- nt4 doesn't setup the pfc flags correctly for rpc packet types
other than normal requests, so don't check for fragmented packets
unless they are of type request
- ensure we give STATUS_BUFFER_OVERFLOW when we return a partial
fragment in SMBtrans requests on ncacn_np
(This used to be commit
83ebffec3215c58c5cebf1a7c9a58904854203c8)
dce_partial_advance(dce_conn, blob.length);
/* see if this is a continued packet */
dce_partial_advance(dce_conn, blob.length);
/* see if this is a continued packet */
- if (!(call->pkt.pfc_flags & DCERPC_PFC_FLAG_FIRST)) {
+ if (call->pkt.ptype == DCERPC_PKT_REQUEST &&
+ !(call->pkt.pfc_flags & DCERPC_PFC_FLAG_FIRST)) {
struct dcesrv_call_state *call2 = call;
uint32_t alloc_size;
struct dcesrv_call_state *call2 = call;
uint32_t alloc_size;
/* this may not be the last pdu in the chain - if its isn't then
just put it on the call_list and wait for the rest */
/* this may not be the last pdu in the chain - if its isn't then
just put it on the call_list and wait for the rest */
- if (!(call->pkt.pfc_flags & DCERPC_PFC_FLAG_LAST)) {
+ if (call->pkt.ptype == DCERPC_PKT_REQUEST &&
+ !(call->pkt.pfc_flags & DCERPC_PFC_FLAG_LAST)) {
DLIST_ADD_END(dce_conn->call_list, call, struct dcesrv_call_state *);
return NT_STATUS_OK;
}
DLIST_ADD_END(dce_conn->call_list, call, struct dcesrv_call_state *);
return NT_STATUS_OK;
}
if (rep->data.length == 0) {
/* we're done with this section of the call */
DLIST_REMOVE(call->replies, rep);
if (rep->data.length == 0) {
/* we're done with this section of the call */
DLIST_REMOVE(call->replies, rep);
+ } else {
+ return STATUS_BUFFER_OVERFLOW;
}
if (call->replies == NULL) {
}
if (call->replies == NULL) {