dsdb-acl: fix the order of special and system checks
[Samba/gebeck_regimport.git] / source4 / libnet / groupman.c
blob9771ea5496690de4234163e5a215f42adf87a74b
1 /*
2 Unix SMB/CIFS implementation.
4 Copyright (C) Rafal Szczesniak 2007
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 a composite function for manipulating (add/edit/del) groups via samr pipe
24 #include "includes.h"
25 #include "libcli/composite/composite.h"
26 #include "libnet/libnet.h"
27 #include "librpc/gen_ndr/ndr_samr_c.h"
30 struct groupadd_state {
31 struct dcerpc_pipe *pipe;
32 struct policy_handle domain_handle;
33 struct samr_CreateDomainGroup creategroup;
34 struct policy_handle group_handle;
35 uint32_t group_rid;
37 void (*monitor_fn)(struct monitor_msg*);
41 static void continue_groupadd_created(struct tevent_req *subreq);
44 struct composite_context* libnet_rpc_groupadd_send(struct dcerpc_pipe *p,
45 TALLOC_CTX *mem_ctx,
46 struct libnet_rpc_groupadd *io,
47 void (*monitor)(struct monitor_msg*))
49 struct composite_context *c;
50 struct groupadd_state *s;
51 struct tevent_req *subreq;
53 if (!p || !io) return NULL;
55 c = composite_create(mem_ctx, dcerpc_event_context(p));
56 if (c == NULL) return NULL;
58 s = talloc_zero(c, struct groupadd_state);
59 if (composite_nomem(s, c)) return c;
61 c->private_data = s;
63 s->domain_handle = io->in.domain_handle;
64 s->pipe = p;
65 s->monitor_fn = monitor;
67 s->creategroup.in.domain_handle = &s->domain_handle;
69 s->creategroup.in.name = talloc_zero(c, struct lsa_String);
70 if (composite_nomem(s->creategroup.in.name, c)) return c;
72 s->creategroup.in.name->string = talloc_strdup(c, io->in.groupname);
73 if (composite_nomem(s->creategroup.in.name->string, c)) return c;
75 s->creategroup.in.access_mask = 0;
77 s->creategroup.out.group_handle = &s->group_handle;
78 s->creategroup.out.rid = &s->group_rid;
80 subreq = dcerpc_samr_CreateDomainGroup_r_send(s, c->event_ctx,
81 s->pipe->binding_handle,
82 &s->creategroup);
83 if (composite_nomem(subreq, c)) return c;
85 tevent_req_set_callback(subreq, continue_groupadd_created, c);
86 return c;
90 NTSTATUS libnet_rpc_groupadd_recv(struct composite_context *c, TALLOC_CTX *mem_ctx,
91 struct libnet_rpc_groupadd *io)
93 NTSTATUS status;
94 struct groupadd_state *s;
96 status = composite_wait(c);
97 if (NT_STATUS_IS_OK(status) && io) {
98 s = talloc_get_type(c->private_data, struct groupadd_state);
99 io->out.group_handle = s->group_handle;
102 talloc_free(c);
103 return status;
107 static void continue_groupadd_created(struct tevent_req *subreq)
109 struct composite_context *c;
110 struct groupadd_state *s;
112 c = tevent_req_callback_data(subreq, struct composite_context);
113 s = talloc_get_type(c->private_data, struct groupadd_state);
115 c->status = dcerpc_samr_CreateDomainGroup_r_recv(subreq, s);
116 TALLOC_FREE(subreq);
117 if (!composite_is_ok(c)) return;
119 c->status = s->creategroup.out.result;
120 if (!NT_STATUS_IS_OK(c->status)) {
121 composite_error(c, c->status);
122 return;
125 composite_done(c);
129 NTSTATUS libnet_rpc_groupadd(struct dcerpc_pipe *p, TALLOC_CTX *mem_ctx,
130 struct libnet_rpc_groupadd *io)
132 struct composite_context *c;
134 c = libnet_rpc_groupadd_send(p, mem_ctx, io, NULL);
135 return libnet_rpc_groupadd_recv(c, mem_ctx, io);
139 struct groupdel_state {
140 struct dcerpc_pipe *pipe;
141 struct policy_handle domain_handle;
142 struct policy_handle group_handle;
143 struct samr_LookupNames lookupname;
144 struct samr_OpenGroup opengroup;
145 struct samr_DeleteDomainGroup deletegroup;
147 /* information about the progress */
148 void (*monitor_fn)(struct monitor_msg *);
152 static void continue_groupdel_name_found(struct tevent_req *subreq);
153 static void continue_groupdel_group_opened(struct tevent_req *subreq);
154 static void continue_groupdel_deleted(struct tevent_req *subreq);
157 struct composite_context* libnet_rpc_groupdel_send(struct dcerpc_pipe *p,
158 TALLOC_CTX *mem_ctx,
159 struct libnet_rpc_groupdel *io,
160 void (*monitor)(struct monitor_msg*))
162 struct composite_context *c;
163 struct groupdel_state *s;
164 struct tevent_req *subreq;
166 /* composite context allocation and setup */
167 c = composite_create(mem_ctx, dcerpc_event_context(p));
168 if (c == NULL) return NULL;
170 s = talloc_zero(c, struct groupdel_state);
171 if (composite_nomem(s, c)) return c;
173 c->private_data = s;
175 /* store function parameters in the state structure */
176 s->pipe = p;
177 s->domain_handle = io->in.domain_handle;
178 s->monitor_fn = monitor;
180 /* prepare parameters to send rpc request */
181 s->lookupname.in.domain_handle = &io->in.domain_handle;
182 s->lookupname.in.num_names = 1;
183 s->lookupname.in.names = talloc_zero(s, struct lsa_String);
184 s->lookupname.in.names->string = io->in.groupname;
185 s->lookupname.out.rids = talloc_zero(s, struct samr_Ids);
186 s->lookupname.out.types = talloc_zero(s, struct samr_Ids);
187 if (composite_nomem(s->lookupname.out.rids, c)) return c;
188 if (composite_nomem(s->lookupname.out.types, c)) return c;
190 /* send the request */
191 subreq = dcerpc_samr_LookupNames_r_send(s, c->event_ctx,
192 p->binding_handle,
193 &s->lookupname);
194 if (composite_nomem(subreq, c)) return c;
196 tevent_req_set_callback(subreq, continue_groupdel_name_found, c);
197 return c;
201 static void continue_groupdel_name_found(struct tevent_req *subreq)
203 struct composite_context *c;
204 struct groupdel_state *s;
206 c = tevent_req_callback_data(subreq, struct composite_context);
207 s = talloc_get_type(c->private_data, struct groupdel_state);
209 /* receive samr_LookupNames result */
210 c->status = dcerpc_samr_LookupNames_r_recv(subreq, s);
211 TALLOC_FREE(subreq);
212 if (!composite_is_ok(c)) return;
214 c->status = s->lookupname.out.result;
215 if (!NT_STATUS_IS_OK(c->status)) {
216 composite_error(c, c->status);
217 return;
220 /* what to do when there's no group account to delete
221 and what if there's more than one rid resolved */
222 if (!s->lookupname.out.rids->count) {
223 c->status = NT_STATUS_NO_SUCH_GROUP;
224 composite_error(c, c->status);
225 return;
227 } else if (!s->lookupname.out.rids->count > 1) {
228 c->status = NT_STATUS_INVALID_ACCOUNT_NAME;
229 composite_error(c, c->status);
230 return;
233 /* prepare the arguments for rpc call */
234 s->opengroup.in.domain_handle = &s->domain_handle;
235 s->opengroup.in.rid = s->lookupname.out.rids->ids[0];
236 s->opengroup.in.access_mask = SEC_FLAG_MAXIMUM_ALLOWED;
237 s->opengroup.out.group_handle = &s->group_handle;
239 /* send rpc request */
240 subreq = dcerpc_samr_OpenGroup_r_send(s, c->event_ctx,
241 s->pipe->binding_handle,
242 &s->opengroup);
243 if (composite_nomem(subreq, c)) return;
245 tevent_req_set_callback(subreq, continue_groupdel_group_opened, c);
249 static void continue_groupdel_group_opened(struct tevent_req *subreq)
251 struct composite_context *c;
252 struct groupdel_state *s;
254 c = tevent_req_callback_data(subreq, struct composite_context);
255 s = talloc_get_type(c->private_data, struct groupdel_state);
257 /* receive samr_OpenGroup result */
258 c->status = dcerpc_samr_OpenGroup_r_recv(subreq, s);
259 TALLOC_FREE(subreq);
260 if (!composite_is_ok(c)) return;
262 c->status = s->opengroup.out.result;
263 if (!NT_STATUS_IS_OK(c->status)) {
264 composite_error(c, c->status);
265 return;
268 /* prepare the final rpc call arguments */
269 s->deletegroup.in.group_handle = &s->group_handle;
270 s->deletegroup.out.group_handle = &s->group_handle;
272 /* send rpc request */
273 subreq = dcerpc_samr_DeleteDomainGroup_r_send(s, c->event_ctx,
274 s->pipe->binding_handle,
275 &s->deletegroup);
276 if (composite_nomem(subreq, c)) return;
278 /* callback handler setup */
279 tevent_req_set_callback(subreq, continue_groupdel_deleted, c);
283 static void continue_groupdel_deleted(struct tevent_req *subreq)
285 struct composite_context *c;
286 struct groupdel_state *s;
288 c = tevent_req_callback_data(subreq, struct composite_context);
289 s = talloc_get_type(c->private_data, struct groupdel_state);
291 /* receive samr_DeleteGroup result */
292 c->status = dcerpc_samr_DeleteDomainGroup_r_recv(subreq, s);
293 TALLOC_FREE(subreq);
294 if (!composite_is_ok(c)) return;
296 /* return the actual function call status */
297 c->status = s->deletegroup.out.result;
298 if (!NT_STATUS_IS_OK(c->status)) {
299 composite_error(c, c->status);
300 return;
303 composite_done(c);
307 NTSTATUS libnet_rpc_groupdel_recv(struct composite_context *c, TALLOC_CTX *mem_ctx,
308 struct libnet_rpc_groupdel *io)
310 NTSTATUS status;
311 struct groupdel_state *s;
313 status = composite_wait(c);
314 if (NT_STATUS_IS_OK(status) && io) {
315 s = talloc_get_type(c->private_data, struct groupdel_state);
316 io->out.group_handle = s->group_handle;
319 talloc_free(c);
320 return status;
324 NTSTATUS libnet_rpc_groupdel(struct dcerpc_pipe *p, TALLOC_CTX *mem_ctx,
325 struct libnet_rpc_groupdel *io)
327 struct composite_context *c;
329 c = libnet_rpc_groupdel_send(p, mem_ctx, io, NULL);
330 return libnet_rpc_groupdel_recv(c, mem_ctx, io);