From patchwork Fri Dec 14 22:38:10 2012 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Chuck Lever X-Patchwork-Id: 206580 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from userp1040.oracle.com (userp1040.oracle.com [156.151.31.81]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "userp1040.oracle.com", Issuer "VeriSign Class 3 International Server CA - G3" (not verified)) by ozlabs.org (Postfix) with ESMTPS id 551712C008F for ; Sat, 15 Dec 2012 09:38:22 +1100 (EST) Received: from acsinet21.oracle.com (acsinet21.oracle.com [141.146.126.237]) by userp1040.oracle.com (Sentrion-MTA-4.2.2/Sentrion-MTA-4.2.2) with ESMTP id qBEMcIh6016774 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Fri, 14 Dec 2012 22:38:19 GMT Received: from oss.oracle.com (oss-external.oracle.com [137.254.96.51]) by acsinet21.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id qBEMcHQR011166 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 14 Dec 2012 22:38:18 GMT Received: from localhost ([127.0.0.1] helo=oss.oracle.com) by oss.oracle.com with esmtp (Exim 4.63) (envelope-from ) id 1TjdtZ-0005vF-SP; Fri, 14 Dec 2012 14:38:17 -0800 Received: from acsinet21.oracle.com ([141.146.126.237]) by oss.oracle.com with esmtp (Exim 4.63) (envelope-from ) id 1TjdtV-0005uv-8b for fedfs-utils-devel@oss.oracle.com; Fri, 14 Dec 2012 14:38:13 -0800 Received: from aserp1020.oracle.com (aserp1020.oracle.com [141.146.126.67]) by acsinet21.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id qBEMcC3C011091 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Fri, 14 Dec 2012 22:38:13 GMT Received: from mail-ie0-f171.google.com (mail-ie0-f171.google.com [209.85.223.171]) by aserp1020.oracle.com (Sentrion-MTA-4.2.2/Sentrion-MTA-4.2.2) with ESMTP id qBEMcC61006461 (version=TLSv1/SSLv3 cipher=RC4-SHA bits=128 verify=OK) for ; Fri, 14 Dec 2012 22:38:12 GMT Received: by mail-ie0-f171.google.com with SMTP id 17so6804722iea.2 for ; Fri, 14 Dec 2012 14:38:11 -0800 (PST) Received: by 10.50.196.133 with SMTP id im5mr3051465igc.61.1355524691870; Fri, 14 Dec 2012 14:38:11 -0800 (PST) Received: from seurat.1015granger.net ([99.26.161.222]) by mx.google.com with ESMTPS id 10sm7768351ign.5.2012.12.14.14.38.11 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 14 Dec 2012 14:38:11 -0800 (PST) From: Chuck Lever To: fedfs-utils-devel@oss.oracle.com Date: Fri, 14 Dec 2012 17:38:10 -0500 Message-ID: <20121214223810.22243.20787.stgit@seurat.1015granger.net> In-Reply-To: <20121214221556.22243.9462.stgit@seurat.1015granger.net> References: <20121214221556.22243.9462.stgit@seurat.1015granger.net> User-Agent: StGIT/0.14.3 MIME-Version: 1.0 X-Flow-Control-Info: class=Default reputation=ipRepBelow100 ip=209.85.223.171 ct-class=R5 ct-vol1=-97 ct-vol2=9 ct-vol3=8 ct-risk=50 ct-spam1=82 ct-spam2=6 ct-bulk=5 rcpts=1 size=5229 X-MM-CT-Classification: not spam X-MM-CT-RefID: str=0001.0A090206.50CBAA54.011D,ss=1,re=0.000,fgs=0 Subject: [fedfs-utils] [PATCH 06/11] nsdbc: Follow LDAP referrals in some NSDB administrative tools X-BeenThere: fedfs-utils-devel@oss.oracle.com X-Mailman-Version: 2.1.9 Precedence: list Reply-To: fedfs-utils Developers List-Id: fedfs-utils Developers List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: fedfs-utils-devel-bounces@oss.oracle.com Errors-To: fedfs-utils-devel-bounces@oss.oracle.com X-Source-IP: acsinet21.oracle.com [141.146.126.237] NSDB tools that perform fileserver queries are allowed to follow LDAP referrals if the NSDB's "follow referrals" flag is on. Signed-off-by: Chuck Lever --- src/nsdbc/nsdb-list.c | 53 ++++++++++++++++++++++++++++++++++++++ src/nsdbc/nsdb-resolve-fsn.c | 59 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 112 insertions(+), 0 deletions(-) diff --git a/src/nsdbc/nsdb-list.c b/src/nsdbc/nsdb-list.c index 0e271b2..e3a8ab0 100644 --- a/src/nsdbc/nsdb-list.c +++ b/src/nsdbc/nsdb-list.c @@ -142,6 +142,52 @@ nsdb_list_resolve_and_display_fsn(nsdb_t host, const char *nce, const char *fsn_ } /** + * Attempt to follow an LDAP referral to another NSDB + * + * @param host OUT: pointer to an initialized nsdb_t that may be replaced + * @return a FedFsStatus code + */ +static FedFsStatus +nsdb_list_follow_ldap_referral(nsdb_t *host) +{ + static unsigned int nest = 0; + FedFsStatus retval; + nsdb_t old, refer; + + old = *host; + if (!nsdb_follow_referrals(old)) { + fprintf(stderr, "LDAP referrals for NSDB %s:%u disallowed\n", + nsdb_hostname(old), nsdb_port(old)); + return FEDFS_ERR_NSDB_LDAP_REFERRAL_NOTFOLLOWED; + } + + if (nest++ > 10) { + fprintf(stderr, "Possible referral loop for NSDB %s:%u\n", + nsdb_hostname(old), nsdb_port(old)); + return FEDFS_ERR_NSDB_LDAP_REFERRAL_NOTFOLLOWED; + } + + retval = nsdb_lookup_nsdb_by_uri(nsdb_referred_to(old), &refer); + switch (retval) { + case FEDFS_OK: + break; + case FEDFS_ERR_NSDB_PARAMS: + fprintf(stderr, "Encountered referral to unrecognized NSDB %s\n", + nsdb_referred_to(old)); + return FEDFS_ERR_NSDB_LDAP_REFERRAL_NOTFOLLOWED; + default: + fprintf(stderr, "Problem following referral: %s", + nsdb_display_fedfsstatus(retval)); + return retval; + } + + nsdb_close_nsdb(old); + nsdb_free_nsdb(old); + *host = refer; + return FEDFS_OK; +} + +/** * Program entry point * * @param argc count of command line arguments @@ -232,6 +278,7 @@ main(int argc, char **argv) goto out; } +again: retval = nsdb_open_nsdb(host, NULL, NULL, &ldap_err); switch (retval) { case FEDFS_OK: @@ -280,6 +327,12 @@ main(int argc, char **argv) fprintf(stderr, "NCE %s does not exist\n", nce); break; case FEDFS_ERR_NSDB_LDAP_VAL: + if (ldap_err == LDAP_REFERRAL) { + retval = nsdb_list_follow_ldap_referral(&host); + if (retval != FEDFS_OK) + break; + goto again; + } fprintf(stderr, "Failed to list FSNs: %s\n", ldap_err2string(ldap_err)); break; diff --git a/src/nsdbc/nsdb-resolve-fsn.c b/src/nsdbc/nsdb-resolve-fsn.c index 0056200..23d292d 100644 --- a/src/nsdbc/nsdb-resolve-fsn.c +++ b/src/nsdbc/nsdb-resolve-fsn.c @@ -190,6 +190,52 @@ nsdb_resolve_fsn_display_fsls(struct fedfs_fsl *fsls) } /** + * Attempt to follow an LDAP referral to another NSDB + * + * @param host OUT: pointer to an initialized nsdb_t that may be replaced + * @return a FedFsStatus code + */ +static FedFsStatus +nsdb_resolve_fsn_follow_ldap_referral(nsdb_t *host) +{ + static unsigned int nest = 0; + FedFsStatus retval; + nsdb_t old, refer; + + old = *host; + if (!nsdb_follow_referrals(old)) { + fprintf(stderr, "LDAP referrals for NSDB %s:%u disallowed\n", + nsdb_hostname(old), nsdb_port(old)); + return FEDFS_ERR_NSDB_LDAP_REFERRAL_NOTFOLLOWED; + } + + if (nest++ > 10) { + fprintf(stderr, "Possible referral loop for NSDB %s:%u\n", + nsdb_hostname(old), nsdb_port(old)); + return FEDFS_ERR_NSDB_LDAP_REFERRAL_NOTFOLLOWED; + } + + retval = nsdb_lookup_nsdb_by_uri(nsdb_referred_to(old), &refer); + switch (retval) { + case FEDFS_OK: + break; + case FEDFS_ERR_NSDB_PARAMS: + fprintf(stderr, "Encountered referral to unrecognized NSDB %s\n", + nsdb_referred_to(old)); + return FEDFS_ERR_NSDB_LDAP_REFERRAL_NOTFOLLOWED; + default: + fprintf(stderr, "Problem following referral: %s\n", + nsdb_display_fedfsstatus(retval)); + return retval; + } + + nsdb_close_nsdb(old); + nsdb_free_nsdb(old); + *host = refer; + return FEDFS_OK; +} + +/** * Program entry point * * @param argc count of command line arguments @@ -292,6 +338,7 @@ main(int argc, char **argv) goto out; } +again: retval = nsdb_open_nsdb(host, NULL, NULL, &ldap_err); switch (retval) { case FEDFS_OK: @@ -332,6 +379,12 @@ main(int argc, char **argv) fprintf(stderr, "Failed to find FSN %s\n", fsn_uuid); goto out_close; case FEDFS_ERR_NSDB_LDAP_VAL: + if (ldap_err == LDAP_REFERRAL) { + retval = nsdb_resolve_fsn_follow_ldap_referral(&host); + if (retval != FEDFS_OK) + goto out_close; + goto again; + } fprintf(stderr, "NSDB LDAP error: %s\n", ldap_err2string(ldap_err)); goto out_close; @@ -366,6 +419,12 @@ main(int argc, char **argv) fprintf(stderr, "Failed to find FSN %s\n", fsn_uuid); break; case FEDFS_ERR_NSDB_LDAP_VAL: + if (ldap_err == LDAP_REFERRAL) { + retval = nsdb_resolve_fsn_follow_ldap_referral(&host); + if (retval != FEDFS_OK) + break; + goto again; + } fprintf(stderr, "NSDB LDAP error: %s\n", ldap_err2string(ldap_err)); break;