Blame SOURCES/libnfsidmap-0.26-rc3.patch

da1e07
diff --git a/.gitignore b/.gitignore
da1e07
index 6244609..d24d727 100644
da1e07
--- a/.gitignore
da1e07
+++ b/.gitignore
da1e07
@@ -17,18 +17,13 @@ libnfsidmap.pc
da1e07
 libtool
da1e07
 .libs/
da1e07
 libnfsidmap.la
da1e07
-libnfsidmap_la-cfg.lo
da1e07
-libnfsidmap_la-libnfsidmap.lo
da1e07
-libnfsidmap_la-strlcpy.lo
da1e07
-nss.lo
da1e07
 nsswitch.la
da1e07
 static.la
da1e07
-static.lo
da1e07
 umich_ldap.la
da1e07
-umich_ldap.lo
da1e07
 configure.in~
da1e07
 m4/
da1e07
 *.o
da1e07
+*.lo
da1e07
 cscope.*
da1e07
 config.h
da1e07
 config.h.in
da1e07
diff --git a/autogen.sh b/autogen.sh
da1e07
index ee89987..c17f6be 100755
da1e07
--- a/autogen.sh
da1e07
+++ b/autogen.sh
da1e07
@@ -37,5 +37,6 @@ fi
da1e07
 
da1e07
 aclocal
da1e07
 libtoolize --force --copy
da1e07
-autoupdate
da1e07
+autoheader
da1e07
+automake --add-missing --copy --gnu
da1e07
 autoreconf -vi -Wall
da1e07
diff --git a/idmapd.conf.5 b/idmapd.conf.5
da1e07
index 9c7f1ae..de1bfa9 100644
da1e07
--- a/idmapd.conf.5
da1e07
+++ b/idmapd.conf.5
da1e07
@@ -31,7 +31,7 @@
da1e07
 .\"
da1e07
 .TH idmapd.conf 5 "19 Nov 2008"
da1e07
 .SH NAME
da1e07
-idmapd.conf
da1e07
+idmapd.conf \- configuration file for libnfsidmap
da1e07
 .SH SYNOPSIS
da1e07
 Configuration file for libnfsidmap.  Used by idmapd and svcgssd to map NFSv4 name to and from ids.
da1e07
 .SH DESCRIPTION
da1e07
@@ -234,7 +234,6 @@ Number of seconds before timing out an LDAP request
da1e07
 .\" -------------------------------------------------------------------
da1e07
 .\"
da1e07
 .SH EXAMPLES
da1e07
-."
da1e07
 An example
da1e07
 .I /etc/idmapd.conf
da1e07
 file:
da1e07
@@ -266,7 +265,7 @@ johndoe@OTHER.DOMAIN.ORG = johnny
da1e07
 LDAP_server = ldap.domain.org
da1e07
 LDAP_base = dc=org,dc=domain
da1e07
 
da1e07
-.fo
da1e07
+.fi
da1e07
 .\"
da1e07
 .\" -------------------------------------------------------------------
da1e07
 .\" Additional sections
da1e07
@@ -275,11 +274,11 @@ LDAP_base = dc=org,dc=domain
da1e07
 .SH SEE ALSO
da1e07
 .BR idmapd (8)
da1e07
 .BR svcgssd (8)
da1e07
-.".SH COMPATIBILITY
da1e07
-.".SH STANDARDS
da1e07
-.".SH ACKNOWLEDGEMENTS
da1e07
-.".SH AUTHORS
da1e07
-.".SH HISTORY
da1e07
+.\".SH COMPATIBILITY
da1e07
+.\".SH STANDARDS
da1e07
+.\".SH ACKNOWLEDGEMENTS
da1e07
+.\".SH AUTHORS
da1e07
+.\".SH HISTORY
da1e07
 .SH BUGS
da1e07
 Report bugs to <nfsv4@linux-nfs.org>
da1e07
-.".SH CAVEATS
da1e07
+.\".SH CAVEATS
da1e07
diff --git a/libnfsidmap.c b/libnfsidmap.c
da1e07
index 57bb6c3..641d766 100644
da1e07
--- a/libnfsidmap.c
da1e07
+++ b/libnfsidmap.c
da1e07
@@ -285,8 +285,9 @@ int nfs4_init_name_mapping(char *conffile)
da1e07
 			}
da1e07
 			buf = malloc(siz);
da1e07
 			if (buf) {
da1e07
+				*buf = 0;
da1e07
 				TAILQ_FOREACH(r, &local_realms->fields, link) {
da1e07
-					sprintf(buf, "'%s' ", r->field);
da1e07
+					sprintf(buf+strlen(buf), "'%s' ", r->field);
da1e07
 				}
da1e07
 				IDMAP_LOG(1, ("libnfsidmap: Realms list: %s", buf));
da1e07
 				free(buf);
da1e07
diff --git a/static.c b/static.c
da1e07
index fffd458..8be87e8 100644
da1e07
--- a/static.c
da1e07
+++ b/static.c
da1e07
@@ -40,6 +40,7 @@
da1e07
 #include <grp.h>
da1e07
 #include <errno.h>
da1e07
 
da1e07
+#include "queue.h"
da1e07
 #include "cfg.h"
da1e07
 #include "nfsidmap.h"
da1e07
 #include "nfsidmap_internal.h"
da1e07
@@ -57,6 +58,40 @@ struct pwbuf {
da1e07
 	char buf[1];
da1e07
 };
da1e07
 
da1e07
+struct grbuf {
da1e07
+	struct group grbuf;
da1e07
+	char buf[1];
da1e07
+};
da1e07
+
da1e07
+struct uid_mapping {
da1e07
+	LIST_ENTRY (uid_mapping) link;
da1e07
+	uid_t uid;
da1e07
+	char * principal;
da1e07
+	char * localname;
da1e07
+};
da1e07
+
da1e07
+struct gid_mapping {
da1e07
+	LIST_ENTRY (gid_mapping) link;
da1e07
+	gid_t gid;
da1e07
+	char * principal;
da1e07
+	char * localgroup;
da1e07
+};
da1e07
+
da1e07
+static __inline__ u_int8_t uid_hash (uid_t uid)
da1e07
+{
da1e07
+	return uid % 256;
da1e07
+}
da1e07
+
da1e07
+static __inline__ u_int8_t gid_hash (gid_t gid)
da1e07
+{
da1e07
+	return gid % 256;
da1e07
+}
da1e07
+
da1e07
+//Hash tables of uid and guids to principals mappings.
da1e07
+//We reuse some queue/hash functions from cfg.c.
da1e07
+LIST_HEAD (uid_mappings, uid_mapping) uid_mappings[256];
da1e07
+LIST_HEAD (gid_mappings, gid_mapping) gid_mappings[256];
da1e07
+
da1e07
 static struct passwd *static_getpwnam(const char *name, const char *domain,
da1e07
 				      int *err_p)
da1e07
 {
da1e07
@@ -75,12 +110,9 @@ static struct passwd *static_getpwnam(const char *name, const char *domain,
da1e07
 	localname = conf_get_str("Static", (char *)name);
da1e07
 	if (!localname) {
da1e07
 		err = ENOENT;
da1e07
-		goto err;
da1e07
+		goto err_free_buf;
da1e07
 	}
da1e07
 
da1e07
-	IDMAP_LOG(4, ("static_getpwnam: name '%s' mapped to '%s'\n",
da1e07
-		  name, localname));
da1e07
-
da1e07
 again:
da1e07
 	err = getpwnam_r(localname, &buf->pwbuf, buf->buf, buflen, &pw;;
da1e07
 
da1e07
@@ -91,12 +123,15 @@ again:
da1e07
 		if (err == 0)
da1e07
 			err = ENOENT;
da1e07
 
da1e07
-		IDMAP_LOG(0, ("static_getpwnam: name '%s' not found\n",
da1e07
-			  localname));
da1e07
+		IDMAP_LOG(0, ("static_getpwnam: localname '%s' for '%s' not found\n",
da1e07
+		  localname, name));
da1e07
 
da1e07
 		goto err_free_buf;
da1e07
 	}
da1e07
 
da1e07
+	IDMAP_LOG(4, ("static_getpwnam: name '%s' mapped to '%s'\n",
da1e07
+		  name, localname));
da1e07
+
da1e07
 	*err_p = 0;
da1e07
 	return pw;
da1e07
 
da1e07
@@ -107,6 +142,56 @@ err:
da1e07
 	return NULL;
da1e07
 }
da1e07
 
da1e07
+static struct group *static_getgrnam(const char *name, const char *domain,
da1e07
+				      int *err_p)
da1e07
+{
da1e07
+	struct group *gr;
da1e07
+	struct grbuf *buf;
da1e07
+	size_t buflen = sysconf(_SC_GETGR_R_SIZE_MAX);
da1e07
+	char *localgroup;
da1e07
+	int err;
da1e07
+
da1e07
+	buf = malloc(sizeof(*buf) + buflen);
da1e07
+	if (!buf) {
da1e07
+		err = ENOMEM;
da1e07
+		goto err;
da1e07
+	}
da1e07
+
da1e07
+	localgroup = conf_get_str("Static", (char *)name);
da1e07
+	if (!localgroup) {
da1e07
+		err = ENOENT;
da1e07
+		goto err_free_buf;
da1e07
+	}
da1e07
+
da1e07
+again:
da1e07
+	err = getgrnam_r(localgroup, &buf->grbuf, buf->buf, buflen, &gr);
da1e07
+
da1e07
+	if (err == EINTR)
da1e07
+		goto again;
da1e07
+
da1e07
+	if (!gr) {
da1e07
+		if (err == 0)
da1e07
+			err = ENOENT;
da1e07
+
da1e07
+		IDMAP_LOG(0, ("static_getgrnam: local group '%s' for '%s' not found\n",
da1e07
+			  localgroup, name));
da1e07
+
da1e07
+		goto err_free_buf;
da1e07
+	}
da1e07
+
da1e07
+	IDMAP_LOG(4, ("static_getgrnam: group '%s' mapped to '%s'\n",
da1e07
+		  name, localgroup));
da1e07
+
da1e07
+	*err_p = 0;
da1e07
+	return gr;
da1e07
+
da1e07
+err_free_buf:
da1e07
+	free(buf);
da1e07
+err:
da1e07
+	*err_p = err;
da1e07
+	return NULL;
da1e07
+}
da1e07
+
da1e07
 static int static_gss_princ_to_ids(char *secname, char *princ,
da1e07
 				   uid_t *uid, uid_t *gid,
da1e07
 				   extra_mapping_params **ex)
da1e07
@@ -151,14 +236,173 @@ static int static_gss_princ_to_grouplist(char *secname, char *princ,
da1e07
 	return -err;
da1e07
 }
da1e07
 
da1e07
+static int static_name_to_uid(char *name, uid_t *uid)
da1e07
+{
da1e07
+	struct passwd *pw;
da1e07
+	int err;
da1e07
+
da1e07
+	pw = static_getpwnam(name, NULL, &err;;
da1e07
+
da1e07
+	if (pw) {
da1e07
+		*uid = pw->pw_uid;
da1e07
+		free(pw);
da1e07
+	}
da1e07
+
da1e07
+	return -err;
da1e07
+}
da1e07
+
da1e07
+static int static_name_to_gid(char *name, gid_t *gid)
da1e07
+{
da1e07
+	struct group *gr;
da1e07
+	int err;
da1e07
+
da1e07
+	gr = static_getgrnam(name, NULL, &err;;
da1e07
+
da1e07
+	if (gr) {
da1e07
+		*gid = gr->gr_gid;
da1e07
+		free(gr);
da1e07
+	}
da1e07
+
da1e07
+	return -err;
da1e07
+}
da1e07
+
da1e07
+static int static_uid_to_name(uid_t uid, char *domain, char *name, size_t len)
da1e07
+{
da1e07
+	struct passwd *pw;
da1e07
+	struct uid_mapping * um;
da1e07
+
da1e07
+	for (um = LIST_FIRST (&uid_mappings[uid_hash (uid)]); um;
da1e07
+		um = LIST_NEXT (um, link)) {
da1e07
+		if (um->uid == uid) {
da1e07
+			strcpy(name, um->principal);
da1e07
+			return 0;
da1e07
+		}
da1e07
+	}
da1e07
+
da1e07
+	return -ENOENT;
da1e07
+}
da1e07
+
da1e07
+static int static_gid_to_name(gid_t gid, char *domain, char *name, size_t len)
da1e07
+{
da1e07
+	struct group *gr;
da1e07
+	struct gid_mapping * gm;
da1e07
+
da1e07
+	for (gm = LIST_FIRST (&gid_mappings[gid_hash (gid)]); gm;
da1e07
+		gm = LIST_NEXT (gm, link)) {
da1e07
+		if (gm->gid == gid) {
da1e07
+			strcpy(name, gm->principal);
da1e07
+			return 0;
da1e07
+		}
da1e07
+	}
da1e07
+
da1e07
+	return -ENOENT;
da1e07
+}
da1e07
+
da1e07
+/*
da1e07
+ * We buffer all UID's for which static mappings is defined in advance, so the
da1e07
+ * uid_to_name functions will be fast enough.
da1e07
+ */
da1e07
+
da1e07
+static int static_init() {	
da1e07
+	int err;
da1e07
+	uid_t uid;
da1e07
+	struct conf_list * princ_list = NULL;
da1e07
+	struct conf_list_node * cln, *next;
da1e07
+	struct uid_mapping * unode;
da1e07
+	struct gid_mapping * gnode;
da1e07
+	struct passwd * pw = NULL;
da1e07
+	struct group * gr = NULL;
da1e07
+	unsigned int i;
da1e07
+
da1e07
+	//init hash_table first
da1e07
+	for (i = 0; i < sizeof uid_mappings / sizeof uid_mappings[0]; i++)
da1e07
+		LIST_INIT (&uid_mappings[i]);
da1e07
+
da1e07
+	//get all principals for which we have mappings
da1e07
+	princ_list = conf_get_tag_list("Static");
da1e07
+
da1e07
+	if (!princ_list) {
da1e07
+		return -ENOENT;
da1e07
+	}
da1e07
+
da1e07
+	/* As we can not distinguish between mappings for users and groups, we try to
da1e07
+	 * resolve all mappings for both cases.
da1e07
+	 */
da1e07
+
da1e07
+	//resolve uid of localname account for all such principals and cache it
da1e07
+	for (cln = TAILQ_FIRST (&princ_list->fields); cln; cln = next) 
da1e07
+	{ 
da1e07
+		next = TAILQ_NEXT (cln, link); 
da1e07
+
da1e07
+		pw = static_getpwnam(cln->field, NULL, &err;;
da1e07
+		if (!pw) {
da1e07
+			continue;
da1e07
+		}
da1e07
+		
da1e07
+		unode = calloc (1, sizeof *unode);
da1e07
+		if (!unode)
da1e07
+		{
da1e07
+			warnx("static_init: calloc (1, %lu) failed",
da1e07
+				(unsigned long)sizeof *unode);
da1e07
+			free(pw);
da1e07
+			return -ENOMEM;
da1e07
+		}
da1e07
+		unode->uid = pw->pw_uid;
da1e07
+		unode->principal = strdup(cln->field);
da1e07
+
da1e07
+		unode->localname = conf_get_str("Static", cln->field);
da1e07
+		if (!unode->localname) {
da1e07
+			free(pw);
da1e07
+			return -ENOENT;
da1e07
+		}
da1e07
+
da1e07
+		free(pw);
da1e07
+
da1e07
+		LIST_INSERT_HEAD (&uid_mappings[uid_hash(unode->uid)], unode, link);
da1e07
+	}
da1e07
+
da1e07
+	//resolve gid of localgroup accounts and cache it
da1e07
+	for (cln = TAILQ_FIRST (&princ_list->fields); cln; cln = next) 
da1e07
+	{ 
da1e07
+		next = TAILQ_NEXT (cln, link); 
da1e07
+
da1e07
+		gr = static_getgrnam(cln->field, NULL, &err;;
da1e07
+		if (!pw) {
da1e07
+			continue;
da1e07
+		}
da1e07
+		
da1e07
+		gnode = calloc (1, sizeof *gnode);
da1e07
+		if (!gnode)
da1e07
+		{
da1e07
+			warnx("static_init: calloc (1, %lu) failed",
da1e07
+				(unsigned long)sizeof *gnode);
da1e07
+			free(pw);
da1e07
+			return -ENOMEM;
da1e07
+		}
da1e07
+		gnode->gid = pw->pw_uid;
da1e07
+		gnode->principal = strdup(cln->field);
da1e07
+
da1e07
+		gnode->localgroup = conf_get_str("Static", cln->field);
da1e07
+		if (!gnode->localgroup) {
da1e07
+			free(pw);
da1e07
+			return -ENOENT;
da1e07
+		}
da1e07
+
da1e07
+		free(pw);
da1e07
+
da1e07
+		LIST_INSERT_HEAD (&gid_mappings[gid_hash(gnode->gid)], gnode, link);
da1e07
+	}
da1e07
+	return 0;
da1e07
+}
da1e07
+
da1e07
 
da1e07
 struct trans_func static_trans = {
da1e07
 	.name			= "static",
da1e07
-	.init			= NULL,
da1e07
-	.name_to_uid		= NULL,
da1e07
-	.name_to_gid		= NULL,
da1e07
-	.uid_to_name		= NULL,
da1e07
-	.gid_to_name		= NULL,
da1e07
+	.init			= static_init,
da1e07
+	.name_to_uid		= static_name_to_uid,
da1e07
+	.name_to_gid		= static_name_to_gid,
da1e07
+	.uid_to_name		= static_uid_to_name,
da1e07
+	.gid_to_name		= static_gid_to_name,
da1e07
 	.princ_to_ids		= static_gss_princ_to_ids,
da1e07
 	.gss_princ_to_grouplist	= static_gss_princ_to_grouplist,
da1e07
 };
da1e07
diff --git a/umich_ldap.c b/umich_ldap.c
da1e07
index f482b0a..b527c5d 100644
da1e07
--- a/umich_ldap.c
da1e07
+++ b/umich_ldap.c
da1e07
@@ -32,8 +32,6 @@
da1e07
  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
da1e07
  */
da1e07
 
da1e07
-#ifdef ENABLE_LDAP
da1e07
-
da1e07
 #include <sys/types.h>
da1e07
 #include <sys/socket.h>
da1e07
 #include <netdb.h>
da1e07
@@ -1302,4 +1300,3 @@ struct trans_func *libnfsidmap_plugin_init()
da1e07
 {
da1e07
 	return (&umichldap_trans);
da1e07
 }
da1e07
-#endif