2 ldb database module to enforce unique local objectSIDs
4 Copyright (C) Andrew Bartlett <abartlet@samba.org> 2017
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 Duplicate ObjectSIDs are possible on foreign security principals and
23 replication conflict records. However a duplicate objectSID within
24 the local domainSID is an error.
26 As the uniqueness requirement depends on the source domain it is not possible
27 to enforce this with a unique index.
29 This module sets the LDB_FLAG_FORCE_UNIQUE_INDEX for objectSIDs in the
34 #include "ldb_module.h"
35 #include "dsdb/samdb/samdb.h"
36 #include "libcli/security/dom_sid.h"
37 #include "dsdb/samdb/ldb_modules/util.h"
40 const struct dom_sid *domain_sid;
45 * Does the add request contain a local objectSID
47 static bool message_contains_local_objectSID(
48 struct ldb_module *module,
49 const struct ldb_message *msg)
51 struct dom_sid *objectSID = NULL;
53 struct private_data *data =
55 ldb_module_get_private(module),
58 TALLOC_CTX *frame = talloc_stackframe();
60 objectSID = samdb_result_dom_sid(frame, msg, "objectSID");
61 if (objectSID == NULL) {
67 * data->domain_sid can be NULL but dom_sid_in_domain handles this
68 * case correctly. See unique_object_sids_init for more details.
70 if (!dom_sid_in_domain(data->domain_sid, objectSID)) {
78 static int flag_objectSID(
79 struct ldb_module *module,
80 struct ldb_request *req,
81 const struct ldb_message *msg,
82 struct ldb_message **new_msg)
84 struct ldb_message_element *el = NULL;
86 *new_msg = ldb_msg_copy_shallow(req, msg);
88 return ldb_module_oom(module);
91 el = ldb_msg_find_element(*new_msg, "objectSID");
93 struct ldb_context *ldb = NULL;
94 ldb = ldb_module_get_ctx(module);
95 ldb_asprintf_errstring(
97 "Unable to locate objectSID in copied request\n");
98 return LDB_ERR_OPERATIONS_ERROR;
100 el->flags |= LDB_FLAG_INTERNAL_FORCE_UNIQUE_INDEX;
105 static int unique_object_sids_add(
106 struct ldb_module *module,
107 struct ldb_request *req)
109 const struct ldb_message *msg = req->op.add.message;
110 struct ldb_message *new_msg = NULL;
111 struct ldb_request *new_req = NULL;
112 struct ldb_context *ldb = NULL;
115 if (!message_contains_local_objectSID(module, msg)) {
117 * Request does not contain a local objectSID so chain the
120 return ldb_next_request(module, req);
124 * The add request contains an objectSID for the local domain
127 rc = flag_objectSID(module, req, msg, &new_msg);
128 if (rc != LDB_SUCCESS) {
132 ldb = ldb_module_get_ctx(module);
133 rc = ldb_build_add_req(
142 if (rc != LDB_SUCCESS) {
146 return ldb_next_request(module, new_req);
150 static int unique_object_sids_modify(
151 struct ldb_module *module,
152 struct ldb_request *req)
155 const struct ldb_message *msg = req->op.mod.message;
156 struct ldb_message *new_msg = NULL;
157 struct ldb_request *new_req = NULL;
158 struct ldb_context *ldb = NULL;
161 if (!message_contains_local_objectSID(module, msg)) {
163 * Request does not contain a local objectSID so chain the
166 return ldb_next_request(module, req);
169 ldb = ldb_module_get_ctx(module);
172 * If DSDB_CONTROL_REPLICATED_UPDATE_OID replicated is set we know
173 * that the modify request is well formed and objectSID only appears
176 * Enforcing this assumption simplifies the subsequent code.
179 if(!ldb_request_get_control(req, DSDB_CONTROL_REPLICATED_UPDATE_OID)) {
180 ldb_asprintf_errstring(
182 "Modify of %s rejected, "
183 "as it is modifying an objectSID\n",
184 ldb_dn_get_linearized(msg->dn));
185 return LDB_ERR_UNWILLING_TO_PERFORM;
189 rc = flag_objectSID(module, req, msg, &new_msg);
190 if (rc != LDB_SUCCESS) {
194 ldb = ldb_module_get_ctx(module);
195 rc = ldb_build_mod_req(
204 if (rc != LDB_SUCCESS) {
208 return ldb_next_request(module, new_req);
212 static int unique_object_sids_init(
213 struct ldb_module *module)
215 struct ldb_context *ldb = ldb_module_get_ctx(module);
216 struct private_data *data = NULL;
219 ret = ldb_next_init(module);
221 if (ret != LDB_SUCCESS) {
225 data = talloc_zero(module, struct private_data);
227 return ldb_module_oom(module);
230 data->domain_sid = samdb_domain_sid(ldb);
231 if (data->domain_sid == NULL) {
233 * Unable to determine the domainSID, this normally occurs
234 * when provisioning. As there is no easy way to detect
235 * that we are provisioning. We currently just log this as a
241 "Unable to determine the DomainSID, "
242 "can not enforce uniqueness constraint on local "
246 ldb_module_set_private(module, data);
251 static const struct ldb_module_ops ldb_unique_object_sids_module_ops = {
252 .name = "unique_object_sids",
253 .init_context = unique_object_sids_init,
254 .add = unique_object_sids_add,
255 .modify = unique_object_sids_modify,
258 int ldb_unique_object_sids_init(const char *version)
260 LDB_MODULE_CHECK_VERSION(version);
261 return ldb_register_module(&ldb_unique_object_sids_module_ops);