2005-05-23 20:25:31 +04:00
/*
* Unix SMB / CIFS implementation .
* Windows NT registry I / O library
* Copyright ( c ) Gerald ( Jerry ) Carter 2005
*
* This program is free software ; you can redistribute it and / or modify
* it under the terms of the GNU General Public License as published by
2007-07-09 23:25:36 +04:00
* the Free Software Foundation ; either version 3 of the License , or
2005-05-23 20:25:31 +04:00
* ( at your option ) any later version .
*
* This program is distributed in the hope that it will be useful ,
* but WITHOUT ANY WARRANTY ; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
* GNU General Public License for more details .
*
* You should have received a copy of the GNU General Public License
2007-07-10 09:23:25 +04:00
* along with this program ; if not , see < http : //www.gnu.org/licenses/>.
2005-05-23 20:25:31 +04:00
*/
/************************************************************
* Most of this information was obtained from
* http : //www.wednesday.demon.co.uk/dosreg.html
* Thanks Nigel !
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
2010-07-16 01:45:29 +04:00
# include "registry/reg_parse_prs.h"
2010-09-21 09:40:13 +04:00
# include "registry/reg_objects.h"
2005-05-23 20:25:31 +04:00
# ifndef _REGFIO_H
# define _REGFIO_H
2009-10-02 02:17:06 +04:00
struct regsubkey_ctr ;
2005-05-23 20:25:31 +04:00
/* Macros */
# define REGF_BLOCKSIZE 0x1000
# define REGF_ALLOC_BLOCK 0x1000
/* header sizes for various records */
# define REGF_HDR_SIZE 4
# define HBIN_HDR_SIZE 4
# define HBIN_HEADER_REC_SIZE 0x24
# define REC_HDR_SIZE 2
# define REGF_OFFSET_NONE 0xffffffff
/* Flags for the vk records */
# define VK_FLAG_NAME_PRESENT 0x0001
# define VK_DATA_IN_OFFSET 0x80000000
/* NK record macros */
# define NK_TYPE_LINKKEY 0x0010
# define NK_TYPE_NORMALKEY 0x0020
# define NK_TYPE_ROOTKEY 0x002c
# define HBIN_STORE_REF(x, y) { x->hbin = y; y->ref_count++ };
# define HBIN_REMOVE_REF(x, y) { x->hbin = NULL; y->ref_count-- /* if the count == 0; we can clean up */ };
/* HBIN block */
struct regf_hbin ;
typedef struct regf_hbin {
struct regf_hbin * prev , * next ;
2015-04-14 17:50:28 +03:00
uint32_t file_off ; /* my offset in the registry file */
uint32_t free_off ; /* offset to free space within the hbin record */
uint32_t free_size ; /* amount of data left in the block */
2005-05-23 20:25:31 +04:00
int ref_count ; /* how many active records are pointing to this block (not used currently) */
char header [ HBIN_HDR_SIZE ] ; /* "hbin" */
2015-04-14 17:50:28 +03:00
uint32_t first_hbin_off ; /* offset from first hbin block */
uint32_t block_size ; /* block size of this blockually a multiple of 4096Kb) */
2005-05-23 20:25:31 +04:00
prs_struct ps ; /* data */
2007-10-19 04:40:25 +04:00
bool dirty ; /* has this hbin block been modified? */
2005-05-23 20:25:31 +04:00
} REGF_HBIN ;
/* ??? List -- list of key offsets and hashed names for consistency */
typedef struct {
2015-04-14 17:50:28 +03:00
uint32_t nk_off ;
2015-05-09 22:19:46 +03:00
uint8_t keycheck [ sizeof ( uint32_t ) ] ;
2005-08-22 23:47:56 +04:00
char * fullname ;
2005-05-23 20:25:31 +04:00
} REGF_HASH_REC ;
typedef struct {
REGF_HBIN * hbin ; /* pointer to HBIN record (in memory) containing this nk record */
2015-04-14 17:50:28 +03:00
uint32_t hbin_off ; /* offset from beginning of this hbin block */
uint32_t rec_size ; /* ((start_offset - end_offset) & 0xfffffff8) */
2005-05-23 20:25:31 +04:00
char header [ REC_HDR_SIZE ] ;
2015-05-09 22:19:46 +03:00
uint16_t num_keys ;
2005-05-23 20:25:31 +04:00
REGF_HASH_REC * hashes ;
} REGF_LF_REC ;
/* Key Value */
typedef struct {
REGF_HBIN * hbin ; /* pointer to HBIN record (in memory) containing this nk record */
2015-04-14 17:50:28 +03:00
uint32_t hbin_off ; /* offset from beginning of this hbin block */
uint32_t rec_size ; /* ((start_offset - end_offset) & 0xfffffff8) */
uint32_t rec_off ; /* offset stored in the value list */
2005-05-23 20:25:31 +04:00
char header [ REC_HDR_SIZE ] ;
char * valuename ;
2015-04-14 17:50:28 +03:00
uint32_t data_size ;
uint32_t data_off ;
2015-05-09 22:19:46 +03:00
uint8_t * data ;
2015-04-14 17:50:28 +03:00
uint32_t type ;
2015-05-09 22:19:46 +03:00
uint16_t flag ;
2005-05-23 20:25:31 +04:00
} REGF_VK_REC ;
/* Key Security */
struct _regf_sk_rec ;
typedef struct _regf_sk_rec {
struct _regf_sk_rec * next , * prev ;
REGF_HBIN * hbin ; /* pointer to HBIN record (in memory) containing this nk record */
2015-04-14 17:50:28 +03:00
uint32_t hbin_off ; /* offset from beginning of this hbin block */
uint32_t rec_size ; /* ((start_offset - end_offset) & 0xfffffff8) */
2005-05-23 20:25:31 +04:00
2015-04-14 17:50:28 +03:00
uint32_t sk_off ; /* offset parsed from NK record used as a key
2005-05-23 20:25:31 +04:00
to lookup reference to this SK record */
char header [ REC_HDR_SIZE ] ;
2015-04-14 17:50:28 +03:00
uint32_t prev_sk_off ;
uint32_t next_sk_off ;
uint32_t ref_count ;
uint32_t size ;
2010-05-18 12:29:34 +04:00
struct security_descriptor * sec_desc ;
2005-05-23 20:25:31 +04:00
} REGF_SK_REC ;
/* Key Name */
typedef struct {
REGF_HBIN * hbin ; /* pointer to HBIN record (in memory) containing this nk record */
2015-04-14 17:50:28 +03:00
uint32_t hbin_off ; /* offset from beginning of this hbin block */
uint32_t subkey_index ; /* index to next subkey record to return */
uint32_t rec_size ; /* ((start_offset - end_offset) & 0xfffffff8) */
2005-05-23 20:25:31 +04:00
/* header information */
char header [ REC_HDR_SIZE ] ;
2015-05-09 22:19:46 +03:00
uint16_t key_type ;
2005-05-23 20:25:31 +04:00
NTTIME mtime ;
2015-04-14 17:50:28 +03:00
uint32_t parent_off ; /* back pointer in registry hive */
uint32_t classname_off ;
2005-05-23 20:25:31 +04:00
char * classname ;
char * keyname ;
/* max lengths */
2015-04-14 17:50:28 +03:00
uint32_t max_bytes_subkeyname ; /* max subkey name * 2 */
uint32_t max_bytes_subkeyclassname ; /* max subkey classname length (as if) */
uint32_t max_bytes_valuename ; /* max valuename * 2 */
uint32_t max_bytes_value ; /* max value data size */
2005-05-23 20:25:31 +04:00
/* unknowns */
2015-04-14 17:50:28 +03:00
uint32_t unk_index ; /* nigel says run time index ? */
2005-05-23 20:25:31 +04:00
/* children */
2015-04-14 17:50:28 +03:00
uint32_t num_subkeys ;
uint32_t subkeys_off ; /* hash records that point to NK records */
uint32_t num_values ;
uint32_t values_off ; /* value lists which point to VK records */
uint32_t sk_off ; /* offset to SK record */
2005-05-23 20:25:31 +04:00
/* link in the other records here */
REGF_LF_REC subkeys ;
REGF_VK_REC * values ;
REGF_SK_REC * sec_desc ;
} REGF_NK_REC ;
/* REGF block */
typedef struct {
/* run time information */
int fd ; /* file descriptor */
int open_flags ; /* flags passed to the open() call */
TALLOC_CTX * mem_ctx ; /* memory context for run-time file access information */
REGF_HBIN * block_list ; /* list of open hbin blocks */
/* file format information */
char header [ REGF_HDR_SIZE ] ; /* "regf" */
2015-04-14 17:50:28 +03:00
uint32_t data_offset ; /* offset to record in the first (or any?) hbin block */
uint32_t last_block ; /* offset to last hbin block in file */
uint32_t checksum ; /* XOR of bytes 0x0000 - 0x01FB */
2005-05-23 20:25:31 +04:00
NTTIME mtime ;
REGF_SK_REC * sec_desc_list ; /* list of security descriptors referenced by NK records */
2019-09-24 00:53:55 +03:00
/* Ignore checksums in input data. Used by fuzzing code to allow more
2023-07-13 10:27:28 +03:00
* coverage without having to calculate a valid checksum . The checksums
2019-09-24 00:53:55 +03:00
* are merely to detect data corruption and don ' t provide a security
* value .
*/
bool ignore_checksums ;
2005-05-23 20:25:31 +04:00
/* unknowns used to simply writing */
2015-04-14 17:50:28 +03:00
uint32_t unknown1 ;
uint32_t unknown2 ;
uint32_t unknown3 ;
uint32_t unknown4 ;
uint32_t unknown5 ;
uint32_t unknown6 ;
2005-05-23 20:25:31 +04:00
} REGF_FILE ;
/* Function Declarations */
REGF_FILE * regfio_open ( const char * filename , int flags , int mode ) ;
int regfio_close ( REGF_FILE * r ) ;
REGF_NK_REC * regfio_rootkey ( REGF_FILE * file ) ;
REGF_NK_REC * regfio_fetch_subkey ( REGF_FILE * file , REGF_NK_REC * nk ) ;
REGF_NK_REC * regfio_write_key ( REGF_FILE * file , const char * name ,
2009-03-23 20:14:17 +03:00
struct regval_ctr * values , struct regsubkey_ctr * subkeys ,
2010-05-18 12:29:34 +04:00
struct security_descriptor * sec_desc , REGF_NK_REC * parent ) ;
2005-05-23 20:25:31 +04:00
# endif /* _REGFIO_H */