From: Samuel Cabrero Date: Mon, 6 Feb 2023 17:35:29 +0000 (+0100) Subject: winbind:varlink: Implement get group record by name X-Git-Tag: tevent-0.17.0~738 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e8813b2d620b9a1896037a479d42249d70bec0a9;p=thirdparty%2Fsamba.git winbind:varlink: Implement get group record by name $> userdbctl -s org.samba.winbind group "AFOREST+domain users" Enabled services: org.samba.winbind Group name: AFOREST+domain users Disposition: regular GID: 20513 Service: org.samba.winbind $> SYSTEMD_LOG_LEVEL=7 getent -sgroup:systemd group "AFOREST+domain users" varlink: Setting state idle-client /run/systemd/userdb/org.samba.winbind: Sending message: {"method":"io.systemd.UserDatabase.GetGroupRecord","parameters":{"groupName":"AFOREST+domain users","service":"org.samba.winbind"}} /run/systemd/userdb/org.samba.winbind: Changing state idle-client → awaiting-reply /run/systemd/userdb/org.samba.winbind: New incoming message: {"parameters":{"incomplete":false,"record":{"gid":20513,"groupName":"AFOREST+domain users","members":["AFOREST+administrator","AFOREST+user1","AFOREST+krbtgt"],"service":"org.samba.winbind"}}} /run/systemd/userdb/org.samba.winbind: Changing state awaiting-reply → processing-reply /run/systemd/userdb/org.samba.winbind: Changing state processing-reply → idle-client varlink: Setting state idle-client /run/systemd/userdb/org.samba.winbind: Sending message: {"method":"io.systemd.UserDatabase.GetMemberships","parameters":{"groupName":"AFOREST+domain users","service":"org.samba.winbind"},"more":true} /run/systemd/userdb/org.samba.winbind: Changing state idle-client → awaiting-reply-more /run/systemd/userdb/org.samba.winbind: New incoming message: {"error":"io.systemd.UserDatabase.NoRecordFound"} /run/systemd/userdb/org.samba.winbind: Changing state awaiting-reply-more → processing-reply Got lookup error: io.systemd.UserDatabase.NoRecordFound /run/systemd/userdb/org.samba.winbind: Changing state processing-reply → idle-client AFOREST+domain users:x:20513:AFOREST+administrator,AFOREST+user1,AFOREST+krbtgt Signed-off-by: Samuel Cabrero Reviewed-by: Andreas Schneider --- diff --git a/source3/winbindd/winbindd_varlink.c b/source3/winbindd/winbindd_varlink.c index dcb3aae590c..95bf0fb4fb5 100644 --- a/source3/winbindd/winbindd_varlink.c +++ b/source3/winbindd/winbindd_varlink.c @@ -297,6 +297,14 @@ static long io_systemd_getgrouprecord(VarlinkService *service, flags, parm_service, parm_gid); + } else if (parm_name != NULL && parm_gid == -1) { + /* getgrnam */ + status = wb_vl_group_by_name(state, + state->ev_ctx, + call, + flags, + parm_service, + parm_name); } if (NT_STATUS_IS_ERR(status)) { diff --git a/source3/winbindd/winbindd_varlink.h b/source3/winbindd/winbindd_varlink.h index 10c6177b455..06caca0bf66 100644 --- a/source3/winbindd/winbindd_varlink.h +++ b/source3/winbindd/winbindd_varlink.h @@ -79,6 +79,12 @@ NTSTATUS wb_vl_group_by_gid(TALLOC_CTX *mem_ctx, uint64_t flags, const char *service, int64_t gid); +NTSTATUS wb_vl_group_by_name(TALLOC_CTX *mem_ctx, + struct tevent_context *ev_ctx, + VarlinkCall *call, + uint64_t flags, + const char *service, + const char *group_name); bool winbind_setup_varlink(TALLOC_CTX *mem_ctx, struct tevent_context *ev_ctx); diff --git a/source3/winbindd/winbindd_varlink_getgrouprecord.c b/source3/winbindd/winbindd_varlink_getgrouprecord.c index 55241b3beda..1245029eddf 100644 --- a/source3/winbindd/winbindd_varlink_getgrouprecord.c +++ b/source3/winbindd/winbindd_varlink_getgrouprecord.c @@ -19,6 +19,7 @@ #include "includes.h" #include "winbindd.h" +#include "lib/util/string_wrappers.h" #include "winbindd_varlink.h" static void group_record_reply(VarlinkCall *call, @@ -500,3 +501,126 @@ fail: TALLOC_FREE(s); return status; } + +/****************************************************************************** + * Group by name + *****************************************************************************/ + +struct group_by_name_state { + struct tevent_context *ev_ctx; + struct winbindd_request *fake_req; + struct winbindd_cli_state *fake_cli; + VarlinkCall *call; +}; + +static int group_by_name_state_destructor(struct group_by_name_state *s) +{ + if (s->call != NULL) { + s->call = varlink_call_unref(s->call); + } + + return 0; +} + +static void group_by_name_getgrnam_done(struct tevent_req *req) +{ + struct group_by_name_state *s = + tevent_req_callback_data(req, struct group_by_name_state); + struct winbindd_response *response = NULL; + NTSTATUS status; + + /* winbindd_*_recv functions expect a talloc-allocated response */ + response = talloc_zero(s, struct winbindd_response); + if (response == NULL) { + DBG_ERR("No memory\n"); + varlink_call_reply_error( + s->call, + WB_VL_REPLY_ERROR_SERVICE_NOT_AVAILABLE, + NULL); + goto out; + } + + status = winbindd_getgrnam_recv(req, response); + TALLOC_FREE(req); + + if (NT_STATUS_EQUAL(status, NT_STATUS_NONE_MAPPED)) { + varlink_call_reply_error(s->call, + WB_VL_REPLY_ERROR_NO_RECORD_FOUND, + NULL); + goto out; + } else if (NT_STATUS_IS_ERR(status)) { + DBG_ERR("winbindd_getgrnam failed: %s\n", nt_errstr(status)); + varlink_call_reply_error( + s->call, + WB_VL_REPLY_ERROR_SERVICE_NOT_AVAILABLE, + NULL); + goto out; + } + + group_record_reply(s->call, + &response->data.gr, + response->extra_data.data, + false); + +out: + TALLOC_FREE(s); +} + +NTSTATUS wb_vl_group_by_name(TALLOC_CTX *mem_ctx, + struct tevent_context *ev_ctx, + VarlinkCall *call, + uint64_t flags, + const char *service, + const char *group_name) +{ + struct group_by_name_state *s = NULL; + struct tevent_req *req = NULL; + NTSTATUS status; + + s = talloc_zero(mem_ctx, struct group_by_name_state); + if (s == NULL) { + DBG_ERR("No memory\n"); + return NT_STATUS_NO_MEMORY; + } + talloc_set_destructor(s, group_by_name_state_destructor); + + s->fake_cli = talloc_zero(s, struct winbindd_cli_state); + if (s->fake_cli == NULL) { + DBG_ERR("No memory\n"); + status = NT_STATUS_NO_MEMORY; + goto fail; + } + + s->fake_req = talloc_zero(s, struct winbindd_request); + if (s->fake_req == NULL) { + DBG_ERR("No memory\n"); + status = NT_STATUS_NO_MEMORY; + goto fail; + } + + s->ev_ctx = ev_ctx; + s->call = varlink_call_ref(call); + + status = wb_vl_fake_cli_state(call, service, s->fake_cli); + if (NT_STATUS_IS_ERR(status)) { + DBG_ERR("Failed to create fake winbindd_cli_state: %s\n", + nt_errstr(status)); + goto fail; + } + + s->fake_req->cmd = WINBINDD_GETGRNAM; + fstrcpy(s->fake_req->data.username, group_name); + + req = winbindd_getgrnam_send(s, s->ev_ctx, s->fake_cli, s->fake_req); + if (req == NULL) { + DBG_ERR("No memory\n"); + status = NT_STATUS_NO_MEMORY; + goto fail; + } + tevent_req_set_callback(req, group_by_name_getgrnam_done, s); + + return NT_STATUS_OK; +fail: + TALLOC_FREE(s); + return status; +}