| | | 1 | | // Licensed to the .NET Foundation under one or more agreements. |
| | | 2 | | // The .NET Foundation licenses this file to you under the MIT license. |
| | | 3 | | |
| | | 4 | | using System.Buffers.Binary; |
| | | 5 | | using System.Collections.Generic; |
| | | 6 | | using System.Globalization; |
| | | 7 | | using System.Text; |
| | | 8 | | |
| | | 9 | | namespace System.Net.Security |
| | | 10 | | { |
| | | 11 | | /// <summary> |
| | | 12 | | /// Decodes the KERB_VALIDATION_INFO structure carried in the "urn:mspac:logon-info" buffer |
| | | 13 | | /// of a Kerberos Privilege Attribute Certificate (PAC). |
| | | 14 | | /// </summary> |
| | | 15 | | /// <remarks> |
| | | 16 | | /// The structure is serialized using NDR type serialization version 1 as described in |
| | | 17 | | /// [MS-RPCE] 2.2.6, wrapping the KERB_VALIDATION_INFO defined in [MS-PAC] 2.5. |
| | | 18 | | /// |
| | | 19 | | /// Only the fields needed to describe the peer identity are retained. The remaining fields |
| | | 20 | | /// are still parsed, because NDR is a positional format and skipping a field would desync |
| | | 21 | | /// the reader from the stream. |
| | | 22 | | /// |
| | | 23 | | /// Every read is bounds checked and any malformed input results in a null result rather |
| | | 24 | | /// than an exception. |
| | | 25 | | /// </remarks> |
| | | 26 | | internal sealed class KerberosPacLogonInfo |
| | | 27 | | { |
| | | 28 | | // A PAC describing a user with more groups than this is treated as malformed. The value |
| | | 29 | | // is far above what Active Directory can issue, since the resulting ticket would exceed |
| | | 30 | | // the maximum Kerberos token size long before this limit is reached. |
| | | 31 | | private const int MaxGroupCount = 8192; |
| | | 32 | | private const byte MaxSidSubAuthorityCount = 15; |
| | | 33 | | private const uint GroupEnabled = 0x00000004; |
| | | 34 | | private const uint GroupUseForDenyOnly = 0x00000010; |
| | | 35 | | private const uint GroupLogonId = 0xC0000000; |
| | | 36 | | |
| | | 37 | | private const byte NdrLittleEndian = 0x10; |
| | | 38 | | private const byte NdrVersion = 1; |
| | | 39 | | private const int NdrCommonHeaderLength = 8; |
| | | 40 | | |
| | 213 | 41 | | public string? EffectiveName { get; private set; } |
| | 213 | 42 | | public string? LogonDomainName { get; private set; } |
| | 88 | 43 | | public string? UserSid { get; private set; } |
| | 72 | 44 | | public string? PrimaryGroupSid { get; private set; } |
| | 834 | 45 | | public List<string> GroupSids { get; } = new List<string>(); |
| | | 46 | | |
| | | 47 | | /// <summary> |
| | | 48 | | /// Decodes the logon information, returning null if <paramref name="buffer"/> is not a |
| | | 49 | | /// well formed KERB_VALIDATION_INFO. |
| | | 50 | | /// </summary> |
| | | 51 | | public static KerberosPacLogonInfo? Decode(ReadOnlySpan<byte> buffer) |
| | 700 | 52 | | { |
| | 700 | 53 | | NdrReader reader = new NdrReader(buffer); |
| | | 54 | | |
| | 700 | 55 | | if (!TryReadTypeSerializationHeader(ref reader)) |
| | 13 | 56 | | { |
| | 13 | 57 | | return null; |
| | | 58 | | } |
| | | 59 | | |
| | | 60 | | // The root of the serialized type is a unique pointer. A null root carries no |
| | | 61 | | // information and is treated as malformed. |
| | 687 | 62 | | if (!reader.TryReadUInt32(out uint rootReferent) || rootReferent == 0) |
| | 4 | 63 | | { |
| | 4 | 64 | | return null; |
| | | 65 | | } |
| | | 66 | | |
| | 683 | 67 | | KerberosPacLogonInfo logonInfo = new KerberosPacLogonInfo(); |
| | 683 | 68 | | return logonInfo.TryReadValidationInfo(ref reader) ? logonInfo : null; |
| | 700 | 69 | | } |
| | | 70 | | |
| | | 71 | | private static bool TryReadTypeSerializationHeader(ref NdrReader reader) |
| | 700 | 72 | | { |
| | | 73 | | // Common type header, [MS-RPCE] 2.2.6.1. |
| | 700 | 74 | | if (!reader.TryReadByte(out byte version) || version != NdrVersion || |
| | 700 | 75 | | !reader.TryReadByte(out byte endianness) || |
| | 700 | 76 | | !reader.TryReadUInt16(out ushort commonHeaderLength) || commonHeaderLength != NdrCommonHeaderLength || |
| | 700 | 77 | | !reader.TrySkip(4)) |
| | 6 | 78 | | { |
| | 6 | 79 | | return false; |
| | | 80 | | } |
| | | 81 | | |
| | | 82 | | // Only little-endian integers with an ASCII character set are produced in practice, |
| | | 83 | | // and byte swapping for the alternative has no way of being tested. |
| | 694 | 84 | | if ((endianness & 0xF0) != NdrLittleEndian) |
| | 2 | 85 | | { |
| | 2 | 86 | | return false; |
| | | 87 | | } |
| | | 88 | | |
| | | 89 | | // Private header, [MS-RPCE] 2.2.6.2. The declared length is not trusted for bounds |
| | | 90 | | // checking; the reader validates every access against the real buffer instead. |
| | 692 | 91 | | return reader.TryReadUInt32(out _) && reader.TrySkip(4); |
| | 700 | 92 | | } |
| | | 93 | | |
| | | 94 | | private bool TryReadValidationInfo(ref NdrReader reader) |
| | 683 | 95 | | { |
| | | 96 | | // Fixed part of KERB_VALIDATION_INFO, [MS-PAC] 2.5. Pointer fields carry only a |
| | | 97 | | // referent id here; the data they point at is deferred to after the fixed part and |
| | | 98 | | // appears in field order. |
| | 683 | 99 | | if (!reader.TrySkip(6 * 8)) // LogonTime .. PasswordMustChange |
| | 3 | 100 | | { |
| | 3 | 101 | | return false; |
| | | 102 | | } |
| | | 103 | | |
| | 680 | 104 | | Span<uint> nameReferents = stackalloc uint[6]; |
| | 9278 | 105 | | for (int i = 0; i < nameReferents.Length; i++) |
| | 3988 | 106 | | { |
| | | 107 | | // EffectiveName, FullName, LogonScript, ProfilePath, HomeDirectory, HomeDirectoryDrive |
| | 3988 | 108 | | if (!TryReadUnicodeStringHeader(ref reader, out nameReferents[i])) |
| | 29 | 109 | | { |
| | 29 | 110 | | return false; |
| | | 111 | | } |
| | 3959 | 112 | | } |
| | | 113 | | |
| | 651 | 114 | | if (!reader.TryReadUInt16(out _) || // LogonCount |
| | 651 | 115 | | !reader.TryReadUInt16(out _) || // BadPasswordCount |
| | 651 | 116 | | !reader.TryReadUInt32(out uint userId) || |
| | 651 | 117 | | !reader.TryReadUInt32(out uint primaryGroupId) || |
| | 651 | 118 | | !reader.TryReadUInt32(out uint groupCount) || |
| | 651 | 119 | | !reader.TryReadUInt32(out uint groupIdsReferent) || |
| | 651 | 120 | | !reader.TryReadUInt32(out _) || // UserFlags |
| | 651 | 121 | | !reader.TrySkip(16)) // UserSessionKey |
| | 19 | 122 | | { |
| | 19 | 123 | | return false; |
| | | 124 | | } |
| | | 125 | | |
| | 632 | 126 | | if (!TryReadUnicodeStringHeader(ref reader, out uint logonServerReferent) || |
| | 632 | 127 | | !TryReadUnicodeStringHeader(ref reader, out uint logonDomainNameReferent) || |
| | 632 | 128 | | !reader.TryReadUInt32(out uint logonDomainIdReferent) || |
| | 632 | 129 | | !reader.TrySkip(8) || // Reserved1[2] |
| | 632 | 130 | | !reader.TryReadUInt32(out _) || // UserAccountControl |
| | 632 | 131 | | !reader.TryReadUInt32(out _) || // SubAuthStatus |
| | 632 | 132 | | !reader.TrySkip(8) || // LastSuccessfulILogon |
| | 632 | 133 | | !reader.TrySkip(8) || // LastFailedILogon |
| | 632 | 134 | | !reader.TryReadUInt32(out _) || // FailedILogonCount |
| | 632 | 135 | | !reader.TryReadUInt32(out _) || // Reserved3 |
| | 632 | 136 | | !reader.TryReadUInt32(out uint sidCount) || |
| | 632 | 137 | | !reader.TryReadUInt32(out uint extraSidsReferent) || |
| | 632 | 138 | | !reader.TryReadUInt32(out uint resourceDomainIdReferent) || |
| | 632 | 139 | | !reader.TryReadUInt32(out uint resourceGroupCount) || |
| | 632 | 140 | | !reader.TryReadUInt32(out uint resourceGroupIdsReferent)) |
| | 39 | 141 | | { |
| | 39 | 142 | | return false; |
| | | 143 | | } |
| | | 144 | | |
| | | 145 | | // Deferred pointer data, in the order the pointers appear above. |
| | 593 | 146 | | string?[] names = new string?[nameReferents.Length]; |
| | 7866 | 147 | | for (int i = 0; i < nameReferents.Length; i++) |
| | 3397 | 148 | | { |
| | 3397 | 149 | | if (!TryReadUnicodeStringData(ref reader, nameReferents[i], out names[i])) |
| | 57 | 150 | | { |
| | 57 | 151 | | return false; |
| | | 152 | | } |
| | 3340 | 153 | | } |
| | | 154 | | |
| | 536 | 155 | | if (!TryReadGroupMemberships(ref reader, groupIdsReferent, groupCount, out GroupMembership[]? groups) || |
| | 536 | 156 | | !TryReadUnicodeStringData(ref reader, logonServerReferent, out _) || |
| | 536 | 157 | | !TryReadUnicodeStringData(ref reader, logonDomainNameReferent, out string? logonDomainName) || |
| | 536 | 158 | | !TryReadSid(ref reader, logonDomainIdReferent, MaxSidSubAuthorityCount - 1, out string? logonDomainSid) |
| | 536 | 159 | | !TryReadExtraSids(ref reader, extraSidsReferent, sidCount, out SidAndAttributes[]? extraSids) || |
| | 536 | 160 | | !TryReadSid(ref reader, resourceDomainIdReferent, MaxSidSubAuthorityCount - 1, out string? resourceDomai |
| | 536 | 161 | | !TryReadGroupMemberships(ref reader, resourceGroupIdsReferent, resourceGroupCount, out GroupMembership[] |
| | 323 | 162 | | { |
| | 323 | 163 | | return false; |
| | | 164 | | } |
| | | 165 | | |
| | 213 | 166 | | EffectiveName = names[0]; |
| | 213 | 167 | | LogonDomainName = logonDomainName; |
| | | 168 | | |
| | | 169 | | // Group membership in the logon domain is expressed as relative identifiers that are |
| | | 170 | | // only meaningful when combined with the domain SID. Without it there is nothing to |
| | | 171 | | // report, but the PAC is still well formed. |
| | 213 | 172 | | if (logonDomainSid is not null) |
| | 107 | 173 | | { |
| | 107 | 174 | | if (userId != 0) |
| | 88 | 175 | | { |
| | 88 | 176 | | UserSid = FormatRid(logonDomainSid, userId); |
| | 88 | 177 | | } |
| | | 178 | | |
| | 107 | 179 | | if (groups is not null) |
| | 95 | 180 | | { |
| | 941 | 181 | | foreach (GroupMembership group in groups) |
| | 328 | 182 | | { |
| | 328 | 183 | | if (IsEnabledGroup(group.Attributes)) |
| | 151 | 184 | | { |
| | 151 | 185 | | string groupSid = FormatRid(logonDomainSid, group.RelativeId); |
| | 151 | 186 | | GroupSids.Add(groupSid); |
| | | 187 | | |
| | 151 | 188 | | if (group.RelativeId == primaryGroupId) |
| | 72 | 189 | | { |
| | 72 | 190 | | PrimaryGroupSid = groupSid; |
| | 72 | 191 | | } |
| | 151 | 192 | | } |
| | 328 | 193 | | } |
| | 95 | 194 | | } |
| | 107 | 195 | | } |
| | | 196 | | |
| | 213 | 197 | | if (extraSids is not null) |
| | 57 | 198 | | { |
| | 57 | 199 | | int firstGroupIndex = 0; |
| | 57 | 200 | | if (userId == 0) |
| | 28 | 201 | | { |
| | 28 | 202 | | if (extraSids.Length == 0 || extraSids[0].Sid is null) |
| | 28 | 203 | | { |
| | 28 | 204 | | return false; |
| | | 205 | | } |
| | | 206 | | |
| | 0 | 207 | | UserSid = extraSids[0].Sid; |
| | 0 | 208 | | firstGroupIndex = 1; |
| | 0 | 209 | | } |
| | | 210 | | |
| | 92 | 211 | | for (int i = firstGroupIndex; i < extraSids.Length; i++) |
| | 17 | 212 | | { |
| | 17 | 213 | | if (extraSids[i].Sid is string sid && IsEnabledGroup(extraSids[i].Attributes)) |
| | 0 | 214 | | { |
| | 0 | 215 | | GroupSids.Add(sid); |
| | 0 | 216 | | } |
| | 17 | 217 | | } |
| | 29 | 218 | | } |
| | 156 | 219 | | else if (userId == 0) |
| | 33 | 220 | | { |
| | 33 | 221 | | return false; |
| | | 222 | | } |
| | | 223 | | |
| | 152 | 224 | | if (resourceDomainSid is not null && resourceGroups is not null) |
| | 14 | 225 | | { |
| | 42 | 226 | | foreach (GroupMembership group in resourceGroups) |
| | 0 | 227 | | { |
| | 0 | 228 | | if (IsEnabledGroup(group.Attributes)) |
| | 0 | 229 | | { |
| | 0 | 230 | | GroupSids.Add(FormatRid(resourceDomainSid, group.RelativeId)); |
| | 0 | 231 | | } |
| | 0 | 232 | | } |
| | 14 | 233 | | } |
| | | 234 | | |
| | 152 | 235 | | return true; |
| | 683 | 236 | | } |
| | | 237 | | |
| | | 238 | | private static string FormatRid(string domainSid, uint relativeId) => |
| | 239 | 239 | | string.Create(CultureInfo.InvariantCulture, $"{domainSid}-{relativeId}"); |
| | | 240 | | |
| | | 241 | | private static bool IsEnabledGroup(uint attributes) |
| | 328 | 242 | | { |
| | | 243 | | const uint RelevantAttributes = GroupEnabled | GroupUseForDenyOnly | GroupLogonId; |
| | 328 | 244 | | return (attributes & RelevantAttributes) == GroupEnabled; |
| | 328 | 245 | | } |
| | | 246 | | |
| | | 247 | | private static bool TryReadUnicodeStringHeader(ref NdrReader reader, out uint referent) |
| | 5247 | 248 | | { |
| | | 249 | | // RPC_UNICODE_STRING: the lengths are byte counts and are redundant with the counts |
| | | 250 | | // carried by the deferred conformant varying array, so only the referent is kept. |
| | 5247 | 251 | | referent = 0; |
| | 5247 | 252 | | return reader.TryReadUInt16(out _) && |
| | 5247 | 253 | | reader.TryReadUInt16(out _) && |
| | 5247 | 254 | | reader.TryReadUInt32(out referent); |
| | 5247 | 255 | | } |
| | | 256 | | |
| | | 257 | | private static bool TryReadUnicodeStringData(ref NdrReader reader, uint referent, out string? value) |
| | 4345 | 258 | | { |
| | 4345 | 259 | | value = null; |
| | 4345 | 260 | | if (referent == 0) |
| | 3793 | 261 | | { |
| | 3793 | 262 | | return true; |
| | | 263 | | } |
| | | 264 | | |
| | | 265 | | // Conformant varying array of wchar. |
| | 552 | 266 | | if (!reader.TryReadUInt32(out uint maxCount) || |
| | 552 | 267 | | !reader.TryReadUInt32(out uint offset) || |
| | 552 | 268 | | !reader.TryReadUInt32(out uint actualCount) || |
| | 552 | 269 | | offset != 0 || |
| | 552 | 270 | | actualCount > maxCount) |
| | 67 | 271 | | { |
| | 67 | 272 | | return false; |
| | | 273 | | } |
| | | 274 | | |
| | 485 | 275 | | if (actualCount > int.MaxValue / 2 || |
| | 485 | 276 | | !reader.TryReadBytes((int)actualCount * 2, out ReadOnlySpan<byte> chars)) |
| | 7 | 277 | | { |
| | 7 | 278 | | return false; |
| | | 279 | | } |
| | | 280 | | |
| | | 281 | | // Some producers include the terminating null in the character count. |
| | 478 | 282 | | value = Encoding.Unicode.GetString(chars).TrimEnd('\0'); |
| | 478 | 283 | | return true; |
| | 4345 | 284 | | } |
| | | 285 | | |
| | | 286 | | private static bool TryReadGroupMemberships(ref NdrReader reader, uint referent, uint count, out GroupMembership |
| | 774 | 287 | | { |
| | 774 | 288 | | groups = null; |
| | 774 | 289 | | if (referent == 0) |
| | 431 | 290 | | { |
| | 431 | 291 | | return count == 0; |
| | | 292 | | } |
| | | 293 | | |
| | | 294 | | // Conformant array of GROUP_MEMBERSHIP. |
| | 343 | 295 | | if (!reader.TryReadUInt32(out uint maxCount) || maxCount != count || count > MaxGroupCount) |
| | 12 | 296 | | { |
| | 12 | 297 | | return false; |
| | | 298 | | } |
| | | 299 | | |
| | 331 | 300 | | GroupMembership[] result = new GroupMembership[count]; |
| | 4086 | 301 | | for (int i = 0; i < result.Length; i++) |
| | 1756 | 302 | | { |
| | 1756 | 303 | | if (!reader.TryReadUInt32(out uint relativeId) || |
| | 1756 | 304 | | !reader.TryReadUInt32(out uint attributes)) |
| | 44 | 305 | | { |
| | 44 | 306 | | return false; |
| | | 307 | | } |
| | | 308 | | |
| | 1712 | 309 | | result[i] = new GroupMembership(relativeId, attributes); |
| | 1712 | 310 | | } |
| | | 311 | | |
| | 287 | 312 | | groups = result; |
| | 287 | 313 | | return true; |
| | 774 | 314 | | } |
| | | 315 | | |
| | | 316 | | private static bool TryReadExtraSids(ref NdrReader reader, uint referent, uint count, out SidAndAttributes[]? si |
| | 427 | 317 | | { |
| | 427 | 318 | | sids = null; |
| | 427 | 319 | | if (referent == 0) |
| | 218 | 320 | | { |
| | 218 | 321 | | return count == 0; |
| | | 322 | | } |
| | | 323 | | |
| | | 324 | | // Conformant array of KERB_SID_AND_ATTRIBUTES. The SID pointers within the array are |
| | | 325 | | // themselves deferred, so the array is read in two passes. |
| | 209 | 326 | | if (!reader.TryReadUInt32(out uint maxCount) || maxCount != count || count > MaxGroupCount) |
| | 8 | 327 | | { |
| | 8 | 328 | | return false; |
| | | 329 | | } |
| | | 330 | | |
| | 201 | 331 | | uint[] referents = new uint[count]; |
| | 201 | 332 | | uint[] attributes = new uint[count]; |
| | 5072 | 333 | | for (int i = 0; i < referents.Length; i++) |
| | 2398 | 334 | | { |
| | 2398 | 335 | | if (!reader.TryReadUInt32(out referents[i]) || |
| | 2398 | 336 | | !reader.TryReadUInt32(out attributes[i])) |
| | 63 | 337 | | { |
| | 63 | 338 | | return false; |
| | | 339 | | } |
| | 2335 | 340 | | } |
| | | 341 | | |
| | 138 | 342 | | SidAndAttributes[] result = new SidAndAttributes[count]; |
| | 610 | 343 | | for (int i = 0; i < referents.Length; i++) |
| | 215 | 344 | | { |
| | 215 | 345 | | if (!TryReadSid(ref reader, referents[i], MaxSidSubAuthorityCount, out string? sid)) |
| | 48 | 346 | | { |
| | 48 | 347 | | return false; |
| | | 348 | | } |
| | | 349 | | |
| | 167 | 350 | | result[i] = new SidAndAttributes(sid, attributes[i]); |
| | 167 | 351 | | } |
| | | 352 | | |
| | 90 | 353 | | sids = result; |
| | 90 | 354 | | return true; |
| | 427 | 355 | | } |
| | | 356 | | |
| | | 357 | | private static bool TryReadSid(ref NdrReader reader, uint referent, int maxSubAuthorityCount, out string? sid) |
| | 984 | 358 | | { |
| | 984 | 359 | | sid = null; |
| | 984 | 360 | | if (referent == 0) |
| | 632 | 361 | | { |
| | 632 | 362 | | return true; |
| | | 363 | | } |
| | | 364 | | |
| | | 365 | | // RPC_SID is a conformant structure whose maximum count carries the sub authority |
| | | 366 | | // count, duplicating the field inside the structure. Both must agree. |
| | 352 | 367 | | if (!reader.TryReadUInt32(out uint maxCount) || |
| | 352 | 368 | | !reader.TryReadByte(out byte revision) || |
| | 352 | 369 | | !reader.TryReadByte(out byte subAuthorityCount) || |
| | 352 | 370 | | !reader.TryReadBytes(6, out ReadOnlySpan<byte> identifierAuthority) || |
| | 352 | 371 | | revision != 1 || |
| | 352 | 372 | | subAuthorityCount > maxSubAuthorityCount || |
| | 352 | 373 | | maxCount != subAuthorityCount) |
| | 144 | 374 | | { |
| | 144 | 375 | | return false; |
| | | 376 | | } |
| | | 377 | | |
| | 208 | 378 | | ulong authority = 0; |
| | 3120 | 379 | | foreach (byte b in identifierAuthority) |
| | 1248 | 380 | | { |
| | 1248 | 381 | | authority = (authority << 8) | b; |
| | 1248 | 382 | | } |
| | | 383 | | |
| | 208 | 384 | | StringBuilder builder = new StringBuilder(); |
| | 208 | 385 | | builder.Append("S-").Append(revision).Append('-') |
| | 208 | 386 | | .Append(authority.ToString(CultureInfo.InvariantCulture)); |
| | | 387 | | |
| | 712 | 388 | | for (int i = 0; i < subAuthorityCount; i++) |
| | 156 | 389 | | { |
| | 156 | 390 | | if (!reader.TryReadUInt32(out uint subAuthority)) |
| | 8 | 391 | | { |
| | 8 | 392 | | return false; |
| | | 393 | | } |
| | | 394 | | |
| | 148 | 395 | | builder.Append('-').Append(subAuthority.ToString(CultureInfo.InvariantCulture)); |
| | 148 | 396 | | } |
| | | 397 | | |
| | 200 | 398 | | sid = builder.ToString(); |
| | 200 | 399 | | return true; |
| | 984 | 400 | | } |
| | | 401 | | |
| | | 402 | | private readonly struct SidAndAttributes |
| | | 403 | | { |
| | | 404 | | public SidAndAttributes(string? sid, uint attributes) |
| | 167 | 405 | | { |
| | 167 | 406 | | Sid = sid; |
| | 167 | 407 | | Attributes = attributes; |
| | 167 | 408 | | } |
| | | 409 | | |
| | 38 | 410 | | public string? Sid { get; } |
| | 0 | 411 | | public uint Attributes { get; } |
| | | 412 | | } |
| | | 413 | | |
| | | 414 | | private readonly struct GroupMembership |
| | | 415 | | { |
| | | 416 | | public GroupMembership(uint relativeId, uint attributes) |
| | 1712 | 417 | | { |
| | 1712 | 418 | | RelativeId = relativeId; |
| | 1712 | 419 | | Attributes = attributes; |
| | 1712 | 420 | | } |
| | | 421 | | |
| | 302 | 422 | | public uint RelativeId { get; } |
| | 328 | 423 | | public uint Attributes { get; } |
| | | 424 | | } |
| | | 425 | | |
| | | 426 | | /// <summary> |
| | | 427 | | /// A forward-only reader over an NDR octet stream that fails rather than throwing when |
| | | 428 | | /// the stream is truncated. |
| | | 429 | | /// </summary> |
| | | 430 | | private ref struct NdrReader |
| | | 431 | | { |
| | | 432 | | private readonly ReadOnlySpan<byte> _buffer; |
| | | 433 | | private int _position; |
| | | 434 | | |
| | | 435 | | public NdrReader(ReadOnlySpan<byte> buffer) |
| | 700 | 436 | | { |
| | 700 | 437 | | _buffer = buffer; |
| | 700 | 438 | | _position = 0; |
| | 700 | 439 | | } |
| | | 440 | | |
| | | 441 | | // NDR aligns each primitive to its own size relative to the start of the octet |
| | | 442 | | // stream. The type serialization headers that precede the data are 16 bytes, a |
| | | 443 | | // multiple of the largest alignment used here, so offsets within this buffer and |
| | | 444 | | // offsets within the NDR stream agree. |
| | | 445 | | private bool TryAlign(int alignment) |
| | 39227 | 446 | | { |
| | 39227 | 447 | | int padding = (alignment - (_position % alignment)) % alignment; |
| | 39227 | 448 | | return TrySkip(padding); |
| | 39227 | 449 | | } |
| | | 450 | | |
| | | 451 | | public bool TrySkip(int count) |
| | 43773 | 452 | | { |
| | 43773 | 453 | | if (count < 0 || _buffer.Length - _position < count) |
| | 17 | 454 | | { |
| | 17 | 455 | | return false; |
| | | 456 | | } |
| | | 457 | | |
| | 43756 | 458 | | _position += count; |
| | 43756 | 459 | | return true; |
| | 43773 | 460 | | } |
| | | 461 | | |
| | | 462 | | public bool TryReadByte(out byte value) |
| | 2032 | 463 | | { |
| | 2032 | 464 | | if (_position >= _buffer.Length) |
| | 10 | 465 | | { |
| | 10 | 466 | | value = 0; |
| | 10 | 467 | | return false; |
| | | 468 | | } |
| | | 469 | | |
| | 2022 | 470 | | value = _buffer[_position++]; |
| | 2022 | 471 | | return true; |
| | 2032 | 472 | | } |
| | | 473 | | |
| | | 474 | | public bool TryReadUInt16(out ushort value) |
| | 12477 | 475 | | { |
| | 12477 | 476 | | value = 0; |
| | 12477 | 477 | | if (!TryAlign(sizeof(ushort)) || !TryReadBytes(sizeof(ushort), out ReadOnlySpan<byte> bytes)) |
| | 33 | 478 | | { |
| | 33 | 479 | | return false; |
| | | 480 | | } |
| | | 481 | | |
| | 12444 | 482 | | value = BinaryPrimitives.ReadUInt16LittleEndian(bytes); |
| | 12444 | 483 | | return true; |
| | 12477 | 484 | | } |
| | | 485 | | |
| | | 486 | | public bool TryReadUInt32(out uint value) |
| | 26750 | 487 | | { |
| | 26750 | 488 | | value = 0; |
| | 26750 | 489 | | if (!TryAlign(sizeof(uint)) || !TryReadBytes(sizeof(uint), out ReadOnlySpan<byte> bytes)) |
| | 260 | 490 | | { |
| | 260 | 491 | | return false; |
| | | 492 | | } |
| | | 493 | | |
| | 26490 | 494 | | value = BinaryPrimitives.ReadUInt32LittleEndian(bytes); |
| | 26490 | 495 | | return true; |
| | 26750 | 496 | | } |
| | | 497 | | |
| | | 498 | | public bool TryReadBytes(int count, out ReadOnlySpan<byte> value) |
| | 40015 | 499 | | { |
| | 40015 | 500 | | if (count < 0 || _buffer.Length - _position < count) |
| | 318 | 501 | | { |
| | 318 | 502 | | value = default; |
| | 318 | 503 | | return false; |
| | | 504 | | } |
| | | 505 | | |
| | 39697 | 506 | | value = _buffer.Slice(_position, count); |
| | 39697 | 507 | | _position += count; |
| | 39697 | 508 | | return true; |
| | 40015 | 509 | | } |
| | | 510 | | } |
| | | 511 | | } |
| | | 512 | | } |
| | | 513 | | |