s3-selftest Add tests to show kerberos works across a password change
[samba.git] / selftest / target / Samba3.pm
1 #!/usr/bin/perl
2 # Bootstrap Samba and run a number of tests against it.
3 # Copyright (C) 2005-2007 Jelmer Vernooij <jelmer@samba.org>
4 # Published under the GNU GPL, v3 or later.
5
6 package Samba3;
7
8 use strict;
9 use Cwd qw(abs_path);
10 use FindBin qw($RealBin);
11 use POSIX;
12
13 sub binpath($$)
14 {
15         my ($self, $binary) = @_;
16
17         if (defined($self->{bindir})) {
18                 my $path = "$self->{bindir}/$binary";
19                 -f $path or die("File $path doesn't exist");
20                 return $path;
21         }
22
23         return $binary;
24 }
25
26 sub new($$) {
27         my ($classname, $bindir, $srcdir) = @_;
28         my $self = { bindir => $bindir,
29                      srcdir => $srcdir
30         };
31         bless $self;
32         return $self;
33 }
34
35 sub teardown_env($$)
36 {
37         my ($self, $envvars) = @_;
38
39         my $smbdpid = read_pid($envvars, "smbd");
40         my $nmbdpid = read_pid($envvars, "nmbd");
41         my $winbinddpid = read_pid($envvars, "winbindd");
42
43         $self->stop_sig_term($smbdpid);
44         $self->stop_sig_term($nmbdpid);
45         $self->stop_sig_term($winbinddpid);
46
47         sleep(2);
48
49         $self->stop_sig_kill($smbdpid);
50         $self->stop_sig_kill($nmbdpid);
51         $self->stop_sig_kill($winbinddpid);
52
53         return 0;
54 }
55
56 sub getlog_env_app($$$)
57 {
58         my ($self, $envvars, $name) = @_;
59
60         my $title = "$name LOG of: $envvars->{NETBIOSNAME}\n";
61         my $out = $title;
62
63         open(LOG, "<".$envvars->{$name."_TEST_LOG"});
64
65         seek(LOG, $envvars->{$name."_TEST_LOG_POS"}, SEEK_SET);
66         while (<LOG>) {
67                 $out .= $_;
68         }
69         $envvars->{$name."_TEST_LOG_POS"} = tell(LOG);
70         close(LOG);
71
72         return "" if $out eq $title;
73  
74         return $out;
75 }
76
77 sub getlog_env($$)
78 {
79         my ($self, $envvars) = @_;
80         my $ret = "";
81
82         $ret .= $self->getlog_env_app($envvars, "SMBD");
83         $ret .= $self->getlog_env_app($envvars, "NMBD");
84         $ret .= $self->getlog_env_app($envvars, "WINBINDD");
85
86         return $ret;
87 }
88
89 sub check_env($$)
90 {
91         my ($self, $envvars) = @_;
92
93         # TODO ...
94         return 1;
95 }
96
97 sub setup_env($$$)
98 {
99         my ($self, $envname, $path) = @_;
100         
101         if ($envname eq "dc") {
102                 return $self->setup_dc("$path/dc");
103         } elsif ($envname eq "secshare") {
104                 return $self->setup_secshare("$path/secshare");
105         } elsif ($envname eq "ktest") {
106                 return $self->setup_ktest("$path/ktest");
107         } elsif ($envname eq "secserver") {
108                 if (not defined($self->{vars}->{dc})) {
109                         $self->setup_dc("$path/dc");
110                 }
111                 return $self->setup_secserver("$path/secserver", $self->{vars}->{dc});
112         } elsif ($envname eq "member") {
113                 if (not defined($self->{vars}->{dc})) {
114                         $self->setup_dc("$path/dc");
115                 }
116                 return $self->setup_member("$path/member", $self->{vars}->{dc});
117         } else {
118                 return undef;
119         }
120 }
121
122 sub setup_dc($$)
123 {
124         my ($self, $path) = @_;
125
126         print "PROVISIONING DC...";
127
128         my $dc_options = "
129         domain master = yes
130         domain logons = yes
131         lanman auth = yes
132 ";
133
134         my $vars = $self->provision($path,
135                                     "LOCALDC2",
136                                     2,
137                                     "localdc2pass",
138                                     $dc_options);
139
140         $self->check_or_start($vars,
141                               ($ENV{SMBD_MAXTIME} or 2700),
142                                "yes", "yes", "yes");
143
144         $self->wait_for_start($vars);
145
146         $vars->{DC_SERVER} = $vars->{SERVER};
147         $vars->{DC_SERVER_IP} = $vars->{SERVER_IP};
148         $vars->{DC_NETBIOSNAME} = $vars->{NETBIOSNAME};
149         $vars->{DC_USERNAME} = $vars->{USERNAME};
150         $vars->{DC_PASSWORD} = $vars->{PASSWORD};
151
152         $self->{vars}->{dc} = $vars;
153
154         return $vars;
155 }
156
157 sub setup_member($$$)
158 {
159         my ($self, $prefix, $dcvars) = @_;
160
161         print "PROVISIONING MEMBER...";
162
163         my $member_options = "
164         security = domain
165         server signing = on
166 ";
167         my $ret = $self->provision($prefix,
168                                    "LOCALMEMBER3",
169                                    3,
170                                    "localmember3pass",
171                                    $member_options);
172
173         $ret or die("Unable to provision");
174
175         my $net = $self->binpath("net");
176         my $cmd = "";
177         $cmd .= "SOCKET_WRAPPER_DEFAULT_IFACE=\"$ret->{SOCKET_WRAPPER_DEFAULT_IFACE}\" ";
178         $cmd .= "$net join $ret->{CONFIGURATION} $dcvars->{DOMAIN} member";
179         $cmd .= " -U$dcvars->{USERNAME}\%$dcvars->{PASSWORD}";
180
181         system($cmd) == 0 or die("Join failed\n$cmd");
182
183         $self->check_or_start($ret,
184                               ($ENV{SMBD_MAXTIME} or 2700),
185                                "yes", "yes", "yes");
186
187         $self->wait_for_start($ret);
188
189         $ret->{DC_SERVER} = $dcvars->{SERVER};
190         $ret->{DC_SERVER_IP} = $dcvars->{SERVER_IP};
191         $ret->{DC_NETBIOSNAME} = $dcvars->{NETBIOSNAME};
192         $ret->{DC_USERNAME} = $dcvars->{USERNAME};
193         $ret->{DC_PASSWORD} = $dcvars->{PASSWORD};
194
195         return $ret;
196 }
197
198 sub setup_secshare($$)
199 {
200         my ($self, $path) = @_;
201
202         print "PROVISIONING server with security=share...";
203
204         my $secshare_options = "
205         security = share
206         lanman auth = yes
207 ";
208
209         my $vars = $self->provision($path,
210                                     "LOCALSHARE4",
211                                     4,
212                                     "local4pass",
213                                     $secshare_options);
214
215         $self->check_or_start($vars,
216                               ($ENV{SMBD_MAXTIME} or 2700),
217                                "yes", "no", "yes");
218
219         $self->wait_for_start($vars);
220
221         $self->{vars}->{secshare} = $vars;
222
223         return $vars;
224 }
225
226 sub setup_secserver($$$)
227 {
228         my ($self, $prefix, $dcvars) = @_;
229
230         print "PROVISIONING server with security=server...";
231
232         my $secserver_options = "
233         security = server
234         password server = $dcvars->{SERVER_IP}
235 ";
236
237         my $ret = $self->provision($prefix,
238                                    "LOCALSERVER5",
239                                    5,
240                                    "localserver5pass",
241                                    $secserver_options);
242
243         $ret or die("Unable to provision");
244
245         $self->check_or_start($ret,
246                               ($ENV{SMBD_MAXTIME} or 2700),
247                                "yes", "no", "yes");
248
249         $self->wait_for_start($ret);
250
251         $ret->{DC_SERVER} = $dcvars->{SERVER};
252         $ret->{DC_SERVER_IP} = $dcvars->{SERVER_IP};
253         $ret->{DC_NETBIOSNAME} = $dcvars->{NETBIOSNAME};
254         $ret->{DC_USERNAME} = $dcvars->{USERNAME};
255         $ret->{DC_PASSWORD} = $dcvars->{PASSWORD};
256
257         return $ret;
258 }
259
260 sub setup_ktest($$$)
261 {
262         my ($self, $prefix, $dcvars) = @_;
263
264         print "PROVISIONING server with security=ads...";
265
266         my $ktest_options = "
267         workgroup = KTEST
268         realm = ktest.samba.example.com
269         security = ads
270         username map = $prefix/lib/username.map
271 ";
272
273         my $ret = $self->provision($prefix,
274                                    "LOCALKTEST6",
275                                    5,
276                                    "localktest6pass",
277                                    $ktest_options);
278
279         $ret or die("Unable to provision");
280
281         open(USERMAP, ">$prefix/lib/username.map") or die("Unable to open $prefix/lib/username.map");
282         print USERMAP "
283 $ret->{USERNAME} = KTEST\\Administrator
284 ";
285         close(USERMAP);
286
287 #This is the secrets.tdb created by 'net ads join' from Samba3 to a
288 #Samba4 DC with the same parameters as are being used here.  The
289 #domain SID is S-1-5-21-1071277805-689288055-3486227160
290
291         system("cp $self->{srcdir}/source3/selftest/ktest-secrets.tdb $prefix/private/secrets.tdb");
292         chmod 0600, "$prefix/private/secrets.tdb";
293
294 #This uses a pre-calculated krb5 credentials cache, obtained by running Samba4 with:
295 # "--option=kdc:service ticket lifetime=239232" "--option=kdc:user ticket lifetime=239232" "--option=kdc:renewal lifetime=239232"
296 #
297 #and having in krb5.conf:
298 # ticket_lifetime = 799718400
299 # renew_lifetime = 799718400
300 #
301 # The commands for the -2 keytab where were:
302 # kinit administrator@KTEST.SAMBA.EXAMPLE.COM
303 # kvno host/localktest6@KTEST.SAMBA.EXAMPLE.COM
304 # kvno cifs/localktest6@KTEST.SAMBA.EXAMPLE.COM
305 # kvno host/LOCALKTEST6@KTEST.SAMBA.EXAMPLE.COM
306 # kvno cifs/LOCALKTEST6@KTEST.SAMBA.EXAMPLE.COM
307 #
308 # and then for the -3 keytab, I did
309 #
310 # net changetrustpw; kdestroy and the same again.
311 #
312 # This creates a credential cache with a very long lifetime (2036 at
313 # at 2011-04), and shows that running 'net changetrustpw' does not
314 # break existing logins (for the secrets.tdb method at least).
315 #
316
317         $ret->{KRB5_CCACHE}="FILE:$prefix/krb5_ccache";
318
319         system("cp $self->{srcdir}/source3/selftest/ktest-krb5_ccache-2 $prefix/krb5_ccache-2");
320         chmod 0600, "$prefix/krb5_ccache-2";
321
322         system("cp $self->{srcdir}/source3/selftest/ktest-krb5_ccache-3 $prefix/krb5_ccache-3");
323         chmod 0600, "$prefix/krb5_ccache-3";
324
325         $self->check_or_start($ret,
326                               ($ENV{SMBD_MAXTIME} or 2700),
327                                "yes", "no", "yes");
328
329         $self->wait_for_start($ret);
330         return $ret;
331 }
332
333 sub stop_sig_term($$) {
334         my ($self, $pid) = @_;
335         kill("USR1", $pid) or kill("ALRM", $pid) or warn("Unable to kill $pid: $!");
336 }
337
338 sub stop_sig_kill($$) {
339         my ($self, $pid) = @_;
340         kill("ALRM", $pid) or warn("Unable to kill $pid: $!");
341 }
342
343 sub write_pid($$$)
344 {
345         my ($env_vars, $app, $pid) = @_;
346
347         open(PID, ">$env_vars->{PIDDIR}/timelimit.$app.pid");
348         print PID $pid;
349         close(PID);
350 }
351
352 sub read_pid($$)
353 {
354         my ($env_vars, $app) = @_;
355
356         open(PID, "<$env_vars->{PIDDIR}/timelimit.$app.pid");
357         my $pid = <PID>;
358         close(PID);
359         return $pid;
360 }
361
362 sub check_or_start($$$$$) {
363         my ($self, $env_vars, $maxtime, $nmbd, $winbindd, $smbd) = @_;
364
365         unlink($env_vars->{NMBD_TEST_LOG});
366         print "STARTING NMBD...";
367         my $pid = fork();
368         if ($pid == 0) {
369                 open STDOUT, ">$env_vars->{NMBD_TEST_LOG}";
370                 open STDERR, '>&STDOUT';
371
372                 SocketWrapper::set_default_iface($env_vars->{SOCKET_WRAPPER_DEFAULT_IFACE});
373
374                 $ENV{WINBINDD_SOCKET_DIR} = $env_vars->{WINBINDD_SOCKET_DIR};
375                 $ENV{NMBD_SOCKET_DIR} = $env_vars->{NMBD_SOCKET_DIR};
376
377                 $ENV{NSS_WRAPPER_PASSWD} = $env_vars->{NSS_WRAPPER_PASSWD};
378                 $ENV{NSS_WRAPPER_GROUP} = $env_vars->{NSS_WRAPPER_GROUP};
379                 $ENV{NSS_WRAPPER_WINBIND_SO_PATH} = $env_vars->{NSS_WRAPPER_WINBIND_SO_PATH};
380
381                 if ($nmbd ne "yes") {
382                         $SIG{USR1} = $SIG{ALRM} = $SIG{INT} = $SIG{QUIT} = $SIG{TERM} = sub {
383                                 my $signame = shift;
384                                 print("Skip nmbd received signal $signame");
385                                 exit 0;
386                         };
387                         sleep($maxtime);
388                         exit 0;
389                 }
390
391                 my @optargs = ("-d0");
392                 if (defined($ENV{NMBD_OPTIONS})) {
393                         @optargs = split(/ /, $ENV{NMBD_OPTIONS});
394                 }
395
396                 $ENV{MAKE_TEST_BINARY} = $self->binpath("nmbd");
397
398                 my @preargs = ($self->binpath("timelimit"), $maxtime);
399                 if(defined($ENV{NMBD_VALGRIND})) { 
400                         @preargs = split(/ /, $ENV{NMBD_VALGRIND});
401                 }
402
403                 exec(@preargs, $self->binpath("nmbd"), "-F", "--no-process-group", "-S", "-s", $env_vars->{SERVERCONFFILE}, @optargs) or die("Unable to start nmbd: $!");
404         }
405         write_pid($env_vars, "nmbd", $pid);
406         print "DONE\n";
407
408         unlink($env_vars->{WINBINDD_TEST_LOG});
409         print "STARTING WINBINDD...";
410         $pid = fork();
411         if ($pid == 0) {
412                 open STDOUT, ">$env_vars->{WINBINDD_TEST_LOG}";
413                 open STDERR, '>&STDOUT';
414
415                 SocketWrapper::set_default_iface($env_vars->{SOCKET_WRAPPER_DEFAULT_IFACE});
416
417                 $ENV{WINBINDD_SOCKET_DIR} = $env_vars->{WINBINDD_SOCKET_DIR};
418                 $ENV{NMBD_SOCKET_DIR} = $env_vars->{NMBD_SOCKET_DIR};
419
420                 $ENV{NSS_WRAPPER_PASSWD} = $env_vars->{NSS_WRAPPER_PASSWD};
421                 $ENV{NSS_WRAPPER_GROUP} = $env_vars->{NSS_WRAPPER_GROUP};
422                 $ENV{NSS_WRAPPER_WINBIND_SO_PATH} = $env_vars->{NSS_WRAPPER_WINBIND_SO_PATH};
423
424                 if ($winbindd ne "yes") {
425                         $SIG{USR1} = $SIG{ALRM} = $SIG{INT} = $SIG{QUIT} = $SIG{TERM} = sub {
426                                 my $signame = shift;
427                                 print("Skip winbindd received signal $signame");
428                                 exit 0;
429                         };
430                         sleep($maxtime);
431                         exit 0;
432                 }
433
434                 my @optargs = ("-d0");
435                 if (defined($ENV{WINBINDD_OPTIONS})) {
436                         @optargs = split(/ /, $ENV{WINBINDD_OPTIONS});
437                 }
438
439                 $ENV{MAKE_TEST_BINARY} = $self->binpath("winbindd");
440
441                 my @preargs = ($self->binpath("timelimit"), $maxtime);
442                 if(defined($ENV{WINBINDD_VALGRIND})) {
443                         @preargs = split(/ /, $ENV{WINBINDD_VALGRIND});
444                 }
445
446                 exec(@preargs, $self->binpath("winbindd"), "-F", "--no-process-group", "-s", $env_vars->{SERVERCONFFILE}, @optargs) or die("Unable to start winbindd: $!");
447         }
448         write_pid($env_vars, "winbindd", $pid);
449         print "DONE\n";
450
451         unlink($env_vars->{SMBD_TEST_LOG});
452         print "STARTING SMBD...";
453         $pid = fork();
454         if ($pid == 0) {
455                 open STDOUT, ">$env_vars->{SMBD_TEST_LOG}";
456                 open STDERR, '>&STDOUT';
457
458                 SocketWrapper::set_default_iface($env_vars->{SOCKET_WRAPPER_DEFAULT_IFACE});
459
460                 $ENV{WINBINDD_SOCKET_DIR} = $env_vars->{WINBINDD_SOCKET_DIR};
461                 $ENV{NMBD_SOCKET_DIR} = $env_vars->{NMBD_SOCKET_DIR};
462
463                 $ENV{NSS_WRAPPER_PASSWD} = $env_vars->{NSS_WRAPPER_PASSWD};
464                 $ENV{NSS_WRAPPER_GROUP} = $env_vars->{NSS_WRAPPER_GROUP};
465                 $ENV{NSS_WRAPPER_WINBIND_SO_PATH} = $env_vars->{NSS_WRAPPER_WINBIND_SO_PATH};
466
467                 if ($smbd ne "yes") {
468                         $SIG{USR1} = $SIG{ALRM} = $SIG{INT} = $SIG{QUIT} = $SIG{TERM} = sub {
469                                 my $signame = shift;
470                                 print("Skip smbd received signal $signame");
471                                 exit 0;
472                         };
473                         sleep($maxtime);
474                         exit 0;
475                 }
476
477                 $ENV{MAKE_TEST_BINARY} = $self->binpath("smbd");
478                 my @optargs = ("-d0");
479                 if (defined($ENV{SMBD_OPTIONS})) {
480                         @optargs = split(/ /, $ENV{SMBD_OPTIONS});
481                 }
482                 my @preargs = ($self->binpath("timelimit"), $maxtime);
483                 if(defined($ENV{SMBD_VALGRIND})) {
484                         @preargs = split(/ /,$ENV{SMBD_VALGRIND});
485                 }
486                 exec(@preargs, $self->binpath("smbd"), "-F", "--no-process-group", "-s", $env_vars->{SERVERCONFFILE}, @optargs) or die("Unable to start smbd: $!");
487         }
488         write_pid($env_vars, "smbd", $pid);
489         print "DONE\n";
490
491         return 0;
492 }
493
494 sub provision($$$$$$)
495 {
496         my ($self, $prefix, $server, $swiface, $password, $extra_options) = @_;
497
498         ##
499         ## setup the various environment variables we need
500         ##
501
502         my %ret = ();
503         my $server_ip = "127.0.0.$swiface";
504         my $domain = "SAMBA-TEST";
505
506         my $unix_name = ($ENV{USER} or $ENV{LOGNAME} or `PATH=/usr/ucb:$ENV{PATH} whoami`);
507         chomp $unix_name;
508         my $unix_uid = $>;
509         my $unix_gids_str = $);
510         my @unix_gids = split(" ", $unix_gids_str);
511
512         my $prefix_abs = abs_path($prefix);
513         my $bindir_abs = abs_path($self->{bindir});
514         my $vfs_modulesdir_abs = ($ENV{VFSLIBDIR} or $bindir_abs);
515
516         my @dirs = ();
517
518         my $shrdir="$prefix_abs/share";
519         push(@dirs,$shrdir);
520
521         my $libdir="$prefix_abs/lib";
522         push(@dirs,$libdir);
523
524         my $piddir="$prefix_abs/pid";
525         push(@dirs,$piddir);
526
527         my $privatedir="$prefix_abs/private";
528         push(@dirs,$privatedir);
529
530         my $lockdir="$prefix_abs/lockdir";
531         push(@dirs,$lockdir);
532
533         my $eventlogdir="$prefix_abs/lockdir/eventlog";
534         push(@dirs,$eventlogdir);
535
536         my $logdir="$prefix_abs/logs";
537         push(@dirs,$logdir);
538
539         my $driver32dir="$shrdir/W32X86";
540         push(@dirs,$driver32dir);
541
542         my $driver64dir="$shrdir/x64";
543         push(@dirs,$driver64dir);
544
545         my $driver40dir="$shrdir/WIN40";
546         push(@dirs,$driver40dir);
547
548         my $ro_shrdir="$shrdir/root-tmp";
549         push(@dirs,$ro_shrdir);
550
551         my $msdfs_shrdir="$shrdir/msdfsshare";
552         push(@dirs,$msdfs_shrdir);
553
554         my $msdfs_deeppath="$msdfs_shrdir/deeppath";
555         push(@dirs,$msdfs_deeppath);
556
557         # this gets autocreated by winbindd
558         my $wbsockdir="$prefix_abs/winbindd";
559         my $wbsockprivdir="$lockdir/winbindd_privileged";
560
561         my $nmbdsockdir="$prefix_abs/nmbd";
562         unlink($nmbdsockdir);
563
564         ## 
565         ## create the test directory layout
566         ##
567         die ("prefix_abs = ''") if $prefix_abs eq "";
568         die ("prefix_abs = '/'") if $prefix_abs eq "/";
569
570         mkdir($prefix_abs, 0777);
571         print "CREATE TEST ENVIRONMENT IN '$prefix'...";
572         system("rm -rf $prefix_abs/*");
573         mkdir($_, 0777) foreach(@dirs);
574
575         ##
576         ## create ro and msdfs share layout
577         ##
578
579         chmod 0755, $ro_shrdir;
580         my $unreadable_file = "$ro_shrdir/unreadable_file";
581         open(UNREADABLE_FILE, ">$unreadable_file") or die("Unable to open $unreadable_file");
582         close(UNREADABLE_FILE);
583         chmod 0600, $unreadable_file;
584
585         my $msdfs_target = "$ro_shrdir/msdfs-target";
586         open(MSDFS_TARGET, ">$msdfs_target") or die("Unable to open $msdfs_target");
587         close(MSDFS_TARGET);
588         chmod 0666, $msdfs_target;
589         symlink "msdfs:$server_ip\\ro-tmp", "$msdfs_shrdir/msdfs-src1";
590         symlink "msdfs:$server_ip\\ro-tmp", "$msdfs_shrdir/deeppath/msdfs-src2";
591
592         my $conffile="$libdir/server.conf";
593
594         my $nss_wrapper_pl = "$ENV{PERL} $self->{srcdir}/lib/nss_wrapper/nss_wrapper.pl";
595         my $nss_wrapper_passwd = "$privatedir/passwd";
596         my $nss_wrapper_group = "$privatedir/group";
597
598         my $mod_printer_pl = "$ENV{PERL} $self->{srcdir}/source3/script/tests/printing/modprinter.pl";
599
600         my @eventlog_list = ("dns server", "application");
601
602         ##
603         ## calculate uids and gids
604         ##
605
606         my ($max_uid, $max_gid);
607         my ($uid_nobody, $uid_root);
608         my ($gid_nobody, $gid_nogroup, $gid_root, $gid_domusers);
609
610         if ($unix_uid < 0xffff - 2) {
611                 $max_uid = 0xffff;
612         } else {
613                 $max_uid = $unix_uid;
614         }
615
616         $uid_root = $max_uid - 1;
617         $uid_nobody = $max_uid - 2;
618
619         if ($unix_gids[0] < 0xffff - 3) {
620                 $max_gid = 0xffff;
621         } else {
622                 $max_gid = $unix_gids[0];
623         }
624
625         $gid_nobody = $max_gid - 1;
626         $gid_nogroup = $max_gid - 2;
627         $gid_root = $max_gid - 3;
628         $gid_domusers = $max_gid - 4;
629
630         ##
631         ## create conffile
632         ##
633
634         open(CONF, ">$conffile") or die("Unable to open $conffile");
635         print CONF "
636 [global]
637         netbios name = $server
638         interfaces = $server_ip/8
639         bind interfaces only = yes
640         panic action = $self->{srcdir}/selftest/gdb_backtrace %d %\$(MAKE_TEST_BINARY)
641
642         workgroup = $domain
643
644         private dir = $privatedir
645         pid directory = $piddir
646         lock directory = $lockdir
647         log file = $logdir/log.\%m
648         log level = 0
649         debug pid = yes
650         max log size = 0
651
652         name resolve order = bcast
653
654         state directory = $lockdir
655         cache directory = $lockdir
656
657         passdb backend = tdbsam
658
659         time server = yes
660
661         add user script =               $nss_wrapper_pl --passwd_path $nss_wrapper_passwd --type passwd --action add --name %u --gid $gid_nogroup
662         add group script =              $nss_wrapper_pl --group_path  $nss_wrapper_group  --type group  --action add --name %g
663         add machine script =            $nss_wrapper_pl --passwd_path $nss_wrapper_passwd --type passwd --action add --name %u --gid $gid_nogroup
664         add user to group script =      $nss_wrapper_pl --passwd_path $nss_wrapper_passwd --type member --action add --member %u --name %g --group_path $nss_wrapper_group
665         delete user script =            $nss_wrapper_pl --passwd_path $nss_wrapper_passwd --type passwd --action delete --name %u
666         delete group script =           $nss_wrapper_pl --group_path  $nss_wrapper_group  --type group  --action delete --name %g
667         delete user from group script = $nss_wrapper_pl --passwd_path $nss_wrapper_passwd --type member --action delete --member %u --name %g --group_path $nss_wrapper_group
668
669         addprinter command =            $mod_printer_pl -a -s $conffile --
670         deleteprinter command =         $mod_printer_pl -d -s $conffile --
671
672         eventlog list = application \"dns server\"
673
674         kernel oplocks = no
675         kernel change notify = no
676
677         syslog = no
678         printing = bsd
679         printcap name = /dev/null
680
681         winbindd:socket dir = $wbsockdir
682         nmbd:socket dir = $nmbdsockdir
683         idmap config * : range = 100000-200000
684         winbind enum users = yes
685         winbind enum groups = yes
686
687 #       min receivefile size = 4000
688
689         max protocol = SMB2
690         read only = no
691         server signing = auto
692
693         smbd:sharedelay = 100000
694 #       smbd:writetimeupdatedelay = 500000
695         map hidden = no
696         map system = no
697         map readonly = no
698         store dos attributes = yes
699         create mask = 755
700         vfs objects = $vfs_modulesdir_abs/xattr_tdb.so $vfs_modulesdir_abs/streams_depot.so
701
702         printing = vlp
703         print command = $bindir_abs/vlp tdbfile=$lockdir/vlp.tdb print %p %s
704         lpq command = $bindir_abs/vlp tdbfile=$lockdir/vlp.tdb lpq %p
705         lp rm command = $bindir_abs/vlp tdbfile=$lockdir/vlp.tdb lprm %p %j
706         lp pause command = $bindir_abs/vlp tdbfile=$lockdir/vlp.tdb lppause %p %j
707         lp resume command = $bindir_abs/vlp tdbfile=$lockdir/vlp.tdb lpresume %p %j
708         queue pause command = $bindir_abs/vlp tdbfile=$lockdir/vlp.tdb queuepause %p
709         queue resume command = $bindir_abs/vlp tdbfile=$lockdir/vlp.tdb queueresume %p
710         lpq cache time = 0
711
712         ncalrpc dir = $lockdir/ncalrpc
713         rpc_server:epmapper = embedded
714
715         # Begin extra options
716         $extra_options
717         # End extra options
718
719         #Include user defined custom parameters if set
720 ";
721
722         if (defined($ENV{INCLUDE_CUSTOM_CONF})) {
723                 print CONF "\t$ENV{INCLUDE_CUSTOM_CONF}\n";
724         }
725
726         print CONF "
727 [tmp]
728         path = $shrdir
729 [tmpguest]
730         path = $shrdir
731         guest ok = yes
732 [guestonly]
733         path = $shrdir
734         guest only = yes
735         guest ok = yes
736 [forceuser]
737         path = $shrdir
738         force user = $unix_name
739         guest ok = yes
740 [forcegroup]
741         path = $shrdir
742         force group = nogroup
743         guest ok = yes
744 [ro-tmp]
745         path = $ro_shrdir
746         guest ok = yes
747 [msdfs-share]
748         path = $msdfs_shrdir
749         msdfs root = yes
750         guest ok = yes
751 [hideunread]
752         copy = tmp
753         hide unreadable = yes
754 [tmpcase]
755         copy = tmp
756         case sensitive = yes
757 [hideunwrite]
758         copy = tmp
759         hide unwriteable files = yes
760 [print1]
761         copy = tmp
762         printable = yes
763
764 [print2]
765         copy = print1
766 [print3]
767         copy = print1
768 [lp]
769         copy = print1
770 [print\$]
771         copy = tmp
772         ";
773         close(CONF);
774
775         ##
776         ## create a test account
777         ##
778
779         open(PASSWD, ">$nss_wrapper_passwd") or die("Unable to open $nss_wrapper_passwd");
780         print PASSWD "nobody:x:$uid_nobody:$gid_nobody:nobody gecos:$prefix_abs:/bin/false
781 $unix_name:x:$unix_uid:$unix_gids[0]:$unix_name gecos:$prefix_abs:/bin/false
782 ";
783         if ($unix_uid != 0) {
784                 print PASSWD "root:x:$uid_root:$gid_root:root gecos:$prefix_abs:/bin/false";
785         }
786         close(PASSWD);
787
788         open(GROUP, ">$nss_wrapper_group") or die("Unable to open $nss_wrapper_group");
789         print GROUP "nobody:x:$gid_nobody:
790 nogroup:x:$gid_nogroup:nobody
791 $unix_name-group:x:$unix_gids[0]:
792 domusers:X:$gid_domusers:
793 ";
794         if ($unix_gids[0] != 0) {
795                 print GROUP "root:x:$gid_root:";
796         }
797
798         close(GROUP);
799
800         foreach my $evlog (@eventlog_list) {
801                 my $evlogtdb = "$eventlogdir/$evlog.tdb";
802                 open(EVENTLOG, ">$evlogtdb") or die("Unable to open $evlogtdb");
803                 close(EVENTLOG);
804         }
805
806         $ENV{NSS_WRAPPER_PASSWD} = $nss_wrapper_passwd;
807         $ENV{NSS_WRAPPER_GROUP} = $nss_wrapper_group;
808
809         open(PWD, "|".$self->binpath("smbpasswd")." -c $conffile -L -s -a $unix_name >/dev/null");
810         print PWD "$password\n$password\n";
811         close(PWD) or die("Unable to set password for test account");
812
813         print "DONE\n";
814
815         open(HOSTS, ">>$ENV{SELFTEST_PREFIX}/dns_host_file") or die("Unable to open $ENV{SELFTEST_PREFIX}/dns_host_file");
816         print HOSTS "A $server $server_ip
817 ";
818         close(HOSTS);
819
820         $ret{SERVER_IP} = $server_ip;
821         $ret{NMBD_TEST_LOG} = "$prefix/nmbd_test.log";
822         $ret{NMBD_TEST_LOG_POS} = 0;
823         $ret{WINBINDD_TEST_LOG} = "$prefix/winbindd_test.log";
824         $ret{WINBINDD_TEST_LOG_POS} = 0;
825         $ret{SMBD_TEST_LOG} = "$prefix/smbd_test.log";
826         $ret{SMBD_TEST_LOG_POS} = 0;
827         $ret{SERVERCONFFILE} = $conffile;
828         $ret{CONFIGURATION} ="-s $conffile";
829         $ret{SERVER} = $server;
830         $ret{USERNAME} = $unix_name;
831         $ret{USERID} = $unix_uid;
832         $ret{DOMAIN} = $domain;
833         $ret{NETBIOSNAME} = $server;
834         $ret{PASSWORD} = $password;
835         $ret{PIDDIR} = $piddir;
836         $ret{WINBINDD_SOCKET_DIR} = $wbsockdir;
837         $ret{WINBINDD_PRIV_PIPE_DIR} = $wbsockprivdir;
838         $ret{NMBD_SOCKET_DIR} = $nmbdsockdir;
839         $ret{SOCKET_WRAPPER_DEFAULT_IFACE} = $swiface;
840         $ret{NSS_WRAPPER_PASSWD} = $nss_wrapper_passwd;
841         $ret{NSS_WRAPPER_GROUP} = $nss_wrapper_group;
842         $ret{NSS_WRAPPER_WINBIND_SO_PATH} = $ENV{NSS_WRAPPER_WINBIND_SO_PATH};
843         $ret{LOCAL_PATH} = "$shrdir";
844
845         return \%ret;
846 }
847
848 sub wait_for_start($$)
849 {
850         my ($self, $envvars) = @_;
851
852         # give time for nbt server to register its names
853         print "delaying for nbt name registration\n";
854         sleep(10);
855         # This will return quickly when things are up, but be slow if we need to wait for (eg) SSL init 
856         system($self->binpath("nmblookup") ." $envvars->{CONFIGURATION} -U $envvars->{SERVER_IP} __SAMBA__");
857         system($self->binpath("nmblookup") ." $envvars->{CONFIGURATION} __SAMBA__");
858         system($self->binpath("nmblookup") ." $envvars->{CONFIGURATION} -U 127.255.255.255 __SAMBA__");
859         system($self->binpath("nmblookup") ." $envvars->{CONFIGURATION} -U $envvars->{SERVER_IP} $envvars->{SERVER}");
860         system($self->binpath("nmblookup") ." $envvars->{CONFIGURATION} $envvars->{SERVER}");
861         # make sure smbd is also up set
862         print "wait for smbd\n";
863         system($self->binpath("smbclient") ." $envvars->{CONFIGURATION} -L $envvars->{SERVER_IP} -U% -p 139 | head -2");
864         system($self->binpath("smbclient") ." $envvars->{CONFIGURATION} -L $envvars->{SERVER_IP} -U% -p 139 | head -2");
865
866         # Ensure we have domain users mapped.
867         system($self->binpath("net") ." $envvars->{CONFIGURATION} groupmap add rid=513 unixgroup=domusers type=domain");
868
869         print $self->getlog_env($envvars);
870 }
871
872 1;