2 Unix SMB/CIFS implementation.
4 Winbind daemon for ntdom nss module
6 Copyright (C) by Tim Potter 2000-2002
7 Copyright (C) Andrew Tridgell 2002
8 Copyright (C) Jelmer Vernooij 2003
9 Copyright (C) Volker Lendecke 2004
11 This program is free software; you can redistribute it and/or modify
12 it under the terms of the GNU General Public License as published by
13 the Free Software Foundation; either version 3 of the License, or
14 (at your option) any later version.
16 This program is distributed in the hope that it will be useful,
17 but WITHOUT ANY WARRANTY; without even the implied warranty of
18 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 GNU General Public License for more details.
21 You should have received a copy of the GNU General Public License
22 along with this program. If not, see <http://www.gnu.org/licenses/>.
26 #include "popt_common.h"
28 #include "nsswitch/winbind_client.h"
29 #include "../../nsswitch/libwbclient/wbc_async.h"
30 #include "librpc/gen_ndr/messaging.h"
31 #include "../librpc/gen_ndr/srv_lsa.h"
32 #include "../librpc/gen_ndr/srv_samr.h"
36 #define DBGC_CLASS DBGC_WINBIND
38 static bool opt_nocache = False;
39 static bool interactive = False;
41 extern bool override_logfile;
43 /**************************************************************************** **
45 **************************************************************************** */
47 static void fault_quit(void)
52 bool winbindd_use_idmap_cache(void)
57 bool winbindd_use_cache(void)
62 int main(int argc, char **argv, char **envp)
64 static bool is_daemon = False;
65 static bool Fork = True;
66 static bool log_stdout = False;
67 static bool no_process_group = False;
74 struct poptOption long_options[] = {
76 { "stdout", 'S', POPT_ARG_NONE, NULL, OPT_LOG_STDOUT, "Log to stdout" },
77 { "foreground", 'F', POPT_ARG_NONE, NULL, OPT_FORK, "Daemon in foreground mode" },
78 { "no-process-group", 0, POPT_ARG_NONE, NULL, OPT_NO_PROCESS_GROUP, "Don't create a new process group" },
79 { "daemon", 'D', POPT_ARG_NONE, NULL, OPT_DAEMON, "Become a daemon (default)" },
80 { "interactive", 'i', POPT_ARG_NONE, NULL, 'i', "Interactive mode" },
81 { "no-caching", 'n', POPT_ARG_NONE, NULL, 'n', "Disable caching" },
87 TALLOC_CTX *frame = talloc_stackframe();
90 /* glibc (?) likes to print "User defined signal 1" and exit if a
91 SIGUSR[12] is received before a handler is installed */
93 CatchSignal(SIGUSR1, SIG_IGN);
94 CatchSignal(SIGUSR2, SIG_IGN);
96 fault_setup((void (*)(void *))fault_quit );
97 dump_core_setup("winbindd");
101 /* Initialise for running in non-root mode */
105 set_remote_machine_name("winbindd", False);
107 /* Set environment variable so we don't recursively call ourselves.
108 This may also be useful interactively. */
110 if ( !winbind_off() ) {
111 DEBUG(0,("Failed to disable recusive winbindd calls. Exiting.\n"));
115 /* Initialise samba/rpc client stuff */
117 pc = poptGetContext("winbindd", argc, (const char **)argv, long_options, 0);
119 while ((opt = poptGetNextOpt(pc)) != -1) {
121 /* Don't become a daemon */
133 case OPT_NO_PROCESS_GROUP:
134 no_process_group = true;
143 d_fprintf(stderr, "\nInvalid option %s: %s\n\n",
144 poptBadOption(pc, 0), poptStrerror(opt));
145 poptPrintUsage(pc, stderr, 0);
150 if (is_daemon && interactive) {
151 d_fprintf(stderr,"\nERROR: "
152 "Option -i|--interactive is not allowed together with -D|--daemon\n\n");
153 poptPrintUsage(pc, stderr, 0);
157 if (log_stdout && Fork) {
158 d_fprintf(stderr, "\nERROR: "
159 "Can't log to stdout (-S) unless daemon is in foreground +(-F) or interactive (-i)\n\n");
160 poptPrintUsage(pc, stderr, 0);
166 if (!override_logfile) {
168 if (asprintf(&lfile,"%s/log.winbindd",
169 get_dyn_LOGFILEBASE()) > 0) {
170 lp_set_logfile(lfile);
174 setup_logging("winbindd", log_stdout);
177 DEBUG(0,("winbindd version %s started.\n", samba_version_string()));
178 DEBUGADD(0,("%s\n", COPYRIGHT_STARTUP_MESSAGE));
180 if (!lp_load_initial_only(get_dyn_CONFIGFILE())) {
181 DEBUG(0, ("error opening config file\n"));
185 /* Initialise messaging system */
187 if (winbind_messaging_context() == NULL) {
191 if (!winbindd_reload_services_file(NULL)) {
192 DEBUG(0, ("error opening config file\n"));
196 if (!directory_exist(lp_lockdir())) {
197 mkdir(lp_lockdir(), 0755);
207 if (!secrets_init()) {
209 DEBUG(0,("Could not initialize domain trust account secrets. Giving up\n"));
213 /* Unblock all signals we are interested in as they may have been
214 blocked by the parent process. */
216 BlockSignals(False, SIGINT);
217 BlockSignals(False, SIGQUIT);
218 BlockSignals(False, SIGTERM);
219 BlockSignals(False, SIGUSR1);
220 BlockSignals(False, SIGUSR2);
221 BlockSignals(False, SIGHUP);
222 BlockSignals(False, SIGCHLD);
225 become_daemon(Fork, no_process_group, log_stdout);
227 pidfile_create("winbindd");
231 * If we're interactive we want to set our own process group for
234 if (interactive && !no_process_group)
235 setpgid( (pid_t)0, (pid_t)0);
240 /* Don't use winbindd_reinit_after_fork here as
241 * we're just starting up and haven't created any
242 * winbindd-specific resources we must free yet. JRA.
245 status = reinit_after_fork(winbind_messaging_context(),
246 winbind_event_context(),
247 procid_self(), false);
248 if (!NT_STATUS_IS_OK(status)) {
249 DEBUG(0,("reinit_after_fork() failed\n"));
253 winbindd_register_handlers();
255 rpc_lsarpc_init(NULL);
258 if (!init_system_info()) {
259 DEBUG(0,("ERROR: failed to setup system user info.\n"));
263 /* setup listen sockets */
265 if (!winbindd_setup_listeners()) {
266 DEBUG(0,("winbindd_setup_listeners() failed\n"));
271 /* Loop waiting for requests */
273 frame = talloc_stackframe();
275 if (tevent_loop_once(winbind_event_context()) == -1) {
276 DEBUG(1, ("tevent_loop_once() failed: %s\n",