15331Samw /*
25331Samw * CDDL HEADER START
35331Samw *
45331Samw * The contents of this file are subject to the terms of the
55331Samw * Common Development and Distribution License (the "License").
65331Samw * You may not use this file except in compliance with the License.
75331Samw *
85331Samw * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
95331Samw * or http://www.opensolaris.org/os/licensing.
105331Samw * See the License for the specific language governing permissions
115331Samw * and limitations under the License.
125331Samw *
135331Samw * When distributing Covered Code, include this CDDL HEADER in each
145331Samw * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
155331Samw * If applicable, add the following below this CDDL HEADER, with the
165331Samw * fields enclosed by brackets "[]" replaced with your own identifying
175331Samw * information: Portions Copyright [yyyy] [name of copyright owner]
185331Samw *
195331Samw * CDDL HEADER END
205331Samw */
215331Samw /*
2212508Samw@Sun.COM * Copyright (c) 2007, 2010, Oracle and/or its affiliates. All rights reserved.
235331Samw */
245331Samw
255331Samw #include <sys/sid.h>
265772Sas200622 #include <sys/nbmlock.h>
275331Samw #include <smbsrv/smb_fsops.h>
285521Sas200622 #include <smbsrv/smb_kproto.h>
295331Samw #include <acl/acl_common.h>
305772Sas200622 #include <sys/fcntl.h>
315772Sas200622 #include <sys/flock.h>
325772Sas200622 #include <fs/fs_subr.h>
335331Samw
346139Sjb150015 extern caller_context_t smb_ct;
356139Sjb150015
369343SAfshin.Ardakani@Sun.COM static int smb_fsop_create_stream(smb_request_t *, cred_t *, smb_node_t *,
3710001SJoyce.McIntosh@Sun.COM char *, char *, int, smb_attr_t *, smb_node_t **);
389343SAfshin.Ardakani@Sun.COM
399343SAfshin.Ardakani@Sun.COM static int smb_fsop_create_file(smb_request_t *, cred_t *, smb_node_t *,
4010001SJoyce.McIntosh@Sun.COM char *, int, smb_attr_t *, smb_node_t **);
419343SAfshin.Ardakani@Sun.COM
429343SAfshin.Ardakani@Sun.COM static int smb_fsop_create_with_sd(smb_request_t *, cred_t *, smb_node_t *,
4310001SJoyce.McIntosh@Sun.COM char *, smb_attr_t *, smb_node_t **, smb_fssd_t *);
449343SAfshin.Ardakani@Sun.COM
459343SAfshin.Ardakani@Sun.COM static int smb_fsop_sdinherit(smb_request_t *, smb_node_t *, smb_fssd_t *);
465331Samw
475331Samw /*
485331Samw * The smb_fsop_* functions have knowledge of CIFS semantics.
495331Samw *
505331Samw * The smb_vop_* functions have minimal knowledge of CIFS semantics and
515331Samw * serve as an interface to the VFS layer.
525331Samw *
535331Samw * Hence, smb_request_t and smb_node_t structures should not be passed
545331Samw * from the smb_fsop_* layer to the smb_vop_* layer.
555331Samw *
565331Samw * In general, CIFS service code should only ever call smb_fsop_*
575331Samw * functions directly, and never smb_vop_* functions directly.
585331Samw *
595331Samw * smb_fsop_* functions should call smb_vop_* functions where possible, instead
605331Samw * of their smb_fsop_* counterparts. However, there are times when
615331Samw * this cannot be avoided.
625331Samw */
635331Samw
645331Samw /*
655331Samw * Note: Stream names cannot be mangled.
665331Samw */
675331Samw
686600Sas200622 /*
696600Sas200622 * smb_fsop_amask_to_omode
706600Sas200622 *
716600Sas200622 * Convert the access mask to the open mode (for use
726600Sas200622 * with the VOP_OPEN call).
736600Sas200622 *
746600Sas200622 * Note that opening a file for attribute only access
756600Sas200622 * will also translate into an FREAD or FWRITE open mode
766600Sas200622 * (i.e., it's not just for data).
776600Sas200622 *
786600Sas200622 * This is needed so that opens are tracked appropriately
796600Sas200622 * for oplock processing.
806600Sas200622 */
816600Sas200622
825331Samw int
smb_fsop_amask_to_omode(uint32_t access)836600Sas200622 smb_fsop_amask_to_omode(uint32_t access)
845331Samw {
856600Sas200622 int mode = 0;
866600Sas200622
876600Sas200622 if (access & (FILE_READ_DATA | FILE_EXECUTE |
886600Sas200622 FILE_READ_ATTRIBUTES | FILE_READ_EA))
896600Sas200622 mode |= FREAD;
906600Sas200622
916600Sas200622 if (access & (FILE_WRITE_DATA | FILE_APPEND_DATA |
926600Sas200622 FILE_WRITE_ATTRIBUTES | FILE_WRITE_EA))
936600Sas200622 mode |= FWRITE;
946600Sas200622
956600Sas200622 if (access & FILE_APPEND_DATA)
966600Sas200622 mode |= FAPPEND;
976600Sas200622
986600Sas200622 return (mode);
995331Samw }
1005331Samw
1015331Samw int
smb_fsop_open(smb_node_t * node,int mode,cred_t * cred)1026600Sas200622 smb_fsop_open(smb_node_t *node, int mode, cred_t *cred)
1035331Samw {
1046600Sas200622 /*
1056600Sas200622 * Assuming that the same vnode is returned as we had before.
1066600Sas200622 * (I.e., with certain types of files or file systems, a
1076600Sas200622 * different vnode might be returned by VOP_OPEN)
1086600Sas200622 */
1096600Sas200622 return (smb_vop_open(&node->vp, mode, cred));
1105331Samw }
1115331Samw
1127348SJose.Borrego@Sun.COM void
smb_fsop_close(smb_node_t * node,int mode,cred_t * cred)1136600Sas200622 smb_fsop_close(smb_node_t *node, int mode, cred_t *cred)
1146600Sas200622 {
1157348SJose.Borrego@Sun.COM smb_vop_close(node->vp, mode, cred);
1166600Sas200622 }
1176600Sas200622
1185331Samw static int
smb_fsop_create_with_sd(smb_request_t * sr,cred_t * cr,smb_node_t * dnode,char * name,smb_attr_t * attr,smb_node_t ** ret_snode,smb_fssd_t * fs_sd)1199343SAfshin.Ardakani@Sun.COM smb_fsop_create_with_sd(smb_request_t *sr, cred_t *cr,
1209343SAfshin.Ardakani@Sun.COM smb_node_t *dnode, char *name,
12110001SJoyce.McIntosh@Sun.COM smb_attr_t *attr, smb_node_t **ret_snode, smb_fssd_t *fs_sd)
1225331Samw {
1235331Samw vsecattr_t *vsap;
1245331Samw vsecattr_t vsecattr;
1255331Samw acl_t *acl, *dacl, *sacl;
1265331Samw smb_attr_t set_attr;
1275331Samw vnode_t *vp;
1285331Samw int aclbsize = 0; /* size of acl list in bytes */
1295331Samw int flags = 0;
1305331Samw int rc;
1317619SJose.Borrego@Sun.COM boolean_t is_dir;
1325331Samw
1335331Samw ASSERT(fs_sd);
1345331Samw
1357348SJose.Borrego@Sun.COM if (SMB_TREE_IS_CASEINSENSITIVE(sr))
1365331Samw flags = SMB_IGNORE_CASE;
1379231SAfshin.Ardakani@Sun.COM if (SMB_TREE_SUPPORTS_CATIA(sr))
1389231SAfshin.Ardakani@Sun.COM flags |= SMB_CATIA;
1395331Samw
1405331Samw ASSERT(cr);
1415331Samw
1425331Samw is_dir = ((fs_sd->sd_flags & SMB_FSSD_FLAGS_DIR) != 0);
1435331Samw
1447348SJose.Borrego@Sun.COM if (smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACLONCREATE)) {
1455331Samw if (fs_sd->sd_secinfo & SMB_ACL_SECINFO) {
1465331Samw dacl = fs_sd->sd_zdacl;
1475331Samw sacl = fs_sd->sd_zsacl;
1485331Samw ASSERT(dacl || sacl);
1495331Samw if (dacl && sacl) {
1505521Sas200622 acl = smb_fsacl_merge(dacl, sacl);
1515331Samw } else if (dacl) {
1525331Samw acl = dacl;
1535331Samw } else {
1545331Samw acl = sacl;
1555331Samw }
1565331Samw
1575521Sas200622 rc = smb_fsacl_to_vsa(acl, &vsecattr, &aclbsize);
1585331Samw
1595331Samw if (dacl && sacl)
1605331Samw acl_free(acl);
1615331Samw
1627619SJose.Borrego@Sun.COM if (rc != 0)
1635331Samw return (rc);
1645331Samw
1655331Samw vsap = &vsecattr;
1667619SJose.Borrego@Sun.COM } else {
1677619SJose.Borrego@Sun.COM vsap = NULL;
1685331Samw }
1695331Samw
1708845Samw@Sun.COM /* The tree ACEs may prevent a create */
1718845Samw@Sun.COM rc = EACCES;
1725331Samw if (is_dir) {
1738845Samw@Sun.COM if (SMB_TREE_HAS_ACCESS(sr, ACE_ADD_SUBDIRECTORY) != 0)
1749343SAfshin.Ardakani@Sun.COM rc = smb_vop_mkdir(dnode->vp, name, attr,
1758845Samw@Sun.COM &vp, flags, cr, vsap);
1765331Samw } else {
1778845Samw@Sun.COM if (SMB_TREE_HAS_ACCESS(sr, ACE_ADD_FILE) != 0)
1789343SAfshin.Ardakani@Sun.COM rc = smb_vop_create(dnode->vp, name, attr,
1798845Samw@Sun.COM &vp, flags, cr, vsap);
1805331Samw }
1815331Samw
1825331Samw if (vsap != NULL)
1835331Samw kmem_free(vsap->vsa_aclentp, aclbsize);
1845331Samw
1855331Samw if (rc != 0)
1865331Samw return (rc);
1875331Samw
1885331Samw set_attr.sa_mask = 0;
1895331Samw
1905331Samw /*
1915331Samw * Ideally we should be able to specify the owner and owning
1925331Samw * group at create time along with the ACL. Since we cannot
1935331Samw * do that right now, kcred is passed to smb_vop_setattr so it
1945331Samw * doesn't fail due to lack of permission.
1955331Samw */
1965331Samw if (fs_sd->sd_secinfo & SMB_OWNER_SECINFO) {
1975331Samw set_attr.sa_vattr.va_uid = fs_sd->sd_uid;
1985331Samw set_attr.sa_mask |= SMB_AT_UID;
1995331Samw }
2005331Samw
2015331Samw if (fs_sd->sd_secinfo & SMB_GROUP_SECINFO) {
2025331Samw set_attr.sa_vattr.va_gid = fs_sd->sd_gid;
2035331Samw set_attr.sa_mask |= SMB_AT_GID;
2045331Samw }
2055331Samw
2067757SJanice.Chang@Sun.COM if (set_attr.sa_mask)
2077757SJanice.Chang@Sun.COM rc = smb_vop_setattr(vp, NULL, &set_attr, 0, kcred);
2085331Samw
2097619SJose.Borrego@Sun.COM if (rc == 0) {
2107619SJose.Borrego@Sun.COM *ret_snode = smb_node_lookup(sr, &sr->arg.open, cr, vp,
21110001SJoyce.McIntosh@Sun.COM name, dnode, NULL);
2127619SJose.Borrego@Sun.COM
2138670SJose.Borrego@Sun.COM if (*ret_snode == NULL)
2147619SJose.Borrego@Sun.COM rc = ENOMEM;
2158670SJose.Borrego@Sun.COM
2168670SJose.Borrego@Sun.COM VN_RELE(vp);
2177619SJose.Borrego@Sun.COM }
2185331Samw } else {
2195331Samw /*
2205331Samw * For filesystems that don't support ACL-on-create, try
2215331Samw * to set the specified SD after create, which could actually
2225331Samw * fail because of conflicts between inherited security
2235331Samw * attributes upon creation and the specified SD.
2245331Samw *
2255331Samw * Passing kcred to smb_fsop_sdwrite() to overcome this issue.
2265331Samw */
2275331Samw
2285331Samw if (is_dir) {
2299343SAfshin.Ardakani@Sun.COM rc = smb_vop_mkdir(dnode->vp, name, attr, &vp,
2307619SJose.Borrego@Sun.COM flags, cr, NULL);
2315331Samw } else {
2329343SAfshin.Ardakani@Sun.COM rc = smb_vop_create(dnode->vp, name, attr, &vp,
2337619SJose.Borrego@Sun.COM flags, cr, NULL);
2345331Samw }
2355331Samw
2365521Sas200622 if (rc != 0)
2375521Sas200622 return (rc);
2385521Sas200622
2397619SJose.Borrego@Sun.COM *ret_snode = smb_node_lookup(sr, &sr->arg.open, cr, vp,
24010001SJoyce.McIntosh@Sun.COM name, dnode, NULL);
2417619SJose.Borrego@Sun.COM
2427619SJose.Borrego@Sun.COM if (*ret_snode != NULL) {
2437619SJose.Borrego@Sun.COM if (!smb_tree_has_feature(sr->tid_tree,
2447619SJose.Borrego@Sun.COM SMB_TREE_NFS_MOUNTED))
2457619SJose.Borrego@Sun.COM rc = smb_fsop_sdwrite(sr, kcred, *ret_snode,
2467619SJose.Borrego@Sun.COM fs_sd, 1);
2477619SJose.Borrego@Sun.COM } else {
2485331Samw rc = ENOMEM;
2495331Samw }
2508670SJose.Borrego@Sun.COM
2518670SJose.Borrego@Sun.COM VN_RELE(vp);
2525331Samw }
2535331Samw
2545521Sas200622 if (rc != 0) {
2557619SJose.Borrego@Sun.COM if (is_dir)
2569343SAfshin.Ardakani@Sun.COM (void) smb_vop_rmdir(dnode->vp, name, flags, cr);
2577619SJose.Borrego@Sun.COM else
2589343SAfshin.Ardakani@Sun.COM (void) smb_vop_remove(dnode->vp, name, flags, cr);
2595521Sas200622 }
2605521Sas200622
2615331Samw return (rc);
2625331Samw }
2635331Samw
2645331Samw /*
2655331Samw * smb_fsop_create
2665331Samw *
2675331Samw * All SMB functions should use this wrapper to ensure that
2685331Samw * all the smb_vop_creates are performed with the appropriate credentials.
2699343SAfshin.Ardakani@Sun.COM * Please document any direct calls to explain the reason for avoiding
2709343SAfshin.Ardakani@Sun.COM * this wrapper.
2715331Samw *
2725331Samw * *ret_snode is returned with a reference upon success. No reference is
2735331Samw * taken if an error is returned.
2745331Samw */
2755331Samw int
smb_fsop_create(smb_request_t * sr,cred_t * cr,smb_node_t * dnode,char * name,smb_attr_t * attr,smb_node_t ** ret_snode)27610001SJoyce.McIntosh@Sun.COM smb_fsop_create(smb_request_t *sr, cred_t *cr, smb_node_t *dnode,
27710001SJoyce.McIntosh@Sun.COM char *name, smb_attr_t *attr, smb_node_t **ret_snode)
2785331Samw {
2799343SAfshin.Ardakani@Sun.COM int rc = 0;
2809343SAfshin.Ardakani@Sun.COM int flags = 0;
2819343SAfshin.Ardakani@Sun.COM char *fname, *sname;
2829343SAfshin.Ardakani@Sun.COM char *longname = NULL;
2835331Samw
2845331Samw ASSERT(cr);
2859343SAfshin.Ardakani@Sun.COM ASSERT(dnode);
2869343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
2879343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
2885331Samw
2895331Samw ASSERT(ret_snode);
2905331Samw *ret_snode = 0;
2915331Samw
2925331Samw ASSERT(name);
2935331Samw if (*name == 0)
2945331Samw return (EINVAL);
2955331Samw
2965331Samw ASSERT(sr);
2975331Samw ASSERT(sr->tid_tree);
2987348SJose.Borrego@Sun.COM
2999343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0)
3007348SJose.Borrego@Sun.COM return (EACCES);
3017348SJose.Borrego@Sun.COM
3027348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
3035331Samw return (EROFS);
3045331Samw
3057348SJose.Borrego@Sun.COM if (SMB_TREE_IS_CASEINSENSITIVE(sr))
3065331Samw flags = SMB_IGNORE_CASE;
3079231SAfshin.Ardakani@Sun.COM if (SMB_TREE_SUPPORTS_CATIA(sr))
3089231SAfshin.Ardakani@Sun.COM flags |= SMB_CATIA;
30910504SKeyur.Desai@Sun.COM if (SMB_TREE_SUPPORTS_ABE(sr))
31010504SKeyur.Desai@Sun.COM flags |= SMB_ABE;
3115331Samw
3129231SAfshin.Ardakani@Sun.COM if (smb_is_stream_name(name)) {
3139231SAfshin.Ardakani@Sun.COM fname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
3149231SAfshin.Ardakani@Sun.COM sname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
3159343SAfshin.Ardakani@Sun.COM smb_stream_parse_name(name, fname, sname);
3165331Samw
3179343SAfshin.Ardakani@Sun.COM rc = smb_fsop_create_stream(sr, cr, dnode,
31810001SJoyce.McIntosh@Sun.COM fname, sname, flags, attr, ret_snode);
3199231SAfshin.Ardakani@Sun.COM
3209231SAfshin.Ardakani@Sun.COM kmem_free(fname, MAXNAMELEN);
3219231SAfshin.Ardakani@Sun.COM kmem_free(sname, MAXNAMELEN);
3229231SAfshin.Ardakani@Sun.COM return (rc);
3239231SAfshin.Ardakani@Sun.COM }
3245521Sas200622
3259231SAfshin.Ardakani@Sun.COM /* Not a named stream */
3269343SAfshin.Ardakani@Sun.COM
327*12890SJoyce.McIntosh@Sun.COM if (SMB_TREE_SUPPORTS_SHORTNAMES(sr) && smb_maybe_mangled(name)) {
3289231SAfshin.Ardakani@Sun.COM longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
32912508Samw@Sun.COM rc = smb_unmangle(dnode, name, longname, MAXNAMELEN, flags);
3309231SAfshin.Ardakani@Sun.COM kmem_free(longname, MAXNAMELEN);
3315331Samw
3329231SAfshin.Ardakani@Sun.COM if (rc == 0)
3339231SAfshin.Ardakani@Sun.COM rc = EEXIST;
3349231SAfshin.Ardakani@Sun.COM if (rc != ENOENT)
3359231SAfshin.Ardakani@Sun.COM return (rc);
3365331Samw }
3375331Samw
3389343SAfshin.Ardakani@Sun.COM rc = smb_fsop_create_file(sr, cr, dnode, name, flags,
33910001SJoyce.McIntosh@Sun.COM attr, ret_snode);
3409343SAfshin.Ardakani@Sun.COM return (rc);
3419343SAfshin.Ardakani@Sun.COM
3429343SAfshin.Ardakani@Sun.COM }
3439343SAfshin.Ardakani@Sun.COM
3449343SAfshin.Ardakani@Sun.COM
3459343SAfshin.Ardakani@Sun.COM /*
3469343SAfshin.Ardakani@Sun.COM * smb_fsop_create_stream
3479343SAfshin.Ardakani@Sun.COM *
3489343SAfshin.Ardakani@Sun.COM * Create NTFS named stream file (sname) on unnamed stream
3499343SAfshin.Ardakani@Sun.COM * file (fname), creating the unnamed stream file if it
3509343SAfshin.Ardakani@Sun.COM * doesn't exist.
3519343SAfshin.Ardakani@Sun.COM * If we created the unnamed stream file and then creation
3529343SAfshin.Ardakani@Sun.COM * of the named stream file fails, we delete the unnamed stream.
3539343SAfshin.Ardakani@Sun.COM * Since we use the real file name for the smb_vop_remove we
3549343SAfshin.Ardakani@Sun.COM * clear the SMB_IGNORE_CASE flag to ensure a case sensitive
3559343SAfshin.Ardakani@Sun.COM * match.
3569343SAfshin.Ardakani@Sun.COM *
3579343SAfshin.Ardakani@Sun.COM * The second parameter of smb_vop_setattr() is set to
3589343SAfshin.Ardakani@Sun.COM * NULL, even though an unnamed stream exists. This is
3599343SAfshin.Ardakani@Sun.COM * because we want to set the UID and GID on the named
3609343SAfshin.Ardakani@Sun.COM * stream in this case for consistency with the (unnamed
3619343SAfshin.Ardakani@Sun.COM * stream) file (see comments for smb_vop_setattr()).
3629343SAfshin.Ardakani@Sun.COM */
3639343SAfshin.Ardakani@Sun.COM static int
smb_fsop_create_stream(smb_request_t * sr,cred_t * cr,smb_node_t * dnode,char * fname,char * sname,int flags,smb_attr_t * attr,smb_node_t ** ret_snode)3649343SAfshin.Ardakani@Sun.COM smb_fsop_create_stream(smb_request_t *sr, cred_t *cr,
3659343SAfshin.Ardakani@Sun.COM smb_node_t *dnode, char *fname, char *sname, int flags,
36610001SJoyce.McIntosh@Sun.COM smb_attr_t *attr, smb_node_t **ret_snode)
3679343SAfshin.Ardakani@Sun.COM {
3689343SAfshin.Ardakani@Sun.COM smb_node_t *fnode;
3699343SAfshin.Ardakani@Sun.COM smb_attr_t fattr;
3709343SAfshin.Ardakani@Sun.COM vnode_t *xattrdvp;
3719343SAfshin.Ardakani@Sun.COM vnode_t *vp;
3729343SAfshin.Ardakani@Sun.COM int rc = 0;
3739343SAfshin.Ardakani@Sun.COM boolean_t fcreate = B_FALSE;
3749343SAfshin.Ardakani@Sun.COM
3759343SAfshin.Ardakani@Sun.COM /* Look up / create the unnamed stream, fname */
3769343SAfshin.Ardakani@Sun.COM rc = smb_fsop_lookup(sr, cr, flags | SMB_FOLLOW_LINKS,
37710001SJoyce.McIntosh@Sun.COM sr->tid_tree->t_snode, dnode, fname, &fnode);
3789343SAfshin.Ardakani@Sun.COM if (rc == ENOENT) {
3799343SAfshin.Ardakani@Sun.COM fcreate = B_TRUE;
3809343SAfshin.Ardakani@Sun.COM rc = smb_fsop_create_file(sr, cr, dnode, fname, flags,
38110001SJoyce.McIntosh@Sun.COM attr, &fnode);
3829343SAfshin.Ardakani@Sun.COM }
3839343SAfshin.Ardakani@Sun.COM if (rc != 0)
3849343SAfshin.Ardakani@Sun.COM return (rc);
3859343SAfshin.Ardakani@Sun.COM
38610001SJoyce.McIntosh@Sun.COM fattr.sa_mask = SMB_AT_UID | SMB_AT_GID;
38710001SJoyce.McIntosh@Sun.COM rc = smb_vop_getattr(fnode->vp, NULL, &fattr, 0, kcred);
38810001SJoyce.McIntosh@Sun.COM
38910001SJoyce.McIntosh@Sun.COM if (rc == 0) {
39010001SJoyce.McIntosh@Sun.COM /* create the named stream, sname */
39110001SJoyce.McIntosh@Sun.COM rc = smb_vop_stream_create(fnode->vp, sname, attr,
39210001SJoyce.McIntosh@Sun.COM &vp, &xattrdvp, flags, cr);
39310001SJoyce.McIntosh@Sun.COM }
3949343SAfshin.Ardakani@Sun.COM if (rc != 0) {
3959343SAfshin.Ardakani@Sun.COM if (fcreate) {
3969343SAfshin.Ardakani@Sun.COM flags &= ~SMB_IGNORE_CASE;
3979343SAfshin.Ardakani@Sun.COM (void) smb_vop_remove(dnode->vp,
3989343SAfshin.Ardakani@Sun.COM fnode->od_name, flags, cr);
3999343SAfshin.Ardakani@Sun.COM }
4009343SAfshin.Ardakani@Sun.COM smb_node_release(fnode);
4019343SAfshin.Ardakani@Sun.COM return (rc);
4029343SAfshin.Ardakani@Sun.COM }
4039343SAfshin.Ardakani@Sun.COM
4049343SAfshin.Ardakani@Sun.COM attr->sa_vattr.va_uid = fattr.sa_vattr.va_uid;
4059343SAfshin.Ardakani@Sun.COM attr->sa_vattr.va_gid = fattr.sa_vattr.va_gid;
4069343SAfshin.Ardakani@Sun.COM attr->sa_mask = SMB_AT_UID | SMB_AT_GID;
4079343SAfshin.Ardakani@Sun.COM
4089343SAfshin.Ardakani@Sun.COM rc = smb_vop_setattr(vp, NULL, attr, 0, kcred);
4099343SAfshin.Ardakani@Sun.COM if (rc != 0) {
4109343SAfshin.Ardakani@Sun.COM smb_node_release(fnode);
4119343SAfshin.Ardakani@Sun.COM return (rc);
4129343SAfshin.Ardakani@Sun.COM }
4139343SAfshin.Ardakani@Sun.COM
4149343SAfshin.Ardakani@Sun.COM *ret_snode = smb_stream_node_lookup(sr, cr, fnode, xattrdvp,
41510001SJoyce.McIntosh@Sun.COM vp, sname);
4169343SAfshin.Ardakani@Sun.COM
4179343SAfshin.Ardakani@Sun.COM smb_node_release(fnode);
4189343SAfshin.Ardakani@Sun.COM VN_RELE(xattrdvp);
4199343SAfshin.Ardakani@Sun.COM VN_RELE(vp);
4209343SAfshin.Ardakani@Sun.COM
4219343SAfshin.Ardakani@Sun.COM if (*ret_snode == NULL)
4229343SAfshin.Ardakani@Sun.COM rc = ENOMEM;
4239343SAfshin.Ardakani@Sun.COM
42411963SAfshin.Ardakani@Sun.COM /* notify change to the unnamed stream */
42511963SAfshin.Ardakani@Sun.COM if (rc == 0)
42611963SAfshin.Ardakani@Sun.COM smb_node_notify_change(dnode);
42711963SAfshin.Ardakani@Sun.COM
4289343SAfshin.Ardakani@Sun.COM return (rc);
4299343SAfshin.Ardakani@Sun.COM }
4309343SAfshin.Ardakani@Sun.COM
4319343SAfshin.Ardakani@Sun.COM /*
4329343SAfshin.Ardakani@Sun.COM * smb_fsop_create_file
4339343SAfshin.Ardakani@Sun.COM */
4349343SAfshin.Ardakani@Sun.COM static int
smb_fsop_create_file(smb_request_t * sr,cred_t * cr,smb_node_t * dnode,char * name,int flags,smb_attr_t * attr,smb_node_t ** ret_snode)4359343SAfshin.Ardakani@Sun.COM smb_fsop_create_file(smb_request_t *sr, cred_t *cr,
4369343SAfshin.Ardakani@Sun.COM smb_node_t *dnode, char *name, int flags,
43710001SJoyce.McIntosh@Sun.COM smb_attr_t *attr, smb_node_t **ret_snode)
4389343SAfshin.Ardakani@Sun.COM {
43912508Samw@Sun.COM smb_arg_open_t *op = &sr->sr_open;
4409343SAfshin.Ardakani@Sun.COM vnode_t *vp;
4419343SAfshin.Ardakani@Sun.COM smb_fssd_t fs_sd;
4429343SAfshin.Ardakani@Sun.COM uint32_t secinfo;
4439343SAfshin.Ardakani@Sun.COM uint32_t status;
4449343SAfshin.Ardakani@Sun.COM int rc = 0;
4459343SAfshin.Ardakani@Sun.COM
4469231SAfshin.Ardakani@Sun.COM if (op->sd) {
4479231SAfshin.Ardakani@Sun.COM /*
4489231SAfshin.Ardakani@Sun.COM * SD sent by client in Windows format. Needs to be
4499231SAfshin.Ardakani@Sun.COM * converted to FS format. No inheritance.
4509231SAfshin.Ardakani@Sun.COM */
4519231SAfshin.Ardakani@Sun.COM secinfo = smb_sd_get_secinfo(op->sd);
4529231SAfshin.Ardakani@Sun.COM smb_fssd_init(&fs_sd, secinfo, 0);
4539231SAfshin.Ardakani@Sun.COM
4549231SAfshin.Ardakani@Sun.COM status = smb_sd_tofs(op->sd, &fs_sd);
4559231SAfshin.Ardakani@Sun.COM if (status == NT_STATUS_SUCCESS) {
4569343SAfshin.Ardakani@Sun.COM rc = smb_fsop_create_with_sd(sr, cr, dnode,
45710001SJoyce.McIntosh@Sun.COM name, attr, ret_snode, &fs_sd);
4589231SAfshin.Ardakani@Sun.COM } else {
4599231SAfshin.Ardakani@Sun.COM rc = EINVAL;
4609231SAfshin.Ardakani@Sun.COM }
4619231SAfshin.Ardakani@Sun.COM smb_fssd_term(&fs_sd);
4629231SAfshin.Ardakani@Sun.COM } else if (sr->tid_tree->t_acltype == ACE_T) {
4639231SAfshin.Ardakani@Sun.COM /*
4649231SAfshin.Ardakani@Sun.COM * No incoming SD and filesystem is ZFS
4659231SAfshin.Ardakani@Sun.COM * Server applies Windows inheritance rules,
4669231SAfshin.Ardakani@Sun.COM * see smb_fsop_sdinherit() comments as to why.
4679231SAfshin.Ardakani@Sun.COM */
4689231SAfshin.Ardakani@Sun.COM smb_fssd_init(&fs_sd, SMB_ACL_SECINFO, 0);
4699343SAfshin.Ardakani@Sun.COM rc = smb_fsop_sdinherit(sr, dnode, &fs_sd);
4709231SAfshin.Ardakani@Sun.COM if (rc == 0) {
4719343SAfshin.Ardakani@Sun.COM rc = smb_fsop_create_with_sd(sr, cr, dnode,
47210001SJoyce.McIntosh@Sun.COM name, attr, ret_snode, &fs_sd);
4739231SAfshin.Ardakani@Sun.COM }
4749231SAfshin.Ardakani@Sun.COM
4759231SAfshin.Ardakani@Sun.COM smb_fssd_term(&fs_sd);
4769231SAfshin.Ardakani@Sun.COM } else {
4779231SAfshin.Ardakani@Sun.COM /*
4789231SAfshin.Ardakani@Sun.COM * No incoming SD and filesystem is not ZFS
4799231SAfshin.Ardakani@Sun.COM * let the filesystem handles the inheritance.
4809231SAfshin.Ardakani@Sun.COM */
4819343SAfshin.Ardakani@Sun.COM rc = smb_vop_create(dnode->vp, name, attr, &vp,
4829231SAfshin.Ardakani@Sun.COM flags, cr, NULL);
4839231SAfshin.Ardakani@Sun.COM
4849231SAfshin.Ardakani@Sun.COM if (rc == 0) {
4859231SAfshin.Ardakani@Sun.COM *ret_snode = smb_node_lookup(sr, op, cr, vp,
48610001SJoyce.McIntosh@Sun.COM name, dnode, NULL);
4879231SAfshin.Ardakani@Sun.COM
4889231SAfshin.Ardakani@Sun.COM if (*ret_snode == NULL)
4899231SAfshin.Ardakani@Sun.COM rc = ENOMEM;
4909231SAfshin.Ardakani@Sun.COM
4919231SAfshin.Ardakani@Sun.COM VN_RELE(vp);
4929231SAfshin.Ardakani@Sun.COM }
4939231SAfshin.Ardakani@Sun.COM
4949231SAfshin.Ardakani@Sun.COM }
49511963SAfshin.Ardakani@Sun.COM
49611963SAfshin.Ardakani@Sun.COM if (rc == 0)
49711963SAfshin.Ardakani@Sun.COM smb_node_notify_parents(dnode);
49811963SAfshin.Ardakani@Sun.COM
4995331Samw return (rc);
5005331Samw }
5015331Samw
5025331Samw /*
5035331Samw * smb_fsop_mkdir
5045331Samw *
5055331Samw * All SMB functions should use this wrapper to ensure that
5065331Samw * the the calls are performed with the appropriate credentials.
5075331Samw * Please document any direct call to explain the reason
5085331Samw * for avoiding this wrapper.
5095331Samw *
5105331Samw * It is assumed that a reference exists on snode coming into this routine.
5115331Samw *
5125331Samw * *ret_snode is returned with a reference upon success. No reference is
5135331Samw * taken if an error is returned.
5145331Samw */
5155331Samw int
smb_fsop_mkdir(smb_request_t * sr,cred_t * cr,smb_node_t * dnode,char * name,smb_attr_t * attr,smb_node_t ** ret_snode)5165331Samw smb_fsop_mkdir(
5176139Sjb150015 smb_request_t *sr,
5185331Samw cred_t *cr,
5199343SAfshin.Ardakani@Sun.COM smb_node_t *dnode,
5205331Samw char *name,
5215331Samw smb_attr_t *attr,
52210001SJoyce.McIntosh@Sun.COM smb_node_t **ret_snode)
5235331Samw {
5245331Samw struct open_param *op = &sr->arg.open;
5255331Samw char *longname;
5265331Samw vnode_t *vp;
5275331Samw int flags = 0;
5285331Samw smb_fssd_t fs_sd;
5295331Samw uint32_t secinfo;
5305331Samw uint32_t status;
5315331Samw int rc;
5325331Samw ASSERT(cr);
5339343SAfshin.Ardakani@Sun.COM ASSERT(dnode);
5349343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
5359343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
5365331Samw
5375331Samw ASSERT(ret_snode);
5385331Samw *ret_snode = 0;
5395331Samw
5405331Samw ASSERT(name);
5415331Samw if (*name == 0)
5425331Samw return (EINVAL);
5435331Samw
5445331Samw ASSERT(sr);
5455331Samw ASSERT(sr->tid_tree);
5467348SJose.Borrego@Sun.COM
5479343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0)
5487348SJose.Borrego@Sun.COM return (EACCES);
5497348SJose.Borrego@Sun.COM
5507348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
5515331Samw return (EROFS);
5529231SAfshin.Ardakani@Sun.COM if (SMB_TREE_SUPPORTS_CATIA(sr))
5539231SAfshin.Ardakani@Sun.COM flags |= SMB_CATIA;
55410504SKeyur.Desai@Sun.COM if (SMB_TREE_SUPPORTS_ABE(sr))
55510504SKeyur.Desai@Sun.COM flags |= SMB_ABE;
5565331Samw
557*12890SJoyce.McIntosh@Sun.COM if (SMB_TREE_SUPPORTS_SHORTNAMES(sr) && smb_maybe_mangled(name)) {
5585331Samw longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
55912508Samw@Sun.COM rc = smb_unmangle(dnode, name, longname, MAXNAMELEN, flags);
5605331Samw kmem_free(longname, MAXNAMELEN);
5615331Samw
5625331Samw /*
5635331Samw * If the name passed in by the client has an unmangled
5645331Samw * equivalent that is found in the specified directory,
5655331Samw * then the mkdir cannot succeed. Return EEXIST.
5665331Samw *
5675331Samw * Only if ENOENT is returned will a mkdir be attempted.
5685331Samw */
5695331Samw
5705331Samw if (rc == 0)
5715331Samw rc = EEXIST;
5725331Samw
5735331Samw if (rc != ENOENT)
5745331Samw return (rc);
5755331Samw }
5765331Samw
5777348SJose.Borrego@Sun.COM if (SMB_TREE_IS_CASEINSENSITIVE(sr))
5785331Samw flags = SMB_IGNORE_CASE;
5795331Samw
5805521Sas200622 if (op->sd) {
5815331Samw /*
5825331Samw * SD sent by client in Windows format. Needs to be
5835331Samw * converted to FS format. No inheritance.
5845331Samw */
5855521Sas200622 secinfo = smb_sd_get_secinfo(op->sd);
5865521Sas200622 smb_fssd_init(&fs_sd, secinfo, SMB_FSSD_FLAGS_DIR);
5875521Sas200622
5885521Sas200622 status = smb_sd_tofs(op->sd, &fs_sd);
5895331Samw if (status == NT_STATUS_SUCCESS) {
5909343SAfshin.Ardakani@Sun.COM rc = smb_fsop_create_with_sd(sr, cr, dnode,
59110001SJoyce.McIntosh@Sun.COM name, attr, ret_snode, &fs_sd);
5925331Samw }
5935331Samw else
5945331Samw rc = EINVAL;
5955521Sas200622 smb_fssd_term(&fs_sd);
5965331Samw } else if (sr->tid_tree->t_acltype == ACE_T) {
5975331Samw /*
5985331Samw * No incoming SD and filesystem is ZFS
5995331Samw * Server applies Windows inheritance rules,
6005331Samw * see smb_fsop_sdinherit() comments as to why.
6015331Samw */
6025521Sas200622 smb_fssd_init(&fs_sd, SMB_ACL_SECINFO, SMB_FSSD_FLAGS_DIR);
6039343SAfshin.Ardakani@Sun.COM rc = smb_fsop_sdinherit(sr, dnode, &fs_sd);
6045331Samw if (rc == 0) {
6059343SAfshin.Ardakani@Sun.COM rc = smb_fsop_create_with_sd(sr, cr, dnode,
60610001SJoyce.McIntosh@Sun.COM name, attr, ret_snode, &fs_sd);
6075331Samw }
6085331Samw
6095521Sas200622 smb_fssd_term(&fs_sd);
6105331Samw
6115331Samw } else {
6129343SAfshin.Ardakani@Sun.COM rc = smb_vop_mkdir(dnode->vp, name, attr, &vp, flags, cr,
6135772Sas200622 NULL);
6145331Samw
6155331Samw if (rc == 0) {
6165331Samw *ret_snode = smb_node_lookup(sr, op, cr, vp, name,
61710001SJoyce.McIntosh@Sun.COM dnode, NULL);
6185331Samw
6198670SJose.Borrego@Sun.COM if (*ret_snode == NULL)
6205331Samw rc = ENOMEM;
6218670SJose.Borrego@Sun.COM
6228670SJose.Borrego@Sun.COM VN_RELE(vp);
6235331Samw }
6245331Samw }
6255331Samw
62611963SAfshin.Ardakani@Sun.COM if (rc == 0)
62711963SAfshin.Ardakani@Sun.COM smb_node_notify_parents(dnode);
62811963SAfshin.Ardakani@Sun.COM
6295331Samw return (rc);
6305331Samw }
6315331Samw
6325331Samw /*
6335331Samw * smb_fsop_remove
6345331Samw *
6355331Samw * All SMB functions should use this wrapper to ensure that
6365331Samw * the the calls are performed with the appropriate credentials.
6375331Samw * Please document any direct call to explain the reason
6385331Samw * for avoiding this wrapper.
6395331Samw *
6405331Samw * It is assumed that a reference exists on snode coming into this routine.
6415331Samw *
6425331Samw * A null smb_request might be passed to this function.
6435331Samw */
6445331Samw int
smb_fsop_remove(smb_request_t * sr,cred_t * cr,smb_node_t * dnode,char * name,uint32_t flags)6455331Samw smb_fsop_remove(
6466139Sjb150015 smb_request_t *sr,
6476139Sjb150015 cred_t *cr,
6489343SAfshin.Ardakani@Sun.COM smb_node_t *dnode,
6496139Sjb150015 char *name,
6509231SAfshin.Ardakani@Sun.COM uint32_t flags)
6515331Samw {
6526139Sjb150015 smb_node_t *fnode;
6536139Sjb150015 char *longname;
6546139Sjb150015 char *fname;
6556139Sjb150015 char *sname;
6566139Sjb150015 int rc;
6575331Samw
6585331Samw ASSERT(cr);
6595331Samw /*
6605331Samw * The state of the node could be SMB_NODE_STATE_DESTROYING if this
6615331Samw * function is called during the deletion of the node (because of
6625331Samw * DELETE_ON_CLOSE).
6635331Samw */
6649343SAfshin.Ardakani@Sun.COM ASSERT(dnode);
6659343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
6665331Samw
6679343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0 ||
6688845Samw@Sun.COM SMB_TREE_HAS_ACCESS(sr, ACE_DELETE) == 0)
6695331Samw return (EACCES);
6705331Samw
6717348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
6725331Samw return (EROFS);
6735331Samw
6745331Samw fname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
6755331Samw sname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
6765331Samw
6779343SAfshin.Ardakani@Sun.COM if (dnode->flags & NODE_XATTR_DIR) {
67811963SAfshin.Ardakani@Sun.COM fnode = dnode->n_dnode;
67911963SAfshin.Ardakani@Sun.COM rc = smb_vop_stream_remove(fnode->vp, name, flags, cr);
68011963SAfshin.Ardakani@Sun.COM
68111963SAfshin.Ardakani@Sun.COM /* notify change to the unnamed stream */
68211963SAfshin.Ardakani@Sun.COM if ((rc == 0) && fnode->n_dnode)
68311963SAfshin.Ardakani@Sun.COM smb_node_notify_change(fnode->n_dnode);
68411963SAfshin.Ardakani@Sun.COM
6859343SAfshin.Ardakani@Sun.COM } else if (smb_is_stream_name(name)) {
6869343SAfshin.Ardakani@Sun.COM smb_stream_parse_name(name, fname, sname);
6878334SJose.Borrego@Sun.COM
6885967Scp160787 /*
6895331Samw * Look up the unnamed stream (i.e. fname).
6905331Samw * Unmangle processing will be done on fname
6915331Samw * as well as any link target.
6925331Samw */
6935331Samw
6945331Samw rc = smb_fsop_lookup(sr, cr, flags | SMB_FOLLOW_LINKS,
69510001SJoyce.McIntosh@Sun.COM sr->tid_tree->t_snode, dnode, fname, &fnode);
6965331Samw
6975331Samw if (rc != 0) {
6985331Samw kmem_free(fname, MAXNAMELEN);
6995331Samw kmem_free(sname, MAXNAMELEN);
7005331Samw return (rc);
7015331Samw }
7025331Samw
7035331Samw /*
7045331Samw * XXX
7055331Samw * Need to find out what permission is required by NTFS
7065331Samw * to remove a stream.
7075331Samw */
7085772Sas200622 rc = smb_vop_stream_remove(fnode->vp, sname, flags, cr);
7095331Samw
7105331Samw smb_node_release(fnode);
71111963SAfshin.Ardakani@Sun.COM
71211963SAfshin.Ardakani@Sun.COM /* notify change to the unnamed stream */
71311963SAfshin.Ardakani@Sun.COM if (rc == 0)
71411963SAfshin.Ardakani@Sun.COM smb_node_notify_change(dnode);
7155331Samw } else {
7169343SAfshin.Ardakani@Sun.COM rc = smb_vop_remove(dnode->vp, name, flags, cr);
7175331Samw
7185331Samw if (rc == ENOENT) {
719*12890SJoyce.McIntosh@Sun.COM if (!SMB_TREE_SUPPORTS_SHORTNAMES(sr) ||
720*12890SJoyce.McIntosh@Sun.COM !smb_maybe_mangled(name)) {
7215331Samw kmem_free(fname, MAXNAMELEN);
7225331Samw kmem_free(sname, MAXNAMELEN);
7235331Samw return (rc);
7245331Samw }
7255331Samw longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
7265331Samw
72710504SKeyur.Desai@Sun.COM if (SMB_TREE_SUPPORTS_ABE(sr))
72810504SKeyur.Desai@Sun.COM flags |= SMB_ABE;
72910504SKeyur.Desai@Sun.COM
73012508Samw@Sun.COM rc = smb_unmangle(dnode, name, longname, MAXNAMELEN,
73112508Samw@Sun.COM flags);
7325331Samw
7335331Samw if (rc == 0) {
7345331Samw /*
7359231SAfshin.Ardakani@Sun.COM * longname is the real (case-sensitive)
7369231SAfshin.Ardakani@Sun.COM * on-disk name.
7375331Samw * We make sure we do a remove on this exact
7385331Samw * name, as the name was mangled and denotes
7395331Samw * a unique file.
7405331Samw */
7415331Samw flags &= ~SMB_IGNORE_CASE;
7429343SAfshin.Ardakani@Sun.COM rc = smb_vop_remove(dnode->vp, longname,
7435772Sas200622 flags, cr);
7445331Samw }
7455331Samw
74611963SAfshin.Ardakani@Sun.COM if (rc == 0)
74711963SAfshin.Ardakani@Sun.COM smb_node_notify_parents(dnode);
74811963SAfshin.Ardakani@Sun.COM
7495331Samw kmem_free(longname, MAXNAMELEN);
7505331Samw }
7515331Samw }
7525331Samw
7535331Samw kmem_free(fname, MAXNAMELEN);
7545331Samw kmem_free(sname, MAXNAMELEN);
75511963SAfshin.Ardakani@Sun.COM
7565331Samw return (rc);
7575331Samw }
7585331Samw
7595331Samw /*
7605331Samw * smb_fsop_remove_streams
7615331Samw *
7625331Samw * This function removes a file's streams without removing the
7635331Samw * file itself.
7645331Samw *
7658670SJose.Borrego@Sun.COM * It is assumed that fnode is not a link.
7665331Samw */
7675331Samw int
smb_fsop_remove_streams(smb_request_t * sr,cred_t * cr,smb_node_t * fnode)7686139Sjb150015 smb_fsop_remove_streams(smb_request_t *sr, cred_t *cr, smb_node_t *fnode)
7695331Samw {
7708670SJose.Borrego@Sun.COM int rc, flags = 0;
7718670SJose.Borrego@Sun.COM uint16_t odid;
7728670SJose.Borrego@Sun.COM smb_odir_t *od;
7738670SJose.Borrego@Sun.COM smb_odirent_t *odirent;
7748670SJose.Borrego@Sun.COM boolean_t eos;
7755331Samw
7767348SJose.Borrego@Sun.COM ASSERT(sr);
7775331Samw ASSERT(cr);
7785331Samw ASSERT(fnode);
7795331Samw ASSERT(fnode->n_magic == SMB_NODE_MAGIC);
7805331Samw ASSERT(fnode->n_state != SMB_NODE_STATE_DESTROYING);
7815331Samw
7829343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, fnode) == 0) {
7839343SAfshin.Ardakani@Sun.COM smbsr_errno(sr, EACCES);
7849343SAfshin.Ardakani@Sun.COM return (-1);
7859343SAfshin.Ardakani@Sun.COM }
7865331Samw
7879343SAfshin.Ardakani@Sun.COM if (SMB_TREE_IS_READONLY(sr)) {
7889343SAfshin.Ardakani@Sun.COM smbsr_errno(sr, EROFS);
7899343SAfshin.Ardakani@Sun.COM return (-1);
7909343SAfshin.Ardakani@Sun.COM }
7915331Samw
7927348SJose.Borrego@Sun.COM if (SMB_TREE_IS_CASEINSENSITIVE(sr))
7935331Samw flags = SMB_IGNORE_CASE;
7949343SAfshin.Ardakani@Sun.COM
7959231SAfshin.Ardakani@Sun.COM if (SMB_TREE_SUPPORTS_CATIA(sr))
7969231SAfshin.Ardakani@Sun.COM flags |= SMB_CATIA;
7975331Samw
7989343SAfshin.Ardakani@Sun.COM if ((odid = smb_odir_openat(sr, fnode)) == 0) {
7999343SAfshin.Ardakani@Sun.COM smbsr_errno(sr, ENOENT);
8009343SAfshin.Ardakani@Sun.COM return (-1);
8019343SAfshin.Ardakani@Sun.COM }
8029343SAfshin.Ardakani@Sun.COM
8039343SAfshin.Ardakani@Sun.COM if ((od = smb_tree_lookup_odir(sr->tid_tree, odid)) == NULL) {
8049343SAfshin.Ardakani@Sun.COM smbsr_errno(sr, ENOENT);
8059343SAfshin.Ardakani@Sun.COM return (-1);
8069343SAfshin.Ardakani@Sun.COM }
8075331Samw
8088670SJose.Borrego@Sun.COM odirent = kmem_alloc(sizeof (smb_odirent_t), KM_SLEEP);
8098670SJose.Borrego@Sun.COM for (;;) {
8108670SJose.Borrego@Sun.COM rc = smb_odir_read(sr, od, odirent, &eos);
8118670SJose.Borrego@Sun.COM if ((rc != 0) || (eos))
8125331Samw break;
8138670SJose.Borrego@Sun.COM (void) smb_vop_remove(od->d_dnode->vp, odirent->od_name,
8148670SJose.Borrego@Sun.COM flags, cr);
8158670SJose.Borrego@Sun.COM }
8168670SJose.Borrego@Sun.COM kmem_free(odirent, sizeof (smb_odirent_t));
8175331Samw
8189635SJoyce.McIntosh@Sun.COM smb_odir_close(od);
8198670SJose.Borrego@Sun.COM smb_odir_release(od);
8205331Samw return (rc);
8215331Samw }
8225331Samw
8235331Samw /*
8245331Samw * smb_fsop_rmdir
8255331Samw *
8265331Samw * All SMB functions should use this wrapper to ensure that
8275331Samw * the the calls are performed with the appropriate credentials.
8285331Samw * Please document any direct call to explain the reason
8295331Samw * for avoiding this wrapper.
8305331Samw *
8315331Samw * It is assumed that a reference exists on snode coming into this routine.
8325331Samw */
8335331Samw int
smb_fsop_rmdir(smb_request_t * sr,cred_t * cr,smb_node_t * dnode,char * name,uint32_t flags)8345331Samw smb_fsop_rmdir(
8356139Sjb150015 smb_request_t *sr,
8366139Sjb150015 cred_t *cr,
8379343SAfshin.Ardakani@Sun.COM smb_node_t *dnode,
8386139Sjb150015 char *name,
8399231SAfshin.Ardakani@Sun.COM uint32_t flags)
8405331Samw {
8416139Sjb150015 int rc;
8426139Sjb150015 char *longname;
8435331Samw
8445331Samw ASSERT(cr);
8455331Samw /*
8465331Samw * The state of the node could be SMB_NODE_STATE_DESTROYING if this
8475331Samw * function is called during the deletion of the node (because of
8485331Samw * DELETE_ON_CLOSE).
8495331Samw */
8509343SAfshin.Ardakani@Sun.COM ASSERT(dnode);
8519343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
8525331Samw
8539343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0 ||
8548845Samw@Sun.COM SMB_TREE_HAS_ACCESS(sr, ACE_DELETE_CHILD) == 0)
8555331Samw return (EACCES);
8565331Samw
8577348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
8585331Samw return (EROFS);
8595331Samw
8609343SAfshin.Ardakani@Sun.COM rc = smb_vop_rmdir(dnode->vp, name, flags, cr);
8615331Samw
8625331Samw if (rc == ENOENT) {
863*12890SJoyce.McIntosh@Sun.COM if (!SMB_TREE_SUPPORTS_SHORTNAMES(sr) ||
864*12890SJoyce.McIntosh@Sun.COM !smb_maybe_mangled(name)) {
8655331Samw return (rc);
866*12890SJoyce.McIntosh@Sun.COM }
8675331Samw
8685331Samw longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
86910504SKeyur.Desai@Sun.COM
87010504SKeyur.Desai@Sun.COM if (SMB_TREE_SUPPORTS_ABE(sr))
87110504SKeyur.Desai@Sun.COM flags |= SMB_ABE;
87212508Samw@Sun.COM rc = smb_unmangle(dnode, name, longname, MAXNAMELEN, flags);
8735331Samw
8745331Samw if (rc == 0) {
8755331Samw /*
8769231SAfshin.Ardakani@Sun.COM * longname is the real (case-sensitive)
8779231SAfshin.Ardakani@Sun.COM * on-disk name.
8785331Samw * We make sure we do a rmdir on this exact
8795331Samw * name, as the name was mangled and denotes
8805331Samw * a unique directory.
8815331Samw */
8825331Samw flags &= ~SMB_IGNORE_CASE;
8839343SAfshin.Ardakani@Sun.COM rc = smb_vop_rmdir(dnode->vp, longname, flags, cr);
8845331Samw }
8855331Samw
8865331Samw kmem_free(longname, MAXNAMELEN);
8875331Samw }
8885331Samw
88911963SAfshin.Ardakani@Sun.COM if (rc == 0)
89011963SAfshin.Ardakani@Sun.COM smb_node_notify_parents(dnode);
89111963SAfshin.Ardakani@Sun.COM
8925331Samw return (rc);
8935331Samw }
8945331Samw
8955331Samw /*
8965331Samw * smb_fsop_getattr
8975331Samw *
8985331Samw * All SMB functions should use this wrapper to ensure that
8995331Samw * the the calls are performed with the appropriate credentials.
9005331Samw * Please document any direct call to explain the reason
9015331Samw * for avoiding this wrapper.
9025331Samw *
9035331Samw * It is assumed that a reference exists on snode coming into this routine.
9045331Samw */
9055331Samw int
smb_fsop_getattr(smb_request_t * sr,cred_t * cr,smb_node_t * snode,smb_attr_t * attr)9066139Sjb150015 smb_fsop_getattr(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
9075331Samw smb_attr_t *attr)
9085331Samw {
9095331Samw smb_node_t *unnamed_node;
9105331Samw vnode_t *unnamed_vp = NULL;
9115331Samw uint32_t status;
9125331Samw uint32_t access = 0;
9135331Samw int flags = 0;
9145772Sas200622 int rc;
9155331Samw
9165331Samw ASSERT(cr);
9175331Samw ASSERT(snode);
9185331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
9195331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
9205331Samw
9218845Samw@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, snode) == 0 ||
9228845Samw@Sun.COM SMB_TREE_HAS_ACCESS(sr, ACE_READ_ATTRIBUTES) == 0)
9235331Samw return (EACCES);
9245331Samw
92510001SJoyce.McIntosh@Sun.COM /* sr could be NULL in some cases */
92610001SJoyce.McIntosh@Sun.COM if (sr && sr->fid_ofile) {
9275331Samw /* if uid and/or gid is requested */
9285331Samw if (attr->sa_mask & (SMB_AT_UID|SMB_AT_GID))
9295331Samw access |= READ_CONTROL;
9305331Samw
9315331Samw /* if anything else is also requested */
9325331Samw if (attr->sa_mask & ~(SMB_AT_UID|SMB_AT_GID))
9335331Samw access |= FILE_READ_ATTRIBUTES;
9345331Samw
9355331Samw status = smb_ofile_access(sr->fid_ofile, cr, access);
9365331Samw if (status != NT_STATUS_SUCCESS)
9375331Samw return (EACCES);
9385331Samw
9397348SJose.Borrego@Sun.COM if (smb_tree_has_feature(sr->tid_tree,
9407348SJose.Borrego@Sun.COM SMB_TREE_ACEMASKONACCESS))
9415331Samw flags = ATTR_NOACLCHECK;
9425331Samw }
9435331Samw
9445331Samw unnamed_node = SMB_IS_STREAM(snode);
9455331Samw
9465331Samw if (unnamed_node) {
9475331Samw ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
9485331Samw ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
9495331Samw unnamed_vp = unnamed_node->vp;
9505331Samw }
9515331Samw
9525772Sas200622 rc = smb_vop_getattr(snode->vp, unnamed_vp, attr, flags, cr);
95311963SAfshin.Ardakani@Sun.COM
95411963SAfshin.Ardakani@Sun.COM if ((rc == 0) && smb_node_is_dfslink(snode)) {
95511963SAfshin.Ardakani@Sun.COM /* a DFS link should be treated as a directory */
95611963SAfshin.Ardakani@Sun.COM attr->sa_dosattr |= FILE_ATTRIBUTE_DIRECTORY;
95711963SAfshin.Ardakani@Sun.COM }
95811963SAfshin.Ardakani@Sun.COM
9595772Sas200622 return (rc);
9605331Samw }
9615331Samw
9625331Samw /*
9639914Samw@Sun.COM * smb_fsop_link
9649914Samw@Sun.COM *
9659914Samw@Sun.COM * All SMB functions should use this smb_vop_link wrapper to ensure that
9669914Samw@Sun.COM * the smb_vop_link is performed with the appropriate credentials.
9679914Samw@Sun.COM * Please document any direct call to smb_vop_link to explain the reason
9689914Samw@Sun.COM * for avoiding this wrapper.
9699914Samw@Sun.COM *
9709914Samw@Sun.COM * It is assumed that references exist on from_dnode and to_dnode coming
9719914Samw@Sun.COM * into this routine.
9729914Samw@Sun.COM */
9739914Samw@Sun.COM int
smb_fsop_link(smb_request_t * sr,cred_t * cr,smb_node_t * from_fnode,smb_node_t * to_dnode,char * to_name)97410966SJordan.Brown@Sun.COM smb_fsop_link(smb_request_t *sr, cred_t *cr, smb_node_t *from_fnode,
97510966SJordan.Brown@Sun.COM smb_node_t *to_dnode, char *to_name)
9769914Samw@Sun.COM {
9779914Samw@Sun.COM char *longname = NULL;
9789914Samw@Sun.COM int flags = 0;
9799914Samw@Sun.COM int rc;
9809914Samw@Sun.COM
9819914Samw@Sun.COM ASSERT(sr);
9829914Samw@Sun.COM ASSERT(sr->tid_tree);
9839914Samw@Sun.COM ASSERT(cr);
9849914Samw@Sun.COM ASSERT(to_dnode);
9859914Samw@Sun.COM ASSERT(to_dnode->n_magic == SMB_NODE_MAGIC);
9869914Samw@Sun.COM ASSERT(to_dnode->n_state != SMB_NODE_STATE_DESTROYING);
9879914Samw@Sun.COM ASSERT(from_fnode);
9889914Samw@Sun.COM ASSERT(from_fnode->n_magic == SMB_NODE_MAGIC);
9899914Samw@Sun.COM ASSERT(from_fnode->n_state != SMB_NODE_STATE_DESTROYING);
9909914Samw@Sun.COM
9919914Samw@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, from_fnode) == 0)
9929914Samw@Sun.COM return (EACCES);
9939914Samw@Sun.COM
9949914Samw@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, to_dnode) == 0)
9959914Samw@Sun.COM return (EACCES);
9969914Samw@Sun.COM
9979914Samw@Sun.COM if (SMB_TREE_IS_READONLY(sr))
9989914Samw@Sun.COM return (EROFS);
9999914Samw@Sun.COM
10009914Samw@Sun.COM if (SMB_TREE_IS_CASEINSENSITIVE(sr))
10019914Samw@Sun.COM flags = SMB_IGNORE_CASE;
10029914Samw@Sun.COM if (SMB_TREE_SUPPORTS_CATIA(sr))
10039914Samw@Sun.COM flags |= SMB_CATIA;
100410504SKeyur.Desai@Sun.COM if (SMB_TREE_SUPPORTS_ABE(sr))
100510504SKeyur.Desai@Sun.COM flags |= SMB_ABE;
10069914Samw@Sun.COM
1007*12890SJoyce.McIntosh@Sun.COM if (SMB_TREE_SUPPORTS_SHORTNAMES(sr) && smb_maybe_mangled(to_name)) {
10089914Samw@Sun.COM longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
100912508Samw@Sun.COM rc = smb_unmangle(to_dnode, to_name, longname,
101012508Samw@Sun.COM MAXNAMELEN, flags);
10119914Samw@Sun.COM kmem_free(longname, MAXNAMELEN);
10129914Samw@Sun.COM
10139914Samw@Sun.COM if (rc == 0)
10149914Samw@Sun.COM rc = EEXIST;
10159914Samw@Sun.COM if (rc != ENOENT)
10169914Samw@Sun.COM return (rc);
10179914Samw@Sun.COM }
10189914Samw@Sun.COM
10199914Samw@Sun.COM rc = smb_vop_link(to_dnode->vp, from_fnode->vp, to_name, flags, cr);
102011963SAfshin.Ardakani@Sun.COM
102111963SAfshin.Ardakani@Sun.COM if ((rc == 0) && from_fnode->n_dnode)
102211963SAfshin.Ardakani@Sun.COM smb_node_notify_parents(from_fnode->n_dnode);
102311963SAfshin.Ardakani@Sun.COM
10249914Samw@Sun.COM return (rc);
10259914Samw@Sun.COM }
10269914Samw@Sun.COM
10279914Samw@Sun.COM /*
10285331Samw * smb_fsop_rename
10295331Samw *
10305331Samw * All SMB functions should use this smb_vop_rename wrapper to ensure that
10315331Samw * the smb_vop_rename is performed with the appropriate credentials.
10325331Samw * Please document any direct call to smb_vop_rename to explain the reason
10335331Samw * for avoiding this wrapper.
10345331Samw *
10359343SAfshin.Ardakani@Sun.COM * It is assumed that references exist on from_dnode and to_dnode coming
10365331Samw * into this routine.
10375331Samw */
10385331Samw int
smb_fsop_rename(smb_request_t * sr,cred_t * cr,smb_node_t * from_dnode,char * from_name,smb_node_t * to_dnode,char * to_name)10395331Samw smb_fsop_rename(
10406139Sjb150015 smb_request_t *sr,
10415331Samw cred_t *cr,
10429343SAfshin.Ardakani@Sun.COM smb_node_t *from_dnode,
10435331Samw char *from_name,
10449343SAfshin.Ardakani@Sun.COM smb_node_t *to_dnode,
10455331Samw char *to_name)
10465331Samw {
10475331Samw smb_node_t *from_snode;
104811963SAfshin.Ardakani@Sun.COM smb_attr_t from_attr;
10495331Samw vnode_t *from_vp;
10509231SAfshin.Ardakani@Sun.COM int flags = 0, ret_flags;
10515331Samw int rc;
10528845Samw@Sun.COM boolean_t isdir;
10535331Samw
10545331Samw ASSERT(cr);
10559343SAfshin.Ardakani@Sun.COM ASSERT(from_dnode);
10569343SAfshin.Ardakani@Sun.COM ASSERT(from_dnode->n_magic == SMB_NODE_MAGIC);
10579343SAfshin.Ardakani@Sun.COM ASSERT(from_dnode->n_state != SMB_NODE_STATE_DESTROYING);
10585331Samw
10599343SAfshin.Ardakani@Sun.COM ASSERT(to_dnode);
10609343SAfshin.Ardakani@Sun.COM ASSERT(to_dnode->n_magic == SMB_NODE_MAGIC);
10619343SAfshin.Ardakani@Sun.COM ASSERT(to_dnode->n_state != SMB_NODE_STATE_DESTROYING);
10625331Samw
10639343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, from_dnode) == 0)
10645331Samw return (EACCES);
10655331Samw
10669343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, to_dnode) == 0)
10675331Samw return (EACCES);
10685331Samw
10695331Samw ASSERT(sr);
10705331Samw ASSERT(sr->tid_tree);
10717348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
10725331Samw return (EROFS);
10735331Samw
10745331Samw /*
10757348SJose.Borrego@Sun.COM * Note: There is no need to check SMB_TREE_IS_CASEINSENSITIVE
10765331Samw * here.
10775331Samw *
10785331Samw * A case-sensitive rename is always done in this routine
10795331Samw * because we are using the on-disk name from an earlier lookup.
10805331Samw * If a mangled name was passed in by the caller (denoting a
10815331Samw * deterministic lookup), then the exact file must be renamed
10825331Samw * (i.e. SMB_IGNORE_CASE must not be passed to VOP_RENAME, or
10835331Samw * else the underlying file system might return a "first-match"
10845331Samw * on this on-disk name, possibly resulting in the wrong file).
10855331Samw */
10865331Samw
10879231SAfshin.Ardakani@Sun.COM if (SMB_TREE_SUPPORTS_CATIA(sr))
10889231SAfshin.Ardakani@Sun.COM flags |= SMB_CATIA;
10899231SAfshin.Ardakani@Sun.COM
10905331Samw /*
10915331Samw * XXX: Lock required through smb_node_release() below?
10925331Samw */
10935331Samw
10949343SAfshin.Ardakani@Sun.COM rc = smb_vop_lookup(from_dnode->vp, from_name, &from_vp, NULL,
109511963SAfshin.Ardakani@Sun.COM flags, &ret_flags, NULL, &from_attr, cr);
10965331Samw
10975331Samw if (rc != 0)
10985331Samw return (rc);
10995331Samw
110011963SAfshin.Ardakani@Sun.COM if (from_attr.sa_dosattr & FILE_ATTRIBUTE_REPARSE_POINT) {
110111963SAfshin.Ardakani@Sun.COM VN_RELE(from_vp);
110211963SAfshin.Ardakani@Sun.COM return (EACCES);
110311963SAfshin.Ardakani@Sun.COM }
110411963SAfshin.Ardakani@Sun.COM
110511963SAfshin.Ardakani@Sun.COM isdir = ((from_attr.sa_dosattr & FILE_ATTRIBUTE_DIRECTORY) != 0);
11068845Samw@Sun.COM
11078845Samw@Sun.COM if ((isdir && SMB_TREE_HAS_ACCESS(sr,
11088845Samw@Sun.COM ACE_DELETE_CHILD | ACE_ADD_SUBDIRECTORY) !=
11098845Samw@Sun.COM (ACE_DELETE_CHILD | ACE_ADD_SUBDIRECTORY)) ||
11108845Samw@Sun.COM (!isdir && SMB_TREE_HAS_ACCESS(sr, ACE_DELETE | ACE_ADD_FILE) !=
111111963SAfshin.Ardakani@Sun.COM (ACE_DELETE | ACE_ADD_FILE))) {
111211963SAfshin.Ardakani@Sun.COM VN_RELE(from_vp);
11138845Samw@Sun.COM return (EACCES);
111411963SAfshin.Ardakani@Sun.COM }
11158845Samw@Sun.COM
111610966SJordan.Brown@Sun.COM /*
111710966SJordan.Brown@Sun.COM * SMB checks access on open and retains an access granted
111810966SJordan.Brown@Sun.COM * mask for use while the file is open. ACL changes should
111910966SJordan.Brown@Sun.COM * not affect access to an open file.
112010966SJordan.Brown@Sun.COM *
112110966SJordan.Brown@Sun.COM * If the rename is being performed on an ofile:
112210966SJordan.Brown@Sun.COM * - Check the ofile's access granted mask to see if the
112310966SJordan.Brown@Sun.COM * rename is permitted - requires DELETE access.
112410966SJordan.Brown@Sun.COM * - If the file system does access checking, set the
112510966SJordan.Brown@Sun.COM * ATTR_NOACLCHECK flag to ensure that the file system
112610966SJordan.Brown@Sun.COM * does not check permissions on subsequent calls.
112710966SJordan.Brown@Sun.COM */
112810966SJordan.Brown@Sun.COM if (sr && sr->fid_ofile) {
112910966SJordan.Brown@Sun.COM rc = smb_ofile_access(sr->fid_ofile, cr, DELETE);
113011963SAfshin.Ardakani@Sun.COM if (rc != NT_STATUS_SUCCESS) {
113111963SAfshin.Ardakani@Sun.COM VN_RELE(from_vp);
113210966SJordan.Brown@Sun.COM return (EACCES);
113311963SAfshin.Ardakani@Sun.COM }
113410966SJordan.Brown@Sun.COM
113510966SJordan.Brown@Sun.COM if (smb_tree_has_feature(sr->tid_tree,
113610966SJordan.Brown@Sun.COM SMB_TREE_ACEMASKONACCESS))
113710966SJordan.Brown@Sun.COM flags = ATTR_NOACLCHECK;
113810966SJordan.Brown@Sun.COM }
113910966SJordan.Brown@Sun.COM
11409343SAfshin.Ardakani@Sun.COM rc = smb_vop_rename(from_dnode->vp, from_name, to_dnode->vp,
11415772Sas200622 to_name, flags, cr);
11425331Samw
11435331Samw if (rc == 0) {
11445331Samw from_snode = smb_node_lookup(sr, NULL, cr, from_vp, from_name,
114510001SJoyce.McIntosh@Sun.COM from_dnode, NULL);
11465331Samw
11475331Samw if (from_snode == NULL) {
11488670SJose.Borrego@Sun.COM rc = ENOMEM;
11498670SJose.Borrego@Sun.COM } else {
11509343SAfshin.Ardakani@Sun.COM smb_node_rename(from_dnode, from_snode,
11519343SAfshin.Ardakani@Sun.COM to_dnode, to_name);
11528670SJose.Borrego@Sun.COM smb_node_release(from_snode);
11535331Samw }
11545331Samw }
11558670SJose.Borrego@Sun.COM VN_RELE(from_vp);
11565331Samw
115711963SAfshin.Ardakani@Sun.COM if (rc == 0)
115811963SAfshin.Ardakani@Sun.COM smb_node_notify_parents(from_dnode);
115911963SAfshin.Ardakani@Sun.COM
11605331Samw /* XXX: unlock */
11615331Samw
11625331Samw return (rc);
11635331Samw }
11645331Samw
11655331Samw /*
11665331Samw * smb_fsop_setattr
11675331Samw *
11685331Samw * All SMB functions should use this wrapper to ensure that
11695331Samw * the the calls are performed with the appropriate credentials.
11705331Samw * Please document any direct call to explain the reason
11715331Samw * for avoiding this wrapper.
11725331Samw *
117310504SKeyur.Desai@Sun.COM * It is assumed that a reference exists on snode coming into
117410504SKeyur.Desai@Sun.COM * this function.
11755331Samw * A null smb_request might be passed to this function.
11765331Samw */
11775331Samw int
smb_fsop_setattr(smb_request_t * sr,cred_t * cr,smb_node_t * snode,smb_attr_t * set_attr)11785331Samw smb_fsop_setattr(
11796139Sjb150015 smb_request_t *sr,
11806139Sjb150015 cred_t *cr,
11816139Sjb150015 smb_node_t *snode,
118210001SJoyce.McIntosh@Sun.COM smb_attr_t *set_attr)
11835331Samw {
11845331Samw smb_node_t *unnamed_node;
11855331Samw vnode_t *unnamed_vp = NULL;
11865331Samw uint32_t status;
11877619SJose.Borrego@Sun.COM uint32_t access;
11885331Samw int rc = 0;
11895331Samw int flags = 0;
11907619SJose.Borrego@Sun.COM uint_t sa_mask;
11915331Samw
11925331Samw ASSERT(cr);
11935331Samw ASSERT(snode);
11945331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
11955331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
11965331Samw
11977348SJose.Borrego@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, snode) == 0)
11985331Samw return (EACCES);
11995331Samw
12007348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
12015331Samw return (EROFS);
12025331Samw
12038845Samw@Sun.COM if (SMB_TREE_HAS_ACCESS(sr,
12048845Samw@Sun.COM ACE_WRITE_ATTRIBUTES | ACE_WRITE_NAMED_ATTRS) == 0)
12058845Samw@Sun.COM return (EACCES);
12068845Samw@Sun.COM
120710504SKeyur.Desai@Sun.COM /*
120810504SKeyur.Desai@Sun.COM * The file system cannot detect pending READDONLY
120910504SKeyur.Desai@Sun.COM * (i.e. if the file has been opened readonly but
121010504SKeyur.Desai@Sun.COM * not yet closed) so we need to test READONLY here.
121110504SKeyur.Desai@Sun.COM */
12127348SJose.Borrego@Sun.COM if (sr && (set_attr->sa_mask & SMB_AT_SIZE)) {
12137348SJose.Borrego@Sun.COM if (sr->fid_ofile) {
12147348SJose.Borrego@Sun.COM if (SMB_OFILE_IS_READONLY(sr->fid_ofile))
12157348SJose.Borrego@Sun.COM return (EACCES);
12167348SJose.Borrego@Sun.COM } else {
12177348SJose.Borrego@Sun.COM if (SMB_PATHFILE_IS_READONLY(sr, snode))
12187348SJose.Borrego@Sun.COM return (EACCES);
12197348SJose.Borrego@Sun.COM }
12207348SJose.Borrego@Sun.COM }
12217348SJose.Borrego@Sun.COM
122210504SKeyur.Desai@Sun.COM /*
122310504SKeyur.Desai@Sun.COM * SMB checks access on open and retains an access granted
122410504SKeyur.Desai@Sun.COM * mask for use while the file is open. ACL changes should
122510504SKeyur.Desai@Sun.COM * not affect access to an open file.
122610504SKeyur.Desai@Sun.COM *
122710504SKeyur.Desai@Sun.COM * If the setattr is being performed on an ofile:
122810504SKeyur.Desai@Sun.COM * - Check the ofile's access granted mask to see if the
122910504SKeyur.Desai@Sun.COM * setattr is permitted.
123010504SKeyur.Desai@Sun.COM * UID, GID - require WRITE_OWNER
123110504SKeyur.Desai@Sun.COM * SIZE, ALLOCSZ - require FILE_WRITE_DATA
123210504SKeyur.Desai@Sun.COM * all other attributes require FILE_WRITE_ATTRIBUTES
123310504SKeyur.Desai@Sun.COM *
123410504SKeyur.Desai@Sun.COM * - If the file system does access checking, set the
123510504SKeyur.Desai@Sun.COM * ATTR_NOACLCHECK flag to ensure that the file system
123610504SKeyur.Desai@Sun.COM * does not check permissions on subsequent calls.
123710504SKeyur.Desai@Sun.COM */
12385331Samw if (sr && sr->fid_ofile) {
12397619SJose.Borrego@Sun.COM sa_mask = set_attr->sa_mask;
12407619SJose.Borrego@Sun.COM access = 0;
12417619SJose.Borrego@Sun.COM
124210504SKeyur.Desai@Sun.COM if (sa_mask & (SMB_AT_SIZE | SMB_AT_ALLOCSZ)) {
12437619SJose.Borrego@Sun.COM access |= FILE_WRITE_DATA;
124410504SKeyur.Desai@Sun.COM sa_mask &= ~(SMB_AT_SIZE | SMB_AT_ALLOCSZ);
12457619SJose.Borrego@Sun.COM }
12467619SJose.Borrego@Sun.COM
12477619SJose.Borrego@Sun.COM if (sa_mask & (SMB_AT_UID|SMB_AT_GID)) {
12485331Samw access |= WRITE_OWNER;
12497619SJose.Borrego@Sun.COM sa_mask &= ~(SMB_AT_UID|SMB_AT_GID);
12507619SJose.Borrego@Sun.COM }
12517619SJose.Borrego@Sun.COM
12527619SJose.Borrego@Sun.COM if (sa_mask)
12535331Samw access |= FILE_WRITE_ATTRIBUTES;
12545331Samw
12555331Samw status = smb_ofile_access(sr->fid_ofile, cr, access);
12565331Samw if (status != NT_STATUS_SUCCESS)
12575331Samw return (EACCES);
12585331Samw
12597348SJose.Borrego@Sun.COM if (smb_tree_has_feature(sr->tid_tree,
12607348SJose.Borrego@Sun.COM SMB_TREE_ACEMASKONACCESS))
12615331Samw flags = ATTR_NOACLCHECK;
12625331Samw }
12635331Samw
12645331Samw unnamed_node = SMB_IS_STREAM(snode);
12655331Samw
12665331Samw if (unnamed_node) {
12675331Samw ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
12685331Samw ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
12695331Samw unnamed_vp = unnamed_node->vp;
12705331Samw }
12717757SJanice.Chang@Sun.COM
12727757SJanice.Chang@Sun.COM rc = smb_vop_setattr(snode->vp, unnamed_vp, set_attr, flags, cr);
12735331Samw return (rc);
12745331Samw }
12755331Samw
12765331Samw /*
12775331Samw * smb_fsop_read
12785331Samw *
12795331Samw * All SMB functions should use this wrapper to ensure that
12805331Samw * the the calls are performed with the appropriate credentials.
12815331Samw * Please document any direct call to explain the reason
12825331Samw * for avoiding this wrapper.
12835331Samw *
12845331Samw * It is assumed that a reference exists on snode coming into this routine.
12855331Samw */
12865331Samw int
smb_fsop_read(smb_request_t * sr,cred_t * cr,smb_node_t * snode,uio_t * uio)128710001SJoyce.McIntosh@Sun.COM smb_fsop_read(smb_request_t *sr, cred_t *cr, smb_node_t *snode, uio_t *uio)
12885331Samw {
12897348SJose.Borrego@Sun.COM caller_context_t ct;
12905772Sas200622 int svmand;
12915331Samw int rc;
12925331Samw
12935331Samw ASSERT(cr);
12945331Samw ASSERT(snode);
12955331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
12965331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
12975331Samw
12985331Samw ASSERT(sr);
12995331Samw ASSERT(sr->fid_ofile);
13005331Samw
13018845Samw@Sun.COM if (SMB_TREE_HAS_ACCESS(sr, ACE_READ_DATA) == 0)
13028845Samw@Sun.COM return (EACCES);
13038845Samw@Sun.COM
13045331Samw rc = smb_ofile_access(sr->fid_ofile, cr, FILE_READ_DATA);
130511963SAfshin.Ardakani@Sun.COM if ((rc != NT_STATUS_SUCCESS) &&
130611963SAfshin.Ardakani@Sun.COM (sr->smb_flg2 & SMB_FLAGS2_READ_IF_EXECUTE))
13075331Samw rc = smb_ofile_access(sr->fid_ofile, cr, FILE_EXECUTE);
130811963SAfshin.Ardakani@Sun.COM
130911963SAfshin.Ardakani@Sun.COM if (rc != NT_STATUS_SUCCESS)
131011963SAfshin.Ardakani@Sun.COM return (EACCES);
13115331Samw
131210001SJoyce.McIntosh@Sun.COM /*
131310001SJoyce.McIntosh@Sun.COM * Streams permission are checked against the unnamed stream,
131410001SJoyce.McIntosh@Sun.COM * but in FS level they have their own permissions. To avoid
131510001SJoyce.McIntosh@Sun.COM * rejection by FS due to lack of permission on the actual
131610001SJoyce.McIntosh@Sun.COM * extended attr kcred is passed for streams.
131710001SJoyce.McIntosh@Sun.COM */
131810001SJoyce.McIntosh@Sun.COM if (SMB_IS_STREAM(snode))
13195331Samw cr = kcred;
13205331Samw
13215772Sas200622 smb_node_start_crit(snode, RW_READER);
13227348SJose.Borrego@Sun.COM rc = nbl_svmand(snode->vp, kcred, &svmand);
13235772Sas200622 if (rc) {
13245772Sas200622 smb_node_end_crit(snode);
13255772Sas200622 return (rc);
13265772Sas200622 }
13275772Sas200622
13287348SJose.Borrego@Sun.COM ct = smb_ct;
13297348SJose.Borrego@Sun.COM ct.cc_pid = sr->fid_ofile->f_uniqid;
13305772Sas200622 rc = nbl_lock_conflict(snode->vp, NBL_READ, uio->uio_loffset,
13317348SJose.Borrego@Sun.COM uio->uio_iov->iov_len, svmand, &ct);
13325772Sas200622
13335772Sas200622 if (rc) {
13345772Sas200622 smb_node_end_crit(snode);
13356432Sas200622 return (ERANGE);
13365772Sas200622 }
133710001SJoyce.McIntosh@Sun.COM
13385772Sas200622 rc = smb_vop_read(snode->vp, uio, cr);
13395772Sas200622 smb_node_end_crit(snode);
13405772Sas200622
13415331Samw return (rc);
13425331Samw }
13435331Samw
13445331Samw /*
13455331Samw * smb_fsop_write
13465331Samw *
13475331Samw * This is a wrapper function used for smb_write and smb_write_raw operations.
13485331Samw *
13495331Samw * It is assumed that a reference exists on snode coming into this routine.
13505331Samw */
13515331Samw int
smb_fsop_write(smb_request_t * sr,cred_t * cr,smb_node_t * snode,uio_t * uio,uint32_t * lcount,int ioflag)13525331Samw smb_fsop_write(
13536139Sjb150015 smb_request_t *sr,
13545331Samw cred_t *cr,
13555331Samw smb_node_t *snode,
13565331Samw uio_t *uio,
13575331Samw uint32_t *lcount,
13587052Samw int ioflag)
13595331Samw {
13607348SJose.Borrego@Sun.COM caller_context_t ct;
13615772Sas200622 int svmand;
13625331Samw int rc;
13635331Samw
13645331Samw ASSERT(cr);
13655331Samw ASSERT(snode);
13665331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
13675331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
13685331Samw
13695331Samw ASSERT(sr);
13705331Samw ASSERT(sr->tid_tree);
13715331Samw ASSERT(sr->fid_ofile);
13725331Samw
13737348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
13745331Samw return (EROFS);
13755772Sas200622
13768845Samw@Sun.COM if (SMB_OFILE_IS_READONLY(sr->fid_ofile) ||
13778845Samw@Sun.COM SMB_TREE_HAS_ACCESS(sr, ACE_WRITE_DATA | ACE_APPEND_DATA) == 0)
13787348SJose.Borrego@Sun.COM return (EACCES);
13797348SJose.Borrego@Sun.COM
13805331Samw rc = smb_ofile_access(sr->fid_ofile, cr, FILE_WRITE_DATA);
13815772Sas200622 if (rc != NT_STATUS_SUCCESS) {
13825772Sas200622 rc = smb_ofile_access(sr->fid_ofile, cr, FILE_APPEND_DATA);
13835772Sas200622 if (rc != NT_STATUS_SUCCESS)
13845772Sas200622 return (EACCES);
13855772Sas200622 }
13865331Samw
138710001SJoyce.McIntosh@Sun.COM /*
138810001SJoyce.McIntosh@Sun.COM * Streams permission are checked against the unnamed stream,
138910001SJoyce.McIntosh@Sun.COM * but in FS level they have their own permissions. To avoid
139010001SJoyce.McIntosh@Sun.COM * rejection by FS due to lack of permission on the actual
139110001SJoyce.McIntosh@Sun.COM * extended attr kcred is passed for streams.
139210001SJoyce.McIntosh@Sun.COM */
139310001SJoyce.McIntosh@Sun.COM if (SMB_IS_STREAM(snode))
13945331Samw cr = kcred;
13955331Samw
13965772Sas200622 smb_node_start_crit(snode, RW_READER);
13977348SJose.Borrego@Sun.COM rc = nbl_svmand(snode->vp, kcred, &svmand);
13985772Sas200622 if (rc) {
13995772Sas200622 smb_node_end_crit(snode);
14005772Sas200622 return (rc);
14015772Sas200622 }
14027348SJose.Borrego@Sun.COM
14037348SJose.Borrego@Sun.COM ct = smb_ct;
14047348SJose.Borrego@Sun.COM ct.cc_pid = sr->fid_ofile->f_uniqid;
14055772Sas200622 rc = nbl_lock_conflict(snode->vp, NBL_WRITE, uio->uio_loffset,
14067348SJose.Borrego@Sun.COM uio->uio_iov->iov_len, svmand, &ct);
14075772Sas200622
14085772Sas200622 if (rc) {
14095772Sas200622 smb_node_end_crit(snode);
14106432Sas200622 return (ERANGE);
14115772Sas200622 }
141210001SJoyce.McIntosh@Sun.COM
14137052Samw rc = smb_vop_write(snode->vp, uio, ioflag, lcount, cr);
14145772Sas200622 smb_node_end_crit(snode);
14155772Sas200622
14165331Samw return (rc);
14175331Samw }
14185331Samw
14195331Samw /*
14205331Samw * smb_fsop_statfs
14215331Samw *
14225331Samw * This is a wrapper function used for stat operations.
14235331Samw */
14245331Samw int
smb_fsop_statfs(cred_t * cr,smb_node_t * snode,struct statvfs64 * statp)14255331Samw smb_fsop_statfs(
14265331Samw cred_t *cr,
14275331Samw smb_node_t *snode,
14285331Samw struct statvfs64 *statp)
14295331Samw {
14305331Samw ASSERT(cr);
14315331Samw ASSERT(snode);
14325331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
14335331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
14345331Samw
14355331Samw return (smb_vop_statfs(snode->vp, statp, cr));
14365331Samw }
14375331Samw
14385331Samw /*
14395331Samw * smb_fsop_access
14406700Sjm199354 *
14416700Sjm199354 * Named streams do not have separate permissions from the associated
14426700Sjm199354 * unnamed stream. Thus, if node is a named stream, the permissions
14436700Sjm199354 * check will be performed on the associated unnamed stream.
14446700Sjm199354 *
14456700Sjm199354 * However, our named streams do have their own quarantine attribute,
14466700Sjm199354 * separate from that on the unnamed stream. If READ or EXECUTE
14476700Sjm199354 * access has been requested on a named stream, an additional access
14486700Sjm199354 * check is performed on the named stream in case it has been
14496700Sjm199354 * quarantined. kcred is used to avoid issues with the permissions
14506700Sjm199354 * set on the extended attribute file representing the named stream.
14515331Samw */
14525331Samw int
smb_fsop_access(smb_request_t * sr,cred_t * cr,smb_node_t * snode,uint32_t faccess)14535331Samw smb_fsop_access(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
14545331Samw uint32_t faccess)
14555331Samw {
14565331Samw int access = 0;
14575331Samw int error;
14585331Samw vnode_t *dir_vp;
14595331Samw boolean_t acl_check = B_TRUE;
14605331Samw smb_node_t *unnamed_node;
14615331Samw
14627348SJose.Borrego@Sun.COM ASSERT(sr);
14635331Samw ASSERT(cr);
14645331Samw ASSERT(snode);
14655331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
14665331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
14675331Samw
1468*12890SJoyce.McIntosh@Sun.COM /* Requests for no access should be denied. */
14695331Samw if (faccess == 0)
1470*12890SJoyce.McIntosh@Sun.COM return (NT_STATUS_ACCESS_DENIED);
14715331Samw
14727348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr)) {
14735331Samw if (faccess & (FILE_WRITE_DATA|FILE_APPEND_DATA|
14745331Samw FILE_WRITE_EA|FILE_DELETE_CHILD|FILE_WRITE_ATTRIBUTES|
14755331Samw DELETE|WRITE_DAC|WRITE_OWNER)) {
14765331Samw return (NT_STATUS_ACCESS_DENIED);
14775331Samw }
14785331Samw }
14795331Samw
148011963SAfshin.Ardakani@Sun.COM if (smb_node_is_reparse(snode) && (faccess & DELETE))
148111963SAfshin.Ardakani@Sun.COM return (NT_STATUS_ACCESS_DENIED);
148211963SAfshin.Ardakani@Sun.COM
14835331Samw unnamed_node = SMB_IS_STREAM(snode);
14845331Samw if (unnamed_node) {
14855331Samw ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
14865331Samw ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
14876700Sjm199354
14886700Sjm199354 /*
14896700Sjm199354 * Perform VREAD access check on the named stream in case it
14906700Sjm199354 * is quarantined. kcred is passed to smb_vop_access so it
14916700Sjm199354 * doesn't fail due to lack of permission.
14926700Sjm199354 */
14936700Sjm199354 if (faccess & (FILE_READ_DATA | FILE_EXECUTE)) {
14946700Sjm199354 error = smb_vop_access(snode->vp, VREAD,
14956700Sjm199354 0, NULL, kcred);
14966700Sjm199354 if (error)
14976700Sjm199354 return (NT_STATUS_ACCESS_DENIED);
14986700Sjm199354 }
14996700Sjm199354
15005331Samw /*
15015331Samw * Streams authorization should be performed against the
15025331Samw * unnamed stream.
15035331Samw */
15045331Samw snode = unnamed_node;
15055331Samw }
15065331Samw
15075331Samw if (faccess & ACCESS_SYSTEM_SECURITY) {
15085331Samw /*
15095331Samw * This permission is required for reading/writing SACL and
15105331Samw * it's not part of DACL. It's only granted via proper
15115331Samw * privileges.
15125331Samw */
15135331Samw if ((sr->uid_user->u_privileges &
15145331Samw (SMB_USER_PRIV_BACKUP |
15155331Samw SMB_USER_PRIV_RESTORE |
15165331Samw SMB_USER_PRIV_SECURITY)) == 0)
15175331Samw return (NT_STATUS_PRIVILEGE_NOT_HELD);
15185331Samw
15195331Samw faccess &= ~ACCESS_SYSTEM_SECURITY;
15205331Samw }
15215331Samw
15225331Samw /* Links don't have ACL */
15237348SJose.Borrego@Sun.COM if ((!smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACEMASKONACCESS)) ||
152411963SAfshin.Ardakani@Sun.COM smb_node_is_symlink(snode))
15255331Samw acl_check = B_FALSE;
15265331Samw
1527*12890SJoyce.McIntosh@Sun.COM /* Deny access based on the share access mask */
1528*12890SJoyce.McIntosh@Sun.COM
1529*12890SJoyce.McIntosh@Sun.COM if ((faccess & ~sr->tid_tree->t_access) != 0)
1530*12890SJoyce.McIntosh@Sun.COM return (NT_STATUS_ACCESS_DENIED);
15318845Samw@Sun.COM
15325331Samw if (acl_check) {
153310122SJordan.Brown@Sun.COM dir_vp = (snode->n_dnode) ? snode->n_dnode->vp : NULL;
15345331Samw error = smb_vop_access(snode->vp, faccess, V_ACE_MASK, dir_vp,
15355331Samw cr);
15365331Samw } else {
15375331Samw /*
15385331Samw * FS doesn't understand 32-bit mask, need to map
15395331Samw */
15405331Samw if (faccess & (FILE_WRITE_DATA | FILE_APPEND_DATA))
15415331Samw access |= VWRITE;
15425331Samw
15435331Samw if (faccess & FILE_READ_DATA)
15445331Samw access |= VREAD;
15455331Samw
15465331Samw if (faccess & FILE_EXECUTE)
15475331Samw access |= VEXEC;
15485331Samw
15495331Samw error = smb_vop_access(snode->vp, access, 0, NULL, cr);
15505331Samw }
15515331Samw
15525331Samw return ((error) ? NT_STATUS_ACCESS_DENIED : NT_STATUS_SUCCESS);
15535331Samw }
15545331Samw
15555331Samw /*
15565331Samw * smb_fsop_lookup_name()
15575331Samw *
15587961SNatalie.Li@Sun.COM * If name indicates that the file is a stream file, perform
15597961SNatalie.Li@Sun.COM * stream specific lookup, otherwise call smb_fsop_lookup.
15605331Samw *
15617961SNatalie.Li@Sun.COM * Return an error if the looked-up file is in outside the tree.
15627961SNatalie.Li@Sun.COM * (Required when invoked from open path.)
156312508Samw@Sun.COM *
156412508Samw@Sun.COM * Case sensitivity flags (SMB_IGNORE_CASE, SMB_CASE_SENSITIVE):
156512508Samw@Sun.COM * if SMB_CASE_SENSITIVE is set, the SMB_IGNORE_CASE flag will NOT be set
156612508Samw@Sun.COM * based on the tree's case sensitivity. However, if the SMB_IGNORE_CASE
156712508Samw@Sun.COM * flag is set in the flags value passed as a parameter, a case insensitive
156812508Samw@Sun.COM * lookup WILL be done (regardless of whether SMB_CASE_SENSITIVE is set
156912508Samw@Sun.COM * or not).
15705331Samw */
15715331Samw
15725331Samw int
smb_fsop_lookup_name(smb_request_t * sr,cred_t * cr,int flags,smb_node_t * root_node,smb_node_t * dnode,char * name,smb_node_t ** ret_snode)15735331Samw smb_fsop_lookup_name(
15746139Sjb150015 smb_request_t *sr,
15755331Samw cred_t *cr,
15765331Samw int flags,
15775331Samw smb_node_t *root_node,
15789343SAfshin.Ardakani@Sun.COM smb_node_t *dnode,
15795331Samw char *name,
158010001SJoyce.McIntosh@Sun.COM smb_node_t **ret_snode)
15815331Samw {
15826139Sjb150015 smb_node_t *fnode;
15836139Sjb150015 vnode_t *xattrdirvp;
15846139Sjb150015 vnode_t *vp;
15856139Sjb150015 char *od_name;
15866139Sjb150015 char *fname;
15876139Sjb150015 char *sname;
15886139Sjb150015 int rc;
15895331Samw
15905331Samw ASSERT(cr);
15919343SAfshin.Ardakani@Sun.COM ASSERT(dnode);
15929343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
15939343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
15945331Samw
15955331Samw /*
15965331Samw * The following check is required for streams processing, below
15975331Samw */
15985331Samw
159912508Samw@Sun.COM if (!(flags & SMB_CASE_SENSITIVE)) {
160012508Samw@Sun.COM if (SMB_TREE_IS_CASEINSENSITIVE(sr))
160112508Samw@Sun.COM flags |= SMB_IGNORE_CASE;
160212508Samw@Sun.COM }
16035331Samw
16045331Samw fname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
16055331Samw sname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
16065331Samw
16079343SAfshin.Ardakani@Sun.COM if (smb_is_stream_name(name)) {
16089343SAfshin.Ardakani@Sun.COM smb_stream_parse_name(name, fname, sname);
16098334SJose.Borrego@Sun.COM
16105331Samw /*
16115331Samw * Look up the unnamed stream (i.e. fname).
16125331Samw * Unmangle processing will be done on fname
16135331Samw * as well as any link target.
16145331Samw */
161510001SJoyce.McIntosh@Sun.COM rc = smb_fsop_lookup(sr, cr, flags, root_node, dnode,
161610001SJoyce.McIntosh@Sun.COM fname, &fnode);
16175331Samw
16185331Samw if (rc != 0) {
16195331Samw kmem_free(fname, MAXNAMELEN);
16205331Samw kmem_free(sname, MAXNAMELEN);
16215331Samw return (rc);
16225331Samw }
16235331Samw
16245331Samw od_name = kmem_alloc(MAXNAMELEN, KM_SLEEP);
16255331Samw
16265331Samw /*
16275331Samw * od_name is the on-disk name of the stream, except
16285331Samw * without the prepended stream prefix (SMB_STREAM_PREFIX)
16295331Samw */
16305331Samw
16315331Samw /*
16325331Samw * XXX
16335331Samw * What permissions NTFS requires for stream lookup if any?
16345331Samw */
16355331Samw rc = smb_vop_stream_lookup(fnode->vp, sname, &vp, od_name,
16365772Sas200622 &xattrdirvp, flags, root_node->vp, cr);
16375331Samw
16385331Samw if (rc != 0) {
16395331Samw smb_node_release(fnode);
16405331Samw kmem_free(fname, MAXNAMELEN);
16415331Samw kmem_free(sname, MAXNAMELEN);
16425331Samw kmem_free(od_name, MAXNAMELEN);
16435331Samw return (rc);
16445331Samw }
16455331Samw
16465331Samw *ret_snode = smb_stream_node_lookup(sr, cr, fnode, xattrdirvp,
164710001SJoyce.McIntosh@Sun.COM vp, od_name);
16485331Samw
16495331Samw kmem_free(od_name, MAXNAMELEN);
16505331Samw smb_node_release(fnode);
16518670SJose.Borrego@Sun.COM VN_RELE(xattrdirvp);
16528670SJose.Borrego@Sun.COM VN_RELE(vp);
16535331Samw
16545331Samw if (*ret_snode == NULL) {
16555331Samw kmem_free(fname, MAXNAMELEN);
16565331Samw kmem_free(sname, MAXNAMELEN);
16575331Samw return (ENOMEM);
16585331Samw }
16595331Samw } else {
16609343SAfshin.Ardakani@Sun.COM rc = smb_fsop_lookup(sr, cr, flags, root_node, dnode, name,
166110001SJoyce.McIntosh@Sun.COM ret_snode);
16625331Samw }
16635331Samw
16645331Samw if (rc == 0) {
16655331Samw ASSERT(ret_snode);
16667348SJose.Borrego@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, *ret_snode) == 0) {
16675331Samw smb_node_release(*ret_snode);
16685331Samw *ret_snode = NULL;
16695331Samw rc = EACCES;
16705331Samw }
16715331Samw }
16725331Samw
16735331Samw kmem_free(fname, MAXNAMELEN);
16745331Samw kmem_free(sname, MAXNAMELEN);
16755331Samw
16765331Samw return (rc);
16775331Samw }
16785331Samw
16795331Samw /*
16805331Samw * smb_fsop_lookup
16815331Samw *
16825331Samw * All SMB functions should use this smb_vop_lookup wrapper to ensure that
16835331Samw * the smb_vop_lookup is performed with the appropriate credentials and using
16845331Samw * case insensitive compares. Please document any direct call to smb_vop_lookup
16855331Samw * to explain the reason for avoiding this wrapper.
16865331Samw *
16879343SAfshin.Ardakani@Sun.COM * It is assumed that a reference exists on dnode coming into this routine
16885331Samw * (and that it is safe from deallocation).
16895331Samw *
16905331Samw * Same with the root_node.
16915331Samw *
16925331Samw * *ret_snode is returned with a reference upon success. No reference is
16935331Samw * taken if an error is returned.
16945331Samw *
16955331Samw * Note: The returned ret_snode may be in a child mount. This is ok for
16968670SJose.Borrego@Sun.COM * readdir.
16975331Samw *
16987348SJose.Borrego@Sun.COM * Other smb_fsop_* routines will call SMB_TREE_CONTAINS_NODE() to prevent
16995331Samw * operations on files not in the parent mount.
170010966SJordan.Brown@Sun.COM *
170110966SJordan.Brown@Sun.COM * Case sensitivity flags (SMB_IGNORE_CASE, SMB_CASE_SENSITIVE):
170210966SJordan.Brown@Sun.COM * if SMB_CASE_SENSITIVE is set, the SMB_IGNORE_CASE flag will NOT be set
170310966SJordan.Brown@Sun.COM * based on the tree's case sensitivity. However, if the SMB_IGNORE_CASE
170410966SJordan.Brown@Sun.COM * flag is set in the flags value passed as a parameter, a case insensitive
170510966SJordan.Brown@Sun.COM * lookup WILL be done (regardless of whether SMB_CASE_SENSITIVE is set
170610966SJordan.Brown@Sun.COM * or not).
17075331Samw */
17085331Samw int
smb_fsop_lookup(smb_request_t * sr,cred_t * cr,int flags,smb_node_t * root_node,smb_node_t * dnode,char * name,smb_node_t ** ret_snode)17095331Samw smb_fsop_lookup(
17106139Sjb150015 smb_request_t *sr,
17115331Samw cred_t *cr,
17125331Samw int flags,
17135331Samw smb_node_t *root_node,
17149343SAfshin.Ardakani@Sun.COM smb_node_t *dnode,
17155331Samw char *name,
171610001SJoyce.McIntosh@Sun.COM smb_node_t **ret_snode)
17175331Samw {
17185331Samw smb_node_t *lnk_target_node;
17195331Samw smb_node_t *lnk_dnode;
17205331Samw char *longname;
17215331Samw char *od_name;
17225331Samw vnode_t *vp;
17235331Samw int rc;
17249231SAfshin.Ardakani@Sun.COM int ret_flags;
172511963SAfshin.Ardakani@Sun.COM smb_attr_t attr;
17265331Samw
17275331Samw ASSERT(cr);
17289343SAfshin.Ardakani@Sun.COM ASSERT(dnode);
17299343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
17309343SAfshin.Ardakani@Sun.COM ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
17315331Samw
17325331Samw if (name == NULL)
17335331Samw return (EINVAL);
17345331Samw
17359343SAfshin.Ardakani@Sun.COM if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0)
17365331Samw return (EACCES);
17375331Samw
173810966SJordan.Brown@Sun.COM if (!(flags & SMB_CASE_SENSITIVE)) {
173910966SJordan.Brown@Sun.COM if (SMB_TREE_IS_CASEINSENSITIVE(sr))
174010966SJordan.Brown@Sun.COM flags |= SMB_IGNORE_CASE;
174110966SJordan.Brown@Sun.COM }
17429231SAfshin.Ardakani@Sun.COM if (SMB_TREE_SUPPORTS_CATIA(sr))
17439231SAfshin.Ardakani@Sun.COM flags |= SMB_CATIA;
174410504SKeyur.Desai@Sun.COM if (SMB_TREE_SUPPORTS_ABE(sr))
174510504SKeyur.Desai@Sun.COM flags |= SMB_ABE;
17465331Samw
17475331Samw od_name = kmem_alloc(MAXNAMELEN, KM_SLEEP);
17485331Samw
17499343SAfshin.Ardakani@Sun.COM rc = smb_vop_lookup(dnode->vp, name, &vp, od_name, flags,
175011963SAfshin.Ardakani@Sun.COM &ret_flags, root_node ? root_node->vp : NULL, &attr, cr);
17515331Samw
17525331Samw if (rc != 0) {
1753*12890SJoyce.McIntosh@Sun.COM if (!SMB_TREE_SUPPORTS_SHORTNAMES(sr) ||
1754*12890SJoyce.McIntosh@Sun.COM !smb_maybe_mangled(name)) {
17555331Samw kmem_free(od_name, MAXNAMELEN);
17565331Samw return (rc);
17575331Samw }
17585331Samw
17595331Samw longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
176012508Samw@Sun.COM rc = smb_unmangle(dnode, name, longname, MAXNAMELEN, flags);
17615331Samw if (rc != 0) {
17625331Samw kmem_free(od_name, MAXNAMELEN);
17635331Samw kmem_free(longname, MAXNAMELEN);
17645331Samw return (rc);
17655331Samw }
17665331Samw
17675331Samw /*
17689231SAfshin.Ardakani@Sun.COM * longname is the real (case-sensitive)
17699231SAfshin.Ardakani@Sun.COM * on-disk name.
17705331Samw * We make sure we do a lookup on this exact
17715331Samw * name, as the name was mangled and denotes
17725331Samw * a unique file.
17735331Samw */
17745331Samw
17755331Samw if (flags & SMB_IGNORE_CASE)
17765331Samw flags &= ~SMB_IGNORE_CASE;
17775331Samw
17789343SAfshin.Ardakani@Sun.COM rc = smb_vop_lookup(dnode->vp, longname, &vp, od_name,
177911963SAfshin.Ardakani@Sun.COM flags, &ret_flags, root_node ? root_node->vp : NULL, &attr,
178011963SAfshin.Ardakani@Sun.COM cr);
17815331Samw
17825331Samw kmem_free(longname, MAXNAMELEN);
17835331Samw
17845331Samw if (rc != 0) {
17855331Samw kmem_free(od_name, MAXNAMELEN);
17865331Samw return (rc);
17875331Samw }
17885331Samw }
17895331Samw
179011963SAfshin.Ardakani@Sun.COM if ((flags & SMB_FOLLOW_LINKS) && (vp->v_type == VLNK) &&
179111963SAfshin.Ardakani@Sun.COM ((attr.sa_dosattr & FILE_ATTRIBUTE_REPARSE_POINT) == 0)) {
17929343SAfshin.Ardakani@Sun.COM rc = smb_pathname(sr, od_name, FOLLOW, root_node, dnode,
17935331Samw &lnk_dnode, &lnk_target_node, cr);
17945331Samw
17955331Samw if (rc != 0) {
17965331Samw /*
17975331Samw * The link is assumed to be for the last component
17985331Samw * of a path. Hence any ENOTDIR error will be returned
17995331Samw * as ENOENT.
18005331Samw */
18015331Samw if (rc == ENOTDIR)
18025331Samw rc = ENOENT;
18035331Samw
18045331Samw VN_RELE(vp);
18055331Samw kmem_free(od_name, MAXNAMELEN);
18065331Samw return (rc);
18075331Samw }
18085331Samw
18095331Samw /*
18105331Samw * Release the original VLNK vnode
18115331Samw */
18125331Samw
18135331Samw VN_RELE(vp);
18145331Samw vp = lnk_target_node->vp;
18155331Samw
18165331Samw rc = smb_vop_traverse_check(&vp);
18175331Samw
18185331Samw if (rc != 0) {
18195331Samw smb_node_release(lnk_dnode);
18205331Samw smb_node_release(lnk_target_node);
18215331Samw kmem_free(od_name, MAXNAMELEN);
18225331Samw return (rc);
18235331Samw }
18245331Samw
18255331Samw /*
18265331Samw * smb_vop_traverse_check() may have returned a different vnode
18275331Samw */
18285331Samw
18295331Samw if (lnk_target_node->vp == vp) {
18305331Samw *ret_snode = lnk_target_node;
18315331Samw } else {
18325331Samw *ret_snode = smb_node_lookup(sr, NULL, cr, vp,
183310001SJoyce.McIntosh@Sun.COM lnk_target_node->od_name, lnk_dnode, NULL);
18348670SJose.Borrego@Sun.COM VN_RELE(vp);
18355331Samw
18368670SJose.Borrego@Sun.COM if (*ret_snode == NULL)
18375331Samw rc = ENOMEM;
18385331Samw smb_node_release(lnk_target_node);
18395331Samw }
18405331Samw
18415331Samw smb_node_release(lnk_dnode);
18425331Samw
18435331Samw } else {
18445331Samw
18455331Samw rc = smb_vop_traverse_check(&vp);
18465331Samw if (rc) {
18475331Samw VN_RELE(vp);
18485331Samw kmem_free(od_name, MAXNAMELEN);
18495331Samw return (rc);
18505331Samw }
18515331Samw
18525331Samw *ret_snode = smb_node_lookup(sr, NULL, cr, vp, od_name,
185310001SJoyce.McIntosh@Sun.COM dnode, NULL);
18548670SJose.Borrego@Sun.COM VN_RELE(vp);
18555331Samw
18568670SJose.Borrego@Sun.COM if (*ret_snode == NULL)
18575331Samw rc = ENOMEM;
18585331Samw }
18595331Samw
18605331Samw kmem_free(od_name, MAXNAMELEN);
18615331Samw return (rc);
18625331Samw }
18635331Samw
18645331Samw int /*ARGSUSED*/
smb_fsop_commit(smb_request_t * sr,cred_t * cr,smb_node_t * snode)18655331Samw smb_fsop_commit(smb_request_t *sr, cred_t *cr, smb_node_t *snode)
18665331Samw {
18675331Samw ASSERT(cr);
18685331Samw ASSERT(snode);
18695331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
18705331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
18715331Samw
18725331Samw ASSERT(sr);
18735331Samw ASSERT(sr->tid_tree);
18747348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
18755331Samw return (EROFS);
18765331Samw
18775772Sas200622 return (smb_vop_commit(snode->vp, cr));
18785331Samw }
18795331Samw
18805331Samw /*
18815331Samw * smb_fsop_aclread
18825331Samw *
18835331Samw * Retrieve filesystem ACL. Depends on requested ACLs in
18845331Samw * fs_sd->sd_secinfo, it'll set DACL and SACL pointers in
18855331Samw * fs_sd. Note that requesting a DACL/SACL doesn't mean that
18865331Samw * the corresponding field in fs_sd should be non-NULL upon
18875331Samw * return, since the target ACL might not contain that type of
18885331Samw * entries.
18895331Samw *
18905331Samw * Returned ACL is always in ACE_T (aka ZFS) format.
18915331Samw * If successful the allocated memory for the ACL should be freed
18925521Sas200622 * using smb_fsacl_free() or smb_fssd_term()
18935331Samw */
18945331Samw int
smb_fsop_aclread(smb_request_t * sr,cred_t * cr,smb_node_t * snode,smb_fssd_t * fs_sd)18955331Samw smb_fsop_aclread(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
18965331Samw smb_fssd_t *fs_sd)
18975331Samw {
18985331Samw int error = 0;
18995331Samw int flags = 0;
19005331Samw int access = 0;
19015331Samw acl_t *acl;
19025331Samw smb_node_t *unnamed_node;
19035331Samw
19045331Samw ASSERT(cr);
19055331Samw
19068845Samw@Sun.COM if (SMB_TREE_HAS_ACCESS(sr, ACE_READ_ACL) == 0)
19078845Samw@Sun.COM return (EACCES);
19088845Samw@Sun.COM
19095331Samw if (sr->fid_ofile) {
19105331Samw if (fs_sd->sd_secinfo & SMB_DACL_SECINFO)
19115331Samw access = READ_CONTROL;
19125331Samw
19135331Samw if (fs_sd->sd_secinfo & SMB_SACL_SECINFO)
19145331Samw access |= ACCESS_SYSTEM_SECURITY;
19155331Samw
19165331Samw error = smb_ofile_access(sr->fid_ofile, cr, access);
19175331Samw if (error != NT_STATUS_SUCCESS) {
19185331Samw return (EACCES);
19195331Samw }
19205331Samw }
19215331Samw
19225331Samw unnamed_node = SMB_IS_STREAM(snode);
19235331Samw if (unnamed_node) {
19245331Samw ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
19255331Samw ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
19265331Samw /*
19275331Samw * Streams don't have ACL, any read ACL attempt on a stream
19285331Samw * should be performed on the unnamed stream.
19295331Samw */
19305331Samw snode = unnamed_node;
19315331Samw }
19325331Samw
19337348SJose.Borrego@Sun.COM if (smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACEMASKONACCESS))
19345331Samw flags = ATTR_NOACLCHECK;
19355331Samw
19365331Samw error = smb_vop_acl_read(snode->vp, &acl, flags,
19375772Sas200622 sr->tid_tree->t_acltype, cr);
19385331Samw if (error != 0) {
19395331Samw return (error);
19405331Samw }
19415331Samw
19425331Samw error = acl_translate(acl, _ACL_ACE_ENABLED,
194311963SAfshin.Ardakani@Sun.COM smb_node_is_dir(snode), fs_sd->sd_uid, fs_sd->sd_gid);
19445331Samw
19455331Samw if (error == 0) {
19465521Sas200622 smb_fsacl_split(acl, &fs_sd->sd_zdacl, &fs_sd->sd_zsacl,
19475331Samw fs_sd->sd_secinfo);
19485331Samw }
19495331Samw
19505331Samw acl_free(acl);
19515331Samw return (error);
19525331Samw }
19535331Samw
19545331Samw /*
19555331Samw * smb_fsop_aclwrite
19565331Samw *
19575331Samw * Stores the filesystem ACL provided in fs_sd->sd_acl.
19585331Samw */
19595331Samw int
smb_fsop_aclwrite(smb_request_t * sr,cred_t * cr,smb_node_t * snode,smb_fssd_t * fs_sd)19605331Samw smb_fsop_aclwrite(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
19615331Samw smb_fssd_t *fs_sd)
19625331Samw {
19635331Samw int target_flavor;
19645331Samw int error = 0;
19655331Samw int flags = 0;
19665331Samw int access = 0;
19675331Samw acl_t *acl, *dacl, *sacl;
19685331Samw smb_node_t *unnamed_node;
19695331Samw
19705331Samw ASSERT(cr);
19715331Samw
19725331Samw ASSERT(sr);
19735331Samw ASSERT(sr->tid_tree);
19747348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
19755331Samw return (EROFS);
19765331Samw
19778845Samw@Sun.COM if (SMB_TREE_HAS_ACCESS(sr, ACE_WRITE_ACL) == 0)
19788845Samw@Sun.COM return (EACCES);
19798845Samw@Sun.COM
19805331Samw if (sr->fid_ofile) {
19815331Samw if (fs_sd->sd_secinfo & SMB_DACL_SECINFO)
19825331Samw access = WRITE_DAC;
19835331Samw
19845331Samw if (fs_sd->sd_secinfo & SMB_SACL_SECINFO)
19855331Samw access |= ACCESS_SYSTEM_SECURITY;
19865331Samw
19875331Samw error = smb_ofile_access(sr->fid_ofile, cr, access);
19885331Samw if (error != NT_STATUS_SUCCESS)
19895331Samw return (EACCES);
19905331Samw }
19915331Samw
19925331Samw switch (sr->tid_tree->t_acltype) {
19935331Samw case ACLENT_T:
19945331Samw target_flavor = _ACL_ACLENT_ENABLED;
19955331Samw break;
19965331Samw
19975331Samw case ACE_T:
19985331Samw target_flavor = _ACL_ACE_ENABLED;
19995331Samw break;
20005331Samw default:
20015331Samw return (EINVAL);
20025331Samw }
20035331Samw
20045331Samw unnamed_node = SMB_IS_STREAM(snode);
20055331Samw if (unnamed_node) {
20065331Samw ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
20075331Samw ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
20085331Samw /*
20095331Samw * Streams don't have ACL, any write ACL attempt on a stream
20105331Samw * should be performed on the unnamed stream.
20115331Samw */
20125331Samw snode = unnamed_node;
20135331Samw }
20145331Samw
20155331Samw dacl = fs_sd->sd_zdacl;
20165331Samw sacl = fs_sd->sd_zsacl;
20175331Samw
20185331Samw ASSERT(dacl || sacl);
20195331Samw if ((dacl == NULL) && (sacl == NULL))
20205331Samw return (EINVAL);
20215331Samw
20225331Samw if (dacl && sacl)
20235521Sas200622 acl = smb_fsacl_merge(dacl, sacl);
20245331Samw else if (dacl)
20255331Samw acl = dacl;
20265331Samw else
20275331Samw acl = sacl;
20285331Samw
202911963SAfshin.Ardakani@Sun.COM error = acl_translate(acl, target_flavor, smb_node_is_dir(snode),
20305331Samw fs_sd->sd_uid, fs_sd->sd_gid);
20315331Samw if (error == 0) {
20327348SJose.Borrego@Sun.COM if (smb_tree_has_feature(sr->tid_tree,
20337348SJose.Borrego@Sun.COM SMB_TREE_ACEMASKONACCESS))
20345331Samw flags = ATTR_NOACLCHECK;
20355331Samw
20365772Sas200622 error = smb_vop_acl_write(snode->vp, acl, flags, cr);
20375331Samw }
20385331Samw
20395331Samw if (dacl && sacl)
20405331Samw acl_free(acl);
20415331Samw
20425331Samw return (error);
20435331Samw }
20445331Samw
20455331Samw acl_type_t
smb_fsop_acltype(smb_node_t * snode)20465331Samw smb_fsop_acltype(smb_node_t *snode)
20475331Samw {
20485331Samw return (smb_vop_acl_type(snode->vp));
20495331Samw }
20505331Samw
20515331Samw /*
20525331Samw * smb_fsop_sdread
20535331Samw *
20545331Samw * Read the requested security descriptor items from filesystem.
20555331Samw * The items are specified in fs_sd->sd_secinfo.
20565331Samw */
20575331Samw int
smb_fsop_sdread(smb_request_t * sr,cred_t * cr,smb_node_t * snode,smb_fssd_t * fs_sd)20585331Samw smb_fsop_sdread(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
20595331Samw smb_fssd_t *fs_sd)
20605331Samw {
20615331Samw int error = 0;
20625331Samw int getowner = 0;
20635331Samw cred_t *ga_cred;
20645331Samw smb_attr_t attr;
20655331Samw
20665331Samw ASSERT(cr);
20675331Samw ASSERT(fs_sd);
20685331Samw
20695331Samw /*
20705331Samw * File's uid/gid is fetched in two cases:
20715331Samw *
20725331Samw * 1. it's explicitly requested
20735331Samw *
20745331Samw * 2. target ACL is ACE_T (ZFS ACL). They're needed for
20755331Samw * owner@/group@ entries. In this case kcred should be used
20765331Samw * because uid/gid are fetched on behalf of smb server.
20775331Samw */
20785331Samw if (fs_sd->sd_secinfo & (SMB_OWNER_SECINFO | SMB_GROUP_SECINFO)) {
20795331Samw getowner = 1;
20805331Samw ga_cred = cr;
20815331Samw } else if (sr->tid_tree->t_acltype == ACE_T) {
20825331Samw getowner = 1;
20835331Samw ga_cred = kcred;
20845331Samw }
20855331Samw
20865331Samw if (getowner) {
20875331Samw /*
20885331Samw * Windows require READ_CONTROL to read owner/group SID since
20895331Samw * they're part of Security Descriptor.
20905331Samw * ZFS only requires read_attribute. Need to have a explicit
20915331Samw * access check here.
20925331Samw */
20935331Samw if (sr->fid_ofile == NULL) {
20945331Samw error = smb_fsop_access(sr, ga_cred, snode,
20955331Samw READ_CONTROL);
20965331Samw if (error)
20979914Samw@Sun.COM return (EACCES);
20985331Samw }
20995331Samw
21005331Samw attr.sa_mask = SMB_AT_UID | SMB_AT_GID;
21015331Samw error = smb_fsop_getattr(sr, ga_cred, snode, &attr);
21025331Samw if (error == 0) {
21035331Samw fs_sd->sd_uid = attr.sa_vattr.va_uid;
21045331Samw fs_sd->sd_gid = attr.sa_vattr.va_gid;
21055331Samw } else {
21065331Samw return (error);
21075331Samw }
21085331Samw }
21095331Samw
21105331Samw if (fs_sd->sd_secinfo & SMB_ACL_SECINFO) {
21115331Samw error = smb_fsop_aclread(sr, cr, snode, fs_sd);
21125331Samw }
21135331Samw
21145331Samw return (error);
21155331Samw }
21165331Samw
21175331Samw /*
21185331Samw * smb_fsop_sdmerge
21195331Samw *
21205331Samw * From SMB point of view DACL and SACL are two separate list
21215331Samw * which can be manipulated independently without one affecting
21225331Samw * the other, but entries for both DACL and SACL will end up
21235331Samw * in the same ACL if target filesystem supports ACE_T ACLs.
21245331Samw *
21255331Samw * So, if either DACL or SACL is present in the client set request
21265331Samw * the entries corresponding to the non-present ACL shouldn't
21275331Samw * be touched in the FS ACL.
21285331Samw *
21295331Samw * fs_sd parameter contains DACL and SACL specified by SMB
21305331Samw * client to be set on a file/directory. The client could
21315331Samw * specify both or one of these ACLs (if none is specified
21325331Samw * we don't get this far). When both DACL and SACL are given
21335331Samw * by client the existing ACL should be overwritten. If only
21345331Samw * one of them is specified the entries corresponding to the other
21355331Samw * ACL should not be touched. For example, if only DACL
21365331Samw * is specified in input fs_sd, the function reads audit entries
21375331Samw * of the existing ACL of the file and point fs_sd->sd_zsdacl
21385331Samw * pointer to the fetched SACL, this way when smb_fsop_sdwrite()
21395331Samw * function is called the passed fs_sd would point to the specified
21405331Samw * DACL by client and fetched SACL from filesystem, so the file
21415331Samw * will end up with correct ACL.
21425331Samw */
21435331Samw static int
smb_fsop_sdmerge(smb_request_t * sr,smb_node_t * snode,smb_fssd_t * fs_sd)21445331Samw smb_fsop_sdmerge(smb_request_t *sr, smb_node_t *snode, smb_fssd_t *fs_sd)
21455331Samw {
21465331Samw smb_fssd_t cur_sd;
21475331Samw int error = 0;
21485331Samw
21495331Samw if (sr->tid_tree->t_acltype != ACE_T)
21505331Samw /* Don't bother if target FS doesn't support ACE_T */
21515331Samw return (0);
21525331Samw
21535331Samw if ((fs_sd->sd_secinfo & SMB_ACL_SECINFO) != SMB_ACL_SECINFO) {
21545331Samw if (fs_sd->sd_secinfo & SMB_DACL_SECINFO) {
21555331Samw /*
21565331Samw * Don't overwrite existing audit entries
21575331Samw */
21585521Sas200622 smb_fssd_init(&cur_sd, SMB_SACL_SECINFO,
21595331Samw fs_sd->sd_flags);
21605331Samw
21615331Samw error = smb_fsop_sdread(sr, kcred, snode, &cur_sd);
21625331Samw if (error == 0) {
21635331Samw ASSERT(fs_sd->sd_zsacl == NULL);
21645331Samw fs_sd->sd_zsacl = cur_sd.sd_zsacl;
21655331Samw if (fs_sd->sd_zsacl && fs_sd->sd_zdacl)
21665331Samw fs_sd->sd_zsacl->acl_flags =
21675331Samw fs_sd->sd_zdacl->acl_flags;
21685331Samw }
21695331Samw } else {
21705331Samw /*
21715331Samw * Don't overwrite existing access entries
21725331Samw */
21735521Sas200622 smb_fssd_init(&cur_sd, SMB_DACL_SECINFO,
21745331Samw fs_sd->sd_flags);
21755331Samw
21765331Samw error = smb_fsop_sdread(sr, kcred, snode, &cur_sd);
21775331Samw if (error == 0) {
21785331Samw ASSERT(fs_sd->sd_zdacl == NULL);
21795331Samw fs_sd->sd_zdacl = cur_sd.sd_zdacl;
21805331Samw if (fs_sd->sd_zdacl && fs_sd->sd_zsacl)
21815331Samw fs_sd->sd_zdacl->acl_flags =
21825331Samw fs_sd->sd_zsacl->acl_flags;
21835331Samw }
21845331Samw }
21855331Samw
21865331Samw if (error)
21875521Sas200622 smb_fssd_term(&cur_sd);
21885331Samw }
21895331Samw
21905331Samw return (error);
21915331Samw }
21925331Samw
21935331Samw /*
21945331Samw * smb_fsop_sdwrite
21955331Samw *
21965331Samw * Stores the given uid, gid and acl in filesystem.
21975331Samw * Provided items in fs_sd are specified by fs_sd->sd_secinfo.
21985331Samw *
21995331Samw * A SMB security descriptor could contain owner, primary group,
22005331Samw * DACL and SACL. Setting an SD should be atomic but here it has to
22015331Samw * be done via two separate FS operations: VOP_SETATTR and
22025331Samw * VOP_SETSECATTR. Therefore, this function has to simulate the
22035331Samw * atomicity as well as it can.
22047619SJose.Borrego@Sun.COM *
22057619SJose.Borrego@Sun.COM * Get the current uid, gid before setting the new uid/gid
22067619SJose.Borrego@Sun.COM * so if smb_fsop_aclwrite fails they can be restored. root cred is
22077619SJose.Borrego@Sun.COM * used to get currend uid/gid since this operation is performed on
22087619SJose.Borrego@Sun.COM * behalf of the server not the user.
22097619SJose.Borrego@Sun.COM *
22107619SJose.Borrego@Sun.COM * If setting uid/gid fails with EPERM it means that and invalid
22117619SJose.Borrego@Sun.COM * owner has been specified. Callers should translate this to
22127619SJose.Borrego@Sun.COM * STATUS_INVALID_OWNER which is not the normal mapping for EPERM
22137619SJose.Borrego@Sun.COM * in upper layers, so EPERM is mapped to EBADE.
22145331Samw */
22155331Samw int
smb_fsop_sdwrite(smb_request_t * sr,cred_t * cr,smb_node_t * snode,smb_fssd_t * fs_sd,int overwrite)22165331Samw smb_fsop_sdwrite(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
22175331Samw smb_fssd_t *fs_sd, int overwrite)
22185331Samw {
22195331Samw int error = 0;
22205331Samw int access = 0;
22215331Samw smb_attr_t set_attr;
22225331Samw smb_attr_t orig_attr;
22235331Samw
22245331Samw ASSERT(cr);
22255331Samw ASSERT(fs_sd);
22265331Samw
22275331Samw ASSERT(sr);
22285331Samw ASSERT(sr->tid_tree);
22297348SJose.Borrego@Sun.COM if (SMB_TREE_IS_READONLY(sr))
22305331Samw return (EROFS);
22315331Samw
22325331Samw bzero(&set_attr, sizeof (smb_attr_t));
22335331Samw
22345331Samw if (fs_sd->sd_secinfo & SMB_OWNER_SECINFO) {
22355331Samw set_attr.sa_vattr.va_uid = fs_sd->sd_uid;
22365331Samw set_attr.sa_mask |= SMB_AT_UID;
22377619SJose.Borrego@Sun.COM access |= WRITE_OWNER;
22385331Samw }
22395331Samw
22405331Samw if (fs_sd->sd_secinfo & SMB_GROUP_SECINFO) {
22415331Samw set_attr.sa_vattr.va_gid = fs_sd->sd_gid;
22425331Samw set_attr.sa_mask |= SMB_AT_GID;
22437619SJose.Borrego@Sun.COM access |= WRITE_OWNER;
22445331Samw }
22455331Samw
22465331Samw if (fs_sd->sd_secinfo & SMB_DACL_SECINFO)
22475331Samw access |= WRITE_DAC;
22485331Samw
22495331Samw if (fs_sd->sd_secinfo & SMB_SACL_SECINFO)
22505331Samw access |= ACCESS_SYSTEM_SECURITY;
22515331Samw
22525331Samw if (sr->fid_ofile)
22535331Samw error = smb_ofile_access(sr->fid_ofile, cr, access);
22545331Samw else
22555331Samw error = smb_fsop_access(sr, cr, snode, access);
22565331Samw
22575331Samw if (error)
22585331Samw return (EACCES);
22595331Samw
22605331Samw if (set_attr.sa_mask) {
22615331Samw orig_attr.sa_mask = SMB_AT_UID | SMB_AT_GID;
22625331Samw error = smb_fsop_getattr(sr, kcred, snode, &orig_attr);
22637619SJose.Borrego@Sun.COM if (error == 0) {
226410001SJoyce.McIntosh@Sun.COM error = smb_fsop_setattr(sr, cr, snode, &set_attr);
22657619SJose.Borrego@Sun.COM if (error == EPERM)
22667619SJose.Borrego@Sun.COM error = EBADE;
22677619SJose.Borrego@Sun.COM }
22685331Samw
22695331Samw if (error)
22705331Samw return (error);
22715331Samw }
22725331Samw
22735331Samw if (fs_sd->sd_secinfo & SMB_ACL_SECINFO) {
22745331Samw if (overwrite == 0) {
22755331Samw error = smb_fsop_sdmerge(sr, snode, fs_sd);
22765331Samw if (error)
22775331Samw return (error);
22785331Samw }
22795331Samw
22805331Samw error = smb_fsop_aclwrite(sr, cr, snode, fs_sd);
22815331Samw if (error) {
22825331Samw /*
22835331Samw * Revert uid/gid changes if required.
22845331Samw */
22855331Samw if (set_attr.sa_mask) {
22865331Samw orig_attr.sa_mask = set_attr.sa_mask;
22875331Samw (void) smb_fsop_setattr(sr, kcred, snode,
228810001SJoyce.McIntosh@Sun.COM &orig_attr);
22895331Samw }
22905331Samw }
22915331Samw }
22925331Samw
22935331Samw return (error);
22945331Samw }
22955331Samw
22965331Samw /*
22975331Samw * smb_fsop_sdinherit
22985331Samw *
22995331Samw * Inherit the security descriptor from the parent container.
23005331Samw * This function is called after FS has created the file/folder
23015331Samw * so if this doesn't do anything it means FS inheritance is
23025331Samw * in place.
23035331Samw *
23045331Samw * Do inheritance for ZFS internally.
23055331Samw *
23065331Samw * If we want to let ZFS does the inheritance the
23075331Samw * following setting should be true:
23085331Samw *
23095331Samw * - aclinherit = passthrough
23105331Samw * - aclmode = passthrough
23115331Samw * - smbd umask = 0777
23125331Samw *
23135331Samw * This will result in right effective permissions but
23145331Samw * ZFS will always add 6 ACEs for owner, owning group
23155331Samw * and others to be POSIX compliant. This is not what
23165331Samw * Windows clients/users expect, so we decided that CIFS
23175331Samw * implements Windows rules and overwrite whatever ZFS
23185331Samw * comes up with. This way we also don't have to care
23195331Samw * about ZFS aclinherit and aclmode settings.
23205331Samw */
23215331Samw static int
smb_fsop_sdinherit(smb_request_t * sr,smb_node_t * dnode,smb_fssd_t * fs_sd)23225331Samw smb_fsop_sdinherit(smb_request_t *sr, smb_node_t *dnode, smb_fssd_t *fs_sd)
23235331Samw {
23245521Sas200622 acl_t *dacl = NULL;
23255521Sas200622 acl_t *sacl = NULL;
232611963SAfshin.Ardakani@Sun.COM int is_dir;
23275331Samw int error;
23285331Samw
23295331Samw ASSERT(fs_sd);
23305331Samw
23315331Samw if (sr->tid_tree->t_acltype != ACE_T) {
23325331Samw /*
23335331Samw * No forced inheritance for non-ZFS filesystems.
23345331Samw */
23355331Samw fs_sd->sd_secinfo = 0;
23365331Samw return (0);
23375331Samw }
23385331Samw
23395331Samw
23405331Samw /* Fetch parent directory's ACL */
23415331Samw error = smb_fsop_sdread(sr, kcred, dnode, fs_sd);
23425331Samw if (error) {
23435331Samw return (error);
23445331Samw }
23455331Samw
23465331Samw is_dir = (fs_sd->sd_flags & SMB_FSSD_FLAGS_DIR);
23475521Sas200622 dacl = smb_fsacl_inherit(fs_sd->sd_zdacl, is_dir, SMB_DACL_SECINFO,
234811963SAfshin.Ardakani@Sun.COM sr->user_cr);
23495521Sas200622 sacl = smb_fsacl_inherit(fs_sd->sd_zsacl, is_dir, SMB_SACL_SECINFO,
235011963SAfshin.Ardakani@Sun.COM sr->user_cr);
23515331Samw
23525521Sas200622 if (sacl == NULL)
23535521Sas200622 fs_sd->sd_secinfo &= ~SMB_SACL_SECINFO;
23545521Sas200622
23555521Sas200622 smb_fsacl_free(fs_sd->sd_zdacl);
23565521Sas200622 smb_fsacl_free(fs_sd->sd_zsacl);
23575331Samw
23585331Samw fs_sd->sd_zdacl = dacl;
23595331Samw fs_sd->sd_zsacl = sacl;
23605331Samw
23615331Samw return (0);
23625331Samw }
23635331Samw
23645331Samw /*
23655331Samw * smb_fsop_eaccess
23665331Samw *
23675331Samw * Returns the effective permission of the given credential for the
23685331Samw * specified object.
23695331Samw *
23705331Samw * This is just a workaround. We need VFS/FS support for this.
23715331Samw */
23725331Samw void
smb_fsop_eaccess(smb_request_t * sr,cred_t * cr,smb_node_t * snode,uint32_t * eaccess)23735331Samw smb_fsop_eaccess(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
23745331Samw uint32_t *eaccess)
23755331Samw {
23765331Samw int access = 0;
23775331Samw vnode_t *dir_vp;
23785331Samw smb_node_t *unnamed_node;
23795331Samw
23805331Samw ASSERT(cr);
23815331Samw ASSERT(snode);
23825331Samw ASSERT(snode->n_magic == SMB_NODE_MAGIC);
23835331Samw ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
23845331Samw
23855331Samw unnamed_node = SMB_IS_STREAM(snode);
23865331Samw if (unnamed_node) {
23875331Samw ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
23885331Samw ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
23895331Samw /*
23905331Samw * Streams authorization should be performed against the
23915331Samw * unnamed stream.
23925331Samw */
23935331Samw snode = unnamed_node;
23945331Samw }
23955331Samw
23967348SJose.Borrego@Sun.COM if (smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACEMASKONACCESS)) {
239710122SJordan.Brown@Sun.COM dir_vp = (snode->n_dnode) ? snode->n_dnode->vp : NULL;
23985331Samw smb_vop_eaccess(snode->vp, (int *)eaccess, V_ACE_MASK, dir_vp,
23995331Samw cr);
24005331Samw return;
24015331Samw }
24025331Samw
24035331Samw /*
24045331Samw * FS doesn't understand 32-bit mask
24055331Samw */
24065331Samw smb_vop_eaccess(snode->vp, &access, 0, NULL, cr);
24078845Samw@Sun.COM access &= sr->tid_tree->t_access;
24085331Samw
24095331Samw *eaccess = READ_CONTROL | FILE_READ_EA | FILE_READ_ATTRIBUTES;
24105331Samw
24115331Samw if (access & VREAD)
24125331Samw *eaccess |= FILE_READ_DATA;
24135331Samw
24145331Samw if (access & VEXEC)
24155331Samw *eaccess |= FILE_EXECUTE;
24165331Samw
24175331Samw if (access & VWRITE)
24185331Samw *eaccess |= FILE_WRITE_DATA | FILE_WRITE_ATTRIBUTES |
24195331Samw FILE_WRITE_EA | FILE_APPEND_DATA | FILE_DELETE_CHILD;
24205331Samw }
24215521Sas200622
24225772Sas200622 /*
24235772Sas200622 * smb_fsop_shrlock
24245772Sas200622 *
24255772Sas200622 * For the current open request, check file sharing rules
24265772Sas200622 * against existing opens.
24275772Sas200622 *
24285772Sas200622 * Returns NT_STATUS_SHARING_VIOLATION if there is any
24295772Sas200622 * sharing conflict. Returns NT_STATUS_SUCCESS otherwise.
24305772Sas200622 *
24315772Sas200622 * Full system-wide share reservation synchronization is available
24325772Sas200622 * when the nbmand (non-blocking mandatory) mount option is set
24335772Sas200622 * (i.e. nbl_need_crit() is true) and nbmand critical regions are used.
24345772Sas200622 * This provides synchronization with NFS and local processes. The
24355772Sas200622 * critical regions are entered in VOP_SHRLOCK()/fs_shrlock() (called
24365772Sas200622 * from smb_open_subr()/smb_fsop_shrlock()/smb_vop_shrlock()) as well
24375772Sas200622 * as the CIFS rename and delete paths.
24385772Sas200622 *
24395772Sas200622 * The CIFS server will also enter the nbl critical region in the open,
24405772Sas200622 * rename, and delete paths when nbmand is not set. There is limited
24415772Sas200622 * coordination with local and VFS share reservations in this case.
24425772Sas200622 * Note that when the nbmand mount option is not set, the VFS layer
24435772Sas200622 * only processes advisory reservations and the delete mode is not checked.
24445772Sas200622 *
24455772Sas200622 * Whether or not the nbmand mount option is set, intra-CIFS share
24465772Sas200622 * checking is done in the open, delete, and rename paths using a CIFS
24475772Sas200622 * critical region (node->n_share_lock).
24485772Sas200622 */
24495772Sas200622 uint32_t
smb_fsop_shrlock(cred_t * cr,smb_node_t * node,uint32_t uniq_fid,uint32_t desired_access,uint32_t share_access)24506139Sjb150015 smb_fsop_shrlock(cred_t *cr, smb_node_t *node, uint32_t uniq_fid,
24515772Sas200622 uint32_t desired_access, uint32_t share_access)
24525772Sas200622 {
24535772Sas200622 int rc;
24545772Sas200622
24555772Sas200622 /* Allow access if the request is just for meta data */
24565772Sas200622 if ((desired_access & FILE_DATA_ALL) == 0)
24575772Sas200622 return (NT_STATUS_SUCCESS);
24585772Sas200622
245911963SAfshin.Ardakani@Sun.COM rc = smb_node_open_check(node, desired_access, share_access);
24605772Sas200622 if (rc)
24615772Sas200622 return (NT_STATUS_SHARING_VIOLATION);
24625772Sas200622
24635772Sas200622 rc = smb_vop_shrlock(node->vp, uniq_fid, desired_access, share_access,
24645772Sas200622 cr);
24655772Sas200622 if (rc)
24665772Sas200622 return (NT_STATUS_SHARING_VIOLATION);
24675772Sas200622
24685772Sas200622 return (NT_STATUS_SUCCESS);
24695772Sas200622 }
24705772Sas200622
24715521Sas200622 void
smb_fsop_unshrlock(cred_t * cr,smb_node_t * node,uint32_t uniq_fid)24725772Sas200622 smb_fsop_unshrlock(cred_t *cr, smb_node_t *node, uint32_t uniq_fid)
24735521Sas200622 {
24745772Sas200622 (void) smb_vop_unshrlock(node->vp, uniq_fid, cr);
24755772Sas200622 }
24766600Sas200622
24776600Sas200622 int
smb_fsop_frlock(smb_node_t * node,smb_lock_t * lock,boolean_t unlock,cred_t * cr)24786600Sas200622 smb_fsop_frlock(smb_node_t *node, smb_lock_t *lock, boolean_t unlock,
24796600Sas200622 cred_t *cr)
24806600Sas200622 {
24816600Sas200622 flock64_t bf;
24826600Sas200622 int flag = F_REMOTELOCK;
24836600Sas200622
24846771Sjb150015 /*
24856771Sjb150015 * VOP_FRLOCK() will not be called if:
24866771Sjb150015 *
24876771Sjb150015 * 1) The lock has a range of zero bytes. The semantics of Windows and
24886771Sjb150015 * POSIX are different. In the case of POSIX it asks for the locking
24896771Sjb150015 * of all the bytes from the offset provided until the end of the
24906771Sjb150015 * file. In the case of Windows a range of zero locks nothing and
24916771Sjb150015 * doesn't conflict with any other lock.
24926771Sjb150015 *
24936771Sjb150015 * 2) The lock rolls over (start + lenght < start). Solaris will assert
24946771Sjb150015 * if such a request is submitted. This will not create
24956771Sjb150015 * incompatibilities between POSIX and Windows. In the Windows world,
24966771Sjb150015 * if a client submits such a lock, the server will not lock any
24976771Sjb150015 * bytes. Interestingly if the same lock (same offset and length) is
24986771Sjb150015 * resubmitted Windows will consider that there is an overlap and
24996771Sjb150015 * the granting rules will then apply.
25006771Sjb150015 */
25016771Sjb150015 if ((lock->l_length == 0) ||
25026771Sjb150015 ((lock->l_start + lock->l_length - 1) < lock->l_start))
25036771Sjb150015 return (0);
25046771Sjb150015
25056600Sas200622 bzero(&bf, sizeof (bf));
25066600Sas200622
25076600Sas200622 if (unlock) {
25086600Sas200622 bf.l_type = F_UNLCK;
25096600Sas200622 } else if (lock->l_type == SMB_LOCK_TYPE_READONLY) {
25106600Sas200622 bf.l_type = F_RDLCK;
25116600Sas200622 flag |= FREAD;
25126600Sas200622 } else if (lock->l_type == SMB_LOCK_TYPE_READWRITE) {
25136600Sas200622 bf.l_type = F_WRLCK;
25146600Sas200622 flag |= FWRITE;
25156600Sas200622 }
25166600Sas200622
25176600Sas200622 bf.l_start = lock->l_start;
25186600Sas200622 bf.l_len = lock->l_length;
25197348SJose.Borrego@Sun.COM bf.l_pid = lock->l_file->f_uniqid;
25206600Sas200622 bf.l_sysid = smb_ct.cc_sysid;
25216600Sas200622
25226600Sas200622 return (smb_vop_frlock(node->vp, cr, flag, &bf));
25236600Sas200622 }
2524