2 * Unix SMB/Netbios implementation.
3 * Utility for managing share permissions
5 * Copyright (C) Tim Potter 2000
6 * Copyright (C) Jeremy Allison 2000
7 * Copyright (C) Jelmer Vernooij 2003
8 * Copyright (C) Gerald (Jerry) Carter 2005.
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
13 * (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
28 #define CREATE_ACCESS_READ READ_CONTROL_ACCESS
30 /* numeric is set when the user wants numeric SIDs and ACEs rather
31 than going via LSA calls to resolve them */
32 static BOOL numeric = False;
34 enum acl_mode {SMB_ACL_REMOVE, SMB_ACL_MODIFY, SMB_ACL_ADD, SMB_ACL_REPLACE, SMB_ACL_VIEW };
35 enum exit_values {EXIT_OK, EXIT_FAILED, EXIT_PARSE_ERROR};
42 /* These values discovered by inspection */
44 static const struct perm_value special_values[] = {
54 static const struct perm_value standard_values[] = {
55 { "READ", 0x001200a9 },
56 { "CHANGE", 0x001301bf },
57 { "FULL", 0x001f01ff },
61 /********************************************************************
62 print an ACE on a FILE, using either numeric or ascii representation
63 ********************************************************************/
65 static void print_ace(FILE *f, SEC_ACE *ace)
67 const struct perm_value *v;
72 sid_to_string(sidstr, &ace->trustee);
74 fprintf(f, "%s:", sidstr);
77 fprintf(f, "%d/%d/0x%08x",
78 ace->type, ace->flags, ace->access_mask);
84 if (ace->type == SEC_ACE_TYPE_ACCESS_ALLOWED) {
85 fprintf(f, "ALLOWED");
86 } else if (ace->type == SEC_ACE_TYPE_ACCESS_DENIED) {
89 fprintf(f, "%d", ace->type);
92 /* Not sure what flags can be set in a file ACL */
94 fprintf(f, "/%d/", ace->flags);
96 /* Standard permissions */
98 for (v = standard_values; v->perm; v++) {
99 if (ace->access_mask == v->mask) {
100 fprintf(f, "%s", v->perm);
105 /* Special permissions. Print out a hex value if we have
106 leftover bits in the mask. */
108 got_mask = ace->access_mask;
111 for (v = special_values; v->perm; v++) {
112 if ((ace->access_mask & v->mask) == v->mask) {
114 fprintf(f, "%s", v->perm);
116 got_mask &= ~v->mask;
122 fprintf(f, "0x%08x", ace->access_mask);
130 /********************************************************************
131 print a ascii version of a security descriptor on a FILE handle
132 ********************************************************************/
134 static void sec_desc_print(FILE *f, SEC_DESC *sd)
139 fprintf(f, "REVISION:%d\n", sd->revision);
141 /* Print owner and group sid */
144 sid_to_string(sidstr, sd->owner_sid);
149 fprintf(f, "OWNER:%s\n", sidstr);
152 sid_to_string(sidstr, sd->group_sid);
157 fprintf(f, "GROUP:%s\n", sidstr);
160 for (i = 0; sd->dacl && i < sd->dacl->num_aces; i++) {
161 SEC_ACE *ace = &sd->dacl->aces[i];
169 /********************************************************************
170 ********************************************************************/
172 static BOOL parse_ace( TALLOC_CTX *ctx, SEC_ACE *ace, char *entry )
175 char *p = strchr_m( entry, ':' );
185 string_to_sid( &sid, entry );
190 mask = GENERIC_RIGHTS_FILE_ALL_ACCESS|STD_RIGHT_ALL_ACCESS;
195 mask = GENERIC_RIGHTS_FILE_READ|GENERIC_RIGHTS_FILE_EXECUTE|\
196 STANDARD_RIGHTS_READ_ACCESS|STANDARD_RIGHTS_EXECUTE_ACCESS;
203 init_sec_access( &sa, mask );
205 /* no flags on share permissions */
206 init_sec_ace( ace, &sid, SEC_ACE_TYPE_ACCESS_ALLOWED, sa, 0 );
212 /********************************************************************
213 ********************************************************************/
215 static SEC_DESC* parse_acl_string( TALLOC_CTX *ctx, const char *szACL, size_t *sd_size )
228 num_ace = count_chars( pacl, ',' ) + 1;
230 if ( !(ace = TALLOC_ZERO_ARRAY( ctx, SEC_ACE, num_ace )) )
233 for ( i=0; i<num_ace; i++ ) {
234 char *end_acl = strchr_m( pacl, ',' );
237 strncpy( acl_string, pacl, MIN( PTR_DIFF( end_acl, pacl ), sizeof(fstring)-1) );
238 acl_string[MIN( PTR_DIFF( end_acl, pacl ), sizeof(fstring)-1)] = '\0';
240 if ( !parse_ace( ctx, &ace[i], acl_string ) )
247 if ( !(acl = make_sec_acl( ctx, NT4_ACL_REVISION, num_ace, ace )) )
250 sd = make_sec_desc( ctx, SEC_DESC_REVISION, SEC_DESC_SELF_RELATIVE,
251 &global_sid_Builtin_Administrators,
252 &global_sid_Builtin_Administrators,
258 /********************************************************************
260 ********************************************************************/
262 int main(int argc, const char *argv[])
265 enum acl_mode mode = SMB_ACL_REPLACE;
266 static char *the_acl = NULL;
268 BOOL force_acl = False;
274 BOOL initialize_sid = False;
275 struct poptOption long_options[] = {
278 { "remove", 'r', POPT_ARG_STRING, NULL, 'r', "Delete an ACE", "ACL" },
279 { "modify", 'm', POPT_ARG_STRING, NULL, 'm', "Modify an acl", "ACL" },
280 { "add", 'a', POPT_ARG_STRING, NULL, 'a', "Add an ACE", "ACL" },
282 { "replace", 'R', POPT_ARG_STRING, NULL, 'R', "Set share mission ACL", "ACLS" },
283 { "view", 'v', POPT_ARG_NONE, NULL, 'v', "View current share permissions" },
284 { "machine-sid", 'M', POPT_ARG_NONE, NULL, 'M', "Initialize the machine SID" },
285 { "force", 'F', POPT_ARG_NONE, NULL, 'F', "Force storing the ACL", "ACLS" },
290 if ( !(ctx = talloc_init("main")) ) {
291 fprintf( stderr, "Failed to initialize talloc context!\n");
295 /* set default debug level to 1 regardless of what smb.conf sets */
296 setup_logging( "sharesec", True );
297 DEBUGLEVEL_CLASS[DBGC_ALL] = 1;
299 x_setbuf( x_stderr, NULL );
305 lp_load( dyn_CONFIGFILE, False, False, False, True );
307 pc = poptGetContext("smbcacls", argc, argv, long_options, 0);
309 poptSetOtherOptionHelp(pc, "sharename\n");
311 while ((opt = poptGetNextOpt(pc)) != -1) {
315 the_acl = smb_xstrdup(poptGetOptArg(pc));
316 mode = SMB_ACL_REMOVE;
320 the_acl = smb_xstrdup(poptGetOptArg(pc));
321 mode = SMB_ACL_MODIFY;
325 the_acl = smb_xstrdup(poptGetOptArg(pc));
330 the_acl = smb_xstrdup(poptGetOptArg(pc));
331 mode = SMB_ACL_REPLACE;
343 initialize_sid = True;
348 /* check for initializing secrets.tdb first */
350 if ( initialize_sid ) {
351 DOM_SID *sid = get_global_sam_sid();
354 fprintf( stderr, "Failed to retrieve Machine SID!\n");
358 printf ("%s\n", sid_string_static( sid ) );
362 if ( mode == SMB_ACL_VIEW && force_acl ) {
363 fprintf( stderr, "Invalid combination of -F and -v\n");
367 /* get the sharename */
369 if(!poptPeekArg(pc)) {
370 poptPrintUsage(pc, stderr, 0);
374 fstrcpy(sharename, poptGetArg(pc));
376 snum = lp_servicenumber( sharename );
378 if ( snum == -1 && !force_acl ) {
379 fprintf( stderr, "Invalid sharename: %s\n", sharename);
385 if (!(secdesc = get_share_security( ctx, sharename,
387 fprintf(stderr, "Unable to retrieve permissions for share [%s]\n", sharename);
390 sec_desc_print( stdout, secdesc );
396 printf( "Not implemented\n");
399 case SMB_ACL_REPLACE:
400 if ( !(secdesc = parse_acl_string( ctx, the_acl, &sd_size )) ) {
401 fprintf( stderr, "Failed to parse acl\n");
405 if ( !set_share_security( ctx, lp_servicename(snum), secdesc ) ) {
406 fprintf( stderr, "Failed to store acl for share [%s]\n", sharename );