Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-dcerpc-spoolss.c
Line
Count
Source
1
/* packet-dcerpc-spoolss.c
2
 * Routines for SMB \PIPE\spoolss packet disassembly
3
 * Copyright 2001-2003, Tim Potter <tpot@samba.org>
4
 *
5
 * Wireshark - Network traffic analyzer
6
 * By Gerald Combs <gerald@wireshark.org>
7
 * Copyright 1998 Gerald Combs
8
 *
9
 * SPDX-License-Identifier: GPL-2.0-or-later
10
 */
11
12
/* TODO list:
13
14
 - audit of item lengths
15
16
*/
17
18
#include "config.h"
19
20
21
#include <epan/packet.h>
22
#include <epan/expert.h>
23
#include <epan/tfs.h>
24
#include <epan/exceptions.h>
25
26
#include <wsutil/ws_roundup.h>
27
28
#include "packet-dcerpc.h"
29
#include "packet-dcerpc-nt.h"
30
#include "packet-dcerpc-spoolss.h"
31
#include "packet-windows-common.h"
32
33
void proto_register_dcerpc_spoolss(void);
34
void proto_reg_handoff_dcerpc_spoolss(void);
35
36
/* GetPrinterDriver2 */
37
38
static int hf_clientmajorversion;
39
static int hf_clientminorversion;
40
static int hf_servermajorversion;
41
static int hf_serverminorversion;
42
static int hf_driverpath;
43
static int hf_datafile;
44
static int hf_configfile;
45
static int hf_helpfile;
46
static int hf_monitorname;
47
static int hf_defaultdatatype;
48
static int hf_driverinfo_cversion;
49
static int hf_dependentfiles;
50
static int hf_previousdrivernames;
51
static int hf_color_profiles;
52
static int hf_core_driver_dependencies;
53
static int hf_driverdate;
54
static int hf_min_inbox_driverdate;
55
static int hf_padding;
56
static int hf_driver_version_low;
57
static int hf_driver_version_high;
58
static int hf_min_inbox_driver_version_low;
59
static int hf_min_inbox_driver_version_high;
60
static int hf_mfgname;
61
static int hf_oemurl;
62
static int hf_hardwareid;
63
static int hf_provider;
64
65
/* GetPrinter */
66
67
/* Times */
68
69
static int hf_start_time;
70
static int hf_end_time;
71
static int hf_elapsed_time;
72
static int hf_device_not_selected_timeout;
73
static int hf_transmission_retry_timeout;
74
75
/****************************************************************************/
76
77
/*
78
 * New hf index values - I'm in the process of doing a bit of a cleanup -tpot
79
 */
80
81
static int hf_opnum;
82
static int hf_hnd;
83
static int hf_rc;
84
static int hf_hresult;
85
static int hf_offered;
86
static int hf_needed;
87
static int hf_returned;
88
static int hf_buffer_size;
89
static int hf_buffer_data;
90
static int hf_string_parm_size;
91
static int hf_string_parm_data;
92
static int hf_offset;
93
static int hf_level;
94
static int hf_access_required;
95
96
static int hf_printername;
97
static int hf_machinename;
98
static int hf_notifyname;
99
static int hf_printerdesc;
100
static int hf_printercomment;
101
static int hf_servername;
102
static int hf_sharename;
103
static int hf_portname;
104
static int hf_printerlocation;
105
static int hf_drivername;
106
static int hf_environment;
107
static int hf_username;
108
static int hf_documentname;
109
static int hf_outputfile;
110
static int hf_datatype;
111
static int hf_textstatus;
112
static int hf_sepfile;
113
static int hf_printprocessor;
114
static int hf_vendor_setup;
115
static int hf_inf_path;
116
static int hf_parameters;
117
static int hf_core_printer_driver_ids;
118
static int hf_core_driver_guid;
119
static int hf_core_driver_size;
120
static int hf_driver_version;
121
static int hf_core_printer_driver_count;
122
static int hf_package_id;
123
static int hf_language;
124
static int hf_driver_package_cab_size;
125
126
/* Printer information */
127
128
static int hf_printer_cjobs;
129
static int hf_printer_total_jobs;
130
static int hf_printer_total_bytes;
131
static int hf_printer_global_counter;
132
static int hf_printer_total_pages;
133
static int hf_printer_major_version;
134
static int hf_printer_build_version;
135
static int hf_printer_unk7;
136
static int hf_printer_unk8;
137
static int hf_printer_unk9;
138
static int hf_printer_session_ctr;
139
static int hf_printer_unk11;
140
static int hf_printer_printer_errors;
141
static int hf_printer_unk13;
142
static int hf_printer_unk14;
143
static int hf_printer_unk15;
144
static int hf_printer_unk16;
145
static int hf_printer_changeid;
146
static int hf_printer_unk18;
147
static int hf_printer_unk20;
148
static int hf_printer_c_setprinter;
149
static int hf_printer_unk22;
150
static int hf_printer_unk23;
151
static int hf_printer_unk24;
152
static int hf_printer_unk25;
153
static int hf_printer_unk26;
154
static int hf_printer_unk27;
155
static int hf_printer_unk28;
156
static int hf_printer_unk29;
157
static int hf_printer_flags;
158
static int hf_printer_priority;
159
static int hf_printer_default_priority;
160
static int hf_printer_jobs;
161
static int hf_printer_averageppm;
162
static int hf_printer_guid;
163
static int hf_printer_action;
164
165
/* Printer data */
166
167
static int hf_printerdata;
168
static int hf_printerdata_key;
169
static int hf_printerdata_value;
170
static int hf_printerdata_type;
171
static int hf_printerdata_size; /* Length of printer data */
172
static int hf_printerdata_data;
173
static int hf_printerdata_data_sz;
174
static int hf_printerdata_data_dword;
175
176
/* Devicemode */
177
178
static int hf_devmodectr_size;
179
180
static int hf_devmode;
181
static int hf_devmode_size;
182
static int hf_devmode_spec_version;
183
static int hf_devmode_driver_version;
184
static int hf_devmode_size2;
185
static int hf_devmode_driver_extra_len;
186
static int hf_devmode_fields;
187
static int hf_devmode_orientation;
188
static int hf_devmode_paper_size;
189
static int hf_devmode_paper_width;
190
static int hf_devmode_paper_length;
191
static int hf_devmode_scale;
192
static int hf_devmode_copies;
193
static int hf_devmode_default_source;
194
static int hf_devmode_print_quality;
195
static int hf_devmode_color;
196
static int hf_devmode_duplex;
197
static int hf_devmode_y_resolution;
198
static int hf_devmode_tt_option;
199
static int hf_devmode_collate;
200
static int hf_devmode_log_pixels;
201
static int hf_devmode_bits_per_pel;
202
static int hf_devmode_pels_width;
203
static int hf_devmode_pels_height;
204
static int hf_devmode_display_flags;
205
static int hf_devmode_display_freq;
206
static int hf_devmode_icm_method;
207
static int hf_devmode_icm_intent;
208
static int hf_devmode_media_type;
209
static int hf_devmode_dither_type;
210
static int hf_devmode_reserved1;
211
static int hf_devmode_reserved2;
212
static int hf_devmode_panning_width;
213
static int hf_devmode_panning_height;
214
static int hf_devmode_driver_extra;
215
216
static int hf_devmode_fields_orientation;
217
static int hf_devmode_fields_papersize;
218
static int hf_devmode_fields_paperlength;
219
static int hf_devmode_fields_paperwidth;
220
static int hf_devmode_fields_scale;
221
static int hf_devmode_fields_position;
222
static int hf_devmode_fields_nup;
223
static int hf_devmode_fields_copies;
224
static int hf_devmode_fields_defaultsource;
225
static int hf_devmode_fields_printquality;
226
static int hf_devmode_fields_color;
227
static int hf_devmode_fields_duplex;
228
static int hf_devmode_fields_yresolution;
229
static int hf_devmode_fields_ttoption;
230
static int hf_devmode_fields_collate;
231
static int hf_devmode_fields_formname;
232
static int hf_devmode_fields_logpixels;
233
static int hf_devmode_fields_bitsperpel;
234
static int hf_devmode_fields_pelswidth;
235
static int hf_devmode_fields_pelsheight;
236
static int hf_devmode_fields_displayflags;
237
static int hf_devmode_fields_displayfrequency;
238
static int hf_devmode_fields_icmmethod;
239
static int hf_devmode_fields_icmintent;
240
static int hf_devmode_fields_mediatype;
241
static int hf_devmode_fields_dithertype;
242
static int hf_devmode_fields_panningwidth;
243
static int hf_devmode_fields_panningheight;
244
245
/* Print job */
246
247
static int hf_job_id;
248
static int hf_job_priority;
249
static int hf_job_position;
250
static int hf_job_totalpages;
251
static int hf_job_totalbytes;
252
static int hf_job_pagesprinted;
253
static int hf_job_bytesprinted;
254
static int hf_job_size;
255
256
static int hf_job_status;
257
static int hf_job_status_paused;
258
static int hf_job_status_error;
259
static int hf_job_status_deleting;
260
static int hf_job_status_spooling;
261
static int hf_job_status_printing;
262
static int hf_job_status_offline;
263
static int hf_job_status_paperout;
264
static int hf_job_status_printed;
265
static int hf_job_status_deleted;
266
static int hf_job_status_blocked;
267
static int hf_job_status_user_intervention;
268
269
/* Forms */
270
271
static int hf_form;
272
static int hf_form_level;
273
static int hf_form_name;
274
static int hf_form_flags;
275
static int hf_form_unknown;
276
static int hf_form_width;
277
static int hf_form_height;
278
static int hf_form_left_margin;
279
static int hf_form_top_margin;
280
static int hf_form_horiz_len;
281
static int hf_form_vert_len;
282
283
static int hf_enumforms_num;
284
285
/* Print notify */
286
287
static int hf_notify_options_version;
288
static int hf_notify_options_flags;
289
static int hf_notify_options_flags_refresh;
290
static int hf_notify_options_count;
291
static int hf_notify_option_type;
292
static int hf_notify_option_reserved1;
293
static int hf_notify_option_reserved2;
294
static int hf_notify_option_reserved3;
295
static int hf_notify_option_count;
296
static int hf_notify_option_data_count;
297
static int hf_notify_info_count;
298
static int hf_notify_info_version;
299
static int hf_notify_info_flags;
300
static int hf_notify_info_data_type;
301
static int hf_notify_info_data_count;
302
static int hf_notify_info_data_id;
303
static int hf_notify_info_data_value1;
304
static int hf_notify_info_data_value2;
305
static int hf_notify_info_data_bufsize;
306
static int hf_notify_info_data_buffer;
307
static int hf_notify_info_data_buffer_len;
308
static int hf_notify_info_data_buffer_data;
309
310
static int hf_notify_field;
311
312
static int hf_printerlocal;
313
314
static int hf_rrpcn_changelow;
315
static int hf_rrpcn_changehigh;
316
static int hf_rrpcn_unk0;
317
static int hf_rrpcn_unk1;
318
319
static int hf_replyopenprinter_unk0;
320
static int hf_replyopenprinter_unk1;
321
322
static int hf_devmode_devicename;
323
static int hf_devmode_form_name;
324
static int hf_relative_string;
325
static int hf_value_name;
326
static int hf_keybuffer;
327
static int hf_value_string;
328
329
static expert_field ei_unimplemented_dissector;
330
static expert_field ei_unknown_data;
331
static expert_field ei_spool_printer_info_level;
332
static expert_field ei_printer_info_level;
333
static expert_field ei_form_level;
334
static expert_field ei_job_info_level;
335
static expert_field ei_driver_info_level;
336
static expert_field ei_level;
337
static expert_field ei_notify_info_data_type;
338
static expert_field ei_enumprinterdataex_value;
339
static expert_field ei_buffer_size_too_long;
340
341
/* Registry data types */
342
343
#define DCERPC_REG_NONE                        0
344
0
#define DCERPC_REG_SZ                          1
345
#define DCERPC_REG_EXPAND_SZ                   2
346
0
#define DCERPC_REG_BINARY                      3
347
0
#define DCERPC_REG_DWORD                       4
348
#define DCERPC_REG_DWORD_LE                    4        /* DWORD, little endian
349
*/
350
#define DCERPC_REG_DWORD_BE                    5        /* DWORD, big endian */
351
#define DCERPC_REG_LINK                        6
352
0
#define DCERPC_REG_MULTI_SZ                    7
353
#define DCERPC_REG_RESOURCE_LIST               8
354
#define DCERPC_REG_FULL_RESOURCE_DESCRIPTOR    9
355
#define DCERPC_REG_RESOURCE_REQUIREMENTS_LIST 10
356
357
static const value_string reg_datatypes[] = {
358
  { DCERPC_REG_NONE, "REG_NONE" },
359
  { DCERPC_REG_SZ, "REG_SZ" },
360
  { DCERPC_REG_EXPAND_SZ, "REG_EXPAND_SZ" },
361
  { DCERPC_REG_BINARY, "REG_BINARY" },
362
  { DCERPC_REG_DWORD, "REG_DWORD" },
363
/*    { DCERPC_REG_DWORD_LE, "REG_DWORD_LE" }, */
364
  { DCERPC_REG_DWORD_BE, "REG_DWORD_BE" },
365
  { DCERPC_REG_LINK, "REG_LINK" },
366
  { DCERPC_REG_MULTI_SZ, "REG_MULTI_SZ" },
367
  { DCERPC_REG_RESOURCE_LIST, "REG_RESOURCE_LIST" },
368
  { DCERPC_REG_FULL_RESOURCE_DESCRIPTOR, "REG_FULL_RESOURCE_DESCRIPTOR" },
369
  { DCERPC_REG_RESOURCE_REQUIREMENTS_LIST, "REG_RESOURCE_REQUIREMENTS_LIST" },
370
  {0, NULL }
371
};
372
static value_string_ext reg_datatypes_ext = VALUE_STRING_EXT_INIT(reg_datatypes);
373
374
/****************************************************************************/
375
376
/*
377
 * Dissect SPOOLSS specific access rights
378
 */
379
380
static int hf_server_access_admin;
381
static int hf_server_access_enum;
382
static int hf_printer_access_admin;
383
static int hf_printer_access_use;
384
static int hf_job_access_admin;
385
386
static void
387
spoolss_printer_specific_rights(tvbuff_t *tvb, unsigned offset, proto_tree *tree,
388
        uint32_t access)
389
0
{
390
0
  proto_tree_add_boolean(
391
0
    tree, hf_printer_access_use, tvb, offset, 4, access);
392
393
0
  proto_tree_add_boolean(
394
0
    tree, hf_printer_access_admin, tvb, offset, 4, access);
395
0
}
396
397
struct access_mask_info spoolss_printer_access_mask_info = {
398
  "SPOOLSS printer",
399
  spoolss_printer_specific_rights,
400
  NULL,     /* Generic mapping table */
401
  NULL      /* Standard mapping table */
402
};
403
404
static void
405
spoolss_printserver_specific_rights(tvbuff_t *tvb, unsigned offset,
406
            proto_tree *tree, uint32_t access)
407
0
{
408
0
  proto_tree_add_boolean(
409
0
    tree, hf_server_access_enum, tvb, offset, 4, access);
410
411
0
  proto_tree_add_boolean(
412
0
    tree, hf_server_access_admin, tvb, offset, 4, access);
413
0
}
414
415
static struct access_mask_info spoolss_printserver_access_mask_info = {
416
  "SPOOLSS print server",
417
  spoolss_printserver_specific_rights,
418
  NULL,     /* Generic mapping table */
419
  NULL      /* Standard mapping table */
420
};
421
422
static void
423
spoolss_job_specific_rights(tvbuff_t *tvb, unsigned offset,
424
          proto_tree *tree, uint32_t access)
425
0
{
426
0
  proto_tree_add_boolean(
427
0
    tree, hf_job_access_admin, tvb, offset, 4, access);
428
0
}
429
430
static struct access_mask_info spoolss_job_access_mask_info = {
431
  "SPOOLSS job",
432
  spoolss_job_specific_rights,
433
  NULL,     /* Generic mapping table */
434
  NULL      /* Standard mapping table */
435
};
436
437
/*
438
 * Routines to dissect a spoolss BUFFER
439
 */
440
441
typedef struct {
442
  tvbuff_t *tvb;
443
  proto_item *tree; /* Proto tree buffer located in */
444
  proto_item *item;
445
} BUFFER;
446
447
static int ett_BUFFER;
448
449
static unsigned
450
dissect_spoolss_buffer_data(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
451
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
452
0
{
453
0
  BUFFER *b = (BUFFER *)di->private_data;
454
0
  proto_item *item;
455
0
  uint32_t size;
456
0
  const uint8_t *data;
457
458
0
  if (di->conformant_run)
459
0
    return offset;
460
461
  /* Dissect size and data */
462
463
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
464
0
            hf_buffer_size, &size);
465
466
  /* Before going any further, we must ensure the bytes
467
     actually esist in the tvb */
468
0
  if ((uint32_t)tvb_reported_length_remaining(tvb, offset) < size) {
469
0
    expert_add_info(pinfo, tree, &ei_buffer_size_too_long);
470
0
    return offset;
471
0
  }
472
473
0
  offset = dissect_ndr_uint8s(tvb, offset, pinfo, NULL, di, drep,
474
0
            hf_buffer_data, size, &data);
475
476
0
  item = proto_tree_add_item(
477
0
    tree, hf_buffer_data, tvb, offset - size,
478
0
    size, ENC_NA);
479
480
  /* Return buffer info */
481
482
0
  if (b) {
483
484
    /* I'm not sure about this.  Putting the buffer into
485
       its own tvb makes sense and the dissection code is
486
       much clearer, but the data is a proper subset of
487
       the actual tvb.  Not adding the new data source
488
       makes the hex display confusing as it switches
489
       between the 'DCERPC over SMB' tvb and the buffer
490
       tvb with no visual cues as to what is going on. */
491
492
0
    b->tvb = tvb_new_child_real_data(tvb, data, size, size);
493
0
    add_new_data_source(pinfo, b->tvb, "SPOOLSS buffer");
494
495
0
    b->item = item;
496
0
    b->tree = proto_item_add_subtree(item, ett_BUFFER);
497
0
  }
498
499
0
  return offset;
500
0
}
501
502
/* Dissect a spoolss buffer and return buffer data */
503
504
static unsigned
505
dissect_spoolss_buffer(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
506
           proto_tree *tree, dcerpc_info *di, uint8_t *drep, BUFFER *b)
507
0
{
508
0
  if (b)
509
0
    memset(b, 0, sizeof(BUFFER));
510
511
0
  di->private_data = b;
512
513
0
  offset = dissect_ndr_pointer(
514
0
    tvb, offset, pinfo, tree, di, drep,
515
0
    dissect_spoolss_buffer_data, NDR_POINTER_UNIQUE,
516
0
    "Buffer", -1);
517
518
0
  return offset;
519
0
}
520
521
static unsigned
522
dissect_spoolss_string_parm_data(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
523
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
524
0
{
525
0
  uint32_t buffer_len;
526
0
  unsigned len;
527
0
  char *s;
528
0
  proto_item *item = NULL;
529
530
0
  if (di->conformant_run)
531
0
    return offset;
532
533
  /* Dissect size and data */
534
535
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
536
0
        hf_string_parm_size, &buffer_len);
537
538
0
  s = (char*)tvb_get_stringz_enc(pinfo->pool, tvb, offset, &len, ENC_UTF_16|ENC_LITTLE_ENDIAN);
539
540
0
  if (tree && buffer_len) {
541
0
    tvb_ensure_bytes_exist(tvb, offset, buffer_len);
542
543
0
    item = proto_tree_add_string(
544
0
      tree, hf_string_parm_data, tvb, offset, len, s);
545
0
  }
546
0
  offset += buffer_len;
547
548
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", s);
549
550
  /* Append string to upper level item */
551
0
  if (tree && item) {
552
0
    item = item->parent != NULL ? item->parent : item;
553
0
    proto_item_append_text(item, ": %s", s);
554
0
  }
555
556
0
  return offset;
557
0
}
558
559
/* Dissect a spoolss string parameter */
560
561
static unsigned
562
dissect_spoolss_string_parm(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
563
           proto_tree *tree, dcerpc_info *di, uint8_t *drep, const char *text)
564
0
{
565
0
  offset = dissect_ndr_pointer(
566
0
    tvb, offset, pinfo, tree, di, drep,
567
0
    dissect_spoolss_string_parm_data, NDR_POINTER_UNIQUE,
568
0
    text, -1);
569
570
0
  return offset;
571
0
}
572
573
/*
574
 * SYSTEM_TIME
575
 */
576
577
static int ett_SYSTEM_TIME;
578
579
static int hf_time_year;
580
static int hf_time_month;
581
static int hf_time_dow;
582
static int hf_time_day;
583
static int hf_time_hour;
584
static int hf_time_minute;
585
static int hf_time_second;
586
static int hf_time_msec;
587
588
static unsigned
589
dissect_SYSTEM_TIME(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
590
        proto_tree *tree, dcerpc_info *di, uint8_t *drep, const char *name,
591
        bool add_subtree, char **data)
592
0
{
593
0
  proto_item *item = NULL;
594
0
  proto_tree *subtree = tree;
595
0
  uint16_t year, month, day, hour, minute, second, millisecond;
596
0
  char *str;
597
598
0
  if (add_subtree) {
599
0
    subtree = proto_tree_add_subtree(tree, tvb, offset, 16, ett_SYSTEM_TIME, &item, name);
600
0
  }
601
602
0
  offset = dissect_ndr_uint16(
603
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_year, &year);
604
605
0
  offset = dissect_ndr_uint16(
606
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_month, &month);
607
608
0
  offset = dissect_ndr_uint16(
609
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_dow, NULL);
610
611
0
  offset = dissect_ndr_uint16(
612
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_day, &day);
613
614
0
  offset = dissect_ndr_uint16(
615
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_hour, &hour);
616
617
0
  offset = dissect_ndr_uint16(
618
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_minute, &minute);
619
620
0
  offset = dissect_ndr_uint16(
621
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_second, &second);
622
623
0
  offset = dissect_ndr_uint16(
624
0
    tvb, offset, pinfo, subtree, di, drep, hf_time_msec, &millisecond);
625
626
0
  str = wmem_strdup_printf(pinfo->pool,
627
0
            "%d/%02d/%02d %02d:%02d:%02d.%03d",
628
0
            year, month, day, hour, minute, second,
629
0
            millisecond);
630
631
0
  if (add_subtree)
632
0
    proto_item_append_text(item, ": %s", str);
633
634
0
  if (data)
635
0
    *data = str;
636
637
0
  return offset;
638
0
}
639
640
static unsigned
641
dissect_SYSTEM_TIME_ptr(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
642
      proto_tree *tree, dcerpc_info *di, uint8_t *drep)
643
0
{
644
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
645
0
  char *str;
646
647
648
0
  offset =  dissect_SYSTEM_TIME(
649
0
    tvb, offset, pinfo, tree, di, drep, NULL, false, &str);
650
0
  dcv->private_data = wmem_strdup(wmem_file_scope(), str);
651
652
0
  return offset;
653
0
}
654
655
/*
656
 * SpoolssClosePrinter
657
 */
658
659
static unsigned
660
SpoolssClosePrinter_q(tvbuff_t *tvb, unsigned offset,
661
         packet_info *pinfo, proto_tree *tree,
662
         dcerpc_info *di, uint8_t *drep)
663
0
{
664
0
  e_ctx_hnd policy_hnd;
665
0
  char *pol_name;
666
667
  /* Parse packet */
668
669
0
  offset = dissect_nt_policy_hnd(
670
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, NULL,
671
0
    PIDL_POLHND_CLOSE);
672
673
0
  dcerpc_fetch_polhnd_data(&policy_hnd, &pol_name, NULL, NULL, NULL,
674
0
           pinfo->num);
675
676
0
  if (pol_name)
677
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
678
0
        pol_name);
679
680
0
  return offset;
681
0
}
682
683
static unsigned
684
SpoolssClosePrinter_r(tvbuff_t *tvb, unsigned offset,
685
         packet_info *pinfo, proto_tree *tree,
686
         dcerpc_info *di, uint8_t *drep)
687
0
{
688
  /* Parse packet */
689
690
0
  offset = dissect_nt_policy_hnd(
691
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
692
0
    PIDL_POLHND_USE);
693
694
695
0
  offset = dissect_doserror(
696
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
697
698
0
  return offset;
699
0
}
700
701
/* Dissect some printer data.  The get/set/enum printerdata routines all
702
   store value/data in a uint8 array.  We could use the ndr routines for
703
   this but that would result in one item for each byte in the printer
704
   data. */
705
706
static int ett_printerdata_data;
707
static int ett_printerdata_value;
708
709
static unsigned
710
dissect_printerdata_data(tvbuff_t *tvb, unsigned offset,
711
            packet_info *pinfo, proto_tree *tree,
712
            dcerpc_info *di, uint8_t *drep, uint32_t type)
713
0
{
714
0
  proto_item *item, *hidden_item;
715
0
  proto_tree *subtree;
716
0
  uint32_t size;
717
718
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_printerdata_data, &item, "Data");
719
720
0
  offset = dissect_ndr_uint32(
721
0
    tvb, offset, pinfo, subtree, di, drep, hf_printerdata_size, &size);
722
723
0
  if (size) {
724
725
0
    offset = dissect_ndr_uint8s(
726
0
      tvb, offset, pinfo, subtree, di, drep,
727
0
      hf_printerdata_data, size, NULL);
728
729
0
    switch(type) {
730
0
    case DCERPC_REG_SZ: {
731
0
      const uint8_t *data;
732
733
0
      hidden_item = proto_tree_add_item_ret_string(
734
0
        tree, hf_printerdata_data_sz, tvb,
735
0
        offset - size, size, ENC_UTF_16|ENC_LITTLE_ENDIAN, pinfo->pool, &data);
736
0
      proto_item_set_hidden(hidden_item);
737
738
0
      proto_item_append_text(item, ": %s", data);
739
740
0
      col_append_fstr(pinfo->cinfo, COL_INFO, " = %s", data);
741
0
      break;
742
0
    }
743
0
    case DCERPC_REG_DWORD: {
744
0
      uint32_t data = tvb_get_letohl(tvb, offset - size);
745
746
0
      proto_item_append_text(item, ": 0x%08x", data);
747
748
0
      col_append_fstr(
749
0
          pinfo->cinfo, COL_INFO, " = 0x%08x",
750
0
          data);
751
752
0
      hidden_item = proto_tree_add_uint(
753
0
        tree, hf_printerdata_data_dword, tvb,
754
0
        offset - size, 4, data);
755
0
      proto_item_set_hidden(hidden_item);
756
757
0
      break;
758
0
    }
759
0
    case DCERPC_REG_BINARY:
760
0
      col_append_str(
761
0
          pinfo->cinfo, COL_INFO,
762
0
          " = <binary data>");
763
0
      break;
764
765
0
    default:
766
0
      break;
767
0
    }
768
0
  }
769
770
0
  proto_item_set_len(item, size + 4);
771
772
0
  return offset;
773
0
}
774
775
/*
776
 * SpoolssGetPrinterData
777
 */
778
779
static unsigned
780
SpoolssGetPrinterData_q(tvbuff_t *tvb, unsigned offset,
781
           packet_info *pinfo, proto_tree *tree,
782
           dcerpc_info *di, uint8_t *drep)
783
0
{
784
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
785
0
  char *value_name;
786
0
  proto_item *hidden_item;
787
788
0
  hidden_item = proto_tree_add_uint(
789
0
    tree, hf_printerdata, tvb, offset, 0, 1);
790
0
  proto_item_set_hidden(hidden_item);
791
792
  /* Parse packet */
793
794
0
  offset = dissect_nt_policy_hnd(
795
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
796
0
    PIDL_POLHND_USE);
797
798
799
0
  value_name = NULL;
800
0
  offset = dissect_ndr_cvstring(
801
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
802
0
    hf_printerdata_value, true, &value_name);
803
  /* GetPrinterData() stores the printerdata in se_data */
804
0
  if(!pinfo->fd->visited){
805
0
    if(!dcv->se_data && value_name){
806
0
      dcv->se_data = wmem_strdup(wmem_file_scope(), value_name);
807
0
    }
808
0
  }
809
810
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", value_name);
811
812
0
  offset = dissect_ndr_uint32(
813
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
814
815
0
  return offset;
816
0
}
817
818
static unsigned
819
SpoolssGetPrinterData_r(tvbuff_t *tvb, unsigned offset,
820
           packet_info *pinfo, proto_tree *tree,
821
           dcerpc_info *di, uint8_t *drep)
822
0
{
823
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
824
0
  uint32_t type;
825
0
  proto_item *hidden_item;
826
0
  const char *data;
827
828
0
  hidden_item = proto_tree_add_uint(
829
0
    tree, hf_printerdata, tvb, offset, 0, 1);
830
0
  proto_item_set_hidden(hidden_item);
831
832
  /* Parse packet */
833
834
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
835
0
            hf_printerdata_type, &type);
836
837
0
  data = (const char *)(dcv->se_data ? dcv->se_data : "????");
838
839
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", data);
840
841
0
  offset = dissect_printerdata_data(
842
0
    tvb, offset, pinfo, tree, di, drep, type);
843
844
0
  offset = dissect_ndr_uint32(
845
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
846
847
0
  offset = dissect_doserror(
848
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
849
850
0
  return offset;
851
0
}
852
853
/*
854
 * SpoolssGetPrinterDataEx
855
 */
856
857
static unsigned
858
SpoolssGetPrinterDataEx_q(tvbuff_t *tvb, unsigned offset,
859
             packet_info *pinfo, proto_tree *tree,
860
             dcerpc_info *di, uint8_t *drep)
861
0
{
862
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
863
0
  char *key_name, *value_name;
864
0
  proto_item *hidden_item;
865
866
0
  hidden_item = proto_tree_add_uint(
867
0
    tree, hf_printerdata, tvb, offset, 0, 1);
868
0
  proto_item_set_hidden(hidden_item);
869
870
  /* Parse packet */
871
872
0
  offset = dissect_nt_policy_hnd(
873
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
874
0
    PIDL_POLHND_USE);
875
876
0
  key_name=NULL;
877
0
  offset = dissect_ndr_cvstring(
878
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
879
0
    hf_printerdata_key, true, &key_name);
880
881
0
  value_name=NULL;
882
0
  offset = dissect_ndr_cvstring(
883
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
884
0
    hf_printerdata_value, true, &value_name);
885
886
  /* GetPrinterDataEx() stores the key/value in se_data */
887
0
  if(!pinfo->fd->visited){
888
0
    if(!dcv->se_data){
889
0
      dcv->se_data = wmem_strdup_printf(wmem_file_scope(),
890
0
        "%s==%s",
891
0
        key_name?key_name:"",
892
0
        value_name?value_name:"");
893
0
    }
894
0
  }
895
896
0
  if (dcv->se_data)
897
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
898
0
        (char *)dcv->se_data);
899
900
0
  offset = dissect_ndr_uint32(
901
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
902
903
0
  return offset;
904
0
}
905
906
static unsigned
907
SpoolssGetPrinterDataEx_r(tvbuff_t *tvb, unsigned offset,
908
             packet_info *pinfo, proto_tree *tree,
909
             dcerpc_info *di, uint8_t *drep)
910
0
{
911
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
912
0
  uint32_t size, type;
913
0
  proto_item *hidden_item;
914
915
0
  hidden_item = proto_tree_add_uint(
916
0
    tree, hf_printerdata, tvb, offset, 0, 1);
917
0
  proto_item_set_hidden(hidden_item);
918
919
  /* Parse packet */
920
921
0
  offset = dissect_ndr_uint32(
922
0
    tvb, offset, pinfo, tree, di, drep, hf_printerdata_type, &type);
923
924
0
  offset = dissect_ndr_uint32(
925
0
    tvb, offset, pinfo, tree, di, drep, hf_returned, &size);
926
927
0
  if (dcv->se_data) {
928
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", (char *)dcv->se_data);
929
0
  }
930
931
0
  if (size)
932
0
    dissect_printerdata_data(tvb, offset, pinfo, tree, di, drep, type);
933
934
0
  offset += size;
935
936
0
  offset = dissect_ndr_uint32(
937
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
938
939
0
  offset = dissect_doserror(
940
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
941
942
0
  return offset;
943
0
}
944
945
/*
946
 * SpoolssSetPrinterData
947
 */
948
949
static unsigned
950
SpoolssSetPrinterData_q(tvbuff_t *tvb, unsigned offset,
951
           packet_info *pinfo, proto_tree *tree,
952
           dcerpc_info *di, uint8_t *drep)
953
0
{
954
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
955
0
  char *value_name;
956
0
  uint32_t type;
957
0
  proto_item *hidden_item;
958
959
0
  hidden_item = proto_tree_add_uint(
960
0
    tree, hf_printerdata, tvb, offset, 0, 1);
961
0
  proto_item_set_hidden(hidden_item);
962
963
  /* Parse packet */
964
965
0
  offset = dissect_nt_policy_hnd(
966
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
967
0
    PIDL_POLHND_USE);
968
969
0
  value_name=NULL;
970
0
  offset = dissect_ndr_cvstring(
971
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
972
0
    hf_printerdata_value, true, &value_name);
973
974
  /* GetPrinterDataEx() stores the key/value in se_data */
975
0
  if(!pinfo->fd->visited){
976
0
    if(!dcv->se_data){
977
0
      dcv->se_data = wmem_strdup(wmem_file_scope(),
978
0
        value_name?value_name:"");
979
0
    }
980
0
  }
981
982
983
0
  if (dcv->se_data){
984
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", (char *)dcv->se_data);
985
0
  }
986
987
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
988
0
            hf_printerdata_type, &type);
989
990
0
  offset = dissect_printerdata_data(
991
0
    tvb, offset, pinfo, tree, di, drep, type);
992
993
0
  offset = dissect_ndr_uint32(
994
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
995
996
0
  return offset;
997
0
}
998
999
static unsigned
1000
SpoolssSetPrinterData_r(tvbuff_t *tvb, unsigned offset,
1001
           packet_info *pinfo, proto_tree *tree,
1002
           dcerpc_info *di, uint8_t *drep)
1003
0
{
1004
0
  proto_item *hidden_item;
1005
1006
0
  hidden_item = proto_tree_add_uint(
1007
0
    tree, hf_printerdata, tvb, offset, 0, 1);
1008
0
  proto_item_set_hidden(hidden_item);
1009
1010
  /* Parse packet */
1011
1012
0
  offset = dissect_doserror(
1013
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
1014
1015
0
  return offset;
1016
0
}
1017
1018
/*
1019
 * SpoolssSetPrinterDataEx
1020
 */
1021
1022
static int hf_setprinterdataex_max_len;
1023
static int hf_setprinterdataex_real_len;
1024
static int hf_setprinterdataex_data;
1025
1026
static unsigned
1027
SpoolssSetPrinterDataEx_q(tvbuff_t *tvb, unsigned offset,
1028
             packet_info *pinfo, proto_tree *tree,
1029
             dcerpc_info *di, uint8_t *drep)
1030
0
{
1031
0
  char *key_name, *value_name;
1032
0
  uint32_t max_len;
1033
0
  proto_item *hidden_item;
1034
1035
0
  hidden_item = proto_tree_add_uint(
1036
0
    tree, hf_printerdata, tvb, offset, 0, 1);
1037
0
  proto_item_set_hidden(hidden_item);
1038
1039
  /* Parse packet */
1040
1041
0
  offset = dissect_nt_policy_hnd(
1042
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
1043
0
    PIDL_POLHND_USE);
1044
1045
0
  offset = dissect_ndr_cvstring(
1046
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
1047
0
    hf_printerdata_key, true, &key_name);
1048
1049
0
  offset = dissect_ndr_cvstring(
1050
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
1051
0
    hf_printerdata_value, true, &value_name);
1052
1053
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s/%s",
1054
0
        key_name, value_name);
1055
1056
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
1057
0
            hf_printerdata_type, NULL);
1058
1059
0
  offset = dissect_ndr_uint32(
1060
0
    tvb, offset, pinfo, tree, di, drep,
1061
0
    hf_setprinterdataex_max_len, &max_len);
1062
1063
0
  offset = dissect_ndr_uint8s(
1064
0
    tvb, offset, pinfo, tree, di, drep,
1065
0
    hf_setprinterdataex_data, max_len, NULL);
1066
1067
0
  offset = dissect_ndr_uint32(
1068
0
    tvb, offset, pinfo, tree, di, drep,
1069
0
    hf_setprinterdataex_real_len, NULL);
1070
1071
0
  return offset;
1072
0
}
1073
1074
static unsigned
1075
SpoolssSetPrinterDataEx_r(tvbuff_t *tvb, unsigned offset,
1076
             packet_info *pinfo, proto_tree *tree,
1077
             dcerpc_info *di, uint8_t *drep)
1078
0
{
1079
0
  proto_item *hidden_item;
1080
1081
0
  hidden_item = proto_tree_add_uint(
1082
0
    tree, hf_printerdata, tvb, offset, 0, 1);
1083
0
  proto_item_set_hidden(hidden_item);
1084
1085
  /* Parse packet */
1086
1087
0
  offset = dissect_doserror(
1088
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
1089
1090
0
  return offset;
1091
0
}
1092
1093
/* XXX - "name" should be an hf_ value for an FT_STRING. */
1094
static unsigned
1095
dissect_spoolss_uint16uni(tvbuff_t *tvb, unsigned offset, packet_info *pinfo _U_,
1096
        proto_tree *tree, uint8_t *drep _U_, char **data,
1097
        int hf_name)
1098
0
{
1099
0
  int len, remaining;
1100
0
  char *text;
1101
1102
0
  offset = WS_ROUNDUP_2(offset);
1103
1104
  /* Get remaining data in buffer as a string */
1105
1106
0
  remaining = tvb_reported_length_remaining(tvb, offset);
1107
0
  if (remaining <= 0) {
1108
0
    if (data)
1109
0
      *data = wmem_strdup(pinfo->pool, "");
1110
0
    return offset;
1111
0
  }
1112
1113
0
  text = (char*)tvb_get_string_enc(pinfo->pool, tvb, offset, remaining, ENC_UTF_16|ENC_LITTLE_ENDIAN);
1114
0
  len = (int)strlen(text);
1115
1116
0
  proto_tree_add_string(tree, hf_name, tvb, offset, len * 2, text);
1117
1118
0
  if (data)
1119
0
    *data = text;
1120
1121
0
  return offset + (len + 1) * 2;
1122
0
}
1123
1124
/*
1125
 * DEVMODE
1126
 */
1127
1128
/* Devicemode orientation values */
1129
1130
static const value_string devmode_orientation_vals[] =
1131
{
1132
  { DEVMODE_ORIENTATION_PORTRAIT, "Portrait" },
1133
  { DEVMODE_ORIENTATION_LANDSCAPE, "Landscape" },
1134
  { 0, NULL }
1135
};
1136
1137
/* Paper size values.  International paper sizes is a fascinating
1138
   topic.  No seriously!  (-: */
1139
1140
static const value_string devmode_papersize_vals[] =
1141
{
1142
  { DEVMODE_PAPERSIZE_LETTER, "Letter" },
1143
  { DEVMODE_PAPERSIZE_LETTERSMALL, "Letter (small)" },
1144
  { DEVMODE_PAPERSIZE_TABLOID, "Tabloid" },
1145
  { DEVMODE_PAPERSIZE_LEDGER, "Ledger" },
1146
  { DEVMODE_PAPERSIZE_LEGAL, "Legal" },
1147
  { DEVMODE_PAPERSIZE_STATEMENT, "Statement" },
1148
  { DEVMODE_PAPERSIZE_EXECUTIVE, "Executive" },
1149
  { DEVMODE_PAPERSIZE_A3, "A3" },
1150
  { DEVMODE_PAPERSIZE_A4, "A4" },
1151
  { DEVMODE_PAPERSIZE_A4SMALL, "A4 (small)" },
1152
  { DEVMODE_PAPERSIZE_A5, "A5" },
1153
  { DEVMODE_PAPERSIZE_B4, "B4" },
1154
  { DEVMODE_PAPERSIZE_B5, "B5" },
1155
  { DEVMODE_PAPERSIZE_FOLIO, "Folio" },
1156
  { DEVMODE_PAPERSIZE_QUARTO, "Quarto" },
1157
  { DEVMODE_PAPERSIZE_10X14, "10x14" },
1158
  { DEVMODE_PAPERSIZE_11X17, "11x17" },
1159
  { DEVMODE_PAPERSIZE_NOTE, "Note" },
1160
  { DEVMODE_PAPERSIZE_ENV9, "Envelope #9" },
1161
  { DEVMODE_PAPERSIZE_ENV10, "Envelope #10" },
1162
  { DEVMODE_PAPERSIZE_ENV11, "Envelope #11" },
1163
  { DEVMODE_PAPERSIZE_ENV12, "Envelope #12" },
1164
  { DEVMODE_PAPERSIZE_ENV14, "Envelope #14" },
1165
  { DEVMODE_PAPERSIZE_CSHEET, "C sheet" },
1166
  { DEVMODE_PAPERSIZE_DSHEET, "D sheet" },
1167
  { DEVMODE_PAPERSIZE_ESHEET, "E sheet" },
1168
  { DEVMODE_PAPERSIZE_ENVDL, "Envelope DL" },
1169
  { DEVMODE_PAPERSIZE_ENVC5, "Envelope C5" },
1170
  { DEVMODE_PAPERSIZE_ENVC3, "Envelope C3" },
1171
  { DEVMODE_PAPERSIZE_ENVC4, "Envelope C4" },
1172
  { DEVMODE_PAPERSIZE_ENVC6, "Envelope C6" },
1173
  { DEVMODE_PAPERSIZE_ENVC65, "Envelope C65" },
1174
  { DEVMODE_PAPERSIZE_ENVB4, "Envelope B4" },
1175
  { DEVMODE_PAPERSIZE_ENVB5, "Envelope B5" },
1176
  { DEVMODE_PAPERSIZE_ENVB6, "Envelope B6" },
1177
  { DEVMODE_PAPERSIZE_ENVITALY, "Envelope (Italy)" },
1178
  { DEVMODE_PAPERSIZE_ENVMONARCH, "Envelope (Monarch)" },
1179
  { DEVMODE_PAPERSIZE_ENVPERSONAL, "Envelope (Personal)" },
1180
  { DEVMODE_PAPERSIZE_FANFOLDUS, "Fanfold (US)" },
1181
  { DEVMODE_PAPERSIZE_FANFOLDSTDGERMAN, "Fanfold (Std German)" },
1182
  { DEVMODE_PAPERSIZE_FANFOLDLGLGERMAN, "Fanfold (Legal German)" },
1183
  { DEVMODE_PAPERSIZE_ISOB4, "B4 (ISO)" },
1184
  { DEVMODE_PAPERSIZE_JAPANESEPOSTCARD, "Japanese postcard" },
1185
  { DEVMODE_PAPERSIZE_9X11, "9x11" },
1186
  { DEVMODE_PAPERSIZE_10X11, "10x11" },
1187
  { DEVMODE_PAPERSIZE_15X11, "15x11" },
1188
  { DEVMODE_PAPERSIZE_ENVINVITE, "Envelope (Invite)" },
1189
  { DEVMODE_PAPERSIZE_RESERVED48, "Reserved (48)" },
1190
  { DEVMODE_PAPERSIZE_RESERVED49, "Reserved (49)" },
1191
  { DEVMODE_PAPERSIZE_LETTEREXTRA, "Letter (Extra)" },
1192
  { DEVMODE_PAPERSIZE_LEGALEXTRA, "Legal (Extra)" },
1193
  { DEVMODE_PAPERSIZE_TABLOIDEXTRA, "Tabloid (Extra)" },
1194
  { DEVMODE_PAPERSIZE_A4EXTRA, "A4 (Extra)" },
1195
  { DEVMODE_PAPERSIZE_LETTERTRANS, "Letter (Transverse)" },
1196
  { DEVMODE_PAPERSIZE_A4TRANS, "A4 (Transverse)" },
1197
  { DEVMODE_PAPERSIZE_LETTEREXTRATRANS, "Letter (Extra, Transverse)" },
1198
  { DEVMODE_PAPERSIZE_APLUS, "A+" },
1199
  { DEVMODE_PAPERSIZE_BPLUS, "B+" },
1200
  { DEVMODE_PAPERSIZE_LETTERPLUS, "Letter+" },
1201
  { DEVMODE_PAPERSIZE_A4PLUS, "A4+" },
1202
  { DEVMODE_PAPERSIZE_A5TRANS, "A5 (Transverse)" },
1203
  { DEVMODE_PAPERSIZE_B5TRANS, "B5 (Transverse)" },
1204
  { DEVMODE_PAPERSIZE_A3EXTRA, "A3 (Extra)" },
1205
  { DEVMODE_PAPERSIZE_A5EXTRA, "A5 (Extra)" },
1206
  { DEVMODE_PAPERSIZE_B5EXTRA, "B5 (Extra)" },
1207
  { DEVMODE_PAPERSIZE_A2, "A2" },
1208
  { DEVMODE_PAPERSIZE_A3TRANS, "A3 (Transverse)" },
1209
  { DEVMODE_PAPERSIZE_A3EXTRATRANS, "A3 (Extra, Transverse" },
1210
  { DEVMODE_PAPERSIZE_DBLJAPANESEPOSTCARD, "Double Japanese Postcard" },
1211
  { DEVMODE_PAPERSIZE_A6, "A6" },
1212
  { DEVMODE_PAPERSIZE_JENVKAKU2, "Japanese Envelope (Kaku #2)" },
1213
  { DEVMODE_PAPERSIZE_JENVKAKU3, "Japanese Envelope (Kaku #3)" },
1214
  { DEVMODE_PAPERSIZE_JENVCHOU3, "Japanese Envelope (Chou #3)" },
1215
  { DEVMODE_PAPERSIZE_JENVCHOU4, "Japanese Envelope (Chou #4)" },
1216
  { DEVMODE_PAPERSIZE_LETTERROT, "Letter (Rotated)" },
1217
  { DEVMODE_PAPERSIZE_A3ROT, "A3 (Rotated)" },
1218
  { DEVMODE_PAPERSIZE_A4ROT, "A4 (Rotated)" },
1219
  { DEVMODE_PAPERSIZE_A5ROT, "A5 (Rotated)" },
1220
  { DEVMODE_PAPERSIZE_B4JISROT, "B4 (JIS, Rotated)" },
1221
  { DEVMODE_PAPERSIZE_B5JISROT, "B5 (JIS, Rotated)"},
1222
  { DEVMODE_PAPERSIZE_JAPANESEPOSTCARDROT,
1223
    "Japanese Postcard (Rotated)" },
1224
  { DEVMODE_PAPERSIZE_DBLJAPANESEPOSTCARDROT82,
1225
    "Double Japanese Postcard (Rotated)" },
1226
  { DEVMODE_PAPERSIZE_A6ROT, "A6 (Rotated)" },
1227
  { DEVMODE_PAPERSIZE_JENVKAKU2ROT,
1228
    "Japanese Envelope (Kaku #2, Rotated)" },
1229
  { DEVMODE_PAPERSIZE_JENVKAKU3ROT,
1230
    "Japanese Envelope (Kaku #3, Rotated)" },
1231
  { DEVMODE_PAPERSIZE_JENVCHOU3ROT,
1232
    "Japanese Envelope (Chou #3, Rotated)" },
1233
  { DEVMODE_PAPERSIZE_JENVCHOU4ROT,
1234
    "Japanese Envelope (Chou #4, Rotated)" },
1235
  { DEVMODE_PAPERSIZE_B6JIS, "B6 (JIS)" },
1236
  { DEVMODE_PAPERSIZE_B6JISROT, "B6 (JIS, Rotated)" },
1237
  { DEVMODE_PAPERSIZE_12X11, "12x11" },
1238
  { DEVMODE_PAPERSIZE_JENVYOU4, "Japanese Envelope (You #4)" },
1239
  { DEVMODE_PAPERSIZE_JENVYOU4ROT,
1240
    "Japanese Envelope (You #4, Rotated" },
1241
  { DEVMODE_PAPERSIZE_P16K, "PRC 16K" },
1242
  { DEVMODE_PAPERSIZE_P32K, "PRC 32K" },
1243
  { DEVMODE_PAPERSIZE_P32KBIG, "P32K (Big)" },
1244
  { DEVMODE_PAPERSIZE_PENV1, "PRC Envelope #1" },
1245
  { DEVMODE_PAPERSIZE_PENV2, "PRC Envelope #2" },
1246
  { DEVMODE_PAPERSIZE_PENV3, "PRC Envelope #3" },
1247
  { DEVMODE_PAPERSIZE_PENV4, "PRC Envelope #4" },
1248
  { DEVMODE_PAPERSIZE_PENV5, "PRC Envelope #5" },
1249
  { DEVMODE_PAPERSIZE_PENV6, "PRC Envelope #6" },
1250
  { DEVMODE_PAPERSIZE_PENV7, "PRC Envelope #7" },
1251
  { DEVMODE_PAPERSIZE_PENV8, "PRC Envelope #8" },
1252
  { DEVMODE_PAPERSIZE_PENV9, "PRC Envelope #9" },
1253
  { DEVMODE_PAPERSIZE_PENV10, "PRC Envelope #10" },
1254
  { DEVMODE_PAPERSIZE_P16KROT, "PRC 16K (Rotated)" },
1255
  { DEVMODE_PAPERSIZE_P32KROT, "PRC 32K (Rotated)" },
1256
  { DEVMODE_PAPERSIZE_P32KBIGROT, "PRC 32K (Big, Rotated)" },
1257
  { DEVMODE_PAPERSIZE_PENV1ROT, "PRC Envelope #1 (Rotated)" },
1258
  { DEVMODE_PAPERSIZE_PENV2ROT, "PRC Envelope #2 (Rotated)" },
1259
  { DEVMODE_PAPERSIZE_PENV3ROT, "PRC Envelope #3 (Rotated)" },
1260
  { DEVMODE_PAPERSIZE_PENV4ROT, "PRC Envelope #4 (Rotated)" },
1261
  { DEVMODE_PAPERSIZE_PENV5ROT, "PRC Envelope #5 (Rotated)" },
1262
  { DEVMODE_PAPERSIZE_PENV6ROT, "PRC Envelope #6 (Rotated)" },
1263
  { DEVMODE_PAPERSIZE_PENV7ROT, "PRC Envelope #7 (Rotated)" },
1264
  { DEVMODE_PAPERSIZE_PENV8ROT, "PRC Envelope #8 (Rotated)" },
1265
  { DEVMODE_PAPERSIZE_PENV9ROT, "PRC Envelope #9 (Rotated)" },
1266
  { DEVMODE_PAPERSIZE_PENV10ROT, "PRC Envelope #10 (Rotated)" },
1267
  { 0, NULL }
1268
};
1269
static value_string_ext devmode_papersize_vals_ext = VALUE_STRING_EXT_INIT(devmode_papersize_vals);
1270
1271
/* List of observed specversions */
1272
1273
static const value_string devmode_specversion_vals[] =
1274
{
1275
  { 0x0320, "Observed" },
1276
  { 0x0400, "Observed" },
1277
  { 0x0401, "Observed" },
1278
  { 0x040d, "Observed" },
1279
  { 0, NULL }
1280
};
1281
1282
/* Paper sources */
1283
1284
static const value_string devmode_papersource_vals[] =
1285
{
1286
  { DEVMODE_PAPERSOURCE_UPPER, "Upper" },
1287
  { DEVMODE_PAPERSOURCE_LOWER, "Lower" },
1288
  { DEVMODE_PAPERSOURCE_MIDDLE, "Middle" },
1289
  { DEVMODE_PAPERSOURCE_MANUAL, "Manual" },
1290
  { DEVMODE_PAPERSOURCE_ENV, "Envelope" },
1291
  { DEVMODE_PAPERSOURCE_ENVMANUAL, "Envelope Manual" },
1292
  { DEVMODE_PAPERSOURCE_AUTO, "Auto" },
1293
  { DEVMODE_PAPERSOURCE_TRACTOR, "Tractor" },
1294
  { DEVMODE_PAPERSOURCE_SMALLFMT, "Small Format" },
1295
  { DEVMODE_PAPERSOURCE_LARGEFMAT, "Large Format" },
1296
  { DEVMODE_PAPERSOURCE_LARGECAP, "Large Capacity" },
1297
  { DEVMODE_PAPERSOURCE_CASSETTE, "Cassette" },
1298
  { DEVMODE_PAPERSOURCE_FORMSRC, "Form Source" },
1299
  { 0, NULL }
1300
};
1301
static value_string_ext devmode_papersource_vals_ext = VALUE_STRING_EXT_INIT(devmode_papersource_vals);
1302
1303
/* Print quality */
1304
1305
static const value_string devmode_printquality_vals[] =
1306
{
1307
  { DEVMODE_PRINTQUALITY_HIGH, "High" },
1308
  { DEVMODE_PRINTQUALITY_MEDIUM, "Medium" },
1309
  { DEVMODE_PRINTQUALITY_LOW, "Low" },
1310
  { DEVMODE_PRINTQUALITY_DRAFT, "Draft" },
1311
  { 0, NULL }
1312
};
1313
1314
/* Color */
1315
1316
static const value_string devmode_colour_vals[] =
1317
{
1318
  { DEVMODE_COLOUR_COLOUR, "Colour" },
1319
  { DEVMODE_COLOUR_MONO, "Monochrome" },
1320
  { 0, NULL }
1321
};
1322
1323
/* TrueType options */
1324
1325
static const value_string devmode_ttoption_vals[] =
1326
{
1327
  { 0, "Not set" },
1328
  { DEVMODE_TTOPTION_BITMAP, "Bitmap" },
1329
  { DEVMODE_TTOPTION_DOWNLOAD, "Download" },
1330
  { DEVMODE_TTOPTION_DOWNLOAD_OUTLINE, "Download outline" },
1331
  { DEVMODE_TTOPTION_SUBDEV, "Substitute device fonts" },
1332
  { 0, NULL }
1333
};
1334
1335
/* Collate info */
1336
1337
static const value_string devmode_collate_vals[] =
1338
{
1339
  { DEVMODE_COLLATE_FALSE, "False" },
1340
  { DEVMODE_COLLATE_TRUE, "True" },
1341
  { 0, NULL }
1342
};
1343
1344
/* Duplex info */
1345
1346
static const value_string devmode_duplex_vals[] =
1347
{
1348
  { DEVMODE_DUPLEX_SIMPLEX, "Simplex" },
1349
  { DEVMODE_DUPLEX_VERT, "Vertical" },
1350
  { DEVMODE_DUPLEX_HORIZ, "Horizontal" },
1351
  { 0, NULL }
1352
};
1353
1354
static const value_string devmode_displayflags_vals[] =
1355
{
1356
  { 0, "Colour" },
1357
  { DEVMODE_DISPLAYFLAGS_GRAYSCALE, "Grayscale" },
1358
  { DEVMODE_DISPLAYFLAGS_INTERLACED, "Interlaced" },
1359
  { 0, NULL }
1360
};
1361
1362
static const value_string devmode_icmmethod_vals[] =
1363
{
1364
  { DEVMODE_ICMMETHOD_NONE, "None" },
1365
  { DEVMODE_ICMMETHOD_SYSTEM, "System" },
1366
  { DEVMODE_ICMMETHOD_DRIVER, "Driver" },
1367
  { DEVMODE_ICMMETHOD_DEVICE, "Device" },
1368
  { 0, NULL }
1369
};
1370
1371
static const value_string devmode_icmintent_vals[] =
1372
{
1373
  { 0, "Not set" },
1374
  { DEVMODE_ICMINTENT_SATURATE, "Saturate" },
1375
  { DEVMODE_ICMINTENT_CONTRAST, "Contrast" },
1376
  { DEVMODE_ICMINTENT_COLORIMETRIC, "Colorimetric" },
1377
  { DEVMODE_ICMINTENT_ABS_COLORIMETRIC, "Absolute colorimetric" },
1378
  { 0, NULL }
1379
};
1380
1381
static const value_string devmode_mediatype_vals[] =
1382
{
1383
  { 0, "Not set" },
1384
  { DEVMODE_MEDIATYPE_STANDARD, "Standard" },
1385
  { DEVMODE_MEDIATYPE_TRANSPARENCY, "Transparency" },
1386
  { DEVMODE_MEDIATYPE_GLOSSY, "Glossy" },
1387
  { 0, NULL }
1388
};
1389
1390
static const value_string devmode_dithertype_vals[] =
1391
{
1392
  { 0, "Not set" },
1393
  { DEVMODE_DITHERTYPE_NONE, "None" },
1394
  { DEVMODE_DITHERTYPE_COARSE, "Coarse" },
1395
  { DEVMODE_DITHERTYPE_LINE, "Line" },
1396
  { DEVMODE_DITHERTYPE_LINEART, "Line art" },
1397
  { DEVMODE_DITHERTYPE_ERRORDIFFUSION, "Error diffusion" },
1398
  { DEVMODE_DITHERTYPE_RESERVED6, "Reserved 6" },
1399
  { DEVMODE_DITHERTYPE_RESERVED7, "Reserved 7" },
1400
  { DEVMODE_DITHERTYPE_GRAYSCALE, "Grayscale" },
1401
  { 0, NULL }
1402
};
1403
1404
static int ett_DEVMODE_fields;
1405
1406
static unsigned
1407
dissect_DEVMODE_fields(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
1408
           proto_tree *tree, dcerpc_info *di, uint8_t *drep, uint32_t *pdata)
1409
0
{
1410
0
  uint32_t fields;
1411
0
  proto_item *hidden_item;
1412
1413
0
  static int * const hf_fields[] = {
1414
0
    &hf_devmode_fields_orientation,
1415
0
    &hf_devmode_fields_papersize,
1416
0
    &hf_devmode_fields_paperlength,
1417
0
    &hf_devmode_fields_paperwidth,
1418
0
    &hf_devmode_fields_scale,
1419
0
    &hf_devmode_fields_position,
1420
0
    &hf_devmode_fields_nup,
1421
0
    &hf_devmode_fields_copies,
1422
0
    &hf_devmode_fields_defaultsource,
1423
0
    &hf_devmode_fields_printquality,
1424
0
    &hf_devmode_fields_color,
1425
0
    &hf_devmode_fields_duplex,
1426
0
    &hf_devmode_fields_yresolution,
1427
0
    &hf_devmode_fields_ttoption,
1428
0
    &hf_devmode_fields_collate,
1429
0
    &hf_devmode_fields_formname,
1430
0
    &hf_devmode_fields_logpixels,
1431
0
    &hf_devmode_fields_bitsperpel,
1432
0
    &hf_devmode_fields_pelswidth,
1433
0
    &hf_devmode_fields_pelsheight,
1434
0
    &hf_devmode_fields_displayflags,
1435
0
    &hf_devmode_fields_displayfrequency,
1436
0
    &hf_devmode_fields_icmmethod,
1437
0
    &hf_devmode_fields_icmintent,
1438
0
    &hf_devmode_fields_mediatype,
1439
0
    &hf_devmode_fields_dithertype,
1440
0
    &hf_devmode_fields_panningwidth,
1441
0
    &hf_devmode_fields_panningheight,
1442
0
    NULL
1443
0
  };
1444
1445
0
  hidden_item = proto_tree_add_uint(
1446
0
    tree, hf_devmode, tvb, offset, 0, 1);
1447
0
  proto_item_set_hidden(hidden_item);
1448
1449
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, NULL, di, drep, -1, &fields);
1450
1451
0
  proto_tree_add_bitmask_value_with_flags(tree, tvb, offset - 4, hf_devmode_fields,
1452
0
          ett_DEVMODE_fields, hf_fields, fields, BMT_NO_APPEND);
1453
1454
0
  if (pdata)
1455
0
    *pdata = fields;
1456
1457
0
  return offset;
1458
0
}
1459
1460
static int ett_DEVMODE;
1461
1462
static unsigned
1463
dissect_DEVMODE(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
1464
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
1465
0
{
1466
0
  proto_item *item;
1467
0
  proto_tree *subtree;
1468
0
  uint16_t driver_extra;
1469
0
  int16_t print_quality;
1470
0
  uint32_t fields;
1471
0
  int struct_start = offset;
1472
1473
0
  if (di->conformant_run)
1474
0
    return offset;
1475
1476
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_DEVMODE, &item, "Devicemode");
1477
1478
0
  offset = dissect_ndr_uint32(
1479
0
    tvb, offset, pinfo, subtree, di, drep, hf_devmode_size,
1480
0
    NULL);
1481
1482
  /* The device name is stored in a 32-wchar buffer */
1483
1484
0
  dissect_spoolss_uint16uni(tvb, offset, pinfo, subtree, drep, NULL, hf_devmode_devicename);
1485
0
  offset += 64;
1486
1487
0
  offset = dissect_ndr_uint16(
1488
0
    tvb, offset, pinfo, subtree, di, drep,
1489
0
    hf_devmode_spec_version, NULL);
1490
1491
0
  offset = dissect_ndr_uint16(
1492
0
    tvb, offset, pinfo, subtree, di, drep,
1493
0
    hf_devmode_driver_version, NULL);
1494
1495
0
  offset = dissect_ndr_uint16(
1496
0
    tvb, offset, pinfo, subtree, di, drep,
1497
0
    hf_devmode_size2, NULL);
1498
1499
0
  offset = dissect_ndr_uint16(
1500
0
    tvb, offset, pinfo, subtree, di, drep,
1501
0
    hf_devmode_driver_extra_len, &driver_extra);
1502
1503
0
  offset = dissect_DEVMODE_fields(
1504
0
    tvb, offset, pinfo, subtree, di, drep, &fields);
1505
1506
0
  offset = dissect_ndr_uint16(
1507
0
    tvb, offset, pinfo, subtree, di, drep,
1508
0
    hf_devmode_orientation, NULL);
1509
1510
0
  offset = dissect_ndr_uint16(
1511
0
    tvb, offset, pinfo, subtree, di, drep,
1512
0
    hf_devmode_paper_size, NULL);
1513
1514
0
  offset = dissect_ndr_uint16(
1515
0
    tvb, offset, pinfo, subtree, di, drep,
1516
0
    hf_devmode_paper_length, NULL);
1517
1518
0
  offset = dissect_ndr_uint16(
1519
0
    tvb, offset, pinfo, subtree, di, drep,
1520
0
    hf_devmode_paper_width, NULL);
1521
1522
0
  offset = dissect_ndr_uint16(
1523
0
    tvb, offset, pinfo, subtree, di, drep,
1524
0
    hf_devmode_scale, NULL);
1525
1526
0
  offset = dissect_ndr_uint16(
1527
0
    tvb, offset, pinfo, subtree, di, drep,
1528
0
    hf_devmode_copies, NULL);
1529
1530
0
  offset = dissect_ndr_uint16(
1531
0
    tvb, offset, pinfo, subtree, di, drep,
1532
0
    hf_devmode_default_source, NULL);
1533
1534
0
  offset = dissect_ndr_uint16(
1535
0
    tvb, offset, pinfo, NULL, di, drep,
1536
0
    hf_devmode_print_quality, (uint16_t*)&print_quality);
1537
1538
0
  if (print_quality < 0)
1539
0
    proto_tree_add_item(
1540
0
      subtree, hf_devmode_print_quality, tvb,
1541
0
      offset - 2, 2, DREP_ENC_INTEGER(drep));
1542
0
  else
1543
0
    proto_tree_add_uint_format_value(
1544
0
      subtree, hf_devmode_print_quality, tvb, offset - 4, 4,
1545
0
      print_quality, "%d dpi", print_quality);
1546
1547
0
  offset = dissect_ndr_uint16(
1548
0
    tvb, offset, pinfo, subtree, di, drep,
1549
0
    hf_devmode_color, NULL);
1550
1551
0
  offset = dissect_ndr_uint16(
1552
0
    tvb, offset, pinfo, subtree, di, drep,
1553
0
    hf_devmode_duplex, NULL);
1554
1555
0
  offset = dissect_ndr_uint16(
1556
0
    tvb, offset, pinfo, subtree, di, drep,
1557
0
    hf_devmode_y_resolution, NULL);
1558
1559
0
  offset = dissect_ndr_uint16(
1560
0
    tvb, offset, pinfo, subtree, di, drep,
1561
0
    hf_devmode_tt_option, NULL);
1562
1563
0
  offset = dissect_ndr_uint16(
1564
0
    tvb, offset, pinfo, subtree, di, drep,
1565
0
    hf_devmode_collate, NULL);
1566
1567
0
  dissect_spoolss_uint16uni(tvb, offset, pinfo, subtree, drep, NULL, hf_devmode_form_name);
1568
0
  offset += 64;
1569
1570
0
  offset = dissect_ndr_uint16(
1571
0
    tvb, offset, pinfo, subtree, di, drep,
1572
0
    hf_devmode_log_pixels, NULL);
1573
1574
0
  offset = dissect_ndr_uint32(
1575
0
    tvb, offset, pinfo, subtree, di, drep,
1576
0
    hf_devmode_bits_per_pel, NULL);
1577
1578
0
  offset = dissect_ndr_uint32(
1579
0
    tvb, offset, pinfo, subtree, di, drep,
1580
0
    hf_devmode_pels_width, NULL);
1581
1582
0
  offset = dissect_ndr_uint32(
1583
0
    tvb, offset, pinfo, subtree, di, drep,
1584
0
    hf_devmode_pels_height, NULL);
1585
1586
0
  offset = dissect_ndr_uint32(
1587
0
    tvb, offset, pinfo, subtree, di, drep,
1588
0
    hf_devmode_display_flags, NULL);
1589
1590
0
  offset = dissect_ndr_uint32(
1591
0
    tvb, offset, pinfo, subtree, di, drep,
1592
0
    hf_devmode_display_freq, NULL);
1593
1594
  /* TODO: Some of the remaining fields are optional.  See
1595
     rpc_parse/parse_spoolss.c in the Samba source for details. */
1596
1597
0
  offset = dissect_ndr_uint32(
1598
0
    tvb, offset, pinfo, subtree, di, drep,
1599
0
    hf_devmode_icm_method, NULL);
1600
1601
0
  offset = dissect_ndr_uint32(
1602
0
    tvb, offset, pinfo, subtree, di, drep,
1603
0
    hf_devmode_icm_intent, NULL);
1604
1605
0
  offset = dissect_ndr_uint32(
1606
0
    tvb, offset, pinfo, subtree, di, drep,
1607
0
    hf_devmode_media_type, NULL);
1608
1609
0
  offset = dissect_ndr_uint32(
1610
0
    tvb, offset, pinfo, subtree, di, drep,
1611
0
    hf_devmode_dither_type, NULL);
1612
1613
0
  offset = dissect_ndr_uint32(
1614
0
    tvb, offset, pinfo, subtree, di, drep,
1615
0
    hf_devmode_reserved1, NULL);
1616
1617
0
  offset = dissect_ndr_uint32(
1618
0
    tvb, offset, pinfo, subtree, di, drep,
1619
0
    hf_devmode_reserved2, NULL);
1620
1621
0
  offset = dissect_ndr_uint32(
1622
0
    tvb, offset, pinfo, subtree, di, drep,
1623
0
    hf_devmode_panning_width, NULL);
1624
1625
0
  offset = dissect_ndr_uint32(
1626
0
    tvb, offset, pinfo, subtree, di, drep,
1627
0
    hf_devmode_panning_height, NULL);
1628
1629
0
  if (driver_extra)
1630
0
    offset = dissect_ndr_uint8s(
1631
0
      tvb, offset, pinfo, subtree, di, drep,
1632
0
      hf_devmode_driver_extra, driver_extra, NULL);
1633
1634
0
  proto_item_set_len(item, offset - struct_start);
1635
1636
0
  return offset;
1637
0
}
1638
1639
/*
1640
 * DEVMODE_CTR
1641
 */
1642
1643
static int ett_DEVMODE_CTR;
1644
1645
unsigned
1646
dissect_DEVMODE_CTR(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
1647
             proto_tree *tree, dcerpc_info *di, uint8_t *drep)
1648
0
{
1649
0
  proto_tree *subtree;
1650
0
  uint32_t size;
1651
1652
0
  subtree = proto_tree_add_subtree(
1653
0
    tree, tvb, offset, 0, ett_DEVMODE_CTR, NULL, "Devicemode container");
1654
1655
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
1656
0
            hf_devmodectr_size, &size);
1657
1658
0
  offset = dissect_ndr_pointer(
1659
0
    tvb, offset, pinfo, subtree, di, drep,
1660
0
    dissect_DEVMODE, NDR_POINTER_UNIQUE, "Devicemode", -1);
1661
1662
0
  return offset;
1663
0
}
1664
1665
/*
1666
 * Relative string given by offset into the current buffer.  Note that
1667
 * the offset for subsequent relstrs are against the structure start, not
1668
 * the point where the offset is parsed from.
1669
 */
1670
1671
static int ett_RELSTR;
1672
1673
static unsigned
1674
dissect_spoolss_relstr(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
1675
           proto_tree *tree, dcerpc_info *di, uint8_t *drep, int hf_index,
1676
           int struct_start, char **data)
1677
0
{
1678
0
  proto_item *item;
1679
0
  proto_tree *subtree;
1680
0
  uint32_t relstr_offset, relstr_start, relstr_end;
1681
0
  char *text;
1682
1683
  /* Peek ahead to read the string.  We need this for the
1684
     proto_tree_add_string() call so filtering will work. */
1685
1686
0
  offset = dissect_ndr_uint32(
1687
0
    tvb, offset, pinfo, NULL, di, drep, hf_offset, &relstr_offset);
1688
1689
0
  relstr_start = relstr_offset + struct_start;
1690
1691
0
  if (relstr_offset) {
1692
0
    relstr_end = dissect_spoolss_uint16uni(
1693
0
      tvb, relstr_start, pinfo, NULL, drep, &text, hf_relative_string);
1694
0
  } else {       /* relstr_offset == 0 is a NULL string */
1695
0
    text = wmem_strdup(pinfo->pool, "");
1696
0
    relstr_end = relstr_start;
1697
0
  }
1698
1699
  /* OK now add the proto item with the string value */
1700
1701
0
  item = proto_tree_add_string(tree, hf_index, tvb, relstr_start, relstr_end - relstr_start, text);
1702
0
  subtree = proto_item_add_subtree(item, ett_RELSTR);
1703
1704
0
  dissect_ndr_uint32(
1705
0
    tvb, offset - 4, pinfo, subtree, di, drep, hf_offset, NULL);
1706
1707
0
  if (relstr_offset)
1708
0
    dissect_spoolss_uint16uni(
1709
0
      tvb, relstr_start, pinfo, subtree, drep, NULL, hf_relative_string);
1710
1711
0
  if (data)
1712
0
    *data = text;
1713
1714
0
  return offset;
1715
0
}
1716
1717
/* An array of relative strings.  This is currently just a copy of the
1718
   dissect_spoolss_relstr() function as I can't find an example driver that
1719
   has more than one dependent file. */
1720
1721
static int ett_RELSTR_ARRAY;
1722
1723
static unsigned
1724
dissect_spoolss_relstrarray(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
1725
          proto_tree *tree, dcerpc_info *di, uint8_t *drep, int hf_index,
1726
          int struct_start, char **data)
1727
0
{
1728
0
  proto_item *item;
1729
0
  proto_tree *subtree;
1730
0
  uint32_t relstr_offset, relstr_start/*, relstr_end, relstr_len*/;
1731
0
  char *text;
1732
1733
0
  item = proto_tree_add_string(tree, hf_index, tvb, offset, 4, "");
1734
1735
0
  subtree = proto_item_add_subtree(item, ett_RELSTR_ARRAY);
1736
1737
0
  offset = dissect_ndr_uint32(
1738
0
    tvb, offset, pinfo, subtree, di, drep, hf_offset, &relstr_offset);
1739
1740
  /* A relative offset of zero is a NULL string */
1741
1742
0
  relstr_start = relstr_offset + struct_start;
1743
1744
0
  if (relstr_offset)
1745
0
    /*relstr_end = */dissect_spoolss_uint16uni(
1746
0
      tvb, relstr_start, pinfo, subtree, drep, &text, hf_relative_string);
1747
0
  else {
1748
0
    text = wmem_strdup(pinfo->pool, "NULL");
1749
    /*relstr_end = offset;*/
1750
0
  }
1751
1752
  /*relstr_len = relstr_end - relstr_start;*/
1753
1754
0
  proto_item_append_text(item, "%s", text);
1755
1756
0
  if (data)
1757
0
    *data = text;
1758
1759
0
  return offset;
1760
0
}
1761
1762
/*
1763
 * PRINTER_INFO_0
1764
 */
1765
1766
static int hf_printer_status;
1767
1768
static const value_string printer_status_vals[] =
1769
{
1770
  { PRINTER_STATUS_OK, "OK" },
1771
  { PRINTER_STATUS_PAUSED, "Paused" },
1772
  { PRINTER_STATUS_ERROR, "Error" },
1773
  { PRINTER_STATUS_PENDING_DELETION, "Pending deletion" },
1774
  { PRINTER_STATUS_PAPER_JAM, "Paper jam" },
1775
  { PRINTER_STATUS_PAPER_OUT, "Paper out" },
1776
  { PRINTER_STATUS_MANUAL_FEED, "Manual feed" },
1777
  { PRINTER_STATUS_PAPER_PROBLEM, "Paper problem" },
1778
  { PRINTER_STATUS_OFFLINE, "Offline" },
1779
  { PRINTER_STATUS_IO_ACTIVE, "IO active" },
1780
  { PRINTER_STATUS_BUSY, "Busy" },
1781
  { PRINTER_STATUS_PRINTING, "Printing" },
1782
  { PRINTER_STATUS_OUTPUT_BIN_FULL, "Output bin full" },
1783
  { PRINTER_STATUS_NOT_AVAILABLE, "Not available" },
1784
  { PRINTER_STATUS_WAITING, "Waiting" },
1785
  { PRINTER_STATUS_PROCESSING, "Processing" },
1786
  { PRINTER_STATUS_INITIALIZING, "Initialising" },
1787
  { PRINTER_STATUS_WARMING_UP, "Warming up" },
1788
  { PRINTER_STATUS_TONER_LOW, "Toner low" },
1789
  { PRINTER_STATUS_NO_TONER, "No toner" },
1790
  { PRINTER_STATUS_PAGE_PUNT, "Page punt" },
1791
  { PRINTER_STATUS_USER_INTERVENTION, "User intervention" },
1792
  { PRINTER_STATUS_OUT_OF_MEMORY, "Out of memory" },
1793
  { PRINTER_STATUS_DOOR_OPEN, "Door open" },
1794
  { PRINTER_STATUS_SERVER_UNKNOWN, "Server unknown" },
1795
  { PRINTER_STATUS_POWER_SAVE, "Power save" },
1796
  { 0, NULL }
1797
};
1798
static value_string_ext printer_status_vals_ext = VALUE_STRING_EXT_INIT(printer_status_vals);
1799
1800
static int ett_PRINTER_INFO_0;
1801
1802
static unsigned
1803
dissect_PRINTER_INFO_0(tvbuff_t *tvb, unsigned offset,
1804
          packet_info *pinfo, proto_tree *tree,
1805
          dcerpc_info *di, uint8_t *drep)
1806
0
{
1807
0
  offset = dissect_spoolss_relstr(
1808
0
    tvb, offset, pinfo, tree, di, drep, hf_printername,
1809
0
    0, NULL);
1810
1811
0
  offset = dissect_spoolss_relstr(
1812
0
    tvb, offset, pinfo, tree, di, drep, hf_servername,
1813
0
    0, NULL);
1814
1815
0
  offset = dissect_ndr_uint32(
1816
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_cjobs, NULL);
1817
1818
0
  offset = dissect_ndr_uint32(
1819
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_total_jobs,
1820
0
    NULL);
1821
1822
0
  offset = dissect_ndr_uint32(
1823
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_total_bytes,
1824
0
    NULL);
1825
1826
0
  offset = dissect_SYSTEM_TIME(
1827
0
    tvb, offset, pinfo, tree, di, drep, "Unknown time", true, NULL);
1828
1829
0
  offset = dissect_ndr_uint32(
1830
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_global_counter,
1831
0
    NULL);
1832
1833
0
  offset = dissect_ndr_uint32(
1834
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_total_pages,
1835
0
    NULL);
1836
1837
0
  offset = dissect_ndr_uint16(
1838
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_major_version,
1839
0
    NULL);
1840
1841
0
  offset = dissect_ndr_uint16(
1842
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_build_version,
1843
0
    NULL);
1844
1845
0
  offset = dissect_ndr_uint32(
1846
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk7, NULL);
1847
1848
0
  offset = dissect_ndr_uint32(
1849
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk8, NULL);
1850
1851
0
  offset = dissect_ndr_uint32(
1852
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk9, NULL);
1853
1854
0
  offset = dissect_ndr_uint32(
1855
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_session_ctr,
1856
0
    NULL);
1857
1858
0
  offset = dissect_ndr_uint32( tvb, offset, pinfo, tree, di, drep,
1859
0
    hf_printer_unk11, NULL);
1860
1861
0
  offset = dissect_ndr_uint32( tvb, offset, pinfo, tree, di, drep,
1862
0
    hf_printer_printer_errors, NULL);
1863
1864
0
  offset = dissect_ndr_uint32(
1865
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk13, NULL);
1866
1867
0
  offset = dissect_ndr_uint32(
1868
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk14, NULL);
1869
1870
0
  offset = dissect_ndr_uint32(
1871
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk15, NULL);
1872
1873
0
  offset = dissect_ndr_uint32(
1874
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk16, NULL);
1875
1876
0
  offset = dissect_ndr_uint32(
1877
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_changeid, NULL);
1878
1879
0
  offset = dissect_ndr_uint32(
1880
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk18, NULL);
1881
1882
0
  offset = dissect_ndr_uint32(
1883
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_status, NULL);
1884
1885
0
  offset = dissect_ndr_uint32(
1886
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk20, NULL);
1887
1888
0
  offset = dissect_ndr_uint32(
1889
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_c_setprinter,
1890
0
    NULL);
1891
1892
0
  offset = dissect_ndr_uint16(
1893
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk22, NULL);
1894
1895
0
  offset = dissect_ndr_uint16(
1896
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk23, NULL);
1897
1898
0
  offset = dissect_ndr_uint16(
1899
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk24, NULL);
1900
1901
0
  offset = dissect_ndr_uint16(
1902
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk25, NULL);
1903
1904
0
  offset = dissect_ndr_uint16(
1905
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk26, NULL);
1906
1907
0
  offset = dissect_ndr_uint16(
1908
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk27, NULL);
1909
1910
0
  offset = dissect_ndr_uint16(
1911
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk28, NULL);
1912
1913
0
  offset = dissect_ndr_uint16(
1914
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_unk29, NULL);
1915
1916
0
  return offset;
1917
0
}
1918
1919
/*
1920
 * PRINTER_INFO_1
1921
 */
1922
1923
static int ett_PRINTER_INFO_1;
1924
1925
static unsigned
1926
dissect_PRINTER_INFO_1(tvbuff_t *tvb, unsigned offset,
1927
          packet_info *pinfo, proto_tree *tree,
1928
          dcerpc_info *di, uint8_t *drep)
1929
0
{
1930
0
  offset = dissect_ndr_uint32(
1931
0
    tvb, offset, pinfo, tree, di, drep,
1932
0
    hf_printer_flags, NULL);
1933
1934
0
  offset = dissect_spoolss_relstr(
1935
0
    tvb, offset, pinfo, tree, di, drep, hf_printerdesc,
1936
0
    0, NULL);
1937
1938
0
  offset = dissect_spoolss_relstr(
1939
0
    tvb, offset, pinfo, tree, di, drep, hf_printername,
1940
0
    0, NULL);
1941
1942
0
  offset = dissect_spoolss_relstr(
1943
0
    tvb, offset, pinfo, tree, di, drep, hf_printercomment,
1944
0
    0, NULL);
1945
1946
0
  return offset;
1947
0
}
1948
1949
/* Job status */
1950
1951
static const true_false_string tfs_job_status_paused = {
1952
  "Job is paused",
1953
  "Job is not paused"
1954
};
1955
1956
static const true_false_string tfs_job_status_error = {
1957
  "Job has an error",
1958
  "Job is OK"
1959
};
1960
1961
static const true_false_string tfs_job_status_deleting = {
1962
  "Job is being deleted",
1963
  "Job is not being deleted"
1964
};
1965
1966
static const true_false_string tfs_job_status_spooling = {
1967
  "Job is being spooled",
1968
  "Job is not being spooled"
1969
};
1970
1971
static const true_false_string tfs_job_status_printing = {
1972
  "Job is being printed",
1973
  "Job is not being printed"
1974
};
1975
1976
static const true_false_string tfs_job_status_offline = {
1977
  "Job is offline",
1978
  "Job is not offline"
1979
};
1980
1981
static const true_false_string tfs_job_status_paperout = {
1982
  "Job is out of paper",
1983
  "Job is not out of paper"
1984
};
1985
1986
static const true_false_string tfs_job_status_printed = {
1987
  "Job has completed printing",
1988
  "Job has not completed printing"
1989
};
1990
1991
static const true_false_string tfs_job_status_deleted = {
1992
  "Job has been deleted",
1993
  "Job has not been deleted"
1994
};
1995
1996
static const true_false_string tfs_job_status_blocked = {
1997
  "Job has been blocked",
1998
  "Job has not been blocked"
1999
};
2000
2001
static const true_false_string tfs_job_status_user_intervention = {
2002
  "User intervention required",
2003
  "User intervention not required"
2004
};
2005
2006
static int ett_job_status;
2007
2008
static unsigned
2009
dissect_job_status(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
2010
       proto_tree *tree, dcerpc_info *di, uint8_t *drep)
2011
0
{
2012
0
  uint32_t status;
2013
0
  static int * const hf_status[] = {
2014
0
    &hf_job_status_user_intervention,
2015
0
    &hf_job_status_blocked,
2016
0
    &hf_job_status_deleted,
2017
0
    &hf_job_status_printed,
2018
0
    &hf_job_status_paperout,
2019
0
    &hf_job_status_offline,
2020
0
    &hf_job_status_printing,
2021
0
    &hf_job_status_spooling,
2022
0
    &hf_job_status_deleting,
2023
0
    &hf_job_status_error,
2024
0
    &hf_job_status_paused,
2025
0
    NULL
2026
0
  };
2027
2028
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, NULL, di, drep, -1, &status);
2029
2030
0
  proto_tree_add_bitmask_value_with_flags(tree, tvb, offset - 4, hf_job_status,
2031
0
          ett_job_status, hf_status, status, BMT_NO_APPEND);
2032
2033
0
  return offset;
2034
0
}
2035
2036
/* Printer attributes */
2037
2038
static int ett_printer_attributes;
2039
2040
static int hf_printer_attributes;
2041
static int hf_printer_attributes_queued;
2042
static int hf_printer_attributes_direct;
2043
static int hf_printer_attributes_default;
2044
static int hf_printer_attributes_shared;
2045
static int hf_printer_attributes_network;
2046
static int hf_printer_attributes_hidden;
2047
static int hf_printer_attributes_local;
2048
static int hf_printer_attributes_enable_devq;
2049
static int hf_printer_attributes_keep_printed_jobs;
2050
static int hf_printer_attributes_do_complete_first;
2051
static int hf_printer_attributes_work_offline;
2052
static int hf_printer_attributes_enable_bidi;
2053
static int hf_printer_attributes_raw_only;
2054
static int hf_printer_attributes_published;
2055
2056
static const true_false_string tfs_printer_attributes_queued = {
2057
  "The printer starts printing after last page spooled",
2058
  "The printer starts printing while spooling"
2059
};
2060
2061
static const true_false_string tfs_printer_attributes_direct = {
2062
  "Jobs are sent directly to the printer",
2063
  "Jobs are spooled to the printer before printing"
2064
};
2065
2066
static const true_false_string tfs_printer_attributes_default = {
2067
  "The printer is the default printer",
2068
  "The printer is not the default printer"
2069
};
2070
2071
static const true_false_string tfs_printer_attributes_shared = {
2072
  "The printer is shared",
2073
  "The printer is not shared"
2074
};
2075
2076
static const true_false_string tfs_printer_attributes_network = {
2077
  "The printer is a network printer connection",
2078
  "The printer is not a network printer connection"
2079
};
2080
2081
static const true_false_string tfs_printer_attributes_hidden = {
2082
  "The printer is hidden from some users on the network",
2083
  "The printer is not hidden from some users on the network"
2084
};
2085
2086
static const true_false_string tfs_printer_attributes_local = {
2087
  "The printer is a local printer",
2088
  "The printer is not a local printer"
2089
};
2090
2091
static const true_false_string tfs_printer_attributes_enable_devq = {
2092
  "The queue on the printer is enabled if available",
2093
  "The queue on the printer is not enabled",
2094
};
2095
2096
static const true_false_string tfs_printer_attributes_keep_printed_jobs = {
2097
  "Jobs are kept after they are printed",
2098
  "Jobs are deleted after they are printed"
2099
};
2100
2101
static const true_false_string tfs_printer_attributes_do_complete_first = {
2102
  "Jobs that have completed spooling are scheduled before still spooling jobs",
2103
  "Jobs are scheduled in the order they start spooling"
2104
};
2105
2106
static const true_false_string tfs_printer_attributes_work_offline = {
2107
  "The printer is currently connected",
2108
  "The printer is currently not connected"
2109
};
2110
2111
static const true_false_string tfs_printer_attributes_enable_bidi = {
2112
  "Bidirectional communications are supported",
2113
  "Bidirectional communications are not supported"
2114
};
2115
2116
static const true_false_string tfs_printer_attributes_raw_only = {
2117
  "Only raw data type print jobs can be spooled",
2118
  "All data type print jobs can be spooled"
2119
};
2120
2121
static const true_false_string tfs_printer_attributes_published = {
2122
  "The printer is published in the directory",
2123
  "The printer is not published in the directory"
2124
};
2125
2126
static unsigned
2127
dissect_printer_attributes(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
2128
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
2129
0
{
2130
0
  uint32_t attributes;
2131
0
  static int * const hf_attributes[] = {
2132
0
    &hf_printer_attributes_published,
2133
0
    &hf_printer_attributes_raw_only,
2134
0
    &hf_printer_attributes_enable_bidi,
2135
0
    &hf_printer_attributes_work_offline,
2136
0
    &hf_printer_attributes_do_complete_first,
2137
0
    &hf_printer_attributes_keep_printed_jobs,
2138
0
    &hf_printer_attributes_enable_devq,
2139
0
    &hf_printer_attributes_local,
2140
0
    &hf_printer_attributes_hidden,
2141
0
    &hf_printer_attributes_network,
2142
0
    &hf_printer_attributes_shared,
2143
0
    &hf_printer_attributes_default,
2144
0
    &hf_printer_attributes_direct,
2145
0
    &hf_printer_attributes_queued,
2146
0
    NULL
2147
0
  };
2148
2149
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, NULL, di, drep, -1, &attributes);
2150
2151
0
  proto_tree_add_bitmask_value_with_flags(tree, tvb, offset - 4, hf_printer_attributes,
2152
0
          ett_printer_attributes, hf_attributes, attributes, BMT_NO_APPEND);
2153
2154
0
  return offset;
2155
0
}
2156
2157
/* Printer Driver attributes */
2158
2159
static int ett_printer_driver_attributes;
2160
2161
static int hf_printer_driver_attributes;
2162
static int hf_printer_driver_attributes_package_aware;
2163
static int hf_printer_driver_attributes_xps;
2164
static int hf_printer_driver_attributes_sandbox_enabled;
2165
static int hf_printer_driver_attributes_class;
2166
static int hf_printer_driver_attributes_derived;
2167
static int hf_printer_driver_attributes_not_shareable;
2168
static int hf_printer_driver_attributes_category_fax;
2169
static int hf_printer_driver_attributes_category_file;
2170
static int hf_printer_driver_attributes_category_virtual;
2171
static int hf_printer_driver_attributes_category_service;
2172
static int hf_printer_driver_attributes_soft_reset_required;
2173
static int hf_printer_driver_attributes_category_3d;
2174
2175
static const true_false_string tfs_printer_driver_attributes_package_aware = {
2176
  "Printer Driver is package aware",
2177
  "Printer Driver is not package aware"
2178
};
2179
2180
static const true_false_string tfs_printer_driver_attributes_xps = {
2181
  "Printer Driver is XPS based",
2182
  "Printer Driver is not XPS based"
2183
};
2184
2185
static const true_false_string tfs_printer_driver_attributes_sandbox_enabled = {
2186
  "Printer Driver is sandbox enabled",
2187
  "Printer Driver is not sandbox enabled"
2188
};
2189
2190
static const true_false_string tfs_printer_driver_attributes_class = {
2191
  "Printer Driver is a Class Printer Driver",
2192
  "Printer Driver is not a Class Printer Driver"
2193
};
2194
2195
static const true_false_string tfs_printer_driver_attributes_derived = {
2196
  "Printer Driver is a derived Printer Driver",
2197
  "Printer Driver is not a derived Printer Driver"
2198
};
2199
2200
static const true_false_string tfs_printer_driver_attributes_not_shareable = {
2201
  "Printer Driver is a not a sharable Printer Driver",
2202
  "Printer Driver is a shareable Printer Driver"
2203
};
2204
2205
static const true_false_string tfs_printer_driver_attributes_category_fax = {
2206
  "Printer Driver is a Fax Printer Driver",
2207
  "Printer Driver is not a Fax Printer Driver"
2208
};
2209
2210
static const true_false_string tfs_printer_driver_attributes_category_file = {
2211
  "Printer Driver is a File Printer Driver",
2212
  "Printer Driver is not a File Printer Driver"
2213
};
2214
2215
static const true_false_string tfs_printer_driver_attributes_category_virtual = {
2216
  "Printer Driver is a Virtual Printer Driver",
2217
  "Printer Driver is not a Virtual Printer Driver"
2218
};
2219
2220
static const true_false_string tfs_printer_driver_attributes_category_service = {
2221
  "Printer Driver is a Service Printer Driver",
2222
  "Printer Driver is not a Service Printer Driver"
2223
};
2224
2225
static const true_false_string tfs_printer_driver_attributes_soft_reset_required = {
2226
  "Soft reset is required for this Printer Driver",
2227
  "No soft reset is required for this Printer Driver"
2228
};
2229
2230
static const true_false_string tfs_printer_driver_attributes_category_3d = {
2231
  "Printer Driver is a 3D Printer Driver",
2232
  "Printer Driver is not a 3D Printer Driver"
2233
};
2234
2235
static unsigned
2236
dissect_printer_driver_attributes(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
2237
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
2238
0
{
2239
0
  uint32_t attributes;
2240
0
  static int * const hf_attributes[] = {
2241
0
    &hf_printer_driver_attributes_package_aware,
2242
0
    &hf_printer_driver_attributes_xps,
2243
0
    &hf_printer_driver_attributes_sandbox_enabled,
2244
0
    &hf_printer_driver_attributes_class,
2245
0
    &hf_printer_driver_attributes_derived,
2246
0
    &hf_printer_driver_attributes_not_shareable,
2247
0
    &hf_printer_driver_attributes_category_fax,
2248
0
    &hf_printer_driver_attributes_category_file,
2249
0
    &hf_printer_driver_attributes_category_virtual,
2250
0
    &hf_printer_driver_attributes_category_service,
2251
0
    &hf_printer_driver_attributes_soft_reset_required,
2252
0
    &hf_printer_driver_attributes_category_3d,
2253
0
    NULL
2254
0
  };
2255
2256
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, NULL, di, drep, -1, &attributes);
2257
2258
0
  proto_tree_add_bitmask_value_with_flags(tree, tvb, offset - 4, hf_printer_driver_attributes,
2259
0
          ett_printer_driver_attributes, hf_attributes, attributes, BMT_NO_APPEND);
2260
2261
0
  return offset;
2262
0
}
2263
2264
2265
/*
2266
 * PRINTER_INFO_2
2267
 */
2268
2269
static int ett_PRINTER_INFO_2;
2270
2271
static unsigned
2272
dissect_PRINTER_INFO_2(tvbuff_t *tvb, unsigned offset,
2273
          packet_info *pinfo, proto_tree *tree,
2274
          dcerpc_info *di, uint8_t *drep)
2275
0
{
2276
0
  uint32_t devmode_offset, secdesc_offset;
2277
2278
0
  offset = dissect_spoolss_relstr(
2279
0
    tvb, offset, pinfo, tree, di, drep, hf_servername,
2280
0
    0, NULL);
2281
2282
0
  offset = dissect_spoolss_relstr(
2283
0
    tvb, offset, pinfo, tree, di, drep, hf_printername,
2284
0
    0, NULL);
2285
2286
0
  offset = dissect_spoolss_relstr(
2287
0
    tvb, offset, pinfo, tree, di, drep, hf_sharename,
2288
0
    0, NULL);
2289
2290
0
  offset = dissect_spoolss_relstr(
2291
0
    tvb, offset, pinfo, tree, di, drep, hf_portname,
2292
0
    0, NULL);
2293
2294
0
  offset = dissect_spoolss_relstr(
2295
0
    tvb, offset, pinfo, tree, di, drep, hf_drivername,
2296
0
    0, NULL);
2297
2298
0
  offset = dissect_spoolss_relstr(
2299
0
    tvb, offset, pinfo, tree, di, drep, hf_printercomment,
2300
0
    0, NULL);
2301
2302
0
  offset = dissect_spoolss_relstr(
2303
0
    tvb, offset, pinfo, tree, di, drep, hf_printerlocation,
2304
0
    0, NULL);
2305
2306
0
  offset = dissect_ndr_uint32(
2307
0
    tvb, offset, pinfo, NULL, di, drep, hf_offset,
2308
0
    &devmode_offset);
2309
2310
  // This is the offset *after* the uint32 containing the DeviceMode
2311
  // size, so it cannot be less than 4.
2312
0
  if (devmode_offset < 4) {
2313
0
    THROW(ReportedBoundsError);
2314
0
  }
2315
2316
0
  dissect_DEVMODE(tvb, devmode_offset - 4, pinfo, tree, di, drep);
2317
2318
0
  offset = dissect_spoolss_relstr(
2319
0
    tvb, offset, pinfo, tree, di, drep, hf_sepfile,
2320
0
    0, NULL);
2321
2322
0
  offset = dissect_spoolss_relstr(
2323
0
    tvb, offset, pinfo, tree, di, drep, hf_printprocessor,
2324
0
    0, NULL);
2325
2326
0
  offset = dissect_spoolss_relstr(
2327
0
    tvb, offset, pinfo, tree, di, drep, hf_datatype,
2328
0
    0, NULL);
2329
2330
0
  offset = dissect_spoolss_relstr(
2331
0
    tvb, offset, pinfo, tree, di, drep, hf_parameters,
2332
0
    0, NULL);
2333
2334
  /*
2335
   * XXX - what *is* the length of this security descriptor?
2336
   * "prs_PRINTER_INFO_2()" is passed to "defer_ptr()", but
2337
   * "defer_ptr" takes, as an argument, a function with a
2338
   * different calling sequence from "prs_PRINTER_INFO_2()",
2339
   * lacking the "len" argument, so that won't work.
2340
   */
2341
2342
0
  offset = dissect_ndr_uint32(
2343
0
    tvb, offset, pinfo, NULL, di, drep, hf_offset,
2344
0
    &secdesc_offset);
2345
2346
0
  dissect_nt_sec_desc(
2347
0
    tvb, secdesc_offset, pinfo, tree, drep,
2348
0
    false, -1,
2349
0
    &spoolss_printer_access_mask_info);
2350
2351
0
  offset = dissect_printer_attributes(tvb, offset, pinfo, tree, di, drep);
2352
2353
0
  offset = dissect_ndr_uint32(
2354
0
    tvb, offset, pinfo, NULL, di, drep, hf_printer_priority,
2355
0
    NULL);
2356
2357
0
  offset = dissect_ndr_uint32(
2358
0
    tvb, offset, pinfo, NULL, di, drep,
2359
0
    hf_printer_default_priority, NULL);
2360
2361
0
  offset = dissect_ndr_uint32(
2362
0
    tvb, offset, pinfo, NULL, di, drep, hf_start_time, NULL);
2363
2364
0
  offset = dissect_ndr_uint32(
2365
0
    tvb, offset, pinfo, NULL, di, drep, hf_end_time, NULL);
2366
2367
0
  offset = dissect_ndr_uint32(
2368
0
    tvb, offset, pinfo, tree, di, drep,
2369
0
    hf_printer_status, NULL);
2370
2371
0
  offset = dissect_ndr_uint32(
2372
0
    tvb, offset, pinfo, NULL, di, drep, hf_printer_jobs,
2373
0
    NULL);
2374
2375
0
  offset = dissect_ndr_uint32(
2376
0
    tvb, offset, pinfo, NULL, di, drep,
2377
0
    hf_printer_averageppm, NULL);
2378
2379
0
  return offset;
2380
0
}
2381
2382
/*
2383
 * PRINTER_INFO_3
2384
 */
2385
2386
static int ett_PRINTER_INFO_3;
2387
2388
static unsigned
2389
dissect_PRINTER_INFO_3(tvbuff_t *tvb, unsigned offset,
2390
          packet_info *pinfo, proto_tree *tree,
2391
          dcerpc_info *di, uint8_t *drep)
2392
0
{
2393
0
  offset = dissect_ndr_uint32(
2394
0
    tvb, offset, pinfo, tree, di, drep,
2395
0
    hf_printer_flags, NULL);
2396
2397
0
  offset = dissect_nt_sec_desc(
2398
0
    tvb, offset, pinfo, tree, drep,
2399
0
    false, -1,
2400
0
    &spoolss_printer_access_mask_info);
2401
2402
0
  return offset;
2403
0
}
2404
2405
/*
2406
 * PRINTER_INFO_5
2407
 */
2408
2409
static int ett_PRINTER_INFO_5;
2410
2411
static unsigned
2412
dissect_PRINTER_INFO_5(tvbuff_t *tvb, unsigned offset,
2413
          packet_info *pinfo, proto_tree *tree,
2414
          dcerpc_info *di, uint8_t *drep)
2415
0
{
2416
0
  offset = dissect_spoolss_relstr(
2417
0
    tvb, offset, pinfo, tree, di, drep, hf_printername,
2418
0
    0, NULL);
2419
2420
0
  offset = dissect_spoolss_relstr(
2421
0
    tvb, offset, pinfo, tree, di, drep, hf_portname,
2422
0
    0, NULL);
2423
2424
0
  offset = dissect_printer_attributes(tvb, offset, pinfo, tree, di, drep);
2425
2426
0
  offset = dissect_ndr_uint32(
2427
0
    tvb, offset, pinfo, tree, di, drep,
2428
0
    hf_device_not_selected_timeout, NULL);
2429
2430
0
  offset = dissect_ndr_uint32(
2431
0
    tvb, offset, pinfo, tree, di, drep,
2432
0
    hf_transmission_retry_timeout, NULL);
2433
2434
0
  return offset;
2435
0
}
2436
2437
2438
/*
2439
 * PRINTER_INFO_7
2440
 */
2441
2442
static int ett_PRINTER_INFO_7;
2443
2444
static const value_string getprinter_action_vals[] = {
2445
  { DS_PUBLISH, "Publish" },
2446
  { DS_UNPUBLISH, "Unpublish" },
2447
  { DS_UPDATE, "Update" },
2448
  { DS_PENDING, "Pending" },
2449
  { DS_REPUBLISH, "Republish" },
2450
  { 0, NULL }
2451
};
2452
2453
static unsigned
2454
dissect_PRINTER_INFO_7(tvbuff_t *tvb, unsigned offset,
2455
          packet_info *pinfo, proto_tree *tree,
2456
          dcerpc_info *di, uint8_t *drep)
2457
0
{
2458
0
  offset = dissect_spoolss_relstr(
2459
0
    tvb, offset, pinfo, tree, di, drep, hf_printer_guid,
2460
0
    0, NULL);
2461
2462
0
  offset = dissect_ndr_uint32(
2463
0
    tvb, offset, pinfo, tree, di, drep,
2464
0
    hf_printer_action, NULL);
2465
2466
0
  return offset;
2467
0
}
2468
2469
/*
2470
 * PRINTER_DATATYPE structure
2471
 */
2472
2473
static int ett_PRINTER_DATATYPE;
2474
2475
static unsigned
2476
dissect_PRINTER_DATATYPE(tvbuff_t *tvb, unsigned offset,
2477
            packet_info *pinfo, proto_tree *tree,
2478
            dcerpc_info *di, uint8_t *drep)
2479
0
{
2480
0
  if (di->conformant_run)
2481
0
    return offset;
2482
2483
0
  offset = dissect_ndr_cvstring(
2484
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
2485
0
    hf_datatype, true, NULL);
2486
2487
0
  return offset;
2488
0
}
2489
2490
/*
2491
 * USER_LEVEL_1 structure
2492
 */
2493
2494
static int ett_USER_LEVEL_1;
2495
2496
static int hf_userlevel_size;
2497
static int hf_userlevel_client;
2498
static int hf_userlevel_user;
2499
static int hf_userlevel_build;
2500
static int hf_userlevel_major;
2501
static int hf_userlevel_minor;
2502
static int hf_userlevel_processor;
2503
2504
static unsigned
2505
dissect_USER_LEVEL_1(tvbuff_t *tvb, unsigned offset,
2506
        packet_info *pinfo, proto_tree *tree,
2507
        dcerpc_info *di, uint8_t *drep)
2508
0
{
2509
0
  uint32_t level;
2510
2511
  /* Guy has pointed out that this dissection looks wrong.  In
2512
     the wireshark output for a USER_LEVEL_1 it looks like the
2513
     info level and container pointer are transposed.  I'm not
2514
     even sure this structure is a container. */
2515
2516
0
  offset = dissect_ndr_uint32(
2517
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
2518
2519
0
  offset = dissect_ndr_uint32(
2520
0
    tvb, offset, pinfo, tree, di, drep, hf_userlevel_size, NULL);
2521
2522
0
  offset = dissect_ndr_str_pointer_item(
2523
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
2524
0
    "Client", hf_userlevel_client, 0);
2525
2526
0
  offset = dissect_ndr_str_pointer_item(
2527
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
2528
0
    "User", hf_userlevel_user, 0);
2529
2530
0
  offset = dissect_ndr_uint32(
2531
0
    tvb, offset, pinfo, tree, di, drep, hf_userlevel_build, NULL);
2532
2533
0
  offset = dissect_ndr_uint32(
2534
0
    tvb, offset, pinfo, tree, di, drep, hf_userlevel_major, NULL);
2535
2536
0
  offset = dissect_ndr_uint32(
2537
0
    tvb, offset, pinfo, tree, di, drep, hf_userlevel_minor, NULL);
2538
2539
0
  offset = dissect_ndr_uint32(
2540
0
    tvb, offset, pinfo, tree, di, drep, hf_userlevel_processor, NULL);
2541
2542
0
  return offset;
2543
0
}
2544
2545
/*
2546
 * USER_LEVEL_CTR structure
2547
 */
2548
2549
static int ett_USER_LEVEL_CTR;
2550
2551
unsigned
2552
dissect_USER_LEVEL_CTR(tvbuff_t *tvb, unsigned offset,
2553
          packet_info *pinfo, proto_tree *tree,
2554
          dcerpc_info *di, uint8_t *drep)
2555
0
{
2556
0
  proto_tree *subtree;
2557
0
  proto_item *item;
2558
0
  uint32_t level;
2559
2560
0
  if (di->conformant_run)
2561
0
    return offset;
2562
2563
0
  subtree = proto_tree_add_subtree(
2564
0
    tree, tvb, offset, 0, ett_USER_LEVEL_CTR, &item, "User level container");
2565
2566
0
  offset = dissect_ndr_uint32(
2567
0
    tvb, offset, pinfo, subtree, di, drep, hf_level, &level);
2568
2569
0
  switch(level) {
2570
0
  case 1:
2571
0
    offset = dissect_ndr_pointer(
2572
0
      tvb, offset, pinfo, subtree, di, drep,
2573
0
      dissect_USER_LEVEL_1, NDR_POINTER_UNIQUE,
2574
0
      "User level 1", -1);
2575
0
    break;
2576
0
  default:
2577
0
    expert_add_info_format(pinfo, item, &ei_level, "Info level %d not decoded", level);
2578
0
    break;
2579
0
  }
2580
2581
0
  return offset;
2582
0
}
2583
2584
/*
2585
 * SpoolssOpenPrinterEx
2586
 */
2587
2588
static unsigned
2589
SpoolssOpenPrinterEx_q(tvbuff_t *tvb, unsigned offset,
2590
          packet_info *pinfo, proto_tree *tree,
2591
          dcerpc_info *di, uint8_t *drep)
2592
0
{
2593
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
2594
0
  char *name;
2595
2596
  /* Parse packet */
2597
2598
0
  dcv->private_data=NULL;
2599
0
  offset = dissect_ndr_pointer_cb(
2600
0
    tvb, offset, pinfo, tree, di, drep,
2601
0
    dissect_ndr_wchar_cvstring, NDR_POINTER_UNIQUE,
2602
0
    "Printer name", hf_printername, cb_wstr_postprocess,
2603
0
    GINT_TO_POINTER(CB_STR_COL_INFO | CB_STR_SAVE | 1));
2604
0
  name = (char *)dcv->private_data;
2605
2606
  /* OpenPrinterEx() stores the key/value in se_data */
2607
0
  if(!pinfo->fd->visited){
2608
0
    if(!dcv->se_data){
2609
0
      dcv->se_data = wmem_strdup(wmem_file_scope(),
2610
0
        name?name:"");
2611
0
    }
2612
0
  }
2613
2614
0
  offset = dissect_ndr_pointer(
2615
0
    tvb, offset, pinfo, tree, di, drep,
2616
0
    dissect_PRINTER_DATATYPE, NDR_POINTER_UNIQUE,
2617
0
    "Printer datatype", -1);
2618
2619
0
  offset = dissect_DEVMODE_CTR(tvb, offset, pinfo, tree, di, drep);
2620
2621
0
  name=(char *)dcv->se_data;
2622
0
  if (name) {
2623
0
    if (name[0] == '\\' && name[1] == '\\')
2624
0
      name += 2;
2625
2626
    /* Determine if we are opening a printer or a print server */
2627
2628
0
    if (strchr(name, '\\'))
2629
0
      offset = dissect_nt_access_mask(
2630
0
        tvb, offset, pinfo, tree, di, drep,
2631
0
        hf_access_required,
2632
0
        &spoolss_printer_access_mask_info, NULL);
2633
0
    else
2634
0
      offset = dissect_nt_access_mask(
2635
0
        tvb, offset, pinfo, tree, di, drep,
2636
0
        hf_access_required,
2637
0
        &spoolss_printserver_access_mask_info, NULL);
2638
0
  } else {
2639
2640
    /* We can't decide what type of object being opened */
2641
2642
0
    offset = dissect_nt_access_mask(
2643
0
      tvb, offset, pinfo, tree, di, drep, hf_access_required,
2644
0
      NULL, NULL);
2645
0
  }
2646
2647
0
  offset = dissect_USER_LEVEL_CTR(tvb, offset, pinfo, tree, di, drep);
2648
2649
0
  return offset;
2650
0
}
2651
2652
static unsigned
2653
SpoolssOpenPrinterEx_r(tvbuff_t *tvb, unsigned offset,
2654
          packet_info *pinfo, proto_tree *tree,
2655
          dcerpc_info *di, uint8_t *drep)
2656
0
{
2657
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
2658
0
  e_ctx_hnd policy_hnd;
2659
0
  proto_item *hnd_item;
2660
0
  uint32_t status;
2661
2662
  /* Parse packet */
2663
2664
0
  offset = dissect_nt_policy_hnd(
2665
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, &hnd_item,
2666
0
    PIDL_POLHND_OPEN);
2667
2668
0
  offset = dissect_doserror(
2669
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, &status);
2670
2671
0
  if( status == 0 ){
2672
0
    const char *pol_name;
2673
2674
0
    if (dcv->se_data){
2675
0
      pol_name = wmem_strdup_printf(pinfo->pool,
2676
0
        "OpenPrinterEx(%s)", (char *)dcv->se_data);
2677
0
    } else {
2678
0
      pol_name = "Unknown OpenPrinterEx() handle";
2679
0
    }
2680
0
    if(!pinfo->fd->visited){
2681
0
      dcerpc_store_polhnd_name(&policy_hnd, pinfo, pol_name);
2682
0
    }
2683
2684
0
    if(hnd_item)
2685
0
      proto_item_append_text(hnd_item, ": %s", pol_name);
2686
0
  }
2687
2688
0
  return offset;
2689
0
}
2690
2691
static const value_string printer_notify_option_data_vals[] = {
2692
  { PRINTER_NOTIFY_SERVER_NAME, "Server name" },
2693
  { PRINTER_NOTIFY_PRINTER_NAME, "Printer name" },
2694
  { PRINTER_NOTIFY_SHARE_NAME, "Share name" },
2695
  { PRINTER_NOTIFY_PORT_NAME, "Port name" },
2696
  { PRINTER_NOTIFY_DRIVER_NAME, "Driver name" },
2697
  { PRINTER_NOTIFY_COMMENT, "Comment" },
2698
  { PRINTER_NOTIFY_LOCATION, "Location" },
2699
  { PRINTER_NOTIFY_DEVMODE, "Devmode" },
2700
  { PRINTER_NOTIFY_SEPFILE, "Sepfile" },
2701
  { PRINTER_NOTIFY_PRINT_PROCESSOR, "Print processor" },
2702
  { PRINTER_NOTIFY_PARAMETERS, "Parameters" },
2703
  { PRINTER_NOTIFY_DATATYPE, "Datatype" },
2704
  { PRINTER_NOTIFY_SECURITY_DESCRIPTOR, "Security descriptor" },
2705
  { PRINTER_NOTIFY_ATTRIBUTES, "Attributes" },
2706
  { PRINTER_NOTIFY_PRIORITY, "Priority" },
2707
  { PRINTER_NOTIFY_DEFAULT_PRIORITY, "Default priority" },
2708
  { PRINTER_NOTIFY_START_TIME, "Start time" },
2709
  { PRINTER_NOTIFY_UNTIL_TIME, "Until time" },
2710
  { PRINTER_NOTIFY_STATUS, "Status" },
2711
  { PRINTER_NOTIFY_STATUS_STRING, "Status string" },
2712
  { PRINTER_NOTIFY_CJOBS, "Cjobs" },
2713
  { PRINTER_NOTIFY_AVERAGE_PPM, "Average PPM" },
2714
  { PRINTER_NOTIFY_TOTAL_PAGES, "Total pages" },
2715
  { PRINTER_NOTIFY_PAGES_PRINTED, "Pages printed" },
2716
  { PRINTER_NOTIFY_TOTAL_BYTES, "Total bytes" },
2717
  { PRINTER_NOTIFY_BYTES_PRINTED, "Bytes printed" },
2718
  { 0, NULL}
2719
};
2720
static value_string_ext printer_notify_option_data_vals_ext = VALUE_STRING_EXT_INIT(printer_notify_option_data_vals);
2721
2722
static const value_string job_notify_option_data_vals[] = {
2723
  { JOB_NOTIFY_PRINTER_NAME, "Printer name" },
2724
  { JOB_NOTIFY_MACHINE_NAME, "Machine name" },
2725
  { JOB_NOTIFY_PORT_NAME, "Port name" },
2726
  { JOB_NOTIFY_USER_NAME, "User name" },
2727
  { JOB_NOTIFY_NOTIFY_NAME, "Notify name" },
2728
  { JOB_NOTIFY_DATATYPE, "Data type" },
2729
  { JOB_NOTIFY_PRINT_PROCESSOR, "Print processor" },
2730
  { JOB_NOTIFY_PARAMETERS, "Parameters" },
2731
  { JOB_NOTIFY_DRIVER_NAME, "Driver name" },
2732
  { JOB_NOTIFY_DEVMODE, "Devmode" },
2733
  { JOB_NOTIFY_STATUS, "Status" },
2734
  { JOB_NOTIFY_STATUS_STRING, "Status string" },
2735
  { JOB_NOTIFY_SECURITY_DESCRIPTOR, "Security descriptor" },
2736
  { JOB_NOTIFY_DOCUMENT, "Document" },
2737
  { JOB_NOTIFY_PRIORITY, "Priority" },
2738
  { JOB_NOTIFY_POSITION, "Position" },
2739
  { JOB_NOTIFY_SUBMITTED, "Submitted" },
2740
  { JOB_NOTIFY_START_TIME, "Start time" },
2741
  { JOB_NOTIFY_UNTIL_TIME, "Until time" },
2742
  { JOB_NOTIFY_TIME, "Time" },
2743
  { JOB_NOTIFY_TOTAL_PAGES, "Total pages" },
2744
  { JOB_NOTIFY_PAGES_PRINTED, "Pages printed" },
2745
  { JOB_NOTIFY_TOTAL_BYTES, "Total bytes" },
2746
  { JOB_NOTIFY_BYTES_PRINTED, "Bytes printed" },
2747
  { 0, NULL}
2748
};
2749
static value_string_ext job_notify_option_data_vals_ext = VALUE_STRING_EXT_INIT(job_notify_option_data_vals);
2750
2751
static unsigned
2752
dissect_notify_field(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
2753
         proto_tree *tree, dcerpc_info *di, uint8_t *drep, uint16_t type,
2754
         uint16_t *data)
2755
0
{
2756
0
  uint16_t field;
2757
0
  const char *str;
2758
2759
0
  offset = dissect_ndr_uint16(
2760
0
    tvb, offset, pinfo, NULL, di, drep,
2761
0
    hf_notify_field, &field);
2762
2763
0
  switch(type) {
2764
0
  case PRINTER_NOTIFY_TYPE:
2765
0
    str = val_to_str_ext_const(field, &printer_notify_option_data_vals_ext,
2766
0
         "Unknown");
2767
0
    break;
2768
0
  case JOB_NOTIFY_TYPE:
2769
0
    str = val_to_str_ext_const(field, &job_notify_option_data_vals_ext,
2770
0
         "Unknown");
2771
0
    break;
2772
0
  default:
2773
0
    str = "Unknown notify type";
2774
0
    break;
2775
0
  }
2776
2777
0
  proto_tree_add_uint_format_value(tree, hf_notify_field, tvb, offset - 2, 2, field, "%s (%d)", str, field);
2778
2779
0
  if (data)
2780
0
    *data = field;
2781
2782
0
  return offset;
2783
0
}
2784
2785
static unsigned
2786
dissect_NOTIFY_OPTION_DATA(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
2787
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
2788
0
{
2789
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
2790
0
  uint32_t count, i;
2791
0
  uint16_t type;
2792
2793
0
  if (di->conformant_run)
2794
0
    return offset;
2795
2796
0
  offset = dissect_ndr_uint32(
2797
0
    tvb, offset, pinfo, tree, di, drep,
2798
0
    hf_notify_option_data_count, &count);
2799
2800
0
  type = GPOINTER_TO_INT(dcv->private_data);
2801
2802
0
  for (i = 0; i < count; i++)
2803
0
    offset = dissect_notify_field(
2804
0
      tvb, offset, pinfo, tree, di, drep, type, NULL);
2805
2806
0
  return offset;
2807
0
}
2808
2809
static const value_string printer_notify_types[] =
2810
{
2811
  { PRINTER_NOTIFY_TYPE, "Printer notify" },
2812
  { JOB_NOTIFY_TYPE, "Job notify" },
2813
  { 0, NULL }
2814
};
2815
2816
static const
2817
char *notify_plural(int count)
2818
0
{
2819
0
  if (count == 1)
2820
0
    return "notification";
2821
2822
0
  return "notifies";
2823
0
}
2824
2825
static int ett_NOTIFY_OPTION;
2826
2827
static unsigned
2828
dissect_NOTIFY_OPTION(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
2829
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
2830
0
{
2831
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
2832
0
  proto_item *item;
2833
0
  proto_tree *subtree;
2834
0
  uint16_t type;
2835
0
  uint32_t count;
2836
2837
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_NOTIFY_OPTION, &item, "Notify Option");
2838
2839
0
  offset = dissect_ndr_uint16(tvb, offset, pinfo, subtree, di, drep,
2840
0
            hf_notify_option_type, &type);
2841
2842
0
  proto_item_append_text(
2843
0
    item, ": %s", val_to_str(pinfo->pool, type, printer_notify_types,
2844
0
           "Unknown (%d)"));
2845
2846
0
  offset = dissect_ndr_uint16(tvb, offset, pinfo, subtree, di, drep,
2847
0
            hf_notify_option_reserved1, NULL);
2848
2849
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
2850
0
            hf_notify_option_reserved2, NULL);
2851
2852
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
2853
0
            hf_notify_option_reserved3, NULL);
2854
2855
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
2856
0
            hf_notify_option_count, &count);
2857
2858
0
  proto_item_append_text(
2859
0
    item, ", %d %s", count, notify_plural(count));
2860
2861
0
  dcv->private_data = GINT_TO_POINTER((int)type);
2862
2863
0
  offset = dissect_ndr_pointer(
2864
0
    tvb, offset, pinfo, subtree, di, drep,
2865
0
    dissect_NOTIFY_OPTION_DATA, NDR_POINTER_UNIQUE,
2866
0
    "Notify Option Data", -1);
2867
2868
0
  return offset;
2869
0
}
2870
2871
static unsigned
2872
dissect_NOTIFY_OPTIONS_ARRAY(tvbuff_t *tvb, unsigned offset,
2873
           packet_info *pinfo, proto_tree *tree,
2874
           dcerpc_info *di, uint8_t *drep)
2875
0
{
2876
  /* Why is a check for di->conformant_run not required here? */
2877
2878
0
  offset = dissect_ndr_ucarray(
2879
0
    tvb, offset, pinfo, tree, di, drep, dissect_NOTIFY_OPTION);
2880
2881
0
  return offset;
2882
0
}
2883
2884
static int ett_notify_options_flags;
2885
2886
static const true_false_string tfs_notify_options_flags_refresh = {
2887
  "Data for all monitored fields is present",
2888
  "Data for all monitored fields not present"
2889
};
2890
2891
static unsigned
2892
dissect_notify_options_flags(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
2893
           proto_tree *tree, dcerpc_info *di, uint8_t *drep)
2894
0
{
2895
0
  uint32_t flags;
2896
0
  static int * const hf_flags[] = {
2897
0
    &hf_notify_options_flags_refresh,
2898
0
    NULL
2899
0
  };
2900
2901
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, NULL, di, drep, -1, &flags);
2902
2903
0
  proto_tree_add_bitmask_value_with_flags(tree, tvb, offset - 4, hf_notify_options_flags,
2904
0
          ett_notify_options_flags, hf_flags, flags, BMT_NO_APPEND);
2905
2906
0
  return offset;
2907
0
}
2908
2909
unsigned
2910
dissect_NOTIFY_OPTIONS_ARRAY_CTR(tvbuff_t *tvb, unsigned offset,
2911
         packet_info *pinfo, proto_tree *tree,
2912
         dcerpc_info *di, uint8_t *drep)
2913
0
{
2914
0
  if (di->conformant_run)
2915
0
    return offset;
2916
2917
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
2918
0
            hf_notify_options_version, NULL);
2919
2920
0
  offset = dissect_notify_options_flags(tvb, offset, pinfo, tree, di, drep);
2921
2922
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
2923
0
            hf_notify_options_count, NULL);
2924
2925
0
  offset = dissect_ndr_pointer(
2926
0
    tvb, offset, pinfo, tree, di, drep,
2927
0
    dissect_NOTIFY_OPTIONS_ARRAY, NDR_POINTER_UNIQUE,
2928
0
    "Notify Options Array", -1);
2929
2930
0
  return offset;
2931
0
}
2932
2933
/*
2934
 * SpoolssRFFPCNEX
2935
 */
2936
2937
static int ett_rffpcnex_flags;
2938
2939
static int hf_rffpcnex_flags;
2940
static int hf_rffpcnex_options;
2941
2942
static int hf_rffpcnex_flags_add_printer;
2943
static int hf_rffpcnex_flags_set_printer;
2944
static int hf_rffpcnex_flags_delete_printer;
2945
static int hf_rffpcnex_flags_failed_printer_connection;
2946
2947
static const true_false_string tfs_rffpcnex_flags_add_printer = {
2948
  "Notify on add printer",
2949
  "Don't notify on add printer"
2950
};
2951
2952
static const true_false_string tfs_rffpcnex_flags_set_printer = {
2953
  "Notify on set printer",
2954
  "Don't notify on set printer"
2955
};
2956
2957
static const true_false_string tfs_rffpcnex_flags_delete_printer = {
2958
  "Notify on delete printer",
2959
  "Don't notify on delete printer"
2960
};
2961
2962
static const true_false_string tfs_rffpcnex_flags_failed_connection_printer = {
2963
  "Notify on failed printer connection",
2964
  "Don't notify on failed printer connection"
2965
};
2966
2967
static int hf_rffpcnex_flags_add_job;
2968
static int hf_rffpcnex_flags_set_job;
2969
static int hf_rffpcnex_flags_delete_job;
2970
static int hf_rffpcnex_flags_write_job;
2971
2972
static const true_false_string tfs_rffpcnex_flags_add_job = {
2973
  "Notify on add job",
2974
  "Don't notify on add job"
2975
};
2976
2977
static const true_false_string tfs_rffpcnex_flags_set_job = {
2978
  "Notify on set job",
2979
  "Don't notify on set job"
2980
};
2981
2982
static const true_false_string tfs_rffpcnex_flags_delete_job = {
2983
  "Notify on delete job",
2984
  "Don't notify on delete job"
2985
};
2986
2987
static const true_false_string tfs_rffpcnex_flags_write_job = {
2988
  "Notify on writejob",
2989
  "Don't notify on write job"
2990
};
2991
2992
static int hf_rffpcnex_flags_add_form;
2993
static int hf_rffpcnex_flags_set_form;
2994
static int hf_rffpcnex_flags_delete_form;
2995
2996
static const true_false_string tfs_rffpcnex_flags_add_form = {
2997
  "Notify on add form",
2998
  "Don't notify on add form"
2999
};
3000
3001
static const true_false_string tfs_rffpcnex_flags_set_form = {
3002
  "Notify on set form",
3003
  "Don't notify on set form"
3004
};
3005
3006
static const true_false_string tfs_rffpcnex_flags_delete_form = {
3007
  "Notify on delete form",
3008
  "Don't notify on delete form"
3009
};
3010
3011
static int hf_rffpcnex_flags_add_port;
3012
static int hf_rffpcnex_flags_configure_port;
3013
static int hf_rffpcnex_flags_delete_port;
3014
3015
static const true_false_string tfs_rffpcnex_flags_add_port = {
3016
  "Notify on add port",
3017
  "Don't notify on add port"
3018
};
3019
3020
static const true_false_string tfs_rffpcnex_flags_configure_port = {
3021
  "Notify on configure port",
3022
  "Don't notify on configure port"
3023
};
3024
3025
static const true_false_string tfs_rffpcnex_flags_delete_port = {
3026
  "Notify on delete port",
3027
  "Don't notify on delete port"
3028
};
3029
3030
static int hf_rffpcnex_flags_add_print_processor;
3031
static int hf_rffpcnex_flags_delete_print_processor;
3032
3033
static const true_false_string tfs_rffpcnex_flags_add_print_processor = {
3034
  "Notify on add driver",
3035
  "Don't notify on add driver"
3036
};
3037
3038
static const true_false_string tfs_rffpcnex_flags_delete_print_processor = {
3039
  "Notify on add driver",
3040
  "Don't notify on add driver"
3041
};
3042
3043
static int hf_rffpcnex_flags_add_driver;
3044
static int hf_rffpcnex_flags_set_driver;
3045
static int hf_rffpcnex_flags_delete_driver;
3046
3047
static const true_false_string tfs_rffpcnex_flags_add_driver = {
3048
  "Notify on add driver",
3049
  "Don't notify on add driver"
3050
};
3051
3052
static const true_false_string tfs_rffpcnex_flags_set_driver = {
3053
  "Notify on set driver",
3054
  "Don't notify on set driver"
3055
};
3056
3057
static const true_false_string tfs_rffpcnex_flags_delete_driver = {
3058
  "Notify on delete driver",
3059
  "Don't notify on delete driver"
3060
};
3061
3062
static int hf_rffpcnex_flags_timeout;
3063
3064
static const true_false_string tfs_rffpcnex_flags_timeout = {
3065
  "Notify on timeout",
3066
  "Don't notify on timeout"
3067
};
3068
3069
static unsigned
3070
SpoolssRFFPCNEX_q(tvbuff_t *tvb, unsigned offset,
3071
           packet_info *pinfo, proto_tree *tree,
3072
           dcerpc_info *di, uint8_t *drep)
3073
0
{
3074
0
  uint32_t flags;
3075
0
  static int * const hf_flags[] = {
3076
0
    &hf_rffpcnex_flags_timeout,
3077
0
    &hf_rffpcnex_flags_delete_driver,
3078
0
    &hf_rffpcnex_flags_set_driver,
3079
0
    &hf_rffpcnex_flags_add_driver,
3080
0
    &hf_rffpcnex_flags_delete_print_processor,
3081
0
    &hf_rffpcnex_flags_add_print_processor,
3082
0
    &hf_rffpcnex_flags_delete_port,
3083
0
    &hf_rffpcnex_flags_configure_port,
3084
0
    &hf_rffpcnex_flags_add_port,
3085
0
    &hf_rffpcnex_flags_delete_form,
3086
0
    &hf_rffpcnex_flags_set_form,
3087
0
    &hf_rffpcnex_flags_add_form,
3088
0
    &hf_rffpcnex_flags_write_job,
3089
0
    &hf_rffpcnex_flags_delete_job,
3090
0
    &hf_rffpcnex_flags_set_job,
3091
0
    &hf_rffpcnex_flags_add_job,
3092
0
    &hf_rffpcnex_flags_failed_printer_connection,
3093
0
    &hf_rffpcnex_flags_delete_printer,
3094
0
    &hf_rffpcnex_flags_set_printer,
3095
0
    &hf_rffpcnex_flags_add_printer,
3096
0
    NULL
3097
0
  };
3098
3099
  /* Parse packet */
3100
3101
0
  offset = dissect_nt_policy_hnd(
3102
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
3103
0
    PIDL_POLHND_USE);
3104
3105
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, NULL, di, drep, -1, &flags);
3106
3107
0
  proto_tree_add_bitmask_value(tree, tvb, offset - 4, hf_rffpcnex_flags,
3108
0
          ett_rffpcnex_flags, hf_flags, flags);
3109
3110
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
3111
0
            hf_rffpcnex_options, NULL);
3112
3113
0
  offset = dissect_ndr_str_pointer_item(
3114
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
3115
0
    "Server", hf_servername, 0);
3116
3117
0
  offset = dissect_ndr_uint32(
3118
0
    tvb, offset, pinfo, tree, di, drep, hf_printerlocal, NULL);
3119
3120
0
  offset = dissect_ndr_pointer(
3121
0
    tvb, offset, pinfo, tree, di, drep,
3122
0
    dissect_NOTIFY_OPTIONS_ARRAY_CTR, NDR_POINTER_UNIQUE,
3123
0
    "Notify Options Container", -1);
3124
3125
0
  return offset;
3126
0
}
3127
3128
static unsigned
3129
SpoolssRFFPCNEX_r(tvbuff_t *tvb, unsigned offset,
3130
           packet_info *pinfo, proto_tree *tree,
3131
           dcerpc_info *di, uint8_t *drep)
3132
0
{
3133
  /* Parse packet */
3134
3135
0
  offset = dissect_doserror(
3136
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3137
3138
0
  return offset;
3139
0
}
3140
3141
/*
3142
 * SpoolssReplyOpenPrinter
3143
 */
3144
3145
static unsigned
3146
SpoolssReplyOpenPrinter_q(tvbuff_t *tvb, unsigned offset,
3147
             packet_info *pinfo, proto_tree *tree,
3148
             dcerpc_info *di, uint8_t *drep)
3149
0
{
3150
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3151
0
  uint32_t printerlocal;
3152
0
  char *name;
3153
3154
  /* Parse packet */
3155
0
  name=NULL;
3156
0
  offset = dissect_ndr_cvstring(
3157
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
3158
0
    hf_servername, true, &name);
3159
  /* ReplyOpenPrinter() stores the printername in se_data */
3160
0
  if(!pinfo->fd->visited){
3161
0
    if(!dcv->se_data){
3162
0
      if(name){
3163
0
        dcv->se_data = wmem_strdup(wmem_file_scope(), name);
3164
0
      }
3165
0
    }
3166
0
  }
3167
3168
0
  if (name)
3169
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", name);
3170
3171
0
  offset = dissect_ndr_uint32(
3172
0
    tvb, offset, pinfo, tree, di, drep, hf_printerlocal,
3173
0
    &printerlocal);
3174
3175
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
3176
0
            hf_printerdata_type, NULL);
3177
3178
0
  offset = dissect_ndr_uint32(
3179
0
    tvb, offset, pinfo, tree, di, drep, hf_replyopenprinter_unk0,
3180
0
    NULL);
3181
3182
0
  offset = dissect_ndr_uint32(
3183
0
    tvb, offset, pinfo, tree, di, drep, hf_replyopenprinter_unk1,
3184
0
    NULL);
3185
3186
0
  return offset;
3187
0
}
3188
3189
static unsigned
3190
SpoolssReplyOpenPrinter_r(tvbuff_t *tvb, unsigned offset,
3191
             packet_info *pinfo, proto_tree *tree,
3192
             dcerpc_info *di, uint8_t *drep)
3193
0
{
3194
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3195
0
  e_ctx_hnd policy_hnd;
3196
0
  proto_item *hnd_item;
3197
0
  uint32_t status;
3198
3199
  /* Parse packet */
3200
3201
0
  offset = dissect_nt_policy_hnd(
3202
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, &hnd_item,
3203
0
    PIDL_POLHND_OPEN);
3204
3205
0
  offset = dissect_doserror(
3206
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, &status);
3207
3208
0
  if( status == 0 ){
3209
0
    const char *pol_name;
3210
3211
0
    if (dcv->se_data){
3212
0
      pol_name = wmem_strdup_printf(pinfo->pool,
3213
0
        "ReplyOpenPrinter(%s)", (char *)dcv->se_data);
3214
0
    } else {
3215
0
      pol_name = "Unknown ReplyOpenPrinter() handle";
3216
0
    }
3217
0
    if(!pinfo->fd->visited){
3218
0
      dcerpc_store_polhnd_name(&policy_hnd, pinfo, pol_name);
3219
0
    }
3220
3221
0
    if(hnd_item)
3222
0
      proto_item_append_text(hnd_item, ": %s", pol_name);
3223
0
  }
3224
3225
0
  return offset;
3226
0
}
3227
3228
/*
3229
 * SpoolssGetPrinter
3230
 */
3231
3232
3233
static unsigned
3234
SpoolssGetPrinter_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3235
             proto_tree *tree, dcerpc_info *di, uint8_t *drep )
3236
0
{
3237
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3238
0
  uint32_t level;
3239
3240
  /* Parse packet */
3241
3242
0
  offset = dissect_nt_policy_hnd(
3243
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
3244
0
    PIDL_POLHND_USE);
3245
3246
0
  offset = dissect_ndr_uint32(
3247
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
3248
3249
  /* GetPrinter() stores the level in se_data */
3250
0
  if(!pinfo->fd->visited){
3251
0
      dcv->se_data = GINT_TO_POINTER((int)level);
3252
0
  }
3253
3254
3255
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
3256
3257
0
  offset = dissect_spoolss_buffer(
3258
0
    tvb, offset, pinfo, tree, di, drep, NULL);
3259
3260
0
  offset = dissect_ndr_uint32(
3261
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
3262
3263
0
  return offset;
3264
0
}
3265
3266
static int ett_PRINTER_INFO;
3267
3268
static unsigned
3269
SpoolssGetPrinter_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3270
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3271
0
{
3272
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3273
0
  BUFFER buffer;
3274
0
  int16_t level = GPOINTER_TO_INT(dcv->se_data);
3275
0
  proto_item *item = NULL;
3276
0
  proto_tree *subtree = NULL;
3277
3278
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
3279
3280
  /* Parse packet */
3281
3282
0
  offset = dissect_spoolss_buffer(
3283
0
    tvb, offset, pinfo, tree, di, drep, &buffer);
3284
3285
0
  if (buffer.tvb) {
3286
0
    subtree = proto_tree_add_subtree_format( buffer.tree, buffer.tvb, 0, -1, ett_PRINTER_INFO, &item, "Print info level %d", level);
3287
3288
0
    switch(level) {
3289
0
    case 0:
3290
0
      dissect_PRINTER_INFO_0(
3291
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3292
0
      break;
3293
0
    case 1:
3294
0
      dissect_PRINTER_INFO_1(
3295
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3296
0
      break;
3297
0
    case 2:
3298
0
      dissect_PRINTER_INFO_2(
3299
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3300
0
      break;
3301
0
    case 3:
3302
0
      dissect_PRINTER_INFO_3(
3303
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3304
0
      break;
3305
0
    case 5:
3306
0
      dissect_PRINTER_INFO_5(
3307
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3308
0
      break;
3309
0
    case 7:
3310
0
      dissect_PRINTER_INFO_7(
3311
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3312
0
      break;
3313
0
    default:
3314
0
      expert_add_info(pinfo, item, &ei_printer_info_level);
3315
0
      break;
3316
0
    }
3317
0
  }
3318
3319
0
  offset = dissect_ndr_uint32(
3320
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
3321
3322
0
  offset = dissect_doserror(
3323
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3324
3325
0
  return offset;
3326
0
}
3327
3328
/*
3329
 * SEC_DESC_BUF
3330
 */
3331
3332
static int ett_SEC_DESC_BUF;
3333
3334
static int hf_secdescbuf_maxlen;
3335
static int hf_secdescbuf_undoc;
3336
static int hf_secdescbuf_len;
3337
3338
static unsigned
3339
dissect_SEC_DESC_BUF(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3340
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3341
0
{
3342
0
  proto_tree *subtree;
3343
0
  uint32_t len;
3344
3345
  /* XXX: I think this is really a array of bytes which can be
3346
     dissected using dissect_ndr_cvstring().  The dissected data
3347
     can be passed to dissect_nt_sec_desc().  The problem is that
3348
     dissect_nt_cvstring() passes back a char * where it really
3349
     should pass back a tvb. */
3350
3351
0
  subtree = proto_tree_add_subtree(
3352
0
    tree, tvb, offset, 0, ett_SEC_DESC_BUF, NULL, "Security descriptor buffer");
3353
3354
0
  offset = dissect_ndr_uint32(
3355
0
    tvb, offset, pinfo, subtree, di, drep,
3356
0
    hf_secdescbuf_maxlen, NULL);
3357
3358
0
  offset = dissect_ndr_uint32(
3359
0
    tvb, offset, pinfo, subtree, di, drep,
3360
0
    hf_secdescbuf_undoc, NULL);
3361
3362
0
  offset = dissect_ndr_uint32(
3363
0
    tvb, offset, pinfo, subtree, di, drep,
3364
0
    hf_secdescbuf_len, &len);
3365
3366
0
  dissect_nt_sec_desc(
3367
0
    tvb, offset, pinfo, subtree, drep, true, len,
3368
0
    &spoolss_printer_access_mask_info);
3369
3370
0
  offset += len;
3371
3372
0
  return offset;
3373
0
}
3374
3375
/*
3376
 * SPOOL_PRINTER_INFO_LEVEL
3377
 */
3378
3379
static int ett_SPOOL_PRINTER_INFO_LEVEL;
3380
3381
/* spool printer info */
3382
3383
static int hf_spool_printer_info_devmode_ptr;
3384
static int hf_spool_printer_info_secdesc_ptr;
3385
3386
unsigned
3387
dissect_SPOOL_PRINTER_INFO(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3388
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3389
0
{
3390
0
  proto_tree *subtree;
3391
0
  uint32_t level;
3392
0
  proto_tree *item;
3393
3394
0
  subtree = proto_tree_add_subtree(
3395
0
    tree, tvb, offset, 0, ett_SPOOL_PRINTER_INFO_LEVEL, &item, "Spool printer info level");
3396
3397
0
  offset = dissect_ndr_uint32(
3398
0
    tvb, offset, pinfo, subtree, di, drep, hf_level, &level);
3399
3400
0
  switch(level) {
3401
0
  case 3: {
3402
0
    uint32_t devmode_ptr, secdesc_ptr;
3403
3404
    /* I can't seem to get this working with the correct
3405
       dissect_ndr_pointer() function so let's cheat and
3406
       dissect the pointers by hand. )-: */
3407
3408
0
    offset = dissect_ndr_uint32(
3409
0
      tvb, offset, pinfo, subtree, di, drep,
3410
0
      hf_spool_printer_info_devmode_ptr,
3411
0
      &devmode_ptr);
3412
3413
0
    offset = dissect_ndr_uint32(
3414
0
      tvb, offset, pinfo, subtree, di, drep,
3415
0
      hf_spool_printer_info_secdesc_ptr,
3416
0
      &secdesc_ptr);
3417
3418
0
    if (devmode_ptr)
3419
0
      offset = dissect_DEVMODE_CTR(
3420
0
        tvb, offset, pinfo, subtree, di, drep);
3421
3422
0
    if (secdesc_ptr)
3423
0
      offset = dissect_SEC_DESC_BUF(
3424
0
        tvb, offset, pinfo, subtree, di, drep);
3425
3426
0
  break;
3427
0
  }
3428
0
  case 2:
3429
0
  default:
3430
0
    expert_add_info_format(pinfo, item, &ei_spool_printer_info_level, "Unknown spool printer info level %d", level);
3431
0
    break;
3432
0
  }
3433
3434
0
  return offset;
3435
0
}
3436
3437
/*
3438
 * SpoolssSetPrinter
3439
 */
3440
3441
static int hf_setprinter_cmd;
3442
3443
static const value_string setprinter_cmd_vals[] = {
3444
  { SPOOLSS_PRINTER_CONTROL_UNPAUSE, "Unpause" },
3445
  { SPOOLSS_PRINTER_CONTROL_PAUSE, "Pause" },
3446
  { SPOOLSS_PRINTER_CONTROL_RESUME, "Resume" },
3447
  { SPOOLSS_PRINTER_CONTROL_PURGE, "Purge" },
3448
  { SPOOLSS_PRINTER_CONTROL_SET_STATUS, "Set status" },
3449
  { 0, NULL }
3450
};
3451
3452
static unsigned
3453
SpoolssSetPrinter_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3454
             proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3455
0
{
3456
0
  uint32_t level;
3457
3458
  /* Parse packet */
3459
3460
0
  offset = dissect_nt_policy_hnd(
3461
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
3462
0
    PIDL_POLHND_USE);
3463
3464
0
  offset = dissect_ndr_uint32(
3465
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
3466
3467
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
3468
3469
0
  offset = dissect_SPOOL_PRINTER_INFO(
3470
0
    tvb, offset, pinfo, tree, di, drep);
3471
3472
0
  offset = dissect_ndr_uint32(
3473
0
    tvb, offset, pinfo, tree, di, drep,
3474
0
    hf_setprinter_cmd, NULL);
3475
3476
0
  return offset;
3477
0
}
3478
3479
static unsigned
3480
SpoolssSetPrinter_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3481
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3482
0
{
3483
  /* Parse packet */
3484
3485
0
  offset = dissect_doserror(
3486
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3487
3488
0
  return offset;
3489
0
}
3490
3491
/*
3492
 * FORM_REL
3493
 */
3494
3495
static const value_string form_type_vals[] =
3496
{
3497
  { SPOOLSS_FORM_USER, "User" },
3498
  { SPOOLSS_FORM_BUILTIN, "Builtin" },
3499
  { SPOOLSS_FORM_PRINTER, "Printer" },
3500
  { 0, NULL }
3501
};
3502
3503
static int ett_FORM_REL;
3504
3505
static unsigned
3506
dissect_FORM_REL(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3507
          proto_tree *tree, dcerpc_info *di, uint8_t *drep, int struct_start)
3508
0
{
3509
0
  proto_item *item;
3510
0
  proto_tree *subtree;
3511
0
  uint32_t flags;
3512
0
  int item_start = offset;
3513
0
  char *name = NULL;
3514
3515
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_FORM_REL, &item, "Form");
3516
3517
0
  offset = dissect_ndr_uint32(
3518
0
    tvb, offset, pinfo, subtree, di, drep, hf_form_flags, &flags);
3519
3520
0
  offset = dissect_spoolss_relstr(
3521
0
    tvb, offset, pinfo, subtree, di, drep, hf_form_name,
3522
0
    struct_start, &name);
3523
3524
0
  if (name) {
3525
0
    proto_item_append_text(item, ": %s", name);
3526
0
  }
3527
3528
0
  offset = dissect_ndr_uint32(
3529
0
    tvb, offset, pinfo, subtree, di, drep,
3530
0
    hf_form_width, NULL);
3531
3532
0
  offset = dissect_ndr_uint32(
3533
0
    tvb, offset, pinfo, subtree, di, drep,
3534
0
    hf_form_height, NULL);
3535
3536
0
  offset = dissect_ndr_uint32(
3537
0
    tvb, offset, pinfo, subtree, di, drep,
3538
0
    hf_form_left_margin, NULL);
3539
3540
0
  offset = dissect_ndr_uint32(
3541
0
    tvb, offset, pinfo, subtree, di, drep,
3542
0
    hf_form_top_margin, NULL);
3543
3544
0
  offset = dissect_ndr_uint32(
3545
0
    tvb, offset, pinfo, subtree, di, drep,
3546
0
    hf_form_horiz_len, NULL);
3547
3548
0
  offset = dissect_ndr_uint32(
3549
0
    tvb, offset, pinfo, subtree, di, drep,
3550
0
    hf_form_vert_len, NULL);
3551
3552
0
  proto_item_set_len(item, offset - item_start);
3553
3554
0
  return offset;
3555
0
}
3556
3557
/*
3558
 * SpoolssEnumForms
3559
 */
3560
3561
static unsigned
3562
SpoolssEnumForms_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3563
            proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3564
0
{
3565
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3566
0
  uint32_t level;
3567
0
  proto_item *hidden_item;
3568
3569
0
  hidden_item = proto_tree_add_uint(
3570
0
    tree, hf_form, tvb, offset, 0, 1);
3571
0
  proto_item_set_hidden(hidden_item);
3572
3573
  /* Parse packet */
3574
3575
0
  offset = dissect_nt_policy_hnd(
3576
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
3577
0
    PIDL_POLHND_USE);
3578
3579
0
  offset = dissect_ndr_uint32(
3580
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
3581
3582
  /* EnumForms() stores the level in se_data */
3583
0
  if(!pinfo->fd->visited){
3584
0
      dcv->se_data = GINT_TO_POINTER((int)level);
3585
0
  }
3586
3587
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
3588
3589
0
  offset = dissect_spoolss_buffer(
3590
0
    tvb, offset, pinfo, tree, di, drep, NULL);
3591
3592
0
  offset = dissect_ndr_uint32(
3593
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
3594
3595
0
  return offset;
3596
0
}
3597
3598
static unsigned
3599
SpoolssEnumForms_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3600
            proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3601
0
{
3602
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3603
0
  BUFFER buffer;
3604
0
  uint32_t level = GPOINTER_TO_UINT(dcv->se_data), i, count;
3605
0
  int buffer_offset;
3606
0
  proto_item *hidden_item;
3607
3608
0
  hidden_item = proto_tree_add_uint(
3609
0
    tree, hf_form, tvb, offset, 0, 1);
3610
0
  proto_item_set_hidden(hidden_item);
3611
3612
  /* Parse packet */
3613
3614
0
  offset = dissect_spoolss_buffer(
3615
0
    tvb, offset, pinfo, tree, di, drep, &buffer);
3616
3617
0
  offset = dissect_ndr_uint32(
3618
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
3619
3620
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
3621
3622
0
  offset = dissect_ndr_uint32(
3623
0
    tvb, offset, pinfo, tree, di, drep, hf_enumforms_num, &count);
3624
3625
  /* Unfortunately this array isn't in NDR format so we can't
3626
     use prs_array().  The other weird thing is the
3627
     struct_start being inside the loop rather than outside.
3628
     Very strange. */
3629
3630
0
  buffer_offset = 0;
3631
3632
0
  for (i = 0; i < count; i++) {
3633
0
    int struct_start = buffer_offset;
3634
3635
0
    buffer_offset = dissect_FORM_REL(
3636
0
      buffer.tvb, buffer_offset, pinfo, buffer.tree, di, drep,
3637
0
      struct_start);
3638
0
  }
3639
3640
0
  offset = dissect_doserror(
3641
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3642
3643
0
  return offset;
3644
0
}
3645
3646
/*
3647
 * SpoolssDeletePrinter
3648
 */
3649
3650
static unsigned
3651
SpoolssDeletePrinter_q(tvbuff_t *tvb, unsigned offset,
3652
          packet_info *pinfo, proto_tree *tree,
3653
          dcerpc_info *di, uint8_t *drep)
3654
0
{
3655
  /* Parse packet */
3656
3657
0
  offset = dissect_nt_policy_hnd(
3658
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
3659
0
    PIDL_POLHND_USE);
3660
3661
0
  return offset;
3662
0
}
3663
3664
static unsigned
3665
SpoolssDeletePrinter_r(tvbuff_t *tvb, unsigned offset,
3666
          packet_info *pinfo, proto_tree *tree,
3667
          dcerpc_info *di, uint8_t *drep)
3668
0
{
3669
  /* Parse packet */
3670
3671
0
  offset = dissect_nt_policy_hnd(
3672
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
3673
0
    PIDL_POLHND_USE);
3674
3675
0
  offset = dissect_doserror(
3676
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3677
3678
0
  return offset;
3679
0
}
3680
3681
static unsigned
3682
SpoolssAddPrinterEx_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3683
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3684
0
{
3685
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3686
0
  e_ctx_hnd policy_hnd;
3687
0
  proto_item *hnd_item;
3688
0
  uint32_t status;
3689
3690
  /* Parse packet */
3691
3692
0
  offset = dissect_nt_policy_hnd(
3693
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, &hnd_item,
3694
0
    PIDL_POLHND_OPEN);
3695
3696
0
  offset = dissect_doserror(
3697
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, &status);
3698
3699
0
  if( status == 0 ){
3700
0
    const char *pol_name;
3701
3702
0
    if (dcv->se_data){
3703
0
      pol_name = wmem_strdup_printf(pinfo->pool,
3704
0
        "AddPrinterEx(%s)", (char *)dcv->se_data);
3705
0
    } else {
3706
0
      pol_name = "Unknown AddPrinterEx() handle";
3707
0
    }
3708
0
    if(!pinfo->fd->visited){
3709
0
      dcerpc_store_polhnd_name(&policy_hnd, pinfo, pol_name);
3710
0
    }
3711
3712
0
    if(hnd_item)
3713
0
      proto_item_append_text(hnd_item, ": %s", pol_name);
3714
0
  }
3715
3716
0
  return offset;
3717
0
}
3718
3719
/*
3720
 * SpoolssEnumPrinterData
3721
 */
3722
3723
static int hf_enumprinterdata_enumindex;
3724
static int hf_enumprinterdata_value_offered;
3725
static int hf_enumprinterdata_data_offered;
3726
static int hf_enumprinterdata_value_len;
3727
static int hf_enumprinterdata_value_needed;
3728
static int hf_enumprinterdata_data_needed;
3729
3730
static unsigned
3731
SpoolssEnumPrinterData_q(tvbuff_t *tvb, unsigned offset,
3732
            packet_info *pinfo, proto_tree *tree,
3733
            dcerpc_info *di, uint8_t *drep)
3734
0
{
3735
0
  uint32_t ndx;
3736
0
  proto_item *hidden_item;
3737
3738
0
  hidden_item = proto_tree_add_uint(
3739
0
    tree, hf_printerdata, tvb, offset, 0, 1);
3740
0
  proto_item_set_hidden(hidden_item);
3741
3742
  /* Parse packet */
3743
3744
0
  offset = dissect_nt_policy_hnd(
3745
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
3746
0
    PIDL_POLHND_USE);
3747
3748
0
  offset = dissect_ndr_uint32(
3749
0
    tvb, offset, pinfo, tree, di, drep,
3750
0
    hf_enumprinterdata_enumindex, &ndx);
3751
3752
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", index %d", ndx);
3753
3754
0
  offset = dissect_ndr_uint32(
3755
0
    tvb, offset, pinfo, tree, di, drep,
3756
0
    hf_enumprinterdata_value_offered, NULL);
3757
3758
0
  offset = dissect_ndr_uint32(
3759
0
    tvb, offset, pinfo, tree, di, drep,
3760
0
    hf_enumprinterdata_data_offered, NULL);
3761
3762
0
  return offset;
3763
0
}
3764
3765
static unsigned
3766
SpoolssEnumPrinterData_r(tvbuff_t *tvb, unsigned offset,
3767
            packet_info *pinfo, proto_tree *tree,
3768
            dcerpc_info *di, uint8_t *drep)
3769
0
{
3770
0
  uint32_t value_len, type;
3771
0
  char *value;
3772
0
  proto_item *value_item;
3773
0
  proto_tree *value_subtree;
3774
0
  proto_item *hidden_item;
3775
3776
0
  hidden_item = proto_tree_add_uint(
3777
0
    tree, hf_printerdata, tvb, offset, 0, 1);
3778
0
  proto_item_set_hidden(hidden_item);
3779
3780
  /* Parse packet */
3781
3782
0
  value_subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_printerdata_value, &value_item, "Value");
3783
3784
0
  offset = dissect_ndr_uint32(
3785
0
    tvb, offset, pinfo, value_subtree, di, drep,
3786
0
    hf_enumprinterdata_value_len, &value_len);
3787
3788
0
  if (value_len) {
3789
0
    dissect_spoolss_uint16uni(
3790
0
      tvb, offset, pinfo, value_subtree, drep, &value, hf_value_name);
3791
3792
0
    offset += value_len * 2;
3793
3794
0
    if (value && value[0])
3795
0
      col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", value);
3796
3797
0
    proto_item_append_text(value_item, ": %s", value);
3798
3799
0
    hidden_item = proto_tree_add_string(
3800
0
      tree, hf_printerdata_value, tvb, offset, 0, value);
3801
0
    proto_item_set_hidden(hidden_item);
3802
0
  }
3803
3804
0
  proto_item_set_len(value_item, value_len * 2 + 4);
3805
3806
0
  offset = dissect_ndr_uint32(
3807
0
    tvb, offset, pinfo, value_subtree, di, drep,
3808
0
    hf_enumprinterdata_value_needed, NULL);
3809
3810
0
  offset = dissect_ndr_uint32(
3811
0
    tvb, offset, pinfo, tree, di, drep, hf_printerdata_type, &type);
3812
3813
0
  offset = dissect_printerdata_data(
3814
0
    tvb, offset, pinfo, tree, di, drep, type);
3815
3816
0
  offset = dissect_ndr_uint32(
3817
0
    tvb, offset, pinfo, tree, di, drep,
3818
0
    hf_enumprinterdata_data_needed, NULL);
3819
3820
0
  offset = dissect_doserror(
3821
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3822
3823
0
  return offset;
3824
0
}
3825
3826
/*
3827
 * SpoolssEnumPrinters
3828
 */
3829
3830
static int ett_enumprinters_flags;
3831
3832
static int hf_enumprinters_flags;
3833
static int hf_enumprinters_flags_local;
3834
static int hf_enumprinters_flags_name;
3835
static int hf_enumprinters_flags_shared;
3836
static int hf_enumprinters_flags_default;
3837
static int hf_enumprinters_flags_connections;
3838
static int hf_enumprinters_flags_network;
3839
static int hf_enumprinters_flags_remote;
3840
3841
static unsigned
3842
SpoolssEnumPrinters_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3843
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3844
0
{
3845
0
  uint32_t level, flags;
3846
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3847
0
  static int * const hf_flags[] = {
3848
0
    &hf_enumprinters_flags_network,
3849
0
    &hf_enumprinters_flags_shared,
3850
0
    &hf_enumprinters_flags_remote,
3851
0
    &hf_enumprinters_flags_name,
3852
0
    &hf_enumprinters_flags_connections,
3853
0
    &hf_enumprinters_flags_local,
3854
0
    &hf_enumprinters_flags_default,
3855
0
    NULL
3856
0
  };
3857
3858
  /* Parse packet */
3859
3860
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, NULL, di, drep, -1, &flags);
3861
3862
0
  proto_tree_add_bitmask_value(tree, tvb, offset - 4, hf_enumprinters_flags,
3863
0
          ett_enumprinters_flags, hf_flags, flags);
3864
3865
0
  offset = dissect_ndr_str_pointer_item(
3866
0
    tvb, offset, pinfo, tree, di, drep,
3867
0
    NDR_POINTER_UNIQUE, "Server name", hf_servername, 0);
3868
3869
0
  offset = dissect_ndr_uint32(
3870
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
3871
3872
  /* GetPrinter() stores the level in se_data */
3873
0
  if(!pinfo->fd->visited){
3874
0
    dcv->se_data = GINT_TO_POINTER((int)level);
3875
0
  }
3876
3877
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
3878
3879
0
  offset = dissect_spoolss_buffer(
3880
0
    tvb, offset, pinfo, tree, di, drep, NULL);
3881
3882
0
  offset = dissect_ndr_uint32(
3883
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
3884
3885
0
  return offset;
3886
0
}
3887
3888
static unsigned
3889
SpoolssEnumPrinters_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3890
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3891
0
{
3892
0
  uint32_t num_drivers;
3893
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
3894
0
  int16_t level = GPOINTER_TO_INT(dcv->se_data);
3895
0
  BUFFER buffer;
3896
0
  proto_item *item;
3897
0
  proto_tree *subtree = NULL;
3898
3899
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
3900
3901
  /* Parse packet */
3902
3903
0
  offset = dissect_spoolss_buffer(
3904
0
    tvb, offset, pinfo, tree, di, drep, &buffer);
3905
3906
0
  if (buffer.tvb) {
3907
0
    subtree = proto_tree_add_subtree_format( buffer.tree, buffer.tvb, 0, -1, ett_PRINTER_INFO, &item, "Print info level %d", level);
3908
3909
0
    switch(level) {
3910
0
    case 0:
3911
0
      dissect_PRINTER_INFO_0(
3912
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3913
0
      break;
3914
0
    case 1:
3915
0
      dissect_PRINTER_INFO_1(
3916
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3917
0
      break;
3918
0
    case 2:
3919
0
      dissect_PRINTER_INFO_2(
3920
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3921
0
      break;
3922
0
    case 3:
3923
0
      dissect_PRINTER_INFO_3(
3924
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3925
0
      break;
3926
0
    case 5:
3927
0
      dissect_PRINTER_INFO_5(
3928
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3929
0
      break;
3930
0
    case 7:
3931
0
      dissect_PRINTER_INFO_7(
3932
0
        buffer.tvb, 0, pinfo, subtree, di, drep);
3933
0
      break;
3934
0
    default:
3935
0
      expert_add_info(pinfo, item, &ei_printer_info_level);
3936
0
      break;
3937
0
    }
3938
0
  }
3939
3940
0
  offset = dissect_ndr_uint32(
3941
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
3942
3943
0
  offset = dissect_ndr_uint32(
3944
0
    tvb, offset, pinfo, tree, di, drep, hf_returned,
3945
0
    &num_drivers);
3946
3947
0
  offset = dissect_doserror(
3948
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3949
3950
0
  return offset;
3951
0
}
3952
3953
/*
3954
 * AddPrinterDriver
3955
 */
3956
static unsigned
3957
SpoolssAddPrinterDriver_r(tvbuff_t *tvb, unsigned offset,
3958
             packet_info *pinfo, proto_tree *tree,
3959
             dcerpc_info *di, uint8_t *drep)
3960
0
{
3961
  /* Parse packet */
3962
3963
0
  offset = dissect_doserror(
3964
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
3965
3966
0
  return offset;
3967
0
}
3968
3969
/*
3970
 * FORM_1
3971
 */
3972
3973
static int ett_FORM_1;
3974
3975
static unsigned
3976
dissect_FORM_1(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
3977
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
3978
0
{
3979
0
  proto_tree *subtree;
3980
0
  uint32_t flags;
3981
3982
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_FORM_1, NULL, "Form level 1");
3983
3984
0
  offset = dissect_ndr_str_pointer_item(
3985
0
    tvb, offset, pinfo, subtree, di, drep, NDR_POINTER_UNIQUE,
3986
0
    "Name", hf_form_name, 0);
3987
3988
  /* Eek - we need to know whether this pointer was NULL or not.
3989
     Currently there is not any way to do this. */
3990
3991
0
  if (tvb_reported_length_remaining(tvb, offset) <= 0)
3992
0
    goto done;
3993
3994
0
  offset = dissect_ndr_uint32(
3995
0
    tvb, offset, pinfo, subtree, di, drep, hf_form_flags, &flags);
3996
3997
0
  offset = dissect_ndr_uint32(
3998
0
    tvb, offset, pinfo, subtree, di, drep,
3999
0
    hf_form_unknown, NULL);
4000
4001
0
  offset = dissect_ndr_uint32(
4002
0
    tvb, offset, pinfo, subtree, di, drep,
4003
0
    hf_form_width, NULL);
4004
4005
0
  offset = dissect_ndr_uint32(
4006
0
    tvb, offset, pinfo, subtree, di, drep,
4007
0
    hf_form_height, NULL);
4008
4009
0
  offset = dissect_ndr_uint32(
4010
0
    tvb, offset, pinfo, subtree, di, drep,
4011
0
    hf_form_left_margin, NULL);
4012
4013
0
  offset = dissect_ndr_uint32(
4014
0
    tvb, offset, pinfo, subtree, di, drep,
4015
0
    hf_form_top_margin, NULL);
4016
4017
0
  offset = dissect_ndr_uint32(
4018
0
    tvb, offset, pinfo, subtree, di, drep,
4019
0
    hf_form_horiz_len, NULL);
4020
4021
0
  offset = dissect_ndr_uint32(
4022
0
    tvb, offset, pinfo, subtree, di, drep,
4023
0
    hf_form_vert_len, NULL);
4024
4025
0
 done:
4026
0
  return offset;
4027
0
}
4028
4029
/*
4030
 * FORM_CTR
4031
 */
4032
4033
static int ett_FORM_CTR;
4034
4035
unsigned
4036
dissect_FORM_CTR(tvbuff_t *tvb, unsigned offset,
4037
          packet_info *pinfo, proto_tree *tree,
4038
          dcerpc_info *di, uint8_t *drep)
4039
0
{
4040
0
  proto_tree *subtree;
4041
0
  proto_item *item;
4042
0
  uint32_t level;
4043
4044
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_FORM_CTR, &item, "Form container");
4045
4046
0
  offset = dissect_ndr_uint32(
4047
0
    tvb, offset, pinfo, subtree, di, drep, hf_form_level, &level);
4048
4049
0
  switch(level) {
4050
0
  case 1:
4051
0
    offset = dissect_FORM_1(tvb, offset, pinfo, subtree, di, drep);
4052
0
    break;
4053
4054
0
  default:
4055
0
    expert_add_info_format(pinfo, item, &ei_form_level, "Unknown form info level %d", level);
4056
0
    break;
4057
0
  }
4058
4059
0
  return offset;
4060
0
}
4061
4062
/*
4063
 * AddForm
4064
 */
4065
4066
static unsigned
4067
SpoolssAddForm_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4068
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4069
0
{
4070
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
4071
0
  uint32_t level;
4072
0
  proto_item *hidden_item;
4073
4074
0
  hidden_item = proto_tree_add_uint(
4075
0
    tree, hf_form, tvb, offset, 0, 1);
4076
0
  proto_item_set_hidden(hidden_item);
4077
4078
  /* Parse packet */
4079
4080
0
  offset = dissect_nt_policy_hnd(
4081
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
4082
0
    PIDL_POLHND_USE);
4083
4084
0
  offset = dissect_ndr_uint32(
4085
0
    tvb, offset, pinfo, tree, di, drep, hf_form_level, &level);
4086
4087
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
4088
4089
  /* AddForm() stores the level in se_data */
4090
0
  if(!pinfo->fd->visited){
4091
0
      dcv->se_data = GUINT_TO_POINTER((int)level);
4092
0
  }
4093
4094
0
  offset = dissect_FORM_CTR(tvb, offset, pinfo, tree, di, drep);
4095
4096
0
  return offset;
4097
0
}
4098
4099
static unsigned
4100
SpoolssAddForm_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4101
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4102
0
{
4103
0
  proto_item *hidden_item;
4104
4105
0
  hidden_item = proto_tree_add_uint(
4106
0
    tree, hf_form, tvb, offset, 0, 1);
4107
0
  proto_item_set_hidden(hidden_item);
4108
4109
  /* Parse packet */
4110
4111
0
  offset = dissect_doserror(
4112
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4113
4114
0
  return offset;
4115
0
}
4116
4117
/*
4118
 * DeleteForm
4119
 */
4120
4121
static unsigned
4122
SpoolssDeleteForm_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4123
             proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4124
0
{
4125
0
  proto_item *hidden_item;
4126
0
  char *name = NULL;
4127
4128
0
  hidden_item = proto_tree_add_uint(
4129
0
    tree, hf_form, tvb, offset, 0, 1);
4130
0
  proto_item_set_hidden(hidden_item);
4131
4132
  /* Parse packet */
4133
4134
0
  offset = dissect_nt_policy_hnd(
4135
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
4136
0
    PIDL_POLHND_USE);
4137
4138
0
  offset = dissect_ndr_cvstring(
4139
0
    tvb, offset, pinfo, tree, di, drep,
4140
0
    sizeof(uint16_t), hf_form_name, true, &name);
4141
4142
0
  if (name)
4143
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", name);
4144
4145
0
  return offset;
4146
0
}
4147
4148
static unsigned
4149
SpoolssDeleteForm_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4150
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4151
0
{
4152
0
  proto_item *hidden_item;
4153
4154
0
  hidden_item = proto_tree_add_uint(
4155
0
    tree, hf_form, tvb, offset, 0, 1);
4156
0
  proto_item_set_hidden(hidden_item);
4157
4158
  /* Parse packet */
4159
4160
0
  offset = dissect_doserror(
4161
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4162
4163
0
  return offset;
4164
0
}
4165
4166
/*
4167
 * SetForm
4168
 */
4169
4170
static unsigned
4171
SpoolssSetForm_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4172
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4173
0
{
4174
0
  char *name = NULL;
4175
0
  uint32_t level;
4176
0
  proto_item *hidden_item;
4177
4178
0
  hidden_item = proto_tree_add_uint(
4179
0
    tree, hf_form, tvb, offset, 0, 1);
4180
0
  proto_item_set_hidden(hidden_item);
4181
4182
  /* Parse packet */
4183
4184
0
  offset = dissect_nt_policy_hnd(
4185
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
4186
0
    PIDL_POLHND_USE);
4187
4188
0
  offset = dissect_ndr_cvstring(
4189
0
    tvb, offset, pinfo, tree, di, drep,
4190
0
    sizeof(uint16_t), hf_form_name, true, &name);
4191
4192
0
  if (name)
4193
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", name);
4194
4195
0
  offset = dissect_ndr_uint32(
4196
0
    tvb, offset, pinfo, tree, di, drep, hf_form_level, &level);
4197
4198
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
4199
4200
0
  offset = dissect_FORM_CTR(tvb, offset, pinfo, tree, di, drep);
4201
4202
0
  return offset;
4203
0
}
4204
4205
static unsigned
4206
SpoolssSetForm_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4207
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4208
0
{
4209
0
  proto_item *hidden_item;
4210
4211
0
  hidden_item = proto_tree_add_uint(
4212
0
    tree, hf_form, tvb, offset, 0, 1);
4213
0
  proto_item_set_hidden(hidden_item);
4214
4215
  /* Parse packet */
4216
4217
0
  offset = dissect_doserror(
4218
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4219
4220
0
  return offset;
4221
0
}
4222
4223
/*
4224
 * GetForm
4225
 */
4226
4227
static unsigned
4228
SpoolssGetForm_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4229
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4230
0
{
4231
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
4232
0
  proto_item *hidden_item;
4233
0
  uint32_t level;
4234
0
  char *name;
4235
4236
0
  hidden_item = proto_tree_add_uint(
4237
0
    tree, hf_form, tvb, offset, 0, 1);
4238
0
  proto_item_set_hidden(hidden_item);
4239
4240
  /* Parse packet */
4241
4242
0
  offset = dissect_nt_policy_hnd(
4243
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
4244
0
    PIDL_POLHND_USE);
4245
4246
0
  offset = dissect_ndr_cvstring(
4247
0
    tvb, offset, pinfo, tree, di, drep,
4248
0
    sizeof(uint16_t), hf_form_name, true, &name);
4249
4250
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", name);
4251
4252
0
  offset = dissect_ndr_uint32(
4253
0
    tvb, offset, pinfo, tree, di, drep, hf_form_level, &level);
4254
4255
  /* GetForm() stores the level in se_data */
4256
0
  if(!pinfo->fd->visited){
4257
0
      dcv->se_data = GUINT_TO_POINTER((int)level);
4258
0
  }
4259
4260
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d",
4261
0
        level);
4262
4263
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep, NULL);
4264
4265
0
  offset = dissect_ndr_uint32(
4266
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
4267
4268
0
  return offset;
4269
0
}
4270
4271
static unsigned
4272
SpoolssGetForm_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4273
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4274
0
{
4275
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
4276
0
  BUFFER buffer;
4277
0
  uint32_t level = GPOINTER_TO_UINT(dcv->se_data);
4278
0
  proto_item *hidden_item;
4279
4280
0
  hidden_item = proto_tree_add_uint(
4281
0
    tree, hf_form, tvb, offset, 0, 1);
4282
0
  proto_item_set_hidden(hidden_item);
4283
4284
  /* Parse packet */
4285
4286
0
  offset = dissect_spoolss_buffer(
4287
0
    tvb, offset, pinfo, tree, di, drep, &buffer);
4288
4289
0
  offset = dissect_ndr_uint32(
4290
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
4291
4292
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
4293
4294
0
  if (buffer.tvb) {
4295
0
    int buffer_offset = 0;
4296
4297
0
    switch(level) {
4298
0
    case 1: {
4299
0
      int struct_start = buffer_offset;
4300
4301
      /*buffer_offset = */dissect_FORM_REL(
4302
0
        buffer.tvb, buffer_offset, pinfo, tree, di, drep,
4303
0
        struct_start);
4304
0
      break;
4305
0
    }
4306
4307
0
    default:
4308
0
      proto_tree_add_expert_format_remaining(buffer.tree, pinfo, &ei_form_level, buffer.tvb, buffer_offset, "Unknown form info level %d", level);
4309
0
      break;
4310
0
    }
4311
0
  }
4312
4313
0
  offset = dissect_doserror(
4314
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4315
4316
0
  return offset;
4317
0
}
4318
4319
4320
/* A generic reply function that just parses the status code.  Useful for
4321
   unimplemented dissectors so the status code can be inserted into the
4322
   INFO column. */
4323
4324
static unsigned
4325
SpoolssGeneric_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4326
          proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4327
0
{
4328
0
  int len = tvb_reported_length(tvb);
4329
4330
0
  proto_tree_add_expert(tree, pinfo, &ei_unimplemented_dissector, tvb, offset, 0);
4331
4332
0
  offset = dissect_doserror(
4333
0
    tvb, len - 4, pinfo, tree, di, drep, hf_rc, NULL);
4334
4335
0
  return offset;
4336
0
}
4337
4338
/*
4339
 * JOB_INFO_1
4340
 */
4341
4342
static int ett_JOB_INFO_1;
4343
4344
static unsigned
4345
dissect_spoolss_JOB_INFO_1(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4346
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4347
0
{
4348
0
  proto_item *item;
4349
0
  proto_tree *subtree;
4350
0
  int struct_start = offset;
4351
0
  char *document_name;
4352
4353
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_JOB_INFO_1, &item, "Job info level 1");
4354
4355
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
4356
0
            hf_job_id, NULL);
4357
4358
0
  offset = dissect_spoolss_relstr(
4359
0
    tvb, offset, pinfo, subtree, di, drep, hf_printername,
4360
0
    struct_start, NULL);
4361
4362
0
  offset = dissect_spoolss_relstr(
4363
0
    tvb, offset, pinfo, subtree, di, drep, hf_servername,
4364
0
    struct_start, NULL);
4365
4366
0
  offset = dissect_spoolss_relstr(
4367
0
    tvb, offset, pinfo, subtree, di, drep, hf_username,
4368
0
    struct_start, NULL);
4369
4370
0
  offset = dissect_spoolss_relstr(
4371
0
    tvb, offset, pinfo, subtree, di, drep, hf_documentname,
4372
0
    struct_start, &document_name);
4373
4374
0
  proto_item_append_text(item, ": %s", document_name);
4375
4376
0
  offset = dissect_spoolss_relstr(
4377
0
    tvb, offset, pinfo, subtree, di, drep, hf_datatype,
4378
0
    struct_start, NULL);
4379
4380
0
  offset = dissect_spoolss_relstr(
4381
0
    tvb, offset, pinfo, subtree, di, drep, hf_textstatus,
4382
0
    struct_start, NULL);
4383
4384
0
  offset = dissect_job_status(tvb, offset, pinfo, subtree, di, drep);
4385
4386
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
4387
0
            hf_job_priority, NULL);
4388
4389
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
4390
0
            hf_job_position, NULL);
4391
4392
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
4393
0
            hf_job_totalpages, NULL);
4394
4395
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
4396
0
            hf_job_pagesprinted, NULL);
4397
4398
0
  offset = dissect_SYSTEM_TIME(
4399
0
    tvb, offset, pinfo, subtree, di, drep, "Job Submission Time",
4400
0
    true, NULL);
4401
4402
0
  proto_item_set_len(item, offset - struct_start);
4403
4404
0
  return offset;
4405
0
}
4406
4407
/*
4408
 * JOB_INFO_2
4409
 */
4410
4411
static int ett_JOB_INFO_2;
4412
4413
static unsigned
4414
dissect_spoolss_JOB_INFO_2(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4415
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4416
0
{
4417
0
  proto_item *item;
4418
0
  proto_tree *subtree;
4419
0
  int struct_start = offset;
4420
0
  char *document_name;
4421
0
  uint32_t devmode_offset, secdesc_offset;
4422
4423
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_JOB_INFO_2, &item, "Job info level 2");
4424
4425
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
4426
0
            hf_job_id, NULL);
4427
4428
0
  offset = dissect_spoolss_relstr(
4429
0
    tvb, offset, pinfo, subtree, di, drep, hf_printername,
4430
0
    struct_start, NULL);
4431
4432
0
  offset = dissect_spoolss_relstr(
4433
0
    tvb, offset, pinfo, subtree, di, drep, hf_machinename,
4434
0
    struct_start, NULL);
4435
4436
0
  offset = dissect_spoolss_relstr(
4437
0
    tvb, offset, pinfo, subtree, di, drep, hf_username,
4438
0
    struct_start, NULL);
4439
4440
0
  offset = dissect_spoolss_relstr(
4441
0
    tvb, offset, pinfo, subtree, di, drep, hf_documentname,
4442
0
    struct_start, &document_name);
4443
4444
0
  proto_item_append_text(item, ": %s", document_name);
4445
4446
0
  offset = dissect_spoolss_relstr(
4447
0
    tvb, offset, pinfo, subtree, di, drep, hf_notifyname,
4448
0
    struct_start, NULL);
4449
4450
0
  offset = dissect_spoolss_relstr(
4451
0
    tvb, offset, pinfo, subtree, di, drep, hf_datatype,
4452
0
    struct_start, NULL);
4453
4454
0
  offset = dissect_spoolss_relstr(
4455
0
    tvb, offset, pinfo, subtree, di, drep, hf_printprocessor,
4456
0
    struct_start, NULL);
4457
4458
0
  offset = dissect_spoolss_relstr(
4459
0
    tvb, offset, pinfo, subtree, di, drep, hf_parameters,
4460
0
    struct_start, NULL);
4461
4462
0
  offset = dissect_spoolss_relstr(
4463
0
    tvb, offset, pinfo, subtree, di, drep, hf_drivername,
4464
0
    struct_start, NULL);
4465
4466
0
  offset = dissect_ndr_uint32(
4467
0
    tvb, offset, pinfo, NULL, di, drep, hf_offset,
4468
0
    &devmode_offset);
4469
4470
  // This is the offset *after* the uint32 containing the DeviceMode
4471
  // size, so it cannot be less than 4.
4472
0
  if (devmode_offset < 4) {
4473
0
    THROW(ReportedBoundsError);
4474
0
  }
4475
4476
0
  dissect_DEVMODE(
4477
0
    tvb, devmode_offset - 4 + struct_start, pinfo, subtree, di, drep);
4478
4479
0
  offset = dissect_spoolss_relstr(
4480
0
    tvb, offset, pinfo, subtree, di, drep, hf_textstatus,
4481
0
    struct_start, NULL);
4482
4483
0
  offset = dissect_ndr_uint32(
4484
0
    tvb, offset, pinfo, NULL, di, drep, hf_offset,
4485
0
    &secdesc_offset);
4486
4487
0
  dissect_nt_sec_desc(
4488
0
    tvb, secdesc_offset, pinfo, subtree, drep,
4489
0
    false, -1,
4490
0
    &spoolss_job_access_mask_info);
4491
4492
0
  offset = dissect_job_status(tvb, offset, pinfo, subtree, di, drep);
4493
4494
0
  offset = dissect_ndr_uint32(
4495
0
    tvb, offset, pinfo, subtree, di, drep, hf_job_priority, NULL);
4496
4497
0
  offset = dissect_ndr_uint32(
4498
0
    tvb, offset, pinfo, subtree, di, drep, hf_job_position, NULL);
4499
4500
0
  offset = dissect_ndr_uint32(
4501
0
    tvb, offset, pinfo, NULL, di, drep, hf_start_time, NULL);
4502
4503
0
  offset = dissect_ndr_uint32(
4504
0
    tvb, offset, pinfo, NULL, di, drep, hf_end_time, NULL);
4505
4506
0
  offset = dissect_ndr_uint32(
4507
0
    tvb, offset, pinfo, subtree, di, drep, hf_job_totalpages, NULL);
4508
4509
0
  offset = dissect_ndr_uint32(
4510
0
    tvb, offset, pinfo, subtree, di, drep, hf_job_size, NULL);
4511
4512
0
  offset = dissect_SYSTEM_TIME(
4513
0
    tvb, offset, pinfo, subtree, di, drep, "Job Submission Time",
4514
0
    true, NULL);
4515
4516
0
  offset = dissect_ndr_uint32(
4517
0
    tvb, offset, pinfo, NULL, di, drep, hf_elapsed_time, NULL);
4518
4519
0
  offset = dissect_ndr_uint32(
4520
0
    tvb, offset, pinfo, subtree, di, drep, hf_job_pagesprinted, NULL);
4521
4522
0
  proto_item_set_len(item, offset - struct_start);
4523
4524
0
  return offset;
4525
0
}
4526
4527
/*
4528
 * EnumJobs
4529
 */
4530
4531
static int hf_enumjobs_firstjob;
4532
static int hf_enumjobs_numjobs;
4533
4534
static unsigned
4535
SpoolssEnumJobs_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4536
           proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4537
0
{
4538
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
4539
0
  uint32_t level;
4540
4541
  /* Parse packet */
4542
4543
0
  offset = dissect_nt_policy_hnd(
4544
0
    tvb, offset, pinfo, tree, di, drep,
4545
0
    hf_hnd, NULL, NULL, PIDL_POLHND_USE);
4546
4547
0
  offset = dissect_ndr_uint32(
4548
0
    tvb, offset, pinfo, tree, di, drep, hf_enumjobs_firstjob, NULL);
4549
4550
0
  offset = dissect_ndr_uint32(
4551
0
    tvb, offset, pinfo, tree, di, drep, hf_enumjobs_numjobs, NULL);
4552
4553
0
  offset = dissect_ndr_uint32(
4554
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
4555
4556
  /* EnumJobs() stores the level in se_data */
4557
0
  if(!pinfo->fd->visited){
4558
0
      dcv->se_data = GUINT_TO_POINTER((int)level);
4559
0
  }
4560
4561
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
4562
4563
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep, NULL);
4564
4565
0
  offset = dissect_ndr_uint32(
4566
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
4567
4568
0
  return offset;
4569
0
}
4570
4571
static unsigned
4572
SpoolssEnumJobs_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4573
           proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4574
0
{
4575
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
4576
0
  int16_t level = GPOINTER_TO_UINT(dcv->se_data);
4577
0
  BUFFER buffer;
4578
0
  uint32_t num_jobs, i;
4579
0
  int buffer_offset;
4580
4581
  /* Parse packet */
4582
4583
0
  offset = dissect_spoolss_buffer(
4584
0
    tvb, offset, pinfo, tree, di, drep, &buffer);
4585
4586
0
  offset = dissect_ndr_uint32(
4587
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
4588
4589
0
  offset = dissect_ndr_uint32(
4590
0
    tvb, offset, pinfo, tree, di, drep, hf_enumjobs_numjobs,
4591
0
    &num_jobs);
4592
4593
0
  buffer_offset = 0;
4594
4595
0
  for (i = 0; i < num_jobs; i++) {
4596
0
    switch(level) {
4597
0
    case 1:
4598
0
      buffer_offset = dissect_spoolss_JOB_INFO_1(
4599
0
        buffer.tvb, buffer_offset, pinfo,
4600
0
        buffer.tree, di, drep);
4601
0
      break;
4602
0
    case 2:
4603
0
      buffer_offset = dissect_spoolss_JOB_INFO_2(
4604
0
        buffer.tvb, buffer_offset, pinfo,
4605
0
        buffer.tree, di, drep);
4606
0
      break;
4607
0
    default:
4608
0
      proto_tree_add_expert_format_remaining( buffer.tree, pinfo, &ei_job_info_level, buffer.tvb, 0, "Unknown job info level %d", level);
4609
0
      break;
4610
0
    }
4611
4612
0
  }
4613
4614
0
  offset = dissect_doserror(
4615
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4616
4617
0
  return offset;
4618
0
}
4619
4620
/*
4621
 * SetJob
4622
 */
4623
4624
static const value_string setjob_commands[] = {
4625
  { JOB_CONTROL_PAUSE, "Pause" },
4626
  { JOB_CONTROL_RESUME, "Resume" },
4627
  { JOB_CONTROL_CANCEL, "Cancel" },
4628
  { JOB_CONTROL_RESTART, "Restart" },
4629
  { JOB_CONTROL_DELETE, "Delete" },
4630
  { 0, NULL }
4631
};
4632
4633
static int hf_setjob_cmd;
4634
4635
static unsigned
4636
SpoolssSetJob_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4637
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4638
0
{
4639
0
  uint32_t jobid, cmd;
4640
4641
  /* Parse packet */
4642
4643
0
  offset = dissect_nt_policy_hnd(
4644
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
4645
0
    PIDL_POLHND_USE);
4646
4647
0
  offset = dissect_ndr_uint32(
4648
0
    tvb, offset, pinfo, tree, di, drep, hf_job_id, &jobid);
4649
4650
0
  offset = dissect_ndr_uint32(
4651
0
    tvb, offset, pinfo, tree, di, drep, hf_level, NULL);
4652
4653
0
  offset = dissect_ndr_uint32(
4654
0
    tvb, offset, pinfo, tree, di, drep, hf_setjob_cmd, &cmd);
4655
4656
0
  col_append_fstr(
4657
0
      pinfo->cinfo, COL_INFO, ", %s jobid %d",
4658
0
      val_to_str(pinfo->pool, cmd, setjob_commands, "Unknown (%d)"),
4659
0
      jobid);
4660
4661
0
  return offset;
4662
0
}
4663
4664
static unsigned
4665
SpoolssSetJob_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4666
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4667
0
{
4668
  /* Parse packet */
4669
4670
0
  offset = dissect_doserror(
4671
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4672
4673
0
  return offset;
4674
0
}
4675
4676
/*
4677
 * GetJob
4678
 */
4679
4680
static unsigned
4681
SpoolssGetJob_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4682
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4683
0
{
4684
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
4685
0
  uint32_t level, jobid;
4686
4687
  /* Parse packet */
4688
4689
0
  offset = dissect_nt_policy_hnd(
4690
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
4691
0
    PIDL_POLHND_USE);
4692
4693
0
  offset = dissect_ndr_uint32(
4694
0
    tvb, offset, pinfo, tree, di, drep, hf_job_id, &jobid);
4695
4696
0
  offset = dissect_ndr_uint32(
4697
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
4698
4699
  /* GetJob() stores the level in se_data */
4700
0
  if(!pinfo->fd->visited){
4701
0
      dcv->se_data = GUINT_TO_POINTER((int)level);
4702
0
  }
4703
4704
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d, jobid %d",
4705
0
        level, jobid);
4706
4707
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep, NULL);
4708
4709
0
  offset = dissect_ndr_uint32(
4710
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
4711
4712
0
  return offset;
4713
0
}
4714
4715
static unsigned
4716
SpoolssGetJob_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4717
      proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4718
0
{
4719
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
4720
0
  int32_t level = GPOINTER_TO_UINT(dcv->se_data);
4721
0
  BUFFER buffer;
4722
4723
  /* Parse packet */
4724
4725
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep,
4726
0
          &buffer);
4727
4728
0
  if (buffer.tvb) {
4729
0
    int buffer_offset = 0;
4730
4731
0
    switch(level) {
4732
0
    case 1:
4733
0
      /*buffer_offset = */dissect_spoolss_JOB_INFO_1(
4734
0
        buffer.tvb, buffer_offset, pinfo,
4735
0
        buffer.tree, di, drep);
4736
0
      break;
4737
0
    case 2:
4738
0
    default:
4739
0
      proto_tree_add_expert_format_remaining( buffer.tree, pinfo, &ei_job_info_level, buffer.tvb, buffer_offset, "Unknown job info level %d", level);
4740
0
      break;
4741
0
    }
4742
0
  }
4743
4744
0
  offset = dissect_ndr_uint32(
4745
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
4746
4747
0
  offset = dissect_doserror(
4748
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4749
4750
0
  return offset;
4751
0
}
4752
4753
/*
4754
 * StartPagePrinter
4755
 */
4756
4757
static unsigned
4758
SpoolssStartPagePrinter_q(tvbuff_t *tvb, unsigned offset,
4759
             packet_info *pinfo, proto_tree *tree,
4760
             dcerpc_info *di, uint8_t *drep)
4761
0
{
4762
0
  e_ctx_hnd policy_hnd;
4763
0
  char *pol_name;
4764
4765
  /* Parse packet */
4766
4767
0
  offset = dissect_nt_policy_hnd(
4768
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, NULL,
4769
0
    PIDL_POLHND_USE);
4770
4771
0
  dcerpc_fetch_polhnd_data(&policy_hnd, &pol_name, NULL, NULL, NULL,
4772
0
           pinfo->num);
4773
4774
0
  if (pol_name)
4775
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
4776
0
        pol_name);
4777
4778
0
  return offset;
4779
0
}
4780
4781
static unsigned
4782
SpoolssStartPagePrinter_r(tvbuff_t *tvb, unsigned offset,
4783
             packet_info *pinfo, proto_tree *tree,
4784
             dcerpc_info *di, uint8_t *drep)
4785
0
{
4786
  /* Parse packet */
4787
4788
0
  offset = dissect_doserror(
4789
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4790
4791
0
  return offset;
4792
0
}
4793
4794
/*
4795
 * EndPagePrinter
4796
 */
4797
4798
static unsigned
4799
SpoolssEndPagePrinter_q(tvbuff_t *tvb, unsigned offset,
4800
           packet_info *pinfo, proto_tree *tree,
4801
           dcerpc_info *di, uint8_t *drep)
4802
0
{
4803
0
  e_ctx_hnd policy_hnd;
4804
0
  char *pol_name;
4805
4806
  /* Parse packet */
4807
4808
0
  offset = dissect_nt_policy_hnd(
4809
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, NULL,
4810
0
    PIDL_POLHND_USE);
4811
4812
0
  dcerpc_fetch_polhnd_data(&policy_hnd, &pol_name, NULL, NULL, NULL,
4813
0
           pinfo->num);
4814
4815
0
  if (pol_name)
4816
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
4817
0
        pol_name);
4818
4819
0
  return offset;
4820
0
}
4821
4822
static unsigned
4823
SpoolssEndPagePrinter_r(tvbuff_t *tvb, unsigned offset,
4824
           packet_info *pinfo, proto_tree *tree,
4825
           dcerpc_info *di, uint8_t *drep)
4826
0
{
4827
  /* Parse packet */
4828
4829
0
  offset = dissect_doserror(
4830
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4831
4832
0
  return offset;
4833
0
}
4834
4835
/*
4836
 * DOC_INFO_1
4837
 */
4838
4839
static int ett_DOC_INFO_1;
4840
4841
static unsigned
4842
dissect_spoolss_doc_info_1(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4843
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4844
0
{
4845
0
  proto_tree *subtree;
4846
4847
0
  subtree = proto_tree_add_subtree(
4848
0
    tree, tvb, offset, 0, ett_DOC_INFO_1, NULL, "Document info level 1");
4849
4850
0
  offset = dissect_ndr_str_pointer_item(
4851
0
    tvb, offset, pinfo, subtree, di, drep, NDR_POINTER_UNIQUE,
4852
0
    "Document name", hf_documentname, 0);
4853
4854
0
  offset = dissect_ndr_str_pointer_item(
4855
0
    tvb, offset, pinfo, subtree, di, drep, NDR_POINTER_UNIQUE,
4856
0
    "Output file", hf_outputfile, 0);
4857
4858
0
  offset = dissect_ndr_str_pointer_item(
4859
0
    tvb, offset, pinfo, subtree, di, drep, NDR_POINTER_UNIQUE,
4860
0
    "Data type", hf_datatype, 0);
4861
4862
0
  return offset;
4863
0
}
4864
4865
static unsigned
4866
dissect_spoolss_doc_info_data(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4867
            proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4868
0
{
4869
0
  if (di->conformant_run)
4870
0
    return offset;
4871
4872
0
  return dissect_spoolss_doc_info_1(tvb, offset, pinfo, tree, di, drep);
4873
0
}
4874
4875
/*
4876
 * DOC_INFO
4877
 */
4878
4879
static int ett_DOC_INFO;
4880
4881
static unsigned
4882
dissect_spoolss_doc_info(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4883
       proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4884
0
{
4885
0
  proto_tree *subtree;
4886
0
  uint32_t level;
4887
4888
0
  subtree = proto_tree_add_subtree(
4889
0
    tree, tvb, offset, 0, ett_DOC_INFO, NULL, "Document info");
4890
4891
0
  offset = dissect_ndr_uint32(
4892
0
    tvb, offset, pinfo, subtree, di, drep, hf_level, &level);
4893
4894
0
  offset = dissect_ndr_pointer(
4895
0
    tvb, offset, pinfo, subtree, di, drep,
4896
0
    dissect_spoolss_doc_info_data,
4897
0
    NDR_POINTER_UNIQUE, "Document info", -1);
4898
4899
0
  return offset;
4900
0
}
4901
4902
/*
4903
 * DOC_INFO_CTR
4904
 */
4905
4906
static int ett_DOC_INFO_CTR;
4907
4908
unsigned
4909
dissect_spoolss_doc_info_ctr(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
4910
           proto_tree *tree, dcerpc_info *di, uint8_t *drep)
4911
0
{
4912
0
  proto_tree *subtree;
4913
4914
0
  subtree = proto_tree_add_subtree(
4915
0
    tree, tvb, offset, 0, ett_DOC_INFO_CTR, NULL, "Document info container");
4916
4917
0
  offset = dissect_ndr_uint32(
4918
0
    tvb, offset, pinfo, subtree, di, drep, hf_level, NULL);
4919
4920
0
  offset = dissect_spoolss_doc_info(
4921
0
    tvb, offset, pinfo, subtree, di, drep);
4922
4923
0
  return offset;
4924
0
}
4925
4926
/*
4927
 * StartDocPrinter
4928
 */
4929
4930
static unsigned
4931
SpoolssStartDocPrinter_q(tvbuff_t *tvb, unsigned offset,
4932
            packet_info *pinfo, proto_tree *tree,
4933
            dcerpc_info *di, uint8_t *drep)
4934
0
{
4935
0
  e_ctx_hnd policy_hnd;
4936
0
  char *pol_name;
4937
4938
  /* Parse packet */
4939
4940
0
  offset = dissect_nt_policy_hnd(
4941
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, NULL,
4942
0
    PIDL_POLHND_USE);
4943
4944
0
  dcerpc_fetch_polhnd_data(&policy_hnd, &pol_name, NULL, NULL, NULL,
4945
0
           pinfo->num);
4946
4947
0
  if (pol_name)
4948
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
4949
0
        pol_name);
4950
4951
0
  offset = dissect_spoolss_doc_info_ctr(tvb, offset, pinfo, tree, di, drep);
4952
4953
0
  return offset;
4954
0
}
4955
4956
static unsigned
4957
SpoolssStartDocPrinter_r(tvbuff_t *tvb, unsigned offset,
4958
            packet_info *pinfo, proto_tree *tree,
4959
            dcerpc_info *di, uint8_t *drep)
4960
0
{
4961
  /* Parse packet */
4962
4963
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
4964
0
            hf_job_id, NULL);
4965
4966
0
  offset = dissect_doserror(
4967
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
4968
4969
0
  return offset;
4970
0
}
4971
4972
/*
4973
 * EndDocPrinter
4974
 */
4975
4976
static unsigned
4977
SpoolssEndDocPrinter_q(tvbuff_t *tvb, unsigned offset,
4978
          packet_info *pinfo, proto_tree *tree,
4979
          dcerpc_info *di, uint8_t *drep)
4980
0
{
4981
0
  e_ctx_hnd policy_hnd;
4982
0
  char *pol_name;
4983
4984
  /* Parse packet */
4985
4986
0
  offset = dissect_nt_policy_hnd(
4987
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, NULL,
4988
0
    PIDL_POLHND_USE);
4989
4990
0
  dcerpc_fetch_polhnd_data(&policy_hnd, &pol_name, NULL, NULL, NULL,
4991
0
           pinfo->num);
4992
4993
0
  if (pol_name)
4994
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
4995
0
        pol_name);
4996
4997
4998
0
  return offset;
4999
0
}
5000
5001
static unsigned
5002
SpoolssEndDocPrinter_r(tvbuff_t *tvb, unsigned offset,
5003
          packet_info *pinfo, proto_tree *tree,
5004
          dcerpc_info *di, uint8_t *drep)
5005
0
{
5006
  /* Parse packet */
5007
5008
0
  offset = dissect_doserror(
5009
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
5010
5011
0
  return offset;
5012
0
}
5013
5014
/*
5015
 * WritePrinter
5016
 */
5017
5018
static int ett_writeprinter_buffer;
5019
5020
static int hf_writeprinter_numwritten;
5021
5022
static unsigned
5023
SpoolssWritePrinter_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
5024
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
5025
0
{
5026
0
  e_ctx_hnd policy_hnd;
5027
0
  char *pol_name;
5028
0
  uint32_t size;
5029
0
  proto_item *item;
5030
0
  proto_tree *subtree;
5031
5032
  /* Parse packet */
5033
5034
0
  offset = dissect_nt_policy_hnd(
5035
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, NULL,
5036
0
    PIDL_POLHND_USE);
5037
5038
0
  dcerpc_fetch_polhnd_data(&policy_hnd, &pol_name, NULL, NULL, NULL,
5039
0
           pinfo->num);
5040
5041
0
  if (pol_name)
5042
0
    col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
5043
0
        pol_name);
5044
5045
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
5046
0
            hf_buffer_size, &size);
5047
5048
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %d bytes", size);
5049
5050
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_writeprinter_buffer, &item, "Buffer");
5051
5052
0
  offset = dissect_ndr_uint8s(tvb, offset, pinfo, subtree, di, drep,
5053
0
            hf_buffer_data, size, NULL);
5054
5055
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
5056
0
            hf_buffer_size, NULL);
5057
5058
0
  proto_item_set_len(item, size + 4);
5059
5060
0
  return offset;
5061
0
}
5062
5063
static unsigned
5064
SpoolssWritePrinter_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
5065
         proto_tree *tree, dcerpc_info *di, uint8_t *drep)
5066
0
{
5067
0
  uint32_t size;
5068
5069
  /* Parse packet */
5070
5071
0
  offset = dissect_ndr_uint32(
5072
0
    tvb, offset, pinfo, tree, di, drep, hf_writeprinter_numwritten,
5073
0
    &size);
5074
5075
0
  col_append_fstr(
5076
0
      pinfo->cinfo, COL_INFO, ", %d bytes written", size);
5077
5078
0
  offset = dissect_doserror(
5079
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
5080
5081
0
  return offset;
5082
0
}
5083
5084
/*
5085
 * DeletePrinterData
5086
 */
5087
5088
static unsigned
5089
SpoolssDeletePrinterData_q(tvbuff_t *tvb, unsigned offset,
5090
              packet_info *pinfo, proto_tree *tree,
5091
              dcerpc_info *di, uint8_t *drep)
5092
0
{
5093
0
  char *value_name;
5094
0
  proto_item *hidden_item;
5095
5096
0
  hidden_item = proto_tree_add_uint(
5097
0
    tree, hf_printerdata, tvb, offset, 0, 1);
5098
0
  proto_item_set_hidden(hidden_item);
5099
5100
  /* Parse packet */
5101
5102
0
  offset = dissect_nt_policy_hnd(
5103
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
5104
0
    PIDL_POLHND_USE);
5105
5106
0
  offset = dissect_ndr_cvstring(
5107
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
5108
0
    hf_printerdata_value, true, &value_name);
5109
5110
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", value_name);
5111
5112
0
  return offset;
5113
0
}
5114
5115
static unsigned
5116
SpoolssDeletePrinterData_r(tvbuff_t *tvb, unsigned offset,
5117
              packet_info *pinfo, proto_tree *tree,
5118
              dcerpc_info *di, uint8_t *drep)
5119
0
{
5120
0
  proto_item *hidden_item;
5121
5122
0
  hidden_item = proto_tree_add_uint(
5123
0
    tree, hf_printerdata, tvb, offset, 0, 1);
5124
0
  proto_item_set_hidden(hidden_item);
5125
5126
  /* Parse packet */
5127
5128
0
  offset = dissect_doserror(
5129
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
5130
5131
0
  return offset;
5132
0
}
5133
5134
/*
5135
 * DRIVER_INFO_1
5136
 */
5137
5138
static int ett_DRIVER_INFO_1;
5139
5140
static unsigned
5141
dissect_DRIVER_INFO_1(tvbuff_t *tvb, unsigned offset,
5142
         packet_info *pinfo, proto_tree *tree,
5143
         dcerpc_info *di, uint8_t *drep)
5144
0
{
5145
0
  proto_tree *subtree;
5146
0
  int struct_start = offset;
5147
5148
0
  subtree = proto_tree_add_subtree(
5149
0
    tree, tvb, offset, 0, ett_DRIVER_INFO_1, NULL, "Driver info level 1");
5150
5151
0
  offset = dissect_spoolss_relstr(
5152
0
    tvb, offset, pinfo, subtree, di, drep, hf_drivername,
5153
0
    struct_start, NULL);
5154
5155
0
  return offset;
5156
0
}
5157
5158
/*
5159
 * DRIVER_INFO_2
5160
 */
5161
5162
static const value_string driverinfo_cversion_vals[] =
5163
{
5164
  { 0, "Windows 95/98/Me" },
5165
  { 2, "Windows NT 4.0" },
5166
  { 3, "Windows 2000/XP" },
5167
  { 0, NULL }
5168
};
5169
5170
static int ett_DRIVER_INFO_2;
5171
5172
static unsigned
5173
dissect_DRIVER_INFO_2(tvbuff_t *tvb, unsigned offset,
5174
   packet_info *pinfo, proto_tree *tree,
5175
   dcerpc_info *di, uint8_t *drep)
5176
0
{
5177
0
  proto_tree *subtree;
5178
0
  int struct_start = offset;
5179
5180
0
  subtree = proto_tree_add_subtree(
5181
0
      tree, tvb, offset, 0, ett_DRIVER_INFO_2, NULL, "Driver info level 2");
5182
5183
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
5184
0
      hf_driverinfo_cversion, NULL);
5185
5186
0
  offset = dissect_spoolss_relstr(
5187
0
      tvb, offset, pinfo, subtree, di, drep, hf_drivername,
5188
0
      struct_start, NULL);
5189
5190
0
  offset = dissect_spoolss_relstr(
5191
0
      tvb, offset, pinfo, subtree, di, drep, hf_environment,
5192
0
      struct_start, NULL);
5193
5194
0
  offset = dissect_spoolss_relstr(
5195
0
      tvb, offset, pinfo, subtree, di, drep, hf_driverpath,
5196
0
      struct_start, NULL);
5197
5198
0
  offset = dissect_spoolss_relstr(
5199
0
      tvb, offset, pinfo, subtree, di, drep, hf_datafile,
5200
0
      struct_start, NULL);
5201
5202
0
  offset = dissect_spoolss_relstr(
5203
0
      tvb, offset, pinfo, subtree, di, drep, hf_configfile,
5204
0
      struct_start, NULL);
5205
5206
0
  return offset;
5207
0
}
5208
5209
/*
5210
 * DRIVER_INFO_3
5211
 */
5212
5213
static int ett_DRIVER_INFO_3;
5214
5215
static unsigned
5216
dissect_DRIVER_INFO_3(tvbuff_t *tvb, unsigned offset,
5217
         packet_info *pinfo, proto_tree *tree,
5218
         dcerpc_info *di, uint8_t *drep)
5219
0
{
5220
0
  proto_tree *subtree;
5221
0
  int struct_start = offset;
5222
5223
0
  subtree = proto_tree_add_subtree(
5224
0
    tree, tvb, offset, 0, ett_DRIVER_INFO_3, NULL, "Driver info level 3");
5225
5226
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
5227
0
            hf_driverinfo_cversion, NULL);
5228
5229
0
  offset = dissect_spoolss_relstr(
5230
0
    tvb, offset, pinfo, subtree, di, drep, hf_drivername,
5231
0
    struct_start, NULL);
5232
5233
0
  offset = dissect_spoolss_relstr(
5234
0
    tvb, offset, pinfo, subtree, di, drep, hf_environment,
5235
0
    struct_start, NULL);
5236
5237
0
  offset = dissect_spoolss_relstr(
5238
0
    tvb, offset, pinfo, subtree, di, drep, hf_driverpath,
5239
0
    struct_start, NULL);
5240
5241
0
  offset = dissect_spoolss_relstr(
5242
0
    tvb, offset, pinfo, subtree, di, drep, hf_datafile,
5243
0
    struct_start, NULL);
5244
5245
0
  offset = dissect_spoolss_relstr(
5246
0
    tvb, offset, pinfo, subtree, di, drep, hf_configfile,
5247
0
    struct_start, NULL);
5248
5249
0
  offset = dissect_spoolss_relstr(
5250
0
    tvb, offset, pinfo, subtree, di, drep, hf_helpfile,
5251
0
    struct_start, NULL);
5252
5253
0
  offset = dissect_spoolss_relstrarray(
5254
0
    tvb, offset, pinfo, subtree, di, drep, hf_dependentfiles,
5255
0
    struct_start, NULL);
5256
5257
0
  offset = dissect_spoolss_relstr(
5258
0
    tvb, offset, pinfo, subtree, di, drep, hf_monitorname,
5259
0
    struct_start, NULL);
5260
5261
0
  offset = dissect_spoolss_relstr(
5262
0
    tvb, offset, pinfo, subtree, di, drep, hf_defaultdatatype,
5263
0
    struct_start, NULL);
5264
5265
0
  return offset;
5266
0
}
5267
5268
5269
/*
5270
  DRIVER_INFO_6
5271
*/
5272
5273
static int ett_DRIVER_INFO_6;
5274
5275
static unsigned
5276
dissect_DRIVER_INFO_6(tvbuff_t *tvb, unsigned offset,
5277
         packet_info *pinfo, proto_tree *tree,
5278
         dcerpc_info *di, uint8_t *drep)
5279
0
{
5280
0
  proto_tree *subtree;
5281
0
  int struct_start = offset;
5282
5283
0
  subtree = proto_tree_add_subtree(
5284
0
      tree, tvb, offset, 0, ett_DRIVER_INFO_6, NULL, "Driver info level 6");
5285
5286
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
5287
0
      hf_driverinfo_cversion, NULL);
5288
5289
0
  offset = dissect_spoolss_relstr(
5290
0
      tvb, offset, pinfo, subtree, di, drep, hf_drivername,
5291
0
      struct_start, NULL);
5292
5293
0
  offset = dissect_spoolss_relstr(
5294
0
      tvb, offset, pinfo, subtree, di, drep, hf_environment,
5295
0
      struct_start, NULL);
5296
5297
0
  offset = dissect_spoolss_relstr(
5298
0
      tvb, offset, pinfo, subtree, di, drep, hf_driverpath,
5299
0
      struct_start, NULL);
5300
5301
0
  offset = dissect_spoolss_relstr(
5302
0
      tvb, offset, pinfo, subtree, di, drep, hf_datafile,
5303
0
      struct_start, NULL);
5304
5305
0
  offset = dissect_spoolss_relstr(
5306
0
      tvb, offset, pinfo, subtree, di, drep, hf_configfile,
5307
0
      struct_start, NULL);
5308
5309
0
  offset = dissect_spoolss_relstr(
5310
0
      tvb, offset, pinfo, subtree, di, drep, hf_helpfile,
5311
0
      struct_start, NULL);
5312
5313
0
  offset = dissect_spoolss_relstr(
5314
0
      tvb, offset, pinfo, subtree, di, drep, hf_monitorname,
5315
0
      struct_start, NULL);
5316
5317
0
  offset = dissect_spoolss_relstr(
5318
0
      tvb, offset, pinfo, subtree, di, drep, hf_defaultdatatype,
5319
0
      struct_start, NULL);
5320
5321
0
  offset = dissect_spoolss_relstrarray(
5322
0
      tvb, offset, pinfo, subtree, di, drep, hf_dependentfiles,
5323
0
      struct_start, NULL);
5324
5325
0
  offset = dissect_spoolss_relstrarray(
5326
0
      tvb, offset, pinfo, subtree, di, drep, hf_previousdrivernames,
5327
0
      struct_start, NULL);
5328
5329
0
  offset = dissect_ndr_nt_NTTIME (
5330
0
      tvb, offset, pinfo, subtree, di, drep,hf_driverdate);
5331
5332
0
  offset = dissect_ndr_uint32(
5333
0
      tvb, offset, pinfo, subtree, di, drep, hf_padding,
5334
0
      NULL);
5335
5336
0
  offset = dissect_ndr_uint32(
5337
0
      tvb, offset, pinfo, subtree, di, drep, hf_driver_version_low,
5338
0
      NULL);
5339
5340
0
  offset = dissect_ndr_uint32(
5341
0
      tvb, offset, pinfo, subtree, di, drep, hf_driver_version_high,
5342
0
      NULL);
5343
5344
0
  offset = dissect_spoolss_relstr(
5345
0
      tvb, offset, pinfo, subtree, di, drep, hf_mfgname,
5346
0
      struct_start, NULL);
5347
5348
0
  offset = dissect_spoolss_relstr(
5349
0
      tvb, offset, pinfo, subtree, di, drep, hf_oemurl,
5350
0
      struct_start, NULL);
5351
5352
0
  offset = dissect_spoolss_relstr(
5353
0
      tvb, offset, pinfo, subtree, di, drep, hf_hardwareid,
5354
0
      struct_start, NULL);
5355
5356
0
  offset = dissect_spoolss_relstr(
5357
0
      tvb, offset, pinfo, subtree, di, drep, hf_provider,
5358
0
      struct_start, NULL);
5359
5360
0
  return offset;
5361
0
}
5362
5363
5364
/*
5365
  DRIVER_INFO_8
5366
*/
5367
5368
static int ett_DRIVER_INFO_8;
5369
5370
static unsigned
5371
dissect_DRIVER_INFO_8(tvbuff_t *tvb, unsigned offset,
5372
         packet_info *pinfo, proto_tree *tree,
5373
         dcerpc_info *di, uint8_t *drep)
5374
0
{
5375
0
  proto_tree *subtree;
5376
0
  int struct_start = offset;
5377
5378
0
  subtree = proto_tree_add_subtree(
5379
0
      tree, tvb, offset, 0, ett_DRIVER_INFO_8, NULL, "Driver info level 8");
5380
5381
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
5382
0
      hf_driverinfo_cversion, NULL);
5383
5384
0
  offset = dissect_spoolss_relstr(
5385
0
      tvb, offset, pinfo, subtree, di, drep, hf_drivername,
5386
0
      struct_start, NULL);
5387
5388
0
  offset = dissect_spoolss_relstr(
5389
0
      tvb, offset, pinfo, subtree, di, drep, hf_environment,
5390
0
      struct_start, NULL);
5391
5392
0
  offset = dissect_spoolss_relstr(
5393
0
      tvb, offset, pinfo, subtree, di, drep, hf_driverpath,
5394
0
      struct_start, NULL);
5395
5396
0
  offset = dissect_spoolss_relstr(
5397
0
      tvb, offset, pinfo, subtree, di, drep, hf_datafile,
5398
0
      struct_start, NULL);
5399
5400
0
  offset = dissect_spoolss_relstr(
5401
0
      tvb, offset, pinfo, subtree, di, drep, hf_configfile,
5402
0
      struct_start, NULL);
5403
5404
0
  offset = dissect_spoolss_relstr(
5405
0
      tvb, offset, pinfo, subtree, di, drep, hf_helpfile,
5406
0
      struct_start, NULL);
5407
5408
0
  offset = dissect_spoolss_relstrarray(
5409
0
      tvb, offset, pinfo, subtree, di, drep, hf_dependentfiles,
5410
0
      struct_start, NULL);
5411
5412
0
  offset = dissect_spoolss_relstr(
5413
0
      tvb, offset, pinfo, subtree, di, drep, hf_monitorname,
5414
0
      struct_start, NULL);
5415
5416
0
  offset = dissect_spoolss_relstr(
5417
0
      tvb, offset, pinfo, subtree, di, drep, hf_defaultdatatype,
5418
0
      struct_start, NULL);
5419
5420
0
  offset = dissect_spoolss_relstrarray(
5421
0
      tvb, offset, pinfo, subtree, di, drep, hf_previousdrivernames,
5422
0
      struct_start, NULL);
5423
5424
0
  offset = dissect_ndr_nt_NTTIME (
5425
0
      tvb, offset, pinfo, subtree, di, drep, hf_driverdate);
5426
5427
0
  offset = dissect_ndr_uint32(
5428
0
      tvb, offset, pinfo, subtree, di, drep, hf_padding,
5429
0
      NULL);
5430
5431
0
  offset = dissect_ndr_uint32(
5432
0
      tvb, offset, pinfo, subtree, di, drep, hf_driver_version_low,
5433
0
      NULL);
5434
5435
0
  offset = dissect_ndr_uint32(
5436
0
      tvb, offset, pinfo, subtree, di, drep, hf_driver_version_high,
5437
0
      NULL);
5438
5439
0
  offset = dissect_spoolss_relstr(
5440
0
      tvb, offset, pinfo, subtree, di, drep, hf_mfgname,
5441
0
      struct_start, NULL);
5442
5443
0
  offset = dissect_spoolss_relstr(
5444
0
      tvb, offset, pinfo, subtree, di, drep, hf_oemurl,
5445
0
      struct_start, NULL);
5446
5447
0
  offset = dissect_spoolss_relstr(
5448
0
      tvb, offset, pinfo, subtree, di, drep, hf_hardwareid,
5449
0
      struct_start, NULL);
5450
5451
0
  offset = dissect_spoolss_relstr(
5452
0
      tvb, offset, pinfo, subtree, di, drep, hf_provider,
5453
0
      struct_start, NULL);
5454
5455
0
  offset = dissect_spoolss_relstr(
5456
0
      tvb, offset, pinfo, subtree, di, drep, hf_printprocessor,
5457
0
      struct_start, NULL);
5458
5459
0
  offset = dissect_spoolss_relstr(
5460
0
      tvb, offset, pinfo, subtree, di, drep, hf_vendor_setup,
5461
0
      struct_start, NULL);
5462
5463
0
  offset = dissect_spoolss_relstrarray(
5464
0
      tvb, offset, pinfo, subtree, di, drep, hf_color_profiles,
5465
0
      struct_start, NULL);
5466
5467
0
  offset = dissect_spoolss_relstr(
5468
0
      tvb, offset, pinfo, subtree, di, drep, hf_inf_path,
5469
0
      struct_start, NULL);
5470
5471
0
  offset = dissect_printer_driver_attributes(
5472
0
      tvb, offset, pinfo, subtree, di, drep);
5473
5474
0
  offset = dissect_spoolss_relstrarray(
5475
0
      tvb, offset, pinfo, subtree, di, drep, hf_core_driver_dependencies,
5476
0
      struct_start, NULL);
5477
5478
0
  offset = dissect_ndr_nt_NTTIME (
5479
0
      tvb, offset, pinfo, subtree, di, drep, hf_min_inbox_driverdate);
5480
5481
0
  offset = dissect_ndr_uint32(
5482
0
      tvb, offset, pinfo, subtree, di, drep, hf_min_inbox_driver_version_low,
5483
0
      NULL);
5484
5485
0
  offset = dissect_ndr_uint32(
5486
0
      tvb, offset, pinfo, subtree, di, drep, hf_min_inbox_driver_version_high,
5487
0
      NULL);
5488
5489
0
  return offset;
5490
0
}
5491
5492
5493
static int ett_DRIVER_INFO_101;
5494
5495
static unsigned
5496
dissect_DRIVER_INFO_101(tvbuff_t *tvb, unsigned offset,
5497
         packet_info *pinfo, proto_tree *tree,
5498
         dcerpc_info *di, uint8_t *drep)
5499
0
{
5500
0
  proto_tree *subtree;
5501
0
  int struct_start = offset;
5502
5503
0
  subtree = proto_tree_add_subtree(
5504
0
      tree, tvb, offset, 0, ett_DRIVER_INFO_101, NULL, "Driver info level 101");
5505
5506
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, subtree, di, drep,
5507
0
      hf_driverinfo_cversion, NULL);
5508
5509
0
  offset = dissect_spoolss_relstr(
5510
0
      tvb, offset, pinfo, subtree, di, drep, hf_drivername,
5511
0
      struct_start, NULL);
5512
5513
0
  offset = dissect_spoolss_relstr(
5514
0
      tvb, offset, pinfo, subtree, di, drep, hf_environment,
5515
0
      struct_start, NULL);
5516
5517
0
  proto_tree_add_expert(subtree, pinfo, &ei_unknown_data, tvb, offset, 0);
5518
5519
0
  return offset;
5520
0
}
5521
5522
/*
5523
  CORE_PRINTER_DRIVER
5524
*/
5525
5526
static int ett_CORE_PRINTER_DRIVER;
5527
5528
static unsigned
5529
dissect_CORE_PRINTER_DRIVER(tvbuff_t *tvb, unsigned offset,
5530
         packet_info *pinfo, proto_tree *tree,
5531
         dcerpc_info *di, uint8_t *drep)
5532
0
{
5533
0
  proto_tree *subtree;
5534
5535
0
  ALIGN_TO_5_BYTES;
5536
5537
0
  subtree = proto_tree_add_subtree(
5538
0
    tree, tvb, offset, 0, ett_CORE_PRINTER_DRIVER, NULL, "Core Printer Driver");
5539
5540
0
  offset = dissect_ndr_uuid_t(tvb, offset, pinfo, subtree, di, drep,
5541
0
    hf_core_driver_guid, NULL);
5542
5543
0
  offset = dissect_ndr_nt_NTTIME(tvb, offset, pinfo, subtree, di, drep,
5544
0
    hf_driverdate);
5545
5546
0
  offset = dissect_ndr_uint64(tvb, offset, pinfo, subtree, di, drep,
5547
0
    hf_driver_version, NULL);
5548
5549
  /* The package id is stored in a 260-wchar buffer */
5550
5551
0
  dissect_spoolss_uint16uni(tvb, offset, pinfo, subtree, drep, NULL,
5552
0
    hf_package_id);
5553
5554
0
  offset += 520;
5555
5556
0
  if (di->call_data->flags & DCERPC_IS_NDR64) {
5557
0
    ALIGN_TO_5_BYTES;
5558
0
  }
5559
5560
0
  return offset;
5561
0
}
5562
5563
5564
/*
5565
 * EnumPrinterDrivers
5566
 */
5567
5568
static unsigned
5569
SpoolssEnumPrinterDrivers_q(tvbuff_t *tvb, unsigned offset,
5570
               packet_info *pinfo, proto_tree *tree,
5571
               dcerpc_info *di, uint8_t *drep)
5572
0
{
5573
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
5574
0
  uint32_t level;
5575
5576
  /* Parse packet */
5577
5578
0
  offset = dissect_ndr_str_pointer_item(
5579
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
5580
0
    "Name", hf_servername, 0);
5581
5582
0
  offset = dissect_ndr_str_pointer_item(
5583
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
5584
0
    "Environment", hf_environment, 0);
5585
5586
0
  offset = dissect_ndr_uint32(
5587
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
5588
5589
  /* EnumPrinterDrivers() stores the level in se_data */
5590
0
  if(!pinfo->fd->visited){
5591
0
      dcv->se_data = GUINT_TO_POINTER((int)level);
5592
0
  }
5593
5594
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
5595
5596
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep, NULL);
5597
5598
0
  offset = dissect_ndr_uint32(
5599
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
5600
5601
0
  return offset;
5602
0
}
5603
5604
static unsigned
5605
SpoolssEnumPrinterDrivers_r(tvbuff_t *tvb, unsigned offset,
5606
               packet_info *pinfo, proto_tree *tree,
5607
               dcerpc_info *di, uint8_t *drep)
5608
0
{
5609
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
5610
0
  uint32_t level = GPOINTER_TO_UINT(dcv->se_data), num_drivers, i;
5611
0
  int buffer_offset;
5612
0
  BUFFER buffer;
5613
5614
  /* Parse packet */
5615
5616
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep,
5617
0
          &buffer);
5618
5619
0
  offset = dissect_ndr_uint32(
5620
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
5621
5622
0
  offset = dissect_ndr_uint32(
5623
0
    tvb, offset, pinfo, tree, di, drep, hf_returned,
5624
0
    &num_drivers);
5625
5626
0
  buffer_offset = 0;
5627
5628
0
  for (i = 0; i < num_drivers; i++) {
5629
0
    switch(level) {
5630
0
    case 1:
5631
0
      buffer_offset = dissect_DRIVER_INFO_1(
5632
0
        buffer.tvb, buffer_offset, pinfo,
5633
0
        buffer.tree, di, drep);
5634
0
      break;
5635
0
    case 2:
5636
0
      buffer_offset = dissect_DRIVER_INFO_2(
5637
0
        buffer.tvb, buffer_offset, pinfo,
5638
0
        buffer.tree, di, drep);
5639
0
      break;
5640
0
    case 3:
5641
0
      buffer_offset = dissect_DRIVER_INFO_3(
5642
0
        buffer.tvb, buffer_offset, pinfo,
5643
0
        buffer.tree, di, drep);
5644
0
      break;
5645
0
    case 6:
5646
0
      buffer_offset = dissect_DRIVER_INFO_6(
5647
0
        buffer.tvb, buffer_offset, pinfo,
5648
0
        buffer.tree, di, drep);
5649
0
      break;
5650
0
    case 8:
5651
0
      buffer_offset = dissect_DRIVER_INFO_8(
5652
0
        buffer.tvb, buffer_offset, pinfo,
5653
0
        buffer.tree, di, drep);
5654
0
      break;
5655
0
    case 101:
5656
0
      /*buffer_offset =*/ dissect_DRIVER_INFO_101(
5657
0
        buffer.tvb, buffer_offset, pinfo,
5658
0
        buffer.tree, di, drep);
5659
      /*break;*/
5660
0
      goto done; /*Not entirely implemented*/
5661
0
    default:
5662
0
      proto_tree_add_expert_format_remaining( buffer.tree, pinfo, &ei_driver_info_level, buffer.tvb, buffer_offset, "Unknown driver info level %d", level);
5663
0
      goto done;
5664
0
    }
5665
0
  }
5666
5667
0
done:
5668
0
  offset = dissect_doserror(
5669
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
5670
5671
0
  return offset;
5672
0
}
5673
5674
/*
5675
 * GetPrinterDriver2
5676
 */
5677
5678
static unsigned
5679
SpoolssGetPrinterDriver2_q(tvbuff_t *tvb, unsigned offset,
5680
              packet_info *pinfo, proto_tree *tree,
5681
              dcerpc_info *di, uint8_t *drep)
5682
0
{
5683
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
5684
0
  e_ctx_hnd policy_hnd;
5685
0
  char *pol_name;
5686
0
  uint32_t level;
5687
5688
  /* Parse packet */
5689
5690
0
  offset = dissect_nt_policy_hnd(
5691
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, &policy_hnd, NULL,
5692
0
    PIDL_POLHND_USE);
5693
5694
0
  dcerpc_fetch_polhnd_data(&policy_hnd, &pol_name, NULL, NULL, NULL,
5695
0
           pinfo->num);
5696
5697
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s",
5698
0
        pol_name);
5699
5700
0
  offset = dissect_ndr_str_pointer_item(
5701
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
5702
0
    "Environment", hf_environment, 0);
5703
5704
0
  offset = dissect_ndr_uint32(
5705
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
5706
5707
  /* GetPrinterDriver2() stores the level in se_data */
5708
0
  if(!pinfo->fd->visited){
5709
0
      dcv->se_data = GUINT_TO_POINTER((int)level);
5710
0
  }
5711
5712
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", level %d", level);
5713
5714
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep, NULL);
5715
5716
0
  offset = dissect_ndr_uint32(
5717
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
5718
5719
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
5720
0
            hf_clientmajorversion, NULL);
5721
5722
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
5723
0
            hf_clientminorversion, NULL);
5724
5725
0
  return offset;
5726
0
}
5727
5728
static unsigned
5729
SpoolssGetPrinterDriver2_r(tvbuff_t *tvb, unsigned offset,
5730
              packet_info *pinfo, proto_tree *tree,
5731
              dcerpc_info *di, uint8_t *drep)
5732
0
{
5733
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
5734
0
  uint32_t level = GPOINTER_TO_UINT(dcv->se_data);
5735
0
  BUFFER buffer;
5736
5737
  /* Parse packet */
5738
5739
0
  offset = dissect_spoolss_buffer(tvb, offset, pinfo, tree, di, drep,
5740
0
          &buffer);
5741
5742
0
  if (buffer.tvb) {
5743
0
    switch(level) {
5744
0
    case 1:
5745
0
      dissect_DRIVER_INFO_1(
5746
0
        buffer.tvb, 0, pinfo, buffer.tree, di, drep);
5747
0
      break;
5748
0
    case 2:
5749
0
      dissect_DRIVER_INFO_2(
5750
0
        buffer.tvb, 0, pinfo, buffer.tree, di, drep);
5751
0
      break;
5752
0
    case 3:
5753
0
      dissect_DRIVER_INFO_3(
5754
0
        buffer.tvb, 0, pinfo, buffer.tree, di, drep);
5755
0
      break;
5756
0
    case 6:
5757
0
      dissect_DRIVER_INFO_6(
5758
0
        buffer.tvb, 0, pinfo, buffer.tree, di, drep);
5759
0
      break;
5760
0
    case 8:
5761
0
      dissect_DRIVER_INFO_8(
5762
0
        buffer.tvb, 0, pinfo, buffer.tree, di, drep);
5763
0
      break;
5764
0
    case 101:
5765
0
      dissect_DRIVER_INFO_101(
5766
0
        buffer.tvb, 0, pinfo, buffer.tree, di, drep);
5767
0
      break;
5768
0
    default:
5769
0
      proto_tree_add_expert_format_remaining( buffer.tree, pinfo, &ei_driver_info_level, buffer.tvb, 0, "Unknown driver info level %d", level);
5770
0
      break;
5771
0
    }
5772
0
  }
5773
5774
0
  offset = dissect_ndr_uint32(
5775
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
5776
5777
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
5778
0
            hf_servermajorversion, NULL);
5779
5780
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
5781
0
            hf_serverminorversion, NULL);
5782
5783
0
  offset = dissect_doserror(
5784
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
5785
5786
0
  return offset;
5787
0
}
5788
5789
static unsigned
5790
dissect_notify_info_data_buffer(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
5791
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
5792
0
{
5793
0
  uint32_t len;
5794
5795
0
  offset = dissect_ndr_uint32(
5796
0
    tvb, offset, pinfo, tree, di, drep,
5797
0
    hf_notify_info_data_buffer_len, &len);
5798
5799
0
  offset = dissect_ndr_uint16s(
5800
0
    tvb, offset, pinfo, tree, di, drep,
5801
0
    hf_notify_info_data_buffer_data, len);
5802
5803
0
  return offset;
5804
0
}
5805
5806
static void
5807
cb_notify_str_postprocess(packet_info *pinfo _U_,
5808
              proto_tree *tree,
5809
              proto_item *item, dcerpc_info *di _U_, tvbuff_t *tvb,
5810
              unsigned start_offset, unsigned end_offset,
5811
              void *callback_args)
5812
0
{
5813
0
  int levels, hf_index = GPOINTER_TO_INT(callback_args);
5814
0
  uint32_t len;
5815
0
  char *s;
5816
0
  proto_item *hidden_item;
5817
5818
  /* Align start_offset on 4-byte boundary. */
5819
5820
0
  start_offset = WS_ROUNDUP_4(start_offset);
5821
5822
  /* Get string length */
5823
5824
0
  len = tvb_get_letohl(tvb, start_offset);
5825
5826
0
  s = (char*)tvb_get_string_enc(pinfo->pool,
5827
0
    tvb, start_offset + 4, (end_offset - start_offset - 4), ENC_UTF_16|ENC_LITTLE_ENDIAN);
5828
5829
  /* Append string to upper-level proto_items */
5830
5831
0
  levels = 2;
5832
5833
0
  if (levels > 0 && item && s && s[0]) {
5834
0
    proto_item_append_text(item, ": %s", s);
5835
0
    item = item->parent;
5836
0
    levels--;
5837
0
    if (levels > 0) {
5838
0
      proto_item_append_text(item, ": %s", s);
5839
0
      item = item->parent;
5840
0
      levels--;
5841
0
      while (levels > 0) {
5842
0
        proto_item_append_text(item, " %s", s);
5843
0
        item = item->parent;
5844
0
        levels--;
5845
0
      }
5846
0
    }
5847
0
  }
5848
5849
  /* Add hidden field so filter brings up any notify data */
5850
5851
0
  if (hf_index > 0) {
5852
0
    hidden_item = proto_tree_add_string(
5853
0
      tree, hf_index, tvb, start_offset, len, s);
5854
0
    proto_item_set_hidden(hidden_item);
5855
0
  }
5856
0
}
5857
5858
/* Return the hf_index for a printer notify field.  This is used to
5859
   add a hidden string to the display so that filtering will bring
5860
   up relevant notify data. */
5861
5862
static int
5863
printer_notify_hf_index(int field)
5864
0
{
5865
0
  int result = -1;
5866
5867
0
  switch(field) {
5868
0
  case PRINTER_NOTIFY_SERVER_NAME:
5869
0
    result = hf_servername;
5870
0
    break;
5871
0
  case PRINTER_NOTIFY_PRINTER_NAME:
5872
0
    result = hf_printername;
5873
0
    break;
5874
0
  case PRINTER_NOTIFY_SHARE_NAME:
5875
0
    result = hf_sharename;
5876
0
    break;
5877
0
  case PRINTER_NOTIFY_PORT_NAME:
5878
0
    result = hf_portname;
5879
0
    break;
5880
0
  case PRINTER_NOTIFY_DRIVER_NAME:
5881
0
    result = hf_drivername;
5882
0
    break;
5883
0
  case PRINTER_NOTIFY_COMMENT:
5884
0
    result = hf_printercomment;
5885
0
    break;
5886
0
  case PRINTER_NOTIFY_LOCATION:
5887
0
    result = hf_printerlocation;
5888
0
    break;
5889
0
  case PRINTER_NOTIFY_SEPFILE:
5890
0
    result = hf_sepfile;
5891
0
    break;
5892
0
  case PRINTER_NOTIFY_PRINT_PROCESSOR:
5893
0
    result = hf_printprocessor;
5894
0
    break;
5895
0
  case PRINTER_NOTIFY_PARAMETERS:
5896
0
    result = hf_parameters;
5897
0
    break;
5898
0
  case PRINTER_NOTIFY_DATATYPE:
5899
0
    result = hf_parameters;
5900
0
    break;
5901
0
  }
5902
5903
0
  return result;
5904
0
}
5905
5906
static int
5907
job_notify_hf_index(int field)
5908
0
{
5909
0
  int result = -1;
5910
5911
0
  switch(field) {
5912
0
  case JOB_NOTIFY_PRINTER_NAME:
5913
0
    result = hf_printername;
5914
0
    break;
5915
0
  case JOB_NOTIFY_MACHINE_NAME:
5916
0
    result = hf_machinename;
5917
0
    break;
5918
0
  case JOB_NOTIFY_PORT_NAME:
5919
0
    result = hf_portname;
5920
0
    break;
5921
0
  case JOB_NOTIFY_USER_NAME:
5922
0
    result = hf_username;
5923
0
    break;
5924
0
  case JOB_NOTIFY_NOTIFY_NAME:
5925
0
    result = hf_notifyname;
5926
0
    break;
5927
0
  case JOB_NOTIFY_DATATYPE:
5928
0
    result = hf_datatype;
5929
0
    break;
5930
0
  case JOB_NOTIFY_PRINT_PROCESSOR:
5931
0
    result = hf_printprocessor;
5932
0
    break;
5933
0
  case JOB_NOTIFY_DRIVER_NAME:
5934
0
    result = hf_drivername;
5935
0
    break;
5936
0
  case JOB_NOTIFY_DOCUMENT:
5937
0
    result = hf_documentname;
5938
0
    break;
5939
0
  case JOB_NOTIFY_PRIORITY:
5940
0
    result = hf_job_priority;
5941
0
    break;
5942
0
  case JOB_NOTIFY_POSITION:
5943
0
    result = hf_job_position;
5944
0
    break;
5945
0
  case JOB_NOTIFY_TOTAL_PAGES:
5946
0
    result = hf_job_totalpages;
5947
0
    break;
5948
0
  case JOB_NOTIFY_PAGES_PRINTED:
5949
0
    result = hf_job_pagesprinted;
5950
0
    break;
5951
0
  case JOB_NOTIFY_TOTAL_BYTES:
5952
0
    result = hf_job_totalbytes;
5953
0
    break;
5954
0
  case JOB_NOTIFY_BYTES_PRINTED:
5955
0
    result = hf_job_bytesprinted;
5956
0
    break;
5957
0
  }
5958
5959
0
  return result;
5960
0
}
5961
5962
static unsigned
5963
dissect_NOTIFY_INFO_DATA_printer(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
5964
         proto_tree *tree, proto_item *item,
5965
         dcerpc_info *di, uint8_t *drep, uint16_t field)
5966
0
{
5967
0
  uint32_t value1;
5968
5969
0
  switch (field) {
5970
5971
    /* String notify data */
5972
5973
0
  case PRINTER_NOTIFY_SERVER_NAME:
5974
0
  case PRINTER_NOTIFY_PRINTER_NAME:
5975
0
  case PRINTER_NOTIFY_SHARE_NAME:
5976
0
  case PRINTER_NOTIFY_DRIVER_NAME:
5977
0
  case PRINTER_NOTIFY_COMMENT:
5978
0
  case PRINTER_NOTIFY_LOCATION:
5979
0
  case PRINTER_NOTIFY_SEPFILE:
5980
0
  case PRINTER_NOTIFY_PRINT_PROCESSOR:
5981
0
  case PRINTER_NOTIFY_PARAMETERS:
5982
0
  case PRINTER_NOTIFY_DATATYPE:
5983
0
  case PRINTER_NOTIFY_PORT_NAME:
5984
5985
0
    offset = dissect_ndr_uint32(
5986
0
      tvb, offset, pinfo, tree, di, drep,
5987
0
      hf_notify_info_data_bufsize, &value1);
5988
5989
0
    offset = dissect_ndr_pointer_cb(
5990
0
      tvb, offset, pinfo, tree, di, drep,
5991
0
      dissect_notify_info_data_buffer,
5992
0
      NDR_POINTER_UNIQUE, "String",
5993
0
      hf_notify_info_data_buffer,
5994
0
      cb_notify_str_postprocess,
5995
0
      GINT_TO_POINTER(printer_notify_hf_index(field)));
5996
5997
0
    break;
5998
5999
0
  case PRINTER_NOTIFY_ATTRIBUTES:
6000
6001
    /* Value 1 is the printer attributes */
6002
6003
0
    offset = dissect_printer_attributes(
6004
0
      tvb, offset, pinfo, tree, di, drep);
6005
6006
0
    offset = dissect_ndr_uint32(
6007
0
      tvb, offset, pinfo, NULL, di, drep,
6008
0
      hf_notify_info_data_value2, NULL);
6009
6010
0
    break;
6011
6012
0
  case PRINTER_NOTIFY_STATUS: {
6013
0
    uint32_t status;
6014
6015
    /* Value 1 is the printer status */
6016
6017
0
    offset = dissect_ndr_uint32(
6018
0
      tvb, offset, pinfo, tree, di, drep,
6019
0
      hf_printer_status, &status);
6020
6021
0
    offset = dissect_ndr_uint32(
6022
0
      tvb, offset, pinfo, NULL, di, drep,
6023
0
      hf_notify_info_data_value2, NULL);
6024
6025
0
    proto_item_append_text(
6026
0
      item, ": %s",
6027
0
      val_to_str_ext_const(status, &printer_status_vals_ext, "Unknown"));
6028
6029
0
    break;
6030
0
  }
6031
6032
    /* Unknown notify data */
6033
6034
0
  case PRINTER_NOTIFY_SECURITY_DESCRIPTOR: /* Secdesc */
6035
0
  case PRINTER_NOTIFY_DEVMODE: /* Devicemode */
6036
6037
0
    offset = dissect_ndr_uint32(
6038
0
      tvb, offset, pinfo, tree, di, drep,
6039
0
      hf_notify_info_data_bufsize, &value1);
6040
6041
0
    offset = dissect_ndr_pointer(
6042
0
      tvb, offset, pinfo, tree, di, drep,
6043
0
      dissect_notify_info_data_buffer,
6044
0
      NDR_POINTER_UNIQUE, "Buffer",
6045
0
      hf_notify_info_data_buffer);
6046
6047
0
    break;
6048
6049
0
  default:
6050
0
    offset = dissect_ndr_uint32(
6051
0
      tvb, offset, pinfo, tree, di, drep,
6052
0
      hf_notify_info_data_value1, NULL);
6053
6054
0
    offset = dissect_ndr_uint32(
6055
0
      tvb, offset, pinfo, tree, di, drep,
6056
0
      hf_notify_info_data_value2, NULL);
6057
6058
0
    break;
6059
0
  }
6060
0
  return offset;
6061
0
}
6062
6063
static void
6064
notify_job_time_cb(packet_info *pinfo _U_, proto_tree *tree _U_,
6065
             proto_item *item, dcerpc_info *di, tvbuff_t *tvb _U_,
6066
             unsigned start_offset _U_, unsigned end_offset _U_,
6067
             void *callback_args _U_)
6068
0
{
6069
0
  dcerpc_call_value *dcv = (dcerpc_call_value *)di->call_data;
6070
0
  char *str = (char *)dcv->private_data;
6071
6072
  /* Append job string stored in dcv->private_data by
6073
     dissect_SYSTEM_TIME_ptr() in the current item as well
6074
     as the parent. */
6075
6076
0
  proto_item_append_text(item, ": %s", str);
6077
6078
0
  if (item)
6079
0
    proto_item_append_text(item->parent, ": %s", str);
6080
0
}
6081
6082
static unsigned
6083
dissect_NOTIFY_INFO_DATA_job(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6084
           proto_tree *tree, proto_item *item, dcerpc_info *di, uint8_t *drep,
6085
           uint16_t field)
6086
0
{
6087
0
  uint32_t value1;
6088
0
  proto_item *hidden_item;
6089
6090
0
  switch (field) {
6091
6092
    /* String notify data */
6093
6094
0
  case JOB_NOTIFY_PRINTER_NAME:
6095
0
  case JOB_NOTIFY_MACHINE_NAME:
6096
0
  case JOB_NOTIFY_PORT_NAME:
6097
0
  case JOB_NOTIFY_USER_NAME:
6098
0
  case JOB_NOTIFY_NOTIFY_NAME:
6099
0
  case JOB_NOTIFY_DATATYPE:
6100
0
  case JOB_NOTIFY_PRINT_PROCESSOR:
6101
0
  case JOB_NOTIFY_PARAMETERS:
6102
0
  case JOB_NOTIFY_DRIVER_NAME:
6103
0
  case JOB_NOTIFY_STATUS_STRING:
6104
0
  case JOB_NOTIFY_DOCUMENT:
6105
6106
0
    offset = dissect_ndr_uint32(
6107
0
      tvb, offset, pinfo, tree, di, drep,
6108
0
      hf_notify_info_data_bufsize, &value1);
6109
6110
0
    offset = dissect_ndr_pointer_cb(
6111
0
      tvb, offset, pinfo, tree, di, drep,
6112
0
      dissect_notify_info_data_buffer,
6113
0
      NDR_POINTER_UNIQUE, "String",
6114
0
      hf_notify_info_data_buffer,
6115
0
      cb_notify_str_postprocess,
6116
0
      GINT_TO_POINTER(job_notify_hf_index(field)));
6117
6118
0
    break;
6119
6120
0
  case JOB_NOTIFY_STATUS:
6121
0
    offset = dissect_job_status(
6122
0
      tvb, offset, pinfo, tree, di, drep);
6123
6124
0
    offset = dissect_ndr_uint32(
6125
0
      tvb, offset, pinfo, NULL, di, drep,
6126
0
      hf_notify_info_data_value2, NULL);
6127
6128
0
    break;
6129
6130
0
  case JOB_NOTIFY_SUBMITTED:
6131
6132
    /* SYSTEM_TIME */
6133
6134
0
    offset = dissect_ndr_uint32(
6135
0
      tvb, offset, pinfo, tree, di, drep,
6136
0
      hf_notify_info_data_buffer_len, NULL);
6137
6138
0
    offset = dissect_ndr_pointer_cb(
6139
0
      tvb, offset, pinfo, tree, di, drep,
6140
0
      dissect_SYSTEM_TIME_ptr, NDR_POINTER_UNIQUE,
6141
0
      "Time submitted", -1, notify_job_time_cb, NULL);
6142
6143
0
    break;
6144
6145
0
  case JOB_NOTIFY_PRIORITY:
6146
0
  case JOB_NOTIFY_POSITION:
6147
0
  case JOB_NOTIFY_TOTAL_PAGES:
6148
0
  case JOB_NOTIFY_PAGES_PRINTED:
6149
0
  case JOB_NOTIFY_TOTAL_BYTES:
6150
0
  case JOB_NOTIFY_BYTES_PRINTED: {
6151
0
    uint32_t value;
6152
6153
0
    offset = dissect_ndr_uint32(
6154
0
      tvb, offset, pinfo, tree, di, drep,
6155
0
      hf_notify_info_data_value1, &value);
6156
6157
0
    offset = dissect_ndr_uint32(
6158
0
      tvb, offset, pinfo, tree, di, drep,
6159
0
      hf_notify_info_data_value2, NULL);
6160
6161
0
    proto_item_append_text(item, ": %d", value);
6162
6163
0
    hidden_item = proto_tree_add_uint(
6164
0
      tree, job_notify_hf_index(field), tvb,
6165
0
      offset, 4, value);
6166
0
    proto_item_set_hidden(hidden_item);
6167
6168
0
    break;
6169
0
  }
6170
6171
    /* Unknown notify data */
6172
6173
0
  case JOB_NOTIFY_DEVMODE:
6174
6175
0
    offset = dissect_ndr_uint32(
6176
0
      tvb, offset, pinfo, tree, di, drep,
6177
0
      hf_notify_info_data_bufsize, &value1);
6178
6179
0
    offset = dissect_ndr_pointer(
6180
0
      tvb, offset, pinfo, tree, di, drep,
6181
0
      dissect_notify_info_data_buffer,
6182
0
      NDR_POINTER_UNIQUE, "Buffer",
6183
0
      hf_notify_info_data_buffer);
6184
6185
0
    break;
6186
6187
0
  default:
6188
0
    offset = dissect_ndr_uint32(
6189
0
      tvb, offset, pinfo, tree, di, drep,
6190
0
      hf_notify_info_data_value1, NULL);
6191
6192
0
    offset = dissect_ndr_uint32(
6193
0
      tvb, offset, pinfo, tree, di, drep,
6194
0
      hf_notify_info_data_value2, NULL);
6195
0
  }
6196
0
  return offset;
6197
0
}
6198
6199
static int ett_NOTIFY_INFO_DATA;
6200
6201
static unsigned
6202
dissect_NOTIFY_INFO_DATA(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6203
       proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6204
0
{
6205
0
  proto_item *item;
6206
0
  proto_tree *subtree;
6207
0
  uint32_t count;
6208
0
  uint16_t type, field;
6209
0
  const char *field_string;
6210
6211
0
  subtree = proto_tree_add_subtree(tree, tvb, offset, 0, ett_NOTIFY_INFO_DATA, &item, "");
6212
6213
0
  offset = dissect_ndr_uint16(
6214
0
    tvb, offset, pinfo, subtree, di, drep,
6215
0
    hf_notify_info_data_type, &type);
6216
6217
0
  offset = dissect_notify_field(
6218
0
    tvb, offset, pinfo, subtree, di, drep, type, &field);
6219
6220
0
  switch(type) {
6221
0
  case PRINTER_NOTIFY_TYPE:
6222
0
    field_string = val_to_str_ext(pinfo->pool,
6223
0
      field, &printer_notify_option_data_vals_ext,
6224
0
      "Unknown (%d)");
6225
0
    break;
6226
0
  case JOB_NOTIFY_TYPE:
6227
0
    field_string = val_to_str_ext(pinfo->pool,
6228
0
      field, &job_notify_option_data_vals_ext,
6229
0
      "Unknown (%d)");
6230
0
    break;
6231
0
  default:
6232
0
    field_string = "Unknown field";
6233
0
    break;
6234
0
  }
6235
6236
0
  proto_item_append_text(
6237
0
    item, "%s, %s",
6238
0
    val_to_str(pinfo->pool, type, printer_notify_types, "Unknown (%d)"),
6239
0
    field_string);
6240
6241
0
  offset = dissect_ndr_uint32(
6242
0
    tvb, offset, pinfo, subtree, di, drep,
6243
0
    hf_notify_info_data_count, &count);
6244
6245
0
  offset = dissect_ndr_uint32(
6246
0
    tvb, offset, pinfo, subtree, di, drep,
6247
0
    hf_notify_info_data_id, NULL);
6248
6249
0
  offset = dissect_ndr_uint32(
6250
0
    tvb, offset, pinfo, subtree, di, drep,
6251
0
    hf_notify_info_data_count, NULL);
6252
6253
  /* The value here depends on (type, field) */
6254
6255
0
  switch (type) {
6256
0
  case PRINTER_NOTIFY_TYPE:
6257
0
    offset = dissect_NOTIFY_INFO_DATA_printer(
6258
0
      tvb, offset, pinfo, subtree, item, di, drep, field);
6259
0
    break;
6260
0
  case JOB_NOTIFY_TYPE:
6261
0
    offset = dissect_NOTIFY_INFO_DATA_job(
6262
0
      tvb, offset, pinfo, subtree, item, di, drep, field);
6263
0
    break;
6264
0
  default:
6265
0
    expert_add_info(pinfo, item, &ei_notify_info_data_type);
6266
0
    break;
6267
0
  }
6268
6269
0
  return offset;
6270
0
}
6271
6272
unsigned
6273
dissect_NOTIFY_INFO(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6274
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6275
0
{
6276
0
  uint32_t count;
6277
6278
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
6279
0
            hf_notify_info_version, NULL);
6280
6281
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
6282
0
            hf_notify_info_flags, NULL);
6283
6284
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
6285
0
            hf_notify_info_count, &count);
6286
6287
0
  if (!di->conformant_run)
6288
0
    col_append_fstr(
6289
0
      pinfo->cinfo, COL_INFO, ", %d %s", count,
6290
0
      notify_plural(count));
6291
6292
0
  offset = dissect_ndr_ucarray(tvb, offset, pinfo, tree, di, drep,
6293
0
             dissect_NOTIFY_INFO_DATA);
6294
6295
0
  return offset;
6296
0
}
6297
6298
/*
6299
 * RFNPCNEX
6300
 */
6301
6302
static unsigned
6303
SpoolssRFNPCNEX_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6304
           proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6305
0
{
6306
0
  uint32_t changeid;
6307
6308
  /* Parse packet */
6309
6310
0
  offset = dissect_nt_policy_hnd(
6311
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6312
0
    PIDL_POLHND_USE);
6313
6314
0
  offset = dissect_ndr_uint32(
6315
0
    tvb, offset, pinfo, tree, di, drep, hf_rrpcn_changelow, &changeid);
6316
6317
0
  col_append_fstr(
6318
0
      pinfo->cinfo, COL_INFO, ", changeid %d", changeid);
6319
6320
0
  offset = dissect_ndr_pointer(
6321
0
    tvb, offset, pinfo, tree, di, drep,
6322
0
    dissect_NOTIFY_OPTIONS_ARRAY_CTR, NDR_POINTER_UNIQUE,
6323
0
    "Notify Options Array Container", -1);
6324
6325
0
  return offset;
6326
0
}
6327
6328
static unsigned
6329
SpoolssRFNPCNEX_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6330
           proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6331
0
{
6332
  /* Parse packet */
6333
6334
0
  offset = dissect_ndr_pointer(
6335
0
    tvb, offset, pinfo, tree, di, drep,
6336
0
    dissect_NOTIFY_INFO, NDR_POINTER_UNIQUE,
6337
0
    "Notify Info", -1);
6338
6339
0
  offset = dissect_doserror(
6340
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6341
6342
0
  return offset;
6343
0
}
6344
6345
/*
6346
 * RRPCN
6347
 */
6348
6349
static unsigned
6350
SpoolssRRPCN_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6351
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6352
0
{
6353
0
  uint32_t changeid;
6354
6355
  /* Parse packet */
6356
6357
0
  offset = dissect_nt_policy_hnd(
6358
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6359
0
    PIDL_POLHND_USE);
6360
6361
0
  offset = dissect_ndr_uint32(
6362
0
    tvb, offset, pinfo, tree, di, drep, hf_rrpcn_changelow, &changeid);
6363
6364
0
  col_append_fstr(
6365
0
      pinfo->cinfo, COL_INFO, ", changeid %d", changeid);
6366
6367
0
  offset = dissect_ndr_uint32(
6368
0
    tvb, offset, pinfo, tree, di, drep, hf_rrpcn_changehigh, NULL);
6369
6370
0
  offset = dissect_ndr_uint32(
6371
0
    tvb, offset, pinfo, tree, di, drep, hf_rrpcn_unk0, NULL);
6372
6373
0
  offset = dissect_ndr_uint32(
6374
0
    tvb, offset, pinfo, tree, di, drep, hf_rrpcn_unk1, NULL);
6375
6376
0
  offset = dissect_ndr_pointer(
6377
0
    tvb, offset, pinfo, tree, di, drep,
6378
0
    dissect_NOTIFY_INFO, NDR_POINTER_UNIQUE,
6379
0
    "Notify Info", -1);
6380
6381
  /* Notify info */
6382
6383
0
  return offset;
6384
0
}
6385
6386
static unsigned
6387
SpoolssRRPCN_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6388
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6389
0
{
6390
  /* Parse packet */
6391
6392
0
  offset = dissect_ndr_uint32(
6393
0
    tvb, offset, pinfo, tree, di, drep, hf_rrpcn_unk0, NULL);
6394
6395
0
  offset = dissect_doserror(
6396
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6397
6398
0
  return offset;
6399
0
}
6400
6401
/*
6402
 * ReplyClosePrinter
6403
 */
6404
6405
static unsigned
6406
SpoolssReplyClosePrinter_q(tvbuff_t *tvb, unsigned offset,
6407
              packet_info *pinfo, proto_tree *tree,
6408
              dcerpc_info *di, uint8_t *drep)
6409
0
{
6410
  /* Parse packet */
6411
6412
0
  offset = dissect_nt_policy_hnd(
6413
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6414
0
    PIDL_POLHND_CLOSE);
6415
6416
0
  return offset;
6417
0
}
6418
6419
static unsigned
6420
SpoolssReplyClosePrinter_r(tvbuff_t *tvb, unsigned offset,
6421
              packet_info *pinfo, proto_tree *tree,
6422
              dcerpc_info *di, uint8_t *drep)
6423
0
{
6424
  /* Parse packet */
6425
6426
0
  offset = dissect_nt_policy_hnd(
6427
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6428
0
    PIDL_POLHND_USE);
6429
6430
0
  offset = dissect_doserror(
6431
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6432
6433
0
  return offset;
6434
0
}
6435
6436
/*
6437
 * FCPN
6438
 */
6439
6440
static unsigned
6441
SpoolssFCPN_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6442
      proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6443
0
{
6444
  /* Parse packet */
6445
6446
0
  offset = dissect_nt_policy_hnd(
6447
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6448
0
    PIDL_POLHND_USE);
6449
6450
0
  return offset;
6451
0
}
6452
6453
static unsigned
6454
SpoolssFCPN_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6455
      proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6456
0
{
6457
  /* Parse packet */
6458
6459
0
  offset = dissect_doserror(
6460
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6461
6462
0
  return offset;
6463
0
}
6464
6465
/*
6466
 * RouterReplyPrinter
6467
 */
6468
6469
static int hf_routerreplyprinter_condition;
6470
static int hf_routerreplyprinter_unknown1;
6471
static int hf_routerreplyprinter_changeid;
6472
6473
static unsigned
6474
SpoolssRouterReplyPrinter_q(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6475
               proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6476
0
{
6477
  /* Parse packet */
6478
6479
0
  offset = dissect_nt_policy_hnd(
6480
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6481
0
    PIDL_POLHND_USE);
6482
6483
0
  offset = dissect_ndr_uint32(
6484
0
    tvb, offset, pinfo, tree, di, drep,
6485
0
    hf_routerreplyprinter_condition, NULL);
6486
6487
0
  offset = dissect_ndr_uint32(
6488
0
    tvb, offset, pinfo, tree, di, drep,
6489
0
    hf_routerreplyprinter_unknown1, NULL);
6490
6491
0
  offset = dissect_ndr_uint32(
6492
0
    tvb, offset, pinfo, tree, di, drep,
6493
0
    hf_routerreplyprinter_changeid, NULL);
6494
6495
0
  return offset;
6496
0
}
6497
6498
static unsigned
6499
SpoolssRouterReplyPrinter_r(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6500
               proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6501
0
{
6502
  /* Parse packet */
6503
6504
0
  offset = dissect_doserror(
6505
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6506
6507
0
  return offset;
6508
0
}
6509
6510
static int hf_keybuffer_size;
6511
6512
static unsigned
6513
dissect_spoolss_keybuffer(tvbuff_t *tvb, unsigned offset, packet_info *pinfo,
6514
        proto_tree *tree, dcerpc_info *di, uint8_t *drep)
6515
0
{
6516
0
  uint32_t size;
6517
0
  unsigned end_offset;
6518
6519
0
  if (di->conformant_run)
6520
0
    return offset;
6521
6522
  /* Dissect size and data */
6523
6524
0
  offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, di, drep,
6525
0
            hf_keybuffer_size, &size);
6526
6527
0
  end_offset = offset + (size*2);
6528
0
  if (end_offset < offset) {
6529
    /*
6530
     * Overflow - make the end offset one past the end of
6531
     * the packet data, so we throw an exception (as the
6532
     * size is almost certainly too big).
6533
     */
6534
0
    end_offset = tvb_reported_length_remaining(tvb, offset) + 1;
6535
0
  }
6536
6537
0
  while (offset > 0 && offset < end_offset) {
6538
0
    offset = dissect_spoolss_uint16uni(
6539
0
      tvb, offset, pinfo, tree, drep, NULL, hf_keybuffer);
6540
0
  }
6541
6542
0
  return offset;
6543
0
}
6544
6545
6546
static unsigned
6547
SpoolssEnumPrinterKey_q(tvbuff_t *tvb, unsigned offset,
6548
           packet_info *pinfo, proto_tree *tree,
6549
           dcerpc_info *di, uint8_t *drep)
6550
0
{
6551
0
  char *key_name;
6552
6553
  /* Parse packet */
6554
6555
0
  offset = dissect_nt_policy_hnd(
6556
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6557
0
    PIDL_POLHND_USE);
6558
6559
0
  offset = dissect_ndr_cvstring(
6560
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
6561
0
    hf_printerdata_key, true, &key_name);
6562
6563
0
  if (!key_name[0])
6564
0
    key_name = "\"\"";
6565
6566
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", key_name);
6567
6568
0
  offset = dissect_ndr_uint32(
6569
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
6570
6571
0
  return offset;
6572
0
}
6573
6574
static unsigned
6575
SpoolssEnumPrinterKey_r(tvbuff_t *tvb, unsigned offset,
6576
           packet_info *pinfo, proto_tree *tree,
6577
           dcerpc_info *di, uint8_t *drep)
6578
0
{
6579
  /* Parse packet */
6580
6581
0
  offset = dissect_spoolss_keybuffer(tvb, offset, pinfo, tree, di, drep);
6582
6583
0
  offset = dissect_ndr_uint32(
6584
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
6585
6586
0
  offset = dissect_doserror(
6587
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6588
6589
0
  return offset;
6590
0
}
6591
6592
static int hf_enumprinterdataex_name_offset;
6593
static int hf_enumprinterdataex_name_len;
6594
static int hf_enumprinterdataex_name;
6595
static int hf_enumprinterdataex_val_offset;
6596
static int hf_enumprinterdataex_val_len;
6597
static int hf_enumprinterdataex_val_dword_low;
6598
static int hf_enumprinterdataex_val_dword_high;
6599
static int hf_enumprinterdataex_value_null;
6600
static int hf_enumprinterdataex_value_uint;
6601
static int hf_enumprinterdataex_value_binary;
6602
static int hf_enumprinterdataex_value_multi_sz;
6603
6604
static unsigned
6605
SpoolssEnumPrinterDataEx_q(tvbuff_t *tvb, unsigned offset,
6606
              packet_info *pinfo, proto_tree *tree,
6607
              dcerpc_info *di, uint8_t *drep)
6608
0
{
6609
0
  char *key_name;
6610
0
  proto_item *hidden_item;
6611
6612
0
  hidden_item = proto_tree_add_uint(
6613
0
    tree, hf_printerdata, tvb, offset, 0, 1);
6614
0
  proto_item_set_hidden(hidden_item);
6615
6616
  /* Parse packet */
6617
6618
0
  offset = dissect_nt_policy_hnd(
6619
0
    tvb, offset, pinfo, tree, di, drep, hf_hnd, NULL, NULL,
6620
0
    PIDL_POLHND_USE);
6621
6622
0
  offset = dissect_ndr_cvstring(
6623
0
    tvb, offset, pinfo, tree, di, drep, sizeof(uint16_t),
6624
0
    hf_printerdata_key, true, &key_name);
6625
6626
0
  col_append_fstr(pinfo->cinfo, COL_INFO, ", %s", key_name);
6627
6628
0
  offset = dissect_ndr_uint32(
6629
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
6630
6631
0
  return offset;
6632
0
}
6633
6634
static int ett_printer_enumdataex_value;
6635
6636
static unsigned
6637
dissect_spoolss_printer_enum_values(tvbuff_t *tvb, unsigned offset,
6638
            packet_info *pinfo, proto_tree *tree,
6639
            dcerpc_info *di, uint8_t *drep)
6640
0
{
6641
0
  uint32_t start_offset = offset;
6642
0
  uint32_t name_offset, name_len, val_offset, val_len, val_type;
6643
0
  char *name;
6644
0
  proto_item *item;
6645
0
  proto_tree *subtree;
6646
6647
  /* Get offset of value name */
6648
6649
0
  offset = dissect_ndr_uint32(
6650
0
    tvb, offset, pinfo, NULL, di, drep,
6651
0
    hf_enumprinterdataex_name_offset, &name_offset);
6652
6653
0
  offset = dissect_ndr_uint32(
6654
0
    tvb, offset, pinfo, NULL, di, drep,
6655
0
    hf_enumprinterdataex_name_len, &name_len);
6656
6657
0
  dissect_spoolss_uint16uni(
6658
0
    tvb, start_offset + name_offset, pinfo, NULL, drep,
6659
0
    &name, hf_enumprinterdataex_name);
6660
6661
0
  subtree = proto_tree_add_subtree_format(tree, tvb, offset, 0, ett_printer_enumdataex_value, &item, "Name: %s", name);
6662
6663
0
  proto_tree_add_uint(subtree, hf_enumprinterdataex_name_offset, tvb, offset - 8, 4, name_offset);
6664
6665
0
  proto_tree_add_uint(subtree, hf_enumprinterdataex_name_len, tvb, offset - 4, 4, name_len);
6666
6667
0
  proto_tree_add_string( subtree, hf_enumprinterdataex_name, tvb, start_offset + name_offset, ((int)strlen(name) + 1) * 2, name);
6668
6669
0
  offset = dissect_ndr_uint32(
6670
0
    tvb, offset, pinfo, subtree, di, drep, hf_printerdata_type,
6671
0
    &val_type);
6672
6673
0
  offset = dissect_ndr_uint32(
6674
0
    tvb, offset, pinfo, subtree, di, drep,
6675
0
    hf_enumprinterdataex_val_offset, &val_offset);
6676
6677
0
  offset = dissect_ndr_uint32(
6678
0
    tvb, offset, pinfo, subtree, di, drep,
6679
0
    hf_enumprinterdataex_val_len, &val_len);
6680
6681
0
  if (val_len == 0) {
6682
0
    proto_tree_add_uint_format_value(subtree, hf_enumprinterdataex_value_null, tvb, start_offset + val_offset, 4, 0, "(null)");
6683
0
    return offset;
6684
0
  }
6685
6686
0
  switch(val_type) {
6687
0
  case DCERPC_REG_DWORD: {
6688
0
    uint32_t value;
6689
0
    uint16_t low, high;
6690
0
    unsigned offset2 = start_offset + val_offset;
6691
6692
    /* Needs to be broken into two 16-byte ints because it may
6693
       not be aligned. */
6694
6695
0
    offset2 = dissect_ndr_uint16(
6696
0
      tvb, offset2, pinfo, subtree, di, drep,
6697
0
      hf_enumprinterdataex_val_dword_low, &low);
6698
6699
    /*offset2 = */dissect_ndr_uint16(
6700
0
      tvb, offset2, pinfo, subtree, di, drep,
6701
0
      hf_enumprinterdataex_val_dword_high, &high);
6702
6703
0
    value = (high << 16) | low;
6704
6705
0
    proto_tree_add_uint(subtree, hf_enumprinterdataex_value_uint, tvb, start_offset + val_offset, 4, value);
6706
6707
0
    proto_item_append_text(item, ", Value: %d", value);
6708
6709
0
    break;
6710
0
  }
6711
0
  case DCERPC_REG_SZ: {
6712
0
    char *value;
6713
6714
0
    dissect_spoolss_uint16uni(
6715
0
      tvb, start_offset + val_offset, pinfo, subtree, drep,
6716
0
      &value, hf_value_string);
6717
6718
0
    proto_item_append_text(item, ", Value: %s", value);
6719
6720
0
    break;
6721
0
  }
6722
0
  case DCERPC_REG_BINARY:
6723
6724
    /* FIXME: nicer way to display this */
6725
6726
0
    proto_tree_add_bytes_format_value( subtree, hf_enumprinterdataex_value_binary, tvb, start_offset + val_offset, val_len, NULL, "<binary data>");
6727
0
    break;
6728
6729
0
  case DCERPC_REG_MULTI_SZ:
6730
6731
    /* FIXME: implement REG_MULTI_SZ support */
6732
6733
0
    proto_tree_add_bytes_format_value(subtree, hf_enumprinterdataex_value_multi_sz, tvb, start_offset + val_offset, val_len, NULL, "<REG_MULTI_SZ not implemented>");
6734
0
    break;
6735
6736
0
  default:
6737
0
    proto_tree_add_expert_format( subtree, pinfo, &ei_enumprinterdataex_value, tvb, start_offset + val_offset, val_len, "%s: unknown type %d", name, val_type);
6738
0
  }
6739
6740
0
  return offset;
6741
0
}
6742
6743
static int ett_PRINTER_DATA_CTR;
6744
6745
static unsigned
6746
SpoolssEnumPrinterDataEx_r(tvbuff_t *tvb, unsigned offset,
6747
           packet_info *pinfo, proto_tree *tree,
6748
           dcerpc_info *di, uint8_t *drep)
6749
0
{
6750
0
  uint32_t size, num_values;
6751
0
  proto_item *hidden_item;
6752
6753
0
  hidden_item = proto_tree_add_uint(
6754
0
    tree, hf_printerdata, tvb, offset, 0, 1);
6755
0
  proto_item_set_hidden(hidden_item);
6756
6757
  /* Parse packet */
6758
6759
0
  offset = dissect_ndr_uint32(
6760
0
    tvb, offset, pinfo, tree, di, drep,
6761
0
    hf_buffer_size, &size);
6762
6763
0
  dissect_ndr_uint32(
6764
0
    tvb, offset + size + 4, pinfo, NULL, di, drep, hf_returned,
6765
0
    &num_values);
6766
6767
0
  if (size) {
6768
0
    proto_tree *subtree;
6769
0
    unsigned offset2 = offset;
6770
0
    uint32_t i;
6771
6772
0
    subtree = proto_tree_add_subtree(
6773
0
      tree, tvb, offset, 0, ett_PRINTER_DATA_CTR, NULL, "Printer data");
6774
6775
0
    for (i=0; i < num_values; i++)
6776
0
      offset2 = dissect_spoolss_printer_enum_values(
6777
0
        tvb, offset2, pinfo, subtree, di, drep);
6778
0
  }
6779
6780
0
  offset += size;
6781
6782
0
  offset = dissect_ndr_uint32(
6783
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
6784
6785
0
  offset = dissect_ndr_uint32(
6786
0
    tvb, offset, pinfo, tree, di, drep, hf_returned, NULL);
6787
6788
0
  offset = dissect_doserror(
6789
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6790
6791
0
  return offset;
6792
0
}
6793
6794
static unsigned
6795
SpoolssGetPrinterDriverDirectory_q(tvbuff_t *tvb, unsigned offset,
6796
              packet_info *pinfo, proto_tree *tree,
6797
              dcerpc_info *di, uint8_t *drep)
6798
0
{
6799
0
  uint32_t level;
6800
6801
  /* Parse packet */
6802
6803
0
  offset = dissect_ndr_str_pointer_item(
6804
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
6805
0
    "Name", hf_servername, 0);
6806
6807
0
  offset = dissect_ndr_str_pointer_item(
6808
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
6809
0
    "Environment", hf_environment, 0);
6810
6811
0
  offset = dissect_ndr_uint32(
6812
0
    tvb, offset, pinfo, tree, di, drep, hf_level, &level);
6813
6814
0
  offset = dissect_spoolss_buffer(
6815
0
    tvb, offset, pinfo, tree, di, drep, NULL);
6816
6817
0
  offset = dissect_ndr_uint32(
6818
0
    tvb, offset, pinfo, tree, di, drep, hf_offered, NULL);
6819
6820
0
  return offset;
6821
0
}
6822
6823
static unsigned
6824
SpoolssGetPrinterDriverDirectory_r(tvbuff_t *tvb, unsigned offset,
6825
              packet_info *pinfo, proto_tree *tree,
6826
              dcerpc_info *di, uint8_t *drep)
6827
0
{
6828
  /* Parse packet */
6829
6830
0
  offset = dissect_spoolss_string_parm(
6831
0
    tvb, offset, pinfo, tree, di, drep, "Directory");
6832
6833
0
  offset = dissect_ndr_uint32(
6834
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
6835
6836
0
  offset = dissect_doserror(
6837
0
    tvb, offset, pinfo, tree, di, drep, hf_rc, NULL);
6838
6839
0
  return offset;
6840
0
}
6841
6842
static unsigned
6843
SpoolssGetCorePrinterDrivers_q(tvbuff_t *tvb, unsigned offset,
6844
             packet_info *pinfo, proto_tree *tree,
6845
             dcerpc_info *di, uint8_t *drep)
6846
0
{
6847
  /* Parse packet */
6848
6849
0
  offset = dissect_ndr_str_pointer_item(
6850
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
6851
0
    "Name", hf_servername, 0);
6852
6853
0
  offset = dissect_ndr_str_pointer_item(
6854
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_REF,
6855
0
    "Environment", hf_environment, 0);
6856
6857
0
  offset = dissect_ndr_uint32(
6858
0
    tvb, offset, pinfo, tree, di, drep,
6859
0
    hf_offered, NULL);
6860
0
#if 1
6861
0
  offset = dissect_spoolss_keybuffer(
6862
0
    tvb, offset, pinfo, tree, di, drep);
6863
#else
6864
  offset = dissect_ndr_uint32(
6865
    tvb, offset, pinfo, tree, di, drep,
6866
    hf_core_driver_size, NULL);
6867
6868
  offset = dissect_spoolss_uint16uni(
6869
    tvb, offset, pinfo, tree, drep,
6870
    NULL, hf_core_printer_driver_ids);
6871
#endif
6872
0
  offset = dissect_ndr_uint32(
6873
0
    tvb, offset, pinfo, tree, di, drep,
6874
0
    hf_core_printer_driver_count, NULL);
6875
6876
0
  return offset;
6877
0
}
6878
6879
static unsigned
6880
SpoolssGetCorePrinterDrivers_r(tvbuff_t *tvb, unsigned offset,
6881
             packet_info *pinfo, proto_tree *tree,
6882
             dcerpc_info *di, uint8_t *drep)
6883
0
{
6884
0
  uint32_t num_drivers, i;
6885
6886
  /* Parse packet */
6887
6888
0
  offset = dissect_ndr_uint32(
6889
0
    tvb, offset, pinfo, tree, di, drep,
6890
0
    hf_core_printer_driver_count,
6891
0
    &num_drivers);
6892
6893
0
  offset = dissect_ndr_uint32(
6894
0
    tvb, offset, pinfo, tree, di, drep, hf_core_printer_driver_ids,
6895
0
    NULL);
6896
6897
0
  for (i = 0; i < num_drivers; i++) {
6898
0
    offset = dissect_CORE_PRINTER_DRIVER(
6899
0
      tvb, offset, pinfo,
6900
0
      tree, di, drep);
6901
0
  }
6902
6903
0
  offset = dissect_hresult(
6904
0
    tvb, offset, pinfo, tree, di, drep, hf_hresult, NULL);
6905
6906
0
  return offset;
6907
0
}
6908
6909
static unsigned
6910
SpoolssGetPrinterDriverPackagePath_q(tvbuff_t *tvb, unsigned offset,
6911
             packet_info *pinfo, proto_tree *tree,
6912
             dcerpc_info *di, uint8_t *drep)
6913
0
{
6914
  /* Parse packet */
6915
6916
0
  offset = dissect_ndr_str_pointer_item(
6917
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
6918
0
    "Name", hf_servername, 0);
6919
6920
0
  offset = dissect_ndr_str_pointer_item(
6921
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_REF,
6922
0
    "Environment", hf_environment, 0);
6923
6924
0
  offset = dissect_ndr_str_pointer_item(
6925
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_UNIQUE,
6926
0
    "Language", hf_language, 0);
6927
6928
0
  offset = dissect_ndr_str_pointer_item(
6929
0
    tvb, offset, pinfo, tree, di, drep, NDR_POINTER_REF,
6930
0
    "PackageId", hf_package_id, 0);
6931
6932
0
  offset = dissect_spoolss_buffer(
6933
0
    tvb, offset, pinfo, tree, di, drep, NULL);
6934
6935
0
  offset = dissect_ndr_uint32(
6936
0
    tvb, offset, pinfo, tree, di, drep,
6937
0
    hf_driver_package_cab_size, NULL);
6938
6939
0
  return offset;
6940
0
}
6941
6942
static unsigned
6943
SpoolssGetPrinterDriverPackagePath_r(tvbuff_t *tvb, unsigned offset,
6944
             packet_info *pinfo, proto_tree *tree,
6945
             dcerpc_info *di, uint8_t *drep)
6946
0
{
6947
  /* Parse packet */
6948
6949
0
  offset = dissect_spoolss_string_parm(
6950
0
    tvb, offset, pinfo, tree, di, drep, "DriverPackageCab");
6951
6952
0
  offset = dissect_ndr_uint32(
6953
0
    tvb, offset, pinfo, tree, di, drep, hf_needed, NULL);
6954
6955
0
  offset = dissect_hresult(
6956
0
    tvb, offset, pinfo, tree, di, drep, hf_hresult, NULL);
6957
6958
0
  return offset;
6959
0
}
6960
6961
/*
6962
 * List of subdissectors for this pipe.
6963
 */
6964
6965
static const dcerpc_sub_dissector dcerpc_spoolss_dissectors[] = {
6966
  { SPOOLSS_ENUMPRINTERS, "EnumPrinters",
6967
    SpoolssEnumPrinters_q, SpoolssEnumPrinters_r },
6968
  { SPOOLSS_OPENPRINTER, "OpenPrinter",
6969
    NULL, SpoolssGeneric_r },
6970
  { SPOOLSS_SETJOB, "SetJob",
6971
    SpoolssSetJob_q, SpoolssSetJob_r },
6972
  { SPOOLSS_GETJOB, "GetJob",
6973
    SpoolssGetJob_q, SpoolssGetJob_r },
6974
  { SPOOLSS_ENUMJOBS, "EnumJobs",
6975
    SpoolssEnumJobs_q, SpoolssEnumJobs_r },
6976
  { SPOOLSS_ADDPRINTER, "AddPrinter",
6977
    NULL, SpoolssGeneric_r },
6978
  { SPOOLSS_DELETEPRINTER, "DeletePrinter",
6979
    SpoolssDeletePrinter_q, SpoolssDeletePrinter_r },
6980
  { SPOOLSS_SETPRINTER, "SetPrinter",
6981
    SpoolssSetPrinter_q, SpoolssSetPrinter_r },
6982
  { SPOOLSS_GETPRINTER, "GetPrinter",
6983
    SpoolssGetPrinter_q, SpoolssGetPrinter_r },
6984
  { SPOOLSS_ADDPRINTERDRIVER, "AddPrinterDriver",
6985
    NULL, SpoolssAddPrinterDriver_r },
6986
  { SPOOLSS_ENUMPRINTERDRIVERS, "EnumPrinterDrivers",
6987
    SpoolssEnumPrinterDrivers_q, SpoolssEnumPrinterDrivers_r },
6988
  { SPOOLSS_GETPRINTERDRIVER, "GetPrinterDriver",
6989
    NULL, SpoolssGeneric_r },
6990
  { SPOOLSS_GETPRINTERDRIVERDIRECTORY, "GetPrinterDriverDirectory",
6991
    SpoolssGetPrinterDriverDirectory_q, SpoolssGetPrinterDriverDirectory_r },
6992
  { SPOOLSS_DELETEPRINTERDRIVER, "DeletePrinterDriver",
6993
    NULL, SpoolssGeneric_r },
6994
  { SPOOLSS_ADDPRINTPROCESSOR, "AddPrintProcessor",
6995
    NULL, SpoolssGeneric_r },
6996
  { SPOOLSS_ENUMPRINTPROCESSORS, "EnumPrintProcessor",
6997
    NULL, SpoolssGeneric_r },
6998
  { SPOOLSS_GETPRINTPROCESSORDIRECTORY, "GetPrintProcessorDirectory",
6999
    NULL, SpoolssGeneric_r },
7000
  { SPOOLSS_STARTDOCPRINTER, "StartDocPrinter",
7001
    SpoolssStartDocPrinter_q, SpoolssStartDocPrinter_r },
7002
  { SPOOLSS_STARTPAGEPRINTER, "StartPagePrinter",
7003
    SpoolssStartPagePrinter_q, SpoolssStartPagePrinter_r },
7004
  { SPOOLSS_WRITEPRINTER, "WritePrinter",
7005
    SpoolssWritePrinter_q, SpoolssWritePrinter_r },
7006
  { SPOOLSS_ENDPAGEPRINTER, "EndPagePrinter",
7007
    SpoolssEndPagePrinter_q, SpoolssEndPagePrinter_r },
7008
  { SPOOLSS_ABORTPRINTER, "AbortPrinter",
7009
    NULL, SpoolssGeneric_r },
7010
  { SPOOLSS_READPRINTER, "ReadPrinter",
7011
    NULL, SpoolssGeneric_r },
7012
  { SPOOLSS_ENDDOCPRINTER, "EndDocPrinter",
7013
    SpoolssEndDocPrinter_q, SpoolssEndDocPrinter_r },
7014
  { SPOOLSS_ADDJOB, "AddJob",
7015
    NULL, SpoolssGeneric_r },
7016
  { SPOOLSS_SCHEDULEJOB, "ScheduleJob",
7017
    NULL, SpoolssGeneric_r },
7018
  { SPOOLSS_GETPRINTERDATA, "GetPrinterData",
7019
    SpoolssGetPrinterData_q, SpoolssGetPrinterData_r },
7020
  { SPOOLSS_SETPRINTERDATA, "SetPrinterData",
7021
    SpoolssSetPrinterData_q, SpoolssSetPrinterData_r },
7022
  { SPOOLSS_WAITFORPRINTERCHANGE, "WaitForPrinterChange",
7023
    NULL, SpoolssGeneric_r },
7024
  { SPOOLSS_CLOSEPRINTER, "ClosePrinter",
7025
    SpoolssClosePrinter_q, SpoolssClosePrinter_r },
7026
  { SPOOLSS_ADDFORM, "AddForm",
7027
    SpoolssAddForm_q, SpoolssAddForm_r },
7028
  { SPOOLSS_DELETEFORM, "DeleteForm",
7029
    SpoolssDeleteForm_q, SpoolssDeleteForm_r },
7030
  { SPOOLSS_GETFORM, "GetForm",
7031
    SpoolssGetForm_q, SpoolssGetForm_r },
7032
  { SPOOLSS_SETFORM, "SetForm",
7033
    SpoolssSetForm_q, SpoolssSetForm_r },
7034
  { SPOOLSS_ENUMFORMS, "EnumForms",
7035
    SpoolssEnumForms_q, SpoolssEnumForms_r },
7036
  { SPOOLSS_ENUMPORTS, "EnumPorts",
7037
    NULL, SpoolssGeneric_r },
7038
  { SPOOLSS_ENUMMONITORS, "EnumMonitors",
7039
    NULL, SpoolssGeneric_r },
7040
  { SPOOLSS_ADDPORT, "AddPort",
7041
    NULL, SpoolssGeneric_r },
7042
  { SPOOLSS_CONFIGUREPORT, "ConfigurePort",
7043
    NULL, SpoolssGeneric_r },
7044
  { SPOOLSS_DELETEPORT, "DeletePort",
7045
    NULL, SpoolssGeneric_r },
7046
  { SPOOLSS_CREATEPRINTERIC, "CreatePrinterIC",
7047
    NULL, SpoolssGeneric_r },
7048
  { SPOOLSS_PLAYGDISCRIPTONPRINTERIC, "PlayDiscriptOnPrinterIC",
7049
    NULL, SpoolssGeneric_r },
7050
  { SPOOLSS_DELETEPRINTERIC, "DeletePrinterIC",
7051
    NULL, SpoolssGeneric_r },
7052
  { SPOOLSS_ADDPRINTERCONNECTION, "AddPrinterConnection",
7053
    NULL, SpoolssGeneric_r },
7054
  { SPOOLSS_DELETEPRINTERCONNECTION, "DeletePrinterConnection",
7055
    NULL, SpoolssGeneric_r },
7056
  { SPOOLSS_PRINTERMESSAGEBOX, "PrinterMessageBox",
7057
    NULL, SpoolssGeneric_r },
7058
  { SPOOLSS_ADDMONITOR, "AddMonitor",
7059
    NULL, SpoolssGeneric_r },
7060
  { SPOOLSS_DELETEMONITOR, "DeleteMonitor",
7061
    NULL, SpoolssGeneric_r },
7062
  { SPOOLSS_DELETEPRINTPROCESSOR, "DeletePrintProcessor",
7063
    NULL, SpoolssGeneric_r },
7064
  { SPOOLSS_ADDPRINTPROVIDER, "AddPrintProvider",
7065
    NULL, SpoolssGeneric_r },
7066
  { SPOOLSS_DELETEPRINTPROVIDER, "DeletePrintProvider",
7067
    NULL, SpoolssGeneric_r },
7068
  { SPOOLSS_ENUMPRINTPROCDATATYPES, "EnumPrintProcDataTypes",
7069
    NULL, SpoolssGeneric_r },
7070
  { SPOOLSS_RESETPRINTER, "ResetPrinter",
7071
    NULL, SpoolssGeneric_r },
7072
  { SPOOLSS_GETPRINTERDRIVER2, "GetPrinterDriver2",
7073
    SpoolssGetPrinterDriver2_q, SpoolssGetPrinterDriver2_r },
7074
  { SPOOLSS_FINDFIRSTPRINTERCHANGENOTIFICATION,
7075
    "FindFirstPrinterChangeNotification",
7076
    NULL, SpoolssGeneric_r },
7077
  { SPOOLSS_FINDNEXTPRINTERCHANGENOTIFICATION,
7078
    "FindNextPrinterChangeNotification",
7079
    NULL, SpoolssGeneric_r },
7080
  { SPOOLSS_FCPN, "FCPN",
7081
    SpoolssFCPN_q, SpoolssFCPN_r },
7082
  { SPOOLSS_ROUTERFINDFIRSTPRINTERNOTIFICATIONOLD,
7083
    "RouterFindFirstPrinterNotificationOld",
7084
    NULL, SpoolssGeneric_r },
7085
  { SPOOLSS_REPLYOPENPRINTER, "ReplyOpenPrinter",
7086
    SpoolssReplyOpenPrinter_q, SpoolssReplyOpenPrinter_r },
7087
  { SPOOLSS_ROUTERREPLYPRINTER, "RouterReplyPrinter",
7088
    SpoolssRouterReplyPrinter_q, SpoolssRouterReplyPrinter_r },
7089
  { SPOOLSS_REPLYCLOSEPRINTER, "ReplyClosePrinter",
7090
    SpoolssReplyClosePrinter_q, SpoolssReplyClosePrinter_r },
7091
  { SPOOLSS_ADDPORTEX, "AddPortEx",
7092
    NULL, SpoolssGeneric_r },
7093
  { SPOOLSS_REMOTEFINDFIRSTPRINTERCHANGENOTIFICATION,
7094
    "RemoteFindFirstPrinterChangeNotification",
7095
    NULL, SpoolssGeneric_r },
7096
  { SPOOLSS_SPOOLERINIT, "SpoolerInit",
7097
    NULL, SpoolssGeneric_r },
7098
  { SPOOLSS_RESETPRINTEREX, "ResetPrinterEx",
7099
    NULL, SpoolssGeneric_r },
7100
  { SPOOLSS_RFFPCNEX, "RFFPCNEX",
7101
    SpoolssRFFPCNEX_q, SpoolssRFFPCNEX_r },
7102
  { SPOOLSS_RRPCN, "RRPCN",
7103
    SpoolssRRPCN_q, SpoolssRRPCN_r },
7104
  { SPOOLSS_RFNPCNEX, "RFNPCNEX",
7105
    SpoolssRFNPCNEX_q, SpoolssRFNPCNEX_r },
7106
  { SPOOLSS_OPENPRINTEREX, "OpenPrinterEx",
7107
    SpoolssOpenPrinterEx_q, SpoolssOpenPrinterEx_r },
7108
  { SPOOLSS_ADDPRINTEREX, "AddPrinterEx",
7109
    NULL, SpoolssAddPrinterEx_r },
7110
  { SPOOLSS_ENUMPRINTERDATA, "EnumPrinterData",
7111
    SpoolssEnumPrinterData_q, SpoolssEnumPrinterData_r },
7112
  { SPOOLSS_DELETEPRINTERDATA, "DeletePrinterData",
7113
    SpoolssDeletePrinterData_q, SpoolssDeletePrinterData_r },
7114
  { SPOOLSS_GETPRINTERDATAEX, "GetPrinterDataEx",
7115
    SpoolssGetPrinterDataEx_q, SpoolssGetPrinterDataEx_r },
7116
  { SPOOLSS_SETPRINTERDATAEX, "SetPrinterDataEx",
7117
    SpoolssSetPrinterDataEx_q, SpoolssSetPrinterDataEx_r },
7118
  { SPOOLSS_ENUMPRINTERDATAEX, "EnumPrinterDataEx",
7119
    SpoolssEnumPrinterDataEx_q, SpoolssEnumPrinterDataEx_r },
7120
  { SPOOLSS_ENUMPRINTERKEY, "EnumPrinterKey",
7121
    SpoolssEnumPrinterKey_q, SpoolssEnumPrinterKey_r },
7122
  { SPOOLSS_DELETEPRINTERDATAEX, "DeletePrinterDataEx",
7123
    NULL, SpoolssGeneric_r },
7124
  { SPOOLSS_DELETEPRINTERDRIVEREX, "DeletePrinterDriverEx",
7125
    NULL, SpoolssGeneric_r },
7126
  { SPOOLSS_ADDPRINTERDRIVEREX, "AddPrinterDriverEx",
7127
    NULL, SpoolssGeneric_r },
7128
  { SPOOLSS_GETCOREPRINTERDRIVERS, "GetCorePrinterDrivers",
7129
    SpoolssGetCorePrinterDrivers_q, SpoolssGetCorePrinterDrivers_r },
7130
  { SPOOLSS_GETPRINTERDRIVERPACKAGEPATH, "GetPrinterDriverPackagePath",
7131
    SpoolssGetPrinterDriverPackagePath_q, SpoolssGetPrinterDriverPackagePath_r },
7132
7133
  { 0, NULL, NULL, NULL },
7134
};
7135
7136
/*
7137
 * Dissector initialisation function
7138
 */
7139
7140
/* Protocol registration */
7141
7142
static int proto_dcerpc_spoolss;
7143
static int ett_dcerpc_spoolss;
7144
7145
void
7146
proto_register_dcerpc_spoolss(void)
7147
16
{
7148
16
  static hf_register_info hf[] = {
7149
7150
    /* GetPrinterDriver2 */
7151
7152
16
    { &hf_clientmajorversion,
7153
16
      { "Client major version", "spoolss.clientmajorversion", FT_UINT32, BASE_DEC,
7154
16
        NULL, 0x0, "Client printer driver major version", HFILL }},
7155
16
    { &hf_clientminorversion,
7156
16
      { "Client minor version", "spoolss.clientminorversion", FT_UINT32, BASE_DEC,
7157
16
        NULL, 0x0, "Client printer driver minor version", HFILL }},
7158
16
    { &hf_servermajorversion,
7159
16
      { "Server major version", "spoolss.servermajorversion", FT_UINT32, BASE_DEC,
7160
16
        NULL, 0x0, "Server printer driver major version", HFILL }},
7161
16
    { &hf_serverminorversion,
7162
16
      { "Server minor version", "spoolss.serverminorversion", FT_UINT32, BASE_DEC,
7163
16
        NULL, 0x0, "Server printer driver minor version", HFILL }},
7164
16
    { &hf_driverpath,
7165
16
      { "Driver path", "spoolss.driverpath", FT_STRING, BASE_NONE,
7166
16
        NULL, 0, NULL, HFILL }},
7167
16
    { &hf_datafile,
7168
16
      { "Data file", "spoolss.datafile", FT_STRING, BASE_NONE,
7169
16
        NULL, 0, NULL, HFILL }},
7170
16
    { &hf_configfile,
7171
16
      { "Config file", "spoolss.configfile", FT_STRING, BASE_NONE,
7172
16
        NULL, 0, "Printer name", HFILL }},
7173
16
    { &hf_helpfile,
7174
16
      { "Help file", "spoolss.helpfile", FT_STRING, BASE_NONE,
7175
16
        NULL, 0, NULL, HFILL }},
7176
16
    { &hf_monitorname,
7177
16
      { "Monitor name", "spoolss.monitorname", FT_STRING, BASE_NONE,
7178
16
        NULL, 0, NULL, HFILL }},
7179
16
    { &hf_defaultdatatype,
7180
16
      { "Default data type", "spoolss.defaultdatatype", FT_STRING, BASE_NONE,
7181
16
        NULL, 0, NULL, HFILL }},
7182
16
    { &hf_driverinfo_cversion,
7183
16
      { "Driver version", "spoolss.drivercversion", FT_UINT32, BASE_DEC,
7184
16
        VALS(driverinfo_cversion_vals), 0, "Printer name", HFILL }},
7185
16
    { &hf_dependentfiles,
7186
16
      { "Dependent files", "spoolss.dependentfiles", FT_STRING, BASE_NONE,
7187
16
        NULL, 0, NULL, HFILL }},
7188
7189
16
    { &hf_printer_status,
7190
16
      { "Status", "spoolss.printer_status", FT_UINT32, BASE_DEC|BASE_EXT_STRING,
7191
16
        &printer_status_vals_ext, 0, NULL, HFILL }},
7192
7193
16
    { &hf_previousdrivernames,
7194
16
      { "Previous Driver Names", "spoolss.previousdrivernames", FT_STRING, BASE_NONE,
7195
16
        NULL, 0, NULL, HFILL }},
7196
7197
16
    { &hf_color_profiles,
7198
16
      { "Color Profiles", "spoolss.colorprofiles", FT_STRING, BASE_NONE,
7199
16
        NULL, 0, NULL, HFILL }},
7200
7201
16
    { &hf_core_driver_dependencies,
7202
16
      { "Core Driver Dependencies", "spoolss.coredriverdependencies", FT_STRING, BASE_NONE,
7203
16
        NULL, 0, NULL, HFILL }},
7204
7205
16
    { &hf_driverdate,
7206
16
      { "Driver Date", "spoolss.driverdate", FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL,
7207
16
        NULL, 0, "Date of driver creation", HFILL }},
7208
7209
16
    { &hf_min_inbox_driverdate,
7210
16
      { "Min Inbox Driver Date", "spoolss.mininboxdriverdate", FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL,
7211
16
        NULL, 0, "Min Inbox Date of driver creation", HFILL }},
7212
7213
16
    { &hf_padding,
7214
16
      { "Padding", "spoolss.padding", FT_UINT32, BASE_HEX,
7215
16
        NULL, 0, "Some padding - conveys no semantic information", HFILL }},
7216
7217
16
    { &hf_driver_version,
7218
16
      { "Driver Version", "spoolss.driverversion", FT_UINT64, BASE_HEX,
7219
16
        NULL, 0, "Driver Version ID", HFILL }},
7220
7221
16
    { &hf_driver_version_low,
7222
16
      { "Minor Driver Version", "spoolss.minordriverversion", FT_UINT32, BASE_HEX,
7223
16
        NULL, 0, "Driver Version Low", HFILL }},
7224
7225
16
    { &hf_driver_version_high,
7226
16
      { "Major Driver Version", "spoolss.majordriverversion", FT_UINT32, BASE_HEX,
7227
16
        NULL, 0, "Driver Version High", HFILL }},
7228
7229
16
    { &hf_min_inbox_driver_version_low,
7230
16
      { "Min Inbox Minor Driver Version", "spoolss.mininboxminordriverversion", FT_UINT32, BASE_HEX,
7231
16
        NULL, 0, "Min Inbox Driver Version Low", HFILL }},
7232
7233
16
    { &hf_min_inbox_driver_version_high,
7234
16
      { "Min Inbox Major Driver Version", "spoolss.mininboxmajordriverversion", FT_UINT32, BASE_HEX,
7235
16
        NULL, 0, "Min Inbox Driver Version High", HFILL }},
7236
7237
16
    { &hf_mfgname,
7238
16
      { "Mfgname", "spoolss.mfgname", FT_STRING, BASE_NONE,
7239
16
        NULL, 0, "Manufacturer Name", HFILL }},
7240
7241
16
    { &hf_oemurl,
7242
16
      { "OEM URL", "spoolss.oemrul", FT_STRING, BASE_NONE,
7243
16
        NULL, 0, "OEM URL - Website of Vendor", HFILL }},
7244
7245
16
    { &hf_hardwareid,
7246
16
      { "Hardware ID", "spoolss.hardwareid", FT_STRING, BASE_NONE,
7247
16
        NULL, 0, "Hardware Identification Information", HFILL }},
7248
7249
16
      { &hf_provider,
7250
16
        { "Provider", "spoolss.provider", FT_STRING, BASE_NONE,
7251
16
        NULL, 0, "Provider of Driver", HFILL }},
7252
7253
    /* Setprinter RPC */
7254
7255
16
    { &hf_setprinter_cmd,
7256
16
      { "Command", "spoolss.setprinter_cmd", FT_UINT32, BASE_DEC,
7257
16
       VALS(setprinter_cmd_vals), 0, NULL, HFILL }},
7258
7259
    /* Enumprinters */
7260
7261
16
    { &hf_enumprinters_flags,
7262
16
      { "Flags", "spoolss.enumprinters.flags",
7263
16
        FT_UINT32, BASE_HEX, NULL, 0, NULL, HFILL }},
7264
7265
16
    { &hf_enumprinters_flags_local,
7266
16
      { "Enum local", "spoolss.enumprinters.flags.enum_local",
7267
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7268
16
        PRINTER_ENUM_LOCAL, NULL, HFILL }},
7269
7270
16
    { &hf_enumprinters_flags_name,
7271
16
      { "Enum name", "spoolss.enumprinters.flags.enum_name",
7272
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7273
16
        PRINTER_ENUM_NAME, NULL, HFILL }},
7274
7275
16
    { &hf_enumprinters_flags_shared,
7276
16
      { "Enum shared", "spoolss.enumprinters.flags.enum_shared",
7277
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7278
16
        PRINTER_ENUM_SHARED, NULL, HFILL }},
7279
7280
16
    { &hf_enumprinters_flags_default,
7281
16
      { "Enum default", "spoolss.enumprinters.flags.enum_default",
7282
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7283
16
        PRINTER_ENUM_DEFAULT, NULL, HFILL }},
7284
7285
16
    { &hf_enumprinters_flags_connections,
7286
16
      { "Enum connections", "spoolss.enumprinters.flags.enum_connections",
7287
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7288
16
        PRINTER_ENUM_CONNECTIONS, NULL, HFILL }},
7289
7290
16
    { &hf_enumprinters_flags_network,
7291
16
      { "Enum network", "spoolss.enumprinters.flags.enum_network",
7292
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7293
16
        PRINTER_ENUM_NETWORK, NULL, HFILL }},
7294
7295
16
    { &hf_enumprinters_flags_remote,
7296
16
      { "Enum remote", "spoolss.enumprinters.flags.enum_remote",
7297
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7298
16
        PRINTER_ENUM_REMOTE, NULL, HFILL }},
7299
7300
    /* GetPrinter */
7301
7302
16
    { &hf_start_time,
7303
16
      { "Start time", "spoolss.start_time",
7304
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7305
7306
16
    { &hf_end_time,
7307
16
      { "End time", "spoolss.end_time",
7308
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7309
7310
16
    { &hf_elapsed_time,
7311
16
      { "Elapsed time", "spoolss.elapsed_time",
7312
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7313
7314
16
    { &hf_device_not_selected_timeout,
7315
16
      { "Device Not Selected Timeout", "spoolss.device_not_selected_timeout",
7316
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7317
7318
16
    { &hf_transmission_retry_timeout,
7319
16
      { "Transmission Retry Timeout", "spoolss.transmission_retry_timeout",
7320
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7321
7322
    /*
7323
     * New hf index values
7324
     */
7325
7326
16
    { &hf_opnum,
7327
16
      { "Operation", "spoolss.opnum", FT_UINT16, BASE_DEC,
7328
16
        NULL, 0x0, NULL, HFILL }},
7329
7330
16
    { &hf_hnd,
7331
16
      { "Context handle", "spoolss.hnd", FT_BYTES, BASE_NONE,
7332
16
        NULL, 0x0, "SPOOLSS policy handle", HFILL }},
7333
7334
16
    { &hf_rc,
7335
16
      { "Return code", "spoolss.rc", FT_UINT32, BASE_HEX | BASE_EXT_STRING,
7336
16
        &DOS_errors_ext, 0x0, "SPOOLSS return code", HFILL }},
7337
7338
16
    { &hf_hresult,
7339
16
      { "HRESULT return code", "spoolss.hresult", FT_UINT32, BASE_HEX | BASE_EXT_STRING,
7340
16
        &HRES_errors_ext, 0x0, "SPOOLSS HRESULT return code", HFILL }},
7341
7342
16
    { &hf_offered,
7343
16
      { "Offered", "spoolss.offered", FT_UINT32, BASE_DEC,
7344
16
        NULL, 0x0, "Size of buffer offered in this request",
7345
16
        HFILL }},
7346
7347
16
    { &hf_needed,
7348
16
      { "Needed", "spoolss.needed", FT_UINT32, BASE_DEC,
7349
16
        NULL, 0x0, "Size of buffer required for request", HFILL }},
7350
7351
16
    { &hf_returned,
7352
16
      { "Returned", "spoolss.returned", FT_UINT32, BASE_DEC,
7353
16
        NULL, 0x0, "Number of items returned", HFILL }},
7354
7355
16
    { &hf_buffer_size,
7356
16
      { "Buffer size", "spoolss.buffer.size", FT_UINT32, BASE_DEC,
7357
16
        NULL, 0x0, "Size of buffer", HFILL }},
7358
7359
16
    { &hf_buffer_data,
7360
16
      { "Buffer data", "spoolss.buffer.data", FT_BYTES, BASE_NONE,
7361
16
        NULL, 0x0, "Contents of buffer", HFILL }},
7362
7363
16
    { &hf_string_parm_size,
7364
16
      { "String buffer size", "spoolss.string.buffersize", FT_UINT32, BASE_DEC,
7365
16
        NULL, 0x0, "Size of string buffer", HFILL }},
7366
7367
16
    { &hf_string_parm_data,
7368
16
      { "String data", "spoolss.string.data", FT_STRINGZ, BASE_NONE,
7369
16
        NULL, 0x0, "Contents of string", HFILL }},
7370
7371
16
    { &hf_offset,
7372
16
      { "Offset", "spoolss.offset", FT_UINT32, BASE_DEC,
7373
16
        NULL, 0x0, "Offset of data", HFILL }},
7374
7375
16
    { &hf_level,
7376
16
      { "Info level", "spoolss.enumjobs.level", FT_UINT32,
7377
16
        BASE_DEC, NULL, 0x0, NULL, HFILL }},
7378
7379
7380
16
    { &hf_printername,
7381
16
      { "Printer name", "spoolss.printername", FT_STRING,
7382
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7383
7384
16
    { &hf_machinename,
7385
16
      { "Machine name", "spoolss.machinename", FT_STRING,
7386
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7387
7388
16
    { &hf_notifyname,
7389
16
      { "Notify name", "spoolss.notifyname", FT_STRING,
7390
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7391
7392
16
    { &hf_printerdesc,
7393
16
      { "Printer description", "spoolss.printerdesc", FT_STRING,
7394
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7395
7396
16
    { &hf_printercomment,
7397
16
      { "Printer comment", "spoolss.printercomment", FT_STRING,
7398
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7399
7400
16
    { &hf_servername,
7401
16
      { "Server name", "spoolss.servername", FT_STRING, BASE_NONE,
7402
16
        NULL, 0, NULL, HFILL }},
7403
7404
16
    { &hf_sharename,
7405
16
      { "Share name", "spoolss.sharename", FT_STRING, BASE_NONE,
7406
16
        NULL, 0, NULL, HFILL }},
7407
7408
16
    { &hf_portname,
7409
16
      { "Port name", "spoolss.portname", FT_STRING, BASE_NONE,
7410
16
        NULL, 0, NULL, HFILL }},
7411
7412
16
    { &hf_printerlocation,
7413
16
      { "Printer location", "spoolss.printerlocation", FT_STRING,
7414
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7415
7416
16
    { &hf_environment,
7417
16
      { "Environment name", "spoolss.environment", FT_STRING,
7418
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7419
7420
16
    { &hf_drivername,
7421
16
      { "Driver name", "spoolss.drivername", FT_STRING, BASE_NONE,
7422
16
        NULL, 0, NULL, HFILL }},
7423
7424
16
    { &hf_username,
7425
16
      { "User name", "spoolss.username", FT_STRING, BASE_NONE,
7426
16
        NULL, 0, NULL, HFILL }},
7427
7428
16
    { &hf_documentname,
7429
16
      { "Document name", "spoolss.document", FT_STRING, BASE_NONE,
7430
16
        NULL, 0, NULL, HFILL }},
7431
7432
16
    { &hf_outputfile,
7433
16
      { "Output file", "spoolss.outputfile", FT_STRING, BASE_NONE,
7434
16
        NULL, 0, NULL, HFILL }},
7435
7436
16
    { &hf_datatype,
7437
16
      { "Datatype", "spoolss.datatype", FT_STRING, BASE_NONE,
7438
16
        NULL, 0, NULL, HFILL }},
7439
7440
16
    { &hf_textstatus,
7441
16
      { "Text status", "spoolss.textstatus", FT_STRING, BASE_NONE,
7442
16
        NULL, 0, NULL, HFILL }},
7443
7444
16
    { &hf_sepfile,
7445
16
      { "Separator file", "spoolss.setpfile", FT_STRING, BASE_NONE,
7446
16
        NULL, 0, NULL, HFILL }},
7447
7448
16
    { &hf_parameters,
7449
16
      { "Parameters", "spoolss.parameters", FT_STRING, BASE_NONE,
7450
16
        NULL, 0, NULL, HFILL }},
7451
7452
16
    { &hf_printprocessor,
7453
16
      { "Print processor", "spoolss.printprocessor", FT_STRING,
7454
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7455
7456
16
    { &hf_vendor_setup,
7457
16
      { "Vendor Setup", "spoolss.vendorsetup", FT_STRING,
7458
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7459
7460
16
    { &hf_inf_path,
7461
16
      { "Inf Path", "spoolss.infpath", FT_STRING,
7462
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7463
7464
16
    { &hf_core_printer_driver_ids,
7465
16
      { "Core Printer Driver IDs", "spoolss.core_printer_driver_ids", FT_STRING,
7466
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7467
7468
16
    { &hf_core_driver_guid,
7469
16
      { "Core Printer Driver GUID", "spoolss.core_driver_guid", FT_GUID,
7470
16
        BASE_NONE, NULL, 0,  NULL, HFILL }},
7471
7472
16
    { &hf_core_driver_size,
7473
16
      { "Core Printer Driver Size", "spoolss.core_driver_size", FT_UINT32,
7474
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
7475
7476
16
    { &hf_core_printer_driver_count,
7477
16
      { "Core Printer Driver Count", "spoolss.core_printer_driver_count", FT_UINT32,
7478
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
7479
7480
16
    { &hf_package_id,
7481
16
      { "PackageId", "spoolss.package_id", FT_STRING,
7482
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7483
7484
16
    { &hf_language,
7485
16
      { "Language name", "spoolss.language", FT_STRING,
7486
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
7487
7488
16
    { &hf_driver_package_cab_size,
7489
16
      { "Driver Package Cabinet Size", "spoolss.driver_package_cab_size", FT_UINT32,
7490
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
7491
7492
    /* Printer data */
7493
7494
16
    { &hf_printerdata,
7495
16
      { "Data", "spoolss.printerdata", FT_UINT32,
7496
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
7497
7498
16
    { &hf_printerdata_key,
7499
16
      { "Key", "spoolss.printerdata.key", FT_STRING,
7500
16
        BASE_NONE, NULL, 0, "Printer data key", HFILL }},
7501
7502
16
    { &hf_printerdata_value,
7503
16
      { "Value", "spoolss.printerdata.value",
7504
16
        FT_STRING, BASE_NONE, NULL, 0, "Printer data value",
7505
16
        HFILL }},
7506
7507
16
    { &hf_printerdata_type,
7508
16
      { "Type", "spoolss.printerdata.type",
7509
16
        FT_UINT32, BASE_DEC|BASE_EXT_STRING, &reg_datatypes_ext, 0,
7510
16
        "Printer data type", HFILL }},
7511
7512
16
    { &hf_printerdata_size,
7513
16
      { "Size", "spoolss.printerdata.size",
7514
16
        FT_UINT32, BASE_DEC, NULL, 0, "Printer data size",
7515
16
        HFILL }},
7516
7517
16
    { &hf_printerdata_data,
7518
16
      { "Data", "spoolss.printerdata.data", FT_BYTES, BASE_NONE,
7519
16
        NULL, 0x0, "Printer data", HFILL }},
7520
7521
16
    { &hf_printerdata_data_dword,
7522
16
      { "DWORD data", "spoolss.printerdata.data.dword",
7523
16
        FT_UINT32, BASE_HEX, NULL, 0, NULL, HFILL }},
7524
7525
16
    { &hf_printerdata_data_sz,
7526
16
      { "String data", "spoolss.printerdata.data.sz",
7527
16
        FT_STRING, BASE_NONE, NULL, 0, NULL,
7528
16
        HFILL }},
7529
7530
    /* Devicemode */
7531
7532
16
    { &hf_devmodectr_size,
7533
16
      { "Devicemode ctr size", "spoolss.devicemodectr.size",
7534
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL,
7535
16
        HFILL }},
7536
7537
16
    { &hf_devmode,
7538
16
      { "Devicemode", "spoolss.devmode", FT_UINT32,
7539
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
7540
7541
16
    { &hf_devmode_size,
7542
16
      { "Size", "spoolss.devmode.size",
7543
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7544
7545
16
    { &hf_devmode_spec_version,
7546
16
      { "Spec version", "spoolss.devmode.spec_version",
7547
16
        FT_UINT16, BASE_DEC, VALS(devmode_specversion_vals),
7548
16
        0, NULL, HFILL }},
7549
7550
16
    { &hf_devmode_driver_version,
7551
16
      { "Driver version", "spoolss.devmode.driver_version",
7552
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7553
7554
16
    { &hf_devmode_size2,
7555
16
      { "Size2", "spoolss.devmode.size2",
7556
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7557
7558
16
    { &hf_devmode_fields,
7559
16
      { "Fields", "spoolss.devmode.fields",
7560
16
        FT_UINT32, BASE_HEX, NULL, 0, NULL, HFILL }},
7561
7562
16
    { &hf_devmode_orientation,
7563
16
      { "Orientation", "spoolss.devmode.orientation",
7564
16
        FT_UINT16, BASE_DEC, VALS(devmode_orientation_vals),
7565
16
        0, NULL, HFILL }},
7566
7567
16
    { &hf_devmode_paper_size,
7568
16
      { "Paper size", "spoolss.devmode.paper_size",
7569
16
        FT_UINT16, BASE_DEC|BASE_EXT_STRING, &devmode_papersize_vals_ext,
7570
16
        0, NULL, HFILL }},
7571
7572
16
    { &hf_devmode_paper_width,
7573
16
      { "Paper width", "spoolss.devmode.paper_width",
7574
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7575
7576
16
    { &hf_devmode_paper_length,
7577
16
      { "Paper length", "spoolss.devmode.paper_length",
7578
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7579
7580
16
    { &hf_devmode_scale,
7581
16
      { "Scale", "spoolss.devmode.scale",
7582
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7583
7584
16
    { &hf_devmode_copies,
7585
16
      { "Copies", "spoolss.devmode.copies",
7586
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7587
7588
16
    { &hf_devmode_default_source,
7589
16
      { "Default source", "spoolss.devmode.default_source",
7590
16
        FT_UINT16, BASE_DEC|BASE_EXT_STRING, &devmode_papersource_vals_ext,
7591
16
        0, NULL, HFILL }},
7592
7593
16
    { &hf_devmode_print_quality,
7594
16
      { "Print quality", "spoolss.devmode.print_quality",
7595
16
        FT_UINT16, BASE_DEC, VALS(devmode_printquality_vals),
7596
16
        0, NULL, HFILL }},
7597
7598
16
    { &hf_devmode_color,
7599
16
      { "Color", "spoolss.devmode.color",
7600
16
        FT_UINT16, BASE_DEC, VALS(devmode_colour_vals), 0,
7601
16
        NULL, HFILL }},
7602
7603
16
    { &hf_devmode_duplex,
7604
16
      { "Duplex", "spoolss.devmode.duplex",
7605
16
        FT_UINT16, BASE_DEC, VALS(devmode_duplex_vals), 0,
7606
16
        NULL, HFILL }},
7607
7608
16
    { &hf_devmode_y_resolution,
7609
16
      { "Y resolution", "spoolss.devmode.y_resolution",
7610
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7611
7612
16
    { &hf_devmode_tt_option,
7613
16
      { "TT option", "spoolss.devmode.tt_option",
7614
16
        FT_UINT16, BASE_DEC, VALS(devmode_ttoption_vals), 0,
7615
16
        NULL, HFILL }},
7616
7617
16
    { &hf_devmode_collate,
7618
16
      { "Collate", "spoolss.devmode.collate",
7619
16
        FT_UINT16, BASE_DEC, VALS(devmode_collate_vals), 0,
7620
16
        NULL, HFILL }},
7621
7622
16
    { &hf_devmode_log_pixels,
7623
16
      { "Log pixels", "spoolss.devmode.log_pixels",
7624
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
7625
7626
16
    { &hf_devmode_bits_per_pel,
7627
16
      { "Bits per pel", "spoolss.devmode.bits_per_pel",
7628
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7629
7630
16
    { &hf_devmode_pels_width,
7631
16
      { "Pels width", "spoolss.devmode.pels_width",
7632
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7633
7634
16
    { &hf_devmode_pels_height,
7635
16
      { "Pels height", "spoolss.devmode.pels_height",
7636
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7637
7638
16
    { &hf_devmode_display_flags,
7639
16
      { "Display flags", "spoolss.devmode.display_flags",
7640
16
        FT_UINT32, BASE_DEC, VALS(devmode_displayflags_vals), 0,
7641
16
        NULL, HFILL }},
7642
7643
16
    { &hf_devmode_display_freq,
7644
16
      { "Display frequency", "spoolss.devmode.display_freq",
7645
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL,
7646
16
        HFILL }},
7647
7648
16
    { &hf_devmode_icm_method,
7649
16
      { "ICM method", "spoolss.devmode.icm_method",
7650
16
        FT_UINT32, BASE_DEC, VALS(devmode_icmmethod_vals), 0,
7651
16
        NULL, HFILL }},
7652
7653
16
    { &hf_devmode_icm_intent,
7654
16
      { "ICM intent", "spoolss.devmode.icm_intent",
7655
16
        FT_UINT32, BASE_DEC, VALS(devmode_icmintent_vals), 0,
7656
16
        NULL, HFILL }},
7657
7658
16
    { &hf_devmode_media_type,
7659
16
      { "Media type", "spoolss.devmode.media_type",
7660
16
        FT_UINT32, BASE_DEC, VALS(devmode_mediatype_vals), 0,
7661
16
        NULL, HFILL }},
7662
7663
16
    { &hf_devmode_dither_type,
7664
16
      { "Dither type", "spoolss.devmode.dither_type",
7665
16
        FT_UINT32, BASE_DEC, VALS(devmode_dithertype_vals), 0,
7666
16
        NULL, HFILL }},
7667
7668
16
    { &hf_devmode_reserved1,
7669
16
      { "Reserved1", "spoolss.devmode.reserved1",
7670
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7671
7672
16
    { &hf_devmode_reserved2,
7673
16
      { "Reserved2", "spoolss.devmode.reserved2",
7674
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7675
7676
16
    { &hf_devmode_panning_width,
7677
16
      { "Panning width", "spoolss.devmode.panning_width",
7678
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7679
7680
16
    { &hf_devmode_panning_height,
7681
16
      { "Panning height", "spoolss.devmode.panning_height",
7682
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
7683
7684
16
    { &hf_devmode_driver_extra_len,
7685
16
      { "Driver extra length",
7686
16
        "spoolss.devmode.driver_extra_len",
7687
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL,
7688
16
        HFILL }},
7689
7690
16
    { &hf_devmode_driver_extra,
7691
16
      { "Driver extra", "spoolss.devmode.driver_extra",
7692
16
        FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }},
7693
7694
    /* Devicemode fields */
7695
7696
16
    { &hf_devmode_fields_orientation,
7697
16
      { "Orientation", "spoolss.devmode.fields.orientation",
7698
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7699
16
        DEVMODE_ORIENTATION, NULL, HFILL }},
7700
7701
16
    { &hf_devmode_fields_papersize,
7702
16
      { "Paper size", "spoolss.devmode.fields.paper_size",
7703
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7704
16
        DEVMODE_PAPERSIZE, NULL, HFILL }},
7705
7706
16
    { &hf_devmode_fields_paperlength,
7707
16
      { "Paper length", "spoolss.devmode.fields.paper_length",
7708
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7709
16
        DEVMODE_PAPERLENGTH, NULL, HFILL }},
7710
7711
16
    { &hf_devmode_fields_paperwidth,
7712
16
      { "Paper width", "spoolss.devmode.fields.paper_width",
7713
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7714
16
        DEVMODE_PAPERWIDTH, NULL, HFILL }},
7715
7716
16
    { &hf_devmode_fields_scale,
7717
16
      { "Scale", "spoolss.devmode.fields.scale",
7718
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7719
16
        DEVMODE_SCALE, NULL, HFILL }},
7720
7721
16
    { &hf_devmode_fields_position,
7722
16
      { "Position", "spoolss.devmode.fields.position",
7723
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7724
16
        DEVMODE_POSITION, NULL, HFILL }},
7725
7726
16
    { &hf_devmode_fields_nup,
7727
16
      { "N-up", "spoolss.devmode.fields.nup",
7728
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7729
16
        DEVMODE_NUP, NULL, HFILL }},
7730
7731
16
    { &hf_devmode_fields_copies,
7732
16
      { "Copies", "spoolss.devmode.fields.copies",
7733
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7734
16
        DEVMODE_COPIES, NULL, HFILL }},
7735
7736
16
    { &hf_devmode_fields_defaultsource,
7737
16
      { "Default source", "spoolss.devmode.fields.default_source",
7738
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7739
16
        DEVMODE_DEFAULTSOURCE, NULL, HFILL }},
7740
7741
16
    { &hf_devmode_fields_printquality,
7742
16
      { "Print quality", "spoolss.devmode.fields.print_quality",
7743
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7744
16
        DEVMODE_PRINTQUALITY, NULL, HFILL }},
7745
7746
16
    { &hf_devmode_fields_color,
7747
16
      { "Color", "spoolss.devmode.fields.color",
7748
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7749
16
        DEVMODE_COLOR, NULL, HFILL }},
7750
7751
16
    { &hf_devmode_fields_duplex,
7752
16
      { "Duplex", "spoolss.devmode.fields.duplex",
7753
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7754
16
        DEVMODE_DUPLEX, NULL, HFILL }},
7755
7756
16
    { &hf_devmode_fields_yresolution,
7757
16
      { "Y resolution", "spoolss.devmode.fields.y_resolution",
7758
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7759
16
        DEVMODE_YRESOLUTION, NULL, HFILL }},
7760
7761
16
    { &hf_devmode_fields_ttoption,
7762
16
      { "TT option", "spoolss.devmode.fields.tt_option",
7763
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7764
16
        DEVMODE_TTOPTION, NULL, HFILL }},
7765
7766
16
    { &hf_devmode_fields_collate,
7767
16
      { "Collate", "spoolss.devmode.fields.collate",
7768
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7769
16
        DEVMODE_COLLATE, NULL, HFILL }},
7770
7771
16
    { &hf_devmode_fields_formname,
7772
16
      { "Form name", "spoolss.devmode.fields.form_name",
7773
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7774
16
        DEVMODE_FORMNAME, NULL, HFILL }},
7775
7776
16
    { &hf_devmode_fields_logpixels,
7777
16
      { "Log pixels", "spoolss.devmode.fields.log_pixels",
7778
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7779
16
        DEVMODE_LOGPIXELS, NULL, HFILL }},
7780
7781
16
    { &hf_devmode_fields_bitsperpel,
7782
16
      { "Bits per pel", "spoolss.devmode.fields.bits_per_pel",
7783
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7784
16
        DEVMODE_BITSPERPEL, NULL, HFILL }},
7785
7786
16
    { &hf_devmode_fields_pelswidth,
7787
16
      { "Pels width", "spoolss.devmode.fields.pels_width",
7788
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7789
16
        DEVMODE_PELSWIDTH, NULL, HFILL }},
7790
7791
16
    { &hf_devmode_fields_pelsheight,
7792
16
      { "Pels height", "spoolss.devmode.fields.pels_height",
7793
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7794
16
        DEVMODE_PELSHEIGHT, NULL, HFILL }},
7795
7796
16
    { &hf_devmode_fields_displayflags,
7797
16
      { "Display flags", "spoolss.devmode.fields.display_flags",
7798
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7799
16
        DEVMODE_DISPLAYFLAGS, NULL, HFILL }},
7800
7801
16
    { &hf_devmode_fields_displayfrequency,
7802
16
      { "Display frequency",
7803
16
        "spoolss.devmode.fields.display_frequency",
7804
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7805
16
        DEVMODE_DISPLAYFREQUENCY, NULL, HFILL }},
7806
7807
16
    { &hf_devmode_fields_icmmethod,
7808
16
      { "ICM method", "spoolss.devmode.fields.icm_method",
7809
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7810
16
        DEVMODE_ICMMETHOD, NULL, HFILL }},
7811
7812
16
    { &hf_devmode_fields_icmintent,
7813
16
      { "ICM intent", "spoolss.devmode.fields.icm_intent",
7814
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7815
16
        DEVMODE_ICMINTENT, NULL, HFILL }},
7816
7817
16
    { &hf_devmode_fields_mediatype,
7818
16
      { "Media type", "spoolss.devmode.fields.media_type",
7819
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7820
16
        DEVMODE_MEDIATYPE, NULL, HFILL }},
7821
7822
16
    { &hf_devmode_fields_dithertype,
7823
16
      { "Dither type", "spoolss.devmode.fields.dither_type",
7824
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7825
16
        DEVMODE_DITHERTYPE, NULL, HFILL }},
7826
7827
16
    { &hf_devmode_fields_panningwidth,
7828
16
      { "Panning width", "spoolss.devmode.fields.panning_width",
7829
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7830
16
        DEVMODE_PANNINGWIDTH, NULL, HFILL }},
7831
7832
16
    { &hf_devmode_fields_panningheight,
7833
16
      { "Panning height", "spoolss.devmode.fields.panning_height",
7834
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
7835
16
        DEVMODE_PANNINGHEIGHT, NULL, HFILL }},
7836
7837
    /* EnumPrinterData RPC */
7838
7839
16
    { &hf_enumprinterdata_enumindex,
7840
16
      { "Enum index", "spoolss.enumprinterdata.enumindex",
7841
16
        FT_UINT32, BASE_DEC, NULL, 0x0,
7842
16
        "Index for start of enumeration", HFILL }},
7843
7844
16
    { &hf_enumprinterdata_value_offered,
7845
16
      { "Value size offered",
7846
16
        "spoolss.enumprinterdata.value_offered", FT_UINT32,
7847
16
        BASE_DEC, NULL, 0x0,
7848
16
        "Buffer size offered for printerdata value", HFILL }},
7849
7850
16
    { &hf_enumprinterdata_data_offered,
7851
16
      { "Data size offered",
7852
16
        "spoolss.enumprinterdata.data_offered", FT_UINT32,
7853
16
        BASE_DEC, NULL, 0x0,
7854
16
        "Buffer size offered for printerdata data", HFILL }},
7855
7856
16
    { &hf_enumprinterdata_value_len,
7857
16
      { "Value length",
7858
16
        "spoolss.enumprinterdata.value_len", FT_UINT32,
7859
16
        BASE_DEC, NULL, 0x0,
7860
16
        "Size of printerdata value", HFILL }},
7861
7862
16
    { &hf_enumprinterdata_value_needed,
7863
16
      { "Value size needed",
7864
16
        "spoolss.enumprinterdata.value_needed", FT_UINT32,
7865
16
        BASE_DEC, NULL, 0x0,
7866
16
        "Buffer size needed for printerdata value", HFILL }},
7867
7868
16
    { &hf_enumprinterdata_data_needed,
7869
16
      { "Data size needed",
7870
16
        "spoolss.enumprinterdata.data_needed", FT_UINT32, BASE_DEC,
7871
16
        NULL, 0x0, "Buffer size needed for printerdata data",
7872
16
        HFILL }},
7873
7874
    /* Print jobs */
7875
7876
16
    { &hf_job_id,
7877
16
      { "Job ID", "spoolss.job.id", FT_UINT32, BASE_DEC,
7878
16
        NULL, 0x0, "Job identification number", HFILL }},
7879
7880
16
    { &hf_job_status,
7881
16
      { "Job status", "spoolss.job.status", FT_UINT32, BASE_DEC,
7882
16
        NULL, 0x0, NULL, HFILL }},
7883
7884
16
    { &hf_job_status_paused,
7885
16
      { "Paused", "spoolss.job.status.paused", FT_BOOLEAN, 32,
7886
16
        TFS(&tfs_job_status_paused), JOB_STATUS_PAUSED,
7887
16
        NULL, HFILL }},
7888
7889
16
    { &hf_job_status_error,
7890
16
      { "Error", "spoolss.job.status.error", FT_BOOLEAN, 32,
7891
16
        TFS(&tfs_job_status_error), JOB_STATUS_ERROR,
7892
16
        NULL, HFILL }},
7893
7894
16
    { &hf_job_status_deleting,
7895
16
      { "Deleting", "spoolss.job.status.deleting", FT_BOOLEAN, 32,
7896
16
        TFS(&tfs_job_status_deleting), JOB_STATUS_DELETING,
7897
16
        NULL, HFILL }},
7898
7899
16
    { &hf_job_status_spooling,
7900
16
      { "Spooling", "spoolss.job.status.spooling", FT_BOOLEAN, 32,
7901
16
        TFS(&tfs_job_status_spooling), JOB_STATUS_SPOOLING,
7902
16
        NULL, HFILL }},
7903
7904
16
    { &hf_job_status_printing,
7905
16
      { "Printing", "spoolss.job.status.printing", FT_BOOLEAN, 32,
7906
16
        TFS(&tfs_job_status_printing), JOB_STATUS_PRINTING,
7907
16
        NULL, HFILL }},
7908
7909
16
    { &hf_job_status_offline,
7910
16
      { "Offline", "spoolss.job.status.offline", FT_BOOLEAN, 32,
7911
16
        TFS(&tfs_job_status_offline), JOB_STATUS_OFFLINE,
7912
16
        NULL, HFILL }},
7913
7914
16
    { &hf_job_status_paperout,
7915
16
      { "Paperout", "spoolss.job.status.paperout", FT_BOOLEAN, 32,
7916
16
        TFS(&tfs_job_status_paperout), JOB_STATUS_PAPEROUT,
7917
16
        NULL, HFILL }},
7918
7919
16
    { &hf_job_status_printed,
7920
16
      { "Printed", "spoolss.job.status.printed", FT_BOOLEAN, 32,
7921
16
        TFS(&tfs_job_status_printed), JOB_STATUS_PRINTED,
7922
16
        NULL, HFILL }},
7923
7924
16
    { &hf_job_status_deleted,
7925
16
      { "Deleted", "spoolss.job.status.deleted", FT_BOOLEAN, 32,
7926
16
        TFS(&tfs_job_status_deleted), JOB_STATUS_DELETED,
7927
16
        NULL, HFILL }},
7928
7929
16
    { &hf_job_status_blocked,
7930
16
      { "Blocked", "spoolss.job.status.blocked", FT_BOOLEAN, 32,
7931
16
        TFS(&tfs_job_status_blocked), JOB_STATUS_BLOCKED,
7932
16
        NULL, HFILL }},
7933
7934
16
    { &hf_job_status_user_intervention,
7935
16
      { "User intervention",
7936
16
        "spoolss.job.status.user_intervention", FT_BOOLEAN, 32,
7937
16
        TFS(&tfs_job_status_user_intervention),
7938
16
        JOB_STATUS_USER_INTERVENTION, NULL,
7939
16
        HFILL }},
7940
7941
16
    { &hf_job_priority,
7942
16
      { "Job priority", "spoolss.job.priority", FT_UINT32,
7943
16
        BASE_DEC, NULL, 0x0, NULL, HFILL }},
7944
7945
16
    { &hf_job_position,
7946
16
      { "Job position", "spoolss.job.position", FT_UINT32,
7947
16
        BASE_DEC, NULL, 0x0, NULL, HFILL }},
7948
7949
16
    { &hf_job_totalpages,
7950
16
      { "Job total pages", "spoolss.job.totalpages", FT_UINT32,
7951
16
        BASE_DEC, NULL, 0x0, NULL, HFILL }},
7952
7953
16
    { &hf_job_totalbytes,
7954
16
      { "Job total bytes", "spoolss.job.totalbytes", FT_UINT32,
7955
16
        BASE_DEC, NULL, 0x0, NULL, HFILL }},
7956
7957
16
    { &hf_job_bytesprinted,
7958
16
      { "Job bytes printed", "spoolss.job.bytesprinted",
7959
16
        FT_UINT32, BASE_DEC, NULL, 0x0, NULL,
7960
16
        HFILL }},
7961
7962
16
    { &hf_job_pagesprinted,
7963
16
      { "Job pages printed", "spoolss.job.pagesprinted",
7964
16
        FT_UINT32, BASE_DEC, NULL, 0x0, NULL,
7965
16
        HFILL }},
7966
7967
16
    { &hf_job_size,
7968
16
      { "Job size", "spoolss.job.size", FT_UINT32, BASE_DEC,
7969
16
        NULL, 0x0, NULL, HFILL }},
7970
7971
    /* Forms */
7972
7973
16
    { &hf_form,
7974
16
      { "Data", "spoolss.form", FT_UINT32,
7975
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
7976
7977
16
    { &hf_form_level,
7978
16
      { "Level", "spoolss.form.level", FT_UINT32,
7979
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
7980
7981
16
    { &hf_form_name,
7982
16
      { "Name", "spoolss.form.name", FT_STRING, BASE_NONE,
7983
16
        NULL, 0, NULL, HFILL }},
7984
7985
16
    { &hf_form_flags,
7986
16
      { "Flags", "spoolss.form.flags", FT_UINT32,
7987
16
        BASE_DEC, VALS(form_type_vals), 0, NULL, HFILL }},
7988
7989
16
    { &hf_form_unknown,
7990
16
      { "Unknown", "spoolss.form.unknown", FT_UINT32,
7991
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
7992
7993
16
    { &hf_form_width,
7994
16
      { "Width", "spoolss.form.width", FT_UINT32,
7995
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
7996
7997
16
    { &hf_form_height,
7998
16
      { "Height", "spoolss.form.height", FT_UINT32,
7999
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8000
8001
16
    { &hf_form_left_margin,
8002
16
      { "Left margin", "spoolss.form.left", FT_UINT32,
8003
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8004
8005
16
    { &hf_form_top_margin,
8006
16
      { "Top", "spoolss.form.top", FT_UINT32,
8007
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8008
8009
16
    { &hf_form_horiz_len,
8010
16
      { "Horizontal", "spoolss.form.horiz", FT_UINT32,
8011
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8012
8013
16
    { &hf_form_vert_len,
8014
16
      { "Vertical", "spoolss.form.vert", FT_UINT32,
8015
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8016
8017
16
    { &hf_enumforms_num,
8018
16
      { "Num", "spoolss.enumforms.num", FT_UINT32,
8019
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8020
8021
    /* Print notify */
8022
8023
16
    { &hf_notify_options_version,
8024
16
      { "Version", "spoolss.notify_options.version", FT_UINT32,
8025
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8026
8027
16
    { &hf_notify_options_flags,
8028
16
      { "Flags", "spoolss.notify_options.flags", FT_UINT32,
8029
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8030
8031
16
    { &hf_notify_options_count,
8032
16
      { "Count", "spoolss.notify_options.count", FT_UINT32,
8033
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8034
8035
16
    { &hf_notify_option_type,
8036
16
      { "Type", "spoolss.notify_option.type", FT_UINT16, BASE_DEC,
8037
16
        VALS(printer_notify_types), 0, NULL, HFILL }},
8038
8039
16
    { &hf_notify_option_reserved1,
8040
16
      { "Reserved1", "spoolss.notify_option.reserved1", FT_UINT16,
8041
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8042
8043
16
    { &hf_notify_option_reserved2,
8044
16
      { "Reserved2", "spoolss.notify_option.reserved2", FT_UINT32,
8045
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8046
8047
16
    { &hf_notify_option_reserved3,
8048
16
      { "Reserved3", "spoolss.notify_option.reserved3", FT_UINT32,
8049
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8050
8051
16
    { &hf_notify_option_count,
8052
16
      { "Count", "spoolss.notify_option.count", FT_UINT32,
8053
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8054
8055
16
    { &hf_notify_option_data_count,
8056
16
      { "Count", "spoolss.notify_option_data.count", FT_UINT32,
8057
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8058
8059
16
    { &hf_notify_options_flags_refresh,
8060
16
      { "Refresh", "spoolss.notify_options.flags.refresh", FT_BOOLEAN, 32,
8061
16
        TFS(&tfs_notify_options_flags_refresh),
8062
16
        PRINTER_NOTIFY_OPTIONS_REFRESH, NULL, HFILL }},
8063
8064
16
    { &hf_notify_info_count,
8065
16
      { "Count", "spoolss.notify_info.count", FT_UINT32, BASE_DEC,
8066
16
        NULL, 0, NULL, HFILL }},
8067
8068
16
    { &hf_notify_info_version,
8069
16
      { "Version", "spoolss.notify_info.version", FT_UINT32,
8070
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8071
8072
16
    { &hf_notify_info_flags,
8073
16
      { "Flags", "spoolss.notify_info.flags", FT_UINT32, BASE_HEX,
8074
16
        NULL, 0, NULL, HFILL }},
8075
8076
16
    { &hf_notify_info_data_type,
8077
16
      { "Type", "spoolss.notify_info_data.type", FT_UINT16,
8078
16
        BASE_DEC, VALS(printer_notify_types), 0, NULL, HFILL }},
8079
8080
16
    { &hf_notify_field,
8081
16
      { "Field", "spoolss.notify_field", FT_UINT16, BASE_DEC,
8082
16
        NULL, 0, NULL, HFILL }},
8083
8084
16
    { &hf_notify_info_data_count,
8085
16
      { "Count", "spoolss.notify_info_data.count", FT_UINT32,
8086
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8087
8088
16
    { &hf_notify_info_data_id,
8089
16
      { "Job Id", "spoolss.notify_info_data.jobid", FT_UINT32,
8090
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8091
8092
16
    { &hf_notify_info_data_value1,
8093
16
      { "Value1", "spoolss.notify_info_data.value1", FT_UINT32,
8094
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
8095
8096
16
    { &hf_notify_info_data_value2,
8097
16
      { "Value2", "spoolss.notify_info_data.value2", FT_UINT32,
8098
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
8099
8100
16
    { &hf_notify_info_data_bufsize,
8101
16
      { "Buffer size", "spoolss.notify_info_data.bufsize",
8102
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8103
8104
16
    { &hf_notify_info_data_buffer,
8105
16
      { "Buffer", "spoolss.notify_info_data.buffer", FT_UINT32,
8106
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
8107
8108
16
    { &hf_notify_info_data_buffer_len,
8109
16
      { "Buffer length", "spoolss.notify_info_data.buffer.len",
8110
16
        FT_UINT32, BASE_HEX, NULL, 0, NULL, HFILL }},
8111
8112
16
    { &hf_notify_info_data_buffer_data,
8113
16
      { "Buffer data", "spoolss.notify_info_data.buffer.data",
8114
16
        FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }},
8115
8116
    /* RffpCNex RPC */
8117
8118
16
    { &hf_rffpcnex_options,
8119
16
      { "Options", "spoolss.rffpcnex.options", FT_UINT32, BASE_DEC,
8120
16
        NULL, 0, "RFFPCNEX options", HFILL }},
8121
8122
16
    { &hf_printerlocal, /* XXX: move me */
8123
16
      { "Printer local", "spoolss.printer_local", FT_UINT32,
8124
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8125
8126
16
    { &hf_rffpcnex_flags,
8127
16
      { "RFFPCNEX flags", "spoolss.rffpcnex.flags", FT_UINT32,
8128
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8129
8130
16
    { &hf_rffpcnex_flags_add_printer,
8131
16
      { "Add printer", "spoolss.rffpcnex.flags.add_printer",
8132
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_add_printer),
8133
16
        SPOOLSS_PRINTER_CHANGE_ADD_PRINTER, NULL,
8134
16
        HFILL }},
8135
8136
16
    { &hf_rffpcnex_flags_set_printer,
8137
16
      { "Set printer", "spoolss.rffpcnex.flags.set_printer",
8138
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_set_printer),
8139
16
        SPOOLSS_PRINTER_CHANGE_SET_PRINTER, NULL,
8140
16
        HFILL }},
8141
8142
16
    { &hf_rffpcnex_flags_delete_printer,
8143
16
      { "Delete printer", "spoolss.rffpcnex.flags.delete_printer",
8144
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_delete_printer),
8145
16
        SPOOLSS_PRINTER_CHANGE_DELETE_PRINTER, NULL,
8146
16
        HFILL }},
8147
8148
16
    { &hf_rffpcnex_flags_add_job,
8149
16
      { "Add job", "spoolss.rffpcnex.flags.add_job",
8150
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_add_job),
8151
16
        SPOOLSS_PRINTER_CHANGE_ADD_JOB, NULL, HFILL }},
8152
8153
16
    { &hf_rffpcnex_flags_set_job,
8154
16
      { "Set job", "spoolss.rffpcnex.flags.set_job",
8155
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_set_job),
8156
16
        SPOOLSS_PRINTER_CHANGE_SET_JOB, NULL, HFILL }},
8157
8158
16
    { &hf_rffpcnex_flags_delete_job,
8159
16
      { "Delete job", "spoolss.rffpcnex.flags.delete_job",
8160
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_delete_job),
8161
16
        SPOOLSS_PRINTER_CHANGE_DELETE_JOB, NULL, HFILL }},
8162
8163
16
    { &hf_rffpcnex_flags_write_job,
8164
16
      { "Write job", "spoolss.rffpcnex.flags.write_job",
8165
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_write_job),
8166
16
        SPOOLSS_PRINTER_CHANGE_WRITE_JOB, NULL, HFILL }},
8167
8168
16
    { &hf_rffpcnex_flags_add_form,
8169
16
      { "Add form", "spoolss.rffpcnex.flags.add_form",
8170
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_add_form),
8171
16
        SPOOLSS_PRINTER_CHANGE_ADD_FORM, NULL, HFILL }},
8172
8173
16
    { &hf_rffpcnex_flags_set_form,
8174
16
      { "Set form", "spoolss.rffpcnex.flags.set_form",
8175
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_set_form),
8176
16
        SPOOLSS_PRINTER_CHANGE_SET_FORM, NULL, HFILL }},
8177
8178
16
    { &hf_rffpcnex_flags_delete_form,
8179
16
      { "Delete form", "spoolss.rffpcnex.flags.delete_form",
8180
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_delete_form),
8181
16
        SPOOLSS_PRINTER_CHANGE_DELETE_FORM, NULL,
8182
16
        HFILL }},
8183
8184
16
    { &hf_rffpcnex_flags_add_port,
8185
16
      { "Add port", "spoolss.rffpcnex.flags.add_port",
8186
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_add_port),
8187
16
        SPOOLSS_PRINTER_CHANGE_ADD_PORT, NULL, HFILL }},
8188
8189
16
    { &hf_rffpcnex_flags_configure_port,
8190
16
      { "Configure port", "spoolss.rffpcnex.flags.configure_port",
8191
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_configure_port),
8192
16
        SPOOLSS_PRINTER_CHANGE_CONFIGURE_PORT, NULL,
8193
16
        HFILL }},
8194
8195
16
    { &hf_rffpcnex_flags_delete_port,
8196
16
      { "Delete port", "spoolss.rffpcnex.flags.delete_port",
8197
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_delete_port),
8198
16
        SPOOLSS_PRINTER_CHANGE_DELETE_PORT, NULL,
8199
16
        HFILL }},
8200
8201
16
    { &hf_rffpcnex_flags_add_print_processor,
8202
16
      { "Add processor", "spoolss.rffpcnex.flags.add_processor",
8203
16
        FT_BOOLEAN, 32,
8204
16
        TFS(&tfs_rffpcnex_flags_add_print_processor),
8205
16
        SPOOLSS_PRINTER_CHANGE_ADD_PRINT_PROCESSOR,
8206
16
        NULL, HFILL }},
8207
8208
16
    { &hf_rffpcnex_flags_delete_print_processor,
8209
16
      { "Delete processor",
8210
16
        "spoolss.rffpcnex.flags.delete_processor", FT_BOOLEAN, 32,
8211
16
        TFS(&tfs_rffpcnex_flags_delete_print_processor),
8212
16
        SPOOLSS_PRINTER_CHANGE_DELETE_PRINT_PROCESSOR,
8213
16
        NULL, HFILL }},
8214
8215
16
    { &hf_rffpcnex_flags_add_driver,
8216
16
      { "Add driver", "spoolss.rffpcnex.flags.add_driver",
8217
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_add_driver),
8218
16
        SPOOLSS_PRINTER_CHANGE_ADD_PRINTER_DRIVER, NULL,
8219
16
        HFILL }},
8220
8221
16
    { &hf_rffpcnex_flags_set_driver,
8222
16
      { "Set driver", "spoolss.rffpcnex.flags.set_driver",
8223
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_set_driver),
8224
16
        SPOOLSS_PRINTER_CHANGE_SET_PRINTER_DRIVER, NULL,
8225
16
        HFILL }},
8226
8227
16
    { &hf_rffpcnex_flags_delete_driver,
8228
16
      { "Delete driver", "spoolss.rffpcnex.flags.delete_driver",
8229
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_delete_driver),
8230
16
        SPOOLSS_PRINTER_CHANGE_DELETE_PRINTER_DRIVER,
8231
16
        NULL, HFILL }},
8232
8233
16
    { &hf_rffpcnex_flags_timeout,
8234
16
      { "Timeout", "spoolss.rffpcnex.flags.timeout",
8235
16
        FT_BOOLEAN, 32, TFS(&tfs_rffpcnex_flags_timeout),
8236
16
        SPOOLSS_PRINTER_CHANGE_TIMEOUT, NULL, HFILL }},
8237
8238
16
    { &hf_rffpcnex_flags_failed_printer_connection,
8239
16
      { "Failed printer connection",
8240
16
        "spoolss.rffpcnex.flags.failed_connection_printer",
8241
16
        FT_BOOLEAN, 32,
8242
16
        TFS(&tfs_rffpcnex_flags_failed_connection_printer),
8243
16
        SPOOLSS_PRINTER_CHANGE_FAILED_CONNECTION_PRINTER,
8244
16
        NULL, HFILL }},
8245
8246
    /* RRPCN RPC */
8247
8248
16
    { &hf_rrpcn_changelow,
8249
16
      { "Change low", "spoolss.rrpcn.changelow", FT_UINT32,
8250
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8251
8252
16
    { &hf_rrpcn_changehigh,
8253
16
      { "Change high", "spoolss.rrpcn.changehigh", FT_UINT32,
8254
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8255
8256
16
    { &hf_rrpcn_unk0,
8257
16
      { "Unknown 0", "spoolss.rrpcn.unk0", FT_UINT32, BASE_DEC,
8258
16
        NULL, 0, NULL, HFILL }},
8259
8260
16
    { &hf_rrpcn_unk1,
8261
16
      { "Unknown 1", "spoolss.rrpcn.unk1", FT_UINT32, BASE_DEC,
8262
16
        NULL, 0, NULL, HFILL }},
8263
8264
    /* ReplyOpenPrinter RPC */
8265
8266
16
    { &hf_replyopenprinter_unk0,
8267
16
      { "Unknown 0", "spoolss.replyopenprinter.unk0", FT_UINT32,
8268
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8269
8270
16
    { &hf_replyopenprinter_unk1,
8271
16
      { "Unknown 1", "spoolss.replyopenprinter.unk1", FT_UINT32,
8272
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8273
8274
16
    { &hf_devmode_devicename,
8275
16
      { "DeviceName", "spoolss.devmode.devicename", FT_STRING,
8276
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8277
8278
16
    { &hf_devmode_form_name,
8279
16
      { "FormName", "spoolss.devmode.form_name", FT_STRING,
8280
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8281
8282
16
    { &hf_relative_string,
8283
16
      { "String", "spoolss.relative_string", FT_STRING,
8284
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8285
8286
16
    { &hf_value_name,
8287
16
      { "Value Name", "spoolss.value_name", FT_STRING,
8288
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8289
8290
16
    { &hf_keybuffer,
8291
16
      { "Key", "spoolss.hf_keybuffer", FT_STRING,
8292
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8293
8294
16
    { &hf_value_string,
8295
16
      { "Value", "spoolss.value_string", FT_STRING,
8296
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8297
8298
    /* Printer attributes */
8299
8300
16
    { &hf_printer_attributes,
8301
16
      { "Attributes", "spoolss.printer_attributes", FT_UINT32,
8302
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
8303
8304
16
    { &hf_printer_attributes_queued,
8305
16
      { "Queued", "spoolss.printer_attributes.queued", FT_BOOLEAN,
8306
16
        32, TFS(&tfs_printer_attributes_queued),
8307
16
        PRINTER_ATTRIBUTE_QUEUED, NULL, HFILL }},
8308
8309
16
    { &hf_printer_attributes_direct,
8310
16
      { "Direct", "spoolss.printer_attributes.direct", FT_BOOLEAN,
8311
16
        32, TFS(&tfs_printer_attributes_direct),
8312
16
        PRINTER_ATTRIBUTE_DIRECT, NULL, HFILL }},
8313
8314
16
    { &hf_printer_attributes_default,
8315
16
      { "Default (9x/ME only)",
8316
16
        "spoolss.printer_attributes.default",FT_BOOLEAN,
8317
16
        32, TFS(&tfs_printer_attributes_default),
8318
16
        PRINTER_ATTRIBUTE_DEFAULT, NULL, HFILL }},
8319
8320
16
    { &hf_printer_attributes_shared,
8321
16
      { "Shared", "spoolss.printer_attributes.shared", FT_BOOLEAN,
8322
16
        32, TFS(&tfs_printer_attributes_shared),
8323
16
        PRINTER_ATTRIBUTE_SHARED, NULL, HFILL }},
8324
8325
16
    { &hf_printer_attributes_network,
8326
16
      { "Network", "spoolss.printer_attributes.network",
8327
16
        FT_BOOLEAN, 32, TFS(&tfs_printer_attributes_network),
8328
16
        PRINTER_ATTRIBUTE_NETWORK, NULL, HFILL }},
8329
8330
16
    { &hf_printer_attributes_hidden,
8331
16
      { "Hidden", "spoolss.printer_attributes.hidden", FT_BOOLEAN,
8332
16
        32, TFS(&tfs_printer_attributes_hidden),
8333
16
        PRINTER_ATTRIBUTE_HIDDEN, NULL, HFILL }},
8334
8335
16
    { &hf_printer_attributes_local,
8336
16
      { "Local", "spoolss.printer_attributes.local", FT_BOOLEAN,
8337
16
        32, TFS(&tfs_printer_attributes_local),
8338
16
        PRINTER_ATTRIBUTE_LOCAL, NULL, HFILL }},
8339
8340
16
    { &hf_printer_attributes_enable_devq,
8341
16
      { "Enable devq", "spoolss.printer_attributes.enable_devq",
8342
16
        FT_BOOLEAN, 32, TFS(&tfs_printer_attributes_enable_devq),
8343
16
        PRINTER_ATTRIBUTE_ENABLE_DEVQ, "Enable evq", HFILL }},
8344
8345
16
    { &hf_printer_attributes_keep_printed_jobs,
8346
16
      { "Keep printed jobs",
8347
16
        "spoolss.printer_attributes.keep_printed_jobs", FT_BOOLEAN,
8348
16
        32, TFS(&tfs_printer_attributes_keep_printed_jobs),
8349
16
        PRINTER_ATTRIBUTE_KEEPPRINTEDJOBS, NULL,
8350
16
        HFILL }},
8351
8352
16
    { &hf_printer_attributes_do_complete_first,
8353
16
      { "Do complete first",
8354
16
        "spoolss.printer_attributes.do_complete_first", FT_BOOLEAN,
8355
16
        32, TFS(&tfs_printer_attributes_do_complete_first),
8356
16
        PRINTER_ATTRIBUTE_DO_COMPLETE_FIRST, NULL,
8357
16
        HFILL }},
8358
8359
16
    { &hf_printer_attributes_work_offline,
8360
16
      { "Work offline (9x/ME only)",
8361
16
        "spoolss.printer_attributes.work_offline", FT_BOOLEAN,
8362
16
        32, TFS(&tfs_printer_attributes_work_offline),
8363
16
        PRINTER_ATTRIBUTE_WORK_OFFLINE, NULL, HFILL }},
8364
8365
16
    { &hf_printer_attributes_enable_bidi,
8366
16
      { "Enable bidi (9x/ME only)",
8367
16
        "spoolss.printer_attributes.enable_bidi", FT_BOOLEAN,
8368
16
        32, TFS(&tfs_printer_attributes_enable_bidi),
8369
16
        PRINTER_ATTRIBUTE_ENABLE_BIDI, NULL, HFILL }},
8370
8371
16
    { &hf_printer_attributes_raw_only,
8372
16
      { "Raw only", "spoolss.printer_attributes.raw_only",
8373
16
        FT_BOOLEAN, 32, TFS(&tfs_printer_attributes_raw_only),
8374
16
        PRINTER_ATTRIBUTE_RAW_ONLY, NULL, HFILL }},
8375
8376
16
    { &hf_printer_attributes_published,
8377
16
      { "Published", "spoolss.printer_attributes.published",
8378
16
        FT_BOOLEAN, 32, TFS(&tfs_printer_attributes_published),
8379
16
        PRINTER_ATTRIBUTE_PUBLISHED, NULL, HFILL }},
8380
8381
    /* Printer Driver attributes */
8382
8383
16
    { &hf_printer_driver_attributes,
8384
16
      { "Driver Attributes", "spoolss.printer_driver_attributes", FT_UINT32,
8385
16
        BASE_HEX, NULL, 0, NULL, HFILL }},
8386
8387
16
    { &hf_printer_driver_attributes_package_aware,
8388
16
      { "Package Aware", "spoolss.printer_driver_attributes.packageaware", FT_BOOLEAN,
8389
16
        32, TFS(&tfs_printer_driver_attributes_package_aware),
8390
16
        PRINTER_DRIVER_PACKAGE_AWARE, NULL, HFILL }},
8391
8392
16
    { &hf_printer_driver_attributes_xps,
8393
16
      { "XPS", "spoolss.printer_driver_attributes.xps", FT_BOOLEAN,
8394
16
        32, TFS(&tfs_printer_driver_attributes_xps),
8395
16
        PRINTER_DRIVER_XPS, NULL, HFILL }},
8396
8397
16
    { &hf_printer_driver_attributes_sandbox_enabled,
8398
16
      { "Sandbox enabled", "spoolss.printer_driver_attributes.sandboxenabled", FT_BOOLEAN,
8399
16
        32, TFS(&tfs_printer_driver_attributes_sandbox_enabled),
8400
16
        PRINTER_DRIVER_SANDBOX_ENABLED, NULL, HFILL }},
8401
8402
16
    { &hf_printer_driver_attributes_class,
8403
16
      { "Class Driver", "spoolss.printer_driver_attributes.class", FT_BOOLEAN,
8404
16
        32, TFS(&tfs_printer_driver_attributes_class),
8405
16
        PRINTER_DRIVER_CLASS, NULL, HFILL }},
8406
8407
16
    { &hf_printer_driver_attributes_derived,
8408
16
      { "Derived Driver", "spoolss.printer_driver_attributes.derived", FT_BOOLEAN,
8409
16
        32, TFS(&tfs_printer_driver_attributes_derived),
8410
16
        PRINTER_DRIVER_DERIVED, NULL, HFILL }},
8411
8412
16
    { &hf_printer_driver_attributes_not_shareable,
8413
16
      { "Not Shareable", "spoolss.printer_driver_attributes.notshareable", FT_BOOLEAN,
8414
16
        32, TFS(&tfs_printer_driver_attributes_not_shareable),
8415
16
        PRINTER_DRIVER_NOT_SHAREABLE, NULL, HFILL }},
8416
8417
16
    { &hf_printer_driver_attributes_category_fax,
8418
16
      { "Category Fax", "spoolss.printer_driver_attributes.categoryfax", FT_BOOLEAN,
8419
16
        32, TFS(&tfs_printer_driver_attributes_category_fax),
8420
16
        PRINTER_DRIVER_CATEGORY_FAX, NULL, HFILL }},
8421
8422
16
    { &hf_printer_driver_attributes_category_file,
8423
16
      { "Category File", "spoolss.printer_driver_attributes.categoryfile", FT_BOOLEAN,
8424
16
        32, TFS(&tfs_printer_driver_attributes_category_file),
8425
16
        PRINTER_DRIVER_CATEGORY_FILE, NULL, HFILL }},
8426
8427
16
    { &hf_printer_driver_attributes_category_virtual,
8428
16
      { "Category Virtual", "spoolss.printer_driver_attributes.categoryvirtual", FT_BOOLEAN,
8429
16
        32, TFS(&tfs_printer_driver_attributes_category_virtual),
8430
16
        PRINTER_DRIVER_CATEGORY_VIRTUAL, NULL, HFILL }},
8431
8432
16
    { &hf_printer_driver_attributes_category_service,
8433
16
      { "Category Service", "spoolss.printer_driver_attributes.categoryservice", FT_BOOLEAN,
8434
16
        32, TFS(&tfs_printer_driver_attributes_category_service),
8435
16
        PRINTER_DRIVER_CATEGORY_SERVICE, NULL, HFILL }},
8436
8437
16
    { &hf_printer_driver_attributes_soft_reset_required,
8438
16
      { "Soft Reset Required", "spoolss.printer_driver_attributes.softresetrequired", FT_BOOLEAN,
8439
16
        32, TFS(&tfs_printer_driver_attributes_soft_reset_required),
8440
16
        PRINTER_DRIVER_SOFT_RESET_REQUIRED, NULL, HFILL }},
8441
8442
16
    { &hf_printer_driver_attributes_category_3d,
8443
16
      { "Category 3D", "spoolss.printer_driver_attributes.category3d", FT_BOOLEAN,
8444
16
        32, TFS(&tfs_printer_driver_attributes_category_3d),
8445
16
        PRINTER_DRIVER_CATEGORY_3D, NULL, HFILL }},
8446
8447
8448
    /* Timestamps */
8449
8450
16
    { &hf_time_year,
8451
16
      { "Year", "spoolss.time.year", FT_UINT32, BASE_DEC,
8452
16
        NULL, 0x0, NULL, HFILL }},
8453
8454
16
    { &hf_time_month,
8455
16
      { "Month", "spoolss.time.month", FT_UINT32, BASE_DEC,
8456
16
        NULL, 0x0, NULL, HFILL }},
8457
8458
16
    { &hf_time_dow,
8459
16
      { "Day of week", "spoolss.time.dow", FT_UINT32, BASE_DEC,
8460
16
        NULL, 0x0, NULL, HFILL }},
8461
8462
16
    { &hf_time_day,
8463
16
      { "Day", "spoolss.time.day", FT_UINT32, BASE_DEC,
8464
16
        NULL, 0x0, NULL, HFILL }},
8465
8466
16
    { &hf_time_hour,
8467
16
      { "Hour", "spoolss.time.hour", FT_UINT32, BASE_DEC,
8468
16
        NULL, 0x0, NULL, HFILL }},
8469
8470
16
    { &hf_time_minute,
8471
16
      { "Minute", "spoolss.time.minute", FT_UINT32, BASE_DEC,
8472
16
        NULL, 0x0, NULL, HFILL }},
8473
8474
16
    { &hf_time_second,
8475
16
      { "Second", "spoolss.time.second", FT_UINT32, BASE_DEC,
8476
16
        NULL, 0x0, NULL, HFILL }},
8477
8478
16
    { &hf_time_msec,
8479
16
      { "Millisecond", "spoolss.time.msec", FT_UINT32, BASE_DEC,
8480
16
        NULL, 0x0, NULL, HFILL }},
8481
8482
    /* Userlevel */
8483
8484
16
    { &hf_userlevel_size,
8485
16
      { "Size", "spoolss.userlevel.size",
8486
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8487
8488
16
    { &hf_userlevel_client,
8489
16
      { "Client", "spoolss.userlevel.client", FT_STRING,
8490
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8491
8492
16
    { &hf_userlevel_user,
8493
16
      { "User", "spoolss.userlevel.user", FT_STRING,
8494
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8495
8496
16
    { &hf_userlevel_build,
8497
16
      { "Build", "spoolss.userlevel.build",
8498
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8499
8500
16
    { &hf_userlevel_major,
8501
16
      { "Major", "spoolss.userlevel.major",
8502
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8503
8504
16
    { &hf_userlevel_minor,
8505
16
      { "Minor", "spoolss.userlevel.minor",
8506
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8507
8508
16
    { &hf_userlevel_processor,
8509
16
      { "Processor", "spoolss.userlevel.processor",
8510
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8511
8512
    /* EnumprinterdataEx RPC */
8513
8514
16
    { &hf_enumprinterdataex_name_offset,
8515
16
      { "Name offset", "spoolss.enumprinterdataex.name_offset",
8516
16
        FT_UINT32, BASE_DEC, NULL, 0x0,
8517
16
        NULL, HFILL }},
8518
8519
16
    { &hf_enumprinterdataex_name_len,
8520
16
      { "Name len", "spoolss.enumprinterdataex.name_len",
8521
16
        FT_UINT32, BASE_DEC, NULL, 0x0,
8522
16
        NULL, HFILL }},
8523
8524
16
    { &hf_enumprinterdataex_name,
8525
16
      { "Name", "spoolss.enumprinterdataex.name",
8526
16
        FT_STRING, BASE_NONE, NULL, 0x0,
8527
16
        NULL, HFILL }},
8528
8529
16
    { &hf_enumprinterdataex_val_offset,
8530
16
      { "Value offset", "spoolss.enumprinterdataex.value_offset",
8531
16
        FT_UINT32, BASE_DEC, NULL, 0x0,
8532
16
        NULL, HFILL }},
8533
8534
16
    { &hf_enumprinterdataex_val_len,
8535
16
      { "Value len", "spoolss.enumprinterdataex.value_len",
8536
16
        FT_UINT32, BASE_DEC, NULL, 0x0,
8537
16
        NULL, HFILL }},
8538
8539
16
    { &hf_enumprinterdataex_val_dword_high,
8540
16
      { "DWORD value (high)",
8541
16
        "spoolss.enumprinterdataex.val_dword.high",
8542
16
        FT_UINT16, BASE_DEC, NULL, 0x0,
8543
16
        NULL, HFILL }},
8544
8545
16
    { &hf_enumprinterdataex_value_null,
8546
16
      { "Value",
8547
16
        "spoolss.enumprinterdataex.val_null",
8548
16
        FT_UINT32, BASE_DEC, NULL, 0x0,
8549
16
        NULL, HFILL }},
8550
8551
16
    { &hf_enumprinterdataex_value_uint,
8552
16
      { "Value",
8553
16
        "spoolss.enumprinterdataex.val_uint",
8554
16
        FT_UINT32, BASE_DEC, NULL, 0x0,
8555
16
        NULL, HFILL }},
8556
8557
16
    { &hf_enumprinterdataex_value_binary,
8558
16
      { "Value",
8559
16
        "spoolss.enumprinterdataex.val_binary",
8560
16
        FT_BYTES, BASE_NONE, NULL, 0x0,
8561
16
        NULL, HFILL }},
8562
8563
16
    { &hf_enumprinterdataex_value_multi_sz,
8564
16
      { "Value",
8565
16
        "spoolss.enumprinterdataex.val_multi_sz",
8566
16
        FT_BYTES, BASE_NONE, NULL, 0x0,
8567
16
        NULL, HFILL }},
8568
8569
16
    { &hf_enumprinterdataex_val_dword_low,
8570
16
      { "DWORD value (low)",
8571
16
        "spoolss.enumprinterdataex.val_dword.low",
8572
16
        FT_UINT16, BASE_DEC, NULL, 0x0,
8573
16
        NULL, HFILL }},
8574
8575
    /* RouterReplyPrinter RPC */
8576
8577
16
    { &hf_routerreplyprinter_condition,
8578
16
      { "Condition", "spoolss.routerreplyprinter.condition",
8579
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8580
8581
16
    { &hf_routerreplyprinter_unknown1,
8582
16
      { "Unknown1", "spoolss.routerreplyprinter.unknown1",
8583
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8584
8585
16
    { &hf_routerreplyprinter_changeid,
8586
16
      { "Change id", "spoolss.routerreplyprinter.changeid",
8587
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8588
8589
    /* EnumPrinterKey RPC */
8590
8591
16
    { &hf_keybuffer_size,
8592
16
      { "Key Buffer size", "spoolss.keybuffer.size", FT_UINT32,
8593
16
        BASE_DEC, NULL, 0x0, "Size of buffer", HFILL }},
8594
8595
    /* SetJob RPC */
8596
8597
16
    { &hf_setjob_cmd,
8598
16
      { "Set job command", "spoolss.setjob.cmd", FT_UINT32,
8599
16
        BASE_DEC, VALS(setjob_commands), 0x0, "Printer data name",
8600
16
        HFILL }},
8601
8602
    /* EnumJobs RPC */
8603
8604
16
    { &hf_enumjobs_firstjob,
8605
16
      { "First job", "spoolss.enumjobs.firstjob", FT_UINT32,
8606
16
        BASE_DEC, NULL, 0x0, "Index of first job to return",
8607
16
        HFILL }},
8608
8609
16
    { &hf_enumjobs_numjobs,
8610
16
      { "Num jobs", "spoolss.enumjobs.numjobs", FT_UINT32,
8611
16
        BASE_DEC, NULL, 0x0, "Number of jobs to return", HFILL }},
8612
8613
    /* Security descriptor buffer */
8614
8615
16
    { &hf_secdescbuf_maxlen,
8616
16
      { "Max len", "spoolss.secdescbuf.max_len",
8617
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8618
8619
16
    { &hf_secdescbuf_undoc,
8620
16
      { "Undocumented", "spoolss.secdescbuf.undoc",
8621
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8622
8623
16
    { &hf_secdescbuf_len,
8624
16
      { "Length", "spoolss.secdescbuf.len",
8625
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8626
8627
    /* Spool printer info */
8628
8629
16
    { &hf_spool_printer_info_devmode_ptr,
8630
16
      { "Devmode pointer", "spoolss.spoolprinterinfo.devmode_ptr",
8631
16
        FT_UINT32, BASE_HEX, NULL, 0, NULL, HFILL }},
8632
8633
16
    { &hf_spool_printer_info_secdesc_ptr,
8634
16
      { "Secdesc pointer", "spoolss.spoolprinterinfo.secdesc_ptr",
8635
16
        FT_UINT32, BASE_HEX, NULL, 0, NULL, HFILL }},
8636
8637
    /* WritePrinter RPC */
8638
8639
16
    { &hf_writeprinter_numwritten,
8640
16
      { "Num written", "spoolss.writeprinter.numwritten",
8641
16
        FT_UINT32, BASE_DEC, NULL, 0x0, "Number of bytes written",
8642
16
        HFILL }},
8643
8644
    /* Setprinterdataex RPC */
8645
8646
16
    { &hf_setprinterdataex_max_len,
8647
16
      { "Max len", "spoolss.setprinterdataex.max_len",
8648
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8649
8650
16
    { &hf_setprinterdataex_real_len,
8651
16
      { "Real len", "spoolss.setprinterdataex.real_len",
8652
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8653
8654
16
    { &hf_setprinterdataex_data,
8655
16
      { "Data", "spoolss.setprinterdataex.data",
8656
16
        FT_BYTES, BASE_NONE, NULL, 0, NULL, HFILL }},
8657
8658
    /* Specific access rights */
8659
8660
16
    { &hf_access_required,
8661
16
      { "Access required", "spoolss.access_required",
8662
16
        FT_UINT32, BASE_HEX, NULL, 0x0, NULL,
8663
16
        HFILL }},
8664
8665
16
    { &hf_server_access_admin,
8666
16
      { "Server admin", "spoolss.access_mask.server_admin",
8667
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
8668
16
        SERVER_ACCESS_ADMINISTER, NULL, HFILL }},
8669
8670
16
    { &hf_server_access_enum,
8671
16
      { "Server enum", "spoolss.access_mask.server_enum",
8672
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
8673
16
        SERVER_ACCESS_ENUMERATE, NULL, HFILL }},
8674
8675
16
    { &hf_printer_access_admin,
8676
16
      { "Printer admin", "spoolss.access_mask.printer_admin",
8677
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
8678
16
        PRINTER_ACCESS_ADMINISTER, NULL, HFILL }},
8679
8680
16
    { &hf_printer_access_use,
8681
16
      { "Printer use", "spoolss.access_mask.printer_use",
8682
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
8683
16
        PRINTER_ACCESS_USE, NULL, HFILL }},
8684
8685
16
    { &hf_job_access_admin,
8686
16
      { "Job admin", "spoolss.access_mask.job_admin",
8687
16
        FT_BOOLEAN, 32, TFS(&tfs_set_notset),
8688
16
        JOB_ACCESS_ADMINISTER, NULL, HFILL }},
8689
8690
    /* Printer information */
8691
8692
16
    { &hf_printer_cjobs,
8693
16
      { "CJobs", "spoolss.printer.cjobs", FT_UINT32,
8694
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8695
8696
16
    { &hf_printer_total_jobs,
8697
16
      { "Total jobs", "spoolss.printer.total_jobs", FT_UINT32,
8698
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8699
8700
16
    { &hf_printer_total_bytes,
8701
16
      { "Total bytes", "spoolss.printer.total_bytes", FT_UINT32,
8702
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8703
8704
16
    { &hf_printer_global_counter,
8705
16
      { "Global counter", "spoolss.printer.global_counter",
8706
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8707
8708
16
    { &hf_printer_total_pages,
8709
16
      { "Total pages", "spoolss.printer.total_pages", FT_UINT32,
8710
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8711
8712
16
    { &hf_printer_major_version,
8713
16
      { "Major version", "spoolss.printer.major_version",
8714
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8715
8716
16
    { &hf_printer_build_version,
8717
16
      { "Build version", "spoolss.printer.build_version",
8718
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8719
8720
16
    { &hf_printer_unk7,
8721
16
      { "Unknown 7", "spoolss.printer.unknown7", FT_UINT32,
8722
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8723
8724
16
    { &hf_printer_unk8,
8725
16
      { "Unknown 8", "spoolss.printer.unknown8", FT_UINT32,
8726
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8727
8728
16
    { &hf_printer_unk9,
8729
16
      { "Unknown 9", "spoolss.printer.unknown9", FT_UINT32,
8730
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8731
8732
16
    { &hf_printer_session_ctr,
8733
16
      { "Session counter", "spoolss.printer.session_ctr",
8734
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8735
8736
16
    { &hf_printer_unk11,
8737
16
      { "Unknown 11", "spoolss.printer.unknown11", FT_UINT32,
8738
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8739
8740
16
    { &hf_printer_printer_errors,
8741
16
      { "Printer errors", "spoolss.printer.printer_errors",
8742
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8743
8744
16
    { &hf_printer_unk13,
8745
16
      { "Unknown 13", "spoolss.printer.unknown13", FT_UINT32,
8746
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8747
8748
16
    { &hf_printer_unk14,
8749
16
      { "Unknown 14", "spoolss.printer.unknown14", FT_UINT32,
8750
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8751
8752
16
    { &hf_printer_unk15,
8753
16
      { "Unknown 15", "spoolss.printer.unknown15", FT_UINT32,
8754
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8755
8756
16
    { &hf_printer_unk16,
8757
16
      { "Unknown 16", "spoolss.printer.unknown16", FT_UINT32,
8758
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8759
8760
16
    { &hf_printer_changeid,
8761
16
      { "Change id", "spoolss.printer.changeid", FT_UINT32,
8762
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8763
8764
16
    { &hf_printer_unk18,
8765
16
      { "Unknown 18", "spoolss.printer.unknown18", FT_UINT32,
8766
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8767
8768
16
    { &hf_printer_unk20,
8769
16
      { "Unknown 20", "spoolss.printer.unknown20", FT_UINT32,
8770
16
        BASE_DEC, NULL, 0, NULL, HFILL }},
8771
8772
16
    { &hf_printer_c_setprinter,
8773
16
      { "Csetprinter", "spoolss.printer.c_setprinter",
8774
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8775
8776
16
    { &hf_printer_unk22,
8777
16
      { "Unknown 22", "spoolss.printer.unknown22",
8778
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8779
8780
16
    { &hf_printer_unk23,
8781
16
      { "Unknown 23", "spoolss.printer.unknown23",
8782
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8783
8784
16
    { &hf_printer_unk24,
8785
16
      { "Unknown 24", "spoolss.printer.unknown24",
8786
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8787
8788
16
    { &hf_printer_unk25,
8789
16
      { "Unknown 25", "spoolss.printer.unknown25",
8790
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8791
8792
16
    { &hf_printer_unk26,
8793
16
      { "Unknown 26", "spoolss.printer.unknown26",
8794
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8795
8796
16
    { &hf_printer_unk27,
8797
16
      { "Unknown 27", "spoolss.printer.unknown27",
8798
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8799
8800
16
    { &hf_printer_unk28,
8801
16
      { "Unknown 28", "spoolss.printer.unknown28",
8802
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8803
8804
16
    { &hf_printer_unk29,
8805
16
      { "Unknown 29", "spoolss.printer.unknown29",
8806
16
        FT_UINT16, BASE_DEC, NULL, 0, NULL, HFILL }},
8807
8808
16
    { &hf_printer_flags,
8809
16
      { "Flags", "spoolss.printer.flags",
8810
16
        FT_UINT32, BASE_HEX, NULL, 0, NULL, HFILL }},
8811
8812
16
    { &hf_printer_priority,
8813
16
      { "Priority", "spoolss.printer.priority",
8814
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8815
8816
16
    { &hf_printer_default_priority,
8817
16
      { "Default Priority", "spoolss.printer.default_priority",
8818
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8819
8820
16
    { &hf_printer_averageppm,
8821
16
      { "Average PPM", "spoolss.printer.averageppm",
8822
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8823
8824
16
    { &hf_printer_jobs,
8825
16
      { "Jobs", "spoolss.printer.jobs",
8826
16
        FT_UINT32, BASE_DEC, NULL, 0, NULL, HFILL }},
8827
8828
16
    { &hf_printer_guid,
8829
16
      { "GUID", "spoolss.printer.guid", FT_STRING,
8830
16
        BASE_NONE, NULL, 0, NULL, HFILL }},
8831
8832
16
    { &hf_printer_action,
8833
16
      { "Action", "spoolss.printer.action", FT_UINT32, BASE_DEC,
8834
16
       VALS(getprinter_action_vals), 0, NULL, HFILL }},
8835
16
  };
8836
8837
16
  static int *ett[] = {
8838
16
    &ett_dcerpc_spoolss,
8839
16
    &ett_PRINTER_DATATYPE,
8840
16
    &ett_DEVMODE_CTR,
8841
16
    &ett_DEVMODE,
8842
16
    &ett_DEVMODE_fields,
8843
16
    &ett_USER_LEVEL_CTR,
8844
16
    &ett_USER_LEVEL_1,
8845
16
    &ett_BUFFER,
8846
16
    &ett_PRINTER_INFO,
8847
16
    &ett_SPOOL_PRINTER_INFO_LEVEL,
8848
16
    &ett_PRINTER_INFO_0,
8849
16
    &ett_PRINTER_INFO_1,
8850
16
    &ett_PRINTER_INFO_2,
8851
16
    &ett_PRINTER_INFO_3,
8852
16
    &ett_PRINTER_INFO_5,
8853
16
    &ett_PRINTER_INFO_7,
8854
16
    &ett_RELSTR,
8855
16
    &ett_RELSTR_ARRAY,
8856
16
    &ett_FORM_REL,
8857
16
    &ett_FORM_CTR,
8858
16
    &ett_FORM_1,
8859
16
    &ett_JOB_INFO_1,
8860
16
    &ett_JOB_INFO_2,
8861
16
    &ett_SEC_DESC_BUF,
8862
16
    &ett_SYSTEM_TIME,
8863
16
    &ett_DOC_INFO_1,
8864
16
    &ett_DOC_INFO,
8865
16
    &ett_DOC_INFO_CTR,
8866
16
    &ett_printerdata_value,
8867
16
    &ett_printerdata_data,
8868
16
    &ett_writeprinter_buffer,
8869
16
    &ett_DRIVER_INFO_1,
8870
16
    &ett_DRIVER_INFO_2,
8871
16
    &ett_DRIVER_INFO_3,
8872
16
    &ett_DRIVER_INFO_6,
8873
16
    &ett_DRIVER_INFO_8,
8874
16
    &ett_DRIVER_INFO_101,
8875
16
    &ett_CORE_PRINTER_DRIVER,
8876
16
    &ett_rffpcnex_flags,
8877
16
    &ett_notify_options_flags,
8878
16
    &ett_NOTIFY_INFO_DATA,
8879
16
    &ett_NOTIFY_OPTION,
8880
16
    &ett_printer_attributes,
8881
16
    &ett_printer_driver_attributes,
8882
16
    &ett_job_status,
8883
16
    &ett_enumprinters_flags,
8884
16
    &ett_PRINTER_DATA_CTR,
8885
16
    &ett_printer_enumdataex_value,
8886
16
  };
8887
8888
16
  static ei_register_info ei[] = {
8889
16
    { &ei_unimplemented_dissector, { "spoolss.unimplemented_dissector", PI_UNDECODED, PI_WARN, "Unimplemented dissector: SPOOLSS", EXPFILL }},
8890
16
    { &ei_unknown_data, { "spoolss.unknown_data", PI_UNDECODED, PI_WARN, "Unknown data follows", EXPFILL }},
8891
16
    { &ei_printer_info_level, { "spoolss.printer.unknown", PI_PROTOCOL, PI_WARN, "Unknown printer info level", EXPFILL }},
8892
16
    { &ei_spool_printer_info_level, { "spoolss.spool_printer.unknown", PI_PROTOCOL, PI_WARN, "Unknown spool printer info level", EXPFILL }},
8893
16
    { &ei_form_level, { "spoolss.form.level.unknown", PI_PROTOCOL, PI_WARN, "Unknown form info level", EXPFILL }},
8894
16
    { &ei_job_info_level, { "spoolss.job_info.level.unknown", PI_PROTOCOL, PI_WARN, "Unknown job info level", EXPFILL }},
8895
16
    { &ei_driver_info_level, { "spoolss.driver_info.level.unknown", PI_PROTOCOL, PI_WARN, "Unknown driver info level", EXPFILL }},
8896
16
    { &ei_level, { "spoolss.level.unknown", PI_PROTOCOL, PI_WARN, "Info level unknown", EXPFILL }},
8897
16
    { &ei_notify_info_data_type, { "spoolss.notify_info_data.type.unknown", PI_PROTOCOL, PI_WARN, "Unknown notify type", EXPFILL }},
8898
16
    { &ei_enumprinterdataex_value, { "spoolss.enumprinterdataex.val_unknown", PI_PROTOCOL, PI_WARN, "Unknown value type", EXPFILL }},
8899
16
    { &ei_buffer_size_too_long, { "spoolss.buffer.size.invalid", PI_PROTOCOL, PI_ERROR, "Buffer size too long", EXPFILL }},
8900
16
  };
8901
8902
16
  expert_module_t* expert_dcerpc_spoolss;
8903
8904
16
  proto_dcerpc_spoolss = proto_register_protocol("Microsoft Spool Subsystem", "SPOOLSS", "spoolss");
8905
8906
16
  proto_register_field_array(proto_dcerpc_spoolss, hf, array_length(hf));
8907
16
  proto_register_subtree_array(ett, array_length(ett));
8908
16
  expert_dcerpc_spoolss = expert_register_protocol(proto_dcerpc_spoolss);
8909
16
  expert_register_field_array(expert_dcerpc_spoolss, ei, array_length(ei));
8910
16
}
8911
8912
/* Protocol handoff */
8913
8914
static e_guid_t uuid_dcerpc_spoolss = {
8915
  0x12345678, 0x1234, 0xabcd,
8916
  { 0xef, 0x00, 0x01, 0x23, 0x45, 0x67, 0x89, 0xab }
8917
};
8918
8919
static uint16_t ver_dcerpc_spoolss = 1;
8920
8921
void
8922
proto_reg_handoff_dcerpc_spoolss(void)
8923
16
{
8924
8925
  /* Register protocol as dcerpc */
8926
8927
16
  dcerpc_init_uuid(proto_dcerpc_spoolss, ett_dcerpc_spoolss,
8928
16
       &uuid_dcerpc_spoolss, ver_dcerpc_spoolss,
8929
16
       dcerpc_spoolss_dissectors, hf_opnum);
8930
16
}
8931
8932
/*
8933
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
8934
 *
8935
 * Local variables:
8936
 * c-basic-offset: 8
8937
 * tab-width: 8
8938
 * indent-tabs-mode: t
8939
 * End:
8940
 *
8941
 * vi: set shiftwidth=8 tabstop=8 noexpandtab:
8942
 * :indentSize=8:tabSize=8:noTabs=false:
8943
 */