summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
| * r22845: Modified and extended the winbindd cache validation code:Michael Adam2007-05-141-137/+283
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Replaced signal catching/longjmp magic by a fork: Let the child do the actual validation of the entries. Exit code and signals are intercepted by waitpid. * Fix logic so that also encounter of an unknown key in the tdb leads to an error. * Extended status of validation is kept in a (as yet simple) stuct and communicated over a pipe from child to parent. * Added two validation_ functions for two new keys. The call of winbindd_validate_cache is still commented out in the winbindd main loop. But I am currently testing it and so far it seems to work fine. The next step in my plan is to generalize the validation mechanism to a tdb_open_log_validate function in lib/util_tdb.c. There ist nothing very special about the cache tdb here, and this might be useful elsewhere... Michael
| * r22844: Introduce const DATA_BLOB data_blob_null = { NULL, 0, NULL }; andVolker Lendecke2007-05-1431-156/+160
| | | | | | | | replace all data_blob(NULL, 0) calls.
| * r22841: Add comment to endif statement.Lars Müller2007-05-141-1/+1
| |
| * r22840: Add -pie support to Python's setup.py. This should fix build of ↵Alexander Bokovoy2007-05-141-0/+2
| | | | | | | | python libs on recent distributions that take care of security.
| * r22839: Fix endif comment.Lars Müller2007-05-141-1/+1
| |
| * r22828: Fix typo. Bugzilla #4589.James Peach2007-05-131-1/+1
| |
| * r22826: Fix the gettimeofday test that I broke in rev 22821.James Peach2007-05-131-3/+2
| |
| * r22821: Replace unnecessary AC_TRY_RUN with AC_TRY_LINK. Fixes bug #2287.James Peach2007-05-131-3/+4
| |
| * r22820: Move FAM libraries from smbd to vfs_fam_notify. Should fix bugzilla ↵James Peach2007-05-132-4/+6
| | | | | | | | #4426.
| * r22819: Fix Bug 4613. We just dumped the must change & friends. With theVolker Lendecke2007-05-121-0/+24
| | | | | | | | | | pass_last_changed == 0 we now return "Change now!" instead of "Change never"
| * r22812: Fix bug #3024 (and also the group varient). Patch fromJeremy Allison2007-05-122-6/+17
| | | | | | | | | | Johann Hanne <jhml@gmx.net> and also Kaya Bekiro?lu <kaya.bekiroglu@isilon.com> Jeremy.
| * r22805: Inform in examples/pdb about the location of the external support forLars Müller2007-05-111-0/+4
| | | | | | | | the SQL backends.
| * r22803: Add some more flesh to the GPO security filtering (still very basic).Günther Deschner2007-05-111-1/+151
| | | | | | | | Guenther
| * r22802: Add dummy gpo_apply_security_filtering() call.Günther Deschner2007-05-113-4/+41
| | | | | | | | Guenther
| * r22801: Pass down the token to add_gplink_to_gpo_list().Günther Deschner2007-05-111-4/+14
| | | | | | | | Guenther
| * r22800: Add GPO_SID_TOKEN and an LDAP function to get tokensids from the ↵Günther Deschner2007-05-114-2/+180
| | | | | | | | | | | | tokenGroup attribute. Guenther
| * r22799: Fix the build.Günther Deschner2007-05-111-1/+1
| | | | | | | | Guenther
| * r22798: Add the "apply group policy" access bit (as seen in type 0x05 ↵Günther Deschner2007-05-112-1/+5
| | | | | | | | | | | | | | | | ALLOWED OBJECT ACEs). Guenther
| * r22797: We are only interested in the DACL of the security descriptor, so ↵Günther Deschner2007-05-115-23/+69
| | | | | | | | | | | | | | | | search with the SD_FLAGS control. Guenther
| * r22796: Add security descriptor to GROUP_POLICY_OBJECT structure (in ↵Günther Deschner2007-05-113-2/+6
| | | | | | | | | | | | | | | | preparation of adding GPO security filtering for libgpo). Guenther
| * r22794: Add "debug_state" and "silent" to pam_winbind.conf template. Honor ↵Günther Deschner2007-05-112-0/+8
| | | | | | | | | | | | | | | | the silent argument when parsing pam configuration file options. Guenther
| * r22787: More from Karolin: Make map_unix_group() static to net_sam.c, add "netVolker Lendecke2007-05-112-64/+118
| | | | | | | | sam unmapunixgroup"
| * r22786: Some cleanup by Karolin Seeger: Remove unused pdb_find_alias, and changeVolker Lendecke2007-05-115-58/+29
| | | | | | | | | | | | return values of some alias-releated pdb functions from BOOL to NTSTATUS Thanks :-)
| * r22784: fixed change notify for delete on closeAndrew Tridgell2007-05-111-0/+4
| |
| * r22779: Patch for not prompting for password on cifs mounts when "sec=none"Steve French2007-05-101-10/+61
| | | | | | | | specified
| * r22777: Fix for [Bug 4543] - POSIX ACL support on FreeBSD.Michael Adam2007-05-102-0/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | This adds vfs_posixacl to the list of static modules and makes use of HAVE_ACL_GET_PERM_NP. This is just a quick fix. FreeBSD acl support is still hardcoded in configure.in, but actually this could be detected in a unified test for freebsd, linux, *, as suggested in the bugreport. This has still to be checked and elaborated. Michael
| * r22775: For the cluster code I've developed a wrapper around tdb to put ↵Volker Lendecke2007-05-106-1/+755
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | different database backends in place dynamically. The main abstractions are db_context and db_record, it should be mainly self-describing, see include/dbwrap.h. You open the db just as you would open a tdb, this time with db_open(). If you want to fetch a record, just do the db->fetch() call, if you want to do operations on it, you need to get it with fetch_locked(). I added dbwrap_file.c (not heavily tested lately) as an example for what can be done with that abstraction, uses a file per key. So if anybody is willing to shape that up, we might have a chance on reiserfs again.... :-) This abstraction works fine for brlock.tdb, locking.tdb, connections.tdb and sessionid.tdb. It should work fine for the others as well, I just did not yet get around to convert them. If nobody loudly screams NO, then I will import the code that uses this soon. Volker
| * r22773: - Clean up the the rest of the cruft from my earlier work on the ↵Derrell Lipman2007-05-101-11/+1
| | | | | | | | | | | | readahead() missing declaration problem.
| * r22772: - Still working on the fact that readahead() is not declared (on at ↵Derrell Lipman2007-05-104-13/+11
| | | | | | | | | | | | | | | | | | | | least one OS) but is available for linking. Instead of running configure tests with -Werror-implicit-function-declaration in developer mode (which may lead to different library functions being used in developer mode than when not in developer mode), add tests for whether readahead is declared. If not, provide a replacement declaration in lib/replace.
| * r22771: One liner fix for idmap_ldapSimo Sorce2007-05-091-0/+1
| | | | | | | | | | | | | | Fixes the strange behavior we were seeing about idmap_ldap creating a new connection for each query. Jerry we need this in for 3.0.25
| * r22767: Argl. Typed in 'svn ci' in the wrong branch. Revert.Volker Lendecke2007-05-093-29/+38
| |
| * r22766: Merge from 3_0:Volker Lendecke2007-05-093-38/+29
| | | | | | | | | | | | | | | | r22412 | obnox | 2007-04-20 14:23:36 +0200 (Fr, 20 Apr 2007) | 5 lines Add a "deletelocalgroup" subcommand to net sam. Thanks to Karolin Seeger <ks@sernet.de>.
| * r22765: Fix from Alison Winters <alisonw@sgi.com> for missing returnJeremy Allison2007-05-091-0/+1
| | | | | | | | | | in sendfilereadbraw. Jeremy.
| * r22761: This introduces lib/conn_tdb.c with two main functions: ↵Volker Lendecke2007-05-0815-241/+210
| | | | | | | | | | | | | | | | | | connections_traverse and connections_forall. This centralizes all the routines that did individual tdb_open("connections.tdb") and direct tdb_traverse. Volker
| * r22759: sync lib/talloc with samba4Stefan Metzmacher2007-05-088-16/+103
| | | | | | | | metze
| * r22755: Second half of r22754. As it stands now, string_replace expects aVolker Lendecke2007-05-071-10/+8
| | | | | | | | | | | | pstring. Give it one, although I hate putting it in :-) Thanks to Tom Bork! :-)
| * r22754: When processing a string, ensure we don't write one pastJeremy Allison2007-05-071-6/+15
| | | | | | | | | | | | | | | | the terminating NULL if we've already processed the null in iconv. Jerry, once I get confirmation from Thomas Bork this needs to be in 3.0.25 final. Tests fine with valgrind here. Jeremy.
| * r22751: Next step for the cluster merge: sessionid.tdb should contain a 'structVolker Lendecke2007-05-076-25/+25
| | | | | | | | server_id' instead of a 'uint32 pid'
| * r22747: Fix some C++ warningsVolker Lendecke2007-05-078-19/+18
| |
| * r22745: Add local groups to the --required-membership-sid test. This needsVolker Lendecke2007-05-072-91/+64
| | | | | | | | | | merging to 3_0_26 once Michael's net conf changes have been merged. It depends on token_utils.c.
| * r22744: Fix a valgrind error. parse_domain_username does not necessarily fill inVolker Lendecke2007-05-071-0/+3
| | | | | | | | the domain.
| * r22740: Move debug_*_user_token to token_utils.cVolker Lendecke2007-05-072-47/+47
| |
| * r22739: Make prototypes in include/util_tdb.h of some functions fromMichael Adam2007-05-071-6/+6
| | | | | | | | | | | | lib/util_tdb.c exactly match the definitions. (There were some [u]int_32_t instead of [u]int32, which made a gcc 2.95 on an old AIX without system [u]int32[_t] types complain...)
| * r22738: Fix a debug message.Volker Lendecke2007-05-071-1/+2
| | | | | | | | | | | | | | | | Günther, please check this! Thanks, Volker
| * r22737: Fix crash bug (info3 is now talloced).Günther Deschner2007-05-071-1/+1
| | | | | | | | Guenther
| * r22736: Start to merge the low-hanging fruit from the now 7000-line cluster ↵Volker Lendecke2007-05-0737-160/+149
| | | | | | | | | | | | | | | | | | patch. This changes "struct process_id" to "struct server_id", keeping both is just too much hassle. No functional change (I hope ;-)) Volker
| * r22732: - Testing of libsmbclient against Vista revealed what is likely a bug inDerrell Lipman2007-05-073-1/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Vista. Vista provides a plethora of kludges to simulate older versions of Windows. The kludges are in the form of shortcuts (or more likely symbolic links, but I don't know enough about Vista to determine that definitively) and in most cases, attempts to access them get back an "access denied" error. On one particular folder, however, "<share>/Users/All Users", it returns an unknown (to ethereal and the Samba3 code) NT status code: 0x8000002d. Although this code does not have a high byte of 0xc0 indicating that it is an error, it appears to be an alternate form of "access denied". Without this patch, libsmbclient times out on an attempt to enumerate that folder rather than returning an error to the caller. This patch corrects that problem.
| * r22731: - Fix bug #4594.Derrell Lipman2007-05-0710-102/+141
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | configure.in determines if -Werror-implicit-function-declaration is available, and if so it enables that flag if --enable-developer is specified. Since the configure tests themselves did not use that flag, it was possible for a configure test to succeed, followed by a failed compilation due to a facility being available but not having a proper declaration in a header file. (This bit me with readahead().) This patch ensures that if implicit function declarations will kill the build, the feature being tested is deselected so the build will succeed. The autoconf manual suggests using return instead of exit in configure tests because the declaration for exit is often missing. We require this now, since we error if prototypes are missing. See section 5.5.1 of http://www.gnu.org/software/autoconf/manual/autoconf.html. This patch makes these changes, because in fact, an external declaration for exit is missing here (and likely elsewhere). I've verified that the features selected (here) with the original configure.in and the new one are the same except for, in my case, readahead. I've also confirmed that the generated Makefile is identical. These changes are not being applied to the 3.0.26 branch because it does not exhibit the initial problem this patch is supposed to solve since it doesn't attempt to use -Werror-implicit-function-declaration.
| * r22730: Fix password changes via pam_winbindd when using "winbind normalize ↵Gerald Carter2007-05-061-0/+2
| | | | | | | | | | | | | | names" and the username has been munged. Make sure to munge it back before performing the change_password() request.
| * r22729: add help text for osver and osname options to 'net ads join' (patch ↵Gerald Carter2007-05-061-1/+6
| | | | | | | | from Dnailo A.)