2 Unix SMB/CIFS implementation.
3 Infrastructure for async winbind requests
4 Copyright (C) Volker Lendecke 2008
6 ** NOTE! The following LGPL license applies to the wbclient
7 ** library. This does NOT imply that all of Samba is released
10 This library is free software; you can redistribute it and/or
11 modify it under the terms of the GNU Lesser General Public
12 License as published by the Free Software Foundation; either
13 version 3 of the License, or (at your option) any later version.
15 This library is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
18 Library General Public License for more details.
20 You should have received a copy of the GNU Lesser General Public License
21 along with this program. If not, see <http://www.gnu.org/licenses/>.
25 #include "system/filesys.h"
26 #include "system/network.h"
31 #include "lib/async_req/async_sock.h"
32 #include "nsswitch/winbind_struct_protocol.h"
33 #include "nsswitch/libwbclient/wbclient.h"
34 #include "nsswitch/libwbclient/wbc_async.h"
36 wbcErr map_wbc_err_from_errno(int error)
41 return WBC_ERR_AUTH_ERROR;
43 return WBC_ERR_NO_MEMORY;
46 return WBC_ERR_UNKNOWN_FAILURE;
50 bool tevent_req_is_wbcerr(struct tevent_req *req, wbcErr *pwbc_err)
52 enum tevent_req_state state;
54 if (!tevent_req_is_error(req, &state, &error)) {
55 *pwbc_err = WBC_ERR_SUCCESS;
60 case TEVENT_REQ_USER_ERROR:
63 case TEVENT_REQ_TIMED_OUT:
64 *pwbc_err = WBC_ERR_UNKNOWN_FAILURE;
66 case TEVENT_REQ_NO_MEMORY:
67 *pwbc_err = WBC_ERR_NO_MEMORY;
70 *pwbc_err = WBC_ERR_UNKNOWN_FAILURE;
76 wbcErr tevent_req_simple_recv_wbcerr(struct tevent_req *req)
80 if (tevent_req_is_wbcerr(req, &wbc_err)) {
84 return WBC_ERR_SUCCESS;
88 struct tevent_queue *queue;
94 static int make_nonstd_fd(int fd)
112 for (i=0; i<num_fds; i++) {
121 /****************************************************************************
122 Set a fd into blocking/nonblocking mode. Uses POSIX O_NONBLOCK if available,
126 Set close on exec also.
127 ****************************************************************************/
129 static int make_safe_fd(int fd)
132 int new_fd = make_nonstd_fd(fd);
138 /* Socket should be nonblocking. */
141 #define FLAG_TO_SET O_NONBLOCK
144 #define FLAG_TO_SET O_NDELAY
146 #define FLAG_TO_SET FNDELAY
150 if ((flags = fcntl(new_fd, F_GETFL)) == -1) {
154 flags |= FLAG_TO_SET;
155 if (fcntl(new_fd, F_SETFL, flags) == -1) {
161 /* Socket should be closed on exec() */
163 result = flags = fcntl(new_fd, F_GETFD, 0);
166 result = fcntl( new_fd, F_SETFD, flags );
176 int sys_errno = errno;
183 /* Just put a prototype to avoid moving the whole function around */
184 static const char *winbindd_socket_dir(void);
186 struct wb_context *wb_context_init(TALLOC_CTX *mem_ctx, const char* dir)
188 struct wb_context *result;
190 result = talloc(mem_ctx, struct wb_context);
191 if (result == NULL) {
194 result->queue = tevent_queue_create(result, "wb_trans");
195 if (result->queue == NULL) {
200 result->is_priv = false;
203 result->dir = talloc_strdup(result, dir);
205 result->dir = winbindd_socket_dir();
207 if (result->dir == NULL) {
214 struct wb_connect_state {
218 static void wbc_connect_connected(struct tevent_req *subreq);
220 static struct tevent_req *wb_connect_send(TALLOC_CTX *mem_ctx,
221 struct tevent_context *ev,
222 struct wb_context *wb_ctx,
225 struct tevent_req *result, *subreq;
226 struct wb_connect_state *state;
227 struct sockaddr_un sunaddr;
232 result = tevent_req_create(mem_ctx, &state, struct wb_connect_state);
233 if (result == NULL) {
237 if (wb_ctx->fd != -1) {
242 /* Check permissions on unix socket directory */
244 if (lstat(dir, &st) == -1) {
245 wbc_err = WBC_ERR_WINBIND_NOT_AVAILABLE;
249 if (!S_ISDIR(st.st_mode) ||
250 (st.st_uid != 0 && st.st_uid != geteuid())) {
251 wbc_err = WBC_ERR_WINBIND_NOT_AVAILABLE;
255 /* Connect to socket */
257 path = talloc_asprintf(talloc_tos(), "%s/%s", dir,
258 WINBINDD_SOCKET_NAME);
263 sunaddr.sun_family = AF_UNIX;
264 strlcpy(sunaddr.sun_path, path, sizeof(sunaddr.sun_path));
267 /* If socket file doesn't exist, don't bother trying to connect
268 with retry. This is an attempt to make the system usable when
269 the winbindd daemon is not running. */
271 if ((lstat(sunaddr.sun_path, &st) == -1)
272 || !S_ISSOCK(st.st_mode)
273 || (st.st_uid != 0 && st.st_uid != geteuid())) {
274 wbc_err = WBC_ERR_WINBIND_NOT_AVAILABLE;
278 wb_ctx->fd = make_safe_fd(socket(AF_UNIX, SOCK_STREAM, 0));
279 if (wb_ctx->fd == -1) {
280 wbc_err = map_wbc_err_from_errno(errno);
284 subreq = async_connect_send(mem_ctx, ev, wb_ctx->fd,
285 (struct sockaddr *)(void *)&sunaddr,
287 if (subreq == NULL) {
290 tevent_req_set_callback(subreq, wbc_connect_connected, result);
294 tevent_req_error(result, wbc_err);
295 return tevent_req_post(result, ev);
301 static void wbc_connect_connected(struct tevent_req *subreq)
303 struct tevent_req *req = tevent_req_callback_data(
304 subreq, struct tevent_req);
307 res = async_connect_recv(subreq, &err);
310 tevent_req_error(req, map_wbc_err_from_errno(err));
313 tevent_req_done(req);
316 static wbcErr wb_connect_recv(struct tevent_req *req)
318 return tevent_req_simple_recv_wbcerr(req);
321 static const char *winbindd_socket_dir(void)
323 #ifdef SOCKET_WRAPPER
326 env_dir = getenv(WINBINDD_SOCKET_DIR_ENVVAR);
332 return WINBINDD_SOCKET_DIR;
335 struct wb_open_pipe_state {
336 struct wb_context *wb_ctx;
337 struct tevent_context *ev;
339 struct winbindd_request wb_req;
342 static void wb_open_pipe_connect_nonpriv_done(struct tevent_req *subreq);
343 static void wb_open_pipe_ping_done(struct tevent_req *subreq);
344 static void wb_open_pipe_getpriv_done(struct tevent_req *subreq);
345 static void wb_open_pipe_connect_priv_done(struct tevent_req *subreq);
347 static struct tevent_req *wb_open_pipe_send(TALLOC_CTX *mem_ctx,
348 struct tevent_context *ev,
349 struct wb_context *wb_ctx,
352 struct tevent_req *result, *subreq;
353 struct wb_open_pipe_state *state;
355 result = tevent_req_create(mem_ctx, &state, struct wb_open_pipe_state);
356 if (result == NULL) {
359 state->wb_ctx = wb_ctx;
361 state->need_priv = need_priv;
363 if (wb_ctx->fd != -1) {
368 subreq = wb_connect_send(state, ev, wb_ctx, wb_ctx->dir);
369 if (subreq == NULL) {
372 tevent_req_set_callback(subreq, wb_open_pipe_connect_nonpriv_done,
381 static void wb_open_pipe_connect_nonpriv_done(struct tevent_req *subreq)
383 struct tevent_req *req = tevent_req_callback_data(
384 subreq, struct tevent_req);
385 struct wb_open_pipe_state *state = tevent_req_data(
386 req, struct wb_open_pipe_state);
389 wbc_err = wb_connect_recv(subreq);
391 if (!WBC_ERROR_IS_OK(wbc_err)) {
392 state->wb_ctx->is_priv = true;
393 tevent_req_error(req, wbc_err);
397 ZERO_STRUCT(state->wb_req);
398 state->wb_req.cmd = WINBINDD_INTERFACE_VERSION;
399 state->wb_req.pid = getpid();
401 subreq = wb_simple_trans_send(state, state->ev, NULL,
402 state->wb_ctx->fd, &state->wb_req);
403 if (tevent_req_nomem(subreq, req)) {
406 tevent_req_set_callback(subreq, wb_open_pipe_ping_done, req);
409 static void wb_open_pipe_ping_done(struct tevent_req *subreq)
411 struct tevent_req *req = tevent_req_callback_data(
412 subreq, struct tevent_req);
413 struct wb_open_pipe_state *state = tevent_req_data(
414 req, struct wb_open_pipe_state);
415 struct winbindd_response *wb_resp;
418 ret = wb_simple_trans_recv(subreq, state, &wb_resp, &err);
421 tevent_req_error(req, map_wbc_err_from_errno(err));
425 if (!state->need_priv) {
426 tevent_req_done(req);
430 state->wb_req.cmd = WINBINDD_PRIV_PIPE_DIR;
431 state->wb_req.pid = getpid();
433 subreq = wb_simple_trans_send(state, state->ev, NULL,
434 state->wb_ctx->fd, &state->wb_req);
435 if (tevent_req_nomem(subreq, req)) {
438 tevent_req_set_callback(subreq, wb_open_pipe_getpriv_done, req);
441 static void wb_open_pipe_getpriv_done(struct tevent_req *subreq)
443 struct tevent_req *req = tevent_req_callback_data(
444 subreq, struct tevent_req);
445 struct wb_open_pipe_state *state = tevent_req_data(
446 req, struct wb_open_pipe_state);
447 struct winbindd_response *wb_resp = NULL;
450 ret = wb_simple_trans_recv(subreq, state, &wb_resp, &err);
453 tevent_req_error(req, map_wbc_err_from_errno(err));
457 close(state->wb_ctx->fd);
458 state->wb_ctx->fd = -1;
460 subreq = wb_connect_send(state, state->ev, state->wb_ctx,
461 (char *)wb_resp->extra_data.data);
462 TALLOC_FREE(wb_resp);
463 if (tevent_req_nomem(subreq, req)) {
466 tevent_req_set_callback(subreq, wb_open_pipe_connect_priv_done, req);
469 static void wb_open_pipe_connect_priv_done(struct tevent_req *subreq)
471 struct tevent_req *req = tevent_req_callback_data(
472 subreq, struct tevent_req);
473 struct wb_open_pipe_state *state = tevent_req_data(
474 req, struct wb_open_pipe_state);
477 wbc_err = wb_connect_recv(subreq);
479 if (!WBC_ERROR_IS_OK(wbc_err)) {
480 tevent_req_error(req, wbc_err);
483 state->wb_ctx->is_priv = true;
484 tevent_req_done(req);
487 static wbcErr wb_open_pipe_recv(struct tevent_req *req)
489 return tevent_req_simple_recv_wbcerr(req);
492 struct wb_trans_state {
493 struct wb_trans_state *prev, *next;
494 struct wb_context *wb_ctx;
495 struct tevent_context *ev;
496 struct winbindd_request *wb_req;
497 struct winbindd_response *wb_resp;
501 static bool closed_fd(int fd)
515 selret = select(fd+1, &r_fds, NULL, NULL, &tv);
522 return (FD_ISSET(fd, &r_fds));
525 static void wb_trans_trigger(struct tevent_req *req, void *private_data);
526 static void wb_trans_connect_done(struct tevent_req *subreq);
527 static void wb_trans_done(struct tevent_req *subreq);
528 static void wb_trans_retry_wait_done(struct tevent_req *subreq);
530 struct tevent_req *wb_trans_send(TALLOC_CTX *mem_ctx,
531 struct tevent_context *ev,
532 struct wb_context *wb_ctx, bool need_priv,
533 struct winbindd_request *wb_req)
535 struct tevent_req *req;
536 struct wb_trans_state *state;
538 req = tevent_req_create(mem_ctx, &state, struct wb_trans_state);
542 state->wb_ctx = wb_ctx;
544 state->wb_req = wb_req;
545 state->need_priv = need_priv;
547 if (!tevent_queue_add(wb_ctx->queue, ev, req, wb_trans_trigger,
549 tevent_req_nomem(NULL, req);
550 return tevent_req_post(req, ev);
555 static void wb_trans_trigger(struct tevent_req *req, void *private_data)
557 struct wb_trans_state *state = tevent_req_data(
558 req, struct wb_trans_state);
559 struct tevent_req *subreq;
561 if ((state->wb_ctx->fd != -1) && closed_fd(state->wb_ctx->fd)) {
562 close(state->wb_ctx->fd);
563 state->wb_ctx->fd = -1;
566 if ((state->wb_ctx->fd == -1)
567 || (state->need_priv && !state->wb_ctx->is_priv)) {
568 subreq = wb_open_pipe_send(state, state->ev, state->wb_ctx,
570 if (tevent_req_nomem(subreq, req)) {
573 tevent_req_set_callback(subreq, wb_trans_connect_done, req);
577 state->wb_req->pid = getpid();
579 subreq = wb_simple_trans_send(state, state->ev, NULL,
580 state->wb_ctx->fd, state->wb_req);
581 if (tevent_req_nomem(subreq, req)) {
584 tevent_req_set_callback(subreq, wb_trans_done, req);
587 static bool wb_trans_retry(struct tevent_req *req,
588 struct wb_trans_state *state,
591 struct tevent_req *subreq;
593 if (WBC_ERROR_IS_OK(wbc_err)) {
597 if (wbc_err == WBC_ERR_WINBIND_NOT_AVAILABLE) {
599 * Winbind not around or we can't connect to the pipe. Fail
602 tevent_req_error(req, wbc_err);
607 * The transfer as such failed, retry after one second
610 if (state->wb_ctx->fd != -1) {
611 close(state->wb_ctx->fd);
612 state->wb_ctx->fd = -1;
615 subreq = tevent_wakeup_send(state, state->ev,
616 timeval_current_ofs(1, 0));
617 if (tevent_req_nomem(subreq, req)) {
620 tevent_req_set_callback(subreq, wb_trans_retry_wait_done, req);
624 static void wb_trans_retry_wait_done(struct tevent_req *subreq)
626 struct tevent_req *req = tevent_req_callback_data(
627 subreq, struct tevent_req);
628 struct wb_trans_state *state = tevent_req_data(
629 req, struct wb_trans_state);
632 ret = tevent_wakeup_recv(subreq);
635 tevent_req_error(req, WBC_ERR_UNKNOWN_FAILURE);
639 subreq = wb_open_pipe_send(state, state->ev, state->wb_ctx,
641 if (tevent_req_nomem(subreq, req)) {
644 tevent_req_set_callback(subreq, wb_trans_connect_done, req);
647 static void wb_trans_connect_done(struct tevent_req *subreq)
649 struct tevent_req *req = tevent_req_callback_data(
650 subreq, struct tevent_req);
651 struct wb_trans_state *state = tevent_req_data(
652 req, struct wb_trans_state);
655 wbc_err = wb_open_pipe_recv(subreq);
658 if (wb_trans_retry(req, state, wbc_err)) {
662 subreq = wb_simple_trans_send(state, state->ev, NULL,
663 state->wb_ctx->fd, state->wb_req);
664 if (tevent_req_nomem(subreq, req)) {
667 tevent_req_set_callback(subreq, wb_trans_done, req);
670 static void wb_trans_done(struct tevent_req *subreq)
672 struct tevent_req *req = tevent_req_callback_data(
673 subreq, struct tevent_req);
674 struct wb_trans_state *state = tevent_req_data(
675 req, struct wb_trans_state);
678 ret = wb_simple_trans_recv(subreq, state, &state->wb_resp, &err);
681 && wb_trans_retry(req, state, map_wbc_err_from_errno(err))) {
685 tevent_req_done(req);
688 wbcErr wb_trans_recv(struct tevent_req *req, TALLOC_CTX *mem_ctx,
689 struct winbindd_response **presponse)
691 struct wb_trans_state *state = tevent_req_data(
692 req, struct wb_trans_state);
695 if (tevent_req_is_wbcerr(req, &wbc_err)) {
699 *presponse = talloc_move(mem_ctx, &state->wb_resp);
700 return WBC_ERR_SUCCESS;