s3:passdb: add sid_check_object_is_for_passdb()
[kai/samba.git] / source3 / smbd / smbXsrv_version.c
1 /*
2    Unix SMB/CIFS implementation.
3
4    Copyright (C) Stefan Metzmacher 2012
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 3 of the License, or
9    (at your option) any later version.
10
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15
16    You should have received a copy of the GNU General Public License
17    along with this program.  If not, see <http://www.gnu.org/licenses/>.
18 */
19
20 #include "includes.h"
21 #include "system/filesys.h"
22 #include "smbd/globals.h"
23 #include "dbwrap/dbwrap.h"
24 #include "dbwrap/dbwrap_open.h"
25 #include "lib/util/util_tdb.h"
26 #include "librpc/gen_ndr/ndr_smbXsrv.h"
27 #include "serverid.h"
28
29 /*
30  * This implements a version scheme for file server internal
31  * states. smbXsrv_version_global.tdb stores the possible
32  * and current versions of structure formats (struct smbXsrv_*_global)
33  * per cluster node.
34  *
35  * If the supported versions doesn't match a version of any
36  * of the other nodes, it refused to start.
37  *
38  * This should prevent silent corruption of the internal
39  * databases and structures, if two incompatible implementations
40  * read and write.
41  *
42  * In future this can be used to implement rolling code upgrades
43  * in a cluster, but for now it is simple.
44  */
45
46 static struct db_context *smbXsrv_version_global_db_ctx = NULL;
47 static uint32_t smbXsrv_version_global_current_version = UINT32_MAX;
48
49 NTSTATUS smbXsrv_version_global_init(const struct server_id *server_id)
50 {
51         const char *global_path = NULL;
52         struct db_context *db_ctx = NULL;
53         struct db_record *db_rec = NULL;
54         TDB_DATA key;
55         TDB_DATA val;
56         DATA_BLOB blob;
57         struct smbXsrv_version_globalB global_blob;
58         enum ndr_err_code ndr_err;
59         struct smbXsrv_version_global0 *global = NULL;
60         uint32_t i;
61         uint32_t num_valid = 0;
62         struct smbXsrv_version_node0 *valid = NULL;
63         struct smbXsrv_version_node0 *local_node = NULL;
64         bool exists;
65         NTSTATUS status;
66         const char *key_string = "smbXsrv_version_global";
67         TALLOC_CTX *frame;
68
69         if (smbXsrv_version_global_db_ctx != NULL) {
70                 return NT_STATUS_OK;
71         }
72
73         frame = talloc_stackframe();
74
75         global_path = lock_path("smbXsrv_version_global.tdb");
76
77         db_ctx = db_open(NULL, global_path,
78                          0, /* hash_size */
79                          TDB_DEFAULT |
80                          TDB_CLEAR_IF_FIRST |
81                          TDB_INCOMPATIBLE_HASH,
82                          O_RDWR | O_CREAT, 0600,
83                          DBWRAP_LOCK_ORDER_1);
84         if (db_ctx == NULL) {
85                 status = map_nt_error_from_unix_common(errno);
86                 DEBUG(0,("smbXsrv_version_global_init: "
87                          "failed to open[%s] - %s\n",
88                          global_path, nt_errstr(status)));
89                 TALLOC_FREE(frame);
90                 return status;
91         }
92
93         key = string_term_tdb_data(key_string);
94
95         db_rec = dbwrap_fetch_locked(db_ctx, db_ctx, key);
96         if (db_rec == NULL) {
97                 status = NT_STATUS_INTERNAL_DB_ERROR;
98                 DEBUG(0,("smbXsrv_version_global_init: "
99                          "dbwrap_fetch_locked(%s) - %s\n",
100                          key_string, nt_errstr(status)));
101                 TALLOC_FREE(frame);
102                 return status;
103         }
104
105         val = dbwrap_record_get_value(db_rec);
106         if (val.dsize == 0) {
107                 global = talloc_zero(frame, struct smbXsrv_version_global0);
108                 if (global == NULL) {
109                         DEBUG(0,("smbXsrv_version_global_init: "
110                                  "talloc_zero failed - %s\n", __location__));
111                         TALLOC_FREE(frame);
112                         return NT_STATUS_NO_MEMORY;
113                 }
114                 ZERO_STRUCT(global_blob);
115                 global_blob.version = SMBXSRV_VERSION_CURRENT;
116                 global_blob.info.info0 = global;
117         } else {
118                 blob = data_blob_const(val.dptr, val.dsize);
119
120                 ndr_err = ndr_pull_struct_blob(&blob, frame, &global_blob,
121                         (ndr_pull_flags_fn_t)ndr_pull_smbXsrv_version_globalB);
122                 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
123                         status = ndr_map_error2ntstatus(ndr_err);
124                         DEBUG(0,("smbXsrv_version_global_init: "
125                                  "ndr_pull_smbXsrv_version_globalB - %s\n",
126                                  nt_errstr(status)));
127                         TALLOC_FREE(frame);
128                         return status;
129                 }
130
131                 switch (global_blob.version) {
132                 case SMBXSRV_VERSION_0:
133                         global = global_blob.info.info0;
134                         if (global == NULL) {
135                                 status = NT_STATUS_INTERNAL_DB_CORRUPTION;
136                                 break;
137                         }
138                         status = NT_STATUS_OK;
139                         break;
140                 default:
141                         status = NT_STATUS_REVISION_MISMATCH;
142                         break;
143                 }
144
145                 if (!NT_STATUS_IS_OK(status)) {
146                         DEBUG(0,("smbXsrv_version_global_init - %s\n",
147                                  nt_errstr(status)));
148                         NDR_PRINT_DEBUG(smbXsrv_version_globalB, &global_blob);
149                         TALLOC_FREE(frame);
150                         return status;
151                 }
152         }
153
154         valid = talloc_zero_array(global,
155                                   struct smbXsrv_version_node0,
156                                   global->num_nodes + 1);
157         if (valid == NULL) {
158                 DEBUG(0,("smbXsrv_version_global_init: "
159                          "talloc_zero_array failed - %s\n", __location__));
160                 TALLOC_FREE(frame);
161                 return NT_STATUS_NO_MEMORY;
162         }
163
164         num_valid = 0;
165         for (i=0; i < global->num_nodes; i++) {
166                 struct smbXsrv_version_node0 *n = &global->nodes[i];
167
168                 exists = serverid_exists(&n->server_id);
169                 if (!exists) {
170                         continue;
171                 }
172
173                 if (n->min_version > n->max_version) {
174                         status = NT_STATUS_INTERNAL_DB_CORRUPTION;
175                         DEBUG(0,("smbXsrv_version_global_init - %s\n",
176                                  nt_errstr(status)));
177                         NDR_PRINT_DEBUG(smbXsrv_version_globalB, &global_blob);
178                         TALLOC_FREE(frame);
179                         return status;
180                 }
181
182                 if (n->min_version > global_blob.version) {
183                         status = NT_STATUS_INTERNAL_DB_CORRUPTION;
184                         DEBUG(0,("smbXsrv_version_global_init - %s\n",
185                                  nt_errstr(status)));
186                         NDR_PRINT_DEBUG(smbXsrv_version_globalB, &global_blob);
187                         TALLOC_FREE(frame);
188                         return status;
189                 }
190
191                 if (n->max_version < global_blob.version) {
192                         status = NT_STATUS_INTERNAL_DB_CORRUPTION;
193                         DEBUG(0,("smbXsrv_version_global_init - %s\n",
194                                  nt_errstr(status)));
195                         NDR_PRINT_DEBUG(smbXsrv_version_globalB, &global_blob);
196                         TALLOC_FREE(frame);
197                         return status;
198                 }
199
200                 valid[num_valid] = *n;
201                 if (server_id->vnn == n->server_id.vnn) {
202                         local_node = &valid[num_valid];
203                 }
204                 num_valid++;
205         }
206
207         if (local_node == NULL) {
208                 local_node = &valid[num_valid];
209                 num_valid++;
210         }
211
212         local_node->server_id = *server_id;
213         local_node->min_version = SMBXSRV_VERSION_0;
214         local_node->max_version = SMBXSRV_VERSION_CURRENT;
215         local_node->current_version = global_blob.version;
216
217         global->num_nodes = num_valid;
218         global->nodes = valid;
219
220         global_blob.seqnum += 1;
221         global_blob.info.info0 = global;
222
223         ndr_err = ndr_push_struct_blob(&blob, db_rec, &global_blob,
224                         (ndr_push_flags_fn_t)ndr_push_smbXsrv_version_globalB);
225         if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
226                 status = ndr_map_error2ntstatus(ndr_err);
227                 DEBUG(0,("smbXsrv_version_global_init: "
228                          "ndr_push_smbXsrv_version_globalB - %s\n",
229                          nt_errstr(status)));
230                 TALLOC_FREE(frame);
231                 return status;
232         }
233
234         val = make_tdb_data(blob.data, blob.length);
235         status = dbwrap_record_store(db_rec, val, TDB_REPLACE);
236         TALLOC_FREE(db_rec);
237         if (!NT_STATUS_IS_OK(status)) {
238                 DEBUG(0,("smbXsrv_version_global_init: "
239                          "dbwrap_record_store - %s\n",
240                          nt_errstr(status)));
241                 TALLOC_FREE(frame);
242                 return status;
243         }
244
245         DEBUG(10,("smbXsrv_version_global_init\n"));
246         if (DEBUGLVL(10)) {
247                 NDR_PRINT_DEBUG(smbXsrv_version_globalB, &global_blob);
248         }
249
250         smbXsrv_version_global_db_ctx = db_ctx;
251         smbXsrv_version_global_current_version = global_blob.version;
252
253         TALLOC_FREE(frame);
254         return NT_STATUS_OK;
255 }
256
257 uint32_t smbXsrv_version_global_current(void)
258 {
259         return smbXsrv_version_global_current_version;
260 }