updated the 3.0 branch from the head branch - ready for alpha18
[ira/wip.git] / source3 / rpc_parse / parse_lsa.c
index cc60ace9fc97d7d9c04ff9e5b3998f7ffbaa49b8..a6aecb796726a499b40918a3969d40f6971cab06 100644 (file)
@@ -1,10 +1,10 @@
 /* 
- *  Unix SMB/Netbios implementation.
- *  Version 1.9.
+ *  Unix SMB/CIFS implementation.
  *  RPC Pipe client / server routines
  *  Copyright (C) Andrew Tridgell              1992-1997,
  *  Copyright (C) Luke Kenneth Casson Leighton 1996-1997,
  *  Copyright (C) Paul Ashton                       1997.
+ *  Copyright (C) Andrew Bartlett                   2002.
  *  
  *  This program is free software; you can redistribute it and/or modify
  *  it under the terms of the GNU General Public License as published by
  */
 
 #include "includes.h"
-#include "nterr.h"
 
-extern int DEBUGLEVEL;
+#undef DBGC_CLASS
+#define DBGC_CLASS DBGC_RPC_PARSE
 
-static void lsa_io_trans_names(char *desc, LSA_TRANS_NAME_ENUM *trn, prs_struct *ps, int depth);
+static BOOL lsa_io_trans_names(char *desc, LSA_TRANS_NAME_ENUM *trn, prs_struct *ps, int depth);
 
 /*******************************************************************
-creates a LSA_TRANS_NAME structure.
+ Inits a LSA_TRANS_NAME structure.
 ********************************************************************/
-void make_lsa_trans_name(LSA_TRANS_NAME *trn, UNISTR2 *uni_name,
-                       uint32 sid_name_use, char *name, uint32 idx)
+
+void init_lsa_trans_name(LSA_TRANS_NAME *trn, UNISTR2 *uni_name,
+                        uint16 sid_name_use, char *name, uint32 idx)
 {
        int len_name = strlen(name);
 
+       if(len_name == 0)
+               len_name = 1;
+
        trn->sid_name_use = sid_name_use;
-       make_uni_hdr(&(trn->hdr_name), len_name, len_name, len_name != 0);
-       make_unistr2(uni_name, name, len_name);
+       init_uni_hdr(&trn->hdr_name, len_name);
+       init_unistr2(uni_name, name, len_name);
        trn->domain_idx = idx;
 }
 
 /*******************************************************************
-reads or writes a LSA_TRANS_NAME structure.
+ Reads or writes a LSA_TRANS_NAME structure.
 ********************************************************************/
-static void lsa_io_trans_name(char *desc, LSA_TRANS_NAME *trn, prs_struct *ps, int depth)
-{
-       if (trn == NULL) return;
 
+static BOOL lsa_io_trans_name(char *desc, LSA_TRANS_NAME *trn, prs_struct *ps, 
+                             int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_trans_name");
        depth++;
 
-       prs_align(ps);
+       if(!prs_align(ps))
+               return False;
        
-       prs_uint32("sid_name_use", ps, depth, &(trn->sid_name_use));
-       smb_io_unihdr ("hdr_name", &(trn->hdr_name), ps, depth);
-       prs_uint32("domain_idx  ", ps, depth, &(trn->domain_idx  ));
+       if(!prs_uint16("sid_name_use", ps, depth, &trn->sid_name_use))
+               return False;
+       if(!prs_align(ps))
+               return False;
+       
+       if(!smb_io_unihdr ("hdr_name", &trn->hdr_name, ps, depth))
+               return False;
+       if(!prs_uint32("domain_idx  ", ps, depth, &trn->domain_idx))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes a DOM_R_REF structure.
+ Reads or writes a DOM_R_REF structure.
 ********************************************************************/
-static void lsa_io_dom_r_ref(char *desc,  DOM_R_REF *r_r, prs_struct *ps, int depth)
+
+static BOOL lsa_io_dom_r_ref(char *desc, DOM_R_REF *r_r, prs_struct *ps, 
+                            int depth)
 {
-       int i, s, n;
+       int i;
 
-       prs_debug(ps, depth, desc, "smb_io_dom_r_ref");
+       prs_debug(ps, depth, desc, "lsa_io_dom_r_ref");
        depth++;
 
-       if (r_r == NULL) return;
-
-       prs_align(ps);
+       if(!prs_align(ps))
+               return False;
        
-       prs_uint32("undoc_buffer  ", ps, depth, &(r_r->undoc_buffer  )); /* undocumented buffer pointer. */
-       prs_uint32("num_ref_doms_1", ps, depth, &(r_r->num_ref_doms_1)); /* num referenced domains? */
-       prs_uint32("undoc_buffer2 ", ps, depth, &(r_r->undoc_buffer2 )); /* undocumented buffer pointer. */
-       prs_uint32("max_entries   ", ps, depth, &(r_r->max_entries   )); /* 32 - max number of entries */
-       prs_uint32("num_ref_doms_2", ps, depth, &(r_r->num_ref_doms_2)); /* 4 - num referenced domains? */
+       if(!prs_uint32("num_ref_doms_1", ps, depth, &r_r->num_ref_doms_1)) /* num referenced domains? */
+               return False;
+       if(!prs_uint32("ptr_ref_dom   ", ps, depth, &r_r->ptr_ref_dom)) /* undocumented buffer pointer. */
+               return False;
+       if(!prs_uint32("max_entries   ", ps, depth, &r_r->max_entries)) /* 32 - max number of entries */
+               return False;
 
-       SMB_ASSERT_ARRAY(r_r->hdr_ref_dom, r_r->num_ref_doms_1-1);
-       SMB_ASSERT_ARRAY(r_r->ref_dom, r_r->num_ref_doms_2);
+       SMB_ASSERT_ARRAY(r_r->hdr_ref_dom, r_r->num_ref_doms_1);
 
-       for (i = 0; i < r_r->num_ref_doms_1; i++)
-       {
-               fstring t;
+       if (r_r->ptr_ref_dom != 0) {
 
-               slprintf(t, sizeof(t) - 1, "dom_ref[%d] ", i);
-               smb_io_unihdr(t, &(r_r->hdr_ref_dom[i].hdr_dom_name), ps, depth);
+               if(!prs_uint32("num_ref_doms_2", ps, depth, &r_r->num_ref_doms_2)) /* 4 - num referenced domains? */
+                       return False;
 
-               slprintf(t, sizeof(t) - 1, "sid_ptr[%d] ", i);
-               prs_uint32(t, ps, depth, &(r_r->hdr_ref_dom[i].ptr_dom_sid));
-       }
+               SMB_ASSERT_ARRAY(r_r->ref_dom, r_r->num_ref_doms_2);
 
-       for (i = 0, n = 0, s = 0; i < r_r->num_ref_doms_2; i++)
-       {
-               fstring t;
+               for (i = 0; i < r_r->num_ref_doms_1; i++) {
+                       fstring t;
 
-               if (r_r->hdr_ref_dom[i].hdr_dom_name.buffer != 0)
-               {
                        slprintf(t, sizeof(t) - 1, "dom_ref[%d] ", i);
-                       smb_io_unistr2(t, &(r_r->ref_dom[n].uni_dom_name), True, ps, depth); /* domain name unicode string */
-                       n++;
-               }
+                       if(!smb_io_unihdr(t, &r_r->hdr_ref_dom[i].hdr_dom_name, ps, depth))
+                               return False;
 
-               if (r_r->hdr_ref_dom[i].ptr_dom_sid != 0)
-               {
                        slprintf(t, sizeof(t) - 1, "sid_ptr[%d] ", i);
-                       smb_io_dom_sid2("", &(r_r->ref_dom[s].ref_dom), ps, depth); /* referenced domain SIDs */
-                       s++;
+                       if(!prs_uint32(t, ps, depth, &r_r->hdr_ref_dom[i].ptr_dom_sid))
+                               return False;
+               }
+
+               for (i = 0; i < r_r->num_ref_doms_2; i++) {
+                       fstring t;
+
+                       if (r_r->hdr_ref_dom[i].hdr_dom_name.buffer != 0) {
+                               slprintf(t, sizeof(t) - 1, "dom_ref[%d] ", i);
+                               if(!smb_io_unistr2(t, &r_r->ref_dom[i].uni_dom_name, True, ps, depth)) /* domain name unicode string */
+                                       return False;
+                               if(!prs_align(ps))
+                                       return False;
+                       }
+
+                       if (r_r->hdr_ref_dom[i].ptr_dom_sid != 0) {
+                               slprintf(t, sizeof(t) - 1, "sid_ptr[%d] ", i);
+                               if(!smb_io_dom_sid2(t, &r_r->ref_dom[i].ref_dom, ps, depth)) /* referenced domain SIDs */
+                                       return False;
+                       }
                }
        }
-}
 
+       return True;
+}
 
 /*******************************************************************
-makes an LSA_SEC_QOS structure.
+ Inits an LSA_SEC_QOS structure.
 ********************************************************************/
-void make_lsa_sec_qos(LSA_SEC_QOS *qos, uint16 imp_lev, uint8 ctxt, uint8 eff,
-                               uint32 unknown)
-{
-       if (qos == NULL) return;
 
-       DEBUG(5,("make_lsa_sec_qos\n"));
+void init_lsa_sec_qos(LSA_SEC_QOS *qos, uint16 imp_lev, uint8 ctxt, uint8 eff)
+{
+       DEBUG(5, ("init_lsa_sec_qos\n"));
 
        qos->len = 0x0c; /* length of quality of service block, in bytes */
        qos->sec_imp_level = imp_lev;
        qos->sec_ctxt_mode = ctxt;
        qos->effective_only = eff;
-       qos->unknown = unknown;
 }
 
 /*******************************************************************
-reads or writes an LSA_SEC_QOS structure.
+ Reads or writes an LSA_SEC_QOS structure.
 ********************************************************************/
-static void lsa_io_sec_qos(char *desc,  LSA_SEC_QOS *qos, prs_struct *ps, int depth)
-{
-       int start;
 
-       if (qos == NULL) return;
+static BOOL lsa_io_sec_qos(char *desc,  LSA_SEC_QOS *qos, prs_struct *ps, 
+                          int depth)
+{
+       uint32 start;
 
        prs_debug(ps, depth, desc, "lsa_io_obj_qos");
        depth++;
 
-       prs_align(ps);
+       if(!prs_align(ps))
+               return False;
        
-       start = ps->offset;
+       start = prs_offset(ps);
 
        /* these pointers had _better_ be zero, because we don't know
           what they point to!
         */
-       prs_uint32("len           ", ps, depth, &(qos->len           )); /* 0x18 - length (in bytes) inc. the length field. */
-       prs_uint16("sec_imp_level ", ps, depth, &(qos->sec_imp_level )); 
-       prs_uint8 ("sec_ctxt_mode ", ps, depth, &(qos->sec_ctxt_mode )); 
-       prs_uint8 ("effective_only", ps, depth, &(qos->effective_only)); 
-       prs_uint32("unknown       ", ps, depth, &(qos->unknown       )); 
-
-       if (qos->len != ps->offset - start)
-       {
+       if(!prs_uint32("len           ", ps, depth, &qos->len)) /* 0x18 - length (in bytes) inc. the length field. */
+               return False;
+       if(!prs_uint16("sec_imp_level ", ps, depth, &qos->sec_imp_level ))
+               return False;
+       if(!prs_uint8 ("sec_ctxt_mode ", ps, depth, &qos->sec_ctxt_mode ))
+               return False;
+       if(!prs_uint8 ("effective_only", ps, depth, &qos->effective_only))
+               return False;
+
+       if (qos->len != prs_offset(ps) - start) {
                DEBUG(3,("lsa_io_sec_qos: length %x does not match size %x\n",
-                        qos->len, ps->offset - start));
+                        qos->len, prs_offset(ps) - start));
        }
-}
 
+       return True;
+}
 
 /*******************************************************************
-makes an LSA_OBJ_ATTR structure.
+ Inits an LSA_OBJ_ATTR structure.
 ********************************************************************/
-void make_lsa_obj_attr(LSA_OBJ_ATTR *attr, uint32 attributes, LSA_SEC_QOS *qos)
-{
-       if (attr == NULL) return;
 
-       DEBUG(5,("make_lsa_obj_attr\n"));
+static void init_lsa_obj_attr(LSA_OBJ_ATTR *attr, uint32 attributes, LSA_SEC_QOS *qos)
+{
+       DEBUG(5, ("init_lsa_obj_attr\n"));
 
        attr->len = 0x18; /* length of object attribute block, in bytes */
        attr->ptr_root_dir = 0;
@@ -179,595 +202,1918 @@ void make_lsa_obj_attr(LSA_OBJ_ATTR *attr, uint32 attributes, LSA_SEC_QOS *qos)
        attr->attributes = attributes;
        attr->ptr_sec_desc = 0;
        
-       if (qos != NULL)
-       {
+       if (qos != NULL) {
                attr->ptr_sec_qos = 1;
                attr->sec_qos = qos;
-       }
-       else
-       {
+       } else {
                attr->ptr_sec_qos = 0;
                attr->sec_qos = NULL;
        }
 }
 
 /*******************************************************************
-reads or writes an LSA_OBJ_ATTR structure.
+ Reads or writes an LSA_OBJ_ATTR structure.
 ********************************************************************/
-static void lsa_io_obj_attr(char *desc,  LSA_OBJ_ATTR *attr, prs_struct *ps, int depth)
-{
-       int start;
 
-       if (attr == NULL) return;
+static BOOL lsa_io_obj_attr(char *desc, LSA_OBJ_ATTR *attr, prs_struct *ps, 
+                           int depth)
+{
+       uint32 start;
 
        prs_debug(ps, depth, desc, "lsa_io_obj_attr");
        depth++;
 
-       prs_align(ps);
+       if(!prs_align(ps))
+               return False;
        
-       start = ps->offset;
+       start = prs_offset(ps);
 
        /* these pointers had _better_ be zero, because we don't know
           what they point to!
         */
-       prs_uint32("len         ", ps, depth, &(attr->len         )); /* 0x18 - length (in bytes) inc. the length field. */
-       prs_uint32("ptr_root_dir", ps, depth, &(attr->ptr_root_dir)); /* 0 - root directory (pointer) */
-       prs_uint32("ptr_obj_name", ps, depth, &(attr->ptr_obj_name)); /* 0 - object name (pointer) */
-       prs_uint32("attributes  ", ps, depth, &(attr->attributes  )); /* 0 - attributes (undocumented) */
-       prs_uint32("ptr_sec_desc", ps, depth, &(attr->ptr_sec_desc)); /* 0 - security descriptior (pointer) */
-       prs_uint32("ptr_sec_qos ", ps, depth, &(attr->ptr_sec_qos )); /* security quality of service (pointer) */
-
-       if (attr->len != ps->offset - start)
-       {
+       if(!prs_uint32("len         ", ps, depth, &attr->len)) /* 0x18 - length (in bytes) inc. the length field. */
+               return False;
+       if(!prs_uint32("ptr_root_dir", ps, depth, &attr->ptr_root_dir)) /* 0 - root directory (pointer) */
+               return False;
+       if(!prs_uint32("ptr_obj_name", ps, depth, &attr->ptr_obj_name)) /* 0 - object name (pointer) */
+               return False;
+       if(!prs_uint32("attributes  ", ps, depth, &attr->attributes)) /* 0 - attributes (undocumented) */
+               return False;
+       if(!prs_uint32("ptr_sec_desc", ps, depth, &attr->ptr_sec_desc)) /* 0 - security descriptior (pointer) */
+               return False;
+       if(!prs_uint32("ptr_sec_qos ", ps, depth, &attr->ptr_sec_qos )) /* security quality of service (pointer) */
+               return False;
+
+       /* code commented out as it's not necessary true (tested with hyena). JFM, 11/22/2001 */
+#if 0
+       if (attr->len != prs_offset(ps) - start) {
                DEBUG(3,("lsa_io_obj_attr: length %x does not match size %x\n",
-                        attr->len, ps->offset - start));
+                        attr->len, prs_offset(ps) - start));
+               return False;
        }
+#endif
 
-       if (attr->ptr_sec_qos != 0 && attr->sec_qos != NULL)
-       {
-               lsa_io_sec_qos("sec_qos", attr->sec_qos, ps, depth);
+       if (attr->ptr_sec_qos != 0) {
+               if (UNMARSHALLING(ps))
+                       if (!(attr->sec_qos = (LSA_SEC_QOS *)prs_alloc_mem(ps,sizeof(LSA_SEC_QOS))))
+                               return False;
+
+               if(!lsa_io_sec_qos("sec_qos", attr->sec_qos, ps, depth))
+                       return False;
        }
+
+       return True;
 }
 
 
 /*******************************************************************
-makes an LSA_Q_OPEN_POL structure.
+ Inits an LSA_Q_OPEN_POL structure.
 ********************************************************************/
-void make_q_open_pol(LSA_Q_OPEN_POL *r_q, uint16 system_name,
-                       uint32 attributes,
-                       uint32 desired_access,
-                       LSA_SEC_QOS *qos)
-{
-       if (r_q == NULL) return;
 
-       DEBUG(5,("make_open_pol: attr:%d da:%d\n", attributes, desired_access));
+void init_q_open_pol(LSA_Q_OPEN_POL *r_q, uint16 system_name,
+                    uint32 attributes, uint32 desired_access,
+                    LSA_SEC_QOS *qos)
+{
+       DEBUG(5, ("init_open_pol: attr:%d da:%d\n", attributes, 
+                 desired_access));
 
        r_q->ptr = 1; /* undocumented pointer */
 
-       if (qos == NULL)
-       {
-               r_q->des_access = desired_access;
-       }
+       r_q->des_access = desired_access;
 
        r_q->system_name = system_name;
-       make_lsa_obj_attr(&(r_q->attr           ), attributes, qos);
+       init_lsa_obj_attr(&r_q->attr, attributes, qos);
 }
 
 /*******************************************************************
-reads or writes an LSA_Q_OPEN_POL structure.
+ Reads or writes an LSA_Q_OPEN_POL structure.
 ********************************************************************/
-void lsa_io_q_open_pol(char *desc,  LSA_Q_OPEN_POL *r_q, prs_struct *ps, int depth)
-{
-       if (r_q == NULL) return;
 
+BOOL lsa_io_q_open_pol(char *desc, LSA_Q_OPEN_POL *r_q, prs_struct *ps, 
+                      int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_q_open_pol");
        depth++;
 
-       prs_uint32("ptr       ", ps, depth, &(r_q->ptr       ));
-       prs_uint16("system_name", ps, depth, &(r_q->system_name ));
-       prs_align ( ps );
+       if(!prs_uint32("ptr       ", ps, depth, &r_q->ptr))
+               return False;
+       if(!prs_uint16("system_name", ps, depth, &r_q->system_name))
+               return False;
+       if(!prs_align( ps ))
+               return False;
 
-       lsa_io_obj_attr("", &(r_q->attr           ), ps, depth);
+       if(!lsa_io_obj_attr("", &r_q->attr, ps, depth))
+               return False;
 
-       if (r_q->attr.ptr_sec_qos == 0)
-       {
-               prs_uint32("des_access", ps, depth, &(r_q->des_access));
-       }
+       if(!prs_uint32("des_access", ps, depth, &r_q->des_access))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes an LSA_R_OPEN_POL structure.
+ Reads or writes an LSA_R_OPEN_POL structure.
 ********************************************************************/
-void lsa_io_r_open_pol(char *desc,  LSA_R_OPEN_POL *r_p, prs_struct *ps, int depth)
-{
-       if (r_p == NULL) return;
 
+BOOL lsa_io_r_open_pol(char *desc, LSA_R_OPEN_POL *r_p, prs_struct *ps, 
+                      int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_r_open_pol");
        depth++;
 
-       smb_io_pol_hnd("", &(r_p->pol), ps, depth);
+       if(!smb_io_pol_hnd("", &r_p->pol, ps, depth))
+               return False;
 
-       prs_uint32("status", ps, depth, &(r_p->status));
+       if(!prs_ntstatus("status", ps, depth, &r_p->status))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-makes an LSA_Q_OPEN_POL2 structure.
+ Inits an LSA_Q_OPEN_POL2 structure.
 ********************************************************************/
-void make_q_open_pol2(LSA_Q_OPEN_POL2 *r_q, char *server_name,
-                       uint32 attributes,
-                       uint32 desired_access,
+
+void init_q_open_pol2(LSA_Q_OPEN_POL2 *r_q, char *server_name,
+                       uint32 attributes, uint32 desired_access,
                        LSA_SEC_QOS *qos)
 {
-       if (r_q == NULL) return;
-
-       DEBUG(5,("make_open_pol2: attr:%d da:%d\n", attributes, desired_access));
+       DEBUG(5, ("init_q_open_pol2: attr:%d da:%d\n", attributes, 
+                 desired_access));
 
        r_q->ptr = 1; /* undocumented pointer */
 
-       if (qos == NULL)
-       {
-               r_q->des_access = desired_access;
-       }
+       r_q->des_access = desired_access;
 
-       make_unistr2     (&(r_q->uni_server_name), server_name, strlen(server_name));
-       make_lsa_obj_attr(&(r_q->attr           ), attributes, qos);
+       init_unistr2(&r_q->uni_server_name, server_name, 
+                    strlen(server_name) + 1);
+
+       init_lsa_obj_attr(&r_q->attr, attributes, qos);
 }
 
 /*******************************************************************
-reads or writes an LSA_Q_OPEN_POL2 structure.
+ Reads or writes an LSA_Q_OPEN_POL2 structure.
 ********************************************************************/
-void lsa_io_q_open_pol2(char *desc,  LSA_Q_OPEN_POL2 *r_q, prs_struct *ps, int depth)
-{
-       if (r_q == NULL) return;
 
+BOOL lsa_io_q_open_pol2(char *desc, LSA_Q_OPEN_POL2 *r_q, prs_struct *ps, 
+                       int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_q_open_pol2");
        depth++;
 
-       prs_uint32("ptr       ", ps, depth, &(r_q->ptr       ));
+       if(!prs_uint32("ptr       ", ps, depth, &r_q->ptr))
+               return False;
 
-       smb_io_unistr2 ("", &(r_q->uni_server_name), r_q->ptr, ps, depth);
-       lsa_io_obj_attr("", &(r_q->attr           ), ps, depth);
+       if(!smb_io_unistr2 ("", &r_q->uni_server_name, r_q->ptr, ps, depth))
+               return False;
+       if(!lsa_io_obj_attr("", &r_q->attr, ps, depth))
+               return False;
 
-       if (r_q->attr.ptr_sec_qos == 0)
-       {
-               prs_uint32("des_access", ps, depth, &(r_q->des_access));
-       }
+       if(!prs_uint32("des_access", ps, depth, &r_q->des_access))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes an LSA_R_OPEN_POL2 structure.
+ Reads or writes an LSA_R_OPEN_POL2 structure.
 ********************************************************************/
-void lsa_io_r_open_pol2(char *desc,  LSA_R_OPEN_POL2 *r_p, prs_struct *ps, int depth)
-{
-       if (r_p == NULL) return;
 
+BOOL lsa_io_r_open_pol2(char *desc, LSA_R_OPEN_POL2 *r_p, prs_struct *ps, 
+                       int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_r_open_pol2");
        depth++;
 
-       smb_io_pol_hnd("", &(r_p->pol), ps, depth);
+       if(!smb_io_pol_hnd("", &r_p->pol, ps, depth))
+               return False;
+
+       if(!prs_ntstatus("status", ps, depth, &r_p->status))
+               return False;
 
-       prs_uint32("status", ps, depth, &(r_p->status));
+       return True;
 }
 
 /*******************************************************************
-makes an LSA_Q_QUERY_INFO structure.
+makes an LSA_Q_QUERY_SEC_OBJ structure.
 ********************************************************************/
-void make_q_query(LSA_Q_QUERY_INFO *q_q, POLICY_HND *hnd, uint16 info_class)
+
+void init_q_query_sec_obj(LSA_Q_QUERY_SEC_OBJ *q_q, const POLICY_HND *hnd, 
+                         uint32 sec_info)
 {
-       if (q_q == NULL || hnd == NULL) return;
+       DEBUG(5, ("init_q_query_sec_obj\n"));
 
-       DEBUG(5,("make_q_query\n"));
+       q_q->pol = *hnd;
+       q_q->sec_info = sec_info;
 
-       memcpy(&(q_q->pol), hnd, sizeof(q_q->pol));
+       return;
+}
 
-       q_q->info_class = info_class;
+/*******************************************************************
+ Reads or writes an LSA_Q_QUERY_SEC_OBJ structure.
+********************************************************************/
+
+BOOL lsa_io_q_query_sec_obj(char *desc, LSA_Q_QUERY_SEC_OBJ *q_q, 
+                           prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_query_sec_obj");
+       depth++;
+
+       if (!smb_io_pol_hnd("", &q_q->pol, ps, depth))
+               return False;
+
+       if (!prs_uint32("sec_info", ps, depth, &q_q->sec_info))
+               return False;
+
+       return True;
+} 
+
+/*******************************************************************
+ Reads or writes a LSA_R_QUERY_SEC_OBJ structure.
+********************************************************************/
+
+BOOL lsa_io_r_query_sec_obj(char *desc, LSA_R_QUERY_SEC_OBJ *r_u, 
+                           prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_query_sec_obj");
+       depth++;
+
+       if (!prs_align(ps))
+               return False;
+
+       if (!prs_uint32("ptr", ps, depth, &r_u->ptr))
+               return False;
+
+       if (r_u->ptr != 0) {
+               if (!sec_io_desc_buf("sec", &r_u->buf, ps, depth))
+                       return False;
+       }
+
+       if (!prs_ntstatus("status", ps, depth, &r_u->status))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes an LSA_Q_QUERY_INFO structure.
+ Inits an LSA_Q_QUERY_INFO structure.
 ********************************************************************/
-void lsa_io_q_query(char *desc,  LSA_Q_QUERY_INFO *q_q, prs_struct *ps, int depth)
+
+void init_q_query(LSA_Q_QUERY_INFO *q_q, POLICY_HND *hnd, uint16 info_class)
 {
-       if (q_q == NULL) return;
+       DEBUG(5, ("init_q_query\n"));
 
+       memcpy(&q_q->pol, hnd, sizeof(q_q->pol));
+
+       q_q->info_class = info_class;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_Q_QUERY_INFO structure.
+********************************************************************/
+
+BOOL lsa_io_q_query(char *desc, LSA_Q_QUERY_INFO *q_q, prs_struct *ps, 
+                   int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_q_query");
        depth++;
 
-       smb_io_pol_hnd("", &(q_q->pol), ps, depth);
+       if(!smb_io_pol_hnd("", &q_q->pol, ps, depth))
+               return False;
 
-       prs_uint16("info_class", ps, depth, &(q_q->info_class));
+       if(!prs_uint16("info_class", ps, depth, &q_q->info_class))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes an LSA_Q_ENUM_TRUST_DOM structure.
+makes an LSA_Q_ENUM_TRUST_DOM structure.
 ********************************************************************/
-void lsa_io_q_enum_trust_dom(char *desc,  LSA_Q_ENUM_TRUST_DOM *q_e, prs_struct *ps, int depth)
+BOOL init_q_enum_trust_dom(LSA_Q_ENUM_TRUST_DOM * q_e, POLICY_HND *pol,
+                          uint32 enum_context, uint32 preferred_len)
 {
-       if (q_e == NULL) return;
+       DEBUG(5, ("init_q_enum_trust_dom\n"));
+
+       q_e->pol = *pol;
+       q_e->enum_context = enum_context;
+       q_e->preferred_len = preferred_len;
+
+       return True;
+}
 
+/*******************************************************************
+ Reads or writes an LSA_Q_ENUM_TRUST_DOM structure.
+********************************************************************/
+
+BOOL lsa_io_q_enum_trust_dom(char *desc, LSA_Q_ENUM_TRUST_DOM *q_e, 
+                            prs_struct *ps, int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_q_enum_trust_dom");
        depth++;
 
+       if(!smb_io_pol_hnd("", &q_e->pol, ps, depth))
+               return False;
 
-       smb_io_pol_hnd("", &(q_e->pol), ps, depth);
+       if(!prs_uint32("enum_context ", ps, depth, &q_e->enum_context))
+               return False;
+       if(!prs_uint32("preferred_len", ps, depth, &q_e->preferred_len))
+               return False;
 
-       prs_uint32("enum_context ", ps, depth, &(q_e->enum_context ));
-       prs_uint32("preferred_len", ps, depth, &(q_e->preferred_len));
+       return True;
 }
 
 /*******************************************************************
-makes an LSA_R_ENUM_TRUST_DOM structure.
+ Inits an LSA_R_ENUM_TRUST_DOM structure.
 ********************************************************************/
-void make_r_enum_trust_dom(LSA_R_ENUM_TRUST_DOM *r_e,
-                           uint32 enum_context, char *domain_name, DOM_SID *domain_sid,
-                           uint32 status)
+
+void init_r_enum_trust_dom(TALLOC_CTX *ctx, LSA_R_ENUM_TRUST_DOM *r_e, uint32 enum_context,
+                          uint32 req_num_domains, uint32 num_domains, TRUSTDOM **td)
+{
+       int i;
+
+        DEBUG(5, ("init_r_enum_trust_dom\n"));
+       
+        r_e->enum_context = enum_context;
+       r_e->num_domains = num_domains;
+       r_e->ptr_enum_domains = 0;
+       r_e->num_domains2 = num_domains;
+       
+       if (num_domains != 0) {
+       
+               /* 
+                * allocating empty arrays of unicode headers, strings
+                * and sids of enumerated trusted domains
+                */
+               if (!(r_e->hdr_domain_name = (UNIHDR2 *)talloc(ctx,sizeof(UNIHDR2) * num_domains))) {
+                       r_e->status = NT_STATUS_NO_MEMORY;
+                       return;
+               }
+               
+               if (!(r_e->uni_domain_name = (UNISTR2 *)talloc(ctx,sizeof(UNISTR2) * num_domains))) {
+                       r_e->status = NT_STATUS_NO_MEMORY;
+                       return;
+               }
+
+               if (!(r_e->domain_sid = (DOM_SID2 *)talloc(ctx,sizeof(DOM_SID2) * num_domains))) {
+                       r_e->status = NT_STATUS_NO_MEMORY;
+                       return;
+               }
+                               
+               for (i = 0; i < num_domains; i++) {
+                       
+                       /* don't know what actually is this for */
+                       r_e->ptr_enum_domains = 1;
+                       
+                       init_uni_hdr2(&r_e->hdr_domain_name[i], strlen_w((td[i])->name));
+                       init_dom_sid2(&r_e->domain_sid[i], &(td[i])->sid);
+                       
+                       init_unistr2_w(ctx, &r_e->uni_domain_name[i], (td[i])->name);
+                       
+               };
+       }
+
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_ENUM_TRUST_DOM structure.
+********************************************************************/
+
+BOOL lsa_io_r_enum_trust_dom(char *desc, LSA_R_ENUM_TRUST_DOM *r_e, 
+                            prs_struct *ps, int depth)
 {
-       if (r_e == NULL) return;
+       prs_debug(ps, depth, desc, "lsa_io_r_enum_trust_dom");
+       depth++;
 
-       DEBUG(5,("make_r_enum_trust_dom\n"));
+       if(!prs_uint32("enum_context    ", ps, depth, &r_e->enum_context))
+               return False;
+       if(!prs_uint32("num_domains     ", ps, depth, &r_e->num_domains))
+               return False;
+       if(!prs_uint32("ptr_enum_domains", ps, depth, &r_e->ptr_enum_domains))
+               return False;
 
-       r_e->enum_context = enum_context;
+       if (r_e->ptr_enum_domains) {
+               int i, num_domains;
 
-       if (status == 0)
-       {
-               int len_domain_name = strlen(domain_name);
+               if(!prs_uint32("num_domains2", ps, depth, &r_e->num_domains2))
+                       return False;
 
-               r_e->num_domains  = 1;
-               r_e->ptr_enum_domains = 1;
-               r_e->num_domains2 = 1;
+               num_domains = r_e->num_domains2;
+
+               if (UNMARSHALLING(ps)) {
+                       if (!(r_e->hdr_domain_name = (UNIHDR2 *)prs_alloc_mem(ps,sizeof(UNIHDR2) * num_domains)))
+                               return False;
+
+                       if (!(r_e->uni_domain_name = (UNISTR2 *)prs_alloc_mem(ps,sizeof(UNISTR2) * num_domains)))
+                               return False;
+
+                       if (!(r_e->domain_sid = (DOM_SID2 *)prs_alloc_mem(ps,sizeof(DOM_SID2) * num_domains)))
+                               return False;
+               }
 
-               make_uni_hdr2(&(r_e->hdr_domain_name ), len_domain_name, len_domain_name, 4);
-               make_unistr2 (&(r_e->uni_domain_name ), domain_name, len_domain_name);
-               make_dom_sid2(&(r_e->other_domain_sid), domain_sid);
+               for (i = 0; i < num_domains; i++) {
+                       if(!smb_io_unihdr2 ("", &r_e->hdr_domain_name[i], ps, 
+                                           depth))
+                               return False;
+               }
+               
+               for (i = 0; i < num_domains; i++) {
+                       if(!smb_io_unistr2 ("", &r_e->uni_domain_name[i],
+                                           r_e->hdr_domain_name[i].buffer,
+                                           ps, depth))
+                               return False;
+                       if(!smb_io_dom_sid2("", &r_e->domain_sid[i], ps, 
+                                           depth))
+                               return False;
+               }
        }
-       else
-       {
-               r_e->num_domains = 0;
-               r_e->ptr_enum_domains = 0;
+
+       if(!prs_ntstatus("status", ps, depth, &r_e->status))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+reads or writes a dom query structure.
+********************************************************************/
+
+static BOOL lsa_io_dom_query(char *desc, DOM_QUERY *d_q, prs_struct *ps, int depth)
+{
+       if (d_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_dom_query");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+
+       if(!prs_uint16("uni_dom_max_len", ps, depth, &d_q->uni_dom_max_len)) /* domain name string length * 2 */
+               return False;
+       if(!prs_uint16("uni_dom_str_len", ps, depth, &d_q->uni_dom_str_len)) /* domain name string length * 2 */
+               return False;
+
+       if(!prs_uint32("buffer_dom_name", ps, depth, &d_q->buffer_dom_name)) /* undocumented domain name string buffer pointer */
+               return False;
+       if(!prs_uint32("buffer_dom_sid ", ps, depth, &d_q->buffer_dom_sid)) /* undocumented domain SID string buffer pointer */
+               return False;
+
+       if(!smb_io_unistr2("unistr2", &d_q->uni_domain_name, d_q->buffer_dom_name, ps, depth)) /* domain name (unicode string) */
+               return False;
+
+       if(!prs_align(ps))
+               return False;
+
+       if (d_q->buffer_dom_sid != 0) {
+               if(!smb_io_dom_sid2("", &d_q->dom_sid, ps, depth)) /* domain SID */
+                       return False;
+       } else {
+               memset((char *)&d_q->dom_sid, '\0', sizeof(d_q->dom_sid));
        }
 
-       r_e->status = status;
+       return True;
 }
 
 /*******************************************************************
-reads or writes an LSA_R_ENUM_TRUST_DOM structure.
+reads or writes a structure.
 ********************************************************************/
-void lsa_io_r_enum_trust_dom(char *desc,  LSA_R_ENUM_TRUST_DOM *r_e, prs_struct *ps, int depth)
+
+static BOOL lsa_io_dom_query_2(char *desc, DOM_QUERY_2 *d_q, prs_struct *ps, int depth)
 {
-       if (r_e == NULL) return;
+       uint32 ptr = 1;
 
-       prs_debug(ps, depth, desc, "lsa_io_r_enum_trust_dom");
+       if (d_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_dom_query_2");
        depth++;
 
-       prs_uint32("enum_context    ", ps, depth, &(r_e->enum_context    ));
-       prs_uint32("num_domains     ", ps, depth, &(r_e->num_domains     ));
-       prs_uint32("ptr_enum_domains", ps, depth, &(r_e->ptr_enum_domains));
+       if (!prs_align(ps))
+               return False;
+
+       if (!prs_uint32("auditing_enabled", ps, depth, &d_q->auditing_enabled))
+               return False;
+       if (!prs_uint32("ptr   ", ps, depth, &ptr))
+               return False;
+       if (!prs_uint32("count1", ps, depth, &d_q->count1))
+               return False;
+       if (!prs_uint32("count2", ps, depth, &d_q->count2))
+               return False;
+
+       if (UNMARSHALLING(ps)) {
+               d_q->auditsettings = (uint32 *)talloc_zero(ps->mem_ctx, d_q->count2 * sizeof(uint32));
+       }
 
-       if (r_e->ptr_enum_domains != 0)
-       {
-               prs_uint32("num_domains2", ps, depth, &(r_e->num_domains2));
-               smb_io_unihdr2 ("", &(r_e->hdr_domain_name ), ps, depth);
-               smb_io_unistr2 ("", &(r_e->uni_domain_name ), r_e->hdr_domain_name.buffer, ps, depth);
-               smb_io_dom_sid2("", &(r_e->other_domain_sid), ps, depth);
+       if (d_q->auditsettings == NULL) {
+               DEBUG(1, ("lsa_io_dom_query_2: NULL auditsettings!\n"));
+               return False;
        }
 
-       prs_uint32("status", ps, depth, &(r_e->status));
+       if (!prs_uint32s(False, "auditsettings", ps, depth, d_q->auditsettings, d_q->count2))
+               return False;
+
+    return True;
 }
 
 /*******************************************************************
-reads or writes an LSA_Q_QUERY_INFO structure.
+ Reads or writes a dom query structure.
 ********************************************************************/
-void lsa_io_r_query(char *desc,  LSA_R_QUERY_INFO *r_q, prs_struct *ps, int depth)
+
+static BOOL lsa_io_dom_query_3(char *desc, DOM_QUERY_3 *d_q, prs_struct *ps, int depth)
 {
-       if (r_q == NULL) return;
+       return lsa_io_dom_query("", d_q, ps, depth);
+}
 
-       prs_debug(ps, depth, desc, "lsa_io_r_query");
+/*******************************************************************
+ Reads or writes a dom query structure.
+********************************************************************/
+
+static BOOL lsa_io_dom_query_5(char *desc, DOM_QUERY_5 *d_q, prs_struct *ps, int depth)
+{
+       return lsa_io_dom_query("", d_q, ps, depth);
+}
+
+/*******************************************************************
+ Reads or writes a dom query structure.
+********************************************************************/
+
+static BOOL lsa_io_dom_query_6(char *desc, DOM_QUERY_6 *d_q, prs_struct *ps, int depth)
+{
+       if (d_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_dom_query_6");
        depth++;
 
-       prs_uint32("undoc_buffer", ps, depth, &(r_q->undoc_buffer));
+       if (!prs_uint16("server_role", ps, depth, &d_q->server_role))
+               return False;
 
-       if (r_q->undoc_buffer != 0)
-       {
-               prs_uint16("info_class", ps, depth, &(r_q->info_class));
+       return True;
+}
 
-               switch (r_q->info_class)
-               {
-                       case 3:
-                       {
-                               smb_io_dom_query_3("", &(r_q->dom.id3), ps, depth);
-                               break;
-                       }
-                       case 5:
-                       {
-                               smb_io_dom_query_5("", &(r_q->dom.id3), ps, depth);
-                               break;
-                       }
-                       default:
-                       {
-                               /* PANIC! */
-                               break;
-                       }
+/*******************************************************************
+ Reads or writes an LSA_R_QUERY_INFO structure.
+********************************************************************/
+
+BOOL lsa_io_r_query(char *desc, LSA_R_QUERY_INFO *r_q, prs_struct *ps,
+                   int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_query");
+       depth++;
+
+       if(!prs_uint32("undoc_buffer", ps, depth, &r_q->undoc_buffer))
+               return False;
+
+       if (r_q->undoc_buffer != 0) {
+               if(!prs_uint16("info_class", ps, depth, &r_q->info_class))
+                       return False;
+
+               if(!prs_align(ps))
+                       return False;
+
+               switch (r_q->info_class) {
+               case 2:
+                       if(!lsa_io_dom_query_2("", &r_q->dom.id2, ps, depth))
+                               return False;
+                       break;
+               case 3:
+                       if(!lsa_io_dom_query_3("", &r_q->dom.id3, ps, depth))
+                               return False;
+                       break;
+               case 5:
+                       if(!lsa_io_dom_query_5("", &r_q->dom.id5, ps, depth))
+                               return False;
+                       break;
+               case 6:
+                       if(!lsa_io_dom_query_6("", &r_q->dom.id6, ps, depth))
+                               return False;
+                       break;
+               default:
+                       /* PANIC! */
+                       break;
                }
        }
 
-       prs_uint32("status", ps, depth, &(r_q->status));
+       if(!prs_align(ps))
+               return False;
+
+       if(!prs_ntstatus("status", ps, depth, &r_q->status))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-makes a LSA_SID_ENUM structure.
+ Inits a LSA_SID_ENUM structure.
 ********************************************************************/
-void make_lsa_sid_enum(LSA_SID_ENUM *sen, int num_entries, DOM_SID **sids)
+
+static void init_lsa_sid_enum(TALLOC_CTX *mem_ctx, LSA_SID_ENUM *sen, 
+                      int num_entries, DOM_SID *sids)
 {
-       int i, i2;
-       if (sen == NULL || sids == NULL) return;
+       int i;
 
-       DEBUG(5,("make_lsa_sid_enum\n"));
+       DEBUG(5, ("init_lsa_sid_enum\n"));
 
        sen->num_entries  = num_entries;
-       sen->ptr_sid_enum = num_entries != 0 ? 1 : 0;
+       sen->ptr_sid_enum = (num_entries != 0);
        sen->num_entries2 = num_entries;
 
-       SMB_ASSERT_ARRAY(sen->sid, sen->num_entries);
+       /* Allocate memory for sids and sid pointers */
 
-       for (i = 0, i2 = 0; i < num_entries; i++)
-       {
-               if (sids[i] != NULL)
-               {
-                       sen->ptr_sid[i] = 1;
-                       make_dom_sid2(&(sen->sid[i2]), sids[i]);
-                       i2++;
-               }
-               else
-               {
-                       sen->ptr_sid[i] = 0;
-               }
+       if (num_entries == 0) return;
+
+       if ((sen->ptr_sid = (uint32 *)talloc_zero(mem_ctx, num_entries * 
+                                            sizeof(uint32))) == NULL) {
+               DEBUG(3, ("init_lsa_sid_enum(): out of memory for ptr_sid\n"));
+               return;
+       }
+
+       if ((sen->sid = (DOM_SID2 *)talloc_zero(mem_ctx, num_entries * 
+                                          sizeof(DOM_SID2))) == NULL) {
+               DEBUG(3, ("init_lsa_sid_enum(): out of memory for sids\n"));
+               return;
+       }
+
+       /* Copy across SIDs and SID pointers */
+
+       for (i = 0; i < num_entries; i++) {
+               sen->ptr_sid[i] = 1;
+               init_dom_sid2(&sen->sid[i], &sids[i]);
        }
 }
 
 /*******************************************************************
-reads or writes a LSA_SID_ENUM structure.
+ Reads or writes a LSA_SID_ENUM structure.
 ********************************************************************/
-static void lsa_io_sid_enum(char *desc, LSA_SID_ENUM *sen,
-                               prs_struct *ps, int depth)
+
+static BOOL lsa_io_sid_enum(char *desc, LSA_SID_ENUM *sen, prs_struct *ps, 
+                           int depth)
 {
        int i;
 
-       if (sen == NULL) return;
-
        prs_debug(ps, depth, desc, "lsa_io_sid_enum");
        depth++;
 
-       prs_align(ps);
+       if(!prs_align(ps))
+               return False;
+       
+       if(!prs_uint32("num_entries ", ps, depth, &sen->num_entries))
+               return False;
+       if(!prs_uint32("ptr_sid_enum", ps, depth, &sen->ptr_sid_enum))
+               return False;
+
+       /*
+          if the ptr is NULL, leave here. checked from a real w2k trace.
+          JFM, 11/23/2001
+        */
        
-       prs_uint32("num_entries ", ps, depth, &(sen->num_entries));
-       prs_uint32("ptr_sid_enum", ps, depth, &(sen->ptr_sid_enum)); 
-       prs_uint32("num_entries2", ps, depth, &(sen->num_entries2)); 
+       if (sen->ptr_sid_enum==0)
+               return True;
+
+       if(!prs_uint32("num_entries2", ps, depth, &sen->num_entries2))
+               return False;
 
-       SMB_ASSERT_ARRAY(sen->ptr_sid, sen->num_entries);
+       /* Mallocate memory if we're unpacking from the wire */
+
+       if (UNMARSHALLING(ps)) {
+               if ((sen->ptr_sid = (uint32 *)prs_alloc_mem( ps,
+                       sen->num_entries * sizeof(uint32))) == NULL) {
+                       DEBUG(3, ("init_lsa_sid_enum(): out of memory for "
+                                 "ptr_sid\n"));
+                       return False;
+               }
+
+               if ((sen->sid = (DOM_SID2 *)prs_alloc_mem( ps,
+                       sen->num_entries * sizeof(DOM_SID2))) == NULL) {
+                       DEBUG(3, ("init_lsa_sid_enum(): out of memory for "
+                                 "sids\n"));
+                       return False;
+               }
+       }
 
-       for (i = 0; i < sen->num_entries; i++)
-       {       
+       for (i = 0; i < sen->num_entries; i++) {        
                fstring temp;
+
                slprintf(temp, sizeof(temp) - 1, "ptr_sid[%d]", i);
-               prs_uint32(temp, ps, depth, &(sen->ptr_sid[i])); /* domain SID pointers to be looked up. */
+               if(!prs_uint32(temp, ps, depth, &sen->ptr_sid[i])) {
+                       return False;
+               }
        }
 
-       SMB_ASSERT_ARRAY(sen->sid, sen->num_entries);
-
-       for (i = 0; i < sen->num_entries; i++)
-       {
+       for (i = 0; i < sen->num_entries; i++) {
                fstring temp;
+
                slprintf(temp, sizeof(temp) - 1, "sid[%d]", i);
-               smb_io_dom_sid2(temp, &(sen->sid[i]), ps, depth); /* domain SIDs to be looked up. */
+               if(!smb_io_dom_sid2(temp, &sen->sid[i], ps, depth)) {
+                       return False;
+               }
        }
+
+       return True;
 }
 
 /*******************************************************************
-makes an LSA_R_ENUM_TRUST_DOM structure.
+ Inits an LSA_R_ENUM_TRUST_DOM structure.
 ********************************************************************/
-void make_q_lookup_sids(LSA_Q_LOOKUP_SIDS *q_l, POLICY_HND *hnd,
-                               int num_sids, DOM_SID **sids,
-                               uint16 level)
-{
-       if (q_l == NULL) return;
 
-       DEBUG(5,("make_r_enum_trust_dom\n"));
-
-       memcpy(&(q_l->pol), hnd, sizeof(q_l->pol));
-       make_lsa_sid_enum(&(q_l->sids), num_sids, sids);
+void init_q_lookup_sids(TALLOC_CTX *mem_ctx, LSA_Q_LOOKUP_SIDS *q_l, 
+                       POLICY_HND *hnd, int num_sids, DOM_SID *sids,
+                       uint16 level)
+{
+       DEBUG(5, ("init_r_enum_trust_dom\n"));
 
-       q_l->names.num_entries     = 0;
-       q_l->names.ptr_trans_names = 0;
-       q_l->names.num_entries2    = 0;
+       ZERO_STRUCTP(q_l);
 
+       memcpy(&q_l->pol, hnd, sizeof(q_l->pol));
+       init_lsa_sid_enum(mem_ctx, &q_l->sids, num_sids, sids);
+       
        q_l->level.value = level;
 }
 
 /*******************************************************************
-reads or writes a LSA_Q_LOOKUP_SIDS structure.
+ Reads or writes a LSA_Q_LOOKUP_SIDS structure.
 ********************************************************************/
-void lsa_io_q_lookup_sids(char *desc, LSA_Q_LOOKUP_SIDS *q_s, prs_struct *ps, int depth)
-{
-       if (q_s == NULL) return;
 
+BOOL lsa_io_q_lookup_sids(char *desc, LSA_Q_LOOKUP_SIDS *q_s, prs_struct *ps,
+                         int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_q_lookup_sids");
        depth++;
 
-       prs_align(ps);
+       if(!prs_align(ps))
+               return False;
        
-       smb_io_pol_hnd     ("pol_hnd", &(q_s->pol), ps, depth); /* policy handle */
-       lsa_io_sid_enum    ("sids   ", &(q_s->sids   ), ps, depth); /* sids to be looked up */
-       lsa_io_trans_names ("names  ", &(q_s->names  ), ps, depth); /* translated names */
-       smb_io_lookup_level("switch ", &(q_s->level  ), ps, depth); /* lookup level */
-
-       prs_uint32("mapped_count", ps, depth, &(q_s->mapped_count));
+       if(!smb_io_pol_hnd("pol_hnd", &q_s->pol, ps, depth)) /* policy handle */
+               return False;
+       if(!lsa_io_sid_enum("sids   ", &q_s->sids, ps, depth)) /* sids to be looked up */
+               return False;
+       if(!lsa_io_trans_names("names  ", &q_s->names, ps, depth)) /* translated names */
+               return False;
+       if(!smb_io_lookup_level("switch ", &q_s->level, ps, depth)) /* lookup level */
+               return False;
+
+       if(!prs_uint32("mapped_count", ps, depth, &q_s->mapped_count))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes a structure.
+ Reads or writes a structure.
 ********************************************************************/
-static void lsa_io_trans_names(char *desc, LSA_TRANS_NAME_ENUM *trn,
-                               prs_struct *ps, int depth)
+
+static BOOL lsa_io_trans_names(char *desc, LSA_TRANS_NAME_ENUM *trn,
+                prs_struct *ps, int depth)
 {
        int i;
-       int i2;
-
-       if (trn == NULL) return;
 
        prs_debug(ps, depth, desc, "lsa_io_trans_names");
        depth++;
 
-       prs_align(ps);
-       
-       prs_uint32("num_entries    ", ps, depth, &(trn->num_entries));
-       prs_uint32("ptr_trans_names", ps, depth, &(trn->ptr_trans_names));
-
-       if (trn->ptr_trans_names != 0)
-       {
-               prs_uint32("num_entries2   ", ps, depth, &(trn->num_entries2));
+       if(!prs_align(ps))
+               return False;
+   
+       if(!prs_uint32("num_entries    ", ps, depth, &trn->num_entries))
+               return False;
+       if(!prs_uint32("ptr_trans_names", ps, depth, &trn->ptr_trans_names))
+               return False;
+
+       if (trn->ptr_trans_names != 0) {
+               if(!prs_uint32("num_entries2   ", ps, depth, 
+                              &trn->num_entries2))
+                       return False;
+
+               if (UNMARSHALLING(ps)) {
+                       if ((trn->name = (LSA_TRANS_NAME *)
+                            prs_alloc_mem(ps, trn->num_entries * 
+                                   sizeof(LSA_TRANS_NAME))) == NULL) {
+                               return False;
+                       }
 
-               SMB_ASSERT_ARRAY(trn->name, trn->num_entries);
+                       if ((trn->uni_name = (UNISTR2 *)
+                            prs_alloc_mem(ps, trn->num_entries *
+                                   sizeof(UNISTR2))) == NULL) {
+                               return False;
+                       }
+               }
 
-               for (i = 0, i2 = 0; i < trn->num_entries2; i++)
-               {
+               for (i = 0; i < trn->num_entries2; i++) {
                        fstring t;
                        slprintf(t, sizeof(t) - 1, "name[%d] ", i);
 
-                       lsa_io_trans_name(t, &(trn->name[i]), ps, depth); /* translated name */
+                       if(!lsa_io_trans_name(t, &trn->name[i], ps, depth)) /* translated name */
+                               return False;
+               }
 
-                       if (trn->name[i].hdr_name.buffer != 0)
-                       {
-                               smb_io_unistr2(t, &(trn->uni_name[i2]), 1, ps, depth);
-                               prs_align(ps);
-                               i2++;
-                       }
+               for (i = 0; i < trn->num_entries2; i++) {
+                       fstring t;
+                       slprintf(t, sizeof(t) - 1, "name[%d] ", i);
+
+                       if(!smb_io_unistr2(t, &trn->uni_name[i], trn->name[i].hdr_name.buffer, ps, depth))
+                               return False;
+                       if(!prs_align(ps))
+                               return False;
                }
        }
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes a structure.
+ Reads or writes a structure.
 ********************************************************************/
-void lsa_io_r_lookup_sids(char *desc,  LSA_R_LOOKUP_SIDS *r_s, prs_struct *ps, int depth)
-{
-       if (r_s == NULL) return;
 
+BOOL lsa_io_r_lookup_sids(char *desc, LSA_R_LOOKUP_SIDS *r_s, 
+                         prs_struct *ps, int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_r_lookup_sids");
        depth++;
 
-       prs_align(ps);
+       if(!prs_align(ps))
+               return False;
        
-       lsa_io_dom_r_ref  ("dom_ref", r_s->dom_ref, ps, depth); /* domain reference info */
-       lsa_io_trans_names("names  ", r_s->names  , ps, depth); /* translated names */
+       if(!prs_uint32("ptr_dom_ref", ps, depth, &r_s->ptr_dom_ref))
+               return False;
+
+       if (r_s->ptr_dom_ref != 0)
+               if(!lsa_io_dom_r_ref ("dom_ref", r_s->dom_ref, ps, depth)) /* domain reference info */
+                       return False;
 
-       prs_align(ps);
+       if(!lsa_io_trans_names("names  ", r_s->names, ps, depth)) /* translated names */
+               return False;
 
-       prs_uint32("mapped_count", ps, depth, &(r_s->mapped_count));
+       if(!prs_align(ps))
+               return False;
 
-       prs_uint32("status      ", ps, depth, &(r_s->status));
+       if(!prs_uint32("mapped_count", ps, depth, &r_s->mapped_count))
+               return False;
+
+       if(!prs_ntstatus("status      ", ps, depth, &r_s->status))
+               return False;
+
+       return True;
 }
 
 /*******************************************************************
-reads or writes a structure.
+makes a structure.
 ********************************************************************/
-void lsa_io_q_lookup_rids(char *desc,  LSA_Q_LOOKUP_RIDS *q_r, prs_struct *ps, int depth)
+
+void init_q_lookup_names(TALLOC_CTX *mem_ctx, LSA_Q_LOOKUP_NAMES *q_l, 
+                        POLICY_HND *hnd, int num_names, const char **names)
 {
        int i;
 
-       if (q_r == NULL) return;
+       DEBUG(5, ("init_q_lookup_names\n"));
 
-       prs_debug(ps, depth, desc, "lsa_io_q_lookup_rids");
-       depth++;
-
-       prs_align(ps);
-       
-       smb_io_pol_hnd("", &(q_r->pol), ps, depth); /* policy handle */
+       ZERO_STRUCTP(q_l);
 
-       prs_uint32("num_entries    ", ps, depth, &(q_r->num_entries));
-       prs_uint32("num_entries2   ", ps, depth, &(q_r->num_entries2));
-       prs_uint32("buffer_dom_sid ", ps, depth, &(q_r->buffer_dom_sid)); /* undocumented domain SID buffer pointer */
-       prs_uint32("buffer_dom_name", ps, depth, &(q_r->buffer_dom_name)); /* undocumented domain name buffer pointer */
+       q_l->pol = *hnd;
+       q_l->num_entries = num_names;
+       q_l->num_entries2 = num_names;
+       q_l->lookup_level = 1;
 
-       SMB_ASSERT_ARRAY(q_r->lookup_name, q_r->num_entries);
+       if ((q_l->uni_name = (UNISTR2 *)talloc_zero(
+               mem_ctx, num_names * sizeof(UNISTR2))) == NULL) {
+               DEBUG(3, ("init_q_lookup_names(): out of memory\n"));
+               return;
+       }
 
-       for (i = 0; i < q_r->num_entries; i++)
-       {
-               smb_io_dom_name("", &(q_r->lookup_name[i]), ps, depth); /* names to be looked up */
+       if ((q_l->hdr_name = (UNIHDR *)talloc_zero(
+               mem_ctx, num_names * sizeof(UNIHDR))) == NULL) {
+               DEBUG(3, ("init_q_lookup_names(): out of memory\n"));
+               return;
        }
 
-       prs_uint8s (False, "undoc          ", ps, depth, q_r->undoc, UNKNOWN_LEN);
+       for (i = 0; i < num_names; i++) {
+               int len;
+               len = strlen(names[i]);
+
+               init_uni_hdr(&q_l->hdr_name[i], len);
+               init_unistr2(&q_l->uni_name[i], names[i], len);
+       }
 }
 
 /*******************************************************************
 reads or writes a structure.
 ********************************************************************/
-void lsa_io_r_lookup_rids(char *desc,  LSA_R_LOOKUP_RIDS *r_r, prs_struct *ps, int depth)
+
+BOOL lsa_io_q_lookup_names(char *desc, LSA_Q_LOOKUP_NAMES *q_r, 
+                          prs_struct *ps, int depth)
 {
        int i;
 
-       if (r_r == NULL) return;
-
-       prs_debug(ps, depth, desc, "lsa_io_r_lookup_rids");
+       prs_debug(ps, depth, desc, "lsa_io_q_lookup_names");
        depth++;
 
-       prs_align(ps);
-       
-       lsa_io_dom_r_ref("", &(r_r->dom_ref), ps, depth); /* domain reference info */
-
-       prs_uint32("num_entries ", ps, depth, &(r_r->num_entries));
-       prs_uint32("undoc_buffer", ps, depth, &(r_r->undoc_buffer));
-       prs_uint32("num_entries2", ps, depth, &(r_r->num_entries2));
-
-       SMB_ASSERT_ARRAY(r_r->dom_rid, r_r->num_entries2);
+       if(!prs_align(ps))
+               return False;
+
+       if(!smb_io_pol_hnd("", &q_r->pol, ps, depth)) /* policy handle */
+               return False;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_uint32("num_entries    ", ps, depth, &q_r->num_entries))
+               return False;
+       if(!prs_uint32("num_entries2   ", ps, depth, &q_r->num_entries2))
+               return False;
+
+       if (UNMARSHALLING(ps)) {
+               if (q_r->num_entries) {
+                       if ((q_r->hdr_name = (UNIHDR *)prs_alloc_mem(ps,
+                                       q_r->num_entries * sizeof(UNIHDR))) == NULL)
+                               return False;
+                       if ((q_r->uni_name = (UNISTR2 *)prs_alloc_mem(ps,
+                                       q_r->num_entries * sizeof(UNISTR2))) == NULL)
+                               return False;
+               }
+       }
 
-       for (i = 0; i < r_r->num_entries2; i++)
-       {
-               smb_io_dom_rid2("", &(r_r->dom_rid[i]), ps, depth); /* domain RIDs being looked up */
+       for (i = 0; i < q_r->num_entries; i++) {
+               if(!prs_align(ps))
+                       return False;
+               if(!smb_io_unihdr("hdr_name", &q_r->hdr_name[i], ps, depth)) /* pointer names */
+                       return False;
        }
 
-       prs_uint32("num_entries3", ps, depth, &(r_r->num_entries3));
+       for (i = 0; i < q_r->num_entries; i++) {
+               if(!prs_align(ps))
+                       return False;
+               if(!smb_io_unistr2("dom_name", &q_r->uni_name[i], q_r->hdr_name[i].buffer, ps, depth)) /* names to be looked up */
+                       return False;
+       }
 
-       prs_uint32("status      ", ps, depth, &(r_r->status));
+       if(!prs_align(ps))
+               return False;
+       if(!prs_uint32("num_trans_entries ", ps, depth, &q_r->num_trans_entries))
+               return False;
+       if(!prs_uint32("ptr_trans_sids ", ps, depth, &q_r->ptr_trans_sids))
+               return False;
+       if(!prs_uint32("lookup_level   ", ps, depth, &q_r->lookup_level))
+               return False;
+       if(!prs_uint32("mapped_count   ", ps, depth, &q_r->mapped_count))
+               return False;
+
+       return True;
 }
 
-
 /*******************************************************************
-makes an LSA_Q_CLOSE structure.
+reads or writes a structure.
 ********************************************************************/
-void make_lsa_q_close(LSA_Q_CLOSE *q_c, POLICY_HND *hnd)
-{
-       if (q_c == NULL || hnd == NULL) return;
-
-       DEBUG(5,("make_lsa_q_close\n"));
-
-       memcpy(&(q_c->pol), hnd, sizeof(q_c->pol));
-}
 
-/*******************************************************************
-reads or writes an LSA_Q_CLOSE structure.
-********************************************************************/
-void lsa_io_q_close(char *desc,  LSA_Q_CLOSE *q_c, prs_struct *ps, int depth)
+BOOL lsa_io_r_lookup_names(char *desc, LSA_R_LOOKUP_NAMES *r_r, 
+                          prs_struct *ps, int depth)
 {
-       if (q_c == NULL) return;
+       int i;
 
-       prs_debug(ps, depth, desc, "lsa_io_q_close");
+       prs_debug(ps, depth, desc, "lsa_io_r_lookup_names");
        depth++;
 
-       smb_io_pol_hnd("", &(q_c->pol), ps, depth);
-}
+       if(!prs_align(ps))
+               return False;
 
-/*******************************************************************
-reads or writes an LSA_R_CLOSE structure.
-********************************************************************/
-void lsa_io_r_close(char *desc,  LSA_R_CLOSE *r_c, prs_struct *ps, int depth)
-{
-       if (r_c == NULL) return;
+       if(!prs_uint32("ptr_dom_ref", ps, depth, &r_r->ptr_dom_ref))
+               return False;
 
+       if (r_r->ptr_dom_ref != 0)
+               if(!lsa_io_dom_r_ref("", r_r->dom_ref, ps, depth))
+                       return False;
+
+       if(!prs_uint32("num_entries", ps, depth, &r_r->num_entries))
+               return False;
+       if(!prs_uint32("ptr_entries", ps, depth, &r_r->ptr_entries))
+               return False;
+
+       if (r_r->ptr_entries != 0) {
+               if(!prs_uint32("num_entries2", ps, depth, &r_r->num_entries2))
+                       return False;
+
+               if (r_r->num_entries2 != r_r->num_entries) {
+                       /* RPC fault */
+                       return False;
+               }
+
+               if (UNMARSHALLING(ps)) {
+                       if ((r_r->dom_rid = (DOM_RID2 *)prs_alloc_mem(ps, r_r->num_entries2 * sizeof(DOM_RID2)))
+                           == NULL) {
+                               DEBUG(3, ("lsa_io_r_lookup_names(): out of memory\n"));
+                               return False;
+                       }
+               }
+
+               for (i = 0; i < r_r->num_entries2; i++)
+                       if(!smb_io_dom_rid2("", &r_r->dom_rid[i], ps, depth)) /* domain RIDs being looked up */
+                               return False;
+       }
+
+       if(!prs_uint32("mapped_count", ps, depth, &r_r->mapped_count))
+               return False;
+
+       if(!prs_ntstatus("status      ", ps, depth, &r_r->status))
+               return False;
+
+       return True;
+}
+
+
+/*******************************************************************
+ Inits an LSA_Q_CLOSE structure.
+********************************************************************/
+
+void init_lsa_q_close(LSA_Q_CLOSE *q_c, POLICY_HND *hnd)
+{
+       DEBUG(5, ("init_lsa_q_close\n"));
+
+       memcpy(&q_c->pol, hnd, sizeof(q_c->pol));
+}
+
+/*******************************************************************
+ Reads or writes an LSA_Q_CLOSE structure.
+********************************************************************/
+
+BOOL lsa_io_q_close(char *desc, LSA_Q_CLOSE *q_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_close");
+       depth++;
+
+       if(!smb_io_pol_hnd("", &q_c->pol, ps, depth))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_CLOSE structure.
+********************************************************************/
+
+BOOL lsa_io_r_close(char *desc,  LSA_R_CLOSE *r_c, prs_struct *ps, int depth)
+{
        prs_debug(ps, depth, desc, "lsa_io_r_close");
        depth++;
 
-       smb_io_pol_hnd("", &(r_c->pol), ps, depth);
+       if(!smb_io_pol_hnd("", &r_c->pol, ps, depth))
+               return False;
+
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_Q_OPEN_SECRET structure.
+********************************************************************/
+
+BOOL lsa_io_q_open_secret(char *desc, LSA_Q_OPEN_SECRET *q_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_open_secret");
+       depth++;
+
+       /* Don't bother to read or write at present... */
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_OPEN_SECRET structure.
+********************************************************************/
+
+BOOL lsa_io_r_open_secret(char *desc, LSA_R_OPEN_SECRET *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_open_secret");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+   
+       if(!prs_uint32("dummy1", ps, depth, &r_c->dummy1))
+               return False;
+       if(!prs_uint32("dummy2", ps, depth, &r_c->dummy2))
+               return False;
+       if(!prs_uint32("dummy3", ps, depth, &r_c->dummy3))
+               return False;
+       if(!prs_uint32("dummy4", ps, depth, &r_c->dummy4))
+               return False;
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Inits an LSA_Q_ENUM_PRIVS structure.
+********************************************************************/
+
+void init_q_enum_privs(LSA_Q_ENUM_PRIVS *q_q, POLICY_HND *hnd, uint32 enum_context, uint32 pref_max_length)
+{
+       DEBUG(5, ("init_q_enum_privs\n"));
+
+       memcpy(&q_q->pol, hnd, sizeof(q_q->pol));
+
+       q_q->enum_context = enum_context;
+       q_q->pref_max_length = pref_max_length;
+}
+
+/*******************************************************************
+reads or writes a structure.
+********************************************************************/
+BOOL lsa_io_q_enum_privs(char *desc, LSA_Q_ENUM_PRIVS *q_q, prs_struct *ps, int depth)
+{
+       if (q_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_q_enum_privs");
+       depth++;
+
+       if (!smb_io_pol_hnd("", &q_q->pol, ps, depth))
+               return False;
+
+       if(!prs_uint32("enum_context   ", ps, depth, &q_q->enum_context))
+               return False;
+       if(!prs_uint32("pref_max_length", ps, depth, &q_q->pref_max_length))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+reads or writes a structure.
+********************************************************************/
+static BOOL lsa_io_priv_entries(char *desc, LSA_PRIV_ENTRY *entries, uint32 count, prs_struct *ps, int depth)
+{
+       uint32 i;
+
+       if (entries == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_priv_entries");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+
+       for (i = 0; i < count; i++) {
+               if (!smb_io_unihdr("", &entries[i].hdr_name, ps, depth))
+                       return False;
+               if(!prs_uint32("luid_low ", ps, depth, &entries[i].luid_low))
+                       return False;
+               if(!prs_uint32("luid_high", ps, depth, &entries[i].luid_high))
+                       return False;
+       }
+
+       for (i = 0; i < count; i++)
+               if (!smb_io_unistr2("", &entries[i].name, entries[i].hdr_name.buffer, ps, depth))
+                       return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Inits an LSA_R_ENUM_PRIVS structure.
+********************************************************************/
+
+void init_lsa_r_enum_privs(LSA_R_ENUM_PRIVS *r_u, uint32 enum_context,
+                         uint32 count, LSA_PRIV_ENTRY *entries)
+{
+       DEBUG(5, ("init_lsa_r_enum_privs\n"));
+
+       r_u->enum_context=enum_context;
+       r_u->count=count;
+       
+       if (entries!=NULL) {
+               r_u->ptr=1;
+               r_u->count1=count;
+               r_u->privs=entries;
+       } else {
+               r_u->ptr=0;
+               r_u->count1=0;
+               r_u->privs=NULL;
+       }               
+}
+
+/*******************************************************************
+reads or writes a structure.
+********************************************************************/
+BOOL lsa_io_r_enum_privs(char *desc, LSA_R_ENUM_PRIVS *r_q, prs_struct *ps, int depth)
+{
+       if (r_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_r_enum_privs");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+
+       if(!prs_uint32("enum_context", ps, depth, &r_q->enum_context))
+               return False;
+       if(!prs_uint32("count", ps, depth, &r_q->count))
+               return False;
+       if(!prs_uint32("ptr", ps, depth, &r_q->ptr))
+               return False;
+
+       if (r_q->ptr) {
+               if(!prs_uint32("count1", ps, depth, &r_q->count1))
+                       return False;
+
+               if (UNMARSHALLING(ps))
+                       if (!(r_q->privs = (LSA_PRIV_ENTRY *)prs_alloc_mem(ps, sizeof(LSA_PRIV_ENTRY) * r_q->count1)))
+                               return False;
+
+               if (!lsa_io_priv_entries("", r_q->privs, r_q->count1, ps, depth))
+                       return False;
+       }
+
+       if(!prs_align(ps))
+               return False;
+
+       if(!prs_ntstatus("status", ps, depth, &r_q->status))
+               return False;
+
+       return True;
+}
+
+void init_lsa_priv_get_dispname(LSA_Q_PRIV_GET_DISPNAME *trn, POLICY_HND *hnd, char *name, uint16 lang_id, uint16 lang_id_sys)
+{
+       int len_name = strlen(name);
+
+       if(len_name == 0)
+               len_name = 1;
+
+       memcpy(&trn->pol, hnd, sizeof(trn->pol));
+
+       init_uni_hdr(&trn->hdr_name, len_name);
+       init_unistr2(&trn->name, name, len_name);
+       trn->lang_id = lang_id;
+       trn->lang_id_sys = lang_id_sys;
+}
+
+/*******************************************************************
+reads or writes a structure.
+********************************************************************/
+BOOL lsa_io_q_priv_get_dispname(char *desc, LSA_Q_PRIV_GET_DISPNAME *q_q, prs_struct *ps, int depth)
+{
+       if (q_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_q_priv_get_dispname");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+
+       if (!smb_io_pol_hnd("", &q_q->pol, ps, depth))
+               return False;
+
+       if (!smb_io_unihdr("hdr_name", &q_q->hdr_name, ps, depth))
+               return False;
+
+       if (!smb_io_unistr2("name", &q_q->name, q_q->hdr_name.buffer, ps, depth))
+               return False;
+
+       if(!prs_uint16("lang_id    ", ps, depth, &q_q->lang_id))
+               return False;
+       if(!prs_uint16("lang_id_sys", ps, depth, &q_q->lang_id_sys))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+reads or writes a structure.
+********************************************************************/
+BOOL lsa_io_r_priv_get_dispname(char *desc, LSA_R_PRIV_GET_DISPNAME *r_q, prs_struct *ps, int depth)
+{
+       if (r_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_r_priv_get_dispname");
+       depth++;
+
+       if (!prs_align(ps))
+               return False;
 
-       prs_uint32("status", ps, depth, &(r_c->status));
+       if (!prs_uint32("ptr_info", ps, depth, &r_q->ptr_info))
+               return False;
+
+       if (r_q->ptr_info){
+               if (!smb_io_unihdr("hdr_name", &r_q->hdr_desc, ps, depth))
+                       return False;
+
+               if (!smb_io_unistr2("desc", &r_q->desc, r_q->hdr_desc.buffer, ps, depth))
+                       return False;
+       }
+/*
+       if(!prs_align(ps))
+               return False;
+*/
+       if(!prs_uint16("lang_id", ps, depth, &r_q->lang_id))
+               return False;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_ntstatus("status", ps, depth, &r_q->status))
+               return False;
+
+       return True;
+}
+
+void init_lsa_q_enum_accounts(LSA_Q_ENUM_ACCOUNTS *trn, POLICY_HND *hnd, uint32 enum_context, uint32 pref_max_length)
+{
+       memcpy(&trn->pol, hnd, sizeof(trn->pol));
+
+       trn->enum_context = enum_context;
+       trn->pref_max_length = pref_max_length;
 }
 
+/*******************************************************************
+reads or writes a structure.
+********************************************************************/
+BOOL lsa_io_q_enum_accounts(char *desc, LSA_Q_ENUM_ACCOUNTS *q_q, prs_struct *ps, int depth)
+{
+       if (q_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_q_enum_accounts");
+       depth++;
+
+       if (!smb_io_pol_hnd("", &q_q->pol, ps, depth))
+               return False;
+
+       if(!prs_uint32("enum_context   ", ps, depth, &q_q->enum_context))
+               return False;
+       if(!prs_uint32("pref_max_length", ps, depth, &q_q->pref_max_length))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Inits an LSA_R_ENUM_PRIVS structure.
+********************************************************************/
+
+void init_lsa_r_enum_accounts(LSA_R_ENUM_ACCOUNTS *r_u, uint32 enum_context)
+{
+       DEBUG(5, ("init_lsa_r_enum_accounts\n"));
+
+       r_u->enum_context=enum_context;
+       if (r_u->enum_context!=0) {
+               r_u->sids.num_entries=enum_context;
+               r_u->sids.ptr_sid_enum=1;
+               r_u->sids.num_entries2=enum_context;
+       } else {
+               r_u->sids.num_entries=0;
+               r_u->sids.ptr_sid_enum=0;
+               r_u->sids.num_entries2=0;
+       }
+}
+
+/*******************************************************************
+reads or writes a structure.
+********************************************************************/
+BOOL lsa_io_r_enum_accounts(char *desc, LSA_R_ENUM_ACCOUNTS *r_q, prs_struct *ps, int depth)
+{
+       if (r_q == NULL)
+               return False;
+
+       prs_debug(ps, depth, desc, "lsa_io_r_enum_accounts");
+       depth++;
+
+       if (!prs_align(ps))
+               return False;
+
+       if(!prs_uint32("enum_context", ps, depth, &r_q->enum_context))
+               return False;
+
+       if (!lsa_io_sid_enum("sids", &r_q->sids, ps, depth))
+               return False;
+
+       if (!prs_align(ps))
+               return False;
+
+       if(!prs_ntstatus("status", ps, depth, &r_q->status))
+               return False;
+
+       return True;
+}
+
+
+/*******************************************************************
+ Reads or writes an LSA_Q_UNK_GET_CONNUSER structure.
+********************************************************************/
+
+BOOL lsa_io_q_unk_get_connuser(char *desc, LSA_Q_UNK_GET_CONNUSER *q_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_unk_get_connuser");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+   
+       if(!prs_uint32("ptr_srvname", ps, depth, &q_c->ptr_srvname))
+               return False;
+
+       if(!smb_io_unistr2("uni2_srvname", &q_c->uni2_srvname, q_c->ptr_srvname, ps, depth)) /* server name to be looked up */
+               return False;
+
+       if (!prs_align(ps))
+         return False;
+
+       if(!prs_uint32("unk1", ps, depth, &q_c->unk1))
+               return False;
+       if(!prs_uint32("unk2", ps, depth, &q_c->unk2))
+               return False;
+       if(!prs_uint32("unk3", ps, depth, &q_c->unk3))
+               return False;
+
+       /* Don't bother to read or write at present... */
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_UNK_GET_CONNUSER structure.
+********************************************************************/
+
+BOOL lsa_io_r_unk_get_connuser(char *desc, LSA_R_UNK_GET_CONNUSER *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_unk_get_connuser");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+   
+       if(!prs_uint32("ptr_user_name", ps, depth, &r_c->ptr_user_name))
+               return False;
+       if(!smb_io_unihdr("hdr_user_name", &r_c->hdr_user_name, ps, depth))
+               return False;
+       if(!smb_io_unistr2("uni2_user_name", &r_c->uni2_user_name, r_c->ptr_user_name, ps, depth))
+               return False;
+
+       if (!prs_align(ps))
+         return False;
+       
+       if(!prs_uint32("unk1", ps, depth, &r_c->unk1))
+               return False;
+
+       if(!prs_uint32("ptr_dom_name", ps, depth, &r_c->ptr_dom_name))
+               return False;
+       if(!smb_io_unihdr("hdr_dom_name", &r_c->hdr_dom_name, ps, depth))
+               return False;
+       if(!smb_io_unistr2("uni2_dom_name", &r_c->uni2_dom_name, r_c->ptr_dom_name, ps, depth))
+               return False;
+
+       if (!prs_align(ps))
+         return False;
+       
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+void init_lsa_q_open_account(LSA_Q_OPENACCOUNT *trn, POLICY_HND *hnd, DOM_SID *sid, uint32 desired_access)
+{
+       memcpy(&trn->pol, hnd, sizeof(trn->pol));
+
+       init_dom_sid2(&trn->sid, sid);
+       trn->access = desired_access;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_Q_OPENACCOUNT structure.
+********************************************************************/
+
+BOOL lsa_io_q_open_account(char *desc, LSA_Q_OPENACCOUNT *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_open_account");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+
+       if(!smb_io_dom_sid2("sid", &r_c->sid, ps, depth)) /* domain SID */
+               return False;
+
+       if(!prs_uint32("access", ps, depth, &r_c->access))
+               return False;
+  
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_OPENACCOUNT structure.
+********************************************************************/
+
+BOOL lsa_io_r_open_account(char *desc, LSA_R_OPENACCOUNT  *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_open_account");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+
+void init_lsa_q_enum_privsaccount(LSA_Q_ENUMPRIVSACCOUNT *trn, POLICY_HND *hnd)
+{
+       memcpy(&trn->pol, hnd, sizeof(trn->pol));
+
+}
+
+/*******************************************************************
+ Reads or writes an LSA_Q_ENUMPRIVSACCOUNT structure.
+********************************************************************/
+
+BOOL lsa_io_q_enum_privsaccount(char *desc, LSA_Q_ENUMPRIVSACCOUNT *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_enum_privsaccount");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LUID structure.
+********************************************************************/
+
+static BOOL lsa_io_luid(char *desc, LUID *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_luid");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_uint32("low", ps, depth, &r_c->low))
+               return False;
+
+       if(!prs_uint32("high", ps, depth, &r_c->high))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LUID_ATTR structure.
+********************************************************************/
+
+static BOOL lsa_io_luid_attr(char *desc, LUID_ATTR *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_luid_attr");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if (!lsa_io_luid(desc, &r_c->luid, ps, depth))
+               return False;
+
+       if(!prs_uint32("attr", ps, depth, &r_c->attr))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an PRIVILEGE_SET structure.
+********************************************************************/
+
+static BOOL lsa_io_privilege_set(char *desc, PRIVILEGE_SET *r_c, prs_struct *ps, int depth)
+{
+       uint32 i;
+
+       prs_debug(ps, depth, desc, "lsa_io_privilege_set");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_uint32("count", ps, depth, &r_c->count))
+               return False;
+       if(!prs_uint32("control", ps, depth, &r_c->control))
+               return False;
+
+       for (i=0; i<r_c->count; i++) {
+               if (!lsa_io_luid_attr(desc, &r_c->set[i], ps, depth))
+                       return False;
+       }
+       
+       return True;
+}
+
+void init_lsa_r_enum_privsaccount(LSA_R_ENUMPRIVSACCOUNT *r_u, LUID_ATTR *set, uint32 count, uint32 control)
+{
+       r_u->ptr=1;
+       r_u->count=count;
+       r_u->set.set=set;
+       r_u->set.count=count;
+       r_u->set.control=control;
+       DEBUG(10,("init_lsa_r_enum_privsaccount: %d %d privileges\n", r_u->count, r_u->set.count));
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_ENUMPRIVSACCOUNT structure.
+********************************************************************/
+
+BOOL lsa_io_r_enum_privsaccount(char *desc, LSA_R_ENUMPRIVSACCOUNT *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_enum_privsaccount");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_uint32("ptr", ps, depth, &r_c->ptr))
+               return False;
+
+       if (r_c->ptr!=0) {
+               if(!prs_uint32("count", ps, depth, &r_c->count))
+                       return False;
+
+               /* malloc memory if unmarshalling here */
+
+               if (UNMARSHALLING(ps) && r_c->count!=0) {
+                       if (!(r_c->set.set = (LUID_ATTR *)prs_alloc_mem(ps,sizeof(LUID_ATTR) * r_c->count)))
+                               return False;
+
+               }
+               
+               if(!lsa_io_privilege_set(desc, &r_c->set, ps, depth))
+                       return False;
+       }
+
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+
+
+/*******************************************************************
+ Reads or writes an  LSA_Q_GETSYSTEMACCOUNTstructure.
+********************************************************************/
+
+BOOL lsa_io_q_getsystemaccount(char *desc, LSA_Q_GETSYSTEMACCOUNT  *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_getsystemaccount");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an  LSA_R_GETSYSTEMACCOUNTstructure.
+********************************************************************/
+
+BOOL lsa_io_r_getsystemaccount(char *desc, LSA_R_GETSYSTEMACCOUNT  *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_getsystemaccount");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_uint32("access", ps, depth, &r_c->access))
+               return False;
+
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+
+/*******************************************************************
+ Reads or writes an LSA_Q_SETSYSTEMACCOUNT structure.
+********************************************************************/
+
+BOOL lsa_io_q_setsystemaccount(char *desc, LSA_Q_SETSYSTEMACCOUNT  *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_setsystemaccount");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+
+       if(!prs_uint32("access", ps, depth, &r_c->access))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_SETSYSTEMACCOUNT structure.
+********************************************************************/
+
+BOOL lsa_io_r_setsystemaccount(char *desc, LSA_R_SETSYSTEMACCOUNT  *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_setsystemaccount");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+
+void init_lsa_q_lookupprivvalue(LSA_Q_LOOKUPPRIVVALUE *trn, POLICY_HND *hnd, char *name)
+{
+       int len_name = strlen(name);
+       memcpy(&trn->pol, hnd, sizeof(trn->pol));
+
+       if(len_name == 0)
+               len_name = 1;
+
+       init_uni_hdr(&trn->hdr_right, len_name);
+       init_unistr2(&trn->uni2_right, name, len_name);
+}
+
+/*******************************************************************
+ Reads or writes an LSA_Q_LOOKUPPRIVVALUE  structure.
+********************************************************************/
+
+BOOL lsa_io_q_lookupprivvalue(char *desc, LSA_Q_LOOKUPPRIVVALUE  *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_lookupprivvalue");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+       if(!smb_io_unihdr ("hdr_name", &r_c->hdr_right, ps, depth))
+               return False;
+       if(!smb_io_unistr2("uni2_right", &r_c->uni2_right, r_c->hdr_right.buffer, ps, depth))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an  LSA_R_LOOKUPPRIVVALUE structure.
+********************************************************************/
+
+BOOL lsa_io_r_lookupprivvalue(char *desc, LSA_R_LOOKUPPRIVVALUE  *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_lookupprivvalue");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+               
+       if(!lsa_io_luid("luid", &r_c->luid, ps, depth))
+               return False;
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+
+/*******************************************************************
+ Reads or writes an LSA_Q_ADDPRIVS structure.
+********************************************************************/
+
+BOOL lsa_io_q_addprivs(char *desc, LSA_Q_ADDPRIVS *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_addprivs");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+       
+       if(!prs_uint32("count", ps, depth, &r_c->count))
+               return False;
+
+       if (UNMARSHALLING(ps) && r_c->count!=0) {
+               if (!(r_c->set.set = (LUID_ATTR *)prs_alloc_mem(ps,sizeof(LUID_ATTR) * r_c->count)))
+                       return False;
+       }
+       
+       if(!lsa_io_privilege_set(desc, &r_c->set, ps, depth))
+               return False;
+       
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_ADDPRIVS structure.
+********************************************************************/
+
+BOOL lsa_io_r_addprivs(char *desc, LSA_R_ADDPRIVS *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_addprivs");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_Q_REMOVEPRIVS structure.
+********************************************************************/
+
+BOOL lsa_io_q_removeprivs(char *desc, LSA_Q_REMOVEPRIVS *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_q_removeprivs");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!smb_io_pol_hnd("pol", &r_c->pol, ps, depth))
+               return False;
+       
+       if(!prs_uint32("allrights", ps, depth, &r_c->allrights))
+               return False;
+
+       if(!prs_uint32("ptr", ps, depth, &r_c->ptr))
+               return False;
+
+       /* 
+        * JFM: I'm not sure at all if the count is inside the ptr
+        * never seen one with ptr=0
+        */
+
+       if (r_c->ptr!=0) {
+               if(!prs_uint32("count", ps, depth, &r_c->count))
+                       return False;
+
+               if (UNMARSHALLING(ps) && r_c->count!=0) {
+                       if (!(r_c->set.set = (LUID_ATTR *)prs_alloc_mem(ps,sizeof(LUID_ATTR) * r_c->count)))
+                               return False;
+               }
+
+               if(!lsa_io_privilege_set(desc, &r_c->set, ps, depth))
+                       return False;
+       }
+
+       return True;
+}
+
+/*******************************************************************
+ Reads or writes an LSA_R_REMOVEPRIVS structure.
+********************************************************************/
+
+BOOL lsa_io_r_removeprivs(char *desc, LSA_R_REMOVEPRIVS *r_c, prs_struct *ps, int depth)
+{
+       prs_debug(ps, depth, desc, "lsa_io_r_removeprivs");
+       depth++;
+
+       if(!prs_align(ps))
+               return False;
+       if(!prs_ntstatus("status", ps, depth, &r_c->status))
+               return False;
+
+       return True;
+}
+
+BOOL policy_handle_is_valid(const POLICY_HND *hnd)
+{
+       POLICY_HND zero_pol;
+
+       ZERO_STRUCT(zero_pol);
+       return ((memcmp(&zero_pol, hnd, sizeof(POLICY_HND)) == 0) ? False : True );
+}