s3:smb2_server: use smbd_smb2_request_verify_sizes() in smb2_negprot.c
authorStefan Metzmacher <metze@samba.org>
Tue, 6 Sep 2011 12:01:43 +0000 (14:01 +0200)
committerKarolin Seeger <kseeger@samba.org>
Wed, 12 Oct 2011 18:58:37 +0000 (20:58 +0200)
metze
(cherry picked from commit 7ec3a35d2a67ca93a49094f07a12b0e37cec1661)
(cherry picked from commit f32047b23d6e16e4cc75ae0b3beaf7b34307703c)

source3/smbd/smb2_negprot.c

index f639503ad4cc418d6728d5ae7937b786ddfe106a..9245d6d79793f44d6e0d14ceb58f9dbc3fcf78d8 100644 (file)
@@ -61,6 +61,7 @@ void reply_smb2002(struct smb_request *req, uint16_t choice)
 
 NTSTATUS smbd_smb2_request_process_negprot(struct smbd_smb2_request *req)
 {
+       NTSTATUS status;
        const uint8_t *inbody;
        const uint8_t *indyn = NULL;
        int i = req->current_idx;
@@ -69,8 +70,6 @@ NTSTATUS smbd_smb2_request_process_negprot(struct smbd_smb2_request *req)
        DATA_BLOB negprot_spnego_blob;
        uint16_t security_offset;
        DATA_BLOB security_buffer;
-       size_t expected_body_size = 0x24;
-       size_t body_size;
        size_t expected_dyn_size = 0;
        size_t c;
        uint16_t security_mode;
@@ -80,17 +79,12 @@ NTSTATUS smbd_smb2_request_process_negprot(struct smbd_smb2_request *req)
 
 /* TODO: drop the connection with INVALID_PARAMETER */
 
-       if (req->in.vector[i+1].iov_len != (expected_body_size & 0xFFFFFFFE)) {
-               return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
+       status = smbd_smb2_request_verify_sizes(req, 0x24);
+       if (!NT_STATUS_IS_OK(status)) {
+               return smbd_smb2_request_error(req, status);
        }
-
        inbody = (const uint8_t *)req->in.vector[i+1].iov_base;
 
-       body_size = SVAL(inbody, 0x00);
-       if (body_size != expected_body_size) {
-               return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);
-       }
-
        dialect_count = SVAL(inbody, 0x02);
        if (dialect_count == 0) {
                return smbd_smb2_request_error(req, NT_STATUS_INVALID_PARAMETER);