2 Unix SMB/CIFS mplementation.
3 DSDB replication service
5 Copyright (C) Stefan Metzmacher 2007
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program. If not, see <http://www.gnu.org/licenses/>.
23 #include "dsdb/samdb/samdb.h"
24 #include "auth/auth.h"
25 #include "smbd/service.h"
26 #include "lib/events/events.h"
27 #include "lib/messaging/irpc.h"
28 #include "dsdb/repl/drepl_service.h"
29 #include "lib/ldb/include/ldb_errors.h"
30 #include "../lib/util/dlinklist.h"
31 #include "librpc/gen_ndr/ndr_misc.h"
32 #include "librpc/gen_ndr/ndr_drsuapi.h"
33 #include "librpc/gen_ndr/ndr_drsblobs.h"
34 #include "libcli/security/dom_sid.h"
35 #include "param/param.h"
37 WERROR dreplsrv_load_partitions(struct dreplsrv_service *s)
40 struct ldb_dn *basedn;
42 struct ldb_message_element *el;
43 static const char *attrs[] = { "hasMasterNCs", "msDS-hasFullReplicaNCs", NULL };
47 basedn = samdb_ntds_settings_dn(s->samdb);
48 W_ERROR_HAVE_NO_MEMORY(basedn);
50 ret = ldb_search(s->samdb, s, &r, basedn, LDB_SCOPE_BASE, attrs,
52 if (ret != LDB_SUCCESS) {
54 } else if (r->count != 1) {
61 el = ldb_msg_find_element(r->msgs[0], "hasMasterNCs");
63 for (i=0; el && i < el->num_values; i++) {
64 const char *v = (const char *)el->values[i].data;
66 struct dreplsrv_partition *p;
68 pdn = ldb_dn_new(s, s->samdb, v);
69 if (!ldb_dn_validate(pdn)) {
73 p = talloc_zero(s, struct dreplsrv_partition);
74 W_ERROR_HAVE_NO_MEMORY(p);
76 p->dn = talloc_steal(p, pdn);
78 DLIST_ADD(s->partitions, p);
80 DEBUG(2, ("dreplsrv_partition[%s] loaded\n", v));
83 el = ldb_msg_find_element(r->msgs[0], "msDS-hasFullReplicaNCs");
85 for (i=0; el && i < el->num_values; i++) {
86 const char *v = (const char *)el->values[i].data;
88 struct dreplsrv_partition *p;
90 pdn = ldb_dn_new(s, s->samdb, v);
91 if (!ldb_dn_validate(pdn)) {
95 p = talloc_zero(s, struct dreplsrv_partition);
96 W_ERROR_HAVE_NO_MEMORY(p);
98 p->dn = talloc_steal(p, pdn);
99 p->incoming_only = true;
101 DLIST_ADD(s->partitions, p);
103 DEBUG(2, ("dreplsrv_partition[%s] loaded (incoming only)\n", v));
108 status = dreplsrv_refresh_partitions(s);
109 W_ERROR_NOT_OK_RETURN(status);
114 WERROR dreplsrv_out_connection_attach(struct dreplsrv_service *s,
115 const struct repsFromTo1 *rft,
116 struct dreplsrv_out_connection **_conn)
118 struct dreplsrv_out_connection *cur, *conn = NULL;
119 const char *hostname;
121 if (!rft->other_info) {
125 if (!rft->other_info->dns_name) {
129 hostname = rft->other_info->dns_name;
131 for (cur = s->connections; cur; cur = cur->next) {
132 if (strcmp(cur->binding->host, hostname) == 0) {
142 conn = talloc_zero(s, struct dreplsrv_out_connection);
143 W_ERROR_HAVE_NO_MEMORY(conn);
147 binding_str = talloc_asprintf(conn, "ncacn_ip_tcp:%s[krb5,seal]",
149 W_ERROR_HAVE_NO_MEMORY(binding_str);
150 nt_status = dcerpc_parse_binding(conn, binding_str, &conn->binding);
151 talloc_free(binding_str);
152 if (!NT_STATUS_IS_OK(nt_status)) {
153 return ntstatus_to_werror(nt_status);
156 DLIST_ADD_END(s->connections, conn, struct dreplsrv_out_connection *);
158 DEBUG(2,("dreplsrv_out_connection_attach(%s): create\n", conn->binding->host));
160 DEBUG(2,("dreplsrv_out_connection_attach(%s): attach\n", conn->binding->host));
167 static WERROR dreplsrv_partition_add_source_dsa(struct dreplsrv_service *s,
168 struct dreplsrv_partition *p,
169 const struct ldb_val *val)
172 enum ndr_err_code ndr_err;
173 struct dreplsrv_partition_source_dsa *source, *s2;
175 source = talloc_zero(p, struct dreplsrv_partition_source_dsa);
176 W_ERROR_HAVE_NO_MEMORY(source);
178 ndr_err = ndr_pull_struct_blob(val, source,
179 &source->_repsFromBlob,
180 (ndr_pull_flags_fn_t)ndr_pull_repsFromToBlob);
181 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
182 NTSTATUS nt_status = ndr_map_error2ntstatus(ndr_err);
184 return ntstatus_to_werror(nt_status);
186 /* NDR_PRINT_DEBUG(repsFromToBlob, &source->_repsFromBlob); */
187 if (source->_repsFromBlob.version != 1) {
189 return WERR_DS_DRA_INTERNAL_ERROR;
192 source->partition = p;
193 source->repsFrom1 = &source->_repsFromBlob.ctr.ctr1;
195 status = dreplsrv_out_connection_attach(s, source->repsFrom1, &source->conn);
196 W_ERROR_NOT_OK_RETURN(status);
198 /* remove any existing source with the same GUID */
199 for (s2=p->sources; s2; s2=s2->next) {
200 if (GUID_compare(&s2->repsFrom1->source_dsa_obj_guid,
201 &source->repsFrom1->source_dsa_obj_guid) == 0) {
202 talloc_free(s2->repsFrom1->other_info);
203 *s2->repsFrom1 = *source->repsFrom1;
204 talloc_steal(s2, s2->repsFrom1->other_info);
210 DLIST_ADD_END(p->sources, source, struct dreplsrv_partition_source_dsa *);
214 WERROR dreplsrv_partition_find_for_nc(struct dreplsrv_service *s,
215 const struct GUID *nc_guid,
216 const struct dom_sid *nc_sid,
217 const char *nc_dn_str,
218 struct dreplsrv_partition **_p)
220 struct dreplsrv_partition *p;
221 bool valid_sid, valid_guid;
222 struct dom_sid null_sid;
223 ZERO_STRUCT(null_sid);
227 valid_sid = nc_sid && !dom_sid_equal(&null_sid, nc_sid);
228 valid_guid = nc_guid && !GUID_all_zero(nc_guid);
230 if (!valid_sid && !valid_guid && !nc_dn_str) {
231 return WERR_DS_DRA_INVALID_PARAMETER;
234 for (p = s->partitions; p; p = p->next) {
235 if ((valid_guid && GUID_equal(&p->nc.guid, nc_guid))
236 || strequal(p->nc.dn, nc_dn_str)
237 || (valid_sid && dom_sid_equal(&p->nc.sid, nc_sid)))
244 return WERR_DS_DRA_BAD_NC;
247 WERROR dreplsrv_partition_source_dsa_by_guid(struct dreplsrv_partition *p,
248 const struct GUID *dsa_guid,
249 struct dreplsrv_partition_source_dsa **_dsa)
251 struct dreplsrv_partition_source_dsa *dsa;
253 SMB_ASSERT(dsa_guid != NULL);
254 SMB_ASSERT(!GUID_all_zero(dsa_guid));
257 for (dsa = p->sources; dsa; dsa = dsa->next) {
258 if (GUID_equal(dsa_guid, &dsa->repsFrom1->source_dsa_obj_guid)) {
264 return WERR_DS_DRA_NO_REPLICA;
267 WERROR dreplsrv_partition_source_dsa_by_dns(const struct dreplsrv_partition *p,
269 struct dreplsrv_partition_source_dsa **_dsa)
271 struct dreplsrv_partition_source_dsa *dsa;
273 SMB_ASSERT(dsa_dns != NULL);
276 for (dsa = p->sources; dsa; dsa = dsa->next) {
277 if (strequal(dsa_dns, dsa->repsFrom1->other_info->dns_name)) {
283 return WERR_DS_DRA_NO_REPLICA;
287 static WERROR dreplsrv_refresh_partition(struct dreplsrv_service *s,
288 struct dreplsrv_partition *p)
291 struct dom_sid *nc_sid;
292 struct ldb_message_element *orf_el = NULL;
293 struct ldb_result *r;
296 TALLOC_CTX *mem_ctx = talloc_new(p);
297 static const char *attrs[] = {
304 DEBUG(2, ("dreplsrv_refresh_partition(%s)\n",
305 ldb_dn_get_linearized(p->dn)));
307 ret = ldb_search(s->samdb, mem_ctx, &r, p->dn, LDB_SCOPE_BASE, attrs,
309 if (ret != LDB_SUCCESS) {
310 talloc_free(mem_ctx);
314 talloc_free(discard_const(p->nc.dn));
316 p->nc.dn = ldb_dn_alloc_linearized(p, p->dn);
317 W_ERROR_HAVE_NO_MEMORY(p->nc.dn);
318 p->nc.guid = samdb_result_guid(r->msgs[0], "objectGUID");
319 nc_sid = samdb_result_dom_sid(p, r->msgs[0], "objectSid");
325 talloc_free(p->uptodatevector.cursors);
326 talloc_free(p->uptodatevector_ex.cursors);
327 ZERO_STRUCT(p->uptodatevector);
328 ZERO_STRUCT(p->uptodatevector_ex);
330 ret = dsdb_load_udv_v2(s->samdb, p->dn, p, &p->uptodatevector.cursors, &p->uptodatevector.count);
331 if (ret != LDB_SUCCESS) {
332 DEBUG(4,(__location__ ": no UDV available for %s\n", ldb_dn_get_linearized(p->dn)));
335 orf_el = ldb_msg_find_element(r->msgs[0], "repsFrom");
337 for (i=0; i < orf_el->num_values; i++) {
338 status = dreplsrv_partition_add_source_dsa(s, p, &orf_el->values[i]);
339 W_ERROR_NOT_OK_RETURN(status);
343 talloc_free(mem_ctx);
348 WERROR dreplsrv_refresh_partitions(struct dreplsrv_service *s)
351 struct dreplsrv_partition *p;
353 for (p = s->partitions; p; p = p->next) {
354 status = dreplsrv_refresh_partition(s, p);
355 W_ERROR_NOT_OK_RETURN(status);