1 /*
2    Unix SMB/CIFS implementation.
3    client file read/write routines
4    Copyright (C) Andrew Tridgell 1994-1998
5    Copyright (C) James Myers 2003
6 
7    This program is free software; you can redistribute it and/or modify
8    it under the terms of the GNU General Public License as published by
9    the Free Software Foundation; either version 2 of the License, or
10    (at your option) any later version.
11 
12    This program is distributed in the hope that it will be useful,
13    but WITHOUT ANY WARRANTY; without even the implied warranty of
14    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15    GNU General Public License for more details.
16 
17    You should have received a copy of the GNU General Public License
18    along with this program; if not, write to the Free Software
19    Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
20 */
21 
22 #include "includes.h"
23 #include "libcli/raw/libcliraw.h"
24 
25 #define SETUP_REQUEST(cmd, wct, buflen) do { \
26 	req = smbcli_request_setup(tree, cmd, wct, buflen); \
27 	if (!req) return NULL; \
28 } while (0)
29 
30 /****************************************************************************
31  low level read operation (async send)
32 ****************************************************************************/
smb_raw_read_send(struct smbcli_tree * tree,union smb_read * parms)33 struct smbcli_request *smb_raw_read_send(struct smbcli_tree *tree, union smb_read *parms)
34 {
35 	BOOL bigoffset = False;
36 	struct smbcli_request *req = NULL;
37 
38 	switch (parms->generic.level) {
39 	case RAW_READ_READBRAW:
40 		if (tree->session->transport->negotiate.capabilities & CAP_LARGE_FILES) {
41 			bigoffset = True;
42 		}
43 		SETUP_REQUEST(SMBreadbraw, bigoffset? 10:8, 0);
44 		SSVAL(req->out.vwv, VWV(0), parms->readbraw.in.file.fnum);
45 		SIVAL(req->out.vwv, VWV(1), parms->readbraw.in.offset);
46 		SSVAL(req->out.vwv, VWV(3), parms->readbraw.in.maxcnt);
47 		SSVAL(req->out.vwv, VWV(4), parms->readbraw.in.mincnt);
48 		SIVAL(req->out.vwv, VWV(5), parms->readbraw.in.timeout);
49 		SSVAL(req->out.vwv, VWV(7), 0); /* reserved */
50 		if (bigoffset) {
51 			SIVAL(req->out.vwv, VWV(8),parms->readbraw.in.offset>>32);
52 		}
53 		break;
54 
55 	case RAW_READ_LOCKREAD:
56 		SETUP_REQUEST(SMBlockread, 5, 0);
57 		SSVAL(req->out.vwv, VWV(0), parms->lockread.in.file.fnum);
58 		SSVAL(req->out.vwv, VWV(1), parms->lockread.in.count);
59 		SIVAL(req->out.vwv, VWV(2), parms->lockread.in.offset);
60 		SSVAL(req->out.vwv, VWV(4), parms->lockread.in.remaining);
61 		break;
62 
63 	case RAW_READ_READ:
64 		SETUP_REQUEST(SMBread, 5, 0);
65 		SSVAL(req->out.vwv, VWV(0), parms->read.in.file.fnum);
66 		SSVAL(req->out.vwv, VWV(1), parms->read.in.count);
67 		SIVAL(req->out.vwv, VWV(2), parms->read.in.offset);
68 		SSVAL(req->out.vwv, VWV(4), parms->read.in.remaining);
69 		break;
70 
71 	case RAW_READ_READX:
72 		if (tree->session->transport->negotiate.capabilities & CAP_LARGE_FILES) {
73 			bigoffset = True;
74 		}
75 		SETUP_REQUEST(SMBreadX, bigoffset ? 12 : 10, 0);
76 		SSVAL(req->out.vwv, VWV(0), SMB_CHAIN_NONE);
77 		SSVAL(req->out.vwv, VWV(1), 0);
78 		SSVAL(req->out.vwv, VWV(2), parms->readx.in.file.fnum);
79 		SIVAL(req->out.vwv, VWV(3), parms->readx.in.offset);
80 		SSVAL(req->out.vwv, VWV(5), parms->readx.in.maxcnt & 0xFFFF);
81 		SSVAL(req->out.vwv, VWV(6), parms->readx.in.mincnt);
82 		SIVAL(req->out.vwv, VWV(7), parms->readx.in.maxcnt >> 16);
83 		SSVAL(req->out.vwv, VWV(9), parms->readx.in.remaining);
84 		/*
85 		 * TODO: give an error when the offset is 64 bit
86 		 *       and the server doesn't support it
87 		 */
88 		if (bigoffset) {
89 			SIVAL(req->out.vwv, VWV(10),parms->readx.in.offset>>32);
90 		}
91 		if (parms->readx.in.read_for_execute) {
92 			uint16_t flags2 = SVAL(req->out.hdr, HDR_FLG2);
93 			flags2 |= FLAGS2_READ_PERMIT_EXECUTE;
94 			SSVAL(req->out.hdr, HDR_FLG2, flags2);
95 		}
96 		break;
97 
98 	case RAW_READ_SMB2:
99 		return NULL;
100 	}
101 
102 	if (!smbcli_request_send(req)) {
103 		smbcli_request_destroy(req);
104 		return NULL;
105 	}
106 
107 	/* the transport layer needs to know that a readbraw is pending
108 	   and handle receives a little differently */
109 	if (parms->generic.level == RAW_READ_READBRAW) {
110 		tree->session->transport->readbraw_pending = 1;
111 	}
112 
113 	return req;
114 }
115 
116 /****************************************************************************
117  low level read operation (async recv)
118 ****************************************************************************/
smb_raw_read_recv(struct smbcli_request * req,union smb_read * parms)119 NTSTATUS smb_raw_read_recv(struct smbcli_request *req, union smb_read *parms)
120 {
121 	if (!smbcli_request_receive(req) ||
122 	    smbcli_request_is_error(req)) {
123 		goto failed;
124 	}
125 
126 	switch (parms->generic.level) {
127 	case RAW_READ_READBRAW:
128 		parms->readbraw.out.nread = req->in.size - NBT_HDR_SIZE;
129 		if (parms->readbraw.out.nread >
130 		    MAX(parms->readx.in.mincnt, parms->readx.in.maxcnt)) {
131 			req->status = NT_STATUS_BUFFER_TOO_SMALL;
132 			goto failed;
133 		}
134 		memcpy(parms->readbraw.out.data, req->in.buffer + NBT_HDR_SIZE, parms->readbraw.out.nread);
135 		break;
136 
137 	case RAW_READ_LOCKREAD:
138 		SMBCLI_CHECK_WCT(req, 5);
139 		parms->lockread.out.nread = SVAL(req->in.vwv, VWV(0));
140 		if (parms->lockread.out.nread > parms->lockread.in.count ||
141 		    !smbcli_raw_pull_data(req, req->in.data+3,
142 				       parms->lockread.out.nread, parms->lockread.out.data)) {
143 			req->status = NT_STATUS_BUFFER_TOO_SMALL;
144 		}
145 		break;
146 
147 	case RAW_READ_READ:
148 		/* there are 4 reserved words in the reply */
149 		SMBCLI_CHECK_WCT(req, 5);
150 		parms->read.out.nread = SVAL(req->in.vwv, VWV(0));
151 		if (parms->read.out.nread > parms->read.in.count ||
152 		    !smbcli_raw_pull_data(req, req->in.data+3,
153 				       parms->read.out.nread, parms->read.out.data)) {
154 			req->status = NT_STATUS_BUFFER_TOO_SMALL;
155 		}
156 		break;
157 
158 	case RAW_READ_READX:
159 		/* there are 5 reserved words in the reply */
160 		SMBCLI_CHECK_WCT(req, 12);
161 		parms->readx.out.remaining       = SVAL(req->in.vwv, VWV(2));
162 		parms->readx.out.compaction_mode = SVAL(req->in.vwv, VWV(3));
163 		parms->readx.out.nread = SVAL(req->in.vwv, VWV(5));
164 
165 		/* handle oversize replies for non-chained readx replies with
166 		   CAP_LARGE_READX. The snia spec has must to answer for. */
167 		if ((req->tree->session->transport->negotiate.capabilities & CAP_LARGE_READX)
168 		    && CVAL(req->in.vwv, VWV(0)) == SMB_CHAIN_NONE &&
169 		    req->in.size >= 0x10000) {
170 			parms->readx.out.nread += (SVAL(req->in.vwv, VWV(7)) << 16);
171 			if (req->in.hdr + SVAL(req->in.vwv, VWV(6)) +
172 			    parms->readx.out.nread <=
173 			    req->in.buffer + req->in.size) {
174 				req->in.data_size += (SVAL(req->in.vwv, VWV(7)) << 16);
175 			}
176 		}
177 
178 		if (parms->readx.out.nread > MAX(parms->readx.in.mincnt, parms->readx.in.maxcnt) ||
179 		    !smbcli_raw_pull_data(req, req->in.hdr + SVAL(req->in.vwv, VWV(6)),
180 				       parms->readx.out.nread,
181 				       parms->readx.out.data)) {
182 			req->status = NT_STATUS_BUFFER_TOO_SMALL;
183 		}
184 		break;
185 
186 	case RAW_READ_SMB2:
187 		req->status = NT_STATUS_INTERNAL_ERROR;
188 		break;
189 	}
190 
191 failed:
192 	return smbcli_request_destroy(req);
193 }
194 
195 /****************************************************************************
196  low level read operation (sync interface)
197 ****************************************************************************/
smb_raw_read(struct smbcli_tree * tree,union smb_read * parms)198 NTSTATUS smb_raw_read(struct smbcli_tree *tree, union smb_read *parms)
199 {
200 	struct smbcli_request *req = smb_raw_read_send(tree, parms);
201 	return smb_raw_read_recv(req, parms);
202 }
203 
204 
205 /****************************************************************************
206  raw write interface (async send)
207 ****************************************************************************/
smb_raw_write_send(struct smbcli_tree * tree,union smb_write * parms)208 struct smbcli_request *smb_raw_write_send(struct smbcli_tree *tree, union smb_write *parms)
209 {
210 	BOOL bigoffset = False;
211 	struct smbcli_request *req = NULL;
212 
213 	switch (parms->generic.level) {
214 	case RAW_WRITE_WRITEUNLOCK:
215 		SETUP_REQUEST(SMBwriteunlock, 5, 3 + parms->writeunlock.in.count);
216 		SSVAL(req->out.vwv, VWV(0), parms->writeunlock.in.file.fnum);
217 		SSVAL(req->out.vwv, VWV(1), parms->writeunlock.in.count);
218 		SIVAL(req->out.vwv, VWV(2), parms->writeunlock.in.offset);
219 		SSVAL(req->out.vwv, VWV(4), parms->writeunlock.in.remaining);
220 		SCVAL(req->out.data, 0, SMB_DATA_BLOCK);
221 		SSVAL(req->out.data, 1, parms->writeunlock.in.count);
222 		if (parms->writeunlock.in.count > 0) {
223 			memcpy(req->out.data+3, parms->writeunlock.in.data,
224 			       parms->writeunlock.in.count);
225 		}
226 		break;
227 
228 	case RAW_WRITE_WRITE:
229 		SETUP_REQUEST(SMBwrite, 5,  3 + parms->write.in.count);
230 		SSVAL(req->out.vwv, VWV(0), parms->write.in.file.fnum);
231 		SSVAL(req->out.vwv, VWV(1), parms->write.in.count);
232 		SIVAL(req->out.vwv, VWV(2), parms->write.in.offset);
233 		SSVAL(req->out.vwv, VWV(4), parms->write.in.remaining);
234 		SCVAL(req->out.data, 0, SMB_DATA_BLOCK);
235 		SSVAL(req->out.data, 1, parms->write.in.count);
236 		if (parms->write.in.count > 0) {
237 			memcpy(req->out.data+3, parms->write.in.data, parms->write.in.count);
238 		}
239 		break;
240 
241 	case RAW_WRITE_WRITECLOSE:
242 		SETUP_REQUEST(SMBwriteclose, 6, 1 + parms->writeclose.in.count);
243 		SSVAL(req->out.vwv, VWV(0), parms->writeclose.in.file.fnum);
244 		SSVAL(req->out.vwv, VWV(1), parms->writeclose.in.count);
245 		SIVAL(req->out.vwv, VWV(2), parms->writeclose.in.offset);
246 		raw_push_dos_date3(tree->session->transport,
247 				  req->out.vwv, VWV(4), parms->writeclose.in.mtime);
248 		SCVAL(req->out.data, 0, 0);
249 		if (parms->writeclose.in.count > 0) {
250 			memcpy(req->out.data+1, parms->writeclose.in.data,
251 			       parms->writeclose.in.count);
252 		}
253 		break;
254 
255 	case RAW_WRITE_WRITEX:
256 		if (tree->session->transport->negotiate.capabilities & CAP_LARGE_FILES) {
257 			bigoffset = True;
258 		}
259 		SETUP_REQUEST(SMBwriteX, bigoffset ? 14 : 12, parms->writex.in.count);
260 		SSVAL(req->out.vwv, VWV(0), SMB_CHAIN_NONE);
261 		SSVAL(req->out.vwv, VWV(1), 0);
262 		SSVAL(req->out.vwv, VWV(2), parms->writex.in.file.fnum);
263 		SIVAL(req->out.vwv, VWV(3), parms->writex.in.offset);
264 		SIVAL(req->out.vwv, VWV(5), 0); /* reserved */
265 		SSVAL(req->out.vwv, VWV(7), parms->writex.in.wmode);
266 		SSVAL(req->out.vwv, VWV(8), parms->writex.in.remaining);
267 		SSVAL(req->out.vwv, VWV(9), parms->writex.in.count>>16);
268 		SSVAL(req->out.vwv, VWV(10), parms->writex.in.count);
269 		SSVAL(req->out.vwv, VWV(11), PTR_DIFF(req->out.data, req->out.hdr));
270 		if (bigoffset) {
271 	      		SIVAL(req->out.vwv,VWV(12),parms->writex.in.offset>>32);
272 		}
273 	      	if (parms->writex.in.count > 0) {
274 			memcpy(req->out.data, parms->writex.in.data, parms->writex.in.count);
275 		}
276 		break;
277 
278 	case RAW_WRITE_SPLWRITE:
279 		SETUP_REQUEST(SMBsplwr, 1, parms->splwrite.in.count);
280 		SSVAL(req->out.vwv, VWV(0), parms->splwrite.in.file.fnum);
281 		if (parms->splwrite.in.count > 0) {
282 			memcpy(req->out.data, parms->splwrite.in.data, parms->splwrite.in.count);
283 		}
284 		break;
285 
286 	case RAW_WRITE_SMB2:
287 		return NULL;
288 	}
289 
290 	if (!smbcli_request_send(req)) {
291 		smbcli_request_destroy(req);
292 		return NULL;
293 	}
294 
295 	return req;
296 }
297 
298 
299 /****************************************************************************
300  raw write interface (async recv)
301 ****************************************************************************/
smb_raw_write_recv(struct smbcli_request * req,union smb_write * parms)302 NTSTATUS smb_raw_write_recv(struct smbcli_request *req, union smb_write *parms)
303 {
304 	if (!smbcli_request_receive(req) ||
305 	    smbcli_request_is_error(req)) {
306 		goto failed;
307 	}
308 
309 	switch (parms->generic.level) {
310 	case RAW_WRITE_WRITEUNLOCK:
311 		SMBCLI_CHECK_WCT(req, 1);
312 		parms->writeunlock.out.nwritten = SVAL(req->in.vwv, VWV(0));
313 		break;
314 	case RAW_WRITE_WRITE:
315 		SMBCLI_CHECK_WCT(req, 1);
316 		parms->write.out.nwritten = SVAL(req->in.vwv, VWV(0));
317 		break;
318 	case RAW_WRITE_WRITECLOSE:
319 		SMBCLI_CHECK_WCT(req, 1);
320 		parms->writeclose.out.nwritten = SVAL(req->in.vwv, VWV(0));
321 		break;
322 	case RAW_WRITE_WRITEX:
323 		SMBCLI_CHECK_WCT(req, 6);
324 		parms->writex.out.nwritten  = SVAL(req->in.vwv, VWV(2));
325 		parms->writex.out.nwritten += (CVAL(req->in.vwv, VWV(4)) << 16);
326 		parms->writex.out.remaining = SVAL(req->in.vwv, VWV(3));
327 		break;
328 	case RAW_WRITE_SPLWRITE:
329 		break;
330 	case RAW_WRITE_SMB2:
331 		req->status = NT_STATUS_INTERNAL_ERROR;
332 		break;
333 	}
334 
335 failed:
336 	return smbcli_request_destroy(req);
337 }
338 
339 /****************************************************************************
340  raw write interface (sync interface)
341 ****************************************************************************/
smb_raw_write(struct smbcli_tree * tree,union smb_write * parms)342 NTSTATUS smb_raw_write(struct smbcli_tree *tree, union smb_write *parms)
343 {
344 	struct smbcli_request *req = smb_raw_write_send(tree, parms);
345 	return smb_raw_write_recv(req, parms);
346 }
347