| 1 | #!/usr/bin/perl
 | 
|---|
| 2 | # Bootstrap Samba and run a number of tests against it.
 | 
|---|
| 3 | # Copyright (C) 2005-2007 Jelmer Vernooij <jelmer@samba.org>
 | 
|---|
| 4 | # Published under the GNU GPL, v3 or later.
 | 
|---|
| 5 | 
 | 
|---|
| 6 | package Samba4;
 | 
|---|
| 7 | 
 | 
|---|
| 8 | use strict;
 | 
|---|
| 9 | use Cwd qw(abs_path);
 | 
|---|
| 10 | use FindBin qw($RealBin);
 | 
|---|
| 11 | use POSIX;
 | 
|---|
| 12 | 
 | 
|---|
| 13 | sub new($$$$$) {
 | 
|---|
| 14 |         my ($classname, $bindir, $ldap, $setupdir, $exeext) = @_;
 | 
|---|
| 15 |         $exeext = "" unless defined($exeext);
 | 
|---|
| 16 |         my $self = { 
 | 
|---|
| 17 |                 vars => {}, 
 | 
|---|
| 18 |                 ldap => $ldap, 
 | 
|---|
| 19 |                 bindir => $bindir, 
 | 
|---|
| 20 |                 setupdir => $setupdir,
 | 
|---|
| 21 |                 exeext => $exeext
 | 
|---|
| 22 |         };
 | 
|---|
| 23 |         bless $self;
 | 
|---|
| 24 |         return $self;
 | 
|---|
| 25 | }
 | 
|---|
| 26 | 
 | 
|---|
| 27 | sub bindir_path($$) {
 | 
|---|
| 28 |         my ($self, $path) = @_;
 | 
|---|
| 29 | 
 | 
|---|
| 30 |         return "$self->{bindir}/$path$self->{exeext}";
 | 
|---|
| 31 | }
 | 
|---|
| 32 | 
 | 
|---|
| 33 | sub openldap_start($$$) {
 | 
|---|
| 34 | }
 | 
|---|
| 35 | 
 | 
|---|
| 36 | sub slapd_start($$)
 | 
|---|
| 37 | {
 | 
|---|
| 38 |         my $count = 0;
 | 
|---|
| 39 |         my ($self, $env_vars) = @_;
 | 
|---|
| 40 |         my $ldbsearch = $self->bindir_path("ldbsearch");
 | 
|---|
| 41 | 
 | 
|---|
| 42 |         my $uri = $env_vars->{LDAP_URI};
 | 
|---|
| 43 | 
 | 
|---|
| 44 |         if (system("$ldbsearch -H $uri -s base -b \"\" supportedLDAPVersion > /dev/null") == 0) {
 | 
|---|
| 45 |             print "A SLAPD is still listening to $uri before we started the LDAP backend.  Aborting!";
 | 
|---|
| 46 |             return 1;
 | 
|---|
| 47 |         }
 | 
|---|
| 48 |         # running slapd in the background means it stays in the same process group, so it can be
 | 
|---|
| 49 |         # killed by timelimit
 | 
|---|
| 50 |         if ($self->{ldap} eq "fedora-ds") {
 | 
|---|
| 51 |                 system("$ENV{FEDORA_DS_ROOT}/sbin/ns-slapd -D $env_vars->{FEDORA_DS_DIR} -d0 -i $env_vars->{FEDORA_DS_PIDFILE}> $env_vars->{LDAPDIR}/logs 2>&1 &");
 | 
|---|
| 52 |         } elsif ($self->{ldap} eq "openldap") {
 | 
|---|
| 53 |                 system("$ENV{OPENLDAP_SLAPD} -d0 -F $env_vars->{SLAPD_CONF_D} -h $uri > $env_vars->{LDAPDIR}/logs 2>&1 &");
 | 
|---|
| 54 |         }
 | 
|---|
| 55 |         while (system("$ldbsearch -H $uri -s base -b \"\" supportedLDAPVersion > /dev/null") != 0) {
 | 
|---|
| 56 |                 $count++;
 | 
|---|
| 57 |                 if ($count > 40) {
 | 
|---|
| 58 |                     $self->slapd_stop($env_vars);
 | 
|---|
| 59 |                     return 0;
 | 
|---|
| 60 |                 }
 | 
|---|
| 61 |                 sleep(1);
 | 
|---|
| 62 |         }
 | 
|---|
| 63 |         return 1;
 | 
|---|
| 64 | }
 | 
|---|
| 65 | 
 | 
|---|
| 66 | sub slapd_stop($$)
 | 
|---|
| 67 | {
 | 
|---|
| 68 |         my ($self, $envvars) = @_;
 | 
|---|
| 69 |         if ($self->{ldap} eq "fedora-ds") {
 | 
|---|
| 70 |                 system("$envvars->{LDAPDIR}/slapd-samba4/stop-slapd");
 | 
|---|
| 71 |         } elsif ($self->{ldap} eq "openldap") {
 | 
|---|
| 72 |                 open(IN, "<$envvars->{OPENLDAP_PIDFILE}") or 
 | 
|---|
| 73 |                         die("unable to open slapd pid file: $envvars->{OPENLDAP_PIDFILE}");
 | 
|---|
| 74 |                 kill 9, <IN>;
 | 
|---|
| 75 |                 close(IN);
 | 
|---|
| 76 |         }
 | 
|---|
| 77 |         return 1;
 | 
|---|
| 78 | }
 | 
|---|
| 79 | 
 | 
|---|
| 80 | sub check_or_start($$$) 
 | 
|---|
| 81 | {
 | 
|---|
| 82 |         my ($self, $env_vars, $max_time) = @_;
 | 
|---|
| 83 |         return 0 if ( -p $env_vars->{SAMBA_TEST_FIFO});
 | 
|---|
| 84 | 
 | 
|---|
| 85 |         unlink($env_vars->{SAMBA_TEST_FIFO});
 | 
|---|
| 86 |         POSIX::mkfifo($env_vars->{SAMBA_TEST_FIFO}, 0700);
 | 
|---|
| 87 |         unlink($env_vars->{SAMBA_TEST_LOG});
 | 
|---|
| 88 |         
 | 
|---|
| 89 |         print "STARTING SAMBA... ";
 | 
|---|
| 90 |         my $pid = fork();
 | 
|---|
| 91 |         if ($pid == 0) {
 | 
|---|
| 92 |                 open STDIN, $env_vars->{SAMBA_TEST_FIFO};
 | 
|---|
| 93 |                 # we want out from samba to go to the log file, but also
 | 
|---|
| 94 |                 # to the users terminal when running 'make test' on the command
 | 
|---|
| 95 |                 # line. This puts it on stderr on the terminal
 | 
|---|
| 96 |                 open STDOUT, "| tee $env_vars->{SAMBA_TEST_LOG} 1>&2";
 | 
|---|
| 97 |                 open STDERR, '>&STDOUT';
 | 
|---|
| 98 | 
 | 
|---|
| 99 |                 SocketWrapper::set_default_iface($env_vars->{SOCKET_WRAPPER_DEFAULT_IFACE});
 | 
|---|
| 100 | 
 | 
|---|
| 101 |                 my $valgrind = "";
 | 
|---|
| 102 |                 if (defined($ENV{SAMBA_VALGRIND})) {
 | 
|---|
| 103 |                     $valgrind = $ENV{SAMBA_VALGRIND};
 | 
|---|
| 104 |                 } 
 | 
|---|
| 105 | 
 | 
|---|
| 106 |                 $ENV{KRB5_CONFIG} = $env_vars->{KRB5_CONFIG}; 
 | 
|---|
| 107 |                 $ENV{WINBINDD_SOCKET_DIR} = $env_vars->{WINBINDD_SOCKET_DIR};
 | 
|---|
| 108 | 
 | 
|---|
| 109 |                 $ENV{NSS_WRAPPER_PASSWD} = $env_vars->{NSS_WRAPPER_PASSWD};
 | 
|---|
| 110 |                 $ENV{NSS_WRAPPER_GROUP} = $env_vars->{NSS_WRAPPER_GROUP};
 | 
|---|
| 111 | 
 | 
|---|
| 112 |                 $ENV{UID_WRAPPER} = "1";
 | 
|---|
| 113 | 
 | 
|---|
| 114 |                 # Start slapd before samba, but with the fifo on stdin
 | 
|---|
| 115 |                 if (defined($self->{ldap})) {
 | 
|---|
| 116 |                     $self->slapd_start($env_vars) or 
 | 
|---|
| 117 |                         die("couldn't start slapd (main run)");
 | 
|---|
| 118 |                 }
 | 
|---|
| 119 | 
 | 
|---|
| 120 |                 my $optarg = "";
 | 
|---|
| 121 |                 if (defined($max_time)) {
 | 
|---|
| 122 |                         $optarg = "--maximum-runtime=$max_time ";
 | 
|---|
| 123 |                 }
 | 
|---|
| 124 |                 if (defined($ENV{SAMBA_OPTIONS})) {
 | 
|---|
| 125 |                         $optarg.= " $ENV{SAMBA_OPTIONS}";
 | 
|---|
| 126 |                 }
 | 
|---|
| 127 |                 my $samba = $self->bindir_path("samba");
 | 
|---|
| 128 | 
 | 
|---|
| 129 |                 # allow selection of the process model using
 | 
|---|
| 130 |                 # the environment varibale SAMBA_PROCESS_MODEL
 | 
|---|
| 131 |                 # that allows us to change the process model for 
 | 
|---|
| 132 |                 # individual machines in the build farm
 | 
|---|
| 133 |                 my $model = "single";
 | 
|---|
| 134 |                 if (defined($ENV{SAMBA_PROCESS_MODEL})) {
 | 
|---|
| 135 |                         $model = $ENV{SAMBA_PROCESS_MODEL};
 | 
|---|
| 136 |                 }
 | 
|---|
| 137 |                 my $ret = system("$valgrind $samba $optarg $env_vars->{CONFIGURATION} -M $model -i");
 | 
|---|
| 138 |                 if ($? == -1) {
 | 
|---|
| 139 |                         print "Unable to start $samba: $ret: $!\n";
 | 
|---|
| 140 |                         exit 1;
 | 
|---|
| 141 |                 }
 | 
|---|
| 142 |                 unlink($env_vars->{SAMBA_TEST_FIFO});
 | 
|---|
| 143 |                 my $exit = $? >> 8;
 | 
|---|
| 144 |                 if ( $ret == 0 ) {
 | 
|---|
| 145 |                         print "$samba exits with status $exit\n";
 | 
|---|
| 146 |                 } elsif ( $ret & 127 ) {
 | 
|---|
| 147 |                         print "$samba got signal ".($ret & 127)." and exits with $exit!\n";
 | 
|---|
| 148 |                 } else {
 | 
|---|
| 149 |                         $ret = $? >> 8;
 | 
|---|
| 150 |                         print "$samba failed with status $exit!\n";
 | 
|---|
| 151 |                 }
 | 
|---|
| 152 |                 exit $exit;
 | 
|---|
| 153 |         }
 | 
|---|
| 154 |         print "DONE\n";
 | 
|---|
| 155 | 
 | 
|---|
| 156 |         open(DATA, ">$env_vars->{SAMBA_TEST_FIFO}");
 | 
|---|
| 157 | 
 | 
|---|
| 158 |         return $pid;
 | 
|---|
| 159 | }
 | 
|---|
| 160 | 
 | 
|---|
| 161 | sub wait_for_start($$)
 | 
|---|
| 162 | {
 | 
|---|
| 163 |         my ($self, $testenv_vars) = @_;
 | 
|---|
| 164 |         # give time for nbt server to register its names
 | 
|---|
| 165 |         print "delaying for nbt name registration\n";
 | 
|---|
| 166 |         sleep 2;
 | 
|---|
| 167 | 
 | 
|---|
| 168 |         # This will return quickly when things are up, but be slow if we 
 | 
|---|
| 169 |         # need to wait for (eg) SSL init 
 | 
|---|
| 170 |         my $nmblookup = $self->bindir_path("nmblookup");
 | 
|---|
| 171 |         system("$nmblookup $testenv_vars->{CONFIGURATION} $testenv_vars->{SERVER}");
 | 
|---|
| 172 |         system("$nmblookup $testenv_vars->{CONFIGURATION} -U $testenv_vars->{SERVER_IP} $testenv_vars->{SERVER}");
 | 
|---|
| 173 |         system("$nmblookup $testenv_vars->{CONFIGURATION} $testenv_vars->{NETBIOSNAME}");
 | 
|---|
| 174 |         system("$nmblookup $testenv_vars->{CONFIGURATION} -U $testenv_vars->{SERVER_IP} $testenv_vars->{NETBIOSNAME}");
 | 
|---|
| 175 |         system("$nmblookup $testenv_vars->{CONFIGURATION} $testenv_vars->{NETBIOSALIAS}");
 | 
|---|
| 176 |         system("$nmblookup $testenv_vars->{CONFIGURATION} -U $testenv_vars->{SERVER_IP} $testenv_vars->{NETBIOSALIAS}");
 | 
|---|
| 177 |         system("$nmblookup $testenv_vars->{CONFIGURATION} $testenv_vars->{SERVER}");
 | 
|---|
| 178 |         system("$nmblookup $testenv_vars->{CONFIGURATION} -U $testenv_vars->{SERVER_IP} $testenv_vars->{SERVER}");
 | 
|---|
| 179 |         system("$nmblookup $testenv_vars->{CONFIGURATION} $testenv_vars->{NETBIOSNAME}");
 | 
|---|
| 180 |         system("$nmblookup $testenv_vars->{CONFIGURATION} -U $testenv_vars->{SERVER_IP} $testenv_vars->{NETBIOSNAME}");
 | 
|---|
| 181 |         system("$nmblookup $testenv_vars->{CONFIGURATION} $testenv_vars->{NETBIOSALIAS}");
 | 
|---|
| 182 |         system("$nmblookup $testenv_vars->{CONFIGURATION} -U $testenv_vars->{SERVER_IP} $testenv_vars->{NETBIOSALIAS}");
 | 
|---|
| 183 | 
 | 
|---|
| 184 |         print $self->getlog_env($testenv_vars);
 | 
|---|
| 185 | }
 | 
|---|
| 186 | 
 | 
|---|
| 187 | sub write_ldb_file($$$)
 | 
|---|
| 188 | {
 | 
|---|
| 189 |         my ($self, $file, $ldif) = @_;
 | 
|---|
| 190 | 
 | 
|---|
| 191 |         my $ldbadd = $self->bindir_path("ldbadd");
 | 
|---|
| 192 |         open(LDIF, "|$ldbadd -H $file >/dev/null");
 | 
|---|
| 193 |         print LDIF $ldif;
 | 
|---|
| 194 |         return close(LDIF);
 | 
|---|
| 195 | }
 | 
|---|
| 196 | 
 | 
|---|
| 197 | sub add_wins_config($$)
 | 
|---|
| 198 | {
 | 
|---|
| 199 |         my ($self, $privatedir) = @_;
 | 
|---|
| 200 | 
 | 
|---|
| 201 |         return $self->write_ldb_file("$privatedir/wins_config.ldb", "
 | 
|---|
| 202 | dn: name=TORTURE_6,CN=PARTNERS
 | 
|---|
| 203 | objectClass: wreplPartner
 | 
|---|
| 204 | name: TORTURE_6
 | 
|---|
| 205 | address: 127.0.0.6
 | 
|---|
| 206 | pullInterval: 0
 | 
|---|
| 207 | pushChangeCount: 0
 | 
|---|
| 208 | type: 0x3
 | 
|---|
| 209 | ");
 | 
|---|
| 210 | }
 | 
|---|
| 211 | 
 | 
|---|
| 212 | sub mk_fedora_ds($$)
 | 
|---|
| 213 | {
 | 
|---|
| 214 |         my ($self, $ldapdir) = @_;
 | 
|---|
| 215 | 
 | 
|---|
| 216 |         #Make the subdirectory be as fedora DS would expect
 | 
|---|
| 217 |         my $fedora_ds_dir = "$ldapdir/slapd-samba4";
 | 
|---|
| 218 | 
 | 
|---|
| 219 |         my $pidfile = "$fedora_ds_dir/logs/slapd-samba4.pid";
 | 
|---|
| 220 | 
 | 
|---|
| 221 |         return ($fedora_ds_dir, $pidfile);
 | 
|---|
| 222 | }
 | 
|---|
| 223 | 
 | 
|---|
| 224 | sub mk_openldap($$)
 | 
|---|
| 225 | {
 | 
|---|
| 226 |         my ($self, $ldapdir) = @_;
 | 
|---|
| 227 | 
 | 
|---|
| 228 |         my $slapd_conf_d = "$ldapdir/slapd.d";
 | 
|---|
| 229 |         my $pidfile = "$ldapdir/slapd.pid";
 | 
|---|
| 230 | 
 | 
|---|
| 231 |         return ($slapd_conf_d, $pidfile);
 | 
|---|
| 232 | }
 | 
|---|
| 233 | 
 | 
|---|
| 234 | sub mk_keyblobs($$)
 | 
|---|
| 235 | {
 | 
|---|
| 236 |         my ($self, $tlsdir) = @_;
 | 
|---|
| 237 | 
 | 
|---|
| 238 |         #TLS and PKINIT crypto blobs
 | 
|---|
| 239 |         my $dhfile = "$tlsdir/dhparms.pem";
 | 
|---|
| 240 |         my $cafile = "$tlsdir/ca.pem";
 | 
|---|
| 241 |         my $certfile = "$tlsdir/cert.pem";
 | 
|---|
| 242 |         my $reqkdc = "$tlsdir/req-kdc.der";
 | 
|---|
| 243 |         my $kdccertfile = "$tlsdir/kdc.pem";
 | 
|---|
| 244 |         my $keyfile = "$tlsdir/key.pem";
 | 
|---|
| 245 |         my $adminkeyfile = "$tlsdir/adminkey.pem";
 | 
|---|
| 246 |         my $reqadmin = "$tlsdir/req-admin.der";
 | 
|---|
| 247 |         my $admincertfile = "$tlsdir/admincert.pem";
 | 
|---|
| 248 |         my $admincertupnfile = "$tlsdir/admincertupn.pem";
 | 
|---|
| 249 | 
 | 
|---|
| 250 |         mkdir($tlsdir, 0777);
 | 
|---|
| 251 | 
 | 
|---|
| 252 |         #This is specified here to avoid draining entropy on every run
 | 
|---|
| 253 |         open(DHFILE, ">$dhfile");
 | 
|---|
| 254 |         print DHFILE <<EOF;
 | 
|---|
| 255 | -----BEGIN DH PARAMETERS-----
 | 
|---|
| 256 | MGYCYQC/eWD2xkb7uELmqLi+ygPMKyVcpHUo2yCluwnbPutEueuxrG/Cys8j8wLO
 | 
|---|
| 257 | svCN/jYNyR2NszOmg7ZWcOC/4z/4pWDVPUZr8qrkhj5MRKJc52MncfaDglvEdJrv
 | 
|---|
| 258 | YX70obsCAQI=
 | 
|---|
| 259 | -----END DH PARAMETERS-----
 | 
|---|
| 260 | EOF
 | 
|---|
| 261 |         close(DHFILE);
 | 
|---|
| 262 | 
 | 
|---|
| 263 |         #Likewise, we pregenerate the key material.  This allows the 
 | 
|---|
| 264 |         #other certificates to be pre-generated
 | 
|---|
| 265 |         open(KEYFILE, ">$keyfile");
 | 
|---|
| 266 |         print KEYFILE <<EOF;
 | 
|---|
| 267 | -----BEGIN RSA PRIVATE KEY-----
 | 
|---|
| 268 | MIICXQIBAAKBgQDKg6pAwCHUMA1DfHDmWhZfd+F0C+9Jxcqvpw9ii9En3E1uflpc
 | 
|---|
| 269 | ol3+S9/6I/uaTmJHZre+DF3dTzb/UOZo0Zem8N+IzzkgoGkFafjXuT3BL5UPY2/H
 | 
|---|
| 270 | 6H+pPqVIRLOmrWImai359YyoKhFyo37Y6HPeU8QcZ+u2rS9geapIWfeuowIDAQAB
 | 
|---|
| 271 | AoGAAqDLzFRR/BF1kpsiUfL4WFvTarCe9duhwj7ORc6fs785qAXuwUYAJ0Uvzmy6
 | 
|---|
| 272 | HqoGv3t3RfmeHDmjcpPHsbOKnsOQn2MgmthidQlPBMWtQMff5zdoYNUFiPS0XQBq
 | 
|---|
| 273 | szNW4PRjaA9KkLQVTwnzdXGkBSkn/nGxkaVu7OR3vJOBoo0CQQDO4upypesnbe6p
 | 
|---|
| 274 | 9/xqfZ2uim8IwV1fLlFClV7WlCaER8tsQF4lEi0XSzRdXGUD/dilpY88Nb+xok/X
 | 
|---|
| 275 | 8Z8OvgAXAkEA+pcLsx1gN7kxnARxv54jdzQjC31uesJgMKQXjJ0h75aUZwTNHmZQ
 | 
|---|
| 276 | vPxi6u62YiObrN5oivkixwFNncT9MxTxVQJBAMaWUm2SjlLe10UX4Zdm1MEB6OsC
 | 
|---|
| 277 | kVoX37CGKO7YbtBzCfTzJGt5Mwc1DSLA2cYnGJqIfSFShptALlwedot0HikCQAJu
 | 
|---|
| 278 | jNKEKnbf+TdGY8Q0SKvTebOW2Aeg80YFkaTvsXCdyXrmdQcifw4WdO9KucJiDhSz
 | 
|---|
| 279 | Y9hVapz7ykEJtFtWjLECQQDIlfc63I5ZpXfg4/nN4IJXUW6AmPVOYIA5215itgki
 | 
|---|
| 280 | cSlMYli1H9MEXH0pQMGv5Qyd0OYIx2DDg96mZ+aFvqSG
 | 
|---|
| 281 | -----END RSA PRIVATE KEY-----
 | 
|---|
| 282 | EOF
 | 
|---|
| 283 |         close(KEYFILE);
 | 
|---|
| 284 | 
 | 
|---|
| 285 |         open(ADMINKEYFILE, ">$adminkeyfile");
 | 
|---|
| 286 | 
 | 
|---|
| 287 |         print ADMINKEYFILE <<EOF;
 | 
|---|
| 288 | -----BEGIN RSA PRIVATE KEY-----
 | 
|---|
| 289 | MIICXQIBAAKBgQD0+OL7TQBj0RejbIH1+g5GeRaWaM9xF43uE5y7jUHEsi5owhZF
 | 
|---|
| 290 | 5iIoHZeeL6cpDF5y1BZRs0JlA1VqMry1jjKlzFYVEMMFxB6esnXhl0Jpip1JkUMM
 | 
|---|
| 291 | XLOP1m/0dqayuHBWozj9f/cdyCJr0wJIX1Z8Pr+EjYRGPn/MF0xdl3JRlwIDAQAB
 | 
|---|
| 292 | AoGAP8mjCP628Ebc2eACQzOWjgEvwYCPK4qPmYOf1zJkArzG2t5XAGJ5WGrENRuB
 | 
|---|
| 293 | cm3XFh1lpmaADl982UdW3gul4gXUy6w4XjKK4vVfhyHj0kZ/LgaXUK9BAGhroJ2L
 | 
|---|
| 294 | osIOUsaC6jdx9EwSRctwdlF3wWJ8NK0g28AkvIk+FlolW4ECQQD7w5ouCDnf58CN
 | 
|---|
| 295 | u4nARx4xv5XJXekBvOomkCQAmuOsdOb6b9wn3mm2E3au9fueITjb3soMR31AF6O4
 | 
|---|
| 296 | eAY126rXAkEA+RgHzybzZEP8jCuznMqoN2fq/Vrs6+W3M8/G9mzGEMgLLpaf2Jiz
 | 
|---|
| 297 | I9tLZ0+OFk9tkRaoCHPfUOCrVWJZ7Y53QQJBAMhoA6rw0WDyUcyApD5yXg6rusf4
 | 
|---|
| 298 | ASpo/tqDkqUIpoL464Qe1tjFqtBM3gSXuhs9xsz+o0bzATirmJ+WqxrkKTECQHt2
 | 
|---|
| 299 | OLCpKqwAspU7N+w32kaUADoRLisCEdrhWklbwpQgwsIVsCaoEOpt0CLloJRYTANE
 | 
|---|
| 300 | yoZeAErTALjyZYZEPcECQQDlUi0N8DFxQ/lOwWyR3Hailft+mPqoPCa8QHlQZnlG
 | 
|---|
| 301 | +cfgNl57YHMTZFwgUVFRdJNpjH/WdZ5QxDcIVli0q+Ko
 | 
|---|
| 302 | -----END RSA PRIVATE KEY-----
 | 
|---|
| 303 | EOF
 | 
|---|
| 304 | 
 | 
|---|
| 305 |         #generated with 
 | 
|---|
| 306 |         # hxtool issue-certificate --self-signed --issue-ca \
 | 
|---|
| 307 |         # --ca-private-key="FILE:$KEYFILE" \
 | 
|---|
| 308 |         # --subject="CN=CA,DC=samba,DC=example,DC=com" \
 | 
|---|
| 309 |         # --certificate="FILE:$CAFILE" --lifetime="25 years"
 | 
|---|
| 310 | 
 | 
|---|
| 311 |         open(CAFILE, ">$cafile");
 | 
|---|
| 312 |         print CAFILE <<EOF;
 | 
|---|
| 313 | -----BEGIN CERTIFICATE-----
 | 
|---|
| 314 | MIICcTCCAdqgAwIBAgIUaBPmjnPVqyFqR5foICmLmikJTzgwCwYJKoZIhvcNAQEFMFIxEzAR
 | 
|---|
| 315 | BgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxlMRUwEwYKCZImiZPy
 | 
|---|
| 316 | LGQBGQwFc2FtYmExCzAJBgNVBAMMAkNBMCIYDzIwMDgwMzAxMTIyMzEyWhgPMjAzMzAyMjQx
 | 
|---|
| 317 | MjIzMTJaMFIxEzARBgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxl
 | 
|---|
| 318 | MRUwEwYKCZImiZPyLGQBGQwFc2FtYmExCzAJBgNVBAMMAkNBMIGfMA0GCSqGSIb3DQEBAQUA
 | 
|---|
| 319 | A4GNADCBiQKBgQDKg6pAwCHUMA1DfHDmWhZfd+F0C+9Jxcqvpw9ii9En3E1uflpcol3+S9/6
 | 
|---|
| 320 | I/uaTmJHZre+DF3dTzb/UOZo0Zem8N+IzzkgoGkFafjXuT3BL5UPY2/H6H+pPqVIRLOmrWIm
 | 
|---|
| 321 | ai359YyoKhFyo37Y6HPeU8QcZ+u2rS9geapIWfeuowIDAQABo0IwQDAOBgNVHQ8BAf8EBAMC
 | 
|---|
| 322 | AaYwHQYDVR0OBBYEFMLZufegDKLZs0VOyFXYK1L6M8oyMA8GA1UdEwEB/wQFMAMBAf8wDQYJ
 | 
|---|
| 323 | KoZIhvcNAQEFBQADgYEAAZJbCAAkaqgFJ0xgNovn8Ydd0KswQPjicwiODPgw9ZPoD2HiOUVO
 | 
|---|
| 324 | yYDRg/dhFF9y656OpcHk4N7qZ2sl3RlHkzDu+dseETW+CnKvQIoXNyeARRJSsSlwrwcoD4JR
 | 
|---|
| 325 | HTLk2sGigsWwrJ2N99sG/cqSJLJ1MFwLrs6koweBnYU0f/g=
 | 
|---|
| 326 | -----END CERTIFICATE-----
 | 
|---|
| 327 | EOF
 | 
|---|
| 328 | 
 | 
|---|
| 329 |         #generated with GNUTLS internally in Samba.  
 | 
|---|
| 330 | 
 | 
|---|
| 331 |         open(CERTFILE, ">$certfile");
 | 
|---|
| 332 |         print CERTFILE <<EOF;
 | 
|---|
| 333 | -----BEGIN CERTIFICATE-----
 | 
|---|
| 334 | MIICYTCCAcygAwIBAgIE5M7SRDALBgkqhkiG9w0BAQUwZTEdMBsGA1UEChMUU2Ft
 | 
|---|
| 335 | YmEgQWRtaW5pc3RyYXRpb24xNDAyBgNVBAsTK1NhbWJhIC0gdGVtcG9yYXJ5IGF1
 | 
|---|
| 336 | dG9nZW5lcmF0ZWQgY2VydGlmaWNhdGUxDjAMBgNVBAMTBVNhbWJhMB4XDTA2MDgw
 | 
|---|
| 337 | NDA0MzY1MloXDTA4MDcwNDA0MzY1MlowZTEdMBsGA1UEChMUU2FtYmEgQWRtaW5p
 | 
|---|
| 338 | c3RyYXRpb24xNDAyBgNVBAsTK1NhbWJhIC0gdGVtcG9yYXJ5IGF1dG9nZW5lcmF0
 | 
|---|
| 339 | ZWQgY2VydGlmaWNhdGUxDjAMBgNVBAMTBVNhbWJhMIGcMAsGCSqGSIb3DQEBAQOB
 | 
|---|
| 340 | jAAwgYgCgYDKg6pAwCHUMA1DfHDmWhZfd+F0C+9Jxcqvpw9ii9En3E1uflpcol3+
 | 
|---|
| 341 | S9/6I/uaTmJHZre+DF3dTzb/UOZo0Zem8N+IzzkgoGkFafjXuT3BL5UPY2/H6H+p
 | 
|---|
| 342 | PqVIRLOmrWImai359YyoKhFyo37Y6HPeU8QcZ+u2rS9geapIWfeuowIDAQABoyUw
 | 
|---|
| 343 | IzAMBgNVHRMBAf8EAjAAMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAsGCSqGSIb3DQEB
 | 
|---|
| 344 | BQOBgQAmkN6XxvDnoMkGcWLCTwzxGfNNSVcYr7TtL2aJh285Xw9zaxcm/SAZBFyG
 | 
|---|
| 345 | LYOChvh6hPU7joMdDwGfbiLrBnMag+BtGlmPLWwp/Kt1wNmrRhduyTQFhN3PP6fz
 | 
|---|
| 346 | nBr9vVny2FewB2gHmelaPS//tXdxivSXKz3NFqqXLDJjq7P8wA==
 | 
|---|
| 347 | -----END CERTIFICATE-----
 | 
|---|
| 348 | EOF
 | 
|---|
| 349 |         close(CERTFILE);
 | 
|---|
| 350 | 
 | 
|---|
| 351 |         #KDC certificate
 | 
|---|
| 352 |         # hxtool request-create \
 | 
|---|
| 353 |         # --subject="CN=krbtgt,CN=users,DC=samba,DC=example,DC=com" \
 | 
|---|
| 354 |         # --key="FILE:$KEYFILE" $KDCREQ
 | 
|---|
| 355 | 
 | 
|---|
| 356 |         # hxtool issue-certificate --ca-certificate=FILE:$CAFILE,$KEYFILE \
 | 
|---|
| 357 |         # --type="pkinit-kdc" \
 | 
|---|
| 358 |         # --pk-init-principal="krbtgt/SAMBA.EXAMPLE.COM@SAMBA.EXAMPLE.COM" \
 | 
|---|
| 359 |         # --req="PKCS10:$KDCREQ" --certificate="FILE:$KDCCERTFILE" \
 | 
|---|
| 360 |         # --lifetime="25 years"
 | 
|---|
| 361 | 
 | 
|---|
| 362 |         open(KDCCERTFILE, ">$kdccertfile");
 | 
|---|
| 363 |         print KDCCERTFILE <<EOF;
 | 
|---|
| 364 | -----BEGIN CERTIFICATE-----
 | 
|---|
| 365 | MIIDDDCCAnWgAwIBAgIUI2Tzj+JnMzMcdeabcNo30rovzFAwCwYJKoZIhvcNAQEFMFIxEzAR
 | 
|---|
| 366 | BgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxlMRUwEwYKCZImiZPy
 | 
|---|
| 367 | LGQBGQwFc2FtYmExCzAJBgNVBAMMAkNBMCIYDzIwMDgwMzAxMTMxOTIzWhgPMjAzMzAyMjQx
 | 
|---|
| 368 | MzE5MjNaMGYxEzARBgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxl
 | 
|---|
| 369 | MRUwEwYKCZImiZPyLGQBGQwFc2FtYmExDjAMBgNVBAMMBXVzZXJzMQ8wDQYDVQQDDAZrcmJ0
 | 
|---|
| 370 | Z3QwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMqDqkDAIdQwDUN8cOZaFl934XQL70nF
 | 
|---|
| 371 | yq+nD2KL0SfcTW5+WlyiXf5L3/oj+5pOYkdmt74MXd1PNv9Q5mjRl6bw34jPOSCgaQVp+Ne5
 | 
|---|
| 372 | PcEvlQ9jb8fof6k+pUhEs6atYiZqLfn1jKgqEXKjftjoc95TxBxn67atL2B5qkhZ966jAgMB
 | 
|---|
| 373 | AAGjgcgwgcUwDgYDVR0PAQH/BAQDAgWgMBIGA1UdJQQLMAkGBysGAQUCAwUwVAYDVR0RBE0w
 | 
|---|
| 374 | S6BJBgYrBgEFAgKgPzA9oBMbEVNBTUJBLkVYQU1QTEUuQ09NoSYwJKADAgEBoR0wGxsGa3Ji
 | 
|---|
| 375 | dGd0GxFTQU1CQS5FWEFNUExFLkNPTTAfBgNVHSMEGDAWgBTC2bn3oAyi2bNFTshV2CtS+jPK
 | 
|---|
| 376 | MjAdBgNVHQ4EFgQUwtm596AMotmzRU7IVdgrUvozyjIwCQYDVR0TBAIwADANBgkqhkiG9w0B
 | 
|---|
| 377 | AQUFAAOBgQBmrVD5MCmZjfHp1nEnHqTIh8r7lSmVtDx4s9MMjxm9oNrzbKXynvdhwQYFVarc
 | 
|---|
| 378 | ge4yRRDXtSebErOl71zVJI9CVeQQpwcH+tA85oGA7oeFtO/S7ls581RUU6tGgyxV4veD+lJv
 | 
|---|
| 379 | KPH5LevUtgD+q9H4LU4Sq5N3iFwBaeryB0g2wg==
 | 
|---|
| 380 | -----END CERTIFICATE-----
 | 
|---|
| 381 | EOF
 | 
|---|
| 382 | 
 | 
|---|
| 383 |         # hxtool request-create \
 | 
|---|
| 384 |         # --subject="CN=Administrator,CN=users,DC=samba,DC=example,DC=com" \
 | 
|---|
| 385 |         # --key="FILE:$ADMINKEYFILE" $ADMINREQFILE
 | 
|---|
| 386 | 
 | 
|---|
| 387 |         # hxtool issue-certificate --ca-certificate=FILE:$CAFILE,$KEYFILE \
 | 
|---|
| 388 |         # --type="pkinit-client" \
 | 
|---|
| 389 |         # --pk-init-principal="administrator@SAMBA.EXAMPLE.COM" \
 | 
|---|
| 390 |         # --req="PKCS10:$ADMINREQFILE" --certificate="FILE:$ADMINCERTFILE" \
 | 
|---|
| 391 |         # --lifetime="25 years"
 | 
|---|
| 392 |         
 | 
|---|
| 393 |         open(ADMINCERTFILE, ">$admincertfile");
 | 
|---|
| 394 |         print ADMINCERTFILE <<EOF;
 | 
|---|
| 395 | -----BEGIN CERTIFICATE-----
 | 
|---|
| 396 | MIIDHTCCAoagAwIBAgIUUggzW4lLRkMKe1DAR2NKatkMDYwwCwYJKoZIhvcNAQELMFIxEzAR
 | 
|---|
| 397 | BgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxlMRUwEwYKCZImiZPy
 | 
|---|
| 398 | LGQBGQwFc2FtYmExCzAJBgNVBAMMAkNBMCIYDzIwMDkwNzI3MDMzMjE1WhgPMjAzNDA3MjIw
 | 
|---|
| 399 | MzMyMTVaMG0xEzARBgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxl
 | 
|---|
| 400 | MRUwEwYKCZImiZPyLGQBGQwFc2FtYmExDjAMBgNVBAMMBXVzZXJzMRYwFAYDVQQDDA1BZG1p
 | 
|---|
| 401 | bmlzdHJhdG9yMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD0+OL7TQBj0RejbIH1+g5G
 | 
|---|
| 402 | eRaWaM9xF43uE5y7jUHEsi5owhZF5iIoHZeeL6cpDF5y1BZRs0JlA1VqMry1jjKlzFYVEMMF
 | 
|---|
| 403 | xB6esnXhl0Jpip1JkUMMXLOP1m/0dqayuHBWozj9f/cdyCJr0wJIX1Z8Pr+EjYRGPn/MF0xd
 | 
|---|
| 404 | l3JRlwIDAQABo4HSMIHPMA4GA1UdDwEB/wQEAwIFoDAoBgNVHSUEITAfBgcrBgEFAgMEBggr
 | 
|---|
| 405 | BgEFBQcDAgYKKwYBBAGCNxQCAjBIBgNVHREEQTA/oD0GBisGAQUCAqAzMDGgExsRU0FNQkEu
 | 
|---|
| 406 | RVhBTVBMRS5DT02hGjAYoAMCAQGhETAPGw1BZG1pbmlzdHJhdG9yMB8GA1UdIwQYMBaAFMLZ
 | 
|---|
| 407 | ufegDKLZs0VOyFXYK1L6M8oyMB0GA1UdDgQWBBQg81bLyfCA88C2B/BDjXlGuaFaxjAJBgNV
 | 
|---|
| 408 | HRMEAjAAMA0GCSqGSIb3DQEBCwUAA4GBAEf/OSHUDJaGdtWGNuJeqcVYVMwrfBAc0OSwVhz1
 | 
|---|
| 409 | 7/xqKHWo8wIMPkYRtaRHKLNDsF8GkhQPCpVsa6mX/Nt7YQnNvwd+1SBP5E8GvwWw9ZzLJvma
 | 
|---|
| 410 | nk2n89emuayLpVtp00PymrDLRBcNaRjFReQU8f0o509kiVPHduAp3jOiy13l
 | 
|---|
| 411 | -----END CERTIFICATE-----
 | 
|---|
| 412 | EOF
 | 
|---|
| 413 |         close(ADMINCERTFILE);
 | 
|---|
| 414 | 
 | 
|---|
| 415 |         # hxtool issue-certificate --ca-certificate=FILE:$CAFILE,$KEYFILE \
 | 
|---|
| 416 |         # --type="pkinit-client" \
 | 
|---|
| 417 |         # --ms-upn="administrator@samba.example.com" \
 | 
|---|
| 418 |         # --req="PKCS10:$ADMINREQFILE" --certificate="FILE:$ADMINCERTUPNFILE" \
 | 
|---|
| 419 |         # --lifetime="25 years"
 | 
|---|
| 420 |         
 | 
|---|
| 421 |         open(ADMINCERTUPNFILE, ">$admincertupnfile");
 | 
|---|
| 422 |         print ADMINCERTUPNFILE <<EOF;
 | 
|---|
| 423 | -----BEGIN CERTIFICATE-----
 | 
|---|
| 424 | MIIDDzCCAnigAwIBAgIUUp3CJMuNaEaAdPKp3QdNIwG7a4wwCwYJKoZIhvcNAQELMFIxEzAR
 | 
|---|
| 425 | BgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxlMRUwEwYKCZImiZPy
 | 
|---|
| 426 | LGQBGQwFc2FtYmExCzAJBgNVBAMMAkNBMCIYDzIwMDkwNzI3MDMzMzA1WhgPMjAzNDA3MjIw
 | 
|---|
| 427 | MzMzMDVaMG0xEzARBgoJkiaJk/IsZAEZDANjb20xFzAVBgoJkiaJk/IsZAEZDAdleGFtcGxl
 | 
|---|
| 428 | MRUwEwYKCZImiZPyLGQBGQwFc2FtYmExDjAMBgNVBAMMBXVzZXJzMRYwFAYDVQQDDA1BZG1p
 | 
|---|
| 429 | bmlzdHJhdG9yMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD0+OL7TQBj0RejbIH1+g5G
 | 
|---|
| 430 | eRaWaM9xF43uE5y7jUHEsi5owhZF5iIoHZeeL6cpDF5y1BZRs0JlA1VqMry1jjKlzFYVEMMF
 | 
|---|
| 431 | xB6esnXhl0Jpip1JkUMMXLOP1m/0dqayuHBWozj9f/cdyCJr0wJIX1Z8Pr+EjYRGPn/MF0xd
 | 
|---|
| 432 | l3JRlwIDAQABo4HEMIHBMA4GA1UdDwEB/wQEAwIFoDAoBgNVHSUEITAfBgcrBgEFAgMEBggr
 | 
|---|
| 433 | BgEFBQcDAgYKKwYBBAGCNxQCAjA6BgNVHREEMzAxoC8GCisGAQQBgjcUAgOgIQwfYWRtaW5p
 | 
|---|
| 434 | c3RyYXRvckBzYW1iYS5leGFtcGxlLmNvbTAfBgNVHSMEGDAWgBTC2bn3oAyi2bNFTshV2CtS
 | 
|---|
| 435 | +jPKMjAdBgNVHQ4EFgQUIPNWy8nwgPPAtgfwQ415RrmhWsYwCQYDVR0TBAIwADANBgkqhkiG
 | 
|---|
| 436 | 9w0BAQsFAAOBgQBk42+egeUB3Ji2PC55fbt3FNKxvmm2xUUFkV9POK/YR9rajKOwk5jtYSeS
 | 
|---|
| 437 | Zd7J9s//rNFNa7waklFkDaY56+QWTFtdvxfE+KoHaqt6X8u6pqi7p3M4wDKQox+9Dx8yWFyq
 | 
|---|
| 438 | Wfz/8alZ5aMezCQzXJyIaJsCLeKABosSwHcpAFmxlQ==
 | 
|---|
| 439 | -----END CERTIFICATE-----
 | 
|---|
| 440 | EOF
 | 
|---|
| 441 | }
 | 
|---|
| 442 | 
 | 
|---|
| 443 | #
 | 
|---|
| 444 | # provision_raw_prepare() is also used by Samba34.pm!
 | 
|---|
| 445 | #
 | 
|---|
| 446 | sub provision_raw_prepare($$$$$$$)
 | 
|---|
| 447 | {
 | 
|---|
| 448 |         my ($self, $prefix, $server_role, $netbiosname, $netbiosalias, $swiface, $password, $kdc_ipv4) = @_;
 | 
|---|
| 449 |         my $ctx;
 | 
|---|
| 450 | 
 | 
|---|
| 451 |         -d $prefix or mkdir($prefix, 0777) or die("Unable to create $prefix");
 | 
|---|
| 452 |         my $prefix_abs = abs_path($prefix);
 | 
|---|
| 453 | 
 | 
|---|
| 454 |         die ("prefix=''") if $prefix_abs eq "";
 | 
|---|
| 455 |         die ("prefix='/'") if $prefix_abs eq "/";
 | 
|---|
| 456 | 
 | 
|---|
| 457 |         (system("rm -rf $prefix_abs/*") == 0) or die("Unable to clean up");
 | 
|---|
| 458 | 
 | 
|---|
| 459 |         $ctx->{prefix} = $prefix;
 | 
|---|
| 460 |         $ctx->{prefix_abs} = $prefix_abs;
 | 
|---|
| 461 |         $ctx->{server_role} = $server_role;
 | 
|---|
| 462 |         $ctx->{netbiosname} = $netbiosname;
 | 
|---|
| 463 |         $ctx->{netbiosalias} = $netbiosalias;
 | 
|---|
| 464 |         $ctx->{swiface} = $swiface;
 | 
|---|
| 465 |         $ctx->{password} = $password;
 | 
|---|
| 466 |         $ctx->{kdc_ipv4} = $kdc_ipv4;
 | 
|---|
| 467 | 
 | 
|---|
| 468 |         $ctx->{server_loglevel} = 1;
 | 
|---|
| 469 |         $ctx->{username} = "Administrator";
 | 
|---|
| 470 |         $ctx->{domain} = "SAMBADOMAIN";
 | 
|---|
| 471 |         $ctx->{realm} = "SAMBA.EXAMPLE.COM";
 | 
|---|
| 472 |         $ctx->{dnsname} = "samba.example.com";
 | 
|---|
| 473 |         $ctx->{basedn} = "dc=samba,dc=example,dc=com";
 | 
|---|
| 474 | 
 | 
|---|
| 475 |         my $unix_name = ($ENV{USER} or $ENV{LOGNAME} or `whoami`);
 | 
|---|
| 476 |         chomp $unix_name;
 | 
|---|
| 477 |         $ctx->{unix_name} = $unix_name;
 | 
|---|
| 478 |         $ctx->{unix_uid} = $>;
 | 
|---|
| 479 |         $ctx->{unix_gids_str} = $);
 | 
|---|
| 480 |         @{$ctx->{unix_gids}} = split(" ", $ctx->{unix_gids_str});
 | 
|---|
| 481 | 
 | 
|---|
| 482 |         $ctx->{etcdir} = "$prefix_abs/etc";
 | 
|---|
| 483 |         $ctx->{piddir} = "$prefix_abs/pid";
 | 
|---|
| 484 |         $ctx->{smb_conf} = "$ctx->{etcdir}/smb.conf";
 | 
|---|
| 485 |         $ctx->{krb5_conf} = "$ctx->{etcdir}/krb5.conf";
 | 
|---|
| 486 |         $ctx->{privatedir} = "$prefix_abs/private";
 | 
|---|
| 487 |         $ctx->{ncalrpcdir} = "$prefix_abs/ncalrpc";
 | 
|---|
| 488 |         $ctx->{lockdir} = "$prefix_abs/lockdir";
 | 
|---|
| 489 |         $ctx->{winbindd_socket_dir} = "$prefix_abs/winbindd_socket";
 | 
|---|
| 490 |         $ctx->{winbindd_privileged_socket_dir} = "$prefix_abs/winbindd_privileged_socket";
 | 
|---|
| 491 |         $ctx->{ntp_signd_socket_dir} = "$prefix_abs/ntp_signd_socket";
 | 
|---|
| 492 |         $ctx->{nsswrap_passwd} = "$ctx->{etcdir}/passwd";
 | 
|---|
| 493 |         $ctx->{nsswrap_group} = "$ctx->{etcdir}/group";
 | 
|---|
| 494 | 
 | 
|---|
| 495 |         $ctx->{tlsdir} = "$ctx->{privatedir}/tls";
 | 
|---|
| 496 | 
 | 
|---|
| 497 |         $ctx->{ipv4} = "127.0.0.$swiface";
 | 
|---|
| 498 |         $ctx->{interfaces} = "$ctx->{ipv4}/8";
 | 
|---|
| 499 | 
 | 
|---|
| 500 |         $ctx->{localbasedn} = $ctx->{basedn};
 | 
|---|
| 501 |         $ctx->{localbasedn} = "CN=$netbiosname" if $server_role eq "member server";
 | 
|---|
| 502 | 
 | 
|---|
| 503 |         push(@{$ctx->{directories}}, $ctx->{privatedir});
 | 
|---|
| 504 |         push(@{$ctx->{directories}}, $ctx->{etcdir});
 | 
|---|
| 505 |         push(@{$ctx->{directories}}, $ctx->{piddir});
 | 
|---|
| 506 |         push(@{$ctx->{directories}}, $ctx->{ncalrpcdir});
 | 
|---|
| 507 |         push(@{$ctx->{directories}}, $ctx->{lockdir});
 | 
|---|
| 508 | 
 | 
|---|
| 509 |         $ctx->{smb_conf_extra_options} = "";
 | 
|---|
| 510 | 
 | 
|---|
| 511 |         my @provision_options = ();
 | 
|---|
| 512 |         push (@provision_options, "NSS_WRAPPER_PASSWD=\"$ctx->{nsswrap_passwd}\"");
 | 
|---|
| 513 |         push (@provision_options, "NSS_WRAPPER_GROUP=\"$ctx->{nsswrap_group}\"");
 | 
|---|
| 514 |         if (defined($ENV{GDB_PROVISION})) {
 | 
|---|
| 515 |                 push (@provision_options, "gdb --args");
 | 
|---|
| 516 |         }
 | 
|---|
| 517 |         if (defined($ENV{VALGRIND_PROVISION})) {
 | 
|---|
| 518 |                 push (@provision_options, "valgrind");
 | 
|---|
| 519 |         }
 | 
|---|
| 520 |         if (defined($ENV{PYTHON})) {
 | 
|---|
| 521 |                 push (@provision_options, $ENV{PYTHON});
 | 
|---|
| 522 |         }
 | 
|---|
| 523 |         push (@provision_options, "$self->{setupdir}/provision");
 | 
|---|
| 524 |         push (@provision_options, "--configfile=$ctx->{smb_conf}");
 | 
|---|
| 525 |         push (@provision_options, "--host-name=$ctx->{netbiosname}");
 | 
|---|
| 526 |         push (@provision_options, "--host-ip=$ctx->{ipv4}");
 | 
|---|
| 527 |         push (@provision_options, "--quiet");
 | 
|---|
| 528 |         push (@provision_options, "--domain=$ctx->{domain}");
 | 
|---|
| 529 |         push (@provision_options, "--realm=$ctx->{realm}");
 | 
|---|
| 530 |         push (@provision_options, "--adminpass=$ctx->{password}");
 | 
|---|
| 531 |         push (@provision_options, "--krbtgtpass=krbtgt$ctx->{password}");
 | 
|---|
| 532 |         push (@provision_options, "--machinepass=machine$ctx->{password}");
 | 
|---|
| 533 |         push (@provision_options, "--root=$ctx->{unix_name}");
 | 
|---|
| 534 |         push (@provision_options, "--server-role=\"$ctx->{server_role}\"");
 | 
|---|
| 535 | 
 | 
|---|
| 536 |         @{$ctx->{provision_options}} = @provision_options;
 | 
|---|
| 537 | 
 | 
|---|
| 538 |         return $ctx;
 | 
|---|
| 539 | }
 | 
|---|
| 540 | 
 | 
|---|
| 541 | #
 | 
|---|
| 542 | # provision_raw_step1() is also used by Samba34.pm!
 | 
|---|
| 543 | #
 | 
|---|
| 544 | # Step1 creates the basic configuration
 | 
|---|
| 545 | #
 | 
|---|
| 546 | sub provision_raw_step1($$)
 | 
|---|
| 547 | {
 | 
|---|
| 548 |         my ($self, $ctx) = @_;
 | 
|---|
| 549 | 
 | 
|---|
| 550 |         mkdir($_, 0777) foreach (@{$ctx->{directories}});
 | 
|---|
| 551 | 
 | 
|---|
| 552 |         open(CONFFILE, ">$ctx->{smb_conf}")
 | 
|---|
| 553 |                 or die("can't open $ctx->{smb_conf}$?");
 | 
|---|
| 554 |         print CONFFILE "
 | 
|---|
| 555 | [global]
 | 
|---|
| 556 |         netbios name = $ctx->{netbiosname}
 | 
|---|
| 557 |         netbios aliases = $ctx->{netbiosalias}
 | 
|---|
| 558 |         workgroup = $ctx->{domain}
 | 
|---|
| 559 |         realm = $ctx->{realm}
 | 
|---|
| 560 |         private dir = $ctx->{privatedir}
 | 
|---|
| 561 |         pid directory = $ctx->{piddir}
 | 
|---|
| 562 |         ncalrpc dir = $ctx->{ncalrpcdir}
 | 
|---|
| 563 |         lock dir = $ctx->{lockdir}
 | 
|---|
| 564 |         setup directory = $self->{setupdir}
 | 
|---|
| 565 |         modules dir = $self->{bindir}/modules
 | 
|---|
| 566 |         winbindd socket directory = $ctx->{winbindd_socket_dir}
 | 
|---|
| 567 |         winbindd privileged socket directory = $ctx->{winbindd_privileged_socket_dir}
 | 
|---|
| 568 |         ntp signd socket directory = $ctx->{ntp_signd_socket_dir}
 | 
|---|
| 569 |         winbind separator = /
 | 
|---|
| 570 |         name resolve order = bcast
 | 
|---|
| 571 |         interfaces = $ctx->{interfaces}
 | 
|---|
| 572 |         tls dh params file = $ctx->{tlsdir}/dhparms.pem
 | 
|---|
| 573 |         panic action = $RealBin/gdb_backtrace \%PID% \%PROG%
 | 
|---|
| 574 |         wins support = yes
 | 
|---|
| 575 |         server role = $ctx->{server_role}
 | 
|---|
| 576 |         notify:inotify = false
 | 
|---|
| 577 |         ldb:nosync = true
 | 
|---|
| 578 | #We don't want to pass our self-tests if the PAC code is wrong
 | 
|---|
| 579 |         gensec:require_pac = true
 | 
|---|
| 580 |         log level = $ctx->{server_loglevel}
 | 
|---|
| 581 |         lanman auth = Yes
 | 
|---|
| 582 | 
 | 
|---|
| 583 |         # Begin extra options
 | 
|---|
| 584 |         $ctx->{smb_conf_extra_options}
 | 
|---|
| 585 |         # End extra options
 | 
|---|
| 586 | ";
 | 
|---|
| 587 |         close(CONFFILE);
 | 
|---|
| 588 | 
 | 
|---|
| 589 |         $self->mk_keyblobs($ctx->{tlsdir});
 | 
|---|
| 590 | 
 | 
|---|
| 591 |         open(KRB5CONF, ">$ctx->{krb5_conf}")
 | 
|---|
| 592 |                 or die("can't open $ctx->{krb5_conf}$?");
 | 
|---|
| 593 |         print KRB5CONF "
 | 
|---|
| 594 | #Generated krb5.conf for $ctx->{realm}
 | 
|---|
| 595 | 
 | 
|---|
| 596 | [libdefaults]
 | 
|---|
| 597 |  default_realm = $ctx->{realm}
 | 
|---|
| 598 |  dns_lookup_realm = false
 | 
|---|
| 599 |  dns_lookup_kdc = false
 | 
|---|
| 600 |  ticket_lifetime = 24h
 | 
|---|
| 601 |  forwardable = yes
 | 
|---|
| 602 | 
 | 
|---|
| 603 | [realms]
 | 
|---|
| 604 |  $ctx->{realm} = {
 | 
|---|
| 605 |   kdc = $ctx->{kdc_ipv4}:88
 | 
|---|
| 606 |   admin_server = $ctx->{kdc_ipv4}:88
 | 
|---|
| 607 |   default_domain = $ctx->{dnsname}
 | 
|---|
| 608 |  }
 | 
|---|
| 609 |  $ctx->{dnsname} = {
 | 
|---|
| 610 |   kdc = $ctx->{kdc_ipv4}:88
 | 
|---|
| 611 |   admin_server = $ctx->{kdc_ipv4}:88
 | 
|---|
| 612 |   default_domain = $ctx->{dnsname}
 | 
|---|
| 613 |  }
 | 
|---|
| 614 |  $ctx->{domain} = {
 | 
|---|
| 615 |   kdc = $ctx->{kdc_ipv4}:88
 | 
|---|
| 616 |   admin_server = $ctx->{kdc_ipv4}:88
 | 
|---|
| 617 |   default_domain = $ctx->{dnsname}
 | 
|---|
| 618 |  }
 | 
|---|
| 619 | 
 | 
|---|
| 620 | [appdefaults]
 | 
|---|
| 621 |         pkinit_anchors = FILE:$ctx->{tlsdir}/ca.pem
 | 
|---|
| 622 | 
 | 
|---|
| 623 | [kdc]
 | 
|---|
| 624 |         enable-pkinit = true
 | 
|---|
| 625 |         pkinit_identity = FILE:$ctx->{tlsdir}/kdc.pem,$ctx->{tlsdir}/key.pem
 | 
|---|
| 626 |         pkinit_anchors = FILE:$ctx->{tlsdir}/ca.pem
 | 
|---|
| 627 | 
 | 
|---|
| 628 | [domain_realm]
 | 
|---|
| 629 |  .$ctx->{dnsname} = $ctx->{realm}
 | 
|---|
| 630 | ";
 | 
|---|
| 631 |         close(KRB5CONF);
 | 
|---|
| 632 | 
 | 
|---|
| 633 |         open(PWD, ">$ctx->{nsswrap_passwd}");
 | 
|---|
| 634 |         print PWD "
 | 
|---|
| 635 | root:x:0:0:root gecos:$ctx->{prefix_abs}:/bin/false
 | 
|---|
| 636 | $ctx->{unix_name}:x:$ctx->{unix_uid}:@{$ctx->{unix_gids}}[0]:$ctx->{unix_name} gecos:$ctx->{prefix_abs}:/bin/false
 | 
|---|
| 637 | nobody:x:65534:65533:nobody gecos:$ctx->{prefix_abs}:/bin/false
 | 
|---|
| 638 | ";
 | 
|---|
| 639 |         close(PWD);
 | 
|---|
| 640 | 
 | 
|---|
| 641 |         open(GRP, ">$ctx->{nsswrap_group}");
 | 
|---|
| 642 |         print GRP "
 | 
|---|
| 643 | root:x:0:
 | 
|---|
| 644 | wheel:x:10:
 | 
|---|
| 645 | users:x:100:
 | 
|---|
| 646 | nobody:x:65533:
 | 
|---|
| 647 | nogroup:x:65534:nobody
 | 
|---|
| 648 | ";
 | 
|---|
| 649 |         close(GRP);
 | 
|---|
| 650 | 
 | 
|---|
| 651 |         my $configuration = "--configfile=$ctx->{smb_conf}";
 | 
|---|
| 652 | 
 | 
|---|
| 653 | #Ensure the config file is valid before we start
 | 
|---|
| 654 |         my $testparm = $self->bindir_path("testparm");
 | 
|---|
| 655 |         if (system("$testparm $configuration -v --suppress-prompt >/dev/null 2>&1") != 0) {
 | 
|---|
| 656 |                 system("$testparm -v --suppress-prompt $configuration >&2");
 | 
|---|
| 657 |                 die("Failed to create a valid smb.conf configuration $testparm!");
 | 
|---|
| 658 |         }
 | 
|---|
| 659 | 
 | 
|---|
| 660 |         (system("($testparm $configuration -v --suppress-prompt --parameter-name=\"netbios name\" --section-name=global 2> /dev/null | grep -i \"^$ctx->{netbiosname}\" ) >/dev/null 2>&1") == 0) or die("Failed to create a valid smb.conf configuration! $self->{bindir}/testparm $configuration -v --suppress-prompt --parameter-name=\"netbios name\" --section-name=global");
 | 
|---|
| 661 | 
 | 
|---|
| 662 |         my $ret = {
 | 
|---|
| 663 |                 KRB5_CONFIG => $ctx->{krb5_conf},
 | 
|---|
| 664 |                 PIDDIR => $ctx->{piddir},
 | 
|---|
| 665 |                 SERVER => $ctx->{netbiosname},
 | 
|---|
| 666 |                 SERVER_IP => $ctx->{ipv4},
 | 
|---|
| 667 |                 NETBIOSNAME => $ctx->{netbiosname},
 | 
|---|
| 668 |                 NETBIOSALIAS => $ctx->{netbiosalias},
 | 
|---|
| 669 |                 DOMAIN => $ctx->{domain},
 | 
|---|
| 670 |                 USERNAME => $ctx->{username},
 | 
|---|
| 671 |                 REALM => $ctx->{realm},
 | 
|---|
| 672 |                 PASSWORD => $ctx->{password},
 | 
|---|
| 673 |                 LDAPDIR => $ctx->{ldapdir},
 | 
|---|
| 674 |                 WINBINDD_SOCKET_DIR => $ctx->{winbindd_socket_dir},
 | 
|---|
| 675 |                 NCALRPCDIR => $ctx->{ncalrpcdir},
 | 
|---|
| 676 |                 LOCKDIR => $ctx->{lockdir},
 | 
|---|
| 677 |                 SERVERCONFFILE => $ctx->{smb_conf},
 | 
|---|
| 678 |                 CONFIGURATION => $configuration,
 | 
|---|
| 679 |                 SOCKET_WRAPPER_DEFAULT_IFACE => $ctx->{swiface},
 | 
|---|
| 680 |                 NSS_WRAPPER_PASSWD => $ctx->{nsswrap_passwd},
 | 
|---|
| 681 |                 NSS_WRAPPER_GROUP => $ctx->{nsswrap_group},
 | 
|---|
| 682 |                 SAMBA_TEST_FIFO => "$ctx->{prefix}/samba_test.fifo",
 | 
|---|
| 683 |                 SAMBA_TEST_LOG => "$ctx->{prefix}/samba_test.log",
 | 
|---|
| 684 |                 SAMBA_TEST_LOG_POS => 0,
 | 
|---|
| 685 |         };
 | 
|---|
| 686 | 
 | 
|---|
| 687 |         return $ret;
 | 
|---|
| 688 | }
 | 
|---|
| 689 | 
 | 
|---|
| 690 | #
 | 
|---|
| 691 | # provision_raw_step2() is also used by Samba34.pm!
 | 
|---|
| 692 | #
 | 
|---|
| 693 | # Step2 runs the provision script
 | 
|---|
| 694 | #
 | 
|---|
| 695 | sub provision_raw_step2($$$)
 | 
|---|
| 696 | {
 | 
|---|
| 697 |         my ($self, $ctx, $ret) = @_;
 | 
|---|
| 698 | 
 | 
|---|
| 699 |         my $provision_cmd = join(" ", @{$ctx->{provision_options}});
 | 
|---|
| 700 |         (system($provision_cmd) == 0) or die("Unable to provision: \n$provision_cmd\n");
 | 
|---|
| 701 | 
 | 
|---|
| 702 |         return $ret;
 | 
|---|
| 703 | }
 | 
|---|
| 704 | 
 | 
|---|
| 705 | sub provision($$$$$$$)
 | 
|---|
| 706 | {
 | 
|---|
| 707 |         my ($self, $prefix, $server_role, $netbiosname, $netbiosalias, $swiface, $password, $kdc_ipv4) = @_;
 | 
|---|
| 708 | 
 | 
|---|
| 709 |         my $ctx = $self->provision_raw_prepare($prefix, $server_role,
 | 
|---|
| 710 |                                                $netbiosname, $netbiosalias,
 | 
|---|
| 711 |                                                $swiface, $password, $kdc_ipv4);
 | 
|---|
| 712 | 
 | 
|---|
| 713 |         $ctx->{tmpdir} = "$ctx->{prefix_abs}/tmp";
 | 
|---|
| 714 |         push(@{$ctx->{directories}}, "$ctx->{tmpdir}");
 | 
|---|
| 715 |         push(@{$ctx->{directories}}, "$ctx->{tmpdir}/test1");
 | 
|---|
| 716 |         push(@{$ctx->{directories}}, "$ctx->{tmpdir}/test2");
 | 
|---|
| 717 | 
 | 
|---|
| 718 |         $ctx->{smb_conf_extra_options} = "
 | 
|---|
| 719 | 
 | 
|---|
| 720 |         max xmit = 32K
 | 
|---|
| 721 |         server max protocol = SMB2
 | 
|---|
| 722 | 
 | 
|---|
| 723 | [tmp]
 | 
|---|
| 724 |         path = $ctx->{tmpdir}
 | 
|---|
| 725 |         read only = no
 | 
|---|
| 726 |         posix:sharedelay = 100000
 | 
|---|
| 727 |         posix:eadb = $ctx->{lockdir}/eadb.tdb
 | 
|---|
| 728 |         posix:oplocktimeout = 3
 | 
|---|
| 729 |         posix:writetimeupdatedelay = 500000
 | 
|---|
| 730 | 
 | 
|---|
| 731 | [test1]
 | 
|---|
| 732 |         path = $ctx->{tmpdir}/test1
 | 
|---|
| 733 |         read only = no
 | 
|---|
| 734 |         posix:sharedelay = 100000
 | 
|---|
| 735 |         posix:eadb = $ctx->{lockdir}/eadb.tdb
 | 
|---|
| 736 |         posix:oplocktimeout = 3
 | 
|---|
| 737 |         posix:writetimeupdatedelay = 500000
 | 
|---|
| 738 | 
 | 
|---|
| 739 | [test2]
 | 
|---|
| 740 |         path = $ctx->{tmpdir}/test2
 | 
|---|
| 741 |         read only = no
 | 
|---|
| 742 |         posix:sharedelay = 100000
 | 
|---|
| 743 |         posix:eadb = $ctx->{lockdir}/eadb.tdb
 | 
|---|
| 744 |         posix:oplocktimeout = 3
 | 
|---|
| 745 |         posix:writetimeupdatedelay = 500000
 | 
|---|
| 746 | 
 | 
|---|
| 747 | [cifs]
 | 
|---|
| 748 |         read only = no
 | 
|---|
| 749 |         ntvfs handler = cifs
 | 
|---|
| 750 |         cifs:server = $ctx->{netbiosname}
 | 
|---|
| 751 |         cifs:share = tmp
 | 
|---|
| 752 | #There is no username specified here, instead the client is expected
 | 
|---|
| 753 | #to log in with kerberos, and the serverwill use delegated credentials.
 | 
|---|
| 754 | 
 | 
|---|
| 755 | [simple]
 | 
|---|
| 756 |         path = $ctx->{tmpdir}
 | 
|---|
| 757 |         read only = no
 | 
|---|
| 758 |         ntvfs handler = simple
 | 
|---|
| 759 | 
 | 
|---|
| 760 | [sysvol]
 | 
|---|
| 761 |         path = $ctx->{lockdir}/sysvol
 | 
|---|
| 762 |         read only = yes
 | 
|---|
| 763 | 
 | 
|---|
| 764 | [netlogon]
 | 
|---|
| 765 |         path = $ctx->{lockdir}/sysvol/$ctx->{dnsname}/scripts
 | 
|---|
| 766 |         read only = no
 | 
|---|
| 767 | 
 | 
|---|
| 768 | [cifsposix]
 | 
|---|
| 769 |         copy = simple
 | 
|---|
| 770 |         ntvfs handler = cifsposix
 | 
|---|
| 771 | ";
 | 
|---|
| 772 | 
 | 
|---|
| 773 |         if (defined($self->{ldap})) {
 | 
|---|
| 774 |                 $ctx->{ldapdir} = "$ctx->{privatedir}/ldap";
 | 
|---|
| 775 |                 push(@{$ctx->{directories}}, "$ctx->{ldapdir}");
 | 
|---|
| 776 | 
 | 
|---|
| 777 |                 my $ldap_uri= "$ctx->{ldapdir}/ldapi";
 | 
|---|
| 778 |                 $ldap_uri =~ s|/|%2F|g;
 | 
|---|
| 779 |                 $ldap_uri = "ldapi://$ldap_uri";
 | 
|---|
| 780 |                 $ctx->{ldap_uri} = $ldap_uri;
 | 
|---|
| 781 |         }
 | 
|---|
| 782 | 
 | 
|---|
| 783 |         my $ret = $self->provision_raw_step1($ctx);
 | 
|---|
| 784 | 
 | 
|---|
| 785 |         if (defined($self->{ldap})) {
 | 
|---|
| 786 |                 $ret->{LDAP_URI} = $ctx->{ldap_uri};
 | 
|---|
| 787 |                 push (@{$ctx->{provision_options}}, "--ldap-backend-type=" . $self->{ldap});
 | 
|---|
| 788 |                 if ($self->{ldap} eq "openldap") {
 | 
|---|
| 789 |                         push (@{$ctx->{provision_options}}, "--slapd-path=" . $ENV{OPENLDAP_SLAPD});
 | 
|---|
| 790 |                         ($ret->{SLAPD_CONF_D}, $ret->{OPENLDAP_PIDFILE}) = $self->mk_openldap($ctx->{ldapdir}) or die("Unable to create openldap directories");
 | 
|---|
| 791 | 
 | 
|---|
| 792 |                 } elsif ($self->{ldap} eq "fedora-ds") {
 | 
|---|
| 793 |                         push (@{$ctx->{provision_options}}, "--slapd-path=" . "$ENV{FEDORA_DS_ROOT}/sbin/ns-slapd");
 | 
|---|
| 794 |                         push (@{$ctx->{provision_options}}, "--setup-ds-path=" . "$ENV{FEDORA_DS_ROOT}/sbin/setup-ds.pl");
 | 
|---|
| 795 |                         ($ret->{FEDORA_DS_DIR}, $ret->{FEDORA_DS_PIDFILE}) = $self->mk_fedora_ds($ctx->{ldapdir}) or die("Unable to create fedora ds directories");
 | 
|---|
| 796 |                 }
 | 
|---|
| 797 | 
 | 
|---|
| 798 |         }
 | 
|---|
| 799 | 
 | 
|---|
| 800 |         $ret = $self->provision_raw_step2($ctx, $ret);
 | 
|---|
| 801 | 
 | 
|---|
| 802 |         return $ret;
 | 
|---|
| 803 | }
 | 
|---|
| 804 | 
 | 
|---|
| 805 | sub provision_member($$$)
 | 
|---|
| 806 | {
 | 
|---|
| 807 |         my ($self, $prefix, $dcvars) = @_;
 | 
|---|
| 808 |         print "PROVISIONING MEMBER...";
 | 
|---|
| 809 | 
 | 
|---|
| 810 |         my $ret = $self->provision($prefix,
 | 
|---|
| 811 |                                    "member server",
 | 
|---|
| 812 |                                    "localmember3",
 | 
|---|
| 813 |                                    "localmember",
 | 
|---|
| 814 |                                    3,
 | 
|---|
| 815 |                                    "localmemberpass",
 | 
|---|
| 816 |                                    $dcvars->{SERVER_IP});
 | 
|---|
| 817 | 
 | 
|---|
| 818 |         $ret or die("Unable to provision");
 | 
|---|
| 819 | 
 | 
|---|
| 820 |         my $net = $self->bindir_path("net");
 | 
|---|
| 821 |         my $cmd = "";
 | 
|---|
| 822 |         $cmd .= "SOCKET_WRAPPER_DEFAULT_IFACE=\"$ret->{SOCKET_WRAPPER_DEFAULT_IFACE}\" ";
 | 
|---|
| 823 |         $cmd .= "KRB5_CONFIG=\"$ret->{KRB5_CONFIG}\" ";
 | 
|---|
| 824 |         $cmd .= "$net join $ret->{CONFIGURATION} $dcvars->{DOMAIN} member";
 | 
|---|
| 825 |         $cmd .= " -U$dcvars->{USERNAME}\%$dcvars->{PASSWORD}";
 | 
|---|
| 826 | 
 | 
|---|
| 827 |         system($cmd) == 0 or die("Join failed\n$cmd");
 | 
|---|
| 828 | 
 | 
|---|
| 829 |         $ret->{DC_SERVER} = $dcvars->{SERVER};
 | 
|---|
| 830 |         $ret->{DC_SERVER_IP} = $dcvars->{SERVER_IP};
 | 
|---|
| 831 |         $ret->{DC_NETBIOSNAME} = $dcvars->{NETBIOSNAME};
 | 
|---|
| 832 |         $ret->{DC_NETBIOSALIAS} = $dcvars->{NETBIOSALIAS};
 | 
|---|
| 833 |         $ret->{DC_USERNAME} = $dcvars->{USERNAME};
 | 
|---|
| 834 |         $ret->{DC_PASSWORD} = $dcvars->{PASSWORD};
 | 
|---|
| 835 | 
 | 
|---|
| 836 |         return $ret;
 | 
|---|
| 837 | }
 | 
|---|
| 838 | 
 | 
|---|
| 839 | sub provision_dc($$)
 | 
|---|
| 840 | {
 | 
|---|
| 841 |         my ($self, $prefix) = @_;
 | 
|---|
| 842 | 
 | 
|---|
| 843 |         print "PROVISIONING DC...";
 | 
|---|
| 844 |         my $ret = $self->provision($prefix,
 | 
|---|
| 845 |                                    "domain controller",
 | 
|---|
| 846 |                                    "localdc1",
 | 
|---|
| 847 |                                    "localdc",
 | 
|---|
| 848 |                                    1,
 | 
|---|
| 849 |                                    "localdcpass",
 | 
|---|
| 850 |                                    "127.0.0.1");
 | 
|---|
| 851 | 
 | 
|---|
| 852 |         $self->add_wins_config("$prefix/private") or 
 | 
|---|
| 853 |                 die("Unable to add wins configuration");
 | 
|---|
| 854 | 
 | 
|---|
| 855 |         return $ret;
 | 
|---|
| 856 | }
 | 
|---|
| 857 | 
 | 
|---|
| 858 | sub teardown_env($$)
 | 
|---|
| 859 | {
 | 
|---|
| 860 |         my ($self, $envvars) = @_;
 | 
|---|
| 861 |         my $pid;
 | 
|---|
| 862 | 
 | 
|---|
| 863 |         close(DATA);
 | 
|---|
| 864 | 
 | 
|---|
| 865 |         if (-f "$envvars->{PIDDIR}/samba.pid" ) {
 | 
|---|
| 866 |                 open(IN, "<$envvars->{PIDDIR}/samba.pid") or die("unable to open server pid file");
 | 
|---|
| 867 |                 $pid = <IN>;
 | 
|---|
| 868 |                 close(IN);
 | 
|---|
| 869 | 
 | 
|---|
| 870 |                 # Give the process 20 seconds to exit.  gcov needs
 | 
|---|
| 871 |                 # this time to write out the covarge data
 | 
|---|
| 872 |                 my $count = 0;
 | 
|---|
| 873 |                 until (kill(0, $pid) == 0) {
 | 
|---|
| 874 |                     # if no process sucessfully signalled, then we are done
 | 
|---|
| 875 |                     sleep(1);
 | 
|---|
| 876 |                     $count++;
 | 
|---|
| 877 |                     last if $count > 20;
 | 
|---|
| 878 |                 }
 | 
|---|
| 879 |                 
 | 
|---|
| 880 |                 # If it is still around, kill it
 | 
|---|
| 881 |                 if ($count > 20) {
 | 
|---|
| 882 |                     print "server process $pid took more than $count seconds to exit, killing\n";
 | 
|---|
| 883 |                     kill 9, $pid;
 | 
|---|
| 884 |                 }
 | 
|---|
| 885 |         }
 | 
|---|
| 886 | 
 | 
|---|
| 887 |         my $failed = $? >> 8;
 | 
|---|
| 888 | 
 | 
|---|
| 889 |         $self->slapd_stop($envvars) if ($self->{ldap});
 | 
|---|
| 890 | 
 | 
|---|
| 891 |         print $self->getlog_env($envvars);
 | 
|---|
| 892 | 
 | 
|---|
| 893 |         return $failed;
 | 
|---|
| 894 | }
 | 
|---|
| 895 | 
 | 
|---|
| 896 | sub getlog_env($$)
 | 
|---|
| 897 | {
 | 
|---|
| 898 |         my ($self, $envvars) = @_;
 | 
|---|
| 899 |         my $title = "SAMBA LOG of: $envvars->{NETBIOSNAME}\n";
 | 
|---|
| 900 |         my $out = $title;
 | 
|---|
| 901 | 
 | 
|---|
| 902 |         open(LOG, "<$envvars->{SAMBA_TEST_LOG}");
 | 
|---|
| 903 | 
 | 
|---|
| 904 |         seek(LOG, $envvars->{SAMBA_TEST_LOG_POS}, SEEK_SET);
 | 
|---|
| 905 |         while (<LOG>) {
 | 
|---|
| 906 |                 $out .= $_;
 | 
|---|
| 907 |         }
 | 
|---|
| 908 |         $envvars->{SAMBA_TEST_LOG_POS} = tell(LOG);
 | 
|---|
| 909 |         close(LOG);
 | 
|---|
| 910 | 
 | 
|---|
| 911 |         return "" if $out eq $title;
 | 
|---|
| 912 |  
 | 
|---|
| 913 |         return $out;
 | 
|---|
| 914 | }
 | 
|---|
| 915 | 
 | 
|---|
| 916 | sub check_env($$)
 | 
|---|
| 917 | {
 | 
|---|
| 918 |         my ($self, $envvars) = @_;
 | 
|---|
| 919 | 
 | 
|---|
| 920 |         return 1 if (-p $envvars->{SAMBA_TEST_FIFO});
 | 
|---|
| 921 | 
 | 
|---|
| 922 |         print $self->getlog_env($envvars);
 | 
|---|
| 923 | 
 | 
|---|
| 924 |         return 0;
 | 
|---|
| 925 | }
 | 
|---|
| 926 | 
 | 
|---|
| 927 | sub setup_env($$$)
 | 
|---|
| 928 | {
 | 
|---|
| 929 |         my ($self, $envname, $path) = @_;
 | 
|---|
| 930 | 
 | 
|---|
| 931 |         if ($envname eq "dc") {
 | 
|---|
| 932 |                 return $self->setup_dc("$path/dc");
 | 
|---|
| 933 |         } elsif ($envname eq "member") {
 | 
|---|
| 934 |                 if (not defined($self->{vars}->{dc})) {
 | 
|---|
| 935 |                         $self->setup_dc("$path/dc");
 | 
|---|
| 936 |                 }
 | 
|---|
| 937 |                 return $self->setup_member("$path/member", $self->{vars}->{dc});
 | 
|---|
| 938 |         } else {
 | 
|---|
| 939 |                 die("Samba4 can't provide environment '$envname'");
 | 
|---|
| 940 |         }
 | 
|---|
| 941 | }
 | 
|---|
| 942 | 
 | 
|---|
| 943 | sub setup_member($$$$)
 | 
|---|
| 944 | {
 | 
|---|
| 945 |         my ($self, $path, $dc_vars) = @_;
 | 
|---|
| 946 | 
 | 
|---|
| 947 |         my $env = $self->provision_member($path, $dc_vars);
 | 
|---|
| 948 | 
 | 
|---|
| 949 |         $self->check_or_start($env, ($ENV{SMBD_MAXTIME} or 7500));
 | 
|---|
| 950 | 
 | 
|---|
| 951 |         $self->wait_for_start($env);
 | 
|---|
| 952 | 
 | 
|---|
| 953 |         return $env;
 | 
|---|
| 954 | }
 | 
|---|
| 955 | 
 | 
|---|
| 956 | sub setup_dc($$)
 | 
|---|
| 957 | {
 | 
|---|
| 958 |         my ($self, $path) = @_;
 | 
|---|
| 959 | 
 | 
|---|
| 960 |         my $env = $self->provision_dc($path);
 | 
|---|
| 961 | 
 | 
|---|
| 962 |         $self->check_or_start($env, 
 | 
|---|
| 963 |                 ($ENV{SMBD_MAXTIME} or 7500));
 | 
|---|
| 964 | 
 | 
|---|
| 965 |         $self->wait_for_start($env);
 | 
|---|
| 966 | 
 | 
|---|
| 967 |         $self->{vars}->{dc} = $env;
 | 
|---|
| 968 | 
 | 
|---|
| 969 |         return $env;
 | 
|---|
| 970 | }
 | 
|---|
| 971 | 
 | 
|---|
| 972 | sub stop($)
 | 
|---|
| 973 | {
 | 
|---|
| 974 |         my ($self) = @_;
 | 
|---|
| 975 | }
 | 
|---|
| 976 | 
 | 
|---|
| 977 | 1;
 | 
|---|