2005-11-11 05:53:54 +00:00
/*
Unix SMB / CIFS implementation .
SMB2 client session handling
Copyright ( C ) Andrew Tridgell 2005
This program is free software ; you can redistribute it and / or modify
it under the terms of the GNU General Public License as published by
2007-07-10 02:07:03 +00:00
the Free Software Foundation ; either version 3 of the License , or
2005-11-11 05:53:54 +00:00
( at your option ) any later version .
This program is distributed in the hope that it will be useful ,
but WITHOUT ANY WARRANTY ; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE . See the
GNU General Public License for more details .
You should have received a copy of the GNU General Public License
2007-07-10 02:07:03 +00:00
along with this program . If not , see < http : //www.gnu.org/licenses/>.
2005-11-11 05:53:54 +00:00
*/
# include "includes.h"
# include "libcli/raw/libcliraw.h"
# include "libcli/smb2/smb2.h"
2005-11-11 06:26:42 +00:00
# include "libcli/smb2/smb2_calls.h"
2005-11-12 01:08:43 +00:00
# include "libcli/composite/composite.h"
# include "auth/gensec/gensec.h"
2007-12-03 17:41:50 +01:00
# include "param/param.h"
2005-11-11 05:53:54 +00:00
2007-12-03 17:41:50 +01:00
/**
2005-11-11 05:53:54 +00:00
initialise a smb2_session structure
*/
struct smb2_session * smb2_session_init ( struct smb2_transport * transport ,
2007-12-07 16:04:25 +01:00
struct loadparm_context * lp_ctx ,
2007-10-06 22:28:14 +00:00
TALLOC_CTX * parent_ctx , bool primary )
2005-11-11 05:53:54 +00:00
{
struct smb2_session * session ;
2005-11-11 06:26:42 +00:00
NTSTATUS status ;
2005-11-11 05:53:54 +00:00
session = talloc_zero ( parent_ctx , struct smb2_session ) ;
if ( ! session ) {
return NULL ;
}
if ( primary ) {
session - > transport = talloc_steal ( session , transport ) ;
} else {
session - > transport = talloc_reference ( session , transport ) ;
}
2005-11-11 06:26:42 +00:00
/* prepare a gensec context for later use */
status = gensec_client_start ( session , & session - > gensec ,
2007-12-03 17:41:50 +01:00
session - > transport - > socket - > event . ctx ,
2007-12-07 16:04:25 +01:00
lp_ctx ) ;
2005-11-11 06:26:42 +00:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
talloc_free ( session ) ;
return NULL ;
}
2005-11-28 22:53:42 +00:00
gensec_want_feature ( session - > gensec , GENSEC_FEATURE_SESSION_KEY ) ;
2005-11-11 05:53:54 +00:00
return session ;
}
2007-12-03 17:41:50 +01:00
/**
2005-11-11 06:26:42 +00:00
send a session setup request
*/
struct smb2_request * smb2_session_setup_send ( struct smb2_session * session ,
struct smb2_session_setup * io )
{
struct smb2_request * req ;
2005-11-11 07:23:45 +00:00
NTSTATUS status ;
2005-11-11 06:26:42 +00:00
req = smb2_request_init ( session - > transport , SMB2_OP_SESSSETUP ,
2007-10-06 22:28:14 +00:00
0x18 , true , io - > in . secblob . length ) ;
2005-11-11 06:26:42 +00:00
if ( req = = NULL ) return NULL ;
2008-02-12 17:00:35 +11:00
SBVAL ( req - > out . hdr , SMB2_HDR_SESSION_ID , session - > uid ) ;
2008-02-12 16:43:38 +11:00
SCVAL ( req - > out . body , 0x02 , io - > in . vc_number ) ;
SCVAL ( req - > out . body , 0x03 , io - > in . security_mode ) ;
SIVAL ( req - > out . body , 0x04 , io - > in . capabilities ) ;
SIVAL ( req - > out . body , 0x08 , io - > in . channel ) ;
SBVAL ( req - > out . body , 0x10 , io - > in . previous_sessionid ) ;
2005-11-16 11:01:15 +00:00
2005-11-12 01:08:43 +00:00
req - > session = session ;
2005-11-16 11:01:15 +00:00
2005-11-17 03:32:38 +00:00
status = smb2_push_o16s16_blob ( & req - > out , 0x0C , io - > in . secblob ) ;
2005-11-11 07:23:45 +00:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
talloc_free ( req ) ;
return NULL ;
}
2005-11-11 06:26:42 +00:00
smb2_transport_send ( req ) ;
return req ;
}
2007-12-03 17:41:50 +01:00
/**
2005-11-11 06:26:42 +00:00
recv a session setup reply
*/
NTSTATUS smb2_session_setup_recv ( struct smb2_request * req , TALLOC_CTX * mem_ctx ,
struct smb2_session_setup * io )
{
2005-11-11 07:23:45 +00:00
NTSTATUS status ;
2005-11-11 06:26:42 +00:00
if ( ! smb2_request_receive ( req ) | |
2005-11-11 07:23:45 +00:00
( smb2_request_is_error ( req ) & &
! NT_STATUS_EQUAL ( req - > status , NT_STATUS_MORE_PROCESSING_REQUIRED ) ) ) {
2005-11-11 06:26:42 +00:00
return smb2_request_destroy ( req ) ;
}
2007-10-06 22:28:14 +00:00
SMB2_CHECK_PACKET_RECV ( req , 0x08 , true ) ;
2005-11-11 23:27:47 +00:00
2008-02-12 16:43:38 +11:00
io - > out . session_flags = SVAL ( req - > in . body , 0x02 ) ;
2008-02-12 17:00:35 +11:00
io - > out . uid = BVAL ( req - > in . hdr , SMB2_HDR_SESSION_ID ) ;
2005-11-11 07:23:45 +00:00
2005-11-16 11:01:15 +00:00
status = smb2_pull_o16s16_blob ( & req - > in , mem_ctx , req - > in . body + 0x04 , & io - > out . secblob ) ;
2005-11-11 07:23:45 +00:00
if ( ! NT_STATUS_IS_OK ( status ) ) {
smb2_request_destroy ( req ) ;
return status ;
}
2005-11-11 06:26:42 +00:00
return smb2_request_destroy ( req ) ;
}
/*
sync session setup request
*/
NTSTATUS smb2_session_setup ( struct smb2_session * session ,
TALLOC_CTX * mem_ctx , struct smb2_session_setup * io )
{
struct smb2_request * req = smb2_session_setup_send ( session , io ) ;
return smb2_session_setup_recv ( req , mem_ctx , io ) ;
}
2005-11-12 01:08:43 +00:00
struct smb2_session_state {
struct smb2_session_setup io ;
struct smb2_request * req ;
NTSTATUS gensec_status ;
} ;
/*
handle continuations of the spnego session setup
*/
static void session_request_handler ( struct smb2_request * req )
{
struct composite_context * c = talloc_get_type ( req - > async . private ,
struct composite_context ) ;
struct smb2_session_state * state = talloc_get_type ( c - > private_data ,
struct smb2_session_state ) ;
struct smb2_session * session = req - > session ;
c - > status = smb2_session_setup_recv ( req , c , & state - > io ) ;
if ( NT_STATUS_EQUAL ( c - > status , NT_STATUS_MORE_PROCESSING_REQUIRED ) | |
( NT_STATUS_IS_OK ( c - > status ) & &
NT_STATUS_EQUAL ( state - > gensec_status , NT_STATUS_MORE_PROCESSING_REQUIRED ) ) ) {
2005-11-25 05:23:55 +00:00
NTSTATUS session_key_err ;
DATA_BLOB session_key ;
2005-11-12 02:16:19 +00:00
c - > status = gensec_update ( session - > gensec , c ,
2005-11-12 01:08:43 +00:00
state - > io . out . secblob ,
& state - > io . in . secblob ) ;
state - > gensec_status = c - > status ;
2005-11-25 05:23:55 +00:00
session_key_err = gensec_session_key ( session - > gensec , & session_key ) ;
if ( NT_STATUS_IS_OK ( session_key_err ) ) {
session - > session_key = session_key ;
}
2005-11-12 01:08:43 +00:00
}
session - > uid = state - > io . out . uid ;
if ( NT_STATUS_EQUAL ( c - > status , NT_STATUS_MORE_PROCESSING_REQUIRED ) ) {
state - > req = smb2_session_setup_send ( session , & state - > io ) ;
if ( state - > req = = NULL ) {
composite_error ( c , NT_STATUS_NO_MEMORY ) ;
2006-03-15 05:53:15 +00:00
return ;
2005-11-12 01:08:43 +00:00
}
state - > req - > async . fn = session_request_handler ;
state - > req - > async . private = c ;
return ;
}
if ( ! NT_STATUS_IS_OK ( c - > status ) ) {
composite_error ( c , c - > status ) ;
return ;
}
composite_done ( c ) ;
}
/*
a composite function that does a full SPNEGO session setup
*/
struct composite_context * smb2_session_setup_spnego_send ( struct smb2_session * session ,
struct cli_credentials * credentials )
{
struct composite_context * c ;
struct smb2_session_state * state ;
2006-07-30 17:29:02 +00:00
c = composite_create ( session , session - > transport - > socket - > event . ctx ) ;
2005-11-12 01:08:43 +00:00
if ( c = = NULL ) return NULL ;
state = talloc ( c , struct smb2_session_state ) ;
2006-07-30 17:29:02 +00:00
if ( composite_nomem ( state , c ) ) return c ;
2005-11-12 01:08:43 +00:00
c - > private_data = state ;
ZERO_STRUCT ( state - > io ) ;
2008-02-12 16:43:38 +11:00
state - > io . in . vc_number = 0 ;
state - > io . in . security_mode = 0 ;
state - > io . in . capabilities = 0 ;
state - > io . in . channel = 0 ;
state - > io . in . previous_sessionid = 0 ;
2005-11-12 01:08:43 +00:00
c - > status = gensec_set_credentials ( session - > gensec , credentials ) ;
2006-07-30 17:29:02 +00:00
if ( ! composite_is_ok ( c ) ) return c ;
2005-11-12 01:08:43 +00:00
c - > status = gensec_set_target_hostname ( session - > gensec ,
session - > transport - > socket - > hostname ) ;
2006-07-30 17:29:02 +00:00
if ( ! composite_is_ok ( c ) ) return c ;
2005-11-12 01:08:43 +00:00
c - > status = gensec_set_target_service ( session - > gensec , " cifs " ) ;
2006-07-30 17:29:02 +00:00
if ( ! composite_is_ok ( c ) ) return c ;
2005-11-12 01:08:43 +00:00
c - > status = gensec_start_mech_by_oid ( session - > gensec , GENSEC_OID_SPNEGO ) ;
2006-07-30 17:29:02 +00:00
if ( ! composite_is_ok ( c ) ) return c ;
2005-11-12 01:08:43 +00:00
c - > status = gensec_update ( session - > gensec , c ,
session - > transport - > negotiate . secblob ,
& state - > io . in . secblob ) ;
if ( ! NT_STATUS_EQUAL ( c - > status , NT_STATUS_MORE_PROCESSING_REQUIRED ) ) {
2006-07-30 17:29:02 +00:00
composite_error ( c , c - > status ) ;
return c ;
2005-11-12 01:08:43 +00:00
}
state - > gensec_status = c - > status ;
state - > req = smb2_session_setup_send ( session , & state - > io ) ;
2006-07-30 17:29:02 +00:00
composite_continue_smb2 ( c , state - > req , session_request_handler , c ) ;
2005-11-12 01:08:43 +00:00
return c ;
}
/*
receive a composite session setup reply
*/
NTSTATUS smb2_session_setup_spnego_recv ( struct composite_context * c )
{
NTSTATUS status ;
status = composite_wait ( c ) ;
talloc_free ( c ) ;
return status ;
}
/*
sync version of smb2_session_setup_spnego
*/
NTSTATUS smb2_session_setup_spnego ( struct smb2_session * session ,
struct cli_credentials * credentials )
{
struct composite_context * c = smb2_session_setup_spnego_send ( session , credentials ) ;
return smb2_session_setup_spnego_recv ( c ) ;
}