Fix crash when get_gpo_info returns incorrect data.
[Samba.git] / source3 / rpc_client / ndr.c
blob8e03f2e0151f14d498a172e315f2ed88b8fbc146
1 /*
2 Unix SMB/CIFS implementation.
4 libndr interface
6 Copyright (C) Jelmer Vernooij 2006
7 Copyright (C) Volker Lendecke 2009
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
23 #include "includes.h"
25 struct cli_do_rpc_ndr_state {
26 const struct ndr_interface_call *call;
27 prs_struct q_ps, r_ps;
28 void *r;
31 static void cli_do_rpc_ndr_done(struct tevent_req *subreq);
33 struct tevent_req *cli_do_rpc_ndr_send(TALLOC_CTX *mem_ctx,
34 struct tevent_context *ev,
35 struct rpc_pipe_client *cli,
36 const struct ndr_interface_table *table,
37 uint32_t opnum,
38 void *r)
40 struct tevent_req *req, *subreq;
41 struct cli_do_rpc_ndr_state *state;
42 struct ndr_push *push;
43 DATA_BLOB blob;
44 enum ndr_err_code ndr_err;
45 bool ret;
47 req = tevent_req_create(mem_ctx, &state,
48 struct cli_do_rpc_ndr_state);
49 if (req == NULL) {
50 return NULL;
53 if (!ndr_syntax_id_equal(&table->syntax_id, &cli->abstract_syntax)
54 || (opnum >= table->num_calls)) {
55 tevent_req_nterror(req, NT_STATUS_INVALID_PARAMETER);
56 return tevent_req_post(req, ev);
59 state->r = r;
60 state->call = &table->calls[opnum];
62 if (DEBUGLEVEL >= 10) {
63 ndr_print_function_debug(state->call->ndr_print,
64 state->call->name, NDR_IN, r);
67 push = ndr_push_init_ctx(talloc_tos());
68 if (tevent_req_nomem(push, req)) {
69 return tevent_req_post(req, ev);
72 ndr_err = state->call->ndr_push(push, NDR_IN, r);
73 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
74 tevent_req_nterror(req, ndr_map_error2ntstatus(ndr_err));
75 TALLOC_FREE(push);
76 return tevent_req_post(req, ev);
79 blob = ndr_push_blob(push);
80 ret = prs_init_data_blob(&state->q_ps, &blob, state);
81 TALLOC_FREE(push);
83 if (!ret) {
84 tevent_req_nterror(req, NT_STATUS_NO_MEMORY);
85 return tevent_req_post(req, ev);
88 subreq = rpc_api_pipe_req_send(state, ev, cli, opnum, &state->q_ps);
89 if (tevent_req_nomem(subreq, req)) {
90 return tevent_req_post(req, ev);
92 tevent_req_set_callback(subreq, cli_do_rpc_ndr_done, req);
93 return req;
96 static void cli_do_rpc_ndr_done(struct tevent_req *subreq)
98 struct tevent_req *req = tevent_req_callback_data(
99 subreq, struct tevent_req);
100 struct cli_do_rpc_ndr_state *state = tevent_req_data(
101 req, struct cli_do_rpc_ndr_state);
102 NTSTATUS status;
104 status = rpc_api_pipe_req_recv(subreq, state, &state->r_ps);
105 TALLOC_FREE(subreq);
106 if (!NT_STATUS_IS_OK(status)) {
107 tevent_req_nterror(req, status);
108 return;
110 tevent_req_done(req);
113 NTSTATUS cli_do_rpc_ndr_recv(struct tevent_req *req, TALLOC_CTX *mem_ctx)
115 struct cli_do_rpc_ndr_state *state = tevent_req_data(
116 req, struct cli_do_rpc_ndr_state);
117 struct ndr_pull *pull;
118 enum ndr_err_code ndr_err;
119 NTSTATUS status;
120 DATA_BLOB blob;
121 bool ret;
123 if (tevent_req_is_nterror(req, &status)) {
124 return status;
127 ret = prs_data_blob(&state->r_ps, &blob, talloc_tos());
128 if (!ret) {
129 return NT_STATUS_NO_MEMORY;
132 pull = ndr_pull_init_blob(&blob, mem_ctx);
133 if (pull == NULL) {
134 return NT_STATUS_NO_MEMORY;
137 /* have the ndr parser alloc memory for us */
138 pull->flags |= LIBNDR_FLAG_REF_ALLOC;
139 ndr_err = state->call->ndr_pull(pull, NDR_OUT, state->r);
140 TALLOC_FREE(pull);
142 if (NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
143 if (DEBUGLEVEL >= 10) {
144 ndr_print_function_debug(state->call->ndr_print,
145 state->call->name, NDR_OUT,
146 state->r);
148 } else {
149 return ndr_map_error2ntstatus(ndr_err);
152 return NT_STATUS_OK;
155 NTSTATUS cli_do_rpc_ndr(struct rpc_pipe_client *cli,
156 TALLOC_CTX *mem_ctx,
157 const struct ndr_interface_table *table,
158 uint32_t opnum, void *r)
160 TALLOC_CTX *frame = talloc_stackframe();
161 struct event_context *ev;
162 struct tevent_req *req;
163 NTSTATUS status = NT_STATUS_OK;
165 ev = event_context_init(frame);
166 if (ev == NULL) {
167 status = NT_STATUS_NO_MEMORY;
168 goto fail;
171 req = cli_do_rpc_ndr_send(frame, ev, cli, table, opnum, r);
172 if (req == NULL) {
173 status = NT_STATUS_NO_MEMORY;
174 goto fail;
177 if (!tevent_req_poll(req, ev)) {
178 status = map_nt_error_from_unix(errno);
179 goto fail;
182 status = cli_do_rpc_ndr_recv(req, mem_ctx);
184 fail:
185 TALLOC_FREE(frame);
186 return status;