added jeremy's new c++-like code for parsing of security descriptors.
[samba.git] / source3 / include / rpc_secdes.h
1 /* 
2    Unix SMB/Netbios implementation.
3    Version 1.9.
4    SMB parameters and setup
5    Copyright (C) Andrew Tridgell 1992-1997
6    Copyright (C) Luke Kenneth Casson Leighton 1996-1997
7    Copyright (C) Paul Ashton 1997
8    
9    This program is free software; you can redistribute it and/or modify
10    it under the terms of the GNU General Public License as published by
11    the Free Software Foundation; either version 2 of the License, or
12    (at your option) any later version.
13    
14    This program is distributed in the hope that it will be useful,
15    but WITHOUT ANY WARRANTY; without even the implied warranty of
16    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
17    GNU General Public License for more details.
18    
19    You should have received a copy of the GNU General Public License
20    along with this program; if not, write to the Free Software
21    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
22 */
23
24 #ifndef _RPC_SECDES_H /* _RPC_SECDES_H */
25 #define _RPC_SECDES_H 
26
27 #define SEC_RIGHTS_QUERY_VALUE    0x00000001
28 #define SEC_RIGHTS_SET_VALUE      0x00000002
29 #define SEC_RIGHTS_CREATE_SUBKEY  0x00000004
30 #define SEC_RIGHTS_ENUM_SUBKEYS   0x00000008
31 #define SEC_RIGHTS_NOTIFY         0x00000010
32 #define SEC_RIGHTS_CREATE_LINK    0x00000020
33 #define SEC_RIGHTS_DELETE         0x00010000
34 #define SEC_RIGHTS_READ_CONTROL   0x00020000
35 #define SEC_RIGHTS_WRITE_DAC      0x00040000
36 #define SEC_RIGHTS_WRITE_OWNER    0x00080000
37
38 #define SEC_RIGHTS_READ           0x00020019
39 #define SEC_RIGHTS_FULL_CONTROL   0x000f003f
40
41
42 #define SEC_ACE_TYPE_ACCESS_ALLOWED     0x0
43 #define SEC_ACE_TYPE_ACCESS_DENIED      0x1
44 #define SEC_ACE_TYPE_SYSTEM_AUDIT       0x2
45 #define SEC_ACE_TYPE_SYSTEM_ALARM       0x3
46
47 #define SEC_ACE_FLAG_OBJECT_INHERIT     0x1
48 #define SEC_ACE_FLAG_CONTAINER_INHERIT  0x2
49 #define SEC_ACE_FLAG_NO_PROPAGATE_INHERIT       0x4
50 #define SEC_ACE_FLAG_INHERIT_ONLY       0x8
51 #define SEC_ACE_FLAG_VALID_INHERIT      0xf
52 #define SEC_ACE_FLAG_SUCCESSFUL_ACCESS  0x40
53 #define SEC_ACE_FLAG_FAILED_ACCESS      0x80
54
55 #define SEC_DESC_OWNER_DEFAULTED        0x0001
56 #define SEC_DESC_GROUP_DEFAULTED        0x0002
57 #define SEC_DESC_DACL_PRESENT           0x0004
58 #define SEC_DESC_DACL_DEFAULTED         0x0008
59 #define SEC_DESC_SACL_PRESENT           0x0010
60 #define SEC_DESC_SACL_DEFAULTED         0x0020
61 #define SEC_DESC_SELF_RELATIVE          0x8000
62
63 /* security information */
64
65 #define OWNER_SECURITY_INFORMATION 0x00000001
66 #define GROUP_SECURITY_INFORMATION 0x00000002
67 #define DACL_SECURITY_INFORMATION  0x00000004
68 #define SACL_SECURITY_INFORMATION  0x00000008
69
70
71
72 /* SEC_ACCESS */
73 typedef struct security_info_info
74 {
75         uint32 mask;
76
77 } SEC_ACCESS;
78
79 /* SEC_ACE */
80 typedef struct security_ace_info
81 {
82         uint8 type;  /* xxxx_xxxx_ACE_TYPE - e.g allowed / denied etc */
83         uint8 flags; /* xxxx_INHERIT_xxxx - e.g OBJECT_INHERIT_ACE */
84         uint16 size;
85
86         SEC_ACCESS info;
87         DOM_SID sid;
88
89 } SEC_ACE;
90
91
92 #define MAX_SEC_ACES 16
93
94 /* SEC_ACL */
95 typedef struct security_acl_info
96 {
97         uint16 revision; /* 0x0002 */
98         uint16 size; /* size in bytes of the entire ACL structure */
99         uint32 num_aces; /* number of Access Control Entries */
100         SEC_ACE *ace_list;
101
102 } SEC_ACL;
103
104
105 /* SEC_DESC */
106 typedef struct security_descriptor_info
107 {
108         uint16 revision; /* 0x0001 */
109         uint16 type;     /* SEC_DESC_xxxx flags */
110
111         uint32 off_owner_sid; /* offset to owner sid */
112         uint32 off_grp_sid  ; /* offset to group sid */
113         uint32 off_sacl     ; /* offset to system list of permissions */
114         uint32 off_dacl     ; /* offset to list of permissions */
115
116         SEC_ACL *dacl; /* user ACL */
117         SEC_ACL *sacl; /* system ACL */
118         DOM_SID *owner_sid; 
119         DOM_SID *grp_sid;
120
121 } SEC_DESC;
122
123 /* SEC_DESC_BUF */
124 typedef struct sec_desc_buf_info
125 {
126         uint32 max_len;
127         uint32 undoc;
128         uint32 len;
129
130         SEC_DESC *sec;
131
132 } SEC_DESC_BUF;
133
134 #endif /* _RPC_SECDES_H */