
    gƀ                        S r SSKrSSKrSSKrSSKrSSKJr  SSKJrJr  SSK	J
r
JrJr  SSK	r	SSKJrJrJrJrJrJr  SSKJr  SSKJr  SS	KJr  SS
KJr  SSKJr  SSKJr  SSKrSr Sr!Sr"Sr#Sr$Sr%Sr&\'" / SQ5      r( " S S\)5      r*S r+S r,S+S jr-S r.S+S jr/S r0S r1S r2S r3S r4S  r5S! r6S" r7S# r8S$ r9S% r:S& r;S' r<S( r=S) r>S* r?g),z>Helpers used for upgrading between different database formats.    N)cmp)Ldbversion)SCOPE_SUBTREESCOPE_ONELEVEL
SCOPE_BASE)provision_paths_from_lpgetpolicypathcreate_gpo_struct	provisionProvisioningErrorsecretsdb_self_join)	FILL_FULL)drsblobs)SEC_CHAN_BDC)
ndr_unpack)SamDB)_glue               )dnwhenCreatedwhenChanged
objectGUID
uSNCreatedreplPropertyMetaData
uSNChanged
parentGUIDobjectCategorydistinguishedNamenTMixedDomainshowInAdvancedViewOnlyinstanceTypezmsDS-Behavior-VersionnextRidcnversionNumberlmPwdHistory
pwdLastSetntPwdHistory
unicodePwddBCSPwdsupplementalCredentialsgPCUserExtensionNamesgPCMachineExtensionNames	maxPwdAgesecretpossibleInferiors	privilegesAMAccountTypec                   2    \ rS rSrS rS rS rS rS rSr	g)	ProvisionLDBD   c                 t    S U l         S U l        S U l        S U l        S U l        S U l        S U l        S U l        g N)samsecretsidmapr6   hkcrhkcuhkuhklmselfs    6/usr/lib/python3/dist-packages/samba/upgradehelpers.py__init__ProvisionLDB.__init__F   s:    
			    c                 ^    U R                   U R                  U R                  U R                  4$ r<   )r=   r>   r?   r6   rD   s    rF   dbsProvisionLDB.dbsP   s!    $,,

DNNCCrI   c                 R    U R                  5        H  nUR                  5         M     g r<   )rK   transaction_startrE   dbs     rF   startTransactionsProvisionLDB.startTransactionsS   s    ((*B  " rI   c                     SnU R                  5        H  n UR                  5         M     U$ ! [         a    Sn M)  f = f)NTF)rK   transaction_cancel	Exception)rE   okrP   s      rF   groupedRollbackProvisionLDB.groupedRollback\   sE    ((*B%%' 
 	  s   -==c                 $    U R                  5        H  nUR                  5         M      U R                  5        H  nUR	                  5         M     g! [         a    U R                  5       s $ f = f! [         a    U R                  5       s $ f = f)NT)rK   transaction_prepare_commitrU   rW   transaction_commitrO   s     rF   groupedCommitProvisionLDB.groupedCommitj   s    	*hhj--/ !	*hhj%%' ! %  	*''))	*  	*''))	*s"   'A 'A2 A/.A/2BB)r@   rA   rC   rB   r?   r6   r=   r>   N)
__name__
__module____qualname____firstlineno__rG   rK   rQ   rW   r\   __static_attributes__ rI   rF   r9   r9   D   s    D#rI   r9   c           	          [        5       n[        U R                  UUUS/SS9Ul        [	        U R
                  X!US9Ul        [	        U R                  X!US9Ul        [	        U R                  X!US9Ul        U$ )au  Return LDB object mapped on most important databases

:param paths: An object holding the different importants paths for provision object
:param creds: Credential used for opening LDB files
:param session: Session to use for opening LDB files
:param lp: A loadparam object
:return: A ProvisionLDB object that contains LDB object for the different LDB files of the provisionzmodules:samba_dsdbr   )session_infocredentialslpoptionsflags)re   rf   rg   )	r9   r   samdbr=   r   r>   idmapdbr?   r6   )pathscredssessionrg   ldbss        rF   get_ldbsrp      sw     >DU[[")!&23DH u}}7RTUDLU]]PRSDJwVXYDN KrI   c                     SnSnSnU(       aT  U[        U5      :X  a  SnM  U [        X   5      :  a  US-  S:X  a  SnSnU [        X   5      :X  a  SnSnUS-   nU(       a  MT  U$ )a  Check if the usn is in one of the range provided.
To do so, the value is checked to be between the lower bound and
higher bound of a range

:param usn: A integer value corresponding to the usn that we want to update
:param range: A list of integer representing ranges, lower bounds are in
              the even indices, higher in odd indices
:return: True if the usn is in one of the range, False otherwise
r   TFr   r   )lenint)usnrangeidxcontrV   s        rF   usn_in_rangerx      s|     CD	B
#e*DUZ Qw!|D#ej/!DBAg $ IrI   c                 t   Ub  [         R                  R                  U5      (       d  [         R                  " U5        [         R                  R	                  US5      n[         R                  R                  U5      (       d  [         R
                  " U5        [         R                  R	                  US5      nUc  U R                  5       n[         R                  R                  U5      (       d  [        SU-  5      eU R                  5       nUR                  U5        [        XDR                  S5      5      nU$ )a  Get paths to important provision objects (smb.conf, ldb files, ...)

:param param: Param object
:param targetdir: Directory where the provision is (or will be) stored
:param smbconf: Path to the smb.conf file
:return: A list with the path of important provision objectsetczsmb.confzUnable to find smb.conf at %srealm)ospathexistsmkdirjoinmakedirsdefault_pathr   LoadParmloadr	   get)param	targetdirsmbconfetcdirrg   rl   s         rF   	get_pathsr      s     ww~~i((HHYi/ww~~f%%KK'',,vz2$$&77>>'"" ?' IJJ		BGGG#Bw8ELrI   c                    UR                  SS[        U R                  5      -   [        SS/S9n[        US   S   5      R	                  SS5      R	                  S	S5      U l        UR                  S
S[        U R                  5      -   [        SS/S9n[        U5      S:X  a7  [        US   S   5      R	                  SS5      R	                  S	S5      U l        gSU l        g)zUpdate policy ids that could have changed after sam update

:param names: List of key provision parameters
:param samdb: An Ldb object conntected with the sam DB
z#(displayName=Default Domain Policy)zCN=Policies,CN=System,r)   displayName
expressionbasescopeattrsr   { }z/(displayName=Default Domain Controllers Policy)r   N)searchstrrootdnr   replacepolicyidrr   policyid_dc)namesrj   resres2s       rF   update_policyidsr      s     ,,"G4s5<<7HH+D-3H  JC Q&..sB7??RHEN<< $.5ELL8II,T=4I  KD 4yA~Q.66sB?GGRP rI   c                    [         R                  R                  U5      (       a  [        R                  " U5        [         R
                  " U5        UR                  SU5        [        XA40 SU_SU_S[        _SU R                  _SU R                  _SU R                  _SU R                  _S	U R                  _S
U R                  _SU R                  _SU R                   R#                  5       _SS_SS_SU R$                  _SU R&                  _SS_SS_SS_SS_SS_SS_SS_SU R(                  _SU R*                  _SS_SS_SU_S U_6$ )!a  Create a new provision.

This provision will be the reference for knowing what has changed in the
since the latest upgrade in the current provision

:param names: List of provision parameters
:param creds: Credentials for the authentication
:param session: Session object
:param smbconf: Path to the smb.conf file
:param provdir: Directory where the provision will be stored
:param logger: A Logger
zProvision stored in %sr   r   
samdb_fillr{   domain
domainguid	domainsidntdsguid
policyguidpolicyguid_dchostnamehostipNhostip6invocationid	adminpass
krbtgtpassmachinepassdnspassrootnobodyusers
serverrolezdomain controllerdom_for_fun_leveldns_backenduseeadbT	use_ntvfsbase_schemaadprep_level)r|   r}   isdirshutilrmtreer   infor   r   r{   r   r   r   r   r   r   netbiosnamelower
invocationr   domainlevelr   )r   rn   r   provdirloggerr   r   s          rF   newprovisionr      s    
ww}}WgHHW
KK('2V 0g 0&03<0DIKK0!LL05:5E5E0  %0 :?0 !&	0 ?D>O>O	0
 $//5570
 AE0
 OS0 #("2"20 ?Doo0 !%0 370 AE0 LP0 !0 )-0 !40 (-'8'80 GLFWFW0 "0 .20 @K0 #/0 0rI   c                    [         R                  " S5      nUR                  [        U 5      5      nUR                  [        U5      5      n[	        [        U5      [        U5      5      n[        U5      S-
  n[        U5      S-
  n[        SU5       Hg  n[        X6U-
     XGU-
     5      n	U	S:w  a  U	s  $ XS-
  :X  d  M-  Xg:w  d.   SSR                  U5      -   S-   SR                  U5      -   5       eXg:  a    g  g   W	$ )zSorts two DNs in the lexicographical order it and put higher level DN
before.

So given the dns cn=bar,cn=foo and cn=foo the later will be return as
smaller

:param x: First object to compare
:param y: Second object to compare
z
(?<!\\), ?r   r   zPB PB PB z / r   )	recompilesplitr   minrr   ru   r   r   )
xyptab1tab2minimumlen1len2irets
             rF   dn_sortr     s     	

=!A773q6?D773q6?D#d)SY'Gt9q=Dt9q=D1g$ax.$ax.1!8JaK|YZ#((4.%@5%H388TX>%YY|;  JrI   c           	          [        U5      R                  SS5      u  p#U R                  U[        R                  " X< SU< 35      S/5        U R                  [        R                  " X< SU< 35      US/5        g)zPerform a back and forth rename to trigger renaming on attribute that
can't be directly modified.

:param lbdobj: An Ldb Object
:param dn: DN of the object to manipulate
=r   z=foozrelax:0N)r   r   renameldbDn)ldbobjr   beforeafters       rF   identic_renamer   +  s^     "gmmC+OV
MM"cffV65%ABYKP
MM#&&vu!=>YKPrI   c           
      	   U" [         S5        U R                  S[        S9nUR                  S[        S9nU(       d   S5       e[        U5      S:X  aj  UR	                  [
        R                  " 5       US   5      nUS   R                  R                  UR
                  5      Ul        UR                  US   5        O=UR	                  US   US   5      nUS   R                  Ul        UR                  U5        U R                  SS[        S/S	9nUR                  SS[        S/S	9n0 n0 n/ n/ n	[
        R                  " 5       n
[        S[        U5      5       H)  nX;   S   U[        X;   S   5      R                  5       '   M+     [        S[        U5      5       H)  nXK   S   U[        XK   S   5      R                  5       '   M+     UR                  5        H0  nX;  a  UR!                  Xl   5        M  U	R!                  Xl   5        M2     U H  nU R                  S
U-  S[        S9nUR	                  XS   5      n["         H  nUR%                  U5        M     U" [&        SUS   R                  -  5        U H  nU" [&        SU-  5        M     US   R                  R                  UR
                  5      Ul        UR                  U5        M     U	 H  nU R                  S
U-  S[        S9nUR                  S
U-  S[        S9nUR	                  US   US   5      n["         H  nUR%                  U5        M     U HQ  nUS:X  a7  U" [&        SUS   R                  -  5        [)        XS   R                  5        M@  UR%                  U5        MS     M     U	 H  nU R                  S
U-  S[        S9nUR                  S
U-  S[        S9nUR	                  US   US   5      n["         H  nUR%                  U5        M     U HD  nUS:X  a  UR%                  U5        US:w  d  M"  U" [&        SU< SUS   R                  < 35        MF     US   R                  Ul        UR                  U5        M     UR                  S[        S/S9n[        U5      S:X  a%  U" [         S5        UR+                  US   S   5        gg)zUpdate secrets.ldb

:param newsecrets_ldb: An LDB object that is connected to the secrets.ldb
    of the reference provision
:param secrets_ldb: An LDB object that is connected to the secrets.ldb
    of the updated provision
zUpdate of secrets.ldbz@MODULES)r   r   z'Reference modules list can not be emptyr   zobjectClass=topr   r   r   distinguishedName=%s)r   r   r   z$Entry %s is missing from secrets.ldbz Adding attribute %snamez/Found attribute name on  %s, must rename the DNmsDS-KeyVersionNumberzAdding/Changing attribute z to z(samaccountname=dns))r   r   r   r   zRemove old dns accountN)SIMPLEr   r   rr   msg_diffr   Messager   copyaddmodifyr   ru   r   r   keysappendhashAttrNotCopiedremoveCHANGEr   delete)newsecrets_ldbsecrets_ldbmessagefunc	referencecurrentdeltahash_newhashlistMissinglistPresentemptyr   kentryattr   s                   rF   update_secretsr   8  s    /0%%:Z%HI  j
 CG???9
7|q$$S[[]IaLAQ<??''		2	!%$$WQZ1>1:==5!%%1B,9$ & II  ,=B'4TF ! DGHDKKKKME1c)n%4=L4FY\$'(..01 &
 1c'l#.5j.>SD!"((*+ $ ]]_=x{+x{+	  "))5Ke5S/1 * H	$$UaL9$CLL %FBaLOO$ 	%C 6 <= Q<??''		2  "))5Ke5S/1 * H	$$0F0NUW+8 % :$$WQZ1>$CLL %Cf}F %:=DQZ]]%L M{aLOO<S!    "))5Ke5SZ\0= * ?	$$0F0NUW+8 % :$$WQZ1>$CLL %C--S!d{F '!*--12	  1:==5!# & )?$1$  AD 4yA~ 89tAwt}- rI   c                     U R                  S[        U5      [        SS/S9n[        U5      S:  a#  US   R	                  S5      (       a
  US   S   nU$ g)zReturn OEM Information on the top level Samba4 use to store version
info in this field

:param samdb: An LDB object connect to sam.ldb
:param rootdn: Root DN of the domain
:return: The content of the field oEMInformation (if any)
(objectClass=*)r   oEMInformationr   r   r   )r   r   r   rr   r   )rj   r   r   r   s       rF   
getOEMInfor     sa     ,,"3#f+'6F/G  IC
3x!|A

#3441v&'rI   c                    U R                  SU[        SS/S9n[        U5      S:  a  US   R                  S5      (       a  [	        US   S   5      nOSnU< S[
        < 3n[        R                  " 5       n[        R                  " U [	        US   S   5      5      Ul	        [        R                  " U[        R                  S5      US'   U R                  U5        gg)	zUpdate the OEMinfo field to add information about upgrade

:param samdb: an LDB object connected to the sam DB
:param rootdn: The string representation of the root DN of
    the provision (ie. DC=...,DC=...)
r   r   r   r   r   r   z, upgrade to N)r   r   rr   r   r   r   r   r   r   r   MessageElementFLAG_MOD_REPLACEr   )rj   r   r   r   r   s        rF   updateOEMInfor    s     ,,"3&'6F/G  IC
3x!|q6::&''s1v./0DD&*G466%SVD\!23"%"4"4T3;O;O5E#GU rI   c                    [        U R                  UR                  UR                  5      n[        R
                  R                  U5      (       d  [        U5        UR                  c  [        S5      e[        U R                  UR                  UR                  5      n[        R
                  R                  U5      (       d  [        U5        gg)z-Create missing GPO file object if needed
    Nz*Policy ID for Domain controller is missing)
r
   sysvol	dnsdomainr   r|   r}   r   r   r   r   )rl   r   dirs      rF   
update_gpor	    s     eoou~~
FC77==#  LMM
eoou7H7H
IC77==# rI   c           	      >   U R                  S[        R                  " U [        U5      5      [        S/S/S9nSn[        U5      S:X  a  [        S5      eU H  n[        UR                  5      R                  5       U;   d  M,  UR                  S5      nU(       d  Sn[        [        U[        UR                  5      R                  5          5      5      n[        [        U5      5      U:  d  M  US-   nU R                  [        UR                  5      S	US
5        M     g)a  For a given hash associating dn and a number, this function will
update the replPropertyMetaData of each dn in the hash, so that the
calculated value of the msDs-KeyVersionNumber is equal or superior to the
one associated to the given dn.

:param samdb: An SamDB object pointing to the sam
:param rootdn: The base DN where we want to start
:param hashDns: A hash with dn as key and number representing the
             minimum value of msDs-KeyVersionNumber that we want to
             have
z(objectClass=user)zmsDs-KeyVersionNumbersearch_options:1:2r   r   r   r   controlsr   z$Unable to find msDs-KeyVersionNumber0r   r.   TN)r   r   r   r   r   rr   r   r   r   r   rs   "set_attribute_replmetadata_version)rj   r   hashDnsr   doneevalr   s           rF   &increment_calculated_keyversion_numberr    s     LL$8!ffUCK8,5L4M#7"8  :E D
5zQ FGGA144y G+ee34Cc'#add)//*;"<=>s3x=7*!8D<<SY=I=DdL rI   c                    U" [         S5        [        XUUS/S9n[        XX$S/S9n[        R                  " 5       nSn	UR	                  SS9n
U
 GH  nUR	                  SUS   -  [
        S	9n[        U5      (       d  UR                  X5      nU" [        S
[        UR                  5      -  5        [        UR                  5      S:X  aW  UR                  [        R                  R                  5      (       a)  UR                  [        R                  R                  5        UR                  R!                  UR                  5      Ul
        UR#                  U5        GM  UR                  US   U5      n[        UR                  5      S:X  a  UR                  XS   5      n	[        UR                  5      S:X  aW  UR                  [        R                  R                  5      (       a)  UR                  [        R                  R                  5        [        UR%                  5       5      S:  d  GM  UR                  R!                  UR                  5      Ul
        UR'                  U5        GM      U	$ )a  Update the provision container db: sam.ldb
This function is aimed for alpha9 and newer;

:param refsampath: Path to the samdb in the reference provision
:param sampath: Path to the samdb in the upgraded provision
:param creds: Credential used for opening LDB files
:param session: Session to use for opening LDB files
:param lp: A loadparam object
:return: A msg_diff object with the difference between the @ATTRIBUTES
         of the current provision and the reference provision
z<Update base samdb by searching difference with reference onezmodules:)re   rf   rg   rh   Nr   r   r   r   )r   r   zAdding %s to sam dbz
@PROVISIONr   z@ATTRIBUTESr   )r   r   r   r   r   r   rr   r   r   r   r   r   sambar   LAST_PROVISION_USN_ATTRIBUTEr   r   r   itemsr   )
refsampathsampathrm   rn   rg   messagerefsamr=   r   	deltaattrr   refentryr   r   s                 rF   delta_update_basesamdbr     s    FJLu.F
g!l$C KKMEI,I

&<x~&M!.  05zzLL1EF1C4DDE8;;</IIeooJJKKU__IIJ{{''		2EHGGENLLq84E8;;=0LL8<	8;;</IIeooJJKKU__IIJ5;;=!A%#;;++EII6

5!) , rI   c                 \    Sn[        U 5      S:  a  SnU  H  nU< SU< S3nM     SU-  nU$ )zConstruct a exists or LDAP search expression.

:param attrs: List of attribute on which we want to create the search
    expression.
:return: A string representing the expression, if attrs is empty an
    empty string is returned
r   r   z(|(z=*)z%s))rr   )r   exprr   s      rF   construct_existor_exprr$  &  s;     D
5zA~C $c*D d{KrI   c                    SUR                   -  nUR                  US/S9n[        US   S   S   5      [        :X  GaF  U R                  U/ S9n[	        U5      S:X  d   e[
        R                  " US   R                  5      n[        R                  " SS5      nUR                  S5      n[
        R                  " U[
        R                  S5      US'   U R                  U5        U R                  SUR                   -  S	/S9n[	        U5      S:X  d   e[        [        US   S	   5      5      n	[        US   S   S   5      n
[        XR                   UR"                  UR$                  UR&                  UR                   UU	U
S
9	  g[)        S5      e)a>  Update (change) the password of the current DC both in the SAM db and in
   secret one

:param samdb: An LDB object related to the sam.ldb file of a given provision
:param secrets_ldb: An LDB object related to the secrets.ldb file of a given
                    provision
:param names: List of key provision parameterszsamAccountName=%s$secureChannelTyper   r   r   r   x   	utf-16-leclearTextPasswordmsDs-keyVersionNumber)r   r{   r   r  r   r   key_version_numbersecure_channel_typez3Unable to find a Secure Channelof type SEC_CHAN_BDCN)r   r   rs   r   rr   r   r   r   r   generate_random_machine_passwordencoder  r  r   r   r   r   r{   r   r  r   )rj   r   r   r   secrets_msgr   msgr   mputf16kvnosecChanTypes              rF   update_machine_account_passwordr5  7  s    &(9(99J$$
,?+@ % BK
;q>-.q12lBlljl;3x1}}kk#a&))$<<S#F$$[1#&#5#5g696J6J6I$K  	Sll';e>O>O'O"9!:  <3x1}}3s1v5678+a.)<=a@AK"'++&+oo&+oo(-(9(9(3/30;	=   !7 8 	8rI   c                     SUR                   -  nUR                  US9n[        U5      S:X  Ga`  U R                  U/ S9n[        U5      S:X  d   e[        R                  " US   R
                  5      n[        R                  " SS5      nUR                  S5      n[        R                  " U[        R                  S	5      US	'   U R                  U5        U R                  US
/S9n[        U5      S:X  d   e[        US   S
   5      n	[        R                  " US   R
                  5      n[        R                  " U[        R                  S5      US'   [        R                  " U	[        R                  S5      US'   UR                  U5        gg)a7  Update (change) the password of the dns both in the SAM db and in
   secret one

:param samdb: An LDB object related to the sam.ldb file of a given provision
:param secrets_ldb: An LDB object related to the secrets.ldb file of a given
                    provision
:param names: List of key provision parameterszsamAccountName=dns-%sr  r   r'  r      r   r)  r*  r+  r4   r   N)r   r   rr   r   r   r   r  generate_random_passwordr/  r  r  r   r   )
rj   r   r   r   r0  r   r1  r   r2  r3  s
             rF   update_dns_account_passwordr9  b  sv    )5+<+<<J$$
$;K
;1lljl;3x1}}kk#a&))$44S#>$$[1#&#5#5g696J6J6I$K  	Sllj"9!:  <3x1}}3q6123kk+a.++,**;+.+?+?+35H (+'9'9$:=:N:N:Q(S#$ 	35 rI   c                 T   SnU R                  U/ S9n[        U5      S:X  d   e[        R                  " US   R                  5      n[
        R                  " SS5      nUR                  S5      n[        R                  " U[        R                  S5      US'   U R                  U5        g	)
zUpdate (change) the password of the krbtgt account

:param samdb: An LDB object related to the sam.ldb file of a given provisionzsamAccountName=krbtgtr'  r   r   r7  r   r)  r*  N)r   rr   r   r   r   r  r.  r/  r  r  r   )rj   r   r   r1  r   kputf16s         rF   update_krbtgt_account_passwordr<    s    
 )J
,,*B,
7Cs8q==
++c!fii
 C 77SAJ,G"11'252F2F2E GC 
LLrI   c           	         0 n[        U5      nUS:X  a  U$ U R                  U[        R                  " U [	        U5      5      [
        USS/S9n[        U5      S:X  a  U$ U H  nU H  nUR                  U5      (       d  M  Xs;   a5  [	        Xg   5      X7   [	        UR                  5      R                  5       '   MU  0 X7'   [	        Xg   5      X7   [	        UR                  5      R                  5       '   M     M     U$ )a  Search a given sam DB for calculated attributes that are
still stored in the db.

:param samdb: An LDB object pointing to the sam
:param rootdn: The base DN where the search should start
:param attrs: A list of attributes to be searched
:return: A hash with attributes as key and an array of
         array. Each array contains the dn and the associated
         values for this attribute as they are stored in the
         sam.r   r  zbypassoperational:0r  r   )
r$  r   r   r   r   r   rr   r   r   r   )rj   r   r   hashAttr#  r   entr   s           rF   search_constructed_attrs_storedr@    s     G!%(DrzLLDsvveS[/I,E#79N"O  QE 5zQCwws||>8;CHGLSVV!2!2!45#%GL8;CHGLSVV!2!2!45   NrI   c                    Sn0 nU R                  US[        R                  S/S/S9nU GH  nUS-   n[        [        R
                  [        US   5      5      R                  nUR                   GH  n[        R                  " UR                  5      S-  nUR                  [        UR                  5      5      n	U	cA  0 n
UR                  U
S'   UR                  U
S	'   SU
S
'   [        UR                  5      /U
S'   0 n	OU	R                  U5      n
U
c?  0 n
UR                  U
S'   UR                  U
S	'   SU
S
'   [        UR                  5      /U
S'   OU
S   UR                  :  a  UR                  U
S'   U
S	   UR                  :  a  UR                  U
S	'   [        UR                  5      U
S   ;  a2  U
S
   S-   U
S
'   U
S   R!                  [        UR                  5      5        XU'   X[        UR                  5      '   GM     GM     X24$ )a  Find ranges of usn grouped by invocation id and then by timestamp
rouned at 1 minute

:param samdb: An LDB object pointing to the samdb
:param basedn: The DN of the forest

:return: A two level dictionary with invoication id as the
        first level, timestamp as the second one and then
        max, min, and number as subkeys, representing respectivily
        the maximum usn for the range, the minimum usn and the number
        of object with usn in this range.
r   zobjectClass=*r    r  )r   r   r   r   r  r   <   r   maxnumlist)r   r   r   r   r   replPropertyMetaDataBlobr   ctrarrayr   nttime2unixoriginating_change_timer   originating_invocation_idoriginating_usnr   r   )rj   basednnb_objhash_idr   r  objominutestamphash_tsobs              rF   findprovisionrangerU    s    FG
,,F ..45!5 6  8C
 !::Q56799< 	 A++A,E,EF"LKkk#a&A&A"BCG--5	--5	5	!!$$i[6
[[-:B ! 1 1BuI ! 1 1BuI !BuI"%add)BvJ%y1#4#44$%$5$55	%y1#4#44$%$5$55	IF3$&uIM5	6
))#add)4#%K 8?C3345;  H rI   c           
         SnU  GHX  nX   n/ nUR                  UR                  5       5        UR                  5         / n	U Hu  n
Xz   nUS   U:  aG  [        R                  " [        R
                  " U
S-  5      5      n[        SXS   US   US   4-  5        Xz   S   S:  d  Md  U	R                  U
5        Mw     [        S[        U	5      5       HZ  nUS:w  d  M  X   nXS	-
     nX-
  S	:X  d  M   [        X~   S   5      [        X   S   5      S	-   :X  d  MG  X~   S   X   S'   S
X~   S'   M\     U	 H)  n
Xz   nUR                  S5      b  M  SX[S   US   U4-  nM+     GM[     US:w  a  [        R                  " USSS9u  nn[        5         [        S5        [        SU-  5        [        SU-  5        [        S[        U5      < SU< S35        SU< SU< 3n[        R                   " UU5        [        R"                  " U5        gg)aE  print the different ranges passed as parameter

:param dic: A dictionary as returned by findprovisionrange
:param limit_print: minimum number of object in a range in order to print it
:param dest: Destination directory
:param samdb_path: Path to the sam.ldb file
:param invoicationid: Invocation ID for the current provision
r   rD  rB  z*%s # of modification: %d  	min: %d max: %dr   rC  iX  r   r   TskippedNz%slastProvisionUSN: %d-%d;%s
usnprovz.ldif)r  prefixsuffixzFTo track the USNs modified/created by provision and upgrade proivsion,zM the following ranges are proposed to be added to your provision sam.ldb: 
%szdWe recommend to review them, and if it's correct to integrate the following ldif: %s in your sam.ldbz,You can load this file like this: ldbadd -H r   
zdn: @PROVISION
provisionnerID: )extendr   sortr   nttime2stringunix2nttimeprintr   ru   rr   rs   r   tempfilemkstempr   r|   writeclose)diclimit_printdest
samdb_pathr   ldifidrS  sorted_keyskept_recordr   rP  dtr   key1key2fdfiles                     rF   print_provision_rangesrr    s    D'7<<>*A*C5zK'(():):1r6)BCCru:GJ5zGJ5zGS S T z% 3&""1%  q#k*+AAv"~"q5);!#7=/0Ce8L4MPQ4QQ 07}U/Ce,37i0 , Aj779%-;tZ?B5z2?O OD = H rz##YwODVW^aeeftw{{|c*oW[\];GN
T
 rI   c                 6    [        U 5      nSUS-  US-	  4-  nU$ )zDisplay the int64 range stored in value as xxx-yyy

:param value: The int64 range
:return: A string of the representation of the range
z%d-%dl        )rs   )valuelvaluer   s      rF   int64range2strrw  :  s*     ZF
VZ'"5
5CJrI   )NN)@__doc__r|   r   r   r  samba.commonr   r   r   r   r   r   r   samba.provisionr	   r
   r   r   r   r   samba.provision.commonr   samba.dcerpcr   samba.dcerpc.miscr   	samba.ndrr   samba.samdbr   r   ra  ERRORr   r   CHANGESDGUESS	PROVISION	CHANGEALLsetr   objectr9   rp   rx   r   r   r   r   r   r   r   r  r	  r  r   r$  r5  r9  r<  r@  rU  rr  rw  rc   rI   rF   <module>r     s   , E 	 	     9 9 
2 2 - ! *      					 M N <6 <~8:4!,0@>
Qd.N",LB.b"(8V% P, F9x8vrI   