s3-talloc Change TALLOC_ARRAY() to talloc_array()
[samba.git] / source3 / libsmb / clirap.c
1 /*
2    Unix SMB/CIFS implementation.
3    client RAP calls
4    Copyright (C) Andrew Tridgell         1994-1998
5    Copyright (C) Gerald (Jerry) Carter   2004
6    Copyright (C) James Peach             2007
7
8    This program is free software; you can redistribute it and/or modify
9    it under the terms of the GNU General Public License as published by
10    the Free Software Foundation; either version 3 of the License, or
11    (at your option) any later version.
12
13    This program is distributed in the hope that it will be useful,
14    but WITHOUT ANY WARRANTY; without even the implied warranty of
15    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16    GNU General Public License for more details.
17
18    You should have received a copy of the GNU General Public License
19    along with this program.  If not, see <http://www.gnu.org/licenses/>.
20 */
21
22 #include "includes.h"
23 #include "../libcli/auth/libcli_auth.h"
24 #include "../librpc/gen_ndr/rap.h"
25 #include "../lib/crypto/arcfour.h"
26 #include "../lib/util/tevent_ntstatus.h"
27 #include "async_smb.h"
28 #include "libsmb/libsmb.h"
29 #include "libsmb/clirap.h"
30 #include "trans2.h"
31
32 #define PIPE_LANMAN   "\\PIPE\\LANMAN"
33
34 /****************************************************************************
35  Call a remote api
36 ****************************************************************************/
37
38 bool cli_api(struct cli_state *cli,
39              char *param, int prcnt, int mprcnt,
40              char *data, int drcnt, int mdrcnt,
41              char **rparam, unsigned int *rprcnt,
42              char **rdata, unsigned int *rdrcnt)
43 {
44         NTSTATUS status;
45
46         uint8_t *my_rparam, *my_rdata;
47         uint32_t num_my_rparam, num_my_rdata;
48
49         status = cli_trans(talloc_tos(), cli, SMBtrans,
50                            PIPE_LANMAN, 0, /* name, fid */
51                            0, 0,           /* function, flags */
52                            NULL, 0, 0,     /* setup */
53                            (uint8_t *)param, prcnt, mprcnt, /* Params, length, max */
54                            (uint8_t *)data, drcnt, mdrcnt,  /* Data, length, max */
55                            NULL,                 /* recv_flags2 */
56                            NULL, 0, NULL,        /* rsetup */
57                            &my_rparam, 0, &num_my_rparam,
58                            &my_rdata, 0, &num_my_rdata);
59         if (!NT_STATUS_IS_OK(status)) {
60                 return false;
61         }
62
63         /*
64          * I know this memcpy massively hurts, but there are just tons
65          * of callers of cli_api that eventually need changing to
66          * talloc
67          */
68
69         *rparam = (char *)memdup(my_rparam, num_my_rparam);
70         if (*rparam == NULL) {
71                 goto fail;
72         }
73         *rprcnt = num_my_rparam;
74         TALLOC_FREE(my_rparam);
75
76         *rdata = (char *)memdup(my_rdata, num_my_rdata);
77         if (*rdata == NULL) {
78                 goto fail;
79         }
80         *rdrcnt = num_my_rdata;
81         TALLOC_FREE(my_rdata);
82
83         return true;
84 fail:
85         TALLOC_FREE(my_rdata);
86         TALLOC_FREE(my_rparam);
87         *rparam = NULL;
88         *rprcnt = 0;
89         *rdata = NULL;
90         *rdrcnt = 0;
91         return false;
92 }
93
94 /****************************************************************************
95  Perform a NetWkstaUserLogon.
96 ****************************************************************************/
97
98 bool cli_NetWkstaUserLogon(struct cli_state *cli,char *user, char *workstation)
99 {
100         char *rparam = NULL;
101         char *rdata = NULL;
102         char *p;
103         unsigned int rdrcnt,rprcnt;
104         char param[1024];
105
106         memset(param, 0, sizeof(param));
107
108         /* send a SMBtrans command with api NetWkstaUserLogon */
109         p = param;
110         SSVAL(p,0,132); /* api number */
111         p += 2;
112         strlcpy(p,"OOWb54WrLh",sizeof(param)-PTR_DIFF(p,param));
113         p = skip_string(param,sizeof(param),p);
114         strlcpy(p,"WB21BWDWWDDDDDDDzzzD",sizeof(param)-PTR_DIFF(p,param));
115         p = skip_string(param,sizeof(param),p);
116         SSVAL(p,0,1);
117         p += 2;
118         strlcpy(p,user,sizeof(param)-PTR_DIFF(p,param));
119         strupper_m(p);
120         p += 21;
121         p++;
122         p += 15;
123         p++;
124         strlcpy(p, workstation,sizeof(param)-PTR_DIFF(p,param));
125         strupper_m(p);
126         p += 16;
127         SSVAL(p, 0, CLI_BUFFER_SIZE);
128         p += 2;
129         SSVAL(p, 0, CLI_BUFFER_SIZE);
130         p += 2;
131
132         if (cli_api(cli,
133                     param, PTR_DIFF(p,param),1024,  /* param, length, max */
134                     NULL, 0, CLI_BUFFER_SIZE,           /* data, length, max */
135                     &rparam, &rprcnt,               /* return params, return size */
136                     &rdata, &rdrcnt                 /* return data, return size */
137                    )) {
138                 cli->rap_error = rparam? SVAL(rparam,0) : -1;
139                 p = rdata;
140
141                 if (cli->rap_error == 0) {
142                         DEBUG(4,("NetWkstaUserLogon success\n"));
143                         cli->privileges = SVAL(p, 24);
144                         /* The cli->eff_name field used to be set here
145                            but it wasn't used anywhere else. */
146                 } else {
147                         DEBUG(1,("NetwkstaUserLogon gave error %d\n", cli->rap_error));
148                 }
149         }
150
151         SAFE_FREE(rparam);
152         SAFE_FREE(rdata);
153         return (cli->rap_error == 0);
154 }
155
156 /****************************************************************************
157  Call a NetShareEnum - try and browse available connections on a host.
158 ****************************************************************************/
159
160 int cli_RNetShareEnum(struct cli_state *cli, void (*fn)(const char *, uint32, const char *, void *), void *state)
161 {
162         char *rparam = NULL;
163         char *rdata = NULL;
164         char *p;
165         unsigned int rdrcnt,rprcnt;
166         char param[1024];
167         int count = -1;
168
169         /* now send a SMBtrans command with api RNetShareEnum */
170         p = param;
171         SSVAL(p,0,0); /* api number */
172         p += 2;
173         strlcpy(p,"WrLeh",sizeof(param)-PTR_DIFF(p,param));
174         p = skip_string(param,sizeof(param),p);
175         strlcpy(p,"B13BWz",sizeof(param)-PTR_DIFF(p,param));
176         p = skip_string(param,sizeof(param),p);
177         SSVAL(p,0,1);
178         /*
179          * Win2k needs a *smaller* buffer than 0xFFFF here -
180          * it returns "out of server memory" with 0xFFFF !!! JRA.
181          */
182         SSVAL(p,2,0xFFE0);
183         p += 4;
184
185         if (cli_api(cli,
186                     param, PTR_DIFF(p,param), 1024,  /* Param, length, maxlen */
187                     NULL, 0, 0xFFE0,            /* data, length, maxlen - Win2k needs a small buffer here too ! */
188                     &rparam, &rprcnt,                /* return params, length */
189                     &rdata, &rdrcnt))                /* return data, length */
190                 {
191                         int res = rparam? SVAL(rparam,0) : -1;
192
193                         if (res == 0 || res == ERRmoredata) {
194                                 int converter=SVAL(rparam,2);
195                                 int i;
196                                 char *rdata_end = rdata + rdrcnt;
197
198                                 count=SVAL(rparam,4);
199                                 p = rdata;
200
201                                 for (i=0;i<count;i++,p+=20) {
202                                         char *sname;
203                                         int type;
204                                         int comment_offset;
205                                         const char *cmnt;
206                                         const char *p1;
207                                         char *s1, *s2;
208                                         size_t len;
209                                         TALLOC_CTX *frame = talloc_stackframe();
210
211                                         if (p + 20 > rdata_end) {
212                                                 TALLOC_FREE(frame);
213                                                 break;
214                                         }
215
216                                         sname = p;
217                                         type = SVAL(p,14);
218                                         comment_offset = (IVAL(p,16) & 0xFFFF) - converter;
219                                         if (comment_offset < 0 ||
220                                                         comment_offset > (int)rdrcnt) {
221                                                 TALLOC_FREE(frame);
222                                                 break;
223                                         }
224                                         cmnt = comment_offset?(rdata+comment_offset):"";
225
226                                         /* Work out the comment length. */
227                                         for (p1 = cmnt, len = 0; *p1 &&
228                                                         p1 < rdata_end; len++)
229                                                 p1++;
230                                         if (!*p1) {
231                                                 len++;
232                                         }
233                                         pull_string_talloc(frame,rdata,0,
234                                                 &s1,sname,14,STR_ASCII);
235                                         pull_string_talloc(frame,rdata,0,
236                                                 &s2,cmnt,len,STR_ASCII);
237                                         if (!s1 || !s2) {
238                                                 TALLOC_FREE(frame);
239                                                 continue;
240                                         }
241
242                                         fn(s1, type, s2, state);
243
244                                         TALLOC_FREE(frame);
245                                 }
246                         } else {
247                                 DEBUG(4,("NetShareEnum res=%d\n", res));
248                         }
249                 } else {
250                         DEBUG(4,("NetShareEnum failed\n"));
251                 }
252
253         SAFE_FREE(rparam);
254         SAFE_FREE(rdata);
255
256         return count;
257 }
258
259 /****************************************************************************
260  Call a NetServerEnum for the specified workgroup and servertype mask.  This
261  function then calls the specified callback function for each name returned.
262
263  The callback function takes 4 arguments: the machine name, the server type,
264  the comment and a state pointer.
265 ****************************************************************************/
266
267 bool cli_NetServerEnum(struct cli_state *cli, char *workgroup, uint32 stype,
268                        void (*fn)(const char *, uint32, const char *, void *),
269                        void *state)
270 {
271         char *rparam = NULL;
272         char *rdata = NULL;
273         char *rdata_end = NULL;
274         unsigned int rdrcnt,rprcnt;
275         char *p;
276         char param[1024];
277         int uLevel = 1;
278         size_t len;
279         uint32 func = RAP_NetServerEnum2;
280         char *last_entry = NULL;
281         int total_cnt = 0;
282         int return_cnt = 0;
283         int res;
284
285         errno = 0; /* reset */
286
287         /*
288          * This may take more than one transaction, so we should loop until
289          * we no longer get a more data to process or we have all of the
290          * items.
291          */
292         do {
293                 /* send a SMBtrans command with api NetServerEnum */
294                 p = param;
295                 SIVAL(p,0,func); /* api number */
296                 p += 2;
297
298                 if (func == RAP_NetServerEnum3) {
299                         strlcpy(p,"WrLehDzz", sizeof(param)-PTR_DIFF(p,param));
300                 } else {
301                         strlcpy(p,"WrLehDz", sizeof(param)-PTR_DIFF(p,param));
302                 }
303
304                 p = skip_string(param, sizeof(param), p);
305                 strlcpy(p,"B16BBDz", sizeof(param)-PTR_DIFF(p,param));
306
307                 p = skip_string(param, sizeof(param), p);
308                 SSVAL(p,0,uLevel);
309                 SSVAL(p,2,CLI_BUFFER_SIZE);
310                 p += 4;
311                 SIVAL(p,0,stype);
312                 p += 4;
313
314                 /* If we have more data, tell the server where
315                  * to continue from.
316                  */
317                 len = push_ascii(p,
318                                 workgroup,
319                                 sizeof(param) - PTR_DIFF(p,param) - 1,
320                                 STR_TERMINATE|STR_UPPER);
321
322                 if (len == (size_t)-1) {
323                         SAFE_FREE(last_entry);
324                         return false;
325                 }
326                 p += len;
327
328                 if (func == RAP_NetServerEnum3) {
329                         len = push_ascii(p,
330                                         last_entry ? last_entry : "",
331                                         sizeof(param) - PTR_DIFF(p,param) - 1,
332                                         STR_TERMINATE);
333
334                         if (len == (size_t)-1) {
335                                 SAFE_FREE(last_entry);
336                                 return false;
337                         }
338                         p += len;
339                 }
340
341                 /* Next time through we need to use the continue api */
342                 func = RAP_NetServerEnum3;
343
344                 if (!cli_api(cli,
345                         param, PTR_DIFF(p,param), 8, /* params, length, max */
346                         NULL, 0, CLI_BUFFER_SIZE, /* data, length, max */
347                             &rparam, &rprcnt, /* return params, return size */
348                             &rdata, &rdrcnt)) { /* return data, return size */
349
350                         /* break out of the loop on error */
351                         res = -1;
352                         break;
353                 }
354
355                 rdata_end = rdata + rdrcnt;
356                 res = rparam ? SVAL(rparam,0) : -1;
357
358                 if (res == 0 || res == ERRmoredata ||
359                     (res != -1 && cli_errno(cli) == 0)) {
360                         char *sname = NULL;
361                         int i, count;
362                         int converter=SVAL(rparam,2);
363
364                         /* Get the number of items returned in this buffer */
365                         count = SVAL(rparam, 4);
366
367                         /* The next field contains the number of items left,
368                          * including those returned in this buffer. So the
369                          * first time through this should contain all of the
370                          * entries.
371                          */
372                         if (total_cnt == 0) {
373                                 total_cnt = SVAL(rparam, 6);
374                         }
375
376                         /* Keep track of how many we have read */
377                         return_cnt += count;
378                         p = rdata;
379
380                         /* The last name in the previous NetServerEnum reply is
381                          * sent back to server in the NetServerEnum3 request
382                          * (last_entry). The next reply should repeat this entry
383                          * as the first element. We have no proof that this is
384                          * always true, but from traces that seems to be the
385                          * behavior from Window Servers. So first lets do a lot
386                          * of checking, just being paranoid. If the string
387                          * matches then we already saw this entry so skip it.
388                          *
389                          * NOTE: sv1_name field must be null terminated and has
390                          * a max size of 16 (NetBIOS Name).
391                          */
392                         if (last_entry && count && p &&
393                                 (strncmp(last_entry, p, 16) == 0)) {
394                             count -= 1; /* Skip this entry */
395                             return_cnt = -1; /* Not part of total, so don't count. */
396                             p = rdata + 26; /* Skip the whole record */
397                         }
398
399                         for (i = 0; i < count; i++, p += 26) {
400                                 int comment_offset;
401                                 const char *cmnt;
402                                 const char *p1;
403                                 char *s1, *s2;
404                                 TALLOC_CTX *frame = talloc_stackframe();
405                                 uint32_t entry_stype;
406
407                                 if (p + 26 > rdata_end) {
408                                         TALLOC_FREE(frame);
409                                         break;
410                                 }
411
412                                 sname = p;
413                                 comment_offset = (IVAL(p,22) & 0xFFFF)-converter;
414                                 cmnt = comment_offset?(rdata+comment_offset):"";
415
416                                 if (comment_offset < 0 || comment_offset >= (int)rdrcnt) {
417                                         TALLOC_FREE(frame);
418                                         continue;
419                                 }
420
421                                 /* Work out the comment length. */
422                                 for (p1 = cmnt, len = 0; *p1 &&
423                                                 p1 < rdata_end; len++)
424                                         p1++;
425                                 if (!*p1) {
426                                         len++;
427                                 }
428
429                                 entry_stype = IVAL(p,18) & ~SV_TYPE_LOCAL_LIST_ONLY;
430
431                                 pull_string_talloc(frame,rdata,0,
432                                         &s1,sname,16,STR_ASCII);
433                                 pull_string_talloc(frame,rdata,0,
434                                         &s2,cmnt,len,STR_ASCII);
435
436                                 if (!s1 || !s2) {
437                                         TALLOC_FREE(frame);
438                                         continue;
439                                 }
440
441                                 fn(s1, entry_stype, s2, state);
442                                 TALLOC_FREE(frame);
443                         }
444
445                         /* We are done with the old last entry, so now we can free it */
446                         if (last_entry) {
447                                 SAFE_FREE(last_entry); /* This will set it to null */
448                         }
449
450                         /* We always make a copy of  the last entry if we have one */
451                         if (sname) {
452                                 last_entry = smb_xstrdup(sname);
453                         }
454
455                         /* If we have more data, but no last entry then error out */
456                         if (!last_entry && (res == ERRmoredata)) {
457                                 errno = EINVAL;
458                                 res = 0;
459                         }
460
461                 }
462
463                 SAFE_FREE(rparam);
464                 SAFE_FREE(rdata);
465         } while ((res == ERRmoredata) && (total_cnt > return_cnt));
466
467         SAFE_FREE(rparam);
468         SAFE_FREE(rdata);
469         SAFE_FREE(last_entry);
470
471         if (res == -1) {
472                 errno = cli_errno(cli);
473         } else {
474                 if (!return_cnt) {
475                         /* this is a very special case, when the domain master for the
476                            work group isn't part of the work group itself, there is something
477                            wild going on */
478                         errno = ENOENT;
479                 }
480             }
481
482         return(return_cnt > 0);
483 }
484
485 /****************************************************************************
486  Send a SamOEMChangePassword command.
487 ****************************************************************************/
488
489 bool cli_oem_change_password(struct cli_state *cli, const char *user, const char *new_password,
490                              const char *old_password)
491 {
492         char param[1024];
493         unsigned char data[532];
494         char *p = param;
495         unsigned char old_pw_hash[16];
496         unsigned char new_pw_hash[16];
497         unsigned int data_len;
498         unsigned int param_len = 0;
499         char *rparam = NULL;
500         char *rdata = NULL;
501         unsigned int rprcnt, rdrcnt;
502
503         if (strlen(user) >= sizeof(fstring)-1) {
504                 DEBUG(0,("cli_oem_change_password: user name %s is too long.\n", user));
505                 return False;
506         }
507
508         SSVAL(p,0,214); /* SamOEMChangePassword command. */
509         p += 2;
510         strlcpy(p, "zsT", sizeof(param)-PTR_DIFF(p,param));
511         p = skip_string(param,sizeof(param),p);
512         strlcpy(p, "B516B16", sizeof(param)-PTR_DIFF(p,param));
513         p = skip_string(param,sizeof(param),p);
514         strlcpy(p,user, sizeof(param)-PTR_DIFF(p,param));
515         p = skip_string(param,sizeof(param),p);
516         SSVAL(p,0,532);
517         p += 2;
518
519         param_len = PTR_DIFF(p,param);
520
521         /*
522          * Get the Lanman hash of the old password, we
523          * use this as the key to make_oem_passwd_hash().
524          */
525         E_deshash(old_password, old_pw_hash);
526
527         encode_pw_buffer(data, new_password, STR_ASCII);
528
529 #ifdef DEBUG_PASSWORD
530         DEBUG(100,("make_oem_passwd_hash\n"));
531         dump_data(100, data, 516);
532 #endif
533         arcfour_crypt( (unsigned char *)data, (unsigned char *)old_pw_hash, 516);
534
535         /*
536          * Now place the old password hash in the data.
537          */
538         E_deshash(new_password, new_pw_hash);
539
540         E_old_pw_hash( new_pw_hash, old_pw_hash, (uchar *)&data[516]);
541
542         data_len = 532;
543
544         if (!cli_api(cli,
545                      param, param_len, 4,               /* param, length, max */
546                      (char *)data, data_len, 0,         /* data, length, max */
547                      &rparam, &rprcnt,
548                      &rdata, &rdrcnt)) {
549                 DEBUG(0,("cli_oem_change_password: Failed to send password change for user %s\n",
550                         user ));
551                 return False;
552         }
553
554         if (rparam) {
555                 cli->rap_error = SVAL(rparam,0);
556         }
557
558         SAFE_FREE(rparam);
559         SAFE_FREE(rdata);
560
561         return (cli->rap_error == 0);
562 }
563
564 /****************************************************************************
565  Send a qpathinfo call.
566 ****************************************************************************/
567
568 struct cli_qpathinfo1_state {
569         struct cli_state *cli;
570         uint32_t num_data;
571         uint8_t *data;
572 };
573
574 static void cli_qpathinfo1_done(struct tevent_req *subreq);
575
576 struct tevent_req *cli_qpathinfo1_send(TALLOC_CTX *mem_ctx,
577                                        struct event_context *ev,
578                                        struct cli_state *cli,
579                                        const char *fname)
580 {
581         struct tevent_req *req = NULL, *subreq = NULL;
582         struct cli_qpathinfo1_state *state = NULL;
583
584         req = tevent_req_create(mem_ctx, &state, struct cli_qpathinfo1_state);
585         if (req == NULL) {
586                 return NULL;
587         }
588         state->cli = cli;
589         subreq = cli_qpathinfo_send(state, ev, cli, fname, SMB_INFO_STANDARD,
590                                     22, cli->max_xmit);
591         if (tevent_req_nomem(subreq, req)) {
592                 return tevent_req_post(req, ev);
593         }
594         tevent_req_set_callback(subreq, cli_qpathinfo1_done, req);
595         return req;
596 }
597
598 static void cli_qpathinfo1_done(struct tevent_req *subreq)
599 {
600         struct tevent_req *req = tevent_req_callback_data(
601                 subreq, struct tevent_req);
602         struct cli_qpathinfo1_state *state = tevent_req_data(
603                 req, struct cli_qpathinfo1_state);
604         NTSTATUS status;
605
606         status = cli_qpathinfo_recv(subreq, state, &state->data,
607                                     &state->num_data);
608         TALLOC_FREE(subreq);
609         if (!NT_STATUS_IS_OK(status)) {
610                 tevent_req_nterror(req, status);
611                 return;
612         }
613         tevent_req_done(req);
614 }
615
616 NTSTATUS cli_qpathinfo1_recv(struct tevent_req *req,
617                              time_t *change_time,
618                              time_t *access_time,
619                              time_t *write_time,
620                              SMB_OFF_T *size,
621                              uint16 *mode)
622 {
623         struct cli_qpathinfo1_state *state = tevent_req_data(
624                 req, struct cli_qpathinfo1_state);
625         NTSTATUS status;
626
627         time_t (*date_fn)(const void *buf, int serverzone);
628
629         if (tevent_req_is_nterror(req, &status)) {
630                 return status;
631         }
632
633         if (state->cli->win95) {
634                 date_fn = make_unix_date;
635         } else {
636                 date_fn = make_unix_date2;
637         }
638
639         if (change_time) {
640                 *change_time = date_fn(state->data+0, state->cli->serverzone);
641         }
642         if (access_time) {
643                 *access_time = date_fn(state->data+4, state->cli->serverzone);
644         }
645         if (write_time) {
646                 *write_time = date_fn(state->data+8, state->cli->serverzone);
647         }
648         if (size) {
649                 *size = IVAL(state->data, 12);
650         }
651         if (mode) {
652                 *mode = SVAL(state->data, l1_attrFile);
653         }
654         return NT_STATUS_OK;
655 }
656
657 NTSTATUS cli_qpathinfo1(struct cli_state *cli,
658                         const char *fname,
659                         time_t *change_time,
660                         time_t *access_time,
661                         time_t *write_time,
662                         SMB_OFF_T *size,
663                         uint16 *mode)
664 {
665         TALLOC_CTX *frame = talloc_stackframe();
666         struct event_context *ev;
667         struct tevent_req *req;
668         NTSTATUS status = NT_STATUS_NO_MEMORY;
669
670         if (cli_has_async_calls(cli)) {
671                 /*
672                  * Can't use sync call while an async call is in flight
673                  */
674                 status = NT_STATUS_INVALID_PARAMETER;
675                 goto fail;
676         }
677         ev = event_context_init(frame);
678         if (ev == NULL) {
679                 goto fail;
680         }
681         req = cli_qpathinfo1_send(frame, ev, cli, fname);
682         if (req == NULL) {
683                 goto fail;
684         }
685         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
686                 goto fail;
687         }
688         status = cli_qpathinfo1_recv(req, change_time, access_time,
689                                      write_time, size, mode);
690  fail:
691         TALLOC_FREE(frame);
692         return status;
693 }
694
695 /****************************************************************************
696  Send a setpathinfo call.
697 ****************************************************************************/
698
699 NTSTATUS cli_setpathinfo_basic(struct cli_state *cli, const char *fname,
700                                time_t create_time,
701                                time_t access_time,
702                                time_t write_time,
703                                time_t change_time,
704                                uint16 mode)
705 {
706         unsigned int data_len = 0;
707         char data[40];
708         char *p;
709
710         p = data;
711
712         /*
713          * Add the create, last access, modification, and status change times
714          */
715         put_long_date(p, create_time);
716         p += 8;
717
718         put_long_date(p, access_time);
719         p += 8;
720
721         put_long_date(p, write_time);
722         p += 8;
723
724         put_long_date(p, change_time);
725         p += 8;
726
727         /* Add attributes */
728         SIVAL(p, 0, mode);
729         p += 4;
730
731         /* Add padding */
732         SIVAL(p, 0, 0);
733         p += 4;
734
735         data_len = PTR_DIFF(p, data);
736
737         return cli_setpathinfo(cli, SMB_FILE_BASIC_INFORMATION, fname,
738                                (uint8_t *)data, data_len);
739 }
740
741 /****************************************************************************
742  Send a qpathinfo call with the SMB_QUERY_FILE_ALL_INFO info level.
743 ****************************************************************************/
744
745 struct cli_qpathinfo2_state {
746         uint32_t num_data;
747         uint8_t *data;
748 };
749
750 static void cli_qpathinfo2_done(struct tevent_req *subreq);
751
752 struct tevent_req *cli_qpathinfo2_send(TALLOC_CTX *mem_ctx,
753                                        struct event_context *ev,
754                                        struct cli_state *cli,
755                                        const char *fname)
756 {
757         struct tevent_req *req = NULL, *subreq = NULL;
758         struct cli_qpathinfo2_state *state = NULL;
759
760         req = tevent_req_create(mem_ctx, &state, struct cli_qpathinfo2_state);
761         if (req == NULL) {
762                 return NULL;
763         }
764         subreq = cli_qpathinfo_send(state, ev, cli, fname,
765                                     SMB_QUERY_FILE_ALL_INFO,
766                                     68, cli->max_xmit);
767         if (tevent_req_nomem(subreq, req)) {
768                 return tevent_req_post(req, ev);
769         }
770         tevent_req_set_callback(subreq, cli_qpathinfo2_done, req);
771         return req;
772 }
773
774 static void cli_qpathinfo2_done(struct tevent_req *subreq)
775 {
776         struct tevent_req *req = tevent_req_callback_data(
777                 subreq, struct tevent_req);
778         struct cli_qpathinfo2_state *state = tevent_req_data(
779                 req, struct cli_qpathinfo2_state);
780         NTSTATUS status;
781
782         status = cli_qpathinfo_recv(subreq, state, &state->data,
783                                     &state->num_data);
784         TALLOC_FREE(subreq);
785         if (!NT_STATUS_IS_OK(status)) {
786                 tevent_req_nterror(req, status);
787                 return;
788         }
789         tevent_req_done(req);
790 }
791
792 NTSTATUS cli_qpathinfo2_recv(struct tevent_req *req,
793                              struct timespec *create_time,
794                              struct timespec *access_time,
795                              struct timespec *write_time,
796                              struct timespec *change_time,
797                              SMB_OFF_T *size, uint16 *mode,
798                              SMB_INO_T *ino)
799 {
800         struct cli_qpathinfo2_state *state = tevent_req_data(
801                 req, struct cli_qpathinfo2_state);
802         NTSTATUS status;
803
804         if (tevent_req_is_nterror(req, &status)) {
805                 return status;
806         }
807
808         if (create_time) {
809                 *create_time = interpret_long_date((char *)state->data+0);
810         }
811         if (access_time) {
812                 *access_time = interpret_long_date((char *)state->data+8);
813         }
814         if (write_time) {
815                 *write_time = interpret_long_date((char *)state->data+16);
816         }
817         if (change_time) {
818                 *change_time = interpret_long_date((char *)state->data+24);
819         }
820         if (mode) {
821                 *mode = SVAL(state->data, 32);
822         }
823         if (size) {
824                 *size = IVAL2_TO_SMB_BIG_UINT(state->data,48);
825         }
826         if (ino) {
827                 *ino = IVAL(state->data, 64);
828         }
829         return NT_STATUS_OK;
830 }
831
832 NTSTATUS cli_qpathinfo2(struct cli_state *cli, const char *fname,
833                         struct timespec *create_time,
834                         struct timespec *access_time,
835                         struct timespec *write_time,
836                         struct timespec *change_time,
837                         SMB_OFF_T *size, uint16 *mode,
838                         SMB_INO_T *ino)
839 {
840         TALLOC_CTX *frame = talloc_stackframe();
841         struct event_context *ev;
842         struct tevent_req *req;
843         NTSTATUS status = NT_STATUS_NO_MEMORY;
844
845         if (cli_has_async_calls(cli)) {
846                 /*
847                  * Can't use sync call while an async call is in flight
848                  */
849                 status = NT_STATUS_INVALID_PARAMETER;
850                 goto fail;
851         }
852         ev = event_context_init(frame);
853         if (ev == NULL) {
854                 goto fail;
855         }
856         req = cli_qpathinfo2_send(frame, ev, cli, fname);
857         if (req == NULL) {
858                 goto fail;
859         }
860         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
861                 goto fail;
862         }
863         status = cli_qpathinfo2_recv(req, create_time, access_time,
864                                      write_time, change_time, size, mode, ino);
865  fail:
866         TALLOC_FREE(frame);
867         return status;
868 }
869
870 /****************************************************************************
871  Get the stream info
872 ****************************************************************************/
873
874 static bool parse_streams_blob(TALLOC_CTX *mem_ctx, const uint8_t *data,
875                                size_t data_len,
876                                unsigned int *pnum_streams,
877                                struct stream_struct **pstreams);
878
879 struct cli_qpathinfo_streams_state {
880         uint32_t num_data;
881         uint8_t *data;
882 };
883
884 static void cli_qpathinfo_streams_done(struct tevent_req *subreq);
885
886 struct tevent_req *cli_qpathinfo_streams_send(TALLOC_CTX *mem_ctx,
887                                               struct tevent_context *ev,
888                                               struct cli_state *cli,
889                                               const char *fname)
890 {
891         struct tevent_req *req = NULL, *subreq = NULL;
892         struct cli_qpathinfo_streams_state *state = NULL;
893
894         req = tevent_req_create(mem_ctx, &state,
895                                 struct cli_qpathinfo_streams_state);
896         if (req == NULL) {
897                 return NULL;
898         }
899         subreq = cli_qpathinfo_send(state, ev, cli, fname,
900                                     SMB_FILE_STREAM_INFORMATION,
901                                     0, cli->max_xmit);
902         if (tevent_req_nomem(subreq, req)) {
903                 return tevent_req_post(req, ev);
904         }
905         tevent_req_set_callback(subreq, cli_qpathinfo_streams_done, req);
906         return req;
907 }
908
909 static void cli_qpathinfo_streams_done(struct tevent_req *subreq)
910 {
911         struct tevent_req *req = tevent_req_callback_data(
912                 subreq, struct tevent_req);
913         struct cli_qpathinfo_streams_state *state = tevent_req_data(
914                 req, struct cli_qpathinfo_streams_state);
915         NTSTATUS status;
916
917         status = cli_qpathinfo_recv(subreq, state, &state->data,
918                                     &state->num_data);
919         TALLOC_FREE(subreq);
920         if (!NT_STATUS_IS_OK(status)) {
921                 tevent_req_nterror(req, status);
922                 return;
923         }
924         tevent_req_done(req);
925 }
926
927 NTSTATUS cli_qpathinfo_streams_recv(struct tevent_req *req,
928                                     TALLOC_CTX *mem_ctx,
929                                     unsigned int *pnum_streams,
930                                     struct stream_struct **pstreams)
931 {
932         struct cli_qpathinfo_streams_state *state = tevent_req_data(
933                 req, struct cli_qpathinfo_streams_state);
934         NTSTATUS status;
935
936         if (tevent_req_is_nterror(req, &status)) {
937                 return status;
938         }
939         if (!parse_streams_blob(mem_ctx, state->data, state->num_data,
940                                 pnum_streams, pstreams)) {
941                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
942         }
943         return NT_STATUS_OK;
944 }
945
946 NTSTATUS cli_qpathinfo_streams(struct cli_state *cli, const char *fname,
947                                TALLOC_CTX *mem_ctx,
948                                unsigned int *pnum_streams,
949                                struct stream_struct **pstreams)
950 {
951         TALLOC_CTX *frame = talloc_stackframe();
952         struct event_context *ev;
953         struct tevent_req *req;
954         NTSTATUS status = NT_STATUS_NO_MEMORY;
955
956         if (cli_has_async_calls(cli)) {
957                 /*
958                  * Can't use sync call while an async call is in flight
959                  */
960                 status = NT_STATUS_INVALID_PARAMETER;
961                 goto fail;
962         }
963         ev = event_context_init(frame);
964         if (ev == NULL) {
965                 goto fail;
966         }
967         req = cli_qpathinfo_streams_send(frame, ev, cli, fname);
968         if (req == NULL) {
969                 goto fail;
970         }
971         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
972                 goto fail;
973         }
974         status = cli_qpathinfo_streams_recv(req, mem_ctx, pnum_streams,
975                                             pstreams);
976  fail:
977         TALLOC_FREE(frame);
978         return status;
979 }
980
981 static bool parse_streams_blob(TALLOC_CTX *mem_ctx, const uint8_t *rdata,
982                                size_t data_len,
983                                unsigned int *pnum_streams,
984                                struct stream_struct **pstreams)
985 {
986         unsigned int num_streams;
987         struct stream_struct *streams;
988         unsigned int ofs;
989
990         num_streams = 0;
991         streams = NULL;
992         ofs = 0;
993
994         while ((data_len > ofs) && (data_len - ofs >= 24)) {
995                 uint32_t nlen, len;
996                 size_t size;
997                 void *vstr;
998                 struct stream_struct *tmp;
999                 uint8_t *tmp_buf;
1000
1001                 tmp = talloc_realloc(mem_ctx, streams,
1002                                            struct stream_struct,
1003                                            num_streams+1);
1004
1005                 if (tmp == NULL) {
1006                         goto fail;
1007                 }
1008                 streams = tmp;
1009
1010                 nlen                      = IVAL(rdata, ofs + 0x04);
1011
1012                 streams[num_streams].size = IVAL_TO_SMB_OFF_T(
1013                         rdata, ofs + 0x08);
1014                 streams[num_streams].alloc_size = IVAL_TO_SMB_OFF_T(
1015                         rdata, ofs + 0x10);
1016
1017                 if (nlen > data_len - (ofs + 24)) {
1018                         goto fail;
1019                 }
1020
1021                 /*
1022                  * We need to null-terminate src, how do I do this with
1023                  * convert_string_talloc??
1024                  */
1025
1026                 tmp_buf = talloc_array(streams, uint8_t, nlen+2);
1027                 if (tmp_buf == NULL) {
1028                         goto fail;
1029                 }
1030
1031                 memcpy(tmp_buf, rdata+ofs+24, nlen);
1032                 tmp_buf[nlen] = 0;
1033                 tmp_buf[nlen+1] = 0;
1034
1035                 if (!convert_string_talloc(streams, CH_UTF16, CH_UNIX, tmp_buf,
1036                                            nlen+2, &vstr, &size))
1037                 {
1038                         TALLOC_FREE(tmp_buf);
1039                         goto fail;
1040                 }
1041
1042                 TALLOC_FREE(tmp_buf);
1043                 streams[num_streams].name = (char *)vstr;
1044                 num_streams++;
1045
1046                 len = IVAL(rdata, ofs);
1047                 if (len > data_len - ofs) {
1048                         goto fail;
1049                 }
1050                 if (len == 0) break;
1051                 ofs += len;
1052         }
1053
1054         *pnum_streams = num_streams;
1055         *pstreams = streams;
1056         return true;
1057
1058  fail:
1059         TALLOC_FREE(streams);
1060         return false;
1061 }
1062
1063 /****************************************************************************
1064  Send a qfileinfo QUERY_FILE_NAME_INFO call.
1065 ****************************************************************************/
1066
1067 NTSTATUS cli_qfilename(struct cli_state *cli, uint16_t fnum, char *name,
1068                        size_t namelen)
1069 {
1070         uint8_t *rdata;
1071         uint32_t num_rdata;
1072         NTSTATUS status;
1073
1074         status = cli_qfileinfo(talloc_tos(), cli, fnum,
1075                                SMB_QUERY_FILE_NAME_INFO,
1076                                4, cli->max_xmit,
1077                                &rdata, &num_rdata);
1078         if (!NT_STATUS_IS_OK(status)) {
1079                 return status;
1080         }
1081
1082         clistr_pull((const char *)rdata, name, rdata+4, namelen, IVAL(rdata, 0),
1083                     STR_UNICODE);
1084         TALLOC_FREE(rdata);
1085         return NT_STATUS_OK;
1086 }
1087
1088 /****************************************************************************
1089  Send a qfileinfo call.
1090 ****************************************************************************/
1091
1092 NTSTATUS cli_qfileinfo_basic(struct cli_state *cli, uint16_t fnum,
1093                              uint16 *mode, SMB_OFF_T *size,
1094                              struct timespec *create_time,
1095                              struct timespec *access_time,
1096                              struct timespec *write_time,
1097                              struct timespec *change_time,
1098                              SMB_INO_T *ino)
1099 {
1100         uint8_t *rdata;
1101         uint32_t num_rdata;
1102         NTSTATUS status;
1103
1104         /* if its a win95 server then fail this - win95 totally screws it
1105            up */
1106         if (cli->win95) {
1107                 return NT_STATUS_NOT_SUPPORTED;
1108         }
1109
1110         status = cli_qfileinfo(talloc_tos(), cli, fnum,
1111                                SMB_QUERY_FILE_ALL_INFO,
1112                                68, MIN(cli->max_xmit, 0xffff),
1113                                &rdata, &num_rdata);
1114         if (!NT_STATUS_IS_OK(status)) {
1115                 return status;
1116         }
1117
1118         if (create_time) {
1119                 *create_time = interpret_long_date((char *)rdata+0);
1120         }
1121         if (access_time) {
1122                 *access_time = interpret_long_date((char *)rdata+8);
1123         }
1124         if (write_time) {
1125                 *write_time = interpret_long_date((char *)rdata+16);
1126         }
1127         if (change_time) {
1128                 *change_time = interpret_long_date((char *)rdata+24);
1129         }
1130         if (mode) {
1131                 *mode = SVAL(rdata, 32);
1132         }
1133         if (size) {
1134                 *size = IVAL2_TO_SMB_BIG_UINT(rdata,48);
1135         }
1136         if (ino) {
1137                 *ino = IVAL(rdata, 64);
1138         }
1139
1140         TALLOC_FREE(rdata);
1141         return NT_STATUS_OK;
1142 }
1143
1144 /****************************************************************************
1145  Send a qpathinfo BASIC_INFO call.
1146 ****************************************************************************/
1147
1148 struct cli_qpathinfo_basic_state {
1149         uint32_t num_data;
1150         uint8_t *data;
1151 };
1152
1153 static void cli_qpathinfo_basic_done(struct tevent_req *subreq);
1154
1155 struct tevent_req *cli_qpathinfo_basic_send(TALLOC_CTX *mem_ctx,
1156                                             struct event_context *ev,
1157                                             struct cli_state *cli,
1158                                             const char *fname)
1159 {
1160         struct tevent_req *req = NULL, *subreq = NULL;
1161         struct cli_qpathinfo_basic_state *state = NULL;
1162
1163         req = tevent_req_create(mem_ctx, &state,
1164                                 struct cli_qpathinfo_basic_state);
1165         if (req == NULL) {
1166                 return NULL;
1167         }
1168         subreq = cli_qpathinfo_send(state, ev, cli, fname,
1169                                     SMB_QUERY_FILE_BASIC_INFO,
1170                                     36, cli->max_xmit);
1171         if (tevent_req_nomem(subreq, req)) {
1172                 return tevent_req_post(req, ev);
1173         }
1174         tevent_req_set_callback(subreq, cli_qpathinfo_basic_done, req);
1175         return req;
1176 }
1177
1178 static void cli_qpathinfo_basic_done(struct tevent_req *subreq)
1179 {
1180         struct tevent_req *req = tevent_req_callback_data(
1181                 subreq, struct tevent_req);
1182         struct cli_qpathinfo_basic_state *state = tevent_req_data(
1183                 req, struct cli_qpathinfo_basic_state);
1184         NTSTATUS status;
1185
1186         status = cli_qpathinfo_recv(subreq, state, &state->data,
1187                                     &state->num_data);
1188         TALLOC_FREE(subreq);
1189         if (!NT_STATUS_IS_OK(status)) {
1190                 tevent_req_nterror(req, status);
1191                 return;
1192         }
1193         tevent_req_done(req);
1194 }
1195
1196 NTSTATUS cli_qpathinfo_basic_recv(struct tevent_req *req,
1197                                   SMB_STRUCT_STAT *sbuf, uint32 *attributes)
1198 {
1199         struct cli_qpathinfo_basic_state *state = tevent_req_data(
1200                 req, struct cli_qpathinfo_basic_state);
1201         NTSTATUS status;
1202
1203         if (tevent_req_is_nterror(req, &status)) {
1204                 return status;
1205         }
1206
1207         sbuf->st_ex_atime = interpret_long_date((char *)state->data+8);
1208         sbuf->st_ex_mtime = interpret_long_date((char *)state->data+16);
1209         sbuf->st_ex_ctime = interpret_long_date((char *)state->data+24);
1210         *attributes = IVAL(state->data, 32);
1211         return NT_STATUS_OK;
1212 }
1213
1214 NTSTATUS cli_qpathinfo_basic(struct cli_state *cli, const char *name,
1215                              SMB_STRUCT_STAT *sbuf, uint32 *attributes)
1216 {
1217         TALLOC_CTX *frame = talloc_stackframe();
1218         struct event_context *ev;
1219         struct tevent_req *req;
1220         NTSTATUS status = NT_STATUS_NO_MEMORY;
1221
1222         if (cli_has_async_calls(cli)) {
1223                 /*
1224                  * Can't use sync call while an async call is in flight
1225                  */
1226                 status = NT_STATUS_INVALID_PARAMETER;
1227                 goto fail;
1228         }
1229         ev = event_context_init(frame);
1230         if (ev == NULL) {
1231                 goto fail;
1232         }
1233         req = cli_qpathinfo_basic_send(frame, ev, cli, name);
1234         if (req == NULL) {
1235                 goto fail;
1236         }
1237         if (!tevent_req_poll_ntstatus(req, ev, &status)) {
1238                 goto fail;
1239         }
1240         status = cli_qpathinfo_basic_recv(req, sbuf, attributes);
1241  fail:
1242         TALLOC_FREE(frame);
1243         return status;
1244 }
1245
1246 /****************************************************************************
1247  Send a qpathinfo SMB_QUERY_FILE_ALT_NAME_INFO call.
1248 ****************************************************************************/
1249
1250 NTSTATUS cli_qpathinfo_alt_name(struct cli_state *cli, const char *fname, fstring alt_name)
1251 {
1252         uint8_t *rdata;
1253         uint32_t num_rdata;
1254         unsigned int len;
1255         char *converted = NULL;
1256         size_t converted_size = 0;
1257         NTSTATUS status;
1258
1259         status = cli_qpathinfo(talloc_tos(), cli, fname,
1260                                SMB_QUERY_FILE_ALT_NAME_INFO,
1261                                4, cli->max_xmit, &rdata, &num_rdata);
1262         if (!NT_STATUS_IS_OK(status)) {
1263                 return status;
1264         }
1265
1266         len = IVAL(rdata, 0);
1267
1268         if (len > num_rdata - 4) {
1269                 return NT_STATUS_INVALID_NETWORK_RESPONSE;
1270         }
1271
1272         /* The returned data is a pushed string, not raw data. */
1273         if (!convert_string_talloc(talloc_tos(),
1274                                    cli_ucs2(cli) ? CH_UTF16LE : CH_DOS,
1275                                    CH_UNIX,
1276                                    rdata + 4,
1277                                    len,
1278                                    &converted,
1279                                    &converted_size)) {
1280                 return NT_STATUS_NO_MEMORY;
1281         }
1282         fstrcpy(alt_name, converted);
1283
1284         TALLOC_FREE(converted);
1285         TALLOC_FREE(rdata);
1286
1287         return NT_STATUS_OK;
1288 }