b1c585447d275973ee3376c3d9dc970b26939d0d
[gd/samba-autobuild/.git] / librpc / rpc / rpc_common.h
1 /*
2    Unix SMB/CIFS implementation.
3
4    Copyright (C) Stefan Metzmacher 2010-2011
5    Copyright (C) Andrew Tridgell 2010-2011
6    Copyright (C) Simo Sorce 2010
7
8    This program is free software; you can redistribute it and/or modify
9    it under the terms of the GNU General Public License as published by
10    the Free Software Foundation; either version 3 of the License, or
11    (at your option) any later version.
12
13    This program is distributed in the hope that it will be useful,
14    but WITHOUT ANY WARRANTY; without even the implied warranty of
15    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16    GNU General Public License for more details.
17
18    You should have received a copy of the GNU General Public License
19    along with this program.  If not, see <http://www.gnu.org/licenses/>.
20 */
21
22 #ifndef __DEFAULT_LIBRPC_RPCCOMMON_H__
23 #define __DEFAULT_LIBRPC_RPCCOMMON_H__
24
25 #include "lib/util/data_blob.h"
26
27 #include "gen_ndr/dcerpc.h"
28 #include "lib/util/attr.h"
29
30 struct dcerpc_binding_handle;
31 struct GUID;
32 struct ndr_interface_table;
33 struct ndr_interface_call;
34 struct ndr_push;
35 struct ndr_pull;
36 struct ncacn_packet;
37 struct epm_floor;
38 struct epm_tower;
39 struct tevent_context;
40 struct tstream_context;
41 struct gensec_security;
42
43 enum dcerpc_transport_t {
44         NCA_UNKNOWN, NCACN_NP, NCACN_IP_TCP, NCACN_IP_UDP, NCACN_VNS_IPC, 
45         NCACN_VNS_SPP, NCACN_AT_DSP, NCADG_AT_DDP, NCALRPC, NCACN_UNIX_STREAM, 
46         NCADG_UNIX_DGRAM, NCACN_HTTP, NCADG_IPX, NCACN_SPX, NCACN_INTERNAL };
47
48 /** this describes a binding to a particular transport/pipe */
49 struct dcerpc_binding;
50
51 /* dcerpc pipe flags */
52 #define DCERPC_DEBUG_PRINT_IN          (1<<0)
53 #define DCERPC_DEBUG_PRINT_OUT         (1<<1)
54 #define DCERPC_DEBUG_PRINT_BOTH (DCERPC_DEBUG_PRINT_IN | DCERPC_DEBUG_PRINT_OUT)
55
56 #define DCERPC_DEBUG_VALIDATE_IN       (1<<2)
57 #define DCERPC_DEBUG_VALIDATE_OUT      (1<<3)
58 #define DCERPC_DEBUG_VALIDATE_BOTH (DCERPC_DEBUG_VALIDATE_IN | DCERPC_DEBUG_VALIDATE_OUT)
59
60 #define DCERPC_CONNECT                 (1<<4)
61 #define DCERPC_SIGN                    (1<<5)
62 #define DCERPC_SEAL                    (1<<6)
63
64 #define DCERPC_PUSH_BIGENDIAN          (1<<7)
65 #define DCERPC_PULL_BIGENDIAN          (1<<8)
66
67 #define DCERPC_SCHANNEL                (1<<9)
68
69 #define DCERPC_ANON_FALLBACK           (1<<10)
70
71 /* use a 128 bit session key */
72 #define DCERPC_SCHANNEL_128            (1<<12)
73
74 /* check incoming pad bytes */
75 #define DCERPC_DEBUG_PAD_CHECK         (1<<13)
76
77 /* set LIBNDR_FLAG_REF_ALLOC flag when decoding NDR */
78 #define DCERPC_NDR_REF_ALLOC           (1<<14)
79
80 #define DCERPC_AUTH_OPTIONS    (DCERPC_SEAL|DCERPC_SIGN|DCERPC_SCHANNEL|DCERPC_AUTH_SPNEGO|DCERPC_AUTH_KRB5|DCERPC_AUTH_NTLM)
81
82 /* select spnego auth */
83 #define DCERPC_AUTH_SPNEGO             (1<<15)
84
85 /* select krb5 auth */
86 #define DCERPC_AUTH_KRB5               (1<<16)
87
88 #define DCERPC_SMB2                    (1<<17)
89
90 /* select NTLM auth */
91 #define DCERPC_AUTH_NTLM               (1<<18)
92
93 /* this triggers the DCERPC_PFC_FLAG_CONC_MPX flag in the bind request */
94 #define DCERPC_CONCURRENT_MULTIPLEX     (1<<19)
95
96 /* this indicates DCERPC_PFC_FLAG_SUPPORT_HEADER_SIGN flag was negotiated */
97 #define DCERPC_HEADER_SIGNING          (1<<20)
98
99 /* use NDR64 transport */
100 #define DCERPC_NDR64                   (1<<21)
101
102 /* handle upgrades or downgrades automatically */
103 #define DCERPC_SCHANNEL_AUTO           (1<<23)
104
105 /* use aes schannel with hmac-sh256 session key */
106 #define DCERPC_SCHANNEL_AES            (1<<24)
107
108 /* this triggers the DCERPC_PFC_FLAG_SUPPORT_HEADER_SIGN flag in the bind request */
109 #define DCERPC_PROPOSE_HEADER_SIGNING          (1<<25)
110
111 #define DCERPC_PACKET                   (1<<26)
112
113 #define DCERPC_SMB1                    (1<<27)
114
115 /* The following definitions come from ../librpc/rpc/dcerpc_error.c  */
116
117 const char *dcerpc_errstr(TALLOC_CTX *mem_ctx, uint32_t fault_code);
118 NTSTATUS dcerpc_fault_to_nt_status(uint32_t fault_code);
119 uint32_t dcerpc_fault_from_nt_status(NTSTATUS nt_status);
120
121 /* The following definitions come from ../librpc/rpc/binding.c  */
122
123 const char *epm_floor_string(TALLOC_CTX *mem_ctx, struct epm_floor *epm_floor);
124 char *dcerpc_floor_get_rhs_data(TALLOC_CTX *mem_ctx, struct epm_floor *epm_floor);
125 enum dcerpc_transport_t dcerpc_transport_by_endpoint_protocol(int prot);
126 struct dcerpc_binding *dcerpc_binding_dup(TALLOC_CTX *mem_ctx,
127                                           const struct dcerpc_binding *b);
128 NTSTATUS dcerpc_binding_build_tower(TALLOC_CTX *mem_ctx,
129                                     const struct dcerpc_binding *binding,
130                                     struct epm_tower *tower);
131 NTSTATUS dcerpc_binding_from_tower(TALLOC_CTX *mem_ctx,
132                                    struct epm_tower *tower,
133                                    struct dcerpc_binding **b_out);
134 NTSTATUS dcerpc_parse_binding(TALLOC_CTX *mem_ctx, const char *s, struct dcerpc_binding **b_out);
135 char *dcerpc_binding_string(TALLOC_CTX *mem_ctx, const struct dcerpc_binding *b);
136 struct GUID dcerpc_binding_get_object(const struct dcerpc_binding *b);
137 NTSTATUS dcerpc_binding_set_object(struct dcerpc_binding *b,
138                                    struct GUID object);
139 enum dcerpc_transport_t dcerpc_binding_get_transport(const struct dcerpc_binding *b);
140 NTSTATUS dcerpc_binding_set_transport(struct dcerpc_binding *b,
141                                       enum dcerpc_transport_t transport);
142 void dcerpc_binding_get_auth_info(const struct dcerpc_binding *b,
143                                   enum dcerpc_AuthType *_auth_type,
144                                   enum dcerpc_AuthLevel *_auth_level);
145 uint32_t dcerpc_binding_get_assoc_group_id(const struct dcerpc_binding *b);
146 NTSTATUS dcerpc_binding_set_assoc_group_id(struct dcerpc_binding *b,
147                                            uint32_t assoc_group_id);
148 struct ndr_syntax_id dcerpc_binding_get_abstract_syntax(const struct dcerpc_binding *b);
149 NTSTATUS dcerpc_binding_set_abstract_syntax(struct dcerpc_binding *b,
150                                             const struct ndr_syntax_id *syntax);
151 const char *dcerpc_binding_get_string_option(const struct dcerpc_binding *b,
152                                              const char *name);
153 char *dcerpc_binding_copy_string_option(TALLOC_CTX *mem_ctx,
154                                         const struct dcerpc_binding *b,
155                                         const char *name);
156 NTSTATUS dcerpc_binding_set_string_option(struct dcerpc_binding *b,
157                                           const char *name,
158                                           const char *value);
159 uint32_t dcerpc_binding_get_flags(const struct dcerpc_binding *b);
160 NTSTATUS dcerpc_binding_set_flags(struct dcerpc_binding *b,
161                                   uint32_t additional,
162                                   uint32_t clear);
163 NTSTATUS dcerpc_floor_get_uuid_full(const struct epm_floor *epm_floor, struct ndr_syntax_id *syntax);
164 const char *derpc_transport_string_by_transport(enum dcerpc_transport_t t);
165 enum dcerpc_transport_t dcerpc_transport_by_name(const char *name);
166 enum dcerpc_transport_t dcerpc_transport_by_tower(const struct epm_tower *tower);
167
168 /* The following definitions come from ../librpc/rpc/binding_handle.c  */
169
170 struct dcerpc_binding_handle_ops {
171         const char *name;
172
173         bool (*is_connected)(struct dcerpc_binding_handle *h);
174         uint32_t (*set_timeout)(struct dcerpc_binding_handle *h,
175                                 uint32_t timeout);
176
177         void (*auth_info)(struct dcerpc_binding_handle *h,
178                           enum dcerpc_AuthType *auth_type,
179                           enum dcerpc_AuthLevel *auth_level);
180
181         struct tevent_req *(*raw_call_send)(TALLOC_CTX *mem_ctx,
182                                             struct tevent_context *ev,
183                                             struct dcerpc_binding_handle *h,
184                                             const struct GUID *object,
185                                             uint32_t opnum,
186                                             uint32_t in_flags,
187                                             const uint8_t *in_data,
188                                             size_t in_length);
189         NTSTATUS (*raw_call_recv)(struct tevent_req *req,
190                                   TALLOC_CTX *mem_ctx,
191                                   uint8_t **out_data,
192                                   size_t *out_length,
193                                   uint32_t *out_flags);
194
195         struct tevent_req *(*disconnect_send)(TALLOC_CTX *mem_ctx,
196                                               struct tevent_context *ev,
197                                               struct dcerpc_binding_handle *h);
198         NTSTATUS (*disconnect_recv)(struct tevent_req *req);
199
200         /* TODO: remove the following functions */
201         bool (*push_bigendian)(struct dcerpc_binding_handle *h);
202         bool (*ref_alloc)(struct dcerpc_binding_handle *h);
203         bool (*use_ndr64)(struct dcerpc_binding_handle *h);
204         void (*do_ndr_print)(struct dcerpc_binding_handle *h,
205                              int ndr_flags,
206                              const void *struct_ptr,
207                              const struct ndr_interface_call *call);
208         void (*ndr_push_failed)(struct dcerpc_binding_handle *h,
209                                 NTSTATUS error,
210                                 const void *struct_ptr,
211                                 const struct ndr_interface_call *call);
212         void (*ndr_pull_failed)(struct dcerpc_binding_handle *h,
213                                 NTSTATUS error,
214                                 const DATA_BLOB *blob,
215                                 const struct ndr_interface_call *call);
216         NTSTATUS (*ndr_validate_in)(struct dcerpc_binding_handle *h,
217                                     TALLOC_CTX *mem_ctx,
218                                     const DATA_BLOB *blob,
219                                     const struct ndr_interface_call *call);
220         NTSTATUS (*ndr_validate_out)(struct dcerpc_binding_handle *h,
221                                      struct ndr_pull *pull_in,
222                                      const void *struct_ptr,
223                                      const struct ndr_interface_call *call);
224 };
225
226 struct dcerpc_binding_handle *_dcerpc_binding_handle_create(TALLOC_CTX *mem_ctx,
227                                         const struct dcerpc_binding_handle_ops *ops,
228                                         const struct GUID *object,
229                                         const struct ndr_interface_table *table,
230                                         void *pstate,
231                                         size_t psize,
232                                         const char *type,
233                                         const char *location);
234 #define dcerpc_binding_handle_create(mem_ctx, ops, object, table, \
235                                 state, type, location) \
236         _dcerpc_binding_handle_create(mem_ctx, ops, object, table, \
237                                 state, sizeof(type), #type, location)
238
239 void *_dcerpc_binding_handle_data(struct dcerpc_binding_handle *h);
240 #define dcerpc_binding_handle_data(_h, _type) \
241         talloc_get_type_abort(_dcerpc_binding_handle_data(_h), _type)
242
243 _DEPRECATED_ void dcerpc_binding_handle_set_sync_ev(struct dcerpc_binding_handle *h,
244                                                     struct tevent_context *ev);
245
246 bool dcerpc_binding_handle_is_connected(struct dcerpc_binding_handle *h);
247
248 uint32_t dcerpc_binding_handle_set_timeout(struct dcerpc_binding_handle *h,
249                                            uint32_t timeout);
250
251 void dcerpc_binding_handle_auth_info(struct dcerpc_binding_handle *h,
252                                      enum dcerpc_AuthType *auth_type,
253                                      enum dcerpc_AuthLevel *auth_level);
254
255 struct tevent_req *dcerpc_binding_handle_raw_call_send(TALLOC_CTX *mem_ctx,
256                                                 struct tevent_context *ev,
257                                                 struct dcerpc_binding_handle *h,
258                                                 const struct GUID *object,
259                                                 uint32_t opnum,
260                                                 uint32_t in_flags,
261                                                 const uint8_t *in_data,
262                                                 size_t in_length);
263 NTSTATUS dcerpc_binding_handle_raw_call_recv(struct tevent_req *req,
264                                              TALLOC_CTX *mem_ctx,
265                                              uint8_t **out_data,
266                                              size_t *out_length,
267                                              uint32_t *out_flags);
268 NTSTATUS dcerpc_binding_handle_raw_call(struct dcerpc_binding_handle *h,
269                                         const struct GUID *object,
270                                         uint32_t opnum,
271                                         uint32_t in_flags,
272                                         const uint8_t *in_data,
273                                         size_t in_length,
274                                         TALLOC_CTX *mem_ctx,
275                                         uint8_t **out_data,
276                                         size_t *out_length,
277                                         uint32_t *out_flags);
278
279 struct tevent_req *dcerpc_binding_handle_disconnect_send(TALLOC_CTX *mem_ctx,
280                                                 struct tevent_context *ev,
281                                                 struct dcerpc_binding_handle *h);
282 NTSTATUS dcerpc_binding_handle_disconnect_recv(struct tevent_req *req);
283
284 struct tevent_req *dcerpc_binding_handle_call_send(TALLOC_CTX *mem_ctx,
285                                         struct tevent_context *ev,
286                                         struct dcerpc_binding_handle *h,
287                                         const struct GUID *object,
288                                         const struct ndr_interface_table *table,
289                                         uint32_t opnum,
290                                         TALLOC_CTX *r_mem,
291                                         void *r_ptr);
292 NTSTATUS dcerpc_binding_handle_call_recv(struct tevent_req *req);
293 NTSTATUS dcerpc_binding_handle_call(struct dcerpc_binding_handle *h,
294                                     const struct GUID *object,
295                                     const struct ndr_interface_table *table,
296                                     uint32_t opnum,
297                                     TALLOC_CTX *r_mem,
298                                     void *r_ptr);
299
300 /**
301  * Extract header information from a ncacn_packet
302  * as a dcerpc_sec_vt_header2 as used by the security verification trailer.
303  *
304  * @param[in] pkt a packet
305  *
306  * @return a dcerpc_sec_vt_header2
307  */
308 struct dcerpc_sec_vt_header2 dcerpc_sec_vt_header2_from_ncacn_packet(const struct ncacn_packet *pkt);
309
310
311 /**
312  * Test if two dcerpc_sec_vt_header2 structures are equal
313  * without consideration of reserved fields.
314  *
315  * @param v1 a pointer to a dcerpc_sec_vt_header2 structure
316  * @param v2 a pointer to a dcerpc_sec_vt_header2 structure
317  *
318  * @retval true if *v1 equals *v2
319  */
320 bool dcerpc_sec_vt_header2_equal(const struct dcerpc_sec_vt_header2 *v1,
321                                  const struct dcerpc_sec_vt_header2 *v2);
322
323 /**
324  * Check for consistency of the security verification trailer with the PDU header.
325  * See <a href="http://msdn.microsoft.com/en-us/library/cc243559.aspx">MS-RPCE 2.2.2.13</a>.
326  * A check with an empty trailer succeeds.
327  *
328  * @param[in] vt a pointer to the security verification trailer.
329  * @param[in] bitmask1 which flags were negotiated on the connection.
330  * @param[in] pcontext the syntaxes negotiated for the presentation context.
331  * @param[in] header2 some fields from the PDU header.
332  *
333  * @retval true on success.
334  */
335 bool dcerpc_sec_verification_trailer_check(
336                 const struct dcerpc_sec_verification_trailer *vt,
337                 const uint32_t *bitmask1,
338                 const struct dcerpc_sec_vt_pcontext *pcontext,
339                 const struct dcerpc_sec_vt_header2 *header2);
340
341 /**
342  * @brief check and optionally extract the Bind Time Features from
343  * the given ndr_syntax_id.
344  *
345  * <a href="http://msdn.microsoft.com/en-us/library/cc243715.aspx">MS-RPCE 3.3.1.5.3 Bind Time Feature Negotiation</a>.
346  *
347  * @param[in]  s the syntax that should be checked.
348  *
349  * @param[out] features This is optional, it will be filled with the extracted
350  *                      features the on success, otherwise it's filled with 0.
351  *
352  * @return true if the syntax matches the 6CB71C2C-9812-4540 prefix with version 1, false otherwise.
353  *
354  * @see dcerpc_construct_bind_time_features
355  */
356 bool dcerpc_extract_bind_time_features(struct ndr_syntax_id syntax, uint64_t *features);
357
358 /**
359  * @brief Construct a ndr_syntax_id used for Bind Time Features Negotiation.
360  *
361  * <a href="http://msdn.microsoft.com/en-us/library/cc243715.aspx">MS-RPCE 3.3.1.5.3 Bind Time Feature Negotiation</a>.
362  *
363  * @param[in] features The supported features.
364  *
365  * @return The ndr_syntax_id with the given features.
366  *
367  * @see dcerpc_extract_bind_time_features
368  */
369 struct ndr_syntax_id dcerpc_construct_bind_time_features(uint64_t features);
370
371 #define DCERPC_AUTH_PAD_LENGTH(stub_length) (\
372         (((stub_length) % DCERPC_AUTH_PAD_ALIGNMENT) > 0)?\
373         (DCERPC_AUTH_PAD_ALIGNMENT - (stub_length) % DCERPC_AUTH_PAD_ALIGNMENT):\
374         0)
375
376 NTSTATUS dcerpc_generic_session_key(DATA_BLOB *session_key);
377
378 NTSTATUS dcerpc_ncacn_push_auth(DATA_BLOB *blob,
379                                 TALLOC_CTX *mem_ctx,
380                                 struct ncacn_packet *pkt,
381                                 struct dcerpc_auth *auth_info);
382
383 void dcerpc_log_packet(const char *packet_log_dir,
384                        const char *interface_name,
385                        uint32_t opnum, uint32_t flags,
386                        const DATA_BLOB *pkt,
387                        const char *why);
388
389 #ifdef DEVELOPER
390 void dcerpc_save_ndr_fuzz_seed(TALLOC_CTX *mem_ctx,
391                                DATA_BLOB raw_blob,
392                                const char *dump_dir,
393                                const char *iface_name,
394                                int flags,
395                                int opnum,
396                                bool ndr64);
397 #else
398 static inline void dcerpc_save_ndr_fuzz_seed(TALLOC_CTX *mem_ctx,
399                                              DATA_BLOB raw_blob,
400                                              const char *dump_dir,
401                                              const char *iface_name,
402                                              int flags,
403                                              int opnum,
404                                              bool ndr64)
405 {
406         return;
407 }
408 #endif
409
410 #endif /* __DEFAULT_LIBRPC_RPCCOMMON_H__ */