2 Unix SMB/CIFS implementation.
6 Copyright (C) Andrew Tridgell 2003
8 This program is free software; you can redistribute it and/or modify
9 it under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 3 of the License, or
11 (at your option) any later version.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with this program. If not, see <http://www.gnu.org/licenses/>.
23 #include "librpc/gen_ndr/ndr_drsuapi_c.h"
24 #include "librpc/ndr/ndr_table.h"
25 #include "torture/rpc/torture_rpc.h"
30 get a DRSUAPI policy handle
32 static bool get_policy_handle(struct dcerpc_binding_handle
*b
,
34 struct policy_handle
*handle
)
37 struct drsuapi_DsBind r
;
40 r
.out
.bind_handle
= handle
;
42 status
= dcerpc_drsuapi_DsBind_r(b
, mem_ctx
, &r
);
43 if (!NT_STATUS_IS_OK(status
)) {
44 printf("drsuapi_DsBind failed - %s\n", nt_errstr(status
));
54 static bool get_policy_handle(struct dcerpc_binding_handle
*b
,
56 struct policy_handle
*handle
)
59 struct samr_Connect r
;
62 r
.in
.access_mask
= SEC_FLAG_MAXIMUM_ALLOWED
;
63 r
.out
.connect_handle
= handle
;
65 status
= dcerpc_samr_Connect_r(b
, mem_ctx
, &r
);
66 if (!NT_STATUS_IS_OK(status
)) {
67 printf("samr_Connect failed - %s\n", nt_errstr(status
));
75 static void fill_blob_handle(DATA_BLOB
*blob
, TALLOC_CTX
*mem_ctx
,
76 struct policy_handle
*handle
)
80 if (blob
->length
< 20) {
84 ndr_push_struct_blob(&b2
, mem_ctx
, handle
, (ndr_push_flags_fn_t
)ndr_push_policy_handle
);
86 memcpy(blob
->data
, b2
.data
, 20);
89 static void reopen(struct torture_context
*tctx
,
90 struct dcerpc_pipe
**p
,
91 const struct ndr_interface_table
*iface
)
97 status
= torture_rpc_connection(tctx
, p
, iface
);
98 if (!NT_STATUS_IS_OK(status
)) {
99 printf("Failed to reopen '%s' - %s\n", iface
->name
, nt_errstr(status
));
104 static void print_depth(int depth
)
107 for (i
=0;i
<depth
;i
++) {
112 static void test_ptr_scan(struct torture_context
*tctx
, const struct ndr_interface_table
*iface
,
113 int opnum
, DATA_BLOB
*base_in
, int min_ofs
, int max_ofs
, int depth
);
115 static void try_expand(struct torture_context
*tctx
, const struct ndr_interface_table
*iface
,
116 int opnum
, DATA_BLOB
*base_in
, int insert_ofs
, int depth
)
118 DATA_BLOB stub_in
, stub_out
;
121 struct dcerpc_pipe
*p
= NULL
;
123 reopen(tctx
, &p
, iface
);
125 /* work out how much to expand to get a non fault */
126 for (n
=0;n
<2000;n
++) {
127 uint32_t out_flags
= 0;
129 stub_in
= data_blob(NULL
, base_in
->length
+ n
);
130 data_blob_clear(&stub_in
);
131 memcpy(stub_in
.data
, base_in
->data
, insert_ofs
);
132 memcpy(stub_in
.data
+insert_ofs
+n
, base_in
->data
+insert_ofs
, base_in
->length
-insert_ofs
);
134 status
= dcerpc_binding_handle_raw_call(p
->binding_handle
,
143 if (NT_STATUS_IS_OK(status
)) {
145 printf("expand by %d gives %s\n", n
, nt_errstr(status
));
147 test_ptr_scan(tctx
, iface
, opnum
, &stub_in
,
148 insert_ofs
, insert_ofs
+n
, depth
+1);
154 printf("expand by %d gives fault %s\n", n
, nt_errstr(status
));
157 if (NT_STATUS_EQUAL(status
, NT_STATUS_ACCESS_DENIED
)) {
158 reopen(tctx
, &p
, iface
);
166 static void test_ptr_scan(struct torture_context
*tctx
, const struct ndr_interface_table
*iface
,
167 int opnum
, DATA_BLOB
*base_in
, int min_ofs
, int max_ofs
, int depth
)
169 DATA_BLOB stub_in
, stub_out
;
172 struct dcerpc_pipe
*p
= NULL
;
174 reopen(tctx
, &p
, iface
);
176 stub_in
= data_blob(NULL
, base_in
->length
);
177 memcpy(stub_in
.data
, base_in
->data
, base_in
->length
);
179 /* work out which elements are pointers */
180 for (ofs
=min_ofs
;ofs
<=max_ofs
-4;ofs
+=4) {
181 uint32_t out_flags
= 0;
183 SIVAL(stub_in
.data
, ofs
, 1);
185 status
= dcerpc_binding_handle_raw_call(p
->binding_handle
,
195 if (!NT_STATUS_IS_OK(status
)) {
197 printf("possible ptr at ofs %d - fault %s\n",
198 ofs
-min_ofs
, nt_errstr(status
));
199 if (NT_STATUS_EQUAL(status
, NT_STATUS_ACCESS_DENIED
)) {
200 reopen(tctx
, &p
, iface
);
203 try_expand(tctx
, iface
, opnum
, &stub_in
, ofs
+4, depth
+1);
205 try_expand(tctx
, iface
, opnum
, &stub_in
, max_ofs
, depth
+1);
207 SIVAL(stub_in
.data
, ofs
, 0);
210 SIVAL(stub_in
.data
, ofs
, 0);
217 static void test_scan_call(struct torture_context
*tctx
, const struct ndr_interface_table
*iface
, int opnum
)
219 DATA_BLOB stub_in
, stub_out
;
222 struct dcerpc_pipe
*p
= NULL
;
223 struct policy_handle handle
;
225 reopen(tctx
, &p
, iface
);
227 get_policy_handle(p
->binding_handle
, tctx
, &handle
);
229 /* work out the minimum amount of input data */
230 for (i
=0;i
<2000;i
++) {
231 uint32_t out_flags
= 0;
233 stub_in
= data_blob(NULL
, i
);
234 data_blob_clear(&stub_in
);
236 status
= dcerpc_binding_handle_raw_call(p
->binding_handle
,
246 if (NT_STATUS_IS_OK(status
)) {
247 printf("opnum %d min_input %d - output %d\n",
248 opnum
, (int)stub_in
.length
, (int)stub_out
.length
);
249 dump_data(0, stub_out
.data
, stub_out
.length
);
251 test_ptr_scan(tctx
, iface
, opnum
, &stub_in
, 0, stub_in
.length
, 0);
255 fill_blob_handle(&stub_in
, tctx
, &handle
);
257 status
= dcerpc_binding_handle_raw_call(p
->binding_handle
,
267 if (NT_STATUS_IS_OK(status
)) {
268 printf("opnum %d min_input %d - output %d (with handle)\n",
269 opnum
, (int)stub_in
.length
, (int)stub_out
.length
);
270 dump_data(0, stub_out
.data
, stub_out
.length
);
272 test_ptr_scan(tctx
, iface
, opnum
, &stub_in
, 0, stub_in
.length
, 0);
276 if (!NT_STATUS_IS_OK(status
)) {
277 printf("opnum %d size %d fault %s\n", opnum
, i
, nt_errstr(status
));
278 if (NT_STATUS_EQUAL(status
, NT_STATUS_ACCESS_DENIED
)) {
279 reopen(tctx
, &p
, iface
);
284 printf("opnum %d size %d error %s\n", opnum
, i
, nt_errstr(status
));
287 printf("opnum %d minimum not found!?\n", opnum
);
292 static void test_auto_scan(struct torture_context
*tctx
, const struct ndr_interface_table
*iface
)
294 test_scan_call(tctx
, iface
, 2);
297 bool torture_rpc_autoidl(struct torture_context
*torture
)
299 const struct ndr_interface_table
*iface
;
301 iface
= ndr_table_by_name("drsuapi");
303 printf("Unknown interface!\n");
307 printf("\nProbing pipe '%s'\n", iface
->name
);
309 test_auto_scan(torture
, iface
);