winbind_getgrnam_r(const char *name
,
890 struct group
*result
, char *buffer
,
891 size_t buflen
, int *errnop
)
894 static struct winbindd_response response
;
895 struct winbindd_request request
;
896 static int keep_response
;
899 fprintf(stderr
, "[%5d]: getgrnam %s\n", getpid(), name
);
903 pthread_mutex_lock(&winbind_nss_mutex
);
906 /* If our static buffer needs to be expanded we are called again */
907 /* Or if the stored response group name differs from the request. */
909 if (!keep_response
|| strcmp(name
,response
.data
.gr
.gr_name
) != 0) {
911 /* Call for the first time */
913 ZERO_STRUCT(request
);
914 ZERO_STRUCT(response
);
916 strncpy(request
.data
.groupname
, name
,
917 sizeof(request
.data
.groupname
));
918 request
.data
.groupname
919 [sizeof(request
.data
.groupname
) - 1] = '\0';
921 ret
= winbindd_request_response(NULL
, WINBINDD_GETGRNAM
,
922 &request
, &response
);
924 if (ret
== NSS_STATUS_SUCCESS
) {
925 ret
= fill_grent(result
, &response
.data
.gr
,
926 (char *)response
.extra_data
.data
,
929 if (ret
== NSS_STATUS_TRYAGAIN
) {
930 keep_response
= true;
931 *errnop
= errno
= ERANGE
;
938 /* We've been called again */
940 ret
= fill_grent(result
, &response
.data
.gr
,
941 (char *)response
.extra_data
.data
, &buffer
,
944 if (ret
== NSS_STATUS_TRYAGAIN
) {
945 keep_response
= true;
946 *errnop
= errno
= ERANGE
;
950 keep_response
= false;
954 winbindd_free_response(&response
);
957 fprintf(stderr
, "[%5d]: getgrnam %s returns %s (%d)\n", getpid(),
958 name
, nss_err_str(ret
), ret
);
962 pthread_mutex_unlock(&winbind_nss_mutex
);
968 /* Return group struct from gid */
971 _nss_winbind_getgrgid_r(gid_t gid
,
972 struct group
*result
, char *buffer
,
973 size_t buflen
, int *errnop
)
976 static struct winbindd_response response
;
977 struct winbindd_request request
;
978 static int keep_response
;
981 fprintf(stderr
, "[%5d]: getgrgid %d\n", getpid(), gid
);
985 pthread_mutex_lock(&winbind_nss_mutex
);
988 /* If our static buffer needs to be expanded we are called again */
989 /* Or if the stored response group name differs from the request. */
991 if (!keep_response
|| gid
!= response
.data
.gr
.gr_gid
) {
993 /* Call for the first time */
995 ZERO_STRUCT(request
);
996 ZERO_STRUCT(response
);
998 request
.data
.gid
= gid
;
1000 ret
= winbindd_request_response(NULL
, WINBINDD_GETGRGID
,
1001 &request
, &response
);
1003 if (ret
== NSS_STATUS_SUCCESS
) {
1005 ret
= fill_grent(result
, &response
.data
.gr
,
1006 (char *)response
.extra_data
.data
,
1009 if (ret
== NSS_STATUS_TRYAGAIN
) {
1010 keep_response
= true;
1011 *errnop
= errno
= ERANGE
;
1018 /* We've been called again */
1020 ret
= fill_grent(result
, &response
.data
.gr
,
1021 (char *)response
.extra_data
.data
, &buffer
,
1024 if (ret
== NSS_STATUS_TRYAGAIN
) {
1025 keep_response
= true;
1026 *errnop
= errno
= ERANGE
;
1030 keep_response
= false;
1034 winbindd_free_response(&response
);
1037 fprintf(stderr
, "[%5d]: getgrgid %d returns %s (%d)\n", getpid(),
1038 (unsigned int)gid
, nss_err_str(ret
), ret
);
1042 pthread_mutex_unlock(&winbind_nss_mutex
);
1047 /* Initialise supplementary groups */
1050 _nss_winbind_initgroups_dyn(char *user
, gid_t group
, long int *start
,
1051 long int *size
, gid_t
**groups
, long int limit
,
1055 struct winbindd_request request
;
1056 struct winbindd_response response
;
1060 fprintf(stderr
, "[%5d]: initgroups %s (%d)\n", getpid(),
1065 pthread_mutex_lock(&winbind_nss_mutex
);
1068 ZERO_STRUCT(request
);
1069 ZERO_STRUCT(response
);
1071 strncpy(request
.data
.username
, user
,
1072 sizeof(request
.data
.username
) - 1);
1074 ret
= winbindd_request_response(NULL
, WINBINDD_GETGROUPS
,
1075 &request
, &response
);
1077 if (ret
== NSS_STATUS_SUCCESS
) {
1078 int num_gids
= response
.data
.num_entries
;
1079 gid_t
*gid_list
= (gid_t
*)response
.extra_data
.data
;
1082 fprintf(stderr
, "[%5d]: initgroups %s: got NSS_STATUS_SUCCESS "
1083 "and %d gids\n", getpid(),
1086 if (gid_list
== NULL
) {
1087 ret
= NSS_STATUS_NOTFOUND
;
1091 /* Copy group list to client */
1093 for (i
= 0; i
< num_gids
; i
++) {
1096 fprintf(stderr
, "[%5d]: initgroups %s (%d): "
1097 "processing gid %d \n", getpid(),
1098 user
, group
, gid_list
[i
]);
1101 /* Skip primary group */
1103 if (gid_list
[i
] == group
) {
1107 /* Skip groups without a mapping */
1108 if (gid_list
[i
] == (uid_t
)-1) {
1112 /* Filled buffer ? If so, resize. */
1114 if (*start
== *size
) {
1118 newsize
= 2 * (*size
);
1120 if (*size
== limit
) {
1123 if (newsize
> limit
) {
1128 newgroups
= (gid_t
*)
1130 newsize
* sizeof(**groups
));
1133 ret
= NSS_STATUS_NOTFOUND
;
1136 *groups
= newgroups
;
1142 (*groups
)[*start
] = gid_list
[i
];
1147 /* Back to your regularly scheduled programming */
1151 fprintf(stderr
, "[%5d]: initgroups %s returns %s (%d)\n", getpid(),
1152 user
, nss_err_str(ret
), ret
);
1156 pthread_mutex_unlock(&winbind_nss_mutex
);
1163 /* return a list of group SIDs for a user SID */
1165 _nss_winbind_getusersids(const char *user_sid
, char **group_sids
,
1167 char *buffer
, size_t buf_size
, int *errnop
)
1170 struct winbindd_request request
;
1171 struct winbindd_response response
;
1174 fprintf(stderr
, "[%5d]: getusersids %s\n", getpid(), user_sid
);
1178 pthread_mutex_lock(&winbind_nss_mutex
);
1181 ZERO_STRUCT(request
);
1182 ZERO_STRUCT(response
);
1184 strncpy(request
.data
.sid
, user_sid
,sizeof(request
.data
.sid
) - 1);
1185 request
.data
.sid
[sizeof(request
.data
.sid
) - 1] = '\0';
1187 ret
= winbindd_request_response(NULL
, WINBINDD_GETUSERSIDS
,
1188 &request
, &response
);
1190 if (ret
!= NSS_STATUS_SUCCESS
) {
1194 if (buf_size
< response
.length
- sizeof(response
)) {
1195 ret
= NSS_STATUS_TRYAGAIN
;
1196 errno
= *errnop
= ERANGE
;
1200 *num_groups
= response
.data
.num_entries
;
1201 *group_sids
= buffer
;
1202 memcpy(buffer
, response
.extra_data
.data
, response
.length
- sizeof(response
));
1203 errno
= *errnop
= 0;
1206 winbindd_free_response(&response
);
1209 pthread_mutex_unlock(&winbind_nss_mutex
);
1216 /* map a user or group name to a SID string */
1218 _nss_winbind_nametosid(const char *name
, char **sid
, char *buffer
,
1219 size_t buflen
, int *errnop
)
1222 struct winbindd_response response
;
1223 struct winbindd_request request
;
1226 fprintf(stderr
, "[%5d]: nametosid %s\n", getpid(), name
);
1230 pthread_mutex_lock(&winbind_nss_mutex
);
1233 ZERO_STRUCT(response
);
1234 ZERO_STRUCT(request
);
1236 strncpy(request
.data
.name
.name
, name
,
1237 sizeof(request
.data
.name
.name
) - 1);
1238 request
.data
.name
.name
[sizeof(request
.data
.name
.name
) - 1] = '\0';
1240 ret
= winbindd_request_response(NULL
, WINBINDD_LOOKUPNAME
,
1241 &request
, &response
);
1242 if (ret
!= NSS_STATUS_SUCCESS
) {
1243 *errnop
= errno
= EINVAL
;
1247 if (buflen
< strlen(response
.data
.sid
.sid
)+1) {
1248 ret
= NSS_STATUS_TRYAGAIN
;
1249 *errnop
= errno
= ERANGE
;
1253 *errnop
= errno
= 0;
1255 strcpy(*sid
, response
.data
.sid
.sid
);
1258 winbindd_free_response(&response
);
1261 pthread_mutex_unlock(&winbind_nss_mutex
);
1267 /* map a sid string to a user or group name */
1269 _nss_winbind_sidtoname(const char *sid
, char **name
, char *buffer
,
1270 size_t buflen
, int *errnop
)
1273 struct winbindd_response response
;
1274 struct winbindd_request request
;
1275 static char sep_char
;
1279 fprintf(stderr
, "[%5d]: sidtoname %s\n", getpid(), sid
);
1283 pthread_mutex_lock(&winbind_nss_mutex
);
1286 ZERO_STRUCT(response
);
1287 ZERO_STRUCT(request
);
1289 /* we need to fetch the separator first time through */
1291 ret
= winbindd_request_response(NULL
, WINBINDD_INFO
,
1292 &request
, &response
);
1293 if (ret
!= NSS_STATUS_SUCCESS
) {
1294 *errnop
= errno
= EINVAL
;
1298 sep_char
= response
.data
.info
.winbind_separator
;
1299 winbindd_free_response(&response
);
1303 strncpy(request
.data
.sid
, sid
,
1304 sizeof(request
.data
.sid
) - 1);
1305 request
.data
.sid
[sizeof(request
.data
.sid
) - 1] = '\0';
1307 ret
= winbindd_request_response(NULL
, WINBINDD_LOOKUPSID
,
1308 &request
, &response
);
1309 if (ret
!= NSS_STATUS_SUCCESS
) {
1310 *errnop
= errno
= EINVAL
;
1315 strlen(response
.data
.name
.dom_name
) +
1316 strlen(response
.data
.name
.name
) + 2;
1318 if (buflen
< needed
) {
1319 ret
= NSS_STATUS_TRYAGAIN
;
1320 *errnop
= errno
= ERANGE
;
1324 snprintf(buffer
, needed
, "%s%c%s",
1325 response
.data
.name
.dom_name
,
1327 response
.data
.name
.name
);
1330 *errnop
= errno
= 0;
1333 winbindd_free_response(&response
);
1336 pthread_mutex_unlock(&winbind_nss_mutex
);
1342 /* map a sid to a uid */
1344 _nss_winbind_sidtouid(const char *sid
, uid_t
*uid
, int *errnop
)
1347 struct winbindd_response response
;
1348 struct winbindd_request request
;
1351 fprintf(stderr
, "[%5d]: sidtouid %s\n", getpid(), sid
);
1355 pthread_mutex_lock(&winbind_nss_mutex
);
1358 ZERO_STRUCT(request
);
1359 ZERO_STRUCT(response
);
1361 strncpy(request
.data
.sid
, sid
, sizeof(request
.data
.sid
) - 1);
1362 request
.data
.sid
[sizeof(request
.data
.sid
) - 1] = '\0';
1364 ret
= winbindd_request_response(NULL
, WINBINDD_SID_TO_UID
,
1365 &request
, &response
);
1366 if (ret
!= NSS_STATUS_SUCCESS
) {
1367 *errnop
= errno
= EINVAL
;
1371 *uid
= response
.data
.uid
;
1376 pthread_mutex_unlock(&winbind_nss_mutex
);
1382 /* map a sid to a gid */
1384 _nss_winbind_sidtogid(const char *sid
, gid_t
*gid
, int *errnop
)
1387 struct winbindd_response response
;
1388 struct winbindd_request request
;
1391 fprintf(stderr
, "[%5d]: sidtogid %s\n", getpid(), sid
);
1395 pthread_mutex_lock(&winbind_nss_mutex
);
1398 ZERO_STRUCT(request
);
1399 ZERO_STRUCT(response
);
1401 strncpy(request
.data
.sid
, sid
, sizeof(request
.data
.sid
) - 1);
1402 request
.data
.sid
[sizeof(request
.data
.sid
) - 1] = '\0';
1404 ret
= winbindd_request_response(NULL
, WINBINDD_SID_TO_GID
,
1405 &request
, &response
);
1406 if (ret
!= NSS_STATUS_SUCCESS
) {
1407 *errnop
= errno
= EINVAL
;
1411 *gid
= response
.data
.gid
;
1416 pthread_mutex_unlock(&winbind_nss_mutex
);
1422 /* map a uid to a SID string */
1424 _nss_winbind_uidtosid(uid_t uid
, char **sid
, char *buffer
,
1425 size_t buflen
, int *errnop
)
1428 struct winbindd_response response
;
1429 struct winbindd_request request
;
1432 fprintf(stderr
, "[%5u]: uidtosid %u\n", (unsigned int)getpid(), (unsigned int)uid
);
1436 pthread_mutex_lock(&winbind_nss_mutex
);
1439 ZERO_STRUCT(response
);
1440 ZERO_STRUCT(request
);
1442 request
.data
.uid
= uid
;
1444 ret
= winbindd_request_response(NULL
, WINBINDD_UID_TO_SID
,
1445 &request
, &response
);
1446 if (ret
!= NSS_STATUS_SUCCESS
) {
1447 *errnop
= errno
= EINVAL
;
1451 if (buflen
< strlen(response
.data
.sid
.sid
)+1) {
1452 ret
= NSS_STATUS_TRYAGAIN
;
1453 *errnop
= errno
= ERANGE
;
1457 *errnop
= errno
= 0;
1459 strcpy(*sid
, response
.data
.sid
.sid
);
1462 winbindd_free_response(&response
);
1465 pthread_mutex_unlock(&winbind_nss_mutex
);
1471 /* map a gid to a SID string */
1473 _nss_winbind_gidtosid(gid_t gid
, char **sid
, char *buffer
,
1474 size_t buflen
, int *errnop
)
1477 struct winbindd_response response
;
1478 struct winbindd_request request
;
1481 fprintf(stderr
, "[%5u]: gidtosid %u\n", (unsigned int)getpid(), (unsigned int)gid
);
1485 pthread_mutex_lock(&winbind_nss_mutex
);
1488 ZERO_STRUCT(response
);
1489 ZERO_STRUCT(request
);
1491 request
.data
.gid
= gid
;
1493 ret
= winbindd_request_response(NULL
, WINBINDD_GID_TO_SID
,
1494 &request
, &response
);
1495 if (ret
!= NSS_STATUS_SUCCESS
) {
1496 *errnop
= errno
= EINVAL
;
1500 if (buflen
< strlen(response
.data
.sid
.sid
)+1) {
1501 ret
= NSS_STATUS_TRYAGAIN
;
1502 *errnop
= errno
= ERANGE
;
1506 *errnop
= errno
= 0;
1508 strcpy(*sid
, response
.data
.sid
.sid
);
1511 winbindd_free_response(&response
);
1514 pthread_mutex_unlock(&winbind_nss_mutex
);