f02230fd0192fa2551658c9e0919943bfaae515c
[mat/samba.git] / source3 / passdb / py_passdb.c
1 /*
2    Python interface to passdb
3
4    Copyright (C) Amitay Isaacs 2011
5
6    This program is free software; you can redistribute it and/or modify
7    it under the terms of the GNU General Public License as published by
8    the Free Software Foundation; either version 3 of the License, or
9    (at your option) any later version.
10
11    This program is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14    GNU General Public License for more details.
15
16    You should have received a copy of the GNU General Public License
17    along with this program.  If not, see <http://www.gnu.org/licenses/>.
18 */
19
20 #include <Python.h>
21 #include <pytalloc.h>
22 #include "includes.h"
23 #include "lib/util/talloc_stack.h"
24 #include "libcli/security/security.h"
25 #include "passdb.h"
26 #include "secrets.h"
27
28 /* There's no Py_ssize_t in 2.4, apparently */
29 #if PY_MAJOR_VERSION == 2 && PY_MINOR_VERSION < 5
30 typedef int Py_ssize_t;
31 typedef inquiry lenfunc;
32 typedef intargfunc ssizeargfunc;
33 #endif
34
35 #ifndef Py_RETURN_NONE
36 #define Py_RETURN_NONE  return Py_INCREF(Py_None), Py_None
37 #endif
38
39 #ifndef Py_TYPE /* Py_TYPE is only available on Python > 2.6 */
40 #define Py_TYPE(ob)             (((PyObject*)(ob))->ob_type)
41 #endif
42
43 #ifndef PY_CHECK_TYPE
44 #define PY_CHECK_TYPE(type, var, fail) \
45         if (!PyObject_TypeCheck(var, type)) {\
46                 PyErr_Format(PyExc_TypeError, __location__ ": Expected type '%s' for '%s' of type '%s'", (type)->tp_name, #var, Py_TYPE(var)->tp_name); \
47                 fail; \
48         }
49 #endif
50
51
52 static PyTypeObject *dom_sid_Type = NULL;
53 static PyTypeObject *security_Type = NULL;
54 static PyTypeObject *guid_Type = NULL;
55
56 staticforward PyTypeObject PySamu;
57 staticforward PyTypeObject PyGroupmap;
58 staticforward PyTypeObject PyPDB;
59
60 static PyObject *py_pdb_error;
61
62 void initpassdb(void);
63
64
65 /************************** PIDL Autogeneratd ******************************/
66
67 static PyObject *py_samu_get_logon_time(PyObject *obj, void *closure)
68 {
69         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
70         PyObject *py_logon_time;
71
72         py_logon_time = PyInt_FromLong(pdb_get_logon_time(sam_acct));
73         return py_logon_time;
74 }
75
76 static int py_samu_set_logon_time(PyObject *obj, PyObject *value, void *closure)
77 {
78         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
79
80         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
81         if (!pdb_set_logon_time(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
82                 return -1;
83         }
84         return 0;
85 }
86
87 static PyObject *py_samu_get_logoff_time(PyObject *obj, void *closure)
88 {
89         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
90         PyObject *py_logoff_time;
91
92         py_logoff_time = PyInt_FromLong(pdb_get_logoff_time(sam_acct));
93         return py_logoff_time;
94 }
95
96 static int py_samu_set_logoff_time(PyObject *obj, PyObject *value, void *closure)
97 {
98         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
99
100         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
101         if (!pdb_set_logoff_time(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
102                 return -1;
103         }
104         return 0;
105 }
106
107 static PyObject *py_samu_get_kickoff_time(PyObject *obj, void *closure)
108 {
109         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
110         PyObject *py_kickoff_time;
111
112         py_kickoff_time = PyInt_FromLong(pdb_get_kickoff_time(sam_acct));
113         return py_kickoff_time;
114 }
115
116 static int py_samu_set_kickoff_time(PyObject *obj, PyObject *value, void *closure)
117 {
118         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
119
120         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
121         if (!pdb_set_kickoff_time(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
122                 return -1;
123         }
124         return 0;
125 }
126
127 static PyObject *py_samu_get_bad_password_time(PyObject *obj, void *closure)
128 {
129         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
130         PyObject *py_bad_password_time;
131
132         py_bad_password_time = PyInt_FromLong(pdb_get_bad_password_time(sam_acct));
133         return py_bad_password_time;
134 }
135
136 static int py_samu_set_bad_password_time(PyObject *obj, PyObject *value, void *closure)
137 {
138         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
139
140         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
141         if (!pdb_set_bad_password_time(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
142                 return -1;
143         }
144         return 0;
145 }
146
147 static PyObject *py_samu_get_pass_last_set_time(PyObject *obj, void *closure)
148 {
149         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
150         PyObject *py_pass_last_set_time;
151
152         py_pass_last_set_time = PyInt_FromLong(pdb_get_pass_last_set_time(sam_acct));
153         return py_pass_last_set_time;
154 }
155
156 static int py_samu_set_pass_last_set_time(PyObject *obj, PyObject *value, void *closure)
157 {
158         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
159
160         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
161         if (!pdb_set_pass_last_set_time(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
162                 return -1;
163         }
164         return 0;
165 }
166
167 static PyObject *py_samu_get_pass_can_change_time(PyObject *obj, void *closure)
168 {
169         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
170         PyObject *py_pass_can_change_time;
171
172         py_pass_can_change_time = PyInt_FromLong(pdb_get_pass_can_change_time(sam_acct));
173         return py_pass_can_change_time;
174 }
175
176 static int py_samu_set_pass_can_change_time(PyObject *obj, PyObject *value, void *closure)
177 {
178         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
179
180         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
181         if (!pdb_set_pass_can_change_time(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
182                 return -1;
183         }
184         return 0;
185 }
186
187 static PyObject *py_samu_get_pass_must_change_time(PyObject *obj, void *closure)
188 {
189         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
190         PyObject *py_pass_must_change_time;
191
192         py_pass_must_change_time = PyInt_FromLong(pdb_get_pass_must_change_time(sam_acct));
193         return py_pass_must_change_time;
194 }
195
196 static int py_samu_set_pass_must_change_time(PyObject *obj, PyObject *value, void *closure)
197 {
198         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
199
200         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
201         if (!pdb_set_pass_must_change_time(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
202                 return -1;
203         }
204         return 0;
205 }
206
207 static PyObject *py_samu_get_username(PyObject *obj, void *closure)
208 {
209         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
210         PyObject *py_username;
211         const char *username;
212
213         username = pdb_get_username(sam_acct);
214         if (username == NULL) {
215                 Py_RETURN_NONE;
216         }
217
218         py_username = PyString_FromString(username);
219         return py_username;
220 }
221
222 static int py_samu_set_username(PyObject *obj, PyObject *value, void *closure)
223 {
224         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
225
226         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
227         if (!pdb_set_username(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
228                 return -1;
229         }
230         return 0;
231 }
232
233 static PyObject *py_samu_get_domain(PyObject *obj, void *closure)
234 {
235         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
236         PyObject *py_domain;
237         const char *domain;
238
239         domain = pdb_get_domain(sam_acct);
240         if (domain == NULL) {
241                 Py_RETURN_NONE;
242         }
243
244         py_domain = PyString_FromString(domain);
245         return py_domain;
246 }
247
248 static int py_samu_set_domain(PyObject *obj, PyObject *value, void *closure)
249 {
250         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
251
252         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
253         if (!pdb_set_domain(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
254                 return -1;
255         }
256         return 0;
257 }
258
259 static PyObject *py_samu_get_nt_username(PyObject *obj, void *closure)
260 {
261         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
262         PyObject *py_nt_username;
263         const char *nt_username;
264
265         nt_username = pdb_get_nt_username(sam_acct);
266         if (nt_username == NULL) {
267                 Py_RETURN_NONE;
268         }
269
270         py_nt_username = PyString_FromString(nt_username);
271         return py_nt_username;
272 }
273
274 static int py_samu_set_nt_username(PyObject *obj, PyObject *value, void *closure)
275 {
276         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
277
278         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
279         if (!pdb_set_nt_username(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
280                 return -1;
281         }
282         return 0;
283 }
284
285 static PyObject *py_samu_get_full_name(PyObject *obj, void *closure)
286 {
287         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
288         PyObject *py_full_name;
289         const char *full_name;
290
291         full_name = pdb_get_fullname(sam_acct);
292         if (full_name == NULL) {
293                 Py_RETURN_NONE;
294         }
295
296         py_full_name = PyString_FromString(full_name);
297         return py_full_name;
298 }
299
300 static int py_samu_set_full_name(PyObject *obj, PyObject *value, void *closure)
301 {
302         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
303
304         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
305         if (!pdb_set_fullname(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
306                 return -1;
307         }
308         return 0;
309 }
310
311 static PyObject *py_samu_get_home_dir(PyObject *obj, void *closure)
312 {
313         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
314         PyObject *py_home_dir;
315         const char *home_dir;
316
317         home_dir = pdb_get_homedir(sam_acct);
318         if (home_dir == NULL) {
319                 Py_RETURN_NONE;
320         }
321
322         py_home_dir = PyString_FromString(home_dir);
323         return py_home_dir;
324 }
325
326 static int py_samu_set_home_dir(PyObject *obj, PyObject *value, void *closure)
327 {
328         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
329
330         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
331         if (!pdb_set_homedir(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
332                 return -1;
333         }
334         return 0;
335 }
336
337 static PyObject *py_samu_get_dir_drive(PyObject *obj, void *closure)
338 {
339         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
340         PyObject *py_dir_drive;
341         const char *dir_drive;
342
343         dir_drive = pdb_get_dir_drive(sam_acct);
344         if (dir_drive == NULL) {
345                 Py_RETURN_NONE;
346         }
347
348         py_dir_drive = PyString_FromString(dir_drive);
349         return py_dir_drive;
350 }
351
352 static int py_samu_set_dir_drive(PyObject *obj, PyObject *value, void *closure)
353 {
354         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
355
356         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
357         if (!pdb_set_dir_drive(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
358                 return -1;
359         }
360         return 0;
361 }
362
363 static PyObject *py_samu_get_logon_script(PyObject *obj, void *closure)
364 {
365         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
366         PyObject *py_logon_script;
367         const char *logon_script;
368
369         logon_script = pdb_get_logon_script(sam_acct);
370         if (logon_script == NULL) {
371                 Py_RETURN_NONE;
372         }
373
374         py_logon_script = PyString_FromString(logon_script);
375         return py_logon_script;
376 }
377
378 static int py_samu_set_logon_script(PyObject *obj, PyObject *value, void *closure)
379 {
380         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
381
382         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
383         if (!pdb_set_logon_script(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
384                 return -1;
385         }
386         return 0;
387 }
388
389 static PyObject *py_samu_get_profile_path(PyObject *obj, void *closure)
390 {
391         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
392         PyObject *py_profile_path;
393         const char *profile_path;
394
395         profile_path = pdb_get_profile_path(sam_acct);
396         if (profile_path == NULL) {
397                 Py_RETURN_NONE;
398         }
399
400         py_profile_path = PyString_FromString(profile_path);
401         return py_profile_path;
402 }
403
404 static int py_samu_set_profile_path(PyObject *obj, PyObject *value, void *closure)
405 {
406         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
407
408         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
409         if (!pdb_set_profile_path(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
410                 return -1;
411         }
412         return 0;
413 }
414
415 static PyObject *py_samu_get_acct_desc(PyObject *obj, void *closure)
416 {
417         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
418         PyObject *py_acct_desc;
419         const char *acct_desc;
420
421         acct_desc = pdb_get_acct_desc(sam_acct);
422         if (acct_desc == NULL) {
423                 Py_RETURN_NONE;
424         }
425
426         py_acct_desc = PyString_FromString(acct_desc);
427         return py_acct_desc;
428 }
429
430 static int py_samu_set_acct_desc(PyObject *obj, PyObject *value, void *closure)
431 {
432         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
433
434         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
435         if (!pdb_set_acct_desc(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
436                 return -1;
437         }
438         return 0;
439 }
440
441 static PyObject *py_samu_get_workstations(PyObject *obj, void *closure)
442 {
443         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
444         PyObject *py_workstations;
445         const char *workstations;
446
447         workstations = pdb_get_workstations(sam_acct);
448         if (workstations == NULL) {
449                 Py_RETURN_NONE;
450         }
451
452         py_workstations = PyString_FromString(workstations);
453         return py_workstations;
454 }
455
456 static int py_samu_set_workstations(PyObject *obj, PyObject *value, void *closure)
457 {
458         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
459
460         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
461         if (!pdb_set_workstations(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
462                 return -1;
463         }
464         return 0;
465 }
466
467 static PyObject *py_samu_get_comment(PyObject *obj, void *closure)
468 {
469         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
470         PyObject *py_comment;
471         const char *comment;
472
473         comment = pdb_get_comment(sam_acct);
474         if (comment == NULL) {
475                 Py_RETURN_NONE;
476         }
477
478         py_comment = PyString_FromString(comment);
479         return py_comment;
480 }
481
482 static int py_samu_set_comment(PyObject *obj, PyObject *value, void *closure)
483 {
484         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
485
486         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
487         if (!pdb_set_comment(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
488                 return -1;
489         }
490         return 0;
491 }
492
493 static PyObject *py_samu_get_munged_dial(PyObject *obj, void *closure)
494 {
495         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
496         PyObject *py_munged_dial;
497         const char *munged_dial;
498
499         munged_dial = pdb_get_munged_dial(sam_acct);
500         if (munged_dial == NULL) {
501                 Py_RETURN_NONE;
502         }
503
504         py_munged_dial = PyString_FromString(munged_dial);
505         return py_munged_dial;
506 }
507
508 static int py_samu_set_munged_dial(PyObject *obj, PyObject *value, void *closure)
509 {
510         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
511
512         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
513         if (!pdb_set_munged_dial(sam_acct, PyString_AsString(value), PDB_CHANGED)) {
514                 return -1;
515         }
516         return 0;
517 }
518
519 static PyObject *py_samu_get_user_sid(PyObject *obj, void *closure)
520 {
521         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
522         PyObject *py_user_sid;
523         const struct dom_sid *user_sid;
524         struct dom_sid *copy_user_sid;
525         TALLOC_CTX *mem_ctx;
526
527         user_sid = pdb_get_user_sid(sam_acct);
528         if(user_sid == NULL) {
529                 Py_RETURN_NONE;
530         }
531
532         mem_ctx = talloc_new(NULL);
533         if (mem_ctx == NULL) {
534                 PyErr_NoMemory();
535                 return NULL;
536         }
537         copy_user_sid = dom_sid_dup(mem_ctx, user_sid);
538         if (copy_user_sid == NULL) {
539                 PyErr_NoMemory();
540                 talloc_free(mem_ctx);
541                 return NULL;
542         }
543
544         py_user_sid = pytalloc_steal(dom_sid_Type, copy_user_sid);
545
546         talloc_free(mem_ctx);
547
548         return py_user_sid;
549 }
550
551 static int py_samu_set_user_sid(PyObject *obj, PyObject *value, void *closure)
552 {
553         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
554
555         PY_CHECK_TYPE(dom_sid_Type, value, return -1;);
556         if (!pdb_set_user_sid(sam_acct, (struct dom_sid *)pytalloc_get_ptr(value), PDB_CHANGED)) {
557                 return -1;
558         }
559         return 0;
560 }
561
562 static PyObject *py_samu_get_group_sid(PyObject *obj, void *closure)
563 {
564         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
565         PyObject *py_group_sid;
566         const struct dom_sid *group_sid;
567         struct dom_sid *copy_group_sid;
568         TALLOC_CTX *mem_ctx;
569
570         mem_ctx = talloc_stackframe();
571         if (mem_ctx == NULL) {
572                 PyErr_NoMemory();
573                 return NULL;
574         }
575
576         group_sid = pdb_get_group_sid(sam_acct);
577         if (group_sid == NULL) {
578                 Py_RETURN_NONE;
579         }
580
581         copy_group_sid = dom_sid_dup(mem_ctx, group_sid);
582         if (copy_group_sid == NULL) {
583                 PyErr_NoMemory();
584                 talloc_free(mem_ctx);
585                 return NULL;
586         }
587
588         py_group_sid = pytalloc_steal(dom_sid_Type, copy_group_sid);
589
590         talloc_free(mem_ctx);
591
592         return py_group_sid;
593 }
594
595 static int py_samu_set_group_sid(PyObject *obj, PyObject *value, void *closure)
596 {
597         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
598
599         PY_CHECK_TYPE(dom_sid_Type, value, return -1;);
600         if (!pdb_set_group_sid(sam_acct, (struct dom_sid *)pytalloc_get_ptr(value), PDB_CHANGED)) {
601                 return -1;
602         }
603         return 0;
604 }
605
606 static PyObject *py_samu_get_lanman_passwd(PyObject *obj, void *closure)
607 {
608         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
609         PyObject *py_lm_pw;
610         const char *lm_pw;
611
612         lm_pw = (const char *)pdb_get_lanman_passwd(sam_acct);
613         if (lm_pw == NULL) {
614                 Py_RETURN_NONE;
615         }
616
617         py_lm_pw = PyString_FromStringAndSize(lm_pw, LM_HASH_LEN);
618         return py_lm_pw;
619 }
620
621 static int py_samu_set_lanman_passwd(PyObject *obj, PyObject *value, void *closure)
622 {
623         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
624
625         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
626         if (!pdb_set_lanman_passwd(sam_acct, (uint8_t *)PyString_AsString(value), PDB_CHANGED)) {
627                 return -1;
628         }
629         return 0;
630 }
631
632 static PyObject *py_samu_get_nt_passwd(PyObject *obj, void *closure)
633 {
634         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
635         PyObject *py_nt_pw;
636         const char *nt_pw;
637
638         nt_pw = (const char *)pdb_get_nt_passwd(sam_acct);
639         if (nt_pw == NULL) {
640                 Py_RETURN_NONE;
641         }
642
643         py_nt_pw = PyString_FromStringAndSize(nt_pw, NT_HASH_LEN);
644         return py_nt_pw;
645 }
646
647 static int py_samu_set_nt_passwd(PyObject *obj, PyObject *value, void *closure)
648 {
649         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
650
651         if (!pdb_set_nt_passwd(sam_acct, (uint8_t *)PyString_AsString(value), PDB_CHANGED)) {
652                 return -1;
653         }
654         return 0;
655 }
656
657 static PyObject *py_samu_get_pw_history(PyObject *obj, void *closure)
658 {
659         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
660         PyObject *py_nt_pw_his;
661         const char *nt_pw_his;
662         uint32_t hist_len;
663
664         nt_pw_his = (const char *)pdb_get_pw_history(sam_acct, &hist_len);
665         if (nt_pw_his == NULL) {
666                 Py_RETURN_NONE;
667         }
668
669         py_nt_pw_his = PyString_FromStringAndSize(nt_pw_his, hist_len*PW_HISTORY_ENTRY_LEN);
670         return py_nt_pw_his;
671 }
672
673 static int py_samu_set_pw_history(PyObject *obj, PyObject *value, void *closure)
674 {
675         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
676         char *nt_pw_his;
677         Py_ssize_t len;
678         uint32_t hist_len;
679
680         PyString_AsStringAndSize(value, &nt_pw_his, &len);
681         hist_len = len / PW_HISTORY_ENTRY_LEN;
682         if (!pdb_set_pw_history(sam_acct, (uint8_t *)nt_pw_his, hist_len, PDB_CHANGED)) {
683                 return -1;
684         }
685         return 0;
686 }
687
688 static PyObject *py_samu_get_plaintext_passwd(PyObject *obj, void *closure)
689 {
690         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
691         PyObject *py_plaintext_pw;
692         const char *plaintext_pw;
693
694         plaintext_pw = pdb_get_plaintext_passwd(sam_acct);
695         if (plaintext_pw == NULL) {
696                 Py_RETURN_NONE;
697         }
698
699         py_plaintext_pw = PyString_FromString(plaintext_pw);
700         return py_plaintext_pw;
701 }
702
703 static int py_samu_set_plaintext_passwd(PyObject *obj, PyObject *value, void *closure)
704 {
705         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
706
707         if (!pdb_set_plaintext_passwd(sam_acct, PyString_AsString(value))) {
708                 return -1;
709         }
710         return 0;
711 }
712
713 static PyObject *py_samu_get_acct_ctrl(PyObject *obj, void *closure)
714 {
715         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
716         PyObject *py_acct_ctrl;
717
718         py_acct_ctrl = PyInt_FromLong(pdb_get_acct_ctrl(sam_acct));
719         return py_acct_ctrl;
720 }
721
722 static int py_samu_set_acct_ctrl(PyObject *obj, PyObject *value, void *closure)
723 {
724         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
725
726         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
727         if (!pdb_set_acct_ctrl(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
728                 return -1;
729         }
730         return 0;
731 }
732
733 static PyObject *py_samu_get_logon_divs(PyObject *obj, void *closure)
734 {
735         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
736         PyObject *py_logon_divs;
737
738         py_logon_divs = PyInt_FromLong(pdb_get_logon_divs(sam_acct));
739         return py_logon_divs;
740 }
741
742 static int py_samu_set_logon_divs(PyObject *obj, PyObject *value, void *closure)
743 {
744         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
745
746         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
747         if (!pdb_set_logon_divs(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
748                 return -1;
749         }
750         return 0;
751 }
752
753 static PyObject *py_samu_get_hours_len(PyObject *obj, void *closure)
754 {
755         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
756         PyObject *py_hours_len;
757
758         py_hours_len = PyInt_FromLong(pdb_get_hours_len(sam_acct));
759         return py_hours_len;
760 }
761
762 static int py_samu_set_hours_len(PyObject *obj, PyObject *value, void *closure)
763 {
764         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
765
766         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
767         if (!pdb_set_hours_len(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
768                 return -1;
769         }
770         return 0;
771 }
772
773 static PyObject *py_samu_get_hours(PyObject *obj, void *closure)
774 {
775         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
776         PyObject *py_hours;
777         const char *hours;
778         int hours_len, i;
779
780         hours = (const char *)pdb_get_hours(sam_acct);
781         if(! hours) {
782                 Py_RETURN_NONE;
783         }
784
785         hours_len = pdb_get_hours_len(sam_acct);
786         if ((py_hours = PyList_New(hours_len)) == NULL) {
787                 PyErr_NoMemory();
788                 return NULL;
789         }
790
791         for (i=0; i<hours_len; i++) {
792                 PyList_SetItem(py_hours, i, PyInt_FromLong(hours[i]));
793         }
794         return py_hours;
795 }
796
797 static int py_samu_set_hours(PyObject *obj, PyObject *value, void *closure)
798 {
799         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
800         int i;
801         uint8_t *hours;
802         int hours_len;
803         bool status;
804
805         PY_CHECK_TYPE(&PyList_Type, value, return -1;);
806
807         hours_len = PyList_GET_SIZE(value);
808
809         hours = talloc_array(pytalloc_get_mem_ctx(obj), uint8_t, hours_len);
810         if (!hours) {
811                 PyErr_NoMemory();
812                 return -1;
813         }
814
815         for (i=0; i < hours_len; i++) {
816                 PY_CHECK_TYPE(&PyInt_Type, PyList_GET_ITEM(value,i), return -1;);
817                 hours[i] = PyInt_AsLong(PyList_GET_ITEM(value, i));
818         }
819
820         status = pdb_set_hours(sam_acct, hours, hours_len, PDB_CHANGED);
821         talloc_free(hours);
822
823         if(! status) {
824                 return -1;
825         }
826         return 0;
827 }
828
829 static PyObject *py_samu_get_bad_password_count(PyObject *obj, void *closure)
830 {
831         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
832         PyObject *py_bad_password_count;
833
834         py_bad_password_count = PyInt_FromLong(pdb_get_bad_password_count(sam_acct));
835         return py_bad_password_count;
836 }
837
838 static int py_samu_set_bad_password_count(PyObject *obj, PyObject *value, void *closure)
839 {
840         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
841
842         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
843         if (!pdb_set_bad_password_count(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
844                 return -1;
845         }
846         return 0;
847 }
848
849 static PyObject *py_samu_get_logon_count(PyObject *obj, void *closure)
850 {
851         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
852         PyObject *py_logon_count;
853
854         py_logon_count = PyInt_FromLong(pdb_get_logon_count(sam_acct));
855         return py_logon_count;
856 }
857
858 static int py_samu_set_logon_count(PyObject *obj, PyObject *value, void *closure)
859 {
860         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
861
862         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
863         if (!pdb_set_logon_count(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
864                 return -1;
865         }
866         return 0;
867 }
868
869 static PyObject *py_samu_get_country_code(PyObject *obj, void *closure)
870 {
871         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
872         PyObject *py_country_code;
873
874         py_country_code = PyInt_FromLong(pdb_get_country_code(sam_acct));
875         return py_country_code;
876 }
877
878 static int py_samu_set_country_code(PyObject *obj, PyObject *value, void *closure)
879 {
880         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
881
882         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
883         if (!pdb_set_country_code(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
884                 return -1;
885         }
886         return 0;
887 }
888
889 static PyObject *py_samu_get_code_page(PyObject *obj, void *closure)
890 {
891         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
892         PyObject *py_code_page;
893
894         py_code_page = PyInt_FromLong(pdb_get_code_page(sam_acct));
895         return py_code_page;
896 }
897
898 static int py_samu_set_code_page(PyObject *obj, PyObject *value, void *closure)
899 {
900         struct samu *sam_acct = (struct samu *)pytalloc_get_ptr(obj);
901
902         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
903         if (!pdb_set_code_page(sam_acct, PyInt_AsLong(value), PDB_CHANGED)) {
904                 return -1;
905         }
906         return 0;
907 }
908
909 static PyGetSetDef py_samu_getsetters[] = {
910         { discard_const_p(char, "logon_time"), py_samu_get_logon_time, py_samu_set_logon_time },
911         { discard_const_p(char, "logoff_time"), py_samu_get_logoff_time, py_samu_set_logoff_time },
912         { discard_const_p(char, "kickoff_time"), py_samu_get_kickoff_time, py_samu_set_kickoff_time },
913         { discard_const_p(char, "bad_password_time"), py_samu_get_bad_password_time, py_samu_set_bad_password_time },
914         { discard_const_p(char, "pass_last_set_time"), py_samu_get_pass_last_set_time, py_samu_set_pass_last_set_time },
915         { discard_const_p(char, "pass_can_change_time"), py_samu_get_pass_can_change_time, py_samu_set_pass_can_change_time },
916         { discard_const_p(char, "pass_must_change_time"), py_samu_get_pass_must_change_time, py_samu_set_pass_must_change_time },
917         { discard_const_p(char, "username"), py_samu_get_username, py_samu_set_username },
918         { discard_const_p(char, "domain"), py_samu_get_domain, py_samu_set_domain },
919         { discard_const_p(char, "nt_username"), py_samu_get_nt_username, py_samu_set_nt_username },
920         { discard_const_p(char, "full_name"), py_samu_get_full_name, py_samu_set_full_name },
921         { discard_const_p(char, "home_dir"), py_samu_get_home_dir, py_samu_set_home_dir },
922         { discard_const_p(char, "dir_drive"), py_samu_get_dir_drive, py_samu_set_dir_drive },
923         { discard_const_p(char, "logon_script"), py_samu_get_logon_script, py_samu_set_logon_script },
924         { discard_const_p(char, "profile_path"), py_samu_get_profile_path, py_samu_set_profile_path },
925         { discard_const_p(char, "acct_desc"), py_samu_get_acct_desc, py_samu_set_acct_desc },
926         { discard_const_p(char, "workstations"), py_samu_get_workstations, py_samu_set_workstations },
927         { discard_const_p(char, "comment"), py_samu_get_comment, py_samu_set_comment },
928         { discard_const_p(char, "munged_dial"), py_samu_get_munged_dial, py_samu_set_munged_dial },
929         { discard_const_p(char, "user_sid"), py_samu_get_user_sid, py_samu_set_user_sid },
930         { discard_const_p(char, "group_sid"), py_samu_get_group_sid, py_samu_set_group_sid },
931         { discard_const_p(char, "lanman_passwd"), py_samu_get_lanman_passwd, py_samu_set_lanman_passwd },
932         { discard_const_p(char, "nt_passwd"), py_samu_get_nt_passwd, py_samu_set_nt_passwd },
933         { discard_const_p(char, "pw_history"), py_samu_get_pw_history, py_samu_set_pw_history },
934         { discard_const_p(char, "plaintext_passwd"), py_samu_get_plaintext_passwd, py_samu_set_plaintext_passwd },
935         { discard_const_p(char, "acct_ctrl"), py_samu_get_acct_ctrl, py_samu_set_acct_ctrl },
936         { discard_const_p(char, "logon_divs"), py_samu_get_logon_divs, py_samu_set_logon_divs },
937         { discard_const_p(char, "hours_len"), py_samu_get_hours_len, py_samu_set_hours_len },
938         { discard_const_p(char, "hours"), py_samu_get_hours, py_samu_set_hours },
939         { discard_const_p(char, "bad_password_count"), py_samu_get_bad_password_count, py_samu_set_bad_password_count },
940         { discard_const_p(char, "logon_count"), py_samu_get_logon_count, py_samu_set_logon_count },
941         { discard_const_p(char, "country_code"), py_samu_get_country_code, py_samu_set_country_code },
942         { discard_const_p(char, "code_page"), py_samu_get_code_page, py_samu_set_code_page },
943         { NULL }
944 };
945
946
947 /************************** PIDL Autogeneratd ******************************/
948
949 static PyObject *py_samu_new(PyTypeObject *type, PyObject *args, PyObject *kwargs)
950 {
951         struct samu *sam_acct;
952
953         sam_acct = samu_new(NULL);
954         if (!sam_acct) {
955                 PyErr_NoMemory();
956                 return NULL;
957         }
958
959         return pytalloc_steal(type, sam_acct);
960 }
961
962 static PyTypeObject PySamu = {
963         .tp_name = "passdb.Samu",
964         .tp_basicsize = sizeof(pytalloc_Object),
965         .tp_getset = py_samu_getsetters,
966         .tp_methods = NULL,
967         .tp_new = py_samu_new,
968         .tp_flags = Py_TPFLAGS_DEFAULT | Py_TPFLAGS_BASETYPE,
969         .tp_doc = "Samu() -> samu object\n",
970 };
971
972
973 static PyObject *py_groupmap_get_gid(PyObject *obj, void *closure)
974 {
975         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
976         PyObject *py_gid;
977
978         py_gid = PyInt_FromLong(group_map->gid);
979         return py_gid;
980 }
981
982 static int py_groupmap_set_gid(PyObject *obj, PyObject *value, void *closure)
983 {
984         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
985
986         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
987         group_map->gid = PyInt_AsLong(value);
988         return 0;
989 }
990
991 static PyObject *py_groupmap_get_sid(PyObject *obj, void *closure)
992 {
993         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
994         PyObject *py_sid;
995         struct dom_sid *group_sid;
996         TALLOC_CTX *mem_ctx;
997
998         mem_ctx = talloc_new(NULL);
999         if (mem_ctx == NULL) {
1000                 PyErr_NoMemory();
1001                 return NULL;
1002         }
1003
1004         group_sid = dom_sid_dup(mem_ctx, &group_map->sid);
1005         if (group_sid == NULL) {
1006                 PyErr_NoMemory();
1007                 talloc_free(mem_ctx);
1008                 return NULL;
1009         }
1010
1011         py_sid = pytalloc_steal(dom_sid_Type, group_sid);
1012
1013         talloc_free(mem_ctx);
1014
1015         return py_sid;
1016 }
1017
1018 static int py_groupmap_set_sid(PyObject *obj, PyObject *value, void *closure)
1019 {
1020         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
1021
1022         PY_CHECK_TYPE(dom_sid_Type, value, return -1;);
1023         group_map->sid = *pytalloc_get_type(value, struct dom_sid);
1024         return 0;
1025 }
1026
1027 static PyObject *py_groupmap_get_sid_name_use(PyObject *obj, void *closure)
1028 {
1029         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
1030         PyObject *py_sid_name_use;
1031
1032         py_sid_name_use = PyInt_FromLong(group_map->sid_name_use);
1033         return py_sid_name_use;
1034 }
1035
1036 static int py_groupmap_set_sid_name_use(PyObject *obj, PyObject *value, void *closure)
1037 {
1038         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
1039
1040         PY_CHECK_TYPE(&PyInt_Type, value, return -1;);
1041         group_map->sid_name_use = PyInt_AsLong(value);
1042         return 0;
1043 }
1044
1045 static PyObject *py_groupmap_get_nt_name(PyObject *obj, void *closure)
1046 {
1047         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
1048         PyObject *py_nt_name;
1049         if (group_map->nt_name == NULL) {
1050                 py_nt_name = Py_None;
1051                 Py_INCREF(py_nt_name);
1052         } else {
1053                 py_nt_name = PyString_FromString(group_map->nt_name);
1054         }
1055         return py_nt_name;
1056 }
1057
1058 static int py_groupmap_set_nt_name(PyObject *obj, PyObject *value, void *closure)
1059 {
1060         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
1061
1062         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
1063         if (value == Py_None) {
1064                 fstrcpy(group_map->nt_name, NULL);
1065         } else {
1066                 fstrcpy(group_map->nt_name, PyString_AsString(value));
1067         }
1068         return 0;
1069 }
1070
1071 static PyObject *py_groupmap_get_comment(PyObject *obj, void *closure)
1072 {
1073         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
1074         PyObject *py_comment;
1075         if (group_map->comment == NULL) {
1076                 py_comment = Py_None;
1077                 Py_INCREF(py_comment);
1078         } else {
1079                 py_comment = PyString_FromString(group_map->comment);
1080         }
1081         return py_comment;
1082 }
1083
1084 static int py_groupmap_set_comment(PyObject *obj, PyObject *value, void *closure)
1085 {
1086         GROUP_MAP *group_map = (GROUP_MAP *)pytalloc_get_ptr(obj);
1087
1088         PY_CHECK_TYPE(&PyString_Type, value, return -1;);
1089         if (value == Py_None) {
1090                 fstrcpy(group_map->comment, NULL);
1091         } else {
1092                 fstrcpy(group_map->comment, PyString_AsString(value));
1093         }
1094         return 0;
1095 }
1096
1097 static PyGetSetDef py_groupmap_getsetters[] = {
1098         { discard_const_p(char, "gid"), py_groupmap_get_gid, py_groupmap_set_gid },
1099         { discard_const_p(char, "sid"), py_groupmap_get_sid, py_groupmap_set_sid },
1100         { discard_const_p(char, "sid_name_use"), py_groupmap_get_sid_name_use, py_groupmap_set_sid_name_use },
1101         { discard_const_p(char, "nt_name"), py_groupmap_get_nt_name, py_groupmap_set_nt_name },
1102         { discard_const_p(char, "comment"), py_groupmap_get_comment, py_groupmap_set_comment },
1103         { NULL }
1104 };
1105
1106 static PyObject *py_groupmap_new(PyTypeObject *type, PyObject *args, PyObject *kwargs)
1107 {
1108         GROUP_MAP *group_map;
1109         TALLOC_CTX *mem_ctx;
1110         PyObject *py_group_map;
1111
1112         mem_ctx = talloc_new(NULL);
1113         if (mem_ctx == NULL) {
1114                 PyErr_NoMemory();
1115                 return NULL;
1116         }
1117
1118         group_map = talloc_zero(mem_ctx, GROUP_MAP);
1119         if (group_map == NULL) {
1120                 PyErr_NoMemory();
1121                 talloc_free(mem_ctx);
1122                 return NULL;
1123         }
1124
1125         py_group_map = pytalloc_steal(type, group_map);
1126         if (py_group_map == NULL) {
1127                 PyErr_NoMemory();
1128                 talloc_free(mem_ctx);
1129                 return NULL;
1130         }
1131
1132         talloc_free(mem_ctx);
1133
1134         return py_group_map;
1135 }
1136
1137
1138 static PyTypeObject PyGroupmap = {
1139         .tp_name = "passdb.Groupmap",
1140         .tp_basicsize = sizeof(pytalloc_Object),
1141         .tp_getset = py_groupmap_getsetters,
1142         .tp_methods = NULL,
1143         .tp_new = py_groupmap_new,
1144         .tp_flags = Py_TPFLAGS_DEFAULT | Py_TPFLAGS_BASETYPE,
1145         .tp_doc = "Groupmap() -> group map object\n",
1146 };
1147
1148
1149 static PyObject *py_pdb_domain_info(pytalloc_Object *self, PyObject *args)
1150 {
1151         struct pdb_methods *methods;
1152         struct pdb_domain_info *domain_info;
1153         PyObject *py_domain_info;
1154         TALLOC_CTX *tframe;
1155         struct dom_sid *sid;
1156         struct GUID *guid;
1157
1158         methods = pytalloc_get_ptr(self);
1159
1160         if ((tframe = talloc_stackframe()) == NULL) {
1161                 PyErr_NoMemory();
1162                 return NULL;
1163         }
1164
1165         domain_info = methods->get_domain_info(methods, tframe);
1166         if (! domain_info) {
1167                 Py_RETURN_NONE;
1168         }
1169
1170         sid = dom_sid_dup(tframe, &domain_info->sid);
1171         if (sid == NULL) {
1172                 PyErr_NoMemory();
1173                 talloc_free(tframe);
1174                 return NULL;
1175         }
1176
1177         guid = talloc(tframe, struct GUID);
1178         if (guid == NULL) {
1179                 PyErr_NoMemory();
1180                 talloc_free(tframe);
1181                 return NULL;
1182         }
1183         *guid = domain_info->guid;
1184
1185         if ((py_domain_info = PyDict_New()) == NULL) {
1186                 PyErr_NoMemory();
1187                 return NULL;
1188         }
1189
1190         PyDict_SetItemString(py_domain_info, "name", PyString_FromString(domain_info->name));
1191         PyDict_SetItemString(py_domain_info, "dns_domain", PyString_FromString(domain_info->name));
1192         PyDict_SetItemString(py_domain_info, "dns_forest", PyString_FromString(domain_info->name));
1193         PyDict_SetItemString(py_domain_info, "dom_sid", pytalloc_steal(dom_sid_Type, sid));
1194         PyDict_SetItemString(py_domain_info, "guid", pytalloc_steal(guid_Type, guid));
1195
1196         talloc_free(tframe);
1197
1198         return py_domain_info;
1199 }
1200
1201
1202 static PyObject *py_pdb_getsampwnam(pytalloc_Object *self, PyObject *args)
1203 {
1204         NTSTATUS status;
1205         const char *username;
1206         struct pdb_methods *methods;
1207         struct samu *sam_acct;
1208         PyObject *py_sam_acct;
1209         TALLOC_CTX *tframe;
1210
1211         if (!PyArg_ParseTuple(args, "s:getsampwnam", &username)) {
1212                 return NULL;
1213         }
1214
1215         methods = pytalloc_get_ptr(self);
1216
1217         if ((tframe = talloc_stackframe()) == NULL) {
1218                 PyErr_NoMemory();
1219                 return NULL;
1220         }
1221
1222         py_sam_acct = py_samu_new(&PySamu, NULL, NULL);
1223         if (py_sam_acct == NULL) {
1224                 PyErr_NoMemory();
1225                 talloc_free(tframe);
1226                 return NULL;
1227         }
1228         sam_acct = (struct samu *)pytalloc_get_ptr(py_sam_acct);
1229
1230         status = methods->getsampwnam(methods, sam_acct, username);
1231         if (!NT_STATUS_IS_OK(status)) {
1232                 PyErr_Format(py_pdb_error, "Unable to get user information for '%s', (%d,%s)",
1233                                 username,
1234                                 NT_STATUS_V(status),
1235                                 get_friendly_nt_error_msg(status));
1236                 Py_DECREF(py_sam_acct);
1237                 talloc_free(tframe);
1238                 return NULL;
1239         }
1240
1241         talloc_free(tframe);
1242         return py_sam_acct;
1243 }
1244
1245 static PyObject *py_pdb_getsampwsid(pytalloc_Object *self, PyObject *args)
1246 {
1247         NTSTATUS status;
1248         struct pdb_methods *methods;
1249         struct samu *sam_acct;
1250         PyObject *py_sam_acct;
1251         TALLOC_CTX *tframe;
1252         PyObject *py_user_sid;
1253
1254         if (!PyArg_ParseTuple(args, "O:getsampwsid", &py_user_sid)) {
1255                 return NULL;
1256         }
1257
1258         methods = pytalloc_get_ptr(self);
1259
1260         if ((tframe = talloc_stackframe()) == NULL) {
1261                 PyErr_NoMemory();
1262                 return NULL;
1263         }
1264
1265         py_sam_acct = py_samu_new(&PySamu, NULL, NULL);
1266         if (py_sam_acct == NULL) {
1267                 PyErr_NoMemory();
1268                 talloc_free(tframe);
1269                 return NULL;
1270         }
1271         sam_acct = (struct samu *)pytalloc_get_ptr(py_sam_acct);
1272
1273         status = methods->getsampwsid(methods, sam_acct, pytalloc_get_ptr(py_user_sid));
1274         if (!NT_STATUS_IS_OK(status)) {
1275                 PyErr_Format(py_pdb_error, "Unable to get user information from SID, (%d,%s)",
1276                                 NT_STATUS_V(status),
1277                                 get_friendly_nt_error_msg(status));
1278                 Py_DECREF(py_sam_acct);
1279                 talloc_free(tframe);
1280                 return NULL;
1281         }
1282
1283         talloc_free(tframe);
1284         return py_sam_acct;
1285 }
1286
1287 static PyObject *py_pdb_create_user(pytalloc_Object *self, PyObject *args)
1288 {
1289         NTSTATUS status;
1290         struct pdb_methods *methods;
1291         const char *username;
1292         unsigned int acct_flags;
1293         unsigned int rid;
1294         TALLOC_CTX *tframe;
1295
1296         if (!PyArg_ParseTuple(args, "sI:create_user", &username, &acct_flags)) {
1297                 return NULL;
1298         }
1299
1300         methods = pytalloc_get_ptr(self);
1301
1302         if ((tframe = talloc_stackframe()) == NULL) {
1303                 PyErr_NoMemory();
1304                 return NULL;
1305         }
1306
1307         status = methods->create_user(methods, tframe, username, acct_flags, &rid);
1308         if (!NT_STATUS_IS_OK(status)) {
1309                 PyErr_Format(py_pdb_error, "Unable to create user (%s), (%d,%s)",
1310                                 username,
1311                                 NT_STATUS_V(status),
1312                                 get_friendly_nt_error_msg(status));
1313                 talloc_free(tframe);
1314                 return NULL;
1315         }
1316
1317         talloc_free(tframe);
1318         return PyInt_FromLong(rid);
1319 }
1320
1321 static PyObject *py_pdb_delete_user(pytalloc_Object *self, PyObject *args)
1322 {
1323         NTSTATUS status;
1324         struct pdb_methods *methods;
1325         TALLOC_CTX *tframe;
1326         struct samu *sam_acct;
1327         PyObject *py_sam_acct;
1328
1329         if (!PyArg_ParseTuple(args, "O!:delete_user", &PySamu, &py_sam_acct)) {
1330                 return NULL;
1331         }
1332
1333         methods = pytalloc_get_ptr(self);
1334
1335         if ((tframe = talloc_stackframe()) == NULL) {
1336                 PyErr_NoMemory();
1337                 return NULL;
1338         }
1339
1340         sam_acct = pytalloc_get_ptr(py_sam_acct);
1341
1342         status = methods->delete_user(methods, tframe, sam_acct);
1343         if (!NT_STATUS_IS_OK(status)) {
1344                 PyErr_Format(py_pdb_error, "Unable to delete user, (%d,%s)",
1345                                 NT_STATUS_V(status),
1346                                 get_friendly_nt_error_msg(status));
1347                 talloc_free(tframe);
1348                 return NULL;
1349         }
1350
1351         talloc_free(tframe);
1352         Py_RETURN_NONE;
1353 }
1354
1355 static PyObject *py_pdb_add_sam_account(pytalloc_Object *self, PyObject *args)
1356 {
1357         NTSTATUS status;
1358         struct pdb_methods *methods;
1359         TALLOC_CTX *tframe;
1360         struct samu *sam_acct;
1361         PyObject *py_sam_acct;
1362
1363         if (!PyArg_ParseTuple(args, "O!:add_sam_account", &PySamu, &py_sam_acct)) {
1364                 return NULL;
1365         }
1366
1367         methods = pytalloc_get_ptr(self);
1368
1369         if ((tframe = talloc_stackframe()) == NULL) {
1370                 PyErr_NoMemory();
1371                 return NULL;
1372         }
1373
1374         sam_acct = pytalloc_get_ptr(py_sam_acct);
1375
1376         status = methods->add_sam_account(methods, sam_acct);
1377         if (!NT_STATUS_IS_OK(status)) {
1378                 PyErr_Format(py_pdb_error, "Unable to add sam account '%s', (%d,%s)",
1379                                 sam_acct->username,
1380                                 NT_STATUS_V(status),
1381                                 get_friendly_nt_error_msg(status));
1382                 talloc_free(tframe);
1383                 return NULL;
1384         }
1385
1386         talloc_free(tframe);
1387         Py_RETURN_NONE;
1388 }
1389
1390 static PyObject *py_pdb_update_sam_account(pytalloc_Object *self, PyObject *args)
1391 {
1392         NTSTATUS status;
1393         struct pdb_methods *methods;
1394         TALLOC_CTX *tframe;
1395         struct samu *sam_acct;
1396         PyObject *py_sam_acct;
1397
1398         if (!PyArg_ParseTuple(args, "O!:update_sam_account", &PySamu, &py_sam_acct)) {
1399                 return NULL;
1400         }
1401
1402         methods = pytalloc_get_ptr(self);
1403
1404         if ((tframe = talloc_stackframe()) == NULL) {
1405                 PyErr_NoMemory();
1406                 return NULL;
1407         }
1408
1409         sam_acct = pytalloc_get_ptr(py_sam_acct);
1410
1411         status = methods->update_sam_account(methods, sam_acct);
1412         if (!NT_STATUS_IS_OK(status)) {
1413                 PyErr_Format(py_pdb_error, "Unable to update sam account, (%d,%s)",
1414                                 NT_STATUS_V(status),
1415                                 get_friendly_nt_error_msg(status));
1416                 talloc_free(tframe);
1417                 return NULL;
1418         }
1419
1420         talloc_free(tframe);
1421         Py_RETURN_NONE;
1422 }
1423
1424 static PyObject *py_pdb_delete_sam_account(pytalloc_Object *self, PyObject *args)
1425 {
1426         NTSTATUS status;
1427         struct pdb_methods *methods;
1428         TALLOC_CTX *tframe;
1429         struct samu *sam_acct;
1430         PyObject *py_sam_acct;
1431
1432         if (!PyArg_ParseTuple(args, "O!:delete_sam_account", &PySamu, &py_sam_acct)) {
1433                 return NULL;
1434         }
1435
1436         methods = pytalloc_get_ptr(self);
1437
1438         if ((tframe = talloc_stackframe()) == NULL) {
1439                 PyErr_NoMemory();
1440                 return NULL;
1441         }
1442
1443         sam_acct = pytalloc_get_ptr(py_sam_acct);
1444
1445         status = methods->delete_sam_account(methods, sam_acct);
1446         if (!NT_STATUS_IS_OK(status)) {
1447                 PyErr_Format(py_pdb_error, "Unable to delete sam account, (%d,%s)",
1448                                 NT_STATUS_V(status),
1449                                 get_friendly_nt_error_msg(status));
1450                 talloc_free(tframe);
1451                 return NULL;
1452         }
1453
1454         talloc_free(tframe);
1455         Py_RETURN_NONE;
1456 }
1457
1458 static PyObject *py_pdb_rename_sam_account(pytalloc_Object *self, PyObject *args)
1459 {
1460         NTSTATUS status;
1461         struct pdb_methods *methods;
1462         TALLOC_CTX *tframe;
1463         struct samu *sam_acct;
1464         const char *new_username;
1465         PyObject *py_sam_acct;
1466
1467         if (!PyArg_ParseTuple(args, "O!s:rename_sam_account", &PySamu, &py_sam_acct,
1468                                         &new_username)) {
1469                 return NULL;
1470         }
1471
1472         methods = pytalloc_get_ptr(self);
1473
1474         if ((tframe = talloc_stackframe()) == NULL) {
1475                 PyErr_NoMemory();
1476                 return NULL;
1477         }
1478
1479         sam_acct = pytalloc_get_ptr(py_sam_acct);
1480
1481         status = methods->rename_sam_account(methods, sam_acct, new_username);
1482         if (!NT_STATUS_IS_OK(status)) {
1483                 PyErr_Format(py_pdb_error, "Unable to rename sam account, (%d,%s)",
1484                                 NT_STATUS_V(status),
1485                                 get_friendly_nt_error_msg(status));
1486                 talloc_free(tframe);
1487                 return NULL;
1488         }
1489
1490         talloc_free(tframe);
1491         Py_RETURN_NONE;
1492 }
1493
1494
1495 static PyObject *py_pdb_getgrsid(pytalloc_Object *self, PyObject *args)
1496 {
1497         NTSTATUS status;
1498         struct pdb_methods *methods;
1499         TALLOC_CTX *tframe;
1500         GROUP_MAP *group_map;
1501         struct dom_sid *domain_sid;
1502         PyObject *py_domain_sid, *py_group_map;
1503
1504         if (!PyArg_ParseTuple(args, "O!:getgrsid", dom_sid_Type, &py_domain_sid)) {
1505                 return NULL;
1506         }
1507
1508         methods = pytalloc_get_ptr(self);
1509
1510         if ((tframe = talloc_stackframe()) == NULL) {
1511                 PyErr_NoMemory();
1512                 return NULL;
1513         }
1514
1515         domain_sid = pytalloc_get_ptr(py_domain_sid);
1516
1517         py_group_map = py_groupmap_new(&PyGroupmap, NULL, NULL);
1518         if (py_group_map == NULL) {
1519                 PyErr_NoMemory();
1520                 talloc_free(tframe);
1521                 return NULL;
1522         }
1523
1524         group_map = pytalloc_get_ptr(py_group_map);
1525
1526         status = methods->getgrsid(methods, group_map, *domain_sid);
1527         if (!NT_STATUS_IS_OK(status)) {
1528                 PyErr_Format(py_pdb_error, "Unable to get group information by sid, (%d,%s)",
1529                                 NT_STATUS_V(status),
1530                                 get_friendly_nt_error_msg(status));
1531                 talloc_free(tframe);
1532                 return NULL;
1533         }
1534
1535         talloc_free(tframe);
1536         return py_group_map;
1537 }
1538
1539
1540 static PyObject *py_pdb_getgrgid(pytalloc_Object *self, PyObject *args)
1541 {
1542         NTSTATUS status;
1543         struct pdb_methods *methods;
1544         TALLOC_CTX *tframe;
1545         GROUP_MAP *group_map;
1546         PyObject *py_group_map;
1547         unsigned int gid_value;
1548
1549         if (!PyArg_ParseTuple(args, "I:getgrgid", &gid_value)) {
1550                 return NULL;
1551         }
1552
1553         methods = pytalloc_get_ptr(self);
1554
1555         if ((tframe = talloc_stackframe()) == NULL) {
1556                 PyErr_NoMemory();
1557                 return NULL;
1558         }
1559
1560         py_group_map = py_groupmap_new(&PyGroupmap, NULL, NULL);
1561         if (py_group_map == NULL) {
1562                 PyErr_NoMemory();
1563                 talloc_free(tframe);
1564                 return NULL;
1565         }
1566
1567         group_map = pytalloc_get_ptr(py_group_map);
1568
1569         status = methods->getgrgid(methods, group_map, gid_value);
1570         if (!NT_STATUS_IS_OK(status)) {
1571                 PyErr_Format(py_pdb_error, "Unable to get group information by gid, (%d,%s)",
1572                                 NT_STATUS_V(status),
1573                                 get_friendly_nt_error_msg(status));
1574                 talloc_free(tframe);
1575                 return NULL;
1576         }
1577
1578         talloc_free(tframe);
1579         return py_group_map;
1580 }
1581
1582
1583 static PyObject *py_pdb_getgrnam(pytalloc_Object *self, PyObject *args)
1584 {
1585         NTSTATUS status;
1586         struct pdb_methods *methods;
1587         TALLOC_CTX *tframe;
1588         GROUP_MAP *group_map;
1589         PyObject *py_group_map;
1590         const char *groupname;
1591
1592         if (!PyArg_ParseTuple(args, "s:getgrnam", &groupname)) {
1593                 return NULL;
1594         }
1595
1596         methods = pytalloc_get_ptr(self);
1597
1598         if ((tframe = talloc_stackframe()) == NULL) {
1599                 PyErr_NoMemory();
1600                 return NULL;
1601         }
1602
1603         py_group_map = py_groupmap_new(&PyGroupmap, NULL, NULL);
1604         if (py_group_map == NULL) {
1605                 PyErr_NoMemory();
1606                 talloc_free(tframe);
1607                 return NULL;
1608         }
1609
1610         group_map = pytalloc_get_ptr(py_group_map);
1611
1612         status = methods->getgrnam(methods, group_map, groupname);
1613         if (!NT_STATUS_IS_OK(status)) {
1614                 PyErr_Format(py_pdb_error, "Unable to get group information by name, (%d,%s)",
1615                                 NT_STATUS_V(status),
1616                                 get_friendly_nt_error_msg(status));
1617                 talloc_free(tframe);
1618                 return NULL;
1619         }
1620
1621         talloc_free(tframe);
1622         return py_group_map;
1623 }
1624
1625
1626 static PyObject *py_pdb_create_dom_group(pytalloc_Object *self, PyObject *args)
1627 {
1628         NTSTATUS status;
1629         struct pdb_methods *methods;
1630         TALLOC_CTX *tframe;
1631         const char *groupname;
1632         uint32_t group_rid;
1633
1634         if (!PyArg_ParseTuple(args, "s:create_dom_group", &groupname)) {
1635                 return NULL;
1636         }
1637
1638         methods = pytalloc_get_ptr(self);
1639
1640         if ((tframe = talloc_stackframe()) == NULL) {
1641                 PyErr_NoMemory();
1642                 return NULL;
1643         }
1644
1645         status = methods->create_dom_group(methods, tframe, groupname, &group_rid);
1646         if (!NT_STATUS_IS_OK(status)) {
1647                 PyErr_Format(py_pdb_error, "Unable to create domain group (%s), (%d,%s)",
1648                                 groupname,
1649                                 NT_STATUS_V(status),
1650                                 get_friendly_nt_error_msg(status));
1651                 talloc_free(tframe);
1652                 return NULL;
1653         }
1654
1655         talloc_free(tframe);
1656         return PyInt_FromLong(group_rid);
1657 }
1658
1659
1660 static PyObject *py_pdb_delete_dom_group(pytalloc_Object *self, PyObject *args)
1661 {
1662         NTSTATUS status;
1663         struct pdb_methods *methods;
1664         TALLOC_CTX *tframe;
1665         unsigned int group_rid;
1666
1667         if (!PyArg_ParseTuple(args, "I:delete_dom_group", &group_rid)) {
1668                 return NULL;
1669         }
1670
1671         methods = pytalloc_get_ptr(self);
1672
1673         if ((tframe = talloc_stackframe()) == NULL) {
1674                 PyErr_NoMemory();
1675                 return NULL;
1676         }
1677
1678         status = methods->delete_dom_group(methods, tframe, group_rid);
1679         if (!NT_STATUS_IS_OK(status)) {
1680                 PyErr_Format(py_pdb_error, "Unable to delete domain group (rid=%d), (%d,%s)",
1681                                 group_rid,
1682                                 NT_STATUS_V(status),
1683                                 get_friendly_nt_error_msg(status));
1684                 talloc_free(tframe);
1685                 return NULL;
1686         }
1687
1688         talloc_free(tframe);
1689         Py_RETURN_NONE;
1690 }
1691
1692
1693 static PyObject *py_pdb_add_group_mapping_entry(pytalloc_Object *self, PyObject *args)
1694 {
1695         NTSTATUS status;
1696         struct pdb_methods *methods;
1697         TALLOC_CTX *tframe;
1698         PyObject *py_group_map;
1699         GROUP_MAP *group_map;
1700
1701         if (!PyArg_ParseTuple(args, "O!:add_group_mapping_entry", &PyGroupmap, &py_group_map)) {
1702                 return NULL;
1703         }
1704
1705         methods = pytalloc_get_ptr(self);
1706
1707         if ((tframe = talloc_stackframe()) == NULL) {
1708                 PyErr_NoMemory();
1709                 return NULL;
1710         }
1711
1712         group_map = pytalloc_get_ptr(py_group_map);
1713
1714         status = methods->add_group_mapping_entry(methods, group_map);
1715         if (!NT_STATUS_IS_OK(status)) {
1716                 PyErr_Format(py_pdb_error, "Unable to add group mapping entry, (%d,%s)",
1717                                 NT_STATUS_V(status),
1718                                 get_friendly_nt_error_msg(status));
1719                 talloc_free(tframe);
1720                 return NULL;
1721         }
1722
1723         talloc_free(tframe);
1724         Py_RETURN_NONE;
1725 }
1726
1727
1728 static PyObject *py_pdb_update_group_mapping_entry(pytalloc_Object *self, PyObject *args)
1729 {
1730         NTSTATUS status;
1731         struct pdb_methods *methods;
1732         TALLOC_CTX *tframe;
1733         PyObject *py_group_map;
1734         GROUP_MAP *group_map;
1735
1736         if (!PyArg_ParseTuple(args, "O!:update_group_mapping_entry", &PyGroupmap, &py_group_map)) {
1737                 return NULL;
1738         }
1739
1740         methods = pytalloc_get_ptr(self);
1741
1742         if ((tframe = talloc_stackframe()) == NULL) {
1743                 PyErr_NoMemory();
1744                 return NULL;
1745         }
1746
1747         group_map = pytalloc_get_ptr(py_group_map);
1748
1749         status = methods->update_group_mapping_entry(methods, group_map);
1750         if (!NT_STATUS_IS_OK(status)) {
1751                 PyErr_Format(py_pdb_error, "Unable to update group mapping entry, (%d,%s)",
1752                                 NT_STATUS_V(status),
1753                                 get_friendly_nt_error_msg(status));
1754                 talloc_free(tframe);
1755                 return NULL;
1756         }
1757
1758         talloc_free(tframe);
1759         Py_RETURN_NONE;
1760 }
1761
1762
1763 static PyObject *py_pdb_delete_group_mapping_entry(pytalloc_Object *self, PyObject *args)
1764 {
1765         NTSTATUS status;
1766         struct pdb_methods *methods;
1767         TALLOC_CTX *tframe;
1768         PyObject *py_group_sid;
1769         struct dom_sid *group_sid;
1770
1771         if (!PyArg_ParseTuple(args, "O!:delete_group_mapping_entry", dom_sid_Type, &py_group_sid)) {
1772                 return NULL;
1773         }
1774
1775         methods = pytalloc_get_ptr(self);
1776
1777         if ((tframe = talloc_stackframe()) == NULL) {
1778                 PyErr_NoMemory();
1779                 return NULL;
1780         }
1781
1782         group_sid = pytalloc_get_ptr(py_group_sid);
1783
1784         status = methods->delete_group_mapping_entry(methods, *group_sid);
1785         if (!NT_STATUS_IS_OK(status)) {
1786                 PyErr_Format(py_pdb_error, "Unable to delete group mapping entry, (%d,%s)",
1787                                 NT_STATUS_V(status),
1788                                 get_friendly_nt_error_msg(status));
1789                 talloc_free(tframe);
1790                 return NULL;
1791         }
1792
1793         talloc_free(tframe);
1794         Py_RETURN_NONE;
1795 }
1796
1797
1798 static PyObject *py_pdb_enum_group_mapping(pytalloc_Object *self, PyObject *args)
1799 {
1800         NTSTATUS status;
1801         struct pdb_methods *methods;
1802         TALLOC_CTX *tframe;
1803         enum lsa_SidType sid_name_use;
1804         int lsa_sidtype_value = SID_NAME_UNKNOWN;
1805         int unix_only = 0;
1806         PyObject *py_domain_sid;
1807         struct dom_sid *domain_sid = NULL;
1808         GROUP_MAP *gmap, *group_map;
1809         size_t num_entries;
1810         PyObject *py_gmap_list, *py_group_map;
1811         int i;
1812
1813         py_domain_sid = Py_None;
1814         Py_INCREF(Py_None);
1815
1816         if (!PyArg_ParseTuple(args, "|O!ii:enum_group_mapping", dom_sid_Type, &py_domain_sid,
1817                                         &lsa_sidtype_value, &unix_only)) {
1818                 return NULL;
1819         }
1820
1821         methods = pytalloc_get_ptr(self);
1822
1823         if ((tframe = talloc_stackframe()) == NULL) {
1824                 PyErr_NoMemory();
1825                 return NULL;
1826         }
1827
1828         sid_name_use = lsa_sidtype_value;
1829
1830         if (py_domain_sid != Py_None) {
1831                 domain_sid = pytalloc_get_ptr(py_domain_sid);
1832         }
1833
1834         status = methods->enum_group_mapping(methods, domain_sid, sid_name_use,
1835                                                 &gmap, &num_entries, unix_only);
1836         if (!NT_STATUS_IS_OK(status)) {
1837                 PyErr_Format(py_pdb_error, "Unable to enumerate group mappings, (%d,%s)",
1838                                 NT_STATUS_V(status),
1839                                 get_friendly_nt_error_msg(status));
1840                 talloc_free(tframe);
1841                 return NULL;
1842         }
1843
1844         py_gmap_list = PyList_New(0);
1845         if (py_gmap_list == NULL) {
1846                 PyErr_NoMemory();
1847                 talloc_free(tframe);
1848                 return NULL;
1849         }
1850
1851         for(i=0; i<num_entries; i++) {
1852                 py_group_map = py_groupmap_new(&PyGroupmap, NULL, NULL);
1853                 if (py_group_map) {
1854                         group_map = pytalloc_get_ptr(py_group_map);
1855                         *group_map = gmap[i];
1856
1857                         PyList_Append(py_gmap_list, py_group_map);
1858                 }
1859         }
1860
1861         free(gmap);
1862         talloc_free(tframe);
1863
1864         return py_gmap_list;
1865 }
1866
1867
1868 static PyObject *py_pdb_enum_group_members(pytalloc_Object *self, PyObject *args)
1869 {
1870         NTSTATUS status;
1871         struct pdb_methods *methods;
1872         TALLOC_CTX *tframe;
1873         PyObject *py_group_sid;
1874         struct dom_sid *group_sid;
1875         uint32_t *member_rids;
1876         size_t num_members;
1877         PyObject *py_sid_list;
1878         struct dom_sid *domain_sid, *member_sid;
1879         int i;
1880
1881         if (!PyArg_ParseTuple(args, "O!:enum_group_members", dom_sid_Type, &py_group_sid)) {
1882                 return NULL;
1883         }
1884
1885         methods = pytalloc_get_ptr(self);
1886
1887         if ((tframe = talloc_stackframe()) == NULL) {
1888                 PyErr_NoMemory();
1889                 return NULL;
1890         }
1891
1892         group_sid = pytalloc_get_ptr(py_group_sid);
1893
1894         status = methods->enum_group_members(methods, tframe, group_sid,
1895                                                 &member_rids, &num_members);
1896         if (!NT_STATUS_IS_OK(status)) {
1897                 PyErr_Format(py_pdb_error, "Unable to enumerate group members, (%d,%s)",
1898                                 NT_STATUS_V(status),
1899                                 get_friendly_nt_error_msg(status));
1900                 talloc_free(tframe);
1901                 return NULL;
1902         }
1903
1904         py_sid_list = PyList_New(0);
1905         if (py_sid_list == NULL) {
1906                 PyErr_NoMemory();
1907                 talloc_free(tframe);
1908                 return NULL;
1909         }
1910
1911         domain_sid = get_global_sam_sid();
1912
1913         for(i=0; i<num_members; i++) {
1914                 member_sid = dom_sid_add_rid(tframe, domain_sid, member_rids[i]);
1915                 PyList_Append(py_sid_list, pytalloc_steal(dom_sid_Type, member_sid));
1916         }
1917
1918         talloc_free(tframe);
1919
1920         return py_sid_list;
1921 }
1922
1923
1924 static PyObject *py_pdb_add_groupmem(pytalloc_Object *self, PyObject *args)
1925 {
1926         NTSTATUS status;
1927         struct pdb_methods *methods;
1928         TALLOC_CTX *tframe;
1929         uint32_t group_rid, member_rid;
1930
1931         if (!PyArg_ParseTuple(args, "II:add_groupmem", &group_rid, &member_rid)) {
1932                 return NULL;
1933         }
1934
1935         methods = pytalloc_get_ptr(self);
1936
1937         if ((tframe = talloc_stackframe()) == NULL) {
1938                 PyErr_NoMemory();
1939                 return NULL;
1940         }
1941
1942         status = methods->add_groupmem(methods, tframe, group_rid, member_rid);
1943         if (!NT_STATUS_IS_OK(status)) {
1944                 PyErr_Format(py_pdb_error, "Unable to add group member, (%d,%s)",
1945                                 NT_STATUS_V(status),
1946                                 get_friendly_nt_error_msg(status));
1947                 talloc_free(tframe);
1948                 return NULL;
1949         }
1950
1951         talloc_free(tframe);
1952         Py_RETURN_NONE;
1953 }
1954
1955
1956 static PyObject *py_pdb_del_groupmem(pytalloc_Object *self, PyObject *args)
1957 {
1958         NTSTATUS status;
1959         struct pdb_methods *methods;
1960         TALLOC_CTX *tframe;
1961         uint32_t group_rid, member_rid;
1962
1963         if (!PyArg_ParseTuple(args, "II:del_groupmem", &group_rid, &member_rid)) {
1964                 return NULL;
1965         }
1966
1967         methods = pytalloc_get_ptr(self);
1968
1969         if ((tframe = talloc_stackframe()) == NULL) {
1970                 PyErr_NoMemory();
1971                 return NULL;
1972         }
1973
1974         status = methods->del_groupmem(methods, tframe, group_rid, member_rid);
1975         if (!NT_STATUS_IS_OK(status)) {
1976                 PyErr_Format(py_pdb_error, "Unable to rename sam account, (%d,%s)",
1977                                 NT_STATUS_V(status),
1978                                 get_friendly_nt_error_msg(status));
1979                 talloc_free(tframe);
1980                 return NULL;
1981         }
1982
1983         talloc_free(tframe);
1984         Py_RETURN_NONE;
1985 }
1986
1987
1988 static PyObject *py_pdb_create_alias(pytalloc_Object *self, PyObject *args)
1989 {
1990         NTSTATUS status;
1991         struct pdb_methods *methods;
1992         TALLOC_CTX *tframe;
1993         const char *alias_name;
1994         uint32_t rid;
1995
1996         if (!PyArg_ParseTuple(args, "s:create_alias", &alias_name)) {
1997                 return NULL;
1998         }
1999
2000         methods = pytalloc_get_ptr(self);
2001
2002         if ((tframe = talloc_stackframe()) == NULL) {
2003                 PyErr_NoMemory();
2004                 return NULL;
2005         }
2006
2007         status = methods->create_alias(methods, alias_name, &rid);
2008         if (!NT_STATUS_IS_OK(status)) {
2009                 PyErr_Format(py_pdb_error, "Unable to create alias (%s), (%d,%s)",
2010                                 alias_name,
2011                                 NT_STATUS_V(status),
2012                                 get_friendly_nt_error_msg(status));
2013                 talloc_free(tframe);
2014                 return NULL;
2015         }
2016
2017         talloc_free(tframe);
2018
2019         return PyInt_FromLong(rid);
2020 }
2021
2022
2023 static PyObject *py_pdb_delete_alias(pytalloc_Object *self, PyObject *args)
2024 {
2025         NTSTATUS status;
2026         struct pdb_methods *methods;
2027         TALLOC_CTX *tframe;
2028         PyObject *py_alias_sid;
2029         struct dom_sid *alias_sid;
2030
2031         if (!PyArg_ParseTuple(args, "O!:delete_alias", dom_sid_Type, &py_alias_sid)) {
2032                 return NULL;
2033         }
2034
2035         methods = pytalloc_get_ptr(self);
2036
2037         if ((tframe = talloc_stackframe()) == NULL) {
2038                 PyErr_NoMemory();
2039                 return NULL;
2040         }
2041
2042         alias_sid = pytalloc_get_ptr(py_alias_sid);
2043
2044         status = methods->delete_alias(methods, alias_sid);
2045         if (!NT_STATUS_IS_OK(status)) {
2046                 PyErr_Format(py_pdb_error, "Unable to delete alias, (%d,%s)",
2047                                 NT_STATUS_V(status),
2048                                 get_friendly_nt_error_msg(status));
2049                 talloc_free(tframe);
2050                 return NULL;
2051         }
2052
2053         talloc_free(tframe);
2054         Py_RETURN_NONE;
2055 }
2056
2057
2058 static PyObject *py_pdb_get_aliasinfo(pytalloc_Object *self, PyObject *args)
2059 {
2060         NTSTATUS status;
2061         struct pdb_methods *methods;
2062         TALLOC_CTX *tframe;
2063         PyObject *py_alias_sid;
2064         struct dom_sid *alias_sid;
2065         struct acct_info alias_info;
2066         PyObject *py_alias_info;
2067
2068         if (!PyArg_ParseTuple(args, "O!:get_aliasinfo", dom_sid_Type, &py_alias_sid)) {
2069                 return NULL;
2070         }
2071
2072         methods = pytalloc_get_ptr(self);
2073
2074         if ((tframe = talloc_stackframe()) == NULL) {
2075                 PyErr_NoMemory();
2076                 return NULL;
2077         }
2078
2079         alias_sid = pytalloc_get_ptr(py_alias_sid);
2080
2081         status = methods->get_aliasinfo(methods, alias_sid, &alias_info);
2082         if (!NT_STATUS_IS_OK(status)) {
2083                 PyErr_Format(py_pdb_error, "Unable to get alias information, (%d,%s)",
2084                                 NT_STATUS_V(status),
2085                                 get_friendly_nt_error_msg(status));
2086                 talloc_free(tframe);
2087                 return NULL;
2088         }
2089
2090         py_alias_info = PyDict_New();
2091         if (py_alias_info == NULL) {
2092                 PyErr_NoMemory();
2093                 talloc_free(tframe);
2094                 return NULL;
2095         }
2096
2097         PyDict_SetItemString(py_alias_info, "acct_name", PyString_FromString(alias_info.acct_name));
2098         PyDict_SetItemString(py_alias_info, "acct_desc", PyString_FromString(alias_info.acct_desc));
2099         PyDict_SetItemString(py_alias_info, "rid", PyInt_FromLong(alias_info.rid));
2100
2101         talloc_free(tframe);
2102
2103         return py_alias_info;
2104 }
2105
2106
2107 static PyObject *py_pdb_set_aliasinfo(pytalloc_Object *self, PyObject *args)
2108 {
2109         NTSTATUS status;
2110         struct pdb_methods *methods;
2111         TALLOC_CTX *tframe;
2112         PyObject *py_alias_sid, *py_alias_info;
2113         struct dom_sid *alias_sid;
2114         struct acct_info alias_info;
2115
2116         if (!PyArg_ParseTuple(args, "O!O:set_alias_info", dom_sid_Type, &py_alias_sid,
2117                                 &py_alias_info)) {
2118                 return NULL;
2119         }
2120
2121         methods = pytalloc_get_ptr(self);
2122
2123         if ((tframe = talloc_stackframe()) == NULL) {
2124                 PyErr_NoMemory();
2125                 return NULL;
2126         }
2127
2128         alias_sid = pytalloc_get_ptr(py_alias_sid);
2129
2130         fstrcpy(alias_info.acct_name, PyString_AsString(PyDict_GetItemString(py_alias_info, "acct_name")));
2131         fstrcpy(alias_info.acct_desc, PyString_AsString(PyDict_GetItemString(py_alias_info, "acct_desc")));
2132
2133         status = methods->set_aliasinfo(methods, alias_sid, &alias_info);
2134         if (!NT_STATUS_IS_OK(status)) {
2135                 PyErr_Format(py_pdb_error, "Unable to set alias information, (%d,%s)",
2136                                 NT_STATUS_V(status),
2137                                 get_friendly_nt_error_msg(status));
2138                 talloc_free(tframe);
2139                 return NULL;
2140         }
2141
2142         talloc_free(tframe);
2143         Py_RETURN_NONE;
2144 }
2145
2146
2147 static PyObject *py_pdb_add_aliasmem(pytalloc_Object *self, PyObject *args)
2148 {
2149         NTSTATUS status;
2150         struct pdb_methods *methods;
2151         TALLOC_CTX *tframe;
2152         PyObject *py_alias_sid, *py_member_sid;
2153         struct dom_sid *alias_sid, *member_sid;
2154
2155         if (!PyArg_ParseTuple(args, "O!O!:add_aliasmem", dom_sid_Type, &py_alias_sid,
2156                                         dom_sid_Type, &py_member_sid)) {
2157                 return NULL;
2158         }
2159
2160         methods = pytalloc_get_ptr(self);
2161
2162         if ((tframe = talloc_stackframe()) == NULL) {
2163                 PyErr_NoMemory();
2164                 return NULL;
2165         }
2166
2167         alias_sid = pytalloc_get_ptr(py_alias_sid);
2168         member_sid = pytalloc_get_ptr(py_member_sid);
2169
2170         status = methods->add_aliasmem(methods, alias_sid, member_sid);
2171         if (!NT_STATUS_IS_OK(status)) {
2172                 PyErr_Format(py_pdb_error, "Unable to add member to alias, (%d,%s)",
2173                                 NT_STATUS_V(status),
2174                                 get_friendly_nt_error_msg(status));
2175                 talloc_free(tframe);
2176                 return NULL;
2177         }
2178
2179         talloc_free(tframe);
2180         Py_RETURN_NONE;
2181 }
2182
2183
2184 static PyObject *py_pdb_del_aliasmem(pytalloc_Object *self, PyObject *args)
2185 {
2186         NTSTATUS status;
2187         struct pdb_methods *methods;
2188         TALLOC_CTX *tframe;
2189         PyObject *py_alias_sid, *py_member_sid;
2190         const struct dom_sid *alias_sid, *member_sid;
2191
2192         if (!PyArg_ParseTuple(args, "O!O!:del_aliasmem", dom_sid_Type, &py_alias_sid,
2193                                         dom_sid_Type, &py_member_sid)) {
2194                 return NULL;
2195         }
2196
2197         methods = pytalloc_get_ptr(self);
2198
2199         if ((tframe = talloc_stackframe()) == NULL) {
2200                 PyErr_NoMemory();
2201                 return NULL;
2202         }
2203
2204         alias_sid = pytalloc_get_ptr(py_alias_sid);
2205         member_sid = pytalloc_get_ptr(py_member_sid);
2206
2207         status = methods->del_aliasmem(methods, alias_sid, member_sid);
2208         if (!NT_STATUS_IS_OK(status)) {
2209                 PyErr_Format(py_pdb_error, "Unable to delete member from alias, (%d,%s)",
2210                                 NT_STATUS_V(status),
2211                                 get_friendly_nt_error_msg(status));
2212                 talloc_free(tframe);
2213                 return NULL;
2214         }
2215
2216         talloc_free(tframe);
2217         Py_RETURN_NONE;
2218 }
2219
2220
2221 static PyObject *py_pdb_enum_aliasmem(pytalloc_Object *self, PyObject *args)
2222 {
2223         NTSTATUS status;
2224         struct pdb_methods *methods;
2225         TALLOC_CTX *tframe;
2226         PyObject *py_alias_sid;
2227         struct dom_sid *alias_sid, *member_sid;
2228         PyObject *py_member_list, *py_member_sid;
2229         size_t num_members;
2230         int i;
2231
2232         if (!PyArg_ParseTuple(args, "O!:enum_aliasmem", dom_sid_Type, &py_alias_sid)) {
2233                 return NULL;
2234         }
2235
2236         methods = pytalloc_get_ptr(self);
2237
2238         if ((tframe = talloc_stackframe()) == NULL) {
2239                 PyErr_NoMemory();
2240                 return NULL;
2241         }
2242
2243         alias_sid = pytalloc_get_ptr(py_alias_sid);
2244
2245         status = methods->enum_aliasmem(methods, alias_sid, tframe, &member_sid, &num_members);
2246         if (!NT_STATUS_IS_OK(status)) {
2247                 PyErr_Format(py_pdb_error, "Unable to enumerate members for alias, (%d,%s)",
2248                                 NT_STATUS_V(status),
2249                                 get_friendly_nt_error_msg(status));
2250                 talloc_free(tframe);
2251                 return NULL;
2252         }
2253
2254         py_member_list = PyList_New(0);
2255         if (py_member_list == NULL) {
2256                 PyErr_NoMemory();
2257                 talloc_free(tframe);
2258                 return NULL;
2259         }
2260
2261         for(i=0; i<num_members; i++) {
2262                 py_member_sid = pytalloc_steal(dom_sid_Type, &member_sid[i]);
2263                 if (py_member_sid) {
2264                         PyList_Append(py_member_list, py_member_sid);
2265                 }
2266         }
2267
2268         talloc_free(tframe);
2269
2270         return py_member_list;
2271 }
2272
2273
2274 static PyObject *py_pdb_get_account_policy(pytalloc_Object *self)
2275 {
2276         NTSTATUS status;
2277         struct pdb_methods *methods;
2278         TALLOC_CTX *tframe;
2279         PyObject *py_acct_policy;
2280         uint32_t value;
2281         const char **names;
2282         int count, i;
2283         enum pdb_policy_type type;
2284
2285         methods = pytalloc_get_ptr(self);
2286
2287         if ((tframe = talloc_stackframe()) == NULL) {
2288                 PyErr_NoMemory();
2289                 return NULL;
2290         }
2291
2292         py_acct_policy = PyDict_New();
2293         if (py_acct_policy == NULL) {
2294                 PyErr_NoMemory();
2295                 return NULL;
2296         }
2297
2298         account_policy_names_list(tframe, &names, &count);
2299         for (i=0; i<count; i++) {
2300                 type = account_policy_name_to_typenum(names[i]);
2301                 status = methods->get_account_policy(methods, type, &value);
2302                 if (NT_STATUS_IS_OK(status)) {
2303                         PyDict_SetItemString(py_acct_policy, names[i], PyInt_FromLong(value));
2304                 }
2305         }
2306
2307         talloc_free(tframe);
2308
2309         return py_acct_policy;
2310 }
2311
2312
2313 static PyObject *py_pdb_set_account_policy(pytalloc_Object *self, PyObject *args)
2314 {
2315         NTSTATUS status;
2316         struct pdb_methods *methods;
2317         TALLOC_CTX *tframe;
2318         PyObject *py_acct_policy, *py_value;
2319         const char **names;
2320         int count, i;
2321         enum pdb_policy_type type;
2322
2323         if (!PyArg_ParseTuple(args, "O!:set_account_policy", PyDict_Type, &py_acct_policy)) {
2324                 return NULL;
2325         }
2326
2327         methods = pytalloc_get_ptr(self);
2328
2329         if ((tframe = talloc_stackframe()) == NULL) {
2330                 PyErr_NoMemory();
2331                 return NULL;
2332         }
2333
2334         account_policy_names_list(tframe, &names, &count);
2335         for (i=0; i<count; i++) {
2336                 if ((py_value = PyDict_GetItemString(py_acct_policy, names[i])) != NULL) {
2337                         type = account_policy_name_to_typenum(names[i]);
2338                         status = methods->set_account_policy(methods, type, PyInt_AsLong(py_value));
2339                         if (!NT_STATUS_IS_OK(status)) {
2340                                 PyErr_Format(py_pdb_error, "Error setting account policy (%s), (%d,%s)",
2341                                                 names[i],
2342                                                 NT_STATUS_V(status),
2343                                                 get_friendly_nt_error_msg(status));
2344                         }
2345                 }
2346         }
2347
2348
2349         talloc_free(tframe);
2350
2351         Py_RETURN_NONE;
2352 }
2353
2354 static PyObject *py_pdb_search_users(pytalloc_Object *self, PyObject *args)
2355 {
2356         NTSTATUS status;
2357         struct pdb_methods *methods;
2358         TALLOC_CTX *tframe;
2359         unsigned int acct_flags;
2360         struct pdb_search *search;
2361         struct samr_displayentry *entry;
2362         PyObject *py_userlist, *py_dict;
2363
2364         if (!PyArg_ParseTuple(args, "I:search_users", &acct_flags)) {
2365                 return NULL;
2366         }
2367
2368         methods = pytalloc_get_ptr(self);
2369
2370         if ((tframe = talloc_stackframe()) == NULL) {
2371                 PyErr_NoMemory();
2372                 return NULL;
2373         }
2374
2375         search = talloc_zero(tframe, struct pdb_search);
2376         if (search == NULL) {
2377                 PyErr_NoMemory();
2378                 talloc_free(tframe);
2379                 return NULL;
2380         }
2381
2382         if (!methods->search_users(methods, search, acct_flags)) {
2383                 PyErr_Format(py_pdb_error, "Unable to search users, (%d,%s)",
2384                                 NT_STATUS_V(status),
2385                                 get_friendly_nt_error_msg(status));
2386                 talloc_free(tframe);
2387                 return NULL;
2388         }
2389
2390         entry = talloc_zero(tframe, struct samr_displayentry);
2391         if (entry == NULL) {
2392                 PyErr_NoMemory();
2393                 talloc_free(tframe);
2394                 return NULL;
2395         }
2396
2397         py_userlist = PyList_New(0);
2398         if (py_userlist == NULL) {
2399                 PyErr_NoMemory();
2400                 talloc_free(tframe);
2401                 return NULL;
2402         }
2403
2404         while (search->next_entry(search, entry)) {
2405                 py_dict = PyDict_New();
2406                 if (py_dict == NULL) {
2407                         PyErr_NoMemory();
2408                 } else {
2409                         PyDict_SetItemString(py_dict, "idx", PyInt_FromLong(entry->idx));
2410                         PyDict_SetItemString(py_dict, "rid", PyInt_FromLong(entry->rid));
2411                         PyDict_SetItemString(py_dict, "acct_flags", PyInt_FromLong(entry->acct_flags));
2412                         PyDict_SetItemString(py_dict, "account_name", PyString_FromString(entry->account_name));
2413                         PyDict_SetItemString(py_dict, "fullname", PyString_FromString(entry->fullname));
2414                         PyDict_SetItemString(py_dict, "description", PyString_FromString(entry->description));
2415                         PyList_Append(py_userlist, py_dict);
2416                 }
2417         }
2418         search->search_end(search);
2419
2420         talloc_free(tframe);
2421
2422         return py_userlist;
2423 }
2424
2425
2426 static PyObject *py_pdb_search_groups(pytalloc_Object *self)
2427 {
2428         NTSTATUS status;
2429         struct pdb_methods *methods;
2430         TALLOC_CTX *tframe;
2431         struct pdb_search *search;
2432         struct samr_displayentry *entry;
2433         PyObject *py_grouplist, *py_dict;
2434
2435         methods = pytalloc_get_ptr(self);
2436
2437         if ((tframe = talloc_stackframe()) == NULL) {
2438                 PyErr_NoMemory();
2439                 return NULL;
2440         }
2441
2442         search = talloc_zero(tframe, struct pdb_search);
2443         if (search == NULL) {
2444                 PyErr_NoMemory();
2445                 talloc_free(tframe);
2446                 return NULL;
2447         }
2448
2449         if (!methods->search_groups(methods, search)) {
2450                 PyErr_Format(py_pdb_error, "Unable to search groups, (%d,%s)",
2451                                 NT_STATUS_V(status),
2452                                 get_friendly_nt_error_msg(status));
2453                 talloc_free(tframe);
2454                 return NULL;
2455         }
2456
2457         entry = talloc_zero(tframe, struct samr_displayentry);
2458         if (entry == NULL) {
2459                 PyErr_NoMemory();
2460                 talloc_free(tframe);
2461                 return NULL;
2462         }
2463
2464         py_grouplist = PyList_New(0);
2465         if (py_grouplist == NULL) {
2466                 PyErr_NoMemory();
2467                 talloc_free(tframe);
2468                 return NULL;
2469         }
2470
2471         while (search->next_entry(search, entry)) {
2472                 py_dict = PyDict_New();
2473                 if (py_dict == NULL) {
2474                         PyErr_NoMemory();
2475                 } else {
2476                         PyDict_SetItemString(py_dict, "idx", PyInt_FromLong(entry->idx));
2477                         PyDict_SetItemString(py_dict, "rid", PyInt_FromLong(entry->rid));
2478                         PyDict_SetItemString(py_dict, "acct_flags", PyInt_FromLong(entry->acct_flags));
2479                         PyDict_SetItemString(py_dict, "account_name", PyString_FromString(entry->account_name));
2480                         PyDict_SetItemString(py_dict, "fullname", PyString_FromString(entry->fullname));
2481                         PyDict_SetItemString(py_dict, "description", PyString_FromString(entry->description));
2482                         PyList_Append(py_grouplist, py_dict);
2483                 }
2484         }
2485         search->search_end(search);
2486
2487         talloc_free(tframe);
2488
2489         return py_grouplist;
2490 }
2491
2492
2493 static PyObject *py_pdb_search_aliases(pytalloc_Object *self, PyObject *args)
2494 {
2495         struct pdb_methods *methods;
2496         TALLOC_CTX *tframe;
2497         struct pdb_search *search;
2498         struct samr_displayentry *entry;
2499         PyObject *py_aliaslist, *py_dict;
2500         PyObject *py_domain_sid;
2501         struct dom_sid *domain_sid = NULL;
2502
2503         py_domain_sid = Py_None;
2504         Py_INCREF(Py_None);
2505
2506         if (!PyArg_ParseTuple(args, "|O!:search_aliases", dom_sid_Type, &py_domain_sid)) {
2507                 return NULL;
2508         }
2509
2510         methods = pytalloc_get_ptr(self);
2511
2512         if ((tframe = talloc_stackframe()) == NULL) {
2513                 PyErr_NoMemory();
2514                 return NULL;
2515         }
2516
2517         if (py_domain_sid != Py_None) {
2518                 domain_sid = pytalloc_get_ptr(py_domain_sid);
2519         }
2520
2521         search = talloc_zero(tframe, struct pdb_search);
2522         if (search == NULL) {
2523                 PyErr_NoMemory();
2524                 talloc_free(tframe);
2525                 return NULL;
2526         }
2527
2528         if (!methods->search_aliases(methods, search, domain_sid)) {
2529                 PyErr_Format(py_pdb_error, "Unable to search aliases");
2530                 talloc_free(tframe);
2531                 return NULL;
2532         }
2533
2534         entry = talloc_zero(tframe, struct samr_displayentry);
2535         if (entry == NULL) {
2536                 PyErr_NoMemory();
2537                 talloc_free(tframe);
2538                 return NULL;
2539         }
2540
2541         py_aliaslist = PyList_New(0);
2542         if (py_aliaslist == NULL) {
2543                 PyErr_NoMemory();
2544                 talloc_free(tframe);
2545                 return NULL;
2546         }
2547
2548         while (search->next_entry(search, entry)) {
2549                 py_dict = PyDict_New();
2550                 if (py_dict == NULL) {
2551                         PyErr_NoMemory();
2552                 } else {
2553                         PyDict_SetItemString(py_dict, "idx", PyInt_FromLong(entry->idx));
2554                         PyDict_SetItemString(py_dict, "rid", PyInt_FromLong(entry->rid));
2555                         PyDict_SetItemString(py_dict, "acct_flags", PyInt_FromLong(entry->acct_flags));
2556                         PyDict_SetItemString(py_dict, "account_name", PyString_FromString(entry->account_name));
2557                         PyDict_SetItemString(py_dict, "fullname", PyString_FromString(entry->fullname));
2558                         PyDict_SetItemString(py_dict, "description", PyString_FromString(entry->description));
2559                         PyList_Append(py_aliaslist, py_dict);
2560                 }
2561         }
2562         search->search_end(search);
2563
2564         talloc_free(tframe);
2565
2566         return py_aliaslist;
2567 }
2568
2569
2570 static PyObject *py_pdb_uid_to_sid(pytalloc_Object *self, PyObject *args)
2571 {
2572         struct pdb_methods *methods;
2573         TALLOC_CTX *tframe;
2574         unsigned int uid;
2575         struct dom_sid user_sid, *copy_user_sid;
2576         PyObject *py_user_sid;
2577
2578         if (!PyArg_ParseTuple(args, "I:uid_to_sid", &uid)) {
2579                 return NULL;
2580         }
2581
2582         methods = pytalloc_get_ptr(self);
2583
2584         if ((tframe = talloc_stackframe()) == NULL) {
2585                 PyErr_NoMemory();
2586                 return NULL;
2587         }
2588
2589         if (!methods->uid_to_sid(methods, uid, &user_sid)) {
2590                 PyErr_Format(py_pdb_error, "Unable to get sid for uid=%d", uid);
2591                 talloc_free(tframe);
2592                 return NULL;
2593         }
2594
2595         copy_user_sid = dom_sid_dup(tframe, &user_sid);
2596         if (copy_user_sid == NULL) {
2597                 PyErr_NoMemory();
2598                 talloc_free(tframe);
2599                 return NULL;
2600         }
2601
2602         py_user_sid = pytalloc_steal(dom_sid_Type, copy_user_sid);
2603
2604         talloc_free(tframe);
2605
2606         return py_user_sid;
2607 }
2608
2609
2610 static PyObject *py_pdb_gid_to_sid(pytalloc_Object *self, PyObject *args)
2611 {
2612         struct pdb_methods *methods;
2613         TALLOC_CTX *tframe;
2614         unsigned int gid;
2615         struct dom_sid group_sid, *copy_group_sid;
2616         PyObject *py_group_sid;
2617
2618         if (!PyArg_ParseTuple(args, "I:gid_to_sid", &gid)) {
2619                 return NULL;
2620         }
2621
2622         methods = pytalloc_get_ptr(self);
2623
2624         if ((tframe = talloc_stackframe()) == NULL) {
2625                 PyErr_NoMemory();
2626                 return NULL;
2627         }
2628
2629         if (!methods->gid_to_sid(methods, gid, &group_sid)) {
2630                 PyErr_Format(py_pdb_error, "Unable to get sid for gid=%d", gid);
2631                 talloc_free(tframe);
2632                 return NULL;
2633         }
2634
2635         copy_group_sid = dom_sid_dup(tframe, &group_sid);
2636         if (copy_group_sid == NULL) {
2637                 PyErr_NoMemory();
2638                 talloc_free(tframe);
2639                 return NULL;
2640         }
2641
2642         py_group_sid = pytalloc_steal(dom_sid_Type, copy_group_sid);
2643
2644         talloc_free(tframe);
2645
2646         return py_group_sid;
2647 }
2648
2649
2650 static PyObject *py_pdb_sid_to_id(pytalloc_Object *self, PyObject *args)
2651 {
2652         struct pdb_methods *methods;
2653         TALLOC_CTX *tframe;
2654         PyObject *py_sid;
2655         struct dom_sid *sid;
2656         union unid_t id;
2657         enum lsa_SidType type;
2658
2659         if (!PyArg_ParseTuple(args, "O!:sid_to_id", dom_sid_Type, &py_sid)) {
2660                 return NULL;
2661         }
2662
2663         methods = pytalloc_get_ptr(self);
2664
2665         if ((tframe = talloc_stackframe()) == NULL) {
2666                 PyErr_NoMemory();
2667                 return NULL;
2668         }
2669
2670         sid = pytalloc_get_ptr(py_sid);
2671
2672         if (!methods->sid_to_id(methods, sid, &id, &type)) {
2673                 PyErr_Format(py_pdb_error, "Unable to get id for sid");
2674                 talloc_free(tframe);
2675                 return NULL;
2676         }
2677
2678         talloc_free(tframe);
2679
2680         return Py_BuildValue("(II)", id.uid, type);
2681 }
2682
2683
2684 static PyObject *py_pdb_new_rid(pytalloc_Object *self)
2685 {
2686         struct pdb_methods *methods;
2687         TALLOC_CTX *tframe;
2688         uint32_t rid;
2689
2690         methods = pytalloc_get_ptr(self);
2691
2692         if ((tframe = talloc_stackframe()) == NULL) {
2693                 PyErr_NoMemory();
2694                 return NULL;
2695         }
2696
2697         if (!methods->new_rid(methods, &rid)) {
2698                 PyErr_Format(py_pdb_error, "Unable to get new rid");
2699                 talloc_free(tframe);
2700                 return NULL;
2701         }
2702
2703         talloc_free(tframe);
2704
2705         return PyInt_FromLong(rid);
2706 }
2707
2708
2709 static PyObject *py_pdb_get_trusteddom_pw(pytalloc_Object *self, PyObject *args)
2710 {
2711         struct pdb_methods *methods;
2712         TALLOC_CTX *tframe;
2713         const char *domain;
2714         char *pwd;
2715         struct dom_sid sid, *copy_sid;
2716         PyObject *py_sid;
2717         time_t last_set_time;
2718         PyObject *py_value;
2719
2720         if (!PyArg_ParseTuple(args, "s:get_trusteddom_pw", &domain)) {
2721                 return NULL;
2722         }
2723
2724         methods = pytalloc_get_ptr(self);
2725
2726         if ((tframe = talloc_stackframe()) == NULL) {
2727                 PyErr_NoMemory();
2728                 return NULL;
2729         }
2730
2731         if (!methods->get_trusteddom_pw(methods, domain, &pwd, &sid, &last_set_time)) {
2732                 PyErr_Format(py_pdb_error, "Unable to get trusted domain password");
2733                 talloc_free(tframe);
2734                 return NULL;
2735         }
2736
2737         copy_sid = dom_sid_dup(tframe, &sid);
2738         if (copy_sid == NULL) {
2739                 PyErr_NoMemory();
2740                 talloc_free(tframe);
2741                 return NULL;
2742         }
2743
2744         py_sid = pytalloc_steal(dom_sid_Type, copy_sid);
2745         if (py_sid == NULL) {
2746                 PyErr_NoMemory();
2747                 talloc_free(tframe);
2748                 return NULL;
2749         }
2750
2751         talloc_free(tframe);
2752
2753         py_value = PyDict_New();
2754         if (py_value == NULL) {
2755                 PyErr_NoMemory();
2756                 return NULL;
2757         }
2758
2759         PyDict_SetItemString(py_value, "pwd", PyString_FromString(pwd));
2760         PyDict_SetItemString(py_value, "sid", py_sid);
2761         PyDict_SetItemString(py_value, "last_set_tim", PyInt_FromLong(last_set_time));
2762
2763         return py_value;
2764 }
2765
2766
2767 static PyObject *py_pdb_set_trusteddom_pw(pytalloc_Object *self, PyObject *args)
2768 {
2769         struct pdb_methods *methods;
2770         TALLOC_CTX *tframe;
2771         const char *domain;
2772         const char *pwd;
2773         const struct dom_sid *domain_sid;
2774         PyObject *py_domain_sid;
2775
2776         if (!PyArg_ParseTuple(args, "ssO!:set_trusteddom_pw", &domain, &pwd,
2777                                         dom_sid_Type, &py_domain_sid)) {
2778                 return NULL;
2779         }
2780
2781         methods = pytalloc_get_ptr(self);
2782
2783         if ((tframe = talloc_stackframe()) == NULL) {
2784                 PyErr_NoMemory();
2785                 return NULL;
2786         }
2787
2788         domain_sid = pytalloc_get_ptr(py_domain_sid);
2789
2790         if (!methods->set_trusteddom_pw(methods, domain, pwd, domain_sid)) {
2791                 PyErr_Format(py_pdb_error, "Unable to set trusted domain password");
2792                 talloc_free(tframe);
2793                 return NULL;
2794         }
2795
2796         Py_RETURN_NONE;
2797 }
2798
2799
2800 static PyObject *py_pdb_del_trusteddom_pw(pytalloc_Object *self, PyObject *args)
2801 {
2802         struct pdb_methods *methods;
2803         TALLOC_CTX *tframe;
2804         const char *domain;
2805
2806         if (!PyArg_ParseTuple(args, "s:del_trusteddom_pw", &domain)) {
2807                 return NULL;
2808         }
2809
2810         methods = pytalloc_get_ptr(self);
2811
2812         if ((tframe = talloc_stackframe()) == NULL) {
2813                 PyErr_NoMemory();
2814                 return NULL;
2815         }
2816
2817         if (!methods->del_trusteddom_pw(methods, domain)) {
2818                 PyErr_Format(py_pdb_error, "Unable to delete trusted domain password");
2819                 talloc_free(tframe);
2820                 return NULL;
2821         }
2822
2823         Py_RETURN_NONE;
2824 }
2825
2826
2827 static PyObject *py_pdb_enum_trusteddoms(pytalloc_Object *self)
2828 {
2829         NTSTATUS status;
2830         struct pdb_methods *methods;
2831         TALLOC_CTX *tframe;
2832         uint32_t num_domains;
2833         struct trustdom_info **domains;
2834         PyObject *py_domain_list, *py_dict;
2835         int i;
2836
2837         methods = pytalloc_get_ptr(self);
2838
2839         if ((tframe = talloc_stackframe()) == NULL) {
2840                 PyErr_NoMemory();
2841                 return NULL;
2842         }
2843
2844         status = methods->enum_trusteddoms(methods, tframe, &num_domains, &domains);
2845         if (!NT_STATUS_IS_OK(status)) {
2846                 PyErr_Format(py_pdb_error, "Unable to enumerate trusted domains, (%d,%s)",
2847                                 NT_STATUS_V(status),
2848                                 get_friendly_nt_error_msg(status));
2849                 talloc_free(tframe);
2850                 return NULL;
2851         }
2852
2853         py_domain_list = PyList_New(0);
2854         if (py_domain_list == NULL) {
2855                 PyErr_NoMemory();
2856                 talloc_free(tframe);
2857                 return NULL;
2858         }
2859
2860         for(i=0; i<num_domains; i++) {
2861                 py_dict = PyDict_New();
2862                 if (py_dict) {
2863                         PyDict_SetItemString(py_dict, "name",
2864                                         PyString_FromString(domains[i]->name));
2865                         PyDict_SetItemString(py_dict, "sid",
2866                                         pytalloc_steal(dom_sid_Type, &domains[i]->sid));
2867                 }
2868
2869                 PyList_Append(py_domain_list, py_dict);
2870         }
2871
2872         talloc_free(tframe);
2873
2874         return py_domain_list;
2875 }
2876
2877
2878 static PyObject *py_pdb_get_trusted_domain(pytalloc_Object *self, PyObject *args)
2879 {
2880         NTSTATUS status;
2881         struct pdb_methods *methods;
2882         TALLOC_CTX *tframe;
2883         const char *domain;
2884         struct pdb_trusted_domain *td;
2885         PyObject *py_domain_info;
2886
2887         if (!PyArg_ParseTuple(args, "s:get_trusted_domain", &domain)) {
2888                 return NULL;
2889         }
2890
2891         methods = pytalloc_get_ptr(self);
2892
2893         if ((tframe = talloc_stackframe()) == NULL) {
2894                 PyErr_NoMemory();
2895                 return NULL;
2896         }
2897
2898         status = methods->get_trusted_domain(methods, tframe, domain, &td);
2899         if (!NT_STATUS_IS_OK(status)) {
2900                 PyErr_Format(py_pdb_error, "Unable to get trusted domain information, (%d,%s)",
2901                                 NT_STATUS_V(status),
2902                                 get_friendly_nt_error_msg(status));
2903                 talloc_free(tframe);
2904                 return NULL;
2905         }
2906
2907         py_domain_info = PyDict_New();
2908         if (py_domain_info == NULL) {
2909                 PyErr_NoMemory();
2910                 talloc_free(tframe);
2911                 return NULL;
2912         }
2913
2914         PyDict_SetItemString(py_domain_info, "domain_name",
2915                         PyString_FromString(td->domain_name));
2916         PyDict_SetItemString(py_domain_info, "netbios_name",
2917                         PyString_FromString(td->netbios_name));
2918         PyDict_SetItemString(py_domain_info, "security_identifier",
2919                         pytalloc_steal(dom_sid_Type, &td->security_identifier));
2920         PyDict_SetItemString(py_domain_info, "trust_auth_incoming",
2921                         PyString_FromStringAndSize((char *)td->trust_auth_incoming.data,
2922                                                 td->trust_auth_incoming.length));
2923         PyDict_SetItemString(py_domain_info, "trust_auth_outgoing",
2924                         PyString_FromStringAndSize((char *)td->trust_auth_outgoing.data,
2925                                                 td->trust_auth_outgoing.length));
2926         PyDict_SetItemString(py_domain_info, "trust_direction",
2927                         PyInt_FromLong(td->trust_direction));
2928         PyDict_SetItemString(py_domain_info, "trust_type",
2929                         PyInt_FromLong(td->trust_type));
2930         PyDict_SetItemString(py_domain_info, "trust_attributes",
2931                         PyInt_FromLong(td->trust_attributes));
2932         PyDict_SetItemString(py_domain_info, "trust_forest_trust_info",
2933                         PyString_FromStringAndSize((char *)td->trust_forest_trust_info.data,
2934                                                 td->trust_forest_trust_info.length));
2935
2936         talloc_free(tframe);
2937
2938         return py_domain_info;
2939 }
2940
2941
2942 static PyObject *py_pdb_get_trusted_domain_by_sid(pytalloc_Object *self, PyObject *args)
2943 {
2944         NTSTATUS status;
2945         struct pdb_methods *methods;
2946         TALLOC_CTX *tframe;
2947         PyObject *py_domain_sid;
2948         struct dom_sid *domain_sid;
2949         struct pdb_trusted_domain *td;
2950         PyObject *py_domain_info;
2951
2952         if (!PyArg_ParseTuple(args, "O!:get_trusted_domain_by_sid", dom_sid_Type, &py_domain_sid)) {
2953                 return NULL;
2954         }
2955
2956         methods = pytalloc_get_ptr(self);
2957
2958         if ((tframe = talloc_stackframe()) == NULL) {
2959                 PyErr_NoMemory();
2960                 return NULL;
2961         }
2962
2963         domain_sid = pytalloc_get_ptr(py_domain_sid);
2964
2965         status = methods->get_trusted_domain_by_sid(methods, tframe, domain_sid, &td);
2966         if (!NT_STATUS_IS_OK(status)) {
2967                 PyErr_Format(py_pdb_error, "Unable to get trusted domain information, (%d,%s)",
2968                                 NT_STATUS_V(status),
2969                                 get_friendly_nt_error_msg(status));
2970                 talloc_free(tframe);
2971                 return NULL;
2972         }
2973
2974         py_domain_info = PyDict_New();
2975         if (py_domain_info == NULL) {
2976                 PyErr_NoMemory();
2977                 talloc_free(tframe);
2978                 return NULL;
2979         }
2980
2981         PyDict_SetItemString(py_domain_info, "domain_name",
2982                         PyString_FromString(td->domain_name));
2983         PyDict_SetItemString(py_domain_info, "netbios_name",
2984                         PyString_FromString(td->netbios_name));
2985         PyDict_SetItemString(py_domain_info, "security_identifier",
2986                         pytalloc_steal(dom_sid_Type, &td->security_identifier));
2987         PyDict_SetItemString(py_domain_info, "trust_auth_incoming",
2988                         PyString_FromStringAndSize((char *)td->trust_auth_incoming.data,
2989                                                 td->trust_auth_incoming.length));
2990         PyDict_SetItemString(py_domain_info, "trust_auth_outgoing",
2991                         PyString_FromStringAndSize((char *)td->trust_auth_outgoing.data,
2992                                                 td->trust_auth_outgoing.length));
2993         PyDict_SetItemString(py_domain_info, "trust_direction",
2994                         PyInt_FromLong(td->trust_direction));
2995         PyDict_SetItemString(py_domain_info, "trust_type",
2996                         PyInt_FromLong(td->trust_type));
2997         PyDict_SetItemString(py_domain_info, "trust_attributes",
2998                         PyInt_FromLong(td->trust_attributes));
2999         PyDict_SetItemString(py_domain_info, "trust_forest_trust_info",
3000                         PyString_FromStringAndSize((char *)td->trust_forest_trust_info.data,
3001                                                 td->trust_forest_trust_info.length));
3002
3003         talloc_free(tframe);
3004
3005         return py_domain_info;
3006 }
3007
3008
3009 static PyObject *py_pdb_set_trusted_domain(pytalloc_Object *self, PyObject *args)
3010 {
3011         NTSTATUS status;
3012         struct pdb_methods *methods;
3013         TALLOC_CTX *tframe;
3014         const char *domain;
3015         PyObject *py_td_info;
3016         struct pdb_trusted_domain td_info;
3017         PyObject *py_tmp;
3018         Py_ssize_t len;
3019
3020         if (!PyArg_ParseTuple(args, "sO!:set_trusted_domain", &domain, &PyDict_Type, &py_td_info)) {
3021                 return NULL;
3022         }
3023
3024         py_tmp = PyDict_GetItemString(py_td_info, "domain_name");
3025         td_info.domain_name = PyString_AsString(py_tmp);
3026
3027         py_tmp = PyDict_GetItemString(py_td_info, "netbios_name");
3028         td_info.netbios_name = PyString_AsString(py_tmp);
3029
3030         py_tmp = PyDict_GetItemString(py_td_info, "security_identifier");
3031         td_info.security_identifier = *pytalloc_get_type(py_tmp, struct dom_sid);
3032
3033         py_tmp = PyDict_GetItemString(py_td_info, "trust_auth_incoming");
3034         PyString_AsStringAndSize(py_tmp, (char **)&td_info.trust_auth_incoming.data, &len);
3035         td_info.trust_auth_incoming.length = len;
3036
3037         py_tmp = PyDict_GetItemString(py_td_info, "trust_auth_outgoing");
3038         PyString_AsStringAndSize(py_tmp, (char **)&td_info.trust_auth_outgoing.data, &len);
3039         td_info.trust_auth_outgoing.length = len;
3040
3041         py_tmp = PyDict_GetItemString(py_td_info, "trust_direction");
3042         td_info.trust_direction = PyInt_AsLong(py_tmp);
3043
3044         py_tmp = PyDict_GetItemString(py_td_info, "trust_type");
3045         td_info.trust_type = PyInt_AsLong(py_tmp);
3046
3047         py_tmp = PyDict_GetItemString(py_td_info, "trust_attributes");
3048         td_info.trust_attributes = PyInt_AsLong(py_tmp);
3049
3050         py_tmp = PyDict_GetItemString(py_td_info, "trust_forest_trust_info");
3051         PyString_AsStringAndSize(py_tmp, (char **)&td_info.trust_forest_trust_info.data, &len);
3052         td_info.trust_forest_trust_info.length = len;
3053
3054         methods = pytalloc_get_ptr(self);
3055
3056         if ((tframe = talloc_stackframe()) == NULL) {
3057                 PyErr_NoMemory();
3058                 return NULL;
3059         }
3060
3061         status = methods->set_trusted_domain(methods, domain, &td_info);
3062         if (!NT_STATUS_IS_OK(status)) {
3063                 PyErr_Format(py_pdb_error, "Unable to set trusted domain information, (%d,%s)",
3064                                 NT_STATUS_V(status),
3065                                 get_friendly_nt_error_msg(status));
3066                 talloc_free(tframe);
3067                 return NULL;
3068         }
3069
3070         talloc_free(tframe);
3071
3072         Py_RETURN_NONE;
3073 }
3074
3075
3076 static PyObject *py_pdb_del_trusted_domain(pytalloc_Object *self, PyObject *args)
3077 {
3078         NTSTATUS status;
3079         struct pdb_methods *methods;
3080         TALLOC_CTX *tframe;
3081         const char *domain;
3082
3083         if (!PyArg_ParseTuple(args, "s:del_trusted_domain", &domain)) {
3084                 return NULL;
3085         }
3086
3087         methods = pytalloc_get_ptr(self);
3088
3089         if ((tframe = talloc_stackframe()) == NULL) {
3090                 PyErr_NoMemory();
3091                 return NULL;
3092         }
3093
3094         status = methods->del_trusted_domain(methods, domain);
3095         if (!NT_STATUS_IS_OK(status)) {
3096                 PyErr_Format(py_pdb_error, "Unable to delete trusted domain, (%d,%s)",
3097                                 NT_STATUS_V(status),
3098                                 get_friendly_nt_error_msg(status));
3099                 talloc_free(tframe);
3100                 return NULL;
3101         }
3102
3103         talloc_free(tframe);
3104
3105         Py_RETURN_NONE;
3106 }
3107
3108
3109 static PyObject *py_pdb_enum_trusted_domains(pytalloc_Object *self)
3110 {
3111         NTSTATUS status;
3112         struct pdb_methods *methods;
3113         TALLOC_CTX *tframe;
3114         uint32_t num_domains;
3115         struct pdb_trusted_domain **td_info, *td;
3116         PyObject *py_td_info, *py_domain_info;
3117         int i;
3118
3119         methods = pytalloc_get_ptr(self);
3120
3121         if ((tframe = talloc_stackframe()) == NULL) {
3122                 PyErr_NoMemory();
3123                 return NULL;
3124         }
3125
3126         status = methods->enum_trusted_domains(methods, tframe, &num_domains, &td_info);
3127         if (!NT_STATUS_IS_OK(status)) {
3128                 PyErr_Format(py_pdb_error, "Unable to delete trusted domain, (%d,%s)",
3129                                 NT_STATUS_V(status),
3130                                 get_friendly_nt_error_msg(status));
3131                 talloc_free(tframe);
3132                 return NULL;
3133         }
3134
3135         py_td_info = PyList_New(0);
3136         if (py_td_info == NULL) {
3137                 PyErr_NoMemory();
3138                 talloc_free(tframe);
3139                 return NULL;
3140         }
3141
3142         for (i=0; i<num_domains; i++) {
3143
3144                 py_domain_info = PyDict_New();
3145                 if (py_domain_info == NULL) {
3146                         PyErr_NoMemory();
3147                         Py_DECREF(py_td_info);
3148                         talloc_free(tframe);
3149                         return NULL;
3150                 }
3151
3152                 td = td_info[i];
3153
3154                 PyDict_SetItemString(py_domain_info, "domain_name",
3155                                 PyString_FromString(td->domain_name));
3156                 PyDict_SetItemString(py_domain_info, "netbios_name",
3157                                 PyString_FromString(td->netbios_name));
3158                 PyDict_SetItemString(py_domain_info, "security_identifier",
3159                                 pytalloc_steal(dom_sid_Type, &td->security_identifier));
3160                 PyDict_SetItemString(py_domain_info, "trust_auth_incoming",
3161                                 PyString_FromStringAndSize((char *)td->trust_auth_incoming.data,
3162                                                         td->trust_auth_incoming.length));
3163                 PyDict_SetItemString(py_domain_info, "trust_auth_outgoing",
3164                                 PyString_FromStringAndSize((char *)td->trust_auth_outgoing.data,
3165                                                         td->trust_auth_outgoing.length));
3166                 PyDict_SetItemString(py_domain_info, "trust_direction",
3167                                 PyInt_FromLong(td->trust_direction));
3168                 PyDict_SetItemString(py_domain_info, "trust_type",
3169                                 PyInt_FromLong(td->trust_type));
3170                 PyDict_SetItemString(py_domain_info, "trust_attributes",
3171                                 PyInt_FromLong(td->trust_attributes));
3172                 PyDict_SetItemString(py_domain_info, "trust_forest_trust_info",
3173                                 PyString_FromStringAndSize((char *)td->trust_forest_trust_info.data,
3174                                                         td->trust_forest_trust_info.length));
3175                 PyList_Append(py_td_info, py_domain_info);
3176         }
3177
3178         talloc_free(tframe);
3179
3180         return py_td_info;
3181 }
3182
3183
3184 static PyObject *py_pdb_get_secret(pytalloc_Object *self, PyObject *args)
3185 {
3186         NTSTATUS status;
3187         struct pdb_methods *methods;
3188         TALLOC_CTX *tframe;
3189         const char *secret_name;
3190         DATA_BLOB secret_current, secret_old;
3191         NTTIME secret_current_lastchange, secret_old_lastchange;
3192         PyObject *py_sd;
3193         struct security_descriptor *sd;
3194         PyObject *py_secret;
3195
3196         if (!PyArg_ParseTuple(args, "s:get_secret_name", &secret_name)) {
3197                 return NULL;
3198         }
3199
3200         methods = pytalloc_get_ptr(self);
3201
3202         if ((tframe = talloc_stackframe()) == NULL) {
3203                 PyErr_NoMemory();
3204                 return NULL;
3205         }
3206
3207         py_sd = pytalloc_new(struct security_descriptor, security_Type);
3208         if (py_sd == NULL) {
3209                 PyErr_NoMemory();
3210                 talloc_free(tframe);
3211                 return NULL;
3212         }
3213         sd = pytalloc_get_ptr(py_sd);
3214
3215         status = methods->get_secret(methods, tframe, secret_name,
3216                                         &secret_current,
3217                                         &secret_current_lastchange,
3218                                         &secret_old,
3219                                         &secret_old_lastchange,
3220                                         &sd);
3221         if (!NT_STATUS_IS_OK(status)) {
3222                 PyErr_Format(py_pdb_error, "Unable to get information for secret (%s), (%d,%s)",
3223                                 secret_name,
3224                                 NT_STATUS_V(status),
3225                                 get_friendly_nt_error_msg(status));
3226                 talloc_free(tframe);
3227                 return NULL;
3228         }
3229
3230         py_secret = PyDict_New();
3231         if (py_secret == NULL) {
3232                 PyErr_NoMemory();
3233                 Py_DECREF(py_sd);
3234                 talloc_free(tframe);
3235                 return NULL;
3236         }
3237
3238         PyDict_SetItemString(py_secret, "secret_current",
3239                         PyString_FromStringAndSize((char *)secret_current.data, secret_current.length));
3240         PyDict_SetItemString(py_secret, "secret_current_lastchange",
3241                         PyLong_FromUnsignedLongLong(secret_current_lastchange));
3242         PyDict_SetItemString(py_secret, "secret_old",
3243                         PyString_FromStringAndSize((char *)secret_old.data, secret_old.length));
3244         PyDict_SetItemString(py_secret, "secret_old_lastchange",
3245                         PyLong_FromUnsignedLongLong(secret_old_lastchange));
3246         PyDict_SetItemString(py_secret, "sd", py_sd);
3247
3248         talloc_free(tframe);
3249
3250         return py_secret;
3251 }
3252
3253
3254 static PyObject *py_pdb_set_secret(pytalloc_Object *self, PyObject *args)
3255 {
3256         NTSTATUS status;
3257         struct pdb_methods *methods;
3258         TALLOC_CTX *tframe;
3259         const char *secret_name;
3260         PyObject *py_secret;
3261         PyObject *py_secret_cur, *py_secret_old, *py_sd;
3262         DATA_BLOB secret_current, secret_old;
3263         struct security_descriptor *sd;
3264         Py_ssize_t len;
3265
3266         if (!PyArg_ParseTuple(args, "sO!:set_secret_name", &secret_name, PyDict_Type, &py_secret)) {
3267                 return NULL;
3268         }
3269
3270         py_secret_cur = PyDict_GetItemString(py_secret, "secret_current");
3271         py_secret_old = PyDict_GetItemString(py_secret, "secret_old");
3272         py_sd = PyDict_GetItemString(py_secret, "sd");
3273
3274         PY_CHECK_TYPE(&PyString_Type, py_secret_cur, return NULL;);
3275         PY_CHECK_TYPE(&PyString_Type, py_secret_old, return NULL;);
3276         PY_CHECK_TYPE(security_Type, py_sd, return NULL;);
3277
3278         methods = pytalloc_get_ptr(self);
3279
3280         if ((tframe = talloc_stackframe()) == NULL) {
3281                 PyErr_NoMemory();
3282                 return NULL;
3283         }
3284
3285         PyString_AsStringAndSize(py_secret_cur, (char **)&secret_current.data, &len);
3286         secret_current.length = len;
3287         PyString_AsStringAndSize(py_secret_old, (char **)&secret_old.data, &len);
3288         secret_current.length = len;
3289         sd = pytalloc_get_ptr(py_sd);
3290
3291         status = methods->set_secret(methods, secret_name, &secret_current, &secret_old, sd);
3292         if (!NT_STATUS_IS_OK(status)) {
3293                 PyErr_Format(py_pdb_error, "Unable to set information for secret (%s), (%d,%s)",
3294                                 secret_name,
3295                                 NT_STATUS_V(status),
3296                                 get_friendly_nt_error_msg(status));
3297                 talloc_free(tframe);
3298                 return NULL;
3299         }
3300
3301         talloc_free(tframe);
3302
3303         Py_RETURN_NONE;
3304 }
3305
3306
3307 static PyObject *py_pdb_delete_secret(pytalloc_Object *self, PyObject *args)
3308 {
3309         NTSTATUS status;
3310         struct pdb_methods *methods;
3311         TALLOC_CTX *tframe;
3312         const char *secret_name;
3313
3314         if (!PyArg_ParseTuple(args, "s:delete_secret", &secret_name)) {
3315                 return NULL;
3316         }
3317
3318         methods = pytalloc_get_ptr(self);
3319
3320         if ((tframe = talloc_stackframe()) == NULL) {
3321                 PyErr_NoMemory();
3322                 return NULL;
3323         }
3324
3325         status = methods->delete_secret(methods, secret_name);
3326         if (!NT_STATUS_IS_OK(status)) {
3327                 PyErr_Format(py_pdb_error, "Unable to delete secret (%s), (%d,%s)",
3328                                 secret_name,
3329                                 NT_STATUS_V(status),
3330                                 get_friendly_nt_error_msg(status));
3331                 talloc_free(tframe);
3332                 return NULL;
3333         }
3334
3335         talloc_free(tframe);
3336
3337         Py_RETURN_NONE;
3338 }
3339
3340 static PyMethodDef py_pdb_methods[] = {
3341         { "domain_info", (PyCFunction)py_pdb_domain_info, METH_NOARGS,
3342                 "domain_info() -> str\n\n \
3343                 Get domain information for the database." },
3344         { "getsampwnam", (PyCFunction)py_pdb_getsampwnam, METH_VARARGS,
3345                 "getsampwnam(username) -> samu object\n\n \
3346                 Get user information by name." },
3347         { "getsampwsid", (PyCFunction)py_pdb_getsampwsid, METH_VARARGS,
3348                 "getsampwsid(user_sid) -> samu object\n\n \
3349                 Get user information by sid (dcerpc.security.dom_sid object)." },
3350         { "create_user", (PyCFunction)py_pdb_create_user, METH_VARARGS,
3351                 "create_user(username, acct_flags) -> rid\n\n \
3352                 Create user. acct_flags are samr account control flags." },
3353         { "delete_user", (PyCFunction)py_pdb_delete_user, METH_VARARGS,
3354                 "delete_user(samu object) -> None\n\n \
3355                 Delete user." },
3356         { "add_sam_account", (PyCFunction)py_pdb_add_sam_account, METH_VARARGS,
3357                 "add_sam_account(samu object) -> None\n\n \
3358                 Add SAM account." },
3359         { "update_sam_account", (PyCFunction)py_pdb_update_sam_account, METH_VARARGS,
3360                 "update_sam_account(samu object) -> None\n\n \
3361                 Update SAM account." },
3362         { "delete_sam_account", (PyCFunction)py_pdb_delete_sam_account, METH_VARARGS,
3363                 "delete_sam_account(samu object) -> None\n\n \
3364                 Delete SAM account." },
3365         { "rename_sam_account", (PyCFunction)py_pdb_rename_sam_account, METH_VARARGS,
3366                 "rename_sam_account(samu object1, new_username) -> None\n\n \
3367                 Rename SAM account." },
3368         /* update_login_attempts */
3369         { "getgrsid", (PyCFunction)py_pdb_getgrsid, METH_VARARGS,
3370                 "getgrsid(group_sid) -> groupmap object\n\n \
3371                 Get group information by sid (dcerpc.security.dom_sid object)." },
3372         { "getgrgid", (PyCFunction)py_pdb_getgrgid, METH_VARARGS,
3373                 "getgrsid(gid) -> groupmap object\n\n \
3374                 Get group information by gid." },
3375         { "getgrnam", (PyCFunction)py_pdb_getgrnam, METH_VARARGS,
3376                 "getgrsid(groupname) -> groupmap object\n\n \
3377                 Get group information by name." },
3378         { "create_dom_group", (PyCFunction)py_pdb_create_dom_group, METH_VARARGS,
3379                 "create_dom_group(groupname) -> group_rid\n\n \
3380                 Create new domain group by name." },
3381         { "delete_dom_group", (PyCFunction)py_pdb_delete_dom_group, METH_VARARGS,
3382                 "delete_dom_group(group_rid) -> None\n\n \
3383                 Delete domain group identified by rid" },
3384         { "add_group_mapping_entry", (PyCFunction)py_pdb_add_group_mapping_entry, METH_VARARGS,
3385                 "add_group_mapping_entry(groupmap) -> None\n \
3386                 Add group mapping entry for groupmap object." },
3387         { "update_group_mapping_entry", (PyCFunction)py_pdb_update_group_mapping_entry, METH_VARARGS,
3388                 "update_group_mapping_entry(groupmap) -> None\n\n \
3389                 Update group mapping entry for groupmap object." },
3390         { "delete_group_mapping_entry", (PyCFunction)py_pdb_delete_group_mapping_entry, METH_VARARGS,
3391                 "delete_group_mapping_entry(groupmap) -> None\n\n \
3392                 Delete group mapping entry for groupmap object." },
3393         { "enum_group_mapping", (PyCFunction)py_pdb_enum_group_mapping, METH_VARARGS,
3394                 "enum_group_mapping([domain_sid, [type, [unix_only]]]) -> List\n\n \
3395                 Return list of group mappings as groupmap objects. Optional arguments are domain_sid object, type of group, unix only flag." },
3396         { "enum_group_members", (PyCFunction)py_pdb_enum_group_members, METH_VARARGS,
3397                 "enum_group_members(group_sid) -> List\n\n \
3398                 Return list of users (dom_sid object) in group." },
3399         /* enum_group_memberships */
3400         /* set_unix_primary_group */
3401         { "add_groupmem", (PyCFunction)py_pdb_add_groupmem, METH_VARARGS,
3402                 "add_groupmem(group_rid, member_rid) -> None\n\n \
3403                 Add user to group." },
3404         { "del_groupmem", (PyCFunction)py_pdb_del_groupmem, METH_VARARGS,
3405                 "del_groupmem(group_rid, member_rid) -> None\n\n \
3406                 Remove user from from group." },
3407         { "create_alias", (PyCFunction)py_pdb_create_alias, METH_VARARGS,
3408                 "create_alias(alias_name) -> alias_rid\n\n \
3409                 Create alias entry." },
3410         { "delete_alias", (PyCFunction)py_pdb_delete_alias, METH_VARARGS,
3411                 "delete_alias(alias_sid) -> None\n\n \
3412                 Delete alias entry." },
3413         { "get_aliasinfo", (PyCFunction)py_pdb_get_aliasinfo, METH_VARARGS,
3414                 "get_aliasinfo(alias_sid) -> Mapping\n\n \
3415                 Get alias information as a dictionary with keys - acct_name, acct_desc, rid." },
3416         { "set_aliasinfo", (PyCFunction)py_pdb_set_aliasinfo, METH_VARARGS,
3417                 "set_alias_info(alias_sid, Mapping) -> None\n\n \
3418                 Set alias information from a dictionary with keys - acct_name, acct_desc." },
3419         { "add_aliasmem", (PyCFunction)py_pdb_add_aliasmem, METH_VARARGS,
3420                 "add_aliasmem(alias_sid, member_sid) -> None\n\n \
3421                 Add user to alias entry." },
3422         { "del_aliasmem", (PyCFunction)py_pdb_del_aliasmem, METH_VARARGS,
3423                 "del_aliasmem(alias_sid, member_sid) -> None\n\n \
3424                 Remove a user from alias entry." },
3425         { "enum_aliasmem", (PyCFunction)py_pdb_enum_aliasmem, METH_VARARGS,
3426                 "enum_aliasmem(alias_sid) -> List\n\n \
3427                 Return a list of members (dom_sid object) for alias entry." },
3428         /* enum_alias_memberships */
3429         /* lookup_rids */
3430         /* lookup_names */
3431         { "get_account_policy", (PyCFunction)py_pdb_get_account_policy, METH_NOARGS,
3432                 "get_account_policy() -> Mapping\n\n \
3433                 Get account policy information as a dictionary." },
3434         { "set_account_policy", (PyCFunction)py_pdb_set_account_policy, METH_VARARGS,
3435                 "get_account_policy(Mapping) -> None\n\n \
3436                 Set account policy settings from a dicionary." },
3437         /* get_seq_num */
3438         { "search_users", (PyCFunction)py_pdb_search_users, METH_VARARGS,
3439                 "search_users(acct_flags) -> List\n\n \
3440                 Search users. acct_flags are samr account control flags.\n \
3441                 Each list entry is dictionary with keys - idx, rid, acct_flags, account_name, fullname, description." },
3442         { "search_groups", (PyCFunction)py_pdb_search_groups, METH_NOARGS,
3443                 "search_groups() -> List\n\n \
3444                 Search unix only groups. \n \
3445                 Each list entry is dictionary with keys - idx, rid, acct_flags, account_name, fullname, description." },
3446         { "search_aliases", (PyCFunction)py_pdb_search_aliases, METH_VARARGS,
3447                 "search_aliases([domain_sid]) -> List\n\n \
3448                 Search aliases. domain_sid is dcerpc.security.dom_sid object.\n \
3449                 Each list entry is dictionary with keys - idx, rid, acct_flags, account_name, fullname, description." },
3450         { "uid_to_sid", (PyCFunction)py_pdb_uid_to_sid, METH_VARARGS,
3451                 "uid_to_sid(uid) -> sid\n\n \
3452                 Return sid for given user id." },
3453         { "gid_to_sid", (PyCFunction)py_pdb_gid_to_sid, METH_VARARGS,
3454                 "gid_to_sid(gid) -> sid\n\n \
3455                 Return sid for given group id." },
3456         { "sid_to_id", (PyCFunction)py_pdb_sid_to_id, METH_VARARGS,
3457                 "sid_to_id(sid) -> Tuple\n\n \
3458                 Return id and type for given sid." },
3459         /* capabilities */
3460         { "new_rid", (PyCFunction)py_pdb_new_rid, METH_NOARGS,
3461                 "new_rid() -> rid\n\n \
3462                 Get a new rid." },
3463         { "get_trusteddom_pw", (PyCFunction)py_pdb_get_trusteddom_pw, METH_VARARGS,
3464                 "get_trusteddom_pw(domain) -> Mapping\n\n \
3465                 Get trusted domain password, sid and last set time in a dictionary." },
3466         { "set_trusteddom_pw", (PyCFunction)py_pdb_set_trusteddom_pw, METH_VARARGS,
3467                 "set_trusteddom_pw(domain, pwd, sid) -> None\n\n \
3468                 Set trusted domain password." },
3469         { "del_trusteddom_pw", (PyCFunction)py_pdb_del_trusteddom_pw, METH_VARARGS,
3470                 "del_trusteddom_pw(domain) -> None\n\n \
3471                 Delete trusted domain password." },
3472         { "enum_trusteddoms", (PyCFunction)py_pdb_enum_trusteddoms, METH_NOARGS,
3473                 "enum_trusteddoms() -> List\n\n \
3474                 Get list of trusted domains. Each item is a dictionary with name and sid keys" },
3475         { "get_trusted_domain", (PyCFunction)py_pdb_get_trusted_domain, METH_VARARGS,
3476                 "get_trusted_domain(domain) -> Mapping\n\n \
3477                 Get trusted domain information by name. Information is a dictionary with keys - domain_name, netbios_name, security_identifier, trust_auth_incoming, trust_auth_outgoing, trust_direction, trust_type, trust_attributes, trust_forest_trust_info." },
3478         { "get_trusted_domain_by_sid", (PyCFunction)py_pdb_get_trusted_domain_by_sid, METH_VARARGS,
3479                 "get_trusted_domain_by_sid(domain_sid) -> Mapping\n\n \
3480                 Get trusted domain information by sid. Information is a dictionary with keys - domain_name, netbios_name, security_identifier, trust_auth_incoming, trust_auth_outgoing, trust_direction, trust_type, trust_attributes, trust_forest_trust_info" },
3481         { "set_trusted_domain", (PyCFunction)py_pdb_set_trusted_domain, METH_VARARGS,
3482                 "set_trusted_domain(domain, Mapping) -> None\n\n \
3483                 Set trusted domain information for domain. Mapping is a dictionary with keys - domain_name, netbios_name, security_identifier, trust_auth_incoming, trust_auth_outgoing, trust_direction, trust_type, trust_attributes, trust_forest_trust_info." },
3484         { "del_trusted_domain", (PyCFunction)py_pdb_del_trusted_domain, METH_VARARGS,
3485                 "del_trusted_domain(domain) -> None\n\n \
3486                 Delete trusted domain." },
3487         { "enum_trusted_domains", (PyCFunction)py_pdb_enum_trusted_domains, METH_VARARGS,
3488                 "enum_trusted_domains() -> List\n\n \
3489                 Get list of trusted domains. Each entry is a dictionary with keys - domain_name, netbios_name, security_identifier, trust_auth_incoming, trust_auth_outgoing, trust_direction, trust_type, trust_attributes, trust_forest_trust_info." },
3490         { "get_secret", (PyCFunction)py_pdb_get_secret, METH_VARARGS,
3491                 "get_secret(secret_name) -> Mapping\n\n \
3492                 Get secret information for secret_name. Information is a dictionary with keys - secret_current, secret_current_lastchange, secret_old, secret_old_lastchange, sd." },
3493         { "set_secret", (PyCFunction)py_pdb_set_secret, METH_VARARGS,
3494                 "set_secret(secret_name, Mapping) -> None\n\n \
3495                 Set secret information for secret_name using dictionary with keys - secret_current, sd." },
3496         { "delete_secret", (PyCFunction)py_pdb_delete_secret, METH_VARARGS,
3497                 "delete_secret(secret_name) -> None\n\n \
3498                 Delete secret information for secret_name." },
3499         { NULL },
3500 };
3501
3502
3503 static PyObject *py_pdb_new(PyTypeObject *type, PyObject *args, PyObject *kwargs)
3504 {
3505         const char *url = NULL;
3506         PyObject *pypdb;
3507         NTSTATUS status;
3508         struct pdb_methods *methods;
3509
3510         if (!PyArg_ParseTuple(args, "s", &url)) {
3511                 return NULL;
3512         }
3513
3514         /* Initalize list of methods */
3515         status = make_pdb_method_name(&methods, url);
3516         if (!NT_STATUS_IS_OK(status)) {
3517                 PyErr_Format(py_pdb_error, "Cannot load backend methods for '%s' backend (%d,%s)",
3518                                 url,
3519                                 NT_STATUS_V(status),
3520                                 get_friendly_nt_error_msg(status));
3521                 return NULL;
3522         }
3523
3524         if ((pypdb = pytalloc_steal(type, methods)) == NULL) {
3525                 PyErr_NoMemory();
3526                 return NULL;
3527         }
3528
3529         return pypdb;
3530 }
3531
3532
3533 static PyTypeObject PyPDB = {
3534         .tp_name = "passdb.PDB",
3535         .tp_basicsize = sizeof(pytalloc_Object),
3536         .tp_new = py_pdb_new,
3537         .tp_flags = Py_TPFLAGS_DEFAULT,
3538         .tp_methods = py_pdb_methods,
3539         .tp_doc = "PDB(url[, read_write_flags]) -> Password DB object\n",
3540 };
3541
3542
3543 /*
3544  * Return a list of passdb backends
3545  */
3546 static PyObject *py_passdb_backends(PyObject *self)
3547 {
3548         PyObject *py_blist;
3549         const struct pdb_init_function_entry *entry;
3550         TALLOC_CTX *tframe;
3551
3552         if ((tframe = talloc_stackframe()) == NULL) {
3553                 PyErr_NoMemory();
3554                 return NULL;
3555         }
3556
3557         entry = pdb_get_backends();
3558         if(! entry) {
3559                 Py_RETURN_NONE;
3560         }
3561
3562         if((py_blist = PyList_New(0)) == NULL) {
3563                 PyErr_NoMemory();
3564                 return NULL;
3565         }
3566
3567         while(entry) {
3568                 PyList_Append(py_blist, PyString_FromString(entry->name));
3569                 entry = entry->next;
3570         }
3571
3572         talloc_free(tframe);
3573
3574         return py_blist;
3575 }
3576
3577
3578 static PyObject *py_set_smb_config(PyObject *self, PyObject *args)
3579 {
3580         const char *smb_config;
3581         TALLOC_CTX *tframe;
3582
3583         if (!PyArg_ParseTuple(args, "s", &smb_config)) {
3584                 return NULL;
3585         }
3586
3587         if ((tframe = talloc_stackframe()) == NULL) {
3588                 PyErr_NoMemory();
3589                 return NULL;
3590         }
3591
3592         /* Load smbconf parameters */
3593         if (!lp_load_global(smb_config)) {
3594                 PyErr_Format(py_pdb_error, "Cannot open '%s'", smb_config);
3595                 return NULL;
3596         }
3597
3598         talloc_free(tframe);
3599
3600         Py_RETURN_NONE;
3601 }
3602
3603
3604 static PyObject *py_set_secrets_dir(PyObject *self, PyObject *args)
3605 {
3606         const char *private_dir;
3607         TALLOC_CTX *tframe;
3608
3609         if (!PyArg_ParseTuple(args, "s", &private_dir)) {
3610                 return NULL;
3611         }
3612
3613         if ((tframe = talloc_stackframe()) == NULL) {
3614                 PyErr_NoMemory();
3615                 return NULL;
3616         }
3617
3618         /* Initialize secrets database */
3619         if (!secrets_init_path(private_dir)) {
3620                 PyErr_Format(py_pdb_error, "Cannot open secrets file database in '%s'",
3621                                 private_dir);
3622                 return NULL;
3623         }
3624
3625         talloc_free(tframe);
3626
3627         Py_RETURN_NONE;
3628 }
3629
3630 static PyObject *py_get_global_sam_sid(PyObject *self)
3631 {
3632         struct dom_sid *domain_sid, *domain_sid_copy;
3633         TALLOC_CTX *tframe;
3634         PyObject *py_dom_sid;
3635
3636         tframe = talloc_stackframe();
3637         if (tframe == NULL) {
3638                 PyErr_NoMemory();
3639                 return NULL;
3640         }
3641
3642         domain_sid = get_global_sam_sid();
3643
3644         domain_sid_copy = dom_sid_dup(tframe, domain_sid);
3645         if (domain_sid_copy == NULL) {
3646                 PyErr_NoMemory();
3647                 talloc_free(tframe);
3648                 return NULL;
3649         }
3650
3651         py_dom_sid = pytalloc_steal(dom_sid_Type, domain_sid_copy);
3652
3653         talloc_free(tframe);
3654
3655         return py_dom_sid;
3656 }
3657
3658
3659 static PyMethodDef py_passdb_methods[] = {
3660         { "get_backends", (PyCFunction)py_passdb_backends, METH_NOARGS,
3661                 "get_backends() -> list\n\n \
3662                 Get a list of password database backends supported." },
3663         { "set_smb_config", (PyCFunction)py_set_smb_config, METH_VARARGS,
3664                 "set_smb_config(path) -> None\n\n \
3665                 Set path to smb.conf file to load configuration parameters." },
3666         { "set_secrets_dir", (PyCFunction)py_set_secrets_dir, METH_VARARGS,
3667                 "set_secrets_dir(private_dir) -> None\n\n \
3668                 Set path to private directory to load secrets database from non-default location." },
3669         { "get_global_sam_sid", (PyCFunction)py_get_global_sam_sid, METH_NOARGS,
3670                 "get_global_sam_sid() -> dom_sid\n\n \
3671                 Return domain SID." },
3672         { NULL },
3673 };
3674
3675 void initpassdb(void)
3676 {
3677         PyObject *m, *mod;
3678         char exception_name[] = "passdb.error";
3679
3680         PyTypeObject *talloc_type = pytalloc_GetObjectType();
3681         if (talloc_type == NULL) {
3682                 return;
3683         }
3684
3685         PyPDB.tp_base = talloc_type;
3686         if (PyType_Ready(&PyPDB) < 0) {
3687                 return;
3688         }
3689
3690         PySamu.tp_base = talloc_type;
3691         if (PyType_Ready(&PySamu) < 0) {
3692                 return;
3693         }
3694
3695         PyGroupmap.tp_base = talloc_type;
3696         if (PyType_Ready(&PyGroupmap) < 0) {
3697                 return;
3698         }
3699
3700         m = Py_InitModule3("passdb", py_passdb_methods, "SAMBA Password Database");
3701         if (m == NULL) {
3702             return;
3703         }
3704
3705         /* Create new exception for passdb module */
3706         py_pdb_error = PyErr_NewException(exception_name, NULL, NULL);
3707         Py_INCREF(py_pdb_error);
3708         PyModule_AddObject(m, "error", py_pdb_error);
3709
3710         Py_INCREF(&PyPDB);
3711         PyModule_AddObject(m, "PDB", (PyObject *)&PyPDB);
3712
3713         Py_INCREF(&PySamu);
3714         PyModule_AddObject(m, "Samu", (PyObject *)&PySamu);
3715
3716         Py_INCREF(&PyGroupmap);
3717         PyModule_AddObject(m, "Groupmap", (PyObject *)&PyGroupmap);
3718
3719         /* Import dom_sid type from dcerpc.security */
3720         mod = PyImport_ImportModule("samba.dcerpc.security");
3721         if (mod == NULL) {
3722                 return;
3723         }
3724
3725         dom_sid_Type = (PyTypeObject *)PyObject_GetAttrString(mod, "dom_sid");
3726         if (dom_sid_Type == NULL) {
3727                 return;
3728         }
3729
3730         /* Import security_descriptor type from dcerpc.security */
3731         security_Type = (PyTypeObject *)PyObject_GetAttrString(mod, "descriptor");
3732         Py_DECREF(mod);
3733         if (security_Type == NULL) {
3734                 return;
3735         }
3736
3737         /* Import GUID type from dcerpc.misc */
3738         mod = PyImport_ImportModule("samba.dcerpc.misc");
3739         if (mod == NULL) {
3740                 return;
3741         }
3742
3743         guid_Type = (PyTypeObject *)PyObject_GetAttrString(mod, "GUID");
3744         Py_DECREF(mod);
3745         if (guid_Type == NULL) {
3746                 return;
3747         }
3748 }