2009-06-02 12:38:37 +02:00
/*
Unix SMB / CIFS implementation .
Core SMB2 server
Copyright ( C ) Stefan Metzmacher 2009
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation ; either version 3 of the License , or
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
along with this program . If not , see < http : //www.gnu.org/licenses/>.
*/
# include "includes.h"
# include "smbd/globals.h"
2009-08-12 17:52:55 +02:00
# include "../libcli/smb/smb_common.h"
2009-06-02 12:38:37 +02:00
2009-06-05 12:26:19 +02:00
static struct tevent_req * smbd_smb2_read_send ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
struct smbd_smb2_request * smb2req ,
uint32_t in_smbpid ,
uint64_t in_file_id_volatile ,
uint32_t in_length ,
uint64_t in_offset ,
uint32_t in_minimum ,
uint32_t in_remaining ) ;
static NTSTATUS smbd_smb2_read_recv ( struct tevent_req * req ,
TALLOC_CTX * mem_ctx ,
DATA_BLOB * out_data ,
uint32_t * out_remaining ) ;
static void smbd_smb2_request_read_done ( struct tevent_req * subreq ) ;
2009-06-02 12:38:37 +02:00
NTSTATUS smbd_smb2_request_process_read ( struct smbd_smb2_request * req )
{
const uint8_t * inhdr ;
const uint8_t * inbody ;
int i = req - > current_idx ;
size_t expected_body_size = 0x31 ;
size_t body_size ;
uint32_t in_smbpid ;
uint32_t in_length ;
uint64_t in_offset ;
uint64_t in_file_id_persistent ;
uint64_t in_file_id_volatile ;
uint32_t in_minimum_count ;
uint32_t in_remaining_bytes ;
2009-06-05 12:26:19 +02:00
struct tevent_req * subreq ;
2009-06-02 12:38:37 +02:00
inhdr = ( const uint8_t * ) req - > in . vector [ i + 0 ] . iov_base ;
if ( req - > in . vector [ i + 1 ] . iov_len ! = ( expected_body_size & 0xFFFFFFFE ) ) {
return smbd_smb2_request_error ( req , NT_STATUS_INVALID_PARAMETER ) ;
}
inbody = ( const uint8_t * ) req - > in . vector [ i + 1 ] . iov_base ;
body_size = SVAL ( inbody , 0x00 ) ;
if ( body_size ! = expected_body_size ) {
return smbd_smb2_request_error ( req , NT_STATUS_INVALID_PARAMETER ) ;
}
in_smbpid = IVAL ( inhdr , SMB2_HDR_PID ) ;
in_length = IVAL ( inbody , 0x04 ) ;
in_offset = BVAL ( inbody , 0x08 ) ;
in_file_id_persistent = BVAL ( inbody , 0x10 ) ;
in_file_id_volatile = BVAL ( inbody , 0x18 ) ;
in_minimum_count = IVAL ( inbody , 0x20 ) ;
in_remaining_bytes = IVAL ( inbody , 0x28 ) ;
/* check the max read size */
2010-04-06 15:43:35 -07:00
if ( in_length > lp_smb2_max_read ( ) ) {
2009-06-02 12:38:37 +02:00
DEBUG ( 0 , ( " here:%s: 0x%08X: 0x%08X \n " ,
2010-04-06 15:43:35 -07:00
__location__ , in_length , lp_smb2_max_read ( ) ) ) ;
2009-06-02 12:38:37 +02:00
return smbd_smb2_request_error ( req , NT_STATUS_INVALID_PARAMETER ) ;
}
2009-06-09 18:47:26 +02:00
if ( req - > compat_chain_fsp ) {
/* skip check */
} else if ( in_file_id_persistent ! = 0 ) {
2009-06-02 12:38:37 +02:00
return smbd_smb2_request_error ( req , NT_STATUS_FILE_CLOSED ) ;
}
2009-06-05 12:26:19 +02:00
subreq = smbd_smb2_read_send ( req ,
2009-08-07 15:21:07 +02:00
req - > sconn - > smb2 . event_ctx ,
2009-06-05 12:26:19 +02:00
req ,
in_smbpid ,
in_file_id_volatile ,
in_length ,
in_offset ,
in_minimum_count ,
in_remaining_bytes ) ;
if ( subreq = = NULL ) {
return smbd_smb2_request_error ( req , NT_STATUS_NO_MEMORY ) ;
}
tevent_req_set_callback ( subreq , smbd_smb2_request_read_done , req ) ;
2009-06-09 22:34:14 +02:00
2009-08-15 10:01:38 +02:00
return smbd_smb2_request_pending_queue ( req , subreq ) ;
2009-06-05 12:26:19 +02:00
}
static void smbd_smb2_request_read_done ( struct tevent_req * subreq )
{
struct smbd_smb2_request * req = tevent_req_callback_data ( subreq ,
struct smbd_smb2_request ) ;
int i = req - > current_idx ;
uint8_t * outhdr ;
DATA_BLOB outbody ;
DATA_BLOB outdyn ;
uint8_t out_data_offset ;
2009-07-24 10:21:07 -04:00
DATA_BLOB out_data_buffer = data_blob_null ;
uint32_t out_data_remaining = 0 ;
2009-06-05 12:26:19 +02:00
NTSTATUS status ;
NTSTATUS error ; /* transport error */
status = smbd_smb2_read_recv ( subreq ,
req ,
& out_data_buffer ,
& out_data_remaining ) ;
TALLOC_FREE ( subreq ) ;
2009-06-02 12:38:37 +02:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
2009-06-05 12:26:19 +02:00
error = smbd_smb2_request_error ( req , status ) ;
if ( ! NT_STATUS_IS_OK ( error ) ) {
2009-08-07 15:21:07 +02:00
smbd_server_connection_terminate ( req - > sconn ,
2009-06-05 12:26:19 +02:00
nt_errstr ( error ) ) ;
return ;
}
2009-06-05 14:31:41 +02:00
return ;
2009-06-02 12:38:37 +02:00
}
out_data_offset = SMB2_HDR_BODY + 0x10 ;
outhdr = ( uint8_t * ) req - > out . vector [ i ] . iov_base ;
outbody = data_blob_talloc ( req - > out . vector , NULL , 0x10 ) ;
if ( outbody . data = = NULL ) {
2009-06-05 12:26:19 +02:00
error = smbd_smb2_request_error ( req , NT_STATUS_NO_MEMORY ) ;
if ( ! NT_STATUS_IS_OK ( error ) ) {
2009-08-07 15:21:07 +02:00
smbd_server_connection_terminate ( req - > sconn ,
2009-06-05 12:26:19 +02:00
nt_errstr ( error ) ) ;
return ;
}
2009-06-05 14:31:41 +02:00
return ;
2009-06-02 12:38:37 +02:00
}
SSVAL ( outbody . data , 0x00 , 0x10 + 1 ) ; /* struct size */
SCVAL ( outbody . data , 0x02 ,
out_data_offset ) ; /* data offset */
SCVAL ( outbody . data , 0x03 , 0 ) ; /* reserved */
SIVAL ( outbody . data , 0x04 ,
out_data_buffer . length ) ; /* data length */
SIVAL ( outbody . data , 0x08 ,
out_data_remaining ) ; /* data remaining */
SIVAL ( outbody . data , 0x0C , 0 ) ; /* reserved */
outdyn = out_data_buffer ;
2009-06-05 12:26:19 +02:00
error = smbd_smb2_request_done ( req , outbody , & outdyn ) ;
if ( ! NT_STATUS_IS_OK ( error ) ) {
2009-08-07 15:21:07 +02:00
smbd_server_connection_terminate ( req - > sconn ,
2009-06-05 12:26:19 +02:00
nt_errstr ( error ) ) ;
return ;
}
2009-06-02 12:38:37 +02:00
}
2009-06-05 12:26:19 +02:00
struct smbd_smb2_read_state {
struct smbd_smb2_request * smb2req ;
DATA_BLOB out_data ;
uint32_t out_remaining ;
} ;
2009-06-05 12:58:26 +02:00
static void smbd_smb2_read_pipe_done ( struct tevent_req * subreq ) ;
2009-06-05 12:26:19 +02:00
static struct tevent_req * smbd_smb2_read_send ( TALLOC_CTX * mem_ctx ,
struct tevent_context * ev ,
struct smbd_smb2_request * smb2req ,
uint32_t in_smbpid ,
uint64_t in_file_id_volatile ,
uint32_t in_length ,
uint64_t in_offset ,
uint32_t in_minimum ,
uint32_t in_remaining )
2009-06-02 12:38:37 +02:00
{
2009-06-05 12:26:19 +02:00
struct tevent_req * req ;
struct smbd_smb2_read_state * state ;
2009-06-02 12:38:37 +02:00
struct smb_request * smbreq ;
2009-06-05 12:26:19 +02:00
connection_struct * conn = smb2req - > tcon - > compat_conn ;
2009-06-02 12:38:37 +02:00
files_struct * fsp ;
ssize_t nread = - 1 ;
struct lock_struct lock ;
2009-06-05 12:26:19 +02:00
req = tevent_req_create ( mem_ctx , & state ,
struct smbd_smb2_read_state ) ;
if ( req = = NULL ) {
return NULL ;
}
state - > smb2req = smb2req ;
state - > out_data = data_blob_null ;
state - > out_remaining = 0 ;
2009-06-02 12:38:37 +02:00
DEBUG ( 10 , ( " smbd_smb2_read: file_id[0x%016llX] \n " ,
( unsigned long long ) in_file_id_volatile ) ) ;
2009-06-05 12:26:19 +02:00
smbreq = smbd_smb2_fake_smb_request ( smb2req ) ;
if ( tevent_req_nomem ( smbreq , req ) ) {
return tevent_req_post ( req , ev ) ;
2009-06-02 12:38:37 +02:00
}
fsp = file_fsp ( smbreq , ( uint16_t ) in_file_id_volatile ) ;
if ( fsp = = NULL ) {
2009-06-05 12:26:19 +02:00
tevent_req_nterror ( req , NT_STATUS_FILE_CLOSED ) ;
return tevent_req_post ( req , ev ) ;
2009-06-02 12:38:37 +02:00
}
if ( conn ! = fsp - > conn ) {
2009-06-05 12:26:19 +02:00
tevent_req_nterror ( req , NT_STATUS_FILE_CLOSED ) ;
return tevent_req_post ( req , ev ) ;
2009-06-02 12:38:37 +02:00
}
2009-06-05 12:26:19 +02:00
if ( smb2req - > session - > vuid ! = fsp - > vuid ) {
tevent_req_nterror ( req , NT_STATUS_FILE_CLOSED ) ;
return tevent_req_post ( req , ev ) ;
2009-06-02 12:38:37 +02:00
}
2010-05-05 09:50:48 -07:00
if ( fsp - > is_directory ) {
tevent_req_nterror ( req , NT_STATUS_INVALID_DEVICE_REQUEST ) ;
return tevent_req_post ( req , ev ) ;
}
2009-06-02 12:38:37 +02:00
2009-06-05 12:26:19 +02:00
state - > out_data = data_blob_talloc ( state , NULL , in_length ) ;
if ( in_length > 0 & & tevent_req_nomem ( state - > out_data . data , req ) ) {
return tevent_req_post ( req , ev ) ;
}
if ( IS_IPC ( smbreq - > conn ) ) {
2009-06-05 12:58:26 +02:00
struct tevent_req * subreq ;
if ( ! fsp_is_np ( fsp ) ) {
tevent_req_nterror ( req , NT_STATUS_FILE_CLOSED ) ;
return tevent_req_post ( req , ev ) ;
}
subreq = np_read_send ( state , smbd_event_context ( ) ,
fsp - > fake_file_handle ,
state - > out_data . data ,
state - > out_data . length ) ;
if ( tevent_req_nomem ( subreq , req ) ) {
return tevent_req_post ( req , ev ) ;
}
tevent_req_set_callback ( subreq ,
smbd_smb2_read_pipe_done ,
req ) ;
return req ;
}
if ( ! CHECK_READ ( fsp , smbreq ) ) {
tevent_req_nterror ( req , NT_STATUS_ACCESS_DENIED ) ;
2009-06-05 12:26:19 +02:00
return tevent_req_post ( req , ev ) ;
2009-06-02 12:38:37 +02:00
}
init_strict_lock_struct ( fsp ,
2010-05-07 07:25:13 -07:00
in_file_id_volatile ,
2009-06-02 12:38:37 +02:00
in_offset ,
in_length ,
READ_LOCK ,
& lock ) ;
if ( ! SMB_VFS_STRICT_LOCK ( conn , fsp , & lock ) ) {
2009-06-05 12:26:19 +02:00
tevent_req_nterror ( req , NT_STATUS_FILE_LOCK_CONFLICT ) ;
return tevent_req_post ( req , ev ) ;
2009-06-02 12:38:37 +02:00
}
nread = read_file ( fsp ,
2009-06-05 12:26:19 +02:00
( char * ) state - > out_data . data ,
2009-06-02 12:38:37 +02:00
in_offset ,
in_length ) ;
SMB_VFS_STRICT_UNLOCK ( conn , fsp , & lock ) ;
2010-03-31 17:40:30 -07:00
DEBUG ( 10 , ( " smbd_smb2_read: file %s handle [0x%016llX] offset=%llu "
" len=%llu returned %lld \n " ,
fsp_str_dbg ( fsp ) ,
( unsigned long long ) in_file_id_volatile ,
( unsigned long long ) in_offset ,
( unsigned long long ) in_length ,
( long long ) nread ) ) ;
2009-06-02 12:38:37 +02:00
if ( nread < 0 ) {
DEBUG ( 5 , ( " smbd_smb2_read: read_file[%s] nread[%lld] \n " ,
2009-07-10 14:50:37 -07:00
fsp_str_dbg ( fsp ) , ( long long ) nread ) ) ;
2009-06-05 12:26:19 +02:00
tevent_req_nterror ( req , NT_STATUS_ACCESS_DENIED ) ;
return tevent_req_post ( req , ev ) ;
2009-06-02 12:38:37 +02:00
}
2010-05-05 09:47:49 -07:00
if ( nread = = 0 & & in_length ! = 0 ) {
2009-06-02 12:38:37 +02:00
DEBUG ( 5 , ( " smbd_smb2_read: read_file[%s] end of file \n " ,
2009-07-10 14:50:37 -07:00
fsp_str_dbg ( fsp ) ) ) ;
2009-06-05 12:26:19 +02:00
tevent_req_nterror ( req , NT_STATUS_END_OF_FILE ) ;
return tevent_req_post ( req , ev ) ;
}
2010-05-05 09:47:49 -07:00
if ( nread < in_minimum ) {
DEBUG ( 5 , ( " smbd_smb2_read: read_file[%s] read less %d than "
" minimum requested %u. Returning end of file \n " ,
fsp_str_dbg ( fsp ) ,
( int ) nread ,
( unsigned int ) in_minimum ) ) ;
tevent_req_nterror ( req , NT_STATUS_END_OF_FILE ) ;
return tevent_req_post ( req , ev ) ;
}
2009-06-05 12:26:19 +02:00
state - > out_data . length = nread ;
state - > out_remaining = 0 ;
tevent_req_done ( req ) ;
return tevent_req_post ( req , ev ) ;
}
2009-06-05 12:58:26 +02:00
static void smbd_smb2_read_pipe_done ( struct tevent_req * subreq )
{
struct tevent_req * req = tevent_req_callback_data ( subreq ,
struct tevent_req ) ;
struct smbd_smb2_read_state * state = tevent_req_data ( req ,
struct smbd_smb2_read_state ) ;
NTSTATUS status ;
ssize_t nread = - 1 ;
bool is_data_outstanding ;
status = np_read_recv ( subreq , & nread , & is_data_outstanding ) ;
TALLOC_FREE ( subreq ) ;
if ( ! NT_STATUS_IS_OK ( status ) ) {
tevent_req_nterror ( req , status ) ;
return ;
}
if ( nread = = 0 & & state - > out_data . length ! = 0 ) {
tevent_req_nterror ( req , NT_STATUS_END_OF_FILE ) ;
return ;
}
state - > out_data . length = nread ;
state - > out_remaining = 0 ;
tevent_req_done ( req ) ;
}
2009-06-05 12:26:19 +02:00
static NTSTATUS smbd_smb2_read_recv ( struct tevent_req * req ,
TALLOC_CTX * mem_ctx ,
DATA_BLOB * out_data ,
uint32_t * out_remaining )
{
NTSTATUS status ;
struct smbd_smb2_read_state * state = tevent_req_data ( req ,
struct smbd_smb2_read_state ) ;
if ( tevent_req_is_nterror ( req , & status ) ) {
tevent_req_received ( req ) ;
return status ;
2009-06-02 12:38:37 +02:00
}
2009-06-05 12:26:19 +02:00
* out_data = state - > out_data ;
talloc_steal ( mem_ctx , out_data - > data ) ;
* out_remaining = state - > out_remaining ;
tevent_req_received ( req ) ;
2009-06-02 12:38:37 +02:00
return NT_STATUS_OK ;
}