gpo: Test gpo hourly scripts apply
[Samba.git] / librpc / rpc / rpc_common.h
bloba606a29ed317acbff11a828fc05ccf5744b0a3e1
1 /*
2 Unix SMB/CIFS implementation.
4 Copyright (C) Stefan Metzmacher 2010-2011
5 Copyright (C) Andrew Tridgell 2010-2011
6 Copyright (C) Simo Sorce 2010
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #ifndef __DEFAULT_LIBRPC_RPCCOMMON_H__
23 #define __DEFAULT_LIBRPC_RPCCOMMON_H__
25 #include "gen_ndr/dcerpc.h"
26 #include "lib/util/attr.h"
28 struct dcerpc_binding_handle;
29 struct GUID;
30 struct ndr_interface_table;
31 struct ndr_interface_call;
32 struct ndr_push;
33 struct ndr_pull;
34 struct ncacn_packet;
35 struct epm_floor;
36 struct epm_tower;
37 struct tevent_context;
38 struct tstream_context;
39 struct gensec_security;
41 enum dcerpc_transport_t {
42 NCA_UNKNOWN, NCACN_NP, NCACN_IP_TCP, NCACN_IP_UDP, NCACN_VNS_IPC,
43 NCACN_VNS_SPP, NCACN_AT_DSP, NCADG_AT_DDP, NCALRPC, NCACN_UNIX_STREAM,
44 NCADG_UNIX_DGRAM, NCACN_HTTP, NCADG_IPX, NCACN_SPX, NCACN_INTERNAL };
46 /** this describes a binding to a particular transport/pipe */
47 struct dcerpc_binding;
49 /* dcerpc pipe flags */
50 #define DCERPC_DEBUG_PRINT_IN (1<<0)
51 #define DCERPC_DEBUG_PRINT_OUT (1<<1)
52 #define DCERPC_DEBUG_PRINT_BOTH (DCERPC_DEBUG_PRINT_IN | DCERPC_DEBUG_PRINT_OUT)
54 #define DCERPC_DEBUG_VALIDATE_IN (1<<2)
55 #define DCERPC_DEBUG_VALIDATE_OUT (1<<3)
56 #define DCERPC_DEBUG_VALIDATE_BOTH (DCERPC_DEBUG_VALIDATE_IN | DCERPC_DEBUG_VALIDATE_OUT)
58 #define DCERPC_CONNECT (1<<4)
59 #define DCERPC_SIGN (1<<5)
60 #define DCERPC_SEAL (1<<6)
62 #define DCERPC_PUSH_BIGENDIAN (1<<7)
63 #define DCERPC_PULL_BIGENDIAN (1<<8)
65 #define DCERPC_SCHANNEL (1<<9)
67 #define DCERPC_ANON_FALLBACK (1<<10)
69 /* use a 128 bit session key */
70 #define DCERPC_SCHANNEL_128 (1<<12)
72 /* check incoming pad bytes */
73 #define DCERPC_DEBUG_PAD_CHECK (1<<13)
75 /* set LIBNDR_FLAG_REF_ALLOC flag when decoding NDR */
76 #define DCERPC_NDR_REF_ALLOC (1<<14)
78 #define DCERPC_AUTH_OPTIONS (DCERPC_SEAL|DCERPC_SIGN|DCERPC_SCHANNEL|DCERPC_AUTH_SPNEGO|DCERPC_AUTH_KRB5|DCERPC_AUTH_NTLM)
80 /* select spnego auth */
81 #define DCERPC_AUTH_SPNEGO (1<<15)
83 /* select krb5 auth */
84 #define DCERPC_AUTH_KRB5 (1<<16)
86 #define DCERPC_SMB2 (1<<17)
88 /* select NTLM auth */
89 #define DCERPC_AUTH_NTLM (1<<18)
91 /* this triggers the DCERPC_PFC_FLAG_CONC_MPX flag in the bind request */
92 #define DCERPC_CONCURRENT_MULTIPLEX (1<<19)
94 /* this indicates DCERPC_PFC_FLAG_SUPPORT_HEADER_SIGN flag was negotiated */
95 #define DCERPC_HEADER_SIGNING (1<<20)
97 /* use NDR64 transport */
98 #define DCERPC_NDR64 (1<<21)
100 /* handle upgrades or downgrades automatically */
101 #define DCERPC_SCHANNEL_AUTO (1<<23)
103 /* use aes schannel with hmac-sh256 session key */
104 #define DCERPC_SCHANNEL_AES (1<<24)
106 /* this triggers the DCERPC_PFC_FLAG_SUPPORT_HEADER_SIGN flag in the bind request */
107 #define DCERPC_PROPOSE_HEADER_SIGNING (1<<25)
109 #define DCERPC_PACKET (1<<26)
111 #define DCERPC_SMB1 (1<<27)
113 /* The following definitions come from ../librpc/rpc/dcerpc_error.c */
115 const char *dcerpc_errstr(TALLOC_CTX *mem_ctx, uint32_t fault_code);
116 NTSTATUS dcerpc_fault_to_nt_status(uint32_t fault_code);
117 uint32_t dcerpc_fault_from_nt_status(NTSTATUS nt_status);
119 /* The following definitions come from ../librpc/rpc/binding.c */
121 const char *epm_floor_string(TALLOC_CTX *mem_ctx, struct epm_floor *epm_floor);
122 char *dcerpc_floor_get_rhs_data(TALLOC_CTX *mem_ctx, struct epm_floor *epm_floor);
123 enum dcerpc_transport_t dcerpc_transport_by_endpoint_protocol(int prot);
124 struct dcerpc_binding *dcerpc_binding_dup(TALLOC_CTX *mem_ctx,
125 const struct dcerpc_binding *b);
126 NTSTATUS dcerpc_binding_build_tower(TALLOC_CTX *mem_ctx,
127 const struct dcerpc_binding *binding,
128 struct epm_tower *tower);
129 NTSTATUS dcerpc_binding_from_tower(TALLOC_CTX *mem_ctx,
130 struct epm_tower *tower,
131 struct dcerpc_binding **b_out);
132 NTSTATUS dcerpc_parse_binding(TALLOC_CTX *mem_ctx, const char *s, struct dcerpc_binding **b_out);
133 char *dcerpc_binding_string(TALLOC_CTX *mem_ctx, const struct dcerpc_binding *b);
134 struct GUID dcerpc_binding_get_object(const struct dcerpc_binding *b);
135 NTSTATUS dcerpc_binding_set_object(struct dcerpc_binding *b,
136 struct GUID object);
137 enum dcerpc_transport_t dcerpc_binding_get_transport(const struct dcerpc_binding *b);
138 NTSTATUS dcerpc_binding_set_transport(struct dcerpc_binding *b,
139 enum dcerpc_transport_t transport);
140 void dcerpc_binding_get_auth_info(const struct dcerpc_binding *b,
141 enum dcerpc_AuthType *_auth_type,
142 enum dcerpc_AuthLevel *_auth_level);
143 uint32_t dcerpc_binding_get_assoc_group_id(const struct dcerpc_binding *b);
144 NTSTATUS dcerpc_binding_set_assoc_group_id(struct dcerpc_binding *b,
145 uint32_t assoc_group_id);
146 struct ndr_syntax_id dcerpc_binding_get_abstract_syntax(const struct dcerpc_binding *b);
147 NTSTATUS dcerpc_binding_set_abstract_syntax(struct dcerpc_binding *b,
148 const struct ndr_syntax_id *syntax);
149 const char *dcerpc_binding_get_string_option(const struct dcerpc_binding *b,
150 const char *name);
151 char *dcerpc_binding_copy_string_option(TALLOC_CTX *mem_ctx,
152 const struct dcerpc_binding *b,
153 const char *name);
154 NTSTATUS dcerpc_binding_set_string_option(struct dcerpc_binding *b,
155 const char *name,
156 const char *value);
157 uint32_t dcerpc_binding_get_flags(const struct dcerpc_binding *b);
158 NTSTATUS dcerpc_binding_set_flags(struct dcerpc_binding *b,
159 uint32_t additional,
160 uint32_t clear);
161 NTSTATUS dcerpc_floor_get_lhs_data(const struct epm_floor *epm_floor, struct ndr_syntax_id *syntax);
162 const char *derpc_transport_string_by_transport(enum dcerpc_transport_t t);
163 enum dcerpc_transport_t dcerpc_transport_by_name(const char *name);
164 enum dcerpc_transport_t dcerpc_transport_by_tower(const struct epm_tower *tower);
166 /* The following definitions come from ../librpc/rpc/dcerpc_util.c */
168 void dcerpc_set_frag_length(DATA_BLOB *blob, uint16_t v);
169 uint16_t dcerpc_get_frag_length(const DATA_BLOB *blob);
170 void dcerpc_set_auth_length(DATA_BLOB *blob, uint16_t v);
171 uint16_t dcerpc_get_auth_length(const DATA_BLOB *blob);
172 uint8_t dcerpc_get_endian_flag(DATA_BLOB *blob);
173 uint8_t dcerpc_get_auth_type(const DATA_BLOB *blob);
174 uint8_t dcerpc_get_auth_level(const DATA_BLOB *blob);
175 uint32_t dcerpc_get_auth_context_id(const DATA_BLOB *blob);
176 const char *dcerpc_default_transport_endpoint(TALLOC_CTX *mem_ctx,
177 enum dcerpc_transport_t transport,
178 const struct ndr_interface_table *table);
180 NTSTATUS dcerpc_pull_ncacn_packet(TALLOC_CTX *mem_ctx,
181 const DATA_BLOB *blob,
182 struct ncacn_packet *r);
185 * @brief Pull a dcerpc_auth structure, taking account of any auth
186 * padding in the blob. For request/response packets we pass
187 * the whole data blob, so auth_data_only must be set to false
188 * as the blob contains data+pad+auth and no just pad+auth.
190 * @param pkt - The ncacn_packet strcuture
191 * @param mem_ctx - The mem_ctx used to allocate dcerpc_auth elements
192 * @param pkt_trailer - The packet trailer data, usually the trailing
193 * auth_info blob, but in the request/response case
194 * this is the stub_and_verifier blob.
195 * @param auth - A preallocated dcerpc_auth *empty* structure
196 * @param auth_length - The length of the auth trail, sum of auth header
197 * lenght and pkt->auth_length
198 * @param auth_data_only - Whether the pkt_trailer includes only the auth_blob
199 * (+ padding) or also other data.
201 * @return - A NTSTATUS error code.
203 NTSTATUS dcerpc_pull_auth_trailer(const struct ncacn_packet *pkt,
204 TALLOC_CTX *mem_ctx,
205 const DATA_BLOB *pkt_trailer,
206 struct dcerpc_auth *auth,
207 uint32_t *auth_length,
208 bool auth_data_only);
209 NTSTATUS dcerpc_verify_ncacn_packet_header(const struct ncacn_packet *pkt,
210 enum dcerpc_pkt_type ptype,
211 size_t max_auth_info,
212 uint8_t required_flags,
213 uint8_t optional_flags);
214 NTSTATUS dcerpc_ncacn_pull_pkt_auth(const struct dcerpc_auth *auth_state,
215 struct gensec_security *gensec,
216 TALLOC_CTX *mem_ctx,
217 enum dcerpc_pkt_type ptype,
218 uint8_t required_flags,
219 uint8_t optional_flags,
220 uint8_t payload_offset,
221 DATA_BLOB *payload_and_verifier,
222 DATA_BLOB *raw_packet,
223 const struct ncacn_packet *pkt);
224 NTSTATUS dcerpc_ncacn_push_pkt_auth(const struct dcerpc_auth *auth_state,
225 struct gensec_security *gensec,
226 TALLOC_CTX *mem_ctx,
227 DATA_BLOB *raw_packet,
228 size_t sig_size,
229 uint8_t payload_offset,
230 const DATA_BLOB *payload,
231 const struct ncacn_packet *pkt);
232 struct tevent_req *dcerpc_read_ncacn_packet_send(TALLOC_CTX *mem_ctx,
233 struct tevent_context *ev,
234 struct tstream_context *stream);
235 NTSTATUS dcerpc_read_ncacn_packet_recv(struct tevent_req *req,
236 TALLOC_CTX *mem_ctx,
237 struct ncacn_packet **pkt,
238 DATA_BLOB *buffer);
240 /* The following definitions come from ../librpc/rpc/binding_handle.c */
242 struct dcerpc_binding_handle_ops {
243 const char *name;
245 bool (*is_connected)(struct dcerpc_binding_handle *h);
246 uint32_t (*set_timeout)(struct dcerpc_binding_handle *h,
247 uint32_t timeout);
249 void (*auth_info)(struct dcerpc_binding_handle *h,
250 enum dcerpc_AuthType *auth_type,
251 enum dcerpc_AuthLevel *auth_level);
253 struct tevent_req *(*raw_call_send)(TALLOC_CTX *mem_ctx,
254 struct tevent_context *ev,
255 struct dcerpc_binding_handle *h,
256 const struct GUID *object,
257 uint32_t opnum,
258 uint32_t in_flags,
259 const uint8_t *in_data,
260 size_t in_length);
261 NTSTATUS (*raw_call_recv)(struct tevent_req *req,
262 TALLOC_CTX *mem_ctx,
263 uint8_t **out_data,
264 size_t *out_length,
265 uint32_t *out_flags);
267 struct tevent_req *(*disconnect_send)(TALLOC_CTX *mem_ctx,
268 struct tevent_context *ev,
269 struct dcerpc_binding_handle *h);
270 NTSTATUS (*disconnect_recv)(struct tevent_req *req);
272 /* TODO: remove the following functions */
273 bool (*push_bigendian)(struct dcerpc_binding_handle *h);
274 bool (*ref_alloc)(struct dcerpc_binding_handle *h);
275 bool (*use_ndr64)(struct dcerpc_binding_handle *h);
276 void (*do_ndr_print)(struct dcerpc_binding_handle *h,
277 int ndr_flags,
278 const void *struct_ptr,
279 const struct ndr_interface_call *call);
280 void (*ndr_push_failed)(struct dcerpc_binding_handle *h,
281 NTSTATUS error,
282 const void *struct_ptr,
283 const struct ndr_interface_call *call);
284 void (*ndr_pull_failed)(struct dcerpc_binding_handle *h,
285 NTSTATUS error,
286 const DATA_BLOB *blob,
287 const struct ndr_interface_call *call);
288 NTSTATUS (*ndr_validate_in)(struct dcerpc_binding_handle *h,
289 TALLOC_CTX *mem_ctx,
290 const DATA_BLOB *blob,
291 const struct ndr_interface_call *call);
292 NTSTATUS (*ndr_validate_out)(struct dcerpc_binding_handle *h,
293 struct ndr_pull *pull_in,
294 const void *struct_ptr,
295 const struct ndr_interface_call *call);
298 struct dcerpc_binding_handle *_dcerpc_binding_handle_create(TALLOC_CTX *mem_ctx,
299 const struct dcerpc_binding_handle_ops *ops,
300 const struct GUID *object,
301 const struct ndr_interface_table *table,
302 void *pstate,
303 size_t psize,
304 const char *type,
305 const char *location);
306 #define dcerpc_binding_handle_create(mem_ctx, ops, object, table, \
307 state, type, location) \
308 _dcerpc_binding_handle_create(mem_ctx, ops, object, table, \
309 state, sizeof(type), #type, location)
311 void *_dcerpc_binding_handle_data(struct dcerpc_binding_handle *h);
312 #define dcerpc_binding_handle_data(_h, _type) \
313 talloc_get_type_abort(_dcerpc_binding_handle_data(_h), _type)
315 _DEPRECATED_ void dcerpc_binding_handle_set_sync_ev(struct dcerpc_binding_handle *h,
316 struct tevent_context *ev);
318 bool dcerpc_binding_handle_is_connected(struct dcerpc_binding_handle *h);
320 uint32_t dcerpc_binding_handle_set_timeout(struct dcerpc_binding_handle *h,
321 uint32_t timeout);
323 void dcerpc_binding_handle_auth_info(struct dcerpc_binding_handle *h,
324 enum dcerpc_AuthType *auth_type,
325 enum dcerpc_AuthLevel *auth_level);
327 struct tevent_req *dcerpc_binding_handle_raw_call_send(TALLOC_CTX *mem_ctx,
328 struct tevent_context *ev,
329 struct dcerpc_binding_handle *h,
330 const struct GUID *object,
331 uint32_t opnum,
332 uint32_t in_flags,
333 const uint8_t *in_data,
334 size_t in_length);
335 NTSTATUS dcerpc_binding_handle_raw_call_recv(struct tevent_req *req,
336 TALLOC_CTX *mem_ctx,
337 uint8_t **out_data,
338 size_t *out_length,
339 uint32_t *out_flags);
340 NTSTATUS dcerpc_binding_handle_raw_call(struct dcerpc_binding_handle *h,
341 const struct GUID *object,
342 uint32_t opnum,
343 uint32_t in_flags,
344 const uint8_t *in_data,
345 size_t in_length,
346 TALLOC_CTX *mem_ctx,
347 uint8_t **out_data,
348 size_t *out_length,
349 uint32_t *out_flags);
351 struct tevent_req *dcerpc_binding_handle_disconnect_send(TALLOC_CTX *mem_ctx,
352 struct tevent_context *ev,
353 struct dcerpc_binding_handle *h);
354 NTSTATUS dcerpc_binding_handle_disconnect_recv(struct tevent_req *req);
356 struct tevent_req *dcerpc_binding_handle_call_send(TALLOC_CTX *mem_ctx,
357 struct tevent_context *ev,
358 struct dcerpc_binding_handle *h,
359 const struct GUID *object,
360 const struct ndr_interface_table *table,
361 uint32_t opnum,
362 TALLOC_CTX *r_mem,
363 void *r_ptr);
364 NTSTATUS dcerpc_binding_handle_call_recv(struct tevent_req *req);
365 NTSTATUS dcerpc_binding_handle_call(struct dcerpc_binding_handle *h,
366 const struct GUID *object,
367 const struct ndr_interface_table *table,
368 uint32_t opnum,
369 TALLOC_CTX *r_mem,
370 void *r_ptr);
373 * Extract header information from a ncacn_packet
374 * as a dcerpc_sec_vt_header2 as used by the security verification trailer.
376 * @param[in] pkt a packet
378 * @return a dcerpc_sec_vt_header2
380 struct dcerpc_sec_vt_header2 dcerpc_sec_vt_header2_from_ncacn_packet(const struct ncacn_packet *pkt);
384 * Test if two dcerpc_sec_vt_header2 structures are equal
385 * without consideration of reserved fields.
387 * @param v1 a pointer to a dcerpc_sec_vt_header2 structure
388 * @param v2 a pointer to a dcerpc_sec_vt_header2 structure
390 * @retval true if *v1 equals *v2
392 bool dcerpc_sec_vt_header2_equal(const struct dcerpc_sec_vt_header2 *v1,
393 const struct dcerpc_sec_vt_header2 *v2);
396 * Check for consistency of the security verification trailer with the PDU header.
397 * See <a href="http://msdn.microsoft.com/en-us/library/cc243559.aspx">MS-RPCE 2.2.2.13</a>.
398 * A check with an empty trailer succeeds.
400 * @param[in] vt a pointer to the security verification trailer.
401 * @param[in] bitmask1 which flags were negotiated on the connection.
402 * @param[in] pcontext the syntaxes negotiatied for the presentation context.
403 * @param[in] header2 some fields from the PDU header.
405 * @retval true on success.
407 bool dcerpc_sec_verification_trailer_check(
408 const struct dcerpc_sec_verification_trailer *vt,
409 const uint32_t *bitmask1,
410 const struct dcerpc_sec_vt_pcontext *pcontext,
411 const struct dcerpc_sec_vt_header2 *header2);
414 * @brief check and optionally extract the Bind Time Features from
415 * the given ndr_syntax_id.
417 * <a href="http://msdn.microsoft.com/en-us/library/cc243715.aspx">MS-RPCE 3.3.1.5.3 Bind Time Feature Negotiation</a>.
419 * @param[in] s the syntax that should be checked.
421 * @param[out] features This is optional, it will be filled with the extracted
422 * features the on success, otherwise it's filled with 0.
424 * @return true if the syntax matches the 6CB71C2C-9812-4540 prefix with version 1, false otherwise.
426 * @see dcerpc_construct_bind_time_features
428 bool dcerpc_extract_bind_time_features(struct ndr_syntax_id syntax, uint64_t *features);
431 * @brief Construct a ndr_syntax_id used for Bind Time Features Negotiation.
433 * <a href="http://msdn.microsoft.com/en-us/library/cc243715.aspx">MS-RPCE 3.3.1.5.3 Bind Time Feature Negotiation</a>.
435 * @param[in] features The supported features.
437 * @return The ndr_syntax_id with the given features.
439 * @see dcerpc_extract_bind_time_features
441 struct ndr_syntax_id dcerpc_construct_bind_time_features(uint64_t features);
443 #define DCERPC_AUTH_PAD_LENGTH(stub_length) (\
444 (((stub_length) % DCERPC_AUTH_PAD_ALIGNMENT) > 0)?\
445 (DCERPC_AUTH_PAD_ALIGNMENT - (stub_length) % DCERPC_AUTH_PAD_ALIGNMENT):\
448 NTSTATUS dcerpc_generic_session_key(DATA_BLOB *session_key);
450 NTSTATUS dcerpc_ncacn_push_auth(DATA_BLOB *blob,
451 TALLOC_CTX *mem_ctx,
452 struct ncacn_packet *pkt,
453 struct dcerpc_auth *auth_info);
455 void dcerpc_log_packet(const char *packet_log_dir,
456 const char *interface_name,
457 uint32_t opnum, uint32_t flags,
458 const DATA_BLOB *pkt,
459 const char *why);
461 #ifdef DEVELOPER
462 void dcerpc_save_ndr_fuzz_seed(TALLOC_CTX *mem_ctx,
463 DATA_BLOB raw_blob,
464 const char *dump_dir,
465 const char *iface_name,
466 int flags,
467 int opnum,
468 bool ndr64);
469 #else
470 static inline void dcerpc_save_ndr_fuzz_seed(TALLOC_CTX *mem_ctx,
471 DATA_BLOB raw_blob,
472 const char *dump_dir,
473 const char *iface_name,
474 int flags,
475 int opnum,
476 bool ndr64)
478 return;
480 #endif
482 #endif /* __DEFAULT_LIBRPC_RPCCOMMON_H__ */