4 Copyright (C) Andrew Bartlett <abartlet@samba.org> 2006
5 Copyright (C) Stefan Metzmacher <metze@samba.org> 2007
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program. If not, see <http://www.gnu.org/licenses/>.
24 * Component: ldb partitions module
26 * Description: Implement LDAP partitions
28 * Author: Andrew Bartlett
29 * Author: Stefan Metzmacher
32 #include "dsdb/samdb/ldb_modules/partition.h"
33 static int partition_sort_compare(const void *v1
, const void *v2
)
35 const struct dsdb_partition
*p1
;
36 const struct dsdb_partition
*p2
;
38 p1
= *((struct dsdb_partition
* const*)v1
);
39 p2
= *((struct dsdb_partition
* const*)v2
);
41 return ldb_dn_compare(p1
->ctrl
->dn
, p2
->ctrl
->dn
);
44 /* Load the list of DNs that we must replicate to all partitions */
45 static int partition_load_replicate_dns(struct ldb_context
*ldb
, struct partition_private_data
*data
, struct ldb_message
*msg
)
47 struct ldb_message_element
*replicate_attributes
= ldb_msg_find_element(msg
, "replicateEntries");
49 talloc_free(data
->replicate
);
50 if (!replicate_attributes
) {
51 data
->replicate
= NULL
;
54 data
->replicate
= talloc_array(data
, struct ldb_dn
*, replicate_attributes
->num_values
+ 1);
55 if (!data
->replicate
) {
56 return LDB_ERR_OPERATIONS_ERROR
;
59 for (i
=0; i
< replicate_attributes
->num_values
; i
++) {
60 data
->replicate
[i
] = ldb_dn_from_ldb_val(data
->replicate
, ldb
, &replicate_attributes
->values
[i
]);
61 if (!ldb_dn_validate(data
->replicate
[i
])) {
62 ldb_asprintf_errstring(ldb
,
64 "invalid DN in partition replicate record: %s",
65 replicate_attributes
->values
[i
].data
);
66 return LDB_ERR_CONSTRAINT_VIOLATION
;
69 data
->replicate
[i
] = NULL
;
74 /* Load the list of modules for the partitions */
75 static int partition_load_modules(struct ldb_context
*ldb
,
76 struct partition_private_data
*data
, struct ldb_message
*msg
)
79 struct ldb_message_element
*modules_attributes
= ldb_msg_find_element(msg
, "modules");
80 talloc_free(data
->modules
);
81 if (!modules_attributes
) {
85 data
->modules
= talloc_array(data
, struct partition_module
*, modules_attributes
->num_values
+ 1);
88 return LDB_ERR_OPERATIONS_ERROR
;
91 for (i
=0; i
< modules_attributes
->num_values
; i
++) {
95 data
->modules
[i
] = talloc(data
->modules
, struct partition_module
);
96 if (!data
->modules
[i
]) {
98 return LDB_ERR_OPERATIONS_ERROR
;
101 base
= talloc_strdup(data
->partitions
, (char *)modules_attributes
->values
[i
].data
);
102 p
= strchr(base
, ':');
104 ldb_asprintf_errstring(ldb
,
105 "partition_load_modules: "
106 "invalid form for partition module record (missing ':'): %s", base
);
107 return LDB_ERR_CONSTRAINT_VIOLATION
;
111 data
->modules
[i
]->modules
= ldb_modules_list_from_string(ldb
, data
->modules
[i
],
114 if (strcmp(base
, "*") == 0) {
115 data
->modules
[i
]->dn
= NULL
;
117 data
->modules
[i
]->dn
= ldb_dn_new(data
->modules
[i
], ldb
, base
);
118 if (!data
->modules
[i
]->dn
|| !ldb_dn_validate(data
->modules
[i
]->dn
)) {
119 return LDB_ERR_OPERATIONS_ERROR
;
123 data
->modules
[i
] = NULL
;
127 static int partition_reload_metadata(struct ldb_module
*module
, struct partition_private_data
*data
, TALLOC_CTX
*mem_ctx
, struct ldb_message
**_msg
)
130 struct ldb_message
*msg
;
131 struct ldb_result
*res
;
132 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
133 const char *attrs
[] = { "partition", "replicateEntries", "modules", NULL
};
134 /* perform search for @PARTITION, looking for module, replicateEntries and ldapBackend */
135 ret
= dsdb_module_search_dn(module
, mem_ctx
, &res
,
136 ldb_dn_new(mem_ctx
, ldb
, DSDB_PARTITION_DN
),
138 if (ret
!= LDB_SUCCESS
) {
144 ret
= partition_load_replicate_dns(ldb
, data
, msg
);
145 if (ret
!= LDB_SUCCESS
) {
149 ret
= partition_load_modules(ldb
, data
, msg
);
150 if (ret
!= LDB_SUCCESS
) {
154 data
->ldapBackend
= talloc_steal(data
, ldb_msg_find_attr_as_string(msg
, "ldapBackend", NULL
));
164 static const char **find_modules_for_dn(struct partition_private_data
*data
, struct ldb_dn
*dn
)
167 struct partition_module
*default_mod
= NULL
;
168 for (i
=0; data
->modules
&& data
->modules
[i
]; i
++) {
169 if (!data
->modules
[i
]->dn
) {
170 default_mod
= data
->modules
[i
];
171 } else if (ldb_dn_compare(dn
, data
->modules
[i
]->dn
) == 0) {
172 return data
->modules
[i
]->modules
;
176 return default_mod
->modules
;
182 static int new_partition_from_dn(struct ldb_context
*ldb
, struct partition_private_data
*data
,
184 struct ldb_dn
*dn
, const char *casefold_dn
,
185 struct dsdb_partition
**partition
) {
186 const char *backend_url
;
187 struct dsdb_control_current_partition
*ctrl
;
188 struct ldb_module
*backend_module
;
189 const char **modules
;
192 (*partition
) = talloc(mem_ctx
, struct dsdb_partition
);
194 return LDB_ERR_OPERATIONS_ERROR
;
197 (*partition
)->ctrl
= ctrl
= talloc((*partition
), struct dsdb_control_current_partition
);
199 talloc_free(*partition
);
201 return LDB_ERR_OPERATIONS_ERROR
;
204 /* See if an LDAP backend has been specified */
205 if (data
->ldapBackend
) {
206 backend_url
= data
->ldapBackend
;
209 /* the backend LDB is the DN (base64 encoded if not 'plain') followed by .ldb */
212 char *base64_dn
= NULL
;
213 for (p
= casefold_dn
; *p
; p
++) {
214 /* We have such a strict check because I don't want shell metacharacters in the file name, nor ../ */
215 if (!(isalnum(*p
) || *p
== ' ' || *p
== '=' || *p
== ',')) {
220 casefold_dn
= base64_dn
= ldb_base64_encode(data
, casefold_dn
, strlen(casefold_dn
));
223 backend_path
= samdb_relative_path(ldb
,
227 talloc_free(base64_dn
);
230 ldb_asprintf_errstring(ldb
,
231 "partition_init: unable to determine an relative path for partition: %s", casefold_dn
);
232 talloc_free(*partition
);
233 return LDB_ERR_OPERATIONS_ERROR
;
235 backend_url
= talloc_asprintf(*partition
, "tdb://%s.ldb",
237 talloc_free(backend_path
);
240 talloc_free(*partition
);
241 return LDB_ERR_OPERATIONS_ERROR
;
245 (*partition
)->backend_url
= backend_url
;
246 ctrl
->version
= DSDB_CONTROL_CURRENT_PARTITION_VERSION
;
247 ctrl
->dn
= talloc_steal(ctrl
, dn
);
249 ret
= ldb_connect_backend(ldb
, backend_url
, NULL
, &backend_module
);
250 if (ret
!= LDB_SUCCESS
) {
253 talloc_steal((*partition
), backend_module
);
255 modules
= find_modules_for_dn(data
, dn
);
257 ret
= ldb_load_modules_list(ldb
, modules
, backend_module
, &(*partition
)->module
);
258 if (ret
!= LDB_SUCCESS
) {
259 ldb_asprintf_errstring(ldb
,
261 "loading backend for %s failed: %s",
262 ldb_dn_get_linearized(dn
), ldb_errstring(ldb
));
263 talloc_free(*partition
);
266 ret
= ldb_init_module_chain(ldb
, (*partition
)->module
);
267 if (ret
!= LDB_SUCCESS
) {
268 ldb_asprintf_errstring(ldb
,
270 "initialising backend for %s failed: %s",
271 ldb_dn_get_linearized(dn
), ldb_errstring(ldb
));
272 talloc_free(*partition
);
276 talloc_steal((*partition
), (*partition
)->module
);
281 /* Tell the rootDSE about the new partition */
282 static int partition_register(struct ldb_context
*ldb
, struct dsdb_control_current_partition
*ctrl
)
284 struct ldb_request
*req
;
287 req
= talloc_zero(NULL
, struct ldb_request
);
290 return LDB_ERR_OPERATIONS_ERROR
;
293 req
->operation
= LDB_REQ_REGISTER_PARTITION
;
294 req
->op
.reg_partition
.dn
= ctrl
->dn
;
295 req
->callback
= ldb_op_default_callback
;
297 ldb_set_timeout(ldb
, req
, 0);
299 req
->handle
= ldb_handle_new(req
, ldb
);
300 if (req
->handle
== NULL
) {
302 return LDB_ERR_OPERATIONS_ERROR
;
305 ret
= ldb_request(ldb
, req
);
306 if (ret
== LDB_SUCCESS
) {
307 ret
= ldb_wait(req
->handle
, LDB_WAIT_ALL
);
309 if (ret
!= LDB_SUCCESS
) {
310 ldb_debug(ldb
, LDB_DEBUG_ERROR
, "partition: Unable to register partition with rootdse!\n");
312 return LDB_ERR_OTHER
;
319 /* Add a newly found partition to the global data */
320 static int add_partition_to_data(struct ldb_context
*ldb
, struct partition_private_data
*data
,
321 struct dsdb_partition
*partition
)
324 /* Count the partitions */
325 for (i
=0; data
->partitions
&& data
->partitions
[i
]; i
++) { /* noop */};
327 /* Add partition to list of partitions */
328 data
->partitions
= talloc_realloc(data
, data
->partitions
, struct dsdb_partition
*, i
+ 2);
329 if (!data
->partitions
) {
331 return LDB_ERR_OPERATIONS_ERROR
;
333 data
->partitions
[i
] = talloc_steal(data
->partitions
, partition
);
334 data
->partitions
[i
+1] = NULL
;
336 /* Sort again (should use binary insert) */
337 qsort(data
->partitions
, i
+1,
338 sizeof(*data
->partitions
), partition_sort_compare
);
340 ret
= partition_register(ldb
, partition
->ctrl
);
341 if (ret
!= LDB_SUCCESS
) {
347 int partition_reload_if_required(struct ldb_module
*module
,
348 struct partition_private_data
*data
)
353 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
354 struct ldb_message
*msg
;
355 struct ldb_message_element
*partition_attributes
;
356 TALLOC_CTX
*mem_ctx
= talloc_new(data
);
358 /* Not initilised yet */
363 return LDB_ERR_OPERATIONS_ERROR
;
365 ret
= partition_primary_sequence_number(module
, mem_ctx
, LDB_SEQ_HIGHEST_SEQ
, &seq
);
366 if (ret
!= LDB_SUCCESS
) {
367 talloc_free(mem_ctx
);
370 if (seq
== data
->metadata_seq
) {
371 talloc_free(mem_ctx
);
375 ret
= partition_reload_metadata(module
, data
, mem_ctx
, &msg
);
376 if (ret
!= LDB_SUCCESS
) {
377 talloc_free(mem_ctx
);
381 data
->metadata_seq
= seq
;
383 partition_attributes
= ldb_msg_find_element(msg
, "partition");
385 for (i
=0; partition_attributes
&& i
< partition_attributes
->num_values
; i
++) {
387 bool new_partition
= true;
389 struct dsdb_partition
*partition
;
390 for (j
=0; data
->partitions
&& data
->partitions
[j
]; j
++) {
391 DATA_BLOB casefold
= data_blob_string_const(ldb_dn_get_casefold(data
->partitions
[j
]->ctrl
->dn
));
392 if (data_blob_cmp(&casefold
, &partition_attributes
->values
[i
]) == 0) {
393 new_partition
= false;
397 if (new_partition
== false) {
401 dn
= ldb_dn_from_ldb_val(mem_ctx
, ldb
, &partition_attributes
->values
[i
]);
403 ldb_asprintf_errstring(ldb
,
404 "partition_init: invalid DN in partition record: %s", (const char *)partition_attributes
->values
[i
].data
);
405 talloc_free(mem_ctx
);
406 return LDB_ERR_CONSTRAINT_VIOLATION
;
409 if (ldb_dn_compare_base(ldb_get_default_basedn(ldb
), dn
) != 0) {
410 ldb_asprintf_errstring(ldb
,
411 "partition_init: invalid DN in partition record: %s is not under %s. Perhaps an old " DSDB_PARTITION_DN
" format?",
412 (const char *)partition_attributes
->values
[i
].data
,
413 ldb_dn_get_linearized(ldb_get_default_basedn(ldb
)));
414 DEBUG(0, ("Unable to load partitions, invalid DN %s found, perhaps you need to reprovision? See partition-upgrade.txt for instructions\n",
415 (const char *)partition_attributes
->values
[i
].data
));
416 talloc_free(mem_ctx
);
417 return LDB_ERR_CONSTRAINT_VIOLATION
;
420 /* We call ldb_dn_get_linearized() because the DN in
421 * partition_attributes is already casefolded
422 * correctly. We don't want to mess that up as the
423 * schema isn't loaded yet */
424 ret
= new_partition_from_dn(ldb
, data
, data
->partitions
, dn
,
425 ldb_dn_get_linearized(dn
),
427 if (ret
!= LDB_SUCCESS
) {
428 talloc_free(mem_ctx
);
432 ret
= add_partition_to_data(ldb
, data
, partition
);
433 if (ret
!= LDB_SUCCESS
) {
434 talloc_free(mem_ctx
);
439 talloc_free(mem_ctx
);
443 /* Copy the metadata (@OPTIONS etc) for the new partition into the partition */
445 static int new_partition_set_replicated_metadata(struct ldb_context
*ldb
,
446 struct ldb_module
*module
, struct ldb_request
*last_req
,
447 struct partition_private_data
*data
,
448 struct dsdb_partition
*partition
)
451 /* for each replicate, copy from main partition. If we get an error, we report it up the chain */
452 for (i
=0; data
->replicate
&& data
->replicate
[i
]; i
++) {
453 struct ldb_result
*replicate_res
;
454 struct ldb_request
*add_req
;
455 ret
= dsdb_module_search_dn(module
, last_req
, &replicate_res
,
458 if (ret
== LDB_ERR_NO_SUCH_OBJECT
) {
461 if (ret
!= LDB_SUCCESS
) {
462 ldb_asprintf_errstring(ldb
,
463 "Failed to search for %s from " DSDB_PARTITION_DN
464 " replicateEntries for new partition at %s on %s: %s",
465 ldb_dn_get_linearized(data
->replicate
[i
]),
466 partition
->backend_url
,
467 ldb_dn_get_linearized(partition
->ctrl
->dn
),
472 /* Build add request */
473 ret
= ldb_build_add_req(&add_req
, ldb
, replicate_res
,
474 replicate_res
->msgs
[0], NULL
, NULL
,
475 ldb_op_default_callback
, last_req
);
477 if (ret
!= LDB_SUCCESS
) {
478 /* return directly, this is a very unlikely error */
482 ret
= partition_request(partition
->module
, add_req
);
484 if (ret
== LDB_SUCCESS
) {
485 ret
= ldb_wait(add_req
->handle
, LDB_WAIT_ALL
);
492 case LDB_ERR_ENTRY_ALREADY_EXISTS
:
493 /* Handle this case specially - if the
494 * metadata already exists, replace it */
496 struct ldb_request
*del_req
;
498 /* Don't leave a confusing string in the ldb_errstring() */
499 ldb_reset_err_string(ldb
);
500 /* Build del request */
501 ret
= ldb_build_del_req(&del_req
, ldb
, replicate_res
, replicate_res
->msgs
[0]->dn
, NULL
, NULL
,
502 ldb_op_default_callback
, last_req
);
504 if (ret
!= LDB_SUCCESS
) {
505 /* return directly, this is a very unlikely error */
509 ret
= partition_request(partition
->module
, del_req
);
512 if (ret
== LDB_SUCCESS
) {
513 ret
= ldb_wait(del_req
->handle
, LDB_WAIT_ALL
);
515 if (ret
!= LDB_SUCCESS
) {
516 ldb_asprintf_errstring(ldb
,
517 "Failed to delete (for re-add) %s from " DSDB_PARTITION_DN
518 " replicateEntries in new partition at %s on %s: %s",
519 ldb_dn_get_linearized(data
->replicate
[i
]),
520 partition
->backend_url
,
521 ldb_dn_get_linearized(partition
->ctrl
->dn
),
526 /* Build add request */
527 ret
= ldb_build_add_req(&add_req
, ldb
, replicate_res
, replicate_res
->msgs
[0], NULL
, NULL
,
528 ldb_op_default_callback
, last_req
);
530 if (ret
!= LDB_SUCCESS
) {
531 /* return directly, this is a very unlikely error */
535 /* do the add again */
536 ret
= partition_request(partition
->module
, add_req
);
539 if (ret
== LDB_SUCCESS
) {
540 ret
= ldb_wait(add_req
->handle
, LDB_WAIT_ALL
);
543 if (ret
!= LDB_SUCCESS
) {
544 ldb_asprintf_errstring(ldb
,
545 "Failed to add (after delete) %s from " DSDB_PARTITION_DN
546 " replicateEntries to new partition at %s on %s: %s",
547 ldb_dn_get_linearized(data
->replicate
[i
]),
548 partition
->backend_url
,
549 ldb_dn_get_linearized(partition
->ctrl
->dn
),
557 ldb_asprintf_errstring(ldb
,
558 "Failed to add %s from " DSDB_PARTITION_DN
559 " replicateEntries to new partition at %s on %s: %s",
560 ldb_dn_get_linearized(data
->replicate
[i
]),
561 partition
->backend_url
,
562 ldb_dn_get_linearized(partition
->ctrl
->dn
),
568 /* And around again, for the next thing we must merge */
573 /* Extended operation to create a new partition, called when
574 * 'new_partition' detects that one is being added based on it's
576 int partition_create(struct ldb_module
*module
, struct ldb_request
*req
)
579 struct ldb_context
*ldb
= ldb_module_get_ctx(module
);
580 struct ldb_request
*mod_req
, *last_req
= req
;
581 struct ldb_message
*mod_msg
;
582 struct partition_private_data
*data
;
583 struct dsdb_partition
*partition
= NULL
;
584 const char *casefold_dn
;
585 bool new_partition
= false;
587 /* Check if this is already a partition */
589 struct dsdb_create_partition_exop
*ex_op
= talloc_get_type(req
->op
.extended
.data
, struct dsdb_create_partition_exop
);
590 struct ldb_dn
*dn
= ex_op
->new_dn
;
592 data
= talloc_get_type(module
->private_data
, struct partition_private_data
);
594 /* We are not going to create a partition before we are even set up */
595 return LDB_ERR_UNWILLING_TO_PERFORM
;
598 for (i
=0; data
->partitions
&& data
->partitions
[i
]; i
++) {
599 if (ldb_dn_compare(data
->partitions
[i
]->ctrl
->dn
, dn
) == 0) {
600 partition
= data
->partitions
[i
];
605 new_partition
= true;
606 mod_msg
= ldb_msg_new(req
);
609 return LDB_ERR_OPERATIONS_ERROR
;
612 mod_msg
->dn
= ldb_dn_new(mod_msg
, ldb
, DSDB_PARTITION_DN
);
613 ret
= ldb_msg_add_empty(mod_msg
, DSDB_PARTITION_ATTR
, LDB_FLAG_MOD_ADD
, NULL
);
614 if (ret
!= LDB_SUCCESS
) {
618 casefold_dn
= ldb_dn_get_casefold(dn
);
620 ret
= ldb_msg_add_string(mod_msg
, DSDB_PARTITION_ATTR
, casefold_dn
);
621 if (ret
!= LDB_SUCCESS
) {
625 /* Perform modify on @PARTITION record */
626 ret
= ldb_build_mod_req(&mod_req
, ldb
, req
, mod_msg
, NULL
, NULL
,
627 ldb_op_default_callback
, req
);
629 if (ret
!= LDB_SUCCESS
) {
635 ret
= partition_request(module
, mod_req
);
636 if (ret
== LDB_SUCCESS
) {
637 ret
= ldb_wait(mod_req
->handle
, LDB_WAIT_ALL
);
640 if (ret
!= LDB_SUCCESS
) {
644 /* Make a partition structure for this new partition, so we can copy in the template structure */
645 ret
= new_partition_from_dn(ldb
, data
, req
, ldb_dn_copy(req
, dn
), casefold_dn
, &partition
);
646 if (ret
!= LDB_SUCCESS
) {
650 /* Start a transaction on the DB (as it won't be in one being brand new) */
652 struct ldb_module
*next
= partition
->module
;
653 PARTITION_FIND_OP(next
, start_transaction
);
655 ret
= next
->ops
->start_transaction(next
);
656 if (ret
!= LDB_SUCCESS
) {
662 ret
= new_partition_set_replicated_metadata(ldb
, module
, last_req
, data
, partition
);
663 if (ret
!= LDB_SUCCESS
) {
668 ret
= add_partition_to_data(ldb
, data
, partition
);
669 if (ret
!= LDB_SUCCESS
) {
674 /* send request done */
675 return ldb_module_done(req
, NULL
, NULL
, LDB_SUCCESS
);
679 int partition_init(struct ldb_module
*module
)
682 TALLOC_CTX
*mem_ctx
= talloc_new(module
);
684 struct partition_private_data
*data
;
687 return LDB_ERR_OPERATIONS_ERROR
;
690 data
= talloc_zero(mem_ctx
, struct partition_private_data
);
692 return LDB_ERR_OPERATIONS_ERROR
;
695 /* This loads the partitions */
696 ret
= partition_reload_if_required(module
, data
);
697 if (ret
!= LDB_SUCCESS
) {
701 ret
= ldb_mod_register_control(module
, LDB_CONTROL_DOMAIN_SCOPE_OID
);
702 if (ret
!= LDB_SUCCESS
) {
703 ldb_debug(ldb_module_get_ctx(module
), LDB_DEBUG_ERROR
,
704 "partition: Unable to register control with rootdse!\n");
705 return LDB_ERR_OPERATIONS_ERROR
;
708 ret
= ldb_mod_register_control(module
, LDB_CONTROL_SEARCH_OPTIONS_OID
);
709 if (ret
!= LDB_SUCCESS
) {
710 ldb_debug(ldb_module_get_ctx(module
), LDB_DEBUG_ERROR
,
711 "partition: Unable to register control with rootdse!\n");
712 return LDB_ERR_OPERATIONS_ERROR
;
715 module
->private_data
= talloc_steal(module
, data
);
717 talloc_free(mem_ctx
);
718 return ldb_next_init(module
);