2 Unix SMB/CIFS implementation.
3 default IPC$ NTVFS backend
5 Copyright (C) Andrew Tridgell 2003
6 Copyright (C) Stefan (metze) Metzmacher 2004-2005
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 this implements the IPC$ backend, called by the NTVFS subsystem to
23 handle requests on IPC$ shares
28 #include "../lib/util/dlinklist.h"
29 #include "ntvfs/ntvfs.h"
30 #include "../librpc/gen_ndr/rap.h"
31 #include "ntvfs/ipc/proto.h"
32 #include "../libcli/smb/smb_constants.h"
33 #include "param/param.h"
34 #include "../lib/tsocket/tsocket.h"
35 #include "../libcli/named_pipe_auth/npa_tstream.h"
36 #include "auth/auth.h"
37 #include "auth/auth_sam_reply.h"
38 #include "lib/socket/socket.h"
39 #include "auth/credentials/credentials.h"
40 #include "auth/credentials/credentials_krb5.h"
41 #include "system/kerberos.h"
42 #include "system/gssapi.h"
43 #include "system/locale.h"
44 #include "system/filesys.h"
46 /* this is the private structure used to keep the state of an open
47 ipc$ connection. It needs to keep information about all open
50 struct ntvfs_module_context *ntvfs;
52 /* a list of open pipes */
54 struct pipe_state *next, *prev;
55 struct ipc_private *ipriv;
56 const char *pipe_name;
57 struct ntvfs_handle *handle;
58 struct tstream_context *npipe;
60 uint16_t device_state;
61 uint64_t allocation_size;
62 struct tevent_queue *write_queue;
63 struct tevent_queue *read_queue;
69 find a open pipe give a file handle
71 static struct pipe_state *pipe_state_find(struct ipc_private *ipriv, struct ntvfs_handle *handle)
76 p = ntvfs_handle_get_backend_data(handle, ipriv->ntvfs);
79 s = talloc_get_type(p, struct pipe_state);
86 find a open pipe give a wire fnum
88 static struct pipe_state *pipe_state_find_key(struct ipc_private *ipriv, struct ntvfs_request *req, const DATA_BLOB *key)
90 struct ntvfs_handle *h;
92 h = ntvfs_handle_search_by_wire_key(ipriv->ntvfs, req, key);
95 return pipe_state_find(ipriv, h);
100 connect to a share - always works
102 static NTSTATUS ipc_connect(struct ntvfs_module_context *ntvfs,
103 struct ntvfs_request *req,
104 union smb_tcon* tcon)
106 struct ipc_private *ipriv;
107 const char *sharename;
109 switch (tcon->generic.level) {
111 sharename = tcon->tcon.in.service;
114 sharename = tcon->tconx.in.path;
117 sharename = tcon->smb2.in.path;
120 return NT_STATUS_INVALID_LEVEL;
123 if (strncmp(sharename, "\\\\", 2) == 0) {
124 char *p = strchr(sharename+2, '\\');
130 ntvfs->ctx->fs_type = talloc_strdup(ntvfs->ctx, "IPC");
131 NT_STATUS_HAVE_NO_MEMORY(ntvfs->ctx->fs_type);
133 ntvfs->ctx->dev_type = talloc_strdup(ntvfs->ctx, "IPC");
134 NT_STATUS_HAVE_NO_MEMORY(ntvfs->ctx->dev_type);
136 if (tcon->generic.level == RAW_TCON_TCONX) {
137 tcon->tconx.out.fs_type = ntvfs->ctx->fs_type;
138 tcon->tconx.out.dev_type = ntvfs->ctx->dev_type;
141 /* prepare the private state for this connection */
142 ipriv = talloc(ntvfs, struct ipc_private);
143 NT_STATUS_HAVE_NO_MEMORY(ipriv);
145 ntvfs->private_data = ipriv;
147 ipriv->ntvfs = ntvfs;
148 ipriv->pipe_list = NULL;
154 disconnect from a share
156 static NTSTATUS ipc_disconnect(struct ntvfs_module_context *ntvfs)
164 static NTSTATUS ipc_unlink(struct ntvfs_module_context *ntvfs,
165 struct ntvfs_request *req,
166 union smb_unlink *unl)
168 return NT_STATUS_ACCESS_DENIED;
172 check if a directory exists
174 static NTSTATUS ipc_chkpath(struct ntvfs_module_context *ntvfs,
175 struct ntvfs_request *req,
176 union smb_chkpath *cp)
178 return NT_STATUS_ACCESS_DENIED;
182 return info on a pathname
184 static NTSTATUS ipc_qpathinfo(struct ntvfs_module_context *ntvfs,
185 struct ntvfs_request *req, union smb_fileinfo *info)
187 switch (info->generic.level) {
188 case RAW_FILEINFO_GENERIC:
189 return NT_STATUS_INVALID_DEVICE_REQUEST;
190 case RAW_FILEINFO_GETATTR:
191 return NT_STATUS_ACCESS_DENIED;
193 return ntvfs_map_qpathinfo(ntvfs, req, info);
198 set info on a pathname
200 static NTSTATUS ipc_setpathinfo(struct ntvfs_module_context *ntvfs,
201 struct ntvfs_request *req, union smb_setfileinfo *st)
203 return NT_STATUS_ACCESS_DENIED;
208 destroy a open pipe structure
210 static int ipc_fd_destructor(struct pipe_state *p)
212 DLIST_REMOVE(p->ipriv->pipe_list, p);
213 ntvfs_handle_remove_backend_data(p->handle, p->ipriv->ntvfs);
217 struct ipc_open_state {
218 struct ipc_private *ipriv;
219 struct pipe_state *p;
220 struct ntvfs_request *req;
222 struct auth_session_info_transport *session_info_transport;
225 static void ipc_open_done(struct tevent_req *subreq);
228 check the pipename is valid
230 static NTSTATUS validate_pipename(const char *name)
233 if (!isalnum(*name) && *name != '_') {
234 return NT_STATUS_INVALID_PARAMETER;
242 open a file - used for MSRPC pipes
244 static NTSTATUS ipc_open(struct ntvfs_module_context *ntvfs,
245 struct ntvfs_request *req, union smb_open *oi)
248 struct pipe_state *p;
249 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
251 struct ntvfs_handle *h;
252 struct ipc_open_state *state;
253 struct tevent_req *subreq;
255 const char *directory;
256 const struct tsocket_address *remote_client_addr;
257 const struct tsocket_address *local_server_addr;
259 switch (oi->generic.level) {
260 case RAW_OPEN_NTCREATEX:
261 case RAW_OPEN_NTTRANS_CREATE:
262 fname = oi->ntcreatex.in.fname;
263 while (fname[0] == '\\') fname++;
266 fname = oi->openx.in.fname;
267 while (fname[0] == '\\') fname++;
268 if (strncasecmp(fname, "PIPE\\", 5) != 0) {
269 return NT_STATUS_OBJECT_PATH_SYNTAX_BAD;
271 while (fname[0] == '\\') fname++;
274 fname = oi->smb2.in.fname;
277 return NT_STATUS_NOT_SUPPORTED;
280 directory = talloc_asprintf(req, "%s/np",
281 lpcfg_ncalrpc_dir(ipriv->ntvfs->ctx->lp_ctx));
282 NT_STATUS_HAVE_NO_MEMORY(directory);
284 state = talloc(req, struct ipc_open_state);
285 NT_STATUS_HAVE_NO_MEMORY(state);
287 status = ntvfs_handle_new(ntvfs, req, &h);
288 NT_STATUS_NOT_OK_RETURN(status);
290 p = talloc(h, struct pipe_state);
291 NT_STATUS_HAVE_NO_MEMORY(p);
293 /* check for valid characters in name */
294 fname = strlower_talloc(p, fname);
296 status = validate_pipename(fname);
297 NT_STATUS_NOT_OK_RETURN(status);
299 p->pipe_name = talloc_asprintf(p, "\\pipe\\%s", fname);
300 NT_STATUS_HAVE_NO_MEMORY(p->pipe_name);
305 p->write_queue = tevent_queue_create(p, "ipc_write_queue");
306 NT_STATUS_HAVE_NO_MEMORY(p->write_queue);
308 p->read_queue = tevent_queue_create(p, "ipc_read_queue");
309 NT_STATUS_HAVE_NO_MEMORY(p->read_queue);
311 state->ipriv = ipriv;
316 status = auth_session_info_transport_from_session(state,
318 ipriv->ntvfs->ctx->event_ctx,
319 ipriv->ntvfs->ctx->lp_ctx,
320 &state->session_info_transport);
322 NT_STATUS_NOT_OK_RETURN(status);
324 local_server_addr = ntvfs_get_local_address(ipriv->ntvfs);
325 remote_client_addr = ntvfs_get_remote_address(ipriv->ntvfs);
327 subreq = tstream_npa_connect_send(p,
328 ipriv->ntvfs->ctx->event_ctx,
335 state->session_info_transport);
336 NT_STATUS_HAVE_NO_MEMORY(subreq);
337 tevent_req_set_callback(subreq, ipc_open_done, state);
339 req->async_states->state |= NTVFS_ASYNC_STATE_ASYNC;
343 static void ipc_open_done(struct tevent_req *subreq)
345 struct ipc_open_state *state = tevent_req_callback_data(subreq,
346 struct ipc_open_state);
347 struct ipc_private *ipriv = state->ipriv;
348 struct pipe_state *p = state->p;
349 struct ntvfs_request *req = state->req;
350 union smb_open *oi = state->oi;
355 ret = tstream_npa_connect_recv(subreq, &sys_errno,
359 &p->allocation_size);
362 status = map_nt_error_from_unix_common(sys_errno);
366 DLIST_ADD(ipriv->pipe_list, p);
367 talloc_set_destructor(p, ipc_fd_destructor);
369 status = ntvfs_handle_set_backend_data(p->handle, ipriv->ntvfs, p);
370 if (!NT_STATUS_IS_OK(status)) {
374 switch (oi->generic.level) {
375 case RAW_OPEN_NTCREATEX:
376 ZERO_STRUCT(oi->ntcreatex.out);
377 oi->ntcreatex.out.file.ntvfs = p->handle;
378 oi->ntcreatex.out.oplock_level = 0;
379 oi->ntcreatex.out.create_action = NTCREATEX_ACTION_EXISTED;
380 oi->ntcreatex.out.create_time = 0;
381 oi->ntcreatex.out.access_time = 0;
382 oi->ntcreatex.out.write_time = 0;
383 oi->ntcreatex.out.change_time = 0;
384 oi->ntcreatex.out.attrib = FILE_ATTRIBUTE_NORMAL;
385 oi->ntcreatex.out.alloc_size = p->allocation_size;
386 oi->ntcreatex.out.size = 0;
387 oi->ntcreatex.out.file_type = p->file_type;
388 oi->ntcreatex.out.ipc_state = p->device_state;
389 oi->ntcreatex.out.is_directory = 0;
392 ZERO_STRUCT(oi->openx.out);
393 oi->openx.out.file.ntvfs = p->handle;
394 oi->openx.out.attrib = FILE_ATTRIBUTE_NORMAL;
395 oi->openx.out.write_time = 0;
396 oi->openx.out.size = 0;
397 oi->openx.out.access = 0;
398 oi->openx.out.ftype = p->file_type;
399 oi->openx.out.devstate = p->device_state;
400 oi->openx.out.action = 0;
401 oi->openx.out.unique_fid = 0;
402 oi->openx.out.access_mask = 0;
403 oi->openx.out.unknown = 0;
406 ZERO_STRUCT(oi->smb2.out);
407 oi->smb2.out.file.ntvfs = p->handle;
408 oi->smb2.out.oplock_level = oi->smb2.in.oplock_level;
409 oi->smb2.out.create_action = NTCREATEX_ACTION_EXISTED;
410 oi->smb2.out.create_time = 0;
411 oi->smb2.out.access_time = 0;
412 oi->smb2.out.write_time = 0;
413 oi->smb2.out.change_time = 0;
414 oi->smb2.out.alloc_size = p->allocation_size;
415 oi->smb2.out.size = 0;
416 oi->smb2.out.file_attr = FILE_ATTRIBUTE_NORMAL;
417 oi->smb2.out.reserved2 = 0;
424 req->async_states->status = status;
425 req->async_states->send_fn(req);
431 static NTSTATUS ipc_mkdir(struct ntvfs_module_context *ntvfs,
432 struct ntvfs_request *req, union smb_mkdir *md)
434 return NT_STATUS_ACCESS_DENIED;
440 static NTSTATUS ipc_rmdir(struct ntvfs_module_context *ntvfs,
441 struct ntvfs_request *req, struct smb_rmdir *rd)
443 return NT_STATUS_ACCESS_DENIED;
447 rename a set of files
449 static NTSTATUS ipc_rename(struct ntvfs_module_context *ntvfs,
450 struct ntvfs_request *req, union smb_rename *ren)
452 return NT_STATUS_ACCESS_DENIED;
458 static NTSTATUS ipc_copy(struct ntvfs_module_context *ntvfs,
459 struct ntvfs_request *req, struct smb_copy *cp)
461 return NT_STATUS_ACCESS_DENIED;
464 struct ipc_readv_next_vector_state {
471 static void ipc_readv_next_vector_init(struct ipc_readv_next_vector_state *s,
472 uint8_t *buf, size_t len)
477 s->len = MIN(len, UINT16_MAX);
480 static int ipc_readv_next_vector(struct tstream_context *stream,
483 struct iovec **_vector,
486 struct ipc_readv_next_vector_state *state =
487 (struct ipc_readv_next_vector_state *)private_data;
488 struct iovec *vector;
492 if (state->ofs == state->len) {
498 pending = tstream_pending_bytes(stream);
503 if (pending == 0 && state->ofs != 0) {
504 /* return a short read */
511 /* we want at least one byte and recheck again */
514 size_t missing = state->len - state->ofs;
515 if (pending > missing) {
516 /* there's more available */
517 state->remaining = pending - missing;
520 /* read what we can get and recheck in the next cycle */
525 vector = talloc_array(mem_ctx, struct iovec, 1);
530 vector[0].iov_base = (char *) (state->buf + state->ofs);
531 vector[0].iov_len = wanted;
533 state->ofs += wanted;
540 struct ipc_read_state {
541 struct ipc_private *ipriv;
542 struct pipe_state *p;
543 struct ntvfs_request *req;
545 struct ipc_readv_next_vector_state next_vector;
548 static void ipc_read_done(struct tevent_req *subreq);
553 static NTSTATUS ipc_read(struct ntvfs_module_context *ntvfs,
554 struct ntvfs_request *req, union smb_read *rd)
556 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
558 struct pipe_state *p;
559 struct ipc_read_state *state;
560 struct tevent_req *subreq;
562 if (rd->generic.level != RAW_READ_GENERIC) {
563 return ntvfs_map_read(ntvfs, req, rd);
566 p = pipe_state_find(ipriv, rd->readx.in.file.ntvfs);
568 return NT_STATUS_INVALID_HANDLE;
571 state = talloc(req, struct ipc_read_state);
572 NT_STATUS_HAVE_NO_MEMORY(state);
574 state->ipriv = ipriv;
579 /* rd->readx.out.data is already allocated */
580 ipc_readv_next_vector_init(&state->next_vector,
582 rd->readx.in.maxcnt);
584 subreq = tstream_readv_pdu_queue_send(req,
585 ipriv->ntvfs->ctx->event_ctx,
588 ipc_readv_next_vector,
589 &state->next_vector);
590 NT_STATUS_HAVE_NO_MEMORY(subreq);
591 tevent_req_set_callback(subreq, ipc_read_done, state);
593 req->async_states->state |= NTVFS_ASYNC_STATE_ASYNC;
597 static void ipc_read_done(struct tevent_req *subreq)
599 struct ipc_read_state *state =
600 tevent_req_callback_data(subreq,
601 struct ipc_read_state);
602 struct ntvfs_request *req = state->req;
603 union smb_read *rd = state->rd;
608 ret = tstream_readv_pdu_queue_recv(subreq, &sys_errno);
611 status = map_nt_error_from_unix_common(sys_errno);
615 status = NT_STATUS_OK;
616 if (state->next_vector.remaining > 0) {
617 status = STATUS_BUFFER_OVERFLOW;
620 rd->readx.out.remaining = state->next_vector.remaining;
621 rd->readx.out.compaction_mode = 0;
622 rd->readx.out.nread = ret;
625 req->async_states->status = status;
626 req->async_states->send_fn(req);
629 struct ipc_write_state {
630 struct ipc_private *ipriv;
631 struct pipe_state *p;
632 struct ntvfs_request *req;
637 static void ipc_write_done(struct tevent_req *subreq);
642 static NTSTATUS ipc_write(struct ntvfs_module_context *ntvfs,
643 struct ntvfs_request *req, union smb_write *wr)
645 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
647 struct pipe_state *p;
648 struct tevent_req *subreq;
649 struct ipc_write_state *state;
651 if (wr->generic.level != RAW_WRITE_GENERIC) {
652 return ntvfs_map_write(ntvfs, req, wr);
655 p = pipe_state_find(ipriv, wr->writex.in.file.ntvfs);
657 return NT_STATUS_INVALID_HANDLE;
660 state = talloc(req, struct ipc_write_state);
661 NT_STATUS_HAVE_NO_MEMORY(state);
663 state->ipriv = ipriv;
667 state->iov.iov_base = discard_const_p(void, wr->writex.in.data);
668 state->iov.iov_len = wr->writex.in.count;
670 subreq = tstream_writev_queue_send(state,
671 ipriv->ntvfs->ctx->event_ctx,
675 NT_STATUS_HAVE_NO_MEMORY(subreq);
676 tevent_req_set_callback(subreq, ipc_write_done, state);
678 req->async_states->state |= NTVFS_ASYNC_STATE_ASYNC;
682 static void ipc_write_done(struct tevent_req *subreq)
684 struct ipc_write_state *state =
685 tevent_req_callback_data(subreq,
686 struct ipc_write_state);
687 struct ntvfs_request *req = state->req;
688 union smb_write *wr = state->wr;
693 ret = tstream_writev_queue_recv(subreq, &sys_errno);
696 status = map_nt_error_from_unix_common(sys_errno);
700 status = NT_STATUS_OK;
702 wr->writex.out.nwritten = ret;
703 wr->writex.out.remaining = 0;
706 req->async_states->status = status;
707 req->async_states->send_fn(req);
713 static NTSTATUS ipc_seek(struct ntvfs_module_context *ntvfs,
714 struct ntvfs_request *req,
717 return NT_STATUS_ACCESS_DENIED;
723 static NTSTATUS ipc_flush(struct ntvfs_module_context *ntvfs,
724 struct ntvfs_request *req,
727 return NT_STATUS_ACCESS_DENIED;
733 static NTSTATUS ipc_close(struct ntvfs_module_context *ntvfs,
734 struct ntvfs_request *req, union smb_close *io)
736 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
738 struct pipe_state *p;
740 if (io->generic.level != RAW_CLOSE_GENERIC) {
741 return ntvfs_map_close(ntvfs, req, io);
744 ZERO_STRUCT(io->generic.out);
746 p = pipe_state_find(ipriv, io->generic.in.file.ntvfs);
748 return NT_STATUS_INVALID_HANDLE;
759 static NTSTATUS ipc_exit(struct ntvfs_module_context *ntvfs,
760 struct ntvfs_request *req)
762 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
764 struct pipe_state *p, *next;
766 for (p=ipriv->pipe_list; p; p=next) {
768 if (p->handle->session_info == req->session_info &&
769 p->handle->smbpid == req->smbpid) {
778 logoff - closing files open by the user
780 static NTSTATUS ipc_logoff(struct ntvfs_module_context *ntvfs,
781 struct ntvfs_request *req)
783 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
785 struct pipe_state *p, *next;
787 for (p=ipriv->pipe_list; p; p=next) {
789 if (p->handle->session_info == req->session_info) {
798 setup for an async call
800 static NTSTATUS ipc_async_setup(struct ntvfs_module_context *ntvfs,
801 struct ntvfs_request *req,
810 static NTSTATUS ipc_cancel(struct ntvfs_module_context *ntvfs,
811 struct ntvfs_request *req)
813 return NT_STATUS_UNSUCCESSFUL;
819 static NTSTATUS ipc_lock(struct ntvfs_module_context *ntvfs,
820 struct ntvfs_request *req, union smb_lock *lck)
822 return NT_STATUS_ACCESS_DENIED;
826 set info on a open file
828 static NTSTATUS ipc_setfileinfo(struct ntvfs_module_context *ntvfs,
829 struct ntvfs_request *req, union smb_setfileinfo *info)
831 return NT_STATUS_ACCESS_DENIED;
835 query info on a open file
837 static NTSTATUS ipc_qfileinfo(struct ntvfs_module_context *ntvfs,
838 struct ntvfs_request *req, union smb_fileinfo *info)
840 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
842 struct pipe_state *p = pipe_state_find(ipriv, info->generic.in.file.ntvfs);
844 return NT_STATUS_INVALID_HANDLE;
846 switch (info->generic.level) {
847 case RAW_FILEINFO_GENERIC:
849 ZERO_STRUCT(info->generic.out);
850 info->generic.out.attrib = FILE_ATTRIBUTE_NORMAL;
851 info->generic.out.fname.s = strrchr(p->pipe_name, '\\');
852 info->generic.out.alloc_size = 4096;
853 info->generic.out.nlink = 1;
854 /* What the heck? Match Win2k3: IPC$ pipes are delete pending */
855 info->generic.out.delete_pending = 1;
858 case RAW_FILEINFO_ALT_NAME_INFO:
859 case RAW_FILEINFO_ALT_NAME_INFORMATION:
860 case RAW_FILEINFO_STREAM_INFO:
861 case RAW_FILEINFO_STREAM_INFORMATION:
862 case RAW_FILEINFO_COMPRESSION_INFO:
863 case RAW_FILEINFO_COMPRESSION_INFORMATION:
864 case RAW_FILEINFO_NETWORK_OPEN_INFORMATION:
865 case RAW_FILEINFO_ATTRIBUTE_TAG_INFORMATION:
866 return NT_STATUS_INVALID_PARAMETER;
867 case RAW_FILEINFO_ALL_EAS:
868 return NT_STATUS_ACCESS_DENIED;
870 return ntvfs_map_qfileinfo(ntvfs, req, info);
876 return filesystem info
878 static NTSTATUS ipc_fsinfo(struct ntvfs_module_context *ntvfs,
879 struct ntvfs_request *req, union smb_fsinfo *fs)
881 return NT_STATUS_ACCESS_DENIED;
885 return print queue info
887 static NTSTATUS ipc_lpq(struct ntvfs_module_context *ntvfs,
888 struct ntvfs_request *req, union smb_lpq *lpq)
890 return NT_STATUS_ACCESS_DENIED;
894 list files in a directory matching a wildcard pattern
896 static NTSTATUS ipc_search_first(struct ntvfs_module_context *ntvfs,
897 struct ntvfs_request *req, union smb_search_first *io,
898 void *search_private,
899 bool (*callback)(void *, const union smb_search_data *))
901 return NT_STATUS_ACCESS_DENIED;
905 continue listing files in a directory
907 static NTSTATUS ipc_search_next(struct ntvfs_module_context *ntvfs,
908 struct ntvfs_request *req, union smb_search_next *io,
909 void *search_private,
910 bool (*callback)(void *, const union smb_search_data *))
912 return NT_STATUS_ACCESS_DENIED;
916 end listing files in a directory
918 static NTSTATUS ipc_search_close(struct ntvfs_module_context *ntvfs,
919 struct ntvfs_request *req, union smb_search_close *io)
921 return NT_STATUS_ACCESS_DENIED;
924 struct ipc_trans_state {
925 struct ipc_private *ipriv;
926 struct pipe_state *p;
927 struct ntvfs_request *req;
928 struct smb_trans2 *trans;
929 struct iovec writev_iov;
930 struct ipc_readv_next_vector_state next_vector;
933 static void ipc_trans_writev_done(struct tevent_req *subreq);
934 static void ipc_trans_readv_done(struct tevent_req *subreq);
936 /* SMBtrans - handle a DCERPC command */
937 static NTSTATUS ipc_dcerpc_cmd(struct ntvfs_module_context *ntvfs,
938 struct ntvfs_request *req, struct smb_trans2 *trans)
940 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
942 struct pipe_state *p;
945 struct ipc_trans_state *state;
946 struct tevent_req *subreq;
949 * the fnum is in setup[1], a 16 bit value
950 * the setup[*] values are already in host byteorder
951 * but ntvfs_handle_search_by_wire_key() expects
954 SSVAL(&fnum, 0, trans->in.setup[1]);
955 fnum_key = data_blob_const(&fnum, 2);
957 p = pipe_state_find_key(ipriv, req, &fnum_key);
959 return NT_STATUS_INVALID_HANDLE;
963 * Trans requests are only allowed
964 * if no other Trans or Read is active
966 if (tevent_queue_length(p->read_queue) > 0) {
967 return NT_STATUS_PIPE_BUSY;
970 state = talloc(req, struct ipc_trans_state);
971 NT_STATUS_HAVE_NO_MEMORY(state);
973 trans->out.setup_count = 0;
974 trans->out.setup = NULL;
975 trans->out.params = data_blob(NULL, 0);
976 trans->out.data = data_blob_talloc(req, NULL, trans->in.max_data);
977 NT_STATUS_HAVE_NO_MEMORY(trans->out.data.data);
979 state->ipriv = ipriv;
982 state->trans = trans;
983 state->writev_iov.iov_base = (char *) trans->in.data.data;
984 state->writev_iov.iov_len = trans->in.data.length;
986 ipc_readv_next_vector_init(&state->next_vector,
987 trans->out.data.data,
988 trans->out.data.length);
990 subreq = tstream_writev_queue_send(state,
991 ipriv->ntvfs->ctx->event_ctx,
994 &state->writev_iov, 1);
995 NT_STATUS_HAVE_NO_MEMORY(subreq);
996 tevent_req_set_callback(subreq, ipc_trans_writev_done, state);
998 req->async_states->state |= NTVFS_ASYNC_STATE_ASYNC;
1002 static void ipc_trans_writev_done(struct tevent_req *subreq)
1004 struct ipc_trans_state *state =
1005 tevent_req_callback_data(subreq,
1006 struct ipc_trans_state);
1007 struct ipc_private *ipriv = state->ipriv;
1008 struct pipe_state *p = state->p;
1009 struct ntvfs_request *req = state->req;
1014 ret = tstream_writev_queue_recv(subreq, &sys_errno);
1015 TALLOC_FREE(subreq);
1017 status = NT_STATUS_PIPE_DISCONNECTED;
1019 } else if (ret == -1) {
1020 status = map_nt_error_from_unix_common(sys_errno);
1024 subreq = tstream_readv_pdu_queue_send(state,
1025 ipriv->ntvfs->ctx->event_ctx,
1028 ipc_readv_next_vector,
1029 &state->next_vector);
1031 status = NT_STATUS_NO_MEMORY;
1034 tevent_req_set_callback(subreq, ipc_trans_readv_done, state);
1038 req->async_states->status = status;
1039 req->async_states->send_fn(req);
1042 static void ipc_trans_readv_done(struct tevent_req *subreq)
1044 struct ipc_trans_state *state =
1045 tevent_req_callback_data(subreq,
1046 struct ipc_trans_state);
1047 struct ntvfs_request *req = state->req;
1048 struct smb_trans2 *trans = state->trans;
1053 ret = tstream_readv_pdu_queue_recv(subreq, &sys_errno);
1054 TALLOC_FREE(subreq);
1056 status = map_nt_error_from_unix_common(sys_errno);
1060 status = NT_STATUS_OK;
1061 if (state->next_vector.remaining > 0) {
1062 status = STATUS_BUFFER_OVERFLOW;
1065 trans->out.data.length = ret;
1068 req->async_states->status = status;
1069 req->async_states->send_fn(req);
1072 /* SMBtrans - set named pipe state */
1073 static NTSTATUS ipc_set_nm_pipe_state(struct ntvfs_module_context *ntvfs,
1074 struct ntvfs_request *req, struct smb_trans2 *trans)
1076 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
1077 struct ipc_private);
1078 struct pipe_state *p;
1081 /* the fnum is in setup[1] */
1082 fnum_key = data_blob_const(&trans->in.setup[1], sizeof(trans->in.setup[1]));
1084 p = pipe_state_find_key(ipriv, req, &fnum_key);
1086 return NT_STATUS_INVALID_HANDLE;
1089 if (trans->in.params.length != 2) {
1090 return NT_STATUS_INVALID_PARAMETER;
1094 * TODO: pass this to the tstream_npa logic
1096 p->device_state = SVAL(trans->in.params.data, 0);
1098 trans->out.setup_count = 0;
1099 trans->out.setup = NULL;
1100 trans->out.params = data_blob(NULL, 0);
1101 trans->out.data = data_blob(NULL, 0);
1103 return NT_STATUS_OK;
1107 /* SMBtrans - used to provide access to SMB pipes */
1108 static NTSTATUS ipc_trans(struct ntvfs_module_context *ntvfs,
1109 struct ntvfs_request *req, struct smb_trans2 *trans)
1113 if (strequal(trans->in.trans_name, "\\PIPE\\LANMAN"))
1114 return ipc_rap_call(req, ntvfs->ctx->event_ctx, ntvfs->ctx->lp_ctx, trans);
1116 if (trans->in.setup_count != 2) {
1117 return NT_STATUS_INVALID_PARAMETER;
1120 switch (trans->in.setup[0]) {
1121 case TRANSACT_SETNAMEDPIPEHANDLESTATE:
1122 status = ipc_set_nm_pipe_state(ntvfs, req, trans);
1124 case TRANSACT_DCERPCCMD:
1125 status = ipc_dcerpc_cmd(ntvfs, req, trans);
1128 status = NT_STATUS_INVALID_PARAMETER;
1135 struct ipc_ioctl_state {
1136 struct ipc_private *ipriv;
1137 struct pipe_state *p;
1138 struct ntvfs_request *req;
1139 union smb_ioctl *io;
1140 struct iovec writev_iov;
1141 struct ipc_readv_next_vector_state next_vector;
1144 static void ipc_ioctl_writev_done(struct tevent_req *subreq);
1145 static void ipc_ioctl_readv_done(struct tevent_req *subreq);
1147 static NTSTATUS ipc_ioctl_smb2(struct ntvfs_module_context *ntvfs,
1148 struct ntvfs_request *req, union smb_ioctl *io)
1150 struct ipc_private *ipriv = talloc_get_type_abort(ntvfs->private_data,
1151 struct ipc_private);
1152 struct pipe_state *p;
1153 struct ipc_ioctl_state *state;
1154 struct tevent_req *subreq;
1156 switch (io->smb2.in.function) {
1157 case FSCTL_NAMED_PIPE_READ_WRITE:
1161 return NT_STATUS_FS_DRIVER_REQUIRED;
1164 p = pipe_state_find(ipriv, io->smb2.in.file.ntvfs);
1166 return NT_STATUS_INVALID_HANDLE;
1170 * Trans requests are only allowed
1171 * if no other Trans or Read is active
1173 if (tevent_queue_length(p->read_queue) > 0) {
1174 return NT_STATUS_PIPE_BUSY;
1177 state = talloc(req, struct ipc_ioctl_state);
1178 NT_STATUS_HAVE_NO_MEMORY(state);
1180 io->smb2.out._pad = 0;
1181 io->smb2.out.function = io->smb2.in.function;
1182 io->smb2.out.unknown2 = 0;
1183 io->smb2.out.unknown3 = 0;
1184 io->smb2.out.in = data_blob_null;
1185 io->smb2.out.out = data_blob_talloc(req, NULL, io->smb2.in.max_response_size);
1186 NT_STATUS_HAVE_NO_MEMORY(io->smb2.out.out.data);
1188 state->ipriv = ipriv;
1192 state->writev_iov.iov_base = (char *) io->smb2.in.out.data;
1193 state->writev_iov.iov_len = io->smb2.in.out.length;
1195 ipc_readv_next_vector_init(&state->next_vector,
1196 io->smb2.out.out.data,
1197 io->smb2.out.out.length);
1199 subreq = tstream_writev_queue_send(state,
1200 ipriv->ntvfs->ctx->event_ctx,
1203 &state->writev_iov, 1);
1204 NT_STATUS_HAVE_NO_MEMORY(subreq);
1205 tevent_req_set_callback(subreq, ipc_ioctl_writev_done, state);
1207 req->async_states->state |= NTVFS_ASYNC_STATE_ASYNC;
1208 return NT_STATUS_OK;
1211 static void ipc_ioctl_writev_done(struct tevent_req *subreq)
1213 struct ipc_ioctl_state *state =
1214 tevent_req_callback_data(subreq,
1215 struct ipc_ioctl_state);
1216 struct ipc_private *ipriv = state->ipriv;
1217 struct pipe_state *p = state->p;
1218 struct ntvfs_request *req = state->req;
1223 ret = tstream_writev_queue_recv(subreq, &sys_errno);
1224 TALLOC_FREE(subreq);
1226 status = map_nt_error_from_unix_common(sys_errno);
1230 subreq = tstream_readv_pdu_queue_send(state,
1231 ipriv->ntvfs->ctx->event_ctx,
1234 ipc_readv_next_vector,
1235 &state->next_vector);
1237 status = NT_STATUS_NO_MEMORY;
1240 tevent_req_set_callback(subreq, ipc_ioctl_readv_done, state);
1244 req->async_states->status = status;
1245 req->async_states->send_fn(req);
1248 static void ipc_ioctl_readv_done(struct tevent_req *subreq)
1250 struct ipc_ioctl_state *state =
1251 tevent_req_callback_data(subreq,
1252 struct ipc_ioctl_state);
1253 struct ntvfs_request *req = state->req;
1254 union smb_ioctl *io = state->io;
1259 ret = tstream_readv_pdu_queue_recv(subreq, &sys_errno);
1260 TALLOC_FREE(subreq);
1262 status = map_nt_error_from_unix_common(sys_errno);
1266 status = NT_STATUS_OK;
1267 if (state->next_vector.remaining > 0) {
1268 status = STATUS_BUFFER_OVERFLOW;
1271 io->smb2.out.out.length = ret;
1274 req->async_states->status = status;
1275 req->async_states->send_fn(req);
1281 static NTSTATUS ipc_ioctl(struct ntvfs_module_context *ntvfs,
1282 struct ntvfs_request *req, union smb_ioctl *io)
1284 switch (io->generic.level) {
1285 case RAW_IOCTL_SMB2:
1286 return ipc_ioctl_smb2(ntvfs, req, io);
1288 case RAW_IOCTL_SMB2_NO_HANDLE:
1289 return NT_STATUS_FS_DRIVER_REQUIRED;
1292 return NT_STATUS_ACCESS_DENIED;
1298 initialialise the IPC backend, registering ourselves with the ntvfs subsystem
1300 NTSTATUS ntvfs_ipc_init(TALLOC_CTX *ctx)
1303 struct ntvfs_ops ops;
1304 NTVFS_CURRENT_CRITICAL_SIZES(vers);
1308 /* fill in the name and type */
1309 ops.name = "default";
1310 ops.type = NTVFS_IPC;
1312 /* fill in all the operations */
1313 ops.connect_fn = ipc_connect;
1314 ops.disconnect_fn = ipc_disconnect;
1315 ops.unlink_fn = ipc_unlink;
1316 ops.chkpath_fn = ipc_chkpath;
1317 ops.qpathinfo_fn = ipc_qpathinfo;
1318 ops.setpathinfo_fn = ipc_setpathinfo;
1319 ops.open_fn = ipc_open;
1320 ops.mkdir_fn = ipc_mkdir;
1321 ops.rmdir_fn = ipc_rmdir;
1322 ops.rename_fn = ipc_rename;
1323 ops.copy_fn = ipc_copy;
1324 ops.ioctl_fn = ipc_ioctl;
1325 ops.read_fn = ipc_read;
1326 ops.write_fn = ipc_write;
1327 ops.seek_fn = ipc_seek;
1328 ops.flush_fn = ipc_flush;
1329 ops.close_fn = ipc_close;
1330 ops.exit_fn = ipc_exit;
1331 ops.lock_fn = ipc_lock;
1332 ops.setfileinfo_fn = ipc_setfileinfo;
1333 ops.qfileinfo_fn = ipc_qfileinfo;
1334 ops.fsinfo_fn = ipc_fsinfo;
1335 ops.lpq_fn = ipc_lpq;
1336 ops.search_first_fn = ipc_search_first;
1337 ops.search_next_fn = ipc_search_next;
1338 ops.search_close_fn = ipc_search_close;
1339 ops.trans_fn = ipc_trans;
1340 ops.logoff_fn = ipc_logoff;
1341 ops.async_setup_fn = ipc_async_setup;
1342 ops.cancel_fn = ipc_cancel;
1344 /* register ourselves with the NTVFS subsystem. */
1345 ret = ntvfs_register(&ops, &vers);
1347 if (!NT_STATUS_IS_OK(ret)) {
1348 DEBUG(0,("Failed to register IPC backend!\n"));