Final fix for #7331 - Compound async SMB 2 requests don't work right.
[Samba/ekacnet.git] / source3 / smbd / smb2_notify.c
blob460e6293f595b19f0152242d9cd8e4bc536fbc35
1 /*
2 Unix SMB/CIFS implementation.
3 Core SMB2 server
5 Copyright (C) Stefan Metzmacher 2009
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "includes.h"
22 #include "smbd/globals.h"
23 #include "../libcli/smb/smb_common.h"
25 static struct tevent_req *smbd_smb2_notify_send(TALLOC_CTX *mem_ctx,
26 struct tevent_context *ev,
27 struct smbd_smb2_request *smb2req,
28 uint16_t in_flags,
29 uint32_t in_output_buffer_length,
30 uint64_t in_file_id_volatile,
31 uint64_t in_completion_filter);
32 static NTSTATUS smbd_smb2_notify_recv(struct tevent_req *req,
33 TALLOC_CTX *mem_ctx,
34 DATA_BLOB *out_output_buffer);
36 static void smbd_smb2_request_notify_done(struct tevent_req *subreq);
37 NTSTATUS smbd_smb2_request_process_notify(struct smbd_smb2_request *req)
39 const uint8_t *inhdr;
40 const uint8_t *inbody;
41 int i = req->current_idx;
42 size_t expected_body_size = 0x20;
43 size_t body_size;
44 uint16_t in_flags;
45 uint32_t in_output_buffer_length;
46 uint64_t in_file_id_persistent;
47 uint64_t in_file_id_volatile;
48 uint64_t in_completion_filter;
49 struct tevent_req *subreq;
51 inhdr = (const uint8_t *)req->in.vector[i+0].iov_base;
52 if (req->in.vector[i+1].iov_len != (expected_body_size & 0xFFFFFFFE)) {
53 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
56 inbody = (const uint8_t *)req->in.vector[i+1].iov_base;
58 body_size = SVAL(inbody, 0x00);
59 if (body_size != expected_body_size) {
60 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
63 in_flags = SVAL(inbody, 0x02);
64 in_output_buffer_length = IVAL(inbody, 0x04);
65 in_file_id_persistent = BVAL(inbody, 0x08);
66 in_file_id_volatile = BVAL(inbody, 0x10);
67 in_completion_filter = IVAL(inbody, 0x18);
70 * 0x00010000 is what Windows 7 uses,
71 * Windows 2008 uses 0x00080000
73 if (in_output_buffer_length > lp_smb2_max_trans()) {
74 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
77 if (req->compat_chain_fsp) {
78 /* skip check */
79 } else if (in_file_id_persistent != 0) {
80 return smbd_smb2_request_error(req, NT_STATUS_FILE_CLOSED);
83 subreq = smbd_smb2_notify_send(req,
84 req->sconn->smb2.event_ctx,
85 req,
86 in_flags,
87 in_output_buffer_length,
88 in_file_id_volatile,
89 in_completion_filter);
90 if (subreq == NULL) {
91 return smbd_smb2_request_error(req, NT_STATUS_NO_MEMORY);
93 tevent_req_set_callback(subreq, smbd_smb2_request_notify_done, req);
95 return smbd_smb2_request_pending_queue(req, subreq);
98 static void smbd_smb2_request_notify_done(struct tevent_req *subreq)
100 struct smbd_smb2_request *req = tevent_req_callback_data(subreq,
101 struct smbd_smb2_request);
102 int i = req->current_idx;
103 uint8_t *outhdr;
104 DATA_BLOB outbody;
105 DATA_BLOB outdyn;
106 uint16_t out_output_buffer_offset;
107 DATA_BLOB out_output_buffer = data_blob_null;
108 NTSTATUS status;
109 NTSTATUS error; /* transport error */
111 if (req->cancelled) {
112 const uint8_t *inhdr = (const uint8_t *)req->in.vector[i].iov_base;
113 uint64_t mid = BVAL(inhdr, SMB2_HDR_MESSAGE_ID);
114 DEBUG(10,("smbd_smb2_request_notify_done: cancelled mid %llu\n",
115 (unsigned long long)mid ));
116 error = smbd_smb2_request_error(req, NT_STATUS_CANCELLED);
117 if (!NT_STATUS_IS_OK(error)) {
118 smbd_server_connection_terminate(req->sconn,
119 nt_errstr(error));
120 return;
122 TALLOC_FREE(subreq);
123 return;
126 status = smbd_smb2_notify_recv(subreq,
127 req,
128 &out_output_buffer);
129 TALLOC_FREE(subreq);
130 if (!NT_STATUS_IS_OK(status)) {
131 error = smbd_smb2_request_error(req, status);
132 if (!NT_STATUS_IS_OK(error)) {
133 smbd_server_connection_terminate(req->sconn,
134 nt_errstr(error));
135 return;
137 return;
140 out_output_buffer_offset = SMB2_HDR_BODY + 0x08;
142 outhdr = (uint8_t *)req->out.vector[i].iov_base;
144 outbody = data_blob_talloc(req->out.vector, NULL, 0x08);
145 if (outbody.data == NULL) {
146 error = smbd_smb2_request_error(req, NT_STATUS_NO_MEMORY);
147 if (!NT_STATUS_IS_OK(error)) {
148 smbd_server_connection_terminate(req->sconn,
149 nt_errstr(error));
150 return;
152 return;
155 SSVAL(outbody.data, 0x00, 0x08 + 1); /* struct size */
156 SSVAL(outbody.data, 0x02,
157 out_output_buffer_offset); /* output buffer offset */
158 SIVAL(outbody.data, 0x04,
159 out_output_buffer.length); /* output buffer length */
161 outdyn = out_output_buffer;
163 error = smbd_smb2_request_done(req, outbody, &outdyn);
164 if (!NT_STATUS_IS_OK(error)) {
165 smbd_server_connection_terminate(req->sconn,
166 nt_errstr(error));
167 return;
171 struct smbd_smb2_notify_state {
172 struct smbd_smb2_request *smb2req;
173 struct smb_request *smbreq;
174 struct tevent_immediate *im;
175 NTSTATUS status;
176 DATA_BLOB out_output_buffer;
179 static void smbd_smb2_notify_reply(struct smb_request *smbreq,
180 NTSTATUS error_code,
181 uint8_t *buf, size_t len);
182 static void smbd_smb2_notify_reply_trigger(struct tevent_context *ctx,
183 struct tevent_immediate *im,
184 void *private_data);
185 static bool smbd_smb2_notify_cancel(struct tevent_req *req);
187 static struct tevent_req *smbd_smb2_notify_send(TALLOC_CTX *mem_ctx,
188 struct tevent_context *ev,
189 struct smbd_smb2_request *smb2req,
190 uint16_t in_flags,
191 uint32_t in_output_buffer_length,
192 uint64_t in_file_id_volatile,
193 uint64_t in_completion_filter)
195 struct tevent_req *req;
196 struct smbd_smb2_notify_state *state;
197 struct smb_request *smbreq;
198 connection_struct *conn = smb2req->tcon->compat_conn;
199 files_struct *fsp;
200 bool recursive = (in_flags & 0x0001) ? true : false;
201 NTSTATUS status;
203 req = tevent_req_create(mem_ctx, &state,
204 struct smbd_smb2_notify_state);
205 if (req == NULL) {
206 return NULL;
208 state->smb2req = smb2req;
209 state->status = NT_STATUS_INTERNAL_ERROR;
210 state->out_output_buffer = data_blob_null;
211 state->im = NULL;
213 DEBUG(10,("smbd_smb2_notify_send: file_id[0x%016llX]\n",
214 (unsigned long long)in_file_id_volatile));
216 smbreq = smbd_smb2_fake_smb_request(smb2req);
217 if (tevent_req_nomem(smbreq, req)) {
218 return tevent_req_post(req, ev);
221 state->smbreq = smbreq;
222 smbreq->async_priv = (void *)req;
224 fsp = file_fsp(smbreq, (uint16_t)in_file_id_volatile);
225 if (fsp == NULL) {
226 tevent_req_nterror(req, NT_STATUS_FILE_CLOSED);
227 return tevent_req_post(req, ev);
229 if (conn != fsp->conn) {
230 tevent_req_nterror(req, NT_STATUS_FILE_CLOSED);
231 return tevent_req_post(req, ev);
233 if (smb2req->session->vuid != fsp->vuid) {
234 tevent_req_nterror(req, NT_STATUS_FILE_CLOSED);
235 return tevent_req_post(req, ev);
239 char *filter_string;
241 filter_string = notify_filter_string(NULL, in_completion_filter);
242 if (tevent_req_nomem(filter_string, req)) {
243 return tevent_req_post(req, ev);
246 DEBUG(3,("smbd_smb2_notify_send: notify change "
247 "called on %s, filter = %s, recursive = %d\n",
248 fsp_str_dbg(fsp), filter_string, recursive));
250 TALLOC_FREE(filter_string);
253 if ((!fsp->is_directory) || (conn != fsp->conn)) {
254 tevent_req_nterror(req, NT_STATUS_INVALID_PARAMETER);
255 return tevent_req_post(req, ev);
258 if (fsp->notify == NULL) {
260 status = change_notify_create(fsp,
261 in_completion_filter,
262 recursive);
263 if (!NT_STATUS_IS_OK(status)) {
264 DEBUG(10, ("change_notify_create returned %s\n",
265 nt_errstr(status)));
266 tevent_req_nterror(req, status);
267 return tevent_req_post(req, ev);
271 if (fsp->notify->num_changes != 0) {
274 * We've got changes pending, respond immediately
278 * TODO: write a torture test to check the filtering behaviour
279 * here.
282 change_notify_reply(fsp->conn, smbreq,
283 NT_STATUS_OK,
284 in_output_buffer_length,
285 fsp->notify,
286 smbd_smb2_notify_reply);
289 * change_notify_reply() above has independently
290 * called tevent_req_done().
292 return tevent_req_post(req, ev);
295 state->im = tevent_create_immediate(state);
296 if (tevent_req_nomem(state->im, req)) {
297 return tevent_req_post(req, ev);
301 * No changes pending, queue the request
304 status = change_notify_add_request(smbreq,
305 in_output_buffer_length,
306 in_completion_filter,
307 recursive, fsp,
308 smbd_smb2_notify_reply);
309 if (!NT_STATUS_IS_OK(status)) {
310 tevent_req_nterror(req, status);
311 return tevent_req_post(req, ev);
314 /* allow this request to be canceled */
315 tevent_req_set_cancel_fn(req, smbd_smb2_notify_cancel);
317 return req;
320 static void smbd_smb2_notify_reply(struct smb_request *smbreq,
321 NTSTATUS error_code,
322 uint8_t *buf, size_t len)
324 struct tevent_req *req = talloc_get_type_abort(smbreq->async_priv,
325 struct tevent_req);
326 struct smbd_smb2_notify_state *state = tevent_req_data(req,
327 struct smbd_smb2_notify_state);
329 state->status = error_code;
330 if (!NT_STATUS_IS_OK(error_code)) {
331 /* nothing */
332 } else if (len == 0) {
333 state->status = STATUS_NOTIFY_ENUM_DIR;
334 } else {
335 state->out_output_buffer = data_blob_talloc(state, buf, len);
336 if (state->out_output_buffer.data == NULL) {
337 state->status = NT_STATUS_NO_MEMORY;
341 if (state->im == NULL) {
342 smbd_smb2_notify_reply_trigger(NULL, NULL, req);
343 return;
347 * if this is called async, we need to go via an immediate event
348 * because the caller replies on the smb_request (a child of req
349 * being arround after calling this function
351 tevent_schedule_immediate(state->im,
352 state->smb2req->sconn->smb2.event_ctx,
353 smbd_smb2_notify_reply_trigger,
354 req);
357 static void smbd_smb2_notify_reply_trigger(struct tevent_context *ctx,
358 struct tevent_immediate *im,
359 void *private_data)
361 struct tevent_req *req = talloc_get_type_abort(private_data,
362 struct tevent_req);
363 struct smbd_smb2_notify_state *state = tevent_req_data(req,
364 struct smbd_smb2_notify_state);
366 if (!NT_STATUS_IS_OK(state->status)) {
367 tevent_req_nterror(req, state->status);
368 return;
371 tevent_req_done(req);
374 static bool smbd_smb2_notify_cancel(struct tevent_req *req)
376 struct smbd_smb2_notify_state *state = tevent_req_data(req,
377 struct smbd_smb2_notify_state);
379 smbd_notify_cancel_by_smbreq(state->smb2req->sconn,
380 state->smbreq);
382 state->smb2req->cancelled = true;
383 tevent_req_done(req);
384 return true;
387 static NTSTATUS smbd_smb2_notify_recv(struct tevent_req *req,
388 TALLOC_CTX *mem_ctx,
389 DATA_BLOB *out_output_buffer)
391 NTSTATUS status;
392 struct smbd_smb2_notify_state *state = tevent_req_data(req,
393 struct smbd_smb2_notify_state);
395 if (tevent_req_is_nterror(req, &status)) {
396 tevent_req_received(req);
397 return status;
400 *out_output_buffer = state->out_output_buffer;
401 talloc_steal(mem_ctx, out_output_buffer->data);
403 tevent_req_received(req);
404 return NT_STATUS_OK;