2 Unix SMB/CIFS implementation.
3 Connect to 445 and 139/nbsesssetup
4 Copyright (C) Volker Lendecke 2010
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "../lib/async_req/async_sock.h"
22 #include "../lib/util/tevent_ntstatus.h"
23 #include "../lib/util/tevent_unix.h"
25 #include "async_smb.h"
26 #include "../libcli/smb/read_smb.h"
27 #include "libsmb/nmblib.h"
29 struct cli_session_request_state
{
30 struct tevent_context
*ev
;
34 uint8_t nb_session_response
;
37 static void cli_session_request_sent(struct tevent_req
*subreq
);
38 static void cli_session_request_recvd(struct tevent_req
*subreq
);
40 static struct tevent_req
*cli_session_request_send(TALLOC_CTX
*mem_ctx
,
41 struct tevent_context
*ev
,
43 const struct nmb_name
*called
,
44 const struct nmb_name
*calling
)
46 struct tevent_req
*req
, *subreq
;
47 struct cli_session_request_state
*state
;
49 req
= tevent_req_create(mem_ctx
, &state
,
50 struct cli_session_request_state
);
57 state
->iov
[1].iov_base
= name_mangle(
58 state
, called
->name
, called
->name_type
);
59 if (tevent_req_nomem(state
->iov
[1].iov_base
, req
)) {
60 return tevent_req_post(req
, ev
);
62 state
->iov
[1].iov_len
= name_len(
63 (unsigned char *)state
->iov
[1].iov_base
,
64 talloc_get_size(state
->iov
[1].iov_base
));
66 state
->iov
[2].iov_base
= name_mangle(
67 state
, calling
->name
, calling
->name_type
);
68 if (tevent_req_nomem(state
->iov
[2].iov_base
, req
)) {
69 return tevent_req_post(req
, ev
);
71 state
->iov
[2].iov_len
= name_len(
72 (unsigned char *)state
->iov
[2].iov_base
,
73 talloc_get_size(state
->iov
[2].iov_base
));
75 _smb_setlen(((char *)&state
->len_hdr
),
76 state
->iov
[1].iov_len
+ state
->iov
[2].iov_len
);
77 SCVAL((char *)&state
->len_hdr
, 0, 0x81);
79 state
->iov
[0].iov_base
= &state
->len_hdr
;
80 state
->iov
[0].iov_len
= sizeof(state
->len_hdr
);
82 subreq
= writev_send(state
, ev
, NULL
, sock
, true, state
->iov
, 3);
83 if (tevent_req_nomem(subreq
, req
)) {
84 return tevent_req_post(req
, ev
);
86 tevent_req_set_callback(subreq
, cli_session_request_sent
, req
);
90 static void cli_session_request_sent(struct tevent_req
*subreq
)
92 struct tevent_req
*req
= tevent_req_callback_data(
93 subreq
, struct tevent_req
);
94 struct cli_session_request_state
*state
= tevent_req_data(
95 req
, struct cli_session_request_state
);
99 ret
= writev_recv(subreq
, &err
);
102 tevent_req_error(req
, err
);
105 subreq
= read_smb_send(state
, state
->ev
, state
->sock
);
106 if (tevent_req_nomem(subreq
, req
)) {
109 tevent_req_set_callback(subreq
, cli_session_request_recvd
, req
);
112 static void cli_session_request_recvd(struct tevent_req
*subreq
)
114 struct tevent_req
*req
= tevent_req_callback_data(
115 subreq
, struct tevent_req
);
116 struct cli_session_request_state
*state
= tevent_req_data(
117 req
, struct cli_session_request_state
);
122 ret
= read_smb_recv(subreq
, talloc_tos(), &buf
, &err
);
130 tevent_req_error(req
, err
);
134 * In case of an error there is more information in the data
135 * portion according to RFC1002. We're not subtle enough to
136 * respond to the different error conditions, so drop the
139 state
->nb_session_response
= CVAL(buf
, 0);
140 tevent_req_done(req
);
143 static bool cli_session_request_recv(struct tevent_req
*req
, int *err
, uint8_t *resp
)
145 struct cli_session_request_state
*state
= tevent_req_data(
146 req
, struct cli_session_request_state
);
148 if (tevent_req_is_unix_error(req
, err
)) {
151 *resp
= state
->nb_session_response
;
155 struct nb_connect_state
{
156 struct tevent_context
*ev
;
157 const struct sockaddr_storage
*addr
;
158 const char *called_name
;
160 struct tevent_req
*session_subreq
;
161 struct nmb_name called
;
162 struct nmb_name calling
;
165 static void nb_connect_cleanup(struct tevent_req
*req
,
166 enum tevent_req_state req_state
);
167 static void nb_connect_connected(struct tevent_req
*subreq
);
168 static void nb_connect_done(struct tevent_req
*subreq
);
170 static struct tevent_req
*nb_connect_send(TALLOC_CTX
*mem_ctx
,
171 struct tevent_context
*ev
,
172 const struct sockaddr_storage
*addr
,
173 const char *called_name
,
175 const char *calling_name
,
178 struct tevent_req
*req
, *subreq
;
179 struct nb_connect_state
*state
;
181 req
= tevent_req_create(mem_ctx
, &state
, struct nb_connect_state
);
186 state
->called_name
= called_name
;
190 make_nmb_name(&state
->called
, called_name
, called_type
);
191 make_nmb_name(&state
->calling
, calling_name
, calling_type
);
193 tevent_req_set_cleanup_fn(req
, nb_connect_cleanup
);
195 subreq
= open_socket_out_send(state
, ev
, addr
, NBT_SMB_PORT
, 5000);
196 if (tevent_req_nomem(subreq
, req
)) {
197 return tevent_req_post(req
, ev
);
199 tevent_req_set_callback(subreq
, nb_connect_connected
, req
);
203 static void nb_connect_cleanup(struct tevent_req
*req
,
204 enum tevent_req_state req_state
)
206 struct nb_connect_state
*state
= tevent_req_data(
207 req
, struct nb_connect_state
);
210 * we need to free a pending request before closing the
211 * socket, see bug #11141
213 TALLOC_FREE(state
->session_subreq
);
215 if (req_state
== TEVENT_REQ_DONE
) {
217 * we keep the socket open for the caller to use
222 if (state
->sock
!= -1) {
230 static void nb_connect_connected(struct tevent_req
*subreq
)
232 struct tevent_req
*req
= tevent_req_callback_data(
233 subreq
, struct tevent_req
);
234 struct nb_connect_state
*state
= tevent_req_data(
235 req
, struct nb_connect_state
);
238 status
= open_socket_out_recv(subreq
, &state
->sock
);
240 if (!NT_STATUS_IS_OK(status
)) {
241 tevent_req_nterror(req
, status
);
244 subreq
= cli_session_request_send(state
, state
->ev
, state
->sock
,
245 &state
->called
, &state
->calling
);
246 if (tevent_req_nomem(subreq
, req
)) {
249 tevent_req_set_callback(subreq
, nb_connect_done
, req
);
250 state
->session_subreq
= subreq
;
253 static void nb_connect_done(struct tevent_req
*subreq
)
255 struct tevent_req
*req
= tevent_req_callback_data(
256 subreq
, struct tevent_req
);
257 struct nb_connect_state
*state
= tevent_req_data(
258 req
, struct nb_connect_state
);
263 state
->session_subreq
= NULL
;
265 ret
= cli_session_request_recv(subreq
, &err
, &resp
);
268 tevent_req_nterror(req
, map_nt_error_from_unix(err
));
273 * RFC1002: 0x82 - POSITIVE SESSION RESPONSE
278 * The server did not like our session request
283 if (strequal(state
->called_name
, "*SMBSERVER")) {
285 * Here we could try a name status request and
286 * use the first 0x20 type name.
289 req
, NT_STATUS_RESOURCE_NAME_NOT_FOUND
);
294 * We could be subtle and distinguish between
295 * different failure modes, but what we do here
296 * instead is just retry with *SMBSERVER type 0x20.
298 state
->called_name
= "*SMBSERVER";
299 make_nmb_name(&state
->called
, state
->called_name
, 0x20);
301 subreq
= open_socket_out_send(state
, state
->ev
, state
->addr
,
303 if (tevent_req_nomem(subreq
, req
)) {
306 tevent_req_set_callback(subreq
, nb_connect_connected
, req
);
310 tevent_req_done(req
);
314 static NTSTATUS
nb_connect_recv(struct tevent_req
*req
, int *sock
)
316 struct nb_connect_state
*state
= tevent_req_data(
317 req
, struct nb_connect_state
);
320 if (tevent_req_is_nterror(req
, &status
)) {
321 tevent_req_received(req
);
326 tevent_req_received(req
);
330 struct smbsock_connect_state
{
331 struct tevent_context
*ev
;
332 const struct sockaddr_storage
*addr
;
333 const char *called_name
;
335 const char *calling_name
;
336 uint8_t calling_type
;
337 struct tevent_req
*req_139
;
338 struct tevent_req
*req_445
;
343 static void smbsock_connect_cleanup(struct tevent_req
*req
,
344 enum tevent_req_state req_state
);
345 static void smbsock_connect_connected(struct tevent_req
*subreq
);
346 static void smbsock_connect_do_139(struct tevent_req
*subreq
);
348 struct tevent_req
*smbsock_connect_send(TALLOC_CTX
*mem_ctx
,
349 struct tevent_context
*ev
,
350 const struct sockaddr_storage
*addr
,
352 const char *called_name
,
354 const char *calling_name
,
357 struct tevent_req
*req
;
358 struct smbsock_connect_state
*state
;
360 req
= tevent_req_create(mem_ctx
, &state
, struct smbsock_connect_state
);
368 (called_name
!= NULL
) ? called_name
: "*SMBSERVER";
370 (called_type
!= -1) ? called_type
: 0x20;
371 state
->calling_name
=
372 (calling_name
!= NULL
) ? calling_name
: lp_netbios_name();
373 state
->calling_type
=
374 (calling_type
!= -1) ? calling_type
: 0x00;
376 tevent_req_set_cleanup_fn(req
, smbsock_connect_cleanup
);
378 if (port
== NBT_SMB_PORT
) {
379 state
->req_139
= nb_connect_send(state
, state
->ev
, state
->addr
,
383 state
->calling_type
);
384 if (tevent_req_nomem(state
->req_139
, req
)) {
385 return tevent_req_post(req
, ev
);
387 tevent_req_set_callback(
388 state
->req_139
, smbsock_connect_connected
, req
);
392 state
->req_445
= open_socket_out_send(state
, ev
, addr
, port
,
394 if (tevent_req_nomem(state
->req_445
, req
)) {
395 return tevent_req_post(req
, ev
);
397 tevent_req_set_callback(
398 state
->req_445
, smbsock_connect_connected
, req
);
406 state
->req_445
= open_socket_out_send(state
, ev
, addr
, TCP_SMB_PORT
, 5000);
407 if (tevent_req_nomem(state
->req_445
, req
)) {
408 return tevent_req_post(req
, ev
);
410 tevent_req_set_callback(state
->req_445
, smbsock_connect_connected
,
414 * After 5 msecs, fire the 139 (NBT) request
416 state
->req_139
= tevent_wakeup_send(
417 state
, ev
, timeval_current_ofs(0, 5000));
418 if (tevent_req_nomem(state
->req_139
, req
)) {
419 TALLOC_FREE(state
->req_445
);
420 return tevent_req_post(req
, ev
);
422 tevent_req_set_callback(state
->req_139
, smbsock_connect_do_139
,
427 static void smbsock_connect_cleanup(struct tevent_req
*req
,
428 enum tevent_req_state req_state
)
430 struct smbsock_connect_state
*state
= tevent_req_data(
431 req
, struct smbsock_connect_state
);
434 * we need to free a pending request before closing the
435 * socket, see bug #11141
437 TALLOC_FREE(state
->req_445
);
438 TALLOC_FREE(state
->req_139
);
440 if (req_state
== TEVENT_REQ_DONE
) {
442 * we keep the socket open for the caller to use
447 if (state
->sock
!= -1) {
455 static void smbsock_connect_do_139(struct tevent_req
*subreq
)
457 struct tevent_req
*req
= tevent_req_callback_data(
458 subreq
, struct tevent_req
);
459 struct smbsock_connect_state
*state
= tevent_req_data(
460 req
, struct smbsock_connect_state
);
463 ret
= tevent_wakeup_recv(subreq
);
466 tevent_req_nterror(req
, NT_STATUS_INTERNAL_ERROR
);
469 state
->req_139
= nb_connect_send(state
, state
->ev
, state
->addr
,
473 state
->calling_type
);
474 if (tevent_req_nomem(state
->req_139
, req
)) {
477 tevent_req_set_callback(state
->req_139
, smbsock_connect_connected
,
481 static void smbsock_connect_connected(struct tevent_req
*subreq
)
483 struct tevent_req
*req
= tevent_req_callback_data(
484 subreq
, struct tevent_req
);
485 struct smbsock_connect_state
*state
= tevent_req_data(
486 req
, struct smbsock_connect_state
);
487 struct tevent_req
*unfinished_req
;
490 if (subreq
== state
->req_445
) {
492 status
= open_socket_out_recv(subreq
, &state
->sock
);
493 TALLOC_FREE(state
->req_445
);
494 unfinished_req
= state
->req_139
;
495 state
->port
= TCP_SMB_PORT
;
497 } else if (subreq
== state
->req_139
) {
499 status
= nb_connect_recv(subreq
, &state
->sock
);
500 TALLOC_FREE(state
->req_139
);
501 unfinished_req
= state
->req_445
;
502 state
->port
= NBT_SMB_PORT
;
505 tevent_req_nterror(req
, NT_STATUS_INTERNAL_ERROR
);
509 if (NT_STATUS_IS_OK(status
)) {
510 TALLOC_FREE(unfinished_req
);
511 state
->req_139
= NULL
;
512 state
->req_445
= NULL
;
513 tevent_req_done(req
);
516 if (unfinished_req
== NULL
) {
518 * Both requests failed
520 tevent_req_nterror(req
, status
);
524 * Do nothing, wait for the second request to come here.
528 NTSTATUS
smbsock_connect_recv(struct tevent_req
*req
, int *sock
,
531 struct smbsock_connect_state
*state
= tevent_req_data(
532 req
, struct smbsock_connect_state
);
535 if (tevent_req_is_nterror(req
, &status
)) {
536 tevent_req_received(req
);
541 if (ret_port
!= NULL
) {
542 *ret_port
= state
->port
;
544 tevent_req_received(req
);
548 NTSTATUS
smbsock_connect(const struct sockaddr_storage
*addr
, uint16_t port
,
549 const char *called_name
, int called_type
,
550 const char *calling_name
, int calling_type
,
551 int *pfd
, uint16_t *ret_port
, int sec_timeout
)
553 TALLOC_CTX
*frame
= talloc_stackframe();
554 struct tevent_context
*ev
;
555 struct tevent_req
*req
;
556 NTSTATUS status
= NT_STATUS_NO_MEMORY
;
558 ev
= samba_tevent_context_init(frame
);
562 req
= smbsock_connect_send(frame
, ev
, addr
, port
,
563 called_name
, called_type
,
564 calling_name
, calling_type
);
568 if ((sec_timeout
!= 0) &&
569 !tevent_req_set_endtime(
570 req
, ev
, timeval_current_ofs(sec_timeout
, 0))) {
573 if (!tevent_req_poll_ntstatus(req
, ev
, &status
)) {
576 status
= smbsock_connect_recv(req
, pfd
, ret_port
);
582 struct smbsock_any_connect_state
{
583 struct tevent_context
*ev
;
584 const struct sockaddr_storage
*addrs
;
585 const char **called_names
;
587 const char **calling_names
;
592 struct tevent_req
**requests
;
597 uint16_t chosen_port
;
601 static void smbsock_any_connect_cleanup(struct tevent_req
*req
,
602 enum tevent_req_state req_state
);
603 static bool smbsock_any_connect_send_next(
604 struct tevent_req
*req
, struct smbsock_any_connect_state
*state
);
605 static void smbsock_any_connect_trynext(struct tevent_req
*subreq
);
606 static void smbsock_any_connect_connected(struct tevent_req
*subreq
);
608 struct tevent_req
*smbsock_any_connect_send(TALLOC_CTX
*mem_ctx
,
609 struct tevent_context
*ev
,
610 const struct sockaddr_storage
*addrs
,
611 const char **called_names
,
613 const char **calling_names
,
615 size_t num_addrs
, uint16_t port
)
617 struct tevent_req
*req
, *subreq
;
618 struct smbsock_any_connect_state
*state
;
620 req
= tevent_req_create(mem_ctx
, &state
,
621 struct smbsock_any_connect_state
);
626 state
->addrs
= addrs
;
627 state
->num_addrs
= num_addrs
;
628 state
->called_names
= called_names
;
629 state
->called_types
= called_types
;
630 state
->calling_names
= calling_names
;
631 state
->calling_types
= calling_types
;
635 tevent_req_set_cleanup_fn(req
, smbsock_any_connect_cleanup
);
637 if (num_addrs
== 0) {
638 tevent_req_nterror(req
, NT_STATUS_INVALID_PARAMETER
);
639 return tevent_req_post(req
, ev
);
642 state
->requests
= talloc_zero_array(state
, struct tevent_req
*,
644 if (tevent_req_nomem(state
->requests
, req
)) {
645 return tevent_req_post(req
, ev
);
647 if (!smbsock_any_connect_send_next(req
, state
)) {
648 return tevent_req_post(req
, ev
);
650 if (state
->num_sent
>= state
->num_addrs
) {
653 subreq
= tevent_wakeup_send(state
, ev
, timeval_current_ofs(0, 10000));
654 if (tevent_req_nomem(subreq
, req
)) {
655 return tevent_req_post(req
, ev
);
657 tevent_req_set_callback(subreq
, smbsock_any_connect_trynext
, req
);
661 static void smbsock_any_connect_cleanup(struct tevent_req
*req
,
662 enum tevent_req_state req_state
)
664 struct smbsock_any_connect_state
*state
= tevent_req_data(
665 req
, struct smbsock_any_connect_state
);
667 TALLOC_FREE(state
->requests
);
669 if (req_state
== TEVENT_REQ_DONE
) {
671 * Keep the socket open for the caller.
676 if (state
->fd
!= -1) {
682 static void smbsock_any_connect_trynext(struct tevent_req
*subreq
)
684 struct tevent_req
*req
= tevent_req_callback_data(
685 subreq
, struct tevent_req
);
686 struct smbsock_any_connect_state
*state
= tevent_req_data(
687 req
, struct smbsock_any_connect_state
);
690 ret
= tevent_wakeup_recv(subreq
);
693 tevent_req_nterror(req
, NT_STATUS_INTERNAL_ERROR
);
696 if (!smbsock_any_connect_send_next(req
, state
)) {
699 if (state
->num_sent
>= state
->num_addrs
) {
702 subreq
= tevent_wakeup_send(state
, state
->ev
,
703 tevent_timeval_set(0, 10000));
704 if (tevent_req_nomem(subreq
, req
)) {
707 tevent_req_set_callback(subreq
, smbsock_any_connect_trynext
, req
);
710 static bool smbsock_any_connect_send_next(
711 struct tevent_req
*req
, struct smbsock_any_connect_state
*state
)
713 struct tevent_req
*subreq
;
715 if (state
->num_sent
>= state
->num_addrs
) {
716 tevent_req_nterror(req
, NT_STATUS_INTERNAL_ERROR
);
719 subreq
= smbsock_connect_send(
720 state
->requests
, state
->ev
, &state
->addrs
[state
->num_sent
],
722 (state
->called_names
!= NULL
)
723 ? state
->called_names
[state
->num_sent
] : NULL
,
724 (state
->called_types
!= NULL
)
725 ? state
->called_types
[state
->num_sent
] : -1,
726 (state
->calling_names
!= NULL
)
727 ? state
->calling_names
[state
->num_sent
] : NULL
,
728 (state
->calling_types
!= NULL
)
729 ? state
->calling_types
[state
->num_sent
] : -1);
730 if (tevent_req_nomem(subreq
, req
)) {
733 tevent_req_set_callback(subreq
, smbsock_any_connect_connected
, req
);
735 state
->requests
[state
->num_sent
] = subreq
;
736 state
->num_sent
+= 1;
741 static void smbsock_any_connect_connected(struct tevent_req
*subreq
)
743 struct tevent_req
*req
= tevent_req_callback_data(
744 subreq
, struct tevent_req
);
745 struct smbsock_any_connect_state
*state
= tevent_req_data(
746 req
, struct smbsock_any_connect_state
);
749 uint16_t chosen_port
;
751 size_t chosen_index
= 0;
753 for (i
=0; i
<state
->num_sent
; i
++) {
754 if (state
->requests
[i
] == subreq
) {
759 if (i
== state
->num_sent
) {
760 tevent_req_nterror(req
, NT_STATUS_INTERNAL_ERROR
);
764 status
= smbsock_connect_recv(subreq
, &fd
, &chosen_port
);
767 state
->requests
[chosen_index
] = NULL
;
769 if (NT_STATUS_IS_OK(status
)) {
771 * tevent_req_done() will kill all the other requests
772 * via smbsock_any_connect_cleanup().
775 state
->chosen_port
= chosen_port
;
776 state
->chosen_index
= chosen_index
;
777 tevent_req_done(req
);
781 state
->num_received
+= 1;
782 if (state
->num_received
< state
->num_addrs
) {
784 * More addrs pending, wait for the others
790 * This is the last response, none succeeded.
792 tevent_req_nterror(req
, status
);
796 NTSTATUS
smbsock_any_connect_recv(struct tevent_req
*req
, int *pfd
,
797 size_t *chosen_index
,
798 uint16_t *chosen_port
)
800 struct smbsock_any_connect_state
*state
= tevent_req_data(
801 req
, struct smbsock_any_connect_state
);
804 if (tevent_req_is_nterror(req
, &status
)) {
805 tevent_req_received(req
);
810 if (chosen_index
!= NULL
) {
811 *chosen_index
= state
->chosen_index
;
813 if (chosen_port
!= NULL
) {
814 *chosen_port
= state
->chosen_port
;
816 tevent_req_received(req
);
820 NTSTATUS
smbsock_any_connect(const struct sockaddr_storage
*addrs
,
821 const char **called_names
,
823 const char **calling_names
,
828 int *pfd
, size_t *chosen_index
,
829 uint16_t *chosen_port
)
831 TALLOC_CTX
*frame
= talloc_stackframe();
832 struct tevent_context
*ev
;
833 struct tevent_req
*req
;
834 NTSTATUS status
= NT_STATUS_NO_MEMORY
;
836 ev
= samba_tevent_context_init(frame
);
840 req
= smbsock_any_connect_send(frame
, ev
, addrs
,
841 called_names
, called_types
,
842 calling_names
, calling_types
,
847 if ((sec_timeout
!= 0) &&
848 !tevent_req_set_endtime(
849 req
, ev
, timeval_current_ofs(sec_timeout
, 0))) {
852 if (!tevent_req_poll_ntstatus(req
, ev
, &status
)) {
855 status
= smbsock_any_connect_recv(req
, pfd
, chosen_index
, chosen_port
);