blob: 81a3d6a944eecff7ce37fd1524f6eecd762ecf4d (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
|
/*
Unix SMB/CIFS implementation.
definitions for marshalling/unmarshalling security descriptors
and related structures
Copyright (C) Andrew Tridgell 2003
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 2 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
*/
/* a domain SID. Note that unlike Samba3 this contains a pointer,
so you can't copy them using assignment */
struct dom_sid {
uint8 sid_rev_num; /**< SID revision number */
uint8 num_auths; /**< Number of sub-authorities */
uint8 id_auth[6]; /**< Identifier Authority */
uint32 *sub_auths;
};
/* use the same structure for dom_sid2 as dom_sid */
#define dom_sid2 dom_sid
/* an access control element */
struct security_ace {
uint8 type; /* xxxx_xxxx_ACE_TYPE - e.g allowed / denied etc */
uint8 flags; /* xxxx_INHERIT_xxxx - e.g OBJECT_INHERIT_ACE */
uint32 access_mask;
/* the 'obj' part is present when type is XXXX_TYPE_XXXX_OBJECT */
struct {
uint32 flags;
GUID object_guid;
GUID inherit_guid;
} *obj;
struct dom_sid trustee;
};
/* a security ACL */
struct security_acl {
uint16 revision;
uint32 num_aces;
struct security_ace *aces;
};
/* a security descriptor */
struct security_descriptor {
uint8 revision;
uint16 type; /* SEC_DESC_xxxx flags */
struct dom_sid *owner_sid;
struct dom_sid *group_sid;
struct security_acl *sacl; /* system ACL */
struct security_acl *dacl; /* user (discretionary) ACL */
};
/*
a security descriptor encapsulated in a buffer.
It is like this IDL:
typedef struct {
uint32 size;
[size_is(size)] uint8 *buf;
} sec_desc_buf;
*/
struct sec_desc_buf {
uint32 size; /* the sd wire size - auto-generated */
struct security_descriptor *sd;
};
/* query security descriptor */
struct smb_query_secdesc {
struct {
uint16 fnum;
uint32 secinfo_flags;
} in;
struct {
struct security_descriptor *sd;
} out;
};
/* set security descriptor */
struct smb_set_secdesc {
struct {
uint16 fnum;
uint32 secinfo_flags;
struct security_descriptor *sd;
} in;
};
|