1 /*
2    Unix SMB/CIFS implementation.
3 
4    routines for marshalling/unmarshalling string types
5 
6    Copyright (C) Andrew Tridgell 2003
7 
8    This program is free software; you can redistribute it and/or modify
9    it under the terms of the GNU General Public License as published by
10    the Free Software Foundation; either version 3 of the License, or
11    (at your option) any later version.
12 
13    This program is distributed in the hope that it will be useful,
14    but WITHOUT ANY WARRANTY; without even the implied warranty of
15    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16    GNU General Public License for more details.
17 
18    You should have received a copy of the GNU General Public License
19    along with this program.  If not, see <http://www.gnu.org/licenses/>.
20 */
21 
22 #include "includes.h"
23 #include "librpc/ndr/libndr.h"
24 
25 /**
26   pull a general string from the wire
27 */
ndr_pull_string(struct ndr_pull * ndr,int ndr_flags,const char ** s)28 _PUBLIC_ enum ndr_err_code ndr_pull_string(struct ndr_pull *ndr, int ndr_flags, const char **s)
29 {
30 	char *as=NULL;
31 	uint32_t len1, ofs, len2;
32 	uint16_t len3;
33 	size_t conv_src_len = 0, converted_size;
34 	int do_convert = 1, chset = CH_UTF16;
35 	unsigned byte_mul = 2;
36 	unsigned flags = ndr->flags;
37 	unsigned c_len_term = 0;
38 
39 	if (!(ndr_flags & NDR_SCALARS)) {
40 		return NDR_ERR_SUCCESS;
41 	}
42 
43 	if (NDR_BE(ndr)) {
44 		chset = CH_UTF16BE;
45 	}
46 
47 	if (flags & LIBNDR_FLAG_STR_ASCII) {
48 		chset = CH_DOS;
49 		byte_mul = 1;
50 		flags &= ~LIBNDR_FLAG_STR_ASCII;
51 	}
52 
53 	if (flags & LIBNDR_FLAG_STR_UTF8) {
54 		chset = CH_UTF8;
55 		byte_mul = 1;
56 		flags &= ~LIBNDR_FLAG_STR_UTF8;
57 	}
58 
59 	if (flags & LIBNDR_FLAG_STR_RAW8) {
60 		do_convert = 0;
61 		byte_mul = 1;
62 		flags &= ~LIBNDR_FLAG_STR_RAW8;
63 	}
64 
65 	flags &= ~LIBNDR_FLAG_STR_CONFORMANT;
66 	if (flags & LIBNDR_FLAG_STR_CHARLEN) {
67 		c_len_term = 1;
68 		flags &= ~LIBNDR_FLAG_STR_CHARLEN;
69 	}
70 
71 	switch (flags & LIBNDR_STRING_FLAGS) {
72 	case LIBNDR_FLAG_STR_LEN4|LIBNDR_FLAG_STR_SIZE4:
73 	case LIBNDR_FLAG_STR_LEN4|LIBNDR_FLAG_STR_SIZE4|LIBNDR_FLAG_STR_NOTERM:
74 		NDR_CHECK(ndr_pull_uint32(ndr, NDR_SCALARS, &len1));
75 		NDR_CHECK(ndr_pull_uint32(ndr, NDR_SCALARS, &ofs));
76 		if (ofs != 0) {
77 			return ndr_pull_error(ndr, NDR_ERR_STRING, "non-zero array offset with string flags 0x%x\n",
78 					      ndr->flags & LIBNDR_STRING_FLAGS);
79 		}
80 		NDR_CHECK(ndr_pull_uint32(ndr, NDR_SCALARS, &len2));
81 		if (len2 > len1) {
82 			return ndr_pull_error(ndr, NDR_ERR_STRING,
83 					      "Bad string lengths len1=%u ofs=%u len2=%u\n",
84 					      len1, ofs, len2);
85 		} else if (len1 != len2) {
86 			DEBUG(6,("len1[%u] != len2[%u] '%s'\n", len1, len2, as));
87 		}
88 		conv_src_len = len2 + c_len_term;
89 		break;
90 
91 	case LIBNDR_FLAG_STR_SIZE4:
92 	case LIBNDR_FLAG_STR_SIZE4|LIBNDR_FLAG_STR_NOTERM:
93 		NDR_CHECK(ndr_pull_uint32(ndr, NDR_SCALARS, &len1));
94 		conv_src_len = len1 + c_len_term;
95 		break;
96 
97 	case LIBNDR_FLAG_STR_LEN4:
98 	case LIBNDR_FLAG_STR_LEN4|LIBNDR_FLAG_STR_NOTERM:
99 		NDR_CHECK(ndr_pull_uint32(ndr, NDR_SCALARS, &ofs));
100 		if (ofs != 0) {
101 			return ndr_pull_error(ndr, NDR_ERR_STRING, "non-zero array offset with string flags 0x%x\n",
102 					      ndr->flags & LIBNDR_STRING_FLAGS);
103 		}
104 		NDR_CHECK(ndr_pull_uint32(ndr, NDR_SCALARS, &len1));
105 		conv_src_len = len1 + c_len_term;
106 		break;
107 
108 	case LIBNDR_FLAG_STR_SIZE2:
109 	case LIBNDR_FLAG_STR_SIZE2|LIBNDR_FLAG_STR_NOTERM:
110 		NDR_CHECK(ndr_pull_uint16(ndr, NDR_SCALARS, &len3));
111 		conv_src_len = len3 + c_len_term;
112 		break;
113 
114 	case LIBNDR_FLAG_STR_SIZE2|LIBNDR_FLAG_STR_NOTERM|LIBNDR_FLAG_STR_BYTESIZE:
115 		NDR_CHECK(ndr_pull_uint16(ndr, NDR_SCALARS, &len3));
116 		conv_src_len = len3;
117 		byte_mul = 1; /* the length is now absolute */
118 		break;
119 
120 	case LIBNDR_FLAG_STR_NULLTERM:
121 		/*
122 		 * We ensure that conv_str_len cannot return 0 by
123 		 * requring that there be enough bytes for at least
124 		 * the NULL terminator
125 		 */
126 		if (byte_mul == 1) {
127 			NDR_PULL_NEED_BYTES(ndr, 1);
128 			conv_src_len = ascii_len_n((const char *)(ndr->data+ndr->offset), ndr->data_size - ndr->offset);
129 		} else {
130 			NDR_PULL_NEED_BYTES(ndr, 2);
131 			conv_src_len = utf16_len_n(ndr->data+ndr->offset, ndr->data_size - ndr->offset);
132 		}
133 		byte_mul = 1; /* the length is now absolute */
134 		break;
135 
136 	case LIBNDR_FLAG_STR_NOTERM:
137 		if (!(ndr->flags & LIBNDR_FLAG_REMAINING)) {
138 			return ndr_pull_error(ndr, NDR_ERR_STRING, "Bad string flags 0x%x (missing NDR_REMAINING)\n",
139 					      ndr->flags & LIBNDR_STRING_FLAGS);
140 		}
141 		conv_src_len = ndr->data_size - ndr->offset;
142 		byte_mul = 1; /* the length is now absolute */
143 		break;
144 
145 	default:
146 		return ndr_pull_error(ndr, NDR_ERR_STRING, "Bad string flags 0x%x\n",
147 				      ndr->flags & LIBNDR_STRING_FLAGS);
148 	}
149 
150 	NDR_PULL_NEED_BYTES(ndr, conv_src_len * byte_mul);
151 	if (conv_src_len == 0) {
152 		as = talloc_strdup(ndr->current_mem_ctx, "");
153 		converted_size = 0;
154 	} else {
155 		if (!do_convert) {
156 			as = talloc_strndup(ndr->current_mem_ctx,
157 			                    (char *)ndr->data + ndr->offset,
158 					    conv_src_len);
159 			if (!as) {
160 				return ndr_pull_error(ndr, NDR_ERR_ALLOC,
161 						      "Failed to talloc_strndup() in RAW8 ndr_string_pull()");
162 			}
163 			converted_size = MIN(strlen(as)+1, conv_src_len);
164 		} else if (!convert_string_talloc(ndr->current_mem_ctx, chset,
165 					   CH_UNIX, ndr->data + ndr->offset,
166 					   conv_src_len * byte_mul,
167 					   (void **)(void *)&as,
168 					   &converted_size)) {
169 			return ndr_pull_error(ndr, NDR_ERR_CHARCNV,
170 					      "Bad character conversion with flags 0x%x", flags);
171 		}
172 	}
173 
174 	/* this is a way of detecting if a string is sent with the wrong
175 	   termination */
176 	if (ndr->flags & LIBNDR_FLAG_STR_NOTERM) {
177 		if (as && converted_size > 0 && as[converted_size-1] == '\0') {
178 			DEBUG(6,("short string '%s', sent with NULL termination despite NOTERM flag in IDL\n", as));
179 		}
180 	} else {
181 		if (as && converted_size > 0 && as[converted_size-1] != '\0') {
182 			DEBUG(6,("long string '%s', send without NULL termination (which was expected)\n", as));
183 		}
184 	}
185 
186 	NDR_CHECK(ndr_pull_advance(ndr, conv_src_len * byte_mul));
187 	*s = as;
188 
189 	return NDR_ERR_SUCCESS;
190 }
191 
192 
193 /**
194   push a general string onto the wire
195 */
ndr_push_string(struct ndr_push * ndr,int ndr_flags,const char * s)196 _PUBLIC_ enum ndr_err_code ndr_push_string(struct ndr_push *ndr, int ndr_flags, const char *s)
197 {
198 	ssize_t s_len, c_len;
199 	size_t d_len;
200 	int do_convert = 1, chset = CH_UTF16;
201 	unsigned flags = ndr->flags;
202 	unsigned byte_mul = 2;
203 	uint8_t *dest = NULL;
204 
205 	if (!(ndr_flags & NDR_SCALARS)) {
206 		return NDR_ERR_SUCCESS;
207 	}
208 
209 	if (NDR_BE(ndr)) {
210 		chset = CH_UTF16BE;
211 	}
212 
213 	s_len = s?strlen(s):0;
214 
215 	if (flags & LIBNDR_FLAG_STR_ASCII) {
216 		chset = CH_DOS;
217 		byte_mul = 1;
218 		flags &= ~LIBNDR_FLAG_STR_ASCII;
219 	}
220 
221 	if (flags & LIBNDR_FLAG_STR_UTF8) {
222 		chset = CH_UTF8;
223 		byte_mul = 1;
224 		flags &= ~LIBNDR_FLAG_STR_UTF8;
225 	}
226 
227 	if (flags & LIBNDR_FLAG_STR_RAW8) {
228 		do_convert = 0;
229 		byte_mul = 1;
230 		flags &= ~LIBNDR_FLAG_STR_RAW8;
231 	}
232 
233 	flags &= ~LIBNDR_FLAG_STR_CONFORMANT;
234 
235 	if (!(flags & LIBNDR_FLAG_STR_NOTERM)) {
236 		s_len++;
237 	}
238 
239 	if (!do_convert) {
240 		d_len = s_len;
241 		dest = (uint8_t *)talloc_strndup(ndr, s, s_len);
242 	} else if (!convert_string_talloc(ndr, CH_UNIX, chset, s, s_len,
243 				   (void **)(void *)&dest, &d_len))
244 	{
245 		return ndr_push_error(ndr, NDR_ERR_CHARCNV,
246 				      "Bad character push conversion with flags 0x%x", flags);
247 	}
248 
249 	if (flags & LIBNDR_FLAG_STR_BYTESIZE) {
250 		c_len = d_len;
251 		flags &= ~LIBNDR_FLAG_STR_BYTESIZE;
252 	} else if (flags & LIBNDR_FLAG_STR_CHARLEN) {
253 		c_len = (d_len / byte_mul)-1;
254 		flags &= ~LIBNDR_FLAG_STR_CHARLEN;
255 	} else {
256 		c_len = d_len / byte_mul;
257 	}
258 
259 	switch ((flags & LIBNDR_STRING_FLAGS) & ~LIBNDR_FLAG_STR_NOTERM) {
260 	case LIBNDR_FLAG_STR_LEN4|LIBNDR_FLAG_STR_SIZE4:
261 		NDR_CHECK(ndr_push_uint32(ndr, NDR_SCALARS, c_len));
262 		NDR_CHECK(ndr_push_uint32(ndr, NDR_SCALARS, 0));
263 		NDR_CHECK(ndr_push_uint32(ndr, NDR_SCALARS, c_len));
264 		NDR_CHECK(ndr_push_bytes(ndr, dest, d_len));
265 		break;
266 
267 	case LIBNDR_FLAG_STR_LEN4:
268 		NDR_CHECK(ndr_push_uint32(ndr, NDR_SCALARS, 0));
269 		NDR_CHECK(ndr_push_uint32(ndr, NDR_SCALARS, c_len));
270 		NDR_CHECK(ndr_push_bytes(ndr, dest, d_len));
271 		break;
272 
273 	case LIBNDR_FLAG_STR_SIZE4:
274 		NDR_CHECK(ndr_push_uint32(ndr, NDR_SCALARS, c_len));
275 		NDR_CHECK(ndr_push_bytes(ndr, dest, d_len));
276 		break;
277 
278 	case LIBNDR_FLAG_STR_SIZE2:
279 		NDR_CHECK(ndr_push_uint16(ndr, NDR_SCALARS, c_len));
280 		NDR_CHECK(ndr_push_bytes(ndr, dest, d_len));
281 		break;
282 
283 	case LIBNDR_FLAG_STR_NULLTERM:
284 		NDR_CHECK(ndr_push_bytes(ndr, dest, d_len));
285 		break;
286 
287 	default:
288 		if (ndr->flags & LIBNDR_FLAG_REMAINING) {
289 			NDR_CHECK(ndr_push_bytes(ndr, dest, d_len));
290 			break;
291 		}
292 
293 		return ndr_push_error(ndr, NDR_ERR_STRING, "Bad string flags 0x%x\n",
294 				      ndr->flags & LIBNDR_STRING_FLAGS);
295 	}
296 
297 	talloc_free(dest);
298 
299 	return NDR_ERR_SUCCESS;
300 }
301 
302 /**
303   push a general string onto the wire
304 */
ndr_string_array_size(struct ndr_push * ndr,const char * s)305 _PUBLIC_ size_t ndr_string_array_size(struct ndr_push *ndr, const char *s)
306 {
307 	size_t c_len;
308 	unsigned flags = ndr->flags;
309 	unsigned byte_mul = 2;
310 	unsigned c_len_term = 1;
311 
312 	if (flags & LIBNDR_FLAG_STR_RAW8) {
313 		c_len = s?strlen(s):0;
314 	} else {
315 		c_len = s?strlen_m(s):0;
316 	}
317 
318 	if (flags & (LIBNDR_FLAG_STR_ASCII|LIBNDR_FLAG_STR_RAW8|LIBNDR_FLAG_STR_UTF8)) {
319 		byte_mul = 1;
320 	}
321 
322 	if (flags & LIBNDR_FLAG_STR_NOTERM) {
323 		c_len_term = 0;
324 	}
325 
326 	c_len = c_len + c_len_term;
327 
328 	if (flags & LIBNDR_FLAG_STR_BYTESIZE) {
329 		c_len = c_len * byte_mul;
330 	}
331 
332 	return c_len;
333 }
334 
ndr_print_string(struct ndr_print * ndr,const char * name,const char * s)335 _PUBLIC_ void ndr_print_string(struct ndr_print *ndr, const char *name, const char *s)
336 {
337 	if (s) {
338 		ndr->print(ndr, "%-25s: '%s'", name, s);
339 	} else {
340 		ndr->print(ndr, "%-25s: NULL", name);
341 	}
342 }
343 
ndr_size_string(int ret,const char * const * string,int flags)344 _PUBLIC_ uint32_t ndr_size_string(int ret, const char * const* string, int flags)
345 {
346 	/* FIXME: Is this correct for all strings ? */
347 	if(!(*string)) return ret;
348 	return ret+strlen(*string)+1;
349 }
350 
351 /**
352   pull a general string array from the wire
353 */
ndr_pull_string_array(struct ndr_pull * ndr,int ndr_flags,const char *** _a)354 _PUBLIC_ enum ndr_err_code ndr_pull_string_array(struct ndr_pull *ndr, int ndr_flags, const char ***_a)
355 {
356 	const char **a = NULL;
357 	uint32_t count;
358 	unsigned flags = ndr->flags;
359 	unsigned saved_flags = ndr->flags;
360 
361 	if (!(ndr_flags & NDR_SCALARS)) {
362 		return NDR_ERR_SUCCESS;
363 	}
364 
365 	switch (flags & (LIBNDR_FLAG_STR_NULLTERM|LIBNDR_FLAG_STR_NOTERM)) {
366 	case LIBNDR_FLAG_STR_NULLTERM:
367 		/*
368 		 * here the strings are null terminated
369 		 * but also the array is null terminated if LIBNDR_FLAG_REMAINING
370 		 * is specified
371 		 */
372 		for (count = 0;; count++) {
373 			TALLOC_CTX *tmp_ctx;
374 			const char *s = NULL;
375 			a = talloc_realloc(ndr->current_mem_ctx, a, const char *, count + 2);
376 			NDR_ERR_HAVE_NO_MEMORY(a);
377 			a[count]   = NULL;
378 			a[count+1]   = NULL;
379 
380 			tmp_ctx = ndr->current_mem_ctx;
381 			ndr->current_mem_ctx = a;
382 			NDR_CHECK(ndr_pull_string(ndr, ndr_flags, &s));
383 			if ((ndr->data_size - ndr->offset) == 0 && ndr->flags & LIBNDR_FLAG_REMAINING)
384 			{
385 				a[count] = s;
386 				break;
387 			}
388 			ndr->current_mem_ctx = tmp_ctx;
389 			if (strcmp("", s)==0) {
390 				a[count] = NULL;
391 				break;
392 			} else {
393 				a[count] = s;
394 			}
395 		}
396 
397 		*_a =a;
398 		break;
399 
400 	case LIBNDR_FLAG_STR_NOTERM:
401 		if (!(ndr->flags & LIBNDR_FLAG_REMAINING)) {
402 			return ndr_pull_error(ndr, NDR_ERR_STRING, "Bad string flags 0x%x (missing NDR_REMAINING)\n",
403 					      ndr->flags & LIBNDR_STRING_FLAGS);
404 		}
405 		/*
406 		 * here the strings are not null terminated
407 		 * but serarated by a null terminator
408 		 *
409 		 * which means the same as:
410 		 * Every string is null terminated exept the last
411 		 * string is terminated by the end of the buffer
412 		 *
413 		 * as LIBNDR_FLAG_STR_NULLTERM also end at the end
414 		 * of the buffer, we can pull each string with this flag
415 		 *
416 		 * The big difference with the case LIBNDR_FLAG_STR_NOTERM +
417 		 * LIBNDR_FLAG_REMAINING is that the last string will not be null terminated
418 		 */
419 		ndr->flags &= ~(LIBNDR_FLAG_STR_NOTERM|LIBNDR_FLAG_REMAINING);
420 		ndr->flags |= LIBNDR_FLAG_STR_NULLTERM;
421 
422 		for (count = 0; ((ndr->data_size - ndr->offset) > 0); count++) {
423 			TALLOC_CTX *tmp_ctx;
424 			const char *s = NULL;
425 			a = talloc_realloc(ndr->current_mem_ctx, a, const char *, count + 2);
426 			NDR_ERR_HAVE_NO_MEMORY(a);
427 			a[count]   = NULL;
428 			a[count+1]   = NULL;
429 
430 			tmp_ctx = ndr->current_mem_ctx;
431 			ndr->current_mem_ctx = a;
432 			NDR_CHECK(ndr_pull_string(ndr, ndr_flags, &s));
433 			ndr->current_mem_ctx = tmp_ctx;
434 			a[count] = s;
435 		}
436 
437 		*_a =a;
438 		break;
439 
440 	default:
441 		return ndr_pull_error(ndr, NDR_ERR_STRING, "Bad string flags 0x%x\n",
442 				      ndr->flags & LIBNDR_STRING_FLAGS);
443 	}
444 
445 	ndr->flags = saved_flags;
446 	return NDR_ERR_SUCCESS;
447 }
448 
449 /**
450   push a general string array onto the wire
451 */
ndr_push_string_array(struct ndr_push * ndr,int ndr_flags,const char ** a)452 _PUBLIC_ enum ndr_err_code ndr_push_string_array(struct ndr_push *ndr, int ndr_flags, const char **a)
453 {
454 	uint32_t count;
455 	unsigned flags = ndr->flags;
456 	unsigned saved_flags = ndr->flags;
457 
458 	if (!(ndr_flags & NDR_SCALARS)) {
459 		return NDR_ERR_SUCCESS;
460 	}
461 
462 	switch (flags & LIBNDR_STRING_FLAGS) {
463 	case LIBNDR_FLAG_STR_NULLTERM:
464 		for (count = 0; a && a[count]; count++) {
465 			NDR_CHECK(ndr_push_string(ndr, ndr_flags, a[count]));
466 		}
467 		/* If LIBNDR_FLAG_REMAINING then we do not add a null terminator to the array */
468 		if (!(flags & LIBNDR_FLAG_REMAINING))
469 		{
470 			NDR_CHECK(ndr_push_string(ndr, ndr_flags, ""));
471 		}
472 		break;
473 
474 	case LIBNDR_FLAG_STR_NOTERM:
475 		if (!(ndr->flags & LIBNDR_FLAG_REMAINING)) {
476 			return ndr_push_error(ndr, NDR_ERR_STRING, "Bad string flags 0x%x (missing NDR_REMAINING)\n",
477 					      ndr->flags & LIBNDR_STRING_FLAGS);
478 		}
479 
480 		for (count = 0; a && a[count]; count++) {
481 			if (count > 0) {
482 				ndr->flags &= ~(LIBNDR_FLAG_STR_NOTERM|LIBNDR_FLAG_REMAINING);
483 				ndr->flags |= LIBNDR_FLAG_STR_NULLTERM;
484 				NDR_CHECK(ndr_push_string(ndr, ndr_flags, ""));
485 				ndr->flags = saved_flags;
486 			}
487 			NDR_CHECK(ndr_push_string(ndr, ndr_flags, a[count]));
488 		}
489 
490 		break;
491 
492 	default:
493 		return ndr_push_error(ndr, NDR_ERR_STRING, "Bad string flags 0x%x\n",
494 				      ndr->flags & LIBNDR_STRING_FLAGS);
495 	}
496 
497 	ndr->flags = saved_flags;
498 	return NDR_ERR_SUCCESS;
499 }
500 
ndr_print_string_array(struct ndr_print * ndr,const char * name,const char ** a)501 _PUBLIC_ void ndr_print_string_array(struct ndr_print *ndr, const char *name, const char **a)
502 {
503 	uint32_t count;
504 	uint32_t i;
505 
506 	for (count = 0; a && a[count]; count++) {}
507 
508 	ndr->print(ndr, "%s: ARRAY(%d)", name, count);
509 	ndr->depth++;
510 	for (i=0;i<count;i++) {
511 		char *idx=NULL;
512 		if (asprintf(&idx, "[%d]", i) != -1) {
513 			ndr_print_string(ndr, idx, a[i]);
514 			free(idx);
515 		}
516 	}
517 	ndr->depth--;
518 }
519 
ndr_size_string_array(const char ** a,uint32_t count,int flags)520 _PUBLIC_ size_t ndr_size_string_array(const char **a, uint32_t count, int flags)
521 {
522 	uint32_t i;
523 	size_t size = 0;
524 	int rawbytes = 0;
525 
526 	if (flags & LIBNDR_FLAG_STR_RAW8) {
527 		rawbytes = 1;
528 		flags &= ~LIBNDR_FLAG_STR_RAW8;
529 	}
530 
531 	switch (flags & LIBNDR_STRING_FLAGS) {
532 	case LIBNDR_FLAG_STR_NULLTERM:
533 		for (i = 0; i < count; i++) {
534 			size += rawbytes?strlen(a[i]) + 1:strlen_m_term(a[i]);
535 		}
536 		break;
537 	case LIBNDR_FLAG_STR_NOTERM:
538 		for (i = 0; i < count; i++) {
539 			size += rawbytes?strlen(a[i]):strlen_m(a[i]);
540 		}
541 		break;
542 	default:
543 		return 0;
544 	}
545 
546 	return size;
547 }
548 
549 /**
550  * Return number of elements in a string including the last (zeroed) element
551  */
ndr_string_length(const void * _var,uint32_t element_size)552 _PUBLIC_ uint32_t ndr_string_length(const void *_var, uint32_t element_size)
553 {
554 	uint32_t i;
555 	uint8_t zero[4] = {0,0,0,0};
556 	const char *var = (const char *)_var;
557 
558 	for (i = 0; memcmp(var+i*element_size,zero,element_size) != 0; i++);
559 
560 	return i+1;
561 }
562 
563 /**
564  * @brief Get the string length including the null terminator if available.
565  *
566  * This checks the string length based on the elements. The returned number
567  * includes the terminating null byte(s) if found.
568  *
569  * @param[in]  _var    The string the calculate the length for.
570  *
571  * @param[in]  length  The length of the buffer passed by _var.
572  *
573  * @param[in]  element_size The element_size of a string char in bytes.
574  *
575  * @return The length of the strings or 0.
576  */
ndr_string_n_length(const void * _var,size_t length,uint32_t element_size)577 static uint32_t ndr_string_n_length(const void *_var,
578 				    size_t length,
579 				    uint32_t element_size)
580 {
581 	size_t i = 0;
582 	uint8_t zero[4] = {0,0,0,0};
583 	const char *var = (const char *)_var;
584 	int cmp;
585 
586 	if (element_size > 4) {
587 		return 0;
588 	}
589 
590 	for (i = 0; i < length; i++, var += element_size) {
591 		cmp = memcmp(var, zero, element_size);
592 		if (cmp == 0) {
593 			break;
594 		}
595 	}
596 
597 	if (i == length) {
598 		return length;
599 	}
600 
601 	return i + 1;
602 }
603 
ndr_check_string_terminator(struct ndr_pull * ndr,uint32_t count,uint32_t element_size)604 _PUBLIC_ enum ndr_err_code ndr_check_string_terminator(struct ndr_pull *ndr, uint32_t count, uint32_t element_size)
605 {
606 	uint32_t i;
607 	uint32_t save_offset;
608 
609 	save_offset = ndr->offset;
610 	NDR_CHECK(ndr_pull_advance(ndr, (count - 1) * element_size));
611 	NDR_PULL_NEED_BYTES(ndr, element_size);
612 
613 	for (i = 0; i < element_size; i++) {
614 		 if (ndr->data[ndr->offset+i] != 0) {
615 			ndr->offset = save_offset;
616 
617 			return ndr_pull_error(ndr, NDR_ERR_ARRAY_SIZE, "String terminator not present or outside string boundaries");
618 		 }
619 	}
620 
621 	ndr->offset = save_offset;
622 
623 	return NDR_ERR_SUCCESS;
624 }
625 
ndr_pull_charset(struct ndr_pull * ndr,int ndr_flags,const char ** var,uint32_t length,uint8_t byte_mul,charset_t chset)626 _PUBLIC_ enum ndr_err_code ndr_pull_charset(struct ndr_pull *ndr, int ndr_flags, const char **var, uint32_t length, uint8_t byte_mul, charset_t chset)
627 {
628 	size_t converted_size;
629 
630 	if (length == 0) {
631 		*var = talloc_strdup(ndr->current_mem_ctx, "");
632 		return NDR_ERR_SUCCESS;
633 	}
634 
635 	if (NDR_BE(ndr) && chset == CH_UTF16) {
636 		chset = CH_UTF16BE;
637 	}
638 
639 	if ((byte_mul != 0) && (length > UINT32_MAX/byte_mul)) {
640 		return ndr_pull_error(ndr, NDR_ERR_BUFSIZE, "length overflow");
641 	}
642 	NDR_PULL_NEED_BYTES(ndr, length*byte_mul);
643 
644 	if (!convert_string_talloc(ndr->current_mem_ctx, chset, CH_UNIX,
645 				   ndr->data+ndr->offset, length*byte_mul,
646 				   discard_const_p(void *, var),
647 				   &converted_size))
648 	{
649 		return ndr_pull_error(ndr, NDR_ERR_CHARCNV,
650 				      "Bad character conversion");
651 	}
652 	NDR_CHECK(ndr_pull_advance(ndr, length*byte_mul));
653 
654 	return NDR_ERR_SUCCESS;
655 }
656 
ndr_pull_charset_to_null(struct ndr_pull * ndr,int ndr_flags,const char ** var,uint32_t length,uint8_t byte_mul,charset_t chset)657 _PUBLIC_ enum ndr_err_code ndr_pull_charset_to_null(struct ndr_pull *ndr, int ndr_flags, const char **var, uint32_t length, uint8_t byte_mul, charset_t chset)
658 {
659 	size_t converted_size;
660 	uint32_t str_len;
661 
662 	if (length == 0) {
663 		*var = talloc_strdup(ndr->current_mem_ctx, "");
664 		return NDR_ERR_SUCCESS;
665 	}
666 
667 	if (NDR_BE(ndr) && chset == CH_UTF16) {
668 		chset = CH_UTF16BE;
669 	}
670 
671 	NDR_PULL_NEED_BYTES(ndr, length*byte_mul);
672 
673 	str_len = ndr_string_n_length(ndr->data+ndr->offset, length, byte_mul);
674 	if (str_len == 0) {
675 		return ndr_pull_error(ndr, NDR_ERR_LENGTH,
676 				      "Invalid length");
677 	}
678 
679 	if (!convert_string_talloc(ndr->current_mem_ctx, chset, CH_UNIX,
680 				   ndr->data+ndr->offset, str_len*byte_mul,
681 				   discard_const_p(void *, var),
682 				   &converted_size))
683 	{
684 		return ndr_pull_error(ndr, NDR_ERR_CHARCNV,
685 				      "Bad character conversion");
686 	}
687 	NDR_CHECK(ndr_pull_advance(ndr, length*byte_mul));
688 
689 	return NDR_ERR_SUCCESS;
690 }
691 
ndr_push_charset(struct ndr_push * ndr,int ndr_flags,const char * var,uint32_t length,uint8_t byte_mul,charset_t chset)692 _PUBLIC_ enum ndr_err_code ndr_push_charset(struct ndr_push *ndr, int ndr_flags, const char *var, uint32_t length, uint8_t byte_mul, charset_t chset)
693 {
694 	size_t required;
695 
696 	if (NDR_BE(ndr) && chset == CH_UTF16) {
697 		chset = CH_UTF16BE;
698 	}
699 
700 	if ((byte_mul != 0) && (length > SIZE_MAX/byte_mul)) {
701 		return ndr_push_error(ndr, NDR_ERR_LENGTH, "length overflow");
702 	}
703 	required = byte_mul * length;
704 
705 	NDR_PUSH_NEED_BYTES(ndr, required);
706 
707 	if (required) {
708 		size_t size = 0;
709 
710 		if (var == NULL) {
711 			return ndr_push_error(ndr, NDR_ERR_INVALID_POINTER, "NULL [ref] pointer");
712 		}
713 
714 		if (!convert_string(CH_UNIX, chset,
715 			     var, strlen(var),
716 			     ndr->data+ndr->offset, required, &size)) {
717 			return ndr_push_error(ndr, NDR_ERR_CHARCNV,
718 				      "Bad character conversion");
719 		}
720 
721 		/* Make sure the remaining part of the string is filled with zeroes */
722 		if (size < required) {
723 			memset(ndr->data+ndr->offset+size, 0, required-size);
724 		}
725 	}
726 
727 	ndr->offset += required;
728 
729 	return NDR_ERR_SUCCESS;
730 }
731 
ndr_push_charset_to_null(struct ndr_push * ndr,int ndr_flags,const char * var,uint32_t length,uint8_t byte_mul,charset_t chset)732 _PUBLIC_ enum ndr_err_code ndr_push_charset_to_null(struct ndr_push *ndr, int ndr_flags, const char *var, uint32_t length, uint8_t byte_mul, charset_t chset)
733 {
734 	const char *str = var;
735 
736 	if (str == NULL) {
737 		str = "\0"; /* i.e. two zero bytes, for UTF16 null word. */
738 		length = 1;
739 	}
740 
741 	return ndr_push_charset(ndr, ndr_flags, str, length, byte_mul, chset);
742 }
743 
744 /* Return number of elements in a string in the specified charset */
ndr_charset_length(const void * var,charset_t chset)745 _PUBLIC_ uint32_t ndr_charset_length(const void *var, charset_t chset)
746 {
747 	switch (chset) {
748 	/* case CH_UTF16: this has the same value as CH_UTF16LE */
749 	case CH_UTF16LE:
750 	case CH_UTF16BE:
751 	case CH_UTF16MUNGED:
752 	case CH_UTF8:
753 		return strlen_m_ext_term((const char *)var, CH_UNIX, chset);
754 	case CH_DOS:
755 	case CH_UNIX:
756 		return strlen((const char *)var)+1;
757 	}
758 
759 	/* Fallback, this should never happen */
760 	return strlen((const char *)var)+1;
761 }
762