s3:services_db: untangle assignments from check in construct_service_sd().
[amitay/samba.git] / source3 / services / services_db.c
1 /* 
2  *  Unix SMB/CIFS implementation.
3  *  Service Control API Implementation
4  * 
5  *  Copyright (C) Marcin Krzysztof Porwit         2005.
6  *  Largely Rewritten by:
7  *  Copyright (C) Gerald (Jerry) Carter           2005.
8  *  
9  *  This program is free software; you can redistribute it and/or modify
10  *  it under the terms of the GNU General Public License as published by
11  *  the Free Software Foundation; either version 3 of the License, or
12  *  (at your option) any later version.
13  *  
14  *  This program is distributed in the hope that it will be useful,
15  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
16  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
17  *  GNU General Public License for more details.
18  *  
19  *  You should have received a copy of the GNU General Public License
20  *  along with this program; if not, see <http://www.gnu.org/licenses/>.
21  */
22
23 #include "includes.h"
24 #include "services/services.h"
25 #include "registry.h"
26 #include "registry/reg_util_legacy.h"
27 #include "registry/reg_dispatcher.h"
28 #include "registry/reg_objects.h"
29
30 struct rcinit_file_information {
31         char *description;
32 };
33
34 struct service_display_info {
35         const char *servicename;
36         const char *daemon;
37         const char *dispname;
38         const char *description;
39 };
40
41 struct service_display_info builtin_svcs[] = {
42   { "Spooler",        "smbd",   "Print Spooler", "Internal service for spooling files to print devices" },
43   { "NETLOGON",       "smbd",   "Net Logon", "File service providing access to policy and profile data (not remotely manageable)" },
44   { "RemoteRegistry", "smbd",   "Remote Registry Service", "Internal service providing remote access to "
45                                 "the Samba registry" },
46   { "WINS",           "nmbd",   "Windows Internet Name Service (WINS)", "Internal service providing a "
47                                 "NetBIOS point-to-point name server (not remotely manageable)" },
48   { NULL, NULL, NULL, NULL }
49 };
50
51 struct service_display_info common_unix_svcs[] = {
52   { "cups",          NULL, "Common Unix Printing System","Provides unified printing support for all operating systems" },
53   { "postfix",       NULL, "Internet Mail Service",     "Provides support for sending and receiving electonic mail" },
54   { "sendmail",      NULL, "Internet Mail Service",     "Provides support for sending and receiving electonic mail" },
55   { "portmap",       NULL, "TCP Port to RPC PortMapper",NULL },
56   { "xinetd",        NULL, "Internet Meta-Daemon",      NULL },
57   { "inet",          NULL, "Internet Meta-Daemon",      NULL },
58   { "xntpd",         NULL, "Network Time Service",      NULL },
59   { "ntpd",          NULL, "Network Time Service",      NULL },
60   { "lpd",           NULL, "BSD Print Spooler",         NULL },
61   { "nfsserver",     NULL, "Network File Service",      NULL },
62   { "cron",          NULL, "Scheduling Service",        NULL },
63   { "at",            NULL, "Scheduling Service",        NULL },
64   { "nscd",          NULL, "Name Service Cache Daemon", NULL },
65   { "slapd",         NULL, "LDAP Directory Service",    NULL },
66   { "ldap",          NULL, "LDAP DIrectory Service",    NULL },
67   { "ypbind",        NULL, "NIS Directory Service",     NULL },
68   { "courier-imap",  NULL, "IMAP4 Mail Service",        NULL },
69   { "courier-pop3",  NULL, "POP3 Mail Service",         NULL },
70   { "named",         NULL, "Domain Name Service",       NULL },
71   { "bind",          NULL, "Domain Name Service",       NULL },
72   { "httpd",         NULL, "HTTP Server",               NULL },
73   { "apache",        NULL, "HTTP Server",               "Provides s highly scalable and flexible web server "
74                                                         "capable of implementing various protocols incluing "
75                                                         "but not limited to HTTP" },
76   { "autofs",        NULL, "Automounter",               NULL },
77   { "squid",         NULL, "Web Cache Proxy ",          NULL },
78   { "perfcountd",    NULL, "Performance Monitoring Daemon", NULL },
79   { "pgsql",         NULL, "PgSQL Database Server",     "Provides service for SQL database from Postgresql.org" },
80   { "arpwatch",      NULL, "ARP Tables watcher",        "Provides service for monitoring ARP tables for changes" },
81   { "dhcpd",         NULL, "DHCP Server",               "Provides service for dynamic host configuration and IP assignment" },
82   { "nwserv",        NULL, "NetWare Server Emulator",   "Provides service for emulating Novell NetWare 3.12 server" },
83   { "proftpd",       NULL, "Professional FTP Server",   "Provides high configurable service for FTP connection and "
84                                                         "file transferring" },
85   { "ssh2",          NULL, "SSH Secure Shell",          "Provides service for secure connection for remote administration" },
86   { "sshd",          NULL, "SSH Secure Shell",          "Provides service for secure connection for remote administration" },
87   { NULL, NULL, NULL, NULL }
88 };
89
90
91 /********************************************************************
92 ********************************************************************/
93
94 static struct security_descriptor* construct_service_sd( TALLOC_CTX *ctx )
95 {
96         struct security_ace ace[4];
97         size_t i = 0;
98         struct security_descriptor *sd = NULL;
99         struct security_acl *theacl = NULL;
100         size_t sd_size;
101
102         /* basic access for Everyone */
103
104         init_sec_ace(&ace[i++], &global_sid_World,
105                 SEC_ACE_TYPE_ACCESS_ALLOWED, SERVICE_READ_ACCESS, 0);
106
107         init_sec_ace(&ace[i++], &global_sid_Builtin_Power_Users,
108                         SEC_ACE_TYPE_ACCESS_ALLOWED, SERVICE_EXECUTE_ACCESS, 0);
109
110         init_sec_ace(&ace[i++], &global_sid_Builtin_Server_Operators,
111                 SEC_ACE_TYPE_ACCESS_ALLOWED, SERVICE_ALL_ACCESS, 0);
112         init_sec_ace(&ace[i++], &global_sid_Builtin_Administrators,
113                 SEC_ACE_TYPE_ACCESS_ALLOWED, SERVICE_ALL_ACCESS, 0);
114
115         /* create the security descriptor */
116
117         theacl = make_sec_acl(ctx, NT4_ACL_REVISION, i, ace);
118         if (theacl == NULL) {
119                 return NULL;
120         }
121
122         sd = make_sec_desc(ctx, SECURITY_DESCRIPTOR_REVISION_1,
123                            SEC_DESC_SELF_RELATIVE, NULL, NULL, NULL,
124                            theacl, &sd_size);
125         if (sd == NULL) {
126                 return NULL;
127         }
128
129         return sd;
130 }
131
132 /********************************************************************
133  This is where we do the dirty work of filling in things like the
134  Display name, Description, etc...
135 ********************************************************************/
136
137 static char *get_common_service_dispname( const char *servicename )
138 {
139         int i;
140
141         for ( i=0; common_unix_svcs[i].servicename; i++ ) {
142                 if (strequal(servicename, common_unix_svcs[i].servicename)) {
143                         char *dispname;
144                         if (asprintf(&dispname,
145                                 "%s (%s)",
146                                 common_unix_svcs[i].dispname,
147                                 common_unix_svcs[i].servicename) < 0) {
148                                 return NULL;
149                         }
150                         return dispname;
151                 }
152         }
153
154         return SMB_STRDUP(servicename );
155 }
156
157 /********************************************************************
158 ********************************************************************/
159
160 static char *cleanup_string( const char *string )
161 {
162         char *clean = NULL;
163         char *begin, *end;
164         TALLOC_CTX *ctx = talloc_tos();
165
166         clean = talloc_strdup(ctx, string);
167         if (!clean) {
168                 return NULL;
169         }
170         begin = clean;
171
172         /* trim any beginning whilespace */
173
174         while (isspace(*begin)) {
175                 begin++;
176         }
177
178         if (*begin == '\0') {
179                 return NULL;
180         }
181
182         /* trim any trailing whitespace or carriage returns.
183            Start at the end and move backwards */
184
185         end = begin + strlen(begin) - 1;
186
187         while ( isspace(*end) || *end=='\n' || *end=='\r' ) {
188                 *end = '\0';
189                 end--;
190         }
191
192         return begin;
193 }
194
195 /********************************************************************
196 ********************************************************************/
197
198 static bool read_init_file( const char *servicename, struct rcinit_file_information **service_info )
199 {
200         struct rcinit_file_information *info = NULL;
201         char *filepath = NULL;
202         char str[1024];
203         XFILE *f = NULL;
204         char *p = NULL;
205
206         if ( !(info = TALLOC_ZERO_P( NULL, struct rcinit_file_information ) ) )
207                 return False;
208
209         /* attempt the file open */
210
211         filepath = talloc_asprintf(info, "%s/%s/%s", get_dyn_MODULESDIR(),
212                                 SVCCTL_SCRIPT_DIR, servicename);
213         if (!filepath) {
214                 TALLOC_FREE(info);
215                 return false;
216         }
217         if (!(f = x_fopen( filepath, O_RDONLY, 0 ))) {
218                 DEBUG(0,("read_init_file: failed to open [%s]\n", filepath));
219                 TALLOC_FREE(info);
220                 return false;
221         }
222
223         while ( (x_fgets( str, sizeof(str)-1, f )) != NULL ) {
224                 /* ignore everything that is not a full line
225                    comment starting with a '#' */
226
227                 if ( str[0] != '#' )
228                         continue;
229
230                 /* Look for a line like '^#.*Description:' */
231
232                 if ( (p = strstr( str, "Description:" )) != NULL ) {
233                         char *desc;
234
235                         p += strlen( "Description:" ) + 1;
236                         if ( !p )
237                                 break;
238
239                         if ( (desc = cleanup_string(p)) != NULL )
240                                 info->description = talloc_strdup( info, desc );
241                 }
242         }
243
244         x_fclose( f );
245
246         if ( !info->description )
247                 info->description = talloc_strdup( info, "External Unix Service" );
248
249         *service_info = info;
250         TALLOC_FREE(filepath);
251
252         return True;
253 }
254
255 /********************************************************************
256  This is where we do the dirty work of filling in things like the
257  Display name, Description, etc...
258 ********************************************************************/
259
260 static void fill_service_values(const char *name, struct regval_ctr *values)
261 {
262         char *dname, *ipath, *description;
263         uint32 dword;
264         int i;
265
266         /* These values are hardcoded in all QueryServiceConfig() replies.
267            I'm just storing them here for cosmetic purposes */
268
269         dword = SVCCTL_AUTO_START;
270         regval_ctr_addvalue( values, "Start", REG_DWORD, (uint8 *)&dword, sizeof(uint32));
271
272         dword = SERVICE_TYPE_WIN32_OWN_PROCESS;
273         regval_ctr_addvalue( values, "Type", REG_DWORD, (uint8 *)&dword, sizeof(uint32));
274
275         dword = SVCCTL_SVC_ERROR_NORMAL;
276         regval_ctr_addvalue( values, "ErrorControl", REG_DWORD, (uint8 *)&dword, sizeof(uint32));
277
278         /* everything runs as LocalSystem */
279
280         regval_ctr_addvalue_sz(values, "ObjectName", "LocalSystem");
281
282         /* special considerations for internal services and the DisplayName value */
283
284         for ( i=0; builtin_svcs[i].servicename; i++ ) {
285                 if ( strequal( name, builtin_svcs[i].servicename ) ) {
286                         ipath = talloc_asprintf(talloc_tos(), "%s/%s/%s",
287                                         get_dyn_MODULESDIR(), SVCCTL_SCRIPT_DIR,
288                                         builtin_svcs[i].daemon);
289                         description = talloc_strdup(talloc_tos(), builtin_svcs[i].description);
290                         dname = talloc_strdup(talloc_tos(), builtin_svcs[i].dispname);
291                         break;
292                 }
293         }
294
295         /* default to an external service if we haven't found a match */
296
297         if ( builtin_svcs[i].servicename == NULL ) {
298                 char *dispname = NULL;
299                 struct rcinit_file_information *init_info = NULL;
300
301                 ipath = talloc_asprintf(talloc_tos(), "%s/%s/%s",
302                                         get_dyn_MODULESDIR(), SVCCTL_SCRIPT_DIR,
303                                         name);
304
305                 /* lookup common unix display names */
306                 dispname = get_common_service_dispname(name);
307                 dname = talloc_strdup(talloc_tos(), dispname ? dispname : "");
308                 SAFE_FREE(dispname);
309
310                 /* get info from init file itself */
311                 if ( read_init_file( name, &init_info ) ) {
312                         description = talloc_strdup(talloc_tos(), init_info->description);
313                         TALLOC_FREE( init_info );
314                 }
315                 else {
316                         description = talloc_strdup(talloc_tos(), "External Unix Service");
317                 }
318         }
319
320         /* add the new values */
321
322         regval_ctr_addvalue_sz(values, "DisplayName", dname);
323         regval_ctr_addvalue_sz(values, "ImagePath", ipath);
324         regval_ctr_addvalue_sz(values, "Description", description);
325
326         TALLOC_FREE(dname);
327         TALLOC_FREE(ipath);
328         TALLOC_FREE(description);
329
330         return;
331 }
332
333 /********************************************************************
334 ********************************************************************/
335
336 static void add_new_svc_name(struct registry_key_handle *key_parent,
337                              struct regsubkey_ctr *subkeys,
338                              const char *name )
339 {
340         struct registry_key_handle *key_service = NULL, *key_secdesc = NULL;
341         WERROR wresult;
342         char *path = NULL;
343         struct regval_ctr *values = NULL;
344         struct regsubkey_ctr *svc_subkeys = NULL;
345         struct security_descriptor *sd = NULL;
346         DATA_BLOB sd_blob;
347         NTSTATUS status;
348
349         /* add to the list and create the subkey path */
350
351         regsubkey_ctr_addkey( subkeys, name );
352         store_reg_keys( key_parent, subkeys );
353
354         /* open the new service key */
355
356         if (asprintf(&path, "%s\\%s", KEY_SERVICES, name) < 0) {
357                 return;
358         }
359         wresult = regkey_open_internal( NULL, &key_service, path,
360                                         get_root_nt_token(), REG_KEY_ALL );
361         if ( !W_ERROR_IS_OK(wresult) ) {
362                 DEBUG(0,("add_new_svc_name: key lookup failed! [%s] (%s)\n",
363                         path, win_errstr(wresult)));
364                 SAFE_FREE(path);
365                 return;
366         }
367         SAFE_FREE(path);
368
369         /* add the 'Security' key */
370
371         wresult = regsubkey_ctr_init(key_service, &svc_subkeys);
372         if (!W_ERROR_IS_OK(wresult)) {
373                 DEBUG(0,("add_new_svc_name: talloc() failed!\n"));
374                 TALLOC_FREE( key_service );
375                 return;
376         }
377
378         fetch_reg_keys( key_service, svc_subkeys );
379         regsubkey_ctr_addkey( svc_subkeys, "Security" );
380         store_reg_keys( key_service, svc_subkeys );
381
382         /* now for the service values */
383
384         wresult = regval_ctr_init(key_service, &values);
385         if (!W_ERROR_IS_OK(wresult)) {
386                 DEBUG(0,("add_new_svc_name: talloc() failed!\n"));
387                 TALLOC_FREE( key_service );
388                 return;
389         }
390
391         fill_service_values( name, values );
392         store_reg_values( key_service, values );
393
394         /* cleanup the service key*/
395
396         TALLOC_FREE( key_service );
397
398         /* now add the security descriptor */
399
400         if (asprintf(&path, "%s\\%s\\%s", KEY_SERVICES, name, "Security") < 0) {
401                 return;
402         }
403         wresult = regkey_open_internal( NULL, &key_secdesc, path,
404                                         get_root_nt_token(), REG_KEY_ALL );
405         if ( !W_ERROR_IS_OK(wresult) ) {
406                 DEBUG(0,("add_new_svc_name: key lookup failed! [%s] (%s)\n",
407                         path, win_errstr(wresult)));
408                 TALLOC_FREE( key_secdesc );
409                 SAFE_FREE(path);
410                 return;
411         }
412         SAFE_FREE(path);
413
414         wresult = regval_ctr_init(key_secdesc, &values);
415         if (!W_ERROR_IS_OK(wresult)) {
416                 DEBUG(0,("add_new_svc_name: talloc() failed!\n"));
417                 TALLOC_FREE( key_secdesc );
418                 return;
419         }
420
421         if ( !(sd = construct_service_sd(key_secdesc)) ) {
422                 DEBUG(0,("add_new_svc_name: Failed to create default sec_desc!\n"));
423                 TALLOC_FREE( key_secdesc );
424                 return;
425         }
426
427         status = marshall_sec_desc(key_secdesc, sd, &sd_blob.data,
428                                    &sd_blob.length);
429         if (!NT_STATUS_IS_OK(status)) {
430                 DEBUG(0, ("marshall_sec_desc failed: %s\n",
431                           nt_errstr(status)));
432                 TALLOC_FREE(key_secdesc);
433                 return;
434         }
435
436         regval_ctr_addvalue(values, "Security", REG_BINARY,
437                             sd_blob.data, sd_blob.length);
438         store_reg_values( key_secdesc, values );
439
440         TALLOC_FREE( key_secdesc );
441
442         return;
443 }
444
445 /********************************************************************
446 ********************************************************************/
447
448 void svcctl_init_keys( void )
449 {
450         const char **service_list = lp_svcctl_list();
451         int i;
452         struct regsubkey_ctr *subkeys = NULL;
453         struct registry_key_handle *key = NULL;
454         WERROR wresult;
455
456         /* bad mojo here if the lookup failed.  Should not happen */
457
458         wresult = regkey_open_internal( NULL, &key, KEY_SERVICES,
459                                         get_root_nt_token(), REG_KEY_ALL );
460
461         if ( !W_ERROR_IS_OK(wresult) ) {
462                 DEBUG(0,("svcctl_init_keys: key lookup failed! (%s)\n",
463                         win_errstr(wresult)));
464                 return;
465         }
466
467         /* lookup the available subkeys */
468
469         wresult = regsubkey_ctr_init(key, &subkeys);
470         if (!W_ERROR_IS_OK(wresult)) {
471                 DEBUG(0,("svcctl_init_keys: talloc() failed!\n"));
472                 TALLOC_FREE( key );
473                 return;
474         }
475
476         fetch_reg_keys( key, subkeys );
477
478         /* the builtin services exist */
479
480         for ( i=0; builtin_svcs[i].servicename; i++ )
481                 add_new_svc_name( key, subkeys, builtin_svcs[i].servicename );
482
483         for ( i=0; service_list && service_list[i]; i++ ) {
484
485                 /* only add new services */
486                 if ( regsubkey_ctr_key_exists( subkeys, service_list[i] ) )
487                         continue;
488
489                 /* Add the new service key and initialize the appropriate values */
490
491                 add_new_svc_name( key, subkeys, service_list[i] );
492         }
493
494         TALLOC_FREE( key );
495
496         /* initialize the control hooks */
497
498         init_service_op_table();
499
500         return;
501 }
502
503 /********************************************************************
504  This is where we do the dirty work of filling in things like the
505  Display name, Description, etc...Always return a default secdesc
506  in case of any failure.
507 ********************************************************************/
508
509 struct security_descriptor *svcctl_get_secdesc( TALLOC_CTX *ctx, const char *name, struct security_token *token )
510 {
511         struct registry_key_handle *key = NULL;
512         struct regval_ctr *values = NULL;
513         struct regval_blob *val = NULL;
514         struct security_descriptor *ret_sd = NULL;
515         char *path= NULL;
516         WERROR wresult;
517         NTSTATUS status;
518
519         /* now add the security descriptor */
520
521         if (asprintf(&path, "%s\\%s\\%s", KEY_SERVICES, name, "Security") < 0) {
522                 return NULL;
523         }
524         wresult = regkey_open_internal( NULL, &key, path, token,
525                                         REG_KEY_ALL );
526         if ( !W_ERROR_IS_OK(wresult) ) {
527                 DEBUG(0,("svcctl_get_secdesc: key lookup failed! [%s] (%s)\n",
528                         path, win_errstr(wresult)));
529                 goto done;
530         }
531
532         wresult = regval_ctr_init(key, &values);
533         if (!W_ERROR_IS_OK(wresult)) {
534                 DEBUG(0,("svcctl_get_secdesc: talloc() failed!\n"));
535                 goto done;
536         }
537
538         if (fetch_reg_values( key, values ) == -1) {
539                 DEBUG(0, ("Error getting registry values\n"));
540                 goto done;
541         }
542
543         if ( !(val = regval_ctr_getvalue( values, "Security" )) ) {
544                 goto fallback_to_default_sd;
545         }
546
547         /* stream the service security descriptor */
548
549         status = unmarshall_sec_desc(ctx, regval_data_p(val),
550                                      regval_size(val), &ret_sd);
551
552         if (NT_STATUS_IS_OK(status)) {
553                 goto done;
554         }
555
556 fallback_to_default_sd:
557         DEBUG(6, ("svcctl_get_secdesc: constructing default secdesc for "
558                   "service [%s]\n", name));
559         ret_sd = construct_service_sd(ctx);
560
561 done:
562         SAFE_FREE(path);
563         TALLOC_FREE(key);
564         return ret_sd;
565 }
566
567 /********************************************************************
568  Wrapper to make storing a Service sd easier
569 ********************************************************************/
570
571 bool svcctl_set_secdesc( TALLOC_CTX *ctx, const char *name, struct security_descriptor *sec_desc, struct security_token *token )
572 {
573         struct registry_key_handle *key = NULL;
574         WERROR wresult;
575         char *path = NULL;
576         struct regval_ctr *values = NULL;
577         DATA_BLOB blob;
578         NTSTATUS status;
579         bool ret = False;
580
581         /* now add the security descriptor */
582
583         if (asprintf(&path, "%s\\%s\\%s", KEY_SERVICES, name, "Security") < 0) {
584                 return false;
585         }
586         wresult = regkey_open_internal( NULL, &key, path, token,
587                                         REG_KEY_ALL );
588         if ( !W_ERROR_IS_OK(wresult) ) {
589                 DEBUG(0,("svcctl_get_secdesc: key lookup failed! [%s] (%s)\n",
590                         path, win_errstr(wresult)));
591                 SAFE_FREE(path);
592                 return False;
593         }
594         SAFE_FREE(path);
595
596         wresult = regval_ctr_init(key, &values);
597         if (!W_ERROR_IS_OK(wresult)) {
598                 DEBUG(0,("svcctl_set_secdesc: talloc() failed!\n"));
599                 TALLOC_FREE( key );
600                 return False;
601         }
602
603         /* stream the printer security descriptor */
604
605         status = marshall_sec_desc(ctx, sec_desc, &blob.data, &blob.length);
606         if (!NT_STATUS_IS_OK(status)) {
607                 DEBUG(0,("svcctl_set_secdesc: ndr_push_struct_blob() failed!\n"));
608                 TALLOC_FREE( key );
609                 return False;
610         }
611
612         regval_ctr_addvalue( values, "Security", REG_BINARY, blob.data, blob.length);
613         ret = store_reg_values( key, values );
614
615         /* cleanup */
616
617         TALLOC_FREE( key);
618
619         return ret;
620 }
621
622 /********************************************************************
623 ********************************************************************/
624
625 const char *svcctl_lookup_dispname(TALLOC_CTX *ctx, const char *name, struct security_token *token )
626 {
627         const char *display_name = NULL;
628         struct registry_key_handle *key = NULL;
629         struct regval_ctr *values = NULL;
630         struct regval_blob *val = NULL;
631         char *path = NULL;
632         WERROR wresult;
633         DATA_BLOB blob;
634
635         /* now add the security descriptor */
636
637         if (asprintf(&path, "%s\\%s", KEY_SERVICES, name) < 0) {
638                 return NULL;
639         }
640         wresult = regkey_open_internal( NULL, &key, path, token,
641                                         REG_KEY_READ );
642         if ( !W_ERROR_IS_OK(wresult) ) {
643                 DEBUG(0,("svcctl_lookup_dispname: key lookup failed! [%s] (%s)\n", 
644                         path, win_errstr(wresult)));
645                 SAFE_FREE(path);
646                 goto fail;
647         }
648         SAFE_FREE(path);
649
650         wresult = regval_ctr_init(key, &values);
651         if (!W_ERROR_IS_OK(wresult)) {
652                 DEBUG(0,("svcctl_lookup_dispname: talloc() failed!\n"));
653                 TALLOC_FREE( key );
654                 goto fail;
655         }
656
657         fetch_reg_values( key, values );
658
659         if ( !(val = regval_ctr_getvalue( values, "DisplayName" )) )
660                 goto fail;
661
662         blob = data_blob_const(regval_data_p(val), regval_size(val));
663         pull_reg_sz(ctx, &blob, &display_name);
664
665         TALLOC_FREE( key );
666
667         return display_name;
668
669 fail:
670         /* default to returning the service name */
671         TALLOC_FREE( key );
672         return talloc_strdup(ctx, name);
673 }
674
675 /********************************************************************
676 ********************************************************************/
677
678 const char *svcctl_lookup_description(TALLOC_CTX *ctx, const char *name, struct security_token *token )
679 {
680         const char *description = NULL;
681         struct registry_key_handle *key = NULL;
682         struct regval_ctr *values = NULL;
683         struct regval_blob *val = NULL;
684         char *path = NULL;
685         WERROR wresult;
686         DATA_BLOB blob;
687
688         /* now add the security descriptor */
689
690         if (asprintf(&path, "%s\\%s", KEY_SERVICES, name) < 0) {
691                 return NULL;
692         }
693         wresult = regkey_open_internal( NULL, &key, path, token,
694                                         REG_KEY_READ );
695         if ( !W_ERROR_IS_OK(wresult) ) {
696                 DEBUG(0,("svcctl_lookup_description: key lookup failed! [%s] (%s)\n", 
697                         path, win_errstr(wresult)));
698                 SAFE_FREE(path);
699                 return NULL;
700         }
701         SAFE_FREE(path);
702
703         wresult = regval_ctr_init(key, &values);
704         if (!W_ERROR_IS_OK(wresult)) {
705                 DEBUG(0,("svcctl_lookup_description: talloc() failed!\n"));
706                 TALLOC_FREE( key );
707                 return NULL;
708         }
709
710         fetch_reg_values( key, values );
711
712         if ( !(val = regval_ctr_getvalue( values, "Description" )) ) {
713                 TALLOC_FREE( key );
714                 return "Unix Service";
715         }
716
717         blob = data_blob_const(regval_data_p(val), regval_size(val));
718         pull_reg_sz(ctx, &blob, &description);
719
720         TALLOC_FREE(key);
721
722         return description;
723 }
724
725
726 /********************************************************************
727 ********************************************************************/
728
729 struct regval_ctr *svcctl_fetch_regvalues(const char *name, struct security_token *token)
730 {
731         struct registry_key_handle *key = NULL;
732         struct regval_ctr *values = NULL;
733         char *path = NULL;
734         WERROR wresult;
735
736         /* now add the security descriptor */
737
738         if (asprintf(&path, "%s\\%s", KEY_SERVICES, name) < 0) {
739                 return NULL;
740         }
741         wresult = regkey_open_internal( NULL, &key, path, token,
742                                         REG_KEY_READ );
743         if ( !W_ERROR_IS_OK(wresult) ) {
744                 DEBUG(0,("svcctl_fetch_regvalues: key lookup failed! [%s] (%s)\n",
745                         path, win_errstr(wresult)));
746                 SAFE_FREE(path);
747                 return NULL;
748         }
749         SAFE_FREE(path);
750
751         wresult = regval_ctr_init(NULL, &values);
752         if (!W_ERROR_IS_OK(wresult)) {
753                 DEBUG(0,("svcctl_fetch_regvalues: talloc() failed!\n"));
754                 TALLOC_FREE( key );
755                 return NULL;
756         }
757         fetch_reg_values( key, values );
758
759         TALLOC_FREE( key );
760         return values;
761 }