Files
Jimmy Fjällid c93999f9b2 mssrvs,msscmr,smb: share/service security descriptors and richer share info
mssrvs:
- NetShareEnumAllExt enumerates shares at info levels 501 and 502 in
  addition to level 1; NetShareEnumAll now delegates to it. Level 501 adds
  Flags; level 502 adds Permissions, MaxUses, CurrentUses, Path and the
  parsed SecurityDescriptor on each NetShare.
- NetShareGetInfo[Ext] queries a single share at levels 0/1/2/501/502.
- NetShareSetInfo plus NetShareSetInfoComment/Flags/SecurityDescriptor
  convenience setters (levels 1004/1005/1501 and the 1/2/502 unions).
- NetServerDiskEnum enumerates the server's disk drives (level 0).
- New SHARE_INFO_{0,2,501,502,1004,1005,1501} structs and the SHARE_INFO
  switch union, with NDR marshalling and round-trip tests.

msscmr:
- GetServiceSecurity[Bytes]/SetServiceSecurity[Bytes] (Opnum 4/5,
  RQueryServiceObjectSecurity/RSetServiceObjectSecurity) and
  GetSCManagerSecurity[Bytes] read and write service and SCM-database
  security descriptors.
- Open SCM/service handles with least privilege: openSCManager uses
  SC_MANAGER_CONNECT and each method opens the service with only the rights
  it needs (DeleteService -> DELETE; ChangeServiceConfig2 derives rights
  from the requested config via ConfigInfoW.RequiredServiceAccess).
- Add SECURITY_INFORMATION and standard-access-right constants; drop the
  unused scActionBuf.

smb:
- QueryInfoSecurityRaw returns the full parsed SecurityDescriptor (every
  ACE and its raw access mask) with a buffer-overflow retry; QueryInfoSecurity
  delegates to it and tolerates a descriptor with no owner/group/DACL.
- OpenFileReadAttributes opens a handle with READ_CONTROL only, enough to
  read a security descriptor without data-read access.
2026-06-06 20:58:22 +02:00
..