2 * Unix SMB/CIFS implementation.
6 * Copyright (c) 2011 Andreas Schneider <asn@samba.org>
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, see <http://www.gnu.org/licenses/>.
27 #include "lib/id_cache.h"
29 #include "../lib/tsocket/tsocket.h"
30 #include "lib/server_prefork.h"
31 #include "lib/server_prefork_util.h"
32 #include "librpc/rpc/dcerpc_ep.h"
34 #include "rpc_server/rpc_server.h"
35 #include "rpc_server/rpc_ep_register.h"
36 #include "rpc_server/rpc_sock_helper.h"
38 #include "librpc/gen_ndr/srv_lsa.h"
39 #include "librpc/gen_ndr/srv_samr.h"
40 #include "librpc/gen_ndr/srv_netlogon.h"
41 #include "rpc_server/lsasd.h"
44 #define DBGC_CLASS DBGC_RPC_SRV
46 #define DAEMON_NAME "lsasd"
47 #define LSASD_MAX_SOCKETS 64
49 static struct server_id parent_id;
50 static struct prefork_pool *lsasd_pool = NULL;
51 static int lsasd_child_id = 0;
53 static struct pf_daemon_config default_pf_lsasd_cfg = {
54 .prefork_status = PFH_INIT,
58 .max_allowed_clients = 100,
59 .child_min_life = 60 /* 1 minute minimum life time */
61 static struct pf_daemon_config pf_lsasd_cfg = { 0 };
63 static void lsasd_reopen_logs(int child_id)
65 char *lfile = lp_logfile(talloc_tos());
70 rc = asprintf(&extension, "%s.%d", DAEMON_NAME, child_id);
72 rc = asprintf(&extension, "%s", DAEMON_NAME);
79 if (lfile == NULL || lfile[0] == '\0') {
80 rc = asprintf(&lfile, "%s/log.%s",
81 get_dyn_LOGFILEBASE(), extension);
83 if (strstr(lfile, extension) == NULL) {
85 rc = asprintf(&lfile, "%s.%d",
86 lp_logfile(talloc_tos()),
89 rc = asprintf(&lfile, "%s.%s",
90 lp_logfile(talloc_tos()),
97 lp_set_logfile(lfile);
101 SAFE_FREE(extension);
106 static void lsasd_smb_conf_updated(struct messaging_context *msg,
109 struct server_id server_id,
112 struct tevent_context *ev_ctx;
114 DEBUG(10, ("Got message saying smb.conf was updated. Reloading.\n"));
115 ev_ctx = talloc_get_type_abort(private_data, struct tevent_context);
117 change_to_root_user();
118 lp_load_global(get_dyn_CONFIGFILE());
120 lsasd_reopen_logs(lsasd_child_id);
121 if (lsasd_child_id == 0) {
122 pfh_daemon_config(DAEMON_NAME,
124 &default_pf_lsasd_cfg);
125 pfh_manage_pool(ev_ctx, msg, &pf_lsasd_cfg, lsasd_pool);
129 static void lsasd_sig_term_handler(struct tevent_context *ev,
130 struct tevent_signal *se,
136 rpc_netlogon_shutdown();
138 rpc_lsarpc_shutdown();
140 DEBUG(0, ("termination signal\n"));
144 static void lsasd_setup_sig_term_handler(struct tevent_context *ev_ctx)
146 struct tevent_signal *se;
148 se = tevent_add_signal(ev_ctx,
151 lsasd_sig_term_handler,
154 DEBUG(0, ("failed to setup SIGTERM handler\n"));
159 static void lsasd_sig_hup_handler(struct tevent_context *ev,
160 struct tevent_signal *se,
167 change_to_root_user();
168 lp_load_global(get_dyn_CONFIGFILE());
170 lsasd_reopen_logs(lsasd_child_id);
171 pfh_daemon_config(DAEMON_NAME,
173 &default_pf_lsasd_cfg);
175 /* relay to all children */
176 prefork_send_signal_to_all(lsasd_pool, SIGHUP);
179 static void lsasd_setup_sig_hup_handler(struct tevent_context *ev_ctx)
181 struct tevent_signal *se;
183 se = tevent_add_signal(ev_ctx,
186 lsasd_sig_hup_handler,
189 DEBUG(0, ("failed to setup SIGHUP handler\n"));
194 /**********************************************************
196 **********************************************************/
198 static void lsasd_chld_sig_hup_handler(struct tevent_context *ev,
199 struct tevent_signal *se,
205 change_to_root_user();
206 lsasd_reopen_logs(lsasd_child_id);
209 static bool lsasd_setup_chld_hup_handler(struct tevent_context *ev_ctx)
211 struct tevent_signal *se;
213 se = tevent_add_signal(ev_ctx,
216 lsasd_chld_sig_hup_handler,
219 DEBUG(1, ("failed to setup SIGHUP handler"));
226 static void parent_ping(struct messaging_context *msg_ctx,
229 struct server_id server_id,
233 /* The fact we received this message is enough to let make the event
234 * loop if it was idle. lsasd_children_main will cycle through
235 * lsasd_next_client at least once. That function will take whatever
236 * action is necessary */
238 DEBUG(10, ("Got message that the parent changed status.\n"));
242 static bool lsasd_child_init(struct tevent_context *ev_ctx,
244 struct pf_worker_data *pf)
247 struct messaging_context *msg_ctx = global_messaging_context();
250 status = reinit_after_fork(msg_ctx, ev_ctx,
251 true, "lsasd-child");
252 if (!NT_STATUS_IS_OK(status)) {
253 DEBUG(0,("reinit_after_fork() failed\n"));
254 smb_panic("reinit_after_fork() failed");
256 initialize_password_db(true, ev_ctx);
258 lsasd_child_id = child_id;
259 lsasd_reopen_logs(child_id);
261 ok = lsasd_setup_chld_hup_handler(ev_ctx);
266 messaging_register(msg_ctx, ev_ctx,
267 MSG_SMB_CONF_UPDATED, lsasd_smb_conf_updated);
268 messaging_register(msg_ctx, ev_ctx,
269 MSG_PREFORK_PARENT_EVENT, parent_ping);
270 id_cache_register_msgs(msg_ctx);
272 status = rpc_lsarpc_init(NULL);
273 if (!NT_STATUS_IS_OK(status)) {
274 DEBUG(0, ("Failed to register lsarpc rpc interface! (%s)\n",
279 status = rpc_samr_init(NULL);
280 if (!NT_STATUS_IS_OK(status)) {
281 DEBUG(0, ("Failed to register samr rpc interface! (%s)\n",
286 status = rpc_netlogon_init(NULL);
287 if (!NT_STATUS_IS_OK(status)) {
288 DEBUG(0, ("Failed to register netlogon rpc interface! (%s)\n",
296 struct lsasd_children_data {
297 struct tevent_context *ev_ctx;
298 struct messaging_context *msg_ctx;
299 struct pf_worker_data *pf;
301 struct pf_listen_fd *listen_fds;
304 static void lsasd_next_client(void *pvt);
306 static int lsasd_children_main(struct tevent_context *ev_ctx,
307 struct messaging_context *msg_ctx,
308 struct pf_worker_data *pf,
311 struct pf_listen_fd *listen_fds,
314 struct lsasd_children_data *data;
318 ok = lsasd_child_init(ev_ctx, child_id, pf);
323 data = talloc(ev_ctx, struct lsasd_children_data);
328 data->ev_ctx = ev_ctx;
329 data->msg_ctx = msg_ctx;
330 data->listen_fd_size = listen_fd_size;
331 data->listen_fds = listen_fds;
333 /* loop until it is time to exit */
334 while (pf->status != PF_WORKER_EXITING) {
335 /* try to see if it is time to schedule the next client */
336 lsasd_next_client(data);
338 ret = tevent_loop_once(ev_ctx);
340 DEBUG(0, ("tevent_loop_once() exited with %d: %s\n",
341 ret, strerror(errno)));
342 pf->status = PF_WORKER_EXITING;
349 static void lsasd_client_terminated(struct pipes_struct *p, void *pvt)
351 struct lsasd_children_data *data;
353 data = talloc_get_type_abort(pvt, struct lsasd_children_data);
355 pfh_client_terminated(data->pf);
357 lsasd_next_client(pvt);
360 struct lsasd_new_client {
361 struct lsasd_children_data *data;
364 static void lsasd_handle_client(struct tevent_req *req);
366 static void lsasd_next_client(void *pvt)
368 struct tevent_req *req;
369 struct lsasd_children_data *data;
370 struct lsasd_new_client *next;
372 data = talloc_get_type_abort(pvt, struct lsasd_children_data);
374 if (!pfh_child_allowed_to_accept(data->pf)) {
375 /* nothing to do for now we are already listening
376 * or we are not allowed to listen further */
380 next = talloc_zero(data, struct lsasd_new_client);
382 DEBUG(1, ("Out of memory!?\n"));
387 req = prefork_listen_send(next,
390 data->listen_fd_size,
393 DEBUG(1, ("Failed to make listening request!?\n"));
397 tevent_req_set_callback(req, lsasd_handle_client, next);
400 static void lsasd_handle_client(struct tevent_req *req)
402 struct lsasd_children_data *data;
403 struct lsasd_new_client *client;
404 const DATA_BLOB ping = data_blob_null;
408 struct tsocket_address *srv_addr;
409 struct tsocket_address *cli_addr;
411 client = tevent_req_callback_data(req, struct lsasd_new_client);
414 tmp_ctx = talloc_stackframe();
415 if (tmp_ctx == NULL) {
416 DEBUG(1, ("Failed to allocate stackframe!\n"));
420 rc = prefork_listen_recv(req,
427 /* this will free the request too */
431 DEBUG(6, ("No client connection was available after all!\n"));
435 /* Warn parent that our status changed */
436 messaging_send(data->msg_ctx, parent_id,
437 MSG_PREFORK_CHILD_EVENT, &ping);
439 DEBUG(2, ("LSASD preforked child %d got client connection!\n",
440 (int)(data->pf->pid)));
442 if (tsocket_address_is_inet(srv_addr, "ip")) {
443 DEBUG(3, ("Got a tcpip client connection from %s on interface %s\n",
444 tsocket_address_string(cli_addr, tmp_ctx),
445 tsocket_address_string(srv_addr, tmp_ctx)));
447 dcerpc_ncacn_accept(data->ev_ctx,
454 lsasd_client_terminated,
456 } else if (tsocket_address_is_unix(srv_addr)) {
460 p = tsocket_address_unix_path(srv_addr, tmp_ctx);
462 talloc_free(tmp_ctx);
473 if (strstr(p, "/np/")) {
474 dcerpc_ncacn_accept(data->ev_ctx,
478 NULL, /* remote client address */
479 NULL, /* local server address */
481 lsasd_client_terminated,
485 dcerpc_ncacn_accept(data->ev_ctx,
492 lsasd_client_terminated,
496 DEBUG(0, ("ERROR: Unsupported socket!\n"));
500 talloc_free(tmp_ctx);
507 static void child_ping(struct messaging_context *msg_ctx,
510 struct server_id server_id,
513 struct tevent_context *ev_ctx;
515 ev_ctx = talloc_get_type_abort(private_data, struct tevent_context);
517 DEBUG(10, ("Got message that a child changed status.\n"));
518 pfh_manage_pool(ev_ctx, msg_ctx, &pf_lsasd_cfg, lsasd_pool);
521 static bool lsasd_schedule_check(struct tevent_context *ev_ctx,
522 struct messaging_context *msg_ctx,
523 struct timeval current_time);
525 static void lsasd_check_children(struct tevent_context *ev_ctx,
526 struct tevent_timer *te,
527 struct timeval current_time,
530 static void lsasd_sigchld_handler(struct tevent_context *ev_ctx,
531 struct prefork_pool *pfp,
534 struct messaging_context *msg_ctx;
536 msg_ctx = talloc_get_type_abort(pvt, struct messaging_context);
538 /* run pool management so we can fork/retire or increase
539 * the allowed connections per child based on load */
540 pfh_manage_pool(ev_ctx, msg_ctx, &pf_lsasd_cfg, lsasd_pool);
543 static bool lsasd_setup_children_monitor(struct tevent_context *ev_ctx,
544 struct messaging_context *msg_ctx)
548 /* add our oun sigchld callback */
549 prefork_set_sigchld_callback(lsasd_pool, lsasd_sigchld_handler, msg_ctx);
551 ok = lsasd_schedule_check(ev_ctx, msg_ctx, tevent_timeval_current());
556 static bool lsasd_schedule_check(struct tevent_context *ev_ctx,
557 struct messaging_context *msg_ctx,
558 struct timeval current_time)
560 struct tevent_timer *te;
561 struct timeval next_event;
563 /* check situation again in 10 seconds */
564 next_event = tevent_timeval_current_ofs(10, 0);
566 /* TODO: check when the socket becomes readable, so that children
567 * are checked only when there is some activity ? */
568 te = tevent_add_timer(ev_ctx, lsasd_pool, next_event,
569 lsasd_check_children, msg_ctx);
571 DEBUG(2, ("Failed to set up children monitoring!\n"));
578 static void lsasd_check_children(struct tevent_context *ev_ctx,
579 struct tevent_timer *te,
580 struct timeval current_time,
583 struct messaging_context *msg_ctx;
585 msg_ctx = talloc_get_type_abort(pvt, struct messaging_context);
587 pfh_manage_pool(ev_ctx, msg_ctx, &pf_lsasd_cfg, lsasd_pool);
589 lsasd_schedule_check(ev_ctx, msg_ctx, current_time);
596 static bool lsasd_create_sockets(struct tevent_context *ev_ctx,
597 struct messaging_context *msg_ctx,
598 struct pf_listen_fd *listen_fd,
601 struct dcerpc_binding_vector *v, *v_orig;
609 tmp_ctx = talloc_stackframe();
610 if (tmp_ctx == NULL) {
614 status = dcerpc_binding_vector_new(tmp_ctx, &v_orig);
615 if (!NT_STATUS_IS_OK(status)) {
619 /* Create only one tcpip listener for all services */
620 status = dcesrv_create_ncacn_ip_tcp_sockets(&ndr_table_lsarpc,
625 if (!NT_STATUS_IS_OK(status)) {
629 /* Start to listen on tcpip sockets */
630 for (i = 0; i < *listen_fd_size; i++) {
631 rc = listen(listen_fd[i].fd, pf_lsasd_cfg.max_allowed_clients);
633 DEBUG(0, ("Failed to listen on tcpip socket - %s\n",
640 status = dcesrv_create_ncacn_np_socket("lsarpc", &fd);
641 if (!NT_STATUS_IS_OK(status)) {
645 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
647 DEBUG(0, ("Failed to listen on lsarpc pipe - %s\n",
651 listen_fd[*listen_fd_size].fd = fd;
652 listen_fd[*listen_fd_size].fd_data = NULL;
656 status = dcesrv_create_ncacn_np_socket("lsass", &fd);
657 if (!NT_STATUS_IS_OK(status)) {
661 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
663 DEBUG(0, ("Failed to listen on lsass pipe - %s\n",
667 listen_fd[*listen_fd_size].fd = fd;
668 listen_fd[*listen_fd_size].fd_data = NULL;
672 status = dcesrv_create_ncalrpc_socket("lsarpc", &fd);
673 if (!NT_STATUS_IS_OK(status)) {
677 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
679 DEBUG(0, ("Failed to listen on lsarpc ncalrpc - %s\n",
683 listen_fd[*listen_fd_size].fd = fd;
684 listen_fd[*listen_fd_size].fd_data = NULL;
688 v = dcerpc_binding_vector_dup(tmp_ctx, v_orig);
693 status = dcerpc_binding_vector_replace_iface(&ndr_table_lsarpc, v);
694 if (!NT_STATUS_IS_OK(status)) {
698 status = dcerpc_binding_vector_add_np_default(&ndr_table_lsarpc, v);
699 if (!NT_STATUS_IS_OK(status)) {
703 status = dcerpc_binding_vector_add_unix(&ndr_table_lsarpc, v, "lsarpc");
704 if (!NT_STATUS_IS_OK(status)) {
708 status = rpc_ep_register(ev_ctx, msg_ctx, &ndr_table_lsarpc, v);
709 if (!NT_STATUS_IS_OK(status)) {
714 status = dcesrv_create_ncacn_np_socket("samr", &fd);
715 if (!NT_STATUS_IS_OK(status)) {
719 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
721 DEBUG(0, ("Failed to listen on samr pipe - %s\n",
725 listen_fd[*listen_fd_size].fd = fd;
726 listen_fd[*listen_fd_size].fd_data = NULL;
730 status = dcesrv_create_ncalrpc_socket("samr", &fd);
731 if (!NT_STATUS_IS_OK(status)) {
735 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
737 DEBUG(0, ("Failed to listen on samr ncalrpc - %s\n",
741 listen_fd[*listen_fd_size].fd = fd;
742 listen_fd[*listen_fd_size].fd_data = NULL;
746 v = dcerpc_binding_vector_dup(tmp_ctx, v_orig);
751 status = dcerpc_binding_vector_replace_iface(&ndr_table_samr, v);
752 if (!NT_STATUS_IS_OK(status)) {
756 status = dcerpc_binding_vector_add_np_default(&ndr_table_samr, v);
757 if (!NT_STATUS_IS_OK(status)) {
761 status = dcerpc_binding_vector_add_unix(&ndr_table_lsarpc, v, "samr");
762 if (!NT_STATUS_IS_OK(status)) {
766 status = rpc_ep_register(ev_ctx, msg_ctx, &ndr_table_samr, v);
767 if (!NT_STATUS_IS_OK(status)) {
772 status = dcesrv_create_ncacn_np_socket("netlogon", &fd);
773 if (!NT_STATUS_IS_OK(status)) {
777 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
779 DEBUG(0, ("Failed to listen on samr pipe - %s\n",
783 listen_fd[*listen_fd_size].fd = fd;
784 listen_fd[*listen_fd_size].fd_data = NULL;
788 status = dcesrv_create_ncalrpc_socket("netlogon", &fd);
789 if (!NT_STATUS_IS_OK(status)) {
793 rc = listen(fd, pf_lsasd_cfg.max_allowed_clients);
795 DEBUG(0, ("Failed to listen on netlogon ncalrpc - %s\n",
799 listen_fd[*listen_fd_size].fd = fd;
800 listen_fd[*listen_fd_size].fd_data = NULL;
804 v = dcerpc_binding_vector_dup(tmp_ctx, v_orig);
809 status = dcerpc_binding_vector_replace_iface(&ndr_table_netlogon, v);
810 if (!NT_STATUS_IS_OK(status)) {
814 status = dcerpc_binding_vector_add_np_default(&ndr_table_netlogon, v);
815 if (!NT_STATUS_IS_OK(status)) {
819 status = dcerpc_binding_vector_add_unix(&ndr_table_lsarpc, v, "netlogon");
820 if (!NT_STATUS_IS_OK(status)) {
824 status = rpc_ep_register(ev_ctx, msg_ctx, &ndr_table_netlogon, v);
825 if (!NT_STATUS_IS_OK(status)) {
834 talloc_free(tmp_ctx);
838 void start_lsasd(struct tevent_context *ev_ctx,
839 struct messaging_context *msg_ctx)
842 struct pf_listen_fd listen_fd[LSASD_MAX_SOCKETS];
843 int listen_fd_size = 0;
848 DEBUG(1, ("Forking LSA Service Daemon\n"));
851 * Block signals before forking child as it will have to
852 * set its own handlers. Child will re-enable SIGHUP as
853 * soon as the handlers are set up.
855 BlockSignals(true, SIGTERM);
856 BlockSignals(true, SIGHUP);
860 DEBUG(0, ("Failed to fork LSASD [%s], aborting ...\n",
865 /* parent or error */
868 /* Re-enable SIGHUP before returnig */
869 BlockSignals(false, SIGTERM);
870 BlockSignals(false, SIGHUP);
875 status = smbd_reinit_after_fork(msg_ctx, ev_ctx, true, "lsasd-master");
876 if (!NT_STATUS_IS_OK(status)) {
877 DEBUG(0,("reinit_after_fork() failed\n"));
878 smb_panic("reinit_after_fork() failed");
880 initialize_password_db(true, ev_ctx);
882 /* save the parent process id so the children can use it later */
883 parent_id = messaging_server_id(msg_ctx);
885 lsasd_reopen_logs(0);
886 pfh_daemon_config(DAEMON_NAME,
888 &default_pf_lsasd_cfg);
890 lsasd_setup_sig_term_handler(ev_ctx);
891 lsasd_setup_sig_hup_handler(ev_ctx);
893 BlockSignals(false, SIGTERM);
894 BlockSignals(false, SIGHUP);
896 ok = lsasd_create_sockets(ev_ctx, msg_ctx, listen_fd, &listen_fd_size);
901 /* start children before any more initialization is done */
902 ok = prefork_create_pool(ev_ctx, /* mem_ctx */
907 pf_lsasd_cfg.min_children,
908 pf_lsasd_cfg.max_children,
909 &lsasd_children_main,
916 messaging_register(msg_ctx,
918 MSG_SMB_CONF_UPDATED,
919 lsasd_smb_conf_updated);
920 messaging_register(msg_ctx, ev_ctx,
921 MSG_PREFORK_CHILD_EVENT, child_ping);
923 status = rpc_lsarpc_init(NULL);
924 if (!NT_STATUS_IS_OK(status)) {
925 DEBUG(0, ("Failed to register lsarpc rpc interface in lsasd! (%s)\n",
930 status = rpc_samr_init(NULL);
931 if (!NT_STATUS_IS_OK(status)) {
932 DEBUG(0, ("Failed to register samr rpc interface in lsasd! (%s)\n",
937 status = rpc_netlogon_init(NULL);
938 if (!NT_STATUS_IS_OK(status)) {
939 DEBUG(0, ("Failed to register netlogon rpc interface in lsasd! (%s)\n",
944 ok = lsasd_setup_children_monitor(ev_ctx, msg_ctx);
946 DEBUG(0, ("Failed to setup children monitoring!\n"));
950 DEBUG(1, ("LSASD Daemon Started (%u)\n", (unsigned int)getpid()));
953 rc = tevent_loop_wait(ev_ctx);
955 /* should not be reached */
956 DEBUG(0,("lsasd: tevent_loop_wait() exited with %d - %s\n",
957 rc, (rc == 0) ? "out of events" : strerror(errno)));