2 Unix SMB/CIFS implementation.
3 SMB client generic functions
4 Copyright (C) Andrew Tridgell 1994-1998
5 Copyright (C) Jeremy Allison 2007.
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 #include "libsmb/libsmb.h"
23 #include "../lib/util/tevent_ntstatus.h"
24 #include "../libcli/smb/smb_signing.h"
25 #include "../libcli/smb/smb_seal.h"
26 #include "async_smb.h"
28 /*******************************************************************
29 Setup the word count and byte count for a client smb message.
30 ********************************************************************/
32 int cli_set_message(char *buf
,int num_words
,int num_bytes
,bool zero
)
34 if (zero
&& (num_words
|| num_bytes
)) {
35 memset(buf
+ smb_size
,'\0',num_words
*2 + num_bytes
);
37 SCVAL(buf
,smb_wct
,num_words
);
38 SSVAL(buf
,smb_vwv
+ num_words
*SIZEOFWORD
,num_bytes
);
39 smb_setlen(buf
,smb_size
+ num_words
*2 + num_bytes
- 4);
40 return (smb_size
+ num_words
*2 + num_bytes
);
43 /****************************************************************************
44 Change the timeout (in milliseconds).
45 ****************************************************************************/
47 unsigned int cli_set_timeout(struct cli_state
*cli
, unsigned int timeout
)
49 unsigned int old_timeout
= cli
->timeout
;
50 cli
->timeout
= timeout
;
54 /****************************************************************************
55 convenience routine to find if we negotiated ucs2
56 ****************************************************************************/
58 bool cli_ucs2(struct cli_state
*cli
)
60 return ((cli_state_capabilities(cli
) & CAP_UNICODE
) != 0);
63 /****************************************************************************
64 Setup basics in a outgoing packet.
65 ****************************************************************************/
67 void cli_setup_packet_buf(struct cli_state
*cli
, char *buf
)
71 SIVAL(buf
,smb_rcls
,0);
72 SSVAL(buf
,smb_pid
,cli
->smb1
.pid
);
73 memset(buf
+smb_pidhigh
, 0, 12);
74 SSVAL(buf
,smb_uid
, cli_state_get_uid(cli
));
75 SSVAL(buf
,smb_mid
, 0);
77 if (cli_state_protocol(cli
) <= PROTOCOL_CORE
) {
81 if (cli
->case_sensitive
) {
82 SCVAL(buf
,smb_flg
,0x0);
84 /* Default setting, case insensitive. */
85 SCVAL(buf
,smb_flg
,0x8);
87 flags2
= FLAGS2_LONG_PATH_COMPONENTS
;
88 if (cli_state_capabilities(cli
) & CAP_UNICODE
)
89 flags2
|= FLAGS2_UNICODE_STRINGS
;
90 if ((cli_state_capabilities(cli
) & CAP_DFS
) && cli
->dfsroot
)
91 flags2
|= FLAGS2_DFS_PATHNAMES
;
92 if (cli_state_capabilities(cli
) & CAP_STATUS32
)
93 flags2
|= FLAGS2_32_BIT_ERROR_CODES
;
94 if (cli_state_capabilities(cli
) & CAP_EXTENDED_SECURITY
)
95 flags2
|= FLAGS2_EXTENDED_SECURITY
;
96 SSVAL(buf
,smb_flg2
, flags2
);
99 /****************************************************************************
100 Initialize Domain, user or password.
101 ****************************************************************************/
103 NTSTATUS
cli_set_domain(struct cli_state
*cli
, const char *domain
)
105 TALLOC_FREE(cli
->domain
);
106 cli
->domain
= talloc_strdup(cli
, domain
? domain
: "");
107 if (cli
->domain
== NULL
) {
108 return NT_STATUS_NO_MEMORY
;
113 NTSTATUS
cli_set_username(struct cli_state
*cli
, const char *username
)
115 TALLOC_FREE(cli
->user_name
);
116 cli
->user_name
= talloc_strdup(cli
, username
? username
: "");
117 if (cli
->user_name
== NULL
) {
118 return NT_STATUS_NO_MEMORY
;
123 NTSTATUS
cli_set_password(struct cli_state
*cli
, const char *password
)
125 TALLOC_FREE(cli
->password
);
127 /* Password can be NULL. */
129 cli
->password
= talloc_strdup(cli
, password
);
130 if (cli
->password
== NULL
) {
131 return NT_STATUS_NO_MEMORY
;
134 /* Use zero NTLMSSP hashes and session key. */
135 cli
->password
= NULL
;
141 /****************************************************************************
142 Initialise credentials of a client structure.
143 ****************************************************************************/
145 NTSTATUS
cli_init_creds(struct cli_state
*cli
, const char *username
, const char *domain
, const char *password
)
147 NTSTATUS status
= cli_set_username(cli
, username
);
148 if (!NT_STATUS_IS_OK(status
)) {
151 status
= cli_set_domain(cli
, domain
);
152 if (!NT_STATUS_IS_OK(status
)) {
155 DEBUG(10,("cli_init_creds: user %s domain %s\n", cli
->user_name
, cli
->domain
));
157 return cli_set_password(cli
, password
);
160 /****************************************************************************
161 Initialise a client structure. Always returns a talloc'ed struct.
162 Set the signing state (used from the command line).
163 ****************************************************************************/
165 struct cli_state
*cli_state_create(TALLOC_CTX
*mem_ctx
,
167 const char *remote_name
,
168 const char *remote_realm
,
169 int signing_state
, int flags
)
171 struct cli_state
*cli
= NULL
;
172 bool allow_smb_signing
;
173 bool desire_smb_signing
;
174 bool mandatory_signing
;
177 bool use_spnego
= lp_client_use_spnego();
178 bool force_dos_errors
= false;
179 bool force_ascii
= false;
180 bool use_level_II_oplocks
= false;
182 /* Check the effective uid - make sure we are not setuid */
183 if (is_setuid_root()) {
184 DEBUG(0,("libsmb based programs must *NOT* be setuid root.\n"));
188 cli
= talloc_zero(mem_ctx
, struct cli_state
);
193 cli
->server_domain
= talloc_strdup(cli
, "");
194 if (!cli
->server_domain
) {
197 cli
->server_os
= talloc_strdup(cli
, "");
198 if (!cli
->server_os
) {
201 cli
->server_type
= talloc_strdup(cli
, "");
202 if (!cli
->server_type
) {
206 cli
->dfs_mountpoint
= talloc_strdup(cli
, "");
207 if (!cli
->dfs_mountpoint
) {
210 cli
->raw_status
= NT_STATUS_INTERNAL_ERROR
;
211 cli
->map_dos_errors
= true; /* remove this */
212 cli
->timeout
= 20000; /* Timeout is in milliseconds. */
213 cli
->case_sensitive
= false;
215 /* Set the CLI_FORCE_DOSERR environment variable to test
216 client routines using DOS errors instead of STATUS32
217 ones. This intended only as a temporary hack. */
218 if (getenv("CLI_FORCE_DOSERR")) {
219 force_dos_errors
= true;
221 if (flags
& CLI_FULL_CONNECTION_FORCE_DOS_ERRORS
) {
222 force_dos_errors
= true;
225 if (getenv("CLI_FORCE_ASCII")) {
228 if (flags
& CLI_FULL_CONNECTION_FORCE_ASCII
) {
232 if (flags
& CLI_FULL_CONNECTION_DONT_SPNEGO
) {
234 } else if (flags
& CLI_FULL_CONNECTION_USE_KERBEROS
) {
235 cli
->use_kerberos
= true;
237 if ((flags
& CLI_FULL_CONNECTION_FALLBACK_AFTER_KERBEROS
) &&
239 cli
->fallback_after_kerberos
= true;
242 if (flags
& CLI_FULL_CONNECTION_USE_CCACHE
) {
243 cli
->use_ccache
= true;
246 if (flags
& CLI_FULL_CONNECTION_OPLOCKS
) {
247 cli
->use_oplocks
= true;
249 if (flags
& CLI_FULL_CONNECTION_LEVEL_II_OPLOCKS
) {
250 use_level_II_oplocks
= true;
253 if (signing_state
== SMB_SIGNING_DEFAULT
) {
254 signing_state
= lp_client_signing();
257 switch (signing_state
) {
258 case SMB_SIGNING_OFF
:
260 allow_smb_signing
= false;
261 desire_smb_signing
= false;
262 mandatory_signing
= false;
265 case SMB_SIGNING_DEFAULT
:
266 case SMB_SIGNING_IF_REQUIRED
:
267 allow_smb_signing
= true;
268 desire_smb_signing
= false;
269 mandatory_signing
= false;
271 case SMB_SIGNING_REQUIRED
:
273 allow_smb_signing
= true;
274 desire_smb_signing
= true;
275 mandatory_signing
= true;
279 /* initialise signing */
280 cli
->signing_state
= smb_signing_init(cli
,
284 if (!cli
->signing_state
) {
288 cli
->conn
.smb1
.client
.capabilities
= 0;
289 cli
->conn
.smb1
.client
.capabilities
|= CAP_LARGE_FILES
;
290 cli
->conn
.smb1
.client
.capabilities
|= CAP_NT_SMBS
| CAP_RPC_REMOTE_APIS
;
291 cli
->conn
.smb1
.client
.capabilities
|= CAP_LOCK_AND_READ
| CAP_NT_FIND
;
292 cli
->conn
.smb1
.client
.capabilities
|= CAP_DFS
| CAP_W2K_SMBS
;
293 cli
->conn
.smb1
.client
.capabilities
|= CAP_LARGE_READX
|CAP_LARGE_WRITEX
;
294 cli
->conn
.smb1
.client
.capabilities
|= CAP_LWIO
;
296 if (!force_dos_errors
) {
297 cli
->conn
.smb1
.client
.capabilities
|= CAP_STATUS32
;
301 cli
->conn
.smb1
.client
.capabilities
|= CAP_UNICODE
;
305 cli
->conn
.smb1
.client
.capabilities
|= CAP_EXTENDED_SECURITY
;
308 if (use_level_II_oplocks
) {
309 cli
->conn
.smb1
.client
.capabilities
|= CAP_LEVEL_II_OPLOCKS
;
312 cli
->conn
.smb1
.client
.max_xmit
= CLI_BUFFER_SIZE
;
314 cli
->conn
.smb1
.capabilities
= cli
->conn
.smb1
.client
.capabilities
;
315 cli
->conn
.smb1
.max_xmit
= 1024;
317 cli
->conn
.smb1
.mid
= 1;
319 cli
->conn
.outgoing
= tevent_queue_create(cli
, "cli_outgoing");
320 if (cli
->conn
.outgoing
== NULL
) {
323 cli
->conn
.pending
= NULL
;
325 cli
->conn
.remote_name
= talloc_strdup(cli
, remote_name
);
326 if (cli
->conn
.remote_name
== NULL
) {
331 cli
->conn
.remote_realm
= talloc_strdup(cli
, remote_realm
);
332 if (cli
->conn
.remote_realm
== NULL
) {
339 ss_length
= sizeof(cli
->conn
.local_ss
);
340 ret
= getsockname(fd
,
341 (struct sockaddr
*)(void *)&cli
->conn
.local_ss
,
346 ss_length
= sizeof(cli
->conn
.remote_ss
);
347 ret
= getpeername(fd
,
348 (struct sockaddr
*)(void *)&cli
->conn
.remote_ss
,
354 cli
->smb1
.pid
= (uint16_t)sys_getpid();
355 cli
->smb1
.vc_num
= cli
->smb1
.pid
;
356 cli
->smb1
.tid
= UINT16_MAX
;
357 cli
->smb1
.uid
= UID_FIELD_INVALID
;
359 cli
->initialised
= 1;
362 /* Clean up after malloc() error */
370 bool cli_state_encryption_on(struct cli_state
*cli
)
372 return common_encryption_on(cli
->trans_enc_state
);
376 /****************************************************************************
377 Close all pipes open on this session.
378 ****************************************************************************/
380 void cli_nt_pipes_close(struct cli_state
*cli
)
382 while (cli
->pipe_list
!= NULL
) {
384 * No TALLOC_FREE here!
386 talloc_free(cli
->pipe_list
);
390 /****************************************************************************
391 Shutdown a client structure.
392 ****************************************************************************/
394 static void _cli_shutdown(struct cli_state
*cli
)
396 cli_nt_pipes_close(cli
);
399 * tell our peer to free his resources. Wihtout this, when an
400 * application attempts to do a graceful shutdown and calls
401 * smbc_free_context() to clean up all connections, some connections
402 * can remain active on the peer end, until some (long) timeout period
403 * later. This tree disconnect forces the peer to clean up, since the
404 * connection will be going away.
406 if (cli_state_has_tcon(cli
)) {
410 data_blob_free(&cli
->user_session_key
);
412 cli_state_disconnect(cli
);
415 * Need to free pending first, they remove themselves
417 while (cli
->conn
.pending
) {
418 talloc_free(cli
->conn
.pending
[0]);
423 void cli_shutdown(struct cli_state
*cli
)
425 struct cli_state
*cli_head
;
429 DLIST_HEAD(cli
, cli_head
);
430 if (cli_head
== cli
) {
432 * head of a DFS list, shutdown all subsidiary DFS
435 struct cli_state
*p
, *next
;
437 for (p
= cli_head
->next
; p
; p
= next
) {
439 DLIST_REMOVE(cli_head
, p
);
443 DLIST_REMOVE(cli_head
, cli
);
449 /****************************************************************************
450 Set socket options on a open connection.
451 ****************************************************************************/
453 void cli_sockopt(struct cli_state
*cli
, const char *options
)
455 set_socket_options(cli
->conn
.fd
, options
);
458 const struct sockaddr_storage
*cli_state_local_sockaddr(struct cli_state
*cli
)
460 return &cli
->conn
.local_ss
;
463 const struct sockaddr_storage
*cli_state_remote_sockaddr(struct cli_state
*cli
)
465 return &cli
->conn
.remote_ss
;
468 const char *cli_state_remote_name(struct cli_state
*cli
)
470 return cli
->conn
.remote_name
;
473 const char *cli_state_remote_realm(struct cli_state
*cli
)
475 return cli
->conn
.remote_realm
;
478 uint16_t cli_state_get_vc_num(struct cli_state
*cli
)
480 return cli
->smb1
.vc_num
;
483 uint32_t cli_state_server_session_key(struct cli_state
*cli
)
485 return cli
->conn
.smb1
.server
.session_key
;
488 /****************************************************************************
489 Set the PID to use for smb messages. Return the old pid.
490 ****************************************************************************/
492 uint16
cli_setpid(struct cli_state
*cli
, uint16 pid
)
494 uint16_t ret
= cli
->smb1
.pid
;
499 uint16_t cli_getpid(struct cli_state
*cli
)
501 return cli
->smb1
.pid
;
504 bool cli_state_has_tcon(struct cli_state
*cli
)
506 if (cli
->smb1
.tid
== UINT16_MAX
) {
513 uint16_t cli_state_get_tid(struct cli_state
*cli
)
515 return cli
->smb1
.tid
;
518 uint16_t cli_state_set_tid(struct cli_state
*cli
, uint16_t tid
)
520 uint16_t ret
= cli
->smb1
.tid
;
525 uint16_t cli_state_get_uid(struct cli_state
*cli
)
527 return cli
->smb1
.uid
;
530 uint16_t cli_state_set_uid(struct cli_state
*cli
, uint16_t uid
)
532 uint16_t ret
= cli
->smb1
.uid
;
537 /****************************************************************************
538 Set the case sensitivity flag on the packets. Returns old state.
539 ****************************************************************************/
541 bool cli_set_case_sensitive(struct cli_state
*cli
, bool case_sensitive
)
543 bool ret
= cli
->case_sensitive
;
544 cli
->case_sensitive
= case_sensitive
;
548 enum protocol_types
cli_state_protocol(struct cli_state
*cli
)
550 return cli
->conn
.protocol
;
553 uint32_t cli_state_capabilities(struct cli_state
*cli
)
555 return cli
->conn
.smb1
.capabilities
;
558 uint32_t cli_state_available_size(struct cli_state
*cli
, uint32_t ofs
)
560 uint32_t ret
= cli
->conn
.smb1
.max_xmit
;
571 uint16_t cli_state_max_requests(struct cli_state
*cli
)
573 return cli
->conn
.smb1
.server
.max_mux
;
576 const uint8_t *cli_state_server_challenge(struct cli_state
*cli
)
578 return cli
->conn
.smb1
.server
.challenge
;
581 const DATA_BLOB
*cli_state_server_gss_blob(struct cli_state
*cli
)
583 return &cli
->conn
.smb1
.server
.gss_blob
;
586 uint16_t cli_state_security_mode(struct cli_state
*cli
)
588 return cli
->conn
.smb1
.server
.security_mode
;
591 int cli_state_server_time_zone(struct cli_state
*cli
)
593 return cli
->conn
.smb1
.server
.time_zone
;
596 time_t cli_state_server_time(struct cli_state
*cli
)
598 return cli
->conn
.smb1
.server
.system_time
;
601 struct cli_echo_state
{
607 static void cli_echo_done(struct tevent_req
*subreq
);
609 struct tevent_req
*cli_echo_send(TALLOC_CTX
*mem_ctx
, struct event_context
*ev
,
610 struct cli_state
*cli
, uint16_t num_echos
,
613 struct tevent_req
*req
, *subreq
;
614 struct cli_echo_state
*state
;
616 req
= tevent_req_create(mem_ctx
, &state
, struct cli_echo_state
);
620 SSVAL(state
->vwv
, 0, num_echos
);
622 state
->num_echos
= num_echos
;
624 subreq
= cli_smb_send(state
, ev
, cli
, SMBecho
, 0, 1, state
->vwv
,
625 data
.length
, data
.data
);
626 if (subreq
== NULL
) {
629 tevent_req_set_callback(subreq
, cli_echo_done
, req
);
636 static void cli_echo_done(struct tevent_req
*subreq
)
638 struct tevent_req
*req
= tevent_req_callback_data(
639 subreq
, struct tevent_req
);
640 struct cli_echo_state
*state
= tevent_req_data(
641 req
, struct cli_echo_state
);
647 status
= cli_smb_recv(subreq
, state
, &inbuf
, 0, NULL
, NULL
,
649 if (!NT_STATUS_IS_OK(status
)) {
650 tevent_req_nterror(req
, status
);
653 if ((num_bytes
!= state
->data
.length
)
654 || (memcmp(bytes
, state
->data
.data
, num_bytes
) != 0)) {
655 tevent_req_nterror(req
, NT_STATUS_INVALID_NETWORK_RESPONSE
);
659 state
->num_echos
-=1;
660 if (state
->num_echos
== 0) {
661 tevent_req_done(req
);
665 if (!cli_smb_req_set_pending(subreq
)) {
666 tevent_req_nterror(req
, NT_STATUS_NO_MEMORY
);
672 * Get the result out from an echo request
673 * @param[in] req The async_req from cli_echo_send
674 * @retval Did the server reply correctly?
677 NTSTATUS
cli_echo_recv(struct tevent_req
*req
)
679 return tevent_req_simple_recv_ntstatus(req
);
683 * @brief Send/Receive SMBEcho requests
684 * @param[in] mem_ctx The memory context to put the async_req on
685 * @param[in] ev The event context that will call us back
686 * @param[in] cli The connection to send the echo to
687 * @param[in] num_echos How many times do we want to get the reply?
688 * @param[in] data The data we want to get back
689 * @retval Did the server reply correctly?
692 NTSTATUS
cli_echo(struct cli_state
*cli
, uint16_t num_echos
, DATA_BLOB data
)
694 TALLOC_CTX
*frame
= talloc_stackframe();
695 struct event_context
*ev
;
696 struct tevent_req
*req
;
697 NTSTATUS status
= NT_STATUS_OK
;
699 if (cli_has_async_calls(cli
)) {
701 * Can't use sync call while an async call is in flight
703 status
= NT_STATUS_INVALID_PARAMETER
;
707 ev
= event_context_init(frame
);
709 status
= NT_STATUS_NO_MEMORY
;
713 req
= cli_echo_send(frame
, ev
, cli
, num_echos
, data
);
715 status
= NT_STATUS_NO_MEMORY
;
719 if (!tevent_req_poll(req
, ev
)) {
720 status
= map_nt_error_from_unix(errno
);
724 status
= cli_echo_recv(req
);
731 * Is the SMB command able to hold an AND_X successor
732 * @param[in] cmd The SMB command in question
733 * @retval Can we add a chained request after "cmd"?
735 bool is_andx_req(uint8_t cmd
)
755 NTSTATUS
cli_smb(TALLOC_CTX
*mem_ctx
, struct cli_state
*cli
,
756 uint8_t smb_command
, uint8_t additional_flags
,
757 uint8_t wct
, uint16_t *vwv
,
758 uint32_t num_bytes
, const uint8_t *bytes
,
759 struct tevent_req
**result_parent
,
760 uint8_t min_wct
, uint8_t *pwct
, uint16_t **pvwv
,
761 uint32_t *pnum_bytes
, uint8_t **pbytes
)
763 struct tevent_context
*ev
;
764 struct tevent_req
*req
= NULL
;
765 NTSTATUS status
= NT_STATUS_NO_MEMORY
;
767 if (cli_has_async_calls(cli
)) {
768 return NT_STATUS_INVALID_PARAMETER
;
770 ev
= tevent_context_init(mem_ctx
);
774 req
= cli_smb_send(mem_ctx
, ev
, cli
, smb_command
, additional_flags
,
775 wct
, vwv
, num_bytes
, bytes
);
779 if (!tevent_req_poll_ntstatus(req
, ev
, &status
)) {
782 status
= cli_smb_recv(req
, NULL
, NULL
, min_wct
, pwct
, pvwv
,
786 if (NT_STATUS_IS_OK(status
) && (result_parent
!= NULL
)) {
787 *result_parent
= req
;