nsssrv.c revision c3ef027218fe9a7d16a70ca9d2f53e3d995e369f
/*
SSSD
NSS Responder
Copyright (C) Simo Sorce <ssorce@redhat.com> 2008
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
#include <stdio.h>
#include <unistd.h>
#include <fcntl.h>
#include <string.h>
#include <errno.h>
#include "popt.h"
#include "responder/nss/nsssrv_mmap_cache.h"
#include "responder/common/negcache.h"
#include "sbus/sssd_dbus.h"
#include "responder/common/responder_packet.h"
#include "responder/common/responder.h"
#include "providers/data_provider.h"
#include "monitor/monitor_interfaces.h"
#include "sbus/sbus_client.h"
#define DEFAULT_PWFIELD "*"
#define DEFAULT_NSS_FD_LIMIT 8192
#define SHELL_REALLOC_INCREMENT 5
#define SHELL_REALLOC_MAX 50
struct sbus_method monitor_nss_methods[] = {
};
struct sbus_interface monitor_nss_interface = {
};
{
int i = 0;
char *sh;
int size;
if (!shells) {
goto done;
}
setusershell();
while ((sh = getusershell())) {
if (!shells[i]) {
endusershell();
goto done;
}
i++;
if (i == size) {
if (size > SHELL_REALLOC_MAX) {
DEBUG(0, ("Reached maximum number of shells [%d]. "
"Users may be denied access. "
break;
}
size);
if (!shells) {
goto done;
}
}
}
endusershell();
if (i + 1 < size) {
if (!shells) {
goto done;
}
}
done:
return ret;
}
struct confdb_ctx *cdb)
{
int ret;
&nctx->neg_timeout);
if (nctx->cache_refresh_percent < 0 ||
DEBUG(0,("Configuration error: entry_cache_nowait_percentage is "
"invalid. Disabling feature.\n"));
nctx->cache_refresh_percent = 0;
}
goto done;
}
&nctx->override_homedir);
&nctx->allowed_shells);
&nctx->vetoed_shells);
&nctx->shell_fallback);
ret = 0;
done:
return ret;
}
static struct sbus_method nss_dp_methods[] = {
};
struct sbus_interface nss_dp_interface = {
};
{
int ret;
/* Did we reconnect successfully? */
if (status == SBUS_RECONNECT_SUCCESS) {
/* Identify ourselves to the data provider */
"NSS");
/* all fine */
return;
}
}
/* Failed to reconnect */
DEBUG(0, ("Could not reconnect to %s provider.\n",
/* FIXME: kill the frontend and let the monitor restart it ? */
/* nss_shutdown(rctx); */
}
struct tevent_context *ev,
struct confdb_ctx *cdb)
{
struct sss_cmd_table *nss_cmds;
int ret, max_retries;
int hret;
int fd_limit;
if (!nctx) {
DEBUG(0, ("fatal error initializing nss_ctx\n"));
return ENOMEM;
}
DEBUG(0, ("fatal error initializing negative cache\n"));
return ret;
}
nss_cmds = get_nss_cmds();
"NSS", &nss_dp_interface,
return ret;
}
DEBUG(0, ("fatal error getting nss config\n"));
return ret;
}
/* Enable automatic reconnection to the Data Provider */
3, &max_retries);
DEBUG(0, ("Failed to set up automatic reconnection\n"));
return ret;
}
}
/* Create the lookup table for netgroup results */
if (hret != HASH_SUCCESS) {
DEBUG(0,("Unable to initialize netgroup hash table\n"));
return EIO;
}
/* create mmap caches */
/* TODO: read cache sizes from configuration */
50000,
&nctx->pwd_mc_ctx);
if (ret) {
}
50000,
&nctx->grp_mc_ctx);
if (ret) {
}
/* Set up file descriptor limits */
&fd_limit);
("Failed to set up file descriptor limit\n"));
return ret;
}
return EOK;
}
{
int opt;
struct main_context *main_ctx;
int ret;
struct poptOption long_options[] = {
};
/* Set debug level to invalid value so we can deside if -d 0 was used. */
switch(opt) {
default:
return 1;
}
}
/* set up things like debug, signals, daemonization, etc... */
debug_log_file = "sssd_nss";
ret = die_if_parent_died();
/* This is not fatal, don't return */
}
/* loop on main */
return 0;
}