2005-09-08 00:09:32 +00:00
|
|
|
/*
|
|
|
|
* COPYRIGHT: See COPYING in the top level directory
|
|
|
|
* PROJECT: ReactOS system libraries
|
|
|
|
* FILE: lib/rtl/security.c
|
|
|
|
* PURPOSE: Security related functions and Security Objects
|
|
|
|
* PROGRAMMER: Eric Kohl
|
2004-05-31 19:33:59 +00:00
|
|
|
*/
|
|
|
|
|
2005-09-08 00:09:32 +00:00
|
|
|
/* INCLUDES *****************************************************************/
|
|
|
|
|
2005-07-26 08:39:07 +00:00
|
|
|
#include <rtl.h>
|
2004-05-31 19:33:59 +00:00
|
|
|
|
|
|
|
#define NDEBUG
|
|
|
|
#include <debug.h>
|
|
|
|
|
2005-09-08 00:09:32 +00:00
|
|
|
/* FUNCTIONS ***************************************************************/
|
2004-05-31 19:33:59 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* @implemented
|
|
|
|
*/
|
2005-10-19 17:03:38 +00:00
|
|
|
NTSTATUS NTAPI
|
2004-05-31 19:33:59 +00:00
|
|
|
RtlImpersonateSelf(IN SECURITY_IMPERSONATION_LEVEL ImpersonationLevel)
|
|
|
|
{
|
|
|
|
HANDLE ProcessToken;
|
|
|
|
HANDLE ImpersonationToken;
|
|
|
|
NTSTATUS Status;
|
2004-12-14 00:41:24 +00:00
|
|
|
OBJECT_ATTRIBUTES ObjAttr;
|
2005-02-22 17:58:19 +00:00
|
|
|
SECURITY_QUALITY_OF_SERVICE Sqos;
|
|
|
|
|
|
|
|
PAGED_CODE_RTL();
|
2005-05-09 01:41:02 +00:00
|
|
|
|
2005-09-22 23:23:00 +00:00
|
|
|
Status = ZwOpenProcessToken(NtCurrentProcess(),
|
2004-05-31 19:33:59 +00:00
|
|
|
TOKEN_DUPLICATE,
|
|
|
|
&ProcessToken);
|
|
|
|
if (!NT_SUCCESS(Status))
|
2004-07-13 11:52:09 +00:00
|
|
|
{
|
|
|
|
DPRINT1("NtOpenProcessToken() failed (Status %lx)\n", Status);
|
2004-05-31 19:33:59 +00:00
|
|
|
return(Status);
|
2004-07-13 11:52:09 +00:00
|
|
|
}
|
2005-05-09 01:41:02 +00:00
|
|
|
|
2004-12-14 00:41:24 +00:00
|
|
|
Sqos.Length = sizeof(SECURITY_QUALITY_OF_SERVICE);
|
|
|
|
Sqos.ImpersonationLevel = ImpersonationLevel;
|
|
|
|
Sqos.ContextTrackingMode = 0;
|
|
|
|
Sqos.EffectiveOnly = FALSE;
|
2005-05-09 01:41:02 +00:00
|
|
|
|
2004-12-14 00:41:24 +00:00
|
|
|
InitializeObjectAttributes(
|
|
|
|
&ObjAttr,
|
|
|
|
NULL,
|
|
|
|
0,
|
|
|
|
NULL,
|
|
|
|
NULL
|
|
|
|
);
|
2005-05-09 01:41:02 +00:00
|
|
|
|
2004-12-14 00:41:24 +00:00
|
|
|
ObjAttr.SecurityQualityOfService = &Sqos;
|
2005-05-09 01:41:02 +00:00
|
|
|
|
2005-09-22 23:23:00 +00:00
|
|
|
Status = ZwDuplicateToken(ProcessToken,
|
2004-05-31 19:33:59 +00:00
|
|
|
TOKEN_IMPERSONATE,
|
2004-12-14 00:41:24 +00:00
|
|
|
&ObjAttr,
|
|
|
|
Sqos.EffectiveOnly, /* why both here _and_ in Sqos? */
|
2004-05-31 19:33:59 +00:00
|
|
|
TokenImpersonation,
|
|
|
|
&ImpersonationToken);
|
|
|
|
if (!NT_SUCCESS(Status))
|
|
|
|
{
|
2004-07-13 11:52:09 +00:00
|
|
|
DPRINT1("NtDuplicateToken() failed (Status %lx)\n", Status);
|
2004-05-31 19:33:59 +00:00
|
|
|
NtClose(ProcessToken);
|
|
|
|
return(Status);
|
|
|
|
}
|
|
|
|
|
2005-09-22 23:23:00 +00:00
|
|
|
Status = ZwSetInformationThread(NtCurrentThread(),
|
2004-05-31 19:33:59 +00:00
|
|
|
ThreadImpersonationToken,
|
|
|
|
&ImpersonationToken,
|
|
|
|
sizeof(HANDLE));
|
2004-07-13 11:52:09 +00:00
|
|
|
if (!NT_SUCCESS(Status))
|
|
|
|
{
|
|
|
|
DPRINT1("NtSetInformationThread() failed (Status %lx)\n", Status);
|
|
|
|
}
|
|
|
|
|
2005-09-22 23:23:00 +00:00
|
|
|
ZwClose(ImpersonationToken);
|
|
|
|
ZwClose(ProcessToken);
|
2004-05-31 19:33:59 +00:00
|
|
|
|
|
|
|
return(Status);
|
|
|
|
}
|
|
|
|
|
2008-09-12 15:09:17 +00:00
|
|
|
/*
|
|
|
|
* @unimplemented
|
|
|
|
*/
|
|
|
|
NTSTATUS
|
|
|
|
NTAPI
|
|
|
|
RtlAcquirePrivilege(IN PULONG Privilege,
|
|
|
|
IN ULONG NumPriv,
|
|
|
|
IN ULONG Flags,
|
|
|
|
OUT PVOID *ReturnedState)
|
|
|
|
{
|
|
|
|
UNIMPLEMENTED;
|
|
|
|
return STATUS_NOT_IMPLEMENTED;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* @unimplemented
|
|
|
|
*/
|
|
|
|
VOID
|
|
|
|
NTAPI
|
|
|
|
RtlReleasePrivilege(IN PVOID ReturnedState)
|
|
|
|
{
|
|
|
|
UNIMPLEMENTED;
|
|
|
|
}
|
2004-05-31 19:33:59 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* @implemented
|
|
|
|
*/
|
2005-10-19 17:03:38 +00:00
|
|
|
NTSTATUS NTAPI
|
2004-05-31 19:33:59 +00:00
|
|
|
RtlAdjustPrivilege(IN ULONG Privilege,
|
|
|
|
IN BOOLEAN Enable,
|
|
|
|
IN BOOLEAN CurrentThread,
|
|
|
|
OUT PBOOLEAN Enabled)
|
|
|
|
{
|
|
|
|
TOKEN_PRIVILEGES NewState;
|
|
|
|
TOKEN_PRIVILEGES OldState;
|
|
|
|
ULONG ReturnLength;
|
|
|
|
HANDLE TokenHandle;
|
|
|
|
NTSTATUS Status;
|
2005-05-09 01:41:02 +00:00
|
|
|
|
2005-02-22 17:58:19 +00:00
|
|
|
PAGED_CODE_RTL();
|
2004-05-31 19:33:59 +00:00
|
|
|
|
|
|
|
DPRINT ("RtlAdjustPrivilege() called\n");
|
|
|
|
|
|
|
|
if (CurrentThread)
|
|
|
|
{
|
2005-09-22 23:23:00 +00:00
|
|
|
Status = ZwOpenThreadToken (NtCurrentThread (),
|
2004-05-31 19:33:59 +00:00
|
|
|
TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY,
|
|
|
|
FALSE,
|
|
|
|
&TokenHandle);
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2005-09-22 23:23:00 +00:00
|
|
|
Status = ZwOpenProcessToken (NtCurrentProcess (),
|
2004-05-31 19:33:59 +00:00
|
|
|
TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY,
|
|
|
|
&TokenHandle);
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!NT_SUCCESS (Status))
|
|
|
|
{
|
|
|
|
DPRINT1 ("Retrieving token handle failed (Status %lx)\n", Status);
|
|
|
|
return Status;
|
|
|
|
}
|
|
|
|
|
|
|
|
OldState.PrivilegeCount = 1;
|
|
|
|
|
|
|
|
NewState.PrivilegeCount = 1;
|
|
|
|
NewState.Privileges[0].Luid.LowPart = Privilege;
|
|
|
|
NewState.Privileges[0].Luid.HighPart = 0;
|
|
|
|
NewState.Privileges[0].Attributes = (Enable) ? SE_PRIVILEGE_ENABLED : 0;
|
|
|
|
|
2005-09-22 23:23:00 +00:00
|
|
|
Status = ZwAdjustPrivilegesToken (TokenHandle,
|
2004-05-31 19:33:59 +00:00
|
|
|
FALSE,
|
|
|
|
&NewState,
|
|
|
|
sizeof(TOKEN_PRIVILEGES),
|
|
|
|
&OldState,
|
|
|
|
&ReturnLength);
|
2005-09-22 23:23:00 +00:00
|
|
|
ZwClose (TokenHandle);
|
2004-05-31 19:33:59 +00:00
|
|
|
if (Status == STATUS_NOT_ALL_ASSIGNED)
|
|
|
|
{
|
|
|
|
DPRINT1 ("Failed to assign all privileges\n");
|
|
|
|
return STATUS_PRIVILEGE_NOT_HELD;
|
|
|
|
}
|
|
|
|
if (!NT_SUCCESS(Status))
|
|
|
|
{
|
|
|
|
DPRINT1 ("NtAdjustPrivilegesToken() failed (Status %lx)\n", Status);
|
|
|
|
return Status;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (OldState.PrivilegeCount == 0)
|
|
|
|
{
|
|
|
|
*Enabled = Enable;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
*Enabled = (OldState.Privileges[0].Attributes & SE_PRIVILEGE_ENABLED);
|
|
|
|
}
|
|
|
|
|
|
|
|
DPRINT ("RtlAdjustPrivilege() done\n");
|
|
|
|
|
|
|
|
return STATUS_SUCCESS;
|
|
|
|
}
|
|
|
|
|
2005-09-08 00:09:32 +00:00
|
|
|
/*
|
|
|
|
* @implemented
|
|
|
|
*/
|
|
|
|
NTSTATUS
|
2005-10-19 17:03:38 +00:00
|
|
|
NTAPI
|
2005-09-08 00:09:32 +00:00
|
|
|
RtlDeleteSecurityObject(IN PSECURITY_DESCRIPTOR *ObjectDescriptor)
|
|
|
|
{
|
|
|
|
DPRINT("RtlDeleteSecurityObject(%p)\n", ObjectDescriptor);
|
|
|
|
|
|
|
|
RtlFreeHeap(RtlGetProcessHeap(),
|
|
|
|
0,
|
|
|
|
*ObjectDescriptor);
|
|
|
|
|
|
|
|
return STATUS_SUCCESS;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* @unimplemented
|
|
|
|
*/
|
|
|
|
NTSTATUS
|
2005-10-19 17:03:38 +00:00
|
|
|
NTAPI
|
2005-09-08 00:09:32 +00:00
|
|
|
RtlNewSecurityObject(IN PSECURITY_DESCRIPTOR ParentDescriptor,
|
|
|
|
IN PSECURITY_DESCRIPTOR CreatorDescriptor,
|
|
|
|
OUT PSECURITY_DESCRIPTOR *NewDescriptor,
|
|
|
|
IN BOOLEAN IsDirectoryObject,
|
|
|
|
IN HANDLE Token,
|
|
|
|
IN PGENERIC_MAPPING GenericMapping)
|
|
|
|
{
|
|
|
|
UNIMPLEMENTED;
|
|
|
|
return STATUS_NOT_IMPLEMENTED;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* @unimplemented
|
|
|
|
*/
|
|
|
|
NTSTATUS
|
2005-10-19 17:03:38 +00:00
|
|
|
NTAPI
|
2005-09-08 00:09:32 +00:00
|
|
|
RtlQuerySecurityObject(IN PSECURITY_DESCRIPTOR ObjectDescriptor,
|
|
|
|
IN SECURITY_INFORMATION SecurityInformation,
|
|
|
|
OUT PSECURITY_DESCRIPTOR ResultantDescriptor,
|
|
|
|
IN ULONG DescriptorLength,
|
|
|
|
OUT PULONG ReturnLength)
|
|
|
|
{
|
2009-01-02 23:52:37 +00:00
|
|
|
NTSTATUS Status;
|
|
|
|
SECURITY_DESCRIPTOR desc;
|
|
|
|
BOOLEAN defaulted, present;
|
|
|
|
PACL pacl;
|
|
|
|
PSID psid;
|
|
|
|
|
|
|
|
Status = RtlCreateSecurityDescriptor(&desc, SECURITY_DESCRIPTOR_REVISION);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
|
|
|
|
if (SecurityInformation & OWNER_SECURITY_INFORMATION)
|
|
|
|
{
|
|
|
|
Status = RtlGetOwnerSecurityDescriptor(ObjectDescriptor, &psid, &defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
Status = RtlSetOwnerSecurityDescriptor(&desc, psid, defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (SecurityInformation & GROUP_SECURITY_INFORMATION)
|
|
|
|
{
|
|
|
|
Status = RtlGetGroupSecurityDescriptor(ObjectDescriptor, &psid, &defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
Status = RtlSetGroupSecurityDescriptor(&desc, psid, defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (SecurityInformation & DACL_SECURITY_INFORMATION)
|
|
|
|
{
|
|
|
|
Status = RtlGetDaclSecurityDescriptor(ObjectDescriptor, &present, &pacl, &defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
Status = RtlSetDaclSecurityDescriptor(&desc, present, pacl, defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (SecurityInformation & SACL_SECURITY_INFORMATION)
|
|
|
|
{
|
|
|
|
Status = RtlGetSaclSecurityDescriptor(ObjectDescriptor, &present, &pacl, &defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
Status = RtlSetSaclSecurityDescriptor(&desc, present, pacl, defaulted);
|
|
|
|
if (!NT_SUCCESS(Status)) return Status;
|
|
|
|
}
|
|
|
|
|
|
|
|
*ReturnLength = DescriptorLength;
|
|
|
|
return RtlAbsoluteToSelfRelativeSD(&desc, ResultantDescriptor, ReturnLength);
|
2005-09-08 00:09:32 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* @unimplemented
|
|
|
|
*/
|
|
|
|
NTSTATUS
|
2005-10-19 17:03:38 +00:00
|
|
|
NTAPI
|
2005-09-08 00:09:32 +00:00
|
|
|
RtlSetSecurityObject(IN SECURITY_INFORMATION SecurityInformation,
|
|
|
|
IN PSECURITY_DESCRIPTOR ModificationDescriptor,
|
|
|
|
OUT PSECURITY_DESCRIPTOR *ObjectsSecurityDescriptor,
|
|
|
|
IN PGENERIC_MAPPING GenericMapping,
|
|
|
|
IN HANDLE Token)
|
|
|
|
{
|
|
|
|
UNIMPLEMENTED;
|
|
|
|
return STATUS_NOT_IMPLEMENTED;
|
|
|
|
}
|
2008-09-12 15:09:17 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* @unimplemented
|
|
|
|
*/
|
|
|
|
NTSTATUS
|
|
|
|
NTAPI
|
|
|
|
RtlRegisterSecureMemoryCacheCallback(IN PRTL_SECURE_MEMORY_CACHE_CALLBACK Callback)
|
|
|
|
{
|
|
|
|
UNIMPLEMENTED;
|
|
|
|
return STATUS_NOT_IMPLEMENTED;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* @unimplemented
|
|
|
|
*/
|
|
|
|
BOOLEAN
|
|
|
|
NTAPI
|
|
|
|
RtlFlushSecureMemoryCache(IN PVOID MemoryCache,
|
|
|
|
IN OPTIONAL SIZE_T MemoryLength)
|
|
|
|
{
|
|
|
|
UNIMPLEMENTED;
|
|
|
|
return FALSE;
|
|
|
|
}
|