Blame idmapwb.c

Packit Service 09cdfc
/*
Packit Service 09cdfc
 * Winbind ID Mapping Plugin
Packit Service 09cdfc
 * Copyright (C) 2012 Jeff Layton (jlayton@samba.org)
Packit Service 09cdfc
 *
Packit Service 09cdfc
 * This program is free software; you can redistribute it and/or modify
Packit Service 09cdfc
 * it under the terms of the GNU General Public License as published by
Packit Service 09cdfc
 * the Free Software Foundation; either version 3 of the License, or
Packit Service 09cdfc
 * (at your option) any later version.
Packit Service 09cdfc
 *
Packit Service 09cdfc
 * This program is distributed in the hope that it will be useful,
Packit Service 09cdfc
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit Service 09cdfc
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
Packit Service 09cdfc
 * GNU General Public License for more details.
Packit Service 09cdfc
 *
Packit Service 09cdfc
 * You should have received a copy of the GNU General Public License
Packit Service 09cdfc
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
Packit Service 09cdfc
 */
Packit Service 09cdfc
Packit Service 09cdfc
#ifdef HAVE_CONFIG_H
Packit Service 09cdfc
#include "config.h"
Packit Service 09cdfc
#endif /* HAVE_CONFIG_H */
Packit Service 09cdfc
Packit Service 09cdfc
#include <stdint.h>
Packit Service 09cdfc
#include <endian.h>
Packit Service 09cdfc
#include <string.h>
Packit Service 09cdfc
#include <errno.h>
Packit Service 09cdfc
#include <stdbool.h>
Packit Service 09cdfc
#include <stdio.h>
Packit Service 09cdfc
#include <stdlib.h>
Packit Service 09cdfc
#include <wbclient.h>
Packit Service 09cdfc
#include <limits.h>
Packit Service 09cdfc
Packit Service 09cdfc
#include "cifsidmap.h"
Packit Service 09cdfc
Packit Service 09cdfc
static const char **plugin_errmsg;
Packit Service 09cdfc
Packit Service 09cdfc
/*
Packit Service 09cdfc
 * Winbind keeps wbcDomainSid fields in host-endian. Copy fields from the
Packit Service 09cdfc
 * csid to the wsid, while converting the subauthority fields from LE.
Packit Service 09cdfc
 */
Packit Service 09cdfc
static void
Packit Service 09cdfc
csid_to_wsid(struct wbcDomainSid *wsid, const struct cifs_sid *csid)
Packit Service 09cdfc
{
Packit Service 09cdfc
	int i;
Packit Service 09cdfc
	uint8_t num_subauth = (csid->num_subauth <= WBC_MAXSUBAUTHS) ?
Packit Service 09cdfc
				csid->num_subauth : WBC_MAXSUBAUTHS;
Packit Service 09cdfc
Packit Service 09cdfc
	wsid->sid_rev_num = csid->revision;
Packit Service 09cdfc
	wsid->num_auths = num_subauth;
Packit Service 09cdfc
	for (i = 0; i < NUM_AUTHS; i++)
Packit Service 09cdfc
		wsid->id_auth[i] = csid->authority[i];
Packit Service 09cdfc
	for (i = 0; i < num_subauth; i++)
Packit Service 09cdfc
		wsid->sub_auths[i] = le32toh(csid->sub_auth[i]);
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
/*
Packit Service 09cdfc
 * Winbind keeps wbcDomainSid fields in host-endian. Copy fields from the
Packit Service 09cdfc
 * wsid to the csid, while converting the subauthority fields to LE.
Packit Service 09cdfc
 */
Packit Service 09cdfc
static void
Packit Service 09cdfc
wsid_to_csid(struct cifs_sid *csid, struct wbcDomainSid *wsid)
Packit Service 09cdfc
{
Packit Service 09cdfc
	int i;
Packit Service 09cdfc
	uint8_t num_subauth = (wsid->num_auths <= SID_MAX_SUB_AUTHORITIES) ?
Packit Service 09cdfc
				wsid->num_auths : SID_MAX_SUB_AUTHORITIES;
Packit Service 09cdfc
Packit Service 09cdfc
	csid->revision = wsid->sid_rev_num;
Packit Service 09cdfc
	csid->num_subauth = num_subauth;
Packit Service 09cdfc
	for (i = 0; i < NUM_AUTHS; i++)
Packit Service 09cdfc
		csid->authority[i] = wsid->id_auth[i];
Packit Service 09cdfc
	for (i = 0; i < num_subauth; i++)
Packit Service 09cdfc
		csid->sub_auth[i] = htole32(wsid->sub_auths[i]);
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
int
Packit Service 09cdfc
cifs_idmap_sid_to_str(void *handle __attribute__ ((unused)),
Packit Service 09cdfc
			const struct cifs_sid *csid, char **string)
Packit Service 09cdfc
{
Packit Service 09cdfc
	int rc;
Packit Service 09cdfc
	wbcErr wbcrc;
Packit Service 09cdfc
	char *domain = NULL;
Packit Service 09cdfc
	char *name = NULL;
Packit Service 09cdfc
	enum wbcSidType sntype;
Packit Service 09cdfc
	struct wbcDomainSid wsid;
Packit Service 09cdfc
	size_t len;
Packit Service 09cdfc
Packit Service 09cdfc
	csid_to_wsid(&wsid, csid);
Packit Service 09cdfc
Packit Service 09cdfc
	wbcrc = wbcLookupSid(&wsid, &domain, &name, &sntype);
Packit Service 09cdfc
	if (!WBC_ERROR_IS_OK(wbcrc)) {
Packit Service 09cdfc
		*plugin_errmsg = wbcErrorString(wbcrc);
Packit Service 09cdfc
		return -EIO;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	/* +1 for '\\' and +1 for NULL terminator */
Packit Service 09cdfc
	len = strlen(domain) + 1 + strlen(name) + 1;
Packit Service 09cdfc
Packit Service 09cdfc
	*string = malloc(len);
Packit Service 09cdfc
	if (!*string) {
Packit Service 09cdfc
		*plugin_errmsg = "Unable to allocate memory";
Packit Service 09cdfc
		rc = -ENOMEM;
Packit Service 09cdfc
		goto out;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	rc = snprintf(*string, len, "%s\\%s", domain, name);
Packit Service 09cdfc
	if (rc >= (long)len) {
Packit Service 09cdfc
		free(*string);
Packit Service 09cdfc
		*plugin_errmsg = "Resulting string was truncated";
Packit Service 09cdfc
		*string = NULL;
Packit Service 09cdfc
		rc = -EIO;
Packit Service 09cdfc
	} else {
Packit Service 09cdfc
		rc = 0;
Packit Service 09cdfc
	}
Packit Service 09cdfc
out:
Packit Service 09cdfc
	wbcFreeMemory(domain);
Packit Service 09cdfc
	wbcFreeMemory(name);
Packit Service 09cdfc
	return rc;
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
int
Packit Service 09cdfc
cifs_idmap_str_to_sid(void *handle __attribute__ ((unused)),
Packit Service 09cdfc
			const char *orig, struct cifs_sid *csid)
Packit Service 09cdfc
{
Packit Service 09cdfc
	wbcErr wbcrc;
Packit Service 09cdfc
	char *name, *domain, *sidstr;
Packit Service 09cdfc
	enum wbcSidType type;
Packit Service 09cdfc
	struct wbcDomainSid wsid;
Packit Service 09cdfc
Packit Service 09cdfc
	sidstr = strdup(orig);
Packit Service 09cdfc
	if (!sidstr) {
Packit Service 09cdfc
		*plugin_errmsg = "Unable to copy string";
Packit Service 09cdfc
		return -ENOMEM;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	name = strchr(sidstr, '\\');
Packit Service 09cdfc
	if (!name) {
Packit Service 09cdfc
		/* might be a raw string representation of SID */
Packit Service 09cdfc
		wbcrc = wbcStringToSid(sidstr, &wsid);
Packit Service 09cdfc
		if (WBC_ERROR_IS_OK(wbcrc))
Packit Service 09cdfc
			goto convert_sid;
Packit Service 09cdfc
Packit Service 09cdfc
		domain = "";
Packit Service 09cdfc
		name = sidstr;
Packit Service 09cdfc
	} else {
Packit Service 09cdfc
		domain = sidstr;
Packit Service 09cdfc
		*name = '\0';
Packit Service 09cdfc
		++name;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	wbcrc = wbcLookupName(domain, name, &wsid, &type);
Packit Service 09cdfc
	/* FIXME: map these to better POSIX error codes? */
Packit Service 09cdfc
	if (!WBC_ERROR_IS_OK(wbcrc)) {
Packit Service 09cdfc
		*plugin_errmsg = wbcErrorString(wbcrc);
Packit Service 09cdfc
		free(sidstr);
Packit Service 09cdfc
		return -EIO;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
convert_sid:
Packit Service 09cdfc
	wsid_to_csid(csid, &wsid);
Packit Service 09cdfc
	free(sidstr);
Packit Service 09cdfc
	return 0;
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
static void
Packit Service 09cdfc
wuxid_to_cuxid(struct cifs_uxid *cuxid, const struct wbcUnixId *wuxid)
Packit Service 09cdfc
{
Packit Service 09cdfc
	switch(wuxid->type) {
Packit Service 09cdfc
	case WBC_ID_TYPE_UID:
Packit Service 09cdfc
		cuxid->id.uid = wuxid->id.uid;
Packit Service 09cdfc
		cuxid->type = CIFS_UXID_TYPE_UID;
Packit Service 09cdfc
		break;
Packit Service 09cdfc
	case WBC_ID_TYPE_GID:
Packit Service 09cdfc
		cuxid->id.gid = wuxid->id.gid;
Packit Service 09cdfc
		cuxid->type = CIFS_UXID_TYPE_GID;
Packit Service 09cdfc
		break;
Packit Service 09cdfc
#ifdef HAVE_WBC_ID_TYPE_BOTH
Packit Service 09cdfc
	case WBC_ID_TYPE_BOTH:
Packit Service 09cdfc
		cuxid->id.uid = wuxid->id.uid;
Packit Service 09cdfc
		cuxid->type = CIFS_UXID_TYPE_BOTH;
Packit Service 09cdfc
		break;
Packit Service 09cdfc
#endif /* HAVE_WBC_ID_TYPE_BOTH */
Packit Service 09cdfc
	default:
Packit Service 09cdfc
		cuxid->type = CIFS_UXID_TYPE_UNKNOWN;
Packit Service 09cdfc
	}
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
int
Packit Service 09cdfc
cifs_idmap_sids_to_ids(void *handle __attribute__((unused)),
Packit Service 09cdfc
			const struct cifs_sid *csid, size_t num,
Packit Service 09cdfc
			struct cifs_uxid *cuxid)
Packit Service 09cdfc
{
Packit Service 09cdfc
	int ret;
Packit Service 09cdfc
	unsigned int i;
Packit Service 09cdfc
	wbcErr wbcret;
Packit Service 09cdfc
	struct wbcDomainSid *wsid;
Packit Service 09cdfc
	struct wbcUnixId *wuxid;
Packit Service 09cdfc
Packit Service 09cdfc
	if (num > UINT_MAX) {
Packit Service 09cdfc
		*plugin_errmsg = "num is too large.";
Packit Service 09cdfc
		return -EINVAL;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	wsid = calloc(num, sizeof(*wsid));
Packit Service 09cdfc
	if (!wsid) {
Packit Service 09cdfc
		*plugin_errmsg = "Unable to allocate memory.";
Packit Service 09cdfc
		return -ENOMEM;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	wuxid = calloc(num, sizeof(*wuxid));
Packit Service 09cdfc
	if (!wuxid) {
Packit Service 09cdfc
		*plugin_errmsg = "Unable to allocate memory.";
Packit Service 09cdfc
		ret = -ENOMEM;
Packit Service 09cdfc
		goto out;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	for (i = 0; i < num; ++i)
Packit Service 09cdfc
		csid_to_wsid(&wsid[i], &csid[i]);
Packit Service 09cdfc
Packit Service 09cdfc
	/*
Packit Service 09cdfc
	 * Winbind does not set an error message in the event that some
Packit Service 09cdfc
	 * mappings fail. So, we preemptively do it here, just in case.
Packit Service 09cdfc
	 */
Packit Service 09cdfc
	*plugin_errmsg = "Some IDs could not be mapped.";
Packit Service 09cdfc
Packit Service 09cdfc
	wbcret = wbcSidsToUnixIds(wsid, num, wuxid);
Packit Service 09cdfc
	if (!WBC_ERROR_IS_OK(wbcret)) {
Packit Service 09cdfc
		*plugin_errmsg = wbcErrorString(wbcret);
Packit Service 09cdfc
		ret = -EIO;
Packit Service 09cdfc
		goto out;
Packit Service 09cdfc
	}
Packit Service 09cdfc
Packit Service 09cdfc
	ret = 0;
Packit Service 09cdfc
	for (i = 0; i < num; ++i)
Packit Service 09cdfc
		wuxid_to_cuxid(&cuxid[i], &wuxid[i]);
Packit Service 09cdfc
out:
Packit Service 09cdfc
	free(wuxid);
Packit Service 09cdfc
	free(wsid);
Packit Service 09cdfc
	return ret;
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
int
Packit Service 09cdfc
cifs_idmap_ids_to_sids(void *handle __attribute__((unused)),
Packit Service 09cdfc
			const struct cifs_uxid *cuxid, size_t num,
Packit Service 09cdfc
			struct cifs_sid *csid)
Packit Service 09cdfc
{
Packit Service 09cdfc
	int ret = -EIO;
Packit Service 09cdfc
	wbcErr wbcrc;
Packit Service 09cdfc
	size_t i;
Packit Service 09cdfc
	struct wbcDomainSid wsid;
Packit Service 09cdfc
Packit Service 09cdfc
	for (i = 0; i < num; ++i) {
Packit Service 09cdfc
		switch(cuxid[i].type) {
Packit Service 09cdfc
		case CIFS_UXID_TYPE_UID:
Packit Service 09cdfc
			wbcrc = wbcUidToSid(cuxid[i].id.uid, &wsid);
Packit Service 09cdfc
			break;
Packit Service 09cdfc
		case CIFS_UXID_TYPE_GID:
Packit Service 09cdfc
			wbcrc = wbcGidToSid(cuxid[i].id.gid, &wsid);
Packit Service 09cdfc
			break;
Packit Service 09cdfc
		case CIFS_UXID_TYPE_BOTH:
Packit Service 09cdfc
			/*
Packit Service 09cdfc
			 * In the BOTH case, prefer a user type first and fall
Packit Service 09cdfc
			 * back to a group if that doesn't map.
Packit Service 09cdfc
			 */
Packit Service 09cdfc
			wbcrc = wbcUidToSid(cuxid[i].id.uid, &wsid);
Packit Service 09cdfc
			if (WBC_ERROR_IS_OK(wbcrc))
Packit Service 09cdfc
				break;
Packit Service 09cdfc
			wbcrc = wbcGidToSid(cuxid[i].id.gid, &wsid);
Packit Service 09cdfc
			break;
Packit Service 09cdfc
		default:
Packit Service 09cdfc
			csid[i].revision = 0;
Packit Service 09cdfc
			*plugin_errmsg = "Invalid CIFS_UXID_TYPE value";
Packit Service 09cdfc
			continue;
Packit Service 09cdfc
		}
Packit Service 09cdfc
Packit Service 09cdfc
		if (WBC_ERROR_IS_OK(wbcrc)) {
Packit Service 09cdfc
			ret = 0;
Packit Service 09cdfc
			wsid_to_csid(&csid[i], &wsid);
Packit Service 09cdfc
		} else {
Packit Service 09cdfc
			csid[i].revision = 0;
Packit Service 09cdfc
			*plugin_errmsg = wbcErrorString(wbcrc);
Packit Service 09cdfc
		}
Packit Service 09cdfc
	}
Packit Service 09cdfc
	return ret;
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
/*
Packit Service 09cdfc
 * For the winbind plugin, we don't need to do anything special on
Packit Service 09cdfc
 * init or exit
Packit Service 09cdfc
 */
Packit Service 09cdfc
int
Packit Service 09cdfc
cifs_idmap_init_plugin(void **handle __attribute__((unused)), const char **errmsg)
Packit Service 09cdfc
{
Packit Service 09cdfc
	plugin_errmsg = errmsg;
Packit Service 09cdfc
	return 0;
Packit Service 09cdfc
}
Packit Service 09cdfc
Packit Service 09cdfc
void
Packit Service 09cdfc
cifs_idmap_exit_plugin(void *handle __attribute__((unused)))
Packit Service 09cdfc
{
Packit Service 09cdfc
	return;
Packit Service 09cdfc
}