57840a4c06d5aa364dc85e2838b7c0b0c6998fd2
[nivanova/samba-autobuild/.git] / source3 / libgpo / gpext / registry.c
1 /*
2  *  Unix SMB/CIFS implementation.
3  *  Group Policy Support
4  *  Copyright (C) Guenther Deschner 2007-2008
5  *
6  *  This program is free software; you can redistribute it and/or modify
7  *  it under the terms of the GNU General Public License as published by
8  *  the Free Software Foundation; either version 3 of the License, or
9  *  (at your option) any later version.
10  *
11  *  This program is distributed in the hope that it will be useful,
12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  *  GNU General Public License for more details.
15  *
16  *  You should have received a copy of the GNU General Public License
17  *  along with this program; if not, see <http://www.gnu.org/licenses/>.
18  */
19
20 #include "includes.h"
21 #include "../libgpo/gpo_ini.h"
22 #include "../libgpo/gpo.h"
23 #include "libgpo/gpo_proto.h"
24 #include "registry.h"
25
26 #define GP_EXT_NAME "registry"
27
28 /* more info can be found at:
29  * http://msdn2.microsoft.com/en-us/library/aa374407.aspx */
30
31 #define GP_REGPOL_FILE  "Registry.pol"
32
33 #define GP_REGPOL_FILE_SIGNATURE 0x67655250 /* 'PReg' */
34 #define GP_REGPOL_FILE_VERSION 1
35
36 static TALLOC_CTX *ctx = NULL;
37
38 struct gp_registry_file_header {
39         uint32_t signature;
40         uint32_t version;
41 };
42
43 struct gp_registry_file_entry {
44         UNISTR key;
45         UNISTR value;
46         enum winreg_Type type;
47         size_t size;
48         uint8_t *data;
49 };
50
51 struct gp_registry_file {
52         struct gp_registry_file_header header;
53         size_t num_entries;
54         struct gp_registry_entry *entries;
55 };
56
57 /****************************************************************
58 ****************************************************************/
59
60 static bool reg_parse_header(const char *desc,
61                              struct gp_registry_file_header *header,
62                              prs_struct *ps,
63                              int depth)
64 {
65         if (!header)
66                 return false;
67
68         prs_debug(ps, depth, desc, "reg_parse_header");
69         depth++;
70
71         if (!prs_uint32("signature", ps, depth, &header->signature))
72                 return false;
73
74         if (!prs_uint32("version", ps, depth, &header->version))
75                 return false;
76
77         return true;
78 }
79
80 /****************************************************************
81 ****************************************************************/
82
83 static bool reg_parse_and_verify_ucs2_char(const char *desc,
84                                            char character,
85                                            prs_struct *ps,
86                                            int depth)
87 {
88         uint16_t tmp;
89
90         if (!prs_uint16(desc, ps, depth, &tmp))
91                 return false;
92
93         if (tmp != UCS2_CHAR(character))
94                 return false;
95
96         return true;
97 }
98
99 /****************************************************************
100 ****************************************************************/
101
102 static bool reg_parse_init(prs_struct *ps, int depth)
103 {
104         return reg_parse_and_verify_ucs2_char("initiator '['", '[',
105                                               ps, depth);
106 }
107
108 /****************************************************************
109 ****************************************************************/
110
111 static bool reg_parse_sep(prs_struct *ps, int depth)
112 {
113         return reg_parse_and_verify_ucs2_char("separator ';'", ';',
114                                               ps, depth);
115 }
116
117 /****************************************************************
118 ****************************************************************/
119
120 static bool reg_parse_term(prs_struct *ps, int depth)
121 {
122         return reg_parse_and_verify_ucs2_char("terminator ']'", ']',
123                                               ps, depth);
124 }
125
126
127 /****************************************************************
128 * [key;value;type;size;data]
129 ****************************************************************/
130
131 static bool reg_parse_entry(TALLOC_CTX *mem_ctx,
132                             const char *desc,
133                             struct gp_registry_file_entry *entry,
134                             prs_struct *ps,
135                             int depth)
136 {
137         uint32_t size = 0;
138
139         if (!entry)
140                 return false;
141
142         prs_debug(ps, depth, desc, "reg_parse_entry");
143         depth++;
144
145         ZERO_STRUCTP(entry);
146
147         if (!reg_parse_init(ps, depth))
148                 return false;
149
150         if (!prs_unistr("key", ps, depth, &entry->key))
151                 return false;
152
153         if (!reg_parse_sep(ps, depth))
154                 return false;
155
156         if (!prs_unistr("value", ps, depth, &entry->value))
157                 return false;
158
159         if (!reg_parse_sep(ps, depth))
160                 return false;
161
162         if (!prs_uint32("type", ps, depth, &entry->type))
163                 return false;
164
165         if (!reg_parse_sep(ps, depth))
166                 return false;
167
168         if (!prs_uint32("size", ps, depth, &size))
169                 return false;
170
171         entry->size = size;
172
173         if (!reg_parse_sep(ps, depth))
174                 return false;
175
176         if (entry->size) {
177                 entry->data = TALLOC_ZERO_ARRAY(mem_ctx, uint8, entry->size);
178                 if (!entry->data)
179                         return false;
180         }
181
182         if (!prs_uint8s(false, "data", ps, depth, entry->data, entry->size))
183                 return false;
184
185         if (!reg_parse_term(ps, depth))
186                 return false;
187
188         return true;
189 }
190
191 /****************************************************************
192 ****************************************************************/
193
194 static bool reg_parse_value(TALLOC_CTX *mem_ctx,
195                             char **value,
196                             enum gp_reg_action *action)
197 {
198         if (!*value) {
199                 *action = GP_REG_ACTION_ADD_KEY;
200                 return true;
201         }
202
203         if (strncmp(*value, "**", 2) != 0) {
204                 *action = GP_REG_ACTION_ADD_VALUE;
205                 return true;
206         }
207
208         if (strnequal(*value, "**DelVals.", 10)) {
209                 *action = GP_REG_ACTION_DEL_ALL_VALUES;
210                 return true;
211         }
212
213         if (strnequal(*value, "**Del.", 6)) {
214                 *value = talloc_strdup(mem_ctx, *value + 6);
215                 *action = GP_REG_ACTION_DEL_VALUE;
216                 return true;
217         }
218
219         if (strnequal(*value, "**SecureKey", 11)) {
220                 if (strnequal(*value, "**SecureKey=1", 13)) {
221                         *action = GP_REG_ACTION_SEC_KEY_SET;
222                         return true;
223                 }
224
225  /*************** not tested from here on ***************/
226                 if (strnequal(*value, "**SecureKey=0", 13)) {
227                         smb_panic("not supported: **SecureKey=0");
228                         *action = GP_REG_ACTION_SEC_KEY_RESET;
229                         return true;
230                 }
231                 DEBUG(0,("unknown: SecureKey: %s\n", *value));
232                 smb_panic("not supported SecureKey method");
233                 return false;
234         }
235
236         if (strnequal(*value, "**DeleteValues", strlen("**DeleteValues"))) {
237                 smb_panic("not supported: **DeleteValues");
238                 *action = GP_REG_ACTION_DEL_VALUES;
239                 return false;
240         }
241
242         if (strnequal(*value, "**DeleteKeys", strlen("**DeleteKeys"))) {
243                 smb_panic("not supported: **DeleteKeys");
244                 *action = GP_REG_ACTION_DEL_KEYS;
245                 return false;
246         }
247
248         DEBUG(0,("unknown value: %s\n", *value));
249         smb_panic(*value);
250         return false;
251 }
252
253 /****************************************************************
254 ****************************************************************/
255
256 static bool gp_reg_entry_from_file_entry(TALLOC_CTX *mem_ctx,
257                                          struct gp_registry_file_entry *file_entry,
258                                          struct gp_registry_entry **reg_entry)
259 {
260         struct registry_value *data = NULL;
261         struct gp_registry_entry *entry = NULL;
262         char *key = NULL;
263         char *value = NULL;
264         enum gp_reg_action action = GP_REG_ACTION_NONE;
265         size_t converted_size;
266
267         ZERO_STRUCTP(*reg_entry);
268
269         data = TALLOC_ZERO_P(mem_ctx, struct registry_value);
270         if (!data)
271                 return false;
272
273         if (strlen_w((const smb_ucs2_t *)file_entry->key.buffer) <= 0)
274                 return false;
275
276         if (!pull_ucs2_talloc(mem_ctx, &key, file_entry->key.buffer,
277                               &converted_size))
278         {
279                 return false;
280         }
281
282         if (strlen_w((const smb_ucs2_t *)file_entry->value.buffer) > 0 &&
283             !pull_ucs2_talloc(mem_ctx, &value, file_entry->value.buffer,
284                               &converted_size))
285         {
286                         return false;
287         }
288
289         if (!reg_parse_value(mem_ctx, &value, &action))
290                 return false;
291
292         data->type = file_entry->type;
293
294         switch (data->type) {
295                 case REG_DWORD:
296                         data->v.dword = atoi((char *)file_entry->data);
297                         break;
298                 case REG_BINARY:
299                         data->v.binary = data_blob_talloc(mem_ctx,
300                                                           file_entry->data,
301                                                           file_entry->size);
302                         break;
303                 case REG_NONE:
304                         break;
305                 case REG_SZ:
306                         if (!pull_ucs2_talloc(mem_ctx, &data->v.sz.str,
307                                               (const smb_ucs2_t *)
308                                               file_entry->data,
309                                               &data->v.sz.len)) {
310                                 data->v.sz.len = -1;
311                         }
312
313                         break;
314                 case REG_DWORD_BIG_ENDIAN:
315                 case REG_EXPAND_SZ:
316                 case REG_LINK:
317                 case REG_MULTI_SZ:
318                 case REG_QWORD:
319 /*              case REG_DWORD_LITTLE_ENDIAN: */
320 /*              case REG_QWORD_LITTLE_ENDIAN: */
321                         printf("not yet implemented: %d\n", data->type);
322                         return false;
323                 default:
324                         printf("invalid reg type defined: %d\n", data->type);
325                         return false;
326
327         }
328
329         entry = TALLOC_ZERO_P(mem_ctx, struct gp_registry_entry);
330         if (!entry)
331                 return false;
332
333         entry->key = key;
334         entry->value = value;
335         entry->data = data;
336         entry->action = action;
337
338         *reg_entry = entry;
339
340         return true;
341 }
342
343 /****************************************************************
344 * [key;value;type;size;data][key;value;type;size;data]...
345 ****************************************************************/
346
347 static bool reg_parse_entries(TALLOC_CTX *mem_ctx,
348                               const char *desc,
349                               struct gp_registry_entry **entries,
350                               size_t *num_entries,
351                               prs_struct *ps,
352                               int depth)
353 {
354
355         if (!entries || !num_entries)
356                 return false;
357
358         prs_debug(ps, depth, desc, "reg_parse_entries");
359         depth++;
360
361         *entries = NULL;
362         *num_entries = 0;
363
364         while (ps->buffer_size > ps->data_offset) {
365
366                 struct gp_registry_file_entry f_entry;
367                 struct gp_registry_entry *r_entry = NULL;
368
369                 if (!reg_parse_entry(mem_ctx, desc, &f_entry,
370                                      ps, depth))
371                         return false;
372
373                 if (!gp_reg_entry_from_file_entry(mem_ctx,
374                                                   &f_entry,
375                                                   &r_entry))
376                         return false;
377
378                 if (!add_gp_registry_entry_to_array(mem_ctx,
379                                                     r_entry,
380                                                     entries,
381                                                     num_entries))
382                         return false;
383         }
384
385         return true;
386 }
387
388 /****************************************************************
389 ****************************************************************/
390
391 static NTSTATUS reg_parse_registry(TALLOC_CTX *mem_ctx,
392                                    uint32_t flags,
393                                    const char *filename,
394                                    struct gp_registry_entry **entries,
395                                    size_t *num_entries)
396 {
397         uint16_t *buf = NULL;
398         size_t n = 0;
399         NTSTATUS status;
400         prs_struct ps;
401         struct gp_registry_file *reg_file;
402         const char *real_filename = NULL;
403
404         reg_file = TALLOC_ZERO_P(mem_ctx, struct gp_registry_file);
405         NT_STATUS_HAVE_NO_MEMORY(reg_file);
406
407         status = gp_find_file(mem_ctx,
408                               flags,
409                               filename,
410                               GP_REGPOL_FILE,
411                               &real_filename);
412         if (!NT_STATUS_IS_OK(status)) {
413                 TALLOC_FREE(reg_file);
414                 return status;
415         }
416
417         buf = (uint16 *)file_load(real_filename, &n, 0, NULL);
418         if (!buf) {
419                 TALLOC_FREE(reg_file);
420                 return NT_STATUS_CANNOT_LOAD_REGISTRY_FILE;
421         }
422
423         if (!prs_init(&ps, n, mem_ctx, UNMARSHALL)) {
424                 status = NT_STATUS_NO_MEMORY;
425                 goto out;
426         }
427
428         if (!prs_copy_data_in(&ps, (char *)buf, n)) {
429                 status = NT_STATUS_NO_MEMORY;
430                 goto out;
431         }
432
433         prs_set_offset(&ps, 0);
434
435         if (!reg_parse_header("header", &reg_file->header, &ps, 0)) {
436                 status = NT_STATUS_REGISTRY_IO_FAILED;
437                 goto out;
438         }
439
440         if (reg_file->header.signature != GP_REGPOL_FILE_SIGNATURE) {
441                 status = NT_STATUS_INVALID_PARAMETER;
442                 goto out;
443         }
444
445         if (reg_file->header.version != GP_REGPOL_FILE_VERSION) {
446                 status = NT_STATUS_INVALID_PARAMETER;
447                 goto out;
448         }
449
450         if (!reg_parse_entries(mem_ctx, "entries", &reg_file->entries,
451                                &reg_file->num_entries, &ps, 0)) {
452                 status = NT_STATUS_REGISTRY_IO_FAILED;
453                 goto out;
454         }
455
456         *entries = reg_file->entries;
457         *num_entries = reg_file->num_entries;
458
459         status = NT_STATUS_OK;
460
461  out:
462         TALLOC_FREE(buf);
463         prs_mem_free(&ps);
464
465         return status;
466 }
467
468 /****************************************************************
469 ****************************************************************/
470
471 static WERROR reg_apply_registry(TALLOC_CTX *mem_ctx,
472                                  const struct nt_user_token *token,
473                                  struct registry_key *root_key,
474                                  uint32_t flags,
475                                  struct gp_registry_entry *entries,
476                                  size_t num_entries)
477 {
478         struct gp_registry_context *reg_ctx = NULL;
479         WERROR werr;
480         size_t i;
481
482         if (num_entries == 0) {
483                 return WERR_OK;
484         }
485
486 #if 0
487         if (flags & GPO_LIST_FLAG_MACHINE) {
488                 werr = gp_init_reg_ctx(mem_ctx, KEY_HKLM, REG_KEY_WRITE,
489                                        get_system_token(),
490                                        &reg_ctx);
491         } else {
492                 werr = gp_init_reg_ctx(mem_ctx, KEY_HKCU, REG_KEY_WRITE,
493                                        token,
494                                        &reg_ctx);
495         }
496         W_ERROR_NOT_OK_RETURN(werr);
497 #endif
498         for (i=0; i<num_entries; i++) {
499
500                 /* FIXME: maybe we should check here if we attempt to go beyond
501                  * the 4 allowed reg keys */
502
503                 werr = reg_apply_registry_entry(mem_ctx, root_key,
504                                                 reg_ctx,
505                                                 &(entries)[i],
506                                                 token, flags);
507                 if (!W_ERROR_IS_OK(werr)) {
508                         DEBUG(0,("failed to apply registry: %s\n",
509                                 win_errstr(werr)));
510                         goto done;
511                 }
512         }
513
514 done:
515         gp_free_reg_ctx(reg_ctx);
516         return werr;
517 }
518
519
520 /****************************************************************
521 ****************************************************************/
522
523 static NTSTATUS registry_process_group_policy(ADS_STRUCT *ads,
524                                               TALLOC_CTX *mem_ctx,
525                                               uint32_t flags,
526                                               struct registry_key *root_key,
527                                               const struct nt_user_token *token,
528                                               struct GROUP_POLICY_OBJECT *gpo,
529                                               const char *extension_guid,
530                                               const char *snapin_guid)
531 {
532         NTSTATUS status;
533         WERROR werr;
534         struct gp_registry_entry *entries = NULL;
535         size_t num_entries = 0;
536         char *unix_path = NULL;
537
538         debug_gpext_header(0, "registry_process_group_policy", flags, gpo,
539                            extension_guid, snapin_guid);
540
541         status = gpo_get_unix_path(mem_ctx, cache_path(GPO_CACHE_DIR), gpo, &unix_path);
542         NT_STATUS_NOT_OK_RETURN(status);
543
544         status = reg_parse_registry(mem_ctx,
545                                     flags,
546                                     unix_path,
547                                     &entries,
548                                     &num_entries);
549         if (!NT_STATUS_IS_OK(status)) {
550                 DEBUG(0,("failed to parse registry: %s\n",
551                         nt_errstr(status)));
552                 return status;
553         }
554
555         dump_reg_entries(flags, "READ", entries, num_entries);
556
557         werr = reg_apply_registry(mem_ctx, token, root_key, flags,
558                                   entries, num_entries);
559         if (!W_ERROR_IS_OK(werr)) {
560                 DEBUG(0,("failed to apply registry: %s\n",
561                         win_errstr(werr)));
562                 return werror_to_ntstatus(werr);
563         }
564
565         return NT_STATUS_OK;
566 }
567
568 /****************************************************************
569 ****************************************************************/
570
571 static NTSTATUS registry_get_reg_config(TALLOC_CTX *mem_ctx,
572                                         struct gp_extension_reg_info **reg_info)
573 {
574         NTSTATUS status;
575         struct gp_extension_reg_info *info = NULL;
576         struct gp_extension_reg_table table[] = {
577                 { "ProcessGroupPolicy", REG_SZ, "registry_process_group_policy" },
578                 { NULL, REG_NONE, NULL }
579         };
580
581         info = TALLOC_ZERO_P(mem_ctx, struct gp_extension_reg_info);
582         NT_STATUS_HAVE_NO_MEMORY(info);
583
584         status = gp_ext_info_add_entry(mem_ctx, GP_EXT_NAME,
585                                        GP_EXT_GUID_REGISTRY,
586                                        table, info);
587         NT_STATUS_NOT_OK_RETURN(status);
588
589         *reg_info = info;
590
591         return NT_STATUS_OK;
592 }
593
594 /****************************************************************
595 ****************************************************************/
596
597 static NTSTATUS registry_initialize(TALLOC_CTX *mem_ctx)
598 {
599         return NT_STATUS_OK;
600 }
601
602 /****************************************************************
603 ****************************************************************/
604
605 static NTSTATUS registry_shutdown(void)
606 {
607         NTSTATUS status;
608
609         status = unregister_gp_extension(GP_EXT_NAME);
610         if (NT_STATUS_IS_OK(status)) {
611                 return status;
612         }
613
614         TALLOC_FREE(ctx);
615
616         return NT_STATUS_OK;
617 }
618
619 /****************************************************************
620 ****************************************************************/
621
622 static struct gp_extension_methods registry_methods = {
623         .initialize             = registry_initialize,
624         .process_group_policy   = registry_process_group_policy,
625         .get_reg_config         = registry_get_reg_config,
626         .shutdown               = registry_shutdown
627 };
628
629 /****************************************************************
630 ****************************************************************/
631
632 NTSTATUS gpext_registry_init(void)
633 {
634         NTSTATUS status;
635
636         ctx = talloc_init("gpext_registry_init");
637         NT_STATUS_HAVE_NO_MEMORY(ctx);
638
639         status = register_gp_extension(ctx, SMB_GPEXT_INTERFACE_VERSION,
640                                        GP_EXT_NAME, GP_EXT_GUID_REGISTRY,
641                                        &registry_methods);
642         if (!NT_STATUS_IS_OK(status)) {
643                 TALLOC_FREE(ctx);
644         }
645
646         return status;
647 }