2
* Unix SMB/CIFS implementation.
3
* Windows NT registry I/O library
4
* Copyright (c) Gerald (Jerry) Carter 2005
6
* This program is free software; you can redistribute it and/or modify
7
* it under the terms of the GNU General Public License as published by
8
* the Free Software Foundation; either version 2 of the License, or
9
* (at your option) any later version.
11
* This program is distributed in the hope that it will be useful,
12
* but WITHOUT ANY WARRANTY; without even the implied warranty of
13
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14
* GNU General Public License for more details.
16
* You should have received a copy of the GNU General Public License
17
* along with this program; if not, write to the Free Software
18
* Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
21
/************************************************************
22
* Most of this information was obtained from
23
* http://www.wednesday.demon.co.uk/dosreg.html
25
***********************************************************/
33
#define REGF_BLOCKSIZE 0x1000
34
#define REGF_ALLOC_BLOCK 0x1000
36
/* header sizes for various records */
38
#define REGF_HDR_SIZE 4
39
#define HBIN_HDR_SIZE 4
40
#define HBIN_HEADER_REC_SIZE 0x24
41
#define REC_HDR_SIZE 2
43
#define REGF_OFFSET_NONE 0xffffffff
45
/* Flags for the vk records */
47
#define VK_FLAG_NAME_PRESENT 0x0001
48
#define VK_DATA_IN_OFFSET 0x80000000
50
/* NK record macros */
52
#define NK_TYPE_LINKKEY 0x0010
53
#define NK_TYPE_NORMALKEY 0x0020
54
#define NK_TYPE_ROOTKEY 0x002c
56
#define HBIN_STORE_REF(x, y) { x->hbin = y; y->ref_count++ };
57
#define HBIN_REMOVE_REF(x, y) { x->hbin = NULL; y->ref_count-- /* if the count == 0; we can clean up */ };
62
typedef struct regf_hbin {
63
struct regf_hbin *prev, *next;
64
uint32 file_off; /* my offset in the registry file */
65
uint32 free_off; /* offset to free space within the hbin record */
66
uint32 free_size; /* amount of data left in the block */
67
int ref_count; /* how many active records are pointing to this block (not used currently) */
69
char header[HBIN_HDR_SIZE]; /* "hbin" */
70
uint32 first_hbin_off; /* offset from first hbin block */
71
uint32 block_size; /* block size of this blockually a multiple of 4096Kb) */
73
prs_struct ps; /* data */
75
BOOL dirty; /* has this hbin block been modified? */
78
/* ??? List -- list of key offsets and hashed names for consistency */
82
uint8 keycheck[sizeof(uint32)];
87
REGF_HBIN *hbin; /* pointer to HBIN record (in memory) containing this nk record */
88
uint32 hbin_off; /* offset from beginning of this hbin block */
89
uint32 rec_size; /* ((start_offset - end_offset) & 0xfffffff8) */
91
char header[REC_HDR_SIZE];
93
REGF_HASH_REC *hashes;
99
REGF_HBIN *hbin; /* pointer to HBIN record (in memory) containing this nk record */
100
uint32 hbin_off; /* offset from beginning of this hbin block */
101
uint32 rec_size; /* ((start_offset - end_offset) & 0xfffffff8) */
102
uint32 rec_off; /* offset stored in the value list */
104
char header[REC_HDR_SIZE];
117
typedef struct _regf_sk_rec {
118
struct _regf_sk_rec *next, *prev;
119
REGF_HBIN *hbin; /* pointer to HBIN record (in memory) containing this nk record */
120
uint32 hbin_off; /* offset from beginning of this hbin block */
121
uint32 rec_size; /* ((start_offset - end_offset) & 0xfffffff8) */
123
uint32 sk_off; /* offset parsed from NK record used as a key
124
to lookup reference to this SK record */
126
char header[REC_HDR_SIZE];
137
REGF_HBIN *hbin; /* pointer to HBIN record (in memory) containing this nk record */
138
uint32 hbin_off; /* offset from beginning of this hbin block */
139
uint32 subkey_index; /* index to next subkey record to return */
140
uint32 rec_size; /* ((start_offset - end_offset) & 0xfffffff8) */
142
/* header information */
144
char header[REC_HDR_SIZE];
147
uint32 parent_off; /* back pointer in registry hive */
148
uint32 classname_off;
154
uint32 max_bytes_subkeyname; /* max subkey name * 2 */
155
uint32 max_bytes_subkeyclassname; /* max subkey classname length (as if) */
156
uint32 max_bytes_valuename; /* max valuename * 2 */
157
uint32 max_bytes_value; /* max value data size */
161
uint32 unk_index; /* nigel says run time index ? */
166
uint32 subkeys_off; /* hash records that point to NK records */
168
uint32 values_off; /* value lists which point to VK records */
169
uint32 sk_off; /* offset to SK record */
171
/* link in the other records here */
175
REGF_SK_REC *sec_desc;
182
/* run time information */
184
int fd; /* file descriptor */
185
int open_flags; /* flags passed to the open() call */
186
TALLOC_CTX *mem_ctx; /* memory context for run-time file access information */
187
REGF_HBIN *block_list; /* list of open hbin blocks */
189
/* file format information */
191
char header[REGF_HDR_SIZE]; /* "regf" */
192
uint32 data_offset; /* offset to record in the first (or any?) hbin block */
193
uint32 last_block; /* offset to last hbin block in file */
194
uint32 checksum; /* XOR of bytes 0x0000 - 0x01FB */
197
REGF_SK_REC *sec_desc_list; /* list of security descriptors referenced by NK records */
199
/* unknowns used to simply writing */
210
/* Function Declarations */
212
REGF_FILE* regfio_open( const char *filename, int flags, int mode );
213
int regfio_close( REGF_FILE *r );
215
REGF_NK_REC* regfio_rootkey( REGF_FILE *file );
216
REGF_NK_REC* regfio_fetch_subkey( REGF_FILE *file, REGF_NK_REC *nk );
217
REGF_NK_REC* regfio_write_key ( REGF_FILE *file, const char *name,
218
REGVAL_CTR *values, REGSUBKEY_CTR *subkeys,
219
SEC_DESC *sec_desc, REGF_NK_REC *parent );
222
#endif /* _REGFIO_H */