2 Unix SMB/CIFS implementation.
3 Samba utility functions
4 Copyright (C) Jelmer Vernooij <jelmer@samba.org> 2008
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #include <structmember.h>
23 #include "librpc/rpc/pyrpc.h"
24 #include "lib/events/events.h"
25 #include "param/pyparam.h"
26 #include "librpc/rpc/dcerpc.h"
27 #include "librpc/rpc/pyrpc_util.h"
28 #include "auth/credentials/pycredentials.h"
29 #include "auth/gensec/gensec.h"
33 staticforward PyTypeObject dcerpc_InterfaceType
;
35 static bool PyString_AsGUID(PyObject
*object
, struct GUID
*uuid
)
38 status
= GUID_from_string(PyString_AsString(object
), uuid
);
39 if (NT_STATUS_IS_ERR(status
)) {
40 PyErr_SetNTSTATUS(status
);
46 static bool ndr_syntax_from_py_object(PyObject
*object
, struct ndr_syntax_id
*syntax_id
)
48 ZERO_STRUCTP(syntax_id
);
50 if (PyString_Check(object
)) {
51 return PyString_AsGUID(object
, &syntax_id
->uuid
);
52 } else if (PyTuple_Check(object
)) {
53 if (PyTuple_Size(object
) < 1 || PyTuple_Size(object
) > 2) {
54 PyErr_SetString(PyExc_ValueError
, "Syntax ID tuple has invalid size");
58 if (!PyString_Check(PyTuple_GetItem(object
, 0))) {
59 PyErr_SetString(PyExc_ValueError
, "Expected GUID as first element in tuple");
63 if (!PyString_AsGUID(PyTuple_GetItem(object
, 0), &syntax_id
->uuid
))
66 if (!PyInt_Check(PyTuple_GetItem(object
, 1))) {
67 PyErr_SetString(PyExc_ValueError
, "Expected version as second element in tuple");
71 syntax_id
->if_version
= PyInt_AsLong(PyTuple_GetItem(object
, 1));
75 PyErr_SetString(PyExc_TypeError
, "Expected UUID or syntax id tuple");
79 static PyObject
*py_iface_server_name(PyObject
*obj
, void *closure
)
81 const char *server_name
;
82 dcerpc_InterfaceObject
*iface
= (dcerpc_InterfaceObject
*)obj
;
84 server_name
= dcerpc_server_name(iface
->pipe
);
85 if (server_name
== NULL
)
88 return PyString_FromString(server_name
);
91 static PyObject
*py_ndr_syntax_id(struct ndr_syntax_id
*syntax_id
)
96 uuid_str
= GUID_string(NULL
, &syntax_id
->uuid
);
100 ret
= Py_BuildValue("(s,i)", uuid_str
, syntax_id
->if_version
);
102 talloc_free(uuid_str
);
107 static PyObject
*py_iface_abstract_syntax(PyObject
*obj
, void *closure
)
109 dcerpc_InterfaceObject
*iface
= (dcerpc_InterfaceObject
*)obj
;
111 return py_ndr_syntax_id(&iface
->pipe
->syntax
);
114 static PyObject
*py_iface_transfer_syntax(PyObject
*obj
, void *closure
)
116 dcerpc_InterfaceObject
*iface
= (dcerpc_InterfaceObject
*)obj
;
118 return py_ndr_syntax_id(&iface
->pipe
->transfer_syntax
);
121 static PyObject
*py_iface_session_key(PyObject
*obj
, void *closure
)
123 dcerpc_InterfaceObject
*iface
= (dcerpc_InterfaceObject
*)obj
;
124 DATA_BLOB session_key
;
126 NTSTATUS status
= dcerpc_fetch_session_key(iface
->pipe
, &session_key
);
127 PyErr_NTSTATUS_IS_ERR_RAISE(status
);
129 return PyString_FromStringAndSize((const char *)session_key
.data
, session_key
.length
);
132 static PyObject
*py_iface_user_session_key(PyObject
*obj
, void *closure
)
134 dcerpc_InterfaceObject
*iface
= (dcerpc_InterfaceObject
*)obj
;
137 struct gensec_security
*security
= NULL
;
138 DATA_BLOB session_key
= data_blob_null
;
139 static PyObject
*session_key_obj
= NULL
;
141 if (iface
->pipe
== NULL
) {
142 PyErr_SetNTSTATUS(NT_STATUS_NO_USER_SESSION_KEY
);
146 if (iface
->pipe
->conn
== NULL
) {
147 PyErr_SetNTSTATUS(NT_STATUS_NO_USER_SESSION_KEY
);
151 if (iface
->pipe
->conn
->security_state
.generic_state
== NULL
) {
152 PyErr_SetNTSTATUS(NT_STATUS_NO_USER_SESSION_KEY
);
156 security
= iface
->pipe
->conn
->security_state
.generic_state
;
158 mem_ctx
= talloc_new(NULL
);
160 status
= gensec_session_key(security
, mem_ctx
, &session_key
);
161 if (!NT_STATUS_IS_OK(status
)) {
162 talloc_free(mem_ctx
);
163 PyErr_SetNTSTATUS(status
);
167 session_key_obj
= PyString_FromStringAndSize((const char *)session_key
.data
,
169 talloc_free(mem_ctx
);
170 return session_key_obj
;
173 static PyGetSetDef dcerpc_interface_getsetters
[] = {
174 { discard_const_p(char, "server_name"), py_iface_server_name
, NULL
,
175 discard_const_p(char, "name of the server, if connected over SMB") },
176 { discard_const_p(char, "abstract_syntax"), py_iface_abstract_syntax
, NULL
,
177 discard_const_p(char, "syntax id of the abstract syntax") },
178 { discard_const_p(char, "transfer_syntax"), py_iface_transfer_syntax
, NULL
,
179 discard_const_p(char, "syntax id of the transfersyntax") },
180 { discard_const_p(char, "session_key"), py_iface_session_key
, NULL
,
181 discard_const_p(char, "session key (as used for blob encryption on LSA and SAMR)") },
182 { discard_const_p(char, "user_session_key"), py_iface_user_session_key
, NULL
,
183 discard_const_p(char, "user_session key (as used for blob encryption on DRSUAPI)") },
187 static PyMemberDef dcerpc_interface_members
[] = {
188 { discard_const_p(char, "request_timeout"), T_INT
,
189 offsetof(struct dcerpc_pipe
, request_timeout
), 0,
190 discard_const_p(char, "request timeout, in seconds") },
194 static PyObject
*py_iface_request(PyObject
*self
, PyObject
*args
, PyObject
*kwargs
)
196 dcerpc_InterfaceObject
*iface
= (dcerpc_InterfaceObject
*)self
;
198 DATA_BLOB data_in
, data_out
;
203 PyObject
*object
= NULL
;
204 struct GUID object_guid
;
205 TALLOC_CTX
*mem_ctx
= talloc_new(NULL
);
206 uint32_t out_flags
= 0;
207 const char *kwnames
[] = { "opnum", "data", "object", NULL
};
209 if (!PyArg_ParseTupleAndKeywords(args
, kwargs
, "is#|O:request",
210 discard_const_p(char *, kwnames
), &opnum
, &in_data
, &in_length
, &object
)) {
211 talloc_free(mem_ctx
);
215 data_in
.data
= (uint8_t *)talloc_memdup(mem_ctx
, in_data
, in_length
);
216 data_in
.length
= in_length
;
218 ZERO_STRUCT(data_out
);
220 if (object
!= NULL
&& !PyString_AsGUID(object
, &object_guid
)) {
221 talloc_free(mem_ctx
);
225 status
= dcerpc_binding_handle_raw_call(iface
->binding_handle
,
226 object
?&object_guid
:NULL
,
235 if (!NT_STATUS_IS_OK(status
)) {
236 PyErr_SetDCERPCStatus(iface
->pipe
, status
);
237 talloc_free(mem_ctx
);
241 ret
= PyString_FromStringAndSize((char *)data_out
.data
, data_out
.length
);
243 talloc_free(mem_ctx
);
247 static PyObject
*py_iface_alter_context(PyObject
*self
, PyObject
*args
, PyObject
*kwargs
)
249 dcerpc_InterfaceObject
*iface
= (dcerpc_InterfaceObject
*)self
;
251 const char *kwnames
[] = { "abstract_syntax", "transfer_syntax", NULL
};
252 PyObject
*py_abstract_syntax
= Py_None
, *py_transfer_syntax
= Py_None
;
253 struct ndr_syntax_id abstract_syntax
, transfer_syntax
;
255 if (!PyArg_ParseTupleAndKeywords(args
, kwargs
, "O|O:alter_context",
256 discard_const_p(char *, kwnames
), &py_abstract_syntax
,
257 &py_transfer_syntax
)) {
261 if (!ndr_syntax_from_py_object(py_abstract_syntax
, &abstract_syntax
))
264 if (py_transfer_syntax
== Py_None
) {
265 transfer_syntax
= ndr_transfer_syntax_ndr
;
267 if (!ndr_syntax_from_py_object(py_transfer_syntax
, &transfer_syntax
))
271 status
= dcerpc_alter_context(iface
->pipe
, iface
->pipe
, &abstract_syntax
,
274 if (!NT_STATUS_IS_OK(status
)) {
275 PyErr_SetDCERPCStatus(iface
->pipe
, status
);
282 static PyMethodDef dcerpc_interface_methods
[] = {
283 { "request", (PyCFunction
)py_iface_request
, METH_VARARGS
|METH_KEYWORDS
, "S.request(opnum, data, object=None) -> data\nMake a raw request" },
284 { "alter_context", (PyCFunction
)py_iface_alter_context
, METH_VARARGS
|METH_KEYWORDS
, "S.alter_context(syntax)\nChange to a different interface" },
285 { NULL
, NULL
, 0, NULL
},
288 static void dcerpc_interface_dealloc(PyObject
* self
)
290 dcerpc_InterfaceObject
*interface
= (dcerpc_InterfaceObject
*)self
;
291 talloc_free(interface
->mem_ctx
);
292 self
->ob_type
->tp_free(self
);
295 static PyObject
*dcerpc_interface_new(PyTypeObject
*type
, PyObject
*args
, PyObject
*kwargs
)
297 dcerpc_InterfaceObject
*ret
;
298 const char *binding_string
;
299 struct cli_credentials
*credentials
;
300 struct loadparm_context
*lp_ctx
= NULL
;
301 PyObject
*py_lp_ctx
= Py_None
, *py_credentials
= Py_None
;
303 struct tevent_context
*event_ctx
;
306 PyObject
*syntax
, *py_basis
= Py_None
;
307 const char *kwnames
[] = {
308 "binding", "syntax", "lp_ctx", "credentials", "basis_connection", NULL
310 struct ndr_interface_table
*table
;
312 if (!PyArg_ParseTupleAndKeywords(args
, kwargs
, "sO|OOO:connect", discard_const_p(char *, kwnames
), &binding_string
, &syntax
, &py_lp_ctx
, &py_credentials
, &py_basis
)) {
316 mem_ctx
= talloc_new(NULL
);
317 if (mem_ctx
== NULL
) {
322 lp_ctx
= lpcfg_from_py_object(mem_ctx
, py_lp_ctx
);
323 if (lp_ctx
== NULL
) {
324 PyErr_SetString(PyExc_TypeError
, "Expected loadparm context");
325 talloc_free(mem_ctx
);
329 credentials
= cli_credentials_from_py_object(py_credentials
);
330 if (credentials
== NULL
) {
331 PyErr_SetString(PyExc_TypeError
, "Expected credentials");
332 talloc_free(mem_ctx
);
335 ret
= PyObject_New(dcerpc_InterfaceObject
, type
);
336 ret
->mem_ctx
= mem_ctx
;
338 event_ctx
= s4_event_context_init(ret
->mem_ctx
);
340 /* Create a dummy interface table struct. TODO: In the future, we should
341 * rather just allow connecting without requiring an interface table.
344 table
= talloc_zero(ret
->mem_ctx
, struct ndr_interface_table
);
347 PyErr_SetString(PyExc_MemoryError
, "Allocating interface table");
348 talloc_free(mem_ctx
);
352 if (!ndr_syntax_from_py_object(syntax
, &table
->syntax_id
)) {
353 talloc_free(mem_ctx
);
358 ret
->binding_handle
= NULL
;
360 if (py_basis
!= Py_None
) {
361 struct dcerpc_pipe
*base_pipe
;
363 if (!PyObject_TypeCheck(py_basis
, &dcerpc_InterfaceType
)) {
364 PyErr_SetString(PyExc_ValueError
, "basis_connection must be a DCE/RPC connection");
365 talloc_free(mem_ctx
);
369 base_pipe
= talloc_reference(ret
->mem_ctx
,
370 ((dcerpc_InterfaceObject
*)py_basis
)->pipe
);
372 status
= dcerpc_secondary_context(base_pipe
, &ret
->pipe
, table
);
374 ret
->pipe
= talloc_steal(ret
->mem_ctx
, ret
->pipe
);
376 status
= dcerpc_pipe_connect(ret
->mem_ctx
, &ret
->pipe
, binding_string
,
377 table
, credentials
, event_ctx
, lp_ctx
);
380 if (!NT_STATUS_IS_OK(status
)) {
381 PyErr_SetDCERPCStatus(ret
->pipe
, status
);
382 talloc_free(ret
->mem_ctx
);
385 ret
->pipe
->conn
->flags
|= DCERPC_NDR_REF_ALLOC
;
386 ret
->binding_handle
= ret
->pipe
->binding_handle
;
387 return (PyObject
*)ret
;
390 static PyTypeObject dcerpc_InterfaceType
= {
391 PyObject_HEAD_INIT(NULL
) 0,
392 .tp_name
= "dcerpc.ClientConnection",
393 .tp_basicsize
= sizeof(dcerpc_InterfaceObject
),
394 .tp_dealloc
= dcerpc_interface_dealloc
,
395 .tp_getset
= dcerpc_interface_getsetters
,
396 .tp_members
= dcerpc_interface_members
,
397 .tp_methods
= dcerpc_interface_methods
,
398 .tp_doc
= "ClientConnection(binding, syntax, lp_ctx=None, credentials=None) -> connection\n"
400 "binding should be a DCE/RPC binding string (for example: ncacn_ip_tcp:127.0.0.1)\n"
401 "syntax should be a tuple with a GUID and version number of an interface\n"
402 "lp_ctx should be a path to a smb.conf file or a param.LoadParm object\n"
403 "credentials should be a credentials.Credentials object.\n\n",
404 .tp_flags
= Py_TPFLAGS_DEFAULT
| Py_TPFLAGS_BASETYPE
,
405 .tp_new
= dcerpc_interface_new
,
412 if (PyType_Ready(&dcerpc_InterfaceType
) < 0)
415 m
= Py_InitModule3("base", NULL
, "DCE/RPC protocol implementation");
419 Py_INCREF((PyObject
*)&dcerpc_InterfaceType
);
420 PyModule_AddObject(m
, "ClientConnection", (PyObject
*)&dcerpc_InterfaceType
);