4 Copyright (C) Andrew Bartlett <abartlet@samba.org> 2006
5 Copyright (C) Stefan Metzmacher <metze@samba.org> 2007
7 * NOTICE: this module is NOT released under the GNU LGPL license as
8 * other ldb code. This module is release under the GNU GPL v3 or
11 This program is free software; you can redistribute it and/or modify
12 it under the terms of the GNU General Public License as published by
13 the Free Software Foundation; either version 3 of the License, or
14 (at your option) any later version.
16 This program is distributed in the hope that it will be useful,
17 but WITHOUT ANY WARRANTY; without even the implied warranty of
18 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 GNU General Public License for more details.
21 You should have received a copy of the GNU General Public License
22 along with this program. If not, see <http://www.gnu.org/licenses/>.
28 * Component: ldb partitions module
30 * Description: Implement LDAP partitions
32 * Author: Andrew Bartlett
33 * Author: Stefan Metzmacher
37 #include "ldb_private.h"
38 #include "dsdb/samdb/samdb.h"
40 struct partition_private_data
{
41 struct dsdb_control_current_partition
**partitions
;
42 struct ldb_dn
**replicate
;
46 struct ldb_module
*module
;
47 struct ldb_request
*req
;
50 struct partition_context
{
51 struct ldb_module
*module
;
52 struct ldb_request
*req
;
55 struct part_request
*part_req
;
57 int finished_requests
;
60 static struct partition_context
*partition_init_ctx(struct ldb_module
*module
, struct ldb_request
*req
)
62 struct partition_context
*ac
;
64 ac
= talloc_zero(req
, struct partition_context
);
66 ldb_set_errstring(module
->ldb
, "Out of Memory");
76 #define PARTITION_FIND_OP(module, op) do { \
77 struct ldb_context *ldbctx = module->ldb; \
78 while (module && module->ops->op == NULL) module = module->next; \
79 if (module == NULL) { \
80 ldb_asprintf_errstring(ldbctx, \
81 "Unable to find backend operation for " #op ); \
82 return LDB_ERR_OPERATIONS_ERROR; \
87 * helper functions to call the next module in chain
90 static int partition_request(struct ldb_module
*module
, struct ldb_request
*request
)
93 switch (request
->operation
) {
95 PARTITION_FIND_OP(module
, search
);
96 ret
= module
->ops
->search(module
, request
);
99 PARTITION_FIND_OP(module
, add
);
100 ret
= module
->ops
->add(module
, request
);
103 PARTITION_FIND_OP(module
, modify
);
104 ret
= module
->ops
->modify(module
, request
);
107 PARTITION_FIND_OP(module
, del
);
108 ret
= module
->ops
->del(module
, request
);
111 PARTITION_FIND_OP(module
, rename
);
112 ret
= module
->ops
->rename(module
, request
);
115 PARTITION_FIND_OP(module
, extended
);
116 ret
= module
->ops
->extended(module
, request
);
119 PARTITION_FIND_OP(module
, request
);
120 ret
= module
->ops
->request(module
, request
);
123 if (ret
== LDB_SUCCESS
) {
126 if (!ldb_errstring(module
->ldb
)) {
127 /* Set a default error string, to place the blame somewhere */
128 ldb_asprintf_errstring(module
->ldb
,
129 "error in module %s: %s (%d)",
131 ldb_strerror(ret
), ret
);
136 static struct dsdb_control_current_partition
*find_partition(struct partition_private_data
*data
,
141 /* Look at base DN */
142 /* Figure out which partition it is under */
143 /* Skip the lot if 'data' isn't here yet (initialistion) */
144 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
145 if (ldb_dn_compare_base(data
->partitions
[i
]->dn
, dn
) == 0) {
146 return data
->partitions
[i
];
154 * fire the caller's callback for every entry, but only send 'done' once.
156 static int partition_req_callback(struct ldb_request
*req
,
157 struct ldb_reply
*ares
)
159 struct partition_context
*ac
;
160 struct ldb_module
*module
;
161 struct ldb_request
*nreq
;
164 ac
= talloc_get_type(req
->context
, struct partition_context
);
167 return ldb_module_done(ac
->req
, NULL
, NULL
,
168 LDB_ERR_OPERATIONS_ERROR
);
171 if (ares
->error
!= LDB_SUCCESS
&& !ac
->got_success
) {
172 return ldb_module_done(ac
->req
, ares
->controls
,
173 ares
->response
, ares
->error
);
176 switch (ares
->type
) {
177 case LDB_REPLY_REFERRAL
:
178 /* ignore referrals for now */
181 case LDB_REPLY_ENTRY
:
182 if (ac
->req
->operation
!= LDB_SEARCH
) {
183 ldb_set_errstring(ac
->module
->ldb
,
184 "partition_req_callback:"
185 " Unsupported reply type for this request");
186 return ldb_module_done(ac
->req
, NULL
, NULL
,
187 LDB_ERR_OPERATIONS_ERROR
);
189 return ldb_module_send_entry(ac
->req
, ares
->message
, ares
->controls
);
192 if (ares
->error
== LDB_SUCCESS
) {
193 ac
->got_success
= true;
195 if (ac
->req
->operation
== LDB_EXTENDED
) {
196 /* FIXME: check for ares->response, replmd does not fill it ! */
197 if (ares
->response
) {
198 if (strcmp(ares
->response
->oid
, LDB_EXTENDED_START_TLS_OID
) != 0) {
199 ldb_set_errstring(ac
->module
->ldb
,
200 "partition_req_callback:"
201 " Unknown extended reply, "
202 "only supports START_TLS");
204 return ldb_module_done(ac
->req
, NULL
, NULL
,
205 LDB_ERR_OPERATIONS_ERROR
);
210 ac
->finished_requests
++;
211 if (ac
->finished_requests
== ac
->num_requests
) {
212 /* this was the last one, call callback */
213 return ldb_module_done(ac
->req
, ares
->controls
,
215 ac
->got_success
?LDB_SUCCESS
:ares
->error
);
218 /* not the last, now call the next one */
219 module
= ac
->part_req
[ac
->finished_requests
].module
;
220 nreq
= ac
->part_req
[ac
->finished_requests
].req
;
222 ret
= partition_request(module
, nreq
);
223 if (ret
!= LDB_SUCCESS
) {
225 return ldb_module_done(ac
->req
, NULL
, NULL
, ret
);
235 static int partition_prep_request(struct partition_context
*ac
,
236 struct dsdb_control_current_partition
*partition
)
239 struct ldb_request
*req
;
241 ac
->part_req
= talloc_realloc(ac
, ac
->part_req
,
243 ac
->num_requests
+ 1);
244 if (ac
->part_req
== NULL
) {
245 ldb_oom(ac
->module
->ldb
);
246 return LDB_ERR_OPERATIONS_ERROR
;
249 switch (ac
->req
->operation
) {
251 ret
= ldb_build_search_req_ex(&req
, ac
->module
->ldb
,
253 ac
->req
->op
.search
.base
,
254 ac
->req
->op
.search
.scope
,
255 ac
->req
->op
.search
.tree
,
256 ac
->req
->op
.search
.attrs
,
258 ac
, partition_req_callback
,
262 ret
= ldb_build_add_req(&req
, ac
->module
->ldb
, ac
->part_req
,
263 ac
->req
->op
.add
.message
,
265 ac
, partition_req_callback
,
269 ret
= ldb_build_mod_req(&req
, ac
->module
->ldb
, ac
->part_req
,
270 ac
->req
->op
.mod
.message
,
272 ac
, partition_req_callback
,
276 ret
= ldb_build_del_req(&req
, ac
->module
->ldb
, ac
->part_req
,
279 ac
, partition_req_callback
,
283 ret
= ldb_build_rename_req(&req
, ac
->module
->ldb
, ac
->part_req
,
284 ac
->req
->op
.rename
.olddn
,
285 ac
->req
->op
.rename
.newdn
,
287 ac
, partition_req_callback
,
291 ret
= ldb_build_extended_req(&req
, ac
->module
->ldb
,
293 ac
->req
->op
.extended
.oid
,
294 ac
->req
->op
.extended
.data
,
296 ac
, partition_req_callback
,
300 ldb_set_errstring(ac
->module
->ldb
,
301 "Unsupported request type!");
302 ret
= LDB_ERR_UNWILLING_TO_PERFORM
;
305 if (ret
!= LDB_SUCCESS
) {
309 ac
->part_req
[ac
->num_requests
].req
= req
;
311 if (ac
->req
->controls
) {
312 req
->controls
= talloc_memdup(req
, ac
->req
->controls
,
313 talloc_get_size(ac
->req
->controls
));
314 if (req
->controls
== NULL
) {
315 ldb_oom(ac
->module
->ldb
);
316 return LDB_ERR_OPERATIONS_ERROR
;
321 ac
->part_req
[ac
->num_requests
].module
= partition
->module
;
323 ret
= ldb_request_add_control(req
,
324 DSDB_CONTROL_CURRENT_PARTITION_OID
,
326 if (ret
!= LDB_SUCCESS
) {
330 if (req
->operation
== LDB_SEARCH
) {
331 /* If the search is for 'more' than this partition,
332 * then change the basedn, so a remote LDAP server
334 if (ldb_dn_compare_base(partition
->dn
,
335 req
->op
.search
.base
) != 0) {
336 req
->op
.search
.base
= partition
->dn
;
341 /* make sure you put the NEXT module here, or
342 * partition_request() will simply loop forever on itself */
343 ac
->part_req
[ac
->num_requests
].module
= ac
->module
->next
;
351 static int partition_call_first(struct partition_context
*ac
)
353 return partition_request(ac
->part_req
[0].module
, ac
->part_req
[0].req
);
357 * Send a request down to all the partitions
359 static int partition_send_all(struct ldb_module
*module
,
360 struct partition_context
*ac
,
361 struct ldb_request
*req
)
364 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
365 struct partition_private_data
);
366 int ret
= partition_prep_request(ac
, NULL
);
367 if (ret
!= LDB_SUCCESS
) {
370 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
371 ret
= partition_prep_request(ac
, data
->partitions
[i
]);
372 if (ret
!= LDB_SUCCESS
) {
377 /* fire the first one */
378 return partition_call_first(ac
);
382 * Figure out which backend a request needs to be aimed at. Some
383 * requests must be replicated to all backends
385 static int partition_replicate(struct ldb_module
*module
, struct ldb_request
*req
, struct ldb_dn
*dn
)
387 struct partition_context
*ac
;
390 struct dsdb_control_current_partition
*partition
;
391 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
392 struct partition_private_data
);
393 if (!data
|| !data
->partitions
) {
394 return ldb_next_request(module
, req
);
397 if (req
->operation
!= LDB_SEARCH
) {
398 /* Is this a special DN, we need to replicate to every backend? */
399 for (i
=0; data
->replicate
&& data
->replicate
[i
]; i
++) {
400 if (ldb_dn_compare(data
->replicate
[i
],
403 ac
= partition_init_ctx(module
, req
);
405 return LDB_ERR_OPERATIONS_ERROR
;
408 return partition_send_all(module
, ac
, req
);
413 /* Otherwise, we need to find the partition to fire it to */
416 partition
= find_partition(data
, dn
);
419 * if we haven't found a matching partition
420 * pass the request to the main ldb
422 * TODO: we should maybe return an error here
423 * if it's not a special dn
426 return ldb_next_request(module
, req
);
429 ac
= partition_init_ctx(module
, req
);
431 return LDB_ERR_OPERATIONS_ERROR
;
434 /* we need to add a control but we never touch the original request */
435 ret
= partition_prep_request(ac
, partition
);
436 if (ret
!= LDB_SUCCESS
) {
440 /* fire the first one */
441 return partition_call_first(ac
);
445 static int partition_search(struct ldb_module
*module
, struct ldb_request
*req
)
447 struct ldb_control
**saved_controls
;
450 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
451 struct partition_private_data
);
454 /* (later) consider if we should be searching multiple
455 * partitions (for 'invisible' partition behaviour */
457 struct ldb_control
*search_control
= ldb_request_get_control(req
, LDB_CONTROL_SEARCH_OPTIONS_OID
);
458 struct ldb_control
*domain_scope_control
= ldb_request_get_control(req
, LDB_CONTROL_DOMAIN_SCOPE_OID
);
460 struct ldb_search_options_control
*search_options
= NULL
;
461 if (search_control
) {
462 search_options
= talloc_get_type(search_control
->data
, struct ldb_search_options_control
);
465 /* Remove the domain_scope control, so we don't confuse a backend server */
466 if (domain_scope_control
&& !save_controls(domain_scope_control
, req
, &saved_controls
)) {
467 ldb_oom(module
->ldb
);
468 return LDB_ERR_OPERATIONS_ERROR
;
472 * for now pass down the LDB_CONTROL_SEARCH_OPTIONS_OID control
473 * down as uncritical to make windows 2008 dcpromo happy.
475 if (search_control
) {
476 search_control
->critical
= 0;
480 Generate referrals (look for a partition under this DN) if we don't have the above control specified
483 if (search_options
&& (search_options
->search_options
& LDB_SEARCH_OPTION_PHANTOM_ROOT
)) {
485 struct partition_context
*ac
;
486 if ((search_options
->search_options
& ~LDB_SEARCH_OPTION_PHANTOM_ROOT
) == 0) {
487 /* We have processed this flag, so we are done with this control now */
489 /* Remove search control, so we don't confuse a backend server */
490 if (search_control
&& !save_controls(search_control
, req
, &saved_controls
)) {
491 ldb_oom(module
->ldb
);
492 return LDB_ERR_OPERATIONS_ERROR
;
495 ac
= partition_init_ctx(module
, req
);
497 return LDB_ERR_OPERATIONS_ERROR
;
500 /* Search from the base DN */
501 if (!req
->op
.search
.base
|| ldb_dn_is_null(req
->op
.search
.base
)) {
502 return partition_send_all(module
, ac
, req
);
504 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
505 bool match
= false, stop
= false;
506 /* Find all partitions under the search base
510 1) the DN we are looking for exactly matches the partition
512 2) the DN we are looking for is a parent of the partition and it isn't
515 3) the DN we are looking for is a child of the partition
517 if (ldb_dn_compare(data
->partitions
[i
]->dn
, req
->op
.search
.base
) == 0) {
519 if (req
->op
.search
.scope
== LDB_SCOPE_BASE
) {
524 (ldb_dn_compare_base(req
->op
.search
.base
, data
->partitions
[i
]->dn
) == 0 &&
525 req
->op
.search
.scope
!= LDB_SCOPE_BASE
)) {
529 ldb_dn_compare_base(data
->partitions
[i
]->dn
, req
->op
.search
.base
) == 0) {
531 stop
= true; /* note that this relies on partition ordering */
534 ret
= partition_prep_request(ac
, data
->partitions
[i
]);
535 if (ret
!= LDB_SUCCESS
) {
542 /* Perhaps we didn't match any partitions. Try the main partition, only */
543 if (ac
->num_requests
== 0) {
545 return ldb_next_request(module
, req
);
548 /* fire the first one */
549 return partition_call_first(ac
);
552 /* Handle this like all other requests */
553 if (search_control
&& (search_options
->search_options
& ~LDB_SEARCH_OPTION_PHANTOM_ROOT
) == 0) {
554 /* We have processed this flag, so we are done with this control now */
556 /* Remove search control, so we don't confuse a backend server */
557 if (search_control
&& !save_controls(search_control
, req
, &saved_controls
)) {
558 ldb_oom(module
->ldb
);
559 return LDB_ERR_OPERATIONS_ERROR
;
563 return partition_replicate(module
, req
, req
->op
.search
.base
);
568 static int partition_add(struct ldb_module
*module
, struct ldb_request
*req
)
570 return partition_replicate(module
, req
, req
->op
.add
.message
->dn
);
574 static int partition_modify(struct ldb_module
*module
, struct ldb_request
*req
)
576 return partition_replicate(module
, req
, req
->op
.mod
.message
->dn
);
580 static int partition_delete(struct ldb_module
*module
, struct ldb_request
*req
)
582 return partition_replicate(module
, req
, req
->op
.del
.dn
);
586 static int partition_rename(struct ldb_module
*module
, struct ldb_request
*req
)
589 struct dsdb_control_current_partition
*backend
, *backend2
;
591 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
592 struct partition_private_data
);
594 /* Skip the lot if 'data' isn't here yet (initialization) */
596 return LDB_ERR_OPERATIONS_ERROR
;
599 backend
= find_partition(data
, req
->op
.rename
.olddn
);
600 backend2
= find_partition(data
, req
->op
.rename
.newdn
);
602 if ((backend
&& !backend2
) || (!backend
&& backend2
)) {
603 return LDB_ERR_AFFECTS_MULTIPLE_DSAS
;
606 if (backend
!= backend2
) {
607 ldb_asprintf_errstring(module
->ldb
,
608 "Cannot rename from %s in %s to %s in %s: %s",
609 ldb_dn_get_linearized(req
->op
.rename
.olddn
),
610 ldb_dn_get_linearized(backend
->dn
),
611 ldb_dn_get_linearized(req
->op
.rename
.newdn
),
612 ldb_dn_get_linearized(backend2
->dn
),
613 ldb_strerror(LDB_ERR_AFFECTS_MULTIPLE_DSAS
));
614 return LDB_ERR_AFFECTS_MULTIPLE_DSAS
;
617 return partition_replicate(module
, req
, req
->op
.rename
.olddn
);
620 /* start a transaction */
621 static int partition_start_trans(struct ldb_module
*module
)
624 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
625 struct partition_private_data
);
626 /* Look at base DN */
627 /* Figure out which partition it is under */
628 /* Skip the lot if 'data' isn't here yet (initialization) */
629 ret
= ldb_next_start_trans(module
);
630 if (ret
!= LDB_SUCCESS
) {
634 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
635 struct ldb_module
*next
= data
->partitions
[i
]->module
;
636 PARTITION_FIND_OP(next
, start_transaction
);
638 ret
= next
->ops
->start_transaction(next
);
639 if (ret
!= LDB_SUCCESS
) {
640 /* Back it out, if it fails on one */
641 for (i
--; i
>= 0; i
--) {
642 next
= data
->partitions
[i
]->module
;
643 PARTITION_FIND_OP(next
, del_transaction
);
645 next
->ops
->del_transaction(next
);
647 ldb_next_del_trans(module
);
654 /* end a transaction */
655 static int partition_end_trans(struct ldb_module
*module
)
658 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
659 struct partition_private_data
);
660 ret
= ldb_next_end_trans(module
);
661 if (ret
!= LDB_SUCCESS
) {
665 /* Look at base DN */
666 /* Figure out which partition it is under */
667 /* Skip the lot if 'data' isn't here yet (initialistion) */
668 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
669 struct ldb_module
*next
= data
->partitions
[i
]->module
;
670 PARTITION_FIND_OP(next
, end_transaction
);
672 ret
= next
->ops
->end_transaction(next
);
673 if (ret
!= LDB_SUCCESS
) {
674 /* Back it out, if it fails on one */
675 for (i
--; i
>= 0; i
--) {
676 next
= data
->partitions
[i
]->module
;
677 PARTITION_FIND_OP(next
, del_transaction
);
679 next
->ops
->del_transaction(next
);
681 ldb_next_del_trans(module
);
689 /* delete a transaction */
690 static int partition_del_trans(struct ldb_module
*module
)
692 int i
, ret
, ret2
= LDB_SUCCESS
;
693 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
694 struct partition_private_data
);
695 ret
= ldb_next_del_trans(module
);
696 if (ret
!= LDB_SUCCESS
) {
700 /* Look at base DN */
701 /* Figure out which partition it is under */
702 /* Skip the lot if 'data' isn't here yet (initialistion) */
703 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
704 struct ldb_module
*next
= data
->partitions
[i
]->module
;
705 PARTITION_FIND_OP(next
, del_transaction
);
707 ret
= next
->ops
->del_transaction(next
);
708 if (ret
!= LDB_SUCCESS
) {
716 /* FIXME: This function is still semi-async */
717 static int partition_sequence_number(struct ldb_module
*module
, struct ldb_request
*req
)
720 uint64_t seq_number
= 0;
721 uint64_t timestamp_sequence
= 0;
722 uint64_t timestamp
= 0;
723 struct partition_private_data
*data
= talloc_get_type(module
->private_data
,
724 struct partition_private_data
);
725 struct ldb_seqnum_request
*seq
;
726 struct ldb_seqnum_result
*seqr
;
727 struct ldb_request
*treq
;
728 struct ldb_seqnum_request
*tseq
;
729 struct ldb_seqnum_result
*tseqr
;
730 struct ldb_extended
*ext
;
731 struct ldb_result
*res
;
733 seq
= talloc_get_type(req
->op
.extended
.data
, struct ldb_seqnum_request
);
737 case LDB_SEQ_HIGHEST_SEQ
:
738 res
= talloc_zero(req
, struct ldb_result
);
740 return LDB_ERR_OPERATIONS_ERROR
;
742 tseq
= talloc_zero(res
, struct ldb_seqnum_request
);
745 return LDB_ERR_OPERATIONS_ERROR
;
747 tseq
->type
= seq
->type
;
749 ret
= ldb_build_extended_req(&treq
, module
->ldb
, res
,
750 LDB_EXTENDED_SEQUENCE_NUMBER
,
754 ldb_extended_default_callback
,
756 ret
= ldb_next_request(module
, treq
);
757 if (ret
== LDB_SUCCESS
) {
758 ret
= ldb_wait(treq
->handle
, LDB_WAIT_ALL
);
760 if (ret
!= LDB_SUCCESS
) {
764 seqr
= talloc_get_type(res
->extended
->data
,
765 struct ldb_seqnum_result
);
766 if (seqr
->flags
& LDB_SEQ_TIMESTAMP_SEQUENCE
) {
767 timestamp_sequence
= seqr
->seq_num
;
769 seq_number
+= seqr
->seq_num
;
773 /* Skip the lot if 'data' isn't here yet (initialistion) */
774 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
776 res
= talloc_zero(req
, struct ldb_result
);
778 return LDB_ERR_OPERATIONS_ERROR
;
780 tseq
= talloc_zero(res
, struct ldb_seqnum_request
);
783 return LDB_ERR_OPERATIONS_ERROR
;
785 tseq
->type
= seq
->type
;
787 ret
= ldb_build_extended_req(&treq
, module
->ldb
, res
,
788 LDB_EXTENDED_SEQUENCE_NUMBER
,
792 ldb_extended_default_callback
,
794 if (ret
!= LDB_SUCCESS
) {
799 ret
= ldb_request_add_control(treq
,
800 DSDB_CONTROL_CURRENT_PARTITION_OID
,
801 false, data
->partitions
[i
]);
802 if (ret
!= LDB_SUCCESS
) {
807 ret
= partition_request(data
->partitions
[i
]->module
, treq
);
808 if (ret
!= LDB_SUCCESS
) {
812 ret
= ldb_wait(treq
->handle
, LDB_WAIT_ALL
);
813 if (ret
!= LDB_SUCCESS
) {
817 tseqr
= talloc_get_type(res
->extended
->data
,
818 struct ldb_seqnum_result
);
819 if (tseqr
->flags
& LDB_SEQ_TIMESTAMP_SEQUENCE
) {
820 timestamp_sequence
= MAX(timestamp_sequence
,
823 seq_number
+= tseqr
->seq_num
;
828 case LDB_SEQ_HIGHEST_TIMESTAMP
:
830 res
= talloc_zero(req
, struct ldb_result
);
832 return LDB_ERR_OPERATIONS_ERROR
;
835 tseq
= talloc_zero(res
, struct ldb_seqnum_request
);
838 return LDB_ERR_OPERATIONS_ERROR
;
840 tseq
->type
= LDB_SEQ_HIGHEST_TIMESTAMP
;
842 ret
= ldb_build_extended_req(&treq
, module
->ldb
, res
,
843 LDB_EXTENDED_SEQUENCE_NUMBER
,
847 ldb_extended_default_callback
,
849 if (ret
!= LDB_SUCCESS
) {
854 ret
= ldb_next_request(module
, treq
);
855 if (ret
!= LDB_SUCCESS
) {
859 ret
= ldb_wait(treq
->handle
, LDB_WAIT_ALL
);
860 if (ret
!= LDB_SUCCESS
) {
865 tseqr
= talloc_get_type(res
->extended
->data
,
866 struct ldb_seqnum_result
);
867 timestamp
= tseqr
->seq_num
;
871 /* Skip the lot if 'data' isn't here yet (initialistion) */
872 for (i
=0; data
&& data
->partitions
&& data
->partitions
[i
]; i
++) {
874 res
= talloc_zero(req
, struct ldb_result
);
876 return LDB_ERR_OPERATIONS_ERROR
;
879 tseq
= talloc_zero(res
, struct ldb_seqnum_request
);
882 return LDB_ERR_OPERATIONS_ERROR
;
884 tseq
->type
= LDB_SEQ_HIGHEST_TIMESTAMP
;
886 ret
= ldb_build_extended_req(&treq
, module
->ldb
, res
,
887 LDB_EXTENDED_SEQUENCE_NUMBER
,
891 ldb_extended_default_callback
,
893 if (ret
!= LDB_SUCCESS
) {
898 ret
= ldb_request_add_control(treq
,
899 DSDB_CONTROL_CURRENT_PARTITION_OID
,
900 false, data
->partitions
[i
]);
901 if (ret
!= LDB_SUCCESS
) {
906 ret
= partition_request(data
->partitions
[i
]->module
, treq
);
907 if (ret
!= LDB_SUCCESS
) {
911 ret
= ldb_wait(treq
->handle
, LDB_WAIT_ALL
);
912 if (ret
!= LDB_SUCCESS
) {
917 tseqr
= talloc_get_type(res
->extended
->data
,
918 struct ldb_seqnum_result
);
919 timestamp
= MAX(timestamp
, tseqr
->seq_num
);
927 ext
= talloc_zero(req
, struct ldb_extended
);
929 return LDB_ERR_OPERATIONS_ERROR
;
931 seqr
= talloc_zero(ext
, struct ldb_seqnum_result
);
934 return LDB_ERR_OPERATIONS_ERROR
;
936 ext
->oid
= LDB_EXTENDED_SEQUENCE_NUMBER
;
941 case LDB_SEQ_HIGHEST_SEQ
:
943 /* Has someone above set a timebase sequence? */
944 if (timestamp_sequence
) {
945 seqr
->seq_num
= (((unsigned long long)timestamp
<< 24) | (seq_number
& 0xFFFFFF));
947 seqr
->seq_num
= seq_number
;
950 if (timestamp_sequence
> seqr
->seq_num
) {
951 seqr
->seq_num
= timestamp_sequence
;
952 seqr
->flags
|= LDB_SEQ_TIMESTAMP_SEQUENCE
;
955 seqr
->flags
|= LDB_SEQ_GLOBAL_SEQUENCE
;
957 case LDB_SEQ_HIGHEST_TIMESTAMP
:
958 seqr
->seq_num
= timestamp
;
962 if (seq
->type
== LDB_SEQ_NEXT
) {
966 /* send request done */
967 return ldb_module_done(req
, NULL
, ext
, LDB_SUCCESS
);
970 static int partition_extended_replicated_objects(struct ldb_module
*module
, struct ldb_request
*req
)
972 struct dsdb_extended_replicated_objects
*ext
;
974 ext
= talloc_get_type(req
->op
.extended
.data
, struct dsdb_extended_replicated_objects
);
976 ldb_debug(module
->ldb
, LDB_DEBUG_FATAL
, "partition_extended_replicated_objects: invalid extended data\n");
977 return LDB_ERR_PROTOCOL_ERROR
;
980 if (ext
->version
!= DSDB_EXTENDED_REPLICATED_OBJECTS_VERSION
) {
981 ldb_debug(module
->ldb
, LDB_DEBUG_FATAL
, "partition_extended_replicated_objects: extended data invalid version [%u != %u]\n",
982 ext
->version
, DSDB_EXTENDED_REPLICATED_OBJECTS_VERSION
);
983 return LDB_ERR_PROTOCOL_ERROR
;
986 return partition_replicate(module
, req
, ext
->partition_dn
);
989 static int partition_extended_schema_update_now(struct ldb_module
*module
, struct ldb_request
*req
)
991 struct dsdb_control_current_partition
*partition
;
992 struct partition_private_data
*data
;
993 struct ldb_dn
*schema_dn
;
994 struct partition_context
*ac
;
997 schema_dn
= talloc_get_type(req
->op
.extended
.data
, struct ldb_dn
);
999 ldb_debug(module
->ldb
, LDB_DEBUG_FATAL
, "partition_extended: invalid extended data\n");
1000 return LDB_ERR_PROTOCOL_ERROR
;
1003 data
= talloc_get_type(module
->private_data
, struct partition_private_data
);
1005 return LDB_ERR_OPERATIONS_ERROR
;
1008 partition
= find_partition( data
, schema_dn
);
1010 return ldb_next_request(module
, req
);
1013 ac
= partition_init_ctx(module
, req
);
1015 return LDB_ERR_OPERATIONS_ERROR
;
1018 /* we need to add a control but we never touch the original request */
1019 ret
= partition_prep_request(ac
, partition
);
1020 if (ret
!= LDB_SUCCESS
) {
1024 /* fire the first one */
1025 return partition_call_first(ac
);
1030 static int partition_extended(struct ldb_module
*module
, struct ldb_request
*req
)
1032 struct partition_private_data
*data
;
1033 struct partition_context
*ac
;
1035 data
= talloc_get_type(module
->private_data
, struct partition_private_data
);
1036 if (!data
|| !data
->partitions
) {
1037 return ldb_next_request(module
, req
);
1040 if (strcmp(req
->op
.extended
.oid
, LDB_EXTENDED_SEQUENCE_NUMBER
) == 0) {
1041 return partition_sequence_number(module
, req
);
1044 if (strcmp(req
->op
.extended
.oid
, DSDB_EXTENDED_REPLICATED_OBJECTS_OID
) == 0) {
1045 return partition_extended_replicated_objects(module
, req
);
1048 /* forward schemaUpdateNow operation to schema_fsmo module*/
1049 if (strcmp(req
->op
.extended
.oid
, DSDB_EXTENDED_SCHEMA_UPDATE_NOW_OID
) == 0) {
1050 return partition_extended_schema_update_now( module
, req
);
1054 * as the extended operation has no dn
1055 * we need to send it to all partitions
1058 ac
= partition_init_ctx(module
, req
);
1060 return LDB_ERR_OPERATIONS_ERROR
;
1063 return partition_send_all(module
, ac
, req
);
1066 static int partition_sort_compare(const void *v1
, const void *v2
)
1068 const struct dsdb_control_current_partition
*p1
;
1069 const struct dsdb_control_current_partition
*p2
;
1071 p1
= *((struct dsdb_control_current_partition
* const*)v1
);
1072 p2
= *((struct dsdb_control_current_partition
* const*)v2
);
1074 return ldb_dn_compare(p1
->dn
, p2
->dn
);
1077 static int partition_init(struct ldb_module
*module
)
1080 TALLOC_CTX
*mem_ctx
= talloc_new(module
);
1081 const char *attrs
[] = { "partition", "replicateEntries", "modules", NULL
};
1082 struct ldb_result
*res
;
1083 struct ldb_message
*msg
;
1084 struct ldb_message_element
*partition_attributes
;
1085 struct ldb_message_element
*replicate_attributes
;
1086 struct ldb_message_element
*modules_attributes
;
1088 struct partition_private_data
*data
;
1091 return LDB_ERR_OPERATIONS_ERROR
;
1094 data
= talloc(mem_ctx
, struct partition_private_data
);
1096 return LDB_ERR_OPERATIONS_ERROR
;
1099 ret
= ldb_search(module
->ldb
, mem_ctx
, &res
,
1100 ldb_dn_new(mem_ctx
, module
->ldb
, "@PARTITION"),
1101 LDB_SCOPE_BASE
, attrs
, NULL
);
1102 if (ret
!= LDB_SUCCESS
) {
1103 talloc_free(mem_ctx
);
1106 if (res
->count
== 0) {
1107 talloc_free(mem_ctx
);
1108 return ldb_next_init(module
);
1111 if (res
->count
> 1) {
1112 talloc_free(mem_ctx
);
1113 return LDB_ERR_CONSTRAINT_VIOLATION
;
1118 partition_attributes
= ldb_msg_find_element(msg
, "partition");
1119 if (!partition_attributes
) {
1120 ldb_set_errstring(module
->ldb
, "partition_init: no partitions specified");
1121 talloc_free(mem_ctx
);
1122 return LDB_ERR_CONSTRAINT_VIOLATION
;
1124 data
->partitions
= talloc_array(data
, struct dsdb_control_current_partition
*, partition_attributes
->num_values
+ 1);
1125 if (!data
->partitions
) {
1126 talloc_free(mem_ctx
);
1127 return LDB_ERR_OPERATIONS_ERROR
;
1129 for (i
=0; i
< partition_attributes
->num_values
; i
++) {
1130 char *base
= talloc_strdup(data
->partitions
, (char *)partition_attributes
->values
[i
].data
);
1131 char *p
= strchr(base
, ':');
1133 ldb_asprintf_errstring(module
->ldb
,
1135 "invalid form for partition record (missing ':'): %s", base
);
1136 talloc_free(mem_ctx
);
1137 return LDB_ERR_CONSTRAINT_VIOLATION
;
1142 ldb_asprintf_errstring(module
->ldb
,
1144 "invalid form for partition record (missing backend database): %s", base
);
1145 talloc_free(mem_ctx
);
1146 return LDB_ERR_CONSTRAINT_VIOLATION
;
1148 data
->partitions
[i
] = talloc(data
->partitions
, struct dsdb_control_current_partition
);
1149 if (!data
->partitions
[i
]) {
1150 talloc_free(mem_ctx
);
1151 return LDB_ERR_OPERATIONS_ERROR
;
1153 data
->partitions
[i
]->version
= DSDB_CONTROL_CURRENT_PARTITION_VERSION
;
1155 data
->partitions
[i
]->dn
= ldb_dn_new(data
->partitions
[i
], module
->ldb
, base
);
1156 if (!data
->partitions
[i
]->dn
) {
1157 ldb_asprintf_errstring(module
->ldb
,
1158 "partition_init: invalid DN in partition record: %s", base
);
1159 talloc_free(mem_ctx
);
1160 return LDB_ERR_CONSTRAINT_VIOLATION
;
1163 data
->partitions
[i
]->backend
= samdb_relative_path(module
->ldb
,
1164 data
->partitions
[i
],
1166 if (!data
->partitions
[i
]->backend
) {
1167 ldb_asprintf_errstring(module
->ldb
,
1168 "partition_init: unable to determine an relative path for partition: %s", base
);
1169 talloc_free(mem_ctx
);
1171 ret
= ldb_connect_backend(module
->ldb
, data
->partitions
[i
]->backend
, NULL
, &data
->partitions
[i
]->module
);
1172 if (ret
!= LDB_SUCCESS
) {
1173 talloc_free(mem_ctx
);
1177 data
->partitions
[i
] = NULL
;
1179 /* sort these into order, most to least specific */
1180 qsort(data
->partitions
, partition_attributes
->num_values
,
1181 sizeof(*data
->partitions
), partition_sort_compare
);
1183 for (i
=0; data
->partitions
[i
]; i
++) {
1184 struct ldb_request
*req
;
1185 req
= talloc_zero(mem_ctx
, struct ldb_request
);
1187 ldb_debug(module
->ldb
, LDB_DEBUG_ERROR
, "partition: Out of memory!\n");
1188 talloc_free(mem_ctx
);
1189 return LDB_ERR_OPERATIONS_ERROR
;
1192 req
->operation
= LDB_REQ_REGISTER_PARTITION
;
1193 req
->op
.reg_partition
.dn
= data
->partitions
[i
]->dn
;
1194 req
->callback
= ldb_op_default_callback
;
1196 ldb_set_timeout(module
->ldb
, req
, 0);
1198 req
->handle
= ldb_handle_new(req
, module
->ldb
);
1199 if (req
->handle
== NULL
) {
1200 return LDB_ERR_OPERATIONS_ERROR
;
1203 ret
= ldb_request(module
->ldb
, req
);
1204 if (ret
== LDB_SUCCESS
) {
1205 ret
= ldb_wait(req
->handle
, LDB_WAIT_ALL
);
1207 if (ret
!= LDB_SUCCESS
) {
1208 ldb_debug(module
->ldb
, LDB_DEBUG_ERROR
, "partition: Unable to register partition with rootdse!\n");
1209 talloc_free(mem_ctx
);
1210 return LDB_ERR_OTHER
;
1215 replicate_attributes
= ldb_msg_find_element(msg
, "replicateEntries");
1216 if (!replicate_attributes
) {
1217 data
->replicate
= NULL
;
1219 data
->replicate
= talloc_array(data
, struct ldb_dn
*, replicate_attributes
->num_values
+ 1);
1220 if (!data
->replicate
) {
1221 talloc_free(mem_ctx
);
1222 return LDB_ERR_OPERATIONS_ERROR
;
1225 for (i
=0; i
< replicate_attributes
->num_values
; i
++) {
1226 data
->replicate
[i
] = ldb_dn_from_ldb_val(data
->replicate
, module
->ldb
, &replicate_attributes
->values
[i
]);
1227 if (!ldb_dn_validate(data
->replicate
[i
])) {
1228 ldb_asprintf_errstring(module
->ldb
,
1230 "invalid DN in partition replicate record: %s",
1231 replicate_attributes
->values
[i
].data
);
1232 talloc_free(mem_ctx
);
1233 return LDB_ERR_CONSTRAINT_VIOLATION
;
1236 data
->replicate
[i
] = NULL
;
1239 /* Make the private data available to any searches the modules may trigger in initialisation */
1240 module
->private_data
= data
;
1241 talloc_steal(module
, data
);
1243 modules_attributes
= ldb_msg_find_element(msg
, "modules");
1244 if (modules_attributes
) {
1245 for (i
=0; i
< modules_attributes
->num_values
; i
++) {
1246 struct ldb_dn
*base_dn
;
1248 struct dsdb_control_current_partition
*partition
= NULL
;
1249 const char **modules
= NULL
;
1251 char *base
= talloc_strdup(data
->partitions
, (char *)modules_attributes
->values
[i
].data
);
1252 char *p
= strchr(base
, ':');
1254 ldb_asprintf_errstring(module
->ldb
,
1256 "invalid form for partition module record (missing ':'): %s", base
);
1257 talloc_free(mem_ctx
);
1258 return LDB_ERR_CONSTRAINT_VIOLATION
;
1263 ldb_asprintf_errstring(module
->ldb
,
1265 "invalid form for partition module record (missing backend database): %s", base
);
1266 talloc_free(mem_ctx
);
1267 return LDB_ERR_CONSTRAINT_VIOLATION
;
1270 modules
= ldb_modules_list_from_string(module
->ldb
, mem_ctx
,
1273 base_dn
= ldb_dn_new(mem_ctx
, module
->ldb
, base
);
1274 if (!ldb_dn_validate(base_dn
)) {
1275 talloc_free(mem_ctx
);
1276 return LDB_ERR_OPERATIONS_ERROR
;
1279 for (partition_idx
= 0; data
->partitions
[partition_idx
]; partition_idx
++) {
1280 if (ldb_dn_compare(data
->partitions
[partition_idx
]->dn
, base_dn
) == 0) {
1281 partition
= data
->partitions
[partition_idx
];
1287 ldb_asprintf_errstring(module
->ldb
,
1289 "invalid form for partition module record (no such partition): %s", base
);
1290 talloc_free(mem_ctx
);
1291 return LDB_ERR_CONSTRAINT_VIOLATION
;
1294 ret
= ldb_load_modules_list(module
->ldb
, modules
, partition
->module
, &partition
->module
);
1295 if (ret
!= LDB_SUCCESS
) {
1296 ldb_asprintf_errstring(module
->ldb
,
1298 "loading backend for %s failed: %s",
1299 base
, ldb_errstring(module
->ldb
));
1300 talloc_free(mem_ctx
);
1303 ret
= ldb_init_module_chain(module
->ldb
, partition
->module
);
1304 if (ret
!= LDB_SUCCESS
) {
1305 ldb_asprintf_errstring(module
->ldb
,
1307 "initialising backend for %s failed: %s",
1308 base
, ldb_errstring(module
->ldb
));
1309 talloc_free(mem_ctx
);
1315 ret
= ldb_mod_register_control(module
, LDB_CONTROL_DOMAIN_SCOPE_OID
);
1316 if (ret
!= LDB_SUCCESS
) {
1317 ldb_debug(module
->ldb
, LDB_DEBUG_ERROR
,
1318 "partition: Unable to register control with rootdse!\n");
1319 return LDB_ERR_OPERATIONS_ERROR
;
1322 ret
= ldb_mod_register_control(module
, LDB_CONTROL_SEARCH_OPTIONS_OID
);
1323 if (ret
!= LDB_SUCCESS
) {
1324 ldb_debug(module
->ldb
, LDB_DEBUG_ERROR
,
1325 "partition: Unable to register control with rootdse!\n");
1326 return LDB_ERR_OPERATIONS_ERROR
;
1329 talloc_free(mem_ctx
);
1330 return ldb_next_init(module
);
1333 _PUBLIC_
const struct ldb_module_ops ldb_partition_module_ops
= {
1334 .name
= "partition",
1335 .init_context
= partition_init
,
1336 .search
= partition_search
,
1337 .add
= partition_add
,
1338 .modify
= partition_modify
,
1339 .del
= partition_delete
,
1340 .rename
= partition_rename
,
1341 .extended
= partition_extended
,
1342 .start_transaction
= partition_start_trans
,
1343 .end_transaction
= partition_end_trans
,
1344 .del_transaction
= partition_del_trans
,