00001
00002
00003
00004
00005
00006
00007
00008
00009
00010
00011
00012
00013
00014
00015
00016
00017
00018
00019
00020
00021
00022
00023
00024
00025
00026
#include "sep.h"
00027
#include "sertlp.h"
00028
#include "tokenp.h"
00029
00030
#ifdef ALLOC_PRAGMA
00031
#pragma alloc_text(PAGE,NtAdjustPrivilegesToken)
00032
#pragma alloc_text(PAGE,NtAdjustGroupsToken)
00033
#pragma alloc_text(PAGE,SepAdjustPrivileges)
00034
#pragma alloc_text(PAGE,SepAdjustGroups)
00035
#endif
00036
00037
00039
00040
00041
00043
00044
00045
NTSTATUS
00046 NtAdjustPrivilegesToken (
00047 IN HANDLE TokenHandle,
00048 IN BOOLEAN DisableAllPrivileges,
00049 IN PTOKEN_PRIVILEGES NewState OPTIONAL,
00050 IN ULONG BufferLength OPTIONAL,
00051 OUT PTOKEN_PRIVILEGES PreviousState OPTIONAL,
00052 OUT PULONG ReturnLength
00053 )
00054
00055
00056
00057
00058
00059
00060
00061
00062
00063
00064
00065
00066
00067
00068
00069
00070
00071
00072
00073
00074
00075
00076
00077
00078
00079
00080
00081
00082
00083
00084
00085
00086
00087
00088
00089
00090
00091
00092
00093
00094
00095
00096
00097
00098
00099
00100
00101
00102
00103
00104
00105
00106
00107
00108
00109
00110
00111
00112
00113
00114
00115
00116
00117
00118
00119
00120
00121
00122
00123
00124
00125
00126
00127
00128
00129
00130
00131
00132
00133
00134
00135 {
00136
KPROCESSOR_MODE PreviousMode;
00137
NTSTATUS Status;
00138
00139
PTOKEN Token;
00140
00141 ACCESS_MASK DesiredAccess;
00142
00143 ULONG CapturedPrivilegeCount;
00144 PLUID_AND_ATTRIBUTES CapturedPrivileges =
NULL;
00145 ULONG CapturedPrivilegesLength;
00146
00147 ULONG LocalReturnLength;
00148 ULONG ChangeCount;
00149 BOOLEAN
ChangesMade;
00150
00151 ULONG ParameterLength;
00152
00153
PAGED_CODE();
00154
00155
00156
00157
00158
00159
00160
00161
00162
00163
00164
00165
00166
if (!
DisableAllPrivileges && !ARGUMENT_PRESENT(NewState)) {
00167
return STATUS_INVALID_PARAMETER;
00168 }
00169
00170
00171
00172
00173
00174 PreviousMode = KeGetPreviousMode();
00175
if (PreviousMode !=
KernelMode) {
00176
try {
00177
00178
00179
00180
00181
00182
if (!
DisableAllPrivileges) {
00183
00184
ProbeForRead(
00185 NewState,
00186
sizeof(TOKEN_PRIVILEGES),
00187
sizeof(ULONG)
00188 );
00189
00190 CapturedPrivilegeCount = NewState->PrivilegeCount;
00191 ParameterLength = (ULONG)
sizeof(TOKEN_PRIVILEGES) +
00192 ( (CapturedPrivilegeCount -
ANYSIZE_ARRAY) *
00193 (ULONG)
sizeof(LUID_AND_ATTRIBUTES) );
00194
00195
ProbeForRead(
00196 NewState,
00197 ParameterLength,
00198
sizeof(ULONG)
00199 );
00200
00201 }
00202
00203
00204
00205
00206
00207
00208
if (ARGUMENT_PRESENT(PreviousState)) {
00209
00210
ProbeForWrite(
00211 PreviousState,
00212 BufferLength,
00213
sizeof(ULONG)
00214 );
00215
00216
ProbeForWriteUlong(ReturnLength);
00217 }
00218
00219
00220 } except(
EXCEPTION_EXECUTE_HANDLER) {
00221
return GetExceptionCode();
00222 }
00223
00224 }
else {
00225
00226
if (!
DisableAllPrivileges) {
00227
00228 CapturedPrivilegeCount = NewState->PrivilegeCount;
00229 }
00230 }
00231
00232
00233
00234
00235
00236
00237
00238
if (!
DisableAllPrivileges) {
00239
00240
try {
00241
00242
00243
Status =
SeCaptureLuidAndAttributesArray(
00244 (NewState->Privileges),
00245 CapturedPrivilegeCount,
00246 PreviousMode,
00247
NULL, 0,
00248
PagedPool,
00249
TRUE,
00250 &CapturedPrivileges,
00251 &CapturedPrivilegesLength
00252 );
00253
00254 } except(
EXCEPTION_EXECUTE_HANDLER) {
00255
00256
return GetExceptionCode();
00257
00258 }
00259
00260
if (!
NT_SUCCESS(
Status)) {
00261
00262
return Status;
00263
00264 }
00265
00266 }
00267
00268
00269
00270
00271
00272
00273
00274
if (ARGUMENT_PRESENT(PreviousState)) {
00275 DesiredAccess = (TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY);
00276 }
else {
00277 DesiredAccess = TOKEN_ADJUST_PRIVILEGES;
00278 }
00279
00280
Status =
ObReferenceObjectByHandle(
00281 TokenHandle,
00282 DesiredAccess,
00283
SepTokenObjectType,
00284 PreviousMode,
00285 (PVOID *)&
Token,
00286
NULL
00287 );
00288
00289
if ( !
NT_SUCCESS(
Status) ) {
00290
00291
if (CapturedPrivileges !=
NULL) {
00292
SeReleaseLuidAndAttributesArray(
00293 CapturedPrivileges,
00294 PreviousMode,
00295
TRUE
00296 );
00297 }
00298
00299
return Status;
00300 }
00301
00302
00303
00304
00305
00306
SepAcquireTokenWriteLock(
Token );
00307
00308
00309
00310
00311
00312
00313
Status =
SepAdjustPrivileges(
00314
Token,
00315
FALSE,
00316
DisableAllPrivileges,
00317 CapturedPrivilegeCount,
00318 CapturedPrivileges,
00319 PreviousState,
00320 &LocalReturnLength,
00321 &ChangeCount,
00322 &
ChangesMade
00323 );
00324
00325
if (ARGUMENT_PRESENT(PreviousState)) {
00326
00327
try {
00328
00329 (*ReturnLength) = LocalReturnLength;
00330
00331 } except(
EXCEPTION_EXECUTE_HANDLER) {
00332
00333
SepReleaseTokenWriteLock(
Token,
FALSE );
00334
ObDereferenceObject(
Token );
00335
00336
if (CapturedPrivileges !=
NULL) {
00337
SeReleaseLuidAndAttributesArray(
00338 CapturedPrivileges,
00339 PreviousMode,
00340
TRUE
00341 );
00342 }
00343
00344
return GetExceptionCode();
00345 }
00346
00347 }
00348
00349
00350
00351
00352
00353
00354
00355
if (ARGUMENT_PRESENT(PreviousState)) {
00356
if (LocalReturnLength > BufferLength) {
00357
00358
SepReleaseTokenWriteLock(
Token,
FALSE );
00359
ObDereferenceObject(
Token );
00360
00361
if (CapturedPrivileges !=
NULL) {
00362
SeReleaseLuidAndAttributesArray(
00363 CapturedPrivileges,
00364 PreviousMode,
00365
TRUE
00366 );
00367 }
00368
00369
return STATUS_BUFFER_TOO_SMALL;
00370 }
00371 }
00372
00373
00374
00375
00376
00377
00378
00379
00380
try {
00381
00382
Status =
SepAdjustPrivileges(
00383
Token,
00384
TRUE,
00385
DisableAllPrivileges,
00386 CapturedPrivilegeCount,
00387 CapturedPrivileges,
00388 PreviousState,
00389 &LocalReturnLength,
00390 &ChangeCount,
00391 &
ChangesMade
00392 );
00393
00394
00395
if (ARGUMENT_PRESENT(PreviousState)) {
00396
00397 PreviousState->PrivilegeCount = ChangeCount;
00398 }
00399
00400 } except(
EXCEPTION_EXECUTE_HANDLER) {
00401
00402
SepReleaseTokenWriteLock(
Token,
TRUE );
00403
ObDereferenceObject(
Token );
00404
if (CapturedPrivileges !=
NULL) {
00405
SeReleaseLuidAndAttributesArray(
00406 CapturedPrivileges,
00407 PreviousMode,
00408
TRUE
00409 );
00410 }
00411
return GetExceptionCode();
00412
00413 }
00414
00415
00416
SepReleaseTokenWriteLock(
Token,
ChangesMade );
00417
ObDereferenceObject(
Token );
00418
if (CapturedPrivileges !=
NULL) {
00419
SeReleaseLuidAndAttributesArray(
00420 CapturedPrivileges,
00421 PreviousMode,
00422
TRUE
00423 );
00424 }
00425
00426
return Status;
00427
00428 }
00429
00430
00431
NTSTATUS
00432 NtAdjustGroupsToken (
00433 IN HANDLE TokenHandle,
00434 IN BOOLEAN ResetToDefault,
00435 IN PTOKEN_GROUPS NewState OPTIONAL,
00436 IN ULONG BufferLength OPTIONAL,
00437 OUT PTOKEN_GROUPS PreviousState OPTIONAL,
00438 OUT PULONG ReturnLength
00439 )
00440
00441
00442
00443
00444
00445
00446
00447
00448
00449
00450
00451
00452
00453
00454
00455
00456
00457
00458
00459
00460
00461
00462
00463
00464
00465
00466
00467
00468
00469
00470
00471
00472
00473
00474
00475
00476
00477
00478
00479
00480
00481
00482
00483
00484
00485
00486
00487
00488
00489
00490
00491
00492
00493
00494
00495
00496
00497
00498
00499
00500
00501
00502
00503
00504
00505
00506
00507
00508
00509
00510
00511
00512
00513
00514
00515
00516
00517
00518
00519
00520
00521
00522
00523
00524
00525
00526 {
00527
00528
KPROCESSOR_MODE PreviousMode;
00529
NTSTATUS Status;
00530
00531
PTOKEN Token;
00532
00533 ACCESS_MASK DesiredAccess;
00534
00535 ULONG CapturedGroupCount;
00536 PSID_AND_ATTRIBUTES CapturedGroups =
NULL;
00537 ULONG CapturedGroupsLength;
00538
00539 ULONG LocalReturnLength;
00540 ULONG ChangeCount;
00541 BOOLEAN
ChangesMade;
00542 PSID SidBuffer;
00543
00544
PAGED_CODE();
00545
00546
00547
00548
00549
00550
00551
00552
00553
00554
00555
00556
00557
00558
if (!ResetToDefault && !ARGUMENT_PRESENT(NewState)) {
00559
return STATUS_INVALID_PARAMETER;
00560 }
00561
00562
00563
00564
00565
00566 PreviousMode = KeGetPreviousMode();
00567
if (PreviousMode !=
KernelMode) {
00568
try {
00569
00570
if (!ResetToDefault) {
00571
ProbeForRead(
00572 NewState,
00573
sizeof(TOKEN_GROUPS),
00574
sizeof(ULONG)
00575 );
00576 }
00577
00578
if (ARGUMENT_PRESENT(PreviousState)) {
00579
00580
ProbeForWrite(
00581 PreviousState,
00582 BufferLength,
00583
sizeof(ULONG)
00584 );
00585
00586
00587
00588
00589
00590
00591
ProbeForWriteUlong(ReturnLength);
00592
00593 }
00594
00595
00596 } except(
EXCEPTION_EXECUTE_HANDLER) {
00597
return GetExceptionCode();
00598 }
00599 }
00600
00601
00602
00603
00604
00605
if (!ResetToDefault) {
00606
00607
try {
00608
00609 CapturedGroupCount = NewState->GroupCount;
00610
Status =
SeCaptureSidAndAttributesArray(
00611 &(NewState->Groups[0]),
00612 CapturedGroupCount,
00613 PreviousMode,
00614
NULL, 0,
00615
PagedPool,
00616
TRUE,
00617 &CapturedGroups,
00618 &CapturedGroupsLength
00619 );
00620
00621
if (!
NT_SUCCESS(
Status)) {
00622
00623
return Status;
00624
00625 }
00626
00627 } except(
EXCEPTION_EXECUTE_HANDLER) {
00628
00629
return GetExceptionCode();
00630
00631 }
00632 }
00633
00634
00635
00636
00637
00638
00639
00640
if (ARGUMENT_PRESENT(PreviousState)) {
00641 DesiredAccess = (TOKEN_ADJUST_GROUPS | TOKEN_QUERY);
00642 }
else {
00643 DesiredAccess = TOKEN_ADJUST_GROUPS;
00644 }
00645
00646
Status =
ObReferenceObjectByHandle(
00647 TokenHandle,
00648 DesiredAccess,
00649
SepTokenObjectType,
00650 PreviousMode,
00651 (PVOID *)&
Token,
00652
NULL
00653 );
00654
00655
if ( !
NT_SUCCESS(
Status) ) {
00656
00657
if (ARGUMENT_PRESENT(CapturedGroups)) {
00658
SeReleaseSidAndAttributesArray( CapturedGroups, PreviousMode,
TRUE );
00659 }
00660
00661
return Status;
00662 }
00663
00664
00665
00666
00667
00668
SepAcquireTokenWriteLock(
Token );
00669
00670
00671
00672
00673
00674
00675
00676
00677
Status =
SepAdjustGroups(
00678
Token,
00679
FALSE,
00680 ResetToDefault,
00681 CapturedGroupCount,
00682 CapturedGroups,
00683 PreviousState,
00684
NULL,
00685 &LocalReturnLength,
00686 &ChangeCount,
00687 &
ChangesMade
00688 );
00689
00690
if (ARGUMENT_PRESENT(PreviousState)) {
00691
00692
try {
00693
00694 (*ReturnLength) = LocalReturnLength;
00695
00696 } except(
EXCEPTION_EXECUTE_HANDLER) {
00697
00698
SepReleaseTokenWriteLock(
Token,
FALSE );
00699
ObDereferenceObject(
Token );
00700
00701
if (ARGUMENT_PRESENT(CapturedGroups)) {
00702
SeReleaseSidAndAttributesArray(
00703 CapturedGroups,
00704 PreviousMode,
00705
TRUE
00706 );
00707 }
00708
00709
return GetExceptionCode();
00710 }
00711 }
00712
00713
00714
00715
00716
00717
if (!
NT_SUCCESS(
Status)) {
00718
00719
SepReleaseTokenWriteLock(
Token,
FALSE );
00720
ObDereferenceObject(
Token );
00721
00722
if (ARGUMENT_PRESENT(CapturedGroups)) {
00723
SeReleaseSidAndAttributesArray(
00724 CapturedGroups,
00725 PreviousMode,
00726
TRUE
00727 );
00728 }
00729
00730
return Status;
00731
00732 }
00733
00734
00735
00736
00737
00738
00739
if (ARGUMENT_PRESENT(PreviousState)) {
00740
if (LocalReturnLength > BufferLength) {
00741
00742
SepReleaseTokenWriteLock(
Token,
FALSE );
00743
ObDereferenceObject(
Token );
00744
00745
if (ARGUMENT_PRESENT(CapturedGroups)) {
00746
SeReleaseSidAndAttributesArray(
00747 CapturedGroups,
00748 PreviousMode,
00749
TRUE
00750 );
00751 }
00752
00753
00754
return STATUS_BUFFER_TOO_SMALL;
00755 }
00756
00757
00758
00759
00760
00761
00762 SidBuffer = (PSID)(
LongAlignPtr(
00763 (PCHAR)PreviousState + (ULONG)
sizeof(TOKEN_GROUPS) +
00764 (ChangeCount * (ULONG)
sizeof(SID_AND_ATTRIBUTES)) -
00765 (
ANYSIZE_ARRAY * (ULONG)
sizeof(SID_AND_ATTRIBUTES))
00766 ) );
00767
00768 }
00769
00770
00771
00772
00773
00774
try {
00775
00776
Status =
SepAdjustGroups(
00777
Token,
00778
TRUE,
00779 ResetToDefault,
00780 CapturedGroupCount,
00781 CapturedGroups,
00782 PreviousState,
00783 SidBuffer,
00784 &LocalReturnLength,
00785 &ChangeCount,
00786 &
ChangesMade
00787 );
00788
00789
if (ARGUMENT_PRESENT(PreviousState)) {
00790
00791 PreviousState->GroupCount = ChangeCount;
00792 }
00793
00794 } except(
EXCEPTION_EXECUTE_HANDLER) {
00795
00796
00797
SepReleaseTokenWriteLock(
Token,
TRUE );
00798
ObDereferenceObject(
Token );
00799
if (ARGUMENT_PRESENT(CapturedGroups)) {
00800
SeReleaseSidAndAttributesArray( CapturedGroups, PreviousMode,
TRUE );
00801 }
00802
return GetExceptionCode();
00803
00804 }
00805
00806
00807
SepReleaseTokenWriteLock(
Token,
ChangesMade );
00808
ObDereferenceObject(
Token );
00809
00810
if (ARGUMENT_PRESENT(CapturedGroups)) {
00811
SeReleaseSidAndAttributesArray( CapturedGroups, PreviousMode,
TRUE );
00812 }
00813
00814
return Status;
00815
00816 }
00817
00818
NTSTATUS
00819 SepAdjustPrivileges(
00820 IN PTOKEN Token,
00821 IN BOOLEAN MakeChanges,
00822 IN BOOLEAN DisableAllPrivileges,
00823 IN ULONG PrivilegeCount OPTIONAL,
00824 IN PLUID_AND_ATTRIBUTES NewState OPTIONAL,
00825 OUT PTOKEN_PRIVILEGES PreviousState OPTIONAL,
00826 OUT PULONG ReturnLength,
00827 OUT PULONG ChangeCount,
00828 OUT PBOOLEAN ChangesMade
00829 )
00830
00831
00832
00833
00834
00835
00836
00837
00838
00839
00840
00841
00842
00843
00844
00845
00846
00847
00848
00849
00850
00851
00852
00853
00854
00855
00856
00857
00858
00859
00860
00861
00862
00863
00864
00865
00866
00867
00868
00869
00870
00871
00872
00873
00874
00875
00876
00877
00878
00879
00880
00881
00882
00883
00884
00885
00886
00887
00888
00889
00890
00891
00892
00893
00894
00895
00896
00897
00898
00899
00900
00901
00902
00903
00904
00905
00906
00907
00908
00909
00910
00911
00912 {
00913
NTSTATUS CompletionStatus = STATUS_SUCCESS;
00914
00915 ULONG OldIndex;
00916 ULONG NewIndex;
00917 BOOLEAN Found;
00918 ULONG MatchCount = 0;
00919
00920 LUID_AND_ATTRIBUTES CurrentPrivilege;
00921
00922
PAGED_CODE();
00923
00924
00925
00926
00927
00928
00929 OldIndex = 0;
00930 (*ChangeCount) = 0;
00931
00932
while (OldIndex <
Token->PrivilegeCount) {
00933
00934 CurrentPrivilege = (
Token->Privileges)[OldIndex];
00935
00936
if (
DisableAllPrivileges) {
00937
00938
if (
SepTokenPrivilegeAttributes(
Token,OldIndex) &
00939 SE_PRIVILEGE_ENABLED ) {
00940
00941
00942
00943
00944
00945
00946
if (MakeChanges) {
00947
00948
if (ARGUMENT_PRESENT(PreviousState)) {
00949
00950 PreviousState->Privileges[(*ChangeCount)] =
00951 CurrentPrivilege;
00952 }
00953
00954
SepTokenPrivilegeAttributes(
Token,OldIndex) &=
00955 ~SE_PRIVILEGE_ENABLED;
00956
00957
00958
00959 }
00960
00961
00962
00963
00964
00965 (*ChangeCount) += 1;
00966
00967 }
00968
00969 }
else {
00970
00971
00972
00973
00974
00975
00976
00977
00978 NewIndex = 0;
00979 Found =
FALSE;
00980
00981
while ( (NewIndex < PrivilegeCount) && !Found) {
00982
00983
00984
00985
00986
00987
if (
RtlEqualLuid(&CurrentPrivilege.Luid,&NewState[NewIndex].Luid)) {
00988
00989 Found =
TRUE;
00990 MatchCount += 1;
00991
00992
if ( (
SepArrayPrivilegeAttributes( NewState, NewIndex ) &
00993 SE_PRIVILEGE_ENABLED)
00994 !=
00995 (
SepTokenPrivilegeAttributes(
Token,OldIndex) &
00996 SE_PRIVILEGE_ENABLED) ) {
00997
00998
00999
01000
01001
01002
01003
if (MakeChanges) {
01004
01005
if (ARGUMENT_PRESENT(PreviousState)) {
01006
01007 PreviousState->Privileges[(*ChangeCount)] =
01008 CurrentPrivilege;
01009 }
01010
01011
SepTokenPrivilegeAttributes(
Token,OldIndex) &=
01012 ~(
SepTokenPrivilegeAttributes(
Token,OldIndex)
01013 & SE_PRIVILEGE_ENABLED);
01014
SepTokenPrivilegeAttributes(
Token,OldIndex) |=
01015 (
SepArrayPrivilegeAttributes(NewState,NewIndex)
01016 & SE_PRIVILEGE_ENABLED);
01017
01018
01019
01020
01021
01022
01023
if (
RtlEqualLuid(&CurrentPrivilege.Luid,
01024 &
SeChangeNotifyPrivilege)) {
01025
Token->TokenFlags ^=
TOKEN_HAS_TRAVERSE_PRIVILEGE;
01026 }
01027
01028
01029
01030 }
01031
01032
01033
01034
01035
01036 (*ChangeCount) += 1;
01037
01038
01039 }
01040
01041 }
01042
01043 NewIndex += 1;
01044
01045 }
01046
01047 }
01048
01049 OldIndex += 1;
01050
01051 }
01052
01053
01054
01055
01056
01057
01058
01059
if (
DisableAllPrivileges) {
01060
Token->TokenFlags &= ~
TOKEN_HAS_TRAVERSE_PRIVILEGE;
01061 }
01062
01063
01064
01065
01066
01067
if (!
DisableAllPrivileges) {
01068
01069
if (MatchCount < PrivilegeCount) {
01070 CompletionStatus = STATUS_NOT_ALL_ASSIGNED;
01071 }
01072 }
01073
01074
01075
01076
01077
01078
if ((*ChangeCount) > 0 && MakeChanges) {
01079 (*ChangesMade) =
TRUE;
01080 }
else {
01081 (*ChangesMade) =
FALSE;
01082 }
01083
01084
01085
01086
01087
01088
if (ARGUMENT_PRESENT(PreviousState)) {
01089
01090 (*ReturnLength) = (ULONG)
sizeof(TOKEN_PRIVILEGES) +
01091 ((*ChangeCount) * (ULONG)
sizeof(LUID_AND_ATTRIBUTES)) -
01092 (
ANYSIZE_ARRAY * (ULONG)
sizeof(LUID_AND_ATTRIBUTES));
01093 }
01094
01095
return CompletionStatus;
01096 }
01097
01098
NTSTATUS
01099 SepAdjustGroups(
01100 IN PTOKEN Token,
01101 IN BOOLEAN MakeChanges,
01102 IN BOOLEAN ResetToDefault,
01103 IN ULONG GroupCount,
01104 IN PSID_AND_ATTRIBUTES NewState OPTIONAL,
01105 OUT PTOKEN_GROUPS PreviousState OPTIONAL,
01106 OUT PSID SidBuffer OPTIONAL,
01107 OUT PULONG ReturnLength,
01108 OUT PULONG ChangeCount,
01109 OUT PBOOLEAN ChangesMade
01110 )
01111
01112
01113
01114
01115
01116
01117
01118
01119
01120
01121
01122
01123
01124
01125
01126
01127
01128
01129
01130
01131
01132
01133
01134
01135
01136
01137
01138
01139
01140
01141
01142
01143
01144
01145
01146
01147
01148
01149
01150
01151
01152
01153
01154
01155
01156
01157
01158
01159
01160
01161
01162
01163
01164
01165
01166
01167
01168
01169
01170
01171
01172
01173
01174
01175
01176
01177
01178
01179
01180
01181
01182
01183
01184
01185
01186
01187
01188
01189
01190
01191
01192
01193
01194
01195
01196
01197
01198
01199
01200
01201
01202
01203
01204 {
01205
01206
NTSTATUS CompletionStatus = STATUS_SUCCESS;
01207
01208 ULONG OldIndex;
01209 ULONG NewIndex;
01210 ULONG SidLength;
01211 ULONG LocalReturnLength = 0;
01212 PSID NextSid;
01213 BOOLEAN Found;
01214 ULONG MatchCount = 0;
01215 BOOLEAN EnableGroup;
01216 BOOLEAN DisableGroup;
01217 ULONG TokenGroupAttributes;
01218
01219 SID_AND_ATTRIBUTES CurrentGroup;
01220
01221
PAGED_CODE();
01222
01223
01224
01225
01226
01227 NextSid = SidBuffer;
01228
01229
01230
01231
01232
01233
01234
01235 OldIndex = 1;
01236 (*ChangeCount) = 0;
01237
01238
while (OldIndex <
Token->UserAndGroupCount) {
01239
01240 CurrentGroup =
Token->UserAndGroups[OldIndex];
01241
01242
if (ResetToDefault) {
01243
01244 TokenGroupAttributes =
SepTokenGroupAttributes(
Token,OldIndex);
01245
01246
01247
01248
01249
01250
01251 EnableGroup = (BOOLEAN)( (TokenGroupAttributes & SE_GROUP_ENABLED_BY_DEFAULT)
01252 && !(TokenGroupAttributes & SE_GROUP_ENABLED));
01253
01254
01255
01256
01257
01258
01259 DisableGroup = (BOOLEAN)( !(TokenGroupAttributes & SE_GROUP_ENABLED_BY_DEFAULT)
01260 && (TokenGroupAttributes & SE_GROUP_ENABLED));
01261
01262
01263
01264
01265
01266
01267
01268
ASSERT(!(TokenGroupAttributes & SE_GROUP_MANDATORY)
01269 || (TokenGroupAttributes & (SE_GROUP_ENABLED_BY_DEFAULT | SE_GROUP_ENABLED)
01270 == (SE_GROUP_ENABLED_BY_DEFAULT | SE_GROUP_ENABLED)));
01271
01272
if ( EnableGroup || DisableGroup ) {
01273
01274 SidLength =
SeLengthSid( CurrentGroup.Sid );
01275 SidLength = (ULONG)LongAlignSize(SidLength);
01276 LocalReturnLength += SidLength;
01277
01278
01279
01280
01281
01282
01283
if (MakeChanges) {
01284
01285
if (ARGUMENT_PRESENT(PreviousState)) {
01286
01287 (*(PreviousState)).Groups[(*ChangeCount)].Attributes =
01288 CurrentGroup.Attributes;
01289
01290 (*(PreviousState)).Groups[(*ChangeCount)].Sid =
01291 NextSid;
01292
01293
RtlCopySid( SidLength, NextSid, CurrentGroup.Sid );
01294 NextSid = (PSID)((ULONG_PTR)NextSid + SidLength);
01295 }
01296
01297
if (EnableGroup) {
01298
SepTokenGroupAttributes(
Token,OldIndex) |= SE_GROUP_ENABLED;
01299 }
else {
01300
SepTokenGroupAttributes(
Token,OldIndex) &= ~SE_GROUP_ENABLED;
01301 }
01302
01303
01304
01305 }
01306
01307
01308
01309
01310
01311 (*ChangeCount) += 1;
01312
01313 }
01314
01315 }
else {
01316
01317
01318
01319
01320
01321
01322
01323
01324 NewIndex = 0;
01325 Found =
FALSE;
01326
01327
while ( (NewIndex < GroupCount) && !Found) {
01328
01329
01330
01331
01332
01333
if (
RtlEqualSid(
01334 CurrentGroup.Sid,
01335 NewState[NewIndex].Sid
01336 ) ) {
01337
01338 Found =
TRUE;
01339 MatchCount += 1;
01340
01341
01342
01343
01344
01345
01346
if ( (
SepArrayGroupAttributes( NewState, NewIndex ) &
01347 SE_GROUP_ENABLED ) !=
01348 (
SepTokenGroupAttributes(
Token,OldIndex) &
01349 SE_GROUP_ENABLED ) ) {
01350
01351
01352
01353
01354
01355
if (
SepTokenGroupAttributes(
Token,OldIndex) &
01356 SE_GROUP_MANDATORY ) {
01357
return STATUS_CANT_DISABLE_MANDATORY;
01358 }
01359
01360
01361
01362
01363
01364
01365
if (
SepTokenGroupAttributes(
Token,OldIndex) &
01366 SE_GROUP_USE_FOR_DENY_ONLY ) {
01367
return STATUS_CANT_ENABLE_DENY_ONLY;
01368 }
01369
01370 SidLength =
SeLengthSid( CurrentGroup.Sid );
01371 SidLength = (ULONG)LongAlignSize(SidLength);
01372 LocalReturnLength += SidLength;
01373
01374
01375
01376
01377
01378
01379
if (MakeChanges) {
01380
01381
if (ARGUMENT_PRESENT(PreviousState)) {
01382
01383 PreviousState->Groups[(*ChangeCount)].Attributes =
01384 CurrentGroup.Attributes;
01385
01386 PreviousState->Groups[(*ChangeCount)].Sid =
01387 NextSid;
01388
01389
RtlCopySid( SidLength, NextSid, CurrentGroup.Sid );
01390
01391 NextSid = (PSID)((ULONG_PTR)NextSid + SidLength);
01392 }
01393
01394
SepTokenGroupAttributes(
Token,OldIndex) &=
01395 ~(
SepTokenGroupAttributes(
Token,OldIndex)
01396 & SE_GROUP_ENABLED);
01397
SepTokenGroupAttributes(
Token,OldIndex) |=
01398 (
SepArrayGroupAttributes(NewState,NewIndex)
01399 & SE_GROUP_ENABLED);
01400
01401
01402
01403 }
01404
01405
01406
01407
01408
01409 (*ChangeCount) += 1;
01410
01411
01412 }
01413
01414 }
01415
01416 NewIndex += 1;
01417
01418 }
01419
01420 }
01421
01422 OldIndex += 1;
01423
01424 }
01425
01426
01427
01428
01429
01430
if (!ResetToDefault) {
01431
01432
if (MatchCount < GroupCount) {
01433 CompletionStatus = STATUS_NOT_ALL_ASSIGNED;
01434 }
01435 }
01436
01437
01438
01439
01440
01441
if ((*ChangeCount) > 0 && MakeChanges) {
01442 (*ChangesMade) =
TRUE;
01443 }
else {
01444 (*ChangesMade) =
FALSE;
01445 }
01446
01447
01448
01449
01450
01451
01452
if (ARGUMENT_PRESENT(PreviousState)) {
01453
01454 (*ReturnLength) = LocalReturnLength +
01455 (ULONG)
sizeof(TOKEN_GROUPS) +
01456 ((*ChangeCount) * (ULONG)
sizeof(SID_AND_ATTRIBUTES)) -
01457 (
ANYSIZE_ARRAY * (ULONG)
sizeof(SID_AND_ATTRIBUTES));
01458 }
01459
01460
return CompletionStatus;
01461 }