Avoid NULL pointer dereference in SMBsendend handler
[samba.git] / source3 / smbd / message.c
index b044b6f92d735ede61d75b8b5697622407ee4cca..a4ffad57b5cebc2dff8f5d81c93f643b8cae5a91 100644 (file)
 
 
 #include "includes.h"
+#include "system/filesys.h"
+#include "smbd/smbd.h"
+#include "smbd/globals.h"
+#include "smbprofile.h"
 
 extern userdom_struct current_user_info;
 
-/* look in server.c for some explanation of these variables */
-static char msgbuf[1600];
-static int msgpos;
-static fstring msgfrom;
-static fstring msgto;
+struct msg_state {
+       char *from;
+       char *to;
+       char *msg;
+};
 
 /****************************************************************************
  Deliver the message.
 ****************************************************************************/
 
-static void msg_deliver(void)
+static void msg_deliver(struct msg_state *state)
 {
-       pstring name;
+       TALLOC_CTX *frame = talloc_stackframe();
+       char *name = NULL;
        int i;
        int fd;
        char *msg;
-       int len;
+       size_t len;
        ssize_t sz;
+       fstring alpha_buf;
+       char *s;
+       mode_t mask;
 
-       if (! (*lp_msg_command())) {
+       if (! (*lp_message_command(frame))) {
                DEBUG(1,("no messaging command specified\n"));
-               msgpos = 0;
-               return;
+               goto done;
        }
 
        /* put it in a temporary file */
-       slprintf(name,sizeof(name)-1, "%s/msg.XXXXXX",tmpdir());
-       fd = smb_mkstemp(name);
+       name = talloc_asprintf(talloc_tos(), "%s/msg.XXXXXX", tmpdir());
+       if (!name) {
+               goto done;
+       }
+       mask = umask(S_IRWXO | S_IRWXG);
+       fd = mkstemp(name);
+       umask(mask);
 
        if (fd == -1) {
-               DEBUG(1,("can't open message file %s\n",name));
-               return;
+               DEBUG(1, ("can't open message file %s: %s\n", name,
+                         strerror(errno)));
+               goto done;
        }
 
        /*
         * Incoming message is in DOS codepage format. Convert to UNIX.
         */
-  
-       if ((len = (int)convert_string_allocate(NULL,CH_DOS, CH_UNIX, msgbuf, msgpos, (void **)(void *)&msg, True)) < 0 || !msg) {
-               DEBUG(3,("Conversion failed, delivering message in DOS codepage format\n"));
-               for (i = 0; i < msgpos;) {
-                       if (msgbuf[i] == '\r' && i < (msgpos-1) && msgbuf[i+1] == '\n') {
-                               i++;
-                               continue;
-                       }
-                       sz = write(fd, &msgbuf[i++], 1);
-                       if ( sz != 1 ) {
-                               DEBUG(0,("Write error to fd %d: %ld(%d)\n",fd, (long)sz, errno ));
-                       }
+
+       if (!convert_string_talloc(talloc_tos(), CH_DOS, CH_UNIX, state->msg,
+                                  talloc_get_size(state->msg), (void *)&msg,
+                                  &len)) {
+               DEBUG(3, ("Conversion failed, delivering message in DOS "
+                         "codepage format\n"));
+               msg = state->msg;
+       }
+
+       for (i = 0; i < len; i++) {
+               if ((msg[i] == '\r') &&
+                   (i < (len-1)) && (msg[i+1] == '\n')) {
+                       continue;
                }
-       } else {
-               for (i = 0; i < len;) {
-                       if (msg[i] == '\r' && i < (len-1) && msg[i+1] == '\n') {
-                               i++;
-                               continue;
-                       }
-                       sz = write(fd, &msg[i++],1);
-                       if ( sz != 1 ) {
-                               DEBUG(0,("Write error to fd %d: %ld(%d)\n",fd, (long)sz, errno ));
-                       }
+               sz = write(fd, &msg[i], 1);
+               if ( sz != 1 ) {
+                       DEBUG(0, ("Write error to fd %d: %ld(%s)\n", fd,
+                                 (long)sz, strerror(errno)));
                }
-               SAFE_FREE(msg);
        }
+
        close(fd);
 
        /* run the command */
-       if (*lp_msg_command()) {
-               fstring alpha_msgfrom;
-               fstring alpha_msgto;
-               pstring s;
+       s = lp_message_command(frame);
+       if (s == NULL) {
+               goto done;
+       }
 
-               pstrcpy(s,lp_msg_command());
-               pstring_sub(s,"%f",alpha_strcpy(alpha_msgfrom,msgfrom,NULL,sizeof(alpha_msgfrom)));
-               pstring_sub(s,"%t",alpha_strcpy(alpha_msgto,msgto,NULL,sizeof(alpha_msgto)));
-               standard_sub_basic(current_user_info.smb_name,
-                               current_user_info.domain, s, sizeof(s));
-               pstring_sub(s,"%s",name);
-               smbrun(s,NULL);
+       alpha_strcpy(alpha_buf, state->from, NULL, sizeof(alpha_buf));
+
+       s = talloc_string_sub(talloc_tos(), s, "%f", alpha_buf);
+       if (s == NULL) {
+               goto done;
        }
 
-       msgpos = 0;
+       alpha_strcpy(alpha_buf, state->to, NULL, sizeof(alpha_buf));
+
+       s = talloc_string_sub(talloc_tos(), s, "%t", alpha_buf);
+       if (s == NULL) {
+               goto done;
+       }
+
+       s = talloc_sub_basic(talloc_tos(), current_user_info.smb_name,
+                            current_user_info.domain, s);
+       if (s == NULL) {
+               goto done;
+       }
+
+       s = talloc_string_sub(talloc_tos(), s, "%s", name);
+       if (s == NULL) {
+               goto done;
+       }
+       smbrun(s, NULL, NULL);
+
+ done:
+       TALLOC_FREE(frame);
+       return;
 }
 
 /****************************************************************************
@@ -114,39 +141,45 @@ static void msg_deliver(void)
  conn POINTER CAN BE NULL HERE !
 ****************************************************************************/
 
-void reply_sends(connection_struct *conn, struct smb_request *req)
+void reply_sends(struct smb_request *req)
 {
+       struct msg_state *state;
        int len;
-       char *msg;
-       char *p;
+       const uint8_t *msg;
+       const uint8_t *p;
 
        START_PROFILE(SMBsends);
 
-       msgpos = 0;
-
-       if (! (*lp_msg_command())) {
-               reply_doserror(req, ERRSRV, ERRmsgoff);
+       if (!(*lp_message_command(talloc_tos()))) {
+               reply_nterror(req, NT_STATUS_REQUEST_NOT_ACCEPTED);
                END_PROFILE(SMBsends);
                return;
        }
 
-       p = smb_buf(req->inbuf)+1;
-       p += srvstr_pull_buf((char *)req->inbuf, req->flags2, msgfrom, p,
-                            sizeof(msgfrom), STR_ASCII|STR_TERMINATE) + 1;
-       p += srvstr_pull_buf((char *)req->inbuf, req->flags2, msgto, p,
-                            sizeof(msgto), STR_ASCII|STR_TERMINATE) + 1;
+       state = talloc(talloc_tos(), struct msg_state);
+
+       p = req->buf + 1;
+       p += srvstr_pull_req_talloc(
+               state, req, &state->from, p, STR_ASCII|STR_TERMINATE) + 1;
+       p += srvstr_pull_req_talloc(
+               state, req, &state->to, p, STR_ASCII|STR_TERMINATE) + 1;
 
        msg = p;
 
        len = SVAL(msg,0);
-       len = MIN(len,sizeof(msgbuf)-msgpos);
+       len = MIN(len, smbreq_bufrem(req, msg+2));
 
-       memset(msgbuf,'\0',sizeof(msgbuf));
+       state->msg = talloc_array(state, char, len);
+
+       if (state->msg == NULL) {
+               reply_nterror(req, NT_STATUS_NO_MEMORY);
+               END_PROFILE(SMBsends);
+               return;
+       }
 
-       memcpy(&msgbuf[msgpos],msg+2,len);
-       msgpos += len;
+       memcpy(state->msg, msg+2, len);
 
-       msg_deliver();
+       msg_deliver(state);
 
        reply_outbuf(req, 0, 0);
 
@@ -159,28 +192,42 @@ void reply_sends(connection_struct *conn, struct smb_request *req)
  conn POINTER CAN BE NULL HERE !
 ****************************************************************************/
 
-void reply_sendstrt(connection_struct *conn, struct smb_request *req)
+void reply_sendstrt(struct smb_request *req)
 {
-       char *p;
+       struct smbXsrv_connection *xconn = req->xconn;
+       const uint8_t *p;
 
        START_PROFILE(SMBsendstrt);
 
-       if (! (*lp_msg_command())) {
-               reply_doserror(req, ERRSRV, ERRmsgoff);
+       if (!(*lp_message_command(talloc_tos()))) {
+               reply_nterror(req, NT_STATUS_REQUEST_NOT_ACCEPTED);
                END_PROFILE(SMBsendstrt);
                return;
        }
 
-       memset(msgbuf,'\0',sizeof(msgbuf));
-       msgpos = 0;
+       TALLOC_FREE(xconn->smb1.msg_state);
 
-       p = smb_buf(req->inbuf)+1;
-       p += srvstr_pull_buf((char *)req->inbuf, req->flags2, msgfrom, p,
-                            sizeof(msgfrom), STR_ASCII|STR_TERMINATE) + 1;
-       p += srvstr_pull_buf((char *)req->inbuf, req->flags2, msgto, p,
-                            sizeof(msgto), STR_ASCII|STR_TERMINATE) + 1;
+       xconn->smb1.msg_state = talloc_zero(xconn, struct msg_state);
 
-       DEBUG( 3, ( "SMBsendstrt (from %s to %s)\n", msgfrom, msgto ) );
+       if (xconn->smb1.msg_state == NULL) {
+               reply_nterror(req, NT_STATUS_NO_MEMORY);
+               END_PROFILE(SMBsendstrt);
+               return;
+       }
+
+       p = req->buf+1;
+       p += srvstr_pull_req_talloc(
+               xconn->smb1.msg_state, req,
+               &xconn->smb1.msg_state->from, p,
+               STR_ASCII|STR_TERMINATE) + 1;
+       p += srvstr_pull_req_talloc(
+               xconn->smb1.msg_state, req,
+               &xconn->smb1.msg_state->to, p,
+               STR_ASCII|STR_TERMINATE) + 1;
+
+       DEBUG(3, ("SMBsendstrt (from %s to %s)\n",
+                 xconn->smb1.msg_state->from,
+                 xconn->smb1.msg_state->to));
 
        reply_outbuf(req, 0, 0);
 
@@ -193,25 +240,47 @@ void reply_sendstrt(connection_struct *conn, struct smb_request *req)
  conn POINTER CAN BE NULL HERE !
 ****************************************************************************/
 
-void reply_sendtxt(connection_struct *conn, struct smb_request *req)
+void reply_sendtxt(struct smb_request *req)
 {
+       struct smbXsrv_connection *xconn = req->xconn;
        int len;
-       char *msg;
+       const char *msg;
+       char *tmp;
+       size_t old_len;
+
        START_PROFILE(SMBsendtxt);
 
-       if (! (*lp_msg_command())) {
-               reply_doserror(req, ERRSRV, ERRmsgoff);
+       if (! (*lp_message_command(talloc_tos()))) {
+               reply_nterror(req, NT_STATUS_REQUEST_NOT_ACCEPTED);
+               END_PROFILE(SMBsendtxt);
+               return;
+       }
+
+       if ((xconn->smb1.msg_state == NULL) || (req->buflen < 3)) {
+               reply_nterror(req, NT_STATUS_INVALID_PARAMETER);
                END_PROFILE(SMBsendtxt);
                return;
        }
 
-       msg = smb_buf(req->inbuf) + 1;
+       msg = (const char *)req->buf + 1;
 
-       len = SVAL(msg,0);
-       len = MIN(len,sizeof(msgbuf)-msgpos);
+       old_len = talloc_get_size(xconn->smb1.msg_state->msg);
 
-       memcpy(&msgbuf[msgpos],msg+2,len);
-       msgpos += len;
+       len = MIN(SVAL(msg, 0), smbreq_bufrem(req, msg+2));
+
+       tmp = talloc_realloc(xconn->smb1.msg_state,
+                            xconn->smb1.msg_state->msg,
+                            char, old_len + len);
+
+       if (tmp == NULL) {
+               reply_nterror(req, NT_STATUS_NO_MEMORY);
+               END_PROFILE(SMBsendtxt);
+               return;
+       }
+
+       xconn->smb1.msg_state->msg = tmp;
+
+       memcpy(&xconn->smb1.msg_state->msg[old_len], msg+2, len);
 
        DEBUG( 3, ( "SMBsendtxt\n" ) );
 
@@ -226,19 +295,28 @@ void reply_sendtxt(connection_struct *conn, struct smb_request *req)
  conn POINTER CAN BE NULL HERE !
 ****************************************************************************/
 
-void reply_sendend(connection_struct *conn, struct smb_request *req)
+void reply_sendend(struct smb_request *req)
 {
+       struct smbXsrv_connection *xconn = req->xconn;
        START_PROFILE(SMBsendend);
 
-       if (! (*lp_msg_command())) {
-               reply_doserror(req, ERRSRV, ERRmsgoff);
+       if (! (*lp_message_command(talloc_tos()))) {
+               reply_nterror(req, NT_STATUS_REQUEST_NOT_ACCEPTED);
+               END_PROFILE(SMBsendend);
+               return;
+       }
+
+       if (xconn->smb1.msg_state == NULL) {
+               reply_nterror(req, NT_STATUS_INVALID_PARAMETER);
                END_PROFILE(SMBsendend);
                return;
        }
 
        DEBUG(3,("SMBsendend\n"));
 
-       msg_deliver();
+       msg_deliver(xconn->smb1.msg_state);
+
+       TALLOC_FREE(xconn->smb1.msg_state);
 
        reply_outbuf(req, 0, 0);