|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
SMB2 client wire codec (MS-SMB2), PROTOCORE_ENABLE_SMB - increment 1: the transport frame, the 64-byte sync packet header, and the NEGOTIATE exchange. More...
#include "protocore_config.h"Go to the source code of this file.
Classes | |
| struct | Smb2Header |
| Parsed SMB2 sync header. More... | |
| struct | Smb2NegotiateContexts |
| Parsed SMB 3.1.1 NEGOTIATE-response negotiate contexts (MS-SMB2 §2.2.4 / §2.2.3.1). More... | |
| struct | Smb2NegotiateResp |
| Parsed NEGOTIATE response (MS-SMB2 §2.2.4). More... | |
| struct | SmbPreauth |
| The SMB 3.1.1 preauth-integrity hash value (MS-SMB2 §3.1.5.2): a running SHA-512 chained over every NEGOTIATE and SESSION_SETUP message of the handshake. Its final value binds the whole pre-authentication exchange and feeds the 3.1.1 signing / encryption key derivation. More... | |
| struct | Smb2SessionSetupResp |
| Parsed SESSION_SETUP response (MS-SMB2 §2.2.6). More... | |
| struct | Smb2TreeConnectResp |
| Parsed TREE_CONNECT response (MS-SMB2 §2.2.10). The TreeId is in the response header. More... | |
| struct | Smb2CreateResp |
| Parsed CREATE response (MS-SMB2 §2.2.14). More... | |
| struct | Smb2CloseResp |
| Parsed CLOSE response (MS-SMB2 §2.2.16). More... | |
| struct | Smb2ReadResp |
| Parsed READ response (MS-SMB2 §2.2.20). More... | |
| struct | Smb2WriteResp |
| Parsed WRITE response (MS-SMB2 §2.2.22). More... | |
| struct | Smb2Ns |
| Dispatch table. Addressed by offset, so the layout is asserted below. More... | |
Macros | |
| #define | PROTOCORE_SMB2_HEADER_SIZE 64 |
| Fixed SMB2 sync header size (MS-SMB2 §2.2.1). | |
| #define | SMB2_NEGOTIATE_SIGNING_ENABLED 0x0001 |
| NEGOTIATE / SESSION_SETUP SecurityMode flags (MS-SMB2 §2.2.3). | |
| #define | SMB2_NEGOTIATE_SIGNING_REQUIRED 0x0002 |
| #define | SMB2_FLAGS_SERVER_TO_REDIR 0x00000001 |
| SMB2 header Flags field (MS-SMB2 §2.2.1.2). | |
| #define | SMB2_FLAGS_SIGNED 0x00000008 |
| the message carries an HMAC signature | |
| #define | SMB2_SESSION_FLAG_IS_GUEST 0x0001 |
| SESSION_SETUP response SessionFlags (MS-SMB2 §2.2.6). | |
| #define | SMB2_SESSION_FLAG_IS_NULL 0x0002 |
| #define | SMB2_SESSION_FLAG_ENCRYPT_DATA 0x0004 |
| #define | SMB2_STATUS_SUCCESS 0x00000000 |
| NT status values seen in the SMB2 header during the SESSION_SETUP exchange. | |
| #define | SMB2_STATUS_MORE_PROCESSING_REQUIRED 0xC0000016 |
| server wants the next round | |
| #define | SMB2_STATUS_END_OF_FILE 0xC0000011 |
| a READ at/past end of file | |
| #define | SMB2_SHARE_TYPE_DISK 0x01 |
| TREE_CONNECT response ShareType (MS-SMB2 §2.2.10). | |
| #define | SMB2_SHARE_TYPE_PIPE 0x02 |
| #define | SMB2_SHARE_TYPE_PRINT 0x03 |
| #define | SMB2_FILE_READ_DATA 0x00000001 |
| CREATE DesiredAccess masks (MS-DTYP ACCESS_MASK; the common file rights). | |
| #define | SMB2_FILE_WRITE_DATA 0x00000002 |
| #define | SMB2_FILE_APPEND_DATA 0x00000004 |
| #define | SMB2_FILE_READ_ATTRIBUTES 0x00000080 |
| #define | SMB2_FILE_GENERIC_READ 0x00120089 |
| RC|SYNC|READ_ATTR|READ_EA|READ_DATA. | |
| #define | SMB2_FILE_GENERIC_WRITE 0x00120116 |
| RC|SYNC|WRITE_ATTR|WRITE_EA|APPEND|WRITE. | |
| #define | SMB2_FILE_SHARE_READ 0x01 |
| CREATE ShareAccess (MS-SMB2 §2.2.13). | |
| #define | SMB2_FILE_SHARE_WRITE 0x02 |
| #define | SMB2_FILE_SHARE_DELETE 0x04 |
| #define | SMB2_FILE_SUPERSEDE 0 |
| CREATE CreateDisposition (MS-SMB2 §2.2.13). | |
| #define | SMB2_FILE_OPEN 1 |
| open an existing file, fail if absent | |
| #define | SMB2_FILE_CREATE 2 |
| create, fail if it exists | |
| #define | SMB2_FILE_OPEN_IF 3 |
| open, create if absent | |
| #define | SMB2_FILE_OVERWRITE 4 |
| open + truncate, fail if absent | |
| #define | SMB2_FILE_OVERWRITE_IF 5 |
| #define | SMB2_FILE_DIRECTORY_FILE 0x00000001 |
| CREATE CreateOptions (MS-SMB2 §2.2.13; the two we set). | |
| #define | SMB2_FILE_NON_DIRECTORY_FILE 0x00000040 |
| #define | SMB2_PREAUTH_INTEGRITY_CAPABILITIES 0x0001 |
| SMB 3.1.1 negotiate-context types (MS-SMB2 §2.2.3.1). | |
| #define | SMB2_ENCRYPTION_CAPABILITIES 0x0002 |
| #define | SMB2_COMPRESSION_CAPABILITIES 0x0003 |
| #define | SMB2_NETNAME_NEGOTIATE_CONTEXT_ID 0x0005 |
| #define | SMB2_TRANSPORT_CAPABILITIES 0x0006 |
| #define | SMB2_RDMA_TRANSFORM_CAPABILITIES 0x0007 |
| #define | SMB2_SIGNING_CAPABILITIES 0x0008 |
| #define | SMB2_PREAUTH_INTEGRITY_SHA512 0x0001 |
| Preauth-integrity hash algorithm IDs (MS-SMB2 §2.2.3.1.1). | |
| #define | SMB2_SIGNING_HMAC_SHA256 0x0000 |
| Signing algorithm IDs (MS-SMB2 §2.2.3.1.7). | |
| #define | SMB2_SIGNING_AES_CMAC 0x0001 |
| #define | SMB2_SIGNING_AES_GMAC 0x0002 |
| #define | SMB2_GLOBAL_CAP_ENCRYPTION 0x00000040 |
NEGOTIATE request/response Capabilities flags (MS-SMB2 §2.2.3 / §2.2.4). A client that supports transport encryption MUST advertise SMB2_GLOBAL_CAP_ENCRYPTION here, or a server (e.g. Samba with smb encrypt = required) will not negotiate a cipher and will reject the unencrypted session (§3.2.4.2.2). | |
| #define | SMB2_ENCRYPTION_AES128_CCM 0x0001 |
| Encryption cipher IDs (MS-SMB2 §2.2.3.1.2). | |
| #define | SMB2_ENCRYPTION_AES128_GCM 0x0002 |
| #define | SMB2_ENCRYPTION_AES256_CCM 0x0003 |
| #define | SMB2_ENCRYPTION_AES256_GCM 0x0004 |
| #define | PROTOCORE_SMB2_MAX_OFFER_CIPHERS 4 |
| Max encryption ciphers a NEGOTIATE request can advertise (the four SMB 3.1.1 ciphers). | |
| #define | PROTOCORE_SMB2_PREAUTH_HASH_LEN 64 |
| Length of the SMB 3.1.1 preauth-integrity hash (SHA-512 digest size). | |
| #define | SMB2_SHAREFLAG_ENCRYPT_DATA 0x00008000 |
| TREE_CONNECT response ShareFlags of interest (MS-SMB2 §2.2.10). | |
| #define | PROTOCORE_SMB2_TRANSFORM_HDR_LEN 52 |
| TRANSFORM_HEADER size: ProtocolId(4)+Signature(16)+Nonce(16)+OriginalMessageSize(4)+Reserved(2)+ Flags(2)+SessionId(8) = 52 bytes (MS-SMB2 §2.2.41). | |
| #define | PROTOCORE_SMB2_TRANSFORM_PROTOCOL_ID 0x424D53FDu |
| TRANSFORM_HEADER ProtocolId 0xFD 'S' 'M' 'B' as a little-endian u32. | |
| #define | PROTOCORE_SMB2_NONCE_FIELD_LEN 16 |
| The TRANSFORM_HEADER Nonce field width (MS-SMB2 §2.2.41). The AEAD uses the leading protocore_smb2_cipher_nonce_len() bytes; the rest are zero. | |
| #define | PROTOCORE_SMB2_GCM_NONCE_LEN 12 |
| AES-GCM nonce length used within the 16-byte Nonce field. | |
| #define | PROTOCORE_SMB2_CCM_NONCE_LEN 11 |
| AES-CCM nonce length used within the 16-byte Nonce field (MS-SMB2 §3.1.4.3). | |
| #define | PROTOCORE_SMB2_MAX_CIPHER_KEY_LEN 32 |
| Largest cipher key length across the four SMB 3.1.1 ciphers (AES-256), for buffer sizing. | |
Typedefs | |
| typedef enum PROTO_ENUM_PACKED | Smb2Command |
| SMB2 command codes (MS-SMB2 §2.2.1.2). | |
| typedef enum PROTO_ENUM_PACKED | Smb2Dialect |
| SMB2 dialect revision numbers (MS-SMB2 §2.2.4). | |
| typedef enum PROTO_ENUM_PACKED | Smb2SignAlgo |
| The per-session message-signing algorithm the client selects from the negotiated dialect. | |
Functions | |
| PROTOCORE_NS_LAYOUT (Smb2Ns, transport_frame, transport_len, build_header, parse_header, build_negotiate, parse_negotiate_response, build_negotiate_311, parse_negotiate_contexts, preauth_init, preauth_update, build_session_setup, parse_session_setup_response, build_tree_connect, parse_tree_connect_response, build_create, parse_create_response, build_close, parse_close_response, build_read, parse_read_response, build_write, parse_write_response, sign, verify, sign_cmac, verify_cmac, derive_signing_key, derive_encryption_keys, encrypt, decrypt) | |
| size_t | protocore_smb2_transport_frame (uint8_t *work, uint8_t *out, size_t cap, const uint8_t *msg, size_t msg_len) |
| Prefix an SMB2 message with the 4-byte Direct-TCP transport header . | |
| uint32_t | protocore_smb2_transport_len (uint8_t *work, const uint8_t *buf, size_t len) |
| Read the Direct-TCP transport length prefix. | |
| size_t | protocore_smb2_build_header (uint8_t *work, uint8_t *buf, size_t cap, Smb2Command command, uint16_t credit_request, uint64_t message_id, uint32_t tree_id, uint64_t session_id) |
| Build a 64-byte SMB2 sync header into buf. | |
| proto_bool | protocore_smb2_parse_header (uint8_t *work, const uint8_t *buf, size_t len, Smb2Header *out) |
| Parse a 64-byte SMB2 sync header (validates ProtocolId + . | |
| size_t | protocore_smb2_build_negotiate (uint8_t *work, uint8_t *buf, size_t cap, const uint8_t *client_guid, uint16_t security_mode) |
| Build a NEGOTIATE request (header + body) offering SMB 2.0.2 / 2.1 . | |
| proto_bool | protocore_smb2_parse_negotiate_response (uint8_t *work, const uint8_t *msg, size_t len, Smb2NegotiateResp *out) |
| Parse a NEGOTIATE response message (the SMB2 header + §2.2.4 body). | |
| size_t | protocore_smb2_build_negotiate_311 (uint8_t *work, uint8_t *buf, size_t cap, const uint8_t *client_guid, uint16_t security_mode, const uint8_t *salt, size_t salt_len, const uint16_t *ciphers, size_t cipher_count) |
| Build an SMB 3.1.1 NEGOTIATE request: the dialect list SMB 2.0.2 .. . | |
| proto_bool | protocore_smb2_parse_negotiate_contexts (uint8_t *work, const uint8_t *msg, size_t len, Smb2NegotiateContexts *out) |
| Walk the negotiate-context list of a 3.1.1 NEGOTIATE response . | |
| void | protocore_smb2_preauth_init (uint8_t *work, SmbPreauth *p) |
| Seed the preauth-integrity hash with 64 zero bytes (the initial . | |
| void | protocore_smb2_preauth_update (uint8_t *work, uint8_t *crypto_work, SmbPreauth *p, const uint8_t *msg, size_t len) |
| Fold one handshake message into the preauth-integrity hash: hash = . | |
| size_t | protocore_smb2_build_session_setup (uint8_t *work, uint8_t *buf, size_t cap, uint64_t message_id, uint64_t session_id, uint8_t security_mode, const uint8_t *sec_buf, size_t sec_len) |
| Build a SESSION_SETUP request (header + §2.2.5 body) carrying a . | |
| proto_bool | protocore_smb2_parse_session_setup_response (uint8_t *work, const uint8_t *msg, size_t len, Smb2SessionSetupResp *out) |
| Parse a SESSION_SETUP response message (the SMB2 header + §2.2.6 . | |
| size_t | protocore_smb2_build_tree_connect (uint8_t *work, uint8_t *buf, size_t cap, uint64_t message_id, uint64_t session_id, const uint8_t *path_utf16, size_t path_len) |
| Build a TREE_CONNECT request (header + §2.2.9 body) for a share path. | |
| proto_bool | protocore_smb2_parse_tree_connect_response (uint8_t *work, const uint8_t *msg, size_t len, Smb2TreeConnectResp *out) |
| Parse a TREE_CONNECT response message (validates command + . | |
| size_t | protocore_smb2_build_create (uint8_t *work, uint8_t *buf, size_t cap, uint64_t message_id, uint64_t session_id, uint32_t tree_id, uint32_t desired_access, uint32_t share_access, uint32_t create_disposition, uint32_t create_options, const uint8_t *name_utf16, size_t name_len) |
| Build a CREATE request (header + §2.2.13 body) to open/create a . | |
| proto_bool | protocore_smb2_parse_create_response (uint8_t *work, const uint8_t *msg, size_t len, Smb2CreateResp *out) |
| Parse a CREATE response message (validates command + StructureSize . | |
| size_t | protocore_smb2_build_close (uint8_t *work, uint8_t *buf, size_t cap, uint64_t message_id, uint64_t session_id, uint32_t tree_id, const uint8_t *file_id) |
| Build a CLOSE request (header + §2.2.15 body) for an open FileId. | |
| proto_bool | protocore_smb2_parse_close_response (uint8_t *work, const uint8_t *msg, size_t len, Smb2CloseResp *out) |
| Parse a CLOSE response message (validates command + StructureSize . | |
| size_t | protocore_smb2_build_read (uint8_t *work, uint8_t *buf, size_t cap, uint64_t message_id, uint64_t session_id, uint32_t tree_id, const uint8_t *file_id, uint32_t length, uint64_t offset) |
| Build a READ request (header + §2.2.19 body) for length bytes at . | |
| proto_bool | protocore_smb2_parse_read_response (uint8_t *work, const uint8_t *msg, size_t len, Smb2ReadResp *out) |
| Parse a READ response message (validates command + StructureSize . | |
| size_t | protocore_smb2_build_write (uint8_t *work, uint8_t *buf, size_t cap, uint64_t message_id, uint64_t session_id, uint32_t tree_id, const uint8_t *file_id, const uint8_t *data, size_t data_len, uint64_t offset) |
| Build a WRITE request (header + §2.2.21 body) writing data at . | |
| proto_bool | protocore_smb2_parse_write_response (uint8_t *work, const uint8_t *msg, size_t len, Smb2WriteResp *out) |
| Parse a WRITE response message (validates command + StructureSize . | |
| void | protocore_smb2_sign (uint8_t *work, uint8_t *crypto_work, const uint8_t *key, uint8_t *msg, size_t msg_len) |
| Sign an SMB2 message in place (MS-SMB2 §3.1.4.1, SMB 2.x). Sets . | |
| proto_bool | protocore_smb2_verify (uint8_t *work, uint8_t *crypto_work, const uint8_t *key, uint8_t *msg, size_t msg_len) |
| Verify an SMB2 message's signature (MS-SMB2 §3.1.5.1). Recomputes . | |
| void | protocore_smb2_sign_cmac (uint8_t *work, uint8_t *crypto_work, const uint8_t *key, uint8_t *msg, size_t msg_len) |
| Sign an SMB2 message in place with AES-128-CMAC (MS-SMB2 §3.1.4.1, . | |
| proto_bool | protocore_smb2_verify_cmac (uint8_t *work, uint8_t *crypto_work, const uint8_t *key, uint8_t *msg, size_t msg_len) |
| Verify an AES-128-CMAC-signed SMB2 message (MS-SMB2 §3.1.5.1, SMB . | |
| proto_bool | protocore_smb2_derive_signing_key (uint8_t *work, const uint8_t *session_key, uint16_t dialect, const uint8_t *preauth, uint8_t *out_key) |
| Derive the 16-byte SMB 3.x signing key from the NTLM session key . | |
| proto_bool | protocore_smb2_derive_encryption_keys (uint8_t *work, const uint8_t *session_key, uint16_t dialect, const uint8_t *preauth, size_t key_len, uint8_t *out_c2s, uint8_t *out_s2c) |
| Derive the two SMB 3.x cipher keys from the NTLM session key . | |
| size_t | protocore_smb2_encrypt (uint8_t *work, uint16_t cipher, const uint8_t *key, const uint8_t *nonce, uint64_t session_id, const uint8_t *msg, size_t msg_len, uint8_t *out, size_t out_cap) |
| Encrypt one SMB2 message into a TRANSFORM_HEADER-wrapped blob . | |
| size_t | protocore_smb2_decrypt (uint8_t *work, uint16_t cipher, const uint8_t *key, const uint8_t *in, size_t in_len, uint8_t *out, size_t out_cap) |
| Decrypt a TRANSFORM_HEADER-wrapped SMB2 message (MS-SMB2 §3.1.4.4): . | |
Variables | |
| PROTOCORE_NS Smb2Ns Smb2 | PROTOCORE_UNUSED |
| Module namespace. | |
SMB2 client wire codec (MS-SMB2), PROTOCORE_ENABLE_SMB - increment 1: the transport frame, the 64-byte sync packet header, and the NEGOTIATE exchange.
Windows-share program storage is a common CNC file path (Fanuc / Haas / Mazak / Heidenhain expose one), so a device can read/write .nc files over SMB2. This is the pure wire layer: build the little-endian SMB2 messages and parse the responses; the TCP socket is the application's. All fields are little-endian (SMB2 is a little-endian protocol).
A client speaks SMB2 over Direct TCP (port 445): each message is prefixed by a 4-byte transport header (0x00 + a 24-bit big-endian length), then the 64-byte SMB2 sync header (MS-SMB2 §2.2.1.2), then the per-command body. The exchange begins with NEGOTIATE (§2.2.3 request / §2.2.4 response): the client offers a dialect list, the server picks one and returns the SPNEGO security token that seeds authentication.
Shipped: the NEGOTIATE exchange; the NTLM crypto (smb_md / ntlm / ntlmssp); the SPNEGO wrapping (spnego); the SESSION_SETUP request/response framing that carries those tokens; and the TREE_CONNECT / CREATE / CLOSE / READ / WRITE file commands - the full read/write-a-file-on-a-share client; SMB 2.x message signing (protocore_smb2_sign / protocore_smb2_verify, HMAC-SHA256) wired into the client's SigningRequired path; and the SMB 3.1.1 negotiate-context codec (protocore_smb2_build_negotiate_311 / protocore_smb2_parse_negotiate_contexts - preauth-integrity SHA-512, signing, and encryption capabilities); and the SP800-108 counter-mode KDF (protocore_kdf_ctr_hmac_sha256 in src/crypto/kdf, NIST-CAVP-verified) that SMB 3.x uses to derive its keys. SMB 3.1.1 runs end to end: the client offers 2.0.2 .. 3.1.1, chains the preauth-integrity hash (protocore_smb_preauth_*) across NEGOTIATE + both SESSION_SETUP rounds, derives the signing key (derive_signing_key), and signs the session with AES-128-CMAC (protocore_smb2_sign_cmac / _verify_cmac; crypto/aes_cmac) - the KDF assembly + CMAC cross-checked byte-for-byte against impacket.
work is bytes the CALLER holds. This module reads none of them: it carries nothing between calls, so there is no state to keep and nothing to wipe. The parameter is there so a caller drives every namespace the same way.
Definition in file smb2.h.
| #define PROTOCORE_SMB2_HEADER_SIZE 64 |
| #define SMB2_NEGOTIATE_SIGNING_ENABLED 0x0001 |
| #define SMB2_FLAGS_SERVER_TO_REDIR 0x00000001 |
| #define SMB2_FLAGS_SIGNED 0x00000008 |
| #define SMB2_SESSION_FLAG_IS_GUEST 0x0001 |
| #define SMB2_STATUS_SUCCESS 0x00000000 |
| #define SMB2_STATUS_MORE_PROCESSING_REQUIRED 0xC0000016 |
| #define SMB2_STATUS_END_OF_FILE 0xC0000011 |
| #define SMB2_SHARE_TYPE_DISK 0x01 |
| #define SMB2_FILE_READ_DATA 0x00000001 |
| #define SMB2_FILE_GENERIC_READ 0x00120089 |
| #define SMB2_FILE_GENERIC_WRITE 0x00120116 |
| #define SMB2_FILE_SHARE_READ 0x01 |
| #define SMB2_FILE_SUPERSEDE 0 |
| #define SMB2_FILE_OPEN 1 |
| #define SMB2_FILE_DIRECTORY_FILE 0x00000001 |
| #define SMB2_PREAUTH_INTEGRITY_CAPABILITIES 0x0001 |
| #define SMB2_PREAUTH_INTEGRITY_SHA512 0x0001 |
| #define SMB2_SIGNING_HMAC_SHA256 0x0000 |
| #define SMB2_GLOBAL_CAP_ENCRYPTION 0x00000040 |
NEGOTIATE request/response Capabilities flags (MS-SMB2 §2.2.3 / §2.2.4). A client that supports transport encryption MUST advertise SMB2_GLOBAL_CAP_ENCRYPTION here, or a server (e.g. Samba with smb encrypt = required) will not negotiate a cipher and will reject the unencrypted session (§3.2.4.2.2).
| #define SMB2_ENCRYPTION_AES128_CCM 0x0001 |
| #define PROTOCORE_SMB2_MAX_OFFER_CIPHERS 4 |
| #define PROTOCORE_SMB2_PREAUTH_HASH_LEN 64 |
| #define SMB2_SHAREFLAG_ENCRYPT_DATA 0x00008000 |
| #define PROTOCORE_SMB2_TRANSFORM_HDR_LEN 52 |
| #define PROTOCORE_SMB2_TRANSFORM_PROTOCOL_ID 0x424D53FDu |
| #define PROTOCORE_SMB2_NONCE_FIELD_LEN 16 |
| #define PROTOCORE_SMB2_GCM_NONCE_LEN 12 |
| #define PROTOCORE_SMB2_CCM_NONCE_LEN 11 |
| #define PROTOCORE_SMB2_MAX_CIPHER_KEY_LEN 32 |
| typedef enum PROTO_ENUM_PACKED Smb2Command |
SMB2 command codes (MS-SMB2 §2.2.1.2).
| typedef enum PROTO_ENUM_PACKED Smb2Dialect |
SMB2 dialect revision numbers (MS-SMB2 §2.2.4).
| typedef enum PROTO_ENUM_PACKED Smb2SignAlgo |
The per-session message-signing algorithm the client selects from the negotiated dialect.
| enum PROTO_ENUM_PACKED |
SMB2 command codes (MS-SMB2 §2.2.1.2).
| enum PROTO_ENUM_PACKED |
SMB2 dialect revision numbers (MS-SMB2 §2.2.4).
| enum PROTO_ENUM_PACKED |
The per-session message-signing algorithm the client selects from the negotiated dialect.
| PROTOCORE_NS_LAYOUT | ( | Smb2Ns | , |
| transport_frame | , | ||
| transport_len | , | ||
| build_header | , | ||
| parse_header | , | ||
| build_negotiate | , | ||
| parse_negotiate_response | , | ||
| build_negotiate_311 | , | ||
| parse_negotiate_contexts | , | ||
| preauth_init | , | ||
| preauth_update | , | ||
| build_session_setup | , | ||
| parse_session_setup_response | , | ||
| build_tree_connect | , | ||
| parse_tree_connect_response | , | ||
| build_create | , | ||
| parse_create_response | , | ||
| build_close | , | ||
| parse_close_response | , | ||
| build_read | , | ||
| parse_read_response | , | ||
| build_write | , | ||
| parse_write_response | , | ||
| sign | , | ||
| verify | , | ||
| sign_cmac | , | ||
| verify_cmac | , | ||
| derive_signing_key | , | ||
| derive_encryption_keys | , | ||
| encrypt | , | ||
| decrypt | |||
| ) |
| size_t protocore_smb2_transport_frame | ( | uint8_t * | work, |
| uint8_t * | out, | ||
| size_t | cap, | ||
| const uint8_t * | msg, | ||
| size_t | msg_len | ||
| ) |
Prefix an SMB2 message with the 4-byte Direct-TCP transport header .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| out | Out |
| cap | Cap |
| msg | Msg |
| msg_len | Msg len |
| uint32_t protocore_smb2_transport_len | ( | uint8_t * | work, |
| const uint8_t * | buf, | ||
| size_t | len | ||
| ) |
Read the Direct-TCP transport length prefix.
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| len | Len |
| size_t protocore_smb2_build_header | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| Smb2Command | command, | ||
| uint16_t | credit_request, | ||
| uint64_t | message_id, | ||
| uint32_t | tree_id, | ||
| uint64_t | session_id | ||
| ) |
Build a 64-byte SMB2 sync header into buf.
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| command | Command |
| credit_request | Credit request |
| message_id | Message id |
| tree_id | Tree id |
| session_id | Session id |
| proto_bool protocore_smb2_parse_header | ( | uint8_t * | work, |
| const uint8_t * | buf, | ||
| size_t | len, | ||
| Smb2Header * | out | ||
| ) |
Parse a 64-byte SMB2 sync header (validates ProtocolId + .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| len | Len |
| out | Out |
| size_t protocore_smb2_build_negotiate | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| const uint8_t * | client_guid, | ||
| uint16_t | security_mode | ||
| ) |
Build a NEGOTIATE request (header + body) offering SMB 2.0.2 / 2.1 .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| client_guid | the 16-byte client GUID 16 bytes |
| security_mode | SMB2_NEGOTIATE_SIGNING_ENABLED and/or _REQUIRED |
| proto_bool protocore_smb2_parse_negotiate_response | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2NegotiateResp * | out | ||
| ) |
Parse a NEGOTIATE response message (the SMB2 header + §2.2.4 body).
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | the SMB2 message (starting at the sync header, transport prefix already stripped) |
| len | Len |
| out | Out |
| size_t protocore_smb2_build_negotiate_311 | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| const uint8_t * | client_guid, | ||
| uint16_t | security_mode, | ||
| const uint8_t * | salt, | ||
| size_t | salt_len, | ||
| const uint16_t * | ciphers, | ||
| size_t | cipher_count | ||
| ) |
Build an SMB 3.1.1 NEGOTIATE request: the dialect list SMB 2.0.2 .. .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| client_guid | 16 bytes |
| security_mode | Security mode |
| salt | the preauth-integrity salt (a fresh random blob the client keeps for the hash chain) |
| salt_len | salt length in bytes (>= 1); a common choice is 32 |
| ciphers | cipher ids to offer, most-preferred first (a server picks the first it supports, in this |
| cipher_count | number of entries in ciphers (0 .. PROTOCORE_SMB2_MAX_OFFER_CIPHERS) |
| proto_bool protocore_smb2_parse_negotiate_contexts | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2NegotiateContexts * | out | ||
| ) |
Walk the negotiate-context list of a 3.1.1 NEGOTIATE response .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | Msg |
| len | Len |
| out | Out |
| void protocore_smb2_preauth_init | ( | uint8_t * | work, |
| SmbPreauth * | p | ||
| ) |
Seed the preauth-integrity hash with 64 zero bytes (the initial .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| p | P |
| void protocore_smb2_preauth_update | ( | uint8_t * | work, |
| uint8_t * | crypto_work, | ||
| SmbPreauth * | p, | ||
| const uint8_t * | msg, | ||
| size_t | len | ||
| ) |
Fold one handshake message into the preauth-integrity hash: hash = .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| crypto_work | Crypto work |
| p | P |
| msg | Msg |
| len | Len |
| size_t protocore_smb2_build_session_setup | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| uint64_t | message_id, | ||
| uint64_t | session_id, | ||
| uint8_t | security_mode, | ||
| const uint8_t * | sec_buf, | ||
| size_t | sec_len | ||
| ) |
Build a SESSION_SETUP request (header + §2.2.5 body) carrying a .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| message_id | the SMB2 MessageId (increments across the exchange) |
| session_id | 0 on the first round; the server-assigned SessionId on the second |
| security_mode | SMB2_NEGOTIATE_SIGNING_ENABLED and/or _REQUIRED (one byte on the wire) |
| sec_buf | Sec buf |
| sec_len | Sec len |
| proto_bool protocore_smb2_parse_session_setup_response | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2SessionSetupResp * | out | ||
| ) |
Parse a SESSION_SETUP response message (the SMB2 header + §2.2.6 .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | the SMB2 message (starting at the sync header, transport prefix already stripped) |
| len | Len |
| out | Out |
| size_t protocore_smb2_build_tree_connect | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| uint64_t | message_id, | ||
| uint64_t | session_id, | ||
| const uint8_t * | path_utf16, | ||
| size_t | path_len | ||
| ) |
Build a TREE_CONNECT request (header + §2.2.9 body) for a share path.
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| message_id | Message id |
| session_id | Session id |
| path_utf16 | the UNC path \\server\share in UTF-16LE (no NUL); path_len its byte length |
| path_len | Path len |
| proto_bool protocore_smb2_parse_tree_connect_response | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2TreeConnectResp * | out | ||
| ) |
Parse a TREE_CONNECT response message (validates command + .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | Msg |
| len | Len |
| out | Out |
| size_t protocore_smb2_build_create | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| uint64_t | message_id, | ||
| uint64_t | session_id, | ||
| uint32_t | tree_id, | ||
| uint32_t | desired_access, | ||
| uint32_t | share_access, | ||
| uint32_t | create_disposition, | ||
| uint32_t | create_options, | ||
| const uint8_t * | name_utf16, | ||
| size_t | name_len | ||
| ) |
Build a CREATE request (header + §2.2.13 body) to open/create a .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| message_id | Message id |
| session_id | Session id |
| tree_id | Tree id |
| desired_access | e.g. SMB2_FILE_GENERIC_READ / _WRITE |
| share_access | SMB2_FILE_SHARE_* bitmask |
| create_disposition | SMB2_FILE_OPEN / _CREATE / _OPEN_IF / |
| create_options | SMB2_FILE_NON_DIRECTORY_FILE for a regular file |
| name_utf16 | the file name relative to the share root in UTF-16LE (no leading backslash, no NUL); |
| name_len | Name len |
| proto_bool protocore_smb2_parse_create_response | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2CreateResp * | out | ||
| ) |
Parse a CREATE response message (validates command + StructureSize .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | Msg |
| len | Len |
| out | Out |
| size_t protocore_smb2_build_close | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| uint64_t | message_id, | ||
| uint64_t | session_id, | ||
| uint32_t | tree_id, | ||
| const uint8_t * | file_id | ||
| ) |
Build a CLOSE request (header + §2.2.15 body) for an open FileId.
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| message_id | Message id |
| session_id | Session id |
| tree_id | Tree id |
| file_id | 16 bytes |
| proto_bool protocore_smb2_parse_close_response | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2CloseResp * | out | ||
| ) |
Parse a CLOSE response message (validates command + StructureSize .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | Msg |
| len | Len |
| out | Out |
| size_t protocore_smb2_build_read | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| uint64_t | message_id, | ||
| uint64_t | session_id, | ||
| uint32_t | tree_id, | ||
| const uint8_t * | file_id, | ||
| uint32_t | length, | ||
| uint64_t | offset | ||
| ) |
Build a READ request (header + §2.2.19 body) for length bytes at .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| message_id | Message id |
| session_id | Session id |
| tree_id | Tree id |
| file_id | 16 bytes |
| length | Length |
| offset | Offset |
| proto_bool protocore_smb2_parse_read_response | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2ReadResp * | out | ||
| ) |
Parse a READ response message (validates command + StructureSize .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | Msg |
| len | Len |
| out | Out |
| size_t protocore_smb2_build_write | ( | uint8_t * | work, |
| uint8_t * | buf, | ||
| size_t | cap, | ||
| uint64_t | message_id, | ||
| uint64_t | session_id, | ||
| uint32_t | tree_id, | ||
| const uint8_t * | file_id, | ||
| const uint8_t * | data, | ||
| size_t | data_len, | ||
| uint64_t | offset | ||
| ) |
Build a WRITE request (header + §2.2.21 body) writing data at .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| buf | Buf |
| cap | Cap |
| message_id | Message id |
| session_id | Session id |
| tree_id | Tree id |
| file_id | 16 bytes |
| data | Data |
| data_len | Data len |
| offset | Offset |
| proto_bool protocore_smb2_parse_write_response | ( | uint8_t * | work, |
| const uint8_t * | msg, | ||
| size_t | len, | ||
| Smb2WriteResp * | out | ||
| ) |
Parse a WRITE response message (validates command + StructureSize .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| msg | Msg |
| len | Len |
| out | Out |
| void protocore_smb2_sign | ( | uint8_t * | work, |
| uint8_t * | crypto_work, | ||
| const uint8_t * | key, | ||
| uint8_t * | msg, | ||
| size_t | msg_len | ||
| ) |
Sign an SMB2 message in place (MS-SMB2 §3.1.4.1, SMB 2.x). Sets .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| crypto_work | Crypto work |
| key | the session signing key (16 octets; the NTLMv2 session key for SMB 2.x) 16 bytes |
| msg | the full message (header + body), modified in place; must be at least a 64-byte header |
| msg_len | total message length. A message shorter than the header is left untouched |
| proto_bool protocore_smb2_verify | ( | uint8_t * | work, |
| uint8_t * | crypto_work, | ||
| const uint8_t * | key, | ||
| uint8_t * | msg, | ||
| size_t | msg_len | ||
| ) |
Verify an SMB2 message's signature (MS-SMB2 §3.1.5.1). Recomputes .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| crypto_work | Crypto work |
| key | 16 bytes |
| msg | Msg |
| msg_len | Msg len |
| void protocore_smb2_sign_cmac | ( | uint8_t * | work, |
| uint8_t * | crypto_work, | ||
| const uint8_t * | key, | ||
| uint8_t * | msg, | ||
| size_t | msg_len | ||
| ) |
Sign an SMB2 message in place with AES-128-CMAC (MS-SMB2 §3.1.4.1, .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| crypto_work | Crypto work |
| key | 16 bytes |
| msg | Msg |
| msg_len | Msg len |
| proto_bool protocore_smb2_verify_cmac | ( | uint8_t * | work, |
| uint8_t * | crypto_work, | ||
| const uint8_t * | key, | ||
| uint8_t * | msg, | ||
| size_t | msg_len | ||
| ) |
Verify an AES-128-CMAC-signed SMB2 message (MS-SMB2 §3.1.5.1, SMB .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| crypto_work | Crypto work |
| key | 16 bytes |
| msg | Msg |
| msg_len | Msg len |
| proto_bool protocore_smb2_derive_signing_key | ( | uint8_t * | work, |
| const uint8_t * | session_key, | ||
| uint16_t | dialect, | ||
| const uint8_t * | preauth, | ||
| uint8_t * | out_key | ||
| ) |
Derive the 16-byte SMB 3.x signing key from the NTLM session key .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| session_key | the 16-byte NTLM ExportedSessionKey (SessionBaseKey for NTLMv2 with no key exch) 16 bytes |
| dialect | the negotiated DialectRevision (only 3.1.1 vs pre-3.1.1 matters here) |
| preauth | the 64-byte final preauth-integrity hash; required iff dialect == 3.1.1, else ignored |
| out_key | receives the 16-byte signing key 16 bytes |
| proto_bool protocore_smb2_derive_encryption_keys | ( | uint8_t * | work, |
| const uint8_t * | session_key, | ||
| uint16_t | dialect, | ||
| const uint8_t * | preauth, | ||
| size_t | key_len, | ||
| uint8_t * | out_c2s, | ||
| uint8_t * | out_s2c | ||
| ) |
Derive the two SMB 3.x cipher keys from the NTLM session key .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| session_key | 16 bytes |
| dialect | Dialect |
| preauth | Preauth |
| key_len | Key len |
| out_c2s | client->server key (ENCRYPTS our requests); out_s2c server->client key (DECRYPTS |
| out_s2c | Out s2c |
| size_t protocore_smb2_encrypt | ( | uint8_t * | work, |
| uint16_t | cipher, | ||
| const uint8_t * | key, | ||
| const uint8_t * | nonce, | ||
| uint64_t | session_id, | ||
| const uint8_t * | msg, | ||
| size_t | msg_len, | ||
| uint8_t * | out, | ||
| size_t | out_cap | ||
| ) |
Encrypt one SMB2 message into a TRANSFORM_HEADER-wrapped blob .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| cipher | one of Smb2Cipher; selects the key length and AEAD nonce length |
| key | cipher key (protocore_smb2_cipher_key_len(cipher) bytes, i.e. the C2S key) |
| nonce | the 16-byte Nonce field; the leading nonce-length bytes must be UNIQUE per key (caller |
| session_id | echoed into the header; out needs >= PROTOCORE_SMB2_TRANSFORM_HDR_LEN + msg_len |
| msg | Msg |
| msg_len | Msg len |
| out | Out |
| out_cap | Out cap |
| size_t protocore_smb2_decrypt | ( | uint8_t * | work, |
| uint16_t | cipher, | ||
| const uint8_t * | key, | ||
| const uint8_t * | in, | ||
| size_t | in_len, | ||
| uint8_t * | out, | ||
| size_t | out_cap | ||
| ) |
Decrypt a TRANSFORM_HEADER-wrapped SMB2 message (MS-SMB2 §3.1.4.4): .
| work | PROTOCORE_SMB2_BORROW bytes the caller took. Not held past the call. |
| cipher | one of Smb2Cipher; key the S2C cipher key; out needs >= OriginalMessageSize |
| key | Key |
| in | In |
| in_len | In len |
| out | Out |
| out_cap | Out cap |
| PROTOCORE_NS Smb2Ns Smb2 PROTOCORE_UNUSED |