8322 nl: misleading-indentation
[unleashed/tickless.git] / usr / src / lib / smbsrv / libsmb / common / smb_idmap.c
blob9edcbea2f9ff742b9a9ceb4d442c37b4c54a4f22
1 /*
2 * CDDL HEADER START
4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://www.opensolaris.org/os/licensing.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
19 * CDDL HEADER END
22 * Copyright (c) 2007, 2010, Oracle and/or its affiliates. All rights reserved.
23 * Copyright 2014 Nexenta Systems, Inc. All rights reserved.
27 * SMB server interface to idmap
28 * (smb_idmap_get..., smb_idmap_batch_...)
30 * There are three implementations of this interface:
31 * uts/common/fs/smbsrv/smb_idmap.c (smbsrv kmod)
32 * lib/smbsrv/libfksmbsrv/common/fksmb_idmap.c (libfksmbsrv)
33 * lib/smbsrv/libsmb/common/smb_idmap.c (libsmb)
35 * There are enough differences (relative to the code size)
36 * that it's more trouble than it's worth to merge them.
38 * This one differs from the others in that it:
39 * calls idmap interfaces (libidmap)
40 * domain SIDs returned are allocated
43 #include <syslog.h>
44 #include <strings.h>
45 #include <smbsrv/libsmb.h>
47 static int smb_idmap_batch_binsid(smb_idmap_batch_t *sib);
50 * Report an idmap error.
52 void
53 smb_idmap_check(const char *s, idmap_stat stat)
55 if (stat != IDMAP_SUCCESS) {
56 if (s == NULL)
57 s = "smb_idmap_check";
59 syslog(LOG_ERR, "%s: %s", s, idmap_stat2string(stat));
64 * smb_idmap_getsid
66 * Tries to get a mapping for the given uid/gid
67 * Allocates ->sim_domsid
69 idmap_stat
70 smb_idmap_getsid(uid_t id, int idtype, smb_sid_t **sid)
72 smb_idmap_batch_t sib;
73 idmap_stat stat;
75 stat = smb_idmap_batch_create(&sib, 1, SMB_IDMAP_ID2SID);
76 if (stat != IDMAP_SUCCESS)
77 return (stat);
79 stat = smb_idmap_batch_getsid(sib.sib_idmaph, &sib.sib_maps[0],
80 id, idtype);
82 if (stat != IDMAP_SUCCESS) {
83 smb_idmap_batch_destroy(&sib);
84 return (stat);
87 stat = smb_idmap_batch_getmappings(&sib);
89 if (stat != IDMAP_SUCCESS) {
90 smb_idmap_batch_destroy(&sib);
91 return (stat);
94 *sid = smb_sid_dup(sib.sib_maps[0].sim_sid);
96 smb_idmap_batch_destroy(&sib);
98 return (IDMAP_SUCCESS);
102 * smb_idmap_getid
104 * Tries to get a mapping for the given SID
106 idmap_stat
107 smb_idmap_getid(smb_sid_t *sid, uid_t *id, int *id_type)
109 smb_idmap_batch_t sib;
110 smb_idmap_t *sim;
111 idmap_stat stat;
113 stat = smb_idmap_batch_create(&sib, 1, SMB_IDMAP_SID2ID);
114 if (stat != IDMAP_SUCCESS)
115 return (stat);
117 sim = &sib.sib_maps[0];
118 sim->sim_id = id;
119 stat = smb_idmap_batch_getid(sib.sib_idmaph, sim, sid, *id_type);
120 if (stat != IDMAP_SUCCESS) {
121 smb_idmap_batch_destroy(&sib);
122 return (stat);
125 stat = smb_idmap_batch_getmappings(&sib);
127 if (stat != IDMAP_SUCCESS) {
128 smb_idmap_batch_destroy(&sib);
129 return (stat);
132 *id_type = sim->sim_idtype;
133 smb_idmap_batch_destroy(&sib);
135 return (IDMAP_SUCCESS);
139 * smb_idmap_batch_create
141 * Creates and initializes the context for batch ID mapping.
143 idmap_stat
144 smb_idmap_batch_create(smb_idmap_batch_t *sib, uint16_t nmap, int flags)
146 idmap_stat stat;
148 if (!sib)
149 return (IDMAP_ERR_ARG);
151 bzero(sib, sizeof (smb_idmap_batch_t));
152 stat = idmap_get_create(&sib->sib_idmaph);
154 if (stat != IDMAP_SUCCESS) {
155 smb_idmap_check("idmap_get_create", stat);
156 return (stat);
159 sib->sib_flags = flags;
160 sib->sib_nmap = nmap;
161 sib->sib_size = nmap * sizeof (smb_idmap_t);
162 sib->sib_maps = malloc(sib->sib_size);
163 if (!sib->sib_maps)
164 return (IDMAP_ERR_MEMORY);
166 bzero(sib->sib_maps, sib->sib_size);
167 return (IDMAP_SUCCESS);
171 * smb_idmap_batch_destroy
173 * Frees the batch ID mapping context.
175 void
176 smb_idmap_batch_destroy(smb_idmap_batch_t *sib)
178 int i;
180 if (sib == NULL)
181 return;
183 if (sib->sib_idmaph) {
184 idmap_get_destroy(sib->sib_idmaph);
185 sib->sib_idmaph = NULL;
188 if (sib->sib_maps == NULL)
189 return;
191 if (sib->sib_flags & SMB_IDMAP_ID2SID) {
193 * SIDs are allocated only when mapping
194 * UID/GID to SIDs
196 for (i = 0; i < sib->sib_nmap; i++) {
197 smb_sid_free(sib->sib_maps[i].sim_sid);
198 free(sib->sib_maps[i].sim_domsid);
202 if (sib->sib_size && sib->sib_maps) {
203 free(sib->sib_maps);
204 sib->sib_maps = NULL;
209 * smb_idmap_batch_getid
211 * Queue a request to map the given SID to a UID or GID.
213 * sim->sim_id should point to variable that's supposed to
214 * hold the returned UID/GID. This needs to be setup by caller
215 * of this function.
216 * If requested ID type is known, it's passed as 'idtype',
217 * if it's unknown it'll be returned in sim->sim_idtype.
219 idmap_stat
220 smb_idmap_batch_getid(idmap_get_handle_t *idmaph, smb_idmap_t *sim,
221 smb_sid_t *sid, int idtype)
223 char sidstr[SMB_SID_STRSZ];
224 idmap_stat stat;
225 int flag = 0;
227 if (idmaph == NULL || sim == NULL || sid == NULL)
228 return (IDMAP_ERR_ARG);
230 smb_sid_tostr(sid, sidstr);
231 if (smb_sid_splitstr(sidstr, &sim->sim_rid) != 0)
232 return (IDMAP_ERR_SID);
233 sim->sim_domsid = sidstr;
234 sim->sim_idtype = idtype;
236 switch (idtype) {
237 case SMB_IDMAP_USER:
238 stat = idmap_get_uidbysid(idmaph, sim->sim_domsid,
239 sim->sim_rid, flag, sim->sim_id, &sim->sim_stat);
240 smb_idmap_check("idmap_get_uidbysid", stat);
241 break;
243 case SMB_IDMAP_GROUP:
244 stat = idmap_get_gidbysid(idmaph, sim->sim_domsid,
245 sim->sim_rid, flag, sim->sim_id, &sim->sim_stat);
246 smb_idmap_check("idmap_get_gidbysid", stat);
247 break;
249 case SMB_IDMAP_UNKNOWN:
250 stat = idmap_get_pidbysid(idmaph, sim->sim_domsid,
251 sim->sim_rid, flag, sim->sim_id, &sim->sim_idtype,
252 &sim->sim_stat);
253 smb_idmap_check("idmap_get_pidbysid", stat);
254 break;
256 default:
257 stat = IDMAP_ERR_ARG;
258 break;
261 /* This was copied by idmap_get_Xbysid. */
262 sim->sim_domsid = NULL;
264 return (stat);
268 * smb_idmap_batch_getsid
270 * Queue a request to map the given UID/GID to a SID.
272 * sim->sim_domsid and sim->sim_rid will contain the mapping
273 * result upon successful process of the batched request.
274 * NB: sim_domsid allocated by strdup, here or in libidmap
276 idmap_stat
277 smb_idmap_batch_getsid(idmap_get_handle_t *idmaph, smb_idmap_t *sim,
278 uid_t id, int idtype)
280 idmap_stat stat;
281 int flag = 0;
283 if (!idmaph || !sim)
284 return (IDMAP_ERR_ARG);
286 switch (idtype) {
287 case SMB_IDMAP_USER:
288 stat = idmap_get_sidbyuid(idmaph, id, flag,
289 &sim->sim_domsid, &sim->sim_rid, &sim->sim_stat);
290 smb_idmap_check("idmap_get_sidbyuid", stat);
291 break;
293 case SMB_IDMAP_GROUP:
294 stat = idmap_get_sidbygid(idmaph, id, flag,
295 &sim->sim_domsid, &sim->sim_rid, &sim->sim_stat);
296 smb_idmap_check("idmap_get_sidbygid", stat);
297 break;
299 case SMB_IDMAP_OWNERAT:
300 /* Current Owner S-1-5-32-766 */
301 sim->sim_domsid = strdup(NT_BUILTIN_DOMAIN_SIDSTR);
302 sim->sim_rid = SECURITY_CURRENT_OWNER_RID;
303 sim->sim_stat = IDMAP_SUCCESS;
304 stat = IDMAP_SUCCESS;
305 break;
307 case SMB_IDMAP_GROUPAT:
308 /* Current Group S-1-5-32-767 */
309 sim->sim_domsid = strdup(NT_BUILTIN_DOMAIN_SIDSTR);
310 sim->sim_rid = SECURITY_CURRENT_GROUP_RID;
311 sim->sim_stat = IDMAP_SUCCESS;
312 stat = IDMAP_SUCCESS;
313 break;
315 case SMB_IDMAP_EVERYONE:
316 /* Everyone S-1-1-0 */
317 sim->sim_domsid = strdup(NT_WORLD_AUTH_SIDSTR);
318 sim->sim_rid = 0;
319 sim->sim_stat = IDMAP_SUCCESS;
320 stat = IDMAP_SUCCESS;
321 break;
323 default:
324 return (IDMAP_ERR_ARG);
327 return (stat);
331 * smb_idmap_batch_getmappings
333 * trigger ID mapping service to get the mappings for queued
334 * requests.
336 * Checks the result of all the queued requests.
338 idmap_stat
339 smb_idmap_batch_getmappings(smb_idmap_batch_t *sib)
341 idmap_stat stat = IDMAP_SUCCESS;
342 smb_idmap_t *sim;
343 int i;
345 if ((stat = idmap_get_mappings(sib->sib_idmaph)) != IDMAP_SUCCESS) {
346 smb_idmap_check("idmap_get_mappings", stat);
347 return (stat);
351 * Check the status for all the queued requests
353 for (i = 0, sim = sib->sib_maps; i < sib->sib_nmap; i++, sim++) {
354 if (sim->sim_stat != IDMAP_SUCCESS) {
355 if (sib->sib_flags == SMB_IDMAP_SID2ID) {
356 smb_tracef("[%d] %d (%d)", sim->sim_idtype,
357 sim->sim_rid, sim->sim_stat);
359 return (sim->sim_stat);
363 if (smb_idmap_batch_binsid(sib) != 0)
364 stat = IDMAP_ERR_OTHER;
366 return (stat);
370 * smb_idmap_batch_binsid
372 * Convert sidrids to binary sids
374 * Returns 0 if successful and non-zero upon failure.
376 static int
377 smb_idmap_batch_binsid(smb_idmap_batch_t *sib)
379 smb_sid_t *sid;
380 smb_idmap_t *sim;
381 int i;
383 if (sib->sib_flags & SMB_IDMAP_SID2ID)
384 /* This operation is not required */
385 return (0);
387 sim = sib->sib_maps;
388 for (i = 0; i < sib->sib_nmap; sim++, i++) {
389 if (sim->sim_domsid == NULL)
390 return (-1);
392 sid = smb_sid_fromstr(sim->sim_domsid);
393 if (sid == NULL)
394 return (-1);
396 sim->sim_sid = smb_sid_splice(sid, sim->sim_rid);
397 smb_sid_free(sid);
400 return (0);