diff --git a/crates/ffi-types/Cargo.toml b/crates/ffi-types/Cargo.toml index b4f43e80..8e50574d 100644 --- a/crates/ffi-types/Cargo.toml +++ b/crates/ffi-types/Cargo.toml @@ -8,6 +8,7 @@ publish = false [features] default = [] winscard = [] +sspi = [] [lints] workspace = true diff --git a/crates/ffi-types/src/lib.rs b/crates/ffi-types/src/lib.rs index eed19fe6..b8a2f1bc 100644 --- a/crates/ffi-types/src/lib.rs +++ b/crates/ffi-types/src/lib.rs @@ -1,4 +1,6 @@ pub mod common; +#[cfg(feature = "sspi")] +pub mod sspi; #[cfg(feature = "winscard")] pub mod winscard; diff --git a/crates/ffi-types/src/sspi/functions.rs b/crates/ffi-types/src/sspi/functions.rs new file mode 100644 index 00000000..a3be5b36 --- /dev/null +++ b/crates/ffi-types/src/sspi/functions.rs @@ -0,0 +1,220 @@ +use core::ffi::c_void; + +use super::{ + LpStr, LpcWStr, PCredHandle, PCtxtHandle, PSecBuffer, PSecBufferDesc, PSecPkgInfoA, PSecPkgInfoW, PSecurityString, + PTimeStamp, SecChar, SecGetKeyFn, SecWChar, SecurityInteger, SecurityStatus, +}; + +pub type FreeCredentialsHandleFn = unsafe extern "system" fn(PCredHandle) -> SecurityStatus; +pub type AcceptSecurityContextFn = unsafe extern "system" fn( + PCredHandle, + PCtxtHandle, + PSecBufferDesc, + u32, + u32, + PCtxtHandle, + PSecBufferDesc, + *mut u32, + *mut SecurityInteger, +) -> SecurityStatus; +pub type CompleteAuthTokenFn = unsafe extern "system" fn(PCtxtHandle, PSecBufferDesc) -> SecurityStatus; +pub type DeleteSecurityContextFn = unsafe extern "system" fn(PCtxtHandle) -> SecurityStatus; +pub type ApplyControlTokenFn = extern "system" fn(PCtxtHandle, PSecBufferDesc) -> SecurityStatus; +pub type ImpersonateSecurityContextFn = extern "system" fn(PCtxtHandle) -> SecurityStatus; +pub type RevertSecurityContextFn = extern "system" fn(PCtxtHandle) -> SecurityStatus; +pub type MakeSignatureFn = extern "system" fn(PCtxtHandle, u32, PSecBufferDesc, u32) -> SecurityStatus; +pub type VerifySignatureFn = extern "system" fn(PCtxtHandle, PSecBufferDesc, u32, *mut u32) -> SecurityStatus; +pub type FreeContextBufferFn = unsafe extern "system" fn(*mut c_void) -> SecurityStatus; +pub type ExportSecurityContextFn = extern "system" fn(PCtxtHandle, u32, PSecBuffer, *mut *mut c_void) -> SecurityStatus; +pub type QuerySecurityContextTokenFn = extern "system" fn(PCtxtHandle, *mut *mut c_void) -> SecurityStatus; +pub type EncryptMessageFn = unsafe extern "system" fn(PCtxtHandle, u32, PSecBufferDesc, u32) -> SecurityStatus; +pub type DecryptMessageFn = unsafe extern "system" fn(PCtxtHandle, PSecBufferDesc, u32, *mut u32) -> SecurityStatus; + +pub type AcquireCredentialsHandleFnA = unsafe extern "system" fn( + LpStr, + LpStr, + u32, + *const c_void, + *const c_void, + SecGetKeyFn, + *const c_void, + PCredHandle, + PTimeStamp, +) -> SecurityStatus; +pub type AcquireCredentialsHandleFnW = unsafe extern "system" fn( + LpcWStr, + LpcWStr, + u32, + *const c_void, + *const c_void, + SecGetKeyFn, + *const c_void, + PCredHandle, + PTimeStamp, +) -> SecurityStatus; +pub type QueryCredentialsAttributesFnA = extern "system" fn(PCredHandle, u32, *mut c_void) -> SecurityStatus; +pub type QueryCredentialsAttributesFnW = extern "system" fn(PCredHandle, u32, *mut c_void) -> SecurityStatus; +pub type InitializeSecurityContextFnA = unsafe extern "system" fn( + PCredHandle, + PCtxtHandle, + *const SecChar, + u32, + u32, + u32, + PSecBufferDesc, + u32, + PCtxtHandle, + PSecBufferDesc, + *mut u32, + PTimeStamp, +) -> SecurityStatus; +pub type InitializeSecurityContextFnW = unsafe extern "system" fn( + PCredHandle, + PCtxtHandle, + *const SecWChar, + u32, + u32, + u32, + PSecBufferDesc, + u32, + PCtxtHandle, + PSecBufferDesc, + *mut u32, + PTimeStamp, +) -> SecurityStatus; +pub type QueryContextAttributesFnA = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void) -> SecurityStatus; +pub type QueryContextAttributesFnW = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void) -> SecurityStatus; +pub type EnumerateSecurityPackagesFnA = unsafe extern "system" fn(*mut u32, *mut PSecPkgInfoA) -> SecurityStatus; +pub type EnumerateSecurityPackagesFnW = unsafe extern "system" fn(*mut u32, *mut PSecPkgInfoW) -> SecurityStatus; +pub type QuerySecurityPackageInfoFnA = unsafe extern "system" fn(*const SecChar, *mut PSecPkgInfoA) -> SecurityStatus; +pub type QuerySecurityPackageInfoFnW = unsafe extern "system" fn(*const SecWChar, *mut PSecPkgInfoW) -> SecurityStatus; +pub type ImportSecurityContextFnA = + extern "system" fn(PSecurityString, PSecBuffer, *mut c_void, PCtxtHandle) -> SecurityStatus; +pub type ImportSecurityContextFnW = + extern "system" fn(PSecurityString, PSecBuffer, *mut c_void, PCtxtHandle) -> SecurityStatus; +pub type AddCredentialsFnA = extern "system" fn( + PCredHandle, + *mut SecChar, + *mut SecChar, + u32, + *mut c_void, + SecGetKeyFn, + *mut c_void, + PTimeStamp, +) -> SecurityStatus; +pub type AddCredentialsFnW = extern "system" fn( + PCredHandle, + *mut SecWChar, + *mut SecWChar, + u32, + *mut c_void, + SecGetKeyFn, + *mut c_void, + PTimeStamp, +) -> SecurityStatus; +pub type SetContextAttributesFnA = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; +pub type SetContextAttributesFnW = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; +pub type SetCredentialsAttributesFnA = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; +pub type SetCredentialsAttributesFnW = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; +pub type ChangeAccountPasswordFnA = unsafe extern "system" fn( + *mut SecChar, + *mut SecChar, + *mut SecChar, + *mut SecChar, + *mut SecChar, + bool, + u32, + PSecBufferDesc, +) -> SecurityStatus; +pub type ChangeAccountPasswordFnW = unsafe extern "system" fn( + *mut SecWChar, + *mut SecWChar, + *mut SecWChar, + *mut SecWChar, + *mut SecWChar, + bool, + u32, + PSecBufferDesc, +) -> SecurityStatus; +pub type QueryContextAttributesExFnA = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; +pub type QueryContextAttributesExFnW = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; +pub type QueryCredentialsAttributesExFnA = extern "system" fn(PCredHandle, u32, *mut c_void, u32) -> SecurityStatus; +pub type QueryCredentialsAttributesExFnW = extern "system" fn(PCredHandle, u32, *mut c_void, u32) -> SecurityStatus; + +#[repr(C)] +pub struct SecurityFunctionTableA { + pub dwVersion: u32, + pub EnumerateSecurityPackagesA: EnumerateSecurityPackagesFnA, + pub QueryCredentialsAttributesA: QueryCredentialsAttributesFnA, + pub AcquireCredentialsHandleA: AcquireCredentialsHandleFnA, + pub FreeCredentialsHandle: FreeCredentialsHandleFn, + pub Reserved2: *const c_void, + pub InitializeSecurityContextA: InitializeSecurityContextFnA, + pub AcceptSecurityContext: AcceptSecurityContextFn, + pub CompleteAuthToken: CompleteAuthTokenFn, + pub DeleteSecurityContext: DeleteSecurityContextFn, + pub ApplyControlToken: ApplyControlTokenFn, + pub QueryContextAttributesA: QueryContextAttributesFnA, + pub ImpersonateSecurityContext: ImpersonateSecurityContextFn, + pub RevertSecurityContext: RevertSecurityContextFn, + pub MakeSignature: MakeSignatureFn, + pub VerifySignature: VerifySignatureFn, + pub FreeContextBuffer: FreeContextBufferFn, + pub QuerySecurityPackageInfoA: QuerySecurityPackageInfoFnA, + pub Reserved3: EncryptMessageFn, + pub Reserved4: DecryptMessageFn, + pub ExportSecurityContext: ExportSecurityContextFn, + pub ImportSecurityContextA: ImportSecurityContextFnA, + pub AddCredentialsA: AddCredentialsFnA, + pub Reserved8: *const c_void, + pub QuerySecurityContextToken: QuerySecurityContextTokenFn, + pub EncryptMessage: EncryptMessageFn, + pub DecryptMessage: DecryptMessageFn, + pub SetContextAttributesA: SetContextAttributesFnA, + pub SetCredentialsAttributesA: SetCredentialsAttributesFnA, + pub ChangeAccountPasswordA: ChangeAccountPasswordFnA, + pub Reserved9: *const c_void, + pub QueryContextAttributesExA: QueryContextAttributesExFnA, + pub QueryCredentialsAttributesExA: QueryCredentialsAttributesExFnA, +} + +pub type PSecurityFunctionTableA = *mut SecurityFunctionTableA; + +#[repr(C)] +pub struct SecurityFunctionTableW { + pub dwVersion: u32, + pub EnumerateSecurityPackagesW: EnumerateSecurityPackagesFnW, + pub QueryCredentialsAttributesW: QueryCredentialsAttributesFnW, + pub AcquireCredentialsHandleW: AcquireCredentialsHandleFnW, + pub FreeCredentialsHandle: FreeCredentialsHandleFn, + pub Reserved2: *const c_void, + pub InitializeSecurityContextW: InitializeSecurityContextFnW, + pub AcceptSecurityContext: AcceptSecurityContextFn, + pub CompleteAuthToken: CompleteAuthTokenFn, + pub DeleteSecurityContext: DeleteSecurityContextFn, + pub ApplyControlToken: ApplyControlTokenFn, + pub QueryContextAttributesW: QueryContextAttributesFnW, + pub ImpersonateSecurityContext: ImpersonateSecurityContextFn, + pub RevertSecurityContext: RevertSecurityContextFn, + pub MakeSignature: MakeSignatureFn, + pub VerifySignature: VerifySignatureFn, + pub FreeContextBuffer: FreeContextBufferFn, + pub QuerySecurityPackageInfoW: QuerySecurityPackageInfoFnW, + pub Reserved3: EncryptMessageFn, + pub Reserved4: DecryptMessageFn, + pub ExportSecurityContext: ExportSecurityContextFn, + pub ImportSecurityContextW: ImportSecurityContextFnW, + pub AddCredentialsW: AddCredentialsFnW, + pub Reserved8: *const c_void, + pub QuerySecurityContextToken: QuerySecurityContextTokenFn, + pub EncryptMessage: EncryptMessageFn, + pub DecryptMessage: DecryptMessageFn, + pub SetContextAttributesW: SetContextAttributesFnW, + pub SetCredentialsAttributesW: SetCredentialsAttributesFnW, + pub ChangeAccountPasswordW: ChangeAccountPasswordFnW, + pub Reserved9: *const c_void, + pub QueryContextAttributesExW: QueryContextAttributesExFnW, + pub QueryCredentialsAttributesExW: QueryCredentialsAttributesExFnW, +} + +pub type PSecurityFunctionTableW = *mut SecurityFunctionTableW; diff --git a/crates/ffi-types/src/sspi/mod.rs b/crates/ffi-types/src/sspi/mod.rs new file mode 100644 index 00000000..ab5c57a5 --- /dev/null +++ b/crates/ffi-types/src/sspi/mod.rs @@ -0,0 +1,576 @@ +//! C-compatible SSPI declarations shared by FFI implementations. + +#![allow(non_snake_case)] + +mod functions; + +use core::ffi::{c_char, c_void}; + +pub use functions::*; + +pub type SecChar = c_char; +pub type LpStr = *const SecChar; +pub type SecWChar = u16; +pub type LpcWStr = *const SecWChar; +pub type SecurityStatus = u32; + +/// [SECURITY_INTEGER](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-security_integer) +/// +/// ```c +/// typedef struct _SECURITY_INTEGER { +/// unsigned long LowPart; +/// long HighPart; +/// } SECURITY_INTEGER, *PSECURITY_INTEGER; +/// ``` +#[repr(C)] +pub struct SecurityInteger { + pub low_part: u32, + pub high_part: i32, +} +pub type PTimeStamp = *mut SecurityInteger; + +/// [SECURITY_STRING](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-security_string) +/// +/// The SECURITY_STRING structure is used as the string interface for kernel operations and is a clone +/// of the [UNICODE_STRING](https://learn.microsoft.com/en-us/windows/win32/api/subauth/ns-subauth-unicode_string) +/// structure. This is used for 32-bit mode. +/// +/// ```c +/// typedef struct _SECURITY_STRING { +/// unsigned short Length; +/// unsigned short MaximumLength; +/// unsigned short *Buffer; +/// } SECURITY_STRING, *PSECURITY_STRING; +/// ``` +#[repr(C)] +pub struct SecurityString { + pub length: u16, + pub maximum_length: u16, + pub buffer: *mut u16, +} +pub type PSecurityString = *mut SecurityString; + +/// [SecBuffer](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secbuffer) +/// +/// ```c +/// typedef struct _SecBuffer { +/// unsigned long cbBuffer; +/// unsigned long BufferType; +///#if ... +/// char *pvBuffer; +///#else +/// void SEC_FAR *pvBuffer; +///#endif +/// } SecBuffer, *PSecBuffer; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecBuffer { + pub cb_buffer: u32, + pub buffer_type: u32, + pub pv_buffer: *mut c_char, +} +pub type PSecBuffer = *mut SecBuffer; + +/// [SecBufferDesc](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secbufferdesc) +/// +/// ```c +/// typedef struct _SecBufferDesc { +/// unsigned long ulVersion; +/// unsigned long cBuffers; +/// PSecBuffer pBuffers; +/// } SecBufferDesc, *PSecBufferDesc; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecBufferDesc { + pub ul_version: u32, + pub c_buffers: u32, + pub p_buffers: PSecBuffer, +} +pub type PSecBufferDesc = *mut SecBufferDesc; + +/// [SecPkgContext_Sizes](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_sizes) +/// +/// ```c +/// typedef struct _SecPkgContext_Sizes { +/// unsigned long cbMaxToken; +/// unsigned long cbMaxSignature; +/// unsigned long cbBlockSize; +/// unsigned long cbSecurityTrailer; +/// } SecPkgContext_Sizes, *PSecPkgContext_Sizes; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgContextSizes { + pub cb_max_token: u32, + pub cb_max_signature: u32, + pub cb_block_size: u32, + pub cb_security_trailer: u32, +} + +/// [SecPkgContext_StreamSizes](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_streamsizes) +/// +/// ```c +/// typedef struct _SecPkgContext_StreamSizes { +/// unsigned long cbHeader; +/// unsigned long cbTrailer; +/// unsigned long cbMaximumMessage; +/// unsigned long cBuffers; +/// unsigned long cbBlockSize; +/// } SecPkgContext_StreamSizes, *PSecPkgContext_StreamSizes; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgContextStreamSizes { + pub cb_header: u32, + pub cb_trailer: u32, + pub cb_maximum_message: u32, + pub c_buffers: u32, + pub cb_block_size: u32, +} +pub type SecGetKeyFn = extern "system" fn(*mut c_void, *mut c_void, u32, *mut *mut c_void, *mut i32); + +/// [SecPkgContext_Flags](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_flags) +/// +/// ```c +/// typedef struct _SecPkgContext_Flags { +/// unsigned long Flags; +/// } SecPkgContext_Flags, *PSecPkgContext_Flags; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgContextFlags { + pub flags: u32, +} + +/// [ALG_ID](https://learn.microsoft.com/en-us/windows/win32/seccrypto/alg-id) +/// typedef unsigned int ALG_ID; +pub type AlgId = u32; + +/// [SecPkgContext_ConnectionInfo](https://learn.microsoft.com/en-us/windows/win32/api/schannel/ns-schannel-secpkgcontext_connectioninfo) +/// +/// ```c +/// typedef struct _SecPkgContext_ConnectionInfo { +/// DWORD dwProtocol; +/// ALG_ID aiCipher; +/// DWORD dwCipherStrength; +/// ALG_ID aiHash; +/// DWORD dwHashStrength; +/// ALG_ID aiExch; +/// DWORD dwExchStrength; +/// } SecPkgContext_ConnectionInfo, *PSecPkgContext_ConnectionInfo; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgContextConnectionInfo { + pub dw_protocol: u32, + pub ai_cipher: AlgId, + pub dw_cipher_strength: u32, + pub ai_hash: AlgId, + pub dw_hash_strength: u32, + pub ai_exch: AlgId, + pub dw_exch_strength: u32, +} + +/// [SecPkgContext_SessionKey](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_sessionkey) +/// +/// ```c +/// typedef struct _SecPkgContext_SessionKey { +/// unsigned long SessionKeyLength; +/// unsigned char *SessionKey; +/// } SecPkgContext_SessionKey, *PSecPkgContext_SessionKey; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgContextSessionKey { + pub session_key_len: u32, + pub session_key: *mut u8, +} + +/// [CERT_TRUST_STATUS](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/ns-wincrypt-cert_trust_status) +/// +/// ```c +/// typedef struct _CERT_TRUST_STATUS { +/// DWORD dwErrorStatus; +/// DWORD dwInfoStatus; +/// } CERT_TRUST_STATUS, *PCERT_TRUST_STATUS; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct CertTrustStatus { + pub dw_error_status: u32, + pub dw_info_status: u32, +} + +/// [SecPkgContext_NamesA](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_namesa) +/// +/// ```c +/// typedef struct _SecPkgContext_NamesA { +/// SEC_CHAR *sUserName; +/// } SecPkgContext_NamesA, *PSecPkgContext_NamesA; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgContextNamesA { + pub user_name: *mut SecChar, +} + +/// [SecPkgContext_NamesW](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_namesw) +/// +/// ```c +/// typedef struct _SecPkgContext_NamesW { +/// SEC_WCHAR *sUserName; +/// } SecPkgContextNamesW, *PSecPkgContextNamesW; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgContextNamesW { + pub user_name: *mut SecWChar, +} + +pub const SECPKG_NEGOTIATION_COMPLETE: u32 = 0; +pub const SECPKG_NEGOTIATION_OPTIMISTIC: u32 = 1; +pub const SECPKG_NEGOTIATION_IN_PROGRESS: u32 = 2; +pub const SECPKG_ATTR_SIZES: u32 = 0; +pub const SECPKG_ATTR_NAMES: u32 = 1; +pub const SECPKG_ATTR_NEGOTIATION_INFO: u32 = 12; +pub const SECPKG_ATTR_STREAM_SIZES: u32 = 4; +pub const SECPKG_ATTR_REMOTE_CERT_CONTEXT: u32 = 0x53; +pub const SECPKG_ATTR_NEGOTIATION_PACKAGE: u32 = 0x80000081; +pub const SECPKG_ATTR_PACKAGE_INFO: u32 = 10; +pub const SECPKG_ATTR_SERVER_AUTH_FLAGS: u32 = 0x80000083; +pub const SECPKG_ATTR_CERT_TRUST_STATUS: u32 = 0x80000084; +pub const SECPKG_ATTR_CONNECTION_INFO: u32 = 0x5a; +pub const SECPKG_ATTR_SESSION_KEY: u32 = 9; +pub const SEC_WINNT_AUTH_IDENTITY_ANSI: u32 = 0x1; +pub const SEC_WINNT_AUTH_IDENTITY_UNICODE: u32 = 0x2; +pub const SEC_WINNT_AUTH_IDENTITY_VERSION: u32 = 0x200; +pub const SEC_WINNT_AUTH_IDENTITY_VERSION_2: u32 = 0x201; + +/// [SecHandle](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sechandle) +/// +/// ```c +/// typedef struct _SecHandle { +/// ULONG_PTR dwLower; +/// ULONG_PTR dwUpper; +/// } SecHandle, *PSecHandle; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecHandle { + pub dw_lower: u64, + pub dw_upper: u64, +} + +pub type PCredHandle = *mut SecHandle; +pub type PCtxtHandle = *mut SecHandle; + +/// [SecPkgInfoW](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkginfow) +/// +/// ```c +/// typedef struct _SecPkgInfoW { +/// unsigned long fCapabilities; +/// unsigned short wVersion; +/// unsigned short wRPCID; +/// unsigned long cbMaxToken; +/// SEC_WCHAR *Name; +/// SEC_WCHAR *Comment; +/// } SecPkgInfoW, *PSecPkgInfoW; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgInfoW { + pub f_capabilities: u32, + pub w_version: u16, + pub w_rpc_id: u16, + pub cb_max_token: u32, + pub name: *mut SecWChar, + pub comment: *mut SecWChar, +} + +pub type PSecPkgInfoW = *mut SecPkgInfoW; + +/// [SecPkgInfoA](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkginfoa) +/// +/// ```c +/// typedef struct _SecPkgInfoA { +/// unsigned long fCapabilities; +/// unsigned short wVersion; +/// unsigned short wRPCID; +/// unsigned long cbMaxToken; +/// SEC_CHAR *Name; +/// SEC_CHAR *Comment; +/// } SecPkgInfoA, *PSecPkgInfoA; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgInfoA { + pub f_capabilities: u32, + pub w_version: u16, + pub w_rpc_id: u16, + pub cb_max_token: u32, + pub name: *mut SecChar, + pub comment: *mut SecChar, +} + +pub type PSecPkgInfoA = *mut SecPkgInfoA; + +/// [SecPkgContext_NegotiationInfoW](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_negotiationinfow) +/// +/// ```c +/// typedef struct _SecPkgContext_NegotiationInfoW { +/// PSecPkgInfoW PackageInfo; +/// unsigned long NegotiationState; +/// } SecPkgContext_NegotiationInfoW, *PSecPkgContext_NegotiationInfoW; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecNegoInfoW { + pub package_info: *mut SecPkgInfoW, + pub nego_state: u32, +} + +/// [SecPkgContext_NegotiationInfoA](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_negotiationinfoa) +/// +/// ```c +/// typedef struct _SecPkgContext_NegotiationInfoA { +/// PSecPkgInfoA PackageInfo; +/// unsigned long NegotiationState; +/// } SecPkgContext_NegotiationInfoA, *PSecPkgContext_NegotiationInfoA; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecNegoInfoA { + pub package_info: *mut SecPkgInfoA, + pub nego_state: u32, +} + +/// [SecPkgCredentials_KdcProxySettingsW](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcredentials_kdcproxysettingsw) +/// +/// ```c +/// typedef struct _SecPkgCredentials_KdcProxySettingsW { +/// ULONG Version; +/// ULONG Flags; +/// USHORT ProxyServerOffset; +/// USHORT ProxyServerLength; +/// USHORT ClientTlsCredOffset; +/// USHORT ClientTlsCredLength; +/// } SecPkgCredentials_KdcProxySettingsW, *PSecPkgCredentials_KdcProxySettingsW; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgCredentialsKdcProxySettingsW { + pub version: u32, + pub flags: u32, + pub proxy_server_offset: u16, + pub proxy_server_length: u16, + pub client_tls_cred_offset: u16, + pub client_tls_cred_length: u16, +} + +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgCredentialsKdcUrlA { + pub kdc_url: *mut SecChar, +} + +#[derive(Debug)] +#[repr(C)] +pub struct SecPkgCredentialsKdcUrlW { + pub kdc_url: *mut SecWChar, +} + +/// [SEC_WINNT_AUTH_IDENTITY_W](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sec_winnt_auth_identity_w) +/// +/// ```c +/// typedef struct _SEC_WINNT_AUTH_IDENTITY_W { +/// unsigned short *User; +/// unsigned long UserLength; +/// unsigned short *Domain; +/// unsigned long DomainLength; +/// unsigned short *Password; +/// unsigned long PasswordLength; +/// unsigned long Flags; +/// } SEC_WINNT_AUTH_IDENTITY_W, *PSEC_WINNT_AUTH_IDENTITY_W; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecWinntAuthIdentityW { + pub user: *const u16, + pub user_length: u32, + pub domain: *const u16, + pub domain_length: u32, + pub password: *const u16, + pub password_length: u32, + pub flags: u32, +} + +/// [SEC_WINNT_AUTH_IDENTITY_A](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sec_winnt_auth_identity_a) +/// +/// ```c +/// typedef struct _SEC_WINNT_AUTH_IDENTITY_A { +/// unsigned char *User; +/// unsigned long UserLength; +/// unsigned char *Domain; +/// unsigned long DomainLength; +/// unsigned char *Password; +/// unsigned long PasswordLength; +/// unsigned long Flags; +/// } SEC_WINNT_AUTH_IDENTITY_A, *PSEC_WINNT_AUTH_IDENTITY_A; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecWinntAuthIdentityA { + pub user: *const c_char, + pub user_length: u32, + pub domain: *const c_char, + pub domain_length: u32, + pub password: *const c_char, + pub password_length: u32, + pub flags: u32, +} + +/// [SEC_WINNT_AUTH_IDENTITY_EXW](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sec_winnt_auth_identity_exw) +/// +/// ```c +/// typedef struct _SEC_WINNT_AUTH_IDENTITY_EXW { +/// unsigned long Version; +/// unsigned long Length; +/// unsigned short *User; +/// unsigned long UserLength; +/// unsigned short *Domain; +/// unsigned long DomainLength; +/// unsigned short *Password; +/// unsigned long PasswordLength; +/// unsigned long Flags; +/// unsigned short *PackageList; +/// unsigned long PackageListLength; +/// } SEC_WINNT_AUTH_IDENTITY_EXW, *PSEC_WINNT_AUTH_IDENTITY_EXW; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecWinntAuthIdentityExW { + pub version: u32, + pub length: u32, + pub user: *const u16, + pub user_length: u32, + pub domain: *const u16, + pub domain_length: u32, + pub password: *const u16, + pub password_length: u32, + pub flags: u32, + pub package_list: *const u16, + pub package_list_length: u32, +} + +/// [SEC_WINNT_AUTH_IDENTITY_EXA](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sec_winnt_auth_identity_exa) +/// +/// ```c +/// typedef struct _SEC_WINNT_AUTH_IDENTITY_EXA { +/// unsigned long Version; +/// unsigned long Length; +/// unsigned char *User; +/// unsigned long UserLength; +/// unsigned char *Domain; +/// unsigned long DomainLength; +/// unsigned char *Password; +/// unsigned long PasswordLength; +/// unsigned long Flags; +/// unsigned char *PackageList; +/// unsigned long PackageListLength; +/// } SEC_WINNT_AUTH_IDENTITY_EXA, *PSEC_WINNT_AUTH_IDENTITY_EXA; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecWinntAuthIdentityExA { + pub version: u32, + pub length: u32, + pub user: *const c_char, + pub user_length: u32, + pub domain: *const c_char, + pub domain_length: u32, + pub password: *const c_char, + pub password_length: u32, + pub flags: u32, + pub package_list: *const c_char, + pub package_list_length: u32, +} + +/// [SEC_WINNT_AUTH_IDENTITY_EX2](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sec_winnt_auth_identity_ex2) +/// +/// ```c +/// typedef struct _SEC_WINNT_AUTH_IDENTITY_EX2 { +/// unsigned long Version; +/// unsigned short cbHeaderLength; +/// unsigned long cbStructureLength; +/// unsigned long UserOffset; +/// unsigned short UserLength; +/// unsigned long DomainOffset; +/// unsigned short DomainLength; +/// unsigned long PackedCredentialsOffset; +/// unsigned short PackedCredentialsLength; +/// unsigned long Flags; +/// unsigned long PackageListOffset; +/// unsigned short PackageListLength; +/// } SEC_WINNT_AUTH_IDENTITY_EX2, *PSEC_WINNT_AUTH_IDENTITY_EX2; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct SecWinntAuthIdentityEx2 { + pub version: u32, + pub cb_header_length: u16, + pub cb_structure_length: u32, + pub user_offset: u32, + pub user_length: u16, + pub domain_offset: u32, + pub domain_length: u16, + pub packed_credentials_offset: u32, + pub packed_credentials_length: u16, + pub flags: u32, + pub package_list_offset: u32, + pub package_list_length: u16, +} + +/// [CREDSPP_SUBMIT_TYPE](https://learn.microsoft.com/en-us/windows/win32/api/credssp/ne-credssp-credspp_submit_type) +/// +/// ```c +/// typedef enum _CREDSSP_SUBMIT_TYPE { +/// CredsspPasswordCreds = 2, +/// CredsspSchannelCreds = 4, +/// CredsspCertificateCreds = 13, +/// CredsspSubmitBufferBoth = 50, +/// CredsspSubmitBufferBothOld = 51, +/// CredsspCredEx = 100 +/// } CREDSPP_SUBMIT_TYPE; +/// ``` +#[derive(Debug, Clone, Copy, Eq, PartialEq)] +#[repr(C)] +pub enum CredSspSubmitType { + CredsspPasswordCreds = 2, + CredsspSchannelCreds = 4, + CredsspCertificateCreds = 13, + CredsspSubmitBufferBoth = 50, + CredsspSubmitBufferBothOld = 51, + CredsspCredEx = 100, +} + +/// [CREDSSP_CRED](https://learn.microsoft.com/en-us/windows/win32/api/credssp/ns-credssp-credssp_cred) +/// +/// ```c +/// typedef struct _CREDSSP_CRED { +/// CREDSPP_SUBMIT_TYPE Type; +/// PVOID pSchannelCred; +/// PVOID pSpnegoCred; +/// } CREDSSP_CRED, *PCREDSSP_CRED; +/// ``` +#[derive(Debug)] +#[repr(C)] +pub struct CredSspCred { + pub submit_type: CredSspSubmitType, + pub p_schannel_cred: *const c_void, + pub p_spnego_cred: *const c_void, +} + +pub type HCRYPTPROV = usize; +pub type HCRYPTKEY = usize; diff --git a/ffi/Cargo.toml b/ffi/Cargo.toml index 6c921f2e..3be93b3d 100644 --- a/ffi/Cargo.toml +++ b/ffi/Cargo.toml @@ -15,10 +15,10 @@ crate-type = ["cdylib"] [features] default = ["aws-lc-rs", "scard", "dpapi"] tsssp = ["sspi/tsssp", "dpapi/tsssp"] -scard = ["sspi/scard", "dep:ffi-types", "dep:winscard", "dep:bitflags", "dep:picky-asn1-x509", "dep:picky-asn1", "dep:picky", "dep:cryptoki"] +scard = ["sspi/scard", "dep:winscard", "dep:bitflags", "dep:picky-asn1-x509", "dep:picky-asn1", "dep:picky", "dep:cryptoki", "ffi-types/winscard"] aws-lc-rs = ["sspi/aws-lc-rs"] ring = ["sspi/ring"] -dpapi = ["dep:dpapi", "dep:dpapi-transport", "dep:dpapi-native-transport", "dep:tokio", "dep:url", "dep:ffi-types"] +dpapi = ["dep:dpapi", "dep:dpapi-transport", "dep:dpapi-native-transport", "dep:tokio", "dep:url"] [dependencies] cfg-if = "1" @@ -26,7 +26,7 @@ num-traits = { version = "0.2", default-features = true } whoami = "2.1" sha1 = { version = "0.11", default-features = false } sha2 = "0.11" -ffi-types = { workspace = true, features = ["winscard"], optional = true } +ffi-types = { workspace = true, features = ["sspi"] } picky = { version = "=7.0.0-rc.26", default-features = false, features = ["x509"], optional = true } picky-asn1-der = "0.5" diff --git a/ffi/build.rs b/ffi/build.rs index d88a883d..3b3f0afb 100644 --- a/ffi/build.rs +++ b/ffi/build.rs @@ -138,8 +138,8 @@ fn main() { .input_extern_file("src/sspi/sec_winnt_auth_identity.rs") .input_extern_file("src/sspi/security_tables.rs") .input_extern_file("src/sspi/sec_buffer.rs") - .input_extern_file("src/sspi/sspi_data_types.rs"); - + .input_extern_file("../crates/ffi-types/src/sspi/functions.rs") + .input_extern_file("../crates/ffi-types/src/sspi/mod.rs"); #[cfg(feature = "dpapi")] { csbindgen_builder = csbindgen_builder diff --git a/ffi/dotnet/Devolutions.Sspi/Sspi.g.cs b/ffi/dotnet/Devolutions.Sspi/Sspi.g.cs index 3c83163e..1433f425 100644 --- a/ffi/dotnet/Devolutions.Sspi/Sspi.g.cs +++ b/ffi/dotnet/Devolutions.Sspi/Sspi.g.cs @@ -1206,35 +1206,6 @@ public static unsafe partial class Sspi } - [StructLayout(LayoutKind.Sequential)] - public unsafe partial struct SecHandle - { - public ulong dw_lower; - public ulong dw_upper; - } - - [StructLayout(LayoutKind.Sequential)] - public unsafe partial struct SecPkgInfoW - { - public uint f_capabilities; - public ushort w_version; - public ushort w_rpc_id; - public uint cb_max_token; - public ushort* name; - public ushort* comment; - } - - [StructLayout(LayoutKind.Sequential)] - public unsafe partial struct SecPkgInfoA - { - public uint f_capabilities; - public ushort w_version; - public ushort w_rpc_id; - public uint cb_max_token; - public byte* name; - public byte* comment; - } - [StructLayout(LayoutKind.Sequential)] public unsafe partial struct SecurityFunctionTableA { @@ -1311,6 +1282,61 @@ public unsafe partial struct SecurityFunctionTableW public delegate* unmanaged[Cdecl] QueryCredentialsAttributesExW; } + /// + /// [SECURITY_INTEGER](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-security_integer) + /// + /// ```c + /// typedef struct _SECURITY_INTEGER { + /// unsigned long LowPart; + /// long HighPart; + /// } SECURITY_INTEGER, *PSECURITY_INTEGER; + /// ``` + /// + [StructLayout(LayoutKind.Sequential)] + public unsafe partial struct SecurityInteger + { + public uint low_part; + public int high_part; + } + + /// + /// [SECURITY_STRING](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-security_string) + /// + /// The SECURITY_STRING structure is used as the string interface for kernel operations and is a clone + /// of the [UNICODE_STRING](https://learn.microsoft.com/en-us/windows/win32/api/subauth/ns-subauth-unicode_string) + /// structure. This is used for 32-bit mode. + /// + /// ```c + /// typedef struct _SECURITY_STRING { + /// unsigned short Length; + /// unsigned short MaximumLength; + /// unsigned short *Buffer; + /// } SECURITY_STRING, *PSECURITY_STRING; + /// ``` + /// + [StructLayout(LayoutKind.Sequential)] + public unsafe partial struct SecurityString + { + public ushort length; + public ushort maximum_length; + public ushort* buffer; + } + + /// + /// [SecBuffer](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secbuffer) + /// + /// ```c + /// typedef struct _SecBuffer { + /// unsigned long cbBuffer; + /// unsigned long BufferType; + /// #if ... + /// char *pvBuffer; + /// #else + /// void SEC_FAR *pvBuffer; + /// #endif + /// } SecBuffer, *PSecBuffer; + /// ``` + /// [StructLayout(LayoutKind.Sequential)] public unsafe partial struct SecBuffer { @@ -1319,6 +1345,17 @@ public unsafe partial struct SecBuffer public byte* pv_buffer; } + /// + /// [SecBufferDesc](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secbufferdesc) + /// + /// ```c + /// typedef struct _SecBufferDesc { + /// unsigned long ulVersion; + /// unsigned long cBuffers; + /// PSecBuffer pBuffers; + /// } SecBufferDesc, *PSecBufferDesc; + /// ``` + /// [StructLayout(LayoutKind.Sequential)] public unsafe partial struct SecBufferDesc { @@ -1327,19 +1364,71 @@ public unsafe partial struct SecBufferDesc public SecBuffer* p_buffers; } + /// + /// [SecHandle](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sechandle) + /// + /// ```c + /// typedef struct _SecHandle { + /// ULONG_PTR dwLower; + /// ULONG_PTR dwUpper; + /// } SecHandle, *PSecHandle; + /// ``` + /// [StructLayout(LayoutKind.Sequential)] - public unsafe partial struct SecurityInteger + public unsafe partial struct SecHandle { - public uint low_part; - public int high_part; + public ulong dw_lower; + public ulong dw_upper; } + /// + /// [SecPkgInfoW](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkginfow) + /// + /// ```c + /// typedef struct _SecPkgInfoW { + /// unsigned long fCapabilities; + /// unsigned short wVersion; + /// unsigned short wRPCID; + /// unsigned long cbMaxToken; + /// SEC_WCHAR *Name; + /// SEC_WCHAR *Comment; + /// } SecPkgInfoW, *PSecPkgInfoW; + /// ``` + /// [StructLayout(LayoutKind.Sequential)] - public unsafe partial struct SecurityString + public unsafe partial struct SecPkgInfoW { - public ushort length; - public ushort maximum_length; - public ushort* buffer; + public uint f_capabilities; + public ushort w_version; + public ushort w_rpc_id; + public uint cb_max_token; + public ushort* name; + public ushort* comment; + } + + /// + /// [SecPkgInfoA](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkginfoa) + /// + /// ```c + /// typedef struct _SecPkgInfoA { + /// unsigned long fCapabilities; + /// unsigned short wVersion; + /// unsigned short wRPCID; + /// unsigned long cbMaxToken; + /// SEC_CHAR *Name; + /// SEC_CHAR *Comment; + /// } SecPkgInfoA, *PSecPkgInfoA; + /// ``` + /// + [StructLayout(LayoutKind.Sequential)] + public unsafe partial struct SecPkgInfoA + { + public uint f_capabilities; + public ushort w_version; + public ushort w_rpc_id; + public uint cb_max_token; + public byte* name; + public byte* comment; } /// diff --git a/ffi/src/sspi/common.rs b/ffi/src/sspi/common.rs index df24a8d7..80cc299b 100644 --- a/ffi/src/sspi/common.rs +++ b/ffi/src/sspi/common.rs @@ -1,6 +1,7 @@ use std::ptr; use std::slice::{from_raw_parts, from_raw_parts_mut}; +use ffi_types::sspi::{PTimeStamp, SecurityStatus}; use libc::c_void; use num_traits::cast::{FromPrimitive, ToPrimitive}; use sspi::{ @@ -15,7 +16,6 @@ use super::sec_buffer::{ PSecBuffer, PSecBufferDesc, SecBuffer, copy_to_c_sec_buffer, p_sec_buffers_to_security_buffers, }; use super::sec_handle::{CredentialsHandle, PCredHandle, PCtxtHandle, p_ctxt_handle_to_sspi_context}; -use super::sspi_data_types::{PTimeStamp, SecurityStatus}; use super::utils::transform_credentials_handle; use crate::sspi::sec_handle::SspiHandle; use crate::utils::into_raw_ptr; @@ -50,8 +50,6 @@ pub unsafe extern "system" fn FreeCredentialsHandle(ph_credential: PCredHandle) 0 } -pub type FreeCredentialsHandleFn = unsafe extern "system" fn(PCredHandle) -> SecurityStatus; - /// The `AcceptSecurityContext` function lets the server component of a transport application /// establish a security context between the server and a remote client. /// @@ -193,18 +191,6 @@ pub unsafe extern "system" fn AcceptSecurityContext( } } -pub type AcceptSecurityContextFn = unsafe extern "system" fn( - PCredHandle, - PCtxtHandle, - PSecBufferDesc, - u32, - u32, - PCtxtHandle, - PSecBufferDesc, - *mut u32, - PTimeStamp, -) -> SecurityStatus; - /// The `CompleteAuthToken` function completes an authentication token. /// /// [MSDN Reference](https://learn.microsoft.com/en-us/windows/win32/api/sspi/nf-sspi-completeauthtoken) @@ -270,8 +256,6 @@ pub unsafe extern "system" fn CompleteAuthToken( } } -pub type CompleteAuthTokenFn = unsafe extern "system" fn(PCtxtHandle, PSecBufferDesc) -> SecurityStatus; - /// The `DeleteSecurityContext` function deletes the local data structures associated with the specified /// `security context` initiated by a previous call to the `InitializeSecurityContext` function or the /// `AcceptSecurityContext` function. @@ -324,8 +308,6 @@ pub unsafe extern "system" fn DeleteSecurityContext(mut ph_context: PCtxtHandle) ) } -pub type DeleteSecurityContextFn = unsafe extern "system" fn(PCtxtHandle) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_ApplyControlToken"))] #[unsafe(no_mangle)] @@ -333,8 +315,6 @@ pub extern "system" fn ApplyControlToken(_ph_context: PCtxtHandle, _p_input: PSe ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type ApplyControlTokenFn = extern "system" fn(PCtxtHandle, PSecBufferDesc) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_ImpersonateSecurityContext"))] #[unsafe(no_mangle)] @@ -342,8 +322,6 @@ pub extern "system" fn ImpersonateSecurityContext(_ph_context: PCtxtHandle) -> S ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type ImpersonateSecurityContextFn = extern "system" fn(PCtxtHandle) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_RevertSecurityContext"))] #[unsafe(no_mangle)] @@ -351,8 +329,6 @@ pub extern "system" fn RevertSecurityContext(_ph_context: PCtxtHandle) -> Securi ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type RevertSecurityContextFn = extern "system" fn(PCtxtHandle) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_MakeSignature"))] #[unsafe(no_mangle)] @@ -365,8 +341,6 @@ pub extern "system" fn MakeSignature( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type MakeSignatureFn = extern "system" fn(PCtxtHandle, u32, PSecBufferDesc, u32) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_VerifySignature"))] #[unsafe(no_mangle)] @@ -379,8 +353,6 @@ pub extern "system" fn VerifySignature( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type VerifySignatureFn = extern "system" fn(PCtxtHandle, PSecBufferDesc, u32, *mut u32) -> SecurityStatus; - /// The `FreeContextBuffer` function enables callers of `security package` functions to free memory buffers /// allocated by the security package. /// @@ -404,8 +376,6 @@ pub unsafe extern "system" fn FreeContextBuffer(pv_context_buffer: *mut c_void) 0 } -pub type FreeContextBufferFn = unsafe extern "system" fn(*mut c_void) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_ExportSecurityContext"))] #[unsafe(no_mangle)] @@ -418,8 +388,6 @@ pub extern "system" fn ExportSecurityContext( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type ExportSecurityContextFn = extern "system" fn(PCtxtHandle, u32, PSecBuffer, *mut *mut c_void) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_QuerySecurityContextToken"))] #[unsafe(no_mangle)] @@ -427,8 +395,6 @@ pub extern "system" fn QuerySecurityContextToken(_ph_context: PCtxtHandle, _toke ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type QuerySecurityContextTokenFn = extern "system" fn(PCtxtHandle, *mut *mut c_void) -> SecurityStatus; - /// The `EncryptMessage` function encrypts a message to provide privacy. /// /// [MSDN Reference](https://learn.microsoft.com/en-us/windows/win32/api/sspi/nf-sspi-encryptmessage) @@ -512,8 +478,6 @@ pub unsafe extern "system" fn EncryptMessage( } } -pub type EncryptMessageFn = unsafe extern "system" fn(PCtxtHandle, u32, PSecBufferDesc, u32) -> SecurityStatus; - /// The `DecryptMessage` function decrypts a message. /// /// Note: `pf_qop` can be null if this library is used as a CredSsp security package. @@ -607,8 +571,6 @@ pub unsafe extern "system" fn DecryptMessage( } } -pub type DecryptMessageFn = unsafe extern "system" fn(PCtxtHandle, PSecBufferDesc, u32, *mut u32) -> SecurityStatus; - /// Creates a vector of [SecurityBufferRef]s from the input C buffers. /// /// # Safety diff --git a/ffi/src/sspi/credentials_attributes.rs b/ffi/src/sspi/credentials_attributes.rs index 80e97cca..66a2f9e4 100644 --- a/ffi/src/sspi/credentials_attributes.rs +++ b/ffi/src/sspi/credentials_attributes.rs @@ -2,10 +2,11 @@ use std::mem::size_of; use std::ptr::NonNull; use std::slice::from_raw_parts; +use ffi_types::sspi::SecWChar; +pub use ffi_types::sspi::{SecPkgCredentialsKdcProxySettingsW, SecPkgCredentialsKdcUrlA, SecPkgCredentialsKdcUrlW}; use libc::c_void; use sspi::{Error, ErrorKind, Result}; -use super::sspi_data_types::{SecChar, SecWChar}; use super::utils::hostname; #[derive(Debug)] @@ -54,16 +55,6 @@ impl CredentialsAttributes { } } -#[repr(C)] -pub struct SecPkgCredentialsKdcProxySettingsW { - pub version: u32, - pub flags: u32, - pub proxy_server_offset: u16, - pub proxy_server_length: u16, - pub client_tls_cred_offset: u16, - pub client_tls_cred_length: u16, -} - /// Extracts [KdcProxySettings]. /// /// # Safety @@ -145,13 +136,3 @@ pub unsafe fn extract_kdc_proxy_settings(p_buffer: NonNull) -> Result SecurityStatus; - /// The `AcquireCredentialsHandleW` function acquires a handle to preexisting credentials of a security principal. /// /// NOTE: Although in the original Windows SSPI, `p_auth_data` parameter can be NULL, in our implementation it must be non-NULL. @@ -500,18 +464,6 @@ pub unsafe extern "system" fn AcquireCredentialsHandleW( } } -pub type AcquireCredentialsHandleFnW = unsafe extern "system" fn( - LpcWStr, - LpcWStr, - u32, - *const c_void, - *const c_void, - SecGetKeyFn, - *const c_void, - PCredHandle, - PTimeStamp, -) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_QueryCredentialsAttributesA"))] #[unsafe(no_mangle)] @@ -523,8 +475,6 @@ pub extern "system" fn QueryCredentialsAttributesA( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type QueryCredentialsAttributesFnA = extern "system" fn(PCredHandle, u32, *mut c_void) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_QueryCredentialsAttributesW"))] #[unsafe(no_mangle)] @@ -536,8 +486,6 @@ pub extern "system" fn QueryCredentialsAttributesW( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type QueryCredentialsAttributesFnW = extern "system" fn(PCredHandle, u32, *mut c_void) -> SecurityStatus; - /// The `InitializeSecurityContextA` function initiates the client side, outbound `security context` from /// a credential handle. The function is used to build a security context between the client application /// and a remote peer. `InitializeSecurityContextA` returns a token that the client must pass to the remote peer, @@ -683,21 +631,6 @@ pub unsafe extern "system" fn InitializeSecurityContextA( } } -pub type InitializeSecurityContextFnA = unsafe extern "system" fn( - PCredHandle, - PCtxtHandle, - *const SecChar, - u32, - u32, - u32, - PSecBufferDesc, - u32, - PCtxtHandle, - PSecBufferDesc, - *mut u32, - PTimeStamp, -) -> SecurityStatus; - /// The `InitializeSecurityContextW` function initiates the client side, outbound `security context` from /// a credential handle. The function is used to build a security context between the client application /// and a remote peer. `InitializeSecurityContextW` returns a token that the client must pass to the remote peer, @@ -849,21 +782,6 @@ pub unsafe extern "system" fn InitializeSecurityContextW( } } -pub type InitializeSecurityContextFnW = unsafe extern "system" fn( - PCredHandle, - PCtxtHandle, - *const SecWChar, - u32, - u32, - u32, - PSecBufferDesc, - u32, - PCtxtHandle, - PSecBufferDesc, - *mut u32, - PTimeStamp, -) -> SecurityStatus; - /// # Safety /// /// - `ph_context` must be a valid pointer to a `SecHandle` structure. @@ -1210,8 +1128,6 @@ pub unsafe extern "system" fn QueryContextAttributesA( unsafe { query_context_attributes_common(ph_context, ul_attribute, p_buffer, false) } } -pub type QueryContextAttributesFnA = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void) -> SecurityStatus; - /// The `QueryContextAttributesW` function lets a transport application query the Credential Security /// Support Provider (CredSSP) `security package` for certain attributes of a `security context`. /// @@ -1239,8 +1155,6 @@ pub unsafe extern "system" fn QueryContextAttributesW( unsafe { query_context_attributes_common(ph_context, ul_attribute, p_buffer, true) } } -pub type QueryContextAttributesFnW = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_ImportSecurityContextA"))] #[unsafe(no_mangle)] @@ -1253,9 +1167,6 @@ pub extern "system" fn ImportSecurityContextA( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type ImportSecurityContextFnA = - extern "system" fn(PSecurityString, PSecBuffer, *mut c_void, PCtxtHandle) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_ImportSecurityContextW"))] #[unsafe(no_mangle)] @@ -1268,9 +1179,6 @@ pub extern "system" fn ImportSecurityContextW( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type ImportSecurityContextFnW = - extern "system" fn(PSecurityString, PSecBuffer, *mut c_void, PCtxtHandle) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_AddCredentialsA"))] #[unsafe(no_mangle)] @@ -1287,17 +1195,6 @@ pub extern "system" fn AddCredentialsA( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type AddCredentialsFnA = extern "system" fn( - PCredHandle, - *mut SecChar, - *mut SecChar, - u32, - *mut c_void, - SecGetKeyFn, - *mut c_void, - PTimeStamp, -) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_AddCredentialsW"))] #[unsafe(no_mangle)] @@ -1314,17 +1211,6 @@ pub extern "system" fn AddCredentialsW( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type AddCredentialsFnW = extern "system" fn( - PCredHandle, - *mut SecWChar, - *mut SecWChar, - u32, - *mut c_void, - SecGetKeyFn, - *mut c_void, - PTimeStamp, -) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_SetContextAttributesA"))] #[unsafe(no_mangle)] @@ -1337,8 +1223,6 @@ pub extern "system" fn SetContextAttributesA( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type SetContextAttributesFnA = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; - #[cfg_attr(windows, rename_symbol(to = "Rust_SetContextAttributesW"))] #[unsafe(no_mangle)] pub extern "system" fn SetContextAttributesW( @@ -1350,8 +1234,6 @@ pub extern "system" fn SetContextAttributesW( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type SetContextAttributesFnW = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; - /// Sets the `attributes` of a `credential`, such as the name associated with the credential. The information /// is valid for any `security context` created with the specified credential. /// @@ -1446,8 +1328,6 @@ pub unsafe extern "system" fn SetCredentialsAttributesA( } } -pub type SetCredentialsAttributesFnA = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; - /// Sets the `attributes` of a `credential`, such as the name associated with the credential. The information /// is valid for any `security context` created with the specified credential. /// @@ -1541,8 +1421,6 @@ pub unsafe extern "system" fn SetCredentialsAttributesW( } } -pub type SetCredentialsAttributesFnW = unsafe extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; - /// The `ChangeAccountPasswordA` function changes the password for a Windows domain account by using /// the specified `Security Support Provider`. /// @@ -1674,17 +1552,6 @@ pub unsafe extern "system" fn ChangeAccountPasswordA( } } -pub type ChangeAccountPasswordFnA = unsafe extern "system" fn( - *mut SecChar, - *mut SecChar, - *mut SecChar, - *mut SecChar, - *mut SecChar, - bool, - u32, - PSecBufferDesc, -) -> SecurityStatus; - /// The `ChangeAccountPasswordW` function changes the password for a Windows domain account by using /// the specified `Security Support Provider`. /// @@ -1789,17 +1656,6 @@ pub unsafe extern "system" fn ChangeAccountPasswordW( } } -pub type ChangeAccountPasswordFnW = unsafe extern "system" fn( - *mut SecWChar, - *mut SecWChar, - *mut SecWChar, - *mut SecWChar, - *mut SecWChar, - bool, - u32, - PSecBufferDesc, -) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_QueryContextAttributesExA"))] #[unsafe(no_mangle)] @@ -1812,8 +1668,6 @@ pub extern "system" fn QueryContextAttributesExA( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type QueryContextAttributesExFnA = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_QueryContextAttributesExW"))] #[unsafe(no_mangle)] @@ -1826,8 +1680,6 @@ pub extern "system" fn QueryContextAttributesExW( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type QueryContextAttributesExFnW = extern "system" fn(PCtxtHandle, u32, *mut c_void, u32) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_QueryCredentialsAttributesExA"))] #[unsafe(no_mangle)] @@ -1840,8 +1692,6 @@ pub extern "system" fn QueryCredentialsAttributesExA( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type QueryCredentialsAttributesExFnA = extern "system" fn(PCredHandle, u32, *mut c_void, u32) -> SecurityStatus; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_QueryCredentialsAttributesExW"))] #[unsafe(no_mangle)] @@ -1854,8 +1704,6 @@ pub extern "system" fn QueryCredentialsAttributesExW( ErrorKind::UnsupportedFunction.to_u32().unwrap() } -pub type QueryCredentialsAttributesExFnW = extern "system" fn(PCredHandle, u32, *mut c_void, u32) -> SecurityStatus; - #[cfg(test)] #[expect( clippy::undocumented_unsafe_blocks, @@ -2545,10 +2393,10 @@ mod tests { fn query_context_session_key() { use std::slice::from_raw_parts; + use ffi_types::sspi::SecPkgContextSessionKey; use sspi::credssp::SspiContext; use crate::sspi::sec_handle::{QueryContextAttributesW, SECPKG_ATTR_SESSION_KEY, SspiHandle}; - use crate::sspi::sspi_data_types::SecPkgContextSessionKey; use crate::utils::into_raw_ptr; let kerberos_client = sspi::kerberos::test_data::fake_client(); @@ -2605,12 +2453,12 @@ mod tests { #[test] fn query_context_names() { + use ffi_types::sspi::{SecPkgContextNamesA, SecPkgContextNamesW}; use sspi::credssp::SspiContext; use crate::sspi::sec_handle::{ QueryContextAttributesA, QueryContextAttributesW, SECPKG_ATTR_NAMES, SspiHandle, }; - use crate::sspi::sspi_data_types::{SecPkgContextNamesA, SecPkgContextNamesW}; use crate::utils::into_raw_ptr; let kerberos_client = sspi::kerberos::test_data::fake_client(); diff --git a/ffi/src/sspi/sec_pkg_info.rs b/ffi/src/sspi/sec_pkg_info.rs index c0f82338..ba58f068 100644 --- a/ffi/src/sspi/sec_pkg_info.rs +++ b/ffi/src/sspi/sec_pkg_info.rs @@ -2,27 +2,17 @@ use std::ffi::CStr; use std::mem::size_of; use std::ptr::copy_nonoverlapping; +use ffi_types::sspi::SecurityStatus; +pub use ffi_types::sspi::{ + EnumerateSecurityPackagesFnA, EnumerateSecurityPackagesFnW, PSecPkgInfoA, PSecPkgInfoW, + QuerySecurityPackageInfoFnA, QuerySecurityPackageInfoFnW, SecChar, SecPkgInfoA, SecPkgInfoW, SecWChar, +}; use sspi::{ Error, KERBEROS_VERSION, PackageInfo, U16CString, Utf16String, Utf16StringExt, enumerate_security_packages, }; #[cfg(windows)] use symbol_rename_macro::rename_symbol; -use super::sspi_data_types::{SecChar, SecWChar, SecurityStatus}; - -#[derive(Debug)] -#[repr(C)] -pub struct SecPkgInfoW { - pub f_capabilities: u32, - pub w_version: u16, - pub w_rpc_id: u16, - pub cb_max_token: u32, - pub name: *mut SecWChar, - pub comment: *mut SecWChar, -} - -pub type PSecPkgInfoW = *mut SecPkgInfoW; - pub struct RawSecPkgInfoW(pub *mut SecPkgInfoW); #[allow(clippy::useless_conversion)] @@ -89,19 +79,6 @@ impl From for RawSecPkgInfoW { } } -#[derive(Debug)] -#[repr(C)] -pub struct SecPkgInfoA { - pub f_capabilities: u32, - pub w_version: u16, - pub w_rpc_id: u16, - pub cb_max_token: u32, - pub name: *mut SecChar, - pub comment: *mut SecChar, -} - -pub type PSecPkgInfoA = *mut SecPkgInfoA; - pub struct RawSecPkgInfoA(pub *mut SecPkgInfoA); #[allow(clippy::useless_conversion)] @@ -174,19 +151,7 @@ impl From for RawSecPkgInfoA { } } -#[derive(Debug)] -#[repr(C)] -pub struct SecNegoInfoW { - pub package_info: *mut SecPkgInfoW, - pub nego_state: u32, -} - -#[derive(Debug)] -#[repr(C)] -pub struct SecNegoInfoA { - pub package_info: *mut SecPkgInfoA, - pub nego_state: u32, -} +pub use ffi_types::sspi::{SecNegoInfoA, SecNegoInfoW}; /// The `EnumerateSecurityPackagesA` function returns an array of `SecPkgInfo` structures that provide /// information about the `security packages` available to the client. @@ -287,8 +252,6 @@ pub unsafe extern "system" fn EnumerateSecurityPackagesA( } } -pub type EnumerateSecurityPackagesFnA = unsafe extern "system" fn(*mut u32, *mut PSecPkgInfoA) -> SecurityStatus; - /// The `EnumerateSecurityPackagesW` function returns an array of `SecPkgInfo` structures that provide /// information about the `security packages` available to the client. /// @@ -388,8 +351,6 @@ pub unsafe extern "system" fn EnumerateSecurityPackagesW( } } -pub type EnumerateSecurityPackagesFnW = unsafe extern "system" fn(*mut u32, *mut PSecPkgInfoW) -> SecurityStatus; - /// Retrieves information about a specified `security package`. This information includes the bounds on /// sizes of authentication information, credentials, and contexts. /// @@ -431,8 +392,6 @@ pub unsafe extern "system" fn QuerySecurityPackageInfoA( } } -pub type QuerySecurityPackageInfoFnA = unsafe extern "system" fn(*const SecChar, *mut PSecPkgInfoA) -> SecurityStatus; - /// Retrieves information about a specified `security package`. This information includes the bounds on /// sizes of authentication information, credentials, and contexts. /// @@ -478,8 +437,6 @@ pub unsafe extern "system" fn QuerySecurityPackageInfoW( } } -pub type QuerySecurityPackageInfoFnW = unsafe extern "system" fn(*const SecWChar, *mut PSecPkgInfoW) -> SecurityStatus; - #[cfg(test)] #[expect( clippy::undocumented_unsafe_blocks, diff --git a/ffi/src/sspi/sec_winnt_auth_identity.rs b/ffi/src/sspi/sec_winnt_auth_identity.rs index 23bbb19e..7aaa6776 100644 --- a/ffi/src/sspi/sec_winnt_auth_identity.rs +++ b/ffi/src/sspi/sec_winnt_auth_identity.rs @@ -1,7 +1,15 @@ use std::ptr::copy_nonoverlapping; use std::slice::from_raw_parts; -use libc::{c_char, c_void}; +#[cfg(feature = "tsssp")] +pub use ffi_types::sspi::{CredSspCred, CredSspSubmitType}; +pub use ffi_types::sspi::{ + SEC_WINNT_AUTH_IDENTITY_ANSI, SEC_WINNT_AUTH_IDENTITY_UNICODE, SEC_WINNT_AUTH_IDENTITY_VERSION, + SEC_WINNT_AUTH_IDENTITY_VERSION_2, SecWinntAuthIdentityA, SecWinntAuthIdentityEx2, SecWinntAuthIdentityExA, + SecWinntAuthIdentityExW, SecWinntAuthIdentityW, +}; +use ffi_types::sspi::{SecWChar, SecurityStatus}; +use libc::c_void; use sspi::utf16string::ZeroizedUtf16String; use sspi::{ AuthIdentityBuffers, CredentialsBuffers, Error, ErrorKind, NonEmpty, Result, Secret, Utf16String, Utf16StringExt, @@ -15,147 +23,11 @@ use windows::Win32::Security::Credentials::CredIsMarshaledCredentialW; #[cfg(feature = "tsssp")] use windows::Win32::Security::Credentials::{CREDUI_INFOW, CredUIPromptForWindowsCredentialsW}; -use super::sspi_data_types::{SecWChar, SecurityStatus}; use crate::utils::{credentials_str_into_bytes, into_raw_ptr}; -pub const SEC_WINNT_AUTH_IDENTITY_ANSI: u32 = 0x1; -pub const SEC_WINNT_AUTH_IDENTITY_UNICODE: u32 = 0x2; - /// Environment variable name for specifying PKCS11 module path. pub const PKCS11_MODULE_PATH_ENV: &str = "SSPI_PKCS11_MODULE_PATH"; -#[repr(C)] -pub struct SecWinntAuthIdentityW { - pub user: *const u16, - pub user_length: u32, - pub domain: *const u16, - pub domain_length: u32, - pub password: *const u16, - pub password_length: u32, - pub flags: u32, -} - -#[repr(C)] -pub struct SecWinntAuthIdentityA { - pub user: *const c_char, - pub user_length: u32, - pub domain: *const c_char, - pub domain_length: u32, - pub password: *const c_char, - pub password_length: u32, - pub flags: u32, -} - -pub const SEC_WINNT_AUTH_IDENTITY_VERSION: u32 = 0x200; - -#[derive(Debug)] -#[repr(C)] -pub struct SecWinntAuthIdentityExW { - pub version: u32, - pub length: u32, - pub user: *const u16, - pub user_length: u32, - pub domain: *const u16, - pub domain_length: u32, - pub password: *const u16, - pub password_length: u32, - pub flags: u32, - pub package_list: *const u16, - pub package_list_length: u32, -} - -#[repr(C)] -pub struct SecWinntAuthIdentityExA { - pub version: u32, - pub length: u32, - pub user: *const c_char, - pub user_length: u32, - pub domain: *const c_char, - pub domain_length: u32, - pub password: *const c_char, - pub password_length: u32, - pub flags: u32, - pub package_list: *const c_char, - pub package_list_length: u32, -} - -pub const SEC_WINNT_AUTH_IDENTITY_VERSION_2: u32 = 0x201; - -/// [SEC_WINNT_AUTH_IDENTITY_EX2](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-sec_winnt_auth_identity_ex2) -/// -/// ```not_rust -/// typedef struct _SEC_WINNT_AUTH_IDENTITY_EX2 { -/// unsigned long Version; -/// unsigned short cbHeaderLength; -/// unsigned long cbStructureLength; -/// unsigned long UserOffset; -/// unsigned short UserLength; -/// unsigned long DomainOffset; -/// unsigned short DomainLength; -/// unsigned long PackedCredentialsOffset; -/// unsigned short PackedCredentialsLength; -/// unsigned long Flags; -/// unsigned long PackageListOffset; -/// unsigned short PackageListLength; -/// } SEC_WINNT_AUTH_IDENTITY_EX2, *PSEC_WINNT_AUTH_IDENTITY_EX2; -/// ``` -#[derive(Debug)] -#[repr(C)] -pub struct SecWinntAuthIdentityEx2 { - pub version: u32, - pub cb_header_length: u16, - pub cb_structure_length: u32, - pub user_offset: u32, - pub user_length: u16, - pub domain_offset: u32, - pub domain_length: u16, - pub packed_credentials_offset: u32, - pub packed_credentials_length: u16, - pub flags: u32, - pub package_list_offset: u32, - pub package_list_length: u16, -} - -/// [CREDSPP_SUBMIT_TYPE](https://learn.microsoft.com/en-us/windows/win32/api/credssp/ne-credssp-credspp_submit_type) -/// -/// ```not_rust -/// typedef enum _CREDSSP_SUBMIT_TYPE { -/// CredsspPasswordCreds = 2, -/// CredsspSchannelCreds = 4, -/// CredsspCertificateCreds = 13, -/// CredsspSubmitBufferBoth = 50, -/// CredsspSubmitBufferBothOld = 51, -/// CredsspCredEx = 100 -/// } CREDSPP_SUBMIT_TYPE; -/// ``` -#[derive(Debug, Clone, Copy, Eq, PartialEq)] -#[repr(C)] -pub enum CredSspSubmitType { - CredsspPasswordCreds = 2, - CredsspSchannelCreds = 4, - CredsspCertificateCreds = 13, - CredsspSubmitBufferBoth = 50, - CredsspSubmitBufferBothOld = 51, - CredsspCredEx = 100, -} - -/// [CREDSSP_CRED](https://learn.microsoft.com/en-us/windows/win32/api/credssp/ns-credssp-credssp_cred) -/// -/// ```not_rust -/// typedef struct _CREDSSP_CRED { -/// CREDSPP_SUBMIT_TYPE Type; -/// PVOID pSchannelCred; -/// PVOID pSpnegoCred; -/// } CREDSSP_CRED, *PCREDSSP_CRED; -/// ``` -#[derive(Debug)] -#[repr(C)] -pub struct CredSspCred { - pub submit_type: CredSspSubmitType, - pub p_schannel_cred: *const c_void, - pub p_spnego_cred: *const c_void, -} - /// Returns auth identity version and flags. /// /// # Safety diff --git a/ffi/src/sspi/security_tables.rs b/ffi/src/sspi/security_tables.rs index 6e50161d..7c8cf662 100644 --- a/ffi/src/sspi/security_tables.rs +++ b/ffi/src/sspi/security_tables.rs @@ -2,121 +2,35 @@ use std::ptr::null; -use libc::c_void; +pub use ffi_types::sspi::{ + AcceptSecurityContextFn, ApplyControlTokenFn, CompleteAuthTokenFn, DecryptMessageFn, DeleteSecurityContextFn, + EncryptMessageFn, ExportSecurityContextFn, FreeContextBufferFn, FreeCredentialsHandleFn, + ImpersonateSecurityContextFn, MakeSignatureFn, PSecurityFunctionTableA, PSecurityFunctionTableW, + QuerySecurityContextTokenFn, RevertSecurityContextFn, SecurityFunctionTableA, SecurityFunctionTableW, + VerifySignatureFn, +}; use sspi::KERBEROS_VERSION; #[cfg(windows)] use symbol_rename_macro::rename_symbol; use super::common::{ - AcceptSecurityContext, AcceptSecurityContextFn, ApplyControlToken, ApplyControlTokenFn, CompleteAuthToken, - CompleteAuthTokenFn, DecryptMessage, DecryptMessageFn, DeleteSecurityContext, DeleteSecurityContextFn, - EncryptMessage, EncryptMessageFn, ExportSecurityContext, ExportSecurityContextFn, FreeContextBuffer, - FreeContextBufferFn, FreeCredentialsHandle, FreeCredentialsHandleFn, ImpersonateSecurityContext, - ImpersonateSecurityContextFn, MakeSignature, MakeSignatureFn, QuerySecurityContextToken, - QuerySecurityContextTokenFn, RevertSecurityContext, RevertSecurityContextFn, VerifySignature, VerifySignatureFn, + AcceptSecurityContext, ApplyControlToken, CompleteAuthToken, DecryptMessage, DeleteSecurityContext, EncryptMessage, + ExportSecurityContext, FreeContextBuffer, FreeCredentialsHandle, ImpersonateSecurityContext, MakeSignature, + QuerySecurityContextToken, RevertSecurityContext, VerifySignature, }; use super::sec_handle::{ - AcquireCredentialsHandleA, AcquireCredentialsHandleFnA, AcquireCredentialsHandleFnW, AcquireCredentialsHandleW, - AddCredentialsA, AddCredentialsFnA, AddCredentialsFnW, AddCredentialsW, ChangeAccountPasswordA, - ChangeAccountPasswordFnA, ChangeAccountPasswordFnW, ChangeAccountPasswordW, ImportSecurityContextA, - ImportSecurityContextFnA, ImportSecurityContextFnW, ImportSecurityContextW, InitializeSecurityContextA, - InitializeSecurityContextFnA, InitializeSecurityContextFnW, InitializeSecurityContextW, QueryContextAttributesA, - QueryContextAttributesExA, QueryContextAttributesExFnA, QueryContextAttributesExFnW, QueryContextAttributesExW, - QueryContextAttributesFnA, QueryContextAttributesFnW, QueryContextAttributesW, QueryCredentialsAttributesA, - QueryCredentialsAttributesExA, QueryCredentialsAttributesExFnA, QueryCredentialsAttributesExFnW, - QueryCredentialsAttributesExW, QueryCredentialsAttributesFnA, QueryCredentialsAttributesFnW, - QueryCredentialsAttributesW, SetContextAttributesA, SetContextAttributesFnA, SetContextAttributesFnW, - SetContextAttributesW, SetCredentialsAttributesA, SetCredentialsAttributesFnA, SetCredentialsAttributesFnW, + AcquireCredentialsHandleA, AcquireCredentialsHandleW, AddCredentialsA, AddCredentialsW, ChangeAccountPasswordA, + ChangeAccountPasswordW, ImportSecurityContextA, ImportSecurityContextW, InitializeSecurityContextA, + InitializeSecurityContextW, QueryContextAttributesA, QueryContextAttributesExA, QueryContextAttributesExW, + QueryContextAttributesW, QueryCredentialsAttributesA, QueryCredentialsAttributesExA, QueryCredentialsAttributesExW, + QueryCredentialsAttributesW, SetContextAttributesA, SetContextAttributesW, SetCredentialsAttributesA, SetCredentialsAttributesW, }; use super::sec_pkg_info::{ - EnumerateSecurityPackagesA, EnumerateSecurityPackagesFnA, EnumerateSecurityPackagesFnW, EnumerateSecurityPackagesW, - QuerySecurityPackageInfoA, QuerySecurityPackageInfoFnA, QuerySecurityPackageInfoFnW, QuerySecurityPackageInfoW, + EnumerateSecurityPackagesA, EnumerateSecurityPackagesW, QuerySecurityPackageInfoA, QuerySecurityPackageInfoW, }; use crate::utils::into_raw_ptr; -#[repr(C)] -pub struct SecurityFunctionTableA { - pub dwVersion: u32, - pub EnumerateSecurityPackagesA: EnumerateSecurityPackagesFnA, - pub QueryCredentialsAttributesA: QueryCredentialsAttributesFnA, - pub AcquireCredentialsHandleA: AcquireCredentialsHandleFnA, - pub FreeCredentialsHandle: FreeCredentialsHandleFn, - pub Reserved2: *const c_void, - pub InitializeSecurityContextA: InitializeSecurityContextFnA, - pub AcceptSecurityContext: AcceptSecurityContextFn, - pub CompleteAuthToken: CompleteAuthTokenFn, - pub DeleteSecurityContext: DeleteSecurityContextFn, - pub ApplyControlToken: ApplyControlTokenFn, - pub QueryContextAttributesA: QueryContextAttributesFnA, - pub ImpersonateSecurityContext: ImpersonateSecurityContextFn, - pub RevertSecurityContext: RevertSecurityContextFn, - pub MakeSignature: MakeSignatureFn, - pub VerifySignature: VerifySignatureFn, - pub FreeContextBuffer: FreeContextBufferFn, - pub QuerySecurityPackageInfoA: QuerySecurityPackageInfoFnA, - // In the Windows sspicli.dll, the `Reserved3` field is used as EncryptFunction - pub Reserved3: EncryptMessageFn, - // In the Windows sspicli.dll, the `Reserved4` field is used as DecryptFunction - pub Reserved4: DecryptMessageFn, - pub ExportSecurityContext: ExportSecurityContextFn, - pub ImportSecurityContextA: ImportSecurityContextFnA, - pub AddCredentialsA: AddCredentialsFnA, - pub Reserved8: *const c_void, - pub QuerySecurityContextToken: QuerySecurityContextTokenFn, - pub EncryptMessage: EncryptMessageFn, - pub DecryptMessage: DecryptMessageFn, - pub SetContextAttributesA: SetContextAttributesFnA, - pub SetCredentialsAttributesA: SetCredentialsAttributesFnA, - pub ChangeAccountPasswordA: ChangeAccountPasswordFnA, - pub Reserved9: *const c_void, - pub QueryContextAttributesExA: QueryContextAttributesExFnA, - pub QueryCredentialsAttributesExA: QueryCredentialsAttributesExFnA, -} - -pub type PSecurityFunctionTableA = *mut SecurityFunctionTableA; - -#[repr(C)] -pub struct SecurityFunctionTableW { - pub dwVersion: u32, - pub EnumerateSecurityPackagesW: EnumerateSecurityPackagesFnW, - pub QueryCredentialsAttributesW: QueryCredentialsAttributesFnW, - pub AcquireCredentialsHandleW: AcquireCredentialsHandleFnW, - pub FreeCredentialsHandle: FreeCredentialsHandleFn, - pub Reserved2: *const c_void, - pub InitializeSecurityContextW: InitializeSecurityContextFnW, - pub AcceptSecurityContext: AcceptSecurityContextFn, - pub CompleteAuthToken: CompleteAuthTokenFn, - pub DeleteSecurityContext: DeleteSecurityContextFn, - pub ApplyControlToken: ApplyControlTokenFn, - pub QueryContextAttributesW: QueryContextAttributesFnW, - pub ImpersonateSecurityContext: ImpersonateSecurityContextFn, - pub RevertSecurityContext: RevertSecurityContextFn, - pub MakeSignature: MakeSignatureFn, - pub VerifySignature: VerifySignatureFn, - pub FreeContextBuffer: FreeContextBufferFn, - pub QuerySecurityPackageInfoW: QuerySecurityPackageInfoFnW, - // In the Windows sspicli.dll, the `Reserved3` field is used as EncryptFunction - pub Reserved3: EncryptMessageFn, - // In the Windows sspicli.dll, the `Reserved4` field is used as DecryptFunction - pub Reserved4: DecryptMessageFn, - pub ExportSecurityContext: ExportSecurityContextFn, - pub ImportSecurityContextW: ImportSecurityContextFnW, - pub AddCredentialsW: AddCredentialsFnW, - pub Reserved8: *const c_void, - pub QuerySecurityContextToken: QuerySecurityContextTokenFn, - pub EncryptMessage: EncryptMessageFn, - pub DecryptMessage: DecryptMessageFn, - pub SetContextAttributesW: SetContextAttributesFnW, - pub SetCredentialsAttributesW: SetCredentialsAttributesFnW, - pub ChangeAccountPasswordW: ChangeAccountPasswordFnW, - pub Reserved9: *const c_void, - pub QueryContextAttributesExW: QueryContextAttributesExFnW, - pub QueryCredentialsAttributesExW: QueryCredentialsAttributesExFnW, -} - -pub type PSecurityFunctionTableW = *mut SecurityFunctionTableW; - #[instrument(skip_all)] #[cfg_attr(windows, rename_symbol(to = "Rust_InitSecurityInterfaceA"))] #[unsafe(no_mangle)] diff --git a/ffi/src/sspi/sspi_data_types.rs b/ffi/src/sspi/sspi_data_types.rs deleted file mode 100644 index f7ceb93e..00000000 --- a/ffi/src/sspi/sspi_data_types.rs +++ /dev/null @@ -1,160 +0,0 @@ -use libc::{c_char, c_void}; -use sspi::CertTrustStatus as SspiCertTrustStatus; - -pub type SecChar = c_char; - -pub type LpStr = *const SecChar; - -pub type SecWChar = u16; - -pub type LpcWStr = *const SecWChar; - -pub type SecurityStatus = u32; - -#[repr(C)] -pub struct SecurityInteger { - pub low_part: u32, - pub high_part: i32, -} - -pub type PTimeStamp = *mut SecurityInteger; - -#[repr(C)] -pub struct SecurityString { - pub length: u16, - pub maximum_length: u16, - pub buffer: *mut u16, -} - -pub type PSecurityString = *mut SecurityString; - -#[repr(C)] -pub struct SecPkgContextSizes { - pub cb_max_token: u32, - pub cb_max_signature: u32, - pub cb_block_size: u32, - pub cb_security_trailer: u32, -} - -/// [SecPkgContext_StreamSizes](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_streamsizes) -/// -/// ```c -/// typedef struct _SecPkgContext_StreamSizes { -/// unsigned long cbHeader; -/// unsigned long cbTrailer; -/// unsigned long cbMaximumMessage; -/// unsigned long cBuffers; -/// unsigned long cbBlockSize; -/// } SecPkgContext_StreamSizes, *PSecPkgContext_StreamSizes; -/// ``` -#[repr(C)] -pub struct SecPkgContextStreamSizes { - pub cb_header: u32, - pub cb_trailer: u32, - pub cb_maximum_message: u32, - pub c_buffers: u32, - pub cb_block_size: u32, -} - -pub type SecGetKeyFn = extern "system" fn(*mut c_void, *mut c_void, u32, *mut *mut c_void, *mut i32); - -/// [SecPkgContext_Flags](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_flags) -/// -/// ```c -/// typedef struct _SecPkgContext_Flags { -/// unsigned long Flags; -/// } SecPkgContext_Flags, *PSecPkgContext_Flags; -/// ``` -#[repr(C)] -pub struct SecPkgContextFlags { - pub flags: u32, -} - -/// [ALG_ID](https://learn.microsoft.com/en-us/windows/win32/seccrypto/alg-id) -/// typedef unsigned int ALG_ID; -pub type AlgId = u32; - -/// [SecPkgContext_ConnectionInfo](https://learn.microsoft.com/en-us/windows/win32/api/schannel/ns-schannel-secpkgcontext_connectioninfo) -/// -/// ```c -/// typedef struct _SecPkgContext_ConnectionInfo { -/// DWORD dwProtocol; -/// ALG_ID aiCipher; -/// DWORD dwCipherStrength; -/// ALG_ID aiHash; -/// DWORD dwHashStrength; -/// ALG_ID aiExch; -/// DWORD dwExchStrength; -/// } SecPkgContext_ConnectionInfo, *PSecPkgContext_ConnectionInfo; -/// ``` -#[repr(C)] -pub struct SecPkgContextConnectionInfo { - pub dw_protocol: u32, - pub ai_cipher: AlgId, - pub dw_cipher_strength: u32, - pub ai_hash: AlgId, - pub dw_hash_strength: u32, - pub ai_exch: AlgId, - pub dw_exch_strength: u32, -} - -/// [SecPkgContext_SessionKey](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_sessionkey) -/// -/// ```c -/// typedef struct _SecPkgContext_SessionKey { -/// unsigned long SessionKeyLength; -/// unsigned char *SessionKey; -/// } SecPkgContext_SessionKey, *PSecPkgContext_SessionKey; -/// ``` -#[repr(C)] -pub struct SecPkgContextSessionKey { - pub session_key_len: u32, - pub session_key: *mut u8, -} - -/// [CERT_TRUST_STATUS](https://learn.microsoft.com/en-us/windows/win32/api/wincrypt/ns-wincrypt-cert_trust_status) -/// -/// ```c -/// typedef struct _CERT_TRUST_STATUS { -/// DWORD dwErrorStatus; -/// DWORD dwInfoStatus; -/// } CERT_TRUST_STATUS, *PCERT_TRUST_STATUS; -/// ``` -#[repr(C)] -pub struct CertTrustStatus { - pub dw_error_status: u32, - pub dw_info_status: u32, -} - -impl From for CertTrustStatus { - fn from(cert_trust_status: SspiCertTrustStatus) -> Self { - Self { - dw_error_status: cert_trust_status.error_status.bits(), - dw_info_status: cert_trust_status.info_status.bits(), - } - } -} - -/// [SecPkgContext_NamesA](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_namesa) -/// -/// ```c -/// typedef struct _SecPkgContext_NamesA { -/// SEC_CHAR *sUserName; -/// } SecPkgContext_NamesA, *PSecPkgContext_NamesA; -/// ``` -#[repr(C)] -pub struct SecPkgContextNamesA { - pub user_name: *mut SecChar, -} - -/// [SecPkgContext_NamesW](https://learn.microsoft.com/en-us/windows/win32/api/sspi/ns-sspi-secpkgcontext_namesw) -/// -/// ```c -/// typedef struct _SecPkgContext_NamesW { -/// SEC_WCHAR *sUserName; -/// } SecPkgContext_NamesW, *PSecPkgContext_NamesW; -/// ``` -#[repr(C)] -pub struct SecPkgContextNamesW { - pub user_name: *mut SecWChar, -} diff --git a/ffi/src/sspi/win_scard_cert.rs b/ffi/src/sspi/win_scard_cert.rs index 0ad1d854..7680270e 100644 --- a/ffi/src/sspi/win_scard_cert.rs +++ b/ffi/src/sspi/win_scard_cert.rs @@ -22,10 +22,7 @@ use windows::core::PWSTR; const CSP_NAME: &str = "Microsoft Base Smart Card Crypto Provider"; -// https://learn.microsoft.com/en-us/windows/win32/seccrypto/hcryptprov -pub type HCRYPTPROV = usize; // ULONG_PTR -// https://learn.microsoft.com/en-us/windows/win32/seccrypto/hcryptkey -pub type HCRYPTKEY = usize; // ULONG_PTR +pub use ffi_types::sspi::{HCRYPTKEY, HCRYPTPROV}; /// Finds a certificate in the given certificate store by thumbprint. ///