31c5b8cf96b022e652eb0406800c4f169854abd0
[kai/samba-autobuild/.git] / source4 / torture / winbind / struct_based.c
1 /*
2    Unix SMB/CIFS implementation.
3    SMB torture tester - winbind struct based protocol
4    Copyright (C) Stefan Metzmacher 2007
5    Copyright (C) Michael Adam 2007
6
7    This program is free software; you can redistribute it and/or modify
8    it under the terms of the GNU General Public License as published by
9    the Free Software Foundation; either version 3 of the License, or
10    (at your option) any later version.
11
12    This program is distributed in the hope that it will be useful,
13    but WITHOUT ANY WARRANTY; without even the implied warranty of
14    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15    GNU General Public License for more details.
16
17    You should have received a copy of the GNU General Public License
18    along with this program.  If not, see <http://www.gnu.org/licenses/>.
19 */
20
21 #include "includes.h"
22 #include "pstring.h"
23 #include "torture/torture.h"
24 #include "torture/winbind/proto.h"
25 #include "nsswitch/winbind_client.h"
26 #include "libcli/security/security.h"
27 #include "librpc/gen_ndr/netlogon.h"
28 #include "param/param.h"
29 #include "auth/ntlm/pam_errors.h"
30
31 #define DO_STRUCT_REQ_REP_EXT(op,req,rep,expected,strict,warnaction,cmt) do { \
32         NSS_STATUS __got, __expected = (expected); \
33         __got = winbindd_request_response(op, req, rep); \
34         if (__got != __expected) { \
35                 const char *__cmt = (cmt); \
36                 if (strict) { \
37                         torture_result(torture, TORTURE_FAIL, \
38                                 __location__ ": " __STRING(op) \
39                                 " returned %d, expected %d%s%s", \
40                                 __got, __expected, \
41                                 (__cmt) ? ": " : "", \
42                                 (__cmt) ? (__cmt) : ""); \
43                         return false; \
44                 } else { \
45                         torture_warning(torture, \
46                                 __location__ ": " __STRING(op) \
47                                 " returned %d, expected %d%s%s", \
48                                 __got, __expected, \
49                                 (__cmt) ? ": " : "", \
50                                 (__cmt) ? (__cmt) : ""); \
51                         warnaction; \
52                 } \
53         } \
54 } while(0)
55
56 #define DO_STRUCT_REQ_REP(op,req,rep) do { \
57         bool __noop = false; \
58         DO_STRUCT_REQ_REP_EXT(op,req,rep,NSS_STATUS_SUCCESS,true,__noop=true,NULL); \
59 } while (0)
60
61 static bool torture_winbind_struct_interface_version(struct torture_context *torture)
62 {
63         struct winbindd_request req;
64         struct winbindd_response rep;
65
66         ZERO_STRUCT(req);
67         ZERO_STRUCT(rep);
68
69         torture_comment(torture, "Running WINBINDD_INTERFACE_VERSION (struct based)\n");
70
71         DO_STRUCT_REQ_REP(WINBINDD_INTERFACE_VERSION, &req, &rep);
72
73         torture_assert_int_equal(torture,
74                                  rep.data.interface_version,
75                                  WINBIND_INTERFACE_VERSION,
76                                  "winbind server and client doesn't match");
77
78         return true;
79 }
80
81 static bool torture_winbind_struct_ping(struct torture_context *torture)
82 {
83         struct timeval tv = timeval_current();
84         int timelimit = torture_setting_int(torture, "timelimit", 5);
85         uint32_t total = 0;
86
87         torture_comment(torture,
88                         "Running WINBINDD_PING (struct based) for %d seconds\n",
89                         timelimit);
90
91         while (timeval_elapsed(&tv) < timelimit) {
92                 DO_STRUCT_REQ_REP(WINBINDD_PING, NULL, NULL);
93                 total++;
94         }
95
96         torture_comment(torture,
97                         "%u (%.1f/s) WINBINDD_PING (struct based)\n",
98                         total, total / timeval_elapsed(&tv));
99
100         return true;
101 }
102
103
104 static char winbind_separator(struct torture_context *torture)
105 {
106         struct winbindd_response rep;
107
108         ZERO_STRUCT(rep);
109
110         DO_STRUCT_REQ_REP(WINBINDD_INFO, NULL, &rep);
111
112         return rep.data.info.winbind_separator;
113 }
114
115 static bool torture_winbind_struct_info(struct torture_context *torture)
116 {
117         struct winbindd_response rep;
118         const char *separator;
119
120         ZERO_STRUCT(rep);
121
122         torture_comment(torture, "Running WINBINDD_INFO (struct based)\n");
123
124         DO_STRUCT_REQ_REP(WINBINDD_INFO, NULL, &rep);
125
126         separator = torture_setting_string(torture,
127                                            "winbindd separator",
128                                            lp_winbind_separator(torture->lp_ctx));
129         torture_assert_int_equal(torture,
130                                  rep.data.info.winbind_separator,
131                                  *separator,
132                                  "winbind separator doesn't match");
133
134         torture_comment(torture, "Samba Version '%s'\n",
135                         rep.data.info.samba_version);
136
137         return true;
138 }
139
140 static bool torture_winbind_struct_priv_pipe_dir(struct torture_context *torture)
141 {
142         struct winbindd_response rep;
143         const char *default_dir;
144         const char *expected_dir;
145         const char *got_dir;
146
147         ZERO_STRUCT(rep);
148
149         torture_comment(torture, "Running WINBINDD_PRIV_PIPE_DIR (struct based)\n");
150
151         DO_STRUCT_REQ_REP(WINBINDD_PRIV_PIPE_DIR, NULL, &rep);
152
153         got_dir = (const char *)rep.extra_data.data;
154
155         torture_assert(torture, got_dir, "NULL WINBINDD_PRIV_PIPE_DIR\n");
156
157         default_dir = lock_path(torture, torture->lp_ctx, 
158                                 WINBINDD_PRIV_SOCKET_SUBDIR);
159         expected_dir = torture_setting_string(torture,
160                                               "winbindd private pipe dir",
161                                               default_dir);
162
163         torture_assert_str_equal(torture, got_dir, expected_dir,
164                                  "WINBINDD_PRIV_PIPE_DIR doesn't match");
165
166         SAFE_FREE(rep.extra_data.data);
167         return true;
168 }
169
170 static bool torture_winbind_struct_netbios_name(struct torture_context *torture)
171 {
172         struct winbindd_response rep;
173         const char *expected;
174
175         ZERO_STRUCT(rep);
176
177         torture_comment(torture, "Running WINBINDD_NETBIOS_NAME (struct based)\n");
178
179         DO_STRUCT_REQ_REP(WINBINDD_NETBIOS_NAME, NULL, &rep);
180
181         expected = torture_setting_string(torture,
182                                           "winbindd netbios name",
183                                           lp_netbios_name(torture->lp_ctx));
184         expected = strupper_talloc(torture, expected);
185         
186         torture_assert_str_equal(torture,
187                                  rep.data.netbios_name, expected,
188                                  "winbindd's netbios name doesn't match");
189
190         return true;
191 }
192
193 static bool get_winbind_domain(struct torture_context *torture, char **domain)
194 {
195         struct winbindd_response rep;
196
197         ZERO_STRUCT(rep);
198
199         DO_STRUCT_REQ_REP(WINBINDD_DOMAIN_NAME, NULL, &rep);
200
201         *domain = talloc_strdup(torture, rep.data.domain_name);
202         torture_assert(torture, domain, "talloc error");
203
204         return true;
205 }
206
207 static bool torture_winbind_struct_domain_name(struct torture_context *torture)
208 {
209         const char *expected;
210         char *domain;
211
212         torture_comment(torture, "Running WINBINDD_DOMAIN_NAME (struct based)\n");
213
214         expected = torture_setting_string(torture,
215                                           "winbindd netbios domain",
216                                           lp_workgroup(torture->lp_ctx));
217
218         get_winbind_domain(torture, &domain);
219
220         torture_assert_str_equal(torture, domain, expected,
221                                  "winbindd's netbios domain doesn't match");
222
223         return true;
224 }
225
226 static bool torture_winbind_struct_check_machacc(struct torture_context *torture)
227 {
228         bool ok;
229         bool strict = torture_setting_bool(torture, "strict mode", false);
230         struct winbindd_response rep;
231
232         ZERO_STRUCT(rep);
233
234         torture_comment(torture, "Running WINBINDD_CHECK_MACHACC (struct based)\n");
235
236         ok = true;
237         DO_STRUCT_REQ_REP_EXT(WINBINDD_CHECK_MACHACC, NULL, &rep,
238                               NSS_STATUS_SUCCESS, strict, ok = false,
239                               "WINBINDD_CHECK_MACHACC");
240
241         if (!ok) {
242                 torture_assert(torture,
243                                strlen(rep.data.auth.nt_status_string)>0,
244                                "Failed with empty nt_status_string");
245
246                 torture_warning(torture,"%s:%s:%s:%d\n",
247                                 nt_errstr(NT_STATUS(rep.data.auth.nt_status)),
248                                 rep.data.auth.nt_status_string,
249                                 rep.data.auth.error_string,
250                                 rep.data.auth.pam_error);
251                 return true;
252         }
253
254         torture_assert_ntstatus_ok(torture,
255                                    NT_STATUS(rep.data.auth.nt_status),
256                                    "WINBINDD_CHECK_MACHACC ok: nt_status");
257
258         torture_assert_str_equal(torture,
259                                  rep.data.auth.nt_status_string,
260                                  nt_errstr(NT_STATUS_OK),
261                                  "WINBINDD_CHECK_MACHACC ok:nt_status_string");
262
263         torture_assert_str_equal(torture,
264                                  rep.data.auth.error_string,
265                                  get_friendly_nt_error_msg(NT_STATUS_OK),
266                                  "WINBINDD_CHECK_MACHACC ok: error_string");
267
268         torture_assert_int_equal(torture,
269                                  rep.data.auth.pam_error,
270                                  nt_status_to_pam(NT_STATUS_OK),
271                                  "WINBINDD_CHECK_MACHACC ok: pam_error");
272
273         return true;
274 }
275
276 struct torture_trust_domain {
277         const char *netbios_name;
278         const char *dns_name;
279         struct dom_sid *sid;
280 };
281
282 static bool get_trusted_domains(struct torture_context *torture,
283                                 struct torture_trust_domain **_d)
284 {
285         struct winbindd_request req;
286         struct winbindd_response rep;
287         struct torture_trust_domain *d = NULL;
288         uint32_t dcount = 0;
289         fstring line;
290         const char *extra_data;
291
292         ZERO_STRUCT(req);
293         ZERO_STRUCT(rep);
294
295         DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
296
297         extra_data = (char *)rep.extra_data.data;
298         if (!extra_data) {
299                 return true;
300         }
301
302         torture_assert(torture, extra_data, "NULL trust list");
303
304         while (next_token(&extra_data, line, "\n", sizeof(fstring))) {
305                 char *p, *lp;
306
307                 d = talloc_realloc(torture, d,
308                                    struct torture_trust_domain,
309                                    dcount + 2);
310                 ZERO_STRUCT(d[dcount+1]);
311
312                 lp = line;
313                 p = strchr(lp, '\\');
314                 torture_assert(torture, p, "missing 1st '\\' in line");
315                 *p = 0;
316                 d[dcount].netbios_name = talloc_strdup(d, lp);
317                 torture_assert(torture, strlen(d[dcount].netbios_name) > 0,
318                                "empty netbios_name");
319
320                 lp = p+1;
321                 p = strchr(lp, '\\');
322                 torture_assert(torture, p, "missing 2nd '\\' in line");
323                 *p = 0;
324                 d[dcount].dns_name = talloc_strdup(d, lp);
325                 /* it's ok to have an empty dns_name */
326
327                 lp = p+1;
328                 d[dcount].sid = dom_sid_parse_talloc(d, lp);
329                 torture_assert(torture, d[dcount].sid,
330                                "failed to parse sid");
331
332                 dcount++;
333         }
334         SAFE_FREE(rep.extra_data.data);
335
336         torture_assert(torture, dcount >= 2,
337                        "The list of trusted domain should contain 2 entries");
338
339         *_d = d;
340         return true;
341 }
342
343 static bool torture_winbind_struct_list_trustdom(struct torture_context *torture)
344 {
345         struct winbindd_request req;
346         struct winbindd_response rep;
347         char *list1;
348         char *list2;
349         bool ok;
350         struct torture_trust_domain *listd = NULL;
351         uint32_t i;
352
353         torture_comment(torture, "Running WINBINDD_LIST_TRUSTDOM (struct based)\n");
354
355         ZERO_STRUCT(req);
356         ZERO_STRUCT(rep);
357
358         req.data.list_all_domains = false;
359
360         DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
361
362         list1 = (char *)rep.extra_data.data;
363
364         torture_comment(torture, "%s\n", list1);
365
366         ZERO_STRUCT(req);
367         ZERO_STRUCT(rep);
368
369         req.data.list_all_domains = true;
370
371         DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
372
373         list2 = (char *)rep.extra_data.data;
374
375         /*
376          * The list_all_domains parameter should be ignored
377          */
378         torture_assert_str_equal(torture, list2, list1, "list_all_domains not ignored");
379
380         SAFE_FREE(list1);
381         SAFE_FREE(list2);
382
383         ok = get_trusted_domains(torture, &listd);
384         torture_assert(torture, ok, "failed to get trust list");
385
386         for (i=0; listd && listd[i].netbios_name; i++) {
387                 if (i == 0) {
388                         struct dom_sid *builtin_sid;
389
390                         builtin_sid = dom_sid_parse_talloc(torture, SID_BUILTIN);
391
392                         torture_assert_str_equal(torture,
393                                                  listd[i].netbios_name,
394                                                  NAME_BUILTIN,
395                                                  "first domain should be 'BUILTIN'");
396
397                         torture_assert_str_equal(torture,
398                                                  listd[i].dns_name,
399                                                  "",
400                                                  "BUILTIN domain should not have a dns name");
401
402                         ok = dom_sid_equal(builtin_sid,
403                                            listd[i].sid);
404                         torture_assert(torture, ok, "BUILTIN domain should have S-1-5-32");
405
406                         continue;
407                 }
408
409                 /*
410                  * TODO: verify the content of the 2nd and 3rd (in member server mode)
411                  *       domain entries
412                  */
413         }
414
415         return true;
416 }
417
418 static bool torture_winbind_struct_domain_info(struct torture_context *torture)
419 {
420         bool ok;
421         struct torture_trust_domain *listd = NULL;
422         uint32_t i;
423
424         torture_comment(torture, "Running WINBINDD_DOMAIN_INFO (struct based)\n");
425
426         ok = get_trusted_domains(torture, &listd);
427         torture_assert(torture, ok, "failed to get trust list");
428
429         for (i=0; listd && listd[i].netbios_name; i++) {
430                 struct winbindd_request req;
431                 struct winbindd_response rep;
432                 struct dom_sid *sid;
433                 char *flagstr = talloc_strdup(torture," ");
434
435                 ZERO_STRUCT(req);
436                 ZERO_STRUCT(rep);
437
438                 fstrcpy(req.domain_name, listd[i].netbios_name);
439
440                 DO_STRUCT_REQ_REP(WINBINDD_DOMAIN_INFO, &req, &rep);
441
442                 torture_assert_str_equal(torture,
443                                          rep.data.domain_info.name,
444                                          listd[i].netbios_name,
445                                          "Netbios domain name doesn't match");
446
447                 torture_assert_str_equal(torture,
448                                          rep.data.domain_info.alt_name,
449                                          listd[i].dns_name,
450                                          "DNS domain name doesn't match");
451
452                 sid = dom_sid_parse_talloc(torture, rep.data.domain_info.sid);
453                 torture_assert(torture, sid, "Failed to parse SID");
454
455                 ok = dom_sid_equal(listd[i].sid, sid);
456                 torture_assert(torture, ok, "SID's doesn't match");
457
458                 if (rep.data.domain_info.primary) {
459                         flagstr = talloc_strdup_append(flagstr, "PR ");
460                 }
461
462                 if (rep.data.domain_info.active_directory) {
463                         torture_assert(torture,
464                                        strlen(rep.data.domain_info.alt_name)>0,
465                                        "Active Directory without DNS name");
466                         flagstr = talloc_strdup_append(flagstr, "AD ");
467                 }
468
469                 if (rep.data.domain_info.native_mode) {
470                         torture_assert(torture,
471                                        rep.data.domain_info.active_directory,
472                                        "Native-Mode, but no Active Directory");
473                         flagstr = talloc_strdup_append(flagstr, "NA ");
474                 }
475
476                 torture_comment(torture, "DOMAIN '%s' => '%s' [%s]\n",
477                                 rep.data.domain_info.name,
478                                 rep.data.domain_info.alt_name,
479                                 flagstr);
480         }
481
482         return true;
483 }
484
485 static bool torture_winbind_struct_getdcname(struct torture_context *torture)
486 {
487         bool ok;
488         bool strict = torture_setting_bool(torture, "strict mode", false);
489         struct torture_trust_domain *listd = NULL;
490         uint32_t i, count = 0;
491
492         torture_comment(torture, "Running WINBINDD_GETDCNAME (struct based)\n");
493
494         ok = get_trusted_domains(torture, &listd);
495         torture_assert(torture, ok, "failed to get trust list");
496
497         for (i=0; listd && listd[i].netbios_name; i++) {
498                 struct winbindd_request req;
499                 struct winbindd_response rep;
500
501                 ZERO_STRUCT(req);
502                 ZERO_STRUCT(rep);
503
504                 fstrcpy(req.domain_name, listd[i].netbios_name);
505
506                 ok = true;
507                 DO_STRUCT_REQ_REP_EXT(WINBINDD_GETDCNAME, &req, &rep,
508                                       NSS_STATUS_SUCCESS,
509                                       (i <2 || strict), ok = false,
510                                       talloc_asprintf(torture, "DOMAIN '%s'",
511                                                       req.domain_name));
512                 if (!ok) continue;
513
514                 /* TODO: check rep.data.dc_name; */
515                 torture_comment(torture, "DOMAIN '%s' => DCNAME '%s'\n",
516                                 req.domain_name, rep.data.dc_name);
517                 count++;
518         }
519
520         if (strict) {
521                 torture_assert(torture, count > 0,
522                                "WiNBINDD_GETDCNAME was not tested");
523         }
524         return true;
525 }
526
527 static bool torture_winbind_struct_dsgetdcname(struct torture_context *torture)
528 {
529         bool ok;
530         bool strict = torture_setting_bool(torture, "strict mode", false);
531         struct torture_trust_domain *listd = NULL;
532         uint32_t i;
533         uint32_t count = 0;
534
535         torture_comment(torture, "Running WINBINDD_DSGETDCNAME (struct based)\n");
536
537         ok = get_trusted_domains(torture, &listd);
538         torture_assert(torture, ok, "failed to get trust list");
539
540         for (i=0; listd && listd[i].netbios_name; i++) {
541                 struct winbindd_request req;
542                 struct winbindd_response rep;
543
544                 ZERO_STRUCT(req);
545                 ZERO_STRUCT(rep);
546
547                 if (strlen(listd[i].dns_name) == 0) continue;
548
549                 /*
550                  * TODO: remove this and let winbindd give no dns name
551                  *       for NT4 domains
552                  */
553                 if (strcmp(listd[i].dns_name, listd[i].netbios_name) == 0) {
554                         continue;
555                 }
556
557                 fstrcpy(req.domain_name, listd[i].dns_name);
558
559                 /* TODO: test more flag combinations */
560                 req.flags = DS_DIRECTORY_SERVICE_REQUIRED;
561
562                 ok = true;
563                 DO_STRUCT_REQ_REP_EXT(WINBINDD_DSGETDCNAME, &req, &rep,
564                                       NSS_STATUS_SUCCESS,
565                                       strict, ok = false,
566                                       talloc_asprintf(torture, "DOMAIN '%s'",
567                                                       req.domain_name));
568                 if (!ok) continue;
569
570                 /* TODO: check rep.data.dc_name; */
571                 torture_comment(torture, "DOMAIN '%s' => DCNAME '%s'\n",
572                                 req.domain_name, rep.data.dc_name);
573
574                 count++;
575         }
576
577         if (count == 0) {
578                 torture_warning(torture, "WINBINDD_DSGETDCNAME"
579                                 " was not tested with %d non-AD domains",
580                                 i);
581         }
582
583         if (strict) {
584                 torture_assert(torture, count > 0,
585                                "WiNBINDD_DSGETDCNAME was not tested");
586         }
587
588         return true;
589 }
590
591 static bool get_user_list(struct torture_context *torture, char ***users)
592 {
593         struct winbindd_request req;
594         struct winbindd_response rep;
595         char **u = NULL;
596         uint32_t count;
597         fstring name;
598         const char *extra_data;
599
600         ZERO_STRUCT(req);
601         ZERO_STRUCT(rep);
602
603         DO_STRUCT_REQ_REP(WINBINDD_LIST_USERS, &req, &rep);
604
605         extra_data = (char *)rep.extra_data.data;
606         torture_assert(torture, extra_data, "NULL extra data");
607
608         for(count = 0;
609             next_token(&extra_data, name, ",", sizeof(fstring));
610             count++)
611         {
612                 u = talloc_realloc(torture, u, char *, count + 2);
613                 u[count+1] = NULL;
614                 u[count] = talloc_strdup(u, name);
615         }
616
617         SAFE_FREE(rep.extra_data.data);
618
619         *users = u;
620         return true;
621 }
622
623 static bool torture_winbind_struct_list_users(struct torture_context *torture)
624 {
625         char **users;
626         uint32_t count;
627         bool ok;
628
629         torture_comment(torture, "Running WINBINDD_LIST_USERS (struct based)\n");
630
631         ok = get_user_list(torture, &users);
632         torture_assert(torture, ok, "failed to get group list");
633
634         for (count = 0; users[count]; count++) { }
635
636         torture_comment(torture, "got %d users\n", count);
637
638         return true;
639 }
640
641 static bool get_group_list(struct torture_context *torture, char ***groups)
642 {
643         struct winbindd_request req;
644         struct winbindd_response rep;
645         char **g = NULL;
646         uint32_t count;
647         fstring name;
648         const char *extra_data;
649
650         ZERO_STRUCT(req);
651         ZERO_STRUCT(rep);
652
653         DO_STRUCT_REQ_REP(WINBINDD_LIST_GROUPS, &req, &rep);
654
655         extra_data = (char *)rep.extra_data.data;
656         torture_assert(torture, extra_data, "NULL extra data");
657
658         for(count = 0;
659             next_token(&extra_data, name, ",", sizeof(fstring));
660             count++)
661         {
662                 g = talloc_realloc(torture, g, char *, count + 2);
663                 g[count+1] = NULL;
664                 g[count] = talloc_strdup(g, name);
665         }
666
667         SAFE_FREE(rep.extra_data.data);
668
669         *groups = g;
670         return true;
671 }
672
673 static bool torture_winbind_struct_list_groups(struct torture_context *torture)
674 {
675         char **groups;
676         uint32_t count;
677         bool ok;
678
679         torture_comment(torture, "Running WINBINDD_LIST_GROUPS (struct based)\n");
680
681         ok = get_group_list(torture, &groups);
682         torture_assert(torture, ok, "failed to get group list");
683
684         for (count = 0; groups[count]; count++) { }
685
686         torture_comment(torture, "got %d groups\n", count);
687
688         return true;
689 }
690
691 struct torture_domain_sequence {
692         const char *netbios_name;
693         uint32_t seq;
694 };
695
696 static bool get_sequence_numbers(struct torture_context *torture,
697                                  struct torture_domain_sequence **seqs)
698 {
699         struct winbindd_request req;
700         struct winbindd_response rep;
701         const char *extra_data;
702         fstring line;
703         uint32_t count = 0;
704         struct torture_domain_sequence *s = NULL;
705
706         ZERO_STRUCT(req);
707         ZERO_STRUCT(rep);
708
709         DO_STRUCT_REQ_REP(WINBINDD_SHOW_SEQUENCE, &req, &rep);
710
711         extra_data = (char *)rep.extra_data.data;
712         torture_assert(torture, extra_data, "NULL sequence list");
713
714         while (next_token(&extra_data, line, "\n", sizeof(fstring))) {
715                 char *p, *lp;
716                 uint32_t seq;
717
718                 s = talloc_realloc(torture, s, struct torture_domain_sequence,
719                                    count + 2);
720                 ZERO_STRUCT(s[count+1]);
721
722                 lp = line;
723                 p = strchr(lp, ' ');
724                 torture_assert(torture, p, "invalid line format");
725                 *p = 0;
726                 s[count].netbios_name = talloc_strdup(s, lp);
727
728                 lp = p+1;
729                 torture_assert(torture, strncmp(lp, ": ", 2) == 0,
730                                "invalid line format");
731                 lp += 2;
732                 if (strcmp(lp, "DISCONNECTED") == 0) {
733                         seq = (uint32_t)-1;
734                 } else {
735                         seq = (uint32_t)strtol(lp, &p, 10);
736                         torture_assert(torture, (*p == '\0'),
737                                        "invalid line format");
738                         torture_assert(torture, (seq != (uint32_t)-1),
739                                        "sequence number -1 encountered");
740                 }
741                 s[count].seq = seq;
742
743                 count++;
744         }
745         SAFE_FREE(rep.extra_data.data);
746
747         torture_assert(torture, count >= 2, "The list of domain sequence "
748                        "numbers should contain 2 entries");
749
750         *seqs = s;
751         return true;
752 }
753
754 static bool torture_winbind_struct_show_sequence(struct torture_context *torture)
755 {
756         bool ok;
757         uint32_t i;
758         struct torture_trust_domain *domlist = NULL;
759         struct torture_domain_sequence *s = NULL;
760
761         torture_comment(torture, "Running WINBINDD_SHOW_SEQUENCE (struct based)\n");
762
763         ok = get_sequence_numbers(torture, &s);
764         torture_assert(torture, ok, "failed to get list of sequence numbers");
765
766         ok = get_trusted_domains(torture, &domlist);
767         torture_assert(torture, ok, "failed to get trust list");
768
769         for (i=0; domlist[i].netbios_name; i++) {
770                 struct winbindd_request req;
771                 struct winbindd_response rep;
772                 uint32_t seq;
773
774                 torture_assert(torture, s[i].netbios_name,
775                                "more domains recieved in second run");
776                 torture_assert_str_equal(torture, domlist[i].netbios_name,
777                                          s[i].netbios_name,
778                                          "inconsistent order of domain lists");
779
780                 ZERO_STRUCT(req);
781                 ZERO_STRUCT(rep);
782                 fstrcpy(req.domain_name, domlist[i].netbios_name);
783
784                 DO_STRUCT_REQ_REP(WINBINDD_SHOW_SEQUENCE, &req, &rep);
785
786                 seq = rep.data.sequence_number;
787
788                 if (i == 0) {
789                         torture_assert(torture, (seq != (uint32_t)-1),
790                                        "BUILTIN domain disconnected");
791                 } else if (i == 1) {
792                         torture_assert(torture, (seq != (uint32_t)-1),
793                                        "local domain disconnected");
794                 }
795
796
797                 if (seq == (uint32_t)-1) {
798                         torture_comment(torture, " * %s : DISCONNECTED\n",
799                                         req.domain_name);
800                 } else {
801                         torture_comment(torture, " * %s : %d\n",
802                                         req.domain_name, seq);
803                 }
804                 torture_assert(torture, (seq >= s[i].seq),
805                                "illegal sequence number encountered");
806         }
807
808         return true;
809 }
810
811 static bool torture_winbind_struct_setpwent(struct torture_context *torture)
812 {
813         struct winbindd_request req;
814         struct winbindd_response rep;
815
816         torture_comment(torture, "Running WINBINDD_SETPWENT (struct based)\n");
817
818         ZERO_STRUCT(req);
819         ZERO_STRUCT(rep);
820
821         DO_STRUCT_REQ_REP(WINBINDD_SETPWENT, &req, &rep);
822
823         return true;
824 }
825
826 static bool torture_winbind_struct_getpwent(struct torture_context *torture)
827 {
828         struct winbindd_request req;
829         struct winbindd_response rep;
830         struct winbindd_pw *pwent;
831
832         torture_comment(torture, "Running WINBINDD_GETPWENT (struct based)\n");
833
834         torture_comment(torture, " - Running WINBINDD_SETPWENT first\n");
835         ZERO_STRUCT(req);
836         ZERO_STRUCT(rep);
837         DO_STRUCT_REQ_REP(WINBINDD_SETPWENT, &req, &rep);
838
839         torture_comment(torture, " - Running WINBINDD_GETPWENT now\n");
840         ZERO_STRUCT(req);
841         ZERO_STRUCT(rep);
842         req.data.num_entries = 1;
843         DO_STRUCT_REQ_REP(WINBINDD_GETPWENT, &req, &rep);
844         pwent = (struct winbindd_pw *)rep.extra_data.data;
845         torture_assert(torture, (pwent != NULL), "NULL pwent");
846         torture_comment(torture, "name: %s, uid: %d, gid: %d, shell: %s\n",
847                         pwent->pw_name, pwent->pw_uid, pwent->pw_gid,
848                         pwent->pw_shell);
849
850         return true;
851 }
852
853 static bool torture_winbind_struct_endpwent(struct torture_context *torture)
854 {
855         struct winbindd_request req;
856         struct winbindd_response rep;
857
858         torture_comment(torture, "Running WINBINDD_ENDPWENT (struct based)\n");
859
860         ZERO_STRUCT(req);
861         ZERO_STRUCT(rep);
862
863         DO_STRUCT_REQ_REP(WINBINDD_ENDPWENT, &req, &rep);
864
865         return true;
866 }
867
868 /* Copy of parse_domain_user from winbindd_util.c.  Parse a string of the
869    form DOMAIN/user into a domain and a user */
870
871 static bool parse_domain_user(struct torture_context *torture,
872                               const char *domuser, fstring domain,
873                               fstring user)
874 {
875         char *p = strchr(domuser, winbind_separator(torture));
876         char *dom;
877
878         if (!p) {
879                 /* Maybe it was a UPN? */
880                 if ((p = strchr(domuser, '@')) != NULL) {
881                         fstrcpy(domain, "");
882                         fstrcpy(user, domuser);
883                         return true;
884                 }
885
886                 fstrcpy(user, domuser);
887                 get_winbind_domain(torture, &dom);
888                 fstrcpy(domain, dom);
889                 return true;
890         }
891
892         fstrcpy(user, p+1);
893         fstrcpy(domain, domuser);
894         domain[PTR_DIFF(p, domuser)] = 0;
895         strupper_m(domain);
896
897         return true;
898 }
899
900 static bool lookup_name_sid_list(struct torture_context *torture, char **list)
901 {
902         uint32_t count;
903
904         for (count = 0; list[count]; count++) {
905                 struct winbindd_request req;
906                 struct winbindd_response rep;
907                 char *sid;
908                 char *name;
909
910                 ZERO_STRUCT(req);
911                 ZERO_STRUCT(rep);
912
913                 parse_domain_user(torture, list[count], req.data.name.dom_name,
914                                   req.data.name.name);
915
916                 DO_STRUCT_REQ_REP(WINBINDD_LOOKUPNAME, &req, &rep);
917
918                 sid = talloc_strdup(torture, rep.data.sid.sid);
919
920                 ZERO_STRUCT(req);
921                 ZERO_STRUCT(rep);
922
923                 fstrcpy(req.data.sid, sid);
924
925                 DO_STRUCT_REQ_REP(WINBINDD_LOOKUPSID, &req, &rep);
926
927                 name = talloc_asprintf(torture, "%s%c%s",
928                                        rep.data.name.dom_name,
929                                        winbind_separator(torture),
930                                        rep.data.name.name);
931
932                 torture_assert_casestr_equal(torture, list[count], name,
933                                          "LOOKUP_SID after LOOKUP_NAME != id");
934
935 #if 0
936                 torture_comment(torture, " %s -> %s -> %s\n", list[count],
937                                 sid, name);
938 #endif
939
940                 talloc_free(sid);
941                 talloc_free(name);
942         }
943
944         return true;
945 }
946
947 static bool name_is_in_list(const char *name, const char **list)
948 {
949         uint32_t count;
950
951         for (count = 0; list[count]; count++) {
952                 if (strequal(name, list[count])) {
953                         return true;
954                 }
955         }
956         return false;
957 }
958
959 static bool torture_winbind_struct_lookup_name_sid(struct torture_context *torture)
960 {
961         struct winbindd_request req;
962         struct winbindd_response rep;
963         const char *invalid_sid = "S-0-0-7";
964         char *domain;
965         const char *invalid_user = "noone";
966         char *invalid_name;
967         bool strict = torture_setting_bool(torture, "strict mode", false);
968         char **users;
969         char **groups;
970         uint32_t count;
971         bool ok;
972
973         torture_comment(torture, "Running WINBINDD_LOOKUP_NAME_SID (struct based)\n");
974
975         ok = get_user_list(torture, &users);
976         torture_assert(torture, ok, "failed to retrieve list of users");
977         lookup_name_sid_list(torture, users);
978
979         ok = get_group_list(torture, &groups);
980         torture_assert(torture, ok, "failed to retrieve list of groups");
981         lookup_name_sid_list(torture, groups);
982
983         ZERO_STRUCT(req);
984         ZERO_STRUCT(rep);
985
986         fstrcpy(req.data.sid, invalid_sid);
987
988         ok = true;
989         DO_STRUCT_REQ_REP_EXT(WINBINDD_LOOKUPSID, &req, &rep,
990                               NSS_STATUS_NOTFOUND,
991                               strict,
992                               ok=false,
993                               talloc_asprintf(torture,
994                                               "invalid sid %s was resolved",
995                                               invalid_sid));
996
997         ZERO_STRUCT(req);
998         ZERO_STRUCT(rep);
999
1000         /* try to find an invalid name... */
1001
1002         count = 0;
1003         get_winbind_domain(torture, &domain);
1004         do {
1005                 count++;
1006                 invalid_name = talloc_asprintf(torture, "%s\\%s%u",
1007                                                domain,
1008                                                invalid_user, count);
1009         } while(name_is_in_list(invalid_name, (const char **)users) ||
1010                 name_is_in_list(invalid_name, (const char **)groups));
1011
1012         fstrcpy(req.data.name.dom_name, domain);
1013         fstrcpy(req.data.name.name,
1014                 talloc_asprintf(torture, "%s%u", invalid_user,
1015                                 count));
1016
1017         ok = true;
1018         DO_STRUCT_REQ_REP_EXT(WINBINDD_LOOKUPNAME, &req, &rep,
1019                               NSS_STATUS_NOTFOUND,
1020                               strict,
1021                               ok=false,
1022                               talloc_asprintf(torture,
1023                                               "invalid name %s was resolved",
1024                                               invalid_name));
1025
1026         talloc_free(users);
1027         talloc_free(groups);
1028
1029         return true;
1030 }
1031
1032 struct torture_suite *torture_winbind_struct_init(void)
1033 {
1034         struct torture_suite *suite = torture_suite_create(talloc_autofree_context(), "STRUCT");
1035
1036         torture_suite_add_simple_test(suite, "INTERFACE_VERSION", torture_winbind_struct_interface_version);
1037         torture_suite_add_simple_test(suite, "PING", torture_winbind_struct_ping);
1038         torture_suite_add_simple_test(suite, "INFO", torture_winbind_struct_info);
1039         torture_suite_add_simple_test(suite, "PRIV_PIPE_DIR", torture_winbind_struct_priv_pipe_dir);
1040         torture_suite_add_simple_test(suite, "NETBIOS_NAME", torture_winbind_struct_netbios_name);
1041         torture_suite_add_simple_test(suite, "DOMAIN_NAME", torture_winbind_struct_domain_name);
1042         torture_suite_add_simple_test(suite, "CHECK_MACHACC", torture_winbind_struct_check_machacc);
1043         torture_suite_add_simple_test(suite, "LIST_TRUSTDOM", torture_winbind_struct_list_trustdom);
1044         torture_suite_add_simple_test(suite, "DOMAIN_INFO", torture_winbind_struct_domain_info);
1045         torture_suite_add_simple_test(suite, "GETDCNAME", torture_winbind_struct_getdcname);
1046         torture_suite_add_simple_test(suite, "DSGETDCNAME", torture_winbind_struct_dsgetdcname);
1047         torture_suite_add_simple_test(suite, "LIST_USERS", torture_winbind_struct_list_users);
1048         torture_suite_add_simple_test(suite, "LIST_GROUPS", torture_winbind_struct_list_groups);
1049         torture_suite_add_simple_test(suite, "SHOW_SEQUENCE", torture_winbind_struct_show_sequence);
1050         torture_suite_add_simple_test(suite, "SETPWENT", torture_winbind_struct_setpwent);
1051         torture_suite_add_simple_test(suite, "GETPWENT", torture_winbind_struct_getpwent);
1052         torture_suite_add_simple_test(suite, "ENDPWENT", torture_winbind_struct_endpwent);
1053         torture_suite_add_simple_test(suite, "LOOKUP_NAME_SID", torture_winbind_struct_lookup_name_sid);
1054
1055         suite->description = talloc_strdup(suite, "WINBIND - struct based protocol tests");
1056
1057         return suite;
1058 }