Clarify use of manual parsers in trustInOutBlob (drsblobs.idl)
[kai/samba.git] / source4 / librpc / idl / drsblobs.idl
index 27f3a9955155044f5c904502f3f2f932ded13e5d..4274d2000a10f2d6ab6bc7bcfc3a728f310fb7a8 100644 (file)
@@ -1,6 +1,6 @@
 #include "idl_types.h"
 
-import "drsuapi.idl";
+import "drsuapi.idl", "misc.idl", "samr.idl", "lsa.idl";
 
 [
   uuid("12345778-1234-abcd-0001-00000001"),
@@ -12,7 +12,7 @@ interface drsblobs {
        typedef bitmap drsuapi_DsReplicaSyncOptions drsuapi_DsReplicaSyncOptions;
        typedef bitmap drsuapi_DsReplicaNeighbourFlags drsuapi_DsReplicaNeighbourFlags;
        typedef [v1_enum] enum drsuapi_DsAttributeId drsuapi_DsAttributeId;
-
+       typedef [v1_enum] enum lsa_TrustAuthType lsa_TrustAuthType;
        /*
         * replPropertyMetaData
         * w2k  uses version 1
@@ -91,7 +91,7 @@ interface drsblobs {
 
        typedef [public,gensize,flag(NDR_PAHEX)] struct {
                /* this includes the 8 bytes of the repsFromToBlob header */
-               [value(ndr_size_repsFromTo1(r, ndr->flags)+8)] uint32 blobsize;
+               [value(ndr_size_repsFromTo1(this, ndr->flags)+8)] uint32 blobsize;
                uint32 consecutive_sync_failures;
                NTTIME_1sec last_success;
                NTTIME_1sec last_attempt;
@@ -205,7 +205,7 @@ interface drsblobs {
        typedef struct {
                [value(2*strlen_m(name))] uint16 name_len;
                [value(strlen(data))] uint16 data_len;
-               uint16 unknown1; /* 2 for name = 'Packages', 1 for name = 'Primary:*' */
+               uint16 reserved; /* 2 for 'Packages', 1 for 'Primary:*', but should be ignored */
                [charset(UTF16)] uint8 name[name_len];
                /* 
                 * the data field contains data as HEX strings
@@ -215,6 +215,9 @@ interface drsblobs {
                 *   as non termiated UTF16 strings with
                 *   a UTF16 NULL byte as separator
                 *
+                * 'Primary:Kerberos-Newer-Keys':
+                *    ...
+                *
                 * 'Primary:Kerberos':
                 *    ...
                 *
@@ -228,11 +231,16 @@ interface drsblobs {
                [charset(DOS)] uint8 data[data_len];
        } supplementalCredentialsPackage;
 
-       /* this are 0x30 (48) whitespaces (0x20) followed by 'P' (0x50) */
-       const string SUPPLEMENTAL_CREDENTIALS_PREFIX = "                                                P";
+       /* this are 0x30 (48) whitespaces (0x20) */
+       const string SUPPLEMENTAL_CREDENTIALS_PREFIX = "                                                ";
+
+       typedef [flag(NDR_PAHEX)] enum {
+               SUPPLEMENTAL_CREDENTIALS_SIGNATURE = 0x0050
+       } supplementalCredentialsSignature;
 
        typedef [gensize] struct {
-               [value(SUPPLEMENTAL_CREDENTIALS_PREFIX),charset(UTF16)] uint16 prefix[0x31];
+               [value(SUPPLEMENTAL_CREDENTIALS_PREFIX),charset(UTF16)] uint16 prefix[0x30];
+               [value(SUPPLEMENTAL_CREDENTIALS_SIGNATURE)] supplementalCredentialsSignature signature;
                uint16 num_packages;
                supplementalCredentialsPackage packages[num_packages];
        } supplementalCredentialsSubBlob;
@@ -264,31 +272,58 @@ interface drsblobs {
        } package_PrimaryKerberosString;
 
        typedef struct {
+               [value(0)] uint16 reserved1;
+               [value(0)] uint16 reserved2;
+               [value(0)] uint32 reserved3;
                uint32 keytype;
                [value((value?value->length:0))] uint32 value_len;
                [relative,subcontext(0),subcontext_size(value_len),flag(NDR_REMAINING)] DATA_BLOB *value;
-               [value(0)] uint32 unknown1;
-               [value(0)] uint32 unknown2;
-       } package_PrimaryKerberosKey;
+       } package_PrimaryKerberosKey3;
 
        typedef struct {
                uint16 num_keys;
                uint16 num_old_keys;
                package_PrimaryKerberosString salt;
-               [value(0)] uint32 unknown1;
-               [value(0)] uint32 unknown2;
-               package_PrimaryKerberosKey keys[num_keys];
-               package_PrimaryKerberosKey old_keys[num_old_keys];
-               udlong unknown3[num_keys];
-               udlong unknown3_old[num_old_keys];
+               package_PrimaryKerberosKey3 keys[num_keys];
+               package_PrimaryKerberosKey3 old_keys[num_old_keys];
+               [value(0)] uint32 padding1;
+               [value(0)] uint32 padding2;
+               [value(0)] uint32 padding3;
+               [value(0)] uint32 padding4;
+               [value(0)] uint32 padding5;
        } package_PrimaryKerberosCtr3;
 
+       typedef struct {
+               [value(0)] uint16 reserved1;
+               [value(0)] uint16 reserved2;
+               [value(0)] uint32 reserved3;
+               uint32 iteration_count;
+               uint32 keytype;
+               [value((value?value->length:0))] uint32 value_len;
+               [relative,subcontext(0),subcontext_size(value_len),flag(NDR_REMAINING)] DATA_BLOB *value;
+       } package_PrimaryKerberosKey4;
+
+       typedef struct {
+               uint16 num_keys;
+               [value(0)] uint16 num_service_keys;
+               uint16 num_old_keys;
+               uint16 num_older_keys;
+               package_PrimaryKerberosString salt;
+               uint32 default_iteration_count;
+               package_PrimaryKerberosKey4 keys[num_keys];
+               package_PrimaryKerberosKey4 service_keys[num_service_keys];
+               package_PrimaryKerberosKey4 old_keys[num_old_keys];
+               package_PrimaryKerberosKey4 older_keys[num_older_keys];
+       } package_PrimaryKerberosCtr4;
+
        typedef [nodiscriminant] union {
                [case(3)] package_PrimaryKerberosCtr3 ctr3;
+               [case(4)] package_PrimaryKerberosCtr4 ctr4;
        } package_PrimaryKerberosCtr;
 
        typedef [public] struct {
-               [value(3)] uint32 version;
+               uint16 version;
+               [value(0)] uint16 flags;
                [switch_is(version)] package_PrimaryKerberosCtr ctr;
        } package_PrimaryKerberosBlob;
 
@@ -322,80 +357,165 @@ interface drsblobs {
                );
 
        typedef struct {
-               NTTIME time1;
-               uint32 unknown1;
-               /* 
-                * the secret value is encoded as UTF16 if it's a string
-                * but krb5 trusts have random bytes here, so converting to UTF16
-                * mayfail...
-                *
-                * TODO: We should try handle the case of a random buffer in all places
-                *       we deal with cleartext passwords from windows
-                *
-                * so we don't use this:
-                *
-                * uint32 value_len;
-                * [charset(UTF16)] uint8 value[value_len];
-                */
-               DATA_BLOB value;
-               [flag(NDR_ALIGN4)] DATA_BLOB _pad;
-       } trustAuthInOutSecret1;
-
-       typedef struct {
-               [relative] trustAuthInOutSecret1 *value1;
-               [relative] trustAuthInOutSecret1 *value2;
-       } trustAuthInOutCtr1;
+               [value(0)] uint32 size;
+       } AuthInfoNone;
 
        typedef struct {
-               NTTIME time1;
-               uint32 unknown1;
-               DATA_BLOB value;
-               NTTIME time2;
-               uint32 unknown2;
-               uint32 unknown3;
-               uint32 unknown4;
-               [flag(NDR_ALIGN4)] DATA_BLOB _pad;
-       } trustAuthInOutSecret2V1;
+               [value(16)] uint32 size;
+               samr_Password password;
+       } AuthInfoNT4Owf;
+
+       /* 
+        * the secret value is encoded as UTF16 if it's a string
+        * but depending the AuthType, it might also be krb5 trusts have random bytes here, so converting to UTF16
+        * mayfail...
+        *
+        * TODO: We should try handle the case of a random buffer in all places
+        *       we deal with cleartext passwords from windows
+        *
+        * so we don't use this:
+        *
+        * uint32 value_len;
+        * [charset(UTF16)] uint8 value[value_len];
+        */
 
        typedef struct {
-               NTTIME time1;
-               uint32 unknown1;
-               DATA_BLOB value;
-               NTTIME time2;
-               uint32 unknown2;
-               uint32 unknown3;
-               [flag(NDR_ALIGN4)] DATA_BLOB _pad;
-       } trustAuthInOutSecret2V2;
+               uint32 size;
+               uint8 password[size];
+       } AuthInfoClear;
 
        typedef struct {
-               [relative] trustAuthInOutSecret2V1 *value1;
-               [relative] trustAuthInOutSecret2V2 *value2;
-       } trustAuthInOutCtr2;
+               [value(4)] uint32 size;
+                uint32 version;
+       } AuthInfoVersion;
 
        typedef [nodiscriminant] union {
-               [case(1)] trustAuthInOutCtr1 ctr1;
-               [case(2)] trustAuthInOutCtr2 ctr2;
-       } trustAuthInOutCtr;
+               [case(TRUST_AUTH_TYPE_NONE)] AuthInfoNone none;
+               [case(TRUST_AUTH_TYPE_NT4OWF)] AuthInfoNT4Owf nt4owf;
+               [case(TRUST_AUTH_TYPE_CLEAR)] AuthInfoClear clear;
+               [case(TRUST_AUTH_TYPE_VERSION)] AuthInfoVersion version;
+       } AuthInfo;
 
        typedef [public] struct {
-               uint32 version;
-               [switch_is(version)] trustAuthInOutCtr ctr;
+               NTTIME LastUpdateTime;
+               lsa_TrustAuthType AuthType;
+               
+               [switch_is(AuthType)] AuthInfo AuthInfo;
+               [flag(NDR_ALIGN4)] DATA_BLOB _pad;
+       } AuthenticationInformation;
+
+       typedef [nopull,nopush,noprint] struct {
+               /* sizeis here is bogus, but this is here just for the structure */
+               [size_is(1)] AuthenticationInformation array[];
+       } AuthenticationInformationArray;
+
+       /* This is nopull,nopush because we pass count down to the
+        * manual parser of AuthenticationInformationArray */
+       typedef [public,nopull,nopush,noprint,gensize] struct {
+               uint32 count;
+               [relative] AuthenticationInformationArray *current;
+               [relative] AuthenticationInformationArray *previous;
        } trustAuthInOutBlob;
 
        void decode_trustAuthInOut(
                [in] trustAuthInOutBlob blob
                );
 
+       typedef [public,gensize] struct {
+               uint32 count;
+               [relative] AuthenticationInformation *current[count];
+       } trustCurrentPasswords;
+
+       typedef [public,nopull] struct {
+               uint8 confounder[512];
+               [subcontext(0),subcontext_size(outgoing_size)] trustCurrentPasswords outgoing;
+               [subcontext(0),subcontext_size(incoming_size)] trustCurrentPasswords incoming;
+               [value(ndr_size_trustCurrentPasswords(&outgoing, ndr->flags))] uint32 outgoing_size;
+               [value(ndr_size_trustCurrentPasswords(&incoming, ndr->flags))] uint32 incoming_size;
+       } trustDomainPasswords;
+
+       void decode_trustDomainPasswords(
+               [in] trustDomainPasswords blob
+               );
+
        typedef [public] struct {
                uint32 marker;
                DATA_BLOB data;
        } DsCompressedChunk;
 
+       typedef struct {
+               uint16 __size;
+               [size_is(__size),charset(DOS)] uint8 *string;
+       } ExtendedErrorAString;
+
+       typedef struct {
+               uint16 __size;
+               [size_is(__size),charset(UTF16)] uint16 *string;
+       } ExtendedErrorUString;
+
+       typedef struct {
+               uint16 length;
+               [size_is(length)] uint8 *data;
+       } ExtendedErrorBlob;
+
+       typedef enum {
+               EXTENDED_ERROR_COMPUTER_NAME_PRESENT    = 1,
+               EXTENDED_ERROR_COMPUTER_NAME_NOT_PRESENT= 2
+       } ExtendedErrorComputerNamePresent;
+
+       typedef [switch_type(ExtendedErrorComputerNamePresent)] union {
+       [case(EXTENDED_ERROR_COMPUTER_NAME_PRESENT)] ExtendedErrorUString name;
+       [case(EXTENDED_ERROR_COMPUTER_NAME_NOT_PRESENT)];
+       } ExtendedErrorComputerNameU;
+
+       typedef struct {
+               ExtendedErrorComputerNamePresent present;
+               [switch_is(present)] ExtendedErrorComputerNameU n;
+       } ExtendedErrorComputerName;
+
+       typedef enum {
+               EXTENDED_ERROR_PARAM_TYPE_ASCII_STRING          = 1,
+               EXTENDED_ERROR_PARAM_TYPE_UNICODE_STRING        = 2,
+               EXTENDED_ERROR_PARAM_TYPE_UINT32                = 3,
+               EXTENDED_ERROR_PARAM_TYPE_UINT16                = 4,
+               EXTENDED_ERROR_PARAM_TYPE_UINT64                = 5,
+               EXTENDED_ERROR_PARAM_TYPE_NONE                  = 6,
+               EXTENDED_ERROR_PARAM_TYPE_BLOB                  = 7
+       } ExtendedErrorParamType;
+
+       typedef [switch_type(ExtendedErrorParamType)] union {
+       [case(EXTENDED_ERROR_PARAM_TYPE_ASCII_STRING)] ExtendedErrorAString a_string;
+       [case(EXTENDED_ERROR_PARAM_TYPE_UNICODE_STRING)] ExtendedErrorUString u_string;
+       [case(EXTENDED_ERROR_PARAM_TYPE_UINT32)] uint32 uint32;
+       [case(EXTENDED_ERROR_PARAM_TYPE_UINT16)] uint16 uint16;
+       [case(EXTENDED_ERROR_PARAM_TYPE_UINT64)] hyper uint64;
+       [case(EXTENDED_ERROR_PARAM_TYPE_NONE)];
+       [case(EXTENDED_ERROR_PARAM_TYPE_BLOB)] ExtendedErrorBlob blob;
+       } ExtendedErrorParamU;
+
+       typedef struct {
+               ExtendedErrorParamType type;
+               [switch_is(type)] ExtendedErrorParamU p;
+       } ExtendedErrorParam;
+
        typedef [public] struct {
-               DsCompressedChunk chunks[5];
-       } DsCompressedBlob;
+               ExtendedErrorInfo *next;
+               ExtendedErrorComputerName computer_name;
+               hyper pid;
+               NTTIME time;
+               uint32 generating_component;
+               WERROR status;
+               uint16 detection_location;
+               uint16 flags;
+               uint16 num_params;
+               [size_is(num_params)] ExtendedErrorParam params[];
+       } ExtendedErrorInfo;
+
+       typedef struct {
+               [unique] ExtendedErrorInfo *info;
+       } ExtendedErrorInfoPtr;
 
-       void decode_DsCompressed(
-               [in] DsCompressedBlob blob
+       void decode_ExtendedErrorInfo (
+               [in,subcontext(0xFFFFFC01)] ExtendedErrorInfoPtr ptr
                );
 }