2 * Unix SMB/CIFS implementation.
3 * RPC Pipe client / server routines
4 * Copyright (C) Andrew Tridgell 1992-2000,
5 * Copyright (C) Jean François Micouleau 1998-2000.
6 * Copyright (C) Gerald Carter 2002-2005.
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, see <http://www.gnu.org/licenses/>.
23 #include "../librpc/gen_ndr/spoolss.h"
24 #include "rpc_server/spoolss/srv_spoolss_util.h"
25 #include "nt_printing.h"
29 #include "../libcli/registry/util_reg.h"
31 #include "../librpc/ndr/libndr.h"
32 #include "rpc_client/cli_winreg_spoolss.h"
35 /*****************************************************************
36 ****************************************************************/
38 static void store_printer_guid(struct messaging_context
*msg_ctx
,
39 const char *printer
, struct GUID guid
)
42 struct auth_session_info
*session_info
= NULL
;
48 tmp_ctx
= talloc_new(NULL
);
50 DEBUG(0, ("store_printer_guid: Out of memory?!\n"));
54 status
= make_session_info_system(tmp_ctx
, &session_info
);
55 if (!NT_STATUS_IS_OK(status
)) {
56 DEBUG(0, ("store_printer_guid: "
57 "Could not create system session_info\n"));
61 guid_str
= GUID_string(tmp_ctx
, &guid
);
63 DEBUG(0, ("store_printer_guid: Out of memory?!\n"));
67 /* We used to store this as a REG_BINARY but that causes
70 if (!push_reg_sz(tmp_ctx
, &blob
, guid_str
)) {
71 DEBUG(0, ("store_printer_guid: "
72 "Could not marshall string %s for objectGUID\n",
77 result
= winreg_set_printer_dataex_internal(tmp_ctx
, session_info
, msg_ctx
,
79 SPOOL_DSSPOOLER_KEY
, "objectGUID",
80 REG_SZ
, blob
.data
, blob
.length
);
81 if (!W_ERROR_IS_OK(result
)) {
82 DEBUG(0, ("store_printer_guid: "
83 "Failed to store GUID for printer %s\n", printer
));
90 static WERROR
nt_printer_dn_lookup(TALLOC_CTX
*mem_ctx
,
95 char *printer_dn
= NULL
;
97 char *srv_cn_0
= NULL
;
98 char *srv_cn_escaped
= NULL
;
99 char *sharename_escaped
= NULL
;
100 char *srv_dn_utf8
= NULL
;
101 char **srv_cn_utf8
= NULL
;
102 size_t converted_size
;
103 ADS_STATUS ads_status
;
108 ads_status
= ads_find_machine_acct(ads
, &res
, lp_netbios_name());
109 if (!ADS_ERR_OK(ads_status
)) {
110 DEBUG(2, ("Failed to find machine account for %s\n",
112 result
= WERR_NOT_FOUND
;
117 * We use ldap_get_dn here as we need the answer in utf8 to call
118 * ldap_explode_dn(). JRA.
120 srv_dn_utf8
= ldap_get_dn((LDAP
*)ads
->ldap
.ld
, (LDAPMessage
*)res
);
121 ads_msgfree(ads
, res
);
122 if (srv_dn_utf8
== NULL
) {
123 result
= WERR_SERVER_UNAVAILABLE
;
127 srv_cn_utf8
= ldap_explode_dn(srv_dn_utf8
, 1);
128 if (srv_cn_utf8
== NULL
) {
129 ldap_memfree(srv_dn_utf8
);
130 result
= WERR_SERVER_UNAVAILABLE
;
134 /* Now convert to CH_UNIX. */
135 ok
= pull_utf8_talloc(mem_ctx
, &srv_dn
, srv_dn_utf8
, &converted_size
);
136 ldap_memfree(srv_dn_utf8
);
138 ldap_memfree(srv_cn_utf8
);
139 result
= WERR_SERVER_UNAVAILABLE
;
143 ok
= pull_utf8_talloc(mem_ctx
, &srv_cn_0
, srv_cn_utf8
[0], &converted_size
);
144 ldap_memfree(srv_cn_utf8
);
146 result
= WERR_SERVER_UNAVAILABLE
;
150 srv_cn_escaped
= escape_rdn_val_string_alloc(srv_cn_0
);
151 if (srv_cn_escaped
== NULL
) {
152 result
= WERR_SERVER_UNAVAILABLE
;
156 sharename_escaped
= escape_rdn_val_string_alloc(printer
);
157 if (sharename_escaped
== NULL
) {
158 result
= WERR_SERVER_UNAVAILABLE
;
162 printer_dn
= talloc_asprintf(mem_ctx
,
167 if (printer_dn
== NULL
) {
172 *pprinter_dn
= printer_dn
;
176 SAFE_FREE(sharename_escaped
);
177 SAFE_FREE(srv_cn_escaped
);
178 TALLOC_FREE(srv_cn_0
);
183 static WERROR
nt_printer_guid_retrieve_internal(ADS_STRUCT
*ads
,
184 const char *printer_dn
,
187 ADS_STATUS ads_status
;
189 const char *attrs
[] = {"objectGUID", NULL
};
193 ads_status
= ads_search_dn(ads
, &res
, printer_dn
, attrs
);
194 if (!ADS_ERR_OK(ads_status
)) {
195 DEBUG(2, ("Failed to retrieve GUID from DC - %s\n",
196 ads_errstr(ads_status
)));
201 ok
= ads_pull_guid(ads
, res
, &guid
);
202 ads_msgfree(ads
, res
);
212 WERROR
nt_printer_guid_retrieve(TALLOC_CTX
*mem_ctx
, const char *printer
,
215 ADS_STRUCT
*ads
= NULL
;
216 char *old_krb5ccname
= NULL
;
219 ADS_STATUS ads_status
;
222 tmp_ctx
= talloc_new(mem_ctx
);
223 if (tmp_ctx
== NULL
) {
227 ads
= ads_init(lp_realm(), lp_workgroup(), NULL
);
229 result
= WERR_SERVER_UNAVAILABLE
;
233 old_krb5ccname
= getenv(KRB5_ENV_CCNAME
);
234 setenv(KRB5_ENV_CCNAME
, "MEMORY:prtpub_cache", 1);
235 SAFE_FREE(ads
->auth
.password
);
236 ads
->auth
.password
= secrets_fetch_machine_password(lp_workgroup(),
239 ads_status
= ads_connect(ads
);
240 if (!ADS_ERR_OK(ads_status
)) {
241 DEBUG(3, ("ads_connect failed: %s\n", ads_errstr(ads_status
)));
242 result
= WERR_ACCESS_DENIED
;
246 result
= nt_printer_dn_lookup(tmp_ctx
, ads
, printer
, &printer_dn
);
247 if (!W_ERROR_IS_OK(result
)) {
251 result
= nt_printer_guid_retrieve_internal(ads
, printer_dn
, pguid
);
253 TALLOC_FREE(tmp_ctx
);
255 ads_kdestroy("MEMORY:prtpub_cache");
256 unsetenv(KRB5_ENV_CCNAME
);
257 if (old_krb5ccname
!= NULL
) {
258 setenv(KRB5_ENV_CCNAME
, old_krb5ccname
, 0);
264 WERROR
nt_printer_guid_get(TALLOC_CTX
*mem_ctx
,
265 const struct auth_session_info
*session_info
,
266 struct messaging_context
*msg_ctx
,
267 const char *printer
, struct GUID
*guid
)
270 enum winreg_Type type
;
276 tmp_ctx
= talloc_new(mem_ctx
);
277 if (tmp_ctx
== NULL
) {
278 DEBUG(0, ("out of memory?!\n"));
282 result
= winreg_get_printer_dataex_internal(tmp_ctx
, session_info
,
289 if (!W_ERROR_IS_OK(result
)) {
290 DEBUG(0, ("Failed to get GUID for printer %s\n", printer
));
293 blob
.length
= (size_t)len
;
295 /* We used to store the guid as REG_BINARY, then swapped
296 to REG_SZ for Vista compatibility so check for both */
301 const char *guid_str
;
302 ok
= pull_reg_sz(tmp_ctx
, &blob
, &guid_str
);
304 DEBUG(0, ("Failed to unmarshall GUID for printer %s\n",
306 result
= WERR_REG_CORRUPT
;
309 status
= GUID_from_string(guid_str
, guid
);
310 if (!NT_STATUS_IS_OK(status
)) {
311 DEBUG(0, ("bad GUID for printer %s\n", printer
));
312 result
= ntstatus_to_werror(status
);
318 if (blob
.length
!= sizeof(struct GUID
)) {
319 DEBUG(0, ("bad GUID for printer %s\n", printer
));
320 result
= WERR_REG_CORRUPT
;
323 memcpy(guid
, blob
.data
, sizeof(struct GUID
));
326 DEBUG(0,("GUID value stored as invalid type (%d)\n", type
));
327 result
= WERR_REG_CORRUPT
;
334 talloc_free(tmp_ctx
);
338 static WERROR
nt_printer_info_to_mods(TALLOC_CTX
*ctx
,
339 struct spoolss_PrinterInfo2
*info2
,
344 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTERNAME
, info2
->sharename
);
345 ads_mod_str(ctx
, mods
, SPOOL_REG_SHORTSERVERNAME
, lp_netbios_name());
346 ads_mod_str(ctx
, mods
, SPOOL_REG_SERVERNAME
, get_mydnsfullname());
348 info_str
= talloc_asprintf(ctx
, "\\\\%s\\%s",
349 get_mydnsfullname(), info2
->sharename
);
350 if (info_str
== NULL
) {
353 ads_mod_str(ctx
, mods
, SPOOL_REG_UNCNAME
, info_str
);
355 info_str
= talloc_asprintf(ctx
, "%d", 4);
356 if (info_str
== NULL
) {
359 ads_mod_str(ctx
, mods
, SPOOL_REG_VERSIONNUMBER
, info_str
);
361 /* empty strings in the mods list result in an attrubute error */
362 if (strlen(info2
->drivername
) != 0)
363 ads_mod_str(ctx
, mods
, SPOOL_REG_DRIVERNAME
, info2
->drivername
);
364 if (strlen(info2
->location
) != 0)
365 ads_mod_str(ctx
, mods
, SPOOL_REG_LOCATION
, info2
->location
);
366 if (strlen(info2
->comment
) != 0)
367 ads_mod_str(ctx
, mods
, SPOOL_REG_DESCRIPTION
, info2
->comment
);
368 if (strlen(info2
->portname
) != 0)
369 ads_mod_str(ctx
, mods
, SPOOL_REG_PORTNAME
, info2
->portname
);
370 if (strlen(info2
->sepfile
) != 0)
371 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTSEPARATORFILE
, info2
->sepfile
);
373 info_str
= talloc_asprintf(ctx
, "%u", info2
->starttime
);
374 if (info_str
== NULL
) {
377 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTSTARTTIME
, info_str
);
379 info_str
= talloc_asprintf(ctx
, "%u", info2
->untiltime
);
380 if (info_str
== NULL
) {
383 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTENDTIME
, info_str
);
385 info_str
= talloc_asprintf(ctx
, "%u", info2
->priority
);
386 if (info_str
== NULL
) {
389 ads_mod_str(ctx
, mods
, SPOOL_REG_PRIORITY
, info_str
);
391 if (info2
->attributes
& PRINTER_ATTRIBUTE_KEEPPRINTEDJOBS
) {
392 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTKEEPPRINTEDJOBS
, "TRUE");
394 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTKEEPPRINTEDJOBS
, "FALSE");
397 switch (info2
->attributes
& 0x3) {
399 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTSPOOLING
,
400 SPOOL_REGVAL_PRINTWHILESPOOLING
);
403 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTSPOOLING
,
404 SPOOL_REGVAL_PRINTAFTERSPOOLED
);
407 ads_mod_str(ctx
, mods
, SPOOL_REG_PRINTSPOOLING
,
408 SPOOL_REGVAL_PRINTDIRECT
);
411 DEBUG(3, ("unsupported printer attributes %x\n",
418 static WERROR
nt_printer_publish_ads(struct messaging_context
*msg_ctx
,
420 struct spoolss_PrinterInfo2
*pinfo2
)
426 WERROR win_rc
= WERR_OK
;
427 const char *printer
= pinfo2
->sharename
;
428 char *printer_dn
= NULL
;
430 /* build the ads mods */
431 ctx
= talloc_init("nt_printer_publish_ads");
436 DEBUG(5, ("publishing printer %s\n", printer
));
438 win_rc
= nt_printer_dn_lookup(ctx
, ads
, printer
, &printer_dn
);
439 if (!W_ERROR_IS_OK(win_rc
)) {
440 DEBUG(2, ("Failed to create printer dn\n"));
445 mods
= ads_init_mods(ctx
);
452 win_rc
= nt_printer_info_to_mods(ctx
, pinfo2
, &mods
);
453 if (!W_ERROR_IS_OK(win_rc
)) {
459 ads_rc
= ads_mod_printer_entry(ads
, printer_dn
, ctx
, &mods
);
460 if (ads_rc
.err
.rc
== LDAP_NO_SUCH_OBJECT
) {
462 for (i
=0; mods
[i
] != 0; i
++)
464 mods
[i
] = (LDAPMod
*)-1;
465 ads_rc
= ads_add_printer_entry(ads
, printer_dn
, ctx
, &mods
);
468 if (!ADS_ERR_OK(ads_rc
)) {
469 DEBUG(3, ("error publishing %s: %s\n",
470 printer
, ads_errstr(ads_rc
)));
473 win_rc
= nt_printer_guid_retrieve_internal(ads
, printer_dn
, &guid
);
474 if (!W_ERROR_IS_OK(win_rc
)) {
479 /* TODO add a return value */
480 store_printer_guid(msg_ctx
, printer
, guid
);
487 static WERROR
nt_printer_unpublish_ads(ADS_STRUCT
*ads
,
491 LDAPMessage
*res
= NULL
;
494 DEBUG(5, ("unpublishing printer %s\n", printer
));
496 /* remove the printer from the directory */
497 ads_rc
= ads_find_printer_on_server(ads
, &res
,
498 printer
, lp_netbios_name());
500 if (ADS_ERR_OK(ads_rc
) && res
&& ads_count_replies(ads
, res
)) {
501 prt_dn
= ads_get_dn(ads
, talloc_tos(), res
);
503 ads_msgfree(ads
, res
);
506 ads_rc
= ads_del_dn(ads
, prt_dn
);
511 ads_msgfree(ads
, res
);
516 /****************************************************************************
517 * Publish a printer in the directory
519 * @param mem_ctx memory context
520 * @param session_info session_info to access winreg pipe
521 * @param pinfo2 printer information
522 * @param action publish/unpublish action
523 * @return WERROR indicating status of publishing
524 ***************************************************************************/
526 WERROR
nt_printer_publish(TALLOC_CTX
*mem_ctx
,
527 const struct auth_session_info
*session_info
,
528 struct messaging_context
*msg_ctx
,
529 struct spoolss_PrinterInfo2
*pinfo2
,
532 uint32_t info2_mask
= SPOOLSS_PRINTER_INFO_ATTRIBUTES
;
533 struct spoolss_SetPrinterInfo2
*sinfo2
;
535 ADS_STRUCT
*ads
= NULL
;
537 char *old_krb5ccname
= NULL
;
539 sinfo2
= talloc_zero(mem_ctx
, struct spoolss_SetPrinterInfo2
);
545 case DSPRINT_PUBLISH
:
547 pinfo2
->attributes
|= PRINTER_ATTRIBUTE_PUBLISHED
;
549 case DSPRINT_UNPUBLISH
:
550 pinfo2
->attributes
&= (~PRINTER_ATTRIBUTE_PUBLISHED
);
553 win_rc
= WERR_NOT_SUPPORTED
;
557 sinfo2
->attributes
= pinfo2
->attributes
;
559 win_rc
= winreg_update_printer_internal(mem_ctx
, session_info
, msg_ctx
,
560 pinfo2
->sharename
, info2_mask
,
562 if (!W_ERROR_IS_OK(win_rc
)) {
563 DEBUG(3, ("err %d saving data\n", W_ERROR_V(win_rc
)));
569 ads
= ads_init(lp_realm(), lp_workgroup(), NULL
);
571 DEBUG(3, ("ads_init() failed\n"));
572 win_rc
= WERR_SERVER_UNAVAILABLE
;
575 old_krb5ccname
= getenv(KRB5_ENV_CCNAME
);
576 setenv(KRB5_ENV_CCNAME
, "MEMORY:prtpub_cache", 1);
577 SAFE_FREE(ads
->auth
.password
);
578 ads
->auth
.password
= secrets_fetch_machine_password(lp_workgroup(),
581 /* ads_connect() will find the DC for us */
582 ads_rc
= ads_connect(ads
);
583 if (!ADS_ERR_OK(ads_rc
)) {
584 DEBUG(3, ("ads_connect failed: %s\n", ads_errstr(ads_rc
)));
585 win_rc
= WERR_ACCESS_DENIED
;
590 case DSPRINT_PUBLISH
:
592 win_rc
= nt_printer_publish_ads(msg_ctx
, ads
, pinfo2
);
594 case DSPRINT_UNPUBLISH
:
595 win_rc
= nt_printer_unpublish_ads(ads
, pinfo2
->sharename
);
601 ads_kdestroy("MEMORY:prtpub_cache");
602 unsetenv(KRB5_ENV_CCNAME
);
603 if (old_krb5ccname
) {
604 setenv(KRB5_ENV_CCNAME
, old_krb5ccname
, 0);
609 WERROR
check_published_printers(struct messaging_context
*msg_ctx
)
612 ADS_STRUCT
*ads
= NULL
;
614 int n_services
= lp_numservices();
615 TALLOC_CTX
*tmp_ctx
= NULL
;
616 struct auth_session_info
*session_info
= NULL
;
617 struct spoolss_PrinterInfo2
*pinfo2
;
620 char *old_krb5ccname
= NULL
;
622 tmp_ctx
= talloc_new(NULL
);
623 if (!tmp_ctx
) return WERR_NOMEM
;
625 ads
= ads_init(lp_realm(), lp_workgroup(), NULL
);
627 DEBUG(3, ("ads_init() failed\n"));
628 return WERR_SERVER_UNAVAILABLE
;
630 old_krb5ccname
= getenv(KRB5_ENV_CCNAME
);
631 setenv(KRB5_ENV_CCNAME
, "MEMORY:prtpub_cache", 1);
632 SAFE_FREE(ads
->auth
.password
);
633 ads
->auth
.password
= secrets_fetch_machine_password(lp_workgroup(),
636 /* ads_connect() will find the DC for us */
637 ads_rc
= ads_connect(ads
);
638 if (!ADS_ERR_OK(ads_rc
)) {
639 DEBUG(3, ("ads_connect failed: %s\n", ads_errstr(ads_rc
)));
640 result
= WERR_ACCESS_DENIED
;
644 status
= make_session_info_system(tmp_ctx
, &session_info
);
645 if (!NT_STATUS_IS_OK(status
)) {
646 DEBUG(0, ("check_published_printers: "
647 "Could not create system session_info\n"));
648 result
= WERR_ACCESS_DENIED
;
652 for (snum
= 0; snum
< n_services
; snum
++) {
653 if (!lp_snum_ok(snum
) || !lp_printable(snum
)) {
657 result
= winreg_get_printer_internal(tmp_ctx
, session_info
, msg_ctx
,
658 lp_servicename(talloc_tos(), snum
),
660 if (!W_ERROR_IS_OK(result
)) {
664 if (pinfo2
->attributes
& PRINTER_ATTRIBUTE_PUBLISHED
) {
665 nt_printer_publish_ads(msg_ctx
, ads
, pinfo2
);
674 ads_kdestroy("MEMORY:prtpub_cache");
675 unsetenv(KRB5_ENV_CCNAME
);
676 if (old_krb5ccname
) {
677 setenv(KRB5_ENV_CCNAME
, old_krb5ccname
, 0);
679 talloc_free(tmp_ctx
);
683 bool is_printer_published(TALLOC_CTX
*mem_ctx
,
684 const struct auth_session_info
*session_info
,
685 struct messaging_context
*msg_ctx
,
686 const char *servername
,
688 struct spoolss_PrinterInfo2
**info2
)
690 struct spoolss_PrinterInfo2
*pinfo2
= NULL
;
692 struct dcerpc_binding_handle
*b
;
694 result
= winreg_printer_binding_handle(mem_ctx
,
698 if (!W_ERROR_IS_OK(result
)) {
702 result
= winreg_get_printer(mem_ctx
, b
,
704 if (!W_ERROR_IS_OK(result
)) {
708 if (!(pinfo2
->attributes
& PRINTER_ATTRIBUTE_PUBLISHED
)) {
714 *info2
= talloc_move(mem_ctx
, &pinfo2
);
720 WERROR
nt_printer_guid_retrieve(TALLOC_CTX
*mem_ctx
, const char *printer
,
723 return WERR_NOT_SUPPORTED
;
726 WERROR
nt_printer_guid_get(TALLOC_CTX
*mem_ctx
,
727 const struct auth_session_info
*session_info
,
728 struct messaging_context
*msg_ctx
,
729 const char *printer
, struct GUID
*guid
)
731 return WERR_NOT_SUPPORTED
;
734 WERROR
nt_printer_publish(TALLOC_CTX
*mem_ctx
,
735 const struct auth_session_info
*session_info
,
736 struct messaging_context
*msg_ctx
,
737 struct spoolss_PrinterInfo2
*pinfo2
,
743 WERROR
check_published_printers(struct messaging_context
*msg_ctx
)
748 bool is_printer_published(TALLOC_CTX
*mem_ctx
,
749 const struct auth_session_info
*session_info
,
750 struct messaging_context
*msg_ctx
,
751 const char *servername
,
753 struct spoolss_PrinterInfo2
**info2
)
757 #endif /* HAVE_ADS */