2 Unix SMB/CIFS mplementation.
4 The module that handles the Schema FSMO Role Owner
5 checkings, it also loads the dsdb_schema.
7 Copyright (C) Stefan Metzmacher <metze@samba.org> 2007
8 Copyright (C) Andrew Bartlett <abartlet@samba.org> 2009-2010
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License as published by
12 the Free Software Foundation; either version 3 of the License, or
13 (at your option) any later version.
15 This program is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 GNU General Public License for more details.
20 You should have received a copy of the GNU General Public License
21 along with this program. If not, see <http://www.gnu.org/licenses/>.
26 #include "ldb_module.h"
27 #include "dsdb/samdb/samdb.h"
28 #include "librpc/gen_ndr/ndr_misc.h"
29 #include "librpc/gen_ndr/ndr_drsuapi.h"
30 #include "librpc/gen_ndr/ndr_drsblobs.h"
31 #include "param/param.h"
32 #include "lib/tdb_wrap/tdb_wrap.h"
33 #include "lib/tdb_compat/tdb_compat.h"
34 #include "dsdb/samdb/ldb_modules/util.h"
36 #include "system/filesys.h"
37 struct schema_load_private_data
{
39 struct tdb_wrap
*metadata
;
42 static int dsdb_schema_from_db(struct ldb_module
*module
, struct ldb_dn
*schema_dn
, uint64_t current_usn
,
43 struct dsdb_schema
**schema
);
46 * Open sam.ldb.d/metadata.tdb.
48 static int schema_metadata_open(struct ldb_module
*module
)
50 struct schema_load_private_data
*data
= talloc_get_type(ldb_module_get_private(module
), struct schema_load_private_data
);
51 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
53 struct loadparm_context
*lp_ctx
;
60 return ldb_module_error(module
, LDB_ERR_OPERATIONS_ERROR
,
61 "schema_load: metadata not initialized");
63 data
->metadata
= NULL
;
65 tmp_ctx
= talloc_new(NULL
);
66 if (tmp_ctx
== NULL
) {
67 return ldb_module_oom(module
);
70 sam_name
= (const char *)ldb_get_opaque(ldb
, "ldb_url");
73 return ldb_operr(ldb
);
75 if (strncmp("tdb://", sam_name
, 6) == 0) {
78 filename
= talloc_asprintf(tmp_ctx
, "%s.d/metadata.tdb", sam_name
);
85 if (stat(filename
, &statbuf
) != 0) {
87 return LDB_ERR_OPERATIONS_ERROR
;
90 lp_ctx
= talloc_get_type_abort(ldb_get_opaque(ldb
, "loadparm"),
91 struct loadparm_context
);
93 data
->metadata
= tdb_wrap_open(data
, filename
, 10,
94 TDB_DEFAULT
, open_flags
, 0660,
96 if (data
->metadata
== NULL
) {
98 return LDB_ERR_OPERATIONS_ERROR
;
101 talloc_free(tmp_ctx
);
105 static int schema_metadata_get_uint64(struct ldb_module
*module
,
106 const char *key
, uint64_t *value
,
107 uint64_t default_value
)
109 struct schema_load_private_data
*data
= talloc_get_type(ldb_module_get_private(module
), struct schema_load_private_data
);
110 struct tdb_context
*tdb
;
111 TDB_DATA tdb_key
, tdb_data
;
115 if (!data
|| !data
->metadata
) {
116 *value
= default_value
;
120 tmp_ctx
= talloc_new(NULL
);
121 if (tmp_ctx
== NULL
) {
122 return ldb_module_oom(module
);
125 tdb
= data
->metadata
->tdb
;
127 tdb_key
.dptr
= (uint8_t *)discard_const_p(char, key
);
128 tdb_key
.dsize
= strlen(key
);
130 tdb_data
= tdb_fetch_compat(tdb
, tdb_key
);
131 if (!tdb_data
.dptr
) {
132 if (tdb_error(tdb
) == TDB_ERR_NOEXIST
) {
133 *value
= default_value
;
134 talloc_free(tmp_ctx
);
137 talloc_free(tmp_ctx
);
138 return ldb_module_error(module
, LDB_ERR_OPERATIONS_ERROR
,
139 tdb_errorstr_compat(tdb
));
143 value_str
= talloc_strndup(tmp_ctx
, (char *)tdb_data
.dptr
, tdb_data
.dsize
);
144 if (value_str
== NULL
) {
145 SAFE_FREE(tdb_data
.dptr
);
146 talloc_free(tmp_ctx
);
147 return ldb_module_oom(module
);
150 *value
= strtoull(value_str
, NULL
, 10);
152 SAFE_FREE(tdb_data
.dptr
);
153 talloc_free(tmp_ctx
);
158 static struct dsdb_schema
*dsdb_schema_refresh(struct ldb_module
*module
, struct dsdb_schema
*schema
, bool is_global_schema
)
160 uint64_t current_usn
, value
;
162 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
163 struct dsdb_schema
*new_schema
;
164 struct ldb_dn
*schema_dn
= ldb_get_schema_basedn(ldb
);
167 struct schema_load_private_data
*private_data
= talloc_get_type(ldb_module_get_private(module
), struct schema_load_private_data
);
169 /* We can't refresh until the init function has run */
173 /* We don't allow a schema reload during a transaction - nobody else can modify our schema behind our backs */
174 if (private_data
->in_transaction
) {
178 lastts
= schema
->last_refresh
;
180 if (lastts
> (ts
- schema
->refresh_interval
)) {
181 DEBUG(11, ("Less than %d seconds since last reload, returning cached version ts = %d\n", (int)schema
->refresh_interval
, (int)lastts
));
186 * We update right now the last refresh timestamp so that if
187 * the schema partition hasn't change we don't keep on retrying.
188 * Otherwise if the timestamp was update only when the schema has
189 * actually changed (and therefor completely reloaded) we would
190 * continue to hit the database to get the highest USN.
193 ret
= schema_metadata_get_uint64(module
, DSDB_METADATA_SCHEMA_SEQ_NUM
, &value
, 0);
194 if (ret
== LDB_SUCCESS
) {
195 schema
->metadata_usn
= value
;
197 /* From an old provision it can happen that the tdb didn't exists yet */
198 DEBUG(0, ("Error while searching for the schema usn in the metadata\n"));
199 schema
->metadata_usn
= 0;
201 schema
->last_refresh
= ts
;
203 ret
= dsdb_module_load_partition_usn(module
, schema_dn
, ¤t_usn
, NULL
, NULL
);
204 if (ret
!= LDB_SUCCESS
|| current_usn
== schema
->loaded_usn
) {
208 ret
= dsdb_schema_from_db(module
, schema_dn
, current_usn
, &new_schema
);
209 if (ret
!= LDB_SUCCESS
) {
213 if (is_global_schema
) {
214 dsdb_make_schema_global(ldb
, new_schema
);
221 Given an LDB module (pointing at the schema DB), and the DN, set the populated schema
224 static int dsdb_schema_from_db(struct ldb_module
*module
, struct ldb_dn
*schema_dn
, uint64_t current_usn
,
225 struct dsdb_schema
**schema
)
227 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
231 struct ldb_result
*schema_res
;
232 struct ldb_result
*res
;
233 static const char *schema_attrs
[] = {
241 tmp_ctx
= talloc_new(module
);
246 /* we don't want to trace the schema load */
247 flags
= ldb_get_flags(ldb
);
248 ldb_set_flags(ldb
, flags
& ~LDB_FLG_ENABLE_TRACING
);
251 * setup the prefix mappings and schema info
253 ret
= dsdb_module_search_dn(module
, tmp_ctx
, &schema_res
,
254 schema_dn
, schema_attrs
,
255 DSDB_FLAG_NEXT_MODULE
, NULL
);
256 if (ret
== LDB_ERR_NO_SUCH_OBJECT
) {
257 ldb_reset_err_string(ldb
);
258 ldb_debug(ldb
, LDB_DEBUG_WARNING
,
259 "schema_load_init: no schema head present: (skip schema loading)\n");
261 } else if (ret
!= LDB_SUCCESS
) {
262 ldb_asprintf_errstring(ldb
,
263 "dsdb_schema: failed to search the schema head: %s",
269 * load the attribute definitions
271 ret
= dsdb_module_search(module
, tmp_ctx
, &res
,
272 schema_dn
, LDB_SCOPE_ONELEVEL
, NULL
,
273 DSDB_FLAG_NEXT_MODULE
|
274 DSDB_SEARCH_SHOW_DN_IN_STORAGE_FORMAT
,
276 "(|(objectClass=attributeSchema)(objectClass=classSchema))");
277 if (ret
!= LDB_SUCCESS
) {
278 ldb_asprintf_errstring(ldb
,
279 "dsdb_schema: failed to search attributeSchema and classSchema objects: %s",
284 ret
= dsdb_schema_from_ldb_results(tmp_ctx
, ldb
,
285 schema_res
, res
, schema
, &error_string
);
286 if (ret
!= LDB_SUCCESS
) {
287 ldb_asprintf_errstring(ldb
,
288 "dsdb_schema load failed: %s",
293 (*schema
)->refresh_in_progress
= true;
295 /* If we have the readOnlySchema opaque, then don't check for
296 * runtime schema updates, as they are not permitted (we would
297 * have to update the backend server schema too */
298 if (!ldb_get_opaque(ldb
, "readOnlySchema")) {
299 (*schema
)->refresh_fn
= dsdb_schema_refresh
;
300 (*schema
)->loaded_from_module
= module
;
301 (*schema
)->loaded_usn
= current_usn
;
304 /* "dsdb_set_schema()" steals schema into the ldb_context */
305 ret
= dsdb_set_schema(ldb
, (*schema
));
307 (*schema
)->refresh_in_progress
= false;
308 (*schema
)->last_refresh
= time(NULL
);
310 if (ret
!= LDB_SUCCESS
) {
311 ldb_debug_set(ldb
, LDB_DEBUG_FATAL
,
312 "schema_load_init: dsdb_set_schema() failed: %d:%s: %s",
313 ret
, ldb_strerror(ret
), ldb_errstring(ldb
));
317 /* Ensure this module won't go away before the callback. This
318 * causes every schema to have the LDB that originally loaded
319 * the first schema as a talloc child. */
320 if (talloc_reference(*schema
, ldb
) == NULL
) {
322 ret
= LDB_ERR_OPERATIONS_ERROR
;
326 if (flags
& LDB_FLG_ENABLE_TRACING
) {
327 flags
= ldb_get_flags(ldb
);
328 ldb_set_flags(ldb
, flags
| LDB_FLG_ENABLE_TRACING
);
330 talloc_free(tmp_ctx
);
335 static int schema_load_init(struct ldb_module
*module
)
337 struct schema_load_private_data
*private_data
;
338 struct dsdb_schema
*schema
;
339 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
341 uint64_t current_usn
;
342 struct ldb_dn
*schema_dn
;
344 private_data
= talloc_zero(module
, struct schema_load_private_data
);
345 if (private_data
== NULL
) {
349 ldb_module_set_private(module
, private_data
);
351 ret
= ldb_next_init(module
);
352 if (ret
!= LDB_SUCCESS
) {
356 if (dsdb_get_schema(ldb
, NULL
)) {
360 schema_dn
= ldb_get_schema_basedn(ldb
);
362 ldb_reset_err_string(ldb
);
363 ldb_debug(ldb
, LDB_DEBUG_WARNING
,
364 "schema_load_init: no schema dn present: (skip schema loading)\n");
368 ret
= dsdb_module_load_partition_usn(module
, schema_dn
, ¤t_usn
, NULL
, NULL
);
369 if (ret
!= LDB_SUCCESS
) {
370 /* Ignore the error and just reload the DB more often */
374 ret
= dsdb_schema_from_db(module
, schema_dn
, current_usn
, &schema
);
375 /* We don't care too much on the result of this action
376 * the most probable reason for this to fail is that the tdb didn't
377 * exists yet and this will be corrected by the partition module.
379 if (ret
== LDB_SUCCESS
&& schema_metadata_open(module
) == LDB_SUCCESS
) {
382 ret
= schema_metadata_get_uint64(module
, DSDB_METADATA_SCHEMA_SEQ_NUM
, &value
, 0);
383 if (ret
== LDB_SUCCESS
) {
384 schema
->metadata_usn
= value
;
386 schema
->metadata_usn
= 0;
392 static int schema_search(struct ldb_module
*module
, struct ldb_request
*req
)
394 struct dsdb_schema
*schema
;
395 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
398 struct schema_load_private_data
*private_data
=
399 talloc_get_type(ldb_module_get_private(module
), struct schema_load_private_data
);
401 schema
= dsdb_get_schema(ldb
, NULL
);
402 if (schema
&& private_data
&& !private_data
->in_transaction
) {
403 ret
= schema_metadata_get_uint64(module
, DSDB_METADATA_SCHEMA_SEQ_NUM
, &value
, 0);
404 if (ret
== LDB_SUCCESS
&& schema
->metadata_usn
< value
) {
405 /* The usn of the schema was changed in the metadata,
406 * this indicate that another process has modified the schema and
407 * that a reload is needed.
409 schema
->last_refresh
= 0;
410 schema
= dsdb_get_schema(ldb
, NULL
);
414 return ldb_next_request(module
, req
);
417 static int schema_load_start_transaction(struct ldb_module
*module
)
419 struct schema_load_private_data
*private_data
=
420 talloc_get_type(ldb_module_get_private(module
), struct schema_load_private_data
);
421 struct dsdb_schema
*schema
;
422 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
426 schema
= dsdb_get_schema(ldb
, NULL
);
427 if (!private_data
->metadata
) {
428 schema_metadata_open(module
);
430 ret
= schema_metadata_get_uint64(module
, DSDB_METADATA_SCHEMA_SEQ_NUM
, &value
, 0);
431 if (ret
== LDB_SUCCESS
&& schema
->metadata_usn
< value
) {
432 /* The usn of the schema was changed in the metadata,
433 * this indicate that another process has modified the schema and
434 * that a reload is needed.
436 schema
->last_refresh
= 0;
437 schema
= dsdb_get_schema(ldb
, NULL
);
439 private_data
->in_transaction
= true;
441 return ldb_next_start_trans(module
);
444 static int schema_load_end_transaction(struct ldb_module
*module
)
446 struct schema_load_private_data
*private_data
=
447 talloc_get_type(ldb_module_get_private(module
), struct schema_load_private_data
);
449 private_data
->in_transaction
= false;
451 return ldb_next_end_trans(module
);
454 static int schema_load_del_transaction(struct ldb_module
*module
)
456 struct schema_load_private_data
*private_data
=
457 talloc_get_type(ldb_module_get_private(module
), struct schema_load_private_data
);
459 private_data
->in_transaction
= false;
461 return ldb_next_del_trans(module
);
464 static int schema_load_extended(struct ldb_module
*module
, struct ldb_request
*req
)
467 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
468 struct dsdb_schema
*schema
;
470 if (strcmp(req
->op
.extended
.oid
, DSDB_EXTENDED_SCHEMA_UPDATE_NOW_OID
) != 0) {
471 return ldb_next_request(module
, req
);
473 lastts
= (time_t *)ldb_get_opaque(ldb
, DSDB_OPAQUE_LAST_SCHEMA_UPDATE_MSG_OPAQUE_NAME
);
475 lastts
= talloc(ldb
, time_t);
477 schema
= dsdb_get_schema(ldb
, NULL
);
478 /* Force a refresh */
479 schema
->last_refresh
= 0;
481 ldb_set_opaque(ldb
, DSDB_OPAQUE_LAST_SCHEMA_UPDATE_MSG_OPAQUE_NAME
, lastts
);
483 /* Pass to next module, the partition one should finish the chain */
484 return ldb_next_request(module
, req
);
488 static const struct ldb_module_ops ldb_schema_load_module_ops
= {
489 .name
= "schema_load",
490 .init_context
= schema_load_init
,
491 .extended
= schema_load_extended
,
492 .search
= schema_search
,
493 .start_transaction
= schema_load_start_transaction
,
494 .end_transaction
= schema_load_end_transaction
,
495 .del_transaction
= schema_load_del_transaction
,
498 int ldb_schema_load_module_init(const char *version
)
500 LDB_MODULE_CHECK_VERSION(version
);
501 return ldb_register_module(&ldb_schema_load_module_ops
);