From: Volker Lendecke Date: Tue, 18 Apr 2023 10:09:45 +0000 (+0200) Subject: rpc: Add global_sid_Samba_NPA_Flags SID X-Git-Tag: talloc-2.4.1~717 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=ebbb93cc7a57a118b82b8f383d25f1eb022397d6;p=thirdparty%2Fsamba.git rpc: Add global_sid_Samba_NPA_Flags SID This will be used as a flexible way to pass per-RPC-connection flags over ncalrpc to the RPC server without having to modify named_pipe_auth_req_info6 every time something new needs to be passed. It's modeled after global_sid_Samba_SMB3. Bug: https://bugzilla.samba.org/show_bug.cgi?id=15361 Signed-off-by: Volker Lendecke Reviewed-by: Stefan Metzmacher --- diff --git a/libcli/security/dom_sid.h b/libcli/security/dom_sid.h index 98ee935ff97..bb81037b904 100644 --- a/libcli/security/dom_sid.h +++ b/libcli/security/dom_sid.h @@ -66,6 +66,9 @@ extern const struct dom_sid global_sid_Unix_NFS_Mode; extern const struct dom_sid global_sid_Unix_NFS_Other; extern const struct dom_sid global_sid_Samba_SMB3; +extern const struct dom_sid global_sid_Samba_NPA_Flags; +#define SAMBA_NPA_FLAGS_NEED_IDLE 1 + struct auth_SidAttr; enum lsa_SidType; diff --git a/libcli/security/util_sid.c b/libcli/security/util_sid.c index 0a8e114c338..6ee22284033 100644 --- a/libcli/security/util_sid.c +++ b/libcli/security/util_sid.c @@ -165,6 +165,13 @@ const struct dom_sid global_sid_Unix_NFS_Other = /* Unix other, MS NFS and Appl const struct dom_sid global_sid_Samba_SMB3 = {1, 1, {0,0,0,0,0,22}, {1397571891, }}; +const struct dom_sid global_sid_Samba_NPA_Flags = {1, + 1, + {0, 0, 0, 0, 0, 22}, + { + 2041152804, + }}; + /* Unused, left here for documentary purposes */ #if 0 #define SECURITY_NULL_SID_AUTHORITY 0 diff --git a/source3/include/proto.h b/source3/include/proto.h index ae2a9533f23..a4ab57e84f3 100644 --- a/source3/include/proto.h +++ b/source3/include/proto.h @@ -437,6 +437,8 @@ NTSTATUS sid_array_from_info3(TALLOC_CTX *mem_ctx, struct dom_sid **user_sids, uint32_t *num_user_sids, bool include_user_group_rid); +bool security_token_find_npa_flags(const struct security_token *token, + uint32_t *_flags); /* The following definitions come from lib/util_sock.c */ diff --git a/source3/lib/util_sid.c b/source3/lib/util_sid.c index c51f6f44bc3..9aebb363815 100644 --- a/source3/lib/util_sid.c +++ b/source3/lib/util_sid.c @@ -170,3 +170,22 @@ NTSTATUS sid_array_from_info3(TALLOC_CTX *mem_ctx, return NT_STATUS_OK; } + +bool security_token_find_npa_flags(const struct security_token *token, + uint32_t *_flags) +{ + const struct dom_sid *npa_flags_sid = NULL; + size_t num_npa_sids; + + num_npa_sids = + security_token_count_flag_sids(token, + &global_sid_Samba_NPA_Flags, + 1, + &npa_flags_sid); + if (num_npa_sids != 1) { + return false; + } + + sid_peek_rid(npa_flags_sid, _flags); + return true; +}