r25293: add WINBIND-STRUCT-CHECK_MACHACC test
[kai/samba.git] / source4 / torture / winbind / struct_based.c
1 /*
2    Unix SMB/CIFS implementation.
3    SMB torture tester - winbind struct based protocol
4    Copyright (C) Stefan Metzmacher 2007
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 3 of the License, or
9    (at your option) any later version.
10
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15
16    You should have received a copy of the GNU General Public License
17    along with this program.  If not, see <http://www.gnu.org/licenses/>.
18 */
19
20 #include "includes.h"
21 #include "pstring.h"
22 #include "torture/torture.h"
23 #include "torture/winbind/proto.h"
24 #include "nsswitch/winbind_client.h"
25 #include "libcli/security/security.h"
26 #include "param/param.h"
27 #include "auth/pam_errors.h"
28
29 #define DO_STRUCT_REQ_REP_EXT(op,req,rep,expected,strict,warnaction,cmt) do { \
30         NSS_STATUS __got, __expected = (expected); \
31         __got = winbindd_request_response(op, req, rep); \
32         if (__got != __expected) { \
33                 const char *__cmt = (cmt); \
34                 if (strict) { \
35                         torture_result(torture, TORTURE_FAIL, \
36                                 __location__ ": " __STRING(op) \
37                                 " returned %d, expected %d%s%s", \
38                                 __got, __expected, \
39                                 (__cmt) ? ": " : "", \
40                                 (__cmt) ? (__cmt) : ""); \
41                         return false; \
42                 } else { \
43                         torture_warning(torture, \
44                                 __location__ ": " __STRING(op) \
45                                 " returned %d, expected %d%s%s", \
46                                 __got, __expected, \
47                                 (__cmt) ? ": " : "", \
48                                 (__cmt) ? (__cmt) : ""); \
49                         warnaction; \
50                 } \
51         } \
52 } while(0)
53
54 #define DO_STRUCT_REQ_REP(op,req,rep) do { \
55         bool __noop = false; \
56         DO_STRUCT_REQ_REP_EXT(op,req,rep,NSS_STATUS_SUCCESS,true,__noop=true,NULL); \
57 } while (0)
58
59 static bool torture_winbind_struct_interface_version(struct torture_context *torture)
60 {
61         struct winbindd_request req;
62         struct winbindd_response rep;
63
64         ZERO_STRUCT(req);
65         ZERO_STRUCT(rep);
66
67         torture_comment(torture, "Running WINBINDD_INTERFACE_VERSION (struct based)\n");
68
69         DO_STRUCT_REQ_REP(WINBINDD_INTERFACE_VERSION, &req, &rep);
70
71         torture_assert_int_equal(torture,
72                                  rep.data.interface_version,
73                                  WINBIND_INTERFACE_VERSION,
74                                  "winbind server and client doesn't match");
75
76         return true;
77 }
78
79 static bool torture_winbind_struct_ping(struct torture_context *torture)
80 {
81         struct timeval tv = timeval_current();
82         int timelimit = torture_setting_int(torture, "timelimit", 5);
83         uint32_t total = 0;
84
85         torture_comment(torture,
86                         "Running WINBINDD_PING (struct based) for %d seconds\n",
87                         timelimit);
88
89         while (timeval_elapsed(&tv) < timelimit) {
90                 DO_STRUCT_REQ_REP(WINBINDD_PING, NULL, NULL);
91                 total++;
92         }
93
94         torture_comment(torture,
95                         "%u (%.1f/s) WINBINDD_PING (struct based)\n",
96                         total, total / timeval_elapsed(&tv));
97
98         return true;
99 }
100
101 static bool torture_winbind_struct_info(struct torture_context *torture)
102 {
103         struct winbindd_response rep;
104         const char *separator;
105
106         ZERO_STRUCT(rep);
107
108         torture_comment(torture, "Running WINBINDD_INFO (struct based)\n");
109
110         DO_STRUCT_REQ_REP(WINBINDD_INFO, NULL, &rep);
111
112         separator = torture_setting_string(torture,
113                                            "winbindd separator",
114                                            lp_winbind_separator());
115         torture_assert_int_equal(torture,
116                                  rep.data.info.winbind_separator,
117                                  *separator,
118                                  "winbind separator doesn't match");
119
120         torture_comment(torture, "Samba Version '%s'\n",
121                         rep.data.info.samba_version);
122
123         return true;
124 }
125
126 static bool torture_winbind_struct_priv_pipe_dir(struct torture_context *torture)
127 {
128         struct winbindd_response rep;
129         const char *default_dir;
130         const char *expected_dir;
131         const char *got_dir;
132
133         ZERO_STRUCT(rep);
134
135         torture_comment(torture, "Running WINBINDD_PRIV_PIPE_DIR (struct based)\n");
136
137         DO_STRUCT_REQ_REP(WINBINDD_PRIV_PIPE_DIR, NULL, &rep);
138
139         got_dir = (const char *)rep.extra_data.data;
140
141         torture_assert(torture, got_dir, "NULL WINBINDD_PRIV_PIPE_DIR\n");
142
143         default_dir = lock_path(torture, WINBINDD_PRIV_SOCKET_SUBDIR);
144         expected_dir = torture_setting_string(torture,
145                                               "winbindd private pipe dir",
146                                               default_dir);
147
148         torture_assert_str_equal(torture, got_dir, expected_dir,
149                                  "WINBINDD_PRIV_PIPE_DIR doesn't match");
150
151         SAFE_FREE(rep.extra_data.data);
152         return true;
153 }
154
155 static bool torture_winbind_struct_netbios_name(struct torture_context *torture)
156 {
157         struct winbindd_response rep;
158         const char *expected;
159
160         ZERO_STRUCT(rep);
161
162         torture_comment(torture, "Running WINBINDD_NETBIOS_NAME (struct based)\n");
163
164         DO_STRUCT_REQ_REP(WINBINDD_NETBIOS_NAME, NULL, &rep);
165
166         expected = torture_setting_string(torture,
167                                           "winbindd netbios name",
168                                           lp_netbios_name());
169
170         torture_assert_str_equal(torture,
171                                  rep.data.netbios_name, expected,
172                                  "winbindd's netbios name doesn't match");
173
174         return true;
175 }
176
177 static bool torture_winbind_struct_domain_name(struct torture_context *torture)
178 {
179         struct winbindd_response rep;
180         const char *expected;
181
182         ZERO_STRUCT(rep);
183
184         torture_comment(torture, "Running WINBINDD_DOMAIN_NAME (struct based)\n");
185
186         DO_STRUCT_REQ_REP(WINBINDD_DOMAIN_NAME, NULL, &rep);
187
188         expected = torture_setting_string(torture,
189                                           "winbindd netbios domain",
190                                           lp_workgroup());
191
192         torture_assert_str_equal(torture,
193                                  rep.data.domain_name, expected,
194                                  "winbindd's netbios domain doesn't match");
195
196         return true;
197 }
198
199 static bool torture_winbind_struct_check_machacc(struct torture_context *torture)
200 {
201         bool ok;
202         bool strict = torture_setting_bool(torture, "strict mode", false);
203         struct winbindd_response rep;
204
205         ZERO_STRUCT(rep);
206
207         torture_comment(torture, "Running WINBINDD_CHECK_MACHACC (struct based)\n");
208
209         ok = true;
210         DO_STRUCT_REQ_REP_EXT(WINBINDD_CHECK_MACHACC, NULL, &rep,
211                               NSS_STATUS_SUCCESS, strict, ok = false,
212                               "WINBINDD_CHECK_MACHACC");
213
214         if (!ok) {
215                 torture_assert(torture,
216                                strlen(rep.data.auth.nt_status_string)>0,
217                                "Failed with empty nt_status_string");
218
219                 torture_warning(torture,"%s:%s:%s:%d\n",
220                                 nt_errstr(NT_STATUS(rep.data.auth.nt_status)),
221                                 rep.data.auth.nt_status_string,
222                                 rep.data.auth.error_string,
223                                 rep.data.auth.pam_error);
224                 return true;
225         }
226
227         torture_assert_ntstatus_ok(torture,
228                                    NT_STATUS(rep.data.auth.nt_status),
229                                    "WINBINDD_CHECK_MACHACC ok: nt_status");
230
231         torture_assert_str_equal(torture,
232                                  rep.data.auth.nt_status_string,
233                                  nt_errstr(NT_STATUS_OK),
234                                  "WINBINDD_CHECK_MACHACC ok:nt_status_string");
235
236         torture_assert_str_equal(torture,
237                                  rep.data.auth.error_string,
238                                  nt_errstr(NT_STATUS_OK),
239                                  "WINBINDD_CHECK_MACHACC ok: error_string");
240
241         torture_assert_int_equal(torture,
242                                  rep.data.auth.pam_error,
243                                  nt_status_to_pam(NT_STATUS_OK),
244                                  "WINBINDD_CHECK_MACHACC ok: pam_error");
245
246         return true;
247 }
248
249 struct torture_trust_domain {
250         const char *netbios_name;
251         const char *dns_name;
252         struct dom_sid *sid;
253 };
254
255 static bool get_trusted_domains(struct torture_context *torture,
256                                 struct torture_trust_domain **_d)
257 {
258         struct winbindd_request req;
259         struct winbindd_response rep;
260         struct torture_trust_domain *d = NULL;
261         uint32_t dcount = 0;
262         fstring line;
263         const char *extra_data;
264
265         ZERO_STRUCT(req);
266         ZERO_STRUCT(rep);
267
268         DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
269
270         extra_data = (char *)rep.extra_data.data;
271         torture_assert(torture, extra_data, "NULL trust list");
272
273         while (next_token(&extra_data, line, "\n", sizeof(fstring))) {
274                 char *p, *lp;
275
276                 d = talloc_realloc(torture, d,
277                                    struct torture_trust_domain,
278                                    dcount + 2);
279                 ZERO_STRUCT(d[dcount+1]);
280
281                 lp = line;
282                 p = strchr(lp, '\\');
283                 torture_assert(torture, p, "missing 1st '\\' in line");
284                 *p = 0;
285                 d[dcount].netbios_name = talloc_strdup(d, lp);
286                 torture_assert(torture, strlen(d[dcount].netbios_name) > 0,
287                                "empty netbios_name");
288
289                 lp = p+1;
290                 p = strchr(lp, '\\');
291                 torture_assert(torture, p, "missing 2nd '\\' in line");
292                 *p = 0;
293                 d[dcount].dns_name = talloc_strdup(d, lp);
294                 /* it's ok to have an empty dns_name */
295
296                 lp = p+1;
297                 d[dcount].sid = dom_sid_parse_talloc(d, lp);
298                 torture_assert(torture, d[dcount].sid,
299                                "failed to parse sid");
300
301                 dcount++;
302         }
303         SAFE_FREE(rep.extra_data.data);
304
305         torture_assert(torture, dcount >= 2,
306                        "The list of trusted domain should contain 2 entries");
307
308         *_d = d;
309         return true;
310 }
311
312 static bool torture_winbind_struct_list_trustdom(struct torture_context *torture)
313 {
314         struct winbindd_request req;
315         struct winbindd_response rep;
316         char *list1;
317         char *list2;
318         bool ok;
319         struct torture_trust_domain *listd = NULL;
320         uint32_t i;
321
322         torture_comment(torture, "Running WINBINDD_LIST_TRUSTDOM (struct based)\n");
323
324         ZERO_STRUCT(req);
325         ZERO_STRUCT(rep);
326
327         req.data.list_all_domains = false;
328
329         DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
330
331         list1 = (char *)rep.extra_data.data;
332         torture_assert(torture, list1, "NULL trust list");
333
334         torture_comment(torture, "%s\n", list1);
335
336         ZERO_STRUCT(req);
337         ZERO_STRUCT(rep);
338
339         req.data.list_all_domains = true;
340
341         DO_STRUCT_REQ_REP(WINBINDD_LIST_TRUSTDOM, &req, &rep);
342
343         list2 = (char *)rep.extra_data.data;
344         torture_assert(torture, list2, "NULL trust list");
345
346         /*
347          * The list_all_domains parameter should be ignored
348          */
349         torture_assert_str_equal(torture, list2, list1, "list_all_domains not ignored");
350
351         SAFE_FREE(list1);
352         SAFE_FREE(list2);
353
354         ok = get_trusted_domains(torture, &listd);
355         torture_assert(torture, ok, "failed to get trust list");
356
357         for (i=0; listd[i].netbios_name; i++) {
358                 if (i == 0) {
359                         struct dom_sid *builtin_sid;
360
361                         builtin_sid = dom_sid_parse_talloc(torture, SID_BUILTIN);
362
363                         torture_assert_str_equal(torture,
364                                                  listd[i].netbios_name,
365                                                  NAME_BUILTIN,
366                                                  "first domain should be 'BUILTIN'");
367
368                         torture_assert_str_equal(torture,
369                                                  listd[i].dns_name,
370                                                  "",
371                                                  "BUILTIN domain should not have a dns name");
372
373                         ok = dom_sid_equal(builtin_sid,
374                                            listd[i].sid);
375                         torture_assert(torture, ok, "BUILTIN domain should have S-1-5-32");
376
377                         continue;
378                 }
379
380                 /*
381                  * TODO: verify the content of the 2nd and 3rd (in member server mode)
382                  *       domain entries
383                  */
384         }
385
386         return true;
387 }
388
389 static bool torture_winbind_struct_domain_info(struct torture_context *torture)
390 {
391         bool ok;
392         struct torture_trust_domain *listd = NULL;
393         uint32_t i;
394
395         torture_comment(torture, "Running WINBINDD_DOMAIN_INFO (struct based)\n");
396
397         ok = get_trusted_domains(torture, &listd);
398         torture_assert(torture, ok, "failed to get trust list");
399
400         for (i=0; listd[i].netbios_name; i++) {
401                 struct winbindd_request req;
402                 struct winbindd_response rep;
403                 struct dom_sid *sid;
404                 char *flagstr = talloc_strdup(torture," ");
405
406                 ZERO_STRUCT(req);
407                 ZERO_STRUCT(rep);
408
409                 fstrcpy(req.domain_name, listd[i].netbios_name);
410
411                 DO_STRUCT_REQ_REP(WINBINDD_DOMAIN_INFO, &req, &rep);
412
413                 torture_assert_str_equal(torture,
414                                          rep.data.domain_info.name,
415                                          listd[i].netbios_name,
416                                          "Netbios domain name doesn't match");
417
418                 torture_assert_str_equal(torture,
419                                          rep.data.domain_info.alt_name,
420                                          listd[i].dns_name,
421                                          "DNS domain name doesn't match");
422
423                 sid = dom_sid_parse_talloc(torture, rep.data.domain_info.sid);
424                 torture_assert(torture, sid, "Failed to parse SID");
425
426                 ok = dom_sid_equal(listd[i].sid, sid);
427                 torture_assert(torture, ok, "SID's doesn't match");
428
429                 if (rep.data.domain_info.primary) {
430                         flagstr = talloc_strdup_append(flagstr, "PR ");
431                 }
432
433                 if (rep.data.domain_info.active_directory) {
434                         torture_assert(torture,
435                                        strlen(rep.data.domain_info.alt_name)>0,
436                                        "Active Directory without DNS name");
437                         flagstr = talloc_strdup_append(flagstr, "AD ");
438                 }
439
440                 if (rep.data.domain_info.native_mode) {
441                         torture_assert(torture,
442                                        rep.data.domain_info.active_directory,
443                                        "Native-Mode, but no Active Directory");
444                         flagstr = talloc_strdup_append(flagstr, "NA ");
445                 }
446
447                 torture_comment(torture, "DOMAIN '%s' => '%s' [%s]\n",
448                                 rep.data.domain_info.name,
449                                 rep.data.domain_info.alt_name,
450                                 flagstr);
451         }
452
453         return true;
454 }
455
456 static bool torture_winbind_struct_getdcname(struct torture_context *torture)
457 {
458         bool ok;
459         bool strict = torture_setting_bool(torture, "strict mode", false);
460         struct torture_trust_domain *listd = NULL;
461         uint32_t i;
462
463         torture_comment(torture, "Running WINBINDD_GETDCNAME (struct based)\n");
464
465         ok = get_trusted_domains(torture, &listd);
466         torture_assert(torture, ok, "failed to get trust list");
467
468         for (i=0; listd[i].netbios_name; i++) {
469                 struct winbindd_request req;
470                 struct winbindd_response rep;
471
472                 ZERO_STRUCT(req);
473                 ZERO_STRUCT(rep);
474
475                 fstrcpy(req.domain_name, listd[i].netbios_name);
476
477                 ok = true;
478                 DO_STRUCT_REQ_REP_EXT(WINBINDD_GETDCNAME, &req, &rep,
479                                       NSS_STATUS_SUCCESS,
480                                       (i <2 || strict), ok = false,
481                                       talloc_asprintf(torture, "DOMAIN '%s'",
482                                                       req.domain_name));
483                 if (!ok) continue;
484
485                 /* TODO: check rep.data.dc_name; */
486                 torture_comment(torture, "DOMAIN '%s' => DCNAME '%s'\n",
487                                 req.domain_name, rep.data.dc_name);
488         }
489
490         return true;
491 }
492
493 struct torture_suite *torture_winbind_struct_init(void)
494 {
495         struct torture_suite *suite = torture_suite_create(talloc_autofree_context(), "STRUCT");
496
497         torture_suite_add_simple_test(suite, "INTERFACE_VERSION", torture_winbind_struct_interface_version);
498         torture_suite_add_simple_test(suite, "PING", torture_winbind_struct_ping);
499         torture_suite_add_simple_test(suite, "INFO", torture_winbind_struct_info);
500         torture_suite_add_simple_test(suite, "PRIV_PIPE_DIR", torture_winbind_struct_priv_pipe_dir);
501         torture_suite_add_simple_test(suite, "NETBIOS_NAME", torture_winbind_struct_netbios_name);
502         torture_suite_add_simple_test(suite, "DOMAIN_NAME", torture_winbind_struct_domain_name);
503         torture_suite_add_simple_test(suite, "CHECK_MACHACC", torture_winbind_struct_check_machacc);
504         torture_suite_add_simple_test(suite, "LIST_TRUSTDOM", torture_winbind_struct_list_trustdom);
505         torture_suite_add_simple_test(suite, "DOMAIN_INFO", torture_winbind_struct_domain_info);
506         torture_suite_add_simple_test(suite, "GETDCNAME", torture_winbind_struct_getdcname);
507
508         suite->description = talloc_strdup(suite, "WINBIND - struct based protocol tests");
509
510         return suite;
511 }