2 * Unix SMB/CIFS implementation.
6 * Copyright (c) 2011 Andreas Schneider <asn@samba.org>
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, see <http://www.gnu.org/licenses/>.
27 #include "../lib/tsocket/tsocket.h"
28 #include "lib/server_prefork.h"
29 #include "lib/server_prefork_util.h"
30 #include "librpc/rpc/dcerpc_ep.h"
32 #include "rpc_server/rpc_server.h"
33 #include "rpc_server/rpc_ep_register.h"
34 #include "rpc_server/rpc_sock_helper.h"
36 #include "librpc/gen_ndr/srv_lsa.h"
37 #include "librpc/gen_ndr/srv_samr.h"
38 #include "librpc/gen_ndr/srv_netlogon.h"
40 #define DAEMON_NAME "lsasd"
41 #define LSASD_MAX_SOCKETS 64
43 static struct prefork_pool *lsasd_pool = NULL;
44 static int lsasd_child_id = 0;
46 static struct pf_daemon_config default_pf_lsasd_cfg = {
47 .prefork_status = PFH_INIT,
51 .max_allowed_clients = 100,
52 .child_min_life = 60 /* 1 minute minimum life time */
54 static struct pf_daemon_config pf_lsasd_cfg = { 0 };
56 void start_lsasd(struct tevent_context *ev_ctx,
57 struct messaging_context *msg_ctx);
59 static void lsasd_reopen_logs(int child_id)
61 char *lfile = lp_logfile();
66 rc = asprintf(&extension, "%s.%d", DAEMON_NAME, child_id);
68 rc = asprintf(&extension, "%s", DAEMON_NAME);
75 if (lfile == NULL || lfile[0] == '\0') {
76 rc = asprintf(&lfile, "%s/log.%s",
77 get_dyn_LOGFILEBASE(), extension);
79 if (strstr(lfile, extension) == NULL) {
81 rc = asprintf(&lfile, "%s.%d",
85 rc = asprintf(&lfile, "%s.%s",
93 lp_set_logfile(lfile);
102 static void lsasd_smb_conf_updated(struct messaging_context *msg,
105 struct server_id server_id,
108 struct tevent_context *ev_ctx;
110 DEBUG(10, ("Got message saying smb.conf was updated. Reloading.\n"));
111 ev_ctx = talloc_get_type_abort(private_data, struct tevent_context);
113 change_to_root_user();
114 lp_load(get_dyn_CONFIGFILE(), true, false, false, true);
116 lsasd_reopen_logs(lsasd_child_id);
117 if (lsasd_child_id == 0) {
118 pfh_daemon_config(DAEMON_NAME,
120 &default_pf_lsasd_cfg);
121 pfh_manage_pool(ev_ctx, msg, &pf_lsasd_cfg, lsasd_pool);
125 static void lsasd_sig_term_handler(struct tevent_context *ev,
126 struct tevent_signal *se,
132 rpc_netlogon_shutdown();
134 rpc_lsarpc_shutdown();
136 DEBUG(0, ("termination signal\n"));
140 static void lsasd_setup_sig_term_handler(struct tevent_context *ev_ctx)
142 struct tevent_signal *se;
144 se = tevent_add_signal(ev_ctx,
147 lsasd_sig_term_handler,
150 DEBUG(0, ("failed to setup SIGTERM handler\n"));
155 static void lsasd_sig_hup_handler(struct tevent_context *ev,
156 struct tevent_signal *se,
163 change_to_root_user();
164 lp_load(get_dyn_CONFIGFILE(), true, false, false, true);
166 lsasd_reopen_logs(lsasd_child_id);
167 pfh_daemon_config(DAEMON_NAME,
169 &default_pf_lsasd_cfg);
171 /* relay to all children */
172 prefork_send_signal_to_all(lsasd_pool, SIGHUP);
175 static void lsasd_setup_sig_hup_handler(struct tevent_context *ev_ctx)
177 struct tevent_signal *se;
179 se = tevent_add_signal(ev_ctx,
182 lsasd_sig_hup_handler,
185 DEBUG(0, ("failed to setup SIGHUP handler\n"));
190 /**********************************************************
192 **********************************************************/
194 struct lsasd_chld_sig_hup_ctx {
195 struct messaging_context *msg_ctx;
196 struct pf_worker_data *pf;
199 static void lsasd_chld_sig_hup_handler(struct tevent_context *ev,
200 struct tevent_signal *se,
206 struct pf_worker_data *pf = (struct pf_worker_data *)pvt;
208 /* avoid wasting CPU cycles if we are going to exit soon anyways */
209 if (pf->cmds == PF_SRV_MSG_EXIT) {
213 change_to_root_user();
214 lsasd_reopen_logs(lsasd_child_id);
217 static bool lsasd_setup_chld_hup_handler(struct tevent_context *ev_ctx,
218 struct pf_worker_data *pf)
220 struct tevent_signal *se;
222 se = tevent_add_signal(ev_ctx,
225 lsasd_chld_sig_hup_handler,
228 DEBUG(1, ("failed to setup SIGHUP handler"));
235 static bool lsasd_child_init(struct tevent_context *ev_ctx,
237 struct pf_worker_data *pf)
240 struct messaging_context *msg_ctx = server_messaging_context();
243 status = reinit_after_fork(msg_ctx, ev_ctx,
244 procid_self(), true);
245 if (!NT_STATUS_IS_OK(status)) {
246 DEBUG(0,("reinit_after_fork() failed\n"));
247 smb_panic("reinit_after_fork() failed");
250 lsasd_child_id = child_id;
251 lsasd_reopen_logs(child_id);
253 ok = lsasd_setup_chld_hup_handler(ev_ctx, pf);
258 if (!serverid_register(procid_self(), FLAG_MSG_GENERAL)) {
262 messaging_register(msg_ctx, ev_ctx,
263 MSG_SMB_CONF_UPDATED, lsasd_smb_conf_updated);
265 status = rpc_lsarpc_init(NULL);
266 if (!NT_STATUS_IS_OK(status)) {
267 DEBUG(0, ("Failed to register lsarpc rpc inteface! (%s)\n",
272 status = rpc_samr_init(NULL);
273 if (!NT_STATUS_IS_OK(status)) {
274 DEBUG(0, ("Failed to register samr rpc inteface! (%s)\n",
279 status = rpc_netlogon_init(NULL);
280 if (!NT_STATUS_IS_OK(status)) {
281 DEBUG(0, ("Failed to register netlogon rpc inteface! (%s)\n",
289 struct lsasd_children_data {
290 struct tevent_context *ev_ctx;
291 struct messaging_context *msg_ctx;
292 struct pf_worker_data *pf;
300 static void lsasd_next_client(void *pvt);
302 static int lsasd_children_main(struct tevent_context *ev_ctx,
303 struct messaging_context *msg_ctx,
304 struct pf_worker_data *pf,
311 struct lsasd_children_data *data;
315 ok = lsasd_child_init(ev_ctx, child_id, pf);
320 data = talloc(ev_ctx, struct lsasd_children_data);
325 data->ev_ctx = ev_ctx;
326 data->msg_ctx = msg_ctx;
327 data->lock_fd = lock_fd;
328 data->listen_fd_size = listen_fd_size;
329 data->listen_fds = listen_fds;
330 data->listening = false;
332 /* loop until it is time to exit */
333 while (pf->status != PF_WORKER_EXITING) {
334 /* try to see if it is time to schedule the next client */
335 lsasd_next_client(data);
337 ret = tevent_loop_once(ev_ctx);
339 DEBUG(0, ("tevent_loop_once() exited with %d: %s\n",
340 ret, strerror(errno)));
341 pf->status = PF_WORKER_EXITING;
348 static void lsasd_client_terminated(void *pvt)
350 struct lsasd_children_data *data;
352 data = talloc_get_type_abort(pvt, struct lsasd_children_data);
354 if (data->pf->num_clients) {
355 data->pf->num_clients--;
357 DEBUG(2, ("Invalid num clients, aborting!\n"));
358 data->pf->status = PF_WORKER_EXITING;
362 lsasd_next_client(pvt);
365 struct lsasd_new_client {
366 struct lsasd_children_data *data;
369 static void lsasd_handle_client(struct tevent_req *req);
371 static void lsasd_next_client(void *pvt)
373 struct tevent_req *req;
374 struct lsasd_children_data *data;
375 struct lsasd_new_client *next;
377 data = talloc_get_type_abort(pvt, struct lsasd_children_data);
379 if (data->pf->num_clients == 0) {
380 data->pf->status = PF_WORKER_IDLE;
383 if (data->pf->cmds == PF_SRV_MSG_EXIT) {
384 DEBUG(2, ("Parent process commands we terminate!\n"));
388 if (data->listening ||
389 data->pf->num_clients >= data->pf->allowed_clients) {
390 /* nothing to do for now we are already listening
391 * or reached the number of clients we are allowed
392 * to handle in parallel */
396 next = talloc_zero(data, struct lsasd_new_client);
398 DEBUG(1, ("Out of memory!?\n"));
403 req = prefork_listen_send(next,
406 data->listen_fd_size,
410 DEBUG(1, ("Failed to make listening request!?\n"));
414 tevent_req_set_callback(req, lsasd_handle_client, next);
416 data->listening = true;
419 static void lsasd_handle_client(struct tevent_req *req)
421 struct lsasd_children_data *data;
422 struct lsasd_new_client *client;
426 struct tsocket_address *srv_addr;
427 struct tsocket_address *cli_addr;
429 client = tevent_req_callback_data(req, struct lsasd_new_client);
432 tmp_ctx = talloc_stackframe();
433 if (tmp_ctx == NULL) {
434 DEBUG(1, ("Failed to allocate stackframe!\n"));
438 rc = prefork_listen_recv(req,
444 /* this will free the request too */
446 /* we are done listening */
447 data->listening = false;
450 DEBUG(1, ("Failed to accept client connection!\n"));
451 /* bail out if we are not serving any other client */
452 if (data->pf->num_clients == 0) {
453 data->pf->status = PF_WORKER_EXITING;
459 DEBUG(1, ("Server asks us to die!\n"));
460 data->pf->status = PF_WORKER_EXITING;
464 DEBUG(2, ("LSASD preforked child %d got client connection!\n",
465 (int)(data->pf->pid)));
467 if (tsocket_address_is_inet(srv_addr, "ip")) {
468 DEBUG(3, ("Got a tcpip client connection from %s on inteface %s\n",
469 tsocket_address_string(cli_addr, tmp_ctx),
470 tsocket_address_string(srv_addr, tmp_ctx)));
472 dcerpc_ncacn_accept(data->ev_ctx,
480 } else if (tsocket_address_is_unix(srv_addr)) {
483 p = tsocket_address_unix_path(srv_addr, tmp_ctx);
485 talloc_free(tmp_ctx);
489 if (strstr(p, "/np/")) {
492 named_pipe_accept_function(data->ev_ctx,
496 lsasd_client_terminated,
501 dcerpc_ncacn_accept(data->ev_ctx,
511 DEBUG(0, ("ERROR: Unsupported socket!\n"));
514 talloc_free(tmp_ctx);
521 static bool lsasd_schedule_check(struct tevent_context *ev_ctx,
522 struct messaging_context *msg_ctx,
523 struct timeval current_time);
525 static void lsasd_check_children(struct tevent_context *ev_ctx,
526 struct tevent_timer *te,
527 struct timeval current_time,
530 static void lsasd_sigchld_handler(struct tevent_context *ev_ctx,
531 struct prefork_pool *pfp,
534 struct messaging_context *msg_ctx;
536 msg_ctx = talloc_get_type_abort(pvt, struct messaging_context);
538 /* run pool management so we can fork/retire or increase
539 * the allowed connections per child based on load */
540 pfh_manage_pool(ev_ctx, msg_ctx, &pf_lsasd_cfg, lsasd_pool);
543 static bool lsasd_setup_children_monitor(struct tevent_context *ev_ctx,
544 struct messaging_context *msg_ctx)
548 /* add our oun sigchld callback */
549 prefork_set_sigchld_callback(lsasd_pool, lsasd_sigchld_handler, msg_ctx);
551 ok = lsasd_schedule_check(ev_ctx, msg_ctx, tevent_timeval_current());
556 static bool lsasd_schedule_check(struct tevent_context *ev_ctx,
557 struct messaging_context *msg_ctx,
558 struct timeval current_time)
560 struct tevent_timer *te;
561 struct timeval next_event;
563 /* check situation again in 10 seconds */
564 next_event = tevent_timeval_current_ofs(10, 0);
566 /* TODO: check when the socket becomes readable, so that children
567 * are checked only when there is some activity ? */
568 te = tevent_add_timer(ev_ctx, lsasd_pool, next_event,
569 lsasd_check_children, msg_ctx);
571 DEBUG(2, ("Failed to set up children monitoring!\n"));
578 static void lsasd_check_children(struct tevent_context *ev_ctx,
579 struct tevent_timer *te,
580 struct timeval current_time,
583 struct messaging_context *msg_ctx;
585 msg_ctx = talloc_get_type_abort(pvt, struct messaging_context);
587 pfh_manage_pool(ev_ctx, msg_ctx, &pf_lsasd_cfg, lsasd_pool);
589 lsasd_schedule_check(ev_ctx, msg_ctx, current_time);
596 static bool lsasd_create_sockets(struct tevent_context *ev_ctx,
597 struct messaging_context *msg_ctx,
601 struct dcerpc_binding_vector *v, *v_orig;
609 tmp_ctx = talloc_stackframe();
610 if (tmp_ctx == NULL) {
614 status = dcerpc_binding_vector_new(tmp_ctx, &v_orig);
615 if (!NT_STATUS_IS_OK(status)) {
620 /* Create only one tcpip listener for all services */
621 status = rpc_create_tcpip_sockets(&ndr_table_lsarpc,
626 if (!NT_STATUS_IS_OK(status)) {
631 /* Start to listen on tcpip sockets */
632 for (i = 0; i < *listen_fd_size; i++) {
633 rc = listen(listen_fd[i], pf_lsasd_cfg.max_allowed_clients);
635 DEBUG(0, ("Failed to listen on tcpip socket - %s\n",
643 fd = create_named_pipe_socket("lsarpc");
648 listen_fd[*listen_fd_size] = fd;
651 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
653 DEBUG(0, ("Failed to listen on lsarpc pipe - %s\n",
659 v = dcerpc_binding_vector_dup(tmp_ctx, v_orig);
665 status = dcerpc_binding_vector_replace_iface(&ndr_table_lsarpc, v);
666 if (!NT_STATUS_IS_OK(status)) {
670 status = dcerpc_binding_vector_add_np_default(&ndr_table_lsarpc, v);
671 if (!NT_STATUS_IS_OK(status)) {
676 status = rpc_ep_register(ev_ctx, msg_ctx, &ndr_table_lsarpc, v);
677 if (!NT_STATUS_IS_OK(status)) {
683 fd = create_named_pipe_socket("samr");
689 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
691 DEBUG(0, ("Failed to listen on samr pipe - %s\n",
696 listen_fd[*listen_fd_size] = fd;
699 v = dcerpc_binding_vector_dup(tmp_ctx, v_orig);
705 status = dcerpc_binding_vector_replace_iface(&ndr_table_samr, v);
706 if (!NT_STATUS_IS_OK(status)) {
710 status = dcerpc_binding_vector_add_np_default(&ndr_table_samr, v);
711 if (!NT_STATUS_IS_OK(status)) {
716 status = rpc_ep_register(ev_ctx, msg_ctx, &ndr_table_samr, v);
717 if (!NT_STATUS_IS_OK(status)) {
723 fd = create_named_pipe_socket("netlogon");
729 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
731 DEBUG(0, ("Failed to listen on samr pipe - %s\n",
736 listen_fd[*listen_fd_size] = fd;
739 v = dcerpc_binding_vector_dup(tmp_ctx, v_orig);
745 status = dcerpc_binding_vector_replace_iface(&ndr_table_netlogon, v);
746 if (!NT_STATUS_IS_OK(status)) {
750 status = dcerpc_binding_vector_add_np_default(&ndr_table_netlogon, v);
751 if (!NT_STATUS_IS_OK(status)) {
756 status = rpc_ep_register(ev_ctx, msg_ctx, &ndr_table_netlogon, v);
757 if (!NT_STATUS_IS_OK(status)) {
763 talloc_free(tmp_ctx);
767 void start_lsasd(struct tevent_context *ev_ctx,
768 struct messaging_context *msg_ctx)
771 int listen_fd[LSASD_MAX_SOCKETS];
772 int listen_fd_size = 0;
777 DEBUG(1, ("Forking LSA Service Daemon\n"));
780 * Block signals before forking child as it will have to
781 * set its own handlers. Child will re-enable SIGHUP as
782 * soon as the handlers are set up.
784 BlockSignals(true, SIGTERM);
785 BlockSignals(true, SIGHUP);
789 DEBUG(0, ("Failed to fork LSASD [%s], aborting ...\n",
794 /* parent or error */
797 /* Re-enable SIGHUP before returnig */
798 BlockSignals(false, SIGTERM);
799 BlockSignals(false, SIGHUP);
805 close_low_fds(false);
807 status = reinit_after_fork(msg_ctx,
809 procid_self(), true);
810 if (!NT_STATUS_IS_OK(status)) {
811 DEBUG(0,("reinit_after_fork() failed\n"));
812 smb_panic("reinit_after_fork() failed");
815 lsasd_reopen_logs(0);
816 pfh_daemon_config(DAEMON_NAME,
818 &default_pf_lsasd_cfg);
820 lsasd_setup_sig_term_handler(ev_ctx);
821 lsasd_setup_sig_hup_handler(ev_ctx);
823 BlockSignals(false, SIGTERM);
824 BlockSignals(false, SIGHUP);
826 ok = lsasd_create_sockets(ev_ctx, msg_ctx, listen_fd, &listen_fd_size);
831 /* start children before any more initialization is done */
832 ok = prefork_create_pool(ev_ctx, /* mem_ctx */
837 pf_lsasd_cfg.min_children,
838 pf_lsasd_cfg.max_children,
839 &lsasd_children_main,
846 if (!serverid_register(procid_self(), FLAG_MSG_GENERAL)) {
850 messaging_register(msg_ctx,
852 MSG_SMB_CONF_UPDATED,
853 lsasd_smb_conf_updated);
855 status = rpc_lsarpc_init(NULL);
856 if (!NT_STATUS_IS_OK(status)) {
857 DEBUG(0, ("Failed to register winreg rpc inteface! (%s)\n",
862 status = rpc_samr_init(NULL);
863 if (!NT_STATUS_IS_OK(status)) {
864 DEBUG(0, ("Failed to register lsasd rpc inteface! (%s)\n",
869 status = rpc_netlogon_init(NULL);
870 if (!NT_STATUS_IS_OK(status)) {
871 DEBUG(0, ("Failed to register lsasd rpc inteface! (%s)\n",
876 ok = lsasd_setup_children_monitor(ev_ctx, msg_ctx);
878 DEBUG(0, ("Failed to setup children monitoring!\n"));
882 DEBUG(1, ("LSASD Daemon Started (%d)\n", getpid()));
885 rc = tevent_loop_wait(ev_ctx);
887 /* should not be reached */
888 DEBUG(0,("lsasd: tevent_loop_wait() exited with %d - %s\n",
889 rc, (rc == 0) ? "out of events" : strerror(errno)));