2 Unix SMB/CIFS mplementation.
3 KCC service periodic handling
5 Copyright (C) Andrew Tridgell 2009
6 based on repl service code
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
24 #include "lib/events/events.h"
25 #include "dsdb/samdb/samdb.h"
26 #include "auth/auth.h"
27 #include "smbd/service.h"
28 #include "lib/messaging/irpc.h"
29 #include "dsdb/kcc/kcc_connection.h"
30 #include "dsdb/kcc/kcc_service.h"
31 #include <ldb_errors.h>
32 #include "../lib/util/dlinklist.h"
33 #include "librpc/gen_ndr/ndr_misc.h"
34 #include "librpc/gen_ndr/ndr_drsuapi.h"
35 #include "librpc/gen_ndr/ndr_drsblobs.h"
36 #include "librpc/gen_ndr/ndr_irpc_c.h"
37 #include "param/param.h"
40 * see if two repsFromToBlob blobs are for the same source DSA
42 static bool kccsrv_same_source_dsa(struct repsFromToBlob *r1, struct repsFromToBlob *r2)
44 return GUID_compare(&r1->ctr.ctr1.source_dsa_obj_guid,
45 &r2->ctr.ctr1.source_dsa_obj_guid) == 0;
49 * see if a repsFromToBlob is in a list
51 static bool reps_in_list(struct repsFromToBlob *r, struct repsFromToBlob *reps, uint32_t count)
54 for (i=0; i<count; i++) {
55 if (kccsrv_same_source_dsa(r, &reps[i])) {
63 make sure we only add repsFrom entries for DCs who are masters for
66 static bool check_MasterNC(struct kccsrv_partition *p, struct repsFromToBlob *r,
67 struct ldb_result *res)
69 struct repsFromTo1 *r1 = &r->ctr.ctr1;
70 struct GUID invocation_id = r1->source_dsa_invocation_id;
73 /* we are expecting only version 1 */
74 SMB_ASSERT(r->version == 1);
76 for (i=0; i<res->count; i++) {
77 struct ldb_message *msg = res->msgs[i];
78 struct ldb_message_element *el;
81 struct GUID id2 = samdb_result_guid(msg, "invocationID");
82 if (GUID_all_zero(&id2) ||
83 !GUID_equal(&invocation_id, &id2)) {
87 el = ldb_msg_find_element(msg, "msDS-hasMasterNCs");
88 if (!el || el->num_values == 0) {
89 el = ldb_msg_find_element(msg, "hasMasterNCs");
90 if (!el || el->num_values == 0) {
94 for (j=0; j<el->num_values; j++) {
95 dn = ldb_dn_from_ldb_val(p, p->service->samdb, &el->values[j]);
96 if (!ldb_dn_validate(dn)) {
100 if (ldb_dn_compare(dn, p->dn) == 0) {
102 DEBUG(5,("%s %s match on %s in %s\n",
103 r1->other_info->dns_name,
105 ldb_dn_get_linearized(dn),
106 ldb_dn_get_linearized(msg->dn)));
115 struct kccsrv_notify_drepl_server_state {
116 struct dreplsrv_refresh r;
119 static void kccsrv_notify_drepl_server_done(struct tevent_req *subreq);
122 * Force dreplsrv to update its state as topology is changed
124 static void kccsrv_notify_drepl_server(struct kccsrv_service *s,
127 struct kccsrv_notify_drepl_server_state *state;
128 struct dcerpc_binding_handle *irpc_handle;
129 struct tevent_req *subreq;
131 state = talloc_zero(s, struct kccsrv_notify_drepl_server_state);
136 irpc_handle = irpc_binding_handle_by_name(state, s->task->msg_ctx,
137 "dreplsrv", &ndr_table_irpc);
138 if (irpc_handle == NULL) {
139 /* dreplsrv is not running yet */
144 subreq = dcerpc_dreplsrv_refresh_r_send(state, s->task->event_ctx,
145 irpc_handle, &state->r);
146 if (subreq == NULL) {
150 tevent_req_set_callback(subreq, kccsrv_notify_drepl_server_done, state);
153 static void kccsrv_notify_drepl_server_done(struct tevent_req *subreq)
155 struct kccsrv_notify_drepl_server_state *state =
156 tevent_req_callback_data(subreq,
157 struct kccsrv_notify_drepl_server_state);
160 status = dcerpc_dreplsrv_refresh_r_recv(subreq, state);
163 /* we don't care about errors */
167 uint32_t kccsrv_replica_flags(struct kccsrv_service *s)
170 return DRSUAPI_DRS_INIT_SYNC |
171 DRSUAPI_DRS_PER_SYNC |
172 DRSUAPI_DRS_ADD_REF |
173 DRSUAPI_DRS_SPECIAL_SECRET_PROCESSING |
174 DRSUAPI_DRS_GET_ALL_GROUP_MEMBERSHIP |
175 DRSUAPI_DRS_NONGC_RO_REP;
177 return DRSUAPI_DRS_INIT_SYNC |
178 DRSUAPI_DRS_PER_SYNC |
179 DRSUAPI_DRS_ADD_REF |
180 DRSUAPI_DRS_WRIT_REP;
184 * add any missing repsFrom structures to our partitions
186 NTSTATUS kccsrv_add_repsFrom(struct kccsrv_service *s, TALLOC_CTX *mem_ctx,
187 struct repsFromToBlob *reps, uint32_t count,
188 struct ldb_result *res)
190 struct kccsrv_partition *p;
191 bool notify_dreplsrv = false;
192 uint32_t replica_flags = kccsrv_replica_flags(s);
194 /* update the repsFrom on all partitions */
195 for (p=s->partitions; p; p=p->next) {
196 struct repsFromToBlob *our_reps;
200 bool modified = false;
202 werr = dsdb_loadreps(s->samdb, mem_ctx, p->dn, "repsFrom", &our_reps, &our_count);
203 if (!W_ERROR_IS_OK(werr)) {
204 DEBUG(0,(__location__ ": Failed to load repsFrom from %s - %s\n",
205 ldb_dn_get_linearized(p->dn), ldb_errstring(s->samdb)));
206 return NT_STATUS_INTERNAL_DB_CORRUPTION;
209 /* see if the entry already exists */
210 for (i=0; i<count; i++) {
211 for (j=0; j<our_count; j++) {
212 if (kccsrv_same_source_dsa(&reps[i], &our_reps[j])) {
213 /* we already have this one -
214 check the replica_flags are right */
215 if (replica_flags != our_reps[j].ctr.ctr1.replica_flags) {
216 /* we need to update the old one with
219 our_reps[j].ctr.ctr1.replica_flags = replica_flags;
225 if (j == our_count) {
226 /* we don't have the new one - add it
229 if (res && !check_MasterNC(p, &reps[i], res)) {
230 /* its not a master, we don't
231 want to pull from it */
234 /* we need to add it to our repsFrom */
235 our_reps = talloc_realloc(mem_ctx, our_reps, struct repsFromToBlob, our_count+1);
236 NT_STATUS_HAVE_NO_MEMORY(our_reps);
237 our_reps[our_count] = reps[i];
238 our_reps[our_count].ctr.ctr1.replica_flags = replica_flags;
241 DEBUG(4,(__location__ ": Added repsFrom for %s\n",
242 reps[i].ctr.ctr1.other_info->dns_name));
246 /* remove any stale ones */
247 for (i=0; i<our_count; i++) {
248 if (!reps_in_list(&our_reps[i], reps, count) ||
249 (res && !check_MasterNC(p, &our_reps[i], res))) {
250 DEBUG(4,(__location__ ": Removed repsFrom for %s\n",
251 our_reps[i].ctr.ctr1.other_info->dns_name));
252 memmove(&our_reps[i], &our_reps[i+1], (our_count-(i+1))*sizeof(our_reps[0]));
260 werr = dsdb_savereps(s->samdb, mem_ctx, p->dn, "repsFrom", our_reps, our_count);
261 if (!W_ERROR_IS_OK(werr)) {
262 DEBUG(0,(__location__ ": Failed to save repsFrom to %s - %s\n",
263 ldb_dn_get_linearized(p->dn), ldb_errstring(s->samdb)));
264 return NT_STATUS_INTERNAL_DB_CORRUPTION;
266 /* dreplsrv should refresh its state */
267 notify_dreplsrv = true;
270 /* remove stale repsTo entries */
272 werr = dsdb_loadreps(s->samdb, mem_ctx, p->dn, "repsTo", &our_reps, &our_count);
273 if (!W_ERROR_IS_OK(werr)) {
274 DEBUG(0,(__location__ ": Failed to load repsTo from %s - %s\n",
275 ldb_dn_get_linearized(p->dn), ldb_errstring(s->samdb)));
276 return NT_STATUS_INTERNAL_DB_CORRUPTION;
279 /* remove any stale ones */
280 for (i=0; i<our_count; i++) {
281 if (!reps_in_list(&our_reps[i], reps, count)) {
282 DEBUG(4,(__location__ ": Removed repsTo for %s\n",
283 our_reps[i].ctr.ctr1.other_info->dns_name));
284 memmove(&our_reps[i], &our_reps[i+1], (our_count-(i+1))*sizeof(our_reps[0]));
292 werr = dsdb_savereps(s->samdb, mem_ctx, p->dn, "repsTo", our_reps, our_count);
293 if (!W_ERROR_IS_OK(werr)) {
294 DEBUG(0,(__location__ ": Failed to save repsTo to %s - %s\n",
295 ldb_dn_get_linearized(p->dn), ldb_errstring(s->samdb)));
296 return NT_STATUS_INTERNAL_DB_CORRUPTION;
298 /* dreplsrv should refresh its state */
299 notify_dreplsrv = true;
303 /* notify dreplsrv toplogy has changed */
304 if (notify_dreplsrv) {
305 kccsrv_notify_drepl_server(s, mem_ctx);
313 this is the core of our initial simple KCC
314 We just add a repsFrom entry for all DCs we find that have nTDSDSA
315 objects, except for ourselves
317 NTSTATUS kccsrv_simple_update(struct kccsrv_service *s, TALLOC_CTX *mem_ctx)
319 struct ldb_result *res;
322 const char *attrs[] = { "objectGUID", "invocationID", "msDS-hasMasterNCs", "hasMasterNCs", NULL };
323 struct repsFromToBlob *reps = NULL;
325 struct kcc_connection_list *ntds_conn, *dsa_conn;
327 ret = ldb_search(s->samdb, mem_ctx, &res, s->config_dn, LDB_SCOPE_SUBTREE,
328 attrs, "objectClass=nTDSDSA");
329 if (ret != LDB_SUCCESS) {
330 DEBUG(0,(__location__ ": Failed nTDSDSA search - %s\n", ldb_errstring(s->samdb)));
331 return NT_STATUS_INTERNAL_DB_CORRUPTION;
334 /* get the current list of connections */
335 ntds_conn = kccsrv_find_connections(s, mem_ctx);
337 dsa_conn = talloc_zero(mem_ctx, struct kcc_connection_list);
339 for (i=0; i<res->count; i++) {
340 struct repsFromTo1 *r1;
341 struct GUID ntds_guid, invocation_id;
343 ntds_guid = samdb_result_guid(res->msgs[i], "objectGUID");
344 if (GUID_compare(&ntds_guid, &s->ntds_guid) == 0) {
345 /* don't replicate with ourselves */
349 invocation_id = samdb_result_guid(res->msgs[i], "invocationID");
351 reps = talloc_realloc(mem_ctx, reps, struct repsFromToBlob, count+1);
352 NT_STATUS_HAVE_NO_MEMORY(reps);
354 ZERO_STRUCT(reps[count]);
355 reps[count].version = 1;
356 r1 = &reps[count].ctr.ctr1;
358 r1->other_info = talloc_zero(reps, struct repsFromTo1OtherInfo);
359 r1->other_info->dns_name = talloc_asprintf(r1->other_info, "%s._msdcs.%s",
360 GUID_string(mem_ctx, &ntds_guid),
361 lpcfg_dnsdomain(s->task->lp_ctx));
362 r1->source_dsa_obj_guid = ntds_guid;
363 r1->source_dsa_invocation_id = invocation_id;
364 r1->replica_flags = kccsrv_replica_flags(s);
365 memset(r1->schedule, 0x11, sizeof(r1->schedule));
367 dsa_conn->servers = talloc_realloc(dsa_conn, dsa_conn->servers,
368 struct kcc_connection,
369 dsa_conn->count + 1);
370 NT_STATUS_HAVE_NO_MEMORY(dsa_conn->servers);
371 dsa_conn->servers[dsa_conn->count].dsa_guid = r1->source_dsa_obj_guid;
377 kccsrv_apply_connections(s, ntds_conn, dsa_conn);
379 return kccsrv_add_repsFrom(s, mem_ctx, reps, count, res);
383 static void kccsrv_periodic_run(struct kccsrv_service *service);
385 static void kccsrv_periodic_handler_te(struct tevent_context *ev, struct tevent_timer *te,
386 struct timeval t, void *ptr)
388 struct kccsrv_service *service = talloc_get_type(ptr, struct kccsrv_service);
391 service->periodic.te = NULL;
393 kccsrv_periodic_run(service);
395 status = kccsrv_periodic_schedule(service, service->periodic.interval);
396 if (!W_ERROR_IS_OK(status)) {
397 task_server_terminate(service->task, win_errstr(status), true);
402 WERROR kccsrv_periodic_schedule(struct kccsrv_service *service, uint32_t next_interval)
405 struct tevent_timer *new_te;
406 struct timeval next_time;
408 /* prevent looping */
409 if (next_interval == 0) next_interval = 1;
411 next_time = timeval_current_ofs(next_interval, 50);
413 if (service->periodic.te) {
415 * if the timestamp of the new event is higher,
416 * as current next we don't need to reschedule
418 if (timeval_compare(&next_time, &service->periodic.next_event) > 0) {
423 /* reset the next scheduled timestamp */
424 service->periodic.next_event = next_time;
426 new_te = tevent_add_timer(service->task->event_ctx, service,
427 service->periodic.next_event,
428 kccsrv_periodic_handler_te, service);
429 W_ERROR_HAVE_NO_MEMORY(new_te);
431 tmp_mem = talloc_new(service);
432 DEBUG(4,("kccsrv_periodic_schedule(%u) %sscheduled for: %s\n",
434 (service->periodic.te?"re":""),
435 nt_time_string(tmp_mem, timeval_to_nttime(&next_time))));
436 talloc_free(tmp_mem);
438 talloc_free(service->periodic.te);
439 service->periodic.te = new_te;
444 static void kccsrv_periodic_run(struct kccsrv_service *service)
449 DEBUG(4,("kccsrv_periodic_run(): simple update\n"));
451 mem_ctx = talloc_new(service);
452 status = kccsrv_simple_update(service, mem_ctx);
453 if (!NT_STATUS_IS_OK(status)) {
454 DEBUG(0,("kccsrv_simple_update failed - %s\n", nt_errstr(status)));
457 status = kccsrv_check_deleted(service, mem_ctx);
458 if (!NT_STATUS_IS_OK(status)) {
459 DEBUG(0,("kccsrv_check_deleted failed - %s\n", nt_errstr(status)));
461 talloc_free(mem_ctx);