2 Unix SMB/CIFS mplementation.
3 KCC service periodic handling
5 Copyright (C) Andrew Tridgell 2009
6 based on repl service code
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
24 #include "lib/events/events.h"
25 #include "dsdb/samdb/samdb.h"
26 #include "auth/auth.h"
27 #include "smbd/service.h"
28 #include "lib/messaging/irpc.h"
29 #include "dsdb/kcc/kcc_connection.h"
30 #include "dsdb/kcc/kcc_service.h"
31 #include "lib/ldb/include/ldb_errors.h"
32 #include "../lib/util/dlinklist.h"
33 #include "librpc/gen_ndr/ndr_misc.h"
34 #include "librpc/gen_ndr/ndr_drsuapi.h"
35 #include "librpc/gen_ndr/ndr_drsblobs.h"
36 #include "param/param.h"
39 * see if a repsFromToBlob is in a list
41 static bool reps_in_list(struct repsFromToBlob
*r
, struct repsFromToBlob
*reps
, uint32_t count
)
44 for (i
=0; i
<count
; i
++) {
45 if (strcmp(r
->ctr
.ctr1
.other_info
->dns_name
,
46 reps
[i
].ctr
.ctr1
.other_info
->dns_name
) == 0 &&
47 GUID_compare(&r
->ctr
.ctr1
.source_dsa_obj_guid
,
48 &reps
[i
].ctr
.ctr1
.source_dsa_obj_guid
) == 0) {
56 make sure we only add repsFrom entries for DCs who are masters for
59 static bool check_MasterNC(struct kccsrv_partition
*p
, struct repsFromToBlob
*r
,
60 struct ldb_result
*res
)
62 struct repsFromTo1
*r1
;
64 struct GUID invocation_id
= r1
->source_dsa_invocation_id
;
67 for (i
=0; i
<res
->count
; i
++) {
68 struct ldb_message
*msg
= res
->msgs
[i
];
69 struct ldb_message_element
*el
;
72 struct GUID id2
= samdb_result_guid(msg
, "invocationID");
73 if (!GUID_equal(&invocation_id
, &id2
)) {
77 el
= ldb_msg_find_element(msg
, "hasMasterNCs");
78 if (!el
|| el
->num_values
== 0) {
81 for (j
=0; j
<el
->num_values
; j
++) {
82 dn
= ldb_dn_from_ldb_val(p
, p
->service
->samdb
, &el
->values
[j
]);
83 if (!ldb_dn_validate(dn
)) {
87 if (ldb_dn_compare(dn
, p
->dn
) == 0) {
99 * add any missing repsFrom structures to our partitions
101 static NTSTATUS
kccsrv_add_repsFrom(struct kccsrv_service
*s
, TALLOC_CTX
*mem_ctx
,
102 struct repsFromToBlob
*reps
, uint32_t count
,
103 struct ldb_result
*res
)
105 struct kccsrv_partition
*p
;
107 /* update the repsFrom on all partitions */
108 for (p
=s
->partitions
; p
; p
=p
->next
) {
109 struct repsFromToBlob
*old_reps
, *reps_to
;
110 uint32_t old_count
, to_count
;
113 bool modified
= false;
115 werr
= dsdb_loadreps(s
->samdb
, mem_ctx
, p
->dn
, "repsFrom", &old_reps
, &old_count
);
116 if (!W_ERROR_IS_OK(werr
)) {
117 DEBUG(0,(__location__
": Failed to load repsFrom from %s - %s\n",
118 ldb_dn_get_linearized(p
->dn
), ldb_errstring(s
->samdb
)));
119 return NT_STATUS_INTERNAL_DB_CORRUPTION
;
122 /* add any new ones */
123 for (i
=0; i
<count
; i
++) {
124 if (!reps_in_list(&reps
[i
], old_reps
, old_count
) &&
125 check_MasterNC(p
, &reps
[i
], res
)) {
126 old_reps
= talloc_realloc(mem_ctx
, old_reps
, struct repsFromToBlob
, old_count
+1);
127 NT_STATUS_HAVE_NO_MEMORY(old_reps
);
128 old_reps
[old_count
] = reps
[i
];
134 /* remove any stale ones */
135 for (i
=0; i
<old_count
; i
++) {
136 if (!reps_in_list(&old_reps
[i
], reps
, count
) ||
137 !check_MasterNC(p
, &old_reps
[i
], res
)) {
138 memmove(&old_reps
[i
], &old_reps
[i
+1], (old_count
-(i
+1))*sizeof(old_reps
[0]));
146 werr
= dsdb_savereps(s
->samdb
, mem_ctx
, p
->dn
, "repsFrom", old_reps
, old_count
);
147 if (!W_ERROR_IS_OK(werr
)) {
148 DEBUG(0,(__location__
": Failed to save repsFrom to %s - %s\n",
149 ldb_dn_get_linearized(p
->dn
), ldb_errstring(s
->samdb
)));
150 return NT_STATUS_INTERNAL_DB_CORRUPTION
;
154 werr
= dsdb_loadreps(s
->samdb
, mem_ctx
, p
->dn
, "repsTo", &reps_to
, &to_count
);
155 if (!W_ERROR_IS_OK(werr
)) {
156 DEBUG(0,(__location__
": Failed to load repsTo from %s - %s\n",
157 ldb_dn_get_linearized(p
->dn
), ldb_errstring(s
->samdb
)));
158 return NT_STATUS_INTERNAL_DB_CORRUPTION
;
162 /* add any new ones */
163 for (i
=0; i
<old_count
; i
++) {
164 if (!reps_in_list(&old_reps
[i
], reps_to
, to_count
)) {
165 reps_to
= talloc_realloc(mem_ctx
, reps_to
, struct repsFromToBlob
, to_count
+1);
166 NT_STATUS_HAVE_NO_MEMORY(reps_to
);
167 reps_to
[to_count
] = old_reps
[i
];
174 werr
= dsdb_savereps(s
->samdb
, mem_ctx
, p
->dn
, "repsTo", reps_to
, to_count
);
175 if (!W_ERROR_IS_OK(werr
)) {
176 DEBUG(0,(__location__
": Failed to save repsTo to %s - %s\n",
177 ldb_dn_get_linearized(p
->dn
), ldb_errstring(s
->samdb
)));
178 return NT_STATUS_INTERNAL_DB_CORRUPTION
;
188 this is the core of our initial simple KCC
189 We just add a repsFrom entry for all DCs we find that have nTDSDSA
190 objects, except for ourselves
192 NTSTATUS
kccsrv_simple_update(struct kccsrv_service
*s
, TALLOC_CTX
*mem_ctx
)
194 struct ldb_result
*res
;
197 const char *attrs
[] = { "objectGUID", "invocationID", "hasMasterNCs", NULL
};
198 struct repsFromToBlob
*reps
= NULL
;
200 struct kcc_connection_list
*ntds_conn
, *dsa_conn
;
202 ret
= ldb_search(s
->samdb
, mem_ctx
, &res
, s
->config_dn
, LDB_SCOPE_SUBTREE
,
203 attrs
, "objectClass=nTDSDSA");
204 if (ret
!= LDB_SUCCESS
) {
205 DEBUG(0,(__location__
": Failed nTDSDSA search - %s\n", ldb_errstring(s
->samdb
)));
206 return NT_STATUS_INTERNAL_DB_CORRUPTION
;
209 /* get the current list of connections */
210 ntds_conn
= kccsrv_find_connections(s
, mem_ctx
);
212 dsa_conn
= talloc_zero(mem_ctx
, struct kcc_connection_list
);
214 for (i
=0; i
<res
->count
; i
++) {
215 struct repsFromTo1
*r1
;
216 struct GUID ntds_guid
, invocation_id
;
218 ntds_guid
= samdb_result_guid(res
->msgs
[i
], "objectGUID");
219 if (GUID_compare(&ntds_guid
, &s
->ntds_guid
) == 0) {
220 /* don't replicate with ourselves */
224 invocation_id
= samdb_result_guid(res
->msgs
[i
], "invocationID");
226 reps
= talloc_realloc(mem_ctx
, reps
, struct repsFromToBlob
, count
+1);
227 NT_STATUS_HAVE_NO_MEMORY(reps
);
229 ZERO_STRUCT(reps
[count
]);
230 reps
[count
].version
= 1;
231 r1
= &reps
[count
].ctr
.ctr1
;
233 r1
->other_info
= talloc_zero(reps
, struct repsFromTo1OtherInfo
);
234 r1
->other_info
->dns_name
= talloc_asprintf(r1
->other_info
, "%s._msdcs.%s",
235 GUID_string(mem_ctx
, &ntds_guid
),
236 lp_dnsdomain(s
->task
->lp_ctx
));
237 r1
->source_dsa_obj_guid
= ntds_guid
;
238 r1
->source_dsa_invocation_id
= invocation_id
;
240 DRSUAPI_DRS_WRIT_REP
|
241 DRSUAPI_DRS_INIT_SYNC
|
242 DRSUAPI_DRS_PER_SYNC
;
243 memset(r1
->schedule
, 0x11, sizeof(r1
->schedule
));
245 dsa_conn
->servers
= talloc_realloc(dsa_conn
, dsa_conn
->servers
,
246 struct kcc_connection
,
247 dsa_conn
->count
+ 1);
248 NT_STATUS_HAVE_NO_MEMORY(dsa_conn
->servers
);
249 dsa_conn
->servers
[dsa_conn
->count
].dsa_guid
= r1
->source_dsa_obj_guid
;
255 kccsrv_apply_connections(s
, ntds_conn
, dsa_conn
);
257 return kccsrv_add_repsFrom(s
, mem_ctx
, reps
, count
, res
);
261 static void kccsrv_periodic_run(struct kccsrv_service
*service
);
263 static void kccsrv_periodic_handler_te(struct tevent_context
*ev
, struct tevent_timer
*te
,
264 struct timeval t
, void *ptr
)
266 struct kccsrv_service
*service
= talloc_get_type(ptr
, struct kccsrv_service
);
269 service
->periodic
.te
= NULL
;
271 kccsrv_periodic_run(service
);
273 status
= kccsrv_periodic_schedule(service
, service
->periodic
.interval
);
274 if (!W_ERROR_IS_OK(status
)) {
275 task_server_terminate(service
->task
, win_errstr(status
), true);
280 WERROR
kccsrv_periodic_schedule(struct kccsrv_service
*service
, uint32_t next_interval
)
283 struct tevent_timer
*new_te
;
284 struct timeval next_time
;
286 /* prevent looping */
287 if (next_interval
== 0) next_interval
= 1;
289 next_time
= timeval_current_ofs(next_interval
, 50);
291 if (service
->periodic
.te
) {
293 * if the timestamp of the new event is higher,
294 * as current next we don't need to reschedule
296 if (timeval_compare(&next_time
, &service
->periodic
.next_event
) > 0) {
301 /* reset the next scheduled timestamp */
302 service
->periodic
.next_event
= next_time
;
304 new_te
= event_add_timed(service
->task
->event_ctx
, service
,
305 service
->periodic
.next_event
,
306 kccsrv_periodic_handler_te
, service
);
307 W_ERROR_HAVE_NO_MEMORY(new_te
);
309 tmp_mem
= talloc_new(service
);
310 DEBUG(2,("kccsrv_periodic_schedule(%u) %sscheduled for: %s\n",
312 (service
->periodic
.te
?"re":""),
313 nt_time_string(tmp_mem
, timeval_to_nttime(&next_time
))));
314 talloc_free(tmp_mem
);
316 talloc_free(service
->periodic
.te
);
317 service
->periodic
.te
= new_te
;
322 static void kccsrv_periodic_run(struct kccsrv_service
*service
)
327 DEBUG(2,("kccsrv_periodic_run(): simple update\n"));
329 mem_ctx
= talloc_new(service
);
330 status
= kccsrv_simple_update(service
, mem_ctx
);
331 if (!NT_STATUS_IS_OK(status
)) {
332 DEBUG(0,("kccsrv_simple_update failed - %s\n", nt_errstr(status
)));
335 status
= kccsrv_check_deleted(service
, mem_ctx
);
336 if (!NT_STATUS_IS_OK(status
)) {
337 DEBUG(0,("kccsrv_check_deleted failed - %s\n", nt_errstr(status
)));
339 talloc_free(mem_ctx
);