2 * Unit tests for lsa functions
4 * Copyright (c) 2006 Robert Reif
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2.1 of the License, or (at your option) any later version.
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
25 #define WIN32_NO_STATUS
34 #include "wine/test.h"
36 DEFINE_GUID(GUID_NULL
,0,0,0,0,0,0,0,0,0,0,0);
38 static HMODULE hadvapi32
;
39 static NTSTATUS (WINAPI
*pLsaClose
)(LSA_HANDLE
);
40 static NTSTATUS (WINAPI
*pLsaEnumerateAccountRights
)(LSA_HANDLE
,PSID
,PLSA_UNICODE_STRING
*,PULONG
);
41 static NTSTATUS (WINAPI
*pLsaFreeMemory
)(PVOID
);
42 static NTSTATUS (WINAPI
*pLsaOpenPolicy
)(PLSA_UNICODE_STRING
,PLSA_OBJECT_ATTRIBUTES
,ACCESS_MASK
,PLSA_HANDLE
);
43 static NTSTATUS (WINAPI
*pLsaQueryInformationPolicy
)(LSA_HANDLE
,POLICY_INFORMATION_CLASS
,PVOID
*);
44 static BOOL (WINAPI
*pConvertSidToStringSidA
)(PSID
,LPSTR
*);
45 static BOOL (WINAPI
*pConvertStringSidToSidA
)(LPCSTR
,PSID
*);
46 static NTSTATUS (WINAPI
*pLsaLookupNames2
)(LSA_HANDLE
,ULONG
,ULONG
,PLSA_UNICODE_STRING
,PLSA_REFERENCED_DOMAIN_LIST
*,PLSA_TRANSLATED_SID2
*);
47 static NTSTATUS (WINAPI
*pLsaLookupSids
)(LSA_HANDLE
,ULONG
,PSID
*,LSA_REFERENCED_DOMAIN_LIST
**,LSA_TRANSLATED_NAME
**);
48 static PVOID (WINAPI
*pFreeSid
)(PSID
);
50 static BOOL
init(void)
52 hadvapi32
= GetModuleHandleA("advapi32.dll");
54 pLsaClose
= (void*)GetProcAddress(hadvapi32
, "LsaClose");
55 pLsaEnumerateAccountRights
= (void*)GetProcAddress(hadvapi32
, "LsaEnumerateAccountRights");
56 pLsaFreeMemory
= (void*)GetProcAddress(hadvapi32
, "LsaFreeMemory");
57 pLsaOpenPolicy
= (void*)GetProcAddress(hadvapi32
, "LsaOpenPolicy");
58 pLsaQueryInformationPolicy
= (void*)GetProcAddress(hadvapi32
, "LsaQueryInformationPolicy");
59 pConvertSidToStringSidA
= (void*)GetProcAddress(hadvapi32
, "ConvertSidToStringSidA");
60 pConvertStringSidToSidA
= (void*)GetProcAddress(hadvapi32
, "ConvertStringSidToSidA");
61 pLsaLookupNames2
= (void*)GetProcAddress(hadvapi32
, "LsaLookupNames2");
62 pLsaLookupSids
= (void*)GetProcAddress(hadvapi32
, "LsaLookupSids");
63 pFreeSid
= (void*)GetProcAddress(hadvapi32
, "FreeSid");
65 if (pLsaClose
&& pLsaEnumerateAccountRights
&& pLsaFreeMemory
&& pLsaOpenPolicy
&& pLsaQueryInformationPolicy
&& pConvertSidToStringSidA
&& pConvertStringSidToSidA
&& pFreeSid
)
71 static void test_lsa(void)
75 LSA_OBJECT_ATTRIBUTES object_attributes
;
77 ZeroMemory(&object_attributes
, sizeof(object_attributes
));
78 object_attributes
.Length
= sizeof(object_attributes
);
80 status
= pLsaOpenPolicy( NULL
, &object_attributes
, POLICY_ALL_ACCESS
, &handle
);
81 ok(status
== STATUS_SUCCESS
|| status
== STATUS_ACCESS_DENIED
,
82 "LsaOpenPolicy(POLICY_ALL_ACCESS) returned 0x%08x\n", status
);
84 /* try a more restricted access mask if necessary */
85 if (status
== STATUS_ACCESS_DENIED
) {
86 trace("LsaOpenPolicy(POLICY_ALL_ACCESS) failed, trying POLICY_VIEW_LOCAL_INFORMATION|POLICY_LOOKUP_NAMES\n");
87 status
= pLsaOpenPolicy( NULL
, &object_attributes
, POLICY_VIEW_LOCAL_INFORMATION
|POLICY_LOOKUP_NAMES
, &handle
);
88 ok(status
== STATUS_SUCCESS
, "LsaOpenPolicy(POLICY_VIEW_LOCAL_INFORMATION|POLICY_LOOKUP_NAMES) returned 0x%08x\n", status
);
91 if (status
== STATUS_SUCCESS
) {
92 PPOLICY_AUDIT_EVENTS_INFO audit_events_info
;
93 PPOLICY_PRIMARY_DOMAIN_INFO primary_domain_info
;
94 PPOLICY_ACCOUNT_DOMAIN_INFO account_domain_info
;
95 PPOLICY_DNS_DOMAIN_INFO dns_domain_info
;
99 status
= pLsaQueryInformationPolicy(handle
, PolicyAuditEventsInformation
, (PVOID
*)&audit_events_info
);
100 if (status
== STATUS_ACCESS_DENIED
)
101 skip("Not enough rights to retrieve PolicyAuditEventsInformation\n");
103 ok(status
== STATUS_SUCCESS
, "LsaQueryInformationPolicy(PolicyAuditEventsInformation) failed, returned 0x%08x\n", status
);
104 if (status
== STATUS_SUCCESS
) {
105 pLsaFreeMemory((LPVOID
)audit_events_info
);
108 status
= pLsaQueryInformationPolicy(handle
, PolicyPrimaryDomainInformation
, (PVOID
*)&primary_domain_info
);
109 ok(status
== STATUS_SUCCESS
, "LsaQueryInformationPolicy(PolicyPrimaryDomainInformation) failed, returned 0x%08x\n", status
);
110 if (status
== STATUS_SUCCESS
) {
111 if (primary_domain_info
->Sid
) {
113 if (pConvertSidToStringSidA(primary_domain_info
->Sid
, &strsid
))
115 if (primary_domain_info
->Name
.Buffer
) {
118 len
= WideCharToMultiByte( CP_ACP
, 0, primary_domain_info
->Name
.Buffer
, -1, NULL
, 0, NULL
, NULL
);
119 name
= LocalAlloc( 0, len
);
120 WideCharToMultiByte( CP_ACP
, 0, primary_domain_info
->Name
.Buffer
, -1, name
, len
, NULL
, NULL
);
121 trace(" name: %s sid: %s\n", name
, strsid
);
124 trace(" name: NULL sid: %s\n", strsid
);
128 trace("invalid sid\n");
131 trace("Running on a standalone system.\n");
132 pLsaFreeMemory((LPVOID
)primary_domain_info
);
135 status
= pLsaQueryInformationPolicy(handle
, PolicyAccountDomainInformation
, (PVOID
*)&account_domain_info
);
136 ok(status
== STATUS_SUCCESS
, "LsaQueryInformationPolicy(PolicyAccountDomainInformation) failed, returned 0x%08x\n", status
);
137 if (status
== STATUS_SUCCESS
) {
138 pLsaFreeMemory((LPVOID
)account_domain_info
);
141 /* This isn't supported in NT4 */
142 status
= pLsaQueryInformationPolicy(handle
, PolicyDnsDomainInformation
, (PVOID
*)&dns_domain_info
);
143 ok(status
== STATUS_SUCCESS
|| status
== STATUS_INVALID_PARAMETER
,
144 "LsaQueryInformationPolicy(PolicyDnsDomainInformation) failed, returned 0x%08x\n", status
);
145 if (status
== STATUS_SUCCESS
) {
146 if (dns_domain_info
->Sid
|| !IsEqualGUID(&dns_domain_info
->DomainGuid
, &GUID_NULL
)) {
151 LPSTR guidstr
= NULL
;
155 pConvertSidToStringSidA(dns_domain_info
->Sid
, &strsid
);
156 StringFromGUID2(&dns_domain_info
->DomainGuid
, guidstrW
, sizeof(guidstrW
)/sizeof(WCHAR
));
157 len
= WideCharToMultiByte( CP_ACP
, 0, guidstrW
, -1, NULL
, 0, NULL
, NULL
);
158 guidstr
= LocalAlloc( 0, len
);
159 WideCharToMultiByte( CP_ACP
, 0, guidstrW
, -1, guidstr
, len
, NULL
, NULL
);
160 if (dns_domain_info
->Name
.Buffer
) {
161 len
= WideCharToMultiByte( CP_ACP
, 0, dns_domain_info
->Name
.Buffer
, -1, NULL
, 0, NULL
, NULL
);
162 name
= LocalAlloc( 0, len
);
163 WideCharToMultiByte( CP_ACP
, 0, dns_domain_info
->Name
.Buffer
, -1, name
, len
, NULL
, NULL
);
165 if (dns_domain_info
->DnsDomainName
.Buffer
) {
166 len
= WideCharToMultiByte( CP_ACP
, 0, dns_domain_info
->DnsDomainName
.Buffer
, -1, NULL
, 0, NULL
, NULL
);
167 domain
= LocalAlloc( 0, len
);
168 WideCharToMultiByte( CP_ACP
, 0, dns_domain_info
->DnsDomainName
.Buffer
, -1, domain
, len
, NULL
, NULL
);
170 if (dns_domain_info
->DnsForestName
.Buffer
) {
171 len
= WideCharToMultiByte( CP_ACP
, 0, dns_domain_info
->DnsForestName
.Buffer
, -1, NULL
, 0, NULL
, NULL
);
172 forest
= LocalAlloc( 0, len
);
173 WideCharToMultiByte( CP_ACP
, 0, dns_domain_info
->DnsForestName
.Buffer
, -1, forest
, len
, NULL
, NULL
);
175 trace(" name: %s domain: %s forest: %s guid: %s sid: %s\n",
176 name
? name
: "NULL", domain
? domain
: "NULL",
177 forest
? forest
: "NULL", guidstr
, strsid
? strsid
: "NULL");
181 LocalFree( guidstr
);
185 trace("Running on a standalone system.\n");
186 pLsaFreeMemory((LPVOID
)dns_domain_info
);
189 /* We need a valid SID to pass to LsaEnumerateAccountRights */
190 ret
= OpenProcessToken( GetCurrentProcess(), TOKEN_QUERY
, &token
);
191 ok(ret
, "Unable to obtain process token, error %u\n", GetLastError( ));
195 TOKEN_USER
*token_user
= (TOKEN_USER
*) buffer
;
196 ret
= GetTokenInformation( token
, TokenUser
, (LPVOID
) token_user
, sizeof(buffer
), &len
);
197 ok(ret
|| GetLastError( ) == ERROR_INSUFFICIENT_BUFFER
, "Unable to obtain token information, error %u\n", GetLastError( ));
198 if (! ret
&& GetLastError( ) == ERROR_INSUFFICIENT_BUFFER
) {
199 trace("Resizing buffer to %u.\n", len
);
200 token_user
= LocalAlloc( 0, len
);
201 if (token_user
!= NULL
)
202 ret
= GetTokenInformation( token
, TokenUser
, (LPVOID
) token_user
, len
, &len
);
206 PLSA_UNICODE_STRING rights
;
208 rights
= (PLSA_UNICODE_STRING
) 0xdeadbeaf;
209 rights_count
= 0xcafecafe;
210 status
= pLsaEnumerateAccountRights(handle
, token_user
->User
.Sid
, &rights
, &rights_count
);
211 ok(status
== STATUS_SUCCESS
|| status
== STATUS_OBJECT_NAME_NOT_FOUND
, "Unexpected status 0x%x\n", status
);
212 if (status
== STATUS_SUCCESS
)
213 pLsaFreeMemory( rights
);
215 ok(rights
== NULL
&& rights_count
== 0, "Expected rights and rights_count to be set to 0 on failure\n");
217 if (token_user
!= NULL
&& token_user
!= (TOKEN_USER
*) buffer
)
218 LocalFree( token_user
);
219 CloseHandle( token
);
222 status
= pLsaClose(handle
);
223 ok(status
== STATUS_SUCCESS
, "LsaClose() failed, returned 0x%08x\n", status
);
227 static void get_sid_info(PSID psid
, LPSTR
*user
, LPSTR
*dom
)
229 static char account
[257], domain
[257];
230 DWORD user_size
, dom_size
;
237 user_size
= dom_size
= 257;
238 account
[0] = domain
[0] = 0;
239 ret
= LookupAccountSidA(NULL
, psid
, account
, &user_size
, domain
, &dom_size
, &use
);
240 ok(ret
, "LookupAccountSidA failed %u\n", GetLastError());
243 static void test_LsaLookupNames2(void)
245 static const WCHAR n1
[] = {'L','O','C','A','L',' ','S','E','R','V','I','C','E'};
246 static const WCHAR n2
[] = {'N','T',' ','A','U','T','H','O','R','I','T','Y','\\','L','o','c','a','l','S','e','r','v','i','c','e'};
250 LSA_OBJECT_ATTRIBUTES attrs
;
251 PLSA_REFERENCED_DOMAIN_LIST domains
;
252 PLSA_TRANSLATED_SID2 sids
;
253 LSA_UNICODE_STRING name
[3];
254 LPSTR account
, sid_dom
;
256 if (!pLsaLookupNames2
)
258 win_skip("LsaLookupNames2 not available\n");
262 if ((PRIMARYLANGID(LANGIDFROMLCID(GetSystemDefaultLCID())) != LANG_ENGLISH
) ||
263 (PRIMARYLANGID(LANGIDFROMLCID(GetThreadLocale())) != LANG_ENGLISH
))
265 skip("Non-English locale (skipping LsaLookupNames2 tests)\n");
269 memset(&attrs
, 0, sizeof(attrs
));
270 attrs
.Length
= sizeof(attrs
);
272 status
= pLsaOpenPolicy(NULL
, &attrs
, POLICY_ALL_ACCESS
, &handle
);
273 ok(status
== STATUS_SUCCESS
|| status
== STATUS_ACCESS_DENIED
,
274 "LsaOpenPolicy(POLICY_ALL_ACCESS) returned 0x%08x\n", status
);
276 /* try a more restricted access mask if necessary */
277 if (status
== STATUS_ACCESS_DENIED
)
279 trace("LsaOpenPolicy(POLICY_ALL_ACCESS) failed, trying POLICY_VIEW_LOCAL_INFORMATION\n");
280 status
= pLsaOpenPolicy(NULL
, &attrs
, POLICY_LOOKUP_NAMES
, &handle
);
281 ok(status
== STATUS_SUCCESS
, "LsaOpenPolicy(POLICY_VIEW_LOCAL_INFORMATION) returned 0x%08x\n", status
);
283 if (status
!= STATUS_SUCCESS
)
285 skip("Cannot acquire policy handle\n");
289 name
[0].Buffer
= HeapAlloc(GetProcessHeap(), 0, sizeof(n1
));
290 name
[0].Length
= name
[0].MaximumLength
= sizeof(n1
);
291 memcpy(name
[0].Buffer
, n1
, sizeof(n1
));
293 name
[1].Buffer
= HeapAlloc(GetProcessHeap(), 0, sizeof(n1
));
294 name
[1].Length
= name
[1].MaximumLength
= sizeof(n1
) - sizeof(WCHAR
);
295 memcpy(name
[1].Buffer
, n1
, sizeof(n1
) - sizeof(WCHAR
));
297 name
[2].Buffer
= HeapAlloc(GetProcessHeap(), 0, sizeof(n2
));
298 name
[2].Length
= name
[2].MaximumLength
= sizeof(n2
);
299 memcpy(name
[2].Buffer
, n2
, sizeof(n2
));
301 /* account name only */
304 status
= pLsaLookupNames2(handle
, 0, 1, &name
[0], &domains
, &sids
);
305 ok(status
== STATUS_SUCCESS
, "expected STATUS_SUCCESS, got %x)\n", status
);
306 ok(sids
[0].Use
== SidTypeWellKnownGroup
, "expected SidTypeWellKnownGroup, got %u\n", sids
[0].Use
);
307 ok(sids
[0].Flags
== 0, "expected 0, got 0x%08x\n", sids
[0].Flags
);
308 ok(domains
->Entries
== 1, "expected 1, got %u\n", domains
->Entries
);
309 get_sid_info(sids
[0].Sid
, &account
, &sid_dom
);
310 ok(!strcmp(account
, "LOCAL SERVICE"), "expected \"LOCAL SERVICE\", got \"%s\"\n", account
);
311 ok(!strcmp(sid_dom
, "NT AUTHORITY"), "expected \"NT AUTHORITY\", got \"%s\"\n", sid_dom
);
312 pLsaFreeMemory(sids
);
313 pLsaFreeMemory(domains
);
315 /* unknown account name */
318 status
= pLsaLookupNames2(handle
, 0, 1, &name
[1], &domains
, &sids
);
319 ok(status
== STATUS_NONE_MAPPED
, "expected STATUS_NONE_MAPPED, got %x)\n", status
);
320 ok(sids
[0].Use
== SidTypeUnknown
, "expected SidTypeUnknown, got %u\n", sids
[0].Use
);
321 ok(sids
[0].Flags
== 0, "expected 0, got 0x%08x\n", sids
[0].Flags
);
322 ok(domains
->Entries
== 0, "expected 0, got %u\n", domains
->Entries
);
323 pLsaFreeMemory(sids
);
324 pLsaFreeMemory(domains
);
326 /* account + domain */
329 status
= pLsaLookupNames2(handle
, 0, 1, &name
[2], &domains
, &sids
);
330 ok(status
== STATUS_SUCCESS
, "expected STATUS_SUCCESS, got %x)\n", status
);
331 ok(sids
[0].Use
== SidTypeWellKnownGroup
, "expected SidTypeWellKnownGroup, got %u\n", sids
[0].Use
);
332 ok(sids
[0].Flags
== 0, "expected 0, got 0x%08x\n", sids
[0].Flags
);
333 ok(domains
->Entries
== 1, "expected 1, got %u\n", domains
->Entries
);
334 get_sid_info(sids
[0].Sid
, &account
, &sid_dom
);
335 ok(!strcmp(account
, "LOCAL SERVICE"), "expected \"LOCAL SERVICE\", got \"%s\"\n", account
);
336 ok(!strcmp(sid_dom
, "NT AUTHORITY"), "expected \"NT AUTHORITY\", got \"%s\"\n", sid_dom
);
337 pLsaFreeMemory(sids
);
338 pLsaFreeMemory(domains
);
343 status
= pLsaLookupNames2(handle
, 0, 3, name
, &domains
, &sids
);
344 ok(status
== STATUS_SOME_NOT_MAPPED
, "expected STATUS_SOME_NOT_MAPPED, got %x)\n", status
);
345 ok(sids
[0].Use
== SidTypeWellKnownGroup
, "expected SidTypeWellKnownGroup, got %u\n", sids
[0].Use
);
346 ok(sids
[1].Use
== SidTypeUnknown
, "expected SidTypeUnknown, got %u\n", sids
[1].Use
);
347 ok(sids
[2].Use
== SidTypeWellKnownGroup
, "expected SidTypeWellKnownGroup, got %u\n", sids
[2].Use
);
348 ok(sids
[0].DomainIndex
== 0, "expected 0, got %u\n", sids
[0].DomainIndex
);
349 ok(domains
->Entries
== 1, "expected 1, got %u\n", domains
->Entries
);
350 pLsaFreeMemory(sids
);
351 pLsaFreeMemory(domains
);
353 HeapFree(GetProcessHeap(), 0, name
[0].Buffer
);
354 HeapFree(GetProcessHeap(), 0, name
[1].Buffer
);
355 HeapFree(GetProcessHeap(), 0, name
[2].Buffer
);
357 status
= pLsaClose(handle
);
358 ok(status
== STATUS_SUCCESS
, "LsaClose() failed, returned 0x%08x\n", status
);
361 static void test_LsaLookupSids(void)
363 LSA_REFERENCED_DOMAIN_LIST
*list
;
364 LSA_OBJECT_ATTRIBUTES attrs
;
365 LSA_TRANSLATED_NAME
*names
;
373 memset(&attrs
, 0, sizeof(attrs
));
374 attrs
.Length
= sizeof(attrs
);
376 status
= pLsaOpenPolicy(NULL
, &attrs
, POLICY_LOOKUP_NAMES
, &policy
);
377 ok(status
== STATUS_SUCCESS
, "got 0x%08x\n", status
);
379 ret
= OpenProcessToken(GetCurrentProcess(), MAXIMUM_ALLOWED
, &token
);
380 ok(ret
, "got %d\n", ret
);
382 ret
= GetTokenInformation(token
, TokenUser
, NULL
, 0, &size
);
383 ok(!ret
, "got %d\n", ret
);
385 user
= HeapAlloc(GetProcessHeap(), 0, size
);
386 ret
= GetTokenInformation(token
, TokenUser
, user
, size
, &size
);
387 ok(ret
, "got %d\n", ret
);
389 status
= pLsaLookupSids(policy
, 1, &user
->User
.Sid
, &list
, &names
);
390 ok(status
== STATUS_SUCCESS
, "got 0x%08x\n", status
);
392 ok(list
->Entries
> 0, "got %d\n", list
->Entries
);
395 ok((char*)list
->Domains
- (char*)list
> 0, "%p, %p\n", list
, list
->Domains
);
396 ok((char*)list
->Domains
[0].Sid
- (char*)list
->Domains
> 0, "%p, %p\n", list
->Domains
, list
->Domains
[0].Sid
);
397 ok(list
->Domains
[0].Name
.MaximumLength
> list
->Domains
[0].Name
.Length
, "got %d, %d\n", list
->Domains
[0].Name
.MaximumLength
,
398 list
->Domains
[0].Name
.Length
);
401 pLsaFreeMemory(names
);
402 pLsaFreeMemory(list
);
404 HeapFree(GetProcessHeap(), 0, user
);
408 status
= pLsaClose(policy
);
409 ok(status
== STATUS_SUCCESS
, "got 0x%08x\n", status
);
412 static void test_LsaLookupSids_NullBuffers(void)
414 LSA_REFERENCED_DOMAIN_LIST
*list
;
415 LSA_OBJECT_ATTRIBUTES attrs
;
416 LSA_TRANSLATED_NAME
*names
;
422 memset(&attrs
, 0, sizeof(attrs
));
423 attrs
.Length
= sizeof(attrs
);
425 status
= pLsaOpenPolicy(NULL
, &attrs
, POLICY_LOOKUP_NAMES
, &policy
);
426 ok(status
== STATUS_SUCCESS
, "got 0x%08x\n", status
);
428 ret
= pConvertStringSidToSidA("S-1-1-0", &sid
);
429 ok(ret
== TRUE
, "pConvertStringSidToSidA returned false\n");
431 status
= pLsaLookupSids(policy
, 1, &sid
, &list
, &names
);
432 ok(status
== STATUS_SUCCESS
, "got 0x%08x\n", status
);
434 ok(list
->Entries
> 0, "got %d\n", list
->Entries
);
438 ok((char*)list
->Domains
- (char*)list
> 0, "%p, %p\n", list
, list
->Domains
);
439 ok((char*)list
->Domains
[0].Sid
- (char*)list
->Domains
> 0, "%p, %p\n", list
->Domains
, list
->Domains
[0].Sid
);
440 ok(list
->Domains
[0].Name
.MaximumLength
> list
->Domains
[0].Name
.Length
, "got %d, %d\n", list
->Domains
[0].Name
.MaximumLength
,
441 list
->Domains
[0].Name
.Length
);
442 ok(list
->Domains
[0].Name
.Buffer
!= NULL
, "domain[0] name buffer is null\n");
445 pLsaFreeMemory(names
);
446 pLsaFreeMemory(list
);
450 status
= pLsaClose(policy
);
451 ok(status
== STATUS_SUCCESS
, "got 0x%08x\n", status
);
457 win_skip("Needed functions are not available\n");
462 test_LsaLookupNames2();
463 test_LsaLookupSids();
464 test_LsaLookupSids_NullBuffers();