Merge commit 'release-4-0-0alpha15' into master4-tmp
[samba.git] / source3 / winbindd / wb_group_members.c
1 /*
2    Unix SMB/CIFS implementation.
3    async lookupgroupmembers
4    Copyright (C) Volker Lendecke 2009
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 3 of the License, or
9    (at your option) any later version.
10
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15
16    You should have received a copy of the GNU General Public License
17    along with this program.  If not, see <http://www.gnu.org/licenses/>.
18 */
19
20 #include "includes.h"
21 #include "winbindd.h"
22 #include "librpc/gen_ndr/ndr_wbint_c.h"
23 #include "../librpc/gen_ndr/ndr_security.h"
24 #include "../libcli/security/security.h"
25
26 /*
27  * We have 3 sets of routines here:
28  *
29  * wb_lookupgroupmem is the low-level one-group routine
30  *
31  * wb_groups_members walks a list of groups
32  *
33  * wb_group_members finally is the high-level routine expanding groups
34  * recursively
35  */
36
37 /*
38  * TODO: fill_grent_mem_domusers must be re-added
39  */
40
41 /*
42  * Look up members of a single group. Essentially a wrapper around the
43  * lookup_groupmem winbindd_methods routine.
44  */
45
46 struct wb_lookupgroupmem_state {
47         struct dom_sid sid;
48         struct wbint_Principals members;
49 };
50
51 static void wb_lookupgroupmem_done(struct tevent_req *subreq);
52
53 static struct tevent_req *wb_lookupgroupmem_send(TALLOC_CTX *mem_ctx,
54                                                  struct tevent_context *ev,
55                                                  const struct dom_sid *group_sid,
56                                                  enum lsa_SidType type)
57 {
58         struct tevent_req *req, *subreq;
59         struct wb_lookupgroupmem_state *state;
60         struct winbindd_domain *domain;
61
62         req = tevent_req_create(mem_ctx, &state,
63                                 struct wb_lookupgroupmem_state);
64         if (req == NULL) {
65                 return NULL;
66         }
67         sid_copy(&state->sid, group_sid);
68
69         domain = find_domain_from_sid_noinit(group_sid);
70         if (domain == NULL) {
71                 tevent_req_nterror(req, NT_STATUS_NO_SUCH_GROUP);
72                 return tevent_req_post(req, ev);
73         }
74
75         subreq = dcerpc_wbint_LookupGroupMembers_send(
76                 state, ev, dom_child_handle(domain), &state->sid, type,
77                 &state->members);
78         if (tevent_req_nomem(subreq, req)) {
79                 return tevent_req_post(req, ev);
80         }
81         tevent_req_set_callback(subreq, wb_lookupgroupmem_done, req);
82         return req;
83 }
84
85 static void wb_lookupgroupmem_done(struct tevent_req *subreq)
86 {
87         struct tevent_req *req = tevent_req_callback_data(
88                 subreq, struct tevent_req);
89         struct wb_lookupgroupmem_state *state = tevent_req_data(
90                 req, struct wb_lookupgroupmem_state);
91         NTSTATUS status, result;
92
93         status = dcerpc_wbint_LookupGroupMembers_recv(subreq, state, &result);
94         TALLOC_FREE(subreq);
95         if (any_nt_status_not_ok(status, result, &status)) {
96                 tevent_req_nterror(req, status);
97                 return;
98         }
99         tevent_req_done(req);
100 }
101
102 static NTSTATUS wb_lookupgroupmem_recv(struct tevent_req *req,
103                                            TALLOC_CTX *mem_ctx,
104                                            int *num_members,
105                                            struct wbint_Principal **members)
106 {
107         struct wb_lookupgroupmem_state *state = tevent_req_data(
108                 req, struct wb_lookupgroupmem_state);
109         NTSTATUS status;
110
111         if (tevent_req_is_nterror(req, &status)) {
112                 return status;
113         }
114
115         *num_members = state->members.num_principals;
116         *members = talloc_move(mem_ctx, &state->members.principals);
117         return NT_STATUS_OK;
118 }
119
120 /*
121  * Same as wb_lookupgroupmem for a list of groups
122  */
123
124 struct wb_groups_members_state {
125         struct tevent_context *ev;
126         struct wbint_Principal *groups;
127         int num_groups;
128         int next_group;
129         struct wbint_Principal *all_members;
130 };
131
132 static NTSTATUS wb_groups_members_next_subreq(
133         struct wb_groups_members_state *state,
134         TALLOC_CTX *mem_ctx, struct tevent_req **psubreq);
135 static void wb_groups_members_done(struct tevent_req *subreq);
136
137 static struct tevent_req *wb_groups_members_send(TALLOC_CTX *mem_ctx,
138                                                  struct tevent_context *ev,
139                                                  int num_groups,
140                                                  struct wbint_Principal *groups)
141 {
142         struct tevent_req *req, *subreq;
143         struct wb_groups_members_state *state;
144         NTSTATUS status;
145
146         req = tevent_req_create(mem_ctx, &state,
147                                 struct wb_groups_members_state);
148         if (req == NULL) {
149                 return NULL;
150         }
151         state->ev = ev;
152         state->groups = groups;
153         state->num_groups = num_groups;
154         state->next_group = 0;
155         state->all_members = NULL;
156
157         status = wb_groups_members_next_subreq(state, state, &subreq);
158         if (tevent_req_nterror(req, status)) {
159                 return tevent_req_post(req, ev);
160         }
161         if (subreq == NULL) {
162                 tevent_req_done(req);
163                 return tevent_req_post(req, ev);
164         }
165         tevent_req_set_callback(subreq, wb_groups_members_done, req);
166         return req;
167 }
168
169 static NTSTATUS wb_groups_members_next_subreq(
170         struct wb_groups_members_state *state,
171         TALLOC_CTX *mem_ctx, struct tevent_req **psubreq)
172 {
173         struct tevent_req *subreq;
174         struct wbint_Principal *g;
175
176         if (state->next_group >= state->num_groups) {
177                 *psubreq = NULL;
178                 return NT_STATUS_OK;
179         }
180
181         g = &state->groups[state->next_group];
182         state->next_group += 1;
183
184         subreq = wb_lookupgroupmem_send(mem_ctx, state->ev, &g->sid, g->type);
185         if (subreq == NULL) {
186                 return NT_STATUS_NO_MEMORY;
187         }
188         *psubreq = subreq;
189         return NT_STATUS_OK;
190 }
191
192 static void wb_groups_members_done(struct tevent_req *subreq)
193 {
194         struct tevent_req *req = tevent_req_callback_data(
195                 subreq, struct tevent_req);
196         struct wb_groups_members_state *state = tevent_req_data(
197                 req, struct wb_groups_members_state);
198         int i, num_all_members;
199         int num_members = 0;
200         struct wbint_Principal *members = NULL;
201         NTSTATUS status;
202
203         status = wb_lookupgroupmem_recv(subreq, state, &num_members,
204                                             &members);
205         TALLOC_FREE(subreq);
206
207         /*
208          * In this error handling here we might have to be a bit more generous
209          * and just continue if an error occured.
210          */
211
212         if (tevent_req_nterror(req, status)) {
213                 return;
214         }
215
216         num_all_members = talloc_array_length(state->all_members);
217
218         state->all_members = talloc_realloc(
219                 state, state->all_members, struct wbint_Principal,
220                 num_all_members + num_members);
221         if ((num_all_members + num_members != 0)
222             && tevent_req_nomem(state->all_members, req)) {
223                 return;
224         }
225         for (i=0; i<num_members; i++) {
226                 struct wbint_Principal *src, *dst;
227                 src = &members[i];
228                 dst = &state->all_members[num_all_members + i];
229                 sid_copy(&dst->sid, &src->sid);
230                 dst->name = talloc_move(state->all_members, &src->name);
231                 dst->type = src->type;
232         }
233         TALLOC_FREE(members);
234
235         status = wb_groups_members_next_subreq(state, state, &subreq);
236         if (tevent_req_nterror(req, status)) {
237                 return;
238         }
239         if (subreq == NULL) {
240                 tevent_req_done(req);
241                 return;
242         }
243         tevent_req_set_callback(subreq, wb_groups_members_done, req);
244 }
245
246 static NTSTATUS wb_groups_members_recv(struct tevent_req *req,
247                                        TALLOC_CTX *mem_ctx,
248                                        int *num_members,
249                                        struct wbint_Principal **members)
250 {
251         struct wb_groups_members_state *state = tevent_req_data(
252                 req, struct wb_groups_members_state);
253         NTSTATUS status;
254
255         if (tevent_req_is_nterror(req, &status)) {
256                 return status;
257         }
258         *num_members = talloc_array_length(state->all_members);
259         *members = talloc_move(mem_ctx, &state->all_members);
260         return NT_STATUS_OK;
261 }
262
263
264 /*
265  * This is the routine expanding a list of groups up to a certain level. We
266  * collect the users in a talloc_dict: We have to add them without duplicates,
267  * and talloc_dict is an indexed (here indexed by SID) data structure.
268  */
269
270 struct wb_group_members_state {
271         struct tevent_context *ev;
272         int depth;
273         struct talloc_dict *users;
274         struct wbint_Principal *groups;
275 };
276
277 static NTSTATUS wb_group_members_next_subreq(
278         struct wb_group_members_state *state,
279         TALLOC_CTX *mem_ctx, struct tevent_req **psubreq);
280 static void wb_group_members_done(struct tevent_req *subreq);
281
282 struct tevent_req *wb_group_members_send(TALLOC_CTX *mem_ctx,
283                                          struct tevent_context *ev,
284                                          const struct dom_sid *sid,
285                                          enum lsa_SidType type,
286                                          int max_depth)
287 {
288         struct tevent_req *req, *subreq;
289         struct wb_group_members_state *state;
290         NTSTATUS status;
291
292         req = tevent_req_create(mem_ctx, &state,
293                                 struct wb_group_members_state);
294         if (req == NULL) {
295                 return NULL;
296         }
297         state->ev = ev;
298         state->depth = max_depth;
299         state->users = talloc_dict_init(state);
300         if (tevent_req_nomem(state->users, req)) {
301                 return tevent_req_post(req, ev);
302         }
303
304         state->groups = talloc(state, struct wbint_Principal);
305         if (tevent_req_nomem(state->groups, req)) {
306                 return tevent_req_post(req, ev);
307         }
308         state->groups->name = NULL;
309         sid_copy(&state->groups->sid, sid);
310         state->groups->type = type;
311
312         status = wb_group_members_next_subreq(state, state, &subreq);
313         if (tevent_req_nterror(req, status)) {
314                 return tevent_req_post(req, ev);
315         }
316         if (subreq == NULL) {
317                 tevent_req_done(req);
318                 return tevent_req_post(req, ev);
319         }
320         tevent_req_set_callback(subreq, wb_group_members_done, req);
321         return req;
322 }
323
324 static NTSTATUS wb_group_members_next_subreq(
325         struct wb_group_members_state *state,
326         TALLOC_CTX *mem_ctx, struct tevent_req **psubreq)
327 {
328         struct tevent_req *subreq;
329
330         if ((talloc_array_length(state->groups) == 0)
331             || (state->depth <= 0)) {
332                 *psubreq = NULL;
333                 return NT_STATUS_OK;
334         }
335         state->depth -= 1;
336
337         subreq = wb_groups_members_send(
338                 mem_ctx, state->ev, talloc_array_length(state->groups),
339                 state->groups);
340         if (subreq == NULL) {
341                 return NT_STATUS_NO_MEMORY;
342         }
343         *psubreq = subreq;
344         return NT_STATUS_OK;
345 }
346
347 static void wb_group_members_done(struct tevent_req *subreq)
348 {
349         struct tevent_req *req = tevent_req_callback_data(
350                 subreq, struct tevent_req);
351         struct wb_group_members_state *state = tevent_req_data(
352                 req, struct wb_group_members_state);
353         int i, num_groups, new_users, new_groups;
354         int num_members = 0;
355         struct wbint_Principal *members = NULL;
356         NTSTATUS status;
357
358         status = wb_groups_members_recv(subreq, state, &num_members, &members);
359         TALLOC_FREE(subreq);
360         if (tevent_req_nterror(req, status)) {
361                 return;
362         }
363
364         new_users = new_groups = 0;
365         for (i=0; i<num_members; i++) {
366                 switch (members[i].type) {
367                 case SID_NAME_DOM_GRP:
368                 case SID_NAME_ALIAS:
369                 case SID_NAME_WKN_GRP:
370                         new_groups += 1;
371                         break;
372                 default:
373                         /* Ignore everything else */
374                         break;
375                 }
376         }
377
378         num_groups = 0;
379         TALLOC_FREE(state->groups);
380         state->groups = talloc_array(state, struct wbint_Principal,
381                                      new_groups);
382
383         /*
384          * Collect the users into state->users and the groups into
385          * state->groups for the next iteration.
386          */
387
388         for (i=0; i<num_members; i++) {
389                 switch (members[i].type) {
390                 case SID_NAME_USER:
391                 case SID_NAME_COMPUTER: {
392                         /*
393                          * Add a copy of members[i] to state->users
394                          */
395                         struct wbint_Principal *m;
396                         struct dom_sid *sid;
397                         DATA_BLOB key;
398
399                         m = talloc(talloc_tos(), struct wbint_Principal);
400                         if (tevent_req_nomem(m, req)) {
401                                 return;
402                         }
403                         sid_copy(&m->sid, &members[i].sid);
404                         m->name = talloc_move(m, &members[i].name);
405                         m->type = members[i].type;
406
407                         sid = &members[i].sid;
408                         key = data_blob_const(
409                                 sid, ndr_size_dom_sid(sid, 0));
410
411                         if (!talloc_dict_set(state->users, key, &m)) {
412                                 tevent_req_nterror(req, NT_STATUS_NO_MEMORY);
413                                 return;
414                         }
415                         break;
416                 }
417                 case SID_NAME_DOM_GRP:
418                 case SID_NAME_ALIAS:
419                 case SID_NAME_WKN_GRP: {
420                         struct wbint_Principal *g;
421                         /*
422                          * Save members[i] for the next round
423                          */
424                         g = &state->groups[num_groups];
425                         sid_copy(&g->sid, &members[i].sid);
426                         g->name = talloc_move(state->groups, &members[i].name);
427                         g->type = members[i].type;
428                         num_groups += 1;
429                         break;
430                 }
431                 default:
432                         /* Ignore everything else */
433                         break;
434                 }
435         }
436
437         status = wb_group_members_next_subreq(state, state, &subreq);
438         if (tevent_req_nterror(req, status)) {
439                 return;
440         }
441         if (subreq == NULL) {
442                 tevent_req_done(req);
443                 return;
444         }
445         tevent_req_set_callback(subreq, wb_group_members_done, req);
446 }
447
448 NTSTATUS wb_group_members_recv(struct tevent_req *req, TALLOC_CTX *mem_ctx,
449                                struct talloc_dict **members)
450 {
451         struct wb_group_members_state *state = tevent_req_data(
452                 req, struct wb_group_members_state);
453         NTSTATUS status;
454
455         if (tevent_req_is_nterror(req, &status)) {
456                 return status;
457         }
458         *members = talloc_move(mem_ctx, &state->users);
459         return NT_STATUS_OK;
460 }