%PDF- %PDF-
Mini Shell

Mini Shell

Direktori : /lib/python3/dist-packages/samba/__pycache__/
Upload File :
Create Path :
Current File : //lib/python3/dist-packages/samba/__pycache__/upgradehelpers.cpython-312.pyc

�

�I�d�����dZddlZddlZddlZddlZddlmZddlmZmZm	Z	ddl
mZmZm
Z
ddl
Z
ddlmZmZmZmZmZmZddlmZddlmZdd	lmZdd
lmZddlmZddlmZddl Z d
Z!dZ"dZ#dZ$dZ%dZ&dZ'e(gd��Z)Gd�de*�Z+d�Z,d�Z-d+d�Z.d�Z/d+d�Z0d�Z1d�Z2d�Z3d�Z4d�Z5d �Z6d!�Z7d"�Z8d#�Z9d$�Z:d%�Z;d&�Z<d'�Z=d(�Z>d)�Z?d*�Z@y),z>Helpers used for upgrading between different database formats.�N)�cmp)�Ldb�version�ntacls)�
SCOPE_SUBTREE�SCOPE_ONELEVEL�
SCOPE_BASE)�provision_paths_from_lp�
getpolicypath�create_gpo_struct�	provision�ProvisioningError�secretsdb_self_join)�	FILL_FULL)�drsblobs)�SEC_CHAN_BDC)�
ndr_unpack)�SamDB)�_glue��������)�dn�whenCreated�whenChanged�
objectGUID�
uSNCreated�replPropertyMetaData�
uSNChanged�
parentGUID�objectCategory�distinguishedName�
nTMixedDomain�showInAdvancedViewOnly�instanceTypezmsDS-Behavior-Version�nextRid�cn�
versionNumber�lmPwdHistory�
pwdLastSet�ntPwdHistory�
unicodePwd�dBCSPwd�supplementalCredentials�gPCUserExtensionNames�gPCMachineExtensionNames�	maxPwdAge�secret�possibleInferiors�	privilege�sAMAccountTypec�*�eZdZd�Zd�Zd�Zd�Zd�Zy)�ProvisionLDBc�t�d|_d|_d|_d|_d|_d|_d|_d|_y�N)�sam�secrets�idmapr7�hkcr�hkcu�hku�hklm��selfs �6/usr/lib/python3/dist-packages/samba/upgradehelpers.py�__init__zProvisionLDB.__init__Fs:����������
������	���	������	�c�^�|j|j|j|jfSr<)r=r>r?r7rDs rF�dbszProvisionLDB.dbsPs!�����$�,�,��
�
�D�N�N�C�CrHc�N�|j�D]}|j��yr<)rJ�transaction_start�rE�dbs  rF�startTransactionszProvisionLDB.startTransactionsSs#���(�(�*�	#�B�� � �"�	#rHc�x�d}|j�D]}	|j��|S#t$rd}Y�%wxYw)NTF)rJ�transaction_cancel�	Exception)rE�okrNs   rF�groupedRollbackzProvisionLDB.groupedRollback\sJ��
���(�(�*�	�B�
��%�%�'�	�
�	���
���
�s�+�9�9c��	|j�D]}|j��		|j�D]}|j	��	y#t$r|j�cYSwxYw#t$r|j�cYSwxYw)NT)rJ�transaction_prepare_commitrRrT�transaction_commitrMs  rF�
groupedCommitzProvisionLDB.groupedCommitjs���	*��h�h�j�
0���-�-�/�
0�	*��h�h�j�
(���%�%�'�
(���%�	*��'�'�)�)�	*���	*��'�'�)�)�	*�s"�%A�%A/�A,�+A,�/B�
BN)�__name__�
__module__�__qualname__rGrJrOrTrX�rHrFr:r:Ds���D�#��rHr:c��t�}t|j|||dgd��|_t	|j
|||��|_t	|j|||��|_t	|j|||��|_|S)a�Return LDB object mapped on most important databases

    :param paths: An object holding the different importants paths for provision object
    :param creds: Credential used for opening LDB files
    :param session: Session to use for opening LDB files
    :param lp: A loadparam object
    :return: A ProvisionLDB object that contains LDB object for the different LDB files of the provisionzmodules:samba_dsdbr)�session_info�credentials�lp�options�flags)r^r_r`)	r:r�samdbr=rr>�idmapdbr?r7)�paths�creds�sessionr`�ldbss     rF�get_ldbsri�s}���>�D��U�[�[�")�!&��2�3���D�H��u�}�}�7��RT�U�D�L��U�]�]��e�PR�S�D�J�����w�E�VX�Y�D�N��KrHc��d}d}d}|rK|t|�k(rd}�|t||�kr|dzdk(rd}d}|t||�k(rd}d}|dz}|r�K|S)a�Check if the usn is in one of the range provided.
    To do so, the value is checked to be between the lower bound and
    higher bound of a range

    :param usn: A integer value corresponding to the usn that we want to update
    :param range: A list of integer representing ranges, lower bounds are in
                  the even indices, higher in odd indices
    :return: True if the usn is in one of the range, False otherwise
    rTFrr)�len�int)�usn�range�idx�contrSs     rF�usn_in_rangerq�s~���C��D�	�B�
��#�e�*���D����U�3�Z�� ��Q�w�!�|����D��#�e�C�j�/�!��D��B��A�g����IrHc�P�|��tjj|�stj|�tjj	|d�}tjj|�stj
|�tjj	|d�}|�|j
�}tjj|�std|z��|j�}|j|�t||jd��}|S)aGet paths to important provision objects (smb.conf, ldb files, ...)

    :param param: Param object
    :param targetdir: Directory where the provision is (or will be) stored
    :param smbconf: Path to the smb.conf file
    :return: A list with the path of important provision objects�etczsmb.confzUnable to find smb.conf at %s�realm)�os�path�exists�mkdir�join�makedirs�default_pathr�LoadParm�loadr
�get)�param�	targetdir�smbconf�etcdirr`res      rF�	get_pathsr��s������w�w�~�~�i�(��H�H�Y�������i��/���w�w�~�~�f�%��K�K����'�'�,�,�v�z�2�����$�$�&��
�7�7�>�>�'�"�� ?�'� I�J�J�	���	�B��G�G�G��#�B����w��8�E��LrHc���|jddt|j�ztddg��}t|dd�j	dd�j	d	d�|_|jd
dt|j�ztddg��}t
|�dk(r7t|dd�j	dd�j	d	d�|_yd|_y)
z�Update policy ids that could have changed after sam update

    :param names: List of key provision parameters
    :param samdb: An Ldb object conntected with the sam DB
    z#(displayName=Default Domain Policy)zCN=Policies,CN=System,r*�displayName��
expression�base�scope�attrsr�{��}z/(displayName=Default Domain Controllers Policy)rN)�search�str�rootdnr�replace�policyidrk�policyid_dc)�namesrc�res�res2s    rF�update_policyidsr��s����,�,�"G�4�s�5�<�<�7H�H�+�D�-�3H��J�C���Q����&�.�.�s�B�7�?�?��R�H�E�N��<�<�$.�5��E�L�L�8I�I�,�T�=�4I��K�D��4�y�A�~���Q���
�.�6�6�s�B�?�G�G��R�P��� ��rHc��tjj|�rtj|�tj
|�|j
d|�t||fid|�d|�dt�d|j�d|j�d|j�d|j�d	|j�d
|j�d|j�d|j j#��d
d�dd�d|j$�d|j&�dd�dd�dd�dd�dd�dd�dd�d|j(�d|j*�dd�dd�d|�d |��S)!a�Create a new provision.

    This provision will be the reference for knowing what has changed in the
    since the latest upgrade in the current provision

    :param names: List of provision parameters
    :param creds: Credentials for the authentication
    :param session: Session object
    :param smbconf: Path to the smb.conf file
    :param provdir: Directory where the provision will be stored
    :param logger: A Logger
    zProvision stored in %sr�r��
samdb_fillrt�domain�
domainguid�	domainsid�ntdsguid�
policyguid�
policyguid_dc�hostname�hostipN�hostip6�invocationid�	adminpass�
krbtgtpass�machinepass�dnspass�root�nobody�users�
serverrolezdomain controller�dom_for_fun_level�dns_backend�useeadbT�	use_ntvfs�base_schema�adprep_level)rurv�isdir�shutil�rmtreerx�infor
rrtr�r�r�r�r�r��netbiosname�lower�
invocationr��domainlevelr�)r�rgr��provdir�loggerr�r�s       rF�newprovisionr��s���
�w�w�}�}�W���
�
�g���H�H�W��
�K�K�(�'�2��V�W�0�g�0�&�0�3<�0�DI�K�K�0�!�L�L�0�5:�5E�5E�0� %���0�:?���0�!&���	0�?D�>O�>O�	0�
$�/�/�5�5�7�0�
AE�0�
OS�0�#(�"2�"2�
0�?D�o�o�
0�!%�0�37�0�AE�0�LP�0�!�0�)-�0�!4�0�(-�'8�'8�0�GL�FW�FW�0�"�0�.2�0�@K�0�#/�0�0rHc��tjd�}|jt|��}|jt|��}t	t|�t|��}t|�dz
}t|�dz
}t
d|�D]g}t|||z
|||z
�}	|	dk7r|	cS||dz
k(s�-||k7s.Jddj|�zdzdj|�z��||kDryy	S)z�Sorts two DNs in the lexicographical order it and put higher level DN
    before.

    So given the dns cn=bar,cn=foo and cn=foo the later will be return as
    smaller

    :param x: First object to compare
    :param y: Second object to compare
    z
(?<!\\), ?rrzPB PB PB� z / r)	�re�compile�splitr��minrkrnrry)
�x�y�p�tab1�tab2�minimum�len1�len2�i�rets
          rF�dn_sortr�s���	�
�
�=�!�A��7�7�3�q�6�?�D��7�7�3�q�6�?�D��#�d�)�S��Y�'�G��t�9�q�=�D��t�9�q�=�D�
�1�g�
�
���$�t�a�x�.�$�t�a�x�.�1���!�8��J��G�a�K���t�|�Y�Z�#�(�(�4�.�%@�5�%H�3�8�8�TX�>�%Y�Y�|��$�;���
��JrHc	���t|�jdd�\}}|j|tj||�d|���dg�|jtj||�d|���|dg�y)z�Perform a back and forth rename to trigger renaming on attribute that
    can't be directly modified.

    :param lbdobj: An Ldb Object
    :param dn: DN of the object to manipulate
    �=rz=foozrelax:0N)r�r��rename�ldb�Dn)�ldbobjr�before�afters    rF�identic_renamer�+s`���"�g�m�m�C��+�O�V�U�
�M�M�"�c�f�f�V�6�5�%A�B�Y�K�P�
�M�M�#�&�&��v�u�!=�>��Y�K�PrHc
�	�|td�|jdt��}|jdt��}|sJd��t|�dk(rP|j	tj�|d�}|dj|_|j|d�n=|j	|d|d�}|dj|_|j|�|jddtdg�	�}|jddtdg�	�}i}i}g}g}	tj�}
tdt|��D]*}||d|t||d�j�<�,tdt|��D]*}||d|t||d�j�<�,|j�D]/}||vr|j||��|	j||��1|D]�}
|jd
|
zdt��}|j	|
|d�}t D]}|j#|��|t$d|djz�|D]}|t$d
|z��|dj|_|j|���|	D]�}
|jd
|
zdt��}|jd
|
zdt��}|j	|d|d�}t D]}|j#|��|D]O}|dk(r7|t$d|djz�t'||dj��?|j#|��Q��|	D]�}
|jd
|
zdt��}|jd
|
zdt��}|j	|d|d�}t D]}|j#|��|D]>}|dk(r|j#|�|dk7s�|t$d|�d|dj����@|dj|_|j|���|jdtdg��}t|�dk(r%|td�|j)|dd�yy)z�Update secrets.ldb

    :param newsecrets_ldb: An LDB object that is connected to the secrets.ldb
        of the reference provision
    :param secrets_ldb: An LDB object that is connected to the secrets.ldb
        of the updated provision
    zUpdate of secrets.ldbz@MODULES)r�r�z'Reference modules list can not be emptyrzobjectClass=topr�rr��distinguishedName=%s)r�r�r�z$Entry %s is missing from secrets.ldbz Adding attribute %s�namez/Found attribute name on  %s, must rename the DN�msDS-KeyVersionNumberzAdding/Changing attribute z to z(samaccountname=dns))r�r�r�rzRemove old dns accountN)�SIMPLEr�r	rk�msg_diffr��Messager�add�modifyrrnr�r��keys�append�hashAttrNotCopied�remove�CHANGEr��delete)�newsecrets_ldb�secrets_ldb�messagefunc�	reference�current�delta�hash_new�hash�listMissing�listPresent�emptyr��k�entry�attr�s                rF�update_secretsr�8s�����/�0��%�%�:�Z�%�H�I�� � �j�
� �C�G��?�?�?�9�
�7�|�q���$�$�S�[�[�]�I�a�L�A���Q�<�?�?������	�!��%��$�$�W�Q�Z��1��>���1�:�=�=������5�!��%�%�1B��,9�$��&�I�I�� � �,=�B�'4�T�F�!�D�G��H�
�D��K��K��K�K�M�E�
�1�c�)�n�
%�G��4=�a�L��4F���Y�q�\�$�'�(�.�.�0�1�G�
�1�c�'�l�
#�?��.5�a�j��.>��S����D�!�
"�
(�
(�
*�+�?��]�]�_�,���D�=����x��{�+����x��{�+�	,����"�)�)�5K�e�5S�/1��*�H�	��$�$�U�I�a�L�9��$�	�C��L�L���	��F�B��a�L�O�O�$�	%��	>�C��� 6�� <�=�	>��Q�<�?�?����������"��"�)�)�5K�e�5S�/1��*�H�	��$�$�0F��0N�UW�+8�%�:���$�$�W�Q�Z��1��>��$�	�C��L�L���	��	"�C��f�}��F�%:�=D�Q�Z�]�]�%L�M��{�I�a�L�O�O�<����S�!�
	"�"� �"��"�)�)�5K�e�5S�Z\�0=�*�?�	��$�$�0F��0N�UW�+8�%�:���$�$�W�Q�Z��1��>��$�	�C��L�L���	��	2�C��-�-����S�!��d�{��F� �'�!�*�-�-�1�2�		2��1�:�=�=������5�!�#"�&���)?�$1�$���A�D��4�y�A�~��� 8�9����t�A�w�t�}�-�rHc��|jdt|�tddg��}t|�dkDr|dj	d�r
|dd}|Sy)z�Return OEM Information on the top level Samba4 use to store version
    info in this field

    :param samdb: An LDB object connect to sam.ldb
    :param rootdn: Root DN of the domain
    :return: The content of the field oEMInformation (if any)
    �(objectClass=*)r�oEMInformationr�rr�)r�r�r	rkr~)rcr�r�r�s    rF�
getOEMInfor��s^���,�,�"3�#�f�+�'��6F�/G��I�C�
�3�x�!�|��A��
�
�#3�4��1�v�&�'����rHc��|jd|tddg��}t|�dkDr�|djd�rt	|dd�}nd}|�dt
��}t
j�}t
j|t	|dd��|_	t
j|tjd�|d<|j|�yy)	z�Update the OEMinfo field to add information about upgrade

    :param samdb: an LDB object connected to the sam DB
    :param rootdn: The string representation of the root DN of
        the provision (ie. DC=...,DC=...)
    r�rr�r�rr�z
, upgrade to N)
r�r	rkr~r�rr�r�r�r�MessageElement�FLAG_MOD_REPLACEr�)rcr�r�r�r�s     rF�
updateOEMInfor��s����,�,�"3�&�'��6F�/G��I�C�
�3�x�!�|��q�6�:�:�&�'��s�1�v�.�/�0�D��D�&*�G�4�����
���6�6�%��S��V�D�\�!2�3���"%�"4�"4�T�3�;O�;O�5E�#G����
���U��rHc��t|j|j|j�}tj
j
|�st|�|j�td��t|j|j|j�}tj
j
|�st|�yy)z-Create missing GPO file object if needed
    Nz*Policy ID for Domain controller is missing)
r�sysvol�	dnsdomainr�rurvr�rr�r)rercr�r`�message�dirs      rF�
update_gpor�s�������e�o�o�u�~�~�
F�C�
�7�7�=�=����#����� �� L�M�M�
����e�o�o�u�7H�7H�
I�C�
�7�7�=�=����#��rHc	�(�|jdtj|t|��tdgdg��}d}t|�dk(rt
d��|D]�}t|j�j�|vs�)|jd�}|sd}tt|t|j�j���}tt|��|ks��|dz}|jt|j�d	|d
���y)aFor a given hash associating dn and a number, this function will
    update the replPropertyMetaData of each dn in the hash, so that the
    calculated value of the msDs-KeyVersionNumber is equal or superior to the
    one associated to the given dn.

    :param samdb: An SamDB object pointing to the sam
    :param rootdn: The base DN where we want to start
    :param hashDns: A hash with dn as key and number representing the
                 minimum value of msDs-KeyVersionNumber that we want to
                 have
    z(objectClass=user)zmsDs-KeyVersionNumber�search_options:1:2�r�r�r�r��controlsrz$Unable to find msDs-KeyVersionNumber�0rr/TN)r�r�r�r�rrkrrr�r~rl�"set_attribute_replmetadata_version)rcr��hashDnsr��done�e�valrs        rF�&increment_calculated_keyversion_numberr
�s���
�L�L�$8�!�f�f�U�C��K�8�,�5L�4M�#7�"8�
�
:�E�
�D�
�5�z�Q��� F�G�G��
	L�A��1�4�4�y��� �G�+��e�e�3�4����C��c�'�#�a�d�d�)�/�/�*;�"<�=�>���s�3�x�=�7�*��!�8�D��<�<�S����Y�=I�=D�d�L�
	LrHc�r�|td�t||||dg��}t||||dg��}tj�}d}	|j	d��}
|
D�]�}|j	d|dzt
�	�}t
|�s�|j||�}
|td
t|j�z�t|j�dk(rR|
jtjj�r)|
jtjj�|j|
_
|j!|
���|j|d|�}
t|j�d
k(r|j||d�}	t|j�dk(rR|
jtjj�r)|
jtjj�t
|
j#��dkDs���|j|
_
|j%|
����|	S)aUpdate the provision container db: sam.ldb
    This function is aimed for alpha9 and newer;

    :param refsampath: Path to the samdb in the reference provision
    :param sampath: Path to the samdb in the upgraded provision
    :param creds: Credential used for opening LDB files
    :param session: Session to use for opening LDB files
    :param lp: A loadparam object
    :return: A msg_diff object with the difference between the @ATTRIBUTES
             of the current provision and the reference provision
    z<Update base samdb by searching difference with reference onezmodules:)r^r_r`raNr��r�r�r)r�r�zAdding %s to sam dbz
@PROVISIONrz@ATTRIBUTESr)r�rr�r�r�rrkr�r�r�rr~�sambar
�LAST_PROVISION_USN_ATTRIBUTEr�r��itemsr�)�
refsampath�sampathrfrgr`r�refsamr=r��	deltaattrr��refentryr�r�s              rF�delta_update_basesamdbr�s����F�J�L�
��'�u����.�F�

�g�G��2�!�l�$�C�
�K�K�M�E��I��
�
��
�,�I��"���
�
�&<�x��~�&M�!.��0���5�z��L�L���1�E��F�1�C����4D�D�E��8�;�;��<�/��I�I�e�o�o�J�J�K����U�_�_�I�I�J��{�{�E�H��G�G�E�N��L�L��q��8�4�E��8�;�;��=�0��L�L��5��8�<�	��8�;�;��<�/��I�I�e�o�o�J�J�K����U�_�_�I�I�J��5�;�;�=�!�A�%�#�;�;����
�
�5�!�)"�,�rHc�R�d}t|�dkDrd}|D]
}|�d|�d�}�d|z}|S)z�Construct a exists or LDAP search expression.

    :param attrs: List of attribute on which we want to create the search
        expression.
    :return: A string representing the expression, if attrs is empty an
        empty string is returned
    r�rz(|�(z=*)z%s))rk)r��exprr�s   rF�construct_existor_exprr&s@���D�
�5�z�A�~����	+�C� $�c�*�D�	+��d�{���KrHc�,�d|jz}|j|dg��}t|ddd�tk(�rK|j|g��}t	|�dk(sJ�tj|dj�}tjdd�}|jd�}tj|t
jd�|d<|j|�|jd|jzd	g��}t	|�dk(sJ�tt|dd	��}	t|ddd�}
t||j |j"|j$|j&|j||	|
�
�	yt)d��)
aRUpdate (change) the password of the current DC both in the SAM db and in
       secret one

    :param samdb: An LDB object related to the sam.ldb file of a given provision
    :param secrets_ldb: An LDB object related to the secrets.ldb file of a given
                        provision
    :param names: List of key provision parameterszsamAccountName=%s$�secureChannelType�r�r�rr�x�	utf-16-le�clearTextPassword�msDs-keyVersionNumber)r�rtr�r�r�r��key_version_number�secure_channel_typez3Unable to find a Secure Channelof type SEC_CHAN_BDCN)r�r�rlrrkr�r�rr� generate_random_machine_password�encoder�r�r�r�rr�rtr�r�r)rcr�r�r��secrets_msgr��msgr��mputf16�kvno�secChanTypes           rF�update_machine_account_passwordr-7s���&��(9�(9�9�J��$�$�
�,?�+@�%�B�K�
�;�q�>�-�.�q�1�2�l�B��l�l�j��l�;���3�x�1�}��}��k�k�#�a�&�)�)�$���<�<�S�#�F���$�$�[�1��#&�#5�#5�g�69�6J�6J�6I�$K��� �	���S���l�l�';�e�>O�>O�'O�"9�!:��<���3�x�1�}��}��3�s�1�v�5�6�7�8���+�a�.�)<�=�a�@�A���K����"'�+�+�&+�o�o�&+�o�o�(-�(9�(9�(3�/3�0;�	=� �!7�8�	8rHc� �d|jz}|j|��}t|�dk(�r^|j|g��}t|�dk(sJ�tj|dj
�}t
jdd�}|jd�}tj|tjd	�|d	<|j|�|j|d
g��}t|�dk(sJ�t|dd
�}	tj|dj
�}tj|tjd�|d<tj|	tjd�|d<|j|�y
y
)aKUpdate (change) the password of the dns both in the SAM db and in
       secret one

    :param samdb: An LDB object related to the sam.ldb file of a given provision
    :param secrets_ldb: An LDB object related to the secrets.ldb file of a given
                        provision
    :param names: List of key provision parameterszsamAccountName=dns-%srrrr�rr!r"r#r5r�N)
r�r�rkr�r�rr�generate_random_passwordr'r�r�r�r�)
rcr�r�r�r(r�r)r�r*r+s
          rF�update_dns_account_passwordr1bsv��)�5�+<�+<�<�J��$�$�
�$�;�K�
�;��1���l�l�j��l�;���3�x�1�}��}��k�k�#�a�&�)�)�$���4�4�S�#�>���$�$�[�1��#&�#5�#5�g�69�6J�6J�6I�$K��� �	���S���l�l�j�"9�!:��<���3�x�1�}��}��3�q�6�1�2�3���k�k�+�a�.�+�+�,���*�*�;�+.�+?�+?�+3�5��H�
�(+�'9�'9�$�:=�:N�:N�:Q�(S��#�$�	���3��5rHc�R�d}|j|g��}t|�dk(sJ�tj|dj�}tjdd�}|jd�}tj|tjd�|d<|j|�y	)
z�Update (change) the password of the krbtgt account

    :param samdb: An LDB object related to the sam.ldb file of a given provisionzsamAccountName=krbtgtrrrr/rr!r"N)r�rkr�r�rrr&r'r�r�r�)rcr�r�r)r��kputf16s      rF�update_krbtgt_account_passwordr4�s���
)�J�
�,�,�*�B�,�
7�C��s�8�q�=��=�

�+�+�c�!�f�i�i�
 �C��7�7��S�A�J�����,�G�"�1�1�'�25�2F�2F�2E� G�C���
�L�L��rHc	���i}t|�}|dk(r|S|j|tj|t	|��t
|ddg��}t
|�dk(r|S|D]�}|D]�}|j|�s�||vr6t	||�||t	|j�j�<�Oi||<t	||�||t	|j�j�<����|S)a�Search a given sam DB for calculated attributes that are
    still stored in the db.

    :param samdb: An LDB object pointing to the sam
    :param rootdn: The base DN where the search should start
    :param attrs: A list of attributes to be searched
    :return: A hash with attributes as key and an array of
             array. Each array contains the dn and the associated
             values for this attribute as they are stored in the
             sam.r�rzbypassoperational:0rr)
rr�r�r�r�rrkr~rr�)rcr�r��hashAttrr��entr�s        rF�search_constructed_attrs_storedr8�s����G�!�%�(�D��r�z����L�L�D�s�v�v�e�S��[�/I�,�E�#7�9N�"O�
�
Q�E��5�z�Q�����F���	F�C��w�w�s�|��'�>�8;�C��H�
�G�C�L��S�V�V��!2�!2�!4�5�#%�G�C�L�8;�C��H�
�G�C�L��S�V�V��!2�!2�!4�5�
	F�F��NrHc��d}i}|j|dtjdgdg��}|D�]�}|dz}ttj
t
|d��j}|jD�]�}tj|j�dz}|jt
|j��}	|	�Ai}
|j|
d<|j|
d	<d|
d
<t
|j�g|
d<i}	n�|	j|�}
|
�?i}
|j|
d<|j|
d	<d|
d
<t
|j�g|
d<n�|
d|jkDr|j|
d<|
d	|jkr|j|
d	<t
|j�|
dvr2|
d
dz|
d
<|
dj!t
|j��|
|	|<|	|t
|j�<������||fS)a Find ranges of usn grouped by invocation id and then by timestamp
        rouned at 1 minute

        :param samdb: An LDB object pointing to the samdb
        :param basedn: The DN of the forest

        :return: A two level dictionary with invoication id as the
                first level, timestamp as the second one and then
                max, min, and number as subkeys, representing respectivily
                the maximum usn for the range, the minimum usn and the number
                of object with usn in this range.
    rz
objectClass=*r!r)r�r�r�r�rr�<r��max�num�list)r�r�rrr�replPropertyMetaDataBlobr��ctr�arrayr�nttime2unix�originating_change_timer~�originating_invocation_id�originating_usnrr�)rc�basedn�nb_obj�hash_idr�r�obj�o�minutestamp�hash_ts�obs           rF�findprovisionrangerM�s���F��G�
�,�,�F�� �.�.�4�5�!5� 6��8�C�
�"@���!�����:�:��Q�5�6�7�9�9<��	����	@�A��+�+�A�,E�,E�F�"�L�K��k�k�#�a�&A�&A�"B�C�G������-�-��5�	��-�-��5�	���5�	�!�!�$�$�i�[��6�
����[�[��-���:��B� !� 1� 1�B�u�I� !� 1� 1�B�u�I� !�B�u�I�"%�a�d�d�)��B�v�J��%�y�1�#4�#4�4�$%�$5�$5��5�	��%�y�1�#4�#4�4�$%�$5�$5��5�	�����I��F��3�$&�u�I��M��5�	��6�
�)�)�#�a�d�d�)�4�#%�G�K� �8?�G�C��3�3�4�5�;	@�"@�H
�V��rHc
��d}|D�]R}||}g}|j|j��|j�g}	|D]r}
||
}|d|kDrFtjtj
|
dz��}t
d||d|d|dfz�||
ddkDs�b|	j|
��ttdt|	��D][}
|
dk7s�	|	|
}|	|
d	z
}||z
d	k(s�t||d�t||d�d	zk(s�F||d||d<d
||d<�]|	D](}
||
}|jd���d
||d|d|fz}�*��U|dk7r�tj|dd��\}}t
�t
d�t
d|z�t
d|z�t
dt|��d|�d��d|�d|��}tj ||�tj"|�yy)ar print the different ranges passed as parameter

        :param dic: A dictionary as returned by findprovisionrange
        :param limit_print: minimum number of object in a range in order to print it
        :param dest: Destination directory
        :param samdb_path: Path to the sam.ldb file
        :param invoicationid: Invocation ID for the current provision
    r�r<r:z*%s # of modification: %d  	min: %d max: %dr�r;iXrrT�skippedNz%slastProvisionUSN: %d-%d;%s
�usnprovz.ldif)r�prefix�suffixzFTo track the USNs modified/created by provision and upgrade proivsion,zM the following ranges are proposed to be added to your provision sam.ldb: 
%szdWe recommend to review them, and if it's correct to integrate the following ldif: %s in your sam.ldbz,You can load this file like this: ldbadd -H r��
zdn: @PROVISION
provisionnerID: )�extendr��sortr�
nttime2string�unix2nttime�printr�rnrkrlr~�tempfile�mkstempr�ru�write�close)�dic�limit_print�dest�
samdb_pathr��ldif�idrK�sorted_keys�kept_recordr�rH�dtr��key1�key2�fd�files                  rF�print_provision_rangesrj�sM���D��"O���b�'�������7�<�<�>�*��������	&�A��!�*�C��5�z�K�'��(�(��):�):�1�r�6�)B�C���C�r�3�u�:�GJ�5�z�GJ�5�z�GS�S�T��q�z�%� �3�&��"�"�1�%�	&��q�#�k�*�+�
	8�A��A�v�"�1�~��"�1�q�5�)���$�;�!�#��7�4�=��/�0�C���
�e�8L�4M�PQ�4Q�Q�07�t�}�U�/C���
�e�,�37���
�i�0�
	8��	O�A��a�j���7�7�9�%�-�;�t�S��Z�?B�5�z�2�?O�O�D�	O�="O�H�r�z��#�#��Y�w�O���D�
��
�V�W�
�^�ae�e�f�
�t�w{�{�|�
�c�*�o�W[�\�]�;G��N��
����T��
�����rHc�6�t|�}d|dz|dz	fz}|S)z�Display the int64 range stored in value as xxx-yyy

    :param value: The int64 range
    :return: A string of the representation of the range
    z%d-%dl��� )rl)�value�lvaluer�s   rF�int64range2strro:s*����Z�F�
�V�Z�'��"��5�
5�C��JrH)NN)A�__doc__rur�r�r�samba.commonrrrrr�rrr	�samba.provisionr
rrr
rr�samba.provision.commonr�samba.dcerpcr�samba.dcerpc.miscr�	samba.ndrr�samba.samdbrrrY�ERRORr�r��CHANGESD�GUESS�	PROVISION�	CHANGEALL�setr��objectr:rirqr�r�r�r�r�r�r�r�rr
rrr-r1r4r8rMrjror\rHrF�<module>rs��,E�	�	�
���&�&�9�9�
�2�2�-�!�*� ����	��	
��	
�������	��	��M�N��<�6�<�~�8�:�4!�,0�@�>
Q�d.�N�"�,�L�B.�b�"(8�V% �P�, �F9�x8�vrH

Zerion Mini Shell 1.0