Changed the sec desc access checks to match the spec. Needs testing.
[sfrench/samba-autobuild/.git] / source / include / rpc_secdes.h
1 /* 
2    Unix SMB/Netbios implementation.
3    Version 1.9.
4    SMB parameters and setup
5    Copyright (C) Andrew Tridgell              1992-2000
6    Copyright (C) Luke Kenneth Casson Leighton 1996-2000
7    
8    This program is free software; you can redistribute it and/or modify
9    it under the terms of the GNU General Public License as published by
10    the Free Software Foundation; either version 2 of the License, or
11    (at your option) any later version.
12    
13    This program is distributed in the hope that it will be useful,
14    but WITHOUT ANY WARRANTY; without even the implied warranty of
15    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16    GNU General Public License for more details.
17    
18    You should have received a copy of the GNU General Public License
19    along with this program; if not, write to the Free Software
20    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
21 */
22
23 #ifndef _RPC_SECDES_H /* _RPC_SECDES_H */
24 #define _RPC_SECDES_H 
25
26 #define SEC_RIGHTS_QUERY_VALUE    0x00000001
27 #define SEC_RIGHTS_SET_VALUE      0x00000002
28 #define SEC_RIGHTS_CREATE_SUBKEY  0x00000004
29 #define SEC_RIGHTS_ENUM_SUBKEYS   0x00000008
30 #define SEC_RIGHTS_NOTIFY         0x00000010
31 #define SEC_RIGHTS_CREATE_LINK    0x00000020
32 #define SEC_RIGHTS_DELETE         0x00010000
33 #define SEC_RIGHTS_READ_CONTROL   0x00020000
34 #define SEC_RIGHTS_WRITE_DAC      0x00040000
35 #define SEC_RIGHTS_WRITE_OWNER    0x00080000
36
37 #define SEC_RIGHTS_READ           0x00020019
38 #define SEC_RIGHTS_FULL_CONTROL   0x000f003f
39 #define SEC_RIGHTS_MAXIMUM_ALLOWED 0x02000000
40
41 #define SEC_ACE_TYPE_ACCESS_ALLOWED     0x0
42 #define SEC_ACE_TYPE_ACCESS_DENIED      0x1
43 #define SEC_ACE_TYPE_SYSTEM_AUDIT       0x2
44 #define SEC_ACE_TYPE_SYSTEM_ALARM       0x3
45
46 #define SEC_ACE_FLAG_OBJECT_INHERIT     0x1
47 #define SEC_ACE_FLAG_CONTAINER_INHERIT  0x2
48 #define SEC_ACE_FLAG_NO_PROPAGATE_INHERIT       0x4
49 #define SEC_ACE_FLAG_INHERIT_ONLY       0x8
50 #define SEC_ACE_FLAG_INHERITED_ACE      0x10 /* New for Windows 2000 */
51 #define SEC_ACE_FLAG_VALID_INHERIT      0xf
52 #define SEC_ACE_FLAG_SUCCESSFUL_ACCESS  0x40
53 #define SEC_ACE_FLAG_FAILED_ACCESS      0x80
54
55 #define SEC_DESC_OWNER_DEFAULTED        0x0001
56 #define SEC_DESC_GROUP_DEFAULTED        0x0002
57 #define SEC_DESC_DACL_PRESENT           0x0004
58 #define SEC_DESC_DACL_DEFAULTED         0x0008
59 #define SEC_DESC_SACL_PRESENT           0x0010
60 #define SEC_DESC_SACL_DEFAULTED         0x0020
61 /*
62  * New Windows 2000 bits.
63  */
64 #define SE_DESC_DACL_AUTO_INHERIT_REQ 0x0100
65 #define SE_DESC_SACL_AUTO_INHERIT_REQ 0x0200
66 #define SE_DESC_DACL_AUTO_INHERITED 0x0400
67 #define SE_DESC_SACL_AUTO_INHERITED 0x0800
68 #define SE_DESC_DACL_PROTECTED          0x1000
69 #define SE_DESC_SACL_PROTECTED          0x2000
70
71 #define SEC_DESC_SELF_RELATIVE          0x8000
72
73 /* security information */
74
75 #define OWNER_SECURITY_INFORMATION 0x00000001
76 #define GROUP_SECURITY_INFORMATION 0x00000002
77 #define DACL_SECURITY_INFORMATION  0x00000004
78 #define SACL_SECURITY_INFORMATION  0x00000008
79
80
81
82 /* SEC_ACCESS */
83 typedef struct security_info_info
84 {
85         uint32 mask;
86
87 } SEC_ACCESS;
88
89 /* SEC_ACE */
90 typedef struct security_ace_info
91 {
92         uint8 type;  /* xxxx_xxxx_ACE_TYPE - e.g allowed / denied etc */
93         uint8 flags; /* xxxx_INHERIT_xxxx - e.g OBJECT_INHERIT_ACE */
94         uint16 size;
95
96         SEC_ACCESS info;
97         DOM_SID sid;
98
99 } SEC_ACE;
100
101 #define ACL_REVISION 0x3
102
103 /* SEC_ACL */
104 typedef struct security_acl_info
105 {
106         uint16 revision; /* 0x0003 */
107         uint16 size; /* size in bytes of the entire ACL structure */
108         uint32 num_aces; /* number of Access Control Entries */
109
110         SEC_ACE *ace;
111
112 } SEC_ACL;
113
114 #define SEC_DESC_REVISION 0x1
115
116 /* SEC_DESC */
117 typedef struct security_descriptor_info
118 {
119         uint16 revision; /* 0x0001 */
120         uint16 type;     /* SEC_DESC_xxxx flags */
121
122         uint32 off_owner_sid; /* offset to owner sid */
123         uint32 off_grp_sid  ; /* offset to group sid */
124         uint32 off_sacl     ; /* offset to system list of permissions */
125         uint32 off_dacl     ; /* offset to list of permissions */
126
127         SEC_ACL *dacl; /* user ACL */
128         SEC_ACL *sacl; /* system ACL */
129         DOM_SID *owner_sid; 
130         DOM_SID *grp_sid;
131
132 } SEC_DESC;
133
134 /* SEC_DESC_BUF */
135 typedef struct sec_desc_buf_info
136 {
137         uint32 max_len;
138         uint32 undoc;
139         uint32 len;
140
141         SEC_DESC *sec;
142
143 } SEC_DESC_BUF;
144
145 #endif /* _RPC_SECDES_H */