#include <sys/types.h>
#include <sys/sockio.h>
#include <sys/socket.h>
#include <sys/utsname.h>
#include <stdarg.h>
#include <unistd.h>
#include <stdlib.h>
#include <time.h>
#include <synch.h>
#include <syslog.h>
#include <string.h>
#include <strings.h>
#include <errno.h>
#include <net/if.h>
#include <netdb.h>
#include <netinet/in.h>
#include <arpa/nameser.h>
#include <resolv.h>
#include <smbsrv/smbinfo.h>
#include <smbsrv/netbios.h>
#include <smbsrv/libsmb.h>
#include <assert.h>
static mutex_t seqnum_mtx;
typedef struct {
char user[SMB_USERNAME_MAXLEN];
uint8_t passwd[SMBAUTH_HASH_SZ];
} smb_ipc_t;
static smb_ipc_t ipc_info;
static smb_ipc_t ipc_orig_info;
static rwlock_t smb_ipc_lock;
void
smb_load_kconfig(smb_kmod_cfg_t *kcfg)
{
struct utsname uts;
int64_t citem;
int rc;
bzero(kcfg, sizeof (smb_kmod_cfg_t));
rc = smb_config_getnum(SMB_CI_MAX_WORKERS, &citem);
if (rc != SMBD_SMF_OK)
citem = SMB_PI_MAX_WORKERS_DEF;
if (citem > SMB_PI_MAX_WORKERS_MAX)
citem = SMB_PI_MAX_WORKERS_MAX;
kcfg->skc_maxworkers = (uint32_t)citem;
rc = smb_config_getnum(SMB_CI_MAXIMUM_CREDITS, &citem);
if (rc != SMBD_SMF_OK)
citem = SMB_PI_MAXIMUM_CREDITS_DEF;
if (citem > SMB_PI_MAXIMUM_CREDITS_MAX)
citem = SMB_PI_MAXIMUM_CREDITS_MAX;
kcfg->skc_maximum_credits = (uint16_t)citem;
if (kcfg->skc_maximum_credits > kcfg->skc_maxworkers)
kcfg->skc_maximum_credits = (uint16_t)kcfg->skc_maxworkers;
rc = smb_config_getnum(SMB_CI_INITIAL_CREDITS, &citem);
if (rc != SMBD_SMF_OK)
citem = SMB_PI_INITIAL_CREDITS_DEF;
if (citem > SMB_PI_INITIAL_CREDITS_MAX)
citem = SMB_PI_INITIAL_CREDITS_MAX;
kcfg->skc_initial_credits = (uint16_t)citem;
if (kcfg->skc_initial_credits > kcfg->skc_maximum_credits)
kcfg->skc_initial_credits = kcfg->skc_maximum_credits;
if (kcfg->skc_initial_credits < SMB_PI_INITIAL_CREDITS_MIN)
kcfg->skc_initial_credits = SMB_PI_INITIAL_CREDITS_MIN;
if (kcfg->skc_maximum_credits < SMB_PI_MAXIMUM_CREDITS_MIN)
kcfg->skc_maximum_credits = SMB_PI_MAXIMUM_CREDITS_MIN;
if (kcfg->skc_maximum_credits < kcfg->skc_initial_credits)
kcfg->skc_maximum_credits = kcfg->skc_initial_credits;
if (kcfg->skc_maxworkers < SMB_PI_MAX_WORKERS_MIN)
kcfg->skc_maxworkers = SMB_PI_MAX_WORKERS_MIN;
if (kcfg->skc_maxworkers < kcfg->skc_maximum_credits)
kcfg->skc_maxworkers = kcfg->skc_maximum_credits;
(void) smb_config_getnum(SMB_CI_KEEPALIVE, &citem);
kcfg->skc_keepalive = (uint32_t)citem;
if ((kcfg->skc_keepalive != 0) &&
(kcfg->skc_keepalive < SMB_PI_KEEP_ALIVE_MIN))
kcfg->skc_keepalive = SMB_PI_KEEP_ALIVE_MIN;
(void) smb_config_getnum(SMB_CI_MAX_CONNECTIONS, &citem);
kcfg->skc_maxconnections = (uint32_t)citem;
(void) smb_config_getnum(SMB_CI_MAX_OPENS, &citem);
kcfg->skc_max_opens = (uint32_t)citem;
kcfg->skc_restrict_anon = smb_config_getbool(SMB_CI_RESTRICT_ANON);
kcfg->skc_signing_enable = smb_config_getbool(SMB_CI_SIGNING_ENABLE);
kcfg->skc_signing_required = smb_config_getbool(SMB_CI_SIGNING_REQD);
kcfg->skc_netbios_enable = smb_config_getbool(SMB_CI_NETBIOS_ENABLE);
kcfg->skc_ipv6_enable = smb_config_getbool(SMB_CI_IPV6_ENABLE);
kcfg->skc_print_enable = smb_config_getbool(SMB_CI_PRINT_ENABLE);
kcfg->skc_oplock_enable = smb_config_getbool(SMB_CI_OPLOCK_ENABLE);
kcfg->skc_sync_enable = smb_config_getbool(SMB_CI_SYNC_ENABLE);
kcfg->skc_traverse_mounts = smb_config_getbool(SMB_CI_TRAVERSE_MOUNTS);
kcfg->skc_short_names = smb_config_getbool(SMB_CI_SHORT_NAMES);
kcfg->skc_max_protocol = smb_config_get_max_protocol();
kcfg->skc_min_protocol = smb_config_get_min_protocol();
kcfg->skc_secmode = smb_config_get_secmode();
kcfg->skc_encrypt = smb_config_get_require(SMB_CI_ENCRYPT);
kcfg->skc_encrypt_ciphers = smb_config_get_encrypt_ciphers();
kcfg->skc_sign_algs = smb_config_get_signing_algs();
(void) smb_getdomainname(kcfg->skc_nbdomain,
sizeof (kcfg->skc_nbdomain));
(void) smb_getfqdomainname(kcfg->skc_fqdn,
sizeof (kcfg->skc_fqdn));
(void) smb_getnetbiosname(kcfg->skc_hostname,
sizeof (kcfg->skc_hostname));
(void) smb_config_getstr(SMB_CI_SYS_CMNT, kcfg->skc_system_comment,
sizeof (kcfg->skc_system_comment));
smb_config_get_version(&kcfg->skc_version);
kcfg->skc_execflags = smb_config_get_execinfo(NULL, NULL, 0);
if (smb_config_get_localuuid(kcfg->skc_machine_uuid) < 0) {
syslog(LOG_ERR, "smb_load_kconfig: no machine_uuid");
uuid_generate_time(kcfg->skc_machine_uuid);
}
(void) uname(&uts);
(void) snprintf(kcfg->skc_native_os, sizeof (kcfg->skc_native_os),
"%s %s %s", uts.sysname, uts.release, uts.version);
(void) strlcpy(kcfg->skc_native_lm, "Native SMB service",
sizeof (kcfg->skc_native_lm));
}
int
smb_getnetbiosname(char *buf, size_t buflen)
{
if (smb_gethostname(buf, buflen, SMB_CASE_UPPER) != 0)
return (-1);
if (buflen >= NETBIOS_NAME_SZ)
buf[NETBIOS_NAME_SZ - 1] = '\0';
return (0);
}
int
smb_getsamaccount(char *buf, size_t buflen)
{
if (smb_getnetbiosname(buf, buflen - 1) != 0)
return (-1);
(void) strlcat(buf, "$", buflen);
return (0);
}
int
smb_gethostname(char *buf, size_t buflen, smb_caseconv_t which)
{
char *p;
if (buf == NULL || buflen == 0)
return (-1);
if (gethostname(buf, buflen) != 0) {
*buf = '\0';
return (-1);
}
buf[buflen - 1] = '\0';
if ((p = strchr(buf, '.')) != NULL)
*p = '\0';
switch (which) {
case SMB_CASE_LOWER:
(void) smb_strlwr(buf);
break;
case SMB_CASE_UPPER:
(void) smb_strupr(buf);
break;
case SMB_CASE_PRESERVE:
default:
break;
}
return (0);
}
int
smb_getfqhostname(char *buf, size_t buflen)
{
char hostname[MAXHOSTNAMELEN];
char domain[MAXHOSTNAMELEN];
hostname[0] = '\0';
domain[0] = '\0';
if (smb_gethostname(hostname, MAXHOSTNAMELEN,
SMB_CASE_LOWER) != 0)
return (-1);
if (smb_getfqdomainname(domain, MAXHOSTNAMELEN) != 0)
return (-1);
if (hostname[0] == '\0')
return (-1);
if (domain[0] == '\0') {
(void) strlcpy(buf, hostname, buflen);
return (0);
}
(void) snprintf(buf, buflen, "%s.%s", hostname, domain);
return (0);
}
int
smb_getdomainname(char *buf, size_t buflen)
{
int rc;
if (buf == NULL || buflen == 0)
return (-1);
*buf = '\0';
rc = smb_config_getstr(SMB_CI_DOMAIN_NAME, buf, buflen);
if ((rc != SMBD_SMF_OK) || (*buf == '\0'))
return (-1);
return (0);
}
int
smb_getfqdomainname(char *buf, size_t buflen)
{
struct __res_state res_state;
int rc;
if (buf == NULL || buflen == 0)
return (-1);
*buf = '\0';
if (smb_config_get_secmode() == SMB_SECMODE_DOMAIN) {
rc = smb_config_getstr(SMB_CI_DOMAIN_FQDN, buf, buflen);
if ((rc != SMBD_SMF_OK) || (*buf == '\0'))
return (-1);
} else {
bzero(&res_state, sizeof (struct __res_state));
if (res_ninit(&res_state))
return (-1);
if (*res_state.defdname == '\0') {
res_ndestroy(&res_state);
return (-1);
}
(void) strlcpy(buf, res_state.defdname, buflen);
res_ndestroy(&res_state);
rc = 0;
}
return (rc);
}
static int
smb_set_machine_passwd(char *passwd)
{
int64_t num;
int rc = -1;
if (smb_config_set(SMB_CI_MACHINE_PASSWD, passwd) != SMBD_SMF_OK)
return (-1);
(void) mutex_lock(&seqnum_mtx);
(void) smb_config_getnum(SMB_CI_KPASSWD_SEQNUM, &num);
if (smb_config_setnum(SMB_CI_KPASSWD_SEQNUM, ++num)
== SMBD_SMF_OK)
rc = 0;
(void) mutex_unlock(&seqnum_mtx);
return (rc);
}
static int
smb_get_machine_passwd(uint8_t *buf, size_t buflen)
{
char pwd[SMB_PASSWD_MAXLEN + 1];
int rc;
if (buflen < SMBAUTH_HASH_SZ)
return (-1);
rc = smb_config_getstr(SMB_CI_MACHINE_PASSWD, pwd, sizeof (pwd));
if ((rc != SMBD_SMF_OK) || *pwd == '\0')
return (-1);
if (smb_auth_ntlm_hash(pwd, buf) != 0)
return (-1);
return (rc);
}
void
smb_ipc_init(void)
{
int rc;
(void) rw_wrlock(&smb_ipc_lock);
bzero(&ipc_info, sizeof (smb_ipc_t));
bzero(&ipc_orig_info, sizeof (smb_ipc_t));
(void) smb_getsamaccount(ipc_info.user, SMB_USERNAME_MAXLEN);
rc = smb_get_machine_passwd(ipc_info.passwd, SMBAUTH_HASH_SZ);
if (rc != 0)
*ipc_info.passwd = 0;
(void) rw_unlock(&smb_ipc_lock);
}
void
smb_ipc_set(char *plain_user, uint8_t *passwd_hash)
{
(void) rw_wrlock(&smb_ipc_lock);
(void) strlcpy(ipc_info.user, plain_user, sizeof (ipc_info.user));
(void) memcpy(ipc_info.passwd, passwd_hash, SMBAUTH_HASH_SZ);
(void) rw_unlock(&smb_ipc_lock);
}
void
smb_ipc_commit(void)
{
(void) rw_wrlock(&smb_ipc_lock);
(void) smb_getsamaccount(ipc_info.user, SMB_USERNAME_MAXLEN);
(void) smb_get_machine_passwd(ipc_info.passwd, SMBAUTH_HASH_SZ);
(void) memcpy(&ipc_orig_info, &ipc_info, sizeof (smb_ipc_t));
(void) rw_unlock(&smb_ipc_lock);
}
void
smb_ipc_rollback(void)
{
(void) rw_wrlock(&smb_ipc_lock);
(void) strlcpy(ipc_info.user, ipc_orig_info.user,
sizeof (ipc_info.user));
(void) memcpy(ipc_info.passwd, ipc_orig_info.passwd,
sizeof (ipc_info.passwd));
(void) rw_unlock(&smb_ipc_lock);
}
void
smb_ipc_get_user(char *buf, size_t buflen)
{
(void) rw_rdlock(&smb_ipc_lock);
(void) strlcpy(buf, ipc_info.user, buflen);
(void) rw_unlock(&smb_ipc_lock);
}
void
smb_ipc_get_passwd(uint8_t *buf, size_t buflen)
{
if (buflen < SMBAUTH_HASH_SZ)
return;
(void) rw_rdlock(&smb_ipc_lock);
(void) memcpy(buf, ipc_info.passwd, SMBAUTH_HASH_SZ);
(void) rw_unlock(&smb_ipc_lock);
}
boolean_t
smb_match_netlogon_seqnum(void)
{
int64_t setpasswd_seqnum;
int64_t netlogon_seqnum;
(void) mutex_lock(&seqnum_mtx);
(void) smb_config_getnum(SMB_CI_KPASSWD_SEQNUM, &setpasswd_seqnum);
(void) smb_config_getnum(SMB_CI_NETLOGON_SEQNUM, &netlogon_seqnum);
(void) mutex_unlock(&seqnum_mtx);
return (setpasswd_seqnum == netlogon_seqnum);
}
int
smb_setdomainprops(char *fqdn, char *server, char *passwd)
{
if (server == NULL || passwd == NULL)
return (-1);
if ((*server == '\0') || (*passwd == '\0'))
return (-1);
if (fqdn && (smb_config_set(SMB_CI_KPASSWD_DOMAIN, fqdn) != 0))
return (-1);
if (smb_config_set(SMB_CI_KPASSWD_SRV, server) != 0)
return (-1);
if (smb_set_machine_passwd(passwd) != 0) {
syslog(LOG_ERR, "smb_setdomainprops: failed to set"
" machine account password");
return (-1);
}
(void) smb_config_setbool(SMB_CI_DOMAIN_MEMB, B_TRUE);
return (0);
}
void
smb_update_netlogon_seqnum(void)
{
int64_t num;
(void) mutex_lock(&seqnum_mtx);
(void) smb_config_getnum(SMB_CI_KPASSWD_SEQNUM, &num);
(void) smb_config_setnum(SMB_CI_NETLOGON_SEQNUM, num);
(void) mutex_unlock(&seqnum_mtx);
}
void
smb_tracef(const char *fmt, ...)
{
va_list ap;
char buf[128];
va_start(ap, fmt);
(void) vsnprintf(buf, 128, fmt, ap);
va_end(ap);
smb_trace(buf);
}
void
smb_trace(const char *s __unused)
{
}
void
smb_tonetbiosname(char *name, char *nb_name, char suffix)
{
char tmp_name[NETBIOS_NAME_SZ];
smb_wchar_t wtmp_name[NETBIOS_NAME_SZ];
int len;
size_t rc;
len = 0;
rc = smb_mbstowcs(wtmp_name, (const char *)name, NETBIOS_NAME_SZ);
if (rc != (size_t)-1) {
wtmp_name[NETBIOS_NAME_SZ - 1] = 0;
rc = ucstooem(tmp_name, wtmp_name, NETBIOS_NAME_SZ,
OEM_CPG_850);
if (rc > 0)
len = strlen(tmp_name);
}
(void) memset(nb_name, ' ', NETBIOS_NAME_SZ - 1);
if (len) {
(void) smb_strupr(tmp_name);
(void) memcpy(nb_name, tmp_name, len);
}
nb_name[NETBIOS_NAME_SZ - 1] = suffix;
}
int
smb_get_nameservers(smb_inaddr_t *ips, int sz)
{
union res_sockaddr_union set[MAXNS];
int i, cnt;
struct __res_state res_state;
char ipstr[INET6_ADDRSTRLEN];
if (ips == NULL)
return (0);
bzero(&res_state, sizeof (struct __res_state));
if (res_ninit(&res_state) < 0)
return (0);
cnt = res_getservers(&res_state, set, MAXNS);
for (i = 0; i < cnt; i++) {
if (i >= sz)
break;
ips[i].a_family = AF_INET;
bcopy(&set[i].sin.sin_addr, &ips[i].a_ipv4, NS_INADDRSZ);
if (inet_ntop(AF_INET, &ips[i].a_ipv4, ipstr,
INET_ADDRSTRLEN)) {
syslog(LOG_DEBUG, "Found %s name server\n", ipstr);
continue;
}
ips[i].a_family = AF_INET6;
bcopy(&set[i].sin.sin_addr, &ips[i].a_ipv6, NS_IN6ADDRSZ);
if (inet_ntop(AF_INET6, &ips[i].a_ipv6, ipstr,
INET6_ADDRSTRLEN)) {
syslog(LOG_DEBUG, "Found %s name server\n", ipstr);
}
}
res_ndestroy(&res_state);
return (i);
}
struct hostent *
smb_gethostbyname(const char *name, int *err_num)
{
struct hostent *h;
h = getipnodebyname(name, AF_INET, 0, err_num);
if ((h == NULL) || h->h_length != INADDRSZ)
h = getipnodebyname(name, AF_INET6, AI_DEFAULT, err_num);
return (h);
}
struct hostent *
smb_gethostbyaddr(const char *addr, int len, int type, int *err_num)
{
struct hostent *h;
h = getipnodebyaddr(addr, len, type, err_num);
return (h);
}
uint32_t
smb_get_netlogon_flags(void)
{
int64_t val;
if (smb_config_getnum(SMB_CI_NETLOGON_FLAGS, &val) != SMBD_SMF_OK)
return (SMB_PI_NETLOGON_FLAGS_DEFAULT);
return ((uint32_t)val);
}