dpward / rpms / sssd

Forked from rpms/sssd 3 years ago
Clone

Blame SOURCES/0026-KRB5-Allow-writing-multiple-addresses-to-the-kdcinfo.patch

ca1eb8
From 73f452058c8ac83117cb86c12d4d266c8caccc57 Mon Sep 17 00:00:00 2001
ca1eb8
From: Jakub Hrozek <jhrozek@redhat.com>
ca1eb8
Date: Tue, 26 Jun 2018 10:35:15 +0200
ca1eb8
Subject: [PATCH] KRB5: Allow writing multiple addresses to the kdcinfo plugin
ca1eb8
ca1eb8
Turns the previous write_krb5info_file() function into a static function
ca1eb8
that writes whatever input it recevies. Adds a wrapper around it that
ca1eb8
accepts a list of strings, turns that into a newline-separated string
ca1eb8
which is then passed to the original function.
ca1eb8
ca1eb8
Related:
ca1eb8
https://pagure.io/SSSD/sssd/issue/3291
ca1eb8
ca1eb8
Reviewed-by: Sumit Bose <sbose@redhat.com>
ca1eb8
(cherry picked from commit 8971399c872c21769d5c62cf753c5f9df4caf8cb)
ca1eb8
---
ca1eb8
 src/providers/ad/ad_common.c     | 12 ++---
ca1eb8
 src/providers/ipa/ipa_common.c   |  8 ++--
ca1eb8
 src/providers/krb5/krb5_common.c | 75 +++++++++++++++++++++++++-------
ca1eb8
 src/providers/krb5/krb5_common.h |  2 +-
ca1eb8
 4 files changed, 70 insertions(+), 27 deletions(-)
ca1eb8
ca1eb8
diff --git a/src/providers/ad/ad_common.c b/src/providers/ad/ad_common.c
ca1eb8
index b103410e5915a380d0404e18da869517e4d4e355..eaf0814f1aaf51a5085e992efa633240f32c498e 100644
ca1eb8
--- a/src/providers/ad/ad_common.c
ca1eb8
+++ b/src/providers/ad/ad_common.c
ca1eb8
@@ -848,7 +848,7 @@ ad_resolve_callback(void *private_data, struct fo_server *server)
ca1eb8
     struct resolv_hostent *srvaddr;
ca1eb8
     struct sockaddr_storage *sockaddr;
ca1eb8
     char *address;
ca1eb8
-    const char *safe_address;
ca1eb8
+    char *safe_addr_list[2] = { NULL, NULL };
ca1eb8
     char *new_uri;
ca1eb8
     int new_port;
ca1eb8
     const char *srv_name;
ca1eb8
@@ -957,17 +957,17 @@ ad_resolve_callback(void *private_data, struct fo_server *server)
ca1eb8
     if ((sdata == NULL || sdata->gc == false) &&
ca1eb8
         service->krb5_service->write_kdcinfo) {
ca1eb8
         /* Write krb5 info files */
ca1eb8
-        safe_address = sss_escape_ip_address(tmp_ctx,
ca1eb8
-                                            srvaddr->family,
ca1eb8
-                                            address);
ca1eb8
-        if (safe_address == NULL) {
ca1eb8
+        safe_addr_list[0] = sss_escape_ip_address(tmp_ctx,
ca1eb8
+                                                  srvaddr->family,
ca1eb8
+                                                  address);
ca1eb8
+        if (safe_addr_list[0] == NULL) {
ca1eb8
             DEBUG(SSSDBG_CRIT_FAILURE, "sss_escape_ip_address failed.\n");
ca1eb8
             ret = ENOMEM;
ca1eb8
             goto done;
ca1eb8
         }
ca1eb8
 
ca1eb8
         ret = write_krb5info_file(service->krb5_service,
ca1eb8
-                                  safe_address,
ca1eb8
+                                  safe_addr_list,
ca1eb8
                                   SSS_KRB5KDC_FO_SRV);
ca1eb8
         if (ret != EOK) {
ca1eb8
             DEBUG(SSSDBG_MINOR_FAILURE,
ca1eb8
diff --git a/src/providers/ipa/ipa_common.c b/src/providers/ipa/ipa_common.c
ca1eb8
index 5808513bfd570c43bc1712114aabba5749ba0fec..0614019764287e5114aa8b8b5c670b717732068b 100644
ca1eb8
--- a/src/providers/ipa/ipa_common.c
ca1eb8
+++ b/src/providers/ipa/ipa_common.c
ca1eb8
@@ -766,7 +766,7 @@ static void ipa_resolve_callback(void *private_data, struct fo_server *server)
ca1eb8
     struct resolv_hostent *srvaddr;
ca1eb8
     struct sockaddr_storage *sockaddr;
ca1eb8
     char *address;
ca1eb8
-    const char *safe_address;
ca1eb8
+    char *safe_addr_list[2] = { NULL, NULL };
ca1eb8
     char *new_uri;
ca1eb8
     const char *srv_name;
ca1eb8
     int ret;
ca1eb8
@@ -829,17 +829,17 @@ static void ipa_resolve_callback(void *private_data, struct fo_server *server)
ca1eb8
     service->sdap->sockaddr = talloc_steal(service, sockaddr);
ca1eb8
 
ca1eb8
     if (service->krb5_service->write_kdcinfo) {
ca1eb8
-        safe_address = sss_escape_ip_address(tmp_ctx,
ca1eb8
+        safe_addr_list[0] = sss_escape_ip_address(tmp_ctx,
ca1eb8
                                              srvaddr->family,
ca1eb8
                                              address);
ca1eb8
-        if (safe_address == NULL) {
ca1eb8
+        if (safe_addr_list[0] == NULL) {
ca1eb8
             DEBUG(SSSDBG_CRIT_FAILURE, "sss_escape_ip_address failed.\n");
ca1eb8
             talloc_free(tmp_ctx);
ca1eb8
             return;
ca1eb8
         }
ca1eb8
 
ca1eb8
         ret = write_krb5info_file(service->krb5_service,
ca1eb8
-                                  safe_address,
ca1eb8
+                                  safe_addr_list,
ca1eb8
                                   SSS_KRB5KDC_FO_SRV);
ca1eb8
         if (ret != EOK) {
ca1eb8
             DEBUG(SSSDBG_OP_FAILURE,
ca1eb8
diff --git a/src/providers/krb5/krb5_common.c b/src/providers/krb5/krb5_common.c
ca1eb8
index 2a50dfec55c29b8d7f8b8751c904977c22aa906a..2b003e1642b449e8db20ba4259ba13273e21212f 100644
ca1eb8
--- a/src/providers/krb5/krb5_common.c
ca1eb8
+++ b/src/providers/krb5/krb5_common.c
ca1eb8
@@ -466,10 +466,9 @@ done:
ca1eb8
     return ret;
ca1eb8
 }
ca1eb8
 
ca1eb8
-
ca1eb8
-errno_t write_krb5info_file(struct krb5_service *krb5_service,
ca1eb8
-                            const char *server,
ca1eb8
-                            const char *service)
ca1eb8
+static errno_t write_krb5info_file_contents(struct krb5_service *krb5_service,
ca1eb8
+                                            const char *contents,
ca1eb8
+                                            const char *service)
ca1eb8
 {
ca1eb8
     int ret;
ca1eb8
     int fd = -1;
ca1eb8
@@ -482,7 +481,7 @@ errno_t write_krb5info_file(struct krb5_service *krb5_service,
ca1eb8
 
ca1eb8
     if (krb5_service == NULL || krb5_service->realm == NULL
ca1eb8
                              || *krb5_service->realm == '\0'
ca1eb8
-                             || server == NULL || *server == '\0'
ca1eb8
+                             || contents == NULL || *contents == '\0'
ca1eb8
                              || service == NULL || *service == '\0') {
ca1eb8
         DEBUG(SSSDBG_CRIT_FAILURE,
ca1eb8
               "Missing or empty realm, server or service.\n");
ca1eb8
@@ -505,7 +504,7 @@ errno_t write_krb5info_file(struct krb5_service *krb5_service,
ca1eb8
         return EINVAL;
ca1eb8
     }
ca1eb8
 
ca1eb8
-    server_len = strlen(server);
ca1eb8
+    server_len = strlen(contents);
ca1eb8
 
ca1eb8
     tmp_ctx = talloc_new(NULL);
ca1eb8
     if (tmp_ctx == NULL) {
ca1eb8
@@ -535,7 +534,7 @@ errno_t write_krb5info_file(struct krb5_service *krb5_service,
ca1eb8
     }
ca1eb8
 
ca1eb8
     errno = 0;
ca1eb8
-    written = sss_atomic_write_s(fd, discard_const(server), server_len);
ca1eb8
+    written = sss_atomic_write_s(fd, discard_const(contents), server_len);
ca1eb8
     if (written == -1) {
ca1eb8
         ret = errno;
ca1eb8
         DEBUG(SSSDBG_CRIT_FAILURE,
ca1eb8
@@ -592,12 +591,56 @@ done:
ca1eb8
     return ret;
ca1eb8
 }
ca1eb8
 
ca1eb8
+errno_t write_krb5info_file(struct krb5_service *krb5_service,
ca1eb8
+                            char **server_list,
ca1eb8
+                            const char *service)
ca1eb8
+{
ca1eb8
+    int i;
ca1eb8
+    errno_t ret;
ca1eb8
+    TALLOC_CTX *tmp_ctx = NULL;
ca1eb8
+    char *contents = NULL;
ca1eb8
+
ca1eb8
+    if (krb5_service == NULL || server_list == NULL || service == NULL) {
ca1eb8
+        return EINVAL;
ca1eb8
+    }
ca1eb8
+
ca1eb8
+    if (server_list[0] == NULL) {
ca1eb8
+        return EOK;
ca1eb8
+    }
ca1eb8
+
ca1eb8
+    tmp_ctx = talloc_new(NULL);
ca1eb8
+    if (tmp_ctx == NULL) {
ca1eb8
+        return ENOMEM;
ca1eb8
+    }
ca1eb8
+
ca1eb8
+    contents = talloc_strdup(tmp_ctx, "");
ca1eb8
+    if (contents == NULL) {
ca1eb8
+        ret = ENOMEM;
ca1eb8
+        goto done;
ca1eb8
+    }
ca1eb8
+
ca1eb8
+    i = 0;
ca1eb8
+    do {
ca1eb8
+        contents = talloc_asprintf_append(contents, "%s\n", server_list[i]);
ca1eb8
+        if (contents == NULL) {
ca1eb8
+            ret = ENOMEM;
ca1eb8
+            goto done;
ca1eb8
+        }
ca1eb8
+        i++;
ca1eb8
+    } while (server_list[i] != NULL);
ca1eb8
+
ca1eb8
+    ret = write_krb5info_file_contents(krb5_service, contents, service);
ca1eb8
+done:
ca1eb8
+    talloc_free(tmp_ctx);
ca1eb8
+    return ret;
ca1eb8
+}
ca1eb8
+
ca1eb8
 static void krb5_resolve_callback(void *private_data, struct fo_server *server)
ca1eb8
 {
ca1eb8
     struct krb5_service *krb5_service;
ca1eb8
     struct resolv_hostent *srvaddr;
ca1eb8
     char *address;
ca1eb8
-    char *safe_address;
ca1eb8
+    char *safe_addr_list[2] = { NULL, NULL };
ca1eb8
     int ret;
ca1eb8
     TALLOC_CTX *tmp_ctx = NULL;
ca1eb8
 
ca1eb8
@@ -630,26 +673,26 @@ static void krb5_resolve_callback(void *private_data, struct fo_server *server)
ca1eb8
         return;
ca1eb8
     }
ca1eb8
 
ca1eb8
-    safe_address = sss_escape_ip_address(tmp_ctx,
ca1eb8
-                                         srvaddr->family,
ca1eb8
-                                         address);
ca1eb8
-    if (safe_address == NULL) {
ca1eb8
+    safe_addr_list[0] = sss_escape_ip_address(tmp_ctx,
ca1eb8
+                                              srvaddr->family,
ca1eb8
+                                              address);
ca1eb8
+    if (safe_addr_list[0] == NULL) {
ca1eb8
         DEBUG(SSSDBG_CRIT_FAILURE, "sss_escape_ip_address failed.\n");
ca1eb8
         talloc_free(tmp_ctx);
ca1eb8
         return;
ca1eb8
     }
ca1eb8
 
ca1eb8
     if (krb5_service->write_kdcinfo) {
ca1eb8
-        safe_address = talloc_asprintf_append(safe_address, ":%d",
ca1eb8
-                                            fo_get_server_port(server));
ca1eb8
-        if (safe_address == NULL) {
ca1eb8
+        safe_addr_list[0] = talloc_asprintf_append(safe_addr_list[0], ":%d",
ca1eb8
+                                                   fo_get_server_port(server));
ca1eb8
+        if (safe_addr_list[0] == NULL) {
ca1eb8
             DEBUG(SSSDBG_CRIT_FAILURE, "talloc_asprintf_append failed.\n");
ca1eb8
             talloc_free(tmp_ctx);
ca1eb8
             return;
ca1eb8
         }
ca1eb8
 
ca1eb8
         ret = write_krb5info_file(krb5_service,
ca1eb8
-                                  safe_address,
ca1eb8
+                                  safe_addr_list,
ca1eb8
                                   krb5_service->name);
ca1eb8
         if (ret != EOK) {
ca1eb8
             DEBUG(SSSDBG_OP_FAILURE,
ca1eb8
diff --git a/src/providers/krb5/krb5_common.h b/src/providers/krb5/krb5_common.h
ca1eb8
index 1c12d5652ccef7e1738177eedad1c9de543916b7..bf36a551a92877ec838d8d3a041903144f22bc8f 100644
ca1eb8
--- a/src/providers/krb5/krb5_common.h
ca1eb8
+++ b/src/providers/krb5/krb5_common.h
ca1eb8
@@ -161,7 +161,7 @@ errno_t sss_krb5_get_options(TALLOC_CTX *memctx, struct confdb_ctx *cdb,
ca1eb8
                              const char *conf_path, struct dp_option **_opts);
ca1eb8
 
ca1eb8
 errno_t write_krb5info_file(struct krb5_service *krb5_service,
ca1eb8
-                            const char *server,
ca1eb8
+                            char **server_list,
ca1eb8
                             const char *service);
ca1eb8
 
ca1eb8
 struct krb5_service *krb5_service_new(TALLOC_CTX *mem_ctx,
ca1eb8
-- 
ca1eb8
2.17.1
ca1eb8