2 Unix SMB/CIFS implementation.
3 Copyright (C) Jelmer Vernooij <jelmer@samba.org> 2007
5 This program is free software; you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation; either version 3 of the License, or
8 (at your option) any later version.
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 GNU General Public License for more details.
15 You should have received a copy of the GNU General Public License
16 along with this program. If not, see <http://www.gnu.org/licenses/>.
19 %module(docstring="Security-related classes.",package="samba.security") security
23 #include "libcli/security/security.h"
25 typedef struct dom_sid dom_sid;
26 typedef struct security_token security_token;
27 typedef struct security_descriptor security_descriptor;
30 %import "../lib/talloc/talloc.i"
32 #include "libcli/util/pyerrors.h"
35 %typemap(out,noblock=1) WERROR {
36 if (!W_ERROR_IS_OK($1)) {
39 } else if ($result == NULL) {
44 %typemap(out,noblock=1) NTSTATUS {
45 if (NT_STATUS_IS_ERR($1)) {
46 PyErr_SetNTSTATUS($1);
48 } else if ($result == NULL) {
53 %typemap(in,noblock=1) NTSTATUS {
54 if (PyLong_Check($input))
55 $1 = NT_STATUS(PyLong_AsUnsignedLong($input));
56 else if (PyInt_Check($input))
57 $1 = NT_STATUS(PyInt_AsLong($input));
59 PyErr_SetString(PyExc_TypeError, "Expected a long or an int");
70 SEC_PRIV_SYSTEMTIME=4,
72 SEC_PRIV_REMOTE_SHUTDOWN=6,
73 SEC_PRIV_TAKE_OWNERSHIP=7,
75 SEC_PRIV_SYSTEM_ENVIRONMENT=9,
76 SEC_PRIV_SYSTEM_PROFILE=10,
77 SEC_PRIV_PROFILE_SINGLE_PROCESS=11,
78 SEC_PRIV_INCREASE_BASE_PRIORITY=12,
79 SEC_PRIV_LOAD_DRIVER=13,
80 SEC_PRIV_CREATE_PAGEFILE=14,
81 SEC_PRIV_INCREASE_QUOTA=15,
82 SEC_PRIV_CHANGE_NOTIFY=16,
84 SEC_PRIV_MANAGE_VOLUME=18,
85 SEC_PRIV_IMPERSONATE=19,
86 SEC_PRIV_CREATE_GLOBAL=20,
87 SEC_PRIV_ENABLE_DELEGATION=21,
88 SEC_PRIV_INTERACTIVE_LOGON=22,
89 SEC_PRIV_NETWORK_LOGON=23,
90 SEC_PRIV_REMOTE_INTERACTIVE_LOGON=24
93 %rename(SecurityToken) security_token;
95 %talloctype(security_token);
97 typedef struct security_token {
99 security_token(TALLOC_CTX *mem_ctx) { return security_token_initialise(mem_ctx); }
100 %feature("docstring") is_sid "S.is_sid(sid) -> bool\n" \
101 "Check whether this token is of the specified SID.";
102 bool is_sid(const struct dom_sid *sid);
103 %feature("docstring") is_system "S.is_system() -> bool\n" \
104 "Check whether this is a system token.";
106 %feature("docstring") is_anonymous "S.is_anonymus() -> bool\n" \
107 "Check whether this is an anonymous token.";
109 bool has_sid(const struct dom_sid *sid);
110 bool has_builtin_administrators();
111 bool has_nt_authenticated_users();
112 bool has_privilege(enum sec_privilege privilege);
113 void set_privilege(enum sec_privilege privilege);
117 %talloctype(security_descriptor);
119 typedef struct security_descriptor {
121 security_descriptor(TALLOC_CTX *mem_ctx) { return security_descriptor_initialise(mem_ctx); }
122 %feature("docstring") sacl_add "S.sacl_add(ace) -> None\n" \
123 "Add a security ace to this security descriptor";
124 NTSTATUS sacl_add(const struct security_ace *ace);
125 NTSTATUS dacl_add(const struct security_ace *ace);
126 NTSTATUS dacl_del(const struct dom_sid *trustee);
127 NTSTATUS sacl_del(const struct dom_sid *trustee);
129 %rename(__eq__) equal;
131 bool equal(const struct security_descriptor *other);
133 } security_descriptor;
135 %rename(Sid) dom_sid;
137 %talloctype(dom_sid);
139 typedef struct dom_sid {
142 int8_t num_auths;/* [range(0,15)] */
147 dom_sid(TALLOC_CTX *mem_ctx, const char *text) {
148 return dom_sid_parse_talloc(mem_ctx, text);
151 const char *__str__(TALLOC_CTX *mem_ctx) {
152 return dom_sid_string(mem_ctx, $self);
154 %rename(__eq__) equal;
156 bool equal(const struct dom_sid *other);
160 return "Sid(%r)" % str(self)
164 %feature("docstring") random_sid "random_sid() -> sid\n" \
165 "Generate a random SID";
168 static struct dom_sid *random_sid(TALLOC_CTX *mem_ctx)
170 char *str = talloc_asprintf(mem_ctx, "S-1-5-21-%u-%u-%u",
171 (unsigned)generate_random(),
172 (unsigned)generate_random(),
173 (unsigned)generate_random());
175 return dom_sid_parse_talloc(mem_ctx, str);
179 %rename(privilege_name) sec_privilege_name;
180 const char *sec_privilege_name(enum sec_privilege privilege);
181 %rename(privilege_id) sec_privilege_id;
182 enum sec_privilege sec_privilege_id(const char *name);