/* [<][>][^][v][top][bottom][index][help] */
DEFINITIONS
This source file includes following definitions.
- find_function
- show_pipes
- show_functions
- stdin_load
- load_iface_from_plugin
- ndrdump_data
- main
1 /*
2 Unix SMB/CIFS implementation.
3 SMB torture tester
4 Copyright (C) Andrew Tridgell 2003
5 Copyright (C) Jelmer Vernooij 2006
6
7 This program is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3 of the License, or
10 (at your option) any later version.
11
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
16
17 You should have received a copy of the GNU General Public License
18 along with this program. If not, see <http://www.gnu.org/licenses/>.
19 */
20
21 #include "includes.h"
22 #include "system/filesys.h"
23 #include "system/locale.h"
24 #include "librpc/ndr/libndr.h"
25 #include "librpc/ndr/ndr_table.h"
26 #if (_SAMBA_BUILD_ >= 4)
27 #include "lib/cmdline/popt_common.h"
28 #include "param/param.h"
29 #endif
30
31 static const struct ndr_interface_call *find_function(
/* [<][>][^][v][top][bottom][index][help] */
32 const struct ndr_interface_table *p,
33 const char *function)
34 {
35 int i;
36 if (isdigit(function[0])) {
37 i = strtol(function, NULL, 0);
38 return &p->calls[i];
39 }
40 for (i=0;i<p->num_calls;i++) {
41 if (strcmp(p->calls[i].name, function) == 0) {
42 break;
43 }
44 }
45 if (i == p->num_calls) {
46 printf("Function '%s' not found\n", function);
47 exit(1);
48 }
49 return &p->calls[i];
50 }
51
52 _NORETURN_ static void show_pipes(void)
/* [<][>][^][v][top][bottom][index][help] */
53 {
54 const struct ndr_interface_list *l;
55 printf("\nYou must specify a pipe\n");
56 printf("known pipes are:\n");
57 for (l=ndr_table_list();l;l=l->next) {
58 if(l->table->helpstring) {
59 printf("\t%s - %s\n", l->table->name, l->table->helpstring);
60 } else {
61 printf("\t%s\n", l->table->name);
62 }
63 }
64 exit(1);
65 }
66
67 _NORETURN_ static void show_functions(const struct ndr_interface_table *p)
/* [<][>][^][v][top][bottom][index][help] */
68 {
69 int i;
70 printf("\nYou must specify a function\n");
71 printf("known functions on '%s' are:\n", p->name);
72 for (i=0;i<p->num_calls;i++) {
73 printf("\t0x%02x (%2d) %s\n", i, i, p->calls[i].name);
74 }
75 exit(1);
76 }
77
78 static char *stdin_load(TALLOC_CTX *mem_ctx, size_t *size)
/* [<][>][^][v][top][bottom][index][help] */
79 {
80 int num_read, total_len = 0;
81 char buf[255];
82 char *result = NULL;
83
84 while((num_read = read(STDIN_FILENO, buf, 255)) > 0) {
85
86 if (result) {
87 result = talloc_realloc(
88 mem_ctx, result, char, total_len + num_read);
89 } else {
90 result = talloc_array(mem_ctx, char, num_read);
91 }
92
93 memcpy(result + total_len, buf, num_read);
94
95 total_len += num_read;
96 }
97
98 if (size)
99 *size = total_len;
100
101 return result;
102 }
103
104 static const struct ndr_interface_table *load_iface_from_plugin(const char *plugin, const char *pipe_name)
/* [<][>][^][v][top][bottom][index][help] */
105 {
106 const struct ndr_interface_table *p;
107 void *handle;
108 char *symbol;
109
110 handle = dlopen(plugin, RTLD_NOW);
111 if (handle == NULL) {
112 printf("%s: Unable to open: %s\n", plugin, dlerror());
113 return NULL;
114 }
115
116 symbol = talloc_asprintf(NULL, "ndr_table_%s", pipe_name);
117 p = (const struct ndr_interface_table *)dlsym(handle, symbol);
118
119 if (!p) {
120 printf("%s: Unable to find DCE/RPC interface table for '%s': %s\n", plugin, pipe_name, dlerror());
121 talloc_free(symbol);
122 return NULL;
123 }
124
125 talloc_free(symbol);
126
127 return p;
128 }
129
130 static void ndrdump_data(uint8_t *d, uint32_t l, bool force)
/* [<][>][^][v][top][bottom][index][help] */
131 {
132 if (force) {
133 dump_data(0, d, l);
134 } else {
135 dump_data_skip_zeros(0, d, l);
136 }
137 }
138
139 int main(int argc, const char *argv[])
/* [<][>][^][v][top][bottom][index][help] */
140 {
141 const struct ndr_interface_table *p = NULL;
142 const struct ndr_interface_call *f;
143 const char *pipe_name, *function, *inout, *filename;
144 uint8_t *data;
145 size_t size;
146 DATA_BLOB blob;
147 struct ndr_pull *ndr_pull;
148 struct ndr_print *ndr_print;
149 TALLOC_CTX *mem_ctx;
150 int flags;
151 poptContext pc;
152 NTSTATUS status;
153 enum ndr_err_code ndr_err;
154 void *st;
155 void *v_st;
156 const char *ctx_filename = NULL;
157 const char *plugin = NULL;
158 bool validate = false;
159 bool dumpdata = false;
160 int opt;
161 enum {OPT_CONTEXT_FILE=1000, OPT_VALIDATE, OPT_DUMP_DATA, OPT_LOAD_DSO};
162 struct poptOption long_options[] = {
163 POPT_AUTOHELP
164 {"context-file", 'c', POPT_ARG_STRING, NULL, OPT_CONTEXT_FILE, "In-filename to parse first", "CTX-FILE" },
165 {"validate", 0, POPT_ARG_NONE, NULL, OPT_VALIDATE, "try to validate the data", NULL },
166 {"dump-data", 0, POPT_ARG_NONE, NULL, OPT_DUMP_DATA, "dump the hex data", NULL },
167 {"load-dso", 'l', POPT_ARG_STRING, NULL, OPT_LOAD_DSO, "load from shared object file", NULL },
168 POPT_COMMON_SAMBA
169 POPT_COMMON_VERSION
170 { NULL }
171 };
172
173 ndr_table_init();
174
175 /* Initialise samba stuff */
176 load_case_tables();
177
178 setlinebuf(stdout);
179
180 dbf = x_stderr;
181
182 setup_logging(argv[0], true);
183
184 pc = poptGetContext("ndrdump", argc, argv, long_options, 0);
185
186 poptSetOtherOptionHelp(
187 pc, "<pipe|uuid> <function> <inout> [<filename>]");
188
189 while ((opt = poptGetNextOpt(pc)) != -1) {
190 switch (opt) {
191 case OPT_CONTEXT_FILE:
192 ctx_filename = poptGetOptArg(pc);
193 break;
194 case OPT_VALIDATE:
195 validate = true;
196 break;
197 case OPT_DUMP_DATA:
198 dumpdata = true;
199 break;
200 case OPT_LOAD_DSO:
201 plugin = poptGetOptArg(pc);
202 break;
203 }
204 }
205
206 pipe_name = poptGetArg(pc);
207
208 if (!pipe_name) {
209 poptPrintUsage(pc, stderr, 0);
210 show_pipes();
211 exit(1);
212 }
213
214 if (plugin != NULL) {
215 p = load_iface_from_plugin(plugin, pipe_name);
216 }
217 if (!p) {
218 p = ndr_table_by_name(pipe_name);
219 }
220
221 if (!p) {
222 struct GUID uuid;
223
224 status = GUID_from_string(pipe_name, &uuid);
225
226 if (NT_STATUS_IS_OK(status)) {
227 p = ndr_table_by_uuid(&uuid);
228 }
229 }
230
231 if (!p) {
232 printf("Unknown pipe or UUID '%s'\n", pipe_name);
233 exit(1);
234 }
235
236 function = poptGetArg(pc);
237 inout = poptGetArg(pc);
238 filename = poptGetArg(pc);
239
240 if (!function || !inout) {
241 poptPrintUsage(pc, stderr, 0);
242 show_functions(p);
243 exit(1);
244 }
245
246 if (strcmp(inout, "in") == 0 ||
247 strcmp(inout, "request") == 0) {
248 flags = NDR_IN;
249 } else if (strcmp(inout, "out") == 0 ||
250 strcmp(inout, "response") == 0) {
251 flags = NDR_OUT;
252 } else {
253 printf("Bad inout value '%s'\n", inout);
254 exit(1);
255 }
256
257 f = find_function(p, function);
258
259 mem_ctx = talloc_init("ndrdump");
260
261 st = talloc_zero_size(mem_ctx, f->struct_size);
262 if (!st) {
263 printf("Unable to allocate %d bytes\n", (int)f->struct_size);
264 exit(1);
265 }
266
267 v_st = talloc_zero_size(mem_ctx, f->struct_size);
268 if (!v_st) {
269 printf("Unable to allocate %d bytes\n", (int)f->struct_size);
270 exit(1);
271 }
272
273 if (ctx_filename) {
274 if (flags == NDR_IN) {
275 printf("Context file can only be used for \"out\" packages\n");
276 exit(1);
277 }
278
279 data = (uint8_t *)file_load(ctx_filename, &size, 0, mem_ctx);
280 if (!data) {
281 perror(ctx_filename);
282 exit(1);
283 }
284
285 blob.data = data;
286 blob.length = size;
287
288 ndr_pull = ndr_pull_init_blob(&blob, mem_ctx, lp_iconv_convenience(cmdline_lp_ctx));
289 ndr_pull->flags |= LIBNDR_FLAG_REF_ALLOC;
290
291 ndr_err = f->ndr_pull(ndr_pull, NDR_IN, st);
292
293 if (ndr_pull->offset != ndr_pull->data_size) {
294 printf("WARNING! %d unread bytes while parsing context file\n", ndr_pull->data_size - ndr_pull->offset);
295 }
296
297 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
298 status = ndr_map_error2ntstatus(ndr_err);
299 printf("pull for context file returned %s\n", nt_errstr(status));
300 exit(1);
301 }
302 memcpy(v_st, st, f->struct_size);
303 }
304
305 if (filename)
306 data = (uint8_t *)file_load(filename, &size, 0, mem_ctx);
307 else
308 data = (uint8_t *)stdin_load(mem_ctx, &size);
309
310 if (!data) {
311 if (filename)
312 perror(filename);
313 else
314 perror("stdin");
315 exit(1);
316 }
317
318 blob.data = data;
319 blob.length = size;
320
321 ndr_pull = ndr_pull_init_blob(&blob, mem_ctx, lp_iconv_convenience(cmdline_lp_ctx));
322 ndr_pull->flags |= LIBNDR_FLAG_REF_ALLOC;
323
324 ndr_err = f->ndr_pull(ndr_pull, flags, st);
325 status = ndr_map_error2ntstatus(ndr_err);
326
327 printf("pull returned %s\n", nt_errstr(status));
328
329 if (ndr_pull->offset != ndr_pull->data_size) {
330 printf("WARNING! %d unread bytes\n", ndr_pull->data_size - ndr_pull->offset);
331 ndrdump_data(ndr_pull->data+ndr_pull->offset,
332 ndr_pull->data_size - ndr_pull->offset,
333 dumpdata);
334 }
335
336 if (dumpdata) {
337 printf("%d bytes consumed\n", ndr_pull->offset);
338 ndrdump_data(blob.data, blob.length, dumpdata);
339 }
340
341 ndr_print = talloc_zero(mem_ctx, struct ndr_print);
342 ndr_print->print = ndr_print_debug_helper;
343 ndr_print->depth = 1;
344 f->ndr_print(ndr_print, function, flags, st);
345
346 if (!NT_STATUS_IS_OK(status)) {
347 printf("dump FAILED\n");
348 exit(1);
349 }
350
351 if (validate) {
352 DATA_BLOB v_blob;
353 struct ndr_push *ndr_v_push;
354 struct ndr_pull *ndr_v_pull;
355 struct ndr_print *ndr_v_print;
356 uint32_t i;
357 uint8_t byte_a, byte_b;
358 bool differ;
359
360 ndr_v_push = ndr_push_init_ctx(mem_ctx, lp_iconv_convenience(cmdline_lp_ctx));
361
362 ndr_err = f->ndr_push(ndr_v_push, flags, st);
363 status = ndr_map_error2ntstatus(ndr_err);
364 printf("push returned %s\n", nt_errstr(status));
365 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
366 printf("validate push FAILED\n");
367 exit(1);
368 }
369
370 v_blob = ndr_push_blob(ndr_v_push);
371
372 if (dumpdata) {
373 printf("%ld bytes generated (validate)\n", (long)v_blob.length);
374 ndrdump_data(v_blob.data, v_blob.length, dumpdata);
375 }
376
377 ndr_v_pull = ndr_pull_init_blob(&v_blob, mem_ctx, lp_iconv_convenience(cmdline_lp_ctx));
378 ndr_v_pull->flags |= LIBNDR_FLAG_REF_ALLOC;
379
380 ndr_err = f->ndr_pull(ndr_v_pull, flags, v_st);
381 status = ndr_map_error2ntstatus(ndr_err);
382 printf("pull returned %s\n", nt_errstr(status));
383 if (!NDR_ERR_CODE_IS_SUCCESS(ndr_err)) {
384 printf("validate pull FAILED\n");
385 exit(1);
386 }
387
388
389 if (ndr_v_pull->offset != ndr_v_pull->data_size) {
390 printf("WARNING! %d unread bytes in validation\n", ndr_v_pull->data_size - ndr_v_pull->offset);
391 ndrdump_data(ndr_v_pull->data+ndr_v_pull->offset,
392 ndr_v_pull->data_size - ndr_v_pull->offset,
393 dumpdata);
394 }
395
396 ndr_v_print = talloc_zero(mem_ctx, struct ndr_print);
397 ndr_v_print->print = ndr_print_debug_helper;
398 ndr_v_print->depth = 1;
399 f->ndr_print(ndr_v_print, function, flags, v_st);
400
401 if (blob.length != v_blob.length) {
402 printf("WARNING! orig bytes:%llu validated pushed bytes:%llu\n",
403 (unsigned long long)blob.length, (unsigned long long)v_blob.length);
404 }
405
406 if (ndr_pull->offset != ndr_v_pull->offset) {
407 printf("WARNING! orig pulled bytes:%llu validated pulled bytes:%llu\n",
408 (unsigned long long)ndr_pull->offset, (unsigned long long)ndr_v_pull->offset);
409 }
410
411 differ = false;
412 byte_a = 0x00;
413 byte_b = 0x00;
414 for (i=0; i < blob.length; i++) {
415 byte_a = blob.data[i];
416
417 if (i == v_blob.length) {
418 byte_b = 0x00;
419 differ = true;
420 break;
421 }
422
423 byte_b = v_blob.data[i];
424
425 if (byte_a != byte_b) {
426 differ = true;
427 break;
428 }
429 }
430 if (differ) {
431 printf("WARNING! orig and validated differ at byte 0x%02X (%u)\n", i, i);
432 printf("WARNING! orig byte[0x%02X] = 0x%02X validated byte[0x%02X] = 0x%02X\n",
433 i, byte_a, i, byte_b);
434 }
435 }
436
437 printf("dump OK\n");
438
439 talloc_free(mem_ctx);
440
441 poptFreeContext(pc);
442
443 return 0;
444 }