4 Copyright (C) Andrew Bartlett <abartlet@samba.org> 2006
5 Copyright (C) Stefan Metzmacher <metze@samba.org> 2007
7 * NOTICE: this module is NOT released under the GNU LGPL license as
8 * other ldb code. This module is release under the GNU GPL v3 or
11 This program is free software; you can redistribute it and/or modify
12 it under the terms of the GNU General Public License as published by
13 the Free Software Foundation; either version 3 of the License, or
14 (at your option) any later version.
16 This program is distributed in the hope that it will be useful,
17 but WITHOUT ANY WARRANTY; without even the implied warranty of
18 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 GNU General Public License for more details.
21 You should have received a copy of the GNU General Public License
22 along with this program. If not, see <http://www.gnu.org/licenses/>.
28 * Component: ldb partitions module
30 * Description: Implement LDAP partitions
32 * Author: Andrew Bartlett
33 * Author: Stefan Metzmacher
37 #include "ldb/include/ldb_includes.h"
38 #include "dsdb/samdb/samdb.h"
40 struct partition_private_data {
41 struct dsdb_control_current_partition **partitions;
42 struct ldb_dn **replicate;
46 struct ldb_module *module;
47 struct ldb_request *req;
50 struct partition_context {
51 struct ldb_module *module;
52 struct ldb_request *req;
54 struct part_request *part_req;
56 int finished_requests;
59 static struct partition_context *partition_init_ctx(struct ldb_module *module, struct ldb_request *req)
61 struct partition_context *ac;
63 ac = talloc_zero(req, struct partition_context);
65 ldb_set_errstring(module->ldb, "Out of Memory");
75 #define PARTITION_FIND_OP(module, op) do { \
76 struct ldb_context *ldbctx = module->ldb; \
77 while (module && module->ops->op == NULL) module = module->next; \
78 if (module == NULL) { \
79 ldb_asprintf_errstring(ldbctx, \
80 "Unable to find backend operation for " #op ); \
81 return LDB_ERR_OPERATIONS_ERROR; \
86 * helper functions to call the next module in chain
89 int partition_request(struct ldb_module *module, struct ldb_request *request)
92 switch (request->operation) {
94 PARTITION_FIND_OP(module, search);
95 ret = module->ops->search(module, request);
98 PARTITION_FIND_OP(module, add);
99 ret = module->ops->add(module, request);
102 PARTITION_FIND_OP(module, modify);
103 ret = module->ops->modify(module, request);
106 PARTITION_FIND_OP(module, del);
107 ret = module->ops->del(module, request);
110 PARTITION_FIND_OP(module, rename);
111 ret = module->ops->rename(module, request);
114 PARTITION_FIND_OP(module, extended);
115 ret = module->ops->extended(module, request);
117 case LDB_SEQUENCE_NUMBER:
118 PARTITION_FIND_OP(module, sequence_number);
119 ret = module->ops->sequence_number(module, request);
122 PARTITION_FIND_OP(module, request);
123 ret = module->ops->request(module, request);
126 if (ret == LDB_SUCCESS) {
129 if (!ldb_errstring(module->ldb)) {
130 /* Set a default error string, to place the blame somewhere */
131 ldb_asprintf_errstring(module->ldb,
132 "error in module %s: %s (%d)",
134 ldb_strerror(ret), ret);
139 static struct dsdb_control_current_partition *find_partition(struct partition_private_data *data,
144 /* Look at base DN */
145 /* Figure out which partition it is under */
146 /* Skip the lot if 'data' isn't here yet (initialistion) */
147 for (i=0; data && data->partitions && data->partitions[i]; i++) {
148 if (ldb_dn_compare_base(data->partitions[i]->dn, dn) == 0) {
149 return data->partitions[i];
157 * fire the caller's callback for every entry, but only send 'done' once.
159 static int partition_req_callback(struct ldb_request *req,
160 struct ldb_reply *ares)
162 struct partition_context *ac;
163 struct ldb_module *module;
164 struct ldb_request *nreq;
167 ac = talloc_get_type(req->context, struct partition_context);
170 return ldb_module_done(ac->req, NULL, NULL,
171 LDB_ERR_OPERATIONS_ERROR);
173 if (ares->error != LDB_SUCCESS) {
174 return ldb_module_done(ac->req, ares->controls,
175 ares->response, ares->error);
178 switch (ares->type) {
179 case LDB_REPLY_REFERRAL:
180 /* ignore referrals for now */
183 case LDB_REPLY_ENTRY:
184 if (ac->req->operation != LDB_SEARCH) {
185 ldb_set_errstring(ac->module->ldb,
186 "partition_req_callback:"
187 " Unsupported reply type for this request");
188 return ldb_module_done(ac->req, NULL, NULL,
189 LDB_ERR_OPERATIONS_ERROR);
191 return ldb_module_send_entry(ac->req, ares->message);
194 if (ac->req->operation == LDB_EXTENDED) {
195 /* FIXME: check for ares->response, replmd does not fill it ! */
196 if (ares->response) {
197 if (strcmp(ares->response->oid, LDB_EXTENDED_START_TLS_OID) != 0) {
198 ldb_set_errstring(ac->module->ldb,
199 "partition_req_callback:"
200 " Unknown extended reply, "
201 "only supports START_TLS");
203 return ldb_module_done(ac->req, NULL, NULL,
204 LDB_ERR_OPERATIONS_ERROR);
209 ac->finished_requests++;
210 if (ac->finished_requests == ac->num_requests) {
211 /* this was the last one, call callback */
212 return ldb_module_done(ac->req, ares->controls,
213 ares->response, ares->error);
216 /* not the last, now call the next one */
217 module = ac->part_req[ac->finished_requests].module;
218 nreq = ac->part_req[ac->finished_requests].req;
220 ret = partition_request(module, nreq);
221 if (ret != LDB_SUCCESS) {
223 return ldb_module_done(ac->req, NULL, NULL, ret);
233 static int partition_prep_request(struct partition_context *ac,
234 struct dsdb_control_current_partition *partition)
237 struct ldb_request *req;
239 ac->part_req = talloc_realloc(ac, ac->part_req,
241 ac->num_requests + 1);
242 if (ac->part_req == NULL) {
243 ldb_oom(ac->module->ldb);
244 return LDB_ERR_OPERATIONS_ERROR;
247 switch (ac->req->operation) {
249 ret = ldb_build_search_req_ex(&req, ac->module->ldb,
251 ac->req->op.search.base,
252 ac->req->op.search.scope,
253 ac->req->op.search.tree,
254 ac->req->op.search.attrs,
256 ac, partition_req_callback,
260 ret = ldb_build_add_req(&req, ac->module->ldb, ac->part_req,
261 ac->req->op.add.message,
263 ac, partition_req_callback,
267 ret = ldb_build_mod_req(&req, ac->module->ldb, ac->part_req,
268 ac->req->op.mod.message,
270 ac, partition_req_callback,
274 ret = ldb_build_del_req(&req, ac->module->ldb, ac->part_req,
277 ac, partition_req_callback,
281 ret = ldb_build_rename_req(&req, ac->module->ldb, ac->part_req,
282 ac->req->op.rename.olddn,
283 ac->req->op.rename.newdn,
285 ac, partition_req_callback,
289 ret = ldb_build_extended_req(&req, ac->module->ldb,
291 ac->req->op.extended.oid,
292 ac->req->op.extended.data,
294 ac, partition_req_callback,
298 ldb_set_errstring(ac->module->ldb,
299 "Unsupported request type!");
300 ret = LDB_ERR_UNWILLING_TO_PERFORM;
303 if (ret != LDB_SUCCESS) {
307 ac->part_req[ac->num_requests].req = req;
309 if (ac->req->controls) {
310 req->controls = talloc_memdup(req, ac->req->controls,
311 talloc_get_size(ac->req->controls));
312 if (req->controls == NULL) {
313 ldb_oom(ac->module->ldb);
314 return LDB_ERR_OPERATIONS_ERROR;
319 ac->part_req[ac->num_requests].module = partition->module;
321 ret = ldb_request_add_control(req,
322 DSDB_CONTROL_CURRENT_PARTITION_OID,
324 if (ret != LDB_SUCCESS) {
328 if (req->operation == LDB_SEARCH) {
329 /* If the search is for 'more' than this partition,
330 * then change the basedn, so a remote LDAP server
332 if (ldb_dn_compare_base(partition->dn,
333 req->op.search.base) != 0) {
334 req->op.search.base = partition->dn;
339 /* make sure you put the NEXT module here, or
340 * partition_request() will simply loop forever on itself */
341 ac->part_req[ac->num_requests].module = ac->module->next;
349 static int partition_call_first(struct partition_context *ac)
351 return partition_request(ac->part_req[0].module, ac->part_req[0].req);
355 * Send a request down to all the partitions
357 static int partition_send_all(struct ldb_module *module,
358 struct partition_context *ac,
359 struct ldb_request *req)
362 struct partition_private_data *data = talloc_get_type(module->private_data,
363 struct partition_private_data);
364 int ret = partition_prep_request(ac, NULL);
365 if (ret != LDB_SUCCESS) {
368 for (i=0; data && data->partitions && data->partitions[i]; i++) {
369 ret = partition_prep_request(ac, data->partitions[i]);
370 if (ret != LDB_SUCCESS) {
375 /* fire the first one */
376 return partition_call_first(ac);
380 * Figure out which backend a request needs to be aimed at. Some
381 * requests must be replicated to all backends
383 static int partition_replicate(struct ldb_module *module, struct ldb_request *req, struct ldb_dn *dn)
385 struct partition_context *ac;
388 struct dsdb_control_current_partition *partition;
389 struct partition_private_data *data = talloc_get_type(module->private_data,
390 struct partition_private_data);
391 if (!data || !data->partitions) {
392 return ldb_next_request(module, req);
395 if (req->operation != LDB_SEARCH) {
396 /* Is this a special DN, we need to replicate to every backend? */
397 for (i=0; data->replicate && data->replicate[i]; i++) {
398 if (ldb_dn_compare(data->replicate[i],
401 ac = partition_init_ctx(module, req);
403 return LDB_ERR_OPERATIONS_ERROR;
406 return partition_send_all(module, ac, req);
411 /* Otherwise, we need to find the partition to fire it to */
414 partition = find_partition(data, dn);
417 * if we haven't found a matching partition
418 * pass the request to the main ldb
420 * TODO: we should maybe return an error here
421 * if it's not a special dn
424 return ldb_next_request(module, req);
427 ac = partition_init_ctx(module, req);
429 return LDB_ERR_OPERATIONS_ERROR;
432 /* we need to add a control but we never touch the original request */
433 ret = partition_prep_request(ac, partition);
434 if (ret != LDB_SUCCESS) {
438 /* fire the first one */
439 return partition_call_first(ac);
443 static int partition_search(struct ldb_module *module, struct ldb_request *req)
445 struct ldb_control **saved_controls;
448 struct partition_private_data *data = talloc_get_type(module->private_data,
449 struct partition_private_data);
452 /* (later) consider if we should be searching multiple
453 * partitions (for 'invisible' partition behaviour */
455 struct ldb_control *search_control = ldb_request_get_control(req, LDB_CONTROL_SEARCH_OPTIONS_OID);
456 struct ldb_control *domain_scope_control = ldb_request_get_control(req, LDB_CONTROL_DOMAIN_SCOPE_OID);
458 struct ldb_search_options_control *search_options = NULL;
459 if (search_control) {
460 search_options = talloc_get_type(search_control->data, struct ldb_search_options_control);
463 /* Remove the domain_scope control, so we don't confuse a backend server */
464 if (domain_scope_control && !save_controls(domain_scope_control, req, &saved_controls)) {
465 ldb_oom(module->ldb);
466 return LDB_ERR_OPERATIONS_ERROR;
470 Generate referrals (look for a partition under this DN) if we don't have the above control specified
473 if (search_options && (search_options->search_options & LDB_SEARCH_OPTION_PHANTOM_ROOT)) {
475 struct partition_context *ac;
476 if ((search_options->search_options & ~LDB_SEARCH_OPTION_PHANTOM_ROOT) == 0) {
477 /* We have processed this flag, so we are done with this control now */
479 /* Remove search control, so we don't confuse a backend server */
480 if (search_control && !save_controls(search_control, req, &saved_controls)) {
481 ldb_oom(module->ldb);
482 return LDB_ERR_OPERATIONS_ERROR;
485 ac = partition_init_ctx(module, req);
487 return LDB_ERR_OPERATIONS_ERROR;
490 /* Search from the base DN */
491 if (!req->op.search.base || ldb_dn_is_null(req->op.search.base)) {
492 return partition_send_all(module, ac, req);
494 for (i=0; data && data->partitions && data->partitions[i]; i++) {
495 /* Find all partitions under the search base */
496 if (ldb_dn_compare_base(data->partitions[i]->dn, req->op.search.base) == 0) {
497 ret = partition_prep_request(ac, data->partitions[i]);
498 if (ret != LDB_SUCCESS) {
504 /* Perhaps we didn't match any partitions. Try the main partition, only */
505 if (ac->num_requests == 0) {
507 return ldb_next_request(module, req);
510 /* fire the first one */
511 return partition_call_first(ac);
514 /* Handle this like all other requests */
515 if (search_control && (search_options->search_options & ~LDB_SEARCH_OPTION_PHANTOM_ROOT) == 0) {
516 /* We have processed this flag, so we are done with this control now */
518 /* Remove search control, so we don't confuse a backend server */
519 if (search_control && !save_controls(search_control, req, &saved_controls)) {
520 ldb_oom(module->ldb);
521 return LDB_ERR_OPERATIONS_ERROR;
525 return partition_replicate(module, req, req->op.search.base);
530 static int partition_add(struct ldb_module *module, struct ldb_request *req)
532 return partition_replicate(module, req, req->op.add.message->dn);
536 static int partition_modify(struct ldb_module *module, struct ldb_request *req)
538 return partition_replicate(module, req, req->op.mod.message->dn);
542 static int partition_delete(struct ldb_module *module, struct ldb_request *req)
544 return partition_replicate(module, req, req->op.del.dn);
548 static int partition_rename(struct ldb_module *module, struct ldb_request *req)
552 struct dsdb_control_current_partition *backend, *backend2;
554 struct partition_private_data *data = talloc_get_type(module->private_data,
555 struct partition_private_data);
557 /* Skip the lot if 'data' isn't here yet (initialization) */
559 return LDB_ERR_OPERATIONS_ERROR;
562 backend = find_partition(data, req->op.rename.olddn);
563 backend2 = find_partition(data, req->op.rename.newdn);
565 if ((backend && !backend2) || (!backend && backend2)) {
566 return LDB_ERR_AFFECTS_MULTIPLE_DSAS;
569 if (backend != backend2) {
570 ldb_asprintf_errstring(module->ldb,
571 "Cannot rename from %s in %s to %s in %s: %s",
572 ldb_dn_get_linearized(req->op.rename.olddn),
573 ldb_dn_get_linearized(backend->dn),
574 ldb_dn_get_linearized(req->op.rename.newdn),
575 ldb_dn_get_linearized(backend2->dn),
576 ldb_strerror(LDB_ERR_AFFECTS_MULTIPLE_DSAS));
577 return LDB_ERR_AFFECTS_MULTIPLE_DSAS;
580 for (i=0; data && data->partitions && data->partitions[i]; i++) {
581 if (ldb_dn_compare_base(data->partitions[i]->dn, req->op.rename.olddn) == 0) {
587 ldb_asprintf_errstring(module->ldb,
588 "Cannot rename from %s to %s, subtree rename would cross partition %s: %s",
589 ldb_dn_get_linearized(req->op.rename.olddn),
590 ldb_dn_get_linearized(req->op.rename.newdn),
591 ldb_dn_get_linearized(data->partitions[matched]->dn),
592 ldb_strerror(LDB_ERR_AFFECTS_MULTIPLE_DSAS));
593 return LDB_ERR_AFFECTS_MULTIPLE_DSAS;
596 return partition_replicate(module, req, req->op.rename.olddn);
599 /* start a transaction */
600 static int partition_start_trans(struct ldb_module *module)
603 struct partition_private_data *data = talloc_get_type(module->private_data,
604 struct partition_private_data);
605 /* Look at base DN */
606 /* Figure out which partition it is under */
607 /* Skip the lot if 'data' isn't here yet (initialization) */
608 ret = ldb_next_start_trans(module);
609 if (ret != LDB_SUCCESS) {
613 for (i=0; data && data->partitions && data->partitions[i]; i++) {
614 struct ldb_module *next = data->partitions[i]->module;
615 PARTITION_FIND_OP(next, start_transaction);
617 ret = next->ops->start_transaction(next);
618 if (ret != LDB_SUCCESS) {
619 /* Back it out, if it fails on one */
620 for (i--; i >= 0; i--) {
621 next = data->partitions[i]->module;
622 PARTITION_FIND_OP(next, del_transaction);
624 next->ops->del_transaction(next);
626 ldb_next_del_trans(module);
633 /* end a transaction */
634 static int partition_end_trans(struct ldb_module *module)
637 struct partition_private_data *data = talloc_get_type(module->private_data,
638 struct partition_private_data);
639 ret = ldb_next_end_trans(module);
640 if (ret != LDB_SUCCESS) {
644 /* Look at base DN */
645 /* Figure out which partition it is under */
646 /* Skip the lot if 'data' isn't here yet (initialistion) */
647 for (i=0; data && data->partitions && data->partitions[i]; i++) {
648 struct ldb_module *next = data->partitions[i]->module;
649 PARTITION_FIND_OP(next, end_transaction);
651 ret = next->ops->end_transaction(next);
652 if (ret != LDB_SUCCESS) {
653 /* Back it out, if it fails on one */
654 for (i--; i >= 0; i--) {
655 next = data->partitions[i]->module;
656 PARTITION_FIND_OP(next, del_transaction);
658 next->ops->del_transaction(next);
660 ldb_next_del_trans(module);
668 /* delete a transaction */
669 static int partition_del_trans(struct ldb_module *module)
671 int i, ret, ret2 = LDB_SUCCESS;
672 struct partition_private_data *data = talloc_get_type(module->private_data,
673 struct partition_private_data);
674 ret = ldb_next_del_trans(module);
675 if (ret != LDB_SUCCESS) {
679 /* Look at base DN */
680 /* Figure out which partition it is under */
681 /* Skip the lot if 'data' isn't here yet (initialistion) */
682 for (i=0; data && data->partitions && data->partitions[i]; i++) {
683 struct ldb_module *next = data->partitions[i]->module;
684 PARTITION_FIND_OP(next, del_transaction);
686 ret = next->ops->del_transaction(next);
687 if (ret != LDB_SUCCESS) {
694 /* NOTE: ldb_sequence_number is still a completely SYNCHRONOUS call
695 * implemented only in ldb_rdb. It does not require ldb_wait() to be
696 * called after a request is made */
697 static int partition_sequence_number(struct ldb_module *module, struct ldb_request *req)
700 uint64_t seq_number = 0;
701 uint64_t timestamp_sequence = 0;
702 uint64_t timestamp = 0;
703 struct partition_private_data *data = talloc_get_type(module->private_data,
704 struct partition_private_data);
706 switch (req->op.seq_num.type) {
708 case LDB_SEQ_HIGHEST_SEQ:
709 ret = ldb_next_request(module, req);
710 if (ret != LDB_SUCCESS) {
713 if (req->op.seq_num.flags & LDB_SEQ_TIMESTAMP_SEQUENCE) {
714 timestamp_sequence = req->op.seq_num.seq_num;
716 seq_number = seq_number + req->op.seq_num.seq_num;
719 /* gross hack part1 */
720 ret = ldb_request_add_control(req,
721 DSDB_CONTROL_CURRENT_PARTITION_OID,
723 if (ret != LDB_SUCCESS) {
727 /* Look at base DN */
728 /* Figure out which partition it is under */
729 /* Skip the lot if 'data' isn't here yet (initialistion) */
730 for (i=0; data && data->partitions && data->partitions[i]; i++) {
732 /* gross hack part2 */
734 for (j=0; req->controls[j]; j++) {
735 if (strcmp(req->controls[j]->oid, DSDB_CONTROL_CURRENT_PARTITION_OID) == 0) {
736 req->controls[j]->data = data->partitions[i];
741 ret = partition_request(data->partitions[i]->module, req);
742 if (ret != LDB_SUCCESS) {
745 if (req->op.seq_num.flags & LDB_SEQ_TIMESTAMP_SEQUENCE) {
746 timestamp_sequence = MAX(timestamp_sequence, req->op.seq_num.seq_num);
748 seq_number = seq_number + req->op.seq_num.seq_num;
752 case LDB_SEQ_HIGHEST_TIMESTAMP:
754 struct ldb_request *date_req = talloc(req, struct ldb_request);
756 return LDB_ERR_OPERATIONS_ERROR;
759 date_req->op.seq_num.flags = LDB_SEQ_HIGHEST_TIMESTAMP;
761 ret = ldb_next_request(module, date_req);
762 if (ret != LDB_SUCCESS) {
765 timestamp = date_req->op.seq_num.seq_num;
767 /* Look at base DN */
768 /* Figure out which partition it is under */
769 /* Skip the lot if 'data' isn't here yet (initialistion) */
770 for (i=0; data && data->partitions && data->partitions[i]; i++) {
772 ret = partition_request(data->partitions[i]->module, req);
773 if (ret != LDB_SUCCESS) {
776 timestamp = MAX(timestamp, date_req->op.seq_num.seq_num);
782 switch (req->op.seq_num.flags) {
784 case LDB_SEQ_HIGHEST_SEQ:
786 req->op.seq_num.flags = 0;
788 /* Has someone above set a timebase sequence? */
789 if (timestamp_sequence) {
790 req->op.seq_num.seq_num = (((unsigned long long)timestamp << 24) | (seq_number & 0xFFFFFF));
792 req->op.seq_num.seq_num = seq_number;
795 if (timestamp_sequence > req->op.seq_num.seq_num) {
796 req->op.seq_num.seq_num = timestamp_sequence;
797 req->op.seq_num.flags |= LDB_SEQ_TIMESTAMP_SEQUENCE;
800 req->op.seq_num.flags |= LDB_SEQ_GLOBAL_SEQUENCE;
802 case LDB_SEQ_HIGHEST_TIMESTAMP:
803 req->op.seq_num.seq_num = timestamp;
807 switch (req->op.seq_num.flags) {
809 req->op.seq_num.seq_num++;
814 static int partition_extended_replicated_objects(struct ldb_module *module, struct ldb_request *req)
816 struct dsdb_extended_replicated_objects *ext;
818 ext = talloc_get_type(req->op.extended.data, struct dsdb_extended_replicated_objects);
820 ldb_debug(module->ldb, LDB_DEBUG_FATAL, "partition_extended_replicated_objects: invalid extended data\n");
821 return LDB_ERR_PROTOCOL_ERROR;
824 if (ext->version != DSDB_EXTENDED_REPLICATED_OBJECTS_VERSION) {
825 ldb_debug(module->ldb, LDB_DEBUG_FATAL, "partition_extended_replicated_objects: extended data invalid version [%u != %u]\n",
826 ext->version, DSDB_EXTENDED_REPLICATED_OBJECTS_VERSION);
827 return LDB_ERR_PROTOCOL_ERROR;
830 return partition_replicate(module, req, ext->partition_dn);
833 static int partition_extended_schema_update_now(struct ldb_module *module, struct ldb_request *req)
835 struct dsdb_control_current_partition *partition;
836 struct partition_private_data *data;
837 struct ldb_dn *schema_dn;
838 struct partition_context *ac;
841 schema_dn = talloc_get_type(req->op.extended.data, struct ldb_dn);
843 ldb_debug(module->ldb, LDB_DEBUG_FATAL, "partition_extended: invalid extended data\n");
844 return LDB_ERR_PROTOCOL_ERROR;
847 data = talloc_get_type(module->private_data, struct partition_private_data);
849 return LDB_ERR_OPERATIONS_ERROR;
852 partition = find_partition( data, schema_dn );
854 return ldb_next_request(module, req);
857 ac = partition_init_ctx(module, req);
859 return LDB_ERR_OPERATIONS_ERROR;
862 /* we need to add a control but we never touch the original request */
863 ret = partition_prep_request(ac, partition);
864 if (ret != LDB_SUCCESS) {
868 /* fire the first one */
869 return partition_call_first(ac);
874 static int partition_extended(struct ldb_module *module, struct ldb_request *req)
876 struct partition_private_data *data;
877 struct partition_context *ac;
879 data = talloc_get_type(module->private_data, struct partition_private_data);
880 if (!data || !data->partitions) {
881 return ldb_next_request(module, req);
884 if (strcmp(req->op.extended.oid, DSDB_EXTENDED_REPLICATED_OBJECTS_OID) == 0) {
885 return partition_extended_replicated_objects(module, req);
888 /* forward schemaUpdateNow operation to schema_fsmo module*/
889 if (strcmp(req->op.extended.oid, DSDB_EXTENDED_SCHEMA_UPDATE_NOW_OID) == 0) {
890 return partition_extended_schema_update_now( module, req );
894 * as the extended operation has no dn
895 * we need to send it to all partitions
898 ac = partition_init_ctx(module, req);
900 return LDB_ERR_OPERATIONS_ERROR;
903 return partition_send_all(module, ac, req);
906 static int partition_sort_compare(const void *v1, const void *v2)
908 struct dsdb_control_current_partition *p1;
909 struct dsdb_control_current_partition *p2;
911 p1 = *((struct dsdb_control_current_partition **)v1);
912 p2 = *((struct dsdb_control_current_partition **)v2);
914 return ldb_dn_compare(p1->dn, p2->dn);
917 static int partition_init(struct ldb_module *module)
920 TALLOC_CTX *mem_ctx = talloc_new(module);
921 const char *attrs[] = { "partition", "replicateEntries", "modules", NULL };
922 struct ldb_result *res;
923 struct ldb_message *msg;
924 struct ldb_message_element *partition_attributes;
925 struct ldb_message_element *replicate_attributes;
926 struct ldb_message_element *modules_attributes;
928 struct partition_private_data *data;
931 return LDB_ERR_OPERATIONS_ERROR;
934 data = talloc(mem_ctx, struct partition_private_data);
936 return LDB_ERR_OPERATIONS_ERROR;
939 ret = ldb_search(module->ldb, mem_ctx, &res,
940 ldb_dn_new(mem_ctx, module->ldb, "@PARTITION"),
941 LDB_SCOPE_BASE, attrs, NULL);
942 if (ret != LDB_SUCCESS) {
943 talloc_free(mem_ctx);
946 if (res->count == 0) {
947 talloc_free(mem_ctx);
948 return ldb_next_init(module);
951 if (res->count > 1) {
952 talloc_free(mem_ctx);
953 return LDB_ERR_CONSTRAINT_VIOLATION;
958 partition_attributes = ldb_msg_find_element(msg, "partition");
959 if (!partition_attributes) {
960 ldb_set_errstring(module->ldb, "partition_init: no partitions specified");
961 talloc_free(mem_ctx);
962 return LDB_ERR_CONSTRAINT_VIOLATION;
964 data->partitions = talloc_array(data, struct dsdb_control_current_partition *, partition_attributes->num_values + 1);
965 if (!data->partitions) {
966 talloc_free(mem_ctx);
967 return LDB_ERR_OPERATIONS_ERROR;
969 for (i=0; i < partition_attributes->num_values; i++) {
970 char *base = talloc_strdup(data->partitions, (char *)partition_attributes->values[i].data);
971 char *p = strchr(base, ':');
973 ldb_asprintf_errstring(module->ldb,
975 "invalid form for partition record (missing ':'): %s", base);
976 talloc_free(mem_ctx);
977 return LDB_ERR_CONSTRAINT_VIOLATION;
982 ldb_asprintf_errstring(module->ldb,
984 "invalid form for partition record (missing backend database): %s", base);
985 talloc_free(mem_ctx);
986 return LDB_ERR_CONSTRAINT_VIOLATION;
988 data->partitions[i] = talloc(data->partitions, struct dsdb_control_current_partition);
989 if (!data->partitions[i]) {
990 talloc_free(mem_ctx);
991 return LDB_ERR_OPERATIONS_ERROR;
993 data->partitions[i]->version = DSDB_CONTROL_CURRENT_PARTITION_VERSION;
995 data->partitions[i]->dn = ldb_dn_new(data->partitions[i], module->ldb, base);
996 if (!data->partitions[i]->dn) {
997 ldb_asprintf_errstring(module->ldb,
998 "partition_init: invalid DN in partition record: %s", base);
999 talloc_free(mem_ctx);
1000 return LDB_ERR_CONSTRAINT_VIOLATION;
1003 data->partitions[i]->backend = samdb_relative_path(module->ldb,
1004 data->partitions[i],
1006 if (!data->partitions[i]->backend) {
1007 ldb_asprintf_errstring(module->ldb,
1008 "partition_init: unable to determine an relative path for partition: %s", base);
1009 talloc_free(mem_ctx);
1011 ret = ldb_connect_backend(module->ldb, data->partitions[i]->backend, NULL, &data->partitions[i]->module);
1012 if (ret != LDB_SUCCESS) {
1013 talloc_free(mem_ctx);
1017 data->partitions[i] = NULL;
1019 /* sort these into order, most to least specific */
1020 qsort(data->partitions, partition_attributes->num_values,
1021 sizeof(*data->partitions), partition_sort_compare);
1023 for (i=0; data->partitions[i]; i++) {
1024 struct ldb_request *req;
1025 req = talloc_zero(mem_ctx, struct ldb_request);
1027 ldb_debug(module->ldb, LDB_DEBUG_ERROR, "partition: Out of memory!\n");
1028 talloc_free(mem_ctx);
1029 return LDB_ERR_OPERATIONS_ERROR;
1032 req->operation = LDB_REQ_REGISTER_PARTITION;
1033 req->op.reg_partition.dn = data->partitions[i]->dn;
1034 req->callback = ldb_op_default_callback;
1036 ldb_set_timeout(module->ldb, req, 0);
1038 req->handle = ldb_handle_new(req, module->ldb);
1039 if (req->handle == NULL) {
1040 return LDB_ERR_OPERATIONS_ERROR;
1043 ret = ldb_request(module->ldb, req);
1044 if (ret == LDB_SUCCESS) {
1045 ret = ldb_wait(req->handle, LDB_WAIT_ALL);
1047 if (ret != LDB_SUCCESS) {
1048 ldb_debug(module->ldb, LDB_DEBUG_ERROR, "partition: Unable to register partition with rootdse!\n");
1049 talloc_free(mem_ctx);
1050 return LDB_ERR_OTHER;
1055 replicate_attributes = ldb_msg_find_element(msg, "replicateEntries");
1056 if (!replicate_attributes) {
1057 data->replicate = NULL;
1059 data->replicate = talloc_array(data, struct ldb_dn *, replicate_attributes->num_values + 1);
1060 if (!data->replicate) {
1061 talloc_free(mem_ctx);
1062 return LDB_ERR_OPERATIONS_ERROR;
1065 for (i=0; i < replicate_attributes->num_values; i++) {
1066 data->replicate[i] = ldb_dn_from_ldb_val(data->replicate, module->ldb, &replicate_attributes->values[i]);
1067 if (!ldb_dn_validate(data->replicate[i])) {
1068 ldb_asprintf_errstring(module->ldb,
1070 "invalid DN in partition replicate record: %s",
1071 replicate_attributes->values[i].data);
1072 talloc_free(mem_ctx);
1073 return LDB_ERR_CONSTRAINT_VIOLATION;
1076 data->replicate[i] = NULL;
1079 /* Make the private data available to any searches the modules may trigger in initialisation */
1080 module->private_data = data;
1081 talloc_steal(module, data);
1083 modules_attributes = ldb_msg_find_element(msg, "modules");
1084 if (modules_attributes) {
1085 for (i=0; i < modules_attributes->num_values; i++) {
1086 struct ldb_dn *base_dn;
1088 struct dsdb_control_current_partition *partition = NULL;
1089 const char **modules = NULL;
1091 char *base = talloc_strdup(data->partitions, (char *)modules_attributes->values[i].data);
1092 char *p = strchr(base, ':');
1094 ldb_asprintf_errstring(module->ldb,
1096 "invalid form for partition module record (missing ':'): %s", base);
1097 talloc_free(mem_ctx);
1098 return LDB_ERR_CONSTRAINT_VIOLATION;
1103 ldb_asprintf_errstring(module->ldb,
1105 "invalid form for partition module record (missing backend database): %s", base);
1106 talloc_free(mem_ctx);
1107 return LDB_ERR_CONSTRAINT_VIOLATION;
1110 modules = ldb_modules_list_from_string(module->ldb, mem_ctx,
1113 base_dn = ldb_dn_new(mem_ctx, module->ldb, base);
1114 if (!ldb_dn_validate(base_dn)) {
1115 talloc_free(mem_ctx);
1116 return LDB_ERR_OPERATIONS_ERROR;
1119 for (partition_idx = 0; data->partitions[partition_idx]; partition_idx++) {
1120 if (ldb_dn_compare(data->partitions[partition_idx]->dn, base_dn) == 0) {
1121 partition = data->partitions[partition_idx];
1127 ldb_asprintf_errstring(module->ldb,
1129 "invalid form for partition module record (no such partition): %s", base);
1130 talloc_free(mem_ctx);
1131 return LDB_ERR_CONSTRAINT_VIOLATION;
1134 ret = ldb_load_modules_list(module->ldb, modules, partition->module, &partition->module);
1135 if (ret != LDB_SUCCESS) {
1136 ldb_asprintf_errstring(module->ldb,
1138 "loading backend for %s failed: %s",
1139 base, ldb_errstring(module->ldb));
1140 talloc_free(mem_ctx);
1143 ret = ldb_init_module_chain(module->ldb, partition->module);
1144 if (ret != LDB_SUCCESS) {
1145 ldb_asprintf_errstring(module->ldb,
1147 "initialising backend for %s failed: %s",
1148 base, ldb_errstring(module->ldb));
1149 talloc_free(mem_ctx);
1155 talloc_free(mem_ctx);
1156 return ldb_next_init(module);
1159 _PUBLIC_ const struct ldb_module_ops ldb_partition_module_ops = {
1160 .name = "partition",
1161 .init_context = partition_init,
1162 .search = partition_search,
1163 .add = partition_add,
1164 .modify = partition_modify,
1165 .del = partition_delete,
1166 .rename = partition_rename,
1167 .extended = partition_extended,
1168 .sequence_number = partition_sequence_number,
1169 .start_transaction = partition_start_trans,
1170 .end_transaction = partition_end_trans,
1171 .del_transaction = partition_del_trans,