2 Unix SMB/CIFS implementation.
4 smbd-specific dcerpc server code
6 Copyright (C) Andrew Tridgell 2003-2005
7 Copyright (C) Stefan (metze) Metzmacher 2004-2005
8 Copyright (C) Jelmer Vernooij <jelmer@samba.org> 2004,2007
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License as published by
12 the Free Software Foundation; either version 3 of the License, or
13 (at your option) any later version.
15 This program is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 GNU General Public License for more details.
20 You should have received a copy of the GNU General Public License
21 along with this program. If not, see <http://www.gnu.org/licenses/>.
25 #include "librpc/gen_ndr/ndr_dcerpc.h"
26 #include "auth/auth.h"
27 #include "../lib/util/dlinklist.h"
28 #include "rpc_server/dcerpc_server.h"
29 #include "rpc_server/dcerpc_server_proto.h"
30 #include "smbd/service.h"
31 #include "system/filesys.h"
32 #include "lib/socket/socket.h"
33 #include "lib/messaging/irpc.h"
34 #include "system/network.h"
35 #include "lib/socket/netif.h"
36 #include "param/param.h"
37 #include "../lib/tsocket/tsocket.h"
38 #include "librpc/rpc/dcerpc_proto.h"
39 #include "../lib/util/tevent_ntstatus.h"
40 #include "libcli/raw/smb.h"
41 #include "../libcli/named_pipe_auth/npa_tstream.h"
43 struct dcesrv_socket_context {
44 const struct dcesrv_endpoint *endpoint;
45 struct dcesrv_context *dcesrv_ctx;
48 static void dcesrv_terminate_connection(struct dcesrv_connection *dce_conn, const char *reason)
50 struct stream_connection *srv_conn;
51 srv_conn = talloc_get_type(dce_conn->transport.private_data,
52 struct stream_connection);
54 stream_terminate_connection(srv_conn, reason);
57 static void dcesrv_sock_reply_done(struct tevent_req *subreq);
59 struct dcesrv_sock_reply_state {
60 struct dcesrv_connection *dce_conn;
61 struct dcesrv_call_state *call;
65 static void dcesrv_sock_report_output_data(struct dcesrv_connection *dce_conn)
67 struct dcesrv_call_state *call;
69 call = dce_conn->call_list;
70 if (!call || !call->replies) {
74 while (call->replies) {
75 struct data_blob_list_item *rep = call->replies;
76 struct dcesrv_sock_reply_state *substate;
77 struct tevent_req *subreq;
79 substate = talloc(call, struct dcesrv_sock_reply_state);
81 dcesrv_terminate_connection(dce_conn, "no memory");
85 substate->dce_conn = dce_conn;
86 substate->call = NULL;
88 DLIST_REMOVE(call->replies, rep);
90 if (call->replies == NULL) {
91 substate->call = call;
94 substate->iov.iov_base = rep->blob.data;
95 substate->iov.iov_len = rep->blob.length;
97 subreq = tstream_writev_queue_send(substate,
100 dce_conn->send_queue,
103 dcesrv_terminate_connection(dce_conn, "no memory");
106 tevent_req_set_callback(subreq, dcesrv_sock_reply_done,
110 DLIST_REMOVE(call->conn->call_list, call);
111 call->list = DCESRV_LIST_NONE;
114 static void dcesrv_sock_reply_done(struct tevent_req *subreq)
116 struct dcesrv_sock_reply_state *substate = tevent_req_callback_data(subreq,
117 struct dcesrv_sock_reply_state);
121 struct dcesrv_call_state *call = substate->call;
123 ret = tstream_writev_queue_recv(subreq, &sys_errno);
126 status = map_nt_error_from_unix(sys_errno);
127 dcesrv_terminate_connection(substate->dce_conn, nt_errstr(status));
131 talloc_free(substate);
137 static struct socket_address *dcesrv_sock_get_my_addr(struct dcesrv_connection *dcesrv_conn, TALLOC_CTX *mem_ctx)
139 struct stream_connection *srv_conn;
140 srv_conn = talloc_get_type(dcesrv_conn->transport.private_data,
141 struct stream_connection);
143 return socket_get_my_addr(srv_conn->socket, mem_ctx);
146 static struct socket_address *dcesrv_sock_get_peer_addr(struct dcesrv_connection *dcesrv_conn, TALLOC_CTX *mem_ctx)
148 struct stream_connection *srv_conn;
149 srv_conn = talloc_get_type(dcesrv_conn->transport.private_data,
150 struct stream_connection);
152 return socket_get_peer_addr(srv_conn->socket, mem_ctx);
155 struct dcerpc_read_ncacn_packet_state {
157 struct smb_iconv_convenience *smb_iconv_c;
160 struct ncacn_packet *pkt;
163 static int dcerpc_read_ncacn_packet_next_vector(struct tstream_context *stream,
166 struct iovec **_vector,
168 static void dcerpc_read_ncacn_packet_done(struct tevent_req *subreq);
170 static struct tevent_req *dcerpc_read_ncacn_packet_send(TALLOC_CTX *mem_ctx,
171 struct tevent_context *ev,
172 struct tstream_context *stream,
173 struct smb_iconv_convenience *ic)
175 struct tevent_req *req;
176 struct dcerpc_read_ncacn_packet_state *state;
177 struct tevent_req *subreq;
179 req = tevent_req_create(mem_ctx, &state,
180 struct dcerpc_read_ncacn_packet_state);
185 state->caller.smb_iconv_c = ic;
186 state->buffer = data_blob_const(NULL, 0);
187 state->pkt = talloc(state, struct ncacn_packet);
188 if (tevent_req_nomem(state->pkt, req)) {
192 subreq = tstream_readv_pdu_send(state, ev,
194 dcerpc_read_ncacn_packet_next_vector,
196 if (tevent_req_nomem(subreq, req)) {
199 tevent_req_set_callback(subreq, dcerpc_read_ncacn_packet_done, req);
203 tevent_req_post(req, ev);
207 static int dcerpc_read_ncacn_packet_next_vector(struct tstream_context *stream,
210 struct iovec **_vector,
213 struct dcerpc_read_ncacn_packet_state *state =
214 talloc_get_type_abort(private_data,
215 struct dcerpc_read_ncacn_packet_state);
216 struct iovec *vector;
219 if (state->buffer.length == 0) {
220 /* first get enough to read the fragment length */
222 state->buffer.length = DCERPC_FRAG_LEN_OFFSET + 2;
223 state->buffer.data = talloc_array(state, uint8_t,
224 state->buffer.length);
225 if (!state->buffer.data) {
228 } else if (state->buffer.length == (DCERPC_FRAG_LEN_OFFSET + 2)) {
229 /* now read the fragment length and allocate the full buffer */
230 size_t frag_len = dcerpc_get_frag_length(&state->buffer);
232 ofs = state->buffer.length;
234 state->buffer.data = talloc_realloc(state,
237 if (!state->buffer.data) {
240 state->buffer.length = frag_len;
242 /* if we reach this we have a full fragment */
248 /* now create the vector that we want to be filled */
249 vector = talloc_array(mem_ctx, struct iovec, 1);
254 vector[0].iov_base = state->buffer.data + ofs;
255 vector[0].iov_len = state->buffer.length - ofs;
262 static void dcerpc_read_ncacn_packet_done(struct tevent_req *subreq)
264 struct tevent_req *req = tevent_req_callback_data(subreq,
266 struct dcerpc_read_ncacn_packet_state *state = tevent_req_data(req,
267 struct dcerpc_read_ncacn_packet_state);
270 struct ndr_pull *ndr;
271 enum ndr_err_code ndr_err;
274 ret = tstream_readv_pdu_recv(subreq, &sys_errno);
277 status = map_nt_error_from_unix(sys_errno);
278 tevent_req_nterror(req, status);
282 ndr = ndr_pull_init_blob(&state->buffer,
284 state->caller.smb_iconv_c);
285 if (tevent_req_nomem(ndr, req)) {
289 if (!(CVAL(ndr->data, DCERPC_DREP_OFFSET) & DCERPC_DREP_LE)) {
290 ndr->flags |= LIBNDR_FLAG_BIGENDIAN;
293 if (CVAL(ndr->data, DCERPC_PFC_OFFSET) & DCERPC_PFC_FLAG_OBJECT_UUID) {
294 ndr->flags |= LIBNDR_FLAG_OBJECT_PRESENT;
297 ndr_err = ndr_pull_ncacn_packet(ndr, NDR_SCALARS|NDR_BUFFERS, state->pkt);
299 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
300 status = ndr_map_error2ntstatus(ndr_err);
301 tevent_req_nterror(req, status);
305 tevent_req_done(req);
308 static NTSTATUS dcerpc_read_ncacn_packet_recv(struct tevent_req *req,
310 struct ncacn_packet **pkt,
313 struct dcerpc_read_ncacn_packet_state *state = tevent_req_data(req,
314 struct dcerpc_read_ncacn_packet_state);
317 if (tevent_req_is_nterror(req, &status)) {
318 tevent_req_received(req);
322 *pkt = talloc_move(mem_ctx, &state->pkt);
324 buffer->data = talloc_move(mem_ctx, &state->buffer.data);
325 buffer->length = state->buffer.length;
328 tevent_req_received(req);
332 static void dcesrv_read_fragment_done(struct tevent_req *subreq);
334 static void dcesrv_sock_accept(struct stream_connection *srv_conn)
337 struct dcesrv_socket_context *dcesrv_sock =
338 talloc_get_type(srv_conn->private_data, struct dcesrv_socket_context);
339 struct dcesrv_connection *dcesrv_conn = NULL;
341 struct tevent_req *subreq;
342 struct loadparm_context *lp_ctx = dcesrv_sock->dcesrv_ctx->lp_ctx;
344 if (!srv_conn->session_info) {
345 status = auth_anonymous_session_info(srv_conn,
348 &srv_conn->session_info);
349 if (!NT_STATUS_IS_OK(status)) {
350 DEBUG(0,("dcesrv_sock_accept: auth_anonymous_session_info failed: %s\n",
352 stream_terminate_connection(srv_conn, nt_errstr(status));
357 status = dcesrv_endpoint_connect(dcesrv_sock->dcesrv_ctx,
359 dcesrv_sock->endpoint,
360 srv_conn->session_info,
364 DCESRV_CALL_STATE_FLAG_MAY_ASYNC,
366 if (!NT_STATUS_IS_OK(status)) {
367 DEBUG(0,("dcesrv_sock_accept: dcesrv_endpoint_connect failed: %s\n",
369 stream_terminate_connection(srv_conn, nt_errstr(status));
373 dcesrv_conn->transport.private_data = srv_conn;
374 dcesrv_conn->transport.report_output_data = dcesrv_sock_report_output_data;
375 dcesrv_conn->transport.get_my_addr = dcesrv_sock_get_my_addr;
376 dcesrv_conn->transport.get_peer_addr = dcesrv_sock_get_peer_addr;
378 TALLOC_FREE(srv_conn->event.fde);
380 dcesrv_conn->send_queue = tevent_queue_create(dcesrv_conn, "dcesrv send queue");
381 if (!dcesrv_conn->send_queue) {
382 status = NT_STATUS_NO_MEMORY;
383 DEBUG(0,("dcesrv_sock_accept: tevent_queue_create(%s)\n",
385 stream_terminate_connection(srv_conn, nt_errstr(status));
389 if (dcesrv_sock->endpoint->ep_description->transport == NCACN_NP) {
390 dcesrv_conn->auth_state.session_key = dcesrv_inherited_session_key;
391 ret = tstream_npa_existing_socket(dcesrv_conn,
392 socket_get_fd(srv_conn->socket),
393 FILE_TYPE_MESSAGE_MODE_PIPE,
394 &dcesrv_conn->stream);
396 ret = tstream_bsd_existing_socket(dcesrv_conn,
397 socket_get_fd(srv_conn->socket),
398 &dcesrv_conn->stream);
401 status = map_nt_error_from_unix(errno);
402 DEBUG(0,("dcesrv_sock_accept: failed to setup tstream: %s\n",
404 stream_terminate_connection(srv_conn, nt_errstr(status));
408 srv_conn->private_data = dcesrv_conn;
410 irpc_add_name(srv_conn->msg_ctx, "rpc_server");
412 subreq = dcerpc_read_ncacn_packet_send(dcesrv_conn,
413 dcesrv_conn->event_ctx,
415 lp_iconv_convenience(lp_ctx));
417 status = NT_STATUS_NO_MEMORY;
418 DEBUG(0,("dcesrv_sock_accept: dcerpc_read_fragment_buffer_send(%s)\n",
420 stream_terminate_connection(srv_conn, nt_errstr(status));
423 tevent_req_set_callback(subreq, dcesrv_read_fragment_done, dcesrv_conn);
428 static void dcesrv_read_fragment_done(struct tevent_req *subreq)
430 struct dcesrv_connection *dce_conn = tevent_req_callback_data(subreq,
431 struct dcesrv_connection);
432 struct ncacn_packet *pkt;
435 struct loadparm_context *lp_ctx = dce_conn->dce_ctx->lp_ctx;
437 status = dcerpc_read_ncacn_packet_recv(subreq, dce_conn,
440 if (!NT_STATUS_IS_OK(status)) {
441 dcesrv_terminate_connection(dce_conn, nt_errstr(status));
445 status = dcesrv_process_ncacn_packet(dce_conn, pkt, buffer);
446 if (!NT_STATUS_IS_OK(status)) {
447 dcesrv_terminate_connection(dce_conn, nt_errstr(status));
451 subreq = dcerpc_read_ncacn_packet_send(dce_conn,
454 lp_iconv_convenience(lp_ctx));
456 status = NT_STATUS_NO_MEMORY;
457 dcesrv_terminate_connection(dce_conn, nt_errstr(status));
460 tevent_req_set_callback(subreq, dcesrv_read_fragment_done, dce_conn);
463 static void dcesrv_sock_recv(struct stream_connection *conn, uint16_t flags)
465 struct dcesrv_connection *dce_conn = talloc_get_type(conn->private_data,
466 struct dcesrv_connection);
467 dcesrv_terminate_connection(dce_conn, "dcesrv_sock_recv triggered");
470 static void dcesrv_sock_send(struct stream_connection *conn, uint16_t flags)
472 struct dcesrv_connection *dce_conn = talloc_get_type(conn->private_data,
473 struct dcesrv_connection);
474 dcesrv_terminate_connection(dce_conn, "dcesrv_sock_send triggered");
478 static const struct stream_server_ops dcesrv_stream_ops = {
480 .accept_connection = dcesrv_sock_accept,
481 .recv_handler = dcesrv_sock_recv,
482 .send_handler = dcesrv_sock_send,
487 static NTSTATUS dcesrv_add_ep_unix(struct dcesrv_context *dce_ctx,
488 struct loadparm_context *lp_ctx,
489 struct dcesrv_endpoint *e,
490 struct tevent_context *event_ctx, const struct model_ops *model_ops)
492 struct dcesrv_socket_context *dcesrv_sock;
496 dcesrv_sock = talloc(event_ctx, struct dcesrv_socket_context);
497 NT_STATUS_HAVE_NO_MEMORY(dcesrv_sock);
499 /* remember the endpoint of this socket */
500 dcesrv_sock->endpoint = e;
501 dcesrv_sock->dcesrv_ctx = talloc_reference(dcesrv_sock, dce_ctx);
503 status = stream_setup_socket(event_ctx, lp_ctx,
504 model_ops, &dcesrv_stream_ops,
505 "unix", e->ep_description->endpoint, &port,
506 lp_socket_options(lp_ctx),
508 if (!NT_STATUS_IS_OK(status)) {
509 DEBUG(0,("service_setup_stream_socket(path=%s) failed - %s\n",
510 e->ep_description->endpoint, nt_errstr(status)));
516 static NTSTATUS dcesrv_add_ep_ncalrpc(struct dcesrv_context *dce_ctx,
517 struct loadparm_context *lp_ctx,
518 struct dcesrv_endpoint *e,
519 struct tevent_context *event_ctx, const struct model_ops *model_ops)
521 struct dcesrv_socket_context *dcesrv_sock;
526 if (!e->ep_description->endpoint) {
527 /* No identifier specified: use DEFAULT.
528 * DO NOT hardcode this value anywhere else. Rather, specify
529 * no endpoint and let the epmapper worry about it. */
530 e->ep_description->endpoint = talloc_strdup(dce_ctx, "DEFAULT");
533 full_path = talloc_asprintf(dce_ctx, "%s/%s", lp_ncalrpc_dir(lp_ctx),
534 e->ep_description->endpoint);
536 dcesrv_sock = talloc(event_ctx, struct dcesrv_socket_context);
537 NT_STATUS_HAVE_NO_MEMORY(dcesrv_sock);
539 /* remember the endpoint of this socket */
540 dcesrv_sock->endpoint = e;
541 dcesrv_sock->dcesrv_ctx = talloc_reference(dcesrv_sock, dce_ctx);
543 status = stream_setup_socket(event_ctx, lp_ctx,
544 model_ops, &dcesrv_stream_ops,
545 "unix", full_path, &port,
546 lp_socket_options(lp_ctx),
548 if (!NT_STATUS_IS_OK(status)) {
549 DEBUG(0,("service_setup_stream_socket(identifier=%s,path=%s) failed - %s\n",
550 e->ep_description->endpoint, full_path, nt_errstr(status)));
555 static NTSTATUS dcesrv_add_ep_np(struct dcesrv_context *dce_ctx,
556 struct loadparm_context *lp_ctx,
557 struct dcesrv_endpoint *e,
558 struct tevent_context *event_ctx, const struct model_ops *model_ops)
560 struct dcesrv_socket_context *dcesrv_sock;
563 if (e->ep_description->endpoint == NULL) {
564 DEBUG(0, ("Endpoint mandatory for named pipes\n"));
565 return NT_STATUS_INVALID_PARAMETER;
568 dcesrv_sock = talloc(event_ctx, struct dcesrv_socket_context);
569 NT_STATUS_HAVE_NO_MEMORY(dcesrv_sock);
571 /* remember the endpoint of this socket */
572 dcesrv_sock->endpoint = e;
573 dcesrv_sock->dcesrv_ctx = talloc_reference(dcesrv_sock, dce_ctx);
575 status = stream_setup_named_pipe(event_ctx, lp_ctx,
576 model_ops, &dcesrv_stream_ops,
577 e->ep_description->endpoint, dcesrv_sock);
578 if (!NT_STATUS_IS_OK(status)) {
579 DEBUG(0,("stream_setup_named_pipe(pipe=%s) failed - %s\n",
580 e->ep_description->endpoint, nt_errstr(status)));
588 add a socket address to the list of events, one event per dcerpc endpoint
590 static NTSTATUS add_socket_rpc_tcp_iface(struct dcesrv_context *dce_ctx, struct dcesrv_endpoint *e,
591 struct tevent_context *event_ctx, const struct model_ops *model_ops,
594 struct dcesrv_socket_context *dcesrv_sock;
598 if (e->ep_description->endpoint) {
599 port = atoi(e->ep_description->endpoint);
602 dcesrv_sock = talloc(event_ctx, struct dcesrv_socket_context);
603 NT_STATUS_HAVE_NO_MEMORY(dcesrv_sock);
605 /* remember the endpoint of this socket */
606 dcesrv_sock->endpoint = e;
607 dcesrv_sock->dcesrv_ctx = talloc_reference(dcesrv_sock, dce_ctx);
609 status = stream_setup_socket(event_ctx, dce_ctx->lp_ctx,
610 model_ops, &dcesrv_stream_ops,
611 "ipv4", address, &port,
612 lp_socket_options(dce_ctx->lp_ctx),
614 if (!NT_STATUS_IS_OK(status)) {
615 DEBUG(0,("service_setup_stream_socket(address=%s,port=%u) failed - %s\n",
616 address, port, nt_errstr(status)));
619 if (e->ep_description->endpoint == NULL) {
620 e->ep_description->endpoint = talloc_asprintf(dce_ctx, "%d", port);
626 static NTSTATUS dcesrv_add_ep_tcp(struct dcesrv_context *dce_ctx,
627 struct loadparm_context *lp_ctx,
628 struct dcesrv_endpoint *e,
629 struct tevent_context *event_ctx, const struct model_ops *model_ops)
633 /* Add TCP/IP sockets */
634 if (lp_interfaces(lp_ctx) && lp_bind_interfaces_only(lp_ctx)) {
637 struct interface *ifaces;
639 load_interfaces(dce_ctx, lp_interfaces(lp_ctx), &ifaces);
641 num_interfaces = iface_count(ifaces);
642 for(i = 0; i < num_interfaces; i++) {
643 const char *address = iface_n_ip(ifaces, i);
644 status = add_socket_rpc_tcp_iface(dce_ctx, e, event_ctx, model_ops, address);
645 NT_STATUS_NOT_OK_RETURN(status);
648 status = add_socket_rpc_tcp_iface(dce_ctx, e, event_ctx, model_ops,
649 lp_socket_address(lp_ctx));
650 NT_STATUS_NOT_OK_RETURN(status);
656 NTSTATUS dcesrv_add_ep(struct dcesrv_context *dce_ctx,
657 struct loadparm_context *lp_ctx,
658 struct dcesrv_endpoint *e,
659 struct tevent_context *event_ctx,
660 const struct model_ops *model_ops)
662 switch (e->ep_description->transport) {
663 case NCACN_UNIX_STREAM:
664 return dcesrv_add_ep_unix(dce_ctx, lp_ctx, e, event_ctx, model_ops);
667 return dcesrv_add_ep_ncalrpc(dce_ctx, lp_ctx, e, event_ctx, model_ops);
670 return dcesrv_add_ep_tcp(dce_ctx, lp_ctx, e, event_ctx, model_ops);
673 return dcesrv_add_ep_np(dce_ctx, lp_ctx, e, event_ctx, model_ops);
676 return NT_STATUS_NOT_SUPPORTED;
681 open the dcerpc server sockets
683 static void dcesrv_task_init(struct task_server *task)
686 struct dcesrv_context *dce_ctx;
687 struct dcesrv_endpoint *e;
689 dcerpc_server_init(task->lp_ctx);
691 task_server_set_title(task, "task[dcesrv]");
693 status = dcesrv_init_context(task->event_ctx,
695 lp_dcerpc_endpoint_servers(task->lp_ctx),
697 if (!NT_STATUS_IS_OK(status)) goto failed;
699 /* Make sure the directory for NCALRPC exists */
700 if (!directory_exist(lp_ncalrpc_dir(task->lp_ctx))) {
701 mkdir(lp_ncalrpc_dir(task->lp_ctx), 0755);
704 for (e=dce_ctx->endpoint_list;e;e=e->next) {
705 status = dcesrv_add_ep(dce_ctx, task->lp_ctx, e, task->event_ctx, task->model_ops);
706 if (!NT_STATUS_IS_OK(status)) goto failed;
711 task_server_terminate(task, "Failed to startup dcerpc server task", true);
714 NTSTATUS server_service_rpc_init(void)
717 return register_server_service("rpc", dcesrv_task_init);