2 Unix SMB/CIFS mplementation.
4 The module that handles the Schema FSMO Role Owner
5 checkings, it also loads the dsdb_schema.
7 Copyright (C) Stefan Metzmacher <metze@samba.org> 2007
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
25 #include "lib/ldb/include/ldb.h"
26 #include "lib/ldb/include/ldb_errors.h"
27 #include "lib/ldb/include/ldb_private.h"
28 #include "dsdb/samdb/samdb.h"
29 #include "librpc/gen_ndr/ndr_misc.h"
30 #include "librpc/gen_ndr/ndr_drsuapi.h"
31 #include "librpc/gen_ndr/ndr_drsblobs.h"
32 #include "lib/util/dlinklist.h"
33 #include "param/param.h"
35 static int schema_fsmo_init(struct ldb_module *module)
39 struct ldb_dn *schema_dn;
40 struct dsdb_schema *schema;
41 struct ldb_result *schema_res;
42 const struct ldb_val *prefix_val;
43 const struct ldb_val *info_val;
44 struct ldb_val info_val_default;
45 struct ldb_result *a_res;
46 struct ldb_result *c_res;
49 static const char *schema_attrs[] = {
56 if (dsdb_get_schema(module->ldb)) {
57 return ldb_next_init(module);
60 schema_dn = samdb_schema_dn(module->ldb);
62 ldb_reset_err_string(module->ldb);
63 ldb_debug(module->ldb, LDB_DEBUG_WARNING,
64 "schema_fsmo_init: no schema dn present: (skip schema loading)\n");
65 return ldb_next_init(module);
68 mem_ctx = talloc_new(module);
71 return LDB_ERR_OPERATIONS_ERROR;
74 schema = dsdb_new_schema(mem_ctx, lp_iconv_convenience(ldb_get_opaque(module->ldb, "loadparm")));
77 return LDB_ERR_OPERATIONS_ERROR;
81 * setup the prefix mappings and schema info
83 ret = ldb_search(module->ldb, schema_dn,
87 if (ret == LDB_ERR_NO_SUCH_OBJECT) {
88 ldb_reset_err_string(module->ldb);
89 ldb_debug(module->ldb, LDB_DEBUG_WARNING,
90 "schema_fsmo_init: no schema head present: (skip schema loading)\n");
92 return ldb_next_init(module);
93 } else if (ret != LDB_SUCCESS) {
94 ldb_asprintf_errstring(module->ldb,
95 "schema_fsmo_init: failed to search the schema head: %s",
96 ldb_errstring(module->ldb));
100 talloc_steal(mem_ctx, schema_res);
101 if (schema_res->count == 0) {
102 ldb_debug(module->ldb, LDB_DEBUG_WARNING,
103 "schema_fsmo_init: no schema head present: (skip schema loading)\n");
104 talloc_free(mem_ctx);
105 return ldb_next_init(module);
106 } else if (schema_res->count > 1) {
107 ldb_debug_set(module->ldb, LDB_DEBUG_FATAL,
108 "schema_fsmo_init: [%u] schema heads found on a base search",
110 talloc_free(mem_ctx);
111 return LDB_ERR_CONSTRAINT_VIOLATION;
114 prefix_val = ldb_msg_find_ldb_val(schema_res->msgs[0], "prefixMap");
116 ldb_debug_set(module->ldb, LDB_DEBUG_FATAL,
117 "schema_fsmo_init: no prefixMap attribute found");
118 talloc_free(mem_ctx);
119 return LDB_ERR_CONSTRAINT_VIOLATION;
121 info_val = ldb_msg_find_ldb_val(schema_res->msgs[0], "schemaInfo");
123 info_val_default = strhex_to_data_blob("FF0000000000000000000000000000000000000000");
124 if (!info_val_default.data) {
125 ldb_oom(module->ldb);
126 return LDB_ERR_OPERATIONS_ERROR;
128 talloc_steal(mem_ctx, info_val_default.data);
129 info_val = &info_val_default;
132 status = dsdb_load_oid_mappings_ldb(schema, prefix_val, info_val);
133 if (!W_ERROR_IS_OK(status)) {
134 ldb_debug_set(module->ldb, LDB_DEBUG_FATAL,
135 "schema_fsmo_init: failed to load oid mappings: %s",
137 talloc_free(mem_ctx);
138 return LDB_ERR_CONSTRAINT_VIOLATION;
142 * load the attribute definitions
144 ret = ldb_search(module->ldb, schema_dn,
146 "(objectClass=attributeSchema)", NULL,
148 if (ret != LDB_SUCCESS) {
149 ldb_asprintf_errstring(module->ldb,
150 "schema_fsmo_init: failed to search attributeSchema objects: %s",
151 ldb_errstring(module->ldb));
152 talloc_free(mem_ctx);
155 talloc_steal(mem_ctx, a_res);
157 for (i=0; i < a_res->count; i++) {
158 struct dsdb_attribute *sa;
160 sa = talloc_zero(schema, struct dsdb_attribute);
162 ldb_oom(module->ldb);
163 return LDB_ERR_OPERATIONS_ERROR;
166 status = dsdb_attribute_from_ldb(schema, a_res->msgs[i], sa, sa);
167 if (!W_ERROR_IS_OK(status)) {
168 ldb_debug_set(module->ldb, LDB_DEBUG_FATAL,
169 "schema_fsmo_init: failed to load attriute definition: %s:%s",
170 ldb_dn_get_linearized(a_res->msgs[i]->dn),
172 talloc_free(mem_ctx);
173 return LDB_ERR_CONSTRAINT_VIOLATION;
176 DLIST_ADD_END(schema->attributes, sa, struct dsdb_attribute *);
181 * load the objectClass definitions
183 ret = ldb_search(module->ldb, schema_dn,
185 "(objectClass=classSchema)", NULL,
187 if (ret != LDB_SUCCESS) {
188 ldb_asprintf_errstring(module->ldb,
189 "schema_fsmo_init: failed to search classSchema objects: %s",
190 ldb_errstring(module->ldb));
191 talloc_free(mem_ctx);
194 talloc_steal(mem_ctx, c_res);
196 for (i=0; i < c_res->count; i++) {
197 struct dsdb_class *sc;
199 sc = talloc_zero(schema, struct dsdb_class);
201 ldb_oom(module->ldb);
202 return LDB_ERR_OPERATIONS_ERROR;
205 status = dsdb_class_from_ldb(schema, c_res->msgs[i], sc, sc);
206 if (!W_ERROR_IS_OK(status)) {
207 ldb_debug_set(module->ldb, LDB_DEBUG_FATAL,
208 "schema_fsmo_init: failed to load class definition: %s:%s",
209 ldb_dn_get_linearized(c_res->msgs[i]->dn),
211 talloc_free(mem_ctx);
212 return LDB_ERR_CONSTRAINT_VIOLATION;
215 DLIST_ADD_END(schema->classes, sc, struct dsdb_class *);
219 schema->fsmo.master_dn = ldb_msg_find_attr_as_dn(module->ldb, schema, schema_res->msgs[0], "fSMORoleOwner");
220 if (ldb_dn_compare(samdb_ntds_settings_dn(module->ldb), schema->fsmo.master_dn) == 0) {
221 schema->fsmo.we_are_master = true;
223 schema->fsmo.we_are_master = false;
226 /* dsdb_set_schema() steal schema into the ldb_context */
227 ret = dsdb_set_schema(module->ldb, schema);
228 if (ret != LDB_SUCCESS) {
229 ldb_debug_set(module->ldb, LDB_DEBUG_FATAL,
230 "schema_fsmo_init: dsdb_set_schema() failed: %d:%s",
231 ret, ldb_strerror(ret));
232 talloc_free(mem_ctx);
236 ldb_debug(module->ldb, LDB_DEBUG_TRACE,
237 "schema_fsmo_init: we are master: %s\n",
238 (schema->fsmo.we_are_master?"yes":"no"));
240 talloc_free(mem_ctx);
241 return ldb_next_init(module);
244 static int schema_fsmo_add(struct ldb_module *module, struct ldb_request *req)
246 struct dsdb_schema *schema;
247 const char *attributeID = NULL;
248 const char *governsID = NULL;
249 const char *oid_attr = NULL;
250 const char *oid = NULL;
254 schema = dsdb_get_schema(module->ldb);
256 return ldb_next_request(module, req);
259 if (!schema->fsmo.we_are_master) {
260 ldb_debug_set(module->ldb, LDB_DEBUG_ERROR,
261 "schema_fsmo_add: we are not master: reject request\n");
262 return LDB_ERR_UNWILLING_TO_PERFORM;
265 attributeID = samdb_result_string(req->op.add.message, "attributeID", NULL);
266 governsID = samdb_result_string(req->op.add.message, "governsID", NULL);
269 oid_attr = "attributeID";
271 } else if (governsID) {
272 oid_attr = "governsID";
277 return ldb_next_request(module, req);
280 status = dsdb_map_oid2int(schema, oid, &id32);
281 if (W_ERROR_IS_OK(status)) {
282 return ldb_next_request(module, req);
283 } else if (!W_ERROR_EQUAL(WERR_DS_NO_MSDS_INTID, status)) {
284 ldb_debug_set(module->ldb, LDB_DEBUG_ERROR,
285 "schema_fsmo_add: failed to map %s[%s]: %s\n",
286 oid_attr, oid, win_errstr(status));
287 return LDB_ERR_UNWILLING_TO_PERFORM;
290 status = dsdb_create_prefix_mapping(module->ldb, schema, oid);
291 if (!W_ERROR_IS_OK(status)) {
292 ldb_debug_set(module->ldb, LDB_DEBUG_ERROR,
293 "schema_fsmo_add: failed to create prefix mapping for %s[%s]: %s\n",
294 oid_attr, oid, win_errstr(status));
295 return LDB_ERR_UNWILLING_TO_PERFORM;
298 return ldb_next_request(module, req);
301 _PUBLIC_ const struct ldb_module_ops ldb_schema_fsmo_module_ops = {
302 .name = "schema_fsmo",
303 .init_context = schema_fsmo_init,
304 .add = schema_fsmo_add