smbXsrv_session: split out smbXsrv_session_remove_channel()
[bbaumbach/samba-autobuild/.git] / source3 / smbd / smbXsrv_session.c
index 2ccae0e6b754abf58973d84b5f5036915b17c150..9bfdb8fbf04ac3abd55483fa60f3d486579ba65e 100644 (file)
@@ -21,6 +21,7 @@
 #include "includes.h"
 #include "system/filesys.h"
 #include <tevent.h>
+#include "lib/util/server_id.h"
 #include "smbd/smbd.h"
 #include "smbd/globals.h"
 #include "dbwrap/dbwrap.h"
@@ -37,6 +38,7 @@
 #include "librpc/gen_ndr/ndr_smbXsrv.h"
 #include "serverid.h"
 #include "lib/util/tevent_ntstatus.h"
+#include "lib/global_contexts.h"
 
 struct smbXsrv_session_table {
        struct {
@@ -51,15 +53,12 @@ struct smbXsrv_session_table {
        } global;
 };
 
-static NTSTATUS smb2srv_session_lookup_raw(struct smbXsrv_session_table *table,
-                                          uint64_t session_id, NTTIME now,
-                                          struct smbXsrv_session **session);
-
 static struct db_context *smbXsrv_session_global_db_ctx = NULL;
 
-NTSTATUS smbXsrv_session_global_init(void)
+NTSTATUS smbXsrv_session_global_init(struct messaging_context *msg_ctx)
 {
        char *global_path = NULL;
+       struct db_context *backend = NULL;
        struct db_context *db_ctx = NULL;
 
        if (smbXsrv_session_global_db_ctx != NULL) {
@@ -69,21 +68,21 @@ NTSTATUS smbXsrv_session_global_init(void)
        /*
         * This contains secret information like session keys!
         */
-       global_path = lock_path("smbXsrv_session_global.tdb");
+       global_path = lock_path(talloc_tos(), "smbXsrv_session_global.tdb");
        if (global_path == NULL) {
                return NT_STATUS_NO_MEMORY;
        }
 
-       db_ctx = db_open(NULL, global_path,
-                        0, /* hash_size */
-                        TDB_DEFAULT |
-                        TDB_CLEAR_IF_FIRST |
-                        TDB_INCOMPATIBLE_HASH,
-                        O_RDWR | O_CREAT, 0600,
-                        DBWRAP_LOCK_ORDER_1,
-                        DBWRAP_FLAG_NONE);
+       backend = db_open(NULL, global_path,
+                         0, /* hash_size */
+                         TDB_DEFAULT |
+                         TDB_CLEAR_IF_FIRST |
+                         TDB_INCOMPATIBLE_HASH,
+                         O_RDWR | O_CREAT, 0600,
+                         DBWRAP_LOCK_ORDER_1,
+                         DBWRAP_FLAG_NONE);
        TALLOC_FREE(global_path);
-       if (db_ctx == NULL) {
+       if (backend == NULL) {
                NTSTATUS status;
 
                status = map_nt_error_from_unix_common(errno);
@@ -91,6 +90,12 @@ NTSTATUS smbXsrv_session_global_init(void)
                return status;
        }
 
+       db_ctx = db_open_watched(NULL, &backend, global_messaging_context());
+       if (db_ctx == NULL) {
+               TALLOC_FREE(backend);
+               return NT_STATUS_NO_MEMORY;
+       }
+
        smbXsrv_session_global_db_ctx = db_ctx;
 
        return NT_STATUS_OK;
@@ -165,6 +170,48 @@ static NTSTATUS smbXsrv_session_local_key_to_id(TDB_DATA key, uint32_t *id)
        return NT_STATUS_OK;
 }
 
+static struct db_record *smbXsrv_session_global_fetch_locked(
+                       struct db_context *db,
+                       uint32_t id,
+                       TALLOC_CTX *mem_ctx)
+{
+       TDB_DATA key;
+       uint8_t key_buf[SMBXSRV_SESSION_GLOBAL_TDB_KEY_SIZE];
+       struct db_record *rec = NULL;
+
+       key = smbXsrv_session_global_id_to_key(id, key_buf);
+
+       rec = dbwrap_fetch_locked(db, mem_ctx, key);
+
+       if (rec == NULL) {
+               DBG_DEBUG("Failed to lock global id 0x%08x, key '%s'\n", id,
+                         hex_encode_talloc(talloc_tos(), key.dptr, key.dsize));
+       }
+
+       return rec;
+}
+
+static struct db_record *smbXsrv_session_local_fetch_locked(
+                       struct db_context *db,
+                       uint32_t id,
+                       TALLOC_CTX *mem_ctx)
+{
+       TDB_DATA key;
+       uint8_t key_buf[SMBXSRV_SESSION_LOCAL_TDB_KEY_SIZE];
+       struct db_record *rec = NULL;
+
+       key = smbXsrv_session_local_id_to_key(id, key_buf);
+
+       rec = dbwrap_fetch_locked(db, mem_ctx, key);
+
+       if (rec == NULL) {
+               DBG_DEBUG("Failed to lock local id 0x%08x, key '%s'\n", id,
+                         hex_encode_talloc(talloc_tos(), key.dptr, key.dsize));
+       }
+
+       return rec;
+}
+
 static void smbXsrv_session_close_loop(struct tevent_req *subreq);
 
 static NTSTATUS smbXsrv_session_table_init(struct smbXsrv_connection *conn,
@@ -204,7 +251,7 @@ static NTSTATUS smbXsrv_session_table_init(struct smbXsrv_connection *conn,
        table->local.highest_id = highest_id;
        table->local.max_sessions = max_sessions;
 
-       status = smbXsrv_session_global_init();
+       status = smbXsrv_session_global_init(client->msg_ctx);
        if (!NT_STATUS_IS_OK(status)) {
                TALLOC_FREE(table);
                return status;
@@ -212,9 +259,9 @@ static NTSTATUS smbXsrv_session_table_init(struct smbXsrv_connection *conn,
 
        table->global.db_ctx = smbXsrv_session_global_db_ctx;
 
-       dbwrap_watch_db(table->global.db_ctx, client->msg_ctx);
-
-       subreq = messaging_read_send(table, client->ev_ctx, client->msg_ctx,
+       subreq = messaging_read_send(table,
+                                    client->raw_ev_ctx,
+                                    client->msg_ctx,
                                     MSG_SMBXSRV_SESSION_CLOSE);
        if (subreq == NULL) {
                TALLOC_FREE(table);
@@ -280,9 +327,9 @@ static void smbXsrv_session_close_loop(struct tevent_req *subreq)
                goto next;
        }
 
-       status = smb2srv_session_lookup_raw(client->session_table,
-                                           close_info0->old_session_wire_id,
-                                           now, &session);
+       status = smb2srv_session_lookup_client(client,
+                                              close_info0->old_session_wire_id,
+                                              now, &session);
        if (NT_STATUS_EQUAL(status, NT_STATUS_USER_SESSION_DELETED)) {
                DEBUG(4,("smbXsrv_session_close_loop: "
                         "old_session_wire_id %llu not found\n",
@@ -332,7 +379,7 @@ static void smbXsrv_session_close_loop(struct tevent_req *subreq)
                goto next;
        }
 
-       subreq = smb2srv_session_shutdown_send(session, client->ev_ctx,
+       subreq = smb2srv_session_shutdown_send(session, client->raw_ev_ctx,
                                               session, NULL);
        if (subreq == NULL) {
                status = NT_STATUS_NO_MEMORY;
@@ -352,7 +399,9 @@ static void smbXsrv_session_close_loop(struct tevent_req *subreq)
 next:
        TALLOC_FREE(rec);
 
-       subreq = messaging_read_send(table, client->ev_ctx, client->msg_ctx,
+       subreq = messaging_read_send(table,
+                                    client->raw_ev_ctx,
+                                    client->msg_ctx,
                                     MSG_SMBXSRV_SESSION_CLOSE);
        if (subreq == NULL) {
                const char *r;
@@ -466,8 +515,6 @@ static NTSTATUS smb1srv_session_local_allocate_id(struct db_context *db,
 
        for (i = 0; i < (range / 2); i++) {
                uint32_t id;
-               uint8_t key_buf[SMBXSRV_SESSION_LOCAL_TDB_KEY_SIZE];
-               TDB_DATA key;
                TDB_DATA val;
                struct db_record *rec = NULL;
 
@@ -481,9 +528,7 @@ static NTSTATUS smb1srv_session_local_allocate_id(struct db_context *db,
                        id = highest_id;
                }
 
-               key = smbXsrv_session_local_id_to_key(id, key_buf);
-
-               rec = dbwrap_fetch_locked(db, mem_ctx, key);
+               rec = smbXsrv_session_local_fetch_locked(db, id, mem_ctx);
                if (rec == NULL) {
                        return NT_STATUS_INSUFFICIENT_RESOURCES;
                }
@@ -533,16 +578,12 @@ static NTSTATUS smb1srv_session_local_allocate_id(struct db_context *db,
 
        if (NT_STATUS_IS_OK(state.status)) {
                uint32_t id;
-               uint8_t key_buf[SMBXSRV_SESSION_LOCAL_TDB_KEY_SIZE];
-               TDB_DATA key;
                TDB_DATA val;
                struct db_record *rec = NULL;
 
                id = state.useable_id;
 
-               key = smbXsrv_session_local_id_to_key(id, key_buf);
-
-               rec = dbwrap_fetch_locked(db, mem_ctx, key);
+               rec = smbXsrv_session_local_fetch_locked(db, id, mem_ctx);
                if (rec == NULL) {
                        return NT_STATUS_INSUFFICIENT_RESOURCES;
                }
@@ -584,6 +625,8 @@ static void smbXsrv_session_local_fetch_parser(TDB_DATA key, TDB_DATA data,
 }
 
 static NTSTATUS smbXsrv_session_local_lookup(struct smbXsrv_session_table *table,
+                                            /* conn: optional */
+                                            struct smbXsrv_connection *conn,
                                             uint32_t session_local_id,
                                             NTTIME now,
                                             struct smbXsrv_session **_session)
@@ -629,6 +672,19 @@ static NTSTATUS smbXsrv_session_local_lookup(struct smbXsrv_session_table *table
                return NT_STATUS_USER_SESSION_DELETED;
        }
 
+       /*
+        * If a connection is specified check if the session is
+        * valid on the channel.
+        */
+       if (conn != NULL) {
+               struct smbXsrv_channel_global0 *c = NULL;
+
+               status = smbXsrv_session_find_channel(state.session, conn, &c);
+               if (!NT_STATUS_IS_OK(status)) {
+                       return status;
+               }
+       }
+
        state.session->idle_time = now;
 
        if (!NT_STATUS_IS_OK(state.session->status)) {
@@ -682,8 +738,6 @@ static NTSTATUS smbXsrv_session_global_allocate(struct db_context *db,
                bool is_free = false;
                bool was_free = false;
                uint32_t id;
-               uint8_t key_buf[SMBXSRV_SESSION_GLOBAL_TDB_KEY_SIZE];
-               TDB_DATA key;
 
                if (i >= min_tries && last_free != 0) {
                        id = last_free;
@@ -697,9 +751,8 @@ static NTSTATUS smbXsrv_session_global_allocate(struct db_context *db,
                        id--;
                }
 
-               key = smbXsrv_session_global_id_to_key(id, key_buf);
-
-               global->db_rec = dbwrap_fetch_locked(db, mem_ctx, key);
+               global->db_rec = smbXsrv_session_global_fetch_locked(db, id,
+                                                                    mem_ctx);
                if (global->db_rec == NULL) {
                        talloc_free(global);
                        return NT_STATUS_INSUFFICIENT_RESOURCES;
@@ -791,6 +844,10 @@ static void smbXsrv_session_global_verify_record(struct db_record *db_rec,
                         hex_encode_talloc(frame, key.dptr, key.dsize),
                         nt_errstr(status)));
                TALLOC_FREE(frame);
+               *is_free = true;
+               if (was_free) {
+                       *was_free = true;
+               }
                return;
        }
 
@@ -806,11 +863,32 @@ static void smbXsrv_session_global_verify_record(struct db_record *db_rec,
                         global_blob.version));
                NDR_PRINT_DEBUG(smbXsrv_session_globalB, &global_blob);
                TALLOC_FREE(frame);
+               *is_free = true;
+               if (was_free) {
+                       *was_free = true;
+               }
                return;
        }
 
        global = global_blob.info.info0;
 
+#define __BLOB_KEEP_SECRET(__blob) do { \
+       if ((__blob).length != 0) { \
+               talloc_keep_secret((__blob).data); \
+       } \
+} while(0)
+       {
+               uint32_t i;
+               __BLOB_KEEP_SECRET(global->application_key_blob);
+               __BLOB_KEEP_SECRET(global->signing_key_blob);
+               __BLOB_KEEP_SECRET(global->encryption_key_blob);
+               __BLOB_KEEP_SECRET(global->decryption_key_blob);
+               for (i = 0; i < global->num_channels; i++) {
+                       __BLOB_KEEP_SECRET(global->channels[i].signing_key_blob);
+               }
+       }
+#undef __BLOB_KEEP_SECRET
+
        exists = serverid_exists(&global->channels[0].server_id);
        if (!exists) {
                struct server_id_buf idbuf;
@@ -900,6 +978,7 @@ struct smb2srv_session_close_previous_state {
        struct tevent_context *ev;
        struct smbXsrv_connection *connection;
        struct dom_sid *current_sid;
+       uint64_t previous_session_id;
        uint64_t current_session_id;
        struct db_record *db_rec;
 };
@@ -920,8 +999,6 @@ struct tevent_req *smb2srv_session_close_previous_send(TALLOC_CTX *mem_ctx,
        uint64_t global_zeros = previous_session_id & 0xFFFFFFFF00000000LLU;
        struct smbXsrv_session_table *table = conn->client->session_table;
        struct security_token *current_token = NULL;
-       uint8_t key_buf[SMBXSRV_SESSION_GLOBAL_TDB_KEY_SIZE];
-       TDB_DATA key;
 
        req = tevent_req_create(mem_ctx, &state,
                                struct smb2srv_session_close_previous_state);
@@ -930,6 +1007,7 @@ struct tevent_req *smb2srv_session_close_previous_send(TALLOC_CTX *mem_ctx,
        }
        state->ev = ev;
        state->connection = conn;
+       state->previous_session_id = previous_session_id;
        state->current_session_id = current_session_id;
 
        if (global_zeros != 0) {
@@ -958,10 +1036,10 @@ struct tevent_req *smb2srv_session_close_previous_send(TALLOC_CTX *mem_ctx,
                return tevent_req_post(req, ev);
        }
 
-       key = smbXsrv_session_global_id_to_key(global_id, key_buf);
-
-       state->db_rec = dbwrap_fetch_locked(table->global.db_ctx,
-                                           state, key);
+       state->db_rec = smbXsrv_session_global_fetch_locked(
+                                                       table->global.db_ctx,
+                                                       global_id,
+                                                       state /* TALLOC_CTX */);
        if (state->db_rec == NULL) {
                tevent_req_nterror(req, NT_STATUS_UNSUCCESSFUL);
                return tevent_req_post(req, ev);
@@ -1017,8 +1095,8 @@ static void smb2srv_session_close_previous_check(struct tevent_req *req)
                return;
        }
 
-       subreq = dbwrap_record_watch_send(state, state->ev,
-                                         state->db_rec, conn->msg_ctx);
+       subreq = dbwrap_watched_watch_send(state, state->ev, state->db_rec,
+                                          (struct server_id){0});
        if (tevent_req_nomem(subreq, req)) {
                TALLOC_FREE(state->db_rec);
                return;
@@ -1050,7 +1128,7 @@ static void smb2srv_session_close_previous_check(struct tevent_req *req)
                return;
        }
 
-       status = messaging_send(conn->msg_ctx,
+       status = messaging_send(conn->client->msg_ctx,
                                global->channels[0].server_id,
                                MSG_SMBXSRV_SESSION_CLOSE, &blob);
        TALLOC_FREE(state->db_rec);
@@ -1070,14 +1148,21 @@ static void smb2srv_session_close_previous_modified(struct tevent_req *subreq)
        struct smb2srv_session_close_previous_state *state =
                tevent_req_data(req,
                struct smb2srv_session_close_previous_state);
+       uint32_t global_id;
        NTSTATUS status;
 
-       status = dbwrap_record_watch_recv(subreq, state, &state->db_rec);
+       status = dbwrap_watched_watch_recv(subreq, NULL, NULL);
        TALLOC_FREE(subreq);
        if (tevent_req_nterror(req, status)) {
                return;
        }
 
+       global_id = state->previous_session_id & UINT32_MAX;
+
+       state->db_rec = smbXsrv_session_global_fetch_locked(
+               state->connection->client->session_table->global.db_ctx,
+               global_id, state /* TALLOC_CTX */);
+
        smb2srv_session_close_previous_check(req);
 }
 
@@ -1094,7 +1179,7 @@ NTSTATUS smb2srv_session_close_previous_recv(struct tevent_req *req)
        return NT_STATUS_OK;
 }
 
-static int smbXsrv_session_destructor(struct smbXsrv_session *session)
+static NTSTATUS smbXsrv_session_clear_and_logoff(struct smbXsrv_session *session)
 {
        NTSTATUS status;
        struct smbXsrv_connection *xconn = NULL;
@@ -1118,10 +1203,19 @@ static int smbXsrv_session_destructor(struct smbXsrv_session *session)
                         */
                        preq->do_signing = false;
                        preq->do_encryption = false;
+                       preq->preauth = NULL;
                }
        }
 
        status = smbXsrv_session_logoff(session);
+       return status;
+}
+
+static int smbXsrv_session_destructor(struct smbXsrv_session *session)
+{
+       NTSTATUS status;
+
+       status = smbXsrv_session_clear_and_logoff(session);
        if (!NT_STATUS_IS_OK(status)) {
                DEBUG(0, ("smbXsrv_session_destructor: "
                          "smbXsrv_session_logoff() failed: %s\n",
@@ -1143,7 +1237,7 @@ NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
        void *ptr = NULL;
        TDB_DATA val;
        struct smbXsrv_session_global0 *global = NULL;
-       struct smbXsrv_channel_global0 *channels = NULL;
+       struct smbXsrv_channel_global0 *channel = NULL;
        NTSTATUS status;
 
        if (table->local.num_sessions >= table->local.max_sessions) {
@@ -1158,6 +1252,7 @@ NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
        session->idle_time = now;
        session->status = NT_STATUS_MORE_PROCESSING_REQUIRED;
        session->client = conn->client;
+       session->homes_snum = -1;
 
        status = smbXsrv_session_global_allocate(table->global.db_ctx,
                                                 session,
@@ -1170,8 +1265,6 @@ NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
 
        if (conn->protocol >= PROTOCOL_SMB2_02) {
                uint64_t id = global->session_global_id;
-               uint8_t key_buf[SMBXSRV_SESSION_LOCAL_TDB_KEY_SIZE];
-               TDB_DATA key;
 
                global->connection_dialect = conn->smb2.server.dialect;
 
@@ -1185,10 +1278,10 @@ NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
 
                session->local_id = global->session_global_id;
 
-               key = smbXsrv_session_local_id_to_key(session->local_id, key_buf);
-
-               local_rec = dbwrap_fetch_locked(table->local.db_ctx,
-                                               session, key);
+               local_rec = smbXsrv_session_local_fetch_locked(
+                                               table->local.db_ctx,
+                                               session->local_id,
+                                               session /* TALLOC_CTX */);
                if (local_rec == NULL) {
                        TALLOC_FREE(session);
                        return NT_STATUS_NO_MEMORY;
@@ -1218,36 +1311,11 @@ NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
        global->creation_time = now;
        global->expiration_time = GENSEC_EXPIRE_TIME_INFINITY;
 
-       global->num_channels = 1;
-       channels = talloc_zero_array(global,
-                                    struct smbXsrv_channel_global0,
-                                    global->num_channels);
-       if (channels == NULL) {
-               TALLOC_FREE(session);
-               return NT_STATUS_NO_MEMORY;
-       }
-       global->channels = channels;
-
-       channels[0].server_id = messaging_server_id(conn->msg_ctx);
-       channels[0].local_address = tsocket_address_string(conn->local_address,
-                                                          channels);
-       if (channels[0].local_address == NULL) {
-               TALLOC_FREE(session);
-               return NT_STATUS_NO_MEMORY;
-       }
-       channels[0].remote_address = tsocket_address_string(conn->remote_address,
-                                                           channels);
-       if (channels[0].remote_address == NULL) {
-               TALLOC_FREE(session);
-               return NT_STATUS_NO_MEMORY;
-       }
-       channels[0].remote_name = talloc_strdup(channels, conn->remote_hostname);
-       if (channels[0].remote_name == NULL) {
+       status = smbXsrv_session_add_channel(session, conn, now, &channel);
+       if (!NT_STATUS_IS_OK(status)) {
                TALLOC_FREE(session);
-               return NT_STATUS_NO_MEMORY;
+               return status;
        }
-       channels[0].signing_key = data_blob_null;
-       channels[0].connection = conn;
 
        ptr = session;
        val = make_tdb_data((uint8_t const *)&ptr, sizeof(ptr));
@@ -1272,11 +1340,10 @@ NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
        }
 
        if (DEBUGLVL(10)) {
-               struct smbXsrv_sessionB session_blob;
-
-               ZERO_STRUCT(session_blob);
-               session_blob.version = SMBXSRV_VERSION_0;
-               session_blob.info.info0 = session;
+               struct smbXsrv_sessionB session_blob = {
+                       .version = SMBXSRV_VERSION_0,
+                       .info.info0 = session,
+               };
 
                DEBUG(10,("smbXsrv_session_create: global_id (0x%08x) stored\n",
                         session->global->session_global_id));
@@ -1287,12 +1354,63 @@ NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
        return NT_STATUS_OK;
 }
 
+NTSTATUS smbXsrv_session_add_channel(struct smbXsrv_session *session,
+                                    struct smbXsrv_connection *conn,
+                                    NTTIME now,
+                                    struct smbXsrv_channel_global0 **_c)
+{
+       struct smbXsrv_session_global0 *global = session->global;
+       struct smbXsrv_channel_global0 *c = NULL;
+
+       if (global->num_channels > 31) {
+               /*
+                * Windows allow up to 32 channels
+                */
+               return NT_STATUS_INSUFFICIENT_RESOURCES;
+       }
+
+       c = talloc_realloc(global,
+                          global->channels,
+                          struct smbXsrv_channel_global0,
+                          global->num_channels + 1);
+       if (c == NULL) {
+               return NT_STATUS_NO_MEMORY;
+       }
+       global->channels = c;
+
+       c = &global->channels[global->num_channels];
+       ZERO_STRUCTP(c);
+
+       c->server_id = messaging_server_id(conn->client->msg_ctx);
+       c->channel_id = conn->channel_id;
+       c->creation_time = now;
+       c->local_address = tsocket_address_string(conn->local_address,
+                                                 global->channels);
+       if (c->local_address == NULL) {
+               return NT_STATUS_NO_MEMORY;
+       }
+       c->remote_address = tsocket_address_string(conn->remote_address,
+                                                  global->channels);
+       if (c->remote_address == NULL) {
+               return NT_STATUS_NO_MEMORY;
+       }
+       c->remote_name = talloc_strdup(global->channels,
+                                      conn->remote_hostname);
+       if (c->remote_name == NULL) {
+               return NT_STATUS_NO_MEMORY;
+       }
+       c->connection = conn;
+
+       global->num_channels += 1;
+
+       *_c = c;
+       return NT_STATUS_OK;
+}
+
 NTSTATUS smbXsrv_session_update(struct smbXsrv_session *session)
 {
        struct smbXsrv_session_table *table = session->table;
        NTSTATUS status;
-       uint8_t key_buf[SMBXSRV_SESSION_GLOBAL_TDB_KEY_SIZE];
-       TDB_DATA key;
 
        if (session->global->db_rec != NULL) {
                DEBUG(0, ("smbXsrv_session_update(0x%08x): "
@@ -1301,18 +1419,11 @@ NTSTATUS smbXsrv_session_update(struct smbXsrv_session *session)
                return NT_STATUS_INTERNAL_ERROR;
        }
 
-       key = smbXsrv_session_global_id_to_key(
+       session->global->db_rec = smbXsrv_session_global_fetch_locked(
+                                       table->global.db_ctx,
                                        session->global->session_global_id,
-                                       key_buf);
-
-       session->global->db_rec = dbwrap_fetch_locked(table->global.db_ctx,
-                                                     session->global, key);
+                                       session->global /* TALLOC_CTX */);
        if (session->global->db_rec == NULL) {
-               DEBUG(0, ("smbXsrv_session_update(0x%08x): "
-                         "Failed to lock global key '%s'\n",
-                         session->global->session_global_id,
-                         hex_encode_talloc(talloc_tos(), key.dptr,
-                                           key.dsize)));
                return NT_STATUS_INTERNAL_DB_ERROR;
        }
 
@@ -1326,11 +1437,10 @@ NTSTATUS smbXsrv_session_update(struct smbXsrv_session *session)
        }
 
        if (DEBUGLVL(10)) {
-               struct smbXsrv_sessionB session_blob;
-
-               ZERO_STRUCT(session_blob);
-               session_blob.version = SMBXSRV_VERSION_0;
-               session_blob.info.info0 = session;
+               struct smbXsrv_sessionB session_blob = {
+                       .version = SMBXSRV_VERSION_0,
+                       .info.info0 = session,
+               };
 
                DEBUG(10,("smbXsrv_session_update: global_id (0x%08x) stored\n",
                          session->global->session_global_id));
@@ -1349,8 +1459,38 @@ NTSTATUS smbXsrv_session_find_channel(const struct smbXsrv_session *session,
        for (i=0; i < session->global->num_channels; i++) {
                struct smbXsrv_channel_global0 *c = &session->global->channels[i];
 
-               if (c->connection == conn) {
-                       *_c = c;
+               if (c->channel_id != conn->channel_id) {
+                       continue;
+               }
+
+               if (c->connection != conn) {
+                       continue;
+               }
+
+               *_c = c;
+               return NT_STATUS_OK;
+       }
+
+       return NT_STATUS_USER_SESSION_DELETED;
+}
+
+NTSTATUS smbXsrv_session_find_auth(const struct smbXsrv_session *session,
+                                  const struct smbXsrv_connection *conn,
+                                  NTTIME now,
+                                  struct smbXsrv_session_auth0 **_a)
+{
+       struct smbXsrv_session_auth0 *a;
+
+       for (a = session->pending_auth; a != NULL; a = a->next) {
+               if (a->channel_id != conn->channel_id) {
+                       continue;
+               }
+
+               if (a->connection == conn) {
+                       if (now != 0) {
+                               a->idle_time = now;
+                       }
+                       *_a = a;
                        return NT_STATUS_OK;
                }
        }
@@ -1358,6 +1498,109 @@ NTSTATUS smbXsrv_session_find_channel(const struct smbXsrv_session *session,
        return NT_STATUS_USER_SESSION_DELETED;
 }
 
+static int smbXsrv_session_auth0_destructor(struct smbXsrv_session_auth0 *a)
+{
+       if (a->session == NULL) {
+               return 0;
+       }
+
+       DLIST_REMOVE(a->session->pending_auth, a);
+       a->session = NULL;
+       return 0;
+}
+
+NTSTATUS smbXsrv_session_create_auth(struct smbXsrv_session *session,
+                                    struct smbXsrv_connection *conn,
+                                    NTTIME now,
+                                    uint8_t in_flags,
+                                    uint8_t in_security_mode,
+                                    struct smbXsrv_session_auth0 **_a)
+{
+       struct smbXsrv_session_auth0 *a;
+       NTSTATUS status;
+
+       status = smbXsrv_session_find_auth(session, conn, 0, &a);
+       if (NT_STATUS_IS_OK(status)) {
+               return NT_STATUS_INTERNAL_ERROR;
+       }
+
+       a = talloc_zero(session, struct smbXsrv_session_auth0);
+       if (a == NULL) {
+               return NT_STATUS_NO_MEMORY;
+       }
+       a->session = session;
+       a->connection = conn;
+       a->in_flags = in_flags;
+       a->in_security_mode = in_security_mode;
+       a->creation_time = now;
+       a->idle_time = now;
+       a->channel_id = conn->channel_id;
+
+       if (conn->protocol >= PROTOCOL_SMB3_10) {
+               a->preauth = talloc(a, struct smbXsrv_preauth);
+               if (a->preauth == NULL) {
+                       TALLOC_FREE(session);
+                       return NT_STATUS_NO_MEMORY;
+               }
+               *a->preauth = conn->smb2.preauth;
+       }
+
+       talloc_set_destructor(a, smbXsrv_session_auth0_destructor);
+       DLIST_ADD_END(session->pending_auth, a);
+
+       *_a = a;
+       return NT_STATUS_OK;
+}
+
+NTSTATUS smbXsrv_session_remove_channel(struct smbXsrv_session *session,
+                                       struct smbXsrv_connection *xconn)
+{
+       struct smbXsrv_session_auth0 *a = NULL;
+       struct smbXsrv_channel_global0 *c = NULL;
+       NTSTATUS status;
+       bool need_update = false;
+
+       status = smbXsrv_session_find_auth(session, xconn, 0, &a);
+       if (!NT_STATUS_IS_OK(status)) {
+               a = NULL;
+       }
+       status = smbXsrv_session_find_channel(session, xconn, &c);
+       if (!NT_STATUS_IS_OK(status)) {
+               c = NULL;
+       }
+       if (session->global->num_channels <= 1) {
+               /*
+                * The last channel is treated different
+                */
+               c = NULL;
+       }
+
+       if (a != NULL) {
+               smbXsrv_session_auth0_destructor(a);
+               a->connection = NULL;
+               need_update = true;
+       }
+
+       if (c != NULL) {
+               struct smbXsrv_session_global0 *global = session->global;
+               ptrdiff_t n;
+
+               n = (c - global->channels);
+               if (n >= global->num_channels || n < 0) {
+                       return NT_STATUS_INTERNAL_ERROR;
+               }
+               ARRAY_DEL_ELEMENT(global->channels, n, global->num_channels);
+               global->num_channels--;
+               need_update = true;
+       }
+
+       if (!need_update) {
+               return NT_STATUS_OK;
+       }
+
+       return smbXsrv_session_update(session);
+}
+
 struct smb2srv_session_shutdown_state {
        struct tevent_queue *wait_queue;
 };
@@ -1412,6 +1655,7 @@ struct tevent_req *smb2srv_session_shutdown_send(TALLOC_CTX *mem_ctx,
                                 */
                                preq->do_signing = false;
                                preq->do_encryption = false;
+                               preq->preauth = NULL;
 
                                if (preq->subreq != NULL) {
                                        tevent_req_cancel(preq->subreq);
@@ -1499,24 +1743,38 @@ NTSTATUS smbXsrv_session_logoff(struct smbXsrv_session *session)
        session->client = NULL;
        session->status = NT_STATUS_USER_SESSION_DELETED;
 
+       /*
+        * For SMB2 this is a bit redundant as files are also close
+        * below via smb2srv_tcon_disconnect_all() -> ... ->
+        * smbXsrv_tcon_disconnect() -> close_cnum() ->
+        * file_close_conn().
+        */
+       file_close_user(sconn, session->global->session_wire_id);
+
+       if (session->tcon_table != NULL) {
+               /*
+                * Note: We only have a tcon_table for SMB2.
+                */
+               status = smb2srv_tcon_disconnect_all(session);
+               if (!NT_STATUS_IS_OK(status)) {
+                       DEBUG(0, ("smbXsrv_session_logoff(0x%08x): "
+                                 "smb2srv_tcon_disconnect_all() failed: %s\n",
+                                 session->global->session_global_id,
+                                 nt_errstr(status)));
+                       error = status;
+               }
+       }
+
+       invalidate_vuid(sconn, session->global->session_wire_id);
+
        global_rec = session->global->db_rec;
        session->global->db_rec = NULL;
        if (global_rec == NULL) {
-               uint8_t key_buf[SMBXSRV_SESSION_GLOBAL_TDB_KEY_SIZE];
-               TDB_DATA key;
-
-               key = smbXsrv_session_global_id_to_key(
+               global_rec = smbXsrv_session_global_fetch_locked(
+                                       table->global.db_ctx,
                                        session->global->session_global_id,
-                                       key_buf);
-
-               global_rec = dbwrap_fetch_locked(table->global.db_ctx,
-                                                session->global, key);
+                                       session->global /* TALLOC_CTX */);
                if (global_rec == NULL) {
-                       DEBUG(0, ("smbXsrv_session_logoff(0x%08x): "
-                                 "Failed to lock global key '%s'\n",
-                                 session->global->session_global_id,
-                                 hex_encode_talloc(global_rec, key.dptr,
-                                                   key.dsize)));
                        error = NT_STATUS_INTERNAL_ERROR;
                }
        }
@@ -1539,20 +1797,11 @@ NTSTATUS smbXsrv_session_logoff(struct smbXsrv_session *session)
 
        local_rec = session->db_rec;
        if (local_rec == NULL) {
-               uint8_t key_buf[SMBXSRV_SESSION_LOCAL_TDB_KEY_SIZE];
-               TDB_DATA key;
-
-               key = smbXsrv_session_local_id_to_key(session->local_id,
-                                                     key_buf);
-
-               local_rec = dbwrap_fetch_locked(table->local.db_ctx,
-                                               session, key);
+               local_rec = smbXsrv_session_local_fetch_locked(
+                                               table->local.db_ctx,
+                                               session->local_id,
+                                               session /* TALLOC_CTX */);
                if (local_rec == NULL) {
-                       DEBUG(0, ("smbXsrv_session_logoff(0x%08x): "
-                                 "Failed to lock local key '%s'\n",
-                                 session->global->session_global_id,
-                                 hex_encode_talloc(local_rec, key.dptr,
-                                                   key.dsize)));
                        error = NT_STATUS_INTERNAL_ERROR;
                }
        }
@@ -1577,29 +1826,6 @@ NTSTATUS smbXsrv_session_logoff(struct smbXsrv_session *session)
        }
        session->db_rec = NULL;
 
-       if (session->compat) {
-               file_close_user(sconn, session->compat->vuid);
-       }
-
-       if (session->tcon_table != NULL) {
-               /*
-                * Note: We only have a tcon_table for SMB2.
-                */
-               status = smb2srv_tcon_disconnect_all(session);
-               if (!NT_STATUS_IS_OK(status)) {
-                       DEBUG(0, ("smbXsrv_session_logoff(0x%08x): "
-                                 "smb2srv_tcon_disconnect_all() failed: %s\n",
-                                 session->global->session_global_id,
-                                 nt_errstr(status)));
-                       error = status;
-               }
-       }
-
-       if (session->compat) {
-               invalidate_vuid(sconn, session->compat->vuid);
-               session->compat = NULL;
-       }
-
        return error;
 }
 
@@ -1611,9 +1837,9 @@ struct smbXsrv_session_logoff_all_state {
 static int smbXsrv_session_logoff_all_callback(struct db_record *local_rec,
                                               void *private_data);
 
-NTSTATUS smbXsrv_session_logoff_all(struct smbXsrv_connection *conn)
+NTSTATUS smbXsrv_session_logoff_all(struct smbXsrv_client *client)
 {
-       struct smbXsrv_session_table *table = conn->client->session_table;
+       struct smbXsrv_session_table *table = client->session_table;
        struct smbXsrv_session_logoff_all_state state;
        NTSTATUS status;
        int count = 0;
@@ -1655,7 +1881,6 @@ static int smbXsrv_session_logoff_all_callback(struct db_record *local_rec,
        TDB_DATA val;
        void *ptr = NULL;
        struct smbXsrv_session *session = NULL;
-       struct smbXsrv_connection *xconn = NULL;
        NTSTATUS status;
 
        val = dbwrap_record_get_value(local_rec);
@@ -1672,30 +1897,151 @@ static int smbXsrv_session_logoff_all_callback(struct db_record *local_rec,
        session = talloc_get_type_abort(ptr, struct smbXsrv_session);
 
        session->db_rec = local_rec;
+       status = smbXsrv_session_clear_and_logoff(session);
+       session->db_rec = NULL;
+       if (!NT_STATUS_IS_OK(status)) {
+               if (NT_STATUS_IS_OK(state->first_status)) {
+                       state->first_status = status;
+               }
+               state->errors++;
+               return 0;
+       }
 
-       if (session->client != NULL) {
-               xconn = session->client->connections;
+       return 0;
+}
+
+struct smbXsrv_session_local_trav_state {
+       NTSTATUS status;
+       int (*caller_cb)(struct smbXsrv_session *session,
+                        void *caller_data);
+       void *caller_data;
+};
+
+static int smbXsrv_session_local_traverse_cb(struct db_record *local_rec,
+                                            void *private_data);
+
+NTSTATUS smbXsrv_session_local_traverse(
+       struct smbXsrv_client *client,
+       int (*caller_cb)(struct smbXsrv_session *session,
+                        void *caller_data),
+       void *caller_data)
+{
+       struct smbXsrv_session_table *table = client->session_table;
+       struct smbXsrv_session_local_trav_state state;
+       NTSTATUS status;
+       int count = 0;
+
+       state = (struct smbXsrv_session_local_trav_state) {
+               .status = NT_STATUS_OK,
+               .caller_cb = caller_cb,
+               .caller_data = caller_data,
+       };
+
+       if (table == NULL) {
+               DBG_DEBUG("empty session_table, nothing to do.\n");
+               return NT_STATUS_OK;
        }
-       for (; xconn != NULL; xconn = xconn->next) {
-               struct smbd_smb2_request *preq;
 
-               for (preq = xconn->smb2.requests; preq != NULL; preq = preq->next) {
-                       if (preq->session != session) {
-                               continue;
-                       }
+       status = dbwrap_traverse(table->local.db_ctx,
+                                smbXsrv_session_local_traverse_cb,
+                                &state,
+                                &count);
+       if (!NT_STATUS_IS_OK(status)) {
+               DBG_ERR("dbwrap_traverse() failed: %s\n", nt_errstr(status));
+               return status;
+       }
+       if (!NT_STATUS_IS_OK(state.status)) {
+               DBG_ERR("count[%d] status[%s]\n",
+                       count, nt_errstr(state.status));
+               return state.status;
+       }
 
-                       preq->session = NULL;
-                       /*
-                        * If we no longer have a session we can't
-                        * sign or encrypt replies.
-                        */
-                       preq->do_signing = false;
-                       preq->do_encryption = false;
-               }
+       return NT_STATUS_OK;
+}
+
+static int smbXsrv_session_local_traverse_cb(struct db_record *local_rec,
+                                            void *private_data)
+{
+       struct smbXsrv_session_local_trav_state *state =
+               (struct smbXsrv_session_local_trav_state *)private_data;
+       TDB_DATA val;
+       void *ptr = NULL;
+       struct smbXsrv_session *session = NULL;
+       int ret;
+
+       val = dbwrap_record_get_value(local_rec);
+       if (val.dsize != sizeof(ptr)) {
+               state->status = NT_STATUS_INTERNAL_ERROR;
+               return -1;
        }
 
-       status = smbXsrv_session_logoff(session);
+       memcpy(&ptr, val.dptr, val.dsize);
+       session = talloc_get_type_abort(ptr, struct smbXsrv_session);
+
+       session->db_rec = local_rec;
+       ret = state->caller_cb(session, state->caller_data);
+       session->db_rec = NULL;
+
+       return ret;
+}
+
+struct smbXsrv_session_disconnect_xconn_state {
+       struct smbXsrv_connection *xconn;
+       NTSTATUS first_status;
+       int errors;
+};
+
+static int smbXsrv_session_disconnect_xconn_callback(struct db_record *local_rec,
+                                              void *private_data);
+
+NTSTATUS smbXsrv_session_disconnect_xconn(struct smbXsrv_connection *xconn)
+{
+       struct smbXsrv_client *client = xconn->client;
+       struct smbXsrv_session_table *table = client->session_table;
+       struct smbXsrv_session_disconnect_xconn_state state;
+       NTSTATUS status;
+       int count = 0;
+
+       if (table == NULL) {
+               DBG_ERR("empty session_table, nothing to do.\n");
+               return NT_STATUS_OK;
+       }
+
+       ZERO_STRUCT(state);
+       state.xconn = xconn;
+
+       status = dbwrap_traverse(table->local.db_ctx,
+                                smbXsrv_session_disconnect_xconn_callback,
+                                &state, &count);
        if (!NT_STATUS_IS_OK(status)) {
+               DBG_ERR("dbwrap_traverse() failed: %s\n",
+                       nt_errstr(status));
+               return status;
+       }
+
+       if (!NT_STATUS_IS_OK(state.first_status)) {
+               DBG_ERR("count[%d] errors[%d] first[%s]\n",
+                       count, state.errors,
+                       nt_errstr(state.first_status));
+               return state.first_status;
+       }
+
+       return NT_STATUS_OK;
+}
+
+static int smbXsrv_session_disconnect_xconn_callback(struct db_record *local_rec,
+                                              void *private_data)
+{
+       struct smbXsrv_session_disconnect_xconn_state *state =
+               (struct smbXsrv_session_disconnect_xconn_state *)private_data;
+       TDB_DATA val;
+       void *ptr = NULL;
+       struct smbXsrv_session *session = NULL;
+       NTSTATUS status;
+
+       val = dbwrap_record_get_value(local_rec);
+       if (val.dsize != sizeof(ptr)) {
+               status = NT_STATUS_INTERNAL_ERROR;
                if (NT_STATUS_IS_OK(state->first_status)) {
                        state->first_status = status;
                }
@@ -1703,6 +2049,19 @@ static int smbXsrv_session_logoff_all_callback(struct db_record *local_rec,
                return 0;
        }
 
+       memcpy(&ptr, val.dptr, val.dsize);
+       session = talloc_get_type_abort(ptr, struct smbXsrv_session);
+
+       session->db_rec = local_rec;
+       status = smbXsrv_session_remove_channel(session, state->xconn);
+       session->db_rec = NULL;
+       if (!NT_STATUS_IS_OK(status)) {
+               if (NT_STATUS_IS_OK(state->first_status)) {
+                       state->first_status = status;
+               }
+               state->errors++;
+       }
+
        return 0;
 }
 
@@ -1722,7 +2081,107 @@ NTSTATUS smb1srv_session_lookup(struct smbXsrv_connection *conn,
        struct smbXsrv_session_table *table = conn->client->session_table;
        uint32_t local_id = vuid;
 
-       return smbXsrv_session_local_lookup(table, local_id, now, session);
+       return smbXsrv_session_local_lookup(table, conn, local_id, now,
+                                           session);
+}
+
+NTSTATUS smbXsrv_session_info_lookup(struct smbXsrv_client *client,
+                                    uint64_t session_wire_id,
+                                    struct auth_session_info **si)
+{
+       struct smbXsrv_session_table *table = client->session_table;
+       uint8_t key_buf[SMBXSRV_SESSION_LOCAL_TDB_KEY_SIZE];
+       struct smbXsrv_session_local_fetch_state state = {
+               .session = NULL,
+               .status = NT_STATUS_INTERNAL_ERROR,
+       };
+       TDB_DATA key;
+       NTSTATUS status;
+
+       if (session_wire_id == 0) {
+               return NT_STATUS_USER_SESSION_DELETED;
+       }
+
+       if (table == NULL) {
+               /* this might happen before the end of negprot */
+               return NT_STATUS_USER_SESSION_DELETED;
+       }
+
+       if (table->local.db_ctx == NULL) {
+               return NT_STATUS_INTERNAL_ERROR;
+       }
+
+       key = smbXsrv_session_local_id_to_key(session_wire_id, key_buf);
+
+       status = dbwrap_parse_record(table->local.db_ctx, key,
+                                    smbXsrv_session_local_fetch_parser,
+                                    &state);
+       if (!NT_STATUS_IS_OK(status)) {
+               return status;
+       }
+       if (!NT_STATUS_IS_OK(state.status)) {
+               return state.status;
+       }
+       if (state.session->global->auth_session_info == NULL) {
+               return NT_STATUS_USER_SESSION_DELETED;
+       }
+
+       *si = state.session->global->auth_session_info;
+       return NT_STATUS_OK;
+}
+
+/*
+ * In memory of get_valid_user_struct()
+ *
+ * This function is similar to smbXsrv_session_local_lookup() and it's wrappers,
+ * but it doesn't implement the state checks of
+ * those. get_valid_smbXsrv_session() is NOT meant to be called to validate the
+ * session wire-id of incoming SMB requests, it MUST only be used in later
+ * internal processing where the session wire-id has already been validated.
+ */
+NTSTATUS get_valid_smbXsrv_session(struct smbXsrv_client *client,
+                                  uint64_t session_wire_id,
+                                  struct smbXsrv_session **session)
+{
+       struct smbXsrv_session_table *table = client->session_table;
+       uint8_t key_buf[SMBXSRV_SESSION_LOCAL_TDB_KEY_SIZE];
+       struct smbXsrv_session_local_fetch_state state = {
+               .session = NULL,
+               .status = NT_STATUS_INTERNAL_ERROR,
+       };
+       TDB_DATA key;
+       NTSTATUS status;
+
+       if (session_wire_id == 0) {
+               return NT_STATUS_USER_SESSION_DELETED;
+       }
+
+       if (table == NULL) {
+               /* this might happen before the end of negprot */
+               return NT_STATUS_USER_SESSION_DELETED;
+       }
+
+       if (table->local.db_ctx == NULL) {
+               return NT_STATUS_INTERNAL_ERROR;
+       }
+
+       key = smbXsrv_session_local_id_to_key(session_wire_id, key_buf);
+
+       status = dbwrap_parse_record(table->local.db_ctx, key,
+                                    smbXsrv_session_local_fetch_parser,
+                                    &state);
+       if (!NT_STATUS_IS_OK(status)) {
+               return status;
+       }
+       if (!NT_STATUS_IS_OK(state.status)) {
+               return state.status;
+       }
+       if (state.session->global->auth_session_info == NULL) {
+               return NT_STATUS_USER_SESSION_DELETED;
+       }
+
+       *session = state.session;
+       return NT_STATUS_OK;
 }
 
 NTSTATUS smb2srv_session_table_init(struct smbXsrv_connection *conn)
@@ -1735,6 +2194,8 @@ NTSTATUS smb2srv_session_table_init(struct smbXsrv_connection *conn)
 }
 
 static NTSTATUS smb2srv_session_lookup_raw(struct smbXsrv_session_table *table,
+                                          /* conn: optional */
+                                          struct smbXsrv_connection *conn,
                                           uint64_t session_id, NTTIME now,
                                           struct smbXsrv_session **session)
 {
@@ -1745,15 +2206,26 @@ static NTSTATUS smb2srv_session_lookup_raw(struct smbXsrv_session_table *table,
                return NT_STATUS_USER_SESSION_DELETED;
        }
 
-       return smbXsrv_session_local_lookup(table, local_id, now, session);
+       return smbXsrv_session_local_lookup(table, conn, local_id, now,
+                                           session);
 }
 
-NTSTATUS smb2srv_session_lookup(struct smbXsrv_connection *conn,
-                               uint64_t session_id, NTTIME now,
-                               struct smbXsrv_session **session)
+NTSTATUS smb2srv_session_lookup_conn(struct smbXsrv_connection *conn,
+                                    uint64_t session_id, NTTIME now,
+                                    struct smbXsrv_session **session)
 {
        struct smbXsrv_session_table *table = conn->client->session_table;
-       return smb2srv_session_lookup_raw(table, session_id, now, session);
+       return smb2srv_session_lookup_raw(table, conn, session_id, now,
+                                         session);
+}
+
+NTSTATUS smb2srv_session_lookup_client(struct smbXsrv_client *client,
+                                      uint64_t session_id, NTTIME now,
+                                      struct smbXsrv_session **session)
+{
+       struct smbXsrv_session_table *table = client->session_table;
+       return smb2srv_session_lookup_raw(table, NULL, session_id, now,
+                                         session);
 }
 
 struct smbXsrv_session_global_traverse_state {
@@ -1785,7 +2257,7 @@ static int smbXsrv_session_global_traverse_fn(struct db_record *rec, void *data)
 
        if (global_blob.version != SMBXSRV_VERSION_0) {
                DEBUG(1,("Invalid record in smbXsrv_session_global.tdb:"
-                        "key '%s' unsuported version - %d\n",
+                        "key '%s' unsupported version - %d\n",
                         hex_encode_talloc(frame, key.dptr, key.dsize),
                         (int)global_blob.version));
                goto done;
@@ -1811,7 +2283,7 @@ NTSTATUS smbXsrv_session_global_traverse(
        };
 
        become_root();
-       status = smbXsrv_session_global_init();
+       status = smbXsrv_session_global_init(NULL);
        if (!NT_STATUS_IS_OK(status)) {
                unbecome_root();
                DEBUG(0, ("Failed to initialize session_global: %s\n",