Fix bug #8953 - winbind can hang as nbt_getdc() has no timeout.
[ddiss/samba.git] / source3 / libsmb / clidgram.c
index 734564dcbb5b349b2a6d7f6dfecc28634cc39659..c7ff6ca30b61ca4fddd4eb53f9597bef7a29e3a5 100644 (file)
 */
 
 #include "includes.h"
-#include "librpc/gen_ndr/messaging.h"
+#include "libsmb/libsmb.h"
+#include "../lib/util/tevent_ntstatus.h"
 #include "libsmb/clidgram.h"
+#include "libsmb/nmblib.h"
+#include "messages.h"
 
 /*
  * cli_send_mailslot, send a mailslot for client code ...
@@ -174,61 +177,16 @@ fail:
        return ret;
 }
 
-bool send_getdc_request(struct messaging_context *msg_ctx,
-                       const struct sockaddr_storage *dc_ss,
-                       const char *domain_name,
-                       const struct dom_sid *sid,
-                       uint32_t nt_version,
-                       int dgm_id)
+static bool parse_getdc_response(
+       struct packet_struct *packet,
+       TALLOC_CTX *mem_ctx,
+       const char *domain_name,
+       uint32_t *nt_version,
+       const char **dc_name,
+       struct netlogon_samlogon_response **samlogon_response)
 {
-       struct packet_struct p;
-       pid_t nmbd_pid;
-       char *my_mailslot;
-       struct in_addr dc_ip;
-       NTSTATUS status;
-
-       if ((nmbd_pid = pidfile_pid("nmbd")) == 0) {
-               DEBUG(3, ("No nmbd found\n"));
-               return False;
-       }
-
-       if (dc_ss->ss_family != AF_INET) {
-               return false;
-       }
-       dc_ip = ((struct sockaddr_in *)dc_ss)->sin_addr;
-
-       my_mailslot = mailslot_name(talloc_tos(), dc_ip);
-       if (my_mailslot == NULL) {
-               return NULL;
-       }
-
-       if (!prep_getdc_request(dc_ss, domain_name, sid, nt_version,
-                               my_mailslot, dgm_id, &p)) {
-               TALLOC_FREE(my_mailslot);
-               return false;
-       }
-
-       status = messaging_send_buf(msg_ctx, pid_to_procid(nmbd_pid),
-                                   MSG_SEND_PACKET,
-                                   (uint8 *)&p, sizeof(p));
-       TALLOC_FREE(my_mailslot);
-
-       return NT_STATUS_IS_OK(status);
-}
-
-bool receive_getdc_response(TALLOC_CTX *mem_ctx,
-                           const struct sockaddr_storage *dc_ss,
-                           const char *domain_name,
-                           int dgm_id,
-                           uint32_t *nt_version,
-                           const char **dc_name,
-                           struct netlogon_samlogon_response **samlogon_response)
-{
-       struct packet_struct *packet = NULL;
-       char *my_mailslot = NULL;
-       struct in_addr dc_ip;
        DATA_BLOB blob;
-       struct netlogon_samlogon_response *r = NULL;
+       struct netlogon_samlogon_response *r;
        union dgram_message_body p;
        enum ndr_err_code ndr_err;
        NTSTATUS status;
@@ -236,37 +194,16 @@ bool receive_getdc_response(TALLOC_CTX *mem_ctx,
        const char *returned_dc = NULL;
        const char *returned_domain = NULL;
 
-       if (dc_ss->ss_family != AF_INET) {
-               return false;
-       }
-
-       dc_ip = ((struct sockaddr_in *)dc_ss)->sin_addr;
-
-       my_mailslot = mailslot_name(mem_ctx, dc_ip);
-       if (!my_mailslot) {
-               return false;
-       }
-
-       packet = receive_unexpected(DGRAM_PACKET, dgm_id, my_mailslot);
-
-       if (packet == NULL) {
-               DEBUG(5, ("Did not receive packet for %s\n", my_mailslot));
-               return False;
-       }
-
-       DEBUG(5, ("Received packet for %s\n", my_mailslot));
-
        blob = data_blob_const(packet->packet.dgram.data,
                               packet->packet.dgram.datasize);
-
        if (blob.length < 4) {
-               DEBUG(0,("invalid length: %d\n", (int)blob.length));
-               goto fail;
+               DEBUG(1, ("invalid length: %d\n", (int)blob.length));
+               return false;
        }
 
        if (RIVAL(blob.data,0) != DGRAM_SMB) {
-               DEBUG(0,("invalid packet\n"));
-               goto fail;
+               DEBUG(1, ("invalid packet\n"));
+               return false;
        }
 
        blob.data += 4;
@@ -275,13 +212,13 @@ bool receive_getdc_response(TALLOC_CTX *mem_ctx,
        ndr_err = ndr_pull_union_blob_all(&blob, mem_ctx, &p, DGRAM_SMB,
                       (ndr_pull_flags_fn_t)ndr_pull_dgram_smb_packet);
        if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
-               DEBUG(0,("failed to parse packet\n"));
-               goto fail;
+               DEBUG(1, ("failed to parse packet\n"));
+               return false;
        }
 
        if (p.smb.smb_command != SMB_TRANSACTION) {
-               DEBUG(0,("invalid smb_command: %d\n", p.smb.smb_command));
-               goto fail;
+               DEBUG(1, ("invalid smb_command: %d\n", p.smb.smb_command));
+               return false;
        }
 
        if (DEBUGLEVEL >= 10) {
@@ -292,12 +229,13 @@ bool receive_getdc_response(TALLOC_CTX *mem_ctx,
 
        r = TALLOC_ZERO_P(mem_ctx, struct netlogon_samlogon_response);
        if (!r) {
-               goto fail;
+               return false;
        }
 
-       status = pull_netlogon_samlogon_response(&blob, mem_ctx, r);
+       status = pull_netlogon_samlogon_response(&blob, r, r);
        if (!NT_STATUS_IS_OK(status)) {
-               goto fail;
+               TALLOC_FREE(r);
+               return false;
        }
 
        map_netlogon_samlogon_response(r);
@@ -311,17 +249,19 @@ bool receive_getdc_response(TALLOC_CTX *mem_ctx,
        if (!strequal(returned_domain, domain_name)) {
                DEBUG(3, ("GetDC: Expected domain %s, got %s\n",
                          domain_name, returned_domain));
-               goto fail;
+               TALLOC_FREE(r);
+               return false;
        }
 
+       if (*returned_dc == '\\') returned_dc += 1;
+       if (*returned_dc == '\\') returned_dc += 1;
+
        *dc_name = talloc_strdup(mem_ctx, returned_dc);
        if (!*dc_name) {
-               goto fail;
+               TALLOC_FREE(r);
+               return false;
        }
 
-       if (**dc_name == '\\')  *dc_name += 1;
-       if (**dc_name == '\\')  *dc_name += 1;
-
        if (samlogon_response) {
                *samlogon_response = r;
        } else {
@@ -331,15 +271,205 @@ bool receive_getdc_response(TALLOC_CTX *mem_ctx,
        DEBUG(10, ("GetDC gave name %s for domain %s\n",
                   *dc_name, returned_domain));
 
-       free_packet(packet);
-       TALLOC_FREE(my_mailslot);
        return True;
+}
 
-fail:
-       TALLOC_FREE(my_mailslot);
-       TALLOC_FREE(r);
-       if (packet != NULL) {
-               free_packet(packet);
+struct nbt_getdc_state {
+       struct tevent_context *ev;
+       struct messaging_context *msg_ctx;
+       struct nb_packet_reader *reader;
+       const char *my_mailslot;
+       pid_t nmbd_pid;
+
+       const struct sockaddr_storage *dc_addr;
+       const char *domain_name;
+       const struct dom_sid *sid;
+       uint32_t nt_version;
+       const char *dc_name;
+       struct netlogon_samlogon_response *samlogon_response;
+
+       struct packet_struct p;
+};
+
+static void nbt_getdc_got_reader(struct tevent_req *subreq);
+static void nbt_getdc_got_response(struct tevent_req *subreq);
+
+struct tevent_req *nbt_getdc_send(TALLOC_CTX *mem_ctx,
+                                 struct tevent_context *ev,
+                                 struct messaging_context *msg_ctx,
+                                 const struct sockaddr_storage *dc_addr,
+                                 const char *domain_name,
+                                 const struct dom_sid *sid,
+                                 uint32_t nt_version)
+{
+       struct tevent_req *req, *subreq;
+       struct nbt_getdc_state *state;
+       uint16_t dgm_id;
+
+       req = tevent_req_create(mem_ctx, &state, struct nbt_getdc_state);
+       if (req == NULL) {
+               return NULL;
+       }
+       state->ev = ev;
+       state->msg_ctx = msg_ctx;
+       state->dc_addr = dc_addr;
+       state->domain_name = domain_name;
+       state->sid = sid;
+       state->nt_version = nt_version;
+
+       if (dc_addr->ss_family != AF_INET) {
+               tevent_req_nterror(req, NT_STATUS_NOT_SUPPORTED);
+               return tevent_req_post(req, ev);
        }
-       return false;
+       state->my_mailslot = mailslot_name(
+               state, ((struct sockaddr_in *)dc_addr)->sin_addr);
+       if (tevent_req_nomem(state->my_mailslot, req)) {
+               return tevent_req_post(req, ev);
+       }
+       state->nmbd_pid = pidfile_pid("nmbd");
+       if (state->nmbd_pid == 0) {
+               DEBUG(3, ("No nmbd found\n"));
+               tevent_req_nterror(req, NT_STATUS_NOT_SUPPORTED);
+               return tevent_req_post(req, ev);
+       }
+
+       generate_random_buffer((uint8_t *)(void *)&dgm_id, sizeof(dgm_id));
+
+       if (!prep_getdc_request(dc_addr, domain_name, sid, nt_version,
+                               state->my_mailslot, dgm_id & 0x7fff,
+                               &state->p)) {
+               DEBUG(3, ("prep_getdc_request failed\n"));
+               tevent_req_nterror(req, NT_STATUS_INVALID_PARAMETER);
+               return tevent_req_post(req, ev);
+       }
+
+       subreq = nb_packet_reader_send(state, ev, DGRAM_PACKET, -1,
+                                      state->my_mailslot);
+       if (tevent_req_nomem(subreq, req)) {
+               return tevent_req_post(req, ev);
+       }
+       tevent_req_set_callback(subreq, nbt_getdc_got_reader, req);
+       return req;
+}
+
+static void nbt_getdc_got_reader(struct tevent_req *subreq)
+{
+       struct tevent_req *req = tevent_req_callback_data(
+               subreq, struct tevent_req);
+       struct nbt_getdc_state *state = tevent_req_data(
+               req, struct nbt_getdc_state);
+       NTSTATUS status;
+
+       status = nb_packet_reader_recv(subreq, state, &state->reader);
+       TALLOC_FREE(subreq);
+       if (tevent_req_nterror(req, status)) {
+               DEBUG(10, ("nb_packet_reader_recv returned %s\n",
+                          nt_errstr(status)));
+               return;
+       }
+
+       status = messaging_send_buf(
+               state->msg_ctx, pid_to_procid(state->nmbd_pid),
+               MSG_SEND_PACKET, (uint8_t *)&state->p, sizeof(state->p));
+
+       if (tevent_req_nterror(req, status)) {
+               DEBUG(10, ("messaging_send_buf returned %s\n",
+                          nt_errstr(status)));
+               return;
+       }
+       subreq = nb_packet_read_send(state, state->ev, state->reader);
+       if (tevent_req_nomem(subreq, req)) {
+               return;
+       }
+       tevent_req_set_callback(subreq, nbt_getdc_got_response, req);
+}
+
+static void nbt_getdc_got_response(struct tevent_req *subreq)
+{
+       struct tevent_req *req = tevent_req_callback_data(
+               subreq, struct tevent_req);
+       struct nbt_getdc_state *state = tevent_req_data(
+               req, struct nbt_getdc_state);
+       struct packet_struct *p;
+       NTSTATUS status;
+       bool ret;
+
+       status = nb_packet_read_recv(subreq, &p);
+       TALLOC_FREE(subreq);
+       if (tevent_req_nterror(req, status)) {
+               return;
+       }
+
+       ret = parse_getdc_response(p, state, state->domain_name,
+                                  &state->nt_version, &state->dc_name,
+                                  &state->samlogon_response);
+       free_packet(p);
+       if (!ret) {
+               tevent_req_nterror(req, NT_STATUS_INVALID_NETWORK_RESPONSE);
+               return;
+       }
+       tevent_req_done(req);
+}
+
+NTSTATUS nbt_getdc_recv(struct tevent_req *req, TALLOC_CTX *mem_ctx,
+                       uint32_t *nt_version, const char **dc_name,
+                       struct netlogon_samlogon_response **samlogon_response)
+{
+       struct nbt_getdc_state *state = tevent_req_data(
+               req, struct nbt_getdc_state);
+       NTSTATUS status;
+
+       if (tevent_req_is_nterror(req, &status)) {
+               return status;
+       }
+       if (nt_version != NULL) {
+               *nt_version = state->nt_version;
+       }
+       if (dc_name != NULL) {
+               *dc_name = talloc_move(mem_ctx, &state->dc_name);
+       }
+       if (samlogon_response != NULL) {
+               *samlogon_response = talloc_move(
+                       mem_ctx, &state->samlogon_response);
+       }
+       return NT_STATUS_OK;
+}
+
+NTSTATUS nbt_getdc(struct messaging_context *msg_ctx,
+                  uint32_t timeout_in_seconds,
+                  const struct sockaddr_storage *dc_addr,
+                  const char *domain_name,
+                  const struct dom_sid *sid,
+                  uint32_t nt_version,
+                  TALLOC_CTX *mem_ctx,
+                  uint32_t *pnt_version,
+                  const char **dc_name,
+                  struct netlogon_samlogon_response **samlogon_response)
+{
+       TALLOC_CTX *frame = talloc_stackframe();
+       struct tevent_context *ev;
+       struct tevent_req *req;
+       NTSTATUS status = NT_STATUS_NO_MEMORY;
+
+       ev = tevent_context_init(frame);
+       if (ev == NULL) {
+               goto fail;
+       }
+       req = nbt_getdc_send(ev, ev, msg_ctx, dc_addr, domain_name,
+                            sid, nt_version);
+       if (req == NULL) {
+               goto fail;
+       }
+       if (!tevent_req_set_endtime(req, ev,
+                       timeval_current_ofs(timeout_in_seconds, 0))) {
+               goto fail;
+       }
+       if (!tevent_req_poll_ntstatus(req, ev, &status)) {
+               goto fail;
+       }
+       status = nbt_getdc_recv(req, mem_ctx, pnt_version, dc_name,
+                               samlogon_response);
+ fail:
+       TALLOC_FREE(frame);
+       return status;
 }