2 Unix SMB/CIFS implementation.
4 Copyright (C) Stefan Metzmacher 2011
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "smbd/smbd.h"
22 #include "smbd/globals.h"
23 #include "dbwrap/dbwrap.h"
24 #include "dbwrap/dbwrap_rbt.h"
25 #include "dbwrap/dbwrap_open.h"
28 #include "../lib/tsocket/tsocket.h"
29 #include "../libcli/security/security.h"
31 #include "lib/util/util_tdb.h"
32 #include "librpc/gen_ndr/ndr_smbXsrv.h"
34 static struct db_context *smbXsrv_session_global_db_ctx = NULL;
36 NTSTATUS smbXsrv_session_global_init(void)
38 const char *global_path = NULL;
39 struct db_context *db_ctx = NULL;
41 if (smbXsrv_session_global_db_ctx != NULL) {
46 * This contains secret information like session keys!
48 global_path = lock_path("smbXsrv_session_global.tdb");
50 db_ctx = db_open(NULL, global_path,
54 TDB_INCOMPATIBLE_HASH,
55 O_RDWR | O_CREAT, 0600,
60 status = map_nt_error_from_unix_common(errno);
65 smbXsrv_session_global_db_ctx = db_ctx;
70 static NTSTATUS smbXsrv_session_table_init(struct smbXsrv_connection *conn,
74 struct smbXsrv_session_table *table = &conn->session_table;
78 table->local.db_ctx = db_open_rbt(conn);
79 if (table->local.db_ctx == NULL) {
80 return NT_STATUS_NO_MEMORY;
82 table->local.lowest_id = lowest_id;
83 table->local.highest_id = highest_id;
85 status = smbXsrv_session_global_init();
86 if (!NT_STATUS_IS_OK(status)) {
90 table->global.db_ctx = smbXsrv_session_global_db_ctx;
95 struct smb1srv_session_local_allocate_state {
96 const uint32_t lowest_id;
97 const uint32_t highest_id;
103 static int smb1srv_session_local_allocate_traverse(struct db_record *rec,
106 struct smb1srv_session_local_allocate_state *state =
107 (struct smb1srv_session_local_allocate_state *)private_data;
108 TDB_DATA key = dbwrap_record_get_key(rec);
111 if (key.dsize != sizeof(uint32_t)) {
113 state->status = NT_STATUS_INTERNAL_DB_CORRUPTION;
119 * We need big endian so that dbwrap_rbt's memcmp
120 * has the same result as integer comparison between the uint32_t
123 * TODO: implement string based key
125 id = RIVAL(key.dptr, 0);
127 if (id <= state->last_id) {
129 state->status = NT_STATUS_INTERNAL_DB_CORRUPTION;
134 if (id > state->useable_id) {
135 state->status = NT_STATUS_OK;
139 state->useable_id +=1;
143 static NTSTATUS smb1srv_session_local_allocate_id(struct db_context *db,
147 struct db_record **_rec,
150 struct smb1srv_session_local_allocate_state state = {
151 .lowest_id = lowest_id,
152 .highest_id = highest_id,
154 .useable_id = lowest_id,
155 .status = NT_STATUS_INTERNAL_ERROR,
165 if (lowest_id > highest_id) {
166 return NT_STATUS_INSUFFICIENT_RESOURCES;
169 range = (highest_id - lowest_id) + 1;
171 for (i = 0; i < range; i++) {
173 uint8_t key_buf[sizeof(uint32_t)];
176 struct db_record *rec = NULL;
178 id = generate_random() % range;
181 if (id < lowest_id) {
184 if (id > highest_id) {
188 RSIVAL(key_buf, 0, id);
189 key = make_tdb_data(key_buf, sizeof(key_buf));
191 rec = dbwrap_fetch_locked(db, mem_ctx, key);
193 return NT_STATUS_INSUFFICIENT_RESOURCES;
196 val = dbwrap_record_get_value(rec);
197 if (val.dsize != 0) {
207 status = dbwrap_traverse_read(db, smb1srv_session_local_allocate_traverse,
209 if (!NT_STATUS_EQUAL(status, NT_STATUS_INTERNAL_DB_CORRUPTION)) {
211 * Here we really expect NT_STATUS_INTERNAL_DB_CORRUPTION!
213 * If we get anything else it is an error, because it
214 * means we did not manage to find a free slot in
217 return NT_STATUS_INSUFFICIENT_RESOURCES;
220 if (NT_STATUS_IS_OK(state.status)) {
222 uint8_t key_buf[sizeof(uint32_t)];
225 struct db_record *rec = NULL;
227 id = state.useable_id;
229 RSIVAL(key_buf, 0, id);
230 key = make_tdb_data(key_buf, sizeof(key_buf));
232 rec = dbwrap_fetch_locked(db, mem_ctx, key);
234 return NT_STATUS_INSUFFICIENT_RESOURCES;
237 val = dbwrap_record_get_value(rec);
238 if (val.dsize != 0) {
240 return NT_STATUS_INTERNAL_DB_CORRUPTION;
251 struct smbXsrv_session_local_fetch_state {
252 struct smbXsrv_session *session;
256 static void smbXsrv_session_local_fetch_parser(TDB_DATA key, TDB_DATA data,
259 struct smbXsrv_session_local_fetch_state *state =
260 (struct smbXsrv_session_local_fetch_state *)private_data;
263 if (data.dsize != sizeof(ptr)) {
264 state->status = NT_STATUS_INTERNAL_DB_ERROR;
268 memcpy(&ptr, data.dptr, data.dsize);
269 state->session = talloc_get_type_abort(ptr, struct smbXsrv_session);
270 state->status = NT_STATUS_OK;
273 static NTSTATUS smbXsrv_session_local_lookup(struct smbXsrv_session_table *table,
274 uint32_t session_local_id,
276 struct smbXsrv_session **_session)
278 struct smbXsrv_session_local_fetch_state state = {
280 .status = NT_STATUS_INTERNAL_ERROR,
282 uint8_t key_buf[sizeof(uint32_t)];
288 if (table->local.db_ctx == NULL) {
289 return NT_STATUS_INTERNAL_ERROR;
292 RSIVAL(key_buf, 0, session_local_id);
293 key = make_tdb_data(key_buf, sizeof(key_buf));
295 status = dbwrap_parse_record(table->local.db_ctx, key,
296 smbXsrv_session_local_fetch_parser,
298 if (NT_STATUS_EQUAL(status, NT_STATUS_NOT_FOUND)) {
299 return NT_STATUS_USER_SESSION_DELETED;
300 } else if (!NT_STATUS_IS_OK(status)) {
303 if (!NT_STATUS_IS_OK(state.status)) {
307 if (!NT_STATUS_IS_OK(state.session->status)) {
308 *_session = state.session;
309 return state.session->status;
312 if (now > state.session->global->expiration_time) {
313 state.session->status = NT_STATUS_NETWORK_SESSION_EXPIRED;
316 *_session = state.session;
317 return state.session->status;
320 static int smbXsrv_session_global_destructor(struct smbXsrv_session_global0 *global)
325 static NTSTATUS smbXsrv_session_global_allocate(struct db_context *db,
327 struct smbXsrv_session_global0 **_global)
330 struct smbXsrv_session_global0 *global = NULL;
334 global = talloc_zero(mem_ctx, struct smbXsrv_session_global0);
335 if (global == NULL) {
336 return NT_STATUS_NO_MEMORY;
338 talloc_set_destructor(global, smbXsrv_session_global_destructor);
340 for (i = 0; i < UINT32_MAX; i++) {
342 uint8_t key_buf[sizeof(uint32_t)];
346 id = generate_random();
347 if (id >= UINT16_MAX) {
348 id = id & UINT16_MAX;
353 if (id == UINT32_MAX) {
357 RSIVAL(key_buf, 0, id);
358 key = make_tdb_data(key_buf, sizeof(key_buf));
360 global->db_rec = dbwrap_fetch_locked(db, mem_ctx, key);
361 if (global->db_rec == NULL) {
363 return NT_STATUS_INSUFFICIENT_RESOURCES;
366 val = dbwrap_record_get_value(global->db_rec);
367 if (val.dsize != 0) {
368 TALLOC_FREE(global->db_rec);
372 global->session_global_id = id;
378 /* should not be reached */
380 return NT_STATUS_INTERNAL_ERROR;
383 static NTSTATUS smbXsrv_session_global_store(struct smbXsrv_connection *sconn,
384 struct smbXsrv_session_global0 *global)
386 struct smbXsrv_session_globalB global_blob;
387 DATA_BLOB blob = data_blob_null;
390 enum ndr_err_code ndr_err;
393 * TODO: if we use other versions than '0'
394 * we would add glue code here, that would be able to
395 * store the information in the old format.
398 if (global->db_rec == NULL) {
399 return NT_STATUS_INTERNAL_ERROR;
402 val = dbwrap_record_get_value(global->db_rec);
404 ZERO_STRUCT(global_blob);
405 global_blob.version = 0;
406 if (val.dsize >= 8) {
407 global_blob.seqnum = IVAL(val.dptr, 4);
409 global_blob.seqnum += 1;
410 global_blob.info.info0 = global;
412 ndr_err = ndr_push_struct_blob(&blob, global->db_rec, &global_blob,
413 (ndr_push_flags_fn_t)ndr_push_smbXsrv_session_globalB);
414 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
415 //status = ndr_err_code;
416 TALLOC_FREE(global->db_rec);
420 val = make_tdb_data(blob.data, blob.length);
421 status = dbwrap_record_store(global->db_rec, val, TDB_REPLACE);
422 TALLOC_FREE(global->db_rec);
423 if (!NT_STATUS_IS_OK(status)) {
430 struct smbXsrv_session_global_fetch_state {
432 struct smbXsrv_session_global *session;
436 static void smbXsrv_session_global_fetch_parser(TDB_DATA key, TDB_DATA data,
439 struct smbXsrv_session_global_fetch_state *state =
440 (struct smbXsrv_session_global_fetch_state *)private_data;
442 state->status = NT_STATUS_NOT_IMPLEMENTED;
445 static NTSTATUS smbXsrv_session_global_lookup(struct smbXsrv_session_table *table,
446 uint32_t session_global_id,
448 struct smbXsrv_session_global **_session)
450 struct smbXsrv_session_global_fetch_state state = {
453 .status = NT_STATUS_INTERNAL_ERROR,
456 uint8_t key_buf[sizeof(uint32_t)];
461 if (table->global.db_ctx == NULL) {
462 return NT_STATUS_INTERNAL_ERROR;
465 /* TODO: key as string */
466 RSIVAL(key_buf, 0, session_global_id);
467 key = make_tdb_data(key_buf, sizeof(key_buf));
469 status = dbwrap_parse_record(table->global.db_ctx, key,
470 smbXsrv_session_global_fetch_parser, &state);
471 if (NT_STATUS_EQUAL(status, NT_STATUS_NOT_FOUND)) {
472 return NT_STATUS_USER_SESSION_DELETED;
473 } else if (!NT_STATUS_IS_OK(status)) {
476 if (!NT_STATUS_IS_OK(state.status)) {
480 *_session = state.session;
484 static int smbXsrv_session_destructor(struct smbXsrv_session *session)
486 struct smbXsrv_session_table *table;
487 struct db_record *local_rec = NULL;
488 struct db_record *global_rec = NULL;
491 if (session->connection == NULL) {
495 table = &session->connection->session_table;
496 session->connection = NULL;
498 local_rec = session->db_rec;
499 session->db_rec = NULL;
500 if (local_rec == NULL) {
501 uint8_t key_buf[sizeof(uint32_t)];
504 RSIVAL(key_buf, 0, session->local_id);
505 key = make_tdb_data(key_buf, sizeof(key_buf));
507 local_rec = dbwrap_fetch_locked(table->local.db_ctx,
511 if (local_rec != NULL) {
512 status = dbwrap_record_delete(local_rec);
515 global_rec = session->global->db_rec;
516 session->global->db_rec = NULL;
517 if (global_rec == NULL) {
518 uint8_t key_buf[sizeof(uint32_t)];
521 RSIVAL(key_buf, 0, session->global->session_global_id);
522 key = make_tdb_data(key_buf, sizeof(key_buf));
524 global_rec = dbwrap_fetch_locked(table->global.db_ctx,
525 session->global, key);
528 if (global_rec != NULL) {
529 status = dbwrap_record_delete(global_rec);
531 TALLOC_FREE(session->global);
536 NTSTATUS smbXsrv_session_create(struct smbXsrv_connection *conn,
538 struct smbXsrv_session **_session)
540 struct smbXsrv_session_table *table = &conn->session_table;
541 uint32_t max_sessions = table->local.highest_id - table->local.lowest_id;
542 struct db_record *local_rec = NULL;
543 struct smbXsrv_session *session = NULL;
546 struct smbXsrv_session_global0 *global = NULL;
547 struct smbXsrv_channel_global0 *channels = NULL;
550 //system("sleep 999999");
552 if (table->local.num_sessions >= max_sessions) {
553 return NT_STATUS_INSUFFICIENT_RESOURCES;
554 // TODO smb1 return NT_STATUS_TOO_MANY_SESSIONS;
557 session = talloc_zero(conn, struct smbXsrv_session);
558 if (session == NULL) {
559 return NT_STATUS_NO_MEMORY;
561 session->status = NT_STATUS_MORE_PROCESSING_REQUIRED;
562 session->connection = conn;
564 status = smbXsrv_session_global_allocate(table->global.db_ctx,
567 if (!NT_STATUS_IS_OK(status)) {
568 talloc_free(session);
571 session->global = global;
573 talloc_set_destructor(session, smbXsrv_session_destructor);
575 if (conn->protocol >= PROTOCOL_SMB2_02) {
576 uint64_t id = global->session_global_id;
577 uint8_t key_buf[sizeof(uint32_t)];
580 global->session_wire_id = id;
581 //global->session_wire_id |= (id << 32) & 0xFFFFFFFF00000000ULL;
583 session->local_id = global->session_global_id;
585 RSIVAL(key_buf, 0, session->local_id);
586 key = make_tdb_data(key_buf, sizeof(key_buf));
588 local_rec = dbwrap_fetch_locked(table->local.db_ctx,
590 if (local_rec == NULL) {
591 return NT_STATUS_NO_MEMORY;
594 val = dbwrap_record_get_value(local_rec);
595 if (val.dsize != 0) {
596 return NT_STATUS_INTERNAL_DB_CORRUPTION;
600 status = smb1srv_session_local_allocate_id(table->local.db_ctx,
601 table->local.lowest_id,
602 table->local.highest_id,
606 if (!NT_STATUS_IS_OK(status)) {
610 global->session_wire_id = session->local_id;
614 val = make_tdb_data((uint8_t const *)&ptr, sizeof(ptr));
615 status = dbwrap_record_store(local_rec, val, TDB_REPLACE);
616 TALLOC_FREE(local_rec);
617 if (!NT_STATUS_IS_OK(status)) {
618 talloc_free(session);
622 global->creation_time = now;
623 global->expiration_time = UINT64_MAX;//NTTIME_INFINITY;
625 global->num_channels = 1;
626 channels = talloc_zero_array(global,
627 struct smbXsrv_channel_global0,
628 global->num_channels);
629 if (channels == NULL) {
630 talloc_free(session);
631 return NT_STATUS_NO_MEMORY;
633 global->channels = channels;
635 channels[0].server_id = messaging_server_id(conn->msg_ctx);
636 channels[0].local_address = tsocket_address_string(conn->local_address,
638 if (channels[0].local_address == NULL) {
639 talloc_free(session);
640 return NT_STATUS_NO_MEMORY;
642 channels[0].remote_address = tsocket_address_string(conn->remote_address,
644 if (channels[0].remote_address == NULL) {
645 talloc_free(session);
646 return NT_STATUS_NO_MEMORY;
648 channels[0].remote_name = talloc_strdup(channels, conn->remote_hostname);
649 if (channels[0].remote_name == NULL) {
650 talloc_free(session);
651 return NT_STATUS_NO_MEMORY;
653 channels[0].signing_key = data_blob_null;
655 status = smbXsrv_session_global_store(conn,
657 if (!NT_STATUS_IS_OK(status)) {
658 talloc_free(session);
663 struct smbXsrv_sessionB session_blob;
665 ZERO_STRUCT(session_blob);
666 session_blob.version = 0;
667 session_blob.info.info0 = session;
669 NDR_PRINT_DEBUG(smbXsrv_sessionB, &session_blob);
676 NTSTATUS smbXsrv_session_update(struct smbXsrv_session *session)
678 struct smbXsrv_session_table *table = &session->connection->session_table;
680 uint8_t key_buf[sizeof(uint32_t)];
683 if (session->global->db_rec != NULL) {
684 return NT_STATUS_INTERNAL_ERROR;
687 RSIVAL(key_buf, 0, session->global->session_global_id);
688 key = make_tdb_data(key_buf, sizeof(key_buf));
690 session->global->db_rec = dbwrap_fetch_locked(table->global.db_ctx,
691 session->global, key);
692 if (session->global->db_rec == NULL) {
693 // TODO proper return code?
694 return NT_STATUS_NO_MEMORY;
697 status = smbXsrv_session_global_store(session->connection,
699 if (!NT_STATUS_IS_OK(status)) {
707 NTSTATUS smb1srv_session_table_init(struct smbXsrv_connection *conn)
710 * Allow a range from 100..65534.
712 return smbXsrv_session_table_init(conn, 100, UINT16_MAX - 1);
715 NTSTATUS smb1srv_session_lookup(struct smbXsrv_session_table *table,
716 uint16_t vuid, NTTIME now,
717 struct smbXsrv_session **session)
719 uint32_t local_id = vuid;
721 return smbXsrv_session_local_lookup(table, local_id, now, session);
724 NTSTATUS smb2srv_session_table_init(struct smbXsrv_connection *conn)
727 * For now use the same range as SMB1.
729 * Allow a range from 100..65534.
731 return smbXsrv_session_table_init(conn, 100, UINT16_MAX - 1);
734 NTSTATUS smb2srv_session_lookup(struct smbXsrv_session_table *table,
735 uint64_t session_id, NTTIME now,
736 struct smbXsrv_session **session)
738 uint32_t local_id = session_id & UINT32_MAX;
740 return smbXsrv_session_local_lookup(table, local_id, now, session);