a7a081c1b1ccd93ae746a6a594c08497dfd96cd0
[samba.git] / librpc / rpc / rpc_common.h
1 /*
2    Unix SMB/CIFS implementation.
3
4    Copyright (C) Stefan Metzmacher 2010-2011
5    Copyright (C) Andrew Tridgell 2010-2011
6    Copyright (C) Simo Sorce 2010
7
8    This program is free software; you can redistribute it and/or modify
9    it under the terms of the GNU General Public License as published by
10    the Free Software Foundation; either version 3 of the License, or
11    (at your option) any later version.
12
13    This program is distributed in the hope that it will be useful,
14    but WITHOUT ANY WARRANTY; without even the implied warranty of
15    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16    GNU General Public License for more details.
17
18    You should have received a copy of the GNU General Public License
19    along with this program.  If not, see <http://www.gnu.org/licenses/>.
20 */
21
22 #ifndef __DEFAULT_LIBRPC_RPCCOMMON_H__
23 #define __DEFAULT_LIBRPC_RPCCOMMON_H__
24
25 struct dcerpc_binding_handle;
26 struct GUID;
27 struct ndr_interface_table;
28 struct ndr_interface_call;
29 struct ndr_push;
30 struct ndr_pull;
31 struct ncacn_packet;
32 struct epm_floor;
33 struct epm_tower;
34 struct tevent_context;
35 struct tstream_context;
36
37 enum dcerpc_transport_t {
38         NCA_UNKNOWN, NCACN_NP, NCACN_IP_TCP, NCACN_IP_UDP, NCACN_VNS_IPC, 
39         NCACN_VNS_SPP, NCACN_AT_DSP, NCADG_AT_DDP, NCALRPC, NCACN_UNIX_STREAM, 
40         NCADG_UNIX_DGRAM, NCACN_HTTP, NCADG_IPX, NCACN_SPX, NCACN_INTERNAL };
41
42 /** this describes a binding to a particular transport/pipe */
43 struct dcerpc_binding {
44         enum dcerpc_transport_t transport;
45         struct ndr_syntax_id object;
46         const char *object_string;
47         const char *host;
48         const char *target_hostname;
49         const char *target_principal;
50         const char *endpoint;
51         const char **options;
52         uint32_t flags;
53         uint32_t assoc_group_id;
54 };
55
56 /* dcerpc pipe flags */
57 #define DCERPC_DEBUG_PRINT_IN          (1<<0)
58 #define DCERPC_DEBUG_PRINT_OUT         (1<<1)
59 #define DCERPC_DEBUG_PRINT_BOTH (DCERPC_DEBUG_PRINT_IN | DCERPC_DEBUG_PRINT_OUT)
60
61 #define DCERPC_DEBUG_VALIDATE_IN       (1<<2)
62 #define DCERPC_DEBUG_VALIDATE_OUT      (1<<3)
63 #define DCERPC_DEBUG_VALIDATE_BOTH (DCERPC_DEBUG_VALIDATE_IN | DCERPC_DEBUG_VALIDATE_OUT)
64
65 #define DCERPC_CONNECT                 (1<<4)
66 #define DCERPC_SIGN                    (1<<5)
67 #define DCERPC_SEAL                    (1<<6)
68
69 #define DCERPC_PUSH_BIGENDIAN          (1<<7)
70 #define DCERPC_PULL_BIGENDIAN          (1<<8)
71
72 #define DCERPC_SCHANNEL                (1<<9)
73
74 #define DCERPC_ANON_FALLBACK           (1<<10)
75
76 /* use a 128 bit session key */
77 #define DCERPC_SCHANNEL_128            (1<<12)
78
79 /* check incoming pad bytes */
80 #define DCERPC_DEBUG_PAD_CHECK         (1<<13)
81
82 /* set LIBNDR_FLAG_REF_ALLOC flag when decoding NDR */
83 #define DCERPC_NDR_REF_ALLOC           (1<<14)
84
85 #define DCERPC_AUTH_OPTIONS    (DCERPC_SEAL|DCERPC_SIGN|DCERPC_SCHANNEL|DCERPC_AUTH_SPNEGO|DCERPC_AUTH_KRB5|DCERPC_AUTH_NTLM)
86
87 /* select spnego auth */
88 #define DCERPC_AUTH_SPNEGO             (1<<15)
89
90 /* select krb5 auth */
91 #define DCERPC_AUTH_KRB5               (1<<16)
92
93 #define DCERPC_SMB2                    (1<<17)
94
95 /* select NTLM auth */
96 #define DCERPC_AUTH_NTLM               (1<<18)
97
98 /* this triggers the DCERPC_PFC_FLAG_CONC_MPX flag in the bind request */
99 #define DCERPC_CONCURRENT_MULTIPLEX     (1<<19)
100
101 /* this indicates DCERPC_PFC_FLAG_SUPPORT_HEADER_SIGN flag was negotiated */
102 #define DCERPC_HEADER_SIGNING          (1<<20)
103
104 /* use NDR64 transport */
105 #define DCERPC_NDR64                   (1<<21)
106
107 /* handle upgrades or downgrades automatically */
108 #define DCERPC_SCHANNEL_AUTO           (1<<23)
109
110 /* use aes schannel with hmac-sh256 session key */
111 #define DCERPC_SCHANNEL_AES            (1<<24)
112
113 /* this triggers the DCERPC_PFC_FLAG_SUPPORT_HEADER_SIGN flag in the bind request */
114 #define DCERPC_PROPOSE_HEADER_SIGNING          (1<<25)
115
116 /* The following definitions come from ../librpc/rpc/dcerpc_error.c  */
117
118 const char *dcerpc_errstr(TALLOC_CTX *mem_ctx, uint32_t fault_code);
119 NTSTATUS dcerpc_fault_to_nt_status(uint32_t fault_code);
120
121 /* The following definitions come from ../librpc/rpc/binding.c  */
122
123 const char *epm_floor_string(TALLOC_CTX *mem_ctx, struct epm_floor *epm_floor);
124 char *dcerpc_floor_get_rhs_data(TALLOC_CTX *mem_ctx, struct epm_floor *epm_floor);
125 enum dcerpc_transport_t dcerpc_transport_by_endpoint_protocol(int prot);
126 struct dcerpc_binding *dcerpc_binding_dup(TALLOC_CTX *mem_ctx,
127                                           const struct dcerpc_binding *b);
128 NTSTATUS dcerpc_binding_build_tower(TALLOC_CTX *mem_ctx,
129                                     const struct dcerpc_binding *binding,
130                                     struct epm_tower *tower);
131 NTSTATUS dcerpc_binding_from_tower(TALLOC_CTX *mem_ctx,
132                                    struct epm_tower *tower,
133                                    struct dcerpc_binding **b_out);
134 NTSTATUS dcerpc_parse_binding(TALLOC_CTX *mem_ctx, const char *s, struct dcerpc_binding **b_out);
135 char *dcerpc_binding_string(TALLOC_CTX *mem_ctx, const struct dcerpc_binding *b);
136 const char *dcerpc_binding_get_string_option(const struct dcerpc_binding *b,
137                                              const char *name);
138 char *dcerpc_binding_copy_string_option(TALLOC_CTX *mem_ctx,
139                                         const struct dcerpc_binding *b,
140                                         const char *name);
141 NTSTATUS dcerpc_binding_set_string_option(struct dcerpc_binding *b,
142                                           const char *name,
143                                           const char *value);
144 NTSTATUS dcerpc_floor_get_lhs_data(const struct epm_floor *epm_floor, struct ndr_syntax_id *syntax);
145 const char *derpc_transport_string_by_transport(enum dcerpc_transport_t t);
146 enum dcerpc_transport_t dcerpc_transport_by_name(const char *name);
147 enum dcerpc_transport_t dcerpc_transport_by_tower(const struct epm_tower *tower);
148
149 /* The following definitions come from ../librpc/rpc/dcerpc_util.c  */
150
151 void dcerpc_set_frag_length(DATA_BLOB *blob, uint16_t v);
152 uint16_t dcerpc_get_frag_length(const DATA_BLOB *blob);
153 void dcerpc_set_auth_length(DATA_BLOB *blob, uint16_t v);
154 uint8_t dcerpc_get_endian_flag(DATA_BLOB *blob);
155 const char *dcerpc_default_transport_endpoint(TALLOC_CTX *mem_ctx,
156                                               enum dcerpc_transport_t transport,
157                                               const struct ndr_interface_table *table);
158
159 /**
160 * @brief        Pull a dcerpc_auth structure, taking account of any auth
161 *               padding in the blob. For request/response packets we pass
162 *               the whole data blob, so auth_data_only must be set to false
163 *               as the blob contains data+pad+auth and no just pad+auth.
164 *
165 * @param pkt            - The ncacn_packet strcuture
166 * @param mem_ctx        - The mem_ctx used to allocate dcerpc_auth elements
167 * @param pkt_trailer    - The packet trailer data, usually the trailing
168 *                         auth_info blob, but in the request/response case
169 *                         this is the stub_and_verifier blob.
170 * @param auth           - A preallocated dcerpc_auth *empty* structure
171 * @param auth_length    - The length of the auth trail, sum of auth header
172 *                         lenght and pkt->auth_length
173 * @param auth_data_only - Whether the pkt_trailer includes only the auth_blob
174 *                         (+ padding) or also other data.
175 *
176 * @return               - A NTSTATUS error code.
177 */
178 NTSTATUS dcerpc_pull_auth_trailer(struct ncacn_packet *pkt,
179                                   TALLOC_CTX *mem_ctx,
180                                   DATA_BLOB *pkt_trailer,
181                                   struct dcerpc_auth *auth,
182                                   uint32_t *auth_length,
183                                   bool auth_data_only);
184 struct tevent_req *dcerpc_read_ncacn_packet_send(TALLOC_CTX *mem_ctx,
185                                                  struct tevent_context *ev,
186                                                  struct tstream_context *stream);
187 NTSTATUS dcerpc_read_ncacn_packet_recv(struct tevent_req *req,
188                                        TALLOC_CTX *mem_ctx,
189                                        struct ncacn_packet **pkt,
190                                        DATA_BLOB *buffer);
191
192 /* The following definitions come from ../librpc/rpc/binding_handle.c  */
193
194 struct dcerpc_binding_handle_ops {
195         const char *name;
196
197         bool (*is_connected)(struct dcerpc_binding_handle *h);
198         uint32_t (*set_timeout)(struct dcerpc_binding_handle *h,
199                                 uint32_t timeout);
200
201         void (*auth_info)(struct dcerpc_binding_handle *h,
202                           enum dcerpc_AuthType *auth_type,
203                           enum dcerpc_AuthLevel *auth_level);
204
205         struct tevent_req *(*raw_call_send)(TALLOC_CTX *mem_ctx,
206                                             struct tevent_context *ev,
207                                             struct dcerpc_binding_handle *h,
208                                             const struct GUID *object,
209                                             uint32_t opnum,
210                                             uint32_t in_flags,
211                                             const uint8_t *in_data,
212                                             size_t in_length);
213         NTSTATUS (*raw_call_recv)(struct tevent_req *req,
214                                   TALLOC_CTX *mem_ctx,
215                                   uint8_t **out_data,
216                                   size_t *out_length,
217                                   uint32_t *out_flags);
218
219         struct tevent_req *(*disconnect_send)(TALLOC_CTX *mem_ctx,
220                                               struct tevent_context *ev,
221                                               struct dcerpc_binding_handle *h);
222         NTSTATUS (*disconnect_recv)(struct tevent_req *req);
223
224         /* TODO: remove the following functions */
225         bool (*push_bigendian)(struct dcerpc_binding_handle *h);
226         bool (*ref_alloc)(struct dcerpc_binding_handle *h);
227         bool (*use_ndr64)(struct dcerpc_binding_handle *h);
228         void (*do_ndr_print)(struct dcerpc_binding_handle *h,
229                              int ndr_flags,
230                              const void *struct_ptr,
231                              const struct ndr_interface_call *call);
232         void (*ndr_push_failed)(struct dcerpc_binding_handle *h,
233                                 NTSTATUS error,
234                                 const void *struct_ptr,
235                                 const struct ndr_interface_call *call);
236         void (*ndr_pull_failed)(struct dcerpc_binding_handle *h,
237                                 NTSTATUS error,
238                                 const DATA_BLOB *blob,
239                                 const struct ndr_interface_call *call);
240         NTSTATUS (*ndr_validate_in)(struct dcerpc_binding_handle *h,
241                                     TALLOC_CTX *mem_ctx,
242                                     const DATA_BLOB *blob,
243                                     const struct ndr_interface_call *call);
244         NTSTATUS (*ndr_validate_out)(struct dcerpc_binding_handle *h,
245                                      struct ndr_pull *pull_in,
246                                      const void *struct_ptr,
247                                      const struct ndr_interface_call *call);
248 };
249
250 struct dcerpc_binding_handle *_dcerpc_binding_handle_create(TALLOC_CTX *mem_ctx,
251                                         const struct dcerpc_binding_handle_ops *ops,
252                                         const struct GUID *object,
253                                         const struct ndr_interface_table *table,
254                                         void *pstate,
255                                         size_t psize,
256                                         const char *type,
257                                         const char *location);
258 #define dcerpc_binding_handle_create(mem_ctx, ops, object, table, \
259                                 state, type, location) \
260         _dcerpc_binding_handle_create(mem_ctx, ops, object, table, \
261                                 state, sizeof(type), #type, location)
262
263 void *_dcerpc_binding_handle_data(struct dcerpc_binding_handle *h);
264 #define dcerpc_binding_handle_data(_h, _type) \
265         talloc_get_type_abort(_dcerpc_binding_handle_data(_h), _type)
266
267 _DEPRECATED_ void dcerpc_binding_handle_set_sync_ev(struct dcerpc_binding_handle *h,
268                                                     struct tevent_context *ev);
269
270 bool dcerpc_binding_handle_is_connected(struct dcerpc_binding_handle *h);
271
272 uint32_t dcerpc_binding_handle_set_timeout(struct dcerpc_binding_handle *h,
273                                            uint32_t timeout);
274
275 void dcerpc_binding_handle_auth_info(struct dcerpc_binding_handle *h,
276                                      enum dcerpc_AuthType *auth_type,
277                                      enum dcerpc_AuthLevel *auth_level);
278
279 struct tevent_req *dcerpc_binding_handle_raw_call_send(TALLOC_CTX *mem_ctx,
280                                                 struct tevent_context *ev,
281                                                 struct dcerpc_binding_handle *h,
282                                                 const struct GUID *object,
283                                                 uint32_t opnum,
284                                                 uint32_t in_flags,
285                                                 const uint8_t *in_data,
286                                                 size_t in_length);
287 NTSTATUS dcerpc_binding_handle_raw_call_recv(struct tevent_req *req,
288                                              TALLOC_CTX *mem_ctx,
289                                              uint8_t **out_data,
290                                              size_t *out_length,
291                                              uint32_t *out_flags);
292 NTSTATUS dcerpc_binding_handle_raw_call(struct dcerpc_binding_handle *h,
293                                         const struct GUID *object,
294                                         uint32_t opnum,
295                                         uint32_t in_flags,
296                                         const uint8_t *in_data,
297                                         size_t in_length,
298                                         TALLOC_CTX *mem_ctx,
299                                         uint8_t **out_data,
300                                         size_t *out_length,
301                                         uint32_t *out_flags);
302
303 struct tevent_req *dcerpc_binding_handle_disconnect_send(TALLOC_CTX *mem_ctx,
304                                                 struct tevent_context *ev,
305                                                 struct dcerpc_binding_handle *h);
306 NTSTATUS dcerpc_binding_handle_disconnect_recv(struct tevent_req *req);
307
308 struct tevent_req *dcerpc_binding_handle_call_send(TALLOC_CTX *mem_ctx,
309                                         struct tevent_context *ev,
310                                         struct dcerpc_binding_handle *h,
311                                         const struct GUID *object,
312                                         const struct ndr_interface_table *table,
313                                         uint32_t opnum,
314                                         TALLOC_CTX *r_mem,
315                                         void *r_ptr);
316 NTSTATUS dcerpc_binding_handle_call_recv(struct tevent_req *req);
317 NTSTATUS dcerpc_binding_handle_call(struct dcerpc_binding_handle *h,
318                                     const struct GUID *object,
319                                     const struct ndr_interface_table *table,
320                                     uint32_t opnum,
321                                     TALLOC_CTX *r_mem,
322                                     void *r_ptr);
323
324 /**
325  * Extract header information from a ncacn_packet
326  * as a dcerpc_sec_vt_header2 as used by the security verification trailer.
327  *
328  * @param[in] pkt a packet
329  *
330  * @return a dcerpc_sec_vt_header2
331  */
332 struct dcerpc_sec_vt_header2 dcerpc_sec_vt_header2_from_ncacn_packet(const struct ncacn_packet *pkt);
333
334
335 /**
336  * Test if two dcerpc_sec_vt_header2 structures are equal
337  * without consideration of reserved fields.
338  *
339  * @param v1 a pointer to a dcerpc_sec_vt_header2 structure
340  * @param v2 a pointer to a dcerpc_sec_vt_header2 structure
341  *
342  * @retval true if *v1 equals *v2
343  */
344 bool dcerpc_sec_vt_header2_equal(const struct dcerpc_sec_vt_header2 *v1,
345                                  const struct dcerpc_sec_vt_header2 *v2);
346
347 /**
348  * Check for consistency of the security verification trailer with the PDU header.
349  * See <a href="http://msdn.microsoft.com/en-us/library/cc243559.aspx">MS-RPCE 2.2.2.13</a>.
350  * A check with an empty trailer succeeds.
351  *
352  * @param[in] vt a pointer to the security verification trailer.
353  * @param[in] bitmask1 which flags were negotiated on the connection.
354  * @param[in] pcontext the syntaxes negotiatied for the presentation context.
355  * @param[in] header2 some fields from the PDU header.
356  *
357  * @retval true on success.
358  */
359 bool dcerpc_sec_verification_trailer_check(
360                 const struct dcerpc_sec_verification_trailer *vt,
361                 const uint32_t *bitmask1,
362                 const struct dcerpc_sec_vt_pcontext *pcontext,
363                 const struct dcerpc_sec_vt_header2 *header2);
364
365 #endif /* __DEFAULT_LIBRPC_RPCCOMMON_H__ */