2 * Unix SMB/CIFS implementation.
6 * Copyright (c) 2011 Andreas Schneider <asn@samba.org>
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, see <http://www.gnu.org/licenses/>.
27 #include "../lib/tsocket/tsocket.h"
28 #include "lib/server_prefork.h"
29 #include "lib/server_prefork_util.h"
30 #include "librpc/rpc/dcerpc_ep.h"
32 #include "rpc_server/rpc_server.h"
33 #include "rpc_server/rpc_ep_register.h"
34 #include "rpc_server/rpc_sock_helper.h"
36 #include "librpc/gen_ndr/srv_lsa.h"
37 #include "librpc/gen_ndr/srv_samr.h"
38 #include "librpc/gen_ndr/srv_netlogon.h"
40 #define DAEMON_NAME "lsasd"
41 #define LSASD_MAX_SOCKETS 64
43 static struct prefork_pool
*lsasd_pool
= NULL
;
44 static int lsasd_child_id
= 0;
46 static struct pf_daemon_config default_pf_lsasd_cfg
= {
47 .prefork_status
= PFH_INIT
,
51 .max_allowed_clients
= 100,
52 .child_min_life
= 60 /* 1 minute minimum life time */
54 static struct pf_daemon_config pf_lsasd_cfg
= { 0 };
56 void start_lsasd(struct tevent_context
*ev_ctx
,
57 struct messaging_context
*msg_ctx
);
59 static void lsasd_reopen_logs(int child_id
)
61 char *lfile
= lp_logfile();
66 rc
= asprintf(&extension
, "%s.%d", DAEMON_NAME
, child_id
);
68 rc
= asprintf(&extension
, "%s", DAEMON_NAME
);
75 if (lfile
== NULL
|| lfile
[0] == '\0') {
76 rc
= asprintf(&lfile
, "%s/log.%s",
77 get_dyn_LOGFILEBASE(), extension
);
79 if (strstr(lfile
, extension
) == NULL
) {
81 rc
= asprintf(&lfile
, "%s.%d",
85 rc
= asprintf(&lfile
, "%s.%s",
93 lp_set_logfile(lfile
);
102 static void lsasd_smb_conf_updated(struct messaging_context
*msg
,
105 struct server_id server_id
,
108 struct tevent_context
*ev_ctx
;
110 DEBUG(10, ("Got message saying smb.conf was updated. Reloading.\n"));
111 ev_ctx
= talloc_get_type_abort(private_data
, struct tevent_context
);
113 change_to_root_user();
114 lp_load(get_dyn_CONFIGFILE(), true, false, false, true);
116 lsasd_reopen_logs(lsasd_child_id
);
117 if (lsasd_child_id
== 0) {
118 pfh_daemon_config(DAEMON_NAME
,
120 &default_pf_lsasd_cfg
);
121 pfh_manage_pool(ev_ctx
, msg
, &pf_lsasd_cfg
, lsasd_pool
);
125 static void lsasd_sig_term_handler(struct tevent_context
*ev
,
126 struct tevent_signal
*se
,
132 rpc_netlogon_shutdown();
134 rpc_lsarpc_shutdown();
136 DEBUG(0, ("termination signal\n"));
140 static void lsasd_setup_sig_term_handler(struct tevent_context
*ev_ctx
)
142 struct tevent_signal
*se
;
144 se
= tevent_add_signal(ev_ctx
,
147 lsasd_sig_term_handler
,
150 DEBUG(0, ("failed to setup SIGTERM handler\n"));
155 static void lsasd_sig_hup_handler(struct tevent_context
*ev
,
156 struct tevent_signal
*se
,
163 change_to_root_user();
164 lp_load(get_dyn_CONFIGFILE(), true, false, false, true);
166 lsasd_reopen_logs(lsasd_child_id
);
167 pfh_daemon_config(DAEMON_NAME
,
169 &default_pf_lsasd_cfg
);
171 /* relay to all children */
172 prefork_send_signal_to_all(lsasd_pool
, SIGHUP
);
175 static void lsasd_setup_sig_hup_handler(struct tevent_context
*ev_ctx
)
177 struct tevent_signal
*se
;
179 se
= tevent_add_signal(ev_ctx
,
182 lsasd_sig_hup_handler
,
185 DEBUG(0, ("failed to setup SIGHUP handler\n"));
190 /**********************************************************
192 **********************************************************/
194 struct lsasd_chld_sig_hup_ctx
{
195 struct messaging_context
*msg_ctx
;
196 struct pf_worker_data
*pf
;
199 static void lsasd_chld_sig_hup_handler(struct tevent_context
*ev
,
200 struct tevent_signal
*se
,
206 struct pf_worker_data
*pf
= (struct pf_worker_data
*)pvt
;
208 /* avoid wasting CPU cycles if we are going to exit soon anyways */
209 if (pf
->cmds
== PF_SRV_MSG_EXIT
) {
213 change_to_root_user();
214 lsasd_reopen_logs(lsasd_child_id
);
217 static bool lsasd_setup_chld_hup_handler(struct tevent_context
*ev_ctx
,
218 struct pf_worker_data
*pf
)
220 struct tevent_signal
*se
;
222 se
= tevent_add_signal(ev_ctx
,
225 lsasd_chld_sig_hup_handler
,
228 DEBUG(1, ("failed to setup SIGHUP handler"));
235 static bool lsasd_child_init(struct tevent_context
*ev_ctx
,
237 struct pf_worker_data
*pf
)
240 struct messaging_context
*msg_ctx
= server_messaging_context();
243 status
= reinit_after_fork(msg_ctx
, ev_ctx
,
244 procid_self(), true);
245 if (!NT_STATUS_IS_OK(status
)) {
246 DEBUG(0,("reinit_after_fork() failed\n"));
247 smb_panic("reinit_after_fork() failed");
250 lsasd_child_id
= child_id
;
251 lsasd_reopen_logs(child_id
);
253 ok
= lsasd_setup_chld_hup_handler(ev_ctx
, pf
);
258 if (!serverid_register(procid_self(), FLAG_MSG_GENERAL
)) {
262 messaging_register(msg_ctx
, ev_ctx
,
263 MSG_SMB_CONF_UPDATED
, lsasd_smb_conf_updated
);
265 status
= rpc_lsarpc_init(NULL
);
266 if (!NT_STATUS_IS_OK(status
)) {
267 DEBUG(0, ("Failed to register lsarpc rpc inteface! (%s)\n",
272 status
= rpc_samr_init(NULL
);
273 if (!NT_STATUS_IS_OK(status
)) {
274 DEBUG(0, ("Failed to register samr rpc inteface! (%s)\n",
279 status
= rpc_netlogon_init(NULL
);
280 if (!NT_STATUS_IS_OK(status
)) {
281 DEBUG(0, ("Failed to register netlogon rpc inteface! (%s)\n",
289 struct lsasd_children_data
{
290 struct tevent_context
*ev_ctx
;
291 struct messaging_context
*msg_ctx
;
292 struct pf_worker_data
*pf
;
299 static void lsasd_next_client(void *pvt
);
301 static int lsasd_children_main(struct tevent_context
*ev_ctx
,
302 struct messaging_context
*msg_ctx
,
303 struct pf_worker_data
*pf
,
309 struct lsasd_children_data
*data
;
313 ok
= lsasd_child_init(ev_ctx
, child_id
, pf
);
318 data
= talloc(ev_ctx
, struct lsasd_children_data
);
323 data
->ev_ctx
= ev_ctx
;
324 data
->msg_ctx
= msg_ctx
;
325 data
->listen_fd_size
= listen_fd_size
;
326 data
->listen_fds
= listen_fds
;
327 data
->listening
= false;
329 /* loop until it is time to exit */
330 while (pf
->status
!= PF_WORKER_EXITING
) {
331 /* try to see if it is time to schedule the next client */
332 lsasd_next_client(data
);
334 ret
= tevent_loop_once(ev_ctx
);
336 DEBUG(0, ("tevent_loop_once() exited with %d: %s\n",
337 ret
, strerror(errno
)));
338 pf
->status
= PF_WORKER_EXITING
;
345 static void lsasd_client_terminated(void *pvt
)
347 struct lsasd_children_data
*data
;
349 data
= talloc_get_type_abort(pvt
, struct lsasd_children_data
);
351 if (data
->pf
->num_clients
) {
352 data
->pf
->num_clients
--;
354 DEBUG(2, ("Invalid num clients, aborting!\n"));
355 data
->pf
->status
= PF_WORKER_EXITING
;
359 lsasd_next_client(pvt
);
362 struct lsasd_new_client
{
363 struct lsasd_children_data
*data
;
366 static void lsasd_handle_client(struct tevent_req
*req
);
368 static void lsasd_next_client(void *pvt
)
370 struct tevent_req
*req
;
371 struct lsasd_children_data
*data
;
372 struct lsasd_new_client
*next
;
374 data
= talloc_get_type_abort(pvt
, struct lsasd_children_data
);
376 if (data
->pf
->num_clients
== 0) {
377 data
->pf
->status
= PF_WORKER_IDLE
;
380 if (data
->pf
->cmds
== PF_SRV_MSG_EXIT
) {
381 DEBUG(2, ("Parent process commands we terminate!\n"));
385 if (data
->listening
||
386 data
->pf
->num_clients
>= data
->pf
->allowed_clients
) {
387 /* nothing to do for now we are already listening
388 * or reached the number of clients we are allowed
389 * to handle in parallel */
393 next
= talloc_zero(data
, struct lsasd_new_client
);
395 DEBUG(1, ("Out of memory!?\n"));
400 req
= prefork_listen_send(next
,
403 data
->listen_fd_size
,
406 DEBUG(1, ("Failed to make listening request!?\n"));
410 tevent_req_set_callback(req
, lsasd_handle_client
, next
);
412 data
->listening
= true;
415 static void lsasd_handle_client(struct tevent_req
*req
)
417 struct lsasd_children_data
*data
;
418 struct lsasd_new_client
*client
;
422 struct tsocket_address
*srv_addr
;
423 struct tsocket_address
*cli_addr
;
425 client
= tevent_req_callback_data(req
, struct lsasd_new_client
);
428 tmp_ctx
= talloc_stackframe();
429 if (tmp_ctx
== NULL
) {
430 DEBUG(1, ("Failed to allocate stackframe!\n"));
434 rc
= prefork_listen_recv(req
,
440 /* this will free the request too */
442 /* we are done listening */
443 data
->listening
= false;
446 DEBUG(6, ("No client connection was available after all!\n"));
450 DEBUG(2, ("LSASD preforked child %d got client connection!\n",
451 (int)(data
->pf
->pid
)));
453 if (tsocket_address_is_inet(srv_addr
, "ip")) {
454 DEBUG(3, ("Got a tcpip client connection from %s on inteface %s\n",
455 tsocket_address_string(cli_addr
, tmp_ctx
),
456 tsocket_address_string(srv_addr
, tmp_ctx
)));
458 dcerpc_ncacn_accept(data
->ev_ctx
,
466 } else if (tsocket_address_is_unix(srv_addr
)) {
469 p
= tsocket_address_unix_path(srv_addr
, tmp_ctx
);
471 talloc_free(tmp_ctx
);
475 if (strstr(p
, "/np/")) {
478 named_pipe_accept_function(data
->ev_ctx
,
482 lsasd_client_terminated
,
487 dcerpc_ncacn_accept(data
->ev_ctx
,
497 DEBUG(0, ("ERROR: Unsupported socket!\n"));
501 talloc_free(tmp_ctx
);
508 static bool lsasd_schedule_check(struct tevent_context
*ev_ctx
,
509 struct messaging_context
*msg_ctx
,
510 struct timeval current_time
);
512 static void lsasd_check_children(struct tevent_context
*ev_ctx
,
513 struct tevent_timer
*te
,
514 struct timeval current_time
,
517 static void lsasd_sigchld_handler(struct tevent_context
*ev_ctx
,
518 struct prefork_pool
*pfp
,
521 struct messaging_context
*msg_ctx
;
523 msg_ctx
= talloc_get_type_abort(pvt
, struct messaging_context
);
525 /* run pool management so we can fork/retire or increase
526 * the allowed connections per child based on load */
527 pfh_manage_pool(ev_ctx
, msg_ctx
, &pf_lsasd_cfg
, lsasd_pool
);
530 static bool lsasd_setup_children_monitor(struct tevent_context
*ev_ctx
,
531 struct messaging_context
*msg_ctx
)
535 /* add our oun sigchld callback */
536 prefork_set_sigchld_callback(lsasd_pool
, lsasd_sigchld_handler
, msg_ctx
);
538 ok
= lsasd_schedule_check(ev_ctx
, msg_ctx
, tevent_timeval_current());
543 static bool lsasd_schedule_check(struct tevent_context
*ev_ctx
,
544 struct messaging_context
*msg_ctx
,
545 struct timeval current_time
)
547 struct tevent_timer
*te
;
548 struct timeval next_event
;
550 /* check situation again in 10 seconds */
551 next_event
= tevent_timeval_current_ofs(10, 0);
553 /* TODO: check when the socket becomes readable, so that children
554 * are checked only when there is some activity ? */
555 te
= tevent_add_timer(ev_ctx
, lsasd_pool
, next_event
,
556 lsasd_check_children
, msg_ctx
);
558 DEBUG(2, ("Failed to set up children monitoring!\n"));
565 static void lsasd_check_children(struct tevent_context
*ev_ctx
,
566 struct tevent_timer
*te
,
567 struct timeval current_time
,
570 struct messaging_context
*msg_ctx
;
572 msg_ctx
= talloc_get_type_abort(pvt
, struct messaging_context
);
574 pfh_manage_pool(ev_ctx
, msg_ctx
, &pf_lsasd_cfg
, lsasd_pool
);
576 lsasd_schedule_check(ev_ctx
, msg_ctx
, current_time
);
583 static bool lsasd_create_sockets(struct tevent_context
*ev_ctx
,
584 struct messaging_context
*msg_ctx
,
588 struct dcerpc_binding_vector
*v
, *v_orig
;
596 tmp_ctx
= talloc_stackframe();
597 if (tmp_ctx
== NULL
) {
601 status
= dcerpc_binding_vector_new(tmp_ctx
, &v_orig
);
602 if (!NT_STATUS_IS_OK(status
)) {
607 /* Create only one tcpip listener for all services */
608 status
= rpc_create_tcpip_sockets(&ndr_table_lsarpc
,
613 if (!NT_STATUS_IS_OK(status
)) {
618 /* Start to listen on tcpip sockets */
619 for (i
= 0; i
< *listen_fd_size
; i
++) {
620 rc
= listen(listen_fd
[i
], pf_lsasd_cfg
.max_allowed_clients
);
622 DEBUG(0, ("Failed to listen on tcpip socket - %s\n",
630 fd
= create_named_pipe_socket("lsarpc");
635 listen_fd
[*listen_fd_size
] = fd
;
638 rc
= listen(fd
, pf_lsasd_cfg
.max_allowed_clients
);
640 DEBUG(0, ("Failed to listen on lsarpc pipe - %s\n",
646 v
= dcerpc_binding_vector_dup(tmp_ctx
, v_orig
);
652 status
= dcerpc_binding_vector_replace_iface(&ndr_table_lsarpc
, v
);
653 if (!NT_STATUS_IS_OK(status
)) {
657 status
= dcerpc_binding_vector_add_np_default(&ndr_table_lsarpc
, v
);
658 if (!NT_STATUS_IS_OK(status
)) {
663 status
= rpc_ep_register(ev_ctx
, msg_ctx
, &ndr_table_lsarpc
, v
);
664 if (!NT_STATUS_IS_OK(status
)) {
670 fd
= create_named_pipe_socket("samr");
676 rc
= listen(fd
, pf_lsasd_cfg
.max_allowed_clients
);
678 DEBUG(0, ("Failed to listen on samr pipe - %s\n",
683 listen_fd
[*listen_fd_size
] = fd
;
686 v
= dcerpc_binding_vector_dup(tmp_ctx
, v_orig
);
692 status
= dcerpc_binding_vector_replace_iface(&ndr_table_samr
, v
);
693 if (!NT_STATUS_IS_OK(status
)) {
697 status
= dcerpc_binding_vector_add_np_default(&ndr_table_samr
, v
);
698 if (!NT_STATUS_IS_OK(status
)) {
703 status
= rpc_ep_register(ev_ctx
, msg_ctx
, &ndr_table_samr
, v
);
704 if (!NT_STATUS_IS_OK(status
)) {
710 fd
= create_named_pipe_socket("netlogon");
716 rc
= listen(fd
, pf_lsasd_cfg
.max_allowed_clients
);
718 DEBUG(0, ("Failed to listen on samr pipe - %s\n",
723 listen_fd
[*listen_fd_size
] = fd
;
726 v
= dcerpc_binding_vector_dup(tmp_ctx
, v_orig
);
732 status
= dcerpc_binding_vector_replace_iface(&ndr_table_netlogon
, v
);
733 if (!NT_STATUS_IS_OK(status
)) {
737 status
= dcerpc_binding_vector_add_np_default(&ndr_table_netlogon
, v
);
738 if (!NT_STATUS_IS_OK(status
)) {
743 status
= rpc_ep_register(ev_ctx
, msg_ctx
, &ndr_table_netlogon
, v
);
744 if (!NT_STATUS_IS_OK(status
)) {
750 talloc_free(tmp_ctx
);
754 void start_lsasd(struct tevent_context
*ev_ctx
,
755 struct messaging_context
*msg_ctx
)
758 int listen_fd
[LSASD_MAX_SOCKETS
];
759 int listen_fd_size
= 0;
764 DEBUG(1, ("Forking LSA Service Daemon\n"));
767 * Block signals before forking child as it will have to
768 * set its own handlers. Child will re-enable SIGHUP as
769 * soon as the handlers are set up.
771 BlockSignals(true, SIGTERM
);
772 BlockSignals(true, SIGHUP
);
776 DEBUG(0, ("Failed to fork LSASD [%s], aborting ...\n",
781 /* parent or error */
784 /* Re-enable SIGHUP before returnig */
785 BlockSignals(false, SIGTERM
);
786 BlockSignals(false, SIGHUP
);
792 close_low_fds(false);
794 status
= reinit_after_fork(msg_ctx
,
796 procid_self(), true);
797 if (!NT_STATUS_IS_OK(status
)) {
798 DEBUG(0,("reinit_after_fork() failed\n"));
799 smb_panic("reinit_after_fork() failed");
802 lsasd_reopen_logs(0);
803 pfh_daemon_config(DAEMON_NAME
,
805 &default_pf_lsasd_cfg
);
807 lsasd_setup_sig_term_handler(ev_ctx
);
808 lsasd_setup_sig_hup_handler(ev_ctx
);
810 BlockSignals(false, SIGTERM
);
811 BlockSignals(false, SIGHUP
);
813 ok
= lsasd_create_sockets(ev_ctx
, msg_ctx
, listen_fd
, &listen_fd_size
);
818 /* start children before any more initialization is done */
819 ok
= prefork_create_pool(ev_ctx
, /* mem_ctx */
824 pf_lsasd_cfg
.min_children
,
825 pf_lsasd_cfg
.max_children
,
826 &lsasd_children_main
,
833 if (!serverid_register(procid_self(), FLAG_MSG_GENERAL
)) {
837 messaging_register(msg_ctx
,
839 MSG_SMB_CONF_UPDATED
,
840 lsasd_smb_conf_updated
);
842 status
= rpc_lsarpc_init(NULL
);
843 if (!NT_STATUS_IS_OK(status
)) {
844 DEBUG(0, ("Failed to register winreg rpc inteface! (%s)\n",
849 status
= rpc_samr_init(NULL
);
850 if (!NT_STATUS_IS_OK(status
)) {
851 DEBUG(0, ("Failed to register lsasd rpc inteface! (%s)\n",
856 status
= rpc_netlogon_init(NULL
);
857 if (!NT_STATUS_IS_OK(status
)) {
858 DEBUG(0, ("Failed to register lsasd rpc inteface! (%s)\n",
863 ok
= lsasd_setup_children_monitor(ev_ctx
, msg_ctx
);
865 DEBUG(0, ("Failed to setup children monitoring!\n"));
869 DEBUG(1, ("LSASD Daemon Started (%d)\n", getpid()));
872 rc
= tevent_loop_wait(ev_ctx
);
874 /* should not be reached */
875 DEBUG(0,("lsasd: tevent_loop_wait() exited with %d - %s\n",
876 rc
, (rc
== 0) ? "out of events" : strerror(errno
)));