2 Unix SMB/CIFS implementation.
3 SMB torture tester - winbind struct based protocol
4 Copyright (C) Stefan Metzmacher 2007
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #include "torture/torture.h"
23 #include "torture/winbind/proto.h"
24 #include "nsswitch/winbind_client.h"
25 #include "libcli/security/security.h"
26 #include "librpc/gen_ndr/netlogon.h"
27 #include "param/param.h"
28 #include "auth/pam_errors.h"
30 #define DO_STRUCT_REQ_REP_EXT(op,req,rep,expected,strict,warnaction,cmt) do { \
31 NSS_STATUS __got, __expected = (expected); \
32 __got = winbindd_request_response(op, req, rep); \
33 if (__got != __expected) { \
34 const char *__cmt = (cmt); \
36 torture_result(torture, TORTURE_FAIL, \
37 __location__ ": " __STRING(op) \
38 " returned %d, expected %d%s%s", \
40 (__cmt) ? ": " : "", \
41 (__cmt) ? (__cmt) : ""); \
44 torture_warning(torture, \
45 __location__ ": " __STRING(op) \
46 " returned %d, expected %d%s%s", \
48 (__cmt) ? ": " : "", \
49 (__cmt) ? (__cmt) : ""); \
55 #define DO_STRUCT_REQ_REP(op,req,rep) do { \
56 bool __noop = false; \
57 DO_STRUCT_REQ_REP_EXT(op,req,rep,NSS_STATUS_SUCCESS,true,__noop=true,NULL); \
60 static bool torture_winbind_struct_interface_version(struct torture_context *torture)
62 struct winbindd_request req;
63 struct winbindd_response rep;
68 torture_comment(torture, "Running WINBINDD_INTERFACE_VERSION (struct based)\n");
70 DO_STRUCT_REQ_REP(WINBINDD_INTERFACE_VERSION, &req, &rep);
72 torture_assert_int_equal(torture,
73 rep.data.interface_version,
74 WINBIND_INTERFACE_VERSION,
75 "winbind server and client doesn't match");
80 static bool torture_winbind_struct_ping(struct torture_context *torture)
82 struct timeval tv = timeval_current();
83 int timelimit = torture_setting_int(torture, "timelimit", 5);
86 torture_comment(torture,
87 "Running WINBINDD_PING (struct based) for %d seconds\n",
90 while (timeval_elapsed(&tv) < timelimit) {
91 DO_STRUCT_REQ_REP(WINBINDD_PING, NULL, NULL);
95 torture_comment(torture,
96 "%u (%.1f/s) WINBINDD_PING (struct based)\n",
97 total, total / timeval_elapsed(&tv));
102 static bool torture_winbind_struct_info(struct torture_context *torture)
104 struct winbindd_response rep;
105 const char *separator;
109 torture_comment(torture, "Running WINBINDD_INFO (struct based)\n");
111 DO_STRUCT_REQ_REP(WINBINDD_INFO, NULL, &rep);
113 separator = torture_setting_string(torture,
114 "winbindd separator",
115 lp_winbind_separator());
116 torture_assert_int_equal(torture,
117 rep.data.info.winbind_separator,
119 "winbind separator doesn't match");
121 torture_comment(torture, "Samba Version '%s'\n",
122 rep.data.info.samba_version);
127 static bool torture_winbind_struct_priv_pipe_dir(struct torture_context *torture)
129 struct winbindd_response rep;
130 const char *default_dir;
131 const char *expected_dir;
136 torture_comment(torture, "Running WINBINDD_PRIV_PIPE_DIR (struct based)\n");
138 DO_STRUCT_REQ_REP(WINBINDD_PRIV_PIPE_DIR, NULL, &rep);
140 got_dir = (const char *)rep.extra_data.data;
142 torture_assert(torture, got_dir, "NULL WINBINDD_PRIV_PIPE_DIR\n");
144 default_dir = lock_path(torture, WINBINDD_PRIV_SOCKET_SUBDIR);
145 expected_dir = torture_setting_string(torture,
146 "winbindd private pipe dir",
149 torture_assert_str_equal(torture, got_dir, expected_dir,
150 "WINBINDD_PRIV_PIPE_DIR doesn't match");
152 SAFE_FREE(rep.extra_data.data);
156 static bool torture_winbind_struct_netbios_name(struct torture_context *torture)
158 struct winbindd_response rep;
159 const char *expected;
163 torture_comment(torture, "Running WINBINDD_NETBIOS_NAME (struct based)\n");
165 DO_STRUCT_REQ_REP(WINBINDD_NETBIOS_NAME, NULL, &rep);
167 expected = torture_setting_string(torture,
168 "winbindd netbios name",
171 torture_assert_str_equal(torture,
172 rep.data.netbios_name, expected,
173 "winbindd's netbios name doesn't match");
178 static bool torture_winbind_struct_domain_name(struct torture_context *torture)
180 struct winbindd_response rep;
181 const char *expected;
185 torture_comment(torture, "Running WINBINDD_DOMAIN_NAME (struct based)\n");
187 DO_STRUCT_REQ_REP(WINBINDD_DOMAIN_NAME, NULL, &rep);
189 expected = torture_setting_string(torture,
190 "winbindd netbios domain",
193 torture_assert_str_equal(torture,
194 rep.data.domain_name, expected,
195 "winbindd's netbios domain doesn't match");
200 static bool torture_winbind_struct_check_machacc(struct torture_context *torture)
203 bool strict = torture_setting_bool(torture, "strict mode", false);
204 struct winbindd_response rep;
208 torture_comment(torture, "Running WINBINDD_CHECK_MACHACC (struct based)\n");
211 DO_STRUCT_REQ_REP_EXT(WINBINDD_CHECK_MACHACC, NULL, &rep,
212 NSS_STATUS_SUCCESS, strict, ok = false,
213 "WINBINDD_CHECK_MACHACC");
216 torture_assert(torture,
217 strlen(rep.data.auth.nt_status_string)>0,
218 "Failed with empty nt_status_string");
220 torture_warning(torture,"%s:%s:%s:%d\n",
221 nt_errstr(NT_STATUS(rep.data.auth.nt_status)),
222 rep.data.auth.nt_status_string,
223 rep.data.auth.error_string,
224 rep.data.auth.pam_error);
228 torture_assert_ntstatus_ok(torture,
229 NT_STATUS(rep.data.auth.nt_status),
230 "WINBINDD_CHECK_MACHACC ok: nt_status");
232 torture_assert_str_equal(torture,
233 rep.data.auth.nt_status_string,
234 nt_errstr(NT_STATUS_OK),
235 "WINBINDD_CHECK_MACHACC ok:nt_status_string");
237 torture_assert_str_equal(torture,
238 rep.data.auth.error_string,
239 nt_errstr(NT_STATUS_OK),
240 "WINBINDD_CHECK_MACHACC ok: error_string");
242 torture_assert_int_equal(torture,
243 rep.data.auth.pam_error,
244 nt_status_to_pam(NT_STATUS_OK),
245 "WINBINDD_CHECK_MACHACC ok: pam_error");
250 struct torture_trust_domain {
251 const char *netbios_name;
252 const char *dns_name;
256 static bool get_trusted_domains(struct torture_context *torture,
257 struct torture_trust_domain **_d)
259 struct winbindd_request req;
260 struct winbindd_response rep;
261 struct torture_trust_domain *d = NULL;
264 const char *extra_data;
269 DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
271 extra_data = (char *)rep.extra_data.data;
272 torture_assert(torture, extra_data, "NULL trust list");
274 while (next_token(&extra_data, line, "\n", sizeof(fstring))) {
277 d = talloc_realloc(torture, d,
278 struct torture_trust_domain,
280 ZERO_STRUCT(d[dcount+1]);
283 p = strchr(lp, '\\');
284 torture_assert(torture, p, "missing 1st '\\' in line");
286 d[dcount].netbios_name = talloc_strdup(d, lp);
287 torture_assert(torture, strlen(d[dcount].netbios_name) > 0,
288 "empty netbios_name");
291 p = strchr(lp, '\\');
292 torture_assert(torture, p, "missing 2nd '\\' in line");
294 d[dcount].dns_name = talloc_strdup(d, lp);
295 /* it's ok to have an empty dns_name */
298 d[dcount].sid = dom_sid_parse_talloc(d, lp);
299 torture_assert(torture, d[dcount].sid,
300 "failed to parse sid");
304 SAFE_FREE(rep.extra_data.data);
306 torture_assert(torture, dcount >= 2,
307 "The list of trusted domain should contain 2 entries");
313 static bool torture_winbind_struct_list_trustdom(struct torture_context *torture)
315 struct winbindd_request req;
316 struct winbindd_response rep;
320 struct torture_trust_domain *listd = NULL;
323 torture_comment(torture, "Running WINBINDD_LIST_TRUSTDOM (struct based)\n");
328 req.data.list_all_domains = false;
330 DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
332 list1 = (char *)rep.extra_data.data;
333 torture_assert(torture, list1, "NULL trust list");
335 torture_comment(torture, "%s\n", list1);
340 req.data.list_all_domains = true;
342 DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
344 list2 = (char *)rep.extra_data.data;
345 torture_assert(torture, list2, "NULL trust list");
348 * The list_all_domains parameter should be ignored
350 torture_assert_str_equal(torture, list2, list1, "list_all_domains not ignored");
355 ok = get_trusted_domains(torture, &listd);
356 torture_assert(torture, ok, "failed to get trust list");
358 for (i=0; listd[i].netbios_name; i++) {
360 struct dom_sid *builtin_sid;
362 builtin_sid = dom_sid_parse_talloc(torture, SID_BUILTIN);
364 torture_assert_str_equal(torture,
365 listd[i].netbios_name,
367 "first domain should be 'BUILTIN'");
369 torture_assert_str_equal(torture,
372 "BUILTIN domain should not have a dns name");
374 ok = dom_sid_equal(builtin_sid,
376 torture_assert(torture, ok, "BUILTIN domain should have S-1-5-32");
382 * TODO: verify the content of the 2nd and 3rd (in member server mode)
390 static bool torture_winbind_struct_domain_info(struct torture_context *torture)
393 struct torture_trust_domain *listd = NULL;
396 torture_comment(torture, "Running WINBINDD_DOMAIN_INFO (struct based)\n");
398 ok = get_trusted_domains(torture, &listd);
399 torture_assert(torture, ok, "failed to get trust list");
401 for (i=0; listd[i].netbios_name; i++) {
402 struct winbindd_request req;
403 struct winbindd_response rep;
405 char *flagstr = talloc_strdup(torture," ");
410 fstrcpy(req.domain_name, listd[i].netbios_name);
412 DO_STRUCT_REQ_REP(WINBINDD_DOMAIN_INFO, &req, &rep);
414 torture_assert_str_equal(torture,
415 rep.data.domain_info.name,
416 listd[i].netbios_name,
417 "Netbios domain name doesn't match");
419 torture_assert_str_equal(torture,
420 rep.data.domain_info.alt_name,
422 "DNS domain name doesn't match");
424 sid = dom_sid_parse_talloc(torture, rep.data.domain_info.sid);
425 torture_assert(torture, sid, "Failed to parse SID");
427 ok = dom_sid_equal(listd[i].sid, sid);
428 torture_assert(torture, ok, "SID's doesn't match");
430 if (rep.data.domain_info.primary) {
431 flagstr = talloc_strdup_append(flagstr, "PR ");
434 if (rep.data.domain_info.active_directory) {
435 torture_assert(torture,
436 strlen(rep.data.domain_info.alt_name)>0,
437 "Active Directory without DNS name");
438 flagstr = talloc_strdup_append(flagstr, "AD ");
441 if (rep.data.domain_info.native_mode) {
442 torture_assert(torture,
443 rep.data.domain_info.active_directory,
444 "Native-Mode, but no Active Directory");
445 flagstr = talloc_strdup_append(flagstr, "NA ");
448 torture_comment(torture, "DOMAIN '%s' => '%s' [%s]\n",
449 rep.data.domain_info.name,
450 rep.data.domain_info.alt_name,
457 static bool torture_winbind_struct_getdcname(struct torture_context *torture)
460 bool strict = torture_setting_bool(torture, "strict mode", false);
461 struct torture_trust_domain *listd = NULL;
464 torture_comment(torture, "Running WINBINDD_GETDCNAME (struct based)\n");
466 ok = get_trusted_domains(torture, &listd);
467 torture_assert(torture, ok, "failed to get trust list");
469 for (i=0; listd[i].netbios_name; i++) {
470 struct winbindd_request req;
471 struct winbindd_response rep;
476 fstrcpy(req.domain_name, listd[i].netbios_name);
479 DO_STRUCT_REQ_REP_EXT(WINBINDD_GETDCNAME, &req, &rep,
481 (i <2 || strict), ok = false,
482 talloc_asprintf(torture, "DOMAIN '%s'",
486 /* TODO: check rep.data.dc_name; */
487 torture_comment(torture, "DOMAIN '%s' => DCNAME '%s'\n",
488 req.domain_name, rep.data.dc_name);
494 static bool torture_winbind_struct_dsgetdcname(struct torture_context *torture)
497 bool strict = torture_setting_bool(torture, "strict mode", false);
498 struct torture_trust_domain *listd = NULL;
502 torture_comment(torture, "Running WINBINDD_DSGETDCNAME (struct based)\n");
504 ok = get_trusted_domains(torture, &listd);
505 torture_assert(torture, ok, "failed to get trust list");
507 for (i=0; listd[i].netbios_name; i++) {
508 struct winbindd_request req;
509 struct winbindd_response rep;
514 if (strlen(listd[i].dns_name) == 0) continue;
517 * TODO: remove this and let winbindd give no dns name
520 if (strcmp(listd[i].dns_name, listd[i].netbios_name) == 0) {
524 fstrcpy(req.domain_name, listd[i].dns_name);
526 /* TODO: test more flag combinations */
527 req.flags = DS_DIRECTORY_SERVICE_REQUIRED;
530 DO_STRUCT_REQ_REP_EXT(WINBINDD_DSGETDCNAME, &req, &rep,
533 talloc_asprintf(torture, "DOMAIN '%s'",
537 /* TODO: check rep.data.dc_name; */
538 torture_comment(torture, "DOMAIN '%s' => DCNAME '%s'\n",
539 req.domain_name, rep.data.dc_name);
545 torture_warning(torture, "WINBINDD_DSGETDCNAME"
546 " was not tested with %d non-AD domains",
551 torture_assert(torture, count > 0,
552 "WiNBINDD_DSGETDCNAME was not tested");
558 struct torture_suite *torture_winbind_struct_init(void)
560 struct torture_suite *suite = torture_suite_create(talloc_autofree_context(), "STRUCT");
562 torture_suite_add_simple_test(suite, "INTERFACE_VERSION", torture_winbind_struct_interface_version);
563 torture_suite_add_simple_test(suite, "PING", torture_winbind_struct_ping);
564 torture_suite_add_simple_test(suite, "INFO", torture_winbind_struct_info);
565 torture_suite_add_simple_test(suite, "PRIV_PIPE_DIR", torture_winbind_struct_priv_pipe_dir);
566 torture_suite_add_simple_test(suite, "NETBIOS_NAME", torture_winbind_struct_netbios_name);
567 torture_suite_add_simple_test(suite, "DOMAIN_NAME", torture_winbind_struct_domain_name);
568 torture_suite_add_simple_test(suite, "CHECK_MACHACC", torture_winbind_struct_check_machacc);
569 torture_suite_add_simple_test(suite, "LIST_TRUSTDOM", torture_winbind_struct_list_trustdom);
570 torture_suite_add_simple_test(suite, "DOMAIN_INFO", torture_winbind_struct_domain_info);
571 torture_suite_add_simple_test(suite, "GETDCNAME", torture_winbind_struct_getdcname);
572 torture_suite_add_simple_test(suite, "DSGETDCNAME", torture_winbind_struct_dsgetdcname);
574 suite->description = talloc_strdup(suite, "WINBIND - struct based protocol tests");