xref: /dflybsd-src/sys/netproto/smb/smb_conn.c (revision e586f31ca9899b49a4fc156613d9ecd853defcec)
1 /*
2  * Copyright (c) 2000-2001 Boris Popov
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. All advertising materials mentioning features or use of this software
14  *    must display the following acknowledgement:
15  *    This product includes software developed by Boris Popov.
16  * 4. Neither the name of the author nor the names of any co-contributors
17  *    may be used to endorse or promote products derived from this software
18  *    without specific prior written permission.
19  *
20  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
21  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
24  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
30  * SUCH DAMAGE.
31  *
32  * $FreeBSD: src/sys/netsmb/smb_conn.c,v 1.1.2.1 2001/05/22 08:32:33 bp Exp $
33  * $DragonFly: src/sys/netproto/smb/smb_conn.c,v 1.20 2006/12/20 18:14:44 dillon Exp $
34  */
35 
36 /*
37  * Connection engine.
38  */
39 
40 #include <sys/param.h>
41 #include <sys/systm.h>
42 #include <sys/kernel.h>
43 #include <sys/malloc.h>
44 #include <sys/proc.h>
45 #include <sys/priv.h>
46 #include <sys/lock.h>
47 #include <sys/sysctl.h>
48 #include <sys/socketvar.h>
49 
50 #include <sys/iconv.h>
51 
52 #include "smb.h"
53 #include "smb_subr.h"
54 #include "smb_conn.h"
55 #include "smb_tran.h"
56 #include "smb_trantcp.h"
57 
58 static struct smb_connobj smb_vclist;
59 static int smb_vcnext = 1;	/* next unique id for VC */
60 
61 SYSCTL_NODE(_net, OID_AUTO, smb, CTLFLAG_RW, NULL, "SMB protocol");
62 
63 MALLOC_DEFINE(M_SMBCONN, "SMB conn", "SMB connection");
64 
65 static void smb_co_init(struct smb_connobj *cp, int level, char *objname);
66 static void smb_co_done(struct smb_connobj *cp);
67 static int  smb_co_lockstatus(struct smb_connobj *cp, struct thread *td);
68 
69 static int  smb_vc_disconnect(struct smb_vc *vcp);
70 static void smb_vc_free(struct smb_connobj *cp);
71 static void smb_vc_gone(struct smb_connobj *cp, struct smb_cred *scred);
72 
73 /*
74  * Connection object
75  */
76 static void smb_co_ref(struct smb_connobj *cp);
77 static void smb_co_rele(struct smb_connobj *cp, struct smb_cred *scred);
78 static int  smb_co_get(struct smb_connobj *cp, int flags, struct smb_cred *scred);
79 static void smb_co_put(struct smb_connobj *cp, struct smb_cred *scred);
80 static int  smb_co_lock(struct smb_connobj *cp, int flags);
81 static void smb_co_unlock(struct smb_connobj *cp, int flags);
82 
83 static smb_co_free_t smb_share_free;
84 static smb_co_gone_t smb_share_gone;
85 
86 static int  smb_sysctl_treedump(SYSCTL_HANDLER_ARGS);
87 
88 SYSCTL_PROC(_net_smb, OID_AUTO, treedump, CTLFLAG_RD | CTLTYPE_OPAQUE,
89 	    NULL, 0, smb_sysctl_treedump, "S,treedump", "Requester tree");
90 
91 int
92 smb_sm_init(void)
93 {
94 	smb_co_init(&smb_vclist, SMBL_SM, "smbsm");
95 	smb_co_unlock(&smb_vclist, 0);
96 	return 0;
97 }
98 
99 int
100 smb_sm_done(void)
101 {
102 
103 	/* XXX: hold the mutex */
104 	if (smb_vclist.co_usecount > 1) {
105 		SMBERROR("%d connections still active\n", smb_vclist.co_usecount - 1);
106 		return EBUSY;
107 	}
108 	smb_co_done(&smb_vclist);
109 	return 0;
110 }
111 
112 static int
113 smb_sm_lockvclist(int flags)
114 {
115 	return smb_co_lock(&smb_vclist, flags | LK_CANRECURSE);
116 }
117 
118 static void
119 smb_sm_unlockvclist(void)
120 {
121 	smb_co_unlock(&smb_vclist, LK_RELEASE);
122 }
123 
124 static int
125 smb_sm_lookupint(struct smb_vcspec *vcspec, struct smb_sharespec *shspec,
126 	struct smb_cred *scred,	struct smb_vc **vcpp)
127 {
128 	struct smb_connobj *scp;
129 	struct smb_vc *vcp;
130 	int exact = 1;
131 	int error;
132 
133 	vcspec->shspec = shspec;
134 	error = ENOENT;
135 	vcp = NULL;
136 	SMBCO_FOREACH(scp, &smb_vclist) {
137 		vcp = (struct smb_vc *)scp;
138 		error = smb_vc_lock(vcp, LK_EXCLUSIVE);
139 		if (error)
140 			continue;
141 
142 		error = 1;
143 		if ((vcp->obj.co_flags & SMBV_PRIVATE) ||
144 		    !CONNADDREQ(vcp->vc_paddr, vcspec->sap) ||
145 		    strcmp(vcp->vc_username, vcspec->username) != 0)
146 			goto unlock;
147 		if (vcspec->owner != SMBM_ANY_OWNER) {
148 			if (vcp->vc_uid != vcspec->owner)
149 				goto unlock;
150 		} else
151 			exact = 0;
152 		if (vcspec->group != SMBM_ANY_GROUP) {
153 			if (vcp->vc_grp != vcspec->group)
154 				goto unlock;
155 		} else
156 			exact = 0;
157 
158 		if (vcspec->mode & SMBM_EXACT) {
159 			if (!exact ||
160 			    (vcspec->mode & SMBM_MASK) != vcp->vc_mode)
161 				goto unlock;
162 		}
163 		if (smb_vc_access(vcp, scred, vcspec->mode) != 0)
164 			goto unlock;
165 		vcspec->ssp = NULL;
166 		if (shspec) {
167 			error = smb_vc_lookupshare(vcp, shspec, scred, &vcspec->ssp);
168 			if (error != 0)
169 				goto unlock;
170 		}
171 		error = 0;
172 		break;
173 unlock:
174 		smb_vc_unlock(vcp, 0);
175 	}
176 	if (vcp) {
177 		smb_vc_ref(vcp);
178 		*vcpp = vcp;
179 	}
180 	return error;
181 }
182 
183 int
184 smb_sm_lookup(struct smb_vcspec *vcspec, struct smb_sharespec *shspec,
185 	struct smb_cred *scred,	struct smb_vc **vcpp)
186 {
187 	struct smb_vc *vcp;
188 	struct smb_share *ssp = NULL;
189 	int error;
190 
191 	*vcpp = vcp = NULL;
192 
193 	error = smb_sm_lockvclist(LK_EXCLUSIVE);
194 	if (error)
195 		return error;
196 	error = smb_sm_lookupint(vcspec, shspec, scred, vcpp);
197 	if (error == 0 || (vcspec->flags & SMBV_CREATE) == 0) {
198 		smb_sm_unlockvclist();
199 		return error;
200 	}
201 	error = smb_sm_lookupint(vcspec, NULL, scred, &vcp);
202 	if (error) {
203 		error = smb_vc_create(vcspec, scred, &vcp);
204 		if (error)
205 			goto out;
206 		error = smb_vc_connect(vcp, scred);
207 		if (error)
208 			goto out;
209 	}
210 	if (shspec == NULL)
211 		goto out;
212 	error = smb_share_create(vcp, shspec, scred, &ssp);
213 	if (error)
214 		goto out;
215 	error = smb_smb_treeconnect(ssp, scred);
216 	if (error == 0)
217 		vcspec->ssp = ssp;
218 	else
219 		smb_share_put(ssp, scred);
220 out:
221 	smb_sm_unlockvclist();
222 	if (error == 0)
223 		*vcpp = vcp;
224 	else if (vcp)
225 		smb_vc_put(vcp, scred);
226 	return error;
227 }
228 
229 /*
230  * Common code for connection object
231  */
232 static void
233 smb_co_init(struct smb_connobj *cp, int level, char *objname)
234 {
235 	SLIST_INIT(&cp->co_children);
236 	smb_sl_init(&cp->co_interlock, objname);
237 	lockinit(&cp->co_lock, objname, 0, 0);
238 	cp->co_level = level;
239 	cp->co_usecount = 1;
240 	smb_co_lock(cp, LK_EXCLUSIVE);
241 }
242 
243 static void
244 smb_co_done(struct smb_connobj *cp)
245 {
246 	smb_sl_destroy(&cp->co_interlock);
247 	lockdestroy(&cp->co_lock);
248 }
249 
250 static void
251 smb_co_gone(struct smb_connobj *cp, struct smb_cred *scred)
252 {
253 	struct smb_connobj *parent;
254 
255 	if (cp->co_gone)
256 		cp->co_gone(cp, scred);
257 	parent = cp->co_parent;
258 	if (parent) {
259 		smb_co_lock(parent, LK_EXCLUSIVE);
260 		SLIST_REMOVE(&parent->co_children, cp, smb_connobj, co_next);
261 		smb_co_put(parent, scred);
262 	}
263 	lockmgr(&cp->co_lock, LK_RELEASE);
264 	while (cp->co_usecount > 0) {
265 		tsleep(&cp->co_lock, 0, "smbgone", hz);
266 	}
267 	if (cp->co_free)
268 		cp->co_free(cp);
269 }
270 
271 void
272 smb_co_ref(struct smb_connobj *cp)
273 {
274 	SMB_CO_LOCK(cp);
275 	cp->co_usecount++;
276 	SMB_CO_UNLOCK(cp);
277 }
278 
279 void
280 smb_co_rele(struct smb_connobj *cp, struct smb_cred *scred)
281 {
282 	SMB_CO_LOCK(cp);
283 	if (cp->co_usecount > 1) {
284 		cp->co_usecount--;
285 		SMB_CO_UNLOCK(cp);
286 		return;
287 	}
288 	if (cp->co_usecount <= 0) {
289 		SMBERROR("negative use_count for object %d", cp->co_level);
290 		SMB_CO_UNLOCK(cp);
291 		return;
292 	}
293 	cp->co_usecount = 0;
294 	if ((cp->co_flags & SMBO_GONE) == 0) {
295 		cp->co_flags |= SMBO_GONE;
296 		SMB_CO_UNLOCK(cp);
297 		lockmgr(&cp->co_lock, LK_EXCLUSIVE);
298 		smb_co_gone(cp, scred);
299 	} else {
300 		SMB_CO_UNLOCK(cp);
301 		wakeup(&cp->co_lock);
302 	}
303 }
304 
305 int
306 smb_co_get(struct smb_connobj *cp, int flags, struct smb_cred *scred)
307 {
308 	int error;
309 
310 	SMB_CO_LOCK(cp);
311 	cp->co_usecount++;
312 	SMB_CO_UNLOCK(cp);
313 	error = smb_co_lock(cp, flags);
314 	if (error) {
315 		SMB_CO_LOCK(cp);
316 		if (cp->co_usecount > 1) {
317 			cp->co_usecount--;
318 			SMB_CO_UNLOCK(cp);
319 		} else if (cp->co_usecount <= 0) {
320 			SMBERROR("negative use_count for object %d", cp->co_level);
321 			SMB_CO_UNLOCK(cp);
322 		} else {
323 			cp->co_usecount = 0;
324 			if ((cp->co_flags & SMBO_GONE) == 0) {
325 				cp->co_flags |= SMBO_GONE;
326 				SMB_CO_UNLOCK(cp);
327 				lockmgr(&cp->co_lock, LK_EXCLUSIVE);
328 				smb_co_gone(cp, scred);
329 			} else {
330 				SMB_CO_UNLOCK(cp);
331 			}
332 		}
333 		return error;
334 	}
335 	return 0;
336 }
337 
338 void
339 smb_co_put(struct smb_connobj *cp, struct smb_cred *scred)
340 {
341 	SMB_CO_LOCK(cp);
342 	if (cp->co_usecount > 1) {
343 		cp->co_usecount--;
344 		SMB_CO_UNLOCK(cp);
345 		lockmgr(&cp->co_lock, LK_RELEASE);
346 		return;
347 	}
348 	if (cp->co_usecount <= 0) {
349 		SMBERROR("negative use_count for object %d", cp->co_level);
350 		SMB_CO_UNLOCK(cp);
351 		return;
352 	}
353 	cp->co_usecount = 0;
354 	if ((cp->co_flags & SMBO_GONE) == 0) {
355 		cp->co_flags |= SMBO_GONE;
356 		SMB_CO_UNLOCK(cp);
357 		lockmgr(&cp->co_lock, LK_RELEASE);
358 		lockmgr(&cp->co_lock, LK_EXCLUSIVE);
359 		smb_co_gone(cp, scred);
360 	} else {
361 		SMB_CO_UNLOCK(cp);
362 		lockmgr(&cp->co_lock, LK_RELEASE);
363 		wakeup(&cp->co_lock);
364 	}
365 }
366 
367 int
368 smb_co_lockstatus(struct smb_connobj *cp, struct thread *td)
369 {
370 	return lockstatus(&cp->co_lock, td);
371 }
372 
373 int
374 smb_co_lock(struct smb_connobj *cp, int flags)
375 {
376 	int error;
377 
378 	KKASSERT(cp->co_usecount > 0);
379 	if (cp->co_flags & SMBO_GONE)
380 		return EINVAL;
381 	if ((flags & LK_TYPE_MASK) == 0)
382 		flags |= LK_EXCLUSIVE;
383 	if (smb_co_lockstatus(cp, curthread) == LK_EXCLUSIVE &&
384 	    (flags & LK_CANRECURSE) == 0) {
385 		SMBERROR("recursive lock for object %d\n", cp->co_level);
386 		return 0;
387 	}
388 	error = lockmgr(&cp->co_lock, flags);
389 	if (error == 0 && (cp->co_flags & SMBO_GONE)) {
390 		lockmgr(&cp->co_lock, LK_RELEASE);
391 		error = EINVAL;
392 	}
393 	return (error);
394 }
395 
396 void
397 smb_co_unlock(struct smb_connobj *cp, int flags)
398 {
399 	lockmgr(&cp->co_lock, flags | LK_RELEASE);
400 }
401 
402 static void
403 smb_co_addchild(struct smb_connobj *parent, struct smb_connobj *child)
404 {
405 	KASSERT(smb_co_lockstatus(parent, curthread) == LK_EXCLUSIVE, ("smb_co_addchild: parent not locked"));
406 	KASSERT(smb_co_lockstatus(child, curthread) == LK_EXCLUSIVE, ("smb_co_addchild: child not locked"));
407 
408 	smb_co_ref(parent);
409 	SLIST_INSERT_HEAD(&parent->co_children, child, co_next);
410 	child->co_parent = parent;
411 }
412 
413 /*
414  * Session implementation
415  */
416 
417 int
418 smb_vc_create(struct smb_vcspec *vcspec,
419 	struct smb_cred *scred, struct smb_vc **vcpp)
420 {
421 	struct smb_vc *vcp;
422 	struct ucred *cred = scred->scr_cred;
423 	uid_t uid = vcspec->owner;
424 	gid_t gid = vcspec->group;
425 	uid_t realuid = cred->cr_uid;
426 	char *domain = vcspec->domain;
427 	int error, isroot;
428 
429 	isroot = smb_suser(cred) == 0;
430 	/*
431 	 * Only superuser can create VCs with different uid and gid
432 	 */
433 	if (uid != SMBM_ANY_OWNER && uid != realuid && !isroot)
434 		return EPERM;
435 	if (gid != SMBM_ANY_GROUP && !groupmember(gid, cred) && !isroot)
436 		return EPERM;
437 
438 	vcp = smb_zmalloc(sizeof(*vcp), M_SMBCONN, M_WAITOK);
439 	smb_co_init(VCTOCP(vcp), SMBL_VC, "smb_vc");
440 	vcp->obj.co_free = smb_vc_free;
441 	vcp->obj.co_gone = smb_vc_gone;
442 	vcp->vc_number = smb_vcnext++;
443 	vcp->vc_timo = SMB_DEFRQTIMO;
444 	vcp->vc_smbuid = SMB_UID_UNKNOWN;
445 	vcp->vc_mode = vcspec->rights & SMBM_MASK;
446 	vcp->obj.co_flags = vcspec->flags & (SMBV_PRIVATE | SMBV_SINGLESHARE);
447 	vcp->vc_tdesc = &smb_tran_nbtcp_desc;
448 	vcp->vc_seqno = 0;
449 	vcp->vc_mackey = NULL;
450 	vcp->vc_mackeylen = 0;
451 
452 	if (uid == SMBM_ANY_OWNER)
453 		uid = realuid;
454 	if (gid == SMBM_ANY_GROUP)
455 		gid = cred->cr_groups[0];
456 	vcp->vc_uid = uid;
457 	vcp->vc_grp = gid;
458 
459 	smb_sl_init(&vcp->vc_stlock, "vcstlock");
460 
461 	do {
462 		error = ENOMEM;
463 		vcp->vc_paddr = dup_sockaddr(vcspec->sap);
464 		if (vcp->vc_paddr == NULL)
465 			break;
466 
467 		vcp->vc_laddr = dup_sockaddr(vcspec->lap);
468 		if (vcp->vc_laddr == NULL)
469 			break;
470 
471 		vcp->vc_pass = smb_strdup(vcspec->pass);
472 		if (vcp->vc_pass == NULL)
473 			break;
474 
475 		vcp->vc_domain = smb_strdup((domain && domain[0]) ? domain
476 								  : "NODOMAIN");
477 		if (vcp->vc_domain == NULL)
478 			break;
479 
480 		vcp->vc_srvname = smb_strdup(vcspec->srvname);
481 		if (vcp->vc_srvname == NULL)
482 			break;
483 		vcp->vc_username = smb_strdup(vcspec->username);
484 		if (vcp->vc_username == NULL)
485 			break;
486 
487 		error = iconv_open("tolower", vcspec->localcs, &vcp->vc_tolower);
488 		if (error != 0)
489 			break;
490 		error = iconv_open("toupper", vcspec->localcs, &vcp->vc_toupper);
491 		if (error != 0)
492 			break;
493 
494 		if (vcspec->servercs[0]) {
495 			error = iconv_open(vcspec->servercs, vcspec->localcs,
496 			    &vcp->vc_toserver);
497 			if (error != 0)
498 				break;
499 			error = iconv_open(vcspec->localcs, vcspec->servercs,
500 			    &vcp->vc_tolocal);
501 			if (error != 0)
502 				break;
503 		}
504 
505 		error = smb_iod_create(vcp);
506 		if (error != 0)
507 			break;
508 		*vcpp = vcp;
509 		smb_co_addchild(&smb_vclist, VCTOCP(vcp));
510 		error = 0;
511 	} while (0);
512 
513 	if (error)
514 		smb_vc_put(vcp, scred);
515 	return error;
516 }
517 
518 static void
519 smb_vc_free(struct smb_connobj *cp)
520 {
521 	struct smb_vc *vcp = CPTOVC(cp);
522 
523 	if (vcp->vc_iod)
524 		smb_iod_destroy(vcp->vc_iod);
525 	SMB_STRFREE(vcp->vc_username);
526 	SMB_STRFREE(vcp->vc_srvname);
527 	SMB_STRFREE(vcp->vc_pass);
528 	SMB_STRFREE(vcp->vc_domain);
529 	if (vcp->vc_mackey)
530 		kfree(vcp->vc_mackey, M_SMBTEMP);
531 	if (vcp->vc_paddr)
532 		kfree(vcp->vc_paddr, M_SONAME);
533 	if (vcp->vc_laddr)
534 		kfree(vcp->vc_laddr, M_SONAME);
535 	if (vcp->vc_tolower)
536 		iconv_close(vcp->vc_tolower);
537 	if (vcp->vc_toupper)
538 		iconv_close(vcp->vc_toupper);
539 	if (vcp->vc_tolocal)
540 		iconv_close(vcp->vc_tolocal);
541 	if (vcp->vc_toserver)
542 		iconv_close(vcp->vc_toserver);
543 	smb_co_done(VCTOCP(vcp));
544 	smb_sl_destroy(&vcp->vc_stlock);
545 	kfree(vcp, M_SMBCONN);
546 }
547 
548 /*
549  * Called when use count of VC dropped to zero.
550  */
551 static void
552 smb_vc_gone(struct smb_connobj *cp, struct smb_cred *scred)
553 {
554 	struct smb_vc *vcp = CPTOVC(cp);
555 
556 	smb_vc_disconnect(vcp);
557 }
558 
559 void
560 smb_vc_ref(struct smb_vc *vcp)
561 {
562 	smb_co_ref(VCTOCP(vcp));
563 }
564 
565 void
566 smb_vc_rele(struct smb_vc *vcp, struct smb_cred *scred)
567 {
568 	smb_co_rele(VCTOCP(vcp), scred);
569 }
570 
571 int
572 smb_vc_get(struct smb_vc *vcp, int flags, struct smb_cred *scred)
573 {
574 	return smb_co_get(VCTOCP(vcp), flags, scred);
575 }
576 
577 void
578 smb_vc_put(struct smb_vc *vcp, struct smb_cred *scred)
579 {
580 	smb_co_put(VCTOCP(vcp), scred);
581 }
582 
583 int
584 smb_vc_lock(struct smb_vc *vcp, int flags)
585 {
586 	return smb_co_lock(VCTOCP(vcp), flags);
587 }
588 
589 void
590 smb_vc_unlock(struct smb_vc *vcp, int flags)
591 {
592 	smb_co_unlock(VCTOCP(vcp), flags);
593 }
594 
595 int
596 smb_vc_access(struct smb_vc *vcp, struct smb_cred *scred, mode_t mode)
597 {
598 	struct ucred *cred = scred->scr_cred;
599 
600 	if (smb_suser(cred) == 0 || cred->cr_uid == vcp->vc_uid)
601 		return 0;
602 	mode >>= 3;
603 	if (!groupmember(vcp->vc_grp, cred))
604 		mode >>= 3;
605 	return (vcp->vc_mode & mode) == mode ? 0 : EACCES;
606 }
607 
608 static int
609 smb_vc_cmpshare(struct smb_share *ssp, struct smb_sharespec *dp)
610 {
611 	int exact = 1;
612 
613 	if (strcmp(ssp->ss_name, dp->name) != 0)
614 		return 1;
615 	if (dp->owner != SMBM_ANY_OWNER) {
616 		if (ssp->ss_uid != dp->owner)
617 			return 1;
618 	} else
619 		exact = 0;
620 	if (dp->group != SMBM_ANY_GROUP) {
621 		if (ssp->ss_grp != dp->group)
622 			return 1;
623 	} else
624 		exact = 0;
625 
626 	if (dp->mode & SMBM_EXACT) {
627 		if (!exact)
628 			return 1;
629 		return (dp->mode & SMBM_MASK) == ssp->ss_mode ? 0 : 1;
630 	}
631 	if (smb_share_access(ssp, dp->scred, dp->mode) != 0)
632 		return 1;
633 	return 0;
634 }
635 
636 /*
637  * Lookup share in the given VC. Share referenced and locked on return.
638  * VC expected to be locked on entry and will be left locked on exit.
639  */
640 int
641 smb_vc_lookupshare(struct smb_vc *vcp, struct smb_sharespec *dp,
642 	struct smb_cred *scred,	struct smb_share **sspp)
643 {
644 	struct smb_connobj *scp = NULL;
645 	struct smb_share *ssp = NULL;
646 	int error;
647 
648 	*sspp = NULL;
649 	dp->scred = scred;
650 	SMBCO_FOREACH(scp, VCTOCP(vcp)) {
651 		ssp = (struct smb_share *)scp;
652 		error = smb_share_lock(ssp, LK_EXCLUSIVE);
653 		if (error)
654 			continue;
655 		if (smb_vc_cmpshare(ssp, dp) == 0)
656 			break;
657 		smb_share_unlock(ssp, 0);
658 	}
659 	if (ssp) {
660 		smb_share_ref(ssp);
661 		*sspp = ssp;
662 		error = 0;
663 	} else
664 		error = ENOENT;
665 	return error;
666 }
667 
668 int
669 smb_vc_connect(struct smb_vc *vcp, struct smb_cred *scred)
670 {
671 
672 	return smb_iod_request(vcp->vc_iod, SMBIOD_EV_CONNECT | SMBIOD_EV_SYNC, NULL);
673 }
674 
675 /*
676  * Destroy VC to server, invalidate shares linked with it.
677  * Transport should be locked on entry.
678  */
679 int
680 smb_vc_disconnect(struct smb_vc *vcp)
681 {
682 
683 	smb_iod_request(vcp->vc_iod, SMBIOD_EV_DISCONNECT | SMBIOD_EV_SYNC, NULL);
684 	return 0;
685 }
686 
687 static char smb_emptypass[] = "";
688 
689 const char *
690 smb_vc_getpass(struct smb_vc *vcp)
691 {
692 	if (vcp->vc_pass)
693 		return vcp->vc_pass;
694 	return smb_emptypass;
695 }
696 
697 static int
698 smb_vc_getinfo(struct smb_vc *vcp, struct smb_vc_info *vip)
699 {
700 	bzero(vip, sizeof(struct smb_vc_info));
701 	vip->itype = SMB_INFO_VC;
702 	vip->usecount = vcp->obj.co_usecount;
703 	vip->uid = vcp->vc_uid;
704 	vip->gid = vcp->vc_grp;
705 	vip->mode = vcp->vc_mode;
706 	vip->flags = vcp->obj.co_flags;
707 	vip->sopt = vcp->vc_sopt;
708 	vip->iodstate = vcp->vc_iod->iod_state;
709 	bzero(&vip->sopt.sv_skey, sizeof(vip->sopt.sv_skey));
710 	ksnprintf(vip->srvname, sizeof(vip->srvname), "%s", vcp->vc_srvname);
711 	ksnprintf(vip->vcname, sizeof(vip->vcname), "%s", vcp->vc_username);
712 	return 0;
713 }
714 
715 u_short
716 smb_vc_nextmid(struct smb_vc *vcp)
717 {
718 	u_short r;
719 
720 	SMB_CO_LOCK(&vcp->obj);
721 	r = vcp->vc_mid++;
722 	SMB_CO_UNLOCK(&vcp->obj);
723 	return r;
724 }
725 
726 /*
727  * Share implementation
728  */
729 /*
730  * Allocate share structure and attach it to the given VC
731  * Connection expected to be locked on entry. Share will be returned
732  * in locked state.
733  */
734 int
735 smb_share_create(struct smb_vc *vcp, struct smb_sharespec *shspec,
736 	struct smb_cred *scred, struct smb_share **sspp)
737 {
738 	struct smb_share *ssp;
739 	struct ucred *cred = scred->scr_cred;
740 	uid_t realuid = cred->cr_uid;
741 	uid_t uid = shspec->owner;
742 	gid_t gid = shspec->group;
743 	int error, isroot;
744 
745 	isroot = smb_suser(cred) == 0;
746 	/*
747 	 * Only superuser can create shares with different uid and gid
748 	 */
749 	if (uid != SMBM_ANY_OWNER && uid != realuid && !isroot)
750 		return EPERM;
751 	if (gid != SMBM_ANY_GROUP && !groupmember(gid, cred) && !isroot)
752 		return EPERM;
753 	error = smb_vc_lookupshare(vcp, shspec, scred, &ssp);
754 	if (!error) {
755 		smb_share_put(ssp, scred);
756 		return EEXIST;
757 	}
758 	if (uid == SMBM_ANY_OWNER)
759 		uid = realuid;
760 	if (gid == SMBM_ANY_GROUP)
761 		gid = cred->cr_groups[0];
762 	ssp = smb_zmalloc(sizeof(*ssp), M_SMBCONN, M_WAITOK);
763 	smb_co_init(SSTOCP(ssp), SMBL_SHARE, "smbss");
764 	ssp->obj.co_free = smb_share_free;
765 	ssp->obj.co_gone = smb_share_gone;
766 	smb_sl_init(&ssp->ss_stlock, "ssstlock");
767 	ssp->ss_name = smb_strdup(shspec->name);
768 	if (shspec->pass && shspec->pass[0])
769 		ssp->ss_pass = smb_strdup(shspec->pass);
770 	ssp->ss_type = shspec->stype;
771 	ssp->ss_tid = SMB_TID_UNKNOWN;
772 	ssp->ss_uid = uid;
773 	ssp->ss_grp = gid;
774 	ssp->ss_mode = shspec->rights & SMBM_MASK;
775 	smb_co_addchild(VCTOCP(vcp), SSTOCP(ssp));
776 	*sspp = ssp;
777 	return 0;
778 }
779 
780 static void
781 smb_share_free(struct smb_connobj *cp)
782 {
783 	struct smb_share *ssp = CPTOSS(cp);
784 
785 	SMB_STRFREE(ssp->ss_name);
786 	SMB_STRFREE(ssp->ss_pass);
787 	smb_sl_destroy(&ssp->ss_stlock);
788 	smb_co_done(SSTOCP(ssp));
789 	kfree(ssp, M_SMBCONN);
790 }
791 
792 static void
793 smb_share_gone(struct smb_connobj *cp, struct smb_cred *scred)
794 {
795 	struct smb_share *ssp = CPTOSS(cp);
796 
797 	smb_smb_treedisconnect(ssp, scred);
798 }
799 
800 void
801 smb_share_ref(struct smb_share *ssp)
802 {
803 	smb_co_ref(SSTOCP(ssp));
804 }
805 
806 void
807 smb_share_rele(struct smb_share *ssp, struct smb_cred *scred)
808 {
809 	smb_co_rele(SSTOCP(ssp), scred);
810 }
811 
812 int
813 smb_share_get(struct smb_share *ssp, int flags, struct smb_cred *scred)
814 {
815 	return smb_co_get(SSTOCP(ssp), flags, scred);
816 }
817 
818 void
819 smb_share_put(struct smb_share *ssp, struct smb_cred *scred)
820 {
821 	smb_co_put(SSTOCP(ssp), scred);
822 }
823 
824 int
825 smb_share_lock(struct smb_share *ssp, int flags)
826 {
827 	return smb_co_lock(SSTOCP(ssp), flags);
828 }
829 
830 void
831 smb_share_unlock(struct smb_share *ssp, int flags)
832 {
833 	smb_co_unlock(SSTOCP(ssp), flags);
834 }
835 
836 int
837 smb_share_access(struct smb_share *ssp, struct smb_cred *scred, mode_t mode)
838 {
839 	struct ucred *cred = scred->scr_cred;
840 
841 	if (smb_suser(cred) == 0 || cred->cr_uid == ssp->ss_uid)
842 		return 0;
843 	mode >>= 3;
844 	if (!groupmember(ssp->ss_grp, cred))
845 		mode >>= 3;
846 	return (ssp->ss_mode & mode) == mode ? 0 : EACCES;
847 }
848 
849 void
850 smb_share_invalidate(struct smb_share *ssp)
851 {
852 	ssp->ss_tid = SMB_TID_UNKNOWN;
853 }
854 
855 int
856 smb_share_valid(struct smb_share *ssp)
857 {
858 	return ssp->ss_tid != SMB_TID_UNKNOWN &&
859 	    ssp->ss_vcgenid == SSTOVC(ssp)->vc_genid;
860 }
861 
862 const char*
863 smb_share_getpass(struct smb_share *ssp)
864 {
865 	struct smb_vc *vcp;
866 
867 	if (ssp->ss_pass)
868 		return ssp->ss_pass;
869 	vcp = SSTOVC(ssp);
870 	if (vcp->vc_pass)
871 		return vcp->vc_pass;
872 	return smb_emptypass;
873 }
874 
875 static int
876 smb_share_getinfo(struct smb_share *ssp, struct smb_share_info *sip)
877 {
878 	bzero(sip, sizeof(struct smb_share_info));
879 	sip->itype = SMB_INFO_SHARE;
880 	sip->usecount = ssp->obj.co_usecount;
881 	sip->tid  = ssp->ss_tid;
882 	sip->type= ssp->ss_type;
883 	sip->uid = ssp->ss_uid;
884 	sip->gid = ssp->ss_grp;
885 	sip->mode= ssp->ss_mode;
886 	sip->flags = ssp->obj.co_flags;
887 	ksnprintf(sip->sname, sizeof(sip->sname), "%s", ssp->ss_name);
888 	return 0;
889 }
890 
891 /*
892  * Dump an entire tree into sysctl call
893  */
894 static int
895 smb_sysctl_treedump(SYSCTL_HANDLER_ARGS)
896 {
897 	struct thread *td = req->td;
898 	struct ucred *ucred;
899 	struct smb_cred scred;
900 	struct smb_connobj *scp1, *scp2;
901 	struct smb_vc *vcp;
902 	struct smb_share *ssp;
903 	struct smb_vc_info vci;
904 	struct smb_share_info ssi;
905 	int error, itype;
906 
907 	KKASSERT(td->td_proc);
908 	ucred = td->td_proc->p_ucred;
909 
910 	smb_makescred(&scred, td, ucred);
911 	error = smb_sm_lockvclist(LK_SHARED);
912 	if (error)
913 		return error;
914 	SMBCO_FOREACH(scp1, &smb_vclist) {
915 		vcp = (struct smb_vc *)scp1;
916 		error = smb_vc_lock(vcp, LK_SHARED);
917 		if (error)
918 			continue;
919 		smb_vc_getinfo(vcp, &vci);
920 		error = SYSCTL_OUT(req, &vci, sizeof(struct smb_vc_info));
921 		if (error) {
922 			smb_vc_unlock(vcp, 0);
923 			break;
924 		}
925 		SMBCO_FOREACH(scp2, VCTOCP(vcp)) {
926 			ssp = (struct smb_share *)scp2;
927 			error = smb_share_lock(ssp, LK_SHARED);
928 			if (error) {
929 				error = 0;
930 				continue;
931 			}
932 			smb_share_getinfo(ssp, &ssi);
933 			smb_share_unlock(ssp, 0);
934 			error = SYSCTL_OUT(req, &ssi, sizeof(struct smb_share_info));
935 			if (error)
936 				break;
937 		}
938 		smb_vc_unlock(vcp, 0);
939 		if (error)
940 			break;
941 	}
942 	if (!error) {
943 		itype = SMB_INFO_NONE;
944 		error = SYSCTL_OUT(req, &itype, sizeof(itype));
945 	}
946 	smb_sm_unlockvclist();
947 	return error;
948 }
949