Blame idmapwb.c

Packit 5f9837
/*
Packit 5f9837
 * Winbind ID Mapping Plugin
Packit 5f9837
 * Copyright (C) 2012 Jeff Layton (jlayton@samba.org)
Packit 5f9837
 *
Packit 5f9837
 * This program is free software; you can redistribute it and/or modify
Packit 5f9837
 * it under the terms of the GNU General Public License as published by
Packit 5f9837
 * the Free Software Foundation; either version 3 of the License, or
Packit 5f9837
 * (at your option) any later version.
Packit 5f9837
 *
Packit 5f9837
 * This program is distributed in the hope that it will be useful,
Packit 5f9837
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit 5f9837
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
Packit 5f9837
 * GNU General Public License for more details.
Packit 5f9837
 *
Packit 5f9837
 * You should have received a copy of the GNU General Public License
Packit 5f9837
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
Packit 5f9837
 */
Packit 5f9837
Packit 5f9837
#ifdef HAVE_CONFIG_H
Packit 5f9837
#include "config.h"
Packit 5f9837
#endif /* HAVE_CONFIG_H */
Packit 5f9837
Packit 5f9837
#include <stdint.h>
Packit 5f9837
#include <endian.h>
Packit 5f9837
#include <string.h>
Packit 5f9837
#include <errno.h>
Packit 5f9837
#include <stdbool.h>
Packit 5f9837
#include <stdio.h>
Packit 5f9837
#include <stdlib.h>
Packit 5f9837
#include <wbclient.h>
Packit 5f9837
#include <limits.h>
Packit 5f9837
Packit 5f9837
#include "cifsidmap.h"
Packit 5f9837
Packit 5f9837
static const char **plugin_errmsg;
Packit 5f9837
Packit 5f9837
/*
Packit 5f9837
 * Winbind keeps wbcDomainSid fields in host-endian. Copy fields from the
Packit 5f9837
 * csid to the wsid, while converting the subauthority fields from LE.
Packit 5f9837
 */
Packit 5f9837
static void
Packit 5f9837
csid_to_wsid(struct wbcDomainSid *wsid, const struct cifs_sid *csid)
Packit 5f9837
{
Packit 5f9837
	int i;
Packit 5f9837
	uint8_t num_subauth = (csid->num_subauth <= WBC_MAXSUBAUTHS) ?
Packit 5f9837
				csid->num_subauth : WBC_MAXSUBAUTHS;
Packit 5f9837
Packit 5f9837
	wsid->sid_rev_num = csid->revision;
Packit 5f9837
	wsid->num_auths = num_subauth;
Packit 5f9837
	for (i = 0; i < NUM_AUTHS; i++)
Packit 5f9837
		wsid->id_auth[i] = csid->authority[i];
Packit 5f9837
	for (i = 0; i < num_subauth; i++)
Packit 5f9837
		wsid->sub_auths[i] = le32toh(csid->sub_auth[i]);
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
/*
Packit 5f9837
 * Winbind keeps wbcDomainSid fields in host-endian. Copy fields from the
Packit 5f9837
 * wsid to the csid, while converting the subauthority fields to LE.
Packit 5f9837
 */
Packit 5f9837
static void
Packit 5f9837
wsid_to_csid(struct cifs_sid *csid, struct wbcDomainSid *wsid)
Packit 5f9837
{
Packit 5f9837
	int i;
Packit 5f9837
	uint8_t num_subauth = (wsid->num_auths <= SID_MAX_SUB_AUTHORITIES) ?
Packit 5f9837
				wsid->num_auths : SID_MAX_SUB_AUTHORITIES;
Packit 5f9837
Packit 5f9837
	csid->revision = wsid->sid_rev_num;
Packit 5f9837
	csid->num_subauth = num_subauth;
Packit 5f9837
	for (i = 0; i < NUM_AUTHS; i++)
Packit 5f9837
		csid->authority[i] = wsid->id_auth[i];
Packit 5f9837
	for (i = 0; i < num_subauth; i++)
Packit 5f9837
		csid->sub_auth[i] = htole32(wsid->sub_auths[i]);
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
int
Packit 5f9837
cifs_idmap_sid_to_str(void *handle __attribute__ ((unused)),
Packit 5f9837
			const struct cifs_sid *csid, char **string)
Packit 5f9837
{
Packit 5f9837
	int rc;
Packit 5f9837
	wbcErr wbcrc;
Packit 5f9837
	char *domain = NULL;
Packit 5f9837
	char *name = NULL;
Packit 5f9837
	enum wbcSidType sntype;
Packit 5f9837
	struct wbcDomainSid wsid;
Packit 5f9837
	size_t len;
Packit 5f9837
Packit 5f9837
	csid_to_wsid(&wsid, csid);
Packit 5f9837
Packit 5f9837
	wbcrc = wbcLookupSid(&wsid, &domain, &name, &sntype);
Packit 5f9837
	if (!WBC_ERROR_IS_OK(wbcrc)) {
Packit 5f9837
		*plugin_errmsg = wbcErrorString(wbcrc);
Packit 5f9837
		return -EIO;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	/* +1 for '\\' and +1 for NULL terminator */
Packit 5f9837
	len = strlen(domain) + 1 + strlen(name) + 1;
Packit 5f9837
Packit 5f9837
	*string = malloc(len);
Packit 5f9837
	if (!*string) {
Packit 5f9837
		*plugin_errmsg = "Unable to allocate memory";
Packit 5f9837
		rc = -ENOMEM;
Packit 5f9837
		goto out;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	rc = snprintf(*string, len, "%s\\%s", domain, name);
Packit 5f9837
	if (rc >= (long)len) {
Packit 5f9837
		free(*string);
Packit 5f9837
		*plugin_errmsg = "Resulting string was truncated";
Packit 5f9837
		*string = NULL;
Packit 5f9837
		rc = -EIO;
Packit 5f9837
	} else {
Packit 5f9837
		rc = 0;
Packit 5f9837
	}
Packit 5f9837
out:
Packit 5f9837
	wbcFreeMemory(domain);
Packit 5f9837
	wbcFreeMemory(name);
Packit 5f9837
	return rc;
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
int
Packit 5f9837
cifs_idmap_str_to_sid(void *handle __attribute__ ((unused)),
Packit 5f9837
			const char *orig, struct cifs_sid *csid)
Packit 5f9837
{
Packit 5f9837
	wbcErr wbcrc;
Packit 5f9837
	char *name, *domain, *sidstr;
Packit 5f9837
	enum wbcSidType type;
Packit 5f9837
	struct wbcDomainSid wsid;
Packit 5f9837
Packit 5f9837
	sidstr = strdup(orig);
Packit 5f9837
	if (!sidstr) {
Packit 5f9837
		*plugin_errmsg = "Unable to copy string";
Packit 5f9837
		return -ENOMEM;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	name = strchr(sidstr, '\\');
Packit 5f9837
	if (!name) {
Packit 5f9837
		/* might be a raw string representation of SID */
Packit 5f9837
		wbcrc = wbcStringToSid(sidstr, &wsid);
Packit 5f9837
		if (WBC_ERROR_IS_OK(wbcrc))
Packit 5f9837
			goto convert_sid;
Packit 5f9837
Packit 5f9837
		domain = "";
Packit 5f9837
		name = sidstr;
Packit 5f9837
	} else {
Packit 5f9837
		domain = sidstr;
Packit 5f9837
		*name = '\0';
Packit 5f9837
		++name;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	wbcrc = wbcLookupName(domain, name, &wsid, &type);
Packit 5f9837
	/* FIXME: map these to better POSIX error codes? */
Packit 5f9837
	if (!WBC_ERROR_IS_OK(wbcrc)) {
Packit 5f9837
		*plugin_errmsg = wbcErrorString(wbcrc);
Packit 5f9837
		free(sidstr);
Packit 5f9837
		return -EIO;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
convert_sid:
Packit 5f9837
	wsid_to_csid(csid, &wsid);
Packit 5f9837
	free(sidstr);
Packit 5f9837
	return 0;
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
static void
Packit 5f9837
wuxid_to_cuxid(struct cifs_uxid *cuxid, const struct wbcUnixId *wuxid)
Packit 5f9837
{
Packit 5f9837
	switch(wuxid->type) {
Packit 5f9837
	case WBC_ID_TYPE_UID:
Packit 5f9837
		cuxid->id.uid = wuxid->id.uid;
Packit 5f9837
		cuxid->type = CIFS_UXID_TYPE_UID;
Packit 5f9837
		break;
Packit 5f9837
	case WBC_ID_TYPE_GID:
Packit 5f9837
		cuxid->id.gid = wuxid->id.gid;
Packit 5f9837
		cuxid->type = CIFS_UXID_TYPE_GID;
Packit 5f9837
		break;
Packit 5f9837
#ifdef HAVE_WBC_ID_TYPE_BOTH
Packit 5f9837
	case WBC_ID_TYPE_BOTH:
Packit 5f9837
		cuxid->id.uid = wuxid->id.uid;
Packit 5f9837
		cuxid->type = CIFS_UXID_TYPE_BOTH;
Packit 5f9837
		break;
Packit 5f9837
#endif /* HAVE_WBC_ID_TYPE_BOTH */
Packit 5f9837
	default:
Packit 5f9837
		cuxid->type = CIFS_UXID_TYPE_UNKNOWN;
Packit 5f9837
	}
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
int
Packit 5f9837
cifs_idmap_sids_to_ids(void *handle __attribute__((unused)),
Packit 5f9837
			const struct cifs_sid *csid, size_t num,
Packit 5f9837
			struct cifs_uxid *cuxid)
Packit 5f9837
{
Packit 5f9837
	int ret;
Packit 5f9837
	unsigned int i;
Packit 5f9837
	wbcErr wbcret;
Packit 5f9837
	struct wbcDomainSid *wsid;
Packit 5f9837
	struct wbcUnixId *wuxid;
Packit 5f9837
Packit 5f9837
	if (num > UINT_MAX) {
Packit 5f9837
		*plugin_errmsg = "num is too large.";
Packit 5f9837
		return -EINVAL;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	wsid = calloc(num, sizeof(*wsid));
Packit 5f9837
	if (!wsid) {
Packit 5f9837
		*plugin_errmsg = "Unable to allocate memory.";
Packit 5f9837
		return -ENOMEM;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	wuxid = calloc(num, sizeof(*wuxid));
Packit 5f9837
	if (!wuxid) {
Packit 5f9837
		*plugin_errmsg = "Unable to allocate memory.";
Packit 5f9837
		ret = -ENOMEM;
Packit 5f9837
		goto out;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	for (i = 0; i < num; ++i)
Packit 5f9837
		csid_to_wsid(&wsid[i], &csid[i]);
Packit 5f9837
Packit 5f9837
	/*
Packit 5f9837
	 * Winbind does not set an error message in the event that some
Packit 5f9837
	 * mappings fail. So, we preemptively do it here, just in case.
Packit 5f9837
	 */
Packit 5f9837
	*plugin_errmsg = "Some IDs could not be mapped.";
Packit 5f9837
Packit 5f9837
	wbcret = wbcSidsToUnixIds(wsid, num, wuxid);
Packit 5f9837
	if (!WBC_ERROR_IS_OK(wbcret)) {
Packit 5f9837
		*plugin_errmsg = wbcErrorString(wbcret);
Packit 5f9837
		ret = -EIO;
Packit 5f9837
		goto out;
Packit 5f9837
	}
Packit 5f9837
Packit 5f9837
	ret = 0;
Packit 5f9837
	for (i = 0; i < num; ++i)
Packit 5f9837
		wuxid_to_cuxid(&cuxid[i], &wuxid[i]);
Packit 5f9837
out:
Packit 5f9837
	free(wuxid);
Packit 5f9837
	free(wsid);
Packit 5f9837
	return ret;
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
int
Packit 5f9837
cifs_idmap_ids_to_sids(void *handle __attribute__((unused)),
Packit 5f9837
			const struct cifs_uxid *cuxid, size_t num,
Packit 5f9837
			struct cifs_sid *csid)
Packit 5f9837
{
Packit 5f9837
	int ret = -EIO;
Packit 5f9837
	wbcErr wbcrc;
Packit 5f9837
	size_t i;
Packit 5f9837
	struct wbcDomainSid wsid;
Packit 5f9837
Packit 5f9837
	for (i = 0; i < num; ++i) {
Packit 5f9837
		switch(cuxid[i].type) {
Packit 5f9837
		case CIFS_UXID_TYPE_UID:
Packit 5f9837
			wbcrc = wbcUidToSid(cuxid[i].id.uid, &wsid);
Packit 5f9837
			break;
Packit 5f9837
		case CIFS_UXID_TYPE_GID:
Packit 5f9837
			wbcrc = wbcGidToSid(cuxid[i].id.gid, &wsid);
Packit 5f9837
			break;
Packit 5f9837
		case CIFS_UXID_TYPE_BOTH:
Packit 5f9837
			/*
Packit 5f9837
			 * In the BOTH case, prefer a user type first and fall
Packit 5f9837
			 * back to a group if that doesn't map.
Packit 5f9837
			 */
Packit 5f9837
			wbcrc = wbcUidToSid(cuxid[i].id.uid, &wsid);
Packit 5f9837
			if (WBC_ERROR_IS_OK(wbcrc))
Packit 5f9837
				break;
Packit 5f9837
			wbcrc = wbcGidToSid(cuxid[i].id.gid, &wsid);
Packit 5f9837
			break;
Packit 5f9837
		default:
Packit 5f9837
			csid[i].revision = 0;
Packit 5f9837
			*plugin_errmsg = "Invalid CIFS_UXID_TYPE value";
Packit 5f9837
			continue;
Packit 5f9837
		}
Packit 5f9837
Packit 5f9837
		if (WBC_ERROR_IS_OK(wbcrc)) {
Packit 5f9837
			ret = 0;
Packit 5f9837
			wsid_to_csid(&csid[i], &wsid);
Packit 5f9837
		} else {
Packit 5f9837
			csid[i].revision = 0;
Packit 5f9837
			*plugin_errmsg = wbcErrorString(wbcrc);
Packit 5f9837
		}
Packit 5f9837
	}
Packit 5f9837
	return ret;
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
/*
Packit 5f9837
 * For the winbind plugin, we don't need to do anything special on
Packit 5f9837
 * init or exit
Packit 5f9837
 */
Packit 5f9837
int
Packit 5f9837
cifs_idmap_init_plugin(void **handle __attribute__((unused)), const char **errmsg)
Packit 5f9837
{
Packit 5f9837
	plugin_errmsg = errmsg;
Packit 5f9837
	return 0;
Packit 5f9837
}
Packit 5f9837
Packit 5f9837
void
Packit 5f9837
cifs_idmap_exit_plugin(void *handle __attribute__((unused)))
Packit 5f9837
{
Packit 5f9837
	return;
Packit 5f9837
}