2 Unix SMB/CIFS implementation.
4 fast routines for getting the wire size of security objects
6 Copyright (C) Andrew Tridgell 2003
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 2 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program; if not, write to the Free Software
20 Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
27 return the wire size of a dom_sid
29 size_t ndr_size_dom_sid(const struct dom_sid *sid, int flags)
32 return 8 + 4*sid->num_auths;
36 return the wire size of a security_ace
38 size_t ndr_size_security_ace(const struct security_ace *ace, int flags)
41 return 8 + ndr_size_dom_sid(&ace->trustee, flags);
46 return the wire size of a security_acl
48 size_t ndr_size_security_acl(const struct security_acl *acl, int flags)
54 for (i=0;i<acl->num_aces;i++) {
55 ret += ndr_size_security_ace(&acl->aces[i], flags);
61 return the wire size of a security descriptor
63 size_t ndr_size_security_descriptor(const struct security_descriptor *sd, int flags)
69 ret += ndr_size_dom_sid(sd->owner_sid, flags);
70 ret += ndr_size_dom_sid(sd->group_sid, flags);
71 ret += ndr_size_security_acl(sd->dacl, flags);
72 ret += ndr_size_security_acl(sd->sacl, flags);
79 void ndr_print_dom_sid(struct ndr_print *ndr, const char *name, const struct dom_sid *sid)
81 ndr->print(ndr, "%-25s: %s", name, dom_sid_string(ndr, sid));
84 void ndr_print_dom_sid2(struct ndr_print *ndr, const char *name, const struct dom_sid *sid)
86 ndr_print_dom_sid(ndr, name, sid);
89 void ndr_print_dom_sid28(struct ndr_print *ndr, const char *name, const struct dom_sid *sid)
91 ndr_print_dom_sid(ndr, name, sid);
96 parse a dom_sid2 - this is a dom_sid but with an extra copy of the num_auths field
98 NTSTATUS ndr_pull_dom_sid2(struct ndr_pull *ndr, int ndr_flags, struct dom_sid *sid)
101 if (!(ndr_flags & NDR_SCALARS)) {
104 NDR_CHECK(ndr_pull_uint32(ndr, NDR_SCALARS, &num_auths));
105 NDR_CHECK(ndr_pull_dom_sid(ndr, ndr_flags, sid));
106 if (sid->num_auths != num_auths) {
107 return ndr_pull_error(ndr, NDR_ERR_ARRAY_SIZE,
108 "Bad array size %u should exceed %u",
109 num_auths, sid->num_auths);
115 parse a dom_sid2 - this is a dom_sid but with an extra copy of the num_auths field
117 NTSTATUS ndr_push_dom_sid2(struct ndr_push *ndr, int ndr_flags, const struct dom_sid *sid)
119 if (!(ndr_flags & NDR_SCALARS)) {
122 NDR_CHECK(ndr_push_uint32(ndr, NDR_SCALARS, sid->num_auths));
123 return ndr_push_dom_sid(ndr, ndr_flags, sid);
127 parse a dom_sid28 - this is a dom_sid in a fixed 28 byte buffer, so we need to ensure there are only upto 5 sub_auth
129 NTSTATUS ndr_pull_dom_sid28(struct ndr_pull *ndr, int ndr_flags, struct dom_sid *sid)
132 struct ndr_pull *subndr;
134 if (!(ndr_flags & NDR_SCALARS)) {
138 subndr = talloc_zero(ndr, struct ndr_pull);
139 NT_STATUS_HAVE_NO_MEMORY(subndr);
140 subndr->flags = ndr->flags;
141 subndr->current_mem_ctx = ndr->current_mem_ctx;
143 subndr->data = ndr->data + ndr->offset;
144 subndr->data_size = 28;
147 NDR_CHECK(ndr_pull_advance(ndr, 28));
149 status = ndr_pull_dom_sid(subndr, ndr_flags, sid);
150 if (!NT_STATUS_IS_OK(status)) {
151 /* handle a w2k bug which send random data in the buffer */
159 push a dom_sid28 - this is a dom_sid in a 28 byte fixed buffer
161 NTSTATUS ndr_push_dom_sid28(struct ndr_push *ndr, int ndr_flags, const struct dom_sid *sid)
166 if (!(ndr_flags & NDR_SCALARS)) {
170 if (sid->num_auths > 5) {
171 return ndr_push_error(ndr, NDR_ERR_RANGE,
172 "dom_sid28 allows only upto 5 sub auth [%u]",
176 old_offset = ndr->offset;
177 NDR_CHECK(ndr_push_dom_sid(ndr, ndr_flags, sid));
179 padding = 28 - (ndr->offset - old_offset);
182 NDR_CHECK(ndr_push_zero(ndr, padding));