xref: /onnv-gate/usr/src/uts/common/fs/smbsrv/smb_fsops.c (revision 9914:15092dda0737)
15331Samw /*
25331Samw  * CDDL HEADER START
35331Samw  *
45331Samw  * The contents of this file are subject to the terms of the
55331Samw  * Common Development and Distribution License (the "License").
65331Samw  * You may not use this file except in compliance with the License.
75331Samw  *
85331Samw  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
95331Samw  * or http://www.opensolaris.org/os/licensing.
105331Samw  * See the License for the specific language governing permissions
115331Samw  * and limitations under the License.
125331Samw  *
135331Samw  * When distributing Covered Code, include this CDDL HEADER in each
145331Samw  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
155331Samw  * If applicable, add the following below this CDDL HEADER, with the
165331Samw  * fields enclosed by brackets "[]" replaced with your own identifying
175331Samw  * information: Portions Copyright [yyyy] [name of copyright owner]
185331Samw  *
195331Samw  * CDDL HEADER END
205331Samw  */
215331Samw /*
228670SJose.Borrego@Sun.COM  * Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
235331Samw  * Use is subject to license terms.
245331Samw  */
255331Samw 
265331Samw #include <sys/sid.h>
275772Sas200622 #include <sys/nbmlock.h>
285331Samw #include <smbsrv/smb_fsops.h>
295521Sas200622 #include <smbsrv/smb_kproto.h>
305521Sas200622 #include <smbsrv/ntstatus.h>
315521Sas200622 #include <smbsrv/ntaccess.h>
325772Sas200622 #include <smbsrv/smb_incl.h>
335331Samw #include <acl/acl_common.h>
345772Sas200622 #include <sys/fcntl.h>
355772Sas200622 #include <sys/flock.h>
365772Sas200622 #include <fs/fs_subr.h>
375331Samw 
386139Sjb150015 extern caller_context_t smb_ct;
396139Sjb150015 
406600Sas200622 extern int smb_fem_oplock_install(smb_node_t *);
416600Sas200622 extern void smb_fem_oplock_uninstall(smb_node_t *);
426600Sas200622 
436600Sas200622 extern int smb_vop_other_opens(vnode_t *, int);
446600Sas200622 
459343SAfshin.Ardakani@Sun.COM static int smb_fsop_create_stream(smb_request_t *, cred_t *, smb_node_t *,
469343SAfshin.Ardakani@Sun.COM     char *, char *, int, smb_attr_t *, smb_node_t **, smb_attr_t *);
479343SAfshin.Ardakani@Sun.COM 
489343SAfshin.Ardakani@Sun.COM static int smb_fsop_create_file(smb_request_t *, cred_t *, smb_node_t *,
499343SAfshin.Ardakani@Sun.COM     char *, int, smb_attr_t *, smb_node_t **, smb_attr_t *);
509343SAfshin.Ardakani@Sun.COM 
519343SAfshin.Ardakani@Sun.COM static int smb_fsop_create_with_sd(smb_request_t *, cred_t *, smb_node_t *,
529343SAfshin.Ardakani@Sun.COM     char *, smb_attr_t *, smb_node_t **, smb_attr_t *, smb_fssd_t *);
539343SAfshin.Ardakani@Sun.COM 
549343SAfshin.Ardakani@Sun.COM static int smb_fsop_sdinherit(smb_request_t *, smb_node_t *, smb_fssd_t *);
555331Samw 
565331Samw /*
575331Samw  * The smb_fsop_* functions have knowledge of CIFS semantics.
585331Samw  *
595331Samw  * The smb_vop_* functions have minimal knowledge of CIFS semantics and
605331Samw  * serve as an interface to the VFS layer.
615331Samw  *
625331Samw  * Hence, smb_request_t and smb_node_t structures should not be passed
635331Samw  * from the smb_fsop_* layer to the smb_vop_* layer.
645331Samw  *
655331Samw  * In general, CIFS service code should only ever call smb_fsop_*
665331Samw  * functions directly, and never smb_vop_* functions directly.
675331Samw  *
685331Samw  * smb_fsop_* functions should call smb_vop_* functions where possible, instead
695331Samw  * of their smb_fsop_* counterparts.  However, there are times when
705331Samw  * this cannot be avoided.
715331Samw  */
725331Samw 
735331Samw /*
745331Samw  * Note: Stream names cannot be mangled.
755331Samw  */
765331Samw 
776600Sas200622 /*
786600Sas200622  * smb_fsop_amask_to_omode
796600Sas200622  *
806600Sas200622  * Convert the access mask to the open mode (for use
816600Sas200622  * with the VOP_OPEN call).
826600Sas200622  *
836600Sas200622  * Note that opening a file for attribute only access
846600Sas200622  * will also translate into an FREAD or FWRITE open mode
856600Sas200622  * (i.e., it's not just for data).
866600Sas200622  *
876600Sas200622  * This is needed so that opens are tracked appropriately
886600Sas200622  * for oplock processing.
896600Sas200622  */
906600Sas200622 
915331Samw int
926600Sas200622 smb_fsop_amask_to_omode(uint32_t access)
935331Samw {
946600Sas200622 	int mode = 0;
956600Sas200622 
966600Sas200622 	if (access & (FILE_READ_DATA | FILE_EXECUTE |
976600Sas200622 	    FILE_READ_ATTRIBUTES | FILE_READ_EA))
986600Sas200622 		mode |= FREAD;
996600Sas200622 
1006600Sas200622 	if (access & (FILE_WRITE_DATA | FILE_APPEND_DATA |
1016600Sas200622 	    FILE_WRITE_ATTRIBUTES | FILE_WRITE_EA))
1026600Sas200622 		mode |= FWRITE;
1036600Sas200622 
1046600Sas200622 	if (access & FILE_APPEND_DATA)
1056600Sas200622 		mode |= FAPPEND;
1066600Sas200622 
1076600Sas200622 	return (mode);
1085331Samw }
1095331Samw 
1105331Samw int
1116600Sas200622 smb_fsop_open(smb_node_t *node, int mode, cred_t *cred)
1125331Samw {
1136600Sas200622 	/*
1146600Sas200622 	 * Assuming that the same vnode is returned as we had before.
1156600Sas200622 	 * (I.e., with certain types of files or file systems, a
1166600Sas200622 	 * different vnode might be returned by VOP_OPEN)
1176600Sas200622 	 */
1186600Sas200622 	return (smb_vop_open(&node->vp, mode, cred));
1195331Samw }
1205331Samw 
1217348SJose.Borrego@Sun.COM void
1226600Sas200622 smb_fsop_close(smb_node_t *node, int mode, cred_t *cred)
1236600Sas200622 {
1247348SJose.Borrego@Sun.COM 	smb_vop_close(node->vp, mode, cred);
1256600Sas200622 }
1266600Sas200622 
1276600Sas200622 int
1286600Sas200622 smb_fsop_oplock_install(smb_node_t *node, int mode)
1295331Samw {
1306600Sas200622 	int rc;
1316600Sas200622 
1326600Sas200622 	if (smb_vop_other_opens(node->vp, mode))
1336600Sas200622 		return (EMFILE);
1346600Sas200622 
1356600Sas200622 	if ((rc = smb_fem_oplock_install(node)))
1366600Sas200622 		return (rc);
1376600Sas200622 
1386600Sas200622 	if (smb_vop_other_opens(node->vp, mode)) {
1396600Sas200622 		(void) smb_fem_oplock_uninstall(node);
1406600Sas200622 		return (EMFILE);
1416600Sas200622 	}
1426600Sas200622 
1436600Sas200622 	return (0);
1446600Sas200622 }
1456600Sas200622 
1466600Sas200622 void
1476600Sas200622 smb_fsop_oplock_uninstall(smb_node_t *node)
1486600Sas200622 {
1496600Sas200622 	smb_fem_oplock_uninstall(node);
1505331Samw }
1515331Samw 
1525331Samw static int
1539343SAfshin.Ardakani@Sun.COM smb_fsop_create_with_sd(smb_request_t *sr, cred_t *cr,
1549343SAfshin.Ardakani@Sun.COM     smb_node_t *dnode, char *name,
1559343SAfshin.Ardakani@Sun.COM     smb_attr_t *attr, smb_node_t **ret_snode, smb_attr_t *ret_attr,
1569343SAfshin.Ardakani@Sun.COM     smb_fssd_t *fs_sd)
1575331Samw {
1585331Samw 	vsecattr_t *vsap;
1595331Samw 	vsecattr_t vsecattr;
1605331Samw 	acl_t *acl, *dacl, *sacl;
1615331Samw 	smb_attr_t set_attr;
1625331Samw 	vnode_t *vp;
1635331Samw 	int aclbsize = 0;	/* size of acl list in bytes */
1645331Samw 	int flags = 0;
1655331Samw 	int rc;
1667619SJose.Borrego@Sun.COM 	boolean_t is_dir;
1675331Samw 
1685331Samw 	ASSERT(fs_sd);
1695331Samw 
1707348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_CASEINSENSITIVE(sr))
1715331Samw 		flags = SMB_IGNORE_CASE;
1729231SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_SUPPORTS_CATIA(sr))
1739231SAfshin.Ardakani@Sun.COM 		flags |= SMB_CATIA;
1745331Samw 
1755331Samw 	ASSERT(cr);
1765331Samw 
1775331Samw 	is_dir = ((fs_sd->sd_flags & SMB_FSSD_FLAGS_DIR) != 0);
1785331Samw 
1797348SJose.Borrego@Sun.COM 	if (smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACLONCREATE)) {
1805331Samw 		if (fs_sd->sd_secinfo & SMB_ACL_SECINFO) {
1815331Samw 			dacl = fs_sd->sd_zdacl;
1825331Samw 			sacl = fs_sd->sd_zsacl;
1835331Samw 			ASSERT(dacl || sacl);
1845331Samw 			if (dacl && sacl) {
1855521Sas200622 				acl = smb_fsacl_merge(dacl, sacl);
1865331Samw 			} else if (dacl) {
1875331Samw 				acl = dacl;
1885331Samw 			} else {
1895331Samw 				acl = sacl;
1905331Samw 			}
1915331Samw 
1925521Sas200622 			rc = smb_fsacl_to_vsa(acl, &vsecattr, &aclbsize);
1935331Samw 
1945331Samw 			if (dacl && sacl)
1955331Samw 				acl_free(acl);
1965331Samw 
1977619SJose.Borrego@Sun.COM 			if (rc != 0)
1985331Samw 				return (rc);
1995331Samw 
2005331Samw 			vsap = &vsecattr;
2017619SJose.Borrego@Sun.COM 		} else {
2027619SJose.Borrego@Sun.COM 			vsap = NULL;
2035331Samw 		}
2045331Samw 
2058845Samw@Sun.COM 		/* The tree ACEs may prevent a create */
2068845Samw@Sun.COM 		rc = EACCES;
2075331Samw 		if (is_dir) {
2088845Samw@Sun.COM 			if (SMB_TREE_HAS_ACCESS(sr, ACE_ADD_SUBDIRECTORY) != 0)
2099343SAfshin.Ardakani@Sun.COM 				rc = smb_vop_mkdir(dnode->vp, name, attr,
2108845Samw@Sun.COM 				    &vp, flags, cr, vsap);
2115331Samw 		} else {
2128845Samw@Sun.COM 			if (SMB_TREE_HAS_ACCESS(sr, ACE_ADD_FILE) != 0)
2139343SAfshin.Ardakani@Sun.COM 				rc = smb_vop_create(dnode->vp, name, attr,
2148845Samw@Sun.COM 				    &vp, flags, cr, vsap);
2155331Samw 		}
2165331Samw 
2175331Samw 		if (vsap != NULL)
2185331Samw 			kmem_free(vsap->vsa_aclentp, aclbsize);
2195331Samw 
2205331Samw 		if (rc != 0)
2215331Samw 			return (rc);
2225331Samw 
2235331Samw 		set_attr.sa_mask = 0;
2245331Samw 
2255331Samw 		/*
2265331Samw 		 * Ideally we should be able to specify the owner and owning
2275331Samw 		 * group at create time along with the ACL. Since we cannot
2285331Samw 		 * do that right now, kcred is passed to smb_vop_setattr so it
2295331Samw 		 * doesn't fail due to lack of permission.
2305331Samw 		 */
2315331Samw 		if (fs_sd->sd_secinfo & SMB_OWNER_SECINFO) {
2325331Samw 			set_attr.sa_vattr.va_uid = fs_sd->sd_uid;
2335331Samw 			set_attr.sa_mask |= SMB_AT_UID;
2345331Samw 		}
2355331Samw 
2365331Samw 		if (fs_sd->sd_secinfo & SMB_GROUP_SECINFO) {
2375331Samw 			set_attr.sa_vattr.va_gid = fs_sd->sd_gid;
2385331Samw 			set_attr.sa_mask |= SMB_AT_GID;
2395331Samw 		}
2405331Samw 
2417757SJanice.Chang@Sun.COM 		if (set_attr.sa_mask)
2427757SJanice.Chang@Sun.COM 			rc = smb_vop_setattr(vp, NULL, &set_attr, 0, kcred);
2435331Samw 
2447619SJose.Borrego@Sun.COM 		if (rc == 0) {
2457619SJose.Borrego@Sun.COM 			*ret_snode = smb_node_lookup(sr, &sr->arg.open, cr, vp,
2469343SAfshin.Ardakani@Sun.COM 			    name, dnode, NULL, ret_attr);
2477619SJose.Borrego@Sun.COM 
2488670SJose.Borrego@Sun.COM 			if (*ret_snode == NULL)
2497619SJose.Borrego@Sun.COM 				rc = ENOMEM;
2508670SJose.Borrego@Sun.COM 
2518670SJose.Borrego@Sun.COM 			VN_RELE(vp);
2527619SJose.Borrego@Sun.COM 		}
2535331Samw 	} else {
2545331Samw 		/*
2555331Samw 		 * For filesystems that don't support ACL-on-create, try
2565331Samw 		 * to set the specified SD after create, which could actually
2575331Samw 		 * fail because of conflicts between inherited security
2585331Samw 		 * attributes upon creation and the specified SD.
2595331Samw 		 *
2605331Samw 		 * Passing kcred to smb_fsop_sdwrite() to overcome this issue.
2615331Samw 		 */
2625331Samw 
2635331Samw 		if (is_dir) {
2649343SAfshin.Ardakani@Sun.COM 			rc = smb_vop_mkdir(dnode->vp, name, attr, &vp,
2657619SJose.Borrego@Sun.COM 			    flags, cr, NULL);
2665331Samw 		} else {
2679343SAfshin.Ardakani@Sun.COM 			rc = smb_vop_create(dnode->vp, name, attr, &vp,
2687619SJose.Borrego@Sun.COM 			    flags, cr, NULL);
2695331Samw 		}
2705331Samw 
2715521Sas200622 		if (rc != 0)
2725521Sas200622 			return (rc);
2735521Sas200622 
2747619SJose.Borrego@Sun.COM 		*ret_snode = smb_node_lookup(sr, &sr->arg.open, cr, vp,
2759343SAfshin.Ardakani@Sun.COM 		    name, dnode, NULL, ret_attr);
2767619SJose.Borrego@Sun.COM 
2777619SJose.Borrego@Sun.COM 		if (*ret_snode != NULL) {
2787619SJose.Borrego@Sun.COM 			if (!smb_tree_has_feature(sr->tid_tree,
2797619SJose.Borrego@Sun.COM 			    SMB_TREE_NFS_MOUNTED))
2807619SJose.Borrego@Sun.COM 				rc = smb_fsop_sdwrite(sr, kcred, *ret_snode,
2817619SJose.Borrego@Sun.COM 				    fs_sd, 1);
2827619SJose.Borrego@Sun.COM 		} else {
2835331Samw 			rc = ENOMEM;
2845331Samw 		}
2858670SJose.Borrego@Sun.COM 
2868670SJose.Borrego@Sun.COM 		VN_RELE(vp);
2875331Samw 	}
2885331Samw 
2895521Sas200622 	if (rc != 0) {
2907619SJose.Borrego@Sun.COM 		if (is_dir)
2919343SAfshin.Ardakani@Sun.COM 			(void) smb_vop_rmdir(dnode->vp, name, flags, cr);
2927619SJose.Borrego@Sun.COM 		else
2939343SAfshin.Ardakani@Sun.COM 			(void) smb_vop_remove(dnode->vp, name, flags, cr);
2945521Sas200622 	}
2955521Sas200622 
2965331Samw 	return (rc);
2975331Samw }
2985331Samw 
2995331Samw /*
3005331Samw  * smb_fsop_create
3015331Samw  *
3025331Samw  * All SMB functions should use this wrapper to ensure that
3035331Samw  * all the smb_vop_creates are performed with the appropriate credentials.
3049343SAfshin.Ardakani@Sun.COM  * Please document any direct calls to explain the reason for avoiding
3059343SAfshin.Ardakani@Sun.COM  * this wrapper.
3065331Samw  *
3075331Samw  * *ret_snode is returned with a reference upon success.  No reference is
3085331Samw  * taken if an error is returned.
3095331Samw  */
3105331Samw int
3119343SAfshin.Ardakani@Sun.COM smb_fsop_create(smb_request_t *sr, cred_t *cr,
3129343SAfshin.Ardakani@Sun.COM     smb_node_t *dnode, char *name,
3139343SAfshin.Ardakani@Sun.COM     smb_attr_t *attr, smb_node_t **ret_snode, smb_attr_t *ret_attr)
3145331Samw {
3159343SAfshin.Ardakani@Sun.COM 	int	rc = 0;
3169343SAfshin.Ardakani@Sun.COM 	int	flags = 0;
3179343SAfshin.Ardakani@Sun.COM 	char	*fname, *sname;
3189343SAfshin.Ardakani@Sun.COM 	char	*longname = NULL;
3195331Samw 
3205331Samw 	ASSERT(cr);
3219343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode);
3229343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
3239343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
3245331Samw 
3255331Samw 	ASSERT(ret_snode);
3265331Samw 	*ret_snode = 0;
3275331Samw 
3285331Samw 	ASSERT(name);
3295331Samw 	if (*name == 0)
3305331Samw 		return (EINVAL);
3315331Samw 
3325331Samw 	ASSERT(sr);
3335331Samw 	ASSERT(sr->tid_tree);
3347348SJose.Borrego@Sun.COM 
3359343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0)
3367348SJose.Borrego@Sun.COM 		return (EACCES);
3377348SJose.Borrego@Sun.COM 
3387348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
3395331Samw 		return (EROFS);
3405331Samw 
3417348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_CASEINSENSITIVE(sr))
3425331Samw 		flags = SMB_IGNORE_CASE;
3439231SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_SUPPORTS_CATIA(sr))
3449231SAfshin.Ardakani@Sun.COM 		flags |= SMB_CATIA;
3455331Samw 
3469231SAfshin.Ardakani@Sun.COM 	if (smb_is_stream_name(name)) {
3479231SAfshin.Ardakani@Sun.COM 		fname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
3489231SAfshin.Ardakani@Sun.COM 		sname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
3499343SAfshin.Ardakani@Sun.COM 		smb_stream_parse_name(name, fname, sname);
3505331Samw 
3519343SAfshin.Ardakani@Sun.COM 		rc = smb_fsop_create_stream(sr, cr, dnode,
3529343SAfshin.Ardakani@Sun.COM 		    fname, sname, flags, attr, ret_snode, ret_attr);
3539231SAfshin.Ardakani@Sun.COM 
3549231SAfshin.Ardakani@Sun.COM 		kmem_free(fname, MAXNAMELEN);
3559231SAfshin.Ardakani@Sun.COM 		kmem_free(sname, MAXNAMELEN);
3569231SAfshin.Ardakani@Sun.COM 		return (rc);
3579231SAfshin.Ardakani@Sun.COM 	}
3585521Sas200622 
3599231SAfshin.Ardakani@Sun.COM 	/* Not a named stream */
3609343SAfshin.Ardakani@Sun.COM 
3619231SAfshin.Ardakani@Sun.COM 	if (smb_maybe_mangled_name(name)) {
3629231SAfshin.Ardakani@Sun.COM 		longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
3639343SAfshin.Ardakani@Sun.COM 		rc = smb_unmangle_name(dnode, name, longname, MAXNAMELEN);
3649231SAfshin.Ardakani@Sun.COM 		kmem_free(longname, MAXNAMELEN);
3655331Samw 
3669231SAfshin.Ardakani@Sun.COM 		if (rc == 0)
3679231SAfshin.Ardakani@Sun.COM 			rc = EEXIST;
3689231SAfshin.Ardakani@Sun.COM 		if (rc != ENOENT)
3699231SAfshin.Ardakani@Sun.COM 			return (rc);
3705331Samw 	}
3715331Samw 
3729343SAfshin.Ardakani@Sun.COM 	rc = smb_fsop_create_file(sr, cr, dnode, name, flags,
3739343SAfshin.Ardakani@Sun.COM 	    attr, ret_snode, ret_attr);
3749343SAfshin.Ardakani@Sun.COM 	return (rc);
3759343SAfshin.Ardakani@Sun.COM 
3769343SAfshin.Ardakani@Sun.COM }
3779343SAfshin.Ardakani@Sun.COM 
3789343SAfshin.Ardakani@Sun.COM 
3799343SAfshin.Ardakani@Sun.COM /*
3809343SAfshin.Ardakani@Sun.COM  * smb_fsop_create_stream
3819343SAfshin.Ardakani@Sun.COM  *
3829343SAfshin.Ardakani@Sun.COM  * Create NTFS named stream file (sname) on unnamed stream
3839343SAfshin.Ardakani@Sun.COM  * file (fname), creating the unnamed stream file if it
3849343SAfshin.Ardakani@Sun.COM  * doesn't exist.
3859343SAfshin.Ardakani@Sun.COM  * If we created the unnamed stream file and then creation
3869343SAfshin.Ardakani@Sun.COM  * of the named stream file fails, we delete the unnamed stream.
3879343SAfshin.Ardakani@Sun.COM  * Since we use the real file name for the smb_vop_remove we
3889343SAfshin.Ardakani@Sun.COM  * clear the SMB_IGNORE_CASE flag to ensure a case sensitive
3899343SAfshin.Ardakani@Sun.COM  * match.
3909343SAfshin.Ardakani@Sun.COM  *
3919343SAfshin.Ardakani@Sun.COM  * The second parameter of smb_vop_setattr() is set to
3929343SAfshin.Ardakani@Sun.COM  * NULL, even though an unnamed stream exists.  This is
3939343SAfshin.Ardakani@Sun.COM  * because we want to set the UID and GID on the named
3949343SAfshin.Ardakani@Sun.COM  * stream in this case for consistency with the (unnamed
3959343SAfshin.Ardakani@Sun.COM  * stream) file (see comments for smb_vop_setattr()).
3969343SAfshin.Ardakani@Sun.COM  */
3979343SAfshin.Ardakani@Sun.COM static int
3989343SAfshin.Ardakani@Sun.COM smb_fsop_create_stream(smb_request_t *sr, cred_t *cr,
3999343SAfshin.Ardakani@Sun.COM     smb_node_t *dnode, char *fname, char *sname, int flags,
4009343SAfshin.Ardakani@Sun.COM     smb_attr_t *attr, smb_node_t **ret_snode, smb_attr_t *ret_attr)
4019343SAfshin.Ardakani@Sun.COM {
4029343SAfshin.Ardakani@Sun.COM 	smb_node_t	*fnode;
4039343SAfshin.Ardakani@Sun.COM 	smb_attr_t	fattr;
4049343SAfshin.Ardakani@Sun.COM 	vnode_t		*xattrdvp;
4059343SAfshin.Ardakani@Sun.COM 	vnode_t		*vp;
4069343SAfshin.Ardakani@Sun.COM 	int		rc = 0;
4079343SAfshin.Ardakani@Sun.COM 	boolean_t	fcreate = B_FALSE;
4089343SAfshin.Ardakani@Sun.COM 
4099343SAfshin.Ardakani@Sun.COM 	/* Look up / create the unnamed stream, fname */
4109343SAfshin.Ardakani@Sun.COM 	rc = smb_fsop_lookup(sr, cr, flags | SMB_FOLLOW_LINKS,
4119343SAfshin.Ardakani@Sun.COM 	    sr->tid_tree->t_snode, dnode, fname,
4129343SAfshin.Ardakani@Sun.COM 	    &fnode, &fattr);
4139343SAfshin.Ardakani@Sun.COM 	if (rc == ENOENT) {
4149343SAfshin.Ardakani@Sun.COM 		fcreate = B_TRUE;
4159343SAfshin.Ardakani@Sun.COM 		rc = smb_fsop_create_file(sr, cr, dnode, fname, flags,
4169343SAfshin.Ardakani@Sun.COM 		    attr, &fnode, &fattr);
4179343SAfshin.Ardakani@Sun.COM 	}
4189343SAfshin.Ardakani@Sun.COM 	if (rc != 0)
4199343SAfshin.Ardakani@Sun.COM 		return (rc);
4209343SAfshin.Ardakani@Sun.COM 
4219343SAfshin.Ardakani@Sun.COM 	/* create the named stream, sname */
4229343SAfshin.Ardakani@Sun.COM 	rc = smb_vop_stream_create(fnode->vp, sname, attr, &vp,
4239343SAfshin.Ardakani@Sun.COM 	    &xattrdvp, flags, cr);
4249343SAfshin.Ardakani@Sun.COM 	if (rc != 0) {
4259343SAfshin.Ardakani@Sun.COM 		if (fcreate) {
4269343SAfshin.Ardakani@Sun.COM 			flags &= ~SMB_IGNORE_CASE;
4279343SAfshin.Ardakani@Sun.COM 			(void) smb_vop_remove(dnode->vp,
4289343SAfshin.Ardakani@Sun.COM 			    fnode->od_name, flags, cr);
4299343SAfshin.Ardakani@Sun.COM 		}
4309343SAfshin.Ardakani@Sun.COM 		smb_node_release(fnode);
4319343SAfshin.Ardakani@Sun.COM 		return (rc);
4329343SAfshin.Ardakani@Sun.COM 	}
4339343SAfshin.Ardakani@Sun.COM 
4349343SAfshin.Ardakani@Sun.COM 	attr->sa_vattr.va_uid = fattr.sa_vattr.va_uid;
4359343SAfshin.Ardakani@Sun.COM 	attr->sa_vattr.va_gid = fattr.sa_vattr.va_gid;
4369343SAfshin.Ardakani@Sun.COM 	attr->sa_mask = SMB_AT_UID | SMB_AT_GID;
4379343SAfshin.Ardakani@Sun.COM 
4389343SAfshin.Ardakani@Sun.COM 	rc = smb_vop_setattr(vp, NULL, attr, 0, kcred);
4399343SAfshin.Ardakani@Sun.COM 	if (rc != 0) {
4409343SAfshin.Ardakani@Sun.COM 		smb_node_release(fnode);
4419343SAfshin.Ardakani@Sun.COM 		return (rc);
4429343SAfshin.Ardakani@Sun.COM 	}
4439343SAfshin.Ardakani@Sun.COM 
4449343SAfshin.Ardakani@Sun.COM 	*ret_snode = smb_stream_node_lookup(sr, cr, fnode, xattrdvp,
4459343SAfshin.Ardakani@Sun.COM 	    vp, sname, ret_attr);
4469343SAfshin.Ardakani@Sun.COM 
4479343SAfshin.Ardakani@Sun.COM 	smb_node_release(fnode);
4489343SAfshin.Ardakani@Sun.COM 	VN_RELE(xattrdvp);
4499343SAfshin.Ardakani@Sun.COM 	VN_RELE(vp);
4509343SAfshin.Ardakani@Sun.COM 
4519343SAfshin.Ardakani@Sun.COM 	if (*ret_snode == NULL)
4529343SAfshin.Ardakani@Sun.COM 		rc = ENOMEM;
4539343SAfshin.Ardakani@Sun.COM 
4549343SAfshin.Ardakani@Sun.COM 	return (rc);
4559343SAfshin.Ardakani@Sun.COM }
4569343SAfshin.Ardakani@Sun.COM 
4579343SAfshin.Ardakani@Sun.COM /*
4589343SAfshin.Ardakani@Sun.COM  * smb_fsop_create_file
4599343SAfshin.Ardakani@Sun.COM  */
4609343SAfshin.Ardakani@Sun.COM static int
4619343SAfshin.Ardakani@Sun.COM smb_fsop_create_file(smb_request_t *sr, cred_t *cr,
4629343SAfshin.Ardakani@Sun.COM     smb_node_t *dnode, char *name, int flags,
4639343SAfshin.Ardakani@Sun.COM     smb_attr_t *attr, smb_node_t **ret_snode, smb_attr_t *ret_attr)
4649343SAfshin.Ardakani@Sun.COM {
4659343SAfshin.Ardakani@Sun.COM 	open_param_t	*op = &sr->arg.open;
4669343SAfshin.Ardakani@Sun.COM 	vnode_t		*vp;
4679343SAfshin.Ardakani@Sun.COM 	smb_fssd_t	fs_sd;
4689343SAfshin.Ardakani@Sun.COM 	uint32_t	secinfo;
4699343SAfshin.Ardakani@Sun.COM 	uint32_t	status;
4709343SAfshin.Ardakani@Sun.COM 	int		rc = 0;
4719343SAfshin.Ardakani@Sun.COM 
4729231SAfshin.Ardakani@Sun.COM 	if (op->sd) {
4739231SAfshin.Ardakani@Sun.COM 		/*
4749231SAfshin.Ardakani@Sun.COM 		 * SD sent by client in Windows format. Needs to be
4759231SAfshin.Ardakani@Sun.COM 		 * converted to FS format. No inheritance.
4769231SAfshin.Ardakani@Sun.COM 		 */
4779231SAfshin.Ardakani@Sun.COM 		secinfo = smb_sd_get_secinfo(op->sd);
4789231SAfshin.Ardakani@Sun.COM 		smb_fssd_init(&fs_sd, secinfo, 0);
4799231SAfshin.Ardakani@Sun.COM 
4809231SAfshin.Ardakani@Sun.COM 		status = smb_sd_tofs(op->sd, &fs_sd);
4819231SAfshin.Ardakani@Sun.COM 		if (status == NT_STATUS_SUCCESS) {
4829343SAfshin.Ardakani@Sun.COM 			rc = smb_fsop_create_with_sd(sr, cr, dnode,
4839231SAfshin.Ardakani@Sun.COM 			    name, attr, ret_snode, ret_attr, &fs_sd);
4849231SAfshin.Ardakani@Sun.COM 		} else {
4859231SAfshin.Ardakani@Sun.COM 			rc = EINVAL;
4869231SAfshin.Ardakani@Sun.COM 		}
4879231SAfshin.Ardakani@Sun.COM 		smb_fssd_term(&fs_sd);
4889231SAfshin.Ardakani@Sun.COM 	} else if (sr->tid_tree->t_acltype == ACE_T) {
4899231SAfshin.Ardakani@Sun.COM 		/*
4909231SAfshin.Ardakani@Sun.COM 		 * No incoming SD and filesystem is ZFS
4919231SAfshin.Ardakani@Sun.COM 		 * Server applies Windows inheritance rules,
4929231SAfshin.Ardakani@Sun.COM 		 * see smb_fsop_sdinherit() comments as to why.
4939231SAfshin.Ardakani@Sun.COM 		 */
4949231SAfshin.Ardakani@Sun.COM 		smb_fssd_init(&fs_sd, SMB_ACL_SECINFO, 0);
4959343SAfshin.Ardakani@Sun.COM 		rc = smb_fsop_sdinherit(sr, dnode, &fs_sd);
4969231SAfshin.Ardakani@Sun.COM 		if (rc == 0) {
4979343SAfshin.Ardakani@Sun.COM 			rc = smb_fsop_create_with_sd(sr, cr, dnode,
4989231SAfshin.Ardakani@Sun.COM 			    name, attr, ret_snode, ret_attr, &fs_sd);
4999231SAfshin.Ardakani@Sun.COM 		}
5009231SAfshin.Ardakani@Sun.COM 
5019231SAfshin.Ardakani@Sun.COM 		smb_fssd_term(&fs_sd);
5029231SAfshin.Ardakani@Sun.COM 	} else {
5039231SAfshin.Ardakani@Sun.COM 		/*
5049231SAfshin.Ardakani@Sun.COM 		 * No incoming SD and filesystem is not ZFS
5059231SAfshin.Ardakani@Sun.COM 		 * let the filesystem handles the inheritance.
5069231SAfshin.Ardakani@Sun.COM 		 */
5079343SAfshin.Ardakani@Sun.COM 		rc = smb_vop_create(dnode->vp, name, attr, &vp,
5089231SAfshin.Ardakani@Sun.COM 		    flags, cr, NULL);
5099231SAfshin.Ardakani@Sun.COM 
5109231SAfshin.Ardakani@Sun.COM 		if (rc == 0) {
5119231SAfshin.Ardakani@Sun.COM 			*ret_snode = smb_node_lookup(sr, op, cr, vp,
5129343SAfshin.Ardakani@Sun.COM 			    name, dnode, NULL, ret_attr);
5139231SAfshin.Ardakani@Sun.COM 
5149231SAfshin.Ardakani@Sun.COM 			if (*ret_snode == NULL)
5159231SAfshin.Ardakani@Sun.COM 				rc = ENOMEM;
5169231SAfshin.Ardakani@Sun.COM 
5179231SAfshin.Ardakani@Sun.COM 			VN_RELE(vp);
5189231SAfshin.Ardakani@Sun.COM 		}
5199231SAfshin.Ardakani@Sun.COM 
5209231SAfshin.Ardakani@Sun.COM 	}
5215331Samw 	return (rc);
5225331Samw }
5235331Samw 
5245331Samw /*
5255331Samw  * smb_fsop_mkdir
5265331Samw  *
5275331Samw  * All SMB functions should use this wrapper to ensure that
5285331Samw  * the the calls are performed with the appropriate credentials.
5295331Samw  * Please document any direct call to explain the reason
5305331Samw  * for avoiding this wrapper.
5315331Samw  *
5325331Samw  * It is assumed that a reference exists on snode coming into this routine.
5335331Samw  *
5345331Samw  * *ret_snode is returned with a reference upon success.  No reference is
5355331Samw  * taken if an error is returned.
5365331Samw  */
5375331Samw int
5385331Samw smb_fsop_mkdir(
5396139Sjb150015     smb_request_t *sr,
5405331Samw     cred_t *cr,
5419343SAfshin.Ardakani@Sun.COM     smb_node_t *dnode,
5425331Samw     char *name,
5435331Samw     smb_attr_t *attr,
5445331Samw     smb_node_t **ret_snode,
5455331Samw     smb_attr_t *ret_attr)
5465331Samw {
5475331Samw 	struct open_param *op = &sr->arg.open;
5485331Samw 	char *longname;
5495331Samw 	vnode_t *vp;
5505331Samw 	int flags = 0;
5515331Samw 	smb_fssd_t fs_sd;
5525331Samw 	uint32_t secinfo;
5535331Samw 	uint32_t status;
5545331Samw 	int rc;
5555331Samw 	ASSERT(cr);
5569343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode);
5579343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
5589343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
5595331Samw 
5605331Samw 	ASSERT(ret_snode);
5615331Samw 	*ret_snode = 0;
5625331Samw 
5635331Samw 	ASSERT(name);
5645331Samw 	if (*name == 0)
5655331Samw 		return (EINVAL);
5665331Samw 
5675331Samw 	ASSERT(sr);
5685331Samw 	ASSERT(sr->tid_tree);
5697348SJose.Borrego@Sun.COM 
5709343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0)
5717348SJose.Borrego@Sun.COM 		return (EACCES);
5727348SJose.Borrego@Sun.COM 
5737348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
5745331Samw 		return (EROFS);
5759231SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_SUPPORTS_CATIA(sr))
5769231SAfshin.Ardakani@Sun.COM 		flags |= SMB_CATIA;
5775331Samw 
5785331Samw 	if (smb_maybe_mangled_name(name)) {
5795331Samw 		longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
5809343SAfshin.Ardakani@Sun.COM 		rc = smb_unmangle_name(dnode, name, longname, MAXNAMELEN);
5815331Samw 		kmem_free(longname, MAXNAMELEN);
5825331Samw 
5835331Samw 		/*
5845331Samw 		 * If the name passed in by the client has an unmangled
5855331Samw 		 * equivalent that is found in the specified directory,
5865331Samw 		 * then the mkdir cannot succeed.  Return EEXIST.
5875331Samw 		 *
5885331Samw 		 * Only if ENOENT is returned will a mkdir be attempted.
5895331Samw 		 */
5905331Samw 
5915331Samw 		if (rc == 0)
5925331Samw 			rc = EEXIST;
5935331Samw 
5945331Samw 		if (rc != ENOENT)
5955331Samw 			return (rc);
5965331Samw 	}
5975331Samw 
5987348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_CASEINSENSITIVE(sr))
5995331Samw 		flags = SMB_IGNORE_CASE;
6005331Samw 
6015521Sas200622 	if (op->sd) {
6025331Samw 		/*
6035331Samw 		 * SD sent by client in Windows format. Needs to be
6045331Samw 		 * converted to FS format. No inheritance.
6055331Samw 		 */
6065521Sas200622 		secinfo = smb_sd_get_secinfo(op->sd);
6075521Sas200622 		smb_fssd_init(&fs_sd, secinfo, SMB_FSSD_FLAGS_DIR);
6085521Sas200622 
6095521Sas200622 		status = smb_sd_tofs(op->sd, &fs_sd);
6105331Samw 		if (status == NT_STATUS_SUCCESS) {
6119343SAfshin.Ardakani@Sun.COM 			rc = smb_fsop_create_with_sd(sr, cr, dnode,
6125331Samw 			    name, attr, ret_snode, ret_attr, &fs_sd);
6135331Samw 		}
6145331Samw 		else
6155331Samw 			rc = EINVAL;
6165521Sas200622 		smb_fssd_term(&fs_sd);
6175331Samw 	} else if (sr->tid_tree->t_acltype == ACE_T) {
6185331Samw 		/*
6195331Samw 		 * No incoming SD and filesystem is ZFS
6205331Samw 		 * Server applies Windows inheritance rules,
6215331Samw 		 * see smb_fsop_sdinherit() comments as to why.
6225331Samw 		 */
6235521Sas200622 		smb_fssd_init(&fs_sd, SMB_ACL_SECINFO, SMB_FSSD_FLAGS_DIR);
6249343SAfshin.Ardakani@Sun.COM 		rc = smb_fsop_sdinherit(sr, dnode, &fs_sd);
6255331Samw 		if (rc == 0) {
6269343SAfshin.Ardakani@Sun.COM 			rc = smb_fsop_create_with_sd(sr, cr, dnode,
6275331Samw 			    name, attr, ret_snode, ret_attr, &fs_sd);
6285331Samw 		}
6295331Samw 
6305521Sas200622 		smb_fssd_term(&fs_sd);
6315331Samw 
6325331Samw 	} else {
6339343SAfshin.Ardakani@Sun.COM 		rc = smb_vop_mkdir(dnode->vp, name, attr, &vp, flags, cr,
6345772Sas200622 		    NULL);
6355331Samw 
6365331Samw 		if (rc == 0) {
6375331Samw 			*ret_snode = smb_node_lookup(sr, op, cr, vp, name,
6389343SAfshin.Ardakani@Sun.COM 			    dnode, NULL, ret_attr);
6395331Samw 
6408670SJose.Borrego@Sun.COM 			if (*ret_snode == NULL)
6415331Samw 				rc = ENOMEM;
6428670SJose.Borrego@Sun.COM 
6438670SJose.Borrego@Sun.COM 			VN_RELE(vp);
6445331Samw 		}
6455331Samw 	}
6465331Samw 
6475331Samw 	return (rc);
6485331Samw }
6495331Samw 
6505331Samw /*
6515331Samw  * smb_fsop_remove
6525331Samw  *
6535331Samw  * All SMB functions should use this wrapper to ensure that
6545331Samw  * the the calls are performed with the appropriate credentials.
6555331Samw  * Please document any direct call to explain the reason
6565331Samw  * for avoiding this wrapper.
6575331Samw  *
6585331Samw  * It is assumed that a reference exists on snode coming into this routine.
6595331Samw  *
6605331Samw  * A null smb_request might be passed to this function.
6615331Samw  */
6625331Samw int
6635331Samw smb_fsop_remove(
6646139Sjb150015     smb_request_t	*sr,
6656139Sjb150015     cred_t		*cr,
6669343SAfshin.Ardakani@Sun.COM     smb_node_t		*dnode,
6676139Sjb150015     char		*name,
6689231SAfshin.Ardakani@Sun.COM     uint32_t		flags)
6695331Samw {
6706139Sjb150015 	smb_node_t	*fnode;
6716139Sjb150015 	smb_attr_t	file_attr;
6726139Sjb150015 	char		*longname;
6736139Sjb150015 	char		*fname;
6746139Sjb150015 	char		*sname;
6756139Sjb150015 	int		rc;
6765331Samw 
6775331Samw 	ASSERT(cr);
6785331Samw 	/*
6795331Samw 	 * The state of the node could be SMB_NODE_STATE_DESTROYING if this
6805331Samw 	 * function is called during the deletion of the node (because of
6815331Samw 	 * DELETE_ON_CLOSE).
6825331Samw 	 */
6839343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode);
6849343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
6855331Samw 
6869343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0 ||
6878845Samw@Sun.COM 	    SMB_TREE_HAS_ACCESS(sr, ACE_DELETE) == 0)
6885331Samw 		return (EACCES);
6895331Samw 
6907348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
6915331Samw 		return (EROFS);
6925331Samw 
6935331Samw 	fname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
6945331Samw 	sname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
6955331Samw 
6969343SAfshin.Ardakani@Sun.COM 	if (dnode->flags & NODE_XATTR_DIR) {
6979343SAfshin.Ardakani@Sun.COM 		rc = smb_vop_stream_remove(dnode->dir_snode->vp,
6985967Scp160787 		    name, flags, cr);
6999343SAfshin.Ardakani@Sun.COM 	} else if (smb_is_stream_name(name)) {
7009343SAfshin.Ardakani@Sun.COM 		smb_stream_parse_name(name, fname, sname);
7018334SJose.Borrego@Sun.COM 
7025967Scp160787 		/*
7035331Samw 		 * Look up the unnamed stream (i.e. fname).
7045331Samw 		 * Unmangle processing will be done on fname
7055331Samw 		 * as well as any link target.
7065331Samw 		 */
7075331Samw 
7085331Samw 		rc = smb_fsop_lookup(sr, cr, flags | SMB_FOLLOW_LINKS,
7099343SAfshin.Ardakani@Sun.COM 		    sr->tid_tree->t_snode, dnode, fname,
7109231SAfshin.Ardakani@Sun.COM 		    &fnode, &file_attr);
7115331Samw 
7125331Samw 		if (rc != 0) {
7135331Samw 			kmem_free(fname, MAXNAMELEN);
7145331Samw 			kmem_free(sname, MAXNAMELEN);
7155331Samw 			return (rc);
7165331Samw 		}
7175331Samw 
7185331Samw 		/*
7195331Samw 		 * XXX
7205331Samw 		 * Need to find out what permission is required by NTFS
7215331Samw 		 * to remove a stream.
7225331Samw 		 */
7235772Sas200622 		rc = smb_vop_stream_remove(fnode->vp, sname, flags, cr);
7245331Samw 
7255331Samw 		smb_node_release(fnode);
7265331Samw 	} else {
7279343SAfshin.Ardakani@Sun.COM 		rc = smb_vop_remove(dnode->vp, name, flags, cr);
7285331Samw 
7295331Samw 		if (rc == ENOENT) {
7305331Samw 			if (smb_maybe_mangled_name(name) == 0) {
7315331Samw 				kmem_free(fname, MAXNAMELEN);
7325331Samw 				kmem_free(sname, MAXNAMELEN);
7335331Samw 				return (rc);
7345331Samw 			}
7355331Samw 			longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
7365331Samw 
7379343SAfshin.Ardakani@Sun.COM 			rc = smb_unmangle_name(dnode, name,
7389231SAfshin.Ardakani@Sun.COM 			    longname, MAXNAMELEN);
7395331Samw 
7405331Samw 			if (rc == 0) {
7415331Samw 				/*
7429231SAfshin.Ardakani@Sun.COM 				 * longname is the real (case-sensitive)
7439231SAfshin.Ardakani@Sun.COM 				 * on-disk name.
7445331Samw 				 * We make sure we do a remove on this exact
7455331Samw 				 * name, as the name was mangled and denotes
7465331Samw 				 * a unique file.
7475331Samw 				 */
7485331Samw 				flags &= ~SMB_IGNORE_CASE;
7499343SAfshin.Ardakani@Sun.COM 				rc = smb_vop_remove(dnode->vp, longname,
7505772Sas200622 				    flags, cr);
7515331Samw 			}
7525331Samw 
7535331Samw 			kmem_free(longname, MAXNAMELEN);
7545331Samw 		}
7555331Samw 	}
7565331Samw 
7575331Samw 	kmem_free(fname, MAXNAMELEN);
7585331Samw 	kmem_free(sname, MAXNAMELEN);
7595331Samw 	return (rc);
7605331Samw }
7615331Samw 
7625331Samw /*
7635331Samw  * smb_fsop_remove_streams
7645331Samw  *
7655331Samw  * This function removes a file's streams without removing the
7665331Samw  * file itself.
7675331Samw  *
7688670SJose.Borrego@Sun.COM  * It is assumed that fnode is not a link.
7695331Samw  */
7705331Samw int
7716139Sjb150015 smb_fsop_remove_streams(smb_request_t *sr, cred_t *cr, smb_node_t *fnode)
7725331Samw {
7738670SJose.Borrego@Sun.COM 	int rc, flags = 0;
7748670SJose.Borrego@Sun.COM 	uint16_t odid;
7758670SJose.Borrego@Sun.COM 	smb_odir_t *od;
7768670SJose.Borrego@Sun.COM 	smb_odirent_t *odirent;
7778670SJose.Borrego@Sun.COM 	boolean_t eos;
7785331Samw 
7797348SJose.Borrego@Sun.COM 	ASSERT(sr);
7805331Samw 	ASSERT(cr);
7815331Samw 	ASSERT(fnode);
7825331Samw 	ASSERT(fnode->n_magic == SMB_NODE_MAGIC);
7835331Samw 	ASSERT(fnode->n_state != SMB_NODE_STATE_DESTROYING);
7845331Samw 
7859343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, fnode) == 0) {
7869343SAfshin.Ardakani@Sun.COM 		smbsr_errno(sr, EACCES);
7879343SAfshin.Ardakani@Sun.COM 		return (-1);
7889343SAfshin.Ardakani@Sun.COM 	}
7895331Samw 
7909343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_IS_READONLY(sr)) {
7919343SAfshin.Ardakani@Sun.COM 		smbsr_errno(sr, EROFS);
7929343SAfshin.Ardakani@Sun.COM 		return (-1);
7939343SAfshin.Ardakani@Sun.COM 	}
7945331Samw 
7957348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_CASEINSENSITIVE(sr))
7965331Samw 		flags = SMB_IGNORE_CASE;
7979343SAfshin.Ardakani@Sun.COM 
7989231SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_SUPPORTS_CATIA(sr))
7999231SAfshin.Ardakani@Sun.COM 		flags |= SMB_CATIA;
8005331Samw 
8019343SAfshin.Ardakani@Sun.COM 	if ((odid = smb_odir_openat(sr, fnode)) == 0) {
8029343SAfshin.Ardakani@Sun.COM 		smbsr_errno(sr, ENOENT);
8039343SAfshin.Ardakani@Sun.COM 		return (-1);
8049343SAfshin.Ardakani@Sun.COM 	}
8059343SAfshin.Ardakani@Sun.COM 
8069343SAfshin.Ardakani@Sun.COM 	if ((od = smb_tree_lookup_odir(sr->tid_tree, odid)) == NULL) {
8079343SAfshin.Ardakani@Sun.COM 		smbsr_errno(sr, ENOENT);
8089343SAfshin.Ardakani@Sun.COM 		return (-1);
8099343SAfshin.Ardakani@Sun.COM 	}
8105331Samw 
8118670SJose.Borrego@Sun.COM 	odirent = kmem_alloc(sizeof (smb_odirent_t), KM_SLEEP);
8128670SJose.Borrego@Sun.COM 	for (;;) {
8138670SJose.Borrego@Sun.COM 		rc = smb_odir_read(sr, od, odirent, &eos);
8148670SJose.Borrego@Sun.COM 		if ((rc != 0) || (eos))
8155331Samw 			break;
8168670SJose.Borrego@Sun.COM 		(void) smb_vop_remove(od->d_dnode->vp, odirent->od_name,
8178670SJose.Borrego@Sun.COM 		    flags, cr);
8188670SJose.Borrego@Sun.COM 	}
8198670SJose.Borrego@Sun.COM 	kmem_free(odirent, sizeof (smb_odirent_t));
8205331Samw 
8219635SJoyce.McIntosh@Sun.COM 	smb_odir_close(od);
8228670SJose.Borrego@Sun.COM 	smb_odir_release(od);
8235331Samw 	return (rc);
8245331Samw }
8255331Samw 
8265331Samw /*
8275331Samw  * smb_fsop_rmdir
8285331Samw  *
8295331Samw  * All SMB functions should use this wrapper to ensure that
8305331Samw  * the the calls are performed with the appropriate credentials.
8315331Samw  * Please document any direct call to explain the reason
8325331Samw  * for avoiding this wrapper.
8335331Samw  *
8345331Samw  * It is assumed that a reference exists on snode coming into this routine.
8355331Samw  */
8365331Samw int
8375331Samw smb_fsop_rmdir(
8386139Sjb150015     smb_request_t	*sr,
8396139Sjb150015     cred_t		*cr,
8409343SAfshin.Ardakani@Sun.COM     smb_node_t		*dnode,
8416139Sjb150015     char		*name,
8429231SAfshin.Ardakani@Sun.COM     uint32_t		flags)
8435331Samw {
8446139Sjb150015 	int		rc;
8456139Sjb150015 	char		*longname;
8465331Samw 
8475331Samw 	ASSERT(cr);
8485331Samw 	/*
8495331Samw 	 * The state of the node could be SMB_NODE_STATE_DESTROYING if this
8505331Samw 	 * function is called during the deletion of the node (because of
8515331Samw 	 * DELETE_ON_CLOSE).
8525331Samw 	 */
8539343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode);
8549343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
8555331Samw 
8569343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0 ||
8578845Samw@Sun.COM 	    SMB_TREE_HAS_ACCESS(sr, ACE_DELETE_CHILD) == 0)
8585331Samw 		return (EACCES);
8595331Samw 
8607348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
8615331Samw 		return (EROFS);
8625331Samw 
8639343SAfshin.Ardakani@Sun.COM 	rc = smb_vop_rmdir(dnode->vp, name, flags, cr);
8645331Samw 
8655331Samw 	if (rc == ENOENT) {
8665331Samw 		if (smb_maybe_mangled_name(name) == 0)
8675331Samw 			return (rc);
8685331Samw 
8695331Samw 		longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
8709343SAfshin.Ardakani@Sun.COM 		rc = smb_unmangle_name(dnode, name, longname, MAXNAMELEN);
8715331Samw 
8725331Samw 		if (rc == 0) {
8735331Samw 			/*
8749231SAfshin.Ardakani@Sun.COM 			 * longname is the real (case-sensitive)
8759231SAfshin.Ardakani@Sun.COM 			 * on-disk name.
8765331Samw 			 * We make sure we do a rmdir on this exact
8775331Samw 			 * name, as the name was mangled and denotes
8785331Samw 			 * a unique directory.
8795331Samw 			 */
8805331Samw 			flags &= ~SMB_IGNORE_CASE;
8819343SAfshin.Ardakani@Sun.COM 			rc = smb_vop_rmdir(dnode->vp, longname, flags, cr);
8825331Samw 		}
8835331Samw 
8845331Samw 		kmem_free(longname, MAXNAMELEN);
8855331Samw 	}
8865331Samw 
8875331Samw 	return (rc);
8885331Samw }
8895331Samw 
8905331Samw /*
8915331Samw  * smb_fsop_getattr
8925331Samw  *
8935331Samw  * All SMB functions should use this wrapper to ensure that
8945331Samw  * the the calls are performed with the appropriate credentials.
8955331Samw  * Please document any direct call to explain the reason
8965331Samw  * for avoiding this wrapper.
8975331Samw  *
8985331Samw  * It is assumed that a reference exists on snode coming into this routine.
8995331Samw  */
9005331Samw int
9016139Sjb150015 smb_fsop_getattr(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
9025331Samw     smb_attr_t *attr)
9035331Samw {
9045331Samw 	smb_node_t *unnamed_node;
9055331Samw 	vnode_t *unnamed_vp = NULL;
9065331Samw 	uint32_t status;
9075331Samw 	uint32_t access = 0;
9085331Samw 	int flags = 0;
9095772Sas200622 	int rc;
9105331Samw 
9115331Samw 	ASSERT(cr);
9125331Samw 	ASSERT(snode);
9135331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
9145331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
9155331Samw 
9168845Samw@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, snode) == 0 ||
9178845Samw@Sun.COM 	    SMB_TREE_HAS_ACCESS(sr, ACE_READ_ATTRIBUTES) == 0)
9185331Samw 		return (EACCES);
9195331Samw 
9205331Samw 	if (sr->fid_ofile) {
9215331Samw 		/* if uid and/or gid is requested */
9225331Samw 		if (attr->sa_mask & (SMB_AT_UID|SMB_AT_GID))
9235331Samw 			access |= READ_CONTROL;
9245331Samw 
9255331Samw 		/* if anything else is also requested */
9265331Samw 		if (attr->sa_mask & ~(SMB_AT_UID|SMB_AT_GID))
9275331Samw 			access |= FILE_READ_ATTRIBUTES;
9285331Samw 
9295331Samw 		status = smb_ofile_access(sr->fid_ofile, cr, access);
9305331Samw 		if (status != NT_STATUS_SUCCESS)
9315331Samw 			return (EACCES);
9325331Samw 
9337348SJose.Borrego@Sun.COM 		if (smb_tree_has_feature(sr->tid_tree,
9347348SJose.Borrego@Sun.COM 		    SMB_TREE_ACEMASKONACCESS))
9355331Samw 			flags = ATTR_NOACLCHECK;
9365331Samw 	}
9375331Samw 
9385331Samw 	unnamed_node = SMB_IS_STREAM(snode);
9395331Samw 
9405331Samw 	if (unnamed_node) {
9415331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
9425331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
9435331Samw 		unnamed_vp = unnamed_node->vp;
9445331Samw 	}
9455331Samw 
9465772Sas200622 	rc = smb_vop_getattr(snode->vp, unnamed_vp, attr, flags, cr);
9475772Sas200622 	if (rc == 0)
9485772Sas200622 		snode->attr = *attr;
9495772Sas200622 
9505772Sas200622 	return (rc);
9515331Samw }
9525331Samw 
9535331Samw /*
954*9914Samw@Sun.COM  * smb_fsop_link
955*9914Samw@Sun.COM  *
956*9914Samw@Sun.COM  * All SMB functions should use this smb_vop_link wrapper to ensure that
957*9914Samw@Sun.COM  * the smb_vop_link is performed with the appropriate credentials.
958*9914Samw@Sun.COM  * Please document any direct call to smb_vop_link to explain the reason
959*9914Samw@Sun.COM  * for avoiding this wrapper.
960*9914Samw@Sun.COM  *
961*9914Samw@Sun.COM  * It is assumed that references exist on from_dnode and to_dnode coming
962*9914Samw@Sun.COM  * into this routine.
963*9914Samw@Sun.COM  */
964*9914Samw@Sun.COM int
965*9914Samw@Sun.COM smb_fsop_link(smb_request_t *sr, cred_t *cr, smb_node_t *to_dnode,
966*9914Samw@Sun.COM     smb_node_t *from_fnode, char *to_name)
967*9914Samw@Sun.COM {
968*9914Samw@Sun.COM 	char	*longname = NULL;
969*9914Samw@Sun.COM 	int	flags = 0;
970*9914Samw@Sun.COM 	int	rc;
971*9914Samw@Sun.COM 
972*9914Samw@Sun.COM 	ASSERT(sr);
973*9914Samw@Sun.COM 	ASSERT(sr->tid_tree);
974*9914Samw@Sun.COM 	ASSERT(cr);
975*9914Samw@Sun.COM 	ASSERT(to_dnode);
976*9914Samw@Sun.COM 	ASSERT(to_dnode->n_magic == SMB_NODE_MAGIC);
977*9914Samw@Sun.COM 	ASSERT(to_dnode->n_state != SMB_NODE_STATE_DESTROYING);
978*9914Samw@Sun.COM 	ASSERT(from_fnode);
979*9914Samw@Sun.COM 	ASSERT(from_fnode->n_magic == SMB_NODE_MAGIC);
980*9914Samw@Sun.COM 	ASSERT(from_fnode->n_state != SMB_NODE_STATE_DESTROYING);
981*9914Samw@Sun.COM 
982*9914Samw@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, from_fnode) == 0)
983*9914Samw@Sun.COM 		return (EACCES);
984*9914Samw@Sun.COM 
985*9914Samw@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, to_dnode) == 0)
986*9914Samw@Sun.COM 		return (EACCES);
987*9914Samw@Sun.COM 
988*9914Samw@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
989*9914Samw@Sun.COM 		return (EROFS);
990*9914Samw@Sun.COM 
991*9914Samw@Sun.COM 	if (SMB_TREE_IS_CASEINSENSITIVE(sr))
992*9914Samw@Sun.COM 		flags = SMB_IGNORE_CASE;
993*9914Samw@Sun.COM 	if (SMB_TREE_SUPPORTS_CATIA(sr))
994*9914Samw@Sun.COM 		flags |= SMB_CATIA;
995*9914Samw@Sun.COM 
996*9914Samw@Sun.COM 	if (smb_maybe_mangled_name(to_name)) {
997*9914Samw@Sun.COM 		longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
998*9914Samw@Sun.COM 		rc = smb_unmangle_name(to_dnode, to_name, longname, MAXNAMELEN);
999*9914Samw@Sun.COM 		kmem_free(longname, MAXNAMELEN);
1000*9914Samw@Sun.COM 
1001*9914Samw@Sun.COM 		if (rc == 0)
1002*9914Samw@Sun.COM 			rc = EEXIST;
1003*9914Samw@Sun.COM 		if (rc != ENOENT)
1004*9914Samw@Sun.COM 			return (rc);
1005*9914Samw@Sun.COM 	}
1006*9914Samw@Sun.COM 
1007*9914Samw@Sun.COM 	rc = smb_vop_link(to_dnode->vp, from_fnode->vp, to_name, flags, cr);
1008*9914Samw@Sun.COM 	return (rc);
1009*9914Samw@Sun.COM }
1010*9914Samw@Sun.COM 
1011*9914Samw@Sun.COM /*
10125331Samw  * smb_fsop_rename
10135331Samw  *
10145331Samw  * All SMB functions should use this smb_vop_rename wrapper to ensure that
10155331Samw  * the smb_vop_rename is performed with the appropriate credentials.
10165331Samw  * Please document any direct call to smb_vop_rename to explain the reason
10175331Samw  * for avoiding this wrapper.
10185331Samw  *
10199343SAfshin.Ardakani@Sun.COM  * It is assumed that references exist on from_dnode and to_dnode coming
10205331Samw  * into this routine.
10215331Samw  */
10225331Samw int
10235331Samw smb_fsop_rename(
10246139Sjb150015     smb_request_t *sr,
10255331Samw     cred_t *cr,
10269343SAfshin.Ardakani@Sun.COM     smb_node_t *from_dnode,
10275331Samw     char *from_name,
10289343SAfshin.Ardakani@Sun.COM     smb_node_t *to_dnode,
10295331Samw     char *to_name)
10305331Samw {
10315331Samw 	smb_node_t *from_snode;
10325331Samw 	smb_attr_t tmp_attr;
10335331Samw 	vnode_t *from_vp;
10349231SAfshin.Ardakani@Sun.COM 	int flags = 0, ret_flags;
10355331Samw 	int rc;
10368845Samw@Sun.COM 	boolean_t isdir;
10375331Samw 
10385331Samw 	ASSERT(cr);
10399343SAfshin.Ardakani@Sun.COM 	ASSERT(from_dnode);
10409343SAfshin.Ardakani@Sun.COM 	ASSERT(from_dnode->n_magic == SMB_NODE_MAGIC);
10419343SAfshin.Ardakani@Sun.COM 	ASSERT(from_dnode->n_state != SMB_NODE_STATE_DESTROYING);
10425331Samw 
10439343SAfshin.Ardakani@Sun.COM 	ASSERT(to_dnode);
10449343SAfshin.Ardakani@Sun.COM 	ASSERT(to_dnode->n_magic == SMB_NODE_MAGIC);
10459343SAfshin.Ardakani@Sun.COM 	ASSERT(to_dnode->n_state != SMB_NODE_STATE_DESTROYING);
10465331Samw 
10479343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, from_dnode) == 0)
10485331Samw 		return (EACCES);
10495331Samw 
10509343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, to_dnode) == 0)
10515331Samw 		return (EACCES);
10525331Samw 
10535331Samw 	ASSERT(sr);
10545331Samw 	ASSERT(sr->tid_tree);
10557348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
10565331Samw 		return (EROFS);
10575331Samw 
10585331Samw 	/*
10597348SJose.Borrego@Sun.COM 	 * Note: There is no need to check SMB_TREE_IS_CASEINSENSITIVE
10605331Samw 	 * here.
10615331Samw 	 *
10625331Samw 	 * A case-sensitive rename is always done in this routine
10635331Samw 	 * because we are using the on-disk name from an earlier lookup.
10645331Samw 	 * If a mangled name was passed in by the caller (denoting a
10655331Samw 	 * deterministic lookup), then the exact file must be renamed
10665331Samw 	 * (i.e. SMB_IGNORE_CASE must not be passed to VOP_RENAME, or
10675331Samw 	 * else the underlying file system might return a "first-match"
10685331Samw 	 * on this on-disk name, possibly resulting in the wrong file).
10695331Samw 	 */
10705331Samw 
10719231SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_SUPPORTS_CATIA(sr))
10729231SAfshin.Ardakani@Sun.COM 		flags |= SMB_CATIA;
10739231SAfshin.Ardakani@Sun.COM 
10745331Samw 	/*
10755331Samw 	 * XXX: Lock required through smb_node_release() below?
10765331Samw 	 */
10775331Samw 
10789343SAfshin.Ardakani@Sun.COM 	rc = smb_vop_lookup(from_dnode->vp, from_name, &from_vp, NULL,
10799231SAfshin.Ardakani@Sun.COM 	    flags, &ret_flags, NULL, cr);
10805331Samw 
10815331Samw 	if (rc != 0)
10825331Samw 		return (rc);
10835331Samw 
10848845Samw@Sun.COM 	isdir = from_vp->v_type == VDIR;
10858845Samw@Sun.COM 
10868845Samw@Sun.COM 	if ((isdir && SMB_TREE_HAS_ACCESS(sr,
10878845Samw@Sun.COM 	    ACE_DELETE_CHILD | ACE_ADD_SUBDIRECTORY) !=
10888845Samw@Sun.COM 	    (ACE_DELETE_CHILD | ACE_ADD_SUBDIRECTORY)) ||
10898845Samw@Sun.COM 	    (!isdir && SMB_TREE_HAS_ACCESS(sr, ACE_DELETE | ACE_ADD_FILE) !=
10908845Samw@Sun.COM 	    (ACE_DELETE | ACE_ADD_FILE)))
10918845Samw@Sun.COM 		return (EACCES);
10928845Samw@Sun.COM 
10939343SAfshin.Ardakani@Sun.COM 	rc = smb_vop_rename(from_dnode->vp, from_name, to_dnode->vp,
10945772Sas200622 	    to_name, flags, cr);
10955331Samw 
10965331Samw 	if (rc == 0) {
10975331Samw 		from_snode = smb_node_lookup(sr, NULL, cr, from_vp, from_name,
10989343SAfshin.Ardakani@Sun.COM 		    from_dnode, NULL, &tmp_attr);
10995331Samw 
11005331Samw 		if (from_snode == NULL) {
11018670SJose.Borrego@Sun.COM 			rc = ENOMEM;
11028670SJose.Borrego@Sun.COM 		} else {
11039343SAfshin.Ardakani@Sun.COM 			smb_node_rename(from_dnode, from_snode,
11049343SAfshin.Ardakani@Sun.COM 			    to_dnode, to_name);
11058670SJose.Borrego@Sun.COM 			smb_node_release(from_snode);
11065331Samw 		}
11075331Samw 	}
11088670SJose.Borrego@Sun.COM 	VN_RELE(from_vp);
11095331Samw 
11105331Samw 	/* XXX: unlock */
11115331Samw 
11125331Samw 	return (rc);
11135331Samw }
11145331Samw 
11155331Samw /*
11165331Samw  * smb_fsop_setattr
11175331Samw  *
11185331Samw  * All SMB functions should use this wrapper to ensure that
11195331Samw  * the the calls are performed with the appropriate credentials.
11205331Samw  * Please document any direct call to explain the reason
11215331Samw  * for avoiding this wrapper.
11225331Samw  *
11235331Samw  * It is assumed that a reference exists on snode coming into this routine.
11245331Samw  * A null smb_request might be passed to this function.
11255331Samw  */
11265331Samw int
11275331Samw smb_fsop_setattr(
11286139Sjb150015     smb_request_t	*sr,
11296139Sjb150015     cred_t		*cr,
11306139Sjb150015     smb_node_t		*snode,
11316139Sjb150015     smb_attr_t		*set_attr,
11326139Sjb150015     smb_attr_t		*ret_attr)
11335331Samw {
11345331Samw 	smb_node_t *unnamed_node;
11355331Samw 	vnode_t *unnamed_vp = NULL;
11365331Samw 	uint32_t status;
11377619SJose.Borrego@Sun.COM 	uint32_t access;
11385331Samw 	int rc = 0;
11395331Samw 	int flags = 0;
11407619SJose.Borrego@Sun.COM 	uint_t sa_mask;
11415331Samw 
11425331Samw 	ASSERT(cr);
11435331Samw 	ASSERT(snode);
11445331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
11455331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
11465331Samw 
11477348SJose.Borrego@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, snode) == 0)
11485331Samw 		return (EACCES);
11495331Samw 
11507348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
11515331Samw 		return (EROFS);
11525331Samw 
11538845Samw@Sun.COM 	if (SMB_TREE_HAS_ACCESS(sr,
11548845Samw@Sun.COM 	    ACE_WRITE_ATTRIBUTES | ACE_WRITE_NAMED_ATTRS) == 0)
11558845Samw@Sun.COM 		return (EACCES);
11568845Samw@Sun.COM 
11577348SJose.Borrego@Sun.COM 	if (sr && (set_attr->sa_mask & SMB_AT_SIZE)) {
11587348SJose.Borrego@Sun.COM 		if (sr->fid_ofile) {
11597348SJose.Borrego@Sun.COM 			if (SMB_OFILE_IS_READONLY(sr->fid_ofile))
11607348SJose.Borrego@Sun.COM 				return (EACCES);
11617348SJose.Borrego@Sun.COM 		} else {
11627348SJose.Borrego@Sun.COM 			if (SMB_PATHFILE_IS_READONLY(sr, snode))
11637348SJose.Borrego@Sun.COM 				return (EACCES);
11647348SJose.Borrego@Sun.COM 		}
11657348SJose.Borrego@Sun.COM 	}
11667348SJose.Borrego@Sun.COM 
11675331Samw 	/* sr could be NULL in some cases */
11685331Samw 	if (sr && sr->fid_ofile) {
11697619SJose.Borrego@Sun.COM 		sa_mask = set_attr->sa_mask;
11707619SJose.Borrego@Sun.COM 		access = 0;
11717619SJose.Borrego@Sun.COM 
11727619SJose.Borrego@Sun.COM 		if (sa_mask & SMB_AT_SIZE) {
11737619SJose.Borrego@Sun.COM 			access |= FILE_WRITE_DATA;
11747619SJose.Borrego@Sun.COM 			sa_mask &= ~SMB_AT_SIZE;
11757619SJose.Borrego@Sun.COM 		}
11767619SJose.Borrego@Sun.COM 
11777619SJose.Borrego@Sun.COM 		if (sa_mask & (SMB_AT_UID|SMB_AT_GID)) {
11785331Samw 			access |= WRITE_OWNER;
11797619SJose.Borrego@Sun.COM 			sa_mask &= ~(SMB_AT_UID|SMB_AT_GID);
11807619SJose.Borrego@Sun.COM 		}
11817619SJose.Borrego@Sun.COM 
11827619SJose.Borrego@Sun.COM 		if (sa_mask)
11835331Samw 			access |= FILE_WRITE_ATTRIBUTES;
11845331Samw 
11855331Samw 		status = smb_ofile_access(sr->fid_ofile, cr, access);
11865331Samw 		if (status != NT_STATUS_SUCCESS)
11875331Samw 			return (EACCES);
11885331Samw 
11897348SJose.Borrego@Sun.COM 		if (smb_tree_has_feature(sr->tid_tree,
11907348SJose.Borrego@Sun.COM 		    SMB_TREE_ACEMASKONACCESS))
11915331Samw 			flags = ATTR_NOACLCHECK;
11925331Samw 	}
11935331Samw 
11945331Samw 	unnamed_node = SMB_IS_STREAM(snode);
11955331Samw 
11965331Samw 	if (unnamed_node) {
11975331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
11985331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
11995331Samw 		unnamed_vp = unnamed_node->vp;
12005331Samw 	}
12017757SJanice.Chang@Sun.COM 
12027757SJanice.Chang@Sun.COM 	rc = smb_vop_setattr(snode->vp, unnamed_vp, set_attr, flags, cr);
12035331Samw 
12045331Samw 	if ((rc == 0) && ret_attr) {
12055331Samw 		/*
12065772Sas200622 		 * Use kcred to update the node attr because this
12075772Sas200622 		 * call is not being made on behalf of the user.
12085331Samw 		 */
12095331Samw 		ret_attr->sa_mask = SMB_AT_ALL;
12107348SJose.Borrego@Sun.COM 		rc = smb_vop_getattr(snode->vp, unnamed_vp, ret_attr, flags,
12117348SJose.Borrego@Sun.COM 		    kcred);
12125772Sas200622 		if (rc == 0)
12135772Sas200622 			snode->attr = *ret_attr;
12145331Samw 	}
12155331Samw 
12165331Samw 	return (rc);
12175331Samw }
12185331Samw 
12195331Samw /*
12205331Samw  * smb_fsop_read
12215331Samw  *
12225331Samw  * All SMB functions should use this wrapper to ensure that
12235331Samw  * the the calls are performed with the appropriate credentials.
12245331Samw  * Please document any direct call to explain the reason
12255331Samw  * for avoiding this wrapper.
12265331Samw  *
12275331Samw  * It is assumed that a reference exists on snode coming into this routine.
12285331Samw  */
12295331Samw int
12305331Samw smb_fsop_read(
12315331Samw     struct smb_request *sr,
12325331Samw     cred_t *cr,
12335331Samw     smb_node_t *snode,
12345331Samw     uio_t *uio,
12355331Samw     smb_attr_t *ret_attr)
12365331Samw {
12375331Samw 	smb_node_t *unnamed_node;
12385331Samw 	vnode_t *unnamed_vp = NULL;
12397348SJose.Borrego@Sun.COM 	caller_context_t ct;
12405772Sas200622 	int svmand;
12415331Samw 	int rc;
12425331Samw 
12435331Samw 	ASSERT(cr);
12445331Samw 	ASSERT(snode);
12455331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
12465331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
12475331Samw 
12485331Samw 	ASSERT(sr);
12495331Samw 	ASSERT(sr->fid_ofile);
12505331Samw 
12518845Samw@Sun.COM 	if (SMB_TREE_HAS_ACCESS(sr, ACE_READ_DATA) == 0)
12528845Samw@Sun.COM 		return (EACCES);
12538845Samw@Sun.COM 
12545331Samw 	rc = smb_ofile_access(sr->fid_ofile, cr, FILE_READ_DATA);
12555331Samw 	if (rc != NT_STATUS_SUCCESS) {
12565331Samw 		rc = smb_ofile_access(sr->fid_ofile, cr, FILE_EXECUTE);
12575331Samw 		if (rc != NT_STATUS_SUCCESS)
12585331Samw 			return (EACCES);
12595331Samw 	}
12605331Samw 
12615331Samw 	unnamed_node = SMB_IS_STREAM(snode);
12625331Samw 	if (unnamed_node) {
12635331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
12645331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
12655331Samw 		unnamed_vp = unnamed_node->vp;
12665331Samw 		/*
12675331Samw 		 * Streams permission are checked against the unnamed stream,
12685331Samw 		 * but in FS level they have their own permissions. To avoid
12695331Samw 		 * rejection by FS due to lack of permission on the actual
12705331Samw 		 * extended attr kcred is passed for streams.
12715331Samw 		 */
12725331Samw 		cr = kcred;
12735331Samw 	}
12745331Samw 
12755772Sas200622 	smb_node_start_crit(snode, RW_READER);
12767348SJose.Borrego@Sun.COM 	rc = nbl_svmand(snode->vp, kcred, &svmand);
12775772Sas200622 	if (rc) {
12785772Sas200622 		smb_node_end_crit(snode);
12795772Sas200622 		return (rc);
12805772Sas200622 	}
12815772Sas200622 
12827348SJose.Borrego@Sun.COM 	ct = smb_ct;
12837348SJose.Borrego@Sun.COM 	ct.cc_pid = sr->fid_ofile->f_uniqid;
12845772Sas200622 	rc = nbl_lock_conflict(snode->vp, NBL_READ, uio->uio_loffset,
12857348SJose.Borrego@Sun.COM 	    uio->uio_iov->iov_len, svmand, &ct);
12865772Sas200622 
12875772Sas200622 	if (rc) {
12885772Sas200622 		smb_node_end_crit(snode);
12896432Sas200622 		return (ERANGE);
12905772Sas200622 	}
12915772Sas200622 	rc = smb_vop_read(snode->vp, uio, cr);
12925772Sas200622 
12935772Sas200622 	if (rc == 0 && ret_attr) {
12945331Samw 		/*
12955772Sas200622 		 * Use kcred to update the node attr because this
12965772Sas200622 		 * call is not being made on behalf of the user.
12975331Samw 		 */
12985331Samw 		ret_attr->sa_mask = SMB_AT_ALL;
12995772Sas200622 		if (smb_vop_getattr(snode->vp, unnamed_vp, ret_attr, 0,
13005772Sas200622 		    kcred) == 0) {
13015772Sas200622 			snode->attr = *ret_attr;
13025772Sas200622 		}
13035331Samw 	}
13045331Samw 
13055772Sas200622 	smb_node_end_crit(snode);
13065772Sas200622 
13075331Samw 	return (rc);
13085331Samw }
13095331Samw 
13105331Samw /*
13115331Samw  * smb_fsop_write
13125331Samw  *
13135331Samw  * This is a wrapper function used for smb_write and smb_write_raw operations.
13145331Samw  *
13155331Samw  * It is assumed that a reference exists on snode coming into this routine.
13165331Samw  */
13175331Samw int
13185331Samw smb_fsop_write(
13196139Sjb150015     smb_request_t *sr,
13205331Samw     cred_t *cr,
13215331Samw     smb_node_t *snode,
13225331Samw     uio_t *uio,
13235331Samw     uint32_t *lcount,
13245331Samw     smb_attr_t *ret_attr,
13257052Samw     int ioflag)
13265331Samw {
13275331Samw 	smb_node_t *unnamed_node;
13285331Samw 	vnode_t *unnamed_vp = NULL;
13297348SJose.Borrego@Sun.COM 	caller_context_t ct;
13305772Sas200622 	int svmand;
13315331Samw 	int rc;
13325331Samw 
13335331Samw 	ASSERT(cr);
13345331Samw 	ASSERT(snode);
13355331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
13365331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
13375331Samw 
13385331Samw 	ASSERT(sr);
13395331Samw 	ASSERT(sr->tid_tree);
13405331Samw 	ASSERT(sr->fid_ofile);
13415331Samw 
13427348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
13435331Samw 		return (EROFS);
13445772Sas200622 
13458845Samw@Sun.COM 	if (SMB_OFILE_IS_READONLY(sr->fid_ofile) ||
13468845Samw@Sun.COM 	    SMB_TREE_HAS_ACCESS(sr, ACE_WRITE_DATA | ACE_APPEND_DATA) == 0)
13477348SJose.Borrego@Sun.COM 		return (EACCES);
13487348SJose.Borrego@Sun.COM 
13495331Samw 	rc = smb_ofile_access(sr->fid_ofile, cr, FILE_WRITE_DATA);
13505772Sas200622 	if (rc != NT_STATUS_SUCCESS) {
13515772Sas200622 		rc = smb_ofile_access(sr->fid_ofile, cr, FILE_APPEND_DATA);
13525772Sas200622 		if (rc != NT_STATUS_SUCCESS)
13535772Sas200622 			return (EACCES);
13545772Sas200622 	}
13555331Samw 
13565331Samw 	unnamed_node = SMB_IS_STREAM(snode);
13575331Samw 
13585331Samw 	if (unnamed_node) {
13595331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
13605331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
13615331Samw 		unnamed_vp = unnamed_node->vp;
13625331Samw 		/*
13635331Samw 		 * Streams permission are checked against the unnamed stream,
13645331Samw 		 * but in FS level they have their own permissions. To avoid
13655331Samw 		 * rejection by FS due to lack of permission on the actual
13665331Samw 		 * extended attr kcred is passed for streams.
13675331Samw 		 */
13685331Samw 		cr = kcred;
13695331Samw 	}
13705331Samw 
13715772Sas200622 	smb_node_start_crit(snode, RW_READER);
13727348SJose.Borrego@Sun.COM 	rc = nbl_svmand(snode->vp, kcred, &svmand);
13735772Sas200622 	if (rc) {
13745772Sas200622 		smb_node_end_crit(snode);
13755772Sas200622 		return (rc);
13765772Sas200622 	}
13777348SJose.Borrego@Sun.COM 
13787348SJose.Borrego@Sun.COM 	ct = smb_ct;
13797348SJose.Borrego@Sun.COM 	ct.cc_pid = sr->fid_ofile->f_uniqid;
13805772Sas200622 	rc = nbl_lock_conflict(snode->vp, NBL_WRITE, uio->uio_loffset,
13817348SJose.Borrego@Sun.COM 	    uio->uio_iov->iov_len, svmand, &ct);
13825772Sas200622 
13835772Sas200622 	if (rc) {
13845772Sas200622 		smb_node_end_crit(snode);
13856432Sas200622 		return (ERANGE);
13865772Sas200622 	}
13877052Samw 	rc = smb_vop_write(snode->vp, uio, ioflag, lcount, cr);
13885772Sas200622 
13895772Sas200622 	if (rc == 0 && ret_attr) {
13905331Samw 		/*
13915772Sas200622 		 * Use kcred to update the node attr because this
13925772Sas200622 		 * call is not being made on behalf of the user.
13935331Samw 		 */
13945331Samw 		ret_attr->sa_mask = SMB_AT_ALL;
13955772Sas200622 		if (smb_vop_getattr(snode->vp, unnamed_vp, ret_attr, 0,
13965772Sas200622 		    kcred) == 0) {
13975772Sas200622 			snode->attr = *ret_attr;
13985772Sas200622 		}
13995331Samw 	}
14005331Samw 
14015772Sas200622 	smb_node_end_crit(snode);
14025772Sas200622 
14035331Samw 	return (rc);
14045331Samw }
14055331Samw 
14065331Samw /*
14075331Samw  * smb_fsop_statfs
14085331Samw  *
14095331Samw  * This is a wrapper function used for stat operations.
14105331Samw  */
14115331Samw int
14125331Samw smb_fsop_statfs(
14135331Samw     cred_t *cr,
14145331Samw     smb_node_t *snode,
14155331Samw     struct statvfs64 *statp)
14165331Samw {
14175331Samw 	ASSERT(cr);
14185331Samw 	ASSERT(snode);
14195331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
14205331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
14215331Samw 
14225331Samw 	return (smb_vop_statfs(snode->vp, statp, cr));
14235331Samw }
14245331Samw 
14255331Samw /*
14265331Samw  * smb_fsop_access
14276700Sjm199354  *
14286700Sjm199354  * Named streams do not have separate permissions from the associated
14296700Sjm199354  * unnamed stream.  Thus, if node is a named stream, the permissions
14306700Sjm199354  * check will be performed on the associated unnamed stream.
14316700Sjm199354  *
14326700Sjm199354  * However, our named streams do have their own quarantine attribute,
14336700Sjm199354  * separate from that on the unnamed stream. If READ or EXECUTE
14346700Sjm199354  * access has been requested on a named stream, an additional access
14356700Sjm199354  * check is performed on the named stream in case it has been
14366700Sjm199354  * quarantined.  kcred is used to avoid issues with the permissions
14376700Sjm199354  * set on the extended attribute file representing the named stream.
14385331Samw  */
14395331Samw int
14405331Samw smb_fsop_access(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
14415331Samw     uint32_t faccess)
14425331Samw {
14435331Samw 	int access = 0;
14445331Samw 	int error;
14455331Samw 	vnode_t *dir_vp;
14465331Samw 	boolean_t acl_check = B_TRUE;
14475331Samw 	smb_node_t *unnamed_node;
14485331Samw 
14497348SJose.Borrego@Sun.COM 	ASSERT(sr);
14505331Samw 	ASSERT(cr);
14515331Samw 	ASSERT(snode);
14525331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
14535331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
14545331Samw 
14555331Samw 	if (faccess == 0)
14565331Samw 		return (NT_STATUS_SUCCESS);
14575331Samw 
14587348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr)) {
14595331Samw 		if (faccess & (FILE_WRITE_DATA|FILE_APPEND_DATA|
14605331Samw 		    FILE_WRITE_EA|FILE_DELETE_CHILD|FILE_WRITE_ATTRIBUTES|
14615331Samw 		    DELETE|WRITE_DAC|WRITE_OWNER)) {
14625331Samw 			return (NT_STATUS_ACCESS_DENIED);
14635331Samw 		}
14645331Samw 	}
14655331Samw 
14665331Samw 	unnamed_node = SMB_IS_STREAM(snode);
14675331Samw 	if (unnamed_node) {
14685331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
14695331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
14706700Sjm199354 
14716700Sjm199354 		/*
14726700Sjm199354 		 * Perform VREAD access check on the named stream in case it
14736700Sjm199354 		 * is quarantined. kcred is passed to smb_vop_access so it
14746700Sjm199354 		 * doesn't fail due to lack of permission.
14756700Sjm199354 		 */
14766700Sjm199354 		if (faccess & (FILE_READ_DATA | FILE_EXECUTE)) {
14776700Sjm199354 			error = smb_vop_access(snode->vp, VREAD,
14786700Sjm199354 			    0, NULL, kcred);
14796700Sjm199354 			if (error)
14806700Sjm199354 				return (NT_STATUS_ACCESS_DENIED);
14816700Sjm199354 		}
14826700Sjm199354 
14835331Samw 		/*
14845331Samw 		 * Streams authorization should be performed against the
14855331Samw 		 * unnamed stream.
14865331Samw 		 */
14875331Samw 		snode = unnamed_node;
14885331Samw 	}
14895331Samw 
14905331Samw 	if (faccess & ACCESS_SYSTEM_SECURITY) {
14915331Samw 		/*
14925331Samw 		 * This permission is required for reading/writing SACL and
14935331Samw 		 * it's not part of DACL. It's only granted via proper
14945331Samw 		 * privileges.
14955331Samw 		 */
14965331Samw 		if ((sr->uid_user->u_privileges &
14975331Samw 		    (SMB_USER_PRIV_BACKUP |
14985331Samw 		    SMB_USER_PRIV_RESTORE |
14995331Samw 		    SMB_USER_PRIV_SECURITY)) == 0)
15005331Samw 			return (NT_STATUS_PRIVILEGE_NOT_HELD);
15015331Samw 
15025331Samw 		faccess &= ~ACCESS_SYSTEM_SECURITY;
15035331Samw 	}
15045331Samw 
15055331Samw 	/* Links don't have ACL */
15067348SJose.Borrego@Sun.COM 	if ((!smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACEMASKONACCESS)) ||
15075331Samw 	    (snode->attr.sa_vattr.va_type == VLNK))
15085331Samw 		acl_check = B_FALSE;
15095331Samw 
15108845Samw@Sun.COM 	/*
15118845Samw@Sun.COM 	 * Use the most restrictive parts of both faccess and the
15128845Samw@Sun.COM 	 * share access.  An AND of the two value masks gives us that
15138845Samw@Sun.COM 	 * since we've already converted to a mask of what we "can"
15148845Samw@Sun.COM 	 * do.
15158845Samw@Sun.COM 	 */
15168845Samw@Sun.COM 	faccess &= sr->tid_tree->t_access;
15178845Samw@Sun.COM 
15185331Samw 	if (acl_check) {
15195331Samw 		dir_vp = (snode->dir_snode) ? snode->dir_snode->vp : NULL;
15205331Samw 		error = smb_vop_access(snode->vp, faccess, V_ACE_MASK, dir_vp,
15215331Samw 		    cr);
15225331Samw 	} else {
15235331Samw 		/*
15245331Samw 		 * FS doesn't understand 32-bit mask, need to map
15255331Samw 		 */
15265331Samw 		if (faccess & (FILE_WRITE_DATA | FILE_APPEND_DATA))
15275331Samw 			access |= VWRITE;
15285331Samw 
15295331Samw 		if (faccess & FILE_READ_DATA)
15305331Samw 			access |= VREAD;
15315331Samw 
15325331Samw 		if (faccess & FILE_EXECUTE)
15335331Samw 			access |= VEXEC;
15345331Samw 
15355331Samw 		error = smb_vop_access(snode->vp, access, 0, NULL, cr);
15365331Samw 	}
15375331Samw 
15385331Samw 	return ((error) ? NT_STATUS_ACCESS_DENIED : NT_STATUS_SUCCESS);
15395331Samw }
15405331Samw 
15415331Samw /*
15425331Samw  * smb_fsop_lookup_name()
15435331Samw  *
15447961SNatalie.Li@Sun.COM  * If name indicates that the file is a stream file, perform
15457961SNatalie.Li@Sun.COM  * stream specific lookup, otherwise call smb_fsop_lookup.
15465331Samw  *
15477961SNatalie.Li@Sun.COM  * Return an error if the looked-up file is in outside the tree.
15487961SNatalie.Li@Sun.COM  * (Required when invoked from open path.)
15495331Samw  */
15505331Samw 
15515331Samw int
15525331Samw smb_fsop_lookup_name(
15536139Sjb150015     smb_request_t *sr,
15545331Samw     cred_t	*cr,
15555331Samw     int		flags,
15565331Samw     smb_node_t	*root_node,
15579343SAfshin.Ardakani@Sun.COM     smb_node_t	*dnode,
15585331Samw     char	*name,
15595331Samw     smb_node_t	**ret_snode,
15605331Samw     smb_attr_t	*ret_attr)
15615331Samw {
15626139Sjb150015 	smb_node_t	*fnode;
15636139Sjb150015 	smb_attr_t	file_attr;
15646139Sjb150015 	vnode_t		*xattrdirvp;
15656139Sjb150015 	vnode_t		*vp;
15666139Sjb150015 	char		*od_name;
15676139Sjb150015 	char		*fname;
15686139Sjb150015 	char		*sname;
15696139Sjb150015 	int		rc;
15705331Samw 
15715331Samw 	ASSERT(cr);
15729343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode);
15739343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
15749343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
15755331Samw 
15765331Samw 	/*
15775331Samw 	 * The following check is required for streams processing, below
15785331Samw 	 */
15795331Samw 
15807348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_CASEINSENSITIVE(sr))
15815331Samw 		flags |= SMB_IGNORE_CASE;
15825331Samw 
15835331Samw 	fname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
15845331Samw 	sname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
15855331Samw 
15869343SAfshin.Ardakani@Sun.COM 	if (smb_is_stream_name(name)) {
15879343SAfshin.Ardakani@Sun.COM 		smb_stream_parse_name(name, fname, sname);
15888334SJose.Borrego@Sun.COM 
15895331Samw 		/*
15905331Samw 		 * Look up the unnamed stream (i.e. fname).
15915331Samw 		 * Unmangle processing will be done on fname
15925331Samw 		 * as well as any link target.
15935331Samw 		 */
15949343SAfshin.Ardakani@Sun.COM 		rc = smb_fsop_lookup(sr, cr, flags, root_node, dnode, fname,
15959231SAfshin.Ardakani@Sun.COM 		    &fnode, &file_attr);
15965331Samw 
15975331Samw 		if (rc != 0) {
15985331Samw 			kmem_free(fname, MAXNAMELEN);
15995331Samw 			kmem_free(sname, MAXNAMELEN);
16005331Samw 			return (rc);
16015331Samw 		}
16025331Samw 
16035331Samw 		od_name = kmem_alloc(MAXNAMELEN, KM_SLEEP);
16045331Samw 
16055331Samw 		/*
16065331Samw 		 * od_name is the on-disk name of the stream, except
16075331Samw 		 * without the prepended stream prefix (SMB_STREAM_PREFIX)
16085331Samw 		 */
16095331Samw 
16105331Samw 		/*
16115331Samw 		 * XXX
16125331Samw 		 * What permissions NTFS requires for stream lookup if any?
16135331Samw 		 */
16145331Samw 		rc = smb_vop_stream_lookup(fnode->vp, sname, &vp, od_name,
16155772Sas200622 		    &xattrdirvp, flags, root_node->vp, cr);
16165331Samw 
16175331Samw 		if (rc != 0) {
16185331Samw 			smb_node_release(fnode);
16195331Samw 			kmem_free(fname, MAXNAMELEN);
16205331Samw 			kmem_free(sname, MAXNAMELEN);
16215331Samw 			kmem_free(od_name, MAXNAMELEN);
16225331Samw 			return (rc);
16235331Samw 		}
16245331Samw 
16255331Samw 		*ret_snode = smb_stream_node_lookup(sr, cr, fnode, xattrdirvp,
16265331Samw 		    vp, od_name, ret_attr);
16275331Samw 
16285331Samw 		kmem_free(od_name, MAXNAMELEN);
16295331Samw 		smb_node_release(fnode);
16308670SJose.Borrego@Sun.COM 		VN_RELE(xattrdirvp);
16318670SJose.Borrego@Sun.COM 		VN_RELE(vp);
16325331Samw 
16335331Samw 		if (*ret_snode == NULL) {
16345331Samw 			kmem_free(fname, MAXNAMELEN);
16355331Samw 			kmem_free(sname, MAXNAMELEN);
16365331Samw 			return (ENOMEM);
16375331Samw 		}
16385331Samw 	} else {
16399343SAfshin.Ardakani@Sun.COM 		rc = smb_fsop_lookup(sr, cr, flags, root_node, dnode, name,
16409231SAfshin.Ardakani@Sun.COM 		    ret_snode, ret_attr);
16415331Samw 	}
16425331Samw 
16435331Samw 	if (rc == 0) {
16445331Samw 		ASSERT(ret_snode);
16457348SJose.Borrego@Sun.COM 		if (SMB_TREE_CONTAINS_NODE(sr, *ret_snode) == 0) {
16465331Samw 			smb_node_release(*ret_snode);
16475331Samw 			*ret_snode = NULL;
16485331Samw 			rc = EACCES;
16495331Samw 		}
16505331Samw 	}
16515331Samw 
16525331Samw 	kmem_free(fname, MAXNAMELEN);
16535331Samw 	kmem_free(sname, MAXNAMELEN);
16545331Samw 
16555331Samw 	return (rc);
16565331Samw }
16575331Samw 
16585331Samw /*
16595331Samw  * smb_fsop_lookup
16605331Samw  *
16615331Samw  * All SMB functions should use this smb_vop_lookup wrapper to ensure that
16625331Samw  * the smb_vop_lookup is performed with the appropriate credentials and using
16635331Samw  * case insensitive compares. Please document any direct call to smb_vop_lookup
16645331Samw  * to explain the reason for avoiding this wrapper.
16655331Samw  *
16669343SAfshin.Ardakani@Sun.COM  * It is assumed that a reference exists on dnode coming into this routine
16675331Samw  * (and that it is safe from deallocation).
16685331Samw  *
16695331Samw  * Same with the root_node.
16705331Samw  *
16715331Samw  * *ret_snode is returned with a reference upon success.  No reference is
16725331Samw  * taken if an error is returned.
16735331Samw  *
16745331Samw  * Note: The returned ret_snode may be in a child mount.  This is ok for
16758670SJose.Borrego@Sun.COM  * readdir.
16765331Samw  *
16777348SJose.Borrego@Sun.COM  * Other smb_fsop_* routines will call SMB_TREE_CONTAINS_NODE() to prevent
16785331Samw  * operations on files not in the parent mount.
16795331Samw  */
16805331Samw int
16815331Samw smb_fsop_lookup(
16826139Sjb150015     smb_request_t *sr,
16835331Samw     cred_t	*cr,
16845331Samw     int		flags,
16855331Samw     smb_node_t	*root_node,
16869343SAfshin.Ardakani@Sun.COM     smb_node_t	*dnode,
16875331Samw     char	*name,
16885331Samw     smb_node_t	**ret_snode,
16899231SAfshin.Ardakani@Sun.COM     smb_attr_t	*ret_attr)
16905331Samw {
16915331Samw 	smb_node_t *lnk_target_node;
16925331Samw 	smb_node_t *lnk_dnode;
16935331Samw 	char *longname;
16945331Samw 	char *od_name;
16955331Samw 	vnode_t *vp;
16965331Samw 	int rc;
16979231SAfshin.Ardakani@Sun.COM 	int ret_flags;
16985331Samw 
16995331Samw 	ASSERT(cr);
17009343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode);
17019343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_magic == SMB_NODE_MAGIC);
17029343SAfshin.Ardakani@Sun.COM 	ASSERT(dnode->n_state != SMB_NODE_STATE_DESTROYING);
17035331Samw 
17045331Samw 	if (name == NULL)
17055331Samw 		return (EINVAL);
17065331Samw 
17079343SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_CONTAINS_NODE(sr, dnode) == 0)
17085331Samw 		return (EACCES);
17095331Samw 
17107348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_CASEINSENSITIVE(sr))
17115331Samw 		flags |= SMB_IGNORE_CASE;
17129231SAfshin.Ardakani@Sun.COM 	if (SMB_TREE_SUPPORTS_CATIA(sr))
17139231SAfshin.Ardakani@Sun.COM 		flags |= SMB_CATIA;
17145331Samw 
17155331Samw 	od_name = kmem_alloc(MAXNAMELEN, KM_SLEEP);
17165331Samw 
17179343SAfshin.Ardakani@Sun.COM 	rc = smb_vop_lookup(dnode->vp, name, &vp, od_name, flags,
17189231SAfshin.Ardakani@Sun.COM 	    &ret_flags, root_node ? root_node->vp : NULL, cr);
17195331Samw 
17205331Samw 	if (rc != 0) {
17215331Samw 		if (smb_maybe_mangled_name(name) == 0) {
17225331Samw 			kmem_free(od_name, MAXNAMELEN);
17235331Samw 			return (rc);
17245331Samw 		}
17255331Samw 
17265331Samw 		longname = kmem_alloc(MAXNAMELEN, KM_SLEEP);
17279343SAfshin.Ardakani@Sun.COM 		rc = smb_unmangle_name(dnode, name, longname, MAXNAMELEN);
17285331Samw 		if (rc != 0) {
17295331Samw 			kmem_free(od_name, MAXNAMELEN);
17305331Samw 			kmem_free(longname, MAXNAMELEN);
17315331Samw 			return (rc);
17325331Samw 		}
17335331Samw 
17345331Samw 		/*
17359231SAfshin.Ardakani@Sun.COM 		 * longname is the real (case-sensitive)
17369231SAfshin.Ardakani@Sun.COM 		 * on-disk name.
17375331Samw 		 * We make sure we do a lookup on this exact
17385331Samw 		 * name, as the name was mangled and denotes
17395331Samw 		 * a unique file.
17405331Samw 		 */
17415331Samw 
17425331Samw 		if (flags & SMB_IGNORE_CASE)
17435331Samw 			flags &= ~SMB_IGNORE_CASE;
17445331Samw 
17459343SAfshin.Ardakani@Sun.COM 		rc = smb_vop_lookup(dnode->vp, longname, &vp, od_name,
17469231SAfshin.Ardakani@Sun.COM 		    flags, &ret_flags, root_node ? root_node->vp : NULL, cr);
17475331Samw 
17485331Samw 		kmem_free(longname, MAXNAMELEN);
17495331Samw 
17505331Samw 		if (rc != 0) {
17515331Samw 			kmem_free(od_name, MAXNAMELEN);
17525331Samw 			return (rc);
17535331Samw 		}
17545331Samw 	}
17555331Samw 
17565331Samw 	if ((flags & SMB_FOLLOW_LINKS) && (vp->v_type == VLNK)) {
17575331Samw 
17589343SAfshin.Ardakani@Sun.COM 		rc = smb_pathname(sr, od_name, FOLLOW, root_node, dnode,
17595331Samw 		    &lnk_dnode, &lnk_target_node, cr);
17605331Samw 
17615331Samw 		if (rc != 0) {
17625331Samw 			/*
17635331Samw 			 * The link is assumed to be for the last component
17645331Samw 			 * of a path.  Hence any ENOTDIR error will be returned
17655331Samw 			 * as ENOENT.
17665331Samw 			 */
17675331Samw 			if (rc == ENOTDIR)
17685331Samw 				rc = ENOENT;
17695331Samw 
17705331Samw 			VN_RELE(vp);
17715331Samw 			kmem_free(od_name, MAXNAMELEN);
17725331Samw 			return (rc);
17735331Samw 		}
17745331Samw 
17755331Samw 		/*
17765331Samw 		 * Release the original VLNK vnode
17775331Samw 		 */
17785331Samw 
17795331Samw 		VN_RELE(vp);
17805331Samw 		vp = lnk_target_node->vp;
17815331Samw 
17825331Samw 		rc = smb_vop_traverse_check(&vp);
17835331Samw 
17845331Samw 		if (rc != 0) {
17855331Samw 			smb_node_release(lnk_dnode);
17865331Samw 			smb_node_release(lnk_target_node);
17875331Samw 			kmem_free(od_name, MAXNAMELEN);
17885331Samw 			return (rc);
17895331Samw 		}
17905331Samw 
17915331Samw 		/*
17925331Samw 		 * smb_vop_traverse_check() may have returned a different vnode
17935331Samw 		 */
17945331Samw 
17955331Samw 		if (lnk_target_node->vp == vp) {
17965331Samw 			*ret_snode = lnk_target_node;
17975331Samw 			*ret_attr = (*ret_snode)->attr;
17985331Samw 		} else {
17995331Samw 			*ret_snode = smb_node_lookup(sr, NULL, cr, vp,
18005331Samw 			    lnk_target_node->od_name, lnk_dnode, NULL,
18015331Samw 			    ret_attr);
18028670SJose.Borrego@Sun.COM 			VN_RELE(vp);
18035331Samw 
18048670SJose.Borrego@Sun.COM 			if (*ret_snode == NULL)
18055331Samw 				rc = ENOMEM;
18065331Samw 			smb_node_release(lnk_target_node);
18075331Samw 		}
18085331Samw 
18095331Samw 		smb_node_release(lnk_dnode);
18105331Samw 
18115331Samw 	} else {
18125331Samw 
18135331Samw 		rc = smb_vop_traverse_check(&vp);
18145331Samw 		if (rc) {
18155331Samw 			VN_RELE(vp);
18165331Samw 			kmem_free(od_name, MAXNAMELEN);
18175331Samw 			return (rc);
18185331Samw 		}
18195331Samw 
18205331Samw 		*ret_snode = smb_node_lookup(sr, NULL, cr, vp, od_name,
18219343SAfshin.Ardakani@Sun.COM 		    dnode, NULL, ret_attr);
18228670SJose.Borrego@Sun.COM 		VN_RELE(vp);
18235331Samw 
18248670SJose.Borrego@Sun.COM 		if (*ret_snode == NULL)
18255331Samw 			rc = ENOMEM;
18265331Samw 	}
18275331Samw 
18285331Samw 	kmem_free(od_name, MAXNAMELEN);
18295331Samw 	return (rc);
18305331Samw }
18315331Samw 
18325331Samw int /*ARGSUSED*/
18335331Samw smb_fsop_commit(smb_request_t *sr, cred_t *cr, smb_node_t *snode)
18345331Samw {
18355331Samw 	ASSERT(cr);
18365331Samw 	ASSERT(snode);
18375331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
18385331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
18395331Samw 
18405331Samw 	ASSERT(sr);
18415331Samw 	ASSERT(sr->tid_tree);
18427348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
18435331Samw 		return (EROFS);
18445331Samw 
18455772Sas200622 	return (smb_vop_commit(snode->vp, cr));
18465331Samw }
18475331Samw 
18485331Samw /*
18495331Samw  * smb_fsop_aclread
18505331Samw  *
18515331Samw  * Retrieve filesystem ACL. Depends on requested ACLs in
18525331Samw  * fs_sd->sd_secinfo, it'll set DACL and SACL pointers in
18535331Samw  * fs_sd. Note that requesting a DACL/SACL doesn't mean that
18545331Samw  * the corresponding field in fs_sd should be non-NULL upon
18555331Samw  * return, since the target ACL might not contain that type of
18565331Samw  * entries.
18575331Samw  *
18585331Samw  * Returned ACL is always in ACE_T (aka ZFS) format.
18595331Samw  * If successful the allocated memory for the ACL should be freed
18605521Sas200622  * using smb_fsacl_free() or smb_fssd_term()
18615331Samw  */
18625331Samw int
18635331Samw smb_fsop_aclread(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
18645331Samw     smb_fssd_t *fs_sd)
18655331Samw {
18665331Samw 	int error = 0;
18675331Samw 	int flags = 0;
18685331Samw 	int access = 0;
18695331Samw 	acl_t *acl;
18705331Samw 	smb_node_t *unnamed_node;
18715331Samw 
18725331Samw 	ASSERT(cr);
18735331Samw 
18748845Samw@Sun.COM 	if (SMB_TREE_HAS_ACCESS(sr, ACE_READ_ACL) == 0)
18758845Samw@Sun.COM 		return (EACCES);
18768845Samw@Sun.COM 
18775331Samw 	if (sr->fid_ofile) {
18785331Samw 		if (fs_sd->sd_secinfo & SMB_DACL_SECINFO)
18795331Samw 			access = READ_CONTROL;
18805331Samw 
18815331Samw 		if (fs_sd->sd_secinfo & SMB_SACL_SECINFO)
18825331Samw 			access |= ACCESS_SYSTEM_SECURITY;
18835331Samw 
18845331Samw 		error = smb_ofile_access(sr->fid_ofile, cr, access);
18855331Samw 		if (error != NT_STATUS_SUCCESS) {
18865331Samw 			return (EACCES);
18875331Samw 		}
18885331Samw 	}
18895331Samw 
18905331Samw 	unnamed_node = SMB_IS_STREAM(snode);
18915331Samw 	if (unnamed_node) {
18925331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
18935331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
18945331Samw 		/*
18955331Samw 		 * Streams don't have ACL, any read ACL attempt on a stream
18965331Samw 		 * should be performed on the unnamed stream.
18975331Samw 		 */
18985331Samw 		snode = unnamed_node;
18995331Samw 	}
19005331Samw 
19017348SJose.Borrego@Sun.COM 	if (smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACEMASKONACCESS))
19025331Samw 		flags = ATTR_NOACLCHECK;
19035331Samw 
19045331Samw 	error = smb_vop_acl_read(snode->vp, &acl, flags,
19055772Sas200622 	    sr->tid_tree->t_acltype, cr);
19065331Samw 	if (error != 0) {
19075331Samw 		return (error);
19085331Samw 	}
19095331Samw 
19105331Samw 	error = acl_translate(acl, _ACL_ACE_ENABLED,
19115331Samw 	    (snode->vp->v_type == VDIR), fs_sd->sd_uid, fs_sd->sd_gid);
19125331Samw 
19135331Samw 	if (error == 0) {
19145521Sas200622 		smb_fsacl_split(acl, &fs_sd->sd_zdacl, &fs_sd->sd_zsacl,
19155331Samw 		    fs_sd->sd_secinfo);
19165331Samw 	}
19175331Samw 
19185331Samw 	acl_free(acl);
19195331Samw 	return (error);
19205331Samw }
19215331Samw 
19225331Samw /*
19235331Samw  * smb_fsop_aclwrite
19245331Samw  *
19255331Samw  * Stores the filesystem ACL provided in fs_sd->sd_acl.
19265331Samw  */
19275331Samw int
19285331Samw smb_fsop_aclwrite(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
19295331Samw     smb_fssd_t *fs_sd)
19305331Samw {
19315331Samw 	int target_flavor;
19325331Samw 	int error = 0;
19335331Samw 	int flags = 0;
19345331Samw 	int access = 0;
19355331Samw 	acl_t *acl, *dacl, *sacl;
19365331Samw 	smb_node_t *unnamed_node;
19375331Samw 
19385331Samw 	ASSERT(cr);
19395331Samw 
19405331Samw 	ASSERT(sr);
19415331Samw 	ASSERT(sr->tid_tree);
19427348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
19435331Samw 		return (EROFS);
19445331Samw 
19458845Samw@Sun.COM 	if (SMB_TREE_HAS_ACCESS(sr, ACE_WRITE_ACL) == 0)
19468845Samw@Sun.COM 		return (EACCES);
19478845Samw@Sun.COM 
19485331Samw 	if (sr->fid_ofile) {
19495331Samw 		if (fs_sd->sd_secinfo & SMB_DACL_SECINFO)
19505331Samw 			access = WRITE_DAC;
19515331Samw 
19525331Samw 		if (fs_sd->sd_secinfo & SMB_SACL_SECINFO)
19535331Samw 			access |= ACCESS_SYSTEM_SECURITY;
19545331Samw 
19555331Samw 		error = smb_ofile_access(sr->fid_ofile, cr, access);
19565331Samw 		if (error != NT_STATUS_SUCCESS)
19575331Samw 			return (EACCES);
19585331Samw 	}
19595331Samw 
19605331Samw 	switch (sr->tid_tree->t_acltype) {
19615331Samw 	case ACLENT_T:
19625331Samw 		target_flavor = _ACL_ACLENT_ENABLED;
19635331Samw 		break;
19645331Samw 
19655331Samw 	case ACE_T:
19665331Samw 		target_flavor = _ACL_ACE_ENABLED;
19675331Samw 		break;
19685331Samw 	default:
19695331Samw 		return (EINVAL);
19705331Samw 	}
19715331Samw 
19725331Samw 	unnamed_node = SMB_IS_STREAM(snode);
19735331Samw 	if (unnamed_node) {
19745331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
19755331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
19765331Samw 		/*
19775331Samw 		 * Streams don't have ACL, any write ACL attempt on a stream
19785331Samw 		 * should be performed on the unnamed stream.
19795331Samw 		 */
19805331Samw 		snode = unnamed_node;
19815331Samw 	}
19825331Samw 
19835331Samw 	dacl = fs_sd->sd_zdacl;
19845331Samw 	sacl = fs_sd->sd_zsacl;
19855331Samw 
19865331Samw 	ASSERT(dacl || sacl);
19875331Samw 	if ((dacl == NULL) && (sacl == NULL))
19885331Samw 		return (EINVAL);
19895331Samw 
19905331Samw 	if (dacl && sacl)
19915521Sas200622 		acl = smb_fsacl_merge(dacl, sacl);
19925331Samw 	else if (dacl)
19935331Samw 		acl = dacl;
19945331Samw 	else
19955331Samw 		acl = sacl;
19965331Samw 
19975331Samw 	error = acl_translate(acl, target_flavor, (snode->vp->v_type == VDIR),
19985331Samw 	    fs_sd->sd_uid, fs_sd->sd_gid);
19995331Samw 	if (error == 0) {
20007348SJose.Borrego@Sun.COM 		if (smb_tree_has_feature(sr->tid_tree,
20017348SJose.Borrego@Sun.COM 		    SMB_TREE_ACEMASKONACCESS))
20025331Samw 			flags = ATTR_NOACLCHECK;
20035331Samw 
20045772Sas200622 		error = smb_vop_acl_write(snode->vp, acl, flags, cr);
20055331Samw 	}
20065331Samw 
20075331Samw 	if (dacl && sacl)
20085331Samw 		acl_free(acl);
20095331Samw 
20105331Samw 	return (error);
20115331Samw }
20125331Samw 
20135331Samw acl_type_t
20145331Samw smb_fsop_acltype(smb_node_t *snode)
20155331Samw {
20165331Samw 	return (smb_vop_acl_type(snode->vp));
20175331Samw }
20185331Samw 
20195331Samw /*
20205331Samw  * smb_fsop_sdread
20215331Samw  *
20225331Samw  * Read the requested security descriptor items from filesystem.
20235331Samw  * The items are specified in fs_sd->sd_secinfo.
20245331Samw  */
20255331Samw int
20265331Samw smb_fsop_sdread(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
20275331Samw     smb_fssd_t *fs_sd)
20285331Samw {
20295331Samw 	int error = 0;
20305331Samw 	int getowner = 0;
20315331Samw 	cred_t *ga_cred;
20325331Samw 	smb_attr_t attr;
20335331Samw 
20345331Samw 	ASSERT(cr);
20355331Samw 	ASSERT(fs_sd);
20365331Samw 
20375331Samw 	/*
20385331Samw 	 * File's uid/gid is fetched in two cases:
20395331Samw 	 *
20405331Samw 	 * 1. it's explicitly requested
20415331Samw 	 *
20425331Samw 	 * 2. target ACL is ACE_T (ZFS ACL). They're needed for
20435331Samw 	 *    owner@/group@ entries. In this case kcred should be used
20445331Samw 	 *    because uid/gid are fetched on behalf of smb server.
20455331Samw 	 */
20465331Samw 	if (fs_sd->sd_secinfo & (SMB_OWNER_SECINFO | SMB_GROUP_SECINFO)) {
20475331Samw 		getowner = 1;
20485331Samw 		ga_cred = cr;
20495331Samw 	} else if (sr->tid_tree->t_acltype == ACE_T) {
20505331Samw 		getowner = 1;
20515331Samw 		ga_cred = kcred;
20525331Samw 	}
20535331Samw 
20545331Samw 	if (getowner) {
20555331Samw 		/*
20565331Samw 		 * Windows require READ_CONTROL to read owner/group SID since
20575331Samw 		 * they're part of Security Descriptor.
20585331Samw 		 * ZFS only requires read_attribute. Need to have a explicit
20595331Samw 		 * access check here.
20605331Samw 		 */
20615331Samw 		if (sr->fid_ofile == NULL) {
20625331Samw 			error = smb_fsop_access(sr, ga_cred, snode,
20635331Samw 			    READ_CONTROL);
20645331Samw 			if (error)
2065*9914Samw@Sun.COM 				return (EACCES);
20665331Samw 		}
20675331Samw 
20685331Samw 		attr.sa_mask = SMB_AT_UID | SMB_AT_GID;
20695331Samw 		error = smb_fsop_getattr(sr, ga_cred, snode, &attr);
20705331Samw 		if (error == 0) {
20715331Samw 			fs_sd->sd_uid = attr.sa_vattr.va_uid;
20725331Samw 			fs_sd->sd_gid = attr.sa_vattr.va_gid;
20735331Samw 		} else {
20745331Samw 			return (error);
20755331Samw 		}
20765331Samw 	}
20775331Samw 
20785331Samw 	if (fs_sd->sd_secinfo & SMB_ACL_SECINFO) {
20795331Samw 		error = smb_fsop_aclread(sr, cr, snode, fs_sd);
20805331Samw 	}
20815331Samw 
20825331Samw 	return (error);
20835331Samw }
20845331Samw 
20855331Samw /*
20865331Samw  * smb_fsop_sdmerge
20875331Samw  *
20885331Samw  * From SMB point of view DACL and SACL are two separate list
20895331Samw  * which can be manipulated independently without one affecting
20905331Samw  * the other, but entries for both DACL and SACL will end up
20915331Samw  * in the same ACL if target filesystem supports ACE_T ACLs.
20925331Samw  *
20935331Samw  * So, if either DACL or SACL is present in the client set request
20945331Samw  * the entries corresponding to the non-present ACL shouldn't
20955331Samw  * be touched in the FS ACL.
20965331Samw  *
20975331Samw  * fs_sd parameter contains DACL and SACL specified by SMB
20985331Samw  * client to be set on a file/directory. The client could
20995331Samw  * specify both or one of these ACLs (if none is specified
21005331Samw  * we don't get this far). When both DACL and SACL are given
21015331Samw  * by client the existing ACL should be overwritten. If only
21025331Samw  * one of them is specified the entries corresponding to the other
21035331Samw  * ACL should not be touched. For example, if only DACL
21045331Samw  * is specified in input fs_sd, the function reads audit entries
21055331Samw  * of the existing ACL of the file and point fs_sd->sd_zsdacl
21065331Samw  * pointer to the fetched SACL, this way when smb_fsop_sdwrite()
21075331Samw  * function is called the passed fs_sd would point to the specified
21085331Samw  * DACL by client and fetched SACL from filesystem, so the file
21095331Samw  * will end up with correct ACL.
21105331Samw  */
21115331Samw static int
21125331Samw smb_fsop_sdmerge(smb_request_t *sr, smb_node_t *snode, smb_fssd_t *fs_sd)
21135331Samw {
21145331Samw 	smb_fssd_t cur_sd;
21155331Samw 	int error = 0;
21165331Samw 
21175331Samw 	if (sr->tid_tree->t_acltype != ACE_T)
21185331Samw 		/* Don't bother if target FS doesn't support ACE_T */
21195331Samw 		return (0);
21205331Samw 
21215331Samw 	if ((fs_sd->sd_secinfo & SMB_ACL_SECINFO) != SMB_ACL_SECINFO) {
21225331Samw 		if (fs_sd->sd_secinfo & SMB_DACL_SECINFO) {
21235331Samw 			/*
21245331Samw 			 * Don't overwrite existing audit entries
21255331Samw 			 */
21265521Sas200622 			smb_fssd_init(&cur_sd, SMB_SACL_SECINFO,
21275331Samw 			    fs_sd->sd_flags);
21285331Samw 
21295331Samw 			error = smb_fsop_sdread(sr, kcred, snode, &cur_sd);
21305331Samw 			if (error == 0) {
21315331Samw 				ASSERT(fs_sd->sd_zsacl == NULL);
21325331Samw 				fs_sd->sd_zsacl = cur_sd.sd_zsacl;
21335331Samw 				if (fs_sd->sd_zsacl && fs_sd->sd_zdacl)
21345331Samw 					fs_sd->sd_zsacl->acl_flags =
21355331Samw 					    fs_sd->sd_zdacl->acl_flags;
21365331Samw 			}
21375331Samw 		} else {
21385331Samw 			/*
21395331Samw 			 * Don't overwrite existing access entries
21405331Samw 			 */
21415521Sas200622 			smb_fssd_init(&cur_sd, SMB_DACL_SECINFO,
21425331Samw 			    fs_sd->sd_flags);
21435331Samw 
21445331Samw 			error = smb_fsop_sdread(sr, kcred, snode, &cur_sd);
21455331Samw 			if (error == 0) {
21465331Samw 				ASSERT(fs_sd->sd_zdacl == NULL);
21475331Samw 				fs_sd->sd_zdacl = cur_sd.sd_zdacl;
21485331Samw 				if (fs_sd->sd_zdacl && fs_sd->sd_zsacl)
21495331Samw 					fs_sd->sd_zdacl->acl_flags =
21505331Samw 					    fs_sd->sd_zsacl->acl_flags;
21515331Samw 			}
21525331Samw 		}
21535331Samw 
21545331Samw 		if (error)
21555521Sas200622 			smb_fssd_term(&cur_sd);
21565331Samw 	}
21575331Samw 
21585331Samw 	return (error);
21595331Samw }
21605331Samw 
21615331Samw /*
21625331Samw  * smb_fsop_sdwrite
21635331Samw  *
21645331Samw  * Stores the given uid, gid and acl in filesystem.
21655331Samw  * Provided items in fs_sd are specified by fs_sd->sd_secinfo.
21665331Samw  *
21675331Samw  * A SMB security descriptor could contain owner, primary group,
21685331Samw  * DACL and SACL. Setting an SD should be atomic but here it has to
21695331Samw  * be done via two separate FS operations: VOP_SETATTR and
21705331Samw  * VOP_SETSECATTR. Therefore, this function has to simulate the
21715331Samw  * atomicity as well as it can.
21727619SJose.Borrego@Sun.COM  *
21737619SJose.Borrego@Sun.COM  * Get the current uid, gid before setting the new uid/gid
21747619SJose.Borrego@Sun.COM  * so if smb_fsop_aclwrite fails they can be restored. root cred is
21757619SJose.Borrego@Sun.COM  * used to get currend uid/gid since this operation is performed on
21767619SJose.Borrego@Sun.COM  * behalf of the server not the user.
21777619SJose.Borrego@Sun.COM  *
21787619SJose.Borrego@Sun.COM  * If setting uid/gid fails with EPERM it means that and invalid
21797619SJose.Borrego@Sun.COM  * owner has been specified. Callers should translate this to
21807619SJose.Borrego@Sun.COM  * STATUS_INVALID_OWNER which is not the normal mapping for EPERM
21817619SJose.Borrego@Sun.COM  * in upper layers, so EPERM is mapped to EBADE.
21825331Samw  */
21835331Samw int
21845331Samw smb_fsop_sdwrite(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
21855331Samw     smb_fssd_t *fs_sd, int overwrite)
21865331Samw {
21875331Samw 	int error = 0;
21885331Samw 	int access = 0;
21895331Samw 	smb_attr_t set_attr;
21905331Samw 	smb_attr_t orig_attr;
21915331Samw 
21925331Samw 	ASSERT(cr);
21935331Samw 	ASSERT(fs_sd);
21945331Samw 
21955331Samw 	ASSERT(sr);
21965331Samw 	ASSERT(sr->tid_tree);
21977348SJose.Borrego@Sun.COM 	if (SMB_TREE_IS_READONLY(sr))
21985331Samw 		return (EROFS);
21995331Samw 
22005331Samw 	bzero(&set_attr, sizeof (smb_attr_t));
22015331Samw 
22025331Samw 	if (fs_sd->sd_secinfo & SMB_OWNER_SECINFO) {
22035331Samw 		set_attr.sa_vattr.va_uid = fs_sd->sd_uid;
22045331Samw 		set_attr.sa_mask |= SMB_AT_UID;
22057619SJose.Borrego@Sun.COM 		access |= WRITE_OWNER;
22065331Samw 	}
22075331Samw 
22085331Samw 	if (fs_sd->sd_secinfo & SMB_GROUP_SECINFO) {
22095331Samw 		set_attr.sa_vattr.va_gid = fs_sd->sd_gid;
22105331Samw 		set_attr.sa_mask |= SMB_AT_GID;
22117619SJose.Borrego@Sun.COM 		access |= WRITE_OWNER;
22125331Samw 	}
22135331Samw 
22145331Samw 	if (fs_sd->sd_secinfo & SMB_DACL_SECINFO)
22155331Samw 		access |= WRITE_DAC;
22165331Samw 
22175331Samw 	if (fs_sd->sd_secinfo & SMB_SACL_SECINFO)
22185331Samw 		access |= ACCESS_SYSTEM_SECURITY;
22195331Samw 
22205331Samw 	if (sr->fid_ofile)
22215331Samw 		error = smb_ofile_access(sr->fid_ofile, cr, access);
22225331Samw 	else
22235331Samw 		error = smb_fsop_access(sr, cr, snode, access);
22245331Samw 
22255331Samw 	if (error)
22265331Samw 		return (EACCES);
22275331Samw 
22285331Samw 	if (set_attr.sa_mask) {
22295331Samw 		orig_attr.sa_mask = SMB_AT_UID | SMB_AT_GID;
22305331Samw 		error = smb_fsop_getattr(sr, kcred, snode, &orig_attr);
22317619SJose.Borrego@Sun.COM 		if (error == 0) {
22325331Samw 			error = smb_fsop_setattr(sr, cr, snode, &set_attr,
22335331Samw 			    NULL);
22347619SJose.Borrego@Sun.COM 			if (error == EPERM)
22357619SJose.Borrego@Sun.COM 				error = EBADE;
22367619SJose.Borrego@Sun.COM 		}
22375331Samw 
22385331Samw 		if (error)
22395331Samw 			return (error);
22405331Samw 	}
22415331Samw 
22425331Samw 	if (fs_sd->sd_secinfo & SMB_ACL_SECINFO) {
22435331Samw 		if (overwrite == 0) {
22445331Samw 			error = smb_fsop_sdmerge(sr, snode, fs_sd);
22455331Samw 			if (error)
22465331Samw 				return (error);
22475331Samw 		}
22485331Samw 
22495331Samw 		error = smb_fsop_aclwrite(sr, cr, snode, fs_sd);
22505331Samw 		if (error) {
22515331Samw 			/*
22525331Samw 			 * Revert uid/gid changes if required.
22535331Samw 			 */
22545331Samw 			if (set_attr.sa_mask) {
22555331Samw 				orig_attr.sa_mask = set_attr.sa_mask;
22565331Samw 				(void) smb_fsop_setattr(sr, kcred, snode,
22575331Samw 				    &orig_attr, NULL);
22585331Samw 			}
22595331Samw 		}
22605331Samw 	}
22615331Samw 
22625331Samw 	return (error);
22635331Samw }
22645331Samw 
22655331Samw /*
22665331Samw  * smb_fsop_sdinherit
22675331Samw  *
22685331Samw  * Inherit the security descriptor from the parent container.
22695331Samw  * This function is called after FS has created the file/folder
22705331Samw  * so if this doesn't do anything it means FS inheritance is
22715331Samw  * in place.
22725331Samw  *
22735331Samw  * Do inheritance for ZFS internally.
22745331Samw  *
22755331Samw  * If we want to let ZFS does the inheritance the
22765331Samw  * following setting should be true:
22775331Samw  *
22785331Samw  *  - aclinherit = passthrough
22795331Samw  *  - aclmode = passthrough
22805331Samw  *  - smbd umask = 0777
22815331Samw  *
22825331Samw  * This will result in right effective permissions but
22835331Samw  * ZFS will always add 6 ACEs for owner, owning group
22845331Samw  * and others to be POSIX compliant. This is not what
22855331Samw  * Windows clients/users expect, so we decided that CIFS
22865331Samw  * implements Windows rules and overwrite whatever ZFS
22875331Samw  * comes up with. This way we also don't have to care
22885331Samw  * about ZFS aclinherit and aclmode settings.
22895331Samw  */
22905331Samw static int
22915331Samw smb_fsop_sdinherit(smb_request_t *sr, smb_node_t *dnode, smb_fssd_t *fs_sd)
22925331Samw {
22935331Samw 	int is_dir;
22945521Sas200622 	acl_t *dacl = NULL;
22955521Sas200622 	acl_t *sacl = NULL;
22965331Samw 	ksid_t *owner_sid;
22975331Samw 	int error;
22985331Samw 
22995331Samw 	ASSERT(fs_sd);
23005331Samw 
23015331Samw 	if (sr->tid_tree->t_acltype != ACE_T) {
23025331Samw 		/*
23035331Samw 		 * No forced inheritance for non-ZFS filesystems.
23045331Samw 		 */
23055331Samw 		fs_sd->sd_secinfo = 0;
23065331Samw 		return (0);
23075331Samw 	}
23085331Samw 
23095331Samw 
23105331Samw 	/* Fetch parent directory's ACL */
23115331Samw 	error = smb_fsop_sdread(sr, kcred, dnode, fs_sd);
23125331Samw 	if (error) {
23135331Samw 		return (error);
23145331Samw 	}
23155331Samw 
23165331Samw 	is_dir = (fs_sd->sd_flags & SMB_FSSD_FLAGS_DIR);
23175331Samw 	owner_sid = crgetsid(sr->user_cr, KSID_OWNER);
23185331Samw 	ASSERT(owner_sid);
23195521Sas200622 	dacl = smb_fsacl_inherit(fs_sd->sd_zdacl, is_dir, SMB_DACL_SECINFO,
23205331Samw 	    owner_sid->ks_id);
23215521Sas200622 	sacl = smb_fsacl_inherit(fs_sd->sd_zsacl, is_dir, SMB_SACL_SECINFO,
23225331Samw 	    (uid_t)-1);
23235331Samw 
23245521Sas200622 	if (sacl == NULL)
23255521Sas200622 		fs_sd->sd_secinfo &= ~SMB_SACL_SECINFO;
23265521Sas200622 
23275521Sas200622 	smb_fsacl_free(fs_sd->sd_zdacl);
23285521Sas200622 	smb_fsacl_free(fs_sd->sd_zsacl);
23295331Samw 
23305331Samw 	fs_sd->sd_zdacl = dacl;
23315331Samw 	fs_sd->sd_zsacl = sacl;
23325331Samw 
23335331Samw 	return (0);
23345331Samw }
23355331Samw 
23365331Samw /*
23375331Samw  * smb_fsop_eaccess
23385331Samw  *
23395331Samw  * Returns the effective permission of the given credential for the
23405331Samw  * specified object.
23415331Samw  *
23425331Samw  * This is just a workaround. We need VFS/FS support for this.
23435331Samw  */
23445331Samw void
23455331Samw smb_fsop_eaccess(smb_request_t *sr, cred_t *cr, smb_node_t *snode,
23465331Samw     uint32_t *eaccess)
23475331Samw {
23485331Samw 	int access = 0;
23495331Samw 	vnode_t *dir_vp;
23505331Samw 	smb_node_t *unnamed_node;
23515331Samw 
23525331Samw 	ASSERT(cr);
23535331Samw 	ASSERT(snode);
23545331Samw 	ASSERT(snode->n_magic == SMB_NODE_MAGIC);
23555331Samw 	ASSERT(snode->n_state != SMB_NODE_STATE_DESTROYING);
23565331Samw 
23575331Samw 	unnamed_node = SMB_IS_STREAM(snode);
23585331Samw 	if (unnamed_node) {
23595331Samw 		ASSERT(unnamed_node->n_magic == SMB_NODE_MAGIC);
23605331Samw 		ASSERT(unnamed_node->n_state != SMB_NODE_STATE_DESTROYING);
23615331Samw 		/*
23625331Samw 		 * Streams authorization should be performed against the
23635331Samw 		 * unnamed stream.
23645331Samw 		 */
23655331Samw 		snode = unnamed_node;
23665331Samw 	}
23675331Samw 
23687348SJose.Borrego@Sun.COM 	if (smb_tree_has_feature(sr->tid_tree, SMB_TREE_ACEMASKONACCESS)) {
23695331Samw 		dir_vp = (snode->dir_snode) ? snode->dir_snode->vp : NULL;
23705331Samw 		smb_vop_eaccess(snode->vp, (int *)eaccess, V_ACE_MASK, dir_vp,
23715331Samw 		    cr);
23725331Samw 		return;
23735331Samw 	}
23745331Samw 
23755331Samw 	/*
23765331Samw 	 * FS doesn't understand 32-bit mask
23775331Samw 	 */
23785331Samw 	smb_vop_eaccess(snode->vp, &access, 0, NULL, cr);
23798845Samw@Sun.COM 	access &= sr->tid_tree->t_access;
23805331Samw 
23815331Samw 	*eaccess = READ_CONTROL | FILE_READ_EA | FILE_READ_ATTRIBUTES;
23825331Samw 
23835331Samw 	if (access & VREAD)
23845331Samw 		*eaccess |= FILE_READ_DATA;
23855331Samw 
23865331Samw 	if (access & VEXEC)
23875331Samw 		*eaccess |= FILE_EXECUTE;
23885331Samw 
23895331Samw 	if (access & VWRITE)
23905331Samw 		*eaccess |= FILE_WRITE_DATA | FILE_WRITE_ATTRIBUTES |
23915331Samw 		    FILE_WRITE_EA | FILE_APPEND_DATA | FILE_DELETE_CHILD;
23925331Samw }
23935521Sas200622 
23945772Sas200622 /*
23955772Sas200622  * smb_fsop_shrlock
23965772Sas200622  *
23975772Sas200622  * For the current open request, check file sharing rules
23985772Sas200622  * against existing opens.
23995772Sas200622  *
24005772Sas200622  * Returns NT_STATUS_SHARING_VIOLATION if there is any
24015772Sas200622  * sharing conflict.  Returns NT_STATUS_SUCCESS otherwise.
24025772Sas200622  *
24035772Sas200622  * Full system-wide share reservation synchronization is available
24045772Sas200622  * when the nbmand (non-blocking mandatory) mount option is set
24055772Sas200622  * (i.e. nbl_need_crit() is true) and nbmand critical regions are used.
24065772Sas200622  * This provides synchronization with NFS and local processes.  The
24075772Sas200622  * critical regions are entered in VOP_SHRLOCK()/fs_shrlock() (called
24085772Sas200622  * from smb_open_subr()/smb_fsop_shrlock()/smb_vop_shrlock()) as well
24095772Sas200622  * as the CIFS rename and delete paths.
24105772Sas200622  *
24115772Sas200622  * The CIFS server will also enter the nbl critical region in the open,
24125772Sas200622  * rename, and delete paths when nbmand is not set.  There is limited
24135772Sas200622  * coordination with local and VFS share reservations in this case.
24145772Sas200622  * Note that when the nbmand mount option is not set, the VFS layer
24155772Sas200622  * only processes advisory reservations and the delete mode is not checked.
24165772Sas200622  *
24175772Sas200622  * Whether or not the nbmand mount option is set, intra-CIFS share
24185772Sas200622  * checking is done in the open, delete, and rename paths using a CIFS
24195772Sas200622  * critical region (node->n_share_lock).
24205772Sas200622  */
24215772Sas200622 
24225772Sas200622 uint32_t
24236139Sjb150015 smb_fsop_shrlock(cred_t *cr, smb_node_t *node, uint32_t uniq_fid,
24245772Sas200622     uint32_t desired_access, uint32_t share_access)
24255772Sas200622 {
24265772Sas200622 	int rc;
24275772Sas200622 
24285772Sas200622 	if (node->attr.sa_vattr.va_type == VDIR)
24295772Sas200622 		return (NT_STATUS_SUCCESS);
24305772Sas200622 
24315772Sas200622 	/* Allow access if the request is just for meta data */
24325772Sas200622 	if ((desired_access & FILE_DATA_ALL) == 0)
24335772Sas200622 		return (NT_STATUS_SUCCESS);
24345772Sas200622 
24355772Sas200622 	rc = smb_node_open_check(node, cr, desired_access, share_access);
24365772Sas200622 	if (rc)
24375772Sas200622 		return (NT_STATUS_SHARING_VIOLATION);
24385772Sas200622 
24395772Sas200622 	rc = smb_vop_shrlock(node->vp, uniq_fid, desired_access, share_access,
24405772Sas200622 	    cr);
24415772Sas200622 	if (rc)
24425772Sas200622 		return (NT_STATUS_SHARING_VIOLATION);
24435772Sas200622 
24445772Sas200622 	return (NT_STATUS_SUCCESS);
24455772Sas200622 }
24465772Sas200622 
24475521Sas200622 void
24485772Sas200622 smb_fsop_unshrlock(cred_t *cr, smb_node_t *node, uint32_t uniq_fid)
24495521Sas200622 {
24505772Sas200622 	if (node->attr.sa_vattr.va_type == VDIR)
24515772Sas200622 		return;
24525772Sas200622 
24535772Sas200622 	(void) smb_vop_unshrlock(node->vp, uniq_fid, cr);
24545772Sas200622 }
24556600Sas200622 
24566600Sas200622 int
24576600Sas200622 smb_fsop_frlock(smb_node_t *node, smb_lock_t *lock, boolean_t unlock,
24586600Sas200622     cred_t *cr)
24596600Sas200622 {
24606600Sas200622 	flock64_t bf;
24616600Sas200622 	int flag = F_REMOTELOCK;
24626600Sas200622 
24636771Sjb150015 	/*
24646771Sjb150015 	 * VOP_FRLOCK() will not be called if:
24656771Sjb150015 	 *
24666771Sjb150015 	 * 1) The lock has a range of zero bytes. The semantics of Windows and
24676771Sjb150015 	 *    POSIX are different. In the case of POSIX it asks for the locking
24686771Sjb150015 	 *    of all the bytes from the offset provided until the end of the
24696771Sjb150015 	 *    file. In the case of Windows a range of zero locks nothing and
24706771Sjb150015 	 *    doesn't conflict with any other lock.
24716771Sjb150015 	 *
24726771Sjb150015 	 * 2) The lock rolls over (start + lenght < start). Solaris will assert
24736771Sjb150015 	 *    if such a request is submitted. This will not create
24746771Sjb150015 	 *    incompatibilities between POSIX and Windows. In the Windows world,
24756771Sjb150015 	 *    if a client submits such a lock, the server will not lock any
24766771Sjb150015 	 *    bytes. Interestingly if the same lock (same offset and length) is
24776771Sjb150015 	 *    resubmitted Windows will consider that there is an overlap and
24786771Sjb150015 	 *    the granting rules will then apply.
24796771Sjb150015 	 */
24806771Sjb150015 	if ((lock->l_length == 0) ||
24816771Sjb150015 	    ((lock->l_start + lock->l_length - 1) < lock->l_start))
24826771Sjb150015 		return (0);
24836771Sjb150015 
24846600Sas200622 	bzero(&bf, sizeof (bf));
24856600Sas200622 
24866600Sas200622 	if (unlock) {
24876600Sas200622 		bf.l_type = F_UNLCK;
24886600Sas200622 	} else if (lock->l_type == SMB_LOCK_TYPE_READONLY) {
24896600Sas200622 		bf.l_type = F_RDLCK;
24906600Sas200622 		flag |= FREAD;
24916600Sas200622 	} else if (lock->l_type == SMB_LOCK_TYPE_READWRITE) {
24926600Sas200622 		bf.l_type = F_WRLCK;
24936600Sas200622 		flag |= FWRITE;
24946600Sas200622 	}
24956600Sas200622 
24966600Sas200622 	bf.l_start = lock->l_start;
24976600Sas200622 	bf.l_len = lock->l_length;
24987348SJose.Borrego@Sun.COM 	bf.l_pid = lock->l_file->f_uniqid;
24996600Sas200622 	bf.l_sysid = smb_ct.cc_sysid;
25006600Sas200622 
25016600Sas200622 	return (smb_vop_frlock(node->vp, cr, flag, &bf));
25026600Sas200622 }
2503