Final fix for #7331 - Compound async SMB 2 requests don't work right.
[samba.git] / source3 / smbd / smb2_notify.c
1 /*
2    Unix SMB/CIFS implementation.
3    Core SMB2 server
4
5    Copyright (C) Stefan Metzmacher 2009
6
7    This program is free software; you can redistribute it and/or modify
8    it under the terms of the GNU General Public License as published by
9    the Free Software Foundation; either version 3 of the License, or
10    (at your option) any later version.
11
12    This program is distributed in the hope that it will be useful,
13    but WITHOUT ANY WARRANTY; without even the implied warranty of
14    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15    GNU General Public License for more details.
16
17    You should have received a copy of the GNU General Public License
18    along with this program.  If not, see <http://www.gnu.org/licenses/>.
19 */
20
21 #include "includes.h"
22 #include "smbd/globals.h"
23 #include "../libcli/smb/smb_common.h"
24
25 static struct tevent_req *smbd_smb2_notify_send(TALLOC_CTX *mem_ctx,
26                                                 struct tevent_context *ev,
27                                                 struct smbd_smb2_request *smb2req,
28                                                 uint16_t in_flags,
29                                                 uint32_t in_output_buffer_length,
30                                                 uint64_t in_file_id_volatile,
31                                                 uint64_t in_completion_filter);
32 static NTSTATUS smbd_smb2_notify_recv(struct tevent_req *req,
33                                       TALLOC_CTX *mem_ctx,
34                                       DATA_BLOB *out_output_buffer);
35
36 static void smbd_smb2_request_notify_done(struct tevent_req *subreq);
37 NTSTATUS smbd_smb2_request_process_notify(struct smbd_smb2_request *req)
38 {
39         const uint8_t *inhdr;
40         const uint8_t *inbody;
41         int i = req->current_idx;
42         size_t expected_body_size = 0x20;
43         size_t body_size;
44         uint16_t in_flags;
45         uint32_t in_output_buffer_length;
46         uint64_t in_file_id_persistent;
47         uint64_t in_file_id_volatile;
48         uint64_t in_completion_filter;
49         struct tevent_req *subreq;
50
51         inhdr = (const uint8_t *)req->in.vector[i+0].iov_base;
52         if (req->in.vector[i+1].iov_len != (expected_body_size & 0xFFFFFFFE)) {
53                 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
54         }
55
56         inbody = (const uint8_t *)req->in.vector[i+1].iov_base;
57
58         body_size = SVAL(inbody, 0x00);
59         if (body_size != expected_body_size) {
60                 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
61         }
62
63         in_flags                = SVAL(inbody, 0x02);
64         in_output_buffer_length = IVAL(inbody, 0x04);
65         in_file_id_persistent   = BVAL(inbody, 0x08);
66         in_file_id_volatile     = BVAL(inbody, 0x10);
67         in_completion_filter    = IVAL(inbody, 0x18);
68
69         /*
70          * 0x00010000 is what Windows 7 uses,
71          * Windows 2008 uses 0x00080000
72          */
73         if (in_output_buffer_length > lp_smb2_max_trans()) {
74                 return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
75         }
76
77         if (req->compat_chain_fsp) {
78                 /* skip check */
79         } else if (in_file_id_persistent != 0) {
80                 return smbd_smb2_request_error(req, NT_STATUS_FILE_CLOSED);
81         }
82
83         subreq = smbd_smb2_notify_send(req,
84                                        req->sconn->smb2.event_ctx,
85                                        req,
86                                        in_flags,
87                                        in_output_buffer_length,
88                                        in_file_id_volatile,
89                                        in_completion_filter);
90         if (subreq == NULL) {
91                 return smbd_smb2_request_error(req, NT_STATUS_NO_MEMORY);
92         }
93         tevent_req_set_callback(subreq, smbd_smb2_request_notify_done, req);
94
95         return smbd_smb2_request_pending_queue(req, subreq);
96 }
97
98 static void smbd_smb2_request_notify_done(struct tevent_req *subreq)
99 {
100         struct smbd_smb2_request *req = tevent_req_callback_data(subreq,
101                                         struct smbd_smb2_request);
102         int i = req->current_idx;
103         uint8_t *outhdr;
104         DATA_BLOB outbody;
105         DATA_BLOB outdyn;
106         uint16_t out_output_buffer_offset;
107         DATA_BLOB out_output_buffer = data_blob_null;
108         NTSTATUS status;
109         NTSTATUS error; /* transport error */
110
111         if (req->cancelled) {
112                 const uint8_t *inhdr = (const uint8_t *)req->in.vector[i].iov_base;
113                 uint64_t mid = BVAL(inhdr, SMB2_HDR_MESSAGE_ID);
114                 DEBUG(10,("smbd_smb2_request_notify_done: cancelled mid %llu\n",
115                         (unsigned long long)mid ));
116                 error = smbd_smb2_request_error(req, NT_STATUS_CANCELLED);
117                 if (!NT_STATUS_IS_OK(error)) {
118                         smbd_server_connection_terminate(req->sconn,
119                                 nt_errstr(error));
120                         return;
121                 }
122                 TALLOC_FREE(subreq);
123                 return;
124         }
125
126         status = smbd_smb2_notify_recv(subreq,
127                                        req,
128                                        &out_output_buffer);
129         TALLOC_FREE(subreq);
130         if (!NT_STATUS_IS_OK(status)) {
131                 error = smbd_smb2_request_error(req, status);
132                 if (!NT_STATUS_IS_OK(error)) {
133                         smbd_server_connection_terminate(req->sconn,
134                                                          nt_errstr(error));
135                         return;
136                 }
137                 return;
138         }
139
140         out_output_buffer_offset = SMB2_HDR_BODY + 0x08;
141
142         outhdr = (uint8_t *)req->out.vector[i].iov_base;
143
144         outbody = data_blob_talloc(req->out.vector, NULL, 0x08);
145         if (outbody.data == NULL) {
146                 error = smbd_smb2_request_error(req, NT_STATUS_NO_MEMORY);
147                 if (!NT_STATUS_IS_OK(error)) {
148                         smbd_server_connection_terminate(req->sconn,
149                                                          nt_errstr(error));
150                         return;
151                 }
152                 return;
153         }
154
155         SSVAL(outbody.data, 0x00, 0x08 + 1);    /* struct size */
156         SSVAL(outbody.data, 0x02,
157               out_output_buffer_offset);        /* output buffer offset */
158         SIVAL(outbody.data, 0x04,
159               out_output_buffer.length);        /* output buffer length */
160
161         outdyn = out_output_buffer;
162
163         error = smbd_smb2_request_done(req, outbody, &outdyn);
164         if (!NT_STATUS_IS_OK(error)) {
165                 smbd_server_connection_terminate(req->sconn,
166                                                  nt_errstr(error));
167                 return;
168         }
169 }
170
171 struct smbd_smb2_notify_state {
172         struct smbd_smb2_request *smb2req;
173         struct smb_request *smbreq;
174         struct tevent_immediate *im;
175         NTSTATUS status;
176         DATA_BLOB out_output_buffer;
177 };
178
179 static void smbd_smb2_notify_reply(struct smb_request *smbreq,
180                                    NTSTATUS error_code,
181                                    uint8_t *buf, size_t len);
182 static void smbd_smb2_notify_reply_trigger(struct tevent_context *ctx,
183                                            struct tevent_immediate *im,
184                                            void *private_data);
185 static bool smbd_smb2_notify_cancel(struct tevent_req *req);
186
187 static struct tevent_req *smbd_smb2_notify_send(TALLOC_CTX *mem_ctx,
188                                                 struct tevent_context *ev,
189                                                 struct smbd_smb2_request *smb2req,
190                                                 uint16_t in_flags,
191                                                 uint32_t in_output_buffer_length,
192                                                 uint64_t in_file_id_volatile,
193                                                 uint64_t in_completion_filter)
194 {
195         struct tevent_req *req;
196         struct smbd_smb2_notify_state *state;
197         struct smb_request *smbreq;
198         connection_struct *conn = smb2req->tcon->compat_conn;
199         files_struct *fsp;
200         bool recursive = (in_flags & 0x0001) ? true : false;
201         NTSTATUS status;
202
203         req = tevent_req_create(mem_ctx, &state,
204                                 struct smbd_smb2_notify_state);
205         if (req == NULL) {
206                 return NULL;
207         }
208         state->smb2req = smb2req;
209         state->status = NT_STATUS_INTERNAL_ERROR;
210         state->out_output_buffer = data_blob_null;
211         state->im = NULL;
212
213         DEBUG(10,("smbd_smb2_notify_send: file_id[0x%016llX]\n",
214                   (unsigned long long)in_file_id_volatile));
215
216         smbreq = smbd_smb2_fake_smb_request(smb2req);
217         if (tevent_req_nomem(smbreq, req)) {
218                 return tevent_req_post(req, ev);
219         }
220
221         state->smbreq = smbreq;
222         smbreq->async_priv = (void *)req;
223
224         fsp = file_fsp(smbreq, (uint16_t)in_file_id_volatile);
225         if (fsp == NULL) {
226                 tevent_req_nterror(req, NT_STATUS_FILE_CLOSED);
227                 return tevent_req_post(req, ev);
228         }
229         if (conn != fsp->conn) {
230                 tevent_req_nterror(req, NT_STATUS_FILE_CLOSED);
231                 return tevent_req_post(req, ev);
232         }
233         if (smb2req->session->vuid != fsp->vuid) {
234                 tevent_req_nterror(req, NT_STATUS_FILE_CLOSED);
235                 return tevent_req_post(req, ev);
236         }
237
238         {
239                 char *filter_string;
240
241                 filter_string = notify_filter_string(NULL, in_completion_filter);
242                 if (tevent_req_nomem(filter_string, req)) {
243                         return tevent_req_post(req, ev);
244                 }
245
246                 DEBUG(3,("smbd_smb2_notify_send: notify change "
247                          "called on %s, filter = %s, recursive = %d\n",
248                          fsp_str_dbg(fsp), filter_string, recursive));
249
250                 TALLOC_FREE(filter_string);
251         }
252
253         if ((!fsp->is_directory) || (conn != fsp->conn)) {
254                 tevent_req_nterror(req, NT_STATUS_INVALID_PARAMETER);
255                 return tevent_req_post(req, ev);
256         }
257
258         if (fsp->notify == NULL) {
259
260                 status = change_notify_create(fsp,
261                                               in_completion_filter,
262                                               recursive);
263                 if (!NT_STATUS_IS_OK(status)) {
264                         DEBUG(10, ("change_notify_create returned %s\n",
265                                    nt_errstr(status)));
266                         tevent_req_nterror(req, status);
267                         return tevent_req_post(req, ev);
268                 }
269         }
270
271         if (fsp->notify->num_changes != 0) {
272
273                 /*
274                  * We've got changes pending, respond immediately
275                  */
276
277                 /*
278                  * TODO: write a torture test to check the filtering behaviour
279                  * here.
280                  */
281
282                 change_notify_reply(fsp->conn, smbreq,
283                                     NT_STATUS_OK,
284                                     in_output_buffer_length,
285                                     fsp->notify,
286                                     smbd_smb2_notify_reply);
287
288                 /*
289                  * change_notify_reply() above has independently
290                  * called tevent_req_done().
291                  */
292                 return tevent_req_post(req, ev);
293         }
294
295         state->im = tevent_create_immediate(state);
296         if (tevent_req_nomem(state->im, req)) {
297                 return tevent_req_post(req, ev);
298         }
299
300         /*
301          * No changes pending, queue the request
302          */
303
304         status = change_notify_add_request(smbreq,
305                         in_output_buffer_length,
306                         in_completion_filter,
307                         recursive, fsp,
308                         smbd_smb2_notify_reply);
309         if (!NT_STATUS_IS_OK(status)) {
310                 tevent_req_nterror(req, status);
311                 return tevent_req_post(req, ev);
312         }
313
314         /* allow this request to be canceled */
315         tevent_req_set_cancel_fn(req, smbd_smb2_notify_cancel);
316
317         return req;
318 }
319
320 static void smbd_smb2_notify_reply(struct smb_request *smbreq,
321                                    NTSTATUS error_code,
322                                    uint8_t *buf, size_t len)
323 {
324         struct tevent_req *req = talloc_get_type_abort(smbreq->async_priv,
325                                                        struct tevent_req);
326         struct smbd_smb2_notify_state *state = tevent_req_data(req,
327                                                struct smbd_smb2_notify_state);
328
329         state->status = error_code;
330         if (!NT_STATUS_IS_OK(error_code)) {
331                 /* nothing */
332         } else if (len == 0) {
333                 state->status = STATUS_NOTIFY_ENUM_DIR;
334         } else {
335                 state->out_output_buffer = data_blob_talloc(state, buf, len);
336                 if (state->out_output_buffer.data == NULL) {
337                         state->status = NT_STATUS_NO_MEMORY;
338                 }
339         }
340
341         if (state->im == NULL) {
342                 smbd_smb2_notify_reply_trigger(NULL, NULL, req);
343                 return;
344         }
345
346         /*
347          * if this is called async, we need to go via an immediate event
348          * because the caller replies on the smb_request (a child of req
349          * being arround after calling this function
350          */
351         tevent_schedule_immediate(state->im,
352                                   state->smb2req->sconn->smb2.event_ctx,
353                                   smbd_smb2_notify_reply_trigger,
354                                   req);
355 }
356
357 static void smbd_smb2_notify_reply_trigger(struct tevent_context *ctx,
358                                            struct tevent_immediate *im,
359                                            void *private_data)
360 {
361         struct tevent_req *req = talloc_get_type_abort(private_data,
362                                                        struct tevent_req);
363         struct smbd_smb2_notify_state *state = tevent_req_data(req,
364                                                struct smbd_smb2_notify_state);
365
366         if (!NT_STATUS_IS_OK(state->status)) {
367                 tevent_req_nterror(req, state->status);
368                 return;
369         }
370
371         tevent_req_done(req);
372 }
373
374 static bool smbd_smb2_notify_cancel(struct tevent_req *req)
375 {
376         struct smbd_smb2_notify_state *state = tevent_req_data(req,
377                                                struct smbd_smb2_notify_state);
378
379         smbd_notify_cancel_by_smbreq(state->smb2req->sconn,
380                                      state->smbreq);
381
382         state->smb2req->cancelled = true;
383         tevent_req_done(req);
384         return true;
385 }
386
387 static NTSTATUS smbd_smb2_notify_recv(struct tevent_req *req,
388                                       TALLOC_CTX *mem_ctx,
389                                       DATA_BLOB *out_output_buffer)
390 {
391         NTSTATUS status;
392         struct smbd_smb2_notify_state *state = tevent_req_data(req,
393                                                struct smbd_smb2_notify_state);
394
395         if (tevent_req_is_nterror(req, &status)) {
396                 tevent_req_received(req);
397                 return status;
398         }
399
400         *out_output_buffer = state->out_output_buffer;
401         talloc_steal(mem_ctx, out_output_buffer->data);
402
403         tevent_req_received(req);
404         return NT_STATUS_OK;
405 }