41608dd73284d2d8eb268c98a505992516082d7f
[metze/samba/wip.git] / source3 / libsmb / clirap.c
1 /*
2    Unix SMB/CIFS implementation.
3    client RAP calls
4    Copyright (C) Andrew Tridgell         1994-1998
5    Copyright (C) Gerald (Jerry) Carter   2004
6    Copyright (C) James Peach             2007
7
8    This program is free software; you can redistribute it and/or modify
9    it under the terms of the GNU General Public License as published by
10    the Free Software Foundation; either version 3 of the License, or
11    (at your option) any later version.
12
13    This program is distributed in the hope that it will be useful,
14    but WITHOUT ANY WARRANTY; without even the implied warranty of
15    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16    GNU General Public License for more details.
17
18    You should have received a copy of the GNU General Public License
19    along with this program.  If not, see <http://www.gnu.org/licenses/>.
20 */
21
22 #include "includes.h"
23 #include "../libcli/auth/libcli_auth.h"
24 #include "../librpc/gen_ndr/rap.h"
25 #include "../lib/crypto/arcfour.h"
26 #include "../lib/util/tevent_ntstatus.h"
27 #include "async_smb.h"
28 #include "libsmb/libsmb.h"
29 #include "libsmb/clirap.h"
30 #include "trans2.h"
31 #include "../libcli/smb/smbXcli_base.h"
32
33 #define PIPE_LANMAN   "\\PIPE\\LANMAN"
34
35 /****************************************************************************
36  Call a remote api
37 ****************************************************************************/
38
39 bool cli_api(struct cli_state *cli,
40              char *param, int prcnt, int mprcnt,
41              char *data, int drcnt, int mdrcnt,
42              char **rparam, unsigned int *rprcnt,
43              char **rdata, unsigned int *rdrcnt)
44 {
45         NTSTATUS status;
46
47         uint8_t *my_rparam, *my_rdata;
48         uint32_t num_my_rparam, num_my_rdata;
49
50         status = cli_trans(talloc_tos(), cli, SMBtrans,
51                            PIPE_LANMAN, 0, /* name, fid */
52                            0, 0,           /* function, flags */
53                            NULL, 0, 0,     /* setup */
54                            (uint8_t *)param, prcnt, mprcnt, /* Params, length, max */
55                            (uint8_t *)data, drcnt, mdrcnt,  /* Data, length, max */
56                            NULL,                 /* recv_flags2 */
57                            NULL, 0, NULL,        /* rsetup */
58                            &my_rparam, 0, &num_my_rparam,
59                            &my_rdata, 0, &num_my_rdata);
60         if (!NT_STATUS_IS_OK(status)) {
61                 return false;
62         }
63
64         /*
65          * I know this memcpy massively hurts, but there are just tons
66          * of callers of cli_api that eventually need changing to
67          * talloc
68          */
69
70         *rparam = (char *)memdup(my_rparam, num_my_rparam);
71         if (*rparam == NULL) {
72                 goto fail;
73         }
74         *rprcnt = num_my_rparam;
75         TALLOC_FREE(my_rparam);
76
77         *rdata = (char *)memdup(my_rdata, num_my_rdata);
78         if (*rdata == NULL) {
79                 goto fail;
80         }
81         *rdrcnt = num_my_rdata;
82         TALLOC_FREE(my_rdata);
83
84         return true;
85 fail:
86         TALLOC_FREE(my_rdata);
87         TALLOC_FREE(my_rparam);
88         *rparam = NULL;
89         *rprcnt = 0;
90         *rdata = NULL;
91         *rdrcnt = 0;
92         return false;
93 }
94
95 /****************************************************************************
96  Perform a NetWkstaUserLogon.
97 ****************************************************************************/
98
99 bool cli_NetWkstaUserLogon(struct cli_state *cli,char *user, char *workstation)
100 {
101         char *rparam = NULL;
102         char *rdata = NULL;
103         char *p;
104         unsigned int rdrcnt,rprcnt;
105         char param[1024];
106
107         memset(param, 0, sizeof(param));
108
109         /* send a SMBtrans command with api NetWkstaUserLogon */
110         p = param;
111         SSVAL(p,0,132); /* api number */
112         p += 2;
113         strlcpy(p,"OOWb54WrLh",sizeof(param)-PTR_DIFF(p,param));
114         p = skip_string(param,sizeof(param),p);
115         strlcpy(p,"WB21BWDWWDDDDDDDzzzD",sizeof(param)-PTR_DIFF(p,param));
116         p = skip_string(param,sizeof(param),p);
117         SSVAL(p,0,1);
118         p += 2;
119         strlcpy(p,user,sizeof(param)-PTR_DIFF(p,param));
120         if (!strupper_m(p)) {
121                 return false;
122         }
123         p += 21;
124         p++;
125         p += 15;
126         p++;
127         strlcpy(p, workstation,sizeof(param)-PTR_DIFF(p,param));
128         if (!strupper_m(p)) {
129                 return false;
130         }
131         p += 16;
132         SSVAL(p, 0, CLI_BUFFER_SIZE);
133         p += 2;
134         SSVAL(p, 0, CLI_BUFFER_SIZE);
135         p += 2;
136
137         if (cli_api(cli,
138                     param, PTR_DIFF(p,param),1024,  /* param, length, max */
139                     NULL, 0, CLI_BUFFER_SIZE,           /* data, length, max */
140                     &rparam, &rprcnt,               /* return params, return size */
141                     &rdata, &rdrcnt                 /* return data, return size */
142                    )) {
143                 cli->rap_error = rparam? SVAL(rparam,0) : -1;
144                 p = rdata;
145
146                 if (cli->rap_error == 0) {
147                         DEBUG(4,("NetWkstaUserLogon success\n"));
148                         /*
149                          * The cli->privileges = SVAL(p, 24); field was set here
150                          * but it was not use anywhere else.
151                          */
152                         /* The cli->eff_name field used to be set here
153                            but it wasn't used anywhere else. */
154                 } else {
155                         DEBUG(1,("NetwkstaUserLogon gave error %d\n", cli->rap_error));
156                 }
157         }
158
159         SAFE_FREE(rparam);
160         SAFE_FREE(rdata);
161         return (cli->rap_error == 0);
162 }
163
164 /****************************************************************************
165  Call a NetShareEnum - try and browse available connections on a host.
166 ****************************************************************************/
167
168 int cli_RNetShareEnum(struct cli_state *cli, void (*fn)(const char *, uint32, const char *, void *), void *state)
169 {
170         char *rparam = NULL;
171         char *rdata = NULL;
172         char *p;
173         unsigned int rdrcnt,rprcnt;
174         char param[1024];
175         int count = -1;
176
177         /* now send a SMBtrans command with api RNetShareEnum */
178         p = param;
179         SSVAL(p,0,0); /* api number */
180         p += 2;
181         strlcpy(p,"WrLeh",sizeof(param)-PTR_DIFF(p,param));
182         p = skip_string(param,sizeof(param),p);
183         strlcpy(p,"B13BWz",sizeof(param)-PTR_DIFF(p,param));
184         p = skip_string(param,sizeof(param),p);
185         SSVAL(p,0,1);
186         /*
187          * Win2k needs a *smaller* buffer than 0xFFFF here -
188          * it returns "out of server memory" with 0xFFFF !!! JRA.
189          */
190         SSVAL(p,2,0xFFE0);
191         p += 4;
192
193         if (cli_api(cli,
194                     param, PTR_DIFF(p,param), 1024,  /* Param, length, maxlen */
195                     NULL, 0, 0xFFE0,            /* data, length, maxlen - Win2k needs a small buffer here too ! */
196                     &rparam, &rprcnt,                /* return params, length */
197                     &rdata, &rdrcnt))                /* return data, length */
198                 {
199                         int res = rparam? SVAL(rparam,0) : -1;
200
201                         if (res == 0 || res == ERRmoredata) {
202                                 int converter=SVAL(rparam,2);
203                                 int i;
204                                 char *rdata_end = rdata + rdrcnt;
205
206                                 count=SVAL(rparam,4);
207                                 p = rdata;
208
209                                 for (i=0;i<count;i++,p+=20) {
210                                         char *sname;
211                                         int type;
212                                         int comment_offset;
213                                         const char *cmnt;
214                                         const char *p1;
215                                         char *s1, *s2;
216                                         size_t len;
217                                         TALLOC_CTX *frame = talloc_stackframe();
218
219                                         if (p + 20 > rdata_end) {
220                                                 TALLOC_FREE(frame);
221                                                 break;
222                                         }
223
224                                         sname = p;
225                                         type = SVAL(p,14);
226                                         comment_offset = (IVAL(p,16) & 0xFFFF) - converter;
227                                         if (comment_offset < 0 ||
228                                                         comment_offset > (int)rdrcnt) {
229                                                 TALLOC_FREE(frame);
230                                                 break;
231                                         }
232                                         cmnt = comment_offset?(rdata+comment_offset):"";
233
234                                         /* Work out the comment length. */
235                                         for (p1 = cmnt, len = 0; *p1 &&
236                                                         p1 < rdata_end; len++)
237                                                 p1++;
238                                         if (!*p1) {
239                                                 len++;
240                                         }
241                                         pull_string_talloc(frame,rdata,0,
242                                                 &s1,sname,14,STR_ASCII);
243                                         pull_string_talloc(frame,rdata,0,
244                                                 &s2,cmnt,len,STR_ASCII);
245                                         if (!s1 || !s2) {
246                                                 TALLOC_FREE(frame);
247                                                 continue;
248                                         }
249
250                                         fn(s1, type, s2, state);
251
252                                         TALLOC_FREE(frame);
253                                 }
254                         } else {
255                                 DEBUG(4,("NetShareEnum res=%d\n", res));
256                         }
257                 } else {
258                         DEBUG(4,("NetShareEnum failed\n"));
259                 }
260
261         SAFE_FREE(rparam);
262         SAFE_FREE(rdata);
263
264         return count;
265 }
266
267 /****************************************************************************
268  Call a NetServerEnum for the specified workgroup and servertype mask.  This
269  function then calls the specified callback function for each name returned.
270
271  The callback function takes 4 arguments: the machine name, the server type,
272  the comment and a state pointer.
273 ****************************************************************************/
274
275 bool cli_NetServerEnum(struct cli_state *cli, char *workgroup, uint32 stype,
276                        void (*fn)(const char *, uint32, const char *, void *),
277                        void *state)
278 {
279         char *rparam = NULL;
280         char *rdata = NULL;
281         char *rdata_end = NULL;
282         unsigned int rdrcnt,rprcnt;
283         char *p;
284         char param[1024];
285         int uLevel = 1;
286         size_t len;
287         uint32 func = RAP_NetServerEnum2;
288         char *last_entry = NULL;
289         int total_cnt = 0;
290         int return_cnt = 0;
291         int res;
292
293         errno = 0; /* reset */
294
295         /*
296          * This may take more than one transaction, so we should loop until
297          * we no longer get a more data to process or we have all of the
298          * items.
299          */
300         do {
301                 /* send a SMBtrans command with api NetServerEnum */
302                 p = param;
303                 SIVAL(p,0,func); /* api number */
304                 p += 2;
305
306                 if (func == RAP_NetServerEnum3) {
307                         strlcpy(p,"WrLehDzz", sizeof(param)-PTR_DIFF(p,param));
308                 } else {
309                         strlcpy(p,"WrLehDz", sizeof(param)-PTR_DIFF(p,param));
310                 }
311
312                 p = skip_string(param, sizeof(param), p);
313                 strlcpy(p,"B16BBDz", sizeof(param)-PTR_DIFF(p,param));
314
315                 p = skip_string(param, sizeof(param), p);
316                 SSVAL(p,0,uLevel);
317                 SSVAL(p,2,CLI_BUFFER_SIZE);
318                 p += 4;
319                 SIVAL(p,0,stype);
320                 p += 4;
321
322                 /* If we have more data, tell the server where
323                  * to continue from.
324                  */
325                 len = push_ascii(p,
326                                 workgroup,
327                                 sizeof(param) - PTR_DIFF(p,param) - 1,
328                                 STR_TERMINATE|STR_UPPER);
329
330                 if (len == (size_t)-1) {
331                         SAFE_FREE(last_entry);
332                         return false;
333                 }
334                 p += len;
335
336                 if (func == RAP_NetServerEnum3) {
337                         len = push_ascii(p,
338                                         last_entry ? last_entry : "",
339                                         sizeof(param) - PTR_DIFF(p,param) - 1,
340                                         STR_TERMINATE);
341
342                         if (len == (size_t)-1) {
343                                 SAFE_FREE(last_entry);
344                                 return false;
345                         }
346                         p += len;
347                 }
348
349                 /* Next time through we need to use the continue api */
350                 func = RAP_NetServerEnum3;
351
352                 if (!cli_api(cli,
353                         param, PTR_DIFF(p,param), 8, /* params, length, max */
354                         NULL, 0, CLI_BUFFER_SIZE, /* data, length, max */
355                             &rparam, &rprcnt, /* return params, return size */
356                             &rdata, &rdrcnt)) { /* return data, return size */
357
358                         /* break out of the loop on error */
359                         res = -1;
360                         break;
361                 }
362
363                 rdata_end = rdata + rdrcnt;
364                 res = rparam ? SVAL(rparam,0) : -1;
365
366                 if (res == 0 || res == ERRmoredata ||
367                     (res != -1 && cli_errno(cli) == 0)) {
368                         char *sname = NULL;
369                         int i, count;
370                         int converter=SVAL(rparam,2);
371
372                         /* Get the number of items returned in this buffer */
373                         count = SVAL(rparam, 4);
374
375                         /* The next field contains the number of items left,
376                          * including those returned in this buffer. So the
377                          * first time through this should contain all of the
378                          * entries.
379                          */
380                         if (total_cnt == 0) {
381                                 total_cnt = SVAL(rparam, 6);
382                         }
383
384                         /* Keep track of how many we have read */
385                         return_cnt += count;
386                         p = rdata;
387
388                         /* The last name in the previous NetServerEnum reply is
389                          * sent back to server in the NetServerEnum3 request
390                          * (last_entry). The next reply should repeat this entry
391                          * as the first element. We have no proof that this is
392                          * always true, but from traces that seems to be the
393                          * behavior from Window Servers. So first lets do a lot
394                          * of checking, just being paranoid. If the string
395                          * matches then we already saw this entry so skip it.
396                          *
397                          * NOTE: sv1_name field must be null terminated and has
398                          * a max size of 16 (NetBIOS Name).
399                          */
400                         if (last_entry && count && p &&
401                                 (strncmp(last_entry, p, 16) == 0)) {
402                             count -= 1; /* Skip this entry */
403                             return_cnt = -1; /* Not part of total, so don't count. */
404                             p = rdata + 26; /* Skip the whole record */
405                         }
406
407                         for (i = 0; i < count; i++, p += 26) {
408                                 int comment_offset;
409                                 const char *cmnt;
410                                 const char *p1;
411                                 char *s1, *s2;
412                                 TALLOC_CTX *frame = talloc_stackframe();
413                                 uint32_t entry_stype;
414
415                                 if (p + 26 > rdata_end) {
416                                         TALLOC_FREE(frame);
417                                         break;
418                                 }
419
420                                 sname = p;
421                                 comment_offset = (IVAL(p,22) & 0xFFFF)-converter;
422                                 cmnt = comment_offset?(rdata+comment_offset):"";
423
424                                 if (comment_offset < 0 || comment_offset >= (int)rdrcnt) {
425                                         TALLOC_FREE(frame);
426                                         continue;
427                                 }
428
429                                 /* Work out the comment length. */
430                                 for (p1 = cmnt, len = 0; *p1 &&
431                                                 p1 < rdata_end; len++)
432                                         p1++;
433                                 if (!*p1) {
434                                         len++;
435                                 }
436
437                                 entry_stype = IVAL(p,18) & ~SV_TYPE_LOCAL_LIST_ONLY;
438
439                                 pull_string_talloc(frame,rdata,0,
440                                         &s1,sname,16,STR_ASCII);
441                                 pull_string_talloc(frame,rdata,0,
442                                         &s2,cmnt,len,STR_ASCII);
443
444                                 if (!s1 || !s2) {
445                                         TALLOC_FREE(frame);
446                                         continue;
447                                 }
448
449                                 fn(s1, entry_stype, s2, state);
450                                 TALLOC_FREE(frame);
451                         }
452
453                         /* We are done with the old last entry, so now we can free it */
454                         if (last_entry) {
455                                 SAFE_FREE(last_entry); /* This will set it to null */
456                         }
457
458                         /* We always make a copy of  the last entry if we have one */
459                         if (sname) {
460                                 last_entry = smb_xstrdup(sname);
461                         }
462
463                         /* If we have more data, but no last entry then error out */
464                         if (!last_entry && (res == ERRmoredata)) {
465                                 errno = EINVAL;
466                                 res = 0;
467                         }
468
469                 }
470
471                 SAFE_FREE(rparam);
472                 SAFE_FREE(rdata);
473         } while ((res == ERRmoredata) && (total_cnt > return_cnt));
474
475         SAFE_FREE(rparam);
476         SAFE_FREE(rdata);
477         SAFE_FREE(last_entry);
478
479         if (res == -1) {
480                 errno = cli_errno(cli);
481         } else {
482                 if (!return_cnt) {
483                         /* this is a very special case, when the domain master for the
484                            work group isn't part of the work group itself, there is something
485                            wild going on */
486                         errno = ENOENT;
487                 }
488             }
489
490         return(return_cnt > 0);
491 }
492
493 /****************************************************************************
494  Send a SamOEMChangePassword command.
495 ****************************************************************************/
496
497 bool cli_oem_change_password(struct cli_state *cli, const char *user, const char *new_password,
498                              const char *old_password)
499 {
500         char param[1024];
501         unsigned char data[532];
502         char *p = param;
503         unsigned char old_pw_hash[16];
504         unsigned char new_pw_hash[16];
505         unsigned int data_len;
506         unsigned int param_len = 0;
507         char *rparam = NULL;
508         char *rdata = NULL;
509         unsigned int rprcnt, rdrcnt;
510
511         if (strlen(user) >= sizeof(fstring)-1) {
512                 DEBUG(0,("cli_oem_change_password: user name %s is too long.\n", user));
513                 return False;
514         }
515
516         SSVAL(p,0,214); /* SamOEMChangePassword command. */
517         p += 2;
518         strlcpy(p, "zsT", sizeof(param)-PTR_DIFF(p,param));
519         p = skip_string(param,sizeof(param),p);
520         strlcpy(p, "B516B16", sizeof(param)-PTR_DIFF(p,param));
521         p = skip_string(param,sizeof(param),p);
522         strlcpy(p,user, sizeof(param)-PTR_DIFF(p,param));
523         p = skip_string(param,sizeof(param),p);
524         SSVAL(p,0,532);
525         p += 2;
526
527         param_len = PTR_DIFF(p,param);
528
529         /*
530          * Get the Lanman hash of the old password, we
531          * use this as the key to make_oem_passwd_hash().
532          */
533         E_deshash(old_password, old_pw_hash);
534
535         encode_pw_buffer(data, new_password, STR_ASCII);
536
537 #ifdef DEBUG_PASSWORD
538         DEBUG(100,("make_oem_passwd_hash\n"));
539         dump_data(100, data, 516);
540 #endif
541         arcfour_crypt( (unsigned char *)data, (unsigned char *)old_pw_hash, 516);
542
543         /*
544          * Now place the old password hash in the data.
545          */
546         E_deshash(new_password, new_pw_hash);
547
548         E_old_pw_hash( new_pw_hash, old_pw_hash, (uchar *)&data[516]);
549
550         data_len = 532;
551
552         if (!cli_api(cli,
553                      param, param_len, 4,               /* param, length, max */
554                      (char *)data, data_len, 0,         /* data, length, max */
555                      &rparam, &rprcnt,
556                      &rdata, &rdrcnt)) {
557                 DEBUG(0,("cli_oem_change_password: Failed to send password change for user %s\n",
558                         user ));
559                 return False;
560         }
561
562         if (rparam) {
563                 cli->rap_error = SVAL(rparam,0);
564         }
565
566         SAFE_FREE(rparam);
567         SAFE_FREE(rdata);
568
569         return (cli->rap_error == 0);
570 }
571
572 /****************************************************************************
573  Send a qpathinfo call.
574 ****************************************************************************/
575
576 struct cli_qpathinfo1_state {
577         struct cli_state *cli;
578         uint32_t num_data;
579         uint8_t *data;
580 };
581
582 static void cli_qpathinfo1_done(struct tevent_req *subreq);
583
584 struct tevent_req *cli_qpathinfo1_send(TALLOC_CTX *mem_ctx,
585                                        struct tevent_context *ev,
586                                        struct cli_state *cli,
587                                        const char *fname)
588 {
589         struct tevent_req *req = NULL, *subreq = NULL;
590         struct cli_qpathinfo1_state *state = NULL;
591
592         req = tevent_req_create(mem_ctx, &state, struct cli_qpathinfo1_state);
593         if (req == NULL) {
594                 return NULL;
595         }
596         state->cli = cli;
597         subreq = cli_qpathinfo_send(state, ev, cli, fname, SMB_INFO_STANDARD,
598                                     22, CLI_BUFFER_SIZE);
599         if (tevent_req_nomem(subreq, req)) {
600                 return tevent_req_post(req, ev);
601         }
602         tevent_req_set_callback(subreq, cli_qpathinfo1_done, req);
603         return req;
604 }
605
606 static void cli_qpathinfo1_done(struct tevent_req *subreq)
607 {
608         struct tevent_req *req = tevent_req_callback_data(
609                 subreq, struct tevent_req);
610         struct cli_qpathinfo1_state *state = tevent_req_data(
611                 req, struct cli_qpathinfo1_state);
612         NTSTATUS status;
613
614         status = cli_qpathinfo_recv(subreq, state, &state->data,
615                                     &state->num_data);
616         TALLOC_FREE(subreq);
617         if (!NT_STATUS_IS_OK(status)) {
618                 tevent_req_nterror(req, status);
619                 return;
620         }
621         tevent_req_done(req);
622 }
623
624 NTSTATUS cli_qpathinfo1_recv(struct tevent_req *req,
625                              time_t *change_time,
626                              time_t *access_time,
627                              time_t *write_time,
628                              off_t *size,
629                              uint16 *mode)
630 {
631         struct cli_qpathinfo1_state *state = tevent_req_data(
632                 req, struct cli_qpathinfo1_state);
633         NTSTATUS status;
634
635         time_t (*date_fn)(const void *buf, int serverzone);
636
637         if (tevent_req_is_nterror(req, &status)) {
638                 return status;
639         }
640
641         if (state->cli->win95) {
642                 date_fn = make_unix_date;
643         } else {
644                 date_fn = make_unix_date2;
645         }
646
647         if (change_time) {
648                 *change_time = date_fn(state->data+0, smb1cli_conn_server_time_zone(state->cli->conn));
649         }
650         if (access_time) {
651                 *access_time = date_fn(state->data+4, smb1cli_conn_server_time_zone(state->cli->conn));
652         }
653         if (write_time) {
654                 *write_time = date_fn(state->data+8, smb1cli_conn_server_time_zone(state->cli->conn));
655         }
656         if (size) {
657                 *size = IVAL(state->data, 12);
658         }
659         if (mode) {
660                 *mode = SVAL(state->data, l1_attrFile);
661         }
662         return NT_STATUS_OK;
663 }
664
665 NTSTATUS cli_qpathinfo1(struct cli_state *cli,
666                         const char *fname,
667                         time_t *change_time,
668                         time_t *access_time,
669                         time_t *write_time,
670                         off_t *size,
671                         uint16 *mode)
672 {
673         TALLOC_CTX *frame = talloc_stackframe();
674         struct tevent_context *ev;
675         struct tevent_req *req;
676         NTSTATUS status = NT_STATUS_NO_MEMORY;
677
678         if (smbXcli_conn_has_async_calls(cli->conn)) {
679                 /*
680                  * Can't use sync call while an async call is in flight
681                  */
682                 status = NT_STATUS_INVALID_PARAMETER;
683                 goto fail;
684         }
685         ev = samba_tevent_context_init(frame);
686         if (ev == NULL) {
687                 goto fail;
688         }
689         req = cli_qpathinfo1_send(frame, ev, cli, fname);
690         if (req == NULL) {
691                 goto fail;
692         }
693         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
694                 goto fail;
695         }
696         status = cli_qpathinfo1_recv(req, change_time, access_time,
697                                      write_time, size, mode);
698  fail:
699         TALLOC_FREE(frame);
700         return status;
701 }
702
703 /****************************************************************************
704  Send a setpathinfo call.
705 ****************************************************************************/
706
707 NTSTATUS cli_setpathinfo_basic(struct cli_state *cli, const char *fname,
708                                time_t create_time,
709                                time_t access_time,
710                                time_t write_time,
711                                time_t change_time,
712                                uint16 mode)
713 {
714         unsigned int data_len = 0;
715         char data[40];
716         char *p;
717
718         p = data;
719
720         /*
721          * Add the create, last access, modification, and status change times
722          */
723         put_long_date(p, create_time);
724         p += 8;
725
726         put_long_date(p, access_time);
727         p += 8;
728
729         put_long_date(p, write_time);
730         p += 8;
731
732         put_long_date(p, change_time);
733         p += 8;
734
735         /* Add attributes */
736         SIVAL(p, 0, mode);
737         p += 4;
738
739         /* Add padding */
740         SIVAL(p, 0, 0);
741         p += 4;
742
743         data_len = PTR_DIFF(p, data);
744
745         return cli_setpathinfo(cli, SMB_FILE_BASIC_INFORMATION, fname,
746                                (uint8_t *)data, data_len);
747 }
748
749 /****************************************************************************
750  Send a qpathinfo call with the SMB_QUERY_FILE_ALL_INFO info level.
751 ****************************************************************************/
752
753 struct cli_qpathinfo2_state {
754         uint32_t num_data;
755         uint8_t *data;
756 };
757
758 static void cli_qpathinfo2_done(struct tevent_req *subreq);
759
760 struct tevent_req *cli_qpathinfo2_send(TALLOC_CTX *mem_ctx,
761                                        struct tevent_context *ev,
762                                        struct cli_state *cli,
763                                        const char *fname)
764 {
765         struct tevent_req *req = NULL, *subreq = NULL;
766         struct cli_qpathinfo2_state *state = NULL;
767
768         req = tevent_req_create(mem_ctx, &state, struct cli_qpathinfo2_state);
769         if (req == NULL) {
770                 return NULL;
771         }
772         subreq = cli_qpathinfo_send(state, ev, cli, fname,
773                                     SMB_QUERY_FILE_ALL_INFO,
774                                     68, CLI_BUFFER_SIZE);
775         if (tevent_req_nomem(subreq, req)) {
776                 return tevent_req_post(req, ev);
777         }
778         tevent_req_set_callback(subreq, cli_qpathinfo2_done, req);
779         return req;
780 }
781
782 static void cli_qpathinfo2_done(struct tevent_req *subreq)
783 {
784         struct tevent_req *req = tevent_req_callback_data(
785                 subreq, struct tevent_req);
786         struct cli_qpathinfo2_state *state = tevent_req_data(
787                 req, struct cli_qpathinfo2_state);
788         NTSTATUS status;
789
790         status = cli_qpathinfo_recv(subreq, state, &state->data,
791                                     &state->num_data);
792         TALLOC_FREE(subreq);
793         if (!NT_STATUS_IS_OK(status)) {
794                 tevent_req_nterror(req, status);
795                 return;
796         }
797         tevent_req_done(req);
798 }
799
800 NTSTATUS cli_qpathinfo2_recv(struct tevent_req *req,
801                              struct timespec *create_time,
802                              struct timespec *access_time,
803                              struct timespec *write_time,
804                              struct timespec *change_time,
805                              off_t *size, uint16 *mode,
806                              SMB_INO_T *ino)
807 {
808         struct cli_qpathinfo2_state *state = tevent_req_data(
809                 req, struct cli_qpathinfo2_state);
810         NTSTATUS status;
811
812         if (tevent_req_is_nterror(req, &status)) {
813                 return status;
814         }
815
816         if (create_time) {
817                 *create_time = interpret_long_date((char *)state->data+0);
818         }
819         if (access_time) {
820                 *access_time = interpret_long_date((char *)state->data+8);
821         }
822         if (write_time) {
823                 *write_time = interpret_long_date((char *)state->data+16);
824         }
825         if (change_time) {
826                 *change_time = interpret_long_date((char *)state->data+24);
827         }
828         if (mode) {
829                 *mode = SVAL(state->data, 32);
830         }
831         if (size) {
832                 *size = IVAL2_TO_SMB_BIG_UINT(state->data,48);
833         }
834         if (ino) {
835                 *ino = IVAL(state->data, 64);
836         }
837         return NT_STATUS_OK;
838 }
839
840 NTSTATUS cli_qpathinfo2(struct cli_state *cli, const char *fname,
841                         struct timespec *create_time,
842                         struct timespec *access_time,
843                         struct timespec *write_time,
844                         struct timespec *change_time,
845                         off_t *size, uint16 *mode,
846                         SMB_INO_T *ino)
847 {
848         TALLOC_CTX *frame = NULL;
849         struct tevent_context *ev;
850         struct tevent_req *req;
851         NTSTATUS status = NT_STATUS_NO_MEMORY;
852
853         if (smbXcli_conn_protocol(cli->conn) >= PROTOCOL_SMB2_02) {
854                 return cli_smb2_qpathinfo2(cli,
855                                         fname,
856                                         create_time,
857                                         access_time,
858                                         write_time,
859                                         change_time,
860                                         size,
861                                         mode,
862                                         ino);
863         }
864
865         frame = talloc_stackframe();
866
867         if (smbXcli_conn_has_async_calls(cli->conn)) {
868                 /*
869                  * Can't use sync call while an async call is in flight
870                  */
871                 status = NT_STATUS_INVALID_PARAMETER;
872                 goto fail;
873         }
874         ev = samba_tevent_context_init(frame);
875         if (ev == NULL) {
876                 goto fail;
877         }
878         req = cli_qpathinfo2_send(frame, ev, cli, fname);
879         if (req == NULL) {
880                 goto fail;
881         }
882         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
883                 goto fail;
884         }
885         status = cli_qpathinfo2_recv(req, create_time, access_time,
886                                      write_time, change_time, size, mode, ino);
887  fail:
888         TALLOC_FREE(frame);
889         return status;
890 }
891
892 /****************************************************************************
893  Get the stream info
894 ****************************************************************************/
895
896 struct cli_qpathinfo_streams_state {
897         uint32_t num_data;
898         uint8_t *data;
899 };
900
901 static void cli_qpathinfo_streams_done(struct tevent_req *subreq);
902
903 struct tevent_req *cli_qpathinfo_streams_send(TALLOC_CTX *mem_ctx,
904                                               struct tevent_context *ev,
905                                               struct cli_state *cli,
906                                               const char *fname)
907 {
908         struct tevent_req *req = NULL, *subreq = NULL;
909         struct cli_qpathinfo_streams_state *state = NULL;
910
911         req = tevent_req_create(mem_ctx, &state,
912                                 struct cli_qpathinfo_streams_state);
913         if (req == NULL) {
914                 return NULL;
915         }
916         subreq = cli_qpathinfo_send(state, ev, cli, fname,
917                                     SMB_FILE_STREAM_INFORMATION,
918                                     0, CLI_BUFFER_SIZE);
919         if (tevent_req_nomem(subreq, req)) {
920                 return tevent_req_post(req, ev);
921         }
922         tevent_req_set_callback(subreq, cli_qpathinfo_streams_done, req);
923         return req;
924 }
925
926 static void cli_qpathinfo_streams_done(struct tevent_req *subreq)
927 {
928         struct tevent_req *req = tevent_req_callback_data(
929                 subreq, struct tevent_req);
930         struct cli_qpathinfo_streams_state *state = tevent_req_data(
931                 req, struct cli_qpathinfo_streams_state);
932         NTSTATUS status;
933
934         status = cli_qpathinfo_recv(subreq, state, &state->data,
935                                     &state->num_data);
936         TALLOC_FREE(subreq);
937         if (!NT_STATUS_IS_OK(status)) {
938                 tevent_req_nterror(req, status);
939                 return;
940         }
941         tevent_req_done(req);
942 }
943
944 NTSTATUS cli_qpathinfo_streams_recv(struct tevent_req *req,
945                                     TALLOC_CTX *mem_ctx,
946                                     unsigned int *pnum_streams,
947                                     struct stream_struct **pstreams)
948 {
949         struct cli_qpathinfo_streams_state *state = tevent_req_data(
950                 req, struct cli_qpathinfo_streams_state);
951         NTSTATUS status;
952
953         if (tevent_req_is_nterror(req, &status)) {
954                 return status;
955         }
956         if (!parse_streams_blob(mem_ctx, state->data, state->num_data,
957                                 pnum_streams, pstreams)) {
958                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
959         }
960         return NT_STATUS_OK;
961 }
962
963 NTSTATUS cli_qpathinfo_streams(struct cli_state *cli, const char *fname,
964                                TALLOC_CTX *mem_ctx,
965                                unsigned int *pnum_streams,
966                                struct stream_struct **pstreams)
967 {
968         TALLOC_CTX *frame = talloc_stackframe();
969         struct tevent_context *ev;
970         struct tevent_req *req;
971         NTSTATUS status = NT_STATUS_NO_MEMORY;
972
973         if (smbXcli_conn_has_async_calls(cli->conn)) {
974                 /*
975                  * Can't use sync call while an async call is in flight
976                  */
977                 status = NT_STATUS_INVALID_PARAMETER;
978                 goto fail;
979         }
980         ev = samba_tevent_context_init(frame);
981         if (ev == NULL) {
982                 goto fail;
983         }
984         req = cli_qpathinfo_streams_send(frame, ev, cli, fname);
985         if (req == NULL) {
986                 goto fail;
987         }
988         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
989                 goto fail;
990         }
991         status = cli_qpathinfo_streams_recv(req, mem_ctx, pnum_streams,
992                                             pstreams);
993  fail:
994         TALLOC_FREE(frame);
995         return status;
996 }
997
998 bool parse_streams_blob(TALLOC_CTX *mem_ctx, const uint8_t *rdata,
999                                size_t data_len,
1000                                unsigned int *pnum_streams,
1001                                struct stream_struct **pstreams)
1002 {
1003         unsigned int num_streams;
1004         struct stream_struct *streams;
1005         unsigned int ofs;
1006
1007         num_streams = 0;
1008         streams = NULL;
1009         ofs = 0;
1010
1011         while ((data_len > ofs) && (data_len - ofs >= 24)) {
1012                 uint32_t nlen, len;
1013                 size_t size;
1014                 void *vstr;
1015                 struct stream_struct *tmp;
1016                 uint8_t *tmp_buf;
1017
1018                 tmp = talloc_realloc(mem_ctx, streams,
1019                                            struct stream_struct,
1020                                            num_streams+1);
1021
1022                 if (tmp == NULL) {
1023                         goto fail;
1024                 }
1025                 streams = tmp;
1026
1027                 nlen                      = IVAL(rdata, ofs + 0x04);
1028
1029                 streams[num_streams].size = IVAL_TO_SMB_OFF_T(
1030                         rdata, ofs + 0x08);
1031                 streams[num_streams].alloc_size = IVAL_TO_SMB_OFF_T(
1032                         rdata, ofs + 0x10);
1033
1034                 if (nlen > data_len - (ofs + 24)) {
1035                         goto fail;
1036                 }
1037
1038                 /*
1039                  * We need to null-terminate src, how do I do this with
1040                  * convert_string_talloc??
1041                  */
1042
1043                 tmp_buf = talloc_array(streams, uint8_t, nlen+2);
1044                 if (tmp_buf == NULL) {
1045                         goto fail;
1046                 }
1047
1048                 memcpy(tmp_buf, rdata+ofs+24, nlen);
1049                 tmp_buf[nlen] = 0;
1050                 tmp_buf[nlen+1] = 0;
1051
1052                 if (!convert_string_talloc(streams, CH_UTF16, CH_UNIX, tmp_buf,
1053                                            nlen+2, &vstr, &size))
1054                 {
1055                         TALLOC_FREE(tmp_buf);
1056                         goto fail;
1057                 }
1058
1059                 TALLOC_FREE(tmp_buf);
1060                 streams[num_streams].name = (char *)vstr;
1061                 num_streams++;
1062
1063                 len = IVAL(rdata, ofs);
1064                 if (len > data_len - ofs) {
1065                         goto fail;
1066                 }
1067                 if (len == 0) break;
1068                 ofs += len;
1069         }
1070
1071         *pnum_streams = num_streams;
1072         *pstreams = streams;
1073         return true;
1074
1075  fail:
1076         TALLOC_FREE(streams);
1077         return false;
1078 }
1079
1080 /****************************************************************************
1081  Send a qfileinfo QUERY_FILE_NAME_INFO call.
1082 ****************************************************************************/
1083
1084 NTSTATUS cli_qfilename(struct cli_state *cli, uint16_t fnum,
1085                        TALLOC_CTX *mem_ctx, char **_name)
1086 {
1087         uint16_t recv_flags2;
1088         uint8_t *rdata;
1089         uint32_t num_rdata;
1090         NTSTATUS status;
1091         char *name = NULL;
1092         uint32_t namelen;
1093
1094         status = cli_qfileinfo(talloc_tos(), cli, fnum,
1095                                SMB_QUERY_FILE_NAME_INFO,
1096                                4, CLI_BUFFER_SIZE, &recv_flags2,
1097                                &rdata, &num_rdata);
1098         if (!NT_STATUS_IS_OK(status)) {
1099                 return status;
1100         }
1101
1102         namelen = IVAL(rdata, 0);
1103         if (namelen > (num_rdata - 4)) {
1104                 TALLOC_FREE(rdata);
1105                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
1106         }
1107
1108         clistr_pull_talloc(mem_ctx,
1109                            (const char *)rdata,
1110                            recv_flags2,
1111                            &name,
1112                            rdata + 4,
1113                            namelen,
1114                            STR_UNICODE);
1115         if (name == NULL) {
1116                 status = map_nt_error_from_unix(errno);
1117                 TALLOC_FREE(rdata);
1118                 return status;
1119         }
1120
1121         *_name = name;
1122         TALLOC_FREE(rdata);
1123         return NT_STATUS_OK;
1124 }
1125
1126 /****************************************************************************
1127  Send a qfileinfo call.
1128 ****************************************************************************/
1129
1130 NTSTATUS cli_qfileinfo_basic(struct cli_state *cli, uint16_t fnum,
1131                              uint16 *mode, off_t *size,
1132                              struct timespec *create_time,
1133                              struct timespec *access_time,
1134                              struct timespec *write_time,
1135                              struct timespec *change_time,
1136                              SMB_INO_T *ino)
1137 {
1138         uint8_t *rdata;
1139         uint32_t num_rdata;
1140         NTSTATUS status;
1141
1142         /* if its a win95 server then fail this - win95 totally screws it
1143            up */
1144         if (cli->win95) {
1145                 return NT_STATUS_NOT_SUPPORTED;
1146         }
1147
1148         status = cli_qfileinfo(talloc_tos(), cli, fnum,
1149                                SMB_QUERY_FILE_ALL_INFO,
1150                                68, CLI_BUFFER_SIZE,
1151                                NULL,
1152                                &rdata, &num_rdata);
1153         if (!NT_STATUS_IS_OK(status)) {
1154                 return status;
1155         }
1156
1157         if (create_time) {
1158                 *create_time = interpret_long_date((char *)rdata+0);
1159         }
1160         if (access_time) {
1161                 *access_time = interpret_long_date((char *)rdata+8);
1162         }
1163         if (write_time) {
1164                 *write_time = interpret_long_date((char *)rdata+16);
1165         }
1166         if (change_time) {
1167                 *change_time = interpret_long_date((char *)rdata+24);
1168         }
1169         if (mode) {
1170                 *mode = SVAL(rdata, 32);
1171         }
1172         if (size) {
1173                 *size = IVAL2_TO_SMB_BIG_UINT(rdata,48);
1174         }
1175         if (ino) {
1176                 *ino = IVAL(rdata, 64);
1177         }
1178
1179         TALLOC_FREE(rdata);
1180         return NT_STATUS_OK;
1181 }
1182
1183 /****************************************************************************
1184  Send a qpathinfo BASIC_INFO call.
1185 ****************************************************************************/
1186
1187 struct cli_qpathinfo_basic_state {
1188         uint32_t num_data;
1189         uint8_t *data;
1190 };
1191
1192 static void cli_qpathinfo_basic_done(struct tevent_req *subreq);
1193
1194 struct tevent_req *cli_qpathinfo_basic_send(TALLOC_CTX *mem_ctx,
1195                                             struct tevent_context *ev,
1196                                             struct cli_state *cli,
1197                                             const char *fname)
1198 {
1199         struct tevent_req *req = NULL, *subreq = NULL;
1200         struct cli_qpathinfo_basic_state *state = NULL;
1201
1202         req = tevent_req_create(mem_ctx, &state,
1203                                 struct cli_qpathinfo_basic_state);
1204         if (req == NULL) {
1205                 return NULL;
1206         }
1207         subreq = cli_qpathinfo_send(state, ev, cli, fname,
1208                                     SMB_QUERY_FILE_BASIC_INFO,
1209                                     36, CLI_BUFFER_SIZE);
1210         if (tevent_req_nomem(subreq, req)) {
1211                 return tevent_req_post(req, ev);
1212         }
1213         tevent_req_set_callback(subreq, cli_qpathinfo_basic_done, req);
1214         return req;
1215 }
1216
1217 static void cli_qpathinfo_basic_done(struct tevent_req *subreq)
1218 {
1219         struct tevent_req *req = tevent_req_callback_data(
1220                 subreq, struct tevent_req);
1221         struct cli_qpathinfo_basic_state *state = tevent_req_data(
1222                 req, struct cli_qpathinfo_basic_state);
1223         NTSTATUS status;
1224
1225         status = cli_qpathinfo_recv(subreq, state, &state->data,
1226                                     &state->num_data);
1227         TALLOC_FREE(subreq);
1228         if (!NT_STATUS_IS_OK(status)) {
1229                 tevent_req_nterror(req, status);
1230                 return;
1231         }
1232         tevent_req_done(req);
1233 }
1234
1235 NTSTATUS cli_qpathinfo_basic_recv(struct tevent_req *req,
1236                                   SMB_STRUCT_STAT *sbuf, uint32 *attributes)
1237 {
1238         struct cli_qpathinfo_basic_state *state = tevent_req_data(
1239                 req, struct cli_qpathinfo_basic_state);
1240         NTSTATUS status;
1241
1242         if (tevent_req_is_nterror(req, &status)) {
1243                 return status;
1244         }
1245
1246         sbuf->st_ex_atime = interpret_long_date((char *)state->data+8);
1247         sbuf->st_ex_mtime = interpret_long_date((char *)state->data+16);
1248         sbuf->st_ex_ctime = interpret_long_date((char *)state->data+24);
1249         *attributes = IVAL(state->data, 32);
1250         return NT_STATUS_OK;
1251 }
1252
1253 NTSTATUS cli_qpathinfo_basic(struct cli_state *cli, const char *name,
1254                              SMB_STRUCT_STAT *sbuf, uint32 *attributes)
1255 {
1256         TALLOC_CTX *frame = talloc_stackframe();
1257         struct tevent_context *ev;
1258         struct tevent_req *req;
1259         NTSTATUS status = NT_STATUS_NO_MEMORY;
1260
1261         if (smbXcli_conn_has_async_calls(cli->conn)) {
1262                 /*
1263                  * Can't use sync call while an async call is in flight
1264                  */
1265                 status = NT_STATUS_INVALID_PARAMETER;
1266                 goto fail;
1267         }
1268         ev = samba_tevent_context_init(frame);
1269         if (ev == NULL) {
1270                 goto fail;
1271         }
1272         req = cli_qpathinfo_basic_send(frame, ev, cli, name);
1273         if (req == NULL) {
1274                 goto fail;
1275         }
1276         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
1277                 goto fail;
1278         }
1279         status = cli_qpathinfo_basic_recv(req, sbuf, attributes);
1280  fail:
1281         TALLOC_FREE(frame);
1282         return status;
1283 }
1284
1285 /****************************************************************************
1286  Send a qpathinfo SMB_QUERY_FILE_ALT_NAME_INFO call.
1287 ****************************************************************************/
1288
1289 NTSTATUS cli_qpathinfo_alt_name(struct cli_state *cli, const char *fname, fstring alt_name)
1290 {
1291         uint8_t *rdata;
1292         uint32_t num_rdata;
1293         unsigned int len;
1294         char *converted = NULL;
1295         size_t converted_size = 0;
1296         NTSTATUS status;
1297
1298         status = cli_qpathinfo(talloc_tos(), cli, fname,
1299                                SMB_QUERY_FILE_ALT_NAME_INFO,
1300                                4, CLI_BUFFER_SIZE, &rdata, &num_rdata);
1301         if (!NT_STATUS_IS_OK(status)) {
1302                 return status;
1303         }
1304
1305         len = IVAL(rdata, 0);
1306
1307         if (len > num_rdata - 4) {
1308                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
1309         }
1310
1311         /* The returned data is a pushed string, not raw data. */
1312         if (!convert_string_talloc(talloc_tos(),
1313                                    smbXcli_conn_use_unicode(cli->conn) ? CH_UTF16LE : CH_DOS,
1314                                    CH_UNIX,
1315                                    rdata + 4,
1316                                    len,
1317                                    &converted,
1318                                    &converted_size)) {
1319                 return NT_STATUS_NO_MEMORY;
1320         }
1321         fstrcpy(alt_name, converted);
1322
1323         TALLOC_FREE(converted);
1324         TALLOC_FREE(rdata);
1325
1326         return NT_STATUS_OK;
1327 }