2 Unix SMB/CIFS implementation.
4 Winbind daemon for ntdom nss module
6 Copyright (C) by Tim Potter 2000-2002
7 Copyright (C) Andrew Tridgell 2002
8 Copyright (C) Jelmer Vernooij 2003
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License as published by
12 the Free Software Foundation; either version 2 of the License, or
13 (at your option) any later version.
15 This program is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 GNU General Public License for more details.
20 You should have received a copy of the GNU General Public License
21 along with this program; if not, write to the Free Software
22 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
27 BOOL opt_nocache
= False
;
28 BOOL opt_dual_daemon
= False
;
30 /* Reload configuration */
32 static BOOL
reload_services_file(BOOL test
)
39 pstrcpy(fname
,lp_configfile());
40 if (file_exist(fname
,NULL
) && !strcsequal(fname
,dyn_CONFIGFILE
)) {
41 pstrcpy(dyn_CONFIGFILE
,fname
);
47 ret
= lp_load(dyn_CONFIGFILE
,False
,False
,True
);
57 /**************************************************************************** **
58 Prepare to dump a core file - carefully!
59 **************************************************************************** */
61 static BOOL
dump_core(void)
65 pstrcpy( dname
, lp_logfile() );
66 if ((p
=strrchr(dname
,'/')))
68 pstrcat( dname
, "/corefiles" );
70 sys_chown( dname
, getuid(), getgid() );
80 getrlimit( RLIMIT_CORE
, &rlp
);
81 rlp
.rlim_cur
= MAX( 4*1024*1024, rlp
.rlim_cur
);
82 setrlimit( RLIMIT_CORE
, &rlp
);
83 getrlimit( RLIMIT_CORE
, &rlp
);
84 DEBUG( 3, ( "Core limits now %d %d\n", (int)rlp
.rlim_cur
, (int)rlp
.rlim_max
) );
89 DEBUG(0,("Dumping core in %s\n",dname
));
95 /**************************************************************************** **
97 **************************************************************************** */
99 static void fault_quit(void)
106 static void winbindd_status(void)
108 struct winbindd_cli_state
*tmp
;
110 DEBUG(0, ("winbindd status:\n"));
112 /* Print client state information */
114 DEBUG(0, ("\t%d clients currently active\n", winbindd_num_clients()));
116 if (DEBUGLEVEL
>= 2 && winbindd_num_clients()) {
117 DEBUG(2, ("\tclient list:\n"));
118 for(tmp
= winbindd_client_list(); tmp
; tmp
= tmp
->next
) {
119 DEBUG(2, ("\t\tpid %d, sock %d, rbl %d, wbl %d\n",
120 tmp
->pid
, tmp
->sock
, tmp
->read_buf_len
,
121 tmp
->write_buf_len
));
126 /* Print winbindd status to log file */
128 static void print_winbindd_status(void)
131 winbindd_cm_status();
134 /* Flush client cache */
136 static void flush_caches(void)
138 /* Clear cached user and group enumation info */
139 wcache_flush_cache();
142 /* Handle the signal by unlinking socket and exiting */
144 static void terminate(void)
150 /* Remove socket file */
151 snprintf(path
, sizeof(path
), "%s/%s",
152 WINBINDD_SOCKET_DIR
, WINBINDD_SOCKET_NAME
);
157 static BOOL do_sigterm
;
159 static void termination_handler(int signum
)
165 static BOOL do_sigusr2
;
167 static void sigusr2_handler(int signum
)
173 static BOOL do_sighup
;
175 static void sighup_handler(int signum
)
181 struct dispatch_table
{
182 enum winbindd_cmd cmd
;
183 enum winbindd_result (*fn
)(struct winbindd_cli_state
*state
);
184 const char *winbindd_cmd_name
;
187 static struct dispatch_table dispatch_table
[] = {
191 { WINBINDD_GETPWNAM
, winbindd_getpwnam
, "GETPWNAM" },
192 { WINBINDD_GETPWUID
, winbindd_getpwuid
, "GETPWUID" },
194 { WINBINDD_SETPWENT
, winbindd_setpwent
, "SETPWENT" },
195 { WINBINDD_ENDPWENT
, winbindd_endpwent
, "ENDPWENT" },
196 { WINBINDD_GETPWENT
, winbindd_getpwent
, "GETPWENT" },
198 { WINBINDD_GETGROUPS
, winbindd_getgroups
, "GETGROUPS" },
200 /* Group functions */
202 { WINBINDD_GETGRNAM
, winbindd_getgrnam
, "GETGRNAM" },
203 { WINBINDD_GETGRGID
, winbindd_getgrgid
, "GETGRGID" },
204 { WINBINDD_SETGRENT
, winbindd_setgrent
, "SETGRENT" },
205 { WINBINDD_ENDGRENT
, winbindd_endgrent
, "ENDGRENT" },
206 { WINBINDD_GETGRENT
, winbindd_getgrent
, "GETGRENT" },
207 { WINBINDD_GETGRLST
, winbindd_getgrent
, "GETGRLST" },
209 /* PAM auth functions */
211 { WINBINDD_PAM_AUTH
, winbindd_pam_auth
, "PAM_AUTH" },
212 { WINBINDD_PAM_AUTH_CRAP
, winbindd_pam_auth_crap
, "AUTH_CRAP" },
213 { WINBINDD_PAM_CHAUTHTOK
, winbindd_pam_chauthtok
, "CHAUTHTOK" },
215 /* Enumeration functions */
217 { WINBINDD_LIST_USERS
, winbindd_list_users
, "LIST_USERS" },
218 { WINBINDD_LIST_GROUPS
, winbindd_list_groups
, "LIST_GROUPS" },
219 { WINBINDD_LIST_TRUSTDOM
, winbindd_list_trusted_domains
, "LIST_TRUSTDOM" },
220 { WINBINDD_SHOW_SEQUENCE
, winbindd_show_sequence
, "SHOW_SEQUENCE" },
222 /* SID related functions */
224 { WINBINDD_LOOKUPSID
, winbindd_lookupsid
, "LOOKUPSID" },
225 { WINBINDD_LOOKUPNAME
, winbindd_lookupname
, "LOOKUPNAME" },
227 /* Lookup related functions */
229 { WINBINDD_SID_TO_UID
, winbindd_sid_to_uid
, "SID_TO_UID" },
230 { WINBINDD_SID_TO_GID
, winbindd_sid_to_gid
, "SID_TO_GID" },
231 { WINBINDD_GID_TO_SID
, winbindd_gid_to_sid
, "GID_TO_SID" },
232 { WINBINDD_UID_TO_SID
, winbindd_uid_to_sid
, "UID_TO_SID" },
236 { WINBINDD_CHECK_MACHACC
, winbindd_check_machine_acct
, "CHECK_MACHACC" },
237 { WINBINDD_PING
, winbindd_ping
, "PING" },
238 { WINBINDD_INFO
, winbindd_info
, "INFO" },
239 { WINBINDD_INTERFACE_VERSION
, winbindd_interface_version
, "INTERFACE_VERSION" },
240 { WINBINDD_DOMAIN_NAME
, winbindd_domain_name
, "DOMAIN_NAME" },
241 { WINBINDD_NETBIOS_NAME
, winbindd_netbios_name
, "NETBIOS_NAME" },
242 { WINBINDD_PRIV_PIPE_DIR
, winbindd_priv_pipe_dir
, "WINBINDD_PRIV_PIPE_DIR" },
246 { WINBINDD_WINS_BYNAME
, winbindd_wins_byname
, "WINS_BYNAME" },
247 { WINBINDD_WINS_BYIP
, winbindd_wins_byip
, "WINS_BYIP" },
251 { WINBINDD_NUM_CMDS
, NULL
, "NONE" }
254 static void process_request(struct winbindd_cli_state
*state
)
256 struct dispatch_table
*table
= dispatch_table
;
258 /* Free response data - we may be interrupted and receive another
259 command before being able to send this data off. */
261 SAFE_FREE(state
->response
.extra_data
);
263 ZERO_STRUCT(state
->response
);
265 state
->response
.result
= WINBINDD_ERROR
;
266 state
->response
.length
= sizeof(struct winbindd_response
);
268 /* Process command */
270 for (table
= dispatch_table
; table
->fn
; table
++) {
271 if (state
->request
.cmd
== table
->cmd
) {
272 DEBUG(10,("process_request: request fn %s\n", table
->winbindd_cmd_name
));
273 state
->response
.result
= table
->fn(state
);
279 DEBUG(10,("process_request: unknown request fn number %d\n", (int)state
->request
.cmd
));
281 /* In case extra data pointer is NULL */
283 if (!state
->response
.extra_data
)
284 state
->response
.length
= sizeof(struct winbindd_response
);
287 /* Process a new connection by adding it to the client connection list */
289 static void new_connection(int listen_sock
, BOOL privileged
)
291 struct sockaddr_un sunaddr
;
292 struct winbindd_cli_state
*state
;
296 /* Accept connection */
298 len
= sizeof(sunaddr
);
301 sock
= accept(listen_sock
, (struct sockaddr
*)&sunaddr
, &len
);
302 } while (sock
== -1 && errno
== EINTR
);
307 DEBUG(6,("accepted socket %d\n", sock
));
309 /* Create new connection structure */
311 if ((state
= (struct winbindd_cli_state
*)
312 malloc(sizeof(*state
))) == NULL
)
318 state
->last_access
= time(NULL
);
320 state
->privileged
= privileged
;
322 /* Add to connection list */
324 winbindd_add_client(state
);
327 /* Remove a client connection from client connection list */
329 static void remove_client(struct winbindd_cli_state
*state
)
331 /* It's a dead client - hold a funeral */
339 /* Free any getent state */
341 free_getent_state(state
->getpwent_state
);
342 free_getent_state(state
->getgrent_state
);
344 /* We may have some extra data that was not freed if the
345 client was killed unexpectedly */
347 SAFE_FREE(state
->response
.extra_data
);
349 /* Remove from list and free */
351 winbindd_remove_client(state
);
357 /* Shutdown client connection which has been idle for the longest time */
359 static BOOL
remove_idle_client(void)
361 struct winbindd_cli_state
*state
, *remove_state
= NULL
;
362 time_t last_access
= 0;
365 for (state
= winbindd_client_list(); state
; state
= state
->next
) {
366 if (state
->read_buf_len
== 0 && state
->write_buf_len
== 0 &&
367 !state
->getpwent_state
&& !state
->getgrent_state
) {
369 if (!last_access
|| state
->last_access
< last_access
) {
370 last_access
= state
->last_access
;
371 remove_state
= state
;
377 DEBUG(5,("Found %d idle client connections, shutting down sock %d, pid %u\n",
378 nidle
, remove_state
->sock
, (unsigned int)remove_state
->pid
));
379 remove_client(remove_state
);
386 /* Process a complete received packet from a client */
388 void winbind_process_packet(struct winbindd_cli_state
*state
)
390 /* Process request */
392 /* Ensure null termination of entire request */
393 state
->request
.null_term
= '\0';
395 state
->pid
= state
->request
.pid
;
397 process_request(state
);
399 /* Update client state */
401 state
->read_buf_len
= 0;
402 state
->write_buf_len
= sizeof(struct winbindd_response
);
404 /* we might need to send it to the dual daemon */
405 if (opt_dual_daemon
) {
406 dual_send_request(state
);
410 /* Read some data from a client connection */
412 void winbind_client_read(struct winbindd_cli_state
*state
)
418 n
= sys_read(state
->sock
, state
->read_buf_len
+
419 (char *)&state
->request
,
420 sizeof(state
->request
) - state
->read_buf_len
);
422 DEBUG(10,("client_read: read %d bytes. Need %d more for a full request.\n", n
, sizeof(state
->request
) - n
- state
->read_buf_len
));
424 /* Read failed, kill client */
426 if (n
== -1 || n
== 0) {
427 DEBUG(5,("read failed on sock %d, pid %d: %s\n",
428 state
->sock
, state
->pid
,
429 (n
== -1) ? strerror(errno
) : "EOF"));
431 state
->finished
= True
;
435 /* Update client state */
437 state
->read_buf_len
+= n
;
438 state
->last_access
= time(NULL
);
441 /* Write some data to a client connection */
443 static void client_write(struct winbindd_cli_state
*state
)
448 /* Write some data */
450 if (!state
->write_extra_data
) {
452 /* Write response structure */
454 data
= (char *)&state
->response
+ sizeof(state
->response
) -
455 state
->write_buf_len
;
459 /* Write extra data */
461 data
= (char *)state
->response
.extra_data
+
462 state
->response
.length
-
463 sizeof(struct winbindd_response
) -
464 state
->write_buf_len
;
467 num_written
= sys_write(state
->sock
, data
, state
->write_buf_len
);
469 DEBUG(10,("client_write: wrote %d bytes.\n", num_written
));
471 /* Write failed, kill cilent */
473 if (num_written
== -1 || num_written
== 0) {
475 DEBUG(3,("write failed on sock %d, pid %d: %s\n",
476 state
->sock
, state
->pid
,
477 (num_written
== -1) ? strerror(errno
) : "EOF"));
479 state
->finished
= True
;
481 SAFE_FREE(state
->response
.extra_data
);
486 /* Update client state */
488 state
->write_buf_len
-= num_written
;
489 state
->last_access
= time(NULL
);
491 /* Have we written all data? */
493 if (state
->write_buf_len
== 0) {
495 /* Take care of extra data */
497 if (state
->write_extra_data
) {
499 SAFE_FREE(state
->response
.extra_data
);
501 state
->write_extra_data
= False
;
503 DEBUG(10,("client_write: client_write: complete response written.\n"));
505 } else if (state
->response
.length
>
506 sizeof(struct winbindd_response
)) {
508 /* Start writing extra data */
510 state
->write_buf_len
=
511 state
->response
.length
-
512 sizeof(struct winbindd_response
);
514 DEBUG(10,("client_write: need to write %d extra data bytes.\n", (int)state
->write_buf_len
));
516 state
->write_extra_data
= True
;
521 /* Process incoming clients on listen_sock. We use a tricky non-blocking,
522 non-forking, non-threaded model which allows us to handle many
523 simultaneous connections while remaining impervious to many denial of
526 static void process_loop(void)
528 /* We'll be doing this a lot */
531 struct winbindd_cli_state
*state
;
533 int maxfd
, listen_sock
, listen_priv_sock
, selret
;
534 struct timeval timeout
;
536 /* Handle messages */
540 /* rescan the trusted domains list. This must be done
541 regularly to cope with transitive trusts */
542 rescan_trusted_domains(False
);
544 /* Free up temporary memory */
547 main_loop_talloc_free();
549 /* Initialise fd lists for select() */
551 listen_sock
= open_winbindd_socket();
552 listen_priv_sock
= open_winbindd_priv_socket();
554 if (listen_sock
== -1 || listen_priv_sock
== -1) {
555 perror("open_winbind_socket");
559 maxfd
= MAX(listen_sock
, listen_priv_sock
);
563 FD_SET(listen_sock
, &r_fds
);
564 FD_SET(listen_priv_sock
, &r_fds
);
566 timeout
.tv_sec
= WINBINDD_ESTABLISH_LOOP
;
569 if (opt_dual_daemon
) {
570 maxfd
= dual_select_setup(&w_fds
, maxfd
);
573 /* Set up client readers and writers */
575 state
= winbindd_client_list();
579 /* Dispose of client connection if it is marked as
582 if (state
->finished
) {
583 struct winbindd_cli_state
*next
= state
->next
;
585 remove_client(state
);
590 /* Select requires we know the highest fd used */
592 if (state
->sock
> maxfd
)
595 /* Add fd for reading */
597 if (state
->read_buf_len
!= sizeof(state
->request
))
598 FD_SET(state
->sock
, &r_fds
);
600 /* Add fd for writing */
602 if (state
->write_buf_len
)
603 FD_SET(state
->sock
, &w_fds
);
610 selret
= sys_select(maxfd
+ 1, &r_fds
, &w_fds
, NULL
, &timeout
);
615 if ((selret
== -1 && errno
!= EINTR
) || selret
== 0) {
617 /* Select error, something is badly wrong */
623 /* Create a new connection if listen_sock readable */
627 if (opt_dual_daemon
) {
631 if (FD_ISSET(listen_sock
, &r_fds
)) {
632 while (winbindd_num_clients() > WINBINDD_MAX_SIMULTANEOUS_CLIENTS
- 1) {
633 DEBUG(5,("winbindd: Exceeding %d client connections, removing idle connection.\n",
634 WINBINDD_MAX_SIMULTANEOUS_CLIENTS
));
635 if (!remove_idle_client()) {
636 DEBUG(0,("winbindd: Exceeding %d client connections, no idle connection found\n",
637 WINBINDD_MAX_SIMULTANEOUS_CLIENTS
));
641 /* new, non-privileged connection */
642 new_connection(listen_sock
, False
);
645 if (FD_ISSET(listen_priv_sock
, &r_fds
)) {
646 while (winbindd_num_clients() > WINBINDD_MAX_SIMULTANEOUS_CLIENTS
- 1) {
647 DEBUG(5,("winbindd: Exceeding %d client connections, removing idle connection.\n",
648 WINBINDD_MAX_SIMULTANEOUS_CLIENTS
));
649 if (!remove_idle_client()) {
650 DEBUG(0,("winbindd: Exceeding %d client connections, no idle connection found\n",
651 WINBINDD_MAX_SIMULTANEOUS_CLIENTS
));
655 /* new, privileged connection */
656 new_connection(listen_priv_sock
, True
);
659 /* Process activity on client connections */
661 for (state
= winbindd_client_list(); state
;
662 state
= state
->next
) {
664 /* Data available for reading */
666 if (FD_ISSET(state
->sock
, &r_fds
)) {
670 winbind_client_read(state
);
673 * If we have the start of a
674 * packet, then check the
675 * length field to make sure
676 * the client's not talking
680 if (state
->read_buf_len
>= sizeof(uint32
)
681 && *(uint32
*) &state
->request
!= sizeof(state
->request
)) {
682 DEBUG(0,("process_loop: Invalid request size from pid %d: %d bytes sent, should be %d\n",
683 state
->request
.pid
, *(uint32
*) &state
->request
, sizeof(state
->request
)));
685 remove_client(state
);
689 /* A request packet might be
692 if (state
->read_buf_len
==
693 sizeof(state
->request
)) {
694 winbind_process_packet(state
);
698 /* Data available for writing */
700 if (FD_ISSET(state
->sock
, &w_fds
))
706 winbindd_check_cache_size(time(NULL
));
709 /* Check signal handling things */
716 DEBUG(3, ("got SIGHUP\n"));
718 /* Flush various caches */
721 reload_services_file(True
);
726 print_winbindd_status();
735 struct winbindd_state server_state
; /* Server state information */
737 int main(int argc
, char **argv
)
740 static BOOL interactive
= False
;
741 static BOOL Fork
= True
;
742 static BOOL log_stdout
= False
;
743 struct poptOption long_options
[] = {
745 { "stdout", 'S', POPT_ARG_VAL
, &log_stdout
, True
, "Log to stdout" },
746 { "foreground", 'F', POPT_ARG_VAL
, &Fork
, False
, "Daemon in foreground mode" },
747 { "interactive", 'i', POPT_ARG_NONE
, NULL
, 'i', "Interactive mode" },
748 { "dual-daemon", 'B', POPT_ARG_VAL
, &opt_dual_daemon
, True
, "Dual daemon mode" },
749 { "no-caching", 'n', POPT_ARG_VAL
, &opt_nocache
, False
, "Disable caching" },
756 /* glibc (?) likes to print "User defined signal 1" and exit if a
757 SIGUSR[12] is received before a handler is installed */
759 CatchSignal(SIGUSR1
, SIG_IGN
);
760 CatchSignal(SIGUSR2
, SIG_IGN
);
762 fault_setup((void (*)(void *))fault_quit
);
764 /* Initialise for running in non-root mode */
768 set_remote_machine_name("winbindd", False
);
770 /* Set environment variable so we don't recursively call ourselves.
771 This may also be useful interactively. */
773 setenv(WINBINDD_DONT_ENV
, "1", 1);
775 /* Initialise samba/rpc client stuff */
777 pc
= poptGetContext("winbindd", argc
, (const char **)argv
, long_options
,
778 POPT_CONTEXT_KEEP_FIRST
);
780 while ((opt
= poptGetNextOpt(pc
)) != -1) {
782 /* Don't become a daemon */
792 if (log_stdout
&& Fork
) {
793 printf("Can't log to stdout (-S) unless daemon is in foreground +(-F) or interactive (-i)\n");
794 poptPrintUsage(pc
, stderr
, 0);
798 snprintf(logfile
, sizeof(logfile
), "%s/log.winbindd", dyn_LOGFILEBASE
);
799 lp_set_logfile(logfile
);
800 setup_logging("winbindd", log_stdout
);
803 DEBUG(1, ("winbindd version %s started.\n", VERSION
) );
804 DEBUGADD( 1, ( "Copyright The Samba Team 2000-2003\n" ) );
806 if (!reload_services_file(False
)) {
807 DEBUG(0, ("error opening config file\n"));
818 if (!secrets_init()) {
820 DEBUG(0,("Could not initialize domain trust account secrets. Giving up\n"));
824 /* Enable netbios namecache */
828 /* Check winbindd parameters are valid */
830 ZERO_STRUCT(server_state
);
832 if (!winbindd_param_init())
835 /* Winbind daemon initialisation */
840 if (!idmap_init_wellknown_sids())
843 /* Unblock all signals we are interested in as they may have been
844 blocked by the parent process. */
846 BlockSignals(False
, SIGINT
);
847 BlockSignals(False
, SIGQUIT
);
848 BlockSignals(False
, SIGTERM
);
849 BlockSignals(False
, SIGUSR1
);
850 BlockSignals(False
, SIGUSR2
);
851 BlockSignals(False
, SIGHUP
);
853 /* Setup signal handlers */
855 CatchSignal(SIGINT
, termination_handler
); /* Exit on these sigs */
856 CatchSignal(SIGQUIT
, termination_handler
);
857 CatchSignal(SIGTERM
, termination_handler
);
859 CatchSignal(SIGPIPE
, SIG_IGN
); /* Ignore sigpipe */
861 CatchSignal(SIGUSR2
, sigusr2_handler
); /* Debugging sigs */
862 CatchSignal(SIGHUP
, sighup_handler
);
867 pidfile_create("winbindd");
871 * If we're interactive we want to set our own process group for
875 setpgid( (pid_t
)0, (pid_t
)0);
878 if (opt_dual_daemon
) {
882 /* Initialise messaging system */
884 if (!message_init()) {
885 DEBUG(0, ("unable to initialise messaging system\n"));
890 /* Loop waiting for requests */
894 trustdom_cache_shutdown();
895 uni_group_cache_shutdown();