Go to file
Stephen Gallagher ced8f89336 NSS: Implement group merging support.
https://sourceware.org/glibc/wiki/Proposals/GroupMerging

== Justification ==
It is common today for users to rely on centrally-managed user stores for
handling their user accounts. However, much software existing today does
not have an innate understanding of such accounts. Instead, they commonly
rely on membership in known groups for managing access-control (for
example the "wheel" group on Fedora and RHEL systems or the "adm" group
on Debian-derived systems). In the present incarnation of nsswitch, the
only way to have such groups managed by a remote user store such as
FreeIPA or Active Directory would be to manually remove the groups from
/etc/group on the clients so that nsswitch would then move past nss_files
and into the SSSD, nss-ldap or other remote user database.

== Solution ==
With this patch, a new action is introduced for nsswitch:
NSS_ACTION_MERGE. To take advantage of it, one will add [SUCCESS=merge]
between two database entries in the nsswitch.conf file. When a group is
located in the first of the two group entries, processing will continue
on to the next one. If the group is also found in the next entry (and the
group name and GID are an exact match), the member list of the second
entry will be added to the group object to be returned.

== Implementation ==
After each DL_LOOKUP_FN() returns, the next action is checked. If the
function returned NSS_STATUS_SUCCESS and the next action is
NSS_ACTION_MERGE, a copy of the result buffer is saved for the next pass
through the loop. If on this next pass through the loop the database
returns another instance of a group matching both the group name and GID,
the member list is added to the previous list and it is returned as a
single object. If the following database does not contain the same group,
then the original is copied back into the destination buffer.

This patch implements merge functionality only for the group database.
For other databases, there is a default implementation that will return
the EINVAL errno if a merge is requested. The merge functionality can be
implemented for other databases at a later time if such is needed. Each
database must provide a unique implementation of the deep-copy and merge
functions.

If [SUCCESS=merge] is present in nsswitch.conf for a glibc version that
does not support it, glibc will process results up until that operation,
at which time it will return results if it has found them or else will
simply return an error. In practical terms, this ends up behaving like
the remainder of the nsswitch.conf line does not exist.

== Iterators ==
This feature does not modify the iterator functionality from its current
behavior. If getgrnam() or getgrgid() is called, glibc will iterate
through all entries in the `group` line in nsswitch.conf and display the
list of members without attempting to merge them. This is consistent with
the behavior of nss_files where if two separate lines are specified for
the same group in /etc/groups, getgrnam()/getgrgid() will display both.
Clients are already expected to handle this gracefully.

== No Premature Optimizations ==
The following is a list of places that might be eligible for
optimization, but were not overengineered for this initial contribution:
 * Any situation where a merge may occur will result in one malloc() of
   the same size as the input buffer.
 * Any situation where a merge does occur will result in a second
   malloc() to hold the list of pointers to member name strings.
 * The list of members is simply concatenated together and is not tested
   for uniqueness (which is identical to the behavior for nss_files,
   which will simply return identical values if they both exist on the
   line in the file. This could potentially be optimized to reduce space
   usage in the buffer, but it is both complex and computationally
   expensive to do so.

== Testing ==
I performed testing by running the getent utility against my newly-built
glibc and configuring /etc/nsswitch.conf with the following entry:
group: group:      files [SUCCESS=merge] sss

In /etc/group I included the line:
wheel10:sgallagh

I then configured my local SSSD using the id_provider=local to respond
with:
wheel:*:10:localuser,localuser2

I then ran `getent group wheel` against the newly-built glibc in
multiple situations and received the expected output as described
above:
 * When SSSD was running.
 * When SSSD was configured in nsswitch.conf but the daemon was not
   running.
 * When SSSD was configured in nsswitch.conf but nss_sss.so.2 was not
   installed on the system.
 * When the order of 'sss' and 'files' was reversed.
 * All of the above with the [SUCCESS=merge] removed (to ensure no
   regressions).
 * All of the above with `getent group 10`.
 * All of the above with `getent group` with and without
   `enumerate=true` set in SSSD.
 * All of the above with and without nscd enabled on the system.
2016-04-29 22:18:21 -04:00
argp argp: Use fwrite_unlocked instead of __fxprintf when !_LIBC 2016-01-07 04:25:54 -05:00
assert Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
benchtests benchtests: Support for cross-building benchmarks 2016-04-20 13:19:01 +05:30
bits non-linux: Apply RFC3542 obsoletion of RFC2292 macros 2016-04-24 19:24:36 +02:00
catgets Fix building glibc master with NDEBUG and --with-cpu. 2016-03-15 23:23:24 -04:00
conform Fix stdio.h namespace for pre-threads POSIX (bug 20014). 2016-04-28 22:01:04 +00:00
crypt Fix build failures with -DDEBUG. 2016-01-15 11:07:41 -07:00
csu Update copyright dates not handled by scripts/update-copyrights. 2016-01-04 16:26:30 +00:00
ctype Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
debug Make shebang interpreter directives consistent 2016-01-07 04:03:21 -05:00
dirent Deprecate readdir_r, readdir64_r [BZ #19056] 2016-02-20 12:56:55 +01:00
dlfcn Fix building glibc master with NDEBUG and --with-cpu. 2016-03-15 23:23:24 -04:00
elf Reduce number of mmap calls from __libc_memalign in ld.so 2016-04-23 06:05:15 -07:00
gmon Copy x86_64 _mcount.op from _mcount.o 2016-03-03 06:56:22 -08:00
gnulib Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
grp NSS: Implement group merging support. 2016-04-29 22:18:21 -04:00
gshadow Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
hesiod Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
hurd Fix O_DIRECTORY lookup on trivial translators 2016-01-13 00:48:30 +01:00
iconv Fix min/max needed for ascii to INTERNAL conversion 2016-03-07 17:47:50 +01:00
iconvdata S390: Fix build error in iconvdata/bug-iconv11.c. 2016-01-20 08:32:37 +01:00
include NSS: Implement group merging support. 2016-04-29 22:18:21 -04:00
inet getnameinfo: Refactor and fix memory leak [BZ #19642] 2016-04-29 17:08:06 +02:00
intl Enable --localedir to set message catalog directory (Bug 14259) 2016-02-24 20:06:04 -05:00
io Make shebang interpreter directives consistent 2016-01-07 04:03:21 -05:00
libidn Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
libio libio: Fix fmemopen append mode failure (BZ# 20012) 2016-04-29 19:25:17 -03:00
locale Fix langinfo.h nl_langinfo_l namespace (bug 19996). 2016-04-26 15:02:26 +00:00
localedata localedata: add more translit entries 2016-04-27 01:09:20 -04:00
login Update copyright dates not handled by scripts/update-copyrights. 2016-01-04 16:26:30 +00:00
mach Fix mach-syscalls.mk build 2016-03-20 19:50:58 +01:00
malloc malloc: Add missing internal_function attributes on function definitions 2016-04-14 12:54:22 +02:00
manual NSS: Implement group merging support. 2016-04-29 22:18:21 -04:00
math Register extra test objects 2016-04-13 17:07:13 +02:00
mathvec Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
misc Fix crash on getauxval call without HAVE_AUX_VECTOR 2016-04-10 23:58:43 +02:00
nis Suppress GCC 6 warning about ambiguous 'else' with -Wparentheses 2016-04-15 13:30:55 +02:00
nptl nptl: support thread stacks that grow up 2016-02-19 12:41:29 -05:00
nptl_db Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
nscd NSS: Implement group merging support. 2016-04-29 22:18:21 -04:00
nss NSS: Implement group merging support. 2016-04-29 22:18:21 -04:00
po Enable --localedir to set message catalog directory (Bug 14259) 2016-02-24 20:06:04 -05:00
posix glob: Simplify the interface for the GLOB_ALTDIRFUNC callback gl_readdir 2016-04-29 09:35:30 +02:00
pwd Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
resolv resolv: Reindent preprocessor conditionals following cleanups 2016-04-28 16:53:56 +02:00
resource Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
rt Fix hurd build 2016-03-16 13:57:57 +01:00
scripts Allow overriding of CFLAGS as well as CPPFLAGS for rtld. 2016-04-09 23:48:32 -04:00
setjmp Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
shadow Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
signal Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
socket Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
soft-fp Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
stdio-common libio: Fix fmemopen append mode failure (BZ# 20012) 2016-04-29 19:25:17 -03:00
stdlib Suppress GCC 6 warning about ambiguous 'else' with -Wparentheses 2016-04-15 13:30:55 +02:00
streams Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
string Move mempcpy, strcpy and stpcpy inlines to string/string-inlines.c as compatibility 2016-04-18 15:30:49 +01:00
sunrpc sunrpc: In key_call_keyenvoy, use int status instead of union wait 2016-03-08 10:04:24 +01:00
sysdeps Fix clone (CLONE_VM) pid/tid reset (BZ#19957) 2016-04-29 18:19:30 -03:00
sysvipc Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
termios Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
time Fix build failures with -DDEBUG. 2016-01-15 11:07:41 -07:00
timezone Remove mention of checktab.awk in timezone/README. 2016-03-14 14:11:51 -04:00
wcsmbs Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
wctype Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
.gitattributes Assume __NR_openat is always defined 2016-03-23 23:35:08 +01:00
.gitignore Add *.pyc to .gitignore 2015-05-18 15:26:26 +05:30
BUGS [BZ #5222] 2007-10-28 08:24:07 +00:00
CONFORMANCE Move __STDC_* predefined macros from features.h to stdc-predef.h. 2012-02-22 12:53:04 +00:00
COPYING Update to latest versions of GPL-2.0 and LGPL-2.1 2013-09-09 12:52:48 +10:00
COPYING.LIB Update to latest versions of GPL-2.0 and LGPL-2.1 2013-09-09 12:52:48 +10:00
ChangeLog NSS: Implement group merging support. 2016-04-29 22:18:21 -04:00
ChangeLog.1
ChangeLog.2
ChangeLog.3
ChangeLog.4
ChangeLog.5 * sysdeps/posix/getaddrinfo.c: Implement configuration file 2006-05-04 06:38:07 +00:00
ChangeLog.6 Revert "ChangeLogs: convert to utf-8" 2016-02-12 16:35:27 -05:00
ChangeLog.7 Revert "ChangeLogs: convert to utf-8" 2016-02-12 16:35:27 -05:00
ChangeLog.8 Revert "ChangeLogs: convert to utf-8" 2016-02-12 16:35:27 -05:00
ChangeLog.9
ChangeLog.10 Revert "ChangeLogs: convert to utf-8" 2016-02-12 16:35:27 -05:00
ChangeLog.11 Revert "ChangeLogs: convert to utf-8" 2016-02-12 16:35:27 -05:00
ChangeLog.12 Revert "ChangeLogs: convert to utf-8" 2016-02-12 16:35:27 -05:00
ChangeLog.13
ChangeLog.14 Revert "ChangeLogs: convert to utf-8" 2016-02-12 16:35:27 -05:00
ChangeLog.15 Split out ChangeLog.15 at 2.3 branch point 2005-02-16 07:34:17 +00:00
ChangeLog.16 Fix typo in name 2012-06-21 16:45:27 +02:00
ChangeLog.17 Revert "Sun agreed to a change of the license for the RPC code to a BSD-like license." 2010-06-27 19:34:03 -07:00
ChangeLog.old-ports Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-aarch64 Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-aix Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-alpha Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-am33 Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-arm Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-cris Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-hppa Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-ia64 Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-linux-generic Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-m68k Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-microblaze Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-mips Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-powerpc Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
ChangeLog.old-ports-tile Move ports/ChangeLog* files to ChangeLog.old-ports*, remove ports/ directory. 2014-04-30 10:40:29 -07:00
INSTALL Require Linux 3.2 except on x86 / x86_64, 3.2 headers everywhere. 2016-02-24 17:15:12 +00:00
LICENSES Expand LICENSES file. 2012-12-05 21:56:15 +00:00
Makeconfig Enable --localedir to set message catalog directory (Bug 14259) 2016-02-24 20:06:04 -05:00
Makefile Fix edito in last change. 2016-03-04 15:45:35 -08:00
Makefile.in New make target to only build benchmark binaries 2016-04-20 10:23:28 +05:30
Makerules Update copyright dates with scripts/update-copyrights. 2016-01-04 16:05:18 +00:00
NAMESPACE
NEWS NSS: Implement group merging support. 2016-04-29 22:18:21 -04:00
PROJECTS
README Require Linux 3.2 except on x86 / x86_64, 3.2 headers everywhere. 2016-02-24 17:15:12 +00:00
Rules New make target to only build benchmark binaries 2016-04-20 10:23:28 +05:30
WUR-REPORT * posix/unistd.h (setuid, setreuid, seteuid, setresuid): 2012-08-01 18:12:58 +02:00
abi-tags Add arm-nacl port. 2015-04-17 09:02:19 -07:00
aclocal.m4 Rename localedir to complocaledir (bug 14259). 2015-11-27 10:22:38 -05:00
config.h.in Remove linux/fanotify.h configure test. 2016-02-24 18:44:10 +00:00
config.make.in Enable --localedir to set message catalog directory (Bug 14259) 2016-02-24 20:06:04 -05:00
configure Regenerated configure scripts. 2016-02-18 18:36:10 -02:00
configure.ac configure: make the unsupported error message less hostile 2016-01-17 15:24:54 -05:00
cppflags-iterator.mk
extra-lib.mk Remove NOT_IN_libc 2014-11-24 15:03:45 +05:30
extra-modules.mk Remove NOT_IN_libc 2014-11-24 15:03:45 +05:30
gen-locales.mk Split locale generation snippet into a separate file 2015-05-13 13:05:28 +05:30
libc-abis A few more archs have IFUNC support. 2010-03-17 02:43:12 -07:00
o-iterator.mk
shlib-versions This is update for configure, build and install of vector math library. 2015-05-14 18:07:06 +03:00
test-skeleton.c test-skeleton.c: Do not set RLIMIT_DATA [BZ #19648] 2016-03-07 13:48:47 +01:00
version.h Open development for 2.24. 2016-02-18 16:11:58 -02:00

README

This directory contains the sources of the GNU C Library.
See the file "version.h" for what release version you have.

The GNU C Library is the standard system C library for all GNU systems,
and is an important part of what makes up a GNU system.  It provides the
system API for all programs written in C and C-compatible languages such
as C++ and Objective C; the runtime facilities of other programming
languages use the C library to access the underlying operating system.

In GNU/Linux systems, the C library works with the Linux kernel to
implement the operating system behavior seen by user applications.
In GNU/Hurd systems, it works with a microkernel and Hurd servers.

The GNU C Library implements much of the POSIX.1 functionality in the
GNU/Hurd system, using configurations i[4567]86-*-gnu.  The current
GNU/Hurd support requires out-of-tree patches that will eventually be
incorporated into an official GNU C Library release.

When working with Linux kernels, this version of the GNU C Library
requires Linux kernel version 3.2 or later on all architectures except
i[4567]86 and x86_64, where Linux kernel version 2.6.32 or later
suffices.

Also note that the shared version of the libgcc_s library must be
installed for the pthread library to work correctly.

The GNU C Library supports these configurations for using Linux kernels:

	aarch64*-*-linux-gnu
	alpha*-*-linux-gnu
	arm-*-linux-gnueabi
	hppa-*-linux-gnu	Not currently functional without patches.
	i[4567]86-*-linux-gnu
	x86_64-*-linux-gnu	Can build either x86_64 or x32
	ia64-*-linux-gnu
	m68k-*-linux-gnu
	microblaze*-*-linux-gnu
	mips-*-linux-gnu
	mips64-*-linux-gnu
	powerpc-*-linux-gnu	Hardware or software floating point, BE only.
	powerpc64*-*-linux-gnu	Big-endian and little-endian.
	s390-*-linux-gnu
	s390x-*-linux-gnu
	sh[34]-*-linux-gnu
	sparc*-*-linux-gnu
	sparc64*-*-linux-gnu
	tilegx-*-linux-gnu
	tilepro-*-linux-gnu

If you are interested in doing a port, please contact the glibc
maintainers; see http://www.gnu.org/software/libc/ for more
information.

See the file INSTALL to find out how to configure, build, and install
the GNU C Library.  You might also consider reading the WWW pages for
the C library at http://www.gnu.org/software/libc/.

The GNU C Library is (almost) completely documented by the Texinfo manual
found in the `manual/' subdirectory.  The manual is still being updated
and contains some known errors and omissions; we regret that we do not
have the resources to work on the manual as much as we would like.  For
corrections to the manual, please file a bug in the `manual' component,
following the bug-reporting instructions below.  Please be sure to check
the manual in the current development sources to see if your problem has
already been corrected.

Please see http://www.gnu.org/software/libc/bugs.html for bug reporting
information.  We are now using the Bugzilla system to track all bug reports.
This web page gives detailed information on how to report bugs properly.

The GNU C Library is free software.  See the file COPYING.LIB for copying
conditions, and LICENSES for notices about a few contributions that require
these additional notices to be distributed.  License copyright years may be
listed using range notation, e.g., 1996-2015, indicating that every year in
the range, inclusive, is a copyrightable year that would otherwise be listed
individually.