/* * Unix SMB/CIFS implementation. * NetApi File Support * Copyright (C) Guenther Deschner 2008 * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 3 of the License, or * (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program; if not, see . */ #include "includes.h" #include "librpc/gen_ndr/libnetapi.h" #include "lib/netapi/netapi.h" #include "lib/netapi/netapi_private.h" #include "lib/netapi/libnetapi.h" #include "../librpc/gen_ndr/cli_srvsvc.h" /**************************************************************** ****************************************************************/ WERROR NetFileClose_r(struct libnetapi_ctx *ctx, struct NetFileClose *r) { WERROR werr; NTSTATUS status; struct rpc_pipe_client *pipe_cli = NULL; werr = libnetapi_open_pipe(ctx, r->in.server_name, &ndr_table_srvsvc.syntax_id, &pipe_cli); if (!W_ERROR_IS_OK(werr)) { goto done; } status = rpccli_srvsvc_NetFileClose(pipe_cli, ctx, r->in.server_name, r->in.fileid, &werr); if (!NT_STATUS_IS_OK(status)) { werr = ntstatus_to_werror(status); goto done; } done: return werr; } /**************************************************************** ****************************************************************/ WERROR NetFileClose_l(struct libnetapi_ctx *ctx, struct NetFileClose *r) { LIBNETAPI_REDIRECT_TO_LOCALHOST(ctx, r, NetFileClose); } /**************************************************************** ****************************************************************/ static NTSTATUS map_srvsvc_FileInfo_to_FILE_INFO_buffer(TALLOC_CTX *mem_ctx, uint32_t level, union srvsvc_NetFileInfo *info, uint8_t **buffer, uint32_t *num_entries) { struct FILE_INFO_2 i2; struct FILE_INFO_3 i3; switch (level) { case 2: i2.fi2_id = info->info2->fid; ADD_TO_ARRAY(mem_ctx, struct FILE_INFO_2, i2, (struct FILE_INFO_2 **)buffer, num_entries); break; case 3: i3.fi3_id = info->info3->fid; i3.fi3_permissions = info->info3->permissions; i3.fi3_num_locks = info->info3->num_locks; i3.fi3_pathname = talloc_strdup(mem_ctx, info->info3->path); i3.fi3_username = talloc_strdup(mem_ctx, info->info3->user); NT_STATUS_HAVE_NO_MEMORY(i3.fi3_pathname); NT_STATUS_HAVE_NO_MEMORY(i3.fi3_username); ADD_TO_ARRAY(mem_ctx, struct FILE_INFO_3, i3, (struct FILE_INFO_3 **)buffer, num_entries); break; default: return NT_STATUS_INVALID_INFO_CLASS; } return NT_STATUS_OK; } /**************************************************************** ****************************************************************/ WERROR NetFileGetInfo_r(struct libnetapi_ctx *ctx, struct NetFileGetInfo *r) { WERROR werr; NTSTATUS status; struct rpc_pipe_client *pipe_cli = NULL; union srvsvc_NetFileInfo info; uint32_t num_entries = 0; if (!r->out.buffer) { return WERR_INVALID_PARAM; } switch (r->in.level) { case 2: case 3: break; default: return WERR_UNKNOWN_LEVEL; } werr = libnetapi_open_pipe(ctx, r->in.server_name, &ndr_table_srvsvc.syntax_id, &pipe_cli); if (!W_ERROR_IS_OK(werr)) { goto done; } status = rpccli_srvsvc_NetFileGetInfo(pipe_cli, ctx, r->in.server_name, r->in.fileid, r->in.level, &info, &werr); if (!W_ERROR_IS_OK(werr)) { goto done; } status = map_srvsvc_FileInfo_to_FILE_INFO_buffer(ctx, r->in.level, &info, r->out.buffer, &num_entries); if (!NT_STATUS_IS_OK(status)) { werr = ntstatus_to_werror(status); goto done; } done: return werr; } /**************************************************************** ****************************************************************/ WERROR NetFileGetInfo_l(struct libnetapi_ctx *ctx, struct NetFileGetInfo *r) { LIBNETAPI_REDIRECT_TO_LOCALHOST(ctx, r, NetFileGetInfo); } /**************************************************************** ****************************************************************/ WERROR NetFileEnum_r(struct libnetapi_ctx *ctx, struct NetFileEnum *r) { WERROR werr; NTSTATUS status; struct rpc_pipe_client *pipe_cli = NULL; struct srvsvc_NetFileInfoCtr info_ctr; struct srvsvc_NetFileCtr2 ctr2; struct srvsvc_NetFileCtr3 ctr3; uint32_t num_entries = 0; uint32_t i; if (!r->out.buffer) { return WERR_INVALID_PARAM; } switch (r->in.level) { case 2: case 3: break; default: return WERR_UNKNOWN_LEVEL; } werr = libnetapi_open_pipe(ctx, r->in.server_name, &ndr_table_srvsvc.syntax_id, &pipe_cli); if (!W_ERROR_IS_OK(werr)) { goto done; } ZERO_STRUCT(info_ctr); info_ctr.level = r->in.level; switch (r->in.level) { case 2: ZERO_STRUCT(ctr2); info_ctr.ctr.ctr2 = &ctr2; break; case 3: ZERO_STRUCT(ctr3); info_ctr.ctr.ctr3 = &ctr3; break; } status = rpccli_srvsvc_NetFileEnum(pipe_cli, ctx, r->in.server_name, r->in.base_path, r->in.user_name, &info_ctr, r->in.prefmaxlen, r->out.total_entries, r->out.resume_handle, &werr); if (NT_STATUS_IS_ERR(status)) { goto done; } for (i=0; i < info_ctr.ctr.ctr2->count; i++) { union srvsvc_NetFileInfo _i; switch (r->in.level) { case 2: _i.info2 = &info_ctr.ctr.ctr2->array[i]; break; case 3: _i.info3 = &info_ctr.ctr.ctr3->array[i]; break; } status = map_srvsvc_FileInfo_to_FILE_INFO_buffer(ctx, r->in.level, &_i, r->out.buffer, &num_entries); if (!NT_STATUS_IS_OK(status)) { werr = ntstatus_to_werror(status); goto done; } } if (r->out.entries_read) { *r->out.entries_read = num_entries; } if (r->out.total_entries) { *r->out.total_entries = num_entries; } done: return werr; } /**************************************************************** ****************************************************************/ WERROR NetFileEnum_l(struct libnetapi_ctx *ctx, struct NetFileEnum *r) { LIBNETAPI_REDIRECT_TO_LOCALHOST(ctx, r, NetFileEnum); } 8' href='#n98'>98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182
/*
   Unix SMB/CIFS implementation.
   Lookup routines for well-known SIDs
   Copyright (C) Andrew Tridgell 1992-1998
   Copyright (C) Luke Kenneth Caseson Leighton 1998-1999
   Copyright (C) Jeremy Allison  1999
   Copyright (C) Volker Lendecke 2005

   This program is free software; you can redistribute it and/or modify
   it under the terms of the GNU General Public License as published by
   the Free Software Foundation; either version 3 of the License, or
   (at your option) any later version.

   This program is distributed in the hope that it will be useful,
   but WITHOUT ANY WARRANTY; without even the implied warranty of
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
   GNU General Public License for more details.

   You should have received a copy of the GNU General Public License
   along with this program.  If not, see <http://www.gnu.org/licenses/>.
*/

#include "includes.h"
#include "../libcli/security/security.h"

struct rid_name_map {
	uint32 rid;
	const char *name;
};

struct sid_name_map_info
{
	const struct dom_sid *sid;
	const char *name;
	const struct rid_name_map *known_users;
};

static const struct rid_name_map everyone_users[] = {
	{ 0, "Everyone" },
	{ 0, NULL}};

static const struct rid_name_map local_authority_users[] = {
	{ 0, "Local" },
	{ 1, "Console Logon" },
	{ 0, NULL}};

static const struct rid_name_map creator_owner_users[] = {
	{ 0, "Creator Owner" },
	{ 1, "Creator Group" },
	{ 2, "Creator Owner Server" },
	{ 3, "Creator Group Server" },
	{ 4, "Owner Rights" },
	{ 0, NULL}};

static const struct rid_name_map nt_authority_users[] = {
	{  1, "Dialup" },
	{  2, "Network"},
	{  3, "Batch"},
	{  4, "Interactive"},
	{  6, "Service"},
	{  7, "Anonymous Logon"},
	{  8, "Proxy"},
	{  9, "Enterprise Domain Controllers"},
	{ 10, "Self"},
	{ 11, "Authenticated Users"},
	{ 12, "Restricted"},
	{ 13, "Terminal Server User"},
	{ 14, "Remote Interactive Logon"},
	{ 15, "This Organization"},
	{ 17, "IUSR"},
	{ 18, "SYSTEM"},
	{ 19, "Local Service"},
	{ 20, "Network Service"},
	{  0,  NULL}};

static struct sid_name_map_info special_domains[] = {
	{ &global_sid_World_Domain, "", everyone_users },
	{ &global_sid_Local_Authority, "", local_authority_users },
	{ &global_sid_Creator_Owner_Domain, "", creator_owner_users },
	{ &global_sid_NT_Authority, "NT Authority", nt_authority_users },
	{ NULL, NULL, NULL }};

bool sid_check_is_wellknown_domain(const struct dom_sid *sid, const char **name)
{
	int i;

	for (i=0; special_domains[i].sid != NULL; i++) {
		if (dom_sid_equal(sid, special_domains[i].sid)) {
			if (name != NULL) {
				*name = special_domains[i].name;
			}
			return True;
		}
	}
	return False;
}

bool sid_check_is_in_wellknown_domain(const struct dom_sid *sid)
{
	struct dom_sid dom_sid;

	sid_copy(&dom_sid, sid);
	sid_split_rid(&dom_sid, NULL);

	return sid_check_is_wellknown_domain(&dom_sid, NULL);
}

/**************************************************************************
 Looks up a known username from one of the known domains.
***************************************************************************/

bool lookup_wellknown_sid(TALLOC_CTX *mem_ctx, const struct dom_sid *sid,
			  const char **domain, const char **name)
{
	int i;
	struct dom_sid dom_sid;
	uint32 rid;
	const struct rid_name_map *users = NULL;

	sid_copy(&dom_sid, sid);
	if (!sid_split_rid(&dom_sid, &rid)) {
		DEBUG(2, ("Could not split rid from SID\n"));
		return False;
	}

	for (i=0; special_domains[i].sid != NULL; i++) {
		if (dom_sid_equal(&dom_sid, special_domains[i].sid)) {
			*domain = talloc_strdup(mem_ctx,
						special_domains[i].name);
			users = special_domains[i].known_users;
			break;
		}
	}

	if (users == NULL) {
		DEBUG(10, ("SID %s is no special sid\n", sid_string_dbg(sid)));
		return False;
	}

	for (i=0; users[i].name != NULL; i++) {
		if (rid == users[i].rid) {
			*name = talloc_strdup(mem_ctx, users[i].name);
			return True;
		}
	}

	DEBUG(10, ("RID of special SID %s not found\n", sid_string_dbg(sid)));

	return False;
}

/**************************************************************************
 Try and map a name to one of the well known SIDs.
***************************************************************************/

bool lookup_wellknown_name(TALLOC_CTX *mem_ctx, const char *name,
			   struct dom_sid *sid, const char **domain)
{
	int i, j;

	DEBUG(10,("map_name_to_wellknown_sid: looking up %s\n", name));

	for (i=0; special_domains[i].sid != NULL; i++) {
		const struct rid_name_map *users =
			special_domains[i].known_users;

		if (users == NULL)
			continue;

		for (j=0; users[j].name != NULL; j++) {
			if ( strequal(users[j].name, name) ) {
				sid_compose(sid, special_domains[i].sid,
					    users[j].rid);
				*domain = talloc_strdup(
					mem_ctx, special_domains[i].name);
				return True;
			}
		}
	}

	return False;
}