andykimpe / rpms / 389-ds-base

Forked from rpms/389-ds-base 5 months ago
Clone
dc8c34
From 54431eb9e2438a838904a6d4846c45131b937cd0 Mon Sep 17 00:00:00 2001
dc8c34
From: Ken Rossato <ken.rossato@redhat.com>
dc8c34
Date: Mon, 24 Sep 2012 19:52:09 -0400
dc8c34
Subject: [PATCH 4/5] Ticket #481 - expand nested posix groups
dc8c34
dc8c34
Description: Add ability to populate memberuid dynamically to
dc8c34
reflect nested grouping.
dc8c34
(cherry picked from commit b9eeb2e1a8e688dfec753e8965d0e5aeb119e638)
dc8c34
---
dc8c34
 Makefile.am                                        |    1 +
dc8c34
 Makefile.in                                        |    1 +
dc8c34
 ldap/ldif/50posix-winsync-plugin.ldif              |    1 +
dc8c34
 ldap/schema/60posix-winsync-plugin.ldif            |   44 +
dc8c34
 .../plugins/posix-winsync/posix-group-func.c       |  846 ++++++++++++++++----
dc8c34
 .../plugins/posix-winsync/posix-group-task.c       |  249 +++++--
dc8c34
 .../plugins/posix-winsync/posix-winsync-config.c   |   16 +
dc8c34
 ldap/servers/plugins/posix-winsync/posix-winsync.c |   72 ++-
dc8c34
 .../plugins/posix-winsync/posix-wsp-ident.h        |    4 +-
dc8c34
 9 files changed, 1008 insertions(+), 226 deletions(-)
dc8c34
 create mode 100644 ldap/schema/60posix-winsync-plugin.ldif
dc8c34
dc8c34
diff --git a/Makefile.am b/Makefile.am
dc8c34
index c5c4080..507a2d6 100644
dc8c34
--- a/Makefile.am
dc8c34
+++ b/Makefile.am
dc8c34
@@ -299,6 +299,7 @@ schema_DATA = $(srcdir)/ldap/schema/00core.ldif \
dc8c34
 	$(srcdir)/ldap/schema/50ns-value.ldif \
dc8c34
 	$(srcdir)/ldap/schema/50ns-web.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60pam-plugin.ldif \
dc8c34
+	$(srcdir)/ldap/schema/60posix-winsync-plugin.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60autofs.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60eduperson.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60mozilla.ldif \
dc8c34
diff --git a/Makefile.in b/Makefile.in
dc8c34
index 3777829..f105932 100644
dc8c34
--- a/Makefile.in
dc8c34
+++ b/Makefile.in
dc8c34
@@ -1527,6 +1527,7 @@ schema_DATA = $(srcdir)/ldap/schema/00core.ldif \
dc8c34
 	$(srcdir)/ldap/schema/50ns-value.ldif \
dc8c34
 	$(srcdir)/ldap/schema/50ns-web.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60pam-plugin.ldif \
dc8c34
+	$(srcdir)/ldap/schema/60posix-winsync-plugin.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60autofs.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60eduperson.ldif \
dc8c34
 	$(srcdir)/ldap/schema/60mozilla.ldif \
dc8c34
diff --git a/ldap/ldif/50posix-winsync-plugin.ldif b/ldap/ldif/50posix-winsync-plugin.ldif
dc8c34
index de8c432..17dc243 100644
dc8c34
--- a/ldap/ldif/50posix-winsync-plugin.ldif
dc8c34
+++ b/ldap/ldif/50posix-winsync-plugin.ldif
dc8c34
@@ -10,6 +10,7 @@ nsslapd-pluginenabled: off
dc8c34
 nsslapd-plugin-depends-on-type: database
dc8c34
 posixWinsyncMsSFUSchema: false
dc8c34
 posixWinsyncMapMemberUID: true
dc8c34
+posixWinsyncMapNestedGrouping: false
dc8c34
 posixWinsyncCreateMemberOfTask: false
dc8c34
 posixWinsyncLowerCaseUID: false
dc8c34
 nsslapd-pluginprecedence: 25
dc8c34
diff --git a/ldap/schema/60posix-winsync-plugin.ldif b/ldap/schema/60posix-winsync-plugin.ldif
dc8c34
new file mode 100644
dc8c34
index 0000000..8d9a72e
dc8c34
--- /dev/null
dc8c34
+++ b/ldap/schema/60posix-winsync-plugin.ldif
dc8c34
@@ -0,0 +1,44 @@
dc8c34
+#
dc8c34
+# BEGIN COPYRIGHT BLOCK
dc8c34
+# This Program is free software; you can redistribute it and/or modify it under
dc8c34
+# the terms of the GNU General Public License as published by the Free Software
dc8c34
+# Foundation; version 2 of the License.
dc8c34
+# 
dc8c34
+# This Program is distributed in the hope that it will be useful, but WITHOUT
dc8c34
+# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
dc8c34
+# FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
dc8c34
+# 
dc8c34
+# You should have received a copy of the GNU General Public License along with
dc8c34
+# this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
dc8c34
+# Place, Suite 330, Boston, MA 02111-1307 USA.
dc8c34
+# 
dc8c34
+# In addition, as a special exception, Red Hat, Inc. gives You the additional
dc8c34
+# right to link the code of this Program with code not covered under the GNU
dc8c34
+# General Public License ("Non-GPL Code") and to distribute linked combinations
dc8c34
+# including the two, subject to the limitations in this paragraph. Non-GPL Code
dc8c34
+# permitted under this exception must only link to the code of this Program
dc8c34
+# through those well defined interfaces identified in the file named EXCEPTION
dc8c34
+# found in the source code files (the "Approved Interfaces"). The files of
dc8c34
+# Non-GPL Code may instantiate templates or use macros or inline functions from
dc8c34
+# the Approved Interfaces without causing the resulting work to be covered by
dc8c34
+# the GNU General Public License. Only Red Hat, Inc. may make changes or
dc8c34
+# additions to the list of Approved Interfaces. You must obey the GNU General
dc8c34
+# Public License in all respects for all of the Program code and other code used
dc8c34
+# in conjunction with the Program except the Non-GPL Code covered by this
dc8c34
+# exception. If you modify this file, you may extend this exception to your
dc8c34
+# version of the file, but you are not obligated to do so. If you do not wish to
dc8c34
+# provide this exception without modification, you must delete this exception
dc8c34
+# statement from your version and license this file solely under the GPL without
dc8c34
+# exception. 
dc8c34
+# 
dc8c34
+#  
dc8c34
+# Copyright (C) 2005 Red Hat, Inc.
dc8c34
+# All rights reserved.
dc8c34
+# END COPYRIGHT BLOCK
dc8c34
+#
dc8c34
+#
dc8c34
+# Schema for representing internal dynamically-generated group members
dc8c34
+#
dc8c34
+dn: cn=schema
dc8c34
+attributeTypes: ( 2.16.840.1.113730.3.1.2141 NAME 'dsOnlyMemberUid' DESC 'Elements from a memberuid attribute created to reflect dynamic group membership' SYNTAX  1.3.6.1.4.1.1466.115.121.1.26 X-ORIGIN 'Red Hat Directory Server' )
dc8c34
+objectClasses: ( 2.16.840.1.113730.3.2.326 NAME 'dynamicGroup' DESC 'Group containing internal dynamically-generated members' SUP posixGroup AUXILIARY MAY ( dsOnlyMemberUid ) X-ORIGIN 'Red Hat Directory Server' )
dc8c34
diff --git a/ldap/servers/plugins/posix-winsync/posix-group-func.c b/ldap/servers/plugins/posix-winsync/posix-group-func.c
dc8c34
index 1403a89..66b9272 100644
dc8c34
--- a/ldap/servers/plugins/posix-winsync/posix-group-func.c
dc8c34
+++ b/ldap/servers/plugins/posix-winsync/posix-group-func.c
dc8c34
@@ -18,11 +18,14 @@
dc8c34
  $Id: posix-group-func.c 28 2011-05-13 14:35:29Z grzemba $
dc8c34
  */
dc8c34
 #include "slapi-plugin.h"
dc8c34
+#include "slapi-private.h"
dc8c34
 
dc8c34
 #include <string.h>
dc8c34
 #include <nspr.h>
dc8c34
 #include "posix-wsp-ident.h"
dc8c34
 
dc8c34
+#define MAX_RECURSION_DEPTH (5)
dc8c34
+
dc8c34
 Slapi_Value **
dc8c34
 valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
dc8c34
 static PRMonitor *memberuid_operation_lock = 0;
dc8c34
@@ -45,58 +48,100 @@ memberUidLockInit()
dc8c34
     return (memberuid_operation_lock = PR_NewMonitor()) != NULL;
dc8c34
 }
dc8c34
 
dc8c34
+void
dc8c34
+addDynamicGroupIfNecessary(Slapi_Entry *entry, Slapi_Mods *smods) {
dc8c34
+    Slapi_Attr *oc_attr = NULL;
dc8c34
+    Slapi_Value *voc = slapi_value_new();
dc8c34
+
dc8c34
+    slapi_value_init_string(voc, "dynamicGroup");
dc8c34
+    slapi_entry_attr_find(entry, "objectClass", &oc_attr);
dc8c34
+
dc8c34
+    if (slapi_attr_value_find(oc_attr, slapi_value_get_berval(voc)) != 0) {
dc8c34
+        if (smods) {
dc8c34
+            slapi_mods_add_string(smods, LDAP_MOD_ADD, "objectClass", "dynamicGroup");
dc8c34
+        }
dc8c34
+        else {
dc8c34
+            smods = slapi_mods_new();
dc8c34
+            slapi_mods_add_string(smods, LDAP_MOD_ADD, "objectClass", "dynamicGroup");
dc8c34
+
dc8c34
+            Slapi_PBlock *mod_pb = slapi_pblock_new();
dc8c34
+            slapi_modify_internal_set_pb_ext(mod_pb, slapi_entry_get_sdn(entry), slapi_mods_get_ldapmods_passout(smods), 0, 0,
dc8c34
+                                             posix_winsync_get_plugin_identity(), 0);
dc8c34
+            slapi_modify_internal_pb(mod_pb);
dc8c34
+            slapi_pblock_destroy(mod_pb);
dc8c34
+
dc8c34
+            slapi_mods_free(&smods);
dc8c34
+        }
dc8c34
+    }
dc8c34
+
dc8c34
+    slapi_value_free(&voc;;
dc8c34
+}
dc8c34
+
dc8c34
+Slapi_Entry *
dc8c34
+getEntry(const char *udn, char **attrs)
dc8c34
+{
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "getEntry: search %s\n", udn);
dc8c34
+
dc8c34
+    Slapi_DN *udn_sdn = slapi_sdn_new_dn_byval(udn);
dc8c34
+    Slapi_Entry *result = NULL;
dc8c34
+    int rc = slapi_search_internal_get_entry(udn_sdn, attrs, &result, posix_winsync_get_plugin_identity());
dc8c34
+    slapi_sdn_free(&udn_sdn);
dc8c34
+
dc8c34
+    if (rc == 0) {
dc8c34
+        if (result != NULL) {
dc8c34
+            return result; /* Must be freed */
dc8c34
+        }
dc8c34
+        else {
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "getEntry: %s not found\n", udn);
dc8c34
+        }
dc8c34
+    }
dc8c34
+    else {
dc8c34
+        slapi_log_error(SLAPI_LOG_FATAL, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "getEntry: error searching for uid: %d", rc);
dc8c34
+    }
dc8c34
+
dc8c34
+    return NULL;
dc8c34
+}
dc8c34
+
dc8c34
 /* search the user with DN udn and returns uid*/
dc8c34
 char *
dc8c34
 searchUid(const char *udn)
dc8c34
 {
dc8c34
-    Slapi_PBlock *int_search_pb = slapi_pblock_new();
dc8c34
-    Slapi_Entry **entries = NULL;
dc8c34
-    char *attrs[] = { "uid", NULL };
dc8c34
+    char *attrs[] = { "uid", "objectclass", NULL };
dc8c34
+    Slapi_Entry *entry = getEntry(udn,
dc8c34
+                                  /* "(|(objectclass=posixAccount)(objectclass=ldapsubentry))", */
dc8c34
+                                  attrs);
dc8c34
     char *uid = NULL;
dc8c34
 
dc8c34
-    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "search Uid: search %s\n", udn);
dc8c34
+    if (entry) {
dc8c34
+        Slapi_Attr *attr = NULL;
dc8c34
+        Slapi_Value *v = NULL;
dc8c34
 
dc8c34
-    slapi_search_internal_set_pb(int_search_pb, udn, LDAP_SCOPE_BASE,
dc8c34
-                                 "(|(objectclass=posixAccount)(objectclass=ldapsubentry))", attrs,
dc8c34
-                                 0 /* attrsonly */, NULL /* controls */, NULL /* uniqueid */,
dc8c34
-                                 posix_winsync_get_plugin_identity(), 0 /* actions */);
dc8c34
-    if (slapi_search_internal_pb(int_search_pb)) {
dc8c34
-        /* get result and log an error */
dc8c34
-        int res = 0;
dc8c34
-        slapi_pblock_get(int_search_pb, SLAPI_PLUGIN_INTOP_RESULT, &res;;
dc8c34
-        slapi_log_error(SLAPI_LOG_FATAL, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                        "searchUid: error searching for uid: %d", res);
dc8c34
-    } else {
dc8c34
-        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "searchUid: searched %s\n",
dc8c34
-                        udn);
dc8c34
-        slapi_pblock_get(int_search_pb, SLAPI_PLUGIN_INTOP_SEARCH_ENTRIES, &entries);
dc8c34
-        if (NULL != entries && NULL != entries[0]) {
dc8c34
-            Slapi_Attr *attr = NULL;
dc8c34
-            Slapi_Value *v = NULL;
dc8c34
+        if (slapi_entry_attr_find(entry, "uid", &attr) == 0 && hasObjectClass(entry, "posixAccount")) {
dc8c34
+            slapi_attr_first_value(attr, &v);
dc8c34
+            uid = slapi_ch_strdup(slapi_value_get_string(v));
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "searchUid: return uid %s\n", uid);
dc8c34
+        } else {
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "searchUid: uid in %s not found\n", udn);
dc8c34
+        }
dc8c34
 
dc8c34
-            if (slapi_entry_attr_find(entries[0], "uid", &attr) == 0) {
dc8c34
-                slapi_attr_first_value(attr, &v);
dc8c34
-                uid = slapi_ch_strdup(slapi_value_get_string(v));
dc8c34
-                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                "searchUid: return uid %s\n", uid);
dc8c34
-                /* slapi_value_free(&v); */
dc8c34
-            } else {
dc8c34
-                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                "searchUid: uid in %s not found\n", udn);
dc8c34
-            }
dc8c34
-            slapi_free_search_results_internal(int_search_pb);
dc8c34
-            slapi_pblock_destroy(int_search_pb);
dc8c34
-            if (uid && posix_winsync_config_get_lowercase()) {
dc8c34
-                return slapi_dn_ignore_case(uid);
dc8c34
-            }
dc8c34
-            return uid;
dc8c34
+        if (uid && posix_winsync_config_get_lowercase()) {
dc8c34
+            uid = slapi_dn_ignore_case(uid);
dc8c34
         }
dc8c34
+
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "searchUid: About to free entry\n", udn);
dc8c34
+        
dc8c34
+        slapi_entry_free(entry);
dc8c34
     }
dc8c34
-    slapi_free_search_results_internal(int_search_pb);
dc8c34
-    slapi_pblock_destroy(int_search_pb);
dc8c34
+
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                    "searchUid: posix user %s not found\n", udn);
dc8c34
-    return NULL;
dc8c34
+                    "searchUid: <==\n", udn);
dc8c34
+        
dc8c34
+    return uid;
dc8c34
 }
dc8c34
 
dc8c34
 int
dc8c34
@@ -152,6 +197,36 @@ uid_in_set(const char* uid, char **uids)
dc8c34
     return false;
dc8c34
 }
dc8c34
 
dc8c34
+int
dc8c34
+uid_in_valueset(const char* uid, Slapi_ValueSet *uids)
dc8c34
+{
dc8c34
+    int i;
dc8c34
+    Slapi_Value *v = NULL;
dc8c34
+
dc8c34
+    if (uid == NULL)
dc8c34
+        return false;
dc8c34
+    for (i = slapi_valueset_first_value(uids, &v); i != -1;
dc8c34
+         i = slapi_valueset_next_value(uids, i, &v)) {
dc8c34
+        Slapi_RDN *i_rdn = NULL;
dc8c34
+        char *i_uid = NULL;
dc8c34
+        char *t = NULL;
dc8c34
+
dc8c34
+        const char *uid_i = slapi_value_get_string(v);
dc8c34
+
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "uid_in_valueset: comp %s %s \n",
dc8c34
+                        uid, uid_i);
dc8c34
+        i_rdn = slapi_rdn_new_dn(uid_i);
dc8c34
+        if (slapi_rdn_get_first(i_rdn, &t, &i_uid) == 1) {
dc8c34
+            if (strncasecmp(uid, i_uid, 256) == 0) {
dc8c34
+                slapi_rdn_free(&i_rdn);
dc8c34
+                return true;
dc8c34
+            }
dc8c34
+        }
dc8c34
+        slapi_rdn_free(&i_rdn);
dc8c34
+    }
dc8c34
+    return false;
dc8c34
+}
dc8c34
+
dc8c34
 /* return 1 if smods already has the given mod - 0 otherwise */
dc8c34
 static int
dc8c34
 smods_has_mod(Slapi_Mods *smods, int modtype, const char *type, const char *val)
dc8c34
@@ -186,7 +261,7 @@ smods_has_mod(Slapi_Mods *smods, int modtype, const char *type, const char *val)
dc8c34
 }
dc8c34
 
dc8c34
 int
dc8c34
-isPosixGroup(Slapi_Entry *entry)
dc8c34
+hasObjectClass(Slapi_Entry *entry, const char *objectClass)
dc8c34
 {
dc8c34
     int rc = 0;
dc8c34
     int i;
dc8c34
@@ -200,7 +275,7 @@ isPosixGroup(Slapi_Entry *entry)
dc8c34
     }
dc8c34
 
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                    "add/mod-GroupMembership scan objectclasses\n");
dc8c34
+                    "Scanning objectclasses\n");
dc8c34
 
dc8c34
     for (
dc8c34
         i = slapi_attr_first_value(obj_attr, &value);
dc8c34
@@ -209,22 +284,357 @@ isPosixGroup(Slapi_Entry *entry)
dc8c34
     ) {
dc8c34
         const char *oc = NULL;
dc8c34
         oc = slapi_value_get_string(value);
dc8c34
-        if (strncasecmp(oc, "posixGroup", 11) == 0) {
dc8c34
-            return 1; /* Entry has objectclass posixGroup */
dc8c34
+        if (strcasecmp(oc, objectClass) == 0) {
dc8c34
+            return 1; /* Entry has the desired objectclass */
dc8c34
+        }
dc8c34
+    }
dc8c34
+    
dc8c34
+    return 0; /* Doesn't have desired objectclass */
dc8c34
+}
dc8c34
+
dc8c34
+void
dc8c34
+posix_winsync_foreach_parent(Slapi_Entry *entry, char **attrs, plugin_search_entry_callback callback, void *callback_data)
dc8c34
+{
dc8c34
+    char *cookie = NULL;
dc8c34
+    Slapi_Backend *be = NULL;
dc8c34
+
dc8c34
+    const char *value = slapi_entry_get_ndn(entry);
dc8c34
+    size_t vallen = value ? strlen(value) : 0;
dc8c34
+    char *filter_escaped_value = slapi_ch_calloc(sizeof(char), vallen*3+1);
dc8c34
+    char *filter = slapi_ch_smprintf("(uniqueMember=%s)", escape_filter_value(value, vallen, filter_escaped_value));
dc8c34
+    slapi_ch_free_string(&filter_escaped_value);
dc8c34
+
dc8c34
+    Slapi_PBlock *search_pb = slapi_pblock_new();
dc8c34
+
dc8c34
+    for (be = slapi_get_first_backend(&cookie); be;
dc8c34
+         be = slapi_get_next_backend(cookie)) {
dc8c34
+        const Slapi_DN *base_sdn = slapi_be_getsuffix(be, 0);
dc8c34
+        if (base_sdn == NULL) {
dc8c34
+            continue;
dc8c34
         }
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "posix_winsync_foreach_parent: Searching subtree %s for %s\n",
dc8c34
+                        slapi_sdn_get_dn(base_sdn),
dc8c34
+                        filter);
dc8c34
+        
dc8c34
+        slapi_search_internal_set_pb(search_pb,
dc8c34
+                                     slapi_sdn_get_dn(base_sdn),
dc8c34
+                                     LDAP_SCOPE_SUBTREE,
dc8c34
+                                     filter,
dc8c34
+                                     attrs, 0, NULL, NULL,
dc8c34
+                                     posix_winsync_get_plugin_identity(), 0);
dc8c34
+        slapi_search_internal_callback_pb(search_pb, callback_data, 0, callback, 0);        
dc8c34
+        
dc8c34
+        slapi_pblock_init(search_pb);
dc8c34
     }
dc8c34
 
dc8c34
-    return 0; /* Doesn't have objectclass "posixGroup" */
dc8c34
+    slapi_pblock_destroy(search_pb);
dc8c34
+    slapi_ch_free((void**)&cookie);
dc8c34
+    slapi_ch_free_string(&filter);
dc8c34
 }
dc8c34
 
dc8c34
-int
dc8c34
-modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify)
dc8c34
+/* Retrieve nested membership from chains of groups.
dc8c34
+ * Muid_vs  in => any preexisting membership list
dc8c34
+ *         out => the union of the input list and the total membership
dc8c34
+ * Muid_nested_vs out => the members of muid_vs "out" that weren't in muid_vs "in"
dc8c34
+ * deletions in => Any elements to NOT consider if members of base_sdn
dc8c34
+ */
dc8c34
+void
dc8c34
+getMembershipFromDownward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, Slapi_ValueSet *muid_nested_vs, Slapi_ValueSet *deletions, const Slapi_DN *base_sdn, int depth)
dc8c34
 {
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "getMembershipFromDownward: ==>\n");
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "getMembershipFromDownward: entry name: %s\n",
dc8c34
+                    slapi_entry_get_dn_const(entry));
dc8c34
+
dc8c34
     int rc = 0;
dc8c34
+    Slapi_Attr *um_attr = NULL; /* Entry attributes uniqueMember */
dc8c34
+    Slapi_Value *uid_value = NULL; /* uniqueMember attribute values */
dc8c34
+
dc8c34
+    if (depth >= MAX_RECURSION_DEPTH) {
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "getMembershipFromDownward: recursion limit reached: %d\n", depth);
dc8c34
+        return;
dc8c34
+    }
dc8c34
+
dc8c34
+    rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
dc8c34
+    if (rc != 0 || um_attr == NULL) {
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "getMembershipFromDownward end: attribute uniquemember not found\n");
dc8c34
+        return;
dc8c34
+    }
dc8c34
+
dc8c34
+    int i;
dc8c34
+    for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
dc8c34
+         i = slapi_attr_next_value(um_attr, i, &uid_value)) {
dc8c34
+
dc8c34
+        char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
dc8c34
+        const char *uid_dn = slapi_value_get_string(uid_value);
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "getMembershipFromDownward: iterating uniqueMember: %s\n",
dc8c34
+                        uid_dn);
dc8c34
+        
dc8c34
+        if (deletions && !slapi_sdn_compare(slapi_entry_get_sdn_const(entry), base_sdn)) {
dc8c34
+            if (slapi_valueset_find(um_attr, deletions, uid_value)) {
dc8c34
+                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                "getMembershipFromDownward: Skipping iteration because of deletion\n");
dc8c34
+
dc8c34
+                continue;
dc8c34
+            }
dc8c34
+        }
dc8c34
+
dc8c34
+        Slapi_Entry *child = getEntry(uid_dn, attrs);
dc8c34
+
dc8c34
+        if (!child) {
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "getMembershipFromDownward end: child not found: %s\n", uid_dn);
dc8c34
+        }
dc8c34
+        else {
dc8c34
+            /* PosixGroups except for the top one are already fully mapped out */
dc8c34
+            if ((!hasObjectClass(entry, "posixGroup") || depth == 0) &&
dc8c34
+                (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup"))) {
dc8c34
+
dc8c34
+                /* Recurse downward */
dc8c34
+                getMembershipFromDownward(child, muid_vs, muid_nested_vs, deletions, base_sdn, depth + 1);
dc8c34
+            }
dc8c34
+
dc8c34
+            if (hasObjectClass(child, "posixAccount")) {
dc8c34
+                Slapi_Attr *uid_attr = NULL;
dc8c34
+                Slapi_Value *v = NULL;
dc8c34
+                if (slapi_entry_attr_find(child, "uid", &uid_attr) == 0) {
dc8c34
+                    slapi_attr_first_value(uid_attr, &v);
dc8c34
+
dc8c34
+                    if (v && !slapi_valueset_find(uid_attr, muid_vs, v)) {                        
dc8c34
+                        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                        "getMembershipFromDownward: adding member: %s\n",
dc8c34
+                                        slapi_value_get_string(v));
dc8c34
+                        slapi_valueset_add_value(muid_vs, v);
dc8c34
+                        slapi_valueset_add_value(muid_nested_vs, v);
dc8c34
+                    }
dc8c34
+                }
dc8c34
+            }
dc8c34
+            slapi_entry_free(child);
dc8c34
+        }
dc8c34
+    }
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "getMembershipFromDownward: <==\n");
dc8c34
+}
dc8c34
+
dc8c34
+struct propogateMembershipUpwardArgs {
dc8c34
+    Slapi_ValueSet *muid_vs;
dc8c34
+    int depth;
dc8c34
+};
dc8c34
+
dc8c34
+/* Forward declaration for next function */
dc8c34
+void propogateMembershipUpward(Slapi_Entry *, Slapi_ValueSet *, int);
dc8c34
+
dc8c34
+int
dc8c34
+propogateMembershipUpwardCallback(Slapi_Entry *child, void *callback_data)
dc8c34
+{
dc8c34
+    struct propogateMembershipUpwardArgs *args = (struct propogateMembershipUpwardArgs *)(callback_data);
dc8c34
+    propogateMembershipUpward(child, args->muid_vs, args->depth);
dc8c34
+    return 0;
dc8c34
+}
dc8c34
+
dc8c34
+void
dc8c34
+propogateMembershipUpward(Slapi_Entry *entry, Slapi_ValueSet *muid_vs, int depth)
dc8c34
+{
dc8c34
+    if (depth >= MAX_RECURSION_DEPTH) {
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "propogateMembershipUpward: recursion limit reached: %d\n", depth);
dc8c34
+        return;
dc8c34
+    }
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "propogateMembershipUpward: ==>\n");
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "propogateMembershipUpward: entry name: %s\n",
dc8c34
+                    slapi_entry_get_dn_const(entry));
dc8c34
+
dc8c34
+    Slapi_ValueSet *muid_here_vs   = NULL;
dc8c34
+    Slapi_ValueSet *muid_upward_vs = NULL;
dc8c34
+
dc8c34
+    /* Get the memberUids at this location, and figure out local changes to memberUid (if any)
dc8c34
+     *  and changes to send upward.
dc8c34
+     */
dc8c34
+    if (depth > 0 && hasObjectClass(entry, "posixGroup")) {
dc8c34
+        int addDynamicGroup = 0;
dc8c34
+        Slapi_Attr *muid_old_attr = NULL;
dc8c34
+        Slapi_ValueSet *muid_old_vs = NULL;
dc8c34
+        int rc = slapi_entry_attr_find(entry, "memberUid", &muid_old_attr);
dc8c34
+        if (rc != 0 || muid_old_attr == NULL) { /* Found no memberUid list, so create  */
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "propogateMembershipUpward: no attribute memberUid\n");
dc8c34
+            
dc8c34
+            /* There's no values from this entry to add */
dc8c34
+            muid_upward_vs = muid_vs;
dc8c34
+            muid_here_vs = muid_vs;
dc8c34
+        }
dc8c34
+        else {
dc8c34
+            /* Eliminate duplicates */
dc8c34
+            muid_upward_vs = slapi_valueset_new();
dc8c34
+            muid_here_vs = slapi_valueset_new();
dc8c34
+
dc8c34
+            slapi_valueset_set_valueset(muid_upward_vs, muid_old_vs);
dc8c34
+
dc8c34
+            slapi_attr_get_valueset(muid_old_attr, &muid_old_vs);
dc8c34
+            int i = 0;
dc8c34
+            Slapi_Value *v = NULL;
dc8c34
+            for (i = slapi_valueset_first_value(muid_vs, &v); i != -1;
dc8c34
+                 i = slapi_valueset_next_value(muid_vs, i, &v)) {
dc8c34
+                
dc8c34
+                if (!slapi_valueset_find(muid_old_attr, muid_old_vs, v)) {
dc8c34
+                    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                    "propogateMembershipUpward: adding %s to set\n",
dc8c34
+                                    slapi_value_get_string(v));
dc8c34
+
dc8c34
+                    addDynamicGroup = 1;
dc8c34
+                    slapi_valueset_add_value(muid_here_vs, v);
dc8c34
+                    slapi_valueset_add_value(muid_upward_vs, v);
dc8c34
+                }
dc8c34
+            }
dc8c34
+        }
dc8c34
+
dc8c34
+        /* Update this group's membership */
dc8c34
+        slapi_entry_add_valueset(entry, "memberUid", muid_here_vs);
dc8c34
+        if (addDynamicGroup) {
dc8c34
+            addDynamicGroupIfNecessary(entry, NULL);
dc8c34
+            slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_here_vs);
dc8c34
+        }
dc8c34
+    }
dc8c34
+    else {
dc8c34
+        muid_upward_vs = muid_vs;
dc8c34
+    }
dc8c34
+
dc8c34
+    /* Find groups containing this one, recurse
dc8c34
+     */
dc8c34
+    char *attrs[] = {"memberUid", "objectClass", NULL};
dc8c34
+    struct propogateMembershipUpwardArgs data = {muid_upward_vs, depth + 1};
dc8c34
+
dc8c34
+    posix_winsync_foreach_parent(entry, attrs, propogateMembershipUpwardCallback, &data);
dc8c34
+
dc8c34
+/* Cleanup */
dc8c34
+    if (muid_here_vs && muid_here_vs != muid_vs) {
dc8c34
+        slapi_valueset_free(muid_here_vs); muid_here_vs = NULL;
dc8c34
+    }
dc8c34
+    if (muid_upward_vs && muid_upward_vs != muid_vs) {
dc8c34
+        slapi_valueset_free(muid_upward_vs); muid_upward_vs = NULL;
dc8c34
+    }
dc8c34
 
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "propogateMembershipUpward: <==\n");
dc8c34
+}
dc8c34
+
dc8c34
+struct propogateDeletionsUpwardArgs {
dc8c34
+    const Slapi_DN *base_sdn;
dc8c34
+    Slapi_ValueSet *smod_deluids;
dc8c34
+    Slapi_ValueSet *del_nested_vs;
dc8c34
+    int depth;
dc8c34
+};
dc8c34
+
dc8c34
+/* Forward declaration for next function */
dc8c34
+void propogateDeletionsUpward(Slapi_Entry *, const Slapi_DN *, Slapi_ValueSet*, Slapi_ValueSet *, int);
dc8c34
+
dc8c34
+int
dc8c34
+propogateDeletionsUpwardCallback(Slapi_Entry *entry, void *callback_data)
dc8c34
+{
dc8c34
+    struct propogateDeletionsUpwardArgs *args = (struct propogateDeletionsUpwardArgs *)(callback_data);
dc8c34
+    propogateDeletionsUpward(entry, args->base_sdn, args->smod_deluids, args->del_nested_vs, args->depth);
dc8c34
+}
dc8c34
+
dc8c34
+void
dc8c34
+propogateDeletionsUpward(Slapi_Entry *entry, const Slapi_DN *base_sdn, Slapi_ValueSet *smod_deluids, Slapi_ValueSet *del_nested_vs, int depth)
dc8c34
+{
dc8c34
+    if (smod_deluids == NULL) return;
dc8c34
+
dc8c34
+    if (depth >= MAX_RECURSION_DEPTH) {
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "propogateDeletionsUpward: recursion limit reached: %d\n", depth);
dc8c34
+        return;
dc8c34
+    }
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "propogateDeletionsUpward: ==>\n");
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "propogateDeletionsUpward: entry name: %s\n",
dc8c34
+                    slapi_entry_get_dn_const(entry));
dc8c34
+
dc8c34
+    char *attrs[] = { "uniqueMember", "memberUid", "objectClass", NULL };
dc8c34
+    struct propogateDeletionsUpwardArgs data = {base_sdn, smod_deluids, del_nested_vs, depth + 1};
dc8c34
+    posix_winsync_foreach_parent(entry, attrs, propogateDeletionsUpwardCallback, &data);
dc8c34
+
dc8c34
+    Slapi_Attr *muid_attr = NULL;
dc8c34
+    int rc = slapi_entry_attr_find(entry, "dsOnlyMemberUid", &muid_attr);
dc8c34
+    
dc8c34
+    if (rc == 0 && muid_attr != NULL) {
dc8c34
+
dc8c34
+        Slapi_ValueSet *muid_vs = slapi_valueset_new();
dc8c34
+        Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
dc8c34
+        Slapi_ValueSet *muid_deletions_vs = slapi_valueset_new();
dc8c34
+
dc8c34
+        getMembershipFromDownward(entry, muid_vs, muid_nested_vs, smod_deluids, base_sdn, 0);
dc8c34
+
dc8c34
+        int i;
dc8c34
+        Slapi_Value *v;
dc8c34
+        for (i = slapi_attr_first_value(muid_attr, &v); i != -1;
dc8c34
+             i = slapi_attr_next_value(muid_attr, i, &v)) {
dc8c34
+            if (!slapi_valueset_find(muid_attr, muid_vs, v)) {
dc8c34
+                const char *uid = slapi_value_get_string(v);
dc8c34
+                if (depth == 0 && !uid_in_valueset(uid, smod_deluids)) {
dc8c34
+                    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                    "propogateDeletionsUpward: Adding deletion to modlist: %s\n",
dc8c34
+                                    slapi_value_get_string(v));
dc8c34
+                    slapi_valueset_add_value(del_nested_vs, v);                    
dc8c34
+                }
dc8c34
+                else if (depth > 0) {
dc8c34
+                    slapi_valueset_add_value(muid_deletions_vs, v);                
dc8c34
+                    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                    "propogateDeletionsUpward: Adding deletion to deletion list: %s\n",
dc8c34
+                                    slapi_value_get_string(v));
dc8c34
+                }
dc8c34
+            }
dc8c34
+        }
dc8c34
+
dc8c34
+        if (depth > 0) {
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "propogateDeletionsUpward: executing deletion list\n");
dc8c34
+
dc8c34
+            Slapi_Mods *smods = slapi_mods_new();
dc8c34
+            slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "memberuid", valueset_get_valuearray(muid_deletions_vs));
dc8c34
+            slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "dsonlymemberuid", valueset_get_valuearray(muid_deletions_vs));
dc8c34
+
dc8c34
+            Slapi_PBlock *mod_pb = slapi_pblock_new();
dc8c34
+            slapi_modify_internal_set_pb_ext(mod_pb, slapi_entry_get_sdn(entry), slapi_mods_get_ldapmods_passout(smods), 0, 0,
dc8c34
+                                             posix_winsync_get_plugin_identity(), 0);
dc8c34
+            slapi_modify_internal_pb(mod_pb);
dc8c34
+            slapi_pblock_destroy(mod_pb);
dc8c34
+
dc8c34
+            slapi_mods_free(&smods);
dc8c34
+        }
dc8c34
+
dc8c34
+        slapi_valueset_free(muid_vs); muid_vs = NULL;
dc8c34
+        slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;
dc8c34
+        slapi_valueset_free(muid_deletions_vs); muid_deletions_vs = NULL;
dc8c34
+    }
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "propogateDeletionsUpward: <==\n");
dc8c34
+}
dc8c34
+
dc8c34
+int
dc8c34
+modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify)
dc8c34
+{
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: ==>\n");
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: Modding %s\n",
dc8c34
+                    slapi_entry_get_dn_const(entry));
dc8c34
 
dc8c34
-    if (!isPosixGroup(entry)) {
dc8c34
+    int posixGroup = hasObjectClass(entry, "posixGroup");
dc8c34
+
dc8c34
+    if (!(posixGroup || hasObjectClass(entry, "ntGroup"))) {
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "modGroupMembership end: Not a posixGroup or ntGroup\n");
dc8c34
         return 0;
dc8c34
     }
dc8c34
 
dc8c34
@@ -232,7 +642,7 @@ modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify)
dc8c34
     Slapi_Mod *nextMod = slapi_mod_new();
dc8c34
     int del_mod = 0; /* Bool: was there a delete mod? */
dc8c34
     char **smod_adduids = NULL;
dc8c34
-    char **smod_deluids = NULL;
dc8c34
+    Slapi_ValueSet *smod_deluids = NULL;
dc8c34
 
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                     "modGroupMembership: posixGroup -> look for uniquemember\n");
dc8c34
@@ -243,15 +653,20 @@ modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify)
dc8c34
         if (slapi_attr_types_equivalent(slapi_mod_get_type(smod), "uniqueMember")) {
dc8c34
             struct berval *bv;
dc8c34
 
dc8c34
+            int current_del_mod = SLAPI_IS_MOD_DELETE(slapi_mod_get_operation(smod));
dc8c34
+            if (current_del_mod) {
dc8c34
+                del_mod = 1;
dc8c34
+            }
dc8c34
+            
dc8c34
             for (bv = slapi_mod_get_first_value(smod); bv;
dc8c34
                  bv = slapi_mod_get_next_value(smod)) {
dc8c34
                 Slapi_Value *sv = slapi_value_new();
dc8c34
 
dc8c34
                 slapi_value_init_berval(sv, bv); /* copies bv_val */
dc8c34
-                if (SLAPI_IS_MOD_DELETE(slapi_mod_get_operation(smod))) {
dc8c34
-                    del_mod = 1;
dc8c34
-                    slapi_ch_array_add(&smod_deluids,
dc8c34
-                                       slapi_ch_strdup(slapi_value_get_string(sv)));
dc8c34
+                if (current_del_mod) {
dc8c34
+                    if (!smod_deluids) smod_deluids = slapi_valueset_new();
dc8c34
+
dc8c34
+                    slapi_valueset_add_value(smod_deluids, sv);
dc8c34
                     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                                     "modGroupMembership: add to deluids %s\n",
dc8c34
                                     bv->bv_val);
dc8c34
@@ -268,60 +683,67 @@ modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify)
dc8c34
     }
dc8c34
     slapi_mod_free(&nextMod);
dc8c34
 
dc8c34
-    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                    "modGroupMembership: entry is posixGroup\n");
dc8c34
-
dc8c34
-    Slapi_Attr * muid_attr = NULL; /* Entry attributes        */
dc8c34
+    int muid_rc = 0;
dc8c34
+    Slapi_Attr * muid_attr  = NULL; /* Entry attributes        */
dc8c34
+    Slapi_ValueSet *muid_vs = NULL;
dc8c34
     Slapi_Value * uid_value = NULL; /* Attribute values        */
dc8c34
 
dc8c34
-    char **adduids = NULL;
dc8c34
-    char **moduids = NULL;
dc8c34
-    char **deluids = NULL;
dc8c34
-    int doModify = false;
dc8c34
+    Slapi_ValueSet *adduids = slapi_valueset_new();
dc8c34
+    Slapi_ValueSet *add_nested_vs = slapi_valueset_new();
dc8c34
+    Slapi_ValueSet *deluids = slapi_valueset_new();
dc8c34
+    Slapi_ValueSet *del_nested_vs = slapi_valueset_new();
dc8c34
+
dc8c34
+    const Slapi_DN *base_sdn = slapi_entry_get_sdn_const(entry);
dc8c34
+
dc8c34
     int j = 0;
dc8c34
 
dc8c34
     if (del_mod || smod_deluids != NULL) {
dc8c34
         do { /* Create a context to "break" from */
dc8c34
-            Slapi_Attr * mu_attr = NULL; /* Entry attributes        */
dc8c34
-            rc = slapi_entry_attr_find(entry, "memberUid", &mu_attr);
dc8c34
-            if (rc != 0 || mu_attr == NULL) {
dc8c34
-                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                "modGroupMembership end: attribute memberUid not found\n");
dc8c34
-                break;
dc8c34
-            }
dc8c34
-            /* found attribute uniquemember */
dc8c34
+            muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
dc8c34
+
dc8c34
             if (smod_deluids == NULL) { /* deletion of the last value, deletes the Attribut from entry complete, this operation has no value, so we must look by self */
dc8c34
                 Slapi_Attr * um_attr = NULL; /* Entry attributes        */
dc8c34
                 Slapi_Value * uid_dn_value = NULL; /* Attribute values        */
dc8c34
                 int rc = slapi_entry_attr_find(entry, "uniquemember", &um_attr);
dc8c34
+                
dc8c34
                 if (rc != 0 || um_attr == NULL) {
dc8c34
                     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                                     "modGroupMembership end: attribute uniquemember not found\n");
dc8c34
                     break;
dc8c34
                 }
dc8c34
-                /* found attribute uniquemember */
dc8c34
-                /* ...loop for value...    */
dc8c34
-                for (j = slapi_attr_first_value(um_attr, &uid_dn_value); j != -1;
dc8c34
-                     j = slapi_attr_next_value(um_attr, j, &uid_dn_value)) {
dc8c34
-                    slapi_ch_array_add(&smod_deluids,
dc8c34
-                                       slapi_ch_strdup(slapi_value_get_string(uid_dn_value)));
dc8c34
-                }
dc8c34
+
dc8c34
+                slapi_attr_get_valueset(um_attr, &smod_deluids);
dc8c34
             }
dc8c34
-            /* ...loop for value...    */
dc8c34
-            for (j = slapi_attr_first_value(mu_attr, &uid_value); j != -1;
dc8c34
-                 j = slapi_attr_next_value(mu_attr, j, &uid_value)) {
dc8c34
-                /* remove from uniquemember: remove from memberUid also */
dc8c34
-                const char *uid = NULL;
dc8c34
+            if (muid_rc != 0 || muid_attr == NULL) {
dc8c34
                 slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                "modGroupMembership: test dellist \n");
dc8c34
-                uid = slapi_value_get_string(uid_value);
dc8c34
-                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                "modGroupMembership: test dellist %s\n", uid);
dc8c34
-                if (uid_in_set(uid, smod_deluids)) {
dc8c34
-                    slapi_ch_array_add(&deluids, slapi_ch_strdup(uid));
dc8c34
+                                "modGroupMembership end: attribute memberUid not found\n");
dc8c34
+            }
dc8c34
+            else if (posix_winsync_config_get_mapMemberUid()) {
dc8c34
+                /* ...loop for value...    */
dc8c34
+                for (j = slapi_attr_first_value(muid_attr, &uid_value); j != -1;
dc8c34
+                     j = slapi_attr_next_value(muid_attr, j, &uid_value)) {
dc8c34
+                    /* remove from uniquemember: remove from memberUid also */
dc8c34
+                    const char *uid = NULL;
dc8c34
                     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                    "modGroupMembership: add to dellist %s\n", uid);
dc8c34
-                    doModify = true;
dc8c34
+                                    "modGroupMembership: test dellist \n");
dc8c34
+                    uid = slapi_value_get_string(uid_value);
dc8c34
+                    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                    "modGroupMembership: test dellist %s\n", uid);
dc8c34
+                    if (uid_in_valueset(uid, smod_deluids)) {
dc8c34
+                        slapi_valueset_add_value(deluids, uid_value);
dc8c34
+                        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                        "modGroupMembership: add to dellist %s\n", uid);
dc8c34
+                    }
dc8c34
+                }
dc8c34
+            }
dc8c34
+            
dc8c34
+            if (posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
+                propogateDeletionsUpward(entry, base_sdn, smod_deluids, del_nested_vs, 0);
dc8c34
+                int i;
dc8c34
+                Slapi_Value *v;
dc8c34
+                for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
dc8c34
+                     i = slapi_valueset_next_value(del_nested_vs, i, &v)) {
dc8c34
+                    slapi_valueset_add_value(deluids, v);
dc8c34
                 }
dc8c34
             }
dc8c34
         } while (false);
dc8c34
@@ -331,93 +753,176 @@ modGroupMembership(Slapi_Entry *entry, Slapi_Mods *smods, int *do_modify)
dc8c34
 
dc8c34
         slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                         "modGroupMembership: posixGroup -> look for uniquemember\n");
dc8c34
-        /* found attribute uniquemember */
dc8c34
-        for (j = 0; smod_adduids[j]; j++) {
dc8c34
-            static char *uid = NULL;
dc8c34
 
dc8c34
-            uid_dn = smod_adduids[j];
dc8c34
-            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                            "modGroupMembership: perform user %s\n", uid_dn);
dc8c34
+        if (muid_rc == 0 && muid_attr == NULL) {
dc8c34
+            muid_rc = slapi_entry_attr_find(entry, "memberUid", &muid_attr);
dc8c34
+        }
dc8c34
+        if (muid_rc == 0 && muid_attr != NULL) {
dc8c34
+            slapi_attr_get_valueset(muid_attr, &muid_vs);
dc8c34
+        }
dc8c34
+        else {
dc8c34
+            muid_vs = slapi_valueset_new();
dc8c34
+        }
dc8c34
 
dc8c34
-            uid = searchUid(uid_dn);
dc8c34
+        if (posix_winsync_config_get_mapMemberUid()) {
dc8c34
+            for (j = 0; smod_adduids[j]; j++) {
dc8c34
+                static char *uid = NULL;
dc8c34
 
dc8c34
-            if (uid == NULL) {
dc8c34
+                uid_dn = smod_adduids[j];
dc8c34
                 slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                "modGroupMembership: uid not found for %s, cannot do anything\n",
dc8c34
-                                uid_dn); /* member on longer on server, do nothing */
dc8c34
-            } else {
dc8c34
-                rc |= slapi_entry_attr_find(entry, "memberUid", &muid_attr);
dc8c34
-                if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create  */
dc8c34
+                                "modGroupMembership: perform user %s\n", uid_dn);
dc8c34
+
dc8c34
+                uid = searchUid(uid_dn);
dc8c34
+
dc8c34
+                if (uid == NULL) {
dc8c34
                     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                                    "modGroupMembership: no attribute memberUid, add with %s \n",
dc8c34
-                                    uid_dn);
dc8c34
-                    slapi_ch_array_add(&adduids, uid);
dc8c34
-                    uid = NULL; /* adduids now owns uid */
dc8c34
-                    doModify = true;
dc8c34
-                } else { /* Found a memberUid list, so modify */
dc8c34
-                    Slapi_ValueSet *vs = NULL;
dc8c34
+                                    "modGroupMembership: uid not found for %s, cannot do anything\n",
dc8c34
+                                    uid_dn); /* member on longer on server, do nothing */
dc8c34
+                } else {
dc8c34
                     Slapi_Value *v = slapi_value_new();
dc8c34
-
dc8c34
                     slapi_value_init_string_passin(v, uid);
dc8c34
-                    slapi_attr_get_valueset(muid_attr, &vs);
dc8c34
-                    if (slapi_valueset_find(muid_attr, vs, v) != NULL) { /* already exist, all ok */
dc8c34
+
dc8c34
+                    if (muid_rc == 0 && muid_attr != NULL &&
dc8c34
+                        slapi_valueset_find(muid_attr, muid_vs, v) != NULL) {
dc8c34
+
dc8c34
                         slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                                         "modGroupMembership: uid found in memberuid list %s nothing to do\n",
dc8c34
                                         uid);
dc8c34
-                    } else {
dc8c34
-                        slapi_ch_array_add(&moduids, uid);
dc8c34
+                    }
dc8c34
+                    else {
dc8c34
+                        slapi_valueset_add_value(adduids, v);
dc8c34
+                        slapi_valueset_add_value(muid_vs, v);
dc8c34
                         slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                                         "modGroupMembership: add to modlist %s\n", uid);
dc8c34
-                        uid = NULL; /* adduids now owns uid */
dc8c34
-                        /* have to clear out v otherwise slapi_value_free will also free uid */
dc8c34
-                        slapi_value_init_berval(v, NULL);
dc8c34
-                        doModify = true;
dc8c34
                     }
dc8c34
+
dc8c34
                     slapi_value_free(&v); /* also frees uid since it was a passin */
dc8c34
-                    slapi_valueset_free(vs); vs = NULL;
dc8c34
                 }
dc8c34
             }
dc8c34
         }
dc8c34
+
dc8c34
+        if (posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
+
dc8c34
+            for (j = 0; smod_adduids[j]; ++j) {
dc8c34
+                char *attrs[] = { "uniqueMember", "memberUid", "uid", "objectClass", NULL };
dc8c34
+                Slapi_Entry *child = getEntry(smod_adduids[j], attrs);
dc8c34
+
dc8c34
+                if (child) {
dc8c34
+                    if (hasObjectClass(child, "ntGroup") || hasObjectClass(child, "posixGroup")) {
dc8c34
+                        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                        "modGroupMembership: Found mod to add group, adding membership: %s\n",
dc8c34
+                                        smod_adduids[j]);
dc8c34
+                        Slapi_ValueSet *muid_tempnested = slapi_valueset_new();
dc8c34
+                        getMembershipFromDownward(child, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
dc8c34
+
dc8c34
+                        slapi_valueset_free(muid_tempnested); muid_tempnested = NULL;
dc8c34
+                    }
dc8c34
+                }
dc8c34
+                else {
dc8c34
+                    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                    "modGroupMembership: entry not found for dn: %s\n",
dc8c34
+                                    smod_adduids[j]);
dc8c34
+                }
dc8c34
+            }
dc8c34
+
dc8c34
+            getMembershipFromDownward(entry, muid_vs, add_nested_vs, smod_deluids, base_sdn, 0);
dc8c34
+            int i = 0;
dc8c34
+            Slapi_Value *v = NULL;
dc8c34
+            for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
dc8c34
+                 i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
dc8c34
+                slapi_valueset_add_value(adduids, v);
dc8c34
+            }
dc8c34
+
dc8c34
+            propogateMembershipUpward(entry, adduids, 0);
dc8c34
+        }
dc8c34
     }
dc8c34
-    if (doModify) {
dc8c34
+    if (posixGroup) {
dc8c34
+        int addDynamicGroup = 0;
dc8c34
         int i;
dc8c34
-        for (i = 0; adduids && adduids[i]; i++) {
dc8c34
-            if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", adduids[i])) {
dc8c34
-                slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", adduids[i]);
dc8c34
+        Slapi_Value *v;
dc8c34
+        for (i = slapi_valueset_first_value(adduids, &v); i != -1;
dc8c34
+             i = slapi_valueset_next_value(adduids, i, &v)){
dc8c34
+            const char *muid = slapi_value_get_string(v);
dc8c34
+            if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", muid)) {
dc8c34
+                *do_modify = 1;
dc8c34
+                slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", muid);
dc8c34
+            }
dc8c34
+        }
dc8c34
+        for (i = slapi_valueset_first_value(add_nested_vs, &v); i != -1;
dc8c34
+             i = slapi_valueset_next_value(add_nested_vs, i, &v)) {
dc8c34
+            const char *muid = slapi_value_get_string(v);
dc8c34
+            if (!smods_has_mod(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid)) {
dc8c34
+                addDynamicGroup = 1;
dc8c34
+                *do_modify = 1;
dc8c34
+                slapi_mods_add_string(smods, LDAP_MOD_ADD, "dsOnlyMemberUid", muid);
dc8c34
             }
dc8c34
         }
dc8c34
-        for (i = 0; moduids && moduids[i]; i++) {
dc8c34
-            if (!smods_has_mod(smods, LDAP_MOD_ADD, "memberUid", moduids[i])) {
dc8c34
-                slapi_mods_add_string(smods, LDAP_MOD_ADD, "memberUid", moduids[i]);
dc8c34
+        for (i = slapi_valueset_first_value(deluids, &v); i != -1;
dc8c34
+             i = slapi_valueset_next_value(deluids, i, &v)){
dc8c34
+            const char *muid = slapi_value_get_string(v);
dc8c34
+            if (!smods_has_mod(smods, LDAP_MOD_DELETE, "memberUid", muid)) {
dc8c34
+                *do_modify = 1;
dc8c34
+                slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberUid", muid);
dc8c34
             }
dc8c34
         }
dc8c34
-        for (i = 0; deluids && deluids[i]; i++) {
dc8c34
-            if (!smods_has_mod(smods, LDAP_MOD_DELETE, "memberUid", deluids[i])) {
dc8c34
-                slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberUid", deluids[i]);
dc8c34
+        for (i = slapi_valueset_first_value(del_nested_vs, &v); i != -1;
dc8c34
+             i = slapi_valueset_next_value(del_nested_vs, i, &v)){
dc8c34
+            const char *muid = slapi_value_get_string(v);
dc8c34
+            if (!smods_has_mod(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid)) {
dc8c34
+                *do_modify = 1;
dc8c34
+                slapi_mods_add_string(smods, LDAP_MOD_DELETE, "dsOnlyMemberUid", muid);
dc8c34
             }
dc8c34
         }
dc8c34
+        if (addDynamicGroup) {
dc8c34
+            addDynamicGroupIfNecessary(entry, smods);
dc8c34
+        }
dc8c34
 
dc8c34
         if (slapi_is_loglevel_set(SLAPI_LOG_PLUGIN))
dc8c34
             slapi_mods_dump(smods, "memberUid - mods dump");
dc8c34
-        *do_modify = 1;
dc8c34
         posix_winsync_config_set_MOFTaskCreated();
dc8c34
     }
dc8c34
     slapi_ch_array_free(smod_adduids);
dc8c34
     smod_adduids = NULL;
dc8c34
-    slapi_ch_array_free(adduids);
dc8c34
-    adduids = NULL;
dc8c34
-    slapi_ch_array_free(smod_deluids);
dc8c34
+    if (smod_deluids) slapi_valueset_free(smod_deluids);
dc8c34
     smod_deluids = NULL;
dc8c34
-    slapi_ch_array_free(deluids);
dc8c34
+
dc8c34
+    slapi_valueset_free(adduids);
dc8c34
+    adduids = NULL;
dc8c34
+    slapi_valueset_free(deluids);
dc8c34
     deluids = NULL;
dc8c34
-    slapi_ch_array_free(moduids);
dc8c34
-    moduids = NULL;
dc8c34
+
dc8c34
+    slapi_valueset_free(add_nested_vs); add_nested_vs = NULL;
dc8c34
+    slapi_valueset_free(del_nested_vs); del_nested_vs = NULL;
dc8c34
+
dc8c34
+    if (muid_vs) {
dc8c34
+        slapi_valueset_free(muid_vs); muid_vs = NULL;
dc8c34
+    }
dc8c34
 
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "modGroupMembership: <==\n");
dc8c34
     return 0;
dc8c34
 }
dc8c34
 
dc8c34
 int
dc8c34
+addUserToGroupMembership(Slapi_Entry *entry)
dc8c34
+{
dc8c34
+    Slapi_Attr *uid_attr = NULL;
dc8c34
+    Slapi_Value *v = NULL;
dc8c34
+    Slapi_ValueSet *muid_vs = slapi_valueset_new();
dc8c34
+
dc8c34
+    if (slapi_entry_attr_find(entry, "uid", &uid_attr) == 0) {
dc8c34
+        slapi_attr_first_value(uid_attr, &v);
dc8c34
+
dc8c34
+        if (v) {
dc8c34
+            slapi_valueset_add_value(muid_vs, v);
dc8c34
+        }
dc8c34
+    }
dc8c34
+
dc8c34
+    propogateMembershipUpward(entry, muid_vs, 0);
dc8c34
+
dc8c34
+    slapi_valueset_free(muid_vs); muid_vs = NULL;
dc8c34
+}
dc8c34
+
dc8c34
+int
dc8c34
 addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry)
dc8c34
 {
dc8c34
     int rc = 0;
dc8c34
@@ -425,7 +930,11 @@ addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry)
dc8c34
 
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: ==>\n");
dc8c34
 
dc8c34
-    if(!isPosixGroup(entry)) {
dc8c34
+    int posixGroup = hasObjectClass(entry, "posixGroup");
dc8c34
+
dc8c34
+    if(!(posixGroup || hasObjectClass(entry, "ntGroup"))) {
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "addGroupMembership: didn't find posixGroup or ntGroup objectclass\n");
dc8c34
         return 0;
dc8c34
     }
dc8c34
 
dc8c34
@@ -448,34 +957,55 @@ addGroupMembership(Slapi_Entry *entry, Slapi_Entry *ad_entry)
dc8c34
     if (rc != 0 || muid_attr == NULL) { /* Found no memberUid list, so create  */
dc8c34
         slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                         "addGroupMembership: no attribute memberUid\n");
dc8c34
+        muid_attr = NULL;
dc8c34
     }
dc8c34
     newvs = slapi_valueset_new();
dc8c34
     /* ...loop for value...    */
dc8c34
-    for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
dc8c34
-         i = slapi_attr_next_value(um_attr, i, &uid_value)) {
dc8c34
-        const char *uid_dn = NULL;
dc8c34
-        static char *uid = NULL;
dc8c34
-        Slapi_Value *v = NULL;
dc8c34
+    if (posix_winsync_config_get_mapMemberUid()) {
dc8c34
+        for (i = slapi_attr_first_value(um_attr, &uid_value); i != -1;
dc8c34
+             i = slapi_attr_next_value(um_attr, i, &uid_value)) {
dc8c34
+            const char *uid_dn = NULL;
dc8c34
+            static char *uid = NULL;
dc8c34
+            Slapi_Value *v = NULL;
dc8c34
 
dc8c34
-        uid_dn = slapi_value_get_string(uid_value);
dc8c34
-        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                        "addGroupMembership: perform member %s\n", uid_dn);
dc8c34
-        uid = searchUid(uid_dn);
dc8c34
-        if (uid == NULL) {
dc8c34
+            uid_dn = slapi_value_get_string(uid_value);
dc8c34
             slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
-                            "addGroupMembership: uid not found for %s, cannot do anything\n",
dc8c34
-                            uid_dn); /* member on longer on server, do nothing */
dc8c34
-        } else {
dc8c34
-            v = slapi_value_new_string(uid);
dc8c34
-            slapi_ch_free_string(&uid);
dc8c34
-            if (slapi_attr_value_find(muid_attr, slapi_value_get_berval(v)) != 0) {
dc8c34
-                slapi_valueset_add_value(newvs, v);
dc8c34
+                            "addGroupMembership: perform member %s\n", uid_dn);
dc8c34
+            uid = searchUid(uid_dn);
dc8c34
+            if (uid == NULL) {
dc8c34
+                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                "addGroupMembership: uid not found for %s, cannot do anything\n",
dc8c34
+                                uid_dn); /* member on longer on server, do nothing */
dc8c34
+            } else {
dc8c34
+                v = slapi_value_new_string(uid);
dc8c34
+                slapi_ch_free_string(&uid);
dc8c34
+                if (slapi_attr_value_find(muid_attr, slapi_value_get_berval(v)) != 0) {
dc8c34
+                    slapi_valueset_add_value(newvs, v);
dc8c34
+                }
dc8c34
+                slapi_value_free(&v);
dc8c34
             }
dc8c34
-            slapi_value_free(&v);
dc8c34
         }
dc8c34
     }
dc8c34
-    slapi_entry_add_valueset(entry, "memberUid", newvs);
dc8c34
-    slapi_valueset_free(newvs);
dc8c34
+
dc8c34
+    if (posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
+        Slapi_ValueSet *muid_nested_vs = slapi_valueset_new();
dc8c34
+
dc8c34
+        getMembershipFromDownward(entry, newvs, muid_nested_vs, NULL, NULL, 0);
dc8c34
+        propogateMembershipUpward(entry, newvs, 0);
dc8c34
+
dc8c34
+        if (posixGroup) {
dc8c34
+            addDynamicGroupIfNecessary(entry, NULL);
dc8c34
+            slapi_entry_add_valueset(entry, "dsOnlyMemberUid", muid_nested_vs);
dc8c34
+        }
dc8c34
+
dc8c34
+        slapi_valueset_free(muid_nested_vs); muid_nested_vs = NULL;   
dc8c34
+    }
dc8c34
+
dc8c34
+    if (posixGroup) {
dc8c34
+        slapi_entry_add_valueset(entry, "memberUid", newvs);
dc8c34
+    }
dc8c34
+
dc8c34
+    slapi_valueset_free(newvs); newvs = NULL;
dc8c34
     posix_winsync_config_get_MOFTaskCreated();
dc8c34
 
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "addGroupMembership: <==\n");
dc8c34
diff --git a/ldap/servers/plugins/posix-winsync/posix-group-task.c b/ldap/servers/plugins/posix-winsync/posix-group-task.c
dc8c34
index e31064c..4555f1b 100644
dc8c34
--- a/ldap/servers/plugins/posix-winsync/posix-group-task.c
dc8c34
+++ b/ldap/servers/plugins/posix-winsync/posix-group-task.c
dc8c34
@@ -25,11 +25,17 @@ typedef struct _cb_data
dc8c34
  } posix_group_data_data;
dc8c34
  */
dc8c34
 
dc8c34
+Slapi_Value **
dc8c34
+valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
dc8c34
+
dc8c34
 /* interface function */
dc8c34
 int
dc8c34
 posix_group_task_add(Slapi_PBlock *pb, Slapi_Entry *e, Slapi_Entry *eAfter, int *returncode,
dc8c34
     char *returntext, void *arg);
dc8c34
 
dc8c34
+Slapi_Entry *
dc8c34
+getEntry(const char *udn, char **attrs);
dc8c34
+
dc8c34
 static void
dc8c34
 posix_group_task_destructor(Slapi_Task *task);
dc8c34
 static void
dc8c34
@@ -67,6 +73,10 @@ posix_group_task_add(Slapi_PBlock *pb, Slapi_Entry *e, Slapi_Entry *eAfter, int
dc8c34
 
dc8c34
     *returncode = LDAP_SUCCESS;
dc8c34
 
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: ==>\n");
dc8c34
+
dc8c34
     /* get arg(s) */
dc8c34
     /* default: set replication basedn */
dc8c34
     if ((dn = fetch_attr(e, "basedn", slapi_sdn_get_dn(posix_winsync_config_get_suffix()))) == NULL) {
dc8c34
@@ -75,12 +85,18 @@ posix_group_task_add(Slapi_PBlock *pb, Slapi_Entry *e, Slapi_Entry *eAfter, int
dc8c34
         goto out;
dc8c34
     }
dc8c34
 
dc8c34
-    if ((filter = fetch_attr(e, "filter", "(&(objectclass=posixGroup)(uniquemember=*))")) == NULL) {
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: retrieved basedn: %s\n", dn);
dc8c34
+
dc8c34
+    if ((filter = fetch_attr(e, "filter", "(objectclass=ntGroup)")) == NULL) {
dc8c34
         *returncode = LDAP_OBJECT_CLASS_VIOLATION;
dc8c34
         rv = SLAPI_DSE_CALLBACK_ERROR;
dc8c34
         goto out;
dc8c34
     }
dc8c34
 
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: retrieved filter: %s\n", filter);
dc8c34
+
dc8c34
     /* setup our task data */
dc8c34
     mytaskdata = (task_data*) slapi_ch_malloc(sizeof(task_data));
dc8c34
     if (mytaskdata == NULL) {
dc8c34
@@ -91,19 +107,41 @@ posix_group_task_add(Slapi_PBlock *pb, Slapi_Entry *e, Slapi_Entry *eAfter, int
dc8c34
     mytaskdata->dn = slapi_ch_strdup(dn);
dc8c34
     mytaskdata->filter_str = slapi_ch_strdup(filter);
dc8c34
 
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: task data allocated\n");
dc8c34
+
dc8c34
     /* allocate new task now */
dc8c34
-    task = slapi_new_task(slapi_entry_get_ndn(e));
dc8c34
+    char * ndn = slapi_entry_get_ndn(e);
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: creating task object: %s\n",
dc8c34
+                    ndn);
dc8c34
+
dc8c34
+    task = slapi_new_task(ndn);
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: task object created\n");
dc8c34
 
dc8c34
     /* register our destructor for cleaning up our private data */
dc8c34
     slapi_task_set_destructor_fn(task, posix_group_task_destructor);
dc8c34
 
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: task destructor set\n");
dc8c34
+
dc8c34
     /* Stash a pointer to our data in the task */
dc8c34
     slapi_task_set_data(task, mytaskdata);
dc8c34
 
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: task object initialized\n");
dc8c34
+
dc8c34
     /* start the sample task as a separate thread */
dc8c34
     thread = PR_CreateThread(PR_USER_THREAD, posix_group_fixup_task_thread, (void *) task,
dc8c34
                              PR_PRIORITY_NORMAL, PR_GLOBAL_THREAD, PR_UNJOINABLE_THREAD,
dc8c34
                              SLAPD_DEFAULT_THREAD_STACKSIZE);
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: thread created\n");
dc8c34
+
dc8c34
     if (thread == NULL) {
dc8c34
         slapi_log_error(SLAPI_LOG_FATAL, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                         "unable to create task thread!\n");
dc8c34
@@ -114,7 +152,11 @@ posix_group_task_add(Slapi_PBlock *pb, Slapi_Entry *e, Slapi_Entry *eAfter, int
dc8c34
         rv = SLAPI_DSE_CALLBACK_OK;
dc8c34
     }
dc8c34
 
dc8c34
-    out: return rv;
dc8c34
+    out: 
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "posix_group_task_add: <==\n", filter);
dc8c34
+
dc8c34
+    return rv;
dc8c34
 }
dc8c34
 
dc8c34
 static void
dc8c34
@@ -195,86 +237,172 @@ posix_group_fix_memberuid(char *dn, char *filter_str, void *txn)
dc8c34
 static int
dc8c34
 posix_group_fix_memberuid_callback(Slapi_Entry *e, void *callback_data)
dc8c34
 {
dc8c34
-    int rc = 0;
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "_fix_memberuid ==>\n");
dc8c34
+    cb_data *the_cb_data = (cb_data *) callback_data;
dc8c34
+
dc8c34
+    int rc;
dc8c34
+    Slapi_Attr *muid_attr = NULL;
dc8c34
+    Slapi_Value *v = NULL;
dc8c34
+
dc8c34
+    Slapi_Mods *smods = slapi_mods_new();
dc8c34
+
dc8c34
     char *dn = slapi_entry_get_dn(e);
dc8c34
     Slapi_DN *sdn = slapi_entry_get_sdn(e);
dc8c34
 
dc8c34
-    Slapi_Attr *obj_attr = NULL;
dc8c34
+/* Clean out memberuids and dsonlymemberuids without a valid referant */
dc8c34
+    rc = slapi_entry_attr_find(e, "memberuid", &muid_attr);
dc8c34
+    if (rc == 0 && muid_attr) {
dc8c34
+        Slapi_PBlock *search_pb = slapi_pblock_new();
dc8c34
+
dc8c34
+        Slapi_Attr *dsmuid_attr = NULL;
dc8c34
+        Slapi_ValueSet *dsmuid_vs = NULL;
dc8c34
+
dc8c34
+        char *attrs[] = { "uid", NULL };
dc8c34
+
dc8c34
+        rc = slapi_entry_attr_find(e, "dsonlymemberuid", &dsmuid_attr);
dc8c34
+        if (rc == 0 && dsmuid_attr) {
dc8c34
+            slapi_attr_get_valueset(dsmuid_attr, &dsmuid_vs);
dc8c34
+        }
dc8c34
+
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "_fix_memberuid scan for orphaned memberuids\n");
dc8c34
+
dc8c34
+        int i;
dc8c34
+        for (i = slapi_attr_first_value(muid_attr, &v); i != -1;
dc8c34
+             i = slapi_attr_next_value(muid_attr, i, &v)) {
dc8c34
+            const char *muid = slapi_value_get_string(v);
dc8c34
+
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "_fix_memberuid iterating memberuid: %s\n",
dc8c34
+                            muid);
dc8c34
+
dc8c34
+            size_t vallen = muid ? strlen(muid) : 0;
dc8c34
+            char *filter_escaped_value = slapi_ch_calloc(sizeof(char), vallen*3+1);
dc8c34
+            char *filter = slapi_ch_smprintf("(uid=%s)", escape_filter_value(muid, vallen, filter_escaped_value));
dc8c34
+            slapi_ch_free_string(&filter_escaped_value);
dc8c34
+
dc8c34
+            Slapi_Entry **search_entries = NULL;
dc8c34
+
dc8c34
+            slapi_search_internal_set_pb(search_pb,
dc8c34
+                                         the_cb_data->dn,
dc8c34
+                                         LDAP_SCOPE_SUBTREE,
dc8c34
+                                         filter,
dc8c34
+                                         attrs, 0, NULL, NULL,
dc8c34
+                                         posix_winsync_get_plugin_identity(), 0);
dc8c34
+
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "_fix_memberuid searching %s with filter: %s\n",
dc8c34
+                            the_cb_data->dn, filter);
dc8c34
 
dc8c34
+            rc = slapi_search_internal_pb(search_pb);
dc8c34
+
dc8c34
+            slapi_pblock_get(search_pb, SLAPI_PLUGIN_INTOP_SEARCH_ENTRIES, &search_entries);
dc8c34
+
dc8c34
+            if (!search_entries || !search_entries[0]) {
dc8c34
+                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                "_fix_memberuid Adding bad memberuid %s\n",
dc8c34
+                                slapi_value_get_string(v));
dc8c34
+
dc8c34
+                slapi_mods_add_string(smods, LDAP_MOD_DELETE, "memberuid", slapi_value_get_string(v));
dc8c34
+
dc8c34
+                if (dsmuid_vs && slapi_valueset_find(dsmuid_attr, dsmuid_vs, v)) {
dc8c34
+                    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                    "_fix_memberuid Adding bad dsonlymemberuid %s\n",
dc8c34
+                                    slapi_value_get_string(v));
dc8c34
+
dc8c34
+                    slapi_mods_add_string(smods, LDAP_MOD_DELETE, "dsonlymemberuid", slapi_value_get_string(v));
dc8c34
+                }
dc8c34
+            }
dc8c34
+
dc8c34
+            slapi_free_search_results_internal(search_pb);
dc8c34
+            slapi_pblock_init(search_pb);
dc8c34
+            slapi_ch_free_string(&filter);
dc8c34
+        }
dc8c34
+
dc8c34
+        if (dsmuid_vs) {
dc8c34
+            slapi_valueset_free(dsmuid_vs); dsmuid_vs = NULL;
dc8c34
+        }
dc8c34
+
dc8c34
+        slapi_pblock_destroy(search_pb); search_pb = NULL;
dc8c34
+    }
dc8c34
+
dc8c34
+    /* Cleanup uniquemembers without a referent, and verify memberuid otherwise */
dc8c34
+    Slapi_Attr *obj_attr = NULL;
dc8c34
     rc = slapi_entry_attr_find(e, "uniquemember", &obj_attr);
dc8c34
-    if (rc == 0) { /* Found uniquemember, so...  */
dc8c34
+    if (rc == 0 && obj_attr) {
dc8c34
+        int fixMembership = 0;
dc8c34
+        Slapi_ValueSet *bad_ums = NULL;
dc8c34
+
dc8c34
         int i;
dc8c34
-        Slapi_Value * value = slapi_value_new(); /* new memberuid Attribute values        */
dc8c34
-        Slapi_Value * uniqval = NULL; /* uniquemeber Attribute values        */
dc8c34
-        Slapi_ValueSet *uids = slapi_valueset_new();
dc8c34
+        Slapi_Value * uniqval = NULL;            /* uniquemeber Attribute values          */
dc8c34
 
dc8c34
         slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
                         "_fix_memberuid scan uniquemember, group %s\n", dn);
dc8c34
         for (i = slapi_attr_first_value(obj_attr, &uniqval); i != -1;
dc8c34
              i = slapi_attr_next_value(obj_attr, i, &uniqval)) {
dc8c34
-            const char *member = NULL;
dc8c34
-            char * uid = NULL;
dc8c34
-            member = slapi_value_get_string(uniqval);
dc8c34
-            /* search uid for member (DN) */
dc8c34
-            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME, "search %s\n", member);
dc8c34
-            if ((uid = searchUid(member)) != NULL) {
dc8c34
-                slapi_value_set_string(value, uid);
dc8c34
-                /* add uids ValueSet */
dc8c34
-                slapi_valueset_add_value(uids, value);
dc8c34
+
dc8c34
+            const char *member = slapi_value_get_string(uniqval);
dc8c34
+            char *attrs[] = { "uid", "objectclass", NULL };
dc8c34
+            Slapi_Entry *child = getEntry(member, attrs);
dc8c34
+
dc8c34
+            if (!child) {
dc8c34
+                slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                                "_fix_memberuid orphaned uniquemember found: %s\n", member);
dc8c34
+
dc8c34
+                if (strncasecmp(member, "cn=", 3) == 0) {
dc8c34
+                    fixMembership = 1;
dc8c34
+                }
dc8c34
+                if (!bad_ums) {
dc8c34
+                    bad_ums = slapi_valueset_new();
dc8c34
+                }
dc8c34
+                slapi_valueset_add_value(bad_ums, uniqval);
dc8c34
             }
dc8c34
         }
dc8c34
-        slapi_value_free(&value);
dc8c34
-
dc8c34
-        /* If we found some posix members, replace the existing memberuid attribute
dc8c34
-         * with the found values.  */
dc8c34
-        if (uids && slapi_valueset_count(uids)) {
dc8c34
-            Slapi_PBlock *mod_pb = slapi_pblock_new();
dc8c34
-            Slapi_Value *val = 0;
dc8c34
-            Slapi_Mod *smod;
dc8c34
-            LDAPMod **mods = (LDAPMod **) slapi_ch_malloc(2 * sizeof(LDAPMod *));
dc8c34
-            int hint = 0;
dc8c34
-            cb_data *the_cb_data = (cb_data *) callback_data;
dc8c34
-
dc8c34
-            smod = slapi_mod_new();
dc8c34
-            slapi_mod_init(smod, 0);
dc8c34
-            slapi_mod_set_operation(smod, LDAP_MOD_REPLACE | LDAP_MOD_BVALUES);
dc8c34
-            slapi_mod_set_type(smod, "memberuid");
dc8c34
-
dc8c34
-            /* Loop through all of our values and add them to smod */
dc8c34
-            hint = slapi_valueset_first_value(uids, &val;;
dc8c34
-            while (val) {
dc8c34
-                /* this makes a copy of the berval */
dc8c34
-                slapi_mod_add_value(smod, slapi_value_get_berval(val));
dc8c34
-                hint = slapi_valueset_next_value(uids, hint, &val;;
dc8c34
-            }
dc8c34
 
dc8c34
-            mods[0] = slapi_mod_get_ldapmod_passout(smod);
dc8c34
-            mods[1] = 0;
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "_fix_memberuid Finishing...\n");
dc8c34
 
dc8c34
-            slapi_modify_internal_set_pb_ext(mod_pb, sdn, mods, 0, 0,
dc8c34
-                                             posix_winsync_get_plugin_identity(), 0);
dc8c34
+        if (fixMembership  && posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
+            Slapi_ValueSet *del_nested_vs = slapi_valueset_new();
dc8c34
 
dc8c34
-            slapi_pblock_set(mod_pb, SLAPI_TXN, the_cb_data->txn);
dc8c34
-            slapi_modify_internal_pb(mod_pb);
dc8c34
+            slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                            "_fix_memberuid group deleted, recalculating nesting\n");
dc8c34
+            propogateDeletionsUpward(e, sdn, bad_ums, del_nested_vs, 0);
dc8c34
 
dc8c34
-            slapi_pblock_get(mod_pb, SLAPI_PLUGIN_INTOP_RESULT, &rc);
dc8c34
+            slapi_valueset_free(del_nested_vs); del_nested_vs = NULL;
dc8c34
+        }
dc8c34
 
dc8c34
-            ldap_mods_free(mods, 1);
dc8c34
-            slapi_mod_free(&smod);
dc8c34
-            slapi_pblock_destroy(mod_pb);
dc8c34
-        } else {
dc8c34
-            /* No member were found, so remove the memberuid attribute
dc8c34
-             * from this entry. */
dc8c34
-            posix_group_del_memberuid_callback(e, callback_data);
dc8c34
+        if (bad_ums) {
dc8c34
+            slapi_mods_add_mod_values(smods, LDAP_MOD_DELETE, "uniquemember", valueset_get_valuearray(bad_ums));
dc8c34
+            slapi_valueset_free(bad_ums); bad_ums = NULL;
dc8c34
         }
dc8c34
-        slapi_valueset_free(uids);
dc8c34
     }
dc8c34
+
dc8c34
+    Slapi_PBlock *mod_pb = slapi_pblock_new();
dc8c34
+
dc8c34
+    slapi_modify_internal_set_pb_ext(mod_pb, sdn, slapi_mods_get_ldapmods_passout(smods), 0, 0,
dc8c34
+                                     posix_winsync_get_plugin_identity(), 0);
dc8c34
+
dc8c34
+    slapi_pblock_set(mod_pb, SLAPI_TXN, the_cb_data->txn);
dc8c34
+    slapi_modify_internal_pb(mod_pb);
dc8c34
+
dc8c34
+    slapi_pblock_get(mod_pb, SLAPI_PLUGIN_INTOP_RESULT, &rc);
dc8c34
+    slapi_pblock_destroy(mod_pb);
dc8c34
+
dc8c34
+    slapi_mods_free(&smods);
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "_fix_memberuid <==\n");
dc8c34
     return rc;
dc8c34
 }
dc8c34
 
dc8c34
 static void
dc8c34
 posix_group_fixup_task_thread(void *arg)
dc8c34
 {
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "_task_thread ==>\n");
dc8c34
+
dc8c34
     Slapi_Task *task = (Slapi_Task *) arg;
dc8c34
     task_data *td = NULL;
dc8c34
     int rc = 0;
dc8c34
@@ -293,11 +421,18 @@ posix_group_fixup_task_thread(void *arg)
dc8c34
 
dc8c34
     /* release the memberOf operation lock */
dc8c34
     memberUidUnlock();
dc8c34
+    
dc8c34
 
dc8c34
     slapi_task_log_notice(task, "posix_group task finished.");
dc8c34
     slapi_task_log_status(task, "posix_group task finished.");
dc8c34
     slapi_task_inc_progress(task);
dc8c34
 
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "_task_thread finishing\n");
dc8c34
+
dc8c34
     /* this will queue the destruction of the task */
dc8c34
     slapi_task_finish(task, rc);
dc8c34
+
dc8c34
+    slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                    "_task_thread <==\n");
dc8c34
 }
dc8c34
diff --git a/ldap/servers/plugins/posix-winsync/posix-winsync-config.c b/ldap/servers/plugins/posix-winsync/posix-winsync-config.c
dc8c34
index a2d21be..a7fd6e9 100644
dc8c34
--- a/ldap/servers/plugins/posix-winsync/posix-winsync-config.c
dc8c34
+++ b/ldap/servers/plugins/posix-winsync/posix-winsync-config.c
dc8c34
@@ -142,6 +142,12 @@ posix_winsync_config_get_msSFUSchema()
dc8c34
     return theConfig.mssfuSchema;
dc8c34
 }
dc8c34
 
dc8c34
+PRBool
dc8c34
+posix_winsync_config_get_mapNestedGrouping()
dc8c34
+{
dc8c34
+    return theConfig.mapNestedGrouping;
dc8c34
+}
dc8c34
+
dc8c34
 Slapi_DN *
dc8c34
 posix_winsync_config_get_suffix()
dc8c34
 {
dc8c34
@@ -182,6 +188,7 @@ posix_winsync_config(Slapi_Entry *config_e)
dc8c34
     theConfig.lowercase = PR_FALSE;
dc8c34
     theConfig.createMemberOfTask = PR_FALSE;
dc8c34
     theConfig.MOFTaskCreated = PR_FALSE;
dc8c34
+    theConfig.mapNestedGrouping = PR_FALSE;
dc8c34
 
dc8c34
     posix_winsync_apply_config(NULL, NULL, config_e, &returncode, returntext, NULL);
dc8c34
     /* config DSE must be initialized before we get here */
dc8c34
@@ -224,6 +231,7 @@ posix_winsync_apply_config(Slapi_PBlock *pb, Slapi_Entry* entryBefore, Slapi_Ent
dc8c34
     PRBool createMemberOfTask = PR_FALSE;
dc8c34
     PRBool lowercase = PR_FALSE;
dc8c34
     Slapi_Attr *testattr = NULL;
dc8c34
+    PRBool mapNestedGrouping = PR_FALSE;
dc8c34
 
dc8c34
     *returncode = LDAP_UNWILLING_TO_PERFORM; /* be pessimistic */
dc8c34
 
dc8c34
@@ -257,6 +265,13 @@ posix_winsync_apply_config(Slapi_PBlock *pb, Slapi_Entry* entryBefore, Slapi_Ent
dc8c34
                         "_apply_config: Config paramter %s: %d\n", POSIX_WINSYNC_LOWER_CASE,
dc8c34
                         lowercase);
dc8c34
     }
dc8c34
+    /* propogate memberuids in nested grouping */
dc8c34
+    if (!slapi_entry_attr_find(e, POSIX_WINSYNC_MAP_NESTED_GROUPING, &testattr) && (NULL != testattr)) {
dc8c34
+        mapNestedGrouping = slapi_entry_attr_get_bool(e, POSIX_WINSYNC_MAP_NESTED_GROUPING);
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
+                        "_apply_config: Config paramter %s: %d\n", POSIX_WINSYNC_MAP_NESTED_GROUPING,
dc8c34
+                        mapNestedGrouping);
dc8c34
+    }
dc8c34
     /* if we got here, we have valid values for everything
dc8c34
      set the config entry */
dc8c34
     slapi_lock_mutex(theConfig.lock);
dc8c34
@@ -269,6 +284,7 @@ posix_winsync_apply_config(Slapi_PBlock *pb, Slapi_Entry* entryBefore, Slapi_Ent
dc8c34
     theConfig.mapMemberUID = mapMemberUID;
dc8c34
     theConfig.createMemberOfTask = createMemberOfTask;
dc8c34
     theConfig.lowercase = lowercase;
dc8c34
+    theConfig.mapNestedGrouping = mapNestedGrouping;
dc8c34
 
dc8c34
     /* success */
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, POSIX_WINSYNC_PLUGIN_NAME,
dc8c34
diff --git a/ldap/servers/plugins/posix-winsync/posix-winsync.c b/ldap/servers/plugins/posix-winsync/posix-winsync.c
dc8c34
index 398541d..aa292c3 100644
dc8c34
--- a/ldap/servers/plugins/posix-winsync/posix-winsync.c
dc8c34
+++ b/ldap/servers/plugins/posix-winsync/posix-winsync.c
dc8c34
@@ -68,7 +68,7 @@
dc8c34
 #include "posix-wsp-ident.h"
dc8c34
 #include "posix-group-func.h"
dc8c34
 
dc8c34
-#define MEMBEROFTASK "memberof task"
dc8c34
+#define MEMBEROFTASK "memberuid task"
dc8c34
 Slapi_Value **
dc8c34
 valueset_get_valuearray(const Slapi_ValueSet *vs); /* stolen from proto-slap.h */
dc8c34
 void *
dc8c34
@@ -103,6 +103,7 @@ static windows_attribute_map user_mssfu_attribute_map[] =
dc8c34
       { "msSFU30gecos", "gecos" },
dc8c34
       { NULL, NULL } };
dc8c34
 
dc8c34
+/* memberUid must be first element or fixup in pre_ad_mod/add_group is required */
dc8c34
 static windows_attribute_map group_attribute_map[] = { { "memberUid", "memberUid" },
dc8c34
                                                        { "gidNumber", "gidNumber" },
dc8c34
                                                        { NULL, NULL } };
dc8c34
@@ -661,7 +662,34 @@ posix_winsync_pre_ad_mod_group_cb(void *cbdata, const Slapi_Entry *rawentry, Sla
dc8c34
                 char *ad_type = NULL;
dc8c34
                 int is_present_local;
dc8c34
 
dc8c34
-                slapi_attr_get_valueset(attr, &vs);
dc8c34
+                if (i == 0) { /* memberUid */
dc8c34
+                    Slapi_Attr *dsmuid_attr = NULL;
dc8c34
+                    Slapi_Value *v = NULL;
dc8c34
+                    slapi_entry_attr_find(ds_entry, "dsonlymemberuid", &dsmuid_attr);
dc8c34
+
dc8c34
+                    if (dsmuid_attr) {
dc8c34
+                        Slapi_ValueSet *dsmuid_vs = NULL;
dc8c34
+                        slapi_attr_get_valueset(dsmuid_attr, &dsmuid_vs);
dc8c34
+                        if (dsmuid_vs) {
dc8c34
+                            vs = slapi_valueset_new();
dc8c34
+
dc8c34
+                            int j;
dc8c34
+                            for (j = slapi_attr_first_value(attr, &v); j != -1;
dc8c34
+                                 j = slapi_attr_next_value(attr, i, &v)) {
dc8c34
+                                if (!slapi_valueset_find(dsmuid_attr, dsmuid_vs, v)) {
dc8c34
+                                    slapi_valueset_add_value(vs, v);
dc8c34
+                                }
dc8c34
+                            }
dc8c34
+
dc8c34
+                            slapi_valueset_free(dsmuid_vs); dsmuid_vs = NULL;
dc8c34
+                        }
dc8c34
+                    }
dc8c34
+                }
dc8c34
+
dc8c34
+                if (!vs) {
dc8c34
+                    slapi_attr_get_valueset(attr, &vs);
dc8c34
+                }
dc8c34
+
dc8c34
                 ad_type = slapi_ch_strdup(attr_map[i].windows_attribute_name);
dc8c34
                 slapi_entry_attr_find(ad_entry, ad_type, &ad_attr);
dc8c34
                 is_present_local = (NULL == ad_attr) ? 0 : 1;
dc8c34
@@ -810,6 +838,12 @@ posix_winsync_pre_ds_mod_user_cb(void *cbdata, const Slapi_Entry *rawentry, Slap
dc8c34
                                           valueset_get_valuearray(oc_vs));
dc8c34
                 slapi_value_free(&oc_nv);
dc8c34
                 slapi_valueset_free(oc_vs);
dc8c34
+
dc8c34
+                if (posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
+                    memberUidLock();
dc8c34
+                    addUserToGroupMembership(ds_entry);
dc8c34
+                    memberUidUnlock();
dc8c34
+                }
dc8c34
             }
dc8c34
         }
dc8c34
         slapi_value_free(&voc;;
dc8c34
@@ -897,7 +931,7 @@ posix_winsync_pre_ds_mod_group_cb(void *cbdata, const Slapi_Entry *rawentry, Sla
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name,
dc8c34
                     "_pre_ds_mod_group_cb present %d modify %d before\n", is_present_local,
dc8c34
                     do_modify_local);
dc8c34
-    if (posix_winsync_config_get_mapMemberUid()) {
dc8c34
+    if (posix_winsync_config_get_mapMemberUid() || posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
         memberUidLock();
dc8c34
         modGroupMembership(ds_entry, smods, do_modify);
dc8c34
         memberUidUnlock();
dc8c34
@@ -999,6 +1033,13 @@ posix_winsync_pre_ds_add_user_cb(void *cbdata, const Slapi_Entry *rawentry, Slap
dc8c34
             slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name,
dc8c34
                             "<-- _pre_ds_add_user_cb -- adding objectclass for new entry failed %d\n",
dc8c34
                             rc);
dc8c34
+        else {
dc8c34
+            if (posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
+                memberUidLock();
dc8c34
+                addUserToGroupMembership(ds_entry);
dc8c34
+                memberUidUnlock();
dc8c34
+            }
dc8c34
+        }
dc8c34
     }
dc8c34
     sync_acct_disable(cbdata, rawentry, ds_entry, ACCT_DISABLE_TO_DS, ds_entry, NULL, NULL);
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name, "<-- _pre_ds_add_user_cb -- end\n");
dc8c34
@@ -1054,14 +1095,14 @@ posix_winsync_pre_ds_add_group_cb(void *cbdata, const Slapi_Entry *rawentry, Sla
dc8c34
             slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name,
dc8c34
                             "<-- _pre_ds_add_group_cb -- adding objectclass for new entry failed %d\n",
dc8c34
                             rc);
dc8c34
-        } else {
dc8c34
-            if (posix_winsync_config_get_mapMemberUid()) {
dc8c34
-                memberUidLock();
dc8c34
-                addGroupMembership(ds_entry, ad_entry);
dc8c34
-                memberUidUnlock();
dc8c34
-            }
dc8c34
         }
dc8c34
     }
dc8c34
+    if (posix_winsync_config_get_mapMemberUid() || posix_winsync_config_get_mapNestedGrouping()) {
dc8c34
+        memberUidLock();
dc8c34
+        addGroupMembership(ds_entry, ad_entry);
dc8c34
+        memberUidUnlock();
dc8c34
+    }
dc8c34
+
dc8c34
     slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name,
dc8c34
                     "<-- posix_winsync_pre_ds_add_group_cb -- end\n");
dc8c34
 
dc8c34
@@ -1274,7 +1315,7 @@ posix_winsync_end_update_cb(void *cbdata, const Slapi_DN *ds_subtree, const Slap
dc8c34
                     "--> posix_winsync_end_update_cb -- begin %d %d\n",
dc8c34
                     posix_winsync_config_get_MOFTaskCreated(),
dc8c34
                     posix_winsync_config_get_createMOFTask());
dc8c34
-    if (posix_winsync_config_get_MOFTaskCreated() && posix_winsync_config_get_createMOFTask()) {
dc8c34
+    if (1 && posix_winsync_config_get_createMOFTask()) {
dc8c34
         /* add a task to schedule memberof Plugin for fix memebrof attributs */
dc8c34
         Slapi_PBlock *pb = slapi_pblock_new();
dc8c34
         Slapi_Entry *e_task = slapi_entry_alloc();
dc8c34
@@ -1291,13 +1332,24 @@ posix_winsync_end_update_cb(void *cbdata, const Slapi_DN *ds_subtree, const Slap
dc8c34
                             posix_winsync_plugin_name, MEMBEROFTASK);
dc8c34
             return;
dc8c34
         }
dc8c34
+
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name,
dc8c34
+                        "--> posix_winsync_end_update_cb, init'ing task\n");
dc8c34
+
dc8c34
         slapi_entry_init(e_task, slapi_ch_strdup(dn), NULL);
dc8c34
         slapi_entry_add_string(e_task, "cn", slapi_ch_strdup(posix_winsync_plugin_name));
dc8c34
         slapi_entry_add_string(e_task, "objectClass", "extensibleObject");
dc8c34
         slapi_entry_add_string(e_task, "basedn", slapi_sdn_get_dn(ds_subtree));
dc8c34
 
dc8c34
         slapi_add_entry_internal_set_pb(pb, e_task, NULL, posix_winsync_get_plugin_identity(), 0);
dc8c34
+
dc8c34
+
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name,
dc8c34
+                        "--> posix_winsync_end_update_cb, adding task\n");
dc8c34
         slapi_add_internal_pb(pb);
dc8c34
+
dc8c34
+        slapi_log_error(SLAPI_LOG_PLUGIN, posix_winsync_plugin_name,
dc8c34
+                        "--> posix_winsync_end_update_cb, retrieving return code\n");
dc8c34
         slapi_pblock_get(pb, SLAPI_PLUGIN_INTOP_RESULT, &rc);
dc8c34
         if (rc != 0) {
dc8c34
             slapi_log_error(SLAPI_LOG_FATAL, posix_winsync_plugin_name,
dc8c34
diff --git a/ldap/servers/plugins/posix-winsync/posix-wsp-ident.h b/ldap/servers/plugins/posix-winsync/posix-wsp-ident.h
dc8c34
index 43a23df..f36fe40 100644
dc8c34
--- a/ldap/servers/plugins/posix-winsync/posix-wsp-ident.h
dc8c34
+++ b/ldap/servers/plugins/posix-winsync/posix-wsp-ident.h
dc8c34
@@ -17,7 +17,7 @@
dc8c34
 #define POSIX_WINSYNC_MAP_MEMBERUID "posixWinsyncMapMemberUID"
dc8c34
 #define POSIX_WINSYNC_CREATE_MEMBEROFTASK "posixWinsyncCreateMemberOfTask"
dc8c34
 #define POSIX_WINSYNC_LOWER_CASE "posixWinsyncLowerCaseUID"
dc8c34
-
dc8c34
+#define POSIX_WINSYNC_MAP_NESTED_GROUPING "posixWinsyncMapNestedGrouping"
dc8c34
 
dc8c34
 void * posix_winsync_get_plugin_identity();
dc8c34
 
dc8c34
@@ -29,6 +29,7 @@ typedef struct posix_winsync_config_struct {
dc8c34
     PRBool lowercase; /* store the uid in group memberuid in lower case */
dc8c34
     PRBool createMemberOfTask; /* should memberOf Plugin Task run after AD sync */
dc8c34
     PRBool MOFTaskCreated;
dc8c34
+    PRBool mapNestedGrouping;
dc8c34
     Slapi_DN *rep_suffix; /* namingContext in DS of the replicated suffix */  
dc8c34
 } POSIX_WinSync_Config;
dc8c34
 
dc8c34
@@ -42,6 +43,7 @@ Slapi_DN *posix_winsync_config_get_suffix();
dc8c34
 void posix_winsync_config_reset_MOFTaskCreated();
dc8c34
 void posix_winsync_config_set_MOFTaskCreated();
dc8c34
 PRBool posix_winsync_config_get_MOFTaskCreated();
dc8c34
+PRBool posix_winsync_config_get_mapNestedGrouping();
dc8c34
 
dc8c34
 int posix_group_task_add(Slapi_PBlock *pb, Slapi_Entry *e,
dc8c34
     Slapi_Entry *eAfter, int *returncode, char *returntext,
dc8c34
-- 
dc8c34
1.7.7.6
dc8c34